A mobility management method based on network twinning
Through the network twin architecture and edge computing technology, the problems of high delay error, low security and privacy data leakage in cloud computing networks are solved, the real-time and reliability of terminal mobility management and data transmission between different base stations are realized, and user privacy protection is enhanced.
Patent Information
- Application Number
- CN202211106389.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-11
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2042-09-11
AI Technical Summary
In the era of the Internet of Things, the existing cloud computing network architecture has problems such as high latency error, low security and privacy data leakage. Especially during the data transmission process between edge devices and cloud computing centers, it is difficult to meet the needs of mobility and privacy protection.
It adopts the Cybertwin architecture, uses the OAI platform and Docker containers as the edge cloud, splits the core network protocol architecture into data management and signaling control modules, and uses edge computing technology to achieve mobility management of terminals between different base stations. It adopts name-address separation and encryption verification transmission process to optimize the data transmission process.
It realizes the real-time transmission of data during the mobility switching process of the terminal between different base stations, improves the effectiveness and reliability of data transmission, reduces network delay, and enhances the protection of user privacy data.
Smart Images

Figure CN115604780B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer network technology, and specifically relates to a mobility management method based on network twins. Background Art
[0002] Currently, as a large number of intelligent agents with perception, reasoning, and execution capabilities gradually develop into essential elements of human production and life, interactions between agents and humans become frequent, and the interplay between physical and virtual spaces is increasing. The Internet has evolved from the Internet of Things (IoT), a traditional information transmission era, to the Internet of Everything (IoE), where humans, machines, and objects converge. Subsequently, cloud computing was introduced. Its core components are scalable infrastructure and cloud-enabled processing engine technologies that optimize the operation of network applications. By establishing cloud computing centers and leveraging their ultra-high computing efficiency to centrally process data, the internet industry can address the storage and computation challenges of massive amounts of data.
[0003] In the interconnected world, traditional cloud computing technology also has certain shortcomings, primarily including latency errors, low security, and high energy consumption. First, massive amounts of real-time data are generated on large-scale edge devices, such as in projects utilizing real-time data processing technologies. Cloud computing technology suffers from high latency due to network bandwidth and centralized management limitations. Second, users' use of social media or search engines involves the transmission of personal privacy information to cloud computing centers, but data security cannot be fully guaranteed during transmission. Furthermore, with the increasing digital transformation of products and applications that touch users' lives, such as homes, the transmission of personal data consumes significant bandwidth resources, creating the risk of privacy leaks.
[0004] Subsequently, researchers proposed new network architectures suitable for cloud computing centers, such as CloNe and CIN (Cloud Integrated Network). These architectures optimized resource management and adopted distributed deployment to reduce the reliance on network capacity during data transmission. However, these architectures still had some shortcomings. For example, the access control policy of the CloNe network architecture was too simple to defend against security issues targeting converged spaces; and the CIN network architecture had difficulty supporting the digital and intelligent expression of physical entities, thus failing to meet the mobility requirements of future internet networks.
[0005] Researchers have recently proposed a cloud-native network architecture based on Cybertwin. This architecture builds a cloud-based backbone network, integrating edge and core clouds into the network. This core network architecture addresses cloud service issues, transforming the traditional end-to-end network architecture into a cloud-to-end one. This cloud-native network architecture shifts from the traditional Internet architecture of separating names and addresses, employing name and address separation to address security risks associated with addressing, protecting user privacy, and improving network security.
[0006] Network twins serve as mobility, transport, and security agents for people, machines, and objects in cloud-native networks. Deployed and running on the edge cloud, they are a critical component of this network architecture. In this new network architecture, network twins act as communication agents, serving as virtual IDs for people, machines, and objects within the network, corresponding one-to-one with their physical counterparts. Users no longer need to connect to a specific server through traditional end-to-end communication. Cloud-native networks leverage this correspondence to effectively address service mobility. Summary of the Invention
[0007] The purpose of the present invention is to propose a mobility management method based on network twins to solve the problem of user privacy data protection in cloud-native network architecture based on network twins (Cybertwin).
[0008] The network twin-based mobility management method provided by the present invention is based on the idea of network twins. It uses the OAI platform to first implement the full process of terminal switching in the LTE system, use the Docker container as the edge cloud, and use edge technology to identify the twin part, split the twin part and encrypt and verify the transmission process part, thereby realizing mobility data management and signaling control; the specific steps are as follows.
[0009] Step 1: Based on the LTE system and OAI platform, while the core network connection remains unchanged, the terminal completes the handover between different base stations based on the logical interface (X2) between base stations. The handover can be divided into three processes: first, handover preparation, including the establishment of the Radio Resource Control (RRC) connection state and the establishment of the logical link between base stations; second, handover execution, including the forwarding of the handover message by the source base station; and finally, handover completion, including the base station requesting the Mobility Management Entity (MME) in the core network to convey the handover command to the Serving GateWay (SGW) in the core network, switching the user plane interface (S1-U) from the source base station to the target base station.
[0010] Step 2: Build a cloud-native network based on network twins
[0011] The backbone network is built based on the cloud. The core cloud is centered on cloud computing. The core network (providing user connection, user management, and business carrying) network elements (MME) and gateways (SGW) are deployed in it to provide cache, computing, and communication resources. The edge cloud is located between the core cloud and the terminal. This method selects the docker (open source application container engine) container as the edge cloud. After the terminal is normally registered with the edge cloud, it obtains the network twin ID corresponding to the access terminal on the base station side, completes the twin identification of the terminal, adopts name-address separation, and the corresponding mapping of the network space address. The terminal only needs to connect to the edge cloud through the network twin, and then connect to the core cloud to achieve cloud-to-end connection and obtain services directly from the network.
[0012] Step 3: Perform mobility management
[0013] According to the direction of data flow and signaling flow, the core network protocol architecture is divided into user plane protocol architecture and control plane protocol architecture, which correspond to the data management module and signaling control module respectively. The data management module is centered on the service gateway (SGW) and is responsible for the routing and forwarding of data services. The signaling entity in the signaling control module is the mobile management network element (MME), which is responsible for processing the sending and receiving of various business signals. Twins are defined for the service gateway and the mobile management network element respectively, and the twin identification of the core network data management module and the signaling control module is completed. They are deployed in the core cloud, and the modules call services and interact through interfaces and protocol stacks.
[0014] Step 4: Based on the corresponding mapping relationship between the location of people, machines, objects, and services and cyberspace addresses in the cloud-native network structure, the mobility issue of services is resolved. Based on the network twin, all types of data generated by users in the network are recorded in real time to enhance the protection of user privacy data. Edge computing is implemented at the edge of the network, processing large amounts of edge data in real time. Terminals access edge services through interfaces, effectively reducing network latency and optimizing data transmission timeliness.
[0015] Beneficial effects
[0016] The network twin-based mobility management method provided by the present invention can realize the movement of terminals between different base stations. During the switching process, various terminal data can be transmitted in real time. The user terminal and the core network data management module and signaling control module respectively identify the twins and split the management. Through edge computing technology, the real-time transmission of various terminal data during mobile switching can be achieved, and the effectiveness and reliability of data transmission can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a flowchart illustrating the terminal switching implementation method in the present invention.
[0018] Figure 2It is a diagram showing an example of the mobility management method based on network twins of the present invention. DETAILED DESCRIPTION
[0019] The following is a further detailed description of the network twin-based mobility management method proposed in the present invention in conjunction with the accompanying drawings and specific embodiments. For the sake of brevity, the content mentioned is often omitted in the following implementation. Therefore, the content not mentioned in the following implementation can refer to the previous part accordingly.
[0020] In the present invention, the implementation process of the terminal full process switching is as follows (see Figure 1 shown):
[0021] During the handover preparation phase, when the terminal enters the radio resource control connection state, the base station completes measurement control and verification with the terminal through a connection reconfiguration message. Afterwards, the source base station and the target base station complete the new resource allocation for the terminal through a handover request message and a handover request authentication indication, and trigger the establishment of a logical link between the base stations to forward the user data and related signaling cached by the source base station. At this point, the handover preparation is successful.
[0022] During the handover execution phase, the source base station completes the handover command forwarding with the terminal through the Radio Resource Control (RRC) connection reconfiguration message; if there is an Evolved Radio Access Bearer (E-RAB) user plane bearer that needs to be forwarded, the source base station sends a state transition message to the target base station and returns the cached data.
[0023] During the handover completion phase, the terminal initiates a random access procedure based on the Radio Resource Control (RRC) Connection Reconfiguration message and sends the Connection Reconfiguration message back to the target base station. The target base station then sends a Path Switch Request message to the mobility management network element, requesting the core network to switch the user plane path, essentially switching the interface from the source base station to the target base station.
[0024] In the present invention, the mobility management method based on network twins mainly includes twin identification and split interaction.
[0025] Using a Docker container as the edge cloud, the terminal device is deployed into the container in the form of a mirror and obtains a Docker ID. In current normal transmission, the terminal device has a unique identity identifier, the International Mobile Subscriber Identity (IMSI). In the network twin, after the terminal registers with the edge cloud, it obtains the network twin ID corresponding to the access terminal on the base station side. When the terminal successfully accesses the core network through interactive authentication and authorization with the Home Subscriber Server (HSS), it is mapped one-to-one with its network twin. Secondly, based on the data flow direction and signaling flow direction in the LTE network protocol architecture, the protocol architecture is split into the user plane protocol architecture and the control plane protocol architecture, and the mobile management network element and service gateway in the protocol architecture are defined as twins respectively. In the network edge cloud, the uplink data at the edge represents the Internet of Things service, and the downlink data represents the cloud service. Each module connects and responds through the interface and protocol stack. The user plane protocol subject of the core network is the service gateway, which is responsible for the data flow direction. After the terminal accesses the wireless resource management state, the source base station needs to transmit information and data packets related to the terminal registration and authentication to the target base station. This relies on the interface connection of the user plane of the logical link between base stations based on the tunnel protocol (GTP-U, forwarding the user's twin ID data packet, etc.). The communication interface (S1) between the base station and the core network is based on the tunnel protocol, connecting the base station and the mobile management network element, and transmitting data between the base station and the network element. The base station and the service gateway are connected through the user plane interface. The control plane part of the core network is responsible for transmitting and processing system coordination signaling. The forwarding of control plane information and terminal switching instructions between base stations is based on the application layer signaling protocol (X2-AP) of the X2 interface between base stations through the control plane information interface (X2-C) between base stations. The control plane main body mobile management network element involves the non-access layer protocol layer (NAS, Non-Access-stratum, processing the transmission of information between the terminal and the mobile management network element), and the protocol between the base station and the mobile management network element (S1AP, S1 Application Protocol, located between the base station and MME, establishing the bearer between the two). The non-access layer protocol handles the information transmission between the terminal and the mobile management network element. The signaling messages in the switching process, including the sending and receiving of connection reconfiguration, establish a connection with the mobile management network element through the wireless resource control layer. When the terminal successfully accesses the core network through interactive authentication and authorization with the home subscriber server (HSS, Home Subscriber Server, which is the database server of the core network and is responsible for storing user information), the data management module twin is connected to the home subscriber server through the signaling plane interface (S11, interactive contract data such as IMSI and authentication user parameters). For the subsequent forwarding of switching instructions and data, the split data management module and the signaling control module can be connected through the signaling plane interface (S11, creating or deleting sessions, establishing or deleting bearer messages).
[0026] In the mobility management method based on network twins, edge technology is also used to encrypt and verify the transmission process to achieve mobility data management and signaling control.
[0027] Figure 2 This is an embodiment of mobility management based on network twins. A commercial mobile phone is used as the terminal. Available user parameters in the core network's user server database are written to a programmable white card, allowing the terminal to successfully authenticate on the core network's mobility management element side, thereby accessing the core network and base station. Opening any video player on the terminal displays normal video playback. After registering with the edge cloud, the terminal obtains a network twin ID and sends it to the base station. The base station receives this information, and a function is written on the core network side to map the network twin to the terminal's physical user identification code. The signaling control module, based on the mobility management element, and the data management module, based on the service gateway, are deployed in the core cloud, and a one-to-one correspondence between the twins is obtained. When the terminal switches from the source base station to the target base station, the twin's radio resource control connection state is the same as that of a normal terminal. The terminal's handover request and the handover command issued by the base station are both executed normally. The measurement control message carrying the ID, neighbor list, measurement quantity, and measurement report quantity is encapsulated into a data packet and forwarded to the base station. The base stations then establish a logical link connection and allocate terminal resources, including temporary identifiers and other wireless resources. During the handover completion phase, the core network switches the user plane path, essentially switching the user plane interface from the source base station to the target base station. The downlink data path then follows the same path: from the data management module to the target base station, and then to the terminal. The data management module prints a modify bearer response message and a reply path switch request authentication message to the signaling control module, which then forwards it to the base station, indicating that the interface has been successfully switched. The target base station also sends a terminal connection release message to the source base station, instructing it to delete the user, confirming the successful handover. During this time, the video continues to play normally.
[0028] During the forwarding of video data packets on the move, they are connected to the edge cloud through the network twin and then to the core cloud. The terminal obtains edge services by calling the interface, and the edge computing platform processes the large amount of edge data generated by edge devices in real time, which reduces network latency to a certain extent. The corresponding mapping relationship between people, machines, objects, service locations and cyberspace addresses in the network twin enables the network twin to still record various user data in real time during the move, thereby achieving reliable transmission.
[0029] According to the description of the above-mentioned preferred embodiments, the present invention can be carried out by ordinary technicians in this field according to the principles of the present invention to make corresponding replacements, adjustments and improvements to the corresponding parameters and configurations. All these replacements, adjustments and improvements should fall within the scope of protection of the claims attached to the present invention.
Claims
1. A mobility management method based on network twins, characterized in that: Using the OAI platform, with Docker containers as the edge cloud, and edge technology, we can identify and split the twin parts, as well as encrypt and verify the transmission process. The specific steps are as follows: Step 1: Switch the terminal's entire process; Based on the LTE system and the Open Access Intelligence (OAI) platform, while maintaining core network connectivity, the terminal completes handover between base stations using the X2 logical interface between base stations. This handover consists of three steps: handover preparation, which includes establishing a radio resource control connection and establishing logical links between base stations. The second is handover execution, which includes forwarding the handover message by the source base station. Finally, handover completion involves the base station requesting the mobility management element in the core network to convey the handover command to the serving gateway (SGW), switching the user plane interface (S1-U) from the source base station to the target base station. Step 2: Build a cloud-native network based on network twins; The backbone network is built based on the cloud. The core cloud is centered on cloud computing. The core network provides user connectivity, user management, and service carrying. Various mobile management network elements and service gateways (SGW) are deployed in it to provide cache, computing, and communication resources. The edge cloud is located between the core cloud and the terminal. A Docker container is selected as the edge cloud. After the terminal is properly registered with the edge cloud, it obtains the network twin ID corresponding to the access terminal on the base station side to complete the terminal twin identification. Using name-address separation and corresponding mapping of network space addresses, the terminal connects to the edge cloud through the network twin, and then connects to the core cloud, obtaining services directly from the network. Step 3: Perform mobility management; According to the direction of data flow and signaling flow, the core network protocol architecture is divided into user plane protocol architecture and control plane protocol architecture, which correspond to the data management module and signaling control module respectively. The data management module is centered on the service gateway (SGW) and is responsible for routing and forwarding data services. The signaling entity in the signaling control module is the mobile management network element, which is responsible for processing the sending and receiving of various business signaling. The service gateway (SGW) and the mobile management network element are defined as twins respectively, and the core network data management module and signaling control module are twin-identified and deployed in the core cloud. The modules call services and interact through interfaces and protocol stacks. Step 4: Based on the corresponding mapping relationship between people, machines, objects, service locations and cyberspace addresses in the cloud-native network structure, all types of data generated by users in the network are recorded in real time based on network twins; edge computing is used to execute at the edge of the network, and the terminal calls the interface to obtain edge services.
2. The mobility management method based on network twin according to claim 1, characterized in that The specific process of terminal full-process switching in step 1 is as follows: During the handover preparation phase, after the terminal enters the radio resource control connected state, the base station completes measurement control and verification with the terminal through a radio resource control connection reconfiguration message. Subsequently, the source and target base stations complete new resource allocation for the terminal through a handover request message and a handover request authentication indication, triggering the establishment of the logical interface X2 between the base stations for forwarding user data and related signaling cached by the source base station. This completes the handover preparation successfully. During the handover execution phase, the source base station completes the handover command forwarding with the terminal through the radio resource control connection reconfiguration message; If there is a radio access bearer user plane bearer that needs to be forwarded, the source base station sends a state transition message to the target base station and returns the cached data; During the handover completion phase, the terminal initiates a random access process based on the radio resource control connection reconfiguration message and feeds back the connection reconfiguration message to the target base station; the target base station then sends a path switching request message to the mobility management network element, requesting the core network to switch the user plane path, that is, switching the interface from the source base station to the target base station.
3. The mobility management method based on network twinning according to claim 1, characterized in that: In the network twin, after the terminal registers with the edge cloud, the base station obtains the network twin ID corresponding to the access terminal. When the terminal successfully accesses the core network through interactive authentication and authorization with the Home Subscriber Server (HSS), it will be mapped one-to-one with its network twin. Based on the data flow and signaling flow directions in the LTE network protocol architecture, the protocol architecture is split into the user plane protocol architecture and the control plane protocol architecture. The mobility management network element and the serving gateway (SGW) in the protocol architecture are defined as twins respectively. In the network edge cloud, uplink data at the edge represents IoT services, while downlink data represents cloud services. Each module connects and responds through interfaces and protocol stacks. The service gateway (SGW) is the main body of the user-plane protocol in the core network and is responsible for the direction of data flow. After the terminal enters the radio resource control state, the source base station transmits information and data packets related to terminal registration and authentication to the target base station. This relies on the X2 user plane interface connection based on the tunnel protocol. The tunnel protocol is used to forward the user's twin ID data packet; The communication interface (S1) between the base station and the core network is based on the tunnel protocol, connecting the base station and the mobility management network element and transmitting data between the base station and the mobility management network element; The base station is connected to the serving gateway (SGW) via a user plane interface (S1-U); The core network control plane is responsible for transmitting and processing system coordination signaling; The forwarding of control plane information and terminal handover instructions between base stations is carried out through the inter-base station control plane information interface according to the application layer signaling protocol of the inter-base station interface. The control plane subject mobility management network element is involved in processing the non-access layer protocol layer (NAS) of information transmission between the terminal and the mobility management network element, and establishing the bearer between the two. The non-access layer protocol layer (NAS) handles the information transmission between the terminal and the mobile management network element. The signaling messages in the switching process, including the sending and receiving of connection reconfiguration, establish a connection with the mobile management network element through the wireless resource control layer. When the terminal successfully accesses the core network through interactive authentication and authorization with the home user server (HSS), the mobile management network element twin is connected to the home user server (HSS) through the signaling plane interface (S11); for the subsequent forwarding of switching instructions and data, the split mobile management network element is connected to the service gateway (SGW) through the signaling plane interface (S11).
Citation Information
Patent Citations
Handover management method based on mobile edge calculation
CN108282801A
High-throughput block chain system for 6G (6th Generation) network
CN114048578A