Data interaction method, device and equipment of SNPN networking system and storage medium
By implementing automated SNPN network selection and handover in the PLMN network, the existing SNPN networking system is solved, and flexible handover between SNPNs and communication quality guarantees are achieved.
Patent Information
- Application Number
- CN202510101200.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-06
AI Technical Summary
The existing SNPN networking system is inflexible in network selection and handover, has high maintenance costs, and users' handover requirements between different SNPNs have not been met.
By implementing automated network selection and handover in the PLMN network, the user equipment selects the target SNPN according to the signal quality after accessing the PLMN, and establishes a PDU session through the PLMN for data interaction. This method allows user equipment to flexibly switch between different SNPNs without manual switching.
It realizes automated handover between SNPNs, reduces maintenance costs, improves network flexibility and user experience, and ensures communication quality.
Smart Images

Figure CN119946904A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a data interaction method, device, equipment and storage medium of a SNPN networking system. Background Art
[0002] SNPN (Stand-alone Non-Public Network) in 5G communication network is a network designed for users in specific vertical industries. It is separated from the public mobile network (PMN) to meet the needs of specific industries. Since SNPN is a non-public network used by corresponding enterprises in a small range, it has the advantages of independence, isolation, flexibility and security; at the same time, it has the disadvantages of high cost, long-term spectrum resource limitation; with the increasingly developed network, closer connection between upstream and downstream of the industrial chain, and increasingly rich application scenarios of SNPN, the independence, isolation and security of SNPN have become its limitations if we want to further popularize the use of SNPN today. With the interaction between various industries and the application of various scenarios, the need for users to switch between different SNPNs has also become an important step in the continued development of SNPN.
[0003] The existing SNPN network composition binding requires multiple configurations, and the same change of the SNPN network composition involves many configurations, which is very inflexible for the composition of the network. Moreover, the main network of the existing SNPN network is the SNPN, that is, the network is responsible for managing other SNPN networks, which is relatively wasteful for SNPNs with high maintenance costs.
[0004] Therefore, there is an urgent need for a data interaction method for an SNPN networking system that can overcome the defects of existing solutions. Summary of the invention
[0005] In view of this, the present application provides a data interaction method, device, equipment and storage medium of an SNPN networking system, which can realize automatic network selection and switching between multiple SNPNs. The technical solution is as follows.
[0006] In a first aspect, the present invention provides a data interaction method of an SNPN networking system, wherein the SNPN networking system includes multiple SNPNs and a networking PLMN, wherein the networking PLMN is communicatively connected with the multiple SNPNs through a SEPP network element, and a base station signal of the networking PLMN covers the multiple SNPNs; the method is executed by a user equipment, and the method includes:
[0007] Initiate a registration request to the target SNPN through the first PDU session, and establish a second PDU session with the target SNPN; the first PDU session is established by the user equipment initiating a registration request to the networking PLMN; the target SNPN is selected based on the signal quality between the user equipment and the SNPN networking system;
[0008] Data is exchanged with the target SNPN according to the first PDU session and the second PDU session.
[0009] In an optional implementation, before the step of initiating a registration request to the target SNPN through the first PDU session, the step further includes:
[0010] If a PDU session has been established with the first SNPN, deregistration is initiated in the first SNPN to cancel the PDU session with the SNPN; the first SNPN is a SNPN other than the target SNPN in the SNPN networking system.
[0011] The data interaction method of the SNPN networking system of the present invention can switch to a new SNPN according to the needs of the user, and only needs to deregister in the current SNPN, cancel the PDU session with the current SNPN, re-initiate a registration request to the new SNPN, establish a new PDU session, and then perform data interaction with the new SNPN based on the new PDU session. No manual switching is required, and the communication quality can be guaranteed.
[0012] In an optional implementation, initiating a registration request to a target SNPN through a first PDU session and establishing a second PDU session with the target SNPN includes:
[0013] Sending a first registration request to the networking PLMN, and establishing a first PDU session with a data network of the networking PLMN;
[0014] Establishing a connection with the non-3GPP access gateway of the target SNPN through the first PDU session;
[0015] A second registration request is sent to the non-3GPP access gateway of the target SNPN, and a second PDU session is established with the data network of the target SNPN.
[0016] In an optional implementation manner, before establishing the first PDU session with the data network of the networking PLMN, the method further includes:
[0017] Sending an authentication request to the access and mobility management function module of the network PLMN; the access and mobility management function module performs a legitimacy check on the user equipment according to the user ID information indicated in the authentication request, and generates a first verification result;
[0018] Receive the first verification result sent by the access and mobility management function module of the networking PLMN.
[0019] In an optional implementation, establishing a connection with the non-3GPP access gateway of the target SNPN through the first PDU session includes:
[0020] Obtain the IP information of the non-3GPP access gateway of the target SNPN;
[0021] Based on the IP information, a connection is established with the non-3GPP access gateway of the target SNPN through a non-3GPP access method.
[0022] The data interaction method of the SNPN networking system of the present invention can prevent user equipment of the SNPN that is not allowed to access from obtaining contract data through isolation protection between the non-3GPP access mode and SEPP, and identity authentication of the non-3GPP access gateway and SNPN is required for access to the SNPN. The SNPN can also refuse access to unauthorized user equipment.
[0023] In an optional implementation, the data interaction with the target SNPN according to the first PDU session and the second PDU session includes:
[0024] Establishing a data transmission link between the user equipment, the data network of the networking PLMN, and the data network of the target SNPN according to the first PDU session and the second PDU session;
[0025] According to the data transmission link, data interaction is performed with the data network of the target SNPN.
[0026] The data interaction method of a SNPN networking system provided by the present invention has the following advantages.
[0027] The data interaction method of the SNPN networking system of the present invention is applied to the SNPN networking system, which is composed of multiple SNPNs and a networking PLMN. The base station signal of the networking PLMN can cover all SNPNs in the SNPN networking system, ensuring that the user equipment can access the PLMN network before accessing the SNPN. In the SNPN networking system, the SEPP network element in the PLMN establishes an N32 link with each SEPP network element in the SNPN to strengthen the security of the contract information interaction of each user equipment in the main network, and maintain the corresponding isolation, independence, security and other characteristics of the SNPN itself. Before accessing the target SNPN, the user equipment first registers with the PLMN and establishes a PDU session with the PLMN. Then, the SNPN signal that can be received is collected, and the SNPN to be accessed is selected according to the quality of the signal. After determining the SNPN to be accessed, a registration request is initiated to the target SNPN through the PDU session established with the PLMN, thereby establishing a PDU session with the target SNPN. Finally, data interaction can be performed with the target SNPN according to the PDU session established with the PLMN and the target SNPN. Taking the PLMN network as the main body, other SNPN networks can be added to the PLMN network as needed to form a PLMN-SNPN networking system. The addition and removal of SNPN are very flexible. In addition, when the user equipment needs to switch to other SNPNs, it only needs to deregister in the current SNPN, cancel the PDU session with the current SNPN, re-initiate a registration request to the SNPN that needs to be switched, establish a new PDU session, and then interact with the new SNPN based on the new PDU session. For switching between SNPNs, this method achieves the effect of switching between different SNPNs by, on the premise of accessing the PLMN network, the user selects a suitable SNPN, obtains the user's identity data in the PLMN for registration and deregistration processes; no manual switching is required, and communication quality can be guaranteed.
[0028] In a second aspect, the present invention provides a data interaction device of an SNPN networking system, the SNPN networking system comprising a plurality of SNPNs and a networking PLMN, the networking PLMN communicating with the plurality of SNPNs through a SEPP network element, the base station signal of the networking PLMN covering the plurality of SNPNs; the device is executed by a user equipment, the device comprising:
[0029] A session establishment module, configured to initiate a registration request to a target SNPN through a first PDU session, and establish a second PDU session with the target SNPN; the first PDU session is established by the user equipment initiating a registration request to the networking PLMN; the target SNPN is selected based on the signal quality between the user equipment and the SNPN networking system;
[0030] The interaction module is used to perform data interaction with the target SNPN according to the first PDU session and the second PDU session.
[0031] In an optional embodiment, the device further comprises:
[0032] The deregistration module is used to initiate deregistration in the first SNPN and cancel the PDU session with the SNPN if a PDU session has been established with the first SNPN; the first SNPN is a SNPN other than the target SNPN in the SNPN networking system.
[0033] In an optional implementation, the session establishing module is specifically used to:
[0034] Sending a first registration request to the networking PLMN, and establishing a first PDU session with a data network of the networking PLMN;
[0035] Establishing a connection with the non-3GPP access gateway of the target SNPN through the first PDU session;
[0036] A second registration request is sent to the non-3GPP access gateway of the target SNPN, and a second PDU session is established with the data network of the target SNPN.
[0037] In an optional implementation, the session establishing module is further used to:
[0038] Sending an authentication request to the access and mobility management function module of the network PLMN; the access and mobility management function module performs a legitimacy check on the user equipment according to the user ID information indicated in the authentication request, and generates a first verification result;
[0039] Receive the first verification result sent by the access and mobility management function module of the networking PLMN.
[0040] In an optional implementation, the session establishing module is further used to:
[0041] Obtain the IP information of the non-3GPP access gateway of the target SNPN;
[0042] Based on the IP information, a connection is established with the non-3GPP access gateway of the target SNPN through a non-3GPP access method.
[0043] In an optional implementation manner, the interaction module is specifically used to:
[0044] Establishing a data transmission link between the user equipment, the data network of the networking PLMN, and the data network of the target SNPN according to the first PDU session and the second PDU session;
[0045] According to the data transmission link, data interaction is performed with the data network of the target SNPN.
[0046] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor are communicatively connected to each other, computer instructions are stored in the memory, and the processor executes the data interaction method of the SNPN networking system of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0047] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the data interaction method of the SNPN networking system of the first aspect or any corresponding embodiment thereof.
[0048] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions, which are used to enable a computer to execute the data interaction method of the SNPN networking system of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0050] Figure 1 It is a structural diagram of a SNPN networking system according to an exemplary embodiment.
[0051] Figure 2 It is a schematic diagram of signal coverage of PLMN and each SNPN in a SNPN networking system according to an exemplary embodiment.
[0052] Figure 3 The present invention is a method flow chart showing a data interaction method of an SNPN networking system according to an exemplary embodiment.
[0053] Figure 4 The figure is a schematic diagram of a process of data interaction between a user equipment and a SNPN via a PLMN according to an exemplary embodiment.
[0054] Figure 5 The diagram is a timing diagram showing mutual access between a PLMN and a SNPN by a user equipment according to an exemplary embodiment.
[0055] Figure 6It is a structural diagram of a data interaction device of an SNPN networking system provided in an embodiment of the present application.
[0056] Figure 7 It is a structural schematic diagram of a computer device provided by an optional embodiment of the present invention. DETAILED DESCRIPTION
[0057] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of this application.
[0058] It should be understood that the "indication" mentioned in the embodiments of the present application can be a direct indication, an indirect indication, or an indication of an association relationship. For example, A indicates B, which can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an association relationship between A and B.
[0059] In the description of the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between two items, or an association relationship between the two items, or a relationship between indication and being indicated, configuration and being configured, and the like.
[0060] In an embodiment of the present application, "predefinition" can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in a device (for example, including a terminal device and a network device). The present application does not limit its specific implementation method.
[0061] First, the terms involved in this application are introduced.
[0062] AMF: Access and Mobility Management Function, access and mobility management function;
[0063] AUSF: Authentication Server Function, authentication service function;
[0064] UDM: Unified Data Management Function, unified data management function;
[0065] UPF: User Plane Function, user plane function;
[0066] DN: Data Network, data network;
[0067] N3IWF: Non-3GPP InterWorking Function, non-3GPP interworking function;
[0068] NRF: NF Repository Function, network storage function;
[0069] PCF: Policy Control Function, policy control function;
[0070] RAN: Radio Access Network, wireless access network;
[0071] SEPP: Security Edge Protection Proxy, security edge protection proxy;
[0072] SMF: Session Management Function;
[0073] SNPN: Stand-alone Non-Public Network, independent non-public network;
[0074] UE:User Equipment, user equipment;
[0075] UPF: User Plane Function, user plane function;
[0076] PDU: Packet Data Unit, packet data unit;
[0077] PLMN: Public Land Mobile Network, public land mobile network;
[0078] PNI-NPN: Public Network Integrated Non-Public Network, public network integrated NPN;
[0079] Qos: Quality of Service, quality service;
[0080] 3GPP: 3rd Generation Partnership Project, third generation communication standard;
[0081] IPsec: Internet Protocol Security, Internet Protocol Security;
[0082] IPsec SA: IPsec Security Association, which is used in the IPsec protocol to define and manage encryption, authentication, and other security policies.
[0083] IPsec Child SA: is a child association of IPsec Security Association (IPsec SA), which is usually derived from the parent SA (Parent SA) and is used for specific data flow protection;
[0084] IKE Create Child SA Request: This is a message type in the Internet Key Exchange (IKE) protocol, used to request the creation of one or more Child SAs based on an established Parent SA.
[0085] IKE Create Child SA Response: This is a message type used in the Internet Key Exchange (IKE) protocol to respond to the IKE Create Child SA Request message.
[0086] PDU Session Establishment: used to establish a PDU (Protocol Data Unit) session in the 5G network;
[0087] N2 Session Response: It is a signaling message used in the N2 interface (network control plane interface) in the 5G network to respond to the N2 Session Request message. During the PDU session establishment process, when the UE initiates a PDU session request and is processed by the relevant network components, the SMF will send the processing result back to the AMF through the N2 Session Response message.
[0088] SNPN (Stand-alone Non-Public Network) in 5G communication network is a network designed for users in specific vertical industries. It is separated from the public mobile network (PMN) to meet the needs of specific industries. Since SNPN is a non-public network used by corresponding enterprises in a small range, it has the advantages of independence, isolation, flexibility and security; at the same time, it has the disadvantages of high cost, long-term spectrum resource limitation; with the increasingly developed network, closer connection between upstream and downstream of the industrial chain, and increasingly rich application scenarios of SNPN, the independence, isolation and security of SNPN have become its limitations if we want to further popularize the use of SNPN today. With the interaction between various industries and the application of various scenarios, the need for users to switch between different SNPNs has also become an important step in the continued development of SNPN.
[0089] For example, in public safety and critical communications scenarios, when a disaster occurs, different emergency response teams (such as fire brigades and police forces) deploy their own dedicated networks to support communications. When multiple networks exist at the same time, all public safety users can automatically and securely connect between these networks, while other unauthorized users cannot access these networks, ensuring the exclusivity and security of communications.
[0090] Similarly, in a port environment, different terminals are managed by their respective operating companies, and each terminal has its own dedicated network to support its business operations. At the same time, the port authority also deploys a dedicated network to provide coverage on the container transportation channels between terminals. When the container ship moves between the terminals and the channels, the equipment on the ship automatically switches between the terminal and the port authority's network, ensuring the continuity and seamless switching of communication services without manual intervention by the user.
[0091] The existing SNPN network composition binding requires multiple configurations, and the same change of the SNPN network composition involves many configurations, which is very inflexible for the composition of the network. Moreover, the main network of the existing SNPN network is the SNPN, that is, the network is responsible for managing other SNPN networks, which is relatively wasteful for SNPNs with high maintenance costs.
[0092] Therefore, in order to overcome the defects of the existing solutions, an embodiment of the present invention provides a data interaction method for an SNPN networking system. When switching between SNPNs, the user selects a suitable SNPN on the premise of accessing the PLMN network, obtains the user's identity data in the PLMN for registration and deregistration processes to achieve the effect of switching between different SNPNs; no manual switching is required, and the communication quality can be guaranteed.
[0093] The data interaction method of the SNPN networking system provided in this embodiment is applied to the SNPN networking system. The structure of the networking system is as follows: Figure 1 As shown, it consists of multiple SNPNs and a networking PLMN. The SEPP network element in the PLMN of the SNPN networking system establishes an N32 link with each SEPP network element in the SNPN to enhance the security of the contract information interaction of each user equipment in the main network and maintain the corresponding isolation, independence, security and other characteristics of the SNPN itself. Figure 1 , the SEEP network element of the PLMN is connected to the SEEP A network element of SNPN A and the SEEP B network element of SNPN B respectively. In addition, in order to ensure that the user equipment can access the PLMN network before accessing the SNPN, the base station signal of the networking PLMN can cover all SNPNs in the SNPN networking system. In the case that the PLMN signal can cover the network of the SNPN, whether the signals between the SNPNs overlap or not is not required, such as Figure 2 shown.
[0094] The data interaction method of the SNPN networking system of this embodiment is a flowchart of the user equipment interacting with the SNPN through the PLMN. Figure 3 As shown, the following steps are included.
[0095] S301. Initiate a registration request to a target SNPN through a first PDU session, and establish a second PDU session with the target SNPN.
[0096] Specifically, in step S301, the first PDU session is that the user equipment initiates a registration request to the networking PLMN and establishes a PDU session, and then initiates a registration request to the target SNPN based on the established PDU session to establish a PDU session with the target SNPN. The target SNPN is selected based on the signal quality between the user equipment and the SNPN networking system. Generally speaking, the SNPN with the best signal is selected for access. If the SNPN with the best signal cannot be accessed, other SNPNs with better signals are accessed.
[0097] S302: Perform data exchange with the target SNPN according to the first PDU session and the second PDU session.
[0098] Specifically, according to the established first PDU session and the second PDU session, a data transmission link is established between the user equipment and the data network of the PLMN and the data network of the target SNPN. Through the established data transmission link, the user equipment can exchange data with the target SNPN.
[0099] Optionally, in step S301, before initiating a registration request to the target SNPN, if the user device has currently established a PDU session with a SNPN in the networking system, and the target SNPN is a SNPN with a better signal, and the user device needs to switch to a SNPN with a better signal, deregistration is initiated in the current SNPN, the PDU session with the current SNPN is canceled, and then the user device registers to the new SNPN according to the above steps for data interaction.
[0100] Optionally, in step S301, establishing a second PDU session with the target SNPN is completed through a non-3GPP access method, specifically including: sending a first registration request to the networking PLMN, and establishing a first PDU session with the data network of the networking PLMN; establishing a connection with the non-3GPP access gateway of the target SNPN through the first PDU session; sending a second registration request to the non-3GPP access gateway of the target SNPN, and establishing a second PDU session with the data network of the target SNPN.
[0101] In the above steps, before establishing the first PDU session and the second PDU session, an authentication step is included. The authentication process of the networking PLMN includes: the user equipment initiates a registration request to the AMF of the PLMN, the AMF discovers the AUSF / UDM through the NRF, obtains the authentication and contract information of the user equipment through the UDM and subscribes, and accepts the registration request of the user equipment in the PLMN; then the user equipment initiates a request to establish a PDU session, and after the SMF in the PLMN accepts the first PDU session establishment request, it obtains the contract information of the user equipment, establishes the first PDU session, and sends the first PDU session information to the user equipment. The authentication process of the target SNPN includes: the user equipment initiates a registration request to the target SNPN, the SNPN discovers the AUSF / UDM in the PLMN through the NRF, and obtains the user's authentication information, so that the isolation between the SNPN and the PLMN can be maintained, and the information security characteristics in the SNPN can be maintained.
[0102] Optionally, in step S301, the process of establishing a PDU session with the target SNPN includes:
[0103] The user equipment is configured with the address or domain name of the N3IWF in each SNPN, and establishes a link with the N3IWF in the selected SNPN (target SNPN) through non-3GPP access. After the above authentication process, the user equipment will generate an N3IWF key, and create an IPsec SA link with the key and N3IWF. The AMF in the SNPN obtains the user's contract information and subscribes, accepts the UE's registration request in the SNPN, and initiates a second PDU session establishment request to the SMF in the SNPN. After accepting the request, the SMF returns a response to the N3IWF to allocate the corresponding session resources, thereby establishing a second PDU session.
[0104] In order to better illustrate the above embodiment, a specific example is used for detailed description below.
[0105] The architecture reference of the SNPN networking system used in this example Figure 1 , PLMN and SNPN coverage reference Figure 2 , the same as the above embodiment.
[0106] In this example, the flowchart of the user equipment accessing the PLMN main network and the SNPN network is shown in Figure 1. Figure 4 In the PLMN and SNPN networking, the user UE first registers to the PLMN core network through the normal registration process, and then the UE collects the SNPN core network signals that can be received. Because the UE accesses the SNPN through non-3GPP access methods, the UE can collect various SNPN signals in the network according to the Wifi signal in the SNPN. After the UE searches for the SNPN information, it selects the domain name or address information of the N3IWF that it has already configured, and selects the SNPN with better signal for access. When the SEPPs of the PLMN and the selected SNPN have established N32 with each other, the PDN session and DN established by the UE in the PLMN can be connected to the N3IWF in the SNPN; the UE registers to the SNPN through the N3IWF, and the N3IWF establishes an IPsecChild SA for control plane signaling interaction to associate the PDU on the PLMN network with the PDU on the SNPN. Specifically, the following steps are included.
[0107] The UE user initially registers on the PLMN main network, and the PLMN main network establishes the user's PDU session after receiving the UE user's request.
[0108] Specifically, the UE first registers on the PLMN main network. The PLMN establishes a PDU session for the user based on the UE's authentication and establishes a transmission channel for data exchange with the DN in the PLMN main network. When the UE registers on the PLMN group network, it will initiate a registration request to the AMF through the base station. The AMF discovers the AUSF / UDM through the NRF, obtains the user's authentication and contract information through the UDM and subscribes to it, and accepts the UE's registration request in the PLMN. Subsequently, the UE initiates a request to establish a PDU session. After accepting the PDU session establishment request, the SMF in the PLMN obtains the UE's contract information, establishes a PDU session, and sends the PDU session information to the UE.
[0109] The UE establishes a connection with the N3IWF in the selected SNPN by means of non-3GPP access. Prior to this, the UE is configured with the addresses / domain names of the various N3IWFs.
[0110] The UE registers with the selected SNPN through N3IWF, and N3IWF establishes a link IPsecSA for control plane signaling interaction. The SNPN initiates a PDU session establishment request based on the UE through the IPsec SA.
[0111] In the above process, when the UE authenticates in SNPN, SNPN will discover AUSF / UDM in the PLMN network through NRF and obtain the user's authentication information, thereby maintaining the isolation between SNPN and PLMN and maintaining the information security characteristics in SNPN. In the process of UDM authentication in the PLMN network, the UE generates the N3IWF key, creates an IPsec SA link with the key and N3IWF, the AMF in SNPN obtains the user's contract information and subscribes, accepts the UE's registration request in SNPN, and initiates a PDU session establishment request to the SMF in SNPN. After receiving the request, the SMF returns a response to N3IWF to allocate the corresponding session resources.
[0112] N3IWF establishes IPsec Child SA for user data plane transmission between PLMN and SNPN for UE. That is, N3IWF will interact with AMF in SNPN according to local policies to establish IPsec Child SA link; after completion, N3IWF will also send a session establishment acceptance response to UE, and N3IWF will also send a PDU session response to the N2 interface of AMF in SNPN.
[0113] The UE exchanges data with the selected SNPN through the PDU session of the associated PLMN and the PDU session of the selected SNPN.
[0114] This example also provides a timing diagram of the user UE accessing the PLMN main network and the SNPN network, such as Figure 5As shown, the specific process is as follows.
[0115] The PLMN main network will establish an N32 connection with the SNPNi network under it through SEPPi. SEPP serves as a way for the UE to connect to the N3IWF of the SNPN to protect the security of the SNPN.
[0116] UE uses its capabilities to receive non-3GPP Access media within its range, such as Wifi signals, and by screening out SNPNs that are both connected to the PLMN and the SNPNs with the best signals, UE establishes a connection with the N3IWF on the SNPN through the PDU session and DN on the PLMN main network, and initiates a private network registration request to the selected SNPN. N3IWF selects AMFi in the SNPN through AMF selection to forward the UE's registration information.
[0117] After AMFi in SNPNi obtains the registration request information of the UE, it discovers the AUSF / UDM of the PLMN environment through the NRFi of the SNPN environment itself, obtains the request information of the UE user from the AUSF / UDM of the PLMN environment, and authenticates the UE user; AMF obtains the UE's subscription data from the UDM in the PLMN network.
[0118] During the authentication process, the N3IWF key is generated, an IPsec SA connection is established through the N3IWF key and N3IWF, and the UE's registration request to the SNPN is subscribed to and accepted; the above AMFi of SNPNi can successfully obtain the authentication information of the UE user of the PLMN environment UDM on the premise that: an N32 connection is established between the PLMN and the SEPP of the SNPNi environment, otherwise the authentication information of the corresponding UE will not be effectively passed to the AMFi of the SNPNi environment.
[0119] UE initiates a PDU session establishment request to AMFi of SNPNi through IPsec SA link. AMFi receives the UE's request to establish a PDU session, which includes SMFi accepting the PDU session request, obtaining the UE's contract data, creating related bearers in UPFi, and returning the PDU session request to the UE after completion.
[0120] AMFi sends an N2 PDU Session Request message to N3IWF, requesting the allocation of resources for PDU session access. N3IWF establishes an IPsec Child SA link based on the locally configured policies, configurations, and QoS policies, and sends an IKECreate Child SA Request message to the UE; the UE accepts the IPsec Child SA Request and replies with an IKE CreateChild SA Response. After the IPsec Child SA link is established, N3IWF forwards the PDU SessionEstablishment information to the UE through the link, and N3IWF sends an N2 Session Response to AMFi. The data interaction link between the UE and the DN information in SNPNi is completed.
[0121] The UE uplink path is: UE->RAN->UPF->DN->N3IWF->UPFi->DNi;
[0122] The UE downlink path is: DNi->UPFi->N3IWF->DN->UPF->RAN->UE.
[0123] In the present invention, the UE's access to the SNPN occurs under the premise of linking the PLMN with the corresponding SNPN through the N32 link. When the UE needs to switch to access a better SNPN, it can initiate a deregistration process through the N3IWF, deregister in the originally visited SNPN, and then register and access the selected SNPN through the above process. The deregistration process will not be repeated here.
[0124] Through the above steps, the effect of switching access in different SNPNs can be achieved.
[0125] In summary, the data interaction method of the SNPN networking system provided by the embodiment of the present invention is applied to the SNPN networking system, which is composed of multiple SNPNs and a networking PLMN. The base station signal of the networking PLMN can cover all SNPNs in the SNPN networking system, ensuring that the user equipment can access the PLMN network before accessing the SNPN. In the SNPN networking system, the SEPP network element in the PLMN establishes an N32 link with each SEPP network element in the SNPN to enhance the security of the contract information interaction of each user equipment in the main network, and to maintain the corresponding isolation, independence, security and other characteristics of the SNPN itself. Before accessing the target SNPN, the user equipment first registers with the PLMN and establishes a PDU session with the PLMN. Then, the SNPN signal that can be received is collected, and the SNPN to be accessed is selected according to the quality of the signal. After determining the SNPN to be accessed, a registration request is initiated to the target SNPN through the PDU session established with the PLMN, thereby establishing a PDU session with the target SNPN. Finally, data interaction can be performed with the target SNPN according to the PDU session established with the PLMN and the target SNPN. Taking the PLMN network as the main body, other SNPN networks can be added to the PLMN network as needed to form a PLMN-SNPN networking system. The addition and removal of SNPN are very flexible. In addition, when the user equipment needs to switch to other SNPNs, it only needs to deregister in the current SNPN, cancel the PDU session with the current SNPN, re-initiate a registration request to the SNPN that needs to be switched, establish a new PDU session, and then interact with the new SNPN based on the new PDU session. For switching between SNPNs, this method achieves the effect of switching between different SNPNs by, on the premise of accessing the PLMN network, the user selects a suitable SNPN, obtains the user's identity data in the PLMN for registration and deregistration processes; no manual switching is required, and communication quality can be guaranteed.
[0126] In the embodiments of the present application, a data interaction device of an SNPN networking system is also provided, which is used to implement the above embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware of a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.
[0127] The present application embodiment provides a data interaction device of an SNPN networking system, Figure 61 is a structural diagram of a data interaction device of an SNPN networking system provided in an embodiment of the present application, wherein the SNPN networking system includes multiple SNPNs and a networking PLMN, wherein the networking PLMN is connected to the multiple SNPNs through a SEPP network element, and a base station signal of the networking PLMN covers the multiple SNPNs; the device is executed by a user equipment, and the device includes:
[0128] The session establishment module 601 is used to initiate a registration request to a target SNPN through a first PDU session, and establish a second PDU session with the target SNPN; the first PDU session is established by the user equipment initiating a registration request to the networking PLMN; the target SNPN is selected based on the signal quality between the user equipment and the SNPN networking system;
[0129] The interaction module 602 is used to perform data interaction with the target SNPN according to the first PDU session and the second PDU session.
[0130] In an optional embodiment, the device further comprises:
[0131] The deregistration module 603 is used to initiate deregistration in the first SNPN and cancel the PDU session with the SNPN if a PDU session has been established with the first SNPN; the first SNPN is a SNPN other than the target SNPN in the SNPN networking system.
[0132] In an optional implementation, the session establishing module 601 is specifically configured to:
[0133] Sending a first registration request to the networking PLMN, and establishing a first PDU session with a data network of the networking PLMN;
[0134] Establishing a connection with the non-3GPP access gateway of the target SNPN through the first PDU session;
[0135] A second registration request is sent to the non-3GPP access gateway of the target SNPN, and a second PDU session is established with the data network of the target SNPN.
[0136] In an optional implementation, the session establishing module 601 is further configured to:
[0137] Sending an authentication request to the access and mobility management function module of the network PLMN; the access and mobility management function module performs a legitimacy check on the user equipment according to the user ID information indicated in the authentication request, and generates a first verification result;
[0138] Receive the first verification result sent by the access and mobility management function module of the networking PLMN.
[0139] In an optional implementation, the session establishing module 601 is further configured to:
[0140] Obtain the IP information of the non-3GPP access gateway of the target SNPN;
[0141] Based on the IP information, a connection is established with the non-3GPP access gateway of the target SNPN through a non-3GPP access method.
[0142] In an optional implementation, the interaction module 602 is specifically configured to:
[0143] Establishing a data transmission link between the user equipment, the data network of the networking PLMN, and the data network of the target SNPN according to the first PDU session and the second PDU session;
[0144] According to the data transmission link, data interaction is performed with the data network of the target SNPN.
[0145] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0146] The data interaction device of the SNPN networking system in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0147] The embodiment of the present invention also provides a computer device having the above Figure 6 The data interaction device of the SNPN networking system shown.
[0148] See also Figure 7 , Figure 7 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 7As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in or on the memory to display graphic information in a graphical user interface on an external input / output device (such as a display device coupled to an interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 7 A processor 10 is taken as an example.
[0149] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0150] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.
[0151] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0152] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0153] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 7 The example of connecting through bus is taken in the following.
[0154] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0155] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.
[0156] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A data interaction method for a SNPN networking system, characterized in that: The SNPN networking system includes multiple SNPNs and a networking PLMN, the networking PLMN is connected to the multiple SNPNs through a SEPP network element, and the base station signal of the networking PLMN covers the multiple SNPNs; The method is performed by a user equipment, and the method includes: Initiate a registration request to the target SNPN through the first PDU session, and establish a second PDU session with the target SNPN; the first PDU session is established by the user equipment initiating a registration request to the networking PLMN; the target SNPN is selected based on the signal quality between the user equipment and the SNPN networking system; Data is exchanged with the target SNPN according to the first PDU session and the second PDU session.
2. The method according to claim 1, characterized in that Before the step of initiating a registration request to the target SNPN through the first PDU session, the method further includes: If a PDU session has been established with the first SNPN, deregistration is initiated in the first SNPN to cancel the PDU session with the SNPN; the first SNPN is an SNPN other than the target SNPN in the SNPN networking system.
3. The method according to claim 2, characterized in that The initiating a registration request to the target SNPN through the first PDU session and establishing a second PDU session with the target SNPN includes: Sending a first registration request to the networking PLMN, and establishing a first PDU session with a data network of the networking PLMN; Establishing a connection with the non-3GPP access gateway of the target SNPN through the first PDU session; A second registration request is sent to the non-3GPP access gateway of the target SNPN, and a second PDU session is established with the data network of the target SNPN.
4. The method according to claim 3, characterized in that Before establishing the first PDU session with the data network of the networking PLMN, the method further includes: Sending an authentication request to the access and mobility management function module of the networking PLMN; the access and mobility management function module performs a legitimacy check on the user equipment according to the user ID information indicated in the authentication request, and generates a first verification result; Receive the first verification result sent by the access and mobility management function module of the networking PLMN.
5. The method according to claim 3, characterized in that: The establishing a connection with the non-3GPP access gateway of the target SNPN through the first PDU session includes: Obtaining IP information of the non-3GPP access gateway of the target SNPN; Based on the IP information, a connection is established with the non-3GPP access gateway of the target SNPN through a non-3GPP access method.
6. The method according to claim 3, characterized in that: The performing data interaction with the target SNPN according to the first PDU session and the second PDU session includes: Establishing a data transmission link between the user equipment, the data network of the networking PLMN, and the data network of the target SNPN according to the first PDU session and the second PDU session; According to the data transmission link, data interaction is performed with the data network of the target SNPN.
7. A data interaction device for a SNPN networking system, characterized in that: The SNPN networking system includes multiple SNPNs and a networking PLMN, the networking PLMN is connected to the multiple SNPNs through a SEPP network element, and the base station signal of the networking PLMN covers the multiple SNPNs; The device is executed by a user equipment, and the device includes: A session establishment module, configured to initiate a registration request to a target SNPN through a first PDU session, and establish a second PDU session with the target SNPN; the first PDU session is established by the user equipment initiating a registration request to the networking PLMN; the target SNPN is selected based on the signal quality between the user equipment and the SNPN networking system; An interaction module is used to interact data with the target SNPN according to the first PDU session and the second PDU session.
8. The device according to claim 7, characterized in that The device also includes: A deregistration module is used to initiate deregistration in a first SNPN and cancel the PDU session with the first SNPN if a PDU session has been established with the first SNPN; the first SNPN is a SNPN other than the target SNPN in the SNPN networking system.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the data interaction method of the SNPN networking system according to any one of claims 1 to 6 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the data interaction method of the SNPN networking system according to any one of claims 1 to 6.