Policy routing dynamic management method and system and storage medium

Through the policy routing control device, it automatically receives and processes the terminal's access request messages and update messages, and sends policy routing management instructions to the gateway device, realizing the automated configuration and maintenance of policy routing based on the source IP address, solving the problem of manual configuration dependence and insufficient adaptability of dynamic source IP in traditional methods, and improving the flexibility and efficiency of routing management.

CN120200957APending Publication Date: 2025-06-24CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510405927.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Traditional policy routing management methods rely highly on manual configuration, resulting in increased network management difficulties and increased maintenance costs, and lack of adaptability in dynamic source IP scenarios.

Method used

The policy routing control device receives the terminal's access request message and/or update message, and sends policy routing management instructions to the gateway device based on these messages, so as to realize the automated configuration and maintenance of the terminal's policy routing based on the source IP address.

Benefits of technology

It greatly improves the flexibility of routing management, enables policy routing to adapt to more application scenarios, significantly reduces the difficulty and maintenance costs of network management, and solves the adaptability problem in dynamic source IP scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200957A_ABST
    Figure CN120200957A_ABST
Patent Text Reader

Abstract

The invention provides a policy routing dynamic management method and system and a storage medium, and relates to the technical field of networks, and the method comprises the following steps: a policy routing control device receives an access request message and / or an update message of a terminal; the policy routing control device sends a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source IP address to gateway equipment according to the access request message and / or the update message; and the gateway equipment configures and / or maintains the policy routing of the terminal based on the source IP address according to the policy routing management instruction, and forwards the network data packet of the terminal based on the policy routing. According to the method, the system and the storage medium, the problems that the network management difficulty is increased, the maintenance cost is increased, and adaptability is lacked in a dynamic source IP scene due to the fact that a traditional policy routing management method highly depends on manual configuration can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technologies, and in particular, to a method, a system, and a storage medium for dynamically managing policy-based routing. Background Art

[0002] Policy-based routing is a technology that controls the forwarding path of data packets according to the policies formulated by network administrators. Different from the traditional forwarding based on the destination IP (Internet Protocol) address and routing table, it can more flexibly guide and manage network traffic.

[0003] However, although policy-based routing has many advantages, it also faces some disadvantages and difficulties. On the one hand, the traditional policy-based routing management method highly depends on manual configuration. With the expansion of the network scale and the continuous increase of source IP address segments, this static configuration method not only becomes increasingly complex, but also is prone to configuration errors or conflicts, significantly increasing the difficulty of network management and maintenance costs. On the other hand, policy-based routing lacks adaptability to dynamic source IPs. For some scenarios where IP addresses are dynamically allocated, such as mobile devices accessing the network or users using dynamic IP address pools, policy-based routing based on the source address may be difficult to accurately manage their traffic, and this limitation restricts the effectiveness and applicability of policy-based routing in more application scenarios. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method, a system, and a storage medium for dynamically managing policy-based routing in view of the above deficiencies of the prior art, so as to solve the problems that the traditional policy-based routing management method highly depends on manual configuration, thus increasing the difficulty of network management and maintenance costs, and lacking adaptability in the dynamic source IP scenario.

[0005] In a first aspect, the present invention provides a method for dynamically managing policy-based routing, which is applied to a system for dynamically managing policy-based routing. The system for dynamically managing policy-based routing includes a policy-based routing control device and a gateway device. The method includes:

[0006] The policy-based routing control device receives an access request message and / or an update message from a terminal;

[0007] The policy-based routing control device sends a policy-based routing management instruction for configuring and / or maintaining the policy-based routing of the terminal based on the source Internet Protocol (IP) address to the gateway device according to the access request message and / or the update message;

[0008] The gateway device configures and / or maintains the policy-based routing of the terminal based on the source IP address according to the policy-based routing management instruction, and forwards the network data packets of the terminal based on the policy-based routing.

[0009] Further, the policy routing control device receives an access request message and / or an update message of the terminal, specifically including:

[0010] The policy routing control device receives the access request message and / or the update message of the terminal sent by the session management function (SMF) network element in the main delivery manner; or,

[0011] The policy routing control device receives the access request message and / or the update message of the terminal sent by the SMF network element or other functional modules in the carbon copy manner.

[0012] Further, if the policy routing control device receives the access request message and / or the update message of the terminal sent by the SMF network element in the main delivery manner, the method further includes:

[0013] Performing access authentication, authorization, and charging on the terminal.

[0014] Further, the access request message includes an authentication request message and a charging request message, the update message includes a charging update message and a charging end message, and the policy routing control device sends a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source Internet Protocol (IP) address to the gateway device according to the access request message and / or the update message, specifically including:

[0015] The policy routing control device obtains the accessible target network information corresponding to the terminal according to the authentication request message or the charging request message, generates a policy routing of the terminal based on the source IP address according to the accessible target network information, and sends a policy routing configuration instruction for configuring the policy routing of the terminal based on the source IP address to the gateway device;

[0016] The policy routing control device sends a policy routing update instruction and / or a policy routing deletion instruction for updating and / or deleting the policy routing of the terminal based on the source IP address to the gateway device according to the charging update message;

[0017] The policy routing control device sends a policy routing deletion instruction for deleting the policy routing of the terminal based on the source IP address to the gateway device according to the charging end message;

[0018] The gateway device configures and / or maintains the policy routing of the terminal based on the source IP address according to the policy routing management instruction, specifically including:

[0019] The gateway device configures the policy routing of the terminal based on the source IP address according to the policy routing configuration instruction;

[0020] The gateway device updates the policy route of the terminal based on the source IP address according to the policy route update instruction;

[0021] The gateway device deletes the policy route of the terminal based on the source IP address according to the policy route deletion instruction.

[0022] Further, the policy route control device obtains the accessible target network information corresponding to the terminal according to the authentication request message or the charging request message, specifically including:

[0023] Obtain the identity information of the terminal from the authentication request message or the charging request message, where the identity information includes at least one of the following: Mobile Station International Subscriber Directory Number (MSISDN), International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI);

[0024] Query and obtain the pre-configured accessible target network information of the terminal according to the identity information.

[0025] Further, the policy route control device sends a policy route update instruction and / or a policy route deletion instruction for updating and / or deleting the policy route of the terminal based on the source IP address to the gateway device according to the charging update message, specifically including:

[0026] If the receiving time of the charging update message is within the preset aging time, the policy route control device determines whether the IP address of the terminal has changed;

[0027] In response to the IP address of the terminal not changing, the policy route control device maintains the policy route of the terminal based on the source IP address;

[0028] In response to the IP address of the terminal changing, and the geographical location and / or access time of the terminal being within the pre-configured access permissions, the policy route control device sends a policy route update instruction for updating the policy route of the terminal based on the source IP address to the gateway device;

[0029] In response to the IP address of the terminal changing, and the geographical location and / or access time of the terminal not being within the pre-configured access permissions, the policy route control device sends a policy route deletion instruction for deleting the policy route of the terminal based on the source IP address to the gateway device.

[0030] Further, the policy route control device sends a policy route deletion instruction for deleting the policy route of the terminal based on the source IP address to the gateway device according to the charging end message, specifically including:

[0031] If the reception time of the charging end message is within a preset aging time, the policy routing control device sends a policy routing deletion instruction to the gateway device for deleting the policy routing of the terminal based on the source IP address.

[0032] Further, the method further includes:

[0033] Within the preset aging time, if the charging update message or the charging end message is not received, the policy routing control device sends a policy routing deletion instruction to the gateway device for deleting the policy routing of the terminal based on the source IP address.

[0034] In a second aspect, the present invention provides a policy routing dynamic management system, including a policy routing control device and a gateway device;

[0035] The policy routing control device is configured to receive an access request message and / or an update message of a terminal;

[0036] The policy routing control device is further configured to send a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source Internet Protocol (IP) address to the gateway device according to the access request message and / or the update message;

[0037] The gateway device is configured to configure and / or maintain the policy routing of the terminal based on the source IP address according to the policy routing management instruction, and forward network data packets of the terminal based on the policy routing.

[0038] In a third aspect, the present invention provides a computer storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the policy routing dynamic management method described in the first aspect above is implemented.

[0039] The present invention provides a method, a system, and a storage medium for dynamically managing policy-based routing. First, a policy-based routing control device receives an access request message and / or an update message from a terminal, and sends a policy-based routing management instruction for configuring and / or maintaining the policy-based routing of the terminal based on the source IP address to a gateway device according to the access request message and / or the update message; then, the gateway device configures and / or maintains the policy-based routing of the terminal based on the source IP address according to the policy-based routing management instruction, and forwards network data packets of the terminal based on the policy-based routing. By automatically receiving and processing the access request message and / or the update message of the terminal by the policy-based routing control device and sending a policy-based routing management instruction to the gateway device accordingly, the present invention realizes the automatic configuration and maintenance of the policy-based routing based on the source IP address, greatly improves the flexibility of routing management, enables the policy-based routing to adapt to more application scenarios, and at the same time significantly reduces the difficulty of network management and the maintenance cost, and solves the problems that the traditional policy-based routing management method highly depends on manual configuration, resulting in an increase in the difficulty of network management and the maintenance cost, and a lack of adaptability in the dynamic source IP scenario. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 It is a flowchart of a method for dynamically managing policy-based routing according to Embodiment 1 of the present invention;

[0041] Figure 2 It is a schematic structural diagram of a system for dynamically managing policy-based routing according to Embodiment 1 of the present invention;

[0042] Figure 3 It is a flowchart of another method for dynamically managing policy-based routing according to Embodiment 1 of the present invention;

[0043] Figure 4 It is a schematic connection diagram of a system for dynamically managing policy-based routing according to Embodiment 1 of the present invention;

[0044] Figure 5 It is a schematic structural diagram of a system for dynamically managing policy-based routing according to Embodiment 2 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] To enable those skilled in the art to better understand the technical solutions of the present invention, the embodiments of the present invention will be further described in detail below in conjunction with the accompanying drawings.

[0046] It can be understood that the specific embodiments and the accompanying drawings described herein are only for explaining the present invention, rather than limiting the present invention.

[0047] It can be understood that, without conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other.

[0048] It is understood that, for ease of description, only the parts related to the present invention are shown in the drawings of the present invention, while the parts unrelated to the present invention are not shown in the drawings.

[0049] It is understood that each unit and module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures. Alternatively, multiple units and modules may also be integrated into one entity structure.

[0050] It is understood that the terms "first", "second", etc. in the embodiments of the present invention are used to distinguish different objects or different processes for the same object, rather than to describe a specific order of the objects.

[0051] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of the present invention may occur in an order different from that marked in the drawings.

[0052] It is understood that in the flowcharts and block diagrams of the present invention, the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the embodiments of the present invention are shown. Among them, each block in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified function. Moreover, each block or combination of blocks in the block diagram and flowchart may be implemented by a hardware-based system for implementing the specified function, or may be implemented by a combination of hardware and computer instructions.

[0053] It is understood that the units and modules involved in the embodiments of the present invention may be implemented in software or in hardware. For example, the units and modules may be located in the processor.

[0054] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, some of the technical terms involved in the embodiments of the present invention will be briefly described below.

[0055] AUSF: Authentication Server Function, authentication service function;

[0056] UDM: Unified Data Management, unified data management function;

[0057] AMF: Access and Management Function, access and mobility management function;

[0058] SMF: Session Management Function, session management function;

[0059] UE: User Equipment, the user terminal (referred to as the terminal for short);

[0060] RAN: Radio Access Network, the radio access network;

[0061] UPF: User Plane Function, the user plane function;

[0062] AAA: Authentication, Authorization and Accounting, authentication, authorization and accounting;

[0063] MSISDN: Mobile Subscriber International ISDN, the international mobile subscriber integrated services digital network;

[0064] IMSI: International Mobile Subscriber Identity, the international mobile subscriber identity;

[0065] IMEI: International Mobile Equipment Identity, the international mobile equipment identity;

[0066] PDU: Protocol Data Unit, the protocol data unit;

[0067] EAP: Extensible Authentication Protocol, the extensible authentication protocol;

[0068] NAS: Non-access stratum, the non-access stratum.

[0069] Example 1:

[0070] This example provides a method for dynamically managing policy routing, which is applied to a policy routing dynamic management system. The policy routing dynamic management system includes a policy routing control device and a gateway device. As Figure 1 shown, this method includes:

[0071] Step S101: The policy routing control device receives an access request message and / or an update message from the terminal.

[0072] In this embodiment, the policy routing dynamic management system is connected to each network element in the mobile communication system and is deployed between the UPF and the data network. It includes a policy routing control device and a gateway device. Among them, the policy routing control device serves as the control plane, and the gateway device serves as the data forwarding plane. The policy routing control device receives the access request message and / or update message of the terminal.

[0073] Optionally, the policy routing control device receiving the access request message and / or update message of the terminal specifically includes:

[0074] The policy routing control device receives the access request message and / or update message of the terminal sent by the session management function (SMF) network element in the main delivery mode; or,

[0075] The policy routing control device receives the access request message and / or update message of the terminal sent by the SMF network element or other functional modules in the carbon copy mode.

[0076] In this embodiment, the access request message and / or update message can be sent by the core network SMF network element to the policy routing control device in the main delivery mode, that is, the SMF sends the access request message and / or update message to the policy routing control device. Or, the access request message and / or update message can also be sent to the policy routing control device in the carbon copy mode, that is, other functional modules in the mobile communication system carbon copy the access request message and / or update message to the policy routing control device. The policy routing control device receives the access request message and / or update message through the Radius (Remote Authentication Dial-In User Service) interface.

[0077] Optionally, if the policy routing control device receives the access request message and / or update message of the terminal sent by the SMF network element in the main delivery mode, the method further includes:

[0078] Performing access authentication, authorization, and accounting on the terminal.

[0079] In this embodiment, in the main delivery mode, the policy routing control device first performs access authentication, authorization, and accounting on the terminal, and then dynamically manages the policy routing of the terminal based on the source IP address according to the received access request message and / or update message to realize the linkage between terminal access authentication and routing management. In the carbon copy mode, the access authentication, authorization, and accounting of the terminal can be completed by other functional modules in the mobile communication system, and the policy routing control device does not participate in the access authentication, authorization, and accounting of the terminal.

[0080] Step S102: The policy routing control device sends a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source Internet Protocol (IP) address to the gateway device according to the access request message and / or the update message.

[0081] In this embodiment, the policy routing control device sends a policy routing management instruction for configuring the policy routing of the terminal based on the source IP address to the gateway device according to the access request message, and / or the policy routing control device sends a policy routing management instruction for maintaining the policy routing of the terminal based on the source IP address to the gateway device according to the update message. The policy routing based on the source IP address is used to direct network data packets from different source IP addresses or source IP address segments to different paths or interfaces for forwarding according to preset rules.

[0082] Step S103: The gateway device configures and / or maintains the policy routing of the terminal based on the source IP address according to the policy routing management instruction, and forwards the network data packets of the terminal based on the policy routing.

[0083] In this embodiment, the gateway device configures and / or maintains the policy routing of the terminal based on the source IP address according to the issued policy routing management instruction. The maintenance includes updating or deleting. When the gateway device receives the network data packets of the terminal, it forwards the network data packets according to the policy routing to implement data communication between the terminal and the target network.

[0084] Optionally, the access request message includes an authentication request message and a charging request message, the update message includes a charging update message and a charging end message. The policy routing control device sending a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source Internet Protocol (IP) address to the gateway device according to the access request message and / or the update message specifically includes:

[0085] The policy routing control device obtains the accessible target network information corresponding to the terminal according to the authentication request message or the charging request message, generates the policy routing of the terminal based on the source IP address according to the accessible target network information, and sends a policy routing configuration instruction for configuring the policy routing of the terminal based on the source IP address to the gateway device;

[0086] The policy routing control device sends a policy routing update instruction and / or a policy routing deletion instruction for updating and / or deleting the policy routing of the terminal based on the source IP address to the gateway device according to the charging update message;

[0087] The policy routing control device sends a policy routing deletion instruction for deleting the policy routing of the terminal based on the source IP address to the gateway device according to the charging end message;

[0088] The gateway device configures and / or maintains the policy-based routing of the terminal based on the source IP address according to the policy-based routing management instruction, specifically including:

[0089] The gateway device configures the policy-based routing of the terminal based on the source IP address according to the policy-based routing configuration instruction;

[0090] The gateway device updates the policy-based routing of the terminal based on the source IP address according to the policy-based routing update instruction;

[0091] The gateway device deletes the policy-based routing of the terminal based on the source IP address according to the policy-based routing deletion instruction.

[0092] It should be noted that the access request message includes an authentication request message and a charging request message, and the update message includes a charging update message and a charging end message. However, in actual applications, other information can also be added as the access request message or the update message according to actual needs.

[0093] In this embodiment, the policy-based routing control device is pre-configured with the target network information accessible to the terminal. The policy-based routing control device queries and matches the accessible target network information corresponding to the terminal according to the received authentication request message or charging request message, generates a policy-based routing based on the source IP address information of the terminal extracted from the message, and sends a policy-based routing configuration instruction to the gateway device.

[0094] It should be noted that when the terminal accesses the network for the first time, the policy-based routing control device receives an authentication request message or a charging request message, and at this time, a corresponding policy-based routing will be generated. When the terminal is always online, the policy-based routing control device will continuously receive charging update messages periodically. At this time, the policy-based routing control device will send a policy-based routing update instruction and / or a policy-based routing deletion instruction to the gateway device according to whether the IP address of the terminal has changed and whether it meets the preset terminal access permission conditions. When the terminal goes offline / leaves the network normally, the policy-based routing control device will receive a charging end message, and at this time, the policy-based routing control device immediately sends a policy-based routing deletion instruction to the gateway device to delete the policy-based routing corresponding to the terminal.

[0095] Optionally, the policy-based routing control device obtains the accessible target network information corresponding to the terminal according to the authentication request message or the charging request message, specifically including:

[0096] Obtain the identity information of the terminal from the authentication request message or the charging request message, where the identity information includes at least one of the following: Mobile Station International Subscriber Directory Number (MSISDN), International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI);

[0097] Query and obtain the target network information accessible to the terminal pre-configured according to the identity information.

[0098] In this embodiment, the authentication request message, the charging request message, the charging update message, and the charging end message all carry the identity information, location information, time information, and IP address (i.e., the temporary IP address) of the terminal. Among them, the identity information includes MSISDN, IMSI, IMEI, etc. The policy routing control device matches the target network information accessible to the terminal according to the identity information of the terminal. The target network information accessible to the terminal includes the target network address and the next-hop gateway IP address for accessing the target network.

[0099] Optionally, the policy routing control device sends a policy routing update instruction and / or a policy routing deletion instruction for updating and / or deleting the policy routing of the terminal based on the source IP address to the gateway device according to the charging update message. Specifically, it includes:

[0100] If the reception time of the charging update message is within the preset aging time, the policy routing control device determines whether the IP address of the terminal has changed;

[0101] In response to the IP address of the terminal not changing, the policy routing control device maintains the policy routing of the terminal based on the source IP address;

[0102] In response to the IP address of the terminal changing and the geographical location and / or access time of the terminal being within the pre-configured access permissions, the policy routing control device sends a policy routing update instruction for updating the policy routing of the terminal based on the source IP address to the gateway device;

[0103] In response to the IP address of the terminal changing and the geographical location and / or access time of the terminal not being within the pre-configured access permissions, the policy routing control device sends a policy routing deletion instruction for deleting the policy routing of the terminal based on the source IP address to the gateway device.

[0104] In this embodiment, to avoid resource occupation when the terminal has gone offline / disconnected from the network for unknown reasons (the gateway device usually needs to maintain a large number of routing entries), an aging time can be preset. The aging time can be timed after the policy-based routing configuration instruction is issued. During the aging time, if a charging update message is received, the policy-based routing control device determines whether the IP address of the terminal has changed. If it has not changed, the effective state of the policy-based routing is maintained, that is, no message is sent to the gateway device. If the IP address has changed, a policy-based routing update instruction is sent to the gateway device to update the IP address of the terminal in the policy-based routing. At the same time, the aging time is cleared and re-timed. Preferably, since some sensitive applications only allow the terminal to access within a preset geographical location and / or access time, the policy-based routing control device can limit the specified geographical location range and specified time range corresponding to the target network information that can be accessed. For example, it can be set that the terminal can access the company's OA system (target network restriction) during working hours on weekdays (access time restriction) and within City A (geographical location restriction). When the IP address of the terminal changes and the geographical location and / or access time of the terminal are within the pre-configured access permissions, a policy-based routing update instruction is sent to the gateway device; otherwise, a policy-based routing deletion instruction is sent.

[0105] Optionally, the policy-based routing control device sends a policy-based routing deletion instruction for deleting the policy-based routing of the terminal based on the source IP address to the gateway device according to the charging end message, specifically including:

[0106] If the receiving time of the charging end message is within the preset aging time, the policy-based routing control device sends a policy-based routing deletion instruction for deleting the policy-based routing of the terminal based on the source IP address to the gateway device.

[0107] In this embodiment, within the preset aging time, if a charging end message is received, it means that the terminal has gone offline / disconnected from the network normally. At this time, a policy-based routing deletion instruction is immediately sent to the gateway device to delete the policy-based routing corresponding to the terminal.

[0108] Optionally, the method further includes:

[0109] Within the preset aging time, if the charging update message or the charging end message is not received, the policy-based routing control device sends a policy-based routing deletion instruction for deleting the policy-based routing of the terminal based on the source IP address to the gateway device.

[0110] In this embodiment, within a preset aging time, if no charging update message or charging end message is received, it indicates that the terminal has gone offline / disconnected from the network for unknown reasons. To maintain the timeliness of the gateway device and the validity of the policy routing table data, a policy routing deletion instruction is sent to the gateway device to delete the policy routing corresponding to the terminal.

[0111] It should be noted that to solve the problem that policy routing in the prior art lacks adaptability to dynamic source IPs, the present invention can determine the online status / status information of the terminal based on authentication request messages, charging request messages, charging update messages, charging end messages, and the content in the messages, and dynamically manage policy routing through this information. Specifically: 1) Generate the corresponding policy routing when the terminal accesses the network; 2) Continuously maintain the validity of the policy routing as long as the terminal is online and the source IP remains unchanged. If the source IP changes, update the policy routing, or further make a judgment based on the access permission; 3) When the terminal goes offline / disconnects from the network normally (marked by receiving a charging end message within the aging time), delete the policy routing corresponding to the terminal; 4) Also delete the policy routing corresponding to the terminal if no charging update message is received within the aging time (which means the terminal has gone offline / disconnected from the network for unknown reasons), thus avoiding the occupation of invalid policy routing entries in the gateway device. When the terminal accesses the network again, usually the IP address will change. At this time, generate the policy routing again according to the changed source IP address, so as to ensure the dynamic adaptability of the network policy and the efficient utilization of resources.

[0112] In a specific embodiment, the policy routing dynamic management method is applied to the policy routing dynamic management system as Figure 2 shown. The system includes a policy routing control device and a gateway device. The policy routing control device includes an authentication unit and a policy routing management unit; the authentication unit is used to perform access authentication, authorization, and charging on the terminal when accessing the mobile network. The authentication unit receives Radius messages through the Radius interface and passes information such as MSISDN or IMSI in the Radius messages to the policy routing management unit; the policy routing management unit is used to dynamically allocate the policy routing for each legal terminal to access the target network by querying the target network information that can be accessed by the terminal pre-configured in the system, and dynamically manage the policy routing according to the online status of the terminal; the gateway device has functions such as route selection, data forwarding, and network isolation, and can receive the policy routing management instructions sent by the policy routing control device in real time to dynamically manage the routing of the terminal to access the target network.

[0113] Based on Figure 2 the policy routing dynamic management system shown, as Figure 3 shown, the policy routing dynamic management method may include the following steps:

[0114] S1. Construct a policy routing control device and a gateway device, configure their connection relationships with other network elements in the system, and pre-configure the target network information accessible to each terminal.

[0115] Specifically, the constructed policy routing control device includes an authentication unit and a policy routing management unit; the authentication unit is used to perform access authentication, authorization, and accounting for the terminal when accessing the data network; the policy routing management unit is used to dynamically allocate the policy routing of the target network accessible to each legal terminal by querying the target network information accessible to each terminal pre-configured in the system, and dynamically manage the policy routing according to the online status of the terminal. At the same time, it also realizes the dynamic management of the network access permissions of the authorized terminals.

[0116] Preferably, in practical applications, in addition to authenticating and managing the terminals requesting access, the authentication unit also has the ability to manage the status of the online terminals. For example, in addition to being able to perform access authentication and management of the terminal based on information such as the location information, user identity information, device fingerprint, and time point of the terminal, the management personnel can also manually manage the online status of the terminal through the authentication unit, such as forcing the terminal to go offline; in addition, the management personnel can also configure a blacklist or a white list in the authentication unit to enable the authentication unit to manage the specified terminals in a specified manner. Thus, for the legal terminals that have successfully accessed the network after passing the authentication of the authentication unit, the policy routing management unit will dynamically manage the policy routing of the target network for the network access of the terminal. Among them, the policy routing management unit has a configuration interface for the terminal access target network information, and can pre-configure the target network information accessible to each terminal in a manual configuration manner or by receiving through the API interface, including but not limited to information such as the terminal MSISDN, IMSI, target network address, and next-hop gateway IP.

[0117] Specifically, as Figure 4As shown in the figure, the policy routing dynamic management system establishes communication connections with the UPF and the data network respectively, so as to realize the secondary authentication of the terminal and the policy routing control for accessing the target network. For the networking architectures of other network elements, such as AUSF, UDM, AMF, and SMF, etc., mainly include: The user terminal UE communicates with the AMF through the N1 interface; the AMF communicates with the AUSF through the N12 interface, communicates with the UDM through the N8 interface, communicates with the SMF through the N11 interface, and communicates with the RAN through the N2 interface; the AUSF communicates with the UDM through the N13 interface; the UDM communicates with the SMF through the N10 interface; the SMF communicates with the UPF through the N4 interface; the RAN communicates with the UPF through the N3 interface. In this way, before the user terminal UE accesses the data network, it first needs to complete the primary authentication and authorization between the UDM and the AUSF through the AMF; subsequently, when the SMF network element establishes the user plane data channel for it, it will decide whether to initiate the secondary identity authentication according to the subscribed information, that is, to perform the secondary authentication through the SMF, UPF to the policy routing control device.

[0118] S2, use the policy routing control device to receive the access request message and / or update message of the terminal.

[0119] Specifically, the access request message mainly includes an authentication request message and a charging request message; the update message mainly includes a charging message. Of course, in actual applications, other information can also be added as the access request message or update message according to actual needs, so as to improve the accuracy of authentication.

[0120] S3, according to the received access request message and / or update message, query and match the corresponding accessible target network information, generate a policy routing, and send a routing instruction (i.e., a policy routing management instruction) to the gateway device to make it effective.

[0121] S3.1, according to the received access request message and / or update message, information such as the MSISDN, IMSI, temporary IP address, IMEI, and geographical location of the terminal can be obtained.

[0122] Among them, the temporary IP address of the terminal is dynamically allocated, that is, the IP address allocated to the user terminal each time it accesses the network may be different; in addition, the geographical location of the terminal will also change as the position of the terminal moves.

[0123] S3.2, according to the known terminal information, query and match the corresponding accessible target network information, generate the corresponding policy routing, and send a routing instruction to the gateway device.

[0124] It should be noted that the "generation" of the policy routing here not only refers to generating the policy routing from scratch, but also includes dynamically adjusting the existing policy routing.

[0125] Optionally, in actual applications, the terminal can also be authenticated, authorized and billed based on the terminal's status information. Different from AAA's secondary authentication, the access authentication, authorization and billing methods provided in this embodiment can not only authenticate, authorize and bill the terminal on the mobile network side, but also match the accessible target network information based on the terminal's identity information on the mobile network side, and control the terminal's access to the target network, thereby realizing the target network access permissions of the linked control terminal; and can dynamically manage policy routing in the case of dynamic IP, so as to correctly match the corresponding network access permissions of the terminal; in addition, this embodiment does not need to install any software or plug-ins for authentication, and can automatically perform authentication and access policy control based on the terminal card information without user login, that is, no manual participation in the authentication process is required, which improves the convenience and efficiency of authentication.

[0126] Optionally, step S3 may further include:

[0127] S3.3, dynamically maintain the effectiveness of policy routing based on the online status of the terminal.

[0128] Specifically, the online status mainly includes the terminal status represented by the access request message and the billing message, wherein the billing message types mainly include the billing update message and the billing end message. The online status can be determined by the access request message and the billing message, and then the effectiveness of the policy routing is maintained according to the online status of the terminal, including:

[0129] A. When receiving an authentication request message or a billing request message, the policy routing control device generates a policy route according to preset target network information accessible to the terminal, wherein the target network information accessible to the terminal can be pre-collected and stored in the policy routing control device to facilitate the retrieval of corresponding data.

[0130] B. If a billing update message is received within the preset aging time, the policy routing is kept valid or updated, wherein the preset aging time can be reasonably set according to actual needs, and the present invention does not impose any limitation on this.

[0131] C. If no billing update message or billing end message is received within the preset aging time, the policy routing corresponding to the terminal is deleted to ensure the security of network access.

[0132] It should be noted that, in actual application, the access request message and the update message can be sent by the core network session management network element to the policy routing control device in a primary sending manner, that is, Figure 4As shown, the SMF sends the access request message and / or the update message to the policy routing dynamic management system. At this time, the policy routing control device performs access authentication, authorization, and charging on the terminal, and dynamically manages the policy routing for the terminal to access the target network according to the received access request message and / or update message.

[0133] Specifically, in the main delivery mode, in actual application, the process of using the policy routing control device for secondary authentication generally includes: the policy routing control device performs access authentication, authorization, and charging on the terminal, and dynamically manages the routing for the terminal to access the target network according to the received access request message and / or update message.

[0134] It should be noted that in other application processes, the access request message and the update message can also be sent to the policy routing control device in a carbon copy mode. The policy routing control device does not process the access request message and the update message, but only reads the interesting information in the messages. At this time, the policy routing control device only dynamically manages the routing for the terminal to access the target network according to the received access request message and / or update message, and does not participate in the access authentication, authorization, and charging of the terminal.

[0135] Specifically, in the carbon copy mode, in actual application, the access authentication, authorization, and charging of the terminal are all completed by other functional modules in the mobile communication system. The authentication unit of the policy routing control device is only used to receive the terminal access request message and update message (mainly including access authentication message and charging message) carbon copied by other functional modules. The authentication unit extracts the interesting information from these messages to trigger the policy routing management unit to dynamically control the corresponding policy routing for the terminal to access the target network.

[0136] S4. According to the status information of the terminal, use the policy routing control device to finally realize the dynamic management of the access permission of the authorized terminal to the network by dynamically managing the policy routing.

[0137] S4.1. Obtain the geographical location and access time of the authorized terminal.

[0138] Specifically, in actual application, when in the application scenario of a dedicated mobile communication network, the core network needs to main deliver or carbon copy the authentication information and charging information of the access terminal. These information need to carry terminal identity information, location information, time information, terminal IP address, etc. Among them, the identity information includes MSISDN, IMSI, IMEI, etc.

[0139] S4.2. According to the geographical location and access time, the policy routing control device controls the access permission of the terminal to the resources in the data network within the specified geographical location range and specified time range according to the status information of the terminal.

[0140] Specifically, based on the terminal identity information, determine the target network information that the terminal can access, and then generate a policy route based on the source address by combining the terminal IP address. After that, based on the terminal location and access time, be able to dynamically and flexibly control the policy route for the terminal to access the target network within the specified geographical location range and specified time range, thereby controlling the permission of the terminal to access resources in the data network.

[0141] It should be noted that since the IP address of the terminal usually changes each time it accesses the network, it is necessary to dynamically manage the policy route corresponding to the terminal. In this way, on the one hand, it can ensure that a counterfeit terminal uses the IP of a legitimate offline terminal to access resources, and on the other hand, it can ensure that the terminal can match the correct policy route each time it accesses the network to access the corresponding resources.

[0142] S4.3, after the terminal goes offline, the policy route control device immediately deletes the policy route corresponding to the terminal. In this way, by shrinking the network route, the risk of the data network being attacked and invaded is reduced, thus ensuring the security of network access.

[0143] It should be noted that during the process of the terminal accessing the 5G private network, first perform the UDM primary authentication to ensure that the terminal accessing the 5G private network has the access permission, thereby ensuring the security of the 5G private network. For a specific network with higher security requirements (such as: enterprise intranet), if the terminal accesses the above specific network, secondary authentication and dynamic policy route management can be performed using the policy route control device after the terminal accesses the 5G private network, further ensuring the security of the specific network. Specifically, in the actual application process, after the terminal registers for the network and passes the primary authentication, it initiates a PDU session. The 5G terminal secondary identity authentication follows EAP, and the authentication message is carried by the NAS signaling. Among them, the terminal UE is the authenticated end, the SMF network element is the authenticating end, the policy route control device provided by the present invention is used as the authentication server, and at the same time, the gateway device provided by the present invention also serves as the gateway for the terminal to access the data network, and by default, does not load all the routes of the terminal to the intranet.

[0144] It should be noted that through the constructed policy route control device in this embodiment, it is possible to dynamically and flexibly manage the policy route on the mobile network side according to the access request message and / or update message, improving the flexibility of the policy route; at the same time, the policy route control device can replace the existing AAA secondary authentication, realizing the linkage between terminal access authentication and route management, solving the problem that the policy route inherently lacks adaptability to dynamic source IPs, greatly improving the flexibility of route management, and enabling the policy route to be applied in more application scenarios.

[0145] It should be noted that in actual applications, there are the following 4 scenarios:

[0146] (1) When the terminal first accesses the network, after the policy routing control device receives Radius messages (including authentication request messages and charging request messages), it extracts the source IP address information of the terminal from the messages, then generates the corresponding policy routing, and finally configures and distributes the policy routing to the gateway device to make it effective (the gateway device is the executor of the policy routing);

[0147] (2) When the terminal is continuously online, the policy routing control device will continuously receive charging update messages periodically. If it is found in the messages that the source IP address of the terminal has changed, it is necessary to immediately update the policy routing information corresponding to the terminal, and at the same time distribute it to the gateway device to update the policy routing configuration being executed in the gateway device, so that the network access of the terminal is not affected;

[0148] (3) When the terminal goes offline / leaves the network normally, the policy routing control device will receive a charging end message, and immediately send an instruction to the gateway device to delete the policy routing configuration corresponding to the terminal;

[0149] (4) When the terminal has gone offline / left the network for unknown reasons, that is, when the policy routing control device has not received the corresponding charging update / end message for the terminal for a long time (aging time threshold), it is considered that the terminal has gone offline / left the network, and the policy routing information corresponding to the terminal is also sent to the gateway device for deletion. The purpose is to keep the gateway device up-to-date and maintain the validity of the policy routing table data, and avoid wasting additional performance resource overhead due to the device maintaining dirty data.

[0150] In another specific embodiment, the policy routing dynamic management method includes the following steps:

[0151] 1. Build a policy routing control device, configure its connection relationship with other network elements in the system, and pre-configure the target network information that each terminal can access.

[0152] 2. Build a gateway device, which is used to receive the policy routing instructions sent by the policy routing control device, and generate or update or delete policy routing entries; forward network data packets according to the policy routing table to realize data communication between the terminal and the target network.

[0153] It should be noted that the policy routing control device is the control plane, and the gateway device is the data forwarding plane. The policy routing control device has the ability of operation and analysis and is responsible for dynamically maintaining the effectiveness of policy routing; while the configuration information of policy routing needs to be sent to the gateway device for execution to take effect. When the information of policy routing changes, the policy routing control device is responsible for calculating the latest policy routing configuration information and then sending it to the gateway device to update and take effect its configuration. That is, the policy routing control device is in the management role and is also the brain of the whole system, while the gateway device is just an executor, accepting the instructions of the policy routing management device.

[0154] 3. Use the policy routing control device to receive the access request message and / or update message of the terminal.

[0155] Among them, the access request message includes an authentication request message and a charging request message; the update message includes a charging message (i.e., a charging update message and a charging end message); the target network information accessible by the terminal includes the target network address and the next-hop gateway IP address for accessing the target network.

[0156] 4. According to the received access request message and / or update message, query and match the corresponding accessible target network information, generate a policy routing, and send the policy routing instruction to the gateway device.

[0157] (1) According to the received access request message and / or update message, information such as the MSISDN, IMSI, temporary IP address, IMEI, and geographical location of the terminal can be obtained;

[0158] (2) According to the known terminal information, query and match the corresponding accessible target network information, generate the corresponding policy routing. The policy routing is a source address-based policy routing, which guides the data packets from different source IP addresses or source IP address segments to different paths or interfaces for forwarding according to the preset rules. After receiving the data packets, the gateway device will extract the source IP address information therein and match it with the configured policy rules. Once the match is successful, it will determine the forwarding path of the data packets according to the corresponding rules, rather than just forwarding based on the traditional destination IP address and routing table.

[0159] It should be noted that the data packets mentioned here refer to the service traffic of the terminal (user). The task of the gateway device is to process and correctly forward the terminal service traffic according to the policy routing, which is the work of the data forwarding plane. The policy routing control device does not process the terminal service traffic, but only receives the control plane Radius message, and then after calculation, issues instructions to the gateway device to realize the control of the forwarding plane.

[0160] (3) Effectiveness of dynamic maintenance of policy routing based on the online status of the terminal. Among them, the online status includes the terminal status represented by information such as the terminal geographical location and temporary IP address in the access request and charging message, and the types of the charging messages include types such as charging start message, charging update message, and charging end message.

[0161] (a) When receiving an access request or a charging message, the policy routing control device generates a policy routing according to the pre-configured target network information accessible by the terminal;

[0162] (b) If a charging update message is received within the preset aging time, the status of the policy routing remains unchanged or is updated;

[0163] (c) If a charging update message is not received or a charging end message is received within the preset aging time, the corresponding policy routing entry is deleted.

[0164] Among them, the aging time refers to the situation that no charging update message and charging end message corresponding to the terminal are received within a certain time. It should be noted that usually, the access request message and the charging request message (also called the charging start message) are only sent once when the terminal accesses the network and will not be sent again later, and the charging end message is only sent once when the terminal goes offline / leaves the network; only the charging update message is continuously sent periodically.

[0165] Among them, the access request message and the charging update message are sent by the core network session management network element to the policy routing control device in the main delivery mode, or, the access request message and the charging update message are sent to the policy routing control device in the carbon copy mode;

[0166] In the main delivery mode, the policy routing control device performs access authentication, authorization, and charging on the terminal, and dynamically manages the routing of the terminal accessing the target network according to the received access request message and / or update message;

[0167] In the carbon copy mode, the policy routing control device only dynamically manages the routing of the terminal accessing the target network according to the received access request message and / or update message, and does not participate in the access authentication, authorization, and charging of the terminal.

[0168] 5. Dynamically manage and update the policy routing configuration information by using the policy routing control device according to the status information of the terminal.

[0169] (1) Obtain the geographical location and access time of the terminal;

[0170] (2) According to the geographical location and access time of the terminal, the policy routing control device can manage the routing of the terminal accessing the target network within the specified geographical location range and specified time range according to the preset policy.

[0171] It should be noted that the method for dynamically managing policy routing provided by the present invention has the following beneficial effects:

[0172] a) The linkage between terminal access authentication and routing management is realized: In the traditional networking architecture, terminal access authentication and network routing management are separated and the linkage cannot be achieved. The present invention realizes the linkage between terminal access authentication and routing management, solves the problem that policy routing inherently lacks adaptability to dynamic source IPs, can greatly improve the flexibility of routing management, and enables policy routing to be applied in more application scenarios.

[0173] b) The automatic dynamic management of policy routing is realized: The traditional method for managing policy routing is to manage and maintain it through manual configuration by network administrators. As the network scale expands and the number of source IP address segments increases, the configuration of policy routing will become more and more complex, prone to configuration errors or conflicts, increasing the difficulty of network management and maintenance costs. Through the automatic policy routing dynamic management method and system of the present invention, the management difficulty of policy routing can be greatly reduced, the labor cost can be reduced, and the accuracy of policy routing can be improved.

[0174] c) A terminal access security management method based on routing management is proposed: The traditional terminal access security management is realized by means such as access authentication and access control policies. On the one hand, it has relatively high requirements for the capabilities of devices. On the other hand, the access control policy is packet control on the basis of a network routing reachable environment, and there is still a risk of network attacks. The present invention proposes a terminal access security management method based on routing management, realizes network security protection through a deeper routing level, avoids the risk of network attacks from the bottom layer, and greatly improves network security.

[0175] The policy-based routing dynamic management method provided by the embodiments of the present invention. First, the policy-based routing control device receives the access request message and / or update message of the terminal, and sends a policy-based routing management instruction for configuring and / or maintaining the policy-based routing of the terminal based on the source IP address to the gateway device according to the access request message and / or update message; then, the gateway device configures and / or maintains the policy-based routing of the terminal based on the source IP address according to the policy-based routing management instruction, and forwards the network data packets of the terminal based on the policy-based routing. The present invention realizes the automatic configuration and maintenance of the policy-based routing based on the source IP address by automatically receiving and processing the access request message and / or update message of the terminal by the policy-based routing control device, and accordingly sending a policy-based routing management instruction to the gateway device, greatly improving the flexibility of routing management, enabling the policy-based routing to adapt to more application scenarios, and at the same time significantly reducing the difficulty of network management and maintenance costs, and solving the problems that the traditional policy-based routing management method highly depends on manual configuration, resulting in an increase in the difficulty of network management and maintenance costs, and a lack of adaptability in the dynamic source IP scenario.

[0176] Embodiment 2:

[0177] As Figure 5 shown, this embodiment provides a policy-based routing dynamic management system, including a policy-based routing control device 11 and a gateway device 12;

[0178] The policy-based routing control device 11 is used to receive the access request message and / or update message of the terminal;

[0179] The policy-based routing control device 11 is further used to send a policy-based routing management instruction for configuring and / or maintaining the policy-based routing of the terminal based on the source Internet Protocol (IP) address to the gateway device 12 according to the access request message and / or update message;

[0180] The gateway device 12 is used to configure and / or maintain the policy-based routing of the terminal based on the source IP address according to the policy-based routing management instruction, and forward the network data packets of the terminal based on the policy-based routing.

[0181] Optionally, the policy-based routing control device 11 is specifically used to receive the access request message and / or update message of the terminal sent by the Session Management Function (SMF) network element in the main delivery mode; or, receive the access request message and / or update message of the terminal sent by the SMF network element or other functional modules in the carbon copy mode.

[0182] Optionally, if the policy-based routing control device 11 receives the access request message and / or update message of the terminal sent by the SMF network element in the main delivery mode, the policy-based routing control device 11 is further used to perform access authentication, authorization, and accounting on the terminal.

[0183] Optionally, the access request message includes an authentication request message and a charging request message, and the update message includes a charging update message and a charging end message. The policy routing control device 11 is specifically configured to:

[0184] Obtain the accessible target network information corresponding to the terminal according to the authentication request message or the charging request message, generate a policy route for the terminal based on the source IP address according to the accessible target network information, and send a policy route configuration instruction for configuring the policy route of the terminal based on the source IP address to the gateway device 12;

[0185] Send a policy route update instruction and / or a policy route deletion instruction for updating and / or deleting the policy route of the terminal based on the source IP address to the gateway device 12 according to the charging update message;

[0186] Send a policy route deletion instruction for deleting the policy route of the terminal based on the source IP address to the gateway device 12 according to the charging end message;

[0187] The gateway device 12 is specifically configured to:

[0188] Configure the policy route of the terminal based on the source IP address according to the policy route configuration instruction;

[0189] Update the policy route of the terminal based on the source IP address according to the policy route update instruction;

[0190] Delete the policy route of the terminal based on the source IP address according to the policy route deletion instruction.

[0191] Optionally, the policy routing control device 11 is further configured to:

[0192] Obtain the identity information of the terminal from the authentication request message or the charging request message, where the identity information includes at least one of the following: international mobile subscriber integrated services digital network MSISDN, international mobile subscriber identification code IMSI, and international mobile equipment identification code IMEI;

[0193] Query and obtain the pre-configured target network information accessible to the terminal according to the identity information.

[0194] Optionally, the policy routing control device 11 is further configured to:

[0195] If the reception time of the charging update message is within a preset aging time, determine whether the IP address of the terminal has changed;

[0196] In response to the IP address of the terminal not changing, maintain the policy route of the terminal based on the source IP address;

[0197] In response to a change in the IP address of the terminal, and when the geographical location and / or access time of the terminal are within the pre-configured access permissions, send a policy route update instruction for updating the policy route of the terminal based on the source IP address to the gateway device 12;

[0198] In response to a change in the IP address of the terminal, and when the geographical location and / or access time of the terminal are not within the pre-configured access permissions, send a policy route deletion instruction for deleting the policy route of the terminal based on the source IP address to the gateway device 12.

[0199] Optionally, the policy route control device 11 is further configured to:

[0200] If the reception time of the charging end message is within the preset aging time, send a policy route deletion instruction for deleting the policy route of the terminal based on the source IP address to the gateway device 12.

[0201] Optionally, the policy route control device 11 is further configured to:

[0202] Within the preset aging time, if the charging update message or the charging end message is not received, send a policy route deletion instruction for deleting the policy route of the terminal based on the source IP address to the gateway device 12.

[0203] Embodiment 3:

[0204] This embodiment provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the policy route dynamic management method in Embodiment 1 above is implemented.

[0205] The computer storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information such as computer instructions, data structures, computer program modules, or other data. Computer storage media includes, but is not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), digital versatile discs (DVDs) or other optical disc storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.

[0206] In summary, for the policy routing dynamic management method, system, and storage medium provided by the embodiments of the present invention, first, the policy routing control device receives an access request message and / or an update message from a terminal, and sends a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source IP address to the gateway device according to the access request message and / or the update message; then, the gateway device configures and / or maintains the policy routing of the terminal based on the source IP address according to the policy routing management instruction, and forwards the network data packets of the terminal based on the policy routing. The present invention automatically receives and processes the access request message and / or the update message of the terminal through the policy routing control device, and sends a policy routing management instruction to the gateway device accordingly, realizing the automatic configuration and maintenance of the policy routing based on the source IP address, greatly improving the flexibility of routing management, enabling the policy routing to adapt to more application scenarios, and at the same time significantly reducing the difficulty of network management and maintenance costs, and solving the problems that the traditional policy routing management method highly depends on manual configuration, resulting in an increase in the difficulty of network management and maintenance costs, and a lack of adaptability in the dynamic source IP scenario.

[0207] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principle of the present invention, and the present invention is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also regarded as the protection scope of the present invention.

Claims

1. A policy routing dynamic management method, characterized in that: Applied to a policy routing dynamic management system, the policy routing dynamic management system includes a policy routing control device and a gateway device, the method includes: The policy routing control device receives an access request message and / or an update message from a terminal; The policy routing control device sends a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source Internet Protocol IP address to the gateway device according to the access request message and / or update message; The gateway device configures and / or maintains the policy routing of the terminal based on the source IP address according to the policy routing management instruction, and forwards the network data packet of the terminal based on the policy routing.

2. The method according to claim 1, characterized in that: The policy routing control device receives an access request message and / or an update message from a terminal, specifically including: The policy routing control device receives the access request message and / or update message of the terminal sent by the session management function SMF network element in a primary sending manner; or, The policy routing control device receives the access request message and / or update message of the terminal sent by the SMF network element or other functional modules in a copy mode.

3. The method according to claim 2, characterized in that If the policy routing control device receives the access request message and / or update message of the terminal sent by the SMF network element in a main sending manner, the method further includes: Access authentication, authorization and billing are performed on the terminal.

4. The method according to claim 1, characterized in that: The access request message includes an authentication request message and a charging request message, the update message includes a charging update message and a charging end message, and the policy routing control device sends a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source Internet Protocol IP address to the gateway device according to the access request message and / or the update message, specifically including: The policy routing control device obtains the accessible target network information corresponding to the terminal according to the authentication request message or the billing request message, generates a policy routing of the terminal based on the source IP address according to the accessible target network information, and sends a policy routing configuration instruction for configuring the policy routing of the terminal based on the source IP address to the gateway device; The policy routing control device sends a policy routing update instruction and / or a policy routing deletion instruction for updating and / or deleting the policy routing of the terminal based on the source IP address to the gateway device according to the billing update message; The policy routing control device sends a policy routing deletion instruction for deleting the policy routing of the terminal based on the source IP address to the gateway device according to the billing end message; The gateway device configures and / or maintains the policy routing of the terminal based on the source IP address according to the policy routing management instruction, specifically including: The gateway device configures the terminal with a policy routing based on a source IP address according to the policy routing configuration instruction; The gateway device updates the policy routing of the terminal based on the source IP address according to the policy routing update instruction; The gateway device deletes the policy routing of the terminal based on the source IP address according to the policy routing deletion instruction.

5. The method according to claim 4, characterized in that The policy routing control device obtains the accessible target network information corresponding to the terminal according to the authentication request message or the accounting request message, specifically including: Acquire the identity information of the terminal from the authentication request message or the charging request message, wherein the identity information includes at least one of the following: an International Mobile Subscriber Integrated Services Digital Network (MSISDN), an International Mobile Subscriber Identity (IMSI), or an International Mobile Equipment Identity (IMEI); The pre-configured target network information accessible to the terminal is queried and acquired according to the identity information.

6. The method according to claim 4, characterized in that The policy routing control device sends a policy routing update instruction and / or a policy routing deletion instruction for updating and / or deleting the policy routing of the terminal based on the source IP address to the gateway device according to the billing update message, specifically including: If the reception time of the billing update message is within the preset aging time, the policy routing control device determines whether the IP address of the terminal has changed; In response to the IP address of the terminal not being changed, the policy routing control device maintains the policy routing of the terminal based on the source IP address; In response to a change in the IP address of the terminal, and the geographical location and / or access time of the terminal being within a pre-configured access permission, the policy routing control device sends a policy routing update instruction for updating the policy routing of the terminal based on the source IP address to the gateway device; In response to a change in the IP address of the terminal and the geographical location and / or access time of the terminal being not within the pre-configured access rights, the policy routing control device sends a policy routing deletion instruction to the gateway device for deleting the policy routing of the terminal based on the source IP address.

7. The method according to claim 4, characterized in that The policy routing control device sends a policy routing deletion instruction for deleting the policy routing of the terminal based on the source IP address to the gateway device according to the billing end message, specifically including: If the reception time of the charging end message is within the preset aging time, the policy routing control device sends a policy routing deletion instruction for deleting the policy routing of the terminal based on the source IP address to the gateway device.

8. The method according to claim 6, characterized in that The method further comprises: If the billing update message or the billing end message is not received within the preset aging time, the policy routing control device sends a policy routing deletion instruction for deleting the policy routing of the terminal based on the source IP address to the gateway device.

9. A policy routing dynamic management system, characterized in that: Including policy routing control device and gateway equipment; The policy routing control device is used to receive an access request message and / or an update message from a terminal; The policy routing control device is also used to send a policy routing management instruction for configuring and / or maintaining the policy routing of the terminal based on the source Internet Protocol IP address to the gateway device according to the access request message and / or update message; The gateway device is used to configure and / or maintain the policy routing of the terminal based on the source IP address according to the policy routing management instruction, and forward the network data packet of the terminal based on the policy routing.

10. A computer storage medium, characterized in that: The computer storage medium stores a computer program, and when the computer program is executed by the processor, the policy routing dynamic management method according to any one of claims 1 to 8 is implemented.