Communication method, gateway and electronic equipment

By establishing a virtual private network VPN on the core network, the stability, reliability and security issues of intercommunication between edge networks are solved, and data transmission between MECs with high bandwidth, low latency and high security is achieved, meeting the needs of 5G networks.

CN120050134APending Publication Date: 2025-05-27CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311605130.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-24
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In wireless communication networks, the intercommunication between multiple access edge computing (MEC) between edge networks has stability, reliability and security problems, and the transmission bandwidth is insufficient, which cannot meet the needs of enhanced mobile bandwidth, ultra-high reliability and low latency of 5G networks.

Method used

By establishing a virtual private network VPN on the core network, data transmission between the first edge network and the second edge network is realized. The specific steps include receiving messages sent by the MEC in the first edge network and sending messages to the gateway in the second edge network based on the VPN, realizing data transmission between MECs.

Benefits of technology

Compared with the interoperability between MECs through wired dedicated lines or Internet VPNs, this method can improve the stability, reliability and security between MECs, and meet the high bandwidth, low latency and high security requirements of 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050134A_ABST
    Figure CN120050134A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method, a gateway and electronic equipment. The method is executed by a first gateway of a first edge network, and the method comprises the following steps: receiving a first message sent by a first multi-access edge computing MEC in the first edge network, the first message being a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network; and sending the first message to a second gateway in the second edge network based on a virtual private network (VPN) established by a core network. Compared with the mode that communication between MECs is achieved through a wired private line or an internet VPN, the method has higher stability, reliability and safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and in particular, to a communication method, a gateway, and an electronic device. Background Art

[0002] In a wireless communication network, the key to the interconnection between multi-access edge computing (MEC) in edge networks is that their respective Internet firewalls can achieve interconnection. Its advantage is that MEC interconnection is achieved through the Internet, with simple access and relatively low costs, which can generally be borne by ordinary enterprises. The disadvantage is that the Internet latency is large, the transmission stability and reliability between MECs are low, and the transmission bandwidth cannot be guaranteed, which is contrary to the network advantages of the fifth-generation mobile communication technology (5G), such as enhanced mobile bandwidth, ultra-high reliability, and low latency. In addition, MEC needs to access the Internet firewall and needs to be deployed in the isolation area, with a relatively low security level, and cannot meet application systems with high security requirements, resulting in limitations in the usage scenarios of MEC. Summary of the Invention

[0003] In view of this, embodiments of this application provide a communication method, a gateway, and an electronic device, aiming to improve the stability, reliability, and security between edge networks.

[0004] The technical solution of the embodiments of this application is implemented as follows:

[0005] In a first aspect, embodiments of this application provide a communication method, which is executed by a first gateway of a first edge network. The method includes:

[0006] Receiving a first message sent by a first multi-access edge computing (MEC) in the first edge network, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network;

[0007] Sending the first message to a second gateway in the second edge network based on a virtual private network (VPN) established by the core network.

[0008] In some embodiments, the method further includes:

[0009] Receiving a second message sent by the second gateway based on the VPN, where the second message is a message sent by a second application system in the second MEC or a terminal in the second edge network to the first MEC;

[0010] Sending the second message to the first MEC.

[0011] In some embodiments, the method further includes at least one of the following:

[0012] Establish the VPN between the first gateway and the second gateway, where the first gateway and the second gateway are connected through a Wide Area Network (WAN) interface.

[0013] Establish a communication connection between the first gateway and the first Multi-Access Edge Computing (MEC), where the first gateway and the first MEC are connected through a Local Area Network (LAN) interface.

[0014] In some embodiments, the method further includes:

[0015] In response to the establishment of the VPN, add the information of the VPN to the routing policy information; and / or, in response to the establishment of the communication connection between the first gateway and the first MEC, add the information of the communication connection to the routing policy information;

[0016] Send the routing policy information to the second gateway. In some embodiments, the method further includes:

[0017] Establish a Generic Routing Encapsulation (GRE) tunnel between the first gateway and the second gateway based on the WAN interface.

[0018] In some embodiments, the method further includes:

[0019] In response to the establishment of the GRE tunnel, add the information of the GRE tunnel to the routing policy information;

[0020] Send the routing policy information to the second gateway.

[0021] In some embodiments, the method further includes:

[0022] Send a first access request message to the core network, where the first access request message is used to request access to the network;

[0023] Receive a first response message sent by the core network, where the first response message includes the Internet Protocol (IP) address of the WAN interface of the first gateway, and the IP address is used to establish the VPN between the first gateway and the second gateway.

[0024] In some embodiments, the method further includes:

[0025] Receive a first authentication request message sent by the core network, where the first authentication request message is used to indicate authenticating the terminal;

[0026] Authenticate the terminal based on the authentication rules included in the first authentication request message;

[0027] Send second response information to the core network, where the second response information indicates the result of authenticating the terminal.

[0028] In a second aspect, an embodiment of the present application provides a communication method, which is executed by a first gateway of a first edge network. The method includes:

[0029] Receive a second message sent by a second gateway of a second edge network based on a virtual private network (VPN) established by the core network. The second message is a message sent by a second application system of a second multi-access edge computing (MEC) in the second edge network or a terminal in the second edge network to a first MEC in the first edge network.

[0030] Send the second message to the first MEC.

[0031] In a third aspect, an embodiment of the present application provides a first gateway, which includes:

[0032] A transceiver module, configured to:

[0033] Receive a first message sent by a first multi-access edge computing (MEC) in a first edge network. The first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network. Send the first message to the second gateway in the second edge network based on a virtual private network (VPN) established by the core network.

[0034] And / or, receive a second message sent by the second gateway in the second edge network based on the VPN. The second message is a message sent by a second application system of the second MEC in the second edge network or a terminal in the second edge network to the first MEC in the first edge network. Send the second message to the first MEC.

[0035] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a processor and a memory for storing a computer program that can run on the processor. Among them,

[0036] When the processor is used to run the computer program, it executes the steps of the method described in the first aspect.

[0037] The technical solution provided by the embodiment of the present application receives a first message sent by a first multi-access edge computing (MEC) in a first edge network, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network; and sends the first message to a second gateway in the second edge network based on a virtual private network (VPN) established on a core network. Here, the message sent by the first application system in the first MEC or the terminal in the first edge network to the second MEC in the second edge network can be transmitted to the second gateway in the second edge network based on the VPN established on the core network, realizing data transmission between the first edge network and the second edge network. Compared with realizing interconnection between MECs through a wired dedicated line or an Internet VPN, it has higher stability, reliability, and security. Description of the Drawings

[0038] Figure 1 Schematic diagram of a communication system provided by an embodiment of the present application;

[0039] Figure 2 Schematic diagram of a communication system provided by an embodiment of the present application;

[0040] Figure 3 Schematic flow diagram of a communication method provided by an embodiment of the present application;

[0041] Figure 4 Schematic diagram of a communication system provided by an embodiment of the present application;

[0042] Figure 5 Schematic flow diagram of a communication method provided by an embodiment of the present application;

[0043] Figure 6 Schematic flow diagram of a communication method provided by an embodiment of the present application;

[0044] Figure 7 Schematic diagram of a communication system provided by an embodiment of the present application;

[0045] Figure 8 Schematic flow diagram of a communication method provided by an embodiment of the present application;

[0046] Figure 9 Schematic diagram of a communication system provided by an embodiment of the present application;

[0047] Figure 10 Schematic diagram of a gateway provided by an embodiment of the present application;

[0048] Figure 11 Schematic diagram of a communication system provided by an embodiment of the present application;

[0049] Figure 12 Schematic diagram of a communication system provided by an embodiment of the present application;

[0050] Figure 13 Schematic diagram of a VLAN function provided by an embodiment of the present application;

[0051] Figure 14 Schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0052] The present application will be further described in detail below with reference to the accompanying drawings and embodiments.

[0053] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used in the description of this application herein are only for the purpose of describing specific embodiments and are not intended to limit this application.

[0054] As the commercialization of 5G gradually matures, MEC has been widely applied in the industry. Deploying the application system at the network edge, closer to the mobile terminal device, fully reflects the network advantages of 5G in enhanced mobile bandwidth, ultra-high reliability, and low latency. With the enrichment of application systems on the MEC side, the need for collaborative interconnection between MECs has become increasingly obvious. The collaborative interconnection between MECs supports various service requirements of different application systems and fully reflects the value of MEC.

[0055] In a scenario embodiment, please refer to Figure 1 , and the interconnection between MECs is achieved through a wired dedicated line. A transmission link is established through a dedicated line between the user plane functions (UPF, User Plane Function) in Edge Network A and Edge Network B to achieve the interconnection of the two edge networks.

[0056] In an embodiment, a transmission link is established between the UPF of Edge Network A and the UPF of Edge Network B, and the UPFs communicate with each other through the N9 interface.

[0057] In an embodiment, the UPF of Edge Network A adds network policy routing and other information of Edge Network B, and the UPF of Edge Network A sends the packets received from Edge Network B to the UPF of Edge Network B.

[0058] In an embodiment, the UPF of Edge Network B adds network policy routing and other information of Edge Network A, and the UPF of Edge Network B sends the packets received from Edge Network A to the UPF of Edge Network B.

[0059] In one embodiment, the MEC of Edge Network A adds information such as the network policy routing of Edge Network B, and the MEC of Edge Network A sends the packets received from Edge Network B to the UPF of Edge Network A.

[0060] In one embodiment, the MEC of Edge Network B adds information such as the network policy routing of Edge Network A, and the MEC of Edge Network B sends the packets received from Edge Network A to the UPF of Edge Network B.

[0061] In one embodiment, the application systems of Edge Network A and Edge Network B communicate with each other. The packets first pass through their respective MECs and UPFs, then reach the UPFs and MECs of the other party, and finally reach the application systems that need to communicate with each other.

[0062] In one embodiment, the UE of Edge Network A communicates with the application system of Edge Network B. The packets first pass through the MEC and UPF of Edge Network A, then pass through the UPF and MEC of Edge Network B, and finally reach the application system of Edge Network B.

[0063] In one embodiment, the UE of Edge Network B communicates with the application system of Edge Network A. The packets first pass through the MEC and UPF of Edge Network B, then pass through the UPF and MEC of Edge Network A, and finally reach the application system of Edge Network A.

[0064] In the above embodiments, the key to the communication between the MECs of edge networks is that the respective UPFs can achieve communication. The communication between UPFs requires pulling physical dedicated lines between UPFs, and data forwarding is completed through the N9 interface between UPFs to achieve communication between MECs. Its advantages are small transmission delay, high stability, and large transmission bandwidth. Its disadvantages are that separate wiring is required, the cycle is long, and in addition, the price of wired dedicated lines is relatively expensive. Moreover, it is highly dependent on the UPF network elements in the 5G network, and the configuration of the UPF in the 5G network needs to be modified when the communication network segment changes, and the flexibility is relatively low.

[0065] In a scenario embodiment, please refer to Figure 2 , the communication between MECs is realized through an Internet Virtual Private Network (VPN). The MECs in Edge Network A and Edge Network B are respectively connected to various Internet firewalls, access the Internet through the Internet firewalls, and then establish a VPN between the firewalls to achieve communication.

[0066] In some embodiments, the MECs of Edge Networks A and B are respectively connected to the Internet firewalls in their respective edge networks, and information such as the policy routing of the peer network is added.

[0067] In some embodiments, on the premise of accessing the Internet, the Internet firewalls of Edge Network A and Edge Network B establish a VPN through fixed public IPs, which can be a secure tunnel such as Internet Protocol Security (IPSec) or Generic Routing Encapsulation (GRE), to achieve interconnection between the two firewalls.

[0068] In some embodiments, the Internet firewalls of Edge Network A and Edge Network B respectively add policy information such as routing for the peer network, and send the packets received from the peer network to the peer firewall.

[0069] In some embodiments, the application systems of Edge Network A and Edge Network B are interconnected. Packets first pass through their respective MECs and Internet firewalls, then reach the Internet firewalls and MECs of the other party, and finally reach the application systems that need to be interconnected.

[0070] In some embodiments, the UE of Edge Network A and the application system of Edge Network B are interconnected. Packets first pass through the MEC and firewall of Edge Network A, then pass through the firewall and MEC of Edge Network B, and finally reach the application system of Edge Network B.

[0071] In some embodiments, the UE of Edge Network B and the application system of Edge Network A are interconnected. Packets first pass through the MEC and firewall of Edge Network B, then pass through the firewall and MEC of Edge Network A, and finally reach the application system of Edge Network A.

[0072] In the above embodiments, the key to the interconnection between MECs in edge networks is that their respective Internet firewalls can achieve interconnection. The advantage is that MEC interconnection is achieved through the Internet, with simple access and low cost, which can be borne by general enterprises. The disadvantage is that the Internet latency is large, the transmission stability and reliability between MECs are low, and the transmission bandwidth cannot be guaranteed, which is contrary to the network advantages of enhanced mobile bandwidth, ultra-high reliability, and low latency of 5G. In addition, the MEC needs to access the Internet firewall and needs to be deployed in the isolation area, with a relatively low security level, and cannot meet the security requirements of application systems with high security requirements, resulting in limitations in the usage scenarios of MECs.

[0073] The wireless communication method provided by the embodiments of this application can be applied to a communication system. The communication system includes a first gateway and a second gateway. Using the above system for communication can achieve data transmission between the first edge network and the second edge network, and has higher stability, reliability, and security compared to achieving interconnection between MECs through wired dedicated lines or Internet VPNs.

[0074] An embodiment of the present application provides a communication method, which is applied to a first gateway. The first gateway here can be applied to a communication system, such as Figure 3 as shown, and the method includes the following steps:

[0075] Step 310: Receive a first message sent by a first multi-access edge computing (MEC) in a first edge network. The first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network.

[0076] Step 320: Send the first message to a second gateway in the second edge network based on a virtual private network (VPN) established by the core network.

[0077] In some embodiments, the first gateway and / or the second gateway may integrate the functions of a fixed network residential gateway (FN-RG), a 5G residential gateway (5G-RG), and / or a wireline access gateway function (W-AGF).

[0078] In some embodiments, the first gateway and / or the second gateway may have all or part of the functions of a terminal and / or a terminal.

[0079] In some embodiments, the first gateway and / or the second gateway may have the functions of a virtual local area network (VLAN), routing, and a virtual private network (VPN).

[0080] In one embodiment, please refer to Figure 4 , the communication system includes a first edge network (for example, edge network A), a second edge network (for example, edge network B), and a core network; the first edge network includes a first MEC and a first gateway (for example, a 5G wired enhanced gateway); the second edge network includes a second MEC and a second gateway; application systems are running in the first MEC and the second MEC. The first MEC and the second MEC can communicate with the terminal through a user plane function (UPF) and a base station.

[0081] In some embodiments, the first MEC and the second MEC are respectively interconnected with their corresponding gateways. The first gateway and the second gateway achieve WAN interconnection through the core network. A VPN is established based on the interconnected WAN.

[0082] In some embodiments, the routing information of the interconnection between the first MEC and the first gateway is added to the routing policy information of the second edge network; and / or, the routing information of the interconnection between the second MEC and the second gateway is added to the routing policy information of the first edge network.

[0083] In some embodiments, the first gateway is interconnected with the first MEC through a LAN interface and serves as the gateway for the first MEC to communicate with the second edge network; and / or, the second gateway is interconnected with the second MEC through a LAN interface and serves as the gateway for the second MEC to communicate with the first edge network.

[0084] In some embodiments, the transmission ports of the first gateway and the second gateway are connected to the bearer network and interconnected with the core network to implement the interface functions of N2 and N3, and access the core network in the manner of a base station.

[0085] In some embodiments, the first gateway and the second gateway send request information to the core network to obtain the static Internet Protocol (IP) addresses assigned by the core network, and the static IP addresses are the IP addresses of the WAN ports. The IP addresses are used to establish the VPN between the first gateway and the second gateway.

[0086] In some embodiments, the core network can enable the terminal IP port intercommunication function for the first gateway and the second gateway, and a GRE tunnel can be established between the first gateway and the second gateway through the WAN port.

[0087] In some embodiments, the first edge network can obtain the routing policy information of the second edge network; and / or, the second edge network can obtain the routing policy information of the first edge network.

[0088] In some embodiments, when the first application system in the first edge network communicates with the second application system in the second edge network, the first packet can first reach the second gateway and the second MEC of the second edge network via the first MEC and the first gateway, and finally be sent to the second application system in the second MEC.

[0089] In some embodiments, when the UE in the first edge network communicates with the second application system in the second edge network, the first packet can first reach the second gateway and the second MEC of the second edge network via the first MEC and the first gateway, and finally be sent to the second application system in the second MEC.

[0090] In some embodiments, when the UE in the second edge network communicates with the first application system in the first edge network, the second packet can first reach the first gateway and the first MEC of the first edge network via the second MEC and the second gateway, and finally be sent to the first application system in the first MEC.

[0091] In some embodiments, a first message sent by a first multi-access edge computing (MEC) in a first edge network is received. The first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network. Based on a virtual private network (VPN) established on a core network, the first message is sent to a second gateway in the second edge network. Based on the VPN, a second message sent by the second gateway is received. The second message is a message sent by a second application system in the second MEC or a terminal in the second edge network to the first MEC. The second message is sent to the first MEC.

[0092] In some embodiments, the VPN between the first gateway and the second gateway is established. The first gateway and the second gateway are connected through a wide area network (WAN) interface. A first message sent by a first multi-access edge computing (MEC) in a first edge network is received. The first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network. Based on a virtual private network (VPN) established on a core network, the first message is sent to a second gateway in the second edge network.

[0093] In some embodiments, a communication connection between the first gateway and the first MEC is established. The first gateway and the first MEC are connected through a local area network (LAN) interface. A first message sent by a first multi-access edge computing (MEC) in a first edge network is received. The first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network. Based on a virtual private network (VPN) established on a core network, the first message is sent to a second gateway in the second edge network.

[0094] In some embodiments, a Generic Routing Encapsulation (GRE) tunnel between the first gateway and the second gateway is established based on the WAN interface. A first message sent by a first multi-access edge computing (MEC) in a first edge network is received. The first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network. Based on a virtual private network (VPN) established on a core network, the first message is sent to a second gateway in the second edge network.

[0095] In some embodiments, in response to the establishment of the VPN, information about the VPN is added to the routing policy information; and / or, in response to the establishment of the communication connection between the first gateway and the first MEC, information about the communication connection is added to the routing policy information; and / or, in response to the establishment of the GRE tunnel, information about the GRE tunnel is added to the routing policy information. The routing policy information is sent to the second gateway. A first message sent by a first multi-access edge computing (MEC) in the first edge network is received, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in the second edge network. Based on a virtual private network (VPN) established by the core network, the first message is sent to the second gateway in the second edge network.

[0096] In some embodiments, a first access request information is sent to the core network, where the first access request information is used to request access to the network. A first response information sent by the core network is received, where the first response information includes the Internet Protocol (IP) address of the WAN interface of the first gateway, and the IP address is used to establish the VPN between the first gateway and the second gateway. A first message sent by a first multi-access edge computing (MEC) in the first edge network is received, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in the second edge network. Based on a virtual private network (VPN) established by the core network, the first message is sent to the second gateway in the second edge network.

[0097] In some embodiments, a first authentication request information sent by the core network is received, where the first authentication request information is used to indicate authenticating the terminal. The terminal is authenticated based on the authentication rules included in the first authentication request information. A second response information is sent to the core network, where the second response information indicates the result of authenticating the terminal. A first message sent by a first multi-access edge computing (MEC) in the first edge network is received, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in the second edge network. Based on a virtual private network (VPN) established by the core network, the first message is sent to the second gateway in the second edge network.

[0098] An embodiment of the present application provides a communication method, which is applied to a first gateway. The first gateway here can be applied to a communication system, such as Figure 5 as shown. The method includes the following steps:

[0099] Step 510: Receive a second message sent by a second gateway of a second edge network based on a VPN established by a core network; wherein, the second message is a message sent by a second application system of a second multi-access edge computing (MEC) in the second edge network or a terminal in the second edge network to a first MEC in the first edge network.

[0100] Step 520: Send the second message to the first MEC.

[0101] In some embodiments, a first gateway of a first edge network receives a first message sent by a first multi-access edge computing (MEC) in the first edge network, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network; based on a virtual private network (VPN) established by a core network, the first gateway sends the first message to a second gateway in the second edge network. Based on the VPN established by the core network, the first gateway receives a second message sent by the second gateway of the second edge network; wherein, the second message is a message sent by a second application system of the second MEC in the second edge network or a terminal in the second edge network to the first MEC in the first edge network; the first gateway sends the second message to the first MEC.

[0102] It should be noted that the above embodiments executed by the first gateway can also be executed in the second gateway; the above embodiments executed by the second gateway can also be executed in the first gateway, which is not limited herein.

[0103] For a better understanding of the embodiments of the present disclosure, please refer to Figure 6 A communication method is provided, which is applied to a communication system. Please refer to Figure 7 The communication system includes: a first gateway (5G wired enhanced gateway). A LAN port, a WAN port, a transmission module, a terminal module, a subscriber identity module (SIM) card for user mode recognition, a gNB module, and a transmission port are provided in the first gateway.

[0104] The method includes:

[0105] Step 610: The terminal module obtains data of the SIM card and initiates an access request (first access request information).

[0106] Step 620: The terminal module sends the access request to the gNB module, and the gNB module transmits the access request to the access and mobility management function (AMF) of the core network through the transmission port.

[0107] Step 630: The AMF sends an authentication message (first authentication request information) to the terminal module and sends it to the terminal module through the gNB module.

[0108] Step 640: The terminal module completes authentication according to the authentication requirements of the AMF, and sends the authentication reply message (the second response message) to the AMF through the gNB module.

[0109] Step 650: The AMF confirms the authentication reply message, assigns a specific IP address to the terminal, and sends it to the terminal module through the eNB module.

[0110] Step 660: After receiving the IP address, the terminal module establishes a virtual network device, writes the IP address into the device, and this virtual network device is the WAN port.

[0111] Step 670: After the WAN port has an IP, it can perform service interactions with the 5GC.

[0112] For a better understanding of the embodiments of the present disclosure, please refer to Figure 8 , a communication method is provided, which is applied to a communication system. Please refer to Figure 9 , the communication system includes: MEC A (the first MEC), MEC B (the second MEC), the first gateway and the second gateway. The first gateway and the second gateway are provided with a LAN port, a WAN port, a transmission module, a terminal module, a SIM card, a gNB module and a transmission port.

[0113] The method includes:

[0114] Step 810: The first application system in the first edge network accesses the second application system in the second edge network, and the first application system transmits the first message to the first gateway.

[0115] Step 820: The first gateway transmits the first message to the transmission module of the first gateway through the LAN port.

[0116] Step 830: The transmission module of the first gateway performs GRE encapsulation on the first message and transmits the first message to the WAN port.

[0117] Step 840: The first message is transmitted to the terminal module through the WAN port.

[0118] Step 850: The terminal module transmits the first message to the base station (gNB) module.

[0119] Step 860: The gNB module performs GTP-U encapsulation on the message and transmits it to the gNB module of the second gateway in the second edge network through the 5GC.

[0120] Step 870: The gNB module of the second gateway performs GTP-U decapsulation on the first message and then transmits it to the terminal module.

[0121] Step 880: The terminal module transmits the first message to the WAN port.

[0122] Step 890: The WAN port transmits the first message to the transmission module.

[0123] Step 891: The transmission module performs GRE decapsulation on the first message and delivers the first message to the LAN port.

[0124] Step 892: The LAN port delivers the message to the second application system of the second MEC that the first MEC wants to access.

[0125] Please refer to Figure 10 , this embodiment of the present application provides a first gateway, and the first gateway includes:

[0126] A transceiver module 101, configured to:

[0127] Receive a first message sent by a first multi-access edge computing (MEC) in a first edge network, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network; and send the first message to a second gateway in the second edge network based on a virtual private network (VPN) established by the core network;

[0128] And / or, receive a second message sent by the second gateway in the second edge network based on the VPN; where the second message is a message sent by a second application system of the second MEC in the second edge network or a terminal in the second edge network to the first MEC in the first edge network; and send the second message to the first MEC.

[0129] To better understand the first gateway and / or the second gateway, the following is further described through an exemplary embodiment:

[0130] In some embodiments, the first gateway and / or the second gateway has terminal functions and interacts with the AMF through the N1 interface; has base station functions and interacts with the AMF through the N2 interface and with the UPF through the N3 interface. The first gateway and / or the second gateway provides an external standard Ethernet interface for interconnection with the MEC and has functions such as VLAN, routing, and VPN.

[0131] In some embodiments, please refer to Figure 11 , the first gateway and / or the second gateway includes a terminal module, a gNB module, and a transmission module, and the interface has three types of interfaces, namely the LAN port, the WAN port, and the transmission port.

[0132] In some embodiments, the terminal module simulates the interaction between the UE and the gNB module, including SIM card processing, N1 message encoding and decoding, N1-related process status processing, and user plane interface processing functions. Exemplarily, it can be subdivided into a Universal Subscriber Identity Module (USIM) module, an N1 module, and a User Plane (UP) module.

[0133] In some embodiments, the USIM module operates on the SIM card using the interface provided by PCSC-LITE (a port from the Windows Personal Computer (PC) or Smart Card stack to a UNIX machine), and obtains SIM card information using a PC or SC card reader, including information such as the Mobile Country Code (MCC), Mobile Network Code (MNC), and International Mobile Subscriber Identity (IMSI).

[0134] In some embodiments, the USIM module completes the authentication and identity verification function of the SIM card, and the bidirectional authentication protocol used is based on the Authentication & Key Agreement (AKA) authentication protocol framework to complete the identity authentication.

[0135] In some embodiments, the N1 module mainly processes Non-Access-Stratum (NAS) messages of the N1 interface, and processes processes such as the network access process, logout process, service request process, Protocol Data Unit (PDU) session establishment process, and PDU session release.

[0136] In some embodiments, during the process of the N1 processing module processing NAS messages, it will involve interaction with the SIM, reading SIM card information, and authentication verification operations. Adopting the solution of PC or SC smart card interface programming, accessing the SIM card through the PC / SC interface can obtain information such as MCC, MNC, and IMSI, and the authentication information can be sent to the card reader. The SIM card calculates the authentication response and returns it to the N1 module to achieve authentication.

[0137] In some embodiments, the UP module is responsible for processing user data, including virtual network card interface management, F1-U encapsulation and decapsulation of packets.

[0138] Exemplarily, please refer to Figure 12 , which shows the design architecture of the UP module in the 5G wired enhanced gateway.

[0139] In some embodiments, the UP module acts as the central unit (DU, Distributed Unit) of the gNB. After receiving the message from the transmission module, it performs F1-U encapsulation on the message and sends it to the gNB-CU-UP. After receiving the message from the gNB-CU-UP (CU is the distributed unit, Distribution Unit), it removes the F1-U header and forwards it to the transmission module.

[0140] In some embodiments, the UP module is responsible for establishing a user data channel between the transmission module and the 5GC. After the N1 module successfully registers with the core network and obtains an IP address, it notifies the UP module to establish a Linux virtual network device as the WAN interface. The downlink data received by the UP module is forwarded to the WAN interface, and the uplink data received by the WAN interface is forwarded to the UP module, and then forwarded by the gNB-CU-UP of the gNB module to the UPF.

[0141] In some embodiments, the gNB module includes the gNB-CU-CP and gNB-CU-UP modules, which are respectively responsible for handling signaling interactions with the AMF and data interactions with the UPF.

[0142] In some embodiments, the gNB-CU-CP is the control plane of the base station central unit, performs signaling interactions with the AMF through the N2 interface, transparently transmits NAS messages on the N1 interface, and completes processes such as PDU session management, UE context management, NAS message transmission, and N2 interface management.

[0143] In some embodiments, the gNB-CU-UP is the user panel of the base station control unit, performs data interactions with the UPF through the N3 interface, transmits data through the GPT-U tunnel, and performs GTP-U encapsulation and decapsulation on data messages.

[0144] In some embodiments, the transmission module mainly implements LAN interface management, VLAN function, routing, and VPN function, is responsible for data communication between the LAN interface and the WAN interface, and establishes a GRE tunnel on the premise of WAN interface intercommunication.

[0145] In some embodiments, it is implemented using Linux VLAN and bridge technologies. The VLAN realizes the isolation function but does not have the switching function. The Bridge specifically realizes the switching function. Mount all sub-devices in the same VLAN on a Bridge, and data can be exchanged between devices. Add the same VLAN tag to the LAN interfaces belonging to the same subnet and join the same Bridge, and the layer 2 forwarding function of the LAN interface can be realized. If the LAN interface needs to support layer 3 forwarding, then the IP address of the subnet needs to be set on the Bridge, and the Bridge is used as the gateway of the subnet to support layer 3 forwarding.

[0146] In some embodiments, refer to Figure 13 , which shows the VLAN function.

[0147] In some embodiments, the routing function provided by LINUX itself is used. The routing table of LINUX is divided into the default route, host route, and network route.

[0148] In some embodiments, for the default route (e.g., 0.0.0.0), when the host cannot find the IP address of the destination host or the network route record in the routing table, the data packet is sent to the default route (default gateway).

[0149] In some embodiments, for the host route (e.g., 255.255.255.255), it is a record in the routing table entry that points to a single IP address or host name.

[0150] In some embodiments, the network route (a specific network segment, e.g., 255.255.255.0): represents the network that the host can reach.

[0151] In some embodiments, the VPN of the 5G wired enhanced wired gateway is implemented using the GRE protocol. GRE provides a mechanism for encapsulating one protocol packet in another protocol packet and is a three-layer tunnel encapsulation technology. It can re-encapsulate the data packets of the IPv4 protocol so that these encapsulated data packets can be transmitted in another network layer protocol (such as IPv4).

[0152] In some embodiments, the ip_gre kernel module of LINUX is used to support the GRE protocol. After loading the kernel module, the two end devices can specify the local address (the local WAN port address) and the remote address (the peer WAN port address) to establish a GRE tunnel.

[0153] In some embodiments, the LAN port is a physical port, electrical port, or optical port, which refers to the port configured to join the VLAN and is used to connect to the MEC.

[0154] In some embodiments, the WAN port is a virtual network device. After the terminal module successfully accesses the network, the IP address assigned by the 5GC is written into this device, which can be used for two 5G wired enhanced gateways to establish a GRE tunnel.

[0155] In some embodiments, the transmission port is a physical port, electrical port, or optical port, which is the port for the 5G wired enhanced gateway to access the bearer network, realizes intercommunication with the 5GC, and bears the signaling and data of the N2 and N3 interfaces.

[0156] It should be noted that when the gateway provided in the above embodiment conducts communication, only the division of the above program modules is used for illustration. In actual applications, the above processing can be allocated to different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the access control device and the access control method embodiment provided in the above embodiment belong to the same concept. For the specific implementation process, please refer to the method embodiment and will not be elaborated here.

[0157] Based on the hardware implementation of the above program modules and in order to implement the method of the embodiments of the present application, the embodiments of the present application also provide an electronic device. Figure 14 Only the exemplary structure of the access control device is shown rather than all structures, and partial or all structures shown can be implemented according to needs. Figure 14 The partial or all structures shown.

[0158] Such as Figure 14 As shown, the electronic device 1000 provided in the embodiments of the present application includes: at least one processor 1001, a memory 1002, a user interface 1003, and at least one network interface 1004. Each component in the access control device 1000 is coupled together through a bus system 1005. It can be understood that the bus system 1005 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 1005 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 14 all kinds of buses are labeled as the bus system 1005.

[0159] Among them, the user interface 1003 may include a display, a keyboard, a mouse, a trackball, a click wheel, a button, a touchpad, or a touch screen, etc.

[0160] The memory 1002 in the embodiments of the present application is used to store various types of data to support the operation of the access control device. Examples of these data include: any computer program for operating on the access control device.

[0161] The access control method disclosed in the embodiments of the present application can be applied to the processor 1001 or implemented by the processor 1001. The processor 1001 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the access control method can be completed by the integrated logic circuit of the hardware in the processor 1001 or the instructions in the form of software. The above-mentioned processor 1001 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 1001 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. Combining the steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or by a combination of the hardware and software modules in the decoding processor. The software module may be located in the storage medium, and this storage medium is located in the memory 1002. The processor 1001 reads the information in the memory 1002 and combines its hardware to complete the steps of the access control method provided in the embodiments of the present application.

[0162] In an exemplary embodiment, the electronic device can be implemented by one or more application-specific integrated circuits (ASICs, Application Specific Integrated Circuits), DSPs, programmable logic devices (PLDs, Programmable Logic Devices), complex programmable logic devices (CPLDs, Complex Programmable Logic Devices), field programmable gate arrays (FPGAs, Field Programmable Gate Arrays), general-purpose processors, controllers, microcontroller units (MCUs, Micro Controller Units), microprocessors (Microprocessors), or other electronic components, and is used to execute the foregoing method.

[0163] It can be understood that the memory 1002 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), an erasable programmable read-only memory (EPROM, Erasable Programmable Read-Only Memory), an electrically erasable programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), a ferromagnetic random access memory (FRAM, ferromagnetic random access memory), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM, Compact Disc Read-Only Memory); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM, Random Access Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as a static random access memory (SRAM, Static Random Access Memory), a synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory), a dynamic random access memory (DRAM, Dynamic Random Access Memory), a synchronous dynamic random access memory (SDRAM, Synchronous Dynamic Random Access Memory), a double data rate synchronous dynamic random access memory (DDR SDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), an enhanced synchronous dynamic random access memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), a sync link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), a direct rambus random access memory (DRRAM, Direct Rambus Random Access Memory).The memories described in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.

[0164] In an exemplary embodiment, the embodiments of the present application further provide an access control authentication system, including a first device and a second device, wherein the number of the first devices is at least two, and the second device is communicatively connected to the first device.

[0165] In an exemplary embodiment, the embodiments of the present application further provide a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, including a memory 1002 storing a computer program, and the above computer program can be executed by a processor 1001 of an electronic device to complete the steps of the method in the embodiments of the present application. The computer-readable storage medium can be a memory such as ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0166] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence.

[0167] In addition, the technical solutions described in the embodiments of the present application can be arbitrarily combined without conflict.

[0168] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A communication method, characterized in that, the method is executed by a first gateway of a first edge network, and the method includes: receiving a first message sent by a first multi-access edge computing (MEC) in the first edge network, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network; sending the first message to a second gateway in the second edge network based on a virtual private network (VPN) established by a core network.

2. The method according to claim 1, characterized in that, the method further includes: receiving a second message sent by the second gateway based on the VPN, where the second message is a message sent by a second application system in the second MEC or a terminal in the second edge network to the first MEC; sending the second message to the first MEC.

3. The method according to claim 1, characterized in that, the method further includes at least one of the following: establishing the VPN between the first gateway and the second gateway, and the first gateway and the second gateway are connected through a wide area network (WAN) interface; establishing a communication connection between the first gateway and the first MEC, and the first gateway and the first MEC are connected through a local area network (LAN) interface.

4. The method according to claim 3, characterized in that, the method further includes: in response to the establishment of the VPN, adding information of the VPN to routing policy information; and / or, in response to the establishment of the communication connection between the first gateway and the first MEC, adding information of the communication connection to routing policy information; sending the routing policy information to the second gateway.

5. The method according to claim 1, characterized in that, the method further includes: establishing a Generic Routing Encapsulation (GRE) tunnel between the first gateway and the second gateway based on the WAN interface.

6. The method according to claim 5, characterized in that, the method further includes: in response to the establishment of the GRE tunnel, adding information of the GRE tunnel to routing policy information; sending the routing policy information to the second gateway.

7. The method according to claim 1, characterized in that, the method further includes: sending first access request information to the core network, where the first access request information is used to request access to the network; receiving first response information sent by the core network, where the first response information includes an Internet Protocol (IP) address of the WAN interface of the first gateway, and the IP address is used to establish the VPN between the first gateway and the second gateway.

8. The method according to claim 1, characterized in that, the method further includes: receiving first authentication request information sent by the core network, where the first authentication request information is used to indicate authenticating the terminal; authenticating the terminal based on an authentication rule included in the first authentication request information; sending second response information to the core network, where the second response information indicates a result of authenticating the terminal.

9. A communication method, characterized in that, The method is executed by a first gateway of a first edge network, and the method includes: Receiving a second message sent by a second gateway of a second edge network based on a virtual private network (VPN) established by a core network; wherein, the second message is a message sent by a second application system of a second multi-access edge computing (MEC) in the second edge network or a terminal in the second edge network to a first MEC in the first edge network; Sending the second message to the first MEC.

10. A first gateway, characterized in that, the first gateway includes: A transceiver module, configured to: Receive a first message sent by a first multi-access edge computing (MEC) in a first edge network, where the first message is a message sent by a first application system in the first MEC or a terminal in the first edge network to a second MEC in a second edge network; and send the first message to the second gateway in the second edge network based on a virtual private network (VPN) established by a core network; and / or, receive a second message sent by the second gateway of the second edge network based on the VPN; wherein, the second message is a message sent by a second application system of the second MEC in the second edge network or a terminal in the second edge network to the first MEC in the first edge network; and send the second message to the first MEC.

11. An electronic device, characterized in that, it includes: A processor and a memory for storing a computer program that can run on the processor, wherein, when the processor is used to run the computer program, it executes the steps of the method according to any one of claims 1 to 8 or 9.