Remote user equipment access method, device, equipment, medium and program product
By accessing the anycast address through the communication connection between the remote user equipment and the relay user equipment and the PDU session, the N3IWF is addressed in anycast mode, which solves the problems of high deployment cost and inaccurate access location and realizes efficient and reliable access to the core network.
Patent Information
- Application Number
- CN202311012260.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-11
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2043-08-11
AI Technical Summary
In the near-domain services defined by 3GPP, remote UEs need to use DNS for distributed addressing when accessing through N3IWF, resulting in high deployment costs, inaccurate access locations, and complex round-trip traffic.
The remote user equipment accesses the pre-configured anycast address through the communication connection and PDU session established with the relay user equipment. The network side determines the target N3IWF among multiple N3IWFs and uses anycast addressing to avoid DNS deployment.
It reduces deployment costs, improves access reliability and user experience, simplifies network construction and routing design, and reduces traffic traveling between different domains.
Smart Images

Figure CN117015075B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of remote user equipment access, and in particular to a remote user equipment access method, apparatus, device, medium and program product. Background Art
[0002] In the Proximity Service (ProSe) defined by 3GPP (3rd Generation Partnership Project), a remote UE (User Equipment) is connected to the Internet with the help of a relay UE.
[0003] When a remote UE accesses the network through the N3IWF (Non-3GPP InterWorking Function), it typically requires the use of the DNS (Domain Name System) for distributed addressing. However, this requires the N3IWF to be located on the public network or a dedicated DNS to be set up in the 5G Core Virtual Private Network (5GC VPN), which results in high deployment costs. Summary of the Invention
[0004] The embodiments of the present application provide a remote user equipment access method, apparatus, device, medium and program product, which use anycast to discover N3IWF, thereby reducing deployment costs.
[0005] In a first aspect, an embodiment of the present application provides a remote user equipment access method, the method comprising:
[0006] The remote user equipment accesses a pre-configured anycast address through a first communication connection established with the relay user equipment and a protocol data unit (PDU) session established by the relay user equipment, so that the network side determines a target N3IWF from among multiple non-3GPP network interconnection functions (N3IWFs) based on the anycast address;
[0007] Establish a second communication connection with the target N3IWF to access the core network through the second communication connection between the target N3IWF.
[0008] In one embodiment, the remote user equipment accesses a pre-configured anycast address through a first communication connection established with the relay user equipment and a PDU session established by the relay user equipment, so that the network side determines a target N3IWF from multiple N3IWFs based on the anycast address, including:
[0009] A data packet sent to an anycast address to a relay user equipment to instruct the relay user equipment to forward the data packet to the anycast address to a target user plane function UPF through a PDU session to determine a target N3IWF corresponding to the anycast address through a data network (DN), wherein the PDU session includes at least one of a local PDU session and a local offload session.
[0010] In one embodiment, the method further comprises:
[0011] Obtain authorization information and service configuration information for the local domain service, including the anycast address.
[0012] In one embodiment, the second communication connection includes an Internet Security Protocol (IPSec) tunnel, and establishing the second communication connection with the target N3IWF includes:
[0013] Establish an IPSec tunnel with the target N3IWF through the Internet Key Exchange (IKE) process.
[0014] In one embodiment, establishing an IPSec tunnel with a target N3IWF through an IKE process includes:
[0015] Perform an initial IKE exchange with the target N3IWF to establish a security association (SA).
[0016] Send an IKE authentication message, which is used to request an IKE authentication exchange to the target N3IWF;
[0017] Receive an IKE authentication response sent by the target N3IWF based on the IKE authentication message, and establish an Extended Authentication Protocol EAP-5G session based on the IKE authentication response;
[0018] Establish an IPSec signaling SA with the target N3IWF and obtain the internal address assigned by the target N3IWF;
[0019] Receive the non-access layer NAS registration success message fed back by the target N3IWF and initiate the process of establishing a non-3GPP access session.
[0020] In one embodiment, establishing an EAP-5G session based on an IKE authentication response includes:
[0021] Send an IKE authentication request to start NAS registration, interact with the access and mobility management function AMF and the authentication service function AUSF to perform the authentication process, create a NAS security context and N3IWF key after successful authentication, and establish an EAP-5G session.
[0022] In a second aspect, an embodiment of the present application provides a remote user equipment access method, the method comprising:
[0023] Addressing the anycast address preset in the remote user equipment based on the first communication connection established between the remote user equipment and the relay user equipment and the PDU session established by the relay user equipment;
[0024] A target N3IWF is determined among multiple N3IWFs based on the anycast address, and the target N3IWF is used to establish a second communication connection with the remote user equipment, so that the remote user equipment accesses the core network through the second communication connection between the remote user equipment and the target N3IWF.
[0025] In one embodiment, the anycast address is used to identify a group of network interfaces, and determining a target N3IWF among multiple N3IWFs based on the anycast address includes:
[0026] The nearest target network interface is found from a group of network interfaces according to the pre-learned anycast routing table, and the N3IWF connected to the target network interface is determined as the target N3IWF.
[0027] In one embodiment, obtaining a pre-set anycast address in the remote user equipment based on a first communication connection established between the remote user equipment and the relay user equipment and a PDU session established by the relay user equipment includes:
[0028] A data packet forwarded to the anycast address by the relay user equipment is received based on the PDU session, where the data packet is sent by the remote user equipment to the relay user equipment based on the first communication connection.
[0029] In a third aspect, an embodiment of the present application provides a remote user equipment access device, the device comprising:
[0030] An address access module is configured to access a pre-configured anycast address through a first communication connection established with a relay user equipment and a protocol data unit (PDU) session established by the relay user equipment, so that the network side determines a target N3IWF from among multiple non-3GPP network interconnection functions (N3IWFs) based on the anycast address;
[0031] The access module is used to establish a second communication connection with the target N3IWF to access the core network through the second communication connection between the target N3IWF and the core network.
[0032] In a fourth aspect, an embodiment of the present application provides a remote user equipment access device, the device comprising:
[0033] An address acquisition module, configured to address an anycast address preset in the remote user equipment based on a first communication connection established between the remote user equipment and the relay user equipment and a PDU session established by the relay user equipment;
[0034] An address access module is used to determine a target N3IWF among multiple N3IWFs based on the anycast address, and the target N3IWF is used to establish a second communication connection with the remote user equipment so that the remote user equipment accesses the core network through the second communication connection between the remote user equipment and the target N3IWF.
[0035] In a fifth aspect, an embodiment of the present application provides a communication device, including: a transceiver;
[0036] A transceiver is used to access a pre-configured anycast address through a first communication connection established with a relay user equipment and a PDU session established by the relay user equipment, so that the network side determines a target N3IWF among multiple N3IWFs based on the anycast address; and establish a second communication connection with the target N3IWF to access the core network through the second communication connection between the target N3IWF and the target N3IWF.
[0037] In a sixth aspect, an embodiment of the present application provides a communication device including: a transceiver and a processor;
[0038] A transceiver configured to address an anycast address preset in the remote user equipment based on a first communication connection established between the remote user equipment and the relay user equipment and a PDU session established by the relay user equipment;
[0039] The processor is configured to determine a target N3IWF among multiple N3IWFs based on the anycast address, where the target N3IWF is configured to establish a second communication connection with a remote user equipment, so that the remote user equipment accesses the core network through the second communication connection with the target N3IWF.
[0040] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the remote user equipment access method provided in the first aspect or the second aspect.
[0041] In an eighth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, characterized in that when the computer program is executed by a processor, the steps of the remote user equipment access method provided in the first aspect or the second aspect are implemented.
[0042] In the above-mentioned remote user equipment access method, apparatus, device, medium and program product, the remote UE accesses a pre-configured anycast address through a first communication connection established with the relay UE and a PDU session established by the relay UE, and the network side determines the target N3IWF from multiple N3IWFs based on the anycast address; thereafter, the remote UE establishes a second communication connection with the target N3IWF and accesses the core network through the second communication connection with the target N3IWF. The embodiment of the present application uses an anycast method to discover the N3IWF, and does not require the deployment of an enhanced DNS and the upgrading of the existing addressing process, thereby reducing deployment costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 This is a diagram of an application environment of a remote user equipment access method according to an embodiment;
[0044] Figure 2 1 is a flow chart of a remote user equipment access method according to an embodiment;
[0045] Figure 3 is a schematic diagram of anycast routing in one embodiment;
[0046] Figure 4 A topological diagram of a network structure in one embodiment;
[0047] Figure 5 1 is a flow chart of a remote user equipment access method according to another embodiment;
[0048] Figure 6 A schematic diagram of a flow chart of steps for establishing an IPSec tunnel in one embodiment;
[0049] Figure 7 is a complete schematic diagram of a remote user equipment access method according to an embodiment;
[0050] Figure 8 1 is a flow chart of a remote user equipment access method in another embodiment;
[0051] Figure 9 is a structural block diagram of a remote user equipment access device in one embodiment;
[0052] Figure 10 is a structural block diagram of a remote user equipment access device in one embodiment;
[0053] Figure 11 is a diagram showing the internal structure of a communication device in one embodiment;
[0054] Figure 12 FIG. 4 is a diagram showing the internal structure of a communication device in another embodiment. DETAILED DESCRIPTION
[0055] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0056] Figure 1 This is a schematic diagram of an application scenario for remote user equipment access provided by an embodiment of the present application. Figure 1 As shown, the application scenario includes a remote UE 101, a relay UE 102, and a network device 103. A point-to-point communication connection can be established between the remote UE 101 and the relay UE 102; and the remote UE 101 and the relay UE 102 can establish a communication connection with the network device 103 respectively.
[0057] The network device 103 may include NG-RAN (Next Generation-Radio Access Network), N3IWF (Non-3GPP InterWorking Function), and UPF (User Plane Function). The NG-RAN may be a base station in a 5G network. The N3IWF may be an access point for non-3GPP access to a mobile network, and may implement functions similar to a base station. The UPF performs network functions such as executing user plane policies and forwarding user data in the 5G core network.
[0058] The remote UE 101 is located at the end in the terminal-to-network near-domain relay networking and is a user device that accesses the Internet through the relay UE; the relay UE 102 is directly connected to the 5G network in the terminal-to-network near-domain relay networking. The remote UE 101 and the relay UE 102 can be wireless terminals, and the wireless terminals can be devices that provide voice and / or other business data connectivity to users, or handheld devices with wireless connection capabilities, or other processing devices connected to wireless modems. The wireless terminal can communicate with one or more core networks via a radio access network (Radio Access Network, abbreviated as RAN). The wireless terminal can be a mobile phone (or "cellular" phone) and a computer with a mobile terminal, for example, a portable, pocket-sized, handheld, computer-built-in or vehicle-mounted mobile device, which exchanges language and / or data with the radio access network. A wireless terminal may also be referred to as a system, subscriber unit, subscriber station, mobile station, mobile, remote station, remote terminal, access terminal, user terminal, user agent, or user equipment, without limitation herein.
[0059] Traditionally, in 3GPP-defined Near Field Services (ProSe), remote UEs rely on relay UEs to connect to the internet. When remote UEs access the network through the N3IWF (Network-Interconnected Wi-Fi Fabric), distributed addressing using DNS is typically required. However, this requires the N3IWF to be located on the public network or a dedicated DNS to be set up within the 5GC VPN, resulting in high deployment costs. In addition, the following problems also exist in traditional technologies: 1. The remote UE needs to use TAI (Tracking Area Identity) to construct the FQDN (Fully Qualified Domain Name) of the N3IWF. If the relay UE does not carry TAI in the discovery information, the remote UE cannot obtain TAI, and the remote UE cannot access the core network; 2. When the FQDN of the N3IWF does not carry TAI information, the DNS needs to determine the access location of the remote UE based on the N6 address segment of the UPF of the relay UE or the address after NAT (Network Address Translation); if the UPF of the relay UE is the central anchor point, the corresponding location information is inaccurate, which will also cause the remote UE to be unable to access the core network; 3. If the DNS of the Internet is reused to avoid duplicate construction, the traffic of the relay UE may travel back and forth between different domains (for example, the Internet, access domain and 5GC VPN, etc.) many times, which brings complexity to network construction and routing design.
[0060] Based on the above-mentioned traditional technology, an embodiment of the present application provides a remote UE access method, in which the remote UE accesses a pre-configured anycast address through a first communication connection established with the relay UE and a PDU session established by the relay UE; then, the network side determines the target N3IWF in the N3IWF based on the anycast address; thereafter, the remote UE establishes a second communication connection with the target N3IWF, and accesses the core network through the second communication connection with the target N3IWF. The technical solution provided by the embodiment of the present application adopts anycast addressing, so DNS does not need to be deployed, thereby reducing deployment costs. Furthermore, the remote UE can access the core network without TAI or precise location information, which ensures the access reliability of the remote UE and improves the user experience; and there is no need for the relay UE's traffic to travel back and forth between different domains, reducing the difficulty of network construction and routing design.
[0061] It should be noted that the beneficial effects or technical problems solved by the embodiments of the present application are not limited to this one, but may also include other implicit or related problems. For details, please refer to the description of the following embodiments.
[0062] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0063] In one embodiment, Figure 2 As shown, a remote user equipment access method is provided, which is applied to Figure 1 The remote UE device in the example is used as an example to illustrate, including the following steps:
[0064] Step 201: Access a pre-configured anycast address through a first communication connection established with a relay UE and a PDU session established by the relay UE, so that the network side determines a target N3IWF among multiple N3IWFs based on the anycast address.
[0065] To implement near-area services, the remote UE and relay UE first obtain authorization information and service configuration information for the near-area services. The service configuration information obtained by the remote UE includes the anycast address. A first communication connection is then established between the remote UE and the relay UE. The relay UE then establishes a PDU session carrying the remote UE's traffic. Specifically, the relay UE establishes a data transmission channel with the Local Area Data Network (LADN) via the NG-RAN and the relay UE's corresponding target UPF.
[0066] After the first communication connection and PDU session are established, the remote UE transmits the anycast address (e.g., IP-ac) to the relay UE's LADN through the first communication connection and PDU session. The routing device in the LADN pre-learns the anycast routing table based on the anycast routing protocol. When addressing the anycast address, the routing device determines the target N3IWF for communication with the remote UE from multiple N3IWFs based on the anycast address and the anycast routing table.
[0067] Anycast, also known as omnicast, selectedcast, or simulcast, is a network addressing and routing strategy that allows data to be sent to the "nearest" or "best" destination based on the routing topology (routing table). In other words, anycast enables a discovery mechanism to the nearest node.
[0068] The basic communication structure of anycast can include addressing, routing, group management and link address resolution. The anycast routing table stores the routing relationships between multiple N3IWFs and the routing relationships between multiple N3IWFs and network interfaces.
[0069] Understandably, determining the target N3IWF through anycast addresses can decouple the binding relationship between edge N3IWF and location, avoiding the impact of changes in network parameters on the process; and, by utilizing the self-learning of the anycast routing protocol, nearby access points can be automatically found, thereby improving the effectiveness of addressing and simplifying network implementation.
[0070] Step 202: Establish a second communication connection with the target N3IWF to access the core network through the second communication connection with the target N3IWF.
[0071] After determining the target N3IWF based on the anycast address, the remote UE establishes a second communication connection with the target N3IWF. This second communication connection may include an IPSec (Internet Protocol Security) tunnel. It should be noted that the second communication connection is not limited to the aforementioned IPSec tunnel and may also be implemented in other ways. The remote UE can then communicate data with the core network through the target N3IWF.
[0072] In the above embodiment, the remote UE accesses a pre-configured anycast address through a first communication connection established with the relay UE and a PDU session established by the relay UE. The network side determines the target N3IWF from multiple N3IWFs based on the anycast address. Thereafter, the remote UE establishes a second communication connection with the target N3IWF and accesses the core network through the second communication connection with the target N3IWF. The embodiment of the present application uses anycast to discover the N3IWF, which does not require the construction of a complex domain name and the deployment of DNS, thereby reducing deployment costs.
[0073] In one embodiment, the above-mentioned remote UE accesses a pre-configured anycast address through a first communication connection established with the relay UE and a PDU session established by the relay UE, so that the network side determines the target N3IWF among multiple N3IWFs based on the anycast address. The step may include: the remote UE sends a data packet to the anycast address to the relay UE to instruct the relay UE to forward the data packet to the anycast address to the target UPF through the PDU session, so as to determine the target N3IWF corresponding to the anycast address through the data network DN. The PDU session includes at least one of a local PDU session and a local offload session: the local PDU session uses a dedicated DDN to terminate the session locally; the local offload session locally offloads traffic by inserting branch points such as ULCL (Uplink Classifier) and BP (Branching Point). The remote UE establishes a first communication connection with the relay UE, and the relay UE establishes a PDU session that carries the remote UE. Afterwards, the remote UE sends a data packet to the anycast address to the relay UE through the first communication connection. After the relay UE receives the data packet of the anycast address, it transmits the data packet to its NG-RAN based on the PDU session, and then transmits it to the target UPF corresponding to the relay UE.
[0074] The target UPF can be located in the same routing domain as the routing device in the local DN of the relay UE, and can pre-learn the anycast routing table based on the anycast routing protocol. After receiving the anycast address, the target UPF can look up the anycast address in the anycast routing table and determine a set of network interfaces corresponding to the anycast address; then, based on the anycast routing protocol, it can determine the network interface closest to the target UPF and determine the N3IWF connected to the network interface as the target N3IWF. Figure 3 shown.
[0075] In one embodiment, since there is no need to deploy DNS, the N3IWF in the local data network can be set in the 5G System network domain, such as Figure 4 When the local data network's N3IWF is not set up in the 5GS network domain, NAT is required between the N3IWF and the UPF in the 5GS network domain for data transmission. However, when the local data network's N3IWF is set up in the 5GS network domain, NAT is no longer required between the UPF and the N3IWF, preventing traffic from being redirected between domains. This further simplifies routing and improves security and efficiency.
[0076] In the above embodiment, the remote UE sends a data packet to the anycast address to the relay UE, instructing the relay UE to forward the data packet to the anycast address to the target UPF via the PDU session, so as to determine the target N3IWF corresponding to the anycast address via the data network. The embodiment of the present application uses the PDU session and the anycast address to increase the speed at which the remote UE discovers the target N3IWF, thereby increasing the access speed of the remote UE.
[0077] In one embodiment, Figure 5 As shown, the remote UE access method provided in the embodiment of the present application may include the following steps:
[0078] Step 301: The relay UE obtains authorization information and service configuration information of the near-area service and establishes an initial session.
[0079] A communication connection has been established between the relay UE and the core network. Therefore, the relay UE can obtain authorization information and service configuration information for the near-area service through the NG-RAN and the target UPF corresponding to the relay UE. The authorization information obtained by the relay UE is used to allow the UE to act as a relay device for the near-area service, and the service configuration information is used to configure the relay UE so that the relay UE has the relevant functions of the near-area service.
[0080] Step 302: The remote UE obtains authorization information and service configuration information of the near-area service.
[0081] The service configuration information includes anycast address, near-domain service policy and URSP (UE Route Selection Policy, user route selection policy).
[0082] The remote UE may set the authorization information and service configuration information for the near-field service at the factory, or obtain the authorization information and service configuration information for the near-field service from the core network when accessing the core network during a historical period. It should be noted that the method for obtaining the authorization information and service configuration information is not limited to the above method, and other methods may also be used.
[0083] The authorization information obtained by the remote UE is used to allow the remote UE to communicate with the relay UE and access the core network through the relay UE; the service configuration information obtained by the remote UE is used to configure the remote UE, so that the remote UE has the relevant functions of the near-area service.
[0084] Step 303: A discovery process is performed between the remote UE and the relay UE.
[0085] In the discovery process, the remote UE selects an L3 relay UE as its Internet access relay and selects "non-seamless offload mode" according to the access policy, that is, accessing the network through the N3IWF.
[0086] Step 304: The remote UE establishes a first communication connection with the relay UE, and the relay UE establishes a PDU session.
[0087] The first communication connection may be a point-to-point communication connection.
[0088] After the remote UE discovers the relay UE, it establishes a point-to-point connection with the relay UE. If no matching session has been established between the remote UE and the relay UE, the relay UE uses the specified session parameters based on the RSC (Relay Service Code) mapping to establish a PDU session that carries the relay traffic.
[0089] The PDU session may include at least one of a local PDU session and a local offload session. The local offload session may employ an uplink classifier (ULCL) or a branch point (BP). It is understood that the local offload session may offload traffic, thereby increasing the speed at which the remote UE discovers the N3IWF and thereby improving the access speed of the remote UE.
[0090] Step 305: The relay UE allocates an IP (Internet Protocol) address to the remote UE.
[0091] The IP address is used for data transmission between the relay UE and the remote UE.
[0092] Step 306: The remote UE sends a data packet to the anycast address to the relay UE through the first communication connection. The relay UE transmits the data packet to the anycast address to the target UPF through the PDU session. The data network DN determines the target N3IWF corresponding to the anycast address.
[0093] In step 307, the remote UE and the target N3IWF establish an IPSec tunnel through the IKE process.
[0094] In the above embodiment, both the relay UE and the remote UE first obtain the authorization information and service configuration information of the near-domain service. After that, the remote UE establishes a first communication connection with the relay UE, and the relay UE establishes a PDU session. Then, the remote UE accesses the anycast address based on the first communication connection and the PDU session. The local data network determines the target N3IWF according to the anycast address. The remote UE and the target N3IWF establish an IPSec tunnel through the IKE process and access the core network through the target N3IWF. In the embodiment of the present application, traffic offloading can be performed through the PDU session, and the target N3IWF can be quickly discovered through the anycast address. Therefore, the remote UE can quickly access the core network, which not only improves the access reliability, but also improves the user experience.
[0095] In one embodiment, Figure 6 As shown, the process of establishing an IPSec tunnel with the target N3IWF through the IKE process may include:
[0096] In step 401, the remote UE performs an initial IKE exchange with the target N3IWF to establish a security association (SA).
[0097] Step 402: The remote UE sends an IKE authentication message IKE_AUTH Req (UE Id, without AUTH).
[0098] The IKE authentication message is used to request IKE authentication exchange from the target N3IWF.
[0099] In step 403, the remote UE receives the IKE authentication response sent by the target N3IWF based on the IKE authentication message, and starts an EAP (Extensive Authentication Protocol)-5G session based on the IKE authentication response.
[0100] The target N3IWF receives the IKE_AUTH Req sent by the remote UE and sends an IKE authentication feedback (EAP-Req / 5G-Start) to the remote UE. The remote UE receives the IKE authentication feedback, sends an IKE authentication request based on the IKE authentication feedback to initiate NAS (Non-access stratum) registration, interacts with the AMF (Access and Mobility Management Function) and AUSF (Authentication Server Function) to perform the authentication process, creates a NAS security context and N3IWF key, and completes the EAP-5G session.
[0101] In step 404, the remote UE establishes an IPSec signaling SA with the target N3IWF and obtains the inner IP address allocated by the target N3IWF to the remote user equipment.
[0102] In step 405, the remote UE receives the non-access stratum (NAS) registration success message fed back by the target N3IWF and initiates a process of establishing a non-3GPP access session.
[0103] The target N3IWF sends a NAS registration success message to the remote UE, indicating that the remote UE has successfully registered. After successful registration, the remote UE initiates a non-3GPP access session process so that the remote UE can use services normally.
[0104] Based on the above embodiment, the complete process can be referred to Figure 7 As shown, SMF (Session Management Function) controls the establishment of UE sessions, manages sessions, and stores UE session contexts to control the user plane forwarding path of the terminal.
[0105] In the above embodiment, the remote UE and the target N3IWF establish an IPSec tunnel based on the IKE process, after identity authentication and key distribution, so that the remote UE can subsequently transmit data with the target N3IWF through a dedicated data transmission channel, thereby ensuring the security and traceability of the remote UE traffic.
[0106] In one embodiment, Figure 8 As shown, a remote user equipment access method is provided, which is applied to Figure 1 The relay UE corresponding to the target UPF is used as an example to illustrate, including the following steps:
[0107] Step 501: The target UPF addresses the anycast address preset in the remote UE based on the first communication connection established between the remote UE and the relay UE and the PDU session established by the relay UE.
[0108] The remote UE is pre-configured with an anycast address. During the implementation of the near-domain service, the remote UE establishes a first communication connection with the relay UE, and the relay UE establishes a PDU session that carries the remote UE's traffic. The remote UE then transmits data packets destined for the anycast address to the relay UE via the first communication connection. The relay UE then transmits data packets destined for the anycast address to the target UPF corresponding to the relay UE based on the PDU session.
[0109] Step 502: Determine a target N3IWF among multiple N3IWFs based on the anycast address.
[0110] The target N3IWF is used to establish a second communication connection with the remote UE, so that the remote UE accesses the core network through the second communication connection between the remote UE and the target N3IWF.
[0111] The target UPF is located in the same routing domain as the routing devices in the local data network and has pre-learned the anycast routing table based on the anycast routing protocol. Upon receiving a packet to the anycast address, the target UPF searches the anycast routing table for a route based on the anycast address and ultimately addresses the target N3IWF to communicate with the remote UE via the local data network.
[0112] In the above embodiment, the target UPF addresses the anycast address pre-set in the remote UE based on the first communication connection established between the remote UE and the relay UE and the PDU session established by the relay UE; the target N3IWF is determined from multiple N3IWFs based on the anycast address; and the target N3IWF establishes a second communication connection with the remote UE, so that the remote UE accesses the core network through the second communication connection between the target N3IWF and the remote UE. In the example of the present application, anycast routing addressing relies on self-learning of routes, does not require the DNS process and the construction of a DNS server, and simplifies the configuration and implementation of the network.
[0113] In one embodiment, the above-mentioned step of obtaining the anycast address pre-set in the remote UE based on the first communication connection established between the remote UE and the relay UE and the PDU session established by the relay UE may include: the target UPF receives the anycast address sent by the relay UE based on the PDU session, and the anycast address is sent by the remote UE to the relay UE based on the first communication connection.
[0114] During the implementation of near-field services, a remote UE establishes a first communication connection with a relay UE. The relay UE then establishes a PDU session that carries the remote UE's traffic. The remote UE then transmits an anycast address to the relay UE via the first communication connection. The relay UE, based on the PDU session, transmits the anycast address to the target UPF corresponding to the relay UE. The target UPF receives the anycast address and determines the target N3IWF based on the anycast address.
[0115] In the above embodiment, the target UPF receives the anycast address sent by the relay UE based on the PDU session, and the PDU session can offload traffic, thereby increasing the speed of discovering the N3IWF and further improving the access reliability of the remote UE.
[0116] In one embodiment, the anycast address is used to identify a group of network interfaces, which typically belong to different nodes. The step of determining a target N3IWF among multiple N3IWFs based on the anycast address may include: searching for the nearest target network interface from the group of network interfaces based on a pre-learned anycast routing table, and determining the N3IWF to which the target network interface is connected as the target N3IWF.
[0117] The routing device will send data packets whose destination address is an anycast address to the network interface closest to the routing device. In the case where the routing device is the target UPF, the target UPF searches the set of network interfaces identified by the anycast address based on the anycast routing table to find the target network interface closest to the target UPF. It then determines the N3IWF connected to the target network interface as the target N3IWF to be communicated with the remote UE.
[0118] It should be noted that the addressing process is usually multi-hop, and each hop has a target network interface.
[0119] In the above embodiment, the target UPF finds the nearest target network interface from a set of network interfaces based on a pre-learned anycast routing table, and determines the N3IWF connected to the target network interface as the target N3IWF. The present embodiment uses anycast routing addressing to decouple the binding relationship between the edge N3IWF identifier and location, thereby avoiding the impact of network parameter changes on the process. Furthermore, the self-learning of the anycast routing protocol can automatically find nearby access points, thereby improving addressing efficiency and simplifying network implementation.
[0120] It should be understood that, although the various steps in the above flow chart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the above flow chart may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0121] In one embodiment, Figure 9 As shown, a remote user equipment access device is provided, comprising:
[0122] An address access module 601 is configured to access a pre-configured anycast address through a first communication connection established with a relay user equipment and a protocol data unit (PDU) session established by the relay user equipment, so that the network side determines a target N3IWF from among multiple non-3GPP network interconnection functions (N3IWFs) based on the anycast address;
[0123] The access module 602 is configured to establish a second communication connection with the target N3IWF, so as to access the core network of the remote user equipment through the second communication connection with the target N3IWF.
[0124] In one embodiment, the address access module 601 is specifically used to send data to the anycast address to the relay user equipment, including instructing the relay user equipment to forward the data packet to the anycast address to the target user plane function UPF through the PDU session, so as to determine the target N3IWF corresponding to the anycast address through the data network DN, wherein the PDU session includes at least one of a local PDU session and a local offload session.
[0125] In one embodiment, the apparatus further comprises:
[0126] The configuration acquisition module is used to obtain authorization information and service configuration information of the local domain service, where the service configuration information includes the anycast address.
[0127] In one embodiment, the second communication connection includes an Internet Security Protocol IPSec tunnel, and the access module 602 is specifically configured to establish the IPSec tunnel with the target N3IWF through an Internet Key Exchange (IKE) process.
[0128] In one of the embodiments, the access module 602 is specifically used to perform an initial IKE exchange with the target N3IWF to establish a security association SA; send an IKE authentication message, which is used to request an IKE authentication exchange from the target N3IWF; receive an IKE authentication response sent by the target N3IWF based on the IKE authentication message, and establish an Extended Authentication Protocol EAP-5G session based on the IKE authentication response; establish an IPSec signaling SA with the target N3IWF, and obtain the internal address allocated by the target N3IWF to the remote user equipment; receive a non-access layer NAS registration success message fed back by the target N3IWF, and initiate a process to establish a non-3GPP access session.
[0129] In one embodiment, the access module 602 is specifically used to send an IKE authentication request to initiate NAS registration, interact with the access and mobility management function AMF and the authentication service function AUSF to perform the authentication process, create a NAS security context and N3IWF key after successful authentication, and establish an EAP-5G session.
[0130] In one embodiment, Figure 10 As shown, a remote user equipment access device is provided, comprising:
[0131] An address acquisition module 701 is configured to address an anycast address preset in the remote user equipment based on a first communication connection established between the remote user equipment and the relay user equipment and a PDU session established by the relay user equipment;
[0132] The address access module 702 is used to determine a target N3IWF among multiple N3IWFs based on the anycast address. The target N3IWF is used to establish a second communication connection with the remote user equipment, so that the remote user equipment accesses the core network through the second communication connection between the target N3IWF and the target N3IWF.
[0133] In one embodiment, the anycast address is used to identify a group of network interfaces, and the address access module 702 is specifically used to find the nearest target network interface from a group of network interfaces based on a pre-learned anycast routing table, and determine the N3IWF connected to the target network interface as the target N3IWF.
[0134] In one embodiment, the address acquisition module 701 is specifically configured to receive an anycast address sent by the relay user equipment based on a PDU session, where the anycast address is sent by the remote user equipment to the relay user equipment based on the first communication connection.
[0135] For specific definitions of the remote user equipment access device, please refer to the definitions of the remote user equipment access method above and will not be repeated here. Each module in the above-mentioned remote user equipment access device can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.
[0136] In one embodiment, Figure 11 , provides a communication device, Figure 11 The terminal device 800 in the embodiment includes: at least one processor 801, a memory 802, at least one network interface 804, and a user interface 803. The various components in the terminal device 800 are coupled together via a bus system 805. It is understood that the bus system 805 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 805 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, the bus system 805 is not described in detail. Figure 1 Various buses are labeled as bus system 805. In addition, in the embodiment of the present application, a transceiver 806 is also included. The transceiver can be multiple components, that is, including a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium.
[0137] The user interface 803 may include a display, a keyboard, or a pointing device (eg, a mouse, a trackball, a touchpad, or a touch screen).
[0138] It is understood that the memory 802 in the embodiment of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DRRAM). The memory 802 of the systems and methods described in the embodiments of the present application is intended to include, but is not limited to, these and any other suitable types of memory.
[0139] In some embodiments, the memory 802 stores the following elements, executable modules or data structures, or a subset thereof, or an extended set thereof: an operating system 8021 and application programs 8022 .
[0140] The operating system 8021 includes various system programs, such as a framework layer, a core library layer, and a driver layer, for implementing various basic services and processing hardware-based tasks. The application program 8022 includes various application programs, such as a media player (MediaPlayer) and a browser (Browser), for implementing various application services. The program implementing the method of the embodiment of the present application can be included in the application program 8022.
[0141] In an embodiment of the present application, by calling the program or instructions stored in the memory 802, specifically, it can be the program or instructions stored in the application 8022, wherein the transceiver is used to access the pre-configured anycast address through a first communication connection established with the relay user equipment and a protocol data unit PDU session established by the relay user equipment, so that the network side determines the target N3IWF among multiple non-3GPP network interconnection functions N3IWF based on the anycast address; establish a second communication connection with the target N3IWF to access the core network through the second communication connection between the target N3IWF.
[0142] In one embodiment, Figure 12 , provides a communication device, which may be a network device. The network device may include a receiver 901, a memory 902, a processor 903, at least one communication bus 904 and a transmitter 905. The communication bus 904 is used to realize the communication connection between the components. The memory 902 may include a high-speed RAM memory, and may also include a non-volatile storage NVM, such as at least one disk storage. Various programs may be stored in the memory 902 to complete various processing functions and implement the method steps of this embodiment. In the embodiment of the present application, the transmitter 905 may be a radio frequency processing module or a baseband processing module in the network device, and the receiver 901 may also be a radio frequency processing module or a baseband processing module in the network device. The transmitter 905 and the receiver 901 may be integrated together to form a transceiver. The transmitter 905 and the receiver 901 may both be coupled to the processor 903, and they may perform receiving or transmitting actions under the instruction or control of the processor 903.
[0143] In an embodiment of the present application, the transceiver is used to address the anycast address pre-set in the remote user equipment based on the first communication connection established between the remote user equipment and the relay user equipment and the PDU session established by the relay user equipment; the processor is used to determine the target N3IWF among multiple N3IWFs based on the anycast address, and the target N3IWF is used to establish a second communication connection with the remote user equipment, so that the remote user equipment can access the core network through the second communication connection between the remote user equipment and the target N3IWF.
[0144] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned remote UE access method are implemented.
[0145] In one embodiment, a computer program product including instructions is further provided, which implements the steps in the above-mentioned remote UE access method when the computer program product is executed.
[0146] Those skilled in the art will appreciate that all or part of the processes in the above embodiments can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0147] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0148] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A remote user equipment access method, characterized in that: The method comprises: The remote user equipment accesses a pre-configured anycast address through a first communication connection established with the relay user equipment and a protocol data unit (PDU) session established by the relay user equipment, so that the network side determines a target N3IWF from among multiple non-3GPP network interconnection functions (N3IWFs) based on the anycast address; Establish a second communication connection with the target N3IWF to access the core network through the second communication connection between the target N3IWF.
2. The method according to claim 1, characterized in that The remote user equipment accesses a pre-configured anycast address through a first communication connection established with the relay user equipment and a PDU session established by the relay user equipment, so that the network side determines a target N3IWF from multiple N3IWFs based on the anycast address, including: A data packet is sent to the relay user equipment to the anycast address to instruct the relay user equipment to forward the data packet to the anycast address to the target user plane function UPF through the PDU session, so as to determine the target N3IWF corresponding to the anycast address through the data network DN, wherein the PDU session includes at least one of a local PDU session and a local offload session.
3. The method according to claim 1 or 2, characterized in that The method further comprises: Acquire authorization information and service configuration information of the near-domain service, where the service configuration information includes the anycast address.
4. The method according to claim 1, wherein The second communication connection includes an Internet Security Protocol (IPSec) tunnel, and establishing the second communication connection with the target N3IWF includes: The IPSec tunnel is established with the target N3IWF through an Internet Key Exchange (IKE) process.
5. The method according to claim 4, characterized in that The establishing of the IPSec tunnel with the target N3IWF through the IKE process includes: Perform an initial IKE exchange with the target N3IWF to establish a security association SA; Sending an IKE authentication message, where the IKE authentication message is used to request an IKE authentication exchange to the target N3IWF; receiving an IKE authentication response sent by the target N3IWF based on the IKE authentication message, and establishing an Extended Authentication Protocol EAP-5G session based on the IKE authentication response; Establishing an IPSec signaling SA with the target N3IWF and obtaining an internal address allocated by the target N3IWF to the remote user equipment; Receive the non-access layer NAS registration success message fed back by the target N3IWF, and initiate the process of establishing a non-3GPP access session.
6. The method according to claim 5, characterized in that The establishing of an Extended Authentication Protocol (EAP)-5G session based on the IKE authentication response includes: Send an IKE authentication request to start NAS registration, interact with the access and mobility management function AMF and the authentication service function AUSF to perform the authentication process, create a NAS security context and N3IWF key after successful authentication, and establish the EAP-5G session.
7. A remote user equipment access method, characterized in that: The method comprises: Addressing the anycast address preset in the remote user equipment based on the first communication connection established between the remote user equipment and the relay user equipment and the PDU session established by the relay user equipment; A target N3IWF is determined among multiple N3IWFs based on the anycast address, and the target N3IWF is used to establish a second communication connection with the remote user equipment, so that the remote user equipment accesses the core network through the second communication connection between the remote user equipment and the target N3IWF.
8. The method according to claim 7, characterized in that The anycast address is used to identify a group of network interfaces, and determining a target N3IWF among a plurality of N3IWFs based on the anycast address includes: The nearest target network interface is found from the group of network interfaces according to the pre-learned anycast routing table, and the N3IWF connected to the target network interface is determined as the target N3IWF.
9. The method according to claim 7, characterized in that The addressing of the anycast address preset in the remote user equipment based on the first communication connection established between the remote user equipment and the relay user equipment and the PDU session established by the relay user equipment includes: A data packet forwarded to the anycast address by the relay user equipment is received based on the PDU session, where the data packet is sent by the remote user equipment to the relay user equipment based on the first communication connection.
10. A remote user equipment access device, characterized in that: The device comprises: An address access module is configured to access a pre-configured anycast address through a first communication connection established with a relay user equipment and a protocol data unit (PDU) session established by the relay user equipment, so that the network side determines a target N3IWF from among multiple non-3GPP network interconnection functions (N3IWFs) based on the anycast address; The access module is used to establish a second communication connection with the target N3IWF to access the core network through the second communication connection between the target N3IWF and the core network.
11. A remote user equipment access device, characterized in that: The device comprises: An address acquisition module, configured to address an anycast address preset in the remote user equipment based on a first communication connection established between the remote user equipment and the relay user equipment and a PDU session established by the relay user equipment; An address access module is used to determine a target N3IWF among multiple N3IWFs based on the anycast address, and the target N3IWF is used to establish a second communication connection with the remote user equipment so that the remote user equipment accesses the core network through the second communication connection between the remote user equipment and the target N3IWF.
12. A communication device, characterized in that: include: transceiver; The transceiver is used to access a pre-configured anycast address through a first communication connection established with a relay user equipment and a PDU session established by the relay user equipment, so that the network side determines a target N3IWF among multiple N3IWFs based on the anycast address; and establish a second communication connection with the target N3IWF to access the core network through the second communication connection between the target N3IWF and the target N3IWF.
13. A communication device, characterized in that: include: transceivers and processors; The transceiver is configured to address the anycast address preset in the remote user equipment based on the first communication connection established between the remote user equipment and the relay user equipment and the PDU session established by the relay user equipment; The processor is configured to determine a target N3IWF among multiple N3IWFs based on the anycast address, and the target N3IWF is configured to establish a second communication connection with the remote user equipment, so that the remote user equipment accesses the core network through the second communication connection between the remote user equipment and the target N3IWF.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.
15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.
Citation Information
Patent Citations
Method and apparatus for supporting connectivity of remote user equipment with relay access via interworking function
CN114868454A
Communication method and communication device
CN114916018A