Session clearing method and device

By implementing the session clearing method of session management nodes in the mobile communication core network, the security and performance problems caused by the failure to release IP resources in a timely manner are solved, and the security and performance of the network are improved.

CN120034991APending Publication Date: 2025-05-23XINYANG BRANCH HENAN CO LTD OF CHINA MOBILE COMM CORP +1
0 Cites 0 Cited by

Patent Information

Application Number
CN202510194817.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the existing mobile communication core network, the IP resources released by the session management nodes are not sensed by the firewall in time, resulting in the old terminal's session still exist in the firewall, causing unauthorized service flow, abnormal billing and security risks.

Method used

A session clearing method is proposed. After monitoring the terminal to delete a session with an external data network, the session management node releases the relevant resources of the target IP, and sends data packets to the target boundary node or generates instructions through the IP resource management function node to instruct the target boundary node to release resources related to the target IP.

Benefits of technology

By timely releasing resources related to the target IP, network congestion and resource leakage are avoided, network performance and security are improved, and network attack risks and abnormal billing problems are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034991A_ABST
    Figure CN120034991A_ABST
Patent Text Reader

Abstract

The invention provides a session clearing method and device, and relates to the technical field of communication, and the method comprises the steps: releasing related resources of a target IP corresponding to a terminal in a session management node after monitoring that the terminal deletes a session with an external data network; sending a data packet to the target boundary node, wherein the data packet is used for indicating the target boundary node to release resources related to the target IP; or, a first instruction is generated based on the target IP and sent to the IP resource management function node, the IP resource management function node is used for generating a second instruction based on the first instruction and sending the second instruction to the target boundary node, and the second instruction is used for indicating the target boundary node to release resources related to the target IP; wherein the target boundary node at least comprises a firewall through which the terminal passes during the session with the external data network. According to the method and the device, the resource related to the target IP is released in time, so that the problem of network congestion or resource leakage caused by the fact that the resource is not released in time is avoided, and the performance and the security of the whole network are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a session clearing method and device thereof. Background Art

[0002] In the existing mobile communication core network, the firewall (Fire Wall, FW) is usually deployed between the core network and the external data network (Data Network, DN), assuming the functions of network address translation (Network Address Translation, NAT) and security control. The firewall protects core network users from unauthorized access and malicious attacks by monitoring network traffic and executing access control policies. In particular, when the terminal uses a private IP address to communicate with the Internet, the firewall will map the private address to a public address through NAT conversion, ensuring the security of the internal network and hiding the true identity of the terminal.

[0003] However, there are significant problems in the prior art. The session management nodes in the mobile core network, such as the Packet Gateway (PGW), Session Management Function (SMF), and User plane function (UPF), are responsible for the allocation and management of user IP sessions. When the user session is released, the IP resources released by the session management node may be allocated to other terminals, but the firewall cannot perceive the release of the session in time. Due to this defect, the IP address released by the session management node may be reallocated to the new terminal device, while the session of the old terminal still exists in the firewall. This leads to the following problems: the new terminal may receive a large number of unauthorized business flows, especially User Datagram Protocol (UDP) data flows, resulting in abnormal billing; at the same time, malicious data flows may attack the new terminal through the firewall, causing security risks; in addition, illegal external data network servers may take advantage of this vulnerability to occupy firewall resources, further leading to security vulnerabilities and resource waste in the core network. Summary of the invention

[0004] The present application aims to solve one of the technical problems in the related art at least to some extent.

[0005] To this end, one purpose of the present application is to propose a session clearing method, which is executed by a session management node, including: after monitoring that the terminal deletes the session with the external data network, releasing the relevant resources of the target IP corresponding to the terminal in the session management node; sending a data packet to the target border node, the data packet is used to instruct the target border node to release the resources related to the target IP; or, generating a first instruction based on the target IP and sending it to the IP resource management function node, wherein the IP resource management function node is used to generate a second instruction based on the first instruction and send the second instruction to the target border node, the second instruction is used to instruct the target border node to release the resources related to the target IP; wherein the target border node includes at least a firewall passed by the terminal when having a session with the external data network.

[0006] The second objective of this application is to propose a session clearing method.

[0007] The third objective of the present application is to provide a session clearing device.

[0008] The fourth objective of the present application is to provide a session clearing device.

[0009] A fifth objective of the present application is to provide an electronic device.

[0010] A sixth object of the present application is to provide a non-transitory computer-readable storage medium.

[0011] A seventh object of the present application is to provide a computer program product.

[0012] To achieve the above-mentioned purpose, the first aspect embodiment of the present application proposes a session clearing method, which is characterized in that it is executed by a session management node, including: after monitoring that the terminal deletes the session with the external data network, releasing the relevant resources of the target IP corresponding to the terminal in the session management node; sending a data packet to the target border node, the data packet is used to instruct the target border node to release the resources related to the target IP; or, generating a first instruction based on the target IP and sending it to the IP resource management function node, wherein the IP resource management function node is used to generate a second instruction based on the first instruction and send the second instruction to the target border node, the second instruction is used to instruct the target border node to release the resources related to the target IP; wherein the target border node includes at least a firewall passed by the terminal when having a session with the external data network.

[0013] According to one embodiment of the present application, sending a data packet to a target border node includes: determining a first mapping relationship between a first candidate IP stored by a session management node and a first candidate border node, and obtaining the target border node by querying the first mapping relationship based on the target IP; and sending a first data packet to the target border node using the target IP.

[0014] According to one embodiment of the present application, sending a data packet to a target border node includes: determining a first mapping relationship between a first candidate IP stored by a session management node and a first candidate border node, and obtaining the target border node by querying the first mapping relationship based on the target IP; and sending a second data packet to the target border node, wherein the second data packet carries the target IP.

[0015] According to one embodiment of the present application, the IP resource management function node stores a second mapping relationship between a second candidate IP and a second candidate boundary node, and the process in which the IP resource management function node generates a second instruction based on the first instruction and sends the second instruction to the target boundary node includes: the IP resource management function node receives the first instruction sent by the session management node and parses it to obtain the target IP carried by the first instruction; the IP resource management function node queries the second mapping relationship based on the target IP to obtain the target boundary node; the IP resource management function node generates a second instruction based on the target IP and sends it to the target boundary node.

[0016] According to one embodiment of the present application, both the session management node and the target border node are configured with an IP address management interface.

[0017] To achieve the above-mentioned purpose, the second aspect embodiment of the present application proposes a session clearing method, which is executed by the target boundary node, including: receiving a data packet sent by the session management node, determining the target IP based on the data packet, and releasing the resources related to the target IP; or, receiving a second instruction sent by the IP resource management function node, parsing the second instruction to obtain the target IP and releasing the resources related to the target IP.

[0018] According to one embodiment of the present application, a data packet sent by a session management node is received, and a target IP is determined based on the data packet, including: receiving a first data packet sent by the session management node, wherein the first data packet is sent by the session management node using a target IP corresponding to the terminal after monitoring that the terminal deletes a session with an external data network; identifying the IP source of the first data packet to obtain the target IP.

[0019] According to one embodiment of the present application, a data packet sent by a session management node is received, and a target IP is determined based on the data packet, including: receiving a second data packet sent by the session management node, wherein the second data packet is sent by the session management node after monitoring that the terminal deletes the session with the external data network, and the second data packet carries the target IP corresponding to the terminal; parsing the second data packet to obtain the target IP carried by the second data packet.

[0020] According to one embodiment of the present application, the IP resource management function node stores a second mapping relationship between a second candidate IP and a second candidate boundary node, and the process of the IP resource management function node generating a second instruction includes: the IP resource management function node receives and parses the first instruction sent by the session management node to obtain the target IP carried by the first instruction; the IP resource management function node queries the second mapping relationship based on the target IP to obtain the target boundary node; the IP resource management function node generates a second instruction based on the target IP and sends it to the target boundary node.

[0021] To achieve the above-mentioned purpose, the third aspect embodiment of the present application proposes a session clearing device, including: a monitoring module, which is used to release the relevant resources of the target IP corresponding to the terminal in the session management node after monitoring that the terminal deletes the session with the external data network; a sending module, which is used to send a data packet to the target boundary node, and the data packet is used to instruct the target boundary node to release the resources related to the target IP; or, generate a first instruction based on the target IP and send it to the IP resource management function node, wherein the IP resource management function node is used to generate a second instruction based on the first instruction and send the second instruction to the target boundary node, and the second instruction is used to instruct the target boundary node to release the resources related to the target IP; wherein the target boundary node includes at least a firewall passed by the terminal when having a session with the external data network.

[0022] According to one embodiment of the present application, a sending module is used to: determine a first mapping relationship between a first candidate IP stored in a session management node and a first candidate boundary node, and obtain a target boundary node by querying the first mapping relationship based on a target IP; and send a first data packet to the target boundary node using the target IP.

[0023] According to one embodiment of the present application, a sending module is used to: determine a first mapping relationship between a first candidate IP stored in a session management node and a first candidate boundary node, and obtain a target boundary node by querying the first mapping relationship based on a target IP; and send a second data packet to the target boundary node, wherein the second data packet carries the target IP.

[0024] According to one embodiment of the present application, the IP resource management function node stores a second mapping relationship between a second candidate IP and a second candidate boundary node, and the process in which the IP resource management function node generates a second instruction based on the first instruction and sends the second instruction to the target boundary node includes: the IP resource management function node receives the first instruction sent by the session management node and parses it to obtain the target IP carried by the first instruction; the IP resource management function node queries the second mapping relationship based on the target IP to obtain the target boundary node; the IP resource management function node generates a second instruction based on the target IP and sends it to the target boundary node.

[0025] According to one embodiment of the present application, both the session management node and the target border node are configured with an IP address management interface.

[0026] To achieve the above-mentioned purpose, the fourth aspect embodiment of the present application proposes a session clearing device, including: a receiving module, used to receive a data packet sent by a session management node or receive a second instruction sent by an IP resource management function node; an execution module, used to determine the target IP according to the data packet and release the resources related to the target IP; or, used to parse the second instruction to obtain the target IP and release the resources related to the target IP.

[0027] According to one embodiment of the present application, a receiving module is used to: receive a first data packet sent by a session management node, wherein the first data packet is sent by the session management node using a target IP corresponding to the terminal after monitoring that the terminal deletes a session with an external data network, and an execution module is used to: identify the IP source of the first data packet and obtain the target IP.

[0028] According to one embodiment of the present application, a receiving module is used to: receive a second data packet sent by a session management node, wherein the second data packet is sent by the session management node after monitoring that the terminal deletes the session with the external data network, and the second data packet carries a target IP corresponding to the terminal; and an execution module is used to: parse the second data packet to obtain the target IP carried by the second data packet.

[0029] According to one embodiment of the present application, the IP resource management function node stores a second mapping relationship between a second candidate IP and a second candidate boundary node, and the process of the IP resource management function node generating a second instruction includes: the IP resource management function node receives and parses the first instruction sent by the session management node to obtain the target IP carried by the first instruction; the IP resource management function node queries the second mapping relationship based on the target IP to obtain the target boundary node; the IP resource management function node generates a second instruction based on the target IP and sends it to the target boundary node.

[0030] To achieve the above-mentioned purpose, the fifth aspect embodiment of the present application proposes an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to implement the session clearing method as described in the first aspect embodiment or the second aspect embodiment of the present application.

[0031] To achieve the above-mentioned purpose, the sixth aspect embodiment of the present application proposes a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to implement the session clearing method as described in the first aspect embodiment or the second aspect embodiment of the present application.

[0032] To achieve the above-mentioned purpose, the seventh aspect embodiment of the present application proposes a computer program product, including a computer program, which, when executed by a processor, implements the session clearing method as described in the first aspect embodiment or the second aspect embodiment of the present application.

[0033] The present application achieves at least the following beneficial effects: the present application avoids network congestion or resource leakage caused by failure to release resources in a timely manner by releasing resources related to the target IP, thereby helping to improve the performance and security of the entire network, especially when the terminal no longer needs the service, by clearing resources, the potential risk of network attacks can be reduced; thereby protecting the mobile core network and terminal users from abnormal downlink traffic attacks or illegal resource occupation, while also protecting mobile network users from abnormal billing problems, thereby enhancing the security of the mobile communication network. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0035] Figure 1 It is a schematic diagram of an exemplary implementation of a session clearing method shown in an embodiment of the present application.

[0036] Figure 2 It is an interactive schematic diagram of an exemplary implementation of a session clearing method shown in an embodiment of the present application.

[0037] Figure 3 It is an interactive schematic diagram of an exemplary implementation of a session clearing method shown in an embodiment of the present application.

[0038] Figure 4 It is an interactive schematic diagram of an exemplary implementation of a session clearing method shown in an embodiment of the present application.

[0039] Figure 5 It is a schematic diagram of a session clearing method shown in an embodiment of the present application.

[0040] Figure 6 It is a schematic diagram of a session clearing device shown in an embodiment of the present application.

[0041] Figure 7 It is a schematic diagram of a session clearing device shown in an embodiment of the present application.

[0042] Figure 8It is a schematic diagram of an electronic device shown in one embodiment of the present application. DETAILED DESCRIPTION

[0043] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0044] The following is an introduction to the terms involved in this application:

[0045] 1. Session management node: Session management node refers to the network element responsible for signaling interaction with user equipment (UE) in the Evolved Packet Core (EPC) / 5G Core (5GC) network architecture, usually including PGW and SMF / UPF, etc. They are directly involved in the establishment, maintenance and release of user IP sessions. The main function of the session management node is to manage and control the life cycle of user data flows, including allocating IP addresses to users, performing traffic monitoring, session state management, etc., to ensure that users can stably communicate data in the mobile network.

[0046] 2. Border nodes: Border nodes are usually located at the edge of the network and are responsible for data transmission between the core network or IoT network and the external environment. They are located between the PGW and SMF (UPF) network elements and the service servers, and assume functions such as firewall (FW), IoT border router, and policy management equipment. The main responsibilities of the border nodes include processing user IP-related service routing, NAT conversion, and security policy execution. Through these nodes, the network can effectively control the inflow and outflow of external traffic, ensure data security, and support traffic scheduling and management of different services.

[0047] Figure 1 is a schematic diagram of an exemplary implementation of a session clearing method shown in the present application, such as Figure 1 As shown, the session clearing method, executed by the session management node, includes the following steps:

[0048] S101, after monitoring that a terminal deletes a session with an external data network, releasing relevant resources of a target IP corresponding to the terminal in a session management node.

[0049] When a user starts to use an external data network, the user terminal completes session establishment by performing signaling interaction with the session management node and obtains an Internet Protocol Address (IP address) from the session management node.

[0050] After obtaining the IP address, the user terminal can communicate with the external network through the firewall or other boundary network nodes.

[0051] When the terminal no longer needs network services, it will interact with the session management node through signaling, triggering the session deletion process. During this process, the session management node will delete the user session and release the user's assigned IP address so that it can be reassigned to other users later.

[0052] In this application, the IP address assigned to the terminal by the session management node is used as the target IP corresponding to the terminal when conducting a session with an external data network. The target IP can also be understood as the private network address assigned to the terminal by the session management node.

[0053] S102, sending a data packet to a target border node, where the data packet is used to instruct the target border node to release resources related to the target IP.

[0054] After the terminal deletes the session with the external data network, the session management node sends a data packet to the target border node, which is used to instruct the target border node to release resources related to the target IP so that the target border node can also know the session deletion and release resources related to the target IP.

[0055] Among them, the resources related to the target IP released by the target border node include at least target IP NAT related resources, target IP service dynamic session resources, target IP other security class UE direction triggered related resources, and other dynamically allocated resources related to the target IP.

[0056] The target border node refers to the border node involved in the conversation between the terminal and the external data network, and at least includes the firewall passed by the terminal when the conversation between the terminal and the external data network occurs.

[0057] S103, generate a first instruction based on the target IP and send it to the IP resource management function node, wherein the IP resource management function node is used to generate a second instruction based on the first instruction and send the second instruction to the target boundary node, and the second instruction is used to instruct the target boundary node to release resources related to the target IP.

[0058] Among them, the IP resource management function node is an intermediate node between the session management node and the target boundary node. The session management node generates a first instruction based on the target IP and sends it to the IP resource management function node. The first instruction carries the target IP. The IP resource management function node parses the received first instruction to obtain the target IP, and determines the target boundary node corresponding to the target IP, and then generates a second instruction based on the target IP and sends it to the target boundary node. The target boundary node parses the received second instruction to obtain the target IP, and releases the resources related to the target IP.

[0059] Among them, the resources related to the target IP released by the target border node include at least target IP NAT related resources, target IP service dynamic session resources, target IP other security class UE direction triggered related resources, and other dynamically allocated resources related to the target IP.

[0060] The target border node refers to the border node involved in the conversation between the terminal and the external data network, and at least includes the firewall passed by the terminal when the conversation between the terminal and the external data network occurs.

[0061] Among them, after executing S101, the above S102 and S103 are two parallel solutions for realizing session clearing, and S102 or S103 can be selected to be executed according to the actual design.

[0062] S102 is a direct implementation method, which introduces that the session management node directly sends a data packet to the target border node to instruct the target border node to release resources related to the target IP.

[0063] S103 is an indirect implementation method, which introduces using an IP resource management function node as an intermediate node to receive a first instruction sent by a session management node and generate a second instruction to send to a target border node, thereby instructing the target border node to release resources related to the target IP.

[0064] The embodiments of the present application avoid network congestion or resource leakage caused by failure to release resources in a timely manner by releasing resources related to the target IP, which helps to improve the performance and security of the entire network. In particular, when the terminal no longer needs the service, the potential risk of network attack can be reduced by clearing resources. The mobile core network and terminal users are protected from abnormal downlink traffic attacks or illegal resource occupation, while also protecting mobile network users from abnormal billing problems, thereby enhancing the security of the mobile communication network.

[0065] Figure 2 is an interactive schematic diagram of an exemplary implementation of a session clearing method shown in the present application, such as Figure 2 As shown, the session clearing method includes the following steps:

[0066] S201, after monitoring that a terminal deletes a session with an external data network, the session management node releases the related resources of the target IP corresponding to the terminal in the session management node.

[0067] Regarding step S201, please refer to the detailed description of the relevant parts in the above embodiment, which will not be repeated here.

[0068] S202: The session management node determines a first mapping relationship between a first candidate IP and a first candidate boundary node stored in the session management node, and queries the first mapping relationship based on the target IP to obtain a target boundary node.

[0069] In the present application, a first mapping relationship between a first candidate IP and a first candidate boundary node may be pre-configured in the session management node, and the session management node queries the first mapping relationship based on the above-determined target IP to obtain the target boundary node.

[0070] The target border node refers to the border node involved in the conversation between the terminal and the external data network, and at least includes the firewall passed by the terminal when the conversation between the terminal and the external data network occurs.

[0071] S203: The session management node sends a first data packet to the target border node using the target IP.

[0072] The session management node may directly use the target IP to send the first data packet to the target border node, such as a simple ICMP message.

[0073] S204: The target border node receives a first data packet sent by the session management node.

[0074] It can be seen from the above that the first data packet is sent by the session management node using the target IP corresponding to the terminal after monitoring that the terminal deletes the session with the external data network.

[0075] S205, the target border node identifies the IP source of the first data packet and obtains the target IP.

[0076] S206: The target border node releases resources related to the target IP.

[0077] Among them, the resources related to the target IP released by the target border node include at least target IP NAT related resources, target IP service dynamic session resources, target IP other security class UE direction triggered related resources, and other dynamically allocated resources related to the target IP.

[0078] Furthermore, both the session management node and the target border node can be configured with an IP address management interface. The IP address management interface configured in the session management node is used to directly send the first data packet to the target border node, and the IP address management interface configured in the target border node is used to receive the first data packet sent by the session management node.

[0079] Optionally, the IP address management interface can be implemented using protocols such as the Simple Network Management Protocol (SNMP), the Hypertext Transfer Protocol (HTTP), the Representational State Transfer (RESTful), the System Logging Protocol (Syslog), etc. This solution includes but is not limited to the use of these upper-layer protocols.

[0080] The embodiment of the present application introduces a direct implementation scheme of sending a first data packet directly to a target border node through a session management node so that the target border node can identify the IP source of the first data packet to obtain the target IP, thereby releasing resources related to the target IP. The logical process is simple and easy to implement. By releasing the resources related to the target IP in a timely manner, network congestion or resource leakage caused by untimely release of resources is avoided, which helps to improve the performance and security of the entire network. In particular, when the terminal no longer needs the service, the potential risk of network attacks can be reduced by clearing resources.

[0081] Figure 3 is an interactive schematic diagram of an exemplary implementation of a session clearing method shown in the present application, such as Figure 3 As shown, the session clearing method includes the following steps:

[0082] S301, after monitoring that a terminal deletes a session with an external data network, the session management node releases the related resources of the target IP corresponding to the terminal in the session management node.

[0083] Regarding step S301, please refer to the detailed description of the relevant parts in the above embodiment, which will not be repeated here.

[0084] S302: The session management node determines a first mapping relationship between a first candidate IP and a first candidate boundary node stored in the session management node, and queries the first mapping relationship based on the target IP to obtain a target boundary node.

[0085] In the present application, a first mapping relationship between a first candidate IP and a first candidate boundary node may be pre-configured in the session management node, and the session management node queries the first mapping relationship based on the above-determined target IP to obtain the target boundary node.

[0086] The target border node refers to the border node involved in the conversation between the terminal and the external data network, and at least includes the firewall passed by the terminal when the conversation between the terminal and the external data network occurs.

[0087] S303: The session management node sends a second data packet to the target border node, wherein the second data packet carries the target IP address.

[0088] Optionally, the second data packet may be an HTTP packet.

[0089] S304: The target border node receives a second data packet sent by the session management node.

[0090] It can be seen from the above that the second data packet is sent by the session management node after monitoring that the terminal deletes the session with the external data network, and the second data packet carries the target IP corresponding to the terminal.

[0091] S305: The target border node parses the second data packet to obtain the target IP carried by the second data packet.

[0092] S306: The target border node releases resources related to the target IP.

[0093] Among them, the resources related to the target IP released by the target border node include at least target IP NAT related resources, target IP service dynamic session resources, target IP other security class UE direction triggered related resources, and other dynamically allocated resources related to the target IP.

[0094] Furthermore, both the session management node and the target border node can be configured with an IP address management interface. The IP address management interface configured in the session management node is used to directly send the second data packet to the target border node, and the IP address management interface configured in the target border node is used to receive the second data packet sent by the session management node.

[0095] Optionally, the IP address management interface may be implemented using SNMP protocol, HTTP protocol, RESTful protocol, Syslog protocol, etc. This solution includes but is not limited to using these upper layer protocols.

[0096] The embodiment of the present application introduces a direct implementation scheme of sending a second data packet directly to a target border node through a session management node so that the target border node can identify the IP carried by the second data packet to obtain the target IP, thereby releasing resources related to the target IP. By timely releasing the resources related to the target IP, network congestion or resource leakage problems caused by untimely release of resources are avoided, which helps to improve the performance and security of the entire network. In particular, when the terminal no longer needs the service, the potential risk of network attacks can be reduced by clearing resources.

[0097] Figure 4 is an interactive schematic diagram of an exemplary implementation of a session clearing method shown in the present application, such as Figure 4 As shown, the session clearing method includes the following steps:

[0098] S401, after monitoring that a terminal deletes a session with an external data network, the session management node releases the related resources of the target IP corresponding to the terminal in the session management node.

[0099] Regarding step S401, please refer to the detailed description of the relevant parts in the above embodiment, which will not be repeated here.

[0100] S402: The session management node generates a first instruction based on the target IP and sends it to the IP resource management function node.

[0101] The first instruction carries the target IP.

[0102] S403: The IP resource management function node receives and parses the first instruction sent by the session management node to obtain a target IP carried by the first instruction.

[0103] S404: The IP resource management function node queries the second mapping relationship based on the target IP to obtain a target boundary node.

[0104] The IP resource management function node pre-stores a second mapping relationship between the second candidate IP and the second candidate boundary node.

[0105] The second mapping relationship may be configured in the IP resource management function node in the following three ways.

[0106] 1. Dynamic configuration: after the terminal establishes a session with the external data network through the target border node, the target border node can report the terminal IP and the target border node identifier corresponding to the session to the IP resource management function node, so that the IP resource management function node can establish the second mapping relationship.

[0107] 2. Dynamic configuration: After the terminal establishes a session with the external data network through the target border node, the terminal IP and target border node identifier corresponding to the session can be reported to the IP resource management function node through the session management node, so that the IP resource management function node can establish a second mapping relationship.

[0108] 3. Static configuration: manually configure the second mapping relationship directly on the IP resource management function node.

[0109] S405: The IP resource management function node generates a second instruction based on the target IP and sends the second instruction to the target boundary node.

[0110] S406: The target border node receives the second instruction sent by the IP resource management function node, parses the second instruction to obtain the target IP, and releases resources related to the target IP.

[0111] Among them, the resources related to the target IP released by the target border node include at least target IP NAT related resources, target IP service dynamic session resources, target IP other security class UE direction triggered related resources, and other dynamically allocated resources related to the target IP.

[0112] Furthermore, both the session management node and the target border node can be configured with an IP address management interface. The IP address management interface configured with the session management node is used to send a first instruction to the IP resource management function node, and the IP address management interface configured with the target border node is used to receive a second instruction sent by the IP resource management function node.

[0113] Optionally, the IP address management interface may be implemented using SNMP protocol, HTTP protocol, RESTful protocol, Syslog protocol, etc. This solution includes but is not limited to using these upper layer protocols.

[0114] The embodiment of the present application uses an IP resource management function node as an intermediate node to receive a first instruction sent by a session management node and generate a second instruction to send to a target border node, thereby instructing the target border node to release resources related to the target IP. By releasing resources related to the target IP in a timely manner, network congestion or resource leakage problems caused by untimely release of resources are avoided, which helps to improve the performance and security of the entire network. In particular, when the terminal no longer needs the service, the potential risk of network attacks can be reduced by clearing resources.

[0115] Figure 5 is a schematic diagram of a session clearing method shown in this application, such as Figure 5 As shown, the session clearing method, executed by the target border node, includes the following steps:

[0116] S501, receiving a data packet sent by a session management node, determining a target IP according to the data packet, or receiving a second instruction sent by an IP resource management function node, parsing the second instruction to obtain the target IP.

[0117] Among them, the two methods introduced in S501 correspond to the direct method and the indirect method introduced in the above embodiments respectively, and can be understood by referring to the detailed introduction in the above embodiments, and will not be described in detail here.

[0118] S502: Release resources related to the target IP.

[0119] The embodiment of the present application timely releases the resources related to the target IP through the IP resource management function node, thereby avoiding network congestion or resource leakage caused by the failure to release resources in time, and helping to improve the performance and security of the entire network. In particular, when the terminal no longer needs the service, the potential risk of network attacks can be reduced by clearing resources.

[0120] Figure 6 is a schematic diagram of a session clearing device shown in the present application, such as Figure 6 As shown, the session clearing device 600 includes a monitoring module 601 and a sending module 602, wherein:

[0121] The monitoring module 601 is used to release the related resources of the target IP corresponding to the terminal in the session management node after monitoring that the terminal deletes the session with the external data network.

[0122] The sending module 602 is used to send a data packet to the target border node, and the data packet is used to instruct the target border node to release resources related to the target IP; or, generate a first instruction based on the target IP and send it to the IP resource management function node, wherein the IP resource management function node is used to generate a second instruction based on the first instruction and send the second instruction to the target border node, and the second instruction is used to instruct the target border node to release resources related to the target IP.

[0123] The target border node at least includes a firewall that the terminal passes through when communicating with an external data network.

[0124] This device avoids network congestion or resource leakage caused by untimely release of resources by releasing resources related to the target IP in a timely manner, which helps to improve the performance and security of the entire network. In particular, when the terminal no longer needs the service, the potential risk of network attacks can be reduced by clearing resources.

[0125] Furthermore, the sending module 602 is used to: determine a first mapping relationship between a first candidate IP stored in the session management node and a first candidate border node, and obtain a target border node by querying the first mapping relationship based on the target IP; and send a first data packet to the target border node using the target IP.

[0126] Furthermore, the sending module 602 is used to: determine a first mapping relationship between a first candidate IP stored in the session management node and a first candidate border node, and obtain a target border node by querying the first mapping relationship based on the target IP; and send a second data packet to the target border node, wherein the second data packet carries the target IP.

[0127] Furthermore, the IP resource management function node introduced in the sending module 602 stores a second mapping relationship between a second candidate IP and a second candidate boundary node. The process in which the IP resource management function node generates a second instruction based on the first instruction and sends the second instruction to the target boundary node includes: the IP resource management function node receives the first instruction sent by the session management node and parses it to obtain the target IP carried by the first instruction; the IP resource management function node queries the second mapping relationship based on the target IP to obtain the target boundary node; the IP resource management function node generates a second instruction based on the target IP and sends it to the target boundary node.

[0128] Furthermore, both the session management node and the target border node are configured with an IP address management interface.

[0129] Figure 7 is a schematic diagram of a session clearing device shown in the present application, such as Figure 7 As shown, the session clearing device 700 includes a receiving module 701 and an execution module 702, wherein:

[0130] The receiving module 701 is used to receive a data packet sent by a session management node or a second instruction sent by an IP resource management function node.

[0131] The execution module 702 is used to determine the target IP according to the data packet and release the resources related to the target IP; or, to parse the second instruction to obtain the target IP and release the resources related to the target IP.

[0132] This device avoids network congestion or resource leakage caused by untimely release of resources by releasing resources related to the target IP in a timely manner, which helps to improve the performance and security of the entire network. In particular, when the terminal no longer needs the service, the potential risk of network attacks can be reduced by clearing resources.

[0133] Furthermore, the receiving module 701 is used to: receive a first data packet sent by a session management node, wherein the first data packet is sent by the session management node using a target IP corresponding to the terminal after monitoring that the terminal deletes the session with the external data network, and the execution module 702 is used to: identify the IP source of the first data packet and obtain the target IP.

[0134] Furthermore, the receiving module 701 is used to: receive a second data packet sent by the session management node, wherein the second data packet is sent by the session management node after monitoring that the terminal deletes the session with the external data network, and the second data packet carries the target IP corresponding to the terminal; the execution module 702 is used to: parse the second data packet to obtain the target IP carried by the second data packet.

[0135] Furthermore, the IP resource management function node involved in the receiving module 701 stores a second mapping relationship between the second candidate IP and the second candidate boundary node. The process of the IP resource management function node generating a second instruction includes: the IP resource management function node receives the first instruction sent by the session management node and parses it to obtain the target IP carried by the first instruction; the IP resource management function node queries the second mapping relationship based on the target IP to obtain the target boundary node; the IP resource management function node generates a second instruction based on the target IP and sends it to the target boundary node.

[0136] In order to implement the above embodiment, the present application embodiment also proposes an electronic device 800, such as Figure 8 As shown, the electronic device 800 includes: a processor 801 and a memory 802 communicatively connected to the processor, the memory 802 stores instructions executable by at least one processor, and the instructions are executed by at least one processor 801 to implement the session clearing method shown in the above embodiment.

[0137] In order to implement the above embodiment, the embodiment of the present application also proposes a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a computer to implement the session clearing method shown in the above embodiment.

[0138] In order to implement the above embodiment, the embodiment of the present application also proposes a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the session clearing method shown in the above embodiment.

[0139] In the description of the present application, it should be understood that the terms "center", "longitudinal", "lateral", "length", "width", "thickness", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", "clockwise", "counterclockwise", "axial", "radial", "circumferential" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the referred device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present application.

[0140] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0141] In the description of this specification, reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application.

[0142] In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and the features of different embodiments or examples without contradiction.

[0143] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A session clearing method, characterized in that: Executed by the session management node, including: After monitoring that the terminal deletes the session with the external data network, releasing the related resources of the target IP corresponding to the terminal in the session management node; Sending a data packet to a target border node, the data packet is used to instruct the target border node to release resources related to the target IP; or, Generate a first instruction based on the target IP and send it to an IP resource management function node, wherein the IP resource management function node is used to generate a second instruction based on the first instruction and send the second instruction to a target border node, wherein the second instruction is used to instruct the target border node to release resources related to the target IP; The target border node at least includes a firewall that the terminal passes through when communicating with the external data network.

2. The method according to claim 1, characterized in that The sending of a data packet to a target border node includes: Determine a first mapping relationship between a first candidate IP and a first candidate border node stored in the session management node, and query the first mapping relationship based on the target IP to obtain a target border node; A first data packet is sent to the target border node using the target IP.

3. The method according to claim 1, characterized in that The sending of a data packet to a target border node includes: Determine a first mapping relationship between a first candidate IP and a first candidate border node stored in the session management node, and query the first mapping relationship based on the target IP to obtain a target border node; A second data packet is sent to the target border node, wherein the second data packet carries the target IP.

4. The method according to claim 1, characterized in that: The IP resource management function node stores a second mapping relationship between a second candidate IP and a second candidate border node, and the specific process of the IP resource management function node generating a second instruction based on the first instruction and sending the second instruction to the target border node includes: The IP resource management function node receives and parses the first instruction sent by the session management node to obtain the target IP carried by the first instruction; The IP resource management function node queries the second mapping relationship based on the target IP to obtain a target boundary node; The IP resource management function node generates a second instruction based on the target IP and sends the second instruction to the target border node.

5. The method according to any one of claims 1 to 4, characterized in that The session management node and the target border node are both configured with an IP address management interface.

6. A session clearing method, characterized in that: Executed by the target boundary node, including: Receive a data packet sent by a session management node, determine a target IP according to the data packet, and release resources related to the target IP; or, Receive a second instruction sent by the IP resource management function node, parse the second instruction to obtain a target IP and release resources related to the target IP.

7. The method according to claim 6, characterized in that The receiving a data packet sent by the session management node and determining a target IP address according to the data packet includes: Receiving a first data packet sent by a session management node, wherein the first data packet is sent by the session management node using a target IP corresponding to the terminal after monitoring that the terminal deletes a session with an external data network; Identify the IP source of the first data packet and obtain the target IP.

8. The method according to claim 6, characterized in that The receiving a data packet sent by the session management node and determining a target IP address according to the data packet includes: receiving a second data packet sent by the session management node, wherein the second data packet is sent by the session management node after monitoring that the terminal deletes the session with the external data network, and the second data packet carries a target IP corresponding to the terminal; The second data packet is parsed to obtain the target IP carried by the second data packet.

9. The method according to claim 6, characterized in that The IP resource management function node stores a second mapping relationship between a second candidate IP and a second candidate boundary node, and the process of the IP resource management function node generating the second instruction includes: The IP resource management function node receives and parses the first instruction sent by the session management node to obtain the target IP carried by the first instruction; The IP resource management function node queries the second mapping relationship based on the target IP to obtain a target boundary node; The IP resource management function node generates a second instruction based on the target IP and sends the second instruction to the target border node.

10. A session clearing device, characterized in that: include: A monitoring module, configured to release the relevant resources of the target IP corresponding to the terminal in the session management node after monitoring that the terminal deletes the session with the external data network; A sending module, used for sending a data packet to a target border node, wherein the data packet is used for instructing the target border node to release resources related to the target IP; Alternatively, a first instruction is generated based on the target IP and sent to an IP resource management function node, wherein the IP resource management function node is used to generate a second instruction based on the first instruction and send the second instruction to a target border node, wherein the second instruction is used to instruct the target border node to release resources related to the target IP; The target border node at least includes a firewall that the terminal passes through when communicating with the external data network.

11. A session clearing device, characterized in that: include: A receiving module, used to receive a data packet sent by a session management node or a second instruction sent by an IP resource management function node; An execution module is used to determine a target IP according to the data packet and release resources related to the target IP; or, to parse the second instruction to obtain the target IP and release resources related to the target IP.

12. An electronic device comprising: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-5 or 6-9.

13. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-5 or 6-9.

14. A computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the method according to any one of claims 1-5 or 6-9.