Traffic processing method and device based on edge network, equipment and storage medium
By performing traffic processing on edge network devices, using user IDs for identity verification and associated information acquisition, the problem of user data isolation in 5G private network scenarios is solved, and centralized control and dynamic authorization of user data is realized.
Patent Information
- Application Number
- CN202311471547.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2025-05-06
AI Technical Summary
In the 5G private network scenario, the data of operator users and enterprise user are isolated from each other, resulting in the operator user plane function (UPF) being unable to perform network traffic offload based on the enterprise user ID.
By implementing the traffic processing method based on the edge network on the first network device, the request information corresponding to the application network sent by the terminal to access the target area is received, the user identification authentication is performed, the association information is obtained, and the traffic authorization information of the terminal is determined based on the network identification and association information to perform traffic permission processing.
It realizes centralized control and synchronization of user data of parks or enterprises, ensures the legal relationship between park user identity and operator access terminal identity, dynamic authorization, and traffic scheduling and diversion based on park user identity.
Smart Images

Figure CN119946631A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a traffic processing method, apparatus, related equipment and storage medium based on an edge network. Background Art
[0002] In the related technology, for the deployment of communication operators' fifth-generation mobile communication technology edge computing (5GMEC) private network scenarios in campus or enterprise networks, as 5G private network terminal users move from outside the campus or enterprise network to inside, user network traffic needs to be offloaded locally. However, the data of operator network users and enterprise users are isolated from each other, resulting in the operator's user plane function (UPF) being unable to offload network traffic based on enterprise user identification. Summary of the invention
[0003] In order to solve the related technical problems, the embodiments of the present application provide a traffic processing method, apparatus, related equipment and storage medium based on an edge network.
[0004] The technical solution of the embodiment of the present application is implemented as follows:
[0005] The embodiment of the present application provides a traffic processing method based on an edge network, which is applied to a first network device, including:
[0006] Receiving first request information corresponding to the application network of the access target area sent by the terminal; the first request information carries the user identifier corresponding to the terminal and the network identifier pre-configured by the first network device;
[0007] Perform identity authentication based on the user identifier to obtain a first authentication result; if the first authentication result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier;
[0008] Determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow authority processing on the terminal according to the flow authorization information.
[0009] In the above scheme, the method further comprises:
[0010] Obtaining a first identity identifier of a user corresponding to at least one of the terminals and a second identity identifier corresponding to a communication operator in the target area that is allowed to access at least one of the terminals;
[0011] The first identity identifier is associated with the second identity identifier to obtain the association information.
[0012] In the above scheme, the method further comprises:
[0013] Configure first information corresponding to at least one user in the target area;
[0014] At each preset period, obtaining business authority information of a user corresponding to at least one enterprise in the target area;
[0015] The first information is updated based on the business authority information to obtain second information corresponding to the at least one user; the second information is used to verify the identity of the user to be registered in the target area.
[0016] In the above scheme, the method further comprises:
[0017] Acquire second request information for terminal registration, and verify the second request information based on the second information;
[0018] If the second request information is successfully verified, a third request information is sent to the second network device; the third request information is used by the second network device to open the corresponding business authority of the enterprise to which the corresponding user of the terminal belongs;
[0019] Receive first response information sent by the second network device based on the third request information, and use the first response information to determine a state parameter of the terminal corresponding to the target service; the state parameter represents whether the target service is activated.
[0020] In the above scheme, the method further comprises:
[0021] In a case where the state parameter indicates that the target service is in an activated state, receiving fourth request information sent by the terminal; the fourth request information carries a session type corresponding to the terminal;
[0022] Determine, based on the session type, a third identity identifier corresponding to the terminal that is allowed to be accessed by a corresponding communication operator in the target area;
[0023] Verifying, according to the third identity identifier, the identity of the corresponding communication operator in the target area that is allowed to access the terminal, to obtain a second verification result;
[0024] If the second verification result indicates that the identity authentication of the corresponding communication operator in the target area allowing access to the terminal is successful, sending a second response message based on the fourth request message to the second network device; the second response message is used by the second network device to allocate an Internet Protocol address IP to the terminal; the IP is used by the terminal to establish communication with the second network device;
[0025] Receive the fifth request information sent by the second network device; the fifth request information carries the IP; the IP is used to associate with the user identifier to obtain the association information.
[0026] In the above scheme, the method comprises:
[0027] When a preset condition is met, determining the identity data of the terminal in the target area according to the network identifier and the association information;
[0028] Acquire identification information of a corresponding communication operator in the target area that is allowed to access the terminal according to the identity data;
[0029] Determine the flow authorization information corresponding to the terminal based on the identification information.
[0030] In the above solution, the preset condition includes a first preset condition, and the method further includes:
[0031] Determining whether the first identity identifier and the second identity identifier are associated for the first time;
[0032] When the first identity identifier and the second identity identifier are associated for the first time, determining that the first preset condition is satisfied;
[0033] When the first identity identifier and the second identity identifier are not associated for the first time, it is determined that the first preset condition is not met.
[0034] In the above solution, the preset condition includes a second preset condition, and satisfying the second preset condition includes at least one of the following:
[0035] The Internet Protocol address IP corresponding to the terminal changes;
[0036] The port number corresponding to the terminal changes;
[0037] The Internet Protocol address IP corresponding to the application network of the target area accessed by the terminal changes;
[0038] The port number corresponding to the application network accessed by the terminal to the target area changes;
[0039] The access permission corresponding to the application network of the target area accessed by the terminal is changed.
[0040] The embodiment of the present application also provides a traffic processing method based on an edge network, which is applied to a terminal, including:
[0041] A first request message corresponding to an application network for accessing a target area is sent to a first network device; the first request message carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; the first request message is used by the network device to perform identity authentication using the user identifier to obtain a first authentication result; when the first authentication result indicates that the identity authentication of the user identifier is successful, associated information related to the user identifier is obtained; and traffic authorization information corresponding to the terminal is determined based on the network identifier and the associated information; and traffic permission processing is performed on the terminal based on the traffic authorization information.
[0042] The embodiment of the present application further provides a traffic processing method based on an edge network, which is applied to a second network device, including:
[0043] Receiving third request information sent by the first network device;
[0044] Using the third request information, opening the business authority corresponding to the enterprise to which the terminal corresponding user belongs;
[0045] A first response message generated based on the third request message is sent to the first network device; the first response message is used by the first network device to determine a state parameter of the terminal corresponding to the target service; the state parameter represents whether the target service is activated.
[0046] In the above scheme, the method further comprises:
[0047] receiving second response information based on fourth request information sent by the first network device; the fourth request information carries a session type corresponding to the terminal;
[0048] Allocating an Internet Protocol address (IP) to the terminal using the second response information; the IP is used for the terminal to establish communication with the second network device;
[0049] A fifth request message is sent to the first network device; the fifth request message carries the IP; the IP is used to associate the first network device with a user identifier corresponding to the terminal to obtain association information.
[0050] The embodiment of the present application further provides a traffic processing device based on an edge network, which is arranged on a first network device and includes:
[0051] A first receiving unit is used to receive first request information corresponding to the application network of the access target area sent by the terminal; the first request information carries the user identifier corresponding to the terminal and the network identifier pre-configured by the first network device;
[0052] An acquiring unit, configured to perform identity authentication based on the user identifier to obtain a first authentication result; if the first authentication result indicates that the identity authentication of the user identifier is successful, acquiring associated information related to the user identifier;
[0053] A processing unit is used to determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow authority processing on the terminal according to the flow authorization information.
[0054] The embodiment of the present application further provides a traffic processing device based on an edge network, which is arranged on a terminal and includes:
[0055] The first sending unit is used to send a first request message corresponding to an application network for accessing a target area to a first network device; the first request message carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; the first request message is used by the network device to perform identity authentication using the user identifier to obtain a first verification result; when the first verification result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier; and determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow permission processing on the terminal according to the flow authorization information.
[0056] The embodiment of the present application further provides a traffic processing device based on an edge network, which is arranged on a second network device, and includes:
[0057] A second receiving unit, configured to receive third request information sent by the first network device;
[0058] An activation unit, configured to activate the business authority corresponding to the enterprise to which the terminal corresponding user belongs by using the third request information;
[0059] The second sending unit is used to send a first response message generated based on the third request information to the first network device; the first response message is used by the first network device to determine the state parameters of the terminal corresponding to the target service; the state parameters represent whether the target service is activated.
[0060] The embodiment of the present application further provides a first network device, comprising: a first processor and a first memory for storing a computer program that can be run on the processor,
[0061] Wherein, when the first processor is used to run the computer program, it executes the steps of any one of the above-mentioned methods on the first network device side.
[0062] The embodiment of the present application further provides a terminal, comprising: a second processor and a second memory for storing a computer program that can be run on the processor,
[0063] Wherein, the second processor is used to execute the steps of any of the above-mentioned terminal side methods when running the computer program.
[0064] The embodiment of the present application further provides a second network device, comprising: a third processor and a third memory for storing a computer program that can be run on the processor,
[0065] Wherein, the third processor is used to execute the steps of any one of the above-mentioned methods on the second network device side when running the computer program.
[0066] An embodiment of the present application also provides a storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the computer program implements the steps of any method on the first network device side, or implements the steps of any method on the terminal side, or implements the steps of any method on the second network device side.
[0067] The edge network-based traffic processing method, apparatus, related equipment and storage medium provided by the embodiment of the present application, the first network device receives the first request information corresponding to the application network of the access target area sent by the terminal; the first request information carries the user identification corresponding to the terminal and the network identification pre-configured by the first network device; identity authentication is performed based on the user identification to obtain a first verification result; when the first verification result indicates that the identity authentication of the user identification is successful, the associated information related to the user identification is obtained; the traffic authorization information corresponding to the terminal is determined according to the network identification and the associated information; and the traffic permission processing is performed on the terminal according to the traffic authorization information. An embodiment of the present application is adopted, by receiving a first request message corresponding to an application network of an access target area (for example, a campus) sent by a terminal and carrying a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; identity authentication is performed based on the user identifier, and when the identity authentication of the user identifier is successful, associated information related to the user identifier is obtained; traffic authorization information corresponding to the terminal is determined based on the network identifier and the associated information; traffic permission processing is performed on the terminal based on the traffic authorization information, thereby realizing centralized management and control of campus or enterprise user data, synchronization of campus user data, and legal association between the campus user identity and the operator access terminal identity, so as to achieve functions such as dynamic authorization of user identity, traffic scheduling and diversion based on campus user identity, etc. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Figure 1 It is the schematic diagram of UL-CL;
[0069] Figure 2 Diverting for BP;
[0070] Figure 3 It is a schematic diagram of MEC-based diversion;
[0071] Figure 4 A schematic diagram of establishing authentication or authorization for a PDU session based on a DN-AAA server;
[0072] Figure 5 A flow chart of a method for traffic processing based on an edge network according to an embodiment of the present application;
[0073] Figure 6 This is a flow chart of another method for traffic processing based on edge network according to an embodiment of the present application;
[0074] Figure 7 This is a flow chart of another method for edge network-based traffic processing according to an embodiment of the present application, which is applied to a second network device;
[0075] Figure 8 This is a schematic diagram of the overall architecture of the system of the embodiment of the present application;
[0076] Fig. 9 This is a schematic diagram of the overall business process of the embodiment of this application;
[0077] Fig.10 This is a schematic diagram of the user identity registration process in the embodiment of the present application;
[0078] Fig.11 A schematic diagram of the process of binding a user identity in an embodiment of the present application;
[0079] Fig.12 A schematic diagram of the user identity binding relationship of the embodiment of the present application;
[0080] Fig.13 A schematic diagram of user traffic scheduling authorization in an embodiment of the present application;
[0081] Fig.14 A schematic diagram of unloading user traffic based on campus user identity in an embodiment of the present application;
[0082] Fig.15 This is a schematic diagram of the structure of a traffic processing device based on an edge network according to an embodiment of the present application;
[0083] Fig.16 This is a structural diagram of another edge network-based traffic processing device according to an embodiment of the present application;
[0084] Fig.17 This is a structural diagram of another edge network-based traffic processing device according to an embodiment of the present application;
[0085] Fig.18 This is a schematic diagram of the structure of the first network device in an embodiment of the present application;
[0086] Fig.19 This is a schematic diagram of the structure of the terminal in the embodiment of the present application;
[0087] Fig. 20 This is a schematic diagram of the structure of the second network device in an embodiment of the present application;
[0088] Fig.21 This is a schematic diagram of the structure of a traffic processing system based on an edge network according to an embodiment of the present application. DETAILED DESCRIPTION
[0089] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments.
[0090] For closed LAN scenarios, such as campus or enterprise networks, the network traffic within the campus or enterprise can be locally diverted by deploying a 5G MEC edge computing platform to meet the real-time, high-bandwidth and high-security requirements of mobile office, video surveillance, on-site data collection and other services within the enterprise.
[0091] In the 5G network, all Internet Protocol (IP) data flows associated with the current user are found based on the International Mobile Subscriber Identity (IMSI) or Subscription Permanent Identifier (SUPI) of the access terminal user, and then the service traffic is filtered based on the IP in the service flow. The 5G core network adopts a C / U separation architecture. The 5G MEC sinks the user plane function network element UPF to the edge of the network on demand according to service needs and is deployed close to the campus. At the same time, the session management function (SMF) is used to centrally schedule the traffic of users accessing IMSI or SUPI. At present, the 3GPP standard defines three diversion schemes, namely, uplink classifier (UL-CL) diversion, Internet Protocol Version 6 branching point (IPv6 BP) diversion and local area data network (LADN) diversion.
[0092] UL-CL diversion: The protocol data unit (PDU) session types supported by UL-CL include IPv4, IPv6, IPv4v6 or Ethernet. The Session Management Function (SMF) decides to insert a "UL CL" into the data path of the current PDU session. The UPF supporting the UL-CL function diverts the local network traffic by matching the flow filter provided by the SMF, such as Figure 1 As shown, Figure 1 Schematic diagram of UL-CL.
[0093] BP splitting: By allocating multiple IPv6 prefix addresses to the terminal, using one PDU session to associate with multiple IPv6 prefixes, the local service traffic is forwarded to the local PDU session anchor point through the UPF supporting the "Branching Point" function according to the IPv6 prefix to complete the local traffic unloading, such as Figure 2 As shown, Figure 2 Divert for BP.
[0094] LADN offload: By configuring the DNN accessed by the UE as a LADN DNN, when the UE enters the area, a PDU session or SR request based on the LADN DNN is triggered, and the network traffic is offloaded to the local area.
[0095] As can be seen above, in the 3GPP standard diversion solution, the access user terminal UE does not participate in the diversion policy configuration. The core network side PCF / SMF / UPF and other network elements mainly perform traffic unloading policy control according to pre-configuration, and filter user traffic according to the access terminal user identity such as IMSI or SUPI. The enterprise / campus is unaware of and cannot control the local network traffic unloading.
[0096] In order to further optimize the UPF diversion strategy, the integration of MEC and 5G technical solutions is supplemented in the relevant standards, and MEC is defined as an extension and expansion of UPF. MEC can be used as an AF function to interconnect with PCF or NEF in the 5G core network through N5 / N33, and finally the diversion strategy configuration is sent to SMF through PCF, so that SMF can centrally schedule all traffic, and then the end user traffic is diverted through the N6 interface. If the Mp2 interface between the MEC platform and UPF is available, traffic rule control can also be implemented through the MEC platform and UPF through the Mp2 interface, such as Figure 3 As shown, Figure 3 Schematic diagram of MEC-based diversion.
[0097] It can be seen that the above technical solutions are mainly based on the terminal access user source IP quintuple or access-specific DNN for service traffic filtering and diversion, which has nothing to do with campus or enterprise users. In addition, network user identifiers such as IMSI or SUPI are key network assets and are at risk of exposure. In order to ensure the legitimacy of access users, 3GPP defines DN-AAA Server in standards TS501 and TS502. During the PDU session establishment process, the enterprise / campus performs secondary authentication and authorization of local users through network element control such as SMF, and defines user identity through DN for authentication and authorization. During the authentication and authorization process, the core network SMF and others are required to provide asset information such as IMSI, SUPI or GPSI of mobile terminal users, as well as the assigned IP address. However, authentication and authorization are only implemented for the access terminal user identity, and there is no user traffic filtering and diversion capability. The specific solutions are as follows: Figure 4 As shown, Figure 4 Schematic diagram of establishing authentication or authorization for a PDU session based on a DN-AAA server.
[0098] The business process is as follows:
[0099] Step 1: If there is no existing N4 session available to carry DN related messages between SMF and DN, the SMF selects UPF and triggers N4 session establishment.
[0100] Step 2: The SMF initiates an authentication procedure with the DN-AAA via the UPF to authenticate the DN-specific identity provided by the UE. If available, the SMF provides the IMSI, SUPI or GPSI in the signaling exchanged with the DN-AAA. The UPF transparently relays the message received from the SMF to the DN-AAA server.
[0101] Steps 3a to 3e: The DN-AAA server sends authentication / authorization messages to SMF, AMF, and UE in turn. The messages are transmitted through UPF and return the terminal access authentication / authorization request.
[0102] Step 4: DN-AAA Server performs authentication / authorization response according to the authentication and authorization scopes.
[0103] Step 5: Establish a terminal PDU session based on the authorization information.
[0104] Step 6: The core network notifies the DN-AAA Server to allocate an IP address to the terminal.
[0105] As mentioned above, the user identity of the enterprise / campus and the user identity in the operator network are isolated from each other. At the same time, the 3GPP standard diversion solution does not require the participation of the UE terminal. The diversion rules are mainly configured based on the core network. In addition, in the MEC technical solution, the MEC platform can deploy AF to notify the UPF diversion rules to the SMF through the N5 / N33 interface, thereby realizing local unloading of network traffic through UL-CL / IPv6 BP / LADN. In the above solution, there are two key issues:
[0106] (1) The UE access terminal identity is isolated from the enterprise / campus user and cannot form an association relationship. The enterprise or campus has its own user system, which is isolated from the communication operator's user system (IMSI, SUPI, GPSI, etc.). Since SUPI, GPSI, etc. are key network assets of the communication operator, there is a huge potential risk of exposure, and it is necessary to solve the problem of secure binding between the two.
[0107] (2) Enterprise / campus user identities cannot be synchronized in real time and automatically. Enterprise or campus users may change dynamically with operations such as joining or leaving the company. The standard traffic diversion solution defined by 5G MEC cannot be synchronized with the enterprise / campus in real time after completing the configuration of the core network, thus failing to ensure the legitimacy of users accessing the 5G private network.
[0108] Therefore, in response to the above-mentioned problems, the present invention provides an edge computing network traffic unloading method based on enterprise user identity to solve how to associate the access terminal identity (IMSI, SUPI, GPSI, etc.) with the campus user identity, how to dynamically synchronize user data in real time, and how to perform local traffic unloading based on the enterprise / campus’ own user identity.
[0109] Based on this, in various embodiments of the present application, by taking the cache size range of the terminal in the first cycle as the ratio of the benchmark, the range of the benchmark is adjusted, so that the first information in the BSR indicates that the cache size range of the closest level is taken in a larger direction more accurately, and there is no indicated cache size range that is too large, so as not to waste wireless resources, so as to improve the utilization rate of wireless resources and system capacity. The present application provides a traffic processing method based on an edge network, which is applied to a first network device, such as Figure 5 As shown, Figure 5 A flow chart of a method for traffic processing based on an edge network according to an embodiment of the present application includes:
[0110] Step 501: receiving first request information corresponding to an application network for accessing a target area sent by a terminal; the first request information carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device;
[0111] Step 502: Perform identity authentication based on the user identifier to obtain a first authentication result; if the first authentication result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier;
[0112] Step 503: Determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow authority processing on the terminal according to the flow authorization information.
[0113] It should be noted that the first network device is determined according to actual conditions and is not limited here. As an example, the first network device can be a multi-access edge computing network device, such as an MEC platform. In actual applications, three modules can be added on the basis of the original functions of the MEC platform. The three modules are "service activation agent module SRPM", "campus identity management module PUIMM" and "5G traffic scheduling module 5G-TCM".
[0114] The terminal may also be determined according to actual conditions, which is not limited here. As an example, the terminal may be a user terminal, a user equipment (User Equipment, UE), for example, an initial access terminal.
[0115] In step 501, the target area can be understood as an area corresponding to a closed local area network scenario, which can be determined according to specific circumstances and is not limited here. As an example, the target area can be a park or an enterprise.
[0116] The first request information carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; wherein the user identifier may be an identifier representing the identity of the user, which is not specifically limited here. As an example, the user identifier may be information such as the user's mobile phone number, name, ID card, etc. The network identifier pre-configured by the first network device.
[0117] In step 502, performing identity authentication based on the user identifier to obtain a first authentication result can be understood as performing access authority authentication based on the user identifier to obtain a first authentication result indicating whether the identity authentication of the user identifier is successful or unsuccessful.
[0118] When the first verification result indicates that the identity authentication of the user identifier is successful, the associated information related to the user identifier is obtained; wherein the associated information can be determined based on the actual situation and is not limited here. As an example, the associated information can include the campus user identity identifier and the access terminal IP address; for example, the associated information can include the assigned IP address and IMSI, SUPI or GPSI information.
[0119] In actual applications, the initial access terminal user is authenticated for access rights, and the secondary authentication process is performed by optimizing the DN-AAA Server. When the "access rights" is configured as True, the access terminal user is allowed to successfully register with the campus network DNN. Otherwise, the access terminal user registration fails, thereby denying the access user access to the campus application. When the access user terminal access authentication succeeds, the 5G core network negotiates or allocates IP addresses and IMSI, SUPI or GPSI data with the DN-AAA Server.
[0120] In step 503, the traffic authorization information corresponding to the terminal is determined according to the network identifier and the associated information; wherein the traffic authorization information can be determined according to actual conditions and is not limited here. As an example, the traffic authorization information may include UTSAC messages and / or traffic diversion rules and / or scheduling strategies.
[0121] Performing traffic permission processing on the terminal according to the traffic authorization information can be understood as limiting the flow of the terminal according to the traffic authorization information and not allowing access to the target application, or diverting the terminal according to the traffic authorization information and allowing access to the target application.
[0122] In actual applications, user traffic scheduling authorization is completed according to the network identifier and the associated information. According to the user traffic routing rules, the core network diverts the user data and enters the 5G traffic scheduling module 5G-TCM through the N6 or Mp2 interface. The application diversion permission is further processed according to the application authorization list. When the application permission is to allow access, 5G-TCM matches according to the access terminal user IP, port number, application IP address, port number, and protocol. If the match is successful, the traffic is allowed to access the target application through the IF6 interface, otherwise the access is denied and the response data message is directly discarded.
[0123] In an embodiment of the present application, a first request message corresponding to an application network of an access target area (for example, a campus) sent by a receiving terminal carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; identity authentication is performed based on the user identifier, and when the identity authentication of the user identifier is successful, associated information related to the user identifier is obtained; traffic authorization information corresponding to the terminal is determined based on the network identifier and the associated information; traffic permission processing is performed on the terminal based on the traffic authorization information, thereby realizing centralized management and control of campus or enterprise user data, synchronization of campus user data, and legal association between the campus user identity and the operator access terminal identity, so as to achieve functions such as dynamic authorization of user identity, traffic scheduling and diversion based on campus user identity, etc.
[0124] In one embodiment, the method further comprises:
[0125] Obtaining a first identity identifier of a user corresponding to at least one of the terminals and a second identity identifier corresponding to a communication operator in the target area that is allowed to access at least one of the terminals;
[0126] The first identity identifier is associated with the second identity identifier to obtain the association information.
[0127] In the embodiment of the present application, the specific number of the terminals can be determined according to the actual situation and is not limited here. In practical applications, the first identity of the user corresponding to at least one of the terminals can be understood as the user identity of the access terminal; the second identity corresponding to at least one of the terminals allowed to access by the communication operator in the target area can be understood as the terminal identity allowed by the operator;
[0128] The first identity identifier is associated with the second identity identifier to obtain the association information; wherein, the association can be determined based on actual conditions and is not limited here. As an example, the association can be understood as establishing a binding relationship or establishing a corresponding relationship; the corresponding relationship can be a one-to-one corresponding relationship.
[0129] In one embodiment, the method further comprises:
[0130] Configure first information corresponding to at least one user in the target area;
[0131] At each preset period, obtaining business authority information of a user corresponding to at least one enterprise in the target area;
[0132] The first information is updated based on the business authority information to obtain second information corresponding to the at least one user; the second information is used to verify the identity of the user to be registered in the target area.
[0133] In this embodiment, the first information corresponding to at least one user in the target area is configured; wherein, the target area may be a park; the at least one user in the target area may be understood as a staff member of each enterprise in the park; the first information may be determined according to actual conditions and is not limited here. As an example, the first information may include identifying the user identity of the access terminal, identifying the terminal user authentication key, identifying the operator user identity, identifying the user name, identifying the user real-name authentication identity, identifying the user industry category, identifying the user service level, identifying the IP address type assigned to the access terminal, identifying the IP address assigned to the access terminal, etc.; for ease of understanding, the first information is illustrated here by example, and the first information may be understood as information related to the user basic data configuration data structure, as shown in Table 1.
[0134] Table 1 User basic data configuration data structure
[0135]
[0136]
[0137] In actual applications, basic user data configuration can be completed on the PUIMM module of the MEC platform, including the mobile phone number, name, ID card and other information of the access terminal user.
[0138] At every preset period, obtain the business authority information of the corresponding user of at least one enterprise in the target area; wherein, the preset period can be determined according to the actual situation and is not limited here. As an example, the preset period can be understood as a timing period, for example, 24 hours. The business authority information can be determined according to the actual situation and is not limited here. As an example, the business authority information can include data such as enterprise user identity identification and business usage authority, and specifically can be an employee ID for identifying the identity of the park user, a park or enterprise name for identifying the park or enterprise information to which the user belongs, a department for identifying the department to which the park user belongs, an application access right for describing the park user's access to application information and authority, and an access right for identifying whether the user is allowed to access the park data network. In actual applications, the business authority information can be understood as information related to the park user identity data structure, as shown in Table 2.
[0139] Table 2 Campus user identity data structure
[0140]
[0141]
[0142]
[0143] As an example, the PUIMM module periodically obtains enterprise user identity, business usage permissions and other data from the campus identity system through the IF5 interface. If the campus identity system does not open the interface, manual registration can be performed in the PUIMM module to obtain or register campus user identity data rules.
[0144] Updating the first information based on the business authority information to obtain the second information corresponding to the at least one user can be understood as determining whether to update the first information based on the business authority information, and obtaining the second information corresponding to the at least one user when the first information needs to be updated.
[0145] In actual application, user data is updated based on the service authority and the first information. The PUIMM module sends a campus user registration request to the SRPM module. As a service activation agent module, SRPM formats the registration request data sent by PUIMM, adapts it to the transmission protocol and data format required by the operator, and completes the service activation. The PUIMM module completes the user service activation status update. The initial status of the service activation status is not "inactivated". After receiving a successful service activation response, the service activation status is set to "activated".
[0146] In one embodiment, the method further comprises:
[0147] Acquire second request information for terminal registration, and verify the second request information based on the second information;
[0148] If the second request information is successfully verified, a third request information is sent to the second network device; the third request information is used by the second network device to open the corresponding business authority of the enterprise to which the corresponding user of the terminal belongs;
[0149] Receive first response information sent by the second network device based on the third request information, and use the first response information to determine a state parameter of the terminal corresponding to the target service; the state parameter represents whether the target service is activated.
[0150] In an embodiment of the present application, second request information for terminal registration is obtained, and the second request information is verified based on the second information; wherein, the second request information can be understood as a campus user registration request; verifying the second request information based on the second information can be understood as determining whether information consistent with the second request information can be matched in the second information, and if information consistent with the second request information can be matched in the second information, then the verification of the second request information is successful; if information consistent with the second request information cannot be matched in the second information, then the verification of the second request information is unsuccessful, that is, the verification fails.
[0151] In actual applications, the PUIMM module sends a campus user registration request to the SRPM module. As a service activation agent module, SRPM formats the registration request data sent by PUIMM and adapts it to the transmission protocol and data format required by the operator to complete the service activation. The PUIMM module completes the user service activation status update. The service activation status is initially not "inactivated". After receiving a successful service activation response, the service activation status is set to "activated".
[0152] In one embodiment, the method further comprises:
[0153] In a case where the state parameter indicates that the target service is in an activated state, receiving fourth request information sent by the terminal; the fourth request information carries a session type corresponding to the terminal;
[0154] Determine, based on the session type, a third identity identifier corresponding to the terminal that is allowed to be accessed by a corresponding communication operator in the target area;
[0155] Verifying, according to the third identity identifier, the identity of the corresponding communication operator in the target area that is allowed to access the terminal, to obtain a second verification result;
[0156] If the second verification result indicates that the identity authentication of the corresponding communication operator in the target area allowing access to the terminal is successful, sending a second response message based on the fourth request message to the second network device; the second response message is used by the second network device to allocate an Internet Protocol address IP to the terminal; the IP is used by the terminal to establish communication with the second network device;
[0157] Receive the fifth request information sent by the second network device; the fifth request information carries the IP; the IP is used to associate with the user identifier to obtain the association information.
[0158] In this embodiment, the state parameter indicating that the target service is in an activated state can be understood as the state parameter indicating that the activation state of the target service is set to "activated".
[0159] The fourth request information carries the session type corresponding to the terminal; wherein, the session type can be determined according to actual conditions and is not limited here. As an example, the session type can be understood as Access-Type; for example, the session type corresponding to a 4G terminal or the session type corresponding to a 5G terminal.
[0160] Based on the session type, determine the third identity identifier corresponding to the terminal that the corresponding communication operator in the target area allows to access; wherein the third identity identifier may be an identity identifier of the access terminal, for example, an access terminal IMSI identity identifier, an access terminal SUPI or GPSI identity identifier, etc.
[0161] The identity of the corresponding communication operator in the target area that is allowed to access the terminal is verified based on the third identity identifier, and obtaining the second verification result can be understood as matching the third identity identifier with the identity of the corresponding communication operator in the target area that is allowed to access the terminal. If the matches are consistent, the second verification result is obtained, indicating that the identity authentication of the corresponding communication operator in the target area that is allowed to access the terminal is successful; if the matches are inconsistent, the second verification result is obtained, indicating that the identity authentication of the corresponding communication operator in the target area that is allowed to access the terminal is unsuccessful. In actual applications, the campus identity management module PUIMM completes the access user identity authentication according to the configured User-Name. After the verification is passed, according to the Access-Type session type, if it is a 4G terminal user, the access terminal IMSI identity identifier is recorded; if it is a 5G terminal user, the access terminal identity identifier such as SUPI or GPSI is recorded.
[0162] The second response information is used by the second network device to allocate an Internet Protocol address IP to the terminal; wherein the IP can be understood as the IP address of the access network terminal; the IP used to establish communication between the terminal and the second network device can be understood as completing the establishment of the user terminal PDU session. In actual applications, after the access terminal user identity authentication is passed, the Access Acept success message is returned to the DN-AAA Server, UPF, UE, etc. in sequence through the IF4 interface. The access network terminal IP address is negotiated through the Accounting-request / Accounting-response accounting message to complete the establishment of the user terminal PDU session.
[0163] The IP is used to associate with the user identifier to obtain the association information; wherein the association can be understood as establishing a binding or corresponding relationship between the IP and the user identifier. In actual applications, the campus identity management module PUIMM obtains information through the IF4 interface to complete the binding between the user campus identity, the access terminal identity, and the access terminal IP address.
[0164] In one embodiment, the method further comprises:
[0165] When a preset condition is met, determining the identity data of the terminal in the target area according to the network identifier and the association information;
[0166] Acquire identification information of a corresponding communication operator in the target area that is allowed to access the terminal according to the identity data;
[0167] Determine the flow authorization information corresponding to the terminal based on the identification information.
[0168] In this embodiment, the preset condition can be determined according to actual conditions, which is not limited here. As an example, the preset condition can be understood as a trigger condition; the preset condition includes a first preset condition and a second preset condition; wherein the first preset condition and the second preset condition can both be determined according to actual conditions, which is not limited here. As an example, the first preset condition can be a first trigger condition; the second preset condition can be an event-based trigger condition.
[0169] The traffic authorization information may be determined according to actual conditions. As an example, the traffic authorization information may include a UTSAC message and / or a traffic diversion rule and / or a scheduling strategy.
[0170] Determine the identity data of the terminal in the target area according to the network identifier and the associated information; wherein the associated information can be determined according to actual conditions, and is not limited here. As an example, the associated information can be understood as information that has an associated relationship with the user identifier; the associated relationship can be determined according to actual conditions, and is not limited here. As an example, the associated relationship can be a corresponding relationship, for example, a corresponding relationship between a user identifier and a network identifier and target area identity data; in actual applications, the user identifier can be understood as a terminal identifier; the network identifier can be understood as an IP address corresponding to the terminal; the target area can be a park; the target area identity data can be park user identity data; the associated information can be a corresponding relationship between the terminal identifier and the IP address and park user identity data, and the corresponding relationship can also be understood as a binding relationship. Determine the identity data of the terminal in the target area according to the network identifier and the associated information can be understood as determining the user identifier corresponding to the network identifier in the associated information according to the network identifier, and then determining the target area identity data corresponding to the user identifier.
[0171] According to the identity data, the identification information of the corresponding communication operator in the target area that is allowed to access the terminal is obtained; wherein, the identification information can be determined according to the actual situation and is not limited here. As an example, the identification information can be the identification information of the traffic scheduling strategy.
[0172] Determining the traffic authorization information corresponding to the terminal based on the identification information can be understood as determining the traffic authorization information corresponding to the terminal based on the identification information of the traffic scheduling policy.
[0173] In actual applications, the trigger condition for sending a routing traffic rule proxy request to AF through the IF7 interface is that the user completes the identity information binding or the application access authorization list changes. There are two trigger conditions for the UTSAC message, namely the first trigger and the event-based trigger. After completing the collection of the user identity data, IP address and other information of the access terminal, the campus identity management module PUIMM sends a routing traffic rule proxy request to AF through the IF7 interface according to the user's access rights to the campus network application. The core network side diversion rules can be completed according to the configured user's permission to access the application. At the same time, the "User traffic scheduling authorization command (UTSAC)" is issued to the 5G traffic scheduling module 5G-TCM through the IF2 interface to finely manage the routing strategy, quality of service (QoS), ACL and other traffic scheduling strategies based on ports, protocols, etc. for user traffic, and reduce the diversion pressure on the 5G core network side.
[0174] In one embodiment, the preset condition includes a first preset condition, and the method further includes:
[0175] Determining whether the first identity identifier and the second identity identifier are associated for the first time;
[0176] When the first identity identifier and the second identity identifier are associated for the first time, determining that the first preset condition is satisfied;
[0177] When the first identity identifier and the second identity identifier are not associated for the first time, it is determined that the first preset condition is not met.
[0178] It should be noted that it is determined whether the first identity identifier and the second identity identifier are associated for the first time; wherein the first association can be understood as the first establishment of a binding or corresponding relationship. In this embodiment, the first preset condition can be understood as the first trigger condition.
[0179] In actual applications, when the campus identity management module PUIMM completes user identity binding for the first time, it triggers the campus identity management module PUIMM to send a UTSAC message to the 5G traffic scheduling module 5G-TCM through the IF2 interface.
[0180] In one embodiment, the preset condition includes a second preset condition, and satisfying the second preset condition includes at least one of the following:
[0181] The Internet Protocol address IP corresponding to the terminal changes;
[0182] The port number corresponding to the terminal changes;
[0183] The Internet Protocol address IP corresponding to the application network of the target area accessed by the terminal changes;
[0184] The port number corresponding to the application network accessed by the terminal to the target area changes;
[0185] The access permission corresponding to the application network of the target area accessed by the terminal is changed.
[0186] It should be noted that the second preset condition can be specifically determined according to actual conditions and is not limited here. A change in the Internet Protocol address IP corresponding to the terminal can be understood as a change in the IP address of the access terminal user; a change in the port number corresponding to the terminal can be understood as a change in the port number of the access terminal user; a change in the Internet Protocol address IP corresponding to the application network of the target area accessed by the terminal can be understood as a change in the access application IP address; a change in the port number corresponding to the application network of the target area accessed by the terminal can be understood as a change in the access application PORT number; a change in the access permission corresponding to the application network of the target area accessed by the terminal can be understood as a change in the application access permission, for example, "whether access is allowed" changes from True to False, or from False to True.
[0187] In this embodiment, the second preset condition can be understood as an event-based trigger condition. In actual applications, when one or more of the following conditions are met, the campus identity management module PUIMM is triggered to send a UTSAC message:
[0188] (1) The IP address of the access terminal user changes;
[0189] (2) The access terminal user port number is changed;
[0190] (3) Change of IP address for accessing applications;
[0191] (4) The port number of the access application PORT is changed;
[0192] (5) Application access permissions are changed, for example, "Is access allowed" is changed from True to False, or from False to True.
[0193] In this embodiment, based on the original functions of the MEC platform, three functional modules are added, namely "service provisioning proxy module SRPM", "campus identity management module PUIMM" and "5G traffic scheduling module 5G-TCM", and IF1, IF2, IF3, IF4, IF5, IF6, IF7 interfaces are added between the three modules and between the external systems to realize centralized management and control of campus / enterprise user data, synchronization of campus user data, and legal association between campus user identity and operator access terminal identity, so as to achieve functions such as dynamic authorization of user identity, traffic scheduling and diversion based on campus user identity, etc.
[0194] Accordingly, the embodiment of the present application also provides a traffic processing method based on an edge network, such as Figure 6 As shown, Figure 6 This is a flow chart of another method for traffic processing based on an edge network according to an embodiment of the present application, which is applied to a terminal and includes:
[0195] Step 601: Send a first request message corresponding to an application network for accessing a target area to a first network device; the first request message carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; the first request message is used by the network device to perform identity authentication using the user identifier to obtain a first verification result; when the first verification result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier; and determine the traffic authorization information corresponding to the terminal based on the network identifier and the associated information; and perform traffic permission processing on the terminal based on the traffic authorization information.
[0196] It should be noted that the first network device is determined according to actual conditions and is not limited here. As an example, the first network device can be a multi-access edge computing network device, such as an MEC platform. In actual applications, three modules can be added on the basis of the original functions of the MEC platform. The three modules are "service activation agent module SRPM", "campus identity management module PUIMM" and "5G traffic scheduling module 5G-TCM".
[0197] The terminal may also be determined according to actual conditions, which is not limited here. As an example, the terminal may be a user terminal, UE, for example, an initial access terminal.
[0198] In step 601, the target area can be understood as an area corresponding to a closed local area network scenario, which can be determined according to specific circumstances and is not limited here. As an example, the target area can be a park or an enterprise.
[0199] The first request information carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; wherein the user identifier may be an identifier representing the identity of the user, which is not specifically limited here. As an example, the user identifier may be information such as the user's mobile phone number, name, ID card, etc. The network identifier pre-configured by the first network device.
[0200] The first request information is used by the network device to perform identity authentication using the user identifier to obtain a first verification result, which can be understood as performing access authority authentication based on the user identifier to obtain a first verification result indicating whether the identity authentication of the user identifier is successful or unsuccessful.
[0201] When the first verification result indicates that the identity authentication of the user identifier is successful, the associated information related to the user identifier is obtained; wherein the associated information can be determined based on the actual situation and is not limited here. As an example, the associated information can include the campus user identity identifier and the access terminal IP address; for example, the associated information can include the assigned IP address and IMSI, SUPI or GPSI information.
[0202] In actual applications, the initial access terminal user is authenticated for access rights, and the secondary authentication process is performed by optimizing the DN-AAA Server. When the "access rights" is configured as True, the access terminal user is allowed to successfully register with the campus network DNN. Otherwise, the access terminal user registration fails, thereby denying the access user access to the campus application. When the access user terminal access authentication succeeds, the 5G core network negotiates or allocates IP addresses and IMSI, SUPI or GPSI data with the DN-AAA Server.
[0203] The traffic authorization information corresponding to the terminal is determined according to the network identifier and the associated information; wherein the traffic authorization information can be determined according to actual conditions and is not limited here. As an example, the traffic authorization information may include UTSAC messages and / or traffic diversion rules and / or scheduling strategies.
[0204] Performing traffic permission processing on the terminal according to the traffic authorization information can be understood as limiting the flow of the terminal according to the traffic authorization information and not allowing access to the target application, or diverting the terminal according to the traffic authorization information and allowing access to the target application.
[0205] In actual applications, user traffic scheduling authorization is completed according to the network identifier and the associated information. According to the user traffic routing rules, the core network diverts the user data and enters the 5G traffic scheduling module 5G-TCM through the N6 or Mp2 interface. The application diversion permission is further processed according to the application authorization list. When the application permission is to allow access, 5G-TCM matches according to the access terminal user IP, port number, application IP address, port number, and protocol. If the match is successful, the traffic is allowed to access the target application through the IF6 interface, otherwise the access is denied and the response data message is directly discarded.
[0206] Accordingly, the embodiment of the present application also provides a traffic processing method based on an edge network, such as Figure 7 As shown, Figure 7 This is a flow chart of another method for traffic processing based on an edge network according to an embodiment of the present application, which is applied to a second network device, including:
[0207] Step 701: Receive third request information sent by the first network device.
[0208] Step 702: Utilize the third request information to activate the corresponding business authority of the enterprise to which the terminal corresponding user belongs.
[0209] Step 703: Send a first response message generated based on the third request message to the first network device; the first response message is used by the first network device to determine the state parameters of the terminal corresponding to the target service; the state parameters represent whether the target service is activated.
[0210] It should be noted that the first network device is determined according to actual conditions and is not limited here. As an example, the first network device can be a multi-access edge computing network device, such as an MEC platform. In actual applications, three modules can be added on the basis of the original functions of the MEC platform. The three modules are "service activation agent module SRPM", "campus identity management module PUIMM" and "5G traffic scheduling module 5G-TCM".
[0211] The terminal may also be determined according to actual conditions, which is not limited here. As an example, the terminal may be a user terminal, UE, for example, an initial access terminal.
[0212] The second network device is determined according to actual conditions and is not limited here. As an example, the second network device may be a data network (DN). In actual applications, the second network device may include a campus identity system and campus applications.
[0213] In step 701, third request information sent by the first network device is received; wherein the third request information is used to activate the corresponding service authority of the enterprise to which the corresponding user of the terminal belongs.
[0214] In step 702, using the third request information to activate the business permissions corresponding to the enterprise to which the terminal corresponding user belongs can be understood as using the third request information to determine whether to activate the business permissions corresponding to the enterprise to which the terminal corresponding user belongs, and obtaining a judgment result of whether to activate the business permissions corresponding to the enterprise to which the terminal corresponding user belongs or not.
[0215] In step 703, a first response message generated based on the third request message is sent to the first network device; the first response message is used by the first network device to determine the state parameters of the target service corresponding to the terminal; wherein the state parameters may include the state parameters of the target service activation state being set to "activated" or the state parameters of the target service activation state being set to "inactivated".
[0216] In actual applications, the PUIMM module sends a campus user registration request to the SRPM module. As a service activation agent module, SRPM formats the registration request data sent by PUIMM and adapts it to the transmission protocol and data format required by the operator to complete the service activation. The PUIMM module completes the user service activation status update. The service activation status is initially not "inactivated". After receiving a successful service activation response, the service activation status is set to "activated".
[0217] In one embodiment, the method further comprises:
[0218] receiving second response information based on fourth request information sent by the first network device; the fourth request information carries a session type corresponding to the terminal;
[0219] Allocating an Internet Protocol address IP to the terminal using the second response information; the IP is used for the terminal to establish communication with the second network device;
[0220] A fifth request message is sent to the first network device; the fifth request message carries the IP; the IP is used to associate the first network device with a user identifier corresponding to the terminal to obtain association information.
[0221] In this embodiment, the fourth request information carries the session type corresponding to the terminal; wherein, the session type can be determined according to actual conditions and is not limited here. As an example, the session type can be understood as Access-Type; for example, the session type corresponding to a 4G terminal or the session type corresponding to a 5G terminal.
[0222] The second response information is used by the second network device to allocate an Internet Protocol address IP to the terminal; wherein the IP can be understood as the IP address of the access network terminal; the IP used to establish communication between the terminal and the second network device can be understood as completing the establishment of the user terminal PDU session. In actual applications, after the access terminal user identity authentication is passed, the Access Acept success message is returned to the DN-AAA Server, UPF, UE, etc. in sequence through the IF4 interface. The access network terminal IP address is negotiated through the Accounting-request / Accounting-response accounting message to complete the establishment of the user terminal PDU session.
[0223] The IP is used to associate with the user identifier to obtain the association information; wherein the association can be understood as establishing a binding or corresponding relationship between the IP and the user identifier. In actual applications, the campus identity management module PUIMM obtains information through the IF4 interface to complete the binding between the user campus identity, the access terminal identity, and the access terminal IP address.
[0224] This embodiment solves the problem of isolating the operator user system from the enterprise or campus user system. By associating the identities of the two, it is convenient to implement dynamic authorization based on the campus user identity, which can effectively enhance the efficiency of access terminal traffic control and the security of access terminal users, make the campus intranet service access controllable, and the access rights synchronized in real time, thereby improving the flexibility of user traffic service scheduling and diversion.
[0225] In practical applications, as an example, the edge network-based traffic processing method may specifically be an edge computing network traffic unloading method based on enterprise user identity identification; as an example, the first network device may be a multi-access edge computing network (for example, a MEC platform); the terminal may be a user terminal.
[0226] Step 1: Overall system architecture.
[0227] On the one hand, based on the original functions of the MEC platform, three modules are added, namely "Service Provisioning Agent Module SRPM", "Campus Identity Management Module PUIMM" and "5G Traffic Scheduling Module 5G-TCM". On the other hand, the interaction process between DN-AAAServer and SMF / UPF is optimized, and the permanent identity of the access user terminal and the negotiated IP address are reported during the secondary authentication process, and a new interface IF4 and signaling interaction process are added between the campus identity management module PUIMM. Among them, DN-AAA Server is usually deployed by operators and can be deployed inside the 5GC core network or in the campus DN data center according to actual conditions. Through the signaling interaction between DN-AAA Server and the campus identity management module PUIMM, the campus user identity is associated with the network user identity, so that the UPF and 5G traffic scheduling modules can be used for diversion according to the campus user identity. The functions of each module are shown below, and the overall system architecture is as follows: Figure 8 As shown, Figure 8 Schematic diagram of the overall architecture of the system according to the embodiment of the present application.
[0228] (1) Service Registration Proxy Module (SRPM): This module is carried on the MEC platform (MEC paltform) and sends requests to network elements such as the BOSS system or NEF deployed in the operator's 5G network to complete functions such as user identity registration and private network service activation.
[0229] (2) Park User Identity Management Module (PUIMM): This module is carried on the MEC platform (MEC paltform) and aggregates and manages park user identity information and 5G private network user identity information. It can manage and control functions such as user traffic offloading based on park user identities and data permissions.
[0230] (3) 5G-Traffic scheduling module (5G-TCM): This module is carried on the MEC platform (MEC paltform) and is used to receive dynamic authorization from the campus identity management module. It combines the UPF user traffic routing strategy to enhance user traffic scheduling and diversion functions.
[0231] In addition, interfaces and signaling interactions between the above modules and between modules and external systems are added inside and outside the MEC system, DN-AAA Server, AF, etc. The new interfaces include IF1, IF2, IF3, IF4, IF5, IF6, and IF7. Through signaling interaction, edge computing network traffic unloading is realized based on enterprise user identification, and the following functions are realized:
[0232] IF1: Interface between the campus identity management module PUIMM and the service provisioning proxy module SRPM to implement functions such as user service provisioning.
[0233] IF2: The interface between the campus identity management module PUIMM and the 5G traffic scheduling module 5G-TCM, which implements functions such as dynamic authorization of the campus identity management module and user traffic scheduling and diversion configuration.
[0234] IF3: The interface between the service provisioning proxy module SRPM and the external network such as BOSS is used to implement functions such as user private network service provisioning.
[0235] IF4: The interface between the campus identity management module PUIMM and the DN-AAA Server is used to obtain network user identity information, negotiated IP addresses, and perform secondary authentication and authorization on 5G terminals.
[0236] IF5: The interface between the campus identity management module PUIMM and the campus identity system, which implements functions such as campus identity information acquisition and access rights configuration.
[0237] IF6: The interface between the 5G traffic scheduling module 5G-TCM and the campus application to realize the target application user traffic data offloading.
[0238] IF7: The interface between the campus identity management module PUIMM and AF will work with AF to control SMF to establish a routing policy in the PDU session based on the enterprise user access authorization information, so as to route user traffic to the user's local data network.
[0239] Step 2: Overall technical solution.
[0240] By optimizing the DN-AAA Server secondary authorization / authentication process mechanism, the campus identity management module PUIMM associates the operator's network access terminal identity (such as IMSI, SUPI or GPSI, etc.) with the campus user, solving the risk of exposing key network asset information. At the same time, combined with UPF and 5G traffic scheduling module 5G-TCM, user traffic unloading based on campus / enterprise user identity is realized. It mainly includes four steps, namely user identity registration (Useridentity registration), user identity binding (User identity binding), user identity authentication / authorization (User identity authentication / authorization) and traffic unloading based on user identity (Traffic diversion based on user identity). The detailed business process and function description are as follows Fig. 9 As shown, Fig. 9 This is a schematic diagram of the overall business process of an embodiment of the present application.
[0241] Step 1: User identity registration: Obtain campus user identity information through external interface IF5, send data to verify campus identity, manage and allocate user rights.
[0242] Step 2: User identity binding: Based on the secondary authentication process, the access terminal user identity is obtained to associate the campus user identity with the operator access terminal identity.
[0243] Step 3: User identity authentication / authorization: After completing the collection of the access terminal user identity data, IP address and other information, complete the user traffic scheduling authorization based on the user's access rights to the campus network application.
[0244] Step 4: Traffic diversion based on user identity: When the access authentication of the user terminal is successful, the application diversion permission is processed according to the authorization information in step 3.
[0245] Step 3: User identity registration technical solution.
[0246] The campus identity management module PUIMM is used to centrally manage campus / enterprise user data, and the IF5 interface is used to synchronize data with the campus identity system. The service provisioning agent module SRPM is then used to complete the operator network data configuration. The specific business process is as follows: Fig.10 shown. Fig.10 This is a schematic diagram of the user identity registration process in an embodiment of the present application.
[0247] Process description:
[0248] Step 1: According to the network access user terminal information, complete the user basic data configuration on the PUIMM module, including the access terminal user's mobile phone number, name, ID card and other information. For specific rules, refer to the previous Table 1.
[0249] Step 2: The PUIMM module periodically obtains enterprise user identity, business usage rights and other data from the campus identity system through the IF5 interface. If the campus identity system does not open the interface, you can manually register in the PUIMM module. The rules for obtaining or registering campus user identity data refer to the previous Table 2. Step 3: Complete the user data update based on the information in Steps 1 and 2.
[0250] Steps 4a~4d: The PUIMM module sends a campus user registration request to the SRPM module. SRPM, as a service activation agent module, formats the registration request data sent by PUIMM and adapts it to the transmission protocol and data format required by the operator to complete the service activation. The specific implementation method is not within the scope of this solution.
[0251] Step 5: The PUIMM module completes the user service activation status update. The service activation status is initially not "inactivated". After receiving a successful service activation response, the service activation status is set to "activated".
[0252] Step 4: User identity binding technical solution.
[0253] When the access user terminal registers to the campus / enterprise private DNN, the 5G core network SMF is triggered to authenticate and authorize the PDU session establishment, and initiate secondary authentication / authorization to the DN-AAA Server, thereby completing the binding between the access terminal user identity and the campus user identity. The specific business process is as follows: Fig.11 As shown, Fig.11 This is a flowchart of user identity binding in an embodiment of the present application.
[0254] Process description:
[0255] Step 1: The access terminal UE carries the authentication message Authenticationmessage when initiating the PDU session establishment process, which includes at least the User-Name, User-Password and other information pre-configured by the campus identity management module PUIMM. It is processed by AMF, SMF and UPF in sequence and sent to the campus identity management module PUIMM through the IF4 interface adapter. Based on the 3GPP definition standard, the Access-Type and Subscription-Permanent-Identifier are newly added to identify the terminal user identity. The specific rules are shown in Table 3.
[0256] Table 3 User access request data structure
[0257]
[0258]
[0259] Step 2: The campus identity management module PUIMM completes the access user identity authentication according to the User-Name configured in the third step. After the authentication is passed, according to the Access-Type session type, if it is a 4G terminal user, the access terminal IMSI identity is recorded; if it is a 5G terminal user, the access terminal identity such as SUPI or GPSI is recorded.
[0260] Steps 3a to 3c: After the access terminal user identity authentication is passed, the Access Acept success message is returned to the DN-AAA Server, UPF, UE, etc. in sequence through the IF4 interface.
[0261] Step 4: Negotiate the IP address of the access network terminal through Accounting-request / Accounting-response accounting messages to complete the establishment of the user terminal PDU session.
[0262] Step 5: The campus identity management module PUIMM obtains information through the IF4 interface to complete the binding between the user campus identity, access terminal identity, and access terminal IP address, such as Fig.12 As shown, Fig.12 A schematic diagram of the user identity binding relationship in an embodiment of the present application.
[0263] Step 5: User identity authorization technical solution.
[0264] Step 1: User traffic scheduling authorization command.
[0265] After completing the collection of user identity data, IP address and other information of the access terminal, the campus identity management module PUIMM sends a routing traffic rule proxy request to AF through the IF7 interface based on the user's access rights to the campus network application, and can complete the core network side diversion rules according to the configured user's permission to access the application. At the same time, the "User Traffic Scheduling Authorization Command (UTSAC)" is sent to the 5G traffic scheduling module 5G-TCM through the IF2 interface to perform refined management of routing strategies, QoS, ACL and other traffic scheduling strategies based on user traffic ports, protocols, etc., and reduce the diversion pressure on the 5G core network side, such as Fig.13 As shown, Fig.13 A schematic diagram of user traffic scheduling authorization in an embodiment of the present application.
[0266] The data structure of the user traffic scheduling authorization command UTSAC message is shown in Table 4.
[0267] Table 4 Data structure of UTSAC message
[0268] For the "user campus identification", its implementation method is the same as the "employee ID" in the "campus user identity" data structure in the third step.
[0269] The implementation method of "User Network Identifier" is the same as that of "Subscription-Permanent-Identifier" in the data structure of "User Access Request" in step 4.
[0270] For the "access terminal IP address", its implementation method is the same as the "allocation of IP address" in the third step "campus user identity" data structure.
[0271] For the "application access authorization list", at least the application name, application access IP address, application access port number, protocol type, and whether access is allowed. Among them, the "application name" is implemented as a string, including numbers, letters, and Chinese characters; the "application access IP address" is implemented as a string that meets the IPV4 or IPv6 format; the "application access port number" is implemented as an integer with a value range of 1 to 65535; the "protocol type" is implemented as a string, including HTTP, HTTPS, TCP, UDP, etc.; the "whether access is allowed" is implemented as a Boolean type. When the value is True, access to the application is allowed, and when the value is False, access to the application is prohibited.
[0272] Step 2: Trigger conditions.
[0273] For sending routing traffic rule proxy requests to AF through the IF7 interface, the triggering condition is that the user completes the identity information binding or the application access authorization list changes.
[0274] There are two trigger conditions for UTSAC messages, namely first trigger and event-based trigger. The specific implementation methods are as follows:
[0275] First trigger condition: When the campus identity management module PUIMM completes the user identity binding for the first time, the campus identity management module PUIMM is triggered to send a UTSAC message to the 5G traffic scheduling module 5G-TCM through the IF2 interface.
[0276] Based on event trigger conditions: When one or more of the following conditions are met, the campus identity management module PUIMM is triggered to send a UTSAC message:
[0277] (6) The IP address of the access terminal user changes;
[0278] (7) Change of access terminal user port number;
[0279] (8) Change of IP address for accessing applications;
[0280] (9) The port number of the access application PORT is changed;
[0281] (10) Application access permission changes, for example, "Is access allowed" changes from True to False, or from False to True.
[0282] Step 3: Implement traffic offloading based on campus user identity.
[0283] After completing user authentication and authorization, UPF diverts the access terminal traffic to the core network side according to the SMF routing traffic rules, and then distributes it to the MEC platform through the N6 or Mp2 interface. The 5G traffic scheduling module 5G-TCM performs further refined traffic control according to the user traffic scheduling authorization command UTSAC. The user service traffic scheduling is completed through the combination of the two, and the business process is realized as follows: Fig.14 As shown, Fig.14 This is a schematic diagram of unloading user traffic based on campus user identity in an embodiment of the present application.
[0284] Step 1: First, perform access authority authentication on the initial access terminal user. As described in step 3, perform secondary authentication by optimizing the DN-AAA Server. When "Access Authority" is configured as True, the access terminal user is allowed to successfully register with the campus network DNN. Otherwise, the access terminal user registration fails, thereby denying the access user access to campus applications.
[0285] Step 2: Secondly, when the access authentication of the access user terminal is successful, the 5G core network and the DN-AAA Server negotiate or allocate the IP address and IMSI, SUPI or GPSI data, and complete the user identity binding as described in the fourth step and complete the user traffic scheduling authorization as described in Section 5.5.1.
[0286] Step 3: According to the user traffic routing rules, the core network diverts the user data and enters the 5G traffic scheduling module 5G-TCM through the N6 or Mp2 interface. It further processes the application diversion permission according to the application authorization list in step 2. When the application permission is to allow access, 5G-TCM matches according to the access terminal user IP, port number, application IP address, port number, and protocol. If the match is successful, the traffic is allowed to access the target application through the IF6 interface. Otherwise, access is denied and the response data message is directly discarded.
[0287] The present invention provides an edge computing network traffic unloading method based on enterprise user identity to solve the problems of how to associate access terminal identity (IMSI, SUPI, GPSI, etc.) with campus user identity, dynamic real-time synchronization of user data, and how to perform local traffic unloading based on enterprise / campus owned user identity.
[0288] The improvements of this application are mainly reflected in the following aspects:
[0289] 1. On the basis of the original functions of the MEC platform, three functional modules are added, namely "Service Provisioning Proxy Module SRPM", "Park Identity Management Module PUIMM" and "5G Traffic Scheduling Module 5G-TCM", and IF1, IF2, IF3, IF4, IF5, IF6, IF7 interfaces are added between the three modules and between the external systems to realize centralized management and control of park / enterprise user data, synchronization of park user data, and legal association between park user identity and operator access terminal identity, so as to achieve functions such as dynamic authorization of user identity, traffic scheduling and diversion based on park user identity, etc.
[0290] 2. Optimize the interaction process and data between DN-AAA Server and SMF / UPF, including at least Access-Type and Subscription-Permanent-Identifier, and add them to the signaling process between PUIMM of the campus identity management module of the MEC platform.
[0291] 3. A new campus user identity registration signaling interaction process is added, which at least includes user basic data configuration, campus / enterprise user data synchronization, and campus user service activation. Among them, user basic data at least includes User-Name, User-Password, mobile phone number, name, ID card and other information, and campus / enterprise user data synchronization data at least includes employee ID, campus / enterprise name, department, application access rights, access rights and other information.
[0292] 4. Add a new IF7 interface to send a routing traffic rule proxy request signaling process to AF, and a new user traffic scheduling authorization command UTSAC. The message includes at least the user campus ID, user network ID, access terminal IP address, access terminal port number, and application access authorization list. The application access authorization list includes at least the application name, application access IP address, application access port number, protocol type, and whether access is allowed.
[0293] The present invention proposes a new method for unloading edge computing network traffic based on enterprise user identity. By optimizing the secondary authentication process and data of DN-AAA Server, adding service activation proxy module SRPM, campus identity management module PUIMM and 5G traffic scheduling module 5G-TCM on the MEC platform, as well as the signaling process of interaction between modules and modules and external systems, the association between campus user identity and operator access terminal identity, centralized user data management and data synchronization, dynamic authorization of user identity, and traffic scheduling and diversion based on campus user identity are realized.
[0294] Compared with the prior art, the advantages of the present invention are: solving the problem of isolation between the operator user system and the enterprise or park user system, and facilitating the implementation of dynamic authorization based on the park user identity by associating the identities of the two, which can effectively enhance the access terminal traffic control efficiency and access terminal user security, make the park intranet service access controllable, and access rights synchronized in real time, thereby improving the flexibility of user traffic service scheduling and diversion.
[0295] In order to implement the method of the embodiment of the present application, the embodiment of the present application also provides a traffic processing device based on an edge network, which is arranged on a first network device, such as Fig.15 As shown, Fig.15 This is a schematic diagram of the structure of a traffic processing device based on an edge network according to an embodiment of the present application; the device 1500 includes:
[0296] The first receiving unit 1501 is used to receive first request information corresponding to the application network of the access target area sent by the terminal; the first request information carries the user identifier corresponding to the terminal and the network identifier pre-configured by the first network device;
[0297] The acquisition unit 1502 is configured to perform identity authentication based on the user identifier to obtain a first authentication result; if the first authentication result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier;
[0298] The processing unit 1503 is used to determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow authority processing on the terminal according to the flow authorization information.
[0299] In one embodiment, the acquisition unit is also used to obtain a first identity identifier of a user corresponding to at least one of the terminals and a second identity identifier corresponding to at least one of the terminals that is allowed to be accessed by a corresponding communication operator in the target area; and associate the first identity identifier with the second identity identifier to obtain the association information.
[0300] In one embodiment, the device further includes a configuration unit and an update unit; wherein,
[0301] The configuration unit is used to configure first information corresponding to at least one user in the target area;
[0302] The acquisition unit 1502 is further configured to acquire, at a preset period, business authority information of a user corresponding to at least one enterprise in the target area;
[0303] The updating unit is used to update the first information based on the service authority information to obtain second information corresponding to the at least one user; the second information is used to verify the identity of the user to be registered in the target area.
[0304] In one embodiment, the device further comprises a sending unit; wherein,
[0305] The acquisition unit 1502 is also used to obtain the second request information for the terminal registration, and verify the second request information based on the second information;
[0306] The sending unit is used to send third request information to the second network device when the second request information is successfully verified; the third request information is used by the second network device to open the corresponding business rights of the enterprise to which the corresponding user of the terminal belongs;
[0307] The first receiving unit 1501 is further configured to receive a first response message sent by the second network device based on the third request message, and use the first response message to determine a state parameter of the terminal corresponding to the target service; the state parameter represents whether the target service is activated.
[0308] In one embodiment, the first receiving unit 1501 is further configured to receive fourth request information sent by the terminal when the state parameter indicates that the target service is in an activated state; the fourth request information carries a session type corresponding to the terminal;
[0309] The processing unit 1503 is further configured to determine, based on the session type, a third identity identifier corresponding to the communication operator in the target area that is allowed to access the terminal; and verify the identity of the communication operator in the target area that is allowed to access the terminal according to the third identity identifier to obtain a second verification result;
[0310] The sending unit is further used to send a second response message based on the fourth request message to the second network device if the second verification result indicates that the identity authentication of the corresponding communication operator in the target area allowing access to the terminal is successful; the second response message is used by the second network device to allocate an Internet Protocol address IP to the terminal; the IP is used by the terminal to establish communication with the second network device;
[0311] The first receiving unit is further used to receive the fifth request information sent by the second network device; the fifth request information carries the IP; the IP is used to associate with the user identifier to obtain the association information.
[0312] In one embodiment, the processing unit 1503 is also used to determine the identity data of the terminal in the target area based on the network identifier and the associated information when a preset condition is met; obtain the identification information of the corresponding communication operator in the target area that is allowed to access the terminal based on the identity data; and determine the traffic authorization information corresponding to the terminal based on the identification information.
[0313] In one embodiment, the preset condition includes a first preset condition, and the device 700 also includes a judgment unit for judging whether the first identity identifier and the second identity identifier are associated for the first time; if the first identity identifier and the second identity identifier are associated for the first time, it is determined that the first preset condition is met; if the first identity identifier and the second identity identifier are not associated for the first time, it is determined that the first preset condition is not met.
[0314] In one embodiment, the preset condition includes a second preset condition, and satisfying the second preset condition includes at least one of the following:
[0315] The Internet Protocol address IP corresponding to the terminal changes;
[0316] The port number corresponding to the terminal changes;
[0317] The Internet Protocol address IP corresponding to the application network of the target area accessed by the terminal changes;
[0318] The port number corresponding to the application network accessed by the terminal to the target area changes;
[0319] The access permission corresponding to the application network of the target area accessed by the terminal is changed.
[0320] In order to implement the method on the terminal side of the embodiment of the present application, the embodiment of the present application also provides a flow processing device based on an edge network, which is set on the terminal, such as Fig.16 As shown, Fig.16 This is a structural diagram of another edge network-based traffic processing device according to an embodiment of the present application. The device 1600 includes:
[0321] The first sending unit 1601 is used to send a first request message corresponding to an application network for accessing a target area to a first network device; the first request message carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; the first request message is used by the network device to perform identity authentication using the user identifier to obtain a first authentication result; when the first authentication result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier; and determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow permission processing on the terminal according to the flow authorization information.
[0322] In order to implement the method on the second network device side of the embodiment of the present application, the embodiment of the present application also provides a traffic processing device based on an edge network, which is arranged on the second network device, such as Fig.17 As shown, Fig.17 This is a structural diagram of another edge network-based traffic processing device according to an embodiment of the present application. The device 1700 includes:
[0323] The second receiving unit 1701 is used to receive third request information sent by the first network device;
[0324] An opening unit 1702 is used to open the business authority corresponding to the enterprise to which the terminal corresponding user belongs by using the third request information;
[0325] The second sending unit 1703 is used to send a first response message generated based on the third request information to the first network device; the first response message is used by the first network device to determine the state parameters of the terminal corresponding to the target service; the state parameters represent whether the target service is activated.
[0326] In one embodiment, the device further comprises a dispensing unit; wherein,
[0327] The second receiving unit 1701 is further configured to receive second response information based on fourth request information sent by the first network device; the fourth request information carries a session type corresponding to the terminal;
[0328] The allocation unit is used to allocate an Internet Protocol address IP to the terminal using the second response information; the IP is used for the terminal to establish communication with the second network device;
[0329] The second sending unit 1703 is further used to send a fifth request message to the first network device; the fifth request message carries the IP; the IP is used to associate the first network device with the user identifier corresponding to the terminal to obtain association information.
[0330] It should be noted that: the edge network-based traffic processing device provided in the above embodiment only uses the division of the above program modules as an example when performing edge network-based traffic processing. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the edge network-based traffic processing device provided in the above embodiment and the edge network-based traffic processing method embodiment belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0331] Based on the hardware implementation of the above-mentioned program module, an embodiment of the present application also provides a first network device, including: a first processor and a first memory for storing a computer program that can be run on the processor, wherein the first processor is used to implement the steps in the edge network-based traffic processing method provided in the above-mentioned embodiment when running the computer program.
[0332] Based on the hardware implementation of the above-mentioned program module, an embodiment of the present application also provides a terminal, including: a second processor and a second memory for storing a computer program that can be run on the processor, wherein the second processor is used to implement the steps in the edge network-based traffic processing method provided in the above-mentioned embodiment when running the computer program.
[0333] Based on the hardware implementation of the above-mentioned program module, an embodiment of the present application also provides a second network device, including: a third processor and a third memory for storing a computer program that can be run on the processor, wherein the third processor is used to implement the steps in the edge network-based traffic processing method provided in the above-mentioned embodiment when running the computer program.
[0334] Correspondingly, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the edge network-based traffic processing method provided in the above embodiment are implemented.
[0335] It should be noted here that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the description of the method embodiments of this application for understanding.
[0336] It should be noted that Fig.18 This is a schematic diagram of the structure of the first network device in the embodiment of the present application, such as Fig.18 As shown, the first network device 1800 includes: a first processor 1801 and a first memory 1803 . Optionally, the first network device 1800 may also include a first communication interface 1802 .
[0337] It can be understood that the first memory 1803 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The first memory 1803 described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memories.
[0338] The method disclosed in the above embodiment of the present application can be applied to the first processor 1801, or implemented by the first processor 1801. The first processor 1801 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the first processor 1801 or an instruction in the form of software. The above-mentioned first processor 1801 may be a general-purpose processor, a digital signal processor (DSP, DigitalSignal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The first processor 1801 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, which is located in the first memory 1803. The first processor 1801 reads the information in the first memory 1803 and completes the steps of the above method in combination with its hardware.
[0339] It should be noted that Fig.18 This is a schematic diagram of the structure of the terminal in the embodiment of the present application. Fig.18 As shown, the first network device 1800 includes: a first processor 1801 and a first memory 1803 . Optionally, the first network device 1800 may also include a first communication interface 1802 .
[0340] It can be understood that the first memory 1803 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The first memory 1803 described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memories.
[0341] The method disclosed in the above embodiment of the present application can be applied to the first processor 1801, or implemented by the first processor 1801. The first processor 1801 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the first processor 1801 or an instruction in the form of software. The above-mentioned first processor 1801 may be a general-purpose processor, a digital signal processor (DSP, DigitalSignal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The first processor 1801 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, which is located in the first memory 1803. The first processor 1801 reads the information in the first memory 1803 and completes the steps of the above method in combination with its hardware.
[0342] It should be noted that Fig.19 is a schematic diagram of the structure of the terminal in the embodiment of the present application, such as Fig.19 As shown, the terminal 1900 includes: a second processor 1901 and a second memory 1903 . Optionally, the terminal 1900 may also include a second communication interface 1902 .
[0343] It can be understood that the second memory 1903 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The second memory 1903 described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memories.
[0344] The method disclosed in the above embodiment of the present application can be applied to the second processor 1901, or implemented by the second processor 1901. The second processor 1901 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of the hardware in the second processor 1901 or an instruction in the form of software. The above-mentioned second processor 1901 may be a general-purpose processor, a digital signal processor (DSP, DigitalSignal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The second processor 1901 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, which is located in the second memory 1903, and the second processor 1901 reads the information in the second memory 1903 and completes the steps of the above method in combination with its hardware.
[0345] It should be noted that Fig. 20 is a schematic diagram of the structure of the second network device in the embodiment of the present application, such as Fig. 20 As shown, the second network device 2000 includes: a third processor 2001 and a third memory 2003 . Optionally, the second network device 2000 may also include a third communication interface 2002 .
[0346] It can be understood that the third memory 2003 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The third memory 2003 described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memories.
[0347] The method disclosed in the above embodiment of the present application can be applied to the third processor 2001, or implemented by the third processor 2001. The third processor 2001 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the third processor 2001. The above third processor 2001 may be a general processor, a digital signal processor (DSP, DigitalSignal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The third processor 2001 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the third memory 2003. The third processor 2001 reads the information in the third memory 2003 and completes the steps of the above method in combination with its hardware.
[0348] In order to implement the method provided in the embodiment of the present application, the embodiment of the present application also provides a traffic processing system based on an edge network, such as Fig.21 As shown, Fig.21 This is a schematic diagram of the structure of a traffic processing system based on an edge network according to an embodiment of the present application. The system includes: a terminal 2101, a first network device 2102, and a second network device 2103.
[0349] Here, it should be noted that the specific processing procedures of the terminal 2101, the first network device 2101 and the second network device 2102 have been described in detail above and will not be repeated here.
[0350] In an exemplary embodiment, the device may be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), field programmable gate array (FPGA), general processor, controller, microcontroller (MCU), microprocessor, or other electronic components to execute the aforementioned method.
[0351] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the size of the sequence number of the above-mentioned processes does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The above-mentioned sequence numbers of the embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.
[0352] It should be noted that, in this application, the terms "include", "comprises" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0353] The methods disclosed in several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0354] The features disclosed in several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0355] The features disclosed in several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0356] The above is only an implementation method of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0357] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0358] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0359] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application.
Claims
1. A traffic processing method based on edge network, characterized in that: Applied to a first network device, comprising: Receiving first request information corresponding to the application network of the access target area sent by the terminal; the first request information carries the user identifier corresponding to the terminal and the network identifier pre-configured by the first network device; Perform identity authentication based on the user identifier to obtain a first authentication result; if the first authentication result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier; Determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow authority processing on the terminal according to the flow authorization information.
2. The method according to claim 1, characterized in that The method further comprises: Obtaining a first identity identifier of a user corresponding to at least one of the terminals and a second identity identifier corresponding to a communication operator in the target area that is allowed to access at least one of the terminals; The first identity identifier is associated with the second identity identifier to obtain the association information.
3. The method according to claim 1, characterized in that The method further comprises: Configuring first information corresponding to at least one user in the target area; At each preset period, obtaining business authority information of a user corresponding to at least one enterprise in the target area; The first information is updated based on the business authority information to obtain second information corresponding to the at least one user; the second information is used to verify the identity of the user to be registered in the target area.
4. The method according to claim 3, characterized in that The method further comprises: Acquire second request information for terminal registration, and verify the second request information based on the second information; If the second request information is successfully verified, a third request information is sent to the second network device; the third request information is used by the second network device to open the corresponding business authority of the enterprise to which the corresponding user of the terminal belongs; Receive first response information sent by the second network device based on the third request information, and use the first response information to determine a state parameter of the terminal corresponding to the target service; the state parameter represents whether the target service is activated.
5. The method according to claim 4, characterized in that The method further comprises: In a case where the state parameter indicates that the target service is in an activated state, receiving fourth request information sent by the terminal; the fourth request information carries a session type corresponding to the terminal; Determine, based on the session type, a third identity identifier corresponding to the terminal that is allowed to be accessed by a corresponding communication operator in the target area; Verifying, according to the third identity identifier, the identity of the corresponding communication operator in the target area that is allowed to access the terminal, to obtain a second verification result; If the second verification result indicates that the identity authentication of the corresponding communication operator in the target area allowing access to the terminal is successful, sending a second response message based on the fourth request message to the second network device; the second response message is used by the second network device to allocate an Internet Protocol address IP to the terminal; the IP is used by the terminal to establish communication with the second network device; Receive the fifth request information sent by the second network device; the fifth request information carries the IP; the IP is used to associate with the user identifier to obtain the association information.
6. The method according to claim 2, characterized in that The method further comprises: When a preset condition is met, determining the identity data of the terminal in the target area according to the network identifier and the association information; Acquire identification information of a corresponding communication operator in the target area that is allowed to access the terminal according to the identity data; Determine the flow authorization information corresponding to the terminal based on the identification information.
7. The method according to claim 6, characterized in that The preset condition includes a first preset condition, and the method further includes: Determining whether the first identity identifier and the second identity identifier are associated for the first time; When the first identity identifier and the second identity identifier are associated for the first time, determining that the first preset condition is satisfied; When the first identity identifier and the second identity identifier are not associated for the first time, it is determined that the first preset condition is not met.
8. The method according to claim 6, characterized in that The preset condition includes a second preset condition, and satisfying the second preset condition includes at least one of the following: The Internet Protocol address IP corresponding to the terminal changes; The port number corresponding to the terminal changes; The Internet Protocol address IP corresponding to the application network of the target area accessed by the terminal changes; The port number corresponding to the application network accessed by the terminal to the target area changes; The access permission corresponding to the application network of the target area accessed by the terminal is changed.
9. A traffic processing method based on an edge network, characterized in that: Applied to terminals, including: A first request message corresponding to an application network for accessing a target area is sent to a first network device; the first request message carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; the first request message is used by the network device to perform identity authentication using the user identifier to obtain a first authentication result; when the first authentication result indicates that the identity authentication of the user identifier is successful, associated information related to the user identifier is obtained; and traffic authorization information corresponding to the terminal is determined based on the network identifier and the associated information; and traffic permission processing is performed on the terminal based on the traffic authorization information.
10. A traffic processing method based on edge network, characterized in that: Applied to the second network device, comprising: Receiving third request information sent by the first network device; Using the third request information, opening the business authority corresponding to the enterprise to which the terminal corresponding user belongs; A first response message generated based on the third request message is sent to the first network device; the first response message is used by the first network device to determine a state parameter of the terminal corresponding to the target service; the state parameter represents whether the target service is activated.
11. The method according to claim 10, characterized in that The method further comprises: receiving second response information based on fourth request information sent by the first network device; the fourth request information carries a session type corresponding to the terminal; Allocating an Internet Protocol address IP to the terminal using the second response information; the IP is used for the terminal to establish communication with the second network device; A fifth request message is sent to the first network device; the fifth request message carries the IP; the IP is used to associate the first network device with a user identifier corresponding to the terminal to obtain association information.
12. A traffic processing device based on an edge network, characterized in that: The device is configured on the first network device, including: A first receiving unit is used to receive first request information corresponding to the application network of the access target area sent by the terminal; the first request information carries the user identifier corresponding to the terminal and the network identifier pre-configured by the first network device; An acquiring unit, configured to perform identity authentication based on the user identifier to obtain a first authentication result; if the first authentication result indicates that the identity authentication of the user identifier is successful, acquiring associated information related to the user identifier; A processing unit is used to determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow authority processing on the terminal according to the flow authorization information.
13. A traffic processing device based on an edge network, characterized in that: Set on the terminal, including: The first sending unit is used to send a first request message corresponding to an application network for accessing a target area to a first network device; the first request message carries a user identifier corresponding to the terminal and a network identifier pre-configured by the first network device; the first request message is used by the network device to perform identity authentication using the user identifier to obtain a first verification result; when the first verification result indicates that the identity authentication of the user identifier is successful, obtain associated information related to the user identifier; and determine the flow authorization information corresponding to the terminal according to the network identifier and the associated information; and perform flow permission processing on the terminal according to the flow authorization information.
14. A traffic processing device based on an edge network, characterized in that: The configuration is performed on the second network device, including: A second receiving unit, configured to receive third request information sent by the first network device; An activation unit, configured to activate the business authority corresponding to the enterprise to which the terminal corresponding user belongs by using the third request information; The second sending unit is used to send a first response message generated based on the third request information to the first network device; the first response message is used by the first network device to determine the state parameters of the terminal corresponding to the target service; the state parameters represent whether the target service is activated.
15. A first network device, characterized in that: include: a first processor and a first memory for storing a computer program executable on the processor, Wherein, when the first processor is used to run the computer program, the steps of the method described in any one of claims 1 to 9 are executed.
16. A terminal, characterized in that: include: a second processor and a second memory for storing a computer program executable on the processor, Wherein, when the second processor is used to run the computer program, it executes the steps of the method according to claim 9.
17. A second network device, characterized in that: include: a third processor and a third memory for storing a computer program executable on the processor, Wherein, the third processor is used to execute the steps of the method described in any one of claims 10 to 11 when running the computer program.
18. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the computer program implements the steps of the method according to any one of claims 1 to 8, or implements the steps of the method according to claim 9, or implements the steps of the method according to any one of claims 10 to 11.