Business processing method and apparatus, electronic device, and storage medium

By working together with UPF and SMF, and using DNN session policies to detect uplink data packets and trigger private network traffic reports, the problem of 5G dual-domain private network terminals being hijacked when accessing the public network is solved, achieving public network isolation before private network access and ensuring private network security.

CN118842637BActive Publication Date: 2026-04-24CHINA MOBILE GRP FUJIAN CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE GRP FUJIAN CO LTD
Filing Date
2024-07-29
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

5G dual-domain private network terminals are at risk of being hijacked when accessing the public network, which makes it impossible to guarantee the security of the private network.

Method used

By working together between UPF and SMF, uplink data packets are detected using DNN session policies, triggering a private network traffic start-up report to discard public network service packets, thus achieving public network isolation before private network access.

Benefits of technology

Effectively blocks public network services, prevents attackers from illegally accessing the private network by hijacking terminals in the public network environment, and ensures the security of the private network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118842637B_ABST
    Figure CN118842637B_ABST
Patent Text Reader

Abstract

The present disclosure provides a service processing method and device, electronic equipment and storage medium. The method is executed by a user plane function unit (UPF), and includes: receiving, by the UPF, a data network name (DNN) session policy sent by a session management function unit (SMF), detecting, by the UPF, an uplink data packet of a user terminal according to the DNN session policy to obtain a packet detection result, and sending, by the UPF, a private network traffic start using report to the SMF in a case where the packet detection result indicates that the uplink data packet includes a private network service packet, wherein the private network traffic start using report is used to trigger the SMF to send a first packet forwarding control protocol (PFCP) session report request message to the UPF, and the first PFCP session report request message is used to trigger the UPF to discard a public network service packet. Thus, the UPF can complete public network isolation before private network access, effectively block public network services, effectively avoid the occurrence of an event of an attacker illegally accessing a private network by hijacking a terminal in a public network environment, and effectively protect the security of the private network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a service processing method, apparatus, electronic device, and storage medium. Background Technology

[0002] 5G dual-domain private network users can use the same terminal or even the same address to access public network and private network "dual-domain" services at the same time. When the terminal accesses the public network, there is a risk of hijacking. Once the terminal is hijacked, the private network may be attacked, and the security of the private network cannot be guaranteed.

[0003] Therefore, how to fundamentally prevent terminals from being hijacked when connected to the public network, and thus avoid attacks on private networks, has become a key research direction. Summary of the Invention

[0004] This disclosure aims to at least partially address one of the technical problems in the related art.

[0005] Therefore, this disclosure provides a business processing method, apparatus, electronic device, storage medium, and computer program product.

[0006] The service processing method proposed in the first aspect of this disclosure is executed by the User Plane Function Unit (UPF), and the method includes:

[0007] Receive the network name and DNN session policy sent by the Session Management Function (SMF) unit;

[0008] The uplink data packets from the user end are detected according to the DNN session policy to obtain the packet detection results;

[0009] If the message detection result indicates that the uplink data message includes private network service messages, a private network traffic start-up report is sent to the Session Management Function Unit (SMF). The private network traffic start-up report is used to trigger the SMF to send a first PFCP session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard public network service messages.

[0010] The service processing method proposed in the second aspect of this disclosure is executed by the Session Management Function (SMF) unit, and the method includes:

[0011] Receive the private network traffic start-up report sent by the User Plane Function Unit (UPF). The private network traffic start-up report is sent by the UPF when it detects that the uplink data packets of the user end include private network service packets.

[0012] The first forwarding action rule (FAR) is updated based on the private network traffic usage report to obtain the second FAR;

[0013] Based on the second FAR, a first PFCP session report request message is generated, wherein the first PFCP session report request message is used to trigger the UPF to drop public network service packets;

[0014] Send the first PFCP session report request message to the UPF.

[0015] The service processing apparatus proposed in the third aspect of this disclosure is executed by a user plane function unit (UPF), and the apparatus includes:

[0016] The first receiving module is used to receive the data network name DNN session policy sent by the session management function unit (SMF).

[0017] The detection module is used to detect the uplink data packets of the user terminal according to the DNN session policy in order to obtain the packet detection results.

[0018] The first sending module is used to send a private network traffic start-up report to the Session Management Function Unit (SMF) when the packet detection result indicates that the uplink data packet includes a private network service packet. The private network traffic start-up report is used to trigger the SMF to send a first packet forwarding control protocol (PFCP) session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard the public network service packet.

[0019] The service processing apparatus proposed in the fourth aspect embodiment of this disclosure is executed by the Session Management Function (SMF) unit, and the apparatus includes:

[0020] The second receiving module is used to receive the private network traffic start-up report sent by the user plane function unit UPF. The private network traffic start-up report is sent by UPF when it detects that the uplink data packets of the user end include private network service packets.

[0021] The update module is used to update the first forwarding action rule (FAR) based on the private network traffic start-up report to obtain the second FAR;

[0022] The generation module is used to generate a first PFCP session report request message based on the second FAR, wherein the first PFCP session report request message is used to trigger the UPF to drop public network service packets;

[0023] The second sending module is used to send the first PFCP session report request message to the UPF.

[0024] A fifth aspect of this disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements a business processing method as proposed in the first aspect of this disclosure, or implements a business processing method as proposed in the second aspect of this disclosure.

[0025] A sixth aspect of this disclosure provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the business processing method as proposed in the first aspect of this disclosure, or implements the business processing method as proposed in the second aspect of this disclosure.

[0026] A seventh aspect embodiment of this disclosure provides a computer program product that, when executed by an instruction processor, performs a business processing method as proposed in a first aspect embodiment of this disclosure, or implements a business processing method as proposed in a second aspect embodiment of this disclosure.

[0027] The service processing method, apparatus, electronic device, storage medium, and computer program product proposed in this disclosure have at least the following beneficial effects: The UPF receives the Data Network Name (DNN) session policy sent by the Session Management Function Unit (SMF), and then detects the uplink data packets of the user terminal according to the DNN session policy to obtain the packet detection result. If the packet detection result indicates that the uplink data packets include private network service packets, the UPF sends a private network traffic start-up report to the Session Management Function Unit (SMF). The private network traffic start-up report is used to trigger the SMF to send a first Packet Forwarding Control Protocol (PFCP) session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard public network service packets. Thus, the UPF can complete public network isolation before private network access, effectively block public network services, effectively prevent attackers from illegally accessing the private network by hijacking terminals in the public network environment, and effectively protect the security of the private network.

[0028] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this disclosure. Attached Figure Description

[0029] The above and / or additional aspects and advantages of this disclosure will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which:

[0030] Figure 1 This is a schematic flowchart of a business processing method proposed in an embodiment of this disclosure;

[0031] Figure 2 This is a schematic diagram of a 5G system architecture proposed in one embodiment of this disclosure;

[0032] Figure 3 This is a schematic flowchart of a business processing method proposed in another embodiment of this disclosure;

[0033] Figure 4 This is a schematic flowchart of a business processing method proposed in an embodiment of this disclosure;

[0034] Figure 5 This is a schematic flowchart of a business processing method proposed in another embodiment of this disclosure;

[0035] Figure 6 This is an interactive schematic diagram of a business processing method proposed in an embodiment of this disclosure.

[0036] Figure 7 This is a schematic diagram of the structure of a service processing apparatus according to an embodiment of this disclosure;

[0037] Figure 8 This is a schematic diagram of the structure of a service processing apparatus according to an embodiment of this disclosure;

[0038] Figure 9 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation

[0039] Embodiments of this disclosure are described in detail below, with examples of embodiments illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are used only to explain this disclosure, and should not be construed as limiting this disclosure. Rather, embodiments of this disclosure include all variations, modifications, and equivalents falling within the spirit and scope of the appended claims.

[0040] The technical solutions provided in this disclosure are applicable to a variety of systems, especially 5G systems. For example, applicable systems may include Global System for Mobile Communication (GSM), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA) General Packet Radio Service (GPRS), Long Term Evolution (LTE), LTE Frequency Division Duplex (FDD), LTE Time Division Duplex (TDD), Long Term Evolution Advanced (LTE-A), Universal Mobile Telecommunication System (UMTS), and 5G New Radio (NR). All of these systems include terminals and network equipment. The systems may also include a core network component, such as Evolved Packet System (EPS) or 5G system (5GS).

[0041] Figure 1 This is a schematic flowchart of a business processing method proposed in an embodiment of this disclosure.

[0042] It should be noted that the execution subject of the service processing method in this embodiment is a service processing device, which can be implemented by software and / or hardware, and can be configured in a network device, without limitation.

[0043] like Figure 1 As shown, the business processing method includes:

[0044] S101: Receives data network name DNN session policy sent by the Session Management Function (SMF) unit.

[0045] Among them, see Figure 2 , Figure 2This is a schematic diagram of a 5G system architecture proposed in one embodiment of the present disclosure. In the 5G system architecture, the Packet Control Function (PCF), Session Management Function (SMF), and User Plane Function (UPF) work together to implement Policy Control and Charging (PCC) session management. The PCF is mainly used to define rule names such as "sessRules" and specific rule content such as using private network slices and private network data network names (DNNs) to establish private network sessions when private network service packets are detected. The PCF sends the rule names and rule content to the SMF. The SMF is mainly used to pass the rule names and specific rule content sent by the PCF to the UPF. The UPF then processes the user data according to the received rules.

[0046] The business processing method described in this embodiment is executed by the User Plane Function (UPF).

[0047] In this embodiment of the disclosure, the UPF can receive the DNN session policy sent by the SMF.

[0048] Optionally, in some embodiments, after receiving the Data Network Name (DNN) session policy sent by the Session Management Function (SMF), the UPF can also receive the PFCP session establishment request message sent by the SMF, and then install the DNN session policy according to the PFCP session establishment request message.

[0049] The PFCP Session Establishment Request message is used to notify UPF to install the DNN session policy.

[0050] In other words, in this embodiment of the present disclosure, after receiving the DNN session policy and PFCP session establishment request message sent by the SMF, the UPF can install the DNN session policy according to the PFCP session establishment request message.

[0051] S102: Detect the uplink data packets of the user terminal according to the DNN session policy to obtain the packet detection results.

[0052] In this embodiment of the disclosure, after the UPF installs the DNN session policy, it can detect the uplink data packets of the user terminal according to the DNN session policy to obtain the corresponding packet detection results. The packet detection results can be used to describe whether the user terminal's service is a private network service. That is, when the packet detection result indicates that there are private network service packets in the uplink data packets, it can be determined that the user terminal's service is a private network service. When the packet detection result indicates that there are no private network service packets in the uplink data packets, it can be determined that the user terminal's service is not a private network service. No restrictions are imposed on this.

[0053] In this embodiment of the disclosure, the UPF can detect the client's line data packets according to the private network URL / URI and IP address / address range in the DNN session policy to obtain the corresponding packet detection results. Then, the packet detection results can be combined to trigger the execution of subsequent business processing methods. For details, please refer to the following embodiments, which will not be repeated here.

[0054] S103: If the packet detection result indicates that the uplink data packet includes a private network service packet, send a private network traffic start-up report to the Session Management Function Unit (SMF). The private network traffic start-up report is used to trigger the SMF to send a first PFCP session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard the public network service packet.

[0055] Among them, the Private Network Traffic Start-up Report is used to trigger the SMF to send the first PFCP Session Report Request message to the UPF. The first PFCP Session Report Request message is used to trigger the UPF to discard public network service packets.

[0056] The report that indicates the start of use of private network traffic is a report with Report Type USAR (Usage Report) and Trigger START (Traffic Start).

[0057] Optionally, in some embodiments, the UPF may also receive a first PFCP session report request message sent by the SMF, and then discard public network service packets according to the first PFCP session report request message.

[0058] In other words, in this embodiment of the present disclosure, when the UPF detects that the uplink data packet includes a private network service packet, it can send a private network traffic start-up report to the Session Management Function Unit (SMF) to trigger the SMF to send a first Packet Forwarding Control Protocol (PFCP) session report request message to the UPF. This allows the UPF to discard the public network service packet according to the first PFCP session report request message F, thereby enabling the UPF to complete public network isolation before private network access, effectively blocking public network services, effectively preventing attackers from illegally accessing the private network by hijacking terminals in the public network environment, and effectively ensuring private network security.

[0059] In this embodiment of the disclosure, after discarding public network service packets, the public network SMF triggers the establishment of a private network DNN session, and after executing the PDU session establishment process of the private network DNN, the user can normally send and receive private network service packets. The private network service route is, for example: UE—base station—public network UPF—private network UPF—private network.

[0060] In this embodiment, the UPF receives the Data Network Name (DNN) session policy sent by the Session Management Function Unit (SMF), and then detects the uplink data packets of the user terminal according to the DNN session policy to obtain the packet detection result. If the packet detection result indicates that the uplink data packets include private network service packets, the UPF sends a private network traffic start-up report to the Session Management Function Unit (SMF). The private network traffic start-up report is used to trigger the SMF to send a first Packet Forwarding Control Protocol (PFCP) session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard public network service packets. Thus, the UPF can complete public network isolation before private network access, effectively block public network services, effectively prevent attackers from illegally accessing the private network by hijacking terminals in the public network environment, and effectively protect the security of the private network.

[0061] Figure 3 This is a flowchart illustrating a business processing method proposed in another embodiment of this disclosure.

[0062] like Figure 3 As shown, the business processing method includes:

[0063] S301: Receives data network name DNN session policy sent by the Session Management Function (SMF) unit.

[0064] S302: Detect the uplink data packets of the user terminal according to the DNN session policy to obtain the packet detection results.

[0065] S303: When the message detection result indicates that the uplink data message includes private network service messages, a private network traffic start-up report is sent to the Session Management Function Unit (SMF). The private network traffic start-up report is used to trigger the SMF to send a first PFCP session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard public network service messages.

[0066] For a detailed description of S301-S303, please refer to the above embodiments, which will not be repeated here.

[0067] S304: If the message detection results within the preset time period indicate that the uplink data packets do not include private network service packets, send a private network traffic stop use report to the SMF. The private network traffic stop use report is used to trigger the SMF to send a second PFCP session report request message to the UPF.

[0068] The preset time period can be, for example, 2 seconds, or it can be adaptively set in conjunction with the business processing requirements in the actual business scenario, without any restrictions.

[0069] Among them, the private network traffic stop use report is used to trigger the SMF to send a second PFCP session report request message to the UPF. The private network traffic stop use report is a report with Report Type USAR (Usage Report) and Trigger STOP (Stop Traffic).

[0070] The second PFCP session report request message is a message sent by the SMF to the UPF to trigger the UPF to continue forwarding public network service packets.

[0071] In other words, in this embodiment of the present disclosure, the UPF can continuously detect the uplink data packets of the user terminal according to the DNN session policy to obtain the packet detection results, and if the packet detection results obtained within a preset time period indicate that the uplink data packets do not include private network service packets, a private network traffic stop-use report is sent to the SMF.

[0072] S305: Receive the second PFCP session report request message sent by SMF.

[0073] In this embodiment of the disclosure, the UPF can receive a second PFCP session report request message sent by the SMF, and then, in conjunction with the second PFCP session report request message, can trigger the execution of subsequent business processing methods. For details, please refer to the following embodiments, which will not be repeated here.

[0074] S306: Re-forward public network service packets according to the second PFCP session report request message.

[0075] In this embodiment of the disclosure, after receiving the second PFCP session report request message sent by the SMF, the UPF can re-forward public network service packets according to the second PFCP session report request message.

[0076] In this embodiment of the disclosure, the UPF can promptly restore the operation of public network services when no private network services are detected, thereby avoiding the inconvenience caused to users accessing the public network by long-term blocking of public network services.

[0077] In this embodiment, the UPF receives the Data Network Name (DNN) session policy sent by the Session Management Function (SMF), and then detects the uplink data packets of the user terminal according to the DNN session policy to obtain the packet detection result. If the packet detection result indicates that the uplink data packets include private network service packets, the UPF sends a private network traffic start-up report to the SMF. This report triggers the SMF to send a first Packet Forwarding Control Protocol (PFCP) session report request message to the UPF. The first PFCP session report request message triggers the UPF to discard public network service packets. Thus, the UPF can complete public network isolation before private network access, effectively blocking public network services and effectively avoiding... Attackers hijack terminals in the public network environment to illegally access the private network, effectively ensuring the security of the private network. Furthermore, if the packet detection results within a preset time period indicate that the uplink data packets do not contain private network service packets, a private network traffic stoppage report is sent to the SMF. The private network traffic startpage report triggers the SMF to send a second PFCP session report request message to the UPF. Upon receiving the second PFCP session report request message from the SMF, the UPF re-forwards public network service packets based on the second PFCP session report request message. Thus, the UPF can promptly restore public network services even when no private network services are detected, thereby avoiding the inconvenience caused to users accessing the public network due to prolonged public network service disruptions.

[0078] Figure 4 This is a schematic flowchart of a business processing method proposed in an embodiment of this disclosure.

[0079] It should be noted that the execution subject of the service processing method in this embodiment is a service processing device, which can be implemented by software and / or hardware, and can be configured in a network device, without limitation.

[0080] like Figure 4 As shown, the business processing method includes:

[0081] S401: Receive a private network traffic start-up report sent by the User Plane Function Unit (UPF). The private network traffic start-up report is sent by the UPF when it detects that the uplink data packets at the user end include private network service packets.

[0082] In this disclosure, the explanations of the same terms as in the above embodiments can be found in the above embodiments, and will not be repeated here.

[0083] The Private Network Traffic Start-up Report is sent by the UPF when it detects that the user's uplink data packets include private network service packets.

[0084] The business processing method described in this embodiment is executed by SMF.

[0085] In this embodiment of the disclosure, the SMF can receive a private network traffic start-up report sent by the User Plane Function Unit (UPF) when it detects that the uplink data packet from the user end includes a private network service packet.

[0086] S402: Update the first forwarding action rule FAR based on the private network traffic start-up report to obtain the second FAR.

[0087] Among them, the First Forwarding Action Rule (FAR) is used in 5G systems to guide the forwarding path and behavior of data packets or messages in the network.

[0088] In this embodiment of the disclosure, after receiving the private network traffic start-up report sent by the User Plane Function Unit (UPF), the SMF can update the Apply Action parameter in the first forwarding action rule (FAR) according to the private network traffic start-up report (wherein, the Apply Action parameter defines whether the UPF needs to perform operations such as forwarding, copying, dropping, or buffering when processing data packets that match a specific packet detection rule, and whether it needs to notify the Control Plane Function (CPF), etc.), so as to obtain the updated second FAR.

[0089] S403: Based on the second FAR, generate a first PFCP session report request message, wherein the first PFCP session report request message is used to trigger the UPF to discard public network service packets.

[0090] In this embodiment of the disclosure, after updating the first forwarding action rule (FAR) based on the private network traffic start-up report to obtain the second FAR, a first packet forwarding control protocol (PFCP) session report request message can be generated based on the second FAR.

[0091] S404: Send the first PFCP session report request message to the UPF.

[0092] In this embodiment of the disclosure, after generating a first Message Forwarding Control Protocol (PFCP) Session Report Request message according to the second FAR, the SMF can send the first PFCP Session Report Request message to the UPF to trigger the UPF to discard public network service packets in a timely manner, thereby eliminating the possibility of the terminal being hijacked when accessing the public network from the root and effectively ensuring the security of the private network.

[0093] In this embodiment, the SMF receives a private network traffic start-up report sent by the User Plane Function Unit (UPF). This report is sent by the UPF when it detects that a private network service packet is included in the uplink data packet from the user terminal. The SMF then updates the first forwarding action rule (FAR) based on the report to obtain a second FAR. Based on the second FAR, a first Packet Forwarding Control Protocol (PFCP) session report request message is generated. This message triggers the UPF to discard public network service packets. By sending this message to the UPF, the SMF responds promptly to the private network traffic start-up report sent by the UPF when it detects that a private network service packet is included in the uplink data packet from the user terminal. This timely generation and feedback of the first PFCP session report request message to the UPF effectively blocks public network services, preventing attackers from illegally accessing the private network by hijacking terminals in the public network environment, thus effectively ensuring private network security.

[0094] Figure 5 This is a schematic flowchart of a business processing method proposed in another embodiment of this disclosure.

[0095] like Figure 5 As shown, the business processing method includes:

[0096] S501: When determining the establishment of a session between the user equipment and the data network DN, a session management policy control creation request is sent to the PCF corresponding to the user equipment to obtain the DNN session policy issued by the PCF according to the session management policy control creation request.

[0097] In this embodiment of the disclosure, the user accesses the public network SMF via 5G and establishes a general DNN session. When the general DNN session is established, the SMF sends a session management policy control creation request (Npcf_SMPolicy Control_Create Request) to the policy control function (PCF) corresponding to the user equipment. After receiving the session management policy control creation request, the PCF will issue the DNN session policy according to the session management policy control creation request.

[0098] S502: Send the DNN session policy to the UPF.

[0099] In this embodiment of the disclosure, when the SMF determines that a session is established between the user equipment and the data network DN, it sends a session management policy control creation request to the PCF corresponding to the user equipment. After obtaining the DNN session policy issued by the PCF according to the session management policy control creation request, it sends the DNN session policy to the UPF.

[0100] S503: Send a PFCP session establishment request message to the UPF, wherein the PFCP session establishment request message is used to trigger the UPF to install the DNN session policy.

[0101] The PFCP session establishment request message is used to trigger the UPF to install the DNN session policy.

[0102] In other words, in this embodiment of the disclosure, the SMF will send a PFCP session establishment request message to the corresponding UPF in a timely manner to notify the UPF to install the DNN session policy.

[0103] S504: Receive a private network traffic start-up report sent by the User Plane Function Unit (UPF). The private network traffic start-up report is sent by the UPF when it detects that the user's uplink data packets include private network service packets.

[0104] S505: Update the first forwarding action rule FAR based on the private network traffic start-up report to obtain the second FAR.

[0105] S506: Based on the second FAR, generate a first PFCP session report request message, wherein the first PFCP session report request message is used to trigger the UPF to discard public network service packets.

[0106] S507: Send the first PFCP session report request message to the UPF.

[0107] For a detailed description of S504-S507, please refer to the above embodiments, which will not be repeated here.

[0108] S508: Receives reports from UPF indicating that private network traffic has stopped being used.

[0109] The Private Network Traffic Start-up Report is sent by the UPF when it detects that the uplink data packets do not include private network service packets within a preset time period.

[0110] In other words, in this embodiment of the present disclosure, the SMF can receive a private network traffic stoppage report sent by the UPF when it detects that the uplink data packets do not include private network service packets within a preset time period. Then, it can trigger the execution of subsequent service processing methods based on the private network traffic stoppage report it received. For details, please refer to the following embodiments, which will not be repeated here.

[0111] S509: Update the second FAR based on the private network traffic stoppage report to obtain the third FAR.

[0112] In this embodiment of the disclosure, after receiving the private network traffic stop-use report sent by the UPF, the SMF can update the Apply Action parameter in the second FAR according to the private network traffic stop-use report to obtain the updated third FAR.

[0113] S510: Based on the third FAR, generate a second PFCP session report request message, wherein the second PFCP session report request message is used to trigger the UPF to continue forwarding public network service packets.

[0114] The second PFCP session report request message is used to trigger the UPF to continue forwarding public network service packets.

[0115] In this embodiment of the disclosure, after the SMF updates the second FAR based on the private network traffic stop-use report to obtain the third FAR, it can generate a second PFCP session report request message based on the third FAR.

[0116] S511: Send a second PFCP session report request message to the UPF.

[0117] In this embodiment of the disclosure, after generating a second PFCP session report request message according to the third FAR, the SMF can send the second PFCP session report request message to the UPF to trigger the UPF to continue forwarding public network service packets in a timely manner and restore public network services in a timely manner, thereby ensuring the operation of private network services.

[0118] In this embodiment, when the SMF determines that a session has been established between the user equipment and the data network (DN), it sends a session management policy control creation request to the PCF corresponding to the user equipment to obtain the DNN session policy issued by the PCF according to the session management policy control creation request. Then, it sends the DNN session policy to the UPF, and then sends a PFCP session establishment request message to the UPF. The PFCP session establishment request message is used to trigger the UPF to install the DNN session policy. Next, it receives a private network traffic start-up report from the user plane functional unit (UPF). This private network traffic start-up report is sent by the UPF when it detects that the uplink data packets from the user end include private network service packets. Then, it updates the first forwarding action rule (FAR) according to the private network traffic start-up report to obtain a second FAR. Finally, based on the second FAR, it generates... The first PFCP session report request message is used to trigger the UPF to discard public network service packets. Then, the first PFCP session report request message is sent to the UPF, thus enabling the UPF to discard public network service packets in a timely manner. Next, the private network traffic stoppage report is received from the UPF, and the second FAR is updated based on the report to obtain the third FAR. Then, based on the third FAR, a second PFCP session report request message is generated. This second PFCP session report request message is used to trigger the UPF to continue forwarding public network service packets. Sending the second PFCP session report request message to the UPF ensures timely resumption of public network services and guarantees the operation of private network services.

[0119] Figure 6 This is an interactive schematic diagram of a business processing method proposed in an embodiment of this disclosure.

[0120] like Figure 6 As shown, the business processing method includes:

[0121] S601: The PCF corresponding to the user sends the DNN session policy to the SMF.

[0122] S602: The SMF sends a PFCP session establishment request message and a DNN session policy to the UPF. The PFCP session establishment request message is used to trigger the UPF to install the DNN session policy.

[0123] S603: UPF installs the DNN session policy based on the PFCP session establishment request message.

[0124] S604: UPF detects uplink data packets from the user terminal according to the DNN session policy to obtain packet detection results.

[0125] S605: When the packet detection result indicates that the uplink data packet includes a private network service packet, the UPF sends a private network traffic start-up report to the Session Management Function Unit (SMF).

[0126] S606: SMF updates the first forwarding action rule (FAR) based on the private network traffic start-up report to obtain the second FAR.

[0127] S607: The SMF generates a first PFCP session report request message based on the second FAR.

[0128] S608: SMF sends the first PFCP session report request message to UPF.

[0129] S609: UPF discards public network service packets based on the first PFCP session report request message.

[0130] S610: If the UPF's message detection results within the preset time period indicate that the uplink data packets do not include private network service packets, a private network traffic stoppage report will be sent to the SMF.

[0131] S611: SMF updates the second FAR based on the private network traffic stoppage report to obtain the third FAR.

[0132] S612: The SMF generates a second PFCP session report request message based on the third FAR. The second PFCP session report request message is used to trigger the UPF to continue forwarding public network service packets.

[0133] S613: SMF sends a second PFCP session report request message to UPF.

[0134] S614: UPF re-forwards public network service packets based on the second PFCP session report request message.

[0135] Figure 7 This is a schematic diagram of the structure of a service processing apparatus according to an embodiment of this disclosure.

[0136] like Figure 7 As shown, the service processing device 70 is executed by the User Plane Function Unit (UPF), and the device includes:

[0137] The first receiving module 701 is used to receive the data network name (DNN) session policy sent by the session management function unit (SMF).

[0138] The detection module 702 is used to detect the uplink data packets of the user terminal according to the DNN session policy in order to obtain the packet detection results;

[0139] The first sending module 703 is used to send a private network traffic start-up report to the session management function unit (SMF) when the message detection result indicates that the uplink data message includes a private network service message. The private network traffic start-up report is used to trigger the SMF to send a first message forwarding control protocol (PFCP) session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard the public network service message.

[0140] In some embodiments of this disclosure, the service processing apparatus 70 is further configured to:

[0141] Receive the first PFCP session report request message sent by SMF;

[0142] Public network service packets are discarded based on the first PFCP session report request message.

[0143] In some embodiments of this disclosure, the first receiving module 701 is further configured to:

[0144] After receiving the Data Network Name (DNN) session policy sent by the Session Management Function (SMF) unit, receive the PFCP session establishment request message sent by the SMF.

[0145] Install the DNN session policy based on the PFCP session establishment request message.

[0146] In some embodiments of this disclosure, the service processing apparatus 70 is further configured to:

[0147] If the message detection results within the preset time period indicate that the uplink data packets do not include private network service packets, a private network traffic stop-use report is sent to the SMF. The private network traffic start-use report is used to trigger the SMF to send a second PFCP session report request message to the UPF.

[0148] In some embodiments of this disclosure, the service processing apparatus 70 is further configured to:

[0149] Receive the second PFCP session report request message sent by SMF;

[0150] Based on the second PFCP session report request message, the public network service packets are re-forwarded.

[0151] With the above Figures 1 to 2 Corresponding to the business processing method provided in the embodiments, this disclosure also provides a business processing apparatus. Since the business processing apparatus provided in the embodiments of this disclosure is similar to the one described above... Figures 1 to 2 The business processing method provided in the embodiments corresponds to the business processing method, and therefore the implementation of the business processing method is also applicable to the business processing apparatus proposed in the embodiments of this disclosure, and will not be described in detail in the embodiments of this disclosure.

[0152] In this embodiment, the UPF receives the Data Network Name (DNN) session policy sent by the Session Management Function Unit (SMF), and then detects the uplink data packets of the user terminal according to the DNN session policy to obtain the packet detection result. If the packet detection result indicates that the uplink data packets include private network service packets, the UPF sends a private network traffic start-up report to the Session Management Function Unit (SMF). The private network traffic start-up report is used to trigger the SMF to send a first Packet Forwarding Control Protocol (PFCP) session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard public network service packets. Thus, the UPF can complete the public network isolation before private network access, effectively block public network services, effectively prevent attackers from hijacking terminals in the public network environment and illegally accessing the private network, and effectively protect the security of the private network.

[0153] Figure 8 This is a schematic diagram of the structure of a service processing apparatus according to an embodiment of this disclosure.

[0154] like Figure 8 As shown, the service processing device 80 is executed by the Session Management Function (SMF) unit, and the device includes:

[0155] The second receiving module 801 is used to receive the private network traffic start-up report sent by the user plane function unit UPF. The private network traffic start-up report is sent by the UPF when it detects that the uplink data packet of the user end includes a private network service packet.

[0156] Update module 802 is used to update the first forwarding action rule FAR based on the private network traffic start-up report to obtain the second FAR;

[0157] The generation module 803 is used to generate a first Message Forwarding Control Protocol (PFCP) Session Report Request message based on the second FAR, wherein the first PFCP Session Report Request message is used to trigger the UPF to discard public network service packets;

[0158] The second sending module 804 is used to send a first PFCP session report request message to the UPF.

[0159] In some embodiments of this disclosure, the service processing apparatus 80 is further configured to:

[0160] When determining the establishment of a session between a user equipment and a data network (DN), a session management policy control creation request is sent to the PCF corresponding to the user equipment to obtain the DNN session policy issued by the PCF according to the session management policy control creation request.

[0161] Send the DNN session policy to the UPF.

[0162] In some embodiments of this disclosure, the service processing apparatus 80 is further configured to:

[0163] Send a PFCP session establishment request message to the UPF. The PFCP session establishment request message is used to trigger the UPF to install the DNN session policy.

[0164] In some embodiments of this disclosure, the service processing apparatus 80 is further configured to:

[0165] Receive reports from UPF indicating that private network traffic has stopped being used;

[0166] The second FAR is updated based on the private network traffic stoppage report to obtain the third FAR. The private network traffic start-up report is sent by the UPF when it detects that the uplink data packets do not include private network service packets within a preset time period.

[0167] Based on the third FAR, a second PFCP session report request message is generated, which is used to trigger the UPF to continue forwarding public network service packets;

[0168] Send a second PFCP session report request message to the UPF.

[0169] With the above Figures 2 to 4 Corresponding to the business processing method provided in the embodiments, this disclosure also provides a business processing apparatus. Since the business processing apparatus provided in the embodiments of this disclosure is similar to the one described above... Figures 2 to 4 The business processing method provided in the embodiments corresponds to the business processing method, and therefore the implementation of the business processing method is also applicable to the business processing apparatus proposed in the embodiments of this disclosure, and will not be described in detail in the embodiments of this disclosure.

[0170] In this embodiment, the SMF receives a private network traffic start-up report sent by the User Plane Function Unit (UPF). This report is sent by the UPF when it detects that a private network service packet is included in the uplink data packet from the user terminal. The SMF then updates the first forwarding action rule (FAR) based on the report to obtain a second FAR. Based on the second FAR, a first Packet Forwarding Control Protocol (PFCP) session report request message is generated. This message triggers the UPF to discard public network service packets. By sending this message to the UPF, the SMF responds promptly to the private network traffic start-up report sent by the UPF when it detects that a private network service packet is included in the uplink data packet from the user terminal. This timely generation and feedback of the first PFCP session report request message to the UPF effectively blocks public network services, preventing attackers from illegally accessing the private network by hijacking terminals in the public network environment, thus effectively ensuring private network security.

[0171] To implement the above embodiments, this disclosure also proposes an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the business processing method proposed in the foregoing embodiments of this disclosure.

[0172] To implement the above embodiments, this disclosure also proposes a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the business processing method proposed in the foregoing embodiments of this disclosure.

[0173] To implement the above embodiments, this disclosure also proposes a computer program product that, when the instruction processor in the computer program product is executed, performs the business processing method proposed in the foregoing embodiments of this disclosure.

[0174] Figure 9 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Figure 9 The electronic device 12 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.

[0175] like Figure 9 As shown, the electronic device 12 is represented in the form of a general-purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and bus 18 connecting different system components (including system memory 28 and processing unit 16).

[0176] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0177] Electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 12, including volatile and non-volatile media, removable and non-removable media.

[0178] Memory 28 may include computer system readable media in the form of volatile memory, such as Random Access Memory (RAM) 30 and / or cache memory 32. Electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (… Figure 9 Not shown; usually referred to as a "hard drive".

[0179] although Figure 9 Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disc drive for reading and writing to a removable non-volatile optical disc (e.g., a compact disc read-only memory (CD-ROM), a digital video disc read-only memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. Memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.

[0180] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of this disclosure.

[0181] Electronic device 12 can also communicate with one or more external devices 14 (e.g., keyboard, pointing device, display 24, etc.), and with one or more devices that enable a user to interact with electronic device 12, and / or with any device that enables electronic device 12 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 22. Furthermore, electronic device 12 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. As shown, network adapter 20 communicates with other modules of electronic device 12 via bus 18. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0182] The processing unit 16 executes various functional applications and business processes by running programs stored in the system memory 28, such as implementing the business processing methods mentioned in the foregoing embodiments.

[0183] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0184] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

[0185] It should be noted that in the description of this disclosure, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this disclosure, unless otherwise stated, "a plurality of" means two or more.

[0186] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of preferred embodiments of this disclosure includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this disclosure pertain.

[0187] It should be understood that various parts of this disclosure can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0188] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0189] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0190] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.

[0191] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0192] Although embodiments of the present disclosure have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A business processing method, characterized in that, The method, executed by the User-Face Function Unit (UPF), includes: Receive the network name and DNN session policy sent by the Session Management Function (SMF) unit; The uplink data packets of the user terminal are detected according to the DNN session strategy to obtain the packet detection results; If the packet detection result indicates that the uplink data packet includes a private network service packet, a private network traffic start-up report is sent to the Session Management Function Unit (SMF). The private network traffic start-up report is used to trigger the SMF to send a first Packet Forwarding Control Protocol (PFCP) session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard the public network service packet. If the packet detection results within the preset time period indicate that the private network service packet is not included in the uplink data packet, a private network traffic stop use report is sent to the SMF, wherein the private network traffic stop use report is used to trigger the SMF to send a second PFCP session report request message to the UPF; Receive the second PFCP session report request message sent by the SMF; Based on the second PFCP session report request message, the public network service packet is re-forwarded.

2. The method as described in claim 1, characterized in that, The method further includes: Receive the first PFCP session report request message sent by the SMF; The public network service packet is discarded according to the first PFCP session report request message.

3. The method as described in claim 1, characterized in that, Following the Data Network Name (DNN) session policy sent by the Receive Session Management Function (SMF) unit, the following is also included: Receive the PFCP session establishment request message sent by the SMF; Install the DNN session policy according to the PFCP session establishment request message.

4. A business processing method, characterized in that, The method, executed by the Session Management Function (SMF) unit, includes: Receive a private network traffic start-up report sent by the User Plane Function Unit (UPF), wherein the private network traffic start-up report is sent by the UPF when it detects that the uplink data packets of the user end include private network service packets; The first forwarding action rule (FAR) is updated based on the private network traffic start-up report to obtain the second FAR; Based on the second FAR, a first PFCP session report request message is generated, wherein the first PFCP session report request message is used to trigger the UPF to discard public network service packets; Send the first PFCP session report request message to the UPF; Receive a private network traffic stoppage report sent by the UPF, wherein the private network traffic stoppage report is sent by the UPF when it detects that the uplink data packets do not include the private network service packets within a preset time period; Based on the private network traffic stoppage report, the second FAR is updated to obtain the third FAR; Based on the third FAR, a second PFCP session report request message is generated, wherein the second PFCP session report request message is used to trigger the UPF to continue forwarding the public network service packet; Send the second PFCP session report request message to the UPF.

5. The method as described in claim 4, characterized in that, The method further includes: When determining the establishment of a session between a user equipment and a data network (DN), a session management policy control creation request is sent to the PCF corresponding to the user equipment to obtain the DNN session policy issued by the PCF according to the session management policy control creation request. Send the DNN session policy to the UPF.

6. The method as described in claim 4 or 5, characterized in that, The method further includes: Send a PFCP session establishment request message to the UPF, wherein the PFCP session establishment request message is used to trigger the UPF to install the DNN session policy.

7. A business processing device, characterized in that, Executed by the User Plane Function (UPF), the apparatus is used to implement the service processing method as described in claim 1, and the apparatus includes: The first receiving module is used to receive the data network name DNN session policy sent by the session management function unit (SMF). The detection module is used to detect the uplink data packets of the user terminal according to the DNN session policy, so as to obtain the packet detection results; The first sending module is configured to send a private network traffic start-up report to the Session Management Function Unit (SMF) when the packet detection result indicates that the uplink data packet includes a private network service packet. The private network traffic start-up report is used to trigger the SMF to send a first Packet Forwarding Control Protocol (PFCP) session report request message to the UPF. The first PFCP session report request message is used to trigger the UPF to discard the public network service packet.

8. A business processing device, characterized in that, The device, executed by the Session Management Function (SMF) unit, is used to implement the service processing method as described in claim 4, and the device includes: The second receiving module is used to receive a private network traffic start-up report sent by the User Plane Function Unit (UPF), wherein the private network traffic start-up report is sent by the UPF when it detects that the uplink data packet of the user end includes a private network service packet. The update module is used to update the first forwarding action rule (FAR) based on the private network traffic start-up report to obtain the second FAR; The generation module is used to generate a first PFCP session report request message based on the second FAR, wherein the first PFCP session report request message is used to trigger the UPF to discard public network service packets; The second sending module is used to send the first PFCP session report request message to the UPF.

9. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-6.

10. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-6.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Access service processing method and device, storage medium and electronic equipment

    CN113473417A

  • Service access processing method and device, equipment and storage medium

    CN115529342A