A communication method, apparatus and system
Through the collaborative work of BNG and FMIF, the authentication information is encapsulated using the Radius or Diameter protocol and the control surface interface, the problem of fixed network users in the 5G communication network cannot be authenticated, and the access and data transmission of fixed network devices in the 5G core network is realized.
Patent Information
- Application Number
- CN202210719731.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-03-18
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2039-03-18
AI Technical Summary
In 5G communication networks, fixed network users cannot authenticate in the core network, resulting in unavailability to access the mobile network for data transmission.
Through the collaborative work of broadband gateway BNG and FMIF, the authentication information of the fixed network device is transmitted to the core network device by using the Radius or Diameter protocol, the authentication information is encapsulated using the control surface interface, and a data surface connection is established to realize the authentication of the fixed network device by the core network.
The 5G core network authentication of fixed network equipment is realized to ensure that fixed network equipment can access and transmit data normally in the 5G communication network.
Smart Images

Figure CN115174172B_ABST
Abstract
Description
[0001] This application is a divisional application of the application with the application date of March 18, 2019, application number 201910205524.7, and invention title "A Communication Method, Device and System" submitted to the China National Intellectual Property Administration. Technical Field
[0002] This application relates to the field of communications, and in particular to a communication method, device and system. Background Art
[0003] Communication networks are divided into mobile networks and fixed networks. Mobile networks allow mobile users to access, and mobile users can send or receive data in mobile networks. Fixed networks allow fixed network users to access, and fixed network users can send or receive data in fixed networks. In 4G communication networks, to facilitate the management of mobile users and fixed network users, fixed network users are allowed to access mobile networks.
[0004] When a fixed network user accesses a mobile network, it needs to be authenticated by the core network of the mobile network. After successful authentication, the fixed network user can send or receive data in the mobile network. However, in communication networks that emerged after 4G communication networks, fixed network users cannot be authenticated in the core network. For example, in 5G communication networks that emerged after 4G communication networks, fixed network users cannot be authenticated in the 5G core network. Summary of the Invention
[0005] In order to enable the 5G core network or a core network higher than 5G to authenticate fixed network devices, embodiments of this application provide a communication method and device. The technical solution is as follows:
[0006] In a first aspect, this application provides a communication method. In this method, a Broadband Network Gateway (BNG) receives a dial-up packet sent by a fixed network device, generates first authentication information for the fixed network device according to the dial-up packet, and the first authentication information includes an identifier of the fixed network device. The BNG sends an access request message carrying the first authentication information to a Fixed-Mobile Interworking Function (FMIF), and the access request message is used for the FMIF to request a core network device to authenticate the fixed network device according to the first authentication information. The communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. Since the BNG sends the authentication information of the fixed network device to the core network device through the FMIF, so that the core network device can authenticate the fixed network device, this can enable the 5G core network or a core network higher than 5G to authenticate the fixed network device.
[0007] In an alternative implementation, the access request message is a Remote Authentication Dial In User Service (Radius) protocol access request message or a Diameter protocol access request message. In this way, the Broadband Network Gateway (BNG) can send the authentication information of the fixed network device to the Fixed-Mobile Interworking Function (FMIF) through the Radius protocol access request message or the Diameter protocol access request message, so that the FMIF can send the authentication information of the fixed network device to the core network device in the 5G core network or a core network higher than 5G.
[0008] In an alternative implementation, the BNG receives the address of the fixed network device sent by the core network device through the FMIF. The address of the fixed network device is allocated by the core network device after receiving a session establishment request message carrying the identifier of the fixed network device. The session establishment request message is sent by the FMIF after the core network device authenticates the fixed network device successfully; according to the address of the fixed network device and the address of the FMIF, a data plane connection corresponding to the fixed network device is established between the BNG and the FMIF. Since the BNG receives the address of the fixed network device, a data plane connection corresponding to the fixed network device can be established between the BNG and the FMIF, so that the service packets of the fixed network device can be transmitted through this data plane connection.
[0009] In a second aspect, the present application provides a communication method. In this method, the Fixed-Mobile Interworking Function (FMIF) receives an access request message sent by a Broadband Network Gateway (BNG). The access request message includes first authentication information of a fixed network device. The first authentication information is generated by the BNG based on a dialing packet sent by the fixed network device and the first authentication information includes the identifier of the fixed network device. The FMIF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain second authentication information, and sends the second authentication information to the core network device through the control plane interface. The second authentication information is used for the core network device to authenticate the fixed network device. The control plane interface is an interface in the FMIF for communicating with the core network device. The communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. Since the FMIF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information, the second authentication information can be sent to the 5G core network or the core network device of a core network higher than 5G through the control plane interface, ensuring the successful authentication of the fixed network device by the core network device.
[0010] In an alternative implementation, the control plane interface includes an N1 interface or an N2 interface, and the second authentication information is a Subscriber Concealed Identifier (SUCI), an encrypted Subscriber Permanent Identifier (SUPI), or a 5G Globally Unique Temporary UE Identity (5G-GUTI).
[0011] In an alternative implementation, the FMIF receives an acknowledgment message sent by the core network device after successful authentication; sends a session establishment request message to the core network device, where the session establishment request message carries the identifier of the fixed network device, and the session establishment request message is used for the core network device to allocate session information, and the session information includes the address of the fixed network device, the tunnel endpoint identifier (TEID) of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The tunnel is the tunnel corresponding to the fixed network device between the FMIF and the core network device; receives the session information sent by the core network device; and establishes a data plane connection corresponding to the fixed network device between the FMIF and the BNG and establishes the tunnel according to the session information. Since the FMIF receives the session information, a data connection corresponding to the fixed network device between the FMIF and the BNG is established according to the session information, and a tunnel corresponding to the fixed network device between the FMIF and the core network device is established, thereby completing the establishment of the data plane connection between the fixed network device and the core network device, so that the fixed network device can use this data plane connection to transmit service packets.
[0012] In an alternative implementation, the FMIF sends the address of the fixed network device to the BNG, and stores the correspondence between the address of the fixed network device and the address of the BNG in a first relationship table, and the first relationship table is used for the FMIF to transmit the downlink service packets of the fixed network device; stores the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side in a second relationship table, and the second relationship table is used for the FMIF to send the uplink service packets of the fixed network device. In this way, the FMIF can forward the service packets of the fixed network device through the first relationship table and the second relationship table.
[0013] In an alternative implementation, the session information further includes the TEID of the tunnel on the FMIF side.
[0014] In an alternative implementation, the FMIF allocates the TEID of the tunnel on the FMIF side, and sends the TEID of the tunnel on the FMIF side to the core network device. The TEID of the tunnel on the FMIF side is used to trigger the core network device to store the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side in a correspondence table, and the correspondence table is used for the core network device to transmit the downlink service packets of the fixed network device.
[0015] In an alternative implementation, the FMIF sends the session establishment request message to the core network device through the control plane interface, and the control plane interface includes the N1 interface or the N2 interface.
[0016] In a third aspect, the present application provides a communication method. In this method, the core network device receives a session establishment request message from a Fixed-Mobile Interworking Function (FMIF). The session establishment request message includes the identifier of the fixed network device. The communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The core network device allocates session information for the fixed network device according to the identifier of the fixed network device. The session information includes the address of the fixed network device, the Tunnel Endpoint Identifier (TEID) of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The tunnel is the tunnel corresponding to the fixed network device between the FMIF and the core network device. The core network device sends the session information to the FMIF, and the session information is used by the FMIF to establish a data plane connection between the fixed network device and the core network device. Since the core network device allocates session information and sends the session information to the FMIF, the FMIF can establish a data connection corresponding to the fixed network device with the Broadband Network Gateway (BNG) and establish a tunnel corresponding to the fixed network device with the core network device according to the session information, thereby completing the establishment of the data plane connection between the fixed network device and the core network device. In this way, the fixed network device can use this data plane connection to transmit service packets.
[0017] In an alternative implementation, the core network device receives the second authentication information sent by the FMIF. The second authentication information is obtained by the FMIF encapsulating the first authentication information according to the message format supported by the control plane interface. The control plane interface is the interface used by the FMIF to communicate with the core network device. The first authentication information includes the identifier of the fixed network device. The fixed network device is authenticated according to the second authentication information. Since the FMIF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information, the second authentication information can be sent to the 5G core network or the core network device higher than the 5G core network through the control plane interface, ensuring that the core network device can successfully authenticate the fixed network device.
[0018] In an alternative implementation, the session information further includes the TEID of the tunnel on the FMIF side.
[0019] In an alternative implementation, the core network device receives the TEID of the tunnel on the FMIF side sent by the FMIF. The TEID of the tunnel on the FMIF side is sent through the session establishment request message or is sent after the FMIF receives the session information.
[0020] In an alternative implementation, the core network device saves the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side into a correspondence table, and the correspondence table is used for the core network device to transmit the downlink service packets of the fixed network device. In this way, the downlink service packets can be sent to the fixed network device through this correspondence table.
[0021] In a fourth aspect, an embodiment of the present application provides a communication method. In this method, the Fixed-Mobile Interworking Function (FMIF) receives a first uplink service packet from the fixed network device; encapsulates the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain a second uplink service packet, where the tunnel is the tunnel corresponding to the fixed network device between the FMIF and the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The FMIF sends the second uplink service packet to the core network device through the tunnel. Since the FMIF encapsulates the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain the second uplink service packet, the second uplink service packet can be sent to the core network device through this tunnel, thereby enabling the fixed network device to send uplink service packets to a 5G core network or a core network higher than 5G.
[0022] In an alternative implementation, the first uplink service packet includes the address of the fixed network device; the FMIF obtains the tunnel endpoint identifier (TEID) of the tunnel on the FMIF side and the TEID of the tunnel on the core network device side from a second relationship table according to the address of the fixed network device, and the second relationship table is used to save the correspondence between the address of the fixed network device, the TEID on the FMIF side, and the TEID on the core network device side; according to the encapsulation method corresponding to the tunnel, adds the packet header corresponding to the tunnel to the first uplink service packet to obtain a second uplink service packet, and the packet header includes the obtained TEID on the FMIF side and the TEID on the core network device side. Thus, the encapsulation of the first uplink service packet is realized.
[0023] In an alternative implementation, the FMIF detects whether the first uplink service packet is a packet of a mobile network service according to a preset field in the packet header of the first uplink service packet. If the first uplink service packet is a packet of a mobile network service, perform the operation of encapsulating the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain a second uplink service packet. Thus, it can be ensured that only the service packets of the mobile network are sent to the core network device.
[0024] In an alternative implementation, the FMIF receives a first downlink service packet sent by the core network device to the fixed network device; de-encapsulates the first downlink service packet according to the de-encapsulation method corresponding to the tunnel to obtain a second downlink service packet; and sends the second downlink service packet to the fixed network device through the data plane connection corresponding to the fixed network device between the FMIF and the BNG.
[0025] In an alternative implementation, the FMIF removes the packet header corresponding to the tunnel from the first downlink service packet according to the de-encapsulation method corresponding to the tunnel to obtain a second downlink service packet.
[0026] In an alternative implementation, the tunnel is a General Packet Radio Service Tunneling Protocol User Plane (GTP-U) tunnel.
[0027] In a fifth aspect, an embodiment of the present application provides a communication method. In this method, the core network device receives a second uplink service packet from the Fixed-Mobile Interworking Function (FMIF). The second uplink service packet is obtained by the FMIF encapsulating a first uplink service packet from the fixed device based on the encapsulation method corresponding to the tunnel. The tunnel is the tunnel corresponding to the fixed network device between the FMIF and the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The core network device de-encapsulates the second uplink service packet according to the de-encapsulation method corresponding to the tunnel to obtain the first uplink service packet. Since the FMIF encapsulates the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain the second uplink service packet, the core network device can receive the second uplink service packet sent by the FMIF through this tunnel, thereby enabling the fixed network device to send uplink service packets to a 5G core network or a core network higher than 5G.
[0028] In an alternative implementation, the core network device obtains a second downlink service packet to be sent to the fixed network device; encapsulates the second downlink service packet according to the encapsulation method corresponding to the tunnel to obtain a first downlink service packet; and sends the first downlink service packet to the FMIF through the tunnel. In this way, the core network device can send downlink service packets to the fixed network device.
[0029] In an alternative implementation, the second downlink service message includes the address of the fixed network device; the core network device obtains the tunnel endpoint identifier (TEID) on the FMIF side and the TEID on the core network device side of the tunnel from the correspondence table according to the address of the fixed network device, where the correspondence table is used to store the correspondence between the address of the fixed network device, the TEID on the FMIF side, and the TEID on the core network device side; according to the encapsulation method corresponding to the tunnel, a message header corresponding to the tunnel is added to the second downlink service message to obtain a first downlink service message, and the message header includes the obtained TEID on the FMIF side and the TEID on the core network device side. In this way, the encapsulation of the downlink service message is achieved.
[0030] In an alternative implementation, the tunnel is a General Packet Radio Service (GPRS) Tunnel Protocol User Plane (GTP-U) tunnel.
[0031] In a sixth aspect, the present application provides a communication method. In this method, an Access Gateway Function (AGF) receives a dialing message sent by a fixed network device; generates first authentication information of the fixed network device according to the dialing message, where the first authentication information includes an identifier of the fixed network device. The AGF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain second authentication information, where the control plane interface is an interface in the AGF for communicating with the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The AGF sends the second authentication information to the core network device through the control plane interface, and the second authentication information is used for the core network device to authenticate the fixed network device. Since the AGF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information, the second authentication information can be sent to the core network device of a 5G core network or a core network higher than 5G through the control plane interface, ensuring successful authentication of the fixed network device by the core network device.
[0032] In an alternative implementation, the control plane interface includes an N1 interface or an N2 interface, and the second authentication information is a Subscriber Concealed Identifier (SUCI), an encrypted Subscriber Permanent Identifier (SUPI), or a 5G Globally Unique Temporary UE Identifier (5G-GUTI).
[0033] In an alternative implementation, the AGF receives a confirmation message sent by the core network device after authentication is passed; and sends a session establishment request message to the core network device. The session establishment request message carries the identifier of the fixed network device, and is used for the core network device to allocate session information. The session information includes the address of the fixed network device, the tunnel endpoint identifier (TEID) of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The tunnel is the tunnel corresponding to the fixed network device between the AGF and the core network device. The AGF receives the session information sent by the core network device; and establishes the tunnel according to the session information. Since the AGF receives the session information and establishes the tunnel corresponding to the fixed network device between the AGF and the core network device according to the session information, the data plane connection between the fixed network device and the core network device is established, so that the fixed network device can use this data plane connection to transmit service packets.
[0034] In an alternative implementation, the AGF stores the correspondence between the address of the fixed network device, the TEID of the tunnel on the AGF side, and the TEID of the tunnel on the core network device side in a second relationship table, and the second relationship table is used for the AGF to send the uplink service packets of the fixed network device. In this way, the AGF can forward the service packets of the fixed network device through the second relationship table.
[0035] In an alternative implementation, the session information further includes the TEID of the tunnel on the AGF side.
[0036] In an alternative implementation, the AGF allocates the TEID of the tunnel on the AGF side and sends the TEID of the tunnel on the AGF side to the core network device. The TEID of the tunnel on the AGF side is stored by the core network device in a correspondence table, and the correspondence table includes the address of the fixed network device, the correspondence between the TEID of the tunnel on the AGF side and the TEID of the tunnel on the core network device side, and the correspondence table is used for the core network device to transmit the downlink service packets of the fixed network device.
[0037] In an alternative implementation, the AGF sends the session establishment request message to the core network device through the control plane interface, and the control plane interface includes the N1 interface or the N2 interface.
[0038] In a seventh aspect, the present application provides a communication method. In this method, an Access Gateway Function (AGF) receives a first uplink service message from the fixed network device; encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message. The tunnel is a tunnel corresponding to the fixed network device between the AGF and the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. Through the tunnel, the second uplink service message is sent to the core network device. Since the AGF encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain the second uplink service message, the second uplink service message can be sent to the core network device through this tunnel, thereby enabling the fixed network device to send uplink service messages to a 5G core network or a core network higher than 5G.
[0039] In an optional implementation, the first uplink service message includes the address of the fixed network device; the AGF obtains the Tunnel Endpoint Identifier (TEID) of the tunnel on the AGF side and the TEID of the tunnel on the core network device side from a second relationship table according to the address of the fixed network device. The second relationship table is used to store the correspondence between the address of the fixed network device, the TEID on the AGF side, and the TEID on the core network device side. The AGF adds a message header corresponding to the tunnel to the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message, and the message header includes the obtained TEID on the AGF side and the TEID on the core network device side. Thus, the encapsulation of the first uplink service message is achieved.
[0040] In an optional implementation, the AGF detects whether the first uplink service message is a message of a mobile network service according to a preset field in the message header of the first uplink service message. If the first uplink service message is a message of a mobile network service, perform the operation of encapsulating the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message. Thus, it can be ensured that only the service messages of the mobile network are sent to the core network device.
[0041] In an optional implementation, the AGF receives a first downlink service message sent by the core network device to the fixed network device; de-encapsulates the first downlink service message according to the de-encapsulation method corresponding to the tunnel to obtain a second downlink service message; and sends the second downlink service message to the fixed network device.
[0042] In an optional implementation, the AGF removes the message header corresponding to the tunnel from the first downlink service message according to the de-encapsulation method corresponding to the tunnel to obtain a second downlink service message.
[0043] In an alternative implementation, the tunnel is a General Packet Radio Service Tunneling Protocol User Plane (GTP-U) tunnel.
[0044] In an eighth aspect, the present application provides a core network device, including an Access and Mobility Management Function (AMF), a Session Management Function (SMF), and a User Plane Function (UPF).
[0045] The AMF is configured to receive a session establishment request message from a Fixed-Mobile Interworking Function (FMIF). The session establishment request message includes an identifier of a fixed network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The AMF allocates session information for the fixed network device according to the identifier of the fixed network device. The session information includes the address of the fixed network device, the Tunnel Endpoint Identifier (TEID) of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The tunnel is a tunnel corresponding to the fixed network device between the FMIF and the core network device.
[0046] The AMF is further configured to send the session information to the FMIF, and send the session information to the UPF through the SMF. The session information is used for the FMIF and the UPF to establish a data plane connection between the fixed network device and the core network device. Since the AMF allocates session information and sends the session information to the FMIF, the FMIF can establish a data connection corresponding to the fixed network device with a Broadband Network Gateway (BNG) and establish a tunnel corresponding to the fixed network device with the core network device according to the session information, thereby completing the establishment of the data plane connection between the fixed network device and the core network device. In this way, the fixed network device can use this data plane connection to transmit service packets. It can be understood that in this solution, an Access Gateway Function (AGF) can be used to replace the BNG and the FMIF, that is, the functions of the BNG and the FMIF are integrated in the AGF. Except that the interaction between the FMIF and the BNG becomes internal processing in the AGF, other processing procedures are similar and will not be elaborated.
[0047] In an alternative implementation, the AMF is configured to receive the second authentication information sent by the FMIF. The second authentication information is obtained by encapsulating the first authentication information according to the message format supported by the control plane interface in the FMIF. The control plane interface is the interface in the FMIF for communicating with the core network device. The first authentication information includes the identifier of the fixed network device. The AMF authenticates the fixed network device based on the second authentication information. Since the FMIF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information, the second authentication information can be sent to the 5G core network or a core network device higher than the 5G core network through the control plane interface, ensuring that the core network device can successfully authenticate the fixed network device.
[0048] In an alternative implementation, the session information further includes the TEID of the tunnel on the FMIF side.
[0049] In an alternative implementation, the AMF receives the TEID of the tunnel on the FMIF side sent by the FMIF and sends the TEID of the tunnel on the FMIF side to the UPF through the SMF; the TEID of the tunnel on the FMIF side is sent through the session establishment request message or is sent after the FMIF receives the session information.
[0050] In an alternative implementation, the UPF is configured to save the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side into a correspondence table, and the correspondence table is used by the UPF to transmit the downlink service packets of the fixed network device. In this way, the downlink service packets can be sent to the fixed network device through this correspondence table.
[0051] In a ninth aspect, the present application provides a core network device, including a core network control device and a user plane function UPF. The core network control device includes an access and mobility management function AMF and a session management function SMF.
[0052] The AMF is configured to receive a session establishment request message carrying the identifier of the fixed network device sent by the fixed-mobile interworking function FMIF. The communication network version to which the core network device belongs is a 5G communication network or a communication network higher than the 5G communication network. The AMF allocates session information for the fixed network device based on the identifier of the fixed network device. The session information includes the address of the fixed network device, the tunnel endpoint identifier TEID of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The tunnel is the tunnel corresponding to the fixed network device between the FMIF and the core network device.
[0053] The AMF is further configured to send the session information to the FMIF and send the session information to the UPF via the SMF. The session information is used by the FMIF and the UPF to establish a data plane connection between the fixed network device and the core network device. Since the AMF allocates the session information and sends it to the FMIF, the FMIF can establish a data connection corresponding to the fixed network device with the BNG and establish a tunnel corresponding to the fixed network device with the core network device according to the session information, thereby completing the establishment of the data plane connection between the fixed network device and the core network device. In this way, the fixed network device can use this data plane connection to transmit service packets. It can be understood that in this solution, the access gateway function (AGF) can be used to replace the BNG and the FMIF, that is, the functions of the BNG and the FMIF are integrated into the AGF. Except that the interaction between the FMIF and the BNG becomes internal processing in the AGF, the other processing procedures are similar and will not be elaborated here.
[0054] In an alternative implementation, the AMF is configured to receive the second authentication information sent by the FMIF. The second authentication information is obtained by encapsulating the first authentication information according to the message format supported by the control plane interface. The control plane interface is an interface in the FMIF for communicating with the core network device. The first authentication information includes the identifier of the fixed network device; and authenticate the fixed network device according to the second authentication information. Since the FMIF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information, the second authentication information can be sent to the 5G core network or a core network device higher than the 5G core network through the control plane interface, ensuring that the core network device can successfully authenticate the fixed network device.
[0055] In an alternative implementation, the session information further includes the TEID of the tunnel on the FMIF side.
[0056] In an alternative implementation, the AMF receives the TEID of the tunnel on the FMIF side sent by the FMIF;
[0057] The SMF is configured to send the TEID of the tunnel on the FMIF side to the UPF; the TEID of the tunnel on the FMIF side is sent through the session establishment request message or sent after the FMIF receives the session information.
[0058] Tenth aspect, an embodiment of the present application provides a communication device, which includes a receiving unit, a processing unit, and a transmitting unit. The receiving unit is configured to receive a dialing message sent by a fixed network device; the processing unit is configured to generate first authentication information of the fixed network device according to the dialing message, and the first authentication information includes an identifier of the fixed network device; the transmitting unit is configured to send an access request message to a fixed-mobile interworking function (FMIF), where the access request message carries the first authentication information, and the access request message is used for the FMIF to request a core network device to authenticate the fixed network device according to the first authentication information, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. Since the transmitting unit sends the authentication information of the fixed network device to the core network device through the FMIF, so that the core network device can authenticate the fixed network device, in this way, a 5G core network or a core network higher than 5G can authenticate the fixed network device.
[0059] In an optional implementation manner, the receiving unit, the processing unit, and the transmitting unit can also be used to perform the operations of the method in any possible implementation manner of the first aspect, which will not be described in detail here.
[0060] Eleventh aspect, an embodiment of the present application provides a communication device, which includes a receiving unit, a processing unit, and a transmitting unit. The receiving unit is configured to receive an access request message sent by a broadband network gateway (BNG) and carrying first authentication information of a fixed network device, where the first authentication information is generated by the BNG based on a dialing message sent by the fixed network device and the first authentication information includes an identifier of the fixed network device. The processing unit is configured to encapsulate the first authentication information according to a message format supported by a control plane interface to obtain second authentication information, where the control plane interface is an interface in the device for communicating with a core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The transmitting unit is configured to send the second authentication information to the core network device through the control plane interface, and the second authentication information is used for the core network device to authenticate the fixed network device. Since the processing unit encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information, in this way, the transmitting unit can send the second authentication information to a 5G core network or a core network device higher than 5G through the control plane interface, ensuring successful authentication of the fixed network device by the core network device.
[0061] In an optional implementation manner, the receiving unit, the processing unit, and the transmitting unit can also be used to perform the operations of the method in any possible implementation manner of the second aspect, which will not be described in detail here.
[0062] In a twelfth aspect, an embodiment of the present application provides a communication device, which includes a receiving unit, a processing unit, and a transmitting unit. The receiving unit is configured to receive a session establishment request message carrying an identifier of a fixed network device sent by a Fixed-Mobile Interworking Function (FMIF), and the communication network version to which the device belongs is a 5G communication network or a communication network higher than 5G. The processing unit is configured to allocate session information for the fixed network device according to the identifier of the fixed network device, where the session information includes an address of the fixed network device, a Tunnel Endpoint Identifier (TEID) of the tunnel on the device side, and tunnel parameters of the tunnel, and the tunnel is a tunnel corresponding to the fixed network device between the FMIF and the device. The transmitting unit is configured to send the session information to the FMIF, and the session information is used by the FMIF to establish a data plane connection between the fixed network device and the core network device. Since the processing unit allocates the session information and the transmitting unit sends the session information to the FMIF, the FMIF can establish a data connection corresponding to the fixed network device with a Broadband Network Gateway (BNG) and establish a tunnel corresponding to the fixed network device with the core network device according to the session information, so as to complete the establishment of the data plane connection between the fixed network device and the core network device, and thus the fixed network device can use the data plane connection to transmit service packets.
[0063] In an optional implementation manner, the receiving unit, the processing unit, and the transmitting unit may also be configured to perform operations of the method in any possible implementation manner of the third aspect, which will not be elaborated herein.
[0064] In a thirteenth aspect, an embodiment of the present application provides a communication device, which includes: a receiving unit, a processing unit, and a transmitting unit. The receiving unit is configured to receive a first uplink service packet from the fixed network device. The processing unit is configured to encapsulate the first uplink service packet according to an encapsulation method corresponding to a tunnel to obtain a second uplink service packet, where the tunnel is a tunnel corresponding to the fixed network device between the device and the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The transmitting unit is configured to send the second uplink service packet to the core network device through the tunnel. Since the processing unit encapsulates the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain the second uplink service packet, the transmitting unit can send the second uplink service packet to the core network device through the tunnel, so as to implement that the fixed network device can send uplink service packets to a 5G core network or a core network higher than 5G.
[0065] In an optional implementation manner, the receiving unit, the processing unit, and the transmitting unit may also be configured to perform operations of the method in any possible implementation manner of the fourth aspect, which will not be elaborated herein.
[0066] In a fourteenth aspect, an embodiment of the present application provides a communication device, the device includes: a receiving unit and a processing unit. The receiving unit is configured to receive a second uplink service message from a Fixed-Mobile Interworking Function (FMIF), where the second uplink service message is obtained by the FMIF encapsulating a first uplink service message from a fixed device based on an encapsulation method corresponding to a tunnel, the tunnel is a tunnel corresponding to the fixed network device between the FMIF and the device, and the communication network version to which the device belongs is a 5G communication network or a communication network higher than 5G. The processing unit is configured to de-encapsulate the second uplink service message according to the de-encapsulation method corresponding to the tunnel to obtain the first uplink service message. Since the FMIF encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain the second uplink service message, the processing unit can receive the second uplink service message sent by the FMIF through this tunnel, so as to realize that the fixed network device can send an uplink service message to a 5G core network or a core network higher than 5G.
[0067] In an alternative implementation, the receiving unit, the processing unit, and the sending unit can also be used to perform the operations of the method in any possible implementation manner of the fifth aspect, which will not be elaborated here.
[0068] In a fifteenth aspect, an embodiment of the present application provides a communication device, the device includes: a receiving unit, a processing unit, and a sending unit. The receiving unit is configured to receive a dialing message sent by a fixed network device; the processing unit is configured to generate first authentication information of the fixed network device according to the dialing message, where the first authentication information includes an identifier of the fixed network device. The processing unit is further configured to encapsulate the first authentication information according to a message format supported by a control plane interface to obtain second authentication information, the control plane interface is an interface in the device for communicating with a core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The sending unit is configured to send the second authentication information to the core network device through the control plane interface, and the second authentication information is used for the core network device to authenticate the fixed network device. Since the processing unit encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information, the sending unit can send the second authentication information to a 5G core network or a core network device higher than 5G through the control plane interface, ensuring successful authentication of the fixed network device by the core network device.
[0069] In an alternative implementation, the receiving unit, the processing unit, and the sending unit can also be used to perform the operations of the method in any possible implementation manner of the sixth aspect, which will not be elaborated here.
[0070] In a sixteenth aspect, an embodiment of the present application provides a communication device, which includes: a receiving unit, a processing unit, and a sending unit. The receiving unit is configured to receive a first uplink service message from the fixed network device. The processing unit is configured to encapsulate the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message. The tunnel is a tunnel corresponding to the fixed network device between the device and the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The sending unit is configured to send the second uplink service message to the core network device through the tunnel. Since the processing unit encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain the second uplink service message, the sending unit can send the second uplink service message to the core network device through this tunnel, thereby enabling the fixed network device to send an uplink service message to a 5G core network or a core network higher than 5G.
[0071] In an optional implementation manner, the receiving unit, the processing unit, and the sending unit can also be used to perform the operations of the method in any possible implementation manner of the seventh aspect, which will not be elaborated here.
[0072] In a seventeenth aspect, an embodiment of the present application provides a communication device, which includes: a processor and a memory, and the processor is connected to the memory; the memory stores one or more programs, and the one or more programs are configured to be executed by the processor, and the one or more programs include instructions for performing the method of the first aspect or any optional implementation manner of the first aspect.
[0073] In an eighteenth aspect, an embodiment of the present application provides a communication device, which includes: a processor and a memory, and the processor is connected to the memory; the memory stores one or more programs, and the one or more programs are configured to be executed by the processor, and the one or more programs include instructions for performing the method of the second aspect, the fourth aspect, any optional implementation manner of the second aspect, or any optional implementation manner of the fourth aspect.
[0074] In a nineteenth aspect, an embodiment of the present application provides a communication device, which includes: a processor and a memory, and the processor is connected to the memory; the memory stores one or more programs, and the one or more programs are configured to be executed by the processor, and the one or more programs include instructions for performing the method of the third aspect, the fifth aspect, any optional implementation manner of the third aspect, or any optional implementation manner of the fifth aspect.
[0075] In a twentieth aspect, an embodiment of the present application provides a communication device, the device comprising: a processor and a memory, the processor being connected to the memory; the memory storing one or more programs, the one or more programs being configured to be executed by the processor, the one or more programs including instructions for performing the methods of any optional implementation manner of the sixth aspect, the seventh aspect, the sixth aspect, or any optional implementation manner of the seventh aspect.
[0076] In a twenty - first aspect, an embodiment of the present application provides a non - volatile computer - readable storage medium for storing a computer program, the computer program being loaded by a processor to execute the instructions of the methods of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, the sixth aspect, the seventh aspect, any optional implementation manner of the first aspect, any optional implementation manner of the second aspect, any optional implementation manner of the third aspect, any optional implementation manner of the fourth aspect, any optional implementation manner of the fifth aspect, any optional implementation manner of the sixth aspect, or any optional implementation manner of the seventh aspect.
[0077] In a twenty - second aspect, an embodiment of the present application provides a chip, the chip comprising programmable logic circuits and / or program instructions, which are used to implement the methods of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, the sixth aspect, the seventh aspect, any optional implementation manner of the first aspect, any optional implementation manner of the second aspect, any optional implementation manner of the third aspect, any optional implementation manner of the fourth aspect, any optional implementation manner of the fifth aspect, any optional implementation manner of the sixth aspect, or any optional implementation manner of the seventh aspect when the chip runs. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] Figure 1 is a schematic diagram of a network architecture provided by an embodiment of the present application;
[0079] Figure 2 is a flowchart of a communication method provided by an embodiment of the present application;
[0080] Figure 3 is a schematic diagram of a network architecture provided by an embodiment of the present application;
[0081] Figure 4 is a flowchart of another communication method provided by an embodiment of the present application;
[0082] Figure 5 is a schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0083] Figure 6 is a schematic diagram of the structure of another communication device provided by an embodiment of the present application;
[0084] Figure 7 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0085] Figure 8 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0086] Figure 9 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0087] Figure 10 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0088] Figure 11 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0089] Figure 12 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0090] Figure 13 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0091] Figure 14 It is a schematic structural diagram of another communication device provided by an embodiment of the present application;
[0092] Figure 15 It is a schematic structural diagram of another communication device provided by an embodiment of the present application. Detailed implementation manners
[0093] The following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0094] See Figure 1 , an embodiment of the present application provides a network architecture, including:
[0095] Fixed network device 1, broadband network gateway (BNG) 2, fixed mobile interworking function (FMIF) 3, and core network device 4. The core network device 4 is located in the core network. The core network device 4 can be a network element that implements the access mobility management function (AMF) function, session management function (SMF) function, and user plane function (UPF) function. The core network device 4 includes virtual machines for implementing the AMF function, virtual machines for implementing the SMF function, and virtual machines for implementing the UPF function. These three virtual machines are respectively called AMF, SMF, and UPF. Alternatively, the core network device 4 can include a core network control device for implementing the AMF function and the SMF function and a UPF. In this case, the UPF can be a physical device that can implement the UPF function. The core network control device for implementing the AMF function and the SMF function includes a virtual machine for implementing the AMF function and a virtual machine for implementing the SMF function. These two virtual machines are respectively called AMF and SMF.
[0096] The communication network version to which the core network device 4 belongs is a 5G communication network or a communication network higher than 5G. The core network can be the core network of a 5G communication network or the core network of a communication network higher than 5G. The fixed network device 1 can be a fixed network residential gateway (FN-RG), etc.
[0097] The FMIF 3 can communicate with the core network device 4 through a control plane interface and a data plane interface. The control plane interface can include an N1 interface or an N2 interface, and the data plane interface can be an N3 interface.
[0098] When the core network device 4 is a network element including AMF, SMF, and UPF, the FMIF 3 can communicate with the AMF in the core network device 4 through the control plane interface, and the FMIF 3 can communicate with the UPF in the core network device 4 through the data plane interface. The SMF and the UPF communicate using the interface between the control plane and the data plane.
[0099] When the core network device 4 includes a core network control device and a UPF, the FMIF 3 can communicate with the AMF in the core network control device through the control plane interface, and the FMIF 3 can communicate with the UPF through the data plane interface. The SMF in the core network control device and the UPF communicate using the interface between the control plane and the data plane.
[0100] Optionally, the interface between the above control plane and data plane may be an N4 interface or the like.
[0101] See Figure 1 , BNG2 includes a Point-to-Point Protocol over Ethernet / Dynamic Host Configuration Protocol (PPPoE / DHCP) module 21, an Authentication, Authorization, Accounting (AAA) module 22, and a session service forwarding module 23. FMIF3 includes an encapsulation / de-encapsulation module 31 and a control plane interface adapter 32, and may further include a service verification module 33.
[0102] The fixed network device 1 may request the core network device 4 to authenticate it through BNG2 and FMIF3. The authentication process may be as follows:
[0103] See Figure 2 For the process of steps 201 to 207, the fixed network device 1 sends a dialing message to BNG2. BNG2 receives the dialing message, generates first authentication information of the fixed network device 1 based on the dialing message. The first authentication information includes the identifier of the fixed network device, and sends an access request message to FMIF3. The access request message carries the first authentication information. FMIF3 encapsulates the first authentication information according to the message format supported by the control plane interface to obtain second authentication information, and sends the second authentication information to the core network device 4 through the control plane interface; the core network device 4 authenticates the fixed network device 1 according to the second authentication information. After authenticating the fixed network device 1 successfully, it sends a confirmation message to FMIF3; FMIF3 then sends the confirmation message to the fixed network device 1 through BNG2.
[0104] In a specific implementation example, the identifier of the fixed network device may be a Line ID. The first authentication information includes the user name information of the fixed network device 1, and may further include the password information of the fixed network device 1. The user name information includes the identifier of the fixed network device 1. Both the user name information and the password information of the fixed network device 1 are used by the core network device 4 to authenticate the fixed network device 1.
[0105] The control plane interface may include an N1 interface or an N2 interface. Assume that the control plane interface is the N1 interface. The FMIF3 encapsulates the first authentication information according to the message format supported by the N1 interface to obtain the second authentication information. The second authentication information may be a subscriber concealed identifier (SUCI), an encrypted subscriber permanent identifier (SUPI), or a 5G globally unique temporary UE identity (5G-GUTI), etc. SUCI, SUPI, or 5G-GUTI are information defined by 3GPP for core network authentication.
[0106] In a specific implementation example, the fixed network device 1 accesses the BNG2 through the access network, and there is a connection between the fixed network device 1 and the BNG2. The PPPoE / DHCP module 21 in the BNG2 receives the dialing packet sent by the fixed network device 1 through this connection, generates the first authentication information based on the dialing packet, and sends the first authentication information to the AAA module 22 of the BNG2. The AAA module 22 sends an access request message carrying the first authentication information to the FMIF3. The control plane interface adapter 32 of the FMIF3 receives this access request message, encapsulates the first authentication information carried in this access request message according to the message format supported by the control plane interface to obtain the second authentication information, and sends the second authentication information to the core network device 4 through the control plane interface.
[0107] Regarding the detailed process of authenticating the fixed network device 1, reference can also be made to the relevant content in steps 201 to 207 in the subsequent Figure 2 illustrated embodiment, and no detailed description will be given here.
[0108] After the core network device 4 authenticates the fixed network device 1 successfully, a data plane connection can be established between the fixed network device 1 and the core network device 4. In a specific implementation example, the process of establishing this data plane connection may be:
[0109] See Figure 2In steps 208 to 211, FMIF3 sends a session establishment request message to core network device 4 through the control plane interface. The session establishment request message carries the identifier of fixed network device 1. Core network device 4 receives the session establishment request message, allocates session information for fixed network device 1 according to the identifier of fixed network device 1 carried in the session establishment request message. The session information includes the address of fixed network device 1, the tunnel endpoint identifier (TEID) of the tunnel on the core network device side, and tunnel parameters of the tunnel, etc. The tunnel parameters may include quality of service (QoS) parameters, etc. Core network device 4 sends the session information to FMIF. The tunnel is the tunnel corresponding to fixed network device 1 between FMIF3 and core network device 4. FMFI3 receives the session information, and establishes the tunnel and establishes a data plane connection corresponding to the fixed network device between FMIF3 and BNG2 according to the session information.
[0110] It can be understood that after receiving the confirmation message, FMIF3 can actively send a session establishment request message to core network device 4 to request the establishment of a data plane connection between fixed network device 1 and core network device 4; or, after receiving the confirmation message, fixed network device 1 sends a session establishment request message to FMIF3 through BNG2; FMIF3 receives the session establishment request message and sends the session establishment request message to core network device 4.
[0111] The tunnel corresponding to fixed network device 1 between FMIF3 and core network device 4 can be a general packet radio service tunnelling protocol user plane (GTP-U) tunnel, etc.
[0112] The process of establishing a data plane connection corresponding to fixed network device 1 between FMIF3 and BNG2 and the process of establishing a tunnel corresponding to fixed network device 2 between FMIF3 and core network device 4 can refer to the relevant content in steps 208 to 211 in the following Figure 2 illustrated embodiments and will not be elaborated here.
[0113] After establishing a data plane connection between fixed network device 1 and core network device 4 located in the core network, fixed network device 1 can send an upstream service packet to core network device 4, and core network device 4 then forwards the upstream service packet; or, core network device 4 obtains a downstream service packet of fixed network device 1 and sends the downstream service packet to fixed network device 1. In a specific embodiment, the implementation process is as follows:
[0114] See Figure 2In steps 212 to 216, for an upstream service message, the fixed network device 1 sends a first upstream service message to the BNG2. The BNG2 receives the first upstream service message and sends the first upstream service message to the FMIF3 through the data plane connection corresponding to the fixed network device 1 between the BNG2 and the FMIF3. The FMIF3 receives the first upstream service message, encapsulates the first upstream service message according to the encapsulation method corresponding to the tunnel to obtain a second upstream service message, and sends the second upstream service message to the core network device 4 through this tunnel. This tunnel is the tunnel corresponding to the fixed network device 1 between the FMIF3 and the core network device 4. The core network device 4 receives the second upstream service message, decapsulates the second upstream service message according to the decapsulation method corresponding to this tunnel to obtain the first upstream service message, and forwards the first upstream service message. For example, the core network device 4 can forward the first upstream service message to the data network.
[0115] In a specific embodiment, during the process of transmitting the first upstream service message mentioned above, the session service forwarding module 23 of the BNG2 can receive the first upstream service message, and detect whether the first upstream service message is a message for the mobile network service according to a preset field in the message header of the first upstream service message. If the first upstream service message is a message for the mobile network service, the BNG2 sends the first upstream service message to the FMIF3 through the data plane connection corresponding to the fixed network device 1 between the BNG2 and the FMIF3. The encapsulation and decapsulation module 31 in the FMIF3 receives the first upstream service message, and can verify whether the first upstream service message is a message for the mobile network service through the service verification module 33. If the first upstream service message is a message for the mobile network service, the first upstream service message is encapsulated according to the encapsulation method corresponding to the tunnel to obtain a second upstream service message. If the first upstream service message is not a message for the mobile network service, the first upstream service message is discarded. This tunnel is the tunnel corresponding to the fixed network device 1 between the FMIF3 and the core network device 4.
[0116] In a specific embodiment, refer to Figure 2 In steps 217 to 221, for a downstream service message, the core network device 4 obtains a second downstream service message to be sent to the fixed network device 1, encapsulates the second downstream service message according to the encapsulation method corresponding to the tunnel to obtain a first downstream service message, and sends the first downstream service message to the FMIF3 through this tunnel. This tunnel is the tunnel corresponding to the fixed network device 1 between the FMIF3 and the core network device 4. The FMIF3 receives the first downstream service message, decapsulates the first downstream service message according to the decapsulation method corresponding to this tunnel to obtain the second downstream service message, and sends the second downstream service message to the BNG2 through the data plane connection corresponding to the fixed network device 1 between the BNG2 and the FMIF3. The BNG2 receives the second downstream service message, sends the second downstream service message to the fixed network device 1, and the fixed network device 1 receives the second downstream service message.
[0117] In the process of transmitting the second downlink service message as described above, the encapsulation and decapsulation module 31 in FMIF3 receives the first downlink service message and decapsulates the first downlink service message according to the decapsulation method corresponding to the tunnel to obtain the second downlink service message.
[0118] See Figure 2 that an embodiment of the present application provides a communication method, which can be applied to the network architecture shown in Figure 1 This method can be used for a fixed network device to request a core network device to authenticate the fixed network device; after the authentication of the fixed network device is passed, this method can be used to establish a data plane connection between the fixed network device and the core network; after the data plane connection is established, this method can be used to transmit the uplink service message or the downlink service message of the fixed network device.
[0119] That is to say: this communication method includes a communication method for authenticating a fixed network device, a communication method for establishing a session connection between a fixed network device and a core network device, a communication method for transmitting an uplink service message, and a communication method for transmitting a downlink service message.
[0120] See Figure 2 that the communication method for authenticating a fixed network device includes the following steps 201 to 207. The steps 201 to 207 are respectively:
[0121] Step 201: The fixed network device sends a dialing message to the BNG.
[0122] The fixed network device accesses the BNG through the access network, that is, there is a connection between the fixed network device and the BNG, so the fixed network device can send a dialing message to the BNG through this connection.
[0123] This dialing message may include the identifier of the fixed network device or may not include the identifier of the fixed network device. The identifier of the fixed network device may be a line identifier (Line ID), etc.
[0124] Step 202: The BNG receives this dialing message and generates the first authentication information of the fixed network device based on this dialing message. The first authentication information includes the identifier of the fixed network device.
[0125] In this step, when the dialing message includes the identifier of the fixed network device, the BNG can extract the identifier of the fixed network device from this dialing message and generate the first authentication information of the fixed network device based on the identifier of the fixed network device. Or,
[0126] when the dialing message does not include the identifier of the fixed network device, the BNG can generate the identifier of the fixed network device according to the preset field in this dialing message and generate the first authentication information of the fixed network device based on the identifier of the fixed network device.
[0127] The preset fields of the dialing message may include at least one of DHCPv4 option 82 exchange, PPPoE circuit and remote attribute value pair insertion, LDRA function DHCPv6 option 18 on the access node, or Line ID Option (LIO) in the RS message.
[0128] The operation for the BNG to generate the first authentication information may be: The BNG generates the username information of the fixed network device based on the identifier of the fixed network device, the username information includes the identifier of the fixed network device, and the first authentication information includes the username information. The BNG may also generate the password information of the fixed network device, and the first authentication information may also include the password information.
[0129] The BNG includes a PPPoE / DHCP module and an AAA module. In this step, the PPPoE / DHCP module may receive the dialing message sent by the fixed network device, extract the identifier of the fixed network device from the dialing message or generate the identifier of the fixed network device according to the preset fields in the dialing message, generate the first authentication information of the fixed network device based on the identifier of the fixed network device, and send the first authentication information to the AAA module.
[0130] Step 203: The BNG sends an access request message to the FMIF, and the access request message carries the first authentication information.
[0131] The BNG may communicate with the FMIF using communication protocols such as the remote authentication dial in user service (Radius) protocol or the Diameter protocol. The access request message may be a Radius protocol access request message or a Diameter protocol access request message, etc.
[0132] In the case where the BNG communicates with the FMIF using the Radius protocol, the BNG sends a Radius protocol access request message to the FMIF, and the Radius protocol access request message carries the first authentication information. In the case where the BNG communicates with the FMIF using the Diameter protocol, the BNG sends a Diameter protocol access request message to the FMIF, and the Diameter protocol access request message carries the first authentication information.
[0133] The BNG includes a PPPoE / DHCP module and an AAA module. In this step, the AAA module may receive the first authentication information sent by the PPPoE / DHCP module and send an access request message carrying the first authentication information to the FMIF.
[0134] Step 204: The FMIF receives the access request message and encapsulates the first authentication information carried in the access request message according to the message format supported by the control plane interface to obtain the second authentication information.
[0135] The FMIF includes a control plane interface, which is an interface in the FMIF for communicating with core network devices. When the core network device is a network element including AMF, SMF, and UPF, this control plane interface is the interface in the FMIF for communicating with the AMF in the core network device. When the core network device includes a core network control device and UPF, this control plane interface is the interface in the FMIF for communicating with the AMF in the core network control device.
[0136] This control plane interface can be the N1 interface or the N2 interface. Assuming that the control plane interface is the N1 interface, the second authentication information can be SUCI, SUPI, or 5G-GUTI. That is, the FMFI can encapsulate the first authentication information into SUCI, SUPI, or 5G-GUTI according to the message format supported by the N1 interface. SUCI, SUPI, or 5G-GUTI are information defined by 3GPP for core network authentication.
[0137] The FMIF includes a control plane interface adapter. In this step, the control plane interface adapter can receive the access request message and encapsulate the first authentication information carried in the access request message according to the message format supported by the control plane interface to obtain the second authentication information.
[0138] Step 205: The FMIF sends the second authentication information to the core network device through this control plane interface.
[0139] Since the second authentication information is encapsulated according to the message format supported by the control plane interface, the FMIF can send the second authentication information to the core network device through the control plane interface, thus ensuring that the second authentication information can be successfully sent to the core network device to provide guarantee for the core network device to authenticate the fixed network device.
[0140] For example, if the control plane interface is the N1 interface and the second authentication information is SUCI, SUPI, or 5G-GUTI, when the core network device is a network element including AMF, SMF, and UPF, the FMIF sends SUCI, SUPI, or 5G-GUTI to the core network device through the N1 interface. When the core network device includes a core network control device and UPF, the FMIF sends SUCI, SUPI, or 5G-GUTI to the core network control device through the N1 interface.
[0141] Step 206: The core network device receives the second authentication information, authenticates the fixed network device according to the second authentication information, and after successfully authenticating the fixed network device, sends a confirmation message to the FMIF.
[0142] In this step, when the core network device is a network element including an AMF, an SMF, and a UPF, the AMF in the core network device authenticates the fixed network device in the Authentication Server Function (AUSF) according to the second authentication information. After the authentication of the fixed network device is passed, an acknowledgment message is sent to the FMIF. When the core network device includes a core network control device and a UPF, the AMF in the core network control device authenticates the fixed network device according to the second authentication information. After the authentication of the fixed network device is passed, an acknowledgment message is sent to the FMIF.
[0143] Step 207: The FMIF receives the acknowledgment message through the control plane interface and sends the acknowledgment message to the fixed network device.
[0144] The control plane interface can be an N1 interface or an N2 interface, etc. The FMIF can receive the acknowledgment message through the N1 interface or the N2 interface and send the acknowledgment message to the BNG. The BNG receives the acknowledgment message and forwards the acknowledgment message to the fixed network device. The fixed network device receives the acknowledgment message to complete the authentication of the fixed network device.
[0145] After completing the authentication of the fixed network device, a data plane connection can be established between the fixed network device and the core network device. The data plane connection between the fixed network device and the core network device includes the data plane connection between the fixed network device and the BNG, the data plane connection between the BNG and the FMIF corresponding to the fixed network device, and the tunnel between the FMIF and the core network device corresponding to the fixed network device. When the core network device is a network element including an AMF, an SMF, and a UPF, the tunnel between the FMIF and the core network device corresponding to the fixed network device is the tunnel between the FMIF and the UPF in the core network device corresponding to the fixed network device. When the core network device includes a core network control device and a UPF, the tunnel between the FMIF and the core network device corresponding to the fixed network device is the tunnel between the FMIF and the UPF corresponding to the fixed network device.
[0146] Since the data plane connection between the fixed network device and the BNG already exists, establishing the data plane connection between the BNG and the FMIF corresponding to the fixed network device and the tunnel between the FMIF and the core network device corresponding to the fixed network device completes the establishment of the data plane connection between the fixed network device and the core network device. The data plane connection between the fixed network device and the core network device can be established through the following steps 208 to 211. The steps 208 to 211 are respectively:
[0147] Step 208: The FMIF sends a session establishment request message to the core network device, and the session establishment request message includes the identifier of the fixed network device.
[0148] After receiving the confirmation message, FMIF can actively send a session establishment request message to the core network device to request the establishment of a data plane connection between the fixed network device 1 and the core network device; alternatively, after receiving the confirmation message, the fixed network device sends a session establishment request message to FMIF through the BNG; FMIF receives the session establishment request message and sends the session establishment request message to the core network device.
[0149] When the core network device is a network element including AMF, SMF, and UPF, FMIF sends the session establishment request message to the AMF in the core network device.
[0150] When the core network device includes a core network control device and UPF, FMIF sends the session establishment request message to the core network control device, and in implementation, FMIF sends the session establishment request message to the AMF in the core network control device.
[0151] FMIF sends the session establishment request message to the core network device through the control plane interface, and the control plane interface can be the N1 interface or the N2 interface, that is, FMIF can send the session establishment request message to the core network device through the N1 interface or the N2 interface.
[0152] In this step, FMIF can also allocate the TEID of the tunnel on the FMIF side, and the session establishment request message can also carry the TEID of the tunnel on the FMIF side, and the tunnel is the tunnel between FMIF and the core network device.
[0153] Step 209: The core network device receives the session establishment request message, and allocates session information of the fixed network device according to the identifier of the fixed network device included in the session establishment request message. The session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, and the tunnel parameters of the tunnel, etc. The tunnel is the tunnel corresponding to the fixed network device between FMIF and the core network device.
[0154] When the core network device is a network element including AMF, SMF, and UPF, in this step, the AMF in the core network device receives the session establishment request message and allocates session information of the fixed network device according to the identifier of the fixed network device included in the session establishment request message.
[0155] When the core network device includes a core network control device and UPF, in this step, the AMF in the core network control device receives the session establishment request message and allocates session information of the fixed network device according to the identifier of the fixed network device included in the session establishment request message.
[0156] The session information allocated by the core network device may also include the TEID of the tunnel on the FMIF side. Among them, the above tunnel parameters may include parameters such as the Quality of Service Flow ID (QFI).
[0157] Step 210: The core network device sends the session information to the FMIF.
[0158] When the core network device is a network element including the AMF, SMF, and UPF, the AMF in the core network device sends the session information to the FMIF. In the core network device, the AMF also transmits the session information to the SMF, and the SMF transmits the session information to the UPF through the interface between the control plane and the data plane.
[0159] When the core network device includes a core network control device and a UPF, the AMF in the core network control device sends the session information to the FMIF. In the core network control device, the AMF also transmits the session information to the SMF, and the SMF in the core network control device sends the session information to the UPF through the interface between the control plane and the data plane.
[0160] The interface between the control plane and the data plane includes the N4 interface.
[0161] Step 211: The FMIF receives the session information and establishes a data plane connection between the BNG and the FMIF corresponding to the fixed network device and a tunnel between the FMIF and the core network device corresponding to the fixed network device according to the session information.
[0162] When establishing the data plane connection, it needs to be completed jointly by the FMIF and the BNG. In implementation, the FMIF sends the address of the fixed network device to the BNG and saves the corresponding relationship between the address of the fixed network device and the address of the BNG in the first relationship table; the BNG receives the address of the fixed network device and saves the corresponding relationship between the address of the fixed network device and the address of the FMIF in the corresponding relationship table to implement the establishment of the data plane connection.
[0163] When establishing the tunnel, it needs to be completed jointly by the FMIF and the core network device. In implementation:
[0164] When the session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, and the tunnel parameters of the tunnel, for the FMIF side, the FMIF allocates the TEID of the tunnel on the FMIF side, allocates resources for the tunnel according to the tunnel parameters, where the resources can be resources such as ports and bandwidth, binds the resources to the TEID of the tunnel on the FMIF side, sends the TEID of the tunnel on the FMIF side to the core network device, and saves the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side in the second relationship table.
[0165] When the core network device is a network element including AMF, SMF, and UPF, the FMIF sends the TEID of the tunnel on the FMIF side to the AMF in the core network device. When the core network device includes a core network control device and UPF, the FMIF sends the TEID of the tunnel on the FMIF side to the AMF in the core network control device.
[0166] When the session information may further include the TEID of the tunnel on the FMIF side, in this case, the FMIF does not need to allocate the TEID of the tunnel on the FMIF side, nor does it need to send the TEID of the tunnel on the FMIF side to the core network device.
[0167] For the core network device side, when the core network device is a network element including AMF, SMF, and UPF, and when the session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, and the tunnel parameters of the tunnel, the AMF in the core network device receives the TEID of the tunnel on the FMIF side sent by the FMIF, transmits the TEID of the tunnel on the FMIF side to the SMF, and the SMF transmits the TEID of the tunnel on the FMIF side to the UPF through the interface between the control plane and the data plane. The UPF in the core network device receives the session information, as well as receives the TEID of the tunnel on the FMIF side, allocates resources for the tunnel according to the tunnel parameters, where the resources can be resources such as ports and bandwidth, binds the resources to the TEID of the tunnel on the core network device side, saves the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side in the correspondence table, and realizes the establishment of the tunnel. It can be understood that in this embodiment, after the AMF in the core network device receives the TEID of the tunnel on the FMIF side sent by the FMIF, it can carry the address of the fixed network device, the TEID of the tunnel on the core network device side, the TEID of the tunnel on the FMIF side, and the tunnel parameters of the tunnel in the session information and send it to the SMF, and the SMF transmits the session information to the UPF through the interface between the control plane and the data plane.
[0168] When the core network device includes a core network control device and a UPF, and the session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, and the tunnel parameters of the tunnel, the AMF in the core network control device receives the TEID of the tunnel on the FMIF side sent by the FMIF, transmits the TEID of the tunnel on the FMIF side to the SMF, and the SMF sends the TEID of the tunnel on the FMIF side to the UPF through the interface between the control plane and the data plane. The UPF receives the session information and the TEID of the tunnel on the FMIF side, allocates resources for the tunnel according to the tunnel parameters. The resources can be resources such as ports and bandwidth, binds the resources to the TEID of the tunnel on the core network device side, and saves the corresponding relationship between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side in the corresponding relationship table, so as to establish the tunnel. It can be understood that in this embodiment, after the AMF in the core network control device receives the TEID of the tunnel on the FMIF side sent by the FMIF, it can carry the address of the fixed network device, the TEID of the tunnel on the core network device side, the TEID of the tunnel on the FMIF side, and the tunnel parameters of the tunnel in the session information and send it to the SMF, and the SMF transmits the session information to the UPF through the interface between the control plane and the data plane.
[0169] When the session information can also include the TEID of the tunnel on the FMIF side, in this step, the core network device or the core network control device does not need to receive the TEID of the tunnel on the FMIF side sent by the FMIF.
[0170] Among them, the FMIF can also allocate the TEID of the tunnel on the FMIF side before sending the session establishment request message, so that the session establishment request message can carry the TEID of the tunnel on the FMIF side. In this case, the FMIF does not need to allocate the TEID of the tunnel on the FMIF side, nor does it need to send the TEID of the tunnel on the FMIF side to the core network device.
[0171] After establishing the data plane connection corresponding to the fixed network device between the BNG and the FMIF and the tunnel corresponding to the fixed network device between the FMIF and the core network device, since there is a data plane connection between the fixed network device and the FMIF, the data plane connection between the fixed network device and the core network device is completed.
[0172] The fixed network device can send the uplink service packet through its data plane connection with the core network device, and can send the uplink service packet through the following steps 212 to 216. The steps 212 to 216 are respectively:
[0173] Step 212: The fixed network device sends a first upstream service message to the BNG. The first upstream service message includes the address of the fixed network device.
[0174] The header of the first upstream service message includes a source address field, and the content carried in the source address field is the address of the fixed network device.
[0175] Step 213: The BNG receives the first upstream service message and sends the first upstream service message to the FMIF through the data plane connection between the BNG and the FMIF.
[0176] The BNG stores a correspondence table. The BNG extracts the address of the fixed network device from the first upstream service message, obtains the corresponding address of the FMIF from the correspondence table according to the address of the fixed network device, and sends the first upstream service message to the FMIF according to the address of the FMIF.
[0177] Only the messages belonging to the mobile network service need to be sent to the core network. In this step, before sending the first upstream service message to the FMIF, the BNG can also detect whether the first upstream service message is a message of the mobile network service. If the first upstream service message is a message of the mobile network service, the first upstream service message is sent to the FMIF through the data plane connection between the BNG and the FMIF.
[0178] The BNG can detect whether the first upstream service message is a message of the mobile network service according to a preset field in the header of the first upstream service message.
[0179] The preset field can be a Service Virtual Local Area Network (S-VLAN) field, etc.
[0180] If the first upstream service message is a message of the mobile network service, the preset field in the header of the first upstream service message carries preset content. In this step, the BNG can extract the field content included in the preset field in the header of the first upstream service message. If the field content is the preset content, it is detected that the first upstream service message is a message of the mobile network service. If the field content is not the preset content, it is detected that the first upstream service message is not a message of the mobile network service.
[0181] The BNG includes a session service forwarding module. In this step, the session service forwarding module can detect whether the first upstream service message is a message of the mobile network service. If the first upstream service message is a message of the mobile network service, the first upstream service message is sent to the FMIF through the data plane connection corresponding to the fixed network device between the BNG and the FMIF.
[0182] Step 214: FMIF receives the first uplink service message, encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel, and obtains the second uplink service message. The tunnel is the tunnel corresponding to the fixed network device between FMIF and the core network device.
[0183] FMIF receives the first uplink service message, extracts the address of the fixed network device from the first uplink service message, obtains the TEID on the FMIF side and the TEID on the core network device side of the tunnel corresponding to the fixed network device from the second relationship table according to the address of the fixed network device, and adds the message header corresponding to the tunnel to the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain the second uplink service message. The message header includes the obtained TEID on the FMIF side and the TEID on the core network device side.
[0184] Before performing the operation of encapsulating the first uplink service message, FMIF can detect whether the first uplink service message is a message of the mobile network service. If the first uplink service message is a message of the mobile network service, the operation of encapsulating the first uplink service message is performed.
[0185] FMIF can detect whether the first uplink service message is a message of the mobile network service according to the preset field in the message header of the first uplink service message.
[0186] In this step, FMIF can extract the field content included in the preset field in the message header of the first uplink service message. If the field content is the preset content, it is detected that the first uplink service message is a message of the mobile network service. If the field content is not the preset content, it is detected that the first uplink service message is not a message of the mobile network service.
[0187] FMIF includes a service verification module and an encapsulation / de-encapsulation module. The service verification module can detect whether the first uplink service message is a message of the mobile network service. If the first uplink service message is a message of the mobile network service, the encapsulation / de-encapsulation module performs the operation of encapsulating the first uplink service message. If the first uplink service message is not a message of the mobile network service, the first uplink service message is discarded.
[0188] Step 215: FMIF sends the second uplink service message to the core network device through the tunnel.
[0189] FMIF includes a data plane interface, which is an interface in FMIF for communicating with the core network device. FMIF can use the data plane interface to send the second uplink service message to the core network device through the tunnel.
[0190] In the case where the core network device is a network element including an AMF, an SMF, and a UPF, the FMIF may use a data plane interface to send a second uplink service message to the UPF in the core network device through this tunnel.
[0191] In the case where the core network device includes a core network control device and a UPF, the FMIF may use a data plane interface to send a second uplink service message to the UPF through this tunnel.
[0192] The data plane interface may be an N4 interface or the like.
[0193] Step 216: The core network device receives the second uplink service message and, according to the decapsulation method corresponding to this tunnel, decapsulates the second uplink service message to obtain a first uplink service message.
[0194] In this step, the core network device receives the second uplink service message and, according to the decapsulation method corresponding to this tunnel, removes the message header corresponding to this tunnel from the second uplink service message to obtain a first uplink service message.
[0195] After obtaining the first uplink service message, the core network device may forward the first uplink service message to the data network.
[0196] In the case where the core network device is a network element including an AMF, an SMF, and a UPF, the UPF in the core network device receives the second uplink service message and, according to the decapsulation method corresponding to this tunnel, removes the message header corresponding to this tunnel from the second uplink service message to obtain a first uplink service message.
[0197] In the case where the core network device includes a core network control device and a UPF, the UPF receives the second uplink service message and, according to the decapsulation method corresponding to this tunnel, removes the message header corresponding to this tunnel from the second uplink service message to obtain a first uplink service message.
[0198] The core network device may send a downlink service message through the data plane connection between it and the fixed network device, and may send an uplink service message through the following steps 217 to 221. These steps 217 to 221 are respectively:
[0199] Step 217: The core network device obtains a second downlink service message to be sent to the fixed network device, and according to the encapsulation method corresponding to the tunnel, encapsulates the second downlink service message to obtain a first downlink service message. This tunnel is the tunnel corresponding to the fixed network device between the FMIF and the core network device.
[0200] The core network device receives a second downlink service message from the data network. The second downlink service message includes the address of the fixed network device. The message header of the second downlink service message includes a destination address field, and this target address field includes the address of the fixed network device.
[0201] In this step, the core network device extracts the address of the fixed network device from the second downlink service message. According to the address of the fixed network device, it obtains the TEID on the FMIF side and the TEID on the core network device side of the tunnel corresponding to the fixed network device from the corresponding relationship table it stores. According to the tunnel encapsulation method, it adds the message header corresponding to the tunnel to the second downlink service message to obtain the first downlink service message, and the message header includes the obtained TEID on the FMIF side and the TEID on the core network device side.
[0202] Step 218: The core network device sends the first downlink service message to the FMIF through this tunnel.
[0203] In the case where the core network device is a network element including an AMF, an SMF, and a UPF, the UPF in the core network device obtains the second downlink service message to be sent to the fixed network device, encapsulates the second downlink service message according to the encapsulation method corresponding to this tunnel to obtain the first downlink service message, and sends the first downlink service message to the FMIF through this tunnel.
[0204] In the case where the core network device includes a core network control device and a UPF, the UPF obtains the second downlink service message to be sent to the fixed network device, encapsulates the second downlink service message according to the encapsulation method corresponding to this tunnel to obtain the first downlink service message, and sends the first downlink service message to the FMIF through this tunnel.
[0205] Step 219: The FMIF receives the first downlink service message and decapsulates the first downlink service message according to the decapsulation method corresponding to this tunnel to obtain the second downlink service message.
[0206] The FMIF determines the message header corresponding to this tunnel from the first downlink service message according to the decapsulation method corresponding to this tunnel, and removes the determined message header from the first downlink service message to obtain the second downlink service message.
[0207] The FMIF includes an encapsulation and decapsulation module, and the encapsulation and decapsulation module can receive the first downlink service message and decapsulate the first downlink service message according to the decapsulation method corresponding to this tunnel to obtain the second downlink service message.
[0208] Step 220: The FMIF sends the second downlink service message to the fixed network device through the data plane connection corresponding to the fixed network device between the FMIF and the BNG.
[0209] The FMIF extracts the address of the fixed network device from the second downstream service message, obtains the corresponding BNG address from the first relationship table according to the address of the fixed network device, and sends the second downstream service message to the BNG according to the BNG address. The BNG receives the second downstream service message and forwards the second downstream service message to the fixed network device.
[0210] Step 221: The fixed network device receives the second downstream service message.
[0211] In the embodiment of the present application, since after the FMIF receives the first authentication information of the fixed network device, it encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information. Since the second authentication information is encapsulated according to the message format supported by the control plane interface, the FMIF can send the second authentication information to the core network device through the control plane interface, so as to ensure that the second authentication information can be successfully sent to the core network device, providing guarantee for the core network device to authenticate the fixed network device. Since the communication network to which the core network device belongs is a 5G communication network or a communication network higher than 5G, the fixed network device can be authenticated in the 5G core network or in a core network higher than 5G. After the authentication is passed, the FMIF sends a session establishment request message carrying the identifier of the fixed network device to the core network device. The core network device allocates the session information of the fixed network device and sends the session information to the FMIF. Since the session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, etc., the FMIF can establish a data plane connection between the fixed network device and the core network device according to the session information. In this way, the fixed network device can transmit service messages with the core network device through the data plane connection.
[0212] See Figure 3 , the embodiment of the present application provides a network architecture. The difference between this network architecture and the Figure 1 shown network architecture is that: the access gateway function (AGF) 2 is used to replace the BNG2 and the FMIF3, that is, the functions of the BNG2 and the FMIF3 are integrated in the AGF2, including:
[0213] Fixed network device 1, AGF 2, and core network device 3. The core network device 3 is located in the core network. The core network device 3 can be a network element that implements the AMF function, SMF function, and UPF function. The core network device 4 includes a virtual machine for implementing the AMF function, a virtual machine for implementing the SMF function, and a virtual machine for implementing the UPF function. These three virtual machines are respectively called AMF, SMF, and UPF. Alternatively, the core network device 4 can include a core network control device for implementing the AMF function and SMF function and a UPF. The UPF is a physical device that can implement the UPF function. The core network control device for implementing the AMF function and SMF function includes a virtual machine for implementing the AMF function and a virtual machine for implementing the SMF function. These two virtual machines are respectively called AMF and SMF.
[0214] The communication network version to which the core network device 3 belongs is a 5G communication network or a communication network higher than 5G. The core network can be the core network of a 5G communication network or a core network higher than 5G. The fixed network device 1 can be an FN-RG, etc.
[0215] The AGF 2 can communicate with the core network device 3 through a control plane interface and a data plane interface. The control plane interface can include an N1 interface or an N2 interface, and the data plane interface can be an N3 interface.
[0216] In the case where the core network device 3 is a network element including AMF, SMF, and UPF, the AGF 2 can communicate with the AMF in the core network device 3 through the control plane interface, and the AGF 2 can communicate with the UPF in the core network device 3 through the data plane interface. The SMF and the UPF communicate using the interface between the control plane and the data plane.
[0217] In the case where the core network device 3 includes a core network control device and a UPF, the AGF 2 can communicate with the AMF in the core network control device through the control plane interface, and the AGF 2 can communicate with the UPF through the data plane interface. The SMF in the core network control device and the UPF communicate using the interface between the control plane and the data plane.
[0218] Optionally, the interface between the above control plane and the data plane can be an N4 interface, etc.
[0219] The fixed network device 1 can request the core network device to authenticate it through the AGF 2. The authentication process can be as follows:
[0220] See Figure 4In steps 401 to 406, the fixed network device 1 sends a dialing message to the AGF 2. The AGF 2 receives the dialing message, generates first authentication information of the fixed network device 1 based on the dialing message. The first authentication information includes the identifier of the fixed network device. The first authentication information is encapsulated according to the message format supported by the control plane interface to obtain second authentication information, and the second authentication information is sent to the core network device 3 through the control plane interface. The core network device 3 authenticates the fixed network device 1 according to the second authentication information. After the authentication of the fixed network device 1 is passed, a confirmation message is sent to the AGF 2. The AGF 2 sends a confirmation message to the fixed network device 1.
[0221] For the detailed process of the fixed network device 1 requesting the core network device 4 to perform authentication, reference can be made to the relevant content in steps 401 to 406 in the subsequent Figure 4 illustrated embodiments, which will not be elaborated here.
[0222] After the core network device authenticates the fixed network device 1, a data plane connection can be established between the fixed network device 1 and the core network device. In a specific embodiment, the process of establishing the data plane connection can be as follows:
[0223] See Figure 4 In steps 408 to 410, the AGF 2 sends a session establishment request message to the core network device 3 through the control plane interface. The session establishment request message carries the identifier of the fixed network device 1. The core network device 3 receives the session establishment request message, allocates session information of the fixed network device 1 according to the identifier of the fixed network device 1 included in the session establishment request message. The session information includes the address of the fixed network device 1, the TEID of the tunnel corresponding to the fixed network device 1 on the core network device 3 side between the AGF 2 and the core network device 3, and the tunnel parameters of the tunnel, etc., and sends the session information to the AGF 2. The AGF 2 receives the session information and establishes the tunnel according to the session information. The tunnel parameters can be QoS parameters, etc. Since there is a data plane connection between the AGF 2 and the fixed network device 1, at this time, the data plane connection between the fixed network device 1 and the core network device 3 is established. The data plane connection between the fixed network device 1 and the core network device 3 includes the data plane connection between the fixed network device 1 and the AGF 2 and the tunnel corresponding to the fixed network device 1 between the AGF 2 and the core network device.
[0224] After receiving the confirmation message, the AGF 2 can actively send a session establishment request message to the core network device 3 to request the establishment of a data plane connection between the fixed network device 1 and the core network device 3; or, after receiving the confirmation message, the fixed network device 1 sends a session establishment request message to the AGF 2. The AGF 2 receives the session establishment request message and sends the session establishment request message to the core network device 3.
[0225] The tunnel corresponding to the fixed network device 1 between AGF2 and the core network device 3 can be a GTP-U tunnel or the like.
[0226] The detailed process of establishing the data plane connection can be referred to in the relevant content of steps 408 to 410 in the subsequent Figure 4 illustrated embodiments and will not be elaborated here.
[0227] After establishing the data plane connection between the fixed network device 1 and the core network device 3 located in the core network, the fixed network device 1 can send an uplink service message to the core network device 3, and the core network device 3 then forwards the uplink service message; alternatively, the core network device 3 obtains the downlink service message of the fixed network device 1 and sends the downlink service message to the fixed network device 1. In a specific embodiment, the implementation process is as follows:
[0228] For the uplink service message, refer to Figure 4 steps 411 to 414, where the fixed network device 1 sends a first uplink service message to AGF2, AGF2 receives the first uplink service message, encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message, and sends the second uplink service message to the core network device 3 through this tunnel, which is the tunnel corresponding to the fixed network device 1 between AGF2 and the core network device 3. The core network device 3 receives the second uplink service message and decapsulates the second uplink service message according to the decapsulation method corresponding to this tunnel to obtain the first uplink service message.
[0229] For the downlink service message, refer to Figure 4 steps 415 to 419, where the core network device 3 obtains a second downlink service message to be sent to the fixed network device 1, encapsulates the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain a first downlink service message, and sends the first downlink service message to AGF2 through this tunnel, which is the tunnel corresponding to the fixed network device 1 between AGF2 and the core network device 3. AGF2 receives the first downlink service message, decapsulates the first downlink service message according to the decapsulation method corresponding to this tunnel to obtain the second downlink service message, and the fixed network device 1 receives the second downlink service message.
[0230] Refer to Figure 4 , the embodiment of the present application provides a communication method, which can be applied to the Figure 3 illustrated network architecture. This method can be used for the fixed network device to request the core network device to authenticate the fixed network device; after the authentication of the fixed network device is passed, this method can be used to establish a data plane connection between the fixed network device and the core network; after establishing this data plane connection, this method can be used to transmit the uplink service message or downlink service message of the fixed network device.
[0231] That is to say: The communication method includes a communication method for authenticating a fixed network device, a communication method for establishing a data plane connection between the fixed network device and the core network device, a communication method for transmitting uplink service packets, and a communication method for transmitting downlink service packets.
[0232] See Figure 4 , the communication method for authenticating a fixed network device includes the following steps 401 to 406. The steps 401 to 406 are respectively:
[0233] Step 401: The fixed network device sends a dialing packet to the AGF.
[0234] The fixed network device accesses the AGF through the access network, that is, there is a connection between the fixed network device and the AGF, so the fixed network device can send a dialing packet to the AGF through this connection.
[0235] The dialing packet may include the identifier of the fixed network device or may not include the identifier of the fixed network device. The identifier of the fixed network device may be a Line ID, etc.
[0236] Step 402: The AGF receives the dialing packet and generates first authentication information of the fixed network device based on the dialing packet. The first authentication information includes the identifier of the fixed network device.
[0237] In this step, when the dialing packet includes the identifier of the fixed network device, the AGF can extract the identifier of the fixed network device from the dialing packet and generate the first authentication information of the fixed network device based on the identifier of the fixed network device. Or,
[0238] When the dialing packet does not include the identifier of the fixed network device, the AGF can generate the identifier of the fixed network device according to the preset field in the dialing packet and generate the first authentication information of the fixed network device based on the identifier of the fixed network device.
[0239] The preset field of the dialing packet may include at least one of DHCPv4 option 82 exchange, PPPoE circuit and remote attribute value pair insertion, LDRA function DHCPv6 option 18 on the access node, or Line ID Option (LIO) in the RS message.
[0240] The operation for the AGF to generate the first authentication information may be: The AGF generates username information of the fixed network device based on the identifier of the fixed network device. The username information includes the identifier of the fixed network device, and the first authentication information includes the username information. The AGF can also generate password information of the fixed network device, and the first authentication information may also include the password information.
[0241] Step 403: The AGF encapsulates the first authentication information according to the message format supported by the control plane interface to obtain second authentication information.
[0242] The AGF includes a control plane interface, which is an interface in the AGF for communicating with core network devices. When the core network device is a network element including an AMF, an SMF, and a UPF, this control plane interface is an interface in the AGF for communicating with the AMF in the core network device. When the core network device includes a core network control device and a UPF, this control plane interface is an interface in the AGF for communicating with the AMF in the core network control device.
[0243] This control plane interface can be an N1 interface or an N2 interface. Assuming that this control plane interface is an N1 interface, the second authentication information can be an SUCI, an SUPI, or a 5G-GUTI, that is, the AGF can encapsulate the first authentication information into an SUCI, an SUPI, or a 5G-GUTI according to the message format supported by the N1 interface.
[0244] Step 404: The AGF sends the second authentication information to the core network device through this control plane interface.
[0245] Since the second authentication information is encapsulated according to the message format supported by the control plane interface, the AGF can send the second authentication information to the core network device through the control plane interface, thereby ensuring that the second authentication information can be successfully sent to the core network device to provide guarantee for the core network device to authenticate the fixed network device.
[0246] For example, the control plane interface is an N1 interface, and the second authentication information is an SUCI, an SUPI, or a 5G-GUTI. When the core network device is a network element including an AMF, an SMF, and a UPF, the AGF sends an SUCI, an SUPI, or a 5G-GUTI to the core network device through the N1 interface. When the core network device includes a core network control device and a UPF, the AGF sends an SUCI, an SUPI, or a 5G-GUTI to the core network control device through the N1 interface.
[0247] Step 405: The core network device receives the second authentication information, authenticates the fixed network device according to the second authentication information, and after successfully authenticating the fixed network device, sends a confirmation message to the FMIF.
[0248] In this step, when the core network device is a network element including an AMF, an SMF, and a UPF, the AMF in the core network device authenticates the fixed network device according to the second authentication information, and after successfully authenticating the fixed network device, sends a confirmation message to the AGF. When the core network device includes a core network control device and a UPF, the AMF in the core network control device authenticates the fixed network device according to the second authentication information, and after successfully authenticating the fixed network device, sends a confirmation message to the AGF.
[0249] Step 406: The AGF receives the confirmation message through the control plane interface and sends the confirmation message to the fixed network device.
[0250] The control plane interface can be the N1 interface or the N2 interface, etc. The AGF can receive the confirmation message through the N1 interface or the N2 interface and forward the confirmation message to the fixed network device. The fixed network device receives the confirmation message to complete the authentication of the fixed network device.
[0251] After completing the authentication of the fixed network device, a data plane connection can be established between the fixed network device and the core network device. The data plane connection between the fixed network device and the core network device includes the data plane connection between the fixed network device and the AGF, and the tunnel corresponding to the fixed network device between the AGF and the core network device. When the core network device is a network element including the AMF, SMF, and UPF, the tunnel corresponding to the fixed network device between the AGF and the core network device is the tunnel corresponding to the fixed network device between the AGF and the UPF in the core network device. When the core network device includes the core network control device and the UPF, the tunnel corresponding to the fixed network device between the AGF and the core network device is the tunnel corresponding to the fixed network device between the AGF and the UPF.
[0252] Since the data plane connection between the fixed network device and the AGF already exists, establishing the tunnel corresponding to the fixed network device between the AGF and the core network device means completing the establishment of the data plane connection between the fixed network device and the core network device. The data plane connection between the fixed network device and the core network device can be established through the following steps 407 to 410, and the steps 407 to 410 are respectively:
[0253] Step 407: The AGF sends a session establishment request message to the core network device, and the session establishment request message includes the identifier of the fixed network device.
[0254] After receiving the confirmation message, the AGF can actively send a session establishment request message to the core network device to request the establishment of a data plane connection between the fixed network device and the core network device; or, after receiving the confirmation message, the fixed network device sends a session establishment request message to the AGF; the AGF receives the session establishment request message and sends the session establishment request message to the core network device.
[0255] The AGF can also allocate the TEID of the tunnel on the FMIF side, and the session establishment request message also carries the TEID of the tunnel on the FMIF side, and the tunnel is the tunnel corresponding to the fixed network device between the AGF and the core network device.
[0256] When the core network device is a network element including the AMF, SMF, and UPF, the AGF sends the session establishment request message to the AMF in the core network control device.
[0257] When the core network device includes a core network control device and a UPF, the AGF sends the session establishment request message to the core network control device. When implemented, the AGFF sends the session establishment request message to the AMF in the core network control device.
[0258] The AGF sends a session establishment request message to the core network device through a control plane interface, and the control plane interface can be an N1 interface or an N2 interface, that is, the AGF can send the session establishment request message to the core network device through the N1 interface or the N2 interface.
[0259] Step 408: The core network device receives the session establishment request message, and allocates session information of the fixed network device according to the identifier of the fixed network device included in the session establishment request message. The session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, and the tunnel parameters of the tunnel, etc. The tunnel is the tunnel corresponding to the fixed network device between the AGF and the core network device.
[0260] When the core network device includes network elements such as an AMF, an SMF, and a UPF, in this step, the AMF in the core network device receives the session establishment request message and allocates session information of the fixed network device according to the identifier of the fixed network device included in the session establishment request message.
[0261] When the core network device includes a core network control device and a UPF, in this step, the AMF in the core network control device receives the session establishment request message and allocates session information of the fixed network device according to the identifier of the fixed network device included in the session establishment request message.
[0262] The session information allocated by the core network device may also include the TEID of the tunnel on the AGF side.
[0263] Step 409: The core network device sends the session information to the AGF.
[0264] When the core network device includes network elements such as an AMF, an SMF, and a UPF, the AMF in the core network device sends the session information to the AGF. In the core network device, the AMF also transmits the session information to the SMF, and the SMF transmits the session information to the UPF through the interface between the control plane and the data plane.
[0265] When the core network device includes a core network control device and a UPF, the AMF in the core network control device sends the session information to the AGF, and the AMF also transmits the session information to the SMF. The SMF in the core network control device sends the session information to the UPF through the interface between the control plane and the data plane.
[0266] The interface between the control plane and the data plane includes the N4 interface.
[0267] Step 410: The AGF receives the session information and establishes a tunnel corresponding to the fixed network device between the AGF and the core network device.
[0268] When establishing this tunnel, the AGF and the core network device need to complete it together. In implementation:
[0269] When the session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, and the tunnel parameters, for the AGF side, the AGF allocates the TEID of the tunnel on the AGF side, allocates resources for the tunnel according to the tunnel parameters, the resources can be resources such as ports and bandwidth, binds the resources to the TEID of the tunnel on the AGF side, sends the TEID of the tunnel on the AGF side to the core network device, and saves the correspondence between the address of the fixed network device, the TEID of the tunnel on the AGF side, and the TEID of the tunnel on the core network device side in the second relationship table.
[0270] When the core network device is a network element including AMF, SMF, and UPF, the AGF sends the TEID of the tunnel on the AGF side to the AMF in the core network device. When the core network device includes a core network control device and UPF, the AGF sends the TEID of the tunnel on the AGF side to the AMF in the core network control device.
[0271] The session information may also include the TEID of the tunnel on the AGF side. In this step, the AGF does not need to allocate the TEID of the tunnel on the AGF side, nor does it need to send the TEID of the tunnel on the AGF side to the core network device.
[0272] For the core network device side, when the session information includes the address of the fixed network device, the TEID of the tunnel on the core network device side, and the tunnel parameters of the tunnel, when the core network device is a network element including AMF, SMF, and UPF, the AMF in the core network device receives the TEID of the tunnel on the AGF side sent by the FMIF, transmits the TEID of the tunnel on the FMIF side to the SMF, and the SMF transmits the TEID of the tunnel on the AGF side to the UPF through the interface between the control plane and the data plane. The UPF in the core network device receives the session information and the TEID of the tunnel on the AGF side, allocates resources for the tunnel according to the tunnel parameters, where the resources can be resources such as ports and bandwidth, binds the resources to the TEID of the tunnel on the core network device side, and saves the correspondence between the address of the fixed network device, the TEID of the tunnel on the AGF side, and the TEID of the tunnel on the core network device side in the correspondence table, thereby establishing the tunnel. When the core network device is a network element including a core network control device and a UPF, the AMF in the core network control device receives the TEID of the tunnel on the AGF side sent by the AGF, transmits the TEID of the tunnel on the AGF side to the SMF, and the SMF sends the TEID of the tunnel on the AGF side to the UPF through the interface between the control plane and the data plane. The UPF receives the session information and the TEID of the tunnel on the FMIF side, allocates resources for the tunnel according to the tunnel parameters, where the resources can be resources such as ports and bandwidth, binds the resources to the TEID of the tunnel on the core network device side, and saves the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the core network device side in the correspondence table, thereby establishing the tunnel.
[0273] The session information may further include the TEID of the tunnel on the AGF side, so that in this step, the core network device or the core network control device does not need to receive the TEID of the tunnel on the AGF side sent by the AGF.
[0274] Among them, the AGF may also allocate the TEID of the tunnel on the AGF side before sending the session establishment request message, so that the session establishment request message can carry the TEID of the tunnel on the AGF side. In this step, the AGF does not need to allocate the TEID of the tunnel on the AGF side after receiving the session information, nor does it need to send the TEID of the tunnel on the AGF side to the core network device.
[0275] After establishing the tunnel corresponding to the fixed network device between the AGF and the core network device, since there is a data plane connection between the fixed network device and the AFG, the data plane connection between the fixed network device and the core network device is completed.
[0276] The fixed network device can send uplink service packets through the data plane connection between it and the core network device, and can send uplink service packets through the following steps 411 to 414. The steps 411 to 414 are respectively:
[0277] Step 411: The fixed network device sends a first uplink service packet to the AGF. The first uplink service packet includes the address of the fixed network device.
[0278] The header of the first uplink service packet includes a source address field, and the content carried in the source address field is the address of the fixed network device.
[0279] Step 412: The AGF receives the first uplink service packet, and encapsulates the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain a second uplink service packet. The tunnel is the tunnel corresponding to the fixed network device between the AGF and the core network device.
[0280] The AGF receives the first uplink service packet, extracts the address of the fixed network device from the first uplink service packet, obtains the TEID on the AGF side and the TEID on the core network device side of the tunnel corresponding to the fixed network device from the second relationship table according to the address of the fixed network device, and adds the header corresponding to the tunnel to the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain a second uplink service packet. The header includes the obtained TEID on the AGF side and the TEID on the core network device side.
[0281] Before performing the operation of encapsulating the first uplink service packet, the AGF can detect whether the first uplink service packet is a packet of a mobile network service. If the first uplink service packet is a packet of a mobile network service, the operation of encapsulating the first uplink service packet is performed.
[0282] The AGF can detect whether the first uplink service packet is a packet of a mobile network service according to a preset field in the header of the first uplink service packet.
[0283] In this step, the AGF can extract the field content included in the preset field in the header of the first uplink service packet. If the field content is the preset content, it is detected that the first uplink service packet is a packet of a mobile network service. If the field content is not the preset content, it is detected that the first uplink service packet is not a packet of a mobile network service.
[0284] The AGF includes a service verification module and an encapsulation / de-encapsulation module. The service verification module can detect whether the first uplink service packet is a packet of a mobile network service. If the first uplink service packet is a packet of a mobile network service, the encapsulation / de-encapsulation module performs the operation of encapsulating the first uplink service packet. If the first uplink service packet is not a packet of a mobile network service, the first uplink service packet is discarded.
[0285] Step 413: The AGF sends a second uplink service message to the core network device through this tunnel.
[0286] The AGF includes a data plane interface, which is an interface in the AGF for communicating with the core network device. The AGF can use the data plane interface to send a second uplink service message to the core network device through this tunnel.
[0287] When the core network device is a network element including an AMF, an SMF, and a UPF, the AGF can use the data plane interface to send a second uplink service message to the UPF in the core network device through this tunnel.
[0288] When the core network device includes a core network control device and a UPF, the AGF can use the data plane interface to send a second uplink service message to the UPF through this tunnel.
[0289] The data plane interface can be an N4 interface, etc.
[0290] Step 414: The core network device receives the second uplink service message and decapsulates the second uplink service message according to the decapsulation method corresponding to this tunnel to obtain a first uplink service message.
[0291] In this step, the core network device receives the second uplink service message and removes the message header corresponding to this tunnel from the second uplink service message according to the decapsulation method corresponding to this tunnel to obtain a first uplink service message.
[0292] After the core network device obtains the first uplink service message, it can forward the first uplink service message to the data network.
[0293] When the core network device is a network element including an AMF, an SMF, and a UPF, the UPF in the core network device receives the second uplink service message and removes the message header corresponding to this tunnel from the second uplink service message according to the decapsulation method corresponding to this tunnel to obtain a first uplink service message.
[0294] When the core network device includes a core network control device and a UPF, the UPF receives the second uplink service message and removes the message header corresponding to this tunnel from the second uplink service message according to the decapsulation method corresponding to this tunnel to obtain a first uplink service message.
[0295] The core network device can send a downlink service message through the data plane connection between it and the fixed network device, and can send an uplink service message through the following steps 415 to 419. The steps 415 to 419 are respectively:
[0296] Step 415: The core network device obtains the second downlink service message to be sent to the fixed network device, and encapsulates the second downlink service message according to the encapsulation method corresponding to the tunnel, where the tunnel is the tunnel corresponding to the fixed network device between the AGF and the core network device, to obtain the first downlink service message.
[0297] The core network device receives the second downlink service message from the data network. The second downlink service message includes the address of the fixed network device. The message header of the second downlink service message includes a destination address field, and the destination address field includes the address of the fixed network device.
[0298] In this step, the core network device extracts the address of the fixed network device from the second downlink service message, and according to the address of the fixed network device, obtains the TEID on the AGF side and the TEID on the core network device side of the tunnel corresponding to the fixed network device from the corresponding relationship table it stores. According to the encapsulation method of the tunnel, a message header corresponding to the tunnel is added to the second downlink service message to obtain the first downlink service message, and the message header includes the obtained TEID on the AGF side and the TEID on the core network device side.
[0299] Step 416: The UPF sends the first downlink service message to the AGF through the tunnel.
[0300] In the case where the core network device is a network element including the AMF, the SMF, and the UPF, the UPF in the core network device obtains the second downlink service message to be sent to the fixed network device, encapsulates the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain the first downlink service message, and sends the first downlink service message to the AGF through the tunnel.
[0301] In the case where the core network device includes a core network control device and a UPF, the UPF obtains the second downlink service message to be sent to the fixed network device, encapsulates the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain the first downlink service message, and sends the first downlink service message to the AGF through the tunnel.
[0302] Step 417: The AGF receives the first downlink service message, and de-encapsulates the first downlink service message according to the de-encapsulation method corresponding to the tunnel to obtain the second downlink service message.
[0303] The AGF determines the message header corresponding to the tunnel from the first downlink service message according to the de-encapsulation method corresponding to the tunnel, and removes the determined message header from the first downlink service message to obtain the second downlink service message.
[0304] Step 418: The AGF sends the second downlink service message to the fixed network device.
[0305] Step 419: The fixed network device receives the second downlink service message.
[0306] In an embodiment of the present application, after the AGF generates the first authentication information of the fixed network device, the first authentication information is encapsulated according to the message format supported by the control plane interface to obtain the second authentication information. Since the second authentication information is encapsulated according to the message format supported by the control plane interface, the AGF can send the second authentication information to the core network device through the control plane interface, thereby ensuring that the second authentication information can be successfully sent to the core network device, so as to provide guarantee for the core network device to authenticate the fixed network device. Since the communication network to which the core network device belongs is a 5G communication network or a communication network higher than 5G, the fixed network device can be authenticated in the 5G core network or in a core network higher than 5G.
[0307] See Figure 5 , an embodiment of the present application provides a communication device 500, and the device 500 can be deployed in the BNG of any of the above embodiments, including:
[0308] A receiving unit 501, configured to receive a dialing packet sent by a fixed network device;
[0309] A processing unit 502, configured to generate the first authentication information of the fixed network device according to the dialing packet, where the first authentication information includes an identifier of the fixed network device;
[0310] A sending unit 503, configured to send an access request message to a fixed-mobile interworking function (FMIF), where the access request message carries the first authentication information, and the access request message is used for the FMIF to request the core network device to authenticate the fixed network device according to the first authentication information, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G.
[0311] Optionally, the access request message is a Remote Authentication Dial In User Service (Radius) protocol access request message, or a Diameter protocol access request message.
[0312] Optionally, for the detailed process of the processing unit 502 and the sending unit 503 sending the authentication information of the fixed network device to the core network device, reference can be made to Figure 2 the operations performed by the BNG in steps 201 to 207 in the embodiment shown.
[0313] Optionally, the receiving unit 501 is further configured to receive the address of the fixed network device sent by the core network device through the FMIF, where the address of the fixed network device is allocated by the core network device after receiving a session establishment request message carrying the identifier of the fixed network device, and the session establishment request message is sent by the FMIF after the core network device authenticates the fixed network device;
[0314] The processing unit 502 is further configured to establish a data plane connection corresponding to the fixed network device between the device 500 and the FMIF according to the address of the fixed network device and the address of the FMIF.
[0315] Optionally, for the detailed process of the processing unit 502 to establish a data plane connection, reference may be made to Figure 2 the operations performed by the BNG in steps 208 to 211 in the illustrated embodiment.
[0316] Optionally, the receiving unit 501 is further configured to receive a first uplink service message from the fixed network device, where the first uplink service message includes the address of the fixed network device;
[0317] The processing unit 502 is further configured to obtain the address of the FMIF from a correspondence table according to the address of the fixed network device, where the correspondence table is used to store the correspondence between the address of the fixed network device and the address of the FMIF;
[0318] The sending unit 503 is further configured to send the first uplink service message to the FMIF according to the address of the FMIF.
[0319] Optionally, the processing unit 502 is further configured to detect whether the first uplink service message is a message of a mobile network service according to a preset field in the message header of the first uplink service message. If the first uplink service message is a message of a mobile network service, perform the operation of obtaining the address of the FMIF from the correspondence table according to the address of the fixed network device. Thereby, it can be ensured that only the service messages of the mobile network are sent to the core network device.
[0320] Optionally, the receiving unit 501 is further configured to receive a second downlink service message, where the second downlink service message includes the address of the fixed network device;
[0321] The sending unit 503 is further configured to send the second downlink service message to the fixed network device.
[0322] Optionally, for the detailed process of the receiving unit 501, the processing unit 502, and the sending unit 503 to forward the first uplink service message, reference may be made to Figure 2 the operations performed by the BNG in steps 212 to 216 in the illustrated embodiment, and for the detailed process of forwarding the second downlink service message, reference may be made to Figure 2 the operations performed by the BNG in steps 220 - 221 in the illustrated embodiment.
[0323] In an embodiment of the present application, the processing unit generates authentication information of the fixed network device, and the sending unit sends the authentication information of the fixed network device to the core network device through the FMIF, so that the core network device can authenticate the fixed network device. Since the communication network to which the core network device belongs is a 5G communication network or a communication network higher than 5G, the fixed network device can be authenticated in the 5G core network or in a core network higher than 5G. Further, after authentication, the receiving unit receives the address of the fixed network device sent by the core network device through the FMIF, and the processing unit establishes a data plane connection corresponding to the fixed network device between the device and the FMIF according to the address of the fixed network device and the address of the FMIF, thereby further establishing a data plane connection between the fixed network device and the core network device, providing guarantee for the device to send and receive service packets of the fixed network device to and from the 5G core network.
[0324] See Figure 6 , an embodiment of the present application provides a communication device 600, and the device 500 can be deployed in the FMIF of any of the above embodiments, including:
[0325] A receiving unit 601, configured to receive an access request message sent by a broadband network gateway (BNG), where the access request message includes first authentication information of a fixed network device, the first authentication information is generated by the BNG based on a dial-up packet sent by the fixed network device, and the first authentication information includes an identifier of the fixed network device;
[0326] A processing unit 602, configured to encapsulate the first authentication information according to a message format supported by a control plane interface to obtain second authentication information, where the control plane interface is an interface in the device 600 for communicating with a core network device, and the communication network to which the core network device belongs is a 5G communication network or a communication network higher than 5G;
[0327] A sending unit 603, configured to send the second authentication information to the core network device through the control plane interface, where the second authentication information is used for the core network device to authenticate the fixed network device.
[0328] Optionally, the control plane interface includes an N1 interface or an N2 interface, and the second authentication information is a SUCI, a SUPI, or a 5G-GUTI.
[0329] Optionally, the detailed process of the processing unit 602 and the sending unit 503 sending the authentication information of the fixed network device to the core network device can be seen in Figure 2 the operations performed by the FMIF in steps 201 to 207 in the embodiment shown.
[0330] Optionally, the receiving unit 601 is further configured to receive a confirmation message sent by the core network device after authentication passes;
[0331] The sending unit 603 is further configured to send a session establishment request message to the core network device. The session establishment request message carries the identifier of the fixed network device, and is used for the core network device to allocate session information. The session information includes the address of the fixed network device, the tunnel endpoint identifier (TEID) of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The tunnel is the tunnel corresponding to the fixed network device between the device and the core network device;
[0332] The receiving unit 601 is further configured to receive the session information sent by the core network device;
[0333] The processing unit 602 is further configured to establish a data plane connection corresponding to the fixed network device between the device and the BNG, and establish the tunnel according to the session information.
[0334] Optionally, for the detailed process of the processing unit 602 to establish a data plane connection corresponding to the fixed network device between the device and the BNG and establish the tunnel, reference may be made to the operations performed by FMIF in steps 208 to 211 in the embodiments shown in Figure 2 the operations performed by FMIF in steps 208 to 211 in the embodiments shown.
[0335] Optionally, the sending unit 603 is further configured to send the address of the fixed network device to the BNG;
[0336] The processing unit is configured to save the correspondence between the address of the fixed network device and the address of the BNG in a first relationship table, and the first relationship table is used for the device to transmit the downlink service packets of the fixed network device;
[0337] Optionally, the receiving unit 601 is further configured to receive the downlink service packets of the fixed network device sent by the core network device. The processing unit 602 determines the BNG connected to the fixed network device according to the first correspondence table, and the sending unit 603 sends the downlink service packets to the fixed network device through the data plane connection corresponding to the fixed network device between the communication device and the BNG.
[0338] The processing unit 602 is further configured to save the correspondence between the address of the fixed network device, the TEID of the tunnel on the device side, and the TEID of the tunnel on the core network device side in a second relationship table. The second relationship table is used for the communication device to send the uplink service packets of the fixed network device. Specifically, after receiving the first uplink service packet sent by the BNG, the communication device encapsulates the first uplink service packet according to the second relationship table to obtain a second uplink service packet, and sends the second uplink service packet to the core network device through the tunnel.
[0339] Optionally, the session information further includes the TEID of the tunnel on the device side.
[0340] Optionally, the processing unit 602 is further configured to allocate the TEID of the tunnel on the device side;
[0341] The sending unit is further configured to send the TEID of the tunnel on the device side to the core network device. The TEID of the tunnel on the device side is saved by the core network device in a correspondence table, which includes the address of the fixed network device, the correspondence between the TEID of the tunnel on the device side and the TEID of the tunnel on the core network device side. The correspondence table is used for the core network device to transmit the downlink service packets of the fixed network device. Specifically, after the core network device obtains a second downlink service packet to be sent to the fixed network device, it encapsulates the second downlink service packet according to the correspondence table to obtain a first downlink service packet, and sends the first downlink service packet to the communication device through the tunnel.
[0342] Optionally, the sending unit 603 is further configured to send the session establishment request message to the core network device through the control plane interface, where the control plane interface includes an N1 interface or an N2 interface.
[0343] In the embodiment of the present application, since the processing unit encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information. Since the second authentication information is encapsulated according to the message format supported by the control plane interface, the sending unit can send the second authentication information to the core network device, so as to ensure that the second authentication information can be successfully sent to the core network device, providing guarantee for the core network device to authenticate the fixed network device. Since the communication network to which the core network device belongs is a 5G communication network or a communication network higher than 5G, the fixed network device can be authenticated in the 5G core network or in a core network higher than 5G. Further, after authentication, the receiving unit receives the session information of the fixed network device sent by the core network device, and the processing unit establishes a data plane connection corresponding to the fixed network device between the device and the BNG and a tunnel corresponding to the fixed network device between the device and the core network device according to the session information, thereby establishing a data plane connection between the fixed network device and the core network device, providing guarantee for the communication device to send and receive the service packets of the fixed network device to / from the 5G core network.
[0344] See Figure 7 , an embodiment of the present application provides a communication device 700, which can be deployed in the core network device in any of the above embodiments, including:
[0345] A receiving unit 701, configured to receive a session establishment request message from a fixed-mobile interworking function (FMIF), where the session establishment request message includes an identifier of a fixed network device, and the communication network version to which the device belongs is a 5G communication network or a communication network higher than 5G;
[0346] A processing unit 702, configured to allocate session information for the fixed network device according to the identifier of the fixed network device, where the session information includes an address of the fixed network device, a tunnel endpoint identifier (TEID) of the tunnel on the device side, and tunnel parameters of the tunnel, and the tunnel is a tunnel corresponding to the fixed network device between the FMIF and the device;
[0347] A sending unit 703, configured to send the session information to the FMIF, where the session information is used by the FMIF to establish a data plane connection between the fixed network device and a core network device.
[0348] Optionally, for the detailed processes of the processing unit 702 and the sending unit 703 to allocate session information and send session information, reference may be made to Figure 2 the operations performed by the core network device in steps 208 to 211 in the illustrated embodiment.
[0349] Optionally, the receiving unit 701 is further configured to receive second authentication information sent by the FMIF, where the second authentication information is obtained by the FMIF encapsulating first authentication information according to a message format supported by a control plane interface, the control plane interface is an interface in the FMIF for communicating with the device, and the first authentication information includes an identifier of the fixed network device;
[0350] The processing unit 702 is further configured to authenticate the fixed network device according to the second authentication information.
[0351] Optionally, for the detailed processes of the receiving unit 701 receiving the second authentication information and the processing unit 702 authenticating the fixed network device, reference may be made to Figure 2 the operations performed by the core network device in steps 201 to 207 in the illustrated embodiment.
[0352] Optionally, the processing unit 702 is further configured to save the correspondence between the address of the fixed network device, the TEID of the tunnel on the FMIF side, and the TEID of the tunnel on the device side to a correspondence table, and the correspondence table is used by the device to transmit downlink service packets of the fixed network device.
[0353] Optionally, for the detailed process of the processing unit 702 transmitting downlink service packets of the fixed network device, reference may be made to Figure 2The operations performed by the core network device in steps 217 - 221 in the illustrated embodiment.
[0354] Optionally, the session information further includes the TEID of the tunnel on the FMIF side or the session establishment request message further carries the TEID of the tunnel on the FMIF side assigned by the FMIF.
[0355] Optionally, the receiving unit is further configured to receive the TEID of the tunnel on the FMIF side sent by the FMIF, and the TEID of the tunnel on the FMIF side is assigned by the FMIF.
[0356] In the embodiment of the present application, since the processing unit allocates session information, which includes the address of the fixed network device, the tunnel endpoint identifier (TEID) of the tunnel on the device side, and the tunnel parameters of the tunnel, the sending unit sends the session information to the FMIF, so that the FMIF can establish a data plane connection between the fixed network device and the core network device, and thus the service packets of the fixed network device can be transmitted through this data plane connection.
[0357] See Figure 8 , the embodiment of the present application provides a communication device 800, which can be deployed in the FMIF of any of the above embodiments, including:
[0358] A receiving unit 801, configured to receive a first uplink service packet from the fixed network device;
[0359] A processing unit 802, configured to encapsulate the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain a second uplink service packet, where the tunnel is the tunnel corresponding to the fixed network device between the device and the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G;
[0360] A sending unit 803, configured to send the second uplink service packet to the core network device through the tunnel.
[0361] Optionally, for the detailed process of the processing unit 802 and the sending unit 803 to encapsulate the first uplink service packet and send the second uplink service packet, reference can be made to Figure 2 the operations performed by the FMIF in steps 211 to 214 in the illustrated embodiment.
[0362] Optionally, the first uplink service packet includes the address of the fixed network device;
[0363] The processing unit 802 is configured to obtain, according to the address of the fixed network device, the tunnel endpoint identifier (TEID) of the tunnel on the device side and the TEID of the tunnel on the core network device side from a second relationship table, where the second relationship table is used to store the correspondence between the address of the fixed network device, the TEID on the device side and the TEID on the core network device side;
[0364] The processing unit 802 is further configured to add, according to the encapsulation mode corresponding to the tunnel, a message header corresponding to the tunnel to the first uplink service message to obtain a second uplink service message, where the message header includes the obtained TEID on the device side and the TEID on the core network device side.
[0365] Optionally, the processing unit 802 is further configured to detect, according to a preset field in the message header of the first uplink service message, whether the first uplink service message is a message of a mobile network service. If the first uplink service message is a message of a mobile network service, perform the operation of encapsulating the first uplink service message according to the encapsulation mode corresponding to the tunnel to obtain a second uplink service message.
[0366] Optionally, the receiving unit 801 is further configured to receive a first downlink service message sent by the core network device to the fixed network device;
[0367] The processing unit 802 is configured to perform decapsulation on the first downlink service message according to the decapsulation mode corresponding to the tunnel to obtain a second downlink service message;
[0368] The sending unit 802 is configured to send the second downlink service message to the fixed network device through the data plane connection corresponding to the fixed network device between the device and the BNG.
[0369] Optionally, the processing unit 802 is configured to remove, according to the decapsulation mode corresponding to the tunnel, the message header corresponding to the tunnel from the first downlink service message to obtain a second downlink service message.
[0370] Optionally, for the detailed process of the receiving unit 801, the processing unit 802 and the sending unit 803 in transmitting the downlink service message of the fixed network device, reference may be made to the operations performed by FMIF in steps 215 to 221 in the Figure 2 illustrated embodiment.
[0371] Optionally, the tunnel is a General Packet Radio Service Tunneling Protocol User Plane (GTP-U) tunnel.
[0372] In the embodiments of the present application, since the processing unit encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message, the sending unit sends the second uplink service message to the core network device through the tunnel. Thus, the uplink service message of the fixed network device can be sent to a 5G core network or a core network device higher than the 5G core network.
[0373] See Figure 9 , embodiments of the present application provide a communication device 900, which can be deployed in the core network device of any of the above embodiments. The device 900 includes:
[0374] A receiving unit 901, configured to receive a second uplink service message from a fixed-mobile interworking function (FMIF). The second uplink service message is obtained by the FMIF encapsulating a first uplink service message from the fixed device according to the encapsulation method corresponding to the tunnel. The tunnel is a tunnel corresponding to the fixed network device between the FMIF and the device, and the communication network version to which the device belongs is a 5G communication network or a communication network higher than 5G;
[0375] A processing unit 902, configured to perform decapsulation on the second uplink service message according to the decapsulation method corresponding to the tunnel to obtain the first uplink service message.
[0376] Optionally, for the detailed process of the receiving unit 901 and the processing unit 902 receiving the second uplink service message and decapsulating the second uplink service message, reference can be made to Figure 2 The operations performed by the core network device in steps 211 to 214 in the embodiments shown.
[0377] Optionally, the device 900 further includes: a sending unit 903.
[0378] The processing unit 902 is configured to obtain a second downlink service message to be sent to the fixed network device; encapsulate the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain a first downlink service message;
[0379] The sending unit 903 is configured to send the first downlink service message to the FMIF through the tunnel.
[0380] Optionally, the second downlink service message includes the address of the fixed network device;
[0381] The processing unit 902 is configured to obtain the tunnel endpoint identifier (TEID) on the FMIF side and the TEID on the device side of the tunnel from a correspondence table according to the address of the fixed network device. The correspondence table is used to store the correspondence between the address of the fixed network device, the TEID on the FMIF side, and the TEID on the device side.
[0382] The processing unit 902 is further configured to add a packet header corresponding to the tunnel to the second downlink service packet according to the encapsulation method corresponding to the tunnel, so as to obtain a first downlink service packet, where the packet header includes the TEID on the FMIF side and the TEID on the device side obtained.
[0383] Optionally, for the detailed process of the sending unit 903 and the processing unit 902 transmitting the downlink service packet of the fixed network device, reference may be made to Figure 2 the operations performed by the core network device in steps 215 to 221 in the illustrated embodiment.
[0384] Optionally, the tunnel is a General Packet Radio Service Tunneling Protocol User Plane GTP-U tunnel.
[0385] In the embodiment of the present application, since the receiving unit receives a second uplink service packet from the FMIF, the processing unit decapsulates the second uplink service packet according to the decapsulation method corresponding to the tunnel to obtain the first uplink service packet. Thus, a core network device of a 5G core network or a core network higher than the 5G core network can receive the uplink service packet of the fixed network device.
[0386] See Figure 10 , the embodiment of the present application provides a communication device 1000, which can be deployed in the AGF of any of the above embodiments. The device 1000 includes:
[0387] A receiving unit 1001, configured to receive a dialing packet sent by a fixed network device;
[0388] A processing unit, configured to generate first authentication information of the fixed network device according to the dialing packet, where the first authentication information includes an identifier of the fixed network device; encapsulate the first authentication information according to a message format supported by a control plane interface, where the control plane interface is an interface in the device 1000 for communicating with a core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than the 5G communication network;
[0389] A sending unit 1003, configured to send the second authentication information to the core network device through the control plane interface, where the second authentication information is used for the core network device to authenticate the fixed network device.
[0390] Optionally, for the detailed process of the receiving unit 1001, the processing unit 1002, and the sending unit 1003 authenticating the fixed network device, reference may be made to Figure 2 the operations performed by the AGF in steps 401-406 in the illustrated embodiment.
[0391] Optionally, the control plane interface includes an N1 interface or an N2 interface, and the second authentication information is a subscriber concealed identifier (SUCI), an encrypted subscriber concealed identifier (SUPI), or a 5G globally unique temporary UE identifier (5G-GUTI).
[0392] Optionally, the receiving unit 1001 is further configured to receive an acknowledgement message sent by the core network device after authentication is passed;
[0393] The sending unit 1003 is further configured to send a session establishment request message to the core network device, where the session establishment request message carries an identifier of the fixed network device, and the session establishment request message is used for the core network device to allocate session information, and the session information includes an address of the fixed network device, a tunnel endpoint identifier (TEID) of the tunnel on the core network device side, and tunnel parameters of the tunnel, and the tunnel is a tunnel corresponding to the fixed network device between the apparatus 1000 and the core network device;
[0394] The receiving unit 1001 is further configured to receive session information sent by the core network device;
[0395] The processing unit 1002 is further configured to establish the tunnel according to the session information.
[0396] Optionally, for the detailed process of the receiving unit 1001, the processing unit 1002, and the sending unit 1003 to establish the tunnel, reference may be made to the operations performed by the AGF in steps 407-410 in the embodiment shown in Figure 2 The operations performed by the AGF in steps 407-410 in the embodiment shown.
[0397] Optionally, the processing unit is further configured to save the correspondence between the address of the fixed network device, the TEID of the tunnel on the apparatus 1000 side, and the TEID of the tunnel on the core network device side in a second relationship table, and the second relationship table is used for the apparatus 1000 to send an uplink service packet of the fixed network device.
[0398] Optionally, the session information further includes the TEID of the tunnel on the apparatus 1000 side.
[0399] Optionally, the processing unit 1002 is further configured to allocate a TEID of the tunnel on the device 1000 side, send the TEID of the tunnel on the device 1000 side to the core network device. The TEID of the tunnel on the device 1000 side is saved by the core network device in a correspondence table, where the correspondence table includes the address of the fixed network device and the correspondence between the TEID of the tunnel on the device 1000 side and the TEID of the tunnel on the core network device side. The correspondence table is used for the core network device to transmit the downlink service packets of the fixed network device.
[0400] Optionally, the AGF sends the session establishment request message to the core network device through the control plane interface, and the control plane interface includes an N1 interface or an N2 interface.
[0401] In the embodiment of the present application, since the processing unit encapsulates the first authentication information according to the message format supported by the control plane interface to obtain the second authentication information. Since the second authentication information is encapsulated according to the message format supported by the control plane interface, the sending unit can send the second authentication information to the core network device, so as to ensure that the second authentication information can be successfully sent to the core network device, providing guarantee for the core network device to authenticate the fixed network device. Since the communication network to which the core network device belongs is a 5G communication network or a communication network higher than 5G, the fixed network device can be authenticated in the 5G core network or in a core network higher than 5G. Further, after authentication, the receiving unit receives the session information of the fixed network device sent by the core network device, and the processing unit establishes a tunnel corresponding to the fixed network device between the device and the core network device according to the session information, thereby establishing a data plane connection between the fixed network device and the core network device, providing guarantee for the communication device to send and receive the service packets of the fixed network device to / from the 5G core network.
[0402] See Figure 11 , an embodiment of the present application provides a communication device 1100, which can be deployed in the AGF of any of the above embodiments. The device 1100 includes:
[0403] A receiving unit 1101, configured to receive a first uplink service packet from the fixed network device;
[0404] A processing unit 1102, configured to encapsulate the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain a second uplink service packet, where the tunnel is a tunnel corresponding to the fixed network device between the AGF and the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G;
[0405] A sending unit 1103, configured to send a second uplink service message to the core network device through the tunnel.
[0406] Optionally, the first uplink service message includes the address of the fixed network device;
[0407] The processing unit 1102 is configured to obtain, according to the address of the fixed network device, the tunnel endpoint identifier (TEID) of the tunnel on the side of the device 1100 and the TEID of the tunnel on the side of the core network device from a second relationship table, where the second relationship table is used to store the correspondence between the address of the fixed network device, the TEID on the side of the device 1100, and the TEID on the side of the core network device;
[0408] The processing unit 1102 is further configured to add, according to the encapsulation method corresponding to the tunnel, a message header corresponding to the tunnel to the first uplink service message to obtain a second uplink service message, where the message header includes the obtained TEID on the AGF side and the TEID on the side of the core network device.
[0409] Optionally, the processing unit 1102 is further configured to detect, according to a preset field in the message header of the first uplink service message, whether the first uplink service message is a message of a mobile network service. If the first uplink service message is a message of a mobile network service, perform an operation of encapsulating the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message.
[0410] Optionally, for the detailed process of the receiving unit 1101, the processing unit 1102, and the sending unit 1103 for transmitting the uplink service message of the fixed network device, reference may be made to Figure 2 the operations performed by the AGF in steps 411 - 414 in the embodiment shown.
[0411] Optionally, the receiving unit 1101 is further configured to receive a first downlink service message sent by the core network device to the fixed network device;
[0412] The processing unit 1102 is further configured to perform decapsulation on the first downlink service message according to the decapsulation method corresponding to the tunnel to obtain a second downlink service message;
[0413] The sending unit 1103 is further configured to send the second downlink service message to the fixed network device.
[0414] The processing unit 1102 is configured to remove, according to the decapsulation method corresponding to the tunnel, the message header corresponding to the tunnel from the first downlink service message to obtain a second downlink service message.
[0415] The tunnel is a General Packet Radio Service (GPRS) Tunneling Protocol (GTP) - User Plane (U) tunnel.
[0416] Optionally, for the detailed process of the receiving unit 1101, the processing unit 1102, and the sending unit 1103 to transmit the downlink service packets of the fixed network device, reference can be made to Figure 2 the operations performed by the AGF in steps 415 - 419 in the embodiment shown.
[0417] In the embodiment of the present application, since the processing unit encapsulates the first uplink service packet according to the encapsulation method corresponding to the tunnel to obtain the second uplink service packet, the sending unit sends the second uplink service packet to the core network device through the tunnel. Thus, the uplink service packets of the fixed network device can be sent to a 5G core network or a core network device higher than the 5G core network.
[0418] Refer to Figure 12 , a schematic diagram of a communication device 1200 provided in the embodiment of the present application. The device 1200 includes a processor 1201, a memory 1202, and a transceiver 1203, and the processor 1201 is connected to the memory 1202 and the transceiver 1203.
[0419] The communication device 1200 is a device with a hardware structure and can be used to implement Figure 5 the functional modules in the Figure 5 device shown. For example, those skilled in the art can conceive that Figure 5 the processing unit 502 in the device 500 shown can be implemented by the processor 1201 calling the code in the memory 1202,
[0420] Optionally, the above - mentioned processor 1201 can be one or more central processing units (CPUs), microprocessors, application - specific integrated circuits (ASICs), or one or more integrated circuits for controlling the execution of the program of the solution of the present application.
[0421] The processor 1201 is used to execute the instructions in the memory 1202 and perform the processing steps applied to Figure 1 the embodiment BNG shown, or execute Figure 2 the steps implemented by the BNG in the embodiment shown.
[0422] The memory 1202, the processor 1201, and the transceiver 1203 are interconnected through a bus 1204; the bus 1204 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0423] In a specific embodiment, the transceiver 1203 is configured to receive a dialing message sent by a fixed network device; for details, reference can be made to Figure 2 the detailed description of step 201 in the embodiment shown.
[0424] The processor 1201 is configured to generate first authentication information of the fixed network device according to the dialing message, where the first authentication information includes an identifier of the fixed network device; for details, reference can be made to Figure 2 the detailed description of step 202 in the embodiment shown.
[0425] The transceiver 1203 is configured to send an access request message to a Fixed-Mobile Interworking Function (FMIF), where the access request message carries the first authentication information, and the access request message is used for the FMIF to request a core network device to authenticate the fixed network device according to the first authentication information, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. For details, reference can be made to Figure 2 the detailed description of step 203 in the embodiment shown.
[0426] In another embodiment, the communication device 1200 can further execute the steps implemented by a Broadband Network Gateway (BNG) in the Figure 2 embodiment shown, such as steps 207, 211 - 213, 220, etc. Details are not described herein one by one.
[0427] Refer to Figure 13 , a schematic diagram of a communication device 1300 provided in an embodiment of the present application. The device 1300 includes a processor 1301, a memory 1302, and a transceiver 1303, and the processor 1301 is connected to the memory 1302 and the transceiver 1303.
[0428] The communication device 1300 is a hardware-structured device and can be used to implement Figure 6 or Figure 8 the functional modules in the Figure 6 device shown. For example, those skilled in the art can think of Figure 8The processing unit 802 in the device 800 shown can be implemented by the processor 1301 calling the code in the memory 1302. Figure 6 The receiving unit 601 and the transmitting unit 603 in the device 600 shown, or Figure 8 The receiving unit 801 and the transmitting unit 803 in the device 800 shown can be implemented by the transceiver 1303.
[0429] Optionally, the above-mentioned processor 1301 can be one or more central processing units (CPUs), microprocessors, application-specific integrated circuits (ASICs), or one or more integrated circuits for controlling the execution of the program of the solution of the present application.
[0430] The processor 1301 is used to execute the instructions in the memory 1302 and execute the above-mentioned processing steps applied to Figure 1 the shown embodiment FMIF, or execute Figure 2 the steps implemented by FMIF in the shown embodiment.
[0431] The memory 1302, the processor 1301, and the transceiver 1303 are interconnected through the bus 1304; the bus 1304 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0432] In a specific embodiment, the transceiver 1303 is used to receive an access request message sent by the broadband network gateway BNG. The access request message includes first authentication information of the fixed network device. The first authentication information is generated by the BNG based on the dialing packet sent by the fixed network device, and the first authentication information includes the identifier of the fixed network device; for details, reference can be made to Figure 2 the detailed description of step 203 in the shown embodiment.
[0433] The processor 1301 is used to encapsulate the first authentication information according to the message format supported by the control plane interface to obtain second authentication information. The control plane interface is an interface in the FMIF for communicating with the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G; for details, reference can be made to Figure 2 the detailed description of step 204 in the shown embodiment.
[0434] The transceiver 1303 is configured to send the second authentication information to the core network device through the control plane interface, where the second authentication information is used for the core network device to authenticate the fixed network device. For details, reference may be made to Figure 2 the detailed description of step 205 in the embodiment shown.
[0435] In another embodiment, the communication device 1300 may further execute the steps performed by FMIF in the Figure 2 embodiment shown, such as steps 207, 208, 214, 215, 219, 220, etc. Details are not described herein one by one.
[0436] Refer to Figure 14 , a schematic diagram of a communication device 1400 provided by an embodiment of the present application. The device 1400 includes a processor 1401, a memory 1402, and a transceiver 1403, and the processor 1401 is connected to the memory 1402 and the transceiver 1403.
[0437] The device 1400 is a hardware-structured device and can be used to implement Figure 7 or Figure 9 the functional modules in the Figure 7 device shown. For example, those skilled in the art can conceive that Figure 9 the processing unit 702 in the device 700 shown or Figure 7 the processing unit 902 in the device 900 shown can be implemented by the processor 1401 calling the code in the memory 1402, Figure 9 and the receiving unit 701 and the sending unit 703 in the device 700 shown or
[0438] the receiving unit 901 and the sending unit 903 in the device 900 shown can be implemented by the transceiver 1403.
[0439] Optionally, the above-mentioned processor 1401 may be one or more central processing units (CPUs), microprocessors, application-specific integrated circuits (ASICs), or one or more integrated circuits for controlling the execution of the program of the solution of the present application. Figure 1 The processor 1401 is configured to execute the instructions in the memory 1402 and perform the processing steps of FMIF in the Figure 2 embodiment shown, or execute the steps performed by the core network device in the
[0440] The memory 1402, the processor 1401, and the transceiver 1403 are interconnected via a bus 1404; the bus 1404 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0441] In a specific embodiment, the transceiver 1403 is configured to receive a session establishment request message from a Fixed-Mobile Interworking Function (FMIF), where the session establishment request message includes an identifier of a fixed network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G; specifically, reference can be made to Figure 2 the detailed description of step 205 in the illustrated embodiment.
[0442] The processor 1401 is configured to allocate session information for the fixed network device according to the identifier of the fixed network device, where the session information includes the address of the fixed network device, the Tunnel Endpoint Identifier (TEID) of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The tunnel is the tunnel corresponding to the fixed network device between the FMIF and the core network device; specifically, reference can be made to Figure 2 the detailed description of step 206 in the illustrated embodiment.
[0443] The transceiver 1403 is configured to send the session information to the FMIF, and the session information is used by the FMIF to establish a data plane connection between the fixed network device and the core network device. Specifically, reference can be made to Figure 2 the detailed description of step 206 in the illustrated embodiment.
[0444] In another embodiment, the communication device 1400 can further execute respectively Figure 2 the steps implemented by the core network device in the illustrated embodiment, such as steps 209, 210, 216 - 218, etc. Details are not described one by one here.
[0445] Refer to Figure 15 , a schematic diagram of a communication device 1500 provided in an embodiment of the present application. The device 1500 includes a processor 1501, a memory 1502, and a transceiver 1503, and the processor 1501 is connected to the memory 1502 and the transceiver 1503.
[0446] The communication device 1500 is a device with a hardware structure and can be used to implement Figure 10 or Figure 11The functional modules in the described device. For example, those skilled in the art can conceive of Figure 10 the processing unit 1002 in the device 1000 shown in Figure 11 or the processing unit 1102 in the device 1100 shown in can be implemented by the processor 1501 calling the code in the memory 1502. Figure 10 the receiving unit 1001 and the sending unit 1003 in the device 1000 shown in Figure 11 or the receiving unit 1101 and the sending unit 1103 in the device 1100 shown in can be implemented by the transceiver 1503.
[0447] Optionally, the above-mentioned processor 1501 may be one or more central processing units (CPUs), microprocessors, application-specific integrated circuits (ASICs), or one or more integrated circuits for controlling the execution of the program of the solution of the present application.
[0448] The processor 1501 is used to execute the instructions in the memory 1502 and execute the processing steps applied to Figure 3 the embodiment AGF shown in, or execute Figure 4 the steps implemented by AGF in the shown embodiment.
[0449] The memory 1502, the processor 1501, and the transceiver 1503 are interconnected with each other through a bus 1504; the bus 1504 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0450] In a specific embodiment, the transceiver 1503 is used to receive the dialing message sent by the fixed network device; for details, reference can be made to Figure 4 the detailed description of step 401 in the shown embodiment.
[0451] The processor 1501 is used to generate the first authentication information of the fixed network device according to the dialing message, and the first authentication information includes the identifier of the fixed network device; encapsulate the first authentication information to obtain the second authentication information; for details, reference can be made to Figure 4 the detailed description of steps 402-403 in the shown embodiment.
[0452] The transceiver 1503 is configured to send the second authentication information to a core network device, where the second authentication information is used by the access network device to authenticate the fixed network device, and the core network device belongs to a communication network version of 5G communication network or a communication network higher than 5G. Specifically, reference may be made to Figure 2 Step 404 in the embodiment shown.
[0453] In another embodiment, the communication device 1500 may further respectively execute Figure 4 The steps implemented by the AGF in the embodiment shown, such as steps 405-407, 409-413, 416-418, etc. Details are not described herein one by one.
[0454] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disk, or the like.
[0455] The above are only optional embodiments of the present application, and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A communication method, characterized in that, The method includes: An Access Gateway Function (AGF) receives a dialing message sent by a fixed network device; The AGF sends second authentication information to a core network device through a control plane interface, where the second authentication information is used for the core network device to authenticate the fixed network device. The second authentication information includes an identifier of the fixed network device. The control plane interface is an interface in the AGF for communicating with the core network device, and the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G; Wherein, the fixed network device is a Fixed Network Residential Gateway (FN-RG), the identifier of the fixed network device is a Line ID, the control plane interface includes an N1 interface or an N2 interface, and the second authentication information is a Subscriber Concealed Identifier (SUCI), an encrypted Subscriber Concealed Identifier (SUPI), or a 5G Globally Unique Temporary UE Identity (5G-GUTI).
2. The method according to claim 1, wherein The method further includes: The AGF encapsulates the identifier of the fixed network device according to the message format supported by the control plane interface to obtain the second authentication information.
3. The method according to claim 1 or 2, characterized in that, The method further includes: The AGF sends a session establishment request message to the core network device, where the session establishment request message is used for the core network device to allocate session information. The session information includes an address of the fixed network device, a Tunnel Endpoint Identifier (TEID) of the tunnel on the core network device side, and tunnel parameters of the tunnel. The tunnel is a tunnel corresponding to the fixed network device between the AGF and the core network device.
4. The method according to claim 3, wherein The method further includes: The AGF receives the session information sent by the core network device; The AGF establishes the tunnel according to the session information.
5. The method according to claim 3, wherein The method further includes: The AGF stores the correspondence between the address of the fixed network device, the TEID of the tunnel on the AGF side, and the TEID of the tunnel on the core network device side in a second relationship table, where the second relationship table is used for the AGF to send an uplink service message of the fixed network device.
6. The method according to claim 4, wherein The session information further includes the TEID of the tunnel on the AGF side.
7. The method according to claim 3, wherein The method further includes: The AGF allocates the TEID of the tunnel on the AGF side; The AGF sends the TEID of the tunnel on the AGF side to the core network device.
8. The method according to claim 3, wherein The AGF sends the session establishment request message to the core network device through the control plane interface.
9. A communication method, characterized in that, The method includes: An Access Gateway Function (AGF) receives a dialing message sent by a fixed network device; The AGF sends second authentication information to the core network device through a control plane interface. The second authentication information is used by the core network device to authenticate the fixed network device. The second authentication information includes the identifier of the fixed network device. The control plane interface is an interface in the AGF for communicating with the core network device. The communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The fixed network device is a fixed network home gateway FN-RG. The identifier of the fixed network device is a line identifier Line ID. The control plane interface includes an N1 interface or an N2 interface. The second authentication information is a subscriber concealed identifier SUCI, an encrypted subscriber concealed identifier SUPI, or a 5G globally unique temporary UE identifier 5G-GUTI; After the core network device successfully authenticates the fixed network device, the AGF receives a first uplink service message from the fixed network device; The AGF encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message. The tunnel is a tunnel corresponding to the fixed network device between the AGF and the core network device; The AGF sends the second uplink service message to the core network device through the tunnel.
10. The method according to claim 9, wherein The AGF encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message, including: The AGF obtains the tunnel endpoint identifier TEID on the AGF side and the TEID on the core network device side of the tunnel from a second relationship table according to the address of the fixed network device. The second relationship table is used to store the correspondence between the address of the fixed network device, the TEID on the AGF side, and the TEID on the core network device side; The AGF adds a message header corresponding to the tunnel to the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain the second uplink service message. The message header includes the obtained TEID on the AGF side and the TEID on the core network device side.
11. The method according to claim 9 or 10, characterized in that, The AGF encapsulates the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message, including: The AGF detects whether the first uplink service message is a message of a mobile network service according to a preset field in the message header of the first uplink service message; When the first uplink service message is a message of a mobile network service, perform the operation of encapsulating the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain the second uplink service message.
12. The method according to claim 9 or 10, characterized in that, The method further includes: The AGF receives a first downlink service message sent by the core network device to the fixed network device; The AGF decapsulates the first downlink service message according to the decapsulation method corresponding to the tunnel to obtain a second downlink service message; The AGF sends the second downlink service message to the fixed network device.
13. The method according to claim 12, characterized in that, The AGF decapsulates the first downlink service message according to the decapsulation method corresponding to the tunnel to obtain a second downlink service message, including: The AGF removes the packet header corresponding to the tunnel from the first downlink service packet according to the decapsulation method corresponding to the tunnel to obtain the second downlink service packet.
14. The method according to claim 12, wherein The tunnel is a General Packet Radio Service Tunneling Protocol User Plane (GTP-U) tunnel.
15. The method according to claim 9 or 10, characterized in that The AGF sends the second uplink service packet to the core network device through a data plane interface, and the data plane interface includes an N3 interface.
16. A communication method, characterized in that, The method includes: The core network device receives second authentication information sent by an Access Gateway Function (AGF) through a control plane interface. The second authentication information includes an identifier of a fixed network device, the fixed network device is a Fixed Network Residential Gateway (FN-RG), the identifier of the fixed network device is a Line ID, the control plane interface is an interface in the AGF for communicating with the core network device, and the control plane interface includes an N1 interface or an N2 interface. The second authentication information is a Subscriber Concealed Identifier (SUCI), an encrypted Subscriber Unique Identifier (SUPI), or a 5G Globally Unique Temporary UE Identity (5G-GUTI). The communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G. The core network device authenticates the fixed network device according to the second authentication information.
17. The method according to claim 16, wherein The method further includes The core network device receives a session establishment request message from the AGF, and the session establishment request message includes an identifier of a fixed network device. The core network device allocates session information for the fixed network device. The session information includes an address of the fixed network device, a Tunnel Endpoint Identifier (TEID) of the tunnel on the core network device side, and tunnel parameters of the tunnel. The tunnel is a tunnel corresponding to the fixed network device between the AGF and the core network device. The core network device sends the session information to the AGF, and the session information is used by the AGF to establish a data plane connection between the fixed network device and the core network device.
18. The method according to claim 17, wherein The session information further includes a TEID of the tunnel on the AGF side.
19. The method according to claim 17 or 18, wherein The method further includes: The core network device receives the TEID of the tunnel on the AGF side sent by the AGF. The TEID of the tunnel on the AGF side is sent through the session establishment request message or is sent after the AGF receives the session information.
20. The method according to claim 17 or 18, characterized in that, After the core network device sends the session information to the AGF, it further includes: The core network device saves the correspondence between the address of the fixed network device, the TEID of the tunnel on the AGF side, and the TEID of the tunnel on the core network device side into a correspondence table, and the correspondence table is used by the core network device to transmit downlink service packets of the fixed network device.
21. The method according to any one of claims 16 to 18, characterized in that After the core network device passes the authentication of the fixed network device, the method further includes: Receive a second uplink service message from the AGF, where the second uplink service message is obtained by the AGF encapsulating a first uplink service message from the fixed network device based on the encapsulation method corresponding to the tunnel, and the tunnel is a tunnel corresponding to the fixed network device between the AGF and the core network device; The core network device decapsulates the second uplink service message according to the decapsulation method corresponding to the tunnel to obtain the first uplink service message.
22. The method according to claim 21, wherein, The method further includes: The core network device obtains a second downlink service message to be sent to the fixed network device; The core network device encapsulates the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain a first downlink service message; The core network device sends the first downlink service message to the AGF through the tunnel.
23. The method according to claim 22, wherein The second downlink service message includes the address of the fixed network device; The core network device encapsulating the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain a first downlink service message includes: The core network device obtains the tunnel endpoint identifier TEID on the AGF side and the TEID on the core network device side from the correspondence table according to the address of the fixed network device, and the correspondence table is used to store the correspondence between the address of the fixed network device, the TEID on the AGF side and the TEID on the core network device side; The core network device adds a message header corresponding to the tunnel to the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain the first downlink service message, and the message header includes the obtained TEID on the AGF side and the TEID on the core network device side.
24. The method according to claim 21, wherein The tunnel is a General Packet Radio Service Tunneling Protocol User Plane GTP-U tunnel.
25. A communication system, characterized in that, Including: An Access Gateway Function AGF and a core network device, where the communication network version to which the core network device belongs is a 5G communication network or a communication network higher than 5G; The AGF is configured to receive a dialing message sent by a fixed network device and send second authentication information to the core network device through a control plane interface, where the second authentication information includes an identifier of the fixed network device, the fixed network device is a Fixed Network Residential Gateway FN-RG, the identifier of the fixed network device is a Line ID, the control plane interface is an interface in the AGF for communicating with the core network device, and the control plane interface includes an N1 interface or an N2 interface, and the second authentication information is a Subscriber Concealed Identifier SUCI, an Encrypted Subscriber Concealed Identifier SUPI or a 5G Globally Unique Temporary UE Identifier 5G-GUTI; The core network device is configured to authenticate the fixed network device according to the second authentication information.
26. The system according to claim 25, wherein The AGF is further configured to send a session establishment request message to the core network device, and the session establishment request message carries the identifier of the fixed network device; The core network device is further configured to allocate session information, where the session information includes the address of the fixed network device, the tunnel endpoint identifier (TEID) of the tunnel on the core network device side, and the tunnel parameters of the tunnel. The session information sent to the AGF is for the tunnel corresponding to the fixed network device between the AGF and the core network device; The AGF is further configured to establish a data plane connection corresponding to the fixed network device between the AGF and the core network device and establish the tunnel according to the session information.
27. The system according to claim 25 or 26, wherein, The AGF is further configured to, after the core network device authenticates the fixed network device successfully, receive a first uplink service message from the fixed network device; encapsulate the first uplink service message according to the encapsulation method corresponding to the tunnel to obtain a second uplink service message; Send the second uplink service message to the core network device through the tunnel, where the tunnel is the tunnel corresponding to the fixed network device between the AGF and the core network device; The core network device is configured to de-encapsulate the second uplink service message according to the de-encapsulation method corresponding to the tunnel to obtain the first uplink service message.
28. The system according to claim 27, wherein, The core network device is further configured to obtain a second downlink service message to be sent to the fixed network device; encapsulate the second downlink service message according to the encapsulation method corresponding to the tunnel to obtain a first downlink service message; send the first downlink service message to the AGF through the tunnel; The AGF is further configured to de-encapsulate the first downlink service message according to the de-encapsulation method corresponding to the tunnel to obtain the second downlink service message; send the second downlink service message to the fixed network device.
29. The system according to claim 26, wherein The tunnel is a General Packet Radio Service Tunneling Protocol User Plane (GTP-U) tunnel.
30. A communication device, characterized in that, The device includes: A processor and a memory, where the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the instructions of the method according to any one of claims 1 to 24.
31. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program, and the computer program is loaded and executed by a processor to implement the instructions of the method according to any one of claims 1 to 24.
Citation Information
Patent Citations
Network accessing method and device as well as network equipment
CN108738013A
Registration method and device
CN108934022A