Communication method, device, equipment and computer storage medium
By introducing a gateway between the SMF network element and the edge UPF network element, and using the gateway to modify the received session instructions and token verification, the security problem between the edge UPF network element and the SMF network element is solved, and the security authentication and communication security improvement of the edge UPF network element is achieved.
Patent Information
- Application Number
- CN202110737412.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-30
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2041-06-30
AI Technical Summary
In the prior art, there is a lack of a perfect security mechanism between the edge UPF network element and the 5G core network SMF network element, which leads to a wide range of impact on the operator's business once the edge UPF network element is attacked.
By introducing a gateway between the SMF network element and the edge UPF network element, the gateway is used to modify and send the received session instructions, receive the response message of the target edge UPF network element, and verify it according to the token to ensure communication security.
Effectively prevent illegal message access, prevent edge UPF network elements from being attacked, avoid security issues of the network carrying between edge UPF network elements and SMF network elements, and improve communication security and stability.
Smart Images

Figure CN115550928B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communications, and particularly relates to a communication method, apparatus, device, and computer storage medium. Background Art
[0002] With the upgrading of mobile communication networks, 5G networks have started to develop rapidly. To meet the requirements of application scenarios, 5G networks need to have large bandwidth, low latency, and high computing power simultaneously.
[0003] To meet the application requirements of 5G networks, an effective method is "edge computing". When using edge computing, the edge user plane function (UPF) network element is often sunk to the district, county, park, or customer-side computer room to facilitate local digestion of local data.
[0004] However, there is currently no perfect security mechanism between the edge UPF network element and the session management function (SMF) network element of the 5G core network. Once the edge UPF network element is attacked, it will have a wide range of impacts on the operator's services. Summary of the Invention
[0005] Embodiments of the present application provide a communication method, apparatus, device, and computer storage medium, which can solve the security problem of the bearer network between the edge UPF network element and the SMF network element of the 5G core network.
[0006] In a first aspect, an embodiment of the present application provides a communication method, which is applied to a gateway. The method includes:
[0007] Receiving a first session instruction sent by a session management function (SMF) network element, where the session instruction includes an access point name (DNN), network slice information, and location information;
[0008] Sending a second session instruction to a target edge UPF network element corresponding to the access point name (DNN), network slice information, and location information, so that the target edge UPF network element generates a first response message according to the second session instruction. The second session instruction is a session instruction generated by adding the communication address information of the target edge UPF network element to the first session instruction. The communication address information includes the Internet protocol (IP) address, port number, and user IP address of the target edge UPF network element. The first response message includes a token of the target edge UPF network element;
[0009] Receiving the first response message sent by the target edge UPF network element;
[0010] Verifying the target edge UPF network element according to the token in the first response message;
[0011] When the target edge UPF network element passes the verification, send a second response message to the SMF network element, where the second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message.
[0012] In an optional implementation manner, the method further includes:
[0013] Receive a registration request from the edge UPF network element, where the registration request includes the authentication information and registration information of the edge UPF network element, and the registration information includes the user plane information of the edge UPF network element, as well as the access point name DNN, network slice information, and location information supported by the edge UPF network element;
[0014] Perform security authentication on the edge UPF network element according to the authentication information;
[0015] When the security authentication passes, determine the edge UPF network element as the first edge UPF network element;
[0016] Send a message accepting registration and a token to the first edge UPF network element, where the token is used for the gateway to verify the first edge UPF network element;
[0017] Store the registration information of the first edge UPF network element for the gateway to determine the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information according to the registration information of the first edge UPF network element, and the first edge UPF network element includes the target edge UPF network element.
[0018] In an optional implementation manner, the above registration information further includes the coverage area, user address pool, device status, and capability information of the edge UPF network element.
[0019] In an optional implementation manner, the method further includes:
[0020] When receiving the data sent by the first edge UPF network element, perform security authentication on the first edge UPF network element; and
[0021] Control the amount of data sent by the first edge UPF network element within the first time period to be less than the first threshold.
[0022] In an optional implementation manner, sending a second session instruction to the target edge user plane function UPF network element corresponding to the access point name DNN, network slice information, and location information includes:
[0023] Send a second session instruction to the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information through the HTTP protocol.
[0024] Second aspect, an embodiment of the present application provides a communication method, which is applied to a Session Management Function (SMF) network element. The method includes:
[0025] Sending a session instruction to a target gateway, where the session instruction includes a Data Network Name (DNN), network slice information, and location information, so as to enable the target gateway to determine a target User Plane Function (UPF) network element corresponding to the DNN, network slice information, and location information. The session instruction includes information for instructing the target edge UPF network element to generate a first response message, and the first response message includes a token of the target edge UPF network element, so as to enable the target gateway to verify the target edge UPF network element according to the token;
[0026] Receiving a second response message sent by the target gateway, where the second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message, and the communication address information includes the Internet Protocol (IP) address, port number, and user IP address of the target edge UPF network element.
[0027] In an optional implementation manner, the method further includes:
[0028] Configuring the identification information of the gateway, where the identification information of the gateway includes the location information of the gateway, the supported DNN, and network slice information. The gateway is a pre-set gateway connected to the SMF network element, and the gateway includes the target gateway;
[0029] Storing the above-mentioned identification information of the gateway;
[0030] Before sending the session instruction to the target proxy gateway, the method further includes: determining the target gateway according to the DNN, network slice information, and location information in the session instruction and the identification information of the gateway.
[0031] Third aspect, an embodiment of the present application provides a communication device, which is applied to a gateway. The device includes:
[0032] A receiving module, configured to receive a first session instruction sent by a Session Management Function (SMF) network element, where the first session instruction includes a Data Network Name (DNN), network slice information, and location information;
[0033] A sending module, configured to send a second session instruction to a target User Plane Function (UPF) network element corresponding to the DNN, network slice information, and location information, so as to enable the target edge UPF network element to generate a first response message according to the second session instruction. The second session instruction is a session instruction generated by adding the communication address information of the target edge UPF network element to the first session instruction, and the communication address information includes the Internet Protocol (IP) address, port number, and user IP address of the target edge UPF network element. The first response message includes a token of the target edge UPF network element;
[0034] The above receiving module is further configured to receive a first response message sent by a target edge UPF network element;
[0035] The verification module is configured to verify the target edge UPF network element according to the token in the first response message;
[0036] The above sending module is further configured to, when the target edge UPF network element passes the verification, send a second response message to the SMF network element, where the second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message.
[0037] In a fourth aspect, an embodiment of the present application provides a communication device applied to a session management function SMF network element. The device includes:
[0038] A sending module, configured to send a session instruction to a target gateway, where the session instruction includes an access point name DNN, network slice information, and location information, so as to enable the target gateway to determine a target edge user plane function UPF network element corresponding to the access point name DNN, network slice information, and location information. The session instruction includes information for instructing the target edge UPF network element to generate a first response message, and the first response message includes a token of the target edge UPF network element, so as to enable the target gateway to verify the target edge UPF network element according to the token;
[0039] A receiving module, configured to receive a second response message sent by the target gateway, where the second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message, and the communication address information includes the Internet protocol IP address, port number, and user IP address of the target edge UPF network element.
[0040] In a fifth aspect, an embodiment of the present application provides an electronic device, including: a processor and a memory storing computer program instructions;
[0041] When the processor executes the computer program instructions, the communication method according to the first aspect, any optional implementation manner of the first aspect, the second aspect, or any optional implementation manner of the second aspect is implemented.
[0042] In a sixth aspect, an embodiment of the present application provides a computer storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the communication method according to the first aspect, any optional implementation manner of the first aspect, the second aspect, or any optional implementation manner of the second aspect is implemented.
[0043] The communication method, apparatus, device, and computer storage medium according to the embodiments of the present application can, when receiving a session instruction sent by an SMF network element, send a modified session instruction to a target edge UPF network element corresponding to the access point name DNN, network slice information, and location information included in the session instruction, and receive a response message generated by the target edge UPF network element according to the modified session instruction, verify the target edge UPF network element according to the token in the response message, and send a modified response message to the SMF network element when the verification is passed. In this way, when receiving a message sent by an edge UPF network element, the security of the edge UPF network element can be verified through a gateway, preventing the access of illegal messages and avoiding the security problem of the bearer network between the edge UPF network element and the SMF network element when the edge UPF network element is attacked. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] To more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0045] Figure 1 FIG. is a schematic diagram of a networking structure provided by an embodiment of the present application;
[0046] Figure 2 FIG. is a schematic diagram of a networking structure provided by an embodiment of the present application;
[0047] Figure 3 FIG. is a schematic flowchart of a communication method provided by an embodiment of the present application;
[0048] Figure 4 FIG. is a schematic structural diagram of a communication apparatus provided by an embodiment of the present application;
[0049] Figure 5 FIG. is a schematic structural diagram of a communication apparatus provided by an embodiment of the present application;
[0050] Figure 6 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] The features and exemplary embodiments of various aspects of the present application will be described in detail below. To make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than limiting the present application. For those skilled in the art, the present application can be implemented without some of these specific details. The following description of the embodiments is only intended to provide a better understanding of the present application by showing examples of the present application. It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including", or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0052] With the upgrading of mobile communication networks, 5G networks have started to develop rapidly. To meet the requirements of application scenarios, 5G networks need to have large bandwidth, low latency, and high computing power at the same time.
[0053] To meet the application requirements of 5G networks, an effective method is "edge computing". When using edge computing, the edge user plane function (UPF) network element is often sunk to the county, district, park, or customer-side computer room to facilitate local data digestion.
[0054] However, there is currently no perfect security mechanism between the edge UPF network element and the session management function (SMF) network element.
[0055] Such as Figure 1As shown in the figure, the 5G core network mainly includes network elements such as the Access and Mobility Management Function (AMF), Policy Control Function (PCF), SMF, Unified Data Management (UDM), Authentication Server Function (AUSF), NF Repository Function (NRF), UPF, and Edge UPF. The UPF and Edge UPF are respectively connected to the operator's data network (DN) and the user's internal network on the user plane.
[0056] Since the Edge UPF is connected to the SMF and they communicate directly, once the Edge UPF is attacked, there will be a risk of paralysis of the bearer network between the Edge UPF and the SMF, which will have a wide - range impact on the operator's services.
[0057] To solve the problems of the existing technology, the embodiments of the present application provide a communication method, device, equipment, and computer storage medium. First, the communication method provided by the embodiments of the present application will be introduced below.
[0058] The communication method of the embodiments of the present application can be executed by a gateway or an SMF. As Figure 2 shown, the gateway is set between the Edge UPF and the SMF, is connected to the SMF through the N4 interface, and all signaling messages between the Edge UPF and the SMF are forwarded by the gateway.
[0059] Figure 3 The figure shows a schematic flowchart of the communication method provided by an embodiment of the present application. This communication method is applied to the gateway and the SMF. As Figure 3 shown, the method may include:
[0060] Step S301, the gateway receives a first session instruction sent by the SMF.
[0061] When the 5G core network obtains a request for a user to perform a service, for example, when the 5G core network obtains a request for a user to perform an Internet access service, the SMF may generate a session instruction for the service request of the user to instruct the Edge UPF to return the information required for the service. The session instruction may include the access point name DNN, network slice information, and location information reported by the user based on the service request.
[0062] In the embodiment of the present application, a gateway is set between the SMF network element and the edge UPF network element to implement communication between the SMF network element and the edge UPF network element.
[0063] In the case of needing to communicate with the edge UPF network element, the SMF network element sends a first session instruction to the gateway. The first session instruction may include an access point name DNN, network slice information, and location information, which are used for the gateway to determine the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information. The first session instruction may include information for instructing the target edge UPF network element to generate a first response message.
[0064] In step S301, the gateway receives the first session instruction sent by the session management function SMF network element. The first session instruction includes an access point name DNN, network slice information, and location information.
[0065] Step S302, the gateway sends a second session instruction to the target edge UPF network element.
[0066] In step S302, the gateway sends a second session instruction to the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information, for the target edge UPF network element to generate a first response message according to the second session instruction. The second session instruction is a session instruction generated by adding the communication address information of the target edge UPF network element to the first session instruction. The communication address information includes the Internet Protocol IP address, port number, and user IP address of the target edge UPF network element. The first response message includes the token of the target edge UPF network element.
[0067] Correspondingly, after receiving the second session instruction, the target edge UPF network element can generate a corresponding first response message according to the second session instruction and send it to the gateway.
[0068] In this step, the gateway can determine the corresponding target edge UPF network element according to the access point name DNN, network slice information, and location information included in the first session instruction, and send a second session instruction to the target edge UPF network element. The second session instruction is a session instruction generated by adding the communication address information of the target edge UPF network element to the first session instruction. Therefore, it can also be called a modified session instruction.
[0069] The token of the target edge UPF network element included in the above first response message may be a token pre-issued by the gateway to the target edge UPF network element.
[0070] In one embodiment, the gateway may determine a target edge UPF network element based on the access point name DNN, network slice information, and location information included in the first session instruction and the relevant information of the edge UPF network element pre-stored. The relevant information may be the user plane information of the edge UPF network element and the access point name DNN, network slice information, and location information supported by the edge UPF network element. In one embodiment, the relevant information may further include the coverage area of the edge UPF network element, user address pool, device status, and the capability information of the edge UPF network element, such as information on the uplink classifier (UL CL) and branching point (BP) function of the edge UPF network element.
[0071] In one embodiment, after the gateway determines the target edge UPF network element based on the access point name DNN, network slice information, and location information included in the first session instruction and the relevant information of the edge UPF network element pre-stored, it may also allocate an IP address, port number, and user IP address to the target edge UPF network element, and modify the first session instruction to add the communication address information of the target edge UPF network element in the first session instruction to generate a second session instruction.
[0072] In one embodiment, when the gateway sends the second session instruction to the target edge UPF network element in step S302, it may also send its own digital certificate to the target edge UPF network element.
[0073] Correspondingly, in the case where the target edge UPF network element receives the digital certificate of the gateway, it may achieve security authentication of the gateway through verification of the digital certificate of the gateway. In the case where the above security authentication passes, the target edge UPF network element generates a first response message according to the second session instruction and sends it to the gateway.
[0074] Step S303, the gateway receives the first response information sent by the target edge UPF network element.
[0075] Step S304, the gateway verifies the target edge UPF network element according to the first response message
[0076] In step S304, the gateway verifies the target edge UPF network element according to the token in the first response message.
[0077] In this step, in the case where the gateway receives the first response message sent by the target edge UPF network element, it may verify the target edge UPF network element according to the token in the response message to achieve security authentication of the target edge UPF network element and avoid illegal access of the edge UPF network element.
[0078] In step S305, when the target edge UPF network element passes the verification, the gateway sends a second response message to the SMF network element.
[0079] In step S305, when the target edge UPF network element passes the verification, the gateway sends a second response message to the SMF network element. The second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message.
[0080] Correspondingly, the SMF network element receives the second response message sent by the gateway.
[0081] In this step, since the second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message, it can also be called the modified response message.
[0082] In one embodiment, when the target edge UPF network element passes the verification, the gateway can also modify the received first response information, and add the IP address, port number, and user IP address of the target edge UPF network element to the first response message to generate the second response message.
[0083] The embodiments of the present application can send a session instruction to the gateway through the SMF network element. The gateway sends a modified session instruction to the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information included in the session instruction according to the session instruction, and receives the response message generated by the target edge UPF network element according to the session instruction, and verifies the target edge UPF network element according to the token in the response message. When the verification passes, a modified response message is sent to the SMF network element. In this way, when a message sent by the edge UPF network element is received, the security of the edge UPF network element can be verified through the gateway, preventing the access of illegal messages and avoiding the security problems of the bearer network between the edge UPF network element and the SMF network element when the edge UPF network element is attacked.
[0084] In one embodiment, the method may further include the following steps performed by the gateway:
[0085] Receive a registration request from the edge UPF network element. The registration request may include the authentication information and registration information of the edge UPF network element. The registration information includes the user plane information of the edge UPF network element, as well as the access point name DNN, network slice information, and location information supported by the edge UPF network element.
[0086] The above authentication information of the target edge UPF network element may be one or more of the device IP, installed software, version, or digital certificate information of the target edge UPF network element.
[0087] Perform security authentication on the edge UPF network element according to the authentication information.
[0088] In the case where the security authentication is passed, determine the edge UPF network element as the first edge UPF network element.
[0089] Send a message accepting registration and a token to the first edge UPF network element. The token is used for the gateway to verify the first edge UPF network element.
[0090] In one embodiment, the gateway can also update the token as needed or periodically and send it to the edge UPF network element that has successfully registered.
[0091] Store the registration information of the first edge UPF network element for the gateway to determine the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information according to the registration information of the first edge UPF network element. The first edge UPF network element includes the target edge UPF network element.
[0092] The gateway performs security authentication on the edge UPF network element that initiates registration with the gateway according to the authentication information of the edge UPF network element, which can avoid illegal access of the edge UPF network element and improve the security of communication; by sending a token to the edge UPF network element that has successfully registered, the edge UPF network element can be securely authenticated through the token, thereby improving the security authentication efficiency of the gateway for the edge UPF network element; by storing the registration information of the edge UPF network element that has successfully registered, in the case of needing to communicate with the edge UPF network element, the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information can be determined through the above registration information, ensuring the smooth progress of the communication process.
[0093] In one embodiment, the above registration information further includes the coverage area, user address pool, device status of the edge UPF network element, and the capability information of the edge UPF network element. Among them, the capability information of the edge UPF network element can include information such as the uplink classifier (UL CL) and branching point (BP) function of the edge UPF network element.
[0094] The gateway determines the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information through the relevant information of the edge UPF network element in the above registration information, which can make the determined target edge UPF network element more in line with the needs of user services.
[0095] To further improve the security of communication, in one embodiment, when the edge UPF network element initiates a registration request to the gateway, it can also initiate a request to obtain the authentication information of the gateway, and the above registration request does not include the registration information of the edge UPF network element.
[0096] After the gateway receives the registration request of the edge UPF network element and the request for obtaining the authentication information of the gateway, it performs security authentication on the edge UPF network element according to the authentication information in the registration request, and sends the authentication information of the gateway to the edge UPF network element.
[0097] When the edge UPF network element passes the security authentication, the gateway sends a message accepting registration and a token to the edge UPF network element. When the gateway passes the security authentication, the edge UPF network element sends the registration information of the edge UPF network element to the gateway.
[0098] The gateway stores the registration information of the edge UPF network element for the gateway to determine the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information according to the registration information of the edge UPF network element.
[0099] In this way, two-way security authentication between the gateway and the edge UPF network element can be achieved, further improving the security of communication.
[0100] In one embodiment, the method may further include the following steps performed by the SMF network element:
[0101] Configure the identification information of the gateway. The identification information of the gateway includes the location information of the gateway, the supported access point name DNN, and network slice information. The gateway is a pre-set gateway connected to the SMF network element, and the gateway includes the target gateway.
[0102] Store the identification information of the gateway.
[0103] Before sending a session instruction to the gateway, the method further includes: determining the target gateway according to the access point name DNN, network slice information, and location information in the session instruction and the identification information of the gateway.
[0104] The SMF network element can configure and store the identification information of the gateway. In this way, the SMF network element only needs to store the identification information of the gateway and does not need to store the data of each edge UPF network element one by one. When it is necessary to communicate with the target edge UPF network element, the target gateway corresponding to the access point name DNN, network slice information, and location information can be determined through the identification information of the gateway, and the target edge UPF network element can be determined through the target gateway and communicate with the target edge UPF network element. In this way, the SMF network element does not need to configure and store any relevant data of the edge UPF network element, reducing the data configuration amount of the SMF network element. It is easy to understand that when the number of edge UPF network elements increases, the SMF network element does not need to update any data and does not need to perform pairing tests with newly accessed edge UPF network elements. In this way, the stability of the core network data is improved, and the operation and maintenance management cost of the SMF network element is reduced.
[0105] In one embodiment, the method may further include the following steps performed by the gateway:
[0106] In the case of receiving data sent by the first edge UPF network element, perform security authentication on the first edge UPF network element. And
[0107] Control the amount of data sent by the first edge UPF network element within the first time period to be less than the first threshold.
[0108] In one embodiment, when the gateway receives data sent by the first edge UPF network element, it may obtain the token of the first edge UPF network element and perform security authentication on the first edge UPF network element.
[0109] Performing security authentication on the edge UPF network element that sends data through the network element can further enhance the security of communication.
[0110] The above control that the amount of data sent by the first edge UPF network element within the first time period is less than the first threshold can be understood as controlling the amount of data sent by the edge UPF network element per unit time to be lower than a preset value. The preset value can be a standard value or can be determined according to the amount of data sent by the edge UPF network element registered with the gateway under normal circumstances.
[0111] In one embodiment, when the edge UPF network element is under an illegal attack, it will send a large amount of data to the SMF network element. If the amount of data sent by the edge UPF network element is not restricted, it will cause the bandwidth of the bearer network between the SMF network element and the edge UPF network element to be abnormally occupied, affecting the normal communication between other edge UPF network elements that are not under attack and the SMF network element.
[0112] By restricting the amount of data sent by the edge UPF network element and controlling the amount of data sent by the edge UPF network element to the gateway per unit time, it is possible to avoid the abnormal occupation of the bandwidth of the bearer network between the SMF network element and the edge UPF network element, ensure the communication efficiency, and improve the security of communication.
[0113] In one embodiment, when the gateway sends a second session instruction to the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information, it may include:
[0114] Send the second session instruction to the target edge UPF network element corresponding to the access point name DNN, network slice information, and location information through the HTTP protocol.
[0115] When the gateway communicates with the edge UPF network element using the HTTP protocol, compared with using the PFCP protocol for communication, it reduces the development difficulty and development cost.
[0116] The gateway and the SMF network element generally communicate through the PFCP protocol. It is easy to understand that when the gateway sends a session instruction or other information to the edge UPF network element, it can also perform protocol conversion on the session instruction or other information. Correspondingly, when the gateway sends information to the SMF network element, it can also perform protocol conversion on the information.
[0117] Figure 4 The structural schematic diagram of a communication device provided by an embodiment of the present application is shown. The communication device can be applied to a gateway.
[0118] As Figure 4 shown, the communication device 400 may include:
[0119] A receiving module 401, configured to receive a first session instruction sent by a session management function (SMF) network element, where the first session instruction includes an access point name (DNN), network slice information, and location information.
[0120] A sending module 402, configured to send a second session instruction to a target edge user plane function (UPF) network element corresponding to the DNN, network slice information, and location information, so that the target edge UPF network element generates a first response message according to the second session instruction. The second session instruction is a session instruction generated by adding the communication address information of the target edge UPF network element to the first session instruction. The communication address information includes the Internet Protocol (IP) address, port number, and user IP address of the target edge UPF network element. The first response message includes a token of the target edge UPF network element.
[0121] A receiving module 401, configured to receive the first response message sent by the target edge UPF network element.
[0122] A verification module 403, configured to verify the target edge UPF network element according to the token in the first response message.
[0123] A sending module 402, configured to send a second response message to the SMF network element when the target edge UPF network element passes the verification. The second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message.
[0124] In an embodiment of the present application, when receiving a session instruction sent by an SMF network element, a modified session instruction is sent to a target edge UPF network element corresponding to the DNN (Data Network Name), network slice information, and location information included in the session instruction, and a response message generated by the target edge UPF network element according to the modified session instruction is received. The target edge UPF network element is verified according to the token in the response message. When the verification is passed, a modified response message is sent to the SMF network element. In this way, when receiving a message sent by an edge UPF network element, the security of the edge UPF network element can be verified through a gateway, preventing the access of illegal messages and avoiding the security problem of the bearer network between the edge UPF network element and the SMF network element when the edge UPF network element is attacked.
[0125] In one embodiment, the communication device 400 may further include:
[0126] A receiving module 401 is further configured to receive a registration request of an edge UPF network element, where the registration request includes authentication information and registration information of the edge UPF network element, and the registration information includes user plane information of the edge UPF network element, and the DNN (Data Network Name), network slice information, and location information supported by the edge UPF network element.
[0127] An authentication module is configured to perform security authentication on the edge UPF network element according to the authentication information.
[0128] A determination module is configured to determine the edge UPF network element as a first edge UPF network element when the security authentication is passed;
[0129] A sending module 402 is configured to send a registration acceptance message and a token to the first edge UPF network element, and the token is used for the gateway to verify the first edge UPF network element.
[0130] A storage module is configured to store the registration information of the first edge UPF network element for the gateway to determine a target edge UPF network element corresponding to the DNN (Data Network Name), network slice information, and location information according to the registration information of the first edge UPF network element, and the first edge UPF network element includes the target edge UPF network element.
[0131] In one embodiment, the above registration information further includes the coverage area, user address pool, device status, and capability information of the edge UPF network element.
[0132] In one embodiment, the communication device 400 may further include:
[0133] The authentication module is further configured to perform security authentication on the first edge UPF network element when receiving data sent by the first edge UPF network element; and
[0134] A control module, configured to control the amount of data sent by the first edge UPF network element within a first time period to be less than a first threshold.
[0135] In one embodiment, the sending module 402 is configured to send a second session instruction to a target edge UPF network element corresponding to an access point name DNN, network slice information, and location information. Specifically, it may include: The sending module 402 is configured to send a second session instruction to a target edge UPF network element corresponding to an access point name DNN, network slice information, and location information through the HTTP protocol.
[0136] Figure 4 Each module in the shown device has the function of implementing Figure 3 each step performed by the gateway in the [description], and can achieve its corresponding technical effects. For the sake of brevity, it will not be elaborated here.
[0137] Figure 5 The figure shows a schematic structural diagram of a communication device provided by an embodiment of the present application. This communication device can be applied to a session management function SMF network element.
[0138] As Figure 5 shown, the communication device 500 may include:
[0139] A sending module 501, configured to send a session instruction to a target gateway. The session instruction includes an access point name DNN, network slice information, and location information, so as to enable the target gateway to determine a target edge user plane function UPF network element corresponding to the access point name DNN, network slice information, and location information. The session instruction includes information for instructing the target edge UPF network element to generate a first response message. The first response message includes a token of the target edge UPF network element, so as to enable the target gateway to verify the target edge UPF network element according to the token.
[0140] A receiving module 502, configured to receive a second response message sent by the target gateway. The second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message. The communication address information includes the Internet protocol IP address, port number, and user IP address of the target edge UPF network element.
[0141] In an embodiment of the present application, when receiving a session instruction sent by an SMF network element, the modified session instruction is sent to a target edge UPF network element corresponding to the DNN (Data Network Name), network slice information, and location information included in the session instruction, and a response message generated by the target edge UPF network element according to the modified session instruction is received. The target edge UPF network element is verified based on the token in the response message. When the verification is passed, the modified response message is sent to the SMF network element. In this way, when receiving a message sent by an edge UPF network element, the security of the edge UPF network element can be verified through a gateway, preventing the access of illegal messages and avoiding the security problem of the bearer network between the edge UPF network element and the SMF network element when the edge UPF network element is attacked.
[0142] In one embodiment, the communication device 500 further includes:
[0143] A configuration module, configured to configure the identification information of the gateway. The identification information of the gateway includes the location information of the gateway, the supported DNN (Data Network Name), and network slice information. The gateway is a pre-set gateway connected to the SMF network element, and the target gateway is included in the gateway.
[0144] A storage module, configured to store the identification information of the gateway.
[0145] A determination module, configured to determine the target gateway according to the DNN (Data Network Name), network slice information, and location information in the session instruction and the identification information of the gateway before sending the session instruction to the target gateway.
[0146] Figure 5 Each module in the device shown has the function of implementing Figure 3 each step executed by the SMF network element in, and can achieve its corresponding technical effects. For the sake of brief description, it will not be elaborated here.
[0147] Figure 6 The schematic diagram of the hardware structure of the electronic device provided by the embodiment of the present application is shown.
[0148] The electronic device may be a gateway or an SMF network element. The electronic device may include a processor 601 and a memory 602 storing computer program instructions.
[0149] Specifically, the above-mentioned processor 601 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0150] The memory 602 may include a mass storage for data or instructions. By way of example and not limitation, the memory 602 may include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 602 may include removable or non-removable (or fixed) media. Where appropriate, the memory 602 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, the memory 602 is a non-volatile solid-state memory.
[0151] The memory may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage media device, an optical storage media device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.
[0152] The processor 601 reads and executes the computer program instructions stored in the memory 602 to implement any one of the communication methods in the above embodiments.
[0153] In one example, the electronic device may further include a communication interface 603 and a bus 610. As shown, Figure 6 the processor 601, the memory 602, and the communication interface 603 are connected via the bus 610 and complete communication with each other.
[0154] The communication interface 603 is mainly used to implement communication between the various modules, devices, units, and / or devices in the embodiments of the present application.
[0155] The bus 610 includes hardware, software, or both, and couples the components of the online data flow metering device to each other. By way of example and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 610 may include one or more buses. Although embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.
[0156] The electronic device can execute the communication method in the embodiments of the present application, thereby implementing Figure 3 the described communication method.
[0157] In addition, in combination with the communication method in the above embodiments, embodiments of the present application can be implemented by providing a computer storage medium. Computer program instructions are stored on the computer storage medium; when the computer program instructions are executed by a processor, any one of the communication methods in the above embodiments is implemented.
[0158] It should be clear that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated, and those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present application.
[0159] The functional blocks shown in the above-described structural block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, and so on. When implemented in software, the elements of the present application are programs or code segments for performing the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or a communication link. A "machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.
[0160] It should also be noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, can be different from the order in the embodiments, or several steps can be executed simultaneously.
[0161] Aspects of the present disclosure have been described above with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block in the flowcharts and / or block diagrams, and the combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine such that the instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the functions / actions specified in one or more blocks of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It should also be understood that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, can also be implemented by dedicated hardware for performing the specified functions or actions, or by a combination of dedicated hardware and computer instructions.
[0162] As described above, this is only the specific implementation manner of the present application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein. It should be understood that the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application.
Claims
1. A communication method, applied to a gateway, characterized in that including: receiving a first session instruction sent by a Session Management Function (SMF) network element, where the first session instruction includes a Data Network Name (DNN), network slice information, and location information; sending a second session instruction to a target User Plane Function (UPF) network element corresponding to the DNN, network slice information, and location information, for the target edge UPF network element to generate a first response message according to the second session instruction, where the second session instruction is a session instruction generated by adding the communication address information of the target edge UPF network element to the first session instruction, and the communication address information includes the Internet Protocol (IP) address, port number, and user IP address of the target edge UPF network element, and the first response message includes a token of the target edge UPF network element; receiving the first response message sent by the target edge UPF network element; verifying the target edge UPF network element according to the token in the first response message; when the target edge UPF network element passes the verification, sending a second response message to the SMF network element, where the second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message.
2. The method according to claim 1, characterized in that, The method further includes: receiving a registration request from an edge UPF network element, where the registration request includes authentication information and registration information of the edge UPF network element, and the registration information includes user plane information of the edge UPF network element, as well as the DNN, network slice information, and location information supported by the edge UPF network element; performing security authentication on the edge UPF network element according to the authentication information; when the security authentication passes, determining the edge UPF network element as a first edge UPF network element; sending a message accepting registration and a token to the first edge UPF network element, where the token is used for the gateway to verify the first edge UPF network element; storing the registration information of the first edge UPF network element, for the gateway to determine the target edge UPF network element corresponding to the DNN, network slice information, and location information according to the registration information of the first edge UPF network element, and the first edge UPF network element includes the target edge UPF network element.
3. The method according to claim 2, wherein the registration information further includes the coverage area, user address pool, device status, and capability information of the edge UPF network element.
4. The method according to claim 2, characterized in that, The method further includes: when receiving data sent by the first edge UPF network element, performing security authentication on the first edge UPF network element; and controlling the amount of data sent by the first edge UPF network element within a first time period to be less than a first threshold.
5. The method according to claim 1, characterized in that The sending the second session instruction to the target User Plane Function (UPF) network element corresponding to the DNN, network slice information, and location information includes: sending the second session instruction to the target edge UPF network element corresponding to the DNN, network slice information, and location information through the HTTP protocol.
6. A communication method, applied to a Session Management Function (SMF) network element, characterized in that including: Send a session instruction to a target gateway, where the session instruction includes an access point name (DNN), network slice information, and location information, for the target gateway to determine a target edge user plane function (UPF) network element corresponding to the access point name (DNN), network slice information, and location information. The session instruction includes information for instructing the target edge UPF network element to generate a first response message, and the first response message includes a token of the target edge UPF network element, for the target gateway to verify the target edge UPF network element according to the token; Receive a second response message sent by the target gateway, where the second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message, and the communication address information includes the Internet Protocol (IP) address, port number, and user IP address of the target edge UPF network element.
7. The method according to claim 6, wherein Further includes: Configure identification information of a gateway, where the identification information of the gateway includes the location information of the gateway, the supported access point name (DNN), and network slice information. The gateway is a pre-set gateway connected to the SMF network element, and the target gateway is included in the gateway; Store the identification information of the gateway; Before sending the session instruction to the target gateway, the method further includes: determining the target gateway according to the access point name (DNN), network slice information, and location information in the session instruction and the identification information of the gateway.
8. A communication device is applied to a gateway, characterized in that, Includes: A receiving module, configured to receive a first session instruction sent by a session management function (SMF) network element, where the first session instruction includes an access point name (DNN), network slice information, and location information; A sending module, configured to send a second session instruction to a target edge user plane function (UPF) network element corresponding to the access point name (DNN), network slice information, and location information, for the target edge UPF network element to generate a first response message according to the second session instruction. The second session instruction is a session instruction generated by adding the communication address information of the target edge UPF network element to the first session instruction, and the communication address information includes the Internet Protocol (IP) address, port number, and user IP address of the target edge UPF network element. The first response message includes a token of the target edge UPF network element; The receiving module, configured to receive the first response message sent by the target edge UPF network element; A verification module, configured to verify the target edge UPF network element according to the token in the first response message; The sending module, configured to send a second response message to the SMF network element when the target edge UPF network element passes the verification. The second response message is a response message generated by adding the communication address information of the target edge UPF network element to the first response message.
9. A communication device, applied to a session management function (SMF) network element, characterized in that Includes: A sending module, configured to send a session instruction to a target gateway, where the session instruction includes an access point name DNN, network slice information, and location information, so as to enable the target gateway to determine a target edge user plane function UPF network element corresponding to the access point name DNN, network slice information, and location information. The session instruction includes information for instructing the target edge UPF network element to generate a first response message, and the first response message includes a token of the target edge UPF network element, so as to enable the target gateway to verify the target edge UPF network element according to the token; A receiving module, configured to receive a second response message sent by the target gateway, where the second response message is a response message generated by adding communication address information of the target edge UPF network element to the first response message, and the communication address information includes an Internet protocol IP address, a port number, and a user IP address of the target edge UPF network element.
10. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the communication method according to any one of claims 1-7 is implemented.
11. A computer storage medium, characterized in that, Computer program instructions are stored on the computer storage medium, and when the computer program instructions are executed by the processor, the communication method according to any one of claims 1-7 is implemented.
Citation Information
Patent Citations
Communication method, device and system
CN110166414A
Method and device for user plane security protection
CN111491394A