IP Library Granted Patent US 12,457,211
Granted Patent B2
US 12,457,211 · App. 18/104,061 · Granted Oct 28, 2025

Access control method, access control apparatus, and communications device

Inventor: Xiaowan Ke (Guangdong, CN)
Assignee: VIVO MOBILE COMMUNICATION CO., LTD.
H04L63/0876H04L63/083H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,211
App. No.
18/104,061
Granted
Oct 28, 2025
Kind
B2
Abstract

An access control method, an access control apparatus, and a communications device. The access control method includes: obtaining first information and/or second information, where the first information includes at least one of the following: indication information of a first access mode, a first-type routing indication, and a first-type network identifier, and the second information includes at least one of the following: the first-type network identifier, the first-type routing indication, a first-type group identifier, and identification information of a terminal; and performing a first operation based on the first information and/or the second information; where the first operation includes at least one of the following: selecting a first authentication service network element; and determining the first-type group identifier, determining the first-type routing indication, or determining the first-type network identifier.

Claims (122)

1. An access control method, performed by a first communications device and comprising:

obtaining first information from a terminal, wherein the first information comprises identification information of the terminal, wherein the identification information of the terminal comprises index information of a default credential server (DCS); and

performing a first operation based on the first information; wherein

the first operation comprises:

sending third information to a third communication device; wherein the third information comprises the index information of the DCS;

receiving a discovered authentication service network element from the third communication device, the index information of the DCS supported by the discovered authentication service network element comprises the index information of the DCS in the third information.

2. The method according to claim 1 , the first information further comprises at least one of the following: indication information of a first access mode, a first-type routing indication, or a first-type network identifier; or

the method further comprises:

obtaining second information, the second information comprises at least one of the following: the first-type network identifier, the first-type routing indication, or a first-type group identifier;

wherein the first operation further comprises at least one of the following:

selecting a first authentication service network element;

determining the first-type group identifier, the first-type routing indication, information about a service provider, and/or the first-type network identifier; or

requesting, based on the first-type group identifier, the first-type routing indication, the first-type network identifier, the information about the service provider, and/or the indication information of the first access mode, to discover an authentication service network element; wherein

the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing a first network to download a credential for accessing a second network, an access mode for accessing the first network without a credential for accessing the first network, an access mode for using only a restricted service, or the credential for accessing the first network by the terminal is a default credential;

wherein the first network and the second network are a same network or different networks;

wherein the first authentication service network element comprises at least one of the following: an authentication service network element that provides an authentication service for a terminal being in the first access mode, or an authentication service network element that provides an authentication service for a terminal having a default credential;

the first-type group identifier comprises: a group identifier of the authentication service network element that provides an authentication service for a terminal being in the first access mode;

the first-type network identifier comprises: a network identifier used in the first access mode;

the first-type routing indication comprises: a routing indication used in the first access mode.

3. The method according to claim 2 , wherein the requesting, based on the first-type group identifier, the first-type routing indication, the first-type network identifier, and/or the indication information of the first access mode, to discover an authentication service network element comprises at least one of the following:

sending the first-type group identifier to a first target end, wherein the first-type group identifier is used by the first target end to discover an authentication service network element matching the first-type group identifier;

sending the indication information of the first access mode to the first target end, wherein the indication information of the first access mode is used by the first target end to discover an authentication service network element matching the indication information of the first access mode;

sending the first-type routing indication to the first target end, wherein the first-type routing indication is used by the first target end to discover an authentication service network element matching the first-type routing indication; or

sending the first-type network identifier to the first target end, wherein the first-type network identifier is used by the first target end to discover an authentication service network element matching the first-type network identifier.

4. The method according to claim 1 , the method further comprises:

obtaining the indication information of the first access mode from the terminal; and

obtaining the first-type group identifier, the first-type routing indication, or the first-type network identifier according to a configuration on the first communications device;

the first operation further comprises at least one of the following:

determining the first-type group identifier, the first-type routing indication, or the first-type network identifier based on the indication information of the first access mode; or

requesting, based on the first-type group identifier, the first-type routing indication, and/or the first-type network identifier, to discover the authentication service network element.

5. The method according to claim 1 , the method further comprises:

obtaining the first-type network identifier and/or the first-type routing indication from the terminal; and

obtaining the first-type group identifier according to a configuration on the first communications device; wherein

the first operation further comprises at least one of the following:

determining the first-type group identifier based on the first-type network identifier and/or the first-type routing indication; or

requesting, based on the first-type group identifier, to discover the authentication service network element.

6. The method according to claim 1 , wherein the first operation further comprises at least one of the following:

receiving an authentication service network element that is discovered as requested;

exporting the first-type network identifier and/or the first-type routing indication based on a second identifier of the terminal or a third identifier of the terminal;

skipping sending the second identifier of the terminal to the first authentication service network element or the discovered authentication service network element;

exporting a first identifier of the terminal based on the third identifier of the terminal; or

sending the first identifier of the terminal to the first authentication service network element or the discovered authentication service network element;

wherein the first identifier comprises the index information of the DCS;

the second identifier comprises the first-type network identifier and/or the first-type routing indication;

the third identifier comprises the index information of the DCS of the terminal, the first-type network identifier and/or the first-type routing indication.

7. The method according to claim 1 , wherein the first communications device comprises access and mobility management function (AMF).

8. The method according to claim 1 , the index information of the DCS is included in a subscription concealed identifier (SUCI) or a subscription permanent identifier (SUPI) of the terminal for transmission.

9. An access control method, performed by a third communications device and comprising:

obtaining third information from a first communications device, the third information comprises index information of a default credential server (DCS);

obtaining fourth information from an authentication service network element, the fourth information comprises the index information of the DCS supported by the authentication service network element, the DCS being capable of authenticating a terminal having a default credential;

performing a third operation based on the third information and the fourth information; wherein

the third operation comprises at least one of the following:

discovering an authentication service network element matching the third information; or

sending the discovered authentication service network element to the first communications device; wherein

the index information of the DCS supported by the discovered authentication service network element comprises the index information of the DCS in the third information.

10. The method according to claim 9 , wherein the third information further comprises at least one of the following: a first-type group identifier, a first-type routing indication, a first-type network identifier, or indication information of a first access mode;

the fourth information comprises at least one of the following: a routing indication supported by the authentication service network element, a network identifier of a network to which the authentication service network element belongs, an identifier of a group to which the authentication service network element belongs, an access mode supported by the authentication service network element, or an authentication service type supported by the authentication service network element; wherein

an authentication service type supported by the authentication service network element comprises supporting provision of an authentication service to a terminal having a default credential;

the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing a first network to download a credential for accessing a second network, an access mode for accessing the first network without a credential for accessing the first network, an access mode for using only a restricted service, or the credential for accessing the first network by the terminal is a default credential;

the first network and the second network are a same network or different networks;

the first-type group identifier comprises: a group identifier of the authentication service network element that provides an authentication service for a terminal being in the first access mode;

the first-type routing indication comprises: a routing indication used in the first access mode; and

the first-type network identifier comprises: a network identifier used in the first access mode.

11. The method according to claim 10 , wherein in the operation of discovering an authentication service network element matching the third information,

in a case that the third information comprises the indication information of the first access mode, an access mode supported by the discovered authentication service network element is the first access mode; or

in a case that the third information comprises the first-type routing indication, a routing indication supported by the discovered authentication service network element is the first-type routing indication; or

in a case that the third information comprises the first-type network identifier, a network identifier of a network to which the discovered authentication service network element belongs is the first-type network identifier; or

in a case that the third information comprises the first-type group identifier, an identifier of a group to which the discovered authentication service network element belongs is the first-type group identifier; or

the discovered authentication service network element satisfies at least one of the following:

a routing indication supported by the discovered authentication service network element is the first-type routing indication;

a network identifier of a network to which the discovered authentication service network element belongs is the first-type network identifier;

an identifier of a group to which the discovered authentication service network element belongs is the first-type group identifier;

an access mode supported by the discovered authentication service network element is the first access mode; or

an authentication service type supported by the discovered authentication service network element is supporting provision of an authentication service to a terminal having a default credential.

12. The method according to claim 9 , the third communications device comprises a network repository function (NRF).

13. A communications device, comprising a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the following steps are implemented:

obtaining first information from a terminal, wherein the first information comprises identification information of the terminal, wherein the identification information of the terminal comprises index information of a default credential server (DCS); and

performing a first operation based on the first information; wherein

the first operation comprises:

sending third information to a third communication device; wherein the third information comprises the index information of the DCS;

receiving a discovered authentication service network element from the third communication device, the index information of the DCS supported by the discovered authentication service network element comprises the index information of the DCS in the third information.

14. The communications device according to claim 13 , the first information further comprises at least one of the following: indication information of a first access mode, a first-type routing indication, or a first-type network identifier; or

wherein when the computer program is executed by the processor, further causes the communications device to:

obtaining second information, the second information comprises at least one of the following: the first-type network identifier, the first-type routing indication, or a first-type group identifier;

wherein the first operation further comprises at least one of the following:

selecting a first authentication service network element;

determining the first-type group identifier, the first-type routing indication, information about a service provider, and/or the first-type network identifier; or

requesting, based on the first-type group identifier, the first-type routing indication, the first-type network identifier, the information about the service provider, and/or the indication information of the first access mode, to discover an authentication service network element; wherein

the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing a first network to download a credential for accessing a second network, an access mode for accessing the first network without a credential for accessing the first network, an access mode for using only a restricted service, or the credential for accessing the first network by the terminal is a default credential;

wherein the first network and the second network are a same network or different networks;

wherein the first authentication service network element comprises at least one of the following: an authentication service network element that provides an authentication service for a terminal being in the first access mode, or an authentication service network element that provides an authentication service for a terminal having a default credential;

the first-type group identifier comprises: a group identifier of the authentication service network element that provides an authentication service for a terminal being in the first access mode;

the first-type network identifier comprises: a network identifier used in the first access mode;

the first-type routing indication comprises: a routing indication used in the first access mode.

15. The communications device according to claim 14 , wherein the requesting, based on the first-type group identifier, the first-type routing indication, the first-type network identifier, and/or the indication information of the first access mode, to discover an authentication service network element comprises at least one of the following:

sending the first-type group identifier to a first target end, wherein the first-type group identifier is used by the first target end to discover an authentication service network element matching the first-type group identifier;

sending the indication information of the first access mode to the first target end, wherein the indication information of the first access mode is used by the first target end to discover an authentication service network element matching the indication information of the first access mode;

sending the first-type routing indication to the first target end, wherein the first-type routing indication is used by the first target end to discover an authentication service network element matching the first-type routing indication; or

sending the first-type network identifier to the first target end, wherein the first-type network identifier is used by the first target end to discover an authentication service network element matching the first-type network identifier.

16. The communications device according to claim 13 , wherein when the computer program is executed by the processor, further causes the communications device to:

obtaining the indication information of the first access mode from the terminal; and

obtaining the first-type group identifier, the first-type routing indication, or the first-type network identifier according to a configuration on the first communications device;

the first operation further comprises at least one of the following:

determining the first-type group identifier, the first-type routing indication, or the first-type network identifier based on the indication information of the first access mode; or

requesting, based on the first-type group identifier, the first-type routing indication, and/or the first-type network identifier, to discover the authentication service network element.

17. The communications device according to claim 13 , wherein when the computer program is executed by the processor, further causes the communications device to:

obtaining the first-type network identifier and/or the first-type routing indication from the terminal; and

obtaining the first-type group identifier according to a configuration on the first communications device; wherein

the first operation further comprises at least one of the following:

determining the first-type group identifier based on the first-type network identifier and/or the first-type routing indication; or

requesting, based on the first-type group identifier, to discover the authentication service network element.

18. The communications device according to claim 13 , wherein the first operation further comprises at least one of the following:

receiving an authentication service network element that is discovered as requested;

exporting the first-type network identifier and/or the first-type routing indication based on a second identifier of the terminal or a third identifier of the terminal;

skipping sending the second identifier of the terminal to the first authentication service network element or the discovered authentication service network element;

exporting a first identifier of the terminal based on the third identifier of the terminal; or

sending the first identifier of the terminal to the first authentication service network element or the discovered authentication service network element;

wherein the first identifier comprises the index information of the DCS;

the second identifier comprises the first-type network identifier and/or the first-type routing indication;

the third identifier comprises the index information of the DCS of the terminal, the first-type network identifier and/or the first-type routing indication.

19. The communications device according to claim 13 , wherein the first communications device comprises access and mobility management function (AMF).

20. The communications device according to claim 13 , the index information of the DCS is included in a subscription concealed identifier (SUCI) or a subscription permanent identifier (SUPI) of the terminal for transmission.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2023
From: KE, XIAOWAN
To: VIVO MOBILE COMMUNICATION CO., LTD.
Reel/Frame 062571/0511 →
Priority Claims (2)
CN 202010762196.3 · Jul 31, 2020 · national
CN 202110369540.7 · Apr 6, 2021 · national
Continuity (2)
Continuation PCTCN2021110015 · Aug 2, 2021
Related Publication 20230179597A1 · Jun 8, 2023
References Cited (81)
US 7840708B2 · Smith · 2010 [cited by examiner]
US 8305596B2 · Hamada · 2012 [cited by examiner]
US 8755389B1 · Poutievski · 2014 [cited by examiner]
US 9118578B2 · Olshansky · 2015 [cited by examiner]
US 9282098B1 · Hitchcock · 2016 [cited by examiner]
US 10136318B1 · Hancock · 2018 [cited by examiner]
US 10263911B2 · Xiang · 2019 [cited by examiner]
US 10701139B2 · Li · 2020 [cited by examiner]
US 11122033B2 · Chen · 2021 [cited by examiner]
US 11397605B2 · Miyakoshi · 2022 [cited by examiner]
US 20020078383A1 · Leerssen · 2002 [cited by examiner]
US 20060031407A1 · Dispensa · 2006 [cited by examiner]
US 20060156385A1 · Chiviendacz · 2006 [cited by examiner]
US 20110197267A1 · Gravel · 2011 [cited by examiner]
US 20130139222A1 · Kirillin · 2013 [cited by examiner]
US 20130198824A1 · Hitchcock · 2013 [cited by examiner]
US 20130312073A1 · Srivastav · 2013 [cited by examiner]
US 20140273958A1 · Messana et al. · 2014 [cited by applicant]
US 20140298421A1 · Johnson · 2014 [cited by examiner]
US 20150043561A1 · Xia · 2015 [cited by applicant]
US 20160105332A1 · Xiang · 2016 [cited by examiner]
US 20160112452A1 · Guevin · 2016 [cited by examiner]
US 20160212017A1 · Li · 2016 [cited by examiner]
US 20160381150A1 · Rajagopal · 2016 [cited by examiner]
US 20170288971A1 · Jayaraman · 2017 [cited by examiner]
US 20170339626A1 · Mustajarvi et al. · 2017 [cited by applicant]
US 20180004563A1 · Miyazaki · 2018 [cited by examiner]
US 20180011730A1 · Zembutsu · 2018 [cited by examiner]
US 20180063334A1 · Nanjundan · 2018 [cited by examiner]
US 20180146031A1 · Li · 2018 [cited by examiner]
US 20180181424A1 · Gokurakuji · 2018 [cited by examiner]
US 20180375766A1 · Filsfils · 2018 [cited by examiner]
US 20190058670A1 · Zhu · 2019 [cited by examiner]
US 20190089588A1 · Xu · 2019 [cited by examiner]
US 20190089780A1 · Yousaf · 2019 [cited by examiner]
US 20190104182A1 · Elzur · 2019 [cited by examiner]
US 20190363924A1 · Tse · 2019 [cited by examiner]
US 20200162856A1 · Ziv · 2020 [cited by examiner]
US 20200186526A1 · Li · 2020 [cited by applicant]
US 20200329008A1 · Dao · 2020 [cited by examiner]
US 20200404069A1 · Li · 2020 [cited by examiner]
US 20210112412A1 · Ke · 2021 [cited by applicant]
US 20210160175A1 · Gupta · 2021 [cited by examiner]
US 20210409933A1 · Jing · 2021 [cited by examiner]
US 20220039003A1 · Castellanos Zamora · 2022 [cited by examiner]
US 20220060325A1 · Castellanos Zamora · 2022 [cited by examiner]
US 20220158910A1 · Santos · 2022 [cited by examiner]
US 20220225168A1 · Kim · 2022 [cited by examiner]
US 20220225170A1 · Xia · 2022 [cited by examiner]
US 20220312311A1 · Vangala · 2022 [cited by examiner]
US 20220329495A1 · Xie · 2022 [cited by examiner]
US 20220345934A1 · Kim · 2022 [cited by examiner]
US 20220361045A1 · Takeda · 2022 [cited by examiner]
US 20220394580A1 · Minokuchi · 2022 [cited by examiner]
US 20230113108A1 · Tao · 2023 [cited by examiner]
US 20230148302A1 · Ping · 2023 [cited by examiner]
US 20230164538A1 · Zhu · 2023 [cited by examiner]
US 20230189190A1 · Ding · 2023 [cited by examiner]
US 20230217362A1 · Sharma · 2023 [cited by examiner]
US 20230261950A1 · Xie · 2023 [cited by examiner]
US 20230262453A1 · Baskaran · 2023 [cited by examiner]
US 20230262463A1 · Kunz · 2023 [cited by examiner]
US 20230362637A1 · Thiebaut · 2023 [cited by examiner]
CN 107211272A · 2017 [cited by applicant]
CN 109413646A · 2019 [cited by applicant]
CN 110636506A · 2019 [cited by applicant]
EP 3358887A1 · 2018 [cited by applicant]
WO 2013159576A1 · 2013 [cited by applicant]
WO 2019035287A1 · 2019 [cited by applicant]
WO 2020098974A1 · 2020 [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/CN2021/110015 , dated Nov. 1, 2021, 9 Pages. [cited by applicant]
Huawei, HiSilicon “Alternative 3GPP Credentials based on Identity-based Cryptography” 3GPP TSG SA WG3 (Security) Meeting #84b, San Diego (USA), Jul. 2016, S3-161365, 5 Pages. [cited by applicant]
First Office Action for Chinese Application No. 202110369540.7, dated Dec. 28, 2023, 17 Pages. [cited by applicant]
Extended European Search Report for Application No. 21851111.1, dated Dec. 14, 2023, 13 Pages. [cited by applicant]
3GPP 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on enhanced support of non-public networks (Release 17) 3GPP TR 23.700-07 V0.4.0, 2020, 159 Pages. [cited by applicant]
Ericsson “AUSF/UDM selection using SUCI” 3GPP SA WG2 Meeting #1278IS, Newport Beach, CA, USA, May 2018, S2-184772, 3 Pages. [cited by applicant]
Motorola Mobility, “KI #1, New Sol: UE external subscription data stored in the SNPN” 3GPP TSG-SA WG2 Meeting #139E {e-meeting), Elbonia, Jun. 2020, S2-2004212, 6 Pages. [cited by applicant]
First Office Action for Japanese Application No. 2023-503412, dated Dec. 11, 2023, 4 Pages. [cited by applicant]
Ericsson “NF selection in SNPN 5GC” 3GPP TSG-SA WG2 Meeting #138E, Elbonia, Apr. 2020, S2-2003250, 3 Pages. [cited by applicant]
Samsung “KI#4, Solution #5: update on UE onboarding and remote provisioning UP solution” 3GPP TSG-WG SA2 Meeting #139e-meeting, Elbonia, Jun. 2020, S2-2004368, 8 Pages. [cited by applicant]
Samsung, “KI#4, new Solution: UE onboarding via control plane” 3GPP TSG-WG SA2 Meeting #139e-meeting, Elbonia, Jun. 2020, S2-2004369, 7 Pages. [cited by applicant]