Implementation method, system, electronic equipment and medium of a telecommunication identification network
By extending the TSRF, TARF, TDSF, and TASF network element functional entities in 5G networks, the problems of high cost, difficult coverage, and poor security in the construction of telecommunications identification networks have been solved, and efficient and secure identification network construction and popularization have been achieved.
Patent Information
- Application Number
- CN202310612004.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-26
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2043-05-26
AI Technical Summary
Building a telecommunications identification network faces challenges such as high network construction costs, long maintenance cycles, difficulties in coverage and popularization, and security challenges. Existing technologies are insufficient to achieve efficient and rapid construction of telecommunications identification networks.
By leveraging the Service Architecture (SBA) of 5G networks, multiple network element functional entities, including TSRF, TARF, TDSF, and TASF, are extended and connected to the core network via a bus to achieve TIN service discovery, address resolution, data storage, and access control, fully utilizing the high performance and security of 5G networks.
It reduced the construction cost of the identification network, improved network performance and accessibility, enhanced security, and enabled rapid construction and expansion of the identification network.
Smart Images

Figure CN116546081B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the field of communication technology, in particular to an implementation method of a telecommunication identification network, an implementation system of a telecommunication identification network, an electronic device and a computer readable storage medium. BACKGROUND
[0002] The core functions of the identification resolution system include three parts of identification coding, identification resolution and identification data service. The goal of the identification system is to realize that any object in the real world has a unique identity code and is quickly resolved, and to realize the whole society information query and sharing across regions, industries and fields. Just like everyone's "identity card" affects everyone's clothing, food, housing and living, the identification of each object, person, group and other tangible or intangible objects in society has great value to the whole society. The identification network will become one of the important networks of the society. The telecommunication identification network (TIN) is an identification network system based on the telecommunication network, which can provide various types of identification and rich information services of the identification.
[0003] Using the telecommunication network, various types of identification and rich information services of the identification are provided.
[0004] The construction of the identification network plays a huge role in social development and economic operation, and people's life, but the construction of the telecommunication identification network will face the following challenges: many problems need to be solved, such as network construction, data storage, data transmission, data security, etc.; high-performance identification network requires huge investment and maintenance cost, and the construction period is long; network coverage and popularization require a lot of promotion work; the security of the network faces great challenges; therefore, finding a fast and efficient construction mode of the telecommunication identification network has a positive significance for the construction and popularization of the identification network and the enrichment of the business scope of the operator. SUMMARY
[0005] In order to at least solve the technical problem of difficult construction of the telecommunication identification network in the prior art, the present disclosure provides an implementation method of a telecommunication identification network, an implementation system of a telecommunication identification network, an electronic device and a computer readable storage medium, which makes full use of the SBA architecture (Service-based Architecture) and openness of the existing core network, can make full use of the high performance, high bandwidth, high speed, high coverage, high reliability and excellent security of the 5G network, and build the TIN network on the basis of the 5G network, which has a positive significance for reducing the cost of the identification network, improving the performance of the identification network, and improving the popularity of the TIN network.
[0006] In a first aspect, the present disclosure provides an implementation method of a telecommunication identification network, the method comprising:
[0007] The SBA architecture based on the core network expands multiple NFs (Network Function) satisfying the TIN, wherein the multiple NFs include a TSRF (TIN Service Repository Function), a TARF (TIN Address Resolution Function), a TDSF (TIN Data Storage Function), and a TASF (TIN Authentication Server Function), and the multiple NFs are connected with the core network through a bus;
[0008] The TSRF is used to complete service discovery, configuration, and management of the TIN service;
[0009] The TARF is used to complete address resolution of the TIN code;
[0010] The TDSF is used to complete storage of different types of TIN identification data in a corresponding MEC (Mobile Edge Computing) storage mode in a storage location of the corresponding MEC;
[0011] The TASF is used to complete permission control of TIN data writing and reading.
[0012] Further, the service discovery, configuration, and management of the TIN service include:
[0013] A service registration list is configured, and information of all TIN service nodes registered in the TSRF is registered in the service registration list and is periodically refreshed;
[0014] Global information of the TIN network is obtained through the bus, and registration and authentication of each TIN service node are completed.
[0015] Further, the configuration of the service registration list, in which information of all TIN service nodes registered in the TSRF is registered and is periodically refreshed, includes:
[0016] When a TIN service node is started, the address, port, service content, and service quality attribute of the node are registered;
[0017] Heartbeat information periodically sent by the TIN service node is received, and the node state of the TIN service node in the service registration list is updated to "available";
[0018] If no heartbeat information sent by a TIN service node is received for two consecutive periods, the TIN service node is deleted from the service registration list;
[0019] The broadcast information is sent so that the TIN application subscribes to the broadcast information sent by the TSRF to obtain the service registration list and service registration list update information when using different categories of TIN services, and the TIN application selects a suitable TIN service node according to the TIN service node address of the service registration list to submit a service request and receives a response from the TIN service node.
[0020] Further, the global information of the TIN network is obtained through the bus, and the registration and authentication of each TIN service node are completed, including:
[0021] The global state information of the TIN network is obtained through the bus and a network element NWDAF (Network Data Analytics Function).
[0022] The static configuration parameters of each TIN service node are stored through the SCC (Service Configuration Center) of the TSRF.
[0023] When the TIN service node is started, the basic information of the TIN service node submitted to the TSRF is received.
[0024] The authentication of the TIN service node is performed through a network element AUSF (Authentication Server Function).
[0025] After the authentication is passed, the static and dynamic parameters are generated according to the basic information of the TIN service node and the network environment information of the location of the TIN service node, and are issued to the requested TIN service node.
[0026] When the environment state of the TIN service node changes, the SCC issues new configurations through the mode subscribed by the TIN service node.
[0027] Further, the address resolution of the TIN code includes:
[0028] The TIN identification code submitted to the TARF is separated to obtain the IMC (Identification Memory Code).
[0029] The TIN identification data routing is obtained according to the separated IMC.
[0030] Further, the TARF includes a TMDF (TIN MEC DNS Function) added in the bus and a TLD (TIN Local DNS) added in the MEC;
[0031] The TIN identification data routing obtained according to the separated IMC includes:
[0032] The IMC in the TIN identification code is submitted to the TMDF, the TMDF translates the IMC into the TLD address in the MEC according to the domain name system DNS (Domain Name System) domain name service of the TIN, and then the TLD corresponding to the TLD address translates the TIN identification code into the storage routing information of the TIN identification data.
[0033] Further, the method further includes:
[0034] The TIN identification data storage routing information is encapsulated by a UPF (User plane Function) in a packet header and a UDP (User Datagram Protocol) / IP packet header, and the related address information of the packet header is used as an identifier to transmit the encapsulated TIN identification data to the terminal by using a point-to-point bidirectional tunnel.
[0035] Further, the address resolution of the TIN code further includes:
[0036] The TIN identification code submitted to the TARF is separated to obtain the phone number of the TIN identification code publishing user;
[0037] The TARF submits an authentication application to the AUSF of the UDM (Unified Data Management) through the bus to authenticate the user number separated from the TIN identification code and obtain an encryption key to ensure the legality of the TIN publishing user, and obtain the key for subsequent transmission.
[0038] Further, the TDSF includes a TDSM (TIN Data Storage Management), a TDAI (TIN Data Access Interface), a metadata node and a data storage node, the TDAI is deployed in different levels and modes of MEC, the metadata node is deployed in different levels and modes of MEC, and the data storage node is deployed in the MEC;
[0039] The storing of the different types of TIN identification data in the corresponding MEC storage location in the corresponding MEC storage mode comprises:
[0040] The TDSM is responsible for the storage data management of the TIN data;
[0041] The TDAI provides a unified interface for users to store data in the MEC, and through the UPF, the TIN data publishing user's storage task request is served by matching, the user published TIN data is stored in the specified location, and the registration in the metadata node is performed;
[0042] The metadata node is responsible for the registration and management of the feature description data and the storage location information of the data stored by the data node;
[0043] The data storage node is responsible for the storage and reading of the TIN data.
[0044] Further, the TASF comprises an AAA (Authentication, Authorization, and Accounting) server deployed in the MEC;
[0045] The permission control of the TIN data writing and reading comprises:
[0046] The AAA server is used to complete the user authentication, authorization, and accounting of the TIN identification data writing and reading, wherein the AAA server adopts an extended RADIUS (Remote Authentication Dial In User Service) protocol, and combines OAuth (Open Authorization) for authentication and authorization.
[0047] Further, the AAA server comprises a RADIUS server;
[0048] The authentication and authorization process comprises:
[0049] Receiving a request for writing or reading TIN identification data sent by a client;
[0050] The RADIUS server sends an authentication application to the AUSF of the core network for the user information of the client making the request;
[0051] If the authentication is successful, the RADIUS server receives an allowed access package sent by the AUSF with an access user number, otherwise, a denied access package sent by the AUSF is received;
[0052] If the RADIUS server receives the access-allowed packet, the RADIUS server looks up the user information library according to the phone number of the user to obtain the role of the user, wherein different roles correspond to different TIN data access and operation permissions;
[0053] The RADIUS server issues a token to the client, so that the client subsequently accesses and operates the TIN data through the token.
[0054] In a second aspect, the disclosure provides an implementation system of a telecommunications identification network, and the system comprises:
[0055] A plurality of NFs satisfying the TIN based on the SBA architecture expansion of the core network, wherein the plurality of NFs comprise: a telecommunications identification network service registration function (TSRF), a telecommunications identification network address resolution function (TARF), a telecommunications identification network data storage function (TDSF), and a telecommunications identification network authentication service function (TASF), and the plurality of NFs are connected with the core network through a bus;
[0056] The TSRF is configured to complete service discovery, configuration, and management of the TIN service;
[0057] The TARF is configured to complete address resolution of the TIN code;
[0058] The TDSF is configured to complete storage of different types of TIN identification data in corresponding MEC storage locations in a corresponding MEC storage mode;
[0059] The TASF is configured to complete permission control of TIN data writing and reading.
[0060] Further, the TSRF comprises:
[0061] A configuration module configured to configure a service registration list, and register and periodically refresh information of all TIN service nodes registered in the TSRF in the service registration list;
[0062] A registration and authentication module configured to obtain global information of the TIN network through the bus, and complete registration and authentication of each TIN service node.
[0063] Further, the configuration module comprises:
[0064] A registration unit configured to receive registration of an address, a port, service content, and service quality attributes of a TIN service node when the TIN service node starts;
[0065] A first receiving unit configured to receive heartbeat information periodically sent by the TIN service node, and update a node state corresponding to the TIN service node in the service registration list to “available”;
[0066] a deletion unit configured to delete a TIN service node in the service registration list if the receiving unit does not receive heartbeat information sent by the TIN service node for two consecutive periods;
[0067] a sending unit configured to send broadcast information, so that the TIN application subscribes to the broadcast information sent by the TSRF to obtain the service registration list and the service registration list update information, and so that the TIN application selects a suitable TIN service node according to the TIN service node address in the service registration list to submit a service request and receives a response from the TIN service node.
[0068] Further, the registration and authentication module comprises:
[0069] an obtaining unit configured to obtain global state information of the TIN network through a bus and a network element NWDAF;
[0070] a storage unit configured to store static configuration parameters of various TIN service nodes through a service configuration center SCC of the TSRF;
[0071] a second receiving unit configured to receive basic information of a TIN service node submitted to the TSRF when the TIN service node is started;
[0072] an authentication unit configured to perform authentication on the TIN service node through a network element AUSF;
[0073] a generating unit configured to generate static and dynamic parameters and issue them to the requested TIN service node according to the basic information of the TIN service node and network environment information of the location of the TIN service node after the authentication unit passes the authentication;
[0074] an issuing unit configured to issue new configurations by the SCC through a mode subscribed by the TIN service node when the environment state of the TIN service node changes.
[0075] Further, the TARF comprises:
[0076] a separation module configured to separate a TIN identification code submitted to the TARF to obtain an identification storage code IMC therein;
[0077] an obtaining module configured to obtain a TIN identification data route according to the IMC separated by the separation module.
[0078] Further, the TARF further comprises a TIN domain name service network element TMDF added in a bus of the 5GC and a TIN local domain name system TLD added in the MEC;
[0079] The acquisition module is specifically configured to:
[0080] The IMC in the TIN identification code is submitted to the TMDF, the TMDF translates the IMC into a TLD address in a corresponding MEC according to a DNS domain name service of the TIN, and then the TLD corresponding to the TLD address translates the TIN identification code into storage routing information of TIN identification data.
[0081] Further, the TARF further includes an authentication module;
[0082] The separation module is further configured to separate the TIN identification code submitted to the TARF, and acquire a phone number of a TIN identification code publishing user;
[0083] The authentication module is configured to submit an authentication application to the AUSF of the UDM through the bus, to authenticate the user number separated from the TIN identification code, acquire an encryption key to ensure the legitimacy of the TIN publishing user, and acquire a key for subsequent transmission.
[0084] Further, the TDSF includes a TIN data management TDSM module, a TIN data access interface TDAI module, a metadata node module and a data storage node module, the TDAI module is deployed in different levels and modes of MECs, the metadata node module is deployed in different levels and modes of MECs, and the data storage node module is deployed in MECs;
[0085] The TDSM module is configured to be responsible for storage data management of TIN data;
[0086] The TDAI module is configured to provide a unified interface for users to store data in MECs, and to realize service matching of a storage task request of a TIN data publishing user through a UPF, store the TIN data published by the user to a specified location, and register in a metadata node;
[0087] The metadata node module is configured to be responsible for registration and management of feature description data and storage location information of data stored by a data node;
[0088] The data storage node module is configured to be responsible for storage and reading of TIN data.
[0089] Further, the TASF includes an AAA server deployed in the MEC;
[0090] The AAA server is configured to complete user verification, authorization and accounting for TIN identification data writing and reading, wherein the AAA server adopts an extended RADIUS protocol and combines OAuth for authentication and authorization.
[0091] Further, the AAA server comprises a RADIUS server;
[0092] The RADIUS server is configured to:
[0093] receive a request for writing or reading TIN identification data sent by a client;
[0094] send an authentication application to an AUSF of a core network for user information of the client making the request;
[0095] if the authentication is successful, receive an access permission packet sent by the AUSF with an access user number, otherwise, receive a rejection access packet sent by the AUSF;
[0096] if the access permission packet is received, search a user information library according to a phone number of the user to obtain a role of the user, wherein different roles correspond to different TIN data access and operation permissions;
[0097] send a token to the client to enable the client to subsequently access and operate the TIN data through the token.
[0098] In a third aspect, the present disclosure provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program stored in the memory, the processor executes the implementation method of the telecommunication identification network according to any one of the first aspect.
[0099] In a fourth aspect, the present disclosure provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and when the computer program is executed by a processor, the implementation method of the telecommunication identification network according to any one of the first aspect is implemented.
[0100] Advantages:
[0101] The implementation method of the telecommunication identification network, the implementation system of the telecommunication identification network, the electronic device and the storage medium provided by the present disclosure make full use of the network fast upgrade brought by the existing core network SBA architecture, improve the network resource utilization, speed up the introduction of new network capabilities, and open to third parties under authorization and other advantages. The management and analysis functions of TIN identification are realized by increasing the network element function entity (NF) that meets the TIN identification network. Therefore, the TIN network is improved in performance, investment, implementability, security, and popularity in core fields with the help of 5G network. This TIN architecture and implementation method has positive significance for the construction and popularization of TIN network. BRIEF DESCRIPTION OF DRAWINGS
[0102] Figure 1 FIG. 1 is a flowchart of an implementation method of a telecommunication identification network according to an embodiment of the present disclosure;
[0103] Figure 2 A TIN core network overall architecture provided for the first embodiment of the present disclosure is shown in FIG. 1.
[0104] Figure 3 A TSRF architecture schematic provided for the first embodiment of the present disclosure is shown in FIG. 2.
[0105] Figure 4 A TIN identification data storage schematic in a 5G network provided for the first embodiment of the present disclosure is shown in FIG. 3.
[0106] Figure 5 A TDSF architecture schematic provided for the first embodiment of the present disclosure is shown in FIG. 4.
[0107] Figure 6 A TASF architecture schematic provided for the first embodiment of the present disclosure is shown in FIG. 5.
[0108] Figure 7 An implementation system architecture of a telecommunication identification network provided for the third embodiment of the present disclosure is shown in FIG. 6.
[0109] Figure 8 An electronic device architecture provided for the fourth embodiment of the present disclosure is shown in FIG. 7. DETAILED DESCRIPTION
[0110] In order for those skilled in the art to better understand the technical solutions of the present disclosure, the present disclosure will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments and drawings described herein are merely for the purpose of explaining the present disclosure, and not limiting the present disclosure.
[0111] It should be noted that the terms "first", "second", and the like in the specification and claims of the present disclosure and the above-described drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence; and, in the case of no conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other at will.
[0112] The terms used in the embodiments of the present disclosure are merely for the purpose of describing specific embodiments, and are not intended to limit the present disclosure. The singular forms "a", "said" and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0113] In the subsequent description, the suffixes such as "module", "part", or "unit" used to represent elements are merely for the purpose of facilitating the description of the present disclosure, and have no specific meaning by themselves. Therefore, "module", "part", or "unit" can be used mixedly.
[0114] The technical solutions of the present disclosure and how the present disclosure solves the above technical problems in the prior art are described in detail below with specific examples. It can be understood that in the present application, the execution subject can execute part or all of the steps in the present application, and these steps or operations are only examples, and the present application can also execute other operations or variations of various operations. In addition, each step can be executed in a different order as presented in the present application, and it is possible that not all operations in the present application are executed. In addition, the following specific examples can be combined with each other, and the same or similar concepts or processes can not be described again in some examples.
[0115] Figure 1 An implementation method of a beacon identification network is provided for the first embodiment of the present disclosure, as shown in Figure 1 The method comprises the following steps:
[0116] Step S101: expanding a plurality of NFs satisfying the TIN based on the service-based architecture SBA architecture of the core network, wherein the plurality of NFs comprise: TSRF (TIN Service Repository Function, TIN service registration function), TARF (TIN Address Resolution Function, TIN address resolution function), TDSF (TIN Data Storage Function, TIN data storage function), TASF (TIN Authentication Server Function, TIN authentication service function), and the plurality of NFs are connected with the core network through a bus;
[0117] Step S102: completing service discovery, configuration and management of the TIN service through the TSRF;
[0118] Step S103: completing address resolution of the TIN code through the TARF;
[0119] Step S104: completing storage of different types of TIN identification data in the storage location of the corresponding MEC in the corresponding MEC storage mode through the TDSF;
[0120] Step S105: completing permission control of TIN data writing and reading through the TASF.
[0121] The core network 5GC of 5G borrows the architecture of cloud native, adopts microservices, network function virtualization, separation of control plane and user plane, network slicing, edge computing, network capability opening and other technologies, so that the 5GC has significant improvement in performance scalability, openness and other aspects compared with the core network (Evolved Packet Core: EPC) of 4G. Before 5G, the C plane (control plane) and the U plane (user plane) of the core network are intertwined and difficult to separate. The 5GC network achieves complete separation of the C plane and the U plane through technologies such as SBA. The functions of the C plane are performed by a number of NFs, and the functions of the U plane are independently performed by the UPF (user plane function). In this way, the UPF can be deployed together with the core network control plane in the core room, or deployed closer to the user in the wireless access network in the form of MEC (mobile edge computing). MEC is an important function expansion of 5G, effectively integrating wireless networks and Internet technologies (ICT) together, and adding computing, storage, processing and other functions on the wireless network side, and opening the wireless network through wireless API to provide customized and differentiated services to users, thereby improving network utilization efficiency and value-added value. At the same time, the deployment strategy of mobile edge computing close to the user side can achieve the advantages of low latency and high bandwidth. MEC can also provide more rich functions by acquiring wireless network information in real time.
[0122] The core network of the embodiment of the present disclosure can be a 5GC or a 6G core network capable of expansion through an SBA architecture. Taking the 5GC as an example, by utilizing the advantages of network rapid upgrade, improving network resource utilization, accelerating the introduction of new network capabilities, and opening to third parties in the case of authorization brought by the SBA architecture of the 5GC, the management and resolution functions of the TIN identifier are realized by increasing the function entities (NFs) of the network elements that meet the TIN identifier network, and the overall architecture is as shown in Figure 2 .
[0123] Among them, the 5GC part is the core network part of 5G based on the SBA architecture, which is composed of network elements and buses. The network elements are expanded through the buses. The TINC (TIN Core) is the expansion part of the TIN based on the SBA architecture of the 5GC, which is connected to the 5GC through the buses, and includes:
[0124] TSRF: completes service discovery, configuration and management of TIN service, and realizes dynamic service discovery, service configuration, service metadata and traffic management through a set of feature sets;
[0125] TARF: completes address resolution of TIN code, separates the address part from the submitted TIN code, and then converts the address in the TIN into the actual storage address through the UDM of the 5GC, and then converts it into the route of the actual storage address of the TIN;
[0126] TDSF: complete different types of TIN identification data to store in the corresponding MEC storage mode in the storage location of the corresponding MEC;
[0127] TASF: complete TIN data write, read permission control, wherein the write permission of TIN data is controlled by TIN system, the read permission of TIN data is controlled by the publisher of TIN data, and authentication service is provided for TIN identification data.
[0128] The embodiments of the present disclosure make full use of the advantages of network rapid upgrade, improvement of network resource utilization, acceleration of network new capability introduction, and opening to third parties under authorization brought by 5G network SBA architecture, and realize the management and resolution function of TIN identification by increasing the network element function entity (NF) meeting the TIN identification network. Therefore, the performance, investment, implementability, security, and popularity of TIN network are improved with the help of 5G network in the core fields. The new TIN architecture and implementation method have positive significance for the construction and popularization of TIN network.
[0129] The embodiments of the present disclosure utilize the architecture of 5G network to build a telecommunications identification network, which has the following advantages:
[0130] 1. Make full use of the excellent network performance of 5G network to make the identification network have good network performance in rate, capacity, and delay;
[0131] 2. Make full use of the new network architecture of 5G network to make the identification network keep advanced and flexible in the overall architecture;
[0132] 3. Make full use of the security system of 5G network to make the identification network have sufficient guarantee and diversity in security, and provide rich services for users;
[0133] 4. Make full use of the data storage and processing capability of MEC of 5G network to reduce the construction period, investment, and management cost of data storage and processing of the identification network;
[0134] 5. Make full use of the extensive coverage of 5G network to build an identification network with extensive coverage in a short period of time, and reduce the maintenance and operation cost of the network;
[0135] Further, the service discovery, configuration, and management of the TIN service include:
[0136] Configure a service registration list, and register and periodically refresh the information of all TIN service nodes registered in the TSRF in the service registration list;
[0137] Obtain global information of the TIN network through the bus, and complete registration and authentication of each TIN service node.
[0138] Service discovery, configuration and management of TIN service include TIN service discovery and state maintenance, configuration management and service, and system management;
[0139] For TIN service discovery and state maintenance, since TIN is distributed in each MEC of 5G, each service node is in dynamic change, and new service nodes are constantly online while original service nodes are constantly offline due to failure, maintenance, etc. Therefore, the address of the service node is dynamically changed, and a fixed address cannot be used to call the service. At the same time, since the environment of the service node is also in dynamic change, the parameter configuration and service policy of the service node are also changed according to the actual environment of the system. Therefore, by configuring the service registration list in the TSRF, the information of all service nodes registered in the TSRF is registered and periodically refreshed. The TSRF structure is shown in Figure 3 .
[0140] When performing configuration management and service, the TIN service node needs to perform a large amount of parameter configuration to work normally, such as the basic environment parameters of the service, the environment parameters required by the policy and algorithm (such as network address, network performance, authentication policy. A large number of parameters need global information for configuration, and the service node has no ability to obtain the required global information. In addition, if local configuration is used for a large number of different types of TIN service nodes, not only the workload is huge, but also different adaptation cannot be made according to the environment change, and the quality cannot be guaranteed. Since the TSRF is in the core network, it can easily obtain global information through the 5GC bus, and complete registration and authentication functions, and then perform configuration editing, storage, distribution, change management, history version management, and change audit. Therefore, the TSRF is used to centrally configure and update the managed TIN service nodes.
[0141] Through system management, the registration and state update, life cycle, resource dependency, health status, traffic management, routing and security policy, and statistical data of various service nodes of the TIN system are completed.
[0142] Further, the configuration service registration list registers and periodically refreshes the information of all TIN service nodes registered in the TSRF, including:
[0143] Receiving the registration of the address, port, service content and service quality attribute of the TIN service node when the TIN service node starts;
[0144] Receiving the heartbeat information periodically sent by the TIN service node, and updating the node state corresponding to the TIN service node in the service registration list to "available";
[0145] If the heartbeat information sent by a TIN service node is not received for two consecutive periods, the TIN service node is deleted from the service registration list;
[0146] Broadcast information is sent so that the TIN application subscribes to the broadcast information sent by the TSRF to obtain the service registration list and service registration list update information when using different categories of TIN services, and so that the TIN application selects a suitable TIN service node according to the TIN service node address in the service registration list to submit a service request and receives a response from the TIN service node.
[0147] The function is implemented as follows:
[0148] 1) When the service node is started, the address, port, service content, service quality (service capability, maximum traffic, minimum delay), and other attributes of the node are registered to the TSRF;
[0149] 1) The service node periodically sends heartbeat information to the TSRF to prove that the service node is available. After receiving the heartbeat information, the TSRF updates the node state of the corresponding service node in the service registration list to "available";
[0150] 2) If the TSRF does not receive the heartbeat information of a service node for two consecutive periods, the node is deleted from the registration list, and the sending of a service request to the unhealthy service node is prevented;
[0151] 3) When the TIN application (TIN app) uses different categories of TIN services, the broadcast information sent by the TSRF is subscribed to, and the service registration list and service registration list update information can be obtained;
[0152] 4) The TIN application selects a suitable service node (for example, a TIN parsing service node) according to the service node address in the service registration list to submit a service request (for example, a TIN payment code), and receives a response (for example, the payment result of the TIN payment code) from the service node.
[0153] Further, the global information of the TIN network is obtained through the bus, and the registration and authentication of each TIN service node are completed, including:
[0154] The global state information of the TIN network is obtained through the bus and the network element NWDAF;
[0155] The static configuration parameters of various TIN service nodes are stored in the SCC of the TSRF;
[0156] The basic information of the TIN service node submitted to the TSRF when the TIN service node is started is received;
[0157] authentication of the TIN service node is performed through a network element AUSF;
[0158] After the authentication, static and dynamic parameters are generated according to basic information of the TIN service node and network environment information of a location of the TIN service node and are issued to the requested TIN service node;
[0159] When an environment state of the TIN service node changes, new configurations are issued by the SCC through a mode subscribed by the TIN service node.
[0160] The basic information of the TIN service node includes a location and a service node type of the TIN service node. The TSRF is adopted to centrally configure and update parameters of the managed TIN service node. The configuration management and service of the TSRF provide parameter configurations and environment parameter services for the service node in a centralized, externalized and dynamic manner, dynamically adjust parameters and strategies of the service node according to a global network state, and uniformly manage parameters of all the managed service nodes, thereby simplifying parameter configurations of the service node and improving efficiency and security of the parameter configurations.
[0161] Further, the address resolution of the TIN code includes:
[0162] The TIN identification code submitted to the TARF is separated to obtain the IMC therein;
[0163] The TIN identification data routing is obtained according to the separated IMC.
[0164] The identification information of the telecommunication identification network TIN is stored based on a MEC of a communication operator. The identification code contains an identification storage code (IMC) which is encoded based on a storage location of the identification. The identification storage code IMC includes four parts:
[0165] {national center node code} + {regional center / provincial capital node code} + {local core / edge node code} + {edge internal node internal code}
[0166] After the TIN identification code is submitted to the TARF, the IMC is separated, the identity authentication of the TIN data, the user data acquisition, the TIN identification data routing and the encryption key are performed through the UDM of the 5GC, and the TIN identification information is returned to the TIN terminal. The storage of the TIN identification data in the 5G is as follows: Figure 4As shown, the UPF in the figure needs to consider the requirements of 4G / 5G interoperation and converged networking, so the UPF needs to be set up in combination with the GW-U, in addition, considering the low latency and large bandwidth requirements of MEC, the UPF needs to access the MEC nearby, and the UPF needs to be deployed in association with the MEC. Since the types of TIN identification data are different, the requirements for bandwidth, reliability, security, delay, etc. are also different, so the storage of TIN identification data fully utilizes the diversity of MEC of 5G to meet the requirements of different TIN identification data, but increases the complexity of TIN identification data routing.
[0167] Further, the TARF includes a TMDF (TIN MEC DNS Function, TIN Domain Name Service network element) added in the bus and a TLD (TIN Local DNS, TIN Local Domain Name System) added in the MEC.
[0168] The TIN identification data routing obtained according to the separated IMC includes:
[0169] The IMC in the TIN identification code is submitted to the TMDF, which translates the IMC into the TLD address in the corresponding MEC according to the DNS domain name service of the TIN, and then the TLD corresponding to the TLD address translates the TIN identification code into the storage routing information of the TIN identification data.
[0170] The specific implementation method of the TARF is as follows:
[0171] IMC (Identification Storage Coding) separation:
[0172] Since the TIN identification code adopts fixed-length coding, the IMC can be directly separated according to the position of the TIN code after the TIN identification code is submitted to the TARF.
[0173] TIN identification data routing:
[0174] The TIN data can be deployed in the central DC (Data Center) / regional DC, core DC, edge MEC, access MEC level and user network DC of 5G. The TIN identification data routing adopts a hierarchical architecture composed of MEC layer routing and local layer routing, so TMDF is added in the bus of 5GC and TLD is added in the MEC. The routing process is to submit the identification storage coding (IMC) in the TIN identification code to the TMDF, translate it into the TLD address in the corresponding MEC by the DNS domain name service of the TIN, and then translate the TIN identification code into the storage routing information of the TIN identification data by the TLD.
[0175] Further, the method further includes:
[0176] The TIN identification data storage routing information is encapsulated by the UPF with a packet header and a UDP / IP header, and the relevant address information of the packet header is used as an identifier to transmit the encapsulated TIN identification data to the terminal by using a point-to-point bidirectional tunnel.
[0177] Since the UPF is a connection anchor point between the 5GC and the MEC, the core network data is forwarded by the UPF to the external network, and the UPF is responsible for the routing and forwarding of data packets, the detection of data packets, the implementation of user plane policies, the execution of Qos (Quality of Service), and the like. The UPF supports static routing, policy routing, and backup routing, supports open standard routing protocols such as OSPF (Open Shortest Path First) and BGP (Border Gateway Protocol), supports route map definition, route import, distribution definition, and rules such as route prefix, autonomous system path, community attribute, and access list. Therefore, the TIN identification data storage routing information is encapsulated by the UPF with a packet header and a UDP / IP header, and the relevant address information of the packet header is used as an identifier to transmit the encapsulated TIN identification data to the terminal by using a point-to-point bidirectional tunnel.
[0178] Further, the address resolution of the TIN code further includes:
[0179] The TIN identification code submitted to the TARF is separated to obtain the phone number of the TIN identification code publishing user;
[0180] The TARF submits an authentication application to the AUSF of the UDM through a bus to authenticate the user number separated from the TIN identification code and obtain an encryption key to ensure the legitimacy of the TIN publishing user and obtain a subsequent transmission key.
[0181] Before obtaining the TIN identification data routing, identity authentication and key acquisition of the TIN identification code publishing user are further needed;
[0182] When the TIN identification code submitted to the TARF is separated, the phone number of the TIN identification code publishing user can be obtained in addition to the IMC. The UDM of the 5GC centrally controls network user data, stores customer data and identity authentication information, and encryption keys, and completes access authorization, user registration, and data network configuration data functions. The TARF submits an authentication application to the authentication server function (AUSF) of the UDM through a 5GC bus to authenticate the user number separated from the TIN and obtain an encryption key to ensure the legitimacy of the TIN publishing user and obtain a subsequent transmission key.
[0183] Further, the TDSF includes a TDSM, a TDAI, a metadata node and a data storage node, the TDAI is deployed in different levels and modes of MEC, the metadata node is deployed in different levels and modes of MEC, and the data storage node is deployed in MEC.
[0184] The storage of different types of TIN identification data in the corresponding MEC storage mode in the storage location of the corresponding MEC includes:
[0185] The TDSM is responsible for the storage data management of TIN data.
[0186] The TDAI provides a unified interface for users to store data in MEC, and through the UPF, the service matching of the storage task request of the TIN data publishing user is implemented, the TIN data published by the user is stored in the designated location, and the registration and management of the feature description data and the storage location information of the data stored in the data node are implemented in the metadata node.
[0187] The metadata node is responsible for the registration and management of the feature description data and the storage location information of the data stored in the data node.
[0188] The data storage node is responsible for the storage and reading of TIN data.
[0189] The TIN data can be deployed in the central DC (data center) / regional DC, core DC, edge MEC, access MEC level and user network DC of 5G. Among them, the deployment mode of MEC in 5G can be divided into the following several modes: a) MEC and UPF integrated deployment, based on ICT (Information and Communication Technology, information and communication technology) integrated edge cloud unified bearing; b) MEC and UPF separate deployment, based on different edge cloud respectively bearing, c) MEC and UPF partially shared deployment.
[0190] As for the deployment location of UPF, according to the differentiated requirements of business scenarios for time delay, bandwidth, reliability, etc., it can be divided into the following several modes: a) Central level UPF suitable for time delay insensitive, high throughput demand and relatively concentrated business; b) Regional level UPF bearing the user plane business in the city area; c) Edge level UPF sinking to the mobile edge node to meet the business requirements of high bandwidth, time delay sensitivity, strong data confidentiality, etc.; d) Enterprise level UPF deployed in enterprise computer room, production data can be terminated in the park, isolated from public network data to ensure the safety and reliability of production, and provide ultra-high bandwidth, ultra-low time delay and ultra-high reliable connection for enterprises.
[0191] The TDSF structure is as shown in Figure 5 The specific implementation mode is as follows:
[0192] 1) TDSM (TIN Data Storage Management)
[0193] Responsible for the storage data management of TIN data, including the policy management of TIN data storage mode and storage location, TIN data storage node management, TIN user identity management, and the collaborative work between different storage locations and storage modes.
[0194] 2) TDAI (TIN Data Access Interface)
[0195] TDAI is deployed in different levels and modes of MEC, provides a unified interface for users to store data in MEC, and realizes the service matching of TIN data publishing user's storage task request through the functions of UPF routing and forwarding, data and service identification, action and policy execution. According to the user's storage task requirements, the user's published TIN data is stored in the specified location, and the registration is carried out in the metadata node. TDAI simplifies the user's TIN data publishing. After the user submits the system according to the data storage description standard of TIN, the user can directly submit TIN identification data, and the system automatically selects the appropriate storage mode and storage location matching.
[0196] 3) Metadata node
[0197] Deployed in different levels and modes of MEC, responsible for the registration and management of data feature description data (metadata) and storage location information of data node storage, including maintaining the file system tree and the metadata management of all files and folders in the file tree and recording all file creation, deletion, renaming and other operations.
[0198] 4) Data storage node
[0199] Deployed in MEC, responsible for the storage and reading of TIN data. When TIN data enters the system through TDAI, it will be stored in data storage nodes according to the type under the management and control of the metadata node. Data storage nodes are divided into block storage nodes, file storage nodes, relational database storage nodes, column data storage nodes, etc. to meet the storage of different data types.
[0200] Further, the TASF includes an AAA server deployed in the MEC;
[0201] The permission control of the TIN data writing and reading includes:
[0202] The user authentication, authorization and accounting of the TIN identification data writing and reading are completed by the AAA server, wherein the AAA server adopts an extended RADIUS protocol and combines OAuth for authentication and authorization.
[0203] Compared with the EPC, the 5GC implements unified authentication, that is, simultaneously supporting 5G AKA (Authentication and Key Agreement) and EAP (Extensive Authentication Protocol) authentication protocols. When a terminal accesses through a 3GPP wireless network (for example, a 5G or 4G cellular network), a 5G AKA authentication process is triggered; when the terminal accesses through a non-3GPP wireless access network (for example, a wired network or a WiFi), an EAP authentication process is triggered.
[0204] The AUSF is a network entity in the 5GC and is implemented as a requester NF (network element) to authenticate a UE (user terminal). The architecture of the TASF is as shown in Figure 6 The specific implementation manner is as follows:
[0205] The TASF adopts the DN-AAA mode of the 5GC for authentication of the TIN, deploys an AAA server in the MEC, and completes user authentication, authorization and accounting of the TIN identification data writing and reading, mainly including: managing the rights of users, allowing business operations, providing authentication and authorization of user identity and service eligibility, and charging services and the like. The main protocol adopted by the AAA is RADIUS, the extended protocol of RADIUS supports adding new attribute values, and a transaction is composed of a variable-length triple "attribute-length-value", and the value of the new attribute can define a new attribute on its own without interrupting the execution of the existing protocol. The embodiment adopts an extended RADIUS protocol and combines OAuth (Open Authorization) for authentication and authorization. OAuth is an open standard that allows users to authorize third-party applications to access information stored in another service provider without providing the user's critical information to the third-party application.
[0206] Further, the AAA server includes a RADIUS server;
[0207] The authentication and authorization process includes:
[0208] Receiving a request for writing or reading TIN identification data sent by a client;
[0209] The RADIUS server sends an authentication application to the AUSF of the core network for user information of the client making the request;
[0210] If the authentication is successful, the RADIUS server receives an access-accept packet sent by the AUSF with the access user number, otherwise receives an access-reject packet sent by the AUSF;
[0211] If the RADIUS server receives the access-accept packet, it searches the user information library according to the user's phone number to obtain the user's role, wherein different roles correspond to different TIN data access and operation permissions;
[0212] The RADIUS server issues a token to the client to enable the client to subsequently access and operate the TIN data through the token.
[0213] By receiving the access-accept packet sent by the AUSF with the access user number (and receiving the access-reject packet sent by the AUSF when the authentication fails), it is determined that the user authentication is successful, thereby obtaining the user's role; a token is sent to the user to complete the permission control of TIN data writing and reading, wherein the writing permission of the TIN data is controlled by the TIN system, and the reading permission of the TIN data is controlled by the publisher of the TIN data, thereby providing an authentication service for the TIN identification data.
[0214] Based on the SBA architecture of the 5GC, the network functions are split, there is no hierarchical relationship between the networks, all network functions are accessed into the system through unified service interfaces, and each NF (network element function entity) is independent of each other, and the addition, upgrade and transformation will not affect other NFs. The SBA architecture and openness of the 5GC are fully utilized in the embodiments of the present disclosure, and the high performance, high bandwidth, high rate, high coverage, high reliability, and excellent security of the 5G network can be fully utilized, and the TIN network is constructed on the basis of the 5G network, which has a positive significance for reducing the cost of the identification network, improving the performance of the identification network, and improving the popularity of the TIN network.
[0215] The second embodiment of the present disclosure also provides an implementation method of a telecommunication identification network, which utilizes the SBA architecture of the 5GC to realize the management and analysis functions of the TIN identification by adding network element function entities (NFs) that meet the requirements of the TIN identification network; the added multiple NFs form a TINC (TIN Core: core network), which is an extension part of the SBA architecture of the TIN based on the 5GC and is connected to the 5GC through a bus, and includes a TSRF, a TARF, a TDSF, and a TASF.
[0216] The TSRF (TIN Service Repository Function) completes service discovery, configuration and management of the TIN service, and realizes dynamic service discovery, service configuration, service metadata and traffic management through a set of feature sets, including TIN service discovery and state maintenance, configuration management and service, and system management. Among them, the TIN service discovery and state maintenance realizes the dynamic change of the service state and address of the service node, and the application obtains the service node list information through the mode of subscribing to the message; the configuration management and service realizes the dynamic change of the configuration parameter with the environmental parameter; and the system management realizes the overall management of the system.
[0217] The TARF (TIN Address Resolution Function) completes address resolution of the TIN code, separates the address part from the submitted TIN code, and then converts the address in the TIN into an actual storage address through the UDM of the 5GC, and then converts into the route of the TIN actual storage address. Among them, the TARF submits the authentication application to the authentication server function AUSF of the UDM through the 5GC bus to authenticate the user number separated from the TIN and obtain the encryption key, ensure the legitimacy of the TIN publishing user, and obtain the key for subsequent transmission. By increasing the TMDF (TIN MEC DNS Function) in the bus of the 5GC, increasing the TLD (TIN Local DNS) in the MEC, submitting the identification storage code (IMC) in the TIN identification code to the TMDF, translating the TIN DNS domain name service into the TLD address in the MEC, and then translating the TIN identification code into the storage routing information of the TIN identification data by the TLD, the routing process of the TIN is realized.
[0218] TDSF (TIN Data Storage Function) stores different types of TIN identification data in corresponding MEC storage locations in corresponding MEC storage modes. Among them, TDSM (TIN Data Storage Management) completes the storage data management of TIN data, including the policy management of TIN data storage mode and storage location, TIN data storage node management, TIN user identity management, and realizes the collaborative work between different storage locations and storage modes. The TDAI (TIN Data Access Interface) deployed in the MEC in different levels and modes provides a unified interface for users to store data in the MEC, and through the routing and forwarding of the UPF, the data and service identification, the action and policy execution function, realizes the service matching of the storage task request of the TIN data publishing user, and stores the TIN data published by the user to the specified location according to the user storage task demand, and registers in the metadata node.
[0219] TASF (TIN Authentication Server Function) completes the permission control of TIN data writing and reading. Among them, TASF adopts the DN-AAA mode of 5GC to authenticate TIN, deploys AAA server in MEC, completes user verification, authorization and accounting of TIN identification data writing and reading. Adopting the extended RADIUS protocol, combined with OAuth (Open Authorization) for authentication and authorization.
[0220] Embodiment three of the present disclosure also provides an implementation system of a telecommunication identification network, as shown in Figure 7 The system comprises:
[0221] a plurality of NFs satisfying TIN based on the service-based architecture SBA architecture expansion of the core network, wherein the plurality of NFs comprise: a telecommunication identification network service registration function TSRF, a telecommunication identification network address resolution function TARF, a telecommunication identification network data storage function TDSF, and a telecommunication identification network authentication service function TASF, and the plurality of NFs are connected with the core network through a bus;
[0222] The TSRF is configured to complete service discovery, configuration and management of TIN service;
[0223] The TARF is configured to complete address resolution of TIN code;
[0224] The TDSF is configured to complete storage of different types of TIN identification data in corresponding MEC storage locations in corresponding MEC storage modes;
[0225] The TASF is configured to complete the permission control of TIN data writing and reading.
[0226] Further, the TSRF comprises:
[0227] A configuration module configured to configure a service registration list, and register and periodically refresh the information of all TIN service nodes registered in the TSRF in the service registration list;
[0228] A registration and authentication module configured to obtain the global information of the TIN network through the bus, and complete the registration and authentication of each TIN service node.
[0229] Further, the configuration module comprises:
[0230] A registration unit configured to receive the registration of the address, port, service content and service quality attribute of the TIN service node when the node is started;
[0231] A first receiving unit configured to receive the heartbeat information periodically sent by the TIN service node, and update the node state corresponding to the TIN service node in the service registration list to "available";
[0232] A deletion unit configured to delete the TIN service node in the service registration list if the receiving unit does not receive the heartbeat information sent by the TIN service node for two consecutive periods;
[0233] A sending unit configured to send broadcast information, so that the TIN application subscribes to the broadcast information sent by the TSRF when using different categories of TIN services, to obtain the service registration list and service registration list update information, and so that the TIN application selects a suitable TIN service node according to the TIN service node address in the service registration list to submit a service request, and receives the response of the TIN service node.
[0234] Further, the registration and authentication module comprises:
[0235] An acquisition unit configured to obtain the global state information of the TIN network through the bus and the network element NWDAF;
[0236] A storage unit configured to store the static configuration parameters of various TIN service nodes through the service configuration center SCC of the TSRF;
[0237] A second receiving unit configured to receive the basic information of the TIN service node submitted to the TSRF when the service node is started;
[0238] An authentication unit configured to perform authentication on the TIN service node through the network element AUSF;
[0239] A generating unit is configured to generate static and dynamic parameters and issue them to the requested TIN service node according to the basic information of the TIN service node and the network environment information of the location of the TIN service node after the authentication unit passes the authentication.
[0240] An issuing unit is configured to issue new configurations by the SCC through the mode subscribed by the TIN service node when the environment state of the TIN service node changes.
[0241] Further, the TARF comprises:
[0242] A separating module is configured to separate the TIN identification code submitted to the TARF to obtain the identification storage code IMC therein.
[0243] An obtaining module is configured to obtain the TIN identification data routing according to the IMC separated by the separating module.
[0244] Further, the TARF further comprises a TIN domain name service network element TMDF added in the bus of the 5GC and a TIN local domain name system TLD added in the MEC.
[0245] The obtaining module is specifically configured to:
[0246] The IMC in the TIN identification code is submitted to the TMDF, the TMDF translates the IMC into the TLD address in the corresponding MEC according to the DNS domain name service of the TIN, and then the TLD corresponding to the TLD address translates the TIN identification code into the storage routing information of the TIN identification data.
[0247] Further, the TARF further comprises an authentication module.
[0248] The separating module is further configured to separate the TIN identification code submitted to the TARF to obtain the phone number of the TIN identification code publishing user.
[0249] The authentication module is configured to submit an authentication application to the AUSF of the UDM through the bus to authenticate the user number separated from the TIN identification code and obtain an encryption key to ensure the legitimacy of the TIN publishing user and obtain the key for subsequent transmission.
[0250] Further, the TDSF comprises a TIN data management TDSM module, a TIN data access interface TDAI module, a metadata node module and a data storage node module, the TDAI module is deployed in different levels and modes of MEC, the metadata node module is deployed in different levels and modes of MEC, and the data storage node module is deployed in the MEC.
[0251] The TDSM module is configured to be responsible for storage data management of the TIN data;
[0252] The TDAI module is configured to provide a unified interface for users to store data in the MEC, and to perform service matching on a storage task request of a TIN data publishing user through the UPF, store the TIN data published by the user to a specified location, and register in a metadata node;
[0253] The metadata node module is configured to be responsible for registration and management of feature description data and storage location information of data stored in the data node;
[0254] The data storage node module is configured to be responsible for storage and reading of the TIN data.
[0255] Further, the TASF comprises an AAA server deployed in the MEC;
[0256] The AAA server is configured to complete user verification, authorization and accounting for writing and reading of the TIN identification data, wherein the AAA server adopts an extended RADIUS protocol and combines OAuth for authentication and authorization.
[0257] Further, the AAA server comprises a RADIUS server;
[0258] The RADIUS server is configured to:
[0259] receive a request for writing or reading the TIN identification data sent by a client;
[0260] send an authentication application to an AUSF of a core network for user information of the client that makes the request;
[0261] if the authentication is successful, receive an access permission packet sent by the AUSF with an access user number, or receive a rejection access packet sent by the AUSF;
[0262] if the access permission packet is received, user information database is searched according to a phone number of the user to obtain a role of the user, wherein different roles correspond to different TIN data access and operation permissions;
[0263] a token is issued to the client to enable the client to subsequently access and operate the TIN data through the token.
[0264] The embodiments of the present disclosure take full advantage of the advantages brought by the SBA architecture of the 5G network, such as fast network upgrade, improvement of network resource utilization, acceleration of introduction of new network capabilities, and opening to third parties in the case of authorization, and realize the management and resolution function of the TIN identification by increasing the network element function entity (NF) that meets the TIN identification network, so as to improve the performance, investment, implementability, security, and popularity of the TIN network with the help of the 5G network. The new TIN architecture and implementation method have positive significance for the construction and popularization of the TIN network.
[0265] The implementation system of the telecommunications identification network of the embodiments of the present disclosure is used to implement the implementation method of the telecommunications identification network in the method embodiments one and two, and is described simply, and the specific implementation can be referred to the related description in the method embodiments one and two, and will not be described here.
[0266] In addition, as shown in Figure 8 The embodiments of the present disclosure also provide an electronic device, including a memory 100 and a processor 200, and the memory 100 stores a computer program, and when the processor 200 runs the computer program stored in the memory 100, the processor 200 executes the above-mentioned various possible methods.
[0267] The memory 100 is connected with the processor 200, the memory 100 can adopt a flash memory or a read-only memory or other memories, and the processor 200 can adopt a central processing unit or a single-chip microcomputer.
[0268] In addition, the embodiments of the present disclosure also provide a computer readable storage medium, and the computer readable storage medium stores a computer program, and the computer program is executed by a processor to execute the above-mentioned various possible methods.
[0269] The computer readable storage medium includes a volatile or non-volatile, removable or non-removable medium implemented in any method or technology for storage of information such as computer readable instructions, data structures, computer program modules or other data. The computer readable storage medium includes, but is not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile discs (DVD, Digital Video Disc) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer.
[0270] It can be understood that the above embodiments are only exemplary embodiments adopted for illustrating the principles of the present disclosure, and the present disclosure is not limited thereto. Various modifications and improvements can be made by those of ordinary skill in the art without departing from the spirit and essence of the present disclosure, and these modifications and improvements are also considered to be within the protection scope of the present disclosure.
Claims
1. A method of implementing a telecommunication identity network, characterized by The method comprises: The core network-based service-based architecture SBA architecture expands a plurality of network element function entities NF satisfying a telecommunications identification network TIN, wherein the plurality of NFs comprise: a telecommunications identification network service registration function TSRF, a telecommunications identification network address resolution function TARF, a telecommunications identification network data storage function TDSF, and a telecommunications identification network authentication service function TASF, and the plurality of NFs are connected with the core network through a bus; The TSRF is used for completing service discovery, configuration and management of TIN services; The TARF is used for completing address resolution of TIN codes; The TDSF is used for storing different types of TIN identification data in corresponding storage positions of edge computing MEC in a corresponding MEC storage mode; The TASF is used for completing permission control of TIN data writing and reading.
2. The method of claim 1, wherein, The service discovery, configuration and management of the TIN services comprise: A service registration list is configured, and information of all TIN service nodes registered in the TSRF is registered in the service registration list and is periodically refreshed; Global information of the TIN network is obtained through the bus, and registration and authentication of each TIN service node are completed.
3. The method of claim 2, wherein, The configuration of the service registration list, the registration of information of all TIN service nodes registered in the TSRF in the service registration list and the periodic refreshing of the information comprise: When a TIN service node starts, the address, port, service content and service quality attribute of the node are registered; Heartbeat information periodically sent by the TIN service node is received, and the node state of the TIN service node in the service registration list is updated to "available"; If heartbeat information sent by a certain TIN service node is not received for two consecutive periods, the TIN service node is deleted in the service registration list; Broadcast information is sent, so that, when different categories of TIN services are used, a TIN application subscribes to the broadcast information sent by the TSRF to obtain the service registration list and service registration list update information, and the TIN application selects a suitable TIN service node according to the TIN service node address of the service registration list to submit a service request, and receives a response of the TIN service node.
4. The method of claim 2, wherein, The obtaining of global information of the TIN network through the bus and the completion of registration and authentication of each TIN service node comprise: Global state information of the TIN network is obtained through the bus and a network element network data analysis function NWDAF; Static configuration parameters of various TIN service nodes are stored in a service configuration center SCC of the TSRF; When a TIN service node starts, basic information of the TIN service node submitted to the TSRF is received; The TIN service node is authenticated through a network element authentication server function AUSF; After the authentication is passed, static and dynamic parameters are generated according to the basic information of the TIN service node and network environment information of a location of the TIN service node, and are issued to the requested TIN service node; When the environment state of the TIN service node changes, new configurations are issued by the SCC through a mode subscribed by the TIN service node.
5. The method of claim 1, wherein, The address resolution of the TIN code comprises: Separating the TIN identification code submitted to the TARF to obtain the identification storage code IMC; Obtaining the TIN identification data routing according to the separated IMC.
6. The method of claim 5, wherein, The TARF includes a TIN domain name service network element TMDF added in the bus and a TIN local domain name system TLD added in the MEC; The obtaining of the TIN identification data routing according to the separated IMC includes: Submitting the IMC in the TIN identification code to the TMDF, translating the IMC into the TLD address in the corresponding MEC according to the domain name system DNS domain name service of the TIN by the TMDF, and then translating the TIN identification code into the storage routing information of the TIN identification data by the TLD corresponding to the TLD address.
7. The method of claim 6, wherein, The method further includes: The TIN identification data storage routing information is encapsulated by a user plane function UPF into a packet header and a user datagram protocol UDP / IP packet header, and the relevant address information of the packet header is used as an identifier to transmit the encapsulated TIN identification data to the terminal by using a point-to-point bidirectional tunnel.
8. The method of claim 5, wherein, The address resolution of the TIN code further includes: Separating the TIN identification code submitted to the TARF to obtain the telephone number of the TIN identification code publishing user; The TARF submits an authentication application to an authentication server function AUSF of a unified data management function UDM through the bus to authenticate the user number separated from the TIN identification code and obtain an encryption key to ensure the legality of the TIN publishing user and obtain a subsequent transmission key.
9. The method of claim 1, wherein, The TDSF includes a TIN data management TDSM, a TIN data access interface TDAI, a metadata node and a data storage node, the TDAI is deployed in different levels and modes of MECs, the metadata node is deployed in different levels and modes of MECs, and the data storage node is deployed in the MECs; The storage of different types of TIN identification data in the storage location of the corresponding MEC in the corresponding MEC storage mode includes: The TDSM is responsible for the storage data management of the TIN data; The TDAI provides a unified interface for the user to store data in the MEC, and the UPF realizes service matching of the storage task request of the TIN data publishing user, stores the TIN data published by the user to a specified location, and registers in the metadata node; The metadata node is responsible for the registration and management of the feature description data and the storage location information of the data stored by the data node; The data storage node is responsible for the storage and reading of the TIN data.
10. The method of claim 1, wherein, The TASF includes an authentication, authorization and accounting AAA server deployed in the MEC; The permission control of the TIN data writing and reading includes: The AAA server is used for completing the user authentication, authorization and accounting of the TIN identification data writing and reading, wherein the AAA server adopts an extended remote authentication dial in user service RADIUS protocol and combines an open authorization OAuth for authentication and authorization.
11. The method of claim 10, wherein, The AAA server includes a RADIUS server; The authentication and authorization process includes: Receiving a request of writing or reading the TIN identification data sent by a client; The RADIUS server sends an authentication application to an AUSF of the core network for a user of a client making a request; If the authentication is successful, the RADIUS server receives an access permission package sent by the AUSF with an access user number, otherwise, the RADIUS server receives a rejection access package sent by the AUSF; If the RADIUS server receives the access permission package, the RADIUS server searches a user information library according to a phone number of the user to obtain a role of the user, wherein different roles correspond to different TIN data access and operation permissions; The RADIUS server issues a token to the client to enable the client to subsequently access and operate the TIN data through the token.
12. A system for implementing a telecommunications identity network, characterized by The system comprises: a plurality of NFs satisfying the TIN based on an SBA architecture of a service architecture of the core network, wherein the plurality of NFs comprises a TSRF, a TARF, a TDSF and a TASF, and the plurality of NFs are connected with the core network through a bus; the TSRF is configured to complete service discovery, configuration and management of the TIN service; the TARF is configured to complete address resolution of the TIN code; the TDSF is configured to complete storage of different types of TIN identification data in a corresponding MEC storage location in a corresponding MEC storage mode; the TASF is configured to complete permission control of TIN data writing and reading.
13. The system of claim 12, wherein, The TSRF comprises: a configuration module configured to configure a service registration list, and register and periodically refresh information of all TIN service nodes registered in the TSRF in the service registration list; a registration and authentication module configured to obtain global information of the TIN network through the bus, and complete registration and authentication of each TIN service node.
14. The system of claim 13, wherein, The configuration module comprises: a registration unit configured to receive registration of an address, a port, service content and quality of service attributes of a TIN service node when the TIN service node starts; a first receiving unit configured to receive heartbeat information periodically sent by the TIN service node, and update a node state of the TIN service node in the service registration list to "available"; a deletion unit configured to delete a TIN service node in the service registration list if the receiving unit does not receive heartbeat information sent by the TIN service node for two consecutive periods; a sending unit configured to send broadcast information, so that a TIN application subscribes to the broadcast information sent by the TSRF when using different categories of TIN services to obtain the service registration list and service registration list update information, and the TIN application selects a suitable TIN service node according to a TIN service node address of the service registration list to submit a service request, and receives a response of the TIN service node.
15. The system of claim 13, wherein, The registration and authentication module comprises: an acquisition unit configured to obtain global state information of the TIN network through the bus and a network element NWDAF; a storage unit configured to store static configuration parameters of various TIN service nodes through a service configuration center SCC of the TSRF; a second receiving unit configured to receive basic information of the TIN service node submitted to the TSRF when the TIN service node is started; an authentication unit configured to authenticate the TIN service node through a network element AUSF; a generating unit configured to generate static and dynamic parameters and issue them to the requested TIN service node according to the basic information of the TIN service node and the network environment information of the location of the TIN service node after the authentication unit passes the authentication; an issuing unit configured to issue new configurations by the SCC through the mode subscribed by the TIN service node when the environment state of the TIN service node changes.
16. The system of claim 12, wherein, The TARF comprises: a separation module configured to separate the TIN identification code submitted to the TARF to obtain the identification storage code IMC; an acquisition module configured to acquire the TIN identification data routing according to the IMC separated by the separation module.
17. The system of claim 16, wherein, The TARF further comprises a TIN domain name service network element TMDF added in the bus of the 5GC and a TIN local domain name system TLD added in the MEC; The acquisition module is specifically configured to: submit the IMC in the TIN identification code to the TMDF, translate the IMC into the TLD address in the corresponding MEC according to the DNS domain name service of the TIN by the TMDF, and then translate the TIN identification code into the storage routing information of the TIN identification data by the TLD corresponding to the TLD address.
18. The system of claim 16, wherein, The TARF further comprises an authentication module; The separation module is further configured to separate the TIN identification code submitted to the TARF to obtain the telephone number of the TIN identification code publishing user; The authentication module is configured to submit an authentication application to the AUSF of the UDM through the bus to authenticate the user number separated from the TIN identification code and obtain an encryption key to ensure the legitimacy of the TIN publishing user and obtain the key for subsequent transmission.
19. The system of claim 12, wherein, The TDSF comprises a TIN data management TDSM module, a TIN data access interface TDAI module, a metadata node module and a data storage node module, the TDAI module is deployed in different levels and modes of MEC, the metadata node module is deployed in different levels and modes of MEC, and the data storage node module is deployed in the MEC; The TDSM module is configured to be responsible for the storage data management of the TIN data; The TDAI module is configured to provide a unified interface for the user to store data in the MEC, and to realize service matching of the storage task request of the TIN data publishing user through the UPF, store the TIN data published by the user to a specified location, and register in the metadata node; The metadata node module is configured to be responsible for the registration and management of the feature description data and the storage location information of the data stored by the data node; The data storage node module is configured to be responsible for the storage and reading of the TIN data.
20. The system of claim 12, wherein, The TASF comprises an AAA server deployed in the MEC; The AAA server is configured to complete user authentication, authorization and accounting for writing and reading TIN identification data, wherein the AAA server adopts an extended RADIUS protocol combined with OAuth for authentication and authorization.
21. The system of claim 20, wherein, The AAA server comprises a RADIUS server; The RADIUS server is configured to: receive a request for writing or reading TIN identification data sent by a client; send an authentication application to an AUSF of a core network for user information of the client making the request; if the authentication is successful, receive an access permission packet sent by the AUSF with an access user number, otherwise receive a rejection access packet sent by the AUSF; if the access permission packet is received, find a user information database according to a phone number of the user to obtain a role of the user, wherein different roles correspond to different TIN data access and operation permissions; send a token to the client to enable the client to subsequently access and operate TIN data through the token.
22. An electronic device, comprising: A computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the implementation method of the telecommunication identification network according to any one of claims 1-11.
23. A computer-readable storage medium, characterized in that, A computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the implementation method of the telecommunication identification network according to any one of claims 1-11.
Citation Information
Patent Citations
Method and descriptors for comparing object-induced information flows in a plurality of interaction networks
CN108604221A
Method for realizing network capability opening and related equipment
CN111356157A