Post-routing networking method, device and equipment based on 5G VPDN
Through the post-routing networking method based on 5G VPDN and the collaborative work of modules such as the access and mobility management modules, the problems of low transmission efficiency and difficult management of wireless networking equipment in 5G networks are solved, and efficient and secure communication tunnel establishment is achieved.
Patent Information
- Application Number
- CN202411842651.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-12-13
AI Technical Summary
When wireless networking devices in existing 5G networks communicate with intranet servers, there are problems such as low transmission efficiency, difficulty in managing downstream devices, and high performance requirements for networking devices.
By adopting a post-routing networking method based on 5G VPDN, the access and mobility management module, session management module, routing forwarding module, tunnel network module and authentication module work together to realize the registration, authentication and communication tunnel establishment of wireless networking equipment, simplifying the steps of establishing traditional communication tunnels.
It improves the transmission efficiency of networking equipment, simplifies the management of downstream equipment, reduces the performance requirements of networking equipment, and realizes the establishment of safe and reliable communication tunnels.
Smart Images

Figure CN119697634B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, in particular to a post-routing networking method, device and equipment based on 5G VPDN. BACKGROUND
[0002] The existing 5G network deploys a VPDN scheme based on L2TP tunnel to provide private network services for enterprises. In addition to this VPDN service, other VPDN private network services can also be provided for new customers. The 5G L2TP networking ensures the security of data transmission. When using wireless devices to build a mobile office network, if the enterprise user wants to realize the intercommunication between branch node network and headquarter network, the traditional solution is to realize the communication between the hanging device and the server through tunnel technologies such as VxLAN and GRE. For example, VxLAN encapsulates the original Ethernet packet in a UDP data packet and adds a VxLAN header.
[0003] The above-mentioned mode has problems of low transmission efficiency, difficult management of hanging devices, and high performance requirements of networking devices due to the large packet header after tunnel superposition.
[0004] The above content is only used to assist in understanding the technical solutions of the present application and does not represent the acknowledgement of the above content as prior art. SUMMARY
[0005] The main purpose of the present application is to provide a post-routing networking method, device and equipment based on 5G VPDN, which aims to solve the technical problems of low transmission efficiency, difficult management of hanging devices, and high performance requirements of networking devices of the existing wireless networking device when communicating with the internal network server.
[0006] To achieve the above-mentioned purpose, the present application provides a post-routing networking method based on 5G VPDN, which is applied to a networking management server. The networking management server at least includes an access and mobility management module, a session management module, a routing forwarding module, a tunnel network module, and an authentication module.
[0007] The method comprises the following steps:
[0008] In response to the registration request initiated by the wireless networking device, the custom dialing information corresponding to the wireless networking device is issued to the wireless networking device;
[0009] The access and mobility management module receives the networking session request initiated by the wireless networking device, and performs one-time authentication according to the networking session request;
[0010] After the one-time authentication is passed, the authentication module feeds back tunnel protocol response information and downlink device routing information to the session management module.
[0011] The session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module;
[0012] The routing forwarding module establishes a communication tunnel with the tunnel network module according to the tunnel protocol response information, and forwards the customized dialing information to the tunnel network module through the communication tunnel;
[0013] The tunnel network module performs secondary authentication according to the customized dialing information;
[0014] After the secondary authentication passes, the routing forwarding module sends a networking session response to the wireless networking device to establish a VPDN communication tunnel between the wireless networking device and the server.
[0015] Optionally, the session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module, comprising:
[0016] The session management module inserts the downlink device routing information into a downlink device routing table to obtain a target downlink device routing table;
[0017] According to the target downlink device routing table and the tunnel protocol response information, a first PFCP response information is generated;
[0018] The first PFCP response information is transmitted to the routing forwarding module.
[0019] Optionally, in response to the registration request initiated by the wireless networking device, the customized dialing information corresponding to the wireless networking device is issued to the wireless networking device, comprising:
[0020] A public data network channel with the wireless access device is established;
[0021] Terminal information and SIM card information of the wireless access device are received through the public data network channel;
[0022] Customized dialing information is generated based on the terminal information and the SIM card information;
[0023] The customized dialing information is issued to the wireless networking device through the public data network channel.
[0024] Optionally, the routing forwarding module sends a networking session response to the wireless networking device, comprising:
[0025] The routing forwarding module sends second PFCP response information to the session management module, wherein the second PFCP response information carries a networking session response;
[0026] The networking session response is sent to the wireless networking device through the first interface, or the networking session response is sent to the access and mobility management module through the second interface, so that the access and mobility management module forwards the networking session response to the wireless networking device.
[0027] Optionally, the 5G VPDN-based post-routing networking method further comprises:
[0028] In response to a communication request of the downlink device, the uplink data packet carried in the communication request is obtained;
[0029] The routing forwarding module encapsulates the uplink data packet to obtain an encapsulated uplink data packet;
[0030] The encapsulated uplink data packet is sent to the tunnel network module through a VPDN tunnel;
[0031] The tunnel network module decapsulates the encapsulated uplink data packet and forwards it to the server.
[0032] Optionally, the 5G VPDN-based post-routing networking method further comprises:
[0033] The downlink data packet sent by the server is received;
[0034] The tunnel network module encapsulates the downlink data packet to obtain an encapsulated downlink data packet;
[0035] The tunnel network module sends the encapsulated downlink data packet to the routing forwarding module through a VPDN tunnel;
[0036] The routing forwarding module decapsulates the encapsulated downlink data packet to obtain a downlink data packet and routing information;
[0037] The downlink data packet is sent to the wireless networking device based on the routing information, so that the wireless networking device forwards the downlink data packet to the downlink device corresponding to the routing information.
[0038] Optionally, the 5G VPDN-based post-routing networking method further comprises:
[0039] The wireless networking device and the downlink device of the wireless networking device are configured with networking data;
[0040] The networking data configuration includes domain name configuration and number card configuration.
[0041] In addition, to achieve the above object, the application further provides a post-routing networking device based on 5G VPDN, which comprises:
[0042] An information issuing module is configured to issue customized dialing information corresponding to the wireless networking device to the wireless networking device in response to a registration request initiated by the wireless networking device.
[0043] A one-time authentication module is configured to receive a networking session request initiated by the wireless networking device through the access and mobility management module, and perform one-time authentication according to the networking session request.
[0044] An information feedback module is configured to feed back tunnel protocol response information and downlink device routing information to the session management module by the authentication module after the one-time authentication is passed.
[0045] An information forwarding module is configured to transmit the tunnel protocol response information and the downlink device routing information to the routing forwarding module by the session management module.
[0046] A tunnel establishment module is configured to establish a communication tunnel between the routing forwarding module and the tunnel network module according to the tunnel protocol response information, and forward the customized dialing information to the tunnel network module through the communication tunnel.
[0047] A two-time authentication module is configured to perform two-time authentication according to the customized dialing information by the tunnel network module.
[0048] A response feedback module is configured to send a networking session response to the wireless networking device by the routing forwarding module after the two-time authentication is passed, so as to establish a VPDN communication tunnel between the wireless networking device and a server.
[0049] In addition, to achieve the above object, the application further provides a post-routing networking device based on 5G VPDN, which comprises a memory, a processor, and a post-routing networking program based on 5G VPDN stored in the memory and executable on the processor, and the post-routing networking program based on 5G VPDN is configured to implement the steps of the post-routing networking method based on 5G VPDN.
[0050] In addition, to achieve the above object, the application further provides a storage medium, which stores a post-routing networking program based on 5G VPDN, and the post-routing networking program based on 5G VPDN implements the steps of the post-routing networking method based on 5G VPDN when executed by a processor.
[0051] In addition, to achieve the above object, the application further provides a computer program product, which comprises a computer program, and the computer program realizes the steps of the 5G VPDN-based post-routing networking method when executed by a processor.
[0052] The one or more technical solutions provided by the application have at least the following technical effects: the application performs one-time authentication by receiving a networking session request initiated by a wireless networking device, completes necessary information configuration for networking, after the one-time authentication is passed, the authentication module feeds back tunnel protocol response information and downlink device routing information to the session management module to synchronously implement establishment of a communication channel and post-routing of a downlink device of the wireless networking device, the session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module, and the routing forwarding module establishes a communication tunnel between the tunnel network module according to the tunnel protocol response information, so that secondary authentication is performed, the networking effect is improved, after the secondary authentication is passed, the routing forwarding module sends a networking session response to the wireless networking device to complete establishment of the communication tunnel, the establishment steps of a conventional communication tunnel are simplified, and the technical problems of low transmission efficiency, difficult management of a downlink device, and high performance requirement of a networking device of the downlink device of the wireless networking device when communicating with the Internet are avoided. BRIEF DESCRIPTION OF DRAWINGS
[0053] The accompanying drawings, which are incorporated into and form a part of the specification, illustrate an embodiment consistent with the present application and, together with the description, serve to explain the principles of the application.
[0054] In order to more clearly illustrate the technical solutions in the embodiments of the application or in the prior art, the accompanying drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, for those skilled in the art, other drawings can also be obtained based on these drawings without any creative effort.
[0055] Figure 1 The flowchart of the first embodiment of the 5G VPDN-based post-routing networking method of the application;
[0056] Figure 2 The architecture diagram of the networking management server of the first embodiment of the 5G VPDN-based post-routing networking method of the application;
[0057] Figure 3 The flowchart of the networking management process of the first embodiment of the 5G VPDN-based post-routing networking method of the application;
[0058] Figure 4 The flowchart of the second embodiment of the 5G VPDN-based post-routing networking method of the application;
[0059] Figure 5 A flowchart of establishing a VPDN tunnel and data uplink and downlink for the 5G VPDN-based post-routing networking method of an embodiment of the present application;
[0060] Figure 6 A networking data configuration flowchart for the 5G VPDN-based post-routing networking method of an embodiment of the present application;
[0061] Figure 7 A structure block diagram of the 5G VPDN-based post-routing networking device of a first embodiment of the present application;
[0062] Figure 8 A structure diagram of the 5G VPDN-based post-routing networking device of a first embodiment of the present application.
[0063] The implementation, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION
[0064] It should be understood that the specific embodiments described herein are merely intended to explain the technical solutions of the present application, and not to limit the present application.
[0065] In order to better understand the technical solutions of the present application, the specific embodiments will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0066] Based on this, the present application provides a 5G VPDN-based post-routing networking method, which will be described below with reference to the accompanying drawings. Figure 1 , Figure 1 A flowchart of the 5G VPDN-based post-routing networking method of a first embodiment of the present application.
[0067] In this embodiment, the 5G VPDN-based post-routing networking method comprises:
[0068] Step S10: in response to a registration request initiated by a wireless networking device, issuing custom dialing information corresponding to the wireless networking device to the wireless networking device
[0069] It should be noted that the execution subject of the present embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device, a networking management server, etc. capable of realizing the above functions. The following will take the networking management server as an example to describe the present embodiment and the following embodiments.
[0070] Reference Figure 2 , Figure 2The schematic diagram of the architecture of the network management server in the embodiment is shown, and specifically, the network management server at least includes an access and mobility management module (Access and Mobility Management Function, AMF), a session management module (Session Management Function, SMF), a routing forwarding module (User Plane Function, UPF), a tunnel network module (L2TP Network Server, LNS), and an authentication module.
[0071] The authentication module is mainly used for AAA authentication, and in the embodiment, the AAA authentication is divided into primary AAA authentication and secondary AAA authentication. The authentication data used in the two times of AAA authentication is different, and the purpose is to detect the security of the network equipment.
[0072] The customized dialing information is mainly used for building an independent VPDN tunnel to realize data transmission in a private network and improve the security of data transmission.
[0073] Further, the customized dialing information corresponding to the wireless network equipment is issued to the wireless network equipment in response to a registration request initiated by the wireless network equipment, and the method comprises the following steps:
[0074] A public data network channel between the wireless access device and the wireless network equipment is established.
[0075] Terminal information and SIM card information of the wireless access device are received through the public data network channel.
[0076] Customized dialing information is generated based on the terminal information and the SIM card information.
[0077] The customized dialing information is issued to the wireless network equipment through the public data network channel.
[0078] In a specific implementation, reference is made to Figure 3 , Figure 3 The network management process of the embodiment is shown, and first, after the wireless access device is powered on, registration and session creation can be completed by using a public DNN dialing. The public DNN establishes a public management channel with a customer terminal device (Customer Premises Equipment, CPE) and a network management platform.
[0079] Wherein, the wireless access device reports terminal information and SIM card information in the format of the object model field through the management channel after the establishment of the public DNN management channel, the CPE terminal standard object model supports four types of services of data reporting, instruction issuing, instruction response and event reporting, and supports carrying single device or multiple device information to realize reporting and issuing for the relevant attributes of the downlink device information, the networking management platform completes authentication for the access device, and issues custom dialing information DNN dialing information, account, password and other information of the SIM card subscription, and synchronously issues downlink device management information.
[0080] The networking management platform can realize unified access and management of enterprise customers, supports operation and maintenance support and statistical analysis, can simulate dialing test, real-time troubleshooting, monitoring and alarm for terminals and networks, provides multi-dimensional analysis of terminal use, network quality, service use and the like through statistical analysis capability, and helps enterprises optimize networking strategy.
[0081] The custom dialing information includes but is not limited to custom dialing information DNN, account, password, protection algorithm, maximum uplink and downlink rate, SSC mode and IP type supported by the session and the like.
[0082] Step S20: receiving, by the access and mobility management module, a networking session request initiated by the wireless networking device, and performing one-time authentication according to the networking session request.
[0083] It should be understood that the networking session request at least contains PDU session ID, key, protection algorithm, maximum uplink and downlink rate, SSC mode and IP type supported by the session and the like, which can be used for subsequent multiple AAA authentication.
[0084] In a specific implementation, the step of receiving, by the access and mobility management module, a networking session request initiated by the wireless networking device, and performing one-time authentication according to the networking session request specifically includes: after receiving the PDU networking session request initiated by the wireless networking device through the access and mobility management module, requesting the session management module to generate an SM context, and sending an one-time AAA authentication request message to the authentication module by the session management module SMF to realize one-time authentication.
[0085] Wherein, the SM context includes but is not limited to PDU session identifier, QoS configuration, charging rule, user location information, RAT type (wireless access technology), S-NSSAI (single network slice selection auxiliary information), MBR (maximum bit rate) and the like, by maintaining these detailed context data, the SMF can effectively manage and control the communication connection between the user equipment (UE) and the data network (DN), and ensure the quality and efficiency of the service.
[0086] Step S30: After the one-time authentication passes, the authentication module feeds back tunnel protocol response information and downlink device routing information to the session management module.
[0087] In a specific implementation, a one-time AAA server authenticates a user, issues corresponding information according to a user subscription service type, and issues tunnel protocol response information LNS and downlink device routing information corresponding to the user in a response message after AAA authentication passes, wherein the LNS information at least includes LNS IP, tunnel key, Hostname, etc.
[0088] The embodiment combines 5G VPDN and post-routing to realize that branch point wireless networking equipment hangs multiple terminal access networks and performs bidirectional data services with network side equipment through a tunnel. 5G VPDN realizes safe tunnel building of UPF and customer LNS through a customized DNN private network, wireless equipment can enter the internal network safely through the tunnel, and bidirectional intercommunication of the wireless networking equipment hanging terminal and internal network equipment is realized by using post-routing technology. The platform can meet the networking management needs of enterprise customers, the wireless equipment and downlink equipment access authentication and management are realized through the management DNN channel in the networking management platform, the platform can configure networking data to the networking network element, and supports completion of processes such as session creation, authentication, channel establishment, and address allocation in the network.
[0089] Among them, VPDN authentication and tunnel can guarantee the safety of wireless equipment access and data packet transmission, post-routing and platform networking can further manage the hanging equipment, and a secure end-to-end path is constructed. VPDN tunnel is built by using a customized DNN to realize network isolation, and private data is transmitted in a private network; the hanging equipment and network side IP intercommunication strategy realized by GRE three-layer tunnel or VxLAN large two-layer technology can be realized through the post-routing function, and secondary tunnel encapsulation of the message is avoided, and transmission efficiency is improved; in the session establishment process, only one authentication process is needed to complete the LNS docking information and the hanging terminal routing information issuing, and VPDN tunnel and post-routing path building are completed in one session;
[0090] The intercommunication ability realized by the fusion of 5G VPDN and post-routing technology is particularly suitable for mobile office networking scenarios, and combined with 5G network and wireless networking equipment, the hanging terminal can safely access enterprise internal network resources through the VPDN tunnel without additional hardware equipment; the embodiment can be realized by simple modification on the existing 5G VPDN network, compared with the traditional leased line network, the method has low cost, fast deployment, and combined with the platform networking ability, the business demand changes of enterprises can be quickly responded; through the double DNN ability supported by the wireless terminal and the number card, the management channel and the data channel of the network can be separated, so that the networking is more secure and convenient.
[0091] Step S40: The session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module.
[0092] It should be noted that the tunnel protocol response information LNS is used to provide secure network access services for remote users, and in this embodiment, it is used as a bridge connecting the public network and the private network, that is, as a relay between the wireless networking device and the server.
[0093] Further, the session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module, comprising:
[0094] The session management module inserts the downlink device routing information into the downlink device routing table according to the downlink device routing information to obtain a target downlink device routing table;
[0095] According to the target downlink device routing table and the tunnel protocol response information, a first PFCP response information is generated;
[0096] The first PFCP response information is transmitted to the routing forwarding module.
[0097] In a specific implementation, as a response to the PDU session establishment request, the session management module SMF informs the access and mobility management module AMF of the result of the session establishment, and the SMF inserts the routing information in the authentication response message into the SMF routing table to obtain a target downlink device routing table, and generates a PFCP Session Establishment Request message based on the target downlink device routing table and the tunnel protocol response information, and carries the downlink device routing information and the L2TP connection information to the routing forwarding module UPF, so as to subsequently establish a communication tunnel and secondary AAA authentication.
[0098] Step S50: The routing forwarding module establishes a communication tunnel with the tunnel network module according to the tunnel protocol response information, and forwards the customized dialing information to the tunnel network module through the communication tunnel.
[0099] Step S60: The tunnel network module performs secondary authentication according to the customized dialing information.
[0100] Both the secondary AAA authentication and the primary AAA authentication are authenticated by using the RADIUS protocol, in order to improve the security of device networking, but the data of the two AAA authentications is different, the primary AAA authentication is for dialing request, and the secondary AAA authentication is for username and password verification.
[0101] Step S70: After the secondary authentication is passed, a network session response is sent to the wireless networking device through the routing forwarding module to establish a VPDN communication tunnel between the wireless networking device and the server.
[0102] It can be understood that the network session response at least includes authentication result, fixed IP address allocated based on SIM card number and the like information.
[0103] Further, the sending of the network session response to the wireless networking device through the routing forwarding module comprises:
[0104] The second PFCP response information is sent to the session management module through the routing forwarding module, and the network session response is carried in the second PFCP response information.
[0105] The network session response is sent to the wireless networking device through the first interface, or the network session response is sent to the access and mobility management module through the second interface, so that the access and mobility management module forwards the network session response to the wireless networking device.
[0106] The UPF returns the L2TP session information to the SMF through the PFCP Session Establishment Response message, and transmits information through the N1 interface (interface with the UE) and the N2 interface (interface with the RAN).
[0107] The embodiment performs primary authentication by receiving the network session request initiated by the wireless networking device, completes the necessary information configuration of the network, after the primary authentication is passed, the authentication module feeds back the tunnel protocol response information and the downlink device routing information to the session management module to synchronously realize the establishment of the communication channel and the post-routing of the downlink device of the wireless networking device, the session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module, and establishes the communication tunnel between the tunnel network module according to the tunnel protocol response information through the routing forwarding module, so as to perform secondary authentication, improve the networking effect, after the secondary authentication is passed, the network session response is sent to the wireless networking device through the routing forwarding module to complete the establishment of the communication tunnel, and the establishment steps of the traditional communication tunnel are simplified.
[0108] Based on the first embodiment of the application, in the second embodiment of the application, the same or similar contents as the above embodiment one can refer to the above introduction, and the following will not be repeated. On this basis, please refer to Figure 4 , after step S70, further comprising:
[0109] Step S80: In response to the communication request of the downlink device, the uplink data packet carried in the communication request is acquired.
[0110] Step S90: The routing forwarding module encapsulates the uplink data packet to obtain an encapsulated uplink data packet.
[0111] Step S100: The encapsulated uplink data packet is sent to a tunnel network module through a VPDN tunnel.
[0112] Step S110: The tunnel network module decapsulates the encapsulated uplink data packet and forwards it to a server.
[0113] It should be noted that, with reference to Figure 5 , Figure 5 A flowchart of establishing a VPDN tunnel and data uplink and downlink for the embodiment is shown, and specifically, the steps corresponding to each time sequence number are as follows: 1. A PDU session establishment request process is initiated by a CPE, and the request message contains key information such as PDU session ID, key, protection algorithm, maximum uplink and downlink rate, SSC mode supported by the session, and IP type; 2. The SMF requests the SM context to be created; 3. The SMF sends an authentication request message to a primary AAA; 4. The primary AAA server authenticates the user and issues corresponding information according to the user's subscribed service type; the LNS information and the user's corresponding downlink device routing information are issued in the response message after the AAA authentication is passed, wherein the LNS information includes LNS IP, tunnel key, Hostname, etc.; 5. As a response to the PDU session establishment request, the AMF is notified of the result of the session establishment; 6. The SMF inserts the routing information in the authentication response message into the SMF routing table and sends a PFCP Session Establishment Request message to the UPF carrying the downlink device routing and L2TP link establishment information; 7. Tunnel establishment process; 8. Session establishment process; 9. Secondary AAA authentication, completing username and password verification, allocating a fixed IP, and returning an authentication result; 10. Address negotiation process; 11. The UPF returns a PFCP Session Establishment Response message to the SMF to report L2TP session information; 12. Information is transmitted through the N1 interface (interface with the UE) and the N2 interface (interface with the RAN); 13. The AMF responds to the PDU session establishment request of the CPE, and the session establishment process is completed; 14. The downlink device such as a PC initiates uplink service, and the CPE closes the NAT function to directly forward the uplink data packet; 15. The UPF receives the encapsulated uplink packet from the downlink device, sends it to the LNS side through the VPDN tunnel, and forwards the data packet to the intranet server after the LNS decapsulates it; 16. The DN side server sends downlink data to the downlink device, and the data is encapsulated by the LNS and sent to the UPF side through the VPDN tunnel; 17. The UPF receives the downlink packet, matches the PDU session, and directly forwards the downlink data packet to the CPE according to the routing information; and the CPE sends the downlink packet to the corresponding downlink device.
[0114] When the downstream device such as a terminal device initiates uplink service, the CPE closes the NAT function and directly forwards the uplink data packet to the routing forwarding module UPF, and the routing forwarding module UPF completes encapsulation and sends the encapsulated uplink data packet to the tunnel network module through the VPDN tunnel established in advance, for information transfer and decapsulation, and realizes interconnection with the Internet.
[0115] Further, the 5G VPDN-based post-routing networking method further comprises:
[0116] receiving the downlink data packet sent by the server;
[0117] The tunnel network module encapsulates the downlink data packet to obtain an encapsulated downlink data packet;
[0118] The tunnel network module sends the encapsulated downlink data packet to the routing forwarding module through the VPDN tunnel;
[0119] The routing forwarding module decapsulates the encapsulated downlink data packet to obtain a downlink data message and routing information;
[0120] Based on the routing information, the downlink data message is sent to the wireless networking device, so that the wireless networking device forwards the downlink data message to the downstream device corresponding to the routing information.
[0121] In a specific implementation, the DN-side server sends downlink data to the downstream device, the data is encapsulated by the LNS and sent to the UPF side through the VPDN tunnel, the UPF receives the downlink message matching the PDU session, and according to the routing information, the downlink data message is directly forwarded to the CPE, and the CPE sends the downlink message to the corresponding downstream device
[0122] Further, the 5G VPDN-based post-routing networking method further comprises:
[0123] The wireless networking device and the downstream device of the wireless networking device are configured with networking data;
[0124] The networking data configuration includes domain name configuration and number card configuration.
[0125] In a specific implementation, reference is made to Figure 6 , Figure 6 The networking data configuration flowchart of the embodiment, before the device access, the networking data configuration needs to be completed in the networking management platform, and the networking data configuration mainly includes two parts: domain name configuration and number card configuration.
[0126] Domain name configuration completes the opening of the customized dialing information DNN and the configuration of the VPDN domain name. Generally, the domain name is consistent with the name of the customized dialing information DNN. When the customized dialing information DNN is opened, the DNN configuration instruction is issued to the UDM, SMF and UPF. The customized dialing information DNN is bound to the public DNN used for platform management in the UDM network element, a new multi-DNN template is created for the card subscription, the SMF is configured to the radius configuration of the one-time AAA, the routing switch is opened after the DNN is opened, the UPF switch is synchronously opened, the VPDN domain name configuration instruction is sent to the one-time AAA and the secondary AAA, and the domain name data is used for the access authentication of the wireless device and the LNS tunnel docking. For example, when the post-routing function is enabled, the post-routing switch is opened under the corresponding domain name in the one-time AAA.
[0127] After the domain name is configured, the card subscription is completed, the networking platform performs the binding of the wireless device and the card and the configuration management of the downlink device, the UDM subscribes to the multi-DNN template and configures the card binding, so that the wireless access device completes the binding with the SIM card in the power-on registration stage. The one-time AAA has configured the domain name, the corresponding username and password are configured for each VPDN access card, and the downlink device address segment of the access card is configured. The address routing information is issued in the one-time AAA authentication stage of the session creation. The secondary AAA has configured the domain name, the corresponding username and password are configured for each VPDN access card, and a fixed IP is allocated. In order to ensure the security of the wireless access device and the downlink device access, the binding of the wireless access device and the card is completed on the networking management platform, the black and white list function is provided for the downlink device of the wireless access device to further enhance the security of the branch point wireless access network, and the platform also provides other CPE related settings.
[0128] The embodiment obtains the uplink data packet carried in the communication request by responding to the communication request of the downlink device. The routing forwarding module encapsulates the uplink data packet to obtain an encapsulated uplink data packet. The encapsulated uplink data packet is sent to the tunnel network module through the VPDN tunnel. The tunnel network module decapsulates the encapsulated uplink data packet and forwards it to the server, so as to realize the uplink of the terminal-server data through the established VPDN tunnel and realize the safe access to the enterprise intranet resources.
[0129] The application also provides a 5G VPDN-based post-routing networking device, please refer to Figure 7 , the 5G VPDN-based post-routing networking device comprises:
[0130] The information issuing module 10 is configured to issue the customized dialing information corresponding to the wireless networking device to the wireless networking device in response to the registration request initiated by the wireless networking device.
[0131] A primary authentication module 20 is configured to receive a networking session request initiated by the wireless networking device through the access and mobility management module, and perform primary authentication according to the networking session request.
[0132] An information feedback module 30 is configured to feed back tunnel protocol response information and downlink device routing information to the session management module by the authentication module after the primary authentication is passed.
[0133] An information forwarding module 40 is configured to transmit the tunnel protocol response information and the downlink device routing information to the routing forwarding module by the session management module.
[0134] A tunnel establishment module 50 is configured to establish a communication tunnel between the routing forwarding module and the tunnel network module according to the tunnel protocol response information, and forward the customized dialing information to the tunnel network module through the communication tunnel.
[0135] A secondary authentication module 60 is configured to perform secondary authentication according to the customized dialing information by the tunnel network module.
[0136] A response feedback module 70 is configured to send a networking session response to the wireless networking device through the routing forwarding module after the secondary authentication is passed, so as to establish a VPDN communication tunnel between the wireless networking device and the server.
[0137] The embodiment performs primary authentication by receiving a networking session request initiated by the wireless networking device, completes necessary information configuration of networking, controls the authentication module to feed back tunnel protocol response information and downlink device routing information to the session management module after the primary authentication is passed, so as to synchronously realize establishment of a communication channel and post-routing of the downlink device of the wireless networking device, the session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module, and the routing forwarding module establishes a communication tunnel between the routing forwarding module and the tunnel network module according to the tunnel protocol response information, so as to perform secondary authentication, improve networking effect, and send a networking session response to the wireless networking device through the routing forwarding module after the secondary authentication is passed, so as to complete establishment of the communication tunnel and simplify the establishment steps of the traditional communication tunnel.
[0138] In an embodiment, the information forwarding module 40 is further configured to insert the downlink device routing information into a downlink device routing table by the session management module, so as to obtain a target downlink device routing table, generate first PFCP response information according to the target downlink device routing table and the tunnel protocol response information, and transmit the first PFCP response information to the routing forwarding module.
[0139] In an embodiment, the information issuing module 10 is further configured to establish a public data network channel with the wireless access device, receive terminal information and SIM card information of the wireless access device through the public data network channel, generate customized dialing information based on the terminal information and the SIM card information, and issue the customized dialing information to the wireless networking device through the public data network channel.
[0140] In an embodiment, the response feedback module 70 is further configured to send second PFCP response information to the session management module through the routing and forwarding module, the second PFCP response information carrying a networking session response, and send the networking session response to the wireless networking device through a first interface or send the networking session response to the access and mobility management module through a second interface, so that the access and mobility management module forwards the networking session response to the wireless networking device.
[0141] In an embodiment, the response feedback module 70 is further configured to, in response to a communication request of a lower-level device, acquire an uplink data packet carried in the communication request, encapsulate the uplink data packet to obtain an encapsulated uplink data packet, send the encapsulated uplink data packet to the tunnel network module through a VPDN tunnel, and decapsulate the encapsulated uplink data packet and forward it to a server.
[0142] In an embodiment, the response feedback module 70 is further configured to receive a downlink data packet sent by the server, encapsulate the downlink data packet to obtain an encapsulated downlink data packet, send the encapsulated downlink data packet to the routing and forwarding module through a VPDN tunnel, decapsulate the encapsulated downlink data packet to obtain a downlink data packet and routing information, and send the downlink data packet to a wireless networking device based on the routing information, so that the wireless networking device forwards the downlink data packet to a lower-level device corresponding to the routing information.
[0143] In an embodiment, the response feedback module 70 is further configured to perform networking data configuration on a to-be-networked device connected to the wireless networking device, and the networking data configuration includes domain name configuration and number card configuration.
[0144] The present application provides a post-routing networking device based on 5G VPDN. The post-routing networking device based on 5G VPDN comprises at least one processor and a memory in communication connection with the at least one processor. The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the post-routing networking method based on 5G VPDN in Embodiment One.
[0145] Reference will now be made to the drawings Figure 8 , which show structural diagrams of a 5G VPDN-based post-routing networking device suitable for implementing embodiments of the present application. The 5G VPDN-based post-routing networking device in embodiments of the present application can include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDA (Personal Digital Assistant), PAD (Portable Application Description), PMP (Portable Media Player), car terminals (e.g., car navigation terminals), and the like, as well as fixed terminals such as digital TVs, desktop computers, and the like. Figure 8 The 5G VPDN-based post-routing networking device shown is merely an example and should not impose any limitations on the functions and use range of embodiments of the present application.
[0146] As shown in Figure 8 , the 5G VPDN-based post-routing networking device can include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, or the like) that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1002 or loaded from a storage device 1003 into a random access memory (RAM) 1004. In the RAM 1004, various programs and data required for operation of the 5G VPDN-based post-routing networking device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. In general, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, and the like; output devices 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; the storage device 1003 including, for example, a magnetic tape, a hard disk, and the like; and a communication device 1009. The communication device 1009 can allow the 5G VPDN-based post-routing networking device to communicate wirelessly or by wire with other devices to exchange data. Although the 5G VPDN-based post-routing networking device is shown as having various systems, it should be understood that all of the systems shown are not required to be implemented or possessed. More or fewer systems can be alternatively implemented or possessed.
[0147] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the method shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network through a communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiments disclosed in the present application are executed.
[0148] The 5G VPDN-based post-routing networking device provided by the present application adopts the 5G VPDN-based post-routing networking method in the above-mentioned embodiments, and can solve the technical problem of 5G VPDN-based post-routing networking. Compared with the prior art, the 5G VPDN-based post-routing networking device provided by the present application has the same beneficial effects as the 5G VPDN-based post-routing networking method provided by the above-mentioned embodiments, and other technical features in the 5G VPDN-based post-routing networking device are the same as the features disclosed in the previous embodiment method, which will not be repeated here.
[0149] It should be understood that parts of the present application can be realized by hardware, software, firmware or a combination thereof. In the description of the above-mentioned embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0150] The above is merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0151] The present application provides a computer readable storage medium having stored thereon computer readable program instructions (i.e. computer program) for executing the 5G VPDN-based post-routing networking method in the above-mentioned embodiments.
[0152] The computer readable storage medium provided in the application may, for example, be a U disk, but is not limited to an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system, system, or device, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electric connection with one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiment, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer readable storage medium can be transmitted by any suitable medium, including but not limited to an electric wire, an optical cable, an RF (Radio Frequency), etc., or any suitable combination of the above.
[0153] The above computer readable storage medium can be contained in the post-routing networking device based on the 5G VPDN, or can exist separately without being assembled into the post-routing networking device based on the 5G VPDN.
[0154] The above computer readable storage medium carries one or more programs, which, when executed by the post-routing networking device based on the 5G VPDN, cause the post-routing networking device based on the 5G VPDN to perform the post-routing networking based on the 5G VPDN.
[0155] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0156] The flow diagrams and the block diagrams in the drawings are meant as methodological and functional description of implementations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may
[0157] The modules involved in the embodiments of the present application can be implemented in the form of software or in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself.
[0158] The readable storage medium provided by the present application is a computer readable storage medium, which stores computer readable program instructions (i.e. computer programs) for executing the above-mentioned 5G VPDN-based post-routing networking method, and can solve the technical problem of 5G VPDN-based post-routing networking. Compared with the prior art, the computer readable storage medium provided by the present application has the same beneficial effects as the 5G VPDN-based post-routing networking method provided by the above-mentioned embodiments, and will not be described here.
[0159] The application also provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of the method for 5G VPDN-based post-routing networking as described above.
[0160] The computer program product provided by the application can solve the technical problem of 5G VPDN-based post-routing networking. Compared with the prior art, the beneficial effects of the computer program product provided by the application are the same as those of the method for 5G VPDN-based post-routing networking provided by the above-mentioned embodiments, and are not described here.
[0161] The above only describes some embodiments of the application, and does not limit the patent scope of the application. Any equivalent structural transformation made by using the content of the specification and drawings, or direct / indirect application in other related technical fields within the technical concept of the application is included in the patent protection scope of the application.
Claims
1. A post-routing networking method based on 5G VPDN, characterized in that: The post-routing networking method based on 5G VPDN is applied to a networking management server, which includes at least: an access and mobility management module, a session management module, a routing forwarding module, a tunnel network module, and an authentication module; The post-routing networking method based on 5G VPDN includes: In response to a registration request initiated by a wireless networking device, issuing customized dialing information corresponding to the wireless networking device to the wireless networking device; receiving, through the access and mobility management module, a networking session request initiated by the wireless networking device, and performing an authentication according to the networking session request; After the authentication is passed once, the authentication module feeds back tunnel protocol response information and downlink device routing information to the session management module; The session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module; The routing forwarding module establishes a communication tunnel with the tunnel network module according to the tunnel protocol response information, and forwards the customized dialing information to the tunnel network module through the communication tunnel; The tunnel network module performs secondary authentication according to the customized dialing information; After the secondary authentication is passed, a networking session response is sent to the wireless networking device through the routing forwarding module to establish a VPDN communication tunnel between the wireless networking device and the server.
2. The post-routing networking method based on 5G VPDN according to claim 1, characterized in that: The session management module transmits the tunnel protocol response information and the downlink device routing information to the routing forwarding module, including: The session management module inserts the downstream device routing information into the downstream device routing table to obtain a target downstream device routing table; Generate first PFCP response information according to the target downlink device routing table and the tunnel protocol response information; The first PFCP response information is transmitted to the routing and forwarding module.
3. The post-routing networking method based on 5G VPDN according to claim 1, characterized in that: The step of sending customized dialing information corresponding to the wireless networking device to the wireless networking device in response to a registration request initiated by the wireless networking device includes: Establish a public data network channel with wireless access equipment; receiving terminal information and SIM card information of the wireless access device through the public data network channel; Generate customized dialing information based on the terminal information and SIM card information; The customized dialing information is sent to the wireless networking device through the public data network channel.
4. The post-routing networking method based on 5G VPDN according to claim 1, characterized in that: The sending of a networking session response to the wireless networking device through the routing forwarding module includes: Sending a second PFCP response message to the session management module through the routing forwarding module, where the second PFCP response message carries a networking session response; The networking session response is sent to the wireless networking device through the first interface, or the networking session response is sent to the access and mobility management module through the second interface, so that the access and mobility management module forwards the networking session response to the wireless networking device.
5. The post-routing networking method based on 5G VPDN according to any one of claims 1 to 4, characterized in that: The post-routing networking method based on 5G VPDN further includes: In response to a communication request from a downlink device, obtaining an uplink data packet carried in the communication request; The routing and forwarding module encapsulates the uplink data packet to obtain an encapsulated uplink data packet; Sending the encapsulated uplink data packet to the tunnel network module through the VPDN tunnel; The tunnel network module decapsulates the encapsulated uplink data packet and forwards it to the server.
6. The post-routing networking method based on 5G VPDN according to claim 5, characterized in that: The post-routing networking method based on 5G VPDN further includes: Receiving a downlink data packet sent by the server; The tunnel network module encapsulates the downlink data packet to obtain an encapsulated downlink data packet; The tunnel network module sends the encapsulated downlink data packet to the routing forwarding module through the VPDN tunnel; The routing forwarding module decapsulates the encapsulated downlink data packet to obtain a downlink data message and routing information; The downlink data message is sent to a wireless networking device based on the routing information, so that the wireless networking device forwards the downlink data message to a downlink device corresponding to the routing information.
7. The post-routing networking method based on 5G VPDN according to claim 5, characterized in that: The post-routing networking method based on 5G VPDN further includes: Performing networking data configuration on the wireless networking device and the device connected to the wireless networking device; The networking data configuration includes domain name configuration and number card configuration.
8. A post-routing networking device based on 5G VPDN, characterized in that: The post-routing networking device based on 5G VPDN includes: An information delivery module, configured to deliver customized dialing information corresponding to the wireless networking device to the wireless networking device in response to a registration request initiated by the wireless networking device; a one-time authentication module, configured to receive a networking session request initiated by the wireless networking device through the access and mobility management module, and perform a one-time authentication according to the networking session request; An information feedback module, configured to, after the authentication is passed once, feed back tunnel protocol response information and downlink device routing information from the authentication module to the session management module; An information forwarding module, configured for the session management module to transmit the tunnel protocol response information and the downlink device routing information to the routing forwarding module; a tunnel establishing module, configured for the routing and forwarding module to establish a communication tunnel with the tunnel network module according to the tunnel protocol response information, and to forward the customized dialing information to the tunnel network module through the communication tunnel; A secondary authentication module, configured for the tunnel network module to perform secondary authentication according to the customized dialing information; The response feedback module is used to send a networking session response to the wireless networking device through the routing forwarding module after the secondary authentication is passed, so as to establish a VPDN communication tunnel between the wireless networking device and the server.
9. A post-routing networking device based on 5G VPDN, characterized in that: The post-routing networking device based on 5G VPDN includes: a memory, a processor, and a post-routing networking program based on 5G VPDN stored on the memory and executable on the processor, wherein the post-routing networking program based on 5G VPDN is configured to implement the post-routing networking method based on 5G VPDN as described in any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium stores a post-routing networking program based on 5G VPDN, and when the post-routing networking program based on 5G VPDN is executed by the processor, the post-routing networking method based on 5G VPDN is implemented as described in any one of claims 1 to 7.
Citation Information
Patent Citations
5G wireless network connection method and electronic equipment
CN116419422A
Post-routing method for 5G system
CN117412351A