An access method, apparatus, device and system
By introducing the Select Functional Entity (SFE), the UE's access request determines its usage type and selects the corresponding dedicated core network node, thus solving the problems of security verification failure and signaling waste during the UE access process and achieving efficient access procedures and network isolation.
Patent Information
- Application Number
- CN202310204424.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2016-04-01
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2036-04-01
AI Technical Summary
In multi-network scenarios, existing technologies suffer from problems such as security verification failures, signaling waste, increased processing latency, and network isolation breaches during UE access, especially during UE access between different types of dedicated core networks.
The Select Function Entity (SFE) is introduced to determine the usage type of the UE based on its access request and select the corresponding dedicated core network node. This ensures that the access request is sent directly to the dedicated core network node that can serve the UE, completes security verification, and avoids multiple signaling interactions and network interactions.
It achieves one-time security verification during UE access, reduces signaling interaction, lowers processing latency and node load, and ensures mutual isolation of dedicated core networks.
Smart Images

Figure CN116233970B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to an access method, apparatus, device and system. Background Technology
[0002] Operators can provide networks with different functions for different types of communication users on the same hardware platform. For example, operators can provide mobile broadband (MBB) networks for mobile broadband users and machine-type communication (MTC) networks for machine-type communication users.
[0003] Taking the Evolved Packet System (EPS) network architecture as an example, the EPS network architecture's Evolved Packet Core (EPC) introduces a dedicated core network (EPC). To achieve the aforementioned network with specific functions, the EPC network will deploy multiple... Each Serving a specific type of user.
[0004] When multiple network sides are deployed At this time, the network side adds a Usage Type attribute to the User Equipment (UE), which is stored in the Home Subscriber Server (HSS) as part of the UE's subscription data. When the UE accesses the network, it first sends an Attach request or Tracking Area Update (TAU) request to the eNodeB (eNB). After receiving the Attach request or TAU request from the UE, the eNB forwards the Attach request or TAU request to the default value stored in the eNB. MME; default After receiving an Attach request or TAU request, the MME obtains the UE's Usage Type from the subscription data stored in the HSS or the UE's context stored in the original MME. Then, it determines the corresponding UE based on the Usage Type. When default MME determines the UE's corresponding Not the default MME is located When the UE is in a multi-network scenario, the UE sends an Attach request or a TAU request to the MME in the default network, and the MME in the default network sends a Redirection message to the eNB, instructing the eNB to send the Attach request or the TAU request to the MME in the network corresponding to the UE. When the MME in the network corresponding to the UE receives the Attach request or the TAU request, the access procedure of the UE is completed.
[0005] However, the above UE access procedure has the following problems:
[0006] 1) In a multi-network scenario, different networks are designed for different types of UEs, and different types of UEs have different security verification mechanisms. Therefore, when the default MME is not in the network corresponding to the UE, the default MME may not be able to complete the security verification of the UE.
[0007] 2) When the network corresponding to the UE is not the default MME, the UE and the network side complete the access procedure twice, causing signaling waste, increasing the processing delay, and increasing the processing burden of the MME in the default network.
[0008] 3) The function of the default MME needs to be redesigned to support the above procedure.
[0009] 4) In the above UE access procedure, when the default MME is in a different network from the network corresponding to the UE, the default MME will obtain the user context from the MME in the original network of the UE in the above procedure, which destroys the network isolation. SUMMARY
[0010] To solve the problems in the UE access in the existing multi-specialized core network scenario, the application provides an access method, device, equipment and system.
[0011] In a first aspect, an access method is provided, applied to a specialized core network, and the method comprises:
[0012] A selection function entity (SFE) receives an access request of a user equipment (UE) sent by a radio access network node (RAN Node);
[0013] The SFE determines the use type of the UE according to the access request of the UE.
[0014] The SFE selects, according to the use type of the UE, a node of a dedicated core network capable of serving the UE, the node of the dedicated core network capable of serving the UE corresponding to the use type of the UE.
[0015] When the SFE receives an access request of the UE, the SFE determines the use type of the UE according to the access request of the UE, and selects a node of a corresponding dedicated core network for the UE according to the use type of the UE, so as to send the access request to the node and complete a subsequent access process; therefore, the node accessed by the UE is the node of the dedicated core network corresponding to the UE, which ensures that the node can complete security verification for the UE; secondly, the method only has one Attach or TAU process, which can reduce signaling interaction, reduce processing delay and processing load of the node; the method does not need to redesign the function of the node; and meanwhile, interaction between dedicated core networks is avoided, which ensures the mutual isolation of the dedicated core networks.
[0016] With reference to the first aspect, in a first implementation manner of the first aspect, the access request comprises a non-access stratum (NAS) request message, and the NAS request message is an attach request message or a tracking area update (TAU) request message.
[0017] With reference to the first aspect or the first implementation manner of the first aspect, in a second implementation manner of the first aspect, the use type of the UE is determined according to the access request of the UE, and the method comprises the following steps.
[0018] The use type of the UE is directly obtained from the access request.
[0019] In this implementation manner, when the access request carries the use type of the UE, the use type of the UE can be directly obtained from the access request, and this obtaining manner is relatively simple, which can reduce the processing load of the SFE.
[0020] With reference to the first aspect or the first implementation manner of the first aspect, in a third implementation manner of the first aspect, the use type of the UE is determined according to the access request of the UE, and the method comprises the following steps.
[0021] An ID of the UE is obtained.
[0022] A subscription data request is sent to a home subscriber server (HSS), the subscription data request comprising the ID of the UE, and the subscription data request being used to request subscription data of the UE.
[0023] Subscription data of the UE returned by the HSS is received, the subscription data of the UE comprising the use type of the UE.
[0024] The use type of the UE is obtained from the subscription data of the UE.
[0025] In the implementation manner, if the access request does not directly carry the use type of the UE, the use type of the UE can be obtained from the subscription data of the UE according to the ID of the UE.
[0026] With reference to the third implementation manner of the first aspect, in a fourth implementation manner of the first aspect, the obtaining of the ID of the UE comprises:
[0027] obtaining the ID of the UE from the access request;
[0028] Alternatively, the obtaining of the ID of the UE comprises:
[0029] sending an ID request to the UE, the ID request being used for requesting the ID of the UE;
[0030] receiving the ID of the UE returned by the UE;
[0031] Alternatively, the obtaining of the ID of the UE comprises:
[0032] obtaining a temporary ID of the UE in the access request, the temporary ID of the UE being allocated by a node in an original dedicated core network in which the UE is located;
[0033] sending a context request to the node in the original dedicated core network, the context request comprising the temporary ID of the UE, the context request being used for requesting a context of the UE;
[0034] receiving the context of the UE returned by the node of the original dedicated core network, and obtaining the ID of the UE from the context of the UE.
[0035] With reference to the first aspect or the first implementation manner of the first aspect, in a fifth implementation manner of the first aspect, the determining of the use type of the UE according to the access request of the UE comprises:
[0036] obtaining a temporary ID of the UE in the access request, the temporary ID of the UE being allocated by a node in an original dedicated core network in which the UE is located;
[0037] sending a context request to the node in the original dedicated core network, the context request comprising the temporary ID of the UE, the context request being used for requesting a context of the UE;
[0038] receiving the context of the UE returned by the node of the original dedicated core network, and obtaining the use type of the UE from the context of the UE.
[0039] In the implementation, if the access request does not directly carry the use type of the UE, the use type of the UE can also be obtained from the node in the original dedicated core network according to the temporary ID of the UE.
[0040] With reference to the first aspect or any one of the first to fifth implementations of the first aspect, in a sixth implementation of the first aspect, after the node of the dedicated core network capable of serving the UE is selected for the UE according to the use type of the UE, the method further includes:
[0041] sending a redirection message to the RAN Node, the redirection message including information of the node of the corresponding dedicated core network selected by the SFE for the UE, so that the RAN Node sends the access request to the node of the corresponding dedicated core network of the UE.
[0042] With reference to the first aspect or any one of the first to fifth implementations of the first aspect, in a seventh implementation of the first aspect, after the node of the dedicated core network capable of serving the UE is selected for the UE according to the use type of the UE, the method further includes:
[0043] directly sending the access request to the node of the corresponding dedicated core network of the UE.
[0044] In the embodiments of the application, the access request is sent to the node, which can be achieved by direct sending or sending a redirection message to the RAN Node.
[0045] With reference to the seventh implementation of the first aspect, in an eighth implementation of the first aspect, the directly sending the access request to the node of the corresponding dedicated core network of the UE includes:
[0046] establishing an S1 connection with the node of the corresponding dedicated core network of the UE;
[0047] sending the access request to the node of the corresponding dedicated core network of the UE through the S1 connection.
[0048] With reference to the seventh or eighth implementation of the first aspect, in a ninth implementation of the first aspect, after the access request is directly sent to the node of the corresponding dedicated core network of the UE, the method further includes:
[0049] the SFE forwarding messages between the node of the corresponding dedicated core network of the UE and the RAN Node as a forwarding node therebetween.
[0050] With reference to the ninth implementation manner of the first aspect, in a tenth implementation manner of the first aspect, the forwarding of the message between the node of the dedicated core network corresponding to the UE and the RAN Node comprises:
[0051] receiving the message sent by the node of the dedicated core network corresponding to the UE;
[0052] forwarding the message to the RAN Node;
[0053] alternatively, receiving the message sent by the RAN Node;
[0054] forwarding the message to the node of the dedicated core network corresponding to the UE.
[0055] The second aspect provides an access method, which comprises:
[0056] a radio access network node RAN Node receives an access request sent by a user equipment UE;
[0057] when the node identifier of the original dedicated core network of the UE is not obtained from the access request, or when the node identifier of the original dedicated core network carried in the access request is not in a preconfigured node identifier table, the RAN Node determines that the node of the original dedicated core network is unreachable;
[0058] the RAN Node sends the access request to a selection function entity SFE.
[0059] when the RAN Node receives the access request sent by the UE, the RAN Node determines whether the node of the original dedicated core network is reachable according to the access request and the preconfigured node identifier table, and when it is determined that the node of the original dedicated core network is unreachable, the RAN Node sends the access request to the selection function entity SFE, so that the SFE can determine the use type of the UE according to the access request of the UE, and select the node of the dedicated core network corresponding to the UE according to the use type of the UE.
[0060] Optionally, the node identifier is a global mobility management entity identifier GUMMEI or a packet temporary mobile user identifier P-TMSI.
[0061] With reference to the second aspect, in a first implementation manner of the second aspect, the method further comprises:
[0062] the RAN Node receives the node of the dedicated core network corresponding to the UE determined by the selection function entity SFE, wherein the node of the dedicated core network corresponding to the UE is the node of the dedicated core network capable of serving the UE selected by the SFE for the UE according to the use type of the UE;
[0063] send the access request of the UE to the node of the dedicated core network corresponding to the UE.
[0064] The RAN node receives the node of the dedicated core network corresponding to the UE determined by the selection function entity SFE upon receiving the access request sent by the UE, and sends the access request of the UE to the node of the dedicated core network corresponding to the UE, to complete a subsequent access procedure; the node accessed by the UE is the node of the dedicated core network corresponding to the UE, which ensures that the node can complete security verification for the UE; secondly, the method only has one Attach or TAU procedure, which can reduce signaling interaction, reduce processing delay and processing load of the node; the method does not need to redesign the function of the node, which reduces the cost; at the same time, the method avoids interaction between dedicated core networks, and ensures the mutual isolation of the dedicated core networks.
[0065] Optionally, the node of the dedicated core network is a control plane device, and the control plane device can be an MME.
[0066] With reference to the first implementation manner of the second aspect, in a second implementation manner of the second aspect, the receiving the node of the dedicated core network corresponding to the UE determined by the selection function entity SFE comprises:
[0067] When the node identifier of the original dedicated core network of the UE is not obtained or the node of the original dedicated core network of the UE is not reachable, the node of the dedicated core network corresponding to the UE determined by the selection function entity SFE is received.
[0068] With reference to the second implementation manner of the second aspect, in a third implementation manner of the second aspect, the receiving the node of the dedicated core network corresponding to the UE determined by the selection function entity SFE comprises:
[0069] The redirection message returned by the SFE is received, and the redirection message includes information of the node of the dedicated core network corresponding to the UE.
[0070] With reference to the first implementation manner of the second aspect, in a fourth implementation manner of the second aspect, the sending the access request to the SFE comprises:
[0071] The access request is sent to the SFE, so that the SFE directly sends the access request to the node of the dedicated core network corresponding to the UE.
[0072] With reference to the fourth implementation manner of the second aspect, in a fifth implementation manner of the second aspect, the sending the access request to the SFE comprises:
[0073] An S1-application protocol AP connection is established with the SFE.
[0074] sending the access request to the SFE through the S1-AP connection.
[0075] With reference to the second aspect or any one of the first to fifth implementations of the second aspect, in a sixth implementation of the second aspect, the node identifier of the original dedicated core network of the UE is a global mobility management entity identifier (GUMMEI) or a packet temporary mobile subscriber identity (P-TMSI).
[0076] With reference to the second aspect or any one of the first to sixth implementations of the second aspect, in a seventh implementation of the second aspect, the access request includes a non-access stratum (NAS) request message, and the NAS request message is an attach request message or a tracking area update (TAU) request message.
[0077] With reference to the second aspect or any one of the first to seventh implementations of the second aspect, in an eighth implementation of the second aspect, after the access request is sent to the SFE, the method further includes:
[0078] sending, to a node of a dedicated core network corresponding to the UE, a message or receiving a message sent by the node of the dedicated core network corresponding to the UE, the node of the dedicated core network corresponding to the UE being a forwarding node between the SFE and the node of the dedicated core network corresponding to the UE.
[0079] With reference to the second aspect or any one of the first to eighth implementations of the second aspect, in a ninth implementation of the second aspect, the RAN Node receives the access request sent by the UE, and the receiving includes:
[0080] receiving the access request sent by the UE through a radio resource control (RRC) message.
[0081] With reference to the ninth implementation of the second aspect, in a tenth implementation of the second aspect, the method further includes:
[0082] determining whether the node identifier of the original dedicated core network of the UE is carried in the RRC message;
[0083] when the node identifier of the original dedicated core network of the UE is carried in the access request, determining whether the node of the original dedicated core network of the UE is reachable.
[0084] In a third aspect, an access apparatus is provided, and the apparatus includes a plurality of units, such as a receiving unit and a processing unit, which are configured to implement the method provided in the first aspect.
[0085] In a fourth aspect, an access apparatus is provided, and the apparatus includes a plurality of units, such as a receiving unit, a processing unit, and a sending unit, which are configured to implement the method provided in the second aspect.
[0086] In a fifth aspect, an access device is provided, which comprises a processor, a memory and a communication interface; the memory is configured to store software programs and modules, and the processor is configured to implement the following by running or executing the software programs and / or modules stored in the memory:
[0087] receiving an access request of a user equipment (UE) sent by a radio access network (RAN) node;
[0088] determining a usage type of the UE according to the access request of the UE;
[0089] selecting a node of a dedicated core network capable of serving the UE for the UE according to the usage type of the UE, wherein the node of the dedicated core network capable of serving the UE corresponds to the usage type of the UE.
[0090] In a sixth aspect, an access device is provided, which comprises a processor, a memory and a communication interface; the memory is configured to store software programs and modules, and the processor is configured to implement the following by running or executing the software programs and / or modules stored in the memory:
[0091] receiving an access request sent by a user equipment (UE);
[0092] determining that a node of an original dedicated core network of the UE is unreachable when a node identifier of the original dedicated core network of the UE is not obtained from the access request or when the node identifier of the original dedicated core network of the UE carried in the access request is not in a preconfigured node identifier list;
[0093] sending the access request to a selection function entity (SFE).
[0094] In a seventh aspect, a computer readable storage medium is provided, which is configured to store program codes executed by the aforementioned processor during service transmission. The program codes comprise instructions for implementing the method provided in the first aspect.
[0095] In an eighth aspect, a computer readable storage medium is provided, which is configured to store program codes executed by the aforementioned processor during service transmission. The program codes comprise instructions for implementing the method provided in the second aspect.
[0096] In a ninth aspect, an access system is provided, which comprises:
[0097] SFE, configured to receive an access request of a user equipment (UE) sent by a radio access network node (RAN Node), determine a usage type of the UE according to the access request of the UE, and select a node of a dedicated core network capable of serving the UE for the UE according to the usage type of the UE, wherein the node of the dedicated core network capable of serving the UE corresponds to the usage type of the UE;
[0098] RAN Node, configured to receive an access request sent by a user equipment (UE), determine that a node of an original dedicated core network of the UE is unreachable when a node identifier of the original dedicated core network of the UE is not obtained from the access request or when the node identifier of the original dedicated core network of the UE carried in the access request is not in a preconfigured node identifier list, and send the access request to a selection function entity (SFE). BRIEF DESCRIPTION OF DRAWINGS
[0099] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort on the basis of these drawings.
[0100] Figure 1 is a schematic diagram of an application scenario provided by the embodiments of the present application;
[0101] Figure 2a is a schematic diagram of a structure of the SFE provided by the embodiments of the present application;
[0102] Figure 2b is a schematic diagram of a structure of the RAN Node provided by the embodiments of the present application;
[0103] Figure 3 is a flowchart of an access method provided by the embodiments of the present application;
[0104] Figure 4 is a flowchart of another access method provided by the embodiments of the present application;
[0105] Figure 5 is a flowchart of another access method provided by the embodiments of the present application;
[0106] Figure 6 is a flowchart of another access method provided by the embodiments of the present application;
[0107] Figure 7 is a flowchart of another access method provided by the embodiments of the present application;
[0108] Figure 8 is a flowchart of another access method provided by the embodiments of the present application;
[0109] Figure 9 This is a schematic diagram of the structure of an access device provided in an embodiment of the present invention;
[0110] Figure 10 This is a schematic diagram of another access device provided in an embodiment of the present invention;
[0111] Figure 11 This is a schematic diagram of the structure of an access system provided in an embodiment of the present invention. Detailed Implementation
[0112] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0113] To facilitate understanding of the technical solutions provided in the embodiments of the present invention, firstly, in conjunction with Figure 1 Let me introduce the application scenarios of this invention.
[0114] This scenario includes UE 11, Radio Access Network Node (RAN Node) 12, and Core Network (CN) 13.
[0115] CN 13 includes multiple networks 131, each network 131 providing services to a specific type of terminal. Each network 131 has a node for control plane management, such as a control plane device 132. Multiple control plane devices 132 can be virtualized from a single control plane network element. Additionally, CN 133 includes an HSS 133. Networks 131 can be either dedicated core networks or network slices in future networks.
[0116] The UE 11 involved in this invention can be a 4G terminal, including handheld devices, in-vehicle devices, wearable devices, computing devices, or other processing devices connected to a wireless modem with wireless communication capabilities, as well as various forms of UEs, mobile stations (MS), terminals, terminal equipment, etc. The UE 11 can also be a terminal supporting 5G networks, including but not limited to machines, sensors, mobile terminals, etc.
[0117] RAN Node 12 refers to a node in the radio access network, responsible for communication between UE 11 and the core network; control plane equipment 132 refers to the control plane in network 131 deployed in the core network, responsible for terminal session management, authentication, access control and other functions.
[0118] Each network 131 is one RAN Node 12 is an eNB, and control plane device 132 is... The MME deployed in China.
[0119] To address the problems existing in the prior art, this invention provides a Selection Function Entity (SFE). The SFE is a new logical network element introduced in this invention, whose main function is to select the corresponding network for the terminal based on its usage type, thereby enabling network access for the terminal. This logical network element can be deployed independently of the dedicated core network on the core network side, or it can be embedded as a functional module into the network control plane; this invention does not impose any limitations on either approach.
[0120] Figure 2a This is a schematic diagram of a possible hardware structure for an SFE. (Example:) Figure 2a As shown, the SFE includes a processor 10, a memory 20, and a communication interface 30. Those skilled in the art will understand that... Figure 2a The structure shown does not constitute a limitation on this SFE and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. Wherein:
[0121] Processor 10 is the control center of the SFE, connecting various parts of the SFE through various interfaces and lines. It performs various functions and processes data by running or executing software programs and / or modules stored in memory 20, and by calling data stored in memory 20, thereby providing overall control of the SFE. Processor 10 can be implemented by a CPU or by a network processor (NP) with control plane functionality.
[0122] The memory 20 can be used to store software programs and modules. The processor 10 performs various functional applications and data processing by running the software programs and modules stored in the memory 20. The memory 20 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system 21, a receiving module 22, a processing module 23, and at least one application program 24 required by a function (such as location area identification list allocation, etc.), etc.; and the data storage area can store data created according to the use of the SFE (such as the location information of the UE, etc.), etc. The memory 20 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk. Accordingly, the memory 20 can also include a memory controller to provide the processor 10 with access to the memory 20.
[0123] The processor 20 performs the following functions by running the receiving module 22: receiving an access request of a user equipment (UE) sent by a radio access network node (RAN Node); and the processor 20 performs the following functions by running the processing module 23: determining a use type of the UE according to the access request of the UE; and selecting a node of a dedicated core network capable of serving the UE for the UE according to the use type of the UE, wherein the node of the dedicated core network capable of serving the UE corresponds to the use type of the UE.
[0124] Figure 2b For Figure 1 A possible hardware structure diagram of the RAN Node is shown. As Figure 2b shown, the RAN Node 12 includes a processor 10, a memory 20, a receiver 30, and a transmitter 40. Those skilled in the art can understand that Figure 2b the structure shown in the figure does not constitute a limitation on the RAN Node, and can include more or fewer components than shown, or combine certain components, or different component arrangements. Among them:
[0125] The processor 10 is a control center of the RAN Node, connects various parts of the RAN Node by various interfaces and lines, performs various functions of the RAN Node and processes data by running or executing software programs and / or modules stored in the memory 20 and calling data stored in the memory 20, thereby performing overall control of the RAN Node. The processor 10 can be implemented by a CPU or a network processor (NP) having a control plane function.
[0126] The memory 20 can be used to store software programs and modules. The processor 10 performs various function applications and data processing by running the software programs and modules stored in the memory 20. The memory 20 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system 21, a receiving module 22, a processing module 23, a sending module 24, and at least one application program 25 required by a function (such as location area identifier list allocation, etc.) and the like; the data storage area can store data (such as UE location information, etc.) created according to the use of the RAN Node and the like. The memory 20 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. Accordingly, the memory 20 can also include a memory controller to provide access of the processor 10 to the memory 20.
[0127] The processor 20 performs the following functions by running the receiving module 22: receiving an access request sent by a user equipment (UE); the processor 20 performs the following functions by running the processing module 23: determining that a node of the original dedicated core network is unreachable when the node identifier of the original dedicated core network of the UE is not obtained from the access request, or when the node identifier of the original dedicated core network carried in the access request is not in the preconfigured node identifier list; the processor 20 performs the following functions by running the sending module 24: sending the access request to a selection function entity (SFE).
[0128] Figure 3 is a flowchart of an access method provided by an embodiment of the present application. The method can be performed by the SFE in the aforementioned application scenarios, as shown in Figure 3 The method comprises the following steps.
[0129] Step 201: The SFE receives an access request of a user equipment (UE) sent by a radio access network node (RAN Node).
[0130] Step 202: Determine the use type of the UE according to the access request of the UE.
[0131] Step 203: Select a node of a dedicated core network capable of serving the UE for the UE according to the use type of the UE, the node of the dedicated core network capable of serving the UE corresponding to the use type of the UE.
[0132] It should be understood that the SFE selecting the node of the dedicated core network capable of serving the UE for the UE according to the use type of the UE can comprise:
[0133] directly selecting the node of the dedicated core network capable of serving the UE for the UE according to the use type of the UE; or
[0134] selecting the node of the dedicated core network capable of serving the UE for the UE according to other information in subscription data of the UE except the use type of the UE and / or a local policy preconfigured on the SFE and the use type of the UE.
[0135] The other information in the subscription data of the UE except the use type of the UE includes but is not limited to a roaming agreement; the local policy preconfigured on the SFE includes but is not limited to a network congestion state, a local network deployment, etc.
[0136] Specifically, in the embodiment of the present application, steps 202 and 203 comprise two implementation manners, the first implementation manner is described with reference to Figure 5 and Figure 6 , and the second implementation manner is described with reference to Figure 7 and Figure 8 .
[0137] In the embodiment of the present application, when the SFE receives the access request of the UE, the use type of the UE is determined according to the access request of the UE, and the node of the corresponding dedicated core network is selected for the UE according to the use type of the UE, so as to send the access request to the node and complete the subsequent access process; therefore, the node accessed by the UE is the node of the corresponding dedicated core network of the UE, which ensures that the node can complete the security verification of the UE; secondly, the method only has one Attach or TAU process, which can reduce the signaling interaction, reduce the processing delay and the processing load of the node; the method does not need to redesign the function of the node; at the same time, the interaction between the dedicated core networks is avoided, and the mutual isolation of the dedicated core networks is ensured.
[0138] Figure 4 is a flowchart of an access method provided by the embodiment of the present application. The method can be performed by the RAN Node in the foregoing application scenario, as shown in Figure 4 The method comprises the following steps.
[0139] Step 301: The RAN Node receives the access request sent by the user equipment (UE).
[0140] Step 302: When the node identifier of the original dedicated core network of the UE is not obtained from the access request, or when the node identifier of the original dedicated core network carried in the access request is not in the preconfigured node identifier table, it is determined that the node of the original dedicated core network is unreachable.
[0141] Step 303: The access request is sent to the selection function entity (SFE).
[0142] In the embodiment of the present application, whether the node of the original dedicated core network is reachable is determined according to the access request and the preconfigured node identifier table, when it is determined that the node of the original dedicated core network is unreachable, the access request is sent to the selection function entity (SFE), so that the SFE can determine the use type of the UE according to the access request of the UE, and select the node of the corresponding dedicated core network for the UE according to the use type of the UE, the node of the dedicated core network corresponding to the UE is determined through the selection function entity (SFE), and the access request of the UE is sent to the node of the dedicated core network corresponding to the UE, so as to complete the subsequent access process; the node accessed by the UE is the node of the dedicated core network corresponding to the UE, which ensures that the node can complete the security verification of the UE; secondly, the method only has one Attach or TAU process, which can reduce the signaling interaction, reduce the processing delay and the processing load of the node; the method does not need to redesign the function of the node, which reduces the cost; at the same time, the interaction between the dedicated core networks is avoided, and the mutual isolation of the dedicated core networks is ensured.
[0143] Figure 5is a flow chart of an access method provided by an embodiment of the present application. In this embodiment, the UE accesses a dedicated core network (referred to as a network) for the first time, and the node of the dedicated core network is taken as an example of a control plane device to describe the access method provided by the SFE and the RAN Node. Figure 3 and Figure 4 The access method performed by the SFE and the RAN Node is described in detail. As shown in Figure 5 , the method comprises the following steps.
[0144] Step 401: The UE sends an initial attach request (Initial Attach Request) to the RAN Node. The Initial Attach Request is an attach request sent by the UE when accessing the network for the first time.
[0145] Since the UE accesses the network for the first time, the UE has not accessed the corresponding network, and the UE has not been allocated a control plane device identifier (such as a Globally Unique MME Identity (GUMMEI) or a Packet Temporary Mobile Subs cription Identity (P-TMSI)).
[0146] Specifically, the UE sends the Initial Attach Request to the RAN Node, which comprises:
[0147] The UE sends the Initial Attach Request to the RAN Node through an RRC message. The RRC message is a message sent to the RAN Node in the process of establishing an RRC connection between the UE and the RAN Node.
[0148] Step 402: The RAN Node sends the Initial Attach Request to the SFE; and the SFE receives the Initial Attach Request of the UE sent by the RAN Node.
[0149] The SFE is a newly added logical network element of the present application, and the RAN Node stores relevant information of the SFE, such as address information.
[0150] The RAN Node sends the Initial Attach Request to the SFE, which can comprise:
[0151] The RAN Node establishes an S1-Application Protocol (AP) connection with the SFE; and sends the Initial Attach Request to the SFE through the S1-AP connection.
[0152] Further, since the RAN Node does not know whether the UE is first access or not, before the RAN Node sends the Initial Attach Request to the SFE, the method further comprises:
[0153] the RAN Node judges whether the control plane device identifier (such as the Global Unique MME Identity (GUMMEI) or the Packet Temporary Mobile Subscriber Identity (P-TMSI)) of the original network of the UE is included in the RRC message; since the UE is first access, the control plane device identifier of the original network of the UE is not included in the RRC message (i.e. the RAN Node does not obtain the control plane device identifier of the original network of the UE), therefore, the RAN Node sends the Initial Attach Request to the SFE.
[0154] After the SFE receives the Initial Attach Request, step 403a is performed, if step 403a fails, steps S403b-S403d are performed, of course, the SFE can not perform step 403a, and directly perform steps S403b-S403d. Steps 403a and S403b-S403d are used to determine the Usage Type of the UE.
[0155] Step 403a: the SFE directly obtains the Usage Type of the UE from the Initial Attach Request.
[0156] In the present application, the Usage Type can be an optional field of the Initial Attach Request.
[0157] Step 403b: the SFE obtains the ID of the UE from the Initial Attach Request.
[0158] Wherein, the Initial Attach Request includes the ID of the UE.
[0159] Step 403c: the SFE sends a Subscriber Data Request to the HSS, the Subscriber Data Request includes the ID of the UE, and the Subscriber Data Request is used to request the Subscriber Data of the UE.
[0160] Step 403d: The SFE receives the Subscriber Data of the UE returned by the HSS, and acquires the Usage Type of the UE from the Subscriber Data of the UE, wherein the Subscriber Data of the UE includes the Usage Type of the UE.
[0161] Specifically, the SFE receives a Subscriber Data Response returned by the HSS, wherein the Subscriber Data Response includes the Subscriber Data of the UE.
[0162] Step 404: The SFE selects a control plane device for the UE according to the Usage Type of the UE.
[0163] Specifically, since different types of UEs have corresponding relationships with networks, the SFE can store the corresponding relationship between the Usage Type and the control plane device in advance, and after acquiring the Usage Type of the UE, the SFE selects the control plane device corresponding to the Usage Type of the UE according to the corresponding relationship between the Usage Type and the control plane device and the Usage Type of the UE.
[0164] The corresponding relationship between the Usage Type and the control plane device can be set as follows: a mobile broadband user corresponds to a control plane device of a mobile broadband network; a machine type communication user corresponds to a control plane device of a machine type communication network; and an inter-vehicle communication user corresponds to a control plane device of an inter-vehicle communication network. Of course, the above corresponding relationship is only an example, and the embodiments of the present application are not limited thereto.
[0165] It should be understood that the SFE selects a node of a dedicated core network capable of serving the UE for the UE according to the usage type of the UE, which can include:
[0166] directly selecting a node of a dedicated core network capable of serving the UE for the UE according to the usage type of the UE; or
[0167] selecting a node of a dedicated core network capable of serving the UE for the UE according to other information in the subscription data of the UE except the usage type of the UE and / or a local policy pre-configured on the SFE and the usage type of the UE.
[0168] The other information in the subscription data of the UE except the usage type of the UE includes but is not limited to a roaming agreement; and the local policy pre-configured on the SFE includes but is not limited to a network congestion state, a local network deployment, etc.
[0169] In an implementation, the selecting the node of the dedicated core network capable of serving the UE according to the information other than the Usage Type of the UE in the subscription data of the UE and / or the local policy pre-configured on the SFE and the Usage Type of the UE can comprise:
[0170] The SFE selects the control plane device for the UE according to the Usage Type of the UE, and determines the control plane device as the control plane device capable of serving the UE when the selected control plane device meets the requirements of the information other than the Usage Type of the UE in the subscription data of the UE and / or the local policy pre-configured on the SFE, otherwise, selects another control plane device as the control plane device capable of serving the UE.
[0171] The meeting the requirements of the information other than the Usage Type of the UE in the subscription data of the UE and / or the local policy pre-configured on the SFE can comprise: matching the information other than the Usage Type of the UE in the subscription data of the UE (such as the roaming agreement), meeting the policy in the local policy (such as the network congestion state).
[0172] For example, the SFE can refer to the roaming agreement of the UE in the subscription data when selecting the control plane device for the UE according to the Usage Type of the UE, and if the UE does not open the roaming service and the control plane device selected according to the Usage Type of the UE is located in the roaming area, the control plane device cannot be the control plane device capable of serving the UE.
[0173] For another example, the SFE can refer to the local congestion state on the SFE when selecting the control plane device for the UE according to the Usage Type of the UE, and if the network congestion of the control plane device selected according to the Usage Type of the UE is greater than a preset value, the control plane device cannot be the control plane device capable of serving the UE.
[0174] The above steps 403a, 403b-403d and 404 are used for selecting the control plane device for the UE.
[0175] Step 405: The SFE sends a redirection message (Redirection Message) to the RAN Node, and the Redirection Message comprises the information of the control plane device corresponding to the Usage Type of the UE; the RAN Node receives the Redirection Message returned by the SFE.
[0176] The information of the control plane device can comprise the identifier or IP address of the control plane device.
[0177] Step 406: The RAN Node sends the Initial Attach Request of the UE to the control plane device.
[0178] The sending of the Initial Attach Request of the UE to the control plane device by the RAN Node can include:
[0179] The RAN Node control plane device establishes an S1 connection, and sends the Initial Attach Request of the UE to the control plane device through the S1 connection.
[0180] After step 406, the UE, the RAN Node and the control plane device complete the Attach procedure in a normal manner, that is, the network access of the UE is realized.
[0181] In the embodiment of the present application, when the RAN Node receives the Initial Attach Request sent by the UE, the RAN Node directly sends the Initial Attach Request to the SFE, then receives the redirection message returned by the SFE, the redirection message including the information of the control plane device (such as MME) selected by the SFE for the UE according to the Usage Type of the UE, and then sends the Initial Attach Request of the UE to the control plane device to complete the subsequent access procedure; the method selects the control plane device for the UE according to the Usage Type of the UE through the SFE, and then makes the UE access the network in which the control plane device is located, that is, the control plane device accessed by the UE is the control plane device of the network corresponding to the UE, which ensures that the control plane device can complete the security verification of the UE; secondly, the method only has one Attach or TAU procedure, which can reduce the signaling interaction, and reduce the processing delay and the processing load of the control plane device; the method does not need to redesign the function of the control plane device; and the interaction between networks is avoided, which ensures the mutual isolation of the networks.
[0182] Figure 6 is a flowchart of an access method provided by the embodiment of the present application. In the embodiment, the UE is taken as an example of moving from a home place to a visited place, and the access method performed by the SFE and the RAN Node provided by the present application is described in detail. Figure 3 and Figure 4 The access method performed by the SFE and the RAN Node provided by the present application is described in detail. As shown in the figure, the method includes the following steps. Figure 6
[0183] Step 501: The UE sends an Attach Request or a TAU Request to the RAN Node.
[0184] Specifically, the sending of the Attach Request or the TAU Request by the UE to the RAN Node includes:
[0185] The UE sends an Attach Request or a TAU Request to the RAN Node through an RRC message. The RRC message is a message sent to the RAN Node in the process of establishing an RRC connection between the UE and the RAN Node.
[0186] The UE has registered in a home location and obtained a temporary identifier allocated by a home network, and the temporary identifier includes a control plane device identifier. When the UE applies for an Attach or a TAU in a visited location, the UE carries the control plane device identifier in an RRC message and transmits the control plane device identifier to the RAN Node (the visited location).
[0187] Step 502: The RAN Node sends an Attach Request or a TAU Request to the SFE; and the SFE receives the Attach Request or the TAU Request of the UE sent by the RAN Node.
[0188] The SFE is a newly added logical network element of the present application, and the RAN Node stores relevant information of the SFE, such as address information.
[0189] The RAN Node sending the Attach Request or the TAU Request to the SFE can include the following steps:
[0190] The RAN Node establishes an S1-AP connection with the SFE, and sends the Attach Request or the TAU Request to the SFE through the S1-AP connection.
[0191] Further, before the RAN Node sends the Attach Request or the TAU Request to the SFE, the method further includes the following steps:
[0192] The RAN Node determines whether the RRC message includes a control plane device identifier of an original network of the UE; when the RRC message includes the control plane device identifier of the original network of the UE, it is determined whether the control plane device of the original network of the UE is reachable; since the control plane device of the original network of the UE is a control plane device of a home location of the UE, the RAN Node in the visited location determines that the control plane device is not reachable, and the RAN Node sends the Attach Request or the TAU Request to the SFE.
[0193] Specifically, the determination of whether the control plane device of the original network of the UE is reachable includes the following steps:
[0194] A preconfigured table of accessible node identifiers;
[0195] According to the node identification table, it is determined that the control plane device identifier of the original network is not in the node identification table, and the control plane device of the original network is unreachable.
[0196] After the SFE receives the Attach Request or the TAU Request, step 503a is performed, if step 503a fails, steps S503b-S503j are performed, of course, the SFE can not perform step 503a, and directly perform steps S503b-S503j. Steps 503a and S503b-S503j are used to determine the Usage Type of the UE.
[0197] Step 503a: The SFE directly obtains the Usage Type of the UE from the Attach Request or the TAU Request.
[0198] In the present application, the Usage Type can be an optional field of the Attach Request or the TAU Request.
[0199] Step 503b: The SFE obtains the temporary identifier of the UE from the Attach Request or the TAU Request.
[0200] The Attach Request or the TAU Request includes the temporary identifier of the UE, and the temporary identifier of the UE includes the control plane device identifier of the original network of the UE.
[0201] Step 503c: The SFE sends a context request (Context Request) to the control plane device (home control plane device) of the original network of the UE, the Context Request includes the temporary identifier of the UE, and the Context Request is used to request the context (Context) of the UE. The SFE can obtain the control plane device of the original network of the UE according to the temporary identifier of the UE. When the SFE receives the Context of the UE returned by the control plane device of the original network, steps 503d-503e are performed; otherwise, steps 503g-503j are performed.
[0202] Specifically, the SFE receives a context response (Context Response) returned by the control plane device of the original network, and the Context Response can include the Context of the UE.
[0203] If the control plane device of the original network has deleted the Context of the UE, the SFE will not receive the Context of the UE returned by the control plane device of the original network.
[0204] Step 503d: judging whether the UE's Usage Type is included in the UE's Context. When the UE's Usage Type is included in the UE's Context, step 503e is performed; otherwise, step 503f is performed.
[0205] Step 503e: obtaining the UE's Usage Type from the UE's Context, wherein the UE's Context includes the UE's Usage Type.
[0206] Step 503f: obtaining the UE's ID from the UE's Context, wherein the UE's Context includes the UE's ID, and then performing steps 503i-503j.
[0207] Step 503g: the SFE sends an Identity Request to the UE.
[0208] Step 503h: the SFE receives the UE's ID returned by the UE.
[0209] In particular, an Identity Response is received, wherein the Identity Response includes the UE's ID.
[0210] Step 503i: the SFE sends a Subscriber Data Request to the HSS, wherein the Subscriber Data Request includes the UE's ID, and the Subscriber Data Request is used to request the UE's Subscriber Data.
[0211] Step 503j: the SFE receives the UE's Subscriber Data returned by the HSS, and obtains the UE's Usage Type from the UE's Subscriber Data, wherein the UE's Subscriber Data includes the UE's Usage Type.
[0212] In particular, a Subscriber Data Response is received, wherein the Subscriber Data Response includes the UE's Subscriber Data.
[0213] Step 504: the SFE selects a control plane device (a control plane device in a roaming area) for the UE according to the UE's Usage Type.
[0214] The specific process of step 504 is the same as that of step 404.
[0215] Step 505: The SFE sends a Redirection Message to the RAN Node, the Redirection Message including the information of the control plane device corresponding to the Usage Type of the UE; the RAN Node receives the Redirection Message returned by the SFE.
[0216] The specific process of step 505 is the same as that of step 405.
[0217] Step 506: The RAN Node sends the Attach Request or TAU Request of the UE to the control plane device.
[0218] The specific process of step 506 is the same as that of step 406.
[0219] In the embodiment of the present application, when the RAN Node receives the access request sent by the UE, if the control plane device of the original network of the UE is unreachable, the RAN Node directly sends the access request to the SFE, then receives the Redirection Message returned by the SFE, the Redirection Message including the information of the control plane device (such as MME) selected by the SFE for the UE according to the Usage Type of the UE, and then sends the access request of the UE to the control plane device, so as to complete the subsequent access process; the method selects the control plane device for the UE according to the Usage Type of the UE through the SFE, and then makes the UE access the network in which the control plane device is located, that is, the control plane device accessed by the UE is the control plane device of the network corresponding to the UE, so that the control plane device can complete the security verification of the UE; secondly, the method only has one Attach or TAU process, which can reduce the signaling interaction, and reduce the processing delay and the processing load of the control plane device; the method does not need to redesign the function of the control plane device; and the interaction between networks is avoided, so that the mutual isolation of the networks is ensured.
[0220] Figure 7 is a flowchart of an access method provided by the embodiment of the present application. In the embodiment, the present application is described in detail by taking the first access of the UE to the network as an example. As shown in Figure 7 , in the flowchart shown in the figure, the flow of the UE interacting with the SFE and the SFE selecting the control plane device for the UE is the same as that of Figure 5 (ie, steps 601-604 are the same as steps 401-404 in Figure 5 , Figure 7 and Figure 5 The difference mainly lies in the subsequent process (steps 605, 606), and the method includes the following steps.
[0221] Step 601: UE sends Initial Attach Request to RAN Node, Initial Attach Request is the attach request sent by UE when accessing network for the first time.
[0222] Step 602: RAN Node sends Initial Attach Request to SFE; SFE receives Initial Attach Request of UE sent by RAN Node.
[0223] After SFE receives Initial Attach Request, step 603a is performed, if step 603a fails, steps S603b-S603d are performed, of course, SFE can not perform step 603a, and directly perform steps S603b-S603d. Steps 603a and steps S603b-S603d are used to determine the Usage Type of UE.
[0224] Step 603a: SFE directly obtains the Usage Type of UE from Initial Attach Request.
[0225] Step 603b: SFE obtains the ID of UE from Initial Attach Request.
[0226] Step 603c: SFE sends Subscriber Data Request to HSS, Subscriber Data Request includes the ID of UE, and Subscriber Data Request is used to request the Subscriber Data of UE.
[0227] Step 603d: SFE receives the Subscriber Data of UE returned by HSS, and obtains the Usage Type of UE from the Subscriber Data of UE, the Subscriber Data of UE includes the Usage Type of UE.
[0228] Step 604: SFE selects the control plane device for UE according to the Usage Type of UE.
[0229] The above steps 603a, steps S603b-S603d and step 604 are used to select the control plane device for UE.
[0230] Step 605: The SFE sends the Initial Attach Request of the UE to the control plane device.
[0231] Wherein, after selecting the control plane device for the UE, the SFE can find the information of the control plane device, and then send the Initial Attach Request of the UE to the control plane device. The information of the control plane device can include the identification or IP address of the control plane device.
[0232] Wherein, step 605 can include: establishing S1 connection with the control plane device, and sending the Initial Attach Request to the control plane device through the S1 connection.
[0233] Step 606: The SFE forwards the messages between the control plane device and the RAN Node as a forwarding node between the control plane device and the RAN Node, so as to complete the access procedure.
[0234] Specifically, the SFE receives the messages sent by the control plane device or the RAN Node, and forwards the messages sent by the control plane device or the RAN Node to the RAN Node or the control plane device.
[0235] Specifically, the process of the SFE forwarding the messages includes: buffering the messages, and forwarding the messages to the RAN Node or the control plane device after completing the routing modification of the messages.
[0236] Wherein, the above-mentioned messages include security verification messages, Accept messages, etc. In the transmission process of the above-mentioned messages, the control plane device transmits the temporary identification (GUTI) allocated to the UE to the UE through the messages.
[0237] Specifically, the control plane device can carry the temporary identification (GUTI) allocated to the UE in the non-access layer acceptance message (NAS Accept message), and transmit the temporary identification (GUTI) to the RAN Node through the SFE, and then the RAN Node forwards the temporary identification (GUTI) to the UE. The temporary identification (GUTI) contains the identification of the control plane device. The UE carries the identification of the control plane device in the subsequent service request message, and the RAN Node can directly transmit the service request message of the UE to the control plane device according to the identification of the control plane device.
[0238] After step 606, the UE, the RAN Node and the control plane device perform subsequent interaction in a normal manner, that is, after completing the access, the RAN Node can directly interact with the control plane device according to the temporary identification, so as to realize the message forwarding between the UE and the control plane device, without the need of forwarding through the SFE.
[0239] In the embodiment of the present application, the RAN Node directly sends the initial attachment request to the SFE when receiving the initial attachment request sent by the UE, the SFE selects the control plane device (such as MME) for the UE according to the Usage Type of the UE, and then sends the initial attachment request of the UE to the control plane device to complete the subsequent access process; the method selects the control plane device for the UE according to the Usage Type of the UE through the SFE, and then makes the UE access the network in which the control plane device is located, that is, the control plane device accessed by the UE is the control plane device of the network corresponding to the UE, which ensures that the control plane device can complete the security verification of the UE; secondly, the method has only one Attach or TAU process, which can reduce the signaling interaction, reduce the processing delay and the processing load of the control plane device; the method does not need to redesign the function of the control plane device; at the same time, the interaction between networks is avoided, and the mutual isolation of the networks is ensured.
[0240] Figure 8 is a flowchart of an access method provided by the embodiment of the present application. In the embodiment, the present application is described in detail by taking the case that the UE moves from the home place to the visited place. As shown in Figure 8 , in the flowchart shown in the figure, the UE interacts with the SFE, and the process of selecting the control plane device for the UE by the SFE is the same as that in Figure 6 (i.e., steps 501-504 in Figure 6 are the same as steps 501-504 in Figure 8 , and the difference between Figure 6 mainly lies in the subsequent process (steps 705 and 706). The method comprises the following steps.
[0241] Step 701: The UE sends the Attach Request or TAU Request to the RAN Node.
[0242] Step 702: The RAN Node sends the Attach Request or TAU Request to the SFE; the SFE receives the Attach Request or TAU Request of the UE sent by the RAN Node.
[0243] After the SFE receives the Attach Request or TAU Request, step 703a is performed, if step 703a fails, steps S703b-703j are performed, of course, the SFE can not perform step 703a, but directly perform steps 703b-703j. Steps 703a and 703b-703j are used to determine the Usage Type of the UE.
[0244] Step 703a: SFE obtains the Usage Type of the UE directly from the Attach Request or TAU Request.
[0245] Step 703b: SFE obtains the temporary identity of the UE from the Attach Request or TAU Request.
[0246] Step 703c: SFE sends a Context Request to the control plane device (home control plane device) of the original network of the UE, the Context Request including the temporary identity of the UE, the Context Request being used to request the context of the UE. When SFE receives the context of the UE returned by the control plane device of the original network, steps 703d-703e are performed; otherwise, steps 703g-703j are performed.
[0247] Step 703d: it is judged whether the context of the UE includes the Usage Type of the UE. When the context of the UE includes the Usage Type of the UE, step 703e is performed; otherwise, step 703f is performed.
[0248] Step 703e: the Usage Type of the UE is obtained from the context of the UE, the context of the UE including the Usage Type of the UE.
[0249] Step 703f: the ID of the UE is obtained from the context of the UE, the context of the UE including the ID of the UE, and then steps 703i-703j are performed.
[0250] Step 703g: SFE sends an Identity Request to the UE.
[0251] Step 703h: SFE receives the ID of the UE returned by the UE.
[0252] Step 703i: SFE sends a Subscriber Data Request to the HSS, the Subscriber Data Request including the ID of the UE, the Subscriber Data Request being used to request the subscriber data of the UE.
[0253] Step 703j: The SFE receives the Subscriber Data of the UE returned by the HSS, and acquires the Usage Type of the UE from the Subscriber Data of the UE, wherein the Subscriber Data of the UE comprises the Usage Type of the UE.
[0254] Step 704: The SFE selects a control plane device (a control plane device in a roaming place) for the UE according to the Usage Type of the UE.
[0255] Step 705: The SFE sends the Initial Attach Request of the UE to the control plane device.
[0256] The specific process of step 705 is the same as that of step 605.
[0257] Step 706: The SFE forwards messages between the control plane device and the RAN Node as a forwarding node between the control plane device and the RAN Node, thereby completing the access process.
[0258] The specific process of step 706 is the same as that of step 606.
[0259] In the embodiment of the present application, when the RAN Node receives the access request sent by the UE, if the control plane device of the original network of the UE is unreachable, the RAN Node directly sends the access request to the SFE, the SFE selects a control plane device (such as an MME) for the UE according to the Usage Type of the UE, and then sends the access request of the UE to the control plane device, so as to complete the subsequent access process; the method selects a control plane device for the UE according to the Usage Type of the UE through the SFE, and then makes the UE access the network in which the control plane device is located, that is, the control plane device accessed by the UE is the control plane device of the network corresponding to the UE, which ensures that the control plane device can complete the security verification of the UE; secondly, the method only has one Attach or TAU process, which can reduce the signaling interaction, and reduce the processing delay and the processing load of the control plane device; the method does not need to redesign the function of the control plane device; and meanwhile, the interaction between networks is avoided, and the mutual isolation of the networks is ensured.
[0260] Figure 9 is a block diagram of an access device provided by the embodiment of the present application. The access device can be realized by software, hardware or a combination of both to become all or part of the SFE, and the access device can realize the steps performed by the SFE in the access method provided in any one of the foregoing Figure 3 or Figures 5 to 8 The access device can comprise a receiving unit 801 and a processing unit 802.
[0261] The receiving unit 801 is configured to receive an access request of a user equipment (UE) sent by a radio access network (RAN) node.
[0262] The processing unit 802 is configured to determine a use type of the UE according to the access request of the UE, and select a node of a dedicated core network capable of serving the UE according to the use type of the UE, so as to send the access request to the node, the node of the dedicated core network corresponding to the use type of the UE.
[0263] In the embodiment of the present application, when the SFE receives the access request of the UE, the SFE determines the use type of the UE according to the access request of the UE, and selects a corresponding node of a dedicated core network for the UE according to the use type of the UE, so as to send the access request to the node, and complete a subsequent access process; therefore, the node accessed by the UE is the node of the dedicated core network corresponding to the UE, which ensures that the node can complete the security verification for the UE; secondly, the method only has one Attach or TAU process, which can reduce signaling interaction, and reduce processing delay and processing load of the node; the method does not need to redesign the function of the node; and meanwhile, the method avoids interaction between the dedicated core networks, and ensures mutual isolation of the dedicated core networks.
[0264] In the embodiment of the present application, the access request includes a non-access stratum (NAS) request message, and the NAS request message is an attach request message or a tracking area update (TAU) request message.
[0265] In a possible implementation, the processing unit 802 is configured to:
[0266] The use type of the UE is directly obtained from the access request.
[0267] In another possible implementation, the processing unit 802 is configured to:
[0268] The ID of the UE is obtained.
[0269] The processing unit 802 is configured to send a subscription data request to a home subscriber server (HSS), the subscription data request including the ID of the UE, and the subscription data request being used to request subscription data of the UE.
[0270] The processing unit 802 is configured to receive the subscription data of the UE returned by the HSS, the subscription data of the UE including the use type of the UE.
[0271] The use type of the UE is obtained from the subscription data of the UE.
[0272] Further, the processing unit 802 is configured to:
[0273] The ID of the UE is obtained from the access request.
[0274] Alternatively, the processing unit 802 is configured to:
[0275] sending an ID request to the UE, the ID request being used to request an ID of the UE;
[0276] receiving the ID of the UE returned by the UE;
[0277] Alternatively, the processing unit 802 is configured to:
[0278] obtaining a temporary ID of the UE in the access request, the temporary ID of the UE being allocated by a node in an original network where the UE is located;
[0279] sending a context request to the node in the original network, the context request including the temporary ID of the UE, the context request being used to request a context of the UE;
[0280] receiving the context of the UE returned by the node in the original network, and obtaining the ID of the UE from the context of the UE.
[0281] In another possible implementation, the processing unit 802 is configured to:
[0282] obtaining a temporary ID of the UE in the access request, the temporary ID of the UE being allocated by a node in an original network where the UE is located;
[0283] sending a context request to the node in the original network, the context request including the temporary ID of the UE, the context request being used to request a context of the UE;
[0284] receiving the context of the UE returned by the node in the original network, and obtaining the usage type of the UE from the context of the UE.
[0285] In a possible implementation, the apparatus further includes a sending unit 803 configured to send a redirection message to the RAN Node, the redirection message including information of a node of a corresponding dedicated core network selected by the SFE for the UE, so that the RAN Node sends the access request to the node of the corresponding dedicated core network of the UE.
[0286] In another possible implementation, the apparatus further includes a sending unit 803 configured to send the access request directly to the node of the corresponding dedicated core network of the UE.
[0287] Further, the sending unit 803 is configured to:
[0288] establishing an S1 connection with the node of the corresponding dedicated core network of the UE;
[0289] sending the access request to the node of the corresponding dedicated core network of the UE through the S1 connection.
[0290] Further, the sending unit 803 is further configured to, as a forwarding node between the node of the dedicated core network corresponding to the UE and the RAN Node, forward a message between the node of the dedicated core network corresponding to the UE and the RAN Node.
[0291] Further, the receiving unit 801 is further configured to receive a message sent by the node of the dedicated core network corresponding to the UE.
[0292] The sending unit 803 is configured to forward the message to the RAN Node.
[0293] Alternatively, the receiving unit is further configured to receive a message sent by the RAN Node.
[0294] The sending unit 803 is configured to forward the message to the node of the dedicated core network corresponding to the UE.
[0295] Figure 10 is a block diagram of an access device provided by an embodiment of the present application. The access device can be realized by software, hardware or combination of both to be all or part of the RAN Node, and the access device can implement steps performed by the RAN Node in the access method provided by any one of the preceding Figures 4 to 8 The access device can include a receiving unit 901, a processing unit 902 and a sending unit 902.
[0296] The receiving unit 901 is configured to receive an access request sent by a user equipment (UE).
[0297] The processing unit 902 is configured to determine that the node of the original dedicated core network is unreachable when the node identifier of the original dedicated core network of the UE is not obtained from the access request, or when the node identifier of the original dedicated core network carried in the access request is not in the preconfigured node identifier list.
[0298] The sending unit 903 is configured to send the access request to a selection function entity (SFE).
[0299] Optionally, the receiving unit 901 is further configured to receive the node of the dedicated core network corresponding to the UE determined by the SFE, and the node of the dedicated core network corresponding to the UE is a node of the dedicated core network capable of serving the UE selected by the SFE for the UE according to a usage type of the UE.
[0300] The sending unit 903 is further configured to send the access request of the UE to the node of the dedicated core network corresponding to the UE.
[0301] In this embodiment of the invention, when the RAN Node receives an access request from the UE, it determines the node of the dedicated core network corresponding to the UE by selecting the functional entity SFE, and sends the UE's access request to the node of the dedicated core network corresponding to the UE to complete the subsequent access process. The node to which the UE accesses is the node of the dedicated core network corresponding to the UE, ensuring that the node can complete the security verification of the UE. Secondly, this method only has one Attach or TAU process, which can reduce signaling interaction, reduce processing latency and node processing load. This method does not require redesigning the functions of the node, reducing costs. At the same time, it avoids interaction between dedicated core networks, ensuring the mutual isolation of dedicated core networks.
[0302] The receiving unit 901 is used for:
[0303] When the node identifier of the UE's original network is not obtained or the node of the UE's original network is unreachable, the node of the dedicated core network corresponding to the UE is determined by the Receive Selection Function Entity (SFE).
[0304] The receiving unit 901 is used to receive the redirection message returned by the SFE. The redirection message includes information about the node of the dedicated core network corresponding to the UE.
[0305] The node identifier of the UE's original dedicated core network is either the Mobility Management Entity Global Identifier (GUMMEI) or the Packet Temporary Mobile Subscriber Identity (P-TMSI).
[0306] The access request includes a non-access stratum NAS request message, which is either an attach request message or a tracking area update TAU request message.
[0307] The transmitting unit 903 is used for:
[0308] The access request is sent to the SFE so that the access request can be sent directly to the node of the dedicated core network corresponding to the UE through the SFE.
[0309] Furthermore, the transmitting unit 903 is used for:
[0310] Establish an S1-application protocol AP connection with the SFE;
[0311] The access request is sent to the SFE via the S1-AP connection.
[0312] In this embodiment of the invention, the sending unit 903 is further configured to use the SFE as a forwarding node between the node of the dedicated core network corresponding to the UE and the RAN Node, and send messages to the node of the dedicated core network corresponding to the UE.
[0313] The receiving unit 901 is further configured to receive a message sent by a node of a dedicated core network corresponding to the UE, as a forwarding node between the node of the dedicated core network corresponding to the UE and the RAN Node.
[0314] In the embodiment of the present application, the receiving unit 901 is configured to:
[0315] receive an access request sent by the UE through a radio resource control (RRC) message.
[0316] Further, the apparatus further comprises:
[0317] The judging unit 904 is configured to judge whether a node identifier of an original network of the UE is carried in the RRC message.
[0318] When the node identifier of the original network of the UE is carried in the access request, judge whether the node of the original network of the UE is reachable.
[0319] Figure 11 is a block diagram of an access system provided by an embodiment of the present application, referring to Figure 11 The system comprises an SFE 1101 and a RAN Node 1102.
[0320] The SFE 1101 is configured to receive an access request of a user equipment (UE) sent by a radio access network (RAN) node; determine a use type of the UE according to the access request of the UE; select a node of a dedicated core network capable of serving the UE for the UE according to the use type of the UE, the node of the dedicated core network capable of serving the UE corresponding to the use type of the UE.
[0321] The RAN Node 1102 is configured to receive an access request sent by a user equipment (UE); when a node identifier of an original dedicated core network of the UE is not obtained from the access request, or when the node identifier of the original dedicated core network carried in the access request is not in a preconfigured node identifier table, determine that the node of the original dedicated core network is unreachable; and send the access request to a selection function entity (SFE).
[0322] The SFE 1101 can implement the steps performed by the SFE in the access method provided by any one of the preceding Figure 3 or Figures 5 to 8 The RAN Node 1102 can implement the steps performed by the RAN Node in the access method provided by any one of the preceding Figures 4 to 8
[0323] It should be noted that the access device provided in the above examples is only exemplified by the division of the above functional units when the UE accesses, and in actual application, the above functions can be completed by different functional units according to needs, that is, the internal structure of the device is divided into different functional units to complete all or part of the functions described above. In addition, the access device and the access method provided in the above examples belong to the same concept, and the specific implementation process is detailed in the method examples, which will not be repeated here.
[0324] A person of ordinary skill in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by program to instruct relevant hardware, and the program can be stored in a computer readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk.
[0325] The above only describes the preferred embodiments of the present application, but the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An access method, characterized by, The method is applied to a dedicated core network, and the method comprises: A radio access network node RAN Node receives an access request sent by a user equipment UE; When a node identifier of an original dedicated core network of the UE is not obtained from the access request, or when a node identifier of the original dedicated core network carried in the access request is not in a preconfigured node identifier list, the RAN Node determines that the node of the original dedicated core network is unreachable; The RAN Node sends the access request to a selection function entity SFE.
2. The method of claim 1, wherein, The method further comprises: The RAN Node receives a node of a dedicated core network corresponding to the UE determined by the SFE, wherein the node of the dedicated core network corresponding to the UE is a node of a dedicated core network capable of serving the UE selected by the SFE according to a use type of the UE; The access request of the UE is sent to the node of the dedicated core network corresponding to the UE.
3. The method according to claim 1 or 2, characterized in that, The sending of the access request to the SFE comprises: The access request is sent to the SFE, so that the SFE directly sends the access request to the node of the dedicated core network corresponding to the UE.
4. The method according to claim 1 or 2, characterized in that, After the access request is sent to the SFE, the method further comprises: The SFE is used as a forwarding node between the node of the dedicated core network corresponding to the UE and the RAN Node, and a message is sent to the node of the dedicated core network corresponding to the UE or a message sent by the node of the dedicated core network corresponding to the UE is received.
5. An access device, characterized in that The apparatus is applied to a radio access network node RAN Node in a dedicated core network, and the apparatus comprises: A receiving unit is configured to receive an access request sent by a user equipment UE; A processing unit is configured to determine that a node of an original dedicated core network is unreachable when a node identifier of the original dedicated core network of the UE is not obtained from the access request, or when a node identifier of the original dedicated core network carried in the access request is not in a preconfigured node identifier list; A sending unit is configured to send the access request to a selection function entity SFE.
6. The apparatus of claim 5, wherein, The receiving unit is further configured to receive a node of a dedicated core network corresponding to the UE determined by the SFE, wherein the node of the dedicated core network corresponding to the UE is a node of a dedicated core network capable of serving the UE selected by the SFE according to a use type of the UE; The sending unit is further configured to send the access request of the UE to the node of the dedicated core network corresponding to the UE.
7. The apparatus of claim 5 or 6, wherein, The sending unit is configured to: The access request is sent to the SFE, so that the SFE directly sends the access request to the node of the dedicated core network corresponding to the UE.
8. The apparatus of claim 5 or 6, wherein, The sending unit is further configured to send a message to the node of the dedicated core network corresponding to the UE with the SFE as a forwarding node between the node of the dedicated core network corresponding to the UE and the RAN Node; The receiving unit is further configured to receive a message sent by the node of the dedicated core network corresponding to the UE with the SFE as the forwarding node between the node of the dedicated core network corresponding to the UE and the RAN Node.
9. An access device, characterized in that The application is applied to a special core network, and the access device comprises a processor, a memory and a communication interface; the memory is used for storing software programs and modules, and the processor realizes the following functions by running or executing the software programs and / or modules stored in the memory: receiving an access request sent by a user equipment (UE); when the node identifier of the original special core network of the UE is not obtained from the access request, or when the node identifier of the original special core network carried in the access request is not in a preconfigured node identifier table, determining that the node of the original special core network is unreachable; sending the access request to a selection function entity (SFE).
10. A computer-readable storage medium, characterized in that, program code for storing by a processor, the program code comprising instructions for implementing the method of any one of claims 1 to 4.
Citation Information
Patent Citations
Methods and mobility management entity, MME, for re-directing a UE to a dedicated core network node
WO2015172088A1