Data transmission method, device, equipment, medium and program product

By adding a P4 programmable converged gateway within the cloud resource pool and establishing a tunnel using shared virtual routing forwarding instances, the problem of limited service scenarios for user-side target terminals accessing cloud resources and complex core network configuration in the 5G environment was solved. This enabled highly secure and high-quality end-to-end access, improving network service quality and activation efficiency.

CN122053485APending Publication Date: 2026-05-15CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD
Filing Date
2026-02-12
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In a 5G environment, existing technologies present challenges when user-side target terminals access the public cloud via wireless networks. These challenges include limited business scenarios, complex core network configurations, and unreliable network quality, making it difficult to meet the demands for service quality, resource isolation, and load balancing across multiple business scenarios.

Method used

By adding a P4 programmable converged gateway within the cloud resource pool, a tunnel is established between user plane function network elements and cloud-network converged network elements using shared virtual routing forwarding instances. This enables tunnel encapsulation and decapsulation, reduces core network configuration complexity, improves 5G cloud access efficiency, and ensures the security and isolation of user service traffic.

Benefits of technology

It enables highly secure, high-quality, and highly isolated end-to-end access to cloud resources in 5G2B service scenarios, simplifies core network configuration, and improves network service quality and commissioning efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053485A_ABST
    Figure CN122053485A_ABST
Patent Text Reader

Abstract

The invention discloses a data transmission method and device, equipment, a storage medium and a program product, and the method comprises the steps: carrying out the tunnel packaging of user service request flow transmitted by a target terminal, and obtaining a user plane tunnel packaging message; sending the user plane tunnel encapsulation message to a cloud network convergence network element based on a shared virtual routing forwarding instance; wherein the shared virtual routing forwarding instance is used for bearing a tunnel between the user plane function network element and the cloud network convergence network element; and receiving a cloud network tunnel encapsulation message sent by the cloud network convergence network element, and performing tunnel de-encapsulation on the cloud network tunnel encapsulation message to obtain a user service response flow.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing technology, and in particular to a data transmission method, apparatus, device, storage medium, and program product. Background Technology

[0002] With the continuous development of cloud computing and network technologies, efficient and secure data transmission between target terminal devices and public clouds has become a key issue in enterprise network architecture. To achieve interconnection between local data centers and cloud resources, various methods are currently employed, including dedicated cloud lines, public network access to the cloud, and Software-Defined Wide Area Network (SD-WAN). In the 5G environment, it has become common for user-side target terminals to access the network via wireless networks and utilize the operator's core network for traffic forwarding. In related technologies, 5G target terminals accessing the public cloud typically use User Plane Function (UPF) to encapsulate service traffic using Generic Routing Encapsulation (GRE) / Internet Protocol Security (IPsec) tunneling, and then decapsulate it via the core network aggregation router before forwarding it to the cloud platform. However, this method relies on fixed tunnel mechanisms and specific routing paths, lacking flexibility and failing to meet the demands for service quality, resource isolation, and load balancing in multi-service scenarios. Summary of the Invention

[0003] To address the aforementioned technical problems, embodiments of this application provide a data transmission method, apparatus, device, storage medium, and program product.

[0004] The data transmission method provided in this application embodiment is applied to a user plane function network element, including: The user service request traffic sent by the target terminal is tunnel encapsulated to obtain user plane tunnel encapsulated packets; The user plane tunnel encapsulation message is sent to the cloud-network converged network element based on the shared virtual routing forwarding instance; wherein, the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the cloud-network converged network element; The system receives cloud-network tunnel encapsulation messages sent by the cloud-network converged network element and performs tunnel decapsulation on the cloud-network tunnel encapsulation messages to obtain user service response traffic.

[0005] The data transmission method provided in this application embodiment is applied to cloud-network converged network elements, including: The system receives user plane tunnel encapsulation packets sent by user plane function network elements through a shared virtual routing forwarding instance; wherein, the user plane tunnel encapsulation packets are obtained by the user plane function network element performing tunnel encapsulation on user service request traffic sent by the target terminal; and the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the programmable cloud-network converged network element. The user plane tunnel encapsulation message is decapsulated to obtain the user service request traffic, and the user service request traffic is forwarded to the virtual private cloud; Receive user service response traffic sent by the virtual private cloud, and perform tunnel encapsulation on the user service response traffic to obtain a cloud network tunnel encapsulation message; Send the cloud network tunnel encapsulation message to the user plane function network element.

[0006] The data transmission apparatus provided in this application embodiment is applied to a user plane function network element and includes: The first processing unit is used to perform tunnel encapsulation on the user service request traffic sent by the target terminal to obtain user plane tunnel encapsulation messages. The first sending unit is used to send the user plane tunnel encapsulation message to the cloud-network converged network element based on a shared virtual routing forwarding instance; wherein, the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the cloud-network converged network element; The first receiving unit is used to receive cloud network tunnel encapsulation messages sent by the cloud network converged network element; The first processing unit is also used to decapsulate the cloud network tunnel encapsulation message to obtain the user service response traffic.

[0007] The data transmission device provided in this application embodiment is applied to a cloud-network converged network element and includes: The second receiving unit is used to receive user plane tunnel encapsulation messages sent by the user plane function network element through a shared virtual routing forwarding instance; wherein, the user plane tunnel encapsulation message is obtained by the user plane function network element performing tunnel encapsulation on the user service request traffic sent by the target terminal; the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the programmable cloud-network converged network element. The second processing unit is used to decapsulate the user plane tunnel encapsulation message to obtain the user service request traffic. The second sending unit is used to forward the user service request traffic to the virtual private cloud; The second receiving unit is also used to receive user service response traffic sent by the virtual private cloud; The second processing unit is further configured to perform tunnel encapsulation on the user service response traffic to obtain a cloud network tunnel encapsulation message; The second sending unit is also used to send the cloud network tunnel encapsulation message to the user plane function network element.

[0008] The communication device provided in this application includes a processor and a memory. The memory is used to store computer programs, and the processor is used to call and run the computer programs stored in the memory to execute any of the above-described data transmission methods.

[0009] The computer-readable storage medium provided in this application embodiment is used to store a computer program that causes a computer to execute any of the above-described data transmission methods.

[0010] The computer program product provided in this application includes computer program instructions that cause a computer to execute any of the above-described data transmission methods.

[0011] In the technical solution of this application embodiment, the user plane function network element performs tunnel encapsulation on the user service request traffic sent by the target terminal to obtain a user plane tunnel encapsulation message; the user plane tunnel encapsulation message is sent to the cloud-network converged network element based on a shared virtual routing forwarding instance; wherein, the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the cloud-network converged network element; the cloud-network tunnel encapsulation message sent by the cloud-network converged network element is received, and the cloud-network tunnel encapsulation message is decapsulated to obtain the user service response traffic. Thus, by establishing a shared virtual routing forwarding instance between the user plane function network element and the cloud-network converged network element to achieve tunnel communication, the core network configuration complexity can be reduced, and the efficiency of 5G cloud access can be improved; at the same time, by utilizing the tunnel encapsulation and decapsulation mechanism, the security and isolation of user service traffic can be ensured, thereby improving network service quality. Attached Figure Description

[0012] Figure 1 This is a schematic diagram of the architecture for a 5G target terminal to access a public cloud in the related technologies provided in the embodiments of this application; Figure 2 This is a flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 1 ; Figure 3 This is a flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 2 ; Figure 4 This is a schematic diagram of the architecture of the method for accessing the cloud resource pool in a 5G2B service scenario provided in the embodiments of this application; Figure 5 This is a schematic diagram of the structure of the data transmission device provided in the embodiments of this application. Figure 1 ; Figure 6This is a schematic diagram of the structure of the data transmission device provided in the embodiments of this application. Figure 2 ; Figure 7 This is a schematic diagram of the structure of the communication device provided in the embodiments of this application. Detailed Implementation

[0013] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0014] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0015] Currently available cloud access methods include dedicated cloud lines, public network access, and SD-WAN access. Dedicated cloud lines enable enterprises to connect their own data centers to cloud resources via wired physical dedicated lines. Public network access enables internet access to cloud resources by opening elastic public IP addresses within the cloud. SD-WAN access enables interconnection between branches, the cloud, and data centers through point-of-presence (POP) access points built by cloud service providers.

[0016] like Figure 1 The diagram illustrates the architecture of a 5G target terminal accessing a public cloud in the related technologies provided in this application. The typical process for a 5G target terminal to access a public cloud is as follows: the user-side target terminal accesses the cloud via a 5G wireless network; service traffic is carried by the local IP Radio Access Network (IPRAN), passes through the core network UPF and core network aggregation router, and then accesses the public cloud through the operator's public network boundary router. Specifically, a GRE / IPsec tunnel is established between the UPF and the core network aggregation router. Inbound traffic is encapsulated by the UPF and decapsulated by the core network aggregation router; outbound traffic is encapsulated by the core network aggregation router and decapsulated by the UPF.

[0017] However, the above method still has the following drawbacks: (1) Limited business scenarios: Users must access the 5G network and access the cloud through a 5G Customer Premise Equipment (CPE), resulting in limited user scenarios. In situations where there is no 5G CPE, users still need to access the cloud through the 5G network, but the relevant technologies do not support this; for example, drones and wireless cameras cannot access the cloud through a 5G CPE in high-speed moving scenarios.

[0018] (2) The core network requires complex configuration: a large number of network configurations are required for key network elements such as the core network UPF and core network aggregation routers. This involves the configuration of virtual private networks (VPN), virtual routing forwarding (VRF), sub-interfaces, etc. of related devices, which affects the stability of existing core network services. The activation time is calculated in weeks.

[0019] (3) Core network UPF elements access the cloud through public network boundary routers, and end-to-end network quality cannot be guaranteed. Since the public network is shared by all users, it cannot provide users with a secure, reliable, stable, and high-speed way to access the cloud.

[0020] Based on this, this application proposes a data transmission method, which aims to provide a method for accessing a cloud resource pool in a 5G2B service scenario. By adding a P4 programmable converged gateway in the cloud resource pool, the core network configuration is simplified, and the problem of single service scenario is solved. By establishing a dedicated line interconnection between the core network and the cloud resource pool, a high-security, high-quality, and highly isolated end-to-end solution for users to access cloud resources is provided.

[0021] To facilitate understanding of the technical solutions of the embodiments of this application, the technical solutions of this application are described in detail below through specific embodiments. The above-mentioned related technologies are optional solutions and can be arbitrarily combined with the technical solutions of the embodiments of this application, all of which fall within the protection scope of the embodiments of this application. The embodiments of this application include at least some of the following contents.

[0022] This application proposes a data transmission method, which is applied to a user plane function network element. This user plane function network element is one of the key components in the 5G core network architecture and is responsible for encapsulating, forwarding, and processing the service request traffic sent by the target terminal device. Figure 2 This is a flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 1 ,like Figure 2 As shown, the method includes the following steps: Step 201: Perform tunnel encapsulation on the user service request traffic sent by the target terminal to obtain user plane tunnel encapsulated packets.

[0023] Here, after the target terminal (such as a drone or camera) accesses the network via the 5G wireless network, it will initiate data requests to the cloud resource pool. These requests may include service types such as video uploads, remote control, and data collection. Since these service traffics need to traverse multiple network domains, they require encapsulation using tunneling technology to ensure that data can be correctly transmitted from the source to the destination. Tunnel encapsulation refers to adding a new header containing the source and destination addresses to the outer layer of the original service data packet to facilitate correct forwarding in the intermediate network. This process of adding a new header containing the source and destination addresses to the outer layer of the original service data packet can be implemented using various tunneling protocols such as GRE and IPsec, enabling the service traffic to be correctly identified and forwarded within a shared virtual routing forwarding instance.

[0024] In this embodiment, the user plane function network element receives user service request traffic sent by the target terminal, and selects an appropriate tunneling protocol to encapsulate the user service request traffic according to the service requirements corresponding to the traffic, thus obtaining a user plane tunnel encapsulated message. The user plane function network element selects different tunneling protocols based on the service requirements of different users. The user service request traffic carries a source address and a destination address; the source address is the user's private network IP address, and the destination address is the virtual private cloud intranet IP address.

[0025] It should be noted that user plane function network elements can also set bandwidth rate limiting policies for tunnels to restrict user-side access traffic in order to prevent network congestion and ensure service quality.

[0026] Step 202: Send user plane tunnel encapsulation packets to cloud-network converged network elements based on the shared virtual routing forwarding instance.

[0027] Among them, the shared virtual routing forwarding instance is used to carry the tunnel between user plane function network elements and cloud-network converged network elements.

[0028] Here, a shared virtual routing forwarding instance (VRF) is a logical network isolation technology, specifically referring to an MPLS Layer 3 Virtual Private Network (MPLS-L3VPN) instance. A shared VRF allows multiple users or services to share the same VRF instance, thereby reducing the configuration complexity of network devices and improving resource utilization. In this application, tunnel communication between user plane function network elements and cloud-network converged network elements is based on routing forwarding using shared virtual routing forwarding instances.

[0029] The cloud-network converged network element refers to the P4 programmable cloud-network converged gateway deployed within a cloud resource pool. P4 is a data plane-oriented programming language that supports flexible configuration of data forwarding behavior for network devices. In this application, the P4 programmable cloud-network converged gateway possesses encapsulation and decapsulation capabilities for various tunnel protocols, such as GRE, IPsec, and Virtual Extensible Local Area Network (VXLAN). Utilizing these capabilities, the P4 programmable cloud-network converged gateway implements a complete service path from user plane functions to hosts within the cloud. Through the P4 programmable cloud-network converged gateway, flexible routing policies and security controls can be provided to ensure the security and stability of service traffic.

[0030] In this embodiment, the user plane function network element and the cloud-network converged network element establish a tunnel connection through a shared virtual routing forwarding instance, forming an end-to-end service tunnel. All users share a single shared virtual routing forwarding instance on the cloud private line network. After the user plane function network element performs tunnel encapsulation on the user service request traffic sent by the target terminal and obtains the user plane tunnel encapsulated packet, it sends the user plane tunnel encapsulated packet to the cloud-network converged network element through the shared virtual routing forwarding instance. Since the shared virtual routing forwarding instance has already preset the correct routing information, the packet sent by the user plane function network element can accurately reach the cloud-network converged network element and enter the subsequent decapsulation processing procedure.

[0031] Step 203: Receive the cloud-network tunnel encapsulation message sent by the cloud-network converged network element, and decapsulate the cloud-network tunnel encapsulation message to obtain the user service response traffic.

[0032] Here, cloud-network tunnel encapsulation refers to the response data packet returned from the cloud-network converged network element to the user plane function network element, which typically contains service response content processed within the cloud. Tunnel decapsulation refers to removing the tunnel header information attached to the packet to restore the original service response traffic. The tunnel decapsulation process is executed by the user plane function network element, and the decapsulated service response traffic will be sent back to the target terminal by the user plane function network element, thus completing the entire service interaction process.

[0033] In this embodiment, when the user plane function network element receives the cloud-network tunnel encapsulation message sent by the cloud-network converged network element, it will perform a tunnel decapsulation operation on the cloud-network tunnel encapsulation message according to the corresponding tunnel parameters and private network routing information to obtain the original user service response traffic. The user service response traffic will be sent to the user-side subnet and finally delivered to the target terminal device. Here, user service response traffic refers to service data returned from the cloud resource pool to the user side, such as server responses, database query results, and remote control commands.

[0034] In some embodiments, the above method further includes: Receive configuration information sent by the cloud-network convergence management and control platform. The configuration information includes the mapping relationship between the private network IP address, private network virtual routing forwarding instance and tunnel port identifier corresponding to each terminal. Determine the identifier of the first tunnel port corresponding to the target terminal; The first tunnel port identifier is matched in the configuration information to obtain the user private network virtual route forwarding instance corresponding to the target terminal, and the user private network virtual route forwarding instance corresponds to the user private network route.

[0035] Here, the cloud-network convergence management and control platform refers to the control plane system responsible for managing and distributing 5G cloud access-related configuration information. This platform centrally manages the access policies and network parameters of multiple target terminals. Configuration information defines how target terminals access the private network environment in the cloud resource pool via tunneling protocols. The private network IP address is an independent IP address assigned to each terminal by the cloud-network convergence network element. It is a "user isolation IP" used by the cloud network side for user traffic isolation and local forwarding, belonging to the internal management address of the cloud network domain, and not the user's actual private network source IP address from the 5G core network. The private network virtual routing forwarding instance is a logical routing table independently created for each terminal or tenant, used to achieve network isolation between different users. The tunnel port identifier is a unique identifier used to identify the tunnel interface used by the target terminal.

[0036] Specifically, the process by which user plane function network elements receive configuration information can be either proactively pushed by the cloud-network convergence management and control platform when the target terminal first accesses the network or when its configuration changes, or passively obtained by the target terminal upon request. The cloud-network convergence management and control platform performs unified mapping of the configuration information to ensure the accuracy and consistency of subsequent tunnel establishment and routing forwarding.

[0037] In this embodiment, the cloud-network convergence management and control platform sends configuration information to the user plane function network element, including the private network IP addresses of different terminals, the mapping relationship between user private network virtual routing forwarding instances and tunnel port identifiers. Then, the user plane function network element parses the identity information of the target terminal and determines the first tunnel port identifier corresponding to the target terminal based on the identity information of the target terminal. Then, it matches the first tunnel port identifier with the mapping relationship in the configuration information to find the user private network virtual routing forwarding instance corresponding to the target terminal, and further obtains the user private network route corresponding to the user private network virtual routing forwarding instance. The user private network route is an internal network routing policy for the target terminal, which is used to guide the forwarding path of user service request traffic sent by the target terminal in the private network.

[0038] Among them, the first tunnel port identifier is a unique tunnel port identifier assigned by the user plane function network element to the target terminal.

[0039] In addition, to improve service reliability, the user plane function network element also supports a primary and backup switching mechanism. That is, the user plane function network element is deployed with a primary user plane function network element and a backup user plane function network element. The primary user plane function network element is configured with a primary static route, and the backup user plane function network element is configured with a backup static route.

[0040] The primary user plane function network element refers to the core network device responsible for handling user service request traffic under normal working conditions; the primary static route is a pre-configured fixed path information, specifically a static route pointing to the Virtual Private Cloud (VPC) network segment within the cloud, used to guide traffic to be forwarded according to the specified next-hop address.

[0041] Backup user plane function network elements refer to redundant network elements that can take over the service processing capabilities of the primary user plane function network element when it fails. Backup user plane function network elements have the same network functions and interface capabilities as the primary user plane function network elements, and are pre-configured with corresponding backup static routes so that service takeover can be completed without additional configuration during the switchover.

[0042] Backup static routes refer to static route entries pre-configured for each tenant's service, pointing to backup user plane function network elements. Backup static route entries are normally inactive and are only activated when the primary user plane function network element fails. The configuration method for backup static routes is the same as that for primary static routes, including parameters such as destination address and next-hop address. Backup static routes have a lower priority than primary static routes, ensuring that traffic does not mistakenly take the backup path during normal operation. By pre-configuring backup static routes, they can be immediately activated in the event of a failure in the primary user plane function network element, reducing switchover latency and ensuring service continuity.

[0043] In some embodiments, the above method further includes: The primary user plane function network element performs tunnel encapsulation on the user service request traffic based on the first tunnel interface and the first tunnel source IP address to obtain a user plane tunnel encapsulation message. The user plane tunnel encapsulation message carries the first tunnel source IP address and the first tunnel port identifier. The primary user plane function network element sends user plane tunnel encapsulation packets to the cloud-network converged network element based on the user's private network routing, shared virtual route forwarding instance, and primary static route; The primary user plane function network element receives cloud-network tunnel encapsulation messages sent by the cloud-network converged network element, and performs tunnel decapsulation on the cloud-network tunnel encapsulation messages based on the first tunnel interface to obtain user service response traffic.

[0044] Here, the user plane function network element is configured with a first tunnel interface and a first tunnel source IP address. The first tunnel interface refers to the logical or physical network interface used by the user plane function network element to establish tunnel communication with the cloud-network converged network element, and it is the entry point for data transmission between the user plane function network element and the cloud-network converged network element. The first tunnel interface is used to encapsulate the user service request traffic sent by the target terminal into tunnel encapsulation packets conforming to a specific tunnel protocol (such as GRE, IPsec) format, and transmit them to the cloud-network converged network element through the cloud private line network.

[0045] The first tunnel source IP address is the IP address used by the user plane function network element to identify itself as the tunnel sender, and it is also the source IP address used by the user plane function network element when encapsulating user service request traffic. The first tunnel source IP address remains unchanged throughout the entire tunnel communication process and is used by the cloud-network converged network element to identify the data source and perform correct decapsulation operations. In this application, multiple user tunnels share the same first tunnel source IP address to reduce the configuration complexity on the core network side.

[0046] Specifically, according to the above method, after determining the user's private network route corresponding to the target terminal, under normal operating conditions, the primary user plane function network element will perform tunnel encapsulation on the user service request traffic based on the first tunnel interface and the first tunnel source IP address, obtaining a user plane tunnel encapsulation packet. This user plane tunnel encapsulation packet includes the original service data (user service request traffic) and tunnel header information, and carries the first tunnel source IP address and the first tunnel port identifier. Then, the primary user plane function network element will determine the redirection point to the shared virtual route forwarding instance based on the configuration in the user's private network route. The system generates flow rules and imports shared virtual routing forwarding instances through these rules. It then combines these rules with primary static routes to determine the forwarding path. Based on this forwarding path, the user plane tunnel encapsulated packets are routed sequentially through the firewall and cloud private line network to the cloud-network converged network element. The primary user plane function network element then receives the cloud-network tunnel encapsulated packets sent by the cloud-network converged network element and performs tunnel decapsulation on the cloud-network tunnel encapsulated packets according to the configuration of the first tunnel interface. This removes the tunnel header from the cloud-network tunnel encapsulated packets and restores the original service data before encapsulation, thereby obtaining the user service response traffic returned from the cloud resource pool to the user side.

[0047] In some embodiments, the above method further includes: When the primary user plane function network element fails, it receives operation information sent by the session management function network element. The operation information is used to instruct the primary tunnel and primary static route between the primary user plane function network element and the cloud-network converged network element to be set to invalid, the backup tunnel and backup static route between the backup user plane function network element and the cloud-network converged network element to be set to valid, and the user service request traffic to be switched to the backup user plane function network element.

[0048] Here, the disaster recovery user plane function network element refers to the user plane function network element used to implement disaster recovery functions. This role is typically assumed by a backup user plane function network element. It possesses the same functional characteristics as the primary user plane function network element, but under normal circumstances, it does not participate in service forwarding. It is only automatically activated when the primary user plane function network element fails to ensure service continuity. For example, the disaster recovery user plane function network element can be deployed in a remote data center to cope with regional disaster events, thereby achieving a high-availability architecture across regions.

[0049] Specifically, the session management function network element monitors the operational status of the primary user plane function network element in real time using mechanisms such as heartbeat detection and link monitoring. Once a failure is detected in the primary user plane function network element, and the route to the tunnel address between the primary user plane function network element and the cloud-network converged network element becomes unreachable, the session management function network element sends operation information to the user plane function network element. This information instructs the connection status of the primary tunnel established between the primary user plane function network element and the cloud-network converged network element to be invalidated, meaning that the primary tunnel is no longer allowed to carry any service traffic. The status of the primary static route is also invalidated to prevent traffic from continuing to be transmitted through unreliable paths. At the same time, the status of the backup tunnel and the backup static route between the backup user plane function network element and the cloud-network converged network element are made valid, thereby guiding user service request traffic to switch to the backup user plane function network element for processing.

[0050] It should be noted that the specific process by which the backup user plane function network element sends user service request traffic to the cloud-network converged network element is the same as the specific process by which the primary user plane function network element sends user service request traffic to the cloud-network converged network element, and will not be elaborated further here.

[0051] In the technical solution of this application embodiment, the user plane function network element performs tunnel encapsulation on the user service request traffic sent by the target terminal to obtain a user plane tunnel encapsulation message; the user plane tunnel encapsulation message is sent to the cloud-network converged network element based on a shared virtual routing forwarding instance; wherein, the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the cloud-network converged network element; the cloud-network tunnel encapsulation message sent by the cloud-network converged network element is received, and the cloud-network tunnel encapsulation message is decapsulated to obtain the user service response traffic. Thus, by establishing a shared virtual routing forwarding instance between the user plane function network element and the cloud-network converged network element to achieve tunnel communication, the core network configuration complexity can be reduced, and the efficiency of 5G cloud access can be improved; at the same time, by utilizing the tunnel encapsulation and decapsulation mechanism, the security and isolation of user service traffic can be ensured, thereby improving network service quality.

[0052] This application also proposes a data transmission method, which is applied to a cloud-network converged network element. Specifically, the cloud-network converged network element is a P4 programmable cloud-network converged gateway in a cloud resource pool. It integrates multiple network functions and is a key bridge connecting the cloud network and the external cloud network. Figure 3 This is a flowchart illustrating the data transmission method provided in the embodiments of this application. Figure 2 ,like Figure 3 As shown, the method includes the following steps: Step 301: Receive user plane tunnel encapsulation packets sent by user plane function network elements through the shared virtual routing forwarding instance.

[0053] Among them, the user plane tunnel encapsulation message is obtained by the user plane function network element performing tunnel encapsulation on the user service request traffic sent by the target terminal; the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the programmable cloud network converged network element.

[0054] In this embodiment, the user plane function network element serves as the entry point for user-side traffic. It encapsulates the user service request traffic generated by the target terminal to obtain a user plane tunnel encapsulation message, and transmits it to the cloud-network converged network element in the cloud resource pool through a shared virtual routing forwarding instance. Thus, the cloud-network converged network element receives the user plane tunnel encapsulation message sent by the user plane function network element through the shared virtual routing forwarding instance.

[0055] It should be noted that cloud-network converged network elements can also be configured with bandwidth limiting policies to limit the rate of service traffic entering the resource pool, thereby ensuring the stable operation of cloud resources.

[0056] Step 302: Decapsulate the user plane tunnel encapsulation message to obtain the user service request traffic, and forward the user service request traffic to the virtual private cloud corresponding to the target terminal.

[0057] Here, a virtual private cloud is a logically isolated computing and network environment provided for a specific tenant (target terminal) within a cloud resource pool, offering high security and flexibility.

[0058] In this embodiment, the cloud-network converged network element can perform multi-layer protocol stripping during the tunnel desealing process, parse the user plane tunnel encapsulation message sent from the user plane function network element, extract the original user service request traffic, and forward the user service request traffic to the virtual private cloud corresponding to the target terminal through a routing matching mechanism. The virtual private cloud then provides resources to support the operation of cloud hosts, containers, or other services within the target terminal.

[0059] Step 303: Receive user service response traffic sent by the virtual private cloud, and perform tunnel encapsulation on the user service response traffic to obtain cloud network tunnel encapsulation messages.

[0060] In this embodiment, user service response traffic refers to the response data returned after processing a user service request in the virtual private cloud. After processing the user service request traffic in the virtual private cloud, user service return traffic is generated and sent to the cloud-network converged network element. After receiving the user service response traffic sent by the virtual private cloud, the cloud-network converged network element will perform tunnel encapsulation on the user service response traffic again to form a cloud-network tunnel encapsulation message.

[0061] In addition, cloud-network converged network elements can embed rate limiting, QoS and other policies during the encapsulation of user service response traffic to further ensure service quality.

[0062] Step 304: Send cloud-network tunnel encapsulation messages to user plane function network elements.

[0063] In this embodiment, after the cloud-network converged network element completes tunnel encapsulation of the user service response traffic to obtain the cloud-network tunnel encapsulated message, it will send the cloud-network tunnel encapsulated message to the user plane function network element through a shared virtual routing forwarding instance. After receiving the cloud-network tunnel encapsulated message, the user plane function network element will further decapsulate the cloud-network tunnel encapsulated message to obtain the original user service response traffic and send the user service response traffic to the target terminal.

[0064] In actual deployments, cloud-network converged network elements and user plane function network elements can be connected via Optical Transport Network (OTN) or high-speed Ethernet to ensure low latency and high bandwidth data transmission. Cloud-network converged network elements also support a primary / backup failover mechanism. User plane function network elements are deployed with a primary user plane function element and a backup user plane function element. When the primary user plane function element fails, the primary tunnel between the cloud-network converged network element and the primary user plane function element becomes unreachable, and the primary tunnel status is set to invalid. Simultaneously, user service request traffic will switch to the backup user plane function element, and the backup tunnel between the cloud-network converged network element and the backup user plane function element will be enabled.

[0065] In some embodiments, the above method further includes: The network function virtualization network element receives user plane tunnel encapsulation packets sent by the user plane function network element through the shared virtual routing forwarding instance, and forwards the user plane tunnel encapsulation packets to the tunnel decapsulation subsystem based on the network segment static route; The tunnel decapsulation subsystem decapsulates user plane tunnel-encapsulated packets to obtain user service request traffic.

[0066] Here, cloud-network converged network elements include network function virtualization (NFV) network elements and tunnel decapsulation subsystems. NFV network elements specifically refer to Virtual Private Gateways (VGWs), used to implement the virtualization deployment of traditional physical network element functions. The tunnel decapsulation subsystem is a device specifically designed to receive and parse encapsulated packets, used for decapsulating user plane tunnel-encapsulated packets and for encapsulating user service response traffic returned from the virtual private cloud.

[0067] Among them, network function virtualization (NFV) network elements are configured with static network segment routes. Static network segment routes are pre-configured static routing table entries in NFV network elements, used to forward data traffic from a specific IP network segment to a specified next-hop path. Static network segment routes are not dynamically updated; instead, they are manually configured by the administrator based on business needs. Static network segment routes ensure that business traffic is forwarded along a predetermined path, avoiding traffic detours or packet loss, and improving forwarding efficiency and reliability. For example, in a 5G cloud deployment scenario, if the target address of a user's business request is located in a specific network segment, configuring static network segment routes can directly guide the user's business request traffic to the corresponding processing node for processing.

[0068] Specifically, when a Network Functions Virtualization (NFV) element receives a user plane tunnel encapsulation packet sent by a user plane function element through a shared virtual routing forwarding instance, the NFV element forwards the packet to the tunnel decapsulation subsystem based on the network segment's static routing. The tunnel decapsulation subsystem then decapsulates the received user plane tunnel encapsulation packet, removing the tunnel header information to restore the original user service request traffic. This user service request traffic carries a source address and a destination address. The source address is the user's private network source IP address, and the destination address is the virtual private cloud intranet IP address. The user's private network source IP address is assigned to the target terminal by the session management element during the Protocol Data Unit (PDU) session establishment phase. It is encapsulated within the tunnel layer for end-to-end transparent transmission and remains unchanged throughout the transmission and processing by the user plane function element, firewall, cloud leased line, NFV element, and tunnel decapsulation subsystem, without being replaced or modified by any intermediate network element.

[0069] In some embodiments, the above method further includes: Receive configuration information sent by the cloud-network convergence management and control platform. The configuration information includes the mapping relationship between the private network IP address, private network virtual routing forwarding instance and tunnel port identifier corresponding to each terminal. The first tunnel port identifier is matched in the configuration information to obtain the user's private network IP address and the user's private network virtual route forwarding instance corresponding to the target terminal. The user's private network IP address corresponds to the second tunnel interface, and the user's private network virtual route forwarding instance corresponds to the user's private network route.

[0070] Among them, the cloud-network converged network element is configured with a second tunnel interface corresponding to the target terminal and a user private network IP address; the user plane tunnel encapsulation message carries the first tunnel source IP address and the first tunnel port identifier corresponding to the target terminal.

[0071] Here, the cloud-network converged network element configures a second tunnel interface and a private network IP address for each terminal. In this application, the second tunnel interface is a virtual interface configured separately for the target terminal on the cloud-network converged network element. It is used to receive encapsulated packets sent from the user plane function network element and to map the second tunnel interface to the corresponding user private network IP address. The user private network IP address is a user isolation identifier address used within the cloud network domain for user traffic isolation and local forwarding. It only applies to internal forwarding, user identification, and traffic isolation between the tunnel decapsulation subsystem and the network function virtualization network element. It is not the terminal's real private network source IP address. Each terminal has a different second tunnel interface and private IP address.

[0072] Specifically, the cloud-network converged network element receives configuration information from the cloud-network converged management and control platform, including the mapping relationship between the private network IP address, private network virtual routing forwarding instance, and tunnel port identifier corresponding to different terminals. The mapping relationship between the private network IP address, private network virtual routing forwarding instance, and tunnel port identifier ensures that each terminal can be correctly routed to the private network environment to which the terminal belongs. Then, after receiving the user plane tunnel encapsulation packet sent by the user plane function network element, the cloud-network converged network element matches the first tunnel port identifier carried in the user plane tunnel encapsulation packet with the mapping relationship in the configuration information, finds the entry corresponding to the first tunnel port identifier, and thus determines the user private network IP address and user private network virtual routing forwarding instance corresponding to the first tunnel port identifier. The user private network IP address is used to identify the location of the target terminal in the private network within the cloud, while the user private network virtual routing forwarding instance determines which virtual subnet the user service request traffic is routed to. Among them, the user private network IP address corresponds to the second tunnel interface, and the user private network virtual routing forwarding instance corresponds to the user private network route.

[0073] In some embodiments, the above method further includes: The tunnel unblocking subsystem binds user service request traffic to the second tunnel interface and forwards the user service request traffic to the network function virtualization network element based on the user's private network routing. The network function virtualization network element forwards user service request traffic to the virtual private cloud based on the first tunnel port identifier and the source and destination addresses of the user service request traffic. The virtual private cloud is used to forward user service request traffic to hosts within the cloud.

[0074] Specifically, after decapsulating the user plane tunnel encapsulation packets and obtaining the user service request traffic, the tunnel decapsulation subsystem binds the user service request traffic to the second tunnel interface corresponding to the target terminal. This second tunnel interface achieves physical-level isolation between the user service request traffic and other service traffic. During this process, the user's private network IP address allocated to the target terminal by the cloud-network converged network element is only used for local routing and user differentiation. It does not overwrite, modify, or replace the user's private network source IP address allocated to the target terminal by the session management function network element in the original service packet. The source and destination addresses of the original service traffic remain in their original state after decapsulation, ensuring transparency and consistency in end-to-end service transmission.

[0075] Next, the tunnel unblocking subsystem will combine the user's private network route corresponding to the target terminal, use the destination address (virtual private cloud intranet IP address) of the original business request traffic as the matching keyword, query to obtain the forwarding exit pointing to the network function virtualization element, and forward the user's business request traffic to the network function virtualization element.

[0076] Upon receiving user service request traffic, the Network Functions Virtualization (NFV) element first confirms user ownership and access permissions based on the first tunnel port identifier corresponding to the target terminal and the source address of the user service request traffic (user's private network source IP address). This completes user-level security verification and routing domain matching. Subsequently, the NFV element queries its locally maintained virtual private cloud routing table and virtual private cloud network segment mapping table based on the destination address of the original service request traffic (virtual private cloud intranet IP address) to determine the virtual private cloud to which the destination address belongs, the corresponding virtual private cloud identifier, and the intranet tunnel identifier. Through this mapping relationship, the NFV element binds the user service request traffic to the virtual private cloud corresponding to the target terminal and forwards the user service request traffic to the virtual private cloud corresponding to the target terminal via the intranet backbone virtual network, completing the routing forwarding from the cloud-network converged access layer to the corresponding virtual private cloud.

[0077] Once user service request traffic reaches the boundary access point of the virtual private cloud corresponding to the target terminal, it is uniformly taken over by the virtual routing and forwarding module and the virtual switching module within the virtual private cloud. The virtual private cloud maintains the subnet segments, host routes, ARP entries, and virtual port mapping relationships to achieve tenant isolation and precise host-level forwarding.

[0078] First, the virtual routing module matches the destination address (VPN internal network IP address) in the original service request traffic against the VPN internal subnet routing table to determine the VPN internal subnet to which the destination address belongs and the forwarding egress virtual switch. Then, the VPN uses a VXLAN tunnel encapsulation mechanism to add a VXLAN network identifier corresponding to the target subnet and target tenant to the user service request traffic. This is then flooded and forwarded point-to-point through the overlay virtual network within the VPN. The VXLAN network identifier is used to identify the isolation domains of different tenants, different VPNs, and different subnets, ensuring that traffic is only transmitted within its own VPN and does not intersect with traffic from other tenants.

[0079] At the virtual switching layer within the Virtual Private Cloud (VPN), the virtual switch queries the Address Resolution Protocol (ARP) table and host port binding table based on the destination address (VPN internal network IP address) to obtain the virtual port identifier and Media Access Control Address (MAC) corresponding to the destination host within the cloud. It then forwards the VXLAN packets through the virtual port to the corresponding virtual network interface card (vNIC) of the target host within the cloud. Finally, the host within the cloud receives user service request traffic from the virtual NIC, completing the full uplink packet transmission from the target terminal to the host within the cloud.

[0080] In some embodiments, the above method further includes: The network function virtualization network element receives user service response traffic sent by the virtual private cloud and forwards the user service response traffic to the tunnel encapsulation subsystem; The tunnel desealing subsystem encapsulates the user service response traffic to obtain the cloud network tunnel encapsulation message, and forwards the cloud network tunnel encapsulation message to the network function virtualization network element; wherein, the cloud network tunnel encapsulation message carries the first tunnel source IP address and the first tunnel port identifier corresponding to the target terminal; Network function virtualization network elements send cloud-network tunnel encapsulation messages to user plane function network elements.

[0081] Specifically, after a host within the cloud completes the processing of a user's service request, the Virtual Private Cloud (VPN) returns the corresponding user service response traffic. The source address of the user service response traffic is the VPN's internal network IP address, and the destination address is the user's private network source IP address. This user service response traffic is then forwarded through the VPN's internal virtual router and VXLAN tunnel to the cloud's dedicated line gateway network function virtualization element, and then forwarded by the network function virtualization element to the tunnel encapsulation subsystem.

[0082] After receiving user service response traffic, the tunnel encapsulation subsystem matches the user's private network source IP address in the local mapping table to obtain the user's private network IP address corresponding to the target terminal based on the user's private network source IP address in the user service response traffic. Then, based on the user's private network IP address corresponding to the target terminal, it queries the mapping relationship between the private network IP address, private network virtual routing forwarding instance, and tunnel port identifier corresponding to each terminal to obtain the first tunnel port identifier corresponding to the target terminal. Subsequently, the tunnel encapsulation subsystem performs tunnel encapsulation on the user service response traffic based on the first tunnel source IP address and the first tunnel port identifier, generating a cloud network tunnel encapsulation packet. That is, the cloud network tunnel encapsulation packet carries the first tunnel source IP address and the first tunnel port identifier corresponding to the target terminal.

[0083] The first tunnel source IP address is the IP address used by the user plane function network element to identify itself as the tunnel sender, and it is also the source IP address used by the user plane function network element when encapsulating user service request traffic. The first tunnel source IP address remains unchanged throughout the tunnel communication process and is used by the cloud-network converged network element to identify the data source and perform correct decapsulation operations. In this application, multiple user tunnels share the same first tunnel source IP address to reduce the configuration complexity on the core network side.

[0084] Next, the tunnel encapsulation subsystem sends the cloud-network tunnel encapsulation message to the network function virtualization (NFV) element. The NFV element, based on the cloud dedicated line route and the first tunnel source IP address and the first tunnel port identifier corresponding to the target terminal carried in the tunnel encapsulation message, performs transparent forwarding of the cloud-network tunnel encapsulation message, directly forwarding it to the user plane function element. Upon receiving the cloud-network tunnel encapsulation message, the user plane function element performs tunnel decapsulation, parses the first tunnel port identifier to identify the corresponding target terminal, and forwards the original user service response traffic to the target terminal, thereby completing the downlink backhaul service transmission.

[0085] In the technical solution of this application embodiment, the cloud-network converged network element receives user plane tunnel encapsulation packets sent by the user plane function network element through a shared virtual routing forwarding instance; it decapsulates the user plane tunnel encapsulation packets to obtain user service request traffic, and forwards the user service request traffic to the virtual private cloud corresponding to the target terminal; it receives user service response traffic sent by the virtual private cloud, and performs tunnel encapsulation on the user service response traffic to obtain cloud-network tunnel encapsulation packets; it sends cloud-network tunnel encapsulation packets to the user plane function network element; wherein, the user plane tunnel encapsulation packets are obtained by the user plane function network element performing tunnel encapsulation on the user service request traffic sent by the target terminal; the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the programmable cloud-network converged network element. Thus, by establishing a shared virtual routing forwarding instance between the user plane function network element and the cloud-network converged network element to achieve tunnel communication, the complexity of core network configuration can be reduced, and the efficiency of 5G cloud access can be improved; at the same time, by utilizing the tunnel encapsulation and decapsulation mechanism, the security and isolation of user service traffic can be ensured, thereby improving network service quality.

[0086] This application also proposes a method for accessing a cloud resource pool in a 5G2B service scenario. By adding a P4 programmable converged gateway within the cloud resource pool, the core network configuration is simplified, addressing the issue of limited service scenarios. Furthermore, by establishing a dedicated line interconnection between the core network and the cloud resource pool, a high-security, high-quality, and highly isolated end-to-end solution for users to access cloud resources is provided. Specifically, this method mainly includes the following: (1) Supports flexible access to the 5G network for user-side terminals to access the cloud, with comprehensive business scenarios: cameras, drones and other devices with wireless functions can directly insert a SIM card to complete 5G access; servers and other devices without wireless functions can complete 5G access through CPE.

[0087] (2) Simplify core network configuration: UPF connects to the cloud private line network through OTN connection network PE, minimizing the workload of core network configuration, without affecting the existing core network services, improving the efficiency of 5G cloud access, and shortening the access time to within 80%.

[0088] (3) Compared with public network access to the cloud, operators establish private cloud dedicated lines to ensure that users' private network access to the cloud is more secure and the network quality is guaranteed.

[0089] (4) Add a P4 programmable cloud network converged gateway to the resource pool to support various tunnel protocols, including encapsulation and decapsulation of IPSec, GRE and other protocols.

[0090] like Figure 4 The diagram shown is an architectural representation of the method for accessing a cloud resource pool in a 5G2B service scenario provided in this application embodiment. The specific content of the method will be described in detail below.

[0091] (1) The tunnel is established between the UPF and the P4 programmable cloud network converged gateway. Uplink traffic is encapsulated in the tunnel through the UPF and then uncapsulated in the cloud resource pool through the P4 programmable cloud network converged gateway. Downlink traffic is encapsulated in the tunnel through the P4 programmable cloud network converged gateway and then uncapsulated in the UPF.

[0092] (2) All user tunnels in the UPF, cloud private line network and cloud resource pool share the MPLS-L3VPN instance. Tenants isolate services through the tunnel. Uplink traffic is deblocked through the P4 programmable cloud network convergence gateway and sent to the VPC; downlink traffic is deblocked through the UPF and sent to the user side subnet.

[0093] (3) Establish tunnel source and destination address routing between UPF and P4 programmable cloud-network converged gateway. To reduce the configuration on the core network UPF side, different user tunnels share a single interface and address on the UPF, and each user is configured with a separate interface and IP address on the P4 programmable cloud-network converged gateway.

[0094] (4) In order to isolate traffic between users in the core network UPF and cloud resource pool, a user private network VPN is configured for each user and a user private network route is configured.

[0095] (5) The core network UPF performs bandwidth rate limiting on the access side user traffic, and the cloud-internal P4 programmable cloud-network converged gateway performs bandwidth rate limiting on the user traffic accessing the cloud. When configuring VPC static routes on the UPF, primary and backup are configured between the two tunnels. When configuring static routes to the 5G network segment on the VGW, primary and backup are configured between the next hops of the two deblocking subsystems.

[0096] (6) Tunnel IP addresses are planned globally in a unified manner to avoid duplication. The leased network is pre-configured, and no dynamic configuration is required after the tenant accesses it. The UPF and P4 programmable cloud network converged gateway dynamically configure the tenant tunnel and service-side routing, simplifying the overall configuration. Configuration is done at the minute level, shortening the end-to-end leased line activation time.

[0097] Based on the above specific configuration, the following section will elaborate on the specific business traffic processing process.

[0098] UPF encapsulates 5G VPN traffic through a tunnel, passing it via a shared MPLS-L3VPN, firewall, cloud private network, and routing to the cloud private gateway (VGW). The VGW then forwards the traffic to the access decapsulation subsystem via static routing. The decapsulation subsystem removes the tunnel encapsulation, exposing the original VPN packets (source and destination addresses are VPC addresses). It then queries the user's private network route and forwards the traffic to the VGW. The VGW then routes this user traffic to the cloud VPC and sends it to the cloud host via a VXLAN tunnel. Both UPF and the decapsulation subsystem utilize disaster recovery primary / backup links.

[0099] On the UPF side, a disaster recovery UPF is deployed. When the primary UPF fails, services switch to the disaster recovery UPF. Two desealing subsystems are deployed on the cloud side as tunnel endpoints. For a single tenant, the UPF and both desealing subsystems establish tunnels simultaneously. For the same service route, the UPF is configured with primary and backup static routes, pointing to the tunnel interfaces of the two desealing subsystems respectively. When the primary UPF fails, the route from the desealing subsystem to the tunnel address of the primary UPF becomes unreachable, the primary tunnel state is set to DOWN, the primary static service route becomes invalid, and the service automatically switches to the backup static route, sending data to the disaster recovery UPF.

[0100] In the technical solution provided in this application embodiment, the UPF core network 2B firewall accesses the cloud private line network through the OTN connection network PE. All tenants share a VPN on the cloud private line network, and each tenant is isolated through a tunnel, reducing the workload of core network configuration, improving the efficiency of 5G cloud private line activation, and shortening the activation time by 80%. Compared with public network access to the cloud, operators establish private cloud private line networks to ensure that users' private network access to the cloud is guaranteed. Through 5G slicing and L3VPN, full-link service isolation security is achieved between the 5G network, cloud private line network, and cloud network, ensuring network quality. At the same time, a P4 programmable cloud-network converged gateway is added to the resource pool, supporting various tunnel protocols, including encapsulation and decapsulation of IPSec, GRE, etc., realizing a complete service path from user plane functions to cloud hosts. Through the P4 programmable cloud-network converged gateway, flexible routing policies and security controls can be provided to ensure the security and stability of service traffic.

[0101] This application also proposes a data transmission device applied to a user plane function network element. Figure 5 This is a schematic diagram of the structure of the data transmission device provided in the embodiments of this application. Figure 1 ,like Figure 5 As shown, the device includes: The first processing unit 501 is used to perform tunnel encapsulation on the user service request traffic sent by the target terminal to obtain a user plane tunnel encapsulation message.

[0102] The first sending unit 502 is used to send user plane tunnel encapsulation messages to cloud-network converged network elements based on a shared virtual routing forwarding instance; wherein, the shared virtual routing forwarding instance is used to carry the tunnel between user plane function network elements and cloud-network converged network elements.

[0103] The first receiving unit 503 is used to receive cloud-network tunnel encapsulation messages sent by cloud-network converged network elements.

[0104] The first processing unit 501 is also used to decapsulate the cloud network tunnel encapsulation message to obtain the user service response traffic.

[0105] In some embodiments, the first receiving unit 503 is further configured to receive configuration information sent by the cloud-network convergence management and control platform. The configuration information includes the mapping relationship between the private network IP address, the private network virtual routing forwarding instance, and the tunnel port identifier corresponding to each terminal.

[0106] In some embodiments, the device further includes: The determining unit is used to determine the first tunnel port identifier corresponding to the target terminal.

[0107] In some embodiments, the first processing unit 501 is further configured to match the first tunnel port identifier in the configuration information to obtain the user private network virtual route forwarding instance corresponding to the target terminal, and the user private network virtual route forwarding instance corresponds to the user private network route.

[0108] In some embodiments, the user plane function network element is configured with a first tunnel interface and a first tunnel source IP address; the user plane function network element includes a primary user plane function network element, which is configured with a primary static route; wherein, the first processing unit 501 is further configured to perform tunnel encapsulation on the user service request traffic based on the first tunnel interface and the first tunnel source IP address by the primary user plane function network element, to obtain a user plane tunnel encapsulation packet, the user plane tunnel encapsulation packet carrying the first tunnel source IP address and the first tunnel port identifier.

[0109] In some embodiments, the first sending unit 502 is further configured to send user plane tunnel encapsulation messages to the cloud-network converged network element based on user private network routing, shared virtual route forwarding instances, and primary static routes.

[0110] In some embodiments, the first receiving unit 503 is further configured to receive cloud-network tunnel encapsulation messages sent by the cloud-network converged network element using the primary user plane function network element.

[0111] In some embodiments, the first processing unit 501 is further configured to perform tunnel decapsulation on the cloud network tunnel encapsulation message based on the first tunnel interface to obtain user service response traffic.

[0112] In some embodiments, the user plane function network element further includes a backup user plane function network element, which is configured with a backup static route; wherein, the first receiving unit 503 is further configured to receive operation information sent by the session management function network element when the primary user plane function network element fails, the operation information being used to instruct the primary tunnel state and the primary static route state between the primary user plane function network element and the cloud-network converged network element to be set to invalid, and the backup tunnel state and the backup static route state between the backup user plane function network element and the cloud-network converged network element to be set to valid, and the user service request traffic to be switched to the backup user plane function network element.

[0113] This application also proposes a data transmission device, which is applied to cloud-network converged network elements. Figure 6 This is a schematic diagram of the structure of the data transmission device provided in the embodiments of this application. Figure 2 ,like Figure 6 As shown, the device includes: The second receiving unit 601 is used to receive user plane tunnel encapsulation messages sent by user plane function network elements through shared virtual routing forwarding instances; wherein, the user plane tunnel encapsulation messages are obtained by user plane function network elements performing tunnel encapsulation on user service request traffic sent by target terminals; the shared virtual routing forwarding instances are used to carry tunnels between user plane function network elements and programmable cloud-network converged network elements.

[0114] The second processing unit 602 is used to decapsulate the user plane tunnel encapsulation message to obtain the user service request traffic.

[0115] The second sending unit 603 is used to forward user service request traffic to the virtual private cloud.

[0116] The second receiving unit 601 is also used to receive user service response traffic sent by the virtual private cloud.

[0117] The second processing unit 602 is also used to perform tunnel encapsulation on user service response traffic to obtain cloud network tunnel encapsulation messages.

[0118] The second sending unit 603 is also used to send cloud-network tunnel encapsulation messages to user plane function network elements.

[0119] In some embodiments, the cloud-network converged network element includes a network function virtualization network element and a tunnel decapsulation subsystem; the network function virtualization network element is configured with a network segment static route; wherein, the second receiving unit 601 is further configured to receive user plane tunnel encapsulation packets sent by the user plane function network element through a shared virtual route forwarding instance.

[0120] In some embodiments, the second sending unit 603 is further configured to forward user plane tunnel encapsulation packets to the tunnel decapsulation subsystem based on network segment static routing.

[0121] In some embodiments, the second processing unit 602 is further configured to perform tunnel decapsulation on the user plane tunnel encapsulation message by the tunnel decapsulation subsystem to obtain the user service request traffic.

[0122] In some embodiments, the cloud-network converged network element is configured with a second tunnel interface corresponding to the target terminal and a user private network IP address; the user plane tunnel encapsulation message carries a first tunnel source IP address and a first tunnel port identifier corresponding to the target terminal; wherein, the second receiving unit 601 is further configured to receive configuration information sent by the cloud-network converged management and control platform, the configuration information including the mapping relationship between the private network IP address, the private network virtual routing forwarding instance and the tunnel port identifier corresponding to each terminal.

[0123] In some embodiments, the second processing unit 602 is further configured to match the first tunnel port identifier in the configuration information to obtain the user private network IP address and the user private network virtual route forwarding instance corresponding to the target terminal, wherein the user private network IP address corresponds to the second tunnel interface and the user private network virtual route forwarding instance corresponds to the user private network route.

[0124] In some embodiments, the second processing unit 602 is further configured to bind user service request traffic to the second tunnel interface in the tunnel unblocking subsystem.

[0125] In some embodiments, the second sending unit 603 is further configured to: the tunnel unblocking subsystem forwards user service request traffic to the network function virtualization network element based on the user's private network route; the network function virtualization network element forwards user service request traffic to the virtual private cloud based on the first tunnel port identifier and the source and destination addresses of the user service request traffic; and the virtual private cloud is used to forward user service request traffic to hosts within the cloud.

[0126] In some embodiments, the second receiving unit 601 is further configured to receive user service response traffic sent by the virtual private cloud via the network function virtualization network element.

[0127] In some embodiments, the second sending unit 603 is further configured to forward user service response traffic to the tunnel encapsulation subsystem via the network function virtualization element.

[0128] In some embodiments, the second processing unit 602 is further configured to encapsulate the user service response traffic in the tunnel decapsulation subsystem to obtain a cloud network tunnel encapsulation message.

[0129] In some embodiments, the second sending unit 603 is further configured to forward the cloud-network tunnel encapsulation message to the network function virtualization network element via the tunnel decapsulation subsystem; wherein the cloud-network tunnel encapsulation message carries the first tunnel source IP address and the first tunnel port identifier corresponding to the target terminal; the network function virtualization network element sends the cloud-network tunnel encapsulation message to the user plane function network element.

[0130] Those skilled in the art should understand that Figure 5 , Figure 6 The functions of each unit in the communication device shown can be understood by referring to the relevant description of the aforementioned method. Figure 5 , Figure 6 The functions of each unit in the communication device shown can be implemented by a program running on a processor or by specific logic circuits.

[0131] Figure 7 This is a schematic diagram of the communication device provided in an embodiment of this application. The communication device may be a target terminal device or a network device. Figure 7 The communication device shown includes a processor 701, which can call and run computer programs from memory to implement the methods in the embodiments of this application.

[0132] Optionally, such as Figure 7 As shown, the communication device may further include a memory 702. The processor 701 can retrieve and run computer programs from the memory 702 to implement the methods described in this embodiment.

[0133] The memory 702 can be a separate device independent of the processor 701, or it can be integrated into the processor 701.

[0134] Optionally, such as Figure 7 As shown, the communication device may also include a transceiver 703, and the processor 701 can control the transceiver 703 to communicate with other devices. Specifically, it can send information or data to other devices or receive information or data sent by other devices.

[0135] The transceiver 703 may include a transmitter and a receiver. The transceiver 703 may further include an antenna, which may be one or more.

[0136] The communication device may specifically be the data transmission device of the embodiments of this application, and the communication device can implement the corresponding processes of the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0137] It should be understood that the processor in the embodiments of this application may be an integrated circuit chip with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor described above can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0138] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0139] This application also provides a computer-readable storage medium for storing a computer program. This computer-readable storage medium can be applied to the communication device in this application embodiment, and the computer program causes the computer to execute the corresponding processes of the various methods implemented in this application embodiment; for brevity, these will not be elaborated further here.

[0140] This application also provides a computer program product, including computer program instructions. This computer program product can be applied to the communication device in this application embodiment, and the computer program instructions cause the computer to execute the corresponding processes implemented by the various methods in this application embodiment; for brevity, these will not be elaborated further here.

[0141] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0142] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0143] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0144] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0145] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0146] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0147] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A data transmission method, characterized in that, Applied to user plane function network elements, the method includes: The user service request traffic sent by the target terminal is tunnel encapsulated to obtain user plane tunnel encapsulated packets; The user plane tunnel encapsulation message is sent to the cloud-network converged network element based on the shared virtual routing forwarding instance; wherein, the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the cloud-network converged network element; The system receives cloud-network tunnel encapsulation messages sent by the cloud-network converged network element and performs tunnel decapsulation on the cloud-network tunnel encapsulation messages to obtain user service response traffic.

2. The method according to claim 1, characterized in that, The method further includes: The system receives configuration information sent by the cloud-network convergence management and control platform. The configuration information includes the mapping relationship between the private network IP address, the private network virtual routing forwarding instance, and the tunnel port identifier corresponding to each terminal. Determine the first tunnel port identifier corresponding to the target terminal; The first tunnel port identifier is matched in the configuration information to obtain the user private network virtual route forwarding instance corresponding to the target terminal, and the user private network virtual route forwarding instance corresponds to the user private network route.

3. The method according to claim 2, characterized in that, The user plane function network element is configured with a first tunnel interface and a first tunnel source IP address; The user plane function network element includes a primary user plane function network element, and the primary user plane function network element is configured with a primary static route; The method further includes: The primary user plane function network element performs tunnel encapsulation on the user service request traffic based on the first tunnel interface and the first tunnel source IP address to obtain the user plane tunnel encapsulation message. The user plane tunnel encapsulation message carries the first tunnel source IP address and the first tunnel port identifier. The primary user plane function network element sends the user plane tunnel encapsulation message to the cloud-network converged network element based on the user private network route, the shared virtual route forwarding instance, and the primary static route; The primary user plane function network element receives the cloud-network tunnel encapsulation message sent by the cloud-network converged network element, and performs tunnel decapsulation on the cloud-network tunnel encapsulation message based on the first tunnel interface to obtain the user service response traffic.

4. The method according to claim 1, characterized in that, The user plane function network element also includes a backup user plane function network element, which is configured with a backup static route. The method further includes: When the primary user plane function network element fails, it receives operation information sent by the session management function network element. The operation information is used to instruct the primary tunnel status and the primary static route status between the primary user plane function network element and the cloud-network converged network element to be set to invalid, the backup tunnel status and the backup static route status between the backup user plane function network element and the cloud-network converged network element to be set to valid, and the user service request traffic to be switched to the backup user plane function network element.

5. A data transmission method, characterized in that, Applied to cloud-network converged network elements, the method includes: The system receives user plane tunnel encapsulation packets sent by user plane function network elements through a shared virtual routing forwarding instance; wherein, the user plane tunnel encapsulation packets are obtained by the user plane function network element performing tunnel encapsulation on user service request traffic sent by the target terminal; and the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the programmable cloud-network converged network element. The user plane tunnel encapsulation message is decapsulated to obtain the user service request traffic, and the user service request traffic is forwarded to the virtual private cloud corresponding to the target terminal; Receive user service response traffic sent by the virtual private cloud, and perform tunnel encapsulation on the user service response traffic to obtain a cloud network tunnel encapsulation message; Send the cloud network tunnel encapsulation message to the user plane function network element.

6. The method according to claim 5, characterized in that, The cloud-network converged network element includes a network function virtualization network element and a tunnel deblocking subsystem; the network function virtualization network element is configured with static network segment routing; The method further includes: The network function virtualization network element receives the user plane tunnel encapsulation message sent by the user plane function network element through the shared virtual routing forwarding instance, and forwards the user plane tunnel encapsulation message to the tunnel decapsulation subsystem based on the network segment static route; The tunnel decapsulation subsystem decapsulates the user plane tunnel encapsulation message to obtain the user service request traffic.

7. The method according to claim 6, characterized in that, The cloud-network converged network element is configured with a second tunnel interface and a user's private network IP address corresponding to the target terminal; The user plane tunnel encapsulation message carries the first tunnel source IP address and the first tunnel port identifier corresponding to the target terminal; the method further includes: The system receives configuration information sent by the cloud-network convergence management and control platform. The configuration information includes the mapping relationship between the private network IP address, the private network virtual routing forwarding instance, and the tunnel port identifier corresponding to each terminal. The first tunnel port identifier is matched in the configuration information to obtain the user's private network IP address and user's private network virtual route forwarding instance corresponding to the target terminal. The user's private network IP address corresponds to the second tunnel interface, and the user's private network virtual route forwarding instance corresponds to the user's private network route.

8. The method according to claim 7, characterized in that, The method further includes: The tunnel unblocking subsystem binds the user service request traffic to the second tunnel interface and forwards the user service request traffic to the network function virtualization network element based on the user private network route; The network function virtualization element forwards the user service request traffic to the virtual private cloud based on the first tunnel port identifier and the source and destination addresses of the user service request traffic. The virtual private cloud is used to forward the user service request traffic to hosts within the cloud.

9. The method according to any one of claims 6 to 8, characterized in that, The method further includes: The network function virtualization network element receives the user service response traffic sent by the virtual private cloud and forwards the user service response traffic to the tunnel encapsulation subsystem; The tunnel decapsulation subsystem encapsulates the user service response traffic to obtain the cloud network tunnel encapsulation message, and forwards the cloud network tunnel encapsulation message to the network function virtualization network element; wherein, the cloud network tunnel encapsulation message carries the first tunnel source IP address and the first tunnel port identifier corresponding to the target terminal; The network function virtualization network element sends the cloud network tunnel encapsulation message to the user plane function network element.

10. A data transmission device, characterized in that, The device, applied to user plane function network elements, includes: The first processing unit is used to perform tunnel encapsulation on the user service request traffic sent by the target terminal to obtain user plane tunnel encapsulation messages. The first sending unit is used to send the user plane tunnel encapsulation message to the cloud-network converged network element based on a shared virtual routing forwarding instance; wherein, the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the cloud-network converged network element; The first receiving unit is used to receive cloud network tunnel encapsulation messages sent by the cloud network converged network element; The first processing unit is also used to decapsulate the cloud network tunnel encapsulation message to obtain the user service response traffic.

11. A data transmission device, characterized in that, The device, applied to cloud-network converged network elements, includes: The second receiving unit is used to receive user plane tunnel encapsulation messages sent by the user plane function network element through a shared virtual routing forwarding instance; wherein, the user plane tunnel encapsulation message is obtained by the user plane function network element performing tunnel encapsulation on the user service request traffic sent by the target terminal; the shared virtual routing forwarding instance is used to carry the tunnel between the user plane function network element and the programmable cloud-network converged network element. The second processing unit is used to decapsulate the user plane tunnel encapsulation message to obtain the user service request traffic. The second sending unit is used to forward the user service request traffic to the virtual private cloud; The second receiving unit is also used to receive user service response traffic sent by the virtual private cloud; The second processing unit is further configured to perform tunnel encapsulation on the user service response traffic to obtain a cloud network tunnel encapsulation message; The second sending unit is also used to send the cloud network tunnel encapsulation message to the user plane function network element.

12. A communication device, characterized in that, include: A processor and a memory for storing a computer program, the processor for calling and running the computer program stored in the memory to perform the method as described in any one of claims 1 to 9.

13. A computer-readable storage medium, characterized in that, Used to store a computer program that causes a computer to perform the method as described in any one of claims 1 to 9.

14. A computer program product, characterized in that, It includes computer program instructions that cause a computer to perform the method as described in any one of claims 1 to 9.