A terminal device access core network control method and device
Patent Information
- Application Number
- CN202310833402.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-07
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-07-07
AI Technical Summary
可以看出,目前通信标准中定义的路由路径较长,并且在工业互联网场景下通常只会布置一套轻量级5GC,其中仅包含一个UPF,从而无法通过N3IWF网元实现终端的差异化计费等功能
[0015]本申请提出在核心网的W-AGF网元中设置数据转发逻辑,W-AGF网元会对来自终端设备的请求连接的信息进行解析,确定其目标地址为N3IWF网元时会直接将其转发到N3IWF。相较于传统的通信标准中定义的,W-AGF网元需要通过UPF向N3IWF网元转发数据,本申请的方案减少了数据的迂回,简化了终端设备接入核心网的路径。
Smart Images

Figure CN116782275B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a control method and apparatus for terminal equipment to access the core network. Background Technology
[0002] In the field of fifth-generation (5G) mobile communication technology, in industrial internet scenarios, when industrial terminal equipment accesses the 5G core network (5G Core, 5GC) from the gateway device, it generally needs to access the 5GC's non-3GPP interworking function (N3IWF) network element for separate authentication. This enables differentiated billing and Quality of Service (QoS) guarantees for different terminal devices. However, communication standards define that data routing for terminal devices requiring access to N3IWF network elements involves two User Plane Function (UPF) network elements to achieve data routing and forwarding.
[0003] For example, see Figure 1 This is a schematic diagram of the architecture of a communication system defined by a communication standard. For example... Figure 1 As shown, in the path of a terminal device accessing the 5GC's Data Network (DN), it first needs to connect to a Wireless Access Gateway Function (W-AGF) network element via a gateway device. Further, it outputs through the N3 interface of the W-AGF network element to the first UPF network element, and then through the N6 interface to the N3IWF. Further still, after accessing the N3IWF, it outputs through the N3 interface to the second UPF network element, finally connecting to the DN. It can be seen that the routing path defined in current communication standards is relatively long, and in industrial internet scenarios, typically only a lightweight 5GC is deployed, containing only one UPF. Therefore, it is impossible to implement terminal-specific billing functions through the N3IWF network element. Summary of the Invention
[0004] This application provides a control method and apparatus for terminal devices to access the core network, which simplifies the path for terminals to access the core network and improves data transmission rate.
[0005] In a first aspect, this application provides a control method for a terminal device to access a core network. The method is applied to a Wireless Access Gateway (W-AGF) network element in the core network, and the method includes: Receive a first request from the terminal device; the first request is used to request the establishment of a data transmission channel with a non-3GPP interoperability function N3IWF network element; The first request is parsed to determine that the target address of the first request is the N3IWF network element; The first request is forwarded to the N3IWF network element according to the target address, and the response information returned by the N3IWF network element is received; the response information is used to indicate that the data transmission channel between the terminal device and the N3IWF network element has been successfully established.
[0006] In some embodiments, before receiving the first request, the method further includes: Receive a second request from the terminal device; the second request is used to request the address information of the N3IWF network element from the data network DN; Forward the second request to the DN, and receive the address information of the N3IWF network element returned by the DN; The address information of the N3IWF network element is sent to the terminal device.
[0007] In some embodiments, the second request is transmitted via a pre-established Management Protocol Data Unit (PDU) session between the gateway device and the DN; the terminal device is connected to the gateway device, and the PDU session is established by the gateway device through the W-AGF when it goes online.
[0008] In some embodiments, after the data transmission channel is successfully established, the method further includes: When a data packet is received from a terminal device, it is determined whether the header of the data packet contains the identifier of the data transmission channel; If the packet header contains the identifier of the data transmission channel, then the data packet is forwarded to the N3IWF network element; If the packet header does not contain the identifier of the data transmission channel, the data packet is forwarded to the User Plane Function (UPF) network element through the N3 interface.
[0009] Secondly, this application provides a control device for terminal equipment to access the core network. The device is applied to a W-AGF network element in the core network, and the device includes: A communication unit is used to receive a first request from a terminal device; the first request is used to request the establishment of a data transmission channel with a non-3GPP interoperability function N3IWF network element. The processing unit is configured to parse the first request and determine that the target address of the first request is the N3IWF network element; The processing unit is further configured to instruct the communication unit to forward the first request to the N3IWF network element according to the target address, and to receive the response information returned by the N3IWF network element; the response information is used to indicate that the data transmission channel between the terminal device and the N3IWF network element has been successfully established.
[0010] In some embodiments, the communication unit is further configured to: Receive a second request from the terminal device; the second request is used to request the address information of the N3IWF network element from the data network DN; Forward the second request to the DN, and receive the address information of the N3IWF network element returned by the DN; The address information of the N3IWF network element is sent to the terminal device.
[0011] In some embodiments, the second request is transmitted via a pre-established Management Protocol Data Unit (PDU) session between the gateway device and the DN; the terminal device is connected to the gateway device, and the PDU session is established by the gateway device through the W-AGF when it goes online.
[0012] In some embodiments, the processing unit is further configured to: When a data packet is received from a terminal device through the communication unit, it is determined whether the header of the data packet contains the identifier of the data transmission channel; When the header contains the identifier of the data transmission channel, it instructs the communication unit to forward the data packet to the N3IWF network element; When the header does not contain the identifier of the data transmission channel, the communication unit is instructed to forward the data packet to the User Plane Function (UPF) network element through the N3 interface.
[0013] Thirdly, an electronic device is provided, comprising a controller and a memory. The memory stores computer-executable instructions, and the controller executes the computer-executable instructions in the memory to perform operational steps of any possible implementation of the method of the first aspect using hardware resources in the controller.
[0014] Fourthly, a computer-readable storage medium is provided, which stores instructions that, when executed on a computer, cause the computer to perform the methods described above.
[0015] This application proposes setting up data forwarding logic in the W-AGF network element of the core network. The W-AGF network element parses the connection request information from the terminal device, and if it determines that the destination address is the N3IWF network element, it will directly forward the request to the N3IWF. Compared to the traditional communication standard, where the W-AGF network element needs to forward data to the N3IWF network element through the UPF, the solution in this application reduces data detours and simplifies the path for the terminal device to access the core network. Attached Figure Description
[0016] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 A schematic diagram of the architecture of a communication system defined by a communication standard; Figure 2A This application provides a schematic diagram of the architecture of a communication system. Figure 2B This is a schematic diagram of the architecture of another communication system provided in an embodiment of this application; Figure 3 A flowchart illustrating a control method for a terminal device to access the core network, as provided in this application embodiment; Figure 4 A flowchart illustrating another control method for terminal equipment accessing the core network provided in this application embodiment; Figure 5 This application provides a schematic diagram of the structure of a control device for a terminal device to access the core network. Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this application. Obviously, the described embodiments are only some embodiments of the technical solutions of this application, and not all embodiments. Based on the embodiments recorded in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the technical solutions of this application.
[0018] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in sequences other than those illustrated or described herein. Furthermore, the term "and / or" herein is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Additionally, the character " / " herein, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.
[0019] The 3GPP communication standard defines a technical solution for accessing 5GC via gateway devices and W-AGF network elements in the R16 5WWC project. In the R18 5WWC Phase 2 project, a further technical solution is defined for terminal devices connected to the gateway device to access 5GC via the gateway device and W-AGF network elements. Currently, terminal devices connected to the gateway device are classified into two categories: Authenticable Non-3GPP devices (AUN3) and Non-Authenticable Non-3GPP devices (NAUN3). These two types of terminals access 5GC in different ways. This application's solution optimizes the access path for AUN3 to 5GC. To facilitate understanding of this application's solution, the technical terms used in this application will be introduced below.
[0020] (1) 5G Core Network: The core network plays a crucial role in the network, serving as the management center for all access and all services. The 5G core network, abbreviated as 5GC, is divided into the Control Plane (CP) and the User Plane (UP). It is interconnected with the Internet, third-party services, or operator services via the N6 interface by UPF network elements, supporting different access types, such as 3GPP access and non-3GPP access. The following describes the various network elements of the core network involved in this application.
[0021] (2) UPF network element: As the interconnection point between the Radio Access Network (RAN) and the DN, it is used to implement the Protocol Data Unit (PDU) session anchor point and realize functions such as packet routing and forwarding, traffic reporting, packet inspection and QoS processing.
[0022] (3) N3IWF network element: responsible for connecting untrusted non-3GPP access networks (such as WiFi) to 5GC. The terminal device establishes an IPSec tunnel with the N3IWF network element for data transmission. The N3IWF accesses the control plane and user plane of 5GC through the N2 interface and N3 interface respectively.
[0023] IPSec, developed based on Security Protocol and Internet Key Exchange (IKE), provides a range of services to communicating parties, including access control, connectionless integrity, data source authentication, encryption, and data stream classification encryption. Security Protocol includes Authentication Header (AH) and Encapsulate Security Payload (ESP). IKE is a hybrid protocol based on the TCP / IP framework of the Internet Security Association and Key Management Protocol (ISAKMP), combining key exchange protocols and key technology protocols. IPSec operates in two modes: tunnel mode and transport mode. In tunnel mode, the AH or ESP header and the ESP-encrypted user data are encapsulated in a new IP packet for transmission. In transport mode, the AH or ESP header and the ESP-encrypted user data are placed after the original IP packet header, without encapsulating a new IP packet.
[0024] (4) Access and Mobility Management Function (AMF) network element: used to perform registration, connection, reachability and mobility management, and provide authentication and authorization functions for terminal devices when they access the network.
[0025] (5) Session Management Function (SMF) network element: used to implement functions such as establishing, updating and releasing management sessions, maintaining PDU session status, group management, controlling and coordinating UPF network element toll data collection and flow control.
[0026] (6) Fully Qualified Domain Name (FQDN): refers to the fully qualified name of a domain that can be registered. Many hosts can be hosted under this domain name. The FQDN can specify the position of each host in the domain name tree.
[0027] With the application of wired access solutions in the Industrial Internet field, industrial terminal devices can connect to 5GC through gateway devices in industrial scenarios. In this scenario, AUN3 terminal devices that can be authenticated by 5GC can connect to N3IWF network elements to enable 5GC to provide differentiated billing and QoS guarantees for different AUN3 terminal devices. However, see [link to relevant documentation]. Figure 1 In this scenario, the communication standard specifies that the routing path for the terminal device requires traversing two UPF network elements. The specific transmission path is: terminal device — gateway device — W-AGF network element — UPF network element — N3IWF network element — UPF network element — DN. The path for the terminal device to connect to the DN through the core network is relatively long and cannot be implemented in the Industrial Internet of Things (IIoT).
[0028] In view of this, this application proposes a control method and apparatus for terminal devices to access the core network. It proposes to configure a routing judgment module in the W-AGF network element to parse the request information sent by the terminal device to access the N3IWF network element. When it is determined that the target address of the request information is the N3IWF network element, the request information is directly sent to the N3IWF network element without going through the UPF. This simplifies the path for the terminal device to access the core network to: terminal device — gateway device — W-AGF network element — N3IWF network element, reducing data detours and making it suitable for the scenario of deploying lightweight 5GC in the industrial Internet.
[0029] The following section first introduces the communication system architecture used in this application. (See also...) Figure 2A This is a schematic diagram of the architecture of a communication system provided in an embodiment of this application. Figure 2A The communication system shown includes terminal equipment, gateway equipment, W-AGF network elements, N3IWF network elements, UPF network elements, and a data network.
[0030] The terminal device can be an AUN3 terminal device in an industrial internet scenario. To implement QoS functions and differentiated billing for the terminal device, it needs to access the N3IWF network element of the core network through a gateway device and a W-AGF network element, and then the N3IWF network element connects to the data network through the N3 interface. The gateway device can be a traditional fixed network gateway (FN-RG) or a 5G-RG.
[0031] It should be noted that this application does not limit the number of terminal devices and gateway devices. Figure 2A This is just one example, and Figure 2A Other network elements included in the core network are not shown in the diagram. For example, see [link to relevant documentation]. Figure 2B This is a schematic diagram of another communication system architecture provided in this application. The core network may also include AMF network elements and SMF network elements.
[0032] Below, in conjunction with Figure 2A and Figure 2B The communication system shown illustrates the solution of this application. See also... Figure 3 This is a flowchart illustrating a control method for a terminal device accessing a core network, provided in an embodiment of this application. Exemplarily, the method flow can be... Figure 2A or Figure 2B The communication system shown includes W-AGF network elements for execution. Figure 3 The method flow shown specifically includes: 301, Received the first request from the terminal device.
[0033] The first request is used to request the establishment of a data transmission channel from the N3IWF network element. Optionally, the first request can be encapsulated using the IKEv2 protocol, and the data transmission channel to be established can be an IPSec tunnel between the terminal device and the N3IWF network element.
[0034] 302. The first request is parsed, and the target address of the first request is determined to be the N3IWF network element.
[0035] Optionally, after receiving the first request, the W-AGF network element can perform decapsulation and decoding on the first request to determine that the target address included is the address of the N3IWF network element.
[0036] 303, forward the first request to the N3IWF network element according to the target address.
[0037] For example, this application embodiment proposes that when the target address of the first request is determined to be an N3IWF network element, the first request can be directly forwarded to the N3IWF network element without having to forward it through the UPF network element.
[0038] 304, receive the response information returned by the N3IWF network element, and forward the response information to the terminal device.
[0039] The response information indicates that the data transmission channel between the terminal device and the N3IWF network element has been successfully established.
[0040] Based on the above scheme, this application proposes setting up data forwarding logic in the W-AGF network element of the core network. The W-AGF network element will parse the connection request information from the terminal device, and if it determines that the destination address is the N3IWF network element, it will directly forward it to the N3IWF. Compared with the traditional communication standard, where the W-AGF network element needs to forward data to the N3IWF network element through the UPF, the scheme of this application reduces data detours and simplifies the path for the terminal device to access the core network.
[0041] In some scenarios, before requesting the establishment of a data transmission channel from an N3IWF network element, the terminal device can first request the address information of the N3IWF network element from the data network (DN), such as requesting the IP address of the N3IWF network element. As an optional approach, the terminal device can send a second request to the W-AGF network element, which requests the address information of the N3IWF network element from the data network. The W-AGF network element forwards the second request to the data network and sends the address information returned by the data network back to the terminal device. For example, the terminal device can send an FQDN identifying the N3IWF to a DNS server and request the DNS server to resolve the FQDN to determine the public IP address of the N3IWF. As an example, the FQDN identifying the N3IWF can be: n3iwf.5gc.mnc <mnc>.mcc <mcc>.pub.3gppnetwork.org.
[0042] For example, such as Figure 2A or Figure 2B As shown in the communication system, when a terminal device sends request information (including the first and second requests mentioned above) to a W-AGF network element, it can also forward the request through a gateway device. For example, the gateway device can perform authentication in the core network through the W-AGF network element when it goes online, and after authentication, establish a PDU session from the gateway device to the UPF network element via the W-AGF network element.
[0043] Furthermore, when a terminal device connects to the gateway device, it can first authenticate with the gateway device. For example, the terminal device can connect to the gateway device via Wi-Fi and authenticate with the gateway device based on the IEEE 802.11 standard. Of course, this application does not limit the authentication method of the terminal device on the gateway device; for example, it can use open system authentication as defined by the IEEE 802.11 standard, or it can use shared key authentication. After authentication, the terminal device can access the data network and obtain the address information of the N3IWF network element through the PDU session created when the gateway device connects.
[0044] Furthermore, the terminal device sends a first request to the N3IWF network element based on the obtained address information of the N3IWF network element, requesting the establishment of a data transmission channel with the N3IWF network element. For example, for ease of description, the following description will use an IPSec tunnel as an example to illustrate the data transmission channel established between the terminal device and the N3IWF network element. The path of the IPSec tunnel is: terminal device — gateway device — W-AGF network element — N3IWF network element.
[0045] After the IPSec tunnel is established, subsequent terminal devices can transmit data to the tunnel via the NWu interface and ultimately to the N3IWF network element. For example, the terminal device can add an IPSec tunnel identifier to the header of data packets transmitted through the core network, so that the W-AGF can determine that the transmission path of the received data packets is an IPSec tunnel based on this identifier.
[0046] The following description, in order to further understand the solution of this application, is provided in conjunction with specific embodiments. (See attached document for details.) Figure 4 The flowchart below illustrates a control method for a terminal device to access the core network, as provided in this application embodiment. The method specifically includes: 401. The terminal device requests the address information of the N3IWF network element from the data network through the connected gateway device.
[0047] 402. The terminal device sends a first request to the W-AGF network element based on the obtained address information.
[0048] The first request is used to request the establishment of an IPSec tunnel with the N3IWF network element.
[0049] 403, the W-AGF network element determines whether the target address of the first request received is the address of the N3IWF network element.
[0050] If so, proceed to step 404.
[0051] If not, proceed to step 408.
[0052] 404. The W-AGF network element forwards the first request to the N3IWF network element and sends the response information returned by the N3IWF network element to the terminal device.
[0053] 405. The terminal device receives the response information and sends the first data packet to the W-AGF network element.
[0054] 406. The W-AGF network element determines whether the header of the first received data packet includes an IPSec tunnel identifier.
[0055] If so, proceed to step 407.
[0056] If not, proceed to step 408.
[0057] 407. The W-AGF network element forwards the first data packet to the N3IWF network element.
[0058] Optionally, after receiving the first data packet, the N3IWF can forward the first data packet to the UPF network element through the N3 interface, and the UPF network element can then transmit the first data packet to the data network.
[0059] 408. The W-AGF network element sends the received information to the UPF network element through the N3 interface.
[0060] Optionally, the UPF network element can route and forward the received information.
[0061] Based on the same concept as the method described above, see [link to relevant documentation]. Figure 5 This application provides a control device 500 for a terminal device to access a core network. The device 500 is used to execute the various steps in the above method, which will not be described again here to avoid repetition. The device 500 includes a communication unit 501 and a processing unit 502.
[0062] Communication unit 501 is used to receive a first request from a terminal device; the first request is used to request the establishment of a data transmission channel with a non-3GPP interoperability function N3IWF network element; Processing unit 502 is used to parse the first request and determine that the target address of the first request is the N3IWF network element; The processing unit 502 is further configured to instruct the communication unit 501 to forward the first request to the N3IWF network element according to the target address, and to receive the response information returned by the N3IWF network element; the response information is used to indicate that the data transmission channel between the terminal device and the N3IWF network element has been successfully established.
[0063] In some embodiments, the communication unit 501 is further configured to: Receive a second request from the terminal device; the second request is used to request the address information of the N3IWF network element from the data network DN; Forward the second request to the DN, and receive the address information of the N3IWF network element returned by the DN; The address information of the N3IWF network element is sent to the terminal device.
[0064] In some embodiments, the second request is transmitted via a pre-established Management Protocol Data Unit (PDU) session between the gateway device and the DN; the terminal device is connected to the gateway device, and the PDU session is established by the gateway device through the W-AGF when it goes online.
[0065] In some embodiments, the processing unit 502 is further configured to: When a data packet is received from a terminal device through the communication unit 501, it is determined whether the header of the data packet contains the identifier of the data transmission channel; When the header contains the identifier of the data transmission channel, the communication unit 501 is instructed to forward the data packet to the N3IWF network element; When the packet header does not contain the identifier of the data transmission channel, the communication unit 501 is instructed to forward the data packet to the User Plane Function (UPF) network element through the N3 interface.
[0066] Figure 6 A schematic diagram of the structure of an electronic device 600 provided in an embodiment of this application is shown. The electronic device 600 in this embodiment may further include a communication interface 603, such as a network port, through which the electronic device can transmit data. For example, the communication interface 603 can be used to implement the above-mentioned... Figure 5 The function of the communication unit 501 in the middle.
[0067] In this embodiment, the memory 602 stores instructions that can be executed by at least one controller 601. By executing the instructions stored in the memory 602, the at least one controller 601 can perform various steps in the above-described method. For example, the controller 601 can implement the above-described... Figure 5 The function of the processing unit 502 in the middle.
[0068] The controller 601 is the control center of the electronic device, capable of connecting various parts of the device via various interfaces and lines. It executes instructions stored in the memory 602 and retrieves data stored in the memory 602. Optionally, the controller 601 may include one or more processing units. The controller 601 may integrate an application controller and a modem controller. The application controller primarily handles the operating system and applications, while the modem controller primarily handles wireless communication. It is understood that the modem controller may not be integrated into the controller 601. In some embodiments, the controller 601 and the memory 602 may be implemented on the same chip; in other embodiments, they may be implemented on separate chips.
[0069] The controller 601 can be a general-purpose controller, such as a central processing unit (CPU), digital signal controller, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose controller can be a microcontroller or any conventional controller. The steps performed by the data statistics platform disclosed in the embodiments of this application can be directly executed by the hardware controller, or executed by a combination of hardware and software modules within the controller.
[0070] Memory 602, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 602 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 602 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 602 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.
[0071] By designing and programming the controller 601, for example, the code corresponding to the method described in the foregoing embodiments can be embedded into the chip, so that the chip can execute the steps of the foregoing method when running. How to design and program the controller 601 is a well-known technique to those skilled in the art, and will not be described in detail here.
[0072] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0073] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a controller of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the controller of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0074] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0075] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0076] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0077] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.< / mcc> < / mnc>
Claims
1. A control method for terminal equipment accessing the core network, characterized in that, The method is applied to the Wireless Access Gateway (W-AGF) network element in the core network, and the method includes: A first request is received from a terminal device; the first request is used to request the establishment of a data transmission channel with a non-3GPP interoperability function N3IWF network element, the data transmission channel to be established is an IPSec tunnel between the terminal device and the N3IWF network element, and the path of the IPSec tunnel flows sequentially through: the terminal device, the pre-established gateway device, the W-AGF network element and the N3IWF network element; The first request is parsed to determine that the target address of the first request is the N3IWF network element; The first request is forwarded to the N3IWF network element according to the target address, and the response information returned by the N3IWF network element is received; the response information is used to indicate that the data transmission channel between the terminal device and the N3IWF network element has been successfully established. After the data transmission channel is successfully established, the method further includes: When a data packet is received from a terminal device, it is determined whether the header of the data packet contains the identifier of the data transmission channel, which is the identifier of the IPSec tunnel; If the packet header contains the identifier of the data transmission channel, then the data packet is forwarded to the N3IWF network element; If the packet header does not contain the identifier of the data transmission channel, the data packet is forwarded to the User Plane Function (UPF) network element through the N3 interface.
2. The method according to claim 1, characterized in that, Before receiving the first request, the method further includes: Receive a second request from the terminal device; the second request is used to request the address information of the N3IWF network element from the data network DN; Forward the second request to the DN, and receive the address information of the N3IWF network element returned by the DN; The address information of the N3IWF network element is sent to the terminal device.
3. The method according to claim 2, characterized in that, The second request is transmitted through a pre-established Management Protocol Data Unit (PDU) session between the gateway device and the DN; the terminal device is connected to the gateway device, and the PDU session is established by the gateway device through the W-AGF when it goes online.
4. A control device for terminal equipment to access the core network, characterized in that, The device is applied to W-AGF network elements in the core network, and the device includes: A communication unit is used to receive a first request from a terminal device; the first request is used to request the establishment of a data transmission channel with a non-3GPP interoperability function N3IWF network element, the data transmission channel to be established is an IPSec tunnel between the terminal device and the N3IWF network element, and the path of the IPSec tunnel flows sequentially through: the terminal device, the pre-established gateway device, the W-AGF network element and the N3IWF network element; The processing unit is configured to parse the first request and determine that the target address of the first request is the N3IWF network element; The processing unit is further configured to instruct the communication unit to forward the first request to the N3IWF network element according to the target address, and to receive response information returned by the N3IWF network element; the response information is used to indicate that the data transmission channel between the terminal device and the N3IWF network element has been successfully established. The processing unit is further configured to: When a data packet is received from a terminal device through the communication unit, it is determined whether the header of the data packet contains the identifier of the data transmission channel, wherein the identifier of the data transmission channel is the identifier of the IPSec tunnel; When the header contains the identifier of the data transmission channel, it instructs the communication unit to forward the data packet to the N3IWF network element; When the header does not contain the identifier of the data transmission channel, the communication unit is instructed to forward the data packet to the User Plane Function (UPF) network element through the N3 interface.
5. The apparatus according to claim 4, characterized in that, The communication unit is further used for: Receive a second request from the terminal device; the second request is used to request the address information of the N3IWF network element from the data network DN; Forward the second request to the DN, and receive the address information of the N3IWF network element returned by the DN; The address information of the N3IWF network element is sent to the terminal device.
6. The apparatus according to claim 5, characterized in that, The second request is transmitted through a pre-established Management Protocol Data Unit (PDU) session between the gateway device and the DN; the terminal device is connected to the gateway device, and the PDU session is established by the gateway device through the W-AGF when it goes online.
7. An electronic device, characterized in that, include: Memory and controller; Memory, used to store program instructions; A controller is configured to invoke program instructions stored in the memory and execute the method of any one of claims 1-3 according to the obtained program.
8. A computer storage medium storing computer-executable instructions, characterized in that, The computer-executable instructions are used to perform the method as described in any one of claims 1-3.
Citation Information
Patent Citations
Communication method, device and system
CN113518475A