Data transmission method, apparatus, medium, device and product

By establishing a dedicated virtual transmission channel between the FMC gateway and the private network gateway, the risk of data leakage in home smart terminals is solved, enabling secure and efficient access to private network data and reducing the complexity of system upgrades.

CN119922042BActive Publication Date: 2025-12-26CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510128183.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-12-26
Estimated Expiration
2045-01-27

AI Technical Summary

Technical Problem

Data from smart home terminals is at risk of leakage when accessed remotely via public cloud over the internet, and traditional methods require upgrading existing network elements and operator systems, which is highly complex.

Method used

By setting up a dedicated virtual transmission channel between the fixed-mobile converged FMC gateway and multiple private network gateways, access requests from terminal devices are received, the target private network gateway is identified, and the target service data is obtained through the dedicated virtual transmission channel, thus avoiding public network transmission.

Benefits of technology

It improves the security of data transmission, reduces the complexity of accessing private network data, and eliminates the need to upgrade existing network equipment. Simply build a new FMC gateway to accurately access private network data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922042B_ABST
    Figure CN119922042B_ABST
Patent Text Reader

Abstract

The application discloses a data transmission method and device, medium, equipment and product, relates to the technical field of communication, and is used for improving the security of a terminal device. The method is applied to a fixed mobile convergence (FMC) gateway, a special virtual transmission channel is arranged between the FMC gateway and each private network gateway in a plurality of private network gateways, and the method comprises the following steps: receiving an access request message of a terminal device; the access request message is used for requesting target service data; determining a target private network gateway corresponding to a source address of the terminal device in the plurality of private network gateways; forwarding the access request message to the target private network gateway through the special virtual transmission channel between the target private network gateway, so as to obtain the target service data; and sending the target service data to the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of communication, and in particular, to a data transmission method, device, medium, equipment and product. BACKGROUND

[0002] With the rapid development of Internet technology, a terminal device can remotely access data of a home smart terminal (such as a home camera). When the terminal device remotely accesses the data of the home smart terminal, the data of the home smart terminal needs to be forwarded to the terminal device through an Internet public cloud, and the data of the home smart terminal is at risk of data leakage.

[0003] In order to reduce the risk of data leakage of the home smart terminal, the functions of some network elements such as the existing network UPF network element and the UDM network element can be upgraded and enhanced, incremental development of the operator BOSS system is also needed, and a private network home UPF network element is newly built to access the data of the home smart terminal based on the private network, which has a high complexity. SUMMARY

[0004] The present application provides a data transmission method, device, medium, equipment and product for improving the security of the data of the home smart terminal.

[0005] To achieve the above-mentioned purpose, the present application adopts the following technical solutions:

[0006] In a first aspect, a data transmission method is provided, applied to a fixed mobile convergence (FMC) gateway, and a dedicated virtual transmission channel is set between the FMC gateway and each private network gateway in a plurality of private network gateways. The method comprises: receiving an access request message of a terminal device; the access request message is used to request target service data; determining a target private network gateway in the plurality of private network gateways corresponding to a source address of the terminal device; forwarding the access request message to the target private network gateway through the dedicated virtual transmission channel between the FMC gateway and the target private network gateway to obtain the target service data; and sending the target service data to the terminal device.

[0007] Optionally, determining the target private network gateway in the plurality of private network gateways corresponding to the source address of the terminal device comprises: obtaining an initial mapping relationship; the initial mapping relationship comprises a mapping relationship between a plurality of source addresses and a plurality of private network gateways; in a case where the initial mapping relationship does not include the source address of the terminal device, obtaining configuration information of the terminal device; and determining the target private network gateway in the plurality of private network gateways corresponding to the source address of the terminal device according to the configuration information.

[0008] Optionally, the configuration information of the terminal device is acquired by: sending a first indication message to a UPF network element; the first indication message is used to acquire the configuration information; and receiving an auxiliary http packet from the UPF network element to acquire the configuration information of the terminal device; the auxiliary http packet is obtained according to the source address and the identification information of the terminal device.

[0009] Optionally, the auxiliary http packet is sent by the UPF network element in a case where a URL address of an original http packet is a target URL address; the target URL address is a preconfigured URL address; and the original http packet is sent by the terminal device in response to the first indication message.

[0010] Optionally, the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways is determined according to the configuration information by: determining whether the terminal device has access permission of the target private network device according to the identification information; and determining the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways in a case where the terminal device has the access permission of the target private network device.

[0011] Based on the technical solutions provided in the present application, when the terminal device needs to access target service data in a private network device, the FMC gateway can determine the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways, and then acquire the target service data in the target private network device according to the target private network gateway. In this way, the process does not need to be transmitted in a public network, thereby improving the security of data transmission. Moreover, the process does not need to upgrade existing network devices, but only needs to newly build the FMC gateway, so that the private network matched with the terminal device can be accurately determined, and the data in the private network that needs to be accessed can be accessed, thereby reducing the complexity of accessing the data in the private network.

[0012] In a second aspect, a data transmission method is provided, and is applied to a terminal device. The method comprises the following steps: sending an access request message to a fixed mobile convergence (FMC) gateway; the access request message is used to request target service data; the FMC gateway determines a target private network gateway corresponding to a source address of the terminal device in a plurality of private network gateways, and forwards the access request message to the target private network gateway through a dedicated virtual transmission channel between the FMC gateway and the target private network gateway, so as to acquire the target service data; and receiving the target service data.

[0013] Optionally, the first indication message of the UPF network element is received; the first indication message is used to acquire the configuration information; and an original http packet is sent to the UPF network element, so that the UPF network element sends an auxiliary http packet to the FMC gateway in a case where a URL address of the original http packet is a target URL address; the auxiliary http packet is obtained according to the source address and the identification information of the terminal device.

[0014] In a third aspect, a data transmission apparatus is provided, which is applied to a fixed mobile convergence (FMC) gateway, and a dedicated virtual transmission channel is arranged between the FMC gateway and each private network gateway in a plurality of private network gateways. The apparatus comprises a receiving unit, a processing unit and a sending unit. The receiving unit is configured to receive an access request message of a terminal device, wherein the access request message is used to request target service data. The processing unit is configured to determine a target private network gateway corresponding to a source address of the terminal device in the plurality of private network gateways. The sending unit is configured to forward the access request message to the target private network gateway through the dedicated virtual transmission channel between the FMC gateway and the target private network gateway, so as to obtain the target service data. The sending unit is further configured to send the target service data to the terminal device.

[0015] Optionally, the processing unit is specifically configured to: obtain an initial mapping relationship, wherein the initial mapping relationship comprises a mapping relationship between a plurality of source addresses and a plurality of private network gateways; obtain configuration information of the terminal device in a case where the initial mapping relationship does not comprise the source address of the terminal device; and determine the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways according to the configuration information.

[0016] Optionally, the receiving unit is specifically configured to: send a first indication message to a UPF network element, wherein the first indication message is used to obtain the configuration information; and receive an auxiliary HTTP packet from the UPF network element, so as to obtain the configuration information of the terminal device, wherein the auxiliary HTTP packet is obtained according to the source address and identification information of the terminal device.

[0017] Optionally, the auxiliary HTTP packet is sent by the UPF network element in a case where a URL address of an original HTTP packet is a target URL address, wherein the target URL address is a preconfigured URL address, and the original HTTP packet is sent by the terminal device in response to the first indication message.

[0018] Optionally, the processing unit is specifically configured to: determine whether the terminal device has access permission of the target private network device according to the identification information; and determine the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways in a case where the terminal device has the access permission of the target private network device.

[0019] In a fourth aspect, a data transmission apparatus is provided, which is applied to a terminal device. The apparatus comprises a sending unit and a receiving unit. The sending unit is configured to send an access request message to a fixed mobile convergence (FMC) gateway, wherein the access request message is used to request target service data. The FMC gateway determines a target private network gateway corresponding to a source address of the terminal device in a plurality of private network gateways, and forwards the access request message to the target private network gateway through a dedicated virtual transmission channel between the FMC gateway and the target private network gateway, so as to obtain the target service data. The receiving unit is configured to receive the target service data.

[0020] Optionally, the receiving unit is further configured to receive a first indication message of the UPF network element; the first indication message is used to obtain configuration information; and the sending unit is further configured to send the original http packet to the UPF network element, so that the UPF network element sends an auxiliary http packet to the FMC gateway when a URL address of the original http packet is a target URL address; the auxiliary http packet is obtained according to the source address and the identification information of the terminal device.

[0021] In a fifth aspect, a data transmission apparatus is provided, which can implement the functions performed by the data transmission apparatus in the above aspects or possible designs, and the functions can be implemented by hardware. In one possible design, the data transmission apparatus can include a processor and a communication interface. The processor can be configured to support the data transmission apparatus to implement the functions involved in the first aspect or any possible design of the first aspect.

[0022] In another possible design, the data transmission apparatus can further include a memory configured to store computer-executable instructions and data necessary for the data transmission apparatus. When the data transmission apparatus is running, the processor executes the computer-executable instructions stored in the memory, so that the data transmission apparatus performs the data transmission method in the first aspect or any possible design of the first aspect.

[0023] In a sixth aspect, a computer-readable storage medium is provided, which can be a readable nonvolatile storage medium. The computer-readable storage medium stores computer instructions or programs, which, when executed on a computer, enable the computer to perform the data transmission method in the first aspect or any possible design of the first aspect.

[0024] In a seventh aspect, a computer program product containing instructions is provided, which, when executed on a computer, enable the computer to perform the data transmission method in the first aspect or any possible design of the first aspect.

[0025] In an eighth aspect, an electronic device is provided, which includes one or more processors and one or more memories. The one or more memories are coupled to the one or more processors, and are configured to store computer program codes including computer instructions. When the one or more processors execute the computer instructions, the electronic device performs the data transmission method in the first aspect or any possible design of the first aspect.

[0026] In a ninth aspect, a chip system is provided, which includes a processor and a communication interface, and can be used to implement the functions performed by the data transmission apparatus in the first aspect or any possible design of the first aspect. In a possible design, the chip system further includes a memory, which is configured to store program instructions and / or data. The chip system can be composed of a chip, or can include a chip and other discrete devices, which is not limited herein. BRIEF DESCRIPTION OF DRAWINGS

[0027] Figure 1 A structural schematic diagram of a data transmission system provided by an embodiment of the present application;

[0028] Figure 2 A structural schematic diagram of another data transmission system provided by an embodiment of the present application;

[0029] Figure 3 A structural schematic diagram of a data transmission apparatus provided by an embodiment of the present application;

[0030] Figure 4 A flowchart of a data transmission method provided by an embodiment of the present application;

[0031] Figure 5 A flowchart of another data transmission method provided by an embodiment of the present application;

[0032] Figure 6 A flowchart of another data transmission method provided by an embodiment of the present application;

[0033] Figure 7 A structural schematic diagram of another data transmission apparatus provided by an embodiment of the present application;

[0034] Figure 8 A structural schematic diagram of another data transmission apparatus provided by an embodiment of the present application. DETAILED DESCRIPTION

[0035] In order to make the ordinary person skilled in the art better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings.

[0036] It should be noted that the terms "first", "second", and the like in the description and claims of the application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the appended claims.

[0037] It should also be understood that the term "comprising" indicates the presence of described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, and / or components.

[0038] With the rapid development of Internet technology, terminal devices can remotely access data of home smart terminals (such as home cameras and the like). When the terminal device remotely accesses the data of the home smart terminal, the data of the home smart terminal needs to be forwarded to the terminal device through the Internet public cloud, and the data of the home smart terminal is at risk of data leakage. And the traditional remote access is limited by the transmission bandwidth of the network, and the data transmission rate is low.

[0039] In order to reduce the risk of leakage of the data of the home smart terminal, the functions of some network elements such as the existing network UPF network element and the UDM network element can be upgraded and enhanced, and the operator BOSS system also needs to be incrementally developed, and a new private network home UPF network element needs to be built to access the data of the home smart terminal based on the private network, which has high complexity.

[0040] In view of this, the embodiments of the present application provide a data transmission method, comprising: receiving an access request message of a terminal device; the access request message is used to request target service data; determining a target private network gateway corresponding to a source address of the terminal device in a plurality of private network gateways; forwarding the access request message to the target private network gateway through a dedicated virtual transmission channel between the target private network gateway, to obtain the target service data; and sending the target service data to the terminal device.

[0041] The method provided by the embodiments of the present application will be described in detail below in conjunction with the drawings of the specification.

[0042] It should be noted that the network system described in the embodiments of the present application is to more clearly illustrate the technical solutions of the embodiments of the present application, and does not constitute a limitation on the technical solutions provided by the embodiments of the present application. It is known to those skilled in the art that with the evolution of network systems and the appearance of other network systems, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0043] Figure 1 Fig. 1 shows a structural schematic diagram of a data transmission system 10 provided by an embodiment of the present application. As shown in the figure, the data transmission system 10 can include a terminal device 11 and an FMC gateway 12. Figure 1

[0044] The terminal device 11 can be used to access target service data in a target private network device. It can also be referred to as a terminal, a mobile station (MS), a mobile terminal (MT), etc. It is a device that provides voice and / or data connectivity to users, for example, the terminal device 11 can be a handheld device with wireless connection function, a vehicle-mounted device, etc. Specifically, it can be a mobile phone, a pocket personal computer (PPC), a palm computer, a personal digital assistant (PDA), a notebook computer, a tablet computer, a wearable device, or a vehicle-mounted device, etc. Embodiments of the present application do not limit the specific technology, the specific number and the specific device form of the terminal device 11.

[0045] The FMC gateway 12 involved in the embodiments of the present application is a gateway device that supports the convergence of fixed networks and mobile networks. It mainly realizes the connection between fixed networks and mobile networks. It supports multiple network interfaces and protocols, and can perform call conversion, data transmission and other services between fixed networks and mobile networks, providing users with more convenient and efficient communication experience. Embodiments of the present application do not limit the specific technology, the specific number and the specific device form of the FMC gateway 12.

[0046] Figure 2 Fig. 2 shows another structural schematic diagram of a data transmission system 10 provided by an embodiment of the present application. As shown in the figure, the data transmission system 10 can include a terminal device 11, an FMC gateway 12, an access network device 13, a core network device 14, a private network gateway 15 (which can also be referred to as a fixed network private network gateway), and a private network device 16. Figure 2

[0047] ​​The access network device 13 can be a next generation radio access network (NG-RAN). The access network device 13 is communicatively connected with the terminal device 11 and the core network device 14. For example, the access network device 13 and the terminal device 11 can be communicatively connected through an N1 interface. The access network device 13 and the core network device 14 can be communicatively connected through an N2 interface and an N3 interface. For example, the access network device 13 and an AMF network element in the core network device 14 can be communicatively connected through the N2 interface. The access network device 13 and a UPF network element in the core network device 14 can be communicatively connected through the N3 interface.

[0048] The core network device 14 can include an access and mobility management function (AMF) network element, a session management function (SMF) network element, a user plane function (UPF), and other network function (NF) network elements.

[0049] The AMF network element and the terminal device 11 can be communicatively connected through an N1 interface, and the AMF network element and the access network device 13 can be communicatively connected through an N2 interface. The AMF network element is configured to be responsible for access and mobility management of the terminal device, including user authentication, location management, session management, and the like. The SMF network element is configured to be responsible for establishment, modification, and deletion of a user session, and management and charging of data traffic. The UPF network element is configured to be responsible for forwarding and processing of user data, including encapsulation, decapsulation, and routing of data packets.

[0050] The private network gateway 15 and the FMC gateway 12 pre-establish a virtual private network (VPN) tunnel. The private network gateway 15 and the FMC gateway 12 can be communicatively connected through the pre-established VPN tunnel. The private network gateway 15 is communicatively connected with the private network device 16.

[0051] The number of the private network devices 16 can be one or more. The types of the private network devices can be a camera, a printer, a network attached storage (NAS) device, and the like.

[0052] In specific implementation, Figure 1 and Figure 2 each device in the above-described embodiments can have the structural components shown in FIG. 8, or include the structural components shown in FIG. 8. Figure 3 Figure 3 ​The components shown. Figure 3 A structural schematic diagram of a data transmission device 200 is provided for an embodiment of the present application. The data transmission device 200 can be a network device, or the data transmission device 200 can be a chip or a system on chip in the network device. As shown in the figure, the data transmission device 200 includes a processor 201, a communication interface 202, and a communication line 203. Figure 3

[0053] Further, the data transmission device 200 can further include a memory 204. The processor 201, the memory 204, and the communication interface 202 can be connected through the communication line 203.

[0054] The processor 201 can be a CPU, a general processor, a network processor (NP), a digital signal processing (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 201 can also be other devices with processing functions, such as a circuit, a device, or a software module, without limitation.

[0055] The communication interface 202 is configured to communicate with other devices or other communication networks. The communication interface 202 can be a module, a circuit, a communication interface, or any device capable of communication.

[0056] The communication line 203 is configured to transmit information between components included in the data transmission device 200.

[0057] The memory 204 is configured to store instructions. The instructions can be a computer program.

[0058] The memory 204 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions, or a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magneto-optical disk, a magnetic disk storage or other magnetic storage devices, etc., without limitation. ​

[0059] It should be noted that the memory 204 can exist independently of the processor 201, or can be integrated with the processor 201. The memory 204 can be used to store instructions or program codes or some data, etc. The memory 204 can be located in the data transmission apparatus 200, or can be located outside the data transmission apparatus 200, without limitation. The processor 201 is configured to execute the instructions stored in the memory 204, so as to implement the data transmission method provided in the embodiments of the present application.

[0060] In an example, the processor 201 can include one or more CPUs, for example, the CPU0 and the CPU1 in the CPU 100. Figure 3

[0061] As an optional implementation, the data transmission apparatus 200 includes multiple processors, for example, in addition to the processor 201 in the CPU 100, the processor 205 can also be included. Figure 3

[0062] It should be noted that the constituent structures shown in the CPU 100 do not constitute a limitation on the CPU 100. Figure 3 The various devices in the CPU 100 and the data transmission apparatus 200 can include more or fewer components than those shown in the CPU 100 and the data transmission apparatus 200, or can combine some components, or have different arrangement of components. Figure 1 The various devices in the CPU 100 and the data transmission apparatus 200 can include more or fewer components than those shown in the CPU 100 and the data transmission apparatus 200, or can combine some components, or have different arrangement of components. Figure 2 The various devices in the CPU 100 and the data transmission apparatus 200 can include more or fewer components than those shown in the CPU 100 and the data transmission apparatus 200, or can combine some components, or have different arrangement of components. Figure 3 The various devices in the CPU 100 and the data transmission apparatus 200 can include more or fewer components than those shown in the CPU 100 and the data transmission apparatus 200, or can combine some components, or have different arrangement of components. Figure 1 The various devices in the CPU 100 and the data transmission apparatus 200 can include more or fewer components than those shown in the CPU 100 and the data transmission apparatus 200, or can combine some components, or have different arrangement of components. Figure 2 The various devices in the CPU 100 and the data transmission apparatus 200 can include more or fewer components than those shown in the CPU 100 and the data transmission apparatus 200, or can combine some components, or have different arrangement of components. Figure 3 The various devices in the CPU 100 and the data transmission apparatus 200 can include more or fewer components than those shown in the CPU 100 and the data transmission apparatus 200, or can combine some components, or have different arrangement of components.

[0063] In the embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices.

[0064] In addition, the actions, terms, etc. involved in the embodiments of the present application can be mutually referred to, without limitation. The message names or parameter names in the messages exchanged between the various devices in the embodiments of the present application are only an example, and other names can also be used in the specific implementation, without limitation.

[0065] In order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, the same items or similar items with basically the same functions and effects are distinguished by using "first", "second", etc. The skilled in the art can understand that "first", "second", etc. do not limit the quantity and execution order, and "first", "second", etc. also do not necessarily mean different.

[0066] ​​It should be noted that the words "exemplary" and "for example" are used herein to mean "an example of" or "one example, among others." Any embodiment or design solution described herein as "exemplary" or "for example" should not be construed as being more advantageous or superior in any way over other embodiments or design solutions. Rather, use of such terms is intended to present concepts in a concrete manner.

[0067] In this application, "at least one" means one or more, and "multiple" means two or more. The relationship between the associated objects described by "and / or" means that there can be three relationships, for example, A and / or B, which means that A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can mean a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.

[0068] The data transmission method provided by the embodiments of the present application will be described below in conjunction with the data transmission system shown in Figure 1 and Figure 2 The data transmission method provided by the embodiments of the present application will be described below in conjunction with the data transmission system shown in

[0069] Figure 4 The flowchart of the data transmission method provided by the embodiments of the present application is shown in Figure 4 The method comprises the following S301-S304:

[0070] S301, the terminal device sends an access request message to a fixed mobile convergence (FMC) gateway. Correspondingly, the FMC gateway receives the access request message of the terminal device.

[0071] The access request message comprises a source address and a destination address of the terminal device. The access request message is used to access target service data in a target private network device.

[0072] As a possible implementation manner, the terminal device can send the access request message to the FMC gateway in response to a control instruction. Correspondingly, the FMC gateway receives the access request message of the terminal device.

[0073] It should be noted that the control instruction can be an instruction generated in response to a control operation of an operator. For example, the control instruction can be an instruction input by the operator through an input device (such as a keyboard) of the terminal device, or can be a control instruction input by the operator through a touch device set by the terminal device.

[0074] In an example, in the case that the operator needs to access the target service data in the target private network device, the control instruction can be an instruction that the operator can open the application software corresponding to the target private network device.

[0075] In another example, in the case that the operator needs to access the target service data in the target private network device, the control instruction can be an instruction that the operator can jump to the destination address corresponding to the target private network device.

[0076] For example, the destination address can be the IP address of the configured broadband local area network.

[0077] For example, in the case that the target private network device includes a camera, a printer, and a NAS device, the IP address of the camera can be 192.168.1.2, the IP address of the NAS device can be 192.168.1.3, and the IP address of the printer can be 192.168.1.4.

[0078] In the case that the user needs to access the target service data (such as a high-definition movie) stored in the NAS device, the user can send an access request message with a destination address of 192.168.1.3 to the FMC gateway through the terminal device.

[0079] The above will be described below Figure 3 The process of sending the access request message by the terminal device will be described. The process of sending the access request message by the terminal device can include the following S1-S3:

[0080] S1, the terminal device sends an access request message to the wireless access network device; correspondingly, the wireless access network receives the access request message.

[0081] In an example, the terminal device can send the access request message to the wireless access network device through an N1 interface.

[0082] S2, the wireless access network device sends the access request message to the UPF network element; correspondingly, the UPF network element receives the access request message.

[0083] In an example, the wireless access network device can send the access request message to the UPF network element through an N3 interface.

[0084] It should be noted that before sending the access request message, the terminal device can send a PDU session request message to the AMF network element through the wireless access network device. Correspondingly, the AMF network element receives the PDU session request message and sends a PDU session request message to the SMF network element. Correspondingly, the SMF network element receives the PDU session establishment request message; and sends a packet forwarding control protocol (PFCP) session establishment request message (PFCP Session Establishment Request) to the UPF network element through the N4 interface to complete the establishment of the PDU session.

[0085] Among them, the PFCP session establishment request message includes a service rule. The service rule is used to specify that the access request message with a private network address as the destination address is forwarded to the FMC gateway, and the public network address is forwarded to the public network.

[0086] In some embodiments, the PFCP session establishment request message further includes a header enrichment information element (Header Enrichment IE).

[0087] Among them, IE represents the header enrichment field. For example, it can include the identification information and IP address of the terminal device.

[0088] S3, the UPF network element sends an access request message to the FMC gateway; correspondingly, the FMC gateway receives the access request message.

[0089] In an example, the access request message includes the source address (such as the IP address) of the terminal device. The UPF network element can determine the type of the IP address, and in the case that the source address of the terminal device is a private network address, send the access request message to the FMC gateway.

[0090] In the case that the source address of the terminal device is a public network address, the UPF network element can send the access request message to the public network.

[0091] It should be noted that the UPF network element pre-stores a plurality of private network addresses to determine the type of the source address of the terminal device. For example, the private network address can be 192.168.1.0 / 24.

[0092] S302, the FMC gateway determines a target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways.

[0093] Among them, the first mapping relationship includes the mapping relationship between the plurality of source addresses and the plurality of private network gateways; the first mapping relationship includes the source address of the terminal device.

[0094] The target private network gateway is in communication with a target private network device corresponding to the destination address. For example, the operator can assign a VPN account to each private network gateway, and each private network gateway can establish a VPN connection with the FMC gateway through the VPN account. Different private network gateways are in communication with the FMC gateway through different dedicated VPN tunnels. The FMC gateway establishes a routing table pointing to the private network gateway.

[0095] As a possible implementation, the FMC gateway can determine, from the first mapping relationship, a private network gateway having a mapping relationship with the source address of the terminal device, and determine the private network gateway as the target private network gateway.

[0096] In an example, the first mapping relationship can include a mapping relationship between a plurality of source addresses and a plurality of VPN accounts (which can be referred to as user) corresponding to a plurality of private network gateways.

[0097] For example, the first mapping relationship can be represented by Table 1 below.

[0098] Table 1: First mapping relationship

[0099] Source address VPN account 10.4.4.2 bjhdsd606 10.4.4.1 Bjxcds515

[0100] It should be noted that Table 1 is only an example for illustration, and the first mapping relationship can also include other corresponding relationships of source addresses and VPN accounts, which are not limited.

[0101] In actual application, in the case that the terminal device does not access the destination address for the first time, the FMC gateway can determine the target private network gateway according to the source address of the terminal device and the first mapping relationship.

[0102] In the case that the terminal device accesses the destination address for the first time, the FMC gateway does not store the source address of the terminal device, i.e., does not store the mapping relationship between the source address of the terminal device and the private network gateway, and cannot determine the target private network gateway. The FMC gateway can establish a mapping relationship between the source address of the terminal device and the private network gateway, obtain the first mapping relationship, and determine the target private network gateway according to the first mapping relationship.

[0103] The process of establishing a mapping relationship between the source address of the terminal device and the private network gateway to obtain the first mapping relationship can be referred to the subsequent description, which is not described here.

[0104] As another possible implementation, the FMC gateway can determine whether the terminal device has opened a private network service (which can also be referred to as a fixed-mobile direct service), and in the case that the private network service is opened, determine, from the first mapping relationship, a private network gateway having a mapping relationship with the source address of the terminal device, and determine the private network gateway as the target private network gateway.

[0105] It should be noted that the first mapping relationship can also include the identifier information of the terminal device that has opened the private network service. The FMC gateway can determine that the terminal device has opened the private network service in a case where the first mapping relationship includes the identifier information of the terminal device, and determine that the terminal device has not opened the private network service in a case where the first mapping relationship does not include the identifier information of the terminal device.

[0106] In some embodiments, in a case where it is determined that the terminal device has not opened the private network service, the FMC gateway can send a link for opening the private network service to the terminal device.

[0107] In actual application, the target private network gateway can be an optical modem, a router, or the like deployed by an operator for a user.

[0108] S303, the FMC gateway forwards the access request message to the target private network gateway through the special virtual transmission channel between the FMC gateway and the target private network gateway, to obtain target service data.

[0109] The target service data is data requested to be accessed by the access request message.

[0110] As a possible implementation manner, after determining the target private network gateway, the FMC gateway can obtain the target service data in the target private network device based on the special VPN tunnel between the FMC gateway and the target private network gateway.

[0111] In an example, in combination with the above Figure 2 The FMC gateway can send the access request message to the target private network gateway. Correspondingly, the target private network gateway receives the access request message and sends the access request message to the target private network device corresponding to the destination IP address in the access request message. Correspondingly, the target private network device receives the access request message and sends the target service data to the FMC gateway through the target private network gateway.

[0112] S304, the FMC gateway sends the target service data to the terminal device; correspondingly, the terminal device receives the target service data.

[0113] As a possible implementation manner, the FMC gateway can send the target service data to the UPF network element, and the UPF network element can send the target service data to the terminal device based on the established PDF session.

[0114] In some embodiments, in order to further improve the security of data transmission, the FMC gateway can encrypt the target service data and send the encrypted target service data to the terminal device; the terminal device receives the encrypted target service data, decrypts the encrypted target service data, and obtains the target service data.

[0115] Based on the technical solutions provided in the present application, when the terminal device needs to access target service data in the private network device, the FMC gateway can determine a target private network gateway corresponding to the source address of the terminal device from the plurality of private network gateways, and then acquire the target service data in the target private network device according to the target private network gateway. In this way, the process does not need to be transmitted in the public network, thereby improving the security of data transmission. Moreover, the process does not need to upgrade the existing network device, but only needs to newly build the FMC gateway, so as to accurately determine the private network matched with the terminal device and access the required data in the private network, thereby reducing the complexity of accessing the private network data.

[0116] A possible embodiment, Figure 5 A flowchart of another data transmission method is shown, as Figure 5 As shown in the figure, the present application can also include the following S401-S403.

[0117] S401, the FMC gateway acquires an initial mapping relationship.

[0118] The initial mapping relationship includes the mapping relationship between the plurality of source addresses and the plurality of private network gateways; the initial mapping relationship does not include the source address of the terminal device.

[0119] In an example, the initial mapping relationship can be as shown in Table 2 below:

[0120] Table 2 Initial mapping relationship

[0121] Source address VPN account None bjhdsd606 10.4.4.1 bjhdsd606 10.4.4.3 Bjxcds515

[0122] It should be noted that Table 2 is only an example of an initial mapping relationship, and the initial mapping relationship can also include a mapping relationship between other source addresses and VPN accounts, which is not limited herein.

[0123] In another example, the initial mapping relationship can also include the identification information of the plurality of terminal devices, the mapping relationship between the plurality of source addresses and the plurality of private network gateways. The initial mapping relationship can be as shown in Table 3 below:

[0124] Table 3 Initial mapping relationship

[0125]

[0126] It should be noted that Table 3 is only an example of an initial mapping relationship, and the initial mapping relationship can also include a mapping relationship between other source addresses and VPN accounts, which is not limited herein.

[0127] As a possible implementation, the FMC gateway can acquire the initial mapping relationship from a preset database in the case of receiving the access request message of the terminal device for the first time.

[0128] S402, in a case where the initial mapping relationship does not include the source address of the terminal device, the FMC gateway acquires configuration information of the terminal device.

[0129] The configuration information includes identification information and the source address of the terminal device.

[0130] As a possible implementation, after acquiring the access request message, the FMC gateway parses the source address of the terminal device in the access request message, and then matches the source address of the terminal device with the initial mapping relationship. In a case where the initial mapping relationship does not include the source address of the terminal device, the FMC gateway sends a first indication message to the terminal device.

[0131] The first indication message is used to instruct the terminal device to send the identification information of the terminal device and the source address of the terminal device to the FMC gateway.

[0132] In combination with Table 2 above, in a case where the source address of the terminal device is 10.4.4.2, the FMC gateway matches the initial mapping relationship of Table 2, and the initial mapping relationship of Table 2 does not include the source address 10.4.4.2 of the terminal device, i.e., the identity of the terminal device and the bound target private network gateway cannot be recognized at present. The FMC gateway can send a first indication message to the terminal device.

[0133] In some embodiments, the FMC gateway can be preconfigured with a WEB page, the FMC gateway can redirect the access request message of the terminal device to the WEB page, and send the first indication message to the terminal device based on the WEB page.

[0134] The WEB page can include prompt information instructing the terminal device to send the identification information of the terminal device and the source address of the terminal device to the FMC gateway.

[0135] In some embodiments, the first indication message includes an information acquisition script, the terminal device can acquire the identification information of the terminal device and the source address of the terminal device in response to a running operation of the information acquisition script, and send the identification information of the terminal device and the source address of the terminal device to the FMC gateway.

[0136] In an example, after the terminal device jumps to the WEB page indicated by the first indication message, the WEB page can include the information acquisition script, the terminal device can acquire the identification information of the terminal device and the source address of the terminal device in response to a click operation of the information acquisition script in the WEB page, implement the running operation of the information acquisition script, and send the identification information of the terminal device and the source address of the terminal device to the FMC gateway.

[0137] In yet some embodiments, the first indication message can comprise a hypertext transfer protocol (HTTP) package sending script, and the terminal device can acquire the identification information of the terminal device and the source address of the terminal device and send the identification information of the terminal device and the source address of the terminal device to the FMC gateway in response to a running operation of the HTTP package sending script.

[0138] In an example, after the terminal device jumps to the WEB page indicated by the first indication message, the WEB page can comprise the HTTP package sending script, and the terminal device can acquire the identification information of the terminal device and the source address of the terminal device and send the identification information of the terminal device and the source address of the terminal device to the FMC gateway in response to a clicking operation of the HTTP package sending script in the WEB page.

[0139] In combination with the above Figure 2 , the terminal device sends the original HTTP package to the UPF in response to the running operation of the HTTP package sending script, and the UPF can add the identification information of the terminal device and the source address of the terminal device to the original HTTP package to obtain an auxiliary HTTP package and send the auxiliary HTTP package to the FMC gateway after receiving the original HTTP package; correspondingly, the FMC gateway receives the auxiliary HTTP package to obtain the identification information of the terminal device and the source address of the terminal device.

[0140] In some embodiments, the HTTP package can comprise a uniform resource locator (URL) address of the above-mentioned WEB page. The UPF network element can determine whether the URL address in the HTTP package is a URL address in the white list after receiving the original HTTP package.

[0141] In a case where the URL address in the original HTTP package belongs to the URL address in the white list, the UPF network element can add the identification information of the terminal device and the source address of the terminal device to the original HTTP package to obtain an auxiliary HTTP package and send the auxiliary HTTP package to the FMC gateway; correspondingly, the FMC gateway receives the auxiliary HTTP package to obtain the identification information of the terminal device and the source address of the terminal device.

[0142] In a case where the URL address in the original HTTP package does not belong to the URL address in the white list, the UPF network element does not need to process the original HTTP package and directly forwards the original HTTP package to the destination address corresponding to the original HTTP package.

[0143] It should be noted that the URL address in the HTTP package can be pre-configured as needed. For example, it can be www.gw.com.

[0144] S403, determining, according to the configuration information, a target private network gateway corresponding to the source address of the terminal device from the plurality of private network gateways.

[0145] As a possible implementation, the FMC gateway can establish a mapping relationship between the identification information of the terminal device and the source address of the terminal device according to the configuration information, and update the mapping relationship to the initial mapping relationship to obtain a first mapping relationship, and then determine the target private network gateway corresponding to the source address of the terminal device from the plurality of private network gateways according to the first mapping relationship.

[0146] As a possible embodiment, in order to establish a mapping relationship between the identification information of the terminal device and the source address of the terminal device, the present application can further include the following S501-S502.

[0147] S501, the FMC gateway determines whether the terminal device has access permission of the target private network device according to the identification information of the terminal device.

[0148] As a possible implementation, the first mapping relationship can further include a mapping relationship between a plurality of identification information of terminal devices, a plurality of source addresses and a plurality of private network gateways. The FMC gateway can determine that the terminal device has access permission of the target private network device in a case where the identification information of the terminal device corresponding to the access request message is included in the plurality of identification information of terminal devices included in the first mapping relationship. In a case where the identification information of the terminal device corresponding to the access request message is not included in the plurality of identification information of terminal devices included in the first mapping relationship, it is determined that the terminal device does not have access permission of the target private network device.

[0149] It should be noted that not having access permission of the target private network device can mean that the terminal device does not have a private network service (which can also be referred to as a fixed mobile direct service).

[0150] In actual application, after the terminal device opens the private network service, the FMC gateway can store the mapping relationship (vpn account) between the identification information of the terminal device and the private network gateway.

[0151] In an example, it is assumed that two groups of home users (family A and family B) open the private network service, the operator allocates VPN account and password to the two groups of home broadband local area network respectively, the VPN account of family A is bjhdsd606, the VPN account of family B is bjhxcds515, family A has two mobile user members C and D, family B has one mobile user member E, the operator allocates the identification information of the terminal device to the three users, the identification information of the terminal device of user C is aB3c5D7eF9g1, the identification information of the terminal device of user D is 2h4I6j8kLmNo, and the identification information of the terminal device of user E is Zp1qRs2tUv3w.

[0152] It should be noted that after the terminal device opens the private network service, the FMC gateway only stores the identification and VPN of the terminal device, but does not store the source IP address of the terminal device. After the terminal device accesses the target service data in the target private network device, the FMC gateway stores the source IP address of the terminal device.

[0153] In actual application, in order to protect the security of user data and not to disclose user subscription information and code number and other data, the identification information of the terminal device is not recommended to directly use SUPI, GPSI, PEI, IMSI, MSISDN, IMEI and the like, but a terminal device identification information is allocated to the mobile network user who opens the fixed-mobile direct service, and is written into the user subscription information and policy.

[0154] S502, the FMC gateway determines the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways in the case that the terminal device has access permission of the target private network device.

[0155] As a possible implementation manner, the FMC gateway can write the identification information of the terminal device and the source address into the table item with mapping relationship in the case that the terminal device has access permission of the target private network device, establish the mapping relationship between the identification information of the terminal device and the source address of the terminal device, and determine the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways based on the mapping relationship.

[0156] In an example, the identification information of the terminal device is aB3c5D7eF9g1, and the source address of the terminal device is 10.4.4.2. In the case of the initial mapping relationship of table 3, the first mapping relationship can be table 4 as follows.

[0157] Table 4 first mapping relationship

[0158]

[0159] It should be noted that Table 4 is only an example, and the first can also include the identification information of other terminal devices, the mapping relationship between the source address and the VPN account, which is not limited here.

[0160] Further, after establishing the mapping relationship between the identification information of the terminal device and the source address of the terminal device, the FMC gateway can activate a web page pop-up prompt for indicating to guide the user to initiate an access request message again.

[0161] In some embodiments, in the case that the terminal device does not have access permission of the target private network device, the FMC gateway can determine that the access application is not passed, and discard the data packet corresponding to the access request message.

[0162] Figure 6 A flowchart of another data transmission method provided by the embodiments of the present application is shown in FIG. 6, which includes the following S11-S23. Figure 6

[0163] S11, establishing a VPN tunnel between the FMC gateway and the target private network gateway.

[0164] In some embodiments, the operator can allocate a VPN account for each private network gateway, and each private network gateway establishes a VPN connection with the FMC gateway through the VPN account, and there is a dedicated VPN tunnel between each fixed network private network and the fixed-mobile convergence gateway, and a routing table pointing to these private network gateways is established and maintained on the FMC gateway.

[0165] S12, the FMC gateway deploys a WEB page and configures an initial mapping relationship.

[0166] The specific implementation of this step can refer to S401, which will not be repeated here.

[0167] S13, the UPF network element configures an HTTP header enhancement function.

[0168] The HTTP header enhancement function is used to enhance the header of the WEB page http packet corresponding to the URL address.

[0169] For example, the enhancement of the header of the http packet can be adding the identification and source IP address of the terminal device sending the http packet to the header of the http packet.

[0170] S14, establishing a PDU session and a session rule.

[0171] ​In some embodiments, the terminal device can request the AMF network element to establish a PDU session through the NG-RAN, and the 5G core control plane (5GC CP) completes the establishment of the PDU session according to the 3GPP standard process. The specific process of establishment can refer to the prior art, and will not be described here.

[0172] In this process, the SMF network element can send a PFCP Session Establishment Request message to the UPF through the N4 interface to issue a session rule. The session rule is used to specify that the UPF network element forwards all private network addresses (each private network address is a 192.168.1.0 / 24 network) to the FMC gateway, and forwards public network addresses to the Internet.

[0173] S15, the terminal device sends an access request message to the UPF network element.

[0174] The specific implementation of this step can refer to S301, and will not be described here.

[0175] S16, the UPF sends an access request message to the FMC gateway in the case of a private network address.

[0176] The specific implementation of this step can refer to S301, and will not be described here.

[0177] S17, the FMC gateway sends a first indication message to the terminal device in the case that the initial mapping relationship does not include the source address of the terminal device.

[0178] The specific implementation of this step can refer to S402, and will not be described here.

[0179] S18, the terminal device sends an original HTTP package to the UPF network element.

[0180] The specific implementation of this step can refer to S403, and will not be described here.

[0181] S19, the UPF network element adds the identification information of the terminal device and the source address of the terminal device to the original HTTP package to obtain an auxiliary HTTP package, and sends the auxiliary HTTP package to the FMC gateway.

[0182] The specific implementation of this step can refer to S403, and will not be described here.

[0183] S20, the FMC gateway establishes a mapping relationship between the identification information of the terminal device and the source address of the terminal device in the case that the terminal device has access permission of the target private network device, and updates the mapping relationship to the initial mapping relationship to obtain a first mapping relationship.

[0184] The specific implementation of this step can refer to S403, and will not be described here.

[0185] S21, the terminal device re-sends an access request message to the FMC gateway.

[0186] The specific implementation of this step can refer to S403, and will not be described here.

[0187] S22, the FMC gateway determines the target private network gateway according to the source address of the terminal device and the first mapping relationship.

[0188] The specific implementation of this step can refer to S302, and will not be described here.

[0189] S23, the FMC gateway sends an access request message to the target private network device based on the target private network gateway.

[0190] The specific implementation of this step can refer to S303, and will not be described here.

[0191] The embodiments of the present application can divide the functional modules or functional units of the data transmission device according to the above-mentioned method examples. For example, each functional module or functional unit can be divided corresponding to each function, or two or more functions can be integrated in one processing module. The above-mentioned integrated module can be realized in the form of hardware or software functional module or functional unit. The division of modules or units in the embodiments of the present application is illustrative, and is only a logical function division. Actual implementation can have another division mode.

[0192] In the case of dividing each functional module corresponding to each function, Figure 7 Another structural schematic diagram of a data transmission device 700 is shown, which can be a data transmission device, or a chip, processor, etc. applied in the data transmission device. The data transmission device 700 can be used to execute the functions of the data transmission device involved in the above-mentioned embodiments. Figure 7The data transmission apparatus 700 shown can include a receiving unit 701, a processing unit 702, and a sending unit 703. The receiving unit 701 is configured to receive an access request message of a terminal device. The access request message is used to request target service data. The processing unit 702 is configured to determine a target private network gateway corresponding to a source address of the terminal device from a plurality of private network gateways. The sending unit 703 is configured to forward the access request message to the target private network gateway through a dedicated virtual transmission channel between the target private network gateway, so as to obtain the target service data. The sending unit 703 is further configured to send the target service data to the terminal device.

[0193] Optionally, the processing unit 702 is specifically configured to: obtain an initial mapping relationship; the initial mapping relationship includes a mapping relationship between a plurality of source addresses and a plurality of private network gateways; in a case where the initial mapping relationship does not include the source address of the terminal device, obtain configuration information of the terminal device; and determine the target private network gateway corresponding to the source address of the terminal device from the plurality of private network gateways according to the configuration information.

[0194] Optionally, the receiving unit 701 is specifically configured to: send a first indication message to a UPF network element; the first indication message is used to obtain the configuration information; and receive an auxiliary http data packet from the UPF network element, so as to obtain the configuration information of the terminal device; the auxiliary http data packet is obtained according to the source address and identification information of the terminal device.

[0195] Optionally, the auxiliary http packet is sent by the UPF network element in a case where a URL address of an original http packet is a target URL address; the target URL address is a preconfigured URL address; and the original http packet is sent by the terminal device in response to the first indication message.

[0196] Optionally, the processing unit 702 is specifically configured to: determine whether the terminal device has access permission of the target private network device according to the identification information; and in a case where the terminal device has the access permission of the target private network device, determine the target private network gateway corresponding to the source address of the terminal device from the plurality of private network gateways.

[0197] Figure 8 A structural schematic diagram of another data transmission apparatus 800 is shown. The data transmission apparatus can be a data transmission apparatus, or a chip, a processor, etc. applied to the data transmission apparatus. The data transmission apparatus 800 can be used to execute the functions of the data transmission apparatus involved in the above embodiments. Figure 8The data transmission apparatus 800 shown can include a sending unit 801 and a receiving unit 802. The sending unit 801 is configured to send an access request message to a fixed mobile convergence (FMC) gateway, the access request message being used to request target service data. The FMC gateway is configured to determine a target private network gateway corresponding to a source address of a terminal device from a plurality of private network gateways, and forward the access request message to the target private network gateway through a dedicated virtual transmission channel between the FMC gateway and the target private network gateway, so as to obtain the target service data. The receiving unit 802 is configured to receive the target service data.

[0198] Optionally, the receiving unit 802 is further configured to receive a first indication message of a UPF network element, the first indication message being used to obtain configuration information. The sending unit 801 is further configured to send an original http packet to the UPF network element, so that the UPF network element sends an auxiliary http packet to the FMC gateway in a case where a URL address of the original http packet is a target URL address. The auxiliary http packet is obtained according to the source address and the identification information of the terminal device.

[0199] The embodiments of the present application further provide a computer readable storage medium. All or part of the processes of the above method embodiments can be completed by a computer program instructing related hardware, and the program can be stored in the computer readable storage medium. When the program is executed, the processes of the above method embodiments can be included. The computer readable storage medium can be an internal storage unit of the data transmission apparatus (including a data sending end and / or a data receiving end) of any of the foregoing embodiments, such as a hard disk or a memory of the data transmission apparatus. The computer readable storage medium can also be an external storage device of the terminal device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, and the like. Further, the computer readable storage medium can include both the internal storage unit and the external storage device of the data transmission apparatus. The computer readable storage medium is used to store the computer program and other programs and data required by the data transmission apparatus. The computer readable storage medium can also be used to temporarily store data that has been output or will be output.

[0200] It should be noted that the terms "first", "second" and "third" and the like in the description and in the claims of the present application are used for distinguishing between similar elements and not necessarily for describing a sequential or chronological order. It is to be understood that the terms so used are interchangeable under appropriate circumstances and embodiments of the application are capable of producing more than one dependent claim effect. Furthermore, the terms "comprise", "have" and any variations thereof are intended to cover a non-exclusive inclusion. For example, a process, method, article, or apparatus that comprises a list of steps or units is not necessarily limited to the listed steps or units but can include additional steps or units not expressly listed or inherent to such process, method, article, or apparatus.

[0201] It should be understood that, in the present application, "at least one" refers to one or more, "multiple" refers to two or more, "at least two" refers to two or three and more, and "and / or" is used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, "A and / or B" can represent three cases of only A, only B and A and B existing at the same time, wherein A and B can be singular or plural. The character " / " generally represents an "or" relationship between the front and rear associated objects. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can represent a, b, c, "a and b", "a and c", "b and c", or "a and b and c", wherein a, b, and c can be single or multiple.

[0202] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of functional modules is taken as an example, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0203] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of modules or units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be through some interface, indirect coupling or communication connection between devices or units, which can be electrical, mechanical or other forms.

[0204] The units described as separate components may or may not be physically separate, and the components displayed as units may be a physical unit or multiple physical units, that is, may be located in one place, or also can be distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present application.

[0205] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0206] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application essentially or say the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions to make a device (which can be a single-chip microcomputer, a chip, etc.) or a processor execute all or part of the steps of the method of each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk and various storage media that can store program codes.

[0207] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data transmission method, characterized by, The application is applied to a fixed mobile convergence (FMC) gateway, a dedicated virtual transmission channel is arranged between the FMC gateway and each private network gateway in a plurality of private network gateways; the method comprises the following steps: receiving an access request message of a terminal device; the access request message is used to request target service data; the access request message is sent by a UPF network element to the FMC gateway when the destination address is a private network address; determining a target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways; forwarding the access request message to the target private network gateway through the dedicated virtual transmission channel between the target private network gateway, so as to obtain the target service data; sending the target service data to the terminal device.

2. The method of claim 1, wherein, The method further comprises the following steps: obtaining an initial mapping relationship; the initial mapping relationship comprises a mapping relationship between a plurality of source addresses and a plurality of private network gateways; obtaining configuration information of the terminal device when the initial mapping relationship does not comprise the source address of the terminal device; determining the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways according to the configuration information.

3. The method of claim 1, wherein, The method further comprises the following steps: sending a first indication message to the UPF network element; the first indication message is used to obtain the configuration information; receiving an auxiliary http data packet from the UPF network element to obtain the configuration information of the terminal device; the auxiliary http data packet is obtained according to the source address and identification information of the terminal device.

4. The method of claim 3, wherein: the auxiliary http packet is sent by the UPF network element when the URL address of the original http packet is a target URL address; the target URL address is a preconfigured URL address; the original http packet is sent by the terminal device to the UPF network element in response to the first indication message.

5. The method of claim 3, wherein, The method further comprises the following steps: determining whether the terminal device has access permission of a target private network device according to the identification information; determining the target private network gateway corresponding to the source address of the terminal device in the plurality of private network gateways when the terminal device has the access permission of the target private network device.

6. A data transmission method, characterized by, The application is applied to a terminal device, and the method comprises the following steps: sending an access request message to a fixed mobile convergence (FMC) gateway; the access request message is sent by a UPF network element to the FMC gateway when the destination address is a private network address; the access request message is used to request target service data; the FMC gateway determines a target private network gateway corresponding to the source address of the terminal device in a plurality of private network gateways, and forwards the access request message to the target private network gateway through a dedicated virtual transmission channel between the target private network gateway, so as to obtain the target service data; receiving the target service data.

7. The method of claim 6, wherein, The method further comprises the following steps: Receiving a first indication message of the UPF network element; the first indication message is used to obtain configuration information; Sending an original http package to the UPF network element, so that the UPF network element sends an auxiliary http package to the FMC gateway when the URL address of the original http package is the target URL address; the auxiliary http data package is obtained according to the source address and identification information of the terminal device.

8. A data transmission apparatus, characterized by comprising: The application is applied to a fixed mobile convergence (FMC) gateway, a dedicated virtual transmission channel is arranged between the FMC gateway and each private network gateway in a plurality of private network gateways, and the device comprises a receiving unit, a processing unit and a sending unit. The receiving unit is configured to receive an access request message of a terminal device; the access request message is used to request target service data; and the access request message is sent by a UPF network element to the FMC gateway when a destination address is a private network address. The processing unit is configured to determine a target private network gateway corresponding to a source address of the terminal device in the plurality of private network gateways. The sending unit is configured to forward the access request message to the target private network gateway through the dedicated virtual transmission channel between the target private network gateway, so as to obtain the target service data. The sending unit is further configured to send the target service data to the terminal device.

9. A data transmission apparatus, characterized by comprising: The application is applied to a terminal device, and the device comprises a sending unit and a receiving unit. The sending unit is configured to send an access request message to a fixed mobile convergence (FMC) gateway; the access request message is sent by a UPF network element to the FMC gateway when a destination address is a private network address; the access request message is used to request target service data; the FMC gateway determines a target private network gateway corresponding to a source address of the terminal device in a plurality of private network gateways, and forwards the access request message to the target private network gateway through a dedicated virtual transmission channel between the target private network gateway, so as to obtain the target service data. The receiving unit is configured to receive the target service data.

10. A computer-readable storage medium, characterized in that, The readable storage medium stores instructions, and when the instructions are executed, the method in any one of claims 1-5 or claims 6 or 7 is implemented.

11. An electronic device, comprising: Comprise: A processor, a memory and a communication interface; wherein the communication interface is used for communication between the electronic device and other devices or networks; The memory is used to store one or more programs, which comprise computer execution instructions, when the electronic device runs, the processor executes the computer execution instructions stored in the memory, so that the electronic device executes the method in any one of claims 1-5 or claims 6 or 7.

12. A computer program product comprising computer instructions, characterized in that, The computer instructions are executed by the processor to implement the method in any one of claims 1-5 or claims 6 or 7.

Citation Information

Patent Citations

  • Internet protocol mapping resolution in fixed mobile convergence networks

    CN103477605A

  • Methods and systems for establishing channel in fixed and mobile network convergence case

    CN104185303A