Message transmission control method, device and system
By working together with gateways and network switching devices on the network side, the network security problem when a personal mobile terminal is simultaneously connected to the Internet and the enterprise network is solved by blocking or allowing UE access to the Internet packets. This achieves time-sharing access control for UEs and ensures the security of the enterprise network.
Patent Information
- Application Number
- CN202410572085.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-09
- Publication Date
- 2025-11-11
Smart Images

Figure CN120935565A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a control method, apparatus and system for message transmission. Background Technology
[0002] Currently, in most cases, personal mobile terminals are mainly used to access services deployed on the Internet through telecommunications operator networks, such as audio and video services, social entertainment services, e-commerce services, and online shopping services.
[0003] With the advancement of mobile communication technologies used by telecommunications operators for business purposes (such as fifth-generation mobile communication technology, 5G, or 5GtoB for business), personal mobile terminals can access enterprise networks (such as government and enterprise private networks, campus intranets, etc.) through the operator's 5G network after subscribing to the operator's 5GtoB value-added services.
[0004] However, while 5GtoB brings convenience, it also presents certain security risks. For example, when a personal mobile terminal is simultaneously connected to the internet and an enterprise network, the personal mobile terminal could become a springboard for attackers to launch attacks on the enterprise network via the internet. Therefore, ensuring the network security of the enterprise network is a pressing technical issue that needs to be addressed when personal mobile terminals can connect to the internet and access the enterprise network through 5GtoB value-added services. Summary of the Invention
[0005] This application provides a method, apparatus, and system for controlling message transmission. The method enables user equipment to access a first network and a second network in a time-sharing manner on the network side, thereby ensuring the network security of the first network.
[0006] The technical solution provided in this application is as follows:
[0007] Firstly, this application provides a message transmission control method applied to a gateway deployed at the edge of a first network. The method includes: acquiring an online message indicating successful authentication of a target user equipment (UE) accessing the first network; the online message including the target UE's Internet Protocol (IP) address; and the target UE accessing the first network via a mobile communication network. In response to the online message, the method allows messages whose source address is the target UE's IP address to pass through; and sends a blocking notification to a network switching device, the blocking notification including the target UE's IP address, indicating that messages whose source address is the target UE's IP address will be blocked. The network switching device is used to allow or block messages from the UE accessing a second network via the mobile communication network.
[0008] The method provided in this application enables a network switching device to block a target UE's access to a second network while the target UE is accessing a first network. This allows for time-sharing control of the target UE's access to both networks from the network side, thereby ensuring the network security of the first network. For example, when the first network is an enterprise network and the second network is the Internet, the method provided in this application can block the target UE's access to the Internet while it is accessing the enterprise network, thus enabling time-sharing control of the UE's access to both the enterprise network and the Internet from the network side, thereby ensuring the network security of the enterprise network.
[0009] In one possible design, obtaining the online message includes: receiving an authentication request sent by a network device in a mobile communication network, the authentication request including the UE identifier of the target UE, the authentication request being used to request authentication of the target UE's permission to access the first network; forwarding the authentication request to the authentication system of the first network; and receiving the online message returned by the authentication system.
[0010] This possible design enables the gateway of the first network to receive the online message of the target UE from the authentication system after the authentication system of the first network successfully authenticates the target UE's access to the first network.
[0011] In another possible design, when the IP address of the target UE is the IP address assigned to the target UE by the mobile communication network, the above authentication request also includes the IP address assigned to the target UE by the mobile communication network.
[0012] In another possible design, when the IP address of the target UE is the IP address assigned to the target UE by the authentication system, the above method further includes: returning the IP address assigned to the target UE by the authentication system to the network device.
[0013] With the above two possible designs, the address for the target UE to access the first network can be assigned by the mobile communication network or the authentication system of the first network, demonstrating the flexibility of the solution.
[0014] In another possible design, the online message and / or blocking notification mentioned above also include the UE identifier of the target UE, which is used to trace and count the messages sent by the target UE.
[0015] With this possible design, even if the IP address used by the target UE changes during the process of accessing the first network or the second network, the gateway of the first network or the network switch that receives the blocking notification can still accurately count the packets sent by the target UE through the UE identifier of the target UE.
[0016] In another possible design approach, sending a blocking notification to the network switching device includes sending a blocking notification to the network switching device based on a system log (Syslog) protocol or a proprietary protocol.
[0017] In another possible design, sending a blocking notification to the network switching device includes: sending a blocking notification to the network switching device via a mobile communication network; or sending a blocking notification to the network switching device via a dedicated communication link between the network switching device and the gateway of the first network.
[0018] The above two possible designs enable the proposed solution to be flexibly implemented and easy to put into practice.
[0019] In another possible design, the above method further includes: determining that the target UE stops accessing the first network; sending a release notification to the network switching device, the release notification including the IP address of the target UE, the release notification being used to indicate that the source address of the packet is an IP address.
[0020] This design enables the target UE to access the second network only after it has stopped accessing the first network. This allows for time-sharing access to both networks by the target UE from the network side. For example, when the first network is an enterprise network and the second network is the internet, the method provided in this application allows the target UE to access the internet only after it has stopped accessing the enterprise network. This enables time-sharing access to both the enterprise network and the internet by the network side, thus ensuring network security for the enterprise network.
[0021] In another possible design, the aforementioned UE identifier is any one of the International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), or Mobile Subscriber Integrated Services Digital Network Number (MSISDN).
[0022] In another possible design, the mobile communication network is a fifth-generation mobile communication technology (5G) network.
[0023] In another possible design, the first network is an enterprise network, and the second network is the Internet.
[0024] Through the above-mentioned possible designs, the proposed solution can be combined with existing technologies and is easy to implement.
[0025] Secondly, this application provides a message transmission control method. This method is applied to a network switching device, which allows or blocks messages from a UE accessing a second network via a mobile communication network. The UE also accesses a first network via the mobile communication network. The method includes: receiving a blocking notification sent by the gateway of the first network, the blocking notification including the IP address of the target UE; and, in response to the blocking notification, blocking messages destined for the second network whose source address is the IP address of the target UE. The blocking notification received by the network switching device is sent by the gateway of the first network when it receives an online message indicating successful authentication for the target UE's access to the first network.
[0026] In one possible design, receiving the blocking notification sent by the gateway of the first network includes: receiving the blocking notification sent by the gateway of the first network based on the Syslog protocol or a proprietary protocol.
[0027] In another possible design, receiving the blocking notification sent by the gateway of the first network includes: receiving the blocking notification sent by the gateway of the first network through the mobile communication network; or receiving the blocking notification sent by the gateway of the first network through a dedicated communication link between the network switching device and the gateway.
[0028] In another possible design, the aforementioned blocking notification also includes the UE identifier of the target UE, which is used to trace and statistically analyze the messages sent by the target UE.
[0029] In another possible design, the above method further includes: receiving a clearance notification sent by the gateway of the first network, the clearance notification including the IP address of the target UE; and in response to the clearance notification, allowing a packet destined for the second network whose source address is the IP address of the target UE to be sent.
[0030] In another possible design, the UE identifier included in the aforementioned blocking notification is any one of IMSI, IMEI, or MSISDN.
[0031] In another possible design approach, the mobile communication network is a 5G network.
[0032] In another possible design, the first network is an enterprise network, and the second network is the Internet.
[0033] In another possible design approach, the network switching device is deployed as a stand-alone device at the boundary between the mobile communication network and the second network.
[0034] In another possible design, the network switch is deployed in the core network of the mobile communication network, and the network switch communicates with the first network via a first user plane function (UPF) device in the core network, and the network switch also communicates with the second network via a second UPF device in the core network; or, the network switch is deployed in the second UPF device.
[0035] It is understood that the beneficial effects achieved by the methods provided by the second aspect and any possible design method in the second aspect can be referred to the technical effects of the corresponding solutions provided by the first aspect and any possible design method in the first aspect, and will not be repeated here.
[0036] Thirdly, this application provides a message transmission control device applied to a gateway deployed at the edge of a first network. The device includes: an acquisition unit for acquiring an online message indicating successful authentication of a target UE's access to the first network; the online message including the IP address of the target UE, indicating that the target UE accesses the first network via a mobile communication network; a processing unit for allowing messages whose source address is the IP address of the target UE in response to the online message; and a sending unit for sending a blocking notification to a network switching device in response to the online message; the blocking notification including the IP address of the target UE, indicating that messages whose source address is the IP address of the target UE are to be blocked. The network switching device is used to allow or block messages from the UE accessing a second network via the mobile communication network.
[0037] In one possible design, the apparatus further includes: a receiving unit, configured to receive an authentication request sent by a network device in a mobile communication network, the authentication request including a UE identifier of a target UE, the authentication request being used to request authentication of the target UE's permission to access a first network; a sending unit, further configured to forward the authentication request to the authentication system of the first network; and a receiving unit, further configured to receive an online message returned by the authentication system.
[0038] In another possible design, when the IP address of the target UE is the IP address assigned to the target UE by the mobile communication network, the above authentication request also includes the IP address assigned to the target UE by the mobile communication network.
[0039] In another possible design, when the IP address of the target UE is the IP address assigned to the target UE by the authentication system, the sending unit is also used to return the IP address assigned to the target UE by the authentication system to the aforementioned network device.
[0040] In another possible design, the online message and / or blocking notification mentioned above also include the UE identifier of the target UE, which is used to trace and count the messages sent by the target UE.
[0041] In another possible design, the sending unit is specifically used to send blocking notifications to the network switching device based on the Syslog protocol or a proprietary protocol.
[0042] In another possible design, the transmitting unit is also specifically used to send a blocking notification to the network switching device via the mobile communication network; or, to send a blocking notification to the network switching device via a dedicated communication link between the network switching device and the gateway of the first network.
[0043] In another possible design, the processing unit is further configured to determine that the target UE has stopped accessing the first network. The sending unit is further configured to send a release notification to the network opening / closing device, the release notification including the IP address of the target UE, the release notification being used to indicate that packets whose source address is an IP address are allowed.
[0044] In another possible design approach, the aforementioned UE identifier is any one of IMSI, IMEI, or MSISDN.
[0045] In another possible design approach, the mobile communication network is a 5G network.
[0046] In another possible design, the first network is an enterprise network, and the second network is the Internet.
[0047] It is understood that the beneficial effects of the device provided by the third aspect and any possible design method in the third aspect can be seen from the technical effects of the corresponding solutions provided by the first aspect and any possible design method in the first aspect, and will not be repeated here.
[0048] Fourthly, this application provides a message transmission control device, which is applied to a network switching device. The network switching device is used to allow or block messages from a UE accessing a second network through a mobile communication network. The UE also accesses a first network through the mobile communication network. The device includes: a receiving unit, used to receive a blocking notification sent by the gateway of the first network, the blocking notification including the IP address of the target UE; and a processing unit, used to block messages sent to the second network whose source address is the IP address of the target UE in response to the blocking notification.
[0049] In one possible design, the receiving unit is specifically used to receive blocking notifications sent by the gateway of the first network based on the Syslog protocol or a proprietary protocol.
[0050] In another possible design, the receiving unit is also specifically used to receive a blocking notification sent by the gateway of the first network through the mobile communication network; or, to receive a blocking notification sent by the gateway of the first network through a dedicated communication link between the network switching device and the gateway.
[0051] In another possible design approach, the blocking notification also includes the UE identifier of the target UE, which is used to trace and statistically analyze the messages sent by the target UE.
[0052] In another possible design, the receiving unit is further configured to receive a clearance notification sent by the gateway of the first network, the clearance notification including the IP address of the target UE. The processing unit is further configured to, in response to the clearance notification, allow packets destined for the second network whose source address is the IP address of the target UE.
[0053] In another possible design approach, the blocking notification includes the UE identifier as any one of IMSI, IMEI, and MSISDN.
[0054] In another possible design approach, the mobile communication network is a 5G network.
[0055] In another possible design, the first network is an enterprise network, and the second network is the Internet.
[0056] In another possible design approach, the network switching device is deployed as a stand-alone device at the boundary between the mobile communication network and the second network.
[0057] In another possible design, the network switching device is deployed in the core network of the mobile communication network, and the network switching device communicates with the first network via a first UPF device in the core network, and also communicates with the second network via a second UPF device in the core network. Alternatively, the network switching device is deployed in the second UPF device.
[0058] It is understood that the beneficial effects of the device provided by the fourth aspect and any possible design method in the fourth aspect can be seen from the technical effects of the corresponding solutions provided by the second aspect and any possible design method in the second aspect, and will not be repeated here.
[0059] Fifthly, this application provides a message transmission control device, the device comprising: a memory, a network interface, and one or more processors, the one or more processors receiving or transmitting data through the network interface, the one or more processors being configured to read program instructions stored in the memory to execute the method provided by the first aspect and any possible design of the first aspect, or to execute the method provided by the second aspect and any possible design of the second aspect.
[0060] Sixthly, this application provides a message transmission control system, which includes a network switching device and a gateway of a first network. The network switching device is used to allow or block messages from a UE accessing a second network through a mobile communication network. The UE also accesses the first network through the mobile communication network. The gateway of the first network is used to obtain an online message indicating that the target UE's access permission to the first network has been successfully authenticated. The online message includes the target UE's Internet Protocol (IP) address. The gateway of the first network is also used, in response to the online message, to allow messages whose source address is the target UE's IP address and to send a blocking notification to the network switching device. The blocking notification includes the target UE's IP address. The network switching device is used to receive the blocking notification and, in response to the blocking notification, to block messages whose source address is the target UE's IP address.
[0061] In another possible design, the gateway of the first network is also used to determine that the target UE has stopped accessing the first network, and to send a permission notification to the network switching device, the permission notification including the IP address of the target UE. The network switching device is also used to receive the permission notification and, in response to the permission notification, to allow packets destined for the second network whose source address is the IP address of the target UE.
[0062] In yet another possible design, the gateway of the first network in the control system is used to perform the methods provided by the first aspect and any possible design of the first aspect, and the network switching device in the control system is used to perform the methods provided by the second aspect and any possible design of the second aspect.
[0063] In another possible design, the gateway of the first network in the control system is, for example, the message transmission control device provided by the third or fifth aspect above, and the network switching device in the control system is, for example, the message transmission control device provided by the fourth or fifth aspect above.
[0064] In a seventh aspect, this application provides a message transmission control system, which includes a network switching device and a gateway for a first network. The gateway for the first network is used to execute the method provided by the first aspect and any possible design of the first aspect, and the network switching device is used to execute the method provided by the second aspect and any possible design of the second aspect. In a specific design, the gateway for the first network is, for example, the message transmission control device provided by the third or fifth aspect described above, and the network switching device is, for example, the message transmission control device provided by the fourth or fifth aspect described above.
[0065] Eighthly, this application provides a computer-readable storage medium that is a non-volatile computer-readable storage medium, the computer-readable storage medium including computer program instructions that, when executed by a computing device or processor, enable the computing device or processor to perform the method provided by the first aspect and any possible design of the first aspect, or to perform the method provided by the second aspect and any possible design of the second aspect.
[0066] Ninthly, this application provides a computer program product comprising instructions that, when executed by a computing device or processor, cause the computing device or processor to perform the method provided by the first aspect and any possible design of the first aspect, or to perform the method provided by the second aspect and any possible design of the second aspect.
[0067] In a tenth aspect, this application provides a chip comprising a processor. When the processor executes program instructions or code, the chip comprising the processor or the device comprising the chip performs the method provided by the first aspect and any possible design scheme of the first aspect, or performs the method provided by the second aspect and any possible design scheme of the second aspect. Exemplarily, the chip further includes an input interface, an output interface, and a memory. The chip's input interface, output interface, processor, and memory are connected via internal interconnection paths within the chip. The memory in the chip stores program instructions or code executed by the processor, and the input interface and output interface are used for communication and connection between the chip and other chips or devices.
[0068] It is understood that any of the message transmission control devices, systems, computer-readable storage media, computer program products or chips provided above can be applied to the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0069] In this application, the names of the control devices, systems, etc., for the aforementioned message transmission do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those in this application, they all fall within the protection scope of this application. Attached Figure Description
[0070] Figure 1 This is a schematic diagram illustrating a mobile phone accessing the Internet and enterprise network via a mobile communication network, provided in an embodiment of this application.
[0071] Figure 2 This is a schematic diagram of an implementation environment for the method provided in the embodiments of this application;
[0072] Figure 3 This is a schematic diagram of another implementation environment of the method provided in the embodiments of this application;
[0073] Figure 4 This is a schematic diagram of another implementation environment of the method provided in the embodiments of this application;
[0074] Figure 5 This is a schematic diagram of another implementation environment of the method provided in the embodiments of this application;
[0075] Figure 6 This is a schematic diagram of another implementation environment of the method provided in the embodiments of this application;
[0076] Figure 7 This is a schematic diagram illustrating the process of authenticating the access rights of a target UE to a first network, as provided in an embodiment of this application.
[0077] Figure 8 This is a schematic diagram illustrating another process for authenticating the access rights of a target UE to a first network, provided in an embodiment of this application.
[0078] Figure 9 This is a flowchart illustrating a message transmission control method provided in an embodiment of this application;
[0079] Figure 10 This is a schematic diagram of a newly created Syslog log template provided in an embodiment of this application;
[0080] Figure 11 This is a flowchart illustrating another message transmission control method provided in an embodiment of this application;
[0081] Figure 12 This is another flowchart illustrating the message transmission control method provided in the embodiments of this application;
[0082] Figure 13 This is a schematic diagram of the structure of a message transmission control device provided in an embodiment of this application;
[0083] Figure 14 This is a schematic diagram of the structure of another message transmission control device provided in the embodiments of this application;
[0084] Figure 15 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application. Detailed Implementation
[0085] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0086] To facilitate understanding, the technologies and background involved in the embodiments of this application will be explained below.
[0087] 1) Mobile communication network
[0088] Mobile communication networks, through the use of mobile communication technologies, enable communication between user equipment (UEs) and allow UEs to access the internet. UEs are also known as terminal equipment or mobile stations (MS).
[0089] The network architecture of a mobile communication network mainly includes the access network, the bearer network (or transmission network), and the core network (CN). The access network refers to the radio access network (RAN), which implements radio access technology and is primarily used to connect the user (UE) to the mobile communication network. For example, the RAN transmits and receives the UE's radio signals through base stations. The bearer network transmits the UE data received by the access network to the core network via a wired network (such as a fiber optic network); essentially, the bearer network acts as a bridge between the access network and the core network. The core network is the collection of the most critical equipment in the mobile communication network, typically deployed in the operator's equipment room, and primarily provides internet access services and related management functions for the UE.
[0090] After several generations of evolution, the latest mobile communication network currently in use is the 5G network, which uses fifth-generation mobile communication technology (5G).
[0091] 2) Session management function (SMF) and user plane function (UPF)
[0092] Both SMF and UPF are components of the 5G core network.
[0093] The SMF (Service Provider Function) is primarily responsible for managing user sessions. In the architecture of 5G networks, the SMF is responsible for tunnel maintenance, Internet Protocol (IP) address allocation and management, user plane (UP) function selection, policy enforcement, quality of service (QoS) control, billing data collection, roaming, and more. The SMF can also select and control user plane functions (UPFs), configure UPF traffic and routing, and forward traffic to appropriate destination networks.
[0094] UPF is the unit responsible for processing user data packets in the 5G core network.
[0095] Currently, UEs (such as personal mobile phones) primarily use operator networks to access internet resources, such as audio and video resources, or for social entertainment, e-commerce, or online shopping. However, with the advancement of 5G for business (5G to business, 5G to B), UEs can also access enterprise networks (such as private networks or intranets) by subscribing to operator 5G to B packages, enabling them to conduct communication, meetings, and mobile office work. (Reference) Figure 1 , Figure 1 This diagram illustrates how a mobile phone accesses the internet and enterprise networks via a mobile communication network. (For example...) Figure 1 As shown, mobile phone 100 can access the Internet through the mobile communication network provided by the operator, and mobile phone 100 can also access the enterprise network through the mobile communication network provided by the operator.
[0096] In related technologies, a traffic splitting mechanism can be used in mobile communication networks to distinguish between enterprise services and internet services of the UE. For example, by applying a traffic splitting mechanism on the UPF in the 5G core network, packets carrying enterprise services are sent to the enterprise network, while packets carrying internet services are sent to the internet. However, this technology only splits the traffic for packets accessing the internet and the enterprise network, without implementing time-sharing isolation for these accesses. This can lead to situations where a UE accesses both the internet and the enterprise network simultaneously, creating security vulnerabilities in the enterprise network. For instance, if a mobile phone is connected to both the internet and the enterprise network at the same time, an attack source on the internet could use the phone as a springboard to launch a network attack on the enterprise network.
[0097] In one related technology, the UE (User Equipment) switches between different network domains by installing client software of a security system. The security system can be configured with multiple network domains and achieve isolation between them. Taking a security system configured with an Internet domain and an enterprise network domain as an example, after the UE installs the client software of this security system, it accesses the Internet by default through the client software. When the UE needs to access the enterprise network, the user switches the network access mode from Internet access mode to enterprise network access mode by operating the client software on the UE. This blocks or intercepts packets carrying the UE's Internet services, preventing the UE from accessing the Internet. Correspondingly, in this case, the UE can use an encrypted tunnel to access the enterprise network. It can be seen that in this technology, the UE can only access a single network domain at a time. For example, when the user selects the enterprise network access mode, the UE can only access applications published within the enterprise network and cannot access applications on other networks, and is prohibited from accessing the Internet. This effectively prevents the UE from being used as a springboard for attacks against the enterprise network. However, in this technology, the UE needs to install the client software of the security system, and the client software obtains higher privileges on the UE system to switch network domains. Mobile terminal operating systems (such as mobile phones) are typically hardened and packaged, thus not supporting system privileges for secondary development. Furthermore, mobile terminal operating systems are frequently updated; any upgrade or iteration of the operating system can render installed client software unusable. In other words, this technology is only suitable for personal computers (PCs), not mobile terminals like mobile phones. Moreover, this technology requires users to manually operate the client software to switch network domains, resulting in poor usability.
[0098] Another related technology, targeting mobile terminals such as mobile phones, allows users to switch between different network modes by manually changing the data network name (DNN) or access point name (APN) on the phone. However, manually switching the DNN or APN is not very user-friendly.
[0099] Based on this, embodiments of this application provide a message transmission control method. This method applies an online / offline mechanism to the UE when it accesses a first network via a mobile communication network. Specifically, it blocks messages from the UE accessing a second network when the UE is online and accessing the first network, and allows messages from the UE accessing the second network when the UE stops accessing the first network (i.e., goes offline). This achieves time-sharing control of the UE's access to the first and second networks on the network side, thereby ensuring the network security of the first network.
[0100] For example, mobile communication networks include, but are not limited to, 5G networks, 4G networks using fourth-generation mobile communication technology (4G), LTE networks using long term evolution (LTE) technology, and 3G networks using third-generation mobile communication technology (3G).
[0101] In this embodiment, the first network imposes access restrictions on the UE, while the second network does not. For example, the first network may include, but is not limited to, a campus network, a data center network, an enterprise intranet, a private enterprise network, or a campus network, while the second network is the Internet. Optionally, the first network imposes access restrictions on UEs capable of accessing the second network to limit their access to the first network; that is, among the UEs capable of accessing the second network, only target UEs with authorized access rights can access the first network. For example, the first network may be a dedicated network of an enterprise data center, and the second network may be the network of the enterprise's campus.
[0102] refer to Figure 2 , Figure 2 A schematic diagram of an implementation environment for the method provided in this application is shown. Figure 2As shown, the implementation environment includes a mobile communication network, a first network, and a second network. UEs 1 through UE n (where n is an integer greater than 1) can access the first network through the mobile communication network, and a gateway is deployed at the edge of the first network. Optionally, this gateway is a gateway with network security protection functions, for example, a firewall is installed in the gateway. Furthermore, UEs 1 through UE n can also access the second network through the mobile communication network.
[0103] In this embodiment of the application, a network switching device is provided for the second network. This device is used to allow or block messages from the UE accessing the second network through the mobile communication network. In one example, such as... Figure 2 As shown, the network switching device is deployed at the boundary between the mobile communication network and the second network. In this case, for example, the network switching device is a router or gateway located at the boundary between the mobile communication network and the second network, or a functional module within that router or gateway; this is not limited. When the network switching device and the gateway of the first network execute the method provided in this application embodiment, it is possible to control the UE to access the first and second networks in a time-sharing manner on the network side, thereby ensuring the network security of the first network.
[0104] In this embodiment, because the first network imposes access restrictions on the UE, when the UE accesses the first network through the mobile communication network, the mobile communication network needs to authenticate the UE's access permission to the first network with the first network's authentication system. Combined with... Figure 2 ,refer to Figure 3 , Figure 3 A schematic diagram of another implementation environment for the method provided in this application is shown. Figure 3 As shown, the mobile communication network includes a network device 300. Upon receiving a message from any UE (e.g., UE 1) requesting access to the first network, the network device 300 initiates authentication of the UE's access permission to the first network through the authentication system of the first network (not shown in the figure). Therefore, after successful authentication by the authentication system of the first network, the method provided in this embodiment is executed through the gateway of the first network and the aforementioned network switching device. This enables time-sharing access of UE 1 to the first and second networks on the network side, thereby ensuring the network security of the first network.
[0105] Optionally, the authentication system of the first network may be, for example, an authentication, authorization, and accounting (AAA) system, abbreviated as 3A system. In one example, the 3A system is implemented as a 3A server. In another example, the authentication system of the first network is deployed internally or externally to the first network. In yet another example, the authentication system of the first network is deployed at the gateway of the first network.
[0106] In some embodiments, when Figure 3 When the mobile communication network shown is a 5G network, optionally, Figure 3 The network device shown is an SMF device in the 5G core network. In this case, combined with... Figure 3 ,refer to Figure 4 , Figure 4 A schematic diagram of yet another implementation environment of the method provided in this application is shown. For example... Figure 4 As shown, the mobile communication network also includes a first UPF device and a second UPF device. The SMF device communicates with the first network via the first UPF device and with the second network via the second UPF device. It can be understood that when the first network is an enterprise network, it indicates that the first network is a commercial network, therefore the first UPF device is also called a business-oriented UPF (to-business UPF). When the second network is the Internet, it indicates that the second network is mainly used to serve consumers, therefore the second UPF device is called a consumer-oriented UPF (to-consumer UPF).
[0107] exist Figure 4 In the implementation environment shown, as an example, such as Figure 4 As shown in (a) of this application embodiment, the network switching device provided is deployed as a standalone device at the boundary between the mobile communication network and the second network. As another example, such as... Figure 4 As shown in (b) of this application embodiment, the network switching device is deployed as a functional module in the second UPF device. This is not a limitation.
[0108] In other embodiments, when the second network is the Internet, the mobile communication network configures a corresponding UPF device for each region's Internet, for different geographical areas (e.g., different cities). In this case, combined with Figure 4 ,refer to Figure 5 , Figure 5 A schematic diagram of yet another implementation environment of the method provided in this application is shown. For example... Figure 5 As shown, a UPF device A is configured for the second network of city A, and a UPF device B is configured for the second network of city B. In this case, the embodiment of this application configures a network switching device A for the second network of city A, and a network switching device B for the second network of city B.
[0109] In one example, such as Figure 5 As shown in (a), network switching device A is deployed as a standalone device at the boundary between the mobile communication network and the second network of city A, and network switching device B is deployed as a standalone device at the boundary between the mobile communication network and the second network of city B. In another example, such as... Figure 5 As shown in (b), network switching device A is deployed as a functional module in UPF device A, and network switching device B is deployed as a functional module in UPF device B.
[0110] In some other embodiments, combined with Figure 4 ,refer to Figure 6 , Figure 6 A schematic diagram of yet another implementation environment of the method provided in this application is shown. For example... Figure 6 As shown, the mobile communication network also includes a main UPF device, which is located between the SMF device and the first UPF device and communicates with the first network through the first UPF device. The main UPF device is also located between the SMF device and the second UPF device and communicates with the second network through the second UPF device.
[0111] It should be understood that the primary UPF device is typically deployed closer to the control plane of the mobile communication network, such as at the center of the mobile communication network. The first and second UPF devices can be considered as auxiliary UPF devices or offloading UPF devices. Typically, auxiliary UPF devices are deployed closer to the service network (such as the Internet or enterprise network), for example, at the edge of the metropolitan area network where the service network is located, but this is not limited to these locations.
[0112] It should also be understood that when a primary UPF device is included in a mobile communication network, in one example, such as Figure 6 As shown in (a) of this application embodiment, the network switching device provided is deployed as a standalone device at the boundary between the mobile communication network and the second network. In another example, such as... Figure 6 As shown in (b) of this embodiment, the network switching device provided in this application is deployed as an independent device between the main UPF device and the second UPF device. In another example, as... Figure 6 As shown in (c) of this application embodiment, the network switching device provided is deployed as a functional module in the second UPF device. In another example, as... Figure 6 As shown in (d) of this application embodiment, the network switching device is deployed as a functional module in the main UPF device.
[0113] It should be understood that the above content is an exemplary description of the implementation environment of the method provided in the embodiments of this application, and does not constitute a limitation on the implementation environment of the method. As those skilled in the art know, as business needs change, the implementation environment can be adjusted according to application requirements, and the embodiments of this application do not list them one by one.
[0114] This application also provides a message transmission control system, which includes... Figures 2-6The network switching device and gateway in the implementation environment shown can, when the network switching device and gateway in the system execute the corresponding steps in the method described below, enable the UE to access the first network and the second network in a time-sharing manner on the network side, so as to ensure the network security of the first network.
[0115] This application also provides a message transmission control device, which is used to execute the method provided in this application to control the UE to access the first network and the second network in a time-sharing manner on the network side, thereby ensuring the network security of the first network.
[0116] In one example, the control device is, for example, the network switching device described above, or a functional module within a network switching device, and is used to perform the corresponding steps in the method described below that are performed by the network switching device. In another example, the control device is applied to the gateway of the first network described above, and, as a functional module within the gateway, performs the corresponding steps in the method described below that are performed by the gateway of the first network.
[0117] Optionally, the aforementioned control device can be any computing device with computing processing capabilities, or a functional module within a computing device; there is no limitation in this regard. For example, the computing device may be implemented as a network device such as a network switch, gateway, or UPF device as described above. As another example, the computing device may be a general-purpose computer, laptop computer, or other computing device; there is no limitation in this regard.
[0118] The implementation process of the message transmission control method provided in the embodiments of this application will be described below.
[0119] In the embodiments of this application, combined with Figures 2-6 In the implementation environment shown, the UE accesses the second network by default. Taking a mobile phone as the UE and the internet as the second network, once the subscriber identity module (SIM) installed in the mobile phone is activated and the SIM card user has purchased network services (or data packages), the mobile phone can access the second network. When the user needs to access the first network, the UE's access permissions need to be authenticated, and the UE is only allowed to access the first network if the authentication is successful.
[0120] The authentication process for any UE (denoted as the target UE) to access the first network will be explained below.
[0121] It should be understood that authentication of the target UE's access to the first network is typically performed by the first network's authentication system. In some embodiments, when the first network's authentication system and the first network's gateway are deployed in separate hardware devices, refer to... Figure 7 , Figure 7This illustration shows a process for authenticating the access rights of a target UE to a first network according to an embodiment of this application. Optionally, this method is applied to... Figures 2-6 The implementation environment shown, and by Figures 2-6 The UE, network devices in the mobile communication network, the gateway of the first network, and the authentication system of the first network in the implementation environment shown execute corresponding steps. Figure 7 As shown, the method includes the following steps 101 to 106.
[0122] Step 101: The target UE sends a target service message, which is used to access the first network.
[0123] When a target UE needs to access the first network, it sends a target service message with the destination address being a host address in the first network, so as to access the first network through the target service message.
[0124] For example, taking a mobile phone as the target UE, the mobile phone sends the target service message to the base station in the mobile communication network through its own antenna module.
[0125] Step 102: The network device in the mobile communication network receives the target service message sent by the target UE.
[0126] This network device refers to a network device in the core network of a mobile communication network. In one example, this network device is an SMF device in the core network of a mobile communication network.
[0127] Specifically, network devices in a mobile communication network receive target service messages sent by the target UE through the wireless access point (such as a base station) and bearer network of the mobile communication network.
[0128] Optionally, after receiving the target service message, the network device in the mobile communication network further verifies the target service message to determine whether it is a legitimate service message. After determining that the target service message is a legitimate message, the network device in the mobile communication network executes step 103.
[0129] In one example, a network device in a mobile communication network extracts the target UE's mobile phone number from the target service message and queries the subscription plan for that mobile phone number based on the extracted number to determine whether the mobile phone number is subscribed to by the mobile communication network operator and whether the mobile phone number has any outstanding fees. If the network device determines that the target UE's mobile phone number is subscribed to by the mobile communication network operator and that the mobile phone number has no outstanding fees, then the target service message sent by the target UE is determined to be a legitimate message.
[0130] Step 103: When a network device in a mobile communication network determines that a target service message is a message accessing the first network, it obtains the UE identifier of the target UE.
[0131] Taking an SMF (Software-Defined Network) device as an example, after receiving a target service packet, the SMF device determines that the target service packet intends to reach the first network based on the destination address (or the network segment where the destination address is located). In other words, the SMF device determines that the target service packet is a packet accessing the first network based on the destination address (or the network segment where the destination address is located). It should be understood that the SMF device pre-stores IP addresses or IP network segments corresponding to different networks.
[0132] Optionally, after determining that the target service message is a message for accessing the first network, the SMF device further queries the subscription plan of the target UE's mobile phone number extracted from the target service message to determine whether the mobile phone number has subscribed to a value-added package for accessing the first network. After the SMF device determines that the target UE's mobile phone number has subscribed to a value-added package for accessing the first network, the SMF obtains the target UE's identifier.
[0133] Specifically, the SMF device obtains the UE identifier of the target UE based on the target service message. Optionally, the UE identifier may include, but is not limited to, any one of the following: International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), or Mobile Subscriber Integrated Services Digital Network Number (MSISDN). IMSI is also known as the SIM card number, and MSISDN is the mobile phone number.
[0134] In one possible scenario, when the UE is identified as an MSISDN, since the target service message sent by the target UE usually carries the target UE's mobile phone number, the SMF device can extract the target UE's mobile phone number from the target service message to obtain the target UE's MSISDN.
[0135] In another possible scenario, when the UE is identified by its IMSI or IMEI, since the target service message sent by the target UE typically does not carry the target UE's IMSI or IMEI, the SMF device queries the target UE's IMSI or IMEI based on the target UE's mobile phone number extracted from the target service message. In one example, the SMF device queries the target UE's IMSI from the mobile network's database or from an upstream node of the SMF device (such as a Mobility Management Entity, MME) based on the target UE's mobile phone number. In another example, the SMF device queries the target UE's IMSI or IMEI based on the target UE's mobile phone number and interacts with the unified data management (UDM) system through the 5G Subscription Data Management interface. It should be understood that the UDM system generally provides functions such as user subscription data management and user identification data management.
[0136] Step 104: The network device of the mobile communication network sends an authentication request to the authentication system of the first network. The authentication request includes the UE identifier of the target UE.
[0137] The authentication request is used to request authentication of the target UE's permission to access the first network, and the authentication system of the first network is used to perform authentication of the target UE's permission to access the first network.
[0138] Specifically, after obtaining the UE identifier of the target UE, the network device in the mobile communication network generates an authentication request including the UE identifier and sends the authentication request to the authentication system of the first network. For example, after generating the authentication request, the network device in the mobile communication network sends the authentication request to the 3A server of the first network through its own network interface.
[0139] Optionally, the authentication request sent by the network device of the mobile communication network to the authentication system of the first network may also include the location information of the target UE. In one example, the target service message sent by the target UE carries the location information of the target UE. In this case, after receiving the target service message sent by the target UE, the network device of the mobile communication network extracts the location information from the target service message, generates an authentication request including the location information and the UE identifier of the target UE, and then sends the authentication request to the authentication system of the first network.
[0140] Optionally, to prevent the leakage of user information, when generating an authentication request that includes the location information and UE identifier of the target UE, the network device of the mobile communication network uses an encryption algorithm to encrypt and encapsulate the location information and / or UE identifier of the target UE. This application embodiment does not specifically limit the encryption algorithm used.
[0141] Step 105: The gateway of the first network receives the authentication request and forwards the authentication request to the authentication system of the first network.
[0142] When a network device in a mobile communication network sends a message to the authentication system of the first network, the message is first received by the gateway of the first network. Therefore, when a network device in a mobile communication network sends an authentication request to the authentication system of the first network, the gateway of the first network receives the authentication request first. For example, the gateway of the first network receives the authentication request sent by the network device in the mobile communication network through its own network interface.
[0143] Optionally, when the IP address used by the target UE to communicate with the first network is an IP address assigned to the target UE by the mobile communication network, the authentication request received by the gateway of the first network also includes the IP address assigned to the target UE by the mobile communication network.
[0144] In one example, combining Figure 4 Taking a 5G mobile communication network and an SMF (Smart Provider Function) device as an example, after receiving a target service message from a target UE, the SMF device assigns an IP address to the target UE, includes this IP address in an authentication request, and sends the authentication request to the authentication system of the first network via a first UPF (User Provider Function). In response, the gateway of the first network receives an authentication request including the IP address and the UE identifier of the target UE.
[0145] In another example, combined Figure 5 Taking a 5G mobile communication network and an SMF (Smart Provider Function) device as an example, after receiving a target service message from a target UE, the SMF device generates an authentication request carrying the UE identifier of the target UE and sends this authentication request to the authentication system of the first network via the primary UPF (User Provider Function) and the first UPF. During this process, upon receiving the authentication request, the primary UPF assigns an IP address to the target UE, adds this IP address to the received authentication request, and sends the authentication request to the authentication system of the first network via the first UPF. In response, the gateway of the first network receives an authentication request including the IP address and the UE identifier of the target UE.
[0146] Furthermore, the gateway of the first network forwards the authentication request to the authentication system of the first network. For example, the gateway of the first network forwards the authentication request to the 3A service in the first network.
[0147] Step 106: The authentication system of the first network receives the authentication request and responds to the authentication request by authenticating the target UE's permission to access the first network based on the UE identifier of the target UE carried in the authentication request.
[0148] Specifically, after receiving an authentication request, the authentication system of the first network parses the UE identifier of the target UE from the authentication request, and in response to the received authentication request, authenticates the target UE's permission to access the first network based on the parsed UE identifier. It should be understood that this application embodiment does not specifically limit the specific implementation method of the authentication system authenticating the UE's permission to access the first network.
[0149] In one example, the authentication system of the first network pre-stores multiple UE identifiers that are allowed to access the first network. In this case, after parsing the UE identifier of the target UE, the authentication system of the first network iterates through the pre-stored multiple UE identifiers to determine whether the target UE's UE identifier is included. If the target UE's UE identifier is included in the pre-stored multiple UE identifiers, the authentication system of the first network determines that the target UE is allowed to access the first network, that is, the target UE is determined to be a legitimate user of the first network, and the authentication result of the first network's authentication system for the target UE's access to the first network is successful. If the target UE's UE identifier is not included in the pre-stored multiple UE identifiers, the authentication system of the first network determines that the target UE is not allowed to access the first network, that is, the target UE is determined to be an illegitimate user of the first network, and the authentication result of the first network's authentication system for the target UE's access to the first network is unsuccessful.
[0150] Steps 101 to 106 are used to authenticate the target UE's access to the first network.
[0151] In other embodiments, when the authentication system of the first network and the gateway of the first network are integrated together, that is, when the authentication system of the first network is deployed in the gateway of the first network, refer to Figure 8 , Figure 8 This illustration shows another process for authenticating a target UE's access to a first network, as provided in an embodiment of this application. Optionally, this method is applied to... Figures 2-6 The implementation environment described herein, and by Figures 2-6 The UE, network devices in the mobile communication network, the gateway of the first network, and the authentication system of the first network in the implementation environment shown execute corresponding steps. Figure 8As shown, the method first executes steps 101 to 104, and then executes step 107 as described below.
[0152] Step 107: The gateway of the first network receives the authentication request and responds to the authentication request by authenticating the target UE's permission to access the first network based on the UE identifier of the target UE carried in the authentication request.
[0153] Specifically, after receiving the authentication request, the gateway of the first network responds to the authentication request by the authentication system deployed on that gateway, which authenticates the target UE's access to the first network based on the UE identifier of the target UE carried in the authentication request. For a detailed explanation, please refer to the relevant description in step 106, which will not be repeated here.
[0154] Thus, through Figure 7 and Figure 8 The process shown achieves the purpose of authenticating the target UE's permission to access the first network when the target UE needs to access the first network.
[0155] The implementation process of the message transmission control method provided in the embodiments of this application is described below.
[0156] refer to Figure 9 , Figure 9 A flowchart illustrating a message transmission control method provided in an embodiment of this application is shown. Optionally, this method is applied to... Figures 2-6 The implementation environment described herein, and by Figures 2-6 The network switching device and the gateway of the first network in the illustrated implementation environment perform corresponding steps. For example... Figure 9 As shown, the method includes the following steps 201 to 204.
[0157] Step 201: The gateway of the first network obtains an online message, which indicates that the target UE has successfully authenticated its access to the first network.
[0158] The online message includes the IP address of the target UE, which is the IP address used by the target UE when accessing the first network.
[0159] In one possible implementation, combining Figure 7 The process shown involves authenticating the target UE's access to the first network. When the authentication system of the first network determines that the authentication of the target UE's access to the first network is successful through step 106, the authentication system generates an online message indicating successful authentication and returns this online message to the gateway of the first network. In response, the gateway of the first network receives the online message, thus acquiring it.
[0160] In one example, when the authentication request received by the first network's authentication system in step 106 includes an IP address assigned to the target UE by the mobile communication network, the first network's authentication system, after successfully authenticating the target UE's access to the first network, generates an online message including the IP address and returns the online message to the first network's gateway. In response, the first network's gateway receives the online message including the IP address.
[0161] In another example, when the mobile communication network does not assign an IP address to the target UE, it means that the authentication request received by the first network's authentication system in step 106 does not include the target UE's IP address. In this case, after successfully authenticating the target UE's access to the first network, the first network's authentication system assigns an IP address to the target UE, generates an online message including that IP address, and returns the online message to the first network's gateway. In response, the first network's gateway receives the online message including the IP address. Furthermore, the first network's gateway also sends the IP address to the originator of the aforementioned authentication request, that is, to the network device of the mobile communication network that initiated the authentication, so that the network device can subsequently replace the source address of packets from the target UE with that IP address, thereby enabling communication between the target UE and the first or second network.
[0162] In another possible implementation, combining Figure 8 The process of authenticating the target UE's access to the first network, as shown, involves the gateway equipped with the first network authentication system generating an online message to indicate the successful authentication of the target UE's access to the first network after executing step 107. That is, the gateway of the first network receives this online message.
[0163] In one example, when the authentication request received by the gateway of the first network in step 107 includes the IP address assigned to the target UE by the mobile communication network, the gateway with the first network authentication system successfully authenticates the target UE's access to the first network and generates an online message including the IP address.
[0164] In another example, when the mobile communication network does not assign an IP address to the target UE, it means that the authentication request received by the gateway of the first network in step 107 does not include the IP address of the target UE. In this case, after the gateway with the first network authentication system successfully authenticates the target UE's access to the first network, it assigns an IP address to the target UE and generates an online message including that IP address. Furthermore, the gateway with the first network authentication system also sends the IP address assigned to the target UE to the originator of the aforementioned authentication request, that is, to the network device of the mobile communication network that initiated the authentication, so that the network device can subsequently replace the source address of the packets from the target UE with that IP address, thereby enabling communication between the target UE and the first or second network.
[0165] It should be understood that when a target UE needs to access the first network, it will send a target service message to the first network via the mobile communication network. Upon receiving the target service message, the mobile communication network will then... Figure 7 or Figure 8 The method shown initiates authentication of the target UE's access to the first network. The gateway of the first network then receives an online message indicating successful authentication of the target UE's access to the first network, and subsequently allows the target UE to access the first network, i.e., it allows packets from the target UE to be passed (refer to the relevant description of step 202 below). In other words, this online message signifies that the target UE has begun accessing the first network; therefore, from the perspective of the first network, the online message of the target UE can be understood as an indication that the target UE has come online.
[0166] Optionally, the online message obtained by the gateway of the first network also includes the UE identifier of the target UE. The UE identifier of the target UE is used to trace and count the packets sent by the target UE. This is because the IP address used by the target UE may change during the process of accessing the first network or the second network, but the UE identifier of the target UE will not change. Therefore, the gateway of the first network can accurately count the packets sent by the target UE in the future by using the UE identifier of the target UE.
[0167] In this scenario, for example, the online message obtained by the gateway of the first network can be represented as: Userlogin succeeded, (User Name = [UE identifier of the target UE], Client IP = [target IP]). Here, "Userlogin succeeded" indicates that the target UE has logged in, "User Name = [UE identifier of the target UE]" indicates that the username of the logged-in user is the UE identifier of the target UE, and "Client IP = [target IP]" indicates that the IP address of the logged-in user is the target IP.
[0168] Optionally, the online message obtained by the gateway of the first network also includes the location information of the target UE. This location information is used to determine the network switching device corresponding to the location of the target UE. The network switching device is used to allow or block messages from the UE accessing the second network through the mobile communication network. Detailed descriptions of the network switching device can be found in [reference needed]. Figures 2-6 The description of the network switching device in the implementation environment shown will not be repeated.
[0169] In one example, combining Figure 7 When a network device in a mobile communication network sends an authentication request to the authentication system of the first network that carries the location information of the target UE, it indicates that the authentication request received by the first network's authentication system in step 106 carries the location information of the target UE. At this point, after successfully authenticating the target UE's access to the first network, the first network's authentication system generates an online message including the target UE's location information and returns this online message to the gateway of the first network. In response, the gateway of the first network receives the online message including the target UE's location information.
[0170] In another example, combined Figure 8 When a network device in a mobile communication network sends an authentication request to the authentication system of the first network that carries the location information of the target UE, it indicates that the gateway with the first network authentication system received the authentication request in step 107, which in turn carries the location information of the target UE. At this point, after successfully authenticating the target UE's access to the first network, the gateway with the first network authentication system generates an online message including the target UE's location information. In other words, the gateway of the first network receives an online message containing the target UE's location information.
[0171] When the login message obtained by the gateway of the first network also includes the location information of the target UE, for example, the login message obtained by the gateway of the first network can be represented as: User login succeeded, (User Name = [UE identifier of the target UE], Client IP = [target IP], User location = [target location]). Another example is that the login message obtained by the gateway of the first network can be represented as: User login succeeded, (Client IP = [target IP], User location = [target location]). Here, "User location" represents the location of the target UE.
[0172] Step 202: In response to the online message, the gateway of the first network allows packets whose source address is the IP address of the target UE, and sends a blocking notification to the network switching device. The blocking notification includes the IP address of the target UE and is used to indicate that packets whose source address is the IP address of the target UE are blocked.
[0173] Once the gateway of the first network receives an online message containing the IP address of the target UE, it can determine that the first network allows the target UE corresponding to that IP address to access the network. At this point, the gateway of the first network generates a permission policy that indicates that packets whose source address is the IP address of the target UE should be allowed to pass. In this way, when the gateway of the first network subsequently receives service packets whose source address is the IP address of the target UE, it will allow those service packets and forward them normally.
[0174] For example, for the target service message (denoted as message 10) received by the network device in the mobile communication network in step 102 above, after receiving message 10, the network device replaces the source address of message 10 with the IP address allocated by the mobile communication network to the target UE (i.e., the IP address allocated by the mobile communication network to the target UE as described in step 105), or replaces it with the IP address allocated by the authentication system of the first network to the target UE received from the gateway of the first network (i.e., the IP address allocated by the authentication system of the first network to the target UE as described in step 201), to obtain message 12. The replaced IP address is the IP address included in the online message obtained by the gateway of the first network. Then, the network device in the mobile communication network sends message 12 to the first network. When the gateway of the first network receives message 12, it queries the release policy based on the source address of message 12, thereby allowing message 12 to pass and forwarding it normally.
[0175] Furthermore, after the gateway of the first network receives an online message containing the target UE's IP address, it also sends a blocking notification to the network switching device, instructing the device to block packets whose source address is the target UE's IP address. This means that the target UE is prohibited from accessing the second network while accessing the first network. In other words, at any given time, the target UE can only choose one network to access—the first or the second. This prevents attackers in the second network from using the target UE as a springboard to attack the first network, thus ensuring the security of the first network.
[0176] The blocking notification includes the IP address of the target UE, which is the same IP address carried in the online message. Optionally, the blocking notification also includes the UE identifier of the target UE, which is used to trace and statistically analyze the packets sent by the target UE. This is because the IP address used by the target UE may change during access to the first or second network, but the UE identifier of the target UE will not change. Therefore, after receiving the blocking notification including the UE identifier of the target UE, the network switching device can accurately count the packets sent by the target UE using the UE identifier.
[0177] Optionally, when the blocking notification also includes the UE identifier of the target UE, to avoid user information leakage, the gateway of the first network uses an encryption algorithm to encrypt the UE identifier of the target UE and sends a blocking notification carrying the encrypted information to the network switching device. Alternatively, the gateway of the first network uses information desensitization technology to process the UE identifier of the target UE and sends a blocking notification carrying the information processed by the information desensitization technology to the network switching device.
[0178] It should be noted that, in combination Figure 5 In the implementation environment shown, since the second networks are distributed in different regions, this embodiment of the application sets up corresponding network switching devices at the boundary between the second network and the mobile communication network in each region. Therefore, after the gateway of the first network receives the online message indicating that the permission authentication for the target UE to access the first network has been successful, it also needs to determine the corresponding network switching device based on the location information of the target UE. In this way, it can be ensured that even after the target UE roams, the communication link for the target UE to access the second network can still be controlled by the network switching device corresponding to the current location of the target UE.
[0179] Optionally, when the online message obtained by the gateway of the first network includes the location information of the target UE, the gateway of the first network selects the network switching device configured in the region corresponding to the location information of the target UE as the network switching device to receive the aforementioned blocking notification. Then, the gateway of the first network sends the aforementioned blocking notification to the network switching device, instructing the network switching device to block packets whose source address is the IP address of the target UE.
[0180] Optionally, when the online message obtained by the gateway of the first network does not include the location information of the target UE, the gateway of the first network queries the current location information of the target UE based on the UE identifier of the target UE, for example, by querying the Global Positioning System (GPS) through the target UE's mobile phone number, to determine the current actual location of the target UE. Then, based on the region corresponding to the current actual location of the target UE, the gateway of the first network selects the network switching device configured in that region as the network switching device to receive the aforementioned blocking notification. Next, the gateway of the first network sends the aforementioned blocking notification to the network switching device, instructing the network switching device to block packets whose source address is the IP address of the target UE.
[0181] In one possible implementation, the gateway of the first network sends a blocking notification to the network switching device using an existing protocol. For example, the gateway of the first network encapsulates the content of the blocking notification (such as the IP address of the target UE, or the IP address and UE identifier of the target UE) using the system log (Syslog) protocol, and sends the encapsulated blocking notification to the network switching device. The Syslog protocol is a standard used to transmit records or messages over the Internet.
[0182] For example, refer to Figure 10 , Figure 10 This illustration shows a schematic diagram of a newly created Syslog log template provided in an embodiment of this application. For example... Figure 10 As shown, the gateway of the first network acts as a Syslog client to create a new Syslog log template. Specifically, the gateway of the first network enters the log name and selects the configuration mode in the Syslog configuration interface. In the session log field, it configures the session information of the first network gateway acting as a Syslog client and the network switching device acting as a Syslog server. The session information includes the source address, source port, destination address, destination port, and network layer protocol, etc., and the content of the blocking notification is entered in the log format field. In this way, the gateway of the first network can encapsulate the blocking notification through the Syslog protocol.
[0183] In another possible implementation, the gateway of the first network sends a blocking notification to the network switching device using a custom proprietary protocol. Optionally, this proprietary protocol is a network layer protocol. In one example, this proprietary protocol is an extension of Transmission Control Protocol (TCP) / IP. In another example, this proprietary protocol is an extension of User Datagram Protocol (UDP). It can be understood that in this implementation, the message carrying the blocking notification is a dedicated notification message specifically used for sending blocking notifications.
[0184] For example, the private protocol provided in this application embodiment is named "PRI-internet+enterprise". The format of the dedicated notification message encapsulated based on this private protocol is: protocol name (PRI-internet+enterprise), source IP address [IP address of the gateway of the first network], destination IP address [IP address of the network switching device], (content of the blocking notification).
[0185] Optionally, the gateway of the first network sends the aforementioned blocking notification to the network switching device via the mobile communication network. That is, the gateway of the first network sends the blocking notification to the network switching device via a communication link through the mobile communication network.
[0186] Optionally, a direct communication link (referred to as a dedicated communication link between the network switch and the gateway of the first network) is configured between the gateway of the first network and the network switch. In this case, the gateway of the first network sends the aforementioned blocking notification via this direct communication link.
[0187] Step 203: The network switching device receives a blocking notification sent by the gateway of the first network.
[0188] For example, the network switching device receives a blocking notification sent by the gateway of the first network through its own network interface.
[0189] Step 204: In response to the blocking notification, the network switching device blocks packets destined for the second network whose source address is the IP address of the target UE.
[0190] In this embodiment of the application, the network opening and closing device is set by default to allow messages sent to the second network.
[0191] When the network switching device receives a blocking notification, it extracts the IP address of the target UE from the notification and, in response, creates a blocking policy based on the extracted IP address. This blocking policy instructs the blocking of packets whose source address is the target UE's IP address. It should be understood that packets received by the network switching device whose source address is the UE's IP address are all packets sent by the UE to the second network. Therefore, it can also be understood that the blocking policy instructs the blocking of packets sent to the second network whose source address is the target UE's IP address.
[0192] Subsequently, when the network switch receives a service packet destined for the second network whose source address is the target UE's IP address, the network switch queries the blocking policy based on the source address in the service packet and responds to the blocking policy, blocking the service packet destined for the second network whose source address is the target UE's IP address. For example, the network switch may discard the service packet destined for the second network whose source address is the target UE's IP address.
[0193] In one example, for any service message (denoted as message 20) for accessing the Internet received by a network device in a mobile communication network from a target UE, the network device replaces the source address of message 20 with the IP address assigned to the target UE by the mobile communication network (i.e., the IP address assigned to the target UE by the mobile communication network as described in step 105), or replaces it with the IP address assigned to the target UE by the authentication system of the first network received from the gateway of the first network (i.e., the IP address assigned to the target UE by the authentication system of the first network as described in step 201), to obtain message 22. Then, the network device in the mobile communication network sends message 22 to the second network. When the network switching device located at the boundary between the second network and the mobile communication network receives message 22, it queries the aforementioned blocking policy based on the source address of message 22, thereby blocking (e.g., discarding) message 22.
[0194] Through steps 201 to 204, it is achieved that while the target UE is accessing the first network, its access to the second network is blocked. In other words, when the first network is an enterprise network and the second network is the Internet, the method provided in this application embodiment can block the target UE's access to the Internet while it is accessing the enterprise network. Thus, it achieves time-sharing control of the UE's access to the enterprise network and the Internet on the network side, thereby ensuring the network security of the enterprise network.
[0195] Subsequently, in some other embodiments, when the target UE stops accessing the first network, refer to Figure 11 , Figure 11 A flowchart illustrating another message transmission control method provided in an embodiment of this application is shown. Optionally, this method is applied to... Figures 2-6 The implementation environment described herein, and by Figures 2-6 The network switching device and the gateway of the first network in the illustrated implementation environment perform corresponding steps. For example... Figure 11 As shown, the method includes the following steps 205 to 208.
[0196] Step 205: The gateway of the first network determines that the target UE stops accessing the first network.
[0197] During the process of the target UE accessing the first network through the mobile communication network, all service packets from the target UE will flow through the gateway of the first network and be allowed by the gateway of the first network according to the release policy described in step 202 above.
[0198] In one possible implementation, if the gateway of the first network does not receive a service message from the target UE within a preset time period, the gateway of the first network determines that the target UE stops accessing the first network.
[0199] After determining that the target UE has stopped accessing the first network, the gateway of the first network will also invalidate or delete the policy that allows service packets whose source address is the target UE's IP address. In this way, the gateway of the first network will subsequently block any service packets whose source address is the target UE's IP address that it receives.
[0200] In another possible implementation, the gateway of the first network responds to the user's input by invalidating or deleting a policy that allows service packets whose source address is the IP address of the target UE. For example, the user inputs a preset operation to the gateway of the first network through an input interface (such as a mouse, keyboard, or touchscreen). The gateway receives the preset operation and responds by invalidating or deleting a policy that allows service packets whose source address is the IP address of the target UE.
[0201] In this situation, the gateway of the first network determines that the target UE should stop accessing the first network.
[0202] Step 206: In response to the target UE stopping access to the first network, the gateway of the first network sends a release notification to the network switching device. The release notification includes the IP address of the target UE and is used to indicate that packets whose source address is an IP address are allowed.
[0203] Optionally, the clearance notification may also include the UE identifier of the target UE, which is used for tracing and statistical analysis of the packets sent by the target UE. This is because the IP address used by the target UE may change during the process of accessing the first network or the second network, but the UE identifier of the target UE will not change. Therefore, the network switching device can accurately count the packets sent by the target UE in the future by using the UE identifier of the target UE.
[0204] Optionally, when the release notification also includes the UE identifier of the target UE, to avoid user information leakage, the gateway of the first network uses an encryption algorithm to encrypt the UE identifier of the target UE and sends a release notification carrying the encrypted information to the network switching device. Alternatively, the gateway of the first network uses information desensitization technology to process the UE identifier of the target UE and sends a release notification carrying the information processed by the information desensitization technology to the network switching device.
[0205] It is understandable that when the gateway of the first network determines that the target UE has stopped accessing the first network, it can be interpreted as the target UE going offline from the perspective of the first network. Therefore, the content in the clearance notification can also be understood as a offline message of the target UE, which includes the IP address of the target UE, or the IP address and UE identifier of the target UE. In one example, the offline message is represented as: User logoff, (User Name = [UE identifier of target UE], Client IP = [target IP]). Here, "User logoff" indicates that the target UE is offline, "User Name = [UE identifier of target UE]" indicates that the username of the offline user is the UE identifier of the target UE, and "Client IP = [target IP]" indicates that the IP address of the offline user is the target IP.
[0206] Furthermore, the network switching device that receives the release notification sent by the first network gateway is the same network switching device used in step 202 to receive the blocking notification of the message indicating that the blocking source address is the IP address of the target UE. Here, a detailed description of the first network gateway sending the release notification to the network switching device can be found in the relevant description of the first network gateway sending the blocking notification to the network switching device in step 202, and will not be repeated here.
[0207] Step 207: The network switching device receives a release notification sent by the gateway of the first network.
[0208] For example, the network switching device receives a release notification sent by the gateway of the first network through its own network interface.
[0209] Step 208: In response to the release notification, the network switching device releases the packet destined for the second network whose source address is the IP address of the target UE.
[0210] After receiving a clearance notification, the network switch extracts the IP address of the target UE from the notification and, in response, creates a clearance policy based on the extracted IP address. This policy instructs the network switch to allow packets whose source address is the target UE's IP address. Since the packets received by the network switch with the UE's IP address as the source address are all packets sent by the UE to the second network, this can also be understood as the network switch resuming the permission to allow packets destined for the second network.
[0211] Subsequently, when the network switch receives a service packet destined for the second network and whose source address is the IP address of the target UE, the network switch queries the allow policy based on the source address in the service packet and responds to the allow policy, thereby allowing the service packet destined for the second network and whose source address is the IP address of the target UE to be sent through, for example, by forwarding the service packet destined for the second network and whose source address is the IP address of the target UE normally.
[0212] Through steps 205 to 208, it is achieved that the target UE can only access the second network normally after it stops accessing the first network. When the first network is an enterprise network and the second network is the Internet, the method provided in this application embodiment can ensure that the target UE can only access the Internet normally after it stops accessing the enterprise network. In this way, it is possible to control the UE's time-sharing access to the enterprise network and the Internet on the network side, thereby ensuring the network security of the enterprise network.
[0213] In summary, the method provided in this application embodiment enables UE to access a first network and a second network in a time-sharing manner, such as time-sharing access to an enterprise network and the Internet. When the first network is an enterprise network and the second network is the Internet, controlling the UE's time-sharing access to the enterprise network and the Internet on the network side can ensure the network security of the enterprise network.
[0214] To enhance understanding of the methods provided in the embodiments of this application, the following description is provided in conjunction with the accompanying drawings. Figure 12 The methods provided in the embodiments of this application will be further described. (See references) Figure 12 , Figure 12 This illustration shows yet another flowchart of the message transmission control method provided in an embodiment of this application. Optionally, this method is applied to... Figures 2-6 The implementation environment described herein, and by Figures 2-6 In the implementation environment shown, any UE (denoted as the target UE), the network switching device, and the gateway of the first network execute the corresponding steps. For example... Figure 12 As shown, the method includes the following steps 301 to 310.
[0215] Step 301: The target UE sends a target service message, which is used to access the first network.
[0216] Step 302: The network device in the mobile communication network receives the target service message sent by the target UE, and when it is determined that the target service message is a message for accessing the first network, it obtains the UE identifier of the target UE.
[0217] Step 303: The network device of the mobile communication network sends an authentication request to the authentication system of the first network. The authentication request includes the UE identifier of the target UE.
[0218] Step 304: The gateway of the first network receives the authentication request and forwards the authentication request to the authentication system of the first network.
[0219] Step 305: The authentication system of the first network receives the authentication request and responds to the authentication request by authenticating the target UE's permission to access the first network based on the UE identifier of the target UE carried in the authentication request.
[0220] For detailed explanations of steps 301 to 305, please refer to the descriptions of steps 101 to 106 above, which will not be repeated here.
[0221] Step 306: When the authentication system of the first network determines that the above authentication result is successful, it generates and sends the online message of the target UE to the gateway of the first network.
[0222] For a detailed explanation of step 306, please refer to the relevant description of step 201, which will not be repeated here.
[0223] Step 307: In response to the online message, the gateway of the first network allows packets whose source address is the IP address of the target UE, and sends a blocking notification to the network switching device. The blocking notification includes the IP address of the target UE and is used to indicate that packets whose source address is the IP address of the target UE are blocked.
[0224] Step 308: The network switching device receives a blocking notification sent by the gateway of the first network and, in response to the blocking notification, blocks a packet destined for the second network whose source address is the IP address of the target UE.
[0225] Step 309: The gateway of the first network determines that the target UE has stopped accessing the first network and sends a release notification to the network switching device. The release notification includes the IP address of the target UE and is used to indicate that packets whose source address is an IP address are allowed.
[0226] Step 310: The network switching device receives the release notification sent by the gateway of the first network, and in response to the release notification, releases the packet destined for the second network whose source address is the IP address of the target UE.
[0227] For detailed explanations of steps 307 to 310, please refer to the descriptions of steps 202 to 208, which will not be repeated here.
[0228] By applying the method provided in this application embodiment, the target UE accesses the second network by default through the mobile communication network. When the target UE accesses the first network through the mobile communication network, the network-side network switching device controls and blocks the UE's access to the second network. Conversely, when the target UE stops accessing the first network, the network-side network switching device controls and restores the access to the second network. In other words, the method provided in this application embodiment enables the UE to access the first and second networks in a time-sharing manner, such as time-sharing access to an enterprise network and the Internet. When the first network is an enterprise network and the second network is the Internet, controlling the UE's time-sharing access to the enterprise network and the Internet on the network side ensures the network security of the enterprise network.
[0229] The methods and technical effects provided in the embodiments of this application will be further explained below in conjunction with specific implementation environments.
[0230] Combination Figure 4 In the illustrated implementation environment, exemplarily, when UE 1 accesses the first network via an IP address assigned to UE 1 by the first network's authentication system (i.e., IP 1), Figure 4 The SMF device shown receives IP 1 from the gateway of the first network, which is assigned to UE 1 by the authentication system of the first network (refer to the relevant description of step 201). In response, the SMF device receives and stores IP 1, and records the correspondence between IP 1 and the UE identifier of UE 1.
[0231] Continue to combine Figure 4 The implementation environment shown is as follows: Figure 4 In the illustrated implementation environment, where the first network is an enterprise network and the second network is the Internet, when UE 1's SIM card has network services activated (such as activating a data package) and accesses the enterprise network's value-added services, UE 1 can access the Internet by default through the mobile communication network. When UE 1 needs to access the enterprise network, by executing steps 301 to 308 described above, the enterprise network's gateway can be configured to allow access to source address IP 1, and the network switching device can be configured to block access to source address IP 1. That is, UE 1 can access the enterprise network but is prohibited from accessing the Internet.
[0232] In one example, after executing steps 301 to 308 described above, UE 1 sends message 30 to the mobile communication network for accessing the enterprise network. Upon receiving message 30, the SMF device obtains the UE identifier of UE 1 based on message 30 and queries the IP address corresponding to that UE identifier. Then, the SMF device replaces the source address of message 30 with IP address 1 to obtain message 32. Next, the SMF device selects the first UPF device to forward message 32 based on the destination address of message 32 (or message 30). Therefore, the SMF device forwards message 32 to the first UPF device, which then forwards it to the gateway of the enterprise network. Upon receiving message 32, the gateway of the enterprise network queries the source address IP address of message 32 and finds the permission policy indicating permission for source address IP address 1. The gateway then allows and forwards message 32 normally.
[0233] In another example, after executing steps 301 to 308 described above, UE 1 sends a message 40 to the mobile communication network for accessing the Internet. Upon receiving message 40, the SMF device obtains the UE identifier of UE 1 based on message 40 and queries the IP address corresponding to that UE identifier. Then, the SMF device replaces the source address of message 40 with IP address 1 to obtain message 42. Next, the SMF device selects a second UPF device to forward message 42 based on the destination address of message 42 (or message 40). Therefore, the SMF device forwards message 42 to the second UPF device. Combined with... Figure 4 In (a) of the diagram, the second UPF device forwards message 42 to the network switch. Upon receiving message 42, the network switch queries the source address IP1 of message 42 to find the blocking policy instructing the blocking of source address IP1, and then blocks message 42. Alternatively, it can be combined with... Figure 4 In (b), after the second UPF device receives message 42, the network switching device deployed in the second UPF device queries the source address IP 1 of message 42 to find the blocking policy that indicates blocking the source address IP 1, thereby blocking message 42.
[0234] Subsequently, by executing steps 309 to 310 described above, the gateway of the enterprise network deletes the allowance policy for source address IP1, and the network switching device is configured to allow the allowance policy for source address IP1. That is, UE 1 is prohibited from accessing the enterprise network, but is allowed to access the Internet.
[0235] In one example, after executing steps 309 to 310 described above, UE 1 sends message 50 to the mobile communication network for accessing the enterprise network. Upon receiving message 50, the SMF device obtains the UE identifier of UE 1 based on message 50 and queries the IP address corresponding to that UE identifier. Then, the SMF device replaces the source address of message 50 with IP address 1 to obtain message 52. Next, the SMF device selects a first UPF device to forward message 52 based on the destination address of message 52 (or message 50). Therefore, the SMF device forwards message 52 to the first UPF device, which then forwards it to the gateway of the enterprise network. Upon receiving message 52, the gateway of the enterprise network, finding no allowance policy indicating permission for the source address IP address 1, blocks message 52.
[0236] In another example, after executing steps 309-310 described above, UE 1 sends a message 60 to the mobile communication network for accessing the Internet. Upon receiving message 60, the SMF device obtains the UE identifier of UE 1 based on message 60 and queries the IP address corresponding to that UE identifier. Then, the SMF device replaces the source address of message 60 with IP address 1 to obtain message 62. Next, the SMF device selects a second UPF device to forward message 62 based on the destination address of message 62 (or message 60). Therefore, the SMF device forwards message 62 to the second UPF device. Combined with... Figure 4 In (a) of the diagram, the second UPF device forwards message 62 to the network switch. Upon receiving message 62, the network switch queries the source address IP1 of message 62 to find the allow policy instructing the network switch to allow message 62. Alternatively, it can be combined with... Figure 4 In (b), after the second UPF device receives message 62, the network switch deployed in the second UPF device queries the source address IP 1 of message 62 to find the release policy that indicates the release of source address IP 1, and thus releases message 62.
[0237] Combination Figure 6 In the implementation environment shown, for example, when the IP address of UE 1 accessing the first network is the IP address (i.e., IP 2) assigned to UE 1 by the main UPF device in the mobile communication network, the main UPF device will record the correspondence between IP 2 and the UE identifier of UE 1.
[0238] Continue to combine Figure 6 The implementation environment shown is as follows: Figure 6In the illustrated implementation environment, where the first network is an enterprise network and the second network is the Internet, when UE 1's SIM card has network services activated (such as activating a data package) and accesses the enterprise network's value-added services, UE 1 can access the Internet by default through the mobile communication network. When UE 1 needs to access the enterprise network, by executing steps 301 to 308 described above, the enterprise network's gateway can be configured to allow access to source address IP 2, and the network switching device can be configured to block access to source address IP 2. That is, UE 1 can access the enterprise network but is prohibited from accessing the Internet.
[0239] In one example, after executing steps 301 to 308 as described above, UE 1 sends message 70 to the mobile communication network for accessing the enterprise network. Upon receiving message 70, the SMF device forwards message 70 to the primary UPF device. After receiving message 70, the primary UPF device obtains the UE identifier of UE 1 based on message 70 and queries the IP address 2 corresponding to that UE identifier. Then, the primary UPF device replaces the source address of message 70 with IP address 2 to obtain message 72. Next, the primary UPF device selects the first UPF device to forward message 72 based on the destination address of message 72 (or message 70). Therefore, the primary UPF device forwards message 72 to the first UPF device, which then forwards it to the gateway of the enterprise network. Upon receiving message 72, the gateway of the enterprise network queries the source address IP address 2 of message 72 to find the allowance policy indicating that the source address IP address 2 is allowed. Therefore, the gateway of the enterprise network allows and forwards message 72 normally.
[0240] In another example, after executing steps 301 to 308 described above, UE 1 sends a message 80 to the mobile communication network for accessing the Internet. Upon receiving message 80, the SMF device forwards message 80 to the primary UPF device. The primary UPF device obtains the UE identifier of UE 1 based on message 80 and queries the IP address 2 corresponding to that UE identifier. Then, the primary UPF device replaces the source address of message 80 with IP address 2 to obtain message 82. Next, the primary UPF device selects a second UPF device to forward message 82 based on the destination address of message 82 (or message 80), thus the primary UPF device forwards message 82 to the second UPF device. Combined with... Figure 6 In (a) of the above, the second UPF device receives message 82 and forwards it to the network switch. Upon receiving message 82, the network switch queries the source address IP 2 of message 82 to find the blocking policy indicating blocking of source address IP 2, and then blocks message 82. Alternatively, in combination with... Figure 6In (b) of this example, after the primary UPF device forwards message 82 to the secondary UPF device, the network switch located between the primary and secondary UPF devices receives message 82. The network switch then uses the source address IP 2 of message 82 to query the blocking policy instructing the blocking of source address IP 2, and subsequently blocks message 82. Alternatively, it can be combined with... Figure 6 In step (c), the second UPF device receives message 82. The network switch deployed in the second UPF device queries the source address IP 2 of message 82 to find the blocking policy indicating blocking source address IP 2, thereby blocking message 82. Alternatively, in combination with... Figure 6 In (d), after the main UPF device obtains message 82 based on message 80, the network switching device deployed in the main UPF device queries the source address IP 2 of message 82 to find the blocking policy that indicates blocking the source address IP 2, thereby blocking message 82.
[0241] Subsequently, by executing steps 309 to 310 described above, the gateway of the enterprise network deletes the allowance policy for source address IP2, and the network switching device is configured to allow the allowance policy for source address IP2. That is, UE 1 is prohibited from accessing the enterprise network but is allowed to access the Internet.
[0242] In one example, after executing steps 309 to 310 described above, UE 1 sends a message 90 to the mobile communication network for accessing the enterprise network. Upon receiving message 90, the SMF device forwards it to the primary UPF device. The primary UPF device, upon receiving message 90, obtains the UE identifier of UE 1 based on message 90 and queries the IP address 2 corresponding to that UE identifier. Then, the primary UPF device replaces the source address of message 90 with IP address 2 to obtain message 92. Next, the primary UPF device selects the first UPF device to forward message 92 based on the destination address of message 92 (or message 90). Therefore, the primary UPF device forwards message 92 to the first UPF device, which then forwards it to the gateway of the enterprise network. Upon receiving message 92, the gateway of the enterprise network, finding no allowance policy indicating permission for the source address IP address 2, blocks message 92.
[0243] In another example, after executing steps 309-310 described above, UE 1 sends a message 100 to the mobile communication network for accessing the Internet. Upon receiving message 100, the SMF device forwards message 100 to the primary UPF device. The primary UPF device obtains the UE identifier of UE 1 based on message 100 and queries the IP address corresponding to that UE identifier. Then, the primary UPF device replaces the source address of message 100 with IP address 2 to obtain message 102. Next, the primary UPF device selects a second UPF device to forward message 102 based on the destination address of message 102 (or message 100). Therefore, the primary UPF device forwards message 102 to the second UPF device. (Combined with...) Figure 6 In (a) of the above, the second UPF device receives message 102 and forwards it to the network switch. Upon receiving message 102, the network switch queries the source address IP 2 of message 102 to find the allow policy instructing the network switch to allow message 102. Alternatively, it can be combined with... Figure 6 In (b) of the diagram, after the primary UPF device forwards message 102 to the secondary UPF device, the network switch located between the primary and secondary UPF devices receives message 102. The network switch then queries the source address IP 2 of message 102 to determine the allowance policy instructing the passage of source address IP 2, and subsequently allows message 102. Alternatively, it can be combined with... Figure 6 In step (c), the second UPF device receives message 102. The network switch deployed in the second UPF device queries the source address IP 2 of message 102 to find the allowance policy indicating that the source address IP 2 should be allowed, and thus allows message 102. Alternatively, in combination with... Figure 6 In (d), after the main UPF device obtains message 102 based on message 100, the network switch deployed in the main UPF device queries the source address IP 2 of message 102 to find the release policy that indicates the release of source address IP 2, and thus releases message 102.
[0244] The above mainly describes the solution provided by the embodiments of this application from a methodological perspective.
[0245] To achieve the above functions, refer to Figure 13 , Figure 13 A schematic diagram of the structure of a message transmission control device provided in an embodiment of this application is shown. Figure 13 As shown, the message transmission control device 1300 is applied to a gateway deployed at the edge of the first network. Specifically, the message transmission control device 1300 is used to execute the message transmission control method described above, for example, to execute... Figure 7 , Figure 8 , Figure 9 , Figure 11 or Figure 12The steps in the method shown are performed by the gateway of the first network. The message transmission control device 1300 may include an acquisition unit 1301, a processing unit 1302, and a sending unit 1303.
[0246] Acquisition unit 1301 is used to acquire an online message, which indicates that the target UE has successfully authenticated its access to the first network. The online message includes the IP address of the target UE, and the target UE accesses the first network via the mobile communication network. Processing unit 1302 is used, in response to the online message, to allow packets whose source address is the IP address of the target UE. Sending unit 1303 is used, in response to the online message, to send a blocking notification to the network switching device. The blocking notification includes the IP address of the target UE and is used to indicate that packets whose source address is the IP address of the target UE will be blocked. The network switching device is used to allow or block packets from the UE accessing the second network via the mobile communication network.
[0247] As an example, combined Figure 9 The acquisition unit 1301 can be used to execute step 201, and the processing unit 1302 and the sending unit 1303 can be used to execute step 202.
[0248] Optionally, the message transmission control device 1300 further includes a receiving unit 1304. The receiving unit 1304 is configured to receive an authentication request sent by a network device in the mobile communication network. The authentication request includes the UE identifier of the target UE and is used to request authentication of the target UE's permission to access the first network. The sending unit 1303 is further configured to forward the authentication request to the authentication system of the first network. The receiving unit 1304 is further configured to receive an online message returned by the authentication system.
[0249] As an example, combined Figure 7 The receiving unit 1304 and the transmitting unit 1303 can be used to perform step 105.
[0250] Optionally, when the IP address of the target UE is an IP address assigned to the target UE by the mobile communication network, the above authentication request may also include the IP address assigned to the target UE by the mobile communication network.
[0251] Optionally, when the IP address of the target UE is the IP address assigned to the target UE by the authentication system, the sending unit 1303 is also used to return the IP address assigned to the target UE by the authentication system to the aforementioned network device.
[0252] Optionally, the online message and / or blocking notification mentioned above may also include the UE identifier of the target UE, which is used to trace and count the messages sent by the target UE.
[0253] Optionally, the sending unit 1303 is specifically used to send a blocking notification to the network switching device based on the Syslog protocol or a proprietary protocol.
[0254] Optionally, the sending unit 1303 is further configured to send a blocking notification to the network switching device via a mobile communication network; or, to send a blocking notification to the network switching device via a dedicated communication link between the network switching device and the gateway of the first network.
[0255] Optionally, the processing unit 1302 is further configured to determine that the target UE has stopped accessing the first network. The sending unit 1303 is further configured to send a release notification to the network opening / closing device, the release notification including the IP address of the target UE, the release notification being used to indicate that packets whose source address is an IP address are allowed.
[0256] As an example, combined Figure 11 The processing unit 1302 can be used to execute step 205, and the sending unit 1303 can be used to execute step 205.
[0257] Optionally, the UE identifier mentioned above can be any one of IMSI, IMEI, or MSISDN.
[0258] Optionally, the mobile communication network is a 5G network.
[0259] Optionally, the first network is an enterprise network, and the second network is the Internet.
[0260] For a detailed description of the above-mentioned optional methods, please refer to the foregoing method embodiments, which will not be repeated here. Furthermore, the explanation of any of the message transmission control devices 1300 provided above, as well as the description of their beneficial effects, can be found in the corresponding method embodiments described above, and will not be repeated here.
[0261] As an example, in conjunction with the following description Figure 15 The functions implemented by the processing unit 1302 in the message transmission control device 1300 can be achieved through... Figure 15 Processor 1501 in the middle executes Figure 15 The program code in memory 1502 is used for implementation. The functions implemented by the sending unit 1303 and receiving unit 1304 in the message transmission control device 1300 can be achieved through... Figure 15 The network interface 1503 shown is used for implementation. The functions implemented by the acquisition unit 1301 in the message transmission control device 1300 can be achieved through... Figure 15 Processor 1501 in the middle executes Figure 15 The program code in memory 1502 is implemented, or through Figure 15 The network interface shown is 1503, and there are no restrictions on its implementation.
[0262] refer to Figure 14, Figure 14 A schematic diagram of another message transmission control device provided in an embodiment of this application is shown. Figure 14 As shown, the message transmission control device 1400 is applied to a network switching device, which is used to allow or block messages from the UE accessing the second network through the mobile communication network. The UE also accesses the first network through the mobile communication network. Specifically, the message transmission control device 1400 is used to execute the message transmission control method described above, for example, to execute... Figure 7 , Figure 8 , Figure 9 , Figure 11 or Figure 12 The steps in the method shown are performed by the network switching device. The message transmission control device 1400 may include a receiving unit 1401 and a processing unit 1402.
[0263] The receiving unit 1401 is configured to receive a blocking notification sent by the gateway of the first network, the blocking notification including the IP address of the target UE. The processing unit 1402 is configured to, in response to the blocking notification, block packets destined for the second network whose source address is the IP address of the target UE.
[0264] As an example, combined Figure 9 The receiving unit 1401 can be used to execute step 203, and the processing unit 1402 can be used to execute step 204.
[0265] Optionally, the receiving unit 1401 is specifically used to receive a blocking notification sent by the gateway of the first network based on the Syslog protocol or a proprietary protocol.
[0266] Optionally, the receiving unit 1401 is further configured to receive a blocking notification sent by the gateway of the first network through the mobile communication network; or, to receive a blocking notification sent by the gateway of the first network through a dedicated communication link between the network switching device and the gateway.
[0267] Optionally, the blocking notification may also include the UE identifier of the target UE, which is used to trace and statistically analyze the messages sent by the target UE.
[0268] Optionally, the receiving unit 1401 is further configured to receive a clearance notification sent by the gateway of the first network, the clearance notification including the IP address of the target UE. The processing unit 1402 is further configured to, in response to the clearance notification, allow a packet destined for the second network whose source address is the IP address of the target UE to be sent.
[0269] As an example, combined Figure 11 The receiving unit 1401 can be used to execute step 207, and the processing unit 1402 can be used to execute step 208.
[0270] Optionally, the UE identifier included in the blocking notification is any one of IMSI, IMEI, and MSISDN.
[0271] Optionally, the mobile communication network is a 5G network.
[0272] Optionally, the first network is an enterprise network and the second network is the Internet.
[0273] Alternatively, the network switching device can be deployed as a stand-alone device at the boundary between the mobile communication network and the second network.
[0274] Optionally, the network switching device is deployed in the core network of the mobile communication network, and the network switching device communicates with the first network via a first UPF device in the core network, and the network switching device also communicates with the second network via a second UPF device in the core network. Alternatively, the network switching device is deployed in the second UPF device.
[0275] For a detailed description of the above-mentioned optional methods, please refer to the foregoing method embodiments, which will not be repeated here. Furthermore, the explanation of any of the message transmission control devices 1400 provided above, as well as the description of their beneficial effects, can be found in the corresponding method embodiments described above, and will not be repeated here.
[0276] As an example, in conjunction with the following description Figure 15 The function implemented by the receiving unit 1401 in the message transmission control device 1400 can be achieved through... Figure 15 The network interface 1503 shown is used for implementation. The functions implemented by the processing unit 1402 in the message transmission control device 1400 can be achieved through... Figure 15 Processor 1501 in the middle executes Figure 15 The program code is implemented in memory 1502.
[0277] Those skilled in the art will readily recognize that, based on the units and algorithm steps described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0278] It should be noted that, Figure 13 and Figure 14 The module / unit division shown is illustrative and represents only one logical functional division; in actual implementation, other division methods are possible. For example, two or more functions can be integrated into a single processing module. These integrated modules can be implemented either in hardware or as software functional modules.
[0279] This application provides a computing device for implementing the aforementioned message transmission control apparatus, thereby enabling the computing device to implement some or all of the functions in the message transmission control method provided in this application. For example, the computing device is implemented as a gateway of the first network described above, or as a network switching device described above, to execute the method steps performed by the gateway or network switching device of the first network in the method provided in this application.
[0280] refer to Figure 15 , Figure 15 A schematic diagram of the structure of a computing device provided in an embodiment of this application is shown. Figure 15 As shown, the computing device 1500 includes a processor 1501, a memory 1502, a network interface 1503, and a bus 1504. The processor 1501, memory 1502, and network interface 1503 are interconnected via the bus 1504. Optionally, the computing device 1500 also includes an input / output interface 1505, which is interconnected with the processor 1501, memory 1502, and network interface 1503 via the bus 1504.
[0281] Processor 1501 may include a general-purpose processor and / or a dedicated hardware chip. A general-purpose processor may include a central processing unit (CPU), a microprocessor, or a graphics processing unit (GPU). The CPU may be a single-core processor or a multi-core processor. A dedicated hardware chip is a high-performance processing hardware module. Dedicated hardware chips include at least one of the following: digital signal processing (DSP), data processing unit (DPU), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, neural processing unit (NPU), tensor processing unit (TPU), artificial intelligence chip, or network processor (NP). Processor 1501 may also be an integrated circuit chip with signal processing capabilities. In the implementation process, some or all of the functions of the method provided in the embodiments of this application can be accomplished by the integrated logic circuit of the hardware in the processor 1501 or by instructions in the form of software.
[0282] Memory 1502 is used to store computer programs, including operating system 1502a and executable code (i.e., program instructions) 1502b. Memory 1502 is, for example, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other types of static storage devices capable of storing static information and instructions; it is also such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), or synchronous linked dynamic random access memory (SDRAM). DRAM (SLDRAM) or other types of dynamic storage devices capable of storing information and instructions, such as read-only optical discs or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired executable code in the form of instructions or data structures and accessible by a computer, but not limited to these. For example, memory 1502 is used to store the aforementioned allowance or blocking policies. Memory 1502 may exist independently and be connected to processor 1501 via bus 1504. Alternatively, memory 1502 and processor 1501 may be integrated. Memory 1502 can store executable code. When the executable code stored in memory 1502 is executed by processor 1501, processor 1501 performs some or all of the functions of the method provided in the embodiments of this application. The implementation of processor 1501 performing this process is described in the relevant descriptions in the foregoing embodiments. The memory 1502 may also include software modules and data required by other running processes, such as the operating system.
[0283] Network interface 1503 uses transceiver modules, such as, but not limited to, transceivers, to enable communication with other devices or communication networks. For example, network interface 1503 can be any one or any combination of the following devices: network interfaces (such as Ethernet interfaces), wireless network cards, and other devices with network access capabilities. Network interface 1503 includes a receiving unit for receiving data / messages and a sending unit for sending data / messages.
[0284] Bus 1504 is any type of communication bus used to interconnect internal devices (e.g., memory 1502, processor 1501, network interface 1503) of computing device 1500. For example, a system bus. This embodiment illustrates the interconnection of the aforementioned devices within computing device 1500 via bus 1504. Optionally, the aforementioned devices within computing device 1500 can also communicate with each other using other connection methods besides bus 1504; for example, the aforementioned devices within computing device 1500 can be interconnected via internal logic interfaces.
[0285] Input / output interface 1505 is used to realize human-computer interaction between the user and computing device 1500. For example, it enables text or voice interaction between the user and computing device 1500. Input / output interface 1505 includes an input interface for the user to input information to computing device 1500, and an output interface for the computing device 1500 to output information to the user. As an example, the input interface includes, but is not limited to, a touchscreen, keyboard, mouse, or microphone, and the output interface includes, but is not limited to, a display screen, speaker, etc. The touchscreen, keyboard, or mouse is used to input text / image information, the microphone is used to input voice information, the display screen is used to output text / image information, and the speaker is used to output voice information.
[0286] It should be noted that the aforementioned devices can be disposed on separate chips, or at least partially or entirely on the same chip. Whether to dispose of the devices independently on different chips or integrate them on one or more chips often depends on the needs of the product design. This application does not limit the specific implementation of the aforementioned devices. Furthermore, the descriptions of the processes corresponding to the various figures above each have their own emphasis; for parts of a process not described in detail in one figure, please refer to the relevant descriptions of other processes.
[0287] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented, in whole or in part, as a computer program product. The computer program product providing the program development platform includes one or more computer instructions. When these computer program instructions are loaded and executed on the computing device 1500, they implement, in whole or in part, some or all of the functions of the message transmission control method provided in the embodiments of this application.
[0288] Furthermore, computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium stores computer program instructions that provide a program development platform.
[0289] This application embodiment also provides a message transmission control system, which includes a network switching device and a gateway for a first network. The network switching device is used to allow or block messages from a UE accessing a second network through a mobile communication network. The UE also accesses the first network through the mobile communication network. For example, the control system includes... Figures 2-6 The network switching device and the gateway of the first network in any of the implementation environments shown.
[0290] The gateway of the first network is used to execute the method steps performed by the gateway of the first network in the above-described method, and the network switching device is used to execute the method steps performed by the network switching device in the above-described method.
[0291] In one example, the network switching device and the gateway of the first network in the above control system are used to perform... Figure 9 The corresponding steps in the method are as follows: For example, the gateway of the first network is used to obtain an online message, which indicates that the target UE's access authorization to the first network has been successfully authenticated. This online message includes the target UE's Internet Protocol (IP) address. The gateway of the first network is also used, in response to the online message, to allow packets whose source address is the target UE's IP address and to send a blocking notification to the network switching device. The blocking notification includes the target UE's IP address. Alternatively, the network switching device is used to receive the blocking notification and, in response to the blocking notification, to block packets whose source address is the target UE's IP address.
[0292] In another example, the network switching device and the gateway of the first network in the aforementioned control system are used to perform... Figure 11The corresponding steps in the method are as follows. For example, the gateway of the first network is used to determine that the target UE has stopped accessing the first network, and is used to send a release notification to the network switching device, the release notification including the IP address of the target UE. Another example is that the network switching device is used to receive the release notification and, in response to the release notification, to allow a packet destined for the second network whose source address is the IP address of the target UE.
[0293] Optionally, the gateway of the first network in the above control system is, for example, Figure 13 The provided message transmission control device, such as the network switching device in the aforementioned control system, is... Figure 14 The control device for the provided message transmission.
[0294] This application also provides a computer-readable storage medium, which is a non-volatile computer-readable storage medium. The computer-readable storage medium includes computer program instructions. When the computer program instructions are executed by a computing device, computer system, or processor, the computing device, computer system, or processor performs the message transmission control method provided in this application.
[0295] This application also provides a computer program product containing instructions that, when executed by a computing device, computer system, or processor, cause the computing device, computer system, or processor to implement the message transmission control method provided in this application.
[0296] A computer system is a system with computational processing capabilities. A computer system generally includes a processor and memory. The processor retrieves and executes instructions stored in memory to enable the computer system to implement the message transmission control method described above. Optionally, a computer system may also include at least one of an input interface or an output interface. The processor, memory, input interface, and output interface of the computer system are interconnected through internal connection paths.
[0297] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware, or by a program instructing the relevant hardware to implement them. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0298] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0299] This application also provides a chip that includes a processor. When the processor executes program instructions or code, the chip including the processor or the device including the chip performs the message transmission control method described above. Exemplarily, the chip further includes an input interface, an output interface, and a memory. The chip's input interface, output interface, processor, and memory are connected via internal interconnection paths. The memory in the chip stores program instructions or code executed by the processor, and the input and output interfaces are used for communication between the chip and other chips or devices.
[0300] In the embodiments of this application, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The term "at least one" refers to one or more, and the term "multiple" refers to multiples, unless otherwise expressly defined.
[0301] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0302] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0303] It should be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0304] It should be understood that the term "comprising" (also referred to as "includes", "including", "comprises" and / or "comprising") as used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0305] It should also be understood that, in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0306] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.
Claims
1. A control method for message transmission, characterized in that, The method, applied to a gateway deployed at the edge of a first network, includes: Obtain an online message, the online message indicating that the target user equipment UE has successfully authenticated its access to the first network, the target UE accesses the first network through the mobile communication network, and the online message includes the Internet Protocol IP address of the target UE; In response to the online message, packets whose source address is the IP address of the target UE are allowed to pass, and a blocking notification is sent to the network switching device. The blocking notification includes the IP address of the target UE and is used to indicate that packets whose source address is the IP address of the target UE are blocked. The network switching device is used to allow or block packets of the UE accessing the second network through the mobile communication network.
2. The method as described in claim 1, characterized in that, The process of obtaining the online message includes: The system receives an authentication request sent by a network device in the mobile communication network. The authentication request includes the UE identifier of the target UE and is used to request authentication of the target UE's permission to access the first network. Forward the authentication request to the authentication system of the first network; Receive the online message returned by the authentication system.
3. The method as described in claim 2, characterized in that, When the IP address of the target UE is the IP address assigned to the target UE by the mobile communication network, the authentication request also includes the IP address assigned to the target UE by the mobile communication network.
4. The method according to any one of claims 1 to 3, characterized in that, The online message and / or the blocking notification also include the UE identifier of the target UE, which is used to trace and count the messages sent by the target UE.
5. The method according to any one of claims 1 to 4, characterized in that, Sending a blocking notification to the network switching device includes: The blocking notification is sent to the network switching device based on the Syslog protocol or a proprietary protocol.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: It is determined that the target UE stops accessing the first network; Send a release notification to the network switching device. The release notification includes the IP address of the target UE and is used to indicate that a packet whose source address is the IP address is allowed.
7. The method as described in claim 2 or 4, characterized in that, The UE identifier is any one of the International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), or International Integrated Services Digital Network (ISDN) Number (MSISDN).
8. The method according to any one of claims 1 to 7, characterized in that, The mobile communication network in question is a 5G network, which is the fifth generation of mobile communication technology.
9. The method according to any one of claims 1 to 8, characterized in that, The first network is an enterprise network, and the second network is the Internet.
10. A method for controlling message transmission, characterized in that, An application is made in a network switching device, the network switching device being used to allow or block messages from a user equipment (UE) accessing a second network through a mobile communication network, wherein the UE also accesses a first network through the mobile communication network, the method comprising: Receive a blocking notification sent by the gateway of the first network, the blocking notification including the Internet Protocol IP address of the target UE; In response to the blocking notification, packets destined for the second network whose source address is the IP address of the target UE are blocked.
11. The method as described in claim 10, characterized in that, The step of receiving the blocking notification sent by the gateway of the first network includes: Receive the blocking notification sent by the gateway based on the Syslog protocol or a private protocol.
12. The method as described in claim 10 or 11, characterized in that, The blocking notification also includes the UE identifier of the target UE, which is used to trace and statistically analyze the messages sent by the target UE.
13. The method according to any one of claims 10 to 12, characterized in that, The method further includes: Receive a clearance notification sent by the gateway, the clearance notification including the IP address of the target UE; In response to the release notification, packets destined for the second network and whose source address is the IP address of the target UE are allowed to pass.
14. The method according to any one of claims 10 to 13, characterized in that, The blocking notification includes a UE identifier that is any one of the International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), or International Integrated Services Digital Network (ISDN) Number (MSISDN).
15. The method according to any one of claims 10 to 14, characterized in that, The network switching device is deployed as a separate device at the boundary between the mobile communication network and the second network.
16. The method according to any one of claims 10 to 15, characterized in that, The network switching device is deployed in the core network of the mobile communication network, and the network switching device communicates with the first network via a first User Plane Function (UPF) device in the core network, and the network switching device communicates with the second network via a second UPF device in the core network; or, the network switching device is deployed in the second UPF device.
17. A control device for message transmission, characterized in that, The device is applied to a gateway deployed at the edge of a first network, and includes: An acquisition unit is used to acquire an online message, wherein the online message indicates that the target user equipment (UE) has successfully authenticated its access to the first network, the target UE accesses the first network through a mobile communication network, and the online message includes the Internet Protocol (IP) address of the target UE. The processing unit is configured to, in response to the online message, allow packets whose source address is the IP address of the target UE to pass through; The sending unit is configured to send a blocking notification to the network switching device in response to the online message. The blocking notification includes the IP address of the target UE and is used to indicate that the blocking source address is the IP address of the target UE. The network switching device is configured to allow or block packets of the UE accessing the second network through the mobile communication network.
18. The apparatus as claimed in claim 17, characterized in that, The device further includes: A receiving unit is configured to receive an authentication request sent by a network device in the mobile communication network. The authentication request includes the UE identifier of the target UE and is used to request authentication of the target UE's permission to access the first network. The sending unit is also configured to forward the authentication request to the authentication system of the first network; The acquisition unit is specifically used to receive the online message returned by the authentication system.
19. The apparatus as claimed in claim 17 or 18, characterized in that, The processing unit is further configured to determine that the target UE stops accessing the first network; The sending unit is further configured to send a release notification to the network switching device, the release notification including the IP address of the target UE, and the release notification being used to indicate that the source address of the packet is the IP address.
20. A control device for message transmission, characterized in that, An application is provided in a network switching device, which allows or blocks messages from a user equipment (UE) accessing a second network through a mobile communication network, wherein the UE also accesses a first network through the mobile communication network. The device comprises: A receiving unit is configured to receive a blocking notification sent by the gateway of the first network, the blocking notification including the Internet Protocol (IP) address of the target UE. The processing unit is configured to, in response to the blocking notification, block packets destined for the second network whose source address is the IP address of the target UE.
21. The apparatus as claimed in claim 20, characterized in that, The receiving unit is further configured to receive a clearance notification sent by the gateway, the clearance notification including the IP address of the target UE; The processing unit is further configured to, in response to the release notification, release a packet destined for the second network whose source address is the IP address of the target UE.
22. A control device for message transmission, characterized in that, include: The device includes a memory, a network interface, and one or more processors, the one or more processors receiving or transmitting data through the network interface, the one or more processors being configured to read program instructions stored in the memory to perform the method as claimed in any one of claims 1 to 9 or 10 to 16.
23. A message transmission control system, characterized in that, The control system includes a network switching device and a gateway for a first network. The network switching device is used to allow or block user equipment (UE) messages from accessing a second network through the mobile communication network. The UE also accesses the first network through the mobile communication network. The gateway is configured to acquire an online message indicating that the target UE has successfully authenticated its access to the first network, the online message including the Internet Protocol (IP) address of the target UE; and to respond to the online message by allowing packets whose source address is the IP address of the target UE to pass through, and sending a blocking notification to the network switching device, the blocking notification including the IP address of the target UE. The network switching device is used to receive the blocking notification and, in response to the blocking notification, block packets whose source address is the IP address of the target UE.
24. The system as described in claim 23, characterized in that, The gateway is further configured to determine that the target UE stops accessing the first network; and to send a permission notification to the network opening / closing device, the permission notification including the IP address of the target UE; The network switching device is further configured to receive the release notification and, in response to the release notification, release a packet destined for the second network whose source address is the IP address of the target UE.
25. A message transmission control system, characterized in that, The control system includes a network switching device and a gateway for a first network, the gateway being used to perform the method as described in any one of claims 1 to 9, and the network switching device being used to perform the method as described in any one of claims 10 to 16.
26. A computer program product containing instructions, characterized in that, When the instructions are executed by a computing device or processor, the computing device or processor performs the method as claimed in any one of claims 1 to 9 or 10 to 16.
27. A computer-readable storage medium, characterized in that, It includes computer program instructions that, when executed by a computing device or processor, perform the method as claimed in any one of claims 1 to 9 or 10 to 16.