Information processing method and apparatus, communication device, and storage medium

By determining whether the address received by the terminal is the address of the authorized local route, the access behavior is controlled, and the problem that the roaming terminal may obtain an unauthorized IP address is solved, and secure access within the scope of authorization is achieved.

WO2025148838A1PCT designated stage expired Publication Date: 2025-07-17VIVO MOBILE COMM CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/070809
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-11
Filing Date
2025-01-06
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

The terminals in the roaming place may obtain IP addresses that do not authorize local routing, resulting in departing from the control of the local operator and increasing the control risks.

Method used

By receiving information and determining based on the second information whether the first address is an address authorized for local routing, access behavior is controlled to reduce control risks.

Benefits of technology

Effectively avoid terminal access to addresses that do not authorize local routes, reduce control risks, and ensure that access behavior is within the scope of authorization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025070809_17072025_PF_FP_ABST
    Figure CN2025070809_17072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and discloses an information processing method and apparatus, a communication device, and a storage medium. The information processing method in embodiments of the present application comprises: a first communication device receives first information, the first information comprising a first address; and, on the basis of second information, the first communication device determines whether the first address is an address authorized to be locally routed.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, device, communication equipment and storage medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese Patent Application No. 202410048341X filed in China on January 11, 2024, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present application belongs to the field of communication technology, and specifically relates to an information processing method, apparatus, communication equipment and storage medium. Background Art

[0004] A terminal in a roaming location (or a visited location) can send a Domain Name System (DNS) query request, which contains information such as the fully qualified domain name (FQDN). If the terminal sends the DNS query request to a local DNS server, the local DNS server can resolve the requested FQDN and obtain the Internet Protocol (IP) address of the server corresponding to the server.

[0005] However, because the local DNS server is deployed in the roaming location, it may resolve an IP address that is not authorized for local routing. If the terminal obtains an IP address returned by the local DNS server and this address is not authorized for local routing or local access by the home operator, the terminal may access the IP address that is not authorized for local routing, thus escaping the control of the home operator and increasing the control risk. Summary of the Invention

[0006] The embodiments of the present application provide an information processing method, apparatus, communication device, and storage medium to determine whether a first address is an authorized local routing address, thereby reducing management and control risks.

[0007] In a first aspect, an information processing method is provided, comprising:

[0008] The first communication device receives first information, where the first information includes a first address;

[0009] The first communication device determines, based on the second information, whether the first address is an address for authorized local routing.

[0010] In a second aspect, an information processing method is provided, comprising:

[0011] The second communication device receives a first request, where the first request is used to request the second communication device to send a first query request, where the first query request includes a first address, where the first address is an address that is not authorized for local routing;

[0012] The second communication device sends the first query request.

[0013] A third aspect provides an information processing method, comprising:

[0014] The third communication device receives a first rule, the first rule comprising: routing a data packet routed to a first address to a third address, the first address being an address for which local routing is not authorized or an address that is not authorized for local routing;

[0015] Upon receiving the first data packet routed to the first address, the third communication device routes the first data packet to the third address.

[0016] A fourth aspect provides an information processing method, comprising:

[0017] The fifth communication device sends third information to the fourth communication device, where the third information includes an address of a first server, where the first server is used to perform domain name resolution;

[0018] The address range resolved by the first server is within the address range of the authorized local route, or the addresses resolved by the first server are all addresses of the authorized local route.

[0019] In a fifth aspect, an information processing device is provided, comprising:

[0020] A first receiving module, configured to receive first information, where the first information includes a first address;

[0021] The first determining module is configured to determine, based on the second information, whether the first address is an address of an authorized local route.

[0022] In a sixth aspect, an information processing device is provided, comprising:

[0023] a second receiving module, configured to receive a first request, where the first request is used to request the second communication device to send a first query request, where the first query request includes a first address, where the first address is an address that does not authorize local routing;

[0024] The third sending module is configured to send the first query request.

[0025] In a seventh aspect, an information processing device is provided, comprising:

[0026] a third receiving module, configured to receive a first rule, wherein the first rule comprises: routing a data packet routed to a first address to a third address, wherein the first address is an address for unauthorized local routing or an address that is not authorized local routing;

[0027] The routing module is configured to, upon receiving a first data packet routed to the first address, route the first data packet to the third address.

[0028] In an eighth aspect, an information processing device is provided, comprising:

[0029] a fifth sending module, configured to send third information to a fourth communication device, wherein the third information includes an address of a first server, and the first server is configured to perform domain name resolution;

[0030] The address range resolved by the first server is within the address range of the authorized local route, or the addresses resolved by the first server are all addresses of the authorized local route.

[0031] In the ninth aspect, a communication device is provided, which includes a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect, or implements the steps of the method described in the third aspect, or implements the steps of the method described in the fourth aspect.

[0032] In the tenth aspect, a communication device is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0033] In the eleventh aspect, a network side device is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented, or the steps of the method described in the fourth aspect are implemented.

[0034] In the twelfth aspect, a network side device is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0035] In the thirteenth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented, or the steps of the method described in the fourth aspect are implemented.

[0036] In the fourteenth aspect, a wireless communication system is provided, comprising: a first communication device, or a second communication device, or a third communication device, or a fifth communication device, wherein the first communication device can be used to perform the steps of the method described in the first aspect, the second communication device can be used to perform the steps of the method described in the second aspect, the third communication device can be used to perform the steps of the method described in the third aspect, and the fifth communication device can be used to perform the steps of the method described in the fourth aspect.

[0037] In the fifteenth aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0038] In the sixteenth aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0039] In an embodiment of the present application, a first communication device receives first information, which includes a first address, and then determines whether the first address is an authorized local routing address based on second information, and judges whether the first address is an authorized or unauthorized local routing address, so as to control access to the first address based on different judgment results and reduce management and control risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] FIG1 is a block diagram of a wireless communication system applicable to embodiments of the present application;

[0041] FIG2 is a schematic diagram of the structure of a communication system in the related art;

[0042] FIG3 is a flowchart of an implementation method of an information processing method in an embodiment of the present application;

[0043] FIG4 is a schematic diagram of a process for routing a DNS response back to a V-SMF according to an embodiment of the present application;

[0044] FIG5 is a schematic diagram of the processing process corresponding to routing back to the local operator in an embodiment of the present application;

[0045] FIG6 is a flowchart of another information processing method according to an embodiment of the present application;

[0046] FIG7 is a flowchart of another information processing method according to an embodiment of the present application;

[0047] FIG8 is a flowchart of another information processing method according to an embodiment of the present application;

[0048] FIG9 is a schematic structural diagram of an information processing device corresponding to FIG3 in an embodiment of the present application;

[0049] FIG10 is a schematic structural diagram of an information processing device corresponding to FIG6 in an embodiment of the present application;

[0050] FIG11 is a schematic structural diagram of an information processing device corresponding to FIG7 in an embodiment of the present application;

[0051] FIG12 is a schematic structural diagram of an information processing device corresponding to FIG8 in an embodiment of the present application;

[0052] FIG13 is a schematic structural diagram of a communication device according to an embodiment of the present application;

[0053] FIG14 is a schematic structural diagram of a network-side device in an embodiment of the present application. DETAILED DESCRIPTION

[0054] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0055] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.

[0056] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.

[0057] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for illustrative purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) systems. th Generation, 6G) communication system.

[0058] FIG1 is a block diagram of a wireless communication system applicable to an embodiment of the present application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device (Wearable Device), an aircraft (Flight Vehicle), a vehicle-mounted device (VUE), a ship-mounted device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), a game console, a personal computer (PC), an ATM, or a self-service machine, or other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may include an access network device or a core network device, wherein the access network device may also be called a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit. The access network device may include a base station, a wireless local area network (WLAN) access point (AS) or a wireless fidelity (WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.

[0059] The core network equipment may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application service discovery function (EASDF), unified data management (UDM), unified data repository (UDR), home user server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (BSF), application function ( Function, AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), Network Data Analytics Function (NWDAF), etc. It should be noted that in the embodiment of the present application, only the core network equipment in the NR system is taken as an example to introduce, and the specific type of the core network equipment is not limited.

[0060] It should be noted that in the embodiment of the present application, the first communication device to the fifth communication device can be at least one or more core network devices, or at least one or more terminals and base stations.

[0061] In the embodiment of the present application, the roaming location can be understood as or equivalent to the visited location.

[0062] In the embodiment of the present application, authorization or non-authorization may be equivalent to permission or non-permission, or permission or non-permission; and authorization or non-authorization of local routing may also be understood as or equivalent to the following concepts:

[0063] Allow or disallow local routing;

[0064] Allow or disallow local diversion;

[0065] Allow or disallow Home Routed Session BreakOut (HR-SBO);

[0066] Allow or disallow routing to the local data network;

[0067] Permit or not permit HR-SBO;

[0068] permitting or not permitting local diversion;

[0069] Allow or disallow local routing;

[0070] Allow or disallow routing to the local data network.

[0071] To facilitate understanding, the relevant technologies and concepts involved in the embodiments of this application are first introduced.

[0072] 1. EASDF

[0073] As shown in Figure 2, the communication system in the related art includes: EASDF, NWDAF, SMF, AMF, NRF, PCF, AF, UDM and other network elements, as well as user equipment (UE, also known as terminal), access network (AN), UPF (Uplink Classifier (UL CL) / Branching Point (BP)), UPF (Central Protocol Data Unit (PDU) Session Anchor (PDU Session Anchor, PSA) (C-PSA)), UPF (Local PSA (L-PSA)), central domain name (Domain Name, DN), local DN, edge application server (EAS), etc.

[0074] EASDF is a 3GPP core network element proposed by SA2 and used to process DNS query requests sent by user equipment (UE, also known as terminal).

[0075] In related technologies, a terminal sends a DNS query request to the EASDF. Based on the DNS query request, the EASDF determines whether to send the DNS query request to the central DNS (C-DNS) or the local DNS (L-DNS). It then sends information such as the fully qualified domain name (FQDN) in the DNS query request to the SMF. The SMF provides the EASDF with the Internet Protocol (IP) address of the corresponding DNS server, such as the IP address of the C-DNS or L-DNS. After the C-DNS or L-DNS finds the IP address corresponding to the FQDN, it sends it to the EASDF. The EASDF saves the DNS query result to the SMF and then sends it to the terminal. In this way, the terminal obtains the IP address of the server corresponding to the requested FQDN.

[0076] 2. Roaming Traffic Diversion

[0077] The home operator, or the Home Public Land Mobile Network (HPLMN), authorizes the roaming operator, or the Visited Public Land Mobile Network (VPLMN), to use HR-SBO. After HR-SBO authorization, the roaming operator can divert certain terminal traffic directly to the home operator's servers, rather than routing it back to the HPLMN through the Home Routing Session (HR session).

[0078] After HR-SBO is authorized, the HPLMN can send the authorized FQDN list and EAS IP list.

[0079] In the embodiment of the present application, authorization can also be understood as permission, or permission, or consent for the roaming operator to divert traffic.

[0080] FQDN list: This list includes the domain names that the EASDF in the roaming location is allowed to query by DNS. FQDNs that the EASDF in the roaming location is not allowed to query by DNS must be sent back to the home operator for DNS query or resolution;

[0081] EAS IP List: This list includes the IP addresses of servers that roaming terminals are allowed to directly access locally or reach via local routing data. For servers that are not allowed to be directly accessed locally or reach via local routing data, routing is not allowed. Alternatively, the IP addresses in this list are servers that roaming terminals can access via the roaming network, local routing, or local locations, or servers that are not allowed to be accessed via the roaming network, local routing, or local locations.

[0082] The roaming SMF (V-SMF) will obtain the authorized IP address range from the home SMF (H-SMF). That is to say, only within this IP address range will local breakout be authorized, and the V-SMF will be authorized to directly establish a roaming user plane connection to the EAS IP.

[0083] The above mechanism in the related art is applicable to the scenario where the terminal sends the DNS query request to the roaming EASDF (V-EASDF), but there is no clear provision for the scenario where the terminal sends the DNS query request to the local DNS server (local DNS server).

[0084] The above introduces the relevant technologies and concepts involved in the embodiments of the present application. Now, in combination with the accompanying drawings, the information processing method provided by the embodiments of the present application is described in detail through some embodiments and their application scenarios.

[0085] FIG3 is a flowchart of an information processing method according to an embodiment of the present application, which includes the following steps:

[0086] S310: A first communication device receives first information, where the first information includes a first address;

[0087] S320: The first communication device determines whether the first address is an address of an authorized local route according to the second information.

[0088] By applying the method provided in the embodiment of the present application, the first communication device receives first information, which includes a first address, and then determines whether the first address is an authorized local routing address based on the second information, and judges whether the first address is an authorized or unauthorized local routing address, so as to control access to the first address based on different judgment results and reduce management and control risks.

[0089] The technical solution provided in the embodiments of the present application can be applied to scenarios such as DNS query and network access by terminals in roaming areas.

[0090] In an embodiment of the present application, the first communication device may be a roaming session management related network element, such as a V-SMF.

[0091] The first communication device may receive first information, where the first information includes a first address. The first address may be an IP address or a FQDN.

[0092] It should be noted that, in the embodiment of the present application, the address is information used to describe a server, which can be an IP address or a domain name FQDN.

[0093] Optionally, the first information may be a first DNS response, the first DNS response carrying a first address, the first address including the FQDN and IP address of the server; the first address may be obtained by resolving the first DNS query request by the first local DNS server, and the first communication device may receive the first information from a second communication device or a third communication device. The second communication device may be a network element related to edge application services in the roaming location, such as a V-EASDF, and the third communication device may be a network element related to a user plane in the roaming location, such as a V-UPF.

[0094] For example, a possible implementation process is as follows:

[0095] After obtaining the address of the first local DNS server, the terminal may send a DNS query request to the third communication device;

[0096] The third communication device forwards the DNS query request to the first local DNS server;

[0097] After the first local DNS server resolves the first address, it sends a DNS response including the first address to the terminal;

[0098] After detecting the DNS response sent by the first local DNS server, the third communication device may send the DNS response to the second communication device, which then forwards it to the first communication device. Alternatively, the third communication device may send the DNS response to the first communication device.

[0099] In one implementation, the V-SMF sets a rule for the V-UPF, such as the N4 rule. All information received from the first local DNS server (for example, the local DNS server in the roaming area), such as the received DNS response, needs to be forwarded to the V-EASDF (first forwarded to the V-EASDF, then forwarded to the V-SMF) or V-SMF. The V-EASDF or V-SMF needs to make a judgment on the IP address of the server carried in the DNS response, such as the EAS IP address, to determine whether the IP address is the address of the authorized local route.

[0100] In this way, the first communication device can receive a DNS response, ie, first information, from the second communication device or the third communication device. The first information includes the first address.

[0101] After receiving the first information, the first communication device may determine whether the first address is an address of an authorized local route according to the second information.

[0102] The second information may be configured by a fifth communication device, where the fifth communication device is a home session management related network element, such as an H-SMF. The first communication device may receive the second information from the fifth communication device.

[0103] In one implementation, the H-SMF sends the second information to the V-SMF through at least one of the following signaling:

[0104] Nsmf_PDUSession_Create response, PDU session generation response;

[0105] Nsmf_PDUSession_Update response, PDU session update response.

[0106] The second information may include at least one of the following:

[0107] The address of the authorized local router;

[0108] Do not authorize local routing addresses;

[0109] At least one third address.

[0110] There can be one or more addresses for authorized local routing, which can also be understood as authorized local traffic diversion, authorized routing to the local data network, etc. There can be one or more addresses for unauthorized local routing, which can also be understood as unauthorized local traffic diversion, unauthorized routing to the local data network, etc.

[0111] It should be noted that in the embodiments of the present application, authorized and allowed have similar meanings and can be used interchangeably.

[0112] The first communication device can accurately determine whether to authorize local routing to the first address based on the address of the authorized local route or the address of the unauthorized local route included in the second information. It can also be understood that the first communication device compares the first address with the address list of authorized local routes in the second information. If the first address can be found in the list, then the first address is considered to be an authorized local route. Similarly, if the first address is found in the address list of unauthorized local routes in the second information, then the first address is considered to be an unauthorized address. It is judged whether the first address is an authorized or unauthorized local route address so as to control access to the first address based on different judgment results and reduce management and control risks.

[0113] In one embodiment, the at least one third address may include at least one of the following:

[0114] The server IP address can be a local server address in the roaming location, a non-local address in the roaming location, or a server IP address in the home operator network;

[0115] HPLMN address;

[0116] HPLMN UPF address;

[0117] HPLMN UPF N9 tunnel information.

[0118] In one embodiment, the third address is an address of an authorized local route.

[0119] The third address, provided by the home operator, instructs the visited operator on how to handle unauthorized addresses. In one implementation, if the first address is an unauthorized locally routable address, the third address specifies how to handle the first address. Specifically, packets destined for the first address are redirected to the third address. This is similar to the case where the first address is a server that is not locally routable. In this case, packets destined for that server will be modified by the V-UPF and sent to the third address. This resolves the issue, ensuring that packets destined for unauthorized addresses are identified and forwarded to authorized addresses.

[0120] In one embodiment, at least one of the unauthorized local routing addresses corresponds to at least one third address. Multiple unauthorized local routing addresses may correspond to one third address, or one unauthorized local routing address may correspond to one third address or multiple third addresses. The so-called correspondence here means that for a data packet sent to the address of the unauthorized local routing, the address of the unauthorized local routing will be replaced with the third address. In other words, there is a correspondence or association between the address of the unauthorized local routing and the third address. This association is to replace the address of the unauthorized local routing of the data packet with the third address, and use the third address as the new destination IP address of the data packet to replace the old destination IP address (i.e., the address of the unauthorized local routing).

[0121] In one implementation, the H-SMF may instruct the V-SMF of the third address corresponding to each address that is not authorized for local routing.

[0122] In one embodiment, the UPF can identify the first address by executing a Packet Detection Rule (PDR); the UPF forwards the data packet sent to the first address to the third address through a Forwarding Action Rule (FAR). The UPF can also perform an IP address replacement operation. When a data packet is sent to a server with the first address as the destination address, the UPF replaces the destination address with the third address, and then sends the data packet to the server corresponding to the third address.

[0123] In some embodiments of the present application, when the first communication device determines that the first address is an address for authorized local routing, the first communication device may send a first indication message to the second communication device or the third communication device, and the first indication message is used to instruct the second communication device or the third communication device to send the first information to a fourth communication device, such as a terminal. That is, after the first communication device determines that the first address is an address for authorized local routing, the first communication device instructs the second communication device or the third communication device to send the first information to the terminal. After receiving the first indication message, the second communication device may send the first information to the third communication device, and the third communication device may send the first information to the fourth communication device, such as the terminal. Alternatively, the third communication device receives the first indication message from the first communication device and sends the first information to the fourth communication device, such as the terminal. In this way, the data packet of the fourth communication device can be locally routed to the first address.

[0124] In the embodiment of the present application, V-UPF is the roaming user plane, which can also be equivalent to UPF, with no functional difference.

[0125] In one embodiment, after a third communication device, such as a V-UPF, receives the first information, such as a DNS response, the V-UPF caches the DNS response; or, the V-UPF copies the DNS response and sends it to the V-EASDF or V-SMF. After the V-UPF receives the first indication information, the V-UPF then sends the first information to the terminal, or the V-UPF sends the cached first information to the terminal.

[0126] In some embodiments of the present application, when the first communication device determines that the first address is an address for which local routing is not authorized or determines that the first address is not an address for which local routing is authorized, the method may further include the following steps:

[0127] The first communication device sends a first request to the second communication device, where the first request is used to request the second communication device to send a first query request;

[0128] The first query request includes the first address.

[0129] In an embodiment of the present application, when the first communication device determines that the first address is an address for which local routing is not authorized or that the first address is not an address for which local routing is authorized, the first communication device may send a first request to the second communication device, requesting the second communication device to send a first query request, where the first query request includes the first address. After receiving the first request, the second communication device may send the first query request.

[0130] In one embodiment, if the V-SMF determines that the first address is an address for unauthorized local routing or determines that the first address is not an address for authorized local routing, the V-SMF sends an EASDF DNS context update request (Neasdf_DNSContext_Update Request) to the V-EASDF, where the request includes the first address or the second address. For example, the first address is the FQDN corresponding to the address for unauthorized local routing, and the second address is the address of the DNS server that resolves the FQDN.

[0131] Optionally, the second communication device can send the first query request to the default DNS server, or send the first query request to the home EASDF (H-EASDF), and the second communication device can receive the address obtained by re-query from the default DNS server or H-EASDF, such as address A. The first query request contains the first address, and the first address at this time is the FQDN, that is, the domain name corresponding to the address that is not authorized for local routing. Optionally, the second communication device can return address A to the first communication device, and the first communication device uses address A to replace the first address, update the first information, and then send the updated first information to the fourth communication device, such as the terminal, through the second communication device or the third communication device. Alternatively, the second communication device can send address A to the third communication device, and the third communication device sends it to the fourth communication device, such as the terminal. After obtaining address A, the fourth communication device can send a data packet to address A.

[0132] Optionally, the first request may include a second address, which is the address of the device receiving the first query request. The second address can be understood as the second address to which a DNS query is re-initiated when the address is determined to be an unauthorized local route. The DNS query needs to be sent to the second address. The second address can be the home operator's DNS server, such as the H-EASDF, a local DNS server, an HPLMN UPF address, or other addresses.

[0133] In one implementation, the second address is also sent to the visited location through the second information, that is, the second address is also provided by the H-SMF or HPLMN to the visited location operator, or provided to the V-SMF.

[0134] In one embodiment, the V-SMF generates or configures a rule for the UPF based on the second information (based on the address of the unauthorized local route in the second information): when the UPF detects an unauthorized IP address, or the UPF detects a DNS response, the UPF needs to send the DNS response to the V-EASDF or V-SMF.

[0135] V-SMF sends the N4 rule, which includes a PDR: detecting an unauthorized IP address, or detecting a DNS response, or detecting a data packet sent from the local DNS server (DNS response). When any of the above three is received, V-UPF performs a FAR and forwards the data packet to V-SMF or V-EASDF.

[0136] In another embodiment, when V-SMF or V-EASDF determines that the first address is the address of an unauthorized local route, V-SMF does not perform a secondary DNS query, but directly changes the route in V-UPF according to the third address corresponding to the first address to: after receiving a data packet sent to the first address, V-UPF forwards it to H-UPF or forwards it to the home operator, so as to avoid local access to an unauthorized address.

[0137] That is, the first communication device includes the second address in the first request sent to the second communication device, so that the second communication device can clearly identify the receiving device of the first query request.

[0138] In an embodiment of the present application, when the first communication device determines that the first address is an address for unauthorized local routing or determines that the first address is not an address for authorized local routing, it requests the second communication device to re-query instead of indicating the first address to the fourth communication device, such as the terminal. This can prevent the fourth communication device from sending data packets to the first address for unauthorized local routing, thereby reducing management and control risks.

[0139] For ease of understanding, the technical solution provided in the embodiment of the present application is explained again by taking the flow chart shown in FIG4 as an example.

[0140] Step 0: The terminal obtains the address of the first local DNS server; the V-SMF configures a routing rule for the V-UPF (or UL CL), that is, if the FQDN included in the DNS query request is in the FQDN list, the DNS query request can be routed to the local DNS server, otherwise, it is routed to the HPLMN;

[0141] Step 1: The terminal sends a DNS query request to the V-UPF;

[0142] Step 2: The V-UPF forwards the DNS query request to the first local DNS server;

[0143] Step 3: The first local DNS server resolves an EAS IP address and sends a DNS response to the terminal; the EAS IP address here may be an address that is not authorized for local routing;

[0144] Step 4: The V-UPF detects the DNS response sent by the first local DNS server and can take the following actions:

[0145] V-UPF sends the DNS response to V-EASDF (pre-configured);

[0146] Alternatively, the V-UPF sends the DNS response to the V-SMF (configured in advance).

[0147] In one embodiment, if the V-UPF sends the DNS response to the V-EASDF, the V-EASDF will continue to send the DNS response to the V-SMF. That is, the V-SMF will ultimately determine whether the EAS IP address is an address for authorized local routing.

[0148] In one implementation, the V-EASDF may also determine whether the EAS IP address is an address of an authorized local route.

[0149] Step 5: V-SMF determines whether the EAS IP address can be locally distributed according to the address range or address list of the authorized local route sent by H-SMF, or determines whether the EAS IP address is the address of the authorized local route;

[0150] Step 6: If the EAS IP address can be locally distributed or is an address authorized for local routing, the V-SMF can instruct the V-UPF to send the DNS response to the terminal; or instruct the V-EASDF to send the DNS response to the terminal through the V-UPF;

[0151] Step 7: If the EAS IP address cannot be locally diverted or is an address that is not authorized for local routing, the V-SMF can instruct the V-EASDF to use the FQDN in the DNS response to send the DNS query request to the default DNS server, or send it back to the H-EASDF of the HPLMN for re-query, so as to replace the EAS IP address with the result of the re-query and send it to the terminal.

[0152] It should be noted here that the source IP address of the DNS response sent to the terminal in step 6 or step 7 needs to be replaced with the IP address of the first local DNS server, that is, it is still considered to be the address resolved by the first local DNS server.

[0153] Through the above operation, the V-SMF can determine whether the EAS IP address included in the DNS response is the address of the authorized local route, and then determine whether to re-query based on the judgment result, which can effectively prevent the terminal from accessing the address of the unauthorized local route.

[0154] In some embodiments of the present application, when the first communication device determines that the first address is an address for which local routing is not authorized or the first address is not an address for which local routing is authorized, the method may further include the following steps:

[0155] The first communication device generates a first rule based on the second information;

[0156] The first rule includes:

[0157] Routes packets destined for the first address to the third address.

[0158] In an embodiment of the present application, the second information may include at least one of an address of authorized local routing, an address of unauthorized local routing, and at least one third address. The address of unauthorized local routing is associated with at least one third address. For example, the addresses of unauthorized local routing included in the second information include address B and address C, and the third addresses included in the second information include third address D and third address E, wherein address B and third address D are associated, and address C and third address D and third address E are associated. As described above, the association here refers to using the third address to replace the address of unauthorized local routing as the destination address for terminal communication; or, using the method of adding a packet header, the third address is used as the destination address and is added to the outside of the data packet sent to the first address as a packet header.

[0159] A first communication device receives first information including a first address. If it is determined that the first address is an address for which local routing is not authorized or that the first address is not an address for which local routing is authorized, the first communication device may generate a first rule based on the second information. The first rule includes routing data packets routed to the first address to a third address. For example, if the first address is address C, the generated first rule may include routing data packets routed to address C to third address D or third address E. This effectively prevents access to the first address for which local routing is not authorized.

[0160] In some embodiments of the present application, the first communication device may send the first rule to the third communication device.

[0161] When the first communication device determines that the first address is an address for which local routing is not authorized or that the first address is not an address for which local routing is authorized, it can generate a first rule based on the second information and send the first rule to the third communication device so that the third communication device processes the data packet sent to the first address according to the first rule.

[0162] In some embodiments of the present application, a third communication device may receive a first rule, which includes: routing a data packet routed to the first address to a third address; and when the third communication device receives a first data packet routed to the first address, routing the first data packet to the third address.

[0163] In an embodiment of the present application, a first communication device can determine whether the first address included in the first information is an address for authorized local routing. If it is determined that it is not an address for authorized local routing, the first communication device can generate a first rule based on the second information and send the first rule to a third communication device. Optionally, in this case, the first communication device can also instruct the second communication device or the third communication device to send the first information to a fourth communication device, such as a terminal. Alternatively, the third communication device can send the first information to a fourth communication device, such as a terminal, before, after, or simultaneously with sending the first information to the first communication device. The fourth communication device obtains the first address included in the first information and can send a data packet to the first address.

[0164] The third communication device may receive the first rule from the first communication device, and learn, according to the first rule, that the data packet that is routed to the first address needs to be routed to the third address.

[0165] Data packets sent by a terminal to the first address will pass through the third communication device. Upon receiving the first data packet routed to the first address, the third communication device can route the first data packet to the third address, where the server corresponding to the third address will actually provide the service. This effectively prevents access to the first address that is not authorized for local routing, or prevents local routing to the first address, thereby reducing management and control risks.

[0166] For example, the first communication device is V-SMF, the third communication device is V-UPF, and the fourth communication device is a terminal. V-SMF can configure an EAS IP address for authorized local routing for V-UPF by default for an FQDN. The information on which this configuration is based is sent by H-SMF to V-SMF. It is equivalent to H-SMF sending a list. If the first address included in the first information received by V-SMF is an EAS IP address for unauthorized local routing in this list, the first address needs to be replaced. That is, when the terminal sends a data packet to an IP address for unauthorized local routing, V-UPF replaces the IP address according to the configuration of V-SMF, such as replacing EAS IP address 1 for unauthorized local routing with EAS IP address 2 for authorized local routing, and routing the terminal's data packet to the EAS IP address that meets the requirements.

[0167] That is, when a terminal performs a DNS query, if the queried address is an authorized local router address, the terminal's data packets can be locally diverted. If the queried address is not an authorized local router address, the terminal sends the data packet to the address normally, and the V-UPF replaces the destination IP address of the data packet. The terminal is unaware of this process and still believes that the data packet is obtained from an unauthorized address, but the server actually serving the terminal has been replaced by the server corresponding to the third address. This can effectively prevent the terminal from accessing addresses that are not authorized local router addresses.

[0168] Optionally, the third address may include a home communication device address, a roaming communication device address, or an address authorized for local routing.

[0169] If the third address is an address for authorized local routing, the third communication device may route the data packet that is routed to the first address for which local routing is not authorized to the third address for which local routing is authorized.

[0170] The third address may be another server in the roaming location, for example, a server having the same domain name as the server corresponding to the first address but a different IP address.

[0171] If the third address includes the address of a home communications device, such as an H-UPF, the third communications device can route packets destined for the first address, which does not authorize local routing, back to the home operator and send them to the first address via the home operator's N6 interface. The third address can be the address of the H-UPF, the HPLMN, or other similar devices.

[0172] In some embodiments of the present application, the method may further include the following steps:

[0173] Step 1: The third communication device receives a second data packet from a third address;

[0174] Step 2: The third communication device sends a second data packet to the fourth communication device.

[0175] That is, if the first address is an address for which local routing is not authorized or the first address is not an address for which local routing is authorized, upon receiving a first data packet routed to the first address, the third communication device routes the first data packet to the third address. The communication device corresponding to the third address can then return a second data packet. After receiving the second data packet from the third address, the third communication device can then send the second data packet to the fourth communication device. From the perspective of the fourth communication device, the fourth communication device is interacting with the communication device corresponding to the first address.

[0176] For ease of understanding, the embodiments of the present application are described with reference to the following specific examples.

[0177] When the V-UPF receives a data packet sent to an EAS IP A that is not authorized for local routing, it routes the data packet to the H-UPF and then accesses the EAS IP A from the HPLMN's N6. This is equivalent to taking a detour and still accessing a server through the home network, rather than directly accessing the server from the roaming network through the local N6 interface.

[0178] As shown in Figure 5, a possible implementation process is as follows:

[0179] Step 1: The V-UPF receives a packet destined for an EAS IP address that is not authorized for local routing.

[0180] Step 2: The V-UPF executes the Forwarding Action Rule (FAR) and performs an outer header creation operation on the received data packet, adding a packet header with the destination address being the H-UPF address or the HPLMN address to route the data packet to the H-UPF (which can also be considered as IP address replacement).

[0181] Step 3: V-UPF sends the data packet with the added header to H-UPF;

[0182] Step 4: After receiving the data packet, the H-UPF executes the Packet Detection Rule (PDR) to remove the outer header of the data packet, removing the header added by the V-UPF. The H-UPF rules are provided by the H-SMF.

[0183] Step 5: If it is found that the data packet after removing the header is sent to the EAS IP address, the H-UPF routes it out from the home operator's data network in a normal manner, that is, routes the data packet normally to the EAS IP address, such as sending it through the home operator's N6 interface.

[0184] Optionally:

[0185] When the H-UPF receives a data packet from the EAS IP address, the H-UPF adds a header to the data packet, adds the address of the destination V-UPF to the data packet header, and routes the data packet to the V-UPF;

[0186] After receiving the data packet, the V-UPF removes the external header of the received data packet and routes the data packet back to the terminal side.

[0187] In an embodiment of the present application, if the first address is an address for which local routing is not authorized, the third communication device will route the received data packets sent to the first address back to the local operator, and access the first address through the N6 interface of the local operator, so that access to the first address is within a controlled range, which can effectively reduce the management and control risks.

[0188] Corresponding to the above method embodiment, the embodiment of the present application further provides an information processing method, as shown in FIG6 , the method includes the following steps:

[0189] S610: The second communication device receives a first request, where the first request is used to request the second communication device to send a first query request, where the first query request includes a first address, where the first address is an address that is not authorized for local routing.

[0190] S620: The second communication device sends a first query request.

[0191] By applying the method provided in the embodiment of the present application, after the second communication device receives the first request, it sends a first query request according to the first request. The first query request includes a first address for unauthorized local routing. That is, when the first address is an address for unauthorized local routing, the address query is performed again to avoid access to the first address for unauthorized local routing and reduce management and control risks.

[0192] In some embodiments of the present application, the first request includes a second address, and the second address is an address of a device that receives the first query request.

[0193] The information processing method provided in the embodiment of the present application can implement the various processes implemented in the method embodiment shown in Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0194] Corresponding to the above method embodiment, the embodiment of the present application further provides an information processing method, as shown in FIG7 , the method includes the following steps:

[0195] S710: The third communication device receives a first rule, where the first rule includes routing a data packet routed to a first address to a third address, where the first address is an address that is not authorized for local routing or is not an address that is authorized for local routing;

[0196] S720: Upon receiving the first data packet routed to the first address, the third communication device routes the first data packet to the third address.

[0197] By applying the method provided in the embodiment of the present application, the third communication device routes the first data packet to the third address according to the first rule when receiving the first data packet routed to the first address that is not authorized for local routing, so as to effectively avoid local routing to the first address and reduce management and control risks.

[0198] In some embodiments of the present application, the first rule is generated based on the second information, and the second information includes at least one of the following:

[0199] The address of the authorized local router;

[0200] Do not authorize local routing addresses;

[0201] At least one third address.

[0202] In some embodiments of the present application, an address for which local routing is not authorized is associated with at least one third address.

[0203] In some embodiments of the present application, the third address includes a home communication device address, a roaming communication device address, or an address of authorized local routing.

[0204] In some embodiments of the present application, the method further comprises:

[0205] The third communication device receives a second data packet from a third address;

[0206] The third communication device sends a second data packet to the fourth communication device.

[0207] The information processing method provided in the embodiment of the present application can implement the various processes implemented in the method embodiment shown in Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0208] The present application also provides an information processing method, as shown in FIG8 , which includes the following steps:

[0209] S810: The fifth communication device sends third information to the fourth communication device, where the third information includes an address of a first server, and the first server is used to perform domain name resolution.

[0210] The address range resolved by the first server is within the address range of the authorized local route, or the addresses resolved by the first server are all addresses of the authorized local route.

[0211] In one embodiment, the first server may be an EASDF, a local DNS server, or a DNS server, which has the following characteristics: the server addresses resolved are all authorized local routing addresses.

[0212] By applying the method provided in the embodiment of the present application, the fifth communication device sends third information to the fourth communication device, where the third information includes the address of the first server. The address range resolved by the first server is within the address range of the authorized local route, or the addresses resolved by the first server are all addresses of the authorized local route. In this way, when the fourth communication device sends a query request to the first server, the address resolved by the first server can be the address of the authorized local route, effectively preventing the fourth communication device from accessing the address of the unauthorized local route and reducing the management and control risks.

[0213] In an embodiment of the present application, the fifth communication device may be a home session management related network element, such as an H-SMF, and the fourth communication device may be a terminal or a V-SMF.

[0214] In one implementation, the H-SMF sends the third information to the V-SMF, and the V-SMF sends the third information to the terminal.

[0215] The fifth communications device determines the first server according to at least one of the following:

[0216] Edge Deployment Information (EDI); EDI includes the IP address range that can be resolved by each DNS server, or the IP address range corresponding to each Data Network Access Identifier (DNAI).

[0217] The fifth communication device compares the address of the authorized local router with the IP address range in the EDI information. The IP address range in the EDI should be within the address range of the authorized local router.

[0218] For example, the IP range given in the EDI information is 100.1.1.1-100.1.1.100; if the authorized address range sent by the H-SMF is smaller than the IP range of the EDI, then an unauthorized IP address may be resolved, because the IP address range given by the EDI is the entire local IP address range of the roaming location.

[0219] When the fourth communication device is in a roaming location, the fifth communication device may send third information to the fourth communication device, where the third information includes the address of the first server, such as the address of the first local DNS server.

[0220] The fourth communication device may send a DNS query request to the first server. The first server performs domain name resolution according to the DNS query request to obtain a corresponding address, and then returns a DNS response to the fourth communication device. The DNS response includes the address obtained by the query / resolution.

[0221] The address range resolved by the first server and assigned by the fifth communication device to the fourth communication device is within the address range of the authorized local route. Therefore, the address resolved by the first server is an address of the authorized local route. Alternatively, all addresses resolved by the first server are addresses of the authorized local route. This ensures that the addresses locally routed to the fourth communication device when roaming are all addresses of the authorized local route, preventing access to addresses not authorized for the local route and reducing management and control risks.

[0222] In some embodiments of the present application, the method may further include:

[0223] The fifth communication device determines the first server according to at least one of the following:

[0224] The address range of authorized local routes;

[0225] The address range for which local routing is not authorized;

[0226] At least one address range that the server can resolve.

[0227] It is understandable that the address ranges that can be resolved by different servers for performing domain name resolution may be the same or different. The fifth communication device can accurately determine the first server to be assigned to the fourth communication device based on the address range of the authorized local route, the address range of the unauthorized local route, or the address range that can be resolved by at least one server, to ensure that the address range resolved by the first server is within the address range of the authorized local route, or that all addresses resolved by the first server are addresses of the authorized local route.

[0228] For example, if the EAS IP range 100.1.XX-100.2.XX is an address range for which local routing is not authorized, then, by comparing the EAS IP range that can be resolved by the local DNS server, a local DNS server whose resolvable EAS IP range does not include the EAS IP range 100.1.XX-100.2.XX is selected, and the selected local DNS server is assigned to the fourth communication device, such as the terminal.

[0229] The information processing method provided in the embodiment of the present application can be executed by an information processing device. In the embodiment of the present application, the information processing device provided in the embodiment of the present application is described by taking the information processing device executing the information processing method as an example.

[0230] As shown in FIG9 , the information processing device 900 includes the following modules:

[0231] A first receiving module 910 is configured to receive first information, where the first information includes a first address;

[0232] The first determining module 920 is configured to determine, based on the second information, whether the first address is an address of an authorized local route.

[0233] The device provided in the embodiment of the present application is used to receive first information, which includes a first address. Then, based on the second information, it is determined whether the first address is an address for authorized local routing, and whether the first address is an address for authorized or unauthorized local routing is judged, so as to control access to the first address based on different judgment results and reduce management and control risks.

[0234] In some embodiments of the present application, the information processing device 900 further includes a first sending module configured to:

[0235] When it is determined that the first address is an address for which local routing is not authorized or when it is determined that the first address is not an address for which local routing is authorized, sending a first request to the second communication device, where the first request is used to request the second communication device to send a first query request;

[0236] The first query request includes the first address.

[0237] In some embodiments of the present application, the first request includes a second address, and the second address is an address of a device that receives the first query request.

[0238] In some embodiments of the present application, the information processing device 900 further includes a generating module for:

[0239] generating a first rule based on the second information when it is determined that the first address is an address for which local routing is not authorized or when it is determined that the first address is not an address for which local routing is authorized;

[0240] The first rule includes:

[0241] Routes packets destined for the first address to the third address.

[0242] In some embodiments of the present application, the information processing device 900 further includes a second sending module, configured to:

[0243] The first rule is sent to the third communication device.

[0244] In some embodiments of the present application, the second information includes at least one of the following:

[0245] The address of the authorized local router;

[0246] Do not authorize local routing addresses;

[0247] At least one third address.

[0248] In some embodiments of the present application, an address for which local routing is not authorized is associated with at least one third address.

[0249] In some embodiments of the present application, the third address includes a home communication device address, a roaming communication device address, or an address of authorized local routing.

[0250] The information processing device 900 provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0251] As shown in FIG10 , the information processing device 1000 includes the following modules:

[0252] A second receiving module 1010 is configured to receive a first request, where the first request is used to request the second communication device to send a first query request, where the first query request includes a first address, where the first address is an address that does not authorize local routing;

[0253] The third sending module 1020 is configured to send a first query request.

[0254] By applying the device provided in the embodiment of the present application, after receiving the first request, a first query request is sent according to the first request, and the first query request includes a first address for unauthorized local routing. That is, when the first address is an address for unauthorized local routing, the address query is performed again to avoid access to the first address for unauthorized local routing and reduce management and control risks.

[0255] In some embodiments of the present application, the first request includes a second address, and the second address is an address of a device that receives the first query request.

[0256] The information processing device 1000 provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 6 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0257] As shown in FIG11 , the information processing device 1100 includes the following modules:

[0258] The third receiving module 1110 is configured to receive a first rule, the first rule comprising: routing a data packet routed to a first address to a third address, the first address being an address for unauthorized local routing or an address not for authorized local routing;

[0259] The routing module 1120 is configured to, upon receiving a first data packet routed to the first address, route the first data packet to a third address.

[0260] By applying the device provided in the embodiment of the present application, according to the first rule, when receiving a first data packet routed to a first address that is not authorized for local routing, the first data packet is routed to a third address to effectively avoid local routing to the first address and reduce management and control risks.

[0261] In some embodiments of the present application, the first rule is generated based on the second information, and the second information includes at least one of the following:

[0262] The address of the authorized local router;

[0263] Do not authorize local routing addresses;

[0264] At least one third address.

[0265] In some embodiments of the present application, an address for which local routing is not authorized is associated with at least one third address.

[0266] In some embodiments of the present application, the third address includes a home communication device address, a roaming communication device address, or an address of authorized local routing.

[0267] In some embodiments of the present application, the information processing device 1100 further includes a fourth receiving module and a fourth sending module;

[0268] a fourth receiving module, configured to receive a second data packet from a third address;

[0269] The fourth sending module is used to send the second data packet to the fourth communication device.

[0270] The information processing device 1100 provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 7 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0271] As shown in FIG12 , the information processing device 1200 includes the following modules:

[0272] a fifth sending module 1210, configured to send third information to a fourth communication device, where the third information includes an address of a first server, and the first server is configured to perform domain name resolution;

[0273] The address range resolved by the first server is within the address range of the authorized local route, or the addresses resolved by the first server are all addresses of the authorized local route.

[0274] Using the device provided in the embodiment of the present application, a third message is sent to the fourth communication device, where the third message includes the address of the first server. The address range resolved by the first server is within the address range of the authorized local route, or the addresses resolved by the first server are all addresses of the authorized local route. In this way, when the fourth communication device sends a query request to the first server, the address resolved by the first server can be the address of the authorized local route, effectively preventing the fourth communication device from accessing the address of the unauthorized local route and reducing the management and control risks.

[0275] In some embodiments of the present application, the information processing device 1200 further includes a second determining module configured to:

[0276] The first server is determined according to at least one of the following:

[0277] The address range for which local routing is authorized; the address range for which local routing is not authorized; and the address range that can be resolved by at least one server.

[0278] The information processing device 1200 provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 8 and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0279] As shown in Figure 13, an embodiment of the present application further provides a communication device 1300, including a processor 1301 and a memory 1302, wherein the memory 1302 stores a program or instruction that can be run on the processor 1301. For example, when the communication device 1300 is a first communication device, the program or instruction is executed by the processor 1301 to implement the various steps of the method embodiment shown in Figure 3 above, and can achieve the same technical effect. When the communication device 1300 is a second communication device, the program or instruction is executed by the processor 1301 to implement the various steps of the method embodiment shown in Figure 6 above, and can achieve the same technical effect. When the communication device 1300 is a third communication device, the program or instruction is executed by the processor 1301 to implement the various steps of the method embodiment shown in Figure 7 above, and can achieve the same technical effect. When the communication device 1300 is a fifth communication device, the program or instruction is executed by the processor 1301 to implement the various steps of the method embodiment shown in Figure 8 above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0280] An embodiment of the present application further provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the method embodiment shown in Figure 3, Figure 6, Figure 7, or Figure 8. This network-side device embodiment corresponds to the above-mentioned method embodiment on the first communication device, the second communication device, the third communication device, or the fifth communication device side, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to this network-side device embodiment and can achieve the same technical effect.

[0281] Specifically, the embodiment of the present application further provides a network side device. As shown in FIG14 , the network side device 1400 includes: a processor 1401, a network interface 1402, and a memory 1403. The network interface 1402 is, for example, a common public radio interface (CPRI).

[0282] Specifically, the network side device 1400 of the embodiment of the present application also includes: instructions or programs stored in the memory 1403 and executable on the processor 1401. The processor 1401 calls the instructions or programs in the memory 1403 to execute the methods executed by the modules shown in FIG. 9 or FIG. 10 or FIG. 11 or FIG. 12, and achieves the same technical effect. To avoid repetition, it will not be described here.

[0283] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0284] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.

[0285] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0286] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0287] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0288] An embodiment of the present application also provides a wireless communication system, including: a first communication device or a second communication device or a third communication device or a fifth communication device, the first communication device can be used to execute the steps of the method embodiment shown in Figure 3, the second communication device can be used to execute the steps of the method embodiment shown in Figure 6, the third communication device can be used to execute the steps of the method embodiment shown in Figure 7, and the fifth communication device can be used to execute the steps of the method embodiment shown in Figure 8.

[0289] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0290] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of a computer software product plus a necessary general-purpose hardware platform, or of course, by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.

[0291] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.

Claims

1. An information processing method, wherein, Comprising: A first communication device receives first information, where the first information includes a first address; The first communication device determines, according to second information, whether the first address is an address authorized for local routing.

2. The method according to claim 1, wherein, In the case where the first communication device determines that the first address is an address not authorized for local routing or determines that the first address is not an address authorized for local routing, the method further includes: The first communication device sends a first request to a second communication device, where the first request is used to request the second communication device to send a first query request; Wherein, the first query request includes the first address.

3. The method according to claim 2, wherein The first request includes a second address, where the second address is the address of the device that receives the first query request.

4. The method according to any one of claims 1 to 3, wherein, In the case where the first communication device determines that the first address is an address not authorized for local routing or determines that the first address is not an address authorized for local routing, the method further includes: The first communication device generates a first rule according to the second information; Wherein, the first rule includes: Routing a data packet routed to the first address to a third address.

5. The method according to claim 4, wherein The method further includes: The first communication device sends the first rule to a third communication device.

6. The method according to any one of claims 1 to 5, wherein The second information includes at least one of the following: Addresses authorized for local routing; Addresses not authorized for local routing; At least one third address.

7. The method according to claim 6, wherein There is an association relationship between the address not authorized for local routing and at least one third address.

8. The method according to claim 6 or 7, wherein The third address includes a home communication device address, or a roaming communication device address, or an address authorized for local routing.

9. The method according to any one of claims 1 to 8, wherein, The method further includes: The first communication device receives the second information from a fifth communication device.

10. An information processing method, wherein, Comprising: A second communication device receives a first request, where the first request is used to request the second communication device to send a first query request, the first query request includes a first address, and the first address is an address not authorized for local routing; The second communication device sends the first query request.

11. The method according to claim 10, wherein, The first request includes a second address, where the second address is the address of the device that receives the first query request.

12. An information processing method, wherein, Comprising: A third communication device receives a first rule, where the first rule includes: routing a data packet routed to a first address to a third address, and the first address is an address not authorized for local routing or is not an address authorized for local routing; In the case where the third communication device receives a first data packet routed to the first address, the third communication device routes the first data packet to the third address.

13. The method according to claim 12, wherein, The first rule is generated according to second information, and the second information includes at least one of the following: Addresses authorized for local routing; Addresses not authorized for local routing; At least one third address.

14. The method according to claim 13, wherein There is an association relationship between the address not authorized for local routing and at least one third address.

15. The method according to any one of claims 12 to 14, wherein, The third address includes a home communication device address, or a roaming communication device address, or an address authorized for local routing.

16. The method according to any one of claims 12 to 15, wherein, The method further includes: The third communication device receives a second data packet from the third address; The third communication device sends the second data packet to a fourth communication device.

17. An information processing method, wherein, Comprising: The fifth communication device sends third information to the fourth communication device, where the third information includes the address of a first server for performing domain name resolution; Among them, the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are the addresses of the authorized local route.

18. The method according to claim 17, wherein The method further includes: The fifth communication device determines the first server according to at least one of the following: The address range of the authorized local route; The address range of the non-authorized local route; The address range resolvable by at least one server.

19. An information processing apparatus, wherein, It includes: A first receiving module, configured to receive first information, where the first information includes a first address; A first determining module, configured to determine whether the first address is an address of an authorized local route according to second information.

20. The apparatus according to claim 19, wherein, The information processing device further includes a first sending module, configured to: In the case of determining that the first address is an address of a non-authorized local route or determining that the first address is not an address of an authorized local route, send a first request to the second communication device, where the first request is used to request the second communication device to send a first query request; Among them, the first query request includes the first address.

21. The device according to claim 19 or 20, wherein, The information processing device further includes a generating module, configured to: In the case of determining that the first address is an address of a non-authorized local route or determining that the first address is not an address of an authorized local route, generate a first rule according to the second information; Among them, the first rule includes: Route the data packet routed to the first address to a third address.

22. The device according to claim 21, wherein, The information processing device further includes a second sending module, configured to: Send the first rule to a third communication device.

23. An information processing apparatus, wherein, It includes: A second receiving module, configured to receive a first request, where the first request is used to request the second communication device to send a first query request, the first query request includes a first address, and the first address is an address of a non-authorized local route; A third sending module, configured to send the first query request.

24. An information processing apparatus, wherein, It includes: A third receiving module, configured to receive a first rule, where the first rule includes: route the data packet routed to the first address to a third address, and the first address is an address of a non-authorized local route or is not an address of an authorized local route; A routing module, configured to route the first data packet to the third address when receiving the first data packet routed to the first address.

25. The device according to claim 24, wherein, The information processing device further includes a fourth receiving module and a fourth sending module; The fourth receiving module is configured to receive a second data packet from the third address; The fourth sending module is configured to send the second data packet to the fourth communication device.

26. An information processing apparatus, wherein, It includes: A fifth sending module, configured to send third information to the fourth communication device, where the third information includes the address of a first server for performing domain name resolution; Among them, the address range resolved by the first server is within the address range of the authorized local route, or all the addresses resolved by the first server are the addresses of the authorized local route.

27. The apparatus according to claim 26, wherein The information processing device further includes a second determining module, configured to: Determine the first server according to at least one of the following: Address range for authorized local routing; Address range for unauthorized local routing; Address range resolvable by at least one server.

28. A communication device, wherein, Comprising a processor and a memory, the memory stores a program or instructions that can run on the processor, and when the program or instructions are executed by the processor, the steps of the information processing method according to any one of claims 1 to 18 are implemented.

29. A readable storage medium, wherein, A program or instructions are stored on the readable storage medium, and when the program or instructions are executed by a processor, the steps of the information processing method according to any one of claims 1 to 18 are implemented.

30. A chip, wherein, The chip comprises a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a program or instructions to implement the method according to any one of claims 1-18.

31. A computer program product, wherein, The computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the method according to any one of claims 1-18.

Citation Information

Patent Citations

  • Edge application server discovery method and device

    CN114125808A

  • Information transmission method and device

    CN115884155A

  • Methods and apparatuses for edge application service

    WO2023016280A1

  • Communication method and apparatus

    WO2023051427A1

  • EDI acquisition, routing reconfiguration, ECS address configuration information acquisition, DNS processing method and apparatus, and device

    WO2023213305A1