Terminal visit management method, device and medium

By introducing a network communication module and a data monitoring and distribution module attached to the terminal during the terminal mutual access process, the problem of unmonitored data during terminal mutual access is solved, enabling full tracking and recording of data, improving the efficiency of terminal mutual access and network security, and adapting to diverse IoT application scenarios.

CN119922121BActive Publication Date: 2025-11-11CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510128140.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-11-11
Estimated Expiration
2045-01-27

AI Technical Summary

Technical Problem

Terminal interoperability technology bypasses core network elements, resulting in data being unregulated, posing network security risks, and lacking flexibility, making it difficult to meet the diverse needs of IoT application scenarios.

Method used

By introducing a network communication module and a data supervision and distribution module attached to the terminal, a first data path and a second data path are established for data supervision and terminal access, respectively. Data replication and distribution are achieved using L2TP tunnels and the LNS platform, and the system is connected to the network data supervision platform to ensure that while data supervision and terminal access are being carried out, IP addresses are allocated according to the communication topology and MAC address, and the terminal access strategy is dynamically adjusted.

Benefits of technology

It enables full tracking and recording of terminal communication data, ensuring data security and effective supervision, improving terminal communication efficiency, enhancing network security and flexibility, and adapting to the communication needs of different IoT application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922121B_ABST
    Figure CN119922121B_ABST
Patent Text Reader

Abstract

This disclosure provides a terminal access management method, apparatus, and medium, relating to the field of communication technology, to address the problem of unregulated terminal access data during terminal access processes. The method includes: obtaining a terminal access request from a source terminal to a target terminal; obtaining a first data path and a second data path based on the terminal access request, wherein the first data path leads to a network data monitoring platform, and the second data path connects the source terminal and the target terminal; replicating and distributing the terminal access data between the source terminal and the target terminal through the first and second data paths, thereby achieving data monitoring of the terminal access data through the first data path, and realizing terminal access between the source terminal and the target terminal through the second data path. This disclosure, by designing data paths and implementing the replication and distribution of terminal access data based on these data paths, achieves both terminal access and monitoring of the terminal access data simultaneously.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates at least to the field of communication technology, and in particular to a terminal inter-access management method, apparatus and medium. Background Technology

[0002] Terminal interoperability technology reduces the traffic transmitted back to the core network, effectively lowering latency and core network load, and improving transmission efficiency during interoperability. However, it poses challenges to network data oversight because data does not pass through all network elements of the core network completely, leaving it unsupervised and posing a threat to network security. Summary of the Invention

[0003] The technical problem to be solved by this disclosure is to provide a terminal access management method, device and medium to address the above-mentioned shortcomings, so as to solve the problem of unregulated terminal access data during the terminal access process.

[0004] In a first aspect, this disclosure provides a terminal inter-access management method, the method comprising:

[0005] Obtain terminal communication requests from the source terminal to the target terminal;

[0006] The first data path and the second data path are obtained according to the terminal access request. The first data path leads to the network data supervision platform, and the second data path connects the source terminal and the target terminal.

[0007] Through the first data path and the second data path, the replication and distribution of terminal access data between the source terminal and the target terminal are realized, so as to realize data supervision of terminal access data through the first data path, and realize terminal access between the source terminal and the target terminal through the second data path.

[0008] Furthermore, among which:

[0009] The first data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network user plane function UPF network element, and / or, a second communication path between the target terminal and the target network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and an interface path between the tunnel service platform and the network data supervision platform.

[0010] The second data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network UPF network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and a second communication path between the target terminal and the target network element; or, a first communication path between the source terminal and the source network element, a third tunnel between the source network element and the target network element via the core network UPF network element, and a second communication path between the target terminal and the target network element.

[0011] The tunnel service platform or the core network UPF element copies the terminal access data into two copies. The first copy of the terminal access data is sent to the network data supervision platform through the first data path to achieve data supervision, and the second copy of the terminal access data is sent through the second data path to achieve terminal access.

[0012] Furthermore, among which:

[0013] The first and second tunnels are specifically Layer 2 Tunneling Protocol (L2TP) tunnels. The source network element includes the source L2TP Access Concentrator (LAC), and the destination network element includes the destination LAC. The tunnel service platform is specifically the L2TP Network Server (LNS). The first tunnel connects the source LAC, the core network UPF element, and the LNS in sequence, and the second tunnel connects the LNS, the core network UPF element, and the destination LAC in sequence.

[0014] Furthermore, the method also includes:

[0015] A network communication management module is set up under the terminal in the core network. The network communication management module under the terminal obtains the communication topology and media access control MAC address of the terminal. Based on the communication topology and MAC address, it assigns Internet Protocol (IP) address to each terminal. Based on the communication topology and IP address, it obtains the Address Resolution Protocol (ARP) table and sends the ARP table to the LNS so that the LNS has IP routing function.

[0016] Furthermore, obtaining terminal access requests from the source terminal to the target terminal specifically includes:

[0017] The terminal is attached to a network communication management module, which includes a core network access and mobility management function (AMF) network element. The core network AMF network element receives terminal inter-terminal communication requests from the source terminal, obtains the MAC address of the source terminal and the MAC address of the target terminal based on the terminal inter-terminal communication request, and obtains the terminal inter-terminal communication data in the terminal inter-terminal communication request.

[0018] Furthermore, obtaining the first data path and the second data path based on the terminal access request specifically includes:

[0019] A data tunnel construction module and a data policing and distribution module are set up in the core network. The data tunnel construction module includes the source LAC and the destination LAC, and the data policing and distribution module includes the LNS. The data tunnel construction module is connected to the network communication management module attached to the terminal.

[0020] Upon receiving a terminal inter-terminal communication request, the network communication management module attached to the terminal notifies the source LAC and the destination LAC to establish a first tunnel and a second tunnel.

[0021] The network communication management module attached to the terminal sends the source terminal MAC address, the target terminal MAC address, and the terminal communication data to the LNS through the first tunnel.

[0022] LNS queries the ARP table based on the source terminal MAC address and the target terminal MAC address to obtain the source terminal IP address and the target terminal IP address, and then obtains the first communication path and the second communication path based on the source terminal IP address and the target terminal IP address.

[0023] Furthermore, through a first data path and a second data path, the replication and distribution of terminal access data between the source terminal and the target terminal are realized. This is achieved through data supervision of the terminal access data via the first data path, and terminal access between the source terminal and the target terminal is realized via the second data path. Specifically, this includes:

[0024] LNS copies the terminal access data into two copies.

[0025] LNS sends the first set of terminal communication data to the network data supervision platform through its interface with the network data supervision platform.

[0026] LNS sends the target terminal IP address and the second set of terminal communication data to the terminal's network communication management module through the second tunnel.

[0027] The network communication management module attached to the terminal sends the second set of terminal communication data to the target terminal based on the target terminal's IP address.

[0028] Furthermore, after implementing data supervision of terminal inter-access data through the first data path, the method further includes:

[0029] In response to the failure to properly monitor the data exchange between terminals, the LNS will not send the target terminal IP address and the second set of terminal exchange data to the network communication management module attached to the terminal, and / or the LNS will interrupt subsequent terminal exchanges between the source terminal and the target terminal.

[0030] Secondly, this disclosure provides a terminal inter-access management device, the device comprising:

[0031] The acquisition unit is used to acquire terminal communication requests from the source terminal to the target terminal.

[0032] The path unit, connected to the acquisition unit, is used to acquire a first data path and a second data path according to the terminal mutual access request. The first data path leads to the network data supervision platform, and the second data path connects the source terminal and the target terminal.

[0033] The distribution unit, connected to the path unit, is used to replicate and distribute terminal access data between the source terminal and the target terminal through a first data path and a second data path, so as to realize data supervision of the terminal access data through the first data path, and to realize terminal access between the source terminal and the target terminal through the second data path.

[0034] Thirdly, this disclosure provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the terminal access management method described above.

[0035] This disclosure provides a terminal access management method, apparatus, and medium. Based on a terminal access request from a source terminal to a target terminal, a first data path leading to a network data monitoring platform and a second data path connecting the source terminal and the target terminal are obtained. The terminal access data is copied and distributed based on the first and second data paths, thereby enabling terminal access and monitoring of the terminal access data. Attached Figure Description

[0036] Figure 1 This is a flowchart of a terminal access management method according to an embodiment of this disclosure;

[0037] Figure 2 This is a schematic diagram of the structure of a terminal access management device according to an embodiment of the present disclosure;

[0038] Figure 3 This is a schematic diagram of an existing terminal communication method.

[0039] Figure 4 This is a schematic diagram of a terminal communication method according to an embodiment of the present disclosure;

[0040] Figure 5 This is a schematic diagram of the structure of a terminal communication system according to an embodiment of this disclosure;

[0041] Figure 6 This is a flowchart of another terminal access management method according to an embodiment of this disclosure. Detailed Implementation

[0042] To enable those skilled in the art to better understand the technical solutions of this disclosure, the embodiments of this disclosure will be further described in detail below with reference to the accompanying drawings.

[0043] It is understood that the specific embodiments and accompanying drawings described herein are for illustrative purposes only and are not intended to limit the scope of this disclosure.

[0044] It is understood that, without conflict, the various embodiments and features in the embodiments of this disclosure can be combined with each other.

[0045] It is understood that, for ease of description, only the parts relevant to this disclosure are shown in the accompanying drawings, while parts unrelated to this disclosure are not shown in the drawings.

[0046] It is understood that each module or unit involved in the embodiments of this disclosure may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple modules or units may be integrated into one entity structure.

[0047] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this disclosure may occur in a different order than that marked in the accompanying drawings.

[0048] It is understood that the flowcharts and block diagrams of this disclosure illustrate the architecture, functions, and operations of possible implementations of systems, apparatuses, devices, and methods according to various embodiments of this disclosure. Each block in a flowchart or block diagram may represent a module, unit, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagrams and flowcharts may be implemented using hardware-based devices to implement the specified function, or using a combination of hardware and computer instructions.

[0049] It is understood that the modules and units involved in the embodiments of this disclosure can be implemented by software or by hardware, for example, the modules and units can be located in a processor.

[0050] Example 1:

[0051] like Figure 1 As shown, this disclosure provides a terminal inter-access management method, the method comprising:

[0052] S1. Obtain the terminal access request from the source terminal to the target terminal;

[0053] S2. Obtain the first data path and the second data path according to the terminal access request. The first data path leads to the network data supervision platform, and the second data path connects the source terminal and the target terminal.

[0054] S3. Through the first data path and the second data path, the replication and distribution of terminal access data between the source terminal and the target terminal are realized, so as to realize data supervision of terminal access data through the first data path, and realize terminal access between the source terminal and the target terminal through the second data path.

[0055] In this embodiment, the method obtains a first data path to the network data monitoring platform and a second data path connecting the source terminal and the target terminal based on the terminal access request from the source terminal to the target terminal. It then replicates and distributes the terminal access data based on the first and second data paths, thereby enabling both terminal access and monitoring of the access data. Figure 1 The method shown is applicable to, for example, Figure 2 The terminal access management device shown.

[0056] Specifically, this embodiment proposes a terminal communication system and method, including a terminal and a... Figure 2 The terminal access management device shown in the diagram, in a single terminal access communication, includes a source terminal and a target terminal. The source terminal initiates a terminal access request. Based on the terminal access request, the terminal access management device obtains a first data path for data supervision and a second data path for terminal access. The first and second data paths may partially overlap, but the terminal access data is distributed into two parts through a data supervision and distribution module. One part is used for supervision, and the other part is used to complete the access, thereby enabling full tracking and recording of data interaction between terminals and ensuring data security and the effectiveness of supervision.

[0057] In one embodiment, wherein:

[0058] The first data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network user plane function UPF network element, and / or, a second communication path between the target terminal and the target network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and an interface path between the tunnel service platform and the network data supervision platform.

[0059] The second data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network UPF network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and a second communication path between the target terminal and the target network element; or, a first communication path between the source terminal and the source network element, a third tunnel between the source network element and the target network element via the core network UPF network element, and a second communication path between the target terminal and the target network element.

[0060] The tunnel service platform or the core network UPF element copies the terminal access data into two copies. The first copy of the terminal access data is sent to the network data supervision platform through the first data path to achieve data supervision, and the second copy of the terminal access data is sent through the second data path to achieve terminal access.

[0061] In this embodiment, a method such as Figure 3 The terminal interoperability technology illustrated here utilizes the User Plane Function (UPF) in the 5G core network (5GC, 5th Generation Core). As a key network element carrying user data, the UPF is responsible for data path selection, forwarding, and traffic control within the user plane. This UPF-based technology reduces traffic backhaul to the core network, eliminating the need for other network elements such as the core network's Service Management Function (SMF). It directly leverages the local UPF for data exchange, effectively lowering terminal interoperability latency and core network load, and improving transmission efficiency during terminal interoperability.

[0062] From a network oversight perspective, this UPF-based terminal communication technology poses a challenge to network data oversight. In typical communication processes, all data usually passes through all network elements in the core network, enabling data oversight platforms to monitor and manage data flows securely. However, UPF-based terminal communication bypasses this process, causing data traffic between terminals to flow directly between them instead of being centrally transmitted back to the core network elements. This results in data lacking oversight, making it impossible for data oversight to identify and block abnormal network behavior and potential network attacks in real time, thus posing a threat to network security.

[0063] While UPF-based terminal communication technology improves the communication efficiency of IoT terminals, it suffers from two main drawbacks: First, data loss of control. Because data exchange between terminals occurs directly within the local UPF, bypassing other network elements in the core network, it makes real-time monitoring of terminal communication behavior difficult. This lack of effective protection against potential security threats may prevent the full identification and prevention of malicious terminal attacks, such as man-in-the-middle attacks, data tampering, or forged communication requests, easily leading to a decline in the overall security of the IoT system and increasing network vulnerabilities. Second, poor flexibility. Existing UPF terminal communication technology lacks the ability to customize traffic control and monitoring for different IoT application scenarios. With the increase in the number of terminals and the diversification of application scenarios, traditional static routing and fixed path selection are insufficient to meet dynamically changing network demands, resulting in low utilization efficiency of communication resources.

[0064] Currently, most UPFs (User-Generated Functions) possess terminal interoperability capabilities in terms of hardware. However, for security reasons, this terminal interoperability function is not enabled in public network communication scenarios. This is because, under normal circumstances, during public network communication, the UPF needs to forward data to the network security management system for security review and oversight. If UPF terminals within the public network were to enable interoperability, data could be directly forwarded between terminals via the UPF without network security oversight, potentially creating data and network risks. However, terminal interoperability technically reduces network layers between terminals, resulting in faster speeds and significantly improved performance in many network scenarios, thus meeting practical needs. Therefore, the key problem this embodiment aims to solve is how to use alternative technical solutions to maintain excellent terminal interoperability performance while achieving network security oversight in a public network environment without enabling UPF terminal interoperability.

[0065] This embodiment proposes as follows: Figure 4 This paper presents a terminal inter-access system and method. The system includes a data monitoring and distribution module, a data tunnel construction module, and a terminal-attached network communication module. It provides a technical solution for monitoring and managing data flow during terminal inter-access, ensuring end-to-end data interaction meets security and privacy requirements, thereby enhancing data transparency and network security. By introducing a terminal-attached network communication module, the system expands the downstream communication capabilities (post-routing capabilities) during terminal inter-access. It automatically adjusts terminal inter-access strategies according to different IoT application scenarios, meeting diverse terminal inter-access needs and improving the utilization rate of communication resources. This enhances terminal inter-access efficiency while ensuring security. The data monitoring and distribution module forwards data to the corresponding network security management system (network data monitoring platform) for monitoring. The data monitoring and distribution module itself does not monitor; instead, it monitors data by transmitting it to a platform with monitoring functions, distributing data to the network monitoring platform, receiving feedback from the network security management system on the data monitoring results, and then taking corresponding actions.

[0066] This embodiment primarily targets IoT scenarios that require terminal interoperability, low latency, high performance, flexible networking, and terminal access to the public network. Traffic control is mainly achieved through a data tunnel construction module, which builds and allocates different tunnels to different scenarios to control different traffic flows. This embodiment is primarily designed for IoT scenarios, but it is applicable to general scenarios as well. Communication scenarios can be divided into two types: voice communication and data communication. IoT systems mostly use data communication, but this embodiment does not exclude the possibility of application in voice communication scenarios.

[0067] Understandable Figure 4The UPF network element is displayed as one, but the actual number is determined according to the communication network structure. It may also be divided into source UPF network elements and destination UPF network elements. In addition, the base station can also be regarded as a network element and divided into source and destination. This embodiment provides an improved terminal mutual access technology through UPF network elements, but it is not limited to this. The terminal mutual access described in this disclosure refers to the fact that the terminal mutual access data does not completely pass through each network element of the core network. Whether the data completely passes through each network element of the core network can be defined according to the consensus in the field.

[0068] In one embodiment, wherein:

[0069] The first and second tunnels are specifically Layer 2 Tunneling Protocol (L2TP) tunnels. The source network element includes the source L2TP Access Concentrator (LAC), and the destination network element includes the destination LAC. The tunnel service platform is specifically the L2TP Network Server (LNS). The first tunnel connects the source LAC, the core network UPF element, and the LNS in sequence, and the second tunnel connects the LNS, the core network UPF element, and the destination LAC in sequence.

[0070] In this embodiment, as Figure 4 As shown, the regulatory capability is mainly achieved through the data regulatory distribution module, which connects communication data to the network security management system and receives feedback from the network security management system. The data regulatory distribution module also plays a crucial role in routing. This module is essentially an LNS platform with IP routing matching capabilities. In this embodiment, the IP routing process is only performed on the LNS platform to more effectively manage terminal communication. Figure 4 In this context, LAC stands for L2TP Access Concentrator; LNS stands for L2TP Network Server; LNS is pre-connected to a network data monitoring platform; and Layer 1, Layer 2, and Layer 3 terminals refer to different levels of terminals in the downstream communication process (referring to terminal inter-terminal communication in this embodiment). For example, Figure 3 No oversight module plays a role in the process; for example, the communication process between terminals A and B is: terminal A – base station A – UPF – base station B – terminal B; while Figure 4 In the process, for example, the communication process between terminal a21 and terminal a31 is: a21–a2–A–base station A–C–D–C–base station A–A–a3–a31, where C is the data tunnel construction module and D is the data supervision and distribution module. The data circulation environment will have a data supervision and distribution module to realize supervision, and the method provided in this embodiment can be applied in both public network communication and non-public network communication.

[0071] The primary function of the terminal-attached network communication management module is to interface with the terminal. This function can be implemented using existing network elements such as AMF, SMF, and AAA. It can serve as a terminal management platform, an operation point for terminal management, or a combined function of multiple network management systems. The data tunnel construction module is specifically designed for terminal interoperability. A key feature is that this tunnel is an L2TP tunnel, which penetrates the UPF and bypasses the UPF's three-layer forwarding, directly interoperating with the LNS platform. The LNS platform sends data to the network security management system via an API (Application Programming Interface). From the core network's perspective, interoperability with the LNS platform generally signifies data oversight, allowing terminal interoperability to bypass the LNS platform. Since the LNS platform is overseen, the data is also overseen, enabling terminal interoperability. The LNS handles tunnel termination and routing, effectively replacing the routing function of network elements. The LNS platform determines the target IP address, thus determining the second data path. Data transmission is essential for the network security management system, but feedback is not. In other words, all data must be distributed to the network administrator, but the network administrator silently listens without necessarily providing feedback, only responding when a problem occurs. In actual business operations, the network administrator's main responsibility is to backtrack after a problem occurs, which is essentially listening. Theoretically, the network administrator should be able to manipulate the data after a problem occurs, but in practice, once the data is sent to the network administrator, it is considered to have passed the monitoring by default. Both the source terminal and the target terminal have tunnels to the data monitoring and distribution module, and then the data monitoring and distribution module distributes a copy of the data to the network administrator.

[0072] In one embodiment, the method further includes:

[0073] A network communication management module is set up under the terminal in the core network. The network communication management module under the terminal obtains the communication topology and media access control MAC address of the terminal. Based on the communication topology and MAC address, it assigns Internet Protocol (IP) address to each terminal. Based on the communication topology and IP address, it obtains the Address Resolution Protocol (ARP) table and sends the ARP table to the LNS so that the LNS has IP routing function.

[0074] In this embodiment, a terminal communication system and method can also be as follows: Figure 5 As shown, a specific terminal communication process is as follows:

[0075] The network communication management module attached to the terminal assigns IP (Internet Protocol) addresses to all terminals under its management (including terminal A and terminal B, where terminal A is the source terminal and terminal B is the destination terminal) according to the communication topology between the terminals and their MAC (Media Access Control) addresses, thus obtaining an ARP (Address Resolution Protocol) table. The data tunnel construction module establishes a dedicated tunnel for transmitting the ARP table and then transmits the ARP table to the data supervision and distribution module through this dedicated tunnel.

[0076] Terminal A initiates a terminal mutual access request to the network communication management module attached to the terminal. The request carries the MAC address information of terminal A, the mutual access data sent by terminal A, and the name of the mutual access target terminal B. The network communication management module attached to the terminal obtains the MAC address of terminal B based on the name of the mutual access target terminal B.

[0077] The data tunnel construction module establishes a dedicated tunnel T for terminal A to access the data monitoring and distribution module. AJ This tunnel is an L2TP (Layer 2 Tunneling Protocol) tunnel.

[0078] The network communication management module attached to the terminal transmits the MAC address information of terminal A, the MAC address information of terminal B, and the mutual communication data of terminal A through tunnel T. AJ Send to the data supervision and distribution module.

[0079] After obtaining the MAC addresses of terminal A and terminal B, the data monitoring and distribution module queries the ARP table to obtain the IP addresses of terminal A and terminal B, respectively, and then sends the mutual access data of terminal A and the IP address of terminal B to the network communication management module attached to the terminal.

[0080] The network communication management module attached to the terminal sends the mutual access data of terminal A to terminal B according to the IP address of terminal B.

[0081] It is understandable that in the above terminal communication process, the terminal communication request carries terminal communication data. Alternatively, terminal A can initiate the terminal communication request first, establishing the first and second data paths, after which terminals A and B send terminal communication data. This data can be sent from either side, or both sides can send it. In this terminal communication process, the terminal communication data is equivalent to passing through… Figure 4LAC1-UPF-LNS, LNS copies data, one copy is given to the network data supervision platform, and the other copy is distributed via LNS-UPF-LAC2-Terminal B. Alternatively, data distribution between terminals can be achieved in the UPF. In this case, the third tunnel is a part of the first tunnel and a part of the second tunnel.

[0082] In one embodiment, S1, obtaining the terminal access request from the source terminal to the target terminal, specifically includes:

[0083] The terminal is attached to a network communication management module, which includes a core network access and mobility management function (AMF) network element. The core network AMF network element receives terminal inter-terminal communication requests from the source terminal, obtains the MAC address of the source terminal and the MAC address of the target terminal based on the terminal inter-terminal communication request, and obtains the terminal inter-terminal communication data in the terminal inter-terminal communication request.

[0084] In this embodiment, the entity corresponding to the terminal-attached network communication management module is the self-developed terminal management platform, which involves core network elements such as AMF, SMF, and AAA server; the entity corresponding to the data tunnel construction module is the tunnel setting-related function in the self-developed service activation system; and the entity corresponding to the data supervision and distribution module is the self-developed LNS platform with IP routing matching function.

[0085] A specific signaling procedure could be:

[0086] Terminal A initiates a terminal mutual access request to the core network AMF (Access and Mobility Management Function), requesting access to terminal B as the target. The terminal mutual access request carries the MAC address of terminal A, the MAC address of the target terminal B, and the service data of the terminal mutual access.

[0087] The core network AMF requests the core network SMF (Service Management Function) to create a terminal communication session.

[0088] The core network SMF sends an authentication request to the AAA (Authentication, Authorization, Accounting) server based on the request.

[0089] The AAA server authenticates terminal A, determines whether terminal A has the permission to access other terminals, and sends the authentication result to the core network SMF.

[0090] The core network SMF sends an acknowledgment to the core network AMF, confirming the establishment of a terminal mutual access tunnel.

[0091] The core network SMF establishes an L2TP tunnel with the core network UPF and the LNS platform with IP routing capabilities.

[0092] When terminal communication data travels from the core network AMF to the core network UPF, it directly connects to the L2TP tunnel port on the core network UPF to reach the LNS platform with IP routing capabilities.

[0093] The LNS platform with IP routing capabilities authenticates the access data sent to the network security management system, receives feedback from the network security management system, and if the content is secure, obtains the corresponding IP address based on the MAC addresses of terminal A and terminal B, and sends the data to terminal B according to the IP routing.

[0094] In one embodiment, S2, a first data path and a second data path are obtained based on the terminal access request. The first data path leads to the network data monitoring platform, and the second data path connects the source terminal and the target terminal. Specifically, this includes:

[0095] A data tunnel construction module and a data policing and distribution module are set up in the core network. The data tunnel construction module includes the source LAC and the destination LAC, and the data policing and distribution module includes the LNS. The data tunnel construction module is connected to the network communication management module attached to the terminal.

[0096] Upon receiving a terminal inter-terminal communication request, the network communication management module attached to the terminal notifies the source LAC and the destination LAC to establish a first tunnel and a second tunnel.

[0097] The network communication management module attached to the terminal sends the source terminal MAC address, the target terminal MAC address, and the terminal communication data to the LNS through the first tunnel.

[0098] LNS queries the ARP table based on the source terminal MAC address and the target terminal MAC address to obtain the source terminal IP address and the target terminal IP address, and then obtains the first communication path and the second communication path based on the source terminal IP address and the target terminal IP address.

[0099] In this embodiment, as Figure 6 As shown, a terminal communication method includes:

[0100] S01: The terminal-attached network communication module receives a terminal inter-terminal communication request and determines the source and target terminals based on the request. The terminal-attached network communication management module can be analogous to a device management system. This system records the topology relationships between different terminals and controls inter-terminal communication requests. When an inter-terminal communication request occurs, this module plans the communication path and ultimately realizes inter-terminal communication through the data tunnel construction module and the data monitoring and distribution module.

[0101] S02: The data tunnel construction module establishes a tunnel between the core network UPF and the data supervision and distribution module. Located in the control plane of the core network, the data tunnel construction module can be compared to a core network management system. It is responsible for configuring and operating various network elements in the core network, and its main function here is tunnel construction.

[0102] S03: The terminal's attached network communication module uses a tunnel to send terminal communication data to the data supervision and distribution module. The terminal communication request mainly carries two parts of data: one part is the target terminal's information, and the other part is the service data that the sending terminal wants to send.

[0103] S04: The data monitoring and distribution module performs IP resolution analysis on the terminal communication data to determine the source and destination terminal IPs, and then distributes the terminal communication data to the terminal's downstream network communication module through a tunnel. The terminal's downstream network communication management module allocates IPs based on the network topology between terminals. Based on the topology of all managed terminals, the terminal's downstream network communication management module assigns an IP to each terminal and synchronizes its IP routing table with the data monitoring and distribution module. The IP routing table is stored in the data monitoring and distribution module, which handles IP resolution and interoperability.

[0104] S05: The network communication module attached to the terminal receives the inter-terminal communication data, as well as the source terminal IP and target terminal IP. After determining the terminal data, it routes the data and transmits it to the target terminal. The lack of oversight of inter-terminal communication data is the primary problem this embodiment aims to solve. To maintain the high-performance advantage of inter-terminal communication while ensuring network security and network management oversight, this solution was designed to make the inter-terminal communication process subject to oversight.

[0105] The terminal-mounted network communication management module only assigns IP addresses; the actual communication between these IPs is handled by the data monitoring and distribution module. This separation of the process into two distinct modules represents an optimized solution that maintains monitoring without adding extra communication overhead. The routing path for terminal data is determined by the terminal's underlying communication path, based on the topology between terminals and network scenario requirements.

[0106] In one embodiment, S3, the replication and distribution of terminal access data between the source terminal and the target terminal are realized through a first data path and a second data path, so as to realize data supervision of terminal access data through the first data path, and to realize terminal access between the source terminal and the target terminal through the second data path, specifically including:

[0107] LNS copies the terminal access data into two copies.

[0108] LNS sends the first set of terminal communication data to the network data supervision platform through its interface with the network data supervision platform.

[0109] LNS sends the target terminal IP address and the second set of terminal communication data to the terminal's network communication management module through the second tunnel.

[0110] The network communication management module attached to the terminal sends the second set of terminal communication data to the target terminal based on the target terminal's IP address.

[0111] In this embodiment, a supervisory function can be added to the UPF. Based on the current evolution trend of 5G (5th Generation Mobile Communication Technology) network technology, which is decoupling—primarily splitting different functions so that each network element is responsible for only one or a type of function—the UPF's main function is forwarding user plane data, requiring high performance and high throughput. In this embodiment, it is preferable that the UPF still independently completes its own tasks, while the interface with the network security management system is handled by other modules. This maintains functional decoupling. In this embodiment, the LNS is chosen to interface with the network security management system. A Layer 2 tunnel is used between the LNS and the UPF. Layer 2 tunnels are lower in the layer and faster, maintaining high communication performance while ensuring low latency for distributed data.

[0112] In one embodiment, after implementing data supervision of terminal inter-access data through a first data path, the method further includes:

[0113] In response to the failure to properly monitor the data exchange between terminals, the LNS will not send the target terminal IP address and the second set of terminal exchange data to the network communication management module attached to the terminal, and / or the LNS will interrupt subsequent terminal exchanges between the source terminal and the target terminal.

[0114] In this embodiment, generally speaking, as Figure 5The system comprises three modules: a terminal-mounted network communication module, responsible for authentication and management of the initiating and destination terminals during terminal communication, and adjusting terminal communication strategies for different application scenarios; a data monitoring and distribution module, responsible for monitoring and analyzing terminal communication data, allocating IP addresses for terminal communication, and located in the metropolitan area network (MAN) to achieve network monitoring through interfacing with the network security management system. This module cannot identify some attack behaviors on its own; it requires feedback from the network security management system to identify attacks. If an attack is detected, the access is interrupted, either for the current access or only for subsequent accesses. This means that distributed data may arrive at both the terminal and the monitoring platform simultaneously, with the second data path not waiting for feedback from the monitoring platform; and a data tunnel construction module, responsible for establishing a dedicated network tunnel between the terminal-mounted network communication module and the data monitoring and distribution module. This avoids Layer 3 routing on the core network UPF elements by using a Layer 2 tunnel, which operates at the data link layer (MAC layer) and can encapsulate various Layer 2 protocols (such as Ethernet frames, PPP (Point-to-Point Protocol)). With protocols, network data streams transmitted within a two-layer tunnel are more transparent to external systems or network environments. Communication within the tunnel can seamlessly transmit original data packets, protocols, and information without significantly altering or affecting the data stream.

[0115] Each of the above modules is not entirely equivalent to a network element. Each module contains some functions of a network element and involves the management plane (control plane) of the network element.

[0116] To facilitate understanding of the solution in this embodiment, let's take an example.

[0117] To illustrate, imagine different devices as different residents in a building, like resident A and resident B. Normally, residents aren't allowed to visit each other directly through the hallways. If resident A wants to visit resident B, they need to register at the property management office. This means resident A needs to go downstairs, exit the building, go to the property management office, register, return to the building entrance, and then go upstairs to resident B's apartment. This allows the property management office to clearly monitor visits between users.

[0118] However, if UPF terminal access is enabled, it allows different residents to visit each other directly through the hallways by knocking on each other's doors without needing to register with the property management office. This way, the property management office will not be aware of the visits between residents.

[0119] However, walking to the property management office is too far and too slow. Therefore, it was proposed to install an app in each household. This app would tell each resident where the unit door of the place they want to visit is located. Each household would also have a dedicated elevator leading directly to their unit door. For example, resident A could use their own elevator to reach their unit door, then find resident B's unit door on the app, register at resident B's unit door, and then directly take the dedicated elevator to resident B's apartment. Resident B's unit door would then directly report the visit to the property management office. This would be faster and allow the property management office to better manage the situation.

[0120] In the above examples, the residents are the terminals, the corridors are the UPF terminal access functions, the APP is the network communication management module attached to the terminal, the elevator leading to each unit is the data tunnel construction module, the unit door is the data supervision and distribution module, and the property management office is the network security management.

[0121] The design of "registering at the unit entrance" is one of the key innovations of this embodiment. Compared to the slow "roundabout" process via the public network, this embodiment avoids exposing data on the public network and distributes it directly through the data monitoring and distribution module, resulting in higher efficiency. Compared to the "direct" but unmonitored UPF terminal access, the data monitoring and distribution module "goes around to the unit entrance and communicates with the property management office through the unit entrance," maintaining monitoring while reasonably shortening the data transmission path and improving the efficiency of terminal access.

[0122] In summary, Embodiment 1 proposes a terminal interoperability system and method. Through a data monitoring and distribution module, it achieves full-process tracking and recording of data interactions between terminals, ensuring data security and effective monitoring. The data tunnel construction module avoids the three-layer routing conversion required in traditional UPF terminal interoperability technology, allowing data from the terminal to be directly transmitted to the data monitoring and distribution module, reducing latency and improving data processing efficiency. By attaching a network communication module to the terminal, the terminal device is not merely responsible for sending and receiving data, but can also collaborate with the network, participating in the selection of data transmission paths by sensing its own communication needs, resource status, and location.

[0123] While data is exchanged between terminal devices using UPF, fine-grained traffic classification and control are achieved (traffic classification and control are mainly achieved by establishing different tunnels). The monitoring module ensures the security of cross-terminal data interaction and meets network security and data compliance requirements (this is achieved by the data monitoring and distribution module forwarding data to the corresponding network security management platform). Simultaneously, it reduces data backhaul to other network elements in the core network, avoiding Layer 3 routing conversions on the UPF, thereby improving network performance for terminal inter-device communication. Dynamically optimizing transmission paths through terminal-based post-routing technology enhances communication efficiency between terminals, improves network adaptability and flexibility, and strengthens the performance of 5G networks in large-scale IoT terminal interconnection.

[0124] The principle behind the three-module design in this embodiment is that to achieve end-to-end monitoring of terminal inter-access, two fundamental problems need to be addressed: the first is how to identify and manage terminals, and the second is how to maintain monitoring during terminal inter-access. The first problem is addressed by using a network communication management module attached to the terminal. The second problem is solved by a data monitoring and distribution module, which interfaces with the network security management system. A derivative problem arises: how to achieve efficient communication between these two modules. This is addressed by using a data tunnel construction module. Since the data monitoring and distribution module is not on the public network, terminal inter-access data is transmitted through a tunnel, offering better privacy and performance. This three-module design is specifically designed to solve the problem of end-to-end monitoring of terminal inter-access. It features a streamlined structure, and because the data monitoring process is integrated with the network security management system through a distribution model, it offers better independence and compatibility.

[0125] Example 2:

[0126] like Figure 2 As shown, this disclosure provides a terminal inter-access management device, the device comprising:

[0127] Acquisition unit 1 is used to acquire terminal communication requests from the source terminal to the target terminal;

[0128] Path unit 2, connected to acquisition unit 1, is used to acquire a first data path and a second data path according to the terminal mutual access request. The first data path leads to the network data supervision platform, and the second data path connects the source terminal and the target terminal.

[0129] Distribution unit 3, connected to path unit 2, is used to copy and distribute terminal access data between source terminal and target terminal through a first data path and a second data path, so as to realize data supervision of terminal access data through the first data path and to realize terminal access between source terminal and target terminal through the second data path.

[0130] In one embodiment, wherein:

[0131] The first data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network user plane function UPF network element, and / or, a second communication path between the target terminal and the target network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and an interface path between the tunnel service platform and the network data supervision platform.

[0132] The second data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network UPF network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and a second communication path between the target terminal and the target network element; or, a first communication path between the source terminal and the source network element, a third tunnel between the source network element and the target network element via the core network UPF network element, and a second communication path between the target terminal and the target network element.

[0133] Distribution unit 3 includes a tunnel service platform or a core network UPF element. The tunnel service platform or core network UPF element copies the terminal mutual access data into two copies. The first copy of the terminal mutual access data is sent to the network data supervision platform through the first data path to realize data supervision, and the second copy of the terminal mutual access data is sent through the second data path to realize terminal mutual access.

[0134] In one embodiment, wherein:

[0135] The first and second tunnels are specifically Layer 2 Tunneling Protocol (L2TP) tunnels. The source network element includes the source L2TP Access Concentrator (LAC), and the destination network element includes the destination LAC. The tunnel service platform is specifically the L2TP Network Server (LNS). The first tunnel connects the source LAC, the core network UPF element, and the LNS in sequence, and the second tunnel connects the LNS, the core network UPF element, and the destination LAC in sequence.

[0136] In one embodiment, the device further includes a network communication management module attached to the terminal:

[0137] A network communication management module is set up under the terminal in the core network. The network communication management module under the terminal obtains the communication topology and media access control MAC address of the terminal. Based on the communication topology and MAC address, it assigns Internet Protocol (IP) address to each terminal. Based on the communication topology and IP address, it obtains the Address Resolution Protocol (ARP) table and sends the ARP table to the LNS so that the LNS has IP routing function.

[0138] In one embodiment, the acquisition unit 1 includes a network communication management module attached to the terminal:

[0139] The terminal is attached to a network communication management module, which includes a core network access and mobility management function (AMF) network element. The core network AMF network element receives terminal inter-terminal communication requests from the source terminal, obtains the MAC address of the source terminal and the MAC address of the target terminal based on the terminal inter-terminal communication request, and obtains the terminal inter-terminal communication data in the terminal inter-terminal communication request.

[0140] In one embodiment, path unit 2 includes a data tunnel construction module and a data monitoring and distribution module:

[0141] A data tunnel construction module and a data policing and distribution module are set up in the core network. The data tunnel construction module includes the source LAC and the destination LAC, and the data policing and distribution module includes the LNS. The data tunnel construction module is connected to the network communication management module attached to the terminal.

[0142] Upon receiving a terminal inter-terminal communication request, the network communication management module attached to the terminal notifies the source LAC and the destination LAC to establish a first tunnel and a second tunnel.

[0143] The network communication management module attached to the terminal sends the source terminal MAC address, the target terminal MAC address, and the terminal communication data to the LNS through the first tunnel.

[0144] LNS queries the ARP table based on the source terminal MAC address and the target terminal MAC address to obtain the source terminal IP address and the target terminal IP address, and then obtains the first communication path and the second communication path based on the source terminal IP address and the target terminal IP address.

[0145] In one embodiment, the distribution unit 3 includes an LNS:

[0146] LNS copies the terminal access data into two copies.

[0147] LNS sends the first set of terminal communication data to the network data supervision platform through its interface with the network data supervision platform.

[0148] LNS sends the target terminal IP address and the second set of terminal communication data to the terminal's network communication management module through the second tunnel.

[0149] The network communication management module attached to the terminal sends the second set of terminal communication data to the target terminal based on the target terminal's IP address.

[0150] In one embodiment, the apparatus further includes a regulatory response unit, including an LNS, for:

[0151] In response to the failure to properly monitor the data exchange between terminals, the LNS will not send the target terminal IP address and the second set of terminal exchange data to the network communication management module attached to the terminal, and / or the LNS will interrupt subsequent terminal exchanges between the source terminal and the target terminal.

[0152] It is understood that the units and modules described in this embodiment can all be partial functions set in some physical device entities. For example, "distribution unit 3 includes LNS" can mean that at least some of the functions corresponding to distribution unit 3 are set in LNS. "acquisition unit 1 includes terminal-attached network communication management module, and terminal-attached network communication management module includes core network access and mobility management function (AMF) network element" is also a similar expression, that is, at least some of the functions corresponding to terminal-attached network communication management module are set in core network AMF network element, and at least some of the functions corresponding to terminal-attached network communication management module are the same as at least some of the functions corresponding to acquisition unit 1.

[0153] Example 3:

[0154] Embodiment 3 of this disclosure provides a computer-readable storage medium storing a computer program. When the computer program is run by a processor, it implements the terminal access management method as described in Embodiment 1, or the terminal access management device as described in Embodiment 2.

[0155] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program units, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.

[0156] Alternatively, this disclosure may also provide a computer device including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the terminal access management method as described in Embodiment 1. This computer device may be the terminal access management device as described in Embodiment 2.

[0157] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.

[0158] Embodiments 1-3 of this disclosure provide a terminal access management method, apparatus, and medium. Based on a terminal access request from a source terminal to a target terminal, a first data path leading to a network data monitoring platform and a second data path connecting the source terminal and the target terminal are obtained. The terminal access data is copied and distributed based on the first and second data paths, thereby enabling the monitoring of the terminal access data while realizing terminal access.

[0159] It is understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of this disclosure, and this disclosure is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and substance of this disclosure, and these modifications and improvements are also considered to be within the scope of protection of this disclosure.

Claims

1. A terminal inter-access management method, characterized in that, The method includes: Obtain terminal communication requests from the source terminal to the target terminal; Based on the terminal access request, a first data path and a second data path are obtained. The first data path leads to the network data supervision platform, and the second data path connects the source terminal and the target terminal, specifically including: A data tunnel construction module and a data policing and distribution module are set up in the core network. The data tunnel construction module includes the source LAC and the destination LAC, and the data policing and distribution module includes the LNS. The data tunnel construction module is connected to the network communication management module attached to the terminal. Upon receiving a terminal inter-terminal communication request, the network communication management module attached to the terminal notifies the source LAC and the destination LAC to establish a first tunnel and a second tunnel. The network communication management module attached to the terminal sends the source terminal MAC address, the target terminal MAC address, and the terminal communication data to the LNS through the first tunnel. LNS queries the ARP table based on the source terminal MAC address and the target terminal MAC address to obtain the source terminal IP address and the target terminal IP address, and then obtains the first communication path and the second communication path based on the source terminal IP address and the target terminal IP address. The LNS enables the replication and distribution of terminal access data between the source terminal and the target terminal, thereby enabling data supervision of the terminal access data through the first data path, and enabling terminal access between the source terminal and the target terminal through the second data path.

2. The method according to claim 1, characterized in that, in: The first data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network user plane function UPF network element, and / or, a second communication path between the target terminal and the target network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and an interface path between the tunnel service platform and the network data supervision platform. The second data path includes: a first communication path between the source terminal and the source network element, a first tunnel between the source network element and the tunnel service platform via the core network UPF network element, a second tunnel between the target network element and the tunnel service platform via the core network UPF network element, and a second communication path between the target terminal and the target network element; or, a first communication path between the source terminal and the source network element, a third tunnel between the source network element and the target network element via the core network UPF network element, and a second communication path between the target terminal and the target network element. The tunnel service platform or the core network UPF element copies the terminal access data into two copies. The first copy of the terminal access data is sent to the network data supervision platform through the first data path to achieve data supervision, and the second copy of the terminal access data is sent through the second data path to achieve terminal access.

3. The method according to claim 2, characterized in that, in: The first and second tunnels are specifically Layer 2 Tunneling Protocol (L2TP) tunnels. The source network element includes the source L2TP Access Concentrator (LAC), and the destination network element includes the destination LAC. The tunnel service platform is specifically the L2TP Network Server (LNS). The first tunnel connects the source LAC, the core network UPF element, and the LNS in sequence, and the second tunnel connects the LNS, the core network UPF element, and the destination LAC in sequence.

4. The method according to claim 3, characterized in that, The method further includes: A network communication management module is set up under the terminal in the core network. The network communication management module under the terminal obtains the communication topology and media access control MAC address of the terminal. Based on the communication topology and MAC address, it assigns Internet Protocol (IP) address to each terminal. Based on the communication topology and IP address, it obtains the Address Resolution Protocol (ARP) table and sends the ARP table to the LNS so that the LNS has IP routing function.

5. The method according to claim 4, characterized in that, Obtain terminal communication requests from the source terminal to the target terminal, specifically including: The terminal is attached to a network communication management module, which includes a core network access and mobility management function (AMF) network element. The core network AMF network element receives terminal inter-terminal communication requests from the source terminal, obtains the MAC address of the source terminal and the MAC address of the target terminal based on the terminal inter-terminal communication request, and obtains the terminal inter-terminal communication data in the terminal inter-terminal communication request.

6. The method according to claim 1, characterized in that, The LNS enables the replication and distribution of terminal access data between the source terminal and the target terminal, thereby achieving data supervision of the terminal access data through a first data path, and enabling terminal access between the source terminal and the target terminal through a second data path, specifically including: LNS copies the terminal access data into two copies. LNS sends the first set of terminal communication data to the network data supervision platform through its interface with the network data supervision platform. LNS sends the target terminal IP address and the second set of terminal communication data to the terminal's network communication management module through the second tunnel. The network communication management module attached to the terminal sends the second set of terminal communication data to the target terminal based on the target terminal's IP address.

7. The method according to claim 6, characterized in that, After implementing data supervision of terminal inter-access data through the first data path, the method further includes: In response to the failure to properly monitor the data exchange between terminals, the LNS will not send the target terminal IP address and the second set of terminal exchange data to the network communication management module attached to the terminal, and / or the LNS will interrupt subsequent terminal exchanges between the source terminal and the target terminal.

8. A terminal inter-access management device, characterized in that, The device includes: The acquisition unit is used to acquire terminal communication requests from the source terminal to the target terminal. A path unit, connected to the acquisition unit, is used to acquire a first data path and a second data path based on a terminal inter-access request. The first data path leads to the network data monitoring platform, and the second data path connects the source terminal and the target terminal. Specifically, it includes: A data tunnel construction module and a data policing and distribution module are set up in the core network. The data tunnel construction module includes the source LAC and the destination LAC, and the data policing and distribution module includes the LNS. The data tunnel construction module is connected to the network communication management module attached to the terminal. Upon receiving a terminal inter-terminal communication request, the network communication management module attached to the terminal notifies the source LAC and the destination LAC to establish a first tunnel and a second tunnel. The network communication management module attached to the terminal sends the source terminal MAC address, the target terminal MAC address, and the terminal communication data to the LNS through the first tunnel. LNS queries the ARP table based on the source terminal MAC address and the target terminal MAC address to obtain the source terminal IP address and the target terminal IP address, and then obtains the first communication path and the second communication path based on the source terminal IP address and the target terminal IP address. The distribution unit, connected to the path unit, is used to replicate and distribute terminal access data between the source terminal and the target terminal through the LNS, to implement data supervision of the terminal access data through the first data path, and to implement terminal access between the source terminal and the target terminal through the second data path.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the terminal access management method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Terminal mutual access management system and method

    CN109660439A

  • Terminal mutual access method, device and system

    CN117062031A