Information processing method and device, communication equipment and storage medium
By receiving information, determine whether the terminal address is an authorized local route and generates regular routing of data packets to the authorized address, the problem of roaming terminals receiving non-authorized IP addresses is solved, and the security control and control risks of data packets are reduced.
Patent Information
- Application Number
- CN202410048341.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-11
- Publication Date
- 2025-07-11
AI Technical Summary
The roaming terminal may receive an IP address that does not authorize local routing, resulting in departing from the control of the home operator and increasing the control risks.
By receiving information and determining based on the second information whether the first address is an address of authorized local routing, control access behavior, including generating rules to route data packets to the authorized address, and re-sent DNS query to avoid accessing the unauthorized address.
It effectively reduces the risk of terminal access not authorizing local routing, ensures that data packets are routed to authorized addresses, and reduces the risk of control.
Smart Images

Figure CN120302288A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technologies, and particularly relates to an information processing method, apparatus, communication device, and storage medium. Background Art
[0002] A terminal located in a roaming area (or called a visited area) can send a Domain Name System (DNS) query request, which contains information such as a Fully Qualified Domain Name (FQDN). If the terminal sends the DNS query request to a local DNS server, the local DNS server can resolve the Internet Protocol (IP) address of the server corresponding to the FQDN requested by the terminal.
[0003] However, since the local DNS server is deployed in the roaming area, this server may resolve an IP address that does not authorize local routing. If the terminal obtains the IP address returned by the local DNS server, and this address is not an address that can be locally routed or locally accessed authorized by the home operator, it may cause the terminal to access the IP address that does not authorize local routing, getting out of the control of the home operator and increasing the control risk. Summary of the Invention
[0004] Embodiments of this application provide an information processing method, apparatus, communication device, and storage medium to determine whether a first address is an address that authorizes local routing, reducing the control risk.
[0005] In a first aspect, an information processing method is provided, including:
[0006] A first communication device receives first information, and the first information includes a first address;
[0007] The first communication device determines whether the first address is an address that authorizes local routing according to second information.
[0008] In a second aspect, an information processing method is provided, including:
[0009] A second communication device receives a first request, where the first request is used to request the second communication device to send a first query request, the first query request includes a first address, and the first address is an address that does not authorize local routing;
[0010] The second communication device sends the first query request.
[0011] In a third aspect, an information processing method is provided, including:
[0012] The third communication device receives a first rule, where the first rule includes: routing a data packet routed to a first address to a third address, where the first address is an address that does not authorize local routing or is not an address that authorizes local routing;
[0013] When the third communication device receives a first data packet routed to the first address, the third communication device routes the first data packet to the third address.
[0014] In a fourth aspect, an information processing method is provided, including:
[0015] A fifth communication device sends third information to a fourth communication device, where the third information includes an address of a first server for performing domain name resolution;
[0016] Wherein, the address range resolved by the first server is within the range of addresses that authorize local routing, or all the addresses resolved by the first server are addresses that authorize local routing.
[0017] In a fifth aspect, an information processing apparatus is provided, including:
[0018] A first receiving module, configured to receive first information, where the first information includes a first address;
[0019] A first determining module, configured to determine whether the first address is an address that authorizes local routing according to second information.
[0020] In a sixth aspect, an information processing apparatus is provided, including:
[0021] A second receiving module, configured to receive a first request for requesting the second communication device to send a first query request, where the first query request includes a first address that is an address that does not authorize local routing;
[0022] A third sending module, configured to send the first query request.
[0023] In a seventh aspect, an information processing apparatus is provided, including:
[0024] A third receiving module, configured to receive a first rule, where the first rule includes: routing a data packet routed to a first address to a third address, where the first address is an address that does not authorize local routing or is not an address that authorizes local routing;
[0025] A routing module, configured to route the first data packet to the third address when receiving a first data packet routed to the first address.
[0026] In an eighth aspect, an information processing apparatus is provided, including:
[0027] A fifth sending module, configured to send third information to a fourth communication device, where the third information includes an address of a first server, and the first server is used to perform domain name resolution;
[0028] Wherein, the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are addresses of the authorized local route.
[0029] In a ninth aspect, a communication device is provided, and the communication device includes a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented, or the steps of the method described in the fourth aspect are implemented.
[0030] In a tenth aspect, a communication device is provided, including a processor and a communication interface. Wherein, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.
[0031] In an eleventh aspect, a network-side device is provided, and the network-side device includes a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented, or the steps of the method described in the fourth aspect are implemented.
[0032] In a twelfth aspect, a network-side device is provided, including a processor and a communication interface. Wherein, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.
[0033] In a thirteenth aspect, a readable storage medium is provided. The readable storage medium stores a program or instruction. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented, or the steps of the method described in the fourth aspect are implemented.
[0034] In a fourteenth aspect, a wireless communication system is provided, including: a first communication device, or a second communication device, or a third communication device, or a fifth communication device. The first communication device can be used to execute the steps of the method described in the first aspect, the second communication device can be used to execute the steps of the method described in the second aspect, the third communication device can be used to execute the steps of the method described in the third aspect, and the fifth communication device can be used to execute the steps of the method described in the fourth aspect.
[0035] In a fifteenth aspect, a chip is provided. The chip includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect, or to implement the steps of the method described in the third aspect, or to implement the steps of the method described in the fourth aspect.
[0036] In a sixteenth aspect, a computer program / program product is provided. The computer program / program product is stored in a storage medium and is executed by at least one processor to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect, or to implement the steps of the method described in the third aspect, or to implement the steps of the method described in the fourth aspect.
[0037] In an embodiment of the present application, the first communication device receives first information, which includes a first address, and then determines whether the first address is an address authorized for local routing according to second information, and judges whether the first address is an address authorized or not authorized for local routing, so as to control the access behavior to the first address based on different judgment results and reduce the management and control risks. Description of the Drawings
[0038] Figure 1 It is a block diagram of a wireless communication system applicable to an embodiment of the present application;
[0039] Figure 2 It is a schematic structural diagram of a communication system in the related art;
[0040] Figure 3 It is an implementation flowchart of an information processing method in an embodiment of the present application;
[0041] Figure 4 It is a schematic diagram of the processing process of DNS response routing back to the V-SMF corresponding to an embodiment of the present application;
[0042] Figure 5 It is a schematic diagram of the processing process of routing back to the home operator corresponding to an embodiment of the present application;
[0043] Figure 6It is a flowchart of another information processing method in an embodiment of the present application;
[0044] Figure 7 It is a flowchart of another information processing method in an embodiment of the present application;
[0045] Figure 8 It is a flowchart of another information processing method in an embodiment of the present application;
[0046] Figure 9 In an embodiment of the present application, it is related to Figure 3 a schematic structural diagram of an information processing device corresponding thereto;
[0047] Figure 10 In an embodiment of the present application, it is related to Figure 6 a schematic structural diagram of an information processing device corresponding thereto;
[0048] Figure 11 In an embodiment of the present application, it is related to Figure 7 a schematic structural diagram of an information processing device corresponding thereto;
[0049] Figure 12 In an embodiment of the present application, it is related to Figure 8 a schematic structural diagram of an information processing device corresponding thereto;
[0050] Figure 13 a schematic structural diagram of a communication device in an embodiment of the present application;
[0051] Figure 14 a schematic structural diagram of a network - side device in an embodiment of the present application. Detailed implementation manners
[0052] Next, the technical solutions in the embodiments of the present application will be clearly described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application belong to the scope of protection of the present application.
[0053] The terms "first", "second", etc. in this application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, so that the embodiments of this application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects. For example, the first object can be one or more. In addition, "or" in this application means at least one of the connected objects. For example, "A or B" covers three scenarios, namely, Scenario 1: including A and not including B; Scenario 2: including B and not including A; Scenario 3: including both A and B. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.
[0054] The term "indication" in this application can be either a direct indication (or an explicit indication) or an indirect indication (or an implicit indication). Among them, a direct indication can be understood as that the sender clearly informs the receiver of specific information, operations to be performed, request results, etc. in the sent indication; an indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or makes a judgment and determines the operations to be performed or request results, etc. according to the judgment result.
[0055] It is worth pointing out that the technology described in the embodiments of this application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, and can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in the embodiments of this application are often used interchangeably, and the described technology can be used in the above-mentioned systems and radio technologies, as well as in other systems and radio technologies. The following description describes the New Radio (NR) system for example purposes, and uses NR terms in most of the following descriptions, but these technologies can also be applied to systems other than the NR system, such as the 6th generation (6 thGeneration, 6G) communication system.
[0056] Figure 1Block diagram of a wireless communication system to which embodiments of the present application can be applied. The wireless communication system includes a terminal 11 and a network-side device 12. Among them, the terminal 11 can be a mobile phone, a tablet personal computer, a laptop computer, a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device, a flight vehicle, a vehicle user equipment (VUE), a shipborne device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, TVs, washing machines, or furniture), a game console, a personal computer (PC), a teller machine, or a self-service machine, etc. Wearable devices include: smart watches, smart bracelets, smart earphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart ankle chains, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle user equipment can also be referred to as a vehicle terminal, a vehicle controller, a vehicle module, a vehicle component, a vehicle chip, or a vehicle unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiments of the present application. The network-side device 12 can include an access network device or a core network device. Among them, the access network device can also be referred to as a radio access network (RAN) device, a radio access network function, or a radio access network unit. The access network device can include a base station, a wireless local area network (WLAN) access point (AP), or a wireless fidelity (WiFi) node, etc.Among them, the base station may be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home Node B (HNB), home evolved Node B, Transmission Reception Point (TRP), or some other suitable term in the art. As long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiments of this application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
[0057] The core network device may include but is not limited to at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), Network Data Analytics Function (NWDAF), etc. It should be noted that in the embodiments of this application, only the core network devices in the NR system are taken as examples for introduction, and the specific types of core network devices are not limited.
[0058] It should be noted that in the embodiments of this application, the first communication device to the fifth communication device may be at least one or more of the core network devices, or at least one or more of the terminals and base stations.
[0059] In the embodiments of the present application, the visited place can be understood as or equivalent to the visited location.
[0060] In the embodiments of the present application, authorizing or not authorizing can be equivalent to permitting or not permitting, or, licensing or not licensing; and for authorizing or not authorizing local routing, it can also be understood as or equivalent to the following concepts:
[0061] Permitting or not permitting local routing;
[0062] Permitting or not permitting local traffic splitting;
[0063] Permitting or not permitting home routed session breakout (HR-SBO);
[0064] Permitting or not permitting routing to the local data network;
[0065] Licensing or not licensing HR-SBO;
[0066] Licensing or not licensing local traffic splitting;
[0067] Licensing or not licensing local routing;
[0068] Licensing or not licensing routing to the local data network.
[0069] For ease of understanding, the related technologies and concepts involved in the embodiments of the present application are introduced first.
[0070] I. EASDF
[0071] As Figure 2 shown, the communication system in the related technology includes: network elements such as EASDF, NWDAF, SMF, AMF, NRF, PCF, AF, UDM, etc., as well as user equipment (UE, also known as the terminal), access network (AN), UPF (uplink classifier (UL CL) / branching point (BP)), UPF (central protocol data unit (PDU) session anchor (PDU Session Anchor, PSA) (C-PSA)), UPF (local PSA (L-PSA)), central domain name (Domain Name, DN), local DN, edge application server (Edge application server, EAS), etc.
[0072] EASDF is a 3GPP core network element proposed by SA2 to handle DNS query requests sent by User Equipment (UE, also known as the terminal).
[0073] In the related art, the terminal sends a DNS query request to EASDF. EASDF determines whether to send the DNS query request to the Center-DNS (C-DNS) or the Local-DNS (L-DNS) based on the DNS query request, and then sends information such as the Fully Qualified Domain Name (FQDN) in the DNS query request to the SMF; the SMF provides the Internet Protocol (IP) address of the corresponding DNS server for EASDF, such as the IP address of the C-DNS or the L-DNS; after the C-DNS or the L-DNS finds the IP address corresponding to the FQDN, it sends it to EASDF; after EASDF saves the DNS query result to the SMF, it sends it to the terminal. In this way, the terminal obtains the IP address of the server corresponding to the requested FQDN.
[0074] II. Roaming traffic diversion
[0075] The home operator, that is, the Home Public Land Mobile Network (HPLMN), will authorize the roaming operator, that is, the HR-SBO of the Visited Public Land Mobile Network (VPLMN). After authorizing the HR-SBO, the roaming operator can directly divert the traffic of some terminals to the home operator's server without routing back to the HPLMN through the Home Routing Session (HR session).
[0076] After the HR-SBO is authorized, the HPLMN can send a list of authorized FQDNs and a list of EASIPs.
[0077] In the embodiments of the present application, authorization can also be understood as permission, or allowance, or consent for the roaming operator to perform traffic diversion.
[0078] FQDN list: This list includes a list of domain names that allow the EASDF in the roaming area to perform DNS queries. For FQDNs that do not allow the EASDF in the roaming area to perform DNS queries, they must be sent back to the home operator for DNS query or resolution.
[0079] EASIP List: This list includes the IP addresses of servers that allow the roaming terminal to directly access locally or route data locally. For servers that do not allow the roaming terminal to directly access locally or route data locally, establishing a route is not allowed. It can also be understood that the IP addresses in this list are the servers that the roaming terminal can access through the roaming network, local routing, or local access, or the IP addresses in this list are the servers that the roaming terminal cannot access through the roaming network, local routing, or local access.
[0080] The visited SMF (V-SMF) obtains the authorized IP address range from the home SMF (H-SMF). That is to say, only within this IP address range is local breakout authorized, and only then is the V-SMF authorized to directly establish a visited user plane connection to the EAS IP.
[0081] The above mechanism in the related art is applicable to the scenario where the terminal sends a DNS query request to the visited EASDF (V-EASDF), but there is no clear regulation for the scenario where the terminal sends a DNS query request to the local DNS server (localDNSserver).
[0082] The related technologies and concepts involved in the embodiments of the present application are introduced above. Next, in combination with the accompanying drawings, the information processing method provided by the embodiments of the present application will be described in detail through some embodiments and their application scenarios.
[0083] See Figure 3 As shown, it is a flowchart of the implementation of an information processing method provided by the embodiments of the present application. The method includes the following steps:
[0084] S310: The first communication device receives the first information, and the first information includes the first address;
[0085] S320: The first communication device determines whether the first address is an address authorized for local routing according to the second information.
[0086] Applying the method provided by the embodiments of the present application, the first communication device receives the first information, which includes the first address, and then determines whether the first address is an address authorized for local routing according to the second information, and judges whether the first address is an address authorized or not authorized for local routing, so as to control the access behavior to the first address based on different judgment results and reduce the management and control risks.
[0087] The technical solutions provided by the embodiments of the present application can be applied to scenarios such as DNS query and network access by terminals in the visited area.
[0088] In an embodiment of the present application, the first communication device may be a network element related to roaming session management, such as a V-SMF.
[0089] The first communication device may receive first information, which includes a first address. The first address may be an IP address or an FQDN.
[0090] It should be noted that, in an embodiment of the present application, the address is used to describe information about a server, and it may be an IP address or a domain name FQDN.
[0091] Optionally, the first information may be a first DNS response, which carries the first address. The first address includes the FQDN and IP address of the server. The first address may be resolved by the first local DNS server for the first DNS query request. The first communication device may receive the first information from the second communication device or the third communication device. The second communication device may be a network element related to roaming edge application services, such as a V-EASDF, and the third communication device may be a network element related to the roaming user plane, such as a V-UPF.
[0092] For example, a possible implementation process is as follows:
[0093] After the terminal obtains the address of the first local DNS server, it may send a DNS query request to the third communication device;
[0094] The third communication device forwards the DNS query request to the first local DNS server;
[0095] After the first local DNS server resolves the first address, it sends a DNS response including the first address to the terminal;
[0096] After the third communication device detects the DNS response sent by the first local DNS server, it may send the DNS response to the second communication device, and then the second communication device forwards it to the first communication device. Alternatively, the third communication device sends the DNS response to the first communication device.
[0097] In one embodiment, the V-SMF sets a rule for the V-UPF, such as the N4 rule. All information received from the first local DNS server (such as the local DNS server in the roaming area), such as the received DNS response, needs to be forwarded to the V-EASDF (first forwarded to the V-EASDF and then to the V-SMF) or the V-SMF first. The V-EASDF or the V-SMF needs to judge the IP address of the server carried in the DNS response, such as the EAS IP address, to determine whether the IP address is an authorized local routing address.
[0098] In this way, the first communication device can receive a DNS response, i.e., the first information, from the second communication device or the third communication device, and the first information includes a first address.
[0099] After receiving the first information, the first communication device can determine whether the first address is an address authorized for local routing according to the second information.
[0100] The second information can be configured by the fifth communication device, and the fifth communication device is a network element related to home session management, such as an H-SMF. The first communication device can receive the second information from the fifth communication device.
[0101] In one implementation, the H-SMF sends the second information to the V-SMF through at least one of the following signaling:
[0102] Nsmf_PDUSession_Createresponse, PDU session creation response;
[0103] Nsmf_PDUSession_Updateresponse, PDU session update response.
[0104] The second information can include at least one of the following:
[0105] Address authorized for local routing;
[0106] Address not authorized for local routing;
[0107] At least one third address.
[0108] Among them, there can be one or more addresses authorized for local routing. Authorized local routing can also be understood as authorized local traffic splitting, authorized routing to the local data network, etc. There can be one or more addresses not authorized for local routing. Not authorized local routing can also be understood as not authorized local traffic splitting, not authorized routing to the local data network, etc.
[0109] It should be noted that in the embodiments of the present application, "authorized" and "allowed" are similar in meaning and can be replaced with each other.
[0110] Based on the address authorizing local routing included in the second information or the address not authorizing local routing, the first communication device can accurately determine whether to authorize local routing to the first address. It can also be understood that the first communication device compares the first address with the list of addresses authorizing local routing in the second information. If the first address can be found in this list, then the first address is considered an authorized local routing address. Similarly, if the first address is found in the list of addresses not authorizing local routing in the second information, then the first address is considered an unauthorized address. Judging whether the first address is an address authorizing or not authorizing local routing is convenient for controlling the access behavior to the first address based on different judgment results and reducing the management and control risks.
[0111] In one implementation, at least one third address may include at least one of the following:
[0112] The server IP address, which may be the local server address at the roaming location, may also be a non-local address at the roaming location, or may be a server IP address within the home operator network;
[0113] The HPLMN address;
[0114] The HPLMN UPF address;
[0115] The N9 tunnel information of the HPLMN UPF.
[0116] In one implementation, the third address is an address authorizing local routing.
[0117] The role of the third address is provided by the home operator to indicate to the visited operator how to handle unauthorized addresses. In one implementation, if the first address is an address not authorizing local routing, then the third address gives the processing method for the first address, that is, changing the data packet sent to the first address to be sent to the third address. Equivalently, if the first address is a server that cannot be locally routed, then the data packet sent to this server will have its IP address modified by the V-UPF and sent to the third address, thus solving the problem and enabling the data packets sent to unauthorized addresses to be forwarded to authorized addresses after being recognized.
[0118] In one implementation, at least one of the non-authorized local routing addresses corresponds to at least one third address. Multiple non-authorized local routing addresses can correspond to one third address, or one non-authorized local routing address can correspond to one third address or multiple third addresses. Here, the so-called "correspondence" means that for a data packet sent to a non-authorized local routing address, the non-authorized local routing address will be replaced by the third address. That is to say, there is a correspondence relationship or an association relationship between the non-authorized local routing address and the third address. This association relationship is that the third address is used to replace the non-authorized local routing address of the data packet, and the third address is used as the new destination IP address of the data packet to replace the old destination IP address (i.e., the non-authorized local routing address).
[0119] In one implementation, the H-SMF can instruct the V-SMF of the third address corresponding to each non-authorized local routing address.
[0120] In one implementation, the UPF can identify the first address by executing a Packet Detection Rule (PDR); the UPF forwards the data packet sent to the first address to the third address through a Forwarding Action Rule (FAR). The UPF can also perform an IP address replacement operation. When a data packet is sent to a server with the first address as the destination address, the UPF replaces the destination address with the third address, and then the UPF sends the data packet to the server corresponding to the third address.
[0121] In some embodiments of the present application, when the first communication device determines that the first address is an authorized local routing address, the first communication device can send first indication information to the second communication device or the third communication device. The first indication information is used to instruct the second communication device or the third communication device to send the first information to the fourth communication device, such as a terminal. That is to say, after the first communication device determines that the first address is an authorized local routing address, the first communication device instructs the second communication device or the third communication device to send the first information to the terminal. After receiving the first indication information, the second communication device can send the first information to the third communication device, and then the third communication device sends the first information to the fourth communication device, such as a terminal. Or, the third communication device receives the first indication information from the first communication device and sends the first information to the fourth communication device, such as a terminal. In this way, the data packet of the fourth communication device can be locally routed to the first address.
[0122] In the embodiments of the present application, the V-UPF is the user plane at the roaming location and can also be equivalent to the UPF, with no difference in function.
[0123] In one implementation, when a third communication device, such as a V-UPF, receives a first piece of information, such as a DNS response, the V-UPF caches the DNS response; alternatively, the V-UPF makes a copy of the DNS response and sends it to the V-EASDF or the V-SMF. When the V-UPF receives the first indication information, the V-UPF then sends the first piece of information to the terminal, or the V-UPF sends the cached first piece of information to the terminal.
[0124] In some embodiments of the present application, in the case where the first communication device determines that the first address is an address not authorized for local routing or determines that the first address is not an address authorized for local routing, the method may further include the following steps:
[0125] The first communication device sends a first request to the second communication device, and the first request is used to request the second communication device to send a first query request;
[0126] Wherein, the first query request includes the first address.
[0127] In an embodiment of the present application, in the case where the first communication device determines that the first address is an address not authorized for local routing or determines that the first address is not an address authorized for local routing, the first communication device may send a first request to the second communication device, requesting the second communication device to send a first query request, and the first query request includes the first address. After receiving the first request, the second communication device may send the first query request.
[0128] In one implementation, if the V-SMF determines that the first address is an address not authorized for local routing or determines that the first address is not an address authorized for local routing, the V-SMF sends an EASDF DNS context update request (Neasdf_DNSContext_Update Request) to the V-EASDF, and the request includes the first address, or the second address. For example, the first address is the FQDN corresponding to the address not authorized for local routing, and the second address is the address of the DNS server that resolves the FQDN.
[0129] Optionally, the second communication device may send the first query request to the default DNS server or send the first query request to the home EASDF (H-EASDF). The second communication device may receive the re-query obtained address, such as address A, from the default DNS server or H-EASDF. The first query request contains the first address, and at this time, the first address is the FQDN, that is, the domain name corresponding to the address that does not authorize local routing. Optionally, the second communication device may return address A to the first communication device. The first communication device replaces the first address with address A, updates the first information, and then sends the updated first information to the fourth communication device, such as a terminal, through the second communication device or the third communication device. Alternatively, the second communication device may send address A to the third communication device, and the third communication device sends it to the fourth communication device, such as a terminal. After obtaining address A, the fourth communication device may send a data packet to address A.
[0130] Optionally, the first request may include a second address, and the second address is the address of the device that receives the first query request. The second address can be understood as follows: when it is determined that the address is not an authorized local routing address, a DNS query is re-initiated, and this DNS query needs to be sent to the second address. The second address may be the DNS server of the home operator, such as H-EASDF, or the localDNS server, or the HPLMNUPF address, or other addresses, etc.
[0131] In one implementation, the second address is also sent to the visited location through the second information, that is, the second address is also provided by the H-SMF or HPLMN to the visited operator or provided to the V-SMF.
[0132] In one implementation, the V-SMF generates or configures a rule for the UPF according to the second information (according to the address that does not authorize local routing in the second information): when the UPF detects an unauthorized IP address or a DNS response, the UPF needs to send the DNS response to the V-EASDF or V-SMF.
[0133] The V-SMF sends an N4 rule, which includes a PDR: when it detects an unauthorized IP address, or a DNS response, or a data packet (DNS response) sent from the local DNS server, and when any one of the above three is received, the V-UPF executes a FAR to forward the data packet to the V-SMF or V-EASDF.
[0134] In another embodiment, when the V-SMF or V-EASDF determines that the first address is an unauthorized local routing address, the V-SMF does not perform a secondary DNS query. Instead, based on the third address corresponding to the first address, the routing in the V-UPF is changed to: when a data packet sent to the first address is received, the V-UPF forwards it to the H-UPF or to the home operator to avoid accessing an unauthorized address locally.
[0135] That is, the first communication device includes a second address in the first request sent to the second communication device, so that the second communication device can clearly identify the receiving device of the first query request.
[0136] In the embodiments of the present application, when the first communication device determines that the first address is an unauthorized local routing address or determines that the first address is not an authorized local routing address, it requests the second communication device to perform a re-query instead of indicating the first address to the fourth communication device, such as a terminal, which can avoid the fourth communication device sending data packets to the unauthorized local routing first address and reduce the control risk.
[0137] For ease of understanding, taking the Figure 4 flowchart shown as an example, the technical solution provided by the embodiments of the present application is described again.
[0138] Step 0: The terminal obtains the address of the first local DNS server; the V-SMF configures a routing rule for the V-UPF (or UL CL), that is, if the FQDN included in the DNS query request is in the FQDN list, the DNS query request can be routed to the local DNS server, otherwise, it is routed to the HPLMN;
[0139] Step 1: The terminal sends a DNS query request to the V-UPF;
[0140] Step 2: The V-UPF forwards the DNS query request to the first local DNS server;
[0141] Step 3: The first local DNS server resolves an EAS IP address and then sends a DNS response to the terminal; this EAS IP address may be an unauthorized local routing address;
[0142] Step 4: When the V-UPF detects the DNS response sent by the first local DNS server, it can perform the following actions:
[0143] The V-UPF sends the DNS response to the V-EASDF (pre-configured);
[0144] Or, the V-UPF sends the DNS response to the V-SMF (pre-configured).
[0145] In one implementation, if the V-UPF sends the DNS response to the V-EASDF, the V-EASDF continues to send the DNS response to the V-SMF. That is, ultimately, the V-SMF determines whether the EAS IP address is an authorized local routing address;
[0146] In one implementation, the V-EASDF can also determine whether the EAS IP address is an authorized local routing address.
[0147] Step 5: The V-SMF determines whether the EAS IP address can be locally shunted based on the authorized local routing address range or address list sent by the H-SMF, or determines whether the EAS IP address is an authorized local routing address;
[0148] Step 6: If the EAS IP address can be locally shunted or is an authorized local routing address, the V-SMF can instruct the V-UPF to send the DNS response to the terminal; or instruct the V-EASDF to send the DNS response to the terminal through the V-UPF;
[0149] Step 7: If the EAS IP address cannot be locally shunted or is not an authorized local routing address, the V-SMF can instruct the V-EASDF to use the FQDN in the DNS response to send the DNS query request to the default DNS server, or send it back to the H-EASDF in the HPLMN for re-querying, so as to replace the EAS IP address with the result obtained from the re-query and send it to the terminal.
[0150] It should be noted here that the source IP address of the DNS response sent to the terminal in Step 6 or Step 7 needs to be replaced with the IP address of the first local DNS server, that is, it is considered that the address is still resolved by the first local DNS server.
[0151] Through the above operations, the V-SMF can determine whether the EAS IP address included in the DNS response is an authorized local routing address, and then determine whether to perform re-querying according to the judgment result, which can effectively prevent the terminal from accessing unauthorized local routing addresses.
[0152] In some embodiments of the present application, in the case where the first communication device determines that the first address is an unauthorized local routing address or the first address is not an authorized local routing address, the method may further include the following steps:
[0153] The first communication device generates a first rule according to the second information;
[0154] Wherein, the first rule includes:
[0155] Route the data packet routed to the first address to the third address.
[0156] In an embodiment of the present application, the second information may include at least one of an address for authorizing local routing, an address for not authorizing local routing, and at least one third address. Among them, there is an association relationship between the address for not authorizing local routing and at least one third address. For example, the addresses for not authorizing local routing included in the second information are Address B and Address C, and the third addresses included in the second information are Third Address D and Third Address E. Among them, there is an association relationship between Address B and Third Address D, and there is an association relationship between Address C and Third Address D and Third Address E. As described above, the association relationship here means that the third address is used to replace the address for not authorizing local routing as the destination address for terminal communication; or, in the way of adding a packet header, the third address is used as the destination address and added to the outside of the data packet sent to the first address as the packet header.
[0157] The first communication device receives the first information, and the first information includes the first address. If it is determined that the first address is an address for not authorizing local routing or it is determined that the first address is not an address for authorizing local routing, the first communication device may generate a first rule according to the second information. The first rule includes routing the data packet routed to the first address to the third address. For example, if the first address is Address C, the generated first rule may include: routing the data packet routed to Address C to Third Address D or Third Address E. This can effectively avoid accessing the first address for not authorizing local routing.
[0158] In some embodiments of the present application, the first communication device may send the first rule to the third communication device.
[0159] When the first communication device determines that the first address is an address for not authorizing local routing or determines that the first address is not an address for authorizing local routing, it may generate a first rule according to the second information and send the first rule to the third communication device, so that the third communication device processes the data packet sent to the first address according to the first rule.
[0160] In some embodiments of the present application, the third communication device may receive the first rule. The first rule includes: routing the data packet routed to the first address to the third address; when the third communication device receives the first data packet routed to the first address, it routes the first data packet to the third address.
[0161] In the embodiment of the present application, the first communication device can determine whether the first address included in the first information is an address authorized for local routing. If it is determined that the address is not an address authorized for local routing, the first communication device can generate a first rule according to the second information and send the first rule to the third communication device. Optionally, in this case, the first communication device can also instruct the second communication device or the third communication device to send the first information to the fourth communication device, such as a terminal. Alternatively, the third communication device can send the first information to the fourth communication device, such as a terminal, before, after, or at the same time as sending the first information to the first communication device. The fourth communication device obtains the first address included in the first information and can send a data packet to the first address.
[0162] The third communication device can receive the first rule from the first communication device and, according to the first rule, know that the data packet routed to the first address needs to be routed to the third address.
[0163] The data packet sent by the fourth communication device, such as a terminal, to the first address will pass through the third communication device. When the third communication device receives the first data packet routed to the first address, it can route the first data packet to the third address, and the service is actually provided by the server corresponding to the third address. This can effectively avoid accessing the first address that is not authorized for local routing or avoid local routing to the first address, reducing the control risk.
[0164] For example, the first communication device is a V-SMF, the third communication device is a V-UPF, and the fourth communication device is a terminal. The V-SMF can default-configure an EAS IP address authorized for local routing for the V-UPF for a FQDN. The information on which this configuration is based is sent by the H-SMF to the V-SMF. It is equivalent to the H-SMF sending a list. If the first address included in the first information received by the V-SMF is an EAS IP address that is not authorized for local routing in this list, then an operation of replacing the first address is required. That is, when the terminal sends a data packet to an IP address that is not authorized for local routing, the V-UPF performs an IP address replacement according to the configuration of the V-SMF. For example, the EAS IP address 1 that is not authorized for local routing is replaced with the EAS IP address 2 that is authorized for local routing, and the data packet of the terminal is routed to the EAS IP address that meets the requirements.
[0165] That is to say, when the terminal performs a DNS query, if the queried address is the address of the authorized local route, the data packets of the terminal can be locally shunted. If the queried address is not the address of the authorized local route, the terminal normally sends data packets to this address, and the V-UPF replaces the destination IP of its data packets. The terminal is unaware of this process and still believes that the data packets are obtained from an unauthorized address, but the server actually serving the terminal has been replaced with the server corresponding to the third address. This can effectively prevent the terminal from accessing an address that is not an authorized local route.
[0166] Optionally, the third address may include the address of the home communication device, or the address of the roaming communication device, or the address of the authorized local route.
[0167] If the third address is the address of the authorized local route, the third communication device can route the data packets routed to the first address that is not an authorized local route to the third address of the authorized local route.
[0168] The third address may be another server in the roaming area. For example, it is a server with the same domain name as the server corresponding to the first address but a different IP address.
[0169] If the third address includes the address of the home communication device, such as the H-UPF, the third communication device can route the data packets routed to the first address that is not an authorized local route back to the home operator and send them to the first address through the N6 interface of the home operator. The third address may be the address of the H-UPF, the address of the HPLMN, etc.
[0170] In some embodiments of the present application, the method may further include the following steps:
[0171] Step 1: The third communication device receives a second data packet from the third address;
[0172] Step 2: The third communication device sends the second data packet to the fourth communication device.
[0173] That is, in the case where the first address is not an authorized local route address or the first address is not the address of the authorized local route, when the third communication device receives the first data packet routed to the first address, it routes the first data packet to the third address. The communication device corresponding to the third address can return the second data packet. After the third communication device receives the second data packet from the third address, it can send the second data packet to the fourth communication device. From the perspective of the fourth communication device, the fourth communication device is interacting with the communication device corresponding to the first address.
[0174] For ease of understanding, the embodiments of the present application are described through the following specific examples.
[0175] When the V-UPF receives a data packet destined for the EAS IP A with unauthorized local routing, it routes this data packet to the H-UPF, and then accesses this EAS IP A from the N6 of the HPLMN. This is equivalent to taking a detour and still accessing a server through the home network, rather than directly accessing the server from the roaming network through the local N6 interface.
[0176] As Figure 5 shown, a possible implementation process is as follows:
[0177] Step 1: The V-UPF receives a data packet destined for the EAS IP address with unauthorized local routing;
[0178] Step 2: The V-UPF executes the Forwarding Action Rule (FAR) to perform an outer header creation operation on the received data packet, adding a packet header with the destination address being the address of the H-UPF or the address of the HPLMN to route the data packet to the H-UPF (which can also be considered as IP address replacement);
[0179] Step 3: The V-UPF sends the data packet with the added packet header to the H-UPF;
[0180] Step 4: After receiving the data packet, the H-UPF executes the Packet Detection Rule (PDR) to perform an outer header removal operation on the data packet, removing the packet header added by the V-UPF; the rules of the H-UPF are provided by the H-SMF;
[0181] Step 5: If it is found that the data packet after removing the packet header is destined for the EAS IP address, the H-UPF routes it out from the data network of the home operator in the normal way, that is, routes the data packet to the EAS IP address normally, such as sending it through the N6 interface of the home operator.
[0182] Optionally:
[0183] When the H-UPF receives a data packet from the EAS IP address, the H-UPF adds a packet header to the data packet, adding the address of the destination V-UPF to the data packet header, and routes the data packet to the V-UPF;
[0184] After receiving the data packet, the V-UPF performs an outer header removal operation on the received data packet and routes the data packet back to the terminal side.
[0185] In the embodiments of the present application, if the first address is an address that does not authorize local routing, the third communication device routes the received data packet destined for the first address back to the home operator and accesses the first address through the N6 interface of the home operator, so that the access to the first address is within the controlled range, effectively reducing the control risk.
[0186] Corresponding to the above method embodiments, the embodiments of the present application also provide an information processing method, as Figure 6 shown, the method includes the following steps:
[0187] S610: The second communication device receives a first request, where the first request is used to request the second communication device to send a first query request, and the first query request includes a first address, and the first address is an address that does not authorize local routing;
[0188] S620: The second communication device sends the first query request.
[0189] Applying the method provided by the embodiments of the present application, after the second communication device receives the first request, it sends the first query request according to the first request. The first query request includes the first address that does not authorize local routing, that is, in the case where the first address is an address that does not authorize local routing, the address query is re-performed to avoid accessing the first address that does not authorize local routing and reduce the control risk.
[0190] In some embodiments of the present application, the first request includes a second address, and the second address is the address of the device that receives the first query request.
[0191] The information processing method provided by the embodiments of the present application can implement Figure 3 each process implemented by the method embodiments shown and achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0192] Corresponding to the above method embodiments, the embodiments of the present application also provide an information processing method, as Figure 7 shown, the method includes the following steps:
[0193] S710: The third communication device receives a first rule, and the first rule includes: routing the data packet routed to the first address to the third address, where the first address is an address that does not authorize local routing or is not an address that authorizes local routing;
[0194] S720: When the third communication device receives the first data packet routed to the first address, it routes the first data packet to the third address.
[0195] Applying the method provided in the embodiments of the present application, when the third communication device receives a first data packet routed to a first address that does not authorize local routing according to a first rule, the third communication device routes the first data packet to a third address, so as to effectively avoid local routing to the first address and reduce the control risk.
[0196] In some embodiments of the present application, the first rule is generated according to second information, and the second information includes at least one of the following:
[0197] An address that authorizes local routing;
[0198] An address that does not authorize local routing;
[0199] At least one third address.
[0200] In some embodiments of the present application, there is an association relationship between the address that does not authorize local routing and at least one third address.
[0201] In some embodiments of the present application, the third address includes the address of the home communication device, or the address of the roaming communication device, or the address that authorizes local routing.
[0202] In some embodiments of the present application, the method further includes:
[0203] The third communication device receives a second data packet from the third address;
[0204] The third communication device sends the second data packet to the fourth communication device.
[0205] The information processing method provided by the embodiments of the present application can implement Figure 3 each process implemented by the method embodiment shown, and achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0206] The embodiments of the present application further provide an information processing method, as Figure 8 shown, and the method includes the following steps:
[0207] S810: The fifth communication device sends third information to the fourth communication device, and the third information includes the address of the first server, and the first server is used to perform domain name resolution;
[0208] Wherein, the address range resolved by the first server is within the address range that authorizes local routing, or all the addresses resolved by the first server are addresses that authorize local routing.
[0209] In one implementation, the first server may be EASDF, a local DNS server, or just a DNS server. This server has the following characteristics: the server addresses resolved are all addresses that authorize local routing.
[0210] Applying the method provided by the embodiment of the present application, a fifth communication device sends third information to a fourth communication device. The third information includes the address of a first server, and the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are the addresses of the authorized local route. In this way, when the fourth communication device sends a query request to the first server, the address resolved by the first server can be the address of the authorized local route, effectively avoiding the fourth communication device from accessing an address that is not an authorized local route and reducing the management and control risk.
[0211] In the embodiment of the present application, the fifth communication device may be a home subscriber session management related network element, such as an H-SMF, and the fourth communication device may be a terminal or a V-SMF.
[0212] In one implementation, the H-SMF sends the third information to the V-SMF, and the V-SMF sends the third information to the terminal.
[0213] The fifth communication device determines the first server according to at least one of the following:
[0214] Edge Deployment Information (EDI); the EDI includes an IP address range, the IP address range that each DNS server can resolve, or the IP address range corresponding to each Data Network Access Identifier (DNAI).
[0215] The fifth communication device compares the address of the authorized local route with the IP address range in the EDI information. The IP address range in the EDI should be within the address range of the authorized local route.
[0216] For example, the EDI information gives an IP range of 100.1.1.1 - 100.1.1.100; if the authorized address range sent by the H-SMF is smaller than the IP range of the EDI, then it is possible to resolve an unauthorized IP address because the IP address range given by the EDI is the entire IP address range of the roaming local area.
[0217] When the fourth communication device is in the roaming area, the fifth communication device may send third information to the fourth communication device. The third information includes the address of a first server, such as the address of a first local DNS server.
[0218] The fourth communication device may send a DNS query request to the first server. The first server performs domain name resolution according to the DNS query request to obtain a corresponding address, and then returns a DNS response to the fourth communication device. The DNS response includes the query / resolved address.
[0219] The address range resolved by the first server assigned by the fifth communication device to the fourth communication device is within the address range of the authorized local route. Therefore, the address resolved by the first server is the address of the authorized local route. Or all the addresses resolved by the first server are the addresses of the authorized local route. This can ensure that when the fourth communication device is in the roaming area, the addresses locally routed to are all the addresses of the authorized local route, avoiding access to the addresses of the unauthorized local route and reducing the control risk.
[0220] In some embodiments of the present application, the method may further include:
[0221] The fifth communication device determines the first server according to at least one of the following:
[0222] The address range of the authorized local route;
[0223] The address range of the unauthorized local route;
[0224] The address range resolvable by at least one server.
[0225] It can be understood that the address ranges resolvable by different servers for performing domain name resolution may be the same or different. The fifth communication device can accurately determine the first server to be assigned to the fourth communication device according to the address range of the authorized local route or the address range of the unauthorized local route or the address range resolvable by at least one server, ensuring that the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are the addresses of the authorized local route.
[0226] For example, if the EAS IP range 100.1.X.X - 100.2.X.X is the address range of the unauthorized local route, then comparing with the EAS IP range resolvable by the local DNS server, a local DNS server whose resolvable EAS IP range does not include the EAS IP range 100.1.X.X - 100.2.X.X should be selected and assigned to the fourth communication device, such as a terminal.
[0227] In the information processing method provided by the embodiments of the present application, the execution subject may be an information processing device. In the embodiments of the present application, the information processing method is executed by the information processing device as an example to illustrate the information processing device provided by the embodiments of the present application.
[0228] As Figure 9 shown, the information processing device 900 includes the following modules:
[0229] The first receiving module 910 is configured to receive the first information, where the first information includes the first address;
[0230] A first determination module 920, configured to determine, according to second information, whether a first address is an address authorized for local routing.
[0231] By applying the device provided in the embodiment of the present application, first information is received, where the first information includes a first address, and then, according to the second information, it is determined whether the first address is an address authorized for local routing, and a judgment is made on whether the first address is an address authorized or not authorized for local routing, so as to control the access behavior to the first address based on different judgment results and reduce the management and control risk.
[0232] In some embodiments of the present application, the information processing device 900 further includes a first sending module, configured to:
[0233] In a case where it is determined that the first address is an address not authorized for local routing or it is determined that the first address is not an address authorized for local routing, send a first request to a second communication device, where the first request is used to request the second communication device to send a first query request;
[0234] Wherein, the first query request includes the first address.
[0235] In some embodiments of the present application, the first request includes a second address, where the second address is the address of the device that receives the first query request.
[0236] In some embodiments of the present application, the information processing device 900 further includes a generation module, configured to:
[0237] In a case where it is determined that the first address is an address not authorized for local routing or it is determined that the first address is not an address authorized for local routing, generate a first rule according to the second information;
[0238] Wherein, the first rule includes:
[0239] Route a data packet routed to the first address to a third address.
[0240] In some embodiments of the present application, the information processing device 900 further includes a second sending module, configured to:
[0241] Send the first rule to a third communication device.
[0242] In some embodiments of the present application, the second information includes at least one of the following:
[0243] An address authorized for local routing;
[0244] An address not authorized for local routing;
[0245] At least one third address.
[0246] In some embodiments of the present application, the address that does not authorize local routing has an associated relationship with at least one third address.
[0247] In some embodiments of the present application, the third address includes the home communication device address, or the roaming communication device address, or the address that authorizes local routing.
[0248] The information processing device 900 provided by the embodiments of the present application can implement Figure 3 each process implemented by the method embodiment shown, and achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0249] As Figure 10 shown, the information processing device 1000 includes the following modules:
[0250] A second receiving module 1010, configured to receive a first request, where the first request is used to request a second communication device to send a first query request, and the first query request includes a first address, and the first address is an address that does not authorize local routing;
[0251] A third sending module 1020, configured to send the first query request.
[0252] By applying the device provided by the embodiments of the present application, after receiving the first request, a first query request is sent according to the first request, and the first query request includes the first address that does not authorize local routing, that is, when the first address is an address that does not authorize local routing, the address query is re-performed to avoid accessing the first address that does not authorize local routing and reduce the management and control risk.
[0253] In some embodiments of the present application, the first request includes a second address, and the second address is the address of the device that receives the first query request.
[0254] The information processing device 1000 provided by the embodiments of the present application can implement Figure 6 each process implemented by the method embodiment shown, and achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0255] As Figure 11 shown, the information processing device 1100 includes the following modules:
[0256] A third receiving module 1110, configured to receive a first rule, where the first rule includes: routing a data packet routed to the first address to the third address, and the first address is an address that does not authorize local routing or is not an address that authorizes local routing;
[0257] A routing module 1120, configured to route the first data packet to the third address when receiving the first data packet routed to the first address.
[0258] Applying the apparatus provided by the embodiments of the present application, according to the first rule, when receiving a first data packet routed to a first address that does not authorize local routing, route the first data packet to a third address to effectively avoid local routing to the first address and reduce the control risk.
[0259] In some embodiments of the present application, the first rule is generated according to second information, and the second information includes at least one of the following:
[0260] Addresses that authorize local routing;
[0261] Addresses that do not authorize local routing;
[0262] At least one third address.
[0263] In some embodiments of the present application, there is an association relationship between the addresses that do not authorize local routing and at least one third address.
[0264] In some embodiments of the present application, the third address includes the address of the home communication device, or the address of the roaming communication device, or the address that authorizes local routing.
[0265] In some embodiments of the present application, the information processing device 1100 further includes a fourth receiving module and a fourth sending module;
[0266] The fourth receiving module is used to receive a second data packet from the third address;
[0267] The fourth sending module is used to send the second data packet to the fourth communication device.
[0268] The information processing device 1100 provided by the embodiments of the present application can implement Figure 7 each process implemented by the method embodiments shown and achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0269] As Figure 12 shown, the information processing device 1200 includes the following modules:
[0270] The fifth sending module 1210 is used to send third information to the fourth communication device, and the third information includes the address of the first server, and the first server is used to perform domain name resolution;
[0271] Among them, the address range resolved by the first server is within the address range that authorizes local routing, or all the addresses resolved by the first server are addresses that authorize local routing.
[0272] Apply the device provided by the embodiments of the present application to send third information to a fourth communication device. The third information includes the address of a first server, and the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are the addresses of the authorized local route. In this way, when the fourth communication device sends a query request to the first server, the address resolved by the first server can be the address of the authorized local route, effectively avoiding the fourth communication device from accessing the address of the unauthorized local route and reducing the control risk.
[0273] In some embodiments of the present application, the information processing device 1200 further includes a second determination module, configured to:
[0274] Determine the first server according to at least one of the following:
[0275] The address range of the authorized local route; the address range of the unauthorized local route; the address range resolvable by at least one server.
[0276] The information processing device 1200 provided by the embodiments of the present application can implement Figure 8 each process implemented by the method embodiments shown, and achieve the same technical effects. To avoid repetition, details are not described here again.
[0277] As Figure 13 shown, the embodiments of the present application further provide a communication device 1300, including a processor 1301 and a memory 1302. A program or instruction that can run on the processor 1301 is stored on the memory 1302. For example, when the communication device 1300 is a first communication device, when the program or instruction is executed by the processor 1301, it implements each step of the method embodiments shown above Figure 3 and can achieve the same technical effects. When the communication device 1300 is a second communication device, when the program or instruction is executed by the processor 1301, it implements each step of the method embodiments shown above Figure 6 and can achieve the same technical effects. When the communication device 1300 is a third communication device, when the program or instruction is executed by the processor 1301, it implements each step of the method embodiments shown above Figure 7 and can achieve the same technical effects. When the communication device 1300 is a fifth communication device, when the program or instruction is executed by the processor 1301, it implements each step of the method embodiments shown above Figure 8 and can achieve the same technical effects. To avoid repetition, details are not described here again.
[0278] The embodiments of the present application further provide a network-side device, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is configured to run a program or instruction to implement as Figure 3 or Figure 6 orFigure 7 or Figure 8 the steps of the method embodiments shown. This network-side device embodiment corresponds to the method embodiments of the above-mentioned first communication device, second communication device, third communication device, or fifth communication device. Each implementation process and implementation manner of the above method embodiments can be applied to this network-side device embodiment, and the same technical effects can be achieved.
[0279] Specifically, an embodiment of the present application further provides a network-side device. As Figure 14 shown, the network-side device 1400 includes: a processor 1401, a network interface 1402, and a memory 1403. Among them, the network interface 1402 is, for example, a common public radio interface (CPRI).
[0280] Specifically, the network-side device 1400 of the embodiment of the present application further includes: instructions or programs stored on the memory 1403 and executable on the processor 1401. The processor 1401 calls the instructions or programs in the memory 1403 to execute Figure 9 or Figure 10 or Figure 11 or Figure 12 the methods executed by the respective modules shown, and the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.
[0281] An embodiment of the present application further provides a readable storage medium. Programs or instructions are stored on the readable storage medium. When the programs or instructions are executed by a processor, the respective processes of the above method embodiments are implemented, and the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.
[0282] Among them, the processor is the processor in the terminal described in the above embodiment. The readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0283] Another embodiment of the present application provides a chip. The chip includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the respective processes of the above method embodiments, and the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.
[0284] It should be understood that the chip mentioned in the embodiment of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip.
[0285] Another embodiment of the present application further provides a computer program / program product. The computer program / program product is stored in a storage medium and is executed by at least one processor to implement the various processes of the above method embodiments, and can achieve the same technical effects. To avoid repetition, details are not described herein again.
[0286] Another embodiment of the present application further provides a wireless communication system, including: a first communication device, a second communication device, a third communication device, or a fifth communication device. The first communication device can be used to execute Figure 3 the steps of the method embodiment shown, the second communication device can be used to execute Figure 6 the steps of the method embodiment shown, the third communication device can be used to execute Figure 7 the steps of the method embodiment shown, and the fifth communication device can be used to execute Figure 8 the steps of the method embodiment shown.
[0287] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the methods and devices in the embodiments of the present application are not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0288] Through the description of the above embodiments, those skilled in the art can clearly understand that the above method embodiments can be implemented by means of a computer software product plus a necessary general hardware platform, and of course, can also be implemented by hardware. This computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disc, etc.) and includes several instructions for causing a terminal or a network-side device to execute the methods described in the various embodiments of the present application.
[0289] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms of implementation manners without departing from the purpose of the present application and the scope protected by the claims. These implementation manners all fall within the protection scope of the present application.
Claims
1. An information processing method, characterized in that, Comprising: A first communication device receives first information, where the first information includes a first address; The first communication device determines, based on second information, whether the first address is an address authorized for local routing.
2. The method according to claim 1, wherein In the case where the first communication device determines that the first address is not an address authorized for local routing or determines that the first address is not an address authorized for local routing, the method further includes: The first communication device sends a first request to a second communication device, where the first request is used to request the second communication device to send a first query request; Wherein, the first query request includes the first address.
3. The method according to claim 2, characterized in that, The first request includes a second address, where the second address is the address of the device that receives the first query request.
4. The method according to any one of claims 1 to 3, characterized in that, In the case where the first communication device determines that the first address is not an address authorized for local routing or determines that the first address is not an address authorized for local routing, the method further includes: The first communication device generates a first rule based on the second information; Wherein, the first rule includes: Route a data packet routed to the first address to a third address.
5. The method according to claim 4, wherein The method further includes: The first communication device sends the first rule to a third communication device.
6. The method according to any one of claims 1 to 5, characterized in that, The second information includes at least one of the following: Addresses authorized for local routing; Addresses not authorized for local routing; At least one third address.
7. The method according to claim 6, characterized in that, There is an association relationship between the addresses not authorized for local routing and at least one third address.
8. The method according to claim 6 or 7, characterized in that, The third address includes a home location communication device address, or a roaming location communication device address, or an address authorized for local routing.
9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: The first communication device receives the second information from a fifth communication device.
10. An information processing method, characterized in that Comprising: A second communication device receives a first request, where the first request is used to request the second communication device to send a first query request, the first query request includes a first address, and the first address is an address not authorized for local routing; The second communication device sends the first query request.
11. The method according to claim 10, characterized in that The first request includes a second address, where the second address is the address of the device that receives the first query request.
12. An information processing method, characterized in that Comprising: A third communication device receives a first rule, where the first rule includes: route a data packet routed to a first address to a third address, and the first address is an address not authorized for local routing or not an address authorized for local routing; In the case where the third communication device receives a first data packet routed to the first address, the third communication device routes the first data packet to the third address.
13. The method according to claim 12, wherein The first rule is generated based on second information, and the second information includes at least one of the following: Addresses authorized for local routing; Addresses not authorized for local routing; At least one third address.
14. The method according to claim 13, wherein There is an association relationship between the addresses not authorized for local routing and at least one third address.
15. The method according to any one of claims 12 to 14, characterized in that, The third address includes a home location communication device address, or a roaming location communication device address, or an address authorized for local routing.
16. The method according to any one of claims 12 to 15, characterized in that, The method further includes: The third communication device receives a second data packet from the third address; The third communication device sends the second data packet to a fourth communication device.
17. An information processing method, characterized in that, Comprising: The fifth communication device sends third information to the fourth communication device, where the third information includes the address of a first server for performing domain name resolution; Among them, the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are addresses of the authorized local route.
18. The method according to claim 17, characterized in that, The method further includes: The fifth communication device determines the first server according to at least one of the following: The address range of the authorized local route; The address range of the unauthorized local route; The address range resolvable by at least one server.
19. An information processing apparatus, characterized in that, Including: A first receiving module, configured to receive first information, where the first information includes a first address; A first determining module, configured to determine, according to second information, whether the first address is an address of the authorized local route.
20. The device according to claim 19, characterized in that, The information processing device further includes a first sending module, configured to: In the case of determining that the first address is an address of the unauthorized local route or determining that the first address is not an address of the authorized local route, send a first request to the second communication device, where the first request is used to request the second communication device to send a first query request; Among them, the first query request includes the first address.
21. The device according to claim 19 or 20, characterized in that, The information processing device further includes a generating module, configured to: In the case of determining that the first address is an address of the unauthorized local route or determining that the first address is not an address of the authorized local route, generate a first rule according to the second information; Among them, the first rule includes: Route the data packet routed to the first address to a third address.
22. The device according to claim 21, wherein, The information processing device further includes a second sending module, configured to: Send the first rule to a third communication device.
23. An information processing apparatus, characterized in that, Including: A second receiving module, configured to receive a first request, where the first request is used to request the second communication device to send a first query request, the first query request includes a first address, and the first address is an address of the unauthorized local route; A third sending module, configured to send the first query request.
24. An information processing apparatus, characterized in that, Including: A third receiving module, configured to receive a first rule, where the first rule includes: route the data packet routed to the first address to a third address, and the first address is an address of the unauthorized local route or not an address of the authorized local route; A routing module, configured to, in the case of receiving a first data packet routed to the first address, route the first data packet to the third address.
25. The device according to claim 24, characterized in that, The information processing device further includes a fourth receiving module and a fourth sending module; The fourth receiving module is configured to receive a second data packet from the third address; The fourth sending module is configured to send the second data packet to a fourth communication device.
26. An information processing apparatus, characterized in that, Including: A fifth sending module, configured to send third information to a fourth communication device, where the third information includes the address of a first server for performing domain name resolution; Among them, the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are addresses of the authorized local route.
27. The device according to claim 26, wherein The information processing device further includes a second determining module, configured to: Determine the first server according to at least one of the following: Address range for authorized local routing; Address range for unauthorized local routing; Address range resolvable by at least one server.
28. A communication device, characterized in that, Comprising a processor and a memory, the memory stores programs or instructions that can run on the processor, and when the programs or instructions are executed by the processor, the steps of the information processing method according to any one of claims 1 to 18 are implemented.
29. A readable storage medium, characterized in that, Programs or instructions are stored on the readable storage medium, and when the programs or instructions are executed by a processor, the steps of the information processing method according to any one of claims 1 to 18 are implemented.