Data transmission method and device of application layer and communication system
By receiving user session establishment requests, obtaining user identification information and querying subscription information, determining data service processing strategies, and utilizing network authentication mechanisms to ensure permission security from the underlying level, the problem of application layer permission management being vulnerable to attacks is solved, and secure transmission and access to application data are achieved.
Patent Information
- Application Number
- CN202511276319.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-12-12
AI Technical Summary
Existing application-layer access control is vulnerable to hacker attacks, leading to sensitive data leaks and abuse of system resources, resulting in insufficient security.
By receiving user session establishment requests, obtaining user identification information, querying subscription information from third-party network functions, determining user data service processing strategies based on subscription information, and ensuring access security from the underlying layer through network authentication mechanisms.
It reduces the risk of unauthorized access and data leakage, ensures accurate determination of user permissions and secure and efficient data transmission, and achieves security of application data during transmission and access.
Smart Images

Figure CN121125221A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of application permission management, and particularly relates to a data transmission method and device of an application layer and a communication system. BACKGROUND
[0002] With the rapid development of information technology, various application programs have been deeply integrated into various fields of production and life. Under this background, application permission management, as a key link to ensure data security, rationally allocate system resources and realize personalized services, is increasingly important. A reasonable permission allocation mechanism needs to dynamically adjust the permission range according to user identity, use scenario, device state and other multi-dimensional factors to ensure the security and efficiency of application running.
[0003] Currently, the permission management scheme of mainstream applications is mostly implemented at the application layer. However, the application layer permission management highly depends on the code integrity of the application program itself. If the application has logical vulnerabilities or is subjected to external malicious attacks, the permission control mechanism is easy to be bypassed or tampered with, resulting in security risks such as sensitive data leakage and system resource abuse.
[0004] Therefore, finding an application layer data transmission method that ensures the security of application data in the transmission and access process has become a current research hotspot. SUMMARY
[0005] The present application provides a data transmission method and device of an application layer and a communication system, which realizes the security of application data in the transmission and access process.
[0006] The present application provides a data transmission method of an application layer, which is applied to a first network function, and the method comprises the following steps: receiving a user session establishment request, wherein the user session establishment request comprises user identification information; sending a subscription information acquisition request to a third network function, wherein the subscription information acquisition request comprises the user identification information; receiving user data service subscription information corresponding to the user identification information fed back by the third network function, wherein the user data service subscription information is used to represent service subscription information of a user to application layer data; determining a user data service processing strategy based on the user data service subscription information, and sending the user data service processing strategy to a second network function.
[0007] According to the application, the method further comprises: sending a data service policy request to a policy control function, the data service policy request carrying the user identifier information and at least part of the user data service subscription information; receiving user data service policy information corresponding to the user identifier information fed back by the policy control function; and determining the user data service processing policy based on the user data service subscription information and the user data service policy information corresponding to the user identifier information.
[0008] According to the application, the subscription information acquisition request further comprises at least one of time information, location information and a data network name (DNN).
[0009] According to the application, the user data service subscription information comprises at least one of a user authority level, accessible data groups and service types.
[0010] According to the application, the at least part of the user data service subscription information comprises a user authority level and service requirement information.
[0011] According to the application, the user data service policy information comprises at least one of quality of service (QoS) parameters and slice configuration information.
[0012] According to the application, the user data service processing policy comprises at least one of user service authority, quality of service (QoS) parameters of data service and slice configuration information.
[0013] The application further provides a data transmission method at an application layer, applied to a second network function, the method comprising: receiving a user data service processing policy sent by a first network function, the user data service processing policy being determined by the first network function based on user data service subscription information after receiving a user session establishment request; and controlling execution of a user data service processing step based on the user data service processing policy.
[0014] According to the application, the user data service processing policy comprises at least one of user service authority, quality of service (QoS) parameters of data service and slice configuration information.
[0015] According to the application, the method further comprises: sending a session user session establishment response to the user equipment before the step of controlling execution of the user data service processing based on the user data service processing policy.
[0016] According to the application, the user data service processing policy comprises at least one of a user service permission, a quality of service (QoS) parameter of the data service, and slice configuration information.
[0017] According to the application, the step of generating the user data service acquisition request and sending the application server comprises any one of the following: generating an IP data packet comprising the user data service acquisition request, and sending the IP data packet to the application server, wherein a selection field of the IP data packet comprises the user service permission; or generating an application layer protocol data packet comprising the user data service acquisition request, and sending the application layer protocol data packet to the application server, wherein an extension header of the application layer protocol data packet comprises the user service permission.
[0018] According to the application, the step of receiving the user data service response fed back by the application server comprises any one of the following: receiving the user data service response fed back by the application server through a transmission tunnel matched with the user service permission; or receiving an IP data packet fed back by the application server, wherein the IP data packet comprises the user data service response, and a selection field of the IP data packet comprises the user service permission; or receiving an application layer protocol data packet fed back by the application server, wherein the application layer protocol data packet comprises the user data service response, and an extension header of the application layer protocol data packet comprises the user service permission.
[0019] According to the application, the method further comprises: sending a data service response to the user equipment, wherein the data service response carries the user service data.
[0020] According to the application, the method for data transmission at the application layer further comprises: adjusting the sending parameters of the user data service obtaining request and the data service response according to at least one of the user service permission, the quality of service (QoS) parameter of the data service, and the slice configuration information after the user data service processing step is controlled to be executed based on the user data service processing policy.
[0021] The application further provides a method for data transmission at the application layer, applied to a third network function, and the method comprises the following steps: receiving a subscription information obtaining request sent by a first network function, wherein the subscription information obtaining request comprises user identifier information; generating user data service subscription information corresponding to the user identifier information based on the subscription information obtaining request, and feeding back the user data service subscription information to the first network function, wherein the user data service subscription information is used to represent service subscription information of the user for application layer data.
[0022] According to the application, the user data service subscription information comprises at least one of a user permission level, an accessible data group, and a service type.
[0023] The application further provides a device for data transmission at the application layer, applied to a first network function, and the device comprises the following modules: a first receiving module, configured to receive a user session establishment request, wherein the user session establishment request comprises user identifier information; a sending module, configured to send a subscription information obtaining request to a third network function, wherein the subscription information obtaining request comprises the user identifier information; a second receiving module, configured to receive user data service subscription information corresponding to the user identifier information fed back by the third network function, wherein the user data service subscription information is used to represent service subscription information of the user for application layer data; and a processing module, configured to determine a user data service processing policy based on the user data service subscription information, and send the user data service processing policy to a second network function.
[0024] The application further provides a device for data transmission at the application layer, applied to a second network function, and the device comprises the following modules: a third receiving module, configured to receive a user data service processing policy sent by a first network function, wherein the user data service processing policy is determined by the first network function based on user data service subscription information after receiving a user session establishment request; and a control module, configured to control a user data service processing step to be executed based on the user data service processing policy.
[0025] The application further provides a data transmission apparatus of an application layer, applied to a third network function, the apparatus comprising: a fourth receiving module, configured to receive a subscription information obtaining request sent by a first network function, the subscription information obtaining request comprising user identity information; a generating module, configured to generate user data service subscription information corresponding to the user identity information based on the subscription information obtaining request, and feed back the user data service subscription information to the first network function, wherein the user data service subscription information is used to represent service subscription information of the user to application layer data.
[0026] The application further provides a first network function, comprising a processor and a memory storing a computer program, wherein the processor implements the steps of the data transmission method of the application layer according to any one of the application when executing the computer program.
[0027] The application further provides a second network function, comprising a processor and a memory storing a computer program, wherein the processor implements the steps of the data transmission method of the application layer according to any one of the application when executing the computer program.
[0028] The application further provides a third network function, comprising a processor and a memory storing a computer program, wherein the processor implements the steps of the data transmission method of the application layer according to any one of the application when executing the computer program.
[0029] The application further provides a communication system, comprising a first network function, a second network function and a third network function.
[0030] The application provides a data transmission method, apparatus and communication system of an application layer, comprising: receiving a user session establishment request, the user session establishment request comprising user identity information; sending a subscription information obtaining request to a third network function, the subscription information obtaining request comprising the user identity information; receiving user data service subscription information corresponding to the user identity information fed back by the third network function, the user data service subscription information being used to represent service subscription information of the user to application layer data; determining a user data service processing strategy based on the user data service subscription information, and sending the user data service processing strategy to a second network function. The user data service subscription information corresponding to the user identity information is obtained through the third network function, and the user data service processing strategy is determined based on the user data service subscription information, so that the permission security can be guaranteed from the bottom layer of the network by using the authentication mechanism of the network. Compared with the prior art of performing permission management at the application layer, the risk of illegal acquisition of permission and data leakage is greatly reduced, the user permission is accurately determined, the data is safely and efficiently transmitted, and the security of application data in the transmission and access process is realized. BRIEF DESCRIPTION OF DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in the application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, the accompanying drawings in the following description are some embodiments of the application, and for those skilled in the art, other drawings can also be obtained based on these drawings without creative effort.
[0032] Figure 1 is one of the flow diagrams of the data transmission method of the application layer provided by the application.
[0033] Figure 2 is the flow diagram of determining the user data service processing strategy based on the user data service subscription information provided by the application.
[0034] Figure 3 is the second flow diagram of the data transmission method of the application layer provided by the application.
[0035] Figure 4 is the flow diagram of controlling the execution of the user data service processing step based on the user data service processing strategy provided by the application.
[0036] Figure 5 is the third flow diagram of the data transmission method of the application layer provided by the application.
[0037] Figure 6 is the application scenario diagram of the data transmission method of the application layer provided by the application.
[0038] Figure 7 is one of the structural diagrams of the data transmission device of the application layer provided by the application.
[0039] Figure 8 is the second structural diagram of the data transmission device of the application layer provided by the application.
[0040] Figure 9 is the third structural diagram of the data transmission device of the application layer provided by the application.
[0041] Figure 10 is the application scenario diagram of the communication system provided by the application.
[0042] Figure 11 is the structural diagram of the electronic device provided by the application. DETAILED DESCRIPTION
[0043] In order to make the purposes, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below in combination with the drawings in the present application. Obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0044] In the existing application permission management scheme, permission control is mainly performed at the application layer. Application layer permission management has many security risks, because it is vulnerable to hacker attacks. Once the application program has code defects or is subjected to external malicious attacks, security vulnerabilities can be exploited, leading to a significant increase in the risk of permission breakthrough and sensitive information leakage. For example, when accessing a content server, a hacker can bypass permission checks by attacking the login verification mechanism of the application program to obtain unauthorized data. Malicious attackers can use application layer vulnerabilities to pretend to be legitimate users and access and steal confidential information of enterprises, private data of users, etc.
[0045] To solve this problem, the application layer data transmission method provided by the present application determines the user data service processing strategy based on user data service subscription information, which can use the authentication mechanism of the network to ensure permission security from the bottom layer of the network. Compared with the existing application layer permission management technology vulnerable to hacker attacks, the risk of illegal access to permissions and data leakage is greatly reduced, ensuring accurate determination of user permissions and efficient transmission of data security, and realizing the security of application data in the transmission and access process.
[0046] Figure 1 is one of the flowcharts of the application layer data transmission method provided by the present application.
[0047] The application layer data transmission method provided by the present application will be described below in combination with Figure 1 The process of the application layer data transmission method provided by the present application will be described below.
[0048] In an exemplary embodiment of the present application, the application layer data transmission method can be applied to a first network function, which can be a Session Management Function (SMF for short) for example. In order to facilitate the description below, the first network function will be referred to as SMF. Figure 1 As can be seen, the application layer data transmission method can include steps 110 to 140, which will be described below.
[0049] In step 110, a user session establishment request is received, and the user session establishment request includes user identification information.
[0050] In an embodiment, the SMF can receive a session establishment request (i.e., a user session establishment request) from an access management function (AMF). The request can include user identification information, which can be a SUPI (Subscription Permanent Identifier) or a temporary ID, for example, as a core element to identify the user identity.
[0051] In step 120, a subscription information obtaining request is sent to a third network function, and the subscription information obtaining request includes the user identification information.
[0052] In yet another embodiment, the SMF can send a subscription information obtaining request to a third network function according to the received user identification information to query the subscription data of the user. The third network function can be a unified data management function (UDM). For ease of description, the third network function is referred to as the UDM hereinafter.
[0053] In the application process, the SMF can send a session AR data service subscription information obtaining request to the UDM. The SMF queries the subscription data of the user according to the session AR data service subscription information obtaining request message sent to the UDM, which contains multiple types of key information for accurately obtaining the subscription permission related information of the user in a specific context.
[0054] In another example embodiment of the present application, the subscription information obtaining request can include at least one of time information, location information, and a data network name (DNN).
[0055] In an embodiment, the subscription information obtaining request can include UE ID information, where the UE ID information (such as a SUPI (Subscription Permanent Identifier) or a temporary ID) is a core element to identify the user identity.
[0056] The subscription information acquisition request can also include location information, where the location information of the UE plays a key role in determining the subscription rights. In the AR inspection scenario, the location information can be accurate to a specific area, such as a certain workshop in a factory (e.g., "Factory-A-Workshop-01"), a specific shelf area in a warehouse (e.g., "Warehouse-B-Shelf-Section-05"), etc. The acquisition of location information can be achieved in various ways, such as GPS positioning of the terminal device, positioning based on Wi-Fi access points, or base station positioning technology, etc. For example, when the inspector is located in a dangerous area of the factory (e.g., near high-voltage equipment, location identified as "Danger-Zone-Near-High-Voltage-Equipment"), his access rights to AR data may be limited to only obtaining public-level data related to safety warnings; while in a normal inspection area (e.g., a regular device inspection path, location identified as "Regular-Patrol-Path"), he may have the right to access ordinary user-level or even high-level user-level data, such as detailed running parameters and maintenance records of the equipment, etc.
[0057] The subscription information acquisition request can also include time information, where the time information specifies the time point or time period of the user's request. This is crucial for certain subscription right controls that have a time limit. For example, the enterprise stipulates that during normal working hours (e.g., 9:00 - 17:00 from Monday to Friday), an ordinary inspector can access real-time running data of the equipment in a certain area (which belongs to ordinary user-level data), but during non-working hours, his access rights may be limited to only viewing the basic status information of the equipment (public-level data). The format of time information can adopt the standard timestamp format, such as "2023-11-20T14:30:00Z" representing 14:30:00 on November 20, 2023 (Z represents Coordinated Universal Time). By combining time information, the UDM can more accurately determine the scope of the user's subscription rights at the current time.
[0058] The subscription information acquisition request can also include DNN information, where the DNN (Data Network Name) information is used to distinguish different data network services. In the AR inspection scene, there can be multiple different DNNs, such as "AR - Patrol - Factory - Network" for AR inspection data transmission within the factory, "AR - Patrol - Outdoor - Network" for data transmission in the outdoor inspection scene, and the like. Different DNNs can correspond to different subscription packages and permission settings. For example, an enterprise signs a senior service package (corresponding to DNN "AR - Patrol - Factory - Network") with the operator for factory AR inspection, which allows senior inspectors to access AR data of a senior user level within the factory, including deep diagnostic information and predictive maintenance data of the equipment; while for the outdoor inspection scene (DNN "AR - Patrol - Outdoor - Network"), only data access permissions of a general user level can be provided, mainly focusing on environmental monitoring data and equipment location information, and the like.
[0059] In the application process, the SMF sends a request message containing the UE ID, location information, time information, and DNN information to the UDM, triggering the UDM to perform a user AR service subscription information confirmation process to accurately determine the user's subscription permissions for accessing AR content information at a specific location and time.
[0060] In step 130, the third network function feedback corresponding to the user identification information is received. The user data service subscription information is used to represent the user's service subscription information for the application layer data.
[0061] In an embodiment, after receiving the request, the UDM can query the user subscription data (i.e., user data service subscription information) corresponding to the user identification information, and return the part related to the application layer data processing (i.e., user data service subscription information) to the SMF.
[0062] In another embodiment, the AR inspection business can be taken as an example to illustrate the scheme. The business / content server is an AR server in the AR inspection business scene, and the UE is an AR glasses or other AR terminal device. Other similar scenarios are also applicable.
[0063] In the application process, the UDM performs user AR service subscription information confirmation. After receiving the request from the SMF, the UDM queries its database or an independent AR permission server to confirm the user's AR service subscription information (corresponding to the user data service subscription information). The confirmation process includes checking the user's permission level, accessible data groups, and service types.
[0064] In yet another exemplary embodiment of the present application, the user data service subscription information can include at least one of a user authority level, accessible data groups, and service types.
[0065] The authority information storage manner determines the specific operation of the query. If the authority information is stored in the UDM's own database, the UDM directly performs a lookup in the user subscription data storage area inside it. Assuming that the UDM's database uses a relational database management system (such as MySQL), the user's subscription information can be stored in a table named "user_subscription", which contains fields such as "SUPI" (storing the user permanent identifier), "Location_Access_Rules" (storing the access authority rules corresponding to different locations), "Time_Access_Rules" (storing the access authority rules for different time periods), "DNN_Access_Rules" (storing the access authority rules corresponding to different DNNs), and the like. The UDM locates the user's record in the "user_subscription" table according to the received UE ID, and then further filters the subscription authority information that meets the conditions in combination with the location, time, and DNN information.
[0066] If the authority information is stored in a separate AR authority server, the UDM uses the received UE ID information (such as SUPI or temporary UE ID) to initiate a query request to the AR authority server according to a predefined interface protocol and query manner. For example, through a RESTful API interface based on HTTPS, the UE ID, location, time, and DNN information are encapsulated in the request body and sent to the AR authority server to request the AR service subscription authority information of the user under the specific location, time, and DNN.
[0067] In yet another embodiment, in the process of authority level confirmation, the UDM determines the user's authority level according to the query result. Taking the factory AR inspection scenario as an example, if the user is a normal inspector, his authority level can be "normal user level", which means he can access AR data of normal user level such as device routine operation parameters, general environmental monitoring data, and the like. The authority level of a senior inspector is "senior user level", which can access higher level information such as part of device core operation data, important environmental monitoring data, and the like. The administrator has "management level" authority and can access all data, including sensitive configuration information, complete device state data and environmental data, and the like.
[0068] In another embodiment, in the process of confirming the data group accessible to the user, the data group accessible to the user can be determined according to the permission level and the relevant rules. For a general patrol inspector, in the normal working area (such as a general production workshop, the location information is marked as "General - Production - Workshop") and the working time (such as Monday to Friday 09:00-17:00), when using the "AR - Patrol - Factory - Network" DNN, the data group accessible to the user can include the basic running state data of the equipment in the workshop (such as whether the temperature and pressure are normal), the conventional indicators in the environmental monitoring data (such as the temperature and humidity range), etc. For a senior patrol inspector in the same area and time, in addition to the above data, the senior patrol inspector can also access the performance optimization parameters of the equipment, the historical maintenance records, etc. to perform more in-depth patrol analysis.
[0069] In another embodiment, in the process of confirming the service type, the UDM also needs to confirm the service type that the user can enjoy. For example, a general patrol inspector can be authorized to use only the AR data viewing service for real-time monitoring of the equipment state; a senior patrol inspector can have the permission of the AR data marking service in addition to the viewing service, and can mark the problems or abnormal data points found to facilitate subsequent processing; an administrator has the full-service type permission including the data management, user permission configuration, etc. and can comprehensively manage and configure the data and user permissions of the entire AR patrol system.
[0070] Further, the UDM can return the session AR data service subscription information to the SMF. The response message returned by the UDM to the SMF should include the following contents: the user permission information and the accessible data group.
[0071] In step 140, a user data service processing strategy is determined based on the user data service subscription information, and is sent to the second network function.
[0072] In another embodiment, after receiving the above-mentioned user data service subscription information, the SMF can convert the user data service subscription information into specific and executable policy rules. Further, the SMF can send the policy rules to the second network function through a session establishment or modification request, so that the second network function can identify the application layer data packet and perform corresponding priority scheduling, low delay queue processing, etc. on the application layer data packet according to the received policy when performing data packet forwarding. The second network function can be a user plane function (User Plane Function, also referred to as UPF). For the convenience of description, the second network function is referred to as UPF hereinafter.
[0073] The application provides a data transmission method and device of an application layer and a communication system. A user session establishment request is received, and the user session establishment request comprises user identification information. A subscription information acquisition request is sent to a third network function, and the subscription information acquisition request comprises the user identification information. User data service subscription information corresponding to the user identification information is received, which is fed back by the third network function, and the user data service subscription information is used to represent service subscription information of the user for application layer data. A user data service processing strategy is determined based on the user data service subscription information, and is sent to a second network function. The user data service subscription information corresponding to the user identification information is obtained through the third network function, and the user data service processing strategy is determined based on the user data service subscription information, so that the authentication mechanism of the network is used to guarantee the security of the right from the bottom layer of the network. Compared with the prior art, the risk of illegal acquisition of the right and data leakage is greatly reduced, the right of the user is accurately determined, the data is efficiently transmitted, and the security of the application data in the transmission and access process is realized.
[0074] Figure 2 FIG. 1 is a flowchart of a process of determining a user data service processing strategy based on user data service subscription information according to the application.
[0075] The application will be described below in combination with Figure 2 The process of determining a user data service processing strategy based on user data service subscription information according to the application will be described.
[0076] In an exemplary embodiment of the application, the process of determining a user data service processing strategy based on user data service subscription information according to the application will be described in combination with Figure 2 It can be known that before the user data service processing strategy is determined based on the user data service subscription information, the data transmission of the application layer can further comprise steps 210 to 230, which will be described below. In step 210, a data service strategy request is sent to a policy control function, and the data service strategy request carries user identification information and at least part of user data service subscription information.
[0077] In an embodiment, the first network function SMF can send a data service strategy request to a policy control function (PCF), and the request carries not only the identification information of the user, but also at least part of the user data service subscription information obtained from the UDM.
[0078] In still another exemplary embodiment of the application, the at least part of the user data service subscription information can comprise user right level and service demand information.
[0079] In yet another embodiment, the SMF can send a session AR data service policy information obtaining request to the PCF. The SMF sends a request to a policy control function (PCF) for AR data service policy information related to the session according to information returned by the UDM. The request message should contain the user's identity information, service requirements, and the user's permission information.
[0080] In step 220, the user data service policy information corresponding to the user identity information fed back by the policy control function is received.
[0081] In step 230, the user data service processing policy is determined based on the user data service subscription information and the user data service policy information corresponding to the user identity information.
[0082] In yet another exemplary embodiment of the present application, the user data service policy information can include at least one of a quality of service (QoS) parameter and slice configuration information.
[0083] In yet another embodiment, after receiving the request, the PCF makes a comprehensive decision according to the pre-configured policy rules in the PCF, the current state of the network, and the user application layer subscription information reported by the SMF. After the decision of the PCF, specific user data service policy information is generated and fed back to the SMF. These policy information are more specific and more network execution-oriented instructions than the subscription information.
[0084] Further, the final user data service processing policy can be determined based on multiple pieces of information, wherein the user data service subscription information obtained from the UDM and the user data service policy information obtained from the PCF are used together to determine the user data service processing policy.
[0085] In yet another exemplary embodiment of the present application, the user data service processing policy can include at least one of user service permissions, a quality of service (QoS) parameter of a data service, and slice configuration information.
[0086] In yet another embodiment, the PCF can send a session AR data service policy information response to the SMF. The response content includes: QoS parameters and slice configuration, wherein the QoS parameters indicate the quality of service requirements required for the session, such as bandwidth, delay, priority, etc.; the slice configuration contains the identifier of the required slice and its corresponding configuration parameters. In the application process, the SMF can determine the AR service permission of this UE session, the slice \ QoS of the AR data service session, etc. according to the foregoing information. After receiving the session AR data service subscription information returned by the UDM and the session AR data service policy information returned by the PCF, the SMF determines the AR service permission of this UE session, the slice \ QoS of the AR data service session, etc. through a pre-provisioned mapping table.
[0087] In yet another embodiment, the SMF can send a session AR data processing policy configuration request to the UPF. After determining the AR service permission of this UE session, the slice (and QoS (etc. information, the SMF can send a session AR data processing policy configuration request to the UPF to guide the UPF to correctly process and transmit the data of the session.
[0088] In order to further introduce the application layer data transmission method described in the present application, the process of determining the AR service permission of this UE session, the slice \ QoS of the AR data service session, etc. by the SMF will be described below in conjunction with the following UE session example.
[0089] In a large intelligent factory, an AR inspection system based on a 5G network is deployed. Among them, the UE information and initial conditions can be determined. The UE ID is UE12345, which is the unique identifier assigned to the AR inspection terminal. The location is production workshop A area in the factory, which mainly produces precision electronic equipment, has strict environmental control requirements (such as temperature, humidity, electrostatic protection, etc.), and deploys multiple types of equipment, including automated production line equipment, high-precision detection equipment, and environmental monitoring equipment, etc. The time is 10:30 am on weekdays, which is within the normal production inspection time period.
[0090] Further, the AR service permission is determined (according to the subscription information stored in the UDM and the information returned by the UDM in step 5, combined with the ID, location and time of the UE). Since UE12345 is in production workshop A area during working hours, its permission is determined to be a senior user level. This means that it can access data determined according to a pre-provisioned mapping relationship (such as public level data and senior user data).
[0091] Further, the slice \QoS can be determined. Among them, there are multiple slices in the factory's 5G network specially divided for AR inspection business. According to the high-level user level permission and business needs of the UE, the SMF allocates a high-performance slice to it, and the slice ID is "AR-Patrol-High-Performance-Slice-01". This slice has rich computing resources (such as high CPU core number, large memory capacity), large network bandwidth reservation, low delay guarantee (end-to-end delay does not exceed 80 milliseconds), and high reliability design (redundant nodes and multi-path transmission) to meet the UE's demand for complex data processing and real-time data transmission in production workshop A area. In terms of QoS configuration, the traffic priority is set to high priority, corresponding to the ExpeditedForwarding (EF) in the DiffServ model, to ensure that the UE's data is transmitted first in network congestion. The dynamic bandwidth allocation strategy is adopted for bandwidth guarantee, which can occupy higher bandwidth (such as 20Mbps) when the network is idle, and at least guarantee 10Mbps bandwidth when the network is congested, to ensure the stable transmission of key data. In terms of delay and jitter control, the delay tolerance does not exceed 50 milliseconds, and the jitter tolerance does not exceed 10 milliseconds, to ensure the accuracy and timeliness of real-time operation.
[0092] Through the above process, for the session of UE12345 at a specific location and time, the SMF determines its AR service permission, selects the appropriate slice and configures the corresponding QoS parameters to ensure that the UE can efficiently and stably obtain the required data and perform related operations in the AR inspection work of the smart factory, and ensure the smooth progress of the production process.
[0093] According to the foregoing description, the application provides a data transmission method and device of an application layer and a communication system, which are applied to a first network function, receive a user session establishment request, the user session establishment request including user identification information; send a subscription information acquisition request to a third network function, the subscription information acquisition request including the user identification information; receive user data service subscription information corresponding to the user identification information fed back by the third network function, the user data service subscription information being used to represent service subscription information of the user to the application layer data; determine a user data service processing strategy based on the user data service subscription information, and send to a second network function. Through the third network function, the user data service subscription information corresponding to the user identification information is obtained, and the user data service processing strategy is determined based on the user data service subscription information, which can use the authentication mechanism of the network to ensure the security of the permission from the bottom of the network. Compared with the existing technology of managing permissions at the application layer, which is vulnerable to hacker attacks, the risk of illegal acquisition of permissions and data leakage is greatly reduced, ensuring accurate determination of user permissions and efficient transmission of data, and realizing the security of application data in the transmission and access process.
[0094] Figure 3 is a flowchart of the data transmission method of the application layer provided by the present application.
[0095] Based on the same inventive concept, the present application further provides another data transmission method applied to the application layer of a second network function, which will be described below in combination with Figure 3 .
[0096] In another exemplary embodiment of the present application, it can be known that the data transmission method applied to the application layer of the second network function can include steps 310 and 320, which will be introduced respectively as follows. Figure 3
[0097] In step 310, a user data service processing policy sent by a first network function is received, which is determined by the first network function according to user data service subscription information after receiving a user session establishment request.
[0098] In an embodiment, the second network function UPF receives policy control information sent by the first network function SMF. The information can be sent through a PFCP (Packet Forwarding Control Protocol) session establishment or modification request message. The user data service processing policy carried therein is determined by the SMF after receiving a PDU session establishment request (user session establishment request), querying and obtaining user data service subscription information from the third network function UDM, and analyzing and deciding based on the subscription information. The processing policy is the SMF's objectified conversion of the application layer subscription requirements.
[0099] In step 320, based on the user data service processing policy, the execution of the user data service processing step is controlled.
[0100] In an embodiment, the UPF can parse and activate the received policy rules, and then control the internal data processing unit to execute the corresponding user data service processing step in the data packet forwarding process of the user data plane. In this embodiment, by performing differentiated scheduling and processing on data packets by the UPF, high-value and network performance-sensitive application data can be ensured to obtain the required network resources (such as bandwidth, low delay), thereby directly realizing the service quality promise to the user and significantly improving the user's experience when using specific applications.
[0101] In another exemplary embodiment of the present application, the user data service processing policy can include at least one of user service permissions, quality of service QoS parameters of data services, and slice configuration information.
[0102] In yet another example embodiment of the present application, before controlling the execution of the user data service processing step based on the user data service processing policy, the data transmission method of the application layer can further include the following steps: sending a session user session establishment response to the user equipment.
[0103] In an embodiment, the second network function UPF can send a user session establishment response to the user equipment UE after successfully receiving and configuring the user data service processing policy issued by the first network function SMF. This response can be an indirect process: after the UPF has completed all the rules required for processing user plane data, it will reply to the SMF with a PFCP session establishment response to confirm that the policy has been activated. Subsequently, the SMF will finally complete the interaction process with the access network and the UE, and the AMF will send a PDU session establishment acceptance message to the UE. This end-to-end completion signal marks that the entire policy issuance and configuration channel from the control plane to the user plane has been successfully established.
[0104] In yet another embodiment, the UPF can send a session AR data processing policy configuration response to the SMF. After receiving the configuration request from the SMF, the UPF prepares for data forwarding according to the configuration policy. After successful configuration, the UPF sends a confirmation response to the SMF, indicating that the policy configuration has been completed. The SMF replies to the AMF with a session establishment success response. The SMF sends a session establishment success message back to the AMF, indicating that the session has been successfully configured. Further, the AMF replies to the user equipment (AR terminal) with a session establishment success response, notifying it that it can start data interaction with the application server (AR server). After receiving this message, the AR terminal performs the corresponding operation according to the allocated slice and QoS configuration.
[0105] Figure 4 is a flowchart of the process of controlling the execution of the user data service processing step based on the user data service processing policy provided by the present application.
[0106] The following will be described in conjunction with Figure 4 The process of controlling the execution of the user data service processing step based on the user data service processing policy provided by the present application will be described.
[0107] In an example embodiment of the present application, the user data service processing policy includes at least one of user service permissions, quality of service QoS parameters of data services, and slice configuration information, in conjunction with Figure 4 It can be seen that controlling the execution of the user data service processing step based on the user data service processing policy can include steps 410 to 430, which will be described below.
[0108] In step 410, a data service request sent by a user equipment is received.
[0109] In an embodiment, the second network function UPF receives a data packet from a user equipment UE, which is a data service request initiated by the UE to an application server after obtaining a session establishment response, for example, a HTTP request.
[0110] In yet another embodiment, a user equipment, for example, an AR terminal, can communicate with an application server, for example, an AR server, through a 5G network, and send a data request to the server. The UPF can intercept the data request, that is, receive the data service request sent by the user equipment. And according to the AR data processing strategy obtained from the SMF, apply for a data group to the AR server through a customized tunnel or a packet header mark. The UPF uses the customized tunnel or marks the unique identifier of the data group on the data packet header according to the indication of the SMF to request the corresponding data group. The identifier should be defined in advance in the interaction logic between the AR server and the operator network, to ensure that the AR server can correctly identify and process the request.
[0111] In step 420, a user data service acquisition request is generated and sent to the application server based on the data service request and the user data service processing strategy, or sent through a transmission tunnel matched with the user service permission, wherein the user data service acquisition request carries the user service permission.
[0112] In an embodiment, the UPF can parse the data service request and match it with the user data service processing strategy issued by the SMF, generate and send a user data service acquisition request. In the application process, the UPF can generate a user data service acquisition request based on the strategy, for example, a special HTTP header field containing the user service permission can be attached to the original request, and then the new request is sent to the application server. This brings the user's network side subscription information to the application layer server, so that it can provide matched services.
[0113] In yet another embodiment, the UPF can also identify the purpose and characteristics of the request, and then send it through a transmission tunnel matched with the user service permission. For example, only user data with high permission will be injected into a special transmission tunnel with low delay and high bandwidth, so as to guarantee the quality of service.
[0114] In step 430, a user data service response feedback by the application server is received, and the user data service response includes user service data.
[0115] In yet another embodiment, after receiving the request, the application server will generate a corresponding user data service response according to the permission information carried therein or the perceived transmission path or tunnel. The UPF can receive these downlink data from the application server.
[0116] In yet another embodiment, the AR server starts sending contents to the AR terminal after receiving the request from the AR terminal forwarded by the UPF and obtaining the corresponding data set according to the permission identified in the request (e.g., the permission level determined by the IP packet Options field, the GRE tunnel ID, or the "AR-Data-Privilege" field in the HTTP request header, etc.).
[0117] Further, the UPF processes the downlink data according to the AR data processing strategy configured by the SMF before receiving the data sent by the AR server, so as to ensure that the data is accurately transmitted to the AR terminal and meets the permission and QoS requirements of the UE in the session.
[0118] In yet another exemplary embodiment of the present application, generating a user data service acquisition request and sending to an application server can include any one of the following: generating an IP packet including a user data service acquisition request and sending the IP packet to an application server, wherein a selection field of the IP packet includes user service permissions; generating an application layer protocol data packet including a data service acquisition request and sending the application layer protocol data packet to an application server, wherein an extension header of the application layer protocol data packet includes user service permissions.
[0119] In an embodiment, the UPF can generate an IP packet, and the core payload of the IP packet is the user data service acquisition request to be sent to the application server. The UPF embeds the user service permission information by modifying or setting the selection field of the IP packet.
[0120] In yet another embodiment, the UPF can generate a complete application layer protocol data packet (e.g., a complete HTTP request message), and the message itself is the data service acquisition request. The UPF embeds the user service permission information by extending the format of the application layer protocol.
[0121] In the application process, the rule configuration can be based on the application layer protocol extension header information, for example, based on the HTTP protocol extension. If the application layer protocol extension header information is used, the SMF can instruct the UPF to add a field in the application layer protocol header to identify the data permission level.
[0122] In yet another embodiment, for the HTTP request of this session, the UPF needs to add a field named "AR - Data- Privilege" in the request header and set its value to "advanced" (which can correspond to the high-level user-level permission). For example, when UE12345 requests the detailed detection result data of the high-precision detection device through the AR application to the AR server, the UPF adds "AR - Data - Privilege: advanced" in the HTTP request header constructed.
[0123] The UPF ensures the correct addition and setting of the field when processing the data packet. After receiving the request, the AR server parses the "AR - Data- Privilege" field, and when it finds that the field value is "advanced", it knows that it is a high-level user-level data request, so it filters out the high-level user-level data group (such as detailed detection result data of high-precision detection device, high-precision environmental monitoring data of workshop A area, etc.) from its data storage, and encapsulates the data in the response according to the agreed HTTP protocol format and returns it to the UPF.
[0124] In this embodiment, the SMF guides the UPF to accurately select the appropriate data processing method according to the permission level of the UE and the business requirements during the interaction with the application server, ensures the safe and efficient transmission of data, and realizes the smooth progress of the business in this session.
[0125] The process of receiving the user data service response fed back by the application server provided in the present application will be described below in conjunction with the following embodiments.
[0126] In an example embodiment of the present application, receiving the user data service response fed back by the application server can include the following contents: receiving the user data service response fed back by the application server through a transmission tunnel matched with the user service permission, and / or receiving the IP data packet fed back by the application server, the IP data packet including the user data service response, and the selection field of the IP data packet including the user service permission, and / or receiving the application layer protocol data packet fed back by the application server, the application layer protocol data packet including the user data service response, and the extension header of the application layer protocol data packet including the user service permission, The data transmission method of the application layer further includes: verifying the user service permission.
[0127] In an embodiment, the UPF can receive the user data service response from the application server through a transmission tunnel matched with the user service permission.
[0128] In yet another embodiment, the UPF receives an IP packet with the payload as the user data service response, which is fed back by the application server. In this way, the application server has marked the user service privilege in the selected field of the IP packet when sending the data.
[0129] In yet another embodiment, the UPF receives an application layer protocol packet (such as an HTTP response message) fed back by the application server, which contains the user data service response. In this way, the application server includes the user service privilege information in the extension header of the application layer protocol packet.
[0130] Further, after receiving the response, the application layer data transmission method also includes a key security step: Verify the user service privilege. Among them, the UPF will extract the "user service privilege" information obtained from the application server response (whether from the tunnel attribute, IP packet header or application layer header), and compare it with the privilege specified in the user data service processing strategy initially issued by the SMF. Confirm whether the data stream returned by the application server is consistent with the service level actually subscribed by the user. If the verification finds that the priority marked by the application server in the IP packet is higher than the level subscribed by the user, the UPF can downgrade it to the correct queue for processing, to prevent the user from obtaining higher level services through fraudulent means, and to ensure the fair use of network resources and the accuracy of billing.
[0131] In an embodiment, the UPF intercepts the data request, and according to the AR data processing strategy obtained from the SMF, applies for the data group from the AR server through custom tunnel or packet header marking. The UPF uses the custom tunnel or marks the unique identifier of the data group on the data packet header according to the indication of the SMF to request the corresponding data group. The identifier should be pre-defined in the interaction logic between the AR server and the operator network, to ensure that the AR server can correctly identify and process the request.
[0132] Further, the application server, such as the AR server, receives the request from the AR terminal forwarded by the UPF, and obtains the corresponding data group according to the privilege identification in the request (such as the privilege level determined by the "AR-Data-Privilege" field in the IP packet Options field, GRE tunnel ID or HTTP request header, etc.). After that, the application server starts to send content to the AR terminal. After receiving the data sent by the AR server, the UPF processes the downlink data according to the AR data processing strategy configured by the SMF previously, to ensure that the data is accurately transmitted to the AR terminal and meets the privilege and QoS requirements of the UE in the session.
[0133] In another embodiment, the data packet can also be parsed and privilege verified. In the application process, the UPF first parses the received data packet, extracts the information for identifying the privilege level according to the type of the data packet (such as IP packet, GRE tunnel encapsulation packet or application layer protocol based packet), and checks the privilege level identification in the Options field if it is an IP packet; if it is a GRE tunnel encapsulation packet, the tunnel ID is checked and the privilege level is determined according to the predefined correspondence between the tunnel ID and the privilege level; if it is an application layer protocol (such as HTTP) based packet, the "AR - Data - Privilege" field in the protocol header is parsed. For example, if the privilege level identification in the data packet is parsed as an advanced user level (such as "advanced"), the UPF regards the data packet as the response data of the advanced user level data request.
[0134] Then, the UPF compares the extracted privilege level with the configuration information of the session to verify whether the privilege of the data packet is consistent with the privilege of the UE in the session. If the privilege is consistent, the subsequent processing is continued; if the privilege is inconsistent, the UPF takes corresponding measures according to the policy, such as discarding the data packet and recording error information (may notify the SMF or other related network entities), to prevent illegal data transmission and privilege boundary access.
[0135] In another exemplary embodiment of the present application, the data transmission method of the application layer continues to be described in the previous embodiment, and the data transmission method of the application layer further includes the following steps: sending a data service response to the user equipment, the data service response carrying user service data.
[0136] In an embodiment, the UPF, as a gateway between the user equipment (UE) and the application server, can send the finally processed data service response to the user equipment. This sending action is the core user plane function of the UPF, which sends the data packet to the radio access network (RAN) through the corresponding bearer tunnel according to the existing session context and forwarding rule, and finally reaches the user equipment.
[0137] In another exemplary embodiment of the present application, after controlling the execution of the user data service processing step based on the user data service processing policy, the data transmission of the application layer can further include the following steps: adjusting the sending parameters of the user data service acquisition request and the data service response according to at least one of the user service privilege, the quality of service QoS parameter of the data service and the slice configuration information.
[0138] In an embodiment, the UPF can perform QoS processing on the data packet according to the QoS parameters configured by the SMF. For traffic priority, the data packet is put into a queue of a corresponding priority. For example, for high user level data, the data packet is put into a high priority queue to ensure that it is processed and transmitted in priority when the network is congested. In terms of bandwidth allocation, the UPF allocates appropriate bandwidth resources for the data packet according to a dynamic bandwidth allocation strategy. If the network is currently in an idle state and the QoS strategy of the session allows the bandwidth to be increased when idle, the UPF allocates a higher bandwidth to the data packet to speed up data transmission; if the network is congested, the data packet is ensured to obtain at least the guaranteed bandwidth to avoid data loss or severe delay due to insufficient bandwidth.
[0139] In terms of delay and jitter control, the UPF adopts corresponding technical means such as cache management and scheduling algorithm optimization. By reasonably setting the cache size, the data packet is prevented from waiting in the cache for too long, reducing the delay. At the same time, the scheduling algorithm is optimized to ensure that the data packet is sent in a predetermined order and time interval, reducing the jitter. For example, for video data with high real-time requirements, the UPF adopts a time slice-based scheduling algorithm to ensure that each video frame can be transmitted to the AR terminal in time and in order, making the video play smoothly and avoiding the phenomenon of picture freezing or tearing.
[0140] Based on the same inventive concept, the present application also provides a data transmission method applied to an application layer of a third network function.
[0141] Figure 5 FIG. 3 is a flowchart of a third data transmission method applied to an application layer of a third network function according to an embodiment of the present application.
[0142] The following will be described in combination with Figure 5 The process of the data transmission method applied to the application layer of the third network function according to the present application will be described.
[0143] In an exemplary embodiment of the present application, the data transmission method applied to the application layer of the third network function is described in combination with Figure 5 As can be seen, the data transmission method applied to the application layer of the third network function can include steps 510 to 520, which will be described below.
[0144] In step 510, a subscription information acquisition request sent by a first network function is received, and the subscription information acquisition request includes user identification information.
[0145] In step 520, user data service subscription information corresponding to the user identification information is generated based on the subscription information acquisition request, and the user data service subscription information is fed back to the first network function, wherein the user data service subscription information is used to represent the service subscription information of the user to the application layer data.
[0146] In an embodiment, the third network function UDM receives a subscription information acquisition request sent from the first network function SMF. The request contains user identifier information of a permanent identifier of the user.
[0147] Further, the UDM indexes the received user identifier information to query user subscription data in its database. The UDM extracts or generates user data service subscription information that strictly corresponds to the user identifier information and is specifically used to describe application layer data services from the data. The UDM encapsulates the generated user data service subscription information in a response message and feeds back to the requester, i.e., the first network function SMF.
[0148] In yet another exemplary embodiment of the present application, the user data service subscription information includes at least one of a user permission level, an accessible data group, and a service type.
[0149] As known from the foregoing description, the present application optimizes the 3GPP session establishment process, utilizes the strong security authentication mechanism of the operator SIM card when determining the AR service permission of the user, and comprehensively considers the UE ID, location information, time information, and DNN information of the user to determine the subscription permission of the user to access AR content in a specific situation. Through interaction with the UDM and other network elements, the user permission information is acquired and confirmed, and multi-dimensional data collection, transmission, and analysis processing are involved to achieve accurate permission judgment and allocation.
[0150] A specific identification field is added in the Options field of the IP data packet, and different field values corresponding to different permission levels (such as 0x0100 for a public level, 0x0200 for a normal user level, 0x0300 for an advanced user level, and 0x0400 for a management level) are defined to distinguish the data permission levels. The UPF processes the data packet according to the field and interacts with the AR server.
[0151] GRE tunnel technology is used to apply for GRE tunnels with different IDs for data of different permission levels, and the UPF communicates with the AR server by encapsulating the data packet in the corresponding tunnel.
[0152] Based on the application layer protocol (such as HTTP), the header information is extended, and an “AR - Data - Privilege” field is added. Different values (such as “public”, “normal”, “advanced”, and “admin”) are set to identify the data permission level. The UPF sets the field when constructing the request, and the AR server returns the corresponding data accordingly.
[0153] In addition, the SMF selects an appropriate slice for the user session from the network configuration according to the user permission information (such as normal user level, advanced user level, management level, etc.) returned by the UDM. For the normal user level, a slice with relatively conservative resource allocation can be selected; for the advanced user level, a high-performance slice is allocated, which has a large number of CPU cores, large memory, large bandwidth reservation, low delay guarantee (such as end-to-end delay not exceeding 100 milliseconds), and high reliability design (such as redundant nodes and multi-path transmission); the management level selects a slice with better performance to meet its demand for a large number of key data processing and system management operations. At the same time, the SMF determines the corresponding QoS parameters, including traffic priority (such as low priority for normal user level, high priority for advanced user level and management level), bandwidth guarantee (dynamic adjustment for normal user level, higher fixed quota or dynamic adjustment strategy for advanced user level and management level), and delay and jitter control (higher tolerance for normal user level, extremely low requirement for advanced user level and management level). Based on these slice and QoS configurations, the SMF formulates the data processing strategy of the UPF, and specifies how the UPF identifies and processes data packets according to the slice ID (such as through GRE tunnel encapsulation or decapsulation), schedules traffic according to QoS parameters (such as placing into corresponding priority queue, allocating bandwidth), and verifies the authority of the data (such as checking the authority identification field in the data packet) when different permission users transmit data, to ensure accurate and efficient transmission of data in the user plane, meet the AR service needs of users and guarantee the service quality.
[0154] Figure 6 is a schematic diagram of an application scenario of the data transmission method provided by the application.
[0155] To further introduce the data transmission method provided by the application, the following will be described in combination with Figure 6 .
[0156] It can be known from Figure 6 that the numbers 0-17 in the diagram represent corresponding steps, and the scheme will be further described taking the AR inspection business as an example. Figure 6 In the flowchart, the business / content server is an AR server in the AR inspection business scenario, and the UE is an AR glasses or other AR terminal device. Other similar scenarios are also applicable.
[0157] In step 0, the AR server and the 5G core network interact with the AR content service classification rule and the data processing method between the UPF and the AR server.
[0158] Among them, the AR server classifies the inspection data according to the business type (such as device operation data, environmental monitoring data, personnel operation record, etc.), the security level (such as public data, internal ordinary data, highly sensitive data) and the importance degree of the data (such as key business data, auxiliary reference data). Assign a unique identifier to each classified data group, and establish a clear mapping relationship between the data group and the user type permission.
[0159] The AR server interacts with the 5G core network through the NEF to exchange AR server content classification rules, which are divided into multiple levels according to the permission level, and different levels correspond to different IDs.
[0160] In addition, the AR server and the 5G core network interact with the UPF and the data processing method between the AR server, that is, the way the UPF applies for different data groups to the AR server, can include adding a specific identification field in the IP packet, establishing a specific tunnel, and expanding the header information based on the application layer protocol. The way to achieve.
[0161] In step 1, the AR terminal (UE) initiates a session establishment request to the AMF after completing network registration.
[0162] In step 2, the AMF selects the SMF and initiates a session establishment request to the SMF.
[0163] In step 3, the SMF sends a session AR data service subscription information acquisition request to the UDM. The SMF constructs a session AR data service subscription information acquisition request message sent to the UDM, which contains multiple types of key information for accurately obtaining the user's subscription permission related information in a specific context. Among them, the multiple types of key information can include UE ID information, location information, time information, DNN information, etc. In the application process, the SMF sends the request message containing the UE ID, location information, time information and DNN information to the UDM, triggering the UDM to perform the user AR service subscription information confirmation process to accurately determine the user's subscription permission for accessing AR content information in a specific location and time.
[0164] In step 4, the UDM performs user AR service subscription information confirmation. After receiving the request from the SMF, the UDM queries its database or an independent AR permission server to confirm the user's AR service subscription information. The confirmation process includes checking the user's permission level, accessible data group and service type.
[0165] In step 5, the UDM returns the session AR data service subscription information to the SMF. The response message returned by the UDM to the SMF should contain the following contents: user permission information and accessible data group.
[0166] In step 6, the SMF sends a session AR data service policy information acquisition request to the PCF. The SMF sends a request to the policy control function (PCF) for AR data service policy information related to the session according to the information returned by the UDM. The identity information of the user, service requirements, and user permission information should be included in the request message.
[0167] In step 7, the PCF sends a session AR data service policy information response to the SMF. The response content includes QoS parameters and slice configuration.
[0168] In step 8, the SMF determines the AR service permissions of the UE session, the slice \ QoS of the AR data service session, and other information according to the information in steps 5 and 7. After receiving the session AR data service subscription information returned by the UDM and the session AR data service policy information returned by the PCF, the SMF determines the AR service permissions of the UE session, the slice \ QoS of the AR data service session, and other information through the following preset mapping relationship.
[0169] In step 9, the SMF sends a session AR data processing policy configuration request to the UPF. After determining the AR service permissions of the UE session, the slice (such as the slice ID "AR-Patrol-High-Performance-Slice-01"), and the QoS (traffic priority EF, dynamic bandwidth allocation, etc.), the SMF sends a session AR data processing policy configuration request to the UPF to guide the UPF to correctly process and transmit the data of the session.
[0170] In step 10, the UPF sends a session AR data processing policy configuration response to the SMF. After receiving the configuration request from the SMF, the UPF prepares for data forwarding according to the configuration policy. After successful configuration, the UPF sends a confirmation response to the SMF indicating that the policy configuration has been completed.
[0171] In step 11, the SMF replies with a session establishment success response to the AMF. The SMF sends a session establishment success message back to the AMF, indicating that the session has been successfully configured.
[0172] In step 12, the AMF replies with an AR terminal session establishment success response, notifying it that it can start data interaction with the AR server. After receiving this message, the AR terminal performs corresponding operations according to the allocated slice and QoS configuration.
[0173] In step 13, the AR terminal communicates with the AR server through the 5G network and sends a data request to the server.
[0174] In step 14, the UPF intercepts the data request in step 13, and according to the AR data processing strategy obtained from the SMF in step 9, applies for a data set from the AR server through a customized tunnel or packet header marking. The UPF uses a customized tunnel or marks a unique identifier of the data set on the data packet header to request the corresponding data set according to the indication of the SMF. The identifier should be pre-defined in the interaction logic between the AR server and the operator network, ensuring that the AR server can correctly identify and process the request.
[0175] In step 15, the AR server sends content to the AR terminal. Upon receiving the request from the AR terminal forwarded by the UPF, and obtaining the corresponding data set according to the permission identifier (such as the permission level determined by the "AR-Data-Privilege" field in the IP packet Options field, GRE tunnel ID or HTTP request header, etc.) in the request, the AR server begins to send content to the AR terminal.
[0176] In step 16, the UPF processes the downlink data based on the AR data processing strategy. After receiving the data sent by the AR server, the UPF processes the downlink data according to the AR data processing strategy configured by the SMF previously, ensuring that the data is accurately transmitted to the AR terminal and meets the permission and QoS requirements of the UE in the session.
[0177] In step 17, the UPF sends content to the AR terminal. After the above processing, the UPF sends the processed data packet to the AR terminal, completing the final delivery of data.
[0178] As described above, the present application combines with the operator SIM card authentication and 5G network, and uses the encryption, authentication mechanism and slice isolation characteristics of the network to ensure the security of the permission from the bottom of the network. Compared with the existing permission management technology at the application layer, which is vulnerable to hacker attacks, the risk of illegal acquisition of permissions and data leakage is greatly reduced. For example, in the AR inspection scenario, even if the application program has vulnerabilities, hackers are difficult to break through the security protection of the network layer to obtain sensitive information such as device key parameters, effectively protecting the security of enterprise data.
[0179] In addition, based on the core network management capability of the 5G network, the centralized management and unified policy deployment of multiple AR devices and servers are realized. The existing technology lacks consistency in permission management in a multi-device and server environment, while the present application ensures that all devices and servers follow the same permission rules, simplifies the management process, reduces management costs, and improves management efficiency. For example, multiple AR inspection devices deployed by an enterprise in different regions can be managed by a unified core network policy, avoiding the management chaos caused by separate management.
[0180] Furthermore, the operator's service differentiation transmission services, such as 5G network slicing, QoS policy, etc. are fully utilized. The prior art does not effectively utilize these services, while the present proposal reasonably divides the network slices and configures the corresponding QoS parameters according to different service types, data security levels and real-time requirements, and provides customized network services for various services. For example, for real-time data of device fault diagnosis in AR inspection, a high-performance slice with high bandwidth and low delay can be allocated to ensure timely and accurate data transmission; for daily environmental monitoring data, resources are reasonably allocated to avoid resource waste and improve resource utilization efficiency.
[0181] Based on the same inventive concept, the application also provides a data transmission device applied to the application layer of the first network function. Figure 7 is one of the structural diagrams of the data transmission device of the application layer provided by the present application. The following will be described in combination with Figure 7 The data transmission device applied to the application layer of the first network function is described.
[0182] In an exemplary embodiment of the present application, the data transmission device of the application layer can be applied to the first network function, in combination with Figure 7 It can be seen that the data transmission device of the application layer can include a first receiving module 710, a sending module 720, a second receiving module 730, and a processing module 740, which will be introduced respectively.
[0183] The first receiving module 710 can be configured to receive a user session establishment request, wherein the user session establishment request includes user identification information; The sending module 720 can be configured to send a subscription information acquisition request to a third network function, wherein the subscription information acquisition request includes the user identification information; The second receiving module 730 can be configured to receive user data service subscription information corresponding to the user identification information fed back by the third network function, wherein the user data service subscription information is used to represent the user's service subscription information for application layer data; The processing module 740 can be configured to determine a user data service processing strategy based on the user data service subscription information and send it to a second network function.
[0184] In another exemplary embodiment of the present application, the processing module 740 can also be configured to: Send a data service strategy request to a policy control function, wherein the data service strategy request carries the user identification information and at least part of the user data service subscription information; Receive user data service strategy information corresponding to the user identification information fed back by the policy control function; The processing module 740 can be configured to determine the user data service processing policy based on the user data service subscription information in the following manner: determine the user data service processing policy based on the user data service subscription information and the user data service policy information corresponding to the user identifier information.
[0185] In another example embodiment of the present application, the subscription information obtaining request further includes at least one of time information, location information, and a data network name (DNN).
[0186] In another example embodiment of the present application, the user data service subscription information includes at least one of a user authority level, accessible data groups, and service types.
[0187] In another example embodiment of the present application, the at least part of the user data service subscription information includes a user authority level and service requirement information.
[0188] In another example embodiment of the present application, the user data service policy information includes at least one of a quality of service (QoS) parameter and slice configuration information.
[0189] The user data service processing policy includes at least one of a user service authority, a quality of service (QoS) parameter of a data service, and slice configuration information.
[0190] Figure 8 FIG. 2 is a structural schematic diagram of a data transmission apparatus at an application layer according to an example embodiment of the present application.
[0191] The data transmission apparatus at the application layer will be described below in conjunction with Figure 8 The structure of the data transmission apparatus at the application layer applied to a second network function will be described.
[0192] In an example embodiment of the present application, the data transmission apparatus at the application layer is applied to a second network function, and in conjunction with Figure 8 As can be seen, the data transmission apparatus at the application layer can include a third receiving module 810 and a control module 820, which will be described below.
[0193] The third receiving module 810 can be configured to receive a user data service processing policy sent by a first network function, the user data service processing policy being determined by the first network function based on user data service subscription information after receiving a user session establishment request; The control module 820 can be configured to control execution of a user data service processing step based on the user data service processing policy.
[0194] In an example embodiment of the present application, the control module 820 can be further configured to: sending a session user session establishment response to the user equipment.
[0195] In an example embodiment of the present application, the user data service processing policy includes at least one of a user service permission, a quality of service (QoS) parameter of a data service, and slice configuration information, and the control module 820 can implement the control of the user data service processing step based on the user data service processing policy in the following manner: receiving a data service request sent by the user equipment; generating a user data service acquisition request based on the data service request and the user data service processing policy and sending the user data service acquisition request to an application server, or sending the user data service acquisition request through a transmission tunnel matched with the user service permission, wherein the user data service acquisition request carries the user service permission; receiving a user data service response fed back by the application server, wherein the user data service response includes user service data.
[0196] In an example embodiment of the present application, the control module 820 can implement the generation of the user data service acquisition request and the sending of the user data service acquisition request to the application server in the following manner: generating an IP data packet including the user data service acquisition request, and sending the IP data packet to the application server, wherein a selection field of the IP data packet includes the user service permission; generating an application layer protocol data packet including the user data service acquisition request, and sending the application layer protocol data packet to the application server, wherein an extension header of the application layer protocol data packet includes the user service permission.
[0197] In an example embodiment of the present application, the control module 820 can implement the receiving of the user data service response fed back by the application server in the following manner: receiving the user data service response fed back by the application server through a transmission tunnel matched with the user service permission, and / or receiving an IP data packet fed back by the application server, wherein the IP data packet includes the user data service response, and a selection field of the IP data packet includes the user service permission, and / or receiving an application layer protocol data packet fed back by the application server, wherein the application layer protocol data packet includes the user data service response, and an extension header of the application layer protocol data packet includes the user service permission; The control module 820 can be further configured to: verify the user service permission.
[0198] In an example embodiment of the present application, the control module 820 can be further configured to: sending a data service response to the user equipment, the data service response carrying the user service data.
[0199] In an example embodiment of the present application, the control module 820 can be further configured to: adjusting sending parameters of the user data service obtaining request and the data service response according to at least one of the user service permission, a quality of service (QoS) parameter of the data service and slice configuration information.
[0200] Figure 9 Fig. 3 is a structure schematic diagram of a data transmission apparatus of an application layer provided by the present application.
[0201] The following will be described in combination with Figure 9 The structure of a data transmission apparatus of an application layer applied to a third network function will be described.
[0202] In an example embodiment of the present application, the data transmission apparatus of the application layer is applied to the third network function, and in combination with Figure 9 It can be known that the data transmission apparatus of the application layer can include a fourth receiving module 910 and a generating module 920, which will be introduced respectively.
[0203] The fourth receiving module 910 can be configured to receive a subscription information obtaining request sent by a first network function, the subscription information obtaining request including the user identifier information. The generating module 920 can be configured to generate user data service subscription information corresponding to the user identifier information based on the subscription information obtaining request, and feed back the user data service subscription information to the first network function, wherein the user data service subscription information is used to represent service subscription information of the user to the application layer data.
[0204] In yet another example embodiment of the present application, the user data service subscription information includes at least one of a user permission level, an accessible data group and a service type.
[0205] The present application further provides a first network function including a processor and a memory storing a computer program, and the processor implements the steps of the data transmission method of the application layer when executing the computer program.
[0206] The present application further provides a second network function including a processor and a memory storing a computer program, and the processor implements the steps of the data transmission method of the application layer when executing the computer program.
[0207] The application further provides a third network function comprising a processor and a memory storing a computer program, wherein the processor implements the steps of the application layer data transmission method when executing the computer program.
[0208] The application further provides a communication system comprising a first network function, a second network function, and a third network function.
[0209] Figure 10 FIG. 1 is a schematic diagram of an application scenario of the communication system provided by the application.
[0210] The following will be described in combination with Figure 10 The structure of the communication system provided by the application will be described.
[0211] In an embodiment, the communication system comprises a first network function SMF, a second network function UPF, and a third network function UDM. Figure 10 It can be seen that the communication system can comprise a first network function SMF, a second network function UPF, and a third network function UDM. Among them, Figure 10 The communication system in the above embodiment further comprises a network repository function (NRF). The NRF is a key service-based architecture component in the 5G core network (5GC). It can be understood as the “service registration and discovery center” or “service directory” of the entire 5G network.
[0212] The communication system further comprises a network slice selection function (NSSF). The NSSF is a key control plane function for network slicing in the 5G core network (5GC). It can be understood as the “slice dispatcher” or “slice navigation system” of the entire 5G network.
[0213] The communication system further comprises a policy control function (PCF). The PCF is the “policy decision brain” in the 5G core network (5GC). Its core responsibility is to uniformly formulate policy rules for quality of service (QoS), charging, access control, etc., and issue these rules to other network functions for execution, thereby intelligently managing network behavior and resource allocation.
[0214] The communication system further comprises an access and mobility management function (AMF). The AMF is the “main entrance” or “reception center” of the 5G network. When accessing the 5G network, the first core network element contacted by all user equipment (UE) is the AMF.
[0215] The communication system further comprises an authentication server function (AUSF), which is a control plane network function in the 5G core network (5GC) and is responsible for user identity authentication. It can be understood as the "security guard" or "identity verification center" of the 5G network.
[0216] In addition, the user equipment UE establishes a connection with the communication system through a radio access network (RAN), and performs according to the data transmission method of the application layer described above, so that the risk of unauthorized access and data leakage can be reduced during data transmission, ensuring accurate determination of user rights and efficient transmission of data security, and realizing the security of application data during transmission and access.
[0217] Figure 11 An example of an electronic device entity structure diagram is shown in Figure 11As shown, the electronic device can include a processor 1110, a communication interface 1120, a memory 1130, and a communication bus 1140, wherein the processor 1110, the communication interface 1120, and the memory 1130 complete mutual communication through the communication bus 1140. The processor 1110 can invoke a computer program in the memory 1130 to execute the steps of the data transmission method of the application layer, wherein the method is applied to a first network function, and the method includes: receiving a user session establishment request, the user session establishment request including user identification information; sending a subscription information acquisition request to a third network function, the subscription information acquisition request including the user identification information; receiving user data service subscription information corresponding to the user identification information fed back by the third network function, the user data service subscription information being used to represent user service subscription information for application layer data; determining a user data service processing strategy based on the user data service subscription information and sending to a second network function. Alternatively, applied to a second network function, the method includes: receiving a user data service processing strategy sent by a first network function, the user data service processing strategy being determined by the first network function according to user data service subscription information after receiving a user session establishment request; controlling execution of user data service processing steps based on the user data service processing strategy. Alternatively, applied to a third network function, the method includes: receiving a subscription information acquisition request sent by a first network function, the subscription information acquisition request including the user identification information; generating user data service subscription information corresponding to the user identification information based on the subscription information acquisition request, and feeding back the user data service subscription information to the first network function, wherein the user data service subscription information is used to represent user service subscription information for application layer data.
[0218] In addition, the logical instructions in the memory 1130 described above can be implemented in the form of a software function unit and sold or used as an independent product, which can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0219] In another aspect, the embodiments of the present application also provide a computer program product, which comprises a computer program, the computer program being stored in a non-transitory computer-readable storage medium, and the computer program being executable by a processor to enable a computer to perform the steps of the application layer data transmission method provided by the above-mentioned embodiments, wherein the method is applied to a first network function, and the method comprises: receiving a user session establishment request, the user session establishment request comprising user identification information; sending a subscription information obtaining request to a third network function, the subscription information obtaining request comprising the user identification information; receiving user data service subscription information corresponding to the user identification information fed back by the third network function, the user data service subscription information being used to represent service subscription information of a user for application layer data; determining a user data service processing strategy based on the user data service subscription information, and sending the user data service processing strategy to a second network function. Alternatively, the method is applied to a second network function, and the method comprises: receiving a user data service processing strategy sent by a first network function, the user data service processing strategy being determined by the first network function according to user data service subscription information after receiving a user session establishment request; and controlling a user data service processing step to be performed based on the user data service processing strategy. Alternatively, the method is applied to a third network function, and the method comprises: receiving a subscription information obtaining request sent by a first network function, the subscription information obtaining request comprising user identification information; generating user data service subscription information corresponding to the user identification information based on the subscription information obtaining request; and feeding back the user data service subscription information to the first network function, wherein the user data service subscription information is used to represent service subscription information of a user for application layer data.
[0220] In another aspect, the embodiments of the present application further provide a processor-readable storage medium, which stores a computer program for causing a processor to execute the steps of the data transmission method of the application layer provided by the above-mentioned embodiments. The method is applied to a first network function, and includes: receiving a user session establishment request, the user session establishment request including user identification information; sending a subscription information obtaining request to a third network function, the subscription information obtaining request including the user identification information; receiving user data service subscription information corresponding to the user identification information fed back by the third network function, the user data service subscription information being used to represent service subscription information of the user for application layer data; determining a user data service processing strategy based on the user data service subscription information, and sending the user data service processing strategy to a second network function. Alternatively, the method is applied to the second network function, and includes: receiving a user data service processing strategy sent by the first network function, the user data service processing strategy being determined by the first network function according to user data service subscription information after receiving a user session establishment request; and controlling execution of a user data service processing step based on the user data service processing strategy. Alternatively, the method is applied to the third network function, and includes: receiving a subscription information obtaining request sent by the first network function, the subscription information obtaining request including the user identification information; generating user data service subscription information corresponding to the user identification information based on the subscription information obtaining request, and feeding back the user data service subscription information to the first network function, wherein the user data service subscription information is used to represent service subscription information of the user for application layer data.
[0221] The processor-readable storage medium can be any available medium or data storage device that can be accessed by a processor, including but not limited to a magnetic storage (e.g., a floppy disk, a hard disk, a magnetic tape, a magneto-optical disk (MO), etc.), an optical storage (e.g., a CD, a DVD, a BD, a HVD, etc.), and a semiconductor memory (e.g., a ROM, an EPROM, an EEPROM, a NAND FLASH, a solid-state disk (SSD)), etc.
[0222] The device embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiments according to actual needs. Those skilled in the art can understand and implement it without creative labor.
[0223] Those skilled in the art can clearly understand the implementation of the various embodiments by means of software and the necessary general hardware platform from the above description of the embodiments, and of course, the embodiments can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that contributes to the technical solutions can be embodied in the form of a software product. The computer software product can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the methods.
[0224] Finally, it should be noted that: the above examples are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing examples, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing examples, or make equivalent replacement for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A data transmission method at the application layer, characterized in that, Applied to a first network function, the method includes: Receive a user session establishment request, the user session establishment request including user identification information; Send a subscription information acquisition request to a third network function, wherein the subscription information acquisition request includes the user identification information; The system receives user data service subscription information corresponding to the user identification information from the third network function. The user data service subscription information is used to represent the user's service subscription information for application layer data. Based on the user data service subscription information, a user data service processing strategy is determined and sent to the second network function.
2. The application layer data transmission method according to claim 1, characterized in that, Before determining the user data service processing strategy based on the user data service subscription information, the method further includes: Send a data service policy request to the policy control function, the data service policy request carrying the user identification information and at least part of the user data service subscription information; Receive user data service policy information corresponding to the user identification information from the policy control function; The step of determining the user data service processing strategy based on the user data service subscription information includes: Based on the user data service subscription information and the user data service policy information corresponding to the user identification information, a user data service processing strategy is determined.
3. The application layer data transmission method according to claim 2, characterized in that, The request for obtaining contract information also includes at least one of time information, location information, and data network name (DNN).
4. The application layer data transmission method according to claim 2, characterized in that, The user data service subscription information includes at least one of the following: user permission level, accessible data groups, and service types.
5. The application layer data transmission method according to claim 2, characterized in that, The at least part of the user data service subscription information includes user permission level and service requirement information.
6. The application layer data transmission method according to claim 2, characterized in that, The user data service policy information includes at least one of the Quality of Service (QoS) parameters and slice configuration information.
7. The application layer data transmission method according to claim 2, characterized in that, The user data service processing strategy includes at least one of the following: user service permissions, QoS parameters for data services, and slice configuration information.
8. A data transmission method at the application layer, characterized in that, Applied to a second network function, the method includes: The system receives a user data service processing strategy sent by a first network function, wherein the user data service processing strategy is determined by the first network function based on the user data service subscription information after receiving a user session establishment request. Based on the aforementioned user data service processing strategy, the execution of user data service processing steps is controlled.
9. The application layer data transmission method according to claim 8, characterized in that, The user data service processing strategy includes at least one of the following: user service permissions, QoS parameters for data services, and slice configuration information.
10. The application layer data transmission method according to claim 8, characterized in that, Before controlling the execution of user data service processing steps based on the user data service processing strategy, the method further includes: Send a session user session establishment response to the user equipment.
11. The application layer data transmission method according to claim 10, characterized in that, The user data service processing strategy includes at least one of user service permissions, QoS parameters for data services, and slice configuration information. The step of controlling the execution of user data service processing steps based on the user data service processing strategy includes: Receive data service requests sent by user equipment; Based on the data service request and the user data service processing strategy, a user data service acquisition request is generated and sent to the application server, or sent through a transmission tunnel matching the user service permissions, wherein the user data service acquisition request carries the user service permissions; Receive user data service response from application server, wherein the user data service response includes user service data.
12. The application layer data transmission method according to claim 11, characterized in that, The process of generating a user data service acquisition request and sending it to the application service includes any one of the following: An IP packet containing the user data service acquisition request is generated and sent to the application server. The selection field of the IP packet includes user service permissions. Generate an application layer protocol data packet for a data service retrieval request, and send the application layer protocol data packet to the application server. The extended header of the application layer protocol data packet includes the user service permissions.
13. The application layer data transmission method according to claim 11, characterized in that, The receiving of the user data service response from the application server includes: Receive user data service responses from the application server via a transport tunnel that matches the user's service permissions, and / or Receive IP data packets from the application server, the IP data packets including the user data service response, and the selection fields of the IP data packets including user service permissions, and / or Receive application layer protocol data packets from the application server, the application layer protocol data packets including the user data service response, and the extended header of the application layer protocol data packets including the user service permissions; The method further includes: Verify the user's service permissions.
14. The application layer data transmission method according to claim 11, characterized in that, The method further includes: Send a data service response to the user equipment, the data service response carrying the user service data.
15. The application layer data transmission method according to claim 11, characterized in that, After controlling the execution of user data service processing steps based on the user data service processing strategy, the method further includes: Based on at least one of the user service permissions, the quality of service (QoS) parameters of the data service, and the slice configuration information, adjust the sending parameters of the user data service acquisition request and the data service response.
16. A data transmission method at the application layer, characterized in that, Applied to a third network function, the method includes: Receive a subscription information acquisition request sent by a first network function, wherein the subscription information acquisition request includes the user identification information; Based on the subscription information acquisition request, user data service subscription information corresponding to the user identification information is generated, and the user data service subscription information is fed back to the first network function. The user data service subscription information is used to represent the user's service subscription information for application layer data.
17. The application layer data transmission method according to claim 16, characterized in that, The user data service subscription information includes at least one of the following: user permission level, accessible data groups, and service types.
18. A data transmission device for the application layer, characterized in that, The device, applied to a first network function, includes: The first receiving module is used to receive a user session establishment request, wherein the user session establishment request includes user identification information; The sending module is used to send a subscription information acquisition request to a third network function, wherein the subscription information acquisition request includes the user identification information; The second receiving module is used to receive user data service subscription information corresponding to the user identification information fed back by the third network function. The user data service subscription information is used to represent the user's service subscription information for application layer data. The processing module is used to determine the user data service processing strategy based on the user data service subscription information and send it to the second network function.
19. A data transmission device for the application layer, characterized in that, For use in a second network function, the device includes: The third receiving module is used to receive the user data service processing strategy sent by the first network function. The user data service processing strategy is determined by the first network function based on the user data service subscription information after receiving the user session establishment request. The control module is used to control the execution of user data service processing steps based on the user data service processing strategy.
20. A data transmission device for the application layer, characterized in that, The device, applied to a third network function, includes: The fourth receiving module is used to receive a subscription information acquisition request sent by the first network function, wherein the subscription information acquisition request includes the user identification information; The generation module is used to generate user data service subscription information corresponding to the user identification information based on the subscription information acquisition request, and to feed back the user data service subscription information to the first network function, wherein the user data service subscription information is used to represent the user's service subscription information for application layer data.
21. A first network function, comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the application layer data transmission method according to any one of claims 1 to 7.
22. A second network function, comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the application layer data transmission method according to any one of claims 8 to 15.
23. A third network function, comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the application layer data transmission method according to any one of claims 16 to 17.
24. A communication system, characterized in that, It includes the first network function as described in claim 21, the second network function as described in claim 22, and the third network function as described in claim 23.