Communication method and communication system

By using multiple VPN encryption certificates to establish dual VPN tunnels in mobile communication base stations, the problem of low data security in a single VPN channel is solved, secure communication between the terminal and the core network is realized, and the security and efficiency of data transmission are improved.

CN120390218APending Publication Date: 2025-07-29CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510727270.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In the prior art, when a mobile communication base station uses public network transmission resources to return to the core network, the data security of a single VPN channel is low and cannot meet the security policy requirements of a dedicated bearer network.

Method used

Multiple VPN encryption certificates are used to establish multiple dedicated network tunnels, and dual VPN channels are established with the network server and security gateway through the wireless backhaul module and the overlay side base station module respectively to realize secure communication between the terminal and the core network.

Benefits of technology

It improves data security during wireless backhaul, meets the security policy requirements of the dedicated bearer network, and enhances the flexibility and scalability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120390218A_ABST
    Figure CN120390218A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method and a communication system. The method comprises the steps that a plurality of virtual private network (VPN) encryption certificates are acquired from a public network, and the number of the VPN encryption certificates is the same as the number of base station modules contained in the wireless backhaul base station; a plurality of VPN encryption certificates are adopted to establish a plurality of private network tunnels, network elements of both communication parties supported by each private network tunnel are different, and the network elements of both communication parties supported by the private network tunnels comprise: a network server supporting a tunnel protocol; and establishing communication between the terminal and the core network through the plurality of private network tunnels. According to the method and the device, the technical problem that the data security is low when a single VPN channel is adopted for wireless backhaul is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technologies, and in particular, to a communication method and a communication system. Background Art

[0002] Due to the security management requirements of mobile communication, currently, the backhaul of mobile communication network base stations to the core network generally relies on a dedicated bearer network, such as an IP Radio Access Network (IPRAN), a Smart Transport Network (STN), etc. In principle, a dedicated bearer network cannot be directly exposed to the public network and can only be connected to the public network through strict isolation policies. When the current mobile communication base station uses public network transmission resources for backhaul, a security gateway needs to be added to access the core network through the dedicated bearer network. However, when the current mobile communication base station uses public network transmission resources for backhaul to the core network, only through the Virtual Private Network (VPN) channel between the mobile communication base station and the security gateway, there is a problem of low data security in using this single VPN channel for wireless backhaul, and it cannot meet the security policy requirements for the security gateway to access the dedicated bearer network.

[0003] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of this application provide a communication method and a communication system to at least solve the technical problem of low data security in wireless backhaul using a single VPN channel.

[0005] According to one aspect of the embodiments of this application, a communication method is provided, including: obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network, where the number of VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station; establishing multiple dedicated network tunnels using the multiple VPN encryption certificates, where the network elements of the two communication parties supported by each dedicated network tunnel are different, and the network elements of the two communication parties supported by the dedicated network tunnel include: a network server that supports the tunnel protocol; establishing communication between the terminal and the core network through the multiple dedicated network tunnels.

[0006] Optionally, the number of VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station, where the base station module includes: a wireless backhaul module and a coverage-side base station module that communicate directly, where the wireless backhaul module is a functional component for implementing wireless transmission, and the coverage-side base station module is a functional component for wirelessly covering terminals; the VPN encryption certificates include: a first VPN encryption certificate for establishing a dedicated network tunnel associated with the wireless backhaul module, and a second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module.

[0007] Optionally, multiple dedicated network tunnels are established using multiple VPN encryption certificates, including: establishing a first dedicated network tunnel between the wireless backhaul module and the network server using the first VPN encryption certificate; and establishing a second dedicated network tunnel between the coverage-side base station module and the security gateway using the second VPN encryption certificate.

[0008] Optionally, communication between the terminal and the core network is established through multiple dedicated network tunnels, including: receiving first-type data sent by the terminal, and transmitting the first-type data to the network server via the first dedicated network tunnel; the network server transmits the first-type data to the security gateway through the dedicated bearer network; the security gateway transmits the first-type data to the core network through the dedicated bearer network; or, transmitting the first-type data to the security gateway via the second dedicated network tunnel, where the security gateway transmits the first-type data to the core network through the dedicated bearer network.

[0009] Optionally, establishing communication between the terminal and the core network through multiple dedicated network tunnels further includes: receiving second-type data sent by the core network, and transmitting the second-type data to the network server via the security gateway; the network server transmits the second-type data to the wireless backhaul base station through the first dedicated network tunnel; transmitting the second-type data to the terminal through the wireless backhaul base station; or, the security gateway transmits the second-type data to the wireless backhaul base station through the second dedicated network tunnel; transmitting the second-type data to the terminal through the wireless backhaul base station.

[0010] Optionally, before establishing the dedicated network tunnel associated with the coverage-side base station module, the method further includes: transmitting the second VPN encryption certificate to the coverage-side base station module through the wireless backhaul module.

[0011] Optionally, obtaining multiple virtual private network (VPN) encryption certificates from the public network includes: accessing the public network through the wireless backhaul module included in the base station module to obtain the VPN encryption certificate.

[0012] Optionally, before obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network, the method further includes: detecting a triggering condition, where the triggering condition includes: the operating state of the communication system to which the wireless backhaul base station belongs, the current time, and the latest authorization time of the VPN encryption certificate; triggering the obtaining of multiple VPN encryption certificates from the public network when the operating state of the communication system is a first startup, or when the current time is later than the latest authorization time of the VPN encryption certificate.

[0013] According to another aspect of the embodiments of the present application, there is also provided a communication system, which is used to implement communication between a terminal associated with the communication system and a core network. The communication system includes: a wireless backhaul base station; the wireless backhaul base station is used to obtain multiple VPN encryption certificates from the public network, where the number of VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station; multiple dedicated network tunnels are established using the multiple VPN encryption certificates, where the network elements of the two communication parties supported by each dedicated network tunnel are different, and the network elements of the two communication parties supported by the dedicated network tunnel include: a network server that supports the tunnel protocol.

[0014] Optionally, the wireless backhaul base station includes: a wireless backhaul module and a coverage-side base station module that communicate directly. The wireless backhaul module is used to obtain multiple VPN encryption certificates from the public network, where the VPN encryption certificates include: a first VPN encryption certificate for establishing a dedicated network tunnel associated with the wireless backhaul module, and a second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module; establishing a dedicated network tunnel according to the first VPN encryption certificate; and transmitting the second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module to the coverage-side base station module; the coverage-side base station module is used to receive the second VPN encryption certificate and establish a dedicated network tunnel using the second VPN encryption certificate.

[0015] Optionally, the wireless backhaul module is used to establish a first dedicated network tunnel according to the first VPN encryption certificate and communicate with a network server that supports the tunnel protocol through the first dedicated network tunnel.

[0016] Optionally, the coverage-side base station module is used to establish a second dedicated network tunnel according to the second VPN encryption certificate and communicate with a security gateway through the second dedicated network tunnel.

[0017] Optionally, the communication system further includes: a security gateway, a user plane function entity, and a network server that supports the tunnel protocol; the security gateway, the user plane function entity, and the network server are all deployed in a dedicated bearer network and communicate through the dedicated bearer network.

[0018] In the embodiment of the present application, multiple Virtual Private Network (VPN) encryption certificates are obtained from the public network, where the number of VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station; multiple dedicated network tunnels are established using the multiple VPN encryption certificates, where the network elements of the two communication parties supported by each dedicated network tunnel are different. The network elements of the two communication parties supported by the dedicated network tunnel include: a network server that supports the tunnel protocol; a method of establishing communication between the terminal and the core network through multiple dedicated network tunnels. By establishing a dual VPN channel, the purpose of enabling data to interact with the core network under the protection of the dual VPN is achieved, thereby realizing the technical effect of improving the data security during wireless backhaul, and further solving the technical problem of low data security in wireless backhaul using a single VPN channel. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The schematic embodiments and descriptions thereof of the present application are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0020] Figure 1 is a schematic diagram of a communication system 100 according to an embodiment of the present application;

[0021] Figure 2 is a flowchart of the steps of a communication method according to an embodiment of the present application;

[0022] Figure 3 is a schematic diagram of communication between a terminal and a core network according to an embodiment of the present application;

[0023] Figure 4 is an architecture diagram of a communication system 400 according to an embodiment of the present application;

[0024] Figure 5 is a flow schematic diagram of implementing communication between a terminal 4002 and a core network 4004 based on the communication system 400 according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0026] It should be noted that the terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0027] To better understand the embodiments of this application, the technical terms involved in the embodiments of this application are explained as follows:

[0028] IP Radio Access Network (IPRAN): A network architecture specifically designed for data transmission in mobile communication networks, based on the Internet Protocol (IP protocol) or the Multiprotocol Label Switching (MPLS protocol).

[0029] Smart Transport Network (STN): An enhanced packet networking technology that combines IPRAN and Packet Transport Network (PTN) technologies. This technology can be superimposed on the mobile service bearer network to achieve intelligent packetized transmission.

[0030] Virtual Private Network (VPN): A network technology that allows users to establish a secure connection through a public network (such as the Internet). Its main function is to establish a private network on the public network for encrypted communication. It has extensive applications in enterprise networks.

[0031] User Plane Function (UPF): Its main function is to open a data path for users and connect users to the data network.

[0032] Customer Premise Equipment (CPE): A new type of wireless terminal access device that can receive wireless signals from wireless routers / Wireless Access Points (APs) / wireless base stations, etc., and also supports inserting a Subscriber Identity Module Card (SIM) to access the mobile network. It can directly act as a wired network interface or convert it into a Wireless Fidelity (Wi-Fi) signal to provide device connections in scenarios such as homes or offices.

[0033] Layer 2 Tunneling Protocol Network Server (LNS): Used to receive connection requests from remote access ends and establish and maintain L2TP tunnels; its main function is to open a data path for users, connecting users and data networks. Through LNS authentication, users can log in to the private network and access private network resources.

[0034] Security gateway: A device or software solution that provides advanced security protection at the network boundary. Security gateways usually integrate multiple security mechanisms and technologies, including but not limited to: firewalls, Virtual Private Networks (VPNs).

[0035] Macro base station: A base station device that provides wide - range wireless coverage.

[0036] In related technologies, wireless backhaul is performed based on a single VPN tunnel between a mobile communication base station and a security gateway. The data security of the single VPN tunnel is low and cannot meet the security policy requirements of the dedicated bearer network for the security gateway. Therefore, there is a problem of low data security. To solve this problem, relevant solutions are provided in the embodiments of this application, which are described in detail below.

[0037] According to the embodiments of this application, a method embodiment of a communication method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer - executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0038] The technical solution of the embodiment of the present application can be applied to various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD), Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system or 5G system, etc.

[0039] Figure 1 is a schematic diagram of a communication system 100. Exemplarily, the communication system 100 to which the embodiment of the present application is applied is as Figure 1 shown. The communication system 100 may include a network device 110, and the network device 110 may be a device that communicates with a terminal device 120 (or referred to as a communication terminal, terminal). The network device 110 may provide communication coverage for a specific geographical area and may communicate with terminal devices located within the coverage area. Optionally, the network device 110 may be a Base Transceiver Station (BTS) in a GSM system or a CDMA system, may also be a NodeB (NB) in a WCDMA system, may also be an Evolutional Node B (eNB or eNodeB) in an LTE system, or a radio controller in a Cloud Radio Access Network (CRAN), or the network device may be a mobile switching center, a relay station, an access point, a vehicle-mounted device, a wearable device, a hub, a switch, a bridge, a router, a network-side device in a 5G network, or a network device in a future evolved Public Land Mobile Network (PLMN), etc.

[0040] The communication system 100 also includes at least one terminal device 120 located within the coverage area of the network device 110. As used herein, "terminal device" includes, but is not limited to, a device that is connected via a wired line, such as a Public Switched Telephone Network (PSTN), a Digital Subscriber Line (DSL), a digital cable, a direct cable connection; and / or another data connection / network; and / or via a wireless interface, such as a cellular network, a Wireless Local Area Network (WLAN), a digital television network such as a DVB-H network, a satellite network, an AM-FM broadcast transmitter; and / or another terminal device configured to receive / send communication signals; and / or an Internet of Things (IoT) device. A terminal device configured to communicate via a wireless interface may be referred to as a "wireless communication terminal," "wireless terminal," or "mobile terminal." Examples of mobile terminals include, but are not limited to, satellite or cellular telephones; Personal Communications System (PCS) terminals that may combine cellular radiotelephones with data processing, fax, and data communications capabilities; PDAs that may include radiotelephones, pagers, Internet / Intranet access, web browsers, organizers, calendars, and / or Global Positioning System (GPS) receivers; and conventional laptop and / or palmtop receivers or other electronic devices that include radiotelephone transceivers. A terminal device may be referred to as an access terminal, user equipment (UE), a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal can be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a 5G network, or a terminal device in a future evolved PLMN, etc.

[0041] Optionally, device to device (D2D) communication may be performed between the terminal devices 120 .

[0042] Optionally, the 5G system or 5G network may also be referred to as a New Radio (NR) system or NR network.

[0043] The embodiments of the present application provide a communication method that can be applied in the above operating environment. Figure 2 It is a flowchart of the steps of the communication method provided by the embodiments of the present application, as Figure 2 shown, the method includes the following steps:

[0044] Step S202, obtain multiple Virtual Private Network (VPN) encryption certificates from the public network, where the number of VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station.

[0045] When the communication method provided by the embodiments of the present application performs data transmission, multiple security policies are combined to improve the security of data during the transmission process. One of the security policies is to transmit data using a VPN channel. The VPN channel is established relying on a VPN encryption certificate. In step S202, the VPN encryption certificate is obtained from the public network. The VPN encryption certificate is a key component for encryption and authentication in a Virtual Private Network (VPN) environment. The VPN encryption certificate contains a public key and a private key pair. Data encrypted with the public key can only be decrypted with the matching private key. This means that even if the data is intercepted by a third party during the transmission process, due to the lack of the private key required for decryption, the data cannot be easily interpreted. Therefore, using a VPN channel established with a VPN encryption certificate to transmit data is an effective security policy that can protect the confidentiality and integrity of the communication. The wireless base station has the characteristic of communicating with the public network. Therefore, the action of obtaining the VPN encryption certificate from the public network can be performed by the wireless base station. To improve the data security during the transmission process, the embodiments of the present application avoid using a single VPN channel, but determine the number of VPN channels to be established according to the data of the base station modules included in the wireless base station, so that each base station module has a uniquely associated VPN channel. Different VPN channels are established relying on different VPN encryption certificates. Therefore, the number of VPN encryption certificates obtained in step S202 should be the same as the number of base station modules included in the wireless base station.

[0046] Optionally, the number of VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station, where the base station modules include: a wireless backhaul module for direct communication and a coverage-side base station module. The wireless backhaul module is a functional component for implementing wireless transmission, and the coverage-side base station module is a functional component for wirelessly covering terminals; the VPN encryption certificates include: a first VPN encryption certificate for establishing a dedicated network tunnel associated with the wireless backhaul module and a second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module.

[0047] In this embodiment, the base station modules included in the wireless backhaul base station are: a wireless backhaul module and a coverage-side base station module. Among them, the wireless backhaul module and the coverage-side base station module are interconnected and can communicate directly; the wireless backhaul module is a component capable of implementing wireless transmission functions, such as a third-generation mobile communication technology (3G) integrated base station, a fourth-generation mobile communication technology (4G) integrated base station, a fifth-generation mobile communication technology (5G) integrated base station, etc. The wireless backhaul module is a functional component for wirelessly covering terminals, such as 3G CPE, 4G CPE, 5G CPE and other mobile communication terminals. Since the number of obtained VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station, then, when the base station modules included in the wireless backhaul base station are a wireless backhaul module and a coverage-side base station module, the number of obtained encryption certificates is 2, namely, the VPN encryption certificate (i.e., the first VPN encryption certificate) for establishing a VPN tunnel (i.e., a private network tunnel) associated with the wireless backhaul module, and the VPN encryption certificate (i.e., the second VPN encryption certificate) for establishing a VPN tunnel (i.e., a private network tunnel) associated with the coverage-side base station module.

[0048] Step S204, establish multiple private network tunnels by using multiple VPN encryption certificates, where the network elements of the two communication parties supported by each private network tunnel are different, and the network elements of the two communication parties supported by the private network tunnel include: a network server that supports the tunnel protocol.

[0049] In step S204, establish a VPN channel (i.e., a private network tunnel) by using each VPN encryption certificate obtained in step S202, and a total of N VPN channels are established, where N represents the number of base station modules included in the wireless base station. In this embodiment, each base station module has a uniquely associated VPN channel, that is, for each VPN channel, the network element of one of the communication parties it supports is the base station module; in order to avoid the problem that the VPN channel between only the mobile communication base station and the security gateway cannot meet the security policy for the security gateway to access the private bearer network, in this embodiment, in addition to the security gateway, there is also a network server (VPN LNS) that supports the tunnel protocol communicating with the base station module, that is, the other communication party supported by the VPN channel includes: the security gateway, a network server (VPN LNS) that supports the tunnel protocol, where each VPN channel is associated with two communication parties; at the same time, the two communication parties (i.e., the two communication sides) supported by each VPN channel are different, and each network element is uniquely associated with a VPN channel.

[0050] Optionally, multiple dedicated network tunnels are established using multiple VPN encryption certificates, including: establishing a first dedicated network tunnel between the wireless backhaul module and the network server using the first VPN encryption certificate; and establishing a second dedicated network tunnel between the coverage-side base station module and the security gateway using the second VPN encryption certificate.

[0051] In this embodiment, when the base station module included in the wireless backhaul base station is the wireless backhaul module and the coverage-side base station module, two VPN channels (i.e., dedicated network tunnels) are established. One is the VPN channel (i.e., the first dedicated network tunnel) for supporting communication between the wireless backhaul module and the network server (VPN LNS), and this VPN channel is established by the wireless backhaul module based on the first VPN encryption certificate. The other is the VPN channel (i.e., the second dedicated network tunnel) for supporting communication between the coverage-side base station module and the security gateway, and this VPN channel (i.e., the second dedicated network tunnel) is established by the coverage-side base station module based on the second VPN encryption certificate.

[0052] Step S206, establish communication between the terminal and the core network through multiple dedicated network tunnels.

[0053] After multiple VPN channels (i.e., dedicated network tunnels) are established in step S204, data can be transmitted between the terminal and the core network deployed in the dedicated bearer network based on the multiple dedicated network tunnels to achieve secure communication between the terminal and the core network.

[0054] According to some optional embodiments of the present application, establishing communication between the terminal and the core network through multiple dedicated network tunnels includes: receiving the first type of data sent by the terminal, transmitting the first type of data to the network server via the first dedicated network tunnel; the network server transmits the first type of data to the security gateway through the dedicated bearer network; the security gateway transmits the first type of data to the core network through the dedicated bearer network; or transmitting the first type of data to the security gateway via the second dedicated network tunnel, where the security gateway transmits the first type of data to the core network through the dedicated bearer network.

[0055] Figure 3 is a schematic diagram of communication between the terminal and the core network, as Figure 3As shown in the figure, the communication system to which the wireless backhaul base station belongs further includes the following network elements: a network server (VPN1 LNS) that supports the tunneling protocol, a user plane function entity (UPF), and a security gateway; these network elements are allowed to communicate through a dedicated bearer network, and the core network is also usually deployed in the dedicated bearer network. Therefore, in the embodiments of the present application, two security policies, namely a VPN channel (i.e., a dedicated network tunnel) and a dedicated bearer network, are combined to protect the security of the data transmission process. Based on the communication system to which the wireless backhaul base station belongs, two-way data transmission between the terminal and the core network can be realized. Specifically, in this embodiment, forwarding the data sent by the terminal (i.e., the first type of data) to the core network can be implemented by the wireless backhaul module in the wireless backhaul base station or by the coverage base station module in the wireless backhaul base station. When the data sent by the terminal (i.e., the first type of data) is forwarded to the core network through the wireless backhaul module, the data forwarding process is as follows: the wireless backhaul module receives the data sent by the terminal wirelessly, and the wireless backhaul module transmits the data sent by the terminal to the network server (VPN1 LNS) through the associated VPN channel (i.e., the first dedicated network tunnel); the network server (VPN1 LNS) communicates with the security gateway based on the dedicated bearer network, and transmits the data sent by the terminal to the security gateway through the link in the dedicated bearer network that supports the communication between the network server (VPN1 LNS) and the security gateway; the security gateway communicates with the core network based on the dedicated bearer network, and transmits the data sent by the terminal to the core network through the link in the dedicated bearer network that supports the communication between the security gateway and the core network; based on the above, the communication between the terminal and the core network is realized. When the data sent by the terminal (i.e., the first type of data) is forwarded to the core network through the coverage base station module, the data forwarding process is as follows: the coverage base station module receives the data sent by the terminal, and the coverage base station module transmits the data sent by the terminal to the security gateway through the associated VPN channel (i.e., the second dedicated network tunnel); the security gateway communicates with the core network based on the dedicated bearer network, and transmits the data sent by the terminal to the core network through the link in the dedicated bearer network that supports the communication between the security gateway and the core network; based on the above, the communication between the terminal and the core network is realized. During the above data transmission process, the VPN encrypts the data for transmission, and further checks the received data at the security gateway to ensure that only legitimate data and data that passes the verification can be transmitted to the core network.

[0056] According to some other optional embodiments of the present application, establishing communication between the terminal and the core network through multiple dedicated network tunnels further includes: receiving the second type of data sent by the core network, and transmitting the second type of data to the network server via the security gateway; the network server transmits the second type of data to the wireless backhaul base station through the first dedicated network tunnel; transmitting the second type of data to the terminal through the wireless backhaul base station; or, the security gateway transmits the second type of data to the wireless backhaul base station through the second dedicated network tunnel; transmitting the second type of data to the terminal through the wireless backhaul base station.

[0057] Figure 3 The communication system shown can also transmit the data sent by the core network (i.e., the second type of data) to the terminal. The specific process is as follows: The core network and the security gateway are deployed in a dedicated bearer network. The core network communicates with the security gateway based on the dedicated bearer network, and transmits the data sent by the core network to the security gateway through the link in the dedicated bearer network that supports the communication between the security gateway and the core network; the security gateway can transmit the data sent by the core network to the coverage-side base station through the VPN tunnel associated with it (i.e., the second dedicated network tunnel), and the coverage-side base station transmits the data sent by the core network to the terminal. Since the security gateway and the network server (VPN1 LNS) are both deployed in the dedicated bearer network, as Figure 3 shown, the security gateway can also transmit the data sent by the core network to the network server (VPN1 LNS) based on the link in the dedicated bearer network that supports the communication between the security gateway and the network server (VPN1 LNS). The network server (VPN1 LNS) transmits the data sent by the core network to the wireless backhaul module through the VPN tunnel associated with it (i.e., the first dedicated network tunnel), and the wireless backhaul module transmits the data sent by the core network to the terminal. In addition, the core network can also directly send the data to the network server (VPN1 LNS) through the link in the dedicated bearer network that supports the communication between the core network and the network server (VPN1 LNS); the network server (VPN1 LNS) transmits the data sent by the core network to the wireless backhaul module through the VPN tunnel associated with it (i.e., the first dedicated network tunnel), and the wireless backhaul module transmits the data sent by the core network to the terminal. That is, the core network can either directly send the data to the network server (VPN1 LNS) or forward the data to the network server (VPN1 LNS) through the security gateway.

[0058] Still as Figure 3 shown, when a macro base station is deployed in the dedicated bearer network, in addition to realizing the communication between the terminal and the core network through the method in the above embodiment, the communication between the terminal and the core network can also be realized based on the assistance of the macro base station and based on the following method. For example, the coverage base station module can first access the macro base station of the mobile communication network through the wireless backhaul module. Then, both the wireless backhaul module and the coverage base station module can transmit the data sent by the terminal to the macro base station after receiving it; the macro base station, UPF, VPN1 LNS, security gateway, and core network are all deployed in the dedicated bearer network and can communicate with each other. Therefore, the macro base station can directly transmit the data sent by the terminal to the core network based on the dedicated bearer network, or transmit the data sent by the terminal to the core network through the user plane function entity (UPF), or also transmit the data sent by the terminal to the core network through other transmission methods shown in Figure 3 it.

[0059] According to an alternative embodiment of the present application, obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network includes: accessing the public network through a wireless backhaul module included in a base station module to obtain VPN encryption certificates.

[0060] In the method provided by the embodiment of the present application, the wireless backhaul base station can communicate with the public network and obtain VPN encryption certificates therefrom because the wireless backhaul base station includes a wireless backhaul module. That is, in the method provided by the embodiment of the present application, it is actually the wireless backhaul module that accesses the public network and automatically obtains the encryption certificates for the VPN1 secure channel (i.e., the first private network tunnel) and the VPN2 secure channel (i.e., the second private network tunnel) from a VPN certificate server deployed in the public network.

[0061] Optionally, before establishing a private network tunnel associated with a coverage-side base station module, the method further includes: transmitting a second VPN encryption certificate to the coverage-side base station module through the wireless backhaul module.

[0062] As mentioned in the previous embodiment, the wireless backhaul base station obtains VPN encryption certificates through the wireless backhaul module it includes. After the wireless backhaul module obtains the VPN encryption certificates, it will forward the encryption certificates for establishing the VPN2 secure channel (i.e., the second private network tunnel) to the coverage-side base station module so that the coverage-side base station module can establish a VPN channel associated with itself.

[0063] According to some other alternative embodiments of the present application, before obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network, the method further includes: detecting a trigger condition, where the trigger condition includes: the operating state of the communication system to which the wireless backhaul base station belongs, the current time, and the latest authorization time of the VPN encryption certificate; when the operating state of the communication system is a first startup, or when the current time is later than the latest authorization time of the VPN encryption certificate, trigger obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network.

[0064] The action of step S202 of "obtaining VPN encryption certificates from the public network" starts to be executed under the condition of meeting a preset trigger condition. In this embodiment, the trigger condition is set to system startup and VPN encryption certificate expiration. When any of the above trigger conditions is met, trigger the wireless backhaul base station to obtain VPN encryption certificates from the public network.

[0065] Through the above steps, it is possible to establish multiple private network tunnels, combine the use of private network tunnels and private bearer networks to transmit data, achieve secure communication between the terminal and the core network, and improve the security and efficiency of data transmission. At the same time, through the collaborative work of the wireless backhaul module and the coverage-side base station module, the flexibility and scalability of the network are enhanced.

[0066] Figure 4It is an architecture diagram of a communication system 400 provided according to an embodiment of the present application. Figure 4 The illustrated communication system 400 is used to implement communication between a terminal 4002 and a core network 4004 associated with the communication system 400. As Figure 4 shown, the communication system includes: a wireless backhaul base station 40; the wireless backhaul base station 40 is used to obtain multiple virtual private network (VPN) encryption certificates from the public network. Among them, the number of VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station 40; multiple dedicated network tunnels are established using the multiple VPN encryption certificates. Among them, the network elements of the two communication parties supported by each dedicated network tunnel are different. The network elements of the two communication parties supported by the dedicated network tunnel include: a network server 42 that supports the tunnel protocol.

[0067] According to some optional embodiments of the present application, the wireless backhaul base station 40 includes: a wireless backhaul module 402 and a coverage-side base station module 404 that communicate directly. Among them, the wireless backhaul module 402 is used to obtain multiple virtual private network (VPN) encryption certificates from the public network. Among them, the VPN encryption certificates include: a first VPN encryption certificate for establishing a dedicated network tunnel associated with the wireless backhaul module 402, and a second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module 404; a dedicated network tunnel is established according to the first VPN encryption certificate; and, the second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module 404 is transmitted to the coverage-side base station module 404; the coverage-side base station module 404 is used to receive the second VPN encryption certificate and establish a dedicated network tunnel using the second VPN encryption certificate.

[0068] Figure 5 It is a schematic diagram of implementing communication between the terminal 4002 and the core network 4004 based on the communication system 400. As Figure 5 shown, to implement communication between the terminal 4002 and the core network 4004, the wireless backhaul base station 40 obtains VPN encryption certificates from a VPN certificate server 4006 deployed in the public network through the included wireless backhaul module 402. The encryption certificates obtained by the wireless backhaul module 402 are respectively the first VPN encryption certificate for establishing a dedicated network tunnel associated with the wireless backhaul module 402 and the second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module 404. Among them, the second VPN encryption certificate is forwarded by the wireless backhaul module 402 to the coverage-side base station module 404; the wireless backhaul module 402 uses the first VPN encryption certificate to establish a VPN channel associated with itself, and the coverage-side base station module 404 uses the second VPN encryption certificate to establish a VPN channel associated with itself.

[0069] Optionally, the wireless backhaul module 402 is configured to establish a first dedicated network tunnel according to the first VPN encryption certificate and communicate with the network server 42 supporting the tunnel protocol through the first dedicated network tunnel.

[0070] As Figure 5 shown, the (first) dedicated network tunnel established by the wireless backhaul module 402 using the first VPN encryption certificate is used to support the communication between the wireless backhaul module 402 and the network server 42, where the network server 42 supports the tunnel protocol, for example, the Layer 2 Tunneling Protocol (L2TP).

[0071] Optionally, the coverage-side base station module 404 is configured to establish a second dedicated network tunnel according to the second VPN encryption certificate and communicate with the security gateway 44 through the second dedicated network tunnel.

[0072] Still as Figure 5 shown, the (second) dedicated network tunnel established by the coverage-side base station module 404 using the second VPN encryption certificate is used to support the communication between the coverage-side base station module 404 and the security gateway 44.

[0073] According to some other optional embodiments of the present application, the communication system 400 further includes: a security gateway 44, a user plane function entity 46, and a network server 42 supporting the tunnel protocol; the security gateway 44, the user plane function entity 46, and the network server 42 are all deployed in a dedicated bearer network and communicate through the dedicated bearer network.

[0074] Multiple network elements deployed in the dedicated bearer network in the communication system can communicate through the dedicated bearer network. For example, the network server 42 and the security gateway 44 can perform data transmission based on the link dedicated to supporting the communication between the network server 42 and the security gateway 44 in the dedicated bearer network. And for a network element like the network server 42 that is both deployed in the dedicated bearer network and has a VPN channel (i.e., a dedicated network tunnel) associated with itself, it can communicate with different network elements in different ways. In addition, still as Figure 5As shown, when a macro base station 48 is deployed in the dedicated bearer network, in addition to implementing communication between the terminal 40002 and the core network 40004 in the manner of the above embodiments, communication between the terminal 4002 and the core network 4004 can also be implemented based on the assistance of the macro base station 48. For example, the coverage base station module 404 can first access the macro base station 48 of the mobile communication network through the wireless backhaul module 402. Then, both the wireless backhaul module 402 and the coverage base station module 404 can transmit the data sent by the terminal 4002 to the macro base station 48 after receiving it; the macro base station 48, the user plane function entity 46, the network server 42, the security gateway 44, and the core network 4004 are all deployed in the dedicated bearer network and can communicate with each other. Therefore, the macro base station 48 can directly transmit the data sent by the terminal 4002 to the core network 4004 based on the dedicated bearer network, or can transmit the data sent by the terminal 4002 to the core network 4004 through the user plane function entity 46, or can also transmit the data sent by the terminal 4002 to the core network 40004 through Figure 5 other transmission methods shown in

[0075] It should be noted that Figure 4 For the preferred implementation manners of the embodiments shown, reference can be made to the relevant descriptions of the embodiments shown in Figure 2 and details are not described herein again.

[0076] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.

[0077] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0078] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces, and the indirect couplings or communication connections of the units or modules can be in an electrical or other form.

[0079] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0080] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0081] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the related technology, or all or part of the technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0082] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A communication method, characterized in that, Including: Obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network, where the number of the VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station; Establishing multiple dedicated network tunnels using the multiple VPN encryption certificates, where the network elements of the two communication parties supported by each dedicated network tunnel are different, and the network elements of the two communication parties supported by the dedicated network tunnel include: a network server that supports the tunnel protocol; Establishing communication between the terminal and the core network through the multiple dedicated network tunnels.

2. The method according to claim 1, wherein The number of the VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station, where The base station module includes: a wireless backhaul module and a coverage-side base station module that communicate directly, where the wireless backhaul module is a functional component for implementing wireless transmission, and the coverage-side base station module is a functional component for wirelessly covering the terminal; The VPN encryption certificate includes: a first VPN encryption certificate for establishing a dedicated network tunnel associated with the wireless backhaul module, and a second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module.

3. The method according to claim 2, wherein ; Establishing multiple dedicated network tunnels using the multiple VPN encryption certificates includes: establishing a first dedicated network tunnel between the wireless backhaul module and the network server using the first VPN encryption certificate; And establishing a second dedicated network tunnel between the coverage-side base station module and the security gateway using the second VPN encryption certificate.

4. The method according to claim 3, characterized in that, Establishing communication between the terminal and the core network through the multiple dedicated network tunnels includes: Receiving first-class data sent by the terminal, and transmitting the first-class data to the network server via the first dedicated network tunnel; the network server transmits the first-class data to the security gateway through a dedicated bearer network; the security gateway transmits the first-class data to the core network through the dedicated bearer network; or, Transmitting the first-class data to the security gateway via the second dedicated network tunnel, where the security gateway transmits the first-class data to the core network through the dedicated bearer network.

5. The method according to claim 3, wherein Establishing communication between the terminal and the core network through the multiple dedicated network tunnels further includes: Receiving second-class data sent by the core network, and transmitting the second-class data to the network server via the security gateway; the network server transmits the second-class data to the wireless backhaul base station through the first dedicated network tunnel; transmitting the second-class data to the terminal through the wireless backhaul base station; or, The security gateway transmits the second-class data to the wireless backhaul base station through the second dedicated network tunnel; transmitting the second-class data to the terminal through the wireless backhaul base station.

6. The method according to claim 2, characterized in that, Before establishing a dedicated network tunnel associated with the coverage-side base station module, the method further includes: transmitting the second VPN encryption certificate to the coverage-side base station module through the wireless backhaul module.

7. The method according to claim 1, wherein Obtain multiple Virtual Private Network (VPN) encryption certificates from the public network, including: accessing the public network through the wireless backhaul module included in the base station module to obtain the VPN encryption certificates.

8. The method according to claim 1, wherein Before obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network, the method further includes: Detecting a trigger condition, where the trigger condition includes: the operating state of the communication system to which the wireless backhaul base station belongs, the current time, and the latest authorization time of the VPN encryption certificate; Trigger obtaining multiple Virtual Private Network (VPN) encryption certificates from the public network when the operating state of the communication system is in its initial startup, or when the current time is later than the latest authorization time of the VPN encryption certificate.

9. A communication system, characterized in that, The communication system is used to implement communication between the terminals associated with the communication system and the core network, where the communication system includes: a wireless backhaul base station; The wireless backhaul base station is used to obtain multiple Virtual Private Network (VPN) encryption certificates from the public network, where the number of the VPN encryption certificates is the same as the number of base station modules included in the wireless backhaul base station; establish multiple dedicated network tunnels using multiple of the VPN encryption certificates, where the network elements of the two communication parties supported by each dedicated network tunnel are different, and the network elements of the two communication parties supported by the dedicated network tunnel include: A network server that supports the tunnel protocol.

10. The communication system according to claim 9, wherein The wireless backhaul base station includes: a wireless backhaul module and a coverage-side base station module in direct communication, where The wireless backhaul module is used to obtain multiple Virtual Private Network (VPN) encryption certificates from the public network, where the VPN encryption certificates include: a first VPN encryption certificate for establishing a dedicated network tunnel associated with the wireless backhaul module, and a second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module; establish the dedicated network tunnel according to the first VPN encryption certificate; and transmit the second VPN encryption certificate for establishing a dedicated network tunnel associated with the coverage-side base station module to the coverage-side base station module; The coverage-side base station module is used to receive the second VPN encryption certificate and establish the dedicated network tunnel using the second VPN encryption certificate.

11. The communication system according to claim 10, wherein The wireless backhaul module is used to establish a first dedicated network tunnel according to the first VPN encryption certificate and communicate with a network server that supports the tunnel protocol through the first dedicated network tunnel.

12. The communication system according to claim 10, wherein, The coverage-side base station module is used to establish a second dedicated network tunnel according to the second VPN encryption certificate and communicate with a security gateway through the second dedicated network tunnel.

13. The communication system according to claim 9, characterized in that, The communication system further includes: a security gateway, a user plane function entity, and a network server that supports the tunnel protocol; the security gateway, the user plane function entity, and the network server are all deployed in a dedicated bearer network and communicate through the dedicated bearer network.