Devices, methods, and programs for providing communication services for accessing IP networks.

A cloud-based communication infrastructure enables IoT devices to access an IP network securely and efficiently by establishing GTP-U and VPN sessions, addressing the cost issue of separate communication services or new system development.

JP7842920B2Active Publication Date: 2026-04-08SORACOM INC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2026-04-08

AI Technical Summary

Technical Problem

Enabling IoT devices to access an IP network without using cellular communication infrastructure incurs increased costs due to the need for separate communication services or developing a new system, which is not efficient.

Method used

A method and device that utilize a cloud-based communication infrastructure connected to an MNO's infrastructure to provide a communication service, enabling IoT devices to access an IP network through a GTP-U and VPN session without a wireless access network, using a first and second instance to establish secure connections and data transmission.

Benefits of technology

IoT devices can securely connect to an MNO's communication infrastructure via a VPN tunnel, transmitting data without a wireless access network, reducing costs and management complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007842920000001
    Figure 0007842920000001
  • Figure 0007842920000002
    Figure 0007842920000002
  • Figure 0007842920000003
    Figure 0007842920000003
Patent Text Reader

Abstract

To provide apparatus, method, and program that enable access without going through a radio access network for cellular communication by using a communication infrastructure connected to an MNO's communication infrastructure.SOLUTION: A device 200 receives a session generation request including a subscriber identifier 232 of a communication service from an IoT device 230, transmits a provisioning call for a GTP tunnel between first and second instances included in a communication infrastructure on a cloud connected to an MNO's communication infrastructure, and receives, from the first instance or the second instance, an ID associated with the subscriber identifier and a source address from which a GTP-U session is transmitted. A provisioning call including a source address and a public key for a VPN tunnel between the IoT device and the first instance is transmitted to the first instance. Connection information is transmitted to an IoT device that stores a private key corresponding to the public key.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus, a method, and a program therefor for providing a communication service for accessing an IP network.

Background Art

[0002] Wireless communication services using a cellular network have conventionally been provided by MNOs (mobile network operators). Users can start using the service by concluding a contract with an MNO, receiving a SIM card from the MNO, and attaching it to a device.

[0003] In recent years, with the emergence of MVNOs (mobile virtual network operators), retail of wireless communication lines has advanced. In this case, users receive SIM cards from MVNOs instead of MNOs. MVNOs can be broadly classified into two types: those that do not have any communication infrastructure of their own and those that have their own communication infrastructure and connect their communication infrastructure to the communication infrastructure of an MNO to provide wireless communication services (see FIG. 1). The latter can set prices according to communication quality such as communication speed and communication capacity, for example, and attempts are being made to meet various needs because they have their own communication infrastructure as compared with the former.

[0004] In recent years, the movement of IoT, which adds a communication function to all things and connects them to the Internet, has been increasing remarkably as a need for wireless communication services. Hereinafter, devices that can be connected to a computer network including the Internet are referred to as "IoT devices". By attaching a SIM card, an IoT device can access an IP network using cellular communication.

[0005] Furthermore, an MVNE (Mobile Virtual Network Enabler) may act as an intermediary between the MNO and MVNO, providing support services to enable the MVNO to operate smoothly. In some cases, the MVNE receives SIM cards from the MNO and then provides them to the MVNO. For example, it is conceivable that the MVNE's communication infrastructure could be connected to the MNO's communication infrastructure to realize wireless communication services, allowing the MVNO, which does not own its own communication infrastructure, to handle retail. [Overview of the project] [Problems that the invention aims to solve]

[0006] However, if you also want to enable IoT devices to access the IP network without using cellular communication, or more specifically, without using a wireless access network for cellular communication, you will need to either use a separate communication service to manage each service from the wireless communication service provided by the MVNO or MVNE mentioned above, or develop your own communication system to manage multiple communication services. This will lead to increased costs such as management costs and development costs.

[0007] This invention has been made in view of the above problems, and its purpose is to provide a device, method, and program for providing a communication service to IoT devices for accessing an IP network using a communication infrastructure connected to an MNO's communication infrastructure, thereby enabling such access without going through a wireless access network for cellular communication.

[0008] Furthermore, a more general objective of the present invention is to enable IoT devices to access an IP network using a communication infrastructure connected to the communication infrastructure of an MNO, without going through a wireless access network for cellular communication.

[0009] Note that the terms MNO, MVNO, and MVNE may have different definitions. In this specification, an MNO is defined as a carrier that owns 3G SGSN and LTE S-GW as its communication infrastructure, while MVNOs and MVNEs are not distinguished and are collectively referred to as carriers that have communication infrastructure connected to an MNO's communication infrastructure. Examples of communication infrastructure owned by such carriers include 3G GGSN and LTE P-GW.

[0010] Furthermore, while the above explanation uses the example of a SIM card being inserted into an IoT device, it is not limited to a physical SIM card. It can also be implemented as a semiconductor chip embedded in the IoT device, or as software installed in a secure area within the IoT device's module, and these will all be collectively referred to as "SIM" below. A SIM stores a SIM identifier that identifies it. Examples of SIM identifiers include IMSI, ICCID, and MSISDN. [Means for solving the problem]

[0011] The present invention has been made in view of the above problems, and its object is a method for providing a communication service to an IoT device for accessing an IP network using equipment provided in a cloud-based communication infrastructure connected to the communication infrastructure of an MNO, the method comprising: receiving a session generation request including a subscriber identifier for identifying a subscriber to the communication service; storing an ID associated with the subscriber identifier; and making a first provisioning call to a first instance and a second instance included in the equipment for generating a GTP-U session between the first instance and the second instance, wherein the first provisioning call including the ID is transmitted to the first instance and the second instance. Steps include: receiving a source address from the first instance or the second instance as a response to the first provisioning call, which will be the source address of the GTP-U session; sending a second provisioning call to the first instance for generating a VPN session between the IoT device and the first instance, which includes the source address and the first credentials; and sending connection information, including the source address and the destination address of the first instance, to the IoT device which stores the first credentials or the second credentials corresponding to the first credentials. Includes.

[0012] Furthermore, a second aspect of the present invention is the method of the first aspect, wherein the connection information includes the port number of the first instance.

[0013] Furthermore, a third aspect of the present invention is the method of the first aspect, wherein the first credential is a public key and the second credential is a private key corresponding to the public key.

[0014] Furthermore, a fourth aspect of the present invention is the method of the first aspect, wherein the session generation request is received from the IoT device.

[0015] Furthermore, a fifth aspect of the present invention is a method according to any of the first to fourth aspects, wherein the first instance and the second instance are instances on a cloud or public cloud.

[0016] A sixth aspect of the present invention is a program that causes a device to execute a method for providing an IoT device with a communication service for accessing an IP network, using equipment provided in a cloud-based communication infrastructure connected to an MNO's communication infrastructure, the method comprising: receiving a session generation request including a subscriber identifier for identifying a subscriber to the communication service; storing an ID associated with the subscriber identifier; and sending a first provisioning call to a first instance and a second instance included in the equipment, the first provisioning call including the ID, for generating a GTP-U session between the first instance and the second instance. The steps include: receiving a source address from the first instance or the second instance as a response to the first provisioning call, which will be the source address of the GTP-U session; sending a second provisioning call to the first instance for generating a VPN session between the IoT device and the first instance, the second provisioning call including the source address and the first credentials; and sending connection information including the source address and the destination address of the first instance to the IoT device which stores the first credentials or the second credentials corresponding to the first credentials.

[0017] Furthermore, a seventh aspect of the present invention is a device for providing a communication service to an IoT device for accessing an IP network, using equipment provided in a cloud-based communication infrastructure connected to the communication infrastructure of an MNO, the device receiving a session generation request including a subscriber identifier for identifying a subscriber to the communication service, storing an ID associated with the subscriber identifier, sending a first provisioning call to a first instance and a second instance included in the equipment, the first provisioning call including the ID for generating a GTP-U session between the first instance and the second instance, receiving a source address that will be the source of the GTP-U session from the first instance or the second instance as a response to the first provisioning call, sending a second provisioning call to the first instance including the source address and a first credential for generating a VPN session between the IoT device and the first instance, and transmitting connection information including the source address and the destination address of the first instance to the IoT device that has stored the first credential or a second credential corresponding to the first credential.

[0018] Furthermore, an eighth aspect of the present invention is a method for providing a communication service for an IoT device to access an IP network using a cloud-based communication infrastructure having a first instance and a second instance during which a GTP-U session is generated, comprising the steps of: the first instance receiving a VPN packet from the IoT device that encapsulates an IP packet encrypted with credentials or temporary credentials stored in the IoT device; and the first instance obtaining credentials or temporary credentials corresponding to a source address or temporary key included in the VPN packet and decrypting the encrypted IP packet. The first instance determines the second instance by referring to the mapping between one or more source addresses and destinations of GTP sessions to which each source address is assigned, which is held by the first instance, based on the source address included in the header of the decrypted IP packet; the first instance sends a GTP packet to the second instance, with the decrypted IP packet as the GTP payload; and the second instance removes the GTP header from the GTP packet and sends the IP packet, which is the GTP payload, to an IP network outside or inside the communication infrastructure.

[0019] Furthermore, a ninth aspect of the present invention is a program for causing a cloud-based communication infrastructure, during which a GTP-U session has been generated, to perform a method for providing a communication service for an IoT device to access an IP network, the method comprising: a first instance of the communication infrastructure receiving a VPN packet from the IoT device, which encapsulates an IP packet encrypted by credentials or temporary credentials stored in the IoT device; the first instance obtaining credentials or temporary credentials corresponding to a source address or temporary key included in the VPN packet and decrypting the encrypted IP packet; the first instance determining a second instance of the communication infrastructure capable of sending IP packets to an IP network outside or inside the communication infrastructure, by referring to a mapping between one or more source addresses and destinations of GTP sessions to which each source address is assigned, which is maintained by the first instance, based on the source address included in the header of the decrypted IP packet; and the first instance sending a GTP packet to the second instance, with the decrypted IP packet as the GTP payload.

[0020] Furthermore, a tenth aspect of the present invention is a cloud-based communication infrastructure for providing a communication service for IoT devices to access an IP network, comprising a first instance and a second instance in which a GTP-U session is generated, wherein the first instance receives a VPN packet from the IoT device that encapsulates an IP packet encrypted by credentials or temporary credentials stored in the IoT device, obtains credentials or temporary credentials corresponding to the source address or temporary key contained in the VPN packet, decrypts the encrypted IP packet, the first instance determines the second instance by referring to the mapping between one or more source addresses and destinations of GTP sessions to which each source address is assigned, which is held by the first instance, based on the source address contained in the header of the decrypted IP packet, and sends a GTP packet to the second instance with the decrypted IP packet as the GTP payload, the second instance removes the GTP header from the GTP packet and sends the IP packet, which is the GTP payload, to an IP network outside or inside the communication infrastructure.

[0021] According to one aspect of the present invention, a secure connection is provided over an IP network such as the Internet via a VPN tunnel, and IoT devices can connect to a communication infrastructure that is connected to the communication infrastructure of an MNO via the secure connection, and which is capable of transmitting data to and receiving data from the IP network via a GTP tunnel, without going through a wireless access network. [Brief explanation of the drawing]

[0022] [Figure 1] This diagram schematically illustrates an MVNO (Mobile Virtual Network Operator) that provides wireless communication services by connecting its own communication infrastructure to the communication infrastructure of an MNO (Mobile Network Operator). [Figure 2]A diagram showing an apparatus for providing a communication service for accessing an IP network according to an embodiment of the present invention. [Figure 3A] A diagram showing the flow of a method for providing a communication service for accessing an IP network according to an embodiment of the present invention. [Figure 3B] A diagram showing the flow of a method for providing a communication service for accessing an IP network according to an embodiment of the present invention. [Figure 4] A diagram showing the data transmission flow in a communication service for an IoT device to access an IP network according to an embodiment of the present invention.

Embodiments for Carrying Out the Invention

[0023] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0024] FIG. 2 shows an apparatus for providing a communication service for accessing an IP network according to an embodiment of the present invention. The apparatus 200 communicates on an IP network with the MVNO communication infrastructure 220 and the IoT device 230 connected to the MNO communication infrastructure 210. Since the apparatus 200 is for establishing a connection for the IoT device 230 to access the IP network, it is also called a connection device. The MVNO communication infrastructure 220 is composed of a plurality of instances on a cloud or a public cloud.

[0025] Here, in this specification, "cloud" refers to a system that can dynamically provision and provide computing resources such as CPU, memory, storage, and network bandwidth according to demand on a network. For example, a cloud can be utilized by AWS or the like. Also, in this specification, "public cloud" refers to a cloud where a plurality of tenants can receive the provision of computing resources.

[0026] The device 200 comprises a communication unit 201 such as a communication interface, a processing unit 202 such as a processor or CPU, and a storage unit 203 including a storage device or storage medium such as memory or a hard disk, and can be configured by executing a program for each process. The device 200 may include one or more devices, computers or servers. The program may also include one or more programs and can be recorded on a computer-readable storage medium to become a non-transient program product. The program can be stored in a storage device or storage medium such as a database 204 accessible from the storage unit 203 or the device 200 via an IP network, and can be executed by the processing unit 202. The data described below as being stored in the storage unit 203 may also be stored in the database 204, and vice versa.

[0027] The device 200 can be one or more instances on a cloud or public cloud, and may be one or more instances on the same cloud as the MVNO's communication infrastructure 220. Each instance of the MVNO's communication infrastructure 220, although not shown in the diagram, can have a hardware configuration similar to that of the connection device 200.

[0028] The following sections will first explain the creation of sessions necessary for communication services, and then describe the transmission of data to the IP network using the created sessions.

[0029] Session creation Figures 3A and 3B show a flow of a method for providing a communication service for accessing an IP network according to one embodiment of the present invention. First, the device 200 receives a session generation request from the IoT device 230, which includes a subscriber identifier for identifying the subscriber of the communication service (S301). The session generation request can be transmitted via an internet communication line other than a cellular line, and for example, it may be transmitted via a fixed internet line or via a cellular line.

[0030] In Figure 2, the IoT device 230 stores a SIM identifier 231 that identifies a SIM for using a communication service to access an IP network provided via a wireless access network using the MVNO's communication infrastructure 220, as well as a subscriber identifier 232 for using a communication service to access an IP network provided without going through the wireless access network. In Figure 2, the subscriber identifier 232 is considered a virtual SIM identifier when a connection is established using it, and is therefore conveniently referred to as "V-SIM (Virtual SIM)". The IoT device 230 may also store a token for legitimately making a session creation request. The IoT device 230 does not necessarily have to store the SIM identifier 231.

[0031] The connection device 200 verifies the token included in the received session generation request as necessary, and then generates and stores an ID associated with the subscriber identifier 232 included in the session generation request (S302). It is also possible that the session generation request may be sent to the connection device 200 from a device other than the IoT device 230 that has legitimate access to the subscriber identifier 232 for the IoT device 230.

[0032] Other devices besides the IoT device 230 include, for example, a computer used by an administrator managing the IoT device 230. This administrator has access to the subscriber identifier 232 and, if granted the necessary token to make a session creation request to the connection device 200, can use that token to make a session creation request for the IoT device 230, including the subscriber identifier 232. Another example of a device other than the IoT device 230 is an authentication server capable of authenticating the IoT device 230 using the SIM identifier 231 stored in the IoT device 230 and establishing a secure connection with it. The authentication server, having received the subscriber identifier 232 from the IoT device 230 via the established secure connection, can be said to have legitimate access to the subscriber identifier 232. If the SIM identified by the SIM identifier 231 is issued by a carrier having a communication infrastructure 220 connected to the MNO's communication infrastructure 210, the authentication server can be one or more instances included in the equipment of the communication infrastructure 220.

[0033] Next, the connection device 200 selects a first instance and a second instance of the communication infrastructure 220 (S303), and sends a provisioning call to the second instance to generate a GTP-U session between the first instance and the second instance (S304). This provisioning call may include the ID stored in the connection device 200 and a first destination address such as the IP address or hostname of the first instance selected by the connection device 200.

[0034] The first instance may be selected from the first group of nodes, and the second instance may be selected from the second group of nodes. Each instance may include multiple servers, and the server from which each instance receives data and the server from which it transmits data may be different. When the MVNO's communication infrastructure 220 provides IoT devices 230 with access to an IP network via a wireless access network, a first server selected from the first group of servers connected to the MNO's communication infrastructure 210 and a second server selected from the second group of servers connected to the first server are used. At least a portion of the second group of nodes may be identical to at least a portion of the second group of servers.

[0035] The second instance sends a response to the provisioning call for the second instance to the connection device 200 (S305). The second instance then enters a listening state for GTP-U sessions (S306). The response may include the ID and a source address, such as the IP address that will be the source of the GTP-U session, and the source address can be adopted by the second instance. Here, it is described as entering a listening state after sending the response, but this order may be reversed. The source address may be assigned by the connection device 200 rather than by the second instance. In this case, the source address may be included in the provisioning call to the second instance. In any case, the second instance can store the source address in association with the ID. The device 200 can also store the source address in association with the subscriber identifier 232.

[0036] Next, the connection device 200 sends a provisioning call to the first instance to generate a GTP-U session between the first instance and the second instance (S307). This provisioning call may include the ID stored in the connection device 200, the source address, and the second destination address of the second instance adopted by the connection device 200.

[0037] Subsequently, the first instance enters a state of listening for GTP-U sessions (S308). At this point, a GTP-U session is established between the first instance and the second instance, and a so-called GTP tunnel is established. The connection device 200 receives a response to the provisioning call to the first instance (S309). The first instance may enter a listening state after sending the response, but it is preferable to send the response after entering the listening state to avoid any period of time when the connection is unavailable.

[0038] The connection device 200 then sends a provisioning call to the first instance to generate a VPN session between the IoT device 230 and the first instance (S310). This provisioning call includes the source address and the credentials associated with the IoT device 230. These credentials may be stored in the database 204 in association with the subscriber identifier 232, or they may be included in the session generation request from the IoT device 230.

[0039] The credentials in question can be, for example, a public key. In this case, the IoT device 230 stores the private key corresponding to the public key. The VPN session may use an encryption method other than public key encryption, and more generally, the necessary first credentials according to the encryption method are sent to the first instance, and the first credentials or a corresponding second credentials are stored in the IoT device 230.

[0040] After receiving a provisioning call to create a VPN session, the first instance stores the source address and credentials and enters a VPN session listening state (S311). The connection device 200 also receives a response to the provisioning call from the first instance (S312). In one example, the response may include the source address and the first destination address of the first instance. The first instance may enter a listening state after sending the response, but it is preferable to send the response after entering the listening state to avoid any period of downtime.

[0041] Upon receiving the response, the connecting device 200 sends connection information to the IoT device 230, adding a port number as necessary to the source address and the first destination address included in the response (S313). If the response from the first instance includes a port number, the receiving connection information should be sent to the IoT device 230. Based on this connection information, the IoT device 230 performs device provisioning and attempts to connect to the first instance (S314). Here, there may be an intermediary device between the IoT device 230 and the first instance. If the first instance sends a success response to the IoT device 230 (S315), the handshake is successful and the VPN tunnel is established. Depending on whether the first instance has received the attempt, sent a success response to the attempt, or more generally after receiving the attempt, the first instance may enter a GTP-U session listening state and the GTP tunnel may be established.

[0042] The first instance may, after sending the success response, notify the connection device 200 that it has gone online, that is, that a connection for communication using subscriber identifier 232 has been established (S316). Upon receiving such notification, the connection device 200 may, for example, transmit online display information to the IoT device 230, or to a device other than the IoT device 230, such as a computer used by an administrator managing the IoT device 230, to indicate that communication using subscriber identifier 232 is possible (S317). Here, the connection device 200 may, upon receiving the response that the attempt was successful, determine and store that subscriber identifier 232 has gone online. The first instance may also determine whether a predetermined period has elapsed (S318), and if so, notify the connection device 200 that it has gone offline, that is, that the connection for communication using subscriber identifier 232 has been lost (S319). Upon receiving such notification, the connecting device 200 may, for example, transmit offline display information indicating that communication using subscriber identifier 232 is not possible, or to a device other than the IoT device 230, such as a computer used by an administrator managing the IoT device 230 (S320). How to define the starting point and duration of the above-mentioned predetermined period for checking the status of the VPN tunnel may be determined according to the specific specifications of the VPN technology. For example, the starting point may be the time when the VPN tunnel is disconnected.

[0043] In the above explanation, a provisioning call was made to the second instance and then to the first instance when establishing the GTP tunnel, but an implementation in the reverse order is also possible. More generally, a first provisioning call to generate a GTP-U session between the first instance and the second instance is sent to the equipment of the cloud-based communication infrastructure 220 connected to the MNO's communication infrastructure 210, putting the first and second instances into a listening state, and it is sufficient to receive the source address of the GTP-U session from either the first or the second instance.

[0044] If a session creation request is sent to the connecting device 200 from a device other than the IoT device 230, the response to that request is sent to the device other than the IoT device 230. If a secure connection is established between the device other than the IoT device 230 and the IoT device 230, connection information can be sent to the IoT device 230 through that secure connection to perform device provisioning. Therefore, it can be said that connection information is sent from the connecting device 200 to the IoT device 230.

[0045] Furthermore, during the handshake, temporary credentials may be generated using the credentials stored in the first instance or the corresponding credentials, and stored in the first instance. In this case, the first instance associates the temporary credentials with the source address. Similarly, temporary credentials are also stored in the IoT device 230. In addition, for example, a temporary key may be generated during the initial handshake, and in addition to associating the key with the source address in the first instance, the temporary credentials may also be associated with the key.

[0046] Sending and receiving data Figure 4 shows the data transmission flow in a communication service for accessing an IP network according to the first embodiment of the present invention.

[0047] First, IoT device 230 encapsulates an IP packet encrypted with credentials or temporary credentials stored in IoT device 230 into a VPN packet and sends it to the first instance (S401). The VPN packet includes the encrypted IP packet and VPN session information relating to the VPN session. The VPN session information includes the source address or a temporary key associated therewith. Here, there may be an intermediary device between IoT device 230 and the first instance.

[0048] The first instance that receives the VPN packet attempts to decrypt the encrypted IP packet by obtaining credentials or temporary credentials corresponding to the source address or temporary key associated therewith included in the VPN session information (S402).

[0049] During the device provisioning process for session generation, routing information may be configured on the IoT device 230. More specifically, the IoT device 230 may determine whether or not to pass encrypted IP packets sent from the IoT device 230 through the VPN tunnel based on the destination address after the GTP tunnel termination.

[0050] Next, the first instance determines the second instance to which the data will be sent, by referring to the mapping between one or more source addresses held by the first instance and the destinations of the GTP sessions to which each source address is assigned, based on the source address included in the header of the decrypted IP packet (S403). The first instance then sends a GTP packet to the determined second instance, with the decrypted IP packet as the GTP payload (S404). This terminates the VPN tunnel. Each instance may include multiple servers, and the server from which each instance receives data and the server from which it sends data may be different.

[0051] In the second instance, the GTP header is removed from the received GTP packet, and the IP packet, which is the GTP payload, is sent to an IP network outside or inside the MVNO's communication infrastructure 220 (S405). The GTP header contains an ID, and the second instance can identify the source address by referring to the association between the ID and the source address stored in the second instance, and can also transitively identify the subscriber identifier by referring to the association between the source address and the subscriber identifier stored in the device 200.

[0052] In this way, a secure connection is provided over an IP network such as the internet via a VPN tunnel, allowing the IoT device 230 to connect to the MVNO's communication infrastructure 220, which performs data communication using the GTP protocol, via the IP network without going through a wireless access network.

[0053] Figure 4 illustrates data transmission, but the MVNO's communication infrastructure 220 receives data from the IP network as follows: When an IP packet destined for IoT device 230 arrives at the second instance, it identifies the GTP-U session corresponding to the address of the destination IoT device 230, adds a GTP header to the IP packet, and sends it to the first instance. The first instance then removes the GTP header from the received GTP packet to obtain an IP packet destined for IoT device 230. It identifies the corresponding VPN session from the destination address of the IP packet, encapsulates the IP packet in a VPN packet using credentials or temporary credentials corresponding to the temporary key associated with the VPN session, and sends it to IoT device 230 via the VPN tunnel. IoT device 230 obtains credentials or temporary credentials corresponding to the temporary key associated with the received VPN packet based on the VPN session information, decrypts the encrypted IP packet, and processes the IP packet.

[0054] A device other than the IoT device 230 that has legitimate access to the subscriber identifier 232, such as a computer used by an administrator managing the IoT device 230, may send a VPN session invalidation request to the connection device 200, which is determined by the source address associated with the subscriber identifier 232 or the corresponding key. In this case, the connection device 200, upon receiving the invalidation request, requests the first instance to discard or invalidate the credentials or temporary credentials corresponding to the source address or the associated key, and updates the stored billing status associated with the subscriber identifier 232 in response to the invalidation of the VPN session. [Explanation of Symbols]

[0055] 200 equipment 201 Communications Department 202 Processing Unit 203 Storage section 204 Databases 210 MNOs' telecommunications infrastructure 220 MNOs' communication infrastructure connected communication infrastructure

Claims

1. A method for providing IoT devices with communication services to access an IP network, using equipment provided by a communication infrastructure connected to an MNO's communication infrastructure, The steps include receiving a session creation request that includes a subscriber identifier for identifying a subscriber to the aforementioned communication service, The steps include sending a provisioning call to an instance included in the equipment, for generating a secure communication session between the IoT device and the instance, the provisioning call including a first set of credentials; The steps include sending connection information, including the destination address of the instance, to the IoT device. Includes.

2. The method according to claim 1, The aforementioned instance is the first instance, The method further includes the step of receiving a source address from the first instance or a second instance included in the facility that will be the source of a GTP-U session between the first instance and the second instance, The aforementioned connection information further includes the aforementioned source address.

3. The method according to claim 2, The aforementioned provisioning call is a second provisioning call, The aforementioned method, A step of storing an ID in association with the subscriber identifier, The process further includes the step of sending a first provisioning call to the first instance and the second instance for generating the GTP-U session, the first provisioning call including the ID, The step of receiving the source address includes receiving the source address as a response to the first provisioning call.

4. The method according to claim 3, The first provisioning call to the second instance further includes the destination address of the first instance.

5. The method according to claim 4, The response to the first provisioning call to the second instance includes the source address.

6. The method according to claim 5, After receiving the response to the first provisioning call to the second instance, the first provisioning call is sent to the first instance. The first provisioning call to the first instance further includes the source address.

7. The method according to claim 6, The first provisioning call to the first instance further includes the destination address of the second instance.

8. The method according to claim 2, The connection information includes the port number of the first instance.

9. The method according to claim 1, The IoT device stores the first credentials or a second set of credentials corresponding to the first credentials.

10. The method according to claim 9, The first credential mentioned above is a public key, The second set of credentials is the private key corresponding to the public key.

11. The method according to claim 1, The aforementioned session creation request is received from the IoT device.

12. The method according to any one of claims 2 to 8, The first instance and the second instance are instances on a cloud or public cloud.

13. A program that causes a device to execute a method for providing a communication service to an IoT device to access an IP network, using equipment provided by a communication infrastructure connected to the communication infrastructure of an MNO, wherein the method is The steps include receiving a session creation request that includes a subscriber identifier for identifying a subscriber to the aforementioned communication service, The steps include sending a provisioning call to an instance included in the equipment, for generating a secure communication session between the IoT device and the instance, the provisioning call including a first set of credentials; The steps include sending connection information, including the destination address of the instance, to the IoT device. Includes.

14. A device that provides communication services to IoT devices for accessing an IP network, using equipment provided by a communication infrastructure connected to an MNO's communication infrastructure, A session creation request is received which includes a subscriber identifier for identifying a subscriber to the aforementioned communication service. A provisioning call is sent to an instance included in the aforementioned equipment to generate a secure communication session between the IoT device and the instance, the provisioning call including a first set of credentials. The IoT device is sent connection information, including the destination address of the instance.

15. A communication infrastructure having a first instance and a second instance in which GTP-U sessions are generated during that time, and a method for providing communication services for IoT devices to access an IP network using a communication infrastructure connected to the communication infrastructure of an MNO, The first instance receives a VPN packet from the IoT device that encapsulates an IP packet encrypted with credentials or temporary credentials, The first instance obtains credentials or temporary credentials corresponding to the source address or temporary key included in the VPN packet and decrypts the encrypted IP packet, The first instance determines the second instance by referring to the association between the VPN packet and the GTP-U session, The first instance transmits a GTP packet generated based on the IP packet to the second instance. Includes.

16. The method according to claim 15, the step of determining the second instance comprising determining the second instance by referring to a mapping between one or more source addresses and destinations of GTP sessions to which each source address is assigned, which is maintained in the first instance based on the source address included in the header of the IP packet.

17. The method according to claim 15, wherein the GTP packet includes the IP packet in the GTP payload.

18. The method according to claim 15, further comprising the step of the second instance transmitting the IP packet obtained from the GTP packet to an IP network outside or inside the communication infrastructure.

19. The method according to claim 15, further comprising the second instance identifying the source address by referring to the association between an ID and a source address stored by the second instance.

20. A method according to any one of claims 15 to 19, The first instance and the second instance are instances on a cloud or public cloud.

21. A communication infrastructure having a first instance and a second instance in which GTP-U sessions are generated during that time, and a program for causing the communication infrastructure connected to the MNO's communication infrastructure to execute a method for providing communication services for IoT devices to access an IP network, wherein the method is: The first instance receives a VPN packet from the IoT device that encapsulates an IP packet encrypted with credentials or temporary credentials, The first instance obtains credentials or temporary credentials corresponding to the source address or temporary key included in the VPN packet and decrypts the encrypted IP packet, The first instance determines the second instance by referring to the association between the VPN packet and the GTP-U session, The first instance transmits a GTP packet generated based on the IP packet to the second instance. Includes.

22. A communication infrastructure connected to the communication infrastructure of an MNO, which provides communication services for IoT devices to access an IP network. During that time, there are first and second instances in which GTP-U sessions are generated, The first instance receives a VPN packet from the IoT device that encapsulates an IP packet encrypted with credentials or temporary credentials, obtains credentials or temporary credentials corresponding to the source address or temporary key contained in the VPN packet, and decrypts the encrypted IP packet. The first instance refers to the association between the VPN packet and the GTP-U session to determine the second instance and sends a GTP packet generated based on the IP packet to the second instance.

Citation Information

Patent Citations

  • Service access system and method of mobile communication network

    CN102149133A

  • Method of managing inter working for transferring multiple service sessions between a mobile network and a wireless local area network, and corresponding equipment

    US20090323635A1

  • Communication system, communication apparatus, communication method, terminal, and program

    WO2017022791A1

  • Control apparatus for gateway in mobile communication system

    WO2017056201A1