Data transmission method and apparatus, and computer-readable storage medium
By using the same first parameter to transmit data in the wireless link between the terminal and the network, the data transmission failure problem caused by wireless link instability is solved, redundant transmission at the air port is realized, the reliability and success rate of data transmission is improved, and fiber optical resources are saved.
Patent Information
- Application Number
- PCT/CN2024/129607
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-03
- Filing Date
- 2024-11-04
- Publication Date
- 2025-05-08
AI Technical Summary
When the wireless link between the terminal and the network is unstable, the data transmission failure will affect the communication quality of the communication system. The end-to-end redundant transmission scheme adds unnecessary fiber resources, resulting in waste of resources.
By obtaining the first parameter associated with the first session, including the first security parameter and/or the first Internet protocol IP address, it is ensured that the terminals associated with the first session use the same parameters to transmit data, and redundant transmission of the air port is realized.
It improves the reliability and success rate of data transmission, saves fiber resources, and reduces the deployment cost of communication systems.
Smart Images

Figure CN2024129607_08052025_PF_FP_ABST
Abstract
Description
Data transmission method and device, and computer-readable storage medium
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 3, 2023, with application number 202311460290.3 and invention name “Data transmission method and device, computer-readable storage medium”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a data transmission method and device, and a computer-readable storage medium. Background Art
[0003] During wireless communication between a terminal and the network, if the wireless link between the two is unstable, data transmission may fail. If the data sent by the terminal is important, if data transmission fails due to an unstable link, the communication quality of the entire communication system will be seriously damaged. For example, in an IoT-based sensor data transmission scenario, the data collected by the sensor is transmitted to the network via a wireless link through the terminal, and then transmitted from the network to an external network (for example, a third-party server or operator server) that uses the sensor data. If the wireless link between the terminal and the network is unstable and the sensor data cannot successfully reach the external network, it will affect the normal use of the sensor data by the external network.
[0004] One existing solution is to implement end-to-end redundant transmission. This involves establishing two completely independent transmission links between the transmitting end (e.g., a terminal) and the receiving end (e.g., an external network), each of which consists of an air interface transmission segment and a fiber transmission segment. While this solution improves the success rate of data reaching the external network through redundant transmission, in practice, data transmission failures are often caused by unstable wireless links in the air interface transmission segment. This existing end-to-end redundant transmission solution also adds unnecessary fiber resources, resulting in significant resource waste.
[0005] Summary of the Invention
[0006] The technical problem solved by this application is how to allow multiple terminals to transmit the same data to achieve redundant transmission on the air interface.
[0007] To solve the above technical problems, an embodiment of the present application provides a data transmission method, including: obtaining a first parameter associated with a first session, the first parameter including a first security parameter and / or a first Internet Protocol (IP) address, and the first session being associated with a first service; using the first parameter to transmit data of the first service through the first session; wherein all terminals associated with the first session use the first parameter to transmit the data.
[0008] Optionally, the first parameter is preconfigured.
[0009] Optionally, the data transmission method further includes: sending first information, where the first information is used to request acquisition of the first parameter; and acquiring the first parameter associated with the first session includes: receiving the first parameter associated with the first session.
[0010] Optionally, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0011] Optionally, the first information is carried via a non-access layer message or an access layer message.
[0012] Optionally, transmitting the data of the first service through the first session using the first parameter includes: processing the data using the first security parameter, and transmitting the processed data as an Ethernet data packet.
[0013] Optionally, transmitting the data of the first service through the first session using the first parameter includes: processing the data using the first security parameter and transmitting the data using the first IP address.
[0014] Optionally, obtaining the first parameter associated with the first session includes: receiving a first message, where the first message includes the first parameter associated with the first session.
[0015] Optionally, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0016] Optionally, the first message is carried by a non-access layer message or an access layer message.
[0017] Optionally, the non-access layer message includes a session management message and / or a mobility management message.
[0018] Optionally, the first parameter multiplexes the second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service.
[0019] Optionally, the action of processing the data using the first security parameter is performed at the service layer, or the action of processing the data using the first security parameter is performed at the protocol layer.
[0020] Optionally, the data transmission method further includes: sending a second message, where the second message is used to request allocation of resources for the first session.
[0021] To solve the above technical problems, an embodiment of the present application also provides a data transmission method, including: receiving data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, the first parameters include a first security parameter and / or a first IP address; merging the received data and transmitting it to the next node.
[0022] Optionally, the next node includes a core network.
[0023] Optionally, the merging the received data and transmitting it to the next node includes: directly merging the received data and transmitting it to the next node.
[0024] Optionally, the first security parameter is a third security parameter, the third security parameter does not reuse the second security parameter of the terminal related to the first session, and the second security parameter is associated with services other than the first service.
[0025] Optionally, the data transmission method further includes: obtaining the first security parameter from a core network.
[0026] Optionally, the merging of the received data and transmitting it to the next node includes: deprocessing the data using the first security parameter and merging to obtain deprocessed data; and transmitting the deprocessed data to the next node.
[0027] Optionally, the action of processing the data using the first security parameter solution is performed at the business layer.
[0028] Optionally, the first security parameter multiplexes a second security parameter of a terminal related to the first session, and the second security parameter is associated with services other than the first service.
[0029] Optionally, the merging of the received data and transmitting it to the next node includes: deprocessing the data using the first security parameter and merging to obtain deprocessed data; and transmitting the deprocessed data to the next node.
[0030] Optionally, the action of processing the data using the first security parameter solution is performed at the protocol layer.
[0031] Optionally, the data transmission method also includes: receiving a third message from the core network, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; sending a fourth message, the fourth message including the second security parameter of the target terminal, and the first security parameter multiplexing the second security parameter of the target terminal.
[0032] Optionally, the first IP address reuses the second IP address of a terminal related to the first session, or the first IP address is a third IP address, the third IP address does not reuse the second IP address of the terminal related to the first session, and the second IP address is associated with a service other than the first service.
[0033] To solve the above technical problems, an embodiment of the present application also provides a data transmission method, including: sending a first parameter associated with a first session, the first parameter including a first security parameter and / or a first IP address, and the first session being associated with a first service; receiving data of the first service transmitted by an access network, the data being transmitted through the first session; wherein all network elements related to the first session use the first parameter to transmit the data.
[0034] Optionally, the data transmission method further includes: receiving first information, where the first information is used to request acquisition of the first parameter.
[0035] Optionally, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0036] Optionally, the first information is carried via a non-access layer message or an access layer message.
[0037] Optionally, the data includes at least one of the following: Ethernet data packet; IP data packet.
[0038] Optionally, sending the first parameter associated with the first session includes: sending a first message, where the first message includes the first parameter associated with the first session.
[0039] Optionally, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0040] Optionally, the first message is carried by a non-access layer message or an access layer message.
[0041] Optionally, the non-access layer message includes a session management message and / or a mobility management message.
[0042] Optionally, the first parameter multiplexes the second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service.
[0043] Optionally, the data transmission method further includes: processing the data using the first security parameter solution.
[0044] Optionally, the data received from the access network is data processed using the first security parameter solution.
[0045] Optionally, the data transmission method further includes: receiving a second message, where the second message is used to request allocation of resources for the first session; and configuring the resources.
[0046] Optionally, the data transmission method also includes: sending a third message, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; receiving a fourth message, the fourth message including the second security parameter of the target terminal, and the first parameter multiplexing the second security parameter.
[0047] Optionally, the first parameter is preconfigured.
[0048] Optionally, the first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
[0049] Optionally, the first network element includes: a first service management function network element, integrated in the signaling plane of the core network; and / or a first service transmission function network element, integrated in the data plane of the core network.
[0050] Optionally, the first network element is provided with a public interface for providing capability information and / or service information of the first service, and / or receiving demand information of the first service.
[0051] To solve the above technical problems, an embodiment of the present application also provides a data transmission device, including: an acquisition module, used to obtain a first parameter associated with a first session, the first parameter including a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module, used to use the first parameter to transmit data of the first service through the first session; wherein, all terminals related to the first session use the first parameter to transmit the data.
[0052] To solve the above technical problems, an embodiment of the present application also provides a data transmission device, including: a receiving module, used to receive data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, the first parameters include a first security parameter and / or a first IP address; a transmission module, used to merge the received data and transmit it to the next node.
[0053] To solve the above technical problems, an embodiment of the present application also provides a data transmission device, including: a sending module, used to send a first parameter associated with a first session, the first parameter includes a first security parameter and / or a first IP address, and the first session is associated with a first service; a receiving module, used to receive data of the first service transmitted by an access network, and the data is transmitted through the first session; wherein, network elements related to the first session all use the first parameter to transmit the data.
[0054] To solve the above technical problems, an embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the above method are executed.
[0055] To solve the above technical problems, an embodiment of the present application also provides a data transmission device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and the processor executes the steps of the above method when running the computer program.
[0056] To solve the above technical problems, an embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is run on a computer, the computer executes the steps of the above method.
[0057] In order to solve the above technical problems, an embodiment of the present application also provides a communication system, including a core network element, a network device and a terminal for executing the above method.
[0058] In order to solve the above technical problems, an embodiment of the present application further provides a chip (or a data transmission device) on which a computer program is stored. When the computer program is executed by the chip, the steps of the above method are implemented.
[0059] Compared with the prior art, the technical solution of the embodiment of the present application has the following beneficial effects:
[0060] Compared to existing technologies that make it difficult for different terminals to transmit the same data, this embodiment ensures that different terminals can send the same data when transmitting data by ensuring that the terminals participating in the first session use the same first parameter. This creates redundant transmission at the air interface, thereby improving data transmission reliability and success rate.
[0061] Furthermore, compared to existing end-to-end redundant transmission solutions, the communication system using this implementation ensures data transmission reliability through redundant transmission at the air interface. After the redundantly transmitted data is successfully received by the access network, it can be reused over the same optical fiber for further transmission. This saves optical fiber resources and helps reduce the deployment cost of the communication system. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] FIG1 is a signaling interaction diagram of a data transmission method provided in an embodiment of the present application;
[0063] FIG2 is a schematic diagram of a communication system protocol stack provided in an embodiment of the present application;
[0064] FIG3 is a schematic diagram of another communication system protocol stack provided in an embodiment of the present application;
[0065] FIG4 is a schematic diagram of another communication system protocol stack provided in an embodiment of the present application;
[0066] 5 is a schematic diagram of the service layer security architecture of a communication system in a first typical application scenario of the present invention;
[0067] FIG6 is a diagram of service layer signaling interaction in the application scenario shown in FIG5 ;
[0068] 7 is a schematic diagram of the service layer security architecture of the communication system in the second typical application scenario of the present invention;
[0069] FIG8 is a diagram of service layer signaling interaction in the application scenario shown in FIG7 ;
[0070] FIG9 is a schematic structural diagram of a data transmission device provided in an embodiment of the present application;
[0071] FIG10 is a schematic structural diagram of another data transmission device provided in an embodiment of the present application;
[0072] FIG11 is a schematic structural diagram of another data transmission device provided in an embodiment of the present application;
[0073] FIG12 is a schematic structural diagram of another data transmission device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0074] The methods provided in the embodiments of this application involve a core network, an access network, and a terminal. The core network and the access network can be collectively referred to as the network side (referred to as the network). The terminal and network devices (e.g., network devices in the access network) perform uplink and downlink signal transmission. Furthermore, data transmitted from the terminal to the core network via the access network is further transmitted to an external network via the core network.
[0075] The terminal in the embodiments of the present application is a device with wireless communication capabilities, which can be referred to as terminal equipment, user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal equipment, vehicle-mounted terminal equipment, industrial control terminal equipment, UE unit, UE station, mobile station, remote station, remote terminal equipment, mobile device, UE terminal equipment, wireless communication equipment, UE agent or UE device, etc. The terminal can be fixed or mobile. It should be noted that the terminal can support at least one wireless communication technology, such as Long Term Evolution (LTE) and New Radio (NR). For example, the terminal may be a mobile phone, a tablet computer, a desktop computer, a laptop computer, an all-in-one computer, an in-vehicle terminal, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a wearable device, a terminal device in a future mobile communication network, or a terminal device in a future evolved public mobile land network (PLMN), etc. In some embodiments of the present application, the terminal may also be a device with transceiver functions, such as a chip system, wherein the chip system may include a chip and may also include other discrete devices.
[0076] The access network of the embodiment of the present application may be, for example, a 5G access network (NG-RAN). The network device of the embodiment of the present application is a device that provides wireless communication functions for UE, and may also be referred to as an access network device, a radio access network (RAN) device, or an access network element. The network device may support at least one wireless communication technology, such as LTE, NR, etc. For example, the network device includes, but is not limited to: a next-generation base station (gNB), an evolved node B (eNB), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (e.g., home evolved node B, or home node B, HNB), a baseband unit (BBU), a transmitting and receiving point (TRP), a transmitting point (TP), a mobile switching center, etc. in the fifth-generation mobile communication system (5G). The network device may also be a wireless controller, a centralized unit (CU), and / or a distributed unit (DU) in a cloud radio access network (CRAN) scenario, or an access network device, and may be a relay station, an access point, a vehicle-mounted device, a terminal device, a wearable device, a network device in future mobile communications, or a network device in a future evolved PLMN. In some embodiments, the network device may also be a device that provides wireless communication functions for a terminal, such as a chip system. For example, the chip system may include a chip and may also include other discrete devices.
[0077] The core network (CN) of the embodiment of the present application is composed of core network elements. Among them, the core network elements can also be called core network devices, which are network elements deployed in the core network, such as core network control plane elements or core network user plane elements. The core network of the embodiment of the present application can be an evolved packet core network (EPC), a 5G core network (5G Core Network), or a new core network in a future communication system. For example, the 5G core network is composed of a group of network elements and implements access and mobility management functions (AMF) that implement functions such as mobility management, user plane functions (UPF) that provide functions such as packet routing and QoS (Quality of Service) management, and session management functions (SMF) that provide functions such as session management, IP address allocation and management. The EPC can be composed of a mobility management entity (MME) that provides functions such as mobility management and gateway selection, a serving gateway (S-GW) that provides functions such as packet forwarding, and a PDN gateway (P-GW) that provides functions such as terminal address allocation and rate control. For Multicast Broadcast Service (MBS), the core network can include several new network elements to implement functions such as packet forwarding, MBS conference management, QoS management, and transmission mode switching (switching between unicast and multicast / broadcast transmission modes). Alternatively, these functions can be implemented by existing core network elements.
[0078] The external network in the embodiments of the present application may also be referred to as an external data network (DNN). Specifically, it refers to a device that accesses the network constructed by the core network and access network to transmit data with the terminal. The external network may, for example, include a server that provides AF / AS. AF stands for Application Function, which refers to various application layer services. It can be an internal operator application such as voice AF or a third-party AF (such as a video server or game server). AS stands for Access Stratum.
[0079] As mentioned in the background, existing technologies typically employ end-to-end redundant transmission to improve data transmission reliability. For example, a transmission link might consist of sensor-terminal 1-access network 1-core network 1-external network, while a completely independent transmission link might consist of sensor-terminal 2-access network 2-core network 2-external network. However, these two completely independent transmission links waste fiber resources between the access network and the core network.
[0080] After analysis, the inventors of this application found that one of the reasons for the above-mentioned problem is that in the prior art, when different terminals perform uplink transmission, it is difficult to generate the same uplink data packet to transmit to the same node, resulting in the inability of the prior art to achieve air interface redundancy. Specifically, in the prior art, different terminals use different Internet Protocol (IP) headers when conducting conversations, and the generated IP packets are also different. In addition, the encryption keys used by different terminals are also different. This results in that even if two terminals receive the same data, the data packets generated after each terminal's internal processing are different, and thus the data (in this embodiment, specifically referring to the aforementioned data packets generated by each terminal's respective processing) ultimately transmitted by the two terminals to the next node (for example, the access network on the network side) are different. If you want to achieve redundant transmission on the air interface end, you must ensure that different terminals transmit the same data, which is obviously impossible to achieve with the prior art.
[0081] To solve the above technical problems, an embodiment of the present application provides a data transmission method, wherein the core network sends a first parameter associated with a first session, and accordingly, the terminal receives the first parameter, the first parameter including a first security parameter and / or a first IP address, and the first session is associated with a first service; the terminal uses the first parameter to transmit data of the first service through the first session, and accordingly, the access network receives the data transmitted by one or more terminals through the first session; the access network merges the received data and transmits it to the next node, and accordingly, the core network directly or indirectly receives the data transmitted by the access network; wherein, the terminals and network elements related to the first session all use the first parameter to transmit the data.
[0082] This embodiment ensures that different terminals can transmit the same data using the same first parameter, ensuring that all participating terminals can transmit the same data. This creates redundant transmission at the air interface, improving data transmission reliability and success rate. Furthermore, after the redundantly transmitted data is successfully received by the access network, it can be reused over the same optical fiber for further transmission. This conserves optical fiber resources and helps reduce the deployment cost of the communication system.
[0083] The first service in this embodiment of the present application refers to an uplink convergence service (or an uplink transmission service performed in a converged manner), or a service with the same or similar characteristics defined in a future protocol. The characteristics (also referred to as features) of the first service include: n (n is greater than or equal to 1) terminals transmitting the same user plane data (hereinafter referred to as data), for example, simultaneously transmitting the same uplink user plane data. In this embodiment of the present application, the same data may refer to the same data packet, i.e., every bit in the data packets transmitted by the n terminals is identical.
[0084] Taking the power grid data transmission scenario as an example, the data collected by the power grid sensors needs to be transmitted to the network data server via the terminal. To avoid the unreliability of a single terminal (for example, data loss / damage), this implementation scheme uses n (for example, n=2) terminals to transmit the data collected by the same sensor. These two terminals transmit the same received data to the access network respectively. Once the access network successfully receives the data sent by any of the terminals, it will continue to transmit it to the next node until the data is successfully transmitted to the network data server as the external network. In the example of n=2, assuming that the two terminals are terminal 1 and terminal 2, terminal 2 can be regarded as a clone of terminal 1.
[0085] The first session in the embodiment of the present application is associated with the first service, specifically a session established for performing the first service, and the first session is associated with a unique identifier (for example, a session ID). The first session may also be referred to as an uplink convergence session. In some embodiments, the first session may be associated with n terminals, that is, n terminals transmit data of the first service to the network through the same first session. For example, the terminals associated with the same first session are respectively configured with the same session ID, and the n terminals configured with the same session ID use the same first parameter to send the same data on the same user plane. Furthermore, the n terminals obtain the same data to be transmitted from the same sending end, where the sending end may be, for example, a sensor.
[0086] In some embodiments, n terminals associated with the same first session (e.g., the same first session identifier) may form a user group, where the user group is uniquely associated with a group identifier. Each terminal may be associated with multiple group identifiers, where each group identifier is associated with a corresponding first session. Thus, the terminal may carry out multiple first services in parallel.
[0087] The second session in the embodiment of the present application refers to a session established for performing services other than the first service, and the second session is associated with a unique identifier. The second session can be, for example, a protocol data unit (PDU) session (PUD session), or can be, for example, a 4G-PDN (4G-Public Data Network). In some embodiments, the second session can correspond one-to-one with the terminal, that is, each network accessing the network establishes its own second session and transmits data for services other than the first service to the network through its associated second session.
[0088] Furthermore, during the process of establishing the second session, or after the second session is established, the terminal may establish the first session with the network.
[0089] In the embodiments of the present application, the first parameter may refer to a parameter used when transmitting data of the first service through the first session. Terminals and network elements (including core network elements and access network elements) associated with the first session all use the same first parameter to transmit the same data. In actual application scenarios, one or more terminals may be unable to transmit data due to unexpected factors such as failures. In this case, at least one of the n terminals associated with the first session transmits data using the same first parameter.
[0090] In some embodiments, the first parameter may include a first security parameter and / or a first IP address. The first security parameter may include user-plane security parameters, keys and algorithms, encryption keys, integrity protection keys, encryption algorithms, and integrity protection algorithms. During the first session establishment process, the first security parameter is generated for use by the terminal. When the terminal transmits user-plane data through the first session, the first security parameter is used to protect the user-plane data, such as by encryption and integrity protection. The first IP address may include a source IP address. During the first session establishment process, the network assigns the terminal a first IP address for use. The source IP address of IP packets sent by the terminal to the network through the first session uses the first IP address.
[0091] The second parameter of the embodiment of the present application may refer to a parameter used when transmitting data of a service other than the first service through a second session. Specifically, the second parameter may include a second security parameter and / or a second IP address. The second security parameter may include a secret key, a security algorithm, etc., and the second security parameter used by the terminal is generated in the process of the terminal accessing the network. When the terminal transmits data of a service other than the first service through the second session, the second security parameter is used to protect the user plane data, such as encryption and integrity protection. The second IP address may include a source IP address. During the process of establishing the second session, the network assigns the terminal a second IP address to be used by the terminal, and the source IP address of the IP data packet sent by the terminal to the network through the second session uses the second IP address.
[0092] In some embodiments, the first parameter may reuse the second parameter of a terminal associated with the first session. Specifically, when configuring the first parameter for n terminals associated with the first session, the network may select a second parameter already configured for one of the n terminals and determine the second parameter of the selected terminal as the first parameter shared by the n terminals. In this embodiment of the present application, the terminal among the n terminals that has the second parameter reused is referred to as the target terminal.
[0093] In some embodiments, the first parameter may be a third parameter, and the third parameter does not reuse the second parameter of the terminal associated with the first session. The third parameter in the embodiment of the present application may refer to a new parameter configured specifically for the n terminals for the first service associated with the first session, and the new parameter is different from the second parameter that has been configured for each of the n terminals.
[0094] For example, the first security parameter may reuse the second security parameter of a terminal associated with the first session. Alternatively, the first IP address may reuse the second IP address of a terminal associated with the first session. Alternatively, both the first security parameter and the first IP address may reuse the second security parameter and the second IP address of a terminal associated with the first session. The second security parameter reused by the first security parameter and the second IP address reused by the first IP address may be associated with the same or different terminals.
[0095] For another example, the first security parameter may be the third security parameter, meaning the second security parameter of the terminal associated with the first session is not reused. Alternatively, the first IP address may be the third IP address, meaning the second IP address of the terminal associated with the first session is not reused. Alternatively, the first security parameter may be the third security parameter, and the first IP address may be the third IP address.
[0096] For another example, the first security parameter may reuse the second security parameter of a terminal associated with the first session, and the first IP address may be the third IP address. Alternatively, the first security parameter may be the third security parameter, and the first IP address may reuse the second IP address of a terminal associated with the first session.
[0097] In order to make the above-mentioned objectives, features and beneficial effects of the present application more obvious and easy to understand, the specific embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0098] FIG1 is a signaling interaction diagram of a data transmission method provided in an embodiment of the present application.
[0099] In a specific implementation, in the data transmission method provided in the following steps (abbreviated as S) 100 to S107, the actions performed by the terminal can be performed by a chip with data transmission capabilities in the terminal, or by a baseband chip in the terminal. The actions performed by the access network can be performed by a chip with data transmission capabilities in a network device, or by a baseband chip in the network device. The actions performed by the core network can be performed by a chip with data transmission capabilities in a core network element, or by a baseband chip in a core network element.
[0100] Specifically, referring to FIG1 , the data transmission method according to this embodiment may include the following steps:
[0101] S101: A core network sends a first parameter associated with a first session to a terminal. Correspondingly, the terminal receives the first parameter from the core network.
[0102] In some embodiments, the core network sends the first parameter to the terminal through the access network.
[0103] In a specific implementation, the core network may actively send the first parameter to the terminal to trigger the terminal to execute the first service.
[0104] In one specific implementation, the first parameter may be preconfigured. For example, it may be preconfigured in a mobile equipment (ME) unit or a universal subscriber identity module (USIM) of the terminal. In this example, the core network action in S101 may be omitted, and the terminal may directly obtain the first parameter from its own ME or USIM.
[0105] In a specific implementation, the following steps may be included before S101: S100: The terminal sends first information to the core network, where the first information is used to request to obtain the first parameter. Correspondingly, the core network receives the first information from the terminal.
[0106] Specifically, the first information may include at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; and identifier of the second session of the terminal related to the first session.
[0107] Furthermore, the first indication information can indicate to the network that the terminal sending the first information needs to execute the first service.
[0108] Furthermore, the identity of the terminal associated with the first session may be, for example, the identity of the terminal other than the terminal that sent the first message among the n terminals. Still taking n=2 as an example, when terminal 2 sends the first message, it may carry the identity of its cloned terminal 1.
[0109] In some embodiments, in a scenario where a terminal has not previously interacted with the network and signed a contract, the network does not know in advance the specific information of the n terminals associated with the first session (i.e., it is not aware that the n terminals serve as backups for each other). Therefore, any of the n terminals can carry the identities of the other n-1 terminals and / or the group identifier of the group to which these n terminals belong in the first information. Accordingly, the core network can configure the same first parameters for the n terminals indicated in the first information.
[0110] In some embodiments, in a scenario where the terminal has signed a contract with the network, the identity of the terminal related to the first session may be omitted from the first information, which is beneficial for saving signaling overhead.
[0111] Furthermore, the session information of the first session may include: information about the external network corresponding to the first service, such as the network name, network identifier, slice information, IP address, and port number of the external network.
[0112] Furthermore, the capability information may indicate whether the terminal supports or does not support a feature corresponding to the first service.
[0113] Furthermore, in S101, the core network sends a first message to the terminal, where the first message includes a first parameter. Correspondingly, the terminal receives the first message from the core network to obtain the first parameter.
[0114] In some embodiments, the first message may further include at least one of the following: second indication information indicating whether the terminal and / or network supports the first service; an identifier of the first session; a terminal type; a service type of the first service; and a session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session. The contents carried in the first message may be collectively referred to as relevant information about the first service.
[0115] Specifically, the terminal may carry its own capability information when sending the first message, and the network (e.g., the core network) may indicate whether the network has the capability of the first service through the second indication information when returning the first message. Furthermore, the first message may also indicate the capability information of other terminals related to the first session.
[0116] Furthermore, by sending the first information, the terminal can request the network to obtain information related to the first service, such as the service type of the first service, the session type of the first session, the first IP address, the first security parameter, the identity of the terminal related to the first service, the identifier of the external data network, the network slice identifier, the identifier of the first session, etc.
[0117] Furthermore, the terminal type may include a basic terminal and an auxiliary terminal, wherein the basic terminal may initiate an application for user plane resources (ie, resources used for the first session), while the auxiliary terminal does not initiate an application for user plane resources.
[0118] Furthermore, the service type may include a basic service and a supplementary service. If the first message indicates that the first service associated with the terminal is a basic service, the terminal determines that it is necessary to initiate an application for user plane resources when executing the first service. If the first message indicates that the first service associated with the terminal is a supplementary service, the terminal determines not to initiate an application for user plane resources when executing the first service.
[0119] Furthermore, the session type may include a basic session and an auxiliary session, wherein a terminal corresponding to a basic session may initiate an application for user plane resources, while a terminal corresponding to an auxiliary session does not initiate an application for user plane resources.
[0120] In some embodiments, when n terminals respectively send first information to request to jointly execute the first service, the core network can specify through the first message that a part of the n terminals initiate an application for user plane resources, and the remaining part does not initiate an application for user plane resources.
[0121] Still taking n=2 as an example, assuming that the service type indicated in the first message received by terminal 1 is a secondary service, terminal 1 does not request allocation of resources for the first session when subsequently executing the first service. assuming that the service type indicated in the first message received by terminal 2 is a basic service, terminal 2 does request allocation of resources for the first session when subsequently executing the first service. The resources requested by terminal 2 for the first session are shared by terminal 1 and terminal 2.
[0122] Assume n = 3. The first message received by Terminal 1 indicates that the terminal type is a basic terminal, while the first messages received by Terminals 2 and 3 each indicate that the terminal type is a secondary terminal. Accordingly, Terminal 1 subsequently requests allocation of resources for the first session when executing the first service, while Terminals 2 and 3 do not initiate resource requests. Terminals 1, 2, and 3 all use the user plane resources requested by Terminal 1 to transmit the same data over the first session.
[0123] In some embodiments, the terminal may request the network to allocate user plane resources, for example, using a service request message (SERVICE REQUEST).
[0124] In some embodiments, the core network may determine, among the n terminals, a terminal whose second IP address is multiplexed as the first IP address as a terminal that needs to request allocation of resources for the first session.
[0125] In one variation, the resources used for the first session may be pre-configured periodic resources. In this variation, part or all of the terminal type, service type, and session type may be omitted from the first message to save signaling overhead.
[0126] In some embodiments, the first information and / or the first message may be transmitted via an access network.
[0127] In a specific implementation, the first information may be carried by a non-access stratum (NAS) message. Similarly, the first message may be carried by a NAS message.
[0128] For example, the first message carried by the NAS message may include the following information element (IE):
[0129] 1. An indication identifier of the first service 1 feature (i.e., the first indication information or the second indication information), which is used to indicate whether the terminal or the network supports the feature corresponding to the first service. This identifier can be one or more bits, such as 0 indicating that the feature corresponding to the first service is not supported, and 1 indicating that the feature corresponding to the first service is supported;
[0130] 2. Terminal type, which can be identified by one or more bits: 0 represents a basic terminal, 1 represents an auxiliary terminal;
[0131] 3. Session type, which can be identified by one or more bits: 0 represents a basic session, and 1 represents an auxiliary session, that is, the terminal does not send a service request message (SERVICE REQUEST).
[0132] In some embodiments, NAS messages may include session management messages (5GS session management messages).
[0133] Specifically, the session management message includes stages such as establishment / modification / release of the PDU session, wherein the modification is performed after the PDU session is established, and a corresponding session management message is sent at each stage. Furthermore, the core network implementing this embodiment can receive the first information or send the first message through the session management message of the corresponding stage during or after the establishment of the second session.
[0134] For example, the session management message that can carry the first information or the first message may include at least one of the following: PDU session establishment request PDU session establishment request, PDU session establishment accept PDU session establishment reject PDU session establishment reject, PDU session authentication command PDU session authentication command, PDU session authentication completion PDU session authentication complete, PDU session authentication result PDU session authentication result, PDU session modification request PDU session modification reject PDU session modification reject, PDU session modification command PDU session modification command, PDU session modification completion PDU session modification complete, PDU session modification command reject, PDU session release request PDU session release request, PDU session release reject PDU session release command PDU session release command, PDU session release completion PDU session release complete, 5G session management status 5GSM status, service-level authentication command Service-level authentication command, service-level authentication complete Service-level authentication complete, remote UE report Remote UE report, remote UE report response Remote UE report response.
[0135] In some embodiments, NAS messages may include mobility management messages (5GS mobility management messages).
[0136] For example, the mobility management message that can carry the first information or the first message may include at least one of the following: Registration request, Registration accept, Registration complete, Registration reject, Deregistration request (UE originating), Deregistration accept (UE originating), Deregistration request (UE terminated), Deregistration accept (UE terminated), Service request, Service reject, Service accept, Control plane service request, Network slice-specific authentication command, Network slice-specific authentication complete, Network slice-specific authentication result, Configuration update command, Configuration update complete, Authentication request, Authentication response, Authentication reject, Authentication failure, Authentication result, Identity request, Identity response, Security mode command, Security mode completion mode complete, Security mode reject, 5G mobility management status 5GMM status, Notification, Notification responseresponse, UL NAS transport, DL NAS transport, Relay key request, Relay key accept, Relay key reject, Relay authentication request, and Relay authentication response.
[0137] In a specific implementation, the first information can be carried by an AS message. Similarly, the first message can be carried by an AS message.
[0138] For example, the AS message that can carry the first information or the first message may include at least one of the following: quantity statistics CounterCheck, quantity statistics response CounterCheckResponse, dedicated system information block (System Information Block, SIB for short) request DedicatedSIBRequest, downlink dedicated message segment DLDedicatedMessageSegment, downlink information transmission DLInformationTransfer, multi-access dual link (Multi-RAT Dual Connectivity, MR-DC) downlink information transmission DLInformationTransferMRDC, failure information FailureInformation, integrated access and backhaul (Integrated access and backhaul, IAB) other information IABOtherInformation, positioning measurement indication LocationMeasurementIndication, log measurement configuration LoggedMeasurementConfiguration, multicast broadcast service (Multicast Broadcast Services, MBS) broadcast configuration MBSBroadcastConfiguration, MBS interest indication MBSInterestIndication, master cell group (Master Cell Group, MCG) failure information MCGFailureInformation, measurement report MeasurementReport, application layer measurement report MeasurementReportAppLayer, master information block (Master Information Block, MIB), MobilityFromNRCommand based on NR command, Paging, Radio Resource Control (RRC),RRC (abbreviated as RRC) reconstruction RRCReestablishment, RRC reconstruction completion RRCReestablishmentComplete, RRC reconstruction request RRCReestablishmentRequest, RRC reconfiguration RRCReconfiguration, RRC reconfiguration completion RRCReconfigurationComplete, RRC rejection RRCReject, RRC release RRCRelease, RRC recovery RRCResume, RRC recovery completion RRCResumeComplete, RRC recovery request RRCResumeRequest, RRC recovery request 1 RRCResumeRequest1, RRC establishment RRCSetup, RRC establishment completion RRCSetupCompletlet, RRC establishment request RRCSetupRequest, RRC system information request RRCSystemInfoRequest, Secondary Cell Group (SCG) failure information SCGFailureInformation, E-UTRA (Evolved UMTS Terrestrial Radio Access, Evolved UMTS Terrestrial Radio Access, where UMTS is Universal Mobile Telecommunications System (UMTS) System))SCG failure information SCGFailureInformationEUTRA, security mode command SecurityModeCommand, security mode completion SecurityModeComplete, security mode failure SecurityModeFailure, system information block 1SIB1, NR auxiliary link terminal information SidelinkUEInformationNR, system informationSystemInformation, terminal assistance information UEAssistanceInformation, terminal capability inquiry UECapabilityEnquiry, terminal capability information UECapabilityInformation, terminal capability request UEInformationRequest, terminal capability response UEInformationResponse, terminal positioning assistance information UEPositioningAssistanceInfo, uplink dedicated message segment ULDedicatedMessageSegment, uplink information transmission ULInformationTransfer, inter radio access technology (Inter Radio Access Technology,IRAT) uplink information transmission ULInformationTransferIRAT, MR-DC uplink information transmission ULInformationTransferMRDC. ,
[0139] In one specific implementation, the first message may be transmitted via a container.
[0140] In one specific implementation, the first message may be transmitted using resources allocated for the first session.
[0141] In a specific implementation, still referring to FIG1 , the data transmission method of this embodiment may further include the steps of:
[0142] S102: For a terminal that is instructed to request allocation of resources for a first session, the terminal sends a second message to a core network. Correspondingly, the core network receives the second message from the terminal.
[0143] Specifically, the second message is used to request allocation of resources for the first session.
[0144] In response to receiving the second message, the core network determines whether the second message triggers resource allocation. For example, if the terminal type of the terminal sending the second message is a basic terminal, the core network determines that resources need to be allocated for the first session. For another example, if the session type carried in the second message is an auxiliary session, the core network determines not to allocate resources in response to the second message.
[0145] In some embodiments, for a terminal that is not indicated to need to request allocation of resources for the first session, S102 is an optional step.
[0146] In some embodiments, the second message may be transmitted to the core network via the access network.
[0147] In a specific implementation, still referring to FIG1 , the data transmission method of this embodiment may further include the steps of:
[0148] S103: In response to obtaining the first parameter, the terminal transmits data of the first service to the access network via the first session using the first parameter. Accordingly, the access network receives data transmitted by one or more terminals via the first session.
[0149] Specifically, S103 may be executed for each of the n terminals related to the first session.
[0150] In some embodiments, in S103, the terminal may process the data using the first security parameter and transmit the processed data as an Ethernet data packet. Specifically, in this example, the data to be transmitted received by the terminal is a Media Access Control (MAC) packet, which begins with a MAC address. Furthermore, in S103, the terminal does not use the first IP address when transmitting the Ethernet data packet, nor does it package the data into an IP data packet.
[0151] Furthermore, the action of the terminal using the first security parameter to process the Ethernet data packet may be performed at the application layer.
[0152] In some embodiments, in S103, the terminal may process data using the first security parameter and transmit the processed data using the first IP address. Specifically, in this example, the terminal packages the received data into an IP data packet and transmits it using the first IP address.
[0153] In a sensor data transmission scenario, the sensor can transmit data for a first service according to network instructions. The user routing selection policy (URSP) of the terminal's ID card that receives the data is configured with an application identifier (APP-ID) and corresponding session attributes (used to configure whether the data transmitted by the corresponding application is processed via Ethernet or IP). Accordingly, the sensor sends data packaged in the corresponding format to the terminal based on the terminal's session attributes. In response to receiving the data, the terminal executes S103 to process and transmit the data to the access network.
[0154] Furthermore, when executing S103 , the terminal determines whether to package the received data into an IP data packet or an Ethernet data packet according to the pre-configured session attributes.
[0155] In a specific implementation, still referring to FIG1 , the data transmission method of this embodiment may further include the steps of:
[0156] In step S104, in response to receiving data transmitted by one or more terminals via the first session, the access network combines the received data and transmits it to the next node. Accordingly, the next node receives the data transmitted by the access network. Figure 1 illustrates this by taking the core network as the next node for example. That is, the core network directly receives data transmitted by the access network.
[0157] In some embodiments, the next node may be, for example, another terminal, which acts as a relay node. The core network indirectly receives data transmitted by the access network through at least one relay node. In this example, when the terminal acts as a relay, the hardware processing capability similar to that of a base station may be enhanced so that the terminal, acting as a relay node, can perform actions similar to those in S104.
[0158] In some embodiments, in response to successfully receiving data of a first service transmitted by a terminal through a first session, the access network may execute S104.
[0159] In one specific implementation, the first security parameter may be a third security parameter, and the action of processing data using the first security parameter may be performed at the terminal's service layer. Furthermore, the first message sent by the core network includes the third security parameter, and the terminal and / or access network determines and uses the third security parameter as the first security parameter. The service layer may include the IP layer and application programs. The MAC layer described in this example is the MAC layer within the 3GPP scope.
[0160] Scenario 1:
[0161] In conjunction with Figures 1 and 2, the first security parameter is carried by a NAS message. In response to obtaining the first security parameter, the terminal uses the first security parameter to encrypt data at the service layer of its own protocol stack, and then transmits it layer by layer to the access network through the first session. For example, on the terminal side, the data processed by the service layer (e.g., IP layer) is transmitted to the access network via the Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP), Radio Link Control (RLC), and MAC layer in sequence.
[0162] Furthermore, the access network does not obtain or use the first security parameter. Accordingly, in S104, the access network transparently transmits the received data to the core network. For example, after receiving data transmitted by at least one terminal through the first session layer by layer via the MAC layer, the RLC layer, the PDCP layer, and the SDAP layer, the access network directly merges the received data and transmits it to the next node.
[0163] Furthermore, in response to receiving the data, the core network may de-process the data using the first security parameter. De-processing may include operations such as decryption and de-protection. For example, a newly added uplink convergence transmission function or user plane function (UPF) in the core network may perform security operations on the data using the first security parameter to obtain de-processed data.
[0164] In other words, in scenario 1, there's no need to transmit the first security parameters via RRC signaling at the PDCP layer on the terminal and access network. Instead, data is encrypted using the first security parameters directly from the terminal's IP layer to the PDCP layer. In this case, the data is transmitted directly through the access network to the core network, where it is decrypted using the first security parameters.
[0165] Furthermore, the decrypted and unprotected data can be further transmitted from the core network to the external network.
[0166] Scenario 2:
[0167] In conjunction with Figures 1 and 3, the first security parameter is carried in a NAS message. Upon receiving the first security parameter, the terminal uses the first security parameter to encrypt data at the service layer of its protocol stack, and then transmits the data layer by layer to the access network via the first session. For example, on the terminal side, data processed at the IP layer is transmitted to the access network via the SDAP layer, PDCP layer, RLC layer, and MAC layer in sequence.
[0168] Furthermore, the data transmission method described in this embodiment may further include the step of: S105, the access network obtaining the first security parameter from the core network. In some embodiments, the access network may obtain the first security parameter from the core network through other channels. For example, the access network may obtain the first security parameter through the N2 interface between the access network and the core network's AMF (Access and Mobility Management Function).
[0169] In response to obtaining the first security parameter, in S104, the access network uses the first security parameter to de-process the same data received from different terminals and merges them to obtain de-processed data, and then transmits the de-processed data to the next node, thereby improving transmission reliability.
[0170] In other words, compared to the protocol stack structure of the existing access network, the protocol stack of the access network in Scenario 2 adds a service layer (e.g., IP layer). This newly added IP layer has a decryption function. The access network decrypts the data and transmits it in plain text to the next node (e.g., the UPF of the core network). The data received by the core network from the access network is processed using the first security parameter.
[0171] Furthermore, the action of using the first security parameter to process the data may be performed at a service layer of the access network, specifically, at a newly added IP layer of the access network.
[0172] In one specific implementation, the first security parameter may reuse a second security parameter of a terminal associated with the first session, and the action of processing data using the first security parameter may be performed at a protocol layer of the terminal. Specifically, the protocol layer refers to protocols within the 3GPP scope, such as SDAP, PDCP, RLC, MAC, MM, and SM.
[0173] Specifically, in conjunction with Figures 1 and 4 , the data transmission method described in this embodiment may further include the following step: S106: The core network sends a third message to the access network. Accordingly, the access network receives the third message from the core network. The third message may include the identity of the target terminal and the identifier of the target terminal's second session. The target terminal specifically refers to the terminal among the n terminals associated with the first session that is multiplexed with the second security parameters.
[0174] Furthermore, the data transmission method of this embodiment may further include the step: S107, the access network sends a fourth message to the core network. In response, the core network receives the fourth message sent by the access network. The fourth message may include the second security parameter of the target terminal.
[0175] In response to acquiring the second security parameter of the multiplexed target terminal, the core network determines the second security parameter as the first security parameter, and sends the first security parameter to the terminal via an AS message by executing S101.
[0176] For example, in S101, the core network sends the first security parameter to the access network through RRC signaling, and the access network obtains and sends the first security parameter to the terminal through the PDCP layer using RRC signaling.
[0177] Further, in S103, the terminal uses the first security parameter to encrypt data at the PDCP layer and transmits the data to the access network layer by layer.
[0178] Furthermore, in S104, the access network uses the first security parameter to process and combine the same data received from different terminals at the protocol layer, and then transmits it in plain text to the next node. For example, the action of processing the data using the first security parameter can be performed at the PDCP layer of the access network.
[0179] Furthermore, the data received by the core network from the access network is data processed using the first security parameter solution.
[0180] As described above, this implementation ensures data transmission reliability through redundant transmission at the air interface. Once the redundantly transmitted data is successfully received by the access network, it can be reused over the same fiber for further transmission. This conserves fiber resources and helps reduce the deployment cost of the communication system.
[0181] In the first typical application scenario (denoted as application scenario 1), the communication system may include a terminal, an access network, a core network and an external network. Figure 5 exemplifies the security architecture of each network component at the service layer, wherein the terminal includes UE1 and UE2, the access network includes NG-RAN, the core network includes AMF network element, SMF network element, first network element and UPF network element, and the external network includes AF / AS server.
[0182] Specifically, the AMF network element is used to provide AMF, the SMF network element is used to provide SMF, and the UPF network element is used to provide UPF.
[0183] Furthermore, compared to the existing core network, the core network of the embodiment of the present application adds a first network element for processing the first service. For example, the first parameter can be configured by the first network element. In some embodiments, the first network element may include a first service management function network element for providing the first service management function. In some embodiments, the first network element may include a first service transmission function network element for providing the first service transmission function.
[0184] Furthermore, the AMF network element, SMF network element and the first service management function network element can be integrated into the signaling plane of the core network.
[0185] Furthermore, the UPF network element and the first service transmission function network element can be integrated into the data plane of the core network.
[0186] In some embodiments, the first network element may implement the following functions:
[0187] 1) Managing (e.g., determining, generating, allocating, updating, and releasing) resources related to the first service. For example, the session type, session ID, and first parameters (including a first IP address and first security parameters (e.g., a key and an algorithm)). These first parameters are used for the first service. For example, when a terminal sends data, the first security parameters are used to protect the data, such as encryption and integrity protection. For example, the first IP address is used as the source IP address of data packets sent by the terminal.
[0188] 2) receiving a request to execute a first service, such as receiving a service request from an AMF, an SMF, or an application function; determining whether the first service can be executed and the related resources of the first service, for example, based on contract information, terminal and network capabilities, load, and other information;
[0189] 3) Providing relevant information of the first service, such as a first parameter, a session type, a session ID, etc. The first parameter may include a first security parameter and a first IP address. The relevant information may be carried in a container, or the relevant information may be transmitted in a message (such as a NAS message, RRC signaling) or in user plane data;
[0190] 4) Providing relevant information of the first service to other network components such as AMF / SMF / UPF / UE;
[0191] 5) Using the first security parameter of the first service (eg, user plane key) to perform security operations on the data, such as decryption and deprotection, for example, decrypting and deprotecting the user plane data packet from the UE; after deprotection, the data packet can be transmitted to the external network.
[0192] Furthermore, the first network element may be provided with a public interface for providing capability information of the first service. For example, the capability information may indicate whether the first service supports n terminals sending the same data on the same user plane.
[0193] Furthermore, the public interface may also provide service information of the first service, such as the start / end time of the first service, the communication status of the network, and the like.
[0194] Furthermore, the public interface may also provide requirement information for receiving the first service.
[0195] The public interface can be a physical / logical interface between the core network and the server of the external network, which is used to transmit relevant information of the first service. For example, referring to Figure 5, the first service management function network element can set a public interface at the AF / AS server. Similarly, the first service transmission function network element can also set a public interface at the AF / AS server. Through this open interface, for example, an information disclosure interface and a service management interface for the first service can be provided. Through this public interface, at least part of the following information can be provided: the execution time of the first service such as the start and end time, the geographical scope such as the tracking area, the cell; the information of the external network corresponding to the first service such as the network name, the IP address; the slice information corresponding to the first service; the service quality of the first service, the information of the terminal associated with the first service, such as the reachability of the terminal, the number of terminals n.
[0196] In some embodiments, network elements other than the first network element of the core network (such as AMF network element, SMF network element, Policy Control Function (PCF) network element, Unified Data Management (UDM) function network element) can implement the following functions:
[0197] 1) Obtaining relevant information of the first service, such as a first security parameter, for example, by obtaining relevant information from a first service management function network element;
[0198] 2) managing (e.g., determining, generating, transmitting, updating, releasing) information related to the first service, such as the first IP address, session ID, session type, session quality, and policy information (e.g., URSP, session management policy);
[0199] 3) receiving a request from the terminal to execute the first service, and determining whether the terminal can execute the first service by referring to the subscription information. The request to execute the first service can be transmitted in a NAS message, such as an MM message or an SM message, or can be transmitted in the user plane;
[0200] 4) managing the related session of the first service (ie, the first session), such as establishing, modifying, and releasing the first session associated with the first service based on a service request of the terminal or a service request of the application;
[0201] 5) Providing relevant information of the first service, such as first parameters (including first IP address, first security parameters), session ID, session type, session quality, and policy information (such as URSP, session management policy);
[0202] 6) Providing relevant information of the first service to the terminal, access network, and other nodes of the core network.
[0203] In some embodiments, the UPF network element can implement the following functions:
[0204] 1) Use the first security parameter of the first service to decrypt and deprotect the data, for example, decrypt and deprotect the user plane data packet sent by the terminal to the UPF network element or the first service transmission function network element, and then transmit it to the external network.
[0205] In some embodiments, the access network may implement the following functions:
[0206] 1) Using the first security parameter of the first service to perform security operations on data, such as decryption and deprotection. For example, decrypting and deprotecting user plane data packets from the terminal;
[0207] 2) Performing aggregation processing on the data from the terminals, wherein the aggregation includes: merging the same data packets from different terminals, which can improve the reliability of transmission.
[0208] In some embodiments, a terminal (for example, UE1 and UE2 shown in FIG5 ) may implement the following functions:
[0209] 1) Using information related to the first service to process data, specifically identifying uplink data belonging to the first service, and protecting the service layer data, for example, using a first security parameter to protect IP packets, Ethernet packets, unstructured data, etc. sent by the terminal, such as encryption and integrity protection; the protection operation can be performed at the service layer of the terminal or at the PDCP; if the protection operation is performed at the service layer, the PDCP layer may not perform security protection such as encryption on the data, that is, no security operations such as encryption on the user plane of the first service are performed between the access network and the terminal;
[0210] 2) Requesting to execute a first service, for example, sending a first message to a base station (such as NG-RAN) / AMF network element / SMF network element / first network element, where the first information includes first service request (such as activation, modification, release) information. The first information may be carried in a NAS message, which may be an MM or SM message; the SM message may be a PDU session activation, modification, release, or other message;
[0211] 3) Receiving relevant information of the first service, for example, receiving relevant information of the first service from the base station / AMF network element / SMF network element / PCF network element / first network element, such as session ID, session type, session quality, policy information (such as URSP, session management policy), first parameters (including first security parameters, first IP address), etc.;
[0212] 4) Save, update, and delete relevant information of the first business;
[0213] 5) Relevant information of the configured first service.
[0214] In a variation, the first service may be implemented by existing network elements of the core network.
[0215] For example, the first service management function can be integrated with the SMF. In this example, the first service management function network element in Figure 5 can be omitted, and the first service management function is implemented by the SMF.
[0216] For another example, the first service transmission function can be integrated with the UPF. In this example, the first service transmission function network element in Figure 5 can be omitted, and the first service transmission function is implemented by the UPF.
[0217] For another example, the first service management function and / or the first service transmission function may be implemented by the PCF of the core network, or may be implemented by the UDM function of the core network.
[0218] In a variation, the first service may be implemented in an access network, that is, a first network element may be added to the access network to implement a first service management function and / or a first service transmission function.
[0219] In application scenario 1, referring to Figure 6 , the communication system shown in Figure 5 can execute the method shown in Figure 1 to perform the first service at the service layer. The following describes in detail the specific process for each network component to execute the first service, using Figures 1 to 6 . In this example, the access network functions are performed by the gNB, equivalent to the NG-RAN shown in Figure 5 .
[0220] In step 0a, UE1 completes registration by interacting with the AMF network element (or SMF network element) through the base station. Similarly, UE2 also completes registration with the network. In some embodiments, the registration message may indicate whether the terminal or the network supports or does not support the first service.
[0221] In step 0b, UE1 and UE2 each establish a second session with the network. The second session can be, for example, a PDU session. For example, UE1 requests data transmission from the network, and the network allocates data transmission resources to various network elements and UE1, thereby completing the establishment of the second session. During and after the second session is established, UE1 and UE2 can establish the first session with the network.
[0222] Step 1, UE2 can send the first information to the AMF network element (or SMF network element) through the base station.
[0223] In step 1b, the AMF network element (or SMF network element) transmits the first information to the first service management function network element to request relevant information of the first service, such as the first parameter.
[0224] In step 2, the first service management function network element manages the first service, for example, by acquiring and determining relevant information about the first service, such as a first parameter. In some embodiments, this information acquisition process may involve interaction with core network elements, such as the UDM for contract information, the PCF for policy information, the SMF for session information, and the UPF for user plane information. This interaction includes operations such as acquisition, provisioning, updating, releasing, and deleting. In this application scenario, the first parameter is the third parameter.
[0225] In step 3a, a core network user plane node such as a UPF network element or a first service transmission function network element may obtain relevant information of the first service, such as a first parameter, from the first service management function network element.
[0226] Step 3b, the first service management function network element provides relevant information of the first service, such as the first parameter, to the AMF / SMF network element.
[0227] In step 3c, the first service management function network element provides the base station with relevant information about the first service, such as the first parameter. Step 3c is optional. In one variation, the first parameter may be forwarded to the base station by the AMF / SMF network element.
[0228] In step 4, the network sends a first message to UE2, where the first message includes the first parameter and other relevant information of the first service. In some embodiments, the first message can be received from any one of the AMF / SMF network element, the base station, and the first service management function network element.
[0229] Step 4': The network instructs UE1 to start executing the first service and sends a first message.
[0230] Step 5: UE2 saves the content of the received first message, such as the first parameter and other related information of the first service. Similarly, UE1 saves the content of the received first message.
[0231] Step 6: The application layer (such as a sensor) sends a data packet 1 to UE 2. The data packet 1 is data of the first service.
[0232] In step 7, UE2 processes data packet 1 using the first security parameter at the service layer to obtain a processed data packet.
[0233] In one embodiment, in step 7, UE2 can use the first security parameter to perform security processing on data packet 1 at the protocol layer. The processed data packet is transmitted to the base station via the first session. In this application scenario, the resources used by UE2 to transmit data of the first service have been preconfigured.
[0234] In response to receiving the data packet transmitted by UE2, the base station may execute step 8a to decrypt and deprotect the received data packet using the first security parameter acquired in step 3c.
[0235] Furthermore, the base station may also receive the same data packet from UE1, and also use the first security parameter to decrypt and deprotect the received data packet.
[0236] Then, the base station may combine the data packets received from UE1 and UE2 and transmit the combined data packets to the core network.
[0237] In some embodiments, in step 7, UE2 can use the first security parameter to securely process data packet 1 at the service layer (e.g., IP layer), and the protocol layer of UE2 (e.g., PDCP layer or SDAP layer) no longer securely processes the data. The processed data packet is transmitted to the base station through the first session, and then transparently transmitted to the core network via the base station.
[0238] In this example, step 3c can be omitted.
[0239] In response to receiving the data packet transparently transmitted by the base station, the UPF network element or the first service transmission function network element executes step 8b to decrypt and deprotect the received data packet using the first security parameter. The decrypted and deprotected data can then be transmitted to the external network.
[0240] In the second typical application scenario (denoted as application scenario 2), the communication system may include a terminal, an access network, a core network and an external network. Figure 7 exemplifies the security architecture of each network component at the service layer, wherein the terminal includes UE1 and UE2, the access network includes NG-RAN, the core network includes AMF network element, SMF network element, first network element and UPF network element, and the external network includes AF / AS server.
[0241] Specifically, the AMF network element is used to provide AMF, the SMF network element is used to provide SMF, and the UPF network element is used to provide UPF.
[0242] Furthermore, compared to the existing core network, the core network of the embodiment of the present application adds a first network element for processing the first service. For example, the first parameter can be configured by the first network element. In some embodiments, the first network element may include a first service management function network element for providing the first service management function.
[0243] Furthermore, the AMF network element, SMF network element and the first service management function network element can be integrated into the signaling plane of the core network.
[0244] Furthermore, the UPF network element can be integrated into the data plane of the core network.
[0245] In some embodiments, a terminal (e.g., UE1, UE2) may implement the following functions:
[0246] 1) Requesting execution of a first service;
[0247] 2) Requesting the network for information related to executing the first service;
[0248] 3) receiving relevant information of the first service 1 obtained from the network;
[0249] 4) Storing, updating, and deleting relevant information of the first service provided by the network;
[0250] 5) Pre-configuring relevant information of the first service in the UE (such as the ME or USIM);
[0251] 6) using relevant information of the first service to process data, such as identifying uplink data belonging to the first service and performing security protection on the uplink data of the first service, such as performing encryption and / or integrity protection at the PDCP layer;
[0252] 7) Applying for resources for the first service, such as executing a service request procedure, the terminal determines whether to initiate a resource application based on at least a portion of the session type, terminal type, and service type configured by the network.
[0253] In some embodiments, the core network implements the following functions:
[0254] 1) The core network manages and allocates resources required for the first service. This can be performed in the AMF, SMF, or other core network functions, such as the first service management function. The core network manages and allocates resources required for the first service after the network receives a request from the terminal to execute the first service, for example, triggered by the terminal's request. It can also be performed before the network receives the terminal's request, for example, when the network originates (or Initiates) the execution of the first service, and the network triggers the processes required to execute the first service, such as the PDU session establishment process.
[0255] 2) The core network provides relevant information of the first service, for example, the core network provides relevant information of the first service to the terminal, access network, and external network such as application service, and the core network network elements provide relevant information of the first service between each other;
[0256] 3) The core network obtains part of the first service related information from the access network, such as the first security parameter. In this application scenario, at least part of the first parameter reuses the second parameter of a terminal related to the first session.
[0257] In some embodiments, the access network may implement the following functions:
[0258] 1) Provide some or all of the information related to the first service, such as the second security parameters of the terminal reused among the n terminals related to the first session. Specifically, the access network can provide some or all of the relevant information of the first service to the core network. Further, the access network can provide some or all of the relevant information of the first service to the terminal. USIM
[0259] In some embodiments, the USIM of the terminal may store and provide information required for the first service, such as policy, service type, session type, application ID, etc.
[0260] Furthermore, the first network element may be provided with a public interface to provide at least a portion of the capability information, service information, and requirement information of the first service. For example, the first service management function and the AF / AS server may communicate with each other via the public interface.
[0261] In application scenario 2, referring to Figure 8 , the communication system shown in Figure 6 can execute the method shown in Figure 1 to perform the first service at the service layer. The specific process for each network component to perform the first service will be described in detail below, using Figures 1 through 4 , 7 , and 8 . In this example, the access network functions are performed by the gNB, equivalent to the NG-RAN shown in Figure 5 .
[0262] The specific contents of step 0a and step 0b can be referred to the relevant description in the application scenario 1 shown in FIG6 , which will not be repeated here. The base station learns the second security parameter and the second IP address of UE1 during the registration process of UE1.
[0263] Specifically, after executing steps 0a and 0b, UE1 and UE2 each obtain their own second security parameters and second IP addresses. The second security parameters are used at the terminal's protocol layer (e.g., the PDCP layer). UE1 and UE2 each notify the base station of the second security parameters and second IP addresses via RRC signaling. UE1's second security parameters are different from UE2's second security parameters, and UE1's second IP address is different from UE2's second IP address.
[0264] In step 1, UE2 may send a first message to an AMF network element (or SMF network element) through a base station. Further, the AMF network element (or SMF network element) transmits the first message to a first service management function network element to request relevant information of the first service, such as a first parameter.
[0265] In step 2, the core network establishes a first session to process the first service and allocates relevant information for the first service to the first session, such as the first IP address and first security parameters used by the terminal to send data, and the identifier of the first session. In this application scenario, the first IP address needs to reuse UE1's second IP address, and the first security parameters need to reuse UE1's second security parameters.
[0266] In step 3, the core network may request the access network for resource information required for the first service, such as UE1's second IP address and / or second security parameters. Accordingly, the access network provides the core network with the resource information required for the first service. For example, the core network's AMF network element may send a third message to the base station via the N2 interface and receive a fourth message fed back by the base station to obtain UE1's second IP address and / or second security parameters. The third message and / or fourth message may be carried by an AS message.
[0267] In some embodiments, the resource information required for the first service provided by the access network to the core network may be a response to a request from the core network for resource information required for the first service from the access network, or may be triggered by the access network (e.g., originating or initiating) to provide the resource information required for the first service to the core network. For example, when the corresponding information in the access network changes, the corresponding information may be proactively updated to the core network. Thus, through subsequent interaction between the network and UE2, UE2 may use UE1's second security parameters to transmit data for the first service.
[0268] In step 4, the network sends a first message to UE2, where the first message includes the first parameter and other relevant information of the first service. In some embodiments, the first message may be received from an AMF / SMF network element. For example, the core network may provide the information in a NAS message, such as a mobility management message or a session management message, or may provide the information through the user plane. In some embodiments, part of the content in the first message (e.g., the second security parameter of UE1) may also be provided to the UE through the access network, such as through a radio resource management message (e.g., RRC signaling).
[0269] In step 4', the network (such as an AMF / SMF network element) instructs UE1 to start executing the first service, and the first IP address of the first service is the second IP address of UE1. Furthermore, the network may also send at least part of the content in the first message, such as the identifier of the first session.
[0270] Step 5: UE2 saves the content of the received first message, such as saving the second IP address and the second security parameter of UE1.
[0271] In step 6, an application layer data source (e.g., a sensor) sends Data Packet 1 to UE1 and UE2. Data Packet 1 contains data for the first service. The source IP address of Data Packet 1 can be the first IP address. In response to receiving Data Packet 1, UE1 sends a second message requesting the network to allocate resources for the first session.
[0272] Specifically, when uploading data, the terminal needs to request the network to allocate resources to the terminal, including time-frequency resources for the air interface. In this embodiment of the present application, UE1 and UE2 use the same time-frequency resources to transmit the same data packet 1, so it is sufficient for one of the terminals to request resource allocation from the network. For example, if the AMF / SMF network element indicates in step 4' that UE1 is the base terminal, UE1 determines in step 6 that it needs to send a second message to request the network to allocate resources for the first session.
[0273] For UE2, UE2 determines that data packet 1 is data of the first service based on the source IP address used by data packet 1, and since the AMF / SMF network element indicates that UE2 is an auxiliary terminal in the first message sent to UE2 in step 4, UE2 does not initiate a resource allocation request in step 6.
[0274] In some embodiments, UE1 may use a SERVICE REQUEST procedure to request resource allocation. Furthermore, the second message may carry an identifier of the first session.
[0275] In some embodiments, the network may allocate resources for the first service after receiving the second message from the terminal, for example, triggered by a request from UE1. Alternatively, the network may allocate resources before receiving the second message from the terminal, for example, when the network initiates the first service through network origination (e.g., initiating). The network triggering the execution of the first service may be implemented, for example, during the establishment of a PDU session.
[0276] In some embodiments, the network may be a function of an access network. For example, a base station may respond to the second message and allocate resources for the first session to the first service.
[0277] In some embodiments, the network may be a function of a core network, for example, an AMF network element or an SMF network element may respond to the second message and allocate resources for the first session to the first service.
[0278] Furthermore, after resource allocation is completed, the base station may notify UE1 that resource establishment for the first session is complete. Optionally, the base station may also notify UE2 that resource establishment for the first session is complete.
[0279] In step 7, UE1 and UE2 each process Data Packet 1 using the information related to the first service. Specifically, UE1 processes Data Packet 1 using its second security parameter as the first security parameter and transmits the processed data over the first session using its second IP address as the first IP address. In parallel, UE2 processes Data Packet 1 using UE1's second security parameter as the first security parameter and transmits the processed data over the first session using UE1's second IP address as the first IP address.
[0280] For either UE1 or UE2, data packet 1 may be processed at the protocol layer using UE1's second security parameters. In response to receiving the same processed data transmitted by UE2 and UE1, the base station may perform step 8a, decrypt and deprotect the received data packet using UE1's second security parameters obtained during UE1's registration phase, and transmit the combined data packet to the core network.
[0281] In a common variation example of the above-mentioned application scenario 1 and application scenario 2, data packet 1 can be an Ethernet data packet. Accordingly, when UE1 and UE2 each process the received data packet 1 using the first security parameter, the processed data is packaged into an Ethernet data packet and transmitted to the next node (for example, a base station).
[0282] In a common variation of the above-mentioned application scenarios 1 and 2, for a terminal (e.g., UE2) that is instructed not to request resources for the first session, after receiving data for the first service from the application layer, UE2 can send a second message. Based on the identifier of the first session in the second message, the network determines whether resources have been allocated for the first session. If resources have been allocated, the network does not respond to UE2's resource allocation request.
[0283] As described above, using this embodiment, different terminals can obtain or pre-configure the same first IP address from the network for use in sending data for the first service. Further, different terminals can obtain or pre-configure the same first security parameters from the network for use in secure processing when sending data for the first service.
[0284] Furthermore, the core network may manage resources related to the first service (eg, information related to the first service), such as generating a first IP address or a first security parameter, or obtaining a first security parameter (eg, a user plane key) from the access network.
[0285] Furthermore, the first information / first message may carry relevant information of the first service / information indicating capability of the first service.
[0286] Furthermore, the network can provide public interfaces related to the first service, such as information disclosure and capability disclosure. For example, a third-party server can submit a service request to the network, such as when the power grid wants the first service to start. This request can then be communicated to the core network via a public interface, and the core network can configure the relevant parameters for the access network and terminals. For another example, the operator server can communicate service information about the first service, such as network communication status, to the third-party server via a public structure on the core network.
[0287] FIG9 is a schematic structural diagram of a data transmission device (denoted as data transmission device 2 ) provided in an embodiment of the present application.
[0288] Those skilled in the art will appreciate that the data transmission device 2 of this embodiment can be used to implement the methods described in the embodiments shown in Figures 1 to 8. The data transmission device 2 can be the terminal mentioned above.
[0289] Specifically, referring to Figure 9, the data transmission device 2 may include: an acquisition module 21, used to obtain a first parameter associated with a first session, the first parameter including a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module 22, used to use the first parameter to transmit data of the first service through the first session; wherein, all terminals related to the first session use the first parameter to transmit the data.
[0290] In some embodiments, the data transmission device 2 may further include: a sending module (not shown) for sending first information for requesting to obtain the first parameter. Further, the obtaining module 21 includes: a receiving unit (not shown) for receiving the first parameter associated with the first session.
[0291] In some embodiments, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity identifier of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; and an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0292] In some embodiments, the first information is carried via a non-access layer message or an access layer message.
[0293] In some embodiments, the transmission module 22 may include: a first transmission unit (not shown) for processing the data using the first security parameters and transmitting the processed data as an Ethernet data packet; or a second transmission unit (not shown) for processing the data using the first security parameters and transmitting it using the first IP address.
[0294] In some embodiments, the acquisition module 21 may include: a receiving unit (not shown), configured to receive a first message, where the first message includes a first parameter associated with the first session.
[0295] In some embodiments, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0296] In some embodiments, the first message is carried via a non-access stratum message or an access stratum message.
[0297] In some embodiments, the first parameter is preconfigured.
[0298] In some embodiments, the first parameter multiplexes the second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service.
[0299] In some embodiments, the action of processing the data using the first security parameter is performed at a service layer, or the action of processing the data using the first security parameter is performed at a protocol layer.
[0300] For more details about the working principle and working mode of the data transmission device 2, please refer to the relevant descriptions in Figures 1 to 8 above, which will not be repeated here.
[0301] In a specific implementation, the above-mentioned data transmission device 2 can correspond to a chip with a data transmission function in the terminal, or to a chip with a data processing function, such as a system-on-a-chip (SOC), a baseband chip, etc.; or to a chip module in the terminal that includes a chip with a data transmission function; or to a chip module with a data processing function chip, or to a terminal.
[0302] Figure 10 is a schematic diagram of the structure of another data transmission device (denoted as data transmission device 3) provided in an embodiment of the present application. Those skilled in the art will appreciate that the data transmission device 3 described in this embodiment can be used to implement the methods described in the embodiments illustrated in Figures 1 to 8 above. Data transmission device 3 can be the access network mentioned above.
[0303] Specifically, referring to Figure 10, the data transmission device 3 may include: a receiving module 31, used to receive data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, and the first parameters include a first security parameter and / or a first IP address; a transmission module 32, used to merge the received data and transmit it to the next node.
[0304] In some embodiments, the first security parameter is a third security parameter, the third security parameter does not reuse the second security parameter of the terminal related to the first session, and the second security parameter is associated with services other than the first service. The data transmission device 3 may also include: an acquisition module (not shown) for obtaining the first security parameter from the core network.
[0305] In some embodiments, the first security parameter multiplexes a second security parameter of a terminal associated with the first session, and the second security parameter is associated with a service other than the first service.
[0306] In some embodiments, the transmission module 32 may include: a processing unit (not shown) for deprocessing the data using the first security parameter and merging them to obtain deprocessed data; and a transmission unit (not shown) for transmitting the deprocessed data to the next node.
[0307] In some embodiments, the action of de-processing the data using the first security parameter is performed at a service layer, or the action of de-processing the data using the first security parameter is performed at a protocol layer.
[0308] In some embodiments, the data transmission device 3 may also include: a receiving unit (not shown in the figure) for receiving a third message from the core network, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; a sending unit (not shown in the figure) for sending a fourth message, the fourth message including the second security parameter of the target terminal, and the first security parameter multiplexing the second security parameter of the target terminal.
[0309] For more details about the working principle and working mode of the data transmission device 3, please refer to the relevant descriptions in Figures 1 to 8 above, which will not be repeated here.
[0310] In a specific implementation, the above-mentioned data transmission device 3 can correspond to a chip with a data transmission function in a network device of an access network, or to a chip with a data processing function, such as a system-on-a-chip (SOC), a baseband chip, etc.; or to a chip module including a chip with a data transmission function in a network device of an access network; or to a chip module with a data processing function chip, or to a network device of an access network.
[0311] Figure 11 is a schematic diagram of the structure of another data transmission device (denoted as data transmission device 4) provided in an embodiment of the present application. Those skilled in the art will appreciate that the data transmission device 4 described in this embodiment can be used to implement the methods described in the embodiments described in Figures 1 to 8 above. Data transmission device 4 can be the core network described above.
[0312] Specifically, referring to Figure 11, the data transmission device 4 may include: a sending module 41, used to send a first parameter associated with a first session, the first parameter includes a first security parameter and / or a first IP address, and the first session is associated with a first service; a receiving module 42, used to receive data of the first service transmitted by the access network, and the data is transmitted through the first session; wherein, network elements related to the first session all use the first parameter to transmit the data.
[0313] In some embodiments, the data transmission device 4 may further include: a first information receiving module (not shown), configured to receive first information, where the first information is used to request acquisition of the first parameter.
[0314] In some embodiments, the sending module 41 may include: a sending unit (not shown), configured to send a first message, where the first message includes a first parameter associated with the first session.
[0315] In some embodiments, the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity identifier of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; and an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
[0316] In some embodiments, the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and / or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
[0317] In some embodiments, the first information is carried via a non-access stratum message or an access stratum message; and / or the first message is carried via a non-access stratum message or an access stratum message.
[0318] In some embodiments, the first parameter multiplexes the second parameter of a terminal associated with the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal associated with the first session, and the second parameter is associated with a service other than the first service; and / or the data includes at least one of the following: Ethernet data packet; IP data packet.
[0319] In some embodiments, the data transmission module 4 may further include: a processing module (not shown) configured to process the data using the first security parameter solution.
[0320] In some embodiments, the data received from the access network is data processed using the first security parameter.
[0321] In some embodiments, the data transmission module 4 may further include: a second message receiving unit (not shown) for receiving a second message for requesting allocation of resources for the first session; and a configuration unit (not shown) for configuring the resources.
[0322] In some embodiments, the data transmission module 4 may also include: a third message sending module (not shown in the figure), used to send a third message, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; a fourth message receiving module (not shown in the figure), used to receive a fourth message, the fourth message including the second security parameter of the target terminal, and the first parameter reuses the second security parameter.
[0323] In some embodiments, the first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
[0324] In some embodiments, the first network element is provided with a public interface for providing capability information and / or service information of the first service, and / or receiving demand information of the first service.
[0325] For more details about the working principle and working mode of the data transmission device 4, please refer to the relevant descriptions in Figures 1 to 8 above, which will not be repeated here.
[0326] In a specific implementation, the above-mentioned data transmission device 4 can correspond to a chip with a data transmission function in a core network network element, or to a chip with a data processing function, such as a system-on-a-chip (SOC), a baseband chip, etc.; or to a chip module in a core network network element that includes a chip with a data transmission function; or to a chip module with a data processing function chip, or to a core network network element.
[0327] In specific implementations, the modules / units included in the various devices and products described in the above embodiments may be software modules / units or hardware modules / units, or may be partially software modules / units and partially hardware modules / units.
[0328] For example, for each device or product applied to or integrated into a chip, each module / unit contained therein may be implemented in the form of hardware such as circuits, or at least some of the modules / units may be implemented in the form of software programs, which run on a processor integrated inside the chip, and the remaining (if any) modules / units may be implemented in the form of hardware such as circuits; for each device or product applied to or integrated into a chip module, each module / unit contained therein may be implemented in the form of hardware such as circuits, and different modules / units may be located in the same component (such as a chip, circuit module, etc.) or different components of the chip module, or at least some of the modules / units may be implemented in the form of software programs. The software program runs on the processor integrated inside the chip module, and the remaining (if any) modules / units can be implemented in hardware such as circuits; for various devices and products applied to or integrated in the terminal, the various modules / units contained therein can be implemented in hardware such as circuits, and different modules / units can be located in the same component (for example, chip, circuit module, etc.) or different components in the terminal, or at least some modules / units can be implemented in the form of a software program, which runs on the processor integrated inside the terminal, and the remaining (if any) modules / units can be implemented in hardware such as circuits.
[0329] An embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the data transmission method provided in the embodiments shown in Figures 1 to 8 above are executed.
[0330] In an embodiment of the present application, the storage medium may include a non-volatile memory or a non-transitory memory, and may also include an optical disk, a mechanical hard disk, a solid-state hard disk, etc.
[0331] FIG12 is a schematic structural diagram of another data transmission device provided in an embodiment of the present application.
[0332] Specifically, with reference to Figure 12, the data transmission device may include a processor 51, and the processor 51 is coupled to a memory 52. The memory 52 may be located inside the device or outside the device. Optionally, a transceiver 53 is also included. The memory 52, the processor 51, and the transceiver 53 may be connected via a communication bus. The memory 52 stores a computer program that can be run on the processor 51. When the processor 51 runs the computer program, the steps of the data transmission method provided in the embodiments shown in Figures 1 to 8 are executed. The transceiver 53 may perform the sending and / or receiving actions mentioned above under the control of the processor 51. The data transmission device may be the network device mentioned above, or a terminal, or a core network element.
[0333] In the embodiment of the present application, the memory 52 includes a non-volatile memory or a non-transitory memory, and may also include an optical disk, a mechanical hard disk, a solid-state hard disk, etc.
[0334] In the embodiment of the present application, the processor 51 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0335] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: ROM, RAM, disk or CD, etc.
[0336] The embodiment description in this application is described with reference to the flow chart and / or block diagram according to the method, equipment (device) and computer program product of embodiment of the present application.It should be understood that each flow process and / or box in the flow chart and / or block diagram and the combination of the flow process and / or box in the flow chart and / or block diagram can be realized by computer program instructions.These computer program instructions can be provided to the processor of general-purpose computer, special-purpose computer, embedded processing machine or other programmable data processing equipment to produce a machine, so that the instruction executed by the processor of computer or other programmable data processing equipment produces the device for realizing the function specified in one flow chart flow chart or multiple flow charts and / or one block or multiple blocks of block diagram.
[0337] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0338] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0339] It should also be noted that, in the embodiments of the present application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can represent: a, b, c, a and b, a and c, b and c or a and b and c, where a, b, c can be single or multiple.
[0340] In the embodiments of the present application, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, commodity, or apparatus comprising the element.
[0341] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0342] The various embodiments in this application are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences from other embodiments. In particular, the device embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the partial description of the method embodiments.
[0343] Those skilled in the art will appreciate that the various units and algorithm steps described in the embodiments of the present application can be implemented using a combination of electronic hardware, computer software, and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0344] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices, apparatuses and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0345] Although the present application is disclosed as above, the present application is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims.
Claims
1. A data transmission method, characterized in that: include: Acquire a first parameter associated with a first session, where the first parameter includes a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; The data of the first service is transmitted through the first session using the first parameter; wherein all terminals related to the first session transmit the data using the first parameter.
2. The data transmission method according to claim 1, characterized in that: Also includes: Sending first information, where the first information is used to request to obtain the first parameter; The obtaining the first parameter associated with the first session includes: receiving the first parameter associated with the first session.
3. The data transmission method according to claim 2, characterized in that: The first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; and an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
4. The data transmission method according to claim 2 or 3, characterized in that: The first information is carried by a non-access layer message or an access layer message.
5. The data transmission method according to any one of claims 1 to 4, characterized in that: The transmitting the data of the first service through the first session using the first parameter includes: Processing the data using the first security parameter and transmitting the processed data as an Ethernet data packet; or The data is processed using the first security parameter and transmitted using the first IP address lose.
6. The data transmission method according to any one of claims 1 to 5, characterized in that: The acquiring the first parameter associated with the first session includes: A first message is received, the first message including a first parameter associated with the first session.
7. The data transmission method according to claim 6, characterized in that: The first message further includes at least one of the following: second indication information, used to indicate whether the terminal and / or the network supports the first service; an identifier of the first session; terminal type; service type of the first service; session type of the first session; Part or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
8. The data transmission method according to claim 6 or 7, characterized in that: The first message is carried by a non-access layer message or an access layer message.
9. The data transmission method according to any one of claims 1 to 8, characterized in that: The first parameter is preconfigured; and / or the first parameter multiplexes a second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service; and / or the action of processing the data using the first security parameter is performed at the service layer, or the action of processing the data using the first security parameter is performed at the protocol layer.
10. A data transmission method, characterized in that: include: receiving data transmitted by one or more terminals through a first session, where the first session is associated with a first service, the data is data of the first service, and the terminals associated with the first session all transmit the data using first parameters, where the first parameters include a first security parameter and / or a first IP address; The received data are combined and transmitted to the next node.
11. The data transmission method according to claim 10, characterized in that: The first security parameter is a third security parameter, the third security parameter does not reuse a second security parameter of a terminal related to the first session, the second security parameter is associated with services other than the first service, and the method further includes: obtaining the first security parameter from a core network.
12. The data transmission method according to claim 10, characterized in that: The first security parameter multiplexes a second security parameter of a terminal related to the first session, and the second security parameter is associated with services other than the first service.
13. The data transmission method according to any one of claims 10 to 12, characterized in that: The combining the received data and transmitting to the next node comprises: De-processing the data using the first security parameter and combining them to obtain de-processed data; The de-processed data is transmitted to the next node.
14. The data transmission method according to claim 13, characterized in that: The action of de-processing the data using the first security parameter is performed at the service layer, or the action of de-processing the data using the first security parameter is performed at the protocol layer.
15. The data transmission method according to any one of claims 10 to 14, characterized in that: Also includes: receiving a third message from the core network, the third message including an identity of the target terminal and an identifier of the second session of the target terminal; A fourth message is sent, where the fourth message includes a second security parameter of the target terminal, and the first security parameter multiplexes the second security parameter of the target terminal.
16. A data transmission method, characterized in that: include: Sending a first parameter associated with a first session, where the first parameter includes a first security parameter and / or a first IP address, and the first session is associated with a first service; Receive data of the first service transmitted by the access network, the data being transmitted through the first Session transfer; Among them, all network elements related to the first session use the first parameter to transmit the data.
17. The data transmission method according to claim 16, characterized in that: Also includes: receiving first information, where the first information is used to request obtaining the first parameter; and / or The sending the first parameter associated with the first session includes: sending a first message, where the first message includes the first parameter associated with the first session.
18. The data transmission method according to claim 17, characterized in that: The first information includes at least one of the following: first indication information for indicating execution of the first service; an identity of a terminal associated with the first session; session information of the first session; capability information of the terminal supporting the first service; a group identifier of a group to which the terminal associated with the first session belongs; an identifier of a second session of the terminal associated with the first session, the second session being associated with services other than the first service; and / or The first message further includes at least one of the following: second indication information, used to indicate whether the terminal and / or the network supports the first service; an identifier of the first session; terminal type; service type of the first service; session type of the first session; Part or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
19. The data transmission method according to claim 17 or 18, characterized in that: The first information is carried by a non-access layer message or an access layer message; and / or the first message is carried by a non-access layer message or an access layer message.
20. The data transmission method according to any one of claims 16 to 19, characterized in that: The first parameter multiplexes the second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service; and / or the data includes at least one of the following: Ethernet data packet; IP data packet.
21. The data transmission method according to any one of claims 16 to 20, characterized in that: Also includes: The data is processed using the first security parameter; or, the data received from the access network is data processed using the first security parameter.
22. The data transmission method according to any one of claims 16 to 21, characterized in that: Also includes: receiving a second message, wherein the second message is used to request allocation of resources for the first session; Configure the resource.
23. The data transmission method according to any one of claims 16 to 22, characterized in that: Also includes: Sending a third message, wherein the third message includes an identity identifier of a target terminal and an identifier of a second session of the target terminal; A fourth message is received, where the fourth message includes a second security parameter of the target terminal, and the first parameter multiplexes the second security parameter.
24. The data transmission method according to any one of claims 16 to 23, characterized in that: The first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
25. The data transmission method according to claim 24, characterized in that: The first network element is provided with a public interface for providing capability information and / or service information of the first service, and / or receiving demand information of the first service.
26. A data transmission device, characterized in that: include: an acquisition module, configured to acquire a first parameter associated with a first session, wherein the first parameter includes a first security parameter and / or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module, configured to transmit data of the first service through the first session using the first parameter; Among them, all terminals related to the first session use the first parameter to transmit the data.
27. A data transmission device, characterized in that: include: a receiving module, configured to receive data transmitted by one or more terminals through a first session, wherein the first session is associated with a first service, the data is data of the first service, and the terminals associated with the first session all transmit the data using first parameters, wherein the first parameters include a first security parameter and / or a first IP address; The transmission module is used to merge the received data and transmit it to the next node.
28. A data transmission device, characterized in that: include: a sending module, configured to send a first parameter associated with a first session, the first parameter including a first security parameter and / or a first IP address, the first session being associated with a first service; a receiving module, configured to receive data of the first service transmitted by an access network, the data being transmitted through the first session; Among them, all network elements related to the first session use the first parameter to transmit the data.
29. A computer-readable storage medium, wherein the computer-readable storage medium is a non-volatile storage medium or a non-transient storage medium, and a computer program is stored thereon, wherein: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 25 are performed.
30. A data transmission device, comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, characterized in that: When the processor runs the computer program, the steps of the method according to any one of claims 1 to 25 are performed.
Citation Information
Patent Citations
Communication method and corresponding device
CN114430592A
Message transmission method and device
CN115209398A
Communication method and device
CN115734398A
Communication method and device
CN116095667A
Data transmission method, device and system
CN116471549A