Information communication method, system, device, computer device and readable storage medium
By configuring IPsec tunnels and using key information in the information communication request, the problem of low security in existing VoWIFI communication is solved, a secure VoWIFI function is realized, terminal hardware upgrades are avoided, and communication security is improved.
Patent Information
- Application Number
- CN202410929724.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-11
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-07-11
AI Technical Summary
The existing communication method of achieving VOWIFI functionality by downloading an app has low security, especially when directly connecting to the IMS system.
By sending protocol signaling that matches the information communication request and configuring an IPsec tunnel using the associated key information, the signaling is encapsulated in the IPsec tunnel and sent to the ePDG gateway. The ePDG gateway is used to obtain protocol signaling and data based on the key information, establish a communication channel with the IMS system, and realize information communication.
It improves the security of information and communication, eliminates the need for hardware upgrades to the terminal, and enables VOWIFI functionality by connecting to the IMS system through the ePDG gateway, thus enhancing communication security.
Smart Images

Figure CN119012191B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to an information communication method, system and device, computer equipment, computer readable storage medium and computer program product. BACKGROUND
[0002] With the development of communication technology, a technology for realizing voice call through Wi-Fi network, i.e. VOWIFI technology, appears. The VOWIFI technology can utilize the IP transmission capability of Wi-Fi network to realize voice call on the Wi-Fi network, convert voice signals into IP data packets, transmit through the Wi-Fi network, and then decode and play on the terminal device to realize voice call through the Wi-Fi network. Therefore, voice communication service can be provided through the Wi-Fi network in the absence of mobile network signal.
[0003] In the traditional technology, if the VOWIFI function needs to be realized, the mobile terminal usually needs to support the VOWIFI function originally. For the mobile terminal that cannot support the VOWIFI function originally, the VOWIFI function can be realized through the terminal APP, i.e. the function is realized through downloading the APP, without the need of replacing the mobile terminal to realize the VOWIFI.
[0004] However, in the current technology for realizing the VOWIFI function through downloading the APP, the terminal is directly connected to the IMS system to realize the VOWIFI function, so that the security of the communication mode is low. SUMMARY
[0005] Therefore, it is necessary to provide an information communication method, system and device, computer equipment, computer readable storage medium and computer program product capable of improving the security of the communication mode in view of the above technical problems.
[0006] In a first aspect, the present application provides an information communication method, comprising:
[0007] In response to an information communication request, sending a protocol signaling matched with the information communication request, and configuring an IPsec tunnel by using key information associated with the information communication request;
[0008] Encapsulating the protocol signaling in the IPsec tunnel and sending to an ePDG gateway; the ePDG gateway is used to acquire the protocol signaling based on the key information and send to an IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and a terminal based on the protocol signaling;
[0009] After the communication channel is successfully established, the information communication request corresponding to the to-be-sent data is encapsulated in the IPsec tunnel, and the to-be-sent data is sent to the ePDG gateway through the communication channel; the ePDG gateway is configured to acquire the to-be-sent data based on the key information, and send the to-be-sent data to the IMS system to perform information communication through the IMS system.
[0010] In one embodiment, the IPsec tunnel is configured by using the key information associated with the information communication request, including: acquiring SIM card information associated with the information communication request, and generating the key information by using the SIM card information; the SIM card information is the SIM card information of a terminal triggering the information communication request; the key information is sent to the ePDG gateway, and in a case where the ePDG gateway returns confirmation information for the key information is received, the IPsec tunnel is configured by using the key information.
[0011] In one embodiment, the information communication request includes a voice call request; the protocol signaling matched with the information communication request is sent by using a pre-configured protocol stack module; the to-be-sent data corresponding to the information communication request is encapsulated in the IPsec tunnel, including: acquiring to-be-sent video data corresponding to the voice call request, and / or to-be-sent voice data corresponding to the voice call request; and the to-be-sent video data and / or the to-be-sent voice data is encapsulated in the IPsec tunnel.
[0012] In one embodiment, the information communication request includes a short message transmission request; the protocol signaling matched with the information communication request is sent by using a pre-configured protocol stack module; the to-be-sent data corresponding to the information communication request is encapsulated in the IPsec tunnel, including: acquiring to-be-sent short message data corresponding to the short message transmission request; and the to-be-sent short message data is encapsulated in the IPsec tunnel.
[0013] In one of the embodiments, before sending the protocol signaling matched with the information communication request in response to the information communication request, the method further comprises: obtaining SIM card information associated with a registration request for an information communication service corresponding to the information communication request; the SIM card information is the SIM card information of a terminal triggering the registration request; configuring an IPsec tunnel by using key information associated with the registration request, encapsulating the SIM card information in the IPsec tunnel, and sending the SIM card information to an ePDG gateway; the ePDG gateway is configured to obtain the SIM card information based on the key information associated with the registration request, and send the SIM card information to a core network, so that the core network obtains an authentication result of the terminal based on the SIM card information; in a case where the authentication result indicates that the authentication is passed, obtaining a terminal identifier of the terminal based on the SIM card information, encapsulating the terminal identifier in the IPsec tunnel, and sending the terminal identifier to the ePDG gateway; the ePDG gateway is configured to obtain the terminal identifier based on the key information associated with the registration request, and send the terminal identifier to an IMS system, so that the IMS system registers the terminal for the information communication service based on the terminal identifier.
[0014] In one of the embodiments, the method further comprises: generating the key information associated with the registration request by using the SIM card information; sending the key information associated with the registration request to the ePDG gateway, and in a case where the ePDG gateway returns confirmation information for the key information associated with the registration request, configuring the IPsec tunnel by using the key information associated with the registration request.
[0015] In a second aspect, the application further provides an information communication system, comprising: an information communication service module, a protocol stack module, and a tunnel processing module; wherein:
[0016] The information communication service module is configured to, in response to an information communication request, invoke the protocol stack module to send protocol signaling matched with the information communication request, and configure an IPsec tunnel by using key information associated with the information communication request;
[0017] The tunnel processing module is further configured to encapsulate the protocol signaling in the IPsec tunnel, and send the protocol signaling to an ePDG gateway; the ePDG gateway is configured to obtain the protocol signaling based on the key information, and send the protocol signaling to an IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and a terminal based on the protocol signaling;
[0018] The tunnel processing module is further configured to, after the communication channel is successfully established, encapsulate the to-be-sent data corresponding to the information communication request in the IPsec tunnel, and send the to-be-sent data to the ePDG gateway through the communication channel; and the ePDG gateway is configured to acquire the to-be-sent data based on the key information, and send the to-be-sent data to the IMS system, so that the IMS system performs information communication.
[0019] In one of the embodiments, the system further comprises a SIM card information acquisition module; and the information communication service module is further configured to acquire the SIM card information associated with the information communication request by invoking the SIM card information acquisition module, and generate the key information based on the SIM card information.
[0020] In one of the embodiments, the information communication service module is further configured to, in response to a registration request for an information communication service corresponding to the information communication request, acquire the SIM card information associated with the registration request, and configure an IPsec tunnel by using the key information associated with the registration request; the SIM card information is the SIM card information of a terminal triggering the registration request; the tunnel processing module is further configured to encapsulate the SIM card information in the IPsec tunnel, and send the SIM card information to the ePDG gateway; and the ePDG gateway is configured to acquire the SIM card information based on the key information associated with the registration request, and send the SIM card information to a core network, so that the core network obtains an authentication result of the terminal based on the SIM card information; the tunnel processing module is further configured to, in a case where the authentication result indicates that the authentication is passed, acquire a terminal identifier of the terminal based on the SIM card information, encapsulate the terminal identifier in the IPsec tunnel, and send the terminal identifier to the ePDG gateway; and the ePDG gateway is configured to acquire the terminal identifier based on the key information associated with the registration request, and send the terminal identifier to the IMS system, so that the IMS system registers the terminal for the information communication service based on the terminal identifier.
[0021] In a third aspect, the present application further provides an information communication device, comprising:
[0022] a tunnel configuration module configured to, in response to an information communication request, send a protocol signaling matched with the information communication request, and configure an IPsec tunnel by using key information associated with the information communication request;
[0023] a protocol sending module configured to encapsulate the protocol signaling in the IPsec tunnel, and send the protocol signaling to an ePDG gateway; and the ePDG gateway is configured to acquire the protocol signaling based on the key information, and send the protocol signaling to an IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and a terminal based on the protocol signaling.
[0024] a data sending module, configured to, after the communication channel is successfully established, encapsulate to-be-sent data corresponding to the information communication request in the IPsec tunnel, and send the to-be-sent data to the ePDG gateway through the communication channel; and the ePDG gateway is configured to acquire the to-be-sent data based on the key information, and send the to-be-sent data to the IMS system, so that information communication is performed through the IMS system.
[0025] In a fourth aspect, the present application further provides a computer device, comprising a memory and a processor, the memory stores a computer program, and the processor implements the steps of the method in any one of the embodiments of the first aspect when executing the computer program.
[0026] In a fifth aspect, the present application further provides a computer readable storage medium, which stores a computer program, and the computer program implements the steps of the method in any one of the embodiments of the first aspect when executed by a processor.
[0027] In a sixth aspect, the present application further provides a computer program product, comprising a computer program, and the computer program implements the steps of the method in any one of the embodiments of the first aspect when executed by a processor.
[0028] The information communication method, device, computer equipment, computer readable storage medium and computer program product can send protocol signaling matched with the information communication request in response to the information communication request, and configure an IPsec tunnel by using key information associated with the information communication request; the protocol signaling is encapsulated in the IPsec tunnel and sent to an ePDG gateway; the ePDG gateway is configured to obtain the protocol signaling based on the key information and send the protocol signaling to an IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and the terminal based on the protocol signaling; after the communication channel is successfully established, the to-be-sent data corresponding to the information communication request is encapsulated in the IPsec tunnel, and the to-be-sent data is sent to the ePDG gateway through the communication channel; the ePDG gateway is configured to obtain the to-be-sent data based on the key information and send the to-be-sent data to the IMS system, so that information communication is performed through the IMS system. According to the present application, when the information communication request is initiated, the protocol signaling can be sent and the IPsec tunnel can be configured by using the key information, so that the protocol signaling can be sent to the ePDG gateway through the IPsec tunnel, and then the communication channel can be established by sending the protocol signaling to the IMS system through the ePDG gateway. After the communication channel is established, the to-be-sent data can be encapsulated in the IPsec tunnel, so that the to-be-sent data can be sent to the ePDG gateway through the communication channel, and finally the information communication can be completed by sending the to-be-sent data to the IMS system through the ePDG gateway. According to the present application, the VOWIFI function can be realized by connecting the IMS system through the ePDG gateway without upgrading the hardware of the terminal. Compared with directly connecting the IMS system to realize the VOWIFI function, the security of information communication can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application or the related art. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other related drawings can also be obtained without creative labor.
[0030] Figure 1 An application environment diagram of an information communication method in an embodiment;
[0031] Figure 2 A flowchart of an information communication method in an embodiment;
[0032] Figure 3 A flowchart of configuring an IPsec tunnel by using key information in an embodiment;
[0033] Figure 4 A flowchart of registering an information communication service in an embodiment;
[0034] Figure 5 a result diagram of the information communication system in one embodiment;
[0035] Figure 6 a component diagram of the VOWiFi service system in one embodiment;
[0036] Figure 7 a structure diagram of the terminal SDK+APP design scheme in one embodiment;
[0037] Figure 8 a structure diagram of the information communication device in one embodiment;
[0038] Figure 9 an internal structure diagram of the computer device in one embodiment. DETAILED DESCRIPTION
[0039] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not used to limit the present application.
[0040] The information communication method provided by the embodiments of the present application can be applied to, for example, Figure 1The application environment shown. Among them, the terminal 101 communicates with the IMS system 103 through the ePDG gateway 102 through the network. Specifically, when receiving an information communication request, the terminal 101 can respond to the request through the application program installed on the terminal 101, send the protocol signaling matched with the request, and configure the IPsec tunnel with the key information associated with the request. Then, the protocol signaling can be encrypted by encapsulating the protocol signaling in the IPsec tunnel and sent to the ePDG gateway 102. The ePDG gateway 102 decrypts the protocol signaling using the key to obtain the protocol signaling and then sends it to the IMS system 103, so that the IMS system 103 can establish a communication channel between the IMS system 103 and the terminal 101 based on the protocol signaling. After the establishment is completed, the terminal 101 can also encrypt the to-be-sent data by encapsulating the to-be-sent data in the IPsec tunnel, and send it to the ePDG gateway 102 through the communication channel. The ePDG gateway 102 can obtain the to-be-sent data again using the key information and send it to the IMS system 103 to complete the communication request response. The terminal 101 can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things device can be a smart speaker, a smart TV, a smart air conditioner, a smart vehicle device, a projection device, etc. The ePDG gateway 102 can be an enhanced packet data gateway, which is a core network element in the LTE / NR network and is mainly used to support VOWIFI function. The IMS system 103 can be used to provide multimedia services on an IP network and can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0041] In one embodiment, as shown in Figure 2 , an information communication method is provided. The method is applied to the terminal 101 in Figure 1 , which is described as follows.
[0042] Step S201, in response to an information communication request, sending protocol signaling matched with the information communication request, and configuring an IPsec tunnel using key information associated with the information communication request.
[0043] The information communication request refers to a request triggered by a user to perform information communication with the IMS system 103, which can be a voice call request, an SMS service request, and the like. The protocol signaling matched with the information communication request can be protocol signaling used in the process of establishing communication. The key information associated with the information communication request refers to key information used in the process of performing information communication. The IPsec tunnel is a communication tunnel established between the terminal 101 and the ePDG gateway 102. Specifically, when the terminal 101 receives the information communication request, the terminal 101 can send corresponding protocol signaling through an application, and then obtain the key information associated with the information communication request, so as to implement configuration of the IPsec tunnel.
[0044] In step S202, the protocol signaling is encapsulated in the IPsec tunnel and sent to the ePDG gateway 102. The ePDG gateway 102 is configured to obtain the protocol signaling based on the key information and send the protocol signaling to the IMS system 103, so that the IMS system 103 establishes a communication channel matched with the information communication request between the IMS system 103 and the terminal 101 based on the protocol signaling.
[0045] The communication channel is a channel used to implement information communication between the terminal 101 and the IMS system 103. Specifically, after the terminal 101 obtains the protocol signaling, the terminal 101 can encapsulate the protocol signaling in the IPsec tunnel. Since the IPsec tunnel is configured by using the key information, the terminal 101 can be regarded as encrypting the protocol signaling by using the key information in the process of encapsulating the protocol signaling. The encrypted protocol signaling is sent to the ePDG gateway 102, so as to implement encrypted transmission. The ePDG gateway 102 can decrypt the encrypted protocol signaling, and then transmit the protocol signaling to the IMS system 103. The IMS system 103 can establish a communication channel between the IMS system 103 and the terminal 101 based on the protocol signaling.
[0046] In step S203, after the communication channel is successfully established, the terminal 101 encapsulates the to-be-sent data corresponding to the information communication request in the IPsec tunnel, and sends the to-be-sent data to the ePDG gateway 102 through the communication channel. The ePDG gateway is configured to obtain the to-be-sent data based on the key information and send the to-be-sent data to the IMS system 103, so as to perform information communication through the IMS system 103.
[0047] The to-be-sent data refers to data that the terminal 101 needs to send to the IMS system 103 for performing an information communication request, for example, voice data or video data when a voice call needs to be performed, or short message data when a short message service needs to be performed. Specifically, after the communication channel is established, the terminal 101 can also encapsulate the to-be-sent data in an IPsec tunnel, and the encapsulation process can also be used to implement encryption of the to-be-sent data, and the to-be-sent data is sent to the ePDG gateway 102 through the communication channel, and the ePDG gateway can decrypt the to-be-sent data based on the key information, and send the to-be-sent data to the IMS system 103 to perform information communication.
[0048] Similarly, if the IMS system 103 needs to feed back information, for example, voice information replied by the opposite party during a voice call, the information needs to be fed back to the terminal 101 through the IMS system 103, and then the IMS system 103 can send the information to the ePDG gateway 102, and the ePDG gateway 102 encapsulates the information in an IPsec tunnel to implement encryption, and sends the information to the terminal 101, and then the terminal 101 decrypts the information through the key information to obtain the feedback information.
[0049] In the information communication method, the terminal 101 sends the protocol signaling matched with the information communication request in response to the information communication request, and configures the IPsec tunnel by using the key information associated with the information communication request; the protocol signaling is encapsulated in the IPsec tunnel and sent to the ePDG gateway 102; the ePDG gateway 102 is configured to acquire the protocol signaling based on the key information and send the protocol signaling to the IMS system 103, so that the IMS system 103 establishes the communication channel matched with the information communication request between the IMS system 103 and the terminal 101 based on the protocol signaling; after the communication channel is successfully established, the to-be-sent data corresponding to the information communication request is encapsulated in the IPsec tunnel, and the to-be-sent data is sent to the ePDG gateway 102 through the communication channel; the ePDG gateway is configured to acquire the to-be-sent data based on the key information and send the to-be-sent data to the IMS system 103, so as to perform information communication through the IMS system 103. According to the present application, when the information communication request is initiated, the protocol signaling can be sent and the IPsec tunnel can be configured by using the key information, so that the protocol signaling can be sent to the ePDG gateway 102 through the IPsec tunnel, and then the communication channel can be established by sending the protocol signaling to the IMS system 103 through the ePDG gateway 102. After the communication channel is established, the to-be-sent data can be encapsulated in the IPsec tunnel, so as to be sent to the ePDG gateway 102 through the communication channel, and finally the ePDG gateway 102 sends the to-be-sent data to the IMS system 103 to complete the response. In this way, the terminal does not need to be upgraded in hardware, and the VOWIFI function can be realized by connecting the IMS system 103 through the ePDG gateway 102. Compared with directly connecting the IMS system 103 to realize the VOWIFI function, the security of information communication can be improved.
[0050] In one embodiment, as shown in FIG. 2, Figure 3 The step S201 can further include:
[0051] In step S301, the SIM card information associated with the information communication request is acquired, and the key information is generated by using the SIM card information. The SIM card information is the SIM card information of the terminal 101 triggering the information communication request.
[0052] In this embodiment, the key information can be generated by using the SIM card information of the terminal 101. For example, the SIM card information can include RES, IK, CK and other information in the SIM card, and the terminal can derive the key information based on the above information, for example, the PSK pre-shared key, so as to realize the generation of the key information.
[0053] In step S302, the key information is sent to the ePDG gateway 102, and in the case that the ePDG gateway 102 returns the confirmation information for the key information, the IPsec tunnel is configured by using the key information.
[0054] The confirmation information is fed back by the ePDG gateway 102 to the terminal 101 to inform the terminal 101 that the key information has been confirmed to be received. After the terminal 101 sends the data to be sent and the IPsec tunnel transmission protocol signaling to the ePDG gateway 102, the ePDG gateway 102 needs to decrypt the data sent, and thus needs to use the key information, which is generated according to the SIM card information of the terminal 101 and cannot be obtained by the ePDG gateway 102. Therefore, the terminal 101 also needs to send the key information to the ePDG gateway 102 when configuring the IPsec tunnel. After the ePDG gateway 102 receives the key information, the ePDG gateway 102 can reply the corresponding confirmation information to the terminal 101. After the terminal 101 receives the confirmation information, the terminal 101 can configure the IPsec tunnel by using the key information.
[0055] In the embodiment, the key information can be generated by the SIM card information of the terminal 101. In this way, the security of the key information can be further improved.
[0056] Further, the information communication request includes a voice call request. Step S101 can further include sending the SIP protocol signaling matched with the voice call request through the pre-configured protocol stack module. Step S103 can further include obtaining the video data to be sent corresponding to the voice call request and / or the voice data to be sent corresponding to the voice call request, and encapsulating the video data to be sent and / or the voice data to be sent in the IPsec tunnel.
[0057] In the embodiment, the information communication request can be a voice call request for implementing a voice call function. In the case of the voice call request, the protocol signaling matched with the information communication request can be the SIP protocol signaling, and the protocol stack module can be a module for coordinating and processing protocols in network communication and ensuring reliable transmission of data in the network. In the embodiment, the terminal 101 can be provided with the protocol stack module. When responding to the voice call request, the terminal 101 can send the SIP protocol signaling through the protocol stack module, so that the IMS system 103 can establish a communication channel with the terminal 101 based on the SIP protocol signaling.
[0058] Similarly, in the scenario of voice call service, the to-be-sent data can include the following two types, to-be-sent video data and to-be-sent voice data. For example, in the video chat service, the data to be sent can be composed of video data and voice data, and in the general call scenario, the to-be-sent data can only include voice data. Specifically, when performing information communication, if the user initiates a voice call request, the terminal 101 can obtain the corresponding to-be-sent video data and to-be-sent voice data, and then encapsulates the video data and the voice data in the IPsec tunnel for encrypted transmission, thereby completing voice communication. In this way, the security of the voice call service can be improved.
[0059] In this embodiment, the information communication method can be applied in the scenario of voice call service. By sending SIP protocol signaling through the protocol stack module, a communication channel matched with the voice call request can be established between the IMS system 103 and the terminal 101, and video data and voice data can also be encapsulated in the IPsec tunnel for encrypted transmission. In this way, the security of the voice call service can be improved.
[0060] In addition, the information communication request can include a short message transmission request, and step S101 can further include sending SIP protocol signaling matched with the short message transmission request through the pre-configured protocol stack module. Step S103 can further include obtaining to-be-sent short message data corresponding to the short message transmission request, and encapsulating the to-be-sent short message data in the IPsec tunnel.
[0061] In this embodiment, the information communication request can also be a short message transmission request for implementing a short message function, and in the case of the short message transmission request, the protocol signaling matched with the information communication request can be SIP protocol signaling, and the protocol stack module can be a module for coordinating and processing protocols in network communication, ensuring reliable transmission of data in the network. In this embodiment, the terminal 101 can also send SIP protocol signaling through the protocol stack module when responding to the short message transmission request, so that the IMS system 103 can establish a communication channel with the terminal 101 based on the SIP protocol signaling.
[0062] In the scenario of short message service, the to-be-sent data can be to-be-sent short message data. Specifically, when performing information communication, if the user initiates a short message transmission request, the terminal 101 can obtain to-be-sent short message data, and then encapsulates the short message data in the IPsec tunnel for encrypted transmission, thereby completing short message transmission communication. In this way, the security of the short message transmission service can be improved.
[0063] In this embodiment, the information communication method can be applied in the scenario of short message transmission service, and by sending SIP protocol signaling in the protocol stack module, a communication channel matched with the short message transmission request can be established between the IMS system 103 and the terminal 101, and the short message data can also be encapsulated in the IPsec tunnel for encrypted transmission, so that the security of the short message transmission service can be improved.
[0064] In one embodiment, as shown in FIG. 1, before step S101, the method can further include: Figure 4
[0065] Step S401, in response to a registration request for an information communication service corresponding to the information communication request, obtaining SIM card information associated with the registration request; the SIM card information is the SIM card information of the terminal 101 triggering the registration request.
[0066] Before using the information communication service corresponding to the information communication request, the terminal 101 needs to register the information communication service, and the registration request is a request initiated by the user for registering the information communication service, and the SIM card information associated with the registration request refers to the SIM card information of the terminal 101 triggering the registration request. Specifically, when the user registers the information communication service corresponding to the information communication request, a registration request can be initiated to the terminal 101, and the terminal 101 can respond to the request to obtain the SIM card information of the terminal 101 as the SIM card information associated with the registration request.
[0067] Step S402, configuring an IPsec tunnel by using the key information associated with the registration request, encapsulating the SIM card information in the IPsec tunnel, and sending to the ePDG gateway 102; the ePDG gateway 102 is configured to obtain the SIM card information based on the key information associated with the registration request, and send to the core network, so that the core network obtains the authentication result of the terminal 101 based on the SIM card information.
[0068] The core network can be a 4G or 5G core network, i.e., an EPC / 5GC network, which connects the ePDG gateway 102 and the IMS system 103. In this embodiment, the terminal 101 needs to pass the authentication of the core network before completing the registration of the information communication service in the IMS system 103, and the key information associated with the registration request is configuration information used for configuring the IPsec tunnel when the terminal 101 completes the registration of the information communication service. Similar to the process of responding to the information communication request, the terminal 101 also needs to configure the IPsec tunnel by using the key information when registering the information communication service, so as to realize the encryption of information transmission.
[0069] Specifically, after obtaining the SIM card information, the terminal 101 can also configure the IPsec tunnel by using the key information associated with the registration request, so as to encapsulate the SIM card information in the IPsec tunnel, to realize encryption of the SIM card information, and send the encrypted SIM card information to the ePDG gateway 102 through the tunnel. Then, the ePDG gateway 102 can decrypt based on the key information, to obtain the SIM card information and send it to the core network, and the core network can authenticate the terminal 101 based on the SIM card information, to obtain the corresponding authentication result.
[0070] In step S403, in the case that the authentication result represents that the authentication is passed, the terminal identifier of the terminal 101 is obtained according to the SIM card information, the terminal identifier is encapsulated in the IPsec tunnel and sent to the ePDG gateway 102; the ePDG gateway 102 is configured to obtain the terminal identifier based on the key information associated with the registration request, and send it to the IMS system 103, so that the IMS system 103 registers the terminal 101 for information communication service based on the terminal identifier.
[0071] The terminal identifier refers to an identifier for identifying the terminal 101, which can be obtained by the SIM card information of the terminal 101. For example, the SIM card information of the terminal 101 can contain IMSI information, and the terminal 101 can derive the IMPI and T-IMPU information based on the IMSI information after the authentication is passed. The IMPI and T-IMPU information can be used as the terminal identifier.
[0072] Then, the terminal 101 can also encapsulate the obtained terminal identifier in the IPsec tunnel to realize encryption of the terminal identifier, and after the terminal identifier is sent to the ePDG gateway 102 through the IPsec tunnel, the ePDG gateway 102 can also decrypt by using the key information associated with the registration request to obtain the terminal identifier, which is sent to the IMS system 103 through the core network, so that the IMS system 103 can register the terminal 101 for information communication service based on the terminal identifier.
[0073] In this embodiment, before the information communication service corresponding to the information communication request is performed, the terminal 101 also needs to register for the information communication service, and in the registration process, the IPsec tunnel can be configured by using the key information, so that when the core network is authenticated, the SIM card information can be encrypted and transmitted, and after the authentication is passed, the terminal identifier can be encapsulated in the IPsec tunnel for encrypted transmission, to realize registration in the IMS system 103. In this way, the security of the information communication service registration can be improved.
[0074] Further, the step S401 can further include: generating the key information associated with the registration request by the SIM card information; sending the key information associated with the registration request to the ePDG gateway 102, and in the case that the ePDG gateway 102 returns the confirmation information for the key information associated with the registration request, configuring the IPsec tunnel by the key information associated with the registration request.
[0075] In the embodiment, the key information associated with the registration request can also be generated by the SIM card information. Specifically, the terminal 101 can derive the PSK key by the RES, IK, CK and other information in the SIM card information, thereby generating the key information associated with the registration request, and then the key information can be sent to the ePDG gateway 102. After the terminal 101 sends the data to be sent and the protocol signaling to the ePDG gateway 102 through the IPsec tunnel transmission protocol, the ePDG gateway 102 can return the corresponding confirmation information to the terminal 101 after receiving the key information. After receiving the confirmation information, the terminal 101 can configure the IPsec tunnel by the key information.
[0076] In the embodiment, the key information associated with the registration request can be generated by the SIM card information of the terminal 101, and in this way, the security of the key information associated with the registration request can be further improved.
[0077] In one embodiment, as shown in FIG. 5, an information communication system is also provided, which includes an information communication service module 501, a protocol stack module 502, and a tunnel processing module 503; wherein: Figure 5 The information communication service module 501 is configured to respond to an information communication request, call the protocol stack module 502 to send the protocol signaling matched with the information communication request, and configure the IPsec tunnel by the key information associated with the information communication request.
[0078] The tunnel processing module 503 is further configured to encapsulate the protocol signaling in the IPsec tunnel and send it to the ePDG gateway; the ePDG gateway is configured to acquire the protocol signaling based on the key information and send it to the IMS system, so that the IMS system establishes the communication channel matched with the information communication request between the IMS system and the terminal based on the protocol signaling.
[0079] The tunnel processing module 503 is further configured to encapsulate the data to be sent corresponding to the information communication request in the IPsec tunnel after the communication channel is successfully established, and send the data to be sent to the ePDG gateway through the communication channel; the ePDG gateway is configured to acquire the data to be sent based on the key information and send it to the IMS system, so as to perform information communication through the IMS system.
[0080]
[0081] In the embodiment, the information communication system can be arranged in the terminal. When the terminal receives an information communication request corresponding to an information communication service, the information communication system can respond to the request through the information communication service module 501, so as to call the protocol stack module 502 to send protocol signaling matched with the information communication request, and configure an IPsec tunnel by using key information associated with the information communication request.
[0082] Then, the tunnel processing module 503 can encapsulate the protocol signaling in the IPsec tunnel, and send the protocol signaling to the ePDG gateway through the IPsec tunnel. The ePDG gateway can obtain the protocol signaling based on the key information, and send the protocol signaling to the IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and the terminal based on the protocol signaling.
[0083] After the communication channel is established, the tunnel processing module 503 can also encapsulate to-be-sent data corresponding to the information communication request in the IPsec tunnel, and send the to-be-sent data to the ePDG gateway through the communication channel. The ePDG gateway can obtain the to-be-sent data based on the key information, and send the to-be-sent data to the IMS system, so that the IMS system can perform information communication.
[0084] In the embodiment, the information communication system can include the information communication service module 501, the protocol stack module 502, and the tunnel processing module 503. When initiating an information communication request, the information communication service module 501 can call the protocol stack module 502 to send protocol signaling, and configure an IPsec tunnel by using key information. Thus, the tunnel processing module 503 can send the protocol signaling to the ePDG gateway through the IPsec tunnel, and then send the protocol signaling to the IMS system through the ePDG gateway to establish a communication channel. After the communication channel is established, the tunnel processing module 503 can also encapsulate to-be-sent data in the IPsec tunnel, so as to send the to-be-sent data to the ePDG gateway through the communication channel, and finally send the to-be-sent data to the IMS system through the ePDG gateway to complete the response. In this way, the terminal does not need to be upgraded in hardware, and the VOWIFI function can be realized by connecting the IMS system through the ePDG gateway. Compared with directly connecting the IMS system to realize the VOWIFI function, the application can improve the security of information communication.
[0085] In one embodiment, the information communication system further includes a SIM card information obtaining module. The information communication service module 501 is further configured to call the SIM card information obtaining module to obtain SIM card information associated with the information communication request, and generate key information by using the SIM card information.
[0086] The SIM card information obtaining module is configured to obtain the SIM card information of the terminal. In addition to the information communication service module 501, the protocol stack module 502, and the tunnel processing module 503, the information communication system can further include the SIM card information obtaining module. After the information communication service module 501 receives the information communication request, the SIM card information obtaining module can be called to obtain the SIM card information associated with the information communication request, i.e., the SIM card information of the terminal triggering the information communication request. Then, the SIM card information can be used to generate the key information. For example, the SIM card information obtaining module can be called to extract the relevant information such as RES, IK, and CK from the SIM card. Then, the key information can be derived from the above information. In this way, the key information can be generated based on the SIM card information of the terminal, and the security of the key information can be further improved.
[0087] In the embodiment, the information communication system can further include the SIM card information obtaining module. The SIM card information obtaining module can be configured to extract the SIM card information, so that the key information can be generated based on the SIM card information. In this way, the security of the key information can be further improved.
[0088] In one embodiment, the information communication service module 501 is further configured to, in response to a registration request for an information communication service corresponding to the information communication request, obtain the SIM card information associated with the registration request, and configure the IPsec tunnel based on the key information associated with the registration request. The SIM card information is the SIM card information of the terminal triggering the registration request.
[0089] The tunnel processing module 503 is further configured to encapsulate the SIM card information in the IPsec tunnel and send the SIM card information to the ePDG gateway. The ePDG gateway is configured to obtain the SIM card information based on the key information associated with the registration request and send the SIM card information to the core network, so that the core network obtains the authentication result of the terminal based on the SIM card information.
[0090] The tunnel processing module 503 is further configured to, in the case that the authentication result indicates that the authentication is passed, obtain the terminal identifier of the terminal based on the SIM card information, encapsulate the terminal identifier in the IPsec tunnel, and send the terminal identifier to the ePDG gateway. The ePDG gateway is configured to obtain the terminal identifier based on the key information associated with the registration request and send the terminal identifier to the IMS system, so that the IMS system registers the terminal for the information communication service based on the terminal identifier.
[0091] In the embodiment, the terminal also needs to register the information communication service before responding to the information communication request. When the user initiates a registration request for the information communication service, the information communication service module 501 in the terminal can respond to the request, obtain the SIM card information of the terminal as the SIM card information associated with the registration request, and configure the IPsec tunnel by using the key information associated with the registration request.
[0092] Then, the tunnel processing module 503 can encapsulate the SIM card information in the IPsec tunnel to encrypt the SIM card information, and send the encrypted SIM card information to the ePDG gateway through the tunnel. Then, the ePDG gateway can decrypt based on the above-mentioned key information to obtain the SIM card information and send it to the core network. The core network authenticates the terminal based on the SIM card information to obtain the corresponding authentication result.
[0093] After the authentication, the terminal can also encapsulate the obtained terminal identifier in the IPsec tunnel to encrypt the terminal identifier. After the terminal identifier is sent to the ePDG gateway 102 through the IPsec tunnel, the ePDG gateway can also decrypt by using the key information associated with the registration request to obtain the terminal identifier, which is sent to the IMS system through the core network, so that the IMS system can register the terminal for the information communication service based on the terminal identifier.
[0094] In the embodiment, before the information communication service corresponding to the information communication request is performed, the terminal also needs to register the information communication service. During the registration process, the information communication service module 501 can configure the IPsec tunnel by using the key information. Therefore, when the core network is authenticated, the tunnel processing module 503 can encrypt and transmit the SIM card information, and after the authentication, the tunnel processing module 503 can encapsulate the terminal identifier in the IPsec tunnel for encrypted transmission to realize the registration in the IMS system. In this way, the security of the information communication service registration can be improved.
[0095] In one embodiment, an APP Over ePDG supporting VOWIFI method is also provided. By designing an APP OVER ePDG SDK in a 5G+ terminal, the APP over ePDG application can access the IMS through the ePDG and EPC / 5GC to realize the VOWIFI function. Only the user needs to install the APP and upgrade the SDK, without the need to replace the modem hardware, thereby reducing the cost of changing the machine, lowering the VOWIFI use threshold, improving the security, improving the use rate and popularity of VOWiFi service, improving the voice coverage range, improving the call quality and user experience, saving network resources and operation cost, and having a wide practical application prospect. The composition of the system can be as followsFigure 6 As shown in the figure, where:
[0096] WIFI part:
[0097] 1) Wireless LAN controller (AC): manages and controls the behavior of multiple access points (APs), coordinates communication between them, ensures network stability and efficiency. Provides centralized management, configuration and monitoring functions for access points. Implements user identity verification, access control and security policy enforcement. Responsible for handling business intelligence, load balancing and traffic control. Supports wireless network roaming, quality assurance and quality of service adjustment;
[0098] 2) Access Point (AP): provides coverage for wireless networks, allowing user devices to access the network through Wi-Fi. Handles communication between terminals and wireless networks, including data transmission, signal reception and transmission. Supports wireless network security mechanisms such as encryption, authentication, etc. Implements roaming functionality in wireless networks to ensure seamless switching between different APs.
[0099] Cellular part:
[0100] 1) EPC / 5GC: 4G, 5G core network, responsible for implementing 4G, 5G terminal user data transmission, call control, mobility management, security management, etc. Provides user access and authentication, user data processing, mobility management and connection management services, respectively connecting 4G, 5G cellular base stations and IMS systems;
[0101] 2) ePDG (evolved Packet Data Gateway): It allows users to access 4G, 5G networks on WiFi networks, i.e. it connects 4G, 5G 4G, 5G core networks - EPC / 5GC, respectively. ePDG is responsible for security and quality control to ensure the security and stability of user data.
[0102] Add new modules on the terminal to support VOWIFI in APP mode:
[0103] 1) APP OVER ePDG: Users can download and install APP over ePDG applications on the terminal from the application store, and with the help of APP OVER ePDG SDK, they can implement APP phone and APP SMS functions in APP over ePDG applications;
[0104] 2) APP OVER ePDG SDK: The terminal does not need to replace or upgrade the MODEM hardware + software, only to upgrade the terminal AP side (application side) SDK, that is, to upgrade the APP OVER ePDG SDK, the APP over ePDG application can call the APP over ePDG SDK function, the terminal APP OVER ePDG accesses to the IMS through the ePDG and EPC / 5GC to realize the VOWIFI function, without the need for users to change the machine, suitable for a large number of existing terminals on the market, and high security.
[0105] Specifically, the terminal SDK + APP design scheme architecture can be as shown in Figure 7 , which can include the following parts:
[0106] 1. Application layer: native phone, native SMS, other native applications, etc., and new APP OVER ePDG application;
[0107] 1.1. The new APP OVER ePDG application includes APP phone (to realize the function of making and receiving phone calls in APP mode), APP SMS (to realize the function of sending and receiving SMS in APP mode), etc.
[0108] 2. Framework layer: native phone service, native SMS service, WIFI data service, other native services, etc., and new APP OVER ePDG SDK (including APP phone service, APP SMS service, IMS / SIP protocol stack, SIM card information acquisition, IKEv2 / IPsec module, and 11 module interfaces (a~k));
[0109] 2.1. APP phone service: provides phone-related services such as making phone calls, answering phone calls, phone call records, phone directories, etc. to the application layer APP phone application;
[0110] 2.2. APP SMS service: provides SMS-related services such as sending SMS, receiving SMS, SMS sending and receiving records, SMS directories, etc. to the application layer APP SMS application;
[0111] 2.3. IMS / SIP protocol stack: implements the IMS and SIP protocol stack, and the APP phone service module calls this module to establish and maintain the VOWiFi call session, and the APP SMS service module calls this module to realize the SMS sending and receiving function based on IMS;
[0112] 2.4, SIM card information acquisition: by adding j interface to SIM card information calling interface to acquire relevant information in SIM card such as IMSI, RES, IK, CK, etc., APP phone service module and APP SMS service module both call this module for core network authentication, phone and SMS information encryption and decryption, IKEv2 / IPsec module calls this module for ePDG authentication and secure communication.
[0113] 2.5, IKEv2 / IPsec: IKEv2 protocol is used for secure communication establishment and key negotiation between terminal and ePDG; IPsec (suite) is used for providing security services at network layer, including data encryption, identity authentication and data integrity protection. IKEv2 needs to be used together with IPsec, when establishing VPN connection, IKEv2 is responsible for secure connection establishment and key negotiation, that is, responsible for negotiating and establishing secure IPsec connection; IPsec is responsible for data encryption, authentication and integrity check, that is, responsible for protecting data security.
[0114] 2.6, a interface: application layer APP phone application calls interface of framework layer APP phone service module;
[0115] 2.7, b interface: framework layer APP phone service module calls interface of framework layer IMS / SIP protocol stack module;
[0116] 2.8, c interface: framework layer APP phone service module calls interface of framework layer SIM card information acquisition module;
[0117] 2.9, d interface: framework layer APP phone service module calls interface of framework layer IKEv2 / IPsec module;
[0118] 2.10, e interface: application layer APP SMS application calls interface of framework layer APP SMS service module;
[0119] 2.11, f interface: framework layer APP SMS service module calls interface of framework layer IMS / SIP protocol stack module;
[0120] 2.12, g interface: framework layer APP SMS service module calls interface of framework layer SIM card information acquisition module;
[0121] 2.13, h interface: framework layer APP SMS service module calls interface of framework layer IKEv2 / IPsec module;
[0122] 2.14, i interface: framework layer IKEv2 / IPsec module calls interface of framework layer SIM card information acquisition module;
[0123] 2.15, j interface: the framework layer SIM card information acquisition module calls the interface of the driving layer SIM card information calling interface module;
[0124] 2.16, k interface: the framework layer IKEv2 / IPsec module calls the interface of the driving layer WIFI communication calling interface module;
[0125] 3, driving layer: cellular communication calling interface, SIM card information calling interface (modified interface), WIFI communication calling interface (modified interface):
[0126] 3.1, SIM card information calling interface (modified interface): an input interface is added, and the permission is opened, which is used as the interface for the framework layer SIM card information acquisition module to call (or acquire) the related information (such as IMSI, RES, IK, CK, etc.) in the SIM card;
[0127] 3.2, WIFI communication calling interface (modified interface): an input interface is added, and the permission is opened, which is used as the interface for the framework layer IKEv2 / IPsec module to output the security connection establishment, key negotiation, and security control information and security data such as encrypted data, identity authentication, and data integrity protection;
[0128] 4, kernel layer: MODEM (4G / 5G) hardware and the MODEM cellular protocol stack (including IMS / SIP) running thereon, which transmits and receives data from the driving layer cellular communication calling interface, in addition, the MODEM (4G / 5G) is connected with and interacts with the SIM; WIFI hardware and the WIFI underlying protocol stack running thereon, which transmits and receives data from the driving layer WIFI communication calling interface.
[0129] The system architecture can be used to implement APP dialing, including the following steps:
[0130] Precondition: the APP phone service module in the APP Over ePDG SDK acquires the related information such as IMSI, RES, IK, CK, etc. in the SIM card through the SIM card information acquisition module, completes the authentication and certification of the APP Over ePDG on the 4G or 5G core network through the IKEv2 / IPsec module encapsulating the IKEv2 message, and then derives the IMPI and T-IMPU from the IMSI to complete the APP Over ePDG application registration to the IMS network.
[0131] Step 1: the user dials a phone through the APP Over ePDG application on the terminal;
[0132] Step 2: the APP Over ePDG application sends a dialing request to the APP phone service;
[0133] Step 3: After receiving the dialing request, the APP phone service calls the IMS / SIP protocol stack module to request call establishment;
[0134] Step 4: After receiving the call request, the IMS / SIP protocol stack starts the call establishment process and sends SIP signaling, etc.
[0135] Step 5: The APP phone service obtains the RES, IK, CK, etc. information in the SIM card through the SIM card information obtaining module to derive the PSK (pre-shared key) used by the IKEv2 / IPsec, that is, the PSK derived from the SIM card information is used to configure the IKEv2 / IPsec;
[0136] Step 6: The IKEv2 / IPsec module encapsulates the SIP signaling data in the IPsec tunnel and performs encrypted transmission of the SIP signaling data from the UE to the ePDG;
[0137] Step 7: After the call session is successfully established, the IKEv2 / IPsec module encapsulates the user call audio or video data in the IPsec tunnel and performs encrypted transmission of the call audio or video data from the UE to the ePDG;
[0138] Step 8: The SIP signaling and audio or video data encapsulated in the IPsec tunnel call the kernel layer WIFI module through the WIFI communication calling interface to transmit to the ePDG, realizing encrypted transmission of the terminal APP to the ePDG and ensuring the security of the call data.
[0139] In this embodiment, VOWIFI is supported by APP Over ePDG mode, the traditional APP access IMS mode is changed, a more convenient experience method and process are provided for users, an APP Over ePDG application is added in a 5G+ terminal, the use threshold of VOWIFI is reduced, the application range of VOWIFI is expanded, an APP Over ePDG SDK is designed, APP phone service, APP short message service, IMS / SIP protocol stack and multiple modules are fused together, technical support is provided for the implementation of VOWIFI function of APP Over ePDG mode, the SDK can cross different mobile phone operating systems or mobile phone platforms, has the advantages of strong adaptability, low coupling degree, easy popularization and the like, an IKEv2 / IPsec module is introduced into the APP Over ePDG SDK for establishing secure communication between APP and ePDG, the security of the system is improved, the interfaces between multiple modules are designed, the SIM card information calling interface and the WIFI communication calling interface are modified, the cooperation and integration between the function modules are realized, the data exchange and communication capacity of the system are enhanced, the user only needs to install the APP and upgrade the SDK, the user does not need to replace the MODEM hardware, the use threshold of VOWIFI and the replacement cost are reduced, the network resource utilization is optimized, the operation cost is reduced, the use rate and the popularization rate of VOWIFI service are improved, and the method for improving the business income space of VOWIFI service is provided.
[0140] It should be understood that, although each step in the flowchart involved in each embodiment as described above is shown in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.
[0141] Based on the same inventive concept, the embodiments of the present application also provide an information communication device for implementing the information communication method described above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, and therefore the specific limitations in one or more information communication device embodiments provided below can refer to the limitations of the information communication method described above, which will not be repeated here.
[0142] In one embodiment, asFigure 8 As shown, an information communication device is provided, comprising: a tunnel configuration module 801, a protocol sending module 802 and a data sending module 803, wherein:
[0143] The tunnel configuration module 801 is configured to, in response to an information communication request, send protocol signaling matched with the information communication request, and configure an IPsec tunnel by using key information associated with the information communication request;
[0144] The protocol sending module 802 is configured to encapsulate the protocol signaling in the IPsec tunnel and send it to an ePDG gateway; the ePDG gateway is configured to obtain the protocol signaling based on the key information and send it to an IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and a terminal based on the protocol signaling;
[0145] The data sending module 803 is configured to, after the communication channel is successfully established, encapsulate to-be-sent data corresponding to the information communication request in the IPsec tunnel, and send the to-be-sent data to the ePDG gateway through the communication channel; the ePDG gateway is configured to obtain the to-be-sent data based on the key information and send it to the IMS system, so that information communication is performed through the IMS system.
[0146] In one embodiment, the tunnel configuration module 801 is further configured to obtain SIM card information associated with the information communication request, and generate the key information by using the SIM card information; the SIM card information is SIM card information of a terminal triggering the information communication request; the key information is sent to the ePDG gateway, and the IPsec tunnel is configured by using the key information in a case where confirmation information returned by the ePDG gateway for the key information is received.
[0147] In one embodiment, the information communication request comprises a voice call request; the tunnel configuration module 801 is further configured to send SIP protocol signaling matched with the voice call request by using a preconfigured protocol stack module; the data sending module 803 is further configured to obtain to-be-sent video data corresponding to the voice call request and / or to-be-sent voice data corresponding to the voice call request; and the to-be-sent video data and / or the to-be-sent voice data are encapsulated in the IPsec tunnel.
[0148] In one embodiment, the information communication request comprises a short message transmission request; the tunnel configuration module 801 is further configured to send SIP protocol signaling matched with the short message transmission request by using a preconfigured protocol stack module; the data sending module 803 is further configured to obtain to-be-sent short message data corresponding to the short message transmission request; and the to-be-sent short message data are encapsulated in the IPsec tunnel.
[0149] In one embodiment, the information communication apparatus further comprises a service registration module configured to: in response to a registration request for an information communication service corresponding to the information communication request, acquire SIM card information associated with the registration request; the SIM card information is SIM card information of a terminal triggering the registration request; configure an IPsec tunnel by using key information associated with the registration request, encapsulate the SIM card information in the IPsec tunnel, and send the SIM card information to an ePDG gateway; the ePDG gateway is configured to acquire the SIM card information based on the key information associated with the registration request, and send the SIM card information to a core network, so that the core network obtains an authentication result of the terminal based on the SIM card information; in a case where the authentication result represents that the authentication passes, acquire a terminal identifier of the terminal according to the SIM card information, encapsulate the terminal identifier in the IPsec tunnel, and send the terminal identifier to the ePDG gateway; the ePDG gateway is configured to acquire the terminal identifier based on the key information associated with the registration request, and send the terminal identifier to an IMS system, so that the IMS system registers the terminal for the information communication service based on the terminal identifier.
[0150] In one embodiment, the service registration module is further configured to: generate the key information associated with the registration request by using the SIM card information; send the key information associated with the registration request to the ePDG gateway, and in a case where the ePDG gateway returns confirmation information for the key information associated with the registration request, configure the IPsec tunnel by using the key information associated with the registration request.
[0151] The above-mentioned modules in the information communication apparatus can be all or partially implemented by software, hardware, or a combination thereof. The above-mentioned modules can be embedded in or independent of a processor in a computer device in a hardware form, or stored in a memory in a computer device in a software form, so as to be called and executed by a processor to perform operations corresponding to the above-mentioned modules.
[0152] In one embodiment, a computer device is provided, which can be a terminal, and an internal structure diagram of the computer device can be as shown in Figure 9The computer device shown in the figure includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be realized through WIFI, mobile cellular network, near field communication (NFC) or other technologies. The computer program is executed by the processor to realize an information communication method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad or mouse, etc.
[0153] Those skilled in the art can understand that, Figure 9 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0154] In one embodiment, a computer device is also provided, including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to realize the steps in each of the above method embodiments.
[0155] In one embodiment, a computer readable storage medium is provided, storing a computer program, and the computer program is executed by a processor to realize the steps in each of the above method embodiments.
[0156] In one embodiment, a computer program product is provided, including a computer program, and the computer program is executed by a processor to realize the steps in each of the above method embodiments.
[0157] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.
[0158] It can be understood by those skilled in the art that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing related hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments of each method. In the embodiments provided in the present application, any reference to memory, database or other medium can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0159] Any technical features in the above embodiments can be combined, and for the sake of brevity, not all possible combinations are described above, however, any combination of these technical features is deemed to be within the scope of the present application.
[0160] The above embodiments only express several implementation manners of the present application, and the description is relatively specific and detailed, but it should not be understood as a limitation on the patent scope of the present application. It should be pointed out that, for ordinary skilled persons in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. An information communication method characterized by comprising: The method comprises: in response to an information communication request, sending protocol signaling matched with the information communication request, and configuring an IPsec tunnel by using key information associated with the information communication request; encapsulating the protocol signaling in the IPsec tunnel by using the key information, and sending to an ePDG gateway; the ePDG gateway is configured to acquire the protocol signaling based on the key information, and send to an IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and a terminal based on the protocol signaling; after the communication channel is successfully established, encapsulating to-be-sent data corresponding to the information communication request in the IPsec tunnel by using the key information, and sending the to-be-sent data to the ePDG gateway through the communication channel; the ePDG gateway is configured to acquire the to-be-sent data based on the key information, and send to the IMS system, so as to perform information communication through the IMS system; the configuration of the IPsec tunnel by using the key information associated with the information communication request comprises: acquiring SIM card information associated with the information communication request, and generating the key information by using the SIM card information; the SIM card information is the SIM card information of a terminal triggering the information communication request; sending the key information to the ePDG gateway, and configuring the IPsec tunnel by using the key information in the case that confirmation information returned by the ePDG gateway for the key information is received.
2. The method of claim 1, wherein, The information communication request comprises a voice call request; the sending of the protocol signaling matched with the information communication request comprises: sending SIP protocol signaling matched with the voice call request by using a pre-configured protocol stack module; the encapsulation of to-be-sent data corresponding to the information communication request in the IPsec tunnel comprises: acquiring to-be-sent video data corresponding to the voice call request, and / or to-be-sent voice data corresponding to the voice call request; encapsulating the to-be-sent video data, and / or the to-be-sent voice data in the IPsec tunnel.
3. The method of claim 1, wherein, The information communication request comprises a short message transmission request; the sending of the protocol signaling matched with the information communication request comprises: sending SIP protocol signaling matched with the short message transmission request by using a pre-configured protocol stack module; the encapsulation of to-be-sent data corresponding to the information communication request in the IPsec tunnel comprises: acquiring to-be-sent short message data corresponding to the short message transmission request; encapsulating the to-be-sent short message data in the IPsec tunnel.
4. The method of claim 1, wherein, Before the sending of the protocol signaling matched with the information communication request in response to the information communication request, the method further comprises: in response to a registration request for an information communication service corresponding to the information communication request, acquiring SIM card information associated with the registration request; the SIM card information is the SIM card information of a terminal triggering the registration request; The IPsec tunnel is configured by using the key information associated with the registration request, the SIM card information is encapsulated in the IPsec tunnel, and is sent to an ePDG gateway; the ePDG gateway is used to acquire the SIM card information based on the key information associated with the registration request, and sends the SIM card information to a core network, so that the core network obtains an authentication result of the terminal based on the SIM card information; In a case where the authentication result represents that the authentication passes, a terminal identifier of the terminal is acquired according to the SIM card information, the terminal identifier is encapsulated in the IPsec tunnel, and is sent to the ePDG gateway; the ePDG gateway is used to acquire the terminal identifier based on the key information associated with the registration request, and sends the terminal identifier to an IMS system, so that the IMS system registers the terminal for an information communication service based on the terminal identifier.
5. The method of claim 4, wherein, The IPsec tunnel is configured by using the key information associated with the registration request, the SIM card information is encapsulated in the IPsec tunnel, and is sent to an ePDG gateway; the ePDG gateway is used to acquire the SIM card information based on the key information associated with the registration request, and sends the SIM card information to a core network, so that the core network obtains an authentication result of the terminal based on the SIM card information; The key information associated with the registration request is generated by using the SIM card information; The key information associated with the registration request is sent to the ePDG gateway, and in a case where the ePDG gateway returns confirmation information for the key information associated with the registration request, the IPsec tunnel is configured by using the key information associated with the registration request.
6. An information communication system, characterized by comprising: The system comprises an information communication service module, a protocol stack module, and a tunnel processing module; wherein: The information communication service module is configured to, in response to an information communication request, call the protocol stack module to send a protocol signaling matched with the information communication request, and configure an IPsec tunnel by using key information associated with the information communication request; The tunnel processing module is further configured to encapsulate the protocol signaling in the IPsec tunnel by using the key information, and send the protocol signaling to an ePDG gateway; the ePDG gateway is configured to acquire the protocol signaling based on the key information, and send the protocol signaling to an IMS system, so that the IMS system establishes a communication channel matched with the information communication request between the IMS system and the terminal based on the protocol signaling; The tunnel processing module is further configured to, after the communication channel is successfully established, encapsulate to-be-sent data corresponding to the information communication request in the IPsec tunnel by using the key information, and send the to-be-sent data to the ePDG gateway through the communication channel; the ePDG gateway is configured to acquire the to-be-sent data based on the key information, and send the to-be-sent data to the IMS system, so that information communication is performed through the IMS system; The system further comprises a SIM card information acquisition module; the information communication service module is further configured to call the SIM card information acquisition module to acquire SIM card information associated with the information communication request, and generate the key information by using the SIM card information; the key information is sent to the ePDG gateway, and in a case where the ePDG gateway returns confirmation information for the key information, the IPsec tunnel is configured by using the key information.
7. The system of claim 6, wherein the information communication service module is further configured to, in response to a registration request for an information communication service corresponding to the information communication request, obtain SIM card information associated with the registration request and configure an IPsec tunnel using key information associated with the registration request; the SIM card information is SIM card information of a terminal triggering the registration request; the tunnel processing module is further configured to encapsulate the SIM card information in the IPsec tunnel and send the SIM card information to an ePDG gateway; the ePDG gateway is configured to obtain the SIM card information based on the key information associated with the registration request, send the SIM card information to a core network, and cause the core network to obtain an authentication result of the terminal based on the SIM card information; the tunnel processing module is further configured to, in a case where the authentication result indicates that the authentication is passed, obtain a terminal identifier of the terminal based on the SIM card information, encapsulate the terminal identifier in the IPsec tunnel, and send the terminal identifier to the ePDG gateway; the ePDG gateway is configured to obtain the terminal identifier based on the key information associated with the registration request, send the terminal identifier to an IMS system, and cause the IMS system to register the terminal for the information communication service based on the terminal identifier. The apparatus comprises:
8. An information communication apparatus characterized by comprising: a tunnel configuration module configured to, in response to an information communication request, send protocol signaling matched with the information communication request and configure an IPsec tunnel using key information associated with the information communication request; a protocol sending module configured to encapsulate the protocol signaling in the IPsec tunnel through the key information and send the protocol signaling to an ePDG gateway; the ePDG gateway is configured to obtain the protocol signaling based on the key information, send the protocol signaling to an IMS system, and cause the IMS system to establish a communication channel matched with the information communication request between the IMS system and a terminal based on the protocol signaling; a data sending module configured to, after the communication channel is successfully established, encapsulate to-be-sent data corresponding to the information communication request in the IPsec tunnel through the key information, send the to-be-sent data to the ePDG gateway through the communication channel, and cause the ePDG gateway to send the to-be-sent data to the IMS system based on the key information to perform information communication through the IMS system; the tunnel configuration module is further configured to obtain SIM card information associated with the information communication request and generate the key information through the SIM card information; the SIM card information is SIM card information of a terminal triggering the information communication request; the key information is sent to the ePDG gateway, and in a case where confirmation information returned by the ePDG gateway for the key information is received, the IPsec tunnel is configured using the key information. The processor, when executing the computer program, implements the steps of the method of any one of claims 1 to 5. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The computer program, when executed by the processor, implements the steps of the method of any one of claims 1 to 5.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, 11. A computer program product comprising a computer program, characterized in that, The computer program, which is executed by a processor, implements the steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
VoWiFi business achieving method, system and AAA server
CN106686589A
Operator ePDG (evolved Packet Data Gateway) access system and method for implementing mobile communication
CN107371157A