Service access processing method, device, equipment and storage medium
By identifying and processing private network services in public network services in 5G networks, user terminals can carry public and private network services on a single session channel, solving the problem that user terminals need to support multiple DNN functions and cumbersome operations, and improving user experience.
Patent Information
- Application Number
- CN202210449285.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-27
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2042-04-27
AI Technical Summary
The existing multi-DNN technical solution requires user terminals to support multi-DNN functions and need to install a dedicated network service APP on the user terminal, resulting in cumbersome operations and being unable to directly access the dedicated network service through the public network service interface.
In the 5G network, the session user-plane network element recognizes the private network services contained in the public network service, sends access events to the control surface network element, starts the private network session process, and replaces the IP address in the user-plane network element to realize data transmission of the private network service and avoids cumbersome configuration of the user terminal.
It realizes that the user terminal carries public and private network services through a single session channel, and the network can be billed and controlled separately. Users can access private network services in public network services without additional operations, improving user experience.
Smart Images

Figure CN115529342B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a service access processing method, device, equipment and storage medium. Background Art
[0002] The multi-DNN (Data Network Name) technical solution refers to signing up users for a general DNN (for example: DNN1) for public network services and a dedicated DNN (for example: DNN2) for private network services. When a user needs to use a public network service, the user uses a general DNN through the user terminal to initiate a PDU session establishment request, and the 5G network establishes a PDU session of general DNN1 for the user terminal to facilitate public network services; when a user needs to use a private network service, the user uses a dedicated DNN through the user terminal to initiate a PDU session establishment request, and the 5G network establishes a PDU session of dedicated DNN for the user terminal to facilitate private network services. As mentioned above, when a user needs to access a private network service while using a public network service, he needs to manually perform the corresponding operation on the user terminal, such as manually activating the corresponding APP on the user terminal interface, and calling the user terminal through the APP to activate the dedicated DNN to achieve access to the private network service. It can be seen that in the existing multi-DNN technical solutions, for users who have needs for both public network services and private network services, on the one hand, they must use user terminals that support multi-DNN functions; on the other hand, they need to install and configure the APP that calls the private network DNN on the user terminal, and manually activate the private network service APP when using the private network service. They cannot use the private network service by clicking on the relevant link on the public network service interface. This not only limits the user's selection of user terminals, but also causes the user to perform more cumbersome operations on the user terminal for private network services. Summary of the Invention
[0003] The embodiments of the present invention provide a service access processing method, apparatus, equipment and storage medium, aiming to solve the problem of enabling a user terminal to carry public network services and private network services through a single session channel, and the network being able to separately bill and manage the private network services and public network services of the user terminal, so as to solve the technical problem that the existing DNN technical solution requires the user terminal to support multiple DNN functions and that the private network services need to be configured and used in a relatively cumbersome manner on the user terminal that supports multiple DNN functions.
[0004] An embodiment of the present invention provides a service access processing method, which is applied to a packet domain device in a mobile communication network. The service access processing method includes:
[0005] Based on the public network service initiated by the user terminal, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, the first session user plane network element sends an access event of the private network service to the first session control plane network element of the public network service;
[0006] The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user;
[0007] The first session user plane network element replaces the first user IP address in all UL uplink data packets of the private network service transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets to the private network through the private network session channel user plane; and
[0008] The first session user plane network element replaces the second user IP address in the DL downlink data message sent from the private network to the user terminal with the first user IP address, and sends the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
[0009] In one embodiment, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, the first session user plane network element sends an access event of the private network service to the first session control plane network element of the public network service, and further includes:
[0010] The first session user plane network element caches all UL uplink data packets of the private network service in the public network session channel user plane; and
[0011] The public network session channel user plane forwards the UL uplink data message and DL downlink data message of the public network service; wherein, the public network service forwarded by the public network session channel user plane does not include the private network service, and the public network service forwarded by the public network session channel user plane does not trigger the process of establishing a private network session for the user.
[0012] In one embodiment, the first session user plane network element replaces the first user IP address in all UL uplink data packets of the private network service transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets to the private network through the private network session channel user plane, including:
[0013] After the private network session channel user plane is established, the first session user plane network element will replace the first user IP address in all UL uplink data messages of the private network service cached before the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and will replace the first user IP address in all UL uplink data messages of the private network service received after the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and will transmit all the replaced UL uplink data messages of the private network service cached before the private network session channel user plane is established and all the replaced UL uplink data messages of the private network service received after the private network session channel user plane is established to the private network in sequence through the private network session channel user plane.
[0014] In one embodiment, the service access processing method further includes:
[0015] The first session user plane network element obtains the destination address information in the UL uplink data message sent by the user terminal, and when identifying that the destination address information is the same as the preset destination address information of the private network service, determines that the UL uplink data message is a private network service;
[0016] The preset destination address information of the private network service is obtained by at least one of the following methods:
[0017] The preset destination address information of the private network service is obtained by the first session user plane network element from its own local configuration;
[0018] The preset destination address information of the private network service is obtained by the first session user plane network element from the preset private network service rule related information sent to itself by the first session control plane network element;
[0019] The preset private network service rule related information is obtained by the first session control plane network element through the PCC method and / or its own local configuration, and the preset private network service rule related information is sent to the first session user plane network element during the process of establishing the public network session channel user plane for the user terminal;
[0020] The first session control plane network element obtains the preset private network service rule related information through the PCC in at least one of the following ways:
[0021] In the process of establishing a public network session for the user terminal, the policy control network element sends a full amount of information related to the preset private network service rules to the first session control plane network element;
[0022] During the process of establishing a public network session for the user terminal, the policy control network element issues a PCC predefined rule to the first session control plane network element. The first session control plane network element obtains the preset private network service rule-related information from its own locally configured PCC predefined policy based on the PCC predefined rule, where the preset private network service rule-related information includes at least a PCC policy identifier, public network name-related information, preset destination address information of the private network service, private network name-related information required for establishing the private network session, and user identifier information.
[0023] In one embodiment, the service access processing method further includes:
[0024] The first session user plane network element obtains the private network name related information required for establishing the private network session that matches the destination address information from the preset private network service rule related information, and generates the access event of the private network service according to the private network name related information required for establishing the private network session; or
[0025] The first session user plane network element generates an access event for the private network service according to the destination address information.
[0026] In one embodiment, based on the public network service initiated by the user terminal, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, before sending the access event of the private network service to the first session control plane network element of the public network service, the method further includes:
[0027] When the session establishment initiating network element receives the public network service activation request initiated by the user terminal, it selects the first session control plane network element corresponding to the public network service of the user terminal and sends a public network session establishment request to the first session control plane network element;
[0028] The first session control plane network element selects a first session user plane network element, and controls the first session user plane network element to establish a public network session channel user plane for the public network service and allocate the first user IP address to the user terminal; wherein, the first user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0029] In one embodiment, the first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, wherein establishing the user plane of the private network session channel for the user includes:
[0030] The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the preset private network service rule related information to obtain the private network name related information required for establishing the private network session based on the destination address information;
[0031] When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element does not also serve as the second session user plane network element, the first session control plane network element determines the second user IP address and the second session user plane network element, and sends the second user IP address to the first session user plane network element; and
[0032] The first session control plane network element controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0033] In one embodiment, the first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, thereby establishing the user plane of the private network session channel for the user, further comprising:
[0034] The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the preset private network service rule related information to obtain the private network name related information required for establishing the private network session based on the destination address information;
[0035] When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element also serves as the second session user plane network element, the first session control plane network element determines the second user IP address and sends the second user IP address to the first session user plane network element; and
[0036] The first session control plane network element controls the first session user plane network element to establish the private network session channel user plane corresponding to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0037] In one embodiment, the first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, thereby establishing the user plane of the private network session channel for the user, further comprising:
[0038] The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the preset private network service rule related information to obtain the private network name related information required for establishing the private network session based on the destination address information;
[0039] When the first session control plane network element determines that it does not concurrently serve as the second session control plane network element and the first session user plane network element does not concurrently serve as the second session user plane network element, the first session control plane network element determines the second session control plane network element and the second session user plane network element, and sends a private network session establishment request to the second session control plane network element; wherein the first session control plane network element determines the second session control plane network element using the same or similar method as that used by the session establishment initiating network element to determine the session control plane network element;
[0040] The second session control plane network element returns a private network session establishment response to the first session control plane network element, where the private network session establishment response includes at least the second user IP address and interface address information of a related interface of the second session user plane network element;
[0041] When the first session control plane network element receives the private network session establishment response, it sends the second user IP address to the first session user plane network element, and controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0042] In one embodiment, the first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user, further comprising:
[0043] When the first session control plane network element determines that the private network needs to start secondary authentication / authorization and it itself stores the user authentication information required for secondary authentication of the user terminal, it can act on behalf of the user terminal to perform the secondary authentication / authorization process according to the local configuration or the preset private network business rule related information, and control the first session user plane network element to execute the relevant authorization of the private network to the user terminal.
[0044] In one embodiment, transmitting the replaced UL uplink data packet to the private network through the private network session channel user plane includes:
[0045] The first session user plane network element executes a service diversion rule to determine a private network session channel identifier according to the UL uplink data message, and transmits the replaced UL uplink data message to the private network through the private network session channel user plane corresponding to the private network session channel identifier.
[0046] In one embodiment, the first session user plane network element replacing the second user IP address in a DL downlink data packet sent from the private network to the user terminal with the first user IP address, and sequentially sending the replaced DL downlink data packet to the user terminal through the public network session channel user plane and the base station includes:
[0047] The first session user plane network element executes a service aggregation rule to aggregate target DL downlink data transmitted by the private network session channel user plane corresponding to the private network session channel identifier into the public network session channel user plane between the first session user plane network element and the base station;
[0048] Replacing the second user IP address in a DL downlink data message sent by the private network to the user terminal with the first user IP address;
[0049] Sending the replaced DL downlink data message to the user terminal in sequence through the first session user plane network element and the base station of the public network session channel user plane; or,
[0050] The replaced DL downlink data message is sent to the user terminal in sequence through the first session user plane network element, the intermediate session user plane network element and the base station of the public network session channel user plane.
[0051] In one embodiment, the first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so that after the user plane of the private network session channel is established for the user, the method further includes:
[0052] When the preset condition is met, the first session control plane network element sends a notification message to the corresponding session establishment initiating network element according to the previously obtained session establishment initiating network element identifier, so as to notify the session establishment initiating network element to count the number of user planes of the private network session channel.
[0053] In one embodiment, the service access processing method further includes:
[0054] The first session control plane network element and the first session user plane network element perform segmented management on the public network session channel user plane and the private network session channel user plane, and perform session management, traffic statistics and billing on the public network session corresponding to the public network service and the private network session corresponding to the private network service, respectively.
[0055] In one embodiment, the service access processing method further includes:
[0056] At least two QoS Flows are used to associate with the user plane of the public network session channel and the user plane of the private network session channel respectively, so as to perform end-to-end session control, traffic statistics and billing for the public network session corresponding to the public network service and the private network session corresponding to the private network service respectively.
[0057] In addition, to achieve the above-mentioned purpose, the present invention further provides a service access processing device, the service access processing device comprising:
[0058] An event sending module is configured to send an access event of the private network service to the first session control plane network element of the public network service when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service based on the public network service initiated by the user terminal;
[0059] a session establishing module, configured to use the first session control plane network element to initiate a process of establishing a private network session for the user according to the access event, and control the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user;
[0060] a service offload module, configured to replace, using the first session user plane network element, the first user IP address in the UL uplink data packets of all the private network services transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmit the replaced UL uplink data packets to the private network through the private network session channel user plane;
[0061] The service aggregation module is used to use the first session user plane network element to replace the second user IP address in the DL downlink data message sent by the private network to the user terminal with the first user IP address, and send the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
[0062] In addition, to achieve the above-mentioned purpose, the present invention also provides a mobile communication network packet domain device, which includes: a memory, a processor, and a service access processing program stored on the memory and capable of running on the processor, and when the service access processing program is executed by the processor, the steps of the above-mentioned service access processing method are implemented.
[0063] In addition, to achieve the above-mentioned purpose, the present invention further provides a storage medium on which a service access processing program is stored. When the service access processing program is executed by a processor, the steps of the above-mentioned service access processing method are implemented.
[0064] For users who need both public and private network services, the existing multi-DNN technology solution requires:
[0065] (1) The user terminal supports multiple DNN functions and can configure the dedicated DNN required for private network services on the relevant interface of the user terminal;
[0066] (2) A private network service APP is installed on the user terminal, and when the user activates the private network service APP, the APP calls the private network DNN of the private network service;
[0067] (3) When users use private network services, they need to first execute the operations of the private network service APP. They cannot use private network services by clicking on the relevant links on the public network service interface.
[0068] Due to the above defects in the existing multi-DNN technical solutions, the following results occur: when the user terminal used by the user does not support the multi-DNN function, the user cannot use public network services and private network services on the same terminal; when the user terminal used by the user supports the multi-DNN function, the user needs to perform more cumbersome operations on the user terminal to use the private network services.
[0069] In order to solve the above-mentioned defects, the present invention proposes a technical solution of a service access processing method, device, equipment and storage medium. After the user terminal initiates a public network service, the present invention uses the first session user plane network element to identify that the public network service transmitted by the public network session channel user plane includes a private network service, and sends an access event of the private network service to the first session control plane network element of the public network service. The first session control plane network element starts the process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute the process of establishing the private network session channel user plane for the user, so as to establish the private network session channel user plane for the user; the first session user plane network element sends the UL of all private network services transmitted by the public network session channel user plane to the public network session channel user plane. The first user IP address in the uplink data message is replaced by the second user IP address assigned to the user terminal by the network, and the replaced UL uplink data message is transmitted to the private network through the user plane of the private network session channel; the first session user plane network element replaces the second user IP address in the DL downlink data message sent by the private network to the user terminal with the first user IP address, and sends the replaced DL downlink data message to the user terminal through the user plane of the public network session channel and the base station in sequence. This technical solution solves the technical problems that the existing DNN technical solution requires the user terminal to support multiple DNN functions and that the user terminal supporting multiple DNN functions needs to perform relatively cumbersome configuration and service use operations for the private network service. The present invention realizes the carrying of public network services and private network services for user terminals through a single session channel, and the network can charge and manage the private network services and public network services of the user terminal separately. For user terminals that do not support multiple DNN functions, public network services and private network services can be provided to users at the same time. When a user uses a private network service through a user terminal that does not support the multi-DNN function or supports the multi-DNN function, the user does not need to perform tedious configuration on the user terminal. The user can start and use the private network service during the use of the public network service by simply clicking a link or entering the destination address on the public network page. The private network can be accessed without performing additional operations, which improves the user's perception of using the private network service through the user terminal and the user's service access experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] Figure 1 A schematic diagram of the hardware operating environment involved in an embodiment of the present invention;
[0071] Figure 2 A schematic diagram of a process for a first session user plane network element to obtain information related to preset private network service rules in the service processing method of the present invention;
[0072] Figure 3 A schematic diagram of the process of establishing a user plane of a public network session channel in the service processing method of the present invention;
[0073] Figure 4A schematic diagram of the present invention's 5G network with a single DNN / single IP address for a user terminal and multiple DNNs on the network side for traffic diversion and aggregation control.
[0074] Figure 5 1 is a specific flow chart of step S220 / step C20 in the business processing method of the present invention;
[0075] Figure 6 This is another specific flow chart of step S220 / step C20 in the business processing method of the present invention;
[0076] Figure 7 2 is another specific flow chart of step S220 / step C20 in the business processing method of the present invention;
[0077] Figure 8 A schematic diagram of the mapping relationship between the first user's IP address and the second user's IP address;
[0078] Figure 9 This is a schematic diagram of a single APN / single IP address for a user terminal in a 4G network and multiple APNs on the network side for traffic distribution and aggregation management.
[0079] Figure 10 This is a functional module diagram of the business processing system of the present invention. DETAILED DESCRIPTION
[0080] To better understand the above technical solutions, exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein. Instead, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.
[0081] like Figure 1 As shown, Figure 1 This is a schematic diagram of the structure of the hardware operating environment involved in the embodiment of the present invention.
[0082] It should be noted that Figure 1 This is a structural diagram of the hardware operating environment of the packet domain device of the mobile communication network.
[0083] As a way to implement this, Figure 1 As shown, the embodiment of the present invention relates to a mobile communication network packet domain device, which includes: a processor 1001, such as a CPU, a memory 1002, and a communication bus 1003. The communication bus 1003 is used to implement connection and communication between these components.
[0084] The memory 1002 may be a high-speed RAX memory or a stable memory (non-volatile RAXory), such as a disk memory. Figure 1 As shown, the memory 1002 as a storage medium may include a service access processing program; and the processor 1001 may be used to call the service access processing program stored in the memory 1002 and perform the following operations:
[0085] Based on the public network service initiated by the user terminal, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, the first session user plane network element sends an access event of the private network service to the first session control plane network element of the public network service;
[0086] The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user;
[0087] The first session user plane network element replaces the first user IP address in all UL uplink data packets of the private network service transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets to the private network through the private network session channel user plane; and
[0088] The first session user plane network element replaces the second user IP address in the DL downlink data message sent from the private network to the user terminal with the first user IP address, and sends the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
[0089] The embodiment of the present invention provides an embodiment of a service access processing method. It should be noted that although a logical sequence is shown in the flowchart, in some cases, the steps shown or described may be executed in an order different from that shown here.
[0090] The terms involved in each embodiment of the present invention in the 5G network scenario are explained as follows: UPF (User Plane Function) is the user plane function, UDM (Unified Data Management) is the unified user data management function, UDR (Unified Data Repository) is the unified user data storage function, DNN (Data Network Name) is the data network name, PCF (Policy Control Function) is the policy control function, S-NSSAI (Single Network Slice Selection Assistance Information) is the single network slice selection auxiliary information, which can also be referred to as the network slice identifier, PCC (Policy and Charging Control) is the policy and charging control, URL / URI (Uniform Resource Locator / Uniform Resource Identifier) is the uniform resource locator / uniform resource identifier, AMF (Access and Mobility Management Function) is the access and mobility management network element, SMF (Session Management Function) is the session management function, I-SMF (Intermediate SMF) is the intermediate SMF, which means the intermediate control plane function, I-UPF (Intermediate SMF) is the intermediate SMF, which means the intermediate control plane function. The UPF (Uniform Provider Function) is the intermediate user plane function, the NRF (Network Repository Function) is the network resource database function, the gNB (gNodeB) is a wireless 5G base station, and the UE (User Equipment) is the user equipment, commonly referred to as a user terminal, such as a 5G mobile phone. A public network DNN is, for example, the Internet DNN, such as the CMNET DNN for China Mobile; a private network DNN is, for example, the enterprise private network DNN. Public network DNN services are called public network services, and private network DNN services are called private network services. A public network session is a PDU (Protocol Data Unit) session of the public network DNN, and the public network session channel user plane is the user plane of the public network session. A private network session is a PDU (Protocol Data Unit) session of the private network DNN, and the private network session channel user plane is the user plane of the private network session.
[0091] like Figure 3As shown, in the first embodiment of the present invention in the 5G network scenario, the service processing method of the present invention, the service processing method includes the following steps S210-S240. This embodiment belongs to the access scenario of the 5G network and supports 5G users. The service processing method is applied to the packet domain equipment of the mobile communication network, and the packet domain equipment of the mobile communication network at least includes a session establishment initiating network element, a first session control plane network element, a second session control plane network element, a first session user plane network element, and a second session user plane network element; usually the packet domain equipment of the mobile communication network will also include: a policy control network element. In some specific scenarios, the first session control plane network element can also serve as the second session control plane network element, and the first session user plane network element can also serve as the second session user plane network element. In the 5G network, the session establishment initiating network element is AMF, the session control plane network element is SMF, the session user plane network element is UPF, the policy control network element is PCF / UDR, the intermediate session control plane network element is I-SMF (Intermediate SMF), the intermediate session user plane network element is I-UPF (Intermediate UPF), the first session control plane network element is represented as the first target SMF, the second session control plane network element is represented as the second target SMF, the first session user plane network element is represented as the first target UPF, and the second session user plane network element is represented as the second target UPF, that is, in some specific scenarios, the first target SMF can be used as the second target SMF, and the first target UPF can be used as the second target UPF.
[0092] like Figure 4 As shown, the session establishment initiating network element corresponds to AMF1, the first target SMF corresponds to SMF1, the second target SMF corresponds to SMF2, the first target UPF corresponds to UPF1, the second target UPF corresponds to UPF2, the intermediate session control plane network element corresponds to I-SMF1, the intermediate session user plane network element corresponds to I-UPF1, and the policy control network element is PCF / UDR. Before executing step S210, the network element corresponding to Figure 4 Perform the following steps:
[0093] Table 1 (5G-related PCC information)
[0094]
[0095] In Table 1, 1) if the same user has only one private network DNN service, the "sequence number" parameter is not required; 2) the destination URL / URI and IP address of private network DNN1 and private network DNN2 cannot be repeated, which needs to be guaranteed when pre-setting the PCC policy.
[0096] Step 0: User signing, including:
[0097] (1) The user's UDM / UDR signs a contract for the user to activate the public network DNN and the network slice identifier S-NSSAI of the public network DNN, the private network DNN and the network slice identifier S-NSSAI of the private network DNN.
[0098] (2) The PCC policy for activating the "private network service diversion strategy in public network service" when the user's PCF / UDR is signed and activated is called the preset PCC policy. The preset PCC policy indicates that when the destination address is detected as one of the destination URL / URI and destination IP address of "private network" in the UL uplink data message of the PDU session of the public network DNN (hereinafter referred to as the public network session), the "private network DNN" is activated for the user. Among them, the destination address in the UL uplink data message should be within the range of all private network destination URL / URI and destination IP address included in the PCC policy information. The information / parameters contained in the preset PCC policy are shown in Table 1.
[0099] (3) When the PCF / UDR issues PCC predefined rules and the SMF locally configures PCC predefined policies, the "destination URL / URI and destination IP address" of the private network service in Table 1 can be locally configured in SMF1, and the PCC predefined rules issued by PCF / UDR to SMF1 include the PCC predefined rule name information of "private network service diversion in public network service" and the related information of the private network name to be established ("private network DNN (including network slice identifier S-NSSAI)" in Table 1), and the diversion of multiple private network services in the public network service of the same user terminal can be achieved by increasing the number of PCC predefined policies for the user.
[0100] When a user activates a private network service, it is necessary to complete the contract for the private network DNN and the S-NSSAI to which the private network DNN belongs in the user's UDM / UDR, and the user will become a private network user at the same time; when it is necessary to provide the private network user with the service of "immediately establishing a dedicated channel for transmitting the corresponding private network service for the user when the private network service is identified in the user's public network service", it is necessary to sign the PCC policy of "diverting private network services from public network services" in the PCF / UDR to which the private network user belongs; in the subsequent process of establishing the PDU session of the user's public network DNN, the SMF1 responsible for the user's public network DNN service obtains the user's PCC policy of "diverting private network services from public network services" from the user's PCF / UDR.
[0101] As described above, the content in Table 1 is the minimum content included in the information related to the preset private network service rules. After a user activates the private network service and activates the service "immediately establish a dedicated channel for transmitting the corresponding private network service for the user when the private network service is identified in the user's public network service", the content in Table 1 is generated. This is completed before the user actually uses the private network service and can be understood as the information related to the preset private network service rules. Regardless of whether the PCC method is adopted, in which the PCF / UDR sends all the information related to the preset private network service rules to SMF1, or whether the PCF / UDR sends the PCC pre-defined rules and SMF1 locally configures the PCC pre-defined policies, before the user sends private network service data packets through the user plane channel of the public network PDU session, the content of the information related to the preset private network service rules has been obtained by SMF1 (see step 3-2 below for details). Furthermore, it can be understood that the PCC policy containing the information related to the preset private network service rules is the PCC policy related to the preset private network service rules, also known as the PCC policy for "diverting private network service from public network service". The information related to the preset private network service rules includes at least the PCC policy identifier, public network name information, preset destination address information of the private network service, private network name information required to establish a private network session, and user identification information. For details, see Table 1.
[0102] In actual application, when a user uses a public network service or a private network service, step S110 to step S120 are first performed. Figure 2 As shown:
[0103] Step S110: When the session establishment initiating network element receives the public network service activation request initiated by the user terminal, it selects a first session control plane network element corresponding to the public network service of the user terminal and sends a public network session establishment request to the first session control plane network element;
[0104] Step S120: The first session control plane network element selects a first session user plane network element, and controls the first session user plane network element to establish a public network session channel user plane for the public network service and allocate the first user IP address to the user terminal.
[0105] The first user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0106] Corresponding to Figure 4Step 1 to Step 3-1: The user uses public network services or private network services. The UE initiates a public network DNN activation request through the UE in the roaming location, also known as a public network service activation request. After AMF1 receives the public network service activation request initiated by the UE, AMF1 performs SMF service discovery to NRF. According to the service discovery result, if the user switches / roams across SMF POOLs, AMF1 selects I-SMF and the first target SMF, corresponding to Figure 4 I-SMF1 and SMF1; If the user does not switch / roam, or switches / roams within the SMF POOL, or activates the public network DNN for the first time, AMF1 directly selects the first target SMF, and there is no I-SMF (in Figure 4 There is no I-SMF1, only SMF1 exists), and the user's public network session establishment request is sent to the first target SMF, namely SMF1, wherein, Figure 4 If I-SMF1 exists, AMF1 sends the public network session establishment request to SMF1 via I-SMF1; if I-SMF1 does not exist, AMF1 sends the public network session establishment request directly to SMF1. After SMF1 of the public network DNN service (referred to as the public network service) performs UDM service discovery on the NRF, it obtains and subscribes to the user's SM (session management) subscription data from the user's home UDM / UDR. The SM subscription data contains the network slice identifier (S-NSSAI) and DNN allowed to be used by the user.
[0107] Step 3-2 to Step 6: The SMF1 of the public network service establishes a public network session for the UE, including SMF1 performing PCF service discovery to the NRF, and obtaining the user's contracted preset PCC policy and the selected first target UPF ( Figure 4 UPF1 in the UE) and sends a preset PCC policy to the selected UPF1, instructs the allocation of session resources for the public network session, and allocates the first user IP address to the UE ( Figure 4 The first user IP address is allocated by SMF1 and sent to the UE through AMF, and UPF1 obtains the first user IP address of the UE by identifying the source IP address in the UL uplink data message sent by the UE. Figure 4If there is an I-SMF1, I-SMF1 forwards the relevant message and instructs I-UPF1 to allocate relevant resources; if there is no I-SMF1, SMF1 communicates directly with AMF1. The above steps follow the 3GPP standard. Among them, after the first user IP address is assigned to the UE, it becomes the IP address of the UE, that is, Figure 4 The IP address 1 in the UL data packet is the source IP address in the UL data packet sent by the UE.
[0108] Furthermore, in the 3GPP standard process of steps 3-2 and 4, the SMF1 of the public network service and the UPF1 selected by the SMF1 need to add the execution processing of the PCC policy of the preset "private network service diversion strategy in the public network service", as follows:
[0109] (1) In step 3-2, through the PCC process, SMF1 of the public network service obtains information related to the preset private network service rules in the preset "Private network service diversion strategy in public network service", including the various parameter information shown in Table 1; specifically, the method of PCF / UDR publishing the full information in 1 to SMF1 can be adopted, or the method of PCF / UDR issuing PCC predefined rules to SMF1 and SMF1 locally configuring PCC predefined rules can be adopted. Among them, the specific process of SMF1 obtaining information related to the preset private network service rules is shown in (2) and (3) of the above step 0.
[0110] (2) After obtaining the information related to the preset private network service rules, including the parameter information in Table 1, the SMF1 of the public network service executes a process to ensure that the first user IP address allocated to the UE is different from the private network service destination IP address in the information related to the preset private network service rules. It should be understood that when the SMF1 of the public network service allocates the first user IP address to the UE, it is necessary to verify whether the first user IP address and the destination IP address of the private network DNN in the preset PCC policy obtained from the user's home PCF (the destination IP address in Table 1) are repeated or conflicting. If the addresses are repeated, the first user IP address to be allocated to the user needs to be replaced with a new first user IP address that is not repeated with the destination IP address of the private network DNN, so as to avoid the situation where the source IP address and the destination IP address are the same when the UE sends an UL uplink data message. Since the source IP address of the private network service UL uplink data message sent by the UE is the first user IP address, and the destination IP address cannot be the same as the source IP address, it is necessary to ensure that the first user IP address assigned to the UE by SMF1 cannot be the same as all the destination IP addresses in the preset destination address information in the preset private network service rule related information (i.e., all the IP addresses in the "destination URL / URI and destination IP address" in Table 1). If SMF1 finds that the first user IP address assigned to the UE is the same as any preset destination address information in the preset private network service rule related information, SMF1 will reallocate a user IP address to the UE, and the reallocated user IP address is an IP address that is different from all the destination IP addresses in the preset private network service rule related information, and the IP address information of the UE in the user's home PCF / UDR is updated through the subsequent PCC process. Among them, the IP address reallocated by SMF1 is the first user IP address.
[0111] (3) In step 4, the SMF1 of the public network service maps the obtained information related to the preset private network service rules to the N4 interface information and sends it to the UPF1 of the public network service. That is, SMF1 sends the information related to the preset private network service rules to UPF1. The information related to the preset private network service rules is shown in Table 1. Among them, SMF1 does not necessarily need to send all the information in Table 1 to UPF1, but it should at least include the "public network DNN (including the network slice identifier S-NSSAI)", "destination URL / URI and destination IP address" and user identification information in Table 1. It can also include "private network DNN (including the network slice identifier S-NSSAI)", and the specific information can be determined according to the situation. If the preset private network service rule information sent by the first session control plane network element to the first session user plane network element includes "private network DNN (including the network slice identifier S-NSSAI)", the subsequent process may correspond to "the first session control plane network element obtains the private network name information required for establishing the private network session and included in the access event" in steps S2211, S2221, and S2231. If the preset private network service rule information sent by the first session control plane network element to the first session user plane network element does not include "private network DNN (including the network slice identifier S-NSSAI)", the subsequent process may correspond to "the first session control plane network element obtains the destination address information included in the access event, and matches the preset private network service rule information based on the destination address information to obtain the private network name information required for establishing the private network session". During the execution of the above service processing, forwarding of data packets of the UE's public network service is not affected.
[0112] Obviously, there is another way to obtain all the information in Table 1. All the information in Table 1 can be achieved through local configuration in UPF1.
[0113] (4) The UPF1 of the public network service selected by the SMF1 of the public network service executes this preset PCC policy while forwarding the user data message of the public network service of the UE (including UL uplink data message and DL downlink data message). When the user data message (also called UL uplink data message) sent by the UE meets the conditions, that is, the destination URL / URI or destination IP address included in the UL uplink data message is the URL / URI in the "Destination URL / URI" or the IP address in the "Destination IP Address" field in Table 1, it is necessary to report the relevant event to the SMF1. The relevant event can be understood as an access event of the user using the private network service. It can also be understood that when a UL uplink data message including the destination address information of the URL / URI or IP address of the private network service is detected in the public network service of the UE, the access event of the private network service is reported to the SMF1. See step 7 described later for details.
[0114] The SMF1 of the public network service executes the preset PCC policy of "private network service diversion strategy in the public network service". When receiving the access event of the private network service reported by UPF1, it activates the PDU private network session (also called private network session) of the corresponding private network DNN for the user. That is, when UPF1 reports that a UL uplink data message with a destination address of the URL / URI or IP address of the private network service is detected in the public network service of the UE, it notifies SMF1 to activate the corresponding private network session for the user. For details, see step 8 described later.
[0115] Step S210: Based on the public network service initiated by the user terminal, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, it sends an access event of the private network service to the first session control plane network element of the public network service.
[0116] In this embodiment, after the user inputs the destination address information that he needs to access through the UE, the UE sends a UL uplink data message of the public network service or the private network service. The public network session channel user plane responsible for the public network service will transmit the UL uplink data message of the public network service and the private network service sent by the UE. UPF1 identifies whether the public network service transmitted by the public network session channel user plane includes the private network service, and decides whether to report the access event of the private network service to SMF1. If UPF1 identifies that the public network service includes the private network service, it means that the user needs to access the private network service, and the access event of the private network service is reported to SMF1.
[0117] Furthermore, the first session user plane network element identifies whether the public network service transmitted by the user plane of the public network session channel includes a private network service, including: the first session user plane network element obtains the destination address information in the UL uplink data message sent by the user terminal, and when it is identified that the destination address information is the same as the preset destination address information of the private network service, determines that the UL uplink data message is a private network service, that is, the public network service includes the private network service.
[0118] It should be understood that the user plane of the public network session channel transmits all UL uplink data messages corresponding to the user's use of private network services in the form of public network services. The UL uplink data messages include the destination address information entered by the user. If UPF1 identifies that the destination address information corresponding to the private network service included in the UL uplink data message is the same as the preset destination address information of the private network service, that is, the destination address information is the same as one of the destination URL / URI and destination IP address in the preset private network service rule related information, it can be determined that the UL uplink data message is a private network service, that is, the public network service includes the private network service.
[0119] The preset destination address information of the private network service is obtained by at least one of the following methods:
[0120] The preset destination address information of the private network service is obtained by the first session user plane network element from its own local configuration;
[0121] The preset destination address information of the private network service is obtained by the first session user plane network element from the preset private network service rule related information sent to itself by the first session control plane network element.
[0122] It should be understood that in the 5G scenario, all the information in Table 1 can be pre-stored in the local configuration of UPF1, because all the information in Table 1 includes the preset destination address information of the private network service. When UPF1 needs to obtain the preset destination address information of the private network service, UPF1 can obtain the preset destination address information of the private network service from its own local configuration; the preset destination address information of the private network service can also be sent to UPF1 by SMF1, SMF1 sends the preset private network service rule related information to UPF1, and UPF1 obtains the preset destination address information of the private network service from the preset private network service rule related information, that is: SMF1 of the public network service maps the obtained preset private network service rule related information to the N4 interface information and sends it to UPF1 of the public network service, SMF1 sends the preset private network service rule related information to UPF1, and the preset private network service rule related information is shown in Table 1. Among them, SMF1 does not necessarily need to send all the information in Table 1 to UPF1, but it should at least include the "public network DNN (including network slice identifier S-NSSAI)", "destination URL / URI and destination IP address" in Table 1, as well as information identifying the user. It can also include "private network DNN (including network slice identifier S-NSSAI)". Of course, it is not ruled out that UPF1 can obtain the preset destination address information of the private network service through other means. It is worth noting that the specific method of obtaining the preset destination address information of the private network service is set according to actual needs.
[0123] How does the first session control plane network element obtain information related to the preset private network service rules? Specifically:
[0124] The information related to the preset private network service rules is obtained by the first session control plane network element through the PCC method and / or its own local configuration, and the information related to the preset private network service rules is sent to the first session user plane network element during the process of establishing the public network session channel user plane for the user terminal.
[0125] It should be understood that in 5G scenarios, SMF1 can obtain information related to preset private network service rules through the PCC, or from its own local configuration. Of course, it is not ruled out that SMF1 may obtain information related to preset private network service rules through other means. It is worth noting that the specific method for obtaining information related to preset private network service rules is determined based on actual needs. Subsequently, SMF1 sends information related to preset private network service rules to UPF1 during the process of establishing the user plane of the public network session channel for the user terminal. The information related to preset private network service rules includes at least the PCC policy identifier, information related to the public network name, information related to the preset destination address of the private network service, information related to the private network name required to establish the private network session, and user identification information. The information related to the private network name refers to necessary information such as the private network name required to establish the private network session. The specific content of the information related to the private network name varies in different network scenarios. In 5G scenarios, the information related to the private network name includes at least the private network DNN and the network slice identifier (S-NSSAI) to which the private network DNN belongs, i.e., the private network name and network slice identifier.
[0126] Specifically, the first session control plane network element obtains the information related to the preset private network service rule through the PCC in at least one of the following ways:
[0127] In the process of establishing a public network session for the user terminal, the policy control network element sends a full amount of preset private network service rule information to the first session control plane network element;
[0128] During the process of establishing a public network session for a user terminal, the policy control network element sends the PCC predefined rules to the first session control plane network element. The first session control plane network element obtains information related to the preset private network service rules from its own locally configured PCC predefined policies based on the PCC predefined rules.
[0129] It should be understood that in the process of establishing the user plane of the public network session channel for the user terminal, it is the PCF / UDR that sends the full amount of information related to the preset private network service rules to SMF1. Alternatively, in the process of establishing the user plane of the public network session channel for the user terminal, the PCF / UDR sends the PCC predefined rules to SMF1, and SMF1 obtains the information related to the preset private network service rules from its own locally configured PCC predefined policies based on the PCC predefined rules. That is: in step 3-2, through the PCC process, the public network service SMF1 obtains the information related to the preset private network service rules in the preset "private network service diversion strategy in the public network service", including the various parameter information shown in Table 1; specifically, the method of PCF / UDR sending the full amount of information in Table 1 to SMF1 can be adopted, or the method of PCF / UDR sending the PCC predefined rules to SMF1 and SMF1 locally configuring the PCC predefined rules can be adopted. Among them, the specific process of SMF1 obtaining the information related to the preset private network service rules can be seen in (2) and (3) of the above step 0.
[0130] Specifically, the local configuration of the first session control plane network stores all the information in Table 1. The first session control plane network element obtains the information related to the preset private network service rules from its own local configuration in the following manner:
[0131] Method 1: SMF1 obtains information related to preset private network service rules from all information in local configuration table 1.
[0132] Method 2: SMF1 obtains information related to the preset private network service rules from all information except the "user identifier" in the local configuration table 1. SMF1 obtains the private network DNN subscribed by the user and the network slice identification information to which the private network DNN belongs from the user's UDM / UDR. If the private network DNN and the network slice identification information to which the private network DNN belongs match the "private network DNN (including network slice identification S-NSSAI)" in the information in the table 1 locally configured by SMF1, the preset "private network service diversion strategy in public network service" is executed for the user's UE, and the preset private network service rule information in Table 1 is obtained and used for the UE.
[0133] Corresponding to Figure 4 Step 6-7, step 6 is to clear the public network service: UE uses the first user IP address of the public network session obtained from the network ( Figure 4The IP address in Table 1) uses the service, UPF1 detects the destination address, i.e., the destination URL / URI and the destination IP address, included in the UL uplink user data message sent by the UE in the user plane of the public network session channel. If the destination URL / URI and the destination IP address are not included in the destination URL / URI and the destination IP address in Table 1, it is identified as a public network service, and then normally unblocked to the public network connected to the N6 interface of the public network session; if the destination URL / URI and the destination IP address in the UL uplink data message are included in the destination URL / URI and the destination IP address stored in Table 1, L / URI and destination IP address, it is identified as a private network service, that is, the public network service includes the private network service, then report to SMF1 "the UE uses the private network service", that is, send the private network service access event to SMF1, and the reported content includes the content that SMF1 specified in step 4 that needs to be reported by UPF1. When UPF1 identifies the first UL uplink data message belonging to the private network service in the public network service, it should immediately send the private network service access event to SMF1. After receiving the confirmation message returned by SMF1 for the private network service access event, The subsequent private network service UL uplink data messages of the same private network service identified in the user plane of this public network session channel can no longer repeatedly send private network service access events to SMF1; at the same time, before the establishment of the private network session channel user plane for the UE is completed, UPF1 needs to cache all identified private network service UL uplink data messages of the private network service until the private network session channel user plane of the UE is established. UPF1 forwards (the first received one is forwarded first) all cached private network service UL uplink data messages of the private network service in sequence, and then forwards the private network service in the private network service of the UE. The UL uplink data message of the private network service received after the establishment of the user plane of the public network session channel is completed, that is, the UL uplink data message of all private network services in the user plane of the public network session channel cached by UPF1, that is, when the first session user plane network element recognizes that the public network service transmitted by the user plane of the public network session channel includes the private network service, it sends the access event of the private network service to the first session control plane network element of the public network service, and also includes the UL uplink data message of all private network services in the user plane of the public network session channel cached by the first session user plane network element, and then waits for the next instruction of SMF1. SMF1 receives the access event of the private network service reported by UPF1 and starts the process of establishing a private network PDU session for the UE. Among them, SMF1 and UPF1 still normally clear the user's public network service while establishing the private network session and the user plane of the private network session channel for the user. The public network service is not affected by the establishment of the private network session and the user plane of the private network session channel.It should be understood that when the first session user plane network element identifies that the public network services transmitted by the public network session channel user plane include private network services, it sends an access event of the private network services to the first session control plane network element of the public network services. At the same time, it also includes: the first session user plane network element caches all UL uplink data packets of the private network services in the public network session channel user plane, and the public network session channel user plane forwards the UL uplink data packets and DL downlink data packets of the public network services, and the public network services forwarded by the public network session channel user plane do not trigger the process of establishing a private network session for the user. Among them, the public network services forwarded by the user plane of the public network session channel do not include private network services, that is, when the UL uplink data message of the same private network service is identified in the user plane of the same public network session channel, the first session user plane network element can send only one private network service access event to the first session control plane network element; for the one private network service access event and multiple private network service access events sent by the first session user plane network element for the same private network service in the user plane of the same public network session channel, the first session control plane network element only executes the private network session establishment process once for the same private network service.
[0134] Furthermore, the access event is generated in the following manner:
[0135] The first session user plane network element obtains the private network name related information required for establishing a private network session that matches the destination address information from the preset private network service rule related information, and generates an access event for the private network service based on the private network name related information required for establishing the private network session; or the first session user plane network element generates an access event for the private network service based on the destination address information.
[0136] When establishing a private network session for a private network service for a user, the first target SMF needs to obtain the private network name-related information corresponding to the private network service. The first target SMF establishes the corresponding private network session for the UE based on the obtained private network name-related information, including the user plane channel of the private network session. Among them, the private network name-related information required to establish a private network session in the 5G scenario includes the private network name and the network slice identifier to which the private network name belongs, that is, the private network DNN and the network slice identifier S-NSSAI to which the private network DNN belongs. The preset private network service rule-related information includes the preset destination address information of the private network service (the "destination URL / URI and destination IP address" in Table 1) and the private network name-related information of the private network service (the "private network DNN (including network slice identifier S-NSSAI)" in Table 1), and there is a corresponding relationship between the two. As shown in Table 1, a group of URLs / URIs and / or a group of IPv4 addresses and / or a group of IPv6 addresses correspond to a private network DNN and the network slice identified by S-NSSAI to which the private network DNN belongs; that is, the private network name-related information of the private network service can be located through the destination address information of the private network service. When there are multiple private network services in the public network service of the same user, the information related to the preset private network service rules also includes a private network service number to distinguish the private network services, as shown in Table 1, where the "serial number" identifies different private network services of the same user, and the destination address information and private network name related information of different private network services of the same user are different, that is, different "serial numbers" in Table 1 correspond to different "destination URL / URI and destination IP address" and "private network DNN (including network slice identifier S-NSSAI)". The information related to the preset private network service rules uses the user identifier as the first index, as shown in Table 1, that is, different users can configure different information related to the preset private network service rules, and the destination address information of the private network services of different users is the same, which can correspond to different private network name related information.
[0137] According to the information related to the preset private network service rules, the private network name information of the private network service is located through the destination address information of the private network service. The first session control plane network element (SMF1) establishes a corresponding private network session for the UE based on the private network name information, and controls the first session user plane network element (UPF1) to establish a user plane channel for the private network session. According to the first session control plane network element (SMF1), the private network service access event is obtained from the first session user plane network element (UPF1), and a corresponding private network session is established for the UE based on the private network name information. It supports the establishment of multiple corresponding private network service sessions for multiple different private network services of the same user in the user plane of the same public network session channel. For example: the private network name information of private network service A is the enterprise 1 private network DNN and belongs to S-NSSAI1; the private network name information of private network service B is the enterprise 2 private network DNN and belongs to S-NSSAI2; the private network name information of private network service C is the enterprise 3 private network DNN and belongs to S-NSSAI2, and so on.
[0138] It should be understood that in one case, since the information related to the preset private network service rules includes the PCC policy identifier, the public network name information, the preset destination address information of the private network service, the private network name information required to establish a private network session, and the user identification information, the corresponding Figure 4In step 4, the first target SMF sends the preset private network service rule related information to the first target UPF in advance, and the first target UPF matches the preset destination address information of the private network service that is the same as the destination address information from the preset private network service rule related information according to the destination address information in the UL uplink data message sent by the user terminal, and then matches the private network name related information according to the matched preset destination address information, and obtains the private network name related information required for establishing a private network session that matches the destination address information, and then generates an access event for the private network service according to the matched private network name related information required for establishing a private network session, that is, the access event of the private network service includes the private network name related information required for establishing a private network session. When the first target SMF receives the access event of the private network service sent by the first target UPF, it can obtain the private network name related information required for establishing a private network session from the access event. In another case, the first target UPF generates an access event for the private network service based on the destination address information in the UL uplink data message sent by the user terminal, that is, the access event includes the destination address information in the UL uplink data message sent by the user terminal. The first target SMF receives the access event for the private network service sent by the first target UPF and can obtain the destination address information in the UL uplink data message sent by the user terminal from the access event. The first target SMF can deduce from the preset private network service rule related information based on the matching rules of the destination address information, the preset destination address information and the private network name related information: the private network name related information required to establish a private network session matched by the destination address information.
[0139] Step S220: The first session control plane network element initiates the process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute the process of establishing the user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user.
[0140] In this embodiment, after SMF1 receives the access event of the private network service reported by UPF1, it starts the process of establishing a private network session for the user to establish a private network session, and controls UPF1 to execute the process of establishing the user plane of the private network session channel for the user to establish the user plane of the private network session channel.
[0141] Further, such as Figure 5 As shown, step S220 includes the following steps:
[0142] Step S2211: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the destination address information with the preset private network service rule related information to obtain the private network name related information required for establishing the private network session;
[0143] Step S2212: When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element does not also serve as the second session user plane network element, the first session control plane network element determines the second user IP address and the second session user plane network element, and sends the second user IP address to the first session user plane network element; wherein the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information;
[0144] Step S2213: The first session control plane network element controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information required to establish the private network session.
[0145] It should be understood that after SMF1 receives the access event of the private network service sent by UPF1, if the access event includes the private network name-related information required to establish a private network session, the private network name-related information required to establish the private network session can be obtained based on the access event; if the access event includes destination address information, the destination address information can be obtained, and then, based on the matching rules of the destination address information, the preset destination address information, and the private network name-related information, it can be deduced from the preset private network service rule-related information: the private network name-related information required to establish the private network session that matches the destination address information. The following explanation is given by taking the private network name as the private network DNN and the network slice identifier S-NSSAI to which the private network name belongs as the private network S-NSSAI as an example.
[0146] In scenarios where the first target SMF also serves as the second target SMF, and the first target UPF does not also serve as the second target UPF, it should be understood that, based on the actual network deployment and service unblocking plan, SMF1 is capable of unblocking both public network services and private network DNN + private network S-NSSAI services, while UPF1 is only capable of unblocking public network services and not private network DNN + private network S-NSSAI services. In other words, SMF1 can serve as SMF2, but UPF1 cannot serve as UPF2. Specifically, after SMF1 obtains the private network DNN and private network S-NSSAI corresponding to the private network services, and determines that it has the ability to unblock the private network DNN and private network S-NSSAI, it determines that it will also serve as SMF2. If it determines that it does not have the ability to unblock the private network DNN and / or private network S-NSSAI, it determines that it will not also serve as SMF2.
[0147] If SMF1 determines that it can act as SMF2, it will act as SMF2, that is, SMF1 and SMF2 are the same network element, which can be called SMF1 / SMF2, and execute the process of SMF2 establishing a private network session for the UE (DNN is the private network DNN, S-NSSAI is the private network S-NSSAI), including obtaining the user's private network DNN and private network S-NSSAI session management subscription data from the user's UDM / UDR, selecting UPF, performing "secondary authentication / authorization" as needed, and allocating a second user IP address to the UE, executing the PCC policy of the private network DNN, and controlling the selected UPF to establish a private network session channel user plane for the UE. That is, there is no need to execute Figure 4 Step 8-2, step 8-3, and step 11 in the process; step 9-1, step 9-2, step 9-3, step 10, step 12, and step 13 need to be executed. Among them: (1) When selecting UPF, SMF1 / SMF2 determines whether UPF1 has the ability to clear the private network DNN and the private network S-NSSAI. If not, UPF1 is determined as the I-UPF of the private network DNN, and the UPF with the ability to clear the private network DNN and the private network S-NSSAI is selected as UPF2; (2) SMF1 / SMF2 obtains the second user IP address allocated by the private network DNN through the "secondary authentication / authorization" process, or SMF1 / SMF2 allocates the second user IP address for the private network DNN to the UE ( Figure 4 (2) and sends it to UPF1 in step 12; for the private network, the source IP address in the UL uplink data message sent by the UE for the private network service received by it should be the second user IP address; (3) in step 13, SMF1 / SMF2 controls UPF2 and UPF1 to establish a user plane channel of the private network DNN for the UE, including the N9 interface between UPF1 and UPF2, and the N6 interface between UPF2 and the private network. Through the above steps, the network side completes the establishment of the private network session channel user plane of the private network DNN+private network S-NSSAI for the UE. When there are multiple private network services, the corresponding multiple private network session channel user planes can be established for the UE through the private network DNN and private network S-NSSAI.
[0148] Further, such as Figure 6 As shown, step S220 further includes the following steps:
[0149] Step S2221: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the destination address information with the preset private network service rule related information to obtain the private network name related information required for establishing the private network session.
[0150] Step S2222: When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element also serves as the second session user plane network element, the first session control plane network element determines the second user IP address and sends the second user IP address to the first session user plane network element, wherein the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information;
[0151] Step S2223: The first session control plane network element controls the first session user plane network element to establish the private network session channel user plane corresponding to the private network name related information required for establishing the private network session.
[0152] It should be understood that after SMF1 receives the access event of the private network service sent by UPF1, if the access event includes the private network name-related information required to establish a private network session, the private network name-related information required to establish the private network session can be obtained based on the access event; if the access event includes destination address information, the destination address information can be obtained, and then, based on the matching rules of the destination address information, the preset destination address information, and the private network name-related information, it can be deduced from the preset private network service rule-related information: the private network name-related information required to establish the private network session that matches the destination address information. The following explanation is given by taking the private network name as the private network DNN and the network slice identifier S-NSSAI to which the private network name belongs as the private network S-NSSAI as an example.
[0153] For the scenarios where the first target SMF also serves as the second target SMF and the first target UPF also serves as the second target UPF, it should be understood that based on the actual network deployment situation and the service unblocking plan, SMF1 has the ability to unblock public network services and private network DNN+private network S-NSSAI services, and UPF1 has the ability to unblock public network services and private network DNN+private network S-NSSAI services, that is: SMF1 can serve as SMF2, and UPF1 can serve as UPF2. Specifically, if SMF1 determines that it can act as SMF2, it will act as SMF2, that is, SMF1 and SMF2 are the same network element, and execute the process of SMF2 establishing a private network session for the UE (DNN is the private network DNN, S-NSSAI is the private network S-NSSAI), including obtaining the user's private network DNN and private network S-NSSAI session management subscription data from the user's UDM / UDR, selecting UPF, performing "secondary authentication / authorization" as needed, and allocating a second user IP address to the UE, executing the PCC policy of the private network DNN, and controlling the selected UPF to establish a private network session channel user plane for the UE. That is, there is no need to execute Figure 4Step 8-2, step 8-3, and step 11 in the process; step 9-1, step 9-2, step 9-3, step 10, step 12, and step 13 need to be executed. Among them: (1) When selecting UPF, SMF1 / SMF2 determines whether UPF1 has the ability to clear the private network DNN and the private network S-NSSAI. If it has, UPF1 is determined as the UPF2 of the private network DNN, that is, UPF1 and UPF2 are the same network element, which can be called UPF1 / UPF2; (2) SMF1 / SMF2 obtains the second user IP address allocated by the private network DNN through the "secondary authentication / authorization" process, or SMF1 / SMF2 allocates the second user IP address for the private network DNN to the UE ( Figure 4 (2) and sends it to UPF1 / UPF2 in step 12; for the private network, the source IP address in the UL uplink data message sent by the UE for the private network service should be the second user IP address; (3) in step 13, SMF1 / SMF2 controls UPF1 / UPF2 to establish a user plane channel of the private network DNN for the UE, including the N6 interface between UPF1 / UPF2 and the private network. Through the above steps, the network side completes the establishment of the private network session channel user plane of the private network DNN+private network S-NSSAI for the UE. When there are multiple private network services, multiple corresponding private network session channel user planes can be established for the UE through the private network DNN and private network S-NSSAI.
[0154] Further, such as Figure 7 As shown, step S220 further includes the following steps:
[0155] Step S2231: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the destination address information with the preset private network service rule related information to obtain the private network name related information required for establishing the private network session.
[0156] Step S2232: When the first session control plane network element determines that it does not serve as the second session control plane network element and the first session user plane network element does not serve as the second session user plane network element, the first session control plane network element determines the second session control plane network element and the second session user plane network element, and sends a private network session establishment request to the second session control plane network element; wherein the first session control plane network element determines the second session control plane network element using the same or similar method as the session establishment initiating network element to determine the session control plane network element, that is, in a 5G network, the first session control plane network element determines the second session control plane network element through NRF service discovery;
[0157] Step S2233: The second session control plane network element returns a private network session establishment response to the first session control plane network element, where the private network session establishment response includes at least the second user IP address and interface address information of a relevant interface of the second session user plane network element, wherein the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information;
[0158] Step S2234: When the first session control plane network element receives the private network session establishment response, it sends the second user IP address to the first session user plane network element, and controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session.
[0159] It should be understood that after SMF1 receives the access event of the private network service sent by UPF1, if the access event includes the private network name-related information required to establish a private network session, the private network name-related information required to establish the private network session can be obtained based on the access event; if the access event includes destination address information, the destination address information can be obtained, and then, based on the matching rules of the destination address information, the preset destination address information, and the private network name-related information, it can be deduced from the preset private network service rule-related information: the private network name-related information required to establish the private network session that matches the destination address information. The following explanation is given by taking the private network name as the private network DNN and the network slice identifier S-NSSAI to which the private network name belongs as the private network S-NSSAI as an example.
[0160] A specific method for determining the second session user plane network element (UPF2) in step S2232 is: when the first session control plane network element (SMF1) determines that it does not serve as the second session control plane network element (SMF2), the first session control plane network element (SMF1) determines the second session control plane network element (SMF2) through NRF service discovery, that is, the first session control plane network element (SMF1) performs SMF service discovery on the network resource database network element (NRF) to which it belongs, and selects the second session control plane network element (SMF2) according to the service discovery result; then the first session The control plane network element (SMF1) determines itself as the intermediate session control plane network element (I-SMF) of the private network session, determines the first session user plane network element (UPF1) as the intermediate session user plane network element (I-UPF) of the private network session, and instructs the first session user plane network element (UPF1) to allocate and report the resources of the intermediate session user plane network element (I-UPF) for the private network service; finally, it sends a private network session establishment request to the second session control plane network element (SMF2), and the second session control plane network element (SMF2) determines the second session user plane network element (UPF2).
[0161] For the scenario where the first target SMF does not serve as the second target SMF and the first target UPF does not serve as the second target UPF, it should be understood that, based on the actual network deployment and service unblocking plan, SMF1 only has the ability to unblock public network services and does not have the ability to unblock private network DNN + private network S-NSSAI services. Since UPF2 should be the UPF controlled by SMF2, UPF1 does not have the ability to unblock private network DNN + private network S-NSSAI services, that is, SMF1 cannot serve as SMF2, and UPF1 cannot serve as UPF2. Specifically, if SMF1 determines that it cannot serve as SMF2, it executes the SMF service discovery process and sends a process for establishing a private network session for the UE (DNN is the private network DNN, S-NSSAI is the private network S-NSSAI) to the selected SMF2. After receiving the private network session (DNN is the private network DNN, S-NSSAI is the private network S-NSSAI) establishment response message returned by SMF2, it controls UPF1 to establish the private network session channel user plane for the UE. That is, the business process from step 8 to step 13 needs to be executed. Among them: SMF1 receives the second user IP address returned by SMF2 (SMF2 obtains the second user IP address allocated by the private network DNN through the "secondary authentication / authorization" process or SMF2 allocates the second user IP address for the private network DNN to the UE ( Figure 4 After receiving the IP address 2) in the private network, it is sent to UPF1 in step 12; for the private network, the source IP address in the UL uplink data message sent by the UE for the private network service should be the second user IP address. Through the above steps, the network side has established a private network session channel user plane of the private network DNN + private network S-NSSAI for the UE. When there are multiple private network services, multiple corresponding private network session channel user planes can be established for the UE through the private network DNN and private network S-NSSAI.
[0162] Corresponding to Figure 4 The business process from step 8 to step 13 is as follows:
[0163] (1) In step 8-1, SMF1 performs SMF service discovery on NRF and selects the second target SMF for establishing a private network DNN for the UE based on the service discovery result; in the scenario where the user is roaming, the second target SMF of the user private network DNN is the user's home SMF, i.e. Figure 4 SMF2 in the user public network DNN will use itself as the I-SMF of the user private network DNN, and will select UPF1 as the I-UPF of the user private network DNN.
[0164] (2) In step 8-2, SMF1 acts as the I-SMF of the user private network DNN and instructs the I-UPF of the user private network DNN ( Figure 4UPF1) allocates and reports the N9 interface resources of the user private network DNN.
[0165] (3) In step 8-3, SMF1 sends a private network session establishment request to SMF2 selected by the user private network DNN.
[0166] Step 9-1 to Step 11: After the SMF2 of the user's private network service performs UDM service discovery on the NRF, it obtains and subscribes to the user's SM (session management) contract data from the user's UDM / UDR, which includes the network slice identifier (S-NSSAI) and DNN allowed to be used by the user. SMF2 establishes a private network session for the UE, including: "secondary authentication / authorization" performed on demand between SMF2 and the private network, after performing PCF service discovery on the NRF, it obtains the user's subscribed private network service preset PCC policy from the user's PCF / UDR, selects UPF2, and sends the private network service preset PCC policy to UPF2, instructs the allocation of session resources for the private network session, and allocates a second user IP address for the UE ( Figure 4 The IP address 2 in the "Secondary Authentication / Authorization" process can also be allocated by the private network IP address 2), etc., and sent to the I-SMF ( Figure 4 SMF1) in returns relevant information and completes related information interaction. The above steps comply with the 3GPP standard.
[0167] Among them, in the "Secondary Authentication / Authorization" of step 9-2, the user authentication information includes the authentication password and username. If the authentication password and username are the same and both are the user MSISDN or IMSI in the MSISDN or IMSI, then the first target SMF of the public network service / I-SMF of the private network service ( Figure 4 The SMF1 in the private network service should be completed on behalf of the UE, and the authentication information does not need to be forwarded to the UE; if the UE needs to provide a user name and password, the first target SMF of the public network service / I-SMF of the private network service (ie SMF1) needs to transparently transmit the user authentication information between the UE and the private network. At the same time, in the private network service, the second target SMF ( Figure 4 SMF2 in the user) is the second user IP address assigned to the user ( Figure 4 In the case of IP address 2), it is necessary to ensure that the second target SMF of the private network service is the second user IP address allocated to the user ( Figure 4 The IP address in 2) should not be repeated with all IP addresses of the private network services that the UE can access, that is, the second user IP address pool configured by the second target SMF of the private network service for the enterprise private network service should not contain any IP address in the "Destination URL / URI and Destination IP Address" field in Table 1, that is, the second user IP address is not the same as the preset destination address information in the preset PCC policy.
[0168] Step 12: The first target SMF of the public network service / I-SMF of the private network service (ie SMF1) and the first target UPF of the public network service / I-UPF of the private network service ( Figure 4 The UPF1 in the private network completes information interaction through the N4 interface, including: SMF1 sends the preset PCC strategy to UPF1, the second target UPF ( Figure 4 N9 interface information of UPF2) and the second user IP address for the user private network DNN ( Figure 4 The first target SMF of the public network service / the I-SMF of the private network service completes the relevant information exchange with the target SMF2 of the user's private network service to complete the establishment of the private network session.
[0169] Step 13: The first target UPF of the public network service / I-UPF of the private network service and the second target UPF of the private network service ( Figure 4 The private network session channel user plane of the private network session is established between the first target UPF and the UPF2) in the private network session, and the private network service of the user is unblocked through the private network session channel user plane, that is, the UL uplink data message of the private network service cached by the first target UPF and the UL uplink data message currently being transmitted (the UL uplink data message of the private network service received by the first target UPF after the private network session channel user plane is established) are transmitted by the private network session channel user plane.
[0170] Further, while executing step S220, for the scenario where the first target SMF also serves as the second target SMF and the first target UPF does not also serve as the second target UPF, or the scenario where the first target SMF also serves as the second target SMF and the first target UPF also serves as the second target UPF, or the scenario where the first target SMF does not also serve as the second target SMF and the first target UPF does not also serve as the second target UPF, if the private network needs to start a secondary authentication / authorization authentication process, the secondary authentication / authorization authentication process includes:
[0171] When the first session control plane network element determines that the private network needs to start secondary authentication / authorization and it has stored the user authentication information required for the secondary authentication of the user terminal, it can act as an agent for the user terminal to perform the secondary authentication / authorization process according to the local configuration or the preset private network service rule related information, and control the first session user plane network element to perform the relevant authorization of the private network to the user terminal. It is worth noting that the secondary authentication / authorization process corresponds to Figure 4 For details, please refer to the specific content of step 9-2 above.
[0172] If SMF1 determines that the private network requires secondary authentication / authorization, and it stores the user authentication information required for secondary authentication of the UE, SMF1 performs secondary authentication on behalf of the UE. This can be understood as SMF1 acting on behalf of the UE to perform the secondary authentication / authorization process based on local configuration or preset PCC policies, and controlling UPF1 to perform the relevant authorization of the private network for the UE. A specific implementation of SMF1 acting on behalf of the UE to perform the secondary authentication / authorization process based on local configuration or preset PCC policies is as follows: SMF1 is locally configured to enable secondary authentication on behalf of the UE for specific private network name-related information (private network name and S-NSSAI to which the private network name belongs), and the authentication parameter is the user identity MSISDN or IMSI. Another implementation method is: add 1 parameter information in Table 1 as "proxy user performs secondary authentication", and the parameter value is: "No", "Yes, and the authentication parameter is the user identifier MSISDN", "Yes, and the authentication parameter is the user identifier IMSI", 3 types. If the value is "No", SMF1 does not perform secondary authentication on the proxy user. If the value is "Yes, and the authentication parameter is the user identifier MSISDN", SMF1 performs secondary authentication on the proxy user, and the authentication parameter is the user identifier MSISDN. If the value is "Yes, and the authentication parameter is the user identifier IMSI", SMF1 performs secondary authentication on the proxy user, and the authentication parameter is the user identifier IMSI.
[0173] In the scenario where the first target SMF also serves as the second target SMF and the first target UPF does not also serve as the second target UPF, or the first target SMF also serves as the second target SMF and the first target UPF also serves as the second target UPF, or the first target SMF does not also serve as the second target SMF and the first target UPF does not also serve as the second target UPF, there is no need to send the user authentication information to the UE. The secondary authentication or authorization process is completed by SMF1 instead of the UE, and the user does not need to manually enter the user authentication information on the UE, thereby realizing the user's unconscious perception of the process of using private network services through the UE, thereby improving the user's service access experience.
[0174] Step S230: The first session user plane network element replaces the first user IP address in the UL uplink data packets of all the private network services transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets to the private network through the private network session channel user plane.
[0175] In this embodiment, after the private network session channel user plane is established, the UPF1 of the public network service has only one public network session channel user plane for the UE side, including the N9 interface (in the case of the existence of I-UPF ( Figure 4In the case of I-UPF1) or N3 interface (in the case of no I-UPF (in Figure 4 There is no I-UPF1); on the network side, there is a public network session channel user plane (only N6 interface exists) and a private network session channel user plane (when UPF1 does not serve as UPF2, there is N9 interface, when UPF1 serves as UPF2, there is N6 interface).
[0176] UPF1 replaces the first user IP address in the UL uplink data message of all private network services transmitted by the user plane of the public network session channel with the second user IP address. Furthermore, UPF1 transmits the replaced UL uplink data message to the private network through the user plane of the private network session channel, that is, service diversion, to achieve access to the private network. Among them, private networks include campus networks, enterprise private networks, etc., and enterprise private networks include private networks of government departments, private networks of public institutions, private networks of private enterprises, etc. UPF1 replaces the first user IP address in the UL uplink data message with the second user IP address, which is an operation completed on behalf of the UE and does not require the UE to support multiple DNN functions.
[0177] Specifically, step S230 includes: after the private network session channel user plane is established, the first session user plane network element will replace the first user IP address in all UL uplink data messages of the private network service cached before the establishment of the private network session channel user plane with the second user IP address assigned to the user terminal by the network, and will replace the first user IP address in all UL uplink data messages of the private network service received after the establishment of the private network session channel user plane with the second user IP address assigned to the user terminal by the network, and will transmit all the replaced UL uplink data messages of the private network service cached before the establishment of the private network session channel user plane and all the replaced UL uplink data messages of the private network service received after the establishment of the private network session channel user plane to the private network through the private network session channel user plane in sequence.
[0178] It should be understood that after the private network session channel user plane is established, UPF1 replaces the first user IP address in all UL uplink data packets of private network services cached before the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and replaces the first user IP address in all UL uplink data packets of private network services received after the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets of all private network services cached before the private network session channel user plane is established and the replaced UL uplink data packets of all private network services received after the private network session channel user plane is established to the private network in sequence through the private network session channel user plane. The private network session channel user plane transmits UL uplink data packets in accordance with the first-received-first-forwarded rule.
[0179] Furthermore, this embodiment supports the diversion and aggregation of multiple private network services within the public network service of the same user. Considering that a user may use multiple private network services through the same UE, based on the private network name information related to the private network service used by the user in the same public network service session channel user plane on the same UE, multiple corresponding private network session channel user planes are established for the UE, that is, the first session user plane network element transmits the replaced UL uplink data message to the private network through the private network session channel user plane, including:
[0180] The first session user plane network element executes a service diversion rule to determine a private network session channel identifier according to the UL uplink data message, and transmits the replaced UL uplink data message to the private network through the private network session channel user plane corresponding to the private network session channel identifier.
[0181] It should be understood that when there are one or more private network services, after the private network session channel user plane is established, each private network service corresponds to a private network session channel user plane, and each private network session channel user plane has a corresponding private network session channel identifier. UPF1 executes the service diversion rule and determines the private network session channel identifier based on the target UL uplink data corresponding to different private network services. The corresponding private network session channel user plane can be matched through the determined private network session channel identifier. UPF1 replaces the first user IP address in each UL uplink data message with the second user IP address, and then transmits each replaced UL uplink data message to the private network through the private network session channel user plane corresponding to the private network name related information according to the corresponding private network session channel identifier, thereby realizing service diversion. Among them, each private network service corresponds to a respective second user IP address.
[0182] Step S240: The first session user plane network element replaces the second user IP address in the DL downlink data message sent from the private network to the user terminal with the first user IP address, and sends the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
[0183] In this embodiment, after UPF1 transmits the replaced UL uplink data message to the private network via the private network session channel user plane, the private network then sends a DL downlink data message to the UE. UPF1 replaces the second user IP address in the DL downlink data message with the first user IP address. Here, the second user IP address and the first user IP address are both understood as destination IP addresses. That is, the first user IP address included in the replaced DL downlink data message corresponds to the first user IP address included in the UL uplink data message before the replacement. Furthermore, UPF1 sends the replaced DL downlink data message to the UE via the public network session channel user plane and the base station. The user can view the access information they need through the UE.
[0184] Among them, UPF1 forwards the data received from the N6 interface of the public network session channel user plane to the N9 interface of the public network session channel user plane (in the case of the existence of I-UPF ( Figure 4 In the case of I-UPF1) or N3 interface (in the case of no I-UPF (in Figure 4 There is no I-UPF1 in the network)), and then sent to the UE through the gNB; UPF1 forwards the data received from the N9 interface (when UPF1 does not serve as UPF2, the N9 interface exists) or N6 interface (when UPF1 serves as UPF2, the N6 interface exists) of the user plane of the private network session channel to the N9 interface of the user plane of the public network session channel (when I-UPF exists ( Figure 4 In the case of I-UPF1) or N3 interface (in the case of no I-UPF (in Figure 4 There is no I-UPF1 in the packet, and then it is sent to the UE via the gNB. The UE's IP address is the first user IP address of the public network session ( Figure 4 For the IP address used for the user plane of the public network session channel ( Figure 4 IP address 1) for the user plane of the private network session channel ( Figure 4 The IP addresses in 2) can all be IPv4v6, IPv4, and IPv6. One implementation of replacing the first user IP address with the second user IP address and replacing the second user IP address with the first user IP address is as follows: Figure 8 As shown, Figure 8 A schematic diagram of the mapping relationship between the first user's IP address and the second user's IP address.
[0185] Furthermore, considering that the user has multiple private network services through the UE, the private network session channel user planes with the same number as the private network services are established accordingly, and the public network session channel user plane is one. The private network will transmit the DL downlink data messages corresponding to different private network services according to the corresponding private network session channel user planes, and each private network session channel user plane will transmit its own transmitted DL downlink data messages to the public network session channel user plane. For the public network with a public network I-UPF ( Figure 4 In the case where the public network I-UPF 1) and the public network I-UPF does not exist, step S240 includes the following steps:
[0186] The first session user plane network element executes a service aggregation rule to aggregate target DL downlink data transmitted by the private network session channel user plane corresponding to the private network session channel identifier into the public network session channel user plane between the first session user plane network element and the base station;
[0187] Replacing the second user IP address in a DL downlink data message sent by the private network to the user terminal with the first user IP address;
[0188] Sending the replaced DL downlink data message to the user terminal in sequence through the first session user plane network element and the base station of the public network session channel user plane; or,
[0189] The replaced DL downlink data message is sent to the user terminal in sequence through the first session user plane network element, the intermediate session user plane network element and the base station of the public network session channel user plane.
[0190] Specifically, in the case where I-UPF1 does not exist in the public network, when there are multiple private network session channel user planes established, UPF1 executes the service aggregation rule to aggregate the target DL downlink data transmitted by the private network session channel user planes corresponding to each private network session channel identifier into the public network session channel user plane between UPF1 and gNB, and then replaces the second user IP address in the DL downlink data message sent from the private network to the UE with the first user IP address, and then sends the replaced DL downlink data message to the UE via UPF1 and gNB in the public network session channel user plane in sequence.
[0191] In the case where I-UPF1 exists in the public network, when there are multiple private network session channel user planes established, UPF1 executes the service aggregation rules to aggregate the target DL downlink data transmitted by the private network session channel user planes corresponding to each private network session channel identifier into the public network session channel user plane between UPF1 and gNB, and then replaces the second user IP address in the DL downlink data message sent from the private network to the UE with the first user IP address, and then sends the replaced DL downlink data message to the UE via UPF1, I-UPF1 and gNB in the public network session channel user plane in sequence.
[0192] According to the above technical solution, this embodiment realizes that public network services and private network services are carried for user terminals through a single session channel, and the network can separately charge and manage the private network services and public network services of the user terminal. For user terminals that do not support the multi-DNN function, public network services and private network services can be provided to users at the same time. When a user uses a private network service through a user terminal that does not support the multi-DNN function or supports the multi-DNN function, the user does not need to perform tedious configuration on the user terminal. The user can start and use the private network service during the use of the public network service by simply clicking a link on the public network page or entering the destination address. The private network can be accessed without performing additional operations, which improves the user's unconsciousness in using the private network service through the user terminal and the user's service access experience.
[0193] Further, based on the above embodiment, step S220 also includes: when the preset conditions are met, the first session control plane network element sends a notification message to the corresponding session establishment initiating network element according to the previously obtained session establishment initiating network element identifier to notify the session establishment initiating network element to count the number of user planes of the private network session channel.
[0194] It should be understood that in the 5G scenario, there are multiple network elements that initiate session establishment, and SMF1 can enable the function of sending notification messages to AMF as needed. The preset conditions are set according to actual needs. For example, the preset condition is that the user plane of the private network session channel is established. When SMF1 turns on this function, SMF1 should support sending notification messages according to AMF, and send notification messages to all or part of the AMFs of the same operator, or send notification messages to the AMFs of some other operators, or not send notification messages to the AMFs of some other operators; wherein, SMF1 can obtain the AMF identifier before establishing the user plane of the public network session channel. When the preset conditions are met, SMF1 sends a notification message to AMF based on the AMF identifier obtained previously, notifying the AMF to count the number of user planes of the private network session channel. For example, if the AMF is Figure 4AMF1 in. SMF1 sends a notification message to AMF based on the previously obtained AMF identifier to notify AMF that "the network has established an additional private network session for the UE", that is, in addition to the public network session, it also includes a private network session. Figure 4 In the process, SMF1 sends a message to AMF1 through I-SMF1 (in the case of I-SMF) or directly (in the case of I-SMF), so as to ensure the consistency of the number of statistical sessions on AMF1 and SMF1. If this step exists, AMF only includes this "private network session established by the network for UE" in the relevant statistical indicators, and does not use it for the sessions (public network sessions and private network sessions) that need to be established for users when users switch / roam across AMFs or cross-SMFs. That is, when the UE switches / roams across AMFs or cross-SMFs, AMF only performs the switching / redirection of the public network session, and does not need to perform the switching / redirection of the private network session.
[0195] Furthermore, based on the above embodiment, the service access processing method further includes:
[0196] The first session control plane network element and the first session user plane network element perform segmented management on the public network session channel user plane and the private network session channel user plane, and perform session management, traffic statistics and billing on the public network session corresponding to the public network service and the private network session corresponding to the private network service, respectively.
[0197] It should be understood that, in the case where SMF1 does not serve as SMF2 and UPF1 does not serve as UPF2, or in the case where SMF1 serves as SMF2 and UPF1 does not serve as UPF2, the first target SMF of the public network service / I-SMF of the private network service (i.e., SMF1) and the first target UPF of the public network service / I-UPF of the private network service (i.e., UPF1) can cooperate to achieve separate traffic statistics and billing records for the public network session and the private network session, and perform separate management and control; Figure 4 As shown: the user plane of the public network session is: UE-wireless gNB-(I-UPF1, if exists)-UPF1-public network; the user plane of the private network session is: UE-wireless gNB-(I-UPF1, if exists)-UPF1 (for UL uplink data messages, the first user IP address is replaced from user IP address 1 to user IP address 2; for DL downlink data messages, the second user IP address is replaced from user IP address 2 to user IP address 1)-UPF2-private network; traffic statistics and billing, and session control are performed separately for the user planes of the above two session channels.
[0198] In the case where SMF1 also serves as SMF2 and UPF1 also serves as UPF2, the first target SMF for public network services / target SMF for private network services (i.e. SMF1) and the first target UPF for public network services / target UPF for private network services (i.e. UPF1) can cooperate to achieve traffic statistics and billing records for public network sessions and private network sessions respectively, and perform management and control respectively; Figure 4 As shown: the user plane of the public network session is: UE—wireless gNB—(I-UPF1, if exists)—UPF1—public network; the user plane of the private network session is: UE—wireless gNB—(I-UPF1, if exists)—UPF1 / UPF2 (for UL uplink data packets, the first user IP address is replaced from user IP address 1 to user IP address 2; for DL downlink data packets, the second user IP address is replaced from user IP address 2 to user IP address 1)—private network; traffic statistics and billing, and session control are performed separately for the user planes of the above two session channels.
[0199] Furthermore, based on the above embodiment, the service access processing method further includes:
[0200] At least two QoS Flows are used to associate with the user plane of the public network session channel and the user plane of the private network session channel respectively, so as to perform end-to-end session control, traffic statistics and billing for the public network session corresponding to the public network service and the private network session corresponding to the private network service respectively.
[0201] It should be understood that, if supported by the UE, two QoS Flows can be used for the "UE-wireless gNB-(I-UPF1, if present)-UPF1 segment", one QoS Flow is associated with the "UPF1-public network" segment of the user plane of the public network session channel, and the other QoS Flow is associated with the "UPF1-UPF2-private network or UPF1 / UPF2-private network" segment of the user plane of the private network session channel, so that the wireless network can perform QoS control, traffic statistics and billing for the UE's public network services and private network services respectively.
[0202] For further reference, Figure 4 , Figure 4 This includes scenarios where the user is roaming and the network has inserted an I-SMF and an I-UPF at the roaming location.
[0203] For scenarios where users are roaming and the network does not insert I-SMF and I-UPF at the roaming location, you can also refer to Figure 4 , the difference is that there is no Figure 4 In I-SMF1 and I-UPF1, AMF and SMF1 communicate directly with each other, and wireless gNB and UPF1 communicate directly with each other.
[0204] For scenarios where the user is not roaming but the network has inserted I-SMF and I-UPF, and the SMF for the public network session provided to the user can select the UPF for private network DNN access, you can also refer to Figure 4 , the difference is Figure 4 SMF1 and SMF2 are the same SMF.
[0205] For scenarios where the user is not roaming but the network has inserted I-SMF and I-UPF, and the UPF for the public network session provided to the user is the UPF for private network DNN access, you can also refer to Figure 4 , the difference is Figure 4 SMF1 and SMF2 are the same SMF, and UPF1 and UPF2 are the same UPF.
[0206] For scenarios where the user is not roaming and the network is not inserted into the I-SMF and I-UPF, and the SMF for the public network session provided to the user can select the UPF for private network DNN access, you can also refer to Figure 4 , the difference is that there is no Figure 4 In I-SMF1 and I-UPF1, AMF and SMF1 are directly interconnected, wireless gNB and UPF1 are directly interconnected, and SMF1 and SMF2 are the same SMF.
[0207] For scenarios where the user is not roaming and the network is not inserted into the I-SMF and I-UPF, and the UPF for the public network session provided to the user is the UPF for private network DNN access, you can also refer to Figure 4 , the difference is that there is no Figure 4 In I-SMF1 and I-UPF1, AMF and SMF1 are directly interconnected, wireless gNB and UPF1 are directly interconnected, SMF1 and SMF2 are the same SMF, and UPF1 and UPF2 are the same UPF.
[0208] For Figure 4 In the scenario, if the UE subsequently crosses the I-SMF ( Figure 4 If the UE switches to the I-SMF1 in the public network or roams, the AMF selects a new I-SMF for the UE, and the first target SMF for the public network service / I-SMF for the private network DNN service ( Figure 4 The SMF1) in the Figure 4 The I-SMF1 and I-UPF1 in the system are replaced with the corresponding new I-SMF and I-UPF, using SSC mode 1. The user's public network services and private network services are not interrupted and comply with 3GPP standards.
[0209] For Figure 4There is no I-SMF scenario, that is, AMF and SMF1 directly communicate with each other, wireless gNB and UPF1 directly communicate with each other, if the UE then crosses the I-SMF ( Figure 4 If the UE switches to another I-SMF (e.g. I-SMF1 in the example), the AMF selects an I-SMF for the UE (e.g. Figure 4 I-SMF1 in the public network service, and the first target SMF of the public network service / I-SMF of the private network DNN service ( Figure 4 The SMF1) in the Figure 4 There are I-SMF1 and I-UPF1 in it, and SSC mode1 is used. The user's public network services and private network services are not interrupted and comply with 3GPP standards.
[0210] It is worth noting that in the above implementation process, except for the technical implementation scheme disclosed in the present invention, all follow the 3GPP standard and are based on the basic specifications of the 5G network. In the process of establishing sessions (public network sessions and private network sessions) for 5G UEs, the network must be based on S-NSSAI (network slice identifier) and DNN. In all the session establishment processes involved in the present invention, the network selects SMF and UPF for the UE and establishes sessions based on S-NSSAI and DNN. In order to simplify the description, all the content involving DNN in the invention application proposal refers to the DNN corresponding to the corresponding S-NSSAI.
[0211] Regarding the allocation of IP addresses for user UEs on the 5G network, the above are all in accordance with the 3GPP standard in which SMF is responsible for allocating user IP addresses, which is also the most commonly used method; in the 3GPP standard, there is also a method in which UPF is responsible for allocating user IP addresses, namely: in the network allocation user IP address stage, SMF sends an instruction to UPF to allocate user IP addresses, and UPF allocates the user IP address and reports it to SMF. SMF then sends it to the user terminal UE through AMF (or through I-SMF and then through AMF) and then through the wireless base station gNB. The present invention is also applicable to this method, that is: in the user IP address allocation stage, SMF1 sends an instruction to UPF1 to allocate a user IP address, and UPF1 allocates a first user IP address and reports it to SMF1. If SMF1 finds that the first user IP address allocated by UPF1 is the same as the destination IP address in the preset private network service rule related information, it sends an instruction to UPF1 to require UPF1 to reallocate a new first user IP address that is not the same as the destination IP address in the preset private network service rule related information; then the first user IP address is sent to the user terminal UE through AMF (or through I-SMF and then through AMF) and then through gNB; SMF2 sends an instruction to UPF2 to allocate a user IP address, and it must be ensured that the second user IP address allocated by UPF2 is not the same as the IP address of the private network service server; UPF2 allocates the second user IP address and reports it to SMF2. After SMF1 obtains the second user IP address from SMF2, it sends it to UPF1 in step 12.
[0212] In the first embodiment of the present invention, a corresponding 5G network element is provided, which is also applicable to the 5G network element functions in the 4G / 5G converged network element. Even if some of the 4G functions do not support the "private network service diversion strategy in the public network service" function of the present invention, it does not affect the 4G / 5G network element providing users with the "private network service diversion strategy in the public network service" service function in the 5G scenario.
[0213] The present invention is also applicable to 4G networks, including: 5G users use multi-mode user terminals supporting 4G functions (for example: 4G / 5G terminals, 3G / 4G / 5G terminals, 2G / 3G / 4G / 5G terminals, etc.) to access the 4G network, and 4G users use user terminals supporting 4G functions (for example: 4G terminals, 3G / 4G terminals, 2G / 3G / 4G, etc., and multi-mode terminals that support both 4G and 5G terminals, etc.) to access the 4G network, and enjoy the service provided by the network of "immediately establishing a dedicated channel for the user to transmit the corresponding private network service when a private network service is identified in the user's public network service." The second embodiment given below is a scenario in which a mobile communication network provides a 5G user who uses a multi-mode user terminal supporting 4G functions to access a 4G network with the service of "immediately establishing a dedicated channel for transmitting the corresponding private network service for the user when a private network service is identified in the user's public network service." Its basic implementation principle is the same as the above-mentioned scenario in which a 5G network provides a 5G user who uses a user terminal supporting 5G functions to access a 5G network with the service of "immediately establishing a dedicated channel for transmitting the corresponding private network service for the user when a private network service is identified in the user's public network service." It is worth noting that a pure 5G user terminal cannot access a 4G network, and a terminal that can access a 4G network must be a 4G terminal, that is, a 5G user who accesses a 4G network must use a 4G / 5G multi-mode terminal that supports 4G functions.
[0214] The relevant names in the 4G network are explained as follows:
[0215] APN, the full name is Access Point Name, translated as access point name;
[0216] EPC, the full name is Evolved Packet Core, which is translated as evolved packet core network;
[0217] EPS, the full name is Evolved Packet System, which is translated as Evolved Packet System;
[0218] DNS, the full name is Domain Name System, translated as domain name resolution system;
[0219] MME, the full name is Mobility Management Entity, which is translated as mobility management equipment;
[0220] SGW, the full name is Service Gateway, translated as service gateway;
[0221] PGW, the full name is PDN Gateway, translated as packet data gateway;
[0222] PDN, the full name is Packet Data Network, translated as packet data network;
[0223] SAE, the full name is System Architecture Evolution, translated as system architecture evolution;
[0224] SAE-GW, the full name is System Architecture Evolution-Gateway, which is translated as System Architecture Evolution Gateway;
[0225] HLR, the full name is Home Location Register, translated as home location register;
[0226] HSS, the full name is Home Subscriber Server, translated as home subscriber server;
[0227] DRA, the full name is Diameter Relay Agent, translated as Diameter relay agent;
[0228] PCC, the full name of which is Policy and Charging Control, is translated as policy and charging control;
[0229] PCRF, the full name is Policy and Charging Rule Function, which is translated as policy and charging rule function;
[0230] SPR, the full name is Subscription Profile Repository, translated as user contract database;
[0231] IMSI, the full name is International Mobile Subscriber Identification, translated as international mobile user identification code;
[0232] MSISDN, the full name is Mobile Subscriber ISDN Number, which translates to the ISDN number of the mobile user;
[0233] MSISDN, the full name can also be Mobile Subscriber Integrated Services Digital Network Number, which is translated as the integrated services digital network number of the mobile user;
[0234] eNB, the full name is evolved NodeB, translated as evolved NodeB, that is, 4G base station;
[0235] LTE, the full name is Long Term Evolution, translated as long-term evolution;
[0236] SGSN, the full name is Serving GPRS Support Node, translated as GPRS service support node;
[0237] GGSN, the full name is Gateway GPRS Support Node, translated as gateway GPRS support node.
[0238] It should be noted that the preset PCC policy applies not only to 5G networks but also to 4G networks. Table 1 above is referred to as Table 2 in 4G networks. The "Subscriber Identity" in Table 2 includes the user's MSISDN and / or IMSI. The related DNNs are all DNN / APNs, i.e., DNNs in 5G and APNs in 4G. APNs are used when 4G users access 4G networks via 4G-capable terminals, and the Network Slice Identifier (S-NSSAI) is not used when 4G users access 4G networks via 4G-capable terminals. The gNB is the eNB. In 4G access scenarios, the session establishment initiator in the 4G network is the MME, which can also be a converged AMF / MME. The session control plane network element is the SMF / PGW-C; the session user plane network element is the UPF / PGW-U; the intermediate session control plane network element is the I-SMF / SGW-C; the intermediate session user plane network element is the I-UPF / SGW-U; the user data management network element is the converged UDM / UDR / HSS; the policy control network element is the converged PCF / UDR / PCRF / SPR; and the network database network element functions are implemented by the DRA, EPC DNS, and NRF. The DRA is responsible for communication between the MME and HSS, and the EPC DNS is used to select the SGW-C and PGW-C. The NRF is usually responsible for the SMF / PGW-C addressing the PCF / UDR / PCRF / SPR, but the DRA can also be responsible for 4G communication between the SMF / PGW-C and the PCF / UDR / PCRF / SPR. In addition, SGW-C and PGW-C are usually combined into SAEGW-C, that is, SMF / SAEGW-C; SGW-U and PGW-U are usually combined into SAEGW-U, that is, UPF / SAEGW-U.
[0239] like Figure 9 As shown, Figure 9 A schematic diagram showing the single APN / single IP address of a user terminal and the multi-APN traffic distribution and aggregation management on the network side in a 4G network according to the present invention. Figure 9 contrast Figure 4 , about to Figure 4 Replace the network elements in the corresponding way to get Figure 9The network elements in the 5G network are: 5G base station gNB should be replaced by 4G base station eNB, AMF should be replaced by AMF / MME or MME, SMF1 should be replaced by SMF / SAEGW-C1 (with both PGW-C and SGW-C functions), UPF1 should be replaced by UPF / SAEGW-U1 (with both PGW-U and SGW-U functions), I-SMF1 should be replaced by I-SGW-C1 or SGW-C1, I-UPF1 should be replaced by I-UPF / SGW-U1 or SGW-U1, SMF2 should be replaced by SMF / PGW-C2, UPF2 should be replaced by UPF / PGW-U2, NRF should be replaced by NRF and DRA, EPCDNS; UDM / UDR should be replaced by UDM / UDR / HSS, PCF / UDR should be replaced by PCF / UDR / PCRF / SPR.
[0240] For ease of understanding, the 5G network element functions are simply mapped to the 4G network element functions as follows: gNB is eNB, AMF is MME, SMF is PGW-C, UPF is PGW-U, I-SMF is SGW-C, I-UPF is SGW-U, NRF is NRF and EPC DNS, user home UDM / UDR is four-convergence UDM / UDR / HSS / HLR, user home PCF / UDR is two-convergence PCF / UDR / PCRF / SPR. For details, please refer to Figure 9 . In other descriptions, UE is a user terminal that supports 4G functions, such as a 4G / 5G multi-mode mobile phone. Public network APN, for example, Internet APN, for China Mobile it is CMNET APN; private network APN, for example, enterprise private network APN. Public network APN services are called public network services, and private network APN services are called private network services; public network sessions are the EPS bearer (i.e., 4G bearer) of the public network APN, and the user plane of the public network session channel is the user plane of the public network 4G bearer; private network sessions are the 4G bearer of the private network APN, and the user plane of the private network session channel is the user plane of the private network 4G bearer.
[0241] In the scenario where a 5G user accesses a 4G network through a multi-mode terminal UE that supports 4G, such as Figure 3As shown, the service processing method includes the following steps C10-C40. This embodiment belongs to the scenario where a 5G user accesses a 4G network through a multi-mode terminal UE that supports 4G, and is applicable to the scenario where a 4G user accesses a 4G network through a terminal UE that supports 4G. The service processing method is applied to a mobile communication network packet domain device, and the mobile communication network packet domain device includes at least a session establishment initiating network element, a policy control network element, a first session control plane network element, a second session control plane network element, a first session user plane network element, and a second session user plane network element. In some specific scenarios, the first session control plane network element can be used as the second session control plane network element, and the second session user plane network element can be used as the second session user plane network element.
[0242] In a 4G network where a 4G user accesses a 4G terminal UE, the session control plane network elements include PGW-C and SGW-C, and the session user plane network elements include PGW-U and SGW-U. SGW-C is an intermediate session control plane network element, and SGW-U is an intermediate session user plane network element. The first session control plane network element is represented as the first target SMF / PGW-C and must also have the SGW-C function, that is, the function of SAEGW-C; the second session control plane network element is represented as the second target SMF / PGW-C, the first session user plane network element is represented as the first target UPF / PGW-U and must also have the SGW-U function, that is, the function of UPF / SAEGW-U; the second session user plane network element is represented as the second target UPF / PGW-U, and the policy control network element is PCRF / SPR. When a 5G user accesses a 4G network through a multi-mode terminal UE that supports 4G, the network element that initiates session establishment is the MME, the session control plane network elements include the SMF / PGW-C and SGW-C, and the session user plane network elements include the UPF / PGW-U and SGW-U. Among them, SGW-C is the intermediate session control plane network element, and SGW-U is the intermediate session user plane network element; the first session control plane network element is represented as the first target SMF / PGW-C, and must also have the SGW-C function, that is, the function of SMF / SAEGW-C; the second session control plane network element is represented as the second target SMF / PGW-C; the first session user plane network element is represented as the first target UPF / PGW-U, and must also have the SGW-U function, that is, the function of UPF / SAEGW-U; the second session user plane network element is represented as the second target UPF / PGW-U, and the policy control network element is PCF / UDR / PCRF / SPR, that is, in some specific scenarios, the first target SMF / PGW-C can be used as the second target SMF / PGW-C, and the first target UPF / PGW-U can be used as the second target UPF / PGW-U.
[0243] like Figure 9As shown, for the scenario where 5G users access the 4G network through a multi-mode terminal that supports 4G, PGW-C should be understood as SMF / PGW-C, and PGW-U should be understood as UPF / PGW-U. The session establishment initiating network element corresponds to MME1, the first target SMF / PGW-C corresponds to SMF / PGW-C1, the second target SMF / PGW-C corresponds to SMF / PGW-C2, the first target UPF / PGW-U corresponds to UPF / PGW-U1, the second target UPF / PGW-U corresponds to UPF / PGW-U2, the intermediate session control plane network element is SGW-C1, and the intermediate session user plane network element is SGW-U1. Before executing step C10, the network element corresponding to Figure 9 Perform the following steps:
[0244] Step 0: User signing, including:
[0245] (1) Sign up for and activate the public network APN and private network APN for the user in the user's home UDM / UDR / HSS / HLR.
[0246] (2) The PCC policy for signing up for the "private network service diversion strategy in public network service" with the user's PCF / UDR / PCRF / SPR is called the preset PCC policy. The preset PCC policy indicates that when the destination address is detected as one of the destination URL / URI and destination IP address of "private network" in the UL uplink data message of the 4G bearer of the public network APN (hereinafter referred to as the public network session), the "private network APN" is activated for the user. The destination address in the UL uplink data message should be within the range of all private network destination URL / URI and destination IP address included in the PCC policy information. The information / parameters included in the preset PCC policy are shown in Table 2.
[0247] (3) When PCF / UDR / PCRF / SPR issues PCC predefined rules and SMF / PGW-C locally configures PCC predefined policies, the "destination URL / URI and destination IP address" of the private network service in Table 2 can be locally configured in SMF / PGW-C1, and the PCC predefined rules issued by PCF / UDR / PCRF / SPR to SMF / PGW-C1 include the PCC predefined rule name information of "diversion of private network services in public network services" and the related information of the private network name to be established ("private network APN" in Table 2), and the diversion of multiple private network services in the public network services of the same user terminal can be achieved by increasing the number of PCC predefined policies for the user.
[0248] When a user activates a private network service, it is necessary to complete the contract for the private network APN in the user's UDM / UDR / HSS / HLR, and the user will become a private network user at the same time; when it is necessary to provide the private network user with the service of "immediately establishing a dedicated channel for transmitting the corresponding private network service for the user when the private network service is identified in the user's public network service", it is necessary to sign a PCC policy of "diverting private network services from public network services" in the PCF / UDR / PCRF / SPR to which the private network user belongs; in the subsequent process of establishing the 4G bearer of the user's public network APN, the SMF / PGW-C1 responsible for the user's public network APN service obtains the user's PCC policy of "diverting private network services from public network services" from the user's PCF / UDR / PCRF / SPR.
[0249] Table 2 (4G-related PCC information)
[0250]
[0251] In Table 2, 1) if the same user has only one private network APN service, the "sequence number" parameter is not required; 2) the URL / URI and IP address of private network APN1 and private network APN2 cannot be repeated, which needs to be guaranteed when pre-setting the PCC policy.
[0252] As mentioned above, the content in Table 2 is at least the content included in the preset private network service rule information. After the user activates the private network service and activates the service of "immediately establishing a dedicated channel for transmitting the corresponding private network service for the user when the private network service is identified in the user's public network service", the content in Table 2 is generated. It is completed before the user actually uses the private network service. It can be understood as the preset private network service rule information. Whether the PCC method of PCF / UDR / PCRF / SPR sending the full amount of preset private network service rule information to PGW-C1 is adopted, or the PCC method of PCF / UDR / PCRF / SPR sending the full amount of preset private network service rule information to PGW-C1 is adopted, In the manner in which F / UDR / PCRF / SPR issues PCC predefined rules and SMF / PGW-C1 locally configures PCC predefined policies, before the user sends private network service data packets through the public network 4G bearer user plane channel, the contents of the preset private network service rule related information have been obtained by SMF / PGW-C1 (see step 3 below for details); and it can be understood that the PCC policy containing the preset private network service rule related information is the preset private network service rule related information PCC policy, also known as the "private network service diversion in public network service" PCC policy. The preset private network service rule related information includes at least the PCC policy identifier, public network name related information, preset destination address information of the private network service, private network name related information required to establish a private network session, and user identification information. For details, see Table 2.
[0253] In actual application, when a user uses data services, step B10 to step B20 are first executed. Figure 2 As shown:
[0254] Step B10: When the session establishment initiating network element receives the public network service activation request initiated by the user terminal, it selects a first session control plane network element corresponding to the public network service of the user terminal and sends a public network session establishment request to the first session control plane network element;
[0255] Step B20: The first session control plane network element selects a first session user plane network element and controls the first session user plane network element to establish a public network session channel user plane for the public network service and allocate the first user IP address to the user terminal. The first user IP address is different from the preset destination address information for the private network service in the preset private network service rule-related information.
[0256] Corresponding to Figure 9 Steps 1 to 3: When a user uses a public network service or a private network service, the UE initiates a public network APN activation request in the roaming location, also known as a public network service activation request. After MME1 receives the public network service activation request initiated by the UE, MME1 queries the EPC DNS. Based on the query result, if the user switches / roams across the SGW-C POOL, MME1 selects the SGW-C and the first target SMF / PGW-C, corresponding to Figure 9 If the user has not switched / roamed, or switched / roamed within the SGW-C POOL, or activated the public network APN for the first time, and the first target SMF / PGW-C has the function of SGW-C, that is, SAEGW-C, then MME1 selects the first target SMF / PGW-C set by the SGW-C and PGW-C (in Figure 9 In the example, SGW-C1 and PGW-C1 are the same network element, namely SMF / PGW-C1 or SMF / SAEGW-C1), and send the user's public network session establishment request to the first target SMF / PGW-C, namely SMF / PGW-C1. Figure 9 If an SGW-C1 exists, MME1 sends the public network session establishment request to PGW-C1 via I-SGW-C1. If SGW-C1 and SMF / PGW-C1 are the same device (i.e., SMF / SAEGW-C1), MME1 sends the public network session establishment request directly to SMF / PGW-C1 (SMF / SAEGW-C1). In a 4G network, the MME obtains user subscription data from the user's home HSS. The MME then includes 4G bearer-related information (including the APN allowed to the user) in a 4G bearer establishment request message and sends it to PGW-C via SGW-C.
[0257] Steps 3 to 6: The SMF / PGW-C1 of the public network service establishes a public network session for the UE, including the SMF / PGW-C1 performing PCF service discovery to the NRF, obtaining the preset PCC policy of the user's subscription from the user's PCF / UDR / PCRF / SPR according to the service discovery result (SMF / PGW-C1 accesses the user's PCRF / SPR through DRA to obtain the preset PCC policy of the user's subscription), the selected first target UPF / PGW-U ( Figure 9 The UPF / PGW-U1 in the network) sends a preset PCC policy to the selected UPF / PGW-U1, instructs the allocation of session resources for the public network session, and allocates the first user IP address to the UE ( Figure 9 The first user IP address is allocated by SMF / PGW-C1 and sent to the UE through SGW-C and MME. UPF / PGW-U1 obtains the first user IP address of the UE by identifying the source IP address in the UL uplink data message sent by the UE. Figure 9 If there is SGW-C1, SGW-C1 forwards the relevant message, and SGW-C1 instructs SGW-U1 to allocate relevant resources; if SGW-C1 and SMF / PGW-C1 are the same SMF / SAE-GW1, SMF / SAE-GW1 communicates directly with MME1, and SMF / SAEGW-C1 instructs UPF / SAEGW-U1 to allocate SGW related resources. The above steps follow the 3GPP standard. Among them, after the first user IP address is allocated to the UE, it is the IP address of the UE, that is, Figure 9 The IP address 1 in the UL data packet is the source IP address in the UL data packet sent by the UE.
[0258] Furthermore, in the 3GPP standard process of step 4, the SMF / PGW-C1 of the public network service and the UPF / PGW-U1 selected by the SMF / PGW-C1 need to add the execution processing of the PCC policy of the preset "private network service diversion strategy in the public network service", as follows:
[0259] (1) In step 3, through the PCC process, the SMF / PGW-C1 of the public network service obtains the information related to the preset private network service rules in the preset "Private network service diversion strategy in public network service", including the various parameter information shown in Table 2; specifically, the PCF / UDR / PCRF / SPR can be used to publish the full information in 2 to the SMF / PGW-C1, or the PCF / UDR / PCRF / SPR can be used to issue the PCC predefined rules to the SMF / PGW-C1 and the SMF / PGW-C1 can locally configure the PCC predefined rules. Among them, the specific process of SMF / PGW-C1 obtaining the information related to the preset private network service rules can be found in (2) and (3) of step 0 above.
[0260] (2) After obtaining the information related to the preset private network service rules, including the parameter information in Table 2, the SMF / PGW-C1 of the public network service executes a process to ensure that the first user IP address allocated to the UE is different from the private network service destination IP address in the information related to the preset private network service rules. It should be understood that when the SMF / PGW-C1 of the public network service allocates the first user IP address to the UE, it is necessary to verify whether the first user IP address and the destination IP address of the private network APN in the preset PCC policy obtained from the user's home PCF / UDR / PCRF / SPR (the destination IP address in Table 2) are repeated or conflicting. If the addresses are repeated, the first user IP address to be allocated to the user needs to be replaced with a new first user IP address that is not repeated with the destination IP address of the private network APN, so as to avoid the situation where the source IP address and the destination IP address are the same when the UE sends an UL uplink data message. Since the source IP address of the private network service UL uplink data message sent by the UE is the first user IP address, and the destination IP address cannot be the same as the source IP address, it is necessary to ensure that the first user IP address assigned to the UE by the SMF / PGW-C1 cannot be the same as all the destination IP addresses in the preset destination address information in the preset private network service rule related information (i.e., all the IP addresses in the "destination URL / URI and destination IP address" in Table 2). If the SMF / PGW-C1 finds that the first user IP address assigned to the UE is the same as any preset destination address information in the preset private network service rule related information, the SMF / PGW-C1 will reallocate a user IP address to the UE, and the reallocated user IP address will be an IP address that is different from all the destination IP addresses in the preset private network service rule related information, and the IP address information of the UE in the user's home PCF / UDR / PCRF / SPR will be updated through the subsequent PCC process. Among them, the IP address reallocated by the SMF / PGW-C1 is the first user IP address.
[0261] (3) In step 4, the SMF / PGW-C1 of the public network service maps the obtained information related to the preset private network service rules into the Sx interface information and sends it to the UPF / PGW-U1 of the public network service. That is, the SMF / PGW-C1 sends the information related to the preset private network service rules to the UPF / PGW-U1. The information related to the preset private network service rules is shown in Table 2. Among them, the SMF / PGW-C1 does not necessarily need to send all the information in Table 2 to the UPF / PGW-U1, but it should at least include the "public network APN", "destination URL / URI and destination IP address" in Table 2, and information identifying the user. It may also include "private network APN", and the specific information can be determined according to the situation. If the information related to the preset private network service rules sent by the first session control plane network element to the first session user plane network element includes "private network DNN," the subsequent process may correspond to "the first session control plane network element obtains information related to the private network name required for establishing the private network session and included in the access event" in steps C211, C221, and C231. If the information related to the preset private network service rules sent by the first session control plane network element to the first session user plane network element does not include "private network DNN," the subsequent process may correspond to "the first session control plane network element obtains destination address information included in the access event, and matches the information related to the preset private network service rules based on the destination address information to obtain information related to the private network name required for establishing the private network session." The execution of the above service processing does not affect the forwarding of data packets of the UE's public network service.
[0262] Obviously, there is another way to obtain all the information in Table 2. All the information in Table 2 can be achieved through local configuration in UPF / PGW-U1.
[0263] (4) The UPF / PGW-U1 of the public network service selected by the SMF / PGW-C1 of the public network service executes this preset PCC policy while forwarding the user data message (including UL uplink data message and DL downlink data message) of the public network service of the UE. When the user data message (also called UL uplink data message) sent by the UE meets the conditions, that is, the destination URL / URI or destination IP address included in the UL uplink data message is the URL / URI in the "Destination URL / URI" or the IP address in the "Destination IP Address" field in Table 2, it is necessary to report the relevant event to the SMF / PGW-C1. The relevant event can be understood as an access event of the user using the private network service. It can also be understood as when a UL uplink data message including the destination address information of the URL / URI or IP address of the private network service is detected in the public network service of the UE, the access event of the private network service is reported to the SMF / PGW-C1. See step 7 described later for details.
[0264] The SMF / PGW-C1 of the public network service executes the preset PCC policy of "private network service diversion strategy in public network service". When it receives the access event of the private network service reported by UPF / PGW-U1, it activates the 4G bearer of the corresponding private network APN (also called private network session) for the user. That is, when UPF / PGW-U1 reports that it detects a UL uplink data message with the destination address being the URL / URI or IP address of the private network service in the public network service of the UE, it notifies SMF / PGW-C1 to activate the corresponding private network session for the user. For details, see step 8 described later.
[0265] Step C10: Based on the public network service initiated by the user terminal, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, it sends an access event of the private network service to the first session control plane network element of the public network service.
[0266] In this embodiment, after the user inputs the destination address information that he needs to access through the UE, the UE sends a UL uplink data message of the public network service or the private network service. The user plane of the public network session channel responsible for the public network service will transmit the UL uplink data message of the public network service and the private network service sent by the UE. The UPF / PGW-U1 identifies whether the public network service transmitted by the user plane of the public network session channel includes the private network service, and decides whether to report the access event of the private network service to the SMF / PGW-C1. If the UPF / PGW-U1 identifies that the public network service includes the private network service, it means that the user needs to access the private network service, and the access event of the private network service is reported to the SMF / PGW-C1.
[0267] Furthermore, the first session user plane network element identifies whether the public network service transmitted by the user plane of the public network session channel includes a private network service, including: the first session user plane network element obtains the destination address information in the UL uplink data message sent by the user terminal, and when it is identified that the destination address information is the same as the preset destination address information of the private network service, determines that the UL uplink data message is a private network service, that is, the public network service includes the private network service.
[0268] It should be understood that the user plane of the public network session channel transmits all UL uplink data packets corresponding to the user's use of private network services in the form of public network services. The UL uplink data packets include the destination address information entered by the user. If UPF / PGW-U1 identifies that the destination address information corresponding to the private network service included in the UL uplink data packet is the same as the preset destination address information of the private network service, that is, the destination address information is the same as one of the destination URL / URI and destination IP address in the preset private network service rule related information, then it can be determined that the UL uplink data packet is a private network service, that is, the public network service includes the private network service.
[0269] The preset destination address information of the private network service is obtained by at least one of the following methods:
[0270] The preset destination address information of the private network service is obtained by the first session user plane network element from its own local configuration;
[0271] The preset destination address information of the private network service is obtained by the first session user plane network element from the preset private network service rule related information sent to itself by the first session control plane network element.
[0272] It should be understood that in the 4G scenario, all the information in Table 2 may be pre-stored in the local configuration of UPF / PGW-U1, since all the information in Table 2 includes the preset destination address information of the private network service. When UPF / PGW-U1 needs to obtain the preset destination address information of the private network service, UPF / PGW-U1 can obtain the preset destination address information of the private network service from its own local configuration; the preset destination address information of the private network service can also be sent to UPF / PGW-U1 by SMF / PGW-C1, SMF / PGW-C1 sends the relevant information of the preset private network service rules to UPF / PGW-U1, and UPF / PGW-U1 obtains the preset destination address information of the private network service from the relevant information of the preset private network service rules, that is: SMF / PGW-C1 of the public network service maps the obtained relevant information of the preset private network service rules to the Sx interface information and sends it to UPF / PGW-U1 of the public network service, SMF / PGW-C1 sends the relevant information of the preset private network service rules to UPF / PGW-U1, and the relevant information of the preset private network service rules is shown in Table 2. The SMF / PGW-C1 does not necessarily need to send all the information in Table 2 to the UPF / PGW-U1. However, it should at least include the "public network APN," "destination URL / URI and destination IP address," and user identification information in Table 2. It may also include the "private network APN." Of course, it is not ruled out that the UPF / PGW-U1 can obtain the preset destination address information for private network services through other means. It is worth noting that the specific method for obtaining the preset destination address information for private network services is determined based on actual needs.
[0273] How does the first session control plane network element obtain information related to the preset private network service rules? Specifically:
[0274] The information related to the preset private network service rules is obtained by the first session control plane network element through the PCC method and / or its own local configuration, and the information related to the preset private network service rules is sent to the first session user plane network element during the process of establishing the public network session channel user plane for the user terminal.
[0275] It should be understood that in 4G scenarios, the SMF / PGW-C1 can obtain information related to preset private network service rules through the PCC, or from its own local configuration. Of course, it is not ruled out that the SMF / PGW-C1 can obtain information related to preset private network service rules through other means. It is worth noting that the specific method for obtaining information related to preset private network service rules is set according to actual needs. Subsequently, the SMF / PGW-C1 sends information related to the preset private network service rules to the UPF / PGW-U1 during the process of establishing the user plane of the public network session channel for the user terminal. The information related to the preset private network service rules includes at least the PCC policy identifier, information related to the public network name, information related to the preset destination address of the private network service, information related to the private network name required to establish the private network session, user identification information, etc.; the information related to the private network name refers to necessary information such as the private network name required to establish the private network session. The specific content of the information related to the private network name varies in different network scenarios. In 4G scenarios, the information related to the private network name includes at least the private network APN, i.e., the private network name.
[0276] Specifically, the first session control plane network element obtains the preset private network service rule related information through the PCC in at least one of the following ways:
[0277] In the process of establishing a public network session for the user terminal, the policy control network element sends a full amount of preset private network service rule information to the first session control plane network element;
[0278] During the process of establishing a public network session for a user terminal, the policy control network element sends the PCC predefined rules to the first session control plane network element. The first session control plane network element obtains information related to the preset private network service rules from its own locally configured PCC predefined policies based on the PCC predefined rules.
[0279] It should be understood that, in the process of establishing the user plane of the public network session channel for the user terminal, it is the PCF / UDR / PCRF / SPR that sends the full amount of information related to the preset private network service rules to the SMF / PGW-C1. Alternatively, in the process of establishing the user plane of the public network session channel for the user terminal, the PCF / UDR / PCRF / SPR sends the PCC predefined rules to the SMF / PGW-C1, and the SMF / PGW-C1 obtains the information related to the preset private network service rules from its own locally configured PCC predefined policies based on the PCC predefined rules. That is, in step 3, through the PCC process, the SMF / PGW-C1 of the public network service obtains the information related to the preset private network service rules in the preset "Private network service diversion strategy in public network service", including the various parameter information shown in Table 2; specifically, the method of PCF / UDR / PCRF / SPR publishing the full information in 2 to SMF / PGW-C1 can be adopted, or the method of PCF / UDR / PCRF / SPR issuing PCC predefined rules to SMF / PGW-C1 and SMF / PGW-C1 locally configuring PCC predefined rules can be adopted. Among them, the specific process of SMF / PGW-C1 obtaining the information related to the preset private network service rules can be found in (2) and (3) of the above step 0.
[0280] Specifically, the local configuration of the first session control plane network stores all the information in Table 2. The first session control plane network element obtains the information related to the preset private network service rules from its own local configuration in the following manner:
[0281] Method 1: SMF / PGW-C1 obtains information related to preset private network service rules from all information in local configuration table 2.
[0282] Method 2: SMF / PGW-C1 obtains information related to the preset private network service rules from all information except "User Identifier" in the locally configured Table 2. Based on the private network APN subscribed to by the user obtained from the user's home UDM / UDR / HSS / HLR, if the private network APN matches the "Private Network APN" in the information in Table 2 locally configured by SMF / PGW-C1, SMF / PGW-C1 executes the preset "Private Network Service Diversion Strategy in Public Network Service" for the user's UE and obtains and uses the information related to the preset private network service rules in Table 2 for the UE.
[0283] Corresponding to Figure 9 Step 6-7, step 6 is to clear the public network service: UE uses the first user IP address of the public network session obtained from the network ( Figure 9The IP address in 1) uses the service, the UPF / PGW-U1 detects the destination address included in the UL uplink user data message sent by the UE in the user plane of the public network session channel, that is, the destination URL / URI and the destination IP address. If the destination URL / URI and the destination IP address are not included in the destination URL / URI and the destination IP address in Table 2, it is identified as a public network service, and then normally unblocked to the public network connected to the SGi interface of the public network session; if the destination URL / URI and the destination IP address in the UL uplink data message are included in the destination URL / URI and the destination IP address stored in Table 2 , it is identified as a private network service, that is, the public network service includes the private network service, then report "the UE uses the private network service" to SMF / PGW-C1, that is, send the private network service access event to SMF / PGW-C1, and the reported content includes the content that SMF / PGW-C1 specified in step 4 that needs to be reported by UPF / PGW-U1. When UPF / PGW-U1 identifies the first UL uplink data message belonging to the private network service in the public network service, it shall immediately send the private network service access event to SMF / PGW-C1. After receiving the private network service access event received from SMF / PGW-C1, After receiving the confirmation message, for the subsequent private network service UL uplink data messages of the same private network service identified in the user plane of this public network session channel, the private network service access event will no longer be repeatedly sent to SMF / PGW-C1; at the same time, before the establishment of the private network session channel user plane for the UE is completed, UPF / PGW-U1 needs to cache all identified private network service UL uplink data messages of the private network service until the private network session channel user plane of the UE is established. UPF / PGW-U1 forwards (the first received one is forwarded first) all cached private network service UL uplink data messages of the private network service in sequence, and then forwards them to the SMF / PGW-C1. The UL uplink data message of the private network service received after the establishment of the private network session channel user plane of E's private network service is completed, that is, the UL uplink data message of all private network services in the user plane of the public network session channel cached by UPF / PGW-U1, that is, when the first session user plane network element recognizes that the public network service transmitted by the public network session channel user plane includes the private network service, it sends the access event of the private network service to the first session control plane network element of the public network service, and also includes the UL uplink data message of all private network services in the user plane of the public network session channel cached by the first session user plane network element, and then waits for the next instruction of SMF / PGW-C1. SMF / PGW-C1 receives the access event of the private network service reported by UPF / PGW-U1 and starts the process of establishing a private network 4G bearer for the UE. Among them, SMF / PGW-C1 and UPF / PGW-U1 still clear the user's public network service normally while establishing the private network session and the user plane of the private network session channel for the user. The public network service is not affected by the establishment of the private network session and the user plane of the private network session channel.It should be understood that when the first session user plane network element identifies that the public network services transmitted by the public network session channel user plane include private network services, it sends an access event of the private network services to the first session control plane network element of the public network services. At the same time, it also includes: the first session user plane network element caches all UL uplink data packets of the private network services in the public network session channel user plane, and the public network session channel user plane forwards the UL uplink data packets and DL downlink data packets of the public network services, and the public network services forwarded by the public network session channel user plane do not trigger the process of establishing a private network session for the user. Among them, the public network services forwarded by the user plane of the public network session channel do not include private network services, that is, when the UL uplink data message of the same private network service is identified in the user plane of the same public network session channel, the first session user plane network element can send only one private network service access event to the first session control plane network element; for the one private network service access event and multiple private network service access events sent by the first session user plane network element for the same private network service in the user plane of the same public network session channel, the first session control plane network element only executes the private network session establishment process once for the same private network service.
[0284] Furthermore, the access event is generated in the following manner:
[0285] The first session user plane network element obtains the private network name related information required for establishing a private network session that matches the destination address information from the preset private network service rule related information, and generates an access event for the private network service based on the private network name related information required for establishing the private network session; or the first session user plane network element generates an access event for the private network service based on the destination address information.
[0286] When establishing a private network session for a private network service for a user, the first target SMF / PGW-C needs to obtain the private network name-related information corresponding to the private network service, and the first target SMF / PGW-C establishes the corresponding private network session for the UE based on the obtained private network name-related information, including the user plane channel of the private network session. Among them, the private network name-related information required to establish a private network session in a 4G scenario includes the private network name, that is, the private network APN. The preset private network service rule-related information includes the preset destination address information of the private network service (the "destination URL / URI and destination IP address" in Table 2) and the private network name-related information of the private network service (the "private network APN" in Table 2), and there is a corresponding relationship between the two. As shown in Table 2, a group of URL / URIs and / or a group of IPv4 addresses and / or a group of IPv6 addresses correspond to a private network APN; that is, the private network name-related information of the private network service can be located through the destination address information of the private network service. When there are multiple private network services in the public network service of the same user, the information related to the preset private network service rules also includes a private network service number to distinguish the private network services, as shown in Table 2, where the "serial number" identifies different private network services of the same user. The destination address information and private network name related information of different private network services of the same user are different, that is, different "serial numbers" in Table 2 correspond to different "destination URL / URI and destination IP address" and "private network APN". The information related to the preset private network service rules uses the user identifier as the first index, as shown in Table 2, that is, different users can configure different information related to the preset private network service rules. The destination address information of the private network services of different users is the same, and can correspond to different information related to the private network name.
[0287] According to the information related to the preset private network service rules, the private network name information of the private network service is located through the destination address information of the private network service. The first session control plane network element (SMF / PGW-C1) establishes a corresponding private network session for the UE based on the private network name information, and controls the first session user plane network element (UPF / PGW-U1) to establish a user plane channel for the private network session. According to the first session control plane network element (SMF / PGW-C1), the private network service access event is obtained from the first session user plane network element (UPF / PGW-U1), and a corresponding private network session is established for the UE based on the private network name information. It supports the establishment of multiple corresponding private network service sessions for multiple different private network services of the same user in the user plane of the same public network session channel. For example: the private network name information of private network service A is the private network APN of enterprise 1; the private network name information of private network service B is the private network APN of enterprise 2; the private network name information of private network service C is the private network APN of enterprise 3, and so on.
[0288] It should be understood that in one case, since the information related to the preset private network service rules includes the PCC policy identifier, the public network name information, the preset destination address information of the private network service, the private network name information required to establish a private network session, and the user identification information, the corresponding Figure 9 In step 4, the first target SMF / PGW-C pre-sends the preset private network service rules to the first target UPF / PGW-U, and the first target UPF / PGW-U matches the preset destination address information of the private network service that is the same as the destination address information from the preset private network service rule related information according to the destination address information in the UL uplink data message sent by the user terminal, and then matches the private network name related information according to the matched preset destination address information, and obtains the private network name related information required for establishing a private network session that matches the destination address information, and then generates an access event for the private network service according to the matched private network name related information required for establishing a private network session, that is, the access event of the private network service includes the private network name related information required for establishing a private network session. When the first target SMF / PGW-C receives the access event of the private network service sent by the first target UPF / PGW-U, it can obtain the private network name related information required for establishing a private network session from the access event. In another case, the first target UPF / PGW-U generates an access event for the private network service based on the destination address information in the UL uplink data message sent by the user terminal, that is, the access event includes the destination address information in the UL uplink data message sent by the user terminal. The first target SMF / PGW-C receives the access event for the private network service sent by the first target UPF / PGW-U, and can obtain the destination address information in the UL uplink data message sent by the user terminal from the access event. The first target SMF / PGW-C can deduce from the preset private network service rule related information based on the matching rules of the destination address information, the preset destination address information and the private network name related information: the private network name related information required to establish a private network session matched by the destination address information.
[0289] Step C20: The first session control plane network element initiates the process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute the process of establishing the user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user.
[0290] In this embodiment, after SMF / PGW-C1 receives the access event of the private network service reported by UPF / PGW-U1, it starts the process of establishing a private network session for the user to establish a private network session, and controls UPF / PGW-U1 to execute the process of establishing the user plane of the private network session channel for the user to establish the user plane of the private network session channel.
[0291] Further, such as Figure 5As shown, step C20 includes the following steps:
[0292] Step C211: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the destination address information with the preset private network service rule related information to obtain the private network name related information required for establishing the private network session;
[0293] Step C212: When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element does not also serve as the second session user plane network element, the first session control plane network element determines the second user IP address and the second session user plane network element, and sends the second user IP address to the first session user plane network element; wherein the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information;
[0294] Step C213: The first session control plane network element controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information required to establish the private network session.
[0295] It should be understood that after SMF / PGW-C1 receives the access event of the private network service sent by UPF / PGW-U1, if the access event includes the private network name-related information required to establish a private network session, the private network name-related information required to establish the private network session can be obtained based on the access event; if the access event includes destination address information, the destination address information can be obtained, and then, based on the matching rules between the destination address information, the preset destination address information, and the private network name-related information, the preset private network service rule-related information can be deduced: the private network name-related information required to establish the private network session that matches the destination address information. The following explanation is based on the example where the private network name is the private network APN.
[0296] In the scenario where the first target SMF / PGW-C also serves as the second target SMF / PGW-C, and the first target UPF / PGW-U does not also serve as the second target UPF / PGW-U, it should be understood that, based on the actual network deployment and service unblocking plan, SMF / PGW-C1 has the ability to unblock both public network services and private network APN services, while UPF / PGW-U1 only has the ability to unblock public network services and does not have the ability to unblock private network APN services. In other words, SMF / PGW-C1 can serve as SMF / PGW-C2, and UPF / PGW-U1 cannot serve as UPF / PGW-U2. Specifically, after SMF / PGW-C1 obtains the private network APN corresponding to the private network service and determines that it has the ability to unblock the private network APN, it determines that it will also serve as SMF / PGW-C2; if it determines that it does not have the ability to unblock the private network APN, it determines that it will not also serve as SMF / PGW-C2.
[0297] If SMF / PGW-C1 determines that it can act as SMF / PGW-C2, it will act as SMF / PGW-C2, that is, SMF / PGW-C1 and SMF / PGW-C2 are the same network element, which can be called SMF / PGW-C1 or SMF / PGW-C2, and execute the process of SMF / PGW-C2 to establish a private network session for the UE (APN is a private network APN), including selecting UPF / PGW-U, performing "secondary authentication / authorization" as needed, allocating a second user IP address to the UE, executing the PCC policy of the private network APN, and controlling the selected UPF / PGW-U to establish a private network session channel user plane for the UE. That is, there is no need to execute Figure 9 Steps 8-2, 8-3, and 11 in the above example need to be executed, and steps 9-1, 9-2, 10, 12, and 13 need to be executed. Among them:
[0298] (1) When selecting UPF / PGW-U, SMF / PGW-C1 or SMF / PGW-C2 determines whether UPF / PGW-U1 has the ability to clear the private network APN. If not, UPF / PGW-U1 is determined as the SGW-U of the private network APN, and the UPF / PGW-U with the ability to clear the private network APN is selected as UPF / PGW-U2.
[0299] (2) SMF / PGW-C1 or SMF / PGW-C2 obtains the second user IP address allocated by the private network APN through the "secondary authentication / authorization" process, or SMF / PGW-C1 or SMF / PGW-C2 allocates the second user IP address for the private network APN to the UE ( Figure 9IP address 2) and sent to UPF / PGW-U1 in step 12; for the private network, the source IP address in the UL uplink data message received by the UE sending the private network service should be the second user IP address.
[0300] (3) In step 13, SMF / PGW-C1 or SMF / PGW-C2 controls UPF / PGW-U2 and UPF / PGW-U1 to establish a user plane channel of the private network APN for the UE, including the S5 interface between UPF / PGW-U1 and UPF / PGW-U2, and the SGi interface between UPF / PGW-U2 and the private network. Through the above steps, the network side completes the establishment of the private network session channel user plane of the private network APN for the UE. When there are multiple private network services, multiple corresponding private network session channel user planes can be established for the UE through the private network APN. It is worth noting that in the 4G network, "secondary authentication / authorization" is called "non-transparent access".
[0301] Further, such as Figure 6 As shown, step C20 further includes the following steps:
[0302] Step C221: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the destination address information with the preset private network service rule related information to obtain the private network name related information required for establishing the private network session;
[0303] Step C222: When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element also serves as the second session user plane network element, the first session control plane network element determines the second user IP address and sends the second user IP address to the first session user plane network element, wherein the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0304] Step C223: The first session control plane network element controls the first session user plane network element to establish the private network session channel user plane corresponding to the private network name related information required for establishing the private network session.
[0305] It should be understood that after SMF / PGW-C1 receives the access event of the private network service sent by UPF / PGW-U1, if the access event includes the private network name-related information required to establish a private network session, the private network name-related information required to establish the private network session can be obtained based on the access event; if the access event includes destination address information, the destination address information can be obtained, and then, based on the matching rules between the destination address information, the preset destination address information, and the private network name-related information, the preset private network service rule-related information can be deduced: the private network name-related information required to establish the private network session that matches the destination address information. The following explanation is based on the example where the private network name is the private network APN.
[0306] For the scenario where the first target SMF / PGW-C also serves as the second target SMF / PGW-C and the first target UPF / PGW-U also serves as the second target UPF / PGW-U, it should be understood that according to the actual network deployment situation and the service unblocking plan, SMF / PGW-C1 has the ability to unblock public network services and private network APN services, and UPF / PGW-U1 has the ability to unblock public network services and private network APN services, that is: SMF / PGW-C1 can serve as SMF / PGW-C2, UPF / PGW-U1 can serve as UPF / PGW-U2. Specifically, if SMF / PGW-C1 determines that it can act as SMF / PGW-C2, it will act as SMF / PGW-C2, that is, SMF / PGW-C1 and SMF / PGW-C2 are the same network element, and execute the process of SMF / PGW-C2 to establish a private network session for the UE (APN is a private network APN), including selecting UPF / PGW-U, performing "secondary authentication / authorization" as needed, allocating a second user IP address to the UE, executing the PCC policy of the private network APN, and controlling the selected UPF / PGW-U to establish a private network session channel user plane for the UE. That is, there is no need to execute Figure 9 Steps 8-2, 8-3, and 11 in the above example need to be executed, and steps 9-1, 9-2, 10, 12, and 13 need to be executed. Among them:
[0307] (1) When selecting UPF / PGW-U, SMF / PGW-C1 / private network SMF / PGW-C determines whether UPF / PGW-U1 has the ability to clear the private network APN. If it does, UPF / PGW-U1 is determined as the SGW-U and UPF / PGW-U of the private network APN, that is, the UPF / SAEGW-U2 of the private network APN. UPF / PGW-U1 and UPF / SAEGW-U are the same network element and can be called UPF / PGW-U1 / SAEGW-U2.
[0308] (2) SMF / PGW-C1 or SMF / PGW-C2 obtains the second user IP address allocated by the private network APN through the "secondary authentication / authorization" process, or SMF / PGW-C1 or SMF / PGW-C2 allocates the second user IP address for the private network APN to the UE ( Figure 9 IP address 2) and sent to SMF / PGW-U1 / SAEGW-U2 in step 12; for a private network, the source IP address in the UL uplink data message received by the UE sending a private network service should be the second user IP address.
[0309] (3) In step 13, SMF / PGW-C1 or SMF / PGW-C2 controls UPF / PGW-U1 / SAEGW-U2 to establish a user plane channel of the private network APN for the UE, including the SGi interface between UPF / PGW-U1 / SAEGW-U2 and the private network, and the internal interface of UPF / PGW-U1 / SAEGW-U2 (i.e., the S5 interface for private network services). Through the above steps, the network side completes the establishment of the private network session channel user plane of the private network APN for the UE. When there are multiple private network services, multiple corresponding private network session channel user planes can be established for the UE through the private network APN. It is worth noting that in the 4G network, "secondary authentication / authorization" is called "non-transparent access".
[0310] Further, such as Figure 7 As shown, step C20 further includes the following steps:
[0311] Step C231: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the destination address information with the preset private network service rule related information to obtain the private network name related information required for establishing the private network session;
[0312] Step C232: When the first session control plane network element determines that it does not concurrently serve as the second session control plane network element and the first session user plane network element does not concurrently serve as the second session user plane network element, the first session control plane network element determines the second session control plane network element and the second session user plane network element, and sends a private network session establishment request to the second session control plane network element. The first session control plane network element determines the second session control plane network element using the same or similar method as that used by the session establishment initiating network element to determine the session control plane network element. That is, in a 4G network, the first session control plane network element determines the second session control plane network element through DNS resolution.
[0313] Step C233: The second session control plane network element returns a private network session establishment response to the first session control plane network element, where the private network session establishment response includes at least the second user IP address and interface address information of a relevant interface of the second session user plane network element, wherein the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information;
[0314] Step C234: When the first session control plane network element receives the private network session establishment response, it sends the second user IP address to the first session user plane network element, and controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session.
[0315] It should be understood that after SMF / PGW-C1 receives the access event of the private network service sent by UPF / PGW-U1, if the access event includes the private network name-related information required to establish a private network session, the private network name-related information required to establish the private network session can be obtained based on the access event; if the access event includes destination address information, the destination address information can be obtained, and then, based on the matching rules between the destination address information, the preset destination address information, and the private network name-related information, the preset private network service rule-related information can be deduced: the private network name-related information required to establish the private network session that matches the destination address information. The following explanation is based on the example where the private network name is the private network APN.
[0316] A specific manner of determining the second session user plane network element in step C232 is as follows: when the first session control plane network element determines that it does not concurrently serve as the second session control plane network element, the first session control plane network element (SMF / PGW-C1) determines the second session control plane network element (SMF / PGW-C2) through DNS resolution. That is, the first session control plane network element (SMF / PGW-C1) initiates a private network DNS resolution to its home network resource database network element (DNS) and selects the second session control plane network element based on the resolution result. Then, the first session control plane network element determines itself as the intermediate session control plane network element for the private network session, determines the first session user plane network element as the intermediate session user plane network element for the private network session, and instructs the first session user plane network element to allocate and report resources of the intermediate session user plane network element for the private network service. Finally, a private network session establishment request is sent to the second session control plane network element, and the second session control plane network element determines the second session user plane network element.
[0317] For the scenario where the first target SMF / PGW-C does not serve as the second target SMF / PGW-C and the first target UPF / PGW-U does not serve as the second target UPF / PGW-U, it should be understood that according to the actual network deployment situation and the service unblocking plan, SMF / PGW-C1 only has the ability to unblock public network services and does not have the ability to unblock private network APN services. Since UPF / PGW-U2 should be the UPF / PGW-U controlled by SMF / PGW-C2, UPF / PGW-U1 does not have the ability to unblock private network APN services, that is: SMF / PGW-C1 cannot serve as SMF / PGW-C2, and UPF / PGW-U1 cannot serve as UPF / PGW-U2. Specifically, if SMF / PGW-C1 determines that it cannot act as SMF / PGW-C2, it will initiate a private network APN resolution request to EPC DNS, and then select SMF / PGW-C2 based on the private network APN resolution result returned by EPC DNS, and send a process of establishing a private network session for the UE (APN is the private network APN) to the selected SMF / PGW-C2. After receiving the private network session (APN is the private network APN) establishment response message returned by SMF / PGW-C2, it controls UPF / PGW-U1 to establish the user plane of the private network session channel for the UE. That is, the business process from step 8 to step 13 needs to be executed. Among them: SMF / PGW-C1 receives the second user IP address returned by SMF / PGW-C2 (SMF / PGW-C2 obtains the second user IP address allocated by the private network APN through the "secondary authentication / authorization" process or the second user IP address for the private network APN allocated by SMF / PGW-C2 to the UE ( Figure 9 After receiving the IP address 2) in step 1), it is sent to UPF / PGW-U1 in step 12; for the private network, the source IP address in the UL uplink data message sent by the UE for the private network service should be the second user IP address. Through the above steps, the network side has established the private network session channel user plane of the private network APN for the UE. When there are multiple private network services, multiple corresponding private network session channel user planes can be established for the UE through the private network APN. It is worth noting that in the 4G network, "secondary authentication / authorization" is called "non-transparent access".
[0318] Corresponding to Figure 9 The business process from step 8 to step 13 is as follows:
[0319] (1) In step 8-1, SMF / PGW-C1 initiates a private network APN resolution request (i.e., PGW query) to the EPC DNS, and selects the second target SMF / PGW-C to establish a private network APN for the UE based on the query result; in the scenario where the user is roaming, the second target SMF / PGW-C of the user's private network APN is the user's home SMF / PGW-C, i.e. Figure 9 The SMF / PGW-C2 in the user's public network APN will use itself as the SGW-C of the user's private network APN, and will select UPF / PGW-U1 as the SGW-U of the user's private network APN.
[0320] (2) In step 8-2, SMF / PGW-C1 acts as the SGW-C of the user private network APN and instructs the SGW-U of the user private network APN ( Figure 9 The UPF / PGW-U1) allocates and reports the S5 interface resources of the user's private network APN.
[0321] (3) In step 8-3, SMF / PGW-C1 sends a private network session establishment request to SMF / PGW-C2 selected by the user's private network APN.
[0322] Steps 9-1 to 11: SMF / PGW-C2 establishes a private network session for the UE, including: "secondary authentication / authorization" between SMF / PGW-C2 and the private network on demand, obtaining the user's subscribed private network service preset PCC policy from the user's home PCF / UDR / PCRF / SPR, selecting UPF / PGW-U2, and issuing the private network service preset PCC policy to UPF / PGW-U2, instructing the allocation of session resources for the private network session, and allocating a second user IP address to the UE ( Figure 9 The IP address 2 in the "Secondary Authentication / Authorization" process can also be allocated by the private network IP address 2), etc., and sent to the SGW-C ( Figure 9 The SMF / PGW-C1 in the network returns relevant information and completes the relevant information exchange. The above steps follow the 3GPP standard. The 4G bearer establishment request message sent by SMF / PGW-C1 to SMF / PGW-C2 already contains relevant information about the user's APN. In the 4G network, "secondary authentication / authorization" is called "non-transparent access."
[0323] Among them, in the "Secondary Authentication / Authorization" of step 9-1, the user authentication information includes the authentication password and username. If the authentication password and username are the same and both are the user MSISDN or IMSI in the MSISDN or IMSI, then the first target SMF / PGW-C of the public network service / SGW-C of the private network service ( Figure 9 The SMF / PGW-C1 in the public network service should complete the authentication on behalf of the UE, without forwarding the authentication information to the UE; if the UE needs to provide a user name and password, the first target SMF / PGW-C of the public network service / SGW-C of the private network service (i.e. SMF / PGW-C1) needs to transparently transmit the user authentication information between the UE and the private network. At the same time, the second target SMF / PGW-C ( Figure 9SMF / PGW-C2 in the second user IP address allocated to the user ( Figure 9 In the case of IP address 2), it is necessary to ensure that the second target SMF / PGW-C of the private network service is the second user IP address allocated to the user ( Figure 9 The IP address in 2) should not be repeated with all IP addresses of the private network services that the UE can access, that is, the second user IP address pool configured by the second target SMF / PGW-C of the private network service for the enterprise private network service should not contain any IP address in the "Destination URL / URI and Destination IP Address" field in Table 2, that is, the second user IP address is not the same as the preset destination address information in the preset PCC policy.
[0324] Step 12: The first target SMF / PGW-C of the public network service / SGW-C of the private network service (ie SMF / PGW-C1) and the first target UPF / PGW-U of the public network service / SGW-U of the private network service ( Figure 9 The UPF / PGW-U1 in the network completes information interaction through the Sx interface, including: SMF / PGW-C1 sends the preset PCC policy to UPF / PGW-U1, the second target UPF / PGW-U ( Figure 9 S5 interface information of UPF / PGW-U2 in the user private network, the second user IP address for the user private network APN ( Figure 9 The first target SMF / PGW-C / SGW-C of the public network service and the target SMF / PGW-C2 of the user's private network service complete the relevant information interaction and complete the establishment of the private network session.
[0325] Step 13: The first target UPF / PGW-U of the public network service / SGW-U of the private network service and the second target UPF / PGW-U of the private network service ( Figure 9 The private network session channel user plane of the private network session is established between the UPF / PGW-U and the UPF / PGW-U in the private network, and the private network service of the user is unblocked through the private network session channel user plane, that is, the UL uplink data message of the private network service cached by the first target UPF / PGW-U and the UL uplink data message currently being transmitted (the UL uplink data message of the private network service received by the first target UPF / PGW-U after the private network session channel user plane is established) are transmitted by the private network session channel user plane.
[0326] Further, while executing step C20, for the scenario where the first target SMF / PGW-C also serves as the second target SMF / PGW-C and the first target UPF / PGW-U does not also serve as the second target UPF / PGW-U, or the scenario where the first target SMF / PGW-C also serves as the second target SMF / PGW-C and the first target UPF / PGW-U also serves as the second target UPF / PGW-U, or the scenario where the first target SMF / PGW-C does not also serve as the second target SMF / PGW-C and the first target UPF / PGW-U does not also serve as the second target UPF / PGW-U, if the private network needs to start the secondary authentication / authorization authentication process, the secondary authentication / authorization authentication process includes:
[0327] When the first session control plane network element determines that the private network needs to start secondary authentication / authorization and it has stored the user authentication information required for the secondary authentication of the user terminal, it can act as an agent for the user terminal to perform the secondary authentication / authorization process according to the local configuration or the preset private network service rule related information, and control the first session user plane network element to perform the relevant authorization of the private network to the user terminal. It is worth noting that the secondary authentication / authorization process corresponds to Figure 9 For details, please refer to step 9-1 above.
[0328] If SMF / PGW-C1 determines that the private network needs to start secondary authentication / authorization authentication, and it stores the user authentication information required for secondary authentication of the UE, SMF / PGW-C1 performs secondary authentication on behalf of the UE. This can be understood as SMF / PGW-C1 acting as an agent for the UE to perform the secondary authentication / authorization process according to the local configuration or preset PCC policy, and controlling UPF / PGW-U1 to perform the relevant authorization of the private network to the UE. Among them, a specific implementation method of SMF / PGW-C1 acting as an agent for the UE to perform the secondary authentication / authorization process according to the local configuration or preset PCC policy is as follows: SMF / PGW-C1 is locally configured to enable the proxy UE to perform secondary authentication for specific private network name related information (private network name), and the authentication parameter is the user identity MSISDN or IMSI. Another implementation method is: add 1 parameter information in Table 2 as "Proxy user performs secondary authentication", the parameter value is: "No", "Yes, and the authentication parameter is the user identifier MSISDN", "Yes, and the authentication parameter is the user identifier IMSI", 3 types, if the value is "No", SMF / PGW-C1 does not perform secondary authentication on the proxy user, if the value is "Yes, and the authentication parameter is the user identifier MSISDN", SMF / PGW-C1 performs secondary authentication on the proxy user, and the authentication parameter is the user identifier MSISDN, if the value is "Yes, and the authentication parameter is the user identifier IMSI", SMF / PGW-C1 performs secondary authentication on the proxy user, and the authentication parameter is the user identifier IMSI.
[0329] In the scenario where the first target SMF / PGW-C also serves as the second target SMF / PGW-C and the first target UPF / PGW-U does not also serve as the second target UPF / PGW-U, or the first target SMF / PGW-C also serves as the second target SMF / PGW-C and the first target UPF / PGW-U also serves as the second target UPF / PGW-U, or the first target SMF / PGW-C does not serve as the second target SMF / PGW-C and the first target UPF / PGW-U does not serve as the second target UPF / PGW-U, there is no need to send the user authentication information to the UE. The secondary authentication or authorization process is completed by SMF / PGW-C1 instead of the UE. The user does not need to manually enter the user authentication information on the UE, which enables the user to use the private network service process through the UE without perception, thereby improving the user's service access experience.
[0330] Step C30: The first session user plane network element replaces the first user IP address in the UL uplink data packets of all the private network services transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets to the private network through the private network session channel user plane.
[0331] In this embodiment, after the private network session channel user plane is established, the UPF / PGW-U1 of the public network service has only one public network session channel user plane for the UE side, including the S5 / S8 interface (in the case of the SGW-U ( Figure 9 There is an SGW-U1) or S1-U interface (SGW-U and UPF / PGW-U1 are the same UPF / SAEGW-U (in Figure 9 In the example, SGW-U1 and UPF / PGW-U1 are the same network element); on the network side, there is a public network session channel user plane (only SGi interface exists) and a private network session channel user plane (when UPF / PGW-U1 does not also serve as UPF / PGW-U2, there is S5 interface; when UPF / PGW-U1 also serves as UPF / PGW-U2, there is SGi interface).
[0332] UPF / PGW-U1 replaces the first user IP address in the UL uplink data message of all private network services transmitted on the user plane of the public network session channel with the second user IP address. Furthermore, UPF / PGW-U1 transmits the replaced UL uplink data message to the private network through the user plane of the private network session channel, that is, service diversion, to achieve access to the private network. Among them, private networks include campus networks, enterprise private networks, etc. Enterprise private networks include private networks of government departments, private networks of public institutions, private networks of private enterprises, etc. UPF / PGW-U1 replaces the first user IP address in the UL uplink data message with the second user IP address. This is an operation completed on behalf of the UE and does not require the UE to support the multi-APN function.
[0333] Specifically, step S230 includes: after the private network session channel user plane is established, the first session user plane network element will replace the first user IP address in all UL uplink data messages of the private network service cached before the establishment of the private network session channel user plane with the second user IP address assigned to the user terminal by the network, and will replace the first user IP address in all UL uplink data messages of the private network service received after the establishment of the private network session channel user plane with the second user IP address assigned to the user terminal by the network, and will transmit all the replaced UL uplink data messages of the private network service cached before the establishment of the private network session channel user plane and all the replaced UL uplink data messages of the private network service received after the establishment of the private network session channel user plane to the private network through the private network session channel user plane in sequence.
[0334] It should be understood that after the private network session channel user plane is established, UPF / PGW-U1 replaces the first user IP address in all UL uplink data packets of private network services cached before the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and replaces the first user IP address in all UL uplink data packets of private network services received after the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets of all private network services cached before the private network session channel user plane is established and the replaced UL uplink data packets of all private network services received after the private network session channel user plane is established to the private network in sequence through the private network session channel user plane. Among them, the private network session channel user plane transmits UL uplink data packets in accordance with the first-received-first-forwarded rule.
[0335] Furthermore, this embodiment supports the diversion and aggregation of multiple private network services within the public network service of the same user. Considering that a user may use multiple private network services through the same UE, based on the private network name information related to the private network service used by the user in the same public network service session channel user plane on the same UE, multiple corresponding private network session channel user planes are established for the UE, that is, the first session user plane network element transmits the replaced UL uplink data message to the private network through the private network session channel user plane, including:
[0336] The first session user plane network element executes a service diversion rule to determine a private network session channel identifier according to the UL uplink data message, and transmits the replaced UL uplink data message to the private network through the private network session channel user plane corresponding to the private network session channel identifier.
[0337] It should be understood that when there are one or more private network services, after the private network session channel user plane is established, each private network service corresponds to a private network session channel user plane, and each private network session channel user plane has a corresponding private network session channel identifier. UPF / PGW-U1 executes the service diversion rule, determines the private network session channel identifier according to the target UL uplink data corresponding to different private network services, and matches the corresponding private network session channel user plane through the determined private network session channel identifier. UPF / PGW-U1 replaces the first user IP address in each UL uplink data message with the second user IP address, and then transmits each replaced UL uplink data message to the private network through the private network session channel user plane corresponding to the private network name related information according to the corresponding private network session channel identifier, thereby realizing service diversion. Among them, each private network service corresponds to a respective second user IP address.
[0338] Step C40: The first session user plane network element replaces the second user IP address in the DL downlink data message sent from the private network to the user terminal with the first user IP address, and sends the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
[0339] In this embodiment, after the UPF / PGW-U1 transmits the replaced UL uplink data message to the private network via the private network session channel user plane, the private network sends a DL downlink data message to the UE. The UPF / PGW-U1 replaces the second user IP address in the DL downlink data message with the first user IP address. Here, the second user IP address and the first user IP address are both understood as the destination IP address, that is, the first user IP address included in the replaced DL downlink data message corresponds to the first user IP address included in the UL uplink data message before the replacement. Furthermore, the UPF / PGW-U1 sends the replaced DL downlink data message to the UE via the public network session channel user plane and the base station in sequence, and the user can view the access information they need through the UE.
[0340] Among them, UPF / PGW-U1 forwards the data received from the SGi interface of the public network session channel user plane to the S5 / S8 interface of the public network session channel user plane (in the case of SGW-U ( Figure 9 There is an SGW-U1) or S1-U interface (SGW-U and UPF / PGW-U1 are the same UPF / SAEGW-U (in Figure 9 SGW-U1 and UPF / PGW-U1 are the same network element)), and then sent to UE through eNB; UPF / PGW-U1 forwards the data received from the S5 interface (when UPF / PGW-U1 does not serve as UPF / PGW-U2, the S5 interface exists) or SGi interface (when UPF / PGW-U1 serves as UPF / PGW-U2, the SGi interface exists) of the user plane of the private network session channel to the S5 / S8 interface of the user plane of the public network session channel (when SGW-U exists ( Figure 9 There is an SGW-U1) or S1-U interface (SGW-U and UPF / PGW-U1 are the same UPF / SAEGW-U (in Figure 9 The SGW-U1 and UPF / PGW-U1 are the same network element)) and then sent to the UE via the eNB. Among them, the UE's IP address is the first user IP address of the public network session ( Figure 9 For the IP address used for the user plane of the public network session channel ( Figure 9 IP address 1) for the user plane of the private network session channel ( Figure 9The IP addresses in 2) can all be IPv4v6, IPv4, and IPv6. One implementation of replacing the first user IP address with the second user IP address and replacing the second user IP address with the first user IP address is as follows: Figure 8 As shown, Figure 8 A schematic diagram of the mapping relationship between the first user's IP address and the second user's IP address.
[0341] Furthermore, considering that the user has multiple private network services through the UE, the private network session channel user planes with the same number as the private network services are established accordingly, and the public network session channel user plane is one, then the private network will transmit the DL downlink data messages corresponding to different private network services according to the corresponding private network session channel user plane, and each private network session channel user plane will transmit its own transmitted DL downlink data messages to the public network session channel user plane. For the public network with a public network SGW-U ( Figure 9 In the case of the public network SGW-U1) and SGW-U and UPF / PGW-U1 are the same UPF / SAEGW-U (in Figure 9 In the case where the SGW-U1 and the UPF / PGW-U1 are the same network element, step C40 includes the following steps:
[0342] The first session user plane network element executes a service aggregation rule to aggregate target DL downlink data transmitted by the private network session channel user plane corresponding to the private network session channel identifier into the public network session channel user plane between the first session user plane network element and the base station;
[0343] Replacing the second user IP address in a DL downlink data message sent by the private network to the user terminal with the first user IP address;
[0344] Sending the replaced DL downlink data message to the user terminal in sequence through the first session user plane network element and the base station of the public network session channel user plane; or,
[0345] The replaced DL downlink data message is sent to the user terminal in sequence through the first session user plane network element, the intermediate session user plane network element and the base station of the public network session channel user plane.
[0346] Specifically, when SGW-U and UPF / PGW-U1 are the same UPF / SAEGW-U (in Figure 9In the case where SGW-U1 and UPF / PGW-U1 are the same network element), when there are multiple established private network session channel user planes, UPF / PGW-U1 executes the service aggregation rule to aggregate the target DL downlink data transmitted by the private network session channel user plane corresponding to each private network session channel identifier into the public network session channel user plane between UPF / PGW-U1 and eNB, and then replaces the second user IP address in the DL downlink data message sent from the private network to the UE with the first user IP address, and then sends the replaced DL downlink data message to the UE via UPF / PGW-U1 and eNB in the public network session channel user plane in turn.
[0347] In the case where SGW-U1 exists in the public network, when there are multiple private network session channel user planes established, UPF / PGW-U1 executes the service aggregation rules to aggregate the target DL downlink data transmitted by the private network session channel user planes corresponding to each private network session channel identifier into the public network session channel user plane between UPF / PGW-U1 and eNB, and then replaces the second user IP address in the DL downlink data message sent from the private network to the UE with the first user IP address, and then sends the replaced DL downlink data message to the UE via UPF / PGW-U1, SGW-U1 and eNB in the public network session channel user plane in sequence.
[0348] According to the above technical solution, this embodiment realizes the carrying of public network services and private network services for user terminals through a single session channel, and the network can separately charge and manage the private network services and public network services of the user terminal. For user terminals that do not support the multi-APN function, public network services and private network services can be provided to users at the same time. When a user uses a private network service through a user terminal that does not support the multi-APN function or supports the multi-APN function, the user does not need to perform tedious configuration on the user terminal. By simply clicking a link on the public network page or entering the destination address, the user can start and use the private network service during the use of the public network service. The private network can be accessed without performing additional operations, which improves the user's unconsciousness in using the private network service through the user terminal and the user's service access experience.
[0349] Further, based on the above embodiment, step C20 also includes: when the preset conditions are met, the first session control plane network element sends a notification message to the corresponding session establishment initiating network element according to the previously obtained session establishment initiating network element identifier to notify the session establishment initiating network element to count the number of user planes of the private network session channel.
[0350] It should be understood that in the 4G scenario, there are multiple network elements for initiating session establishment, and SMF / PGW-C1 can enable the function of sending notification messages to MME as needed. The preset conditions are set according to actual needs. For example, the preset condition is that the establishment of the user plane of the private network session channel is completed. When SMF / PGW-C1 turns on this function, SMF / PGW-C1 should support sending notification messages according to MME, and realize sending notification messages to all or part of the MMEs of the same operator, or sending notification messages to some MMEs of other operators, or not sending notification messages to some MMEs of other operators; wherein, SMF / PGW-C1 can obtain SGW-C and SGW identifiers before establishing the user plane of the public network session channel. When the preset conditions are met, SMF / PGW-C1 sends a notification message to MME based on the previously obtained SGW-C and SGW identifiers, notifying the MME to count the number of user planes of the private network session channel, for example, the MME is Figure 9 MME1 in. SMF / PGW-C1 sends a notification message to MME based on the previously obtained SGW-C and SGW identifiers to inform MME that "the network has established an additional private network session for the UE", that is, in addition to the public network session, it also includes a private network session. Figure 9 SMF / PGW-C1 in the SGW-C1 through SGW-C1 (in the case of SGW-C) or directly (in the case of SGW-U and UPF / PGW-U1 being the same UPF / SAEGW-U) Figure 9 In the example, SGW-U1 and UPF / PGW-U1 are the same network element) send a message to MME1 to ensure the consistency of the number of statistical sessions on MME1, SGW-C and SMF / PGW-C1. If this step is present, the MME only includes this "private network session established additionally by the network for the UE" in the relevant statistical indicators, and does not use it for the sessions (public network sessions and private network sessions) that need to be established for the user when the user switches / roams across MMEs or across SMF / PGW-Cs. That is, when the UE switches / roams across MMEs or across SMF / PGW-Cs, the MME only performs the switching / redirection of the public network session, and does not need to perform the switching / redirection of the private network session.
[0351] Furthermore, based on the above embodiment, the service access processing method further includes:
[0352] The first session control plane network element and the first session user plane network element perform segmented management on the public network session channel user plane and the private network session channel user plane, and perform session management, traffic statistics and billing on the public network session corresponding to the public network service and the private network session corresponding to the private network service, respectively.
[0353] It should be understood that, in the case where SMF / PGW-C1 does not serve as SMF / PGW-C2 and UPF / PGW-U1 does not serve as UPF / PGW-U2, or in the case where SMF / PGW-C1 serves as SMF / PGW-C2 and UPF / PGW-U1 does not serve as UPF / PGW-U2, the first target SMF / PGW-C for public network services / SGW-C for private network services (i.e., SMF / PGW-C1) and the first target UPF / PGW-U for public network services / SGW-U for private network services (i.e., UPF / PGW-U1) can cooperate to implement traffic statistics and billing records for public network sessions and private network sessions, and perform management and control respectively; such as Figure 9 As shown: the public network session user plane is: UE—wireless eNB—(SGW-U1, independent or the same network element as UPF / PGW-U1)—UPF / PGW-U1—public network; the private network session user plane is: UE—wireless eNB—(SGW-U1, independent or the same network element as UPF / PGW-U1)—UPF / PGW-U1 / SGW-U2 (for UL uplink data packets, the first user IP address is replaced from user IP address 1 to user IP address 2; for DL downlink data packets, the second user IP address is replaced from user IP address 2 to user IP address 1)—UPF / PGW-U2—private network; traffic statistics and billing, and session control are performed separately for the user planes of the above two session channels.
[0354] In the case where SMF / PGW-C1 also serves as SMF / PGW-C2, and UPF / PGW-U1 also serves as UPF / PGW-U2, the first target SMF / PGW-C for public network services / the target SMF / PGW-C for private network services (i.e., SMF / PGW-C1) and the first target UPF / PGW-U for public network services / the target UPF / PGW-U for private network services (i.e., UPF / PGW-U1) can cooperate to implement traffic statistics and billing records for public network sessions and private network sessions respectively, and perform management and control separately; for example Figure 9 As shown: the public network session user plane is: UE—wireless eNB—(SGW-U1, independent or the same network element as UPF / PGW-U1)—UPF / PGW-U1—public network; the private network session user plane is: UE—wireless eNB—(SGW-U1, independent or the same network element as UPF / PGW-U1)—UPF / PGW-U1 / SGW-U2 / UPF / PGW-U2 (for UL uplink data packets, the first user IP address is replaced from user IP address 1 to user IP address 2; for DL downlink data packets, the second user IP address is replaced from user IP address 2 to user IP address 1)—private network; traffic statistics and billing, and session control are performed separately for the user planes of the above two session channels.
[0355] Furthermore, based on the above embodiment, the service access processing method further includes:
[0356] At least two QoS Flows are used to associate with the user plane of the public network session channel and the user plane of the private network session channel respectively, so as to perform end-to-end session control, traffic statistics and billing for the public network session corresponding to the public network service and the private network session corresponding to the private network service respectively.
[0357] It should be understood that, if the UE supports it, for the "UE-wireless eNB-(SGW-U1, independent or the same network element as UPF / PGW-U1)-UPF / PGW-U1 segment", two QoS Flows can be used, one QoS Flow is associated with the "UPF / PGW-U1-public network" segment of the user plane of the public network session channel, and the other QoS Flow is associated with the "UPF / PGW-U1 / SGW-U2-UPF / PGW-U2-private network or UPF / PGW-U1 / SGW-U2 / UPF / PGW-U2-private network" segment of the user plane of the private network session channel, so that the wireless network can easily perform QoS control, traffic statistics and billing for the UE's public network services and private network services respectively.
[0358] For further reference, Figure 9 , Figure 9 This includes scenarios where the user is roaming and the network already has independent SGW-C and SGW-U in the roaming location.
[0359] For scenarios where users roam and the network does not have independent SGW-C and SGW-U in the roaming location, you can also refer to Figure 9 , the difference is Figure 9 The SGW-C1 and SMF / PGW-C1 are the same network element SMF / SAEGW-C1, the SGW-U1 and UPF / PGW-U1 are the same network element UPF / SAEGW-U1, the MME and SMF / PGW-C1 are directly interconnected, and the wireless eNB and UPF / SAEGW-U1 are directly interconnected.
[0360] For scenarios where the user is not roaming but the network already has independent SGW-C and SGW-U, and the SMF / PGW-C providing the user with a public network session can select the UPF / PGW-U accessed by the private network APN, you can also refer to Figure 9 , the difference is Figure 9 The SMF / PGW-C1 and SMF / SAEGW-C2 are the same SMF / PGW-C1 / SAEGW-C2.
[0361] For scenarios where the user is not roaming but the network already has independent SGW-C and SGW-U, and the UPF / PGW-U providing the user with a public network session is the UPF / PGW-U accessed by the private network APN, you can also refer to Figure 9 , the difference is Figure 9 In the example, SMF / PGW-C1 and SMF / SAEGW-C2 are the same SMF / PGW-C1 / SAEGW-C2, and UPF / PGW-U1 and UPF / SAEGW-U2 are the same UPF / PGW-U1 / SAEGW-U2.
[0362] For scenarios where the user is not roaming and the network does not have independent SGW-C and SGW-U, and the SMF / PGW-C providing the public network session for the user can select the UPF / PGW-U accessed by the private network APN, you can also refer to Figure 9 , the difference is Figure 9 The SGW-C1 and SMF / PGW-C1 are the same network element SMF / SAEGW-C1, the SGW-U1 and UPF / PGW-U1 are the same network element UPF / SAEGW-U1, the MME and SMF / PGW-C1 are directly interconnected, the wireless eNB and UPF / SAEGW-U1 are directly interconnected, and the SMF / PGW-C1 and SMF / SAEGW-C2 are the same SMF / PGW-C1 / SAEGW-C2.
[0363] For scenarios where the user is not roaming and the network does not have independent SGW-C and SGW-U, and the UPF / PGW-U providing the user with a public network session is a UPF / PGW-U accessed by a private network APN, you can also refer to Figure 9 , the difference is Figure 9 The SGW-C1 and SMF / PGW-C1 are the same network element SMF / SAEGW-C1, the SGW-U1 and UPF / PGW-U1 are the same network element UPF / SAEGW-U1, the MME and SMF / PGW-C1 are directly interconnected, the wireless eNB and UPF / SAEGW-U1 are directly interconnected, the SMF / PGW-C1 and SMF / SAEGW-C2 are the same SMF / PGW-C1 / SAEGW-C2, and the UPF / PGW-U1 and UPF / SAEGW-U2 are the same UPF / PGW-U1 / SAEGW-U2.
[0364] For Figure 9 In the scenario, if the UE subsequently crosses the SGW-C ( Figure 9 In the case of handover / roaming of SGW-C1 in the public network, the MME selects a new SGW-C for the UE, and the first target SMF / PGW-C of the public network service / SGW-C of the private network APN service ( Figure 9The SMF / PGW-C1) in Figure 9 The SGW-C1 and SGW-U1 in the network are replaced with the corresponding new SGW-C and SGW-U, using SSC mode 1. The user's public network services and private network services are not interrupted and comply with 3GPP standards.
[0365] For Figure 9 In the scenario where SGW-C1 and SMF / PGW-C1 are the same network element SMF / SAEGW-C1, that is, MME and SMF / PGW-C1 are directly interconnected, and wireless eNB and UPF / SAEGW-U1 are directly interconnected, if the UE subsequently crosses SGW-C ( Figure 9 If the UE switches to SGW-C (e.g. Figure 9 The first target of public network services is SMF / PGW-C / SGW-C of private network APN services ( Figure 9 The SMF / PGW-C1) in Figure 9 There are independent SGW-C1 and SGW-U1 in the network, using SSC mode1. The user's public network services and private network services are not interrupted and comply with 3GPP standards.
[0366] It is worth noting that in the above implementation process, except for the technical implementation scheme disclosed in the present invention, all are in compliance with the 3GPP standard and based on the basic specifications of the 4G network. The network must be based on the APN when establishing sessions (public network sessions and private network sessions) for 4G UEs. In all the session establishment processes involved in the present invention, the network selects SMF / PGW-C and UPF / PGW-U for the UE and establishes the session based on the APN. In order to simplify the description, all the contents involving APN in the invention application proposal refer to the corresponding APN.
[0367] The present invention is also applicable to 4G users who use user terminals supporting 4G functions (for example: 4G terminals, 3G / 4G terminals, 2G / 3G / 4G, etc., and multi-mode terminals that support both 4G and 5G terminals, etc.) to access the 4G network and enjoy the service provided by the network of "immediately establishing a dedicated channel for the user to transmit the corresponding private network service when a private network service is identified in the user's public network service". The 4G network provides a scenario in which a dedicated channel for transmitting the corresponding private network service is immediately established for the user when a private network service is identified in the user's public network service for the 4G user who accesses the 4G network using a user terminal supporting 4G functions. The basic implementation principle is basically the same as that of the second embodiment, with the only difference being that: the session control plane network element can be a PGW-C or PGW-C / GGSN-C that does not have the SMF function; the session user plane network element can be a PGW-U or PGW-U / GGSN-U that does not have the UPF function; the user data management network element is an HSS or UDM / UDR / HSS or HSS / HLR or UDM / UDR / HSS / HLR; the policy control network element is a PCRF / SPR or PCF / UDR / PCRF / SPR; the functions of the network database network element can be implemented by a DRA and an EPC DNS, wherein: the DRA is responsible for the communication between the MME and the HSS, and between the PGW-C and the PCRF, and the EPC DNS is used to select SGW-C and PGW-C; and: SGW-C and PGW-C are usually combined into SAEGW-C or SAEGW / GGSN-C; SGW-U and PGW-U are usually combined into SAEGW-U or SAEGW / GGSN-U; in 4G networks, session control plane network elements and session user plane network elements can be combined into SGW, PGW, SAEGW, PGW / GGSN, SAE-GW / GGSN.
[0368] like Figure 10 As shown, the present invention provides a service access processing device, the service access processing device comprising:
[0369] An event sending module 310 is configured to send an access event of the private network service to the first session control plane network element of the public network service when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service based on the public network service initiated by the user terminal;
[0370] a session establishing module 320, configured to use the first session control plane network element to initiate a process of establishing a private network session for the user according to the access event, and control the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user;
[0371] The service offload module 330 is configured to replace the first user IP address in the UL uplink data packets of all the private network services transmitted by the user plane of the public network session channel with the second user IP address assigned to the user terminal by the network, using the first session user plane network element, and transmit the replaced UL uplink data packets to the private network through the user plane of the private network session channel;
[0372] The service aggregation module 340 is used to use the first session user plane network element to replace the second user IP address in the DL downlink data message sent by the private network to the user terminal with the first user IP address, and send the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
[0373] Furthermore, the event sending module 310 is also used to use the first session user plane network element to cache all UL uplink data packets of the private network services in the public network session channel user plane; and forward the UL uplink data packets and DL downlink data packets of the public network services through the public network session channel user plane; wherein, the public network services forwarded by the public network session channel user plane do not include the private network services, and the public network services forwarded by the public network session channel user plane do not trigger the process of establishing a private network session for the user.
[0374] Furthermore, the service diversion module 330 is specifically used to, after the private network session channel user plane is established, use the first session user plane network element to replace the first user IP address in all UL uplink data messages of the private network service cached before the establishment of the private network session channel user plane with the second user IP address assigned to the user terminal by the network, and replace the first user IP address in all UL uplink data messages of the private network service received after the establishment of the private network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmit the replaced UL uplink data messages of all the private network services cached before the establishment of the private network session channel user plane and the replaced UL uplink data messages of all the private network services received after the establishment of the private network session channel user plane to the private network in sequence through the private network session channel user plane.
[0375] Further, the event sending module 310 is further configured to obtain, by the user plane network element of the first session, the destination address information in the UL uplink data message sent by the user terminal, and determine that the UL uplink data message is a private network service when it is identified that the destination address information is the same as the preset destination address information of the private network service;
[0376] The preset destination address information of the private network service is obtained by at least one of the following methods:
[0377] The preset destination address information of the private network service is obtained by the first session user plane network element from its own local configuration;
[0378] The preset destination address information of the private network service is obtained by the first session user plane network element from the preset private network service rule related information sent to itself by the first session control plane network element;
[0379] The preset private network service rule related information is obtained by the first session control plane network element through the PCC method and / or its own local configuration, and the preset private network service rule related information is sent to the first session user plane network element during the process of establishing the public network session channel user plane for the user terminal;
[0380] The first session control plane network element obtains the preset private network service rule related information through the PCC in at least one of the following ways:
[0381] In the process of establishing a public network session for the user terminal, the policy control network element sends a full amount of information related to the preset private network service rules to the first session control plane network element;
[0382] During the process of establishing a public network session for the user terminal, the policy control network element issues a PCC predefined rule to the first session control plane network element. The first session control plane network element obtains the preset private network service rule-related information from its own locally configured PCC predefined policy based on the PCC predefined rule, where the preset private network service rule-related information includes at least a PCC policy identifier, public network name-related information, preset destination address information of the private network service, private network name-related information required for establishing the private network session, and user identifier information.
[0383] Further, the event sending module 310 is further configured to use the first session user plane network element to obtain the private network name related information required for establishing the private network session that matches the destination address information from the preset private network service rule related information, and generate the access event of the private network service according to the private network name related information required for establishing the private network session; or,
[0384] The first session user plane network element generates an access event for the private network service according to the destination address information.
[0385] Furthermore, the service access processing device further includes:
[0386] a public network session request sending unit, configured to, upon receiving a public network service activation request initiated by the user terminal by adopting a session establishment initiating network element, select a first session control plane network element corresponding to the public network service of the user terminal, and send a public network session establishment request to the first session control plane network element;
[0387] A public network session establishing unit, configured to select a first session user plane network element using the first session control plane network element, and control the first session user plane network element to establish the public network session channel user plane of the public network service and allocate the first user IP address to the user terminal; wherein the first user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0388] Furthermore, the session establishing module 320 includes:
[0389] a first information acquisition unit, configured to use the first session control plane network element to acquire, included in the access event, information related to a private network name required for establishing a private network session, or to obtain, by the first session control plane network element, destination address information included in the access event, and to match, based on the destination address information, information related to preset private network service rules to obtain information related to the private network name required for establishing the private network session;
[0390] a first information sending unit, configured to, when the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element does not also serve as the second session user plane network element, determine the second user IP address and the second session user plane network element, and send the second user IP address to the first session user plane network element; and
[0391] The first user plane establishment unit is used for the first session control plane network element to control the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0392] Furthermore, the session establishing module 320 further includes:
[0393] a second information acquisition unit, configured to use the first session control plane network element to acquire, included in the access event, information related to a private network name required for establishing a private network session, or to obtain, by the first session control plane network element, destination address information included in the access event, and to match, based on the destination address information, information related to preset private network service rules to obtain information related to the private network name required for establishing the private network session;
[0394] a second information sending unit, configured to, when the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element also serves as the second session user plane network element, determine the second user IP address and send the second user IP address to the first session user plane network element; and
[0395] The second user plane establishing unit is used to use the first session control plane network element to control the first session user plane network element to establish the private network session channel user plane corresponding to the private network name related information required for establishing the private network session.
[0396] Furthermore, the session establishing module 320 further includes:
[0397] a third information acquisition unit, configured to use the first session control plane network element to acquire, included in the access event, information related to a private network name required for establishing a private network session, or to obtain, by the first session control plane network element, destination address information included in the access event, and to match, based on the destination address information, information related to preset private network service rules to obtain information related to the private network name required for establishing the private network session;
[0398] a third information sending unit, configured to, when the first session control plane network element determines that it does not concurrently serve as the second session control plane network element and the first session user plane network element does not concurrently serve as the second session user plane network element, determine the second session control plane network element and the second session user plane network element, and send a private network session establishment request to the second session control plane network element; wherein the first session control plane network element determines the second session control plane network element using the same or similar method as that used by the session establishment initiating network element to determine the session control plane network element;
[0399] a fourth information sending unit, configured to use the second session control plane network element to return a private network session establishment response to the first session control plane network element, where the private network session establishment response includes at least the second user IP address and interface address information of a related interface of the second session user plane network element;
[0400] The third user plane establishment unit is used to send the second user IP address to the first session user plane network element when the first session control plane network element receives the private network session establishment response, and control the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
[0401] Furthermore, the session establishing module 320 further includes:
[0402] The authentication unit is used to use the first session control plane network element to determine that the private network needs to start secondary authentication / authorization, and when it itself stores the user authentication information required for secondary authentication of the user terminal, it can act on behalf of the user terminal to perform the secondary authentication / authorization process according to the local configuration or preset private network business rule related information, and control the first session user plane network element to execute the relevant authorization of the private network to the user terminal.
[0403] Furthermore, the service offload module 320 is specifically configured to transmit the replaced UL uplink data message to the private network through the user plane of the private network session channel:
[0404] The first session user plane network element is used to execute service diversion rules to determine the private network session channel identifier based on the UL uplink data message, and the replaced UL uplink data message is transmitted to the private network through the private network session channel user plane corresponding to the private network session channel identifier.
[0405] Furthermore, the service convergence module 340 includes:
[0406] a message aggregation unit, configured to use the first session user plane network element to execute a service aggregation rule to aggregate target DL downlink data transmitted by the private network session channel user plane corresponding to the private network session channel identifier to the public network session channel user plane between the first session user plane network element and the base station;
[0407] An address replacement unit, configured to replace the second user IP address in a DL downlink data message sent by the private network to the user terminal with the first user IP address;
[0408] An address sending unit is used to send the replaced DL downlink data message to the user terminal in sequence through the first session user plane network element of the public network session channel user plane and the base station; or to send the replaced DL downlink data message to the user terminal in sequence through the first session user plane network element, the intermediate session user plane network element and the base station of the public network session channel user plane.
[0409] Furthermore, the service access processing device further includes:
[0410] A quantity statistics unit is used to use the first session control plane network element to send a notification message to the corresponding session establishment initiation network element according to the previously obtained session establishment initiation network element identifier when a preset condition is met, so as to notify the session establishment initiation network element to count the number of user planes of the private network session channel.
[0411] Furthermore, the service access processing device further includes:
[0412] The first management and control unit is configured to use the first session control plane network element and the first session user plane network element to segment the user plane of the public network session channel and the user plane of the private network session channel, and to perform session management, traffic statistics, and billing on the public network session corresponding to the public network service and the private network session corresponding to the private network service, respectively.
[0413] Furthermore, the service access processing device further includes:
[0414] The second management and control unit is used to use at least two QoS Flows to associate with the user plane of the public network session channel and the user plane of the private network session channel, so as to perform end-to-end session management, traffic statistics and billing for the public network session corresponding to the public network service and the private network session corresponding to the private network service.
[0415] The specific implementation of the business processing system of the present invention is basically the same as the various embodiments of the above-mentioned business processing method, and will not be repeated here.
[0416] The present invention also provides a mobile communication network packet domain device, which includes: a memory, a processor, and a service access processing program stored in the memory and executable on the processor. When the service access processing program is executed by the processor, the steps of the above-mentioned service access processing method are implemented.
[0417] Furthermore, the present invention also provides a storage medium on which a service access processing program is stored. When the service access processing program is executed by a processor, the steps of the above-mentioned service access processing method are implemented.
[0418] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0419] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0420] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0421] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0422] It should be noted that in the claims, any reference signs placed between parentheses shall not be construed as limiting the claims. The word "comprising" does not exclude the presence of components or steps not listed in the claim. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The invention can be implemented by means of hardware comprising several different components and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, third etc. does not indicate any order. These words may be interpreted as names.
[0423] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0424] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A service access processing method, characterized in that: Applied to a mobile communication network packet domain device, the service access processing method includes: Based on the public network service initiated by the user terminal, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, the first session user plane network element sends an access event of the private network service to the first session control plane network element of the public network service; The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user; The first session user plane network element replaces the first user IP address in all UL uplink data packets of the private network service transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets to the private network through the private network session channel user plane, wherein the first user IP address is the IP address assigned to the user terminal by the first session control plane network element, and the second user IP address is the IP address assigned to the user terminal by the second session control plane network element; and The first session user plane network element replaces the second user IP address in the DL downlink data message sent from the private network to the user terminal with the first user IP address, and sends the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
2. The method according to claim 1, wherein When the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, the method further includes: The first session user plane network element caches all UL uplink data packets of the private network service in the public network session channel user plane; and The public network session channel user plane forwards the UL uplink data message and DL downlink data message of the public network service; wherein, the public network service forwarded by the public network session channel user plane does not include the private network service, and the public network service forwarded by the public network session channel user plane does not trigger the process of establishing a private network session for the user.
3. The method according to claim 1, wherein The first session user plane network element replaces the first user IP address in all UL uplink data packets of the private network service transmitted by the public network session channel user plane with the second user IP address assigned to the user terminal by the network, and transmits the replaced UL uplink data packets to the private network through the private network session channel user plane, including: After the private network session channel user plane is established, the first session user plane network element will replace the first user IP address in all UL uplink data messages of the private network service cached before the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and will replace the first user IP address in all UL uplink data messages of the private network service received after the private network session channel user plane is established with the second user IP address assigned to the user terminal by the network, and will transmit all the replaced UL uplink data messages of the private network service cached before the private network session channel user plane is established and all the replaced UL uplink data messages of the private network service received after the private network session channel user plane is established to the private network in sequence through the private network session channel user plane.
4. The method according to claim 1, wherein The service access processing method further includes: The first session user plane network element obtains the destination address information in the UL uplink data message sent by the user terminal, and when identifying that the destination address information is the same as the preset destination address information of the private network service, determines that the UL uplink data message is a private network service; The preset destination address information of the private network service is obtained by at least one of the following methods: The preset destination address information of the private network service is obtained by the first session user plane network element from its own local configuration; The preset destination address information of the private network service is obtained by the first session user plane network element from the preset private network service rule related information sent to itself by the first session control plane network element; The preset private network service rule related information is obtained by the first session control plane network element through the PCC method and / or its own local configuration, and the preset private network service rule related information is sent to the first session user plane network element during the process of establishing the public network session channel user plane for the user terminal; The first session control plane network element obtains the preset private network service rule related information through the PCC in at least one of the following ways: In the process of establishing a public network session for the user terminal, the policy control network element sends a full amount of information related to the preset private network service rules to the first session control plane network element; During the process of establishing a public network session for the user terminal, the policy control network element issues a PCC predefined rule to the first session control plane network element. The first session control plane network element obtains the preset private network service rule-related information from its own locally configured PCC predefined policy based on the PCC predefined rule, where the preset private network service rule-related information includes at least a PCC policy identifier, public network name-related information, preset destination address information of the private network service, private network name-related information required for establishing the private network session, and user identifier information.
5. The method according to claim 4, wherein The service access processing method further includes: The first session user plane network element obtains the private network name related information required for establishing the private network session that matches the destination address information from the preset private network service rule related information, and generates the access event of the private network service according to the private network name related information required for establishing the private network session; or The first session user plane network element generates an access event for the private network service according to the destination address information.
6. The method according to claim 1, wherein For the public network service initiated by the user terminal, when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service, before sending the access event of the private network service to the first session control plane network element of the public network service, the method further includes: When the session establishment initiating network element receives the public network service activation request initiated by the user terminal, it selects the first session control plane network element corresponding to the public network service of the user terminal and sends a public network session establishment request to the first session control plane network element; The first session control plane network element selects a first session user plane network element, and controls the first session user plane network element to establish a public network session channel user plane for the public network service and allocate the first user IP address to the user terminal; wherein, the first user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
7. The method according to claim 1, wherein The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing the private network session channel user plane for the user, whereby establishing the private network session channel user plane for the user includes: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the preset private network service rule related information to obtain the private network name related information required for establishing the private network session based on the destination address information; When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element does not also serve as the second session user plane network element, the first session control plane network element determines the second user IP address and the second session user plane network element, and sends the second user IP address to the first session user plane network element; and The first session control plane network element controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
8. The method according to claim 1, wherein The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user, further comprising: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the preset private network service rule related information to obtain the private network name related information required for establishing the private network session based on the destination address information; When the first session control plane network element determines that it also serves as the second session control plane network element and the first session user plane network element also serves as the second session user plane network element, the first session control plane network element determines the second user IP address and sends the second user IP address to the first session user plane network element; and The first session control plane network element controls the first session user plane network element to establish the private network session channel user plane corresponding to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
9. The method according to claim 1, wherein The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user, further comprising: The first session control plane network element obtains the private network name related information required for establishing the private network session included in the access event, or the first session control plane network element obtains the destination address information included in the access event, and matches the preset private network service rule related information to obtain the private network name related information required for establishing the private network session based on the destination address information; When the first session control plane network element determines that it does not concurrently serve as the second session control plane network element and the first session user plane network element does not concurrently serve as the second session user plane network element, the first session control plane network element determines the second session control plane network element and the second session user plane network element, and sends a private network session establishment request to the second session control plane network element; wherein the first session control plane network element determines the second session control plane network element using the same or similar method as that used by the session establishment initiating network element to determine the session control plane network element; The second session control plane network element returns a private network session establishment response to the first session control plane network element, where the private network session establishment response includes at least the second user IP address and interface address information of a related interface of the second session user plane network element; When the first session control plane network element receives the private network session establishment response, it sends the second user IP address to the first session user plane network element, and controls the first session user plane network element and the second session user plane network element to establish the private network session channel user plane corresponding to the private network name related information according to the private network name related information required to establish the private network session; wherein, the second user IP address is different from the preset destination address information of the private network service in the preset private network service rule related information.
10. The method according to any one of claims 7 to 9, wherein The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user, further comprising: When the first session control plane network element determines that the private network needs to start secondary authentication / authorization and it itself stores the user authentication information required for secondary authentication of the user terminal, it can act on behalf of the user terminal to perform the secondary authentication / authorization process according to the local configuration or the preset private network business rule related information, and control the first session user plane network element to execute the relevant authorization of the private network to the user terminal.
11. The method according to claim 1, wherein The transmitting the replaced UL uplink data message to the private network through the private network session channel user plane includes: The first session user plane network element executes a service diversion rule to determine a private network session channel identifier according to the UL uplink data message, and transmits the replaced UL uplink data message to the private network through the private network session channel user plane corresponding to the private network session channel identifier.
12. The method according to claim 11, wherein The first session user plane network element replacing the second user IP address in a DL downlink data message sent from the private network to the user terminal with the first user IP address, and sequentially sending the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station includes: The first session user plane network element executes a service aggregation rule to aggregate target DL downlink data transmitted by the private network session channel user plane corresponding to the private network session channel identifier into the public network session channel user plane between the first session user plane network element and the base station; Replacing the second user IP address in a DL downlink data message sent by the private network to the user terminal with the first user IP address; Sending the replaced DL downlink data message to the user terminal in sequence through the first session user plane network element and the base station of the public network session channel user plane; or, The replaced DL downlink data message is sent to the user terminal in sequence through the first session user plane network element, the intermediate session user plane network element and the base station of the public network session channel user plane.
13. The method according to claim 1, wherein The first session control plane network element initiates a process of establishing a private network session for the user according to the access event, and controls the first session user plane network element to execute a process of establishing the private network session channel user plane for the user, so that after the private network session channel user plane is established for the user, the process further includes: When the preset condition is met, the first session control plane network element sends a notification message to the corresponding session establishment initiating network element according to the previously obtained session establishment initiating network element identifier, so as to notify the session establishment initiating network element to count the number of user planes of the private network session channel.
14. The method according to claim 1, wherein The service access processing method further includes: The first session control plane network element and the first session user plane network element perform segmented management on the public network session channel user plane and the private network session channel user plane, and perform session management, traffic statistics and billing on the public network session corresponding to the public network service and the private network session corresponding to the private network service, respectively.
15. The method according to claim 1, wherein The service access processing method further includes: At least two QoS Flows are used to associate with the user plane of the public network session channel and the user plane of the private network session channel respectively, so as to perform end-to-end session control, traffic statistics and billing for the public network session corresponding to the public network service and the private network session corresponding to the private network service respectively.
16. A service access processing device, characterized in that: The service access processing device includes: An event sending module is configured to send an access event of the private network service to the first session control plane network element of the public network service when the first session user plane network element identifies that the public network service transmitted by the user plane of the public network session channel includes a private network service based on the public network service initiated by the user terminal; a session establishing module, configured to use the first session control plane network element to initiate a process of establishing a private network session for the user according to the access event, and control the first session user plane network element to execute a process of establishing a user plane of the private network session channel for the user, so as to establish the user plane of the private network session channel for the user; a service offload module, configured to replace, using the first session user plane network element, the first user IP address in the UL uplink data packets of all the private network services transmitted by the public network session channel user plane with the second user IP address assigned by the network to the user terminal, and transmit the replaced UL uplink data packets to the private network through the private network session channel user plane, wherein the first user IP address is the IP address assigned by the first session control plane network element to the user terminal, and the second user IP address is the IP address assigned by the second session control plane network element to the user terminal; The service aggregation module is used to use the first session user plane network element to replace the second user IP address in the DL downlink data message sent by the private network to the user terminal with the first user IP address, and send the replaced DL downlink data message to the user terminal through the public network session channel user plane and the base station in sequence.
17. A mobile communication network packet domain device, characterized in that: The mobile communication network packet domain device includes: a memory, a processor, and a service access processing program stored in the memory and executable on the processor. When the service access processing program is executed by the processor, the service access processing method according to any one of claims 1 to 15 is implemented.
18. A storage medium, characterized in that A service access processing program is stored thereon, and when the service access processing program is executed by a processor, the service access processing method according to any one of claims 1 to 15 is implemented.
Citation Information
Patent Citations
Private network registration method and system, and corresponding network element device
CN106332047A
Realization method and device for public network user accessing private network
CN109561430A