Connection establishment method, apparatus, related equipment and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-22
- Publication Date
- 2026-08-14
AI Technical Summary
[0005]然而,上述5G与MEC结合的方案无法满足MEP之间相互连接的需求
其中,所述第二处理器用于运行所述计算机程序时,执行核心网设备侧任一项所述方法的步骤。
Smart Images

Figure CN116347658B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly to a connection establishment method, apparatus, related equipment, and storage medium. Background Technology As a new generation of communication technology, fifth-generation mobile communication technology (5G) has many advantages such as large bandwidth, low latency, high reliability, high connectivity, and ubiquitous network, thereby promoting the rapid development and transformation of vertical industries, such as the rise of smart healthcare, smart education, and smart agriculture.
[0002] Mobile Edge Computing (MEC), as one of the key technologies for 5G evolution, is a general-purpose information technology (IT) platform with wireless network information application programming interface (API) interaction capabilities, as well as computing, storage, and analysis functions. Relying on MEC technology, traditional external applications can be brought into the operator's internal system to provide users with localized application services, bringing them closer to users, thereby improving user experience and maximizing the value of edge networks.
[0003] By combining 5G and MEC technologies, different technology combinations can be introduced to meet the needs of different industries and scenarios, such as Quality of Service (QoS), end-to-end network slicing, network capability openness, and edge cloud, thereby providing customized solutions.
[0004] In related technologies, such as Figure 1 As shown, the main solutions combining 5G and MEC technologies include: 1) To enable low-latency, high-bandwidth, and high-reliability edge applications in vertical industries, the User Plane Function (UPF) is deployed to the industry customer campus, close to the MEC edge server (also known as the Mobile Edge Computing Platform (MEP)). Data is forwarded to the MEP through the UPF's local traffic offloading technology (i.e., uplink filter / IPv6 branching point (UL-CL / IPv6 BP)). 2) Application functions (AFs) in the core network are moved down to the MEP side to provide better data flow control strategies (such as coding strategies, QoS strategies, routing strategies, etc.) for applications deployed on the MEP.
[0005] However, the above-mentioned 5G and MEC combination solution cannot meet the needs of interconnection between MEPs. Summary of the Invention
[0006] To address the related technical problems, embodiments of this application provide a connection establishment method, apparatus, related devices, and storage medium.
[0007] The technical solution of this application embodiment is implemented as follows: This application provides a connection establishment method, applied to a first device, including: The device receives a first request from a first platform; the first request is used to request the establishment of a channel with a second platform; the first device connects to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; Based on the first request, a second request is sent to the core network, the second request being used to request the establishment of a channel between the first platform and the second platform; Establish a secure channel with the first UPF.
[0008] In the above scheme, the first request carries at least one of the following information: Information related to the first platform; Information related to the second platform; Information related to data transmission between the first platform and the second platform.
[0009] In the above scheme, the relevant information of the first platform includes at least one of the following: The geographical location information of the first platform; The data network name (DNN) of the first platform.
[0010] In the above scheme, the relevant information of the second platform includes at least one of the following: The geographical location information of the second platform; The second platform's DNN.
[0011] In the above scheme, the data transmission information between the first platform and the second platform includes at least one of the following: The network slice identifier required to establish a channel between the first platform and the second platform; QoS information between the first platform and the second platform.
[0012] In the above scheme, the second request carries at least the following information: The information carried in the first request; Address information of the first device; Address information of the second device; The identity authentication information of the first device.
[0013] The method in the above scheme further includes: Receive the response message sent by the core network; And / or, Send a response message to the first platform.
[0014] In the above scheme, a second request is sent to the core network by calling the API.
[0015] This application also provides a connection establishment method, applied to a core network device, including: The device receives a second request from a first device, the second request being used to request the establishment of a channel between the first platform and a second platform, the first device being connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; Based on the second request, determine the first UPF corresponding to the first platform and the second UPF corresponding to the second platform; Establish a connection between the first UPF and the second UPF.
[0016] In the above scheme, determining the first UPF corresponding to the first platform and the second UPF corresponding to the second platform based on the second request includes: The identity authentication information of the first device carried in the second request is used to verify the contract information of the first device; After successful verification, the first UPF is determined using the relevant information of the first platform carried in the second request, and / or the second UPF is determined using the relevant information of the second platform carried in the second request.
[0017] In the above scheme, establishing the connection between the first UPF and the second UPF includes: Establish a tunnel between the first UPF and the second UPF; Configure forwarding rules on the first UPF and the second UPF using the address information of the first device and the address information of the second device carried in the second request; And / or, Configure QoS rules on the first UPF and the second UPF using the data transmission information between the first platform and the second platform carried in the second request.
[0018] The method in the above scheme further includes: Send a response message to the first device.
[0019] This application embodiment also provides a connection establishment device, disposed on a first device, including: A first receiving unit is configured to receive a first request sent by a first platform; the first request is configured to request the establishment of a channel with a second platform; the first device is connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; The sending unit is used to send a second request to the core network based on the first request, wherein the second request is used to request the establishment of a channel between the first platform and the second platform; The first processing unit is used to receive the response message sent by the core network based on the second request and establish a secure channel with the first UPF.
[0020] This application embodiment also provides a connection establishment device, disposed on a core network device, including: The second receiving unit is configured to receive a second request sent by the first device, the second request being for requesting the establishment of a channel between the first platform and the second platform, wherein the first device is connected to at least one platform including the first platform; and the first platform and the second platform are at least capable of providing services to the application. The determining unit is configured to determine, based on the second request, the first UPF corresponding to the first platform and the second UPF corresponding to the second platform; The second processing unit is used to establish a connection between the first UPF and the second UPF.
[0021] This application also provides a first device, characterized in that it includes: a first processor and a first memory for storing a computer program capable of running on the processor. Wherein, when the first processor is used to run the computer program, it executes any of the steps of the method on the first device side.
[0022] This application also provides a core network device, characterized in that it includes: a second processor and a second memory for storing computer programs capable of running on the processor. Wherein, when the second processor runs the computer program, it executes any of the steps of the method on the core network device side.
[0023] This application embodiment also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of any of the methods described in the first device side above, or implements the steps of any of the methods described in the core network device side.
[0024] The connection establishment method, apparatus, related devices, and storage medium provided in this application embodiment include: a first device receiving a first request from a first platform; the first request is used to request the establishment of a channel with a second platform; the first device connects to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to an application; based on the first request, a second request is sent to the core network, the second request being used to request the establishment of a channel between the first platform and the second platform; the core network device receives the second request from the first device; based on the second request, a first UPF corresponding to the first platform and a second UPF corresponding to the second platform are determined; a connection is established between the first UPF and the second UPF; and the first device establishes a secure channel with the first UPF. In the solution provided in this application embodiment, the core network device responds to the request from the first device, establishes a connection between UPFs, and thus establishes a connection between different platforms, such as a connection between MEPs. This satisfies the communication needs between platforms. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of the system architecture combining 5G and MEC technologies in related technologies; Figure 2 This is a schematic diagram of a system architecture in which MEP accesses 5G in a non-3GPP (3rd Generation Partnership Project) manner. Figure 3 This is a schematic diagram of a 5G industry cloud-network convergence system architecture in an embodiment of this application; Figure 4 This is a schematic flowchart of the first connection establishment method according to an embodiment of this application; Figure 5 This is a schematic flowchart of the second connection establishment method according to an embodiment of this application; Figure 6 This is a schematic diagram of the system architecture for implementing wide-area interconnection between MEPs in an application embodiment of this application; Figure 7 This is a schematic diagram of the method for implementing wide-area interconnection between MEPs in an application embodiment of this application; Figure 8 This is a schematic diagram of the structure of the first connection establishment device according to an embodiment of this application; Figure 9 This is a schematic diagram of the second connection establishment device according to an embodiment of this application; Figure 10 This is a schematic diagram of the structure of the first device according to an embodiment of this application; Figure 11 This is a schematic diagram of the core network device structure in an embodiment of this application. Detailed Implementation
[0026] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.
[0027] In related technologies, for Figure 1 The 5G and MEC technology combination scheme shown requires local offloading to the UPF corresponding to the MEC. In the current 3GPP-defined 5G network, local offloading technology can include the following three implementation methods: 1. UL-CL method UL-CL is a feature of UPF that supports local forwarding of data packets conforming to filtering rules issued by the Session Management Function (SMF). UL-CL supports Protocol Data Unit (PDU) sessions of IPv4, IPv6, and IPv4 / Pv6 Ethernet types. The insertion and deletion of UL-CL packets are determined by the SMF and controlled by the UPF through the N4 interface. Furthermore, the MEP can configure UL-CL forwarding rules using 5G network capability opening technology.
[0028] 2. IPv6 BP method The above method only applies to IPv6 PDU sessions. The UPF implements local traffic offloading based on the IPv6 address prefix of the data packet. Similar to the UL-CL method, the insertion and deletion of BPs are determined by the SMF and controlled by the UPF through the N4 interface. Furthermore, the MEP can configure BP forwarding rules through 5G network capability opening technology.
[0029] 3. DNN method The DNN method uses a dedicated DNN to indicate the data network corresponding to the MEP. When the User Equipment (UE) creates a PDU session to access the MEP, it needs to carry the dedicated DNN. The 5G network will select the corresponding anchor point UPF based on the dedicated DNN to achieve traffic offloading.
[0030] In practical applications, in vertical industry scenarios, besides the need for local data offloading, there is also a need for wide-area interconnection between MEPs, such as data sharing between different hospitals and remote collaborative diagnosis. However, based on Figure 1 The scheme shown only supports PDU sessions from the terminal to the data network (DN), and does not support DN-to-DN connections. In other words, the UPF only supports data connections from the terminal to the MEP, and does not support interconnection between MEPs.
[0031] To address the aforementioned issues, the following methods have been proposed for supporting wide-area interconnection between MEPs in industry application scenarios: 1. MEPs are interconnected via dedicated lines. Industry users subscribe to dedicated line services from operators to connect MEPs in different geographical locations to achieve network and service interconnection.
[0032] 2. MEP accesses the 5G network via 5G base stations. MEPs access the 5G network via 5G base stations through secure 5G modules or by connecting to 5G Customer Premise Equipment (CPE). In this way, an MEP can be used as a 5G UE to connect to other MEPs, thereby achieving wide-area interconnection between MEPs.
[0033] 3. MEP accesses the 5G network via non-3GPP methods. like Figure 2 As shown, based on the non-3GPP access method defined by the 3GPP standard, the MEP accesses the 5G network through the non-3GPP interworking function (N3IWF) added by 5G, thereby realizing the connection with other MEPs.
[0034] However, all three implementation methods mentioned above have certain technical problems. Specifically, The first option requires industry users to separately order, activate, manage, and maintain dedicated lines, meaning they cannot use the operator's existing 5G network and therefore cannot utilize the cutting-edge technological features of 5G. This results in high adoption and operating costs, complex network management, and low flexibility in network evolution.
[0035] The second option, while utilizing the operator's existing 5G network, will consume a significant amount of 5G wireless access resources, increase the load on 5G base stations, and may also impact other 5G applications in the industry.
[0036] The third option requires significant modifications to the 5G network and MEP (Mobile Equipment Processor), such as deploying N3IWF in the 5G core network and requiring the MEP to support the 3GPP standard N1 and Nwu interfaces. In other words, implementing the third option involves high costs, a wide range of aspects, and is unlikely to be achieved in the short term.
[0037] In practical applications, to address the communication security issues that arise when 5G and MEC technologies are combined, a 5G industry cloud-network converged system architecture is proposed. For example... Figure 3 As shown, the security capabilities of the communication system are improved by deploying an Industry Gateway (iGW) between the UPF and MEP.
[0038] In related technologies, Figure 3As shown in the network architecture, there is currently no effective solution for achieving wide-area interconnection between MEPs.
[0039] Based on this, in various embodiments of this application, the core network (i.e., 5G network) device establishes a connection between corresponding UPFs by responding to the inter-platform connection request sent by the first device, thereby realizing wide-area interconnection between platforms.
[0040] This application provides a connection establishment method, applied to a first device, such as... Figure 4 As shown, the method includes: Step 401: Receive a first request sent by the first platform; the first request is used to request the establishment of a channel with the second platform; the first device is connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; Step 402: Based on the first request, send a second request to the core network, the second request being used to request the establishment of a channel between the first platform and the second platform; Step 403: Establish a secure channel with the first UPF.
[0041] The first device is located between the first platform and the first UPF; the first device may also be referred to as iGW, but the name of the first device is not limited in this embodiment.
[0042] Here, the first platform and the second platform can at least provide services for the application. The first platform and the second platform may specifically include MEP or private cloud platform. This application embodiment does not limit the type of the first platform and the second platform.
[0043] In practical applications, when both the first and second platforms include MEP, such as Figure 3 The system architecture shown here, to avoid security risks to the core network from applications on the MEP, prevents the MEP from communicating directly with the Network Exposure Function (NEF) in the core network. Instead, it connects to the NEF in the core network through a first device acting as a network capability exposure proxy, providing network capability exposure services to the MEP. During this process, industry users also need to sign a contract with the core network to grant the first device access to the core network.
[0044] Therefore, in step 401, the first device can receive a first request sent by the first platform (specifically, it may include the first MEP) to request the establishment of a channel with the second platform (specifically, it may include the second MEP). Specifically, the first device can receive the first request sent by the first platform via Transmission Control Protocol / Internet Protocol (TCP / IP).
[0045] Here, the first request will also carry information about the first platform and the second platform in order to establish a connection with the second platform.
[0046] Based on this, in one embodiment, the first request carries at least one of the following information: Information related to the first platform; Information related to the second platform; Information related to data transmission between the first platform and the second platform.
[0047] In practical applications, the relevant information of the first platform, the second platform, and the data transmission information between the first platform and the second platform can be pre-configured by the user on the first platform. This application embodiment does not limit this.
[0048] In one embodiment, the relevant information of the first platform includes at least one of the following: The geographical location information of the first platform; The DNN of the first platform.
[0049] Here, the geographic location information of the first platform can indicate the location of the first platform, specifically including the latitude and longitude information of the location of the first MEP or the address information (e.g., street information) of the location of the first MEP; the DNN of the first platform is used to indicate the data network corresponding to the first platform.
[0050] Specifically, in one embodiment, the relevant information of the second platform includes at least one of the following: The geographical location information of the second platform; The second platform's DNN.
[0051] Here, the geographic location information of the second platform can indicate the location of the second platform, specifically including the latitude and longitude information of the location of the second MEP or the physical address of the location of the second MEP (e.g., street information); the DNN of the second platform is used to indicate the data network corresponding to the second platform.
[0052] Specifically, in one embodiment, the data transmission related information between the first platform and the second platform includes at least one of the following: The network slice identifier required to establish a channel between the first platform and the second platform; QoS information between the first platform and the second platform.
[0053] The QoS information may include information such as required bandwidth, rate requirements, and latency requirements.
[0054] Next, in step 402, the first device will send a second request to the core network based on the first request to request the establishment of a channel between the first platform and the second platform.
[0055] In one embodiment, the second request carries at least the following information: The information carried in the first request; Address information of the first device; Address information of the second device; The identity authentication information of the first device.
[0056] Here, the identity authentication information of the first device may include the identifier of the first device, security certificate and other information; the identity authentication information of the first device is used by the core network to verify the contract information.
[0057] For example, after receiving the authentication information of the first device, the core network can verify the first device's access rights to the core network based on the identity identifier in the authentication information. If the verification is successful, the first device can successfully send the second request to the core network. Otherwise, the first device can receive a verification failure message returned by the core network to indicate that the first device cannot access the core network.
[0058] In addition, the second request may also carry the address information of the first device (such as IP address) and the address information of the second device, so that the core network device can configure forwarding rules.
[0059] In practical applications, when the first device sends a second request to the core network, it can act as a network capability open proxy to connect with the core network.
[0060] Based on this, in one embodiment, a second request is sent to the core network by calling an API.
[0061] In practical applications, the first device can send a second request to the NEF of the core network by calling the network capability open API provided by the core network. Based on the second request, the core network can establish a connection between the first UPF corresponding to the first platform and the second UPF corresponding to the second platform. Specifically, it can establish a connection between the first UPF corresponding to the first MEP and the second UPF corresponding to the second MEP.
[0062] The API may include a generic RESTful interface.
[0063] In practical applications, before step 403, the first device may also receive a response message returned by the core network based on the second request to determine whether the first platform and the second platform can connect.
[0064] Specifically, in one embodiment, the method may further include: Receive the response message sent by the core network; The response message sent by the core network contains at least the IP address of the first device.
[0065] In practical applications, based on the communication mechanism between the first device and the core network, the first device can receive response messages sent by the core network and determine the connection status of the first platform and the second platform based on the response messages.
[0066] Specifically, after receiving the response message sent by the core network, if the first device can determine, based on the response message, that a connection has been established between the first UPF and the second UPF, it can establish a secure channel with the first UPF. If the response message determines that no connection has been established between the first UPF and the second UPF, the first device can stop establishing a secure channel with the first UPF and can resend the second request to the core network based on a preset time interval.
[0067] For example, the first device can establish a secure channel with the first UPF through the Internet Protocol Security (IPsec).
[0068] In practical applications, the secure channel established between the first device and the first UPF can be understood as a Layer 3 channel, including the IP layer channel, which is mainly used for the transmission of secure encrypted data.
[0069] In this scenario, once the first device establishes a secure channel with the first UPF, a wide-area interconnection between the first platform and the second platform is achieved because a connection is established between the first UPF and the second UPF, and a connection is also established between the second UPF and the second device. Specifically, this wide-area interconnection between the first MEP and the second MEP can be realized.
[0070] In practical applications, after establishing a connection between the first platform and the second platform, the first device can also send a response message to the first platform so that the first platform can determine the connection status with the second platform.
[0071] Specifically, in one embodiment, the method further includes: Send a response message to the first platform.
[0072] In practical applications, after establishing a secure channel with the first UPF, the first device can send a response message to the first platform to inform the first platform that the channel between the first platform and the second platform has been successfully established.
[0073] In summary, by employing steps 401 to 403, the first device can establish a connection between the first MEP and the second MEP, thus satisfying the requirement for wide-area interconnection between MEPs. Similarly, when the first platform and the second platform include a private cloud platform, the first device can also establish a connection between the first private cloud platform and the second private cloud platform through the above steps 401 to 403 to meet the interconnection requirements between private cloud platforms. In addition, the first device can also be configured with Network Address Translation (NAT) functionality for the first platform. This is because, when the first platform is in an intranet mechanism and has an intranet address, if the first platform needs to communicate with the external network through the first device, the configured NAT function can be used to translate the intranet address of the first platform into an external address to enable communication with the external network.
[0074] Accordingly, embodiments of this application also provide a connection establishment method, applied to core network devices, such as... Figure 5 As shown, the method includes: Step 501: Receive a second request sent by the first device, the second request being used to request the establishment of a channel between the first platform and the second platform, the first device being connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; Step 502: Based on the second request, determine the first UPF corresponding to the first platform and the second UPF corresponding to the second platform; Step 503: Establish a connection between the first UPF and the second UPF.
[0075] In practical applications, in step 501, the NEF in the core network device can receive the second request sent by the first device through an API interface; the API interface may include a RESTful interface.
[0076] The NEF can provide network capabilities through APIs, which can specifically include the following types: 1) Monitoring capabilities: The core network monitors specified events of the UE and generates corresponding event notifications to send to third-party networks. These monitoring capabilities can be used for UE mobility management, such as monitoring UE location, reachability, and connection loss events.
[0077] 2) Pre-configuration capabilities: Third-party networks provide relevant information to the core network through capability openness, such as the UE's expected route and the UE's network requirements, enabling the core network to perform targeted optimizations.
[0078] 3) Policy / Charging Capabilities: Third-party networks issue charging policies, QoS policies, and other policies to the core network through capability opening.
[0079] 4) Analysis report capability: Third-party networks can obtain 5G network analysis reports through capability opening.
[0080] Furthermore, with the development of technologies such as network slicing, edge computing, big data, and artificial intelligence (AI), the core network can abstract more capabilities to provide to the business application layer, such as network slicing services, edge computing services, location services, 5G voice and messaging, and data analysis services.
[0081] In practical applications, after receiving the second request sent by the first device, the core network device can first verify the first device.
[0082] Based on this, in one embodiment, determining the first UPF corresponding to the first platform and the second UPF corresponding to the second platform based on the second request includes: The identity authentication information of the first device carried in the second request is used to verify the contract information of the first device; After successful verification, the first UPF is determined using the relevant information of the first platform carried in the second request; The second UPF is determined using the relevant information of the second platform carried in the second request.
[0083] In practical applications, after receiving the second request from the first device, NEF can send the received second request to the Unified Data Management (UDM) in the core network device so that the UDM can verify the identity of the first device.
[0084] Here, industry users typically sign a contract with the core network through a first device to subscribe to the core network's network capabilities before accessing it. Therefore, the UDM can use the stored contract information and the first device's authentication information (such as an identity identifier) carried in the second request to find the corresponding contract information and thus determine the first device's access rights to the core network.
[0085] For example, if the UDM can find the subscription information corresponding to the identity of the first device, it can determine that the verification is successful, that is, the first device has the right to access the core network. Then, the UDM sends the received second request to the SMF of the core network device; wherein, the selection of the SMF can be based on the internal implementation of the core network.
[0086] For example, the SMF can be selected by the first device when ordering network capabilities for the core network, or it can be automatically specified by the NEF, or it can be selected by the NEF through the Network Repository Function (NRF).
[0087] If the UDM cannot find the subscription information corresponding to the authentication information of the first device, it can determine that the verification failed, meaning that the first device does not have permission to access the core network. In this case, the UDM can send the verification result to the NEF, so that the NEF can return the verification result to the first device via API to indicate that the first device does not have permission to access the core network.
[0088] In practical applications, after receiving the second request sent by the UDM, the SMF can determine the first UPF corresponding to the first platform and the second UPF corresponding to the second platform based on the geographical location information of the first platform, the DNN of the first platform, the geographical location information of the second platform, and the DNN of the second platform carried in the second request, so as to establish a connection between the first platform and the second platform.
[0089] Here, when the first platform and the second platform are specifically MEPs, the SMF can determine the first UPF corresponding to the first MEP and the UPF corresponding to the second MEP based on the relevant information carried in the second request. Then, the SMF can establish a connection between the determined first UPF and the second UPF to realize the interconnection between the first MEP and the second MEP.
[0090] Specifically, in one embodiment, establishing the connection between the first UPF and the second UPF includes: Establish a tunnel between the first UPF and the second UPF; Configure forwarding rules on the first UPF and the second UPF using the address information of the first device and the address information of the second device carried in the second request; Configure QoS rules on the first UPF and the second UPF using the data transmission information between the first MEP and the second MEP carried in the second request.
[0091] In practical applications, the SMF can establish an N9 tunnel between the first UPF and the second UPF to establish a connection between the first UPF and the second UPF.
[0092] Next, the SMF can configure forwarding rules for the first UPF and the second UPF based on the address information of the first device and the address information of the second device carried in the second request, such as the IP address of the first device and the IP address of the second device, respectively, so as to realize the forwarding of data packets.
[0093] In addition, SMF can also configure QoS rules based on data transmission information between the first MEP and the second MEP carried in the second request, such as QoS information between the first MEP and the second MEP, which may specifically include information such as required bandwidth, rate requirements and latency requirements.
[0094] Next, SMF can also return a response message to the first device corresponding to the second request.
[0095] Specifically, in one embodiment, the method further includes: Send a response message to the first device.
[0096] In practical applications, the SMF can first send a response message carrying the first UPF address to the NEF. After receiving the response message carrying the first UPF address information from the SMF, the NEF can send the response message to the first device through the API interface, enabling the first device to establish a secure channel with the first UPF based on the address information of the first UPF.
[0097] In the above process, the core network device responds to the second request sent by the first device and establishes a connection between the first MEP and the second MEP by establishing a connection between the first UPF corresponding to the first MEP and the second UPF corresponding to the second MEP. In other words, the core network device creates a PDU dialogue between the first device and the DNN corresponding to the second MEP based on the network slice specified by the first device, enabling the first MEP to establish a connection with the second MEP through the NAT function configured by the first device and based on the created PDU dialogue.
[0098] In summary, by using steps 501 to 503, the core network equipment can establish a connection between the first MEP and the second MEP, thus meeting the requirements for wide-area interconnection between MEPs.
[0099] Similarly, when the first platform and the second platform include private cloud platforms, the core network equipment can also establish a connection between the first private cloud platform and the second private cloud platform through the above steps 501 to 503 to meet the interconnection requirements between private cloud platforms.
[0100] The connection establishment method provided in this application embodiment includes the following steps: A first device receives a first request sent by a first platform; the first request is used to request the establishment of a channel with a second platform; the first device connects to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to an application; based on the first request, a second request is sent to the core network, the second request being used to request the establishment of a channel between the first platform and the second platform; the core network device receives the second request sent by the first device; based on the second request, a first UPF corresponding to the first platform and a second UPF corresponding to the second platform are determined; a connection is established between the first UPF and the second UPF; and the first device establishes a secure channel with the first UPF. The solution provided in this application embodiment allows the core network device to respond to the request of the first device, establish a connection between UPFs, and thus establish a connection between different platforms, such as a connection between MEPs. This satisfies the communication needs between platforms.
[0101] The present application will be further described in detail below with reference to application examples.
[0102] like Figure 6 As shown in the application embodiment, this application proposes a system for realizing wide-area interconnection between MEPs, specifically including MEP1, iGW1, 5G core network (5GC), MEP2, and iGW2; MEP1 is connected to iGW1; MEP2 is connected to iGW2; iGW1 and iGW2 are capable of communicating and interacting with 5GC.
[0103] Specifically, the 5GC includes: NEF is used to communicate and interact with iGW1; UDM is used to verify the contract information of industry gateways that interact with NEF. SMF is used to create the N9 tunnel between UPF1 and UPF2; UPF1 (i.e., the first UPF) is used to connect MEP1 and MEP2; UPF2 (i.e., the second UPF) is used to connect MEP1 and MEP2.
[0104] Specifically, based on Figure 6 The system shown is a wide-area interconnection system between MEPs, such as Figure 7 As shown, the process of achieving wide-area interconnection between MEP1 and MEP2 includes the following steps: Step 701: MEP1 sends an interconnection request with MEP2 to iGW1; The interconnection request carries the address location of MEP1, the DNN to which MEP1 belongs, the address location of MEP2, the DNN to which MEP2 belongs, the network slice ID of the interconnection access between MEP1 and MEP2, and the QoS requirements for the interconnection between MEP1 and MEP2 (such as required bandwidth, rate requirements, and latency requirements).
[0105] Step 702: After receiving the interconnection request sent by MEP1, iGW1 calls the Wide Area Interconnection Link API to send a Wide Area Interconnection Link request to NEF; The wide area interconnection link request includes relevant information carried in the interconnection request, the IP address of iGW1 used for wide area interconnection, and the identity authentication information of iGW1 (such as the identifier or certificate information of iGW1).
[0106] To simplify the protocols required for MEP and iGW and avoid significant modifications to industry MEPs, 5GC will implement the network capability opening function for creating wide-area interconnection links and will expose its API through NEF. Therefore, iGW1 will access 5GC through the API exposed by NEF.
[0107] Step 703: After NEF receives the wide area interconnection link request sent by iGW1 through the API, it uses UDM to verify the subscription information of iGW1. In practical applications, industry users typically subscribe to 5GC's wide area interconnection capability open service through an industry gateway before accessing 5GC, i.e., they obtain access rights to 5GC and complete the contract signing process with 5GC. In this case, when NEF receives the API message, it uses the contract information stored in UDM to verify iGW1.
[0108] Specifically, NEF sends the authentication information (such as identity identifier) carried in the API message to UDM, so that UDM can find the contract information that matches the authentication information. If UDM can find the matching contract information, it means that the verification is successful, and UDM will return the successful verification result to NEF; if UDM cannot find the matching contract information, it means that the verification fails, and UDM will return the failed verification result to NEF.
[0109] Step 704: When NEF determines that the verification is successful based on the verification result, it forwards the wide area interconnection link request to SMF; In practical applications, the selection of the SMF can depend on the internal implementation of 5GC, specifically including: iGW1 selecting the SMF when iGW1 subscribes to the wide area interconnection capability open service, NEF obtaining the SMF from NRF, or NEF formulating the SMF itself.
[0110] Additionally, when NEF determines that the verification has failed based on the verification result, it can return a prompt message to iGW1 via API; the prompt message is used to indicate that iGW1 does not have permission to access 5GC.
[0111] Step 705: After receiving the wide area interconnection link request, the SMF selects the UPF1 corresponding to MEP1; In practical applications, SMF can determine the UPF1 corresponding to MEP1 based on the geographical location, DNN, and network slice ID of MEP1 carried in the WAN interconnection link request.
[0112] Step 706: After receiving the wide area interconnection link request, the SMF selects the UPF2 corresponding to MEP2; In practical applications, SMF can determine the UPF2 corresponding to MEP2 based on the geographical location of MEP2 carried in the WAN interconnection link request, as well as the DNN to which it belongs and the network slice ID of the interconnection access.
[0113] Step 707: SMF creates an N9 tunnel between UPF1 and UPF2 and configures forwarding rules and QoS rules; Here, the SMF configures forwarding rules on UPF1 and UPF2 based on the IP address of iGW1 used for WAN interconnection carried in the WAN interconnection link request. Additionally, the SMF can also configure QoS rules on UPF1 and UPF2 based on the QoS requirements for the interconnection of MEP1 and MEP2 carried in the WAN interconnection link request.
[0114] Step 708: SMF returns a response message to NEF; The response message returned by the SMF carries the IP address of UPF1.
[0115] Step 709: NEF returns a response message to iGW1; The response message returned by NEF carries the IP address of UPF1.
[0116] Step 710: iGW1 and UPF1 establish a secure data transmission channel; In practical applications, iGW1 establishes a secure encrypted data transmission channel with UPF1 based on the IP address of UPF1 carried in the received response message.
[0117] For example, iGW1 establishes a secure encrypted data transmission channel with UPF1 via an IPsec connection.
[0118] Then, iGW1 will configure NAT functionality for MEP1 so that MEP1 can achieve wide-area interconnection between MEPs based on the established links.
[0119] Step 711: iGW1 returns a response message to MEP1.
[0120] Here, the response message returned by iGW1 is used to inform MEP1 and MEP2 that the connection has been successfully established.
[0121] Through the above steps, a PDU session for a specified network slice was created between the DNNs belonging to iGW and MEP2 based on the 5GC network. MEP1 achieved wide-area interconnection with MEP2 through the NAT function configured in iGW1 and the created PDU session.
[0122] In this application embodiment, a method for wide-area interconnection of industry edge computing platforms is proposed based on a novel 5G cloud-network converged system architecture. Wide-area interconnection between MEPs is achieved through the network capability opening function of the iGW. Furthermore, this method can utilize existing operator 5G networks, requires minimal modification to MEPs, and is low-cost and simple to manage.
[0123] To implement the solution on the first device side of this application embodiment, this application embodiment also provides a connection establishment device, which is disposed on the first device, such as... Figure 8 As shown, the device includes: The first receiving unit 801 is configured to receive a first request sent by a first platform; the first request is used to request the establishment of a channel with a second platform; the first device is connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; The sending unit 802 is used to send a second request to the core network based on the first request, wherein the second request is used to request the establishment of a channel between the first platform and the second platform; The first processing unit 803 is used to establish a secure channel with the first UPF.
[0124] In one embodiment, the first receiving unit 801 is further configured to receive a response message sent by the core network; The sending unit 802 is also used to send a response message to the first platform.
[0125] In one embodiment, a second request is sent to the core network by calling an API.
[0126] In practical applications, the first receiving unit 801 can be implemented by the communication interface in the connection establishment device; the sending unit 802 can be implemented by the communication interface in the connection establishment device combined with a processor; and the first processing unit 803 can be implemented by the processor in the connection establishment device.
[0127] To implement the solution on the core network device side of this application embodiment, this application embodiment also provides a connection establishment device, which is installed on the core network device, such as... Figure 9 As shown, the device includes: The second receiving unit 901 is configured to receive a second request sent by the first device, the second request being for requesting the establishment of a channel between the first platform and the second platform, the first device being connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; The determining unit 902 is configured to determine, based on the second request, the first UPF corresponding to the first platform and the second UPF corresponding to the second platform; The second processing unit 903 is used to establish a connection between the first UPF and the second UPF.
[0128] In one embodiment, the determining unit 902 is specifically used for: The identity authentication information of the first device carried in the second request is used to verify the contract information of the first device; After successful verification, the first UPF is determined using the relevant information of the first platform carried in the second request, and / or the second UPF is determined using the relevant information of the second platform carried in the second request.
[0129] In one embodiment, the second processing unit 903 is specifically used for: Establish a tunnel between the first UPF and the second UPF; Configure forwarding rules on the first UPF and the second UPF using the address information of the first device and the address information of the second device carried in the second request; And / or, Configure QoS rules on the first UPF and the second UPF using the data transmission information between the first platform and the second platform carried in the second request.
[0130] In one embodiment, the second processing unit 903 is further configured to send a response message to the first device.
[0131] In practical applications, the second receiving unit 901 can be implemented by the communication interface in the connection establishment device; the determining unit 902 can be implemented by the processor in the connection establishment device; and the second processing unit 903 can be implemented by the processor in the connection establishment device in combination with the communication interface.
[0132] It should be noted that the connection establishment device provided in the above embodiments is only illustrated by the division of the above-described program units. In practical applications, the above processing can be assigned to different program units as needed, that is, the internal structure of the device can be divided into different program units to complete all or part of the processing described above. In addition, the connection establishment device and the connection establishment method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.
[0133] Based on the hardware implementation of the above program modules, and in order to implement the method on the first device side of the embodiments of this application, the embodiments of this application also provide a first device, such as... Figure 10 As shown, the first device 1000 includes: The first communication interface 1001 is capable of exchanging information with core network equipment; The first processor 1002 is connected to the first communication interface 1001 to enable information interaction with the core network equipment. When running a computer program, it executes the methods provided by one or more technical solutions on the first device side. The computer program is stored on the first memory 1003.
[0134] Specifically, the first communication interface 1001 is used to receive a first request sent by the first platform; the first request is used to request the establishment of a channel with the second platform; the first device is connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; The first processor 1002 is used for: Based on the first request, a second request is sent to the core network through the first communication interface 1001. The second request is used to request the establishment of a channel between the first platform and the second platform. A secure channel is established with the first UPF through the first communication interface 1001.
[0135] In one embodiment, the first communication interface 1001 is further configured to: Receive the response message sent by the core network; And / or, Send a response message to the first platform.
[0136] In one embodiment, a second request is sent to the core network by calling an API.
[0137] It should be noted that the specific processing procedures of the first processor 1002 and the first communication interface 1001 can be understood by referring to the above method.
[0138] Of course, in practical applications, the various components in the first device are coupled together through the bus system 1004. It can be understood that the bus system 1004 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 1004 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 10 The general labeled all buses as Bus System 1004.
[0139] The first memory 1003 in this embodiment is used to store various types of data to support the operation of the first device 1000. Examples of such data include any computer program used to operate on the first device 1000.
[0140] The methods disclosed in the above embodiments of this application can be applied to the first processor 1002, or implemented by the first processor 1002. The first processor 1002 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 1002. The first processor 1002 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 1002 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 1003. The first processor 1002 reads the information in the first memory 1003 and completes the steps of the aforementioned method in combination with its hardware.
[0141] In an exemplary embodiment, the first device 1000 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.
[0142] Based on the hardware implementation of the above program modules, and in order to implement the method on the core network device side of the embodiments of this application, the embodiments of this application also provide a core network, such as... Figure 11 As shown, the core network device 1100 includes: The second communication interface 1101 is capable of exchanging information with the first device; The second processor 1102 is connected to the second communication interface 1101 to enable information interaction with the first device. When running a computer program, it executes the methods provided by one or more technical solutions on the core network device side. The computer program is stored on the second memory 1103.
[0143] Specifically, the second processor 1102 is used for: The second request sent by the first device is received through the second communication interface 1101. The second request is used to request the establishment of a channel between the first platform and the second platform. The first device is connected to at least one platform including the first platform. The first platform and the second platform are at least capable of providing services to the application. Based on the second request, determine the first UPF corresponding to the first platform and the second UPF corresponding to the second platform; A connection between the first UPF and the second UPF is established through the second communication interface 1101.
[0144] In one embodiment, the second processor 1102 is specifically used for: The identity authentication information of the first device carried in the second request is used to verify the contract information of the first device; After successful verification, the first UPF is determined using the relevant information of the first platform carried in the second request, and / or the second UPF is determined using the relevant information of the second platform carried in the second request.
[0145] In one embodiment, the second processor 1102 is specifically used for: A tunnel is established between the first UPF and the second UPF through the second communication interface 1101; Configure forwarding rules on the first UPF and the second UPF using the address information of the first device and the address information of the second device carried in the second request; And / or, Configure QoS rules on the first UPF and the second UPF using the data transmission information between the first platform and the second platform carried in the second request.
[0146] In one embodiment, the second processor 1102 is further configured to: A response message is sent to the first device through the second communication interface 1101.
[0147] It should be noted that the specific processing procedures of the second processor 1102 and the second communication interface 1101 can be understood by referring to the above method.
[0148] Of course, in practical applications, the various components in the core network equipment are coupled together through the bus system 1104. It can be understood that the bus system 1104 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 1104 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 11 The general designated all buses as Bus System 1104.
[0149] The second memory 1103 in this embodiment is used to store various types of data to support the operation of the core network device 1100. Examples of such data include any computer programs used to operate on the core network device 1100.
[0150] The methods disclosed in the above embodiments of this application can be applied to the second processor 1102, or implemented by the second processor 1102. The second processor 1102 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the second processor 1102. The second processor 1102 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1102 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the second memory 1103. The second processor 1102 reads the information in the second memory 1103 and completes the steps of the aforementioned method in conjunction with its hardware.
[0151] In an exemplary embodiment, the core network device 1100 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.
[0152] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium. For example, it may include a first memory 1003 storing a computer program, which can be executed by a first processor 1002 of a first device 1000 to complete the steps described in the aforementioned first device-side method. Another example is a second memory 1103 storing a computer program, which can be executed by a second processor 1102 of a core network device 1100 to complete the steps described in the aforementioned core network device-side method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.
[0153] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0154] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.
[0155] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A connection establishment method, characterized in that, Applied to the first device, including: The device receives a first request sent by a first platform; the first request is used to request the establishment of a channel with a second platform; the first device connects to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application; the first device is located between the first platform and the first user plane function (UPF); the first platform and the second platform are multi-access edge computing platforms (MEP) or private cloud platforms; the first device includes an industry gateway. Based on the first request, a second request is sent to the core network, the second request being used to request the establishment of a channel between the first platform and the second platform; When a connection is established between the first UPF and the second UPF corresponding to the second platform, a secure channel is established with the first user plane function UPF; wherein, the first request carries at least one of the following information: Information related to the first platform; Information related to the second platform; Information related to data transmission between the first platform and the second platform.
2. The method according to claim 1, characterized in that, The relevant information of the first platform includes at least one of the following: The geographical location information of the first platform; The data network name of the first platform is DNN.
3. The method according to claim 1, characterized in that, The relevant information of the second platform includes at least one of the following: The geographical location information of the second platform; The second platform's DNN.
4. The method according to claim 1, characterized in that, The data transmission information between the first platform and the second platform includes at least one of the following: The network slice identifier required to establish a channel between the first platform and the second platform; Quality of Service (QoS) information between the first platform and the second platform.
5. The method according to claim 1, characterized in that, The second request must carry at least the following information: The information carried in the first request; Address information of the first device; The address information of the second device, which is located between the second platform and the second UPF; The identity authentication information of the first device.
6. The method according to claim 1, characterized in that, The method further includes: Receive the response message sent by the core network; And / or, Send a response message to the first platform.
7. The method according to any one of claims 1 to 6, characterized in that, A second request is sent to the core network by calling the application programming interface (API).
8. A connection establishment method, characterized in that, Applied to core network equipment, including; The device receives a second request from a first device, the second request being used to request the establishment of a channel between a first platform and a second platform, the first device connecting to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to the application, the first device is located between the first platform and a first UPF corresponding to the first platform, the first platform and the second platform are MEP or private cloud platforms; the first device includes an industry gateway; Based on the second request, determine the first UPF corresponding to the first platform and the second UPF corresponding to the second platform; A connection is established between the first UPF and the second UPF to enable the first device to establish a channel with the first UPF; wherein the second request is sent based on the first request, which is sent by the first platform to the first device, and the first request is used to request the establishment of a channel with the second platform, and the first request carries at least one of the following information: Information related to the first platform; Information related to the second platform; Information related to data transmission between the first platform and the second platform.
9. The method according to claim 8, characterized in that, The step of determining the first UPF corresponding to the first platform and the second UPF corresponding to the second platform based on the second request includes: The identity authentication information of the first device carried in the second request is used to verify the contract information of the first device; After successful verification, the first UPF is determined using the relevant information of the first platform carried in the second request, and / or the second UPF is determined using the relevant information of the second platform carried in the second request.
10. The method according to claim 9, characterized in that, Establishing the connection between the first UPF and the second UPF includes: Establish a tunnel between the first UPF and the second UPF; Using the address information of the first device and the address information of the second device carried in the second request, forwarding rules are configured on the first UPF and the second UPF, and the second device is set between the second platform and the second UPF; And / or, Configure QoS rules on the first UPF and the second UPF using the data transmission information between the first platform and the second platform carried in the second request.
11. The method according to any one of claims 8 to 10, characterized in that, The method further includes: Send a response message to the first device.
12. A connection establishment device, characterized in that, Configured on the first device, including: A first receiving unit is configured to receive a first request sent by a first platform; the first request is configured to request the establishment of a channel with a second platform; the first device is connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services for the application; the first device is disposed between the first platform and the first UPF; the first platform and the second platform are MEP or private cloud platforms; the first device includes an industry gateway. The sending unit is used to send a second request to the core network based on the first request, wherein the second request is used to request the establishment of a channel between the first platform and the second platform; The first processing unit is configured to establish a secure channel with the first UPF when a connection is established between the first UPF and the second UPF corresponding to the second platform; wherein the first request carries at least one of the following information: Information related to the first platform; Information related to the second platform; Information related to data transmission between the first platform and the second platform.
13. A connection establishment device, characterized in that, Configured on core network equipment, including: The second receiving unit is configured to receive a second request sent by the first device, the second request being for requesting the establishment of a channel between the first platform and the second platform, the first device being connected to at least one platform including the first platform; the first platform and the second platform are at least capable of providing services to applications, the first device being positioned between the first platform and a first UPF corresponding to the first platform, the first platform and the second platform being a MEP or a private cloud platform; the first device includes an industry gateway. The determining unit is configured to determine, based on the second request, the first UPF corresponding to the first platform and the second UPF corresponding to the second platform; The second processing unit is configured to establish a connection between the first UPF and the second UPF, so that the first device establishes a channel with the first UPF; wherein the second request is sent based on the first request, the first request being sent by the first platform to the first device, the first request being used to request the establishment of a channel with the second platform, and the first request carrying at least one of the following information: Information related to the first platform; Information related to the second platform; Information related to data transmission between the first platform and the second platform.
14. A first device, characterized in that, include: A first processor and a first memory for storing computer programs capable of running on the processor. Wherein, when the first processor is used to run the computer program, it performs the steps of the method according to any one of claims 1 to 7.
15. A core network device, characterized in that, include: A second processor and a second memory for storing computer programs that can run on the processor. Wherein, when the second processor is used to run the computer program, it performs the steps of the method according to any one of claims 8 to 11.
16. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7, or the steps of the method according to any one of claims 8 to 11.
Citation Information
Patent Citations
Business redirection methods and devices
CN109548082A
Method, device and equipment for realizing edge network capability opening and storage medium
CN109818868A
Mobile edge computing application data migration method, device, and core network node
WO2021093535A1