Method, device and system for establishing communication tunnel and computer readable storage medium

The authentication device on the terminal side automatically sends authentication information and performs authentication on the gateway side, which solves the problems of complex operation and low efficiency caused by the user's manual input of authentication information, and realizes automatic establishment of communication tunnels and improved user experience.

CN120389928APending Publication Date: 2025-07-29HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410120970.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-29
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In the prior art, users need to manually input authentication information to establish a communication tunnel, resulting in complex operations and inefficient efficiency.

Method used

The authentication device on the terminal side automatically sends the stored authentication information, and the gateway side authenticates to establish a communication tunnel, simplifies user operations and improves efficiency.

Benefits of technology

The automatic establishment of communication tunnels is realized, which improves efficiency and success rate and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389928A_ABST
    Figure CN120389928A_ABST
Patent Text Reader

Abstract

The invention discloses a method, device and system for establishing a communication tunnel and a computer readable storage medium, and belongs to the technical field of communication. In the method, a terminal side sends an authentication request to a gateway side, the authentication request comprises first authentication information stored by an authentication device of the terminal side, and the authentication request is used for the gateway side to authenticate the first authentication information. And under the condition that the first authentication information passes the authentication of the gateway side, establishing a communication tunnel between the terminal side and the gateway side. According to the invention, a user does not need to manually input the authentication information, and the authentication request carrying the first authentication information can be sent to the gateway side based on the first authentication information stored by the authentication device. When the first authentication information passes the authentication, a communication tunnel can be established with the gateway side. Therefore, not only is the establishment efficiency of the communication tunnel improved, but also the operation complexity of the user is reduced, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and particularly to a method, apparatus, system, and computer-readable storage medium for establishing a communication tunnel. Background Art

[0002] In the field of communication technologies, a communication tunnel can be established between the terminal side and the gateway side of a communication network, enabling the terminal side to remotely access the communication network through the communication tunnel. For example, if the communication network includes an enterprise intranet, the terminal side can establish a communication tunnel with the gateway side of the enterprise intranet, thereby remotely accessing the enterprise intranet through the communication tunnel.

[0003] In related technologies, after a user downloads a client on the terminal side, the user manually inputs authentication information into the client. Subsequently, the client sends an authentication request carrying the authentication information to the gateway side. When the authentication information passes the authentication of the gateway side, a communication tunnel is established between the terminal side and the gateway side.

[0004] However, since in related technologies, the user needs to manually input authentication information into the client, the operation is relatively complex for the user and it is prone to reducing the efficiency of establishing a communication tunnel. Summary of the Invention

[0005] This application provides a method, apparatus, system, and computer-readable storage medium for establishing a communication tunnel to improve the problem of low efficiency in establishing a communication tunnel. The technical solutions provided in this application include the following aspects.

[0006] In a first aspect, a method for establishing a communication tunnel is provided. This method is applicable to the terminal side. For example, the terminal side includes, but is not limited to: a terminal, a communication module in the terminal, a circuit, a chip, or a chip system in the terminal responsible for communication functions, etc. For example, chips include, but are not limited to: a modulation / demodulation (modem) chip (also known as a baseband chip), a system on chip (SoC) chip or a system in package (SIP) chip containing a modem core (also known as a modem module), etc. Among them, a chip system may include at least one chip.

[0007] In this method, the terminal side sends an authentication request to the gateway side. The authentication request includes first authentication information stored in an authentication device of the terminal side, and this authentication request is used for the gateway side to authenticate the first authentication information. When the first authentication information passes the authentication of the gateway side, a communication tunnel is established between the terminal side and the gateway side. Taking the application of this method to a terminal as an example, the terminal sends an authentication request to the gateway side. The authentication request includes first authentication information stored in an authentication device of the terminal. When the first authentication information passes the authentication of the gateway side, a communication tunnel is established between the terminal and the gateway side.

[0008] In this application, the terminal side can send an authentication request carrying the first authentication information to the gateway side based on the first authentication information stored in the authentication device on the terminal side. When the first authentication information passes the authentication, a communication tunnel is established between the terminal side and the gateway side, making it possible to remotely access the communication network where the gateway side is located through the communication tunnel. Therefore, the user does not need to manually input the authentication information. This method not only improves the establishment efficiency and success rate of the communication tunnel, but also enhances the user experience because the establishment process of the communication tunnel can be imperceptible to the user, and the establishment process of the communication tunnel can be automatically completed after the terminal side is started.

[0009] In a possible implementation, the method further includes: receiving an authentication response sent by the gateway side, where the authentication response is used to indicate that the first authentication information has passed the authentication on the gateway side.

[0010] Based on the authentication response sent by the gateway side, the terminal side can determine that the first authentication information has passed the authentication, thereby triggering the subsequent process of establishing the communication tunnel. This method is simple and fast, and has strong applicability.

[0011] In a possible implementation, before sending the authentication request to the gateway side, the method further includes: when the authentication device is detected, obtaining the first authentication information stored in the authentication device, and generating an authentication request based on the first authentication information.

[0012] Thus, when the authentication device is detected on the terminal side, the first authentication information stored in the authentication device can be automatically obtained and an authentication request can be generated, thereby realizing the automatic establishment of the communication tunnel. The automatic establishment process of the communication tunnel is imperceptible to the user, improving the user experience.

[0013] In a possible implementation, generating an authentication request based on the first authentication information includes: calling the protocol stack interface according to the program stored in the authentication device, and generating an authentication request based on the first authentication information through the protocol stack interface.

[0014] In this implementation, the program (such as a small program) stored in the authentication device calls the protocol stack interface, thereby generating an authentication request through the protocol stack interface. This not only has strong universality, but also is conducive to quickly realizing the automatic establishment of the communication tunnel.

[0015] In a possible implementation, the format in which the authentication device stores information is the first format, and the format in which the protocol stack interface transmits information is the second format. Generating an authentication request based on the first authentication information through the protocol stack interface includes: converting the first authentication information in the first format into the first authentication information in the second format through the protocol stack interface, and generating an authentication request including the first authentication information in the second format. Sending the authentication request to the gateway side includes: sending the authentication request to the gateway side through the protocol stack interface.

[0016] By performing format conversion, the format of the first authentication information is converted from the format suitable for storage by the authentication device to the format suitable for transmission to the gateway side through the protocol stack interface, ensuring the successful transmission of the authentication request, and thus improving the efficiency and success rate of establishing a communication tunnel.

[0017] In a possible implementation, the first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device.

[0018] Such identification information not only has uniqueness, but also has strong complexity and reliability, which is beneficial to improving the accuracy of authenticating the first authentication information, ensuring the security of the established communication tunnel, and preventing users without access rights from remotely accessing the communication network where the gateway side is located.

[0019] In a possible implementation, the authentication device includes a subscriber identity module (SIM).

[0020] In a possible implementation, the authentication device includes a universal serial bus (USB) key.

[0021] Whether it is a SIM or a USB Key, both have strong universality. The terminal side can support SIM and USB Key without improvement, reducing the implementation cost of the method for establishing a communication tunnel provided in this application.

[0022] In a possible implementation, the communication tunnel includes a virtual private network (VPN) tunnel.

[0023] In a second aspect, a method for establishing a communication tunnel is provided, and this method is applicable to the gateway side. For example, the gateway side includes but is not limited to: gateway devices, components in gateway devices, and so on. For instance, gateway devices include but are not limited to: servers, and components in gateway devices include but are not limited to: communication modules, circuits, chips, or chip systems, and so on. The description of chips and chip systems can refer to the first aspect above and will not be elaborated here.

[0024] In this method, the gateway side receives an authentication request sent by the terminal side. The authentication request includes first authentication information stored in an authentication device on the terminal side. When the first authentication information passes the authentication, the gateway side establishes a communication tunnel with the terminal side. Taking the application of this method to a gateway device as an example, the gateway device receives an authentication request sent by the terminal side. The authentication request includes first authentication information stored in an authentication device on the terminal side. When the first authentication information passes the authentication, the gateway device establishes a communication tunnel with the terminal side.

[0025] In this application, after the gateway side receives the authentication request sent by the terminal side, it can authenticate the first authentication information. When the first authentication information passes the authentication, it establishes a communication tunnel with the terminal side. Among them, the first authentication information in the authentication request is the first authentication information stored in the authentication device on the terminal side, so the user does not need to manually input the authentication information. This method not only improves the establishment efficiency and success rate of the communication tunnel, realizes the automatic establishment of the communication tunnel, and the user does not need to perceive this automatic establishment process, but also improves the user experience.

[0026] In a possible implementation manner, the method further includes: receiving second authentication information sent by the mobile communication core network side. When the first authentication information matches the second authentication information, it is determined that the first authentication information passes the authentication, and an authentication response is sent to the terminal side. The authentication response is used to indicate that the first authentication information passes the authentication. For example, the mobile communication core network side includes but is not limited to: mobile communication core network devices, components in mobile communication core network devices, etc. For instance, mobile communication core network devices include but are not limited to: servers, and components in mobile communication core network devices include but are not limited to: communication modules, circuits, chips or chip systems, etc., which will not be elaborated here.

[0027] In this implementation manner, the gateway side interacts with the mobile communication core network side to obtain the second authentication information, so as to authenticate the first authentication information on the gateway side through the second authentication information. This method is simple and fast and has strong applicability.

[0028] In a possible implementation manner, when the first authentication information matches the second authentication information, determining that the first authentication information passes the authentication includes: when the first authentication information matches the second authentication information, sending a challenge request to the mobile communication core network side. The challenge request includes the first authentication information and is used for the mobile communication core network side to authenticate the first authentication information. Receiving a challenge response sent by the mobile communication core network side, and determining that the first authentication information passes the authentication. The challenge response is used to indicate that the first authentication information passes the authentication on the mobile communication core network side.

[0029] That is to say, after the first authentication information passes the authentication on the gateway side, it is also authenticated by the mobile communication core network side, which improves the authentication strength of the first authentication information, ensures the accuracy of authentication, is conducive to ensuring the security of the established communication tunnel, and prevents users without access rights from remotely accessing the communication network where the gateway side is located.

[0030] In a possible implementation manner, when the first authentication information matches the third authentication information on the mobile communication core network side, the first authentication information passes the authentication on the mobile communication core network side, and the third authentication information is obtained by updating the second authentication information on the mobile communication core network side.

[0031] Since the third authentication information is obtained by updating the second authentication information, compared with the second authentication information, the third authentication information has stronger timeliness and higher accuracy. Authenticating the first authentication information with the third authentication information has high accuracy.

[0032] In a possible implementation manner, when the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication on the mobile communication core network side, and the terminal side and the reference terminal side where the authentication device is located are determined according to the first authentication information.

[0033] In this implementation manner, when the first authentication information of the authentication device passes the authentication, it is further determined whether the authentication device is located on the correct terminal side, that is, whether it is located on the reference terminal side bound to the authentication device. Thus, not only the flexibility of the authentication process is improved, but also the accuracy and security of the authentication are ensured.

[0034] In a possible implementation manner, the second authentication information is in a first format, and the first authentication information is in a second format. The method further includes: converting the second authentication information in the first format into the second authentication information in the second format. Among them, the matching of the first authentication information and the second authentication information includes: the first authentication information in the second format matches the second authentication information in the second format.

[0035] When the formats of the first authentication information and the second authentication information are different, the gateway side performs format conversion to unify the formats of the first authentication information and the second authentication information, ensuring the normal progress of the authentication process.

[0036] In a possible implementation manner, the first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device.

[0037] In a possible implementation manner, the authentication device includes a SIM.

[0038] In a possible implementation manner, the authentication device includes a USB key.

[0039] In a possible implementation, the communication tunnel includes a VPN tunnel.

[0040] In a third aspect, a method for establishing a communication tunnel is provided. The method is applied to a communication system, which includes a terminal side and a gateway side, and the terminal side includes an authentication device. In this method, the terminal side sends an authentication request to the gateway side. The authentication request includes first authentication information stored in the authentication device of the terminal side, and the authentication request is used for the gateway side to authenticate the first authentication information. The gateway side receives the authentication request sent by the terminal side. When the first authentication information passes the authentication of the gateway side, a communication tunnel is established between the gateway side and the terminal side.

[0041] In a possible implementation, the method further includes: the gateway side receives second authentication information sent by the mobile communication core network side; when the first authentication information matches the second authentication information, the gateway side determines that the first authentication information passes the authentication; the gateway side sends an authentication response to the terminal side, and the authentication response is used to indicate that the first authentication information passes the authentication. The terminal side receives the authentication response sent by the gateway side, and the authentication response is used to indicate that the first authentication information passes the authentication of the gateway side.

[0042] In a possible implementation, when the first authentication information matches the second authentication information, the gateway side determines that the first authentication information passes the authentication, including: when the first authentication information matches the second authentication information, the gateway side sends a challenge request to the mobile communication core network side. The challenge request includes the first authentication information, and the challenge request is used for the mobile communication core network side to authenticate the first authentication information; the gateway side receives the challenge response sent by the mobile communication core network side and determines that the first authentication information passes the authentication. The challenge response is used to indicate that the first authentication information passes the authentication of the mobile communication core network side.

[0043] In a possible implementation, when the first authentication information matches the third authentication information of the mobile communication core network side, the first authentication information passes the authentication of the mobile communication core network side, and the third authentication information is obtained by updating the second authentication information of the mobile communication core network side.

[0044] In a possible implementation, when the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication of the mobile communication core network side, and the terminal side where the authentication device is located and the reference terminal side are determined according to the first authentication information.

[0045] In a possible implementation, the second authentication information is in a first format, and the first authentication information is in a second format. The method further includes: the gateway side converts the second authentication information in the first format into the second authentication information in the second format. Among them, the matching of the first authentication information and the second authentication information includes: the first authentication information in the second format matches the second authentication information in the second format.

[0046] In a possible implementation, before the terminal side sends an authentication request to the gateway side, the method further includes: when the terminal side detects the authentication device, the terminal side obtains the first authentication information stored in the authentication device; the terminal side generates an authentication request according to the first authentication information.

[0047] In a possible implementation, the terminal side generates an authentication request according to the first authentication information, including: the terminal side calls the protocol stack interface according to the program stored in the authentication device, and the terminal side generates an authentication request according to the first authentication information through the protocol stack interface.

[0048] In a possible implementation, the format of the information stored in the authentication device is the first format, and the format of the information transmitted by the protocol stack interface is the second format. The terminal side generates an authentication request according to the first authentication information through the protocol stack interface, including: the terminal side converts the first authentication information in the first format into the first authentication information in the second format through the protocol stack interface, and generates an authentication request including the first authentication information in the second format. The terminal side sends the authentication request to the gateway side, including: the terminal side sends the authentication request to the gateway side through the protocol stack interface.

[0049] In a possible implementation, the first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device.

[0050] In a possible implementation, the authentication device includes a SIM.

[0051] In a possible implementation, the authentication device includes a USB key.

[0052] In a possible implementation, the communication tunnel includes a VPN tunnel.

[0053] In a fourth aspect, a device for establishing a communication tunnel is provided. The device has the function of implementing the first aspect or any possible implementation of the first aspect. For example, the device includes modules, units or means for performing the operations involved in the method of establishing a communication tunnel, and the method of establishing a communication tunnel is the method provided by the first aspect or any possible implementation of the first aspect. Among them, the modules, units or means can be implemented by software, or by hardware, or by a combination of software and hardware.

[0054] For example, the device for establishing a communication tunnel includes a transceiver module and an establishment module. Among them, the transceiver module is used to send an authentication request to the gateway side. The authentication request includes the first authentication information stored in the authentication device on the terminal side, and the authentication request is used for the gateway side to authenticate the first authentication information; the establishment module is used to establish a communication tunnel with the gateway side when the first authentication information passes the authentication of the gateway side.

[0055] In a possible implementation manner, the transceiver module is further used to receive an authentication response sent by the gateway side, and the authentication response is used to indicate that the first authentication information passes the authentication of the gateway side.

[0056] In a possible implementation manner, the device further includes: a generation module, which is used to obtain the first authentication information stored in the authentication device when detecting the authentication device; and generate an authentication request according to the first authentication information.

[0057] In a possible implementation manner, the generation module is used to call the protocol stack interface according to the program stored in the authentication device; and generate an authentication request according to the first authentication information through the protocol stack interface.

[0058] In a possible implementation manner, the format of the information stored in the authentication device is the first format, and the format of the information transmitted by the protocol stack interface is the second format;

[0059] The generation module is used to convert the first authentication information in the first format into the first authentication information in the second format through the protocol stack interface, and generate an authentication request including the first authentication information in the second format;

[0060] The transceiver module is used to send the authentication request to the gateway side through the protocol stack interface.

[0061] In a possible implementation manner, the first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device.

[0062] In a possible implementation manner, the authentication device includes a SIM.

[0063] In a possible implementation manner, the authentication device includes a USB key.

[0064] In a possible implementation manner, the communication tunnel includes a VPN tunnel.

[0065] In a fifth aspect, a device for establishing a communication tunnel is provided. The device has the functions of implementing the second aspect or any possible implementation manner of the second aspect. For example, the device includes modules, units or means for performing operations involved in the method for establishing a communication tunnel, and the method for establishing a communication tunnel is the method provided by the second aspect or any possible implementation manner of the second aspect. Among them, the modules, units or means can be implemented by software, or by hardware, or by a combination of software and hardware.

[0066] For example, the device for establishing a communication tunnel includes a transceiver module and an establishment module. Among them, the transceiver module is used to receive an authentication request sent by the terminal side, and the authentication request includes first authentication information stored in an authentication device on the terminal side; the establishment module is used to establish a communication tunnel with the terminal side when the first authentication information passes the authentication.

[0067] In a possible implementation manner, the transceiver module is further used to receive second authentication information sent by the mobile communication core network side; when the first authentication information matches the second authentication information, it is determined that the first authentication information passes the authentication; and an authentication response is sent to the terminal side, and the authentication response is used to indicate that the first authentication information passes the authentication.

[0068] In a possible implementation manner, the transceiver module is used to send a challenge request to the mobile communication core network side when the first authentication information matches the second authentication information, and the challenge request includes the first authentication information, and the challenge request is used for the mobile communication core network side to authenticate the first authentication information; receive a challenge response sent by the mobile communication core network side, and determine that the first authentication information passes the authentication, and the challenge response is used to indicate that the first authentication information passes the authentication by the mobile communication core network side.

[0069] In a possible implementation manner, when the first authentication information matches the third authentication information of the mobile communication core network side, the first authentication information passes the authentication of the mobile communication core network side, and the third authentication information is obtained by updating the second authentication information of the mobile communication core network side.

[0070] In a possible implementation manner, when the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication of the mobile communication core network side, and the terminal side where the authentication device is located and the reference terminal side are determined according to the first authentication information.

[0071] In a possible implementation, the second authentication information is in a first format, and the first authentication information is in a second format. The apparatus further includes: a conversion module, configured to convert the second authentication information in the first format into the second authentication information in the second format; wherein, the matching between the first authentication information and the second authentication information includes: the first authentication information in the second format matches the second authentication information in the second format.

[0072] In a possible implementation, the first authentication information includes identification information, and the identification information is used to uniquely identify an authentication device.

[0073] In a possible implementation, the authentication device includes a SIM.

[0074] In a possible implementation, the authentication device includes a USB key.

[0075] In a possible implementation, the communication tunnel includes a VPN tunnel.

[0076] In a sixth aspect, an apparatus for establishing a communication tunnel is provided. The apparatus includes a memory and a processor; at least one computer instruction is stored in the memory, and the at least one computer instruction is loaded and executed by the processor, so that the apparatus for establishing a communication tunnel implements the method for establishing a communication tunnel provided in the first aspect or the second aspect and corresponding possible implementations. Wherein, the at least one computer instruction may refer to part or all of the computer programs or instructions required to implement the above method for establishing a communication tunnel.

[0077] In a possible implementation, the apparatus for establishing a communication tunnel may further include an interface circuit, wherein the processor is configured to communicate with other devices or components through the interface circuit.

[0078] In a possible implementation, the apparatus for establishing a communication tunnel may further include a memory, and the memory is separately arranged from the processor.

[0079] Optionally, the processor is one or more, and the memory is one or more.

[0080] For example, in the case where the apparatus for establishing a communication tunnel implements the method for establishing a communication tunnel provided in the first aspect and corresponding possible implementations, the apparatus for establishing a communication tunnel may be a terminal, a communication module in the terminal, a circuit, a chip, or a chip system responsible for the communication function in the terminal, and so on. For example, the chip may be a modem chip, an SoC chip including a modem core, or a SIP chip, and so on.

[0081] For another example, in the case where the device for establishing a communication tunnel implements the method for establishing a communication tunnel provided by the second aspect and the corresponding possible implementation manners, the device for establishing a communication tunnel may be a gateway device, a component in the gateway device, and so on. The gateway device includes but is not limited to: a server, and the components in the gateway device include but are not limited to: a communication module, a circuit, a chip, or a chip system, and so on.

[0082] In a seventh aspect, a communication system is provided. The communication system includes a terminal side and a gateway side. The terminal side is configured to execute the method for establishing a communication tunnel provided by the first aspect and the corresponding possible implementation manners, and the gateway side is configured to execute the method for establishing a communication tunnel provided by the second aspect and the corresponding possible implementation manners.

[0083] In an eighth aspect, a computer program or a computer program product is provided. The computer program or the computer program product includes: computer instructions, which, when run on a computer, cause the computer to execute the method for establishing a communication tunnel provided by the first aspect or the second aspect and the corresponding possible implementation manners.

[0084] In a ninth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores computer instructions, which, when run on a computer, cause the computer to execute the method for establishing a communication tunnel provided by the first aspect or the second aspect and the corresponding possible implementation manners.

[0085] It should be understood that for the technical effects achieved by the technical solutions provided by the third aspect to the ninth aspect of this application and the corresponding possible implementation manners, reference may be made to the descriptions of the technical effects achieved by the technical solutions provided by the first aspect and the second aspect and the corresponding possible implementation manners above, and details are not described herein again. BRIEF DESCRIPTION OF THE DRAWINGS

[0086] Figure 1 FIG. is a schematic diagram of establishing a communication tunnel in a related art provided by an embodiment of this application;

[0087] Figure 2 FIG. is a schematic diagram of establishing a communication tunnel in another related art provided by an embodiment of this application;

[0088] Figure 3 FIG. is a schematic diagram of a communication system provided by an embodiment of this application;

[0089] Figure 4 FIG. is a schematic diagram of another communication system provided by an embodiment of this application;

[0090] Figure 5 FIG. is a schematic diagram of yet another communication system provided by an embodiment of this application;

[0091] Figure 6A schematic structural diagram of an authentication device provided by an embodiment of the present application;

[0092] Figure 7 A schematic diagram of another communication system provided by an embodiment of the present application;

[0093] Figure 8 A schematic diagram of still another communication system provided by an embodiment of the present application;

[0094] Figure 9 A flowchart of a method for establishing a communication tunnel provided by an embodiment of the present application;

[0095] Figure 10 A schematic structural diagram of a device for establishing a communication tunnel provided by an embodiment of the present application;

[0096] Figure 11 A schematic structural diagram of another device for establishing a communication tunnel provided by an embodiment of the present application;

[0097] Figure 12 A schematic structural diagram of a device for establishing a communication tunnel provided by an embodiment of the present application;

[0098] Figure 13 A schematic structural diagram of a terminal provided by an embodiment of the present application. Detailed implementation manners

[0099] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. The technical solutions in the embodiments of the present application can be applied to various communication systems, such as Universal Mobile Telecommunications System (UMTS), Wireless Local Area Network (WLAN), Wireless Fidelity (Wi-Fi) system, 4th generation (4G) mobile communication system, such as Long Term Evolution (LTE) system, 5th generation (5G) mobile communication system, such as New Radio (NR) system, and future evolved communication systems, such as 6th generation (6G) mobile communication system, etc.

[0100] The present application will present various aspects, embodiments or features around a system that may include multiple devices, components, modules, etc. It should be understood and clear that each system may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. In addition, combinations of these solutions can also be used.

[0101] In addition, in the embodiments of the present application, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner. In the embodiments of the present application, "of", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, their intended meanings are the same.

[0102] The communication systems and service scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0103] In a communication system, there is a need for users to remotely access a communication network. Therefore, it is necessary to establish a communication tunnel between the terminal side used by the user and the gateway side of the communication network to meet this need. For example, if the communication network to be remotely accessed is a private network, a communication tunnel can be established between the terminal side and the gateway side through a public network (including but not limited to the Internet, etc.). For instance, the private network is an enterprise internal network, and users such as home office users, business trip users, and cooperative users need to remotely access the enterprise internal network.

[0104] In Related Art One, as Figure 1 shown, the user downloads a first client (also referred to as an application (APP)) in the terminal. The first client is used to generate service traffic and has the ability to establish a communication tunnel. The user manually inputs authentication information into the first client, and the terminal sends an authentication request to the server of the communication network (such as a private network). The authentication request carries the authentication information manually input by the user. After the authentication information passes the authentication of the server, a communication tunnel is established between the terminal and the server through the public network. After the communication tunnel is established, the service traffic generated by the first client can be transmitted to the server of the communication network through the communication tunnel, and the server can also respond through the communication tunnel, thereby realizing the user's remote access to the communication network.

[0105] In Related Art Two, see Figure 2, the user downloads the first client and the second client on the terminal. The first client is used to generate service traffic, but it does not have the ability to establish a communication tunnel, while the second client has the ability to establish a communication tunnel. The user manually inputs authentication information into the second client, and the terminal sends an authentication request to the gateway device of the communication network (such as a private network). The authentication request carries the authentication information manually input by the user. After the authentication information passes the authentication of the gateway device, a communication tunnel is established between the terminal and the gateway device through the public network. After the communication tunnel is established, the service traffic generated by the first client can be transmitted through the communication tunnel to the gateway device of the communication network, so that the gateway device forwards the service traffic to the server of the communication network, and the server can also respond through the gateway device and the communication tunnel, thereby realizing the user's remote access to the communication network.

[0106] In both Related Technology 1 and Related Technology 2, during the establishment of the communication tunnel, the user needs to download the client on the terminal, configure the client (such as inputting the address of the gateway device (dialing), inputting the authentication method, etc.), and manually input the authentication information (such as the user account, user password, etc.) into the client. The installation, configuration of the client and the manual input of the authentication information have a certain technical threshold, which is difficult and complex for the user to operate, affecting the user experience. Moreover, it also results in a low efficiency in establishing the communication tunnel, and even the communication tunnel cannot be established due to the user's operation errors.

[0107] An embodiment of the present application provides a method for establishing a communication tunnel, which can be applied to Figure 3 the communication system shown. As Figure 3 shown, this communication system includes a terminal side and a gateway side. The terminal side is communicatively connected to the gateway side of the communication network (such as a private network), for example, communicatively connected through a public network such as the Internet. The gateway side can also be communicatively connected to the server in the communication network. There is an authentication device on the terminal side, and the authentication information is stored in the authentication device. The method for establishing a communication tunnel provided by the embodiment of the present application is implemented based on the authentication information stored in the authentication device on the terminal side, as detailed in the description in the method embodiment shown below Figure 9 shown.

[0108] Exemplarily, the terminal side can be a device in the communication system or a component included in the device, and the terminal side has a communication function. For example, the terminal side includes but is not limited to: a terminal, a communication module in the terminal, a circuit, a chip or a chip system in the terminal responsible for the communication function, etc. The chip system can include at least one chip, and the communication module, circuit, chip or chip system can perform corresponding communication functions. Exemplarily, the chip includes but is not limited to: a modem chip, an SoC chip containing a modem core or a SIP chip, etc. Program instructions for performing corresponding communication functions can also be configured in the terminal.

[0109] A terminal may also be referred to as a user equipment (UE), user device, access terminal, user unit, user station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal unit, terminal station, terminal device, wireless communication device, user agent, or user device. Exemplarily, the terminals in the embodiments of the present application include, but are not limited to: mobile phones, personal digital assistants (PDAs), laptop computers, tablets (Pads), drones, computers with wireless transceiver functions, machine type communication (MTC) terminals, virtual reality (VR) terminals, augmented reality (AR) terminals, Internet of Things (IoT) terminals, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical, wireless terminals in smart grid, wireless terminals in transportation safety, wireless terminals in smart city, wireless terminals in smart home (such as game consoles, smart TVs, smart speakers, smart refrigerators, and fitness equipment, etc.), transportation vehicles with wireless communication functions, communication modules, and roadside units (RSUs) with terminal functions.

[0110] In some embodiments, as Figure 4 shown, when the terminal is on the terminal side, the terminal may provide an interface ( Figure 4 not shown in Figure 4is connected to components such as a chip in the figure). Exemplarily, the authentication device includes, but is not limited to: a subscriber identity module (SIM), a universal serial bus (USB) key, and the like. Alternatively, the terminal side does not need to provide an interface, and the authentication device is a SIM. Components such as a chip and the authentication device are integrated into the same device, and the integrated device is called an embedded SIM (eSIM), and the eSIM is located inside the terminal. Of course, the embodiments of the present application do not limit the authentication device, and other devices with the ability to store authentication information can also be used as the authentication device according to actual needs.

[0111] In some other embodiments, as Figure 5 shown, when the terminal side is a communication module, a circuit, a chip, or a chip system ( Figure 5 shown as a chip in the figure) included in the terminal, components such as a chip can be connected to the authentication device. For examples of the authentication device, reference can be made to Figure 4 the corresponding description, and details will not be elaborated here.

[0112] In an exemplary embodiment, the structure of the authentication device can be referred to Figure 6 . In Figure 6 , the authentication device includes a microprocessor, a random access memory (RAM), a read-only memory (ROM), and a serial communication unit. The serial communication unit is an interface for the authentication device to interact with external devices, and is used to interact instructions and information between the authentication device and external devices. The external devices include, but are not limited to, a communication module, a circuit, a chip, or a chip system ( Figure 6 shown as a chip in the figure). The ROM is used to store the operating system, programs, and authentication information of the authentication device. The programs include, but are not limited to, applets. The microprocessor is used to load the operating system and programs stored in the ROM into the RAM, execute instructions issued by external devices (received through the serial communication unit) by running programs on the operating system, and issue instructions to external devices (sent through the serial communication unit). The microprocessor is also used to send the authentication information stored in the ROM to external devices through the serial communication unit.

[0113] In an exemplary embodiment, the gateway side may be a device in a communication system or a component included in a device, and the gateway side has a communication function. The gateway side may also be configured with program instructions for performing corresponding communication functions. The gateway side includes, but is not limited to: gateway devices, components in gateway devices, and so on. For example, gateway devices include, but are not limited to: servers, and components in gateway devices include, but are not limited to: communication modules, circuits, chips, or chip systems. For the description of chips and chip systems, reference may be made to the above, and details are not elaborated here.

[0114] Exemplarily, as Figure 7 shown, the communication system may further include a mobile communication core network side, which is communicatively connected to the gateway side. The mobile communication core network side may be a device in a communication system or a component included in a device, and the mobile communication core network side has a communication function. The gateway side may also be configured with program instructions for performing corresponding communication functions. The mobile communication core network side includes, but is not limited to: mobile communication core network devices, components in mobile communication core network devices, and so on. For example, mobile communication core network devices include, but are not limited to: servers, and components in mobile communication core network devices include, but are not limited to: communication modules, circuits, chips, or chip systems, etc., and details are not elaborated here. Exemplarily, the mobile communication technologies used by the mobile communication core network side include, but are not limited to: the third generation (3G), 4G, 5G, 6G, etc. For example, in the 4G scenario, the mobile communication core network device is an evolved packet core (EPC) device, and in the 5G scenario, the mobile communication core network device is a 5G core (5GC) device, and so on.

[0115] Taking the 5GC device as an example, as Figure 8 shown, the modules included in the 5GC device include, but are not limited to: a unified data management (UDM) module, a binding support function (BSF) module, a network exposure function (NEF) module, and so on. The embodiments of the present application do not limit the modules included in the 5GC device. The public network where the 5GC device is located may be a mobile network operator (MNO) network.

[0116] Exemplarily, the mobile communication core network side may be an independent device or a device cluster including multiple devices. Still taking Figure 8Taking the scenario shown as an example, when the mobile communication core network side is an independent device, the UDM module, BSF module, and NEF module are different modules in this device; when the mobile communication core network side is a device cluster, the UDM module, BSF module, and NEF module are different devices in the device cluster.

[0117] It can be understood that Figures 3 to 5 This is only a simplified schematic diagram shown for the convenience of understanding. The communication system may further include other possible devices, such as wireless relay devices and wireless backhaul devices. Each device may further include different functional modules or functional units, which are not shown in Figures 3 to 5 In the embodiments of the present application, the communication between different devices may refer to direct communication between different devices (i.e., no other device is required for relaying or forwarding), or it may also refer to communication between different devices through other devices (i.e., other devices are required for relaying or forwarding), or it may also refer to communication between a functional module or functional unit inside a device and other devices through another functional module or functional unit. For example, in the embodiments of the present application, "sending information to... (terminal side or gateway side)" can be understood as the destination of the information being the terminal side or gateway side, and it may include directly or indirectly sending information to the terminal side or gateway side. "Receiving information from... (terminal side or gateway side)" can be understood as the source of the information being the terminal side or gateway side, and it may include directly or indirectly receiving information from the terminal side or gateway side. Necessary processing may be performed on the information between the source and destination of the information sending, including but not limited to format change, digital-to-analog conversion, amplification, filtering, etc., but the destination can understand the valid information from the source. The information may refer to data, requests, or instructions. Similar expressions in the present application can be understood similarly and will not be elaborated here.

[0118] The embodiments of the present application provide a method for establishing a communication tunnel. This method can be implemented through the interaction between the terminal side and the gateway side based on the authentication information stored in the authentication device on the terminal side (i.e., the first authentication information in the following method embodiments). For example, this method can be implemented through the interaction between the terminal and the gateway device. For another example, this method can be implemented through the interaction between the chip in the terminal and the gateway device. For yet another example, this method can be implemented through the interaction between the chip in the terminal and the chip in the gateway device. The embodiments of the present application do not limit the terminal side and the gateway side, and other cases will not be exemplified one by one here. As Figure 9 shown, this method includes the following steps 901 to 904.

[0119] Step 901, the terminal side sends an authentication request to the gateway side. The authentication request includes the first authentication information stored in the authentication device on the terminal side, and the authentication request is used for the gateway side to authenticate the first authentication information.

[0120] Among them, since the authentication device on the terminal side stores the first authentication information, it is sufficient to carry the first authentication information stored in the authentication device in the authentication request, so that the authentication request includes the first authentication information stored in the authentication device. The user does not need to deploy the client or manually input the authentication information anymore. For the user, the operation is relatively simple. Or rather, no operation is required from the user, so that the process of the terminal side sending an authentication request to the gateway side to establish a communication tunnel can be imperceptible to the user.

[0121] Exemplarily, the first authentication information stored in the authentication device has a relatively high complexity to improve the accuracy of authenticating the first authentication information, ensure the security of the established communication tunnel, and prevent users without access rights from remotely accessing the communication network where the gateway side is located. In Related Art 1 and Related Art 2, since the user needs to manually input the authentication information, the authentication information is often information with a relatively low complexity that the user can remember and understand, such as a user account, a user password, etc. In the embodiments of the present application, since the first authentication information is stored in the authentication device and does not need to be remembered and understood by the user, the first authentication information can have a relatively high complexity. For example, when the length of the first authentication information is greater than or equal to a first threshold, or when the first authentication information includes multiple types of characters and the total number of types is greater than or equal to a second threshold, the first authentication information has a relatively high complexity. Among them, the values of the first threshold and the second threshold can be set according to experience or actual requirements.

[0122] Exemplarily, the first authentication information includes identification information, which is used to uniquely identify the authentication device. For example, when the authentication device is a SIM or eSIM, the identification information is the international mobile subscriber identity (IMSI). Another example is that when the authentication device is a USB Key, the identification information is the identification code used to uniquely identify the USB Key. As mentioned above, in Related Art One and Related Art Two, the authentication information manually input by the user is the user account, user password, etc., but there may be duplicates among these manually input authentication information. For example, different users may both use "user1" as the user account, so there are duplicates among the user accounts of different users, which affects the accuracy of authentication. In the embodiments of the present application, since the first authentication information is stored in the authentication device, based on the characteristic that the authentication device has the identification information used to uniquely identify the authentication device, the first authentication information includes the identification information, so that the first authentication information has uniqueness. Or rather, the first authentication information and the authentication device where the first authentication information is located are in one-to-one correspondence, thus ensuring the accuracy of authenticating the first authentication information, ensuring the security of the subsequent established communication tunnel, and preventing users without access rights from remotely accessing the communication network on the gateway side. Of course, in addition to including the identification information, the first authentication information may also include other information according to actual needs, and the embodiments of the present application do not limit other information.

[0123] Exemplarily, the authentication device is manufactured by the operator and issued to the user, and the first authentication information and the program (such as an applet) are stored in the authentication device during the manufacturing process of the authentication device. In addition, the operator will also send the first authentication information to the mobile communication core network side, and the mobile communication core network side receives and stores the first authentication information, thereby realizing the registration of the authentication device in the mobile communication core network side. To facilitate the distinction from the first authentication information stored in the authentication device, the information stored in the mobile communication core network side is denoted as the second authentication information. Exemplarily, the information content of the first authentication information and the second authentication information is the same, except that the first authentication information is stored in the authentication device and the second authentication information is stored in the mobile communication core network side.

[0124] In an exemplary embodiment, the method provided by the embodiments of the present application further includes: when the terminal side detects the authentication device, obtaining the first authentication information stored in the authentication device, and generating an authentication request according to the first authentication information. Among them, when the terminal side is the terminal, if the authentication device can be inserted into the interface provided by the terminal, the terminal can confirm the detection of the authentication device after detecting that the authentication device is inserted into the interface. If the terminal does not provide an interface and the authentication device is inside the terminal, the terminal can detect the authentication device after startup. Or, when the terminal side is a communication module, circuit, chip or chip system included in the terminal, the detection of the authentication device can be confirmed after establishing a connection with the authentication device.

[0125] When the authentication device is detected, the terminal side obtains the first authentication information stored in the authentication device from the authentication device, so as to generate an authentication request according to the first authentication information. In some embodiments, the authentication device pushes (or actively sends) the first authentication information to the terminal side. For example, the microprocessor in the authentication device loads the operating system and applet stored in the ROM into the RAM, runs the applet on the operating system, and the running applet indicates that the first authentication information needs to be pushed. Therefore, the microprocessor reads the first authentication information stored in the ROM and pushes the first authentication information to the terminal side through the serial communication unit. Or, in some other embodiments, the authentication device sends (or passively sends) the first authentication information to the terminal side according to the read instruction of the terminal side. For example, the microprocessor in the authentication device loads the operating system and applet stored in the ROM into the RAM, runs the applet on the operating system, and the running applet indicates that the first authentication information needs to be sent according to the read instruction. After the terminal side sends a read instruction to the authentication device, the serial communication unit in the authentication device forwards the read instruction to the microprocessor. The microprocessor reads the first authentication information stored in the ROM according to the read instruction and sends the first authentication information to the terminal side through the serial communication unit.

[0126] Exemplarily, in the embodiments of the present application, when the terminal side detects the authentication device and completes the network access process of the authentication device, the terminal side can obtain the first authentication information stored in the authentication device from the authentication device. The network access process is used for the authentication device to obtain service permissions such as Internet access and calls. For example, taking the authentication device including a SIM as an example, the network access process is illustrated. When the terminal side detects that the SIM has been inserted, it reads the IMSI stored in the SIM from the SIM (for the reading method, refer to the description of the reading process of the first authentication information above, which will not be elaborated here), sends the IMSI to the mobile communication core network side. The mobile communication core network side receives and stores the IMSI, and generates a random value and returns it to the terminal side. The terminal side sends the random value to the SIM, and the SIM calculates the first calculation result according to the random value and the key identifier (Ki) value corresponding to the IMSI, and sends the first calculation result to the terminal side. The terminal side forwards the first calculation result to the mobile communication core network side. The mobile communication core network side calculates the second calculation result according to the random value and the Ki value corresponding to the IMSI. If the received first calculation result is consistent with the calculated second calculation result, the network access process of the SIM is completed, and it is confirmed that the SIM has service permissions such as Internet access and calls.

[0127] Exemplarily, after the network access process of the authentication device is completed, the microprocessor in the authentication device loads the operating system and the applet stored in the ROM into the RAM, and runs the applet on the operating system, so that the terminal side can obtain the first authentication information stored in the authentication device from the authentication device in the manner described above based on the running applet.

[0128] In some embodiments, the microprocessor in the authentication device sends a query instruction to the terminal side through the serial communication unit. The terminal side returns status information according to the query instruction, and the status information is used to indicate whether the network access process of the authentication device is completed. After the microprocessor receives the status information through the serial communication unit, if the status information indicates that the network access process of the authentication device has been completed, it can load the operating system and the applet stored in the ROM into the RAM, and run the applet on the operating system, realizing the automatic triggering of the applet operation. If the status information indicates that the network access process of the authentication device has not been completed, the microprocessor does not load the operating system and the applet temporarily, but waits for a certain period of time and then sends a query instruction to the terminal side again until the status information returned by the terminal side according to the query instruction indicates that the network access process of the authentication device has been completed, and then the microprocessor loads the operating system and the applet.

[0129] Alternatively, in some other embodiments, after the network access process of the authentication device is completed, the terminal side sends status information indicating that the network access process of the authentication device has been completed to the authentication device. After the microprocessor in the authentication device receives such status information through the serial communication unit, it can load the operating system and applet stored in the ROM into the RAM and run the applet on the operating system.

[0130] After the terminal side detects the authentication device and obtains the first authentication information stored in the authentication device, the terminal side can generate an authentication request based on the first authentication information. Exemplarily, the terminal side generates an authentication request based on the first authentication information, including: calling the protocol stack interface according to the program call protocol stack stored in the authentication device, and generating an authentication request based on the first authentication information through the protocol stack interface. The protocol stack interface can refer to Figure 8 , Exemplarily, the protocol stack interface includes, but is not limited to: internet protocol (IP) stack interface, cellular stack interface, etc., and the embodiments of the present application do not limit this. Among them, the cellular stack interface is also called the baseband interface.

[0131] In an exemplary embodiment, in addition to sending (actively or passively) the first authentication information to the terminal side, the authentication device also sends a call instruction to the terminal side, and the call instruction is used to indicate calling the protocol stack interface. After the terminal side obtains the first authentication information and the call instruction, it calls the protocol stack interface according to the indication of the call instruction, so that it can generate an authentication request based on the first authentication information through the protocol stack interface.

[0132] Exemplarily, the format of the information stored in the authentication device is the first format, and the format of the information transmitted by the protocol stack interface is the second format. The second format is, for example, the information transmission format defined in the communication protocol used by the protocol stack interface, and the first format is different from the second format. Accordingly, the terminal side generates an authentication request based on the first authentication information through the protocol stack interface, including: the terminal side converts the first authentication information in the first format into the first authentication information in the second format through the protocol stack interface, and generates an authentication request including the first authentication information in the second format. The terminal side sends the authentication request to the gateway side, including: the terminal side sends the authentication request to the gateway side through the protocol stack interface.

[0133] Among them, the first authentication information in the first format is converted into the first authentication information in the second format through the protocol stack interface, that is, the first authentication information is converted from the format suitable for storage in the authentication device to the format suitable for transmission through the protocol stack interface. After obtaining the first authentication information in the second format through conversion, an authentication request can be generated through the protocol stack interface. The first authentication information in the generated authentication request is the first authentication information in the second format. Then, the authentication request including the first authentication information in the second format is sent to the gateway side through the protocol stack interface.

[0134] Step 902, the gateway side receives the authentication request sent by the terminal side.

[0135] After the terminal side sends the authentication request to the gateway side, the authentication request is transmitted through a public network such as the Internet, so that the gateway side can receive the authentication request sent by the terminal side.

[0136] Step 903, when the first authentication information passes the authentication, the gateway side and the terminal side establish a communication tunnel.

[0137] After the gateway side receives the authentication request, it parses the authentication request to obtain the first authentication information included in the authentication request, so as to authenticate the first authentication information. If the first authentication information fails the authentication, it means that the terminal side does not have the permission to access the communication network where the gateway side is located, and the gateway side does not establish a communication tunnel with the terminal side. If the first authentication information passes the authentication, it means that the terminal side has the permission to access the communication network where the gateway side is located, and the gateway side establishes a communication tunnel with the terminal side. In an exemplary embodiment, the communication network where the gateway side is located is a private network, and the communication tunnel includes but is not limited to a virtual private network (VPN) tunnel. In this case, the protocol stack interface described above is also called a VPN interface. The embodiment of the present application does not limit the type of the communication tunnel, and the type can be set according to actual needs.

[0138] In an exemplary embodiment, the method provided by the embodiment of the present application further includes: the gateway side receives the second authentication information sent by the mobile communication core network side. When the first authentication information matches the second authentication information, it is determined that the first authentication information passes the authentication, and an authentication response is sent to the terminal side. The authentication response is used to indicate that the first authentication information passes the authentication. Thus, the terminal side can receive the authentication response and determine that the first authentication information passes the authentication of the gateway side according to the authentication response. In addition, when the first authentication information does not match the second authentication information, the gateway side determines that the first authentication information fails the authentication, and sends a first rejection response to the terminal side. The first rejection response is used to indicate that the first authentication information fails the authentication, for example, fails the authentication of the gateway side.

[0139] According to the description in step 901, the core network side of the mobile communication can store the second authentication information. Therefore, the gateway side can receive the second authentication information sent by the core network side of the mobile communication. For example, the gateway side sends a fetch request to the core network side of the mobile communication and receives the second authentication information returned by the core network side of the mobile communication according to the fetch request. For another example, the gateway side receives the second authentication information pushed by the core network side of the mobile communication. As Figure 8 shown, taking the core network side of the mobile communication including 5GC devices as an example, the UDM module in the core network side of the mobile communication stores the second authentication information, the BSF module obtains the second authentication information from the UDM module, and then sends the second authentication information to the gateway side through the NEF module, so that the gateway side obtains the second authentication information. The process by which the gateway side obtains the second authentication information from the 5GC device is called the General Bootstrapping Architecture (GBA). The embodiments of the present application do not limit the manner in which the gateway side obtains the second authentication information. For example, the gateway side can also obtain the second authentication information through manual configuration and other means.

[0140] Exemplarily, the gateway side can obtain multiple pieces of second authentication information, that is, multiple pieces of second authentication information corresponding one by one to multiple authentication devices. In the case where the first authentication information is different from any of the second authentication information among the multiple pieces of second authentication information, it is determined that the first authentication information does not match the second authentication information, and the first authentication information fails the authentication. In the case where the first authentication information is the same as any one of the second authentication information among the multiple pieces of second authentication information, it is determined that the first authentication information matches the second authentication information, and the first authentication information passes the authentication.

[0141] Exemplarily, the second authentication information is in the first format, and the first authentication information is in the second format. The method provided by the embodiments of the present application further includes: the gateway side converts the second authentication information in the first format into the second authentication information in the second format. That is to say, the first authentication information parsed by the gateway side from the authentication request is in the second format, while the second authentication information obtained from the core network side of the mobile communication is in the first format. Therefore, it is necessary to unify the formats to facilitate determining whether the first authentication information and the second authentication information match.

[0142] In some embodiments, after the gateway side obtains the second authentication information in the first format, it first converts the second authentication information in the first format into the second authentication information in the second format, and then stores the second authentication information in the second format. Thus, after parsing the authentication request to obtain the first authentication information in the second format, the first authentication information in the second format can be matched with the second authentication information in the second format, improving the matching efficiency, and further improving the efficiency of authenticating the first authentication information and the efficiency of establishing a communication tunnel. Among them, the matching of the first authentication information and the second authentication information includes: the first authentication information in the second format is matched with the second authentication information in the second format. If the first authentication information and the second authentication information do not match, it may include: the first authentication information in the second format does not match the second authentication information in the second format.

[0143] Alternatively, in some other embodiments, after the gateway side obtains the second authentication information in the first format, it stores the second authentication information in the first format. After parsing the authentication request to obtain the first authentication information in the second format, the first authentication information in the second format is converted into the first authentication information in the first format, and the first authentication information in the first format is matched with the second authentication information in the first format. Among them, the matching of the first authentication information and the second authentication information includes: the first authentication information in the first format is matched with the first authentication information in the first format. If the first authentication information and the second authentication information do not match, it includes: the first authentication information in the first format is matched with the second authentication information in the first format.

[0144] The above describes the authentication process of the first authentication information by the gateway side. In some embodiments, when the first authentication information and the second authentication information match, the gateway side determines that the first authentication information has passed the authentication, and no other authentication process is performed. It can send an authentication response to the terminal side according to the above description. Alternatively, in some other embodiments, when the first authentication information and the second authentication information match, the gateway side also performs other authentication processes on the first authentication information. When the other authentication processes also pass, it is determined that the first authentication information has passed the authentication, and the authentication response described above is sent to the terminal side. Among them, the other authentication process is, for example, the process of authenticating the first authentication information (referring to the first authentication information that matches the second authentication information) by the mobile communication core network side. This process is also called two-way challenge authentication. Two-way challenge authentication can strengthen the authentication intensity of the first authentication and ensure the security of the established communication tunnel, thereby preventing users without access rights from remotely accessing the communication network where the gateway side is located.

[0145] For the case where other authentication processes are also performed, in the embodiments of the present application, when the first authentication information matches the second authentication information, it is determined that the first authentication information passes the authentication, including: when the first authentication information matches the second authentication information, the gateway side sends a challenge request to the mobile communication core network side, the challenge request includes the first authentication information, and the challenge request is used for the mobile communication core network side to authenticate the first authentication information; receiving the challenge response sent by the mobile communication core network side, and determining that the first authentication information passes the authentication, where the challenge response is used to indicate that the first authentication information passes the authentication of the mobile communication core network side.

[0146] Wherein, the mobile communication core network side receives the challenge request, parses the challenge request to obtain the first authentication information, and authenticates the first authentication information. If the first authentication information fails to pass the authentication, the mobile communication core network side sends a second rejection response to the gateway side, and the second rejection response is used to indicate that the first authentication information fails to pass the authentication of the mobile communication core network side. If the first authentication information passes the challenge authentication, the mobile communication core network side sends a challenge response to the gateway side, and the challenge response indicates that the first authentication information passes the authentication of the mobile communication core network side.

[0147] Correspondingly, if the gateway side receives the second rejection response sent by the mobile communication core network side, it means that the first authentication information only passes the authentication of the gateway side and fails to pass the authentication of the mobile communication core network side. Then, the gateway side can send a third rejection response to the terminal side, and the third rejection response is used to indicate that the first authentication information fails to pass the authentication, for example, passes the authentication of the gateway side but fails to pass the authentication of the mobile communication core network side. If the gateway side receives the challenge response sent by the mobile communication core network side, it means that the first authentication information passes both the authentication of the gateway side and the authentication of the mobile communication core network side. Then, the gateway side can send the authentication response described above to the terminal side.

[0148] In an exemplary embodiment, the mobile communication core network side can authenticate the first authentication information in multiple ways based on the authentication and key management for applications (AKMA) mechanism, so that there are multiple situations where the first authentication information passes the authentication of the mobile communication core network side. Exemplarily, the multiple situations include, but are not limited to, the following Situation 1 to Situation 3.

[0149] Situation 1, when the first authentication information matches the third authentication information of the mobile communication core network side, the first authentication information passes the authentication of the mobile communication core network side, and the third authentication information is obtained by updating the second authentication information of the mobile communication core network side.

[0150] After storing the second authentication information on the mobile communication core network side, the communication network where the gateway side is located can update the second authentication information in the mobile communication core network side according to the actual situation to obtain the third authentication information. For example, if the server in the communication network determines that an authentication device originally had the permission to access the communication network but no longer has such permission, it sends a first update instruction to the mobile communication core network side. The first update instruction is used to delete the second authentication information corresponding to the authentication device from the second authentication information in the mobile communication core network side to obtain the third authentication information. Another example is that if the server in the communication network determines that an authentication device originally did not have the permission to access the communication network but is updated to have the permission to access the communication network, it sends a second update instruction to the mobile communication core network side. The second update instruction is used to add the second authentication information corresponding to the authentication device to the second authentication information in the mobile communication core network side to obtain the third authentication information.

[0151] It can be seen that the third authentication information is different from the second authentication information. If only the gateway side matches the first authentication information and the second authentication information to complete the authentication, the authentication may be inaccurate, and it is also necessary to match the first authentication information and the third authentication information by the mobile communication core network side. Among them, if the first authentication information is different from any of the third authentication information in the third authentication information on the mobile communication core network side, the first authentication information does not match the third authentication information, and the first authentication information fails the authentication by the mobile communication core network side. If the first authentication information is the same as any one of the third authentication information on the mobile communication core network side, the first authentication information matches the third authentication information, and the first authentication information passes the authentication by the mobile communication core network side.

[0152] Exemplarily, in addition to determining whether the first authentication information matches the third authentication information by the mobile communication core network side, the gateway side can also determine whether the first authentication information matches the third authentication information. For example, the gateway side can obtain the third authentication information from the mobile communication core network side, so as to determine whether the first authentication information matches the third authentication information on the gateway side.

[0153] Case 2: When the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication by the mobile communication core network side, and the terminal side and the reference terminal side where the authentication device is located are determined according to the first authentication information.

[0154] According to the description in step 901, there is an access process between the terminal side and the mobile communication core network side. The mobile communication core network side can record the first correspondence relationship between the first authentication information of the authentication device and the terminal side where the authentication device is located during the access process. In addition, the mobile communication core network side can also record the second correspondence relationship between the first authentication information of the authentication device and the reference terminal side bound to the authentication device, and this second correspondence relationship can be configured in the mobile communication core network side by the operator or the server in the communication network. Therefore, the mobile communication core network side can query the first correspondence relationship according to the first authentication information to obtain the terminal side where the authentication device is located, and the mobile communication core network side can also query the second correspondence relationship according to the first authentication information to obtain the reference terminal side bound to the authentication device.

[0155] If the terminal side where the authentication device is located is different from the reference terminal side, then the terminal side where the authentication device is located does not match the reference terminal side bound to the authentication device, and the first authentication information fails the authentication of the mobile communication core network side. If the terminal side where the authentication device is located is the same as the reference terminal side, then the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, and the first authentication information passes the authentication of the mobile communication core network side.

[0156] Of course, using whether the terminal side where the authentication device is located is the same as the reference terminal side to determine whether the terminal side where the authentication device is located matches the reference terminal side is only an example and is not used to limit the embodiments of the present application. The embodiments of the present application can also determine whether the terminal side where the authentication device is located matches the reference terminal side by means such as whether the terminal side where the authentication device is located and the reference terminal side are devices of the same type. For example, when the terminal side where the authentication device is located and the reference terminal side are devices of the same type, it is determined that the terminal side where the authentication device is located matches the reference terminal side.

[0157] Case 3: When the terminal side where the authentication device is located is within the specified range, the first authentication information passes the authentication of the mobile communication core network side.

[0158] The mobile communication core network side can record the third correspondence relationship between the first authentication information of the authentication device and the location where the terminal side where the authentication device is located during the access process. The location where the terminal side is located is, for example, the location where the terminal side is located when the access process is executed. In addition, the mobile communication core network side can also record the fourth correspondence relationship between the first authentication information of the authentication device and the specified range used as a reference, and this fourth correspondence relationship can be configured in the mobile communication core network side by the operator or the server in the communication network. Therefore, the mobile communication core network side can query the third correspondence relationship according to the first authentication information to obtain the location where the terminal side where the authentication device is located, and the mobile communication core network side can also query the fourth correspondence relationship according to the first authentication information to obtain the specified range used as a reference.

[0159] If the location of the terminal side is outside the specified range, the terminal side where the authentication device is located is not within the specified range, and the first authentication information fails the authentication on the mobile communication core network side. If the location of the terminal side is within the specified range, the terminal side where the authentication device is located is within the specified range, and the first authentication information passes the authentication on the mobile communication core network side.

[0160] In the embodiments of the present application, the three cases exemplified above can be flexibly combined. For example, cases one and two can be combined. Then, when the first authentication information matches the third authentication information on the mobile communication core network side, and the terminal side where the authentication device is located also matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication on the mobile communication core network side. For other combination methods, no further examples will be given here.

[0161] Regardless of the method used to authenticate the first authentication information, when the first authentication information passes the authentication, the gateway side can establish a communication tunnel with the terminal side. For example, the gateway side negotiates with the terminal side to establish a communication tunnel. During this negotiation process, the gateway side sends the address of the first interface of the gateway side to the terminal side, and the terminal side sends the address of the second interface of the terminal side to the gateway side, thereby establishing a communication tunnel between the first interface and the second interface. This communication tunnel can be used for interaction between the terminal side and the gateway side. For example, refer to Figure 8 , a client for generating service traffic is installed on the terminal side. The service traffic generated by the client can be transmitted to the gateway side of the communication network through the communication tunnel. The gateway side forwards the service traffic to the server of the communication network, and the server can also respond through the communication tunnel and the gateway side, thereby realizing the user's remote access to the communication network.

[0162] Step 904, when the first authentication information passes the authentication of the gateway side, the terminal side and the gateway side establish a communication tunnel.

[0163] According to the description in step 903, when the first authentication information passes the authentication on the gateway side, the gateway side sends an authentication response to the terminal side, and this authentication response is used to indicate that the first authentication information has passed the authentication. Therefore, the terminal side can receive the authentication response sent by the gateway side and determine that the first authentication information has passed the authentication based on this authentication response. For example, when the gateway side does not perform other authentication processes in step 903, the terminal side determines that the first authentication information has passed the authentication of the gateway side based on the authentication response. Another example is that when the gateway side performs other authentication processes in step 903, the terminal side determines that the first authentication information has passed the authentication of the gateway side and the authentication of the mobile communication core network side based on the authentication response. Then, the terminal side can establish a communication tunnel with the gateway side. The process of establishing the communication tunnel can refer to the description in step 903 and will not be elaborated here.

[0164] In summary, the terminal side can send an authentication request carrying the first authentication information stored in the authentication device of the terminal side to the gateway side. When the first authentication information passes the authentication, a communication tunnel can be established between the terminal side and the gateway side, enabling the user to remotely access the communication network where the gateway side is located through the communication tunnel. Compared with Related Art One and Related Art Two, in the embodiment of the present application, the user does not need to deploy a client and does not need to manually input authentication information either. The terminal side can automatically use the first authentication information stored in the authentication device. Thus, not only the establishment efficiency and success rate of the communication tunnel are improved, but also the user experience is enhanced because the establishment process of the communication tunnel can be imperceptible to the user, and the establishment process of the communication tunnel can be automatically completed after the terminal side is started.

[0165] The embodiment of the present application also provides a method for establishing a communication tunnel. This method is applied to a communication system, and the communication system includes a terminal side and a gateway side. The terminal side includes an authentication device. This method includes the following steps 1 to 3.

[0166] Step 1, the terminal side sends an authentication request to the gateway side. The authentication request includes the first authentication information stored in the authentication device of the terminal side, and the authentication request is used for the gateway side to authenticate the first authentication information.

[0167] In an exemplary embodiment, the first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device. Exemplarily, the authentication device includes a SIM. Exemplarily, the authentication device includes a USB key.

[0168] Exemplarily, before the terminal side sends an authentication request to the gateway side, the method further includes: when the terminal side detects the authentication device, it obtains the first authentication information stored in the authentication device; the terminal side generates an authentication request according to the first authentication information.

[0169] In an exemplary embodiment, the terminal side generates an authentication request based on the first authentication information, including: the terminal side calls the protocol stack interface according to the program stored in the authentication device, and the terminal side generates an authentication request through the protocol stack interface according to the first authentication information.

[0170] Exemplarily, the format of the information stored in the authentication device is the first format, and the format of the information transmitted by the protocol stack interface is the second format. The terminal side generates an authentication request through the protocol stack interface according to the first authentication information, including: the terminal side converts the first authentication information in the first format into the first authentication information in the second format through the protocol stack interface, and generates an authentication request including the first authentication information in the second format. The terminal side sends the authentication request to the gateway side, including: the terminal side sends the authentication request to the gateway side through the protocol stack interface.

[0171] The implementation manner of this step 1 can refer to the description in step 901 above, and will not be elaborated here.

[0172] Step 2, the gateway side receives the authentication request sent by the terminal side.

[0173] Exemplarily, the method further includes: the gateway side receives the second authentication information sent by the mobile communication core network side; in the case where the first authentication information matches the second authentication information, the gateway side determines that the first authentication information passes the authentication; the gateway side sends an authentication response to the terminal side, and the authentication response is used to indicate that the first authentication information passes the authentication, and the terminal side receives the authentication response sent by the gateway side, and the authentication response is used to indicate that the first authentication information passes the authentication of the gateway side.

[0174] In an exemplary embodiment, in the case where the first authentication information matches the second authentication information, the gateway side determines that the first authentication information passes the authentication, including: in the case where the first authentication information matches the second authentication information, the gateway side sends a challenge request to the mobile communication core network side, and the challenge request includes the first authentication information, and the challenge request is used for the mobile communication core network side to authenticate the first authentication information; the gateway side receives the challenge response sent by the mobile communication core network side, and determines that the first authentication information passes the authentication, and the challenge response is used to indicate that the first authentication information passes the authentication of the mobile communication core network side.

[0175] Exemplarily, in the case where the first authentication information matches the third authentication information of the mobile communication core network side, the first authentication information passes the authentication of the mobile communication core network side, and the third authentication information is obtained by updating the second authentication information of the mobile communication core network side.

[0176] In an exemplary embodiment, in the case where the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication of the mobile communication core network side, and the terminal side where the authentication device is located and the reference terminal side are determined according to the first authentication information.

[0177] In an exemplary embodiment, the second authentication information is in a first format, and the first authentication information is in a second format. The method further includes: the gateway side converts the second authentication information in the first format into the second authentication information in the second format. Wherein, the matching of the first authentication information and the second authentication information includes: the first authentication information in the second format matches the second authentication information in the second format.

[0178] The implementation manner of this step 2 can refer to the description in step 902 above, and will not be elaborated here.

[0179] Step 3, when the first authentication information passes the authentication of the gateway side, a communication tunnel is established between the gateway side and the terminal side.

[0180] The implementation manner of this step 3 can refer to the descriptions in step 903 and step 904 above, and will not be elaborated here. Exemplarily, the communication tunnel includes a VPN tunnel.

[0181] The beneficial effects of the above steps 1 to 3 are the same as those of Figure 9 the method for establishing a communication tunnel shown, and will not be elaborated here.

[0182] The method for establishing a communication tunnel provided by the embodiments of the present application is introduced above. Corresponding to the above method, the embodiments of the present application also provide a device for establishing a communication tunnel. Figure 10 FIG. shows a possible exemplary block diagram of a device for establishing a communication tunnel involved in the embodiments of the present application. As Figure 10 shown, the device for establishing a communication tunnel may include modules or units for implementing the corresponding method embodiments above, such as modules or units for implementing the steps executed by the terminal side in the above method embodiments. Exemplarily, the device for establishing a communication tunnel includes a transceiver module 1001 and an establishment module 1002.

[0183] The transceiver module 1001 is configured to send an authentication request to the gateway side. The authentication request includes the first authentication information stored in the authentication device of the terminal side, and the authentication request is used for the gateway side to authenticate the first authentication information;

[0184] The establishment module 1002 is configured to establish a communication tunnel with the gateway side when the first authentication information passes the authentication of the gateway side.

[0185] In an exemplary embodiment, the transceiver module 1001 is further configured to receive an authentication response sent by the gateway side, and the authentication response is used to indicate that the first authentication information passes the authentication of the gateway side.

[0186] In an exemplary embodiment, the device further includes: a generation module, configured to obtain the first authentication information stored in the authentication device when detecting the authentication device; generate an authentication request according to the first authentication information.

[0187] In an exemplary embodiment, a generation module is configured to call a protocol stack interface according to a program stored in an authentication device; and generate an authentication request according to the first authentication information through the protocol stack interface.

[0188] In an exemplary embodiment, the format of the information stored in the authentication device is a first format, and the format of the information transmitted by the protocol stack interface is a second format;

[0189] The generation module is configured to convert the first authentication information in the first format into the first authentication information in the second format through the protocol stack interface, and generate an authentication request including the first authentication information in the second format;

[0190] A transceiver module 1001 is configured to send the authentication request to the gateway side through the protocol stack interface.

[0191] In an exemplary embodiment, the first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device.

[0192] In an exemplary embodiment, the authentication device includes a SIM.

[0193] In an exemplary embodiment, the authentication device includes a USB key.

[0194] In an exemplary embodiment, the communication tunnel includes a VPN tunnel.

[0195] Exemplarily, Figure 10 The device for establishing a communication tunnel shown may be the terminal side in the above embodiment. For example, the terminal side includes a terminal, a communication module in the terminal, a circuit, a chip, or a chip system in the terminal responsible for communication functions.

[0196] In some embodiments, when Figure 10 The device for establishing a communication tunnel shown is a terminal or a communication module in the terminal, the function of the establishment module 1002 may be implemented by one or more processors. The processor may include: a modem chip, or a SoC chip or a SIP chip including a modem core. The function of the transceiver module 1001 may be implemented by a transceiver circuit.

[0197] In other embodiments, when Figure 10 The device for establishing a communication tunnel shown is a circuit, a chip, or a chip system in the terminal responsible for communication functions, such as a modem chip or a SoC chip or a SIP chip including a modem core, the function of the establishment module 1002 may be implemented by a circuit system including one or more processors or processor cores in the above chip. The function of the transceiver module 1001 may be implemented by an interface circuit or a data transceiver circuit on the above chip.

[0198] The embodiment of the present application also provides another device for establishing a communication tunnel. Figure 11 Fig. shows a possible exemplary block diagram of a device for establishing a communication tunnel involved in the embodiment of the present application. As Figure 11 shown, the device for establishing a communication tunnel may include modules or units corresponding to the above method embodiments, such as modules or units for implementing the steps executed on the gateway side in the above method embodiments. Exemplarily, the device for establishing a communication tunnel includes the following transceiver module 1101 and establishment module 1102.

[0199] The transceiver module 1101 is configured to receive an authentication request sent by the terminal side, where the authentication request includes first authentication information stored in an authentication device on the terminal side;

[0200] The establishment module 1102 is configured to establish a communication tunnel with the terminal side when the first authentication information passes the authentication.

[0201] In an exemplary embodiment, the transceiver module 1101 is further configured to receive second authentication information sent by the mobile communication core network side; determine that the first authentication information passes the authentication when the first authentication information matches the second authentication information; and send an authentication response to the terminal side, where the authentication response is used to indicate that the first authentication information passes the authentication.

[0202] In an exemplary embodiment, the transceiver module 1101 is configured to send a challenge request to the mobile communication core network side when the first authentication information matches the second authentication information, where the challenge request includes the first authentication information and is used for the mobile communication core network side to authenticate the first authentication information; receive a challenge response sent by the mobile communication core network side, and determine that the first authentication information passes the authentication, where the challenge response is used to indicate that the first authentication information passes the authentication by the mobile communication core network side.

[0203] In an exemplary embodiment, when the first authentication information matches the third authentication information on the mobile communication core network side, the first authentication information passes the authentication by the mobile communication core network side, and the third authentication information is obtained by updating the second authentication information on the mobile communication core network side.

[0204] In an exemplary embodiment, when the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication by the mobile communication core network side, and the terminal side where the authentication device is located and the reference terminal side are determined according to the first authentication information.

[0205] In an exemplary embodiment, the second authentication information is in a first format, and the first authentication information is in a second format. The apparatus further includes: a conversion module configured to convert the second authentication information in the first format into the second authentication information in the second format; wherein, the matching of the first authentication information and the second authentication information includes: the matching of the first authentication information in the second format and the second authentication information in the second format.

[0206] In an exemplary embodiment, the first authentication information includes identification information, and the identification information is used to uniquely identify an authentication device.

[0207] In an exemplary embodiment, the authentication device includes a SIM.

[0208] In an exemplary embodiment, the authentication device includes a USB key.

[0209] In an exemplary embodiment, the communication tunnel includes a VPN tunnel.

[0210] Exemplarily, Figure 11 The apparatus for establishing a communication tunnel shown may be the gateway side in the above embodiment. For example, the gateway side includes a gateway device, a communication module in the gateway device, a circuit, a chip, or a chip system in the gateway device responsible for communication functions.

[0211] In some embodiments, when Figure 11 The apparatus for establishing a communication tunnel shown is a gateway device or a communication module in the gateway device, the function of the establishment module 1102 may be implemented by one or more processors. The processor may include: a modem chip, or a SoC chip or a SIP chip including a modem core. The function of the transceiver module 1101 may be implemented by a transceiver circuit.

[0212] In other embodiments, when Figure 11 The apparatus for establishing a communication tunnel shown is a circuit, a chip, or a chip system in the gateway device responsible for communication functions, such as a modem chip or a SoC chip or a SIP chip including a modem core, the function of the establishment module 1102 may be implemented by a circuit system including one or more processors or processor cores in the above chip. The function of the transceiver module 1101 may be implemented by an interface circuit or a data transceiver circuit on the above chip.

[0213] It should be understood that when the above Figure 10 and Figure 11 shown apparatus implements its functions, the beneficial effects it has are the same as Figure 9The beneficial effects of the methods shown are the same. The division of modules in the above device is only a division of logical functions. Each function can correspond to a functional module, or two or more functions can be integrated into one functional module. In actual implementation, all or part of the modules can be integrated into one physical entity or distributed among different physical entities. In addition, the above functional modules can be implemented in the form of hardware, software, or a combination of hardware and software. Additionally, the device provided in the above embodiment and the method embodiment belong to the same concept. For the specific implementation process, please refer to the method embodiment and will not be elaborated here.

[0214] In an exemplary embodiment, the functional module in any of the above devices can be configured as: one or more integrated circuits for implementing the above methods. For example, one or more application specific integrated circuits (ASICs), or one or more central processing units (CPUs), one or more microcontroller units (MCUs), one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.

[0215] Optionally, any of the above devices may further include a storage module for storing at least one of program code or data. Exemplarily, the storage module may include at least one of random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory or registers, etc.

[0216] See Figure 12 , Figure 12 shows a schematic structural diagram of a device 1200 for establishing a communication tunnel according to an exemplary embodiment of the present application. The device 1200 for establishing a communication tunnel includes at least one processor 1201, a memory 1203, and at least one network interface 1204.

[0217] The processor 1201 is, for example, a general-purpose CPU, DSP, network processor (NP), graphics processing unit (GPU), neural-network processing units (NPU), data processing unit (DPU), microprocessor, or one or more integrated circuits or ASICs, programmable logic devices (PLDs), other general-purpose processors, or other programmable logic devices, discrete gates, transistor logic devices, discrete hardware components, or any combination thereof for implementing the solution of this application. The PLD is, for example, a complex programmable logic device (CPLD), FPGA, generic array logic (GAL), or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor, etc. It should be noted that the processor can be a processor that supports the advanced RISC machines (ARM) architecture. It can implement or execute various logic blocks, modules, and circuits described in connection with the disclosure of this application. The processor can also be a combination that implements computing functions, such as including a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on.

[0218] Optionally, the device 1200 for establishing a communication tunnel further includes a bus 1202. The bus 1202 is used to transfer information between the components of the device 1200 for establishing a communication tunnel. The bus 1202 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus 1202 can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 12 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus.

[0219] The memory 1203 is, for example, a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache.

[0220] By way of example but not limitation, many forms of ROM and RAM are available. For example, the ROM is a compact disc read-only memory (CD-ROM). The RAM includes but is not limited to static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0221] The memory 1203 may also be other types of storage devices that can store static information and instructions. Or it may be other types of dynamic storage devices that can store information and instructions. Or it may be other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1203 is, for example, stand-alone and connected to the processor 1201 through the bus 1202. The memory 1203 may also be integrated with the processor 1201.

[0222] The network interface 1204 uses any transceiver-like device for communicating with other devices or communication networks, which can be Ethernet, radio access network (RAN), wireless local area network (WLAN), etc. The network interface 1204 can include a wired network interface and can also include a wireless network interface. Specifically, the network interface 1204 can be an Ethernet interface, such as a fast Ethernet (FE) interface, a gigabit Ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a WLAN interface, a cellular network interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In some embodiments of the present application, the network interface 1204 can be used for the device 1200 that establishes a communication tunnel to communicate with other devices.

[0223] In a specific implementation, as some embodiments, the processor 1201 can include one or more CPUs, such as Figure 12 CPU0 and CPU1 shown in. Each of these processors can be a single-core processor or a multi-core processor. The processor here can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0224] In a specific implementation, as some embodiments, the device 1200 that establishes a communication tunnel can include multiple processors, such as Figure 12 the processor 1201 and the processor 1205 shown in. Each of these processors can be a single-core processor or a multi-core processor. The processor here can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0225] In some embodiments, the memory 1203 is used to store the program instructions 1210 for executing the solution of the present application, and the processor 1201 can execute the program instructions 1210 stored in the memory 1203. That is, the device 1200 that establishes a communication tunnel can implement the method provided in the method embodiment through the processor 1201 and the program instructions 1210 in the memory 1203, that is, Figure 9 the method shown. The program instructions 1210 can include one or more software modules. Optionally, the processor 1201 itself can also store the program instructions for executing the solution of the present application.

[0226] In a specific implementation process, the device 1200 for establishing a communication tunnel in the present application may correspond to a terminal or a gateway device for executing the above method. The processor 1201 in the device 1200 for establishing a communication tunnel reads the instructions in the memory 1203, so that Figure 12 the device 1200 for establishing a communication tunnel shown is capable of executing all or part of the steps in the method embodiment.

[0227] The device 1200 for establishing a communication tunnel may also correspond to the above Figure 10 or Figure 11 shown device, Figure 10 or Figure 11 and each functional module in the shown device is implemented by the software of the device 1200 for establishing a communication tunnel. In other words, Figure 10 or Figure 11 the functional modules included in the shown device are generated after the processor 1201 of the device 1200 for establishing a communication tunnel reads the program instructions 1210 stored in the memory 1203.

[0228] Among them, Figure 9 each step of the shown method is completed by the integrated logic circuit of the hardware in the processor of the device 1200 for establishing a communication tunnel or the instructions in the form of software. Combining the steps of the method embodiment disclosed in the present application can be directly embodied as being executed and completed by the hardware processor, or executed and completed by the combination of the hardware and software modules in the processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method embodiment. To avoid repetition, it will not be described in detail here.

[0229] Referring to Figure 13 , which is a schematic structural diagram of a terminal 1300 provided by an embodiment of the present application. The terminal 1300 may correspond to Figure 4 , Figure 5 or Figure 8 the terminal shown in, and is used to implement the operations of the terminal in the above embodiments. As Figure 13 shown, the terminal includes: one or more antennas 1310, a radio frequency processing system 1320, and a processor system 1330.

[0230] In the downlink direction, the radio frequency processing system 1320 receives a radio frequency signal through the antenna 1310 and sends the signal after radio frequency processing to the processor system 1330 for further processing. In the uplink direction, the processor system 1330 processes the information on the terminal side into a signal and sends it to the radio frequency processing system 1320. The radio frequency processing system 1320 performs radio frequency processing on the signal and then sends it through the antenna 1310.

[0231] In one example, the radio frequency (RF) processing system 1320, as a communication interface for the terminal to communicate externally, may include an RF front end 1321 (RF Front end, RFFE) and an RF transceiver 1322. The RFFE 1321 is mainly used to perform processing such as shaping, passband selection, and / or gain on the RF signal received by the antenna or the RF signal to be sent through the antenna, and may include one or more of components such as an RF switch, a duplexer, a filter, a power amplifier, antenna tuning, and a low noise amplifier. The RFFE 1321 may be a circuit system composed of multiple discrete devices or may be integrated and packaged in one or more chips. The RF transceiver 1322 is used to process the RF signal received by the RFFE into a baseband / intermediate frequency signal for the processor system 1330 to perform further processing, and to process the baseband / intermediate frequency signal provided by the processor system 1330 into an RF signal to be sent to the RFFE 1321. The baseband / intermediate frequency signal transmitted between the transceiver 1320 and the processor system 1330 may be a digital signal or an analog signal. The RF transceiver 1322 may be implemented by one or more chips, which are usually referred to as RF integrated circuits (RFICs).

[0232] In one example, the processor system 1330 may include one or more processors for processing signals and executing one or more communication protocols, as well as a memory 1336. In one example, the one or more processors include at least one baseband processor 1331 (also known as a modem processor). The memory 1336 is used to store data and / or computer program instructions. Optionally, the processor system 1330 may further include one or more application processors 1332 for implementing the processing of the terminal operating system and the application layer; optionally, the processor system 1330 may further include a voice subsystem 1333, a multimedia subsystem 1334, an interface circuit 1335, and / or a memory 1336. Among them, the voice subsystem 1333 is used to process voice signals, the multimedia subsystem 1334 is used to process multimedia-related operations, such as video codec and image processing, etc., and the interface circuit 1335 is used to implement communication with other terminal components, such as a display 1340, an input device 1350, a memory 1360, etc. The above components in the processor system 1330 may communicate with each other through a bus or a communication interface circuit.

[0233] In one example, the processor system 1330 may be packaged into a processor chip, such as a system-on-a-chip (SoC) chip or a system-in-package (SIP) chip. In one example, the processor system 1330 may be a system composed of multiple chips. For example, the baseband processor 1331 may be separately packaged into a chip, or packaged into a chip together with part or all of the circuits of the RF processing system.

[0234] In one example, the memory 1336 may be an on-chip memory, i.e., located on the chip of the processor system 1330. In one example, the memory 1360 may be an off-chip memory, i.e., located outside the chip of the processor system 1330.

[0235] In one example, the baseband processor 1331 may include one or more processor cores 13311, a memory 13312, and an interface circuit 13314. The one or more processor cores 13311 are used to process signals and execute one or more communication protocols. The memory 13312 is used to store at least part of the corresponding computer program instructions and / or data. In one example, the one or more processor cores 13311 implement the related operations in the above method embodiments (such as Figure 9 each operation in the method embodiment shown). In this application, the memory 13312 being used to store the corresponding computer program instructions and / or data may mean that the memory 13312 is used to store all the corresponding computer program instructions and / or data for the processor core 13311 to execute; or it may mean that the memory 13312 is used to store part of the corresponding computer program instructions and / or data, and this part of the corresponding computer program instructions and / or data includes the computer program instructions and / or data that the processor 13311 currently needs to execute. The memory 13312 may store different parts of the computer program instructions and / or data multiple times for the processor core 13311 to execute to implement the related operations in the above method embodiments. The interface circuit 13314 is used as a communication interface to implement communication with other components, such as transmitting signals to the radio frequency processing system 1320, and communicating with other subsystems and related components of the processor system 1330 through a bus, such as transmitting data control signals between the application processor 1332 and the voice subsystem communication 1333, and transmitting data or computer program instructions between the memory 1336 or the memory 1360. Optionally, in order to reduce the load of the processor core, a baseband signal processing circuit 13313 may also be provided to implement at least part of the baseband signal processing work, including signal demodulation, modulation, encoding, or decoding, etc.

[0236] In one example, the device for establishing a communication tunnel provided in this application may be the terminal 1300, a communication module including the processor system 1330 and the radio frequency system 1320, the processor system 1330, or the baseband processor 1331.

[0237] The above-mentioned processor, processor system, application processor, baseband processor, processor circuit or processor core may be collectively referred to as a processor, which may include one or a combination of a central processing unit (CPU), DSP, microprocessor unit (MPU), MCU, GPU, FPGA, artificial intelligence processor, or NPU.

[0238] The above-mentioned memory may include one or more of the following storage media: such as RAM, SRAM, DRAM, phase-change memory (PCM), resistive RAM (ReRAM), magnetoresistive RAM (MRAM), ferroelectric RAM (FRAM), cache, register, ROM, flash memory, EPROM, hard disk, etc. In one example, the computer program instructions for executing the above-mentioned embodiments may be stored on a non-volatile memory, such as at least a part of the above-mentioned memory 1360 (such as one or more of ROM, Flash memory, EPROM, or Hard disk). When the terminal is running, the corresponding computer program instructions may be partially or fully loaded onto a memory with a faster transmission speed with the processor, such as at least a part of the above-mentioned memory 1336 and / or memory 13312 (such as one or more of RAM, SRAM, DRAM, PCM, RERAM, MRAM, FRAM, cache, or Register), for the processor to execute to implement the steps in the above-mentioned method embodiments.

[0239] In one example, the radio frequency transceiver 1322 and the RFFE 1321 may also be packaged in one chip. In one example, the radio frequency transceiver 1322, the RFFE 1321, and the baseband processor 1331 may also be packaged in one chip.

[0240] In an exemplary embodiment, the embodiment of the present application provides a device for establishing a communication tunnel. The device includes a memory and a processor; at least one computer instruction is stored in the memory, and the at least one computer instruction is loaded and executed by the processor so that the device for establishing a communication tunnel realizes Figure 9Steps performed by the terminal side or the gateway side in the method for establishing a communication tunnel as shown. Among them, at least one computer instruction may refer to part or all of the computer program or instructions required to implement the above method for establishing a communication tunnel. Exemplarily, the apparatus for establishing a communication tunnel may further include an interface circuit, and the processor is used to communicate with other devices or components through the interface circuit. Optionally, there is one or more processors, and there is one or more memories.

[0241] For example, in the case where the apparatus for establishing a communication tunnel implements the steps performed by the terminal side in the method for establishing a communication tunnel, the apparatus for establishing a communication tunnel may be a terminal, a communication module in the terminal, a circuit, a chip, or a chip system responsible for the communication function in the terminal, and so on. For another example, in the case where the apparatus for establishing a communication tunnel implements the steps performed by the gateway side in the method for establishing a communication tunnel, the apparatus for establishing a communication tunnel may be a gateway device, a component in the gateway device, and so on. The components in the gateway device include but are not limited to: a communication module, a circuit, a chip, or a chip system, and so on.

[0242] In an exemplary embodiment, the embodiments of the present application provide a communication system, which includes a terminal side and a gateway side. The terminal side is used to execute Figure 9 the steps performed by the terminal side in the method for establishing a communication tunnel as shown, and the gateway side is used to execute Figure 9 the steps performed by the gateway side in the method for establishing a communication tunnel as shown.

[0243] In an exemplary embodiment, the embodiments of the present application provide a computer program or a computer program product, which includes: computer instructions. When the computer instructions are run on a computer, the computer is caused to execute Figure 9 the steps performed by the terminal side or the gateway side in the method for establishing a communication tunnel as shown.

[0244] In an exemplary embodiment, the embodiments of the present application provide a computer-readable storage medium, which stores computer instructions. When the computer instructions are run on a computer, the steps performed by the terminal side or the gateway side in the above Figure 9 method for establishing a communication tunnel as shown are executed by the computer.

[0245] Exemplarily, the above computer may refer to a terminal, a gateway device, or a base station, and the embodiments of the present application do not make any limitations in this regard.

[0246] In this application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and effects. It should be understood that there is no logical or chronological dependency between "first", "second", and "nth", nor are the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another.

[0247] It should also be understood that in various embodiments of this application, the magnitude of the serial numbers of each process does not indicate the order of execution. The execution order of each process should be determined by its function and internal logic, and should not impose any limitation on the implementation process of the embodiments of this application.

[0248] In this application, the meaning of the term "at least one" refers to one or more, and the meaning of the term "a plurality of" refers to two or more. For example, a plurality of second feature information refers to two or more second feature information. In this article, the terms "system" and "network" are often used interchangeably.

[0249] It should be understood that the terms used in the description of various examples herein are only for describing specific examples and are not intended to be limiting. As used in the description of various examples and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0250] It should also be understood that the term "and / or" used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or" is a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Among them, A and B can be singular or plural. In addition, the character " / " in this application generally represents an "or" relationship between the front and back associated objects. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, "at least one of A, B, or C" includes A, B, C, AB, AC, BC, or ABC, and "at least one of A, B, and C" can also be understood to include A, B, C, AB, AC, BC, or ABC.

[0251] It should also be understood that the terms "if" and "when" can be interpreted to mean "when" or "upon" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if it is determined that..." or "if [the stated condition or event] is detected" can be interpreted to mean "when it is determined that..." or "in response to determining..." or "when [the stated condition or event] is detected" or "in response to detecting [the stated condition or event]".

[0252] Those skilled in the art will appreciate that the embodiments of the present application may be provided as a method, a system, or a computer program product. Accordingly, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, optical storage, etc.) that contain computer-usable program code.

[0253] In the present application, the description has been made with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices produce means for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0254] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means that implement the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0255] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are performed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0256] The above are only embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall be included within the protection scope of the present application.

Claims

1. A method for establishing a communication tunnel, characterized in that, The method is applicable to the terminal side, and the method includes: Sending an authentication request to the gateway side, where the authentication request includes first authentication information stored in an authentication device on the terminal side, and the authentication request is used for the gateway side to authenticate the first authentication information; Establishing a communication tunnel with the gateway side when the first authentication information passes the authentication of the gateway side.

2. The method according to claim 1, characterized in that The method further includes: Receiving an authentication response sent by the gateway side, where the authentication response is used to indicate that the first authentication information passes the authentication of the gateway side.

3. The method according to claim 1 or 2, characterized in that, Before sending the authentication request to the gateway side, the method further includes: When detecting the authentication device, obtaining the first authentication information stored in the authentication device; Generating the authentication request according to the first authentication information.

4. The method according to claim 3, characterized in that, The generating the authentication request according to the first authentication information includes: Invoking a protocol stack interface according to a program stored in the authentication device; Generating the authentication request according to the first authentication information through the protocol stack interface.

5. The method according to claim 4, wherein The format of the information stored in the authentication device is a first format, and the format of the information transmitted by the protocol stack interface is a second format; The generating the authentication request according to the first authentication information through the protocol stack interface includes: converting the first authentication information in the first format into the first authentication information in the second format through the protocol stack interface, and generating an authentication request including the first authentication information in the second format; The sending the authentication request to the gateway side includes: sending the authentication request to the gateway side through the protocol stack interface.

6. The method according to any one of claims 1-5, characterized in that, The first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device.

7. According to the method described in any one of claims 1-6, characterized in that, The authentication device includes a subscriber identity module (SIM).

8. The method according to any one of claims 1-6, characterized in that, The authentication device includes a universal serial bus (USB) key.

9. The method according to any one of claims 1-8, characterized in that, The communication tunnel includes a virtual private network (VPN) tunnel.

10. A method for establishing a communication tunnel, characterized in that: The method is applicable to the gateway side, and the method includes: Receiving an authentication request sent by the terminal side, where the authentication request includes first authentication information stored in an authentication device on the terminal side; Establishing a communication tunnel with the terminal side when the first authentication information passes the authentication.

11. The method according to claim 10, characterized in that, The method further includes: Receiving second authentication information sent by the mobile communication core network side; Determining that the first authentication information passes the authentication when the first authentication information matches the second authentication information; Sending an authentication response to the terminal side, where the authentication response is used to indicate that the first authentication information passes the authentication.

12. The method according to claim 11, characterized in that The determining that the first authentication information passes the authentication when the first authentication information matches the second authentication information includes: When the first authentication information matches the second authentication information, sending a challenge request to the mobile communication core network side, where the challenge request includes the first authentication information, and the challenge request is used for the mobile communication core network side to authenticate the first authentication information; Receiving a challenge response sent by the mobile communication core network side, and determining that the first authentication information passes the authentication, where the challenge response is used to indicate that the first authentication information passes the authentication of the mobile communication core network side.

13. The method according to claim 12, characterized in that, When the first authentication information matches the third authentication information on the mobile communication core network side, the first authentication information passes the authentication on the mobile communication core network side, and the third authentication information is obtained by updating the second authentication information on the mobile communication core network side.

14. The method according to claim 12 or 13, characterized in that, When the terminal side where the authentication device is located matches the reference terminal side bound to the authentication device, the first authentication information passes the authentication on the mobile communication core network side, and the terminal side where the authentication device is located and the reference terminal side are determined based on the first authentication information.

15. The method according to any one of claims 11-14, characterized in that, The second authentication information is in a first format, the first authentication information is in a second format, and the method further includes: converting the second authentication information in the first format into the second authentication information in the second format; The first authentication information matches the second authentication information, which includes: the first authentication information in the second format matches the second authentication information in the second format.

16. The method according to any one of claims 10 to 15, characterized in that: The first authentication information includes identification information, and the identification information is used to uniquely identify the authentication device.

17. The method according to any one of claims 10 to 16, characterized in that: The authentication device includes a subscriber identity module SIM.

18. The method according to any one of claims 10 - 16, characterized in that, The authentication device includes a serial universal bus USB key.

19. The method according to any one of claims 10 to 18, characterized in that: The communication tunnel includes a virtual private network VPN tunnel.

20. A device for establishing a communication tunnel, characterized in that: The device comprises: a transceiver module, configured to send an authentication request to the gateway side, wherein the authentication request includes first authentication information stored by the authentication device on the terminal side, and the authentication request is used by the gateway side to authenticate the first authentication information; An establishing module is used to establish a communication tunnel with the gateway side when the first authentication information passes the authentication of the gateway side.

21. A device for establishing a communication tunnel, characterized in that: The device comprises: a transceiver module, configured to receive an authentication request sent by a terminal side, wherein the authentication request includes first authentication information stored by an authentication device on the terminal side; An establishing module is used to establish a communication tunnel with the terminal side when the first authentication information passes the authentication.

22. A device for establishing a communication tunnel, characterized in that: The device includes a memory and a processor; the memory stores at least one computer instruction, and the at least one computer instruction is loaded and executed by the processor, so that the device for establishing a communication tunnel implements the method for establishing a communication tunnel described in any one of claims 1-19.

23. A communication system, characterized in that, The communication system includes a terminal side and a gateway side, the terminal side is used to execute the method for establishing a communication tunnel described in any one of claims 1-9, and the gateway side is used to execute the method for establishing a communication tunnel described in any one of claims 10-19.

24. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer instruction, and the at least one computer instruction is loaded and executed by a processor to enable a computer to implement the method for establishing a communication tunnel according to any one of claims 1 to 19.

25. A computer program product, characterized in that, The computer program product includes computer instructions, and the computer instructions are executed by a processor to enable a computer to implement the method for establishing a communication tunnel according to any one of claims 1 to 19.