Session control device, session control system, and session control method
The session control device and method facilitate communication through local network VPN services, reducing UPF load and preventing congestion by establishing sessions within the local network, thus addressing the challenge of increased load in SNPNs.
Patent Information
- Application Number
- JP2024507417
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-18
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2042-03-18
AI Technical Summary
The increased load on UPFs serving as anchor points for IoT terminals in Standalone Non-Public Networks (SNPNs) due to managing connections across multiple networks leads to potential failures and congestion.
A session control device and method that identifies a VPN service and communication device within a local network to establish a session, allowing communication terminals to connect to a data network through the local network's VPN service, thereby reducing the need for the UPF to manage connections directly.
This approach reduces the load on communication devices by enabling terminals to communicate through local network sessions, minimizing the management burden on UPFs and preventing congestion.
Smart Images

Figure 0007810252000001 
Figure 0007810252000002 
Figure 0007810252000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a session control device, a session control system, a session control method, and a non-transitory computer-readable medium. [Background technology]
[0002] The 3GPP (3rd Generation Partnership Project), which defines standards for mobile communications, is considering using 5G (5th Generation) systems as private networks. 3GPP is standardizing 5G systems used as private networks as Standalone Non-Public Networks (SNPNs). SNPNs are constructed as networks independent of public networks.
[0003] Non-Patent Document 1 describes connection configurations of multiple SNPNs. Furthermore, Non-Patent Document 1 describes multiple scenarios regarding paths for establishing a PDU (Protocol Data Unit) session when a UE (User Equipment) moves from one SNPN to another SNPN. Specifically, Non-Patent Document 1 describes that when a UE moves from SNPN#1 to SNPN#2, the anchor point of the PDU session established by the UE is set to SNPN#1. The PDU session is established between the UE and a UPF (User Plane Function) entity (hereinafter referred to as UPF) that relays user plane data. In other words, the PDU session is terminated between the UE and the UPF. Here, when a UE moves from SNPN#1 to SNPN#2 and accesses SNPN#2, a PDU session is established between the UE and the UPF located in SNPN#1 via SNPN#2. The PDU session established between the UE and the UPF located in SNPN#1 arrives from the UE via SNPN#2 to the UPF located in SNPN#1. [Prior art documents] [Non-patent literature]
[0004] [Non-Patent Document 1] 3GPP TR 23.700-07 V17.0.0 (2021-03) Summary of the Invention [Problem to be solved by the invention]
[0005] When a UE that can use SNPN#1 accesses SNPN#2, the UPF of SNPN#1, which serves as the anchor point, needs to manage the connection of UEs that are not in SNPN#1. In the future, when a large number of IoT (Internet of Things) terminals are used as UEs, the UPF of SNPN#1, which serves as the anchor point, will need to manage the connection of a large number of IoT terminals, regardless of which SNPN the IoT terminals use. As a result, the load on the UPF of SNPN#1 increases, which can lead to problems such as failures or congestion.
[0006] In view of the above-mentioned problems, one of the objectives of the present disclosure is to provide a session control device, a session control system, a session control method, and a non-transitory computer-readable medium that can suppress an increase in the load on communication devices that make up a network. [Means for solving the problem]
[0007] A session control device according to a first aspect of the present disclosure includes a communication unit that receives a request message from a communication terminal located in a communication area formed by a first local network requesting communication to a second data network that can be connected to via a second local network, an identification unit that identifies a VPN service that can be connected to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network, and a control unit that establishes a session between the communication terminal and the communication device.
[0008] A session control system according to a second aspect of the present disclosure comprises a communication terminal located in a communication area formed by a first local network, a first session control device that controls a session established in the first local network, and a second session control device that controls a session established in a second local network that is connectable to a second data network, wherein when the second session control device receives a request message from the first session control device indicating that the communication terminal requests communication to the second data network, the second session control device sends a first response message to the first session control device, the first response message including VPN information indicating a VPN service that can be connected to the second data network, and the first session control device identifies a communication device that is used to connect to the VPN service and is located on the first local network, and establishes a session between the communication terminal and the communication device.
[0009] A session control method according to a third aspect of the present disclosure receives a request message from a communication terminal located in a communication area formed by a first local network requesting communication with a second data network connectable via a second local network, identifies a VPN service connectable to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network, and establishes a session between the communication terminal and the communication device.
[0010] A program according to a fourth aspect of the present disclosure causes a computer to receive a request message from a communication terminal located in a communication area formed by a first local network, requesting communication to a second data network connectable via a second local network, identify a VPN service connectable to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network, and establish a session between the communication terminal and the communication device. [Effects of the Invention]
[0011] The present disclosure makes it possible to provide a session control device, a session control system, a session control method, and a non-transitory computer-readable medium that can suppress an increase in the load on communication devices that make up a network. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a configuration diagram of a session control device according to a first embodiment. [Figure 2] 10 is a flowchart of a session control process according to the first embodiment; [Figure 3] FIG. 10 is a configuration diagram of a communication system according to a second embodiment. [Figure 4] FIG. 10 is a diagram showing the flow of VPN setting processing according to the second embodiment. [Figure 5]FIG. 10 is a diagram showing the flow of VPN setting processing according to the second embodiment. [Figure 6] FIG. 10 is a diagram illustrating a communication path according to a second embodiment. [Figure 7] FIG. 10 is a configuration diagram of a session control device according to a second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0013] (Embodiment 1) Hereinafter, embodiments of the present invention will be described with reference to the drawings. An example of the configuration of a session control device 10 according to the first embodiment will be described with reference to FIG. 1. The session control device 10 may be a computer device that operates when a processor executes a program stored in a memory. The session control device 10 may be a node device or a communication device that constitutes a mobile communication network.
[0014] The session control device 10 has a communication unit 11, an identification unit 12, and a control unit 13. The communication unit 11, the identification unit 12, and the control unit 13 may be software or modules that are executed by a processor executing a program stored in a memory, or the communication unit 11, the identification unit 12, and the control unit 13 may be hardware such as a circuit or a chip.
[0015] The communication unit 11 receives a request message from a communication terminal located in a communication area formed by the first local network, requesting communication with a data network connectable via the second local network.
[0016] A local network may also be referred to as a private network. A local network may not be a so-called public network, but may be a network that allows access only from specific users. A local network may also be a network that constitutes an internal company network such as an intranet. When a company with multiple locations builds an internal company network, it may build a local network for each location and interconnect the respective local networks. Specifically, a company may build a local network at its headquarter (HQ) and a local network at its branch office, and interconnect the respective local networks. The first local network and the second local network may be networks at different locations.
[0017] The communication area formed by the local network is a communication area in which a communication terminal can access the local network. The communication terminal accesses the local network using a wireless communication line or a wired communication line. The communication area formed by the local network may be, for example, a communication area formed by a wireless communication device.
[0018] The data network may be, for example, a network having a server device in which data used by a user is stored, or a server device that a user wishes to access. A network having a server device may be rephrased as a network to which a server device is connected. A local network may be used as a network that relays communications between a communication terminal and a data network. Furthermore, the data network may be included in the local network. In other words, the data network may be a part of a network that constitutes the local network.
[0019] The identification unit 12 identifies a VPN (Virtual Private Network) service connectable to a data network and a communication device used to connect to the VPN service. The communication device used to connect to the VPN service is located on a first local network.
[0020] A VPN service is a service that builds a virtual dedicated line in a public network such as the Internet. A VPN service is a service that builds a virtual dedicated line in a public network to connect a first local network and a second local network. In the virtual dedicated line, data confidentiality is maintained by encrypting the data.
[0021] VPN services may be, for example, L2VPN or L3VPN services. These technologies are generally used to interconnect private networks. L2VPN services interconnect LANs (Local Area Networks) built at different locations, making the entire network behave as if it were a single large LAN. As a result, even if a terminal moves from the head office to a branch office and accesses the branch office LAN, it can use the same IP address because the IP subnet configured on the LAN is the same. L3VPN services interconnect distant IP subnets and behave like a router. As a result, the head office and branch office environments can have separate network designs and can be updated independently. On the other hand, when a terminal moves from the head office to a branch office, it must use the branch office's IP address. Although the terminal's IP address changes, IP reachability between the connected IP subnets is maintained, so a terminal accessing the branch office LAN can use services connected to the head office LAN. Both L2VPN and L3VPN services can be isolated from other L2VPN and L3VPN services. For example, even if overlapping private addresses are used in a VPN service for company X and a VPN service for company Y, the addresses are recognized as private addresses for company X and company Y. The L2VPN service may be, for example, an EVPN (Ethernet (registered trademark) VPN). EVPN is implemented, for example, in an MPLS (Multi Protocol Label Switching) network or a Segment Routing network equipped with Traffic Engineering.
[0022] A communication device is a device that enables access to a network that runs a VPN service. For example, the communication device may be a device located in the network that runs the VPN service, or a device connected to a data network used to access the network that runs the VPN service. A single local network (e.g., a branch office local network) may have a multi-stage configuration or a distributed deployment, such as an edge environment (e.g., each floor or each building) and a center environment (e.g., a management office or a server room). In this case, the communication device may be a device located on the edge side and connected to a data network used to access the network that runs the VPN service. A single local network (e.g., a branch office local network) may have a multi-stage configuration or a distributed deployment, such as an edge environment (e.g., each floor or each building) and a center environment (e.g., a management office or a server room). In this case, the communication device may be a device located on the center side and connected to a data network used to access the network that runs the VPN service.
[0023] The control unit 13 establishes a session between the communication terminal and the communication device identified by the identification unit 12. In other words, a session is established with the communication terminal and the communication device as endpoints. Establishing a session between the communication terminal and the communication device enables the communication terminal to communicate with the communication device, and further enables communication via the communication device. Furthermore, since the communication device is located in the first local network, the session is established in the first local network. In other words, the session is terminated in the first local network. The communication terminal may establish a different session for each application service to be used, or may use multiple application services using a single session. The session between the communication terminal and the communication device may also be referred to as a communication path between the communication terminal and the communication device.
[0024] By establishing a session between the communication terminal and the communication device, the communication terminal is connected to a network that runs a VPN service via the communication device, and further, the communication terminal is connected to a data network of a second local network via the communication device and the VPN service.
[0025] Next, a flowchart of the session control process executed in the session control device 10 will be described with reference to FIG.
[0026] First, the communication unit 11 receives a request message from a communication terminal located in a communication area formed by a first local network, requesting communication with a connectable data network via a second local network (S11). Next, the identification unit 12 identifies a VPN service connectable to the data network and a communication device used to connect to the VPN service (S12). The communication device is a device located in the first local network. Next, the control unit 13 establishes a session between the communication terminal and the communication device (S13).
[0027] As described above, when a communication terminal located in a communication area formed by a first local network communicates with a data network, the session control device 10 establishes a session in the first local network. The data network is a network connectable via a second local network. In other words, the communication terminal can communicate with the data network via the session established in the first local network and the VPN service, without establishing a session with the second local network. As a result, the second local network does not need to manage connections of communication terminals located in the first local network, thereby reducing the management load on the communication terminals.
[0028] (Embodiment 2) Next, a configuration example of a communication system according to the second embodiment will be described with reference to Fig. 3. The communication system of Fig. 3 includes two local networks: a Standalone Non-Public Network (SNPN) branch 20 and an SNPN headquarters 30. The SNPN is a network being standardized by 3GPP. The SNPN branch 20 may have a different PLMN (Public Land Mobile Network) ID (Identifier) from that of the SNPN headquarters 30. A PLMN ID is generally an ID that identifies a network managed by a telecommunications carrier. On the other hand, when a carrier or company manages multiple SNPNs, a PLMN ID may be assigned to each SNPN. Alternatively, one PLMN ID may be assigned to two or more SNPNs. When one PLMN ID is assigned to two or more SNPNs, each SNPN may be assigned a Network ID (NID). In other words, an SNPN may be identified by an NID.
[0029] Here, the SNPN branch 20 and the SNPN head office 30 constitute a single in-house network, with the SNPN head office 30 being the network at the head office and the SNPN branch 20 being the network at the branch office. The local network is not limited to a network established between the head office and the branch office, but may also be established, for example, in a factory, on a floor-by-floor basis in a building, or on a division-by-division basis within a company.
[0030] The SNPN branch 20 is recognized as an equivalent SNPN of the SNPN headquarters 30. The SNPN headquarters 30 is also recognized as an equivalent SNPN of the SNPN branch 20. For example, a UE 23 having a subscription and credentials for connecting to or being registered with the SNPN headquarters 30 is not treated as roaming even if it moves from the communication area formed by the SNPN headquarters 30 to the communication area formed by the SNPN branch 20. When connecting to the SNPN branch 20, the UE 23 can use the subscription and credentials for connecting to the SNPN headquarters 30. The subscription indicates subscriber data, and the credentials indicates authentication data.
[0031] The SNPN branch 20 includes an AMF (Access and Mobility Function) entity 21, an SMF (Session Management Function) entity 22, a UE (User Equipment) 23, an (R)AN ((Radio) Access Network) 24, a UPF (User Plane Function) entity 25, a DN (Data Network) 26, an edge device 27, and an NSSMF (Network Slice Subnet Management Function) entity 28. The AMF (Access and Mobility Function) entity 21 is hereinafter referred to as the AMF 21. The SMF (Session Management Function) entity 22 is hereinafter referred to as the SMF 22. The UPF (User Plane Function) entity 25 is hereinafter referred to as the UPF 25. The NSSMF (Network Slice Subnet Management Function) entity 28 is hereinafter referred to as the NSSMF 28.
[0032] UE (User Equipment) is a general term used for communication terminals in 3GPP. The UE 23 may be, for example, a smartphone terminal, a tablet terminal, or an IoT (Internet of Things) terminal.
[0033] The AMF 21 performs mobility control and authentication processing for the UE 23. The SMF 22 performs session control for the UE 23. The SMF 22 corresponds to the session control device 10 in FIG. 1. The (R)AN 24 is an access network for connecting to a core network. The (R)AN 24 may be configured using, for example, a gNB (gNode B), or may be configured using a wireless device that supports a wireless communication standard different from the wireless communication standard defined in 3GPP. For example, the (R)AN 24 may be a wireless device that performs wireless LAN (Local Area Network) communication. Alternatively, the (R)AN 24 may be a device that provides a wired communication line.
[0034] The UPF 25 transfers or relays user plane data, which may also be referred to as user data. Control data used to control the UPF 25 may also be referred to as control plane data.
[0035] The DN 26 may be, for example, an IP network that performs communication using IP used in the Internet or the like. The DN 26 may be, for example, a LAN to which the UPF 25 is connected. The DN 26 may be a physically constructed network, or may be a virtually constructed network on a physically constructed network using VLAN (Virtual LAN), VXLAN (Virtual eXtensible LAN), GRE (Generic Routing Encapsulation), or the like. In the following explanation, the name used to identify the DN 26 will be explained as n6-site-branch. The DN 26 is connected to the UPF 25 via the N6 interface in 3GPP.
[0036] The edge device 27 is a network device that terminates the n6-site-branch and may be, for example, a router or a leaf / spine switch. The edge device 27 may be, for example, a provider edge router (PE router). The PE router may be a router managed by another network provider. For example, a company may own the SNPN headquarters 30 and the SNPN branches 20, but may use a VPN service provided by another network provider to interconnect the two. The edge device 27 may also have a virtual instance that provides a VPN service. The virtual instance terminates, for example, EVPN, a VPN service that connects the SNPN branches 20 and the SNPN headquarters 30, and the n6-site-branch. The virtual instance also forwards Ethernet frames. In the following description, the name identifying the virtual instance owned by the edge device 27 will be referred to as evpn-gw-branch. The edge device 27 may also be referred to as a gateway device.
[0037] The NSSMF 28 provides provisioning management services for the network slice subnets that make up the SNPN branch 20. A network slice is a logical network that is virtually divided from a single network infrastructure. For example, operational policies or security policies may differ for each network slice. For example, a network slice may be generated for a specific purpose, such as for each service provided. A network slice subnet is a logical network that is virtually divided from a network slice.
[0038] The SNPN headquarters 30 has an SMF entity 31, an edge device 32, a DN 33, an AF (Application Function) entity 34, an NSMF (Network Slice Management) entity 35, and an NSSMF entity 36. The SMF entity 31 will be referred to as SMF 31 below. The AF entity 34 will be referred to as AF 34 below. The NSMF entity 35 will be referred to as NSMF 35 below. The NSSMF entity 36 will be referred to as NSSMF 36 below.
[0039] The SMF 31 performs session control for the UE 23. The SMF 31 may also perform session control for the UE located in the communication area formed by the SNPN headquarters 30.
[0040] The AF 34 may be a server device that provides application services or stores data, and may be, for example, an in-house server located in the SNPN headquarters 30 .
[0041] The DN33 may be, for example, an IP network that performs communication using IP used in the so-called Internet, etc. The DN33 may be, for example, a LAN to which the AF34 is connected. The DN33 may be a physically constructed network, or may be a virtually constructed network on a physically constructed network using a Virtual LAN, a VXLAN (Virtual eXtensible LAN), a GRE (Generic Routing Encapsulation), or the like. In the following description, the name used to identify the DN33 will be described as n6-site-hq.
[0042] The edge device 32 is a network device that terminates n6-site-hq, and may be, for example, a router device or a Leaf / Spine switch. The edge device 32 may be, for example, a Provider Edge router (PE router). The edge device 32 may also have a virtual instance that provides a VPN service. The virtual instance terminates, for example, EVPN, which is a VPN service connecting the SNPN branch 20 and the SNPN headquarters 30, and n6-site-hq. The virtual instance also forwards Ethernet frames. In the following description, the name that identifies the virtual instance owned by the edge device 32 will be described as evpn-gw-hq. The edge device 32 may also be called a gateway device.
[0043] The NSSMF 36 provides provisioning management services for the network slice subnets that constitute the SNPN headquarters 30. The NSMF 35 provides provisioning management services for the network slices including the network slice subnets that constitute the SNPN branches 20 and the network sub-slice subnets that constitute the SNPN headquarters 30.
[0044] 3 illustrates a configuration in which the SNPN branch 20 includes the NSSMF 28 and the SNPN headquarters 30 includes the NSMF 35 and the NSSMF 36, but is not limited to this. For example, the NSMF 35 may be located in the SNPN branch 20, or may be located in a location different from the SNPN branch 20 and the SNPN headquarters 30. The NSSMF 28 and the NSSMF 36 may also be located in a location different from the SNPN branch 20 and the SNPN headquarters 30. In addition, the NSMF 35, the NSSMF 36, and the NSSMF 28 may be referred to as management devices.
[0045] A service-based architecture is applied to the AMF 21, SMF 22, NSSMF 28, SMF 31, NSMF 35, and NSSMF 36, and they are connected to each other via a service-based interface, which may use, for example, HTTP (HyperText Transfer Protocol).
[0046] Next, the flow of VPN setup processing according to the second embodiment will be described with reference to Figures 4 and 5. Before the VPN setup processing shown in Figures 4 and 5 is executed, it is assumed that evpn-gw-branch is configured in the edge device 27 and evpn-gw-hq is configured in the edge device 32. As a result, EVPN, which is an L2VPN service, is deployed in the transport network between the edge device 27 and the edge device 32. The transport network may be a transport network slice. Furthermore, it is assumed that n6-site-hq is connected to evpn-gw-hq. It is also assumed that n6-site-branch is not connected to evpn-gw-hq. When n6-site-branch is not connected to evpn-gw-hq, that is, when n6-site-branch is not connected to evpn-gw-hq, it means that DN 26 is not configured between the UPF 25 and the edge device 27 and a data communication path is not configured. Furthermore, suppose that UE 23 moves from the communication area formed by SNPN headquarters 30 to the communication area formed by SNPN branch 20. Specifically, suppose that UE 23 has handed over from the communication area formed by SNPN headquarters 30 to the communication area formed by SNPN branch 20. Alternatively, suppose that UE 23 has been registered with SNPN headquarters 30 but has not yet communicated, and has moved to the communication area formed by SNPN branch 20. Alternatively, suppose that UE 23 holds subscriber data for connecting to SNPN headquarters 30 and has started communication in the communication area formed by SNPN branch 20.
[0047] First, when the AMF 21 receives a PDU Session connection request message from the UE 23, it calls the Nsmf_PDUSession_CreateSMContext service of the SMF 22 (S21). Specifically, the AMF 21 sends a request message to the SMF 22 to call the Nsmf_PDUSession_CreateSMContext service of the SMF 22. The AMF 21 specifies a resource called sm-contexts and sends a request message to the SMF 22 in which data {"SmContextCreateData":{"dnn": "n6-site-hq"}} is set. The SmContextCreateData is information about the PDU Session requested by the UE 23, and the dnn (Data Network Name) is the name of the DN (Data Network) that the UE 23 wishes to use. In other words, the dnn indicates the DN to which the UE 23 is to be connected. Here, it is shown that the UE 23 specifies n6-site-hq as the dnn. That is, the UE 23 requests connection to the DN 33 of the SNPN headquarters 30 via the SNPN branch 20 .
[0048] Also, it is assumed that Ethernet is set as the service type in the PDU Session connection request message transmitted from the UE 23 .
[0049] Next, when the Nsmf_PDUSession_CreateSMContext service is called, the SMF 22 calls the Nsmf_PDUSession_Create service of the SMF 31 (S22). The SMF 22 may request information about the PDU session to connect to the DN 33 of the SNPN headquarters 30 using a VPN service. Specifically, the SMF 22 sends a request message to the SMF 31 to call the Nsmf_PDUSession_Create service of the SMF 31. The SMF 22 specifies a resource called pdu-sessions and sends a request message to the SMF 31 in which the data {"PduSessionCreateData":{"dnn": "n6-site-hq", "requestedConnectivity": "l2vpn-svc"}} is set. Note that the SMF 22 may identify the SMF 31 based on the DN specified by dnn.
[0050] PduSessionCreateData is information about the PDU Session requested by the UE 23, and dnn is the name of the DN (Data Network) that the UE 23 wishes to use. requestedConnectivity is used to specify a service for connecting to n6-site-hq. In step S22, l2vpn-svc, which indicates an L2VPN service, is specified as the service for connecting to n6-site-hq. Since the service type of the PDU Session specified by the UE 23 is Ethernet, the SMF 22 may specify l2vpn-svc. IETF RFC8466 defines a YANG data model that can be used to configure an L2VPN service, and l2vpn-svc indicates a parameter used in the YANG data model. Note that if the service type of the PDU Session specified by the UE 23 is IP, the SMF 22 may specify an L3VPN service.
[0051] Next, SMF 31 calls the Provisioning Management Service of NSSMF 36 to update the DNFunction information (S23). Specifically, SMF 31 sends a request message to NSSMF 36 to call the Provisioning Management Service. SMF 31 specifies a resource called DNFunction and sends a request message to NSSMF 36 in which the data {“managedVpnService”: {network-access-id”: “n6-site-hq”}} is set as a filter condition.
[0052] The DNFunction information includes managedVpnService, vpn-id, network-access-id, site-id, and device-id. managedVpnService indicates the VPN service type. The VPN service type may indicate, for example, L2VPN or L3VPN. vpn-id is identification information for identifying the VPN service. network-access-id indicates the data network accommodated in the VPN service type indicated in managedVpnService. site-id indicates the location where the data network is located. device-id indicates the edge device, which is a physical device that terminates the VPN service indicated in vpn-id.
[0053] Step S23 in Figure 4 shows that the DNFunction information includes at least one managedVpnService information. The managedVpnService information may be described in accordance with the YANG data model defined in IETF RFC8466. "Described" may also be rephrased as "indicated" or "set." In other words, the managedVpnService information may include one l2vpn-svc.
[0054] The network-access-id is a parameter for extracting DN33 accommodated in l2vpn-svc. Being accommodated may also be referred to as being connected. In step S23, the network-access-id is used as a filter condition, and n6-site-hq is extracted as the network-access-id.
[0055] Next, the NSSMF 36 transmits a response message to the SMF 31 in response to the update of the DNFunction information (S24). The NSSMF 36 may use the managedVpnService information received in S23 as a filter condition and transmit matching DNFunction information to the SMF 31 as a response message. Specifically, it is assumed that the NSSMF 36 has DNFunction information in which the managedVpnService is l2vpn-svc, the vpn-id is evpn, the network-access-id is n6-site-hq, the site-id is SNPN-hq, and the device-id is pe-hq. The evpn is a parameter that identifies the EVPN service. Note that the inclusion of the evpn may indicate that the EVPN service is requested. The SNPN-hq indicates the SNPN headquarters 30, and the pe-hq indicates the edge device 32. When NSSMF 36 receives a request message in which network-access-id is n6-site-hq, it transmits a response message including information indicating that vpn-id is evpn to SMF 31. In other words, NSSMF 36 notifies SMF 31 that the identification information identifying the VPN service to which n6-site-hq connects is evpn. NSSMF 36 transmits a response message in which the following data is set to SMF 31: {"DNFunction": {"managedVpnService": {"l2vpn-svc": {"vpn-id": "evpn"}}}}.
[0056] Next, SMF 31 transmits a response message to step S22 to SMF 22 (S25). As the response message to step S22, SMF 31 may transmit information about a PDU session for connecting to DN 33 owned by the SNPN head office 30 using a VPN service to SMF 22. SMF 31 transmits a response message to SMF 22 in which the data {“PduSessionCreateData”:{“managedVpnService”:{“l2vpn-svc”:{“vpn-id”:“evpn”}}}} is set. PduSessionCreateData includes PDU Session information generated in SMF 31. Step S25 in FIG. 3 indicates that vpn-id is evpn, and SMF 22 acquires evpn as identification information for the L2VPN service used between the SNPN branch 20 and the SNPN head office 30.
[0057] Next, the SMF 22 calls the Provisioning Management Service of the NSMF 35 to acquire DNFunction information (S26). To use the VPN service (evpn in this case) acquired in S25, the SMF 22 may request information about the edge device 27 in the SNPN branch that corresponds to the VPN service from the NSMF 35. Specifically, the SMF 22 sends a request message to the NSMF 35 to call the Provisioning Management Service. The SMF 22 specifies a resource called DNFunction and sends a request message to the NSMF 35 in which the message {“managedVpnService”: {“l2vpn-svc”: {“vpn-id”: “evpn”, “site-id”: “SNPN-Branch”}}} is set as a filter condition.
[0058] Next, the NSMF 35 transmits a response message to step S26 to the SMF 22 (S27). The NSMF 35 may transmit information about the edge device 27 in the SNPN branch that corresponds to the VPN service to the SMF 22 as the response message to step S26. Assume that the NSMF 35 has DNFunction information in which the managedVpnService is l2vpn-svc, the vpn-id is evpn, the network-access-id is n6-site-branch, the site-id is SNPN-branch, and the device-id is pe-branch. The pe-branch indicates the edge device 27. The NSMF 35 finds DNFunction information that matches the filter condition in which the vpn-id is evpn and the site-id is SNPN-Branch. As a result, the NSMF 35 sends a response message to the SMF 22 with the following data set: {“managedVpnService”: {“l2vpn-svc”: {“vpn-id”: “evpn”, “site-id”: “SNPN-Branch”, “device-id”: “pe-branch”, “network-access-id”: n6-site-branch}}}.
[0059] Next, the SMF 22 selects a UPF (S28). The SMF 22 selects the UPF 25 as a UPF that can be connected to the n6-site-branch included in the DNFunction acquired in step S27.
[0060] Next, the SMF 22 invokes the Provisioning Management Service of the NSMF 35 to update the UPFFunction information (S29). In other words, the SMF 22 invokes the Provisioning Management Service of the NSMF 35 to execute processing for connecting the n6-site-branch to the UPF 25. The SMF 22 may request the NSMF 35 to configure a connection between the UPF 25 and the edge device 27. Specifically, the SMF 22 specifies a resource called UPFFunction and transmits a request message to the NSSMF 36, in which the following registration data is configured: {“EP_N6”: {“localAddress”: “Bearer IP address of UPF”, “remoteAddress”: “Bearer IP address of pe-branch”}}. The Bearer IP address of UPF configured as the localAddress is the IP address of the physical network interface configured in the UPF 25. The Bearer IP address of pe-branch configured as the remoteAddress is the IP address of the physical network interface configured in the edge device 27. EP_N6 indicates that this is endpoint information for the N6 interface. The N6 interface is an interface defined in 3GPP as an interface between the UPF and the DN. The endpoint is the Bearer IP address of the UPF and the Bearer IP address of the pe-branch.
[0061] Next, the NSMF 35 calls the Provisioning Management Service of the NSSMF 28 to update the UPFFunction information (S30). Specifically, the NSMF 35 specifies a resource called UPFFunction and transmits to the NSSMF 28 a request message in which the registration data {“EP_N6”: {“localAddress”: “Bearer IP address of UPF”, “remoteAddress”: “Bearer IP address of pe-branch”}} is set.
[0062] Next, the NSSMF 28 updates the EP_N6 information in the UPF 25 (S31). The NSSMF 28 may request the UPF 25 to perform settings for connecting the UPF 25 and the edge device 27. Specifically, the NSSMF 28 transmits a request message to the UPF 25, in which the following registration data is set: {"EP_N6": {"localAddress": "Bearer IP address of UPF", "remoteAddress": "Bearer IP address of pe-branch"}}. For example, an IP address used by the UPF, such as 192.168.0.10, is set as the Bearer IP address of UPF. Furthermore, for example, an IP address used by the pe-branch, such as 192.168.0.254, is set as the Bearer IP address of pe-branch.
[0063] By executing the process of step S31, an IP address is set to the physical interface of UPF 25, and furthermore, the IP address of edge device 27, which is the endpoint of the N6 interface, is recognized. As a result, UPF 25 can set the IP address of the physical interface of UPF 25 as the source address of the transmission data, and set the IP address of edge device 27 as the destination address. As a result, UPF 25 and edge device 27 can communicate with each other.
[0064] Next, the NSSMF 28 executes a process to connect the UPF 25 and the edge device 27 via VXLAN. Specifically, the NSSMF 28 sends a request message including a VXLAN configuration to the UPF 25 (S32). The UPF 25 acquires the VXLAN configuration and sets the VXLAN endpoint as an endpoint of the N6 interface. Next, the NSSMF 28 creates a VXLAN endpoint in the edge device 27 and connects the created VXLAN endpoint to the evpn-gw-branch (S33). By executing the processes of steps S32 and S33, the UPF 25 can connect to the EVPN via VXLAN.
[0065] FIG. 6 shows a communication path for the UE 23. The (R)AN 37 and the UPF 38 constitute the SNPN headquarters 30. Also, it shows that the UE 23 connected to the (R)AN 37 has moved to the SNPN branch 20. The processes shown in FIGS. 4 and 5 are executed, and the UE 23 receives a response message to the PDU Session connection request message, thereby establishing a PDU Session between the UE 23 and the UPF 25. Furthermore, a VXLAN is set as the communication path between the UPF 25 and the DN 26. Furthermore, the DN 26 and the DN 33 are connected via EVPN. When the UE 23 communicates with the AF 34, the UE 23 communicates with the AF 34 according to the communication path shown in FIG. 6.
[0066] As described above, by connecting UPF 25 to evpn-gw-branch via n6-site-branch, UE 23 can use EVPN, which is an L2VPN service set up between SNPN branch 20 and SNPN headquarters 30. As a result, UE 23 can communicate with AF 34 connected to n6-site-hq in SNPN headquarters 30. In other words, when UE 23 communicates with AF 34, it does not establish a PDU session with the UPF in SNPN headquarters 30 as the anchor point. This makes it possible to prevent an increase in the load on UPF in SNPN headquarters 30.
[0067] (Modification 1 of Embodiment 2) Here, a first modification of the second embodiment will be described. For example, when the SMF 22 receives a request message specifying n6-site-hq as the dnn in step S21 of FIG. 4, it may determine whether or not it has previously received a request message specifying n6-site-hq. For example, the SMF 22 may manage a network name set in the dnn included in the request message in association with a VPN-ID accommodating that network. When the SMF 22 determines that it has previously received a request message specifying n6-site-hq, that is, when it has managed n6-site-hq, it identifies the VPN-ID associated with n6-site-hq. For example, the SMF 22 may use the VPN-ID corresponding to n6-site-hq that it previously received as a message corresponding to step S25 of FIG. 4. Note that the message corresponding to step S25 of FIG. 4 may be a message for a UE different from the UE 23. Specifically, the SMF 22 identifies evpn as a VPN service accommodating n6-site-hq. In this case, SMF 22 can skip the processing of steps S22 to S25 in Fig. 4. Also, assume that SMF 22 manages n6-site-hq, vpn-id, and even n6-site-branch in the SNPN branch 20 in association with each other. In this case, when SMF 22 receives a request message specifying n6-site-hq, it can identify n6-site-branch. In this case, SMF 22 can skip the processing of steps S22 to S27 in Fig. 4.
[0068] If the SMF 22 determines that it has not previously received a request message specifying n6-site-hq, the process proceeds to step S22 and subsequent steps in FIG.
[0069] (Modification 2 of Embodiment 2) Here, a second modification of the second embodiment will be described. For example, when the SMF 22 receives a request message specifying n6-site-hq as the dnn in step S21 of Fig. 4, the SMF 22 may inquire of the NSMF 35 whether or not processing for connecting to the VPN service with n6-site-hq has been previously executed.
[0070] If the NSMF 35 determines that it has previously executed a process for connecting to the VPN service with n6-site-hq, it may transmit a response message including the data set in step S27 of Fig. 4 to the SMF 22. This allows the SMF 22 to skip the processes from steps S22 to S26.
[0071] If the NSMF 35 determines that it has not previously executed a process for connecting to the VPN service with n6-site-hq, the processes from step S22 onward in FIG. 4 are executed.
[0072] Fig. 7 is a block diagram showing an example of the configuration of the session control device 10 described in the above embodiment. Referring to Fig. 7, the session control device 10 includes a network interface 1201, a processor 1202, and a memory 1203. The network interface 1201 may be used to communicate with a network node. The network interface 1201 may include, for example, a network interface card (NIC) that complies with the IEEE 802.3 series. IEEE stands for Institute of Electrical and Electronics Engineers.
[0073] The processor 1202 reads and executes software (computer programs) from the memory 1203 to perform the processing of the session control device 10 described using the flowcharts in the above-described embodiment. The processor 1202 may be, for example, a microprocessor, an MPU, or a CPU. The processor 1202 may include multiple processors.
[0074] The memory 1203 is configured by a combination of volatile memory and non-volatile memory. The memory 1203 may include storage located remotely from the processor 1202. In this case, the processor 1202 may access the memory 1203 via an I / O (Input / Output) interface (not shown).
[0075] 7, memory 1203 is used to store software modules. Processor 1202 reads and executes these software modules from memory 1203, thereby performing the processing of session control device 10 described in the above embodiment.
[0076] As explained using FIG. 7, each of the processors of the session control device 10 in the above-described embodiment executes one or more programs including a set of instructions for causing a computer to perform the algorithms explained using the drawings.
[0077] In the above examples, the program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disc (DVD), Blu-ray® disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.
[0078] The technical ideas shown in the present disclosure are not limited to the above-described embodiments, and can be modified as appropriate within the scope of the gist thereof.
[0079] Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes. (Appendix 1) a communication unit that receives a request message from a communication terminal located in a communication area formed by the first local network, requesting communication with a second data network connectable via the second local network; an identification unit that identifies a Virtual Private Network (VPN) service connectable to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network; a control unit that establishes a session between the communication terminal and the communication device. (Appendix 2) The communication unit After receiving the request message, send a first inquiry message to another session control device that controls the session established in the second local network, inquiring about the VPN service; The session control device according to claim 1, which receives a first response message including VPN information indicating the VPN service from the other session control device. (Appendix 3) The communication unit sending a second inquiry message to a management device inquiring about a first data network connectable to the VPN service; receiving a second response message including network identification information indicating the first data network connectable to the VPN service; The identification unit After receiving the second response message, identify the communication device that is connectable to the first data network; 3. The session control device according to claim 1, wherein the first data network is a data network in the first local network. (Appendix 4) 4. The session control device according to claim 3, wherein the second inquiry message includes VPN information indicating the VPN service. (Appendix 5) The session control device according to claim 3, wherein the identification unit identifies the communication device connectable to the first data network based on the network identification information. (Appendix 6) a management unit that manages VPN information indicating the VPN service; When the communication unit receives a request message from another communication terminal requesting connection to the second data network, the identification unit The session control device according to any one of Supplementary Note 1 to 5, which identifies the communication device based on the managed VPN information. (Appendix 7) a communication terminal located in a communication area formed by a first local network; a first session control device that controls a session established in the first local network; a second session control device that controls a session established in a second local network connectable to a second data network; The second session control device upon receiving from the first session control device a first request message indicating that the communication terminal requests communication to the second data network, transmitting a first response message to the first session control device, the first response message including VPN information indicating a VPN service connectable to the second data network; The first session control device A session control system that identifies a communication device used to connect to the VPN service and that is located on the first local network, and establishes a session between the communication terminal and the communication device. (Appendix 8) The first session control device a first inquiry message inquiring about an access network connectable to the VPN service to a first management device, and a second response message is received; and the communication device is configured to identify the communication device connectable to the access network; The session control system described in Appendix 7, wherein the second response message includes network identification information indicating a first data network that can be connected to the VPN service, and the first data network is a data network in the first local network. (Appendix 9) The second session control device A session control system as described in Appendix 7 or 8, which sends a third inquiry message to a second management device inquiring about VPN services that can be connected to the second data network, and receives a third response message including the VPN information indicating the VPN service. (Appendix 10) receiving a request message from a communication terminal located in a communication area formed by the first local network, the request message requesting communication to a second data network connectable via the second local network; Identifying a VPN service connectable to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network; A session control method for establishing a session between the communication terminal and the communication device. (Appendix 11) After receiving the request message, send a first inquiry message to another session control device that controls the session established in the second local network, inquiring about the VPN service; A session control method according to claim 10, further comprising receiving a first response message from the other session control device, the first response message including VPN information indicating the VPN service. (Appendix 12) sending a second inquiry message to a management device inquiring about a first data network connectable to the VPN service; receiving a second response message including network identification information indicating the first data network connectable to the VPN service; After receiving the second response message, identify the communication device that is connectable to the first data network; 12. The session control method according to claim 10, wherein the first data network is a data network in the first local network. (Appendix 13) 13. The session control method according to claim 12, wherein the second inquiry message includes VPN information indicating the VPN service. (Appendix 14) 13. The session control method according to claim 12, further comprising identifying the communication device connectable to the first data network based on the network identification information. (Appendix 15) When a request message requesting connection to the second data network is received from another communication terminal, The session control method according to any one of appendices 10 to 14, wherein the communication device is identified based on VPN information indicating the VPN service. (Appendix 16) receiving a request message from a communication terminal located in a communication area formed by the first local network, the request message requesting communication to a second data network connectable via the second local network; Identifying a VPN service connectable to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network; A non-transitory computer-readable medium storing a program that causes a computer to establish a session between the communication terminal and the communication device. (Appendix 17) After receiving the request message, send a first inquiry message to another session control device that controls the session established in the second local network, inquiring about the VPN service; A non-transitory computer-readable medium having stored thereon the program of Appendix 16, causing a computer to execute the following: receive a first response message from the other session control device, the first response message including VPN information indicating the VPN service. (Appendix 18) sending a second inquiry message to a management device inquiring about a first data network connectable to the VPN service; receiving a second response message including network identification information indicating the first data network connectable to the VPN service; After receiving the second response message, identify the communication device that is connectable to the first data network; A non-transitory computer-readable medium having stored thereon the program of claim 16 or claim 17, causing a computer to execute the following: the first data network is a data network in the first local network. (Appendix 19) 19. A non-transitory computer-readable medium having stored thereon a program as described in Appendix 18, wherein the second inquiry message includes VPN information indicating the VPN service. (Appendix 20) A non-transitory computer-readable medium having stored thereon the program of Appendix 18, causing a computer to execute the following: identify the communication device that can connect to the first data network based on the network identification information. (Appendix 21) When a request message requesting connection to the second data network is received from another communication terminal, A non-transitory computer-readable medium having stored thereon a program described in any one of appendices 16 to 20, which causes a computer to identify the communication device based on VPN information indicating the VPN service. [Explanation of symbols]
[0080] 10 Session Control Device 11 Communications Department 12 Specific part 13 Control Unit 20 SNPN Branch 21 AMF 22 SMF 23UE 24 (R)AN 25 UPF 26DN 27 Edge Device 28 NSSMF 30 SNPN Headquarters 31 SMF 32 Edge Device 33DN 34AF 35 NSMF 36 NSSMF
Claims
1. a communication unit that receives, from a device that performs mobility control for a communication terminal, a request message indicating that the communication terminal located in a communication area formed by a first local network requests communication with a second data network that is connectable via a second local network; an identification unit that identifies a Virtual Private Network (VPN) service connectable to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network; a control unit that establishes a session between the communication terminal and the communication device.
2. The communication unit After receiving the request message, sending a first inquiry message to another session control device that controls the session established in the second local network to inquire about the VPN service; The session control device according to claim 1 , further comprising: a first response message including VPN information indicating the VPN service from the other session control device;
3. The communication unit sending a second inquiry message to a management device inquiring about a first data network connectable to the VPN service; receiving a second response message including network identification information indicating the first data network connectable to the VPN service; The identification unit After receiving the second response message, identify the communication device that is connectable to the first data network; 3. The session control device according to claim 1, wherein the first data network is a data network in the first local network.
4. The session control device according to claim 3 , wherein the second inquiry message includes VPN information indicating the VPN service.
5. The session control device according to claim 3 , wherein the identifying unit identifies the communication device connectable to the first data network based on the network identification information.
6. a management unit that manages VPN information indicating the VPN service; When the communication unit receives a request message requesting connection to the second data network from another communication terminal, the identification unit The session control device according to claim 1 , wherein the communication device is identified based on the managed VPN information.
7. a communication terminal located in a communication area formed by a first local network; a first session control device for controlling a session established in the first local network; a second session control device that controls a session established in a second local network connectable to a second data network; The second session control device upon receiving from the first session control device a first request message indicating that the communication terminal requests communication to the second data network, transmitting a first response message to the first session control device, the first response message including VPN information indicating a VPN service connectable to the second data network; The first session control device A session control system that identifies a communication device used to connect to the VPN service and that is located on the first local network, and establishes a session between the communication terminal and the communication device.
8. The first session control device a first inquiry message inquiring about an access network connectable to the VPN service to a first management device, and a second response message is received; and the communication device is configured to identify the communication device connectable to the access network; 8. The session control system of claim 7, wherein the second response message includes network identification information indicating a first data network connectable to the VPN service, the first data network being a data network in the first local network.
9. The second session control device 9. A session control system as described in claim 7 or 8, which sends a third inquiry message to a second management device inquiring about a VPN service that can be connected to the second data network, and receives a third response message including the VPN information indicating the VPN service.
10. receiving, from a device that performs mobility control for a communication terminal located in a communication area formed by a first local network, a request message indicating a request for communication to a second data network connectable via a second local network; Identifying a VPN service connectable to the second data network and a communication device used to connect to the VPN service, the communication device being located on the first local network; A session control method for establishing a session between the communication terminal and the communication device.
Citation Information
Patent Citations
Apparatus and method for providing virtual private network service based on mutual authentication
EP2575297A2
Multiple hop point-to-point protocol
JP1999355272A
Mobile network agent
US20050083883A1
Automatic remote services provided by a home relationship between a device and a server
US20060013197A1
Method of providing 5glan service and terminal device and server using the same
US20200059977A1