Session request processing method, satellite access gateway device, and storage medium

By adding I-SBC capabilities and PEP components to the satellite access gateway equipment, optimizing protocol conversion and using the improved UDP protocol, the high delay and high code error problems of comprehensive voice services in satellite links are solved, low latency and high reliability communication effects are achieved, and the QoS needs of comprehensive voice services are met.

CN114679211BActive Publication Date: 2025-05-09CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011547894.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-24
Publication Date
2025-05-09
Estimated Expiration
2040-12-24

AI Technical Summary

Technical Problem

The prior art cannot effectively support the implementation of integrated voice services in satellite links, especially in ensuring QoS and solving high latency and high code error problems.

Method used

By adding support for I-SBC capabilities in satellite access gateway devices and introducing PEP components based on integrated voice service models, optimizing protocol conversion and data processing flow, an improved UDP protocol is adopted to improve communication reliability and low latency performance.

Benefits of technology

It realizes supporting comprehensive voice services in the integrated satellite and IMS network, improves the network's low latency and high reliability, and meets the QoS needs of comprehensive voice services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114679211B_ABST
    Figure CN114679211B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention provides a session request processing method, a satellite access gateway device, and a readable storage medium, which belong to the field of communications. The session request processing method is applied to a satellite access gateway device and includes: receiving a session request initiated by a terminal device UE; judging whether the session request initiated by the UE comes from a trusted network or there is a malicious attack; and when judging that the session request initiated by the UE is safe, sending the session request initiated by the UE to the IP Multimedia Subsystem IMS core network. This solution can effectively realize an integrated voice satellite access gateway and its architecture components that support ISBC capabilities and can realize integrated voice services in a satellite and IMS fusion network, and adds support for I‑SBC capabilities in the satellite access gateway to realize the PEP component's guarantee of QoS for integrated voice services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of communications, and specifically to a combination of satellite access and an IMS core network, and in particular to a session request processing method, a satellite access gateway device, and a readable storage medium. Background Art

[0002] Traditional satellite gateway technology does not study the realization of integrated voice services in satellite and IMS converged networks, nor does it support I-SBC capabilities. Therefore, when facing integrated voice services, the network capabilities cannot guarantee the QoS requirements of integrated voice services. In addition, the main functions of the intelligent gateway proposed in the relevant technology include autonomously controlling the traffic operation of the equipment accessing the gateway and autonomously cutting off the data traffic of the equipment accessing the gateway, but it does not specifically target the high latency and high bit error characteristics of satellite links. In addition, the accelerator set in the gateway in the relevant technology still uses the TCP protocol for communication, which cannot effectively guarantee low latency and high reliability.

[0003] The prior art discloses a method and device for satellite communication, which is used to solve the problem in the related art of realizing communication between a satellite terminal and a mobile terminal through a mobile communication system. However, the method provided by the prior art is used to receive a short message sent by the mobile terminal through the intermediate node; and obtain a satellite short message generated by the mobile terminal from the short message, and send the satellite short message to a satellite terminal in a satellite communication network. However, there is no research on how to realize integrated voice services through satellite access, and there is no consideration of I-SBC capability support, so it is impossible to effectively guarantee the QoS required for the integrated voice services.

[0004] The prior art also discloses an intelligent gateway for a wireless sensor network, which solves the technical problem of autonomously cutting off the data traffic of network devices in arrears. However, the intelligent gateway device proposed in the prior art is mainly used to autonomously control the traffic operation of network devices accessing the gateway and autonomously cut off the data traffic of network devices. The prior art does not specifically support the I-SBC capability for integrated voice services, does not pay attention to the guarantee of high QoS for integrated voice services, and does not specifically consider the characteristics of high latency and high bit error of satellite links, and cannot effectively improve the communication capability of satellite networks.

[0005] The prior art also discloses a TCP acceleration method suitable for satellite links. However, the prior art uses the TCP protocol, and the complex confirmation mechanism and retransmission mechanism of the protocol itself cannot guarantee the low-delay transmission requirements of the integrated voice service, and the efficiency of protocol conversion is not considered in the design of the satellite gateway, and the problem of high delay and high bit error of the satellite link cannot be solved.

[0006] The prior art also discloses a satellite access gateway device, and also discloses a satellite network system based on an IP multimedia system IMS having the satellite access gateway device. However, in order to ensure consistency with the core network technical system and the scalability of future networks, the core network side of the satellite communication system in the prior art adopts an IMS architecture. Although the interconnection between satellite network users and ground core network users and between users of different satellite network systems can be achieved, the prior art still adopts the traditional satellite link TCP acceleration method, the satellite gateway accelerates TCP data, and the improved TCP protocol is still used between gateways. Summary of the invention

[0007] The purpose of the embodiment of the present invention is to provide a session request processing method implemented by a satellite access gateway device, a satellite access gateway device, and a computer-readable storage medium storing a related program for implementing the session request processing method, so as to realize an integrated voice satellite access gateway supporting I-SBC capability and its architecture components that can realize integrated voice services in a satellite and IMS fusion network, and to increase support for I-SBC capabilities in the satellite access gateway, as well as the PEP component to guarantee the QoS of the integrated voice service. In addition, the high delay and high bit error problems of the satellite link are particularly solved, and the system has the characteristics of low delay and high reliability.

[0008] In order to solve the above technical problems, the embodiment of the present invention is implemented as follows:

[0009] In a first aspect, an embodiment of the present invention provides a session request processing method, the method being applied to a satellite access gateway device, the method comprising:

[0010] Receiving a session request initiated by a terminal device UE;

[0011] Determining whether the session request initiated by the UE comes from a trusted network or whether there is a malicious attack; and

[0012] When it is determined that the session request initiated by the UE is safe, the session request initiated by the UE is sent to an IP Multimedia Subsystem IMS core network.

[0013] Optionally, the method further includes:

[0014] According to the priority decision, assigning a high priority to a session request involving an integrated voice service among the session requests initiated by the UE;

[0015] Prioritize the completion of the protocol conversion process of the session request with a high priority and put it into the cache; and

[0016] The session request after protocol conversion stored in the cache is sent to the IMS core network.

[0017] Optionally, after receiving the session request initiated by the UE, the method further includes:

[0018] completing identity authentication and address conversion of data packets contained in the session request initiated by the UE; and

[0019] An early pseudo-acknowledgement is returned to the UE.

[0020] Optionally, after receiving a true response to the session request initiated by the UE sent by the IMS, the method further includes:

[0021] If the real response is received within the specified time, the backup of the session request after protocol conversion stored in the cache is deleted; or

[0022] If the real response is not received within a specified time, the backup of the session request after protocol conversion stored in the cache is retransmitted.

[0023] Optionally, when it is determined that the session request initiated by the UE comes from a trusted network or there is a malicious attack, the method further includes:

[0024] rejecting a session request initiated by the UE; and

[0025] The session request initiated by the UE is put into a blacklist.

[0026] Optionally, the determining whether the session request initiated by the UE comes from a trusted network or whether there is a malicious attack specifically includes:

[0027] Performing message filtering on the session request initiated by the UE according to a five-tuple; and

[0028] The session request initiated by the UE in the abnormal message is judged as not coming from a trusted network or as being a malicious attack,

[0029] The five-tuple includes source IP, destination IP, transport protocol, source port, and destination port.

[0030] Optionally, when it is determined that the session request initiated by the UE is secure, sending the session request initiated by the UE to an IP Multimedia Subsystem IMS core network specifically includes:

[0031] When it is determined that the session request initiated by the UE is safe, decapsulation processing and SIP protocol header processing are performed on the message of the session request initiated by the UE; and

[0032] The processed session request is sent to the IMS core network via the Gm and Mw interfaces.

[0033] Optionally, the session request message initiated by the UE complies with the UDP protocol.

[0034] In a second aspect, an embodiment of the present disclosure provides a satellite access gateway device, including:

[0035] A first receiving module is used to receive a session request initiated by a terminal device UE; a first judging module is used to judge whether the session request initiated by the UE comes from a trusted network or there is a malicious attack; and a first sending module is used to send the session request initiated by the UE to the IP Multimedia Subsystem IMS core network when it is judged that the session request initiated by the UE is safe.

[0036] Optionally, the satellite access gateway device also includes: a priority assignment module, used to assign a high priority to the session request involving integrated voice services among the session requests initiated by the UE according to the priority decision; a protocol conversion module, used to preferentially complete the protocol conversion process of the session request with a high priority and put it into the cache; and a second sending module, used to send the session request after protocol conversion stored in the cache to the IMS core network.

[0037] Optionally, the satellite access gateway device further includes: an address conversion module, used to complete identity authentication and address conversion of the data packet contained in the session request initiated by the UE; and a pseudo response module, used to return an advance pseudo response to the UE.

[0038] Optionally, if a true response to the session request initiated by the UE sent by the IMS is received within a specified time, the satellite access gateway device deletes the backup of the session request after protocol conversion stored in the cache; or, if no true response to the session request initiated by the UE sent by the IMS is received within a specified time, the satellite access gateway device retransmits the backup of the session request after protocol conversion stored in the cache.

[0039] Optionally, the satellite access gateway device rejects the session request initiated by the UE; and puts the session request initiated by the UE into a blacklist.

[0040] Optionally, the satellite access gateway device filters messages about the session request initiated by the UE according to a five-tuple, and determines that the session request initiated by the UE with an abnormal message is not from a trusted network or has a malicious attack. The five-tuple includes a source IP, a destination IP, a transport protocol, a source port, and a destination port.

[0041] Optionally, when it is determined that the session request initiated by the UE is safe, the first sending module decapsulates the message of the session request initiated by the UE and performs SIP protocol header processing; and the first sending module sends the processed session request to the IMS core network via the Gm and Mw interfaces.

[0042] Optionally, the session request message initiated by the UE complies with the UDP protocol.

[0043] In a third aspect, an embodiment of the present disclosure provides a satellite access gateway device, comprising: a memory, a processor, a transceiver, and a program stored in the memory and executable on the processor; when the processor executes the program, the transceiver implements the various steps of the session request processing method according to the first aspect.

[0044] In a fourth aspect, an embodiment of the present disclosure provides a readable storage medium, on which a program is stored. When the program is executed by a processor, each step of the session request processing method according to the first aspect is implemented.

[0045] According to the session request processing method implemented by the satellite access gateway device, the satellite access gateway device, and the readable storage medium storing the relevant program for implementing the session request processing method, the satellite access gateway and its architecture components that support I-SBC capability and can realize integrated voice services in the satellite and IMS converged network can be effectively realized, and the satellite access gateway has added support for I-SBC capability and the PEP component guarantees the QoS of the integrated voice service. It can especially solve the technical problems of high delay and high bit error of satellite links, and has the advantages of low delay and high reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0047] Figure 1 The overall architecture of the terrestrial IMS and satellite communication converged network implemented by an integrated voice satellite access gateway supporting I-SBC capabilities according to an embodiment of the present invention is shown.

[0048] Figure 2 An exemplary flow chart of a session request processing method executed by a satellite access gateway according to an embodiment of the present invention is shown.

[0049] Figure 3 A block diagram of functional modules included in a satellite access gateway according to an embodiment of the present invention is shown.

[0050] Figure 4 The timing diagram shows a specific working process of an integrated voice satellite access gateway supporting I-SBC capability according to an embodiment of the present invention.

[0051] Figure 5 An exemplary flow chart showing an example of adding a priority decision process to a traditional transparent PEP based on a comprehensive voice service model according to an embodiment of the present invention.

[0052] Figure 6 A timing diagram showing a specific workflow after adding a PEP capability component based on an integrated voice service model according to an embodiment of the present invention is shown.

[0053] Figure 7 A timing diagram showing a specific workflow after adding an I-SBC capability component according to an embodiment of the present invention is shown.

[0054] Figure 8 A block diagram of a satellite access gateway device according to an embodiment of the present invention is shown.

[0055] Fig. 9 A schematic structural diagram of a satellite access gateway device according to an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0056] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0057] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0058] Definition of important terms

[0059] First, for the convenience of description, the meanings of some key terms involved in this application are given.

[0060] IP Multimedia Subsystem (IMS) core network: In order to keep the goal consistent with the Next Generation Network (NGN), 3GPP first proposed the concept of IMS in R5, and improved the concept, architecture, process and other aspects in R6 and R7. Due to the access-independent characteristics of the IMS network, it is considered to be an important technical foundation for realizing the convergence of fixed and mobile networks, as well as the convergence of differentiated voice, data and video services. IMS is a mobile multimedia communication technology based on packet switching technology. As the core standard framework of the next generation network recognized by ITU.T and ETSI (European Telecommunications Standardization Institute), it adopts the SIP protocol. Its main feature is access-independence. It can provide services for various types of terminals connected to the IMS network through IP, so that various types of clients can establish peer-to-peer communication and obtain the service quality required by the business. The IMS network has functions such as session management, service registration, security authentication, billing, bearer control, and roaming. Inter-Session Border Controller (I-SBC) is a gateway device that provides IP network to IP network in IMS network. It is usually deployed between different IMS core networks (i.e., Network to Network Interface (NNI) interface) or between IMS core network and other IP Phone networks (NNI interface). It connects to Interrogating-Call Session Control Function (I-CSCF) in the core network through Mx interface. The interface protocol is SIP (Session Initiation Protocol). I-SBC is responsible for providing signaling processing, media resource management, codec conversion, SIP trunk access, routing, QoS policy control, security, business support and other functions.

[0061] Access network: At present, ground access still has certain defects, such as limited working distance and coverage blind spots in remote areas. The advantages of satellite access, such as wide coverage, flexible resource allocation, and strong system anti-destruction, make up for the limitations of ground access, making the combination of satellite access and IMS core network a development trend.

[0062] Comprehensive voice services: With the development of Internet networks based on the TCP / IP protocol suite, voice services carried by IP protocols have become mainstream. After the emergence of SIP and H.323 protocols, various VoIP voice gateway products have emerged in large numbers.

[0063] Therefore, in the technical background of the combination of satellite communication and IMS core network, how to realize VoIP voice service under satellite access scenario in this converged communication system has become a technical breakthrough that needs urgent research.

[0064] In conjunction with the accompanying drawings, the session request processing method implemented by the satellite access gateway device, the satellite access gateway device, and the computer-readable storage medium storing the relevant program implementing the session request processing method provided by the embodiments of the present invention are described in detail through specific embodiments and their application scenarios.

[0065] Overall system architecture

[0066] Integrated voice services have strict requirements on delay range and delay jitter. In order to achieve QoS guarantee for integrated voice services, the ground mobile communication network must have the ability to reserve and control resources. The satellite access gateway can realize the interconnection between the ground IMS network and the satellite communication network, thereby providing integrated voice services to terminal users. The embodiment of the present invention proposes an integrated voice satellite access gateway that supports I-SBC capabilities, and fully describes the functional architecture and communication process of the integrated voice satellite access gateway that supports I-SBC capabilities, and innovatively proposes a performance optimization proxy (PEP) component that can support an integrated voice service model and a lightweight inter-session border controller (I-SBC) capability component that adapts to satellite access. The ground IMS and satellite communication converged network is realized by an integrated voice satellite access gateway that supports I-SBC capabilities. The overall architecture of the network is as follows: Figure 1 shown.

[0067] Figure 1 The overall architecture of the terrestrial IMS and satellite communication converged network implemented by an integrated voice satellite access gateway supporting I-SBC capabilities according to an embodiment of the present invention is shown. Figure 1 As shown, the converged network includes a user equipment (UE) 1000, a satellite access gateway 2000, and a core network 3000. Figure 1 Only one UE 1000, satellite access gateway 2000, and core network 3000 are shown in the figure, but those skilled in the art can understand that the number of UE 1000, satellite access gateway 2000, and core network 3000 can also be multiple, as long as the technical solution provided by the embodiment of the present invention can be implemented. Figure 1Only main functional components of the satellite access gateway 2000 and the core network 3000 are shown. According to actual needs, the satellite access gateway 2000 and the core network 3000 may also include any known or unknown other functional components, but are not limited thereto.

[0068] In addition, if Figure 1 As shown, UE 1000 can be a mobile electronic device or a non-mobile electronic device. For example, the mobile electronic device can be a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook or a personal digital assistant (PDA), etc. Similarly, for example, the non-mobile electronic device can be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine or a self-service machine, etc., and the embodiments of the present invention do not specifically limit this.

[0069] In addition, if Figure 1 As shown, the satellite access gateway 2000 includes an I-SBC capability component 2010, a protocol conversion component (i.e., PEP based on an integrated voice service model) 2020, an address management 2030, and a communication control 2040, etc. On the other hand, the core network 3000 includes an I-CSCF 3010, a P-CSCF 3020, and an S-CSCF 3030.

[0070] According to various embodiments of the present invention, the integrated voice service has strict requirements on the delay range and delay jitter. In order to achieve QoS guarantee for the integrated voice service, the ground mobile communication network must have the ability to reserve and control resources. The satellite access gateway can realize the interconnection between the ground IMS network and the satellite communication network, thereby providing integrated voice services to terminal users. Various embodiments of the present invention propose an integrated voice satellite access gateway that supports I-SBC capabilities, and fully describe the functional architecture and communication process of the integrated voice satellite access gateway that supports I-SBC capabilities, and innovatively propose a PEP component 2020 that can support an integrated voice service model and a lightweight I-SBC capability component 2010 adapted to satellite access.

[0071] like Figure 1As shown, the data packet sent by UE 1000 enters the satellite access gateway 2000 through the interface Gm, and enters each network element (I-CSCF 3010, P-CSCF 3020, and S-CSCF 3030) of the ground IMS core network 3000 through the Gm and Mw interfaces after completing the protocol conversion, communication control and other processing in the gateway 2000. The integrated voice satellite access gateway 2000 supporting I-SBC capability realizes the interconnection and interoperability between the IMS core network 3000 and the satellite network through protocol conversion (including PEP capability based on the integrated voice service model) in the physical layer, data link layer, routing layer and upper layer messages.

[0072] Functional architecture and implementation method of integrated voice satellite access gateway supporting I-SBC capability

[0073] The various embodiments of the present invention expand the PEP capabilities based on the integrated voice service model on the original functional modules of the satellite access gateway. In addition, it innovatively proposes to adapt some security functions and signaling processing functions of the I-SBC network element in the IMS core network to the satellite access gateway in the form of lightweight capability components.

[0074] Figure 2 FIG. 2 shows an exemplary flow chart of a session request processing method executed by the satellite access gateway 2000 according to an embodiment of the present invention. Figure 2 As shown, the session request processing method includes, for example: the satellite access gateway 2000 receives a session request initiated by the UE 1000 (step S201); the satellite access gateway 2000 determines whether the session request initiated by the UE 1000 comes from a trusted network or there is a malicious attack (step S202); and, when the satellite access gateway 2000 determines that the session request initiated by the UE 1000 is safe, the session request initiated by the UE 1000 is sent to the IMS core network 3000 (step S203).

[0075] Optionally, the session request processing method may further include: assigning a high priority to a session request involving an integrated voice service among the session requests initiated by the UE 1000 according to a priority decision; preferentially completing the protocol conversion process of the session request with a high priority and placing it in a cache; and sending the session request after protocol conversion stored in the cache to the IMS core network 3000.

[0076] Optionally, after receiving the session request initiated by the UE 1000, the session request processing method may further include: completing identity authentication and address conversion of a data packet included in the session request initiated by the UE 1000; and returning an early pseudo response to the UE 1000.

[0077] Optionally, after receiving a true response to the session request initiated by the UE 1000 and sent by the IMS, the session request processing method may further include: if the true response is received within a specified time, deleting the backup of the session request after protocol conversion stored in the cache; or if the true response is not received within the specified time, retransmitting the backup of the session request after protocol conversion stored in the cache.

[0078] Optionally, when it is determined that the session request initiated by the UE 1000 comes from a trusted network or there is a malicious attack, the session request processing method may also include: rejecting the session request initiated by the UE 1000; and placing the session request initiated by the UE 1000 in a blacklist.

[0079] Optionally, the determining whether the session request initiated by the UE 1000 is from a trusted network or there is a malicious attack specifically includes: filtering messages about the session request initiated by the UE 1000 according to a five-tuple; and determining the session request initiated by the UE 1000 of the abnormal message as not coming from a trusted network or there is a malicious attack. Here, the five-tuple includes a source IP, a destination IP, a transport protocol, a source port, and a destination port.

[0080] Optionally, when it is determined that the session request initiated by the UE 1000 is safe, the session request initiated by the UE 1000 is sent to the IP Multimedia Subsystem IMS core network 3000, specifically including: when it is determined that the session request initiated by the UE is safe, the message of the session request initiated by the UE 1000 is decapsulated and the header of the SIP protocol is processed; and the processed session request is sent to the IMS core network 3000 via the Gm and Mw interfaces.

[0081] Optionally, the session request message initiated by the UE 1000 complies with the UDP protocol.

[0082] Accordingly, the block diagram of the specific functional architecture of the integrated voice satellite access gateway 2000 supporting I-SBC capability proposed in the embodiment of the present invention is as follows: Figure 3 shown.

[0083] In the process of interconnecting the satellite network and the terrestrial network, in view of the characteristics of the satellite network, each embodiment of the present invention proposes a network architecture adapted to the satellite operation characteristics. In the face of heterogeneous satellite networks and terrestrial networks, it is necessary to design a gateway according to the characteristics of the satellite network architecture to achieve interconnection between the two. Figure 3As shown, the functional modules included in the satellite access gateway 2000 according to the embodiment of the present invention can be roughly divided into: (1) communication control 2040, used to receive data from the user terminal 1000 or send data to the user terminal 1000; (2) identity authentication 2060, used to store access authentication information and perform identity authentication on the user terminal 1000 that wants to access; (3) address management 2030, used to complete the mapping of satellite logical link to IP link by binding the satellite address to the IP address, so as to realize the connection of the satellite terminal user to the IMS domain; (4) protocol conversion component 2020, used to realize the interconnection and interoperability of heterogeneous networks by converting the satellite network protocol and the ground network protocol; (5) resource management 2050, used to store the geographical location information of the network related to the mobile or fixed user, etc., and manage all resources in the gateway 2000; and (6) I-SBC capability component 2010, used to realize some security functions and signaling processing functions. The specific implementation method will be described in detail below.

[0084] Here, the integrated voice service has strict requirements on the delay range and is sensitive to delay changes. In order to ensure the QoS of the integrated voice service in the integrated network of satellite communication and IMS core network, various embodiments of the present invention propose a PEP based on the integrated voice service model in the protocol conversion component 2020, and add a priority decision process on the basis of the traditional transparent PEP. By giving high priority to the integrated voice service data packet, its processing delay in PEP is reduced, and the delay requirements of the integrated voice service are met. In addition, the lightweight I-SBC capability component 2010 adapted to satellite access provided by various embodiments of the present invention realizes the signaling processing and security functions of non-registered messages, improves network security, marginalizes some core network functions, and simplifies the architecture of the core network 3000.

[0085] Specifically, the specific workflow of the integrated voice satellite access gateway supporting I-SBC capabilities is as follows: Figure 4 shown. Figure 4The flowchart of the specific working process of the integrated voice satellite access gateway supporting I-SBC capability according to an embodiment of the present invention is shown, which specifically includes the following steps. The data packet from the user terminal 1000 enters the satellite access gateway through the Gm interface (steps S401, S402), firstly receives the data packet from the user terminal 1000 through the communication control module 2040 (step S403), and forwards the user's session request to the identity authentication module 2060 (step S404). Then the identity authentication module 2060 authenticates the user (step S405), and after completing the identity authentication, sends the data packet to the address management module 2030 (step S406). The address management module 2030 completes the mapping of the satellite logical link to the IP link in combination with the user information stored in the resource management module 2050 (step S407), and then transmits the data packet to the protocol conversion component 2020 containing the PEP capability based on the integrated voice business model (step S408). On the one hand, the protocol conversion component 2020 returns a pseudo response to the UE 1000 (step S409). On the other hand, the protocol conversion component 2020 reduces the waiting time of the integrated voice service data packet through priority decision. After completing the protocol conversion, the data packet is added to the sending buffer and forwarded to the I-SBC capability component 2010 (steps S410, S411). The I-SBC capability component 2010 determines whether the data packet comes from a trusted network or there is a malicious attack (step S412). If it is safe, the data packet is processed to complete the session control (step S413). Finally, the integrated voice satellite access gateway 2000 supporting the I-SBC capability sends the data packet to the IMS core network 3000 via the Gm and Mw interfaces (step S413).

[0086] Compared with the existing satellite gateway technology, the existing satellite gateway technology does not study the realization of integrated voice services in the satellite and IMS converged network, and the support for I-SBC capabilities. Therefore, when facing the integrated voice service, the network capabilities cannot guarantee to meet the QoS requirements of the integrated voice service. The various embodiments of the present invention propose an integrated voice satellite access gateway supporting I-SBC capabilities and its architecture components that can realize integrated voice services in the satellite and IMS converged network, and add support for I-SBC capabilities in the satellite access gateway, as well as the PEP component to ensure the QoS of the integrated voice service.

[0087] PEP (Performance Optimization Proxy) based on comprehensive voice service model

[0088] The voice service based on the integrated voice service model is more sensitive to delay changes and has higher requirements for delay stability compared to other data services. Due to the characteristics of satellite links such as long delay, high bit error, and large delay-bandwidth product, the performance of the TCP protocol is greatly affected in satellite link transmission and cannot meet the requirements of the integrated voice service model for low delay. Therefore, various embodiments of the present invention propose a PEP based on the integrated voice service model to meet the requirements of integrated voice and data services for low delay.

[0089] Two types of first-in-first-out buffers are set in traditional transparent PEP. One type is a first-in-first-out store and forward buffer (SF buffer), which is used to cache all data sent by the data sender to the receiver. Each data stream shares this buffer. The other type is a PEP buffer (PEP buffer), which is used to control the number of pseudo responses sent and retransmit partially lost data packets. Each TCP link has its own PEP buffer. When PEP2020 according to an embodiment of the present invention receives a data packet from the source host UE 1000, it will perform protocol conversion processing in the order of arrival to implement TCP segmentation, and store the processed data packets in the SF buffer, and then send them out in sequence. At the same time, a backup of the data packet is stored in the PEP buffer in case of retransmission of the data packet, and an advance pseudo response is sent to the source host to replace the response sent by the target host to the source host (see Figure 4 On the other hand, after receiving the pseudo response, the source host UE 1000 can continue to send new data packets without waiting. PEP receives multiple TCP connections at the same time, and a large number of data packets continuously enter PEP for protocol conversion processing and are sent. The waiting process for processing and sending will bring some additional delays, which has a negative impact on the performance of delay-sensitive applications such as integrated voice services. Therefore, the embodiment of the present invention provides a priority decision process based on the integrated voice service model in the traditional transparent PEP, such as Figure 5 When a data packet is received (step S501), it is first determined whether the data packet is an integrated voice service (step S502). If it is an integrated voice service, the data packet is given a higher priority (steps S503, S504), and the protocol conversion is processed before other services, and when entering the SF buffer, it is sent before the data packets with lower priority than it, reducing the queuing waiting time and meeting the delay requirements of the integrated voice service (steps S505 to S510).

[0090] In addition, the embodiment of the present invention expands the original protocol conversion module in the satellite access gateway and adds the PEP capability based on the integrated voice service model. The specific workflow after the function expansion is as follows: Figure 6 shown.

[0091] The data packet entering the gateway 2000 through the Gm interface is first intercepted by the communication control module 2040 (step S601). After being processed by the identity authentication module 2060 and the address management module 2030, it enters the protocol conversion function module (containing the PEP capability based on the integrated voice service) 2020 for processing (step S602). The gateway (i.e., the PEP capability component 2020 of the integrated voice service) will respond to the data sending end with a pseudo-response in advance (step S603). The PEP capability component 2020 based on the integrated voice service makes a priority decision, i.e., determines whether the received data packet is an integrated voice service data packet. If so, it is given a high priority, otherwise it is given a low priority. Data packets with high priority can be processed for protocol conversion faster, and when added to the sending cache queue after processing, they are arranged before data packets with lower priority than it to be sent first (steps S604 to S607). Compared with traditional transparent PEP, PEP based on integrated voice services reduces the processing delay of integrated voice services in PEP capability component 2020 while ensuring system compatibility and link utilization, meets the delay-sensitive characteristics of integrated voice services, and effectively guarantees the QoS of integrated voice services.

[0092] Compared with the various embodiments of the present invention, the main functions of the traditional intelligent gateway include autonomously controlling the operation of the device traffic of the access gateway and autonomously cutting off the device data traffic of the access gateway. In comparison, the integrated voice satellite access gateway technology supporting I-SBC capability proposed based on the interconnection between the ground IMS core network and the satellite network according to the various embodiments of the present invention fully considers the realization of integrated voice services under the satellite access form and the service QoS guarantee, and enhances the PEP capability component according to the high latency and high bit error characteristics of the satellite link.

[0093] Lightweight I-SBC capability component adapted for satellite access

[0094] In various embodiments of the present invention, a lightweight I-SBC capability component 2010 adapted to satellite access is proposed. The lightweight I-SBC capability component 2010 implements some functions of the I-SBC device on the original core network side in the satellite access gateway 2000, including information storage, deletion and addition of non-registered messages in the network and security functions (for example, firewall functions and simulated DoS attacks). In addition, the control of sessions is implemented in the satellite gateway 2000, while simplifying the architecture of the IMS core network 3000. The lightweight I-SBC capability component 2010 can automatically intercept DoS attacks, filter according to the five-tuple (source IP, destination IP, transport protocol, source port, destination port), discard abnormal messages, and improve the security performance of the gateway 2000.

[0095] In each embodiment of the present invention, an I-SBC capability component 2010 is added to the original functional module in the satellite access gateway 2000. The specific workflow after the functional expansion is as follows: Figure 7 shown.

[0096] First, the data packet sent by the terminal 1000 enters the gateway 2000 via the Gm interface (step S701), and is then intercepted by the communication control module 2040, and then processed by the address management module 2030, the identity authentication module 2060 and the protocol conversion function module (containing the PEP capability based on the integrated voice service) 2020, and forwarded to the I-SBC capability component 2010 (steps S702 to S705). The I-SBC capability component 2010 filters the message through the five-tuple to determine whether the session request information comes from a trusted network (step S706), and at the same time determines whether the session request has a malicious attack (such as a Dos attack), and automatically intercepts the attack for messages with security risks (step S706). If the request is safe and reliable, the SIP protocol header is processed after decapsulation (step S707), and finally the processed session request is sent to the IMS core network 3000 via the Gm and Mw interfaces (step S708).

[0097] Compared with the various embodiments of the present invention, the accelerators set in the traditional gateway still use the TCP protocol for communication. The various embodiments of the present invention innovatively propose to use an improved UDP protocol on the satellite link, which can effectively improve the reliability of the UDP protocol while ensuring low latency, and realize the interconnection between the ground communication network and the satellite network, while realizing the provision of high-quality integrated voice services by the satellite and IMS fusion network, laying a solid technical foundation for the integration of satellite networks and ground networks.

[0098] In addition, the embodiment of the present invention further provides a satellite access gateway device 8000, such as Figure 8As shown, it includes: a first receiving module 8010, used to receive a session request initiated by UE 1000; a first judging module 8020, used to judge whether the session request initiated by the UE 1000 comes from a trusted network or there is a malicious attack; and a first sending module 8030, when it is judged that the session request initiated by the UE 1000 is safe, is used to send the session request initiated by the UE 1000 to the IMS core network 3000.

[0099] Optionally, the satellite access gateway device 8000 also includes: a priority assignment module, used to assign a high priority to the session request involving the integrated voice service among the session requests initiated by the UE 1000 according to the priority decision; a protocol conversion module, used to preferentially complete the protocol conversion process of the session request with a high priority and put it into the cache; and a second sending module, used to send the session request after the protocol conversion stored in the cache to the IMS core network 3000.

[0100] Optionally, the satellite access gateway device 8000 further includes: an address conversion module, used to complete the identity authentication and address conversion of the data packet included in the session request initiated by the UE 1000; and a pseudo response module, used to return an early pseudo response to the UE 1000.

[0101] Optionally, when a true response to the session request initiated by the UE 1000 and sent by the IMS 3000 is received within a specified time, the satellite access gateway device 8000 deletes the backup of the session request after protocol conversion stored in the cache. Alternatively, when no true response to the session request initiated by the UE 1000 and sent by the IMS 3000 is received within a specified time, the satellite access gateway device 8000 retransmits the backup of the session request after protocol conversion stored in the cache.

[0102] Optionally, the satellite access gateway device 8000 rejects the session request initiated by the UE 1000; and the satellite access gateway device 8000 puts the session request initiated by the UE 1000 into a blacklist.

[0103] Optionally, the satellite access gateway device 8000 performs message filtering on the session request initiated by the UE 1000 according to a five-tuple; and the satellite access gateway device 8000 determines that the session request initiated by the UE 1000 of the abnormal message is not from a trusted network or there is a malicious attack. Here, the five-tuple includes source IP, destination IP, transport protocol, source port, and destination port.

[0104] Optionally, when it is determined that the session request initiated by the UE is secure, the first sending module 8030 decapsulates the message of the session request initiated by the UE and performs SIP protocol header processing; and the first sending module 8030 sends the processed session request to the IMS core network 3000 via the Gm and Mw interfaces.

[0105] Optionally, the session request message initiated by the UE 1000 complies with the UDP protocol.

[0106] In addition, the embodiment of the present invention further provides a satellite access gateway device 9000, such as Fig. 9 As shown, it includes: a memory 9030, a processor 9010, a transceiver 9040, a bus interface 9020, and a program stored in the memory 9030 and executable on the processor 9010; when the processor 9010 executes the program, each process of the above-mentioned session request processing method embodiment is implemented, and the same or similar technical effects can be achieved. To avoid repetition, it is not repeated here.

[0107] In addition, an embodiment of the present invention further provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the above-mentioned session request processing method embodiment is implemented, and the same or similar technical effects can be achieved. To avoid repetition, it will not be repeated here.

[0108] The processor is a processor in the electronic device described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0109] It should be noted that, in this article, the terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0110] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present application.

[0111] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

Claims

1. A session request processing method, the method being applied to a satellite access gateway device, characterized in that: The method comprises: Receiving a session request initiated by a terminal device UE; Determining whether the session request initiated by the UE comes from a trusted network or whether there is a malicious attack; and When it is determined that the session request initiated by the UE is safe, sending the session request initiated by the UE to an IP Multimedia Subsystem IMS core network; The session request message initiated by the UE complies with the UDP protocol; Wherein, the method further comprises: According to the priority decision, assigning a high priority to a session request involving an integrated voice service among the session requests initiated by the UE; Prioritize the completion of the protocol conversion process of the session request with a high priority and put it into the cache; and The session request after protocol conversion stored in the cache is sent to the IMS core network.

2. The method according to claim 1, characterized in that After receiving a session request initiated by the UE, the method further includes: completing identity authentication and address conversion of data packets contained in the session request initiated by the UE; and An early pseudo-acknowledgement is returned to the UE.

3. The method according to claim 1, characterized in that After receiving a true response to the session request initiated by the UE sent by the IMS, the method further includes: If the real response is received within the specified time, the backup of the session request after protocol conversion stored in the cache is deleted; or If the real response is not received within a specified time, the backup of the session request after protocol conversion stored in the cache is retransmitted.

4. The method according to any one of claims 1 to 3, characterized in that When it is determined that the session request initiated by the UE comes from a trusted network or there is a malicious attack, the method further includes: rejecting a session request initiated by the UE; and The session request initiated by the UE is put into a blacklist.

5. The method according to any one of claims 1 to 4, characterized in that The determining whether the session request initiated by the UE comes from a trusted network or whether there is a malicious attack specifically includes: Performing message filtering on the session request initiated by the UE according to a five-tuple; and The session request initiated by the UE in the abnormal message is judged as not coming from a trusted network or as being a malicious attack, The five-tuple includes source IP, destination IP, transport protocol, source port, and destination port.

6. The method according to any one of claims 1 to 5, characterized in that When it is determined that the session request initiated by the UE is safe, sending the session request initiated by the UE to an IP Multimedia Subsystem IMS core network specifically includes: When it is determined that the session request initiated by the UE is safe, decapsulation processing and SIP protocol header processing are performed on the message of the session request initiated by the UE; and The processed session request is sent to the IMS core network via the Gm and Mw interfaces.

7. A satellite access gateway device, characterized in that: include: A first receiving module, configured to receive a session request initiated by a terminal device UE; A first determination module, used to determine whether the session request initiated by the UE comes from a trusted network or whether there is a malicious attack; as well as A first sending module, when it is determined that the session request initiated by the UE is safe, is used to send the session request initiated by the UE to the IP Multimedia Subsystem IMS core network; The session request message initiated by the UE complies with the UDP protocol; Wherein, the satellite access gateway device further includes: A priority designation module, configured to assign a high priority to a session request involving an integrated voice service among the session requests initiated by the UE according to a priority decision; A protocol conversion module, used to preferentially complete the protocol conversion process of the session request with a high priority and put it into the cache; and The second sending module is used to send the session request after the protocol conversion stored in the cache to the IMS core network.

8. The satellite access gateway device according to claim 7, characterized in that: Also includes: An address conversion module, used to complete the identity authentication and address conversion of the data packet contained in the session request initiated by the UE; as well as The pseudo response module is used to return an early pseudo response to the UE.

9. The satellite access gateway device according to claim 7, characterized in that: When a true response to the session request initiated by the UE and sent by the IMS is received within a specified time, the satellite access gateway device deletes the backup of the session request after protocol conversion stored in the cache; or In the case that no real response to the session request initiated by the UE and sent by the IMS is received within a specified time, the satellite access gateway device retransmits the backup of the session request after protocol conversion stored in the cache.

10. The satellite access gateway device according to any one of claims 7 to 9, characterized in that: The satellite access gateway device rejects the session request initiated by the UE; and The session request initiated by the UE is put into a blacklist.

11. The satellite access gateway device according to any one of claims 7 to 10, characterized in that: The satellite access gateway device performs message filtering on the session request initiated by the UE according to a five-tuple; as well as The session request initiated by the UE in the abnormal message is judged as not coming from a trusted network or as being a malicious attack, The five-tuple includes source IP, destination IP, transport protocol, source port, and destination port.

12. The satellite access gateway device according to any one of claims 7 to 11, characterized in that: When it is determined that the session request initiated by the UE is safe, the first sending module decapsulates the message of the session request initiated by the UE and performs SIP protocol header processing; as well as The first sending module sends the processed session request to the IMS core network via the Gm and Mw interfaces.

13. A satellite access gateway device, comprising: A memory, a processor, a transceiver, and a program stored on the memory and executable on the processor; When the processor executes the program, the steps of the session request processing method according to any one of claims 1 to 6 are implemented through the transceiver.

14. A readable storage medium having a program stored thereon, wherein the program, when executed by a processor, implements the steps of the session request processing method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Integrated channel control equipment

    CN103532879A