WO2014063360A1 - 业务接入的控制方法及设备 - Google Patents

业务接入的控制方法及设备 Download PDF

Info

Publication number
WO2014063360A1
WO2014063360A1 PCT/CN2012/083600 CN2012083600W WO2014063360A1 WO 2014063360 A1 WO2014063360 A1 WO 2014063360A1 CN 2012083600 W CN2012083600 W CN 2012083600W WO 2014063360 A1 WO2014063360 A1 WO 2014063360A1
Authority
WO
WIPO (PCT)
Prior art keywords
service
terminal
network
allowed
access
Prior art date
Application number
PCT/CN2012/083600
Other languages
English (en)
French (fr)
Inventor
张万强
赵旸
马德曼·弗兰克
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2012/083600 priority Critical patent/WO2014063360A1/zh
Priority to CN201280002943.7A priority patent/CN104662966B/zh
Priority to CN201811545031.XA priority patent/CN109963320B/zh
Publication of WO2014063360A1 publication Critical patent/WO2014063360A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery
    • H04W48/10Access restriction or access information delivery, e.g. discovery data delivery using broadcasted information

Definitions

  • the invention belongs to the field of communications, and in particular relates to a method and a device for controlling service access.
  • the 3rd Generation Partnership Project, 3GPP has proposed some access control mechanisms, such as Access Class Barring (ACB), Domain Access Control (Domain) Specific Access Control (DSAC), Service Specific Access (Service Specific Access) Control, SSAC) and extended access control (Extended Access) Barring, EAB), etc.
  • ACB and EAB initiate user origination of all services on the terminal in the case of network congestion (Mobile origination, MO Request, the DSAC mechanism only controls the terminal to initiate Circuit Switched (CS) domain services or packet switching (Packet) Switched) domain services, SSAC is only to control the initiation of voice or video calls and other services.
  • ACB and EAB initiate user origination of all services on the terminal in the case of network congestion (Mobile origination, MO Request
  • the DSAC mechanism only controls the terminal to initiate Circuit Switched (CS) domain services or packet switching (Packet) Switched) domain services
  • SSAC is only to control the initiation of voice or video calls and other services.
  • the 3GPP standards organization also proposed service-based data connectivity and congestion control (Application Specific Congestion control for Data Connectivity, ACDC) research project, discussed the above application scenarios and needs, but has not yet proposed a corresponding solution.
  • ACDC Application Specific Congestion control for Data Connectivity
  • the embodiment of the invention provides a control method for service access, which implements control of a specific service access network.
  • the network notifies the terminal that the ACDC is activated, and the terminal controls the service, or the network controls the terminal access message to ensure that the specific service is allowed to access the network even if the access control is implemented. And prohibit other services from accessing the network.
  • network resources are saved, access to the allowed service is guaranteed, and the operator's ability to control the service and the emergency event is enhanced.
  • the first aspect is a method for controlling service access, where the method includes:
  • the terminal acquires service list information or service level index information, where the service list information includes identification information of a service that is allowed and/or prohibited, and the service level index information includes identification and level information of the allowed and/or prohibited services;
  • the terminal After the terminal receives the indication sent by the network, it determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access, and if so, initiates the terminal to initiate to the network. If the service access request is not, the service access request to be initiated by the terminal is prohibited from being initiated to the network.
  • the acquiring, by the terminal, the service list information or the service level index information from the network is specifically:
  • the terminal receives service list information or service level index information in a manner that the network passes through the OMA DM.
  • the acquiring, by the terminal, the service list information or the service level index information from the network is specifically:
  • the terminal receives service list information or service level index information by means of NAS signaling by the network.
  • the acquiring, by the terminal, the service list information or the service level index information from the network is specifically:
  • the terminal receives the service list information or the service level index information that is broadcast by the network through the system.
  • the fourth aspect of the first aspect In conjunction with the first aspect or the first possible implementation of the first aspect or in combination with the second possible implementation of the first aspect or in combination with the third possible implementation of the first aspect, the fourth aspect of the first aspect In a possible implementation manner, after the terminal receives the indication sent by the network, determining, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to be:
  • the non-access stratum or the access layer of the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access.
  • the method further includes:
  • the terminal When the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed to access, the terminal initiates a connection establishment request message to the network, where the request information carries the service permission. And determining, by the network, whether the service to be initiated by the terminal is allowed according to the identifier.
  • the terminal when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal initiates request information to the network.
  • the request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to be specifically:
  • the access layer of the terminal When the terminal determines, according to the service list information or the service level index information, the service permission to be initiated by the terminal, the access layer of the terminal initiates an RRC connection request message to the network, where the RRC connection request information is carried. Whether the service allows the identification, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to access;
  • the non-access stratum of the terminal initiates a NAS message to the network, where the NAS message carries the service. Whether the identification is allowed, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to access.
  • the receiving, by the terminal, the indication sent by the network is specifically:
  • the terminal acquires an indication from the network by means of a system broadcast message or a dedicated signaling manner or an application layer.
  • the terminal after the terminal receives the indication sent by the network, determining, according to the service list information or the service level index information, whether the service to be initiated by the terminal allows specific for:
  • the terminal After the terminal receives the indication sent by the network, the terminal determines, by the terminal firewall, whether the service to be initiated by the terminal is allowed to access according to the service list information or the service level index information.
  • the second aspect is a method for controlling service access, where the method includes:
  • the network configures the service list information or the service level index information to the terminal;
  • the network configuration service list information or service level index information to the terminal is specifically:
  • the network configures service list information or configures service level index information to the terminal in the manner of OMA DM.
  • the network configuration service list information or service level index information is specifically provided to the terminal:
  • the network configures service list information or configures service level index information to the terminal in the manner of NAS signaling.
  • the network configuration service list information or service level index information is specifically provided to the terminal:
  • the network configures service list information or configures service level index information to the terminal by means of system broadcast.
  • the sending, by the network, the indication to the terminal is specifically:
  • the network sends an indication to the terminal by way of system broadcast or dedicated signaling.
  • the method further includes:
  • connection establishment request message sent by the terminal, where the connection establishment request message carries an identifier of whether the service is allowed to access
  • the network determines, according to the identifier, whether the service to be initiated by the terminal allows access.
  • the network determines, according to the identifier of the service that is carried in the request information sent by the terminal, Whether the business is allowed to be specific:
  • the radio access network of the network determines whether the service to be initiated by the terminal is allowed according to whether the RRC connection request information initiated by the terminal carries the identifier allowed by the service.
  • the network determines, according to the identifier of the service that is carried in the request information sent by the terminal, Whether the business is allowed to be specific:
  • the core network of the network determines whether the service to be initiated by the terminal is allowed according to whether the NAS message initiated by the terminal carries the identifier allowed by the service.
  • the network configured to configure the service list information or the service level index information to the terminal, specifically:
  • the network configures service list information or service level index information to the terminal through the firewall server.
  • the indication sent by the network to the terminal is specifically:
  • the network sends an indication to the terminal in a manner of a system broadcast or a dedicated signaling manner or an application layer.
  • a third aspect is a terminal device, where the device includes:
  • An obtaining unit configured to acquire, by the terminal, service list information or service level index information, where the service list information includes identification information of a service that is allowed and/or prohibited, where the service level index information includes an identifier of a service that is allowed and/or prohibited. Level information; the obtaining unit sends the obtained service list information or service level index information to the access control unit;
  • the access control unit is configured to: after the terminal receives the indication sent by the network, determine, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access, and if yes, The network initiates a service access request to be initiated by the terminal, and if not, the service access request to be initiated by the terminal is prohibited from being initiated to the network.
  • the acquiring unit is specifically configured to:
  • the terminal receives service list information or service level index information in a manner that the network passes through the OMA DM.
  • the acquiring unit is specifically configured to:
  • the terminal receives service list information or service level index information by means of NAS signaling by the network.
  • the acquiring unit is specifically configured to:
  • the terminal receives the service list information or the service level index information that is broadcast by the network through the system.
  • the access control unit is specifically configured to:
  • the non-access stratum or the access layer of the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access.
  • the device further includes:
  • an identifier unit configured to: when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal initiates request information to the network, where the request information carries the service permission.
  • the identifier is such that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the identifying unit is specifically configured to:
  • the access layer of the terminal When the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed to access, the access layer of the terminal initiates radio resource control RRC connection request information to the network, where the RRC And determining, by the connection request information, whether the service is allowed to be accessed, and determining, by the network, whether the service to be initiated by the terminal is allowed to access according to the identifier;
  • the non-access stratum of the terminal initiates a NAS message to the network, where the NAS message carries the service. Whether the identification is allowed, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to access.
  • the access control unit is specifically configured to:
  • the terminal acquires an indication from the network by means of a system broadcast message or a dedicated signaling manner or an application layer.
  • the access control unit is specifically configured to:
  • the terminal After the terminal receives the indication sent by the network, the terminal determines, by the terminal firewall, whether the service to be initiated by the terminal is allowed to access according to the service list information or the service level index information.
  • a fourth aspect is a network element device, where the device includes:
  • a configuration unit configured to configure, by the network, service list information or service level index information to the terminal;
  • a sending unit configured to send, by the network, an indication sent by the network to the terminal, so that the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access.
  • configuration unit is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal in the manner of OMA DM.
  • configuration unit is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal in the manner of NAS signaling.
  • the network configures service list information or configures service level index information to the terminal by means of system broadcast.
  • the sending unit is specifically configured to:
  • the network sends an indication to the terminal by way of system broadcast or dedicated signaling.
  • the device further includes:
  • a processing unit configured to receive, by the network, a connection establishment request message sent by the terminal, where the connection establishment request message carries an identifier indicating whether the service is allowed to access;
  • the network determines, according to the identifier, whether the service to be initiated by the terminal allows access.
  • processing unit is specifically configured to:
  • the radio access network of the network determines whether the service to be initiated by the terminal is allowed according to whether the RRC connection request information initiated by the terminal carries the identifier allowed by the service.
  • processing unit is specifically configured to:
  • the core network of the network determines whether the service to be initiated by the terminal is allowed according to whether the NAS message initiated by the terminal carries the identifier allowed by the service.
  • configuration unit is specifically configured to:
  • the network sends the service list information or the service level index information to the terminal through the firewall server.
  • the sending unit is specifically configured to:
  • the network sends an indication to the terminal in a manner of a system broadcast or a dedicated signaling manner or an application layer.
  • a fifth aspect is a terminal device, where the device includes:
  • An obtaining unit configured to acquire, by the terminal, service list information or service level index information, where the service list information includes identification information of a service that is allowed and/or prohibited, where the service level index information includes an identifier of a service that is allowed and/or prohibited. Level information; the obtaining unit sends the obtained service list information or service level index information to the access control unit;
  • the access control unit is configured to: after the terminal receives the indication sent by the network, determine, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access, and if yes, The network initiates a service access request to be initiated by the terminal, and if not, the service access request to be initiated by the terminal is prohibited from being initiated to the network.
  • the device includes a processor, a communication interface, a memory, and a bus;
  • the processor, the communication interface, and the memory complete communication with each other through the bus;
  • the communication interface is configured to communicate with a network element device
  • the processor is configured to execute a program
  • the memory is configured to store a program
  • the program is used by the terminal to pre-configure, or obtain service list information or service level index information from the network, where the service list information or the service level index information includes identification information of the allowed and/or prohibited services; After receiving the indication sent by the network, the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access, and if so, initiates the service connection initiated by the terminal to the network. If the request is negative, the service access request to be initiated by the terminal is prohibited from being initiated to the network.
  • the acquiring unit is specifically configured to:
  • the terminal receives service list information or service level index information in a manner that the network passes through the OMA DM.
  • the acquiring unit is specifically configured to:
  • the terminal receives service list information or service level index information by means of NAS signaling by the network.
  • the acquiring unit is specifically configured to:
  • the terminal receives service list information or service level index information that is broadcast by the network through the system.
  • the non-access stratum or the access layer of the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access.
  • the device further includes:
  • an identifier unit configured to: when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal initiates request information to the network, where the request information carries the service permission.
  • the identifier is such that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the identifier unit is specifically configured to:
  • the access layer of the terminal When the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed to access, the access layer of the terminal initiates radio resource control RRC connection request information to the network, where the RRC And determining, by the connection request information, whether the service is allowed to be accessed, and determining, by the network, whether the service to be initiated by the terminal is allowed to access according to the identifier;
  • the non-access stratum of the terminal initiates a NAS message to the network, where the NAS message carries the service. Whether the identification is allowed, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to access.
  • the access control unit is specifically configured to:
  • the terminal acquires an indication from the network by means of a system broadcast message or a dedicated signaling manner or an application layer.
  • the access control unit is specifically configured to:
  • the terminal After the terminal receives the indication sent by the network, the terminal determines, by the terminal firewall, whether the service to be initiated by the terminal is allowed to access according to the service list information or the service level index information.
  • the sixth aspect is a network element device, where the network element device includes:
  • a configuration unit configured to configure, by the network, service list information or service level index information to the terminal;
  • a sending unit configured to: send, by the network, an indication sent by the network to the terminal, so that the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access.
  • the network element device includes a processor, a communication interface, a memory, and a bus:
  • the processor, the communication interface, and the memory complete communication with each other through the bus;
  • the communication interface is configured to communicate with a terminal device
  • the processor is configured to execute a program
  • the memory is configured to store a program
  • the program is used by the network to configure the service list information or the service level index information to the terminal; the indication sent by the network to the terminal, so that the terminal determines that the terminal is to be initiated according to the service list information or the service level index information. Whether the business allows access.
  • the configuration unit is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal in the manner of OMA DM.
  • the configuration unit is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal in the manner of NAS signaling.
  • the configuration unit is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal by means of system broadcast.
  • the sending unit is specifically configured to:
  • the network sends an indication to the terminal by way of system broadcast or dedicated signaling.
  • the device further includes:
  • a processing unit configured to receive, by the network, a connection establishment request message sent by the terminal, where the connection establishment request message carries an identifier indicating whether the service is allowed to access;
  • the network determines, according to the identifier, whether the service to be initiated by the terminal allows access.
  • processing unit is specifically configured to:
  • the radio access network of the network determines whether the service to be initiated by the terminal is allowed according to whether the RRC connection request information initiated by the terminal carries the identifier allowed by the service.
  • processing unit is specifically configured to:
  • the core network of the network determines whether the service to be initiated by the terminal is allowed according to whether the NAS message initiated by the terminal carries the identifier allowed by the service.
  • the configuration unit is specifically configured to:
  • the network sends the service list information or the service level index information to the terminal through the firewall server.
  • the sending unit is specifically configured to:
  • the network sends an indication to the terminal in a manner of a system broadcast or a dedicated signaling manner or an application layer.
  • the present invention discloses a method for controlling service access, which obtains service list information or service level index information from a network through a terminal; and when the terminal receives an indication sent by the network, according to the service
  • the list information or the service level index information is used to determine whether the service to be initiated by the terminal is allowed, and if so, the service to be initiated by the terminal is initiated to the network, and if not, the service to be initiated by the terminal is prohibited from being initiated to the network;
  • the network may also verify the service access message to be initiated by the terminal, and implement the network to control the service to be initiated by the terminal.
  • the service access control in a specific scenario or network congestion is implemented, the network resources are saved to ensure the access of the allowed service, and the operator's ability to control the service and the emergency event is enhanced.
  • Embodiment 1 is a flowchart of a method for controlling service access according to Embodiment 1 of the present invention
  • FIG. 2 is a flowchart of a method for controlling service access according to Embodiment 2 of the present invention
  • Embodiment 3 is a flowchart of a method for controlling service access according to Embodiment 3 of the present invention.
  • Embodiment 4 is a flowchart of a method for controlling service access according to Embodiment 4 of the present invention.
  • FIG. 5 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 8 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 10 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 11 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 12 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 13 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 14 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention.
  • FIG. 15 is a structural diagram of a device of a terminal device according to Embodiment 5 of the present invention.
  • FIG. 16 is a structural diagram of a device of a network element device according to Embodiment 6 of the present invention.
  • FIG. 17 is a structural diagram of a device of a terminal device according to Embodiment 7 of the present invention.
  • FIG. 18 is a structural diagram of a device of a network element device according to Embodiment 8 of the present invention.
  • FIG. 1 is a flowchart of a method for controlling access of a service according to Embodiment 1 of the present invention. As shown in Figure 1, the method includes the following steps:
  • Step 101 The terminal acquires service list information or service level index information, where the service list information includes identification information of a service that is allowed and/or prohibited, and the service level index information includes identifier and level information of the allowed and/or prohibited services. ;
  • the terminal can obtain service list information or service level index information in a pre-configured manner.
  • the pre-configured manner may be configured to store the service list information or the service level index information on the mobile phone SIM card in advance.
  • the service list information may be in the form of a black or white list, and the list includes a service identifier that allows or prohibits the service.
  • the service level index information includes the service identifier of the service type, and the level index information of the service type, and the service is divided according to the type of the service, and the index information is established according to the division, so that the terminal can perform the preset type service. To allow or prohibit the operation, it is also possible to allow or prohibit the operation of different levels of business.
  • the service to be initiated by the terminal belongs to the allowed level in the service level index information, it is determined that the service to be initiated by the terminal is allowed to access.
  • the manner in which the terminal obtains the service list information or the service level index information from the network includes but is not limited to the following manner: through the open mobile alliance device management through the receiving network (Open Mobile Alliance Device Management, OMA DM) mode service list information or service level index information, or receiving network through non-access stratum (Non-Access) Stratum, NAS) signaling service list information or service level index information, or service list information or service level index information sent by the network through the system broadcast, or the terminal receives broadcast by the network through the system Way of business listing information or business class index information.
  • OMA DM Open Mobile Alliance Device Management
  • NAS non-access stratum
  • the terminal obtains the service list information or the service level index information from the network, specifically:
  • the terminal receives service list information or service level index information in a manner that the network passes through the OMA DM.
  • the network passes OMA
  • the DM mode configures service list information or service level index information to the terminal.
  • the network passes OMA.
  • the DM mode configures service list information or service level index information to the terminal.
  • the terminal passes the OMA by receiving the network
  • the service list information or the service level index information sent by the DM can be configured to configure service list information or service level index information for a single user of the terminal.
  • the terminal obtains the service list information or the service level index information from the network, specifically:
  • the terminal receives service list information or service level index information by means of NAS signaling by the network.
  • the NAS signaling includes, but is not limited to, a method of establishing a connection request message, such as a terminal initiated attachment or tracking area update or a routing area update or a PDN connection establishment, when the core network of the network is in an attachment or tracking area update or routing area.
  • the service list information or the service level index information is transmitted to the terminal in a response message such as an update or PDN connection establishment.
  • the terminal can perform service list information or service level index information for a single user of the terminal by receiving the service list information or the service level index information sent by the network through the NAS signaling.
  • the terminal obtains the service list information or the service level index information from the network, specifically:
  • the terminal receives service list information or service level index information that is broadcast by the network through the system.
  • the radio access network determines to start the service-based data connection congestion control when the core network is congested or its own congestion occurs.
  • ACDC Application Specific Congestion control for Data The Connectivity
  • the terminal can configure the same service list information or service level index information for all users of the terminal by receiving the service list information or the service level index information sent by the network in the manner of the system broadcast, but the terminal cannot be configured to the terminal.
  • a single user performs configuration service list information or service level index information.
  • Step 102 After the terminal receives the indication sent by the network, determine, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed, and if yes, initiate the terminal to the network. If the service access request is initiated, if not, the service access request to be initiated by the terminal is prohibited from being initiated to the network.
  • the service list information or the service level index information includes the service permission and/or the forbidden access information.
  • the terminal receives the service to be initiated by the terminal delivered by the network, according to the service list information or service level. Determining whether the service to be initiated by the terminal in the index information is allowed to access, determining whether the service to be initiated by the terminal allows access in the service list information or the service level index information, and if so, initiating the terminal to the network If the service access request is to be initiated, if not, the service access request to be initiated by the terminal is prohibited from being initiated to the network.
  • the indication is used to notify the terminal to perform access control on the service, for example, the indication may be an indication that the ACDC is activated, or an indication that the network is congested.
  • the terminal receives the indication sent by the network, determining, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to be specifically:
  • the non-access stratum of the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed.
  • the indications sent by the network include, but are not limited to, the manner in which the indication is sent.
  • the terminal receives the indication sent by the network, determining, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to be:
  • the access layer of the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed.
  • the access layer of the terminal determines whether the service to be initiated by the terminal is allowed according to the service list information or the service level index information. For details, refer to the descriptions in FIGS. 5, 6, and 7.
  • the terminal receives the network delivery indication, determining, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to be:
  • the terminal After receiving the indication sent by the network, the terminal determines, by the terminal firewall, whether the service to be initiated by the terminal is allowed according to the service list information or the service level index information.
  • the UE firewall determines whether the service is allowed by checking the service list. Referring to step 903 of FIG. 9, the UE firewall allows or denies by opening or closing the port according to whether the service is allowed. Business list.
  • the indication that the terminal receives the network delivery is specifically:
  • the terminal acquires an indication from the network by means of a system broadcast message.
  • the radio access network when the radio access network is congested or the core network is congested, the radio access network is notified; the radio access network sends an ACDC start notification and service list information or service level index information to the firewall server, where the radio access network passes
  • the system broadcast message notifies the non-access stratum or the access layer of the terminal to start the ACDC, the service list information or the service level index information is simultaneously sent to the non-access stratum or access layer of the terminal.
  • the indication that the terminal receives the network delivery is specifically:
  • the terminal acquires an indication from the network by means of dedicated signaling or an application layer.
  • the firewall server when the core network is congested, notifies the firewall server that the core network is congested; or when the radio access network is congested, the radio access network notifies the firewall server that the radio access network is congested.
  • the firewall server After receiving the congestion information of the core network or the radio access network, the firewall server sends an ACDC start notification message to the UE firewall (the terminal firewall), and sends the service list information or the service level index information to the UE firewall.
  • the embodiment of the present invention discloses a method for controlling service access, where the terminal obtains service list information or service level index information through pre-configuration or from the network; when the terminal receives the indication sent by the network, And determining, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed, and if yes, initiating the service to be initiated by the terminal to the network, and if not, prohibiting the terminal from being initiated to the network.
  • FIG. 2 is a flowchart of a method for controlling service access according to Embodiment 2 of the present invention. As shown in FIG. 2, the method includes:
  • Step 201 The terminal acquires service list information or service level index information, where the service list information includes identification information of allowed and/or forbidden services, where the service level index information includes identifiers and level information of allowed and/or prohibited services. ;
  • Step 202 After the terminal receives the indication sent by the network, determine, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access, and if yes, initiate the foregoing to the network. If the service access request is to be initiated by the terminal, if not, the service access request to be initiated by the terminal is prohibited from being initiated to the network;
  • Step 203 When the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed to access, the terminal initiates a connection establishment request message to the network, where the request information carries the service. Whether the identification is allowed, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the terminal when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal initiates a connection establishment request message to the network, where the request information is carried in the request information.
  • the service is allowed to be identified, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to be specifically:
  • the access layer of the terminal When the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed to access, the access layer of the terminal initiates radio resource control RRC connection request information to the network, where the RRC
  • the connection request information carries an identifier of whether the service is allowed, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to access.
  • the access layer of the terminal initiates an RRC connection request message, where the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the LTE connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the terminal when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal initiates request information to the network, where the request information carries the service.
  • the allowed identifier is used to determine, according to the identifier, whether the service to be initiated by the terminal is allowed to be specifically:
  • the non-access stratum of the terminal initiates a NAS message to the network, where the NAS message carries the service. Whether the identification is allowed, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed to access.
  • the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal does not access.
  • the layer sends a NAS message to the network, where the NAS message carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the terminal when the terminal determines that the service is allowed by the non-access stratum or the access layer, the terminal continues to send the RRC connection setup request message to the network to carry the information unit (Information Element, IE), indicating that the RRC connection request is initiated by the allowed service, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • Information Element Information Element
  • FIG. 3 is a flowchart of a method for controlling service access according to Embodiment 3 of the present invention.
  • the method includes:
  • Step 301 The network configures service list information or service level index information to the terminal.
  • the network configuration service list information or service level index information is specifically provided to the terminal:
  • the network configures service list information or configures service level index information to the terminal in the manner of OMA DM.
  • the network passes OMA Configure the service list information or configure the service level index information to the terminal in the DM mode.
  • the OMA DM can be used to configure service list information or service level index information for a single user.
  • the network configuration service list information or service level index information is specifically provided to the terminal:
  • the network configures service list information or configures service level index information to the terminal in the manner of NAS signaling.
  • the core network is The service list information or the service level index information is sent to the terminal in a response message such as an attachment or tracking area update or a routing area update or a PDN connection establishment.
  • the network can configure service list information or service level index information for a single user by means of NAS signaling.
  • the network configuration service list information or service level index information is specifically provided to the terminal:
  • the network configures service list information or configures service level index information to the terminal by means of system broadcast.
  • the radio access network notifies the terminal access layer to start ACDC through the system broadcast message.
  • the system broadcast message carries the ACDC service configuration list configuration to the terminal.
  • the network can perform the same service list information or service level index information for multiple users by means of system broadcast.
  • the network configuration service list information or service level index information is specifically provided to the terminal:
  • the network sends the service list information or the service level index information to the terminal through the firewall server.
  • the network sends the service list information or the service level index information to the terminal through the firewall server.
  • the network sends the service list information or the service level index information to the terminal through the firewall server, and can configure the service list information or the service level index information for the single user.
  • Step 302 The network sends an indication to the terminal, so that the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed to access.
  • the sending, by the network, the indication to the terminal is specifically:
  • the network sends an indication to the terminal by way of system broadcast or dedicated signaling.
  • the network sends an indication to the terminal by means of system broadcast or dedicated signaling.
  • the sending, by the network, the indication to the terminal is specifically:
  • the network sends an indication to the terminal in an application layer manner.
  • the network sends an indication to the terminal in an application layer manner.
  • An embodiment of the present invention discloses a method for controlling service access, where the terminal allocates service list information or service level index information to a terminal through a network, and the network sends an indication to the terminal, so that the terminal is configured according to the terminal.
  • the service list information or the service level index information determines whether the service to be initiated by the terminal is allowed.
  • Service access control in the case of a specific scenario or network congestion, saving network resources to ensure access to services, and enhancing operators' ability to control services and emergencies.
  • FIG. 4 it is a flowchart of a control manner of service access according to Embodiment 4 of the present invention.
  • Step 401 The network configures service list information or service level index information to the terminal.
  • Step 402 The network sends an indication to the terminal, so that the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed.
  • Step 403 The network determines, according to the identifier of the service that is carried in the request information sent by the terminal, whether the service to be initiated by the terminal is allowed.
  • the network determines, according to whether the service is allowed to be carried in the request information sent by the terminal, whether the service to be initiated by the terminal is allowed to be:
  • the radio access network of the network determines whether the service to be initiated by the terminal is allowed according to whether the RRC connection request information initiated by the terminal carries the identifier allowed by the service.
  • the access layer of the terminal initiates an RRC connection request message, where the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the LTE connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the network determines, according to whether the service is allowed to be carried in the request information sent by the terminal, whether the service to be initiated by the terminal is allowed to be:
  • the core network of the network determines whether the service to be initiated by the terminal is allowed according to whether the NAS message initiated by the terminal carries the identifier allowed by the service.
  • the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal does not access.
  • the layer sends a NAS message to the network, where the NAS message carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the terminal when the terminal determines that the service is allowed by the non-access stratum or the access layer, the terminal continues to send the RRC connection setup request message to the network to carry the information unit (Information Element, IE), indicating that the RRC connection request is initiated by the allowed service, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • Information Element Information Element
  • FIG. 6 FIG. 7, FIG. 8, FIG. 9, FIG. 10, FIG. 11, FIG. 12, FIG. 13, and FIG. 14 are service control connections provided by the first, second, third, and fourth embodiments of the present invention. Schematic diagram of the control method entered.
  • FIG. 5 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention. As shown in Figure 5:
  • the DM mode configures the service list to the terminal, and the service list may be in the form of a black or white list, and the list includes a service identifier that allows or prohibits the service;
  • the radio access network determines to start the ACDC when the radio access network learns that the core network is congested or itself is congested.
  • the radio access network broadcasts a message through the system, and notifies the terminal access layer to start ACDC.
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the access layer After receiving the ACDC start message broadcasted by the system, the access layer notifies the non-access stratum of the terminal to start the ACDC.
  • the application layer or the application layer sends a service request to the non-access stratum of the terminal through the operating system, and carries the service-related information, where the service-related information corresponds to the identifier of the service in the service list.
  • Application identification to identify the business;
  • the terminal non-access stratum After obtaining the service identifier carried in the service request sent by the application layer or the operating system, the terminal non-access stratum checks the ACDC service list received in step 501 to see whether the service to be initiated is in the allowed service list.
  • the terminal non-access stratum rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued.
  • the application identifier of the service request may be sent to the non-access stratum of the terminal, and the non-access stratum of the terminal sends the service identifier information to the terminal access layer, where the terminal access layer If the service to be initiated is not allowed in the service list, the terminal non-access layer rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued.
  • the terminal non-access layer rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued.
  • FIG. 6 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention. As shown in Figure 6:
  • the terminal establishes a connection request message by initiating an attach or tracking area update or a routing area update or a PDN connection establishment.
  • the core network sends the service list to the terminal in a response message such as an attachment or tracking area update or a routing area update PDN connection establishment.
  • the service list may be in the form of a black or white list, where the list includes a service identifier that allows or prohibits the service.
  • the radio access network determines to start the ACDC when the radio access network learns that the core network is congested or itself is congested.
  • the radio access network broadcasts a message through the system, and notifies the terminal access layer to start ACDC;
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the access layer After receiving the ACDC start message broadcasted by the system, the access layer notifies the non-access stratum of the terminal to start the ACDC.
  • the application layer or the application layer sends a service request to the non-access stratum of the terminal through the operating system, and carries the service-related information, where the service-related information corresponds to the identifier of the service in the service list.
  • Application identification to identify the business;
  • the terminal non-access stratum After obtaining the service identifier carried in the service request sent by the application layer or the operating system, the terminal non-access stratum checks the ACDC service list received in step 602 to see whether the service to be initiated is in the allowed service list.
  • the terminal non-access stratum rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued.
  • the terminal access layer may also determine whether the service is allowed, that is, in step 606, the ACDC service list is sent by the non-access stratum to the access layer.
  • the service request is sent by the application layer to the non-access stratum, and then sent by the non-access stratum to the access stratum, and the terminal access layer determines whether the service is allowed: if the service to be initiated is not in the allowed service list, Then, the terminal non-access stratum rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued, as shown in FIG. 11 .
  • FIG. 7 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention. As shown in Figure 7:
  • the radio access network determines to start the ACDC when it is informed that the core network is congested or itself is congested.
  • the radio access network broadcasts a message to notify the terminal access layer to start the ACDC, and the system broadcast message carries the ACDC service list to the terminal.
  • the service list may be in the form of a black/white service list, and the list includes permission/prohibition. Business identity of the business.
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the access layer After receiving the ACDC start message broadcasted by the system, the access layer notifies the terminal to the non-access stratum of the ACDC.
  • the application layer or the application layer sends a service request to the non-access stratum of the terminal through the operating system, and carries the service-related information, where the service-related information corresponds to the identifier of the service in the service list, if both are used.
  • Application identification to identify the business;
  • the terminal non-access stratum After obtaining the service identifier carried in the service request sent by the application layer or the operating system, the terminal non-access stratum checks the ACDC service list received in step 701 to see whether the service to be initiated is in the allowed service list.
  • the terminal non-access stratum rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued.
  • the terminal access layer may also determine whether the service is allowed, that is, step 704 is omitted, and after step 705, the terminal non-access stratum sends the service identification information to the terminal access layer, and the terminal accesses. If the service to be initiated is not in the allowed service list, the terminal non-access stratum rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued. Refer specifically to Figure 12 for details.
  • FIG. 8 is a schematic diagram of a control manner of service access according to an embodiment of the present invention. As shown in Figure 8:
  • the radio access network is congested, or the radio access network is notified when the core network is congested;
  • the radio access network sends an ACDC startup notification and a service list to the firewall server.
  • the radio access network notifies the non-access stratum/access layer of the terminal to start the ACDC by using the broadcast message, and sends the ACDC service list to the non-access stratum/access stratum.
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the terminal non-access stratum/access layer notifies the UE that the firewall ACDC is started, and sends the ACDC service list to the UE firewall.
  • the terminal application layer/operating system sends a service request to the UE firewall, where the message carries the service identifier.
  • the UE firewall checks the ACDC service list to confirm whether the service is allowed to be initiated.
  • the UE firewall allows/deny service initiation according to the check result.
  • FIG. 9 is a schematic diagram of a control manner of service access according to an embodiment of the present invention. As shown in Figure 9:
  • the core network When the core network is congested, the core network notifies the firewall server that the core network is congested; or when the radio access network is congested, the radio access network notifies the firewall server that the radio access network is congested;
  • the firewall server After receiving the congestion information of the core network or the radio access network, the firewall server sends an ACDC startup notification message to the UE firewall, and sends the ACDC service list to the UE firewall.
  • the terminal sends a service request to the terminal firewall first, and the terminal firewall checks the ACDC service list to determine whether the service is allowed.
  • the terminal firewall allows or denies the service request by opening or closing the port according to whether the service is allowed, and the terminal side service initiates control.
  • FIG. 10 is a schematic diagram of a control manner of service access according to an embodiment of the present invention. As shown in Figure 10:
  • the DM (Device Management) configures the service list to the terminal, and the service list may be in the form of a black/white list, and the list includes a service flag for allowing/disabling the service;
  • 1002 Send, by the non-access stratum, the ACDC service list to the access layer.
  • the radio access network determines to start the ACDC when the radio access network is informed that the core network is congested or its own congestion occurs.
  • the radio access network broadcasts a message through the system, and notifies the terminal access layer to start ACDC;
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the application layer or the application layer sends a service request to the non-access stratum of the terminal through the operating system, and carries the service-related information, where the service-related information corresponds to the service identifier in the service list, if both are used.
  • Application identification to identify the business;
  • the terminal access layer After receiving the service identifier carried in the service request sent by the application layer or the operating system, the terminal access layer checks the ACDC service list received in step 1001 to see whether the service to be initiated is in the allowed service list.
  • FIG. 11 is a schematic diagram of a control manner of service access according to an embodiment of the present invention. As shown in Figure 11:
  • the terminal establishes a connection request message by initiating an attach or tracking area update or a routing area update or a PDN connection establishment.
  • the core network sends the service list to the terminal in a response message such as an attachment or tracking area update or a routing area update PDN connection establishment, and the service list may be in the form of a black or white list, and the list includes a service identifier that allows or prohibits the service;
  • the radio access network determines to start the ACDC when the radio access network learns that the core network is congested or itself is congested.
  • the radio access network broadcasts a message through the system, and notifies the terminal access layer to start ACDC;
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the non-access stratum sends the ACDC service list to the access layer.
  • the service request is sent by the application layer to the non-access stratum, and then sent by the non-access stratum to the access layer, and the terminal access layer determines whether the service is allowed: if the service to be initiated is not in the allowed service list, The terminal non-access stratum rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued;
  • the terminal access layer After obtaining the service identifier carried in the service request sent by the application layer or the operating system, the terminal access layer checks the ACDC service list received in step 1102 to see whether the service to be initiated is in the allowed service list.
  • the terminal non-access stratum rejects the service request; if the service to be initiated is in the allowed service list, the subsequent service initiation process is continued.
  • FIG. 12 is a schematic diagram of a control manner of service access according to an embodiment of the present invention. As shown in Figure 12:
  • the radio access network determines to start the ACDC when it is informed that the core network is congested or itself is congested;
  • the radio access network broadcasts a message to notify the terminal access layer to start the ACDC, and the system broadcast message carries the ACDC service list and is configured to the terminal.
  • the service list may be in the form of a black/white service list, and the list includes the permission/prohibition. Business identity of the business.
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the application layer initiates a service
  • the application layer or the application layer sends a service request to the access layer of the terminal through the operating system, and carries the service-related information, where the service-related information corresponds to the service identifier in the service list, and the application is adopted. Identification to identify the business;
  • the terminal access layer After obtaining the service identifier carried in the service request sent by the application layer or the operating system, the terminal access layer checks the ACDC service list received in step 1201 to see whether the service to be initiated is in the allowed service list.
  • FIG. 13 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention. The method includes the following steps:
  • the terminal configures an ACDC service list, and the configuration manner includes: terminal pre-configuration, or through OMA
  • the DM mode obtains the ACDC service list by broadcasting the system message to the terminal or by attaching/tracking area update/routing area update/PDN connection establishment.
  • This embodiment does not limit the manner in which the terminal ACDC service list is configured.
  • the service list may be in the form of a black/white list, and the list includes service identifiers for allowing/disabling the service;
  • the radio access network determines to start the ACDC when the radio access network learns that the core network is congested or itself is congested.
  • the radio access network broadcasts a message through the system, and notifies the terminal access layer to start ACDC.
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the access layer After receiving the ACDC start message broadcasted by the system, the access layer notifies the non-access stratum of the terminal to start the ACDC.
  • the application layer or the application layer sends a service request to the non-access stratum of the terminal through the operating system, and carries the service-related information, where the service-related information corresponds to the service identifier in the service list.
  • Application identification to identify the business;
  • the terminal access layer After obtaining the service identifier carried in the service request sent by the application layer or the operating system, the terminal access layer checks the ACDC service list of the terminal in step 1301 to see whether the service to be initiated is in the allowed service list.
  • the access layer carries the IE information, such as “MO-ACDC permitted”, in the initiated RRC connection establishment connection request message.
  • the network element for example, the radio access network, when receiving the RRC connection setup request message, check whether the RRC connection establishment request message carries the IE information described in step 1308, such as “MO-ACDC”. Permitted.”
  • the network element such as the radio access network according to the RRC connection establishment request message carries the IE information described in step 1308 to determine whether to accept or reject the RRC connection establishment connection request message, if the RRC connection establishes a connection request message
  • the RRC connection setup connection request message that does not contain this IE value is prohibited, and the mechanism to be initiated is controlled by this mechanism.
  • FIG. 14 is a schematic diagram of a method for controlling service access according to an embodiment of the present invention. The method is as follows:
  • the terminal configures an ACDC service list, and the configuration manner includes: terminal pre-configuration, or through OMA
  • the DM mode obtains the ACDC service list by broadcasting the system message to the terminal or by attaching/tracking area update/routing area update/PDN connection establishment.
  • This embodiment does not limit the manner in which the terminal ACDC service list is configured.
  • the service list may be in the form of a black/white list, and the list includes service identifiers for allowing/disabling the service;
  • the radio access network determines to start the ACDC when the radio access network learns that the core network is congested or itself is congested.
  • the radio access network broadcasts a message through the system, and notifies the terminal access layer to start ACDC.
  • the notification message of the ACDC may also be sent through dedicated signaling, and is not limited to the notification manner of the broadcast message;
  • the access layer After receiving the ACDC start message broadcasted by the system, the access layer notifies the non-access stratum of the terminal to start the ACDC.
  • the application layer or the application layer When the application layer initiates the service, the application layer or the application layer sends a service request to the non-access stratum of the terminal through the operating system, and carries the service-related information, where the service-related information corresponds to the service identifier in the service list, if both are used.
  • Application identification to identify the business;
  • the terminal non-access stratum After obtaining the service identifier carried in the service request sent by the application layer or the operating system, the terminal non-access stratum checks the ACDC service list of the terminal in step 1401 to see whether the service to be initiated is in the allowed service list.
  • the non-access stratum is in the initiated NAS connection request message, such as service request or PDN connectivity.
  • Reqeust message carrying IE information, such as "ACDC service permitted”.
  • the network element such as the MME or the SGSN, checks whether the IMS information in step 1408 is carried in the NAS connection establishment request message, such as “ACDC”. Service permitted”.
  • the network element determines whether to accept or reject the NAS request according to whether the NAS message carries the IE information described in step 1408. If the NAS message does not include the NAS message of the IE value in the connection request message in the NAS message. It is forbidden to control the business to be initiated through this mechanism.
  • FIG. 15 is a structural diagram of a terminal device according to Embodiment 5 of the present invention.
  • the device includes:
  • the obtaining unit 1501 is configured to perform the step 101 in the first embodiment of the present invention
  • the access control unit 1502 is configured to perform the step 102 in the first embodiment
  • the identifying unit 1503 is configured to perform the steps in FIG. 2 in the second embodiment. 203.
  • each unit included in the terminal device in the fifth embodiment of the present invention is only divided according to functional logic, but is not limited to the foregoing division, as long as the corresponding function can be implemented;
  • the specific names of the respective functional units are only for the purpose of facilitating mutual differentiation, and are not intended to limit the scope of protection of the present application.
  • the obtaining unit 1501 is configured to acquire, by the terminal, the service list information or the service level index information, where the service list information includes the identification information of the allowed and/or forbidden service, where the service level index information includes the identifier of the allowed and/or prohibited service. And the level information; the obtaining unit sends the obtained service list information or service level index information to the access control unit;
  • the terminal can obtain service list information or service level index information in a pre-configured manner.
  • the pre-mode may store the service list information or the service level index information on the mobile phone SIM card in advance.
  • the service list information may be in the form of a black or white list, and the list includes a service identifier that allows or prohibits the service.
  • the service level index information includes a service identifier that allows or prohibits the service, and includes the level index information of the service importance.
  • the service is divided according to the priority of the service, and the index information is established according to the division, so that the terminal can perform a certain service. To allow or prohibit the operation, it is also possible to allow or prohibit the operation of different levels of business.
  • the terminal obtains the service list information or the service level index information from the network, including but not limited to the OMA through the receiving network.
  • the obtaining unit 1501 is specifically configured to:
  • the terminal receives service list information or service level index information in a manner that the network passes through the OMA DM.
  • the network passes OMA
  • the DM mode configures service list information or service level index information to the terminal. Referring specifically to step 501 of FIG. 5, the network passes OMA.
  • the DM mode configures service list information or service level index information to the terminal.
  • the terminal passes the OMA by receiving the network
  • the service list information or the service level index information sent by the DM can be configured to configure service list information or service level index information for a single user of the terminal.
  • the obtaining unit is specifically configured to:
  • the terminal receives service list information or service level index information by means of NAS signaling by the network.
  • the core network of the network responds to an attachment or tracking area update or a routing area update or a PDN connection establishment.
  • the middle office sends the service list information or the service level index information to the terminal.
  • the terminal can perform service list information or service level index information for a single user of the terminal by receiving the service list information or the service level index information sent by the network through the NAS signaling.
  • the obtaining unit 1501 is specifically configured to:
  • the terminal receives service list information or service level index information that is broadcast by the network through the system.
  • the radio access network determines the indication when the core network is congested or itself is congested; the radio access network passes the system.
  • the broadcast message informs the terminal to start the ACDC, and the system broadcast message carries the ACDC service list information and is configured to the terminal.
  • the terminal can configure the same service list information or service level index information for all users of the terminal by receiving the service list information or the service level index information sent by the network in the manner of the system broadcast, but the terminal cannot be configured to the terminal.
  • a single user performs configuration service list information or service level index information.
  • the access control unit 1502 is configured to: after the terminal receives the indication sent by the network, determine, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed, and if yes, The network initiates the service to be initiated by the terminal, and if not, the service initiated by the terminal is prohibited from being initiated to the network.
  • the access control unit 1502 is specifically configured to:
  • the non-access stratum of the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed.
  • the access control unit 1502 is specifically configured to:
  • the access layer of the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed.
  • the access layer of the terminal determines whether the service to be initiated by the terminal is allowed according to the service list information or the service level index information. For details, refer to the descriptions in FIGS. 5, 6, and 7.
  • the access control unit 1502 is specifically configured to:
  • the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed by the terminal firewall.
  • the UE firewall checks whether the service is allowed by checking the service list. Referring to step 903 of FIG. 9, the UE firewall allows or denies by opening or closing the port according to whether the service is allowed. Business list.
  • the access control unit 1502 is specifically configured to:
  • the terminal acquires an indication from the network by means of a system broadcast message.
  • the radio access network when the radio access network is congested or the core network is congested, the radio access network is notified; the radio access network sends an ACDC initiation notification and service list information or service level index information to the firewall server, and the radio access network passes the
  • the system broadcast message notifies the non-access stratum or the access layer of the terminal to start the ACDC, the service list information or the service level index information is simultaneously sent to the non-access stratum or access layer of the terminal.
  • the access control unit 1502 is specifically configured to:
  • the terminal acquires an indication from the network by means of dedicated signaling or an application layer.
  • the core network when the core network is congested, notifies the firewall server that the core network is congested; or when the radio access network is congested, the radio access network notifies the firewall server that the radio access network is congested.
  • the firewall server After receiving the congestion information of the core network or the radio access network, the firewall server sends an ACDC start notification message to the UE firewall (the terminal firewall), and sends the service list information or the service level index information to the UE firewall.
  • the device further includes:
  • the identifier unit 1503 is configured to: when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the terminal initiates request information to the network, where the request information carries the service
  • the allowed identifier is such that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the identifier unit 1503 is specifically configured to:
  • the access layer of the terminal When the terminal determines, according to the service list information or the service level index information, the service permission to be initiated by the terminal, the access layer of the terminal initiates an RRC connection request message to the network, where the RRC connection request information is carried. Whether the service is allowed to be identified, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the access layer of the terminal when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the access layer of the terminal The network initiates an RRC connection request message, where the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the LTE connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the identifier unit 1503 is specifically configured to:
  • the non-access stratum of the terminal initiates a NAS message to the network, where the NAS message carries the service permission.
  • the identifier is such that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the non-access of the terminal is The layer sends a NAS message to the network, where the NAS message carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the NAS message carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the embodiment of the present invention discloses a device for controlling a service, where the device includes an obtaining unit 1501, and an access control unit 1502.
  • the terminal uses the obtaining unit 1501 to pre-configure or obtain service list information or service level index information from a network.
  • the access control unit 1502 is configured to determine, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed, and if yes, to the network, after the terminal receives the indication sent by the network.
  • the service to be initiated by the terminal is initiated, and if not, the service to be initiated by the terminal is prohibited from being initiated to the network.
  • Service access control in the case of a specific scenario or network congestion, saving network resources to ensure access to services, and enhancing operators' ability to control services and emergencies.
  • FIG. 16 is a structural diagram of a network element device according to Embodiment 6 of the present invention.
  • the device includes:
  • the configuration unit 1601 is configured to perform step 301 in FIG. 3 of the third embodiment
  • the sending unit 1602 is configured to perform step 302 in the third embodiment of FIG. 3
  • the processing unit 1603 is configured to perform step 403 in FIG. 4 in the fourth embodiment. .
  • each unit included in the terminal device in the fifth embodiment of the present invention is only divided according to functional logic, but is not limited to the foregoing division, as long as the corresponding function can be implemented;
  • the specific names of the respective functional units are only for the purpose of facilitating mutual differentiation, and are not intended to limit the scope of protection of the present application.
  • the configuration unit 1601 is configured to configure, by the network, service list information or service level index information to the terminal;
  • the configuration unit 1601 is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal in the manner of OMA DM.
  • the network passes OMA Configure the service list information or configure the service level index information to the terminal in the DM mode.
  • the OMA DM can be used to configure service list information or service level index information for a single user.
  • the configuration unit 1601 is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal in the manner of NAS signaling.
  • step 601 and step 602 shown in FIG. 6 or FIG. 11, or steps 1101 and 1102 when the terminal establishes a connection request message by initiating an attach or tracking area update or routing area update or PDN connection establishment, etc.
  • the core network sends the service list information or the service level index information to the terminal in a response message such as an attachment or tracking area update or a routing area update or a PDN connection establishment.
  • the network can configure service list information or service level index information for a single user by means of NAS signaling.
  • the configuration unit 1601 is specifically configured to:
  • the network configures service list information or configures service level index information to the terminal by means of system broadcast.
  • the radio access network notifies the terminal access layer to start ACDC through the system broadcast message.
  • the system broadcast message carries the ACDC service configuration list configuration to the terminal.
  • the network can perform the same service list information or service level index information for multiple users by means of system broadcast.
  • the configuration unit 1601 is specifically configured to:
  • the network sends the service list information or the service level index information to the terminal through the firewall server.
  • the network sends the service list information or the service level index information to the terminal through the firewall server.
  • the network sends the service list information or the service level index information to the terminal through the firewall server, and can configure the service list information or the service level index information for the single user.
  • the sending unit 1602 is configured to: send, by the network, an indication to the terminal, so that the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed.
  • the sending unit 1602 is specifically configured to:
  • the network sends an indication to the terminal by way of system broadcast or dedicated signaling.
  • the network sends an indication to the terminal by means of system broadcast or dedicated signaling.
  • the sending unit 1602 is specifically configured to:
  • the network sends an indication to the terminal in an application layer manner.
  • the network sends an indication to the terminal in an application layer manner.
  • the device further includes:
  • the processing unit 1603 is configured to determine, by the network, whether the service to be initiated by the terminal is allowed according to whether the service is allowed to be carried in the request information sent by the terminal.
  • the processing unit 1603 is specifically configured to:
  • the radio access network of the network determines whether the service to be initiated by the terminal is allowed according to whether the RRC connection request information initiated by the terminal carries the identifier allowed by the service.
  • the access layer of the terminal when the terminal determines, according to the service list information or the service level index information, that the service to be initiated by the terminal is allowed, the access layer of the terminal The network initiates an RRC connection request message, where the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection request information carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the LTE connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the processing unit 1603 is specifically configured to:
  • the core network of the network determines whether the service to be initiated by the terminal is allowed according to whether the NAS message initiated by the terminal carries the identifier allowed by the service.
  • the non-access of the terminal is The layer sends a NAS message to the network, where the NAS message carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the NAS message carries an identifier that is allowed by the service, so that the network determines, according to the identifier, whether the service to be initiated by the terminal is allowed.
  • the RRC connection establishment request message is sent to the network to carry the IE value, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • the terminal when the terminal determines that the service is allowed by the non-access stratum or the access layer, the terminal continues to send the RRC connection setup request message to the network to carry the information unit (Information Element, IE), indicating that the RRC connection request is initiated by the allowed service, so that the network continues to determine whether the service is allowed according to the IE value. Therefore, it is possible to further detect the service and prevent the terminal from performing a correct judgment through the network when the terminal operation detection fails.
  • Information Element Information Element
  • FIG. 17 is a terminal device 1700 according to an embodiment of the present invention.
  • the terminal device may be a mobile phone or the like.
  • the specific embodiment of the present invention does not limit the specific implementation of the terminal device.
  • the device 1700 includes:
  • Processor 1701 communication interface (Communications) Interface 1702, memory 1703, bus 1704.
  • the processor 1701, the communication interface 1702, and the memory 1703 complete communication with each other via the bus 1704.
  • a communication interface 1702 configured to communicate with a network element
  • the processor 1701 is configured to execute the program 1705.
  • program 1705 can include program code, the program code including computer operating instructions.
  • the processor 1701 may be a central processing unit CPU or a specific integrated circuit ASIC (Application) Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.
  • ASIC Application Specific Integrated Circuit
  • the memory 1703 is configured to store the program 1705.
  • the memory 1703 may include a high speed RAM memory and may also include a non-volatile memory (non-volatile memory) Memory), such as at least one disk storage.
  • the program 1705 may specifically include:
  • the obtaining unit 1501 is configured to obtain, by the pre-configuration, the service list information or the service level index information, where the service list information or the service level index information includes the identification information of the allowed and/or prohibited services;
  • the access control unit 1502 is configured to: after the terminal receives the indication sent by the network, determine, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed, and if yes, to the network The service to be initiated by the terminal is initiated, and if not, the service to be initiated by the terminal is prohibited from being initiated to the network.
  • each unit in the program 1705 refers to the corresponding unit in the embodiment shown in FIG. 15, and details are not described herein.
  • FIG. 18 is a network element device 1800 according to an embodiment of the present invention.
  • the specific embodiment of the present invention does not limit the specific implementation of the terminal device.
  • the device 1800 includes:
  • Processor 1801 communication interface (Communications) Interface 1802, memory 1803, bus 1804.
  • the processor 1801, the communication interface 1802, and the memory 1803 complete communication with each other via the bus 1804.
  • a communication interface 1802 configured to communicate with a network element
  • the processor 1801 is configured to execute the program 1805.
  • program 1805 can include program code, the program code including computer operating instructions.
  • the processor 1801 may be a central processing unit CPU or a specific integrated circuit ASIC (Application) Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.
  • ASIC Application Specific Integrated Circuit
  • the memory 1803 is configured to store the program 1805.
  • the memory 1803 may include a high speed RAM memory and may also include a non-volatile memory (non-volatile memory) Memory), such as at least one disk storage.
  • the program 1805 may specifically include:
  • the configuration unit 1601 is configured to configure, by the network, service list information or service level index information to the terminal;
  • the sending unit 1602 is configured to: send, by the network, an indication sent by the network to the terminal, so that the terminal determines, according to the service list information or the service level index information, whether the service to be initiated by the terminal is allowed.
  • each unit in the program 1805 refers to the corresponding unit in the embodiment shown in FIG. 16, and details are not described herein.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种业务接入的控制方法,所述方法通过终端通过预配置,或从网络中获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。从而实现可在特定场景或在网络拥塞的情况下,节省网络资源,保障允许业务的接入,加强运营商对业务的控制及突发事件的处理能力。

Description

业务接入的控制方法及设备 技术领域
本发明属于通信领域,尤其涉及业务接入的控制方法及设备。
背景技术
近年来,移动互联网应用发展迅速,手机终端可以轻松下载安装各种应用程序。但是在网络拥塞的情况下,这些应用将加重无线接入网(Radio AccessNetwork, RAN)或核心网(Core Network, CN)侧的拥塞。当网络发生拥塞时,应禁止某些应用接入网络以节省网络资源。另外,一些应用也会导致问题,如某些应用会在用户没有许可的情况下泄漏用户的个人信息或违背当地法律。因此,应提供一种机制让网络可以禁止某些应用接入网络。而另一方面,在特殊情况下某些应用非常重要,比如当自然灾害发生时,灾害信息公告栏服务或灾害语音信息服务等可以让人们确认亲属的安全。因此运营商希望有一种控制接入机制,即网络在发生拥塞的情况下仍能为上述重要服务提供接入,而同时又能禁止其他业务来保证重要业务的使用。
第三代合作伙伴计划(The 3rd Generation Partnership Project,3GPP)已提出了一些接入控制的机制,如接入级别禁止(Access Class Barring,ACB) ,域接入控制(Domain Specific Access Control,DSAC),业务接入控制(Service Specific Access Control,SSAC)和扩展的接入控制(Extended Access Barring,EAB)等。ACB和EAB在网络拥塞情况下限制终端上所有业务的用户终端发起(Mobile origination,MO )请求,DSAC机制只是控制终端可以发起电路交换(Circuit Switched,CS)域业务或者分组交换(Packet Switched)域业务,SSAC也只是控制发起语音或视频电话等业务。
目前尚未有一种机制能够实现对特定业务的允许或限制控制,因此需要提供一种机制在接入控制实施的情况下仍允许特定业务接入网络。基于上述需求,3GPP标准组织也提出了基于业务的数据连接和拥塞控制(Application specific Congestion control for Data Connectivity,ACDC)研究项目,对上述应用场景和需求进行讨论,但目前还未提出相应的解决方案。
技术问题
本发明实施例提供了业务接入的控制方法,实现对特定业务接入网络的控制。在网络拥塞或灾害发生等情况下,网络通知终端ACDC启动,由终端进行业务的控制,或由网络对终端接入消息进行控制,保证在接入控制实施的情况下仍允许特定业务接入网络,而禁止其他业务接入网络。这样可以在特定场景或在网络拥塞的情况下,节省网络资源,保障允许业务的接入,加强运营商对业务的控制及突发事件的处理能力。
技术解决方案
第一方面,一种业务接入的控制方法,其特征在于,所述方法包括:
终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;
当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。
第一方面的第一种可能的实现方式中,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
所述终端接收由所述网络通过OMA DM的方式业务列表信息或业务等级索引信息。
第一方面的第二种可能的实现方式中,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
所述终端接收由所述网络通过NAS信令的方式业务列表信息或业务等级索引信息。
第一方面的第三种可能的实现方式中,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
,所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
结合第一方面或第一方面的第一种可能的实现方式或结合第一方面的第二种可能的实现方式或结合第一方面的第三种可能的实现方式,第一方面的第四种可能的实现方式,所述当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许具体为:
所述终端接收所述网络下发的指示后,所述终端的非接入层或接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
结合第一方面或第一方面的第一种可能的实现方式或结合第一方面的第二种可能的实现方式或结合第一方面的第三种可能的实现方式或第一方面的第四种可能的实现方式,第一方面的第五种可能的实现方式,所述方法还包括:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端向所述网络发起建立连接请求消息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
结合第一方面的第五种可能的实现方式,所述当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端向所述网络发起请求信息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许具体为:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的接入层向所述网络发起RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入;
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
第一方面的第六种可能的实现方式,所述终端接收所述网络下发的指示具体为:
所述终端通过***广播消息的方式或专用信令的方式或应用层的方式从网络获取指示。
结合第一方面的第六种可能的实现方式,所述当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许具体为:
所述终端接收所述网络下发的指示后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
第二方面,一种业务接入的控制方法,所述方法包括:
网络将业务列表信息或业务等级索引信息配置到终端;
所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
第二方面的第一种可能的实现方式,所述网络配置业务列表信息或业务等级索引信息给终端具体为:
所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
第二方面的第二种可能的实现方式,所述网络配置业务列表信息或业务等级索引信息给终端具体为:
所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
第二方面的第三种可能的实现方式,所述网络配置业务列表信息或业务等级索引信息给终端具体为:
所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
结合第二方面或第二方面的第一种可能的实现方式或结合第二方面的第二种可能的实现方式或结合第二方面的第三种可能的实现方式,第二方面的第四种可能的实现方式,所述网络向所述终端下发指示具体为:
所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
结合第二方面的第四种可能的实现方式,第二方面的第五种可能的实现方式,所述方法还包括:
所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;
所述网络根据所述标识,判断终端要发起的业务是否允许接入。
结合第二方面的第五种可能的实现方式,第二方面的第六种可能的实现方式,所述网络根据所述终端发送的请求信息中是否携带的业务允许的标识,判断终端要发起的业务是否允许具体为:
所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
结合第二方面的第五种可能的实现方式,第二方面的第七种可能的实现方式,所述网络根据所述终端发送的请求信息中是否携带的业务允许的标识,判断终端要发起的业务是否允许具体为:
所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
第二方面的第八种可能的实现方式,所述网络将业务列表信息或业务等级索引信息配置到终端具体为:
所述网络通过防火墙服务器将业务列表信息或业务等级索引信息配置到终端。
结合第二方面的第八种可能的实现方式,所述网络向所述终端下发的指示具体为:
所述网络通过***广播的方式或者专用信令的方式或应用层的方式向所述终端下发指示。
第三方面,一种终端设备,所述设备包括:
获取单元,用于终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;所述获取单元将获取的业务列表信息或业务等级索引信息发送给接入控制单元;
所述接入控制单元,用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。
第三方面的第一种可能的实现方式,所述获取单元具体用于:
所述终端接收由所述网络通过OMA DM的方式业务列表信息或业务等级索引信息。
第三方面的第二种可能的实现方式,所述获取单元具体用于:
所述终端接收由所述网络通过NAS信令的方式业务列表信息或业务等级索引信息。
第三方面的第三种可能的实现方式,所述获取单元具体用于:
,所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
结合第三方面或第三方面的第一种可能的实现方式或第三方面的第二种可能的实现方式或第三方面的第三种可能的实现方式,第三方面的第四种可能的实现方式,所述接入控制单元具体用于:
所述终端接收所述网络下发的指示后,所述终端的非接入层或接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
结合第三方面或第三方面的第一种可能的实现方式或第三方面的第二种可能的实现方式或第三方面的第三种可能的实现方式或第三方面的第四种可能的实现方式,第三方面的第五种可能的实现方式,所述设备还包括:
标识单元,用于当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端向所述网络发起请求信息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
结合第三方面的第五种可能的实现方式,所述标识单元具体用于:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的接入层向所述网络发起无线资源控制RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入;
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
第三方面的第六种可能的实现方式,所述接入控制单元具体用于:
所述终端通过***广播消息的方式或专用信令的方式或应用层的方式从网络获取指示。
结合第三方面的第六种可能的实现方式,所述接入控制单元具体用于:
所述终端接收所述网络下发的指示后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
第四方面,一种网元设备,所述设备包括:
配置单元,用于网络将业务列表信息或业务等级索引信息配置到终端;
下发单元,用于所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
第四方面的第一种可能的实现方式,所述配置单元具体用于:
所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
第四方面的第二种可能的实现方式,所述配置单元具体用于:
所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
第四方面的第三种可能的实现方式,所述配置单元具体用于:
所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
结合第四方面或第四方面的第一种可能的实现方式或第四方面的第二种可能的实现方式或第四方面的第三种可能的实现方式,第四方面的第四种可能的实现方式,所述下发单元具体用于:
所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
结合第四方面的第四种可能的实现方式,第四方面的第五种可能的实现方式,所述设备还包括:
处理单元,用于所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;
所述网络根据所述标识,判断终端要发起的业务是否允许接入。
结合第四方面的第五种可能的实现方式,所述处理单元具体用于:
所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
结合第四方面的第五种可能的实现方式,所述处理单元具体用于:
所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
第四方面的第六种可能的实现方式,所述配置单元具体用于:
所述网络通过防火墙服务器将业务列表信息或业务等级索引信息下发给终端。
结合第四方面的第六种可能的实现方式,所述下发单元具体用于:
所述网络通过***广播的方式或者专用信令的方式或应用层的方式向所述终端下发指示。
第五方面,一种终端设备,所述设备包括:
获取单元,用于终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;所述获取单元将获取的业务列表信息或业务等级索引信息发送给接入控制单元;
所述接入控制单元,用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。
第五方面的第一种可能的实现方式,所述设备包括处理器,通信接口,存储器和总线;
其中处理器、通信接口、存储器通过总线完成相互间的通信;
所述通信接口,用于与网元设备进行通信;
所述处理器,用于执行程序;
所述存储器,用于存放程序;
其中程序用于终端通过预配置,或从网络中获取业务列表信息或业务等级索引信息,所述业务列表信息或业务等级索引信息包含允许和/或禁止的业务的标识信息;用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。
结合第五方面的第一种可能的实现方式,第五方面的第二种可能的实现方式,所述获取单元具体用于:
所述终端接收由所述网络通过OMA DM的方式业务列表信息或业务等级索引信息。
结合第五方面的第一种可能的实现方式,第五方面的第三种可能的实现方式,所述获取单元具体用于:
所述终端接收由所述网络通过NAS信令的方式业务列表信息或业务等级索引信息。
结合第五方面的第一种可能的实现方式,第五方面的第四种可能的实现方式,所述获取单元具体用于:
所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
结合第五方面的第一种可能的实现方式或第五方面的第二种可能的实现方式或第五方面的第三种可能的实现方式或第五方面的第四种可能的实现方式,第五方面的第五种可能的实现方式,所述接入控制单元具体用于:
所述终端接收所述网络下发的指示后,所述终端的非接入层或接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
结合第五方面的第一种可能的实现方式或第五方面的第二种可能的实现方式或第五方面的第三种可能的实现方式或第五方面的第四种可能的实现方式或第五方面的第五种可能的实现方式,第五方面的第六种可能的实现方式,所述设备还包括:
标识单元,用于当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端向所述网络发起请求信息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
结合第五方面的第六种可能的实现方式,所述标识单元具体用于:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的接入层向所述网络发起无线资源控制RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入;
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
结合第五方面的第一种可能的实现方式,第五方面的第七种可能的实现方式,所述接入控制单元具体用于:
所述终端通过***广播消息的方式或专用信令的方式或应用层的方式从网络获取指示。
结合第五方面的第七种可能的实现方式,第五方面的第八种可能的实现方式,所述接入控制单元具体用于:
所述终端接收所述网络下发的指示后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
第六方面,一种网元设备,所述网元设备包括:
配置单元,用于网络将业务列表信息或业务等级索引信息配置到终端;
下发单元,用于,所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
第六方面的第一种可能的实现方式,所述网元设备包括处理器,通信接口,存储器和总线:
其中处理器、通信接口、存储器通过总线完成相互间的通信;
所述通信接口,用于与终端设备进行通信;
所述处理器,用于执行程序;
所述存储器,用于存放程序;
其中程序用于网络将业务列表信息或业务等级索引信息配置到终端;,所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
结合第六方面的第一种可能的实现方式,第六方面的第二种可能的实现方式,所述配置单元具体用于:
所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
结合第六方面的第一种可能的实现方式,第六方面的第三种可能的实现方式,所述配置单元具体用于:
所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
结合第六方面的第一种可能的实现方式,第六方面的第四种可能的实现方式,所述配置单元具体用于:
,所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
结合第六方面的第一种可能的实现方法或第六方面的第二种可能的实现方法或第六方面的第三种可能的实现方法或者第六方面的第四种可能的实现方法,第六方面的第五种可能的实现方法,所述下发单元具体用于:
所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
结合第六方面的第五种可能的实现方式,第六方面的第六种可能的实现方式,所述设备还包括:
处理单元,用于所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;
所述网络根据所述标识,判断终端要发起的业务是否允许接入。
结合第六方面的第六种可能的实现方式,所述处理单元具体用于:
所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
结合第六方面的第六种可能的实现方式,所述处理单元具体用于:
所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
结合第六方面的第一种可能的实现方式,第六方面的第七种可能的实现方式,所述配置单元具体用于:
所述网络通过防火墙服务器将业务列表信息或业务等级索引信息下发给终端。
结合第六方面的第七种可能的实现方式,所述下发单元具体用于:
所述网络通过***广播的方式或者专用信令的方式或应用层的方式向所述终端下发指示。
有益效果
本发明公开了一种业务接入的控制方法,所述方法通过终端从网络中获取业务列表信息或业务等级索引信息;当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许,若是,则向所述网络发起所述终端要发起的业务,若否,则禁止向所述网络发起所述终端要发起的业务;所述网络也可对所述终端要发起的业务接入消息进行验证,实现网络对所述终端要发起的业务进行控制。通过上述终端或网络的控制,实现特定场景或网络拥塞情况下的业务接入控制,节省网络资源以保障允许业务的接入,加强运营商对业务的控制及突发事件的处理能力。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1是本发明实施例一提供的一种业务接入的控制方法流程图;
图2是本发明实施例二提供的一种业务接入的控制方法流程图;
图3是本发明实施例三提供的一种业务接入的控制方法流程图;
图4是本发明实施例四提供的一种业务接入的控制方法流程图;
图5是本发明实施例提供的一种业务接入的控制方法示意图;
图6是本发明实施例提供的一种业务接入的控制方法示意图;
图7是本发明实施例提供的一种业务接入的控制方法示意图;
图8是本发明实施例提供的一种业务接入的控制方法示意图;
图9是本发明实施例提供的一种业务接入的控制方法示意图;
图10是本发明实施例提供的一种业务接入的控制方法示意图;
图11是本发明实施例提供的一种业务接入的控制方法示意图;
图12是本发明实施例提供的一种业务接入的控制方法示意图;
图13是本发明实施例提供的一种业务接入的控制方法示意图;
图14是本发明实施例提供的一种业务接入的控制方法示意图;
图15是本发明实施例五提供的一种终端设备的设备结构图;
图16是本发明实施例六提供的一种网元设备的设备结构图;
图17是本发明实施例七提供的一种终端设备的设备结构图;
图18是本发明实施例八提供的一种网元设备的设备结构图。
本发明的实施方式
为了使本发明的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本发明进行进一步详细说明。应当理解,此处所描述的具体实施例仅仅用以解释本发明,并不用于限定本发明。
以上所述仅为本发明的较佳实施例而已,并不用以限制本发明,凡在本发明的精神和原则之内所作的任何修改、等同替换和改进等,均应包含在本发明的保护范围之内。
实施例一
参考图1,图1是本发明实施例一提供的一种业务接入的控制的方法流程图。如图1所示,该方法包括以下步骤:
步骤101,终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;
本步骤中,终端可以通过预配置的方式获取业务列表信息或业务等级索引信息。所述预配置的方式可以预先将所述业务列表信息或业务等级索引信息储存在手机SIM卡上,所述业务列表信息可以是黑或白列表的形式,列表中包括允许或禁止业务的业务标识。所述业务等级索引信息包括允许或禁止业务的业务标识外,还包括业务类型的等级索引信息,将业务按业务的类型进行划分,并根据划分建立索引信息,使得终端可以对预设的类型业务进行允许或禁止操作,也可以对不同等级的业务进行允许或禁止操作。
本步骤中,根据所述业务列表信息,当所述终端要发起的业务在所述业务列表信息中是允许的,则判断所述终端要发起的业务是允许接入的;
或根据所述业务等级索引信息,当所述终端要发起的业务在所述业务等级索引信息中是属于允许的等级,则判断所述终端要发起的业务是允许接入的。
其中,终端从网络中获取业务列表信息或业务等级索引信息的方式包括但不限于如下方式:通过接收网络通过开放式移动联盟设备管理(Open Mobile Alliance Device Management,OMA DM)的方式业务列表信息或业务等级索引信息,或接收网络通过非接入层(Non-Access Stratum,NAS)信令的方式业务列表信息或业务等级索引信息,或接收网络通过***广播的方式下发的业务列表信息或业务等级索引信息,或,所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
可优选的,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
所述终端接收由所述网络通过OMA DM的方式业务列表信息或业务等级索引信息。
本步骤中,网络通过OMA DM的方式将业务列表信息或业务等级索引信息配置到所述终端。具体参考图5的步骤501,网络通过OMA DM的方式将业务列表信息或业务等级索引信息配置到终端。
其中,所述终端通过接收所述网络通过OMA DM的方式下发的业务列表信息或业务等级索引信息使得可以对终端的单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
所述终端接收由所述网络通过NAS信令的方式业务列表信息或业务等级索引信息。
本步骤中,NAS信令包括但不限于终端发起附着或跟踪区更新或路由区更新或PDN连接建立等建立连接请求消息的方式,当所述网络的核心网在附着或跟踪区更新或路由区更新或PDN连接建立等响应消息中将业务列表信息或业务等级索引信息发送到所述终端。具体参考图6的步骤601和602。
其中,所述终端通过接收所述网络通过NAS信令的方式下发的业务列表信息或业务等级索引信息使得可以对终端的单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
本步骤中,若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;所述无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,决定启动基于业务的数据连接拥塞控制(Application specific Congestion control for Data Connectivity,ACDC)消息;无线接入网通过***广播消息,通知终端要启动ACDC,同时***广播消息携带ACDC业务列表信息配置到终端。具体步骤参考图7中的步骤701-703。
其中,所述终端通过接收所述网络通过***广播的方式下发的业务列表信息或业务等级索引信息使得可以对终端的所有用户进行配置相同的业务列表信息或业务等级索引信息,但无法对终端的单个用户进行配置业务列表信息或业务等级索引信息。
步骤102,当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。
本步骤中,所述业务列表信息或业务等级索引信息包含业务允许和/或禁止接入信息,当终端接收所述网络下发的终端要发起的业务时,根据所述业务列表信息或业务等级索引信息中的终端要发起的业务是否允许接入的信息,判断终端要发起的业务在所述业务列表信息或业务等级索引信息中是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。所述指示用于通知该终端对业务进行接入控制,例如,该指示可以是ACDC启动的指示,或者网络发生拥塞的指示。
可优选的,当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许具体为:
所述终端接收所述网络下发的指示后,所述终端的非接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
其中,网络下发的指示包括但不限于使用下发指示的方式。
可优先的,所述当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许具体为:
所述终端接收所述网络下发的指示后,所述终端的接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
本步骤中,当终端通过OMA DM或NAS信令或***广播的方式接收所述网络下发的业务列表信息或业务等级索引信息时,当所述终端接收所述网络下方的指示后,所述终端的接入层或者非接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。具体参考图5、图6、图7中的说明。
可优选的,所述当所述终端接收所述网络下发指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许具体为:
所述终端接收所述网络下发的指示后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
本步骤中,参考图8的步骤806所示,UE防火墙通过检查业务列表,判断业务是否允许;参考图9的步骤903所示,UE防火墙根据业务是否允许,通过开放或关闭端口来允许或拒绝业务列表。
可优选的,所述终端接收所述网络下发的指示具体为:
所述终端通过***广播消息的方式从网络获取指示。
本步骤中,无线接入网发生拥塞或者核心网发生拥塞时通知无线接入网;无线接入网向防火墙服务器发送ACDC启动通知及业务列表信息或业务等级索引信息,所述无线接入网通过***广播消息向终端非接入层或接入层通知启动ACDC时,同时将业务列表信息或业务等级索引信息发送给所述终端非接入层或接入层。具体参考图8的步骤801-803。
可优选的,所述终端接收所述网络下发的指示具体为:
所述终端通过专用信令的方式或应用层的方式从网络获取指示。
本步骤中,核心网发生拥塞情况下,由核心网通知防火墙服务器核心网发生拥塞;或者无线接入网发生拥塞时,由无线接入网通知防火墙服务器无线接入网发生拥塞。防火墙服务器收到核心网或者无线接入网拥塞信息后,发送ACDC启动通知消息给UE防火墙(终端防火墙),同时将业务列表信息或业务等级索引信息发送给UE防火墙。具体参考图9中步骤901-902。
本发明实施例公开了一种业务接入的控制方法,所述方法终端通过预配置或从网络中获取业务列表信息或业务等级索引信息;当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许,若是,则向所述网络发起所述终端要发起的业务,若否,则禁止向所述网络发起所述终端要发起的业务。实现特定场景或网络拥塞的情况下的业务接入控制,节省网络资源以保障允许业务的接入,加强运营商对业务的控制及突发事件的处理能力。
实施例二
参考图2,图2是本发明实施例二提供的一种业务接入的控制的方法流程图。如图2所示,所述方法包括:
步骤201,终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;
步骤202,当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求;
步骤203,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端向所述网络发起建立连接请求消息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
可优选的,所述当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端向所述网络发起建立连接请求消息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许具体为:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的接入层向所述网络发起无线资源控制RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
本步骤中,结合图10,图11,图12的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的接入层向所述网络发起RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图13所示。
其中,终端通过接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
可优先的,所述当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端向所述网络发起请求信息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许具体为:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
本步骤中,结合图5,图6,图7中的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图14所示。
其中,终端通过非接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
本发明实施例中,终端通过非接入层或接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带信息单位(Information Element,IE),指示该RRC连接请求是由允许业务发起使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
实施例三
参考图3,图3是本发明实施例三提供的一种业务接入的控制的方法流程图。所述方法包括:
步骤301,网络将业务列表信息或业务等级索引信息配置到终端;
可优选的,所述网络配置业务列表信息或业务等级索引信息给终端具体为:
所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
本步骤中,参考图5或图10的步骤501或步骤1001。所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
其中,网络通过OMA DM的方式可以对单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述网络配置业务列表信息或业务等级索引信息给终端具体为:
所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
本步骤中,参考图6或图11所示的步骤601和602,或1101和1102,当终端在发起附着或跟踪区更新或路由区更新或PDN连接建立等建立连接请求消息时,核心网在附着或跟踪区更新或路由区更新或PDN连接建立等响应消息中将业务列表信息或业务等级索引信息发送给终端。
其中,网络通过NAS信令的方式可以对单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述网络配置业务列表信息或业务等级索引信息给终端具体为:
所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
本步骤中,参考图7或图12的步骤703或步骤1203所示,无线接入网通过***广播消息,通知终端接入层要启动ACDC ,同时通过***广播消息携带ACDC业务配置列表配置到终端。
其中,网络通过***广播的方式可以对多个用户进行配置相同的业务列表信息或业务等级索引信息。
可优选的,所述网络配置业务列表信息或业务等级索引信息给终端具体为:
所述网络通过防火墙服务器将业务列表信息或业务等级索引信息下发给终端。
本步骤中,参考图8的步骤803或图9中步骤902,所述网络通过防火墙服务器将业务列表信息或业务等级索引信息下发给终端。
其中,网络通过防火墙服务器的方式将业务列表信息或业务等级索引信息下发给终端,可以对单个用户进行配置业务列表信息或者业务等级索引信息。
步骤302,,所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
可优选的,所述网络向所述终端下发指示具体为:
所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
本步骤中,结合图5或图6或图7或图10或图11或图12或图8所示的实施例,所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
可优选的,所述所述网络向所述终端下发指示具体为:
所述网络通过应用层的方式向所述终端下发指示。
本步骤中,参考图9的步骤902,所述网络通过应用层的方式向所述终端下发指示。
本发明实施例公开了一种业务接入的控制方法,所述方法终端通过网络配置业务列表信息或业务等级索引信息给终端;,所述网络向所述终端下发指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。实现特定场景或网络拥塞的情况下的业务接入控制,节省网络资源以保障允许业务的接入,加强运营商对业务的控制及突发事件的处理能力。
实施例四
参考图4,图是本发明实施例四提供的一种业务接入的控制方式流程图。
步骤401,网络将业务列表信息或业务等级索引信息配置到终端;
步骤402,,所述网络向所述终端下发指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许;
步骤403,所述网络根据所述终端发送的请求信息中是否携带的业务允许的标识,判断终端要发起的业务是否允许。
可优选的,所述网络根据所述终端发送的请求信息中是否携带的业务允许的标识,判断终端要发起的业务是否允许具体为:
所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
本步骤中,结合图10,图11,图12的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的接入层向所述网络发起RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图13所示。
其中,终端通过接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
可优选的,所述网络根据所述终端发送的请求信息中是否携带的业务允许的标识,判断终端要发起的业务是否允许具体为:
所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
本步骤中,结合图5,图6,图7中的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图14所示。
其中,终端通过非接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
本发明实施例中,终端通过非接入层或接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带信息单位(Information Element,IE),指示该RRC连接请求是由允许业务发起使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
为了更清楚的说明实施例一、实施例二、实施例三、实施例四中的实施例,以下以信令交互的方式对实施例一、二、三、四做更详细的说明。其中,下图图5、图6、图7、图8、图9、图10、图11、图12、图13、图14是本发明实施例一、二、三、四提供的业务控制接入的控制方法示意图。
图5是本发明实施例提供的一种业务接入的控制方法示意图。如图5所示:
501、网络通过OMA DM的方式将业务列表配置至终端,业务列表可以是黑或白列表的形式,列表中包括允许或禁止业务的业务标识;
502、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
503、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,无线接入网决定启动ACDC;
504、无线接入网通过***广播消息,通知终端接入层要启动ACDC; 对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
505、接入层在收到***广播的ACDC启动消息后,将ACDC启动通知给终端的非接入层;
506、应用层发起业务时,由应用层或应用层通过操作***向终端的非接入层发送业务请求,携带业务相关信息,该业务相关信息与业务列表中业务的标识相对应,如都采用应用标识来识别业务;
507、终端非接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤501中收到的ACDC业务列表,看要发起的业务是否在允许业务列表中;
508、若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许业务列表中,则继续后续业务发起流程。
可优选的,图5中步骤506可采用将业务请求的应用标识发送到终端非接入层,由所述终端非接入层再将业务标识信息发送给终端接入层,由终端接入层进行业务是否允许的判断;若要发起的业务不在允许的业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许的业务列表中,则继续后续业务发起流程,具体参考图10所示。
图6是本发明实施例提供的一种业务接入的控制方法示意图。如图6所示:
601、终端在发起附着或跟踪区更新或路由区更新或PDN连接建立等建立连接请求消息。
602、核心网在附着或跟踪区更新或路由区更新PDN连接建立等响应消息中将业务列表发送至终端,业务列表可以是黑或白列表的形式,列表中包括允许或禁止业务的业务标识;
603、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
604、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,无线接入网决定启动ACDC;
605、无线接入网通过***广播消息,通知终端接入层要启动ACDC; 对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
606、接入层在收到***广播的ACDC启动消息后,将ACDC启动通知给终端的非接入层;
607、应用层发起业务时,由应用层或应用层通过操作***向终端的非接入层发送业务请求,携带业务相关信息,该业务相关信息与业务列表中业务的标识相对应,如都采用应用标识来识别业务;
608、终端非接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤602中收到的ACDC业务列表,看要发起的业务是否在允许业务列表中;
609、若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许业务列表中,则继续后续业务发起流程。
在本图6中,也可以由终端接入层来判断业务是否允许,即在步骤606中由非接入层将ACDC服务列表发送给接入层。步骤607中业务请求由应用层发送给非接入层,再由非接入层发送给接入层,由终端接入层进行业务是否允许的判断:若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许业务列表中,则继续后续业务发起流程,具体参考图11所示。
图7是本发明实施例提供的一种业务接入的控制方法示意图。如图7所示:
701、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
702、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,决定启动ACDC;
703、无线接入网通过***广播消息,通知终端接入层要启动ACDC,同时***广播消息携带ACDC业务列表配置至终端,业务列表可以是黑/白业务名单的形式,列表中包括允许/禁止业务的业务标识。对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
704、接入层在收到***广播的ACDC启动消息后,将ACDC启动通知给终端非接入层。
705、应用层发起业务时,由应用层或应用层通过操作***向终端的非接入层发送业务请求,携带业务相关信息,该业务相关信息与业务列表中业务的标识相对应,如都采用应用标识来识别业务;
706、终端非接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤701中收到的ACDC业务列表,看要发起的业务是否在允许业务列表中;
707、若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许业务列表中,则继续后续业务发起流程。
在图7中,也可以由终端接入层来判断业务是否允许,即略去步骤704,而在步骤705后由终端非接入层将业务标识信息发送给终端接入层,由终端接入层进行业务是否允许的判断:若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许业务列表中,则继续后续业务发起流程。具体参考图12所示。
图8是本发明实施例提供的一种业务接入的控制方式示意图。如图8所示:
801、无线接入网发生拥塞,或者核心网发生拥塞时通知无线接入网;
802、无线接入网向防火墙服务器发送ACDC启动通知及业务列表;
803、无线接入网通过广播消息向终端非接入层/接入层通知ACDC启动,同时将ACDC业务列表发送给非接入层/接入层。对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
804、终端非接入层/接入层通知UE防火墙ACDC启动,同时将ACDC业务列表发送给UE防火墙;
805、终端应用层/操作***发送业务请求给UE防火墙,该消息携带业务标识;
806、UE防火墙检查ACDC业务列表,确认该业务是否允许发起
807、UE防火墙根据检查结果,允许/拒绝业务发起。
图9是本发明实施例提供的一种业务接入的控制方式示意图。如图9所示:
901、核心网发生拥塞情况下,由核心网通知防火墙服务器核心网发生拥塞;或者无线接入网发生拥塞时,由无线接入网通知防火墙服务器无线接入网发生拥塞;
902、防火墙服务器收到核心网或无线接入网拥塞信息后,发送ACDC启动通知消息给UE防火墙,同时将ACDC服务列表下发给UE防火墙;
903、终端发起业务请求时先发送给终端防火墙,终端防火墙检查ACDC服务列表,判断该业务是否允许;
904、终端防火墙根据业务是否允许,通过开放或关闭端口来允许或拒绝业务请求,达到终端侧业务发起控制的目的。
图10是本发明实施例提供的一种业务接入的控制方式示意图。如图10所示:
1001、网络通过OMA DM(设备管理)将业务列表配置至终端,业务列表可以是黑/白列表的形式,列表中包括允许/禁止业务的业务标志;
1002、由非接入层将ACDC业务列表发送给接入层;
1003、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
1004、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,无线接入网决定启动ACDC;
1005、无线接入网通过***广播消息,通知终端接入层要启动ACDC; 对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
1006、应用层发起业务时,由应用层或应用层通过操作***向终端的非接入层发送业务请求,携带业务相关信息,该业务相关信息与业务列表中业务的标识相对应,如都采用应用标识来识别业务;
1007、终端接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤1001中收到的ACDC业务列表,看要发起的业务是否在允许业务列表中;
1008a)若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;
1008b) 若要发起的业务在允许业务列表中,则继续后续业务发起流程。
图11是本发明实施例提供的一种业务接入的控制方式示意图。如图11所示:
1101、终端在发起附着或跟踪区更新或路由区更新或PDN连接建立等建立连接请求消息。
1102、核心网在附着或跟踪区更新或路由区更新PDN连接建立等响应消息中将业务列表发送至终端,业务列表可以是黑或白列表的形式,列表中包括允许或禁止业务的业务标识;
1103、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
1104、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,无线接入网决定启动ACDC;
1105、无线接入网通过***广播消息,通知终端接入层要启动ACDC; 对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
1106、非接入层将ACDC服务列表发送给接入层;
1107、业务请求由应用层发送给非接入层,再由非接入层发送给接入层,由终端接入层进行业务是否允许的判断:若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许业务列表中,则继续后续业务发起流程;
1108、终端接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤1102中收到的ACDC业务列表,看要发起的业务是否在允许业务列表中;
1109、若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;若要发起的业务在允许业务列表中,则继续后续业务发起流程。
图12是本发明实施例提供的一种业务接入的控制方式示意图。如图12所示:
1201、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
1202、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,决定启动ACDC;
1203、无线接入网通过***广播消息,通知终端接入层要启动ACDC,同时***广播消息携带ACDC业务列表配置至终端,业务列表可以是黑/白业务名单的形式,列表中包括允许/禁止业务的业务标识。对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
1204、应用层发起业务时,由应用层或应用层通过操作***向终端的接入层发送业务请求,携带业务相关信息,该业务相关信息与业务列表中业务的标识相对应,如都采用应用标识来识别业务;
1205、终端接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤1201中收到的ACDC业务列表,看要发起的业务是否在允许业务列表中;
1206a)、若要发起的业务不在允许业务列表中,则终端非接入层拒绝该业务请求;
1206a)、若要发起的业务在允许业务列表中,则继续后续业务发起流程。
图13是本发明实施例提供的一种业务接入的控制方法示意图。所述方法包括如下步骤:
1301、终端配置ACDC业务列表,配置方式包括:终端预配置, 或通过OMA DM的方式,或通过***消息广播至终端,或通过附着/跟踪区更新/路由区更新/PDN连接建立等流程获取ACDC业务列表。该实施例对配置终端ACDC业务列表的方式不加限制。业务列表可以是黑/白列表的形式,列表中包括允许/禁止业务的业务标识;
1302、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
1303、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,无线接入网决定启动ACDC;
1304、无线接入网通过***广播消息,通知终端接入层要启动ACDC。对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
1305、接入层在收到***广播的ACDC启动消息后,将ACDC启动通知给终端非接入层;
1306、应用层发起业务时,由应用层或应用层通过操作***向终端的非接入层发送业务请求,携带业务相关信息,该业务相关信息与业务列表中业务的标识相对应,如都采用应用标识来识别业务;
1307、终端接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤1301中终端ACDC业务列表,看要发起的业务是否在允许业务列表中;
1308、若要发起的业务在允许业务列表中,则接入层在发起的RRC连接建立连接请求消息中,携带IE信息,比如“MO-ACDC permitted”。
1309、网络网元,如无线接入网在收到RRC连接建立连接请求消息时,检查该RRC连接建立连接请求消息中是否携带步骤1308中所述的IE信息,如“MO-ACDC permitted”。
1310、网络网元,如无线接入网根据RRC连接建立连接请求消息中是否携带步骤1308中所述的IE信息来判断是否接受或拒绝RRC连接建立连接请求消息,如果RRC连接建立连接请求消息中不包含此IE值的RRC连接建立连接请求消息被禁止,通过该机制来对要发起的业务进行控制。
图14是本发明实施例提供的一种业务接入的控制方法示意图。所述方法如下:
1401、终端配置ACDC业务列表,配置方式包括:终端预配置,或通过OMA DM的方式,或通过***消息广播至终端,或通过附着/跟踪区更新/路由区更新/PDN连接建立等流程获取ACDC业务列表。该实施例对配置终端ACDC业务列表的方式不加限制。业务列表可以是黑/白列表的形式,列表中包括允许/禁止业务的业务标识;
1402、若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;
1403、无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,无线接入网决定启动ACDC;
1404、无线接入网通过***广播消息,通知终端接入层要启动ACDC。对于连接态的终端,ACDC的通知消息也可以通过专用信令发送,不限于广播消息的通知方式;
1405、接入层在收到***广播的ACDC启动消息后,将ACDC启动通知给终端非接入层;
1406、应用层发起业务时,由应用层或应用层通过操作***向终端的非接入层发送业务请求,携带业务相关信息,该业务相关信息与业务列表中业务的标识相对应,如都采用应用标识来识别业务;
1407、终端非接入层在获得应用层或操作***发送的业务请求中携带的业务标识后,检查步骤1401中终端ACDC业务列表,看要发起的业务是否在允许业务列表中;
1408、若要发起的业务在允许业务列表中,则非接入层在发起的NAS建立连接请求消息中,如service request或PDN connectivity reqeust消息,携带IE信息,比如“ACDC service permitted”。
1409、网络网元,如MME或SGSN在收到NAS建立连接请求消息时,检查该NAS建立连接请求消息中是否携带步骤1408中所述的IE信息,如“ACDC service permitted”。
1410、网络网元,如MME或SGSN根据NAS消息中是否携带步骤1408中所述的IE信息来判断是否接受或拒绝NAS请求,如果NAS消息中建立连接请求消息中不包含此IE值的NAS消息被禁止,通过该机制来对要发起的业务进行控制。
实施例五
参考图15,图15是本发明实施例五中提供的一种终端设备结构图。所述设备包括:
获取单元1501,接入控制单元1502,标识单元1503;
其中,获取单元1501用于执行实施例一图1中的步骤101,接入控制单元1502用于执行实施例一图1中的步骤102,标识单元1503用于执行实施例二中图2的步骤203。
本领域普通技术人员可以理解为所述本发明实施例五中的终端设备所包括的各个单元只是按照功能逻辑进行划分的,但并不局限于上述的划分,只要能够实现相应的功能即可;另外,各功能单元的具体名称也只是为了便于相互区分,并不用于限制本申请的保护范围。
获取单元1501,用于终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;所述获取单元将获取的业务列表信息或业务等级索引信息发送给接入控制单元;
本单元中,终端可以通过预配置的方式获取业务列表信息或业务等级索引信息。所述预方式可以预先将所述业务列表信息或业务等级索引信息储存在手机SIM卡上,所述业务列表信息可以是黑或白列表的形式,列表中包括允许或禁止业务的业务标识。所述业务等级索引信息包括允许或禁止业务的业务标识外,还包括业务重要性的等级索引信息,将业务按业务的优先级进行划分,并根据划分建立索引信息,使得终端可以对某种业务进行允许或禁止操作,也可以对不同等级的业务进行允许或禁止操作。
其中,终端从网络中获取业务列表信息或业务等级索引信息包括但不限于通过接收网络通过OMA DM的方式业务列表信息或业务等级索引信息,或接收网络通过NAS信令的方式业务列表信息或业务等级索引信息,或接收网络通过***广播的方式下发的业务列表信息或业务等级索引信息,或接收网络通过网络的防火墙服务器下发的业务列表信息或业务等级索引信息。
可优选的,所述获取单元1501具体用于:
所述终端接收由所述网络通过OMA DM的方式业务列表信息或业务等级索引信息。
本单元中,网络通过OMA DM的方式将业务列表信息或业务等级索引信息配置到所述终端。具体参考图5的步骤501,网络通过OMA DM的方式将业务列表信息或业务等级索引信息配置到终端。
其中,所述终端通过接收所述网络通过OMA DM的方式下发的业务列表信息或业务等级索引信息使得可以对终端的单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述获取单元具体用于:
所述终端接收由所述网络通过NAS信令的方式业务列表信息或业务等级索引信息。
本单元中,终端在发起附着或跟踪区更新或路由区更新或PDN连接建立等建立连接请求消息时,所述网络的核心网在附着或跟踪区更新或路由区更新或PDN连接建立等响应消息中将业务列表信息或业务等级索引信息发送到所述终端。具体参考图6的步骤601和602。
其中,所述终端通过接收所述网络通过NAS信令的方式下发的业务列表信息或业务等级索引信息使得可以对终端的单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述获取单元1501具体用于:
所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
本单元中,若核心网发生拥塞,则将网络拥塞状况通知给无线接入网;所述无线接入网在获知核心网拥塞或者自身发生拥塞的情况下,决定指示;无线接入网通过***广播消息,通知终端要启动ACDC,同时***广播消息携带ACDC业务列表信息配置到终端。具体步骤参考图7中的步骤701-703。
其中,所述终端通过接收所述网络通过***广播的方式下发的业务列表信息或业务等级索引信息使得可以对终端的所有用户进行配置相同的业务列表信息或业务等级索引信息,但无法对终端的单个用户进行配置业务列表信息或业务等级索引信息。
所述接入控制单元1502,用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许,若是,则向所述网络发起所述终端要发起的业务,若否,则禁止向所述网络发起所述终端要发起的业务。
可优选的,所述接入控制单元1502具体用于:
所述终端接收所述网络下发的指示后,所述终端的非接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
可优选的,所述接入控制单元1502具体用于:
所述终端接收所述网络下发的指示后,所述终端的接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
本单元中,当终端通过OMA DM或NAS信令或***广播的方式接收所述网络下发的业务列表信息或业务等级索引信息时,当所述终端接收所述网络下方的指示后,所述终端的接入层或者非接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。具体参考图5、图6、图7中的说明。
可优选的,所述接入控制单元1502具体用于:
所述终端接收所述网络下发的启动ACDC 消息后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
本单元中,参考图8的步骤806所示,UE防火墙通过检查业务列表,判断业务是否允许;参考图9的步骤903所示,UE防火墙根据业务是否允许,通过开放或关闭端口来允许或拒绝业务列表。
可优选的,所述接入控制单元1502具体用于:
所述终端通过***广播消息的方式从网络获取指示。
本单元中,无线接入网发生拥塞或者核心网发生拥塞时通知无线接入网;无线接入网向防火墙服务器发送ACDC启动通知及业务列表信息或业务等级索引信息,所述无线接入网通过***广播消息向终端非接入层或接入层通知启动ACDC时,同时将业务列表信息或业务等级索引信息发送给所述终端非接入层或接入层。具体参考图8的步骤801-803。
可优选的,所述接入控制单元1502具体用于:
所述终端通过专用信令的方式或应用层的方式从网络获取指示。
本单元中,核心网发生拥塞情况下,由核心网通知防火墙服务器核心网发生拥塞;或者无线接入网发生拥塞时,由无线接入网通知防火墙服务器无线接入网发生拥塞。防火墙服务器收到核心网或者无线接入网拥塞信息后,发送ACDC启动通知消息给UE防火墙(终端防火墙),同时将业务列表信息或业务等级索引信息发送给UE防火墙。具体参考图9中步骤901-902。
作为另一种可优选的实施例,所述设备还包括:
标识单元1503,用于当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端向所述网络发起请求信息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
可优选的,所述标识单元1503具体用于:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的接入层向所述网络发起RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
本单元中,结合图10,图11,图12的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的接入层向所述网络发起RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图13所示。
其中,终端通过接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
可优选的,所述标识单元1503具体用于:
当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
本单元中,结合图5,图6,图7中的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图14所示。
其中,终端通过非接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
本发明实施例公开了一种控制业务的设备,所述设备包括获取单元1501,接入控制单元1502,终端通过获取单元1501用于预配置或从网络中获取业务列表信息或业务等级索引信息;通过接入控制单元1502用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许,若是,则向所述网络发起所述终端要发起的业务,若否,则禁止向所述网络发起所述终端要发起的业务。实现特定场景或网络拥塞的情况下的业务接入控制,节省网络资源以保障允许业务的接入,加强运营商对业务的控制及突发事件的处理能力。
实施例六
参考图16,图16是本发明实施例六提供的一种网元设备结构图。所述设备包括:
配置单元1601,下发单元1602,处理单元1603;
其中,配置单元1601用于执行实施例三图3中的步骤301,下发单元1602用于执行实施例三图3中的步骤302,处理单元1603用于执行实施例四中图4的步骤403。
本领域普通技术人员可以理解为所述本发明实施例五中的终端设备所包括的各个单元只是按照功能逻辑进行划分的,但并不局限于上述的划分,只要能够实现相应的功能即可;另外,各功能单元的具体名称也只是为了便于相互区分,并不用于限制本申请的保护范围。
配置单元1601,用于网络将业务列表信息或业务等级索引信息配置到终端;
可优选的,配置单元1601具体用于:
所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
本单元中,参考图5或图10的步骤501或步骤1001。所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
其中,网络通过OMA DM的方式可以对单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述配置单元1601具体用于:
所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
本单元中,参考图6或图11所示的步骤601和步骤602,或步骤1101和步骤1102,当终端在发起附着或跟踪区更新或路由区更新或PDN连接建立等建立连接请求消息时,核心网在附着或跟踪区更新或路由区更新或PDN连接建立等响应消息中将业务列表信息或业务等级索引信息发送给终端。
其中,网络通过NAS信令的方式可以对单个用户进行配置业务列表信息或业务等级索引信息。
可优选的,所述配置单元1601具体用于:
所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
本单元中,参考图7或图12的步骤703或步骤1203所示,无线接入网通过***广播消息,通知终端接入层要启动ACDC ,同时通过***广播消息携带ACDC业务配置列表配置到终端。
其中,网络通过***广播的方式可以对多个用户进行配置相同的业务列表信息或业务等级索引信息。
可优选的,所述配置单元1601具体用于:
所述网络通过防火墙服务器将业务列表信息或业务等级索引信息下发给终端。
本单元中,参考图8的步骤803或图9中步骤902,所述网络通过防火墙服务器将业务列表信息或业务等级索引信息下发给终端。
其中,网络通过防火墙服务器的方式将业务列表信息或业务等级索引信息下发给终端,可以对单个用户进行配置业务列表信息或者业务等级索引信息。
下发单元1602,用于,所述网络向所述终端下发指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
可优选的,所述下发单元1602具体用于:
所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
本单元中,结合图5或图6或图7或图10或图11或图12或图8所示的实施例,所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
可优选的,所述下发单元1602具体用于:
所述网络通过应用层的方式向所述终端下发指示。
本单元中,参考图9的步骤902,所述网络通过应用层的方式向所述终端下发指示。
作为一种可优选的实施例,所述设备还包括:
处理单元1603,用于所述网络根据所述终端发送的请求信息中是否携带的业务允许的标识,判断终端要发起的业务是否允许。
可优选的, 所述处理单元1603具体用于:
所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
本单元中,结合图10,图11,图12的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的接入层向所述网络发起RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图13所示。
其中,终端通过接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
可优选的,所述处理单元1603具体用于:
所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
本单元中,结合图5,图6,图7中的实施例,当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。具体参考图14所示。
其中,终端通过非接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带IE值,使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
本发明实施例中,终端通过非接入层或接入层判断业务允许时,后续继续向网络发送RRC连接建立连接请求消息中携带信息单位(Information Element,IE),指示该RRC连接请求是由允许业务发起使得所述网络根据所述IE值继续判断业务是否允许。从而实现可以对业务做进一步检测,防止当终端运行检测发生故障时,可以通过网络做正确的判断。
实施例七
参考图17,图17是本发明实施例提供的一种终端设备1700,所述终端设备可以是移动手机等,本发明具体实施例并不对所述终端设备的具体实现做限定。所述设备1700包括:
处理器(processor)1701,通信接口(Communications Interface)1702,存储器(memory)1703,总线1704。
处理器1701,通信接口1702,存储器1703通过总线1704完成相互间的通信。
通信接口1702,用于与网元通信;
处理器1701,用于执行程序1705。
具体地,程序1705可以包括程序代码,所述程序代码包括计算机操作指令。
处理器1701可能是一个中央处理器CPU,或者是特定集成电路ASIC(Application Specific Integrated Circuit),或者是被配置成实施本发明实施例的一个或多个集成电路。
存储器1703,用于存放程序1705。存储器1703可能包含高速RAM存储器,也可能还包括非易失性存储器(non-volatile memory),例如至少一个磁盘存储器。程序1705具体可以包括:
获取单元1501,用于终端通过预配置,或从网络中获取业务列表信息或业务等级索引信息,所述业务列表信息或业务等级索引信息包含允许和/或禁止的业务的标识信息;
接入控制单元1502,用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许,若是,则向所述网络发起所述终端要发起的业务,若否,则禁止向所述网络发起所述终端要发起的业务。
程序1705中各单元的具体实现参见图15所示实施例中的相应单元,在此不赘述。
实施例八
参考图18,图18是本发明实施例提供的一种网元设备1800,本发明具体实施例并不对所述终端设备的具体实现做限定。所述设备1800包括:
处理器(processor)1801,通信接口(Communications Interface)1802,存储器(memory)1803,总线1804。
处理器1801,通信接口1802,存储器1803通过总线1804完成相互间的通信。
通信接口1802,用于与网元通信;
处理器1801,用于执行程序1805。
具体地,程序1805可以包括程序代码,所述程序代码包括计算机操作指令。
处理器1801可能是一个中央处理器CPU,或者是特定集成电路ASIC(Application Specific Integrated Circuit),或者是被配置成实施本发明实施例的一个或多个集成电路。
存储器1803,用于存放程序1805。存储器1803可能包含高速RAM存储器,也可能还包括非易失性存储器(non-volatile memory),例如至少一个磁盘存储器。程序1805具体可以包括:
配置单元1601,用于网络将业务列表信息或业务等级索引信息配置到终端;
下发单元1602,用于,所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许。
程序1805中各单元的具体实现参见图16所示实施例中的相应单元,在此不赘述。
以上所述仅为本发明的优选实施方式,并不构成对本发明保护范围的限定。任何在本发明的精神和原则之内所作的任何修改、等同替换和改进等,均应包含在本发明要求包含范围之内。

Claims (61)

  1. 一种业务接入的控制方法,其特征在于,所述方法包括:
    终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;
    当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断所述终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求。
  2. 根据权利要求1所述的方法,其特征在于,所述根据所述业务列表信息或业务等级索引信息判断所述终端要发起的业务是否允许接入具体为:
    根据所述业务列表信息,当所述终端要发起的业务在所述业务列表信息中是允许的,则判断所述终端要发起的业务是允许接入的;
    或根据所述业务等级索引信息,当所述终端要发起的业务在所述业务等级索引信息中是属于允许的等级,则判断所述终端要发起的业务是允许接入的。
  3. 根据权利要求1所述的方法,其特征在于,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
    所述终端接收由所述网络通过开放式移动联盟设备管理OMA DM的方式业务列表信息或业务等级索引信息。
  4. 根据权利要求1所述的方法,其特征在于,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
    所述终端接收由所述网络通过非接入层NAS信令的方式业务列表信息或业务等级索引信息。
  5. 根据权利要求1所述的方法,其特征在于,所述终端从网络中获取业务列表信息或业务等级索引信息具体为:
    所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
  6. 根据权利要求1-5任一项所述的方法,其特征在于,所述当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许具体为:
    所述终端接收所述网络下发的指示后,所述终端的非接入层或接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  7. 根据权利要求1-6任一项的方法,其特征在于,所述方法还包括:
    当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端向所述网络发起建立连接请求消息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
  8. 根据权利要求7所述的方法,其特征在于,所述当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许时,则所述终端向所述网络发起建立连接请求消息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许具体为:
    当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的接入层向所述网络发起无线资源控制RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入;
    当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
  9. 根据权利要求1所述的方法,其特征在于,所述终端接收所述网络下发的指示具体为:
    所述终端通过***广播消息的方式或专用信令的方式或应用层的方式从网络获取指示。
  10. 根据权利要求9所述的方法,其特征在于,所述当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许具体为:
    所述终端接收所述网络下发的指示后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  11. 一种业务接入的控制方法,其特征在于,所述方法包括:
    网络将业务列表信息或业务等级索引信息配置到终端;
    所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  12. 根据权利要求11所述的方法,其特征在于,所述网络将业务列表信息或业务等级索引信息配置到终端具体为:
    所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
  13. 根据权利要求11所述的方法,其特征在于,所述网络将业务列表信息或业务等级索引信息配置到终端具体为:
    所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
  14. 根据权利要求11所述的方法,其特征在于,所述网络将业务列表信息或业务等级索引信息配置到终端具体为:
    所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
  15. 根据权利要求11-14任一项所述的方法,其特征在于,所述网络向所述终端下发指示具体为:
    所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
  16. 根据权利要求15所述的方法,其特征在于,所述方法还包括:
    所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;
    所述网络根据所述标识,判断终端要发起的业务是否允许接入。
  17. 根据权利要求16所述的方法,其特征在于,所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;所述网络根据所述标识,判断终端要发起的业务是否允许接入具体为:
    所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
  18. 根据权利要求16所述的方法,其特征在于,所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;所述网络根据所述标识,判断终端要发起的业务是否允许接入具体为:
    所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
  19. 根据权利要求11所述的方法,其特征在于,所述网络将业务列表信息或业务等级索引信息配置到终端具体为:
    所述网络通过防火墙服务器将业务列表信息或业务等级索引信息配置到终端。
  20. 根据权利要求19所述的方法,其特征在于,所述网络向所述终端下发的指示具体为:
    所述网络通过***广播的方式或者专用信令的方式或应用层的方式向所述终端下发指示。
  21. 一种终端设备,其特征在于,所述设备包括:
    获取单元,用于终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;
    所述接入控制单元,用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断所述终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求。
  22. 根据权利要求21所述的终端设备,其特征在于,所述接入控制单元用于执行步骤所述根据所述业务列表信息或业务等级索引信息判断所述终端要发起的业务是否允许接入具体为:
    根据所述业务列表信息,当所述终端要发起的业务在所述业务列表信息中是允许的,则判断所述终端要发起的业务是允许接入的;
    或根据所述业务等级索引信息,当所述终端要发起的业务在所述业务等级索引信息中是属于允许的等级,则判断所述终端要发起的业务是允许接入的。
  23. 根据权利要求21所述的设备,其特征在于,所述获取单元具体用于:
    所述终端接收由所述网络通过OMA DM的方式业务列表信息或业务等级索引信息。
  24. 根据权利要求21所述的设备,其特征在于,所述获取单元具体用于:
    所述终端接收由所述网络通过NAS信令的方式业务列表信息或业务等级索引信息。
  25. 根据权利要求21所述的设备,其特征在于,所述获取单元具体用于:
    所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
  26. 根据权利要求21-25任一项所述的设备,其特征在于,所述接入控制单元具体用于:
    所述终端接收所述网络下发的指示后,所述终端的非接入层或接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  27. 根据权利要求21-26任一项所述的设备,其特征在于,所述设备还包括:
    标识单元,用于当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端向所述网络发起建立连接请求消息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
  28. 根据权利要求27所述的设备,其特征在于,所述标识单元具体用于:
    当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的接入层向所述网络发起无线资源控制RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入;
    当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
  29. 根据权利要求21所述的设备,其特征在于,所述接入控制单元具体用于:
    所述终端通过***广播消息的方式或专用信令的方式或应用层的方式从网络获取指示。
  30. 根据权利要求29所述的设备,其特征在于,所述接入控制单元具体用于:
    所述终端接收所述网络下发的指示后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  31. 一种网元设备,其特征在于,所述设备包括:
    配置单元,用于网络将业务列表信息或业务等级索引信息配置到终端;
    下发单元,用于所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  32. 根据权利要求31所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
  33. 根据权利要求31所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
  34. 根据权利要求31所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
  35. 根据权利要求31-34任一项所述的设备,其特征在于,所述下发单元具体用于:
    所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
  36. 根据权利要求35所述的设备,其特征在于,所述设备还包括:
    处理单元,用于所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;
    所述网络根据所述标识,判断终端要发起的业务是否允许接入。
  37. 根据权利要求36所述的设备,其特征在于,所述处理单元具体用于:
    所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
  38. 根据权利要求36所述的设备,其特征在于,所述处理单元具体用于:
    所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
  39. 根据权利要求31所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过防火墙服务器将业务列表信息或业务等级索引信息配置到终端。
  40. 根据权利要求39所述的设备,其特征在于,所述下发单元具体用于:
    所述网络通过***广播的方式或者专用信令的方式或应用层的方式向所述终端下发指示。
  41. 一种终端设备,其特征在于,所述设备包括:
    获取单元,用于终端获取业务列表信息或业务等级索引信息,所述业务列表信息包含允许和/或禁止的业务的标识信息,所述业务等级索引信息包含允许和/或禁止的业务的标识及等级信息;所述获取单元将获取的业务列表信息或业务等级索引信息发送给接入控制单元;
    所述接入控制单元,用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。
  42. 根据权利要求41所述的设备,其特征在于,所述设备包括处理器,通信接口,存储器和总线;
    其中处理器、通信接口、存储器通过总线完成相互间的通信;
    所述通信接口,用于与网元设备进行通信;
    所述处理器,用于执行程序;
    所述存储器,用于存放程序;
    其中程序用于终端通过预配置,或从网络中获取业务列表信息或业务等级索引信息,所述业务列表信息或业务等级索引信息包含允许和/或禁止的业务的标识信息;用于当所述终端接收所述网络下发的指示后,则根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入,若是,则向所述网络发起所述终端要发起的业务接入请求,若否,则禁止向所述网络发起所述终端要发起的业务接入请求。
  43. 根据权利要求42所述的设备,其特征在于,所述获取单元具体用于:
    所述终端接收由所述网络通过OMA DM的方式业务列表信息或业务等级索引信息。
  44. 根据权利要求42所述的设备,其特征在于,所述获取单元具体用于:
    所述终端接收由所述网络通过NAS信令的方式业务列表信息或业务等级索引信息。
  45. 根据权利要求42所述的设备,其特征在于,所述获取单元具体用于:
    所述终端接收由所述网络通过***广播的方式业务列表信息或业务等级索引信息。
  46. 根据权利要求42-45任一项所述的设备,其特征在于,所述接入控制单元具体用于:
    所述终端接收所述网络下发的指示后,所述终端的非接入层或接入层根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  47. 根据权利要求42-46任一项所述的设备,其特征在于,所述设备还包括:
    标识单元,用于当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端向所述网络发起建立连接请求消息,所述请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许。
  48. 根据权利要求47所述的设备,其特征在于,所述标识单元具体用于:
    当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的接入层向所述网络发起无线资源控制RRC连接请求信息,所述RRC连接请求信息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入;
    当所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务允许接入时,则所述终端的非接入层向所述网络发起NAS消息,所述NAS消息中携带业务是否允许的标识,使得所述网络根据所述标识判断所述终端要发起的业务是否允许接入。
  49. 根据权利要求42所述的设备,其特征在于,所述接入控制单元具体用于:
    所述终端通过***广播消息的方式或专用信令的方式或应用层的方式从网络获取指示。
  50. 根据权利要求49所述的设备,其特征在于,所述接入控制单元具体用于:
    所述终端接收所述网络下发的指示后,所述终端通过终端防火墙根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  51. 一种网元设备,其特征在于,所述网元设备包括:
    配置单元,用于网络将业务列表信息或业务等级索引信息配置到终端;
    下发单元,用于,所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  52. 根据权利要求51所述的设备,其特征在于,所述网元设备包括处理器,通信接口,存储器和总线:
    其中处理器、通信接口、存储器通过总线完成相互间的通信;
    所述通信接口,用于与终端设备进行通信;
    所述处理器,用于执行程序;
    所述存储器,用于存放程序;
    其中程序用于网络将业务列表信息或业务等级索引信息配置到终端;,所述网络向所述终端下发的指示,使得所述终端根据所述业务列表信息或业务等级索引信息判断终端要发起的业务是否允许接入。
  53. 根据权利要求52所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过OMA DM的方式配置业务列表信息或配置业务等级索引信息给终端。
  54. 根据权利要求52所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过NAS信令的方式配置业务列表信息或配置业务等级索引信息给终端。
  55. 根据权利要求52所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过***广播的方式配置业务列表信息或配置业务等级索引信息给终端。
  56. 根据权利要求53-55任一项所述的设备,其特征在于,所述下发单元具体用于:
    所述网络通过***广播的方式或专用信令的方式将指示发送到终端。
  57. 根据权利要求56所述的设备,其特征在于,所述设备还包括:
    处理单元,用于所述网络接收所述终端发送的建立连接请求消息,所述建立连接请求消息中携带业务是否允许接入的标识;
    所述网络根据所述标识,判断终端要发起的业务是否允许接入。
  58. 根据权利要求57所述的设备,其特征在于,所述处理单元具体用于:
    所述网络的无线接入网根据终端发起的RRC连接请求信息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
  59. 根据权利要求57所述的设备,其特征在于,所述处理单元具体用于:
    所述网络的核心网根据终端发起的NAS消息中是否携带业务允许的标识,判断终端要发起的业务是否允许。
  60. 根据权利要求52所述的设备,其特征在于,所述配置单元具体用于:
    所述网络通过防火墙服务器将业务列表信息或业务等级索引信息下发给终端。
  61. 根据权利要求60所述的设备,其特征在于,所述下发单元具体用于:
    所述网络通过***广播的方式或者专用信令的方式或应用层的方式向所述终端下发指示。
PCT/CN2012/083600 2012-10-26 2012-10-26 业务接入的控制方法及设备 WO2014063360A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
PCT/CN2012/083600 WO2014063360A1 (zh) 2012-10-26 2012-10-26 业务接入的控制方法及设备
CN201280002943.7A CN104662966B (zh) 2012-10-26 2012-10-26 业务接入的控制方法及设备
CN201811545031.XA CN109963320B (zh) 2012-10-26 2012-10-26 业务接入的控制方法及设备

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2012/083600 WO2014063360A1 (zh) 2012-10-26 2012-10-26 业务接入的控制方法及设备

Publications (1)

Publication Number Publication Date
WO2014063360A1 true WO2014063360A1 (zh) 2014-05-01

Family

ID=50543905

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/083600 WO2014063360A1 (zh) 2012-10-26 2012-10-26 业务接入的控制方法及设备

Country Status (2)

Country Link
CN (2) CN104662966B (zh)
WO (1) WO2014063360A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104662966A (zh) * 2012-10-26 2015-05-27 华为技术有限公司 业务接入的控制方法及设备
WO2018086059A1 (en) * 2016-11-11 2018-05-17 Qualcomm Incorporated Access control in connected mode, idle mode, and inactive state
CN112601253A (zh) * 2015-09-30 2021-04-02 Oppo广东移动通信有限公司 业务承载拥塞控制的方法及装置
WO2023071782A1 (zh) * 2021-10-25 2023-05-04 惠州Tcl移动通信有限公司 传输方法、电子设备及计算机可读存储介质

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105847102B (zh) * 2016-04-29 2020-11-24 珠海格力智能装备技术研究院有限公司 一种实现现场总线通信的方法、设备及***
CN108738072B (zh) * 2017-04-21 2023-08-15 中兴通讯股份有限公司 一种实现网络切片接纳控制的方法及装置和终端
EP3806545A4 (en) * 2018-06-07 2021-06-16 Huawei Technologies Co., Ltd. METHOD, DEVICE, AND SYSTEM FOR SENDING A SERVICE REQUEST
CN110971622A (zh) * 2020-03-04 2020-04-07 信联科技(南京)有限公司 一种公网应用***与内网应用***间双向访问方法及***
WO2023141771A1 (zh) * 2022-01-25 2023-08-03 北京小米移动软件有限公司 提供感知服务的方法、装置、通信设备及存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101925151A (zh) * 2009-06-12 2010-12-22 华为技术有限公司 接入控制方法、设备及***
CN102118833A (zh) * 2011-03-04 2011-07-06 电信科学技术研究院 一种小区接入指示方法、小区选择方法和设备
WO2011131064A1 (zh) * 2010-04-21 2011-10-27 中兴通讯股份有限公司 家用基站接入的控制方法及***

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7941669B2 (en) * 2001-01-03 2011-05-10 American Express Travel Related Services Company, Inc. Method and apparatus for enabling a user to select an authentication method
US20040177247A1 (en) * 2003-03-05 2004-09-09 Amir Peles Policy enforcement in dynamic networks
CN101969635A (zh) * 2010-04-30 2011-02-09 中兴通讯股份有限公司 一种机器通信的接入控制方法及***和***
CN102271382B (zh) * 2010-06-07 2014-08-20 电信科学技术研究院 一种mtc设备的接入控制方法和设备
CN102340821B (zh) * 2010-07-20 2015-09-16 中兴通讯股份有限公司 一种mtc设备的接入控制方法和***
CN102469520B (zh) * 2010-11-09 2015-09-09 大唐移动通信设备有限公司 一种拥塞控制方法和设备
US20120170503A1 (en) * 2010-12-30 2012-07-05 Motorola, Inc. Method and apparatus for controlling network access in a multi-technology wireless communication system
WO2014063360A1 (zh) * 2012-10-26 2014-05-01 华为技术有限公司 业务接入的控制方法及设备

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101925151A (zh) * 2009-06-12 2010-12-22 华为技术有限公司 接入控制方法、设备及***
WO2011131064A1 (zh) * 2010-04-21 2011-10-27 中兴通讯股份有限公司 家用基站接入的控制方法及***
CN102118833A (zh) * 2011-03-04 2011-07-06 电信科学技术研究院 一种小区接入指示方法、小区选择方法和设备

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104662966A (zh) * 2012-10-26 2015-05-27 华为技术有限公司 业务接入的控制方法及设备
CN104662966B (zh) * 2012-10-26 2019-02-19 华为技术有限公司 业务接入的控制方法及设备
CN112601253A (zh) * 2015-09-30 2021-04-02 Oppo广东移动通信有限公司 业务承载拥塞控制的方法及装置
WO2018086059A1 (en) * 2016-11-11 2018-05-17 Qualcomm Incorporated Access control in connected mode, idle mode, and inactive state
US11240733B2 (en) 2016-11-11 2022-02-01 Qualcomm Incorporated Access control in connected mode, idle mode, and inactive state
WO2023071782A1 (zh) * 2021-10-25 2023-05-04 惠州Tcl移动通信有限公司 传输方法、电子设备及计算机可读存储介质

Also Published As

Publication number Publication date
CN104662966B (zh) 2019-02-19
CN109963320B (zh) 2021-03-23
CN104662966A (zh) 2015-05-27
CN109963320A (zh) 2019-07-02

Similar Documents

Publication Publication Date Title
WO2014063360A1 (zh) 业务接入的控制方法及设备
WO2020204501A1 (en) Method for supporting access to closed network, ue, base station and readable storage medium
WO2020251302A1 (en) Method and system for handling of closed access group related procedure
WO2017123002A1 (en) Method and equipment for determining iot service, and method and equipment for controlling iot service behavior
WO2018111030A1 (ko) 무선 통신 시스템에서 핸드오버 수행 방법 및 이를 위한 장치
WO2018030819A1 (en) Method and apparatus for supporting movement of user equipment in wireless communications
WO2018008944A1 (ko) 무선 통신 시스템에서 등록 관리 방법 및 이를 위한 장치
WO2015190895A1 (en) Method and device for selective communication service in communication system
EP3420754A1 (en) Method and enb equipment for supporting seamless handover
WO2016018017A1 (en) Mobile communication system, different mobile devices sharing same phone number on mobile communication system, and method of providing mobile communication service between different mobile devices sharing same phone number
WO2019107977A1 (en) Method and electronic device for providing communication service
WO2019194633A1 (ko) 무선 통신 시스템에서 사용자 장치의 정책 관리를 위한 장치 및 방법
WO2019177397A1 (en) Method and apparatus for establishing radio bearer
WO2012165794A2 (ko) 이기종 네트워크 기반 데이터 동시 전송 서비스 시스템 및 그 방법
WO2020171672A1 (en) Method for interoperating between bundle download process and esim profile download process by ssp terminal
WO2020159291A1 (en) Method and device for connection reestablishment and context management in a wireless communication system
WO2021133092A1 (en) Method and apparatus to manage nssaa procedure in wireless communication network
EP3155866A1 (en) Method and device for selective communication service in communication system
WO2020149617A1 (en) A method of securing unicast message communication in 3gpp based wireless networks
WO2018016895A1 (ko) Nb-iot 단말의 이동성 처리 수행 방법 및 그 장치
WO2017171506A1 (en) Method and enb equipment for supporting seamless handover
WO2022015109A1 (en) Method and node for communication in communication system supporting integrated access and backhaul (iab)
WO2023075352A1 (en) Method and apparatus for communicating ue information in ntn
WO2013109063A1 (en) Method for establishing user plane after relay node moves
WO2018143769A1 (en) Method and device for controlling data transmission, method and apparatus for controlling continuity of ue

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12887149

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12887149

Country of ref document: EP

Kind code of ref document: A1