A communication method, related device and system
By using the N32f link to send feedback messages and releasing N32c link resources between SEPP devices, the resource occupation problem in the prior art is solved, and communication efficiency and system resource utilization are improved.
Patent Information
- Application Number
- CN202011232419.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-06
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2040-11-06
AI Technical Summary
In the prior art, SEPP devices need to maintain and use the resources of the N32c link when sending error reports, resulting in resource occupancy and inefficiency.
The SEPP device sends feedback messages to the peer SEPP device through the N32f link, indicating that the roaming message cannot be processed, avoid occupying N32c link resources, and releases the N32c link and TLS link if necessary, and utilizes the IPX device on the N32f link.
It reduces the occupation of N32c link resources, improves the utilization efficiency of system resources, reduces the waste of system resources, and improves the processing efficiency.
Smart Images

Figure CN114531675B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication method, related devices and systems. Background Art
[0002] Currently, the 3rd Generation Partner Project (3GPP) defines the security and edge protection proxy (SEPP) device as a border security gateway for the 5G core network (5Gcore, 5GC). Figure 1 As shown, the SEPP device 101 and the SEPP device 102 communicate with each other via an N32-C (abbreviated as N32c) link and an N32-F (abbreviated as N32f) link.
[0003] In the prior art, SEPP device 102 receives roaming signaling from SEPP device 101, which is forwarded by one or more IP exchange service (IPX) devices included in an N32f link. If SEPP device 102 determines that it cannot process the roaming signaling, SEPP device 102 sends an error report to SEPP device 101 via the N32c link, indicating that SEPP device 102 cannot process the roaming signaling.
[0004] In the existing technical solution, when SEPP devices send error reports between each other, it is necessary to maintain and use the resources of the N32c link. Summary of the Invention
[0005] The embodiments of the present application provide a communication method, related devices, and systems for reducing the occupancy of N32c link resources in the process of sending error reports.
[0006] In a first aspect, an embodiment of the present invention provides a communication method, comprising: a first security and edge proxy (SEPP) device receiving a roaming message from an IP exchange operator (IPX) device, the roaming message being used to implement a roaming service between the first SEPP device and a second SEPP device; the first SEPP device determining that it cannot process the roaming message, and sending a feedback message to the IPX device, the feedback message being used to indicate that the first SEPP device cannot process the roaming message.
[0007] As can be seen, if the first SEPP device determines that it cannot process the roaming message from the second SEPP device, it can send a feedback message to the second SEPP device via the N32f link, indicating that the first SEPP device cannot process the roaming message. This feedback message can be used to send an error report. Because the feedback message is transmitted via the N32f link, transmission of the feedback message does not occupy resources on the N32c link. The roaming message and feedback message can be transmitted via the N32f link, reducing the difficulty of the first SEPP device indicating to the second SEPP device that it cannot process the roaming message and improving efficiency. Furthermore, by having the IPX device included in the N32f link send the feedback message to the second SEPP device, the utilization rate of each IPX device can be improved, fully utilizing each IPX device on the N32f link. This avoids inefficient occupation of system resources by IPX devices during transmission of the feedback message via the N32c link, improving system resource utilization efficiency and avoiding waste of system resources.
[0008] Based on the first aspect, in an optional implementation, the method further includes: when a target shared key has been exchanged between the first SEPP device and the second SEPP device through the N32c link, the first SEPP device releasing the N32c link, and the target shared key is used to implement secure communication between the first SEPP device and the second SEPP device.
[0009] Based on the first aspect, in an optional implementation, the method further includes: the first SEPP device sending a release request message to the second SEPP device through the N32c link, where the release request message is used to request the second SEPP device to release the N32c link.
[0010] Based on the first aspect, in an optional implementation, the method further includes: the first SEPP device releasing the connection relationship between the transport layer security (TLS) link and the N32c link, and clearing resources related to the N32c link to release the N32c link. After the N32c link is released, the TLS link can be released.
[0011] It can be seen that the first SEPP device and the second SEPP device perform the process of transmitting the feedback message through the N32f link. If the N32f link is successfully established, the first SEPP device and the second SEPP device can release the N32c link, thereby effectively saving the overhead of maintaining the long connection of the N32c link.
[0012] Based on the first aspect, in an optional implementation, before the first security and edge proxy SEPP device receives a roaming message from an IP exchange operator IPX device, the method further includes: the first SEPP device sending a roaming request message to the IPX device, the roaming request message being used to request a roaming service from the second SEPP device, the roaming request message including the address of the second SEPP device; and the roaming message being a roaming response message generated by the second SEPP device based on the roaming request message.
[0013] As can be seen, in this implementation, the first SEPP device serves as the requester of the roaming service, and the second SEPP device serves as the responder of the roaming service. The first SEPP device requests the roaming service from the second SEPP device through the roaming request message.
[0014] Based on the first aspect, in an optional implementation, the method further includes: the first SEPP device determining an address of a corresponding second SEPP device based on the N32f context identifier included in the roaming message; and the first SEPP device generating the feedback message, the feedback message including the address of the second SEPP device, and the feedback message being used to indicate that the first SEPP device cannot process the roaming response message.
[0015] As can be seen, if the first SEPP device determines that it cannot process the roaming response message, it sends a feedback message to the second SEPP device via the N32f link. Sending the feedback message to the second SEPP device via N32f eliminates the need to occupy N32c link resources, thereby improving the utilization of the IPX devices included in the N32c link.
[0016] Based on the first aspect, in an optional implementation, the roaming message is a roaming request message for requesting a roaming service from the first SEPP device, and the roaming message includes an address of the first SEPP device.
[0017] As can be seen, in this implementation, the first SEPP device acts as a responder of the roaming service, and the second SEPP device acts as a requester of the roaming service. The second SEPP device requests the roaming service from the first SEPP device through the roaming message.
[0018] Based on the first aspect, in an optional implementation, the method further includes: if the first SEPP device determines that the roaming message satisfies at least one of the following items, then determining that the first SEPP device cannot process the roaming message: failure to decrypt the roaming message, failure to check the integrity of the roaming message, failure to check the integrity of a modified block of the roaming message, failure to apply a JSON patch to the modified block of the roaming message, or failure to reconstruct a next-generation Hypertext Transfer Protocol Security (HTTP / 2) message based on the roaming message.
[0019] Based on the first aspect, in an optional implementation, the feedback message is further used to indicate a reason why the first SEPP device cannot process the roaming message, where the reason may be one or more of the following reasons:
[0020] Unable to decrypt the roaming message, failed to check the integrity of the roaming message, failed to check the integrity of the modified block of the roaming message, failed to apply the JSON patch program to the modified block of the roaming message, or failed to reconstruct the next generation Hypertext Transfer Protocol Security HTTP / 2 message based on the roaming message.
[0021] Reconstructing the HTTP / 2 message according to the roaming message may include extracting the HTTP / 2 message from the message body of the roaming message.
[0022] Based on the first aspect, in an optional implementation, the feedback message includes an N32f context identifier, where the N32f context identifier is used to indicate a target shared key for decrypting the feedback message.
[0023] Based on the first aspect, in an optional implementation, after the first SEPP device determines that the roaming message cannot be processed, the method further includes: the first SEPP device sending the feedback message to a network function NF.
[0024] In a second aspect, an embodiment of the present invention provides a communication method, comprising: a second security and border proxy SEPP device receives a signaling message sent from a network function device NF, and sends a roaming message to an IP exchange operator IPX device, where the roaming message is used to implement a roaming service between the first SEPP device and the second SEPP device, and the roaming message includes the signaling message; and the second SEPP device receives a feedback message from the IPX device, where the feedback message is used to indicate that the first SEPP device cannot process the roaming message.
[0025] For a detailed description of the beneficial effects shown in this aspect, please refer to the first aspect and the details will not be repeated here.
[0026] Based on the second aspect, in an optional implementation, the method further includes: when a target shared key has been exchanged between the first SEPP device and the second SEPP device through the N32c link, the second SEPP device releasing the N32c link, and the target shared key is used to implement secure communication between the first SEPP device and the second SEPP device.
[0027] Based on the second aspect, in an optional implementation, the second SEPP device receives a release request message from the first SEPP device, where the release request message is used to request the second SEPP device to release the N32c link.
[0028] Based on the second aspect, in an optional implementation, the second SEPP device releases the N32c link according to the release request message and clears resources related to the N32c link on the second SEPP device side. After the N32c link is released, the TLS link can be released.
[0029] Based on the second aspect, in an optional implementation, before the second security and border proxy SEPP device sends a roaming message to the IP exchange operator IPX device, the method further includes: the second SEPP device receiving a roaming request message from the IPX device, the roaming request message being used to request roaming services from the second SEPP device, the roaming request message including the address of the second SEPP device; and the second SEPP device generating a roaming response message based on the roaming request message, the roaming response message being the roaming message.
[0030] Based on the second aspect, in an optional implementation, the feedback message includes an address of the second SEPP device, and the feedback message is used to indicate that the first SEPP device cannot process the roaming response message.
[0031] Based on the second aspect, in an optional implementation, the roaming message is a roaming request message for requesting a roaming service from the first SEPP device, and the roaming message includes an address of the first SEPP device.
[0032] Based on the second aspect, in an optional implementation, the feedback message is further used to indicate a reason why the first SEPP device cannot process the roaming message.
[0033] Based on the second aspect, in an optional implementation, the reason is at least one of the following: inability to decrypt the roaming message, failure in integrity check of the roaming message, failure in integrity check of the modified block of the roaming message, failure in applying the JSON patch program to the modified block of the roaming message, or failure in reconstructing the next-generation Hypertext Transfer Protocol Security HTTP / 2 message based on the roaming message.
[0034] Based on the second aspect, in an optional implementation, the feedback message includes an N32f context identifier. After the second SEPP device receives the feedback message from the IPX device, the method further includes: obtaining, by the second SEPP device, a target shared key corresponding to the N32f context identifier; and decrypting, by the second SEPP device, the feedback message using the target shared key.
[0035] In a third aspect, an embodiment of the present invention provides a security and border protection agent SEPP device, comprising: at least one processor and a mutually coupled memory, the memory storing computer program code, the processor calling and executing the computer program code in the memory, so that the SEPP device executes the method shown in any one of the first aspects above or executes the method shown in any one of the second aspects above.
[0036] In a fourth aspect, an embodiment of the present invention provides a security and border protection agent SEPP device, comprising: a receiving unit, a processing unit, and a sending unit, wherein the receiving unit is used to execute the steps related to reception shown in any one of the first aspect or the second aspect above, the processing unit is used to execute the steps related to processing shown in any one of the first aspect or the second aspect above, and the sending unit is used to execute the steps related to sending shown in any one of the first aspect or the second aspect above.
[0037] In a fifth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it can complete the method shown in any one of the first aspects above or execute the method shown in any one of the second aspects above.
[0038] In a sixth aspect, an embodiment of the present invention provides a communication system, comprising a first security and border proxy SEPP device and a second SEPP device, wherein the first SEPP device is configured to execute the method as shown in any one of the first aspects above, and the second SEPP device is configured to execute the method as shown in any one of the second aspects above.
[0039] In the seventh aspect, an embodiment of the present invention provides a communication device, comprising: at least one input device, a processor and at least one output device; wherein the input device is used to execute the steps related to reception shown in any one of the above-mentioned first aspect or second aspect, the processor is used to execute the steps related to processing shown in any one of the above-mentioned first aspect or second aspect, and the output device is used to execute the steps related to sending shown in any one of the above-mentioned first aspect or second aspect.
[0040] In an eighth aspect, an embodiment of the present invention provides a communication device, comprising: an input interface circuit, a logic circuit, and an output interface circuit, wherein the logic circuit is used to execute the method shown in any one of the first aspects above, which is executed by the first SEPP device in the embodiment of the present application, or the logic circuit is used to execute the method shown in any one of the second aspects above, which is executed by the second SEPP device in the embodiment of the present application.
[0041] In the ninth aspect, an embodiment of the present invention provides a computer program product comprising instructions, which, when run on a computer device, enables the computer device to execute the method shown in any one of the above-mentioned first aspects that can be executed by the first SEPP device, or enables the computer device to execute the method shown in any one of the above-mentioned second aspects that can be executed by the second SEPP device.
[0042] In a tenth aspect, an embodiment of the present invention provides a communication system, including a first security and border proxy SEPP device and an IPX device, wherein the IPX device is used to send a roaming message to the first SEPP device, and the roaming message is used to implement a roaming service between the first SEPP device and a second SEPP device; the first SEPP device is configured to execute the method as shown in any one of the above-mentioned first aspects.
[0043] In the eleventh aspect, an embodiment of the present invention provides a communication system, including: a network function device NF and a second security and border protection agent SEPP device, the network function device NF is configured to execute the step of sending a signaling message to the second SEPP device; the second SEPP device is configured to execute the method shown in any one of the above-mentioned second aspects.
[0044] In any of the above technical solutions, the address of the SEPP device may be a fully qualified domain name (FQDN), a physical address, an IP address, etc. The address of the SEPP device may be referred to as an identifier of the SEPP device.
[0045] In any of the above technical solutions, the roaming message may be a service discovery request or a network slicing request. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 A structural example diagram of a communication system;
[0047] Figure 2 A schematic diagram of a 5G network architecture provided in an embodiment of the present application;
[0048] Figure 3 Another structural example diagram of a communication system;
[0049] Figure 4 A flowchart of a communication method provided in an embodiment of the present application;
[0050] Figure 5 A flowchart of another communication method provided in an embodiment of the present application;
[0051] Figure 6A flowchart of another communication method provided in an embodiment of the present application;
[0052] Figure 7 This is a structural example of the SEPP device provided in the embodiment of the present application;
[0053] Figure 8 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0054] Figure 9 A schematic diagram of an interface of a single board in a communication device provided in an embodiment of the present application;
[0055] Figure 10 This is another structural example of the SEPP device provided in the embodiments of the present application. DETAILED DESCRIPTION
[0056] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present invention.
[0057] The terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish similar items and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, such that the embodiments described herein can be practiced in an order other than that shown or described herein.
[0058] See also Figure 2 , Figure 2 This is a schematic diagram of a 5G network architecture as an example of an embodiment of the present application. The 5G network splits some functional devices of the 4G network (such as the mobility management entity (MME) and so on) and defines an architecture based on a service-oriented architecture. Figure 2 In the network architecture shown, the functions similar to those of the MME in the 4G network are split into the access and mobility management function (AMF) and the session management function (SMF), etc.
[0059] The following describes the 5G network architecture:
[0060] User equipment (UE) accesses a data network (DN) by accessing an operator's network, thereby enabling the UE to use services provided by the operator or a third party on the data network.
[0061] For ease of explanation, in the embodiments of the present application, user terminals, user equipment, terminal devices, mobile terminals, or terminals may be collectively referred to as UEs. That is, unless otherwise specified, the UEs described in the embodiments of the present application may be replaced with user terminals, user equipment, terminal devices, mobile terminals, or terminals, and of course, they may also be interchangeable.
[0062] The access and mobility management function (AMF) is a control plane function device in the 3GPP network, which is mainly responsible for access control and mobility management of UE access to the operator network. Among them, the security anchor function (SEAF) can be deployed in the AMF, or SEAF can also be deployed in another device different from the AMF. Figure 2 In the example above, SEAF is deployed in AMF. When SEAF is deployed in AMF, SEAF and AMF can be collectively referred to as AMF.
[0063] The Session Management Function (SMF) is a control plane function in 3GPP networks. The SMF is primarily responsible for managing UE packet data unit (PDU) sessions. A PDU session is a channel for transmitting PDUs. The UE can exchange PDUs with the DN through a PDU session. The SMF is responsible for establishing, maintaining, and deleting PDU sessions.
[0064] The data network, also known as the packet data network (PDN), is a network located outside the 3GPP network. The 3GPP network can access multiple DNs, on which various services provided by operators or third parties can be deployed.
[0065] The unified data management (UDM) entity is also a control plane functional device in the 3GPP network. The UDM is primarily responsible for storing the subscription data, credentials, and subscriber permanent identifier (SUPI) of subscriber users (UEs) in the 3GPP network. This data can be used to authenticate and authorize UEs to access the operator's 3GPP network. Furthermore, the UDM can also integrate the functions of the home subscriber server (HSS) and home location register (HLR) in the network.
[0066] The authentication server function (AUSF) is also a control plane function device in the 3GPP network. AUSF is mainly used for the first level of authentication (i.e., the authentication of the 3GPP network to its subscribers).
[0067] The Network Exposure Function (NEF) is a control plane function in the 3GPP network. NEF is responsible for opening the external interfaces of the 3GPP network to third parties in a secure manner.
[0068] The network repository function (NRF) is also a control plane functional device in the 3GPP network. It is mainly responsible for storing the configuration and service profiles of accessible network functions (NFs) and providing network function discovery services for other network elements.
[0069] The user plane function (UPF) is the gateway for communication between the 3GPP network and the DN.
[0070] The Policy Control Function (PCF) is a control plane function in the 3GPP network that provides PDU session policies to the SMF. Policies may include billing, quality of service (QoS), authorization-related policies, etc.
[0071] The access network (AN) is a subnetwork of the 3GPP network. To access the 3GPP network, the UE must first pass through the AN. In wireless access scenarios, the AN is also called the radio access network (RAN).
[0072] As a border security gateway of the 5G core network (5GC), the SEPP device mainly acts as a proxy for connection between operator networks. The signaling messages between the internal network function (NF) of the 5G core network and the roaming network are forwarded through the SEPP device.
[0073] 3GPP network refers to a network that complies with 3GPP standards. Figure 2 The parts other than UE and DN can be regarded as 3GPP network. 3GPP network is not limited to 5G network, but also includes 2G, 3G, and 4G networks. Usually 3GPP network is operated by operators. Figure 2 In the illustrated architecture, N1, N2, N3, N4, and N6 represent reference points between related entities or network functions, respectively. Nausf, Namf, and so on represent service-oriented interfaces of related network functions, respectively.
[0074] Of course, 3GPP networks and non-3GPP networks may coexist, and some network elements in 5G networks may also be used in some non-5G networks.
[0075] Combine Figure 1 and Figure 2 As shown, the SEPP device serves as a border security gateway, supports integrity and confidentiality protection of transmission messages, and also supports the IPX device to identify or modify at least one item of the content of the transmission message, wherein the SEPP device modifying the transmission message can be the SEPP device modifying the message header of the transmission message.
[0076] The IPX device may include a Diameter Routing Agent (DRA) device or a Domain Name Server (DNS). In addition, the IPX device may be called a Hyper Text Transfer Protocol (HTTP) proxy.
[0077] In the embodiments of the present application, a SEPP device may be referred to as a SEPP (e.g., a first SEPP device may be referred to as a first SEPP, a second SEPP device may be referred to as a second SEPP, and so on), meaning that SEPP and SEPP devices can be used interchangeably. An IPX device may be referred to as an IPX (e.g., a first IPX device may be referred to as a first IPX, a second IPX device may be referred to as a second IPX, and so on), meaning that IPX and IPX devices can be used interchangeably.
[0078] When a UE roams between networks of different operators, the types of SEPP devices can be divided into visited SEPP devices (vSEPP devices) and home SEPP devices (hSEPP devices).
[0079] See also Figure 1 When SEPP devices 101 and 102 belong to different carrier networks, they can be connected via an N32 interface. For example, when SEPP device 101 functions as a vSEPP device and SEPP 102 functions as an hSEPP device, SEPP devices 101 and 102 are directly connected via an N32-C (N32c) interface. The link between SEPP devices 101 and 102 for communication based on the N32c interface is called an N32c link. This N32c link is used to perform initial handshakes and negotiation between SEPP devices 101 and 102 for N32 message transmission.
[0080] SEPP device 102 can also connect to an IPX device via an N32-F (N32f) interface, which in turn connects to SEPP device 101 via an N32f interface. The link between SEPP devices 101 and 102, which communicates over the N32f interface, is called an N32f link. The N32f interface enables communication between network function 103 and network function 104. Network function 103 is the network function connected to SEPP device 101, and network function 104 is the network device connected to SEPP device 102.
[0081] One or more IPX devices may be connected between the SEPP device 101 and the SEPP device 102. This embodiment does not limit the number of IPX devices connected between the SEPP device 101 and the SEPP device 102. For example, Figure 1 As shown, the SEPP device 101 and the SEPP device 102 are connected to the IPX device 105 and the IPX device 106 in sequence.
[0082] It should be clear that this embodiment is for two connected SEPP devices (eg Figure 1The types of SEPP devices 101 and 102 shown are provided for optional examples and are not limiting. For example, from the perspective of providing services and consuming services, SEPP device types can be further categorized as consumer's SEPP devices (cSEPP) and producer's SEPP devices (pSEPP). A vSEPP device may be a pSEPP device, while an hSEPP device may be a cSEPP device. Alternatively, a vSEPP device may be a cSEPP device, while an hSEPP device may be a pSEPP device.
[0083] To be clear, in Figure 1 and Figure 2 In the example shown, a 5GC deploying a SEPP device is used as an example for illustrative description. This embodiment does not limit the number of SEPP devices deployed by a 5GC. For example, Figure 3 As shown, the public land mobile network (PLMN) of operator A includes 5GC310 and SEPP devices 311...SEPP devices 31N connected to 5GC310 respectively. This embodiment does not limit the specific value of N, as long as N is a positive integer greater than 1.
[0084] Operator A connects with multiple other operator networks (or roaming partners for short), where different roaming partners have different PLMNs. Figure 3 The example of operator A corresponding to roaming partner 1 and roaming partner C is used for exemplary description. Roaming partner 1's PLMN includes 5GC 320 and SEPP devices 321 ... 32M connected to 5GC 320, respectively. Roaming partner C's PLMN includes 5GC 330 and SEPP devices 331 ... 33P connected to 5GC 330, respectively. This embodiment does not limit the specific values of M and P, as long as M and P are positive integers greater than 1.
[0085] For example, if operator A is connected to roaming partner 1, operator A's SEPP device 311 communicates with roaming partner 1's SEPP device 321 via an N32c link and an N32f link. For another example, if operator A is connected to roaming partner C, operator A's SEPP device 31N communicates with roaming partner C's SEPP device 33P via an N32c link and an N32f link. The N32c link and the N32f link are described above and are not detailed here.
[0086] Based on the above network architecture, the embodiment of the present application provides a communication method. By using the communication method shown in this embodiment, it is possible to execute the error reporting process between two SEPP devices without the need for coordination between the N32c link and the N32f link, effectively reducing the complexity of executing the error reporting process and improving efficiency. Figure 4 The following illustrates the execution process of the communication method provided in this application:
[0087] Step 401: An N32c link and an N32f link are established between a first SEPP device and a second SEPP device.
[0088] The first SEPP device and the second SEPP device shown in this embodiment may belong to PLMNs of different operators, and the first SEPP device shown in this embodiment is a requester of the roaming service, while the second SEPP device is a responder of the roaming service.
[0089] For example, in this embodiment, the first SEPP device is a cSEPP, and the second SEPP device is a pSEPP. In another example, the first SEPP device is a vSEPP device, and the second SEPP device is an hSEPP device.
[0090] It should be clarified that, in other examples, the "first" and "second" in the first SEPP device and the second SEPP device are used to distinguish two different SEPP devices. It should be understood that the first SEPP device and the second SEPP device are interchangeable, that is, the first SEPP device is the responder of the roaming service, and the second SEPP device is the requester of the roaming service.
[0091] Next, the purpose of establishing an N32c link between the first SEPP device and the second SEPP device is explained:
[0092] When the N32c link is established between the first SEPP device and the second SEPP device, the first SEPP device and the second SEPP device may agree on a security mechanism for protecting messages transmitted on the N32f.
[0093] The process of establishing an N32c link between the first SEPP device and the second SEPP device is described again with reference to the following steps:
[0094] Step a1: The first SEPP device sends a first request message to the second SEPP device. The first request message includes at least initial security negotiation data and the address of the first SEPP device.
[0095] The initial security negotiation data is security negotiation data supported by the first SEPP device, and the security negotiation data may be at least one of a protocol for N32 interconnect security (PRINS) parameter or a transport layer security (TLS) parameter.
[0096] Specifically, the first SEPP device pre-stores the address of the second SEPP device. When an N32c link is established between the first SEPP device and the second SEPP device, the first SEPP device can send the first request message to the second SEPP device having the address of the second SEPP device.
[0097] Optionally, the first request message may further include information about the operator to which the first SEPP device belongs and an identifier of the first SEPP device, etc. The first request message may also carry an address of the second SEPP device.
[0098] Step a2: The second SEPP device sends a first response message to the first SEPP device.
[0099] The first response message includes a "200" status code and target security negotiation data selected by the second SEPP device.
[0100] The target security negotiation data is security negotiation data determined by the second SEPP device and supported by both the first SEPP device and the second SEPP device.
[0101] Specifically, the second SEPP device may send the first response message to the first SEPP device based on the address of the first SEPP device included in the first request message.
[0102] The first SEPP device and the second SEPP device implement the establishment of the N32c link by executing steps a1 and a2.
[0103] The first SEPP device and the second SEPP device perform an initial handshake and negotiation between the first SEPP device and the second SEPP device via the N32c link to transmit an N32 message, thereby establishing an N32f link.
[0104] Step 402: The first NF sends a first signaling message to the first SEPP device.
[0105] The first NF and the first SEPP device belong to the same PLMN. The first NF requests a roaming service from the PLMN to which the second SEPP device belongs through the first signaling message. It should be noted that this embodiment does not limit the specific service type of the roaming service.
[0106] For example, the roaming service may be any one of a roaming registration service, a roaming deregistration service, and a roaming location discovery service.
[0107] The roaming registration service refers to the UE in the PLMN belonging to the first SEPP device moving to the PLMN to which the second SEPP device belongs. The first signaling message is used to request that the UE be registered in the PLMN of the second SEPP so that the UE can use the roaming service of the PLMN to which the second SEPP device belongs.
[0108] The roaming deregistration service means that the UE deregisters from the PLMN to which the second SEPP device belongs and no longer uses the roaming service of the PLMN to which the second SEPP device belongs.
[0109] The roaming location discovery service means that a UE belonging to a PLMN of a first SEPP moves to a PLMN to which a second SEPP device belongs. The first signaling message is used to request the second SEPP device to send the location information of the UE.
[0110] There is no limitation on the execution sequence between step 401 and step 402 in this embodiment.
[0111] Step 403: The first SEPP device sends a roaming request message to the IPX device.
[0112] The roaming request message shown in this embodiment is a roaming message used to request a roaming service from the second SEPP.
[0113] Specifically, the first signaling message is a next-generation Hypertext Transfer Protocol over Secure / 2 (HTTPS / 2) message. The first SEPP device may convert the first signaling message into a roaming request message that can be transmitted via an N32f interface. The roaming request message complies with the N32f interface protocol, so that the roaming request message can be transmitted via the N32f interface.
[0114] The following describes how the first SEPP device converts the first signaling message into a roaming request message:
[0115] When the first SEPP device receives the first signaling message from the first NF, the first SEPP device may convert the first signaling message into a roaming request message. Specifically, the roaming request message includes at least the encrypted first signaling message, the address of the second SEPP device, and the N32f context identifier.
[0116] Specifically, the first SEPP device may encrypt the first signaling message using a target shared key (referred to as shared key) to generate the roaming request message. The target shared key is described below:
[0117] In this embodiment, the first SEPP device and the second SEPP device call a transport layer security (TLS) protocol stack to establish a TLS link between the first SEPP device and the second SEPP device.
[0118] When a TLS link is established between the first SEPP device and the second SEPP device, the first SEPP device and the second SEPP device can use the TLS link to conduct secure communication between them, thereby establishing an N32c link and an N32f link between the first SEPP device and the second SEPP device. The specific process of establishing the N32c link and the N32f link is shown in step 401 and is not described in detail here.
[0119] After the TLS link is successfully established, the first SEPP device and the second SEPP device derive a target shared key through the TLS link. The target shared key is used to protect the transmission of related messages on the N32f link.
[0120] In this embodiment, when an N32f link is established between a first SEPP device and a second SEPP device, the first SEPP device and the second SEPP device each establish an N32f context. The N32f context stored by the first SEPP device includes at least a correspondence between an N32f context identifier, the target shared key, and the address of the second SEPP device. The N32f context stored by the second SEPP device includes at least a correspondence between an N32f context identifier, the target shared key, and the address of the first SEPP device.
[0121] Based on the N32f context, the first SEPP device and the second SEPP device can exchange messages through the N32f link.
[0122] The corresponding relationship shown in this embodiment can be saved or recorded in the form of a functional relationship, a table, a mapping relationship, etc.
[0123] When the second SEPP device receives the N32f context identifier, the second SEPP device may decrypt the encrypted first signaling message using the target shared key corresponding to the N32f context identifier to obtain the first signaling message.
[0124] In the case that the first SEPP device has obtained the roaming request message, the first SEPP device sends the roaming request message to the second SEPP device in the following manner.
[0125] 1) If the N32f link between the first SEPP device and the second SEPP device includes an IPX device, the first SEPP device sends the roaming request message to the IPX device through the N32f interface.
[0126] Specifically, the first SEPP device pre-stores the address of the IPX device, and the first SEPP device can send the roaming request message to the IPX device having the IPX address.
[0127] The IPX device sends the roaming request message to the second SEPP device having the address of the second SEPP device according to the address of the second SEPP device included in the roaming request message.
[0128] 2) If the N32f link between the first SEPP device and the second SEPP device includes multiple IPX devices, e.g. Figure 1 As shown in the example, the N32f link includes two IPX devices, namely IPX device 105 and IPX device 106. The first SEPP device sends the roaming request message to the IPX device 105 connected to the first SEPP device via the N32f interface.
[0129] The IPX device 106 determines that the next-hop IPX device for sending the roaming request message to the second SEPP device is the IPX device 106 based on the address of the second SEPP device included in the roaming request message. Then, the IPX device 105 can send the roaming request message to the IPX device 106 .
[0130] The IPX device 106 sends the roaming request message to the second SEPP device having the address of the second SEPP device through the address of the second SEPP device included in the roaming request message.
[0131] The specific format of the roaming request message is described below. It should be noted that the description of the format of the roaming request message in this embodiment is an optional example and is not limiting.
[0132] The roaming request message shown in this embodiment mainly consists of two parts: a request header and a request body.
[0133] The request header includes at least the HTTP / 2 protocol version used for interactive messages between the first SEPP device and the second SEPP device. The request body includes the above roaming request message.
[0134] Step 404: The IPX device sends a roaming request message to the second SEPP device.
[0135] Step 405 : The second SEPP device determines whether it can process the roaming request message. If so, execute step 406 ; if not, execute step 407 .
[0136] Specifically, if the second SEPP device determines that the received roaming request message satisfies at least one of the following conditions, the second SEPP device may determine that the second SEPP device cannot process the roaming request message:
[0137] The second SEPP device cannot decrypt the roaming request message, the second SEPP device fails to check the integrity of the roaming request message, the second SEPP device fails to check the integrity of the modified block of the roaming request message, the second SEPP device fails to apply the JSON patch program to the modified block of the roaming request message, or the second SEPP device fails to reconstruct the HTTP / 2 message based on the roaming message.
[0138] The inability of the second SEPP device to decrypt the roaming request message may be that the second SEPP device obtains a target shared key corresponding to the N32f context identifier according to the N32f context identifier included in the roaming request message, and then decrypts the encrypted first signaling message using the target shared key. If the second SEPP determines that the encrypted first signaling message cannot be decrypted based on the shared key, it is determined that the second SEPP device cannot decrypt the roaming request message.
[0139] The second SEPP device failing to detect the integrity of the roaming request message may be that the second SEPP device fails to detect the integrity of the roaming request message, and then determines that the roaming request message has been tampered with.
[0140] The failure of the second SEPP device to perform integrity check on the modified block of the roaming request message specifically means that the modified block of the roaming request message is a portion of the roaming request message that has been changed. The second SEPP device fails to perform integrity check on the modified block of the roaming request message, and determines that the modified block of the roaming request message has been tampered with.
[0141] The failure of the second SEPP device to reconstruct the HTTP / 2 message based on the roaming request message specifically means that, in this embodiment, in order to enable the PLMN to which the second SEPP device belongs to provide the roaming service requested by the roaming request message from the first SEPP device, the second SEPP device may reconstruct the roaming request message into an HTTP / 2 message so that the second NF belonging to the second PLMN can process the second signaling message to provide the roaming service requested by the first SEPP device. Therefore, if the second SEPP device cannot successfully reconstruct the roaming request message into an HTTP / 2 message, the second SEPP device determines that the reconstruction of the HTTP / 2 message has failed.
[0142] Step 406: The second SEPP device sends the second signaling message to the second NF.
[0143] If the second SEPP device is capable of processing the roaming request message, the second SEPP device may obtain the second signaling message and send the second signaling message to the second NF, so that the second NF performs the corresponding roaming service according to the second signaling message.
[0144] For example, if the second signaling message is used to register the UE with the second PLMN, the second NF can register the UE with the second PLMN so that the second PLMN can provide roaming services to the UE. For another example, if the second signaling message is used to deregister the UE from the second PLMN to which the second NF belongs, the second NF can deregister the UE from the second PLMN, so that the second PLMN no longer provides roaming services to the UE.
[0145] Step 407: The second SEPP device sends a first roaming response message to the IPX device.
[0146] In this embodiment, when the second SEPP device determines that it cannot process the roaming request message, the second SEPP device may generate a first roaming response message, which is a feedback message indicating that the second SEPP device cannot process the roaming request message.
[0147] Specifically, the first roaming response message includes a first indication message, where the first indication message is used to indicate an event that the second SEPP device cannot process the roaming request message.
[0148] This embodiment does not limit the specific content of the first indication message, as long as the first SEPP device and the second SEPP device have both determined that the first indication message is used to indicate an event in which the roaming request message cannot be processed.
[0149] To reduce the complexity of indicating to the first SEPP device that the second SEPP device cannot process the roaming request message and improve efficiency, this embodiment shows that the first roaming response message is transmitted through the N32f link between the first SEPP device and the second SEPP device. It can be seen that the first roaming response message shown in this embodiment satisfies the N32f interface protocol, so that the first roaming response message can be transmitted through the N32f interface.
[0150] In this embodiment, the second SEPP device returns the first roaming response message through the original path of receiving the roaming request message, for example, Figure 1 As shown, if the first SEPP device 101 sends the roaming request message to the second SEPP device 102 through the IPX device 105 and the IPX device 106 in sequence, the second SEPP device 102 returns the first roaming response message to the first SEPP device 101 through the IPX device 106 and the IPX device 105 in sequence.
[0151] Specifically, the second SEPP device determines a target IPX device, wherein the target IPX device is the IPX device that sends the roaming request message to the second SEPP device. In this embodiment, the target IPX device is the IPX device 106.
[0152] When the second SEPP device sends the first roaming response message to the first SEPP device, the first roaming response message can be sent to the target IPX device, thereby returning the first roaming response message to the first SEPP device. Therefore, when the target IPX device (i.e., IPX device 106) receives the first roaming response message, the IPX device 106 can send the first roaming response message to the IPX device 105, and the IPX device 105 can send the first roaming response message to the first SEPP device.
[0153] Step 408: The IPX device sends a first roaming response message to the first SEPP device.
[0154] When the first SEPP device receives the first roaming response message, the first SEPP device may determine, according to the first indication message included in the first roaming response message, that the second SEPP device cannot process the roaming request message.
[0155] Optionally, when the first roaming response message includes the second indication message, the first SEPP device may perform corresponding processing. For example, if the second indication message is used to indicate that the second SEPP device cannot decrypt the roaming request message, the first SEPP device may re-encrypt the first signaling message based on the shared key to regenerate the roaming request message, and send the regenerated roaming request message to the second SEPP via the N32f link.
[0156] Step 409: The second SEPP sends a first indication message to the second NF.
[0157] Step 409 shown in this embodiment is an optional step. If this step is performed, this embodiment does not limit the execution sequence between step 409 and step 407.
[0158] When the second NF receives the first indication message, it can be determined that the second SEPP device cannot process the roaming request message from the first SEPP device, and further determines that the second SEPP device cannot implement the roaming service with the first SEPP device.
[0159] Optionally, the second SEPP may further send a second indication message to the second NF. The second indication message is used to indicate the reason why the second SEPP device cannot process the roaming request message. The second NF can determine the specific reason why the second SEPP device cannot process the roaming request message based on the second indication message.
[0160] Step 410: The first SEPP device sends a first indication message to the first NF.
[0161] This step is optional. Specifically, the first SEPP device may obtain the first indication message from the first roaming response message and convert the format of the first indication message into an https / 2 message so that the first NF can receive and process the first indication message.
[0162] Optionally, if the first roaming response message includes a second indication message, the first SEPP device may also send the second indication message to the first NF. For the specific sending process, refer to the process of sending the first indication message, which will not be described in detail.
[0163] Using the communication method described in this embodiment, if the second SEPP device determines that it cannot process the roaming request message from the first SEPP device, the second SEPP device may send a first roaming response message to the first SEPP device via the N32f link, indicating that the second SEPP device cannot process the roaming request message. Because the first roaming response message is transmitted via the N32f link, the transmission of the first roaming response message does not require the use of N32c link resources. The roaming request message and the first roaming response message can be transmitted via the N32f link, reducing the difficulty for the second SEPP device to indicate to the first SEPP device that it cannot process the roaming request message, thereby improving efficiency.
[0164] Furthermore, by sending the first roaming response message to the first SEPP device through the IPX device included in the N32f link, the utilization rate of each IPX device can be improved, and each IPX device on the N32f link can be fully utilized, thereby avoiding the ineffective occupation of system resources by the IPX device during the process of transmitting the first roaming response message through the N32c link, thereby improving the utilization efficiency of system resources and avoiding waste of system resources.
[0165] In this embodiment, the specific message format of the first roaming response message is not limited. As long as the first roaming response message indicates to the first SEPP device that the second SEPP device cannot process the roaming request message, the first roaming response message will be described in detail below with reference to a specific example:
[0166] Example 1
[0167] The first roaming response message shown in this example mainly consists of two parts: a response header and a response body.
[0168] The response header may include a status code, which consists of three decimal digits. The first decimal digit defines the status code type, and the second two digits serve as a classification. Different status codes represent different meanings. The status code included in the first roaming response message shown in this embodiment may be "200" or "400." The specific value is not limited in this embodiment.
[0169] The response body includes an event indicating that the second SEPP device cannot process the roaming request message.
[0170] Optionally, to facilitate the first SEPP in determining the reason why the second SEPP device cannot process the roaming request message, the response header or response body may further include a second indication message, where the second indication message indicates the reason why the second SEPP device cannot process the roaming request message. This embodiment is illustratively described using the example where the response body includes the second indication message.
[0171] Specifically, the second SEPP device may predetermine the correspondence between different fields and the reason why the second SEPP device cannot process the roaming request message. This embodiment does not limit the content included in each field, as long as the first SEPP device and the second SEPP device can mutually agree on the reason for not being able to process the roaming request message indicated by each field.
[0172] For example, if the second SEPP device determines that the reason for not being able to process the roaming request message is that the roaming request message cannot be decrypted, the second SEPP device obtains a first field indicating that the roaming request message cannot be decrypted, and can set the first field in the second indication message.
[0173] For example, if the second SEPP device determines that the reason for not being able to process the roaming request message is the failure of the integrity check of the modified block of the roaming request message, then the second SEPP device obtains a second field for indicating the failure of the integrity check of the modified block of the roaming message, and the second SEPP device can set the second field in the second indication message.
[0174] Example 2
[0175] The format of the first roaming response message can be pre-agreed between the first SEPP device and the second SEPP device shown in this embodiment, and the first roaming response message can be transmitted via the N32f link. For the description of the specific content of the first roaming response message, please refer to the above description and will not be described in detail.
[0176] The following combination Figure 5 Another embodiment of the communication method provided by the present application is described as shown in FIG. Figure 4 The illustrated embodiment illustrates how, when the second SEPP device is unable to process the roaming request message, the second SEPP device indicates to the first SEPP the event that the roaming request message cannot be processed. Figure 5 The illustrated embodiment illustrates how, when the second SEPP device is able to successfully process the roaming request message, if the first SEPP device is unable to process the roaming response message, the first SEPP device indicates to the second SEPP device that the first SEPP device is unable to process the roaming response message. The details are as follows:
[0177] Step 501: An N32c link and an N32f link are established between a first SEPP device and a second SEPP device.
[0178] Step 502: The first NF sends a first signaling message to the first SEPP device.
[0179] Step 503: The first SEPP device sends a roaming request message to the IPX device.
[0180] Step 504: The IPX device sends a roaming request message to the second SEPP device.
[0181] For details on the specific execution process of steps 501 to 504 shown in this embodiment, please refer to Figure 4 As shown in step 401 to step 404, the specific execution process is not repeated in this embodiment.
[0182] Step 505: The second SEPP device sends the second signaling message to the second NF.
[0183] For details on the execution process of step 505 shown in this embodiment, please refer to Figure 4 As shown in step 406, the specific execution process is not repeated in this embodiment.
[0184] Step 506: The second SEPP device sends a second roaming response message to the IPX device.
[0185] Step 507: The IPX device sends a second roaming response message to the first SEPP device.
[0186] In this embodiment, the second roaming response message is a message used to implement roaming between the first SEPP device and the second SEPP device.
[0187] The second SEPP device can successfully process the roaming request message from the first SEPP device. Therefore, the second roaming response message shown in this embodiment includes a third indication message. The third indication message is used to indicate that the second SEPP device can successfully process the roaming request message.
[0188] The second roaming response message shown in this embodiment includes the third indication message. For details on the process in which the second SEPP device sends the second roaming response message to the first SEPP device shown in this embodiment, see Figure 4 The process of the second SEPP device sending the first roaming response message to the first SEPP device shown in step 408 is not described in detail.
[0189] For details on the specific format of the second roaming response message in this embodiment, please refer to Figure 4 The embodiment shown is not described in detail in this embodiment.
[0190] Step 508 : The first SEPP device determines whether it can process the second roaming response message. If so, execute step 509 ; if not, execute step 510 .
[0191] Specifically, if the first SEPP device determines that the received second roaming response message satisfies at least one of the following conditions, the first SEPP device may determine that the first SEPP device cannot process the roaming request message:
[0192] The first SEPP device cannot decrypt the second roaming response message, the first SEPP device fails to check the integrity of the second roaming response message, the first SEPP device fails to check the integrity of the modified block of the second roaming response message, the first SEPP device fails to apply the JSON patch program to the modified block of the second roaming response message, or the first SEPP device fails to reconstruct the HTTP / 2 message based on the roaming message. For detailed descriptions of each unhandled situation, see Figure 4 The embodiment shown is not described in detail in this embodiment.
[0193] Step 509: The first SEPP device sends a third indication message to the first NF.
[0194] If the first SEPP device is capable of processing the second roaming response message, the first SEPP device can obtain the third indication message and send the third indication message to the first NF, so that the first NF determines that the second NF can implement the roaming service requested by the first NF. For a description of the roaming service, please see Figure 4 The embodiments shown are not described in detail.
[0195] Step 510: The first SEPP device sends a third roaming response message to the IPX device.
[0196] In this embodiment, if the first SEPP device determines that it cannot process the second roaming response message, the first SEPP device may generate a third roaming response message, where the third roaming response message includes a fourth indication message, where the fourth indication message is used to indicate an event that the first SEPP device cannot process the second roaming response message.
[0197] For details on the format of the third roaming response message, please refer to Figure 4 The format of the first roaming response message shown is not described in detail.
[0198] Step 511: The IPX device sends a third roaming response message to the second SEPP device.
[0199] In this embodiment, the first SEPP device returns the third roaming response message along the original path of receiving the second roaming response message, for example, Figure 1As shown, if the second SEPP device 102 sends the second roaming response message to the first SEPP device 101 through the IPX device 106 and the IPX device 105 in sequence, the first SEPP device 101 sends the third roaming response message to the second SEPP device 102 through the IPX device 105 and the IPX device 106 in sequence.
[0200] Specifically, the first SEPP device stores a correspondence between the N32f context identifier, the target shared key, and the address of the second SEPP device. The first SEPP device can determine the address of the corresponding second SEPP device based on the N32f context identifier included in the second roaming response message. The first SEPP device sends the third roaming response message to the second SEPP device based on the address of the second SEPP device.
[0201] It can be seen that when the second SEPP device receives the third roaming response message, it can be determined that the first SEPP device cannot process the second roaming message.
[0202] For a description of the content and format of the fourth instruction message, see Figure 4 The description of the first indication message in the illustrated embodiment is omitted for clarity.
[0203] To reduce the complexity of indicating to the second SEPP device that the first SEPP device cannot process the second roaming response message and improve efficiency, this embodiment shows that the third roaming response message is transmitted through the N32f link between the first SEPP device and the second SEPP device. It can be seen that the third roaming response message shown in this embodiment satisfies the N32f interface protocol, so that the third roaming response message can be transmitted through the N32f interface.
[0204] Steps 510 to 511 shown in this embodiment are optional steps, that is, when the first SEPP device determines that the second roaming response message cannot be processed, the first SEPP device may send a third indication message to the first NF instead of sending the third roaming response message to the second SEPP device.
[0205] Step 512: The second SEPP sends a fourth indication message to the second NF.
[0206] This step is optional. Specifically, the second SEPP device parses the fourth indication message from the third roaming response message and converts the format of the fourth indication message into an https / 2 message so that the second NF can receive and process the fourth indication message. For the specific processing process, please refer to Figure 4 The process of the first NF processing the first indication message is not described in detail in this embodiment.
[0207] Using the communication method described in this embodiment, if the first SEPP device determines that it cannot process the second roaming response message from the second SEPP device, the first SEPP device may send a third roaming response message to the second SEPP device via the N32f link, indicating that the first SEPP device cannot process the second roaming response message. Because the third roaming response message is transmitted via the N32f link, transmission of the third roaming response message does not require the use of N32c link resources; the third roaming response message can be transmitted via the N32f link. This reduces the difficulty for the first SEPP device to indicate to the second SEPP device that it cannot process the second roaming response message, thereby improving efficiency.
[0208] Furthermore, by sending the third roaming response message to the second SEPP device through the IPX device included in the N32f link, the utilization rate of each IPX device can be improved, and each IPX device on the N32f link can be fully utilized. This avoids the ineffective occupation of system resources by the IPX device during the process of transmitting the third roaming response message through the N32c link, thereby improving the utilization efficiency of system resources and avoiding waste of system resources.
[0209] based on Figure 4 and Figure 5 The embodiment shown below is combined with Figure 6 The following describes how to reduce the overhead of the communication system:
[0210] Step 601: An N32c link and an N32f link are established between a first SEPP device and a second SEPP device.
[0211] For details on the specific execution process of step 601 shown in this embodiment, please refer to Figure 4 As shown in step 401, the specific execution process is not repeated here.
[0212] Step 602: The first SEPP device sends a release request message to the second SEPP device.
[0213] Specifically, in this embodiment, when an N32f link has been successfully established between the first SEPP device and the second SEPP device, Figure 4 and Figure 5 As can be seen from the illustrated embodiment, the error reporting process can be performed between the first SEPP device and the second SEPP device based on the N32f link. To reduce the overhead of the communication system, the N32c link can be released in this embodiment.
[0214] In order to release the N32c link, the first SEPP device sends a release request message to the second SEPP device through the N32c link. The release request message is used to request the second SEPP device to release the N32c link.
[0215] Optionally, the release request message includes at least the address of the second SEPP device and a fifth indication message, wherein the fifth indication message is used to indicate an event that the second SEPP device releases the N32c link.
[0216] Step 603: The second SEPP device releases the N32c link according to the release request message.
[0217] In this embodiment, when the second SEPP device receives the release request message, it can determine to release the N32c link according to the fifth indication message.
[0218] Specifically, the second SEPP device releases the N32c link according to the release request message and clears resources related to the N32c link on the second SEPP device side. After the N32c link is released, the TLS link is also released.
[0219] Step 604: The first SEPP device releases the N32c link.
[0220] This embodiment does not limit the execution sequence between step 604 and step 602. When the N32f link is successfully established, the first SEPP device may release the connection relationship between the TLS link and the N32c link, and clear resources related to the N32c link on the second SEPP device to release the N32c link.
[0221] Step 605: The first NF sends a first signaling message to the first SEPP device.
[0222] This embodiment does not limit the execution sequence of step 605 and steps 602 to 604 .
[0223] Step 606: The first SEPP device sends a roaming request message to the IPX device.
[0224] Step 607: The IPX device sends a roaming request message to the second SEPP device.
[0225] Step 608: The second SEPP device determines whether it can process the roaming request message. If so, execute step 609; if not, execute step 610.
[0226] Step 609: The second SEPP device sends the second signaling message to the second NF.
[0227] Step 610: The second SEPP device sends a first roaming response message to the IPX device.
[0228] Step 611: The IPX device sends a first roaming response message to the first SEPP device.
[0229] Step 612: The second SEPP sends a first indication message to the second NF.
[0230] Step 613: The first SEPP device sends a first indication message to the first NF.
[0231] For details on the specific execution process of steps 605 to 613 shown in this embodiment, please refer to Figure 4 As shown in step 402 to step 410, the specific details are not repeated in this embodiment.
[0232] It can be seen that by adopting the method shown in this embodiment, the error reporting process can be performed between the first SEPP device and the second SEPP device through the N32f link. Then, when the N32f link is successfully established, the first SEPP device and the second SEPP device can release the N32c link, thereby effectively saving the overhead of maintaining the long connection of the N32c link.
[0233] The following combination Figure 7 As shown, the structure of the SEPP device shown in the embodiment for executing the above method is described:
[0234] The SEPP device 700 specifically includes a receiving unit 701 , a processing unit 702 and a sending unit 703 .
[0235] If the SEPP device 700 is used as the first SEPP device, then,
[0236] The receiving unit 701 is configured to receive a roaming message from an IP exchange operator IPX device, where the roaming message is used to implement a roaming service between the first SEPP device and the second SEPP device;
[0237] The processing unit 702 is configured to determine that the roaming message cannot be processed;
[0238] The sending unit 703 is configured to send a feedback message to the IPX device, where the feedback message is used to indicate that the roaming message cannot be processed.
[0239] The receiving unit 701, the processing unit 702 and the sending unit 703 cooperate with each other to implement the communication method provided in the above embodiment performed by the first SEPP device. The specific implementation process and beneficial effects can refer to the description of the above aspects.
[0240] Optionally, the processing unit 702 is configured to, when the first SEPP device and the second SEPP device have exchanged a target shared key via an N32c link, cause the first SEPP device to release the N32c link, where the target shared key is used to implement secure communication between the first SEPP device and the second SEPP device.
[0241] Optionally, the sending unit 703 is configured to send a roaming request message to the IPX device, the roaming request message being used to request a roaming service from the second SEPP device, the roaming request message including the address of the second SEPP device, and the roaming response message being generated by the second SEPP device according to the roaming request message.
[0242] Optionally, the receiving unit 701 is configured to obtain the feedback message, where the feedback message includes the address of the second SEPP device, and the feedback message is used to indicate that the first SEPP device cannot process the roaming response message.
[0243] Optionally, the processing unit 702 is configured to determine that the first SEPP device cannot process the roaming message if, upon determining that the roaming message satisfies at least one of the following conditions:
[0244] Unable to decrypt the roaming message, failed to check the integrity of the roaming message, failed to check the integrity of the modified block of the roaming message, failed to apply the JSON patch program to the modified block of the roaming message, or failed to reconstruct the next generation Hypertext Transfer Protocol Security HTTP / 2 message based on the roaming message.
[0245] Optionally, the feedback message is further used to indicate the reason why the first SEPP device cannot process the roaming message.
[0246] Optionally, the feedback message includes an N32f context identifier, where the N32f context identifier is used to indicate a target shared key for decrypting the feedback message.
[0247] Optionally, the sending unit 703 is further configured to send the feedback message to the network function NF.
[0248] If the SEPP device 700 is used as the second SEPP device, then,
[0249] The sending unit 703 is used to send a roaming message to the IP exchange operator IPX device, where the roaming message is used to implement a roaming service between the first SEPP device and the second SEPP device;
[0250] The receiving unit 701 is configured to receive a feedback message from the IPX device, where the feedback message is used to indicate that the first SEPP device cannot process the roaming message.
[0251] The receiving unit 701, the processing unit 702 and the sending unit 703 cooperate with each other to implement the communication method provided in the above embodiment performed by the second SEPP device. The specific implementation process and beneficial effects can refer to the description of the above aspects.
[0252] Optionally, the processing unit 702 is configured to release the N32c link when a target shared key has been exchanged between the first SEPP device and the second SEPP device via the N32c link, where the target shared key is used to implement secure communication between the first SEPP device and the second SEPP device.
[0253] Optionally, the receiving unit 701 is configured to receive a roaming request message from the IPX device, where the roaming request message is used to request a roaming service from the second SEPP device, and the roaming request message includes an address of the second SEPP device;
[0254] The processing unit 702 is configured to generate a roaming response message according to the roaming request message, where the roaming response message is the roaming message.
[0255] Optionally, the feedback message includes the address of the second SEPP device, and the feedback message is used to indicate that the first SEPP device cannot process the roaming response message.
[0256] Optionally, the roaming message is a roaming request message for requesting a roaming service from the first SEPP device, and the roaming message includes an address of the first SEPP device.
[0257] Optionally, the feedback message is further used to indicate the reason why the first SEPP device cannot process the roaming message.
[0258] The reason is at least one of the following:
[0259] Unable to decrypt the roaming message, failed to check the integrity of the roaming message, failed to check the integrity of the modified block of the roaming message, failed to apply the JSON patch program to the modified block of the roaming message, or failed to reconstruct the next generation Hypertext Transfer Protocol Security HTTP / 2 message based on the roaming message.
[0260] Optionally, the processing unit 702 is configured to obtain a target shared key corresponding to the N32f context identifier; and decrypt the feedback message using the target shared key.
[0261] The following combination Figure 8 and Figure 9 The structure of the communication device provided by this application is described as shown in FIG. Figure 8 This is an example diagram of the structure of the communication device provided in an embodiment of the present application. Figure 9 This is an example diagram of the interface of the communication board 830 in the communication device provided in an embodiment of the present application.
[0262] The communication device primarily includes a cabinet 800 and a communication board 830 mounted therein. The communication board 830 primarily comprises a circuit board, chips mounted thereon, and other electronic components, and provides communication services. The number of communication boards 830 can be increased or decreased based on actual needs, and this embodiment does not limit the specific number.
[0263] In addition, the cabinet 800 also includes a fan frame 820 for installing cooling fans and a cabinet management board 810 for managing the cabinet. The cabinet management board 810 is used to manage the working status of the entire cabinet, such as the power-on status, operating temperature, and alarm status of the cabinet.
[0264] like Figure 9 As shown, the communication board 830 includes multiple input / output interfaces, such as a display interface 832 for connecting to an external display, network interfaces 831 and 833 for connecting to a communication network, and a Universal Serial Bus (USB) interface 834. The network interface 833 may be an Ethernet interface, and the network interface 831 may be a fiber optic interface.
[0265] In addition, the communication board 830 further includes a power interface 836 for connecting to a power source and an expansion slot 835 for expanding the functions of the communication board 830 .
[0266] The communication device described above implements different functions by installing different communication boards 830. For example, it can implement the functions of the first SEPP device and the second SEPP device in the embodiments of the present application. The communication board 830 is equipped with control components such as a general-purpose processor, control chip, and logic circuit. The communication board 830 may also be equipped with memory such as a memory chip. These processors and memories can cooperate with relevant communication interfaces to execute some or all of the operations of any method that can be executed by the first or second SEPP device in the embodiments of the present application.
[0267] The following combination Figure 10 As shown, the structure of the SEPP device provided by this application is described from the perspective of physical hardware:
[0268] The SEPP device provided in this embodiment may be the first SEPP device or the second SEPP device shown in the above method embodiment. For the specific process of executing the communication method shown in this application, please refer to the above method embodiment, and the details will not be repeated here.
[0269] The SEPP device may be a general-purpose computer, which includes a processor 1001 , a memory 1002 , a bus 1003 , an input device 1004 , an output device 1005 , and a network interface 1006 .
[0270] Specifically, the memory 1002 may include computer storage media in the form of volatile and / or nonvolatile memory, such as read-only memory and / or random access memory. The memory 1002 may store an operating system, application programs, other program modules, executable code, and program data.
[0271] An input device 1004, such as a keyboard or pointing device, such as a mouse, trackball, touchpad, microphone, joystick, game pad, satellite TV dish, scanner, or similar device, can be used to input commands and information to the SEPP device. These input devices can be connected to the processor 1001 via the bus 1003.
[0272] The output device 1005 can be used to output information from the SEPP device. In addition to the monitor, the output device 1005 can also be other peripheral output devices, such as speakers and / or printing devices. These output devices can also be connected to the processor 1001 through the bus 1003.
[0273] The SEPP device can be connected to a communication network, such as a local area network (LAN), via the network interface 1006. In a networked environment, the computer executable instructions stored in the SEPP device can be stored in a remote storage device, rather than being limited to local storage.
[0274] When the processor 1001 in the SEPP device executes the executable code or application stored in the memory 1002, the SEPP device may perform the method operations on the first SEPP device side in the above method embodiment, or may perform the method operations on the second SEPP device side in the above method implementation. The specific execution process is described in the above method embodiment and is not repeated here.
[0275] The above-mentioned computer can be implemented by actual hardware or virtualized hardware, such as a virtual machine. A virtual machine provides virtual CPU, storage, network and other resources, which are obtained by virtualizing the underlying hardware resources.
[0276] At this point, the software package corresponding to the SEPP device can be deployed on a virtual machine. The SEPP device can be called a virtualized network function (VNF) device. These NFV devices can have the same functional behavior and external interfaces as traditional network function devices, for example, an N32-F interface.
[0277] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A communication method, characterized in that: The method comprises: The first security and border proxy SEPP device sends a roaming request message to the IP exchange operator IPX device, where the roaming request message is used to request a roaming service from the second SEPP device, and the roaming request message includes an address of the second SEPP device; The first SEPP device receives a roaming message from the IPX device, where the roaming message is a roaming response message generated by the second SEPP device according to the roaming request message, and is used to implement a roaming service between the first SEPP device and the second SEPP device; The first SEPP device determines that the roaming message satisfies at least one of the following conditions, and then determines that the first SEPP device cannot process the roaming message: Failure to decrypt the roaming message, failure to apply a JSON patch to a modified block of the roaming message, or failure to reconstruct an HTTP / 2 message based on the roaming message; The first SEPP device sends a feedback message to the IPX device through the N32f link, where the feedback message is used to indicate that the first SEPP device cannot process the roaming message and further indicates a reason why the first SEPP device cannot process the roaming message.
2. The method according to claim 1, characterized in that The method further comprises: In a case where the first SEPP device and the second SEPP device have exchanged a target shared key via the N32c link, the first SEPP device releases the N32c link, and the target shared key is used to implement secure communication between the first SEPP device and the second SEPP device.
3. The method according to claim 1, characterized in that The method further comprises: The first SEPP device determines the address of the second SEPP device according to the roaming message, the feedback message includes the address of the second SEPP device, and the feedback message is used to indicate that the first SEPP device cannot process the roaming response message.
4. The method according to claim 1 or 2, characterized in that The first SEPP device determining that the first SEPP device cannot process the roaming message further includes: The first SEPP device determines that the roaming message satisfies at least one of the following conditions, and then determines that the first SEPP device cannot process the roaming message: The integrity check of the roaming message fails, and the integrity check of the modified block of the roaming message fails.
5. The method according to claim 1 or 2, characterized in that The feedback message includes an N32f context identifier, where the N32f context identifier is used to indicate a target shared key for decrypting the feedback message.
6. The method according to claim 1 or 2, characterized in that After the first SEPP device determines that it cannot process the roaming message, the method further includes: The first SEPP device sends the feedback message to the network function NF.
7. A communication method, characterized in that: The method comprises: The second security and border proxy SEPP device receives a roaming request message from an IP exchange operator IPX device, where the roaming request message is used to request a roaming service from the second SEPP device, and the roaming request message includes an address of the second SEPP device; The second SEPP device receives the signaling message sent by the network function device NF, and sends a roaming message to the IPX device, where the roaming message is a roaming response message generated by the second SEPP device according to the roaming request message, and is used to implement a roaming service between the first SEPP device and the second SEPP device. The roaming message includes the signaling message, and the roaming response message is the roaming message. The second SEPP device receives a feedback message from the IPX device through the N32f link, where the feedback message indicates that the first SEPP device cannot process the roaming message. The feedback message further indicates a reason why the first SEPP device cannot process the roaming message, where the reason is at least one of the following: Failure to decrypt the roaming message, failure to apply a JSON patch to a modified block of the roaming message, or failure to reconstruct an HTTP / 2 message from the roaming message.
8. The method according to claim 7, characterized in that The method further comprises: In a case where the first SEPP device and the second SEPP device have exchanged a target shared key via an N32c link, the second SEPP device releases the N32c link, and the target shared key is used to implement secure communication between the first SEPP device and the second SEPP device.
9. The method according to claim 7 or 8, characterized in that The feedback message includes the address of the second SEPP device, and the feedback message is used to indicate that the first SEPP device cannot process the roaming response message.
10. The method according to claim 7 or 8, characterized in that The reason further includes at least one of a failure in integrity check of the roaming message and a failure in integrity check of a modification block of the roaming message.
11. The method according to claim 7 or 8, characterized in that The feedback message includes an N32f context identifier. After the second SEPP device receives the feedback message from the IPX device, the method further includes: The second SEPP device obtains a target shared key corresponding to the N32f context identifier; The second SEPP device decrypts the feedback message using the target shared key.
12. A security and perimeter protection proxy SEPP device, characterized in that, include: At least one processor and a memory coupled to each other, wherein the memory stores computer program code, and the processor calls and executes the computer program code in the memory, so that the SEPP device performs the method according to any one of claims 1 to 11.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 11 is implemented.
14. A communication system, characterized in that: Including the first security and border agent SEPP equipment and IPX equipment, The IPX device is used to send a roaming request message to the second SEPP device, where the roaming request message is used to request a roaming service from the second SEPP device; The IPX device is further configured to send a roaming message to the first SEPP device, where the roaming message is a roaming response message generated by the second SEPP device according to the roaming request message, and is configured to implement a roaming service between the first SEPP device and the second SEPP device; The first SEPP device is configured to perform the method according to any one of claims 1 to 6.
15. A communication system, characterized in that: include: A network function device NF and a second security and border protection proxy SEPP device, wherein the network function device NF is configured to execute the step of sending a signaling message to the second SEPP device; The second SEPP device is configured to perform the method according to any one of claims 7 to 11.
Citation Information
Patent Citations
Secure communication method, related device and system
CN113873510A
Error handling framework for security management in a communication system
WO2019220006A1