UPF forwarding tunnel establishment method and device
By receiving the selection rule instructions from the SMF and generating the CN endpoint selection rules for the UPF forwarding tunnel based on the user's subscription data, the problem of strong randomness in the selection of the UPF forwarding tunnel is solved, and the precise tunnel allocation required by the operator is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-04-07
AI Technical Summary
In existing technologies, the selection of the CN endpoint for UPF forwarding tunnels is too random and cannot meet the specific needs of operators, resulting in unreasonable tunnel allocation.
By receiving selection rule instructions sent by the Session Management Function (SMF), the system generates CN endpoint selection rules for the UPF forwarding tunnel based on user subscription data, selects and allocates CN tunnel information according to the rules, and ensures that the tunnel selection meets the operator's needs.
It enables precise control of the CN endpoint selection of UPF forwarding tunnels according to operator needs, meeting the tunnel allocation requirements of different users and improving the rationality and efficiency of tunnel allocation.
Smart Images

Figure CN121815260A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method and device for establishing a UPF forwarding tunnel. Background Technology
[0002] Core Network (CN) tunnel information management in user plane management is jointly completed by the Session Management Function (SMF) and the User Port Function (UPF). CN tunnel information is the core network address of the UPF forwarding tunnel (N3 / N9 tunnel) corresponding to the user's PDU (Packet Data Unit) session.
[0003] If the UPF is required to allocate / release CN tunnel information, the SMF should instruct the UPF. The UPF performs the allocation and release of CN tunnel information when a PDU session is established or released. If the network is configured to perform CN tunnel information allocation / release within the UPF, the UPF will manage the CN tunnel information. When a PDU session is established or the UPF is added to the user plane path of an existing PDU session, the SMF will request the UPF to allocate CN tunnel information for the applicable N3 / N9 reference points via an N4 message; in response, the UPF provides the CN tunnel information to the SMF. When a PDU session is released or the UPF is removed from the user plane path of an existing PDU session, the SMF will request the UPF to release the CN tunnel information for the corresponding PDU session.
[0004] If a UPF that establishes an N4 connection with an SMF is configured with multiple N3 / N9 tunnel CN endpoints, and the SMF does not pass corresponding N3 / N9 tunnel CN endpoint selection rules through N4 messages, the UPF can only randomly allocate N3 / N9 tunnel CN endpoints according to the configured weights. This method is too random and cannot reasonably plan and allocate multiple N3 / N9 tunnel CN endpoints configured on a UPF to establish forwarding tunnels according to the specific needs of the operator. Summary of the Invention
[0005] The purpose of this application is to provide a UPF forwarding tunnel establishment method and device to solve the problem that the randomness of the CN endpoint in the existing UPF forwarding tunnel selection is too strong and cannot meet the needs of operators.
[0006] In a first aspect, embodiments of this application provide a UPF forwarding tunnel establishment method, applied to UPF, the method comprising: Receive selection rule instructions sent by the Session Management Function (SMF); Based on the selection rule instructions, determine the CN endpoint selection rule for the UPF forwarding tunnel; According to the CN endpoint selection rules, select the CN endpoint of the UPF forwarding tunnel; Assign CN tunnel information to the selected CN endpoint.
[0007] In some possible embodiments, the selection rule indication sent by the receiving session management function (SMF) includes: The Receive Session Management Function (SMF) sends selection rule instructions based on user subscription data.
[0008] In some possible embodiments, the selection rule indication sent by the receiving session management function (SMF) includes: Receive N4 messages sent by SMF; Obtain the selection rule indication from the security indication information element in the N4 message.
[0009] In some possible embodiments, the selection rule indication includes: User plane integrity protection indication is used to indicate the selection of CN endpoints according to the user plane integrity requirements in the user's subscription data; The confidentiality protection instruction is used to instruct users to select the CN endpoint for confidentiality requirements in their contracted data.
[0010] In some possible embodiments, the N4 message is a Packet Forwarding Control (PFCP) session establishment request message.
[0011] Secondly, embodiments of this application provide a UPF forwarding tunnel establishment method, applied to SMF, including: During the PDU session establishment process, user subscription data is obtained; Based on the user subscription data, determine the CN endpoint selection rules for the UPF forwarding tunnel; Send a selection rule indication to the UPF, the selection rule indication being used to indicate the selection rule for the CN endpoint.
[0012] In some possible embodiments, sending the rule selection instruction to the UPF includes: Send an N4 message to the UPF, wherein the security indication information element in the N4 message carries the selection rule indication.
[0013] In some possible embodiments, the selection rule indication includes: User plane integrity protection indication is used to indicate the selection of CN endpoints according to the user plane integrity requirements in the user's subscription data; The confidentiality protection instruction is used to instruct users to select the CN side for confidentiality requirements in their contracted data.
[0014] In some possible embodiments, obtaining user subscription data during the PDU session establishment process includes: During the PDU session establishment process, user subscription data is obtained from the Unified Data Management (UDM) or the Unified Data Repository (UDR).
[0015] Thirdly, another embodiment of this application also provides a UPF forwarding tunnel establishment device, including at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform any of the methods provided in the first aspect above, or to perform any of the methods provided in the second aspect above.
[0016] Fourthly, another embodiment of this application also provides a UPF forwarding tunnel establishment device, which serves as a UPF and includes: The rule instruction receiving module is used to receive selection rule instructions sent by the Session Management Function (SMF). The rule determination module is used to determine the CN endpoint selection rule for the UPF forwarding tunnel according to the selection rule indication; The endpoint selection module is used to select the CN endpoint of the UPF forwarding tunnel according to the CN endpoint selection rules. The tunnel allocation module is used to allocate CN tunnel information to the selected CN endpoints.
[0017] Fifthly, embodiments of this application provide a UPF forwarding tunnel establishment device, which serves as an SMF and includes: The contract data acquisition module is used to acquire user contract data during the PDU session establishment process; The rule determination module is used to determine the CN endpoint selection rules for the UPF forwarding tunnel based on the user subscription data. The rule indication module is used to send a rule selection indication to the UPF, which is used to instruct the CN endpoint to select a rule.
[0018] In a sixth aspect, another embodiment of this application also provides a computer storage medium storing a computer program for causing a computer to execute any of the UPF forwarding tunnel establishment methods provided in the first aspect above, or to execute any of the UPF forwarding tunnel establishment methods provided in the second aspect above.
[0019] The UPF forwarding tunnel establishment method and device provided in this application embodiment can accurately control the same UPF to select the CN endpoint of the UPF forwarding tunnel desired by the operator to establish a forwarding tunnel during the process of establishing a PDU session by the user subscription data issued by the operator. This achieves the purpose of the operator to accurately select the CN endpoint of different UPF forwarding tunnels for different users. Attached Figure Description
[0020] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 A flowchart of a UPF forwarding tunnel establishment method for UPF provided in an embodiment of this application; Figure 2 A flowchart of a UPF forwarding tunnel establishment method for SMF provided in this application embodiment; Figure 3 A detailed flowchart of the UPF forwarding tunnel establishment method provided in the embodiments of this application; Figure 4 A structural diagram of a UPF forwarding tunnel establishment device provided as an embodiment of this application; Figure 5 A diagram of a UPF forwarding tunnel establishment device as an SMF provided in an embodiment of this application; Figure 6 A structural diagram of the UPF forwarding tunnel establishment device provided in the embodiments of this application. Detailed Implementation
[0022] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on conventional or non-inventive effort. For steps that do not logically have a necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application. In actual processing or when the control device executes the method, it may be executed sequentially or in parallel according to the method shown in the embodiments or drawings.
[0023] In related technologies, the UPF allocates / releases CN tunnel information through SMF indication. CN tunnel information is the N3 (RAN (Radio Access Network) to UPF) / N9 (between UPF) tunnel core network address corresponding to the user PDU session. It includes the TEID (Tunnel EndPoint identifier) and IP (Internet Protocol) address of the UPF device selected by SMF through the N4 interface when the user PDU session is established.
[0024] Given the excessive randomness in selecting the CN endpoint of the UPF forwarding tunnel in related technologies, which fails to meet the needs of operators, this application proposes a method and device for establishing a UPF forwarding tunnel.
[0025] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings.
[0026] The UPF forwarding tunnel establishment method provided in this application embodiment is described in detail below with reference to the accompanying drawings.
[0027] like Figure 1 As shown in the figure, this application provides a UPF forwarding tunnel establishment method, applied to UPF, the method including: Step 101: Receive the selection rule instruction sent by the Session Management Function (SMF); The UPF selection rule indication is obtained from the SMF. In some possible embodiments, the UPF receives the CN endpoint selection rule indication of the UPF forwarding tunnel sent by the Session Management Function (SMF) based on user subscription data. The aforementioned UPF tunnel is an N3 / N9 tunnel. When the UPF includes multiple N3 / N9 tunnel CN endpoints, this application proposes a CN endpoint selection rule instruction based on the UPF forwarding tunnel generated from user subscription data sent by the SMF to select and allocate CN tunnel information (TEID and IP address of the UPF device) for CN endpoint selection.
[0028] During the establishment of a user's PDU session, the SMF (Service Provider Function) obtains user subscription data issued by the operator. This user subscription data includes multiple pieces of information. In this embodiment, the SMF generates a CN endpoint selection rule indication for the UPF forwarding tunnel based on the user subscription data. The method by which the SMF obtains the user subscription data is not limited; it can be obtained from any device capable of providing user subscription data. The method for generating the CN endpoint selection rule indication for the UPF forwarding tunnel based on the user subscription data is also not limited. Since the user subscription data contains information related to the CN endpoint of the UPF forwarding tunnel, either the original user subscription data or information related to the CN endpoint of the UPF forwarding tunnel can be used as the CN endpoint selection rule indication. Alternatively, the SMF can process the information related to the CN endpoint of the UPF forwarding tunnel and use the processing result as the CN endpoint selection rule for the UPF forwarding tunnel, thus determining it as the CN endpoint selection rule indication for the UPF forwarding tunnel.
[0029] Step 102: Determine the CN endpoint selection rule for the UPF forwarding tunnel according to the selection rule instructions; The CN endpoint selection rule indicated above may be in the manner shown in step 101. The CN endpoint selection of the UPF forwarding tunnel determined according to the selection rule indication can be understood as the constraint information that needs to be followed when selecting the CN endpoint. The specific content is not limited in the embodiments of this application.
[0030] Step 103: Select the CN endpoint of the UPF forwarding tunnel according to the CN endpoint selection rules; Step 104: Assign CN tunnel information to the selected CN endpoint.
[0031] The UPF forwarding tunnel establishment method provided in this application embodiment can, based on the selection rule indication sent by SMF, precisely control the selection of the CN endpoint of the UPF forwarding tunnel desired by the operator to establish a forwarding tunnel during the process of user establishing PDU session. This achieves the purpose of the operator to accurately select the CN endpoint of different UPF forwarding tunnels for different users.
[0032] In some possible embodiments, receiving a selection rule indication sent by the Session Management Function (SMF) includes: receiving an N4 message sent by the SMF; and obtaining the selection rule indication from the security indication element in the N4 message. The N4 message includes a security indication element, the content of which is a CN endpoint selection rule indication for the UPF forwarding tunnel determined based on user subscription data.
[0033] During the user's PDU session establishment process, the SMF sends an N4 message to the UPF via the N4 interface. This message instructs the UPF to allocate CN tunnel information. If a UPF that has established an N4 connection with the SMF is configured with multiple N3 / N9 tunnel CN endpoints, and the SMF does not transmit the corresponding N3 / N9 tunnel CN endpoint selection rules via the N4 message, the UPF can only randomly allocate N3 / N9 tunnel endpoints according to the configured weights. This method is too random and cannot reasonably plan and allocate multiple N3 / N9 tunnel CN endpoints configured on a UPF to establish forwarding tunnels according to the specific needs of the operator. This application embodiment adds extended security credits to the N4 message. The content of the security indication information element is an indication of the CN endpoint selection rule for the UPF forwarding tunnel determined based on user subscription data. The purpose of this application is to enable the SMF to obtain and identify the operator's N3 / N9 tunnel CN endpoint selection rule through user subscription data, and send the subscription data corresponding to the user's N3 / N9 tunnel CN endpoint selection rule to the UPF through the N4 message. After obtaining and identifying the user's subscription data, the UPF selects the corresponding N3 / N9 tunnel CN endpoint to establish the N3 / N9 forwarding tunnel. Thus, the operator can accurately control the UPF to allocate N3 / N9 tunnel CN endpoints to establish N3 / N9 forwarding tunnels for different users according to its specific needs, without increasing signaling overhead.
[0034] In some possible embodiments, the CN endpoint selection rule indication includes a user plane integrity protection indication, used to indicate the selection of a CN endpoint according to user plane integrity requirements in the user subscription data; and a confidentiality protection indication, used to indicate the selection of a CN endpoint according to confidentiality requirements in the user subscription data. The user subscription data in related technologies includes various types of information, among which the CN endpoint selection rule related to the UPF forwarding tunnel includes subscription security information. This subscription security information can be used to obtain the user plane integrity protection indication and the confidentiality protection indication, including constraints restricting compliance with the user plane integrity protection indication and confidentiality protection.
[0035] In some possible embodiments, selecting the CN endpoint of the UPF forwarding tunnel according to the CN endpoint selection rules includes: selecting the CN endpoint corresponding to the user plane integrity protection indication and confidentiality protection indication from the CN endpoints of a plurality of locally configured UPF forwarding tunnels.
[0036] When the CN endpoint selection rule includes user plane integrity protection and confidentiality protection, the UPF selects the CN endpoint that meets the requirements of user plane integrity protection and confidentiality protection from multiple locally configured UPF forwarding tunnels when selecting the CN endpoint for the UPF forwarding tunnel, based on the constraints of user plane integrity protection and confidentiality protection.
[0037] In some possible embodiments, the N4 message is a PFCP session establishment request message for requesting the establishment of a new Packet Forwarding Control (PFCP) session context.
[0038] When a UE establishes a PDU session, it follows the general 3GPP standards (3GPP TS 23.501 "System architecture for 5G System (5GS)"; 3GPP TS 23.502 "Procedures for the 5G System (5GS)"). After the SMF obtains the subscription security upSecurity (a structured information element containing upIntegr and upConfid sub-information elements) from the user's subscription data from the UDM (Unified Data Management) / UDR (Unified Data Repository), the SMF sends the upSecurity from the user's subscription data to the UPF through the N4 message after extending the information element. The UPF allocates different N3 / N9 tunnel CN endpoints to establish N3 / N9 forwarding tunnels based on the upSecurity in the user's subscription data.
[0039] Based on the same inventive concept, embodiments of this application provide a UPF forwarding tunnel establishment method, applied to SMF, such as... Figure 2 As shown, it includes: Step 201: During the PDU session establishment process, obtain user subscription data; Step 202: Based on the user subscription data, determine the CN endpoint selection rules for the UPF forwarding tunnel; Step 203: Send a selection rule instruction to the UPF, the selection rule instruction being used to instruct the CN endpoint selection rule.
[0040] In some possible embodiments, sending a rule selection instruction to the UPF includes: Send an N4 message to the UPF, wherein the security indication information element in the N4 message carries the selection rule indication.
[0041] In some possible embodiments, the above selection rule indication includes: User plane integrity protection indication is used to indicate the selection of CN endpoints according to the user plane integrity requirements in the user's subscription data; The confidentiality protection instruction is used to instruct users to select the CN side for confidentiality requirements in their contracted data.
[0042] In some possible embodiments, during the PDU session establishment process, user subscription data is obtained, including: During the PDU session establishment process, user subscription data is obtained from the Unified Data Management (UDM) or the Unified Data Repository (UDR).
[0043] Examples of relevant steps in the UPF forwarding tunnel establishment method applied to SMF are described in the above-described UPF forwarding tunnel establishment method examples, and will not be detailed here.
[0044] The following describes the specific process of the UPF forwarding tunnel establishment method provided in the embodiments of this application, based on the perspective of interaction between different network entities. Figure 3 As shown, it mainly includes
[0045] Step 1: The UE initiates a PDU session establishment request to the AMF (Access and Mobility Management Function). This PDU session establishment request carries slice information, DNN (Data Network Name) information, and PDU session identifier, PDU session ID, and other relevant parameters. Step 2, AMF performs SMF selection; Step 3: After selecting the SMF, the AMF sends a PDU session context establishment request message Nsmf_PDU session_createSMcontext_request to the SMF. This message contains information such as SUPI (SUbscription Permanent Identifier), data network name DNN, and PDU session ID. Step 4: SMF performs a subscription retrieval, specifically by retrieving user subscription data related to the user session from the Unified Data Management (UDM) / Unified Data Repository (UDR). This user subscription data includes the user's permanent identifier (SUPI), data network name (DNN), S-NSSAI (Single Network Slice Selection Assistance information) of the HPLMN (Home Public Land Mobile Network), and subscription security information such as upSecurity. Step 5: The SMF sends a PDU session context establishment response message Nsmf_PDU session_createSMcontext_response to the AMF. This message contains information such as the session context ID and the N1 SM (SM message) container. Step 6: Based on the UE's request type, the SMF determines whether to perform secondary authentication / authorization (PDU sessionauthentication / authorization). If yes, secondary authentication is performed; otherwise, step 7 is executed. Step 7: Based on the PDU session type, the SMF decides whether to select the PCF (Policy Control Function) to obtain the PCC (Policy Control and Charging) policy. If yes, the SMF and PCF interact to establish / modify the session management policy; otherwise, proceed to step 8. Step 8: SMF selects UPF as the anchor point for the PDU session; Step 9: SMF sends updated session policy information to PCF as needed and performs session management policy modification. Step 10: The SMF executes the session establishment process for the N4 interface (N4: session establishment request / Ack). The SMF sends a PFCP Session Establishment Request message to the UPF, requesting the establishment of a new PFCP session context. The PFCP Session Establishment Request message is used to provide data monitoring, reporting rules, CN tunnel information, etc. for this PDU session. At the same time, it sends the Extended Credit Security Indication (IE) information (compiled from the subscription security upSecurity in the user subscription data obtained from UDM / UDR in Step 4, which includes user plane integrity protection indication and confidentiality protection indication) to the UPF. The UPF sends a PFCP Session Establishment Response message to the SMF, and according to the Security Indication information sent by the SMF, selects the N3 / N9 tunnel CN endpoint corresponding to the user plane integrity protection indication and confidentiality protection indication, allocates CN tunnel information, and sends the selected N3 / N9 tunnel CN endpoint to the SMF. Step 11: SMF sends a session establishment and acceptance message Namf_communication_N1N2 messagetransfer to AMF; Step 12: The AMF sends a PDU session request (N2 PDU session Request) to the RAN to notify the RAN to establish radio resources. This PDU session request includes both the N1 SM container and the N2 SM container. Step 13: The RAN and UE interact to perform the access network radio resource establishment process AN specific resourcesetup (PDU Session Establishment Accept). If two CN tunnel information are established in one PDU session, the RAN will also allocate two related access network AN tunnel information, and the SMF will instruct one of the AN tunnels to be used for redundant transmission. Step 14: After the radio bearer is successfully established, the RAN sends a PDU session establishment response (N2 PDU sessionACK) to the AMF. This PDU session establishment response contains N2 SM information. Steps 15-17: AMF sends a PDU session update SM context request message Nsmf_PDU Session_Update SMContext Request to SMF; SMF sends an N4: session modification request / Ack message to UPF; and SMF sends a PDU session establishment update SM context response message Nsmf_PDUSession_Update SMContext Response to AMF, completing the PDU session update process. In the N4 session flow, if redundant transmission mode is used, SMF performs redundant transmission for one or more QoS flows of the PDU and instructs UPF to perform packet duplication for the downlink QoS flows according to the forwarding rules.
[0046] Step 18: If the PDU session type is IPv6 or IPv4v6, the SMF generates an IPv6 router and broadcasts the IPv6 address configuration information to the UE.
[0047] Based on the same inventive concept, this application also provides a UPF forwarding tunnel establishment device, which serves as a UPF, such as Figure 4 As shown, the device includes: Rule indication receiving module 401 is used to receive selection rule indications sent by Session Management Function (SMF); The rule determination module 402 is used to determine the CN endpoint selection rule of the UPF forwarding tunnel according to the selection rule instruction; Endpoint selection module 403 is used to select the CN endpoint of the UPF forwarding tunnel according to the CN endpoint selection rules; The tunnel allocation module 404 is used to allocate CN tunnel information to the selected CN endpoint.
[0048] In some possible embodiments, the rule indication receiving module receives a selection rule indication sent by the Session Management Function (SMF), including: receiving a selection rule indication sent by the SMF based on user subscription data.
[0049] In some possible embodiments, the rule indication receiving module receives a selection rule indication sent by the Session Management Function (SMF), including: receiving an N4 message sent by the SMF; and obtaining the selection rule indication from the security indication information element in the N4 message.
[0050] In some possible embodiments, the selection rule indication includes: User plane integrity protection indication is used to indicate the selection of CN endpoints according to the user plane integrity requirements in the user's subscription data; The confidentiality protection instruction is used to instruct users to select the CN endpoint for confidentiality requirements in their contracted data.
[0051] In some possible embodiments, the N4 message is a Packet Forwarding Control (PFCP) session establishment request message.
[0052] Based on the same inventive concept, embodiments of this application provide a UPF forwarding tunnel establishment device, which serves as an SMF, such as Figure 5 As shown, it includes: The contract data acquisition module 501 is used to acquire user contract data during the PDU session establishment process; The rule determination module 502 is used to determine the CN endpoint selection rule of the UPF forwarding tunnel based on the user subscription data; The rule indication module 503 is used to send a rule selection indication to the UPF, wherein the rule selection indication is used to instruct the CN endpoint to select a rule.
[0053] In some possible embodiments, the rule indication module sends a rule selection indication to the UPF, including sending an N4 message to the UPF, wherein the security indication element in the N4 message carries the rule selection indication.
[0054] In some possible embodiments, the selection rule indication includes: User plane integrity protection indication is used to indicate the selection of CN endpoints according to the user plane integrity requirements in the user's subscription data; The confidentiality protection instruction is used to instruct users to select the CN side for confidentiality requirements in their contracted data.
[0055] In some possible embodiments, the subscription data acquisition module acquires user subscription data during the PDU session establishment process, including: During the PDU session establishment process, user subscription data is obtained from the Unified Data Management (UDM) or the Unified Data Repository (UDR).
[0056] After introducing the UPF forwarding tunnel establishment method and apparatus according to exemplary embodiments of this application, the UPF forwarding tunnel establishment device according to another exemplary embodiment of this application will be introduced next.
[0057] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."
[0058] In some possible implementations, the UPF forwarding tunnel establishment device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps in the UPF forwarding tunnel establishment method applied to a UPF according to various exemplary embodiments of this application described above, or to perform the steps in the UPF forwarding tunnel establishment method applied to a SMF according to various exemplary embodiments of this application described above.
[0059] The following reference Figure 6 This application describes a UPF forwarding tunnel establishment device 160 according to this embodiment. Figure 6 The UPF forwarding tunnel establishment device 160 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0060] like Figure 6 As shown, the UPF forwarding tunnel establishment device 160 is presented in the form of a general-purpose electronic device. The components of the UPF forwarding tunnel establishment device 160 may include, but are not limited to: at least one processor 161, at least one memory 162, and a bus 163 connecting different system components (including memory 162 and processor 161).
[0061] Bus 163 represents one or more of several bus architectures, including a memory bus or memory controller, peripheral bus, processor, or local bus using any of the various bus architectures.
[0062] The memory 162 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 1621 and / or cache memory 1622, and may further include read-only memory (ROM) 1623.
[0063] The memory 162 may also include a program / utility 1625 having a set (at least one) of program modules 1624, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.
[0064] UPF forwarding tunnel establishment device 160 can also communicate with one or more external devices 164 (e.g., keyboard, pointing device, etc.), one or more devices that enable users to interact with UPF forwarding tunnel establishment device 150, and / or any device that enables UPF forwarding tunnel establishment device 160 to communicate with one or more other electronic devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 165. Furthermore, UPF forwarding tunnel establishment device 160 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 166. As shown, network adapter 166 communicates with other modules used for UPF forwarding tunnel establishment device 160 via bus 163. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with UPF forwarding tunnel establishment device 160, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0065] In some possible implementations, various aspects of the UPF forwarding tunnel establishment method provided in this application can also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to cause the computer device to perform the steps in the UPF forwarding tunnel establishment method according to the various exemplary embodiments of this application described above.
[0066] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0067] The program product for establishing a UPF forwarding tunnel according to the embodiments of this application can be a portable compact disc read-only memory (CD-ROM) and include program code, and can run on an electronic device. However, the program product of this application is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0068] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0069] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0070] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's electronic device, partially on the user's device, as a standalone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving remote electronic devices, the remote electronic device can be connected to the user's electronic device via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external electronic device (e.g., via the Internet using an Internet service provider).
[0071] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.
[0072] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0073] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0074] This application is described with reference to flowchart illustrations and block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block and / or segment of the flowchart illustrations and block diagrams, as well as combinations of blocks and segments in the flowchart illustrations and block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart. Figure 1 One or more processes and boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0075] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and boxes Figure 1 The function specified in one or more boxes.
[0076] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and boxes Figure 1 The steps of the function specified in one or more boxes.
[0077] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0078] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for establishing a UPF forwarding tunnel, applied to UPF, characterized in that, The method includes: Receive selection rule instructions sent by the Session Management Function (SMF); Based on the selection rule instructions, determine the CN endpoint selection rule for the UPF forwarding tunnel; According to the CN endpoint selection rules, select the CN endpoint of the UPF forwarding tunnel; Assign CN tunnel information to the selected CN endpoint.
2. The method according to claim 1, characterized in that, The selection rule indication sent by the Receive Session Management Function (SMF) includes: The Receive Session Management Function (SMF) sends selection rule instructions based on user subscription data.
3. The method according to claim 1 or 2, characterized in that, The selection rule indication sent by the Receive Session Management Function (SMF) includes: Receive N4 messages sent by SMF; Obtain the selection rule indication from the security indication information element in the N4 message.
4. The method according to claim 3, characterized in that, The selection rule indicates that: User plane integrity protection indication is used to indicate the selection of CN endpoints according to the user plane integrity requirements in the user's subscription data; The confidentiality protection instruction is used to instruct users to select the CN endpoint for confidentiality requirements in their contracted data.
5. The method according to claim 3, characterized in that, The N4 message is a Packet Forwarding Control (PFCP) session establishment request message.
6. A UPF forwarding tunnel establishment method, applied to SMF, characterized in that, include: During the PDU session establishment process, user subscription data is obtained; Based on the user subscription data, determine the CN endpoint selection rules for the UPF forwarding tunnel; Send a selection rule indication to the UPF, the selection rule indication being used to indicate the selection rule for the CN endpoint.
7. The method according to claim 6, characterized in that, Sending the rule selection instruction to the UPF includes: Send an N4 message to the UPF, wherein the security indication information element in the N4 message carries the selection rule indication.
8. The method according to claim 7, characterized in that, The selection rule indicates that: User plane integrity protection indication is used to indicate the selection of CN endpoints according to the user plane integrity requirements in the user's subscription data; The confidentiality protection instruction is used to instruct users to select the CN side for confidentiality requirements in their contracted data.
9. The method according to claim 6, characterized in that, The process of obtaining user subscription data during PDU session establishment includes: During the PDU session establishment process, user subscription data is obtained from the Unified Data Management (UDM) or the Unified Data Repository (UDR).
10. A UPF forwarding tunnel establishment device, characterized in that, The method includes at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method as described in any one of claims 1-5, or to perform the method as described in any one of claims 6-9.