5G wireless network connection method and electronic device
Through the 5G wireless network connection method, the AAA server and core network elements are used to control the wireless connection between government and enterprise remote terminals and the intranet, solving the problem of network interruption caused by optical cable breakage, achieving rapid and unsensing switching, and ensuring the continuity of high-bandwidth and large-traffic services.
Patent Information
- Application Number
- CN202111643178.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-29
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2041-12-29
AI Technical Summary
When an emergency causes optical cable or network cable to break, the existing technology needs to repair physical lines or manually build temporary wired communication methods. The recovery time is long and costly, and it is impossible to quickly establish a wireless private network connection between the remote terminal of the government and enterprise intranets, affecting the continuity of high bandwidth and large traffic services.
Through the 5G wireless network connection method, the AAA server is used to authenticate and generate authorization information. The core network element controls the user's station equipment to establish a wireless network connection with the government and enterprise intranets, achieving fast and unsensed handover, and establishing a virtual private dial-up network channel with 5G base stations, core network elements, user plane function equipment and network servers.
When the wired connection is interrupted, the terminal device hanging down can quickly switch to 5G wireless network communication, ensuring the continuity of high bandwidth and large traffic services, avoiding additional configurations, and shortening fault repair and network re-access time.
Smart Images

Figure CN116419422B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a 5G wireless network connection method and electronic device. Background Art
[0002] With the rapid development of network technology, the demand for government and enterprise dedicated line services is increasing, requiring carrier-grade, highly reliable infrastructure for emergency communications, image access, video conferencing, and other services. Currently, the network architecture of government and enterprise dedicated lines generally relies on wired connections. For example, the dedicated network connection between government and enterprise remote terminals and the government and enterprise intranet primarily relies on fiber optic cables or optical fibers. However, emergencies such as heavy rain and flooding can cause fiber optic cables or network cables to break in certain sections, resulting in network outages and impacting the normal use of government and enterprise customers' communication services.
[0003] At present, in response to the above-mentioned emergencies, when the optical cable breaks, if you want to maintain network connection, you need to repair the physical line or manually build a temporary wired communication method. Under harsh environmental conditions, the recovery time of wired networks such as optical cables or network cables is long and the cost is high.
[0004] In view of this, how to quickly establish a wireless private network connection between government and enterprise remote terminals and government and enterprise intranets when the optical cable or network cable is interrupted due to a fault has become a technical problem that needs to be solved urgently. Summary of the Invention
[0005] In view of this, an embodiment of the present application provides a 5G wireless network connection method and electronic device, which enables enterprise users to switch to 5G wireless network communication in a fast and imperceptible manner when the wired connection is interrupted.
[0006] In the first aspect, an embodiment of the present application provides a method for 5G wireless network connection, the method including: an authentication, authorization, and billing AAA server receives a connection authentication request for a wireless network sent by a user premises equipment when a wired connection fails, wherein the wired connection is a connection between the user premises equipment and a government or enterprise intranet; the AAA server performs identity authentication on the user premises equipment based on the connection authentication request, generates authorization information after successful identity authentication, and sends the authorization information to a core network network element, so that the core network network element controls the user premises equipment to establish a network connection with the government or enterprise intranet through the network server based on the authorization information.
[0007] In certain embodiments of the present application, the AAA server is a 5G virtual private dial-up network service AAA server, the core network network element is a session management function or an access and mobility management function, the user plane function device is a user plane function device sunk into the 5G core network, the network server is a second-layer tunnel protocol network server, and the network connection established between the user plane function device and the network server is a virtual private dial-up network channel.
[0008] In certain embodiments of the present application, the wired connection is a connection between a user premises equipment and a government or enterprise intranet through a wired relay device. The connection authentication request includes the IP address of the wired relay device and an emergency access status identification number. The AAA server performs identity authentication on the user premises equipment based on the connection authentication request, including: the AAA server determines that the user premises equipment is in an emergency access state based on the IP address of the wired relay device and the emergency access status identification number, and generates authorization information for the emergency access state after successful authentication.
[0009] In the second aspect, an embodiment of the present application provides a 5G wireless network connection method, including: a core network network element receives a first connection authentication request for a wireless network sent by a user premises equipment; the core network network element converts the first connection authentication request into a second connection authentication request readable by an AAA server, and then sends the second connection authentication request to the AAA server; the core network network element receives authorization information sent by the AAA server; the core network network element extracts the network server connection attributes in the authorization information and sends it to the user plane functional device to control the user plane functional device to establish a network connection with the network server; the core network network element extracts the configuration attributes of the user premises equipment in the authorization information and sends it to the user premises equipment to control the user premises equipment to establish a network connection with the user plane functional device.
[0010] In certain embodiments of the present application, the core network network element is a session management function or an access and mobility management function, the user plane function device is a user plane function device sunk into the 5G core network, the network server is a second-layer tunnel protocol network server, and the network connection established between the user plane function device and the network server is a virtual private dial-up network channel. The network server connection attribute content includes the IP address and connection key of the network server, and the configuration attributes of the user premises equipment include the allocation of an IPv4 address or an IPv6 address, the IP address of the user plane function device, and the IP address of the DNS server.
[0011] On the third aspect, an embodiment of the present application provides a 5G wireless network connection method, including: when the wired connection fails, the user premises equipment sends a wireless network connection authentication request to the core network network element, wherein the wired connection is the connection between the user premises equipment and the government and enterprise intranet; the user premises equipment receives the authorization message sent by the core network network element; the user premises equipment establishes a wireless network connection with the government and enterprise intranet through the network server.
[0012] In certain embodiments of the present application, before the customer premises equipment sends a wireless network connection authentication request to the core network element when the wired connection fails, it also includes: the customer premises equipment judges the wired connection, and if the wired connection is interrupted, sends a wireless network connection authentication request.
[0013] In certain embodiments of the present application, the authorization information is generated by the AAA server based on the customer premises equipment identification number included in the connection authentication request and the USIM card number in the customer premises equipment. The authorization message information includes an IPv4 address or an IPv6 address. The customer premises equipment establishes a network connection with the network server based on the configured IPv4 address or IPv6 address.
[0014] In certain embodiments of the present application, a user premises equipment establishes a wireless network connection with a government or enterprise intranet through a network server, including: the user premises equipment establishes a wireless network connection with a user plane functional device based on an authorization message; the user premises equipment establishes a wireless network connection with a network server through a user plane functional device; the user premises equipment establishes a wireless network connection with a government or enterprise intranet through a network server.
[0015] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising: a processor; and a memory for storing processor-executable instructions, wherein the processor is used to execute the 5G wireless network connection method of the first, second or third aspect above.
[0016] An embodiment of the present application provides a method and electronic device for connecting to a 5G wireless network. The method receives a connection authentication request for a wireless network sent by a user premises equipment through an AAA server and performs identity authentication on the user premises equipment. After successful authentication, authorization information is generated and the authorization information is sent to a core network network element, so that the core network network element controls the user premises equipment to establish a network connection with the government and enterprise intranet through a network server, so that the downstream terminal equipment can switch to 5G wireless network communication in a fast and imperceptible manner when the wired connection is interrupted. There is no need for additional configuration of the downstream terminal equipment and the user premises equipment, and the communication recovery time is fast, thereby ensuring the continuity of the high-bandwidth and high-traffic communication services of the downstream terminal equipment. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1It is a structural diagram of a wired connection network provided by an exemplary embodiment of the present application.
[0018] Figure 2 It is a structural diagram of a wired connection network provided by another exemplary embodiment of the present application.
[0019] Figure 3 It is a flowchart of a 5G wireless network connection method provided by another exemplary embodiment of the present application.
[0020] Figure 4 It is a flowchart of a 5G wireless network connection method provided by another exemplary embodiment of the present application.
[0021] Figure 5 It is a flowchart of a 5G wireless network connection method provided by another exemplary embodiment of the present application.
[0022] Figure 6 This is a flowchart of a downstream terminal device accessing a network provided by an exemplary embodiment of the present application.
[0023] Figure 7 It is a flowchart of a method for 5G wireless network connection provided by another exemplary embodiment of the present application.
[0024] Figure 8 It is a structural diagram of the AAA service provided by an exemplary embodiment of the present application.
[0025] Figure 9 It is a structural diagram of a core network element device provided by an exemplary embodiment of the present application.
[0026] Figure 10 It is a structural diagram of a customer premises equipment provided by an exemplary embodiment of the present application.
[0027] Figure 11 is a block diagram of an electronic device provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0028] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0029] Government and enterprise private networks can provide government and enterprise customers with a more secure, reliable, and high-speed dedicated data channel environment. However, in scenarios where the optical cable is broken and a wired connection cannot be used, if you want to maintain network connection, you need to repair the physical line or manually build a temporary wired communication method, which has the disadvantages of being time-consuming and costly. If a wireless connection is adopted, a temporary network connection can be achieved quickly. However, in the case of a 4G network, since all services must be centrally routed to the operator's provincial core network and the 4G network bandwidth is small, there will be problems such as large latency, high bit error rate, and unsatisfactory customer perception. In addition, when the terminal equipment under the government and enterprise is connected to the network through VPDN in an emergency, cumbersome configuration is required before it can be used, which greatly affects the emergency support services of the government and enterprise private lines.
[0030] With the maturity of 5G network technology, the use of 5G government and enterprise dedicated line emergency terminals has the advantage of rapid deployment. When the optical cable fails, wireless access is used to replace the original wired connection, providing temporary emergency guarantees to achieve wireless network communication, minimize the time for fault repair and network re-access, and ensure the continuity of customer services, especially supporting the normal use of high-bandwidth, high-traffic services.
[0031] In the embodiments of the present application, multiple English abbreviations are involved. First, the English full names and Chinese full names corresponding to the English abbreviations involved in the embodiments of the present application are explained in the following table.
[0032]
[0033]
[0034] Figure 1 This is a schematic diagram of a wired connection network architecture provided by an exemplary embodiment of the present application. Figure 1 As shown, when the optical cable or network cable is connected normally, the terminal equipment and wired relay equipment of the government and enterprise remotely connected to the government and enterprise intranet are connected by optical cable or network cable to realize data communication between the terminal equipment and the government and enterprise intranet remotely connected to the government and enterprise.
[0035] Figure 2 FIG. 1 is a structural diagram of a wired connection network provided by another exemplary embodiment of the present application. Figure 2 As shown in the figure, when the optical cable or network cable connection is normal, the terminal equipment remotely connected to the government and enterprise, 5G CPE, wired relay equipment and the government and enterprise intranet are connected by optical cables or network cables to realize data communication between the terminal equipment remotely connected to the government and enterprise and the government and enterprise intranet.
[0036] An embodiment of the present application provides a method for 5G wireless network connection. When an optical cable or network cable fails and the wired connection cannot be used normally, in order to ensure the continuity of high-bandwidth and high-traffic services for government and enterprise users, a wireless network architecture is used to enable government and enterprise users to switch their wired services to a 5G wireless private network in a non-perceptual manner, thereby ensuring the normal use of customer services.
[0037] Figure 3 It is a flowchart of a 5G wireless network connection method provided by another exemplary embodiment of the present application. Figure 3 The method is executed by a server, such as an authentication, authorization, or accounting AAA server. Figure 3 As shown, the 5G wireless network connection method includes the following contents.
[0038] 310: The authentication, authorization, and accounting AAA server receives a wireless network connection authentication request sent by the customer premises equipment when a wired connection fails, where the wired connection is a connection between the customer premises equipment and a government or enterprise intranet.
[0039] Customer premises equipment, abbreviated as CPE, can also be called customer terminal equipment. It is installed and deployed on the government and enterprise user side. CPE can have downstream terminal devices, which can be connected to the CPE network through a wired connection.
[0040] Under normal circumstances, connected terminal devices access the network via a wired connection. When a wired connection fails, such as when the optical or network cable breaks, the CPE sends a connection authentication request to the AAA server. This connection authentication request can also be a first request sent by the connected terminal device to the CPE when accessing the network, followed by the CPE sending the connection authentication request to the AAA server. This connection authentication request can also be an access request, an authentication request, an address allocation request, or other information indicating the intention to access the network. For simplicity, these are collectively referred to as connection authentication requests.
[0041] In one embodiment of the present application, the CPE device is a 5G CPE. The 5G CPE wirelessly accesses a nearby 5G base station and sends a connection authentication request. The 5G base station forwards the connection authentication request to the 5G core network, and the 5G core network sends the connection authentication request to the AAA server.
[0042] 320: The AAA server authenticates the user premises equipment based on the connection authentication request. After successful authentication, it generates authorization information and sends the authorization information to the core network element. The core network element controls the user premises equipment to establish a network connection with the government and enterprise intranet through the network server based on the authorization information.
[0043] AAA is the abbreviation of Authentication, Authorization, and Accounting. It is a security management mechanism for access control in network security, providing three security services: authentication, authorization, and accounting.
[0044] The AAA server receives the connection authentication request, which includes key parameters for identity authentication. The AAA server authenticates the CPE to determine the legitimacy of its access to the government or enterprise intranet and generates authentication results, including an indication of whether the authentication was successful. If the CPE successfully authenticates, the AAA server generates authorization information, which includes the authentication result and key parameters required for the CPE to connect to the network.
[0045] It should be understood that the information of the authentication result can be carried in the authentication return message, and it is not a specific message. The authentication return message can be a variety of types of messages that can carry the information of the authentication result. As long as the message can carry the information of the authentication result, it can serve as an authentication return message.
[0046] In one embodiment of the present application, the AAA server performs identity authentication on the customer premises equipment based on a connection authentication request, generates authorization information after successful identity authentication, and sends the authorization information to the core network network element, so that the core network network element controls the customer premises equipment to establish a network connection with the user plane function based on the authorization information, and at the same time controls the user plane function to establish a network connection with the network server, so that the customer premises equipment establishes a network connection with the government and enterprise intranet through the network connection established by the user plane function and the network server.
[0047] Specifically, the 5G AAA server receives the network access authentication request sent by the 5G CPE and performs identity authentication on the 5G CPE. After successful identity authentication, authorization information is generated. The 5G AAA server sends the authorization information to the 5G core network element. The core network element sends the authorization information to the user plane functional device to establish a network connection between the user plane functional device and the network server. At the same time, the core network element sends the authorization information to the 5G CPE to establish a network connection between the 5G CPE and the user plane functional device. The 5G CPE establishes a network connection with the network server through the user plane functional device, thereby enabling the 5G CPE to establish a network connection with the government and enterprise intranet through the network server.
[0048] It can be seen from this that the embodiment of the present application receives the connection authentication request for the wireless network sent by the user premises equipment through the authentication, authorization, and billing AAA server and performs identity authentication on the user premises equipment. After successful authentication, authorization information is generated and sent to the core network network element, so that the core network network element controls the user premises equipment to establish a network connection with the government and enterprise intranet through the network server, so that the terminal equipment connected to the network can switch to the 5G wireless network communication in a fast and imperceptible manner when the wired connection is interrupted. There is no need for additional configuration of the user premises equipment and the terminal equipment connected to the network, and the communication recovery time is fast, thereby ensuring the continuity of the high-bandwidth and high-traffic communication services of the terminal equipment connected to the network.
[0049] In one embodiment of the present application, the AAA server is a 5G virtual private dial-up network service AAA server, the core network network element is a session management function or an access and mobility management function, the user plane function device is a user plane function device sunk into the 5G core network, the network server is a second layer tunnel protocol network server, and the network connection established by the user plane function device and the network server is a virtual private dial-up network channel.
[0050] In this embodiment, the 5G VPDN AAA server receives a connection authentication request sent by the CPE, which can be sent by the CPE to the 5G core network AMF or SMF through the 5G base station. The 5G VPDN AAA server receives the connection authentication request sent by the 5G core network AMF or SMF, performs identity authentication on the CPE, and generates authorization information if the authentication is successful. The authorization information is sent to the sinking UPF, so that the CPE establishes a virtual private dial-up network channel with the network server through the sinking UPF, and the network server is an LNS device.
[0051] In one embodiment of the present application, the wired connection is a connection between a user premises equipment and a government or enterprise intranet through a wired relay device. The connection authentication request includes the IP address of the wired relay device and an emergency access status identification number. The AAA server performs identity authentication on the user premises equipment based on the connection authentication request, including: the AAA server determines that the user premises equipment is in an emergency access state based on the IP address of the wired relay device and the emergency access status identification number, and generates authorization information for the emergency access state after successful authentication.
[0052] In this embodiment, the connection authentication request sent by the 5G CPE includes the IP address of the wired relay device and the emergency access status identification number. The 5G VPDN AAA server determines whether the connection authentication request is in the emergency access state based on the information recorded in the IP address of the wired relay device and the emergency access status identification number. If the connection authentication request is in the emergency access state, authorization information is generated, and the authorization information is used for network connection in the emergency access state.
[0053] Optionally, the connection authentication request sent by the 5G CPE may include the user premises equipment identification number, the USIM card number in the user premises equipment, and the authorization information includes the IPv4 address or IPv6 address assigned to the user premises equipment, the IP address of the user plane functional device, and the information of the network server assigned to the user plane functional device.
[0054] In one embodiment of the present application, the AAA server performs service authorization based on a virtual private dial-up network of the second layer tunnel protocol. The core network network element controls the UPF device to establish a virtual private tunnel with the network server LNS through the LNS server-related information in the service authorization issued by AAA, using the second layer tunnel protocol. At the same time, the core network network element controls the CPE to establish a wireless network connection with the UPF device through the IP address, session duration, DNS server address, UPF address and other related information in the service authorization issued by AAA.
[0055] Optionally, the 5G VPDN AAA server has the function of completing some of the terminal device information to support the end-to-end business process of the 5G VPDN. Specifically, the 5G VPDN AAA server supports automatic identification of whether the terminal device information reported by the CPE in the connection authentication request is missing. If the connection authentication request sent by the CPE cannot carry information such as the user name and domain name, the 5G VPDN AAA server can send relevant information in the authorization information according to the preset policy; if the connection authentication request sent by the CPE can carry information such as the user name and domain name, the 5G VPDN AAA server does not need to send relevant information in the authorization information.
[0056] In one implementation, a network server, such as an LNS, configures the CPE's IMSI number and the network segment address of the terminal device connected to the CPE, and then generates a routing table entry behind the CPE. The network segment address of the terminal device connected to the CPE includes the IP address assigned by the CPE through DHCP.
[0057] The IP address used by the CPE to access the network is not necessarily fixed, but the IMSI number corresponding to the CPE remains unchanged. Therefore, the post-routing uses the CPE IMSI and the network segment address of the terminal device connected to the CPE to form the CPE post-routing forwarding table entry.
[0058] Figure 4 FIG. 1 is a flow chart of a 5G wireless network connection method provided by another exemplary embodiment of the present application. Figure 4 As shown, the 5G wireless network connection method includes the following contents.
[0059] 410: The core network element receives a first wireless network connection authentication request sent by the customer premises equipment.
[0060] The first connection authentication request is sent by the customer premises equipment in an emergency state when a wired connection network of the customer premises equipment fails.
[0061] 420: The core network element converts the first connection authentication request into a second connection authentication request readable by the AAA server, and then sends the second connection authentication request to the AAA server.
[0062] The core network element converts the first connection authentication request into a second authentication request message based on the Remote Authentication Dial-In User Service (RADIUS) protocol. The AAA server performs identity authentication on the customer premises equipment based on the second authentication request message and generates authorization information if the identity authentication is successful.
[0063] 430: The core network element receives the authorization information sent by the AAA server.
[0064] 440: The core network element extracts the network server connection attribute from the authorization information and sends it to the user plane functional device to control the user plane functional device to establish a network connection with the network server.
[0065] 450: The core network element extracts the configuration attributes of the customer premises equipment from the authorization information and sends them to the customer premises equipment, controlling the customer premises equipment to establish a network connection with the user plane functional device.
[0066] According to the method of this embodiment, the core network network element sends a connection authentication request to the AAA server, receives authorization information returned by the AAA server, sends the configuration attributes of the customer premises equipment in the authorization information to the CPE device, and simultaneously sends the network server connection attributes in the authorization information to the user plane function device, so that the core network network element controls the customer premises equipment to establish a network connection with the user plane function based on the authorization information, and simultaneously controls the user plane function to establish a network connection with the network server, thereby enabling the customer premises equipment to establish a network connection with the government and enterprise intranet through the network connection established by the user plane function and the network server.
[0067] It can be seen from this that this method allows the downstream terminal devices to switch to 5G wireless network communication in a fast and imperceptible manner when the wired connection is interrupted. No additional configuration is required for the user premises equipment and the downstream terminal devices, and the communication recovery time is fast, thereby ensuring the continuity of the high-bandwidth, high-traffic communication services of the downstream terminal devices.
[0068] Furthermore, the core network network element is a session management function or an access and mobility management function, the user plane functional device is a user plane functional device sunk into the 5G core network, the network server is a second-layer tunneling protocol network server, and the network connection established between the user plane functional device and the network server is a virtual private dial-up network channel. The network server connection attributes include the IP address and connection key of the network server, and the configuration attributes of the user premises equipment include the allocation of an IPv4 address or an IPv6 address, the IP address of the user plane functional device, and the DNS server IP address.
[0069] In this embodiment, the 5G core network AMF or SMF sends a connection authentication request, receives the authorization information sent by the 5G VPDN AAA server, and the 5G core network AMF or SMF selects the sinking UPF to send an authorization message to establish a virtual private dial-up network channel between the UPF and the LNS.
[0070] Figure 5 FIG. 1 is a flow chart of a 5G wireless network connection method provided by another exemplary embodiment of the present application. Figure 5 As shown, the 5G wireless network connection method includes the following contents.
[0071] 510: When the wired connection of the customer premises equipment fails, the customer premises equipment sends a wireless network connection authentication request to the core network element, where the wired connection is the connection between the customer premises equipment and the government or enterprise intranet.
[0072] Customer Premises Equipment (CPE), installed and deployed at government and enterprise customer locations, connects to multiple downstream devices. When wired connections are functioning properly, these devices access the government and enterprise intranet through the CPE and wired relay equipment. If a wired connection fails and becomes unusable, the CPE detects the faulty link and automatically switches between wired and wireless connections, ensuring seamless transitions. At this point, the CPE sends a connection authentication request to the core network element. This authentication message verifies that the CPE is legitimately connecting to the wireless network.
[0073] 520: The customer premises equipment receives the authorization message sent by the core network element.
[0074] 530: The user premises equipment establishes a wireless network connection with the government and enterprise intranet through the network server.
[0075] The CPE device provides routing functions when connected to a wired network. The CPE device can also assign IP addresses to downstream terminal devices. Specifically, the CPE can assign IP addresses to downstream devices through the DHCP function to implement access requests from downstream terminal devices to the government and enterprise intranet.
[0076] More specifically, when the wired connection between the terminal equipment under the government and enterprise and the government and enterprise intranet fails and cannot be used, the CPE automatically switches to the wireless connection line, and government and enterprise users use the CPE for internal networking. The CPE is equipped with a SIM card, and the SIM card number is configured with a DNN identifier. The CPE establishes a signal connection with the base station through the SIM card and sends a connection authentication request. When the connection authentication request is successfully authorized, a VPDN tunnel is established between the CPE and the network server to realize data transmission.
[0077] It can be seen from this that the method provided in the embodiment of the present application has the ability to perceive faulty links when an emergency situation occurs, and has an automatic switching function, ensuring seamless switching of wired and wireless connections, ensuring the continuity of network connections, and ensuring that the services of downstream terminal devices are not affected.
[0078] In one embodiment of the present application, before the customer premises equipment sends a wireless network connection authentication request to the core network element when the wired connection fails, it also includes: the customer premises equipment judges the wired connection, and if the wired connection is interrupted, sends a wireless network connection authentication request.
[0079] Figure 6 This is a flowchart of a downstream terminal device accessing a network provided by an exemplary embodiment of the present application.
[0080] like Figure 6 As shown, in this embodiment, the process of the connected terminal device accessing the network includes the following content.
[0081] 610: The CPE receives a connection authentication request for accessing the government or enterprise intranet from a downstream terminal device.
[0082] It should be understood that, for the convenience of description, in this embodiment, the user terminal may also be used to represent the terminal device connected to the CPE.
[0083] 620: The CPE determines whether the network connection is in an emergency state. If so, the process proceeds to step 630; if not, the process proceeds to step 640.
[0084] 630: CPE switches the wired connection to a wireless connection and sends a connection authentication request. For details, refer to Figure 5 The method described in the embodiment.
[0085] 640: The CPE maintains a wired connection and does not need to switch network connections.
[0086] 650: The attached terminal device enables access to the government and enterprise intranet.
[0087] In one embodiment of the present application, the authorization information is generated by the AAA server based on the customer premises equipment identification number included in the connection authentication request and the USIM card number in the customer premises equipment. The authorization message information includes an IPv4 address or an IPv6 address. The customer premises equipment establishes a network connection with the network server based on the configured IPv4 address or IPv6 address.
[0088] In one embodiment of the present application, a user premises equipment establishes a wireless network connection with a government or enterprise intranet through a network server, including: the user premises equipment establishes a wireless network connection with a user plane functional device based on an authorization message; the user premises equipment establishes a wireless network connection with a network server through a user plane functional device; the user premises equipment establishes a wireless network connection with a government or enterprise intranet through a network server.
[0089] Specifically, the core network element controls the UPF device to establish a virtual private tunnel with the network server LNS through the LNS server-related information in the service authorization issued by AAA, such as the IP address of the network server, the connection key, etc., using the second layer tunnel protocol. At the same time, the core network element controls the CPE to establish a wireless network connection with the UPF device through the user premises equipment IP address, session duration, DNS server address, UPF address and other related information in the authorization message generated by AAA.
[0090] It should be noted that after the LNS is configured with the CPE's IMSI number and the network segment address of the terminal device connected to the CPE, the LNS generates a routing table entry behind the CPE. The network segment address of the terminal device connected to the CPE includes the IP address assigned by the CPE through the DHCP function.
[0091] The IP address used by the CPE to access the network is not necessarily fixed, but the IMSI number corresponding to the CPE remains unchanged. Therefore, the post-routing uses the CPE IMSI and the network segment address of the terminal device connected to the CPE to form the CPE post-routing forwarding table entry.
[0092] Figure 7 FIG. 1 is a flow chart of a method for connecting a 5G wireless network provided by another exemplary embodiment of the present application. Figure 7 As shown, the method includes the following contents.
[0093] 710: The 5G CPE sends a wireless network connection authentication request to the 5G core network.
[0094] 720: The 5G core network forwards the connection authentication request to the 5G VPDN AAA server.
[0095] For details on the implementation of steps 710 and 720, please refer to Figure 5 and Figure 6 Related descriptions in the illustrated embodiments.
[0096] 730: 5G VPDN AAA generates authorization information and completes CPE information.
[0097] 740: The 5G core network sends authorization information to the 5G CPE to establish a network connection between the 5G CPE and the UPF.
[0098] 750: The 5G core network selects the downlink UPF based on the authorization information, so that the UPF selects the LNS and establishes a VPDN connection channel.
[0099] 760: 5G CPE is connected to the government and enterprise intranet through UPF and LNS.
[0100] 770: The downstream terminal device sends data through the 5G CPE.
[0101] For details of step 730, please refer to Figure 3 The details are described in the examples and will not be expanded here.
[0102] For details of steps 740 to 750, please refer to Figure 4 The details are described in the examples and will not be expanded here.
[0103] Figure 8 It is a structural diagram of the AAA service provided by an exemplary embodiment of the present application.
[0104] In an embodiment of the present application, an AAA server 800 is provided. Figure 8 As shown, the AAA server 800 includes: a receiving module 810, which is used to receive a connection authentication request for a wireless network sent by a user premises equipment when a wired connection fails, wherein the wired connection is a connection between the user premises equipment and a government or enterprise intranet; an authentication module 820, which is used to authenticate the identity of the user premises equipment based on the connection authentication request, generate authorization information after the identity authentication is successful, and send the authorization information to the core network network element, so that the core network network element controls the user premises equipment to establish a network connection with the government or enterprise intranet through the network server based on the authorization information.
[0105] According to an embodiment of the present application, the authentication module 820 is further configured to determine whether the customer premises equipment is in an emergency access state based on the IP address of the wired relay device and the emergency access state identification number, and generate the authorization information for the emergency access state after successful authentication.
[0106] It should be understood that the specific working process and functions of the receiving module 810 and the authentication module 820 in the above embodiment can refer to the above Figure 3 To avoid repetition, the description of the 5G wireless network connection method provided in the embodiment will not be repeated here.
[0107] According to the AAA server 800 provided in the embodiment of the present application, a connection authentication request for a wireless network sent by a user premises equipment is received and the identity of the user premises equipment is authenticated. After successful authentication, authorization information is generated and the authorization information is sent to the core network network element, so that the core network network element controls the user premises equipment to establish a network connection with the government and enterprise intranet through the network server, so that the terminal device connected to the network can switch to the 5G wireless network communication in a fast and imperceptible manner when the wired connection is interrupted. No additional configuration is required for the user premises equipment and the terminal device connected to the network, and the communication recovery time is fast, thereby ensuring the continuity of the high-bandwidth and high-traffic communication services of the terminal device connected to the network.
[0108] Figure 9 This is a schematic diagram of the structure of a core network element device provided by an exemplary embodiment of the present application. Figure 9 As shown, the core network element device 900 includes: a first receiving module 910 , a first sending module 920 , a second receiving module 930 , a second sending module 940 and a third sending module 950 .
[0109] The first receiving module 910 is configured to receive a wireless network connection authentication request from a customer premises equipment (CPE). The first sending module 920 is configured to convert the connection authentication request into a second connection authentication request readable by the AAA server and then send the second connection authentication request to the AAA server. The second receiving module 930 is configured to receive authorization information from the AAA server. The second sending module 940 is configured to extract network server connection attributes from the authorization information and send them to a user plane functional device to control the user plane functional device to establish a network connection with the network server. The third sending module 950 is configured to extract CPE configuration attributes from the authorization information and send them to the CPE to control the CPE to establish a network connection with the user plane functional device.
[0110] It should be understood that the specific working processes and functions of the first receiving module 910, the first sending module 920, the second receiving module 930, the second sending module 940 and the third sending module 950 in the above embodiment can be referred to above. Figure 4 To avoid repetition, the description of the 5G wireless network connection method provided in the embodiment will not be repeated here.
[0111] According to the core network element device provided in the embodiment of the present application, the downstream terminal device can switch to 5G wireless network communication in a fast and imperceptible manner when the wired connection is interrupted, without the need for additional configuration of the user premises equipment and the downstream terminal device, and the communication recovery time is fast, thereby ensuring the continuity of the high-bandwidth, high-traffic communication services of the downstream terminal device.
[0112] Figure 10 FIG. 1 is a structural diagram of a user premises equipment provided by an exemplary embodiment of the present application. Figure 10 As shown, the CPE 1000 includes a sending module 1010 and a receiving module 1020 .
[0113] The sending module 1010 is used to send a wireless network connection authentication request to the core network element when a wired connection fails, wherein the wired connection is the connection between the customer premises equipment and the government and enterprise intranet. The receiving module 1020 is used to receive the authorization message sent by the core network element.
[0114] According to an embodiment of the present application, the CPE 1000 further includes a determination module 1030 configured to determine the wired connection and send a wireless network connection authentication request if the wired connection is interrupted.
[0115] The user premises equipment 1000 provided in accordance with the embodiment of the present application can realize fault link perception when an emergency occurs and has an automatic switching function, thereby ensuring seamless switching of wired and wireless connections, ensuring network connection continuity, and ensuring that the services of downstream terminal devices are not affected.
[0116] Figure 11 is a block diagram of an electronic device provided by an exemplary embodiment of the present application.
[0117] Reference Figure 11 , the electronic device 1100 includes a processing component 1110, which further includes one or more processors, and a memory resource represented by a memory 1120 for storing instructions executable by the processing component 1110, such as applications. The applications stored in the memory 1120 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 1110 is configured to execute instructions to perform the above Figure 3 , Figure 4 or Figure 5 The 5G wireless network connection method.
[0118] The electronic device 1100 may further include a power supply component configured to perform power management of the electronic device 1100, a wired or wireless network interface configured to connect the electronic device 1100 to a network, and an input / output (I / O) interface. The electronic device 1100 may be operated based on an operating system stored in the memory 1120, such as Windows Server 2003. TM , MacOS X TM , Unix TM , Linux TM , FreeBSD TM or similar.
[0119] A non-temporary computer-readable storage medium, when the instructions in the storage medium are executed by the processor of the above-mentioned electronic device 1100, enables the above-mentioned electronic device 1100 to execute a method for 5G wireless network connection, including: an authentication, authorization, and billing AAA server receives a connection authentication request for a wireless network sent by a user premises equipment when a wired connection fails, wherein the wired connection is a connection between the user premises equipment and a government or enterprise intranet; the AAA server performs identity authentication on the user premises equipment based on the connection authentication request, generates authorization information after the identity authentication is successful, and sends the authorization information to a core network network element, so that the core network network element controls the user premises equipment to establish a network connection with the government or enterprise intranet through the network server based on the authorization information. Alternatively, when the instructions in the storage medium are executed by the processor of the above-mentioned user premises equipment 1000, the above-mentioned user premises equipment 1000 is enabled to execute a method for connecting to a 5G wireless network, including: the core network network element receives a connection authentication request for a wireless network sent by the user premises equipment; the core network network element converts the connection authentication request into a second connection authentication request readable by the AAA server, and then sends the second connection authentication request to the AAA server; the core network network element receives authorization information sent by the AAA server; the core network network element extracts the network server connection attributes in the authorization information and sends it to the user plane functional device to control the user plane functional device to establish a network connection with the network server; the core network network element extracts the configuration attributes of the user premises equipment in the authorization information and sends it to the user premises equipment to control the user premises equipment to establish a network connection with the user plane functional device. Alternatively, when the instructions in the storage medium are executed by the processor of the above-mentioned user premises equipment 1000, the above-mentioned user premises equipment 1000 is capable of executing a 5G wireless network connection method, including: when the wired connection fails, the user premises equipment sends a wireless network connection authentication request to the core network network element, wherein the wired connection is the connection between the user premises equipment and the government and enterprise intranet; the user premises equipment receives the authorization message sent by the core network network element; the user premises equipment establishes a wireless network connection between the government and enterprise intranet through the network server
[0120] All of the above optional technical solutions can be arbitrarily combined to form optional embodiments of the present application, and will not be described in detail here.
[0121] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0122] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0123] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0124] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0125] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0126] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program check codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0127] It should be noted that, in the description of this application, the terms "first," "second," "third," etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance. In addition, in the description of this application, unless otherwise specified, "plurality" means two or more.
[0128] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A 5G wireless network connection method, characterized in that: include: The authentication, authorization, and accounting AAA server receives a wireless network connection authentication request sent by a customer premises equipment when a wired connection fails, wherein the wired connection is a connection between a terminal device connected to the customer premises equipment and a government or enterprise intranet; The AAA server performs identity authentication on the user premises equipment based on the connection authentication request, generates authorization information after successful identity authentication, and sends the authorization information to the core network network element, so that the core network network element controls the user premises equipment to establish a network connection with the government and enterprise intranet through the network server based on the authorization information.
2. The method according to claim 1, characterized in that The AAA server is a 5G virtual private dial-up network service AAA server, the core network network element is a session management function or an access and mobility management function, the user plane function device is a user plane function device sunk into the 5G core network, the network server is a second layer tunneling protocol network server, and the network connection established between the user plane function device and the network server is a virtual private dial-up network channel.
3. The method according to claim 1, characterized in that The wired connection is a connection between the customer premises equipment and the government and enterprise intranet through a wired relay device, the connection authentication request includes the IP address of the wired relay device and an emergency access status identification number, and the AAA server performs identity authentication on the customer premises equipment based on the connection authentication request, including: The AAA server determines that the customer premises equipment is in the emergency access state based on the IP address of the wired relay device and the emergency access state identification number, and generates the authorization information for the emergency access state after successful authentication.
4. A 5G wireless network connection method, characterized in that: include: The core network element receives a first connection authentication request for a wireless network sent by a customer premises equipment; the first connection authentication request is sent by the customer premises equipment when a wired connection network of the customer premises equipment fails; The core network element converts the first connection authentication request into a second connection authentication request readable by the AAA server, and then sends the second connection authentication request to the AAA server; The core network element receives the authorization information sent by the AAA server; The core network element extracts the network server connection attribute in the authorization information and sends it to the user plane function device to control the user plane function device to establish a network connection with the network server; The core network element extracts the configuration attributes of the customer premises equipment from the authorization information and sends the attributes to the customer premises equipment, so as to control the customer premises equipment to establish a network connection with the user plane functional device.
5. The method according to claim 4, characterized in that The core network network element is a session management function or an access and mobility management function, the user plane function device is a user plane function device sunk to the 5G core network, the network server is a second-layer tunneling protocol network server, and the network connection established between the user plane function device and the network server is a virtual private dial-up network channel. The network server connection attribute content includes the IP address and connection key of the network server, and the configuration attributes of the customer premises equipment include the allocation of an IPv4 address or an IPv6 address, the IP address of the user plane function device, and the DNS server IP address.
6. A 5G wireless network connection method, characterized in that: include: The customer premises equipment sends a wireless network connection authentication request to the core network element when the wired connection fails, wherein the wired connection is the connection between the terminal device connected to the customer premises equipment and the government and enterprise intranet; The customer premises equipment receives an authorization message sent by a core network element; The user premises equipment establishes a wireless network connection with the government and enterprise intranet through a network server.
7. The method according to claim 6, characterized in that Before the customer premises equipment sends a wireless network connection authentication request to a core network element when a wired connection fails, the method further includes: The customer premises equipment determines the wired connection, and if the wired connection is interrupted, sends a connection authentication request to the wireless network.
8. The method according to claim 6, characterized in that The authorization information is generated by the AAA server based on the customer premises equipment identification number included in the connection authentication request and the USIM card number in the customer premises equipment. The authorization message information includes an IPv4 address or an IPv6 address. The customer premises equipment establishes a network connection with the network server based on the configured IPv4 address or IPv6 address.
9. The method according to claim 6, characterized in that The customer premises equipment establishes a wireless network connection with the government and enterprise intranet through a network server, including: The customer premises equipment establishes a wireless network connection with a user plane function device based on the authorization message; The customer premises equipment establishes a wireless network connection with the network server through the user plane function device; The user premises equipment establishes a wireless network connection with the government and enterprise intranet through the network server.
10. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor, The processor is configured to execute the 5G wireless network connection method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Method, device and system for network access
CN109391940A