Data transmission method and device and computer readable storage medium
By using the same first parameter to transmit data in the wireless link between the terminal and the network, the data transmission failure problem caused by wireless link instability is solved, redundant transmission at the air port is realized, the reliability and success rate of data transmission is improved, and fiber optical resources are saved.
Patent Information
- Application Number
- CN202311460290.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-03
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art causes data transmission failure when the wireless link between the terminal and the network is unstable, and the end-to-end redundant transmission scheme adds unnecessary fiber resources, resulting in waste of resources.
By obtaining the first parameters associated with the first session, including the first security parameters and/or the first Internet protocol IP address, the data is transmitted through the first session, ensuring that different terminals transmit the same data, forming redundant transmission at the air port.
It improves the reliability and success rate of data transmission, saves fiber resources, and reduces the deployment cost of communication systems.
Smart Images

Figure CN119946675A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a data transmission method and device, and a computer-readable storage medium. Background Art
[0002] During wireless communication between the terminal and the network, if the wireless link between the two is unstable, data transmission may fail. When the data sent by the terminal is important, if the data transmission fails due to an unstable link, the communication quality of the entire communication system will be seriously damaged. For example, in a sensor data transmission scenario based on the Internet of Things, the data collected by the sensor is transmitted to the network through the terminal via a wireless link, and then transmitted by the network to an external network that uses the sensor data (for example, a third-party server or operator server). If the sensor data cannot successfully reach the external network due to an unstable wireless link between the terminal and the network, it will affect the normal use of the sensor data by the external network.
[0003] One existing solution is to perform end-to-end redundant transmission, that is, to establish two completely independent transmission links between the sending end (e.g., the terminal) and the receiving end (e.g., the external network), wherein each transmission link includes an air interface transmission section and an optical fiber transmission section. Although this solution improves the success rate of data reaching the external network side through redundant transmission, in practice, data transmission failures are mostly caused by the instability of the wireless link in the air interface transmission section. The existing end-to-end redundant transmission solution adds unnecessary optical fiber resources, resulting in a very large waste of resources. Summary of the invention
[0004] The technical problem solved by the present application is how to allow multiple terminals to transmit the same data to achieve redundant transmission at the air interface.
[0005] To solve the above technical problems, an embodiment of the present application provides a data transmission method, including: obtaining a first parameter associated with a first session, the first parameter including a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; using the first parameter to transmit data of the first service through the first session; wherein all terminals related to the first session use the first parameter to transmit the data.
[0006] Optionally, the first parameter is preconfigured.
[0007] Optionally, the data transmission method further includes: sending first information, where the first information is used to request to obtain the first parameter; and obtaining the first parameter associated with the first session includes: receiving the first parameter associated with the first session.
[0008] Optionally, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0009] Optionally, the first information is carried via a non-access layer message or an access layer message.
[0010] Optionally, transmitting the data of the first service through the first session using the first parameter includes: processing the data using the first security parameter, and transmitting the processed data as an Ethernet data packet.
[0011] Optionally, transmitting the data of the first service through the first session using the first parameter includes: processing the data using the first security parameter, and transmitting the data using the first IP address.
[0012] Optionally, acquiring the first parameter associated with the first session includes: receiving a first message, where the first message includes the first parameter associated with the first session.
[0013] Optionally, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0014] Optionally, the first message is carried by a non-access layer message or an access layer message.
[0015] Optionally, the non-access layer message includes a session management message and / or a mobility management message.
[0016] Optionally, the first parameter multiplexes a second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service.
[0017] Optionally, the action of processing the data using the first security parameter is performed at the business layer, or the action of processing the data using the first security parameter is performed at the protocol layer.
[0018] Optionally, the data transmission method further includes: sending a second message, where the second message is used to request allocation of resources for the first session.
[0019] To solve the above technical problems, an embodiment of the present application also provides a data transmission method, including: receiving data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, the first parameters include a first security parameter and / or a first IP address; merging the received data and transmitting it to the next node.
[0020] Optionally, the next node includes a core network.
[0021] Optionally, the merging the received data and transmitting it to the next node includes: directly merging the received data and transmitting it to the next node.
[0022] Optionally, the first security parameter is a third security parameter, the third security parameter does not reuse a second security parameter of a terminal related to the first session, and the second security parameter is associated with services other than the first service.
[0023] Optionally, the data transmission method also includes: obtaining the first security parameter from a core network.
[0024] Optionally, the merging of the received data and transmitting to the next node includes: deprocessing the data using the first security parameter and merging to obtain deprocessed data; and transmitting the deprocessed data to the next node.
[0025] Optionally, the action of processing the data using the first security parameter is performed at the business layer.
[0026] Optionally, the first security parameter multiplexes a second security parameter of a terminal related to the first session, and the second security parameter is associated with services other than the first service.
[0027] Optionally, the merging of the received data and transmitting to the next node includes: deprocessing the data using the first security parameter and merging to obtain deprocessed data; and transmitting the deprocessed data to the next node.
[0028] Optionally, the action of processing the data using the first security parameter solution is performed at the protocol layer.
[0029] Optionally, the data transmission method also includes: receiving a third message from the core network, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; sending a fourth message, the fourth message including the second security parameter of the target terminal, and the first security parameter multiplexing the second security parameter of the target terminal.
[0030] Optionally, the first IP address reuses the second IP address of a terminal related to the first session, or the first IP address is a third IP address, the third IP address does not reuse the second IP address of the terminal related to the first session, and the second IP address is associated with a service other than the first service.
[0031] To solve the above technical problems, an embodiment of the present application also provides a data transmission method, including: sending a first parameter associated with a first session, the first parameter including a first security parameter and / or a first IP address, the first session being associated with a first service; receiving data of the first service transmitted by an access network, the data being transmitted through the first session; wherein network elements related to the first session all use the first parameter to transmit the data.
[0032] Optionally, the data transmission method further includes: receiving first information, where the first information is used to request to obtain the first parameter.
[0033] Optionally, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0034] Optionally, the first information is carried via a non-access layer message or an access layer message.
[0035] Optionally, the data includes at least one of the following: Ethernet data packet; IP data packet.
[0036] Optionally, sending the first parameter associated with the first session includes: sending a first message, where the first message includes the first parameter associated with the first session.
[0037] Optionally, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0038] Optionally, the first message is carried by a non-access layer message or an access layer message.
[0039] Optionally, the non-access layer message includes a session management message and / or a mobility management message.
[0040] Optionally, the first parameter multiplexes a second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service.
[0041] Optionally, the data transmission method further includes: processing the data using the first security parameter solution.
[0042] Optionally, the data received from the access network is data processed using the first security parameter solution.
[0043] Optionally, the data transmission method further includes: receiving a second message, where the second message is used to request allocation of resources for the first session; and configuring the resources.
[0044] Optionally, the data transmission method also includes: sending a third message, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; receiving a fourth message, the fourth message including the second security parameter of the target terminal, the first parameter multiplexing the second security parameter.
[0045] Optionally, the first parameter is preconfigured.
[0046] Optionally, the first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
[0047] Optionally, the first network element includes: a first service management function network element, integrated in the signaling plane of the core network; and / or a first service transmission function network element, integrated in the data plane of the core network.
[0048] Optionally, the first network element is provided with a public interface for providing capability information and / or service information of the first service, and / or receiving demand information of the first service.
[0049] To solve the above technical problems, an embodiment of the present application also provides a data transmission device, including: an acquisition module, used to obtain a first parameter associated with a first session, the first parameter includes a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module, used to use the first parameter to transmit data of the first service through the first session; wherein, all terminals related to the first session use the first parameter to transmit the data.
[0050] To solve the above technical problems, an embodiment of the present application also provides a data transmission device, including: a receiving module, used to receive data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, the first parameters include a first security parameter and / or a first IP address; a transmission module, used to merge the received data and transmit it to the next node.
[0051] To solve the above technical problems, an embodiment of the present application also provides a data transmission device, including: a sending module, used to send a first parameter associated with a first session, the first parameter includes a first security parameter and / or a first IP address, and the first session is associated with a first service; a receiving module, used to receive data of the first service transmitted by an access network, and the data is transmitted through the first session; wherein, network elements related to the first session all use the first parameter to transmit the data.
[0052] To solve the above technical problems, an embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored, and when the computer program is run by a processor, the steps of the above method are executed.
[0053] To solve the above technical problems, an embodiment of the present application further provides a data transmission device, comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and the processor executes the steps of the above method when running the computer program.
[0054] In order to solve the above technical problems, an embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is run on a computer, the computer executes the steps of the above method.
[0055] In order to solve the above technical problems, an embodiment of the present application also provides a communication system, including a core network element, a network device and a terminal for executing the above method.
[0056] In order to solve the above technical problems, an embodiment of the present application further provides a chip (or a data transmission device), on which a computer program is stored. When the computer program is executed by the chip, the steps of the above method are implemented.
[0057] Compared with the prior art, the technical solution of the embodiment of the present application has the following beneficial effects:
[0058] Compared with the prior art, which makes it difficult for different terminals to transmit the same data, this embodiment enables the terminals participating in the first session to transmit the same data using the same first parameter, thereby ensuring that different terminals can send the same data when performing data transmission. Thus, redundant transmission is formed at the air interface, thereby improving data transmission reliability and success rate.
[0059] Furthermore, compared with the existing end-to-end redundant transmission solution, the communication system using this implementation scheme ensures data transmission reliability through redundant transmission at the air interface end. After the redundantly transmitted data is successfully received at the access network side, the same optical fiber can be reused for further transmission. This saves optical fiber resources and helps reduce the deployment cost of the communication system. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 It is a signaling interaction diagram of a data transmission method provided in an embodiment of the present application;
[0061] Figure 2 It is a schematic diagram of a communication system protocol stack provided by an embodiment of the present application;
[0062] Figure 3 It is a schematic diagram of another communication system protocol stack provided in an embodiment of the present application;
[0063] Figure 4 It is another schematic diagram of a communication system protocol stack provided in an embodiment of the present application;
[0064] Figure 5 It is a schematic diagram of the service layer security architecture of the communication system in the first typical application scenario of the present invention;
[0065] Figure 6 yes Figure 5 The service layer signaling interaction diagram in the application scenario shown;
[0066] Figure 7 It is a schematic diagram of the service layer security architecture of the communication system in the second typical application scenario of the present invention;
[0067] Figure 8 yes Figure 7 The service layer signaling interaction diagram in the application scenario shown;
[0068] Fig. 9It is a structural schematic diagram of a data transmission device provided in an embodiment of the present application;
[0069] Fig.10 is a structural schematic diagram of another data transmission device provided in an embodiment of the present application;
[0070] Fig.11 is a structural diagram of another data transmission device provided in an embodiment of the present application;
[0071] Fig.12 It is a structural diagram of another data transmission device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0072] The method provided in the embodiment of the present application involves a core network, an access network and a terminal. The core network and the access network can be collectively referred to as the network side (referred to as the network), and the terminal and the equipment in the network (for example, the network equipment of the access network) perform uplink and downlink signal transmission. Furthermore, the data transmitted from the terminal to the core network through the access network is further transmitted to the external network via the core network.
[0073] The terminal in the embodiment of the present application is a device with a wireless communication function, which can be called a terminal device, a user equipment (UE), a mobile station (MS), a mobile terminal (MT), an access terminal device, a vehicle-mounted terminal device, an industrial control terminal device, a UE unit, a UE station, a mobile station, a remote station, a remote terminal device, a mobile device, a UE terminal device, a wireless communication device, a UE agent or a UE device, etc. The terminal can be fixed or mobile. It should be noted that the terminal can support at least one wireless communication technology, such as Long Term Evolution (LTE), a new radio (NR), etc. For example, the terminal may be a mobile phone, a tablet computer (pad), a desktop computer, a laptop computer, an all-in-one computer, a vehicle-mounted terminal, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a wearable device, a terminal device in a future mobile communication network, or a terminal device in a future evolved public mobile land network (PLMN), etc. In some embodiments of the present application, the terminal may also be a device with a transceiver function, such as a chip system, wherein the chip system may include a chip and may also include other discrete devices.
[0074] The access network of the embodiment of the present application may be, for example, a 5G access network (NG-RAN), and the network device of the embodiment of the present application is a device that provides wireless communication functions for UE, and may also be referred to as an access network device, a radio access network (RAN) device, or an access network element. Among them, the network device may support at least one wireless communication technology, such as LTE, NR, etc. For example, the network device includes, but is not limited to: a next generation base station (generation nodeB, gNB), an evolved node B (evolved node B, eNB), a radio network controller (radio network controller, RNC), a node B (node B, NB), a base station controller (base station controller, BSC), a base transceiver station (base transceiver station, BTS), a home base station (for example, home evolved node B, or home node B, HNB), a baseband unit (baseband unit, BBU), a transmitting and receiving point (transmitting and receiving point, TRP), a transmitting point (transmitting point, TP), a mobile switching center, etc. in the fifth generation mobile communication system (5th-generation, 5G). The network device may also be a wireless controller, a centralized unit (CU), and / or a distributed unit (DU) in a cloud radio access network (CRAN) scenario, or an access network device, and may be a relay station, an access point, a vehicle-mounted device, a terminal device, a wearable device, and a network device in future mobile communications or a network device in a future evolved PLMN, etc. In some embodiments, the network device may also be a device having a wireless communication function for a terminal, such as a chip system. For example, the chip system may include a chip and may also include other discrete devices.
[0075] The core network (CN) of the embodiment of the present application is composed of core network elements. Among them, the core network element can also be called a core network device, which is a network element deployed in the core network, such as a core network control plane element or a core network user plane element. The core network of the embodiment of the present application can be an evolved packet core network (EPC), a 5G core network (5G Core Network), or a new core network in a future communication system. For example, the 5G core network is composed of a group of network elements, and implements access and mobility management functions (AMF) such as mobility management, user plane functions (UPF) that provide functions such as packet routing and forwarding and QoS (Quality of Service) management, and session management functions (SMF) that provide functions such as session management, IP address allocation and management. EPC can be composed of a mobility management entity (MME) that provides functions such as mobility management and gateway selection, a Serving Gateway (S-GW) that provides functions such as packet forwarding, and a PDN Gateway (P-GW) that provides functions such as terminal address allocation and rate control. For Multicast Broadcast Service (MBS), the core network may include several new network elements to implement functions such as data packet forwarding, MBS conference management, QoS management, transmission mode switching (switching between unicast and multicast / broadcast transmission modes), etc. Another way is that the functions can be implemented by existing core network elements.
[0076] The external network of the embodiment of the present application may also be referred to as an external data network (Data Network Name, DNN), which specifically refers to a device that accesses the network constructed by the core network and the access network to transmit data with the terminal. The external network may, for example, include a server that provides AF / AS. AF is an application function, which refers to various services at the application layer. It can be an application within the operator such as voice AF (volte AF), or a third-party AF (such as a video server, a game server). AS is an access layer (Access Stratum).
[0077] As mentioned in the background technology, in order to improve the reliability of data transmission, the prior art usually adopts end-to-end redundant transmission. For example, sensor-terminal 1-access network 1-core network 1-external network forms a transmission link, and sensor-terminal 2-access network 2-core network 2-external network forms another completely independent transmission link. However, two completely independent transmission links will cause a waste of optical fiber resources between the access network and the core network.
[0078] The inventor of the present application has found through analysis that one of the reasons for the above-mentioned problem is that, in the prior art, when different terminals perform uplink transmission, it is difficult to generate the same uplink data packet to transmit to the same node, resulting in the inability of the prior art to achieve air interface redundancy. Specifically, in the prior art, different terminals use different Internet Protocol (IP) headers when conducting conversations, and the generated IP packets are also different, and the encryption keys used by different terminals are also different. This results in that even if two terminals receive the same data, the data packets generated by each terminal after processing are different, and then the data (in this embodiment, specifically refers to the aforementioned data packets generated by each terminal after processing) that the two terminals ultimately transmit to the next node (for example, the access network on the network side) are different. If you want to achieve redundant transmission on the air interface, you must ensure that different terminals transmit the same data, and the prior art obviously cannot achieve this.
[0079] To solve the above technical problems, an embodiment of the present application provides a data transmission method, wherein a core network sends a first parameter associated with a first session, and correspondingly, a terminal receives the first parameter, the first parameter including a first security parameter and / or a first IP address, and the first session is associated with a first service; the terminal uses the first parameter to transmit data of the first service through the first session, and correspondingly, the access network receives the data transmitted by one or more terminals through the first session; the access network merges the received data and transmits it to the next node, and correspondingly, the core network directly or indirectly receives the data transmitted by the access network; wherein, the terminals and network elements related to the first session both use the first parameter to transmit the data.
[0080] By adopting this implementation scheme, by enabling the terminals participating in the first session to transmit the same data using the same first parameter, it is ensured that different terminals can send the same data when performing data transmission. Thus, redundant transmission is formed at the air interface, thereby improving the reliability and success rate of data transmission. Furthermore, after the redundantly transmitted data is successfully received at the access network side, the same optical fiber can be reused for further transmission. Thus, optical fiber resources are saved, which is conducive to reducing the deployment cost of the communication system.
[0081] The first service of the embodiment of the present application refers to an uplink convergence service (or an uplink transmission service performed in a convergence manner), or a service with the same or similar characteristics defined in a future protocol. The characteristics (also referred to as features) of the first service include: n (n is greater than or equal to 1) terminals send the same user plane (in user plane) data (hereinafter referred to as data), for example, sending the same uplink user plane data at the same time. In the embodiment of the present application, the same data may refer to the same data packet, that is, each bit in the data packet sent by each of the n terminals is the same.
[0082] Taking the power grid data transmission scenario as an example, the data collected by the power grid sensor needs to be transmitted to the network data server via the terminal. In order to avoid the unreliability of a single terminal (for example, data loss / destruction), this implementation scheme uses n (for example, n=2) terminals to transmit the data collected by the same sensor. The two terminals transmit the same received data to the access network respectively. When the access network successfully receives the data sent by any of the terminals, it continues to transmit it to the next node until the data is successfully transmitted to the network data server as the external network. In the example of n=2, assuming that the two terminals are terminal 1 and terminal 2, terminal 2 can be regarded as a clone of terminal 1.
[0083] The first session in the embodiment of the present application is associated with the first service, specifically refers to a session established for performing the first service, and the first session is associated with a unique identifier (for example, a session ID). The first session may also be referred to as an uplink aggregation session. In some embodiments, the first session may be associated with n terminals, that is, the n terminals transmit data of the first service to the network through the same first session. For example, the terminals associated with the same first session are respectively configured with the same session ID, and the n terminals configured with the same session ID use the same first parameters to send the same data on the same user plane. Furthermore, the n terminals obtain the same data to be transmitted from the same sending end, where the sending end may be, for example, a sensor.
[0084] In some embodiments, n terminals associated with the same first session (e.g., the same first session identifier) may form a user group, and the user group is uniquely associated with a group identifier. For each terminal, the terminal may be associated with multiple group identifiers, wherein each group identifier is associated with a corresponding first session, thereby the terminal may carry out multiple first services in parallel.
[0085] The second session of the embodiment of the present application refers to a session established for performing services other than the first service, and the second session is associated with a unique identifier. The second session may be, for example, a protocol data unit (PDU) session (PUD session), or may be, for example, a 4G-PDN (4G-Public Data Network). In some embodiments, the second session may correspond to the terminal one-to-one, that is, each network accessing the network establishes its own second session, and transmits data of services other than the first service to the network through its own associated second session.
[0086] Further, during the process of establishing the second session, or after the second session is established, the terminal may establish the first session with the network.
[0087] The first parameter of the embodiment of the present application may refer to a parameter used when transmitting data of the first service through the first session, and the terminals and network elements (including core network elements and access network elements) related to the first session all use the same first parameter to transmit the same data. In actual application scenarios, there are situations where one or more terminals cannot transmit data due to unexpected factors such as failures. At this time, at least one of the n terminals related to the first session uses the same first parameter to transmit data.
[0088] In some embodiments, the first parameter may include a first security parameter and / or a first IP address. The first security parameter may include user-plane security parameters, keys and algorithms, encryption keys, integrity protection keys, encryption algorithms and integrity protection algorithms, etc. The first security parameter is generated for use by the terminal during the first session establishment process. When the terminal transmits user-plane data through the first session, the first security parameter is used to protect the user-plane data, such as encryption and integrity protection. The first IP address may include a source IP address. During the first session establishment process, the network allocates the first IP address used by the terminal to the terminal. The source IP address of the IP data packet sent by the terminal to the network through the first session uses the first IP address.
[0089] The second parameter of the embodiment of the present application may refer to a parameter used when transmitting data of a service other than the first service through a second session. Specifically, the second parameter may include a second security parameter and / or a second IP address. Among them, the second security parameter may include a secret key, a security algorithm, etc., and the second security parameter used by the terminal is generated in the process of the terminal accessing the network. When the terminal transmits data of a service other than the first service through the second session, the second security parameter is used to protect the user plane data, such as encryption and integrity protection. The second IP address may include a source IP address. In the process of establishing the second session, the network assigns the terminal a second IP address used by the terminal, and the source IP address of the IP data packet sent by the terminal to the network through the second session uses the second IP address.
[0090] In some embodiments, the first parameter may reuse a second parameter of a terminal associated with the first session. Specifically, when the network configures the first parameter for the n terminals associated with the first session, it may select a second parameter that has been configured for one of the n terminals, and determine the second parameter of the selected terminal as the first parameter commonly used by the n terminals. In the embodiment of the present application, the terminal that reuses the second parameter among the n terminals is recorded as the target terminal.
[0091] In some embodiments, the first parameter may be a third parameter, and the third parameter does not reuse the second parameter of the terminal associated with the first session. The third parameter of the embodiment of the present application may refer to a new parameter configured specifically for the n terminals for the first service associated with the first session, and the new parameter is different from the second parameter that has been configured for each of the n terminals.
[0092] For example, the first security parameter may reuse the second security parameter of a terminal associated with the first session. Alternatively, the first IP address may reuse the second IP address of a terminal associated with the first session. Alternatively, the first security parameter and the first IP address may both reuse the second security parameter and the second IP address of a terminal associated with the first session, wherein the second security parameter reused by the first security parameter and the second IP address reused by the first IP address may be associated with the same or different terminals.
[0093] For another example, the first security parameter may be the third security parameter, that is, the second security parameter of the terminal associated with the first session is not reused. Alternatively, the first IP address may be the third IP address, that is, the second IP address of the terminal associated with the first session is not reused. Alternatively, the first security parameter may be the third security parameter and the first IP address may be the third IP address.
[0094] For another example, the first security parameter may reuse the second security parameter of a terminal associated with the first session, and the first IP address may be the third IP address. Alternatively, the first security parameter may be the third security parameter, and the first IP address may reuse the second IP address of a terminal associated with the first session.
[0095] In order to make the above-mentioned purposes, features and beneficial effects of the present application more obvious and easy to understand, the specific embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0096] Figure 1 It is a signaling interaction diagram of a data transmission method provided in an embodiment of the present application.
[0097] In a specific implementation, in the data transmission method provided by the following steps (abbreviated as S) 100 to S107, the action performed by the terminal can be performed by a chip with a data transmission function in the terminal, or by a baseband chip in the terminal. The action performed by the access network can be performed by a chip with a data transmission function in a network device, or by a baseband chip in the network device. The action performed by the core network can be performed by a chip with a data transmission function in a core network element, or by a baseband chip in a core network element.
[0098] Specifically, refer to Figure 1 The data transmission method described in this embodiment may include the following steps:
[0099] S101: A core network sends a first parameter associated with a first session to a terminal. Correspondingly, the terminal receives the first parameter from the core network.
[0100] In some embodiments, the core network sends the first parameter to the terminal through the access network.
[0101] In a specific implementation, the core network may actively send the first parameter to the terminal to trigger the terminal to execute the first service.
[0102] In a specific implementation, the first parameter may be preconfigured. For example, it may be preconfigured in a ME (Mobile equipment) unit or a USIM (Universal Subscriber Identity Module) of the terminal. In this example, the action of the core network in S101 may be omitted, and the terminal directly obtains the first parameter from its own ME or USIM.
[0103] In a specific implementation, the following steps may be included before S101: S100, the terminal sends first information to the core network, where the first information is used to request to obtain the first parameter. Correspondingly, the core network receives the first information from the terminal.
[0104] Specifically, the first information may include at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; and identifier of a second session of the terminal related to the first session.
[0105] Furthermore, the first indication information can indicate to the network that the terminal sending the first information needs to execute the first service.
[0106] Furthermore, the identity of the terminal related to the first session may be, for example, the identity of the terminal among the n terminals except the terminal that sends the first information. Still taking n=2 as an example, when terminal 2 sends the first information, it may carry the identity of terminal 1 that it clones.
[0107] In some embodiments, in a scenario where the terminal has not pre-interacted and signed a contract with the network, the network does not know in advance the specific information of the n terminals associated with the first session (that is, it does not know that the n terminals are backed up for each other), so any of the n terminals can carry the identity identifiers of the other n-1 terminals and / or the group identifier of the group to which the n terminals belong in the first information. Accordingly, the core network can configure the same first parameter to the n terminals indicated by the first information.
[0108] In some embodiments, in a scenario where the terminal has signed a contract with the network, the identity of the terminal related to the first session may be omitted in the first information, which is conducive to saving signaling overhead.
[0109] Furthermore, the session information of the first session may include: information of the external network corresponding to the first service, such as the network name, network identifier, slice information, IP address, and port number of the external network.
[0110] Furthermore, the capability information may indicate whether the terminal supports or does not support a feature corresponding to the first service.
[0111] Further, in S101, the core network sends a first message to the terminal, the first message including a first parameter. Correspondingly, the terminal receives the first message from the core network to obtain the first parameter.
[0112] In some embodiments, the first message may further include at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein part or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session. The content carried in the first message may be collectively referred to as relevant information of the first service.
[0113] Specifically, the terminal may carry its own capability information when sending the first message, and the network (eg, core network) may indicate whether the network has the capability of the first service through the second indication information when returning the first message. Furthermore, the first message may also indicate the capability information of other terminals related to the first session.
[0114] Furthermore, by sending the first information, the terminal can request the network to obtain information related to the first service, such as the service type of the first service, the session type of the first session, the first IP address, the first security parameter, the identity of the terminal related to the first service, the identifier of the external data network, the network slice identifier, the identifier of the first session, etc.
[0115] Furthermore, the terminal type may include a basic terminal and an auxiliary terminal, wherein the basic terminal may initiate an application for user plane resources (ie, resources used for the first session), while the auxiliary terminal does not initiate an application for user plane resources.
[0116] Furthermore, the service type may include a basic service and an auxiliary service. If the first message indicates that the first service associated with the terminal is a basic service, the terminal determines that it needs to initiate an application for user plane resources when executing the first service. If the first message indicates that the first service associated with the terminal is an auxiliary service, the terminal determines not to initiate an application for user plane resources when executing the first service.
[0117] Furthermore, the session type may include a basic session and an auxiliary session, wherein the terminal corresponding to the basic session may initiate an application for user plane resources, and the terminal corresponding to the auxiliary session may not initiate an application for user plane resources.
[0118] In some embodiments, when n terminals respectively send first information to request to jointly execute the first service, the core network can specify through the first message that a part of the n terminals initiate an application for user plane resources, and the remaining part does not initiate an application for user plane resources.
[0119] Still taking n=2 as an example, assuming that the service type indicated in the first message received by terminal 1 is an auxiliary service, terminal 1 does not request allocation of resources for the first session when subsequently executing the first service, and assuming that the service type indicated in the first message received by terminal 2 is a basic service, terminal 2 requests allocation of resources for the first session when subsequently executing the first service. The resources for the first session requested by terminal 2 are shared by terminal 1 and terminal 2.
[0120] Assume that n=3, the terminal type indicated in the first message received by terminal 1 is a basic terminal, and the terminal types indicated in the first messages received by terminal 2 and terminal 3 are all auxiliary terminals. Accordingly, terminal 1 requests allocation of resources for the first session when subsequently executing the first service, and terminal 2 and terminal 3 do not initiate resource applications. Terminal 1, terminal 2, and terminal 3 all use the user plane resources applied for by terminal 1 to transmit the same data through the first session.
[0121] In some embodiments, the terminal may request the network to allocate user plane resources, for example, using a service request message (SERVICE REQUEST).
[0122] In some embodiments, the core network may determine, among the n terminals, a terminal whose second IP address is multiplexed as the first IP address as a terminal that needs to request allocation of resources for the first session.
[0123] In a variation, the resource used for the first session may be a preconfigured periodic resource. In this variation, part or all of the terminal type, service type, and session type may be omitted in the first message to save signaling overhead.
[0124] In some embodiments, the first information and / or the first message may be transmitted via an access network.
[0125] In a specific implementation, the first information may be carried by a non-access stratum (NAS) message. Similarly, the first message may be carried by a NAS message.
[0126] For example, the first message carried by the NAS message may include the following information element (IE):
[0127] 1. The indication mark of the first service 1 feature (i.e., the first indication information or the second indication information) is used to indicate whether the terminal or the network supports the feature corresponding to the first service. It can be identified by one or more bits, such as 0 represents that the feature corresponding to the first service is not supported, and 1 represents that the feature corresponding to the first service is supported;
[0128] 2. Terminal type, which can be identified by one or more bits: 0 represents a basic terminal, 1 represents an auxiliary terminal;
[0129] 3. Session type, which can be identified by one or more bits: 0 represents a basic session, and 1 represents an auxiliary session, that is, the terminal does not send a service request message (SERVICE REQUEST).
[0130] In some embodiments, NAS messages may include session management messages (5GS session management messages).
[0131] Specifically, the session management message includes the establishment / modification / release stages of the PDU session, wherein the modification is performed after the PDU session is established, and a corresponding session management message is sent at each stage. Further, the core network implementing this implementation scheme can receive the first information or send the first message through the session management message of the corresponding stage during or after the establishment of the second session.
[0132] For example, the session management message that can carry the first information or the first message may include at least one of the following: PDU session establishment request PDU session establishment request, PDU session establishment accept PDU session establishment reject PDU session establishment reject, PDU session authentication command PDU session authentication command, PDU session authentication completion PDU session authentication complete, PDU session authentication result PDU session authentication result, PDU session modification request PDU session modification reject, PDU session modification command PDU session modification command, PDU session modification completion PDU session modification complete, PDU session modification command reject, PDU session release request PDU session release request, PDU session release reject, PDU session release command PDU session release command, PDU session release completion PDU session release complete, 5G session management status 5GSM status, service layer authentication command Service-level authentication command, service layer authentication completion Service-level authentication complete, remote UE report Remote UE report, and remote UE report response Remote UE report response.
[0133] In some embodiments, NAS messages may include mobility management messages (5GS mobility management messages).
[0134] For example, the mobility management message that can carry the first information or the first message may include at least one of the following: registration request, registration accept, registration complete, registration reject, deregistration request (UE originating), deregistration accept (UE originating), deregistration request (UE terminated), deregistration accept (UE terminated), service request, service reject, service accept, control plane service request, network slice-specific authentication command, network slice-specific authentication complete, network slice-specific authentication result, configuration update command, configuration update complete, authentication request, authentication response, authentication reject, authentication failure, authentication result, identity request, identity response, and security mode command. command, Security mode complete, Security mode reject, 5GMM status, Notification, Notification responseThe following are the steps of: responding to the TCP connection: UL NAS transport, DL NAS transport, Relay key request, Relay key accept, Relay key reject, Relay authentication request, and Relay authentication response.
[0135] In a specific implementation, the first information may be carried by an AS message. Similarly, the first message may be carried by an AS message.
[0136] For example, the AS message that can carry the first information or the first message may include at least one of the following: quantity statistics CounterCheck, quantity statistics response CounterCheckResponse, dedicated system information block (SystemInformation Block, SIB for short) request DedicatedSIBRequest, downlink dedicated message segment DLDedicatedMessageSegment, downlink information transmission DLInformationTransfer, multi-access dual link (Multi-RAT Dual Connectivity, MR-DC) downlink information transmission DLInformationTransferMRDC, failure information FailureInformation, integrated access and backhaul (Integrated access and backhaul, IAB) other information IAB OtherInformation, positioning measurement indication LocationMeasurementIndication, log measurement configuration LoggedMeasurementConfiguration, multicast broadcast service (Multicast Broadcast Services, MBS) broadcast configuration MBSBroadcastConfiguration, MBS interest indication MBSInterestIndication, master cell group (Master Cell Group, MCG) failure information MCGFailureInformation, measurement report MeasurementReport, application layer measurement report MeasurementReportAppLayer, Master Information Block (MIB), NR command-based mobility MobilityFromNRCommand, paging Paging, Radio Resource Control (Radio Resource Control,RRC (abbreviated as RRC) reconstruction RRCReestablishment, RRC reconstruction completion RRCReestablishmentComplete, RRC reconstruction request RRCReestablishmentRequest, RRC reconfiguration RRCReconfiguration, RRC reconfiguration completion RRCReconfigurationComplete, RRC rejection RRCReject, RRC release RRCRelease, RRC recovery RRCResume, RRC recovery completion RRCResumeComplete, RRC recovery request RRCResumeRequest, RRC recovery request 1RRCResumeRequest1, RRC establishment RRCSetup, RRC establishment completion RRCSetupComplete, RRC establishment request RRCSetupRequest, RRC system information request RRCSystemInfoRequest, Secondary Cell Group (SCG) failure information SCGFailureInformation, E-UTRA (Evolved UMTS Terrestrial Radio Access, Evolved UMTS Terrestrial Radio Access, where UMTS is Universal Mobile Telecommunications System (Universal MobileTelecommunications System))SCG failure information SCGFailureInformationEUTRA, security mode command SecurityModeCommand, security mode completion SecurityModeComplete, security mode failure SecurityModeFailure, system information block 1SIB1, NR auxiliary link terminal information SidelinkUEInformationNR, system informationSystemInformation, terminal assistance information UEAssistanceInformation, terminal capability inquiry UECapabilityEnquiry, terminal capability information UECapabilityInformation, terminal capability request UEInformationRequest, terminal capability response UEInformationResponse, terminal positioning assistance information UEPositioningAssistanceInfo, uplink dedicated message segment ULDedicatedMessageSegment, uplink information transmission ULInformationTransfer, Inter Radio Access Technology (Inter Radio Access Technology,IRAT) uplink information transmission ULInformationTransferIRAT, MR-DC uplink information transmission ULInformationTransferMRDC. ,
[0137] In a specific implementation, the first message may be transmitted via a container.
[0138] In one specific implementation, the first message may be transmitted using resources allocated for the first session.
[0139] In a specific implementation, continue to refer to Figure 1 The data transmission method described in this embodiment may further include the steps of:
[0140] S102: For a terminal that is indicated to need to request allocation of resources for a first session, the terminal sends a second message to a core network. Correspondingly, the core network receives the second message from the terminal.
[0141] Specifically, the second message is used to request allocation of resources for the first session.
[0142] In response to receiving the second message, the core network determines whether the second message triggers resource allocation. For example, if the terminal type of the terminal sending the second message is a basic terminal, the core network determines that resources need to be configured for the first session. For another example, if the session type carried by the second message is an auxiliary session, the core network determines not to configure resources in response to the second message.
[0143] In some embodiments, for a terminal that is not indicated to need to request allocation of resources for the first session, S102 is an optional step.
[0144] In some embodiments, the second message may be transmitted to the core network via the access network.
[0145] In a specific implementation, continue to refer to Figure 1 The data transmission method described in this embodiment may further include the steps of:
[0146] S103: In response to acquiring the first parameter, the terminal transmits data of the first service to the access network through the first session using the first parameter. Accordingly, the access network receives data transmitted by one or more terminals through the first session.
[0147] Specifically, for each of the n terminals related to the first session, S103 may be executed.
[0148] In some embodiments, in S103, the terminal may process data using the first security parameter and transmit the processed data as an Ethernet data packet. Specifically, in this example, the data to be transmitted received by the terminal is a Media Access Control (MAC) packet, which begins with a MAC address. Further, in S103, the terminal does not use the first IP address when transmitting the Ethernet data packet, nor does it package the data into an IP data packet.
[0149] Furthermore, the action of the terminal using the first security parameter to process the Ethernet data packet may be performed at the application layer.
[0150] In some embodiments, in S103, the terminal may process data using the first security parameter and transmit the processed data using the first IP address. Specifically, in this example, the terminal packages the received data into an IP data packet and transmits it using the first IP address.
[0151] In the sensor data transmission scenario, the sensor can transmit the data of the first service according to the network instruction, and the user route selection policy (URSP) of the identity card of the terminal receiving the data is configured with the application identifier (APP-ID) and the corresponding session attribute (used to configure whether the data transmitted by the corresponding application is processed in Ethernet or IP form). Accordingly, the sensor sends the data packaged in the corresponding form to the terminal according to the session attribute of the terminal. In response to receiving the data, the terminal executes S103 to process and transmit the data to the access network.
[0152] Further, when executing S103, the terminal determines whether to package the received data into an IP data packet or an Ethernet data packet according to the pre-configured session attributes.
[0153] In a specific implementation, continue to refer to Figure 1 The data transmission method described in this embodiment may further include the steps of:
[0154] S104: In response to receiving data transmitted by one or more terminals through the first session, the access network combines the received data and transmits it to the next node. Correspondingly, the next node receives the data transmitted by the access network. Figure 1 The following node is taken as the core network for exemplary display, that is, the core network directly receives data transmitted by the access network.
[0155] In some embodiments, the next node may be, for example, another terminal, which acts as a relay node, and the core network indirectly receives data transmitted by the access network through at least one relay node. In this example, when the terminal acts as a relay, the hardware processing capability similar to that of the base station may be enhanced so that the terminal as a relay node may perform actions similar to S104.
[0156] In some embodiments, in response to successfully receiving data of a first service transmitted by a terminal through a first session, the access network may execute S104.
[0157] In a specific implementation, the first security parameter may be a third security parameter, and the action of processing data using the first security parameter may be performed at the service layer (serving layer) of the terminal. Further, the first message sent by the core network includes the third security parameter, and the terminal and / or the access network determines the third security parameter as the first security parameter and uses it. The service layer may include an IP layer and an application, and the MAC layer described in this example is a MAC layer within the 3GPP scope.
[0158] Scenario 1:
[0159] Combination Figure 1 and Figure 2 , the first security parameter is carried by a NAS message. In response to obtaining the first security parameter, the terminal uses the first security parameter to encrypt data at the service layer of its own protocol stack, and then transmits it layer by layer to the access network through the first session. For example, on the terminal side, the data processed by the service layer (e.g., IP layer) is transmitted to the access network via the Service Data Adaptation Protocol (SDAP), the Packet Data Convergence Protocol (PDCP), the Radio Link Control (RLC) layer, and the MAC layer in sequence.
[0160] Further, the access network does not obtain and use the first security parameter, and accordingly, in S104, the access network transparently transmits the received data to the core network. For example, on the access network side, after receiving data transmitted by at least one terminal through the first session layer by layer via the MAC layer, the RLC layer, the PDCP layer, and the SDAP layer, the received data is directly merged and transmitted to the next node.
[0161] Further, in response to receiving the data, the core network may use the first security parameter to decrypt the data. The decryption may include operations such as decryption and deprotection. For example, an uplink convergence transmission function or a user plane function (UPF) specially added by the core network may use the first security parameter to perform security operations on the data to obtain decrypted data.
[0162] In other words, in scenario 1, there is no need to transmit the first security parameter using RRC signaling at the PDCP layer of the terminal and the access network, but the data is encrypted using the first security parameter directly from the IP layer on the terminal side to the PDCP layer. At this time, the data is directly transmitted to the core network through the access network, and the core network performs decryption operations using the first security parameter.
[0163] Furthermore, the decrypted and unprotected data can be further transmitted from the core network to the external network.
[0164] Scenario 2:
[0165] Combination Figure 1 and Figure 3 , the first security parameter is carried by the NAS message. In response to obtaining the first security parameter, the terminal uses the first security parameter to encrypt data at the service layer of its own protocol stack, and then transmits it to the access network layer by layer through the first session. For example, on the terminal side, the data processed by the IP layer is transmitted to the access network via the SDAP layer, PDCP layer, RLC layer, and MAC layer in sequence.
[0166] Further, the data transmission method described in this embodiment may also include the step: S105, the access network obtains the first security parameter from the core network. In some embodiments, the access network may obtain the first security parameter from the core network through other channels. For example, the access network may obtain the first security parameter through the N2 interface between the access network and the AMF (Access and Mobility Management Function) of the core network.
[0167] In response to obtaining the first security parameter, in S104, the access network uses the first security parameter to de-process the same data received from different terminals and merges them to obtain de-processed data, and then transmits the de-processed data to the next node, thereby improving the reliability of transmission.
[0168] In other words, compared with the protocol stack structure of the existing access network, the protocol stack of the access network in scenario 2 adds a service layer (e.g., IP layer), and the newly added IP layer has a decryption function. The access network decrypts the data and transmits it in plain text to the next node (e.g., UPF of the core network). The data received by the core network from the access network is processed using the first security parameter solution.
[0169] Furthermore, the action of using the first security parameter to process data may be performed at a service layer of the access network, specifically, at a newly added IP layer of the access network.
[0170] In a specific implementation, the first security parameter may reuse a second security parameter of a terminal associated with the first session, and the action of processing data using the first security parameter may be performed at a protocol layer of the terminal. Specifically, the protocol layer refers to a protocol within the 3GPP scope, such as SDAP, PDCP, RLC, MAC, MM, and SM.
[0171] Specifically, combined Figure 1 and Figure 4 The data transmission method described in this implementation scheme may further include the step: S106, the core network sends a third message to the access network. Correspondingly, the access network receives the third message from the core network. The third message may include the identity of the target terminal and the identity of the second session of the target terminal. The target terminal specifically refers to the terminal that multiplexes the second security parameter among the n terminals related to the first session.
[0172] Furthermore, the data transmission method described in this embodiment may further include the step: S107, the access network sends a fourth message to the core network. Correspondingly, the core network receives the fourth message sent by the access network. The fourth message may include the second security parameter of the target terminal.
[0173] In response to acquiring the second security parameter of the multiplexed target terminal, the core network determines the second security parameter as the first security parameter, and sends the first security parameter to the terminal through an AS message by executing S101.
[0174] For example, in S101, the core network sends the first security parameter to the access network through RRC signaling, and the access network obtains and sends the first security parameter to the terminal through the PDCP layer using RRC signaling.
[0175] Further, in S103, the terminal uses the first security parameter to encrypt data at the PDCP layer and transmits the data to the access network layer by layer.
[0176] Further, in S104, the access network uses the first security parameter to process and merge the same data received from different terminals at the protocol layer, and then transmits it to the next node in plain text. For example, the action of processing the data using the first security parameter can be performed at the PDCP layer of the access network.
[0177] Further, the data received by the core network from the access network is data processed using the first security parameter solution.
[0178] From the above, by adopting this implementation scheme, the communication system ensures data transmission reliability through redundant transmission at the air interface, and after the redundantly transmitted data is successfully received at the access network side, the same optical fiber can be reused for further transmission. Thus, optical fiber resources are saved, which is conducive to reducing the deployment cost of the communication system.
[0179] In the first typical application scenario (referred to as application scenario 1), the communication system may include a terminal, an access network, a core network, and an external network. Figure 5 The security architecture of each network component at the service layer is exemplified, wherein the terminals include UE1 and UE2, the access network includes NG-RAN, the core network includes AMF network element, SMF network element, first network element and UPF network element, and the external network includes AF / AS server.
[0180] Specifically, the AMF network element is used to provide AMF, the SMF network element is used to provide SMF, and the UPF network element is used to provide UPF.
[0181] Further, compared with the existing core network, the core network of the embodiment of the present application adds a first network element for processing the first service. For example, the first parameter can be configured by the first network element. In some embodiments, the first network element may include a first service management function network element for providing a first service management function. In some embodiments, the first network element may include a first service transmission function network element for providing a first service transmission function.
[0182] Furthermore, the AMF network element, the SMF network element and the first service management function network element can be integrated into the signaling plane of the core network.
[0183] Furthermore, the UPF network element and the first service transmission function network element can be integrated into the data plane of the core network.
[0184] In some embodiments, the first network element may implement the following functions:
[0185] 1) Manage (e.g., determine, generate, allocate, update, release) the resources related to the first service. For example, session type, session ID, first parameter (including first IP address, first security parameter (e.g., key, algorithm)), etc. This first parameter is used for the first service. For example, when the terminal sends data, the first security parameter is used to protect the data, such as encryption and integrity protection. For example, the first IP address is used as the source IP address of the data packet sent by the terminal;
[0186] 2) receiving a request to execute the first service, such as receiving a service request from an AMF, an SMF, or an application function; determining whether the first service can be executed and the related resources of the first service, for example, based on contract information, terminal and network capabilities, load, and other information;
[0187] 3) Providing relevant information of the first service, such as a first parameter, a session type, a session ID, etc. The first parameter may include a first security parameter and a first IP address. The relevant information may be carried in a container, or the relevant information may be transmitted in a message (such as a NAS message, RRC signaling) or in user plane data;
[0188] 4) Providing relevant information of the first service to other network components such as AMF / SMF / UPF / UE;
[0189] 5) Using the first security parameter of the first service (eg, the user plane key) to perform security operations on the data, such as decryption and deprotection, for example, decrypting and deprotecting the user plane data packet from the UE; after deprotection, the data packet can be transmitted to the external network.
[0190] Furthermore, the first network element may be provided with a public interface for providing capability information of the first service. For example, the capability information may indicate whether the first service supports n terminals to send the same data on the same user plane.
[0191] Furthermore, the public interface may also provide service information of the first service, such as the start / end time of the first service, the communication status of the network, and the like.
[0192] Furthermore, the public interface may also provide requirement information for receiving the first service.
[0193] The public interface may be a physical / logical interface between the core network and the server of the external network, used to transmit the relevant information of the first service. Figure 5 , the first service management function network element can set a public interface at the AF / AS server. Similarly, the first service transmission function network element can also set a public interface at the AF / AS server. Through this open interface, for example, an information disclosure interface and a service management interface of the first service can be provided. Through this public interface, at least part of the following information can be provided: the execution time of the first service, such as the start and end time, the geographical scope, such as the tracking area, the cell; the information of the external network corresponding to the first service, such as the network name, the IP address; the slice information corresponding to the first service; the service quality of the first service, the information of the terminal associated with the first service, such as the reachability of the terminal, the number of terminals n.
[0194] In some embodiments, network elements other than the first network element of the core network (such as AMF network element, SMF network element, policy control function (PCF) network element, unified data management (UDM) function network element) can implement the following functions:
[0195] 1) Obtaining relevant information of the first service, such as a first security parameter, for example, the relevant information may be obtained from a first service management function network element;
[0196] 2) managing (e.g., determining, generating, transmitting, updating, releasing) relevant information of the first service, such as the first IP address, session ID, session type, session quality, and policy information (e.g., URSP, session management policy);
[0197] 3) receiving a request from the terminal to execute the first service, and referring to the contract information to determine whether the terminal can execute the first service. The request to execute the first service can be transmitted in a NAS message, such as an MM message or an SM message, or can be transmitted in a user plane;
[0198] 4) managing the related session of the first service (ie, the first session), such as establishing, modifying, and releasing the first session associated with the first service based on a service request of the terminal or a service request of the application;
[0199] 5) Providing relevant information of the first service, such as first parameters (including first IP address, first security parameters), session ID, session type, session quality, and policy information (such as URSP, session management policy);
[0200] 6) Providing relevant information of the first service to the terminal, access network, and other nodes of the core network.
[0201] In some embodiments, the UPF network element can implement the following functions:
[0202] 1) Use the first security parameter of the first service to decrypt and deprotect the data, for example, decrypt and deprotect the user plane data packet sent by the terminal to the UPF network element or the first service transmission function network element, and then transmit it to the external network.
[0203] In some embodiments, the access network may implement the following functions:
[0204] 1) Using the first security parameter of the first service to perform security operations on the data, such as decryption and deprotection. For example, decrypting and deprotecting the user plane data packet from the terminal;
[0205] 2) Performing aggregation processing on the data from the terminal, the aggregation includes: merging the same data packets from different terminals, which can improve the reliability of transmission.
[0206] In some embodiments, a terminal (e.g., Figure 5 The UE1 and UE2 shown can implement the following functions:
[0207] 1) Using the information related to the first service to process data, specifically, uplink data belonging to the first service can be identified, and the service layer data can be protected, for example, using the first security parameter to protect the IP packet, Ethernet packet, unstructured data, etc. sent by the terminal, such as encryption and integrity protection; the protection operation can be performed at the service layer of the terminal or at the PDCP; if the protection operation is performed at the service layer, the PDCP layer may not perform security protection such as encryption on the data, that is, the access network and the terminal do not perform security operations such as encryption on the user plane of the first service;
[0208] 2) Requesting to execute a first service, for example, sending a first message to a base station (such as NG-RAN) / AMF network element / SMF network element / first network element, where the first message includes first service request (such as activation, modification, release) information, and the first information may be carried in a NAS message, which may be an MM or SM message; the SM message may be a PDU session activation, modification, release, and other messages;
[0209] 3) receiving relevant information of the first service, for example, receiving relevant information of the first service from the base station / AMF network element / SMF network element / PCF network element / first network element, such as session ID, session type, session quality, policy information (such as URSP, session management policy), first parameters (including first security parameters, first IP address), etc.;
[0210] 4) Save, update, and delete relevant information of the first business;
[0211] 5) Relevant information of the configured first service.
[0212] In a variation, the first service may be implemented by existing network elements of the core network.
[0213] For example, the first business management function can be integrated with the SMF. In this example, Figure 5 The first service management function network element can be omitted and the first service management function can be implemented by SMF.
[0214] For another example, the first service transmission function can be integrated with the UPF. In this example, Figure 5 The first service transmission function network element can be omitted, and the first service transmission function can be implemented by UPF.
[0215] For another example, the first service management function and / or the first service transmission function may be implemented by a PCF of the core network, or may be implemented by a UDM function of the core network.
[0216] In a variation, the first service may be implemented in an access network, that is, the access network may add a first network element to implement a first service management function and / or a first service transmission function.
[0217] In application scenario 1, refer to Figure 6 , the above Figure 5 The communication system shown can perform the above Figure 1 The method shown is used to execute the first business at the service layer. Figures 1 to 6 The specific process of each network component executing the first service is described in detail. In this example, the function of the access network is performed by the base station gNB, which is equivalent to the above Figure 5 NG-RAN shown.
[0218] Step 0a, UE1 completes registration by interacting with the AMF network element (or SMF network element) through the base station, and similarly, UE2 also completes registration with the network. In some embodiments, the registration message may indicate that the terminal or the network supports or does not support the first service.
[0219] In step 0b, UE1 and UE2 respectively establish a second session with the network, and the second session may be, for example, a PDU session. For example, UE1 requests data transmission from the network, and the network allocates data transmission resources to each network element and UE1, thereby completing the establishment of the second session. During and after the second session is established, UE1 and UE2 may establish a first session with the network.
[0220] Step 1, UE2 can send the first information to the AMF network element (or SMF network element) through the base station.
[0221] Step 1b, the AMF network element (or SMF network element) transmits the first information to the first service management function network element to request relevant information of the first service, such as the first parameter.
[0222] Step 2, the first service management function network element manages the first service, for example, obtains and determines relevant information of the first service, such as the first parameter. In some embodiments, the process of obtaining information can interact with the core network element, such as interacting with the UDM for contract information, interacting with the PCF for policy information, interacting with the SMF for session information, and interacting with the UPF for user plane information. The interaction includes operations such as obtaining, providing, updating, releasing, and deleting. In this application scenario, the first parameter is the third parameter.
[0223] In step 3a, a core network user plane node such as a UPF network element or a first service transmission function network element may obtain relevant information of the first service, such as a first parameter, from a first service management function network element.
[0224] Step 3b, the first service management function network element provides the AMF / SMF network element with relevant information of the first service, such as the first parameter.
[0225] Step 3c: The first service management function network element provides the base station with relevant information of the first service, such as the first parameter. Step 3c is an optional step. In a variation, the first parameter may be forwarded to the base station by the AMF / SMF network element.
[0226] Step 4: The network sends a first message to UE2, where the first message includes the first parameter and other relevant information of the first service. In some embodiments, the first message may be received from any one of the AMF / SMF network element, the base station, and the first service management function network element.
[0227] Step 4': The network instructs UE1 to start executing the first service and sends a first message.
[0228] Step 5: UE2 saves the content of the received first message, such as saving the first parameter and other related information of the first service. Similarly, UE1 saves the content of the received first message.
[0229] Step 6: The application layer (such as a sensor) sends a data packet 1 to UE 2. The data packet 1 is data of the first service.
[0230] Step 7: UE2 processes data packet 1 using the first security parameter at the service layer to obtain a processed data packet.
[0231] In one embodiment, in step 7, UE2 can use the first security parameter at the protocol layer to perform security processing on data packet 1. The processed data packet is transmitted to the base station through the first session. In this application scenario, the resources used by UE2 to transmit data of the first service have been preconfigured.
[0232] In response to receiving the data packet transmitted by UE2, the base station may execute step 8a to decrypt and deprotect the received data packet using the first security parameter acquired in step 3c.
[0233] Furthermore, the base station may also receive the same data packet from UE1, and also use the first security parameter to decrypt and deprotect the received data packet.
[0234] Then, the base station may combine the data packets received from UE1 and UE2 and transmit the combined data packets to the core network.
[0235] In some embodiments, in step 7, UE2 can use the first security parameter to securely process data packet 1 at the service layer (e.g., IP layer), and the protocol layer of UE2 (e.g., PDCP layer or SDAP layer) no longer securely processes the data. The processed data packet is transmitted to the base station through the first session, and then transparently transmitted to the core network via the base station.
[0236] In this example, step 3c may be omitted.
[0237] In response to receiving the data packet transparently transmitted by the base station, the UPF network element or the first service transmission function network element executes step 8b to decrypt and deprotect the received data packet using the first security parameter. The decrypted and deprotected data can then be transmitted to the external network.
[0238] In the second typical application scenario (referred to as application scenario 2), the communication system may include a terminal, an access network, a core network, and an external network. Figure 7 The security architecture of each network component at the service layer is exemplified, wherein the terminals include UE1 and UE2, the access network includes NG-RAN, the core network includes AMF network element, SMF network element, first network element and UPF network element, and the external network includes AF / AS server.
[0239] Specifically, the AMF network element is used to provide AMF, the SMF network element is used to provide SMF, and the UPF network element is used to provide UPF.
[0240] Furthermore, compared to the existing core network, the core network of the embodiment of the present application adds a first network element for processing the first service. For example, the first parameter can be configured by the first network element. In some embodiments, the first network element may include a first service management function network element for providing the first service management function.
[0241] Furthermore, the AMF network element, the SMF network element and the first service management function network element can be integrated into the signaling plane of the core network.
[0242] Furthermore, the UPF network element can be integrated into the data plane of the core network.
[0243] In some embodiments, the terminal (eg, UE1, UE2) may implement the following functions:
[0244] 1) Requesting to execute a first service;
[0245] 2) requesting the network for information related to executing the first service;
[0246] 3) receiving relevant information of the first service 1 obtained from the network;
[0247] 4) Storing, updating, and deleting relevant information of the first service provided by the network;
[0248] 5) Pre-configuring relevant information of the first service in the UE (such as the ME or the USIM);
[0249] 6) using the relevant information of the first service to process data, such as identifying uplink data belonging to the first service, and performing security protection on the uplink data of the first service, such as performing encryption and / or integrity protection at the PDCP layer;
[0250] 7) Applying for resources for the first service, such as executing a service request procedure, the terminal determines whether to initiate a resource application according to at least a part of the session type, terminal type and service type configured by the network.
[0251] In some embodiments, the core network implements the following functions:
[0252] 1) The core network manages and allocates resources required for the first service, which can be specifically performed in AMF, SMF, or other core network functions such as the first service management function. The action of the core network managing and allocating resources required for the first service can be performed after the network receives a request from the terminal to execute the first service, for example, triggered by the request of the terminal. It can also be performed before the network receives a request from the terminal, for example, when the network originates (or Initiates) the execution of the first service, the network triggers the process required for executing the first service, such as the establishment process of the PDU session.
[0253] 2) The core network provides relevant information of the first service, for example, the core network provides relevant information of the first service to the terminal, the access network, and the external network such as the application service, and the core network network elements provide relevant information of the first service;
[0254] 3) The core network obtains part of the first service related information from the access network, such as the first security parameter. In this application scenario, at least part of the first parameter reuses the second parameter of a terminal related to the first session.
[0255] In some embodiments, the access network may implement the following functions:
[0256] 1) Providing some or all of the information related to the first service, such as the second security parameter of the terminal reused among the n terminals related to the first session. Specifically, the access network may provide some or all of the relevant information of the first service to the core network. Further, the access network may provide some or all of the relevant information of the first service to the terminal. USIM
[0257] In some embodiments, the USIM of the terminal may store and provide information required for the first service, such as policy, service type, session type, application ID, etc.
[0258] Furthermore, the first network element may be provided with a public interface to provide at least a portion of capability information, service information and demand information of the first service. For example, the first service management function and the AF / AS server may communicate with each other through the public interface.
[0259] In application scenario 2, refer to Figure 8 , the above Figure 6The communication system shown can perform the above Figure 1 The method shown is used to execute the first business at the service layer. Figures 1 to 4 , Figure 7 and Figure 8 The specific process of each network component executing the first service is described in detail. In this example, the function of the access network is performed by the base station gNB, which is equivalent to the above Figure 5 NG-RAN shown.
[0260] The details of step 0a and step 0b can be found in the above Figure 6 The relevant descriptions in the application scenario 1 are not repeated here. The base station obtains the second security parameter and the second IP address of UE1 during the registration process of UE1.
[0261] Specifically, after executing step 0a and step 0b, UE1 and UE2 each obtain their own second security parameters and second IP addresses, which are used in the protocol layer (e.g., PDCP layer) of the terminal, and UE1 and UE2 respectively inform the base station of the second security parameters and second IP addresses through RRC signaling. The second security parameters of UE1 are different from the second security parameters of UE2, and the second IP address of UE1 is different from the second IP address of UE2.
[0262] Step 1: UE2 may send first information to an AMF network element (or SMF network element) through a base station. Further, the AMF network element (or SMF network element) transmits the first information to a first service management function network element to request relevant information of the first service, such as a first parameter.
[0263] Step 2: The core network establishes a first session to process the first service, and allocates relevant information of the first service to the first session, such as the first IP address and first security parameter used by the terminal to send data, and the identifier of the first session. In this application scenario, the first IP address needs to reuse the second IP address of UE1, and the first security parameter reuses the second security parameter of UE1.
[0264] In step 3, the core network may request the access network for resource information required for the first service, such as the second IP address and / or second security parameters of UE1. Accordingly, the access network provides the core network with the resource information required for the first service. For example, the AMF network element of the core network may send a third message to the base station via the N2 interface, and receive a fourth message fed back by the base station to obtain the second IP address and / or second security parameters of UE1. The third message and / or the fourth message may be carried by an AS message.
[0265] In some embodiments, the resource information required for the first service provided by the access network to the core network may be a response to the resource information required for the first service requested by the core network to the access network, or may be triggered by the access network (e.g., originating, or Initiating) to provide the resource information required for the first service to the core network. For example, when the corresponding information in the access network changes, the corresponding information may be actively updated to the core network. Thus, through the subsequent interaction between the network and UE2, UE2 may use the second security parameter of UE1 to transmit data of the first service.
[0266] Step 4: The network sends a first message to UE2, where the first message includes the first parameter and other relevant information of the first service. In some embodiments, the first message may be received from an AMF / SMF network element. For example, the core network may provide the information in a NAS message, such as a mobility management message, a session management message, or may provide the information through a user plane. In some embodiments, part of the content in the first message (e.g., the second security parameter of UE1) may also be provided to the UE through the access network, such as through a radio resource management message (e.g., RRC signaling).
[0267] Step 4', the network (such as AMF / SMF network element) instructs UE1 to start executing the first service, and the first IP address of the first service is the second IP address of UE1. Further, the network may also send at least part of the content in the first message, such as the identifier of the first session.
[0268] Step 5: UE2 saves the content of the received first message, such as saving the second IP address and the second security parameter of UE1.
[0269] Step 6: The application layer data source (such as a sensor) sends data packet 1 to UE1 and UE2, where data packet 1 is data of the first service. The source IP address of the transmission data packet 1 may be the first IP address. In response to receiving data packet 1, UE1 sends a second message to request the network to allocate resources for the first session.
[0270] Specifically, the terminal needs to request the network to allocate resources to the terminal when uploading data, including the time-frequency resources of the air interface. In the embodiment of the present application, UE1 and UE2 use the same time-frequency resources to transmit the same data packet 1, so one of the terminals can request the network to allocate resources. For example, the AMF / SMF network element indicates that UE1 is the basic terminal in step 4', then UE1 determines in step 6 that it needs to send a second message to request the network to allocate resources for the first session.
[0271] For UE2, UE2 determines that data packet 1 is data of the first service based on the source IP address used by data packet 1, and because the AMF / SMF network element indicates that UE2 is an auxiliary terminal in the first message sent to UE2 in step 4, UE2 does not initiate a resource allocation request in step 6.
[0272] In some embodiments, UE1 may request resource allocation using a SERVICE REQUEST procedure. Further, the second message may carry an identifier of the first session.
[0273] In some embodiments, the network allocates resources for the first service after the network receives the second message from the terminal, for example, triggered by the request of UE1. It can also be before the network receives the second message from the terminal, for example, when the network triggers (for example: Network originating, or Initiating) to actively execute the first service. The process of network triggering the execution of the first service can be implemented, for example, during the establishment of the PDU session.
[0274] In some embodiments, the network may be a function of an access network. For example, a base station may respond to the second message and allocate resources for the first session to the first service.
[0275] In some embodiments, the network may be a function of a core network, for example, an AMF network element or an SMF network element may respond to the second message and allocate resources for the first session to the first service.
[0276] Further, after the resource allocation is completed, the base station may notify UE1 that the resource establishment for the first session is completed. Optionally, the base station may also notify UE2 that the resource establishment for the first session is completed.
[0277] Step 7, UE1 and UE2 respectively use the relevant information of the first service to process data packet 1. Specifically, UE1 uses its own second security parameter as the first security parameter to process data packet 1, and uses its own second IP address as the first IP address to transmit the processed data through the first session. In parallel, UE2 uses UE1's second security parameter as the first security parameter to process data packet 1, and uses UE1's second IP address as the first IP address to transmit the processed data through the first session.
[0278] For any terminal of UE1 and UE2, the second security parameter of UE1 may be used at the protocol layer to process data packet 1. In response to receiving the same processed data transmitted by UE2 and UE1 respectively, the base station may perform step 8a, decrypt and deprotect the received data packet using the second security parameter of UE1 obtained during the registration phase of UE1, and transmit the data packet to the core network after merging.
[0279] In a common variation example of the above-mentioned application scenario 1 and application scenario 2, data packet 1 may be an Ethernet data packet. Accordingly, when UE1 and UE2 each process the received data packet 1 using the first security parameter, the processed data is packaged into an Ethernet data packet for transmission to the next node (e.g., a base station).
[0280] In a common variation of the above application scenario 1 and application scenario 2, for a terminal (such as UE2) that is instructed not to request resources for the first session, after receiving data of the first service from the application layer, UE2 can send a second message. The network determines whether resources have been allocated for the first session based on the identifier of the first session in the second message. If resources have been allocated, the resource allocation request of UE2 is not responded to.
[0281] From the above, using this implementation, different terminals can obtain or preconfigure the same first IP address from the network for the terminal to send data of the first service. Further, different terminals can obtain or preconfigure the same first security parameter from the network for security processing when the terminal sends data of the first service.
[0282] Further, the core network may manage resources related to the first service (eg, information related to the first service), such as generating a first IP address or a first security parameter, or obtaining a first security parameter (eg, a user plane key) from the access network.
[0283] Furthermore, the first information / first message may carry relevant information of the first service / information indicating capability of the first service.
[0284] Furthermore, the network can provide a public interface related to the first service, such as information disclosure and capability disclosure. For example, a third-party server can propose a service requirement to the network: when does the power grid want the first service to start? At this time, the demand information can be told to the core network through a public interface, and the core network configures the relevant parameters to the access network and the terminal. For another example, the operator server can inform the third-party server of the service information of the first service, such as the communication status of the network, through the core network through a public structure.
[0285] Fig. 9 It is a structural schematic diagram of a data transmission device (denoted as data transmission device 2) provided in an embodiment of the present application.
[0286] Those skilled in the art will appreciate that the data transmission device 2 of this embodiment can be used to implement the above Figures 1 to 8 The method described in the embodiment. The data transmission device 2 may be the terminal mentioned above.
[0287] Specifically, refer to Fig. 9The data transmission device 2 may include: an acquisition module 21, used to acquire a first parameter associated with a first session, the first parameter including a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module 22, used to transmit data of the first service through the first session using the first parameter; wherein all terminals associated with the first session use the first parameter to transmit the data.
[0288] In some embodiments, the data transmission device 2 may further include: a sending module (not shown) for sending first information, the first information being used to request the acquisition of the first parameter. Further, the acquisition module 21 includes: a receiving unit (not shown) for receiving the first parameter associated with the first session.
[0289] In some embodiments, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0290] In some embodiments, the first information is carried via a non-access layer message or an access layer message.
[0291] In some embodiments, the transmission module 22 may include: a first transmission unit (not shown) for processing the data using the first security parameter and transmitting the processed data as an Ethernet data packet; or a second transmission unit (not shown) for processing the data using the first security parameter and transmitting it using the first IP address.
[0292] In some embodiments, the acquisition module 21 may include: a receiving unit (not shown), configured to receive a first message, where the first message includes a first parameter associated with the first session.
[0293] In some embodiments, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0294] In some embodiments, the first message is carried via a non-access layer message or an access layer message.
[0295] In some embodiments, the first parameter is preconfigured.
[0296] In some embodiments, the first parameter multiplexes a second parameter of a terminal associated with the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal associated with the first session, and the second parameter is associated with a service other than the first service.
[0297] In some embodiments, the action of processing the data using the first security parameter is performed at a service layer, or the action of processing the data using the first security parameter is performed at a protocol layer.
[0298] For more information about the working principle and working mode of the data transmission device 2, please refer to the above Figures 1 to 8 The relevant description in will not be repeated here.
[0299] In a specific implementation, the above-mentioned data transmission device 2 can correspond to a chip with a data transmission function in a terminal, or to a chip with a data processing function, such as a system-on-a-chip (SOC for short), a baseband chip, etc.; or to a chip module in a terminal that includes a chip with a data transmission function; or to a chip module with a chip with a data processing function, or to a terminal.
[0300] Fig.10 2 is a schematic diagram of the structure of another data transmission device (referred to as data transmission device 3) provided in an embodiment of the present application. A person skilled in the art will appreciate that the data transmission device 3 described in this embodiment can be used to implement the above Figures 1 to 8 The method described in the embodiment. The data transmission device 3 may be the access network mentioned above.
[0301] Specifically, refer to Fig.10 The data transmission device 3 may include: a receiving module 31, used to receive data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, and the first parameters include a first security parameter and / or a first IP address; a transmission module 32, used to merge the received data and transmit it to the next node.
[0302] In some embodiments, the first security parameter is a third security parameter, the third security parameter does not reuse the second security parameter of the terminal related to the first session, and the second security parameter is associated with services other than the first service. The data transmission device 3 may also include: an acquisition module (not shown) for acquiring the first security parameter from the core network.
[0303] In some embodiments, the first security parameter multiplexes a second security parameter of a terminal related to the first session, and the second security parameter is associated with a service other than the first service.
[0304] In some embodiments, the transmission module 32 may include: a processing unit (not shown) for deprocessing the data using the first security parameter and merging them to obtain deprocessed data; and a transmission unit (not shown) for transmitting the deprocessed data to the next node.
[0305] In some embodiments, the action of de-processing the data using the first security parameter is performed at a service layer, or the action of de-processing the data using the first security parameter is performed at a protocol layer.
[0306] In some embodiments, the data transmission device 3 may also include: a receiving unit (not shown in the figure), used to receive a third message from the core network, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; a sending unit (not shown in the figure), used to send a fourth message, the fourth message including the second security parameter of the target terminal, and the first security parameter multiplexes the second security parameter of the target terminal.
[0307] For more information about the working principle and working mode of the data transmission device 3, please refer to the above Figures 1 to 8 The relevant description in will not be repeated here.
[0308] In a specific implementation, the above-mentioned data transmission device 3 may correspond to a chip with a data transmission function in a network device of an access network, or to a chip with a data processing function, such as a system-on-a-chip (SOC for short), a baseband chip, etc.; or to a chip module including a chip with a data transmission function in a network device of an access network; or to a chip module with a chip with a data processing function, or to a network device of an access network.
[0309] Fig.11 1 is a schematic diagram of the structure of another data transmission device (referred to as data transmission device 4) provided in an embodiment of the present application. A person skilled in the art will appreciate that the data transmission device 4 described in this embodiment can be used to implement the above Figures 1 to 8 The method described in the embodiment. The data transmission device 4 may be the core network mentioned above.
[0310] Specifically, refer to Fig.11The data transmission device 4 may include: a sending module 41, used to send a first parameter associated with a first session, the first parameter includes a first security parameter and / or a first IP address, and the first session is associated with a first service; a receiving module 42, used to receive data of the first service transmitted by an access network, and the data is transmitted through the first session; wherein the network elements related to the first session all use the first parameter to transmit the data.
[0311] In some embodiments, the data transmission device 4 may further include: a first information receiving module (not shown) for receiving first information, where the first information is used to request to obtain the first parameter.
[0312] In some embodiments, the sending module 41 may include: a sending unit (not shown), configured to send a first message, where the first message includes a first parameter associated with the first session.
[0313] In some embodiments, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0314] In some embodiments, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0315] In some embodiments, the first information is carried via a non-access layer message or an access layer message; and / or, the first message is carried via a non-access layer message or an access layer message.
[0316] In some embodiments, the first parameter multiplexes the second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service; and / or the data includes at least one of the following: Ethernet data packet; IP data packet.
[0317] In some embodiments, the data transmission module 4 may further include: a processing module (not shown) configured to process the data using the first security parameter solution.
[0318] In some embodiments, the data received from the access network is data processed using the first security parameter solution.
[0319] In some embodiments, the data transmission module 4 may further include: a second message receiving unit (not shown) for receiving a second message for requesting allocation of resources for the first session; and a configuration unit (not shown) for configuring the resources.
[0320] In some embodiments, the data transmission module 4 may also include: a third message sending module (not shown in the figure), used to send a third message, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; a fourth message receiving module (not shown in the figure), used to receive a fourth message, the fourth message including the second security parameter of the target terminal, and the first parameter reuses the second security parameter.
[0321] In some embodiments, the first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
[0322] In some embodiments, the first network element is provided with a public interface for providing capability information and / or service information of the first service, and / or receiving demand information of the first service.
[0323] For more information about the working principle and working mode of the data transmission device 4, please refer to the above Figures 1 to 8 The relevant description in will not be repeated here.
[0324] In a specific implementation, the above-mentioned data transmission device 4 may correspond to a chip with a data transmission function in a core network element, or to a chip with a data processing function, such as a system-on-a-chip (SOC for short), a baseband chip, etc.; or to a chip module in a core network element that includes a chip with a data transmission function; or to a chip module with a chip with a data processing function, or to a core network element.
[0325] In a specific implementation, each module / unit included in each device or product described in the above embodiments may be a software module / unit or a hardware module / unit, or may be partly a software module / unit and partly a hardware module / unit.
[0326] For example, for each device or product applied to or integrated in a chip, each module / unit contained therein may be implemented in the form of hardware such as circuits, or at least some of the modules / units may be implemented in the form of software programs, which run on a processor integrated inside the chip, and the remaining (if any) modules / units may be implemented in the form of hardware such as circuits; for each device or product applied to or integrated in a chip module, each module / unit contained therein may be implemented in the form of hardware such as circuits, and different modules / units may be located in the same component (such as a chip, circuit module, etc.) or different components of the chip module, or at least some of the modules / units may be implemented in the form of software programs. The element can be implemented in the form of a software program, which runs on a processor integrated inside the chip module, and the remaining (if any) modules / units can be implemented in the form of hardware such as circuits; for various devices and products applied to or integrated in the terminal, the various modules / units contained therein can be implemented in the form of hardware such as circuits, and different modules / units can be located in the same component (for example, chip, circuit module, etc.) or in different components in the terminal, or, at least some modules / units can be implemented in the form of a software program, which runs on a processor integrated inside the terminal, and the remaining (if any) modules / units can be implemented in the form of hardware such as circuits.
[0327] The embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored, and the computer program is executed by a processor to enable the above Figures 1 to 8 The steps of the data transmission method provided in the illustrated embodiment are executed.
[0328] In an embodiment of the present application, the storage medium may include a non-volatile memory or a non-transitory memory, and may also include an optical disk, a mechanical hard disk, a solid-state hard disk, etc.
[0329] Fig.12 It is a structural diagram of another data transmission device provided in an embodiment of the present application.
[0330] Specifically, refer to Fig.12 The data transmission device may include a processor 51, the processor 51 and a memory 52 are coupled, and the memory 52 may be located inside the device or outside the device. Optionally, a transceiver 53 is further included. The memory 52, the processor 51 and the transceiver 53 may be connected via a communication bus. The memory 52 stores a computer program that can be run on the processor 51, and the processor 51 executes the above-mentioned Figures 1 to 8In the steps of the data transmission method provided in the illustrated embodiment, the transceiver 53 can perform the sending and / or receiving actions mentioned above under the control of the processor 51. The data transmission device can be the network device mentioned above, or a terminal, or a core network element.
[0331] In the embodiment of the present application, the memory 52 includes a non-volatile memory or a non-transitory memory, and may also include an optical disk, a mechanical hard disk, a solid-state hard disk, etc.
[0332] In the embodiment of the present application, the processor 51 may be a central processing unit (CPU), and the processor 51 may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0333] A person skilled in the art may understand that all or part of the steps in the various methods of the above embodiments may be completed by instructing the relevant hardware through a program, and the program may be stored in a computer-readable storage medium, which may include: ROM, RAM, disk or CD, etc.
[0334] The embodiments described in this application are described with reference to the flowcharts and / or block diagrams of the methods, devices (apparatus), and computer program products according to the embodiments of the application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0335] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0336] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0337] It should also be noted that in the embodiments of the present application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can be represented by: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, c can be single or multiple.
[0338] In the embodiments of the present application, the terms "include", "comprises" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the presence of other identical elements in the process, method, commodity or device including the element.
[0339] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0340] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0341] Those skilled in the art will appreciate that the various units and algorithm steps described in the embodiments of the present application can be implemented by a combination of electronic hardware, computer software, and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0342] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices, apparatuses and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0343] Although the present application is disclosed as above, the present application is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application shall be subject to the scope defined by the claims.
Claims
1. A data transmission method, characterized in that: include: Acquire a first parameter associated with a first session, where the first parameter includes a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; transmitting data of the first service through the first session using the first parameter; Among them, all terminals related to the first session use the first parameter to transmit the data.
2. The data transmission method according to claim 1, characterized in that: Also includes: Sending first information, where the first information is used to request to obtain the first parameter; The obtaining the first parameter associated with the first session includes: receiving the first parameter associated with the first session.
3. The data transmission method according to claim 2, characterized in that: The first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; and an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
4. The data transmission method according to claim 2 or 3, characterized in that: The first information is carried by a non-access layer message or an access layer message.
5. The data transmission method according to any one of claims 1 to 4, characterized in that: The transmitting the data of the first service through the first session using the first parameter includes: Processing the data using the first security parameter and transmitting the processed data as an Ethernet data packet; or The data is processed using the first security parameters and transmitted using the first IP address.
6. The data transmission method according to any one of claims 1 to 5, characterized in that: The acquiring the first parameter associated with the first session includes: A first message is received, the first message including a first parameter associated with the first session.
7. The data transmission method according to claim 6, characterized in that: The first message further includes at least one of the following: second indication information, used to indicate whether the terminal and / or the network supports the first service; an identifier of the first session; terminal type; service type of the first service; session type of the first session; Part or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
8. The data transmission method according to claim 6 or 7, characterized in that: The first message is carried by a non-access layer message or an access layer message.
9. The data transmission method according to any one of claims 1 to 8, characterized in that: The first parameter is preconfigured; and / or the first parameter multiplexes a second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service; and / or the action of processing the data using the first security parameter is performed at the service layer, or the action of processing the data using the first security parameter is performed at the protocol layer.
10. A data transmission method, characterized in that: include: receiving data transmitted by one or more terminals through a first session, where the first session is associated with a first service, the data is data of the first service, and the terminals associated with the first session all transmit the data using first parameters, where the first parameters include a first security parameter and / or a first IP address; The received data are combined and transmitted to the next node.
11. The data transmission method according to claim 10, characterized in that: The first security parameter is a third security parameter, the third security parameter does not reuse a second security parameter of a terminal related to the first session, the second security parameter is associated with services other than the first service, and the method further includes: obtaining the first security parameter from a core network.
12. The data transmission method according to claim 10, characterized in that: The first security parameter multiplexes a second security parameter of a terminal related to the first session, and the second security parameter is associated with services other than the first service.
13. The data transmission method according to any one of claims 10 to 12, characterized in that: The combining the received data and transmitting to the next node comprises: De-processing the data using the first security parameter and combining them to obtain de-processed data; The de-processed data is transmitted to the next node.
14. The data transmission method according to claim 13, characterized in that: The action of de-processing the data using the first security parameter is performed at the service layer, or the action of de-processing the data using the first security parameter is performed at the protocol layer.
15. The data transmission method according to any one of claims 10 to 14, characterized in that: Also includes: receiving a third message from the core network, the third message including an identity of the target terminal and an identifier of the second session of the target terminal; A fourth message is sent, where the fourth message includes a second security parameter of the target terminal, and the first security parameter multiplexes the second security parameter of the target terminal.
16. A data transmission method, characterized in that: include: Sending a first parameter associated with a first session, where the first parameter includes a first security parameter and / or a first IP address, and the first session is associated with a first service; Receive data of the first service transmitted by the access network, the data being transmitted through the first session; wherein network elements related to the first session all use the first parameters to transmit the data.
17. The data transmission method according to claim 16, characterized in that: Also includes: receiving first information, where the first information is used to request obtaining the first parameter; and / or The sending the first parameter associated with the first session includes: sending a first message, where the first message includes the first parameter associated with the first session.
18. The data transmission method according to claim 17, characterized in that: The first information includes at least one of the following: first indication information for indicating execution of the first service; an identity of a terminal associated with the first session; session information of the first session; capability information of the terminal supporting the first service; a group identifier of a group to which the terminal associated with the first session belongs; an identifier of a second session of the terminal associated with the first session, the second session being associated with services other than the first service; and / or The first message further includes at least one of the following: second indication information, used to indicate whether the terminal and / or the network supports the first service; an identifier of the first session; terminal type; service type of the first service; session type of the first session; Part or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
19. The data transmission method according to claim 17 or 18, characterized in that: The first information is carried by a non-access layer message or an access layer message; and / or the first message is carried by a non-access layer message or an access layer message.
20. The data transmission method according to any one of claims 16 to 19, characterized in that: The first parameter multiplexes the second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service; and / or the data includes at least one of the following: Ethernet data packet; IP data packet.
21. The data transmission method according to any one of claims 16 to 20, characterized in that: Also includes: The data is processed using the first security parameter; or, the data received from the access network is data processed using the first security parameter.
22. The data transmission method according to any one of claims 16 to 21, characterized in that: Also includes: receiving a second message, wherein the second message is used to request allocation of resources for the first session; Configure the resource.
23. The data transmission method according to any one of claims 16 to 22, characterized in that: Also includes: Sending a third message, wherein the third message includes an identity identifier of a target terminal and an identifier of a second session of the target terminal; A fourth message is received, where the fourth message includes a second security parameter of the target terminal, and the first parameter multiplexes the second security parameter.
24. The data transmission method according to any one of claims 16 to 23, characterized in that: The first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
25. The data transmission method according to claim 24, characterized in that: The first network element is provided with a public interface for providing capability information and / or service information of the first service, and / or receiving demand information of the first service.
26. A data transmission device, characterized in that: include: an acquisition module, configured to acquire a first parameter associated with a first session, wherein the first parameter includes a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module, configured to transmit data of the first service through the first session using the first parameter; Among them, all terminals related to the first session use the first parameter to transmit the data.
27. A data transmission device, characterized in that: include: a receiving module, configured to receive data transmitted by one or more terminals through a first session, wherein the first session is associated with a first service, the data is data of the first service, and the terminals associated with the first session all transmit the data using first parameters, wherein the first parameters include a first security parameter and / or a first IP address; The transmission module is used to merge the received data and transmit it to the next node.
28. A data transmission device, characterized in that: include: A sending module, configured to send a first parameter associated with a first session, where the first parameter includes a first security parameter and / or a first IP address, and the first session is associated with a first service; A receiving module, configured to receive data of the first service transmitted by an access network, wherein the data is transmitted through the first session; Among them, all network elements related to the first session use the first parameter to transmit the data.
29. A computer-readable storage medium, wherein the computer-readable storage medium is a non-volatile storage medium or a non-transient storage medium, and a computer program is stored thereon, wherein: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 25 are performed.
30. A data transmission device, comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, characterized in that: When the processor runs the computer program, the steps of the method according to any one of claims 1 to 25 are performed.