Controllable terminal access to ePDG implementation method

By persistently storing and forcibly distributing the terminal's PGW address in the HSS, and combining this with matching the local PGW list of the ePDG, the problem of terminals accessing the ePDG from the nearest location is solved, enabling controllable and low-latency access for operators and reducing transformation costs.

CN120957204BActive Publication Date: 2026-02-03IPLOOK NETWORKS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511476945.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-16
Publication Date
2026-02-03
Estimated Expiration
2045-10-16

AI Technical Summary

Technical Problem

In existing technologies, terminals cannot effectively access the nearest location when selecting ePDG, resulting in cross-regional access problems that cannot be controlled by operators and rely on the Tracking Area Code (TAC) carried by the terminal to achieve uncertainty.

Method used

By persistently storing the terminal's local PGW address in the HSS and forcibly sending it to the ePDG during WLAN access, the ePDG has a pre-set local PGW list. If a match is found, a session is created; otherwise, access is rejected. The IKEv2 protocol is used to trigger the terminal to reselect another ePDG, thus achieving controllable proximity access on the operator's side.

Benefits of technology

It enables operators to have complete control over the nearest ePDG access for terminals, reduces transmission latency, and eliminates the need to modify terminals or DNS infrastructure, saving approximately 30% of the cost of existing network upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120957204B_ABST
    Figure CN120957204B_ABST
Patent Text Reader

Abstract

The application relates to an implementation method of controllable terminal access to an ePDG, which is used for solving the cross-region access problem caused by the terminal not carrying a tracking area code (TAC) in a VoWiFi scene. The method stores the local PGW address of the terminal by a HSS when the terminal accesses in LTE; the HSS forces to issue the PGW address to the ePDG when the terminal accesses through WLAN; the ePDG presets a local PGW list, and decides whether to create a session by matching the issued PGW address with the list; if the PGW address matches the list, the connection is established; otherwise, the terminal is triggered to reselect other ePDGs by carrying a "PND connection rejection" reason value through an IKEv2 protocol. The method actively controls the PGW address distribution and verification on the operator side, realizes the terminal access to the ePDG, does not need to depend on the terminal behavior or TAC information, effectively reduces the time delay, and improves the load balancing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information transmission, in particular to an implementation method of controllable terminal access to ePDG. BACKGROUND

[0002] VoWiFi (Voice over Wi-Fi) is a technology for transmitting voice calls through a wireless local area network (WLAN). In simple terms, it is a way of converting traditional mobile calls into calls made over a Wi-Fi network. With the support of VoWiFi, a user's mobile phone or other mobile device can use network data to make voice calls when connected to a Wi-Fi network, without relying on the cellular network of a mobile operator.

[0003] Disadvantages of the prior art: In the current vowifi network deployment, ePDG is deployed in different regions according to the geographical and population distribution. In order to reduce the latency and load balancing, it is usually desired that the terminal accesses the ePDG in the local area. The common method is that the terminal uses the FQDN carrying the tracking area code (TAC) to perform DNS query when selecting the ePDG, and the ePDG address in the region is carried by the response of the DNS server to realize the terminal access to the ePDG in the local area. However, whether the terminal carries the tracking area code depends largely on the implementation of the terminal manufacturer, and the operator cannot control the use of what type of mobile phone by the user. Therefore, this method cannot achieve the purpose of accessing the ePDG in the local area in actual deployment. SUMMARY

[0004] In order to solve the above-mentioned problems existing in the prior art, the present application aims to provide an implementation method of controllable terminal access to ePDG. The solution proposed by the present application for the above-mentioned shortcomings of the prior art is that the HSS persistently stores the local PGW address of the terminal when the terminal accesses LTE, and the PGW address is forced to be issued to the ePDG when the terminal accesses WLAN. The ePDG is preconfigured with a local PGW list, and the PGW address issued by the HSS is compared. If the PGW address is matched, a session is created, otherwise the access is rejected. The "PND connection rejection" reason value is carried through the IKEv2 protocol to trigger the terminal to reselect other ePDG, so as to realize the controllable access to the ePDG in the local area on the operator side, without relying on the terminal behavior, and solve the problem of cross-region access caused by the terminal not carrying TAC information in the traditional DNS resolution.

[0005] The implementation method of controllable terminal access to ePDG according to the present application comprises the following steps:

[0006] Step S101, terminal position information collection: the terminal accesses the LTE network through the base station, and the base station sends a signaling message carrying a tracking area identifier (TAI) to the MME.

[0007] Step S102: Local PGW selection and registration: The MME generates an FQDN containing TAC and PLMN based on TAI, selects a local PGW for the terminal through DNS query, and registers the PGW address and APN to HSS persistent storage.

[0008] Step S103: After the terminal connects to WiFi, the ePDG access request obtains multiple ePDG addresses through DNS resolution, selects one, and initiates a WLAN untrusted access request.

[0009] Step S104: PGW information transmission via ePDG in the authentication process, forcibly obtains the PGW address registered by the terminal on the LTE side from HSS (HSS enhancement point: persistent storage and forced delivery).

[0010] Step S105: The nearest access point is determined by comparing the received PGW address with the preset local PGW list through ePDG. If they match, proceed to step S106; otherwise, proceed to step S107.

[0011] Step S106: During session establishment, the ePDG uses the PGW address to create a session, allowing the terminal to perform vowifi service through the current ePDG;

[0012] In step S107, the ePDG sends an IKEv2Notify Payload carrying the cause value PND (connection rejection) to the terminal, triggering the terminal to reselect another ePDG.

[0013] Preferably, in step S101, the terminal initiates an access request, the base station verifies the identity and obtains access authorization. After authorization, the base station generates a signaling message containing a tracking area identifier, determines the format, and forwards it to the mobility management entity to obtain transmission confirmation. The mobility management entity parses the identifier, determines the terminal's location, updates the terminal's tracking area record and obtains the update status. Based on this, the mobility management entity returns a location confirmation to the base station to determine the terminal's location. Finally, the mobility management entity uses this location information to send location data to the network core to complete data synchronization.

[0014] Preferably, in step S102, the terminal initiates an access request, the base station verifies the identity and obtains access authorization. When the authorization is valid, the base station generates a fully qualified domain name (FQDN) by combining the tracking area code and the public land mobile network identifier. It obtains a valid local packet gateway address by querying the domain name through DNS. The mobility management entity selects a packet gateway based on this address and generates an access point name (APN). Subsequently, the mobility management entity sends a registration request to the home subscriber server (HSS) to store the PGW address and APN. After the HSS successfully stores the information, it returns a registration confirmation. The mobility management entity parses the confirmation and updates the terminal's local PGW configuration. Finally, the mobility management entity sends the PGW address and APN to the network core to complete data synchronization.

[0015] Preferably, in step S103, the terminal generates a domain name query request containing the access point identifier based on the WiFi status, obtains multiple ePDG address lists through DNS resolution, compares address priorities according to preset rules, selects the highest one, and then sends an untrusted WLAN access request containing the terminal and access point identifiers to the ePDG. The ePDG generates an authentication request based on this and sends it to the authentication server. After receiving the result, the ePDG uses the K-nearest neighbor algorithm to verify the matching degree between the terminal identifier and the whitelist and determines the authentication status. If successful, the ePDG allocates session resources and generates a session identifier based on the access point identifier. Finally, the ePDG sends the session identifier and access confirmation to the terminal through an encrypted channel to obtain its connection confirmation.

[0016] Preferably, in step S104, the ePDG generates a query request based on the terminal identifier and sends it to the HSS to obtain the PGW address registered by the terminal in the LTE network. The HSS receives the request, parses the identifier, and queries the database to obtain the PGW address. If the address is not empty, it returns the address to the ePDG through an encrypted channel. After receiving the address, the ePDG uses a consistent hash algorithm to verify the validity of the address. If valid, the ePDG generates a session initialization request (including the terminal identifier and PGW address) and sends it to the PGW. If the session initialization is successful, the ePDG sends session confirmation information to the terminal through an encrypted channel. After receiving the connection confirmation from the terminal, the ePDG allocates session resources, generates a session identifier, and determines the session establishment status.

[0017] Preferably, in step S105, after receiving the PGW address, the ePDG queries the local PGW list to determine if the address exists. If it exists, it sends a session initialization request to the PGW. Upon success, the ePDG sends session confirmation information to the terminal through an encrypted channel. After receiving confirmation from the terminal, the ePDG uses a consistent hashing algorithm to allocate resources and generate a session identifier to establish a session. If the address does not exist, the ePDG queries the backup PGW list according to preset rules to obtain the address and sends a redirection request to the backup PGW. Upon successful redirection, the ePDG sends redirection confirmation information to the terminal through an encrypted channel to determine the connection status.

[0018] Preferably, in step S106, after receiving the PGW address, the ePDG queries the local PGW list to check its existence. If it exists, the ePDG generates a session initialization request based on the terminal identifier and sends it to the PGW. After receiving the response, the ePDG uses a consistent hashing algorithm to allocate resources and create a session ID. Subsequently, the ePDG sends the session ID and confirmation information to the terminal through an encrypted channel. If the terminal confirms successfully, the ePDG queries the service policy table to obtain the priority configuration and uses a weighted round-robin algorithm to allocate bandwidth resources. Finally, the ePDG sends the bandwidth allocation status to the terminal through an encrypted channel to determine the service connection status.

[0019] Preferably, in step S107, the ePDG generates an IKEv2 notification payload containing a rejection reason value and sends it to the terminal via an encrypted channel. If the terminal successfully receives the payload, it queries the gateway list to obtain available ePDG candidate addresses. The terminal uses a consistent hashing algorithm to select the highest priority gateway and sends a new connection request. The ePDG receiving the request queries the gateway status table to determine feasibility. If allowed, it generates a session initialization request based on the terminal identifier and sends it to the PGW. After receiving the response, the ePDG sends the session identifier to the terminal via an encrypted channel. If the terminal confirms success, the ePDG then allocates bandwidth resources according to the service policy table using a weighted round-robin algorithm to determine the terminal's service access status.

[0020] The controllable terminal access to the nearest ePDG method described in this application has the advantage that by persistently storing and forcibly distributing the terminal's PGW address on the LTE side through HSS, the ePDG actively verifies the matching, completely eliminating the dependence on the terminal manufacturer's implementation (whether or not it carries a TAC), and realizing the operator's complete control over the nearest access.

[0021] ePDG pre-configures a local PGW list, and combines terminal location data and geographical distance calculations to ensure that sessions are only established on PGWs within a threshold distance from the terminal, significantly reducing transmission latency.

[0022] No modifications to terminals or DNS infrastructure are required; only upgrades to HSS (supporting PGW address storage and forced distribution) and ePDG (pre-configured PGW list and matching logic) are needed, saving approximately 30% of the cost of existing network modifications. Attached Figure Description

[0023] Figure 1 This application describes a method for implementing controllable terminal access to ePDG based on proximity. Figure 1 ;

[0024] Figure 2 This application describes a method for implementing controllable terminal access to ePDG based on proximity. Figure 2 . Detailed Implementation

[0025] like Figures 1-2 As shown, the method for implementing controllable terminal access to ePDG according to this application includes the following steps:

[0026] like Figures 1-2 As shown, in step S101, the terminal location information is collected by accessing the LTE network through the base station, and the base station sends a signaling message carrying the Tracking Area Identifier (TAI) to the MME.

[0027] Furthermore, in step S101, the terminal device initiates an access request, the base station receives and verifies the terminal's identity, and obtains access authorization;

[0028] If access authorization is granted, the base station generates a signaling message containing the tracking area identifier and determines the message format;

[0029] According to the signaling message content, the base station forwards the tracking area identifier to the mobility management entity and receives a transmission confirmation;

[0030] The mobility management entity parses the tracking area identifier in the signaling message to determine the location of the terminal.

[0031] If the area location determination is completed, the mobility management entity updates the terminal's tracking area record and obtains the update status;

[0032] Based on the updated status, the mobility management entity returns area location confirmation to the base station to determine the terminal's location information;

[0033] Using the terminal's location information, the mobility management entity sends location data to the network core to achieve data synchronization.

[0034] Specifically, in step S101, the terminal accesses the base station through a communication module that supports the LTE protocol. The module automatically scans the frequency band (2600MHz) and selects the base station with the strongest signal strength (RSRP value -80dBm).

[0035] The access process adopts the standard LTE attach procedure, in which the terminal sends an attach request, including the IMSI (e.g., 901405123456789).

[0036] After receiving the request, the base station forwards the signaling message to the MME through the S1-MME interface. The message embeds the Tracking Area Identifier (TAI), such as TAI=460001234.

[0037] The base station uses the X2AP protocol to encapsulate signaling and adds a timestamp (accurate to milliseconds, such as 2025-07-22T23:18:45.123) to ensure timing consistency;

[0038] MME parses signaling, extracts TAI and queries the local database. The database stores the mapping between TAI and geographical region (e.g., 460001234 corresponds to Haidian District, Beijing).

[0039] MME uses an algorithm (based on the hash function of TAI, hash(TAI)=hash(460001234)mod 1024=512) to allocate the Tracking Area List (TAL), generating a list containing up to 8 TAIs (such as 460001234, 460001235, etc.).

[0040] MME then updates the terminal location record, which includes latitude and longitude (e.g., 39.9042, 116.4074) and timestamp;

[0041] If the terminal moves and causes a change in TAI, the base station detects the change in RSRP (e.g., drops to -90dBm), triggers a location update request, and the MME recalculates TAL and sends it through the S1 interface.

[0042] During the analysis, MME uses a location prediction algorithm (Kalman filter, input historical latitude and longitude sequence, output predicted location error <50 meters) to optimize network resource allocation, such as prioritizing the allocation of low-load base stations (load rate <60%).

[0043] If a terminal enters a high-load area, the MME selects a new base station using a load balancing algorithm (based on the number of base station connections, such as if the current number of connections is less than 500) to ensure service quality.

[0044] This process forms a closed loop, ensuring accurate collection and updating of location information.

[0045] In one embodiment, the definition of terms includes:

[0046] vowifi (Voice over Wi-Fi): A technology that transmits voice calls over a wireless local area network (WLAN);

[0047] ePDG (evolved Packet Data Gateway): An evolved packet data gateway;

[0048] UE (User Equipment): User equipment, also known as a terminal;

[0049] LTE (Long Term Evolution): LTE is a fourth-generation (4G) radio access technology defined by 3GPP, designed to improve data transmission rates, reduce latency, and optimize spectrum efficiency;

[0050] EPC (Evolved Packet Core): EPC is the core network part of LTE, responsible for functions such as user data routing, mobility management, and session management.

[0051] like Figures 1-2 As shown, in step S102, the local PGW selection and registration generates an FQDN containing TAC and PLMN based on TAI through MME, selects a local PGW for the terminal through DNS query, and registers the PGW address and APN to HSS persistent storage.

[0052] Further, in step S102, the terminal initiates an access request, and the base station obtains access authorization through terminal authentication and determines the authorization status;

[0053] If the authorization status is valid, the base station generates a fully qualified domain name based on the tracking area code and the public land mobile network identifier, and obtains the domain name data;

[0054] The domain name system is used to query domain name data, obtain the local packet gateway address, and determine the validity of the address;

[0055] The mobility management entity selects a packet gateway based on the local packet gateway address, generates an access point name, and obtains name data.

[0056] The mobility management entity sends a registration request to the home subscriber server based on the name data, persistently stores the packet gateway address and access point name, and obtains the storage status;

[0057] If the storage status is successful, the home user server generates a registration confirmation based on the registration request, sends it to the mobility management entity, and receives the confirmation data.

[0058] The mobility management entity parses and confirms the data, updates the terminal's local packet gateway configuration, and determines the configuration status;

[0059] Based on the configuration status, the mobility management entity sends the packet gateway address and access point name to the network core to obtain the data synchronization status.

[0060] Specifically, in step S102, when the terminal registers through the LTE network, the MME uses the terminal's tracking area identifier (TAI, such as 460001567).

[0061] Generate a fully qualified domain name (FQDN) containing a tracking area code (TAC, such as 12345) and a public land mobile network identifier (PLMN, such as 46000), in the following format:

[0062] "tac12345.plmn46000.epc.mnc460.mcc00.3gppnetwork.org";

[0063] The MME queries the FQDN through the Domain Name System (DNS) to resolve the IP address of the local packet gateway (PGW) (e.g., 192.168.10.10).

[0064] The DNS query uses a recursive resolution algorithm. The MME first sends a request to the local DNS server (address 10.0.0.1). The server queries the global 3GPP network database and returns the PGW (geographical distance < 10 km, calculated based on latitude and longitude, such as the Euclidean distance between 39.9042, 116.4074 and PGW location 39.9050, 116.4080) that is closest to the terminal.

[0065] After the MME selects the PGW, it registers the PGW address and access point name (APN, such as “internet.mnc460.mcc00”) with the Home Subscription Server (HSS) through the S6a interface.

[0066] HSS uses a key-value store database (such as Redis) to persistently store the PGW address, APN, and registration timestamp (such as 2025-07-22T23:20:15.456) using the terminal's International Mobile Subscriber Identity (IMSI, such as 901405987654321) as the key.

[0067] The registration process uses the SHA-256 algorithm to generate a verification value (e.g., hash(IMSI+APN)=a1b2c3d4) to ensure data integrity.

[0068] If a DNS query returns multiple PGW addresses, the MME selects the optimal PGW using a load balancing algorithm (based on the current number of PGW sessions, such as <1000).

[0069] If the PGW load exceeds 80%, the MME will re-initiate a DNS query to resolve the backup PGW address (e.g., 192.168.10.11). After the HSS is updated, the registration will be confirmed as successful via the Diameter protocol (message type Update-Location-Answer), carrying a confirmation timestamp (e.g., 2025-07-22T23:20:15.789).

[0070] This process ensures that terminals can access the local PGW and complete registration through automated signaling interaction, supporting services such as low-latency data transmission.

[0071] like Figures 1-2 As shown in step S103, after the ePDG access request connects to WiFi via the terminal, it obtains multiple ePDG addresses through DNS resolution, selects one of them, and initiates a WLAN untrusted access request.

[0072] Further, in step S103, the terminal generates a domain name query request containing the access point identifier based on the WiFi network connection status, sends it to the Domain Name System, resolves it to obtain multiple Evolved Packet Data Gateway addresses, and determines the address list;

[0073] Based on the address list, the terminal applies preset rules, compares the priorities of multiple Evolved Packet Data Gateway addresses, selects the address with the highest priority, and determines the selected address.

[0074] The terminal generates an untrusted wireless LAN access request based on the selected address, which includes the terminal identifier and the access point identifier, and sends it to the evolved packet data gateway to obtain the access request status.

[0075] If the access request status is successful, the Evolved Packet Data Gateway generates an authentication request based on the terminal identifier, sends it to the authentication server, and obtains the authentication result.

[0076] Based on the authentication results, the Evolved Packet Data Gateway uses the K-Nearest Neighbor algorithm to verify the degree of matching between the terminal identifier and the preset whitelist, and determines the authentication pass status.

[0077] If the authentication pass status is true, the Evolved Packet Data Gateway allocates session resources, generates a session identifier, and determines the session establishment status based on the access point identifier.

[0078] Based on the session establishment status, the evolved packet data gateway sends a session identifier and access confirmation to the terminal through an encrypted channel to obtain the terminal's connection confirmation status.

[0079] Specifically, in step S103, when the terminal initiates untrusted access through the WiFi network, it first detects the WiFi signal (SSID such as "PublicWiFi_001", signal strength -65dBm) and obtains the local DNS server address (such as 172.16.0.1).

[0080] The terminal generates the fully qualified domain name (FQDN) of the ePDG according to the device configuration, in the format of "epdg.mnc460.mcc00.3gppnetwork.org";

[0081] The terminal sends a query request to the DNS server, which uses an iterative resolution algorithm. The DNS server starts from the root server and queries the authoritative servers level by level, eventually returning three ePDG addresses (192.168.20.1, 192.168.20.2, and 192.168.20.3).

[0082] The terminal uses a weighted round-robin algorithm to select the ePDG. The weights are based on the ePDG's response time (20ms, 25ms, and 30ms respectively). The calculation formula is weight = 1 / response time, resulting in weight values ​​of 0.05, 0.04, and 0.033. The terminal selects the ePDG with the shortest response time, 192.168.20.1.

[0083] The terminal initiates an access request via the IKEv2 protocol, carrying the International Mobile Subscriber Identity (IMSI, such as 901405123456789) and the Access Point Name (APN, such as “wlan.mnc460.mcc00”).

[0084] After receiving the request, ePDG verifies the IMSI through the AAA server and generates an authentication vector (key K=xyz789, authentication token=5f6g7h8i) using the HMAC-SHA-256 algorithm to ensure the integrity of the request;

[0085] After successful authentication, ePDG assigns an IP address (10.10.10.100) and establishes an IPSec tunnel. The tunnel parameters include the AES-256 encryption algorithm and a time-to-live (TTL) of 7200 seconds.

[0086] ePDG registers terminal information with the AAA server through the SWm interface, stores IMSI, IP address and timestamp (2025-07-22T23:30:22.123), and uses MongoDB database to persist the data;

[0087] If the ePDG load exceeds 75% (current session count > 1500), the terminal re-initiates a DNS query and selects the suboptimal address 192.168.20.2;

[0088] The AAA server returns an acknowledgment message (message type Authentication-Answer) via the Diameter protocol, carrying a timestamp (2025-07-22T23:30:22.456).

[0089] The entire process is completed through automated signaling interaction to enable terminal access.

[0090] like Figures 1-2 As shown, in step S104, PGW information is transmitted through ePDG during the authentication process, forcibly obtaining the PGW address registered by the terminal on the LTE side from the HSS (HSS enhancement point: persistent storage and forced distribution).

[0091] Further, in step S104, the evolved packet data gateway generates a query request based on the terminal identifier, sends it to the home subscription server, obtains the packet data gateway address registered by the terminal on the Long Term Evolution network side, and determines the query result;

[0092] The home subscription server receives the query request, parses the terminal identifier, uses a database query to retrieve the preset terminal registration information database, and obtains the corresponding packet data gateway address;

[0093] If the packet data gateway address is not empty, the home subscription server returns the packet data gateway address to the evolved packet data gateway through an encrypted channel to determine the address transmission status.

[0094] The evolved packet data gateway receives the packet data gateway address, uses a consistent hashing algorithm to verify the degree of matching between the address and the terminal identifier, and determines the validity of the address;

[0095] Based on the address validity, the evolved packet data gateway generates a session initialization request, which includes the terminal identifier and the packet data gateway address, and sends it to the packet data gateway to obtain the session initialization status.

[0096] If the session initialization status is successful, the Evolved Packet Data Gateway sends session confirmation information to the terminal through an encrypted channel to obtain the terminal's connection confirmation status.

[0097] Based on the connection confirmation status, the evolved packet data gateway allocates session resources, generates a session identifier, and determines the session establishment status.

[0098] Specifically, in step S104, after the terminal completes the initial connection through the WiFi network, the ePDG needs to obtain the PGW address registered by the terminal on the LTE side from the HSS to ensure seamless handover.

[0099] ePDG receives authentication requests sent by the terminal through the SWu interface, carrying IMSI (e.g., 901408987654321) and APN (e.g., "lte.mnc460.mcc00").

[0100] ePDG uses the Diameter protocol to send a Server-Assignment-Request to HSS via the SWx interface. The request includes IMSI and APN. HSS queries its Redis database, which stores key-value pairs (IMSI: 901408987654321, PGW address: 172.16.10.10).

[0101] HSS looks up the PGW address based on the IMSI. If no record is found, the default PGW address 172.16.10.11 is used.

[0102] HSS selects the primary PGW node using a consistent hashing algorithm. The calculation formula is hash(IMSI) mod N (N=3, the number of PGW nodes), resulting in node index 1, corresponding to 172.16.10.10.

[0103] HSS forcibly sends a PGW address, with a timestamp (2025-07-22T23:45:12.789) and a validity period of 3600 seconds;

[0104] After receiving the Server-Assignment-Answer message, ePDG verifies the message integrity and generates a check value using the SHA-256 algorithm (key K=abc123, check token=7h8i9j0k).

[0105] If the verification passes, the ePDG updates the terminal context to the AAA server via the SWm interface, including the IMSI, PGW address, and encryption parameters (AES-128, time to live 5400 seconds).

[0106] The AAA server stores the information in a MySQL database, with the following table structure:

[0107] (IMSI, PGW_IP, Timestamp), recorded as: (901408987654321, 172.16.10.10, 2025-07-22T23:45:12.789).

[0108] If the PGW load exceeds 80% (number of sessions > 2000), the ePDG will re-request the suboptimal PGW address 172.16.10.12 from the HSS via the Diameter protocol, and repeat the above process.

[0109] The entire process is completed through automated signaling interaction, ensuring accurate transmission of PGW addresses.

[0110] like Figures 1-2 As shown, in step S105, the nearest access point is determined by comparing the received PGW address with the preset local PGW list through ePDG. If they match, step S106 is executed; otherwise, step S107 is executed.

[0111] Further, in step S107, the evolved packet data gateway receives the packet data gateway address, uses a database query to retrieve a preset local packet data gateway list, determines whether the address exists in the list, and obtains the address matching status;

[0112] If the address matching status is present, the evolved packet data gateway generates a session initialization request based on the terminal identifier, sends it to the packet data gateway, and obtains the session initialization status.

[0113] Based on the session initialization state, the Evolved Packet Data Gateway sends session confirmation information to the terminal through an encrypted channel to obtain the connection confirmation state;

[0114] If the connection confirmation status is successful, the Evolved Packet Data Gateway uses the consistent hashing algorithm to allocate session resources, generate session identifiers, and determine the session establishment status.

[0115] If the address matching status is not found, the evolved packet data gateway will use the preset address redirection rules to query the list of backup packet data gateways and obtain the backup packet data gateway address.

[0116] Based on the backup packet data gateway address, the evolved packet data gateway generates a redirection request, sends it to the backup packet data gateway, and obtains the redirection confirmation status.

[0117] If the redirection confirmation status is successful, the Evolved Packet Data Gateway sends a redirection confirmation message to the terminal through an encrypted channel to determine the terminal's connection status.

[0118] Specifically, in step S105, after the ePDG receives the PGW address (such as 192.168.20.5) issued by the HSS, it needs to compare it with the locally preset PGW address list to determine whether to execute the nearest access point logic.

[0119] The local list is stored in ePDG's in-memory database as a JSON array, containing PGW addresses and geographic coordinates, for example:

[0120] [{"IP":"192.168.20.5","Lat":35.6895,"Lon":139.6917},{"IP":"192.168.20.6","Lat":34.6937,"Lon":135.5022}];

[0121] The ePDG uses a string matching algorithm to check if 192.168.20.5 is in the list. If the match is successful, proceed to step S106: The ePDG calculates the geographical distance between the terminal location (based on the latitude and longitude reported by the WiFi access point, such as Lat:35.7000, Lon:139.7000) and the PGW address, using the Havesing formula. The calculation result is 1.2 kilometers, which is less than the threshold of 5 kilometers, so it is determined to access the nearest one. The ePDG sends a context update request to the AAA server through the SWm interface, which includes the IMSI (901408123456789), the PGW address (192.168.20.5), and the timestamp (2025-07-22T23:50:00.123).

[0122] If the match fails, proceed to step S107: ePDG sends a Location-Update-Request of the Diameter protocol to HSS, carrying the IMSI and terminal location. HSS reselects the PGW address (e.g., 192.168.20.7) according to the consistent hash algorithm (hash(IMSI)mod4, number of nodes N=4), and confirms its load (number of sessions 1500, less than the threshold of 2000) by querying Redis.

[0123] HSS returns a new PGW address, ePDG verifies message integrity using the HMAC-SHA-256 algorithm (key K=xyz789, generated verification token=9a1b2c3d).

[0124] After successful verification, ePDG updates its local cache, storing the new PGW address and its validity period of 7200 seconds;

[0125] The entire process is completed through automated signaling interaction, ensuring that the access point determination logic is rigorous.

[0126] like Figures 1-2 As shown, in step S106, during session establishment, the ePDG uses the PGW address to create a session, allowing the terminal to perform vowifi service through the current ePDG.

[0127] Further, in step S106, the evolved packet data gateway receives the packet data gateway address, queries the database to retrieve the preset local packet data gateway list, and obtains the address matching status;

[0128] If the address matching status is present, the evolved packet data gateway generates a session initialization request based on the terminal identifier, sends it to the packet data gateway, and obtains a session initialization response.

[0129] Based on the session initialization response, the Evolved Packet Data Gateway uses a consistent hashing algorithm to allocate session resources, generate session identifiers, and determine the session allocation status.

[0130] Through an encrypted channel, the evolved packet data gateway sends a session identifier and confirmation information to the terminal to obtain the terminal's connection confirmation status.

[0131] If the terminal connection confirmation status is successful, the evolved packet data gateway queries the pre-configured service policy table based on the session identifier to obtain the service priority configuration;

[0132] Based on the service priority configuration, the evolved packet data gateway uses a weighted round-robin algorithm to allocate network bandwidth resources and generate bandwidth allocation status.

[0133] Through an encrypted channel, the evolved packet data gateway sends bandwidth allocation status to the terminal to determine the terminal's service connection status.

[0134] Specifically, in step S106, during the session establishment process, after the ePDG receives the PGW address (such as 10.10.30.8) allocated by the HSS, it starts the VoWiFi session creation process;

[0135] First, ePDG negotiates an IPSec tunnel with the terminal via the IKEv2 protocol, using the Diffie-Hellman algorithm (2048-bit modulus, generating a shared key K=abc123).

[0136] After the negotiation is completed, ePDG obtains the IMSI (901405987654321) from the terminal and verifies its legality. By querying the local SQLite database, it confirms whether the IMSI exists in the list of authorized users (the list contains 10,000 records, and the query takes 0.02 seconds).

[0137] Subsequently, ePDG constructs a GRE tunnel to encapsulate data packets, sets the PGW address 10.10.30.8 as the tunnel endpoint, assigns an internal network IP (172.16.1.100) to the terminal, and limits the bandwidth to 50Mbps;

[0138] ePDG sends an authentication request to the AAA server via the RADIUS protocol, which includes IMSI, Tunnel ID (TID=789456) and timestamp (2025-07-22T23:55:00.456).

[0139] After the AAA server responds to the successful authentication, ePDG configures the session parameters according to the QoS requirements reported by the terminal (voice priority=5, latency threshold<150ms), and uses the Weighted Round-Robin algorithm to allocate bandwidth resources to ensure that voice data packets have higher priority than other traffic (queue weight ratio 3:1).

[0140] If the PGW load is too high (session count reaches 2500, threshold 2000), ePDG obtains an alternative PGW address (e.g., 10.10.30.9) through DNS resolution and uses the SHA-256 algorithm to verify message integrity (key K=def456, generated checksum = 5e4f6g7h).

[0141] After the session is established, ePDG updates the local Redis cache, stores the session ID (SID=123456789) and the validity period of 3600 seconds, and sends the session status (active connection count=1200) to the network management system via the SNMP protocol.

[0142] The entire process is completed through automated signaling interaction, ensuring efficient establishment of VoWiFi sessions.

[0143] like Figures 1-2 As shown, in step S107, when access is rejected and the ePDG is reselected, the terminal sends an IKEv2 Notify Payload carrying the cause value PND for connection rejection to the terminal, triggering the terminal to reselect another ePDG.

[0144] Further, in step S107, the Evolved Packet Data Gateway generates an IKEv2 notification payload containing a rejection reason value and sends it to the terminal through an encrypted channel to obtain the terminal's reception status.

[0145] If the terminal receives the data successfully, the terminal queries the preset gateway list based on the received rejection reason value, obtains the available Evolved Packet Data Gateway address, and determines the gateway candidate list.

[0146] The terminal uses a consistent hashing algorithm to select the highest priority Evolved Packet Data Gateway from the gateway candidate list, generates a new connection request, and obtains the request sending status.

[0147] The evolved packet data gateway receives connection requests from terminals, queries the preset gateway status table to obtain the gateway availability status, and determines the feasibility of the connection.

[0148] If the connection is feasible, the evolved packet data gateway generates a session initialization request based on the terminal identifier, sends it to the packet data gateway, obtains the session initialization response, and determines the session allocation status.

[0149] Based on the session allocation status, the evolved packet data gateway sends a session identifier to the terminal through an encrypted channel to obtain the terminal connection confirmation status and determine the service connection status.

[0150] If the service connection status is successful, the evolved packet data gateway obtains the bandwidth allocation priority according to the pre-set service policy table, uses a weighted round-robin algorithm to allocate network resources, and determines the terminal service access status.

[0151] Specifically, in step S107, when the ePDG detects that the terminal's VoWiFi access request needs to be rejected due to limited resources (such as the current number of active sessions reaching 1800, and the threshold being 1500), the ePDG sends a NotifyPayload to the terminal via the IKEv2 protocol, carrying the rejection reason value PND (a value of 47, indicating insufficient resources).

[0152] According to the local load balancing strategy, ePDG queries the MongoDB database (containing 5000 ePDG records, query time 0.015 seconds) to obtain the highest priority backup ePDG address (such as 10.20.40.7).

[0153] Subsequently, the ePDG constructs an IKEv2 message containing the backup ePDG address and uses the HMAC-SHA1 algorithm (key K=xyz789, generated checksum=8a9b0c1d) to ensure message integrity;

[0154] After receiving the rejection message, the terminal parses the Notify Payload, extracts the backup ePDG address, and initiates the reselection process;

[0155] ePDG sends a notification to HSS via the Diameter protocol, including the terminal IMSI (901405123456789), the rejection timestamp (2025-07-22T23:58:00.123), and the reason code;

[0156] HSS updates the terminal's access priority (from 3 to 2) based on historical records (85% success rate of the most recent 100 access attempts).

[0157] At the same time, ePDG uses the consistent hashing algorithm to redistribute terminals to the new ePDG (node ​​hash value = 0x5f3e2d1c) to ensure load balancing (target node session count < 1000).

[0158] To prevent reselection failure, the ePDG sends a pre-allocation request to the standby ePDG via a Kafka message queue, which includes the terminal identifier and the expected bandwidth requirement (20Mbps).

[0159] After the backup ePDG responds, the ePDG updates the local Memcached cache, recording the reselection event ID (RID=987654321) and the validity period of 1800 seconds;

[0160] The entire process is completed through automated signaling interaction, ensuring that the terminal quickly switches to an available ePDG.

[0161] For those skilled in the art, various other corresponding changes and modifications can be made based on the technical solutions and concepts described above, and all such changes and modifications should fall within the protection scope of the claims of this application.

Claims

1. A method for controllable terminal access to ePDG from the nearest location, characterized in that, Includes the following steps: Step S101: Terminal location information is collected by accessing the LTE network through the base station. The base station sends a signaling message carrying the Tracking Area Identifier (TAI) to the MME to transmit the location information. Step S102: Based on the TAI, the MME generates an FQDN containing TAC and PLMN, selects a local PGW for the terminal through DNS query, and registers the selected PGW address and APN to HSS persistent storage. Step S103: After the terminal connects to WiFi, it obtains multiple ePDG addresses through DNS resolution, selects one, and initiates a WLAN untrusted access request to the selected ePDG. Step S104: In response to the access request, the ePDG forcibly obtains the PGW address stored in step S102 from the HSS during the authentication process. Step S105: ePDG compares the obtained PGW address with the preset local PGW list. If they match, proceed to step S106; otherwise, proceed to step S107. Step S106: The ePDG uses the PGW address to create a session, enabling the terminal to perform VoWiFi service through the current ePDG; Step S107: The ePDG sends an IKEv2 Notify Payload carrying the cause value PND (connection refused) to the terminal, triggering the terminal to reselect another ePDG.

2. The method for implementing controllable terminal access to ePDG according to claim 1, characterized in that, In step S102, HSS uses a key-value database to persistently store the PGW address and APN with IMSI as the key, and the storage process generates a SHA-256 checksum.

3. The method for implementing controllable terminal access to ePDG according to claim 1, characterized in that, In step S103, the terminal selects the ePDG using a weighted round-robin algorithm. The weight calculation formula is: weight = 1 / response time.

4. The method for implementing controllable terminal access to ePDG according to claim 1, characterized in that, The address matching determination in step S105 includes geographical distance verification: ePDG calculates the Havesing distance between the terminal location and the PGW; If the distance is less than the preset threshold, proceed to step S106; otherwise, proceed to step S107.

5. The method for implementing controllable terminal access to ePDG according to claim 1, characterized in that, The session establishment in S106 includes: The IPSec tunnel is negotiated using the IKEv2 protocol, and a shared key is generated using the Diffie-Hellman algorithm. The Weighted Round-Robin algorithm is used to allocate bandwidth resources based on voice priority.

6. The method for implementing controllable terminal access to ePDG according to claim 1, characterized in that, The reselection process in step S107 includes: ePDG queries the MongoDB database for the backup ePDG address; Send an IKEv2 message carrying a backup ePDG address to the terminal. The message uses the HMAC-SHA1 algorithm to generate a checksum.

7. The method for implementing controllable terminal access to ePDG according to claim 1, characterized in that, In step S105, a pre-set local PGW list is stored in the ePDG memory database in JSON format, containing the PGW's IP address and latitude and longitude coordinates.

Citation Information

Patent Citations

  • Method and device for selecting gateways

    CN102781004A

  • Node selection in network transitions

    US20160037328A1