Method for using a user equipment with a telecommunication network
Patent Information
- Application Number
- CN202380089377.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2023-01-02
- Filing Date
- 2023-12-04
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2043-12-04
AI Technical Summary
[0006]然而,(对于用户装备或其应用)必须请求与数据网络名称和/或网络切片的连通性的此类需求通常使得与特定联网资源或资源提供商的连接或连通性的建立比所需的更麻烦和/或更复杂
[0038]此外,根据本发明有利地可能并且优选地,与经由因特网的连通性相比,与另外的网络相关联的数据网络名称提供不同的、特别是更高的服务质量,使得与过顶方法相比,朝向该另外的网络的连通性能够以更高的可靠性和/或质量来实现。
Smart Images

Figure CN120530715B_ABST
Abstract
Description
Background Technology
[0001] The present invention relates to a method for using user equipment with a telecommunications network, wherein the user equipment requests connection to or access to an additional network when connected to the telecommunications network, wherein the telecommunications network includes control plane functions and user plane functions, wherein the additional network is a virtual network as part of a cloud provider infrastructure, and the additional network can access from within the cloud provider infrastructure using target network identifier information.
[0002] Furthermore, the present invention relates to a user equipment for operating with a telecommunications network, wherein the user equipment is configured to request connection to or access to an additional network when connected to the telecommunications network, the additional network being a virtual network as part of a cloud provider's infrastructure, and the additional network using target network identifier information to access from within the cloud provider's infrastructure.
[0003] Additionally, the present invention relates to a system or telecommunications network for use with a user equipment in conjunction with a telecommunications network, wherein the user equipment requests connection to or access to an additional network when connected to the telecommunications network, wherein the telecommunications network includes control plane functions and user plane functions, wherein the additional network is a virtual network as part of a cloud provider infrastructure, and wherein the additional network can access from within the cloud provider infrastructure using target network identifier information.
[0004] Furthermore, the present invention relates to a program and a computer-readable medium for using user equipment with a telecommunications network according to the method of the present invention.
[0005] In conventional telecommunications networks, where user equipment (particularly its applications or applications running on that user equipment) requires connectivity to a specific network resource or resource provider, such connectivity typically requires the establishment or provision of a data network associated with a data network name (DNN) within that telecommunications network or its corresponding core network. Therefore, in conventional telecommunications networks, as a prerequisite for user equipment (or its applications) to have or obtain connectivity to such specific network resources or resource providers, the corresponding (or considered) user equipment (or its applications) needs to request connectivity with a data network (or data network name, DNN) or a combination of data network (name) (DNN) and network slice (S-NSSAI, Single Network Slice Selection Auxiliary Information).
[0006] However, such requirements (for user equipment or its applications) to request connectivity to data network names and / or network slices often make establishing a connection or connectivity to a specific network resource or resource provider more cumbersome and / or complex than necessary. Summary of the Invention
[0007] The object of this invention is to provide a technically simple, effective, and cost-efficient solution for using user equipment with a telecommunications network, wherein the user equipment, when connected to the telecommunications network, requests connection to or access to an additional network, wherein the additional network can use target network identifier information to access from within the cloud provider's infrastructure. Another object of this invention is to provide corresponding user equipment, systems, or telecommunications networks, as well as corresponding programs and computer-readable media.
[0008] The object of the present invention is achieved by a method for using user equipment with a telecommunications network, wherein the user equipment, when connected to the telecommunications network, requests to connect to or access an additional network, wherein the telecommunications network includes control plane functions and user plane functions, and wherein the additional network is a virtual network as part of a cloud provider's infrastructure.
[0009] The additional network can use target network identifier information to access the cloud provider's infrastructure.
[0010] In order for the user's equipment to use or access the additional network, a data network and an associated data network name need to be configured or established at the telecommunications network or between the telecommunications network and the cloud provider's infrastructure.
[0011] To enable the user equipment to connect to or access the additional network, the method includes the following steps:
[0012] -- In the first step, the user equipment uses target network identifier information to request the establishment of a communication session to or toward the other network, the target network identifier information being part of a request message transmitted by the user equipment to the control plane function of the telecommunications network.
[0013] -- In the second step, the communication session is associated with the data network and / or data network name so that connectivity to the additional network can be provided via the cloud provider's infrastructure using the data network and / or data network name.
[0014] -- In the third step, the user equipment receives a communication session establishment acceptance message transmitted by the control plane function of the telecommunications network.
[0015] -- In the fourth step, the user equipment accesses the other network via the established communication session using the user plane function of the telecommunications network.
[0016] According to the invention, it is advantageous that, in telecommunications networks (typically but not necessarily mobile communication networks), user equipment can use target network identifier information to request connectivity to a specific network resource or resource provider (i.e., to another network accessible from within a cloud provider's infrastructure), which is the opposite of the paradigm in conventionally known telecommunications networks where connectivity must be requested using a combination of data network name (DNN) and / or network slice.
[0017] In current telecommunications networks, enabling user equipment (UE) to access networks within a cloud provider's infrastructure relies solely on VPNs (Virtual Private Networks). While the network operator (of the telecommunications network to which the UE connects) can provide connectivity to the data network (DN), anything beyond that connectivity requires "over-the-top (OTT)" access; typically, the UE needs prior knowledge of certain parameters to achieve connectivity with the intended network. This requirement for prior knowledge of the UE (or at the UE itself) conflicts with the intention to simplify the UE and to allow user equipment local access to third-party networks and allow operators to abstract away the underlying network complexities.
[0018] In currently known telecommunications networks – typically based on the separation between user equipment, (radio) access network, and core network – to provide connectivity to a data network (DN) (e.g., the Internet) for the user equipment, the user equipment communicates with the access network (particularly via a radio interface to the radio access network in a mobile communication network) and with the core network, and the data network provides connectivity to applications (e.g., the backend of an application running on the user equipment) by establishing a Packet Data Unit session (PDU session) between the user equipment and the data network. In this sense, conventionally known telecommunications networks (e.g., 5G systems) provide a “pipeline” (i.e., a Packet Data Unit session) to achieve connectivity to a given data network. This connectivity is then typically exposed by the operating system to applications(s) in the user equipment via a network interface, which can be addressed within the data network via, for example, an IP address 10.10.10.42 assigned to the user equipment on PDU session 1 and another IP address 192.168.0.23 assigned to the user equipment on PDU session 2.
[0019] In the context of cloudification and the use of public / hybrid clouds, virtual networks, i.e., separate networks, are typically used, independent of the telecommunications networks to which user equipment is connected. While different cloud providers may use different names (e.g., virtual network, "Vnet"; virtual private cloud, "VPC"), a virtual network within the cloud is a virtual version of the physical network, implemented within the cloud provider's production network (i.e., within the cloud provider's infrastructure); typically, a virtual network can then be further segmented into several subnets. The virtual network provides network connectivity and address allocation to the components within it (e.g., cloud resources such as virtual machines).
[0020] Such virtual networks are typically built within a (public) cloud (i.e., cloud provider infrastructure) and usually use private ranges or IP addresses (e.g., within a Class A address range, for example, 10.0.0.0 / 8). As a private network, if connectivity is provided within that network or cloud provider infrastructure (usually via a VPN gateway accessible via the public internet), then any device outside the cloud (or cloud provider infrastructure) under consideration can only be part of such a virtual network. Virtual networks – typically all cloud resources – are usually identified by a unique identifier, a virtual network identifier, most commonly such as a Universally Unique Identifier (UUID), for example, “00112233-4455-6677-c899-aabbccddeeff”.
[0021] Therefore, a virtual network is a private network placed within a cloud provider or its infrastructure, where cloud resources (e.g., virtual machines, Kubernetes (k8s) clusters, Software as a Service (SaaS) products, etc.) can be instantiated / addressed. However, such resources within a virtual network – and the virtual network itself – cannot be accessed from the “outside” (i.e., the Internet) unless a given resource has been assigned a public IP address (in which case the given resource is addressable via the Internet) or via a VPN tunnel, by which the virtual network can be connected to other networks on the other side of the VPN tunnel using routing mechanisms.
[0022] According to the present invention, it is advantageous that user equipment can easily achieve connectivity to a cloud-based network (another network), the establishment of which requires prior knowledge of certain parameters so that the user equipment can achieve such connectivity to the intended network: the proposed method advantageously reduces the complexity of achieving such connectivity for the user equipment under consideration: the user equipment only needs to know the other network it wants to connect to (i.e., its corresponding target network identifier information), indicate it to the network, and the rest of the transactions are handled by the telecommunications network.
[0023] Specifically, according to the invention, a user equipment (or an application triggering the user equipment) initiates the establishment of a communication session (particularly a packet data unit session) targeting an additional network that is not directly accessible (via the telecommunications network to which the user equipment is attached). The user equipment only needs to know the target network identifier information, i.e., what the virtual network (requiring connectivity) is, not how to achieve it. According to the invention, this is achieved by the user equipment including the virtual network identifier (i.e., the target network identifier information) in the communication session establishment request (typically a PDU session establishment request). Based on subscriber data (e.g., whether the user equipment is permitted to obtain the connectivity, what quality of service level will be applied, or whether the user equipment is permitted to achieve connectivity via which network slice), the telecommunications network (to which the user equipment is connected) associates the communication session (or PDU session) with an existing data network name (DNN) and / or network slice (S-NSSAI), through which this information can be routed to another network within the cloud provider's infrastructure, or the telecommunications network is equipped with connectivity to the corresponding other network. The user equipment then receives a communication session acceptance message (usually a PDU session establishment acceptance message) and can transmit and / or receive data as normally does via a communication session (or PDU session), except that in this case, connectivity (the user equipment’s initial request) is usually not (or not necessarily) directed toward a combination of DNN or DNN / S-NSSAI, but toward another network as a virtual network.
[0024] According to the present invention, it is assumed that the user equipment is used in conjunction with a telecommunications network, that is, it is connected to the user equipment, and while connected to the telecommunications network, the user equipment requests to connect to or access another network, which is a virtual network as part of a cloud provider's infrastructure. The telecommunications network includes control plane functions and user plane functions, and the other network can use the target network identifier information of the other network to access from within the cloud provider's infrastructure (specifically, only from within, i.e., not from outside).
[0025] Furthermore, it is assumed that in order for user equipment to use or access another network, a data network and an associated data network name need to be configured or established at the telecommunications network or between the telecommunications network and the cloud provider infrastructure. That is, the cloud provider infrastructure is reached from the telecommunications network via the data network. In the context of this invention, the terms data network and data network name are used quite synonymously, especially in relation to data network identification information to indicate or refer to an associated data network – particularly for the purposes of the telecommunications network or its core network. In order for a user equipment (UE) to actually connect to or access another network, (in the first step of the method of the present invention) the UE uses target network identifier information as part of a request message transmitted by the UE to the control plane function of the telecommunications network to request the establishment of a communication session to or toward the other network; (in the second step of the method of the present invention) the communication session is associated with the data network name so as to provide connectivity to the other network via the cloud provider infrastructure using the data network name; furthermore, (in the third step of the method of the present invention) the UE receives a communication session establishment acceptance message transmitted by the control plane function of the telecommunications network; and (in the fourth step of the method of the present invention) the UE uses the established communication session to access the other network via the user plane function of the telecommunications network. Specifically, (in the first step of the method of the present invention) the UE's communication session establishment request does not necessarily include a reference to or indication of the data network name (example) to be used. Furthermore, when the UE requests the establishment of a communication session to or toward the other network, the data network name may not yet be configured or established.
[0026] According to the present invention, it is also advantageously possible and preferably possible for additional networks to access the cloud provider's infrastructure solely using the target network identifier information.
[0027] Specifically, this additional network cannot be directly accessed from outside the cloud provider's infrastructure.
[0028] Therefore, the method of the present invention can be advantageously implemented and carried out in a relatively simple and efficient manner: even if another network (by means of using target network identifier information) cannot be accessed (directly) from the telecommunications network, it is still advantageous for the user equipment to obtain connectivity to that other network according to the present invention.
[0029] According to the invention, it is also advantageously possible and preferably that the communication session is or corresponds to a Protocol Data Unit (PDU) session, and / or wherein the control plane function is or corresponds to a session management function or a session management function instance.
[0030] Therefore, the method of the present invention can be advantageously implemented and carried out in a relatively simple and efficient manner.
[0031] Furthermore, according to the invention, it is advantageously possible and preferably – after the data network name is configured or established – that data network name and the additional network and its target network identifier information are mutually assigned.
[0032] Specifically, such assignments are stored in the repository entity or functionality of the telecommunications network.
[0033] In particular, such assignments are carried out.
[0034] -- Before the first step, or
[0035] -- After the first step, and especially after the third step.
[0036] Therefore, it is advantageous to implement and carry out the method of the present invention efficiently in a relatively simple and flexible manner, since the assignment of data network names and other network and target network identifier information can be performed at different points in time.
[0037] Furthermore, according to the invention, it is advantageously possible and preferably that data network names and other network and target network identifier information are mutually assigned, wherein such assignment and the configuration or establishment of the data network name are performed after the first step, and in particular, after the third step.
[0038] Furthermore, according to the invention, it is advantageous and preferably possible that data network names associated with other networks provide different, particularly higher, quality of service compared to connectivity via the Internet, so that connectivity toward the other network can be achieved with higher reliability and / or quality compared to over-the-top methods.
[0039] Furthermore, according to the invention, it is advantageous and preferably possible that, for a given additional network, when different user equipment requests to establish a communication session to or toward that additional network, different data networks providing connectivity toward that additional network may be used for the different user equipment, particularly when the selection of the data network and / or associated quality is based on subscriber or policy information associated with one or more user equipment.
[0040] Additionally, according to the invention, it is advantageous and preferably possible that if the data network name is no longer in use or needed, for example, when all user equipment requiring connectivity to that additional network is deregistered from the network, a data network instance is not configured, so that resource usage and / or costs, particularly the instantiation resources, reserved capacity and / or connectivity required on the cloud provider infrastructure side, can be optimized.
[0041] Therefore, the method of the present invention can be advantageously implemented and carried out in a relatively simple and efficient manner.
[0042] Furthermore, according to the invention, it is advantageously possible and preferably that the cloud provider infrastructure includes a cloud controller entity or function and / or a cloud ingress router entity or function, wherein equipping or establishing a data network name and / or assigning or associating the data network name, the additional network, and its target network identifier information relates to contacting the cloud controller entity or function and / or the cloud ingress router entity or function via a telecommunications network, and wherein the cloud ingress router entity can access the telecommunications network via the data network name and forward data packets between the additional network and the telecommunications network.
[0043] Therefore, the method of the present invention can be advantageously implemented and carried out in a relatively simple and efficient manner.
[0044] Furthermore, according to the invention, it is advantageously possible and preferably that the target network identifier information is, corresponds to, or includes, the universally unique identifier (UUID) information of the other network.
[0045] Specifically, the target network identifier information includes infrastructure identifier information that is related to or identifies the cloud provider's infrastructure.
[0046] Therefore, the method of the present invention can be advantageously implemented and carried out in a relatively simple and efficient manner.
[0047] Furthermore, the present invention relates to a user equipment for operating with a telecommunications network, wherein the user equipment is configured to request connection to or access to an additional network when connected to the telecommunications network, the additional network being a virtual network as part of a cloud provider's infrastructure, and the additional network using target network identifier information to access from within the cloud provider's infrastructure.
[0048] In order for the user equipment to use or access the additional network, a data network and an associated data network name need to be configured or established at the telecommunications network or between the telecommunications network and the cloud provider's infrastructure.
[0049] In order for the user equipment to connect to or access the additional network, the user equipment is configured such that:
[0050] -- The user equipment uses the target network identifier information to request the establishment of a communication session to or toward the other network, the target network identifier information being part of a request message transmitted by the user equipment to the telecommunications network for the control plane function.
[0051] -- The user equipment receives a communication session establishment accept message transmitted by the control plane function of the telecommunications network.
[0052] -- After the communication session is associated with the data network name, the user equipment uses the established communication session via the user plane function of the telecommunications network to access the other network in order to provide connectivity to the other network via the data network name through the cloud provider infrastructure.
[0053] Furthermore, the present invention relates to a system or telecommunications network for use with a user equipment (UE) connected to a telecommunications network, wherein the UE requests connection to or access to an additional network when connected to the telecommunications network, wherein the telecommunications network includes control plane functions and user plane functions, and wherein the additional network is a virtual network as part of a cloud provider's infrastructure.
[0054] The additional network can use target network identifier information to access the cloud provider's infrastructure.
[0055] In order for the user equipment to use or access the additional network, a data network and an associated data network name need to be configured or established at the telecommunications network or between the telecommunications network and the cloud provider's infrastructure.
[0056] In order for the user equipment to connect to or access the additional network, the system or telecommunications network is configured such that:
[0057] -- The telecommunications network receives a request message from the user equipment regarding the establishment of a communication session to or toward the other network, the target network identifier information being part of the request message received by the control plane function of the telecommunications network.
[0058] -- This communication session is associated with the data network and / or data network name so that the data network name can be used to provide connectivity to the additional network via the cloud provider's infrastructure.
[0059] -- The control plane function of the telecommunications network transmits a communication session establishment acceptance message, and the user equipment receives the communication session establishment acceptance message.
[0060] -- The established communication session is used by the user equipment to access the other network via the user plane function of the telecommunications network.
[0061] Additionally, the present invention relates to a program comprising computer-readable program code that, when executed on a computer, and / or on a user equipment, and / or on a network node of a telecommunications network, particularly on a control plane function, or partially on a user equipment, and / or partially on a network node of a telecommunications network, particularly on a control plane function, causes the computer and / or the user equipment and / or the network node of the telecommunications network to execute the method of the present invention.
[0062] Additionally, the present invention relates to a computer-readable medium comprising instructions that, when executed on a computer, and / or on a user equipment, and / or on a network node of a telecommunications network, particularly on a control plane function, or partially on a user equipment, and / or partially on a network node of a telecommunications network, particularly on a control plane function, cause the computer and / or the user equipment and / or the network node of the telecommunications network to perform the method of the present invention.
[0063] These and other features, characteristics, and advantages of the invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings, in which the principles of the invention are illustrated by way of example. This specification is for illustrative purposes only and is not intended to limit the scope of the invention. Reference is made to the accompanying drawings cited below. Attached Figure Description
[0064] Figure 1 The illustration depicts a telecommunications network comprising an access network, a core network, and user equipment, wherein the core network typically includes several network functions or services, and wherein the telecommunications network is connected to a cloud provider infrastructure that includes additional networks, which are virtual networks that are part of the cloud provider infrastructure.
[0065] Figure 2 An example of data network connectivity for a user equipment (or its application) using a telecommunications network (i.e., access network and core network) is illustrated, wherein the data network connectivity of the user equipment is implemented toward multiple data networks or data network names.
[0066] Figure 3 It schematically illustrates the different connection or connectivity possibilities of different user equipment.
[0067] Figure 4 An example of a user device connecting to a virtual network is illustrated, where connectivity to the virtual network already exists.
[0068] Figure 5 The diagram illustrates the communication between user equipment, the control plane function of the telecommunications network, the user plane function of the telecommunications network, and the cloud provider infrastructure in a scenario where connectivity to the virtual network already exists.
[0069] Figure 6 The diagram illustrates the communication between user equipment, the control plane function of the telecommunications network, the user plane function of the telecommunications network, and the cloud provider infrastructure in a scenario where connectivity to the virtual network does not yet exist (i.e., needs to be established). Detailed Implementation
[0070] The invention will be described with respect to specific embodiments and with reference to certain accompanying drawings, but the invention is not limited thereto, but is defined only by the claims. The described drawings are merely illustrative and not restrictive. In the drawings, some elements may be enlarged and not drawn to scale for illustrative purposes.
[0071] Use the indefinite or definite article when referring to a singular noun. For example, unless otherwise specified, “one,” “a,” and “the” include the plural form of the noun.
[0072] Furthermore, the terms first, second, third, etc., used in the specification and claims are used to distinguish between similar elements and are not necessarily used to describe order or chronological sequence. It should be understood that such terms are interchangeable where appropriate, and the embodiments of the invention described herein can operate in an order different from that described or illustrated herein.
[0073] exist Figure 1 The diagram schematically illustrates a telecommunications network 100 comprising an access network 110 and a core network 120. The telecommunications network 100, particularly the core network 120, typically includes several network functions or services. The access network 110 includes multiple radio cells 11, 12. Figure 1 In the exemplary situation or scenario shown, a first base station entity 111 generates or is associated with or spans a first radio cell 11, and a second base station entity 112 generates or is associated with or spans a second radio cell 12. Figure 1 In the illustrated exemplary scenario, user equipment 20 is connected to telecommunications network 100 via a radio interface to a first base station entity 111. User equipment 20 is typically, but not necessarily, mobile, i.e., capable of moving relative to the (typically, but not necessarily, static) radio cells 11, 12 or corresponding base station entities 111, 112 of access network 110. According to the invention, user equipment 20 typically includes an application 21 that typically runs on user equipment 20 (in... Figure 1 (Illustrated schematically as part of user equipment 20), that is, user equipment 20 typically runs or executes an operating system (such as a mobile (device) operating system, such as Android, iOS, iPadOS, etc.), and application 21 runs on the operating system; alternatively, application 21 may also be a low-level application that does not run on the operating system or is not part of the operating system but runs as, for example, part of the subscriber identity module of user equipment 20.
[0074] According to the present invention, telecommunications network 100 is connected to cloud provider infrastructure 200, which includes additional network 250, which is a virtual network that is part of cloud provider infrastructure 200. Furthermore, in Figure 1 In this context, cloud provider infrastructure 200 is represented as also including cloud controller entity or functionality 210 and cloud ingress router entity or functionality 220.
[0075] exist Figure 2 The diagram schematically illustrates an example of data network connectivity of user equipment 20 (or its application 21), wherein user equipment 20 (application 21) uses telecommunications network 100 (i.e., access network and core network, particularly implemented as a 5G system) to provide services such as 171, 172, and the data network connectivity of user equipment 20 (application 21) is implemented using communication sessions 151, 152, particularly packet data unit sessions 151, 152, toward multiple data networks or data network names 161, 162. Such data network connectivity for user equipment is already possible in currently known telecommunications networks; for example, connectivity to data networks 161, 162 is exposed as a network interface to user equipment 20 and / or its application 21, for example, user equipment 20 is addressable within data networks 161, 162, for example via IP addresses (e.g., IP address 10.10.10.42 assigned to user equipment 20 (or application 21) on the first packet data unit session 151 and usable by the first data network 161, and another IP address 192.168.0.23 assigned to user equipment 20 (or application 21) on the second packet data unit session 152 and usable by the second data network 162). Similarly, connectivity to user equipment 20 (or to application 21) is also exposed to the first data network 161 and / or the second data network 162 via network addresses (e.g., IP addresses). Therefore, the first service 171 can be provided to the user equipment 20 or application 21 via (or using) the first data network 161 and the first packet data unit session 151, and the second service 172 can be provided to the user equipment 20 or application 21 via (or using) the second data network 162 and the second packet data unit session 152.
[0076] According to the present invention, the telecommunications network 100 – based on currently or conventionally known mobile networks – is organized or constructed based on the separation between user equipment 20, (radio) access network 110 and core network, which is applied, for example, to 5G systems (5GS), i.e., telecommunications networks based on 5G standards.
[0077] The purpose is to provide user equipment 20 with access to a data network (DN) (e.g., the Internet, for example, such as...). Figure 2The data networks 161 and 162 shown provide connectivity. In the case where the telecommunications network 100 is a mobile communication network (or cellular network), the user equipment 20 communicates with the radio access network 110 (or its base station entity 111, particularly the gB node) via a radio interface (Uu interface or reference point), which is used to convey both signaling information and data traffic. Data networks 161 and 162 provide connectivity to services or backend applications 171 and 172 (e.g., the backend for application 21 running on the user equipment 20). Additionally, (network) slicing allows the telecommunications network 100 to be divided into logical segments (i.e., "slices") that can be accessed by the user equipment 20 and used to provide differentiated services.
[0078] Furthermore, according to the present invention, as in currently known networks, such systems typically separate the control plane from the user plane (i.e., signaling traffic and (user) data traffic are separate); traffic between user equipment 20 and telecommunications network 100 is transmitted via communication sessions 151, 152 (particularly packet data unit sessions 151, 152), which are anchored at PDU session anchors (PSAs), especially in the case where telecommunications network 100 is a 5G network (particularly using the N3 interface or reference point between gNB and UPF), particularly the user plane function (UPF). Similarly, the access and mobility management function (AMF) acts as a signaling anchor (the so-called N1 / N2 interface) for control plane traffic.
[0079] In order for user equipment 20 to have connectivity toward services 171, 172, it is necessary to establish data networks 161, 162 – or corresponding data network names – and to establish corresponding communication sessions, in particular packet data unit sessions 151, 152.
[0080] Especially in the context of conventionally known 5G systems, such Packet Data Unit (PDU) session establishment procedures (according to 3GPP TS 23.502, Clause 4.3.2.2.1) include the following procedures in Part 1: These procedures assume that the user equipment (UE) is already registered with the AMF, and therefore (unless the UE is urgently registered) the AMF has retrieved the user subscription data from the Unified Data Management (UDM); the UE transmits non-access stratum messages (to the Access and Mobility Management functions), which include:
[0081] -- Corresponding (requested) (various) S-NSSAI,
[0082] -- The data network name DNN requested by the user's equipment.
[0083] -- PDU Session ID
[0084] -- Request type information,
[0085] -- Old PDU session ID,
[0086] -- N1 SM (Session Management) container (including PDU session establishment requests, and possibly a port management information container).
[0087] To establish a new PDU session, the user equipment generates a new PDU session ID, and the user equipment initiates the PDU session establishment procedure requested by the user equipment through the transmission of a NAS message containing a PDU session establishment request within the N1 SM container.
[0088] Therefore, in currently known telecommunications networks and as already mentioned, in order to provide user equipment with connectivity toward a data network, the user equipment communicates with the access network and the core network, and the data network provides connectivity toward the service by means of packet data unit sessions (PDU sessions), that is, the telecommunications network (e.g., 5G system) provides packet data unit sessions as a "pipeline" to achieve connectivity to a given data network.
[0089] In cases where another network (or a service connected via Packet Data Unit Session) is part of a cloud provider's infrastructure, such resources within the virtual network, or the virtual network itself, are typically not equippable by the user and accessible via the Packet Data Unit Session and data network without prior or prior knowledge and / or prior configuration steps; this will be explained below:
[0090] In a typical setup of a cloud-based virtual network, such a virtual network includes, for example, multiple virtual machines, a Software-as-a-Service database, and / or a Kubernetes cluster (k8s cluster). The associated or corresponding cloud provider infrastructure includes, for example, a load balancer with a public IP address (or associated with a public IP address) that allows internet users to access the load balancer (i.e., the cloud provider infrastructure) via their public IP address, but not the virtual network itself. Furthermore, the cloud provider infrastructure includes, for example, a VPN gateway pointing to a corporate network (which also includes a VPN gateway terminating the VPN tunnel on its other side); corporate users can route traffic between the virtual network and the corporate network via this VPN tunnel. However, such connectivity to a virtual network is only possible if a VPN tunnel has been established; a virtual network or resources within a virtual network cannot be directly accessed from the “outside” (i.e., the Internet) unless a given resource is assigned a public IP address (in which case the given resource can be addressed via the Internet) or via a VPN tunnel (in which case the virtual network can connect to other networks on the other side of the VPN tunnel by means of a routing mechanism); in addition, there are similar methods for connecting different virtual networks within a cloud provider or cloud provider infrastructure.
[0091] Alternatively or cumulatively, in terms of connectivity, connectivity to the cloud or to a virtual network may also be achieved via dedicated connectivity: this is the preferred option when applications have stringent performance requirements or when traffic (even in encrypted form) is not expected to run over the Internet.
[0092] Therefore, it is possible to connect to a virtual network via VPN, via the Internet, via private connectivity, and also using both methods simultaneously (e.g., for redundancy and / or cost-effective load balancing); an alternative between these two solutions is to reach the cloud service provider or virtual network via a private peering point instead of via the Internet, allowing VPN endpoints to be reached as reliably as via the Internet.
[0093] in this regard, Figure 3 The illustration schematically and exemplaryly depicts different connection or connectivity possibilities for various user equipment UE1, UE2, UE3, and UE4 (which are part of or connected to the telecommunications network 100), and potentially linked to (or providing connectivity to) a first virtual network 251 or a second virtual network 252 of the cloud provider infrastructure 200 via a VPN endpoint 201 or a direct connection endpoint 202 of the cloud provider infrastructure 200.
[0094] In currently known telecommunications networks, user equipment UE1, UE2, UE3, and UE4 (e.g., mobile devices, but this also applies to fixed network devices connected via 3GPP-based systems) can request (and be provided with) connectivity to a given DNN 161, 162, and 163 via a PDU session establishment (request). For example, UE1 may need connectivity to a first virtual network 251; UE2 may need access to a second virtual network 252; UE3 may need low latency and access to the second virtual network 252; and UE4 may need low latency and access to the enterprise's corporate network (local network) as well as the first virtual network 251. To achieve this connectivity scenario, the network can be configured such that: a first data network name 161 is configured to provide access to the Internet; a second data network name 162 is configured to provide direct access to a second virtual network 252; a third data network name 163 is configured to provide connectivity to a local network; a default (network) slice providing connectivity to the first data network name 161 and the second data network name 162 is enabled for UE1 and UE2; additionally, priority-ordered (network) slices (e.g., reserved RAN resources) providing connectivity to the first data network name 161, the second data network name 162, and the third data network name 163 are enabled for UE3 and UE4; each of the UEs is configured to request the appropriate (each) PDU session for the slice / DNN pair providing access to the correct data network name (i.e., corresponding to the exemplary scenario described above). In the case of the first data network name 161, the application (on the corresponding user equipment) will then have to additionally launch a VPN client with appropriate (re)configuration on top of the PDU session to enable the establishment of a connection to the cloud provider's virtual networks 251, 252. Therefore, such connectivity scenarios could be implemented in conventionally known telecommunications networks; however, keeping track of all those (potentially changed) configurations can be quite complex.
[0095] As described above, according to the present invention, it is advantageous that user equipment can use target network identifier information to request connectivity to a specific network resource or resource provider (i.e., to another network accessible from within a cloud provider's infrastructure), which is the opposite of the paradigm in conventional known telecommunications networks where connectivity must be requested in combination with a data network name (DNN) and / or network slice.
[0096] Therefore, also according to the present invention, user equipment 20 connects to telecommunications network 100 and, simultaneously with being connected, requests to connect to or access another network 250 – that is, a virtual network that is part of cloud provider infrastructure 200 and can access from within cloud provider infrastructure 200 using its target network identifier information 251. Hereinafter, the other network 250 is also referred to as virtual network 250. Also according to the present invention, it is assumed that in order for user equipment 20 to use or access the other network 250, a data network and associated data network name need to be provided or established at telecommunications network 100 or between telecommunications network 100 and cloud provider infrastructure 200; however, such data network name does not necessarily need to be instantiated (or exist) before or at the time of the user equipment 20's connectivity request. According to the present invention, the steps required to provide user equipment 20 with connectivity to the other network 250 include…
[0097] User equipment 20 uses target network identifier information 251 to request the establishment of a communication session to or toward another network 250. The network identifier information 251 is part of a request message transmitted by user equipment 20 to control plane function 130 of telecommunications network 100.
[0098] -- A communication session is associated with a data network name so that the data network name can be used by the cloud provider infrastructure 200 to provide connectivity to another network 250.
[0099] -- User equipment 20 receives a communication session establishment and acceptance message transmitted by the control plane function 130 of the telecommunications network 100, and
[0100] -- User equipment 20 uses the established communication session via user plane function 140 of telecommunications network 100 to access another network 250.
[0101] Therefore, according to the present invention, user equipment 20 does not necessarily need to transmit a data network (name) identifier or corresponding information as part of its request to establish a communication session. User equipment 20 can subsequently establish communication with cloud provider infrastructure 200 via this communication session, and user equipment 20 does not need to store addressing information of control plane and / or user plane elements of cloud provider infrastructure 200. Therefore, according to the present invention, the complexity of providing connectivity to another network 250 or providing access to another network 250 to user equipment 20 can be reduced: user equipment 20 only needs to know the network it wants to connect to (i.e., target network identifier information), indicate it to telecommunications network 100, and the rest is handled by that telecommunications network. That is, user equipment 20 does not need to know any information related to the underlying data network (name), underlying slice (identifier), and / or any other parameters (such as quality of service) used to provide connectivity between telecommunications network 100 and cloud provider infrastructure 200 to reach another network 250. Therefore, user equipment 20 (or application 21 that triggers user equipment 20 (running or executing on user equipment 20)) triggers the establishment of a communication session (particularly packet data unit session establishment) targeting another network 250 that is not directly accessible (via the telecommunications network 100 to which user equipment 20 is attached); user equipment 20 only needs to know the target network identifier information, i.e., the virtual network to be connected – and does not need to know how to achieve such connectivity. According to the invention, this is achieved by user equipment 20 including the virtual network identifier (i.e., target network identifier information 251) in the communication session establishment request (typically a PDU session establishment request). Based on subscriber and / or policy data associated with User Equipment 20 (e.g., whether User Equipment 20 is permitted to obtain the connectivity, what quality of service level will be applied, or whether User Equipment 20 is permitted to achieve the connectivity via which network slice), the telecommunications network 100 to which User Equipment 20 is connected associates a communication session (or PDU session) with an existing Data Network Name (DNN) and / or Network Slice (S-NSSAI), through which this information is available, or the telecommunications network provides connectivity to a corresponding additional network. User Equipment 20 then receives a communication session acceptance message and can transmit and / or receive data as normally does via a communication (PDU) session, except that in this case, connectivity is typically not (or not necessarily) requested from the DNN / S-NSSAI, but rather from another network 250, which is a virtual network.
[0102] According to a first variation of the invention, connectivity (to the core network 120 or a portion thereof) to the virtual network 250 already exists (when the user equipment 20 requests a connection), while according to a second variation of the invention, connectivity to the virtual network 250 does not yet exist, i.e., it needs to be established (when the user equipment 20 requests a connection).
[0103] Figure 4 and Figure 5 This relates to a first variation of the invention. Figure 4 The diagram schematically illustrates an example of a user equipment 20 (via access network 110 and core network 120 of telecommunications network 100) connecting to a virtual network 250 (as part of cloud provider infrastructure 200), wherein a connection (to the core network 120 or a portion thereof) to the virtual network 250 already exists: the user equipment 20 requests the establishment of a communication session to obtain connectivity to the other network 250 by means of a request message including (in particular, replacing DNN / S-NSSAI information) the target network identifier information 251 of the virtual network 250. Specifically, the requested target network identifier information 251 of the virtual network 250 has been mapped by the core network 120 to a data network (name) (and / or mapped to S-NSSAI), which is configured to provide access to the specific requested (pre-configured) virtual network 250; for example, traffic from the user equipment 20 is directed to Classless Inter-Domain Routing (CIDR) 10.0.0.0 / 8. The corresponding data network is connected, for example, via interface X, and the virtual network router interface is connected via interface Y. The routing table is typically configured, for example, via Border Gateway Protocol (BGP) to route traffic to 10.0.0.0 / 8 via interface Y. On the cloud provider infrastructure 200 side, incoming traffic (at interface Y) is routed to the virtual network within cloud provider infrastructure 200 based on the configured routing table (incoming interface, destination CIDR). (Other virtual networks may use the same (or overlapping) CIDRs, but such virtual networks will use other interfaces.)
[0104] Therefore, in cases where connectivity from telecommunications network 100 to virtual network 250 already exists, when a request including a virtual network identifier (or target network identifier information 251) is received (from user equipment 20), core network 120 maps the target user plane connectivity to the given existing connectivity, i.e., the data network (name). That is, using the virtual network identifier (target network identifier information 251) (as part of a connectivity request transmitted by user equipment 20) also results in – just as user equipment 20 (and any other user equipment requiring connectivity to another network 250) being configured to map connectivity requests toward another network 250 to requests for a given DNN or DNN / S-NSSAI pair – user equipment 20 connecting to (or obtaining) connectivity to another network 250 without requiring specific mappings configured and maintained on user equipment 20 requiring connectivity to another network 250. Whether to use specific user plane functions (UPF) / session management functions (SMF) (e.g., reserved for a given slice ID, S-NSSAI) can also be handled by the core network 120. That is, user equipment 20 can be assigned higher QoS network functions based on the mapping configured in the core network 120 and / or based on subscription information associated with user equipment 20 or credentials used by user equipment 20.
[0105] exist Figure 4 In the example, virtual network 250 (or another network 250) uses a 10.0.0.0 / 8 CIDR, which can be routed to the configured virtual network 250 by routers on the core network 120 and the cloud provider side. While other virtual networks (as part of cloud provider infrastructure 200) can (and most likely do) use the exact same CIDR, the combination of the input interface (i.e., interfaces X and / or Y) and the CIDR is unique, thus traffic can be routed by a specific link (e.g., via VLAN) between the telecommunications network 100 on one side and the cloud provider infrastructure 200 on the other. The cloud provider (i.e., cloud provider infrastructure 200) uses similar means to route traffic to the correct virtual network 250.
[0106] exist Figure 5The diagram schematically illustrates the communication graph between User Equipment 20, Control Plane Function 130 of Telecommunication Network 100 (or its Core Network 120), User Plane Function 140 of Telecommunication Network 100 (or its Core Network 120), and Cloud Provider Infrastructure 200, particularly regarding user plane data flow, when connectivity to Virtual Network 250 already exists. For example, connectivity from Core Network 120 or its components to Virtual Network 250 already exists due to pre-configured routing connections, where traffic from a given router interface can be directly routed to an IP range within Virtual Network 250 – subsequently, Core Network 120 does not need to establish new connectivity to Virtual Network 250.
[0107] In the first processing step 301, the user equipment requests a PDU session from another network 250 (or virtual network 250). In the second processing step 302, a PDU session establishment acceptance message is transmitted to the user equipment 20, which specifically includes security parameters. In the third processing step 303, data packets are sent via the user plane to an endpoint in the virtual network 250, meaning that such data packets are transmitted to the user plane function 140 within the telecommunications network 100. In the fourth processing step 304, the user plane function 140 forwards the data packets to the cloud ingress router entity or function 220 of the cloud provider infrastructure 200. In the fifth processing step 305, the data packets are sent via the user plane to the cloud ingress router entity or function 220, and in the sixth processing step 306, the data packets are sent to the virtual network 250.
[0108] exist Figure 6 The diagram schematically illustrates the communication between User Equipment 20, the control plane function 130 of Telecommunication Network 100 (or its core network 120), the user plane function 140 of Telecommunication Network 100 (or its core network 120), and the cloud provider infrastructure 200, particularly regarding user plane data flow, when connectivity to the virtual network 250 is not yet established (i.e., needs to be established). The availability of connectivity to the virtual network 250 also ensures end-to-end (E2E) security. Subscribers may not expect the information exchanged between User Equipment 20 and the virtual network 250 to be visible and / or modifiable, and therefore may expect encryption and / or data protection.
[0109] For this description, it is advantageous to separate network functions into control plane (signaling) functions and user plane (data traffic) functions. In the first processing step 311, the PDU session establishment request (transmitted by user equipment 20) is received by the control plane function 130 of the core network 120. In a 5G network, the SM (Session Management) NAS (Non-Access Layer) container sent by user equipment 20 via the Access and Mobility Management Function (AMF) is transparently forwarded by the access network 110 to the Access and Mobility Management Function via the NG-AP interface. This message triggers a connectivity request from the virtual network 250 to the control plane (cloud controller entity or function 210) of the cloud provider (hereinafter also referred to as the "cloud controller") (see [link]). Figure 6 In the second processing step 312, the following information is considered in the connectivity request: the virtual network identifier (i.e., target network identifier information 251), the endpoint address of the user plane function (which would be the user plane function in a 5G network) that the cloud provider can send user plane (data packets) to; and information about the user equipment 20 requesting connectivity. In the third processing step 313, the cloud controller 210 sends back: the endpoint to which the user plane function can send traffic; and additional security parameters, such as encryption and integrity protection, that the user equipment 20 can use to set for data protection of data sent via the network to the virtual network 250. In the fourth processing step 314, the user equipment 20 receives the PDU session acceptance message and any additional parameters. In the fifth processing step 315, security negotiation can be established between the user equipment 20 and the cloud controller 210; existing means can be reused here. In the sixth processing step 316, user equipment 20 can then protect data packets according to any negotiated parameters, such as encrypting the data packets to make their content invisible to telecommunications network 100, or adding checksums / signatures to make them unmodifiable. In the seventh processing step 317, the data packets are sent via the user plane to the endpoints in virtual network 250, i.e., to user plane function 140. In the eighth and ninth processing steps 318 and 319, user plane function 140 forwards the packets to the ingress router 220 of cloud provider infrastructure 200 according to the endpoints negotiated in the second and third processing steps 312 and 313. The packets are then received by the ingress router 220, and in the tenth processing step 320, the ingress router 220 then forwards the data packets to the remote endpoints in virtual network 250.
[0110] According to the invention, in order to assist telecommunications network 100 in mapping target network identifier information 251 (or virtual network identifier) to a given cloud provider (i.e., cloud provider infrastructure 200), it is particularly preferred that the virtual network identifier be configured to also include a provider identifier, which the network can then map to the given cloud provider / cloud controller. The structure of the target network identifier information 251 (or Vnet identifier) then also includes an indication of the cloud provider. While virtual networks within a cloud provider (or cloud provider infrastructure 200) are typically (uniquely, and therefore sufficiently in principle) identified by a Universally Unique Identifier (UUID), it may also be advantageous to allow user equipment 20 to further indicate which provider the UUID (i.e., target network identifier information 251) belongs to. This can be achieved by having the user equipment 20 indicate a cloud provider identifier (such as a string, identifier, or UUID) or by using a virtual network identifier (target network identifier information 251) that includes the cloud provider identifier; examples of such implementations include, for example: provider-name-00112233-4455-6677-c899-aabbccddeeff (based on string); 0001-00112233-4455-6677-c899-aabbccddeeff (based on identifier).
Claims
1. A method for using user equipment (20) with a telecommunications network (100), wherein the user equipment (20) requests connection to or access to an additional network (250) when connected to the telecommunications network (100), wherein the telecommunications network (100) includes control plane functions (130) and user plane functions (140), wherein the additional network (250) is a virtual network as part of a cloud provider infrastructure (200). The additional network (250) can use target network identifier information (251) to access from within the cloud provider infrastructure (200). in, In order for the user equipment (20) to use or access the additional network (250), a data network and associated data network name need to be configured or established at the telecommunications network (100) or between the telecommunications network (100) and the cloud provider infrastructure (200). In order to enable the user equipment (20) to connect to or access the additional network (250), the method includes the following steps: -- In the first step, the user equipment (20) uses the target network identifier information (251) to request the establishment of a communication session to or toward the other network (250), the target network identifier information (251) being part of a request message from the user equipment (20) to the control plane function (130) of the telecommunications network (100). -- In the second step, the communication session is associated with the data network and / or data network name in order to provide connectivity to the additional network (250) via the cloud provider infrastructure (200) using the data network. -- In the third step, the user equipment (20) receives a communication session establishment acceptance message transmitted by the control plane function (130) of the telecommunications network (100). -- In the fourth step, the user equipment (20) uses the established communication session via the user plane function (140) of the telecommunications network (100) to access the other network (250).
2. The method of claim 1, wherein the additional network (250) may use the target network identifier information (251) to access only from within the cloud provider infrastructure (200).
3. The method of claim 1, wherein the additional network (250) is not directly accessible from outside the cloud provider infrastructure (200).
4. The method according to any of the preceding claims, wherein the communication session is or corresponds to a Protocol Data Unit (PDU) session, and / or wherein the control plane function (130) is or corresponds to a session management function or a session management function instance.
5. The method according to claim 1, wherein – after the data network is configured or established – the data network and the other network (250) and their target network identifier information (251) are mutually assigned, in, The assignment is stored in a repository entity or functionality of the telecommunications network (100). Wherein, the assignment -- Executed before the first step, or -- After the first step.
6. The method of claim 1, wherein – after the data network is equipped or established – the data network and the other network (250) and their target network identifier information (251) are mutually assigned, wherein the assignment is stored in a repository entity or functionality of the telecommunications network (100), wherein the assignment is performed after the third step.
7. The method of claim 1, wherein the data network and the other network (250) and / or the data network name and its target network identifier information (251) are mutually assigned, wherein the assignment and the configuration or establishment of the data network are performed after the first step.
8. The method according to claim 1, wherein the data network and the other network (250) and / or the data network name and its target network identifier information (251) are mutually assigned, wherein the assignment and the configuration or establishment of the data network are performed after the third step.
9. The method according to claim 1, wherein the cloud provider infrastructure (200) includes a cloud controller entity or function (210) and / or a cloud ingress router entity or function (220), wherein, Equipping or establishing the data network and / or assigning or associating the data network, the other network (250) and their target network identifier information (251) involves the telecommunications network (100) contacting the cloud controller entity or functionality (210) and / or the cloud ingress router entity or functionality (220).
10. The method according to claim 1, wherein the target network identifier information (251) is or corresponds to or includes the universally unique identifier (UUID) information of the other network (250).
11. The method of claim 1, wherein the target network identifier information (251) includes infrastructure identifier information that is associated with or identifies the cloud provider infrastructure (200).
12. A user equipment (20) for operation with a telecommunications network (100), wherein the user equipment (20) is configured to request connection to or access to an additional network (250) upon connection to the telecommunications network (100), the additional network (250) being a virtual network as part of a cloud provider infrastructure (200), and the additional network (250) being able to access from within the cloud provider infrastructure (200) using target network identifier information (251). in, In order for the user equipment (20) to use or access the additional network (250), a data network and associated data network name need to be configured or established at the telecommunications network (100) or between the telecommunications network (100) and the cloud provider infrastructure (200). In order for the user equipment (20) to connect to or access the additional network (250), the user equipment (20) is configured such that: -- The user equipment (20) uses the target network identifier information (251) to request the establishment of a communication session to or toward the other network (250), the target network identifier information (251) being part of a request message transmitted by the user equipment (20) to the control plane function (130) of the telecommunications network (100). -- The user equipment (20) receives a communication session establishment acceptance message transmitted by the control plane function (130) of the telecommunications network (100). -- After the communication session is associated with the data network and / or the data network name, the user equipment (20) uses the established communication session via the user plane function (140) of the telecommunications network (100) to access the other network (250) so as to provide connectivity to the other network (250) via the data network through the cloud provider infrastructure (200).
13. A system or telecommunications network (100) for use with a user equipment (20) and a telecommunications network (100), wherein the user equipment (20) requests connection to or access to an additional network (250) when connected to the telecommunications network (100), wherein the telecommunications network (100) includes control plane functions (130) and user plane functions (140), wherein the additional network (250) is a virtual network as part of a cloud provider infrastructure (200). The additional network (250) can use target network identifier information (251) to access from within the cloud provider infrastructure (200). in, In order for the user equipment (20) to use or access the additional network (250), a data network and associated data network name need to be configured or established at the telecommunications network (100) or between the telecommunications network (100) and the cloud provider infrastructure (200). In order for the user equipment (20) to connect to or access the additional network (250), the system or telecommunications network (100) is configured such that: -- The telecommunications network (100) receives a request message from the user equipment (20) regarding the establishment of a communication session to or toward the other network (250), wherein the target network identifier information (251) is part of the request message received by the control plane function (130) of the telecommunications network (100). -- The communication session is associated with the data network and / or the data network name in order to provide connectivity to the additional network (250) via the cloud provider infrastructure (200) using the data network. -- The control plane function (130) of the telecommunications network (100) transmits a communication session establishment acceptance message, and the user equipment (20) receives the communication session establishment acceptance message. -- The established communication session is used by the user equipment (20) to access the other network (250) via the user plane function (140) of the telecommunications network (100).
14. A computer program product comprising computer-readable program code, which, when executed on a computer, and / or on a user equipment (20), and / or on a network node of a telecommunications network (100), or partially on the user equipment (20), and / or partially on a network node of a telecommunications network (100), causes the computer and / or the user equipment (20) and / or the network node of the telecommunications network (100) to perform the method as described in any one of claims 1 to 11.
15. A computer-readable medium comprising instructions which, when executed on a computer, and / or on a user equipment (20), and / or on a network node of a telecommunications network (100), or partially on the user equipment (20), and / or partially on a network node of a telecommunications network (100), cause the computer and / or the user equipment (20) and / or the network node of the telecommunications network (100) to perform the method as described in any one of claims 1 to 11.
Citation Information
Patent Citations
Network identification as a service
CN107251528A
Apparatus and method for sponsored connectivity to wireless networks using application-specific network access credentials
CN107409137A