Apparatus, method and program for providing communication services for accessing IP network
Patent Information
- Application Number
- JP2025022437
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-06-22
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-26
- Estimated Expiration
- 2042-05-26
AI Technical Summary
The prior art is difficult to manage each service through an independent communication service without using a cellular communication network, or develop a communication system that manages multiple communication services internally, resulting in an increase in management costs and development costs.
By connecting to the MNO's communication infrastructure in the cloud, a communication service is provided, receiving a session generation request containing a subscription identifier, storing an ID and sending a first preconfigured call to generate a GTP-U session, the first preconfigured call containing an ID.
It realizes the communication services of IoT devices that can access IP networks without the need to pass through cellular communication networks, reducing management and development costs, while improving the flexibility and efficiency of communication services.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an apparatus, a method, and a program for providing a communication service for accessing an IP network. [Background technology]
[0002] Wireless communication services using cellular networks have traditionally been provided by MNOs (mobile network operators). Users sign a contract with an MNO, receive a SIM card from the MNO, and can begin using the service by inserting it into their device.
[0003] In recent years, the emergence of MVNOs (Mobile Virtual Network Operators) has led to increased retail sales of wireless communication lines, in which case users receive SIM cards from the MVNO rather than the MNO. MVNOs can be broadly divided into those that do not have any communications infrastructure of their own, and those that have their own communications infrastructure and connect it to the MNO's communications infrastructure to provide wireless communication services. Compared to the former, the latter (see Figure 1) has its own communications infrastructure, so it is possible to set prices according to communication quality such as communication speed and communication capacity, for example, and is attempting to meet various needs.
[0004] The need for wireless communication services has been increasing significantly in recent years due to the IoT movement, which adds communication capabilities to all kinds of things and connects them to the Internet. Hereafter, devices that can connect to computer networks, including the Internet, are referred to as "IoT devices." By installing a SIM card, IoT devices can access IP networks using cellular communication.
[0005] In addition, there are cases where an MVNE (Mobile Virtual Network Provider) exists between the MNO and the MVNO to provide support services to enable the MVNO to operate smoothly, and the MVNE receives SIM cards from the MNO and then provides them to the MVNO. For example, the MVNE's communications infrastructure could be connected to the MNO's communications infrastructure to provide wireless communication services, and the MVNO, which does not have its own communications infrastructure, could handle retail. Summary of the Invention [Problem to be solved by the invention]
[0006] However, if it is also desired to enable IoT devices to access IP networks without using cellular communications, more specifically, without using a radio access network for cellular communications, it will be necessary to use a communications service separate from the wireless communication services provided by the MVNO or MVNE described above and manage each of them, or to develop an in-house communications system for managing multiple communications services, which will result in increased costs such as management costs and development costs.
[0007] The present invention has been made in consideration of these problems, and its purpose is to provide an apparatus, method, and program for providing IoT devices with communication services for accessing an IP network using a communication infrastructure connected to an MNO's communication infrastructure, which enables such access without going through a wireless access network for cellular communication.
[0008] Furthermore, a more general object of the present invention is to provide a communication service for IoT devices to access an IP network, which enables the access without going through a radio access network for cellular communication, by using a communication infrastructure connected to an MNO's communication infrastructure.
[0009] The terms MNO, MVNO, and MVNE may have different definitions. In this specification, MNO has 3G SGSN and LTE S-GW as communication infrastructure, and MVNO and MVNE are not differentiated, and are collectively referred to as operators who have communication infrastructure connected to MNO's communication infrastructure. Examples of communication infrastructure owned by such operators include 3G GGSN and LTE P-GW.
[0010] In the above explanation, a SIM card is attached to an IoT device, but it is not limited to a physical SIM card. It may be implemented by a semiconductor chip built into an IoT device, software installed in a secure area in a module of an IoT device, etc., and hereinafter, these are collectively referred to as "SIM". A SIM stores a SIM identifier that identifies the SIM. Examples of SIM identifiers include IMSI, ICCID, MSISDN, etc. [Means for solving the problem]
[0011] The present invention has been made in view of the above problems, and an object of the present invention is to provide a method for providing an IoT device with a communication service for accessing an IP network, using equipment provided in a communication infrastructure on a cloud connected to an MNO's communication infrastructure, the method including a step of receiving a session generation request including a subscriber identifier for identifying a subscriber of the communication service, a step of storing an ID in association with the subscriber identifier, and a step of transmitting a first provisioning call including the ID to a first instance and a second instance included in the equipment, the first provisioning call being for generating a GTP-U session between the first instance and the second instance. receiving, from the first instance or the second instance, a source address that is to be a source of the GTP-U session as a response to the first provisioning call; transmitting, to the first instance, a second provisioning call for generating a VPN session between the IoT device and the first instance, the second provisioning call including the source address and a first credential; and transmitting connection information including the source address and a destination address of the first instance to the IoT device that has stored the first credential or a second credential corresponding to the first credential. Includes.
[0012] A second aspect of the present invention is the method of the first aspect, wherein the connection information includes a port number of the first instance.
[0013] A third aspect of the present invention is the method of the first aspect, wherein the first credential is a public key, and the second credential is a private key corresponding to the public key.
[0014] Also, a fourth aspect of the present invention is the method of the first aspect, wherein the session generation request is received from the IoT device.
[0015] A fifth aspect of the present invention is the method according to any one of the first to fourth aspects, wherein the first instance and the second instance are instances on a cloud or a public cloud.
[0016] Further, a sixth aspect of the present invention is a program for causing an apparatus to execute a method for providing an IoT device with a communication service for accessing an IP network, using equipment provided in a communication infrastructure on a cloud connected to an MNO's communication infrastructure, the method including a step of receiving a session generation request including a subscriber identifier for identifying a subscriber of the communication service, a step of storing an ID in association with the subscriber identifier, and a step of transmitting a first provisioning call to a first instance and a second instance included in the equipment, the first provisioning call being for generating a GTP-U session between the first instance and the second instance, the first provisioning call including the ID. the step of receiving from the first instance or the second instance a source address that will be the source of the GTP-U session in response to the first provisioning call; the step of sending to the first instance a second provisioning call for generating a VPN session between the IoT device and the first instance, the second provisioning call including the source address and a first credential; and the step of sending connection information including the source address and a destination address of the first instance toward the IoT device that has stored the first credential or a second credential corresponding to the first credential.
[0017] A seventh aspect of the present invention is an apparatus for providing an IoT device with a communication service for accessing an IP network, using equipment provided by a communication infrastructure on a cloud connected to an MNO's communication infrastructure, the apparatus receiving a session generation request including a subscriber identifier for identifying a subscriber of the communication service, storing an ID in association with the subscriber identifier, transmitting a first provisioning call to a first instance and a second instance included in the equipment, the first provisioning call being for generating a GTP-U session between the first instance and the second instance, the first provisioning call being for generating a GTP-U session between the first instance and the second instance, the first provisioning call being for generating a VPN session between the IoT device and the first instance, the second ...
[0018] Also, an eighth aspect of the present invention is a method for providing a communication service for an IoT device to access an IP network using a communication infrastructure on a cloud having a first instance and a second instance between which a GTP-U session is generated, the method comprising the steps of: receiving, from the IoT device, a VPN packet encapsulating an IP packet encrypted by a credential or a temporary credential stored in the IoT device; and obtaining, by the first instance, a credential or a temporary credential corresponding to a source address or a temporary key included in the VPN packet, and decrypting the encrypted IP packet. The method includes a step of the first instance determining the second instance based on a source address included in the header of the decrypted IP packet by referring to a correspondence between one or more source addresses and the destination of the GTP session to which each source address is assigned, which is held in the first instance; a step of the first instance transmitting a GTP packet to the second instance, the GTP packet having the decrypted IP packet as a GTP payload; and a step of the second instance removing the GTP header from the GTP packet and transmitting the IP packet as the GTP payload to an IP network external or internal to the communication infrastructure.
[0019] Further, a ninth aspect of the present invention is a program for executing a method of providing a communication service for an IoT device to access an IP network to a communication infrastructure on a cloud during which a GTP-U session was generated, the method including the steps of: a first instance of the communication infrastructure receiving from the IoT device a VPN packet encapsulating an IP packet encrypted by a credential or a temporary credential stored in the IoT device; the first instance obtaining a credential or a temporary credential corresponding to a source address or a temporary key included in the VPN packet and decrypting the encrypted IP packet; the first instance determining a second instance of the communication infrastructure that is capable of transmitting an IP packet to an IP network outside or inside the communication infrastructure based on a source address included in a header of the decrypted IP packet, by referring to a correspondence between one or more source addresses and destinations of GTP sessions to which each source address is assigned, held in the first instance; and the first instance transmitting a GTP packet with the decrypted IP packet as a GTP payload to the second instance.
[0020] In addition, a tenth aspect of the present invention is a communication infrastructure on a cloud for providing a communication service for an IoT device to access an IP network, the communication infrastructure having a first instance and a second instance between which a GTP-U session is generated, the first instance receives a VPN packet from the IoT device encapsulating an IP packet encrypted by a credential or a temporary credential stored in the IoT device, obtains a credential or a temporary credential corresponding to a source address or a temporary key included in the VPN packet, and decrypts the encrypted IP packet, the first instance determines the second instance based on the source address included in the header of the decrypted IP packet by referring to a correspondence between one or more source addresses and the destination of the GTP session to which each source address is assigned, which is held in the first instance, and transmits a GTP packet to the second instance with the decrypted IP packet as a GTP payload, and the second instance removes the GTP header from the GTP packet and transmits the IP packet as the GTP payload to an IP network outside or inside the communication infrastructure.
[0021] According to one aspect of the present invention, a VPN tunnel provides a secret line over an IP network such as the Internet, and an IoT device can be connected to a communications infrastructure that is connected to an MNO's communications infrastructure via the secret line and that can transmit data to the IP network and receive data from the IP network via a GTP tunnel, without going through a wireless access network. [Brief description of the drawings]
[0022] [Figure 1] FIG. 1 is a diagram illustrating an MVNO that provides wireless communication services by connecting its own communications infrastructure to the MNO's communications infrastructure. [Diagram 2]FIG. 2 is a diagram showing an apparatus for providing a communication service for accessing an IP network according to one embodiment of the present invention. [Figure 3A] 1 is a diagram showing a method flow for providing communication services for accessing an IP network according to one embodiment of the present invention. [Figure 3B] 1 is a diagram showing a method flow for providing communication services for accessing an IP network according to one embodiment of the present invention. [Figure 4] FIG. 1 is a diagram showing the flow of data transmission in a communication service for an IoT device to access an IP network according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0023] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings.
[0024] 2 shows an apparatus for providing a communication service for accessing an IP network according to an embodiment of the present invention. The apparatus 200 communicates with an MVNO's communication infrastructure 220 connected to an MNO's communication infrastructure 210 and an IoT device 230 over an IP network. The apparatus 200 is also called a connection apparatus because it is for establishing a connection for the IoT device 230 to access the IP network. The MVNO's communication infrastructure 220 is composed of multiple instances on a cloud or a public cloud.
[0025] In this specification, "cloud" refers to a system that can dynamically provision and provide computing resources such as CPU, memory, storage, and network bandwidth on a network according to demand. For example, a cloud can be used with AWS or the like. In addition, in this specification, "public cloud" refers to a cloud that allows multiple tenants to receive computing resources.
[0026] The device 200 includes a communication unit 201 such as a communication interface, a processing unit 202 such as a processor or CPU, and a storage unit 203 including a storage device or storage medium such as a memory or a hard disk, and can be configured by executing a program for performing each process. The device 200 may include one or more devices, computers, or servers. The program may include one or more programs, and may be recorded in a computer-readable storage medium to form a non-transient program product. The program may be stored in a storage device or storage medium such as the storage unit 203 or a database 204 accessible from the device 200 via an IP network, and may be executed by the processing unit 202. Data described below as being stored in the storage unit 203 may be stored in the database 204, and vice versa.
[0027] The device 200 may be one or more instances on a cloud or a public cloud, and may be one or more instances on the same cloud as the MVNO's communication infrastructure 220. Although not shown, each instance of the MVNO's communication infrastructure 220 may have the same hardware configuration as the connection device 200.
[0028] In the following, first, the generation of a session necessary for a communication service will be described, and then the transmission of data to an IP network using the generated session will be described.
[0029] Creating a session 3A and 3B show a flow of a method for providing a communication service for accessing an IP network according to an embodiment of the present invention. First, the device 200 receives a session creation request including a subscriber identifier for identifying a subscriber of the communication service from the IoT device 230 (S301). The session creation request can be transmitted via an Internet communication line other than a cellular line, and may be transmitted via a fixed Internet line or a cellular line, for example.
[0030] In FIG. 2, the IoT device 230 stores a SIM identifier 231 for identifying a SIM for using a communication service for accessing an IP network provided via a wireless access network using the MVNO's communication infrastructure 220, and also stores a subscriber identifier 232 for using a communication service for accessing an IP network provided without a wireless access network. In FIG. 2, the subscriber identifier 232 is considered to be a virtual SIM identifier when a connection is established using this, and is therefore shown as "V-SIM (Virtual SIM)" for convenience. The IoT device 230 may also store a token for validly making a session generation request. The IoT device 230 does not necessarily have to store the SIM identifier 231.
[0031] The connection device 200 verifies the token included in the received session creation request as necessary, and then generates and stores an ID in association with the subscriber identifier 232 included in the session creation request (S302). Note that the session creation request may be transmitted to the connection device 200 from a device other than the IoT device 230 that can legitimately access the subscriber identifier 232 for the IoT device 230.
[0032] An example of a device other than the IoT device 230 is a computer used by an administrator who manages the IoT device 230. If the administrator can access the subscriber identifier 232 and is given a token required to make a session generation request to the connection device 200, the administrator can use the token to make a session generation request including the subscriber identifier 232 for the IoT device 230. Another example of a device other than the IoT device 230 is an authentication server that can authenticate the IoT device 230 using the SIM identifier 231 stored in the IoT device 230 and establish a secret line between the IoT device 230 and the authentication server. It can be said that the authentication server that receives the subscriber identifier 232 from the IoT device 230 through the established secret line has legitimate access to the subscriber identifier 232. When the SIM identified by the SIM identifier 231 is issued by a business operator that has the communication infrastructure 220 connected to the communication infrastructure 210 of the MNO, the authentication server can be one or more instances included in the equipment of the communication infrastructure 220.
[0033] Next, the connection device 200 selects a first instance and a second instance that the communication infrastructure 220 has (S303), and transmits a provisioning call to the second instance to generate a GTP-U session between the first instance and the second instance (S304). This provisioning call can include the ID stored in the connection device 200 and a first destination address such as an IP address or a host name of the first instance selected by the connection device 200.
[0034] The first instance may be selected from a first group of nodes, and the second instance may be selected from a second group of nodes. Each instance includes multiple servers, and the server from which each instance receives data may be different from the server from which each instance transmits data. When the MVNO's communication infrastructure 220 provides the IoT device 230 with access to an IP network via a wireless access network, a first server selected from a first group of servers connected to the MNO's communication infrastructure 210 and a second server selected from a second group of servers connected to the first server are used. At least a portion of the second group of nodes may be the same as at least a portion of the second group of servers.
[0035] The second instance transmits a response to the provisioning call for the second instance to the connection device 200 (S305). Then, the second instance goes into standby state for a GTP-U session (S306). The response may include the ID and a source address such as an IP address that is the source for the GTP-U session, and the source address may be adopted by the second instance. Here, it has been described that the standby state is entered after the response is transmitted, but this order may be reversed. The source address may be assigned not by the second instance but by the connection device 200. In this case, the source address may be included in the provisioning call to the second instance. In any case, the second instance may store the source address in association with the ID. Also, the device 200 may store the source address in association with the subscriber identifier 232.
[0036] Then, the connection device 200 sends a provisioning call to the first instance to generate a GTP-U session between the first instance and the second instance (S307). This provisioning call can include the ID stored in the connection device 200, a source address, and a second destination address of the second instance adopted by the connection device 200.
[0037] Thereafter, the first instance enters a standby state for a GTP-U session (S308). Here, a GTP-U session is generated between the first instance and the second instance, and a so-called GTP tunnel is established. The connection device 200 receives a response to the provisioning call to the first instance (S309). Although the first instance may enter a standby state after transmitting the response, it is preferable to transmit the response after entering a standby state so as to avoid a period during which the first instance cannot connect.
[0038] The connection device 200 then sends a provisioning call to the first instance to create a VPN session between the IoT device 230 and the first instance (S310). The provisioning call includes the source address and credentials associated with the IoT device 230. The credentials may be stored in the database 204 in association with the subscriber identifier 232, or may be included in the session creation request from the IoT device 230.
[0039] The credential may be, for example, a public key. In this case, a private key corresponding to the public key is stored in the IoT device 230. An encryption method other than the public key encryption method may be used for the VPN session, and more generally, a first credential required for the encryption method is transmitted to the first instance, and the first credential or a second credential corresponding to the first credential is stored in the IoT device 230.
[0040] After receiving a provisioning call for generating a VPN session, the first instance stores the source address and the credentials and goes into a standby state for the VPN session (S311). The connection device 200 also receives a response to the provisioning call from the first instance (S312). In one example, the response may include the source address and the first destination address of the first instance. Although the first instance may go into a standby state after sending the response, it is preferable to send the response after going into a standby state so as to avoid a period during which the instance is unable to connect.
[0041] The connection device 200 that has received the response transmits connection information, which is the source address and the first destination address included in the response, plus a port number as necessary, to the IoT device 230 (S313). If the response from the first instance includes a port number, the connection information received may be transmitted to the IoT device 230. In the IoT device 230, device provisioning is performed based on the connection information, and a connection to the first instance is attempted (S314). Here, an intermediate device may exist between the IoT device 230 and the first instance. If the first instance transmits a success response to the IoT device 230 (S315), the handshake is successful, and the VPN tunnel is established. In response to receiving the attempt, in response to transmitting a success response to the attempt, or more generally after receiving the attempt, the first instance may enter a waiting state for a GTP-U session, and a GTP tunnel may be established.
[0042] After the first instance transmits the response of success, it may notify the connection device 200 that it has become online, that is, that a connection for communication using the subscriber identifier 232 has been established (S316). The connection device 200 that receives such a notification may transmit online display information for indicating that communication using the subscriber identifier 232 is possible to the IoT device 230 or a device other than the IoT device 230, such as a computer used by an administrator that manages the IoT device 230 (S317). Here, upon receiving the response that the attempt was successful, the connection device 200 may determine and store that the subscriber identifier 232 has become online. In addition, the first instance may determine whether a predetermined period has passed (S318), and if so, may notify the connection device 200 that it has become offline, that is, that a connection for communication using the subscriber identifier 232 has been lost (S319). The connection device 200 that has received such a notification may transmit, for example, offline display information indicating that communication using the subscriber identifier 232 is not possible to a device other than the IoT device 230, such as a computer used by an administrator who manages the IoT device 230 (S320). How to define the start point and period of the above-mentioned predetermined period for confirming the existence of the VPN tunnel may be determined according to the individual specifications of the VPN technology. For example, the start point may be the time when the VPN tunnel is disconnected.
[0043] In the above description, a provisioning call is made to the second instance and then to the first instance when establishing a GTP tunnel, but implementation in the reverse order is also possible. More generally, it is sufficient to send a first provisioning call to a first instance and a second instance included in the equipment of the communication infrastructure 220 on the cloud connected to the communication infrastructure 210 of the MNO to generate a GTP-U session between the first instance and the second instance, put the first and second instances in a standby state, and receive a source address of the GTP-U session from the first instance or the second instance.
[0044] When a session generation request is transmitted to the connection device 200 from a device other than the IoT device 230, a response to the request is transmitted to the device other than the IoT device 230. If a secret line is established between the IoT device 230 and a device other than the IoT device 230, connection information can be transmitted to the IoT device 230 through the secret line to perform device provisioning. Therefore, it can be said that the connection information is transmitted from the connection device 200 to the IoT device 230.
[0045] Also, at the time of handshake, a temporary credential may be generated using the credential stored in the first instance or a credential corresponding thereto, and stored in the first instance. In this case, the temporary credential is associated with the source address in the first instance. Similarly, the temporary credential is stored in the IoT device 230. Also, for example, at the time of the initial handshake, a temporary key may be generated, and in addition to associating the key with the source address in the first instance, the temporary credential is associated with the key.
[0046] Sending and receiving data FIG. 4 shows a flow of data transmission in a communication service for accessing an IP network according to the first embodiment of the present invention.
[0047] First, the IoT device 230 encapsulates an IP packet encrypted by a credential or a temporary credential stored in the IoT device 230 into a VPN packet and transmits the packet to the first instance (S401). The VPN packet includes the encrypted IP packet and VPN session information related to the VPN session. The VPN session information includes a source address or a temporary key associated therewith. Here, there may be an intervening device between the IoT device 230 and the first instance.
[0048] The first instance that receives the VPN packet obtains credentials or temporary credentials corresponding to the source address included in the VPN session information or the temporary key associated therewith, and attempts to decrypt the encrypted IP packet (S402).
[0049] At the time of device provisioning in the session generation process, routing information may be set in the IoT device 230. More specifically, the IoT device 230 may determine whether or not to pass the encrypted IP packet through the VPN tunnel depending on the destination address after the GTP tunnel is terminated, of the encrypted IP packet sent from the IoT device 230.
[0050] Next, the first instance determines a second instance to be a destination based on the source address included in the header of the decrypted IP packet by referring to the correspondence between one or more source addresses held in the first instance and the destination of the GTP session to which each source address is assigned (S403). Then, the first instance transmits a GTP packet with the decrypted IP packet as the GTP payload to the determined second instance (S404). This terminates the VPN tunnel. Each instance includes multiple servers, and the server from which each instance receives data may be different from the server from which the instance transmits data.
[0051] The second instance removes the GTP header from the received GTP packet, and transmits the IP packet, which is the GTP payload, to an external or internal IP network of the MVNO's communication infrastructure 220 (S405). The GTP header includes an ID, and the second instance can identify the source address by referring to the correspondence between the ID and the source address stored in the second instance, and can transitively identify the subscriber identifier by referring to the correspondence between the source address and the subscriber identifier stored in the device 200.
[0052] In this way, the VPN tunnel provides a secret line over an IP network such as the Internet, enabling the IoT device 230 to connect to the MVNO's communication infrastructure 220, which performs data communication using the GTP protocol, via the IP network without going through a wireless access network.
[0053] FIG. 4 shows data transmission, but the MVNO communication infrastructure 220 receives data from the IP network as follows. When an IP packet addressed to the IoT device 230 arrives at the second instance, the GTP-U session corresponding to the address of the IoT device 230 as the destination is identified, and the IP packet is sent to the first instance with a GTP header added. The first instance then removes the GTP header from the received GTP packet to obtain an IP packet addressed to the IoT device 230. The corresponding VPN session is identified from the destination address of the IP packet, and the IP packet is encapsulated into a VPN packet using a credential or temporary credential corresponding to a temporary key associated with the VPN session, and sent to the IoT device 230 via the VPN tunnel. The IoT device 230 obtains the credential or temporary credential corresponding to the temporary key associated with the received VPN packet based on the VPN session information, decrypts the encrypted IP packet, and processes the IP packet.
[0054] A request to disable a VPN session determined by a source address associated with the subscriber identifier 232 or a key corresponding thereto may be sent to the connection device 200 from a device other than the IoT device 230 that can legitimately access the subscriber identifier 232, such as a computer used by an administrator who manages the IoT device 230. In this case, the connection device 200 that receives the request to disable requests the first instance to revoke or disable the credentials or temporary credentials corresponding to the source address or the key associated therewith, and updates the stored billing status associated with the subscriber identifier 232 in response to the disablement of the VPN session. [Explanation of symbols]
[0055] 200 equipment 201 Communications Department 202 Processing section 203 Storage section 204 Database 210 MNO Communication Infrastructure 220 Communications infrastructure connected to MNO's communications infrastructure
Claims
1. A method for providing an IoT device with a communication service for accessing an IP network using a facility of a communication infrastructure connected to an MNO's communication infrastructure, comprising: receiving a session creation request including a subscriber identifier for identifying a subscriber of the communication service; sending a provisioning call to an instance included in the equipment for generating a secure communication session between the IoT device and the instance, the provisioning call including a first credential; sending connection information including a destination address of the instance to the IoT device; Includes.
2. 2. The method of claim 1 , the instance is a first instance, The method further includes receiving, from the first instance or a second instance included in the equipment, a source address from which a GTP-U session between the first instance and the second instance is to be transmitted; The connection information further includes the source address.
3. 3. The method of claim 2, the provisioning call is a second provisioning call; The method comprises: storing an ID in association with said subscriber identifier; sending a first provisioning call to the first instance and the second instance for creating the GTP-U session, the first provisioning call including the ID; Receiving the source address includes receiving the source address in response to the first provisioning call.
4. 4. The method of claim 3, The first provisioning call to the second instance further includes the destination address of the first instance.
5. 5. The method of claim 4, A response of the first provisioning call to the second instance includes the source address.
6. 6. The method of claim 5, sending the first provisioning call to the first instance after receiving the response of the first provisioning call to the second instance; The first provisioning call to the first instance further includes the source address.
7. 7. The method of claim 6, The first provisioning call to the first instance further includes a destination address of the second instance.
8. 3. The method of claim 2, The connection information includes a port number of the first instance.
9. 2. The method of claim 1 , The IoT device stores the first credential or a second credential corresponding to the first credential.
10. 10. The method of claim 9, the first credential is a public key; The second credential is a private key that corresponds to the public key.
11. 2. The method of claim 1 , The session creation request is received from the IoT device.
12. 9. The method according to any one of claims 2 to 8, The first instance and the second instance are instances on a cloud or a public cloud.
13. A program for causing an apparatus to execute a method for providing an IoT device with a communication service for accessing an IP network by using facilities of a communication infrastructure connected to an MNO's communication infrastructure, the method comprising: receiving a session creation request including a subscriber identifier for identifying a subscriber of the communication service; sending a provisioning call to an instance included in the equipment for generating a secure communication session between the IoT device and the instance, the provisioning call including a first credential; sending connection information including a destination address of the instance to the IoT device; Includes.
14. A device for providing an IoT device with a communication service for accessing an IP network using facilities of a communication infrastructure connected to an MNO's communication infrastructure, receiving a session creation request including a subscriber identifier for identifying a subscriber of the communication service; Sending a provisioning call to an instance included in the equipment for generating a secure communication session between the IoT device and the instance, the provisioning call including a first credential; Connection information including a destination address of the instance is transmitted to the IoT device.
15. 1. A method for providing a communication service for an IoT device to access an IP network using a communication infrastructure having a first instance and a second instance between which a GTP-U session is created, the communication infrastructure being connected to a communication infrastructure of an MNO, the method comprising the steps of: receiving, by the first instance, from the IoT device, a VPN packet encapsulating an IP packet encrypted by a credential or a temporary credential; The first instance obtains a credential or a temporary credential corresponding to a source address or a temporary key included in the VPN packet to decrypt the encrypted IP packet; The first instance determines the second instance by referring to the association between the VPN packet and the GTP-U session; the first instance sending to the second instance a GTP packet generated based on the IP packet; Includes.
16. A method according to claim 15, wherein the step of determining the second instance includes the first instance determining the second instance by referring to a correspondence between one or more source addresses and the destination of the GTP session to which each source address is assigned, held in the first instance, based on a source address included in a header of the IP packet.
17. The method of claim 15, wherein the GTP packet includes the IP packet in a GTP payload.
18. The method of claim 15, further comprising a step in which the second instance transmits the IP packet obtained from the GTP packet to an IP network external or internal to the communications infrastructure.
19. A method as described in claim 15, further comprising the second instance identifying the source address by referring to a correspondence between IDs and source addresses stored by the second instance.
20. A method according to any one of claims 15 to 19, comprising: The first instance and the second instance are instances on a cloud or a public cloud.
21. 1. A program for causing a communication infrastructure having a first instance and a second instance between which a GTP-U session is generated, the communication infrastructure being connected to an MNO's communication infrastructure, to execute a method for providing a communication service for an IoT device to access an IP network, the method comprising: receiving, by the first instance, from the IoT device, a VPN packet encapsulating an IP packet encrypted by a credential or a temporary credential; The first instance obtains a credential or a temporary credential corresponding to a source address or a temporary key included in the VPN packet to decrypt the encrypted IP packet; The first instance determines the second instance by referring to the association between the VPN packet and the GTP-U session; the first instance sending to the second instance a GTP packet generated based on the IP packet; Includes.
22. A communication infrastructure connected to an MNO's communication infrastructure for providing communication services for IoT devices to access IP networks, having a first instance and a second instance between which a GTP-U session is created; The first instance receives a VPN packet encapsulating an IP packet encrypted by a credential or a temporary credential from the IoT device, obtains a credential or a temporary credential corresponding to a source address or a temporary key included in the VPN packet, and decrypts the encrypted IP packet; The first instance determines the second instance by referring to the correspondence between the VPN packet and the GTP-U session, and transmits a GTP packet generated based on the IP packet to the second instance.