IP Library Granted Patent US 12677149
Granted Patent B2
US 12677149 · App. 18/829,976 · Granted Jul 7, 2026

Access control method and apparatus

Inventors: Chunyan Ma (Shenzhen, CN); Hui Ding (Xi'an, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/06H04W76/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12677149
App. No.
18/829,976
Granted
Jul 7, 2026
Kind
B2
Abstract

This application discloses an access control method and an apparatus. The method includes: An SMF receives a session establishment request sent by a terminal. The SMF determines, based on the request, to send an authentication request to a campus server. The SMF receives an authentication failure response message sent by the campus server. When the SMF determines to accept the session establishment request, the SMF sends a policy association establishment request to a PCF and receives a policy association establishment response sent by the PCF. The SMF enforces a policy for a session of the terminal according to a policy rule in the policy association establishment response. The SMF sends a session establishment response message to the terminal.

Claims (46)

1 . An access control method, wherein the method comprises:

receiving, by a session management function network element (SMF), a session establishment request from a terminal;

sending, by the SMF, an authentication request to a campus server based on the session establishment request;

receiving, by the SMF, an authentication failure response message from the campus server; and

when the SMF determines to accept the session establishment request after receiving the authentication failure response message indicating that accessing a campus data network (DN) by the terminal is rejected, sending, by the SMF, a policy association establishment request to a policy control function network element (PCF), and receiving a policy rule from the PCF, wherein the policy rule is a policy rule that is not of a campus, and the policy rule is used to establish a session of the terminal.

2 . The method according to claim 1 , wherein before the SMF receives the authentication failure response message from an authentication server, the method further comprises:

obtaining, by the SMF, subscription information of the terminal from a unified data management network element (UDM), wherein the subscription information comprises error handling indication information indicating that the session establishment request of the terminal is still accepted when authentication on the terminal fails; and

that the SMF determines to accept the session establishment request comprises:

determining, by the SMF based on the error handling indication information, to accept the session establishment request.

3 . The method according to claim 1 , wherein that the SMF determines to accept the session establishment request comprises:

determining, by the SMF based on local configuration information, to accept the session establishment request.

4 . The method according to claim 1 , wherein the policy association establishment request comprises indication information indicating that the terminal fails to access the campus DN, to enable a policy association response sent by the PCF not to comprise a policy rule of the campus DN.

5 . The method according to claim 1 , wherein a policy association establishment response comprises a policy rule of the campus DN; and

the method further comprises:

skipping, by the SMF, enforcing the policy rule of the campus DN; and

sending, by the SMF to the PCF, indication information indicating that the enforcement of the policy rule of the campus DN fails.

6 . The method according to claim 5 , wherein the policy rule of the campus DN comprises a data network access identifier (DNAI) corresponding to a campus service, routing information corresponding to the campus service, and a policy and charging rule corresponding to the campus service.

7 . The method according to claim 5 , wherein the method further comprises:

determining, by the SMF, that a policy rule is the policy rule of the campus DN based on DNAI access point information corresponding to a campus service.

8 . The method according to claim 1 , wherein the sending, by the SMF, an authentication request to a campus server based on the session establishment request comprises:

determining, by the SMF based on location information of the terminal, subscription information of the terminal, or local configuration information of the SMF, to send the authentication request to the campus server.

9 . The method according to claim 1 , wherein the authentication failure response message comprises an authentication failure cause.

10 . The method according to claim 1 , wherein the policy association establishment request comprises an identifier (ID) of a session of the terminal.

11 . The method according to claim 1 , wherein the sending, by the SMF, an authentication request to a campus server based on the session establishment request comprises:

determining, by the SMF based on service information of the session establishment request, that the terminal requests to establish a session for a campus service; and

determining, by the SMF, to send the authentication request to the campus server.

12 . An access control method, wherein the method comprises:

receiving, by a policy control function network element (PCF), indication information indicating that authentication for a terminal to access a campus data network (DN) fails; and

sending, by the PCF, a policy association message to a session management function network element (SMF) based on the indication information, wherein the policy association message comprises a policy rule that is not of the campus DN and does not comprise a policy rule of the campus DN.

13 . The method according to claim 12 , wherein the receiving, by a PCF, indication information indicating that authentication for a terminal to access a campus DN fails comprises:

receiving, by the PCF, a policy association establishment request sent by the SMF, wherein the policy association establishment request comprises the indication information indicating that the authentication for the terminal to access the campus data network DN fails; and

the policy association message is a response message to the policy association establishment request.

14 . The method according to claim 13 , wherein the policy association establishment request comprises an identifier (ID) of a session of the terminal.

15 . The method according to claim 12 , wherein the receiving, by a PCF, indication information indicating that authentication for a terminal to access a campus DN fails comprises:

receiving, by the PCF, a policy authorization request message sent by a campus server, wherein the policy authorization request message comprises the indication information indicating that the authentication for the terminal to access the campus data network DN fails; and

the policy association message is a policy association update message sent by the PCF to the SMF, to indicate that an updated policy rule of a session of the terminal comprises the policy rule of a public network DN but does not comprise the policy rule of the campus DN.

16 . An access control method, wherein the method comprises:

receiving, by a campus server, an authentication request from a session management function network element (SMF), wherein the authentication request comprises an identifier of a terminal that requests to access a campus data network (DN);

determining, by the campus server, to reject accessing the campus DN by the terminal; and

sending, by the campus server, an authentication response to the SMF, wherein the authentication response indicates that authentication succeeds but accessing the campus DN by the terminal is rejected, wherein the authentication response comprises an authentication failure cause.

17 . The method according to claim 16 , wherein the authentication response comprises authorization profile index information, to enable the SMF to send the authorization profile index information to a policy control function network element (PCF), wherein the authorization profile index information indicates that accessing the campus DN by the terminal is rejected.

18 . The method according to claim 17 , wherein the authorization profile index information is used to index policy information configured on the SMF or the PCF.

19 . The method according to claim 16 , wherein the determining, by the campus server, to reject accessing the campus DN by the terminal comprises:

exchanging an extensible authentication protocol (EAP) message with the terminal to obtain authentication information.

20 . The method according to claim 19 , wherein the method further comprises:

determining, by the campus server based on the obtained authentication information or locally configured information, that the terminal is still allowed to establish a session even if accessing the campus DN by the terminal is rejected.