Service distribution method based on core network sharing type UPF, AMF entity and UPF entity
Patent Information
- Application Number
- CN202411804426.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2044-12-09
AI Technical Summary
一方面,当数据包需要经过多个网络节点进行转发时,网络延迟会显著增加,尤其是在带宽受限的情况下,处理效率直接关系到数据的传输速度,从而导致整体网络性能下降
[0042]本发明仅需一个共享UPF(一个本地共享型UPF实体或一个漫游地共享型UPF实体)即可实现分流,相较于现有的业务分流方案,能够提高业务分流效率。具体的有效效果如下:
Smart Images

Figure CN119729626B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network communication technology, and in particular relates to a service offloading method based on a core network shared UPF, an AMF entity, and a UPF entity. Background Technology
[0002] In the core network, traffic offloading is crucial for improving network efficiency and quality of service. A common offloading scheme is traffic scheduling based on User Plane Function (UPF).
[0003] Through intelligent traffic identification and control, UPF can accurately allocate data traffic to appropriate network paths based on different service types and user needs, optimizing bandwidth utilization and reducing latency. Combining Dedicated and General Data Network Names (DNNs) with UPF's Uplink Control Layer (ULCL) technology enables flexible and efficient traffic management, effectively distinguishing between internal network services and public network services. Therefore, the combination of Dedicated / General DNNs and UPF ULCL is increasingly becoming a key strategy for core network service offloading.
[0004] The specific implementation schemes for combining dedicated / general-purpose DNNs with UPF ULCL include the following combinations: First, by separating internal and public network services through general-purpose DNNs and ULCLs, a network architecture is formed, which includes "general-purpose DNN (such as 3gnet) + PCF subscription + designated TAI area + ULCL secondary anchor point + UPF primary anchor point"; Second, the combination of dedicated DNNs and ULCLs focuses on the campus, realizing the separation of internal and public network services, while effectively solving the problem of IP address conflicts; Finally, when the internal network is located in a city, general-purpose DNNs and dedicated DNNs can work together to achieve access separation through 5G access, while when using 4G access or roaming, users can manually switch to dedicated DNNs to access the internal network.
[0005] While traffic offloading solutions based on DNN and UPF ULCL offer many advantages, they also face several challenges. Firstly, network latency increases significantly when data packets need to be forwarded through multiple network nodes, especially under bandwidth constraints. Processing efficiency directly impacts data transmission speed, leading to a decline in overall network performance. Secondly, network bandwidth utilization efficiency is limited by router processing capabilities and the efficiency of UPF ULCL. If routers cannot efficiently handle large volumes of traffic, frequent network congestion will occur, affecting users' bandwidth access and ultimately reducing service quality. Summary of the Invention
[0006] The technical problem to be solved by this invention is to address the above-mentioned shortcomings of the prior art by proposing a service offloading method, AMF entity, and UPF based on a core network shared UPF.
[0007] This business offloading method only requires a single shared UPF (either a local shared UPF entity or a roaming shared UPF entity) to achieve offloading, which can effectively improve business offloading efficiency compared to existing business offloading solutions.
[0008] Firstly, this invention provides a service offloading method based on a core network shared UPF, which is applied to AMF (Access and Mobility Management).
[0009] Function (Access and Mobility Management Function) entity, the method includes the following steps:
[0010] Obtain terminal service requests;
[0011] Based on the service type of the terminal service request, a shared UPF entity is selected for data forwarding to achieve service offloading based on the core network shared UPF;
[0012] Specifically, if the terminal service request is a local public network service or a local private network service, a local shared UPF entity is selected for data traffic forwarding; if the terminal service request is a roaming public network service or a roaming private network service, a roaming shared UPF entity is selected for data traffic forwarding; the data traffic is the traffic carried by the terminal service request.
[0013] Furthermore, the step of selecting a local shared UPF entity for data forwarding specifically includes the following steps:
[0014] Based on the private network DNN and terminal IP address carried in the terminal service request, a local shared UPF entity is selected so that the local shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user's detailed routing table.
[0015] Specifically, if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0016] Furthermore, the selection of a roaming shared UPF entity for data forwarding specifically includes the following steps:
[0017] Based on the private network DNN and terminal IP address carried in the terminal service request, select the roaming shared UPF entity so that the roaming shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user's detailed routing table.
[0018] Specifically, if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network; if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0019] Secondly, this invention provides a service offloading method based on a core network shared UPF, the method being applied to a UPF entity, and the method comprising the following steps:
[0020] Receive terminal service requests forwarded by the AMF entity;
[0021] Determine whether the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table:
[0022] If the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the data traffic is sent to the private network; if the IP address to be accessed in the terminal service request is not a private network segment in the detailed routing table, the data traffic is forwarded to the security policy module, so that the security policy module translates different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmits the data traffic to the public network through the GRE tunnel, so as to realize service diversion based on the core network shared UPF.
[0023] The data traffic refers to the traffic carried by terminal service requests, and the detailed routing table is established by the routing module for the user.
[0024] Thirdly, the present invention provides an AMF entity, the AMF entity comprising:
[0025] The acquisition unit is used to acquire terminal service requests;
[0026] The selection unit, connected to the acquisition unit, is used to select a shared UPF entity for data forwarding according to the service type of the terminal service request, so as to realize service diversion based on the core network shared UPF.
[0027] Specifically, if the terminal service request is a local public network service or a local private network service, a local shared UPF entity is selected for data traffic forwarding; if the terminal service request is a roaming public network service or a roaming private network service, a roaming shared UPF entity is selected for data traffic forwarding; the data traffic is the traffic carried by the terminal service request.
[0028] Furthermore, the selection unit includes a first selection unit;
[0029] The first selection unit is connected to the acquisition unit and is used to select a local shared UPF entity based on the private network DNN and terminal IP address carried in the terminal service request, so that the local shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table.
[0030] Specifically, if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0031] Furthermore, the selection unit also includes a second selection unit;
[0032] The second selection unit is connected to the acquisition unit and is used to select a roaming shared UPF entity based on the private network DNN and terminal IP address carried in the terminal service request, so that the roaming shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table.
[0033] Specifically, if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network; if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0034] Fourthly, the present invention provides a UPF entity, the UPF entity comprising:
[0035] The receiving unit is used to receive terminal service requests forwarded by the AMF entity.
[0036] The determination unit, connected to the receiving unit, is used to determine whether the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table;
[0037] The first forwarding unit, connected to the determination unit, is used to send the data traffic to the private network when the determination unit determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table.
[0038] The second forwarding unit, connected to the determination unit, is used to forward the data traffic to the security policy module when the determination unit determines that the IP address to be accessed in the terminal service request is not a private network segment in the detailed routing table. This allows the security policy module to translate different IP addresses to be accessed into public IP addresses on different virtual firewalls and then transmit the data traffic to the public network through the GRE tunnel, thereby achieving service diversion based on the core network shared UPF.
[0039] The data traffic refers to the traffic carried by terminal service requests, and the detailed routing table is established by the routing module for the user.
[0040] Fifthly, the present invention provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the service offloading method based on a core network shared UPF as described in the first aspect, or executes the service offloading method based on a core network shared UPF as described in the second aspect.
[0041] In a sixth aspect, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the service offloading method based on a core network shared UPF as described in the first aspect, or implements the service offloading method based on a core network shared UPF as described in the second aspect.
[0042] This invention requires only one shared UPF (either a local shared UPF entity or a roaming shared UPF entity) to achieve traffic offloading, which improves traffic offloading efficiency compared to existing solutions. The specific effective effects are as follows:
[0043] 1. Intelligent UPF Entity Selection: This invention can intelligently select the most suitable shared UPF entity based on different service request types (such as local public network / private network services or roaming public network / private network services). Upon receiving a terminal service request, this invention analyzes the requested service type and quickly determines the optimal UPF entity for data forwarding. This service type-based selection method optimizes resource allocation, ensures data flows along the optimal path, thereby improving network response speed and service quality.
[0044] 2. Fine-grained Traffic Management: This invention achieves fine-grained data traffic management by analyzing the private network DNN and IP address in terminal service requests. The locally shared UPF entity uses the user's detailed routing table to determine the affiliation of the IP address to be accessed. When the IP address belongs to the private network segment, the traffic is directly forwarded to the private network to ensure data flow security; if the IP address is not in the private network segment, the traffic is forwarded to the security policy module and then transmitted to the public network via a GRE tunnel after passing through the virtual firewall. This design not only improves the flexibility of data processing but also enhances network security.
[0045] 3. Flexible Roaming Service Handling: When handling roaming services, this invention can intelligently select a shared UPF entity in the roaming location for data forwarding, thereby improving the user's access experience in different network environments. The shared UPF entity in the roaming location determines the IP address to be accessed based on the user's detailed routing table. If the IP address belongs to a private network segment, the data flow will be directly forwarded to the private network; otherwise, the traffic will be forwarded to the security policy module to ensure the security of public network access. This flexible strategy ensures that users can smoothly access the required network resources during roaming, maintaining the continuity and stability of services.
[0046] 4. Enhanced Network Security: This invention introduces a security policy module and a virtual firewall, effectively improving network security. For IP addresses outside the dedicated network segment, the data stream undergoes IP address translation via the virtual firewall before being transmitted to the public network through a GRE tunnel. This method effectively defends against potential security threats and ensures the confidentiality and integrity of data communication.
[0047] 5. Optimize Bandwidth Usage and Reduce Latency: This invention optimizes bandwidth utilization and reduces latency through intelligent routing. The system can dynamically distribute traffic according to different service types and needs. In both local and roaming scenarios, selecting an appropriate shared UPF for data forwarding can effectively shorten data transmission paths, reduce latency, and thus improve user experience.
[0048] 6. Supports Diverse Business Needs: This invention can flexibly adapt to various business scenarios, supporting the different needs of local and roaming users. Based on different DNN service requests, this invention can flexibly handle intranet and public network traffic, meeting diverse service requirements. This provides network operators with richer service options and further enhances the user experience. Attached Figure Description
[0049] Figure 1 This is a diagram illustrating the overall framework of service offloading based on a core network shared UPF in this embodiment of the invention.
[0050] Figure 2 This is a flowchart of the service offloading method based on a core network shared UPF in an embodiment of the present invention;
[0051] Figure 3 This is a flowchart illustrating the specific implementation of service offloading based on a core network shared UPF in this embodiment of the invention.
[0052] Figure 4 This is a schematic diagram of the network connection status in an embodiment of the present invention;
[0053] Figure 5 This is a schematic diagram of UPF comparison in an embodiment of the present invention;
[0054] Figure 6 This is a schematic diagram of a service offloading device based on a core network shared UPF in an embodiment of the present invention;
[0055] In the attached figures, 10 is the acquisition unit and 20 is the selection unit. Detailed Implementation
[0056] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0057] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.
[0058] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.
[0059] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.
[0060] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.
[0061] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.
[0062] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0063] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.
[0064] Example 1:
[0065] like Figure 1 and Figure 2As shown, this embodiment provides a service offloading method based on a core network shared UPF (User Plane Function Module), which is applied to the AMF (Access Control Function) entity. The AMF entity's network access control module is responsible for managing user equipment access and mobility, performing core functions such as user authentication, access authorization, and session management to ensure secure access and service continuity for devices in the 5G network. It also closely collaborates with other network function modules (such as UDM and UPF) to achieve dynamic network slicing and quality of service management. This module is a key component of the 5G network architecture, providing users with an efficient and reliable connection experience. This embodiment provides a service offloading method based on a core network shared UPF, which can efficiently separate private network and public network access through a single UPF. In specific operation, the system uses a detailed routing table to accurately determine the user's access target: when the route in the user's access request is within the detailed routing table, the data will be directly forwarded to the private network; if the requested route is not in the routing table, the data will be forwarded to the security policy module for processing. The security policy module is responsible for translating the private network IP address into a public IP address to enable subsequent public network access. This approach significantly simplifies the network structure by using only a single UPF, while simultaneously improving data processing efficiency. Furthermore, this service offloading method is applicable to various scenarios, particularly valuable in enterprise intranets and mobile communication environments. In remote work environments, employees can securely access private network resources by connecting to the private network DNN (Data Network Name), regardless of their location, while also enabling flexible public network access through detailed routing tables. This design ensures user security and convenience under different network requirements, improving overall work efficiency. In mobile communication networks, this method provides operators with an efficient resource management solution, enabling users to quickly respond to diverse service needs, thereby enhancing user experience and satisfaction.
[0066] The method includes the following steps:
[0067] Obtain terminal service requests;
[0068] Based on the service type of the terminal service request, a shared UPF entity is selected for data forwarding to achieve service offloading based on the core network shared UPF;
[0069] Specifically, if the terminal service request is a local public network service or a local private network service, a local shared UPF entity is selected for data traffic forwarding; if the terminal service request is a roaming public network service or a roaming private network service, a roaming shared UPF entity is selected for data traffic forwarding; the data traffic is the traffic carried by the terminal service request.
[0070] As a specific implementation method, the selection of a local shared UPF entity for data forwarding includes the following steps:
[0071] Based on the private network DNN and terminal IP address carried in the terminal service request, a local shared UPF entity is selected so that the local shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user's detailed routing table.
[0072] Specifically, if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0073] As a specific implementation method, the selection of a roaming shared UPF entity for data forwarding includes the following steps:
[0074] Based on the private network DNN and terminal IP address carried in the terminal service request, select the roaming shared UPF entity so that the roaming shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user's detailed routing table.
[0075] Specifically, if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network; if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0076] Finally, detailed examples are provided below:
[0077] Suppose a user at location A needs to access both the public and private networks, and frequently travels to location B. The user's access scenarios can be categorized into four cases: accessing the public network at location A, accessing the private network at location A, accessing the public network at location B, and accessing the private network at location B. When the user accesses the network at location A, the network access control module can directly and quickly forward their data to the shared UPF (User Plane Function Module). When the user is at location B, the network access control module first forwards the user's data to the access class UPF at location B, and then the access class UPF further transmits the data to the shared UPF, ensuring that the user's data is processed efficiently and uniformly regardless of whether it is local or roaming access.
[0078] A detailed routing table is configured in the routing module, which includes explicitly defined private network address ranges. When user data is received, the routing module determines the user's access address (IP address). If the IP is in the detailed routing table, it indicates that the user wishes to access the private network, and the data will be forwarded directly to the private network. If the IP is not in the detailed routing table, it is assumed to be a public IP address, and the data is forwarded to the security policy module (firewall) for further processing. This design ensures that user requests are correctly identified and processed, while guaranteeing network security and smooth operation.
[0079] To avoid configuration conflicts in the private network routing tables of different users, the security policy module needs to configure a unique virtual firewall for each user to achieve secure data isolation and effective management. For example, user A's detailed routing table is MA, and its corresponding virtual firewall is FWA; user B uses the detailed routing table MB and the virtual firewall FWB. When user A accesses an IP address outside the private network, the virtual firewall FWA will translate it into a public IP address; similarly, the virtual firewall FWB will also process user B's public network access. Furthermore, the terminal device module is responsible for establishing GRE tunnels to securely transmit data processed and forwarded from the virtual firewall to the public network, thereby ensuring the security and stability of data flow.
[0080] like Figure 4 As shown, this embodiment implements Virtual Firewall (VSYS) technology in the security policy module to achieve efficient isolation of different services. This technology allows the creation of multiple virtual firewall instances on the same physical firewall, enabling each instance to independently manage its specific traffic and security policies. Furthermore, the virtual firewall translates the IP addresses used by users to access the public network, ensuring that each user's services maintain their independence and security while successfully accessing the public network. This design not only improves the utilization efficiency of network resources but also enhances system security, ensuring that data from different services does not interfere with or leak.
[0081] like Figure 5 As shown, this embodiment employs a shared UPF (User Plane Function Module) and its configured detailed flows. The system utilizes the detailed routing table to accurately identify specific traffic accessing the private network and forwards it directly to the private network. Simultaneously, all requests not belonging to a specific traffic type are forwarded to the public network through a security policy module. Compared to traditional UCCL systems, this design eliminates the need for multiple UPFs to achieve traffic splitting, significantly simplifying the network architecture and improving overall efficiency. It allows for efficient management and splitting of different types of network traffic using only a single UPF.
[0082] The user plane function module (shared UPF) in this embodiment can effectively separate private network and public network access through only one UPF. In addition, this embodiment also configures only one private network DNN (data network name), thereby significantly improving the efficiency of service diversion.
[0083] This embodiment supports flexible access in various network environments, enabling seamless connectivity between the intranet and the public network regardless of whether the user is on a 4G or 5G network or roaming across regions. This design eliminates geographical and network standard limitations, providing users with a more convenient network access experience.
[0084] Furthermore, this embodiment ensures that latency and bandwidth metrics on the network side remain consistent with the public network, thereby significantly improving the user experience. On the network side, no new equipment or additional investment is required; existing equipment can fully utilize its redundancy protection capabilities to ensure stable operation of public network access services even in the event of a failure within the private network. This efficient solution not only reduces operating costs but also enhances network security and reliability, allowing users to receive high-quality service under any circumstances.
[0085] Example 2:
[0086] like Figure 1 As shown, this embodiment provides a service offloading method based on a core network shared UPF. The method is applied to a UPF entity and includes the following steps:
[0087] Receive terminal service requests forwarded by the AMF entity;
[0088] Determine whether the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table:
[0089] If the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the data traffic is sent to the private network; if the IP address to be accessed in the terminal service request is not a private network segment in the detailed routing table, the data traffic is forwarded to the security policy module, so that the security policy module translates different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmits the data traffic to the public network through the GRE tunnel, so as to realize service diversion based on the core network shared UPF.
[0090] The data traffic refers to the traffic carried by terminal service requests, and the detailed routing table is established by the routing module for the user.
[0091] The User Plane Function (UPF) entity is responsible for efficiently managing the forwarding and processing of user data in 5G networks, ensuring smooth data connectivity between the User Equipment (UE) and the external network, and supporting traffic management, session control, and quality of service assurance. Through collaboration with core network functions such as the AMF, the UPF enables real-time transmission, monitoring, and optimization of user data, efficiently meeting diverse network requirements.
[0092] The method in this embodiment corresponds to the method in Embodiment 1, and together they complete the service offloading based on the core network shared UPF.
[0093] Example 3:
[0094] like Figure 6 As shown, this embodiment provides an AMF entity, the AMF entity comprising:
[0095] Acquisition unit 10 is used to acquire terminal service requests;
[0096] Selection unit 20, connected to acquisition unit 10, is used to select a shared UPF entity for data forwarding according to the service type of the terminal service request, so as to realize service diversion based on core network shared UPF;
[0097] Specifically, if the terminal service request is a local public network service or a local private network service, a local shared UPF entity is selected for data traffic forwarding; if the terminal service request is a roaming public network service or a roaming private network service, a roaming shared UPF entity is selected for data traffic forwarding; the data traffic is the traffic carried by the terminal service request.
[0098] In one specific implementation, the selection unit includes a first selection unit;
[0099] The first selection unit is connected to the acquisition unit and is used to select a local shared UPF entity based on the private network DNN and terminal IP address carried in the terminal service request, so that the local shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table.
[0100] Specifically, if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0101] In a more specific implementation, the selection unit further includes a second selection unit;
[0102] The second selection unit is connected to the acquisition unit and is used to select a roaming shared UPF entity based on the private network DNN and terminal IP address carried in the terminal service request, so that the roaming shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table.
[0103] Specifically, if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network; if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
[0104] The AMF entity in this embodiment can perform the method in embodiment 1.
[0105] Example 4:
[0106] This embodiment provides a UPF entity, the UPF entity comprising:
[0107] The receiving unit is used to receive terminal service requests forwarded by the AMF entity.
[0108] The determination unit, connected to the receiving unit, is used to determine whether the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table.
[0109] The first forwarding unit, connected to the determination unit, is used to send the data traffic to the private network when the determination unit determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table.
[0110] The second forwarding unit, connected to the determination unit, is used to forward the data traffic to the security policy module when the determination unit determines that the IP address to be accessed in the terminal service request is not a private network segment in the detailed routing table. This allows the security policy module to translate different IP addresses to be accessed into public IP addresses on different virtual firewalls and then transmit the data traffic to the public network through the GRE tunnel, thereby achieving service diversion based on the core network shared UPF.
[0111] The data traffic refers to the traffic carried by terminal service requests, and the detailed routing table is established by the routing module for the user.
[0112] The UPF entity in this embodiment can execute the method in embodiment 2.
[0113] Example 5:
[0114] This embodiment provides an electronic device, which includes a memory and a processor. The memory stores a computer program. When the processor runs the computer program stored in the memory, the processor executes the service offloading method based on a core network shared UPF as described in Embodiment 1, or executes the service offloading method based on a core network shared UPF as described in Embodiment 2.
[0115] Example 6:
[0116] This embodiment provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the service offloading method based on a core network shared UPF as described in Embodiment 1, or the service offloading method based on a core network shared UPF as described in Embodiment 2.
[0117] Example 7:
[0118] This embodiment provides a core network shared UPF private network service offloading system, which corresponds to the method in Embodiment 1. The system includes: a network access control module, a user plane function module, a routing selection module, a security policy module, and a terminal device module.
[0119] Network Access Control Module: This module is responsible for identifying user access requirements, configuring the private network DNN according to different service types, and selecting an appropriate UPF for data forwarding to ensure the correct allocation of traffic.
[0120] The user plane module is responsible for handling the forwarding and routing of user data packets. Based on the configuration information from the network access control module, this module further separates traffic between the internal network and the public network according to the policies of the routing selection module.
[0121] Routing Module: This module is responsible for separating internal network and public network traffic according to the defined detailed routing policies. It provides specific routing information for different data to the user plane function modules, ensuring that internal network service traffic is delivered directly to the internal network via dedicated lines, while public network service traffic is forwarded through the default route.
[0122] Security Policy Module: The security policy module is responsible for controlling public network access in the system. By enabling the Virtual Firewall (VSYS), this module can effectively manage access permissions for different business traffic, ensuring the secure separation of public network traffic.
[0123] Terminal device module: This module serves as the entry point for connecting to the public network. It establishes a secure channel with the virtual firewall through the GRE tunnel to ensure the smooth transmission of public network business traffic.
[0124] Specifically, such as Figure 3 As shown, the specific process implemented in this embodiment is as follows:
[0125] S1: When a user accesses the network, the network access control module identifies the type of service requested by the user and selects an appropriate UPF for data forwarding based on the type of service requirement.
[0126] Specifically, when a user accesses the network using only a private network DNN, and the user's service requirement is a roaming service, the network control module selects the access class UPF in the roaming location for data forwarding, and the roaming access class UPF then selects the user plane function module for data forwarding. When the user's service requirement is a local service, the network access control module will select the user plane function module for data forwarding.
[0127] S2: The user plane function module receives service information from the network access control module, and the routing module determines how the user plane function module processes data traffic based on the service type.
[0128] Specifically, the routing module establishes a detailed routing table for each user. It then determines the IP address the user wants to access. If the IP address is within a private network segment in the detailed routing table, the routing module instructs the user plane module to forward the data traffic to the private network. If the IP address is not within a private network segment in the detailed routing table, it means the IP address belongs to a public network segment in the detailed routing table. In this case, the IP address is not processed, is treated as the default route, and the data traffic is sent to the security policy module.
[0129] S3: The security policy module enables the virtual firewall, configures traffic access permissions, and establishes a connection with the user plane function module to ensure secure isolation of traffic.
[0130] Specifically, the security policy module enables different virtual firewalls for different user accesses, ensuring secure traffic isolation between different users and between private networks and the public network. For example, the virtual firewalls corresponding to users A, B, and C are FWA, FWB, and FWC, respectively, and FWA, FWB, and FWC each establish connections with the user's plane function module. The security policy module translates the IP addresses that different users want to access into public IP addresses on different virtual firewalls.
[0131] S4: The security policy module and the terminal device module establish a secure communication channel through the GRE tunnel. Public network service traffic is securely transmitted to the public network through the GRE tunnel.
[0132] Specifically, the terminal device module establishes a tunnel connection with the security policy module, and forwards the received data to the public network.
[0133] The User Plane Function Module (Shared UPF) in this embodiment can effectively separate private network and public network access using only a single UPF. Specifically, traffic management is achieved through the configuration of a detailed routing table: when a user's requested access destination route is in the detailed routing table, the traffic will be directly forwarded to the private network; if it is not in the routing table, the data will be forwarded to the security policy module, and subsequent public network access will be handled by the security policy module. This design significantly simplifies the network architecture, improves system operating efficiency, and allows for the effective management of different types of traffic using only a single UPF.
[0134] Furthermore, this embodiment configures only one private network DNN (Data Network Name) to route public network access requests through detailed routes shared by the UPF. To enable public network access, the security policy module translates the private network IP address into a public IP address. By configuring only one private network DNN, the system further optimizes configuration efficiency, ensures full utilization of network resources, simplifies overall network management, and improves the convenience of configuration and maintenance.
[0135] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A service offloading method based on a core network shared UPF, applied to an AMF entity, characterized in that, The method includes the following steps: Obtain terminal service requests; only one private network DNN is configured. Based on the service type of the terminal service request, a shared UPF entity is selected for data forwarding to achieve service offloading based on the core network shared UPF; the service type includes local public network services, local private network services, roaming public network services, or roaming private network services; If the terminal service request is a local public network service or a local private network service, then a local shared UPF entity is selected for data traffic forwarding; if the terminal service request is a roaming public network service or a roaming private network service, then a roaming shared UPF entity is selected for data traffic forwarding; the data traffic is the traffic carried by the terminal service request. The step of selecting a local shared UPF entity for data traffic forwarding specifically includes the following steps: Based on the private network DNN and terminal IP address carried in the terminal service request, a local shared UPF entity is selected so that the local shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table. If the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel. The process of selecting a shared UPF entity for roaming locations to forward data traffic includes the following steps: Based on the private network DNN and terminal IP address carried in the terminal service request, a roaming shared UPF entity is selected so that the roaming shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table. If the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network. If the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
2. A service offloading method based on a core network shared UPF, applied to a UPF entity, characterized in that, The method includes the following steps: Receive terminal service requests forwarded by the AMF entity; Determine whether the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table: If the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the data traffic is sent to the private network; if the IP address to be accessed in the terminal service request is not a private network segment in the detailed routing table, the data traffic is forwarded to the security policy module, so that the security policy module translates different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmits the data traffic to the public network through the GRE tunnel, so as to realize service diversion based on the core network shared UPF. The data traffic refers to the traffic carried by terminal service requests, and the detailed routing table is established by the routing module for the user. The data traffic forwarding includes selecting a local shared UPF entity for data traffic forwarding and selecting a roaming shared UPF entity for data traffic forwarding; The step of selecting a local shared UPF entity for data traffic forwarding specifically includes the following steps: If the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel. The process of selecting a shared UPF entity for roaming locations to forward data traffic includes the following steps: If the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network; if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel. In this configuration, only one private network DNN is configured. Both the local shared UPF entity and the roaming shared UPF entity are selected based on the private network DNN and the terminal IP address carried in the terminal service request. They are used to perform different data traffic forwarding on the IP address to be accessed in the service request according to the user detailed routing table.
3. An AMF entity, characterized in that, The AMF entity includes: The acquisition unit is used to acquire terminal service requests; only one private network DNN is configured. The selection unit, connected to the acquisition unit, is used to select a shared UPF entity for data forwarding according to the service type of the terminal service request, so as to realize service offloading based on the core network shared UPF; the service type includes local public network service, local private network service, roaming public network service or roaming private network service; If the terminal service request is a local public network service or a local private network service, then a local shared UPF entity is selected for data traffic forwarding; if the terminal service request is a roaming public network service or a roaming private network service, then a roaming shared UPF entity is selected for data traffic forwarding; the data traffic is the traffic carried by the terminal service request. The step of selecting a local shared UPF entity for data traffic forwarding specifically includes the following steps: Based on the private network DNN and terminal IP address carried in the terminal service request, a local shared UPF entity is selected so that the local shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table. If the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel. The process of selecting a shared UPF entity for roaming locations to forward data traffic includes the following steps: Based on the private network DNN and terminal IP address carried in the terminal service request, a roaming shared UPF entity is selected so that the roaming shared UPF entity forwards different data traffic to the IP address to be accessed in the terminal service request according to the user detailed routing table. If the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network. If the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel.
4. A UPF entity, characterized in that, The UPF entity includes: The receiving unit is used to receive terminal service requests forwarded by the AMF entity. The determination unit, connected to the receiving unit, is used to determine whether the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table; The first forwarding unit, connected to the determination unit, is used to send the data traffic to the private network when the determination unit determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table. The second forwarding unit, connected to the determination unit, is used to forward the data traffic to the security policy module when the determination unit determines that the IP address to be accessed in the terminal service request is not a private network segment in the detailed routing table. This allows the security policy module to translate different IP addresses to be accessed into public IP addresses on different virtual firewalls and then transmit the data traffic to the public network through the GRE tunnel, thereby achieving service diversion based on the core network shared UPF. The data traffic refers to the traffic carried by terminal service requests, and the detailed routing table is established by the routing module for the user. The data traffic forwarding includes selecting a local shared UPF entity for data traffic forwarding and selecting a roaming shared UPF entity for data traffic forwarding; The step of selecting a local shared UPF entity for data traffic forwarding specifically includes the following steps: If the local shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the local shared UPF entity will send the data traffic to the private network; if the local shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the local shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel. The process of selecting a shared UPF entity for roaming locations to forward data traffic includes the following steps: If the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is a private network segment in the detailed routing table, the roaming shared UPF entity will send the data traffic to the private network; if the roaming shared UPF entity determines that the IP address to be accessed in the terminal service request is not a private network segment in the user's detailed routing table, the roaming shared UPF entity will forward the data traffic to the security policy module, so that the security policy module can translate different IP addresses to be accessed into public IP addresses on different virtual firewalls, and then transmit the data traffic to the public network through the GRE tunnel. In this configuration, only one private network DNN is configured. Both the local shared UPF entity and the roaming shared UPF entity are selected based on the private network DNN and the terminal IP address carried in the terminal service request. They are used to perform different data traffic forwarding on the IP address to be accessed in the service request according to the user detailed routing table.
5. An electronic device, characterized in that, It includes a memory and a processor. The memory stores a computer program. When the processor runs the computer program stored in the memory, the processor executes the service offloading method based on a core network shared UPF according to claim 1, or executes the service offloading method based on a core network shared UPF according to claim 2.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the service offloading method based on a core network shared UPF as described in claim 1, or the service offloading method based on a core network shared UPF as described in claim 2.
Citation Information
Patent Citations
Park terminal private network and public network access method and device and storage medium
CN117336882A
Data distribution method, system and device and storage medium
CN117998367A