Data transmission method, security gateway, control unit, medium and program product
By replacing the packet address during data transmission through a security gateway, the problem of exposing the real address of the user plane gateway is solved, thereby improving network security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2026-01-30
- Publication Date
- 2026-04-24
AI Technical Summary
In an isolated network, the real address of the user plane gateway is exposed to the external network, which expands the network attack surface and reduces security.
By obtaining the address mapping relationship through the security gateway, the destination address of the message sent from the external network is replaced with the real address of the user plane gateway, and the source address of the message sent from the user plane gateway is replaced with the external address. In this way, only the external address is exposed in the external network, avoiding the exposure of the real address.
Reduce the network's attack surface, improve network security, and prevent attackers from exploiting critical network element information.
Smart Images

Figure CN121923927A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network security technology, and in particular to a data transmission method, a security gateway, a control unit, a computer-readable medium, and a computer program product. Background Technology
[0002] Some network elements in an independent network can serve as user plane gateways, allowing other network elements within the network to connect to external networks through these gateways.
[0003] To enable communication with external networks, the real address of the user plane gateway must be exposed to the external network. This results in the information of critical network elements being directly exposed to a complex external risk environment. The real address may be illegally intercepted and used by attackers, expanding the network's attack surface and reducing security. Summary of the Invention
[0004] This disclosure provides a data transmission method, a security gateway, a control unit, a computer-readable medium, and a computer program product.
[0005] In a first aspect, embodiments of this disclosure provide a data transmission method for a security gateway in a first network, wherein a first user plane gateway in the first network is connected to an external network outside the first network through the security gateway; the method includes:
[0006] Obtain the address mapping relationship; the address mapping relationship includes the real address of the first user plane gateway and its corresponding external address;
[0007] In response to receiving a first message from the external network with a destination address of the external address, the destination address of the first message is replaced with the real address, and then the first message is sent to the first user plane gateway.
[0008] In response to receiving a second message whose source address is the real address and which is destined for the external network, the source address of the second message is replaced with the external address, and then the second message is sent to the external network.
[0009] In a second aspect, embodiments of this disclosure provide a data transmission method for a control unit in a first network, wherein a first user plane gateway in the first network is connected to an external network outside the first network via a security gateway; the method includes:
[0010] Obtain the address mapping relationship; the address mapping relationship includes the real address of the first user plane gateway and its corresponding external address;
[0011] The first network is managed according to the address mapping relationship.
[0012] Thirdly, embodiments of this disclosure provide a security gateway, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any of the data transmission methods of embodiments of this disclosure.
[0013] Fourthly, embodiments of this disclosure provide a control unit, which includes a memory and a processor; the memory stores a computer program executable by the processor, and when the computer program is executed by the processor, it implements any of the data transmission methods of embodiments of this disclosure.
[0014] Fifthly, embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any of the data transmission methods of embodiments of this disclosure.
[0015] Sixthly, embodiments of this disclosure provide a computer program product, which includes a computer program that, when executed by a processor, implements any of the data transmission methods of embodiments of this disclosure.
[0016] In this embodiment of the disclosure, for a first packet entering the first network from an external network, the security gateway replaces its destination address from the external address of the first user plane gateway with its real address before transmitting it to the first user plane gateway. For a second packet sent from the first user plane gateway, the security gateway replaces its source address from its real address with its external address before sending it to the external network. Thus, the first network only publicly discloses its external address, while the real address of the first user plane gateway is not publicly disclosed. This avoids the exposure of information of critical network elements, reduces the attack surface of the network, and improves security. Attached Figure Description
[0017] In the accompanying drawings of the embodiments disclosed herein:
[0018] Figure 1 This is an architecture diagram of a network in related technologies.
[0019] Figure 2 This is an architecture diagram of a data transmission method provided in an embodiment of this disclosure.
[0020] Figure 3 An architecture diagram of another data transmission method provided in an embodiment of this disclosure.
[0021] Figure 4 A flowchart illustrating a method for data transmission for a security gateway, as provided in an embodiment of this disclosure.
[0022] Figure 5 A flowchart illustrating a method for data transmission in a control unit, provided as an embodiment of this disclosure.
[0023] Figure 6 This is a block diagram of a security gateway provided in an embodiment of the present disclosure.
[0024] Figure 7 This is a block diagram of a control unit provided in an embodiment of the present disclosure.
[0025] Figure 8 This is a block diagram illustrating the composition of a computer-readable medium provided in an embodiment of the present disclosure.
[0026] Figure 9 This is an example of an architecture diagram of a data transmission method as part of an embodiment of this disclosure.
[0027] Figure 10 This is an architectural diagram of a data transmission method as an example of another part of the embodiments of this disclosure.
[0028] Figure 11 This is a signaling diagram of Example 1 of an embodiment of this disclosure.
[0029] Figure 12 This is a signaling diagram for Example 6 of an embodiment of this disclosure.
[0030] Figure 13 This is a signaling diagram for Example 9 of an embodiment of this disclosure.
[0031] Figure 14 This is a signaling diagram of Example 10 of an embodiment of this disclosure. Detailed Implementation
[0032] To enable those skilled in the art to better understand the technical solutions of this disclosure, the data transmission method, security gateway, control unit, computer-readable medium, and computer program product provided in the embodiments of this disclosure will be described in detail below with reference to the accompanying drawings.
[0033] The present disclosure will be described more fully below with reference to the accompanying drawings; however, the embodiments shown may be embodied in different forms, and the present disclosure should not be construed as limited to the embodiments set forth below. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will enable those skilled in the art to fully understand the scope of the disclosure.
[0034] The accompanying drawings are provided to further illustrate this disclosure and form part of the specification. They are used together with the detailed embodiments to explain this disclosure and do not constitute a limitation thereof. These and other features and advantages will become more apparent to those skilled in the art from the description of detailed embodiments with reference to the accompanying drawings.
[0035] Unless otherwise specified, each embodiment and feature of this disclosure may be used individually or in combination with other embodiments and features thereof.
[0036] Those skilled in the art will understand that various changes in form and detail may be made to the embodiments of this disclosure without departing from the scope of this disclosure as set forth by the appended claims.
[0037] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the disclosure. The term "and / or" as used in this disclosure includes any and all combinations of one or more of the associated enumerated entries. The singular forms "a" and "the" as used in this disclosure are also intended to include the plural forms, unless the context clearly indicates otherwise. The terms "comprising," "made of," etc., as used in this disclosure specify the presence of the stated feature, integral, step, operation, element, and / or component, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof.
[0038] Unless otherwise specified, all terms used in this disclosure (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this disclosure, and will not be interpreted as having an idealized or overly formal meaning, unless expressly so defined in this disclosure.
[0039] This disclosure is not limited to the embodiments shown in the accompanying drawings, but includes modifications to the configuration based on the manufacturing process. Therefore, the areas illustrated in the drawings are schematic, and the shapes of the areas shown illustrate specific shapes of areas of an element, but are not intended to be limiting.
[0040] Driven by the digital wave, network infrastructure is undergoing profound cloudification and ubiquitous evolution.
[0041] For example, with the deep integration of fifth-generation mobile communication (5G), sixth-generation mobile communication (6G), the Internet of Things, and the Industrial Internet, functional virtualization, service-oriented architecture, and open capability interfaces have been realized, transforming the network from a closed communication channel into an open digital foundation that supports the operation of society. The openness and flexibility have been greatly improved, and a wealth of converged services for users (2B) and enterprises (2C) have emerged.
[0042] To achieve network flexibility, cloudification, and extensive roaming capabilities, each relatively independent network, such as carrier networks and campus networks, needs to be able to easily connect to external networks. For example, some network elements in the network can be set up as "gateways," and the network can connect to external networks through the gateways.
[0043] For example, refer to Figure 1Within the operator's network, there is a user plane gateway a, which terminals can connect to via access network elements. Control plane network elements are used to control these network elements. In the campus network, there can be a user plane gateway b, which is connected to the data network (DN). By connecting user plane gateway a and user plane gateway b to the public network, the connection between the operator's network and the campus network can be achieved.
[0044] Therefore, referring to Figure 1 When network elements in the operator's network need to communicate with network elements in the campus network, such as when a terminal needs to access the data network, the control plane network element can control the establishment of a user plane tunnel between user plane gateway a and user plane gateway b to transmit user messages: messages sent from the terminal to the data network need to be sent from user plane gateway a to user plane gateway b through the user plane tunnel, and the source address of the message is the real address IPa1 of user plane gateway a; while messages sent from the data network to the terminal need to be sent from user plane gateway b to user plane gateway a through the user plane tunnel, and the destination address of the message is IPa1.
[0045] Therefore, as a key network element of the operator's network, the real address IPa1 of the user plane gateway a is transmitted in plaintext along with packets in the public network, which is easily intercepted and used by attackers, such as for the abuse of Packet Forwarding Control Protocol (PFCP), user plane distributed denial of service (DDOS) attacks, and signaling plane penetration.
[0046] It should be understood that the real address of user plane gateway a is not limited to being exposed in the packets of the user plane tunnel. For example, when user plane gateway a performs address reporting, its real address will also be exposed.
[0047] It should be understood that user plane gateway b is also a user plane gateway of a network, so it also suffers from the problem of exposing its real address.
[0048] In summary, the network architecture in related technologies leads to the exposure of critical network element information to a complex external risk environment, expanding the network's attack surface and reducing security.
[0049] Firstly, referring to Figures 2 to 5 This disclosure provides a data transmission method for a security gateway in a first network, wherein a first user plane gateway in the first network is connected to an external network outside the first network through the security gateway.
[0050] Reference Figure 2 , Figure 3The data transmission method of this embodiment is performed by a security gateway located in the user plane of a first network.
[0051] The security gateway is connected to the first user plane gateway in the user plane of the first network, and the security gateway is also connected to an external network different from the first network.
[0052] The first user plane gateway is a network element in the first network that acts as an "interface gateway". It connects with other network elements in the user plane of the first network, such as terminals, access network elements, and data networks, and thus can serve as an interface for communication between other network elements and external networks.
[0053] For example, the first network can be a relatively independent communication network of various forms, such as a carrier network or a campus network.
[0054] For example, the first user plane gateway can be various network elements or modules that can function as gateways, such as User Plane Function (UPF), Public Data Network Gateway (PGW), Gateway GPRS Support Node (GGSN), Broadband Remote Access Server (BRAS), Access Controller (AC), etc.
[0055] For example, access network elements can take the form of base stations, access points (APs), access gateways, etc.
[0056] For example, the terminal may be in the form of a mobile phone, tablet computer, etc.
[0057] In this embodiment of the disclosure, the first network may further include a control unit for controlling each network element of the user plane of the first network, and the control unit may be located in the control plane.
[0058] For example, the control unit may refer to Figure 2 This refers to the control plane network element used to control the first network; or, it can also be referred to... Figure 3 The control unit is a signaling gateway connected between the control plane network element and the security gateway.
[0059] In this embodiment of the disclosure, the external network refers to a communication network that is outside the first network and connected to the security gateway, thereby enabling it to communicate with the first user plane gateway.
[0060] For example, see point 2. Figure 3The external network includes a second network, which may include a second user plane gateway. The second user plane gateway may be connected to a security gateway. For example, both the security gateway and the second user plane gateway may be connected to an intermediary network, thereby enabling the first user plane gateway to connect to the external network.
[0061] For example, the second network can also be a relatively independent communication network of various forms, such as a carrier network or a campus network.
[0062] For example, the second user plane gateway may also be a network element or module such as UPF, PGW, GGSN, BRAS, AC, etc. in the second network.
[0063] For example, the intermediary network can be a communication network that is connected to both the first network and the second network, such as the Internet or other public networks.
[0064] It should be understood that the specific forms of the various networks and network elements described above are merely exemplary, and the embodiments disclosed herein are not limited to these specific examples.
[0065] It should be understood that the first network is also an external network for the second network. Therefore, the second network may also have a "second security gateway". The second user plane gateway can connect to the first network through the second security gateway, so that the second security gateway can also execute the method of the embodiments of this disclosure.
[0066] Reference Figure 4 The data transmission method of this disclosure includes:
[0067] S101. Obtain the address mapping relationship.
[0068] The address mapping relationship includes the real address of the first user plane gateway and its corresponding external address.
[0069] S102A: In response to receiving a first message from an external network with a destination address that is an external address, the destination address of the first message is replaced with the real address, and then the first message is sent to the first user plane gateway.
[0070] S102B: In response to receiving a second message whose source address is a real address and which is destined for an external network, the source address of the second message is replaced with the external address, and then the second message is sent to the external network.
[0071] In this embodiment of the disclosure, the security gateway first needs to determine the "address mapping relationship". The address mapping relationship includes the real address of the first user plane gateway to which the security gateway is connected, and the external address "corresponding" to the real address. The external address refers to the address provided by the first network to the external network as a network interface.
[0072] For example, refer to Figure 2 , Figure 3 If the IP address of the first user plane gateway is IPa1, then its real address can be IPa1, while its external address can be another different IP address IPa2.
[0073] Therefore, the destination address of the first message received by the security gateway from the external network and destined for the first user plane gateway must be the external address IPa2. In other words, the external network will "think" that the first message is sent to the external address. Thus, the security gateway can replace the destination address in the first message from the external address to the real address, that is, replace IPa2 with IPa1, so that the first message can be sent to the first user plane gateway according to the real address IPa1.
[0074] It should be understood that replacing the destination address of the first message with the actual address only indicates that the destination of the first message in "this transmission" is the first user plane gateway, or in other words, it only replaces the "outer destination address" of the first message, and does not mean that the "final destination" of the first message is the first user plane gateway. For example, after receiving the first message, the first user plane gateway can decapsulate and analyze it, and then further forward it to other network elements such as terminals, or perform the necessary processing, etc.
[0075] The source address of the second message received by the security gateway from the first user plane gateway and sent to the external network must be the real address IPa1. Therefore, the security gateway can replace the source address of the second message from the real address to the external address, that is, replace IPa1 with IPa2, and then send the second message to the external network. In other words, the external network that receives the second message will "think" that the source address of the second message is the external address IPa2.
[0076] It should be understood that the source address of the second message being a real address means that the second message was sent from the first user plane gateway in "this transmission," or in other words, the "outer source address" of the first message is a real address. However, it does not mean that the "original source" of the second message is the first user plane gateway. For example, the second message could be sent from a terminal or other network element to the first user plane gateway, and then forwarded by the first user plane gateway.
[0077] It should be understood that when a security gateway connects to multiple first user plane gateways simultaneously, the real addresses of these different first user plane gateways are different, and the external addresses corresponding to these different real addresses are also different. Therefore, the security gateway needs to determine "multiple sets" of address mapping relationships, each set including a real address and its corresponding external address.
[0078] For example, when a security gateway has multiple sets of address mapping relationships, upon receiving the first message, it needs to determine which set of address mapping relationships it corresponds to based on the external address in the first message, that is, to determine which first user plane gateway the first message is sent to, and replace the external address with the real address in the corresponding address mapping relationship, and then continue to send the first message to the first user plane gateway with that real address.
[0079] For example, when a security gateway has multiple sets of address mapping relationships, upon receiving a second message, it needs to determine which first user plane gateway the second message comes from based on the real address in the second message, replace the real address with the external address in the corresponding set of address mapping relationships, and then send the second message to the external network.
[0080] In some embodiments, in the address mapping relationship, the real address corresponds to multiple external addresses, and each external address corresponds to a session or a network element in the first network; replacing the source address of the second message with the external address and then sending the second message to the external network (S102B) includes:
[0081] S102B1. Determine the session or network element corresponding to the second message, and replace the source address of the second message with the external address corresponding to the session or network element.
[0082] As one embodiment of this disclosure, in a set of address mapping relationships, one real address can correspond to multiple external addresses, that is, IPa1 and IPa2 can have a "one-to-many" relationship, and different external addresses can correspond to different sessions or network elements, so that the packets of different sessions or network elements in the first network can have different external address information.
[0083] Therefore, when performing address replacement on the second message, the security gateway needs to further determine which session or network element the second message corresponds to, and then replace the real address in it with the external address of the corresponding session or network element.
[0084] The above methods enable each first user plane gateway to present multiple different addresses to the external network, thereby further enhancing the deceptiveness of the publicly disclosed network element information. Moreover, the lifespan of each address is the same as the existence period of the session or network element, and it will not exist for a long time, thus further enhancing the security of the first network.
[0085] In this embodiment of the disclosure, for a first packet entering the first network from an external network, the security gateway replaces its destination address from the external address of the first user plane gateway with its real address before transmitting it to the first user plane gateway. For a second packet sent from the first user plane gateway, the security gateway replaces its source address from its real address with its external address before sending it to the external network. Thus, the first network only publicly discloses its external address, while the real address of the first user plane gateway is not publicly disclosed. This avoids the exposure of information of critical network elements, reduces the attack surface of the network, and improves security.
[0086] In some embodiments, obtaining the address mapping relationship (S101) includes at least one of the following:
[0087] S101A, at least receives the external address sent by the control unit in the first network.
[0088] S101B, at least receives the external address sent by the first user plane gateway.
[0089] To determine the above address mapping relationship, the security gateway obviously needs to obtain the external address of the first user plane gateway.
[0090] As one embodiment of this disclosure, the security gateway may receive the external address of the first user plane gateway from other network elements.
[0091] For example, a security gateway can receive an external address from a control unit, such as a control plane network element or a signaling gateway; while the external address of the control unit can be calculated and generated by itself and then sent to the security gateway, or it can be received from a management plane network element or a first user plane gateway and then "forwarded" to the security gateway.
[0092] For example, the security gateway can also receive the external address from the first user plane gateway. The external address of the first user plane gateway can be calculated and generated by itself and sent to the security gateway, or it can be received from the control unit and "forwarded" to the security gateway.
[0093] It should be understood that the security gateway also needs to obtain the real address of the first user plane gateway and match it with its external address in order to determine the address mapping relationship. However, since the security gateway and the first user plane gateway are in the same network and interconnected, the security gateway can obtain the real address of the first user plane gateway in multiple ways.
[0094] For example, the first user plane gateway can send the real address to the security gateway so that the security gateway can form an address mapping relationship based on the real address and the external address.
[0095] Alternatively, the control unit could send the real address of the first user plane gateway to the security gateway so that the security gateway can form an address mapping relationship.
[0096] For example, the security gateway could pre-save the real address of the first user plane gateway when it goes online to form an address mapping relationship.
[0097] In some embodiments, obtaining the address mapping relationship (S101) includes at least one of the following:
[0098] S101C generates external addresses according to a preset mapping algorithm.
[0099] S101D receives configuration instructions, which include the external address.
[0100] S101E: Use the currently configured address as the external address.
[0101] Alternatively, as another embodiment of this disclosure, the security gateway may also determine its external address "self" in a specific manner.
[0102] For example, a security gateway may have a pre-defined mapping algorithm for generating external addresses. For instance, the security gateway may perform specific operations on the real address and use the result as the external address; alternatively, the security gateway may have a pre-configured address mapping table, from which the appropriate external address is selected based on specific circumstances, such as time or the real address.
[0103] For example, a security gateway can also receive configuration commands input by the administrator and use the external address set in the configuration command.
[0104] For example, as a network element in the first network, the security gateway itself can also be configured with an address, so that the security gateway can directly use its currently configured address as its external address.
[0105] In some embodiments, after obtaining the address mapping relationship (S101), at least one of the following is also included:
[0106] S103A, At least the external address is sent to the control unit in the first network.
[0107] S103B: At least the external address is sent to the first user plane gateway so that the first user plane gateway can forward the external address to the control unit.
[0108] As one embodiment of this disclosure, after the security gateway "self" determines the address mapping relationship, that is, determines the external address, if other network elements in the first network also need an external address, such as the control unit needing to establish a user plane tunnel based on the external address, the security gateway can also send the external address to the control unit, including forwarding the external address to the control unit through the first user plane gateway.
[0109] It should be understood that when the security gateway generates an external address according to a preset mapping algorithm, other network elements such as the control unit can also generate the same external address according to the same mapping algorithm to determine the address mapping relationship, so that the security gateway no longer needs to send the external address.
[0110] Alternatively, when the security gateway determines the external address based on the configuration instructions, other network elements such as the control unit can also receive the same configuration instructions, so the security gateway no longer needs to send the external address.
[0111] Alternatively, when the security gateway uses the currently configured address as its external address, other network elements such as the control unit can directly use the internally stored address of the security gateway as its external address, so that the security gateway no longer needs to send its external address.
[0112] In some embodiments, the security gateway and the first user plane gateway are integrated into one structure.
[0113] As one embodiment of this disclosure, the security gateway can be integrated with the first user plane gateway; or, it can be understood that a module is provided at the interface connecting the first user plane gateway to the external network element, which has the function of a security gateway and can perform address replacement on the "body part" of the packets coming from or sent to the first user plane gateway.
[0114] It should be understood that if it is a reference Figure 2 , Figure 3 It is also feasible for the security gateway and the first user plane gateway to be two independent devices.
[0115] A standalone security gateway can be a new network element or an existing device such as an inter-PLMN user plane security device (IPUPS, Inter-PLMN User Plane Security).
[0116] In some embodiments, the address of the security gateway is an external address.
[0117] As one embodiment of this disclosure, the address used by the security gateway itself may be the external address, including the initial address of the security gateway; or, the security gateway may use its own configured address as the external address and then send the external address to the first user plane gateway, control unit, etc.; or, the security gateway may receive the external address sent by the first user plane gateway, control unit, etc., and then set its own address as the external address.
[0118] Therefore, from the perspective of the external network, the first message sent to the external address will naturally reach the security gateway; while from the perspective of the first user plane gateway, it only needs to set the outer destination address of the second message sent to the outside to the external address, and the message will reach the security gateway. It is evident that by using the external address, the security gateway can easily receive the first and second messages for address replacement.
[0119] Following the above method, the address of the security gateway will also be exposed to the external network. However, unlike the first user plane gateway, which serves as the "interface gateway" of the first network, the security gateway "only" connects directly to the first user plane gateway and does not connect directly to other network elements in the first network. Therefore, the security gateway does not contain information about other network elements, and even if its address is leaked, the impact on network security is relatively limited.
[0120] It should be understood that it is also feasible if the external address is not the address of the security gateway, as long as the second message sent from the external network to the external address can enter the security gateway.
[0121] For example, as a new communication method, the first user plane gateway may also be configured with the external address, or the first user plane gateway may have two addresses, and the security gateway may be located in the necessary routing path between the first user plane gateway and the external network, thereby ensuring that the second message sent to the first user plane gateway will necessarily pass through the security gateway so that address replacement can be performed there.
[0122] For example, as another new communication method, the external address can correspond to the external interface of the first network, but it is not specifically configured on a certain network element of the first network. The first user plane gateway is located at the external interface of the first network, thereby ensuring that all second messages sent to the first network pass through the security gateway.
[0123] In some embodiments, after obtaining the address mapping relationship (S101), the method further includes:
[0124] S104. Announce the external address to the external network.
[0125] As one embodiment of this disclosure, after obtaining the address mapping relationship, the security gateway can continue to announce the external address to the external network, that is, inform the external network that the address of the interface of the first network is the external address, so that the second message sent by the external network to the external address can be correctly routed to the interface of the first network, that is, routed to the security gateway.
[0126] In some embodiments, the external network includes a second network, and the security gateway is connected to a second user plane gateway in the second network;
[0127] The second user plane gateway connects to the external address via a user plane tunnel, and the security gateway is located within the user plane tunnel.
[0128] As one embodiment of this disclosure, reference is made to... Figure 2 , Figure 3 The external network may include the second network mentioned above, such as the carrier network, campus network, etc.; moreover, the second user plane gateway of the second network is connected to the above external address through a "user plane tunnel", and the security gateway is located in the user plane tunnel. Therefore, the packets transmitted in the user plane tunnel must pass through the security gateway. Thus, it can be guaranteed that the security gateway performs correct address replacement for packets from and sent to the first user plane gateway.
[0129] For example, the above user plane tunnel can be a bidirectional user plane tunnel or two unidirectional user plane tunnels in opposite directions.
[0130] For example, the user plane tunnel mentioned above can be in the form of N9 interface tunnel, GPRS Tunneling Protocol (GTP) tunnel, Generic Routing Encapsulation (GRE) tunnel, etc.
[0131] For example, the identifier used to distinguish user plane tunnels may be in the form of a tunnel endpoint identifier (TEID).
[0132] For example, for a user plane tunnel in the first network, the above TEID can be uniquely generated by the first user plane gateway and used to indicate the receiving end of the user plane tunnel; thus, for the user plane tunnel, the receiving end indicated by the TEID is the first user plane gateway, but the address of the receiving end is also the external address.
[0133] In some embodiments, the security gateway is connected to a second user plane gateway via an intermediary network.
[0134] Furthermore, as one embodiment of this disclosure, the second user plane gateway can be connected to the security gateway via an intermediary network such as the Internet. Since intermediary networks are typically relatively open public networks, user plane tunnels passing through intermediary networks are more prone to information leakage, making this method more suitable for embodiments of this disclosure.
[0135] It should be understood that the second network and the intermediate network in the embodiments of this disclosure are not limited to the specific forms described above, and the embodiments of this disclosure are not limited to architectures with a second network and an intermediate network, nor are they limited to architectures with user plane tunnels.
[0136] Secondly, referring to Figures 2 to 5This disclosure provides a data transmission method for a control unit in a first network, wherein a first user plane gateway in the first network is connected to an external network outside the first network through a security gateway.
[0137] Reference Figure 2 , Figure 3 This embodiment of the disclosure is executed by a control unit in a first network.
[0138] Reference Figure 5 The data transmission method of this disclosure includes:
[0139] S201. Obtain the address mapping relationship.
[0140] The address mapping relationship includes the real address of the first user plane gateway and its corresponding external address.
[0141] S202. Manage the first network according to the address mapping relationship.
[0142] As one embodiment of this disclosure, a control unit may also be provided in the first network. The control unit may be located in the control plane and may also obtain the above address mapping relationship in order to manage and control at least some network elements in the first network according to the address mapping relationship.
[0143] In some embodiments, in the address mapping relationship, the real address corresponds to multiple external addresses, and each external address corresponds to a session or a network element in the first network.
[0144] As one embodiment of this disclosure, in a set of address mapping relationships, one real address can correspond to multiple external addresses, that is, IPa1 and IPa2 can have a "one-to-many" relationship, and different external addresses can correspond to different sessions or network elements.
[0145] In some embodiments, obtaining the address mapping relationship (S201) includes at least one of the following:
[0146] S201A, at least receive external addresses from management plane network elements in the first network.
[0147] S201B, at least receive external addresses from the first user plane gateway.
[0148] S201C, at least receive external addresses from the security gateway.
[0149] As one embodiment of this disclosure, the address mapping relationship in the control unit can also be obtained by receiving an external address.
[0150] For example, the control unit can receive the above external addresses from the management plane network element, the first user plane gateway, the security gateway, etc. The external addresses provided by the management plane network element, the first user plane gateway, and the security gateway can be determined by themselves or received from other network elements and forwarded to the control unit.
[0151] For example, the above management plane network elements are network elements located in the management plane and used to manage the first network. They may take the form of Authentication Management Function (AMF), Unified Data Management (UDM), Mobility Management Entity (MME), etc.
[0152] In some embodiments, obtaining the address mapping relationship (S201) includes at least one of the following:
[0153] S201D: Generates an external address according to a preset mapping algorithm.
[0154] S201E: Receive configuration instructions, which include the external address.
[0155] As another embodiment of this disclosure, the external address of the address mapping relationship in the control unit can also be determined by the control unit itself.
[0156] For example, the control unit may generate an external address according to a predetermined mapping algorithm, or it may use an external address set by configuration instructions.
[0157] It should be understood that in order to determine the address mapping relationship, the control unit also needs to obtain the real address of the first user plane gateway. There are various ways to obtain it, such as the control unit receiving its real address from the first user plane gateway, or the control unit receiving the real address issued by the management plane network element, etc., which will not be described in detail here.
[0158] In some embodiments, managing the first network according to the address mapping relationship (S202) includes:
[0159] S202A1, At least send the external address to the security gateway.
[0160] S202A2, At least the external address shall be sent to the first user plane gateway so that the first user plane gateway may forward the external address to the security gateway.
[0161] As one embodiment of this disclosure, after the control unit determines the address mapping relationship, it can send at least the external address to the security gateway, including sending it directly to the security gateway or forwarding it to the security gateway through the first user plane gateway, so that the security gateway can perform address replacement.
[0162] It should be understood that when the control unit and the security gateway each determine the same external address in the same way, or when the control unit receives the external address from the security gateway, the control unit does not need to send the external address to the security gateway.
[0163] It should be understood that the control unit should have the ability to communicate with the security gateway.
[0164] For example, the control unit can be directly or indirectly connected to the security gateway, and can obtain the address of the security gateway in advance, such as receiving its own address sent by the security gateway, or receiving the address of the security gateway issued by the management plane network element, etc.
[0165] In some embodiments, the external network includes a second network, and the security gateway is connected to a second user plane gateway in the second network; managing the first network according to the address mapping relationship (S202) includes:
[0166] S202B1, Send a first tunnel establishment request to the first user plane gateway.
[0167] The first tunnel establishment request is used to control the first user plane gateway to establish a user plane tunnel connecting to the second user plane gateway.
[0168] The method in this disclosure embodiment further includes:
[0169] S202B2, Send a second tunnel establishment request to the second user plane gateway.
[0170] The second tunnel establishment request includes an external address and is used to control the second user plane gateway to establish a user plane tunnel that connects to the external address and passes through a security gateway.
[0171] As one embodiment of this disclosure, the external network may include a second network, and the second user plane gateway of the second network may be connected to a security gateway, such as through an intermediary network like the Internet.
[0172] In this case, under the control of the above control unit, a user plane tunnel connecting the two networks can be established, and the user plane tunnel can specifically be two unidirectional user plane tunnels in opposite directions.
[0173] Therefore, the control unit can send a first tunnel establishment request and a second tunnel establishment request to the first user plane gateway and the second user plane gateway respectively, requesting the two to establish a unidirectional user plane tunnel connecting to each other.
[0174] The first tunnel establishment request sent to the first user plane gateway should include the address of the second user plane gateway so that the first user plane gateway can establish a one-way user plane tunnel connecting to the second user plane gateway.
[0175] Unlike a regular tunnel establishment request, the address of the first user plane gateway carried in the second tunnel establishment request sent to the second user plane gateway is not its real address, but its corresponding external address. That is, the second tunnel establishment request controls the one-way user plane tunnel established by the second user plane gateway, and the other end is connected to the "external address".
[0176] It should be understood that when different sessions or network elements correspond to different external addresses, different second tunnel establishment requests should be sent according to the different external addresses, and user plane tunnels with different sessions or network elements should be established respectively.
[0177] It should be understood that the process of establishing a user plane tunnel may include other known steps besides the steps of the control unit sending the first tunnel establishment request and the second tunnel establishment request to the first user plane gateway and the second user plane gateway, respectively. These steps may include the steps of the user plane gateway issuing a session / tunnel establishment response, the steps of the user plane gateway generating tunnel identifiers such as TEID and sending them to the control unit, and the steps of the control unit sending the tunnel identifier generated by the user plane gateway to the "peer" user plane gateway. These steps will not be described in detail here.
[0178] In some embodiments, the second tunnel establishment request includes a Forwarding Action Rule (FAR), with the external address carried in the FAR.
[0179] As one embodiment of this disclosure, the second tunnel establishment request may include a FAR, and the external address may be carried in the FAR and sent.
[0180] It should be understood that the specific form of the second tunnel establishment request, or the specific form of the message carrying the external address, is not limited to FAR.
[0181] In some embodiments, the control unit is a control plane element of the first network.
[0182] As one embodiment of this disclosure, reference is made to... Figure 2 The control unit can be an existing network element or module in the control plane of the communication network that is used to transmit control plane messages, that is, a control plane network element.
[0183] For example, control plane network elements can take the form of Service Management Facility (SMF), Serving Gateway (SGW), Serving General Packet Radio Service Support Node (SGSN), etc.
[0184] In some embodiments, the control unit is a signaling gateway connected between the control plane network element of the first network and the security gateway.
[0185] As one embodiment of this disclosure, reference is made to... Figure 3 The control unit can also be a newly added signaling gateway, which is connected between the control plane network element and the security gateway.
[0186] Since a security gateway can be a "new" network element, existing control plane network elements may not necessarily have an interface to connect to it, nor may they necessarily have the ability to perform operations related to address mapping.
[0187] Therefore, it can be referred to Figure 3 A signaling gateway is provided in the control plane, connecting the control plane network element and the security gateway, as the control unit of this embodiment; thus, the structure and function of the original control plane network element in the first network can be implemented without changing the structure of the control plane network element.
[0188] For example, the signaling gateway can be a newly added network element, or it can be a proxy entity or other forms.
[0189] In some embodiments, sending a second tunnel establishment request to a second user plane gateway (S202B1) includes:
[0190] S202B11, Receive the original second tunnel establishment request from the control plane network element.
[0191] The original second tunnel establishment request includes the real address and is used to control the second user plane gateway to establish a user plane tunnel connecting to the real address.
[0192] S202B2: Replace the real address in the original second tunnel establishment request with the external address to obtain the second tunnel establishment request, and send the second tunnel establishment request to the second user plane gateway.
[0193] As one embodiment of this disclosure, when the control unit is in the form of the above signaling gateway, the control plane network element can generate an original second tunnel establishment request in a conventional manner according to the needs of the session. The original second tunnel establishment request carries the real address of the first user plane gateway. That is, the original second tunnel establishment request is used to control the second user plane gateway to establish a user plane tunnel connecting to the first user plane gateway.
[0194] In this case, the control plane network element will first send the original second tunnel establishment request to the signaling gateway, which is the control unit. The signaling gateway can find the corresponding external address based on the session and the real address, and replace the real address in the original second tunnel establishment request with the external address, making it "become" a second tunnel establishment request, and then send the second tunnel establishment request to the second user plane gateway.
[0195] It should be understood, with reference Figure 3 When the above signaling gateways are present, during the establishment of the user plane tunnel, various interactions with the first user plane gateway can still be directly executed by the control plane network elements.
[0196] It should be understood, with reference Figure 3 When the above signaling gateways are present, various operations related to external addresses, such as sending external addresses to the security gateway, can also be performed by the above signaling gateways.
[0197] In some embodiments, the signaling gateway and the control plane network element are integrated into one structure.
[0198] As one embodiment of this disclosure, the signaling gateway can also be integrated with the control plane network element. For example, the interface connecting the control plane network element to the security gateway and the second user plane gateway may be equipped with a module that functions as a signaling gateway.
[0199] The following describes the data transmission method of this disclosure embodiment with reference to some examples.
[0200] Reference Figure 9 , Figure 10 In the following example, the first network of this disclosure embodiment is an operator network, wherein the user plane gateway a is the first user plane gateway of this disclosure embodiment, its pre-configured real address is IPa1, and the corresponding external address is represented by IPa2. The first user plane gateway is connected to the terminal through the access network element and is controlled by the control plane network element, which is controlled by the management plane network element.
[0201] The second network in this embodiment is a campus network, wherein the user plane gateway b is the second user plane gateway in this embodiment, its address is IPb, and it is connected to the data network.
[0202] User plane gateway b also passes through a security gateway via the public network; therefore, the public network is the intermediary network in this embodiment of the disclosure.
[0203] Example 1
[0204] Reference Figure 9 In this example, the control plane network element serves as the control unit in this embodiment of the disclosure, and it is directly connected to the security gateway through a newly added interface.
[0205] Reference Figure 11 This example describes the process of establishing a user plane tunnel in the data transmission method, which includes the following steps:
[0206] A100, the control plane network element determines the address mapping relationship between IPA1 and IPA2 of user plane gateway a.
[0207] In this step, the address mapping relationship can be generated by the control plane network element according to a specific mapping algorithm, or it can be received from the management plane network element, or it can be set by the configuration command input by the user.
[0208] A101. The control plane network element determines that a user plane tunnel needs to be established between user plane gateway a and user plane gateway b, so it initiates the user plane tunnel establishment process between user plane gateway a and user plane gateway b.
[0209] A102. The control plane network element sends a session establishment request message to the user plane gateway b, namely the "second tunnel establishment request" in this embodiment of the present disclosure, and carries IPa2 in the FAR of the session establishment request message.
[0210] A103. Upon receiving the session establishment request message, the user plane gateway b generates a tunnel identifier b, such as TEIDb.
[0211] Tunnel identifiers can be used to uniquely indicate user plane tunnels. For example, the receiving user plane gateway of each unidirectional user plane tunnel can generate its own corresponding TEID and send it to the control unit. The control unit then sends the TEID to the user plane gateway at the other end. The other end can then indicate that the message should be sent to the receiving user plane gateway through the data plane tunnel by carrying the TEID in the message.
[0212] A104. User plane gateway b sends a session establishment response message, or tunnel establishment response message, to the control plane network element, carrying the tunnel identifier b.
[0213] A105. The control plane network element sends a session establishment request message to the user plane gateway a, namely the "first tunnel establishment request" in this embodiment of the present disclosure, and carries the address IPb and tunnel identifier b of the user plane gateway b in the session establishment request message.
[0214] Optionally, this step can also be divided into two separate messages: one message carrying IPb and the other message carrying tunnel identifier b.
[0215] A106. After receiving the session establishment request message, the user plane gateway a generates a tunnel identifier a, which is TEIDa.
[0216] A107. User plane gateway a sends a session establishment response message to the control plane network element, carrying tunnel identifier a.
[0217] A108. The control plane network element sends the tunnel identifier a to the user plane gateway b.
[0218] A109. The control plane network element sends the address mapping relationship between IPa1 and IPa2 to the security gateway.
[0219] A110. The security gateway stores the address mapping relationship between IPa1 and IPa2.
[0220] It should be understood that steps A109 and A110 above can be performed at any time after the address mapping relationship is determined in step A100 and before the actual transmission of packets using the user plane tunnel.
[0221] It should be understood that the execution order of steps A105~A108, in which the control plane network element interacts with user plane gateway a, and steps A102~A104, in which the control plane network element interacts with user plane gateway b, can be interchanged. That is, the control plane network element can first send a session establishment request message to user plane gateway a and obtain the tunnel identifier a returned by it, then send a session establishment request message to user plane gateway b, and additionally carry the tunnel identifier a in it, and then send the tunnel identifier b obtained from user plane gateway b to user plane gateway a separately.
[0222] Example 2
[0223] This example is similar to Example 1, except that:
[0224] In this example, the security gateway generates the address mapping relationship between IPa1 and IPa2 according to the mapping algorithm, and then sends the address mapping relationship to the control plane network element.
[0225] In this example, since the address mapping relationship is generated by the security gateway, steps A100 and A109 no longer need to be executed.
[0226] In this example, the step of the security gateway sending the address mapping relationship to the control plane network element is feasible as long as it is completed before step A102, that is, before the control plane network element sends the session establishment request message carrying IPa2 to the user plane gateway b.
[0227] Example 3
[0228] This example is similar to Example 1, except that:
[0229] In this example, the user plane gateway a generates the address mapping relationship between IPa1 and IPa2 according to the mapping algorithm, and then the user plane gateway a sends IPa2 to the control plane network element at least once; while the address mapping relationship between IPa1 and IPa2 can be sent to the security gateway by the control plane network element or the user plane gateway a, which is equivalent to replacing step A109.
[0230] In this example, since the address mapping is generated by the user plane gateway a, step A100 no longer needs to be executed.
[0231] In this example, the step of sending the address mapping relationship to the control plane network element is feasible as long as it is completed before step A102, that is, before the control plane network element sends the session establishment request message carrying IPa2 to the user plane gateway b.
[0232] Example 4
[0233] This example is similar to Example 1, except that:
[0234] In this example, there is no direct interface connection between the control plane network element and the security gateway. The address mapping relationship between IPa1 and IPa2 is generated by the security gateway according to the mapping algorithm. Then, the security gateway sends IPa2 to the user plane gateway a, and the user plane gateway a forwards IPa2 to the control plane network element.
[0235] In this example, since the address mapping relationship is generated by the security gateway, steps A100 and A109 no longer need to be executed.
[0236] In this example, user plane gateway a should obtain IPA2 sent by the security gateway before step A102 and forward it to the control plane network element.
[0237] For example, if the control plane network element first sends a session establishment request message to the user plane gateway a, then the user plane gateway a can request IPa2 from the security gateway after receiving the session establishment request message, and add IPa2 to the session establishment response message, and send it to the control plane network element together with its own generated TEIDa, so that the control plane network element can subsequently send a session establishment response message carrying IPa2 to the user plane gateway b.
[0238] Example 5
[0239] This example is similar to Example 1, except that:
[0240] In this example, the address mapping relationship between IPa1 and IPa2 is generated by the control plane network element and the security gateway respectively based on a consistent mapping algorithm, such as selecting the address mapping relationship from a pre-set address mapping relationship table.
[0241] In this example, since the address mapping relationship is generated by the control plane network element and the security gateway respectively, step A109 no longer needs to be executed, or it can be understood that step A109 is replaced by the step of the security gateway generating the address mapping relationship.
[0242] Example 6
[0243] Reference Figure 10 In this example, a signaling gateway is also provided between the control plane network element and the security gateway, serving as the control unit of this embodiment, so that the signaling gateway provides the address mapping relationship to the security gateway.
[0244] Reference Figure 12 This example describes the process of establishing a user plane tunnel in the data transmission method, which includes the following steps:
[0245] A200, the signaling gateway generates, configures, or obtains the address mapping relationship between IPA1 and IPA2 of user plane gateway a.
[0246] A201. The control plane network element determines that a user plane tunnel needs to be established between user plane gateway a and user plane gateway b, so it initiates the user plane tunnel establishment process between user plane gateway a and user plane gateway b.
[0247] A202. The control plane network element sends a session establishment request message to the signaling gateway, namely the "original second tunnel establishment request" in this embodiment of the disclosure, which carries the real address IPa1 of the user plane gateway a in its FAR.
[0248] A203. The signaling gateway replaces IPa1 in the FAR of the session establishment request message with IPa2 to obtain a new session establishment request message, namely the "second tunnel establishment request" in this embodiment of the present disclosure, thereby avoiding the transmission of IPa1 in the public network.
[0249] A204. The signaling gateway sends a session establishment request message to the user plane gateway b, and its FAR carries IPa2.
[0250] A205. Upon receiving the session establishment request message, the user plane gateway b generates tunnel identifier b.
[0251] A206. User plane gateway b sends a session establishment response message to the signaling gateway, carrying tunnel identifier b.
[0252] A207. The signaling gateway forwards the received session establishment response message to the control plane network element.
[0253] A208. The control plane network element sends a session establishment request message to the user plane gateway a, carrying the tunnel identifier b and IP b.
[0254] Optionally, this step can also be divided into two separate messages: one message carrying IPb and the other message carrying tunnel identifier b.
[0255] A209. After receiving the session establishment request message, the user plane gateway a generates the tunnel identifier a.
[0256] A210. User plane gateway a sends a session establishment response message to the control plane network element, which carries the tunnel identifier a.
[0257] A211. The control plane network element sends the tunnel identifier a to the user plane gateway b via the signaling gateway.
[0258] A212. The signaling gateway notifies the security gateway of the address mapping relationship between IPa1 and IPa2.
[0259] A213. The security gateway stores the address mapping relationship between IPa1 and IPa2.
[0260] It should be understood that steps A212 and A213 above can be performed at any time after the address mapping relationship is determined in step A200 and before the actual transmission of packets using the user plane tunnel.
[0261] It should be understood that the execution order of steps A208~A210, in which the control plane network element interacts with user plane gateway a, and steps A202~A207, in which the control plane network element, signaling gateway, and user plane gateway b interact, can be interchanged. That is, the control plane network element can first send a session establishment request message to user plane gateway a and obtain the tunnel identifier a returned by it, then send a session establishment request message to user plane gateway b, and additionally carry the tunnel identifier a in it, and then send the tunnel identifier b obtained from user plane gateway b separately to user plane gateway a.
[0262] Example 7
[0263] This example is similar to Example 6, except that:
[0264] In this example, the security gateway generates the address mapping relationship between IPa1 and IPa2 and provides this address mapping relationship to the signaling gateway.
[0265] In this example, since the address mapping relationship is generated by the security gateway, steps A200 and A212 no longer need to be executed.
[0266] In this example, the step of sending the address mapping relationship to the signaling gateway is feasible as long as it is completed before step A203, that is, before the signaling gateway replaces the address in the session establishment request message.
[0267] For example, after receiving a session establishment request message, the signaling gateway may request IPa2 from the security gateway and then replace IPa1 in the session establishment request message with IPa2.
[0268] Example 8
[0269] This example is similar to Example 6, except that:
[0270] In this example, the address mapping relationship between IPa1 and IPa2 is generated by the signaling gateway and the security gateway respectively based on a consistent mapping algorithm, such as selecting the address mapping relationship from a pre-set address mapping relationship table.
[0271] In this example, since the address mapping relationship is generated by the signaling gateway and the security gateway respectively, step A212 no longer needs to be executed, or it can be understood that step A212 is replaced by the step of the security gateway generating the address mapping relationship.
[0272] Example 9
[0273] Reference Figure 9 , Figure 10 This example describes the process of transmitting data through the user plane tunnel after establishing it according to the methods described in the examples above.
[0274] Reference Figure 13 The method in this example includes the following steps:
[0275] A301. The terminal sends a second message to the user plane gateway a via the access network element.
[0276] A302. User plane gateway a forwards the second message to user plane gateway b. Its outer source address is IPa1 and its outer destination address is IPb.
[0277] Since the security gateway is located at the interface of the user plane of the operator's network, or in other words, in the user plane tunnel, the second message sent by the user plane gateway a will first be sent to the security gateway.
[0278] A303. After receiving the second message from user plane gateway a, the security gateway looks up the address mapping relationship and converts the outer source address of the second message from IPa1 to IPa2.
[0279] A304. The security gateway sends a second message, which carries the tunnel identifier b, with the outer source address being IPa2 and the destination address being IPb.
[0280] It is evident that the second message sent over the public network did not expose the real address IPa1 of the user plane gateway a, thus achieving the purpose of address hiding.
[0281] Example 10
[0282] Reference Figure 9 , Figure 10 This example describes the process of transmitting data through the user plane tunnel after establishing it according to the methods described in the examples above.
[0283] Reference Figure 14 The method in this example includes the following steps:
[0284] A401. User plane gateway b receives the first message sent to the terminal, such as the first message from the data network.
[0285] A402. User plane gateway b sends a first message to user plane gateway a, which carries tunnel identifier a; and, based on the information received in the FAR, user plane gateway b sets the outer destination address of the message to IPa2, and also sets the outer source address of the message to IPb.
[0286] Since the security gateway is located at the interface of the carrier network user plane, or in other words, in the user plane tunnel, the first packet will be routed to the security gateway according to IPa2.
[0287] It is evident that the first message sent through the public network did not expose the real address IPa1 of the user plane gateway a, thus achieving the purpose of address hiding.
[0288] A403. After receiving the first message from user plane gateway b, the security gateway looks up the address mapping relationship and converts the outer destination address of the first message from IPa2 to IPa1.
[0289] A404. The security gateway sends the first message to the user plane gateway a, which carries the tunnel identifier a, the outer source address is IPb, and the outer destination address is IPa1.
[0290] A405. User plane gateway a looks up the local session table based on the tunnel identifier a in the first message, decapsulates the message, and analyzes it.
[0291] A406. User plane gateway a sends the first message to the terminal through the access network element.
[0292] Example 11
[0293] This example is similar to the examples above, except that:
[0294] In this example, one physical address IPa1 can correspond to multiple external addresses IPa2, and different IPa2 correspond to different network elements or sessions.
[0295] For example, refer to Figure 9 , Figure 10 The terminal in the network can be IPA2-1, and the external address of other terminals or sessions in the first network can be IPA2-2, IPA2-3, IPA2-4, etc.
[0296] Correspondingly, when generating the address mapping relationship between IPa1 and IPa2, control plane network elements, security gateways, user plane gateways, signaling gateways, etc., need to generate different IPa2 for each different terminal or session.
[0297] Correspondingly, when storing address mapping relationships, control plane network elements, security gateways, and signaling gateways need to record the correspondence between each IPA1 and multiple IPA2s, and record which terminal or session each IPA2 corresponds to.
[0298] Correspondingly, during the establishment of the user plane tunnel, the control plane network element and the signaling gateway need to select a specific IPA2 from the multiple IPA2s corresponding to IPA1 and add it to the session establishment request message, based on which terminal or session the user plane tunnel corresponds to.
[0299] Correspondingly, after the user plane tunnel is established, when the security gateway receives the first message destined for user plane gateway a, the IPa2 carried in it should be one of the multiple IPa2s corresponding to IPa1. Therefore, the security gateway may replace different IPa2s in different first messages with the same IPa1 before sending them to user plane gateway a.
[0300] Correspondingly, after the user plane tunnel is established, when the security gateway receives the second message destined for the user plane gateway b, it can find multiple different IPa2s based on IPa1. Therefore, the security gateway also needs to select the corresponding IPa2 to replace IPa1 based on which terminal or session the second message comes from, such as the inner source address of the second message, and then send it to the user plane gateway b.
[0301] Thirdly, referring to Figure 6 This disclosure provides a security gateway, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any of the data transmission methods of this disclosure.
[0302] Fourthly, refer to Figure 7 This disclosure provides a control unit, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any of the data transmission methods of this disclosure.
[0303] Fifthly, refer to Figure 8 This disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements any of the data transmission methods of this disclosure.
[0304] Sixthly, embodiments of this disclosure provide a computer program product, which includes a computer program that, when executed by a processor, implements any of the data transmission methods of embodiments of this disclosure.
[0305] In this embodiment of the disclosure, the processor is a device with data processing capabilities, including but not limited to a central processing unit (CPU); the memory is a device with data storage capabilities, including but not limited to random access memory (RAM), more specifically such as SDRAM, DDR, etc., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory (FLASH); the I / O interface, or read-write interface, is connected between the processor and the memory, enabling information exchange between the memory and the processor, including but not limited to a data bus (Bus).
[0306] Those skilled in the art will understand that all or some of the steps, systems, and devices disclosed above, as functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0307] In hardware implementations, the division between functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be executed by several physical components working together.
[0308] Some or all of the physical components may be implemented as software executed by a processor, such as a central processing unit (CPU), digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software may be distributed on a computer-readable medium, which may include computer storage media and communication media. In embodiments of this disclosure, computer storage media include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, and any other media that can be used to store desired information and can be accessed by a computer. In embodiments of this disclosure, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
Claims
1. A method for data transmission, used in a security gateway in a first network, wherein a first user plane gateway in the first network is connected to an external network outside the first network through the security gateway; the method includes: Obtain the address mapping relationship; The address mapping relationship includes the real address of the first user plane gateway and its corresponding external address; In response to receiving a first message from the external network with a destination address of the external address, the destination address of the first message is replaced with the real address, and then the first message is sent to the first user plane gateway. In response to receiving a second message whose source address is the real address and which is destined for the external network, the source address of the second message is replaced with the external address, and then the second message is sent to the external network.
2. The method according to claim 1, wherein, The acquisition of the address mapping relationship includes at least one of the following: At least receive the external address sent by the control unit in the first network; At least the external address sent by the first user plane gateway is received.
3. The method according to claim 1, wherein, The acquisition of the address mapping relationship includes at least one of the following: The external address is generated according to a preset mapping algorithm; Receive a configuration instruction, the configuration instruction including the external address; The currently configured address is used as the external address.
4. The method according to claim 1, wherein, After obtaining the address mapping relationship, at least one of the following is also included: The external address should be sent to at least the control unit in the first network; The external address is sent to the first user plane gateway at least once, so that the first user plane gateway can forward the external address to the control unit.
5. The method according to claim 1, wherein, The security gateway and the first user plane gateway are integrated into one structure.
6. The method according to claim 1, wherein, In the address mapping relationship, the real address corresponds to multiple external addresses, and each external address corresponds to a session or a network element in the first network; The step of replacing the source address of the second message with the external address and then sending the second message to the external network includes: Determine the session or network element corresponding to the second message, and replace the source address of the second message with the external address corresponding to that session or network element.
7. The method according to claim 1, wherein, The address of the security gateway is the external address.
8. The method according to claim 1, wherein, After obtaining the address mapping relationship, the following is also included: The external address is announced to the external network.
9. The method according to claim 1, wherein, The external network includes a second network, and the security gateway is connected to a second user plane gateway in the second network; The second user plane gateway is connected to the external address through a user plane tunnel, and the security gateway is located in the user plane tunnel.
10. The method according to claim 9, wherein, The security gateway is connected to the second user plane gateway through an intermediary network.
11. A method for data transmission, used in a control unit in a first network, wherein a first user plane gateway in the first network is connected to an external network outside the first network via a security gateway; the method includes: Obtain the address mapping relationship; The address mapping relationship includes the real address of the first user plane gateway and its corresponding external address; The first network is managed according to the address mapping relationship.
12. The method according to claim 11, wherein, The acquisition of the address mapping relationship includes at least one of the following: At least the external address received from the management plane network element in the first network; At least the external address received from the first user plane gateway; At least the external address received from the security gateway.
13. The method according to claim 11, wherein, The acquisition of the address mapping relationship includes at least one of the following: The external address is generated according to a preset mapping algorithm; Receive configuration instructions, the configuration instructions including the external address.
14. The method according to claim 11, wherein, Managing the first network according to the address mapping relationship includes at least one of the following: At least the external address should be sent to the security gateway; The external address is sent to the first user plane gateway at least once, so that the first user plane gateway can forward the external address to the security gateway.
15. The method according to claim 11, wherein, In the address mapping relationship, the real address corresponds to multiple external addresses, and each external address corresponds to a session or a network element in the first network.
16. The method according to claim 11, wherein, The external network includes a second network, and the security gateway is connected to a second user plane gateway in the second network; The step of managing the first network according to the address mapping relationship includes: sending a first tunnel establishment request to the first user plane gateway; the first tunnel establishment request is used to control the first user plane gateway to establish a user plane tunnel connecting to the second user plane gateway. The method further includes: sending a second tunnel establishment request to the second user plane gateway; the second tunnel establishment request includes the external address and is used to control the second user plane gateway to establish a user plane tunnel connected to the external address and passing through the security gateway.
17. The method according to claim 16, wherein, The second tunnel establishment request includes a forwarding action rule (FAR), in which the external address is carried.
18. The method according to claim 16, wherein, The control unit is a control plane element of the first network.
19. The method of claim 16, wherein, The control unit is a signaling gateway connected between the control plane network element of the first network and the security gateway.
20. The method according to claim 19, wherein, Sending the second tunnel establishment request to the second user plane gateway includes: Receive an original second tunnel establishment request from the control plane network element; the original second tunnel establishment request includes the real address and is used to control the second user plane gateway to establish a user plane tunnel connected to the real address; The real address in the original second tunnel establishment request is replaced with the external address to obtain the second tunnel establishment request, which is then sent to the second user plane gateway.
21. The method according to claim 19, wherein, The signaling gateway and the control plane network element are integrated into one structure.
22. A security gateway comprising a memory and a processor; the memory storing a computer program executable by the processor, the computer program, when executed by the processor, implementing the data transmission method according to any one of claims 1 to 10.
23. A control unit comprising a memory and a processor; the memory storing a computer program executable by the processor, the computer program, when executed by the processor, implementing the data transmission method according to any one of claims 11 to 21.
24. A computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the method of data transmission according to any one of claims 1 to 21.
25. A computer program product comprising a computer program that, when executed by a processor, implements the method of data transmission as described in any one of claims 1 to 21.