Terminal visit management method and system, electronic device and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-28
- Publication Date
- 2026-08-11
AI Technical Summary
这种方式在面对客户关系层级复杂、互访需求动态变化的场景时,容易出现管理复杂的问题,还容易出现DNN下地址池内终端间互访无法隔离的问题,从而出现终端交互的安全性问题
[0037] The terminal inter-access management method, system, electronic device, and storage medium proposed in this application obtain the inter-access configuration and encoding set of address segments in a user address pool. The encoding set includes multiple unassigned tag codes. Based on the inter-access configuration of the address segments, inter-access tags and inter-access address segments are determined. Tag codes conforming to the meaning of the inter-access tags are extracted from the encoding set according to the inter-access tags of the address segments, and these tag codes are assigned to the address segments and their inter-access address segments. Then, the address segments of the user address pool and the tag codes of each address segment are configured on the service network elements, enabling the service network elements to route and forward terminal data packets according to the inter-access rules of the tag codes. This application controls terminal inter-access within and between address segments by configuring inter-access tags for address segments in the address pool, achieving address inter-access management configuration within the address pool, effectively isolating complex-level terminals, and improving the security of inter-terminal access.
Smart Images

Figure CN119316394B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a terminal inter-access management method, system, electronic device, and storage medium. Background Technology
[0002] With the widespread adoption of 5G technology, enterprise customers in customized network scenarios have a large number of terminal devices accessing the network, creating extensive inter-terminal communication needs. Simultaneously, these customers require providing inter-terminal communication services to secondary customers. Once the core network terminal communication function is enabled, terminals can achieve point-to-point communication through the core network gateway. However, managing terminal communication requires configuring predefined rules between terminals or configuring access policies on the terminals themselves. This approach can easily lead to management complexity issues when dealing with scenarios involving complex customer relationship hierarchies and dynamically changing communication needs. Furthermore, it can result in the inability to isolate inter-terminal communication within the address pool under the DNN, leading to security issues in terminal interaction. Summary of the Invention
[0003] The main objective of this application is to propose a terminal inter-access management method, system, electronic device, and storage medium, which aims to simplify the terminal inter-access configuration management method and improve the security of inter-terminal access.
[0004] To achieve the above objectives, one aspect of this application proposes a terminal inter-access management method, comprising the following steps:
[0005] Obtain the mutual access configuration and encoding set of address segments in the user address pool, wherein the encoding set includes multiple unassigned tag encodings;
[0006] The mutual access label and mutual access address range of the address range are determined based on the mutual access configuration of the address range;
[0007] Based on the mutual access tags of the address range, extract the tag codes that match the meaning of the mutual access tags from the code set, and assign the tag codes to the address range and the mutual access address range of the address range;
[0008] The address ranges of the user address pool and the tag codes of each address range are configured on the service network elements so that the service network elements can route and forward the terminal's data packets according to the mutual access rules of the tag codes.
[0009] In some embodiments, the mutual access configuration in the user address pool is obtained through the following steps:
[0010] The network configuration is obtained through the network management platform, wherein the network configuration includes multiple networks, and each network is defined by at least one address range from the user address pool;
[0011] Display the network configuration on the customer relationship management platform to obtain the mutual access configuration for each address range.
[0012] In some embodiments, the encoding set is updated through the following steps:
[0013] Determine the encoding configuration status of each address segment, wherein the encoding configuration status includes encoding allocation, encoding change, and encoding recycling;
[0014] When the encoding configuration status is encoding allocation, the tag encoding allocated to the address segment is deleted from the encoding set;
[0015] When the encoding configuration status is "encoding change", the newly assigned tag code to the address segment is deleted from the encoding set, and the tag code of the address segment before the change is written into the encoding set;
[0016] When the encoding configuration status is encoding recycling, the current tag encoding of the address segment is written into the encoding set.
[0017] In some embodiments, the step of extracting tag codes that conform to the meaning of the mutual access tags from the code set based on the mutual access tags of the address segments, and allocating the tag codes to the address segments and the mutual access address segments of the address segments, includes the following steps:
[0018] The corresponding encoding range is obtained by querying the encoding label mapping table based on the mutual access label of the address range. The encoding label mapping table is used to record the mapping relationship between the encoding range and the mutual access label.
[0019] Extract any tag code located within the encoding interval from the encoding set, and assign the extracted tag code to the address segment and the mutual access address segment of the address segment.
[0020] In some embodiments, the mutual access label includes intra-segment and inter-segment mutual access labels, inter-segment mutual access labels, and address segment mutual access disable labels.
[0021] In some embodiments, the service network element routes and forwards data packets through the following steps:
[0022] Receive data packets from the terminal;
[0023] The corresponding address range and the tag code of the address range are determined based on the address information carried in the data packet;
[0024] The corresponding mutual access tag is determined by querying the coded tag mapping table based on the tag encoding.
[0025] The corresponding mutual access rules are determined based on the mutual access labels, and the data packets are routed and forwarded according to the mutual access rules.
[0026] In some embodiments, determining the corresponding mutual access rules based on the mutual access labels and routing and forwarding the data packets according to the mutual access rules includes the following steps:
[0027] When the mutual access label of the address segment is an intra-address segment mutual access label or an inter-address segment mutual access label, the first mutual access rule is used to route and forward the data packet. The first mutual access rule is to find the mutual access address segment with the same label code as the address segment, determine the intra-address segment and the mutual access address segment as the allowed forwarding range of the data packet, and route and forward the data packet according to the allowed forwarding range.
[0028] When the inter-address segment's inter-address segment label is an inter-address segment inter-inter-interface label, the second inter-interface rule is used to route and forward the data packet. The second inter-interface rule is to find the inter-interface address segment with the same label code as the address segment, determine the inter-interface address segment as the allowed forwarding range of the data packet, and route and forward the data packet according to the allowed forwarding range.
[0029] If the address segment inter-access label is the address segment inter-access closed label, then the data packet is discarded.
[0030] To achieve the above objectives, another aspect of this application proposes a terminal inter-access management system, comprising:
[0031] The first module is used to obtain the mutual access configuration and encoding set of address segments in the user address pool, wherein the encoding set includes multiple unassigned tag encodings;
[0032] The second module is used to determine the mutual access label and mutual access address range of the address range based on the mutual access configuration of the address range;
[0033] The third module is used to extract tag codes that conform to the meaning of the mutual access tags from the code set according to the mutual access tags of the address segments, and to allocate the tag codes to the address segments and the mutual access address segments of the address segments;
[0034] The fourth module is used to configure the address ranges of the user address pool and the tag codes of each address range onto the service network element, so that the service network element can route and forward the terminal's data packets according to the mutual access rules of the tag codes.
[0035] To achieve the above objectives, another aspect of the present application provides an electronic device, which includes a memory, a processor, a program stored in the memory and executable on the processor, and a data bus for enabling communication between the processor and the memory. When the program is executed by the processor, it implements the method described in the above embodiments.
[0036] To achieve the above objectives, another aspect of the embodiments of this application proposes a storage medium, which is a computer-readable storage medium for computer-readable storage. The storage medium stores one or more programs that can be executed by one or more processors to implement the methods described in the above embodiments.
[0037] The terminal inter-access management method, system, electronic device, and storage medium proposed in this application obtain the inter-access configuration and encoding set of address segments in a user address pool. The encoding set includes multiple unassigned tag codes. Based on the inter-access configuration of the address segments, inter-access tags and inter-access address segments are determined. Tag codes conforming to the meaning of the inter-access tags are extracted from the encoding set according to the inter-access tags of the address segments, and these tag codes are assigned to the address segments and their inter-access address segments. Then, the address segments of the user address pool and the tag codes of each address segment are configured on the service network elements, enabling the service network elements to route and forward terminal data packets according to the inter-access rules of the tag codes. This application controls terminal inter-access within and between address segments by configuring inter-access tags for address segments in the address pool, achieving address inter-access management configuration within the address pool, effectively isolating complex-level terminals, and improving the security of inter-terminal access. Attached Figure Description
[0038] Figure 1 This is a flowchart of the terminal access management method provided in the embodiments of this application;
[0039] Figure 2 yes Figure 1 Flowchart of the mutual access configuration acquisition method in step S101;
[0040] Figure 3 yes Figure 1 Flowchart of the set encoding update method in step S101;
[0041] Figure 4 yes Figure 1 The flowchart of step S103 in the process;
[0042] Figure 5 yes Figure 1 The flowchart of step S104 in the process;
[0043] Figure 6This is a schematic diagram of the terminal access management system provided in the embodiments of this application;
[0044] Figure 7 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application;
[0045] Figure 8 This is a schematic diagram illustrating the overall implementation process of the terminal access management method provided in this application embodiment;
[0046] Figure 9 This is a schematic diagram of the tag encoding lifecycle provided in the embodiments of this application;
[0047] Figure 10 This is a schematic diagram of the service gateway routing and forwarding control process provided in the embodiments of this application. Detailed Implementation
[0048] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0049] It should be noted that although the system is divided into functional modules and the flowchart shows a logical order, in some cases, the steps shown or described may be executed in a different order than the module division in the system or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0050] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0051] First, let's analyze some of the terms used in this application:
[0052] 5G (5th Generation Mobile Communication Technology): The full name is the fifth generation of mobile communication technology, which is the latest generation of cellular mobile communication technology.
[0053] CRM (Customer Relationship Management) is a customer-centric enterprise management software that encompasses all the strategies, tools, and technologies an organization uses to improve customer development and customer relationships.
[0054] CMP (Connectivity Management Platform) is an important application specifically designed for monitoring, analyzing, configuring, and modifying cellular Internet of Things (IoT) and machine-to-machine (M2M) deployments. The CMP platform plays a crucial role in the IoT ecosystem, helping enterprises effectively manage their IoT devices and connections, reduce operating costs, and improve operational efficiency.
[0055] OSS (Operational Support System): The operator's operation support system is an integrated support system for telecommunications operators that enables information resource sharing.
[0056] DNN (Data Network Name): Equivalent to APN (Access Point Name) in 4G networks, it plays an important role in 5G networks, used to identify an external data network.
[0057] This application provides a terminal inter-access management method, system, electronic device, and storage medium, which aims to simplify the terminal inter-access configuration management method and improve the security of inter-terminal access.
[0058] The terminal access management method, system, electronic device and storage medium provided in the embodiments of this application are specifically described through the following embodiments. First, the terminal access management method in the embodiments of this application is described.
[0059] The terminal access management method provided in this application relates to the field of communication technology. This method can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the terminal access management method, but is not limited to the above forms.
[0060] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0061] According to some embodiments of this application, the terminal inter-access management method of this application can be implemented based on a 5G core network, a CRM system, a 5G connection management platform, and a network management platform. The CRM system, 5G connection management platform, and network management platform assign unique inter-access labels to address segments. Combined with the configuration features supported by the upgraded UPF (User Plane Function) network elements in the core network, an address segment inter-access label function is added to achieve address inter-access control. The CRM system and network management platform are responsible for the allocation, updating, and querying of address segment inter-access labels, ensuring the uniqueness of the inter-access labels across different user address pools. The 5G gateway is responsible for routing and forwarding based on the address inter-access labels, enabling inter-terminal access. Furthermore, the terminal inter-access management method of this application also has a mechanism for mapping and updating the relationship between customer levels and address inter-access configurations, improving the security of internal terminal communication within the enterprise.
[0062] Figure 1 This is an optional flowchart of the terminal access management method provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S101 to S104.
[0063] Step S101: Obtain the mutual access configuration and encoding set of address segments in the user address pool, wherein the encoding set includes multiple unassigned tag encodings;
[0064] Step S102: Determine the mutual access label and mutual access address range based on the mutual access configuration of the address range;
[0065] Step S103: Extract tag codes that match the meaning of mutual access tags from the code set according to the mutual access tags of the address segments, and assign the tag codes to the address segments and the mutual access address segments of the address segments;
[0066] Step S104: Configure the address ranges of the user address pool and the label codes of each address range on the service network element so that the service network element can route and forward the terminal's data packets according to the mutual access rules of the label codes.
[0067] In step S101 of some embodiments, in the field of customer-customized DNN, address pools can be customized for customers. Each user address pool includes address segments allocated to customers. Customers can assign IP addresses to their IoT terminals based on the allocated address segments. In practical applications, customers' IoT devices need to enable terminal inter-access functionality. This embodiment can provide a terminal inter-access management system, offering an inter-access configuration page to users. Users can input the inter-access configuration of address segments in their address pool through the inter-access configuration page. The inter-access configuration defines which address segments can access each other within a segment, which address segments can access each other between segments, and which address segments are prohibited from accessing each other. The encoding set in this embodiment includes multiple preset tag codes, and none of the tag codes in the stored encoding set have been assigned to any non-inter-access address segment.
[0068] Please see Figure 2 In some embodiments, the mutual access configuration in the user address pool in step S101 can be obtained through, but is not limited to, steps S201 to S202:
[0069] Step S201: Obtain network configuration through the network management platform. The network configuration includes multiple networks, and each network is defined by at least one address range from the user address pool.
[0070] Step S202: Display the network configuration on the customer relationship management platform to obtain the mutual access configuration for each address range.
[0071] In this embodiment, the network management platform relies on a customized network and connects to public capability platforms such as IoT CRM, CMP, and AEP. It possesses capabilities such as multi-regional and multi-channel business acceptance, visualized network orchestration, and hierarchical management, providing customers with a one-stop self-service platform. The network management platform enables customer-level network orchestration capabilities. When customers have network isolation or multi-level network requirements, the platform can segment address pools according to network needs, and the mutual access attributes of address segments within the address pool correspond to the network architecture. When customer business expansion requires adding new address segments, these segments are added within the corresponding subnets, and devices that do not require subnetting inherit all global network attributes. For example, please refer to... Figure 8 The network management platform can configure the address ranges of each network. For example, a customer's network includes network-1 formed by address range-1, network-2 formed by address range-2 and address range-3, network-3 formed by address range-4, and secondary customer network-1 formed by address range-n.
[0072] In this embodiment, the Customer Relationship Management platform, also known as the CRM system, serves as a customer business entry system, responsible for handling customized DNN (Dedicated Network Provider) transactions. The customized DNN provides customers with granular business isolation capabilities, offering customization options such as address pools, access methods, and access policies. When handling DNN address pool transactions, address segment inter-segment inter-access label codes (IDs) can be assigned based on the inter-access configuration entered by the user on the platform. These label codes are automatically assigned by the system, and each user's address pool has a unique label code. The CRM platform can display the network configuration so that users can refer to it to configure inter-access, configuring address segments within the same network for inter-segment inter-access. For example, the address segment label codes assigned according to the inter-access configuration in the CRM system's inter-access label management module are as follows: Figure 8 As shown, label code 10000 for address segment-1 indicates intra-segment access; label codes 10001 for address segments-2 and-3 indicate both intra-segment and inter-segment access; label codes 20000 for address segments-4 and-5 indicate inter-segment access only; the label code for address segment-6 is empty, indicating that the client has not configured this address segment, and this address segment can inherit the global access attribute; label code 30000 for address segment-n indicates that address segment access is disabled. The meanings of the access labels represented by the above label codes are only illustrative, and the specific meanings can be determined by the mapping relationship between label codes and access labels in the system.
[0073] Furthermore, please continue to refer to Figure 8The OSS side maintains and updates the SMF / UPF information list corresponding to customer business services nationwide, ensuring the accuracy of the nationwide SMF / UPF information. The OSS sends DNN activation commands to the SMF / UPF and simultaneously configures the DNN, address pool, address range, and mutual access label encoding onto the service network element. The 5G CMP connection management platform is a management platform providing IoT customers with machine-to-machine (MTM) connectivity services. Based on five capabilities—business operation, application integration, value-added services, security protection, and international business—it helps customers quickly customize and operate their own services and manage the entire lifecycle of the SIM card. The CMP platform provides network management platform connection service management capabilities through open APIs, rule engines, and service orchestration. The UPF (User Plane Function) network element in the 5G core network is an important component of the 5G core network (5GC) system architecture, primarily responsible for routing and forwarding user plane data packets. Address pool configuration is a crucial aspect of the 5G network. The address pool section involves configuring the address pool and allocating IP addresses for User Equipment (UE). Address pool configuration includes address pool definition, address allocation method settings, SMF or UPF address pool information configuration, and DNN mapping. Once the DNN terminal inter-access function is enabled, all terminals within a DNN or terminals between DNNs can access each other. In this embodiment, the method adds core network label encoding configuration to the address segment configuration. After a terminal goes online, addresses are allocated according to the address pool address allocation method (static allocation or dynamic allocation). Based on the label encoding of the address segment where the terminal's allocated address is located, terminal data packets are routed and forwarded according to the corresponding label encoding strategy. Furthermore, the address inter-access label management module assigns generated labels to address segments and updates database records for subsequent management and querying. The CRM system distributes customer-customized network information and address labels to the 5G connection management platform and synchronizes them with the network management platform. As the inter-access address segments and label relationships change, the CMP platform monitors and updates the inter-access label information in real time.
[0074] Please see Figure 3 In some embodiments, the encoding set in step S101 can be updated through, but is not limited to, steps S301 to S304:
[0075] Step S301: Determine the encoding configuration status of each address segment, wherein the encoding configuration status includes encoding allocation, encoding change and encoding recycling;
[0076] Step S302: When the encoding configuration status is encoding allocation, the tag encoding allocated to the address segment is deleted from the encoding set;
[0077] Step S303: When the encoding configuration status is encoding change, the tag encoding newly assigned to the address segment is deleted from the encoding set, and the tag encoding before the address segment change is written into the encoding set;
[0078] Step S304: When the encoding configuration status is encoding recycling, the current tag encoding of the address segment is written into the encoding set.
[0079] In some embodiments, the mutual access label management module in the CRM system is responsible for the generation, allocation, recycling, and modification of label codes for address ranges. The lifecycle of a label code is as follows: Figure 9 As shown, the lifecycle of a tag code includes generation, distribution, configuration, use, recycling, and modification. Correspondingly, for an address segment, its code configuration status includes code allocation, code modification, and code recycling. Code allocation refers to the process of assigning a tag code from the code set to the address segment. Code modification refers to the process of modifying the tag codes already allocated to the address segment. Code recycling refers to the process of reclaiming the tag codes already allocated to the address segment without needing to configure the inter-access attributes of the address segment. Code set updates occur under different code configuration statuses. When an address segment is undergoing code allocation, the tag codes allocated to that address segment need to be deleted from the code set to ensure that the code set stores unallocated tag codes. When an address segment is undergoing code modification, the newly allocated tag codes to that address segment are deleted from the code set to ensure that the code set stores unallocated tag codes, and the tag codes before the address segment change are written back to the code set, realizing the recycling of old tag codes. When an address segment is undergoing code recycling, the current tag codes of that address segment are written back to the code set, realizing the recycling of tag codes.
[0080] In step S102 of some embodiments, when a user sets the mutual access configuration of address segments in the user address pool through the interactive interface, they can set a mutual access label for each address segment. The mutual access label can be one of the following: intra-segment and inter-segment mutual access label, inter-segment mutual access label, or address segment mutual access disable label. Further, for address segments without a set mutual access label, the system can default to using a global mutual access attribute, meaning that data packets from this address segment will be routed and forwarded using preset global routing rules in subsequent service network elements. For address segments using intra-segment and inter-segment mutual access labels, the user can write their mutual access address segments to enable inter-segment mutual access between the address segment and the mutual access address segments. If the user does not write a mutual access address segment for the address segment (equivalent to an empty mutual access address segment), the system considers the address segment to only have intra-segment mutual access. For address segments using inter-segment mutual access labels, the user can write their mutual access address segments to enable inter-segment mutual access between the address segment and the mutual access address segments.
[0081] In step S103 of some embodiments, by using the mapping relationship between tag codes and mutual access tag meanings stored in the system, tag codes that match the mutual access tag of the address segment can be extracted from the code set, and the tag code is assigned to the address segment. If the address segment has a mutual access address segment, the tag code is also assigned to the mutual access address segment. For a user address pool, the address segment and the mutual access address segment are the same, which facilitates the subsequent service gateway to realize inter-segment mutual access between the address segment and its mutual access address segment based on the same tag code.
[0082] Please see Figure 4 In some embodiments, step S103 may include, but is not limited to, steps S401 to S403:
[0083] Step S401: Query the encoding label mapping table according to the mutual access label of the address segment to obtain the corresponding encoding range. The encoding label mapping table is used to record the mapping relationship between the encoding range and the mutual access label.
[0084] Step S402: Extract any tag code located within the encoding interval from the encoding set, and assign the extracted tag code to the address segment and the mutual access address segment of the address segment.
[0085] In this embodiment, the CRM system can perform tag coding planning and generate a coding tag mapping table. The tag coding planning corresponds to the mutual access tag attributes. For example, the coding range of 10000-19999 is the mutual access tag within and between address ranges. After the terminal accesses the network, it performs mutual access in the service network element (such as the core network) according to the mutual access tag corresponding to the coding range. For example, the coding tag mapping table is shown in Table 1.
[0086]
[0087] For example, if the mutual access label of the address segment indicates mutual access between address segments, the corresponding encoding range is 20000-29999. Any label code located within the encoding range of 20000-29999 is extracted from the encoding set, and the extracted label code is assigned to the address segment and the mutual access address segment of the address segment, so that the label code of the address segment can accurately represent the mutual access label, and the uniqueness of the label code in other address pools of the entire network is guaranteed.
[0088] In another example, if the mutual access label of the address segment is closed, the corresponding encoding range is 30000-39999. Extract any tag code located within the encoding range of 30000-39999 from the encoding set, and assign the extracted tag code to the address segment. Since there is no mutual access address segment in this address segment, the operation of assigning the extracted tag code to the mutual access address segment of the address segment can be considered invalid.
[0089] In another example, for address ranges without mutual access labels, there is no need to assign label encoding to these address ranges. In the subsequent service network element routing process, for address ranges with empty label encoding (Null), they inherit the global attributes by default and adopt the globally set mutual access forwarding strategy.
[0090] In step S104 of some embodiments, the address ranges of the user address pool and the label codes of each address range are configured on the service network element, so that the service network element routes and forwards the terminal's data packets according to the mutual access rules of the label codes. The service gateway is also configured with label codes and mutual access label mapping tables and mutual access rules for different mutual access labels. The service network element can determine the mutual access rule that the data packet needs to use by querying the mapping table, and thus route and forward or drop the data packet according to the corresponding rule, thereby realizing mutual access control.
[0091] Please see Figure 5 In some embodiments, the service network element in step S104 can route and forward data packets through steps S501 to S504, but is not limited to:
[0092] Step S501: Receive data packets from the terminal;
[0093] Step S502: Determine the corresponding address segment and the tag encoding of the address segment based on the address information carried by the data packet;
[0094] Step S503: Determine the corresponding mutual access label by querying the coded label mapping table according to the label code;
[0095] Step S504: Determine the corresponding mutual access rules based on the mutual access labels, and route and forward the data packets according to the mutual access rules.
[0096] In this embodiment, after the service gateway is configured, during the actual routing process, the service network element receives data packets from various terminals. The data packets carry source IP addresses and destination IP addresses. Based on the carried IP addresses, the corresponding address range of the data packet can be determined. The label code of the address range is determined by the pre-configured label codes of each address range. Then, the mapping table is queried according to the label codes to determine the mutual access rules that the data packet needs to use, thereby routing and forwarding the data packet under the corresponding rules to achieve mutual access control.
[0097] In some embodiments, step S504 includes, but is not limited to, steps S601 to S602:
[0098] Step S601: When the mutual access label of the address segment is the mutual access label within the address segment and between address segments, the first mutual access rule is used to route and forward the data packet. The first mutual access rule is to find the mutual access address segment with the same label code as the address segment, determine the internal and mutual access address segments as the allowed forwarding range of the data packet, and route and forward the data packet according to the allowed forwarding range.
[0099] Step S602: When the mutual access label of the address segment is an inter-address segment mutual access label, the second mutual access rule is used to route and forward the data packet. The second mutual access rule is to find the mutual access address segment with the same label code as the address segment, determine the mutual access address segment as the allowed forwarding range of the data packet, and route and forward the data packet according to the allowed forwarding range.
[0100] Step S603: When the address segment inter-access label is the address segment inter-access closed label, the data packet is discarded.
[0101] Specifically, when devices within the mutual access group need to communicate with other terminals, the service traffic is forwarded directly from uplink user plane traffic to downlink user plane traffic within the UPF according to the tag code. Address ranges without configured tag codes inherit system attributes and are not interconnected with mutual access tag address ranges. For example, please refer to... Figure 10The process begins with receiving a data packet from the terminal. The packet is then tagged with an address range. If the tag code falls within the range of 10000-19999, the packet is routed using the first mutual access rule (matching intra- and inter-address range mutual access strategies). This first rule involves finding mutual access address ranges with the same tag code as the address range, defining intra- and inter-address ranges as the allowed forwarding range for the packet, and routing the packet accordingly. For example, if the destination IP address is within the allowed range, the packet is forwarded; otherwise, it is discarded. If the tag code falls within the range of 20000-29999, the packet is routed using the second mutual access rule (matching inter-address range mutual access strategies). This second rule involves finding mutual access address ranges with the same tag code as the address range, defining these mutual access address ranges as the allowed forwarding range for the packet, and routing the packet accordingly. If the tag code falls within the 30000-39999 encoding range, the third mutual access rule (i.e., matching the address range mutual access closure policy) is used to route and forward the data packet, for example, by directly discarding the data packet to improve data security. If the tag code is empty, the global forwarding policy is matched, and the specific rules of this global forwarding policy can be set according to business needs. Furthermore, during operation, the system in this embodiment continuously collects and analyzes information such as the network status of the network management platform and the status of the mutual access tag management module, and dynamically adjusts and optimizes mutual access tag management, forwarding policies, and access control based on this information.
[0102] In some embodiments, the method of this application can realize the mutual access function between secondary customers, that is, mutual access between secondary customers under primary customers. The mutual access label management module generates a unique label code for the address segment corresponding to the subnet of the secondary customer under primary customers. The label code is matched and bound with the address segment information that needs to be mutually accessed in the address pool under DNN. The core network determines whether mutual access is possible based on whether the label configured in the address segment where the terminal address is located is consistent.
[0103] The method described in this application embodiment can also enable inter-client communication, i.e., client-to-client communication. Customized network clients use customized DNNs. Client-to-client communication requires enabling the inter-client communication function of the customized DNNs and configuring consistent inter-client communication label codes for the address segments that need to be communicated within the two DNNs. The labels are mapped and bound to the address segment information that needs to be communicated within the address pool under the DNN. The core network determines whether inter-client communication is possible based on whether the DNN where the terminal address is located has enabled inter-client communication and whether the labels configured for the address segments are consistent.
[0104] According to some embodiments of this application, the method of this application has the following beneficial effects:
[0105] The DNN address pool configures mutual access labels for address segments, and the application of label attributes enables access control for point-to-multipoint and multipoint-to-multipoint networks, solving the problem of arbitrary mutual access between addresses within the address pool. By using labels to achieve user isolation, the use of core network directed access rules is reduced, providing a mechanism for terminal address isolation within the address pool.
[0106] By associating address ranges with customer subnets using address interoperability labels, the complexity of building a customer's self-organizing network platform is reduced. Interoperable address ranges use unique interoperability label encodings, improving network expansion flexibility.
[0107] Implementing DNN subnet isolation on the core network UPF reduces network deployment and usage costs, accelerating the large-scale development of customized 5G networks. Inter-terminal access control is implemented on the core network, reducing customer network construction and operation costs. By using labels to logically divide the DNN into several subnets, the number of customer-level customized DNN configurations for 5G networks is reduced.
[0108] Please see Figure 6 This application also provides a terminal access management system, including:
[0109] The first module is used to obtain the mutual access configuration and encoding set of address segments in the user address pool, wherein the encoding set includes multiple unassigned tag encodings;
[0110] The second module is used to determine the mutual access label and mutual access address range based on the mutual access configuration of the address range;
[0111] The third module is used to extract tag codes that match the meaning of mutual access tags from the code set based on the mutual access tags of the address segments, and to assign the tag codes to the address segments and the mutual access address segments of the address segments;
[0112] The fourth module is used to configure the address ranges of the user address pool and the tag codes of each address range onto the service network elements, so that the service network elements can route and forward the terminal's data packets according to the mutual access rules of the tag codes.
[0113] It is understood that the content of the above-described terminal access management method embodiments is applicable to this system embodiment. The specific functions implemented in this system embodiment are the same as those in the above-described terminal access management method embodiments, and the beneficial effects achieved are also the same as those achieved in the above-described terminal access management method embodiments.
[0114] This application also provides an electronic device, which includes: a memory, a processor, a program stored in the memory and executable on the processor, and a data bus for communication between the processor and the memory. When the program is executed by the processor, it implements the aforementioned terminal access management method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0115] Please see Figure 7 , Figure 7 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes:
[0116] The processor 701 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.
[0117] The memory 702 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 702 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 702 and is called and executed by the processor 701 using the terminal access management method of the embodiments of this application.
[0118] The input / output interface 703 is used to implement information input and output;
[0119] The communication interface 704 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0120] Bus 705 transmits information between various components of the device (e.g., processor 701, memory 702, input / output interface 703, and communication interface 704);
[0121] The processor 701, memory 702, input / output interface 703, and communication interface 704 are connected to each other within the device via bus 705.
[0122] This application also provides a storage medium, which is a computer-readable storage medium for computer-readable storage. The storage medium stores one or more programs, which can be executed by one or more processors to implement the above-described terminal access management method.
[0123] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0124] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0125] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0126] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0127] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0128] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0129] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0130] In the embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between systems or units may be electrical, mechanical, or other forms.
[0131] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0132] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0133] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0134] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.
Claims
1. A terminal inter-access management method, characterized in that, Includes the following steps: Obtain the mutual access configuration and encoding set of address segments in the user address pool, wherein the encoding set includes multiple unassigned tag encodings; The mutual access label and mutual access address range of the address range are determined according to the mutual access configuration of the address range; the mutual access label is used to indicate at least one of the following: mutual access within and between address ranges, mutual access between address ranges, and mutual access between address ranges is disabled; The corresponding encoding range is obtained by querying the encoding label mapping table based on the mutual access label of the address range. The encoding label mapping table is used to record the mapping relationship between the encoding range and the mutual access label. For address segments with mutually accessible tags within and between address segments, extract any tag code located within the corresponding coding interval from the coding set, and assign the extracted tag code to the address segment and the mutually accessible address segments of the address segment; For an address segment with inter-address access tags, extract any tag code located within the corresponding coding interval from the coding set, and assign the extracted tag code to the address segment and the inter-address access address segment of the address segment; For address segments with closed tags for inter-address access, extract any tag code located within the corresponding encoding interval from the encoding set, and assign the extracted tag code to the address segment; The address ranges of the user address pool and the tag codes of each address range are configured on the service network elements so that the service network elements can route and forward the terminal's data packets according to the mutual access rules of the tag codes. The encoding set is updated through the following steps: Determine the encoding configuration status of each address segment, wherein the encoding configuration status includes encoding allocation, encoding change, and encoding recycling; When the encoding configuration status is encoding allocation, the tag encoding allocated to the address segment is deleted from the encoding set; When the encoding configuration status is "encoding change", the newly assigned tag code to the address segment is deleted from the encoding set, and the tag code of the address segment before the change is written into the encoding set; When the encoding configuration status is encoding recycling, the current tag encoding of the address segment is written into the encoding set.
2. The terminal inter-access management method according to claim 1, characterized in that, The mutual access configuration in the user address pool is obtained through the following steps: The network configuration is obtained through the network management platform, wherein the network configuration includes multiple networks, and each network is defined by at least one address range from the user address pool; Display the network configuration on the customer relationship management platform to obtain the mutual access configuration for each address range.
3. The terminal inter-access management method according to claim 1, characterized in that, The service network element routes and forwards data packets through the following steps: Receive data packets from the terminal; The corresponding address range and the tag code of the address range are determined based on the address information carried in the data packet; The corresponding mutual access tag is determined by querying the coded tag mapping table based on the tag encoding. The corresponding mutual access rules are determined based on the mutual access labels, and the data packets are routed and forwarded according to the mutual access rules.
4. The terminal inter-access management method according to claim 3, characterized in that, The step of determining the corresponding mutual access rules based on the mutual access labels and routing and forwarding the data packets according to the mutual access rules includes the following steps: When the mutual access label of the address segment is the intra-address segment and inter-address segment mutual access label, the first mutual access rule is used to route and forward the data packet. The first mutual access rule is to find the mutual access address segment with the same label code as the address segment, determine the intra-address segment and the mutual access address segment as the allowed forwarding range of the data packet, and route and forward the data packet according to the allowed forwarding range. When the inter-address segment's inter-address segment label is an inter-address segment inter-inter-interface label, the second inter-interface rule is used to route and forward the data packet. The second inter-interface rule is to find the inter-interface address segment with the same label code as the address segment, determine the inter-interface address segment as the allowed forwarding range of the data packet, and route and forward the data packet according to the allowed forwarding range. If the address segment inter-access label is the address segment inter-access closed label, then the data packet is discarded.
5. A terminal inter-access management system, characterized in that, include: The first module is used to obtain the mutual access configuration and encoding set of address segments in the user address pool, wherein the encoding set includes multiple unassigned tag encodings; The second module is used to determine the mutual access label and mutual access address range of the address range according to the mutual access configuration of the address range; the mutual access label is used to indicate at least one of the following: mutual access within and between address ranges, mutual access between address ranges, and mutual access between address ranges is disabled; The third module is used to query the encoding label mapping table based on the mutual access labels of the address segments to obtain the corresponding encoding intervals. The encoding label mapping table records the mapping relationship between encoding intervals and mutual access labels. For address segments with mutual access labels within or between address segments, any label code located within the corresponding encoding interval is extracted from the encoding set, and the extracted label code is assigned to the address segment and its mutual access address segments. For address segments with mutual access labels between address segments, any label code located within the corresponding encoding interval is extracted from the encoding set, and the extracted label code is assigned to the address segment and its mutual access address segments. For address segments with mutual access disabled labels, any label code located within the corresponding encoding interval is extracted from the encoding set, and the extracted label code is assigned to the address segment. The fourth module is used to configure the address ranges of the user address pool and the tag codes of each address range onto the service network element, so that the service network element can route and forward the terminal's data packets according to the mutual access rules of the tag codes. The terminal access management system is also used to encode a set through the following steps: Determine the encoding configuration status of each address segment, wherein the encoding configuration status includes encoding allocation, encoding change, and encoding recycling; When the encoding configuration status is encoding allocation, the tag encoding allocated to the address segment is deleted from the encoding set; When the encoding configuration status is "encoding change", the newly assigned tag code to the address segment is deleted from the encoding set, and the tag code of the address segment before the change is written into the encoding set; When the encoding configuration status is encoding recycling, the current tag encoding of the address segment is written into the encoding set.
6. An electronic device, characterized in that, The electronic device includes a memory, a processor, a program stored in the memory and executable on the processor, and a data bus for enabling communication between the processor and the memory, wherein the program, when executed by the processor, implements the steps of the method as described in any one of claims 1 to 4.
7. A storage medium, said storage medium being a computer-readable storage medium for computer-readable storage, characterized in that, The storage medium stores one or more programs, which can be executed by one or more processors to implement the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Data access method and device, electronic equipment and storage medium
CN117459259A