Communication configuration method, device, computer equipment and storage medium

By receiving the registration request and configuring encryption items in the IMS system of the home network, the problem of cumbersome multimedia data encryption and decryption process of roaming terminals is solved, and efficient multimedia data encryption and decryption and legal monitoring are achieved.

CN117041948BActive Publication Date: 2025-10-03CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310827333.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-06
Publication Date
2025-10-03
Estimated Expiration
2043-07-06

AI Technical Summary

Technical Problem

In roaming scenarios, the configuration process of multimedia data encryption and decryption in the IMS system of the roaming terminal by the visited network is cumbersome and inefficient.

Method used

By receiving the registration request of the roaming terminal in the IMS system of the home network, obtaining the subscription information, and configuring the encryption items according to the media plane configuration message, indicating whether to encrypt the multimedia data, including permission indication and the management of the latest configuration items, it avoids frequently obtaining subscription information from the user database.

Benefits of technology

Without changing the standard signaling negotiation architecture, the encryption and decryption process of multimedia data is greatly simplified, configuration efficiency is improved, and flexible encryption and decryption and legal monitoring of multimedia data of roaming terminals are realized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117041948B_ABST
    Figure CN117041948B_ABST
Patent Text Reader

Abstract

The present application discloses a communication configuration method, apparatus, computer equipment, and storage medium. The method can be applied to the field of terminal communication technology, and specifically may include: receiving a first registration request sent by a second network element in a roaming network where a roaming terminal is located, the first registration request carries a first media plane configuration message, executing a registration process for the roaming terminal according to the first registration request, and obtaining the contract information corresponding to the roaming terminal during the registration process, and configuring the encryption items in the contract information according to the first media plane configuration message. Based on the method of the present application, the roaming terminal can complete the configuration processing of the encryption items in the contract information while registering with the IMS system in the home network, so as to realize the encryption and decryption of the multimedia data corresponding to the roaming terminal. On the basis of not changing the standard signaling negotiation architecture, the encryption and decryption process of the multimedia data for the roaming terminal can be greatly simplified, thereby improving the configuration efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of terminal communication technology, and in particular to a communication configuration method, apparatus, computer equipment, and storage medium. Background Art

[0002] Currently, roaming services on the 5G core network are provided by the roaming user's home network. This means that the roaming user's data and voice services must be transferred back to the home network, where services are provided. In a roaming scenario, a roaming terminal registered with the visited network (i.e., roaming network) in the visited location registers with the multimedia system (IMS) of the home network through local routing.

[0003] If the visited network at the visited location needs to configure the encryption and decryption of multimedia data (mainly including data and voice) in the IMS system of the roaming terminal (for example, to decrypt multimedia data to achieve lawful interception), a relatively cumbersome negotiation process is required, which is inefficient. Summary of the Invention

[0004] Based on this, it is necessary to provide a communication configuration method, device, computer equipment and storage medium to address the above technical problems, which greatly simplifies the encryption and decryption configuration process of multimedia data.

[0005] In a first aspect, the present application provides a communication configuration method, which is applied to a first network element of an IMS system of a home network of a roaming terminal, the method comprising:

[0006] receiving a first registration request sent by a second network element in a roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0007] executing a registration process for the roaming terminal according to the first registration request, and obtaining contract information corresponding to the roaming terminal during the registration process;

[0008] The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0009] In one embodiment, the contract information further includes a permission indication item, and configuring and processing the encryption item in the contract information according to the first media plane configuration message includes:

[0010] Determine whether the configuration permission is granted according to the permission indicator;

[0011] In the case of having the configuration authority, the step of configuring the encryption item in the contract information according to the first media plane configuration message is executed.

[0012] In one embodiment, determining whether configuration permission is granted according to the permission indicator includes:

[0013] If the permission indication item indicates that the encryption item in the contract information can be configured by network elements of other networks, determining that the configuration permission exists;

[0014] When the permission indication item indicates that the encryption item in the contract information cannot be configured by network elements of other networks, it is determined that the configuration permission is not possessed.

[0015] In one embodiment, the contract information further includes a most recent configuration item, where the most recent configuration item is used to indicate at least one of a target network element for most recently configuring the contract information and a network to which the target network element belongs. The method further includes:

[0016] The latest configuration item is updated according to at least one of the roaming network and the second network element.

[0017] In one embodiment, the contract information further includes at least one of the following:

[0018] Encryption mode item, which is used to indicate the encryption mode of the roaming terminal;

[0019] The security protocol type item is used to indicate the transmission protocol type.

[0020] In one embodiment, obtaining subscription information corresponding to the roaming terminal according to the first registration request includes:

[0021] According to the first registration request, the subscription information is obtained from the user database HSS.

[0022] In one embodiment, obtaining subscription information from a user database HSS according to the first registration request includes:

[0023] If the monitoring clock is not set or has timed out, performing the step of obtaining subscription information from the HSS according to the first registration request;

[0024] The monitoring clock is started when a registration request for the roaming terminal sent by a network element of a non-home network is received or when a switching of a network element associated with the roaming terminal is detected.

[0025] In one embodiment, the method further comprises:

[0026] When the monitoring clock has not timed out, it is prohibited to obtain the subscription information from the HSS, and it is determined whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the subscription information of the roaming terminal stored in the local database.

[0027] In one embodiment, the method further comprises:

[0028] After the roaming terminal enters the coverage of the home network, receiving a second registration request sent by a third network element in the home network, where the second registration request carries a second media plane configuration message;

[0029] According to the second registration request, the contract information corresponding to the roaming terminal is obtained, and the encryption item in the contract information is configured and processed according to the second media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0030] In one embodiment, a response message is returned to the second network element, where the response message carries the registration request result and the configuration processing result;

[0031] The registration request result is used to indicate whether the roaming terminal has been successfully registered; the configuration processing result is used to indicate whether the encryption item in the subscription information of the roaming terminal has been successfully configured.

[0032] In a second aspect, the present application further provides a communication configuration device, which is applied to a first network element of an IMS system of a home network of a roaming terminal, comprising:

[0033] A first receiving module is configured to receive a first registration request sent by a second network element in a roaming network where a roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0034] An execution module, configured to execute a registration process for the roaming terminal according to the first registration request, and obtain contract information corresponding to the roaming terminal during the registration process;

[0035] The first configuration module is used to configure and process the encryption item in the contract information according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0036] In a third aspect, the present application further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0037] receiving a first registration request sent by a second network element in a roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0038] executing a registration process for the roaming terminal according to the first registration request, and obtaining contract information corresponding to the roaming terminal during the registration process;

[0039] The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0040] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following steps:

[0041] receiving a first registration request sent by a second network element in a roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0042] executing a registration process for the roaming terminal according to the first registration request, and obtaining contract information corresponding to the roaming terminal during the registration process;

[0043] The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0044] In a fifth aspect, the present application further provides a computer program product, the computer program product comprising a computer program, which, when executed by a processor, implements the following steps:

[0045] receiving a first registration request sent by a second network element in a roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0046] executing a registration process for the roaming terminal according to the first registration request, and obtaining contract information corresponding to the roaming terminal during the registration process;

[0047] The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0048] The above-mentioned communication configuration method, apparatus, computer equipment, and storage medium are applied to the first network element of the IMS system of the home network of the roaming terminal, and receive a first registration request sent by the second network element in the roaming network where the roaming terminal is located. The first registration request carries a first media plane configuration message. According to the first registration request, a registration process for the roaming terminal is executed, and during the registration process, the contract information corresponding to the roaming terminal is obtained. The encryption items in the contract information are configured and processed according to the first media plane configuration message. The configured encryption items are used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal. Based on the method of the present application, the roaming terminal can complete the configuration processing of the encryption items in the contract information while registering with the IMS system in the home network to implement encryption and decryption of the multimedia data corresponding to the roaming terminal. This can greatly simplify the encryption and decryption process of the multimedia data for the roaming terminal without changing the standard signaling negotiation architecture, thereby improving configuration efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 An application environment diagram of the first communication configuration method provided in this embodiment;

[0050] Figure 2 A schematic diagram of a flow chart of a first communication configuration method provided in this embodiment;

[0051] Figure 3 This is a diagram of an application environment for the second communication configuration method provided in this embodiment;

[0052] Figure 4 A schematic diagram of the process of configuring and processing encryption items in contract information provided in this embodiment;

[0053] Figure 5 This is a schematic diagram of the contract information provided in this embodiment;

[0054] Figure 6 A schematic diagram of a flow chart of a second communication configuration method provided in this embodiment;

[0055] Figure 7 A schematic diagram of a flow chart of a third communication configuration method provided in this embodiment;

[0056] Figure 8 A schematic diagram of a flow chart of a fourth communication configuration method provided in this embodiment;

[0057] Figure 9 This is a flowchart of the first registration of a roaming terminal provided in this embodiment;

[0058] Figure 10 A flowchart of the second registration of a roaming terminal provided in this embodiment;

[0059] Figure 11A structural block diagram of the first communication configuration device provided in this embodiment;

[0060] Figure 12 A structural block diagram of the second communication configuration device provided in this embodiment;

[0061] Figure 13 A structural block diagram of the third communication configuration device provided in this embodiment;

[0062] Figure 14 This is a diagram of the internal structure of the computer device provided in this embodiment. DETAILED DESCRIPTION

[0063] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0064] The communication configuration method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, communication services (i.e., multimedia data, mainly including data and voice) generated by a roaming terminal UE (User Equipment) in a roaming network (i.e., a visited network) 102 need to be provided by a home network 104. To configure encryption and decryption of multimedia data in the IMS (IP Multimedia Subsystem) system of the roaming terminal UE, the roaming network 102 configures encryption and decryption of the multimedia data. A first network element in the home network 104 receives a first registration request sent by a second network element in the roaming network 102 where the roaming terminal UE resides. The first registration request carries a first media plane configuration message. Based on the first registration request, the first network element in the home network 104 performs a registration process for the roaming terminal UE. During the registration process, the first network element obtains subscription information corresponding to the roaming terminal from the subscriber database HSS. The first network element in the subscription information is configured based on the first media plane configuration message. The configured encryption item indicates whether to encrypt multimedia data corresponding to the roaming terminal. For example, after the first network element configures and processes the encryption item in the contract information according to the first media plane configuration message, it turns off the encryption item of the multimedia data corresponding to the roaming terminal UE. At this time, the roaming terminal UE can be legally monitored through the network element associated with the roaming terminal UE in the roaming network 102.

[0065] In the embodiments of the present application, user terminals, user equipment, terminal devices, or terminals may be collectively referred to as UEs. That is, unless otherwise specified, the UEs described herein can be replaced with user terminals, user equipment, terminal devices, or terminals, and they are also interchangeable. The roaming terminal UE in this embodiment may be, but is not limited to, a terminal that supports VoLTE (Voice over Long-Term Evolution, a high-speed wireless communication standard for mobile phones and data terminals) and VoNR (Voice over NR, a target voice solution for 5G networks).

[0066] IMS, the IP Multimedia System, is a new form of multimedia service that meets end-user demands for newer and more diverse multimedia services. IMS is a core technology for next-generation networks and a key approach to facilitating the convergence of mobile and fixed networks, introducing differentiated services such as triple-play voice, data, and video.

[0067] The roaming network and home network belong to different public land mobile networks (PLMNs) and support roaming, namely the EPC core network or 5GC core network. The home network refers to the network of the roaming terminal's home location, while the roaming network refers to the network of the roaming terminal's current location. The EPC (Evolved Packet Core) core network refers to the core network of the 4G mobile communication network. It has traditional mobile network capabilities such as user subscription data storage, mobility management, and data exchange, and can provide users with an ultra-high-speed Internet experience. The 5GC core network refers to the 5G core network. The network elements of the 5G core network include: UPF network element, AUSF network element, UDM network element, AMF network element, SMF network element, PCF network element, NSSF network element, NRF network element, NEF network element, etc.

[0068] The first network element and the second network element refer to network elements with different functions. A network element can be simply understood as an element or device in a network. A network element is the smallest unit that can be monitored and managed in network management.

[0069] In one embodiment, Figure 2 This is a flow chart of a communication configuration method provided according to an embodiment of the present application, which is applied to the first network element of the IMS system of the home network of the roaming terminal, and is applied to Figure 1 Taking the first network element in FIG. 1 as an example, the method includes the following steps:

[0070] S201: Receive a first registration request sent by a second network element in a roaming network where a roaming terminal is located. The first registration request carries a first media plane configuration message.

[0071] Among them, the first registration request refers to a registration request submitted by the roaming terminal to the network element of the home network through the second network element under the condition that the roaming terminal has not yet registered in the home network; the first media plane configuration message refers to a message for configuring the media plane security of the IMS system of the roaming terminal, which is used to configure the encryption and decryption of the multimedia data corresponding to the roaming terminal.

[0072] An optional implementation of this embodiment is as follows: receiving a first registration request sent by a second network element in a roaming network where a roaming terminal is located, determining a flag in the first registration request, and obtaining a first media plane configuration message carried in the first registration request based on the flag. The flag may be a special character or a characteristic parameter. The first media plane configuration message and the flag are combined according to a preset rule, and the flag is subsequently parsed according to the preset rule to obtain the first media plane configuration message.

[0073] When the first network element is an S-CSCF network element in the home network and the second network element is a P-CSCF network element in the roaming network, such as Figure 3 As shown, another optional implementation of this embodiment is: the P-CSCF network element of the roaming network sends a first registration request to the I-CSCF network element of the home network. After determining the S-CSCF network element, the I-CSCF network element of the home network forwards the first registration request to the S-CSCF network element of the home network. The S-CSCF network element of the home network then receives the first registration request sent by the P-CSCF network element (i.e., the second network element) in the roaming network where the roaming terminal is located. The first registration request carries a first media plane configuration message, wherein the first media plane configuration message can be configured in the header field of the first registration request.

[0074] In this embodiment, the S-CSCF (Server CSCF) network element plays a core control role in the IMS system. It is responsible for terminal registration authentication and session control, performs basic session routing functions for calling and called IMS system users, and triggers value-added service routing and service control interaction to the AS based on the IMS system triggering rules signed by the user when conditions are met.

[0075] The I-CSCF (Interrogating CSCF) network element is located at the edge of the home network domain. Its main functions are to query the user database HSS to select an S-CSCF and forward SIP messages to the S-CSCF.

[0076] The P-CSCF (Proxy-CSCF) network element is the entry point of the IMS system in the roaming network. Session messages initiated and terminated by the terminal must pass through the P-CSCF network element.

[0077] (R)AN: (Radio) access network (R)AN) mainly controls UE's wireless access to the mobile communication network.

[0078] The user plane function (UPF) is a gateway for communication between a 3GPP network and a DN (Data Network), wherein the 3GPP network refers to a network that complies with the 3GPP standard.

[0079] A Data Network (DN), also known as a Packet Data Network (PDN), is a network located outside the 3GPP network. The 3GPP network can access multiple DNs, on which various services provided by operators or third parties can be deployed. For example, a DN is the private network of a smart factory. The sensors installed in the smart factory workshop act as UEs, and the DN contains a control server for the sensors. The UE communicates with the control server, and after receiving instructions from the control server, the UE can transmit the collected data to the control server according to these instructions. For another example, the DN is an internal office network of a company, and the terminals used by the company's employees can act as UEs, which can access information and other resources within the company.

[0080] Figure 3 N1, N2, N3, N4, N6, N9, etc. in the architecture represent reference points between related network entities / network functions.

[0081] S202: Execute a registration process for the roaming terminal according to the first registration request, and obtain contract information corresponding to the roaming terminal during the registration process.

[0082] Among them, the contract information refers to the user contract data. Compared with the contract information required for traditional roaming terminal registration, the contract information in this embodiment has at least added an encryption item, which is used to configure the encryption and decryption of multimedia data corresponding to the roaming terminal; the registration process refers to the authentication and certification process of the roaming terminal, which is used to ensure the security of the network.

[0083] Optionally, in this embodiment, based on the first registration request, the terminal identity of the roaming terminal is obtained, and based on the terminal identity, the authentication data is downloaded from the user database HSS, the registration process for the roaming terminal is executed, and the user contract data is downloaded after the registration is successful, and the contract information corresponding to the roaming terminal is obtained based on the user contract data.

[0084] S203: Configure and process the encryption item in the subscription information according to the first media plane configuration message. The configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0085] The encryption item refers to an item configured in the contract information that can be used to indicate whether to encrypt multimedia data corresponding to the roaming terminal. By configuring the encryption item, encryption and decryption configuration of the multimedia data can be achieved.

[0086] Optionally, in this embodiment, if the first media plane configuration message representation is used to turn off the encryption item in the contract data (for example, the first media plane configuration message is to turn off the media plane encryption item), the encryption item in the contract information is turned off, and the multimedia data corresponding to the roaming terminal is in an unencrypted state; if the first media plane configuration message representation is used to encrypt the encryption item in the contract data, the encryption item in the contract information is encrypted (for example, an encryption password is configured), and the multimedia data corresponding to the roaming terminal is in an encrypted state.

[0087] In the above-mentioned communication configuration method, a first registration request is received from a second network element in the roaming network where the roaming terminal is located. The first registration request carries a first media plane configuration message. Based on the first registration request, a registration process for the roaming terminal is executed, and during the registration process, the contract information corresponding to the roaming terminal is obtained. The encryption items in the contract information are configured and processed based on the first media plane configuration message. The configured encryption items are used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal. Based on the method of the present application, the roaming terminal can complete the configuration processing of the encryption items in the contract information while registering with the IMS system in the home network to implement encryption and decryption of the multimedia data corresponding to the roaming terminal. This can greatly simplify the encryption and decryption process of multimedia data for the roaming terminal without changing the standard signaling negotiation architecture, thereby improving configuration efficiency.

[0088] In one embodiment, the contract information also includes an authority indicator. On this basis, Figure 4 As shown, an optional implementation method of configuring the encryption item in the contract information according to the first media plane configuration message in step S203 includes:

[0089] S401: Determine whether the configuration permission is available according to the permission indicator.

[0090] The permission indicator item is used to indicate whether the user has the permission to configure the encryption item. In this embodiment, the permission indicator item includes whether the user can configure the encryption item by network elements of other networks or not.

[0091] Optionally, in this embodiment, when the permission indicator indicates that the encryption item in the contract information can be configured by the network element of other networks, it is determined that the configuration authority is possessed. That is, when the permission indicator indicates that the encryption item in the contract information can be configured by the network element of other networks, the network element of the roaming network has the configuration authority and can configure and process the encryption item in the contract information of the roaming terminal. For example, the permission indicator corresponding to the roaming terminal indicates "YES" or "Yes". In this case, the permission indicator indicates that the encryption item in the contract information can be configured by the network element of other networks, that is, the network element of the roaming network has the configuration authority and can configure and process the encryption item in the contract information of the roaming terminal.

[0092] In the case where the permission indicator indicates that the encryption item in the contract information cannot be configured by the network elements of other networks, it is determined that the configuration permission is not possessed. That is to say, in the case where the permission indicator indicates that the encryption item in the contract information cannot be configured by the network elements of other networks, the network elements of the roaming network do not have the configuration permission and cannot configure and process the encryption item in the contract information of the roaming terminal. For example, the permission indicator corresponding to the roaming terminal indicates "NO" or "No". In this case, the permission indicator indicates that the encryption item in the contract information cannot be configured by the network elements of other networks, that is, the network elements of the roaming network do not have the configuration permission and cannot configure and process the encryption item in the contract information of the roaming terminal.

[0093] S402: If the user has the configuration permission, execute the step of configuring the encryption item in the contract information according to the first media plane configuration message.

[0094] In this embodiment, a permission indicator item is added to the contract information, and whether the configuration permission is possessed can be determined based on the permission indicator item. If the configuration permission is possessed, the steps of configuring and processing the encryption items in the contract information according to the first media surface configuration message are executed, thereby realizing flexible management and control of the encryption items and avoiding malicious or arbitrary tampering of the encryption items.

[0095] In one embodiment, as shown in Table 1, the contract information further includes a most recent configuration item, which is used to indicate the target network element (ie, Figure 1 At least one of the most recently set network element domain name in Table 1) and the network to which the target network element belongs (i.e., the most recently set PLMN ID in Table 1). The target network element refers to the network element that has recently configured the encryption item of the subscription information.

[0096] Table 1

[0097]

[0098] Optionally, in this embodiment, the most recent configuration item may be updated based on at least one of the roaming network and the second network element. One optional implementation is: based on the field for updating the most recent configuration item that the roaming network may add to the first media plane configuration message in the first registration request, after the encryption item configuration is completed, the most recent configuration item is updated. If the most recent configuration item is the target network element, the target network element is updated to the second network element. If the most recent configuration item is the network to which the target network element belongs, the network to which the target network element belongs is updated to the roaming network. Another optional implementation is: after the first network element completes the configuration of the encryption item, the most recent configuration item is automatically updated. If the most recent configuration item is the target network element, the target network element is updated to the second network element. If the most recent configuration item is the network to which the target network element belongs, the network to which the target network element belongs is updated to the roaming network.

[0099] In this embodiment, the target network element and / or the network to which the target network element belongs that last configured the subscription information can be known based on the latest configuration item in the subscription information, and the latest configuration item can be updated based on the roaming network or the second network element.

[0100] In one embodiment, as shown in Table 1, the subscription information further includes at least one of an encryption method and a security protocol type. The encryption method indicates the encryption method of the roaming terminal. The security protocol type indicates the transmission protocol type.

[0101] In this embodiment, the encryption mode item includes at least end-to-end encryption (e.g., e2e in Table 1), end-to-edge encryption (e.g., null in Table 1), and encryption disabled. The encryption mode can be configured if "Configurable by other networks" is set to "YES." The transport protocol refers to a media plane security protocol and can be abbreviated, such as the SRTP and TLS transport protocols in Table 1.

[0102] The subscription information in this embodiment may include an encryption method item and a security protocol type item. Based on the encryption method item and the security protocol type item, the current encryption method and transmission protocol of the roaming terminal can be clearly understood.

[0103] It should be noted that general contract information also includes other contract matters of the user, such as Figure 5 As shown, for example, including lock settings, registration settings, roaming settings, etc., in order to facilitate the classified management of contract information, a terminal media plane encryption setting can be added to the contract information, and the permission indication item, recent configuration item, encryption method item and transmission protocol type item can be configured in the terminal media plane encryption setting option in the form of a table.

[0104] In one embodiment, to facilitate obtaining the contract information, obtaining the contract information corresponding to the roaming terminal according to the first registration request includes:

[0105] Optionally, in this embodiment, subscription information may be obtained from the user database HSS based on the first registration request. Specifically, when the monitoring clock is not set or the monitoring clock has timed out, when the first network element (e.g., the S-CSCF network element) receives the first registration request, the subscription data corresponding to the identity identifier of the roaming terminal corresponding to the first registration request is obtained from the user database.

[0106] The monitoring clock is a clock set in the home network that monitors the time difference between two consecutive registration requests received by a roaming terminal. The monitoring clock is activated when a registration request for a roaming terminal is received from a network element in a non-home network or when a handover of the associated network element of the roaming terminal is detected. The associated network element mainly refers to the AMF network element.

[0107] AMF (Access and Mobility Management Function) is a control plane function in the 3GPP network, which is mainly responsible for access control and mobility management of UE accessing the operator network.

[0108] In this embodiment, the subscription information of the roaming terminal can be quickly obtained from the user database HSS according to the first registration request.

[0109] Based on the above embodiment, in order to save network resources of the home network and improve communication configuration efficiency, an optional implementation method for obtaining the subscription information is as follows:

[0110] Optionally, in this embodiment, if the monitoring clock has not timed out, obtaining the subscription information from the HSS is prohibited, and whether to encrypt the multimedia data of the roaming terminal is determined based on the encryption item of the subscription information of the roaming terminal stored in the local database. Specifically, if the monitoring clock has not timed out, when determining the first network element, the first network element that processed the previous registration request is still selected. Because the first network element has already obtained the subscription information of the roaming terminal from the HSS when processing the previous registration request, it does not need to obtain the information from the HSS again when processing the current registration request. Instead, it only needs to obtain the subscription information of the roaming terminal from the local database, and determines whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the subscription information of the roaming terminal stored in the local database.

[0111] The monitoring clock not timing out means that the time difference between two consecutive registration requests of the same roaming terminal detected by the monitoring clock is less than the time difference threshold.

[0112] In this embodiment, a monitoring clock for monitoring registration requests of roaming terminals is added. When the monitoring clock has not timed out, it is prohibited to obtain contract information from the HSS, and whether the multimedia data of the roaming terminal is encrypted is determined based on the encryption item of the contract information of the roaming terminal stored in the local database. This saves network resources of the home network and effectively avoids the "ping-pong effect" caused by frequent updates of the roaming terminal at the edge of the home network and the roaming network. When the monitoring clock has not timed out, there is no need to frequently obtain contract information from the HSS, thereby reducing the waste of network resources.

[0113] In one embodiment, after the roaming terminal enters the coverage of the home network, in order to configure the encryption item in the subscription information of the roaming terminal, such as Figure 6 As shown, an optional implementation of a communication configuration method includes:

[0114] S601: After a roaming terminal enters coverage of a home network, it receives a second registration request sent by a third network element in the home network. The second registration request carries a second media plane configuration message.

[0115] The third network element is a network element in the home network used to send the second registration request, typically a P-CSCF network element in the home network. The second registration request is a request instruction sent by a roaming terminal to the home network after returning to the home network for IMS system registration, wherein the second registration request carries the second media plane configuration message.

[0116] An optional implementation of this embodiment is: after the roaming terminal enters the coverage of the home network, a second registration request sent by a third network element of the home network is received, an identification bit is determined in the second registration request, and based on the identification bit, a second media plane configuration message carried in the first registration request can be obtained from the first registration request, where the identification bit can be a special character or a characteristic parameter, the second media plane configuration message and the flag bit are combined according to a preset rule, and the flag bit can be subsequently parsed according to the preset rule to obtain the second media plane configuration message.

[0117] When the first network element is an S-CSCF network element in the home network, and the third network element is a P-CSCF network element in the home network, another optional implementation of this embodiment is as follows: the P-CSCF network element in the home network sends a second registration request to the I-CSCF network element in the home network. After determining the S-CSCF network element in the home network, the I-CSCF network element in the home network forwards the second registration request to the S-CSCF network element in the home network. The S-CSCF network element in the home network then receives the second registration request sent by the P-CSCF network element (i.e., the second network element) in the roaming network where the roaming terminal is located. The second registration request carries a second media plane configuration message.

[0118] S602, according to the second registration request, obtain the contract information corresponding to the roaming terminal, and configure the encryption item in the contract information according to the second media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0119] It should be noted that, according to the second registration request, the contract information corresponding to the roaming terminal is obtained, and the encryption item in the contract information is configured and processed according to the second media plane configuration message, and the configured encryption item is used to indicate whether the multimedia data corresponding to the roaming terminal is encrypted. The method can refer to the above embodiment in which, according to the first registration request, the contract information corresponding to the roaming terminal is obtained, and the encryption item in the contract information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether the multimedia data corresponding to the roaming terminal is encrypted. The scheme will not be repeated here.

[0120] In this embodiment, after the roaming terminal enters the coverage of the home network, a second registration request is received from a third network element in the home network. The second registration request carries a second media plane configuration message. Based on the second registration request, the user obtains the subscription information corresponding to the roaming terminal, and configures the encryption items in the subscription information based on the second media plane configuration message. This enables encryption and decryption configuration of multimedia data corresponding to the roaming terminal after the roaming terminal enters the coverage of the home network.

[0121] In one embodiment, in order to feed back the registration request result and the configuration processing result to the roaming terminal and the second network element, such as Figure 7 As shown, an optional implementation of a communication configuration method includes:

[0122] S701: Receive a first registration request sent by a second network element in a roaming network where a roaming terminal is located. The first registration request carries a media plane configuration message.

[0123] S702: Execute a registration process for the roaming terminal according to the first registration request, and obtain contract information corresponding to the roaming terminal during the registration process.

[0124] S703: Configure the encryption item in the subscription information according to the media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0125] S704: Return a response message to the second network element. The response message carries the registration request result and the configuration processing result.

[0126] The registration request result is used to indicate whether the roaming terminal has been successfully registered; the configuration processing result is used to indicate whether the encryption item in the contract information of the roaming terminal has been successfully configured.

[0127] Optionally, in this embodiment, if the second network element is a P-CSCF network element in the roaming network and the first network element is an S-CSCF network element in the home network, after completing registration of the roaming terminal and configuring encryption items, the S-CSCF network element in the home network sends a response message to the I-CSCF network element in the home network. The I-CSCF network element in the home network forwards the response message to the P-CSCF network element in the roaming network. The response message carries the registration request result and configuration processing result.

[0128] In one embodiment, Figure 8 As shown, an optional implementation of a communication configuration method includes:

[0129] S801: Receive a first registration request sent by a second network element in a roaming network where a roaming terminal is located. The first registration request carries a first media plane configuration message.

[0130] S802: Determine whether the monitoring clock has timed out based on the first registration request. If so, execute S803; if not, execute S804.

[0131] S803: Obtain the subscription information from the user database HSS.

[0132] Among them, the contract information includes an authority indication item, a recent configuration item, an encryption method item, and a security protocol type item. When the authority indication item indicates that the encryption item in the contract information can be configured by network elements of other networks, it is determined that the configuration authority is possessed. When the authority indication item indicates that the encryption item in the contract information cannot be configured by network elements of other networks, it is determined that the configuration authority is not possessed. The recent configuration item is used to indicate at least one of the target network element for the most recent configuration of the contract information and the network to which the target network element belongs. The encryption method item is used to indicate the encryption method of the roaming terminal. The security protocol type item is used to indicate the transmission protocol type.

[0133] S804: Prohibit obtaining the subscription information from the HSS, and determine whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the subscription information of the roaming terminal stored in the local database.

[0134] S805: Determine whether the configuration permission is available based on the permission indicator.

[0135] S806: If the configuration authority is granted, the encryption item in the contract information is configured according to the first media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0136] S807: Update the latest configuration item according to at least one of the roaming network and the second network element.

[0137] S808: Return a response message to the second network element, carrying a registration request result and a configuration processing result. The registration request result indicates whether the roaming terminal has been successfully registered; the configuration processing result indicates whether the encryption item in the subscription information of the roaming terminal has been successfully configured.

[0138] This embodiment is applied to a first network element of an IMS system in a home network of a roaming terminal. By receiving a first registration request sent by a second network element in the roaming network where the roaming terminal resides, the first registration request carries a first media plane configuration message. Based on the first registration request, a registration process for the roaming terminal is executed. During the registration process, subscription information corresponding to the roaming terminal is obtained. The encryption items in the subscription information are configured based on the first media plane configuration message. The configured encryption items are used to indicate whether multimedia data corresponding to the roaming terminal is encrypted. Based on the method of this application, the roaming terminal can simultaneously configure the encryption items in the subscription information while registering with the IMS system in the home network to implement encryption and decryption of the multimedia data corresponding to the roaming terminal. This significantly simplifies the encryption and decryption process for multimedia data of the roaming terminal without changing the standard signaling negotiation architecture, thereby improving configuration efficiency. By configuring the encryption and decryption of the multimedia data of the roaming terminal, legal interception of the data and voice of the roaming terminal can be flexibly configured.

[0139] In order to better understand the above embodiment, a detailed explanation is given below in conjunction with a specific embodiment. Figure 9 and 10 As shown, when a roaming terminal UE registers with the IMS system in the home network, it needs to go through two registration processes. Figure 9 The first registration process is as follows: the roaming terminal UE sends an initial registration request Register to the P-CSCF network element of the roaming network. The P-CSCF network element of the roaming network adds the first media plane configuration message in the header field of the initial registration request to form the first registration request Register, and sends the first registration request to the I-CSCF network element of the home network (when the I-CSCF network element of the home network receives the first registration request, the monitoring clock of the roaming terminal starts). The I-CSCF network element of the home network selects a suitable first S-CSCF network element according to the capabilities of each S-CSCF network element received from the HSS, and sends the first registration request to the selected first S-CSCF network element. The first S-CSCF network element obtains user authentication data and user subscription data from the HSS, authenticates the roaming terminal, and creates a 401Unauthorized response. The 401Unauthorized response is returned to the roaming terminal UE along the original path, and the roaming terminal UE verifies the 401Unauthorized response. If the verification is valid, initiate the second registration process, such as Figure 10 As shown, the roaming terminal UE sends an initial registration request Register to the P-CSCF network element of the roaming network. The P-CSCF network element of the roaming network adds the first media plane configuration message in the header field of the initial registration request to form a first registration request Register, and sends the first registration request to the I-CSCF network element of the home network. The I-CSCF network element of the home network determines whether the monitoring clock has timed out. If not, the S-CSCF network element is not reselected and the first registration request is sent to the first S-CSCF network element. The first S-CSCF network element does not need to obtain user authentication data and The user subscription data can use the user authentication data and user subscription data downloaded and stored in the local database last time. The first S-CSCF network element executes the registration process for the roaming terminal according to the first registration request, and obtains the subscription information corresponding to the roaming terminal during the registration process (which can be obtained from the user subscription data). The encryption item in the subscription information is configured according to the first media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal. After the first S-CSCF network element completes the registration and the encryption item configuration, it returns a response message (i.e., Figure 10 The response message carries the registration request result and the configuration processing result. The I-CSCF network element in the home network returns the response message to the P-CSCF network element in the roaming network. The P-CSCF network element in the roaming network extracts the configuration processing result (e.g., configuration success or configuration failure) from the 200OK message and returns a 200OK message without the configuration processing result to the roaming terminal UE.

[0140] It should be noted that the first registration process is an authentication process and does not require configuration of registration and encryption items.

[0141] It should also be noted that during the execution of the second registration process, if the I-CSCF network element of the home network determines that the monitoring clock has timed out, it selects a suitable second S-CSCF network element based on the capabilities of each S-CSCF network element received from the HSS, and sends the first registration request to the selected second S-CSCF network element. The second S-CSCF network element re-obtains user authentication data and user subscription data from the HSS, and executes subsequent registration and encryption item configuration processes.

[0142] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0143] Based on the same inventive concept, embodiments of the present application further provide a communication configuration device for implementing the aforementioned communication configuration method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations in the one or more communication configuration device embodiments provided below can be found in the above-mentioned limitations on the communication configuration method and will not be further elaborated here.

[0144] In one embodiment, by Figure 11 FIG. 1 shows a structural block diagram of a communication configuration device in one embodiment. Figure 11 As shown, a communication configuration device 1 is provided, which is applied to a first network element of an IMS system of a home network of a roaming terminal. The device includes: a first receiving module 10, an execution module 20 and a first configuration module 30, wherein:

[0145] A first receiving module 10 is configured to receive a first registration request sent by a second network element in a roaming network where a roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0146] An execution module 20 is configured to execute a registration process for the roaming terminal according to the first registration request, and obtain contract information corresponding to the roaming terminal during the registration process;

[0147] The first configuration module 30 is used to configure the encryption item in the subscription information according to the first media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0148] The communication configuration device receives a first registration request sent by a second network element in a roaming network where a roaming terminal resides, the first registration request carrying a first media plane configuration message. Based on the first registration request, the device executes a registration process for the roaming terminal, obtains contract information corresponding to the roaming terminal during the registration process, and configures encryption items in the contract information based on the first media plane configuration message. The configured encryption items are used to indicate whether to encrypt multimedia data corresponding to the roaming terminal. Based on the method of the present application, the roaming terminal can complete the configuration of the encryption items in the contract information while registering with the IMS system in the home network to implement encryption and decryption of multimedia data corresponding to the roaming terminal. This significantly simplifies the encryption and decryption process for multimedia data of the roaming terminal without changing the standard signaling negotiation architecture, thereby improving configuration efficiency.

[0149] In one embodiment, the Figure 11 The contract information in the execution module 20 also includes permission execution items. On this basis, Figure 12 As shown, the execution module 20 further includes:

[0150] The permission judging unit 201 is configured to determine whether the user has the configuration permission according to the permission indicator.

[0151] The execution unit 202, when having the configuration authority, executes the step of configuring the encryption item in the contract information according to the first media plane configuration message.

[0152] In one embodiment, the Figure 12 The authority judgment unit in the contract is specifically used to: determine that it has configuration authority when the authority indication item indicates that the encryption item in the contract information can be configured by network elements of other networks; determine that it does not have configuration authority when the authority indication item indicates that the encryption item in the contract information cannot be configured by network elements of other networks.

[0153] In one embodiment, the Figure 11 The contract information in the execution module 20 also includes a recent configuration item, which is used to indicate the target network element for the most recent configuration of the contract information and at least one of the networks to which the target network element belongs. On this basis, the execution module 20 is also specifically used to update the recent configuration item according to at least one of the roaming network and the second network element.

[0154] In one embodiment, the Figure 11 The contract information in the execution module 20 also includes at least one of the following: an encryption method item, which is used to indicate the encryption method of the roaming terminal; and a security protocol type item, which is used to indicate the transmission protocol type.

[0155] In one embodiment, in one embodiment, the Figure 11 The execution module 20 further includes:

[0156] The acquiring unit is configured to acquire the subscription information from the user database HSS according to the first registration request.

[0157] In one embodiment, the acquiring unit is specifically configured to: when a monitoring clock is not set or has timed out, execute the step of acquiring the subscription information from the HSS according to the first registration request. The monitoring clock is initiated upon receiving a registration request for a roaming terminal sent by a network element of a non-home network or upon detecting a handover of an associated network element of the roaming terminal.

[0158] In one of the embodiments, the acquisition unit is further specifically used to: prohibit obtaining the contract information from the HSS when the monitoring clock has not timed out, and determine whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the contract information of the roaming terminal stored in the local database.

[0159] In one embodiment, Figure 11 As shown, a communication configuration device further includes:

[0160] The second receiving module is configured to receive a second registration request sent by a third network element in the home network after the roaming terminal enters the coverage of the home network, where the second registration request carries the second media plane configuration message.

[0161] In one embodiment, Figure 11 On the basis of Figure 13 As shown, a communication configuration device further includes:

[0162] The return module 40 is configured to return a response message to the second network element, the response message carrying the registration request result and the configuration processing result. The registration request result indicates whether the roaming terminal has been successfully registered; the configuration processing result indicates whether the encryption item in the roaming terminal's subscription information has been successfully configured.

[0163] Each module in the above-mentioned communication configuration device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0164] In one embodiment, a computer device is provided. The computer device may be a platform side, and its internal structure diagram may be as follows: Figure 14As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store communication configuration data. The network interface of the computer device is used to communicate with an external user side via a network connection. When the computer program is executed by the processor, a communication configuration method is implemented.

[0165] Those skilled in the art will understand that Figure 14 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. Specifically, the computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0166] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:

[0167] receiving a first registration request sent by a second network element in a roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0168] executing a registration process for the roaming terminal according to the first registration request, and obtaining contract information corresponding to the roaming terminal during the registration process;

[0169] The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0170] In one embodiment, when the processor executes the computer program, the following steps are further implemented: the contract information further includes a permission indication item, and the encryption item in the contract information is configured and processed according to the first media plane configuration message, including:

[0171] Determine whether the configuration permission is granted according to the permission indicator;

[0172] In the case of having the configuration authority, the step of configuring the encryption item in the contract information according to the first media plane configuration message is executed.

[0173] In one embodiment, when executing the computer program, the processor further implements the following steps: determining whether the configuration permission exists according to the permission indicator, including:

[0174] If the permission indication item indicates that the encryption item in the contract information can be configured by network elements of other networks, determining that the configuration permission exists;

[0175] When the permission indication item indicates that the encryption item in the contract information cannot be configured by network elements of other networks, it is determined that the configuration permission is not possessed.

[0176] In one embodiment, when the processor executes the computer program, the following steps are further implemented: the contract information further includes a recent configuration item, the recent configuration item is used to indicate at least one of a target network element for most recently configuring the contract information and a network to which the target network element belongs; and the method further includes:

[0177] The latest configuration item is updated according to at least one of the roaming network and the second network element.

[0178] In one embodiment, when the processor executes the computer program, the following steps are further implemented: the contract information further includes at least one of the following:

[0179] Encryption mode item, which is used to indicate the encryption mode of the roaming terminal;

[0180] The security protocol type item is used to indicate the transmission protocol type.

[0181] In one embodiment, when the processor executes the computer program, the processor further implements the following steps: obtaining subscription information corresponding to the roaming terminal according to the first registration request, including:

[0182] According to the first registration request, the subscription information is obtained from the user database HSS.

[0183] In one embodiment, when the processor executes the computer program, the processor further implements the following steps: obtaining subscription information from the user database HSS according to the first registration request, including:

[0184] If the monitoring clock is not set or has timed out, performing the step of obtaining subscription information from the HSS according to the first registration request;

[0185] The monitoring clock is started when a registration request for the roaming terminal sent by a network element of a non-home network is received or when a switching of a network element associated with the roaming terminal is detected.

[0186] In one embodiment, when the processor executes the computer program, the method further implements the following steps:

[0187] When the monitoring clock has not timed out, it is prohibited to obtain the subscription information from the HSS, and it is determined whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the subscription information of the roaming terminal stored in the local database.

[0188] In one embodiment, when the processor executes the computer program, the method further implements the following steps:

[0189] After the roaming terminal enters the coverage of the home network, receiving a second registration request sent by a third network element in the home network, where the second registration request carries a second media plane configuration message;

[0190] According to the second registration request, the contract information corresponding to the roaming terminal is obtained, and the encryption item in the contract information is configured and processed according to the second media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0191] In one embodiment, when the processor executes the computer program, it further implements the following steps: returning a response message to the second network element, where the response message carries the registration request result and the configuration processing result;

[0192] The registration request result is used to indicate whether the roaming terminal has been successfully registered; the configuration processing result is used to indicate whether the encryption item in the subscription information of the roaming terminal has been successfully configured.

[0193] The principles and specific processes of implementing the computer device provided above in each embodiment can be found in the description of the communication configuration method embodiment in the aforementioned embodiment, and will not be repeated here.

[0194] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are performed:

[0195] receiving a first registration request sent by a second network element in a roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0196] executing a registration process for the roaming terminal according to the first registration request, and obtaining contract information corresponding to the roaming terminal during the registration process;

[0197] The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0198] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the contract information further includes a permission indication item, and the encryption item in the contract information is configured and processed according to the first media plane configuration message, including:

[0199] Determine whether the configuration permission is granted according to the permission indicator;

[0200] In the case of having the configuration authority, the step of configuring the encryption item in the contract information according to the first media plane configuration message is executed.

[0201] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determining whether the configuration permission is granted according to the permission indicator, including:

[0202] If the permission indication item indicates that the encryption item in the contract information can be configured by network elements of other networks, determining that the configuration permission exists;

[0203] When the permission indication item indicates that the encryption item in the contract information cannot be configured by network elements of other networks, it is determined that the configuration permission is not possessed.

[0204] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the contract information further includes a recent configuration item, the recent configuration item is used to indicate at least one of a target network element for most recently configuring the contract information and a network to which the target network element belongs; the method further includes:

[0205] The latest configuration item is updated according to at least one of the roaming network and the second network element.

[0206] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: the contract information further includes at least one of the following:

[0207] Encryption mode item, which is used to indicate the encryption mode of the roaming terminal;

[0208] The security protocol type item is used to indicate the transmission protocol type.

[0209] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: obtaining subscription information corresponding to the roaming terminal according to the first registration request, including:

[0210] According to the first registration request, the subscription information is obtained from the user database HSS.

[0211] In one embodiment, obtaining subscription information from a user database HSS according to the first registration request includes:

[0212] If the monitoring clock is not set or has timed out, performing the step of obtaining subscription information from the HSS according to the first registration request;

[0213] The monitoring clock is started when a registration request for the roaming terminal sent by a network element of a non-home network is received or when a switching of a network element associated with the roaming terminal is detected.

[0214] In one embodiment, when the computer program is executed by a processor, the method further implements the following steps:

[0215] When the monitoring clock has not timed out, it is prohibited to obtain the subscription information from the HSS, and it is determined whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the subscription information of the roaming terminal stored in the local database.

[0216] In one embodiment, when the computer program is executed by a processor, the method further implements the following steps:

[0217] After the roaming terminal enters the coverage of the home network, receiving a second registration request sent by a third network element in the home network, where the second registration request carries a second media plane configuration message;

[0218] According to the second registration request, the contract information corresponding to the roaming terminal is obtained, and the encryption item in the contract information is configured and processed according to the second media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0219] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: returning a response message to the second network element, the response message carrying the registration request result and the configuration processing result;

[0220] The registration request result is used to indicate whether the roaming terminal has been successfully registered; the configuration processing result is used to indicate whether the encryption item in the subscription information of the roaming terminal has been successfully configured.

[0221] The principles and specific processes of the computer-readable storage medium provided above in implementing each embodiment can be found in the description of the target detection method embodiment in the aforementioned embodiment, and will not be repeated here.

[0222] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:

[0223] receiving a first registration request sent by a second network element in a roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message;

[0224] executing a registration process for the roaming terminal according to the first registration request, and obtaining contract information corresponding to the roaming terminal during the registration process;

[0225] The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt multimedia data corresponding to the roaming terminal.

[0226] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the contract information further includes a permission indication item, and the encryption item in the contract information is configured and processed according to the first media plane configuration message, including:

[0227] Determine whether the configuration permission is granted according to the permission indicator;

[0228] In the case of having the configuration authority, the step of configuring the encryption item in the contract information according to the first media plane configuration message is executed.

[0229] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determining whether the configuration permission is granted according to the permission indicator, including:

[0230] If the permission indication item indicates that the encryption item in the contract information can be configured by network elements of other networks, determining that the configuration permission exists;

[0231] When the permission indication item indicates that the encryption item in the contract information cannot be configured by network elements of other networks, it is determined that the configuration permission is not possessed.

[0232] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: the contract information further includes a recent configuration item, the recent configuration item is used to indicate at least one of a target network element for most recently configuring the contract information and a network to which the target network element belongs; the method further includes:

[0233] The latest configuration item is updated according to at least one of the roaming network and the second network element.

[0234] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: the contract information further includes at least one of the following:

[0235] Encryption mode item, which is used to indicate the encryption mode of the roaming terminal;

[0236] The security protocol type item is used to indicate the transmission protocol type.

[0237] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: obtaining subscription information corresponding to the roaming terminal according to the first registration request, including:

[0238] According to the first registration request, the subscription information is obtained from the user database HSS.

[0239] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: obtaining subscription information from the user database HSS according to the first registration request, including:

[0240] If the monitoring clock is not set or has timed out, performing the step of obtaining subscription information from the HSS according to the first registration request;

[0241] The monitoring clock is started when a registration request for the roaming terminal sent by a network element of a non-home network is received or when a switching of a network element associated with the roaming terminal is detected.

[0242] In one embodiment, when the computer program is executed by a processor, the method further implements the following steps:

[0243] When the monitoring clock has not timed out, it is prohibited to obtain the subscription information from the HSS, and it is determined whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the subscription information of the roaming terminal stored in the local database.

[0244] In one embodiment, when the computer program is executed by a processor, the method further implements the following steps:

[0245] After the roaming terminal enters the coverage of the home network, receiving a second registration request sent by a third network element in the home network, where the second registration request carries a second media plane configuration message;

[0246] According to the second registration request, the contract information corresponding to the roaming terminal is obtained, and the encryption item in the contract information is configured and processed according to the second media plane configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

[0247] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: returning a response message to the second network element, the response message carrying the registration request result and the configuration processing result;

[0248] The registration request result is used to indicate whether the roaming terminal has been successfully registered; the configuration processing result is used to indicate whether the encryption item in the subscription information of the roaming terminal has been successfully configured.

[0249] The principles and specific processes of the computer program products provided above in implementing each embodiment can be found in the description of the target detection method embodiment in the aforementioned embodiment, and will not be repeated here.

[0250] It should be noted that the data involved in this application (including but not limited to data in the communication configuration process, etc.) are all data that have been fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0251] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0252] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0253] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A communication configuration method, characterized in that: Applied in a first network element of an IMS system of a home network of a roaming terminal, the method includes: receiving a first registration request sent by a second network element in the roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message; executing a registration process for the roaming terminal according to the first registration request, and obtaining subscription information corresponding to the roaming terminal during the registration process; The encryption item in the subscription information is configured and processed according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

2. The method according to claim 1, characterized in that The contract information further includes a permission indication item, and the configuring and processing the encryption item in the contract information according to the first media plane configuration message includes: Determining whether the configuration permission is granted according to the permission indicator; In the case of having the configuration authority, the step of configuring the encryption item in the contract information according to the first media plane configuration message is performed.

3. The method according to claim 2, characterized in that The determining whether the configuration permission is granted according to the permission indicator includes: If the permission indication item indicates that the encryption item in the contract information can be configured by network elements of other networks, determining that the user has the configuration permission; When the permission indication item indicates that the encryption item in the contract information cannot be configured by network elements of other networks, it is determined that the configuration permission is not possessed.

4. The method according to claim 1, wherein The contract information further includes a most recent configuration item, where the most recent configuration item is used to indicate at least one of a target network element for most recently configuring the contract information and a network to which the target network element belongs. The method further includes: The latest configuration item is updated according to at least one of the roaming network and the second network element.

5. The method according to any one of claims 1 to 4, characterized in that: The contract information also includes at least one of the following: An encryption mode item, where the encryption mode item is used to indicate the encryption mode of the roaming terminal; A security protocol type item, where the security protocol type item is used to indicate the transmission protocol type.

6. The method according to any one of claims 1 to 4, characterized in that: The acquiring, according to the first registration request, subscription information corresponding to the roaming terminal includes: According to the first registration request, the subscription information is obtained from the user database HSS.

7. The method according to claim 6, characterized in that The acquiring the subscription information from a user database HSS according to the first registration request includes: When the monitoring clock is not set or the monitoring clock has timed out, performing the step of obtaining the subscription information from the HSS according to the first registration request; The monitoring clock is started when a registration request for the roaming terminal sent by a network element of a non-home network is received or when a switching of a network element associated with the roaming terminal is detected.

8. The method according to claim 7, characterized in that The method further comprises: When the monitoring clock has not timed out, obtaining the subscription information from the HSS is prohibited, and determining whether to encrypt the multimedia data of the roaming terminal based on the encryption item of the subscription information of the roaming terminal stored in the local database.

9. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: After the roaming terminal enters the coverage of the home network, receiving a second registration request sent by a third network element in the home network, where the second registration request carries a second media plane configuration message; According to the second registration request, the contract information corresponding to the roaming terminal is obtained, and the encryption item in the contract information is configured and processed according to the second media interface configuration message. The configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

10. The method according to claim 1, characterized in that The method further includes: returning a response message to the second network element, wherein the response message carries a registration request result and a configuration processing result; The registration request result is used to indicate whether the roaming terminal has been successfully registered; and the configuration processing result is used to indicate whether the encryption item in the contract information of the roaming terminal has been successfully configured.

11. A communication configuration device, characterized in that: A first network element of an IMS system of a home network of a roaming terminal includes: A first receiving module is configured to receive a first registration request sent by a second network element in the roaming network where the roaming terminal is located, where the first registration request carries a first media plane configuration message; an execution module, configured to execute a registration process for the roaming terminal according to the first registration request, and obtain subscription information corresponding to the roaming terminal during the registration process; The first configuration module is used to configure the encryption item in the contract information according to the first media plane configuration message, and the configured encryption item is used to indicate whether to encrypt the multimedia data corresponding to the roaming terminal.

12. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Voice roaming method, mobility management network element, and access network element

    CN108141741A

  • Forwarding IMS-related information for lawful interception for mobility in s8hr

    CN109417703A