A processing method, a processing apparatus, an electronic device, and a storage medium

CN116367152BActive Publication Date: 2026-09-22LENOVO (BEIJING) LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310342133.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-31
Publication Date
2026-09-22
Estimated Expiration
2043-03-31

AI Technical Summary

Benefits of technology

[0028]本申请实施例还提供了一种存储介质,存储有计算机程序,所述计算机程序被处理器执行时实现上述任意实施例提供的处理方法中任一项方法步骤。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116367152B_ABST
    Figure CN116367152B_ABST
Patent Text Reader

Abstract

The application discloses a processing method, a processing device, an electronic device and a storage medium. The method comprises the following steps: acquiring service identification information of a user terminal; determining a target encryption tunnel and a target working thread corresponding to the user terminal according to preset encryption tunnel information based on at least the service identification information; and receiving or sending service packets through the target working thread and the target encryption tunnel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a processing method, processing device, electronic device, and storage medium. Background Technology

[0002] The User Plane Function (UPF), as a user plane network element in the 5G core network (5GC), primarily supports the routing and forwarding of UE service data. To ensure information security during transmission, encryption schemes such as IPsec can be introduced into the UPF in industry private network scenarios. These encryption schemes provide high-quality, interoperable, and cryptographically based security guarantees for the data transmitted by the UPF. However, in traditional data communication products, such encryption technologies are only sufficient for establishing a single tunnel. When applied to the UPF, because the UPF faces multiple service flows entering from different cores and being processed simultaneously, the encryption technology cannot match the high-performance forwarding capabilities of the UPF. Therefore, how to improve the UPF's packet processing capabilities after applying encryption technology is an urgent technical problem to be solved. Summary of the Invention

[0003] On one hand, embodiments of this application provide a processing method applied to user plane function network elements, including:

[0004] Obtain the service identification information of the user terminal;

[0005] At least based on the service identification information, the target encrypted tunnel and target working thread corresponding to the user terminal are determined according to the preset encrypted tunnel information;

[0006] The target worker thread is used to receive or send service messages through the target encrypted tunnel.

[0007] In some embodiments, the methods for obtaining the preset encrypted tunnel information include:

[0008] Receive service request messages sent by each user terminal, wherein each service request includes the corresponding service identification information of each user terminal;

[0009] Based on the service identification information, encrypted tunnels are established between each user terminal to construct the preset encrypted tunnel information; wherein, the encrypted tunnel corresponds to the IP address configured on the N6 interface, and the N6 interface is configured with at least two IP addresses.

[0010] In some embodiments, the method further includes:

[0011] Create a worker thread that corresponds to the IP address;

[0012] A mapping relationship is established based on the encrypted tunnel, the IP address, and the corresponding worker thread.

[0013] In some embodiments, determining the target encrypted tunnel and target working thread corresponding to the user terminal based at least on the service identification information and preset encrypted tunnel information includes:

[0014] Based on the service identification information and mapping relationship, the corresponding tunnel identification information is determined, and the target encrypted tunnel and the corresponding target working thread are determined based on the tunnel identification information, so as to use the target working thread to receive uplink service messages from the user terminal through the target encrypted tunnel.

[0015] In some embodiments, determining the target encrypted tunnel and target working thread corresponding to the user terminal based at least on the service identification information and preset encrypted tunnel information includes:

[0016] When a downlink service message corresponding to the uplink service message is received, the five-tuple information of the downlink service message is obtained;

[0017] Based on the five-tuple information, the corresponding tunnel identification information is determined from multiple encrypted tunnels and working threads according to the determination and mapping relationship. The target encrypted tunnel and the corresponding target working thread are determined based on the tunnel identification information, so as to use the target working thread to send the downlink service message to the user terminal through the target encrypted tunnel.

[0018] In some embodiments, the method further includes: the encrypted tunnels each having corresponding encrypted information;

[0019] Based on the target encrypted tunnel, the corresponding target encryption information is determined, and the target worker thread is used to perform encryption and encapsulation processing on the uplink service message based on the target encryption information, so as to encrypt the uplink service message before transmission.

[0020] In some embodiments, the encrypted tunnels each have corresponding encrypted information;

[0021] Sending the downlink service message to the user terminal via the target encrypted tunnel using the target worker thread includes:

[0022] Based on the target encrypted tunnel, the corresponding target encryption information is determined. The target working thread is used to decrypt and encapsulate the downlink service message based on the target encryption information, so as to send the decrypted downlink service message to the user terminal.

[0023] Based on the same inventive concept, embodiments of this application also provide a processing apparatus, including:

[0024] The acquisition module is configured to acquire the service identification information of the user terminal;

[0025] The determination module is configured to determine, at least based on the service identification information, the target encrypted tunnel and the target working thread corresponding to the user terminal according to the preset encrypted tunnel information;

[0026] The processing module is configured to receive or send service messages through the target encrypted tunnel using the target worker thread.

[0027] This application also provides an electronic device, which includes at least a memory, a processor, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory via the bus. When the machine-readable instructions are executed by the processor, any one of the method steps in the processing method provided in any of the above embodiments is implemented.

[0028] This application also provides a storage medium storing a computer program, which, when executed by a processor, implements any one of the method steps in the processing methods provided in any of the above embodiments.

[0029] The processing method of this application embodiment can determine the target encryption tunnel and target working thread corresponding to the encryption technology based on the service identification information of the user terminal. The target working thread can be allocated to the corresponding CPU core for encryption processing and transmission, which can improve data processing capability and ensure good security during data transmission. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0031] Figure 1 A flowchart of a processing method provided in this application is shown;

[0032] Figure 2 A schematic diagram of the structure of a processing apparatus provided in this application is shown;

[0033] Figure 3 A schematic diagram of the structure of an electronic device provided in this application is shown;

[0034] Figure 4 A schematic diagram of a scenario illustrating the processing method provided in this application is shown. Detailed Implementation

[0035] Various embodiments and features of this application are described herein with reference to the accompanying drawings.

[0036] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.

[0037] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0038] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.

[0039] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application, which have the features described in the claims and are therefore all within the scope of protection defined herein.

[0040] The above and other aspects, features and advantages of this application will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.

[0041] Specific embodiments of this application are described thereafter with reference to the accompanying drawings; however, it should be understood that the claimed embodiments are merely examples of this application, which can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the application. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but merely serve as the basis and representative basis for the claims to teach those skilled in the art to use this application in a variety of substantially any suitable detailed structures.

[0042] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in other embodiments,” all of which may refer to one or more of the same or different embodiments according to this application.

[0043] Figure 1 An embodiment of this application provides a processing method. For example... Figure 1 As shown, the processing method in this application embodiment includes:

[0044] S100, obtain the service identification information of the user terminal;

[0045] S200, at least based on the service identification information, determine the target encrypted tunnel and target working thread corresponding to the user terminal according to the preset encrypted tunnel information;

[0046] S300, the target worker thread is used to receive or send service messages through the target encrypted tunnel.

[0047] The processing method of this application embodiment is mainly applied to the User Plane Function (UPF) network element. When processing a large amount of message data, the UPF network element determines the target encryption tunnel and target working thread corresponding to the encryption technology based on the service identification information of the user terminal. The target working thread can be allocated to the corresponding CPU core for encryption processing and transmission, which can improve data processing capability and ensure good security of data transmission.

[0048] In this embodiment, the UE's service identification information can be used to determine its identity information, thereby determining its pre-negotiated encrypted tunnel information based on this identity information. To address the security issue of data transmission, the UPF network element establishes an encrypted tunnel with the UE to transmit service packets. For example, using IPSEC encryption technology, the UPF network element can establish multiple IPSEC encrypted tunnels based on the UE's service request information or a custom partitioning type to generate corresponding preset encrypted tunnel information.

[0049] In specific applications, multiple worker threads can be pre-established and configured for each encrypted tunnel. These worker threads can be allocated to different CPU cores based on actual needs, allowing the UPF network element to utilize the corresponding CPU core for each worker thread to process service packets through the encrypted tunnel. The establishment and allocation of worker threads can be configured according to actual needs or based on the method of establishing the encrypted tunnel. For example, when a UPF network element establishes encrypted tunnels corresponding to different types of service requirements based on the IP addresses configured on its interfaces, worker threads can also be established accordingly based on the number of IP addresses, thus creating a one-to-one correspondence between worker threads and encrypted tunnels based on IP addresses.

[0050] For example, the UE's service identification information can be obtained based on the subscription information corresponding to the SIM card. UEs with different service types use their own customized SIM cards, and the customized SIM cards can have corresponding service identification information for each service type, enabling differentiation between different service types. When the UPF network element receives a service request from the UE, it can obtain the corresponding service identification information based on the SIM card, thereby identifying the UE's service type and identity information. Subsequently, the UPF network element determines the target encrypted tunnel corresponding to the UE based on the matching between the user terminal's identity information recorded in the preset encrypted tunnel information and the encrypted tunnel. At the same time, it obtains the target working thread allocated to the target encrypted tunnel, so as to utilize the CPU core corresponding to the target working thread to encrypt, decrypt, and transmit the service packets of user terminal UE1 through the target encrypted tunnel.

[0051] Understandably, under the invention concept of establishing an IPSEC encrypted tunnel based on a custom service type classification method by the UPF network element, the UE's service identification information can be allocated based on the service classification method corresponding to this invention concept to identify the corresponding service type and identity information, so that the UPF network element can determine the target encrypted tunnel and target working thread corresponding to the UE based on the information recorded in the preset encrypted tunnel information.

[0052] In some embodiments, the methods for obtaining the preset encrypted tunnel information include:

[0053] Receive service request messages sent by each user terminal, wherein each service request includes the corresponding service identification information of each user terminal;

[0054] Based on the service identification information, encrypted tunnels are established between each user terminal to construct the preset encrypted tunnel information; wherein, the encrypted tunnel corresponds to the IP address configured on the N6 interface, and the N6 interface is configured with at least two IP addresses.

[0055] This embodiment aims to establish encrypted tunnels based on various user terminals and generate preset encrypted tunnel information. In this embodiment, after a user terminal accesses the UPF network element via a wireless network, it sends a service request message. The service identifier information of the user terminal in the service request is used by the UPF network element for identity verification. After the UPF network element successfully verifies the identity of the user terminal, it can establish an encrypted tunnel to facilitate subsequent data transmission. In some specific applications, the N6 interface of the UPF network element can be configured with two or more IP addresses as needed, each with a different network segment. In some practical applications, when establishing an encrypted tunnel, the UPF network element can determine the service requirements or service type based on the identity verification of the user terminal, determine the corresponding tunnel parameter information based on the service requirements or service type, and allocate an IP address to establish an encrypted tunnel adapted to the user terminal's requirements. The tunnel parameter information includes protocol information, encryption information, encapsulation information, etc., such as the security protocol type used by both parties, the encryption and verification algorithms adopted by the protocol, the encapsulation mode used for data transmission, and the key used for data transmission, etc.

[0056] In some practical applications, tunnel parameter information can be pre-set by the UPF network element according to the service type or service requirements, so that it can be directly called according to the service type or service requirements of the user terminal when establishing an encrypted tunnel; or, the UPF network element can also determine the corresponding tunnel parameter information through negotiation with the user terminal, which is not limited here.

[0057] In some embodiments, the process further includes:

[0058] Create a worker thread that corresponds to the IP address;

[0059] A mapping relationship is established based on the encrypted tunnel, the IP address, and the corresponding worker thread.

[0060] In this embodiment, after configuring two or more IP addresses for the N6 interface, the UPF network element activates corresponding worker threads based on each IP address. This allows the encrypted tunnels established based on IP addresses to be associated with specific worker threads. Then, the UPF network element can establish a one-to-one mapping between IP addresses, worker threads, and encrypted tunnels, thereby determining the other two based on this mapping and one piece of information. For example, based on the mapping and IP addresses, the corresponding worker thread and encrypted tunnel can be determined.

[0061] In some practical applications, the UPF network element can allocate worker threads to different CPU cores for processing based on actual needs or usage. For example, it can determine whether to prioritize CPU cores based on polling available CPU cores, the priority of the service type corresponding to the user's service identifier, or the allocation to idle CPU cores based on task completion status. Thus, the established worker threads can fully utilize multiple CPU cores to process service packets, preventing any single CPU core from becoming fully loaded or overflowing, improving data transmission security, and simultaneously increasing data processing efficiency.

[0062] In some embodiments, determining the target encrypted tunnel and target working thread corresponding to the user terminal based at least on the service identification information and preset encrypted tunnel information includes:

[0063] Based on the service identification information and mapping relationship, the corresponding tunnel identification information is determined, and the target encrypted tunnel and the corresponding target working thread are determined based on the tunnel identification information, so as to use the target working thread to receive uplink service messages from the user terminal through the target encrypted tunnel.

[0064] In this embodiment, the tunnel identification information is used to uniquely identify an encrypted tunnel. The specific content can be encoded and set by technical personnel, and this application does not limit this. Considering that the encrypted tunnel is established based on the service identification information of the user terminal, when the service identification information of the user terminal is obtained, a pre-established mapping relationship can be used to query and determine the tunnel identification information used to identify and determine the encrypted tunnel. Then, based on the tunnel encryption identification information, the corresponding encrypted tunnel is determined as the target encrypted tunnel for the user terminal, as well as the allocated target working thread. Thus, the UPF network element can enable the target working thread for the user terminal and use the target encrypted tunnel to process the service packets sent by the user terminal before forwarding them to the subsequent data network (DN), improving the security of data transmission.

[0065] In some embodiments, determining the target encrypted tunnel and target working thread corresponding to the user terminal based at least on the service identification information and preset encrypted tunnel information includes:

[0066] When a downlink service message corresponding to the uplink service message is received, the five-tuple information of the downlink service message is obtained;

[0067] Based on the five-tuple information, the corresponding tunnel identification information is determined from multiple encrypted tunnels and working threads according to the determination and mapping relationship. The target encrypted tunnel and the corresponding target working thread are determined based on the tunnel identification information, so as to use the target working thread to send the downlink service message to the user terminal through the target encrypted tunnel.

[0068] In this embodiment, the five-tuple information of the downlink service packet includes the source IP address, source port, destination IP address, destination port, and transport layer protocol. Based on the corresponding uplink service packet and the aforementioned embodiment, the destination IP address in the downlink service packet is the IP address allocated by the UPF network element to the user terminal. Therefore, the UPF network element can query the destination IP address in the downlink service packet's five-tuple information, combined with a pre-established mapping relationship, to determine the tunnel identifier information used to identify and determine the encrypted tunnel. Then, based on the tunnel encryption identifier information, it determines the corresponding encrypted tunnel as the target encrypted tunnel for the downlink service packet, as well as the corresponding target worker thread. Thus, the UPF network element can activate the target worker thread for the downlink service packet, process the downlink service packet using the target encrypted tunnel, and then forward it to the subsequent user terminal.

[0069] In some embodiments, the processing method further includes: the encrypted tunnels each having corresponding encrypted information;

[0070] Based on the target encrypted tunnel, the corresponding target encryption information is determined, and the target worker thread is used to perform encryption and encapsulation processing on the uplink service message based on the target encryption information, so as to encrypt the uplink service message before transmission.

[0071] This embodiment applies to the process of processing uplink service messages. Based on the establishment process of the encrypted tunnel, it is known that each encrypted tunnel has its own corresponding tunnel parameter information, including data transmission protocols, keys, and other encryption information. In some practical applications, the encrypted tunnel can select corresponding algorithms and protocols according to actual needs, such as the Data Encryption Standard (DES) algorithm, the 3DES algorithm, etc. Protocol types can include international protocols and national cryptographic protocols, etc. Multiple algorithms can also be combined in the encryption algorithm; this is not limited here.

[0072] In some specific applications, after the UPF network element determines the target encrypted tunnel based on the service identification information, it can determine the target encryption information, such as the transmission protocol, encryption algorithm, and key corresponding to the target encrypted tunnel, based on the aforementioned negotiated encrypted tunnel information. This allows it to encrypt the uplink service packets based on the corresponding transmission protocol, encryption algorithm, and key before sending them to the data network. In some practical applications, when the tunnel negotiation information includes encapsulation information, the UPF can process it according to the negotiated encapsulation mode.

[0073] In some embodiments, the encrypted tunnels each have corresponding encrypted information;

[0074] Sending the downlink service message to the user terminal via the target encrypted tunnel using the target worker thread includes:

[0075] Based on the target encrypted tunnel, the corresponding target encryption information is determined. The target working thread is used to decrypt and encapsulate the downlink service message based on the target encryption information, so as to send the decrypted downlink service message to the user terminal.

[0076] This embodiment applies to the process of processing downlink service packets. In conjunction with the aforementioned embodiments, in some specific applications, after the UPF network element determines the target encrypted tunnel based on the five-tuple information of the downlink service packet, it can determine the target encryption information, such as the transmission protocol, encryption algorithm, and key corresponding to the target encrypted tunnel, based on the negotiated encrypted tunnel information. Therefore, it can decrypt the downlink service packet based on the corresponding transmission protocol, encryption algorithm, and key, and then decrypt the uplink service packet before sending it to the user terminal. In some practical applications, when the tunnel negotiation information includes encapsulation information, the UPF can process the decrypted packet according to the negotiated encapsulation mode.

[0077] Based on the same inventive concept, embodiments of this application also provide a processing device, such as... Figure 2 As shown, the processing device includes:

[0078] Module 10 is configured to acquire the service identification information of the user terminal;

[0079] The determination module 20 is configured to determine, at least based on the service identification information, the target encrypted tunnel and the target working thread corresponding to the user terminal according to the preset encrypted tunnel information;

[0080] The processing module 30 is configured to receive or send service messages through the target encrypted tunnel using the target worker thread.

[0081] The processing device described in this application embodiment, through its configured acquisition module 10, determination module 20 and processing module 30, can implement the steps of the processing method provided in any embodiment of this application, which will not be repeated here.

[0082] This application also provides an electronic device, including at least a memory 501, a processor 502, and a bus (not shown), wherein the structural schematic diagram of the electronic device can be as follows: Figure 3 As shown, the memory 501 stores machine-readable instructions that can be executed by the processor 502. When the electronic device is running, the processor 502 communicates with the memory 501 via a bus. When the machine-readable instructions are executed by the processor, they perform the steps of the processing method provided in any embodiment of this application.

[0083] Since the electronic device described in this application embodiment is an electronic device equipped with a memory for implementing the processing method disclosed in this application embodiment, those skilled in the art can understand the structure and variations of the electronic device described in this application embodiment based on the processing method described in this application embodiment, and therefore will not be described again here.

[0084] This application also provides a computer-readable storage medium storing a computer program thereon, which, when run by a processor, executes any one of the method steps in the processing method provided in any of the above embodiments.

[0085] The storage medium in this embodiment may be included in an electronic device; or it may exist independently and not be assembled into an electronic device. The storage medium carries one or more computer programs, which, when executed, implement the steps of the processing method provided in the embodiments of this application.

[0086] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. Optionally, specific examples in this embodiment can refer to the examples described in any embodiment of this application, which will not be repeated here. Obviously, those skilled in the art should understand that the various modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this application is not limited to any particular hardware and software combination.

[0087] For example, Figure 4 A schematic diagram illustrating a scenario using the processing method described in an embodiment of this application is shown. For example... Figure 4 As shown, the application scenario is a 5G core network, which includes a data network (DN), user plane function (UPF) network elements, and user terminals (UEs). In some practical applications, the UE communicates with the UPF network elements through the radio access network (RAN), and the UPF network elements communicate with the DN through the N6 interface. Thus, the UPF network elements can receive service packets from the UE and forward them to the DN, or receive service packets from the DN and forward them to the UE.

[0088] The processing method described in this application is applied to a UPF network element. Taking IPsec encryption technology as an example, in order to encrypt, decrypt, and transmit service packets, the UPF network element negotiates and establishes multiple IPsec tunnels based on the IP addresses configured in its interfaces and the service requests of the UEs. Each tunnel can support the encryption and decryption of the corresponding UE's service packets and is assigned to a corresponding worker thread for execution. In some practical applications, the UPF network element can store mapping table entries based on the identification information and encryption information of the IPsec tunnels, the identification information of the user terminals, and the worker threads, so as to facilitate subsequent querying during the processing of service packets.

[0089] For example, after user terminal UE1 wirelessly accesses the UPF network element through RAN1 and initiates a service packet transmission request, the UPF network element can obtain the identification information of user terminal UE1 based on the transmission request. Then, the UPF network element can determine the service type and identity information of user terminal UE1 based on this identification information. Afterwards, the UPF network element can query the pre-built encrypted tunnel information recorded in the mapping table. When the IPSEC tunnel information corresponding to the UE is found, the corresponding IPSEC tunnel is used as the target encrypted tunnel, and the allocated worker thread is determined as worker thread 1 based on the queried IPSEC information. Thus, the UPF network element can use the CPU core corresponding to worker thread 1 to encrypt, decrypt, and transmit the service packets of user terminal UE1 through the target encrypted tunnel. It can be understood that the UPF network element can use the CPU core corresponding to worker thread 2 to encrypt, decrypt, and transmit the service packets of user terminal UE2 through the target encrypted tunnel, and use the CPU core corresponding to worker thread 3 to encrypt, decrypt, and transmit the service packets of user terminal UE3 through the target encrypted tunnel. In some practical applications, UPF network elements allocate worker threads to different CPU cores for processing. They can determine whether to prioritize CPU cores based on polling available CPU cores, or based on the priority of the service type corresponding to the user's service identifier, or allocate them to idle CPU cores according to the task completion status. This can make full use of multiple CPU cores to process service packets, prevent a CPU core from being fully loaded or even overflowing, improve the security of data transmission, and achieve high data processing efficiency.

[0090] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0091] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

[0092] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. Multitasking and parallel processing may be advantageous in certain environments. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this application. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0093] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

[0094] The above embodiments are merely exemplary embodiments of this application and are not intended to limit this application. The scope of protection of this application is defined by the claims. Those skilled in the art can make various modifications or equivalent substitutions to this application within its substance and scope of protection, and such modifications or equivalent substitutions should also be considered to fall within the scope of protection of this application.

Claims

1. A processing method applied to a user plane function network element, comprising: Obtain the service identification information of the user terminal; At least based on the service identification information, the target encrypted tunnel and target working thread corresponding to the user terminal are determined according to the preset encrypted tunnel information; The target worker thread is used to receive or send service messages through the target encrypted tunnel; The methods for obtaining the preset encrypted tunnel information include: Receive service request messages sent by each user terminal, wherein each service request includes the corresponding service identification information of each user terminal; Based on the service identification information, encrypted tunnels are established between each user terminal to construct the preset encrypted tunnel information; wherein, the encrypted tunnel corresponds to the IP address configured on the N6 interface, and the N6 interface is configured with at least two IP addresses; Create a worker thread that corresponds to the IP address; A mapping relationship is established based on the encrypted tunnel, the IP address, and the corresponding worker thread.

2. The method according to claim 1, wherein at least based on the service identification information, a target encrypted tunnel and a target working thread corresponding to the user terminal are determined according to preset encrypted tunnel information, comprising: Based on the service identification information and mapping relationship, the corresponding tunnel identification information is determined, and the target encrypted tunnel and the corresponding target working thread are determined based on the tunnel identification information, so as to use the target working thread to receive uplink service messages from the user terminal through the target encrypted tunnel.

3. The method according to claim 1, wherein at least based on the service identification information, a target encrypted tunnel and a target working thread corresponding to the user terminal are determined according to preset encrypted tunnel information, comprising: When a downlink service message corresponding to an uplink service message is received, the five-tuple information of the downlink service message is obtained; Based on the quintuple information and mapping relationship, the corresponding tunnel identification information is determined from multiple encrypted tunnels and working threads. Based on the tunnel identification information, the target encrypted tunnel and the corresponding target working thread are determined, so that the target working thread can be used to send the downlink service message to the user terminal through the target encrypted tunnel.

4. The method according to claim 2, further comprising: Each encrypted tunnel has corresponding encrypted information; Based on the target encrypted tunnel, the corresponding target encryption information is determined, and the target worker thread is used to perform encryption and encapsulation processing on the uplink service message based on the target encryption information, so as to encrypt the uplink service message before transmission.

5. The method according to claim 3, wherein each encrypted tunnel has corresponding encrypted information; Sending the downlink service message to the user terminal via the target encrypted tunnel using the target worker thread includes: Based on the target encrypted tunnel, the corresponding target encryption information is determined. The target working thread is used to decrypt and encapsulate the downlink service message based on the target encryption information, so as to send the decrypted downlink service message to the user terminal.

6. A processing apparatus, comprising: The acquisition module is configured to acquire the service identification information of the user terminal; The determination module is configured to determine, at least based on the service identification information, the target encrypted tunnel and the target working thread corresponding to the user terminal according to the preset encrypted tunnel information; The processing module is configured to receive or send service messages through the target encrypted tunnel using the target worker thread; The methods for obtaining the preset encrypted tunnel information include: Receive service request messages sent by each user terminal, wherein each service request includes the corresponding service identification information of each user terminal; Based on the service identification information, encrypted tunnels are established between each user terminal to construct the preset encrypted tunnel information; wherein, the encrypted tunnel corresponds to the IP address configured on the N6 interface, and the N6 interface is configured with at least two IP addresses; Create a worker thread that corresponds to the IP address; A mapping relationship is established based on the encrypted tunnel, the IP address, and the corresponding worker thread.

7. An electronic device comprising at least a memory, a processor, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is in operation, the processor communicates with the memory via the bus, and when the machine-readable instructions are executed by the processor, the steps of the processing method as described in any one of claims 1 to 5 are implemented.

8. A storage medium storing a computer program, which, when executed by a processor, implements the steps of the processing method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Communication method and device, user plane network element and storage medium

    CN114650197A

  • Method and device for establishing multiple communication tunnels, medium and electronic equipment

    CN115834292A