Terminal cross-domain switching processing method and system and storage medium
Synchronize the context information of the terminal device to the UDM of VPLMN through the central network management server, solving the problems of complexity and security risks of the terminal's cross-PLMN handover process, and achieving fast and secure seamless handover.
Patent Information
- Application Number
- CN202510576974.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-07-29
AI Technical Summary
In the prior art, the cross-PLMN switching process of terminals is complicated, resulting in increased delay and network security risks, which cannot meet the seamless switching needs in the industrial 5G private network environment.
The central network management server synchronizes the context information of the terminal device to the UDM of the VPLMN that the industrial equipment needs to be connected to, and directly reads the context information from the UDM for authentication, simplifies the signaling interaction process and ensures fast switching and network security.
It realizes seamless switching between terminal devices between different security domains, reduces switching time and network security risks, and is in line with the existing factory security policies.
Smart Images

Figure CN120390265A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a terminal cross-domain handover processing method, system and storage medium. Background Art
[0002] Terminal cross-domain handover refers to the process of maintaining service continuity when a user experience (UE) migrates between different network domains. In the industrial 5th Generation Mobile Communication Technology (5G) private network environment, different isolated network security domains exist, and independent 5G private networks, namely independent Public Land Mobile Networks (PLMNs), are deployed in each security domain. When industrial IoT devices operate between different security domains, they need to switch between different PLMNs.
[0003] Existing cross-PLMN handover mechanisms require complex signaling interactions between different network elements. Consequently, existing cross-domain handover methods increase device handover latency and complicate system deployment. Furthermore, because existing cross-PLMN handover mechanisms require dedicated signaling channels for signaling interaction, this requires opening specific ports for data transmission within the boundary firewalls of different security domains in accordance with the Third Generation Partnership Project (3GPP) protocol. This can alter existing network security policies, potentially introducing potential network security risks or preventing deployment due to violations of existing factory security policies. Summary of the Invention
[0004] The purpose of this application is to address the deficiencies in the above-mentioned prior art and provide a terminal cross-domain handover processing method, system and storage medium to simplify the terminal cross-domain handover process and eliminate signaling interaction.
[0005] To achieve the above purpose, the technical solution adopted in the embodiment of the present application is as follows:
[0006] In a first aspect, an embodiment of the present application provides a terminal inter-domain handover processing method, which is applied to a terminal inter-domain handover processing system, wherein the terminal inter-domain handover processing system includes at least: a central network management server and at least one visited public land mobile network (VPLMN); the method includes:
[0007] After the terminal device switches to the VPLMN and establishes a session, the local network management server in the VPLMN receives the address of the industrial device connected to the terminal device;
[0008] The local network management server obtains a first allowed access network list corresponding to the industrial device based on the address of the industrial device, and determines whether the current base station identifier exists in the first allowed access network list according to the first allowed access network list, the identifier of the current base station accessed by the terminal device, and the identifier of the VPLMN, wherein the first allowed access network list includes the address of the industrial device, the identifier of the target VPLMN allowed to be accessed by the industrial device, and the identifier of the tracking area allowed to be accessed by the industrial device;
[0009] If so, the central network management server sends the context information of the terminal device to each target VPLMN that the industrial device is allowed to access, so that the unified data management module UDM in each target VPLMN updates the mobility restriction list information of the terminal device according to the context information of the terminal device;
[0010] If not, the SMF in the VPLMN closes the session between the terminal device and the VPLMN, and the UDM in the VPLMN updates the first allowed access network list to the mobility restriction list information of the terminal device.
[0011] Optionally, the local network management server obtains a first list of allowed access networks corresponding to the industrial device based on the address of the industrial device, including:
[0012] The local network management server sends an acquisition request to the central network management server, wherein the acquisition request includes the address of the industrial device connected to the terminal device;
[0013] The central network management server determines a target address that matches the address of the industrial device from a preset network list database, and sends a list of all allowed access networks containing the target address as the first allowed access network list to the local network management server;
[0014] The local network management server receives the first allowed access network list.
[0015] Optionally, the determining, according to the first allowed access network list, the current base station identifier accessed by the terminal device, and the identifier of the VPLMN, whether the current base station identifier exists in the first allowed access network list includes:
[0016] If the tracking area identifiers in the first allowed access network list that the industrial device is allowed to access include an identifier that matches the current base station identifier, and the VPLMN identifier and the tracking area identifier that matches the current base station identifier are in the same allowed access network list, determining that the current base station identifier exists in the first allowed access network list;
[0017] If there is no identifier matching the current base station identifier in the tracking area identifier allowed to access the industrial equipment in the first allowed access network list, or the VPLMN identifier and the tracking area identifier matching the current base station identifier are not in the same allowed access network list, it is determined that the current base station identifier does not exist in the first allowed access network list.
[0018] Optionally, the central network management server sends the context information of the terminal device to each target VPLMN that the industrial device is allowed to access, including:
[0019] The central network management server receives the context information of the terminal device and the address of the industrial device connected to the terminal device sent by the local network management server;
[0020] The central network management server determines the address of the local network management server of each target VPLMN according to the address of the industrial device;
[0021] The central network management server sends the context information of the terminal device to the local network management server corresponding to the address of each local network management server of the target VPLMN.
[0022] Optionally, the central network management server determines the address of the local network management server of each target VPLMN according to the address of the industrial device, including:
[0023] The central network management server obtains a first allowed access network list corresponding to the industrial device according to the address of the industrial device, and determines the identifier of each target VPLMN from the first allowed access network list;
[0024] The central network management server determines the network private network information of each target VPLMN according to the identifier of each target VPLMN and a network private network information database pre-stored in the central network management server, wherein the network private network information includes: the identifier of the target VPLMN and the address of the local network management server of the target VPLMN;
[0025] The central network management server obtains the address of the local network management server of each target VPLMN from the network private network information of each target VPLMN.
[0026] Optionally, the unified data management module UDM in each of the target VPLMNs updates the mobility restriction list information of the terminal device according to the context information of the terminal device, including:
[0027] The local network management server of the target VPLMN sends a first update request to the network exposure module in the target VPLMN, and the first update request includes the context information of the terminal device;
[0028] The network exposure module in the target VPLMN sends a data modification request to the unified data management module in the target VPLMN, and the unified data management module in the target VPLMN updates the mobility restriction list in the context information of the terminal device to the unified data management module in the target VPLMN based on the data modification request.
[0029] Optionally, the session management module in the VPLMN closes the session between the terminal device and the VPLMN, and the unified data management module in the VPLMN updates the first allowed access network list to the mobility restriction list information of the terminal device, including:
[0030] The session management module in the VPLMN closes the session between the terminal device and the VPLMN, and the network exposure module in the VPLMN closes the network connection of the VPLMN and sends a second update request to the unified data management module of the VPLMN, and the second update request includes the first allowed access network list;
[0031] The unified data management module in the VPLMN updates the first allowed access network list to the mobility restriction list information of the terminal device.
[0032] Optionally, the terminal cross-domain handover processing system further includes: a home public land mobile network HPLMN;
[0033] Before the terminal device switches to the VPLMN and establishes a session, it further includes:
[0034] After the terminal device establishes a session with the HPLMN, the session management module of the HPLMN sends a notification that the session establishment between the terminal device and the HPLMN is completed to the network exposure module;
[0035] After receiving the session establishment completion notification, the network exposure module sends acquisition instructions for the context information of the terminal device to the session management module, the access and mobility management module, and the unified data management module respectively;
[0036] The network opening module receives the context information of the terminal device and reports the context information to the local network management server of the HPLMN.
[0037] In a second aspect, an embodiment of the present application further provides a terminal cross-domain handover processing system, where the terminal cross-domain handover processing system includes: a central network management server, a home public land mobile network (HPLMN), and at least one visited public land mobile network (VPLMN);
[0038] The central network management server is configured to execute the method steps performed by the central network management server in the first aspect above; the HPLMN is configured to execute the method steps performed by the HPLMN in the first aspect above; the VPLMN is configured to execute the method steps performed by the VPLMN in the first aspect above.
[0039] In a third aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and the computer program is read and executed to perform the steps of the terminal cross-domain handover processing method in the first aspect above.
[0040] The beneficial effects of the present application are:
[0041] A terminal cross - domain handover processing method, system and storage medium provided by the present application. After the terminal device first switches to the VPLMN in the industrial 5G environment and establishes a session with the VPLMN, the local network management server in the VPLMN receives the addresses of the industrial devices connected to the terminal device. Then, the local network management server obtains the first allowed access network list corresponding to the industrial devices based on the addresses of the industrial devices, and determines whether the current base station identifier exists in the first allowed access network list according to the first allowed access network list, the current base station identifier to which the terminal device is connected, and the identifier of the VPLMN; if so, the central network management server sends the context information of the terminal device to each target VPLMN that allows the industrial device to access, so that the UDM in each target VPLMN updates the mobility restriction list information of the terminal device according to the context information of the terminal device. This can enable all target VPLMNs that allow the industrial device to access to pre - store the mobility restriction list information of the terminal device in the UDMs of each target VPLMN. When the terminal device subsequently switches to each target VPLMN, each target VPLMN can directly implement rapid verification of the terminal device through the UDM, so that the terminal device and each target VPLMN can quickly access and establish a session, avoiding the need for complex signaling interactions in the prior art, thus greatly shortening the handover time, also avoiding the need to open additional ports on the firewall, reducing potential network security risks, and at the same time conforming to the existing security policies of the factory, ensuring seamless handover of the terminal device between different security domains. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] To more clearly illustrate the technical solutions of the embodiments of the present application, the accompanying drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0043] Figure 1 is a system architecture diagram of UE handover in the prior art;
[0044] Figure 2 is a flow schematic diagram of UE handover from HPLMN to VPLMN in the prior art;
[0045] Figure 3 is an architecture schematic diagram of a terminal cross - domain handover processing system provided by an embodiment of the present application;
[0046] Figure 4 is a flow schematic diagram of a terminal cross - domain handover processing method provided by an embodiment of the present application; Figure 5 is a flow schematic diagram of a second terminal cross - domain handover processing method provided by an embodiment of the present application;
[0047] Figure 6 This is a schematic flowchart of the third terminal cross - domain handover processing method provided by the embodiments of the present application;
[0048] Figure 7 This is a schematic flowchart of the fourth terminal cross - domain handover processing method provided by the embodiments of the present application. Detailed implementation manners
[0049] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. It should be understood that the accompanying drawings in the present application are only for the purposes of illustration and description, and are not used to limit the protection scope of the present application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in the present application illustrate the operations implemented according to some embodiments of the present application. It should be understood that the operations in the flowchart may not be implemented in sequence, and steps without a logical context relationship may be reversed in order or implemented simultaneously. In addition, those skilled in the art may add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of the present application.
[0050] In addition, the described embodiments are only some embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application usually described and illustrated in the accompanying drawings here may be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application claimed, but merely represents the selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.
[0051] It should be noted that the term "including" will be used in the embodiments of the present application to indicate the existence of the features stated thereafter, but does not exclude the addition of other features.
[0052] Figure 1 This is a system architecture diagram of UE handover in the prior art. Refer to Figure 1 , when UE hands over in the prior art, it involves the user terminal, AMF in VPLMN, AUSF and UDM in HPLMN, hSEPP in HPLMN, vSEPPP in HPLMN, and AMF in VPLMN. In Figure 1Based on the system architecture shown, the process of a UE in the prior art switching from an HPLMN (Home Public Land Mobile Network) to a VPLMN (Visited Public Land Mobile Network) is as follows. Figure 2 It is a schematic diagram of the process of a UE in the prior art switching from an HPLMN to a VPLMN:
[0053] Step 1: The UE sends an attachment request to the VPLMN through the visited radio base station.
[0054] Step 2: The Access and Mobility Management Function (AMF) in the VPLMN sends an authentication request to the HPLMN.
[0055] Step 3: The Authentication Server Function (AUSF) and the Unified Data Model (UDM) in the HPLMN authenticate the UE.
[0056] Step 4: The Home Security Edge Protection Proxy (hSEPP) ensures secure communication with the VPLMN.
[0057] Step 5: The Visited Security Edge Protection Proxy (vSEPP) receives the authentication response and ensures secure communication between networks.
[0058] Step 6: The Access and Mobility Management Function (AMF) and the Session Management Function (SMF) in the VPLMN establish a session for the UE.
[0059] Step 7: The Network Slice Selection Function selects an appropriate network slice.
[0060] Step 8: The Policy Control Function manages session application policies and charging rules.
[0061] Step 9: The User Plane Function routes data directly from the UE to the data network.
[0062] Step 10: The UE accesses the Internet through the data network.
[0063] As can be seen from the above-mentioned existing cross-PLMN handover process, during the cross-domain handover process, the UE needs to perform complex signaling interaction processes between different network elements. On the one hand, this increases the trial of device handover, and on the other hand, it makes the system deployment more complex. In addition, during the existing cross-PLMN handover process, signaling interaction needs to be carried out through a dedicated signaling channel, which requires opening data transmission of specific ports in the border firewalls of different security domains in the manner specified by the 3GPP protocol. This will lead to the change of the existing network security policy, thus causing potential network security risks or being unable to be deployed due to violating the existing security policy of the factory.
[0064] In view of the above technical problems existing in the prior art, the present application provides a method for handling terminal cross-domain handover. This method is applied to a terminal cross-domain handover processing system, which at least includes a central network management server, at least one visited public land mobile network (VPLMN), and the central network management server. The context information of the UE is synchronized by the central network management server to the UDM of the VPLMN that the industrial device to be connected to the UR needs to access during operation, so that when the UE enters the coverage area of the VPLMN, the local network management server in the VPLMN directly reads the context information of the UE from the UDM in the VPLMN, quickly completes the authentication of the UE, thereby establishing a session between the VPLMN and the UE and completing the handover process of the UE.
[0065] Figure 3 The following is a schematic diagram of the architecture of a terminal cross-domain handover processing system provided by an embodiment of the present application. As Figure 3 shown, in the industrial 5G private network environment, it includes a central network management server, an HPLMN, and at least one VPLMN, such as VPLMN1, VPLMN2, VPLMN3, etc. The HPLMN and each VPLMN are located in different network security domains. As Figure 1 shown, the HPLMN is located in security domain 2, VPLMN1 is located in security domain 1, VPLMN2 is located in security domain 2, and so on. Industrial devices can shuttle between the HPLMN and different VPLMNs to work. A local network management server is deployed in each security domain, and moreover, the local network management server deployed in each security domain can establish a data connection with the central network management server through the ports allowed by the network firewall between the securities.
[0066] Exemplarily, a local network management server h is deployed in the HPLMN, a local network management server 1 is deployed in VPLMN1, a local network management server 2 is deployed in VPLMN2, a local network management server 3 is deployed in VPLMN3, and so on.
[0067] Among them, the HPLMN or VPLMN may further include: a Network Exposure Function (NEF), a Unified Data Model (UDM), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), etc.
[0068] Optionally, the user can pre-enter the network list information allowed to be accessed by industrial devices in the central network management server, the first allowed access network list corresponding to the industrial devices, and store the first allowed access network list corresponding to each industrial device in the network list database in the central network management server. The first allowed access network list is [industrial device IP, [PLMN ID, [TAI]]], where the industrial device IP is the IP address of the industrial device, the PLMN ID is the PLMN identifier allowed to be accessed by the industrial device, and the TAI is the tracking area identifier allowed for the industrial device to access under the PLMN ID.
[0069] Optionally, the user can pre-enter the network private network information of the PLMN deployed in each security domain in the central network management server, and store the network private network information of the PLMN deployed in each security domain in the network private network information database in the central network management server. The network private network information of each PLMN is specifically [server IP, PLMN ID]. Among them, the server IP is the IP address of the local network management server of each PLMN, and the PLMN ID is the PLMN identifier.
[0070] Next, the specific implementation process of the terminal cross-domain handover processing provided in the embodiments of the present application will be specifically explained.
[0071] Figure 4 It is a schematic flowchart of a method for terminal cross-domain handover processing provided in an embodiment of the present application. This method is applied to the Figure 3 terminal cross-domain handover processing system shown above. The terminal cross-domain handover processing system at least includes: a central management server and at least one VPLMN. As Figure 4 shown, this method includes:
[0072] S101. The UE sends a session request to the AMF of the VPLMN.
[0073] S102. The AMF of the VPLMN returns a session establishment to the UE.
[0074] S103 : After the UE establishes a session with the VPLMN, the UE sends the address of the industrial device to which the UE is connected to the local network management server in the VPLMN.
[0075] The local network management server in the VPLMN receives the address of the industrial device connected to the terminal device.
[0076] As can be seen from the above, there are multiple VPLMNs in the industrial 5G private network environment. The VPLMN to which the terminal device switches in step S101 is selected from multiple VPLMNs for switching, and the terminal device is connected to the VPLMN for the first time in the industrial 5G private network environment. It is worth noting that if the UDM in the VPLMN does not store the context information of the terminal device, then the process when the terminal device switches to the VPLMN for the first time and establishes a session is the same as the switching process in the prior art shown in the above steps one to ten, and will not be repeated here. If the UDM in the VPLMN has stored the context information of the terminal device, then when the terminal device switches to the VPLMN for the first time, the context information of the terminal device is directly obtained from the UDM in the VPLMN, thereby realizing the identity authentication of the terminal device. When the verification is passed, the terminal device switches to the VPLMN and establishes a session.
[0077] Optionally, when the terminal device switches to the VPLMN and establishes a session, the terminal device sends the address of the industrial device connected to the terminal device to the local network management server of the VPLMN that establishes a session with the terminal device, and the VPLMN that establishes a session with the terminal device receives the address of the industrial device connected to the terminal device sent by the terminal device.
[0078] The address of the industrial device may refer to the Internet Protocol Address (IP) of the industrial device.
[0079] For example, for terminal device A, when it first accesses a VPLMN in an industrial 5G private network environment, it selects a VPLMN from the industrial 5G private network environment for access, such as VPLMN1, and then terminal device A switches to VPLMN1 and establishes a session with VPLMN1. If the address of industrial device 1 connected to terminal device A is IP1, after the terminal device A establishes a session with the VPLMN, the terminal device A sends the address IP1 of industrial device 1 to the local network management server 1 of VPLMN1, and the local network management server 1 of VPLMN1 receives the address IP1 of the industrial device.
[0080] S104: The local network server sends an acquisition request to the central network management server.
[0081] S105: The central network management server returns a first allowed access network list corresponding to the industrial device based on the acquisition request.
[0082] S106: The local network management server determines whether the current base station identifier exists in the first allowed access network list.
[0083] Optionally, if yes, execute S107; if no, execute S1010.
[0084] Optionally, the local network management server obtains a first list of allowed access networks corresponding to the industrial device based on the address of the industrial device.
[0085] The first allowed access network list includes: the address of the industrial device, the identifier of the target VPLMN that the industrial device is allowed to access, and the identifier of the tracking area that the industrial device is allowed to access.
[0086] Specifically, the local network management server determines whether the current base station identifier exists in the first allowed access network list according to the first allowed access network list, the identifier of the current base station accessed by the terminal device, and the identifier of the VPLMN.
[0087] The current base station accessed by the terminal device refers to the base station visited when the terminal device accesses the VPLMN in step S103. For example, when terminal device A accesses the VPLMN through visited base station B, the current base station identifier accessed by the terminal device is base station B. The identifier of the VPLMN in step S106 refers to the identifier of the VPLMN to which the terminal device switched in step S103.
[0088] Specifically, if the current base station identifier accessed by terminal device A exists in the first allowed access network list corresponding to the industrial equipment, execute the following step S107; if the current base station identifier accessed by terminal device A does not exist in the first allowed access network list corresponding to the industrial equipment, execute the following step S1010.
[0089] Exemplarily, when the local network management server 1 of VPLMN1 receives the address IP1 of the industrial device 1 connected to the terminal device A, the local network management server 1 can use a preset method to obtain the first allowed access network list corresponding to the industrial device 1 based on the address IP1. Furthermore, the local network management server 1 can use a preset method to determine whether the current base station B accessed by the terminal device A exists in the first allowed access network list corresponding to the industrial device 1 based on the first allowed access network list corresponding to the industrial device 1, the current base station B accessed by the terminal device A, and the identifier VPLMN1 of the VPLMN accessed by the terminal device A.
[0090] S107. The local network management server sends a yes result to the UE.
[0091] S108. The UE sends the context information of the UE and the address of the industrial device connected to the lower layer of the UE to the central management server.
[0092] S109. The central network management server determines each target VPLMN and sends the context information of the terminal device to each target VPLMN. Optionally, the central network management server sends the context information of the terminal device to each target VPLMN that allows the industrial device to access, so that the UDM in each target VPLMN updates the mobility restriction list information of the terminal device according to the context information of the terminal device.
[0093] Among them, each target VPLMN refers to each VPLMN that the industrial device is allowed to access in the first allowed access network list corresponding to the industrial device. The mobility restriction list information of the terminal device exists in the context information of the terminal device. The mobility restriction list information of the terminal device includes the list of mobility restriction area identifiers (TAI) associated with the terminal device and whether each mobility restriction area (TAI) can allow access. Then, the mobility restriction list information of the terminal device can be used to determine whether the base station accessed by the terminal device is allowed to access.
[0094] Among them, the context information of the terminal device is generated in the HPLMN before step S101. When the current base station accessed by the terminal device exists in the first allowed access network list corresponding to the industrial device, the terminal device sends the context information of the terminal device to the central network management server. When the central network management server receives the context information of the terminal device, it sends the context information of the terminal device to each target VPLMN that the industrial device is allowed to access, so that the UDM in each target VPLMN can update the mobility restriction list information of the terminal device according to the context information of the terminal device, that is, update the mobility restriction list information of the terminal device in the UDM of each VPLMN. When the terminal device subsequently switches to each target VPLMN, the authentication of the terminal device can be directly implemented through the mobility restriction list information in the UDM of each target VPLMN, so that the VPLM can quickly access each target VPLMN.
[0095] Exemplarily, when the current base station B accessed by the terminal device A exists in the first allowed access network list corresponding to the industrial device 1, the terminal device A sends the context information of the terminal device A to the central network management server. When the central network management server receives the context information of the terminal device A and it is in the first allowed access network list corresponding to the industrial device 1, the target VPLMNs allowed to access by the industrial device 1, for example, include: VPLMN1, VPLMN2, VPLMN3, VPLMN4. Then the central network management server can send the context information of the terminal device A to VPLMN1, VPLMN2, VPLMN3, and VPLMN4 respectively, so that the UDM in VPLMN1 updates the mobility restriction list information of the terminal device A, the UDM1 in VPLMN1 updates the mobility restriction list information of the terminal device A, the UDM2 in VPLMN2 updates the mobility restriction list information of the terminal device A, the UDM3 in VPLMN3 updates the mobility restriction list information of the terminal device A, and the UDM4 in VPLMN4 updates the mobility restriction list information of the terminal device A. When the terminal device A switches to VPLMN3, it can directly implement the quick verification of the terminal device A through the UDM3 in VPLMN3.
[0096] S1010. If not, the SMF in the VPLMN closes the session between the terminal device and the VPLMN, and the UDM in the VPLMN updates the first allowed access network list to the mobility restriction list information of the terminal device.
[0097] Among them, the VPLMN in S108 refers to the VPLMN that establishes a session with the terminal device in step S103. For example, VPLMN1.
[0098] Specifically, when it is determined that the current base station accessed by the terminal device does not exist in the first allowed access network list corresponding to the industrial device, the SMF in the VPLMN that establishes a session with the terminal device closes the session between the terminal device and the VPLMN, and the UDM in the VPLMN that establishes a session with the terminal device updates the first allowed access network list corresponding to the industrial device to the mobility restriction list information of the terminal device.
[0099] Exemplarily, when the current base station B accessed by the terminal device A does not exist in the first allowed access network list corresponding to the industrial device 1, the session between the terminal device A and VPLMN1 is closed, and the UDM in VPLMN1 updates the first allowed access network list corresponding to the industrial device 1 to the mobility restriction list information of the terminal device A.
[0100] In this embodiment, after the terminal device switches to the VPLMN in the industrial 5G environment for the first time and establishes a session with the VPLMN, the local network management server in the VPLMN receives the addresses of the industrial devices connected to the terminal device. Then, the local network management server obtains the first allowed access network list corresponding to the industrial devices based on the addresses of the industrial devices, and determines whether the current base station identifier exists in the first allowed access network list according to the first allowed access network list, the current base station identifier to which the terminal device is connected, and the identifier of the VPLMN. If so, the central network management server sends the context information of the terminal device to each target VPLMN that allows the industrial device to access, so that the UDM in each target VPLMN can update the mobility restriction list information of the terminal device according to the context information of the terminal device. This can ensure that all target VPLMNs that allow the industrial device to access can pre-store the mobility restriction list information of the terminal device in the UDM of each target VPLMN. When the terminal device switches to each target VPLMN subsequently, each target VPLMN can directly perform quick verification of the terminal device through the UDM, enabling the terminal device and each target VPLMN to quickly access and establish a session, avoiding the need for complex signaling interactions in the prior art, thus significantly shortening the handover time, also avoiding the need to open additional ports on the firewall, reducing potential network security risks, and at the same time conforming to the existing security policies of the factory, ensuring seamless handover of the terminal device between different security domains.
[0101] Figure 5 It is a schematic flowchart of the second terminal cross-domain handover processing method provided by the embodiment of the present application. As Figure 5 shown, the above S102, where the local network management server obtains the first allowed access network list corresponding to the industrial devices based on the addresses of the industrial devices, may include:
[0102] S201. The local network management server sends a retrieval request to the central network management server.
[0103] Among them, the retrieval request includes the addresses of the industrial devices connected to the terminal device. For example, the address IP1 of industrial device 1 in step S101. The retrieval request is used to obtain the first allowed access network list corresponding to the industrial devices.
[0104] As can be seen from the foregoing, the user can pre-enter the first allowed access network list [industrial device IP, [PLMN ID, [TAI]]] corresponding to the industrial devices in the central network management server. Specifically, the local network management server in the VPLMN that establishes a session with the terminal device sends a retrieval request to the central network management server to obtain the first allowed access network list corresponding to the industrial devices pre-stored in the central network management server.
[0105] For example, after VPLMN1 establishes a session with terminal device A, terminal device A sends the address IP1 of the downstream industrial device 1 to the local network management server of VPLMN1. When the local network management server 1 receives the address IP1 of the industrial device 1, the local network management server 1 sends an acquisition request containing IP1 to the central network management server.
[0106] S202: The central network management server determines a target address that matches the address of the industrial device from a preset network list database, and sends a list of all allowed access networks containing the target address as a first allowed access network list to the local network management server.
[0107] The preset network list database includes lists of networks allowed to be accessed corresponding to different industrial devices.
[0108] For example, when the central network management server receives the address IP1 of industrial device 1, it can search for the address IP1 from the network list database storing each industrial device, determine the target address that matches IP1, and then send all the allowed access network lists containing IP1 as the first allowed access network list to the local network management server 1.
[0109] For example, in the central network management server, the list of all allowed access networks including the address IP1 of industrial equipment 1 is [IP1, [VPLMN1, [TAI1]]], [IP1, [VPLMN2, [TAI2]]], [IP1, [VPLMN3, [TAI2]]], [IP1, [VPLMN4, [TAI3]]], then [IP1, [VPLMN1, [TAI1]]], [IP1, [VPLMN2, [TAI2]]], [IP1, [VPLMN3, [TAI2]]], [IP1, [VPLMN4, [TAI3]]] are sent to the local network management server as the first allowed access network list.
[0110] S203: The local network server receives a first list of allowed access networks.
[0111] Exemplarily, the local network management server 1 may receive a first list of networks allowed to be accessed corresponding to the industrial device 1 .
[0112] Optionally, the above S103, in which the local network management server determines whether the current base station identifier exists in the first allowed access network list according to the first allowed access network list, the identifier of the current base station accessed by the terminal device, and the identifier of the VPLMN, may include:
[0113] Specifically, if there is an identifier in the tracking area identifiers that allow industrial devices to access in the first allowed access network list and that matches the current base station identifier, and the identifier of the VPLMN that establishes a call with the terminal device in step S101 and the tracking area identifier that matches the current base station identifier are in the same allowed access network list, it is determined that the current base station exists in the first allowed access network list.
[0114] Exemplarily, the first allowed access network list corresponding to industrial device 1 is [IP1, [VPLMN1, [TAIB]]], [IP1, [VPLMN2, [TAIC]]], [IP1, [VPLMN3, [TAIC]]], [IP1, [VPLMN4, [TAIB]]], where TAIB and TAIC are tracking area identifiers that allow industrial device 1 to access. The current base station identifier when the terminal device A accesses with VPLMN1 is B. There is a TAIB in the first allowed access list that is the same as the current base station B, and TAIB and VPLMN1 are in the same allowed access list. Then it is determined that the current base station B exists in the first allowed access network list.
[0115] Specifically, if there is no identifier in the tracking area identifiers that allow industrial devices to access in the first allowed access network list and that matches the current base station identifier, or the identifier of the VPLMN that establishes a call with the terminal device in step S101 and the tracking area identifier that matches the current base station identifier are not in the same allowed access network list, it is determined that the current base station does not exist in the first allowed access network list.
[0116] Exemplarily, if the first allowed access network list corresponding to industrial device 1 is [IP1, [VPLMN1, [TAIC]]], [IP1, [VPLMN2, [TAIC]]], [IP1, [VPLMN3, [TAIC]]], [IP1, [VPLMN4, [TAID]]], where TAIC and TAID are tracking area identifiers that allow industrial device 1 to access. The current base station identifier when the terminal device A accesses with VPLMN1 is B. There is no tracking area identifier in the first allowed access list that is the same as the current base station B. Then the current base station B does not exist in the first allowed access network list.
[0117] For example, if the first allowed access network list corresponding to industrial equipment 1 is [IP1, [VPLMN1, [TAIC]]], [IP1, [VPLMN2, [TAIB]]], [IP1, [VPLMN3, [TAIC]]], [IP1, [VPLMN4, [TAID]]], where TAIB, TAIC and TAID are tracking area identifiers allowed for access by industrial equipment 1, and the current base station identifier when terminal device A accesses VPLMN1 is B, there is a tracking area identifier identical to the current base station B in the first allowed access list, but TAIB and VPLMN1 are not in the same allowed access network list. Therefore, the current base station B does not exist in the first allowed access network list.
[0118] Figure 6 A flow chart of a third terminal cross-domain handover processing method provided in an embodiment of the present application is shown as follows: Figure 6 As shown, the above S104, the central network management server sends the context information of the terminal device to each target VPLMN that allows the industrial device to access, which may include:
[0119] S301: The central network management server receives context information of a terminal device and an address of an industrial device connected to the terminal device, sent by a local network management server.
[0120] Specifically, when it is determined that the current base station identifier accessed by the terminal device exists in the first allowed access network list corresponding to the industrial device, the local network management server of the VPLMN that establishes a session with the terminal device sends the context information of the terminal device and the address of the industrial device connected to the terminal device to the central network management server, and the central network management server receives the context information of the terminal device and the address of the industrial device connected to the terminal device. After the VPLMN establishes a session with the terminal device, the terminal device sends the context information of the terminal device and the identifier of the industrial device connected to the terminal device to the local network management server of the VPLMN.
[0121] For example, when it is determined that the current base station identifier B accessed by the terminal device A exists in the first allowed access network list corresponding to the industrial device 1, the local network management server 1 of the VPLMN1 that establishes a session with the terminal device A sends the context information of the terminal device A and the address IP1 of the industrial device 1 connected to the terminal device A to the central network management server.
[0122] S302: The central management server determines the address of the local network management server of each target VPLMN according to the address of the industrial device.
[0123] For example, the central server can use a preset method to determine the address of the local network management server of each target VPLMN that the industrial device 1 is allowed to access based on the address IP1 of the industrial device 1. For example, the addresses of the local network management servers of each target VPLMN are respectively server addresses IP x1 、Server IP address x2 、Server IP address x3 And the server IP address x4 .
[0124] S303: The central network management server sends the context information of the terminal device to the local network management server corresponding to the address of the local network management server of each target VPLMN.
[0125] For example, the central network management server can send server address IP x1 The corresponding local network management server 1 sends the context information of terminal device A to the server address IP x2 The corresponding local network management server 2 sends the context information of terminal device A to the server address IP x3 The corresponding local network management server 3 sends the context information of terminal device A to the server address IP x4 The corresponding local network management server 4 sends the context information of the terminal device A.
[0126] In this embodiment, after the central network management server determines the address of the local network management server of each target VPLMN that the industrial device is allowed to access based on the address of the industrial device connected to the terminal device, the central network management server distributes the context information of the terminal device to the local network management server of each target VPLMN, so that when the terminal device switches to the target VPLMN in the future, it can switch quickly and realize fast switching between different security domains, thereby ensuring uninterrupted wireless connection and eliminating the need for complex signaling interaction on the network firewalls between different security domains, significantly reducing the complexity of industrial 5G network deployment.
[0127] Figure 7 A flowchart of a fourth terminal cross-domain handover processing method provided in an embodiment of the present application is shown as follows: Figure 7 As shown, the above S302, in which the central management server determines the address of the local network management server of each target VPLMN according to the address of the industrial device, may include:
[0128] S401: The central management server obtains a first allowed access network list corresponding to the industrial device according to the address of the industrial device, and determines an identifier of each target VPLMN from the first allowed access network list.
[0129] Optionally, the central network management server may obtain the first allowed access network list corresponding to the industrial device from the network list database in the central network management server according to the address of the industrial device, and determine the identifiers of the target VPLMNs to which the industrial device is allowed to access from the first allowed access network list.
[0130] Exemplarily, according to the address IP1 of industrial device 1, the central management server may obtain the first allowed access network list corresponding to industrial device 1, namely [IP1, [VPLMN1, [TAIB]]], [IP1, [VPLMN2, [TAIC]]], [IP1, [VPLMN3, [TAIC]]], [IP1, [VPLMN4, [TAID]]] from the network list database, and use VPLMN1, VPLMN2, VPLMN3, and VPLMN4 as the identifiers of the target VPLMNs.
[0131] S402. The central network management server determines the network private network information of each target VPLMN according to the identifier of each target VPLMN and the network private network information database pre-stored in the central network management server.
[0132] Among them, the network private network information includes the identifier of the target VPLMN and the address of the local network management server of the target VPLMN, specifically [server IP, PLMN ID].
[0133] Exemplarily, the central network server may determine the private network information 1 of VPLMN1 [server IP x1 , VPLMN1] according to the identifier of VPLMN1, determine the private network information 2 of VPLMN2 [server IP x2 , VPLMN2] according to the identifier of VPLMN2, determine the private network information 3 of VPLMN3 [server IP x3 , VPLMN3] according to the identifier of VPLMN3, and determine the private network information 4 of VPLMN4 [server IP x4 , VPLMN4] according to the identifier of VPLMN4.
[0134] S403. The central network management server obtains the addresses of the local network management servers of each target VPLMN from the network private network information of each target VPLMN.
[0135] Exemplarily, the central network management server may obtain the address IP of the local network management server of VPLMN1 from the private network information 1 [server IP x1 , VPLMN1], and obtain the address IP of the local network management server of VPLMN2 from the private network information 2 [server IP x1 , and x2,VPLMN2] to obtain the IP address of the local network management server of VPLMN2 x2 , from private network information 3 [server IP x3 ,VPLMN3] to obtain the IP address of the local network management server of VPLMN3 x3 , from private network information 4 [server IP x4 ,VPLMN4] to obtain the IP address of the local network management server of VPLMN4 x4 .
[0136] Optionally, in S104, the UDM in each target VPLMN updates the mobility restriction list information of the terminal device according to the context information of the device on the terminal, which may include:
[0137] Specifically, when the target VPLMN receives the context information of the terminal device, the local network management server in the target VPLMN sends a first update request to the NEF in the target VPLMN. After receiving the first update request, the NEF in the target VPLMN sends a data modification request to the UDM in the target VPLMN. When the UDM in the target VPLMN receives the data modification request, the UDM in the target VPLMN updates the mobility restriction list of the terminal device in the context information of the terminal device to the UDM in the target VPLMN based on the data modification request.
[0138] Optionally, in the above S105, the SMF in the VPLMN closes the session between the terminal device and the VPLMN, and the UDM in the VPLMN updates the first allowed access network list to the mobility restriction list information of the terminal device, which may include:
[0139] Specifically, when the SMF in the VPLMN that has established a session with the terminal device receives a session close request from the VPLMN's local network management server, the SMF closes the session between the terminal device and the VPLMN, and the NEF in the VPLMN closes the VPLMN's network connection. The NEF then sends a second update request to the UDM of the VPLMN, which includes the context information of the terminal device. After receiving the second update request, the UDM of the VPLMN updates the first allowed access network list corresponding to the industrial device connected to the terminal device in the central network management server to the mobility restriction list information of the terminal device.
[0140] In this embodiment, when the current base station accessed by the terminal device does not exist in the first allowed access network list corresponding to the industrial equipment, the UDM in the VPLMN that establishes a session with the terminal device updates the mobility restriction list information of the terminal device, that is, the first allowed access network list corresponding to the industrial equipment connected to the terminal device stored in the central network management server is updated to the mobility restriction list information of the terminal device.
[0141] Optionally, the terminal inter-domain handover processing system further includes: a home public land mobile network HPLMN.
[0142] Optionally, before the terminal device switches to the VPLMN and establishes a session in S101, the following steps may be included:
[0143] Optionally, after the terminal device establishes a session with the HPLMN, the HPLMN's SMF sends a notification to the NEF regarding the completion of the session establishment between the terminal device and the HPLMN. Upon receiving the notification, the NEF sends instructions for obtaining context information for the terminal device to the SMF, AMF, and UDM, respectively. The NEF receives the context information of the terminal device and reports it to the local network management server of the HPLMN. The context information of the terminal device is generated when the terminal device first establishes a session with the HPLMN. That is, when the terminal device first enters the HPLMN, the HPLMN generates the context information of the terminal device.
[0144] Among them, the context information of the terminal device may include: user identification: SUPI (User Permanent Identifier), GPSI (Globally Unique User Identifier), etc., which are used to uniquely identify the user. PDU session related identification: PDU session ID, used to distinguish different PDU sessions. Data network identification: DNN (Data Network Name) of the network currently accessed by the UE. Slice information: S-NSSAI, the network slice identifier currently accessed by the UE. User location information: identification information of the base station accessed by the user this time. Mobility restriction list: list of mobility restriction tracking area (TA) identifiers associated with the UE.
[0145] An embodiment of the present application further provides a terminal inter-domain handover processing system, which includes: a central network management server, a home public land mobile network HPLMN, and at least one visited public land mobile network VPLMN.
[0146] Among them, the central network management server is used for the method steps executed by the central network management server in the above specific implementation, the HPLMN is used for executing the method steps executed by the HPLMN in the above specific implementation, and the VPLMN is used for executing the method steps executed by the VPLMN in the above specific implementation.
[0147] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the method steps in the embodiment of the above terminal cross-domain switching processing method are executed.
[0148] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the method embodiments, which will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the devices or modules can be in an electrical, mechanical, or other form.
[0149] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0150] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application.
Claims
1. A method for processing cross-domain switching of a terminal, characterized in that Applied to a terminal cross-domain handover processing system, the terminal cross-domain handover processing system at least includes: a central network management server and at least one visited public land mobile network (VPLMN); the method includes: After the terminal device hands over to the VPLMN and establishes a session, the local network management server in the VPLMN receives the address of the industrial device connected to the lower layer of the terminal device. The local network management server obtains the first allowed access network list corresponding to the industrial device based on the address of the industrial device, and determines whether the current base station identifier exists in the first allowed access network list according to the first allowed access network list, the current base station identifier accessed by the terminal device, and the identifier of the VPLMN. The first allowed access network list includes the address of the industrial device, the identifier of the target VPLMN allowed for the industrial device to access, and the tracking area identifier allowed for the industrial device to access. If so, the central network management server sends the context information of the terminal device to each target VPLMN allowed for the industrial device to access, so that the unified data management module (UDM) in each target VPLMN updates the mobility restriction list information of the terminal device according to the context information of the terminal device. If not, the session between the terminal device and the VPLMN is closed by the SMF in the VPLMN, and the UDM in the VPLMN updates the first allowed access network list to the mobility restriction list information of the terminal device.
2. The terminal cross-domain switching processing method according to claim 1, wherein The local network management server obtaining the first allowed access network list corresponding to the industrial device based on the address of the industrial device includes: The local network management server sends a retrieval request to the central network management server, and the retrieval request includes the address of the industrial device connected to the lower layer of the terminal device. The central network management server determines the target address matching the address of the industrial device from the preset network list database, and sends all the allowed access network lists containing the target address to the local network management server as the first allowed access network list. The local network management server receives the first allowed access network list.
3. The terminal cross-domain switching processing method according to claim 1, wherein Determining whether the current base station identifier exists in the first allowed access network list according to the first allowed access network list, the current base station identifier accessed by the terminal device, and the identifier of the VPLMN includes: If there is an identifier in the tracking area identifier allowed for the industrial device to access in the first allowed access network list that matches the current base station identifier, and the identifier of the VPLMN and the tracking area identifier matching the current base station identifier are in the same allowed access network list, it is determined that the current base station identifier exists in the first allowed access network list. If there is no identifier matching the current base station identifier in the tracking area identifier allowed to access the industrial equipment in the first allowed access network list, or the VPLMN identifier and the tracking area identifier matching the current base station identifier are not in the same allowed access network list, it is determined that the current base station identifier does not exist in the first allowed access network list.
4. The terminal cross-domain switching processing method according to claim 1, wherein The central network management server sends the context information of the terminal device to each target VPLMN that the industrial device is allowed to access, including: The central network management server receives the context information of the terminal device and the address of the industrial device connected to the terminal device sent by the local network management server; The central network management server determines the address of the local network management server of each target VPLMN according to the address of the industrial device; The central network management server sends the context information of the terminal device to the local network management server corresponding to the address of each local network management server of the target VPLMN.
5. The terminal cross-domain switching processing method according to claim 4, wherein The central network management server determines the address of the local network management server of each target VPLMN according to the address of the industrial device, including: The central network management server obtains a first allowed access network list corresponding to the industrial device according to the address of the industrial device, and determines the identifier of each target VPLMN from the first allowed access network list; The central network management server determines the network private network information of each target VPLMN according to the identifier of each target VPLMN and a network private network information database pre-stored in the central network management server, wherein the network private network information includes: the identifier of the target VPLMN and the address of the local network management server of the target VPLMN; The central network management server obtains the address of the local network management server of each target VPLMN from the network private network information of each target VPLMN.
6. The terminal cross-domain switching processing method according to claim 1, wherein The unified data management module UDM in each of the target VPLMNs updates the mobility restriction list information of the terminal device according to the context information of the terminal device, including: The local network management server of the target VPLMN sends a first update request to the network open module in the target VPLMN, where the first update request includes the context information of the terminal device; The network opening module in the target VPLMN sends a data modification request to the unified data management module in the target VPLMN, and the unified data management module in the target VPLMN updates the mobility restriction list of the terminal device in the context information of the terminal device to the unified data management module in the target VPLMN based on the data modification request.
7. The terminal cross-domain switching processing method according to claim 1, wherein The session management module in the VPLMN closes the session between the terminal device and the VPLMN, and the unified data management module in the VPLMN updates the first allowed access network list to mobility restriction list information of the terminal device, including: The session management module in the VPLMN closes the session between the terminal device and the VPLMN, and the network opening module in the VPLMN closes the network connection of the VPLMN and sends a second update request to the unified data management module in the VPLMN. The second update request includes a first allowed access network list; The unified data management module in the VPLMN updates the first allowed access network list to the mobility restriction list information of the terminal device.
8. The terminal cross-domain switching processing method according to claim 1, wherein The terminal cross-domain handover processing system further includes: a home public land mobile network HPLMN; Before the terminal device hands over to the VPLMN and establishes a session, it further includes: After the terminal device establishes a session with the HPLMN, the session management module of the HPLMN sends a notification of the completion of the session establishment between the terminal device and the HPLMN to the network opening module; After receiving the session establishment completion notification, the network opening module sends acquisition instructions for the context information of the terminal device to the session management module, the access and mobility management module, and the unified data management module respectively; The network opening module receives the context information of the terminal device and reports the context information to the local network management server of the HPLMN.
9. In a terminal cross-domain switching processing system, it is characterized in that, The terminal cross-domain handover processing system includes: a central network management server, a home public land mobile network HPLMN, and at least one visited public land mobile network VPLMN; The central network management server is used to execute the method steps performed by the central network management server in any one of the above claims 1-8; the HPLMN is used to execute the method steps described in claim 8 above; the VPLMN is used to execute the method steps performed by the VPLMN in any one of the above claims 1-8.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is run by a processor, it executes the steps of the terminal cross-domain handover processing method described in any one of claims 1-8.