Communication system, control method thereof, and program
The communication system addresses the challenge of restricting user equipment communications by employing a tier 2 server architecture and session manager to enforce subscriber-specific restrictions, effectively managing network resources and adhering to contract terms without affecting the control plane.
Patent Information
- Application Number
- PCT/JP2025/002314
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-29
- Filing Date
- 2025-01-24
- Publication Date
- 2025-08-07
AI Technical Summary
Existing communication systems lack the ability to effectively restrict user equipment communications based on subscriber status, leading to potential misuse or overuse of network resources.
A communication system that includes a management means for managing subscriber identities with communication restrictions, utilizing a tier 2 server architecture to enforce restrictions such as low-speed access or blocking, and a session manager to dynamically update forwarding information for individual subscribers.
Enables flexible and efficient restriction of user equipment communications, reducing network load and ensuring compliance with subscriber contracts without requiring changes to the user equipment, while maintaining C-plane functionality.
Smart Images

Figure JP2025002314_07082025_PF_FP_ABST
Abstract
Description
Communication system, control method thereof, and program
[0001] The present invention relates to a communication system, a control method thereof, and a program.
[0002] A mobile communication network provides a service for user equipment to communicate with external networks. Patent Document 1 describes a method for transferring data transmitted by a user equipment to a server corresponding to a destination network.
[0003] International Publication No. 2017 / 056201
[0004] A communication carrier may restrict communications by a user equipment depending on the subscriber's status. Some aspects of the present invention aim to provide a technique for enabling communications by a user equipment to be restricted as intended.
[0005] According to some embodiments, there is provided a communications system comprising: a communications means for performing processing related to communications of user equipment; and a management means for managing subscriber identities that are subject to communication restrictions, wherein the communications means restricts communications of restricted user equipment that is associated with subscriber identities that are managed as subject to communication restrictions.
[0006] According to some embodiments, user equipment communications can be restricted as desired.
[0007] Other features and advantages of the present invention will become apparent from the following description taken in conjunction with the accompanying drawings, in which the same or similar elements are designated by the same reference numerals.
[0008] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments of the present invention, and together with the description, serve to explain the principles of the present invention. A block diagram illustrating an example configuration of a mobile communication network according to some embodiments. A block diagram illustrating an example hardware configuration of a computer according to some embodiments. A block diagram illustrating an example protocol configuration according to some embodiments. A block diagram illustrating an example configuration of a P-GW according to some embodiments. A diagram illustrating example forwarding information according to some embodiments. A flow diagram illustrating an example operation of a communication system according to some embodiments. A sequence diagram illustrating an example operation of a communication system according to some embodiments. A sequence diagram illustrating an example operation of a communication system according to some embodiments. A sequence diagram illustrating an example operation of a communication system according to some embodiments.
[0009] Hereinafter, the embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all combinations of features described in the embodiments are necessarily essential to the invention. Two or more of the features described in the embodiments may be combined in any desired manner. Furthermore, the same reference numerals are used to designate identical or similar components, and redundant descriptions will be omitted.
[0010] Referring to Fig. 1, a configuration of a mobile communication network 100 according to some embodiments of the present invention will be described. Fig. 1 illustrates a mobile communication network conforming to LTE (Long Term Evolution). The present invention is also applicable to mobile communication networks conforming to 3G, 5G, or other standards. The mobile communication network 100 provides communication services to a user equipment (UE) 130. The mobile communication network 100 may be composed of a communication system 110 and a communication system 120. Any of the components included in the mobile communication network 100 may be entities that perform processing related to communication of the UE 130.
[0011] The communication system 110 may include an evolved Node B (eNB) 111, a Serving Gateway (S-GW) 112, a Mobile Switching Center (MSC) 113, and a Mobility Management Entity (MME) 114. The communication system 120 may include a Packet data network Gateway (P-GW) 121, a Home Subscriber Server / Home Location Register (HSS / HLR) 124, a session manager 125, a Gateway Mobile Switching Center (GMSC) 126, an Unstructured Supplementary Service Data (USSD) gateway 127, an application server 128, and a Short Message Service Center (SMSC) 129. In the example of FIG. 1 , the communication system 110 is provided by a Mobile Network Operator (MNO), and the communication system 120 is provided by a Mobile Virtual Network Operator (MVNO). Alternatively, both communication system 110 and communication system 120 may be provided by the MNO. P-GW 121 and session manager 125 may be constructed by the MVNO itself, or may be constructed and operated by a Mobile Virtual Network Enabler (MVNE) at the request of the MVNO. S-GW 112 may be included in communication system 120 provided by the MVNO, instead of being included in communication system 110 provided by the MNO.
[0012] The UE 130 is a device that can use communication services provided by the mobile communication network 100. The UE 130 may be, for example, a mobile phone, a personal computer, a sensor, an actuator, or the like. In particular, the UE 130 may be an Internet of Things (IoT) device. The UE 130 includes a SIM 131. The SIM 131 is an integrated circuit that stores data and programs used for communication with the mobile communication network 100. The SIM 131 may be an embedded SIM (eSIM) or a physical SIM. The SIM 131 stores an International Mobile Subscriber Identity (IMSI) assigned by an operator of the communication system 120. The IMSI is an example of subscriber identification information uniquely assigned for each subscription. The SIM 131 may store only one IMSI or multiple IMSIs. When SIM 131 stores multiple IMSIs, UE 130 may select one of the multiple IMSIs to communicate with mobile communication network 100 or another mobile communication network. The multiple IMSIs may be stored in physically different SIMs or may be stored in the same SIM.
[0013] The mobile communication network 100 provides a packet communication function between the UE 130 and the external network 140. A packet is an IP datagram, an Ethernet frame, or any protocol data unit, which is a data unit transmitted and received at the network layer according to the Internet Protocol (IP).
[0014] The eNB 111 connects the UE 130 to the S-GW 112 and forwards packets between the UE 130 and the S-GW 112. In this specification, entities of the mobile communication network 100 (e.g., the eNB 111, the S-GW 112, the P-GW 121, etc.) may add / modify / delete portions of packets (e.g., headers) or split or combine packets when forwarding packets. Thus, forwarding a packet may involve transmitting a received packet as is, or transmitting a new packet based on at least a portion of the received packet. The eNB 111 further provides the UE 130 with a radio resource management function, a mobility management function, a scheduling function, etc. The eNB 111 connects the UE 130 to the MSC 113 and forwards data between the UE 130 and the MSC 113. The data transferred between the UE 130 and the MSC 113 may include voice data, messages, etc.
[0015] The HSS / HLR 124 manages information about subscribers of the mobile communication network 100. For example, the HSS / HLR 124 stores subscriber location information, service subscription information, authentication information, etc., and adds, changes, deletes, etc., this information.
[0016] The S-GW 112 provides a function for routing packets from or to the UE 130. The S-GW 112 corresponds to a Serving GPRS Support Node (SGSN) in a 3G network.
[0017] The P-GW 121 has a function of providing the UE 130 with access to the external network 140. The P-GW 121 is a gateway device that functions as an endpoint of a core network included in the mobile communication network 100. The external network 140 is a network different from the mobile communication network 100. The external network 140 may include a public network such as the Internet, or may include a private network provided by an individual company or the like. The P-GW 121 corresponds to a GGSN (Gateway GPRS Support Node) in a 3G network, and an SMF (Session Management Function) and UPF (User Plane Function) in a 5G network.
[0018] Packets from the eNB 111 to the P-GW 121 are transferred in an encapsulated state through a tunnel (GTP tunnel) established in accordance with the GPRS Tunneling Protocol (GTP). Instead of the GTP tunnel, another L2 (Layer 2) tunnel may be used.
[0019] The P-GW 121 may be configured with one or more tier 1 servers 122 and one or more tier 2 servers 123. In the example of FIG. 1 , the P-GW 121 is configured with a plurality of tier 1 servers 122 and a plurality of tier 2 servers 123. The tier 1 server 122 is connected to the S-GW 112. The tier 1 server 122 receives a packet sent by the UE 130 and forwarded by the S-GW 112. The tier 1 server 122 forwards this packet to one of the one or more tier 2 servers 123. In addition, the tier 1 server 122 forwards a packet received from the external network 140 by one of the tier 2 servers 123 to the S-GW 112.
[0020] The tier 2 server 123 receives packets forwarded from the tier 1 server. The tier 2 server 123 may forward these packets to the external network 140. As described below, any of the multiple tier 2 servers 123 may discard at least a portion of the packets forwarded from the tier 1 server 122. The tier 2 server 123 may provide various services for communications by the UE 130. For example, the tier 2 server 123 may function as a NAT (Network Address Translation) that performs processing in the network layer or as a proxy that performs processing in the application layer. Furthermore, the tier 2 server 123 may process images and videos, assign credentials, and the like on behalf of the UE 130.
[0021] The upper limit of the number of servers that can be simultaneously connected to the S-GW 112 as the P-GW 121 is determined by the MNO. Therefore, in this embodiment, by separating the P-GW 121 into a server (tier 1 server 122) that exchanges packets (data) with the S-GW 112 and a server (tier 2 server 123) that provides access to the external network 140 and various additional services, the number of tier 2 servers 123 can be increased beyond the upper limit of the number of connections set by the MNO.
[0022] The session manager 125 is a server for controlling the operation of the P-GW 121. The session manager 125 may also be called a control server. For example, the session manager 125 may select the tier 2 server 123 to which the tier 1 server 122 forwards packets. The detailed operation of the session manager 125 will be described later.
[0023] The MSC 113 is a switching center that sets up and releases a call path with the UE 130. The MSC 113 forwards data received from the UE 130 to the GMSC 126 or the SMSC 129. For example, the MSC 113 may forward an SMS message sent by the UE 130 to the SMSC 129. The MSC 113 may forward a USSD message sent by the UE 130 to the GMSC 126.
[0024] The MME 114 is an entity that performs location information and paging of the UE 130, mobility control, establishment and deletion of bearers, etc. The MME 114 may authenticate the UE 130 based on authentication information notified from the HSS / HLR 124.
[0025] The GMSC 126 is a switching center that interconnects with the telephone network and other mobile communication networks. The GMSC 126 may forward a USSD message received from the UE 130 via the MSC 113 to a USSD gateway 127. The USSD gateway 127 forwards the USSD message to an application server 128. The application server 128 processes the USSD message. For example, the application server 128 may convert the USSD message to the TCP / IP protocol and transmit it to the external network 140.
[0026] The SMSC 129 is a switching center that transmits and receives SMS messages. The SMSC 129 may forward an SMS message received from the UE 130 via the MSC 113 to an SMSC 141 in another mobile communication network, or may transmit the SMS message to a destination UE 130 connected to the mobile communication network 100. The SMSC 129 may also transmit an SMS message received from the SMSC 141 to a destination UE 130 connected to the mobile communication network 100.
[0027] Next, an example of a hardware configuration of a computer 200 according to some embodiments will be described with reference to Fig. 2. The computer 200 may be used to implement any of the components of the mobile communication network 100. The components of the mobile communication network 100 may be implemented by a single computer 200, or may be distributed and implemented across multiple computers 200. Furthermore, two or more components of the mobile communication network 100 may be implemented by a single computer 200.
[0028] The computer 200 may be located in an on-premises environment. Alternatively or additionally, a cloud may be configured by multiple computers 200, and any component of the mobile communication network 100 may be implemented by a virtual machine in the cloud (i.e., as a cloud instance). The cloud may be a public cloud such as Amazon Web Services (AWS), or a private cloud built for a single company. When the cloud is a public cloud, one or more tier 1 servers 122 and one or more tier 2 servers 123 may belong to a virtual private network on the cloud. For example, when the cloud is AWS, a virtual private network may be built using a Virtual Private Cloud (VPC) function.
[0029] By constructing the P-GW 121 on the cloud, it is possible to change the performance of the P-GW 121 at appropriate times according to the processing status of the P-GW 121. The change in performance of the P-GW 121 may be realized by replacing one server with another server (a server with higher or lower processing capacity than the original server) (so-called scale-up / scale-down), or by changing the number of servers (so-called scale-out / scale-in).
[0030] The computer 200 may have the hardware shown in Fig. 2. The processor 201 controls the overall operation of the computer 200. The processor 201 may be configured by, for example, a CPU (Central Processing Unit). The processor 201 may be a single processor or a set of multiple processors connected to each other so that they can communicate with each other.
[0031] The memory 202 stores programs and data used in the processing of the computer 200. The memory 202 may be configured, for example, by a combination of a random access memory (RAM) and a read-only memory (ROM). The operation of each component of the mobile communication network 100 may be performed by the processor 201 executing a program loaded into the memory 202. Alternatively, at least a portion of the operation of each component of the mobile communication network 100 may be performed by a dedicated integrated circuit such as an application specific integrated circuit (ASIC).
[0032] The input device 203 is a device for obtaining instructions from a user of the computer 200. The input device 203 may be configured, for example, by a combination of one or more of a keyboard, a button, a touchpad, and a microphone. The display device 204 is a device for visually presenting information to the user of the computer 200. The display device 204 may be, for example, a dot matrix display such as a liquid crystal display. The input device 203 and the display device 204 may be external to the computer. In this case, the computer 200 may have an interface for communicating with the external input device 203 and display device 204.
[0033] The communication device 205 is a device for communicating with devices external to the computer 200. When the computer 200 performs wired communication, the communication device 205 may be a network interface card (NIC) having a connector for connecting a cable. When the computer 200 performs wireless communication, the communication device 205 may be a wireless communication module including an antenna and a baseband processing circuit.
[0034] The secondary storage device 206 is a device for non-volatilely storing programs and data used in the processing of the computer 200. The secondary storage device 206 is configured by, for example, a hard disk drive (HDD) or a solid state drive (SSD).
[0035] Next, an example of a protocol configuration of the U-plane (user plane) of the mobile communication network 100 of Fig. 1 will be described with reference to Fig. 3. An end-to-end session 301 is established between the UE 130 and the tier 2 server 123. Packets transmitted from the UE 130 are forwarded to the tier 2 server 123 through the session 301. The tier 2 server 123 is assigned an IP address to be used in an IP connection 302 with the UE 130 and an IP address to be used in an IP connection 303 with the tier 1 server 122. IP packets from the UE 130 are forwarded through the IP connection 302, and GTP packets from the tier 1 server 122 are forwarded through the IP connection 303.
[0036] Next, an example configuration of the P-GW 121 will be described with reference to FIG. 4. For simplicity's sake, FIG. 4 will describe a case where the P-GW 121 includes one tier 1 server 122. If the P-GW 121 includes multiple tier 1 servers 122, each of the multiple tier 1 servers 122 may perform the following operations. Furthermore, in the description of FIG. 4, subscripts are added as UEs 130a to 130d to distinguish between the four UEs 130. It is assumed that the external network 140 includes a private network 140a and the Internet 140b. It is assumed that the P-GW 121 includes four tier 2 servers 123. Subscripts are added as tier 2 servers 123a to 123d to distinguish between the four tier 2 servers 123. Furthermore, the tier 2 servers 123a to 123d will be referred to as a forwarding server 123a, a forwarding server 123b, a low-speed server 123c, and a blocking server 123d according to their roles.
[0037] Assume that a telecommunications carrier (specifically, an MVNO; the same applies below) specifies that UE 130a can only access private network 140a through mobile communication network 100. Tier 1 server 122 forwards packets sent from UE 130a to forwarding server 123a. Forwarding server 123a is configured to be accessible only to private network 140a. Forwarding server 123a forwards packets forwarded from tier 1 server 122 to private network 140a. As a result, packets sent by UE 130a are forwarded only to private network 140a. UE 130a may be able to access both private network 140a and the Internet 140b. In this case, forwarding server 123a is configured to be accessible only to private network 140a and the Internet 140b.
[0038] Assume that a telecommunications carrier (specifically, an MVNO; the same applies below) specifies that UE 130b can only access the Internet 140b through the mobile communication network 100. Tier 1 server 122 forwards packets transmitted from UE 130b to forwarding server 123b. Forwarding server 123b is configured to be able to access only the Internet 140b. Forwarding server 123b forwards packets forwarded from tier 1 server 122 to the Internet 140b. As a result, packets transmitted by UE 130b are forwarded only to the Internet 140b.
[0039] Assume that UEs 130c and 130d are restricted from communicating through the mobile communication network 100. For example, communication by UE 130 may be restricted by a communication carrier when UE 130 uses up the communication capacity specified in the contract, when the contract period for the communication service expires, or when the fee for the communication service is unpaid. The restriction on communication may be a reduction in communication speed or a cut-off of communication. The following describes a case where a communication carrier can perform both a reduction in communication speed and a cut-off of communication. Alternatively, the communication carrier may be able to perform only one of a reduction in communication speed and a cut-off of communication.
[0040] Assume that the telecommunications carrier specifies that the UE 130c can only access the Internet 140b at a low speed through the mobile communication network 100. The tier 1 server 122 forwards packets transmitted from the UE 130c to the low-speed server 123c. The low-speed server 123c forwards packets forwarded from the tier 1 server 122 to the Internet 140b. As a result, packets transmitted by the UE 130c are forwarded only to the Internet 140b. Furthermore, the low-speed server 123c discards only a portion of the packets forwarded from the tier 1 server 122 and forwards the remaining packets to the Internet 140b. In this way, the low-speed server 123c reduces the communication speed of the UE 130c. For example, if the communication speed of packets forwarded from the low-speed server 123c to the Internet 140b exceeds an upper limit speed (e.g., 1 kbps) specified by the telecommunications carrier, the low-speed server 123c may discard the excess packets. UE 130c may have low speed access to a private network instead of or in addition to the Internet 140b.
[0041] Assume that the telecommunications carrier prohibits the UE 130d from communicating through the mobile communication network 100. The tier 1 server 122 forwards packets transmitted from the UE 130d to the blocking server 123d. The blocking server 123d discards all packets forwarded from the tier 1 server 122. In this manner, the blocking server 123d blocks communication of the UE 130d. The blocking server 123d may discard packets using a firewall function of an operating system (OS) (e.g., Linux (registered trademark)).
[0042] As described above, the low-speed server 123c and the blocking server 123d restrict communication of the UE 130 by discarding at least a portion of the packets forwarded from the tier 1 server 122. Therefore, both the low-speed server 123c and the blocking server 123d may be referred to as restriction servers.
[0043] An example of forwarding information 500 will be described with reference to FIG. 5 . Forwarding information 500 may be information related to the forwarding of data from UE 130 by communication system 120. In FIG. 5 , forwarding information 500 is managed in a table format. Alternatively, forwarding information 500 may be managed in another format. For example, forwarding information 500 may be managed by session manager 125. Specifically, a storage unit of session manager 125 (memory 202 or secondary storage device 206 of computer 200 constituting session manager 125) may store forwarding information 500.
[0044] The forwarding information 500 has an entry for each subscriber of the mobile communication network 100. Each entry in the forwarding information 500 represents the settings for an individual subscriber. Column 501 of the forwarding information 500 represents the identification information of each subscriber, i.e., subscriber identification information. The subscriber identification information used in the mobile communication network 100 may be any information that uniquely identifies a subscriber. In the example of FIG. 5, IMSI is used as an example of the subscriber identification information. Column 501 may include other subscriber identification information, such as a Subscription Permanent Identifier (SUPI), an ICCID, or a Mobile Station International Subscriber Directory Number (MDISDN), instead of or in addition to the IMSI. For example, column 501 may include both the IMSI and the MSISDN as subscriber identification information. When column 501 includes multiple types of subscriber identification information, column 501 may be divided into multiple columns. Additionally, if an identity of the UE 130 (eg, an International Mobile Equipment Identifier (IMEI)) is associated with a subscriber, the identity of the UE 130 may be used as the subscriber identity.
[0045] Column 502 of the forwarding information 500 indicates the identification information of the tier 2 server 123 assigned to each subscriber. When the communication system 120 includes multiple P-GWs 121, column 502 may indicate identification information indicating one of the P-GWs 121. The identification information of the tier 2 server 123 may be, for example, an identifier uniquely assigned to each tier 2 server 123 by a carrier. Alternatively, the identification information of the tier 2 server 123 may be the IP address of the tier 2 server 123. Each subscriber is assigned one of the multiple tier 2 servers 123 included in the P-GW 121. Alternatively, two or more tier 2 servers 123 having the same functions may be assigned to at least some subscribers. As described above, subscribers whose forwarding destination is the low-speed server 123c or the blocking server 123d have their packet communication restricted. On the other hand, subscribers whose forwarding destination is the forwarding server 123a or the forwarding server 123b have their packet communication unrestricted.
[0046] Column 503 of forwarding information 500 indicates whether each subscriber is authorized to use the SMS service. In the example of FIG. 5 , a subscriber whose column 503 indicates "Forward" is authorized to use the SMS service, and the mobile communication network 100 forwards the subscriber's SMS messages. A subscriber whose column 503 indicates "Block" is restricted (specifically, prohibited) from using the SMS service, and the mobile communication network 100 blocks the subscriber's SMS messages. The authorization to use the SMS service may be further specified in forwarding information 500. For example, forwarding information 500 may independently manage messages sent by UE 130 (i.e., mobile originated messages) and messages received by UE 130 (i.e., mobile terminated messages). Furthermore, forwarding information 500 may individually allow or prohibit the use of the SMS service for a specific sender or a specific destination. For example, the forwarding information 500 may prohibit general message sending and receiving by users (e.g., message sending and receiving between users), while permitting message sending and receiving between users and a telecommunications carrier's support desk or subscriber information management server.
[0047] Column 504 of forwarding information 500 indicates whether each subscriber is authorized to use the USSD service. In the example of Figure 5, a subscriber whose column 504 indicates "Forward" is authorized to use the USSD service, and mobile communication network 100 will forward the subscriber's USSD messages. A subscriber whose column 504 indicates "Block" is restricted (specifically, prohibited) from using the USSD service, and mobile communication network 100 will block the subscriber's USSD messages.
[0048] 5, SMS and USSD services are used as examples of messaging services. Alternatively, forwarding information 500 may indicate whether the subscriber is authorized to use other messaging services. For example, forwarding information 500 may indicate whether the subscriber is authorized to use calling services.
[0049] 5, session manager 125 manages subscriber identification information that is subject to communication restrictions using forwarding information 500. Furthermore, session manager 125 manages subscriber identification information that is subject to communication restrictions separately for packet communication and messaging service for each subscriber (specifically, for each subscriber identification information) using forwarding information 500. Alternatively, session manager 125 may manage subscriber identification information that is subject to communication restrictions only for packet communication, or may manage subscriber identification information that is subject to communication restrictions only for messaging service.
[0050] Session manager 125 may provide an API (Application Programming Interface) for editing forwarding information 500. Through this API, an external entity (e.g., a telecommunications carrier administrator or a billing server program) may be able to edit forwarding information 500. For example, the external entity may instruct session manager 125 to edit forwarding information 500 (e.g., delete an entry, add an entry, or change each item of an entry).
[0051] Next, an example of a control method for the communication system 120 will be described with reference to Fig. 6. The method of Fig. 6 may be repeatedly executed during operation of the communication system 120.
[0052] In S601, the session manager 125 determines whether it has received an instruction (i.e., an edit instruction) from an external entity to edit the transfer information 500. If it is determined that an edit instruction has been received ("YES" in S601), the session manager 125 transitions the process to S602, and otherwise ("NO" in S601), it repeats S601. The edit instruction may include the specification of the subscriber identification information of the subscriber to be edited and the edit content.
[0053] In S602, the session manager 125 updates the forwarding information 500 in accordance with the editing instruction. The update of the forwarding information 500 includes updating the subscriber identification information that is subject to communication restrictions. For example, if the forwarding destination (column 502) of an entry having specific subscriber identification information specified in the editing instruction is changed from a forwarding server to a slow server or a blocked server, packet communication by the UE 130 associated with this specific subscriber identification information will be restricted. If the forwarding destination (column 502) of an entry having specific subscriber identification information specified in the editing instruction is changed from a slow server or a blocked server to a forwarding server, the restriction on packet communication by the UE 130 associated with this specific subscriber identification information will be lifted. Restrictions on messaging services can also be set or lifted in a similar manner.
[0054] When multiple subscriber identities (e.g., IMSIs) are assigned to one UE 130 and an edit instruction is issued for one of the subscriber identities, session manager 125 may update only the entry for that one subscriber identity. Alternatively, session manager 125 may update not only the entry for that one subscriber identity but also the entries for the remaining subscriber identities according to the edit content of the edit instruction.
[0055] In S603, session manager 125 determines whether the update of forwarding information 500 in S602 includes a change in the forwarding destination (column 502). If session manager 125 determines that the update of forwarding information 500 includes a change in the forwarding destination ("YES" in S603), it transitions the process to S604, and otherwise ("NO" in S603), it transitions the process to S601. In S604, session manager 125 instructs tier 1 server 122 to disconnect the session with UE 130 associated with the subscriber identification information of the entry whose forwarding destination has been changed.
[0056] In S605, the tier 1 server 122 determines whether a session with the UE 130 instructed in S604 has been established. If it is determined that a session has been established ("YES" in S605), the tier 1 server 122 transitions the process to S606, and otherwise ("NO" in S605), transitions the process to S601. In S606, the tier 1 server 122 disconnects the session with the UE 130 instructed in S604.
[0057] Even if the tier 1 server 122 changes the tier 2 server 123 to which packets are forwarded, the tier 1 server 122 continues to forward packets to the previous tier 2 server 123 as long as the session with the UE 130 is maintained. Therefore, even if an instruction to restrict packet communication of a specific user equipment is issued, this restriction is not immediately reflected. Therefore, when an instruction to restrict packet communication of a specific user equipment is issued (for example, when the packet forwarding destination is changed to a low-speed server or a blocked server), the communication system 120 disconnects the session with the UE 130 so that this restriction is reflected. The same applies to lifting the restriction on packet communication of a specific user equipment.
[0058] Next, the overall operation of the communication system 120 for packet communication will be described with reference to FIGS. 7A and 7B. In the following description, processing for one specific UE 130 will be described. Unless otherwise specified, the UE 130 represents the same UE throughout FIGS. 7A and 7B. Processing related to packet communication restrictions will be mainly described in FIGS. 7A and 7B. Therefore, in FIGS. 7A and 7B, some processing for establishing a session between the UE 130 and the mobile communication network 100 may be omitted. Furthermore, the processing for establishing a session between the UE 130 and the mobile communication network 100 (e.g., the authentication processing of S701 to S706) is not limited to the example of FIG. 7A, and other processing may be performed. In the processing of FIGS. 7A to 9, communication between the UE 130 and the communication system 120 is relayed by the communication system 110. In the processing of FIGS. 7A to 9, the latter operation of two consecutive operations may be performed in accordance with the former operation, unless otherwise specified.
[0059] At S701, the UE 130 sends an attach request to the MME 114. The attach request includes subscriber identification information (e.g., IMSI) of the UE 130. At S702, the MME 114 sends an authentication information request to the HSS / HLR 124, requesting authentication information for the UE 130. The authentication information request includes the subscriber identification information (e.g., IMSI) of the UE 130. At S703, the HSS / HLR 124 responds to the MME 114 with authentication information corresponding to the subscriber identification information to be processed.
[0060] In S704, the MME 114 generates an authentication request based on the authentication information received from the HSS / HLR 124 and transmits it to the UE 130. In S705, the UE 130 responds to the authentication request. In S706, the MME 114 performs an authentication process for the UE 130 based on the response, thereby determining whether the user of the UE 130 is a legitimate user.
[0061] In the example of FIG. 7A , it is assumed that the UE 130 is properly authenticated. In step S707, the MME 114 sends a location update request to the HSS / HLR 124 to request an update of the location of the UE 130. The location update request includes the subscriber identification information (e.g., IMSI) of the UE 130 and the current location of the UE 130. The HSS / HLR 124 updates the location information of the UE 130 in response to the location update request. In step S708, the HSS / HLR 124 sends subscription information to the MME 114. The subscription information may include, for example, the content of permitted services, a subscribed access point name (APN), and settings related to quality of service (QoS). The MME 114 stores the subscription information and forwards packets from the UE 130 to the Tier 1 server 122 in subsequent processing based on the subscription information. The MME 114 also sends subscription information to the UE 130 .
[0062] When a session is to be created simultaneously with the initial connection, in S709, the MME 114 transmits a session creation request to the tier 1 server 122, requesting that a session be created between the UE 130 and the P-GW 121. The communication system 110 establishes a GTP tunnel (GTP-C) for the control plane (C-plane) between the communication system 110 and one of the one or more tier 1 servers 122, and transmits the session creation request to the tier 1 server 122 through this GTP tunnel. For example, the MME 114 selects one tier 1 server 122 from the one or more tier 1 servers 122 connected to the communication system 110 in a round-robin manner. The session creation request includes subscriber identification information (e.g., IMSI) of the UE 130. The MME 114 may transmit the session creation request to the tier 1 server 122 in response to a request from the UE 130 after the initial connection process.
[0063] In S710, the tier 1 server 122 inquires of the session manager 125 about the subscriber identification information to be processed included in the session creation request, and to which of the multiple tier 2 servers 123 the packet should be forwarded. This inquiry includes the subscriber identification information to be processed.
[0064] In S711, the session manager 125 refers to the forwarding information 500 to identify the tier 2 server 123 (column 502) associated with the target subscriber identification information (column 501) included in the query from the tier 1 server 122. As described above with respect to the forwarding information 500, if the target subscriber identification information is subject to packet communication restrictions, the session manager 125 selects the low-speed server 123c or the blocking server 123d. If the target subscriber identification information is not subject to packet communication restrictions, the session manager 125 selects the forwarding server 123a or the forwarding server 123b. The session manager 125 responds to the tier 1 server 122 with information for connecting to the identified tier 2 server 123. For example, the session manager 125 responds with routing information such as the IP address of the identified tier 2 server 123. The tier 2 server 123 identified by the session manager 125 becomes the tier 2 server 123 to which packets from the UE 130 are forwarded. The tier 1 server 122 stores the information received from the session manager 125 (including the IP address of the tier 2 server 123 to which the request is forwarded) in association with the IP address assigned to the UE 130 for subsequent processing.
[0065] In S712, the tier 1 server 122 assigns an IP address to the UE 130 and transmits this IP address to the UE 130. Furthermore, the tier 1 server 122 establishes a session between the UE 130 and the forwarding destination tier 2 server 123. A TEID (Tunnel Endpoint IDentifier) may also be agreed upon between the S-GW 112 and the tier 1 server 122, and between the tier 1 server 122 and the forwarding destination tier 2 server 123. In S713, the MME 114 notifies the UE 130 that the connection has been approved.
[0066] As described above, communication system 120 executes the processes of S701 to S713 in the C-plane regardless of whether UE 130 is subject to packet communication restriction. In this way, communication system 120 does not restrict communication in the C-plane of UE 130 even if UE 130 is subject to packet communication restriction. In other words, communication system 120 performs the same process in the C-plane for a restricted UE and a non-restricted UE if the conditions other than the packet communication restriction are the same.
[0067] In S714, the UE 130 transmits an IP packet addressed to a server in the external network 140 to the tier 1 server 122 through the session. This IP packet may be an IP packet for transmitting data of any application that uses the TCP / IP protocol stack, such as an IP packet for transmitting an HTTP request. S714 may be executed in response to a request by this application. The UE 130 sets the source IP address of this IP packet to the IP address transmitted in S712.
[0068] The subsequent processing differs depending on whether the UE 130 to be processed is restricted from packet communication. First, a case where the UE 130 to be processed is not restricted from packet communication will be described. In the example of Fig. 4 described above, UE 130a and UE 130b correspond to such UEs 130. As described above, packets transmitted from UE 130a are forwarded to forwarding server 123a, and packets transmitted from UE 130b are forwarded to forwarding server 123b.
[0069] At S720, the tier 1 server 122 forwards the IP packet sent by the UE 130 to a forwarding server (e.g., forwarding server 123a) through the session established at S712. In this forwarding, the GTP packet is sent to the IP address of the tier 2 server 123 associated with the TEID included in the GTP packet. This TEID is uniquely associated with the subscriber identity (e.g., IMSI) of the UE 130. Therefore, the IP packet sent by the UE 130 is forwarded to the tier 2 server 123 (in this example, forwarding server 123a) configured for the subscriber identity of the UE 130. The method of forwarding the IP packet to the tier 2 server 123 configured for the subscriber identity of the UE 130 is not limited to using the TEID in this manner, and other forwarding methods may also be used. At S721, the forwarding server 123a terminates the session, extracts the IP packet from the GTP packet, and forwards it to the external network 140 (e.g., private network 140a).
[0070] In S722, the forwarding server 123a receives an IP packet including a response to the request from the external network 140. In S723, the forwarding server 123a adds a GTP header to the IP packet and then forwards it to the tier 1 server 122. In S724, the tier 1 server 122 forwards the GTP packet to the UE 130 through the session. Thereafter, the tier 1 server 122 may terminate the session between the UE 130 and the forwarding server 123a.
[0071] Next, a case where packet communication of the UE 130 to be processed is restricted will be described. In the example of FIG. 4 described above, UE 130c and UE 130d correspond to such UEs 130. Packets transmitted from UE 130c are forwarded to the low-speed server 123c. Processing of packets transmitted from UE 130c may be similar to S720 to S724, except that some packets are discarded in S721. Therefore, a case where packet communication of the UE 130 to be processed is prohibited (i.e., the case where UE 130d is the UE) will be described. Packets transmitted from UE 130d are forwarded to the blocking server 123d.
[0072] In S730, the tier 1 server 122 forwards the IP packet sent by the UE 130 to the interception server 123d through the session established in S712. In this forwarding, the GTP packet is sent to the IP address of the tier 2 server 123 associated with the TEID included in the GTP packet. In S731, the interception server 123d discards the IP packet sent by the UE 130. For example, the interception server 123d may discard the GTP packet including the IP packet, or may discard the IP packet after extracting it from the GTP packet. If the IP packet is discarded, the request sent from the UE 130 in S714 may time out. In the above example, the IP packet sent by the UE 130 is sent to the tier 2 server 123 through the session. Alternatively, IP packets sent by UE 130 may be sent through a tunnel using another protocol (e.g., Segment Routing over IPv6 (SRv6)) or without using a tunnel.
[0073] As described above, the communication system 120 restricts communication in the U-plane when the UE 130 is subject to packet communication restriction. The restricted UE 130 is managed by the session manager 125 in association with subscriber identification information. Therefore, even if, for example, the SIM 131 is replaced with another UE 130, communication from a subscriber managed as a communication restriction target can be restricted as intended. According to the above-described embodiment, a restriction on packet communication of the UE 130 can be set and lifted simply by changing the forwarding destination of packets in the U-plane. Therefore, there is no need to change the settings of the UE 130 (e.g., suspend the status of the SIM 131), and therefore there is no need to reboot the UE 130 to lift the restriction. Furthermore, in the above-described embodiment, although packet communication in the U-plane is restricted, communication in the C-plane is not restricted. Therefore, excessive requests in the C-plane (e.g., session creation requests) are suppressed.
[0074] In the method of Figures 7A and 7B, the communication system 120 does not restrict communication in the C-plane but restricts communication in the U-plane. Alternatively, the communication system 120 may restrict communication patterns based on authorization information transmitted in the C-plane. For example, before transmitting the subscriber contract information in S708 described above, the HSS / HLR 124 may inquire of the session manager 125 about communication restrictions for the subscriber identification information to be processed. Based on the result of this inquiry, the HSS / HLR 124 determines the information to be transmitted to the MME 114 in S708. For example, when the HSS / HLR 124 is notified by the session manager 125 that communication restrictions are imposed on the subscriber identification information to be processed, the HSS / HLR 124 may transmit authorization information to the MME 114 including information indicating that communication has been restricted (e.g., whether data communication is permitted, maximum bit rate restrictions, whether SMS message transmission is permitted, etc.). Rejecting data communication may involve restricting communication in the U-plane without restricting communication in the C-plane, or may involve rejecting location registration or session creation in the C-plane. HSS / HLR 124 may transmit such authorization information to MME 114 not only at the time of initial connection of UE 130 but also in response to an update to forwarding information 500. Forwarding information 500 may include a setting regarding whether to restrict communication in the U-plane without restricting communication in the C-plane, or to restrict communication patterns based on authorization information transmitted in the C-plane. Session manager 125 may determine the information to transmit to MME 114 in S708 based on this setting.
[0075] The communication system 120 may execute a combination of a method of restricting communication in the U-plane without restricting communication in the C-plane, and a method of restricting communication in the C-plane without establishing a U-plane. Which of these two methods to execute may be configurable for each subscriber identification information, and this setting may be stored in the forwarding information 500.
[0076] Next, the overall operation of the communication system 120 for communicating an SMS message will be described with reference to Figure 8. The following description will explain the processing for one particular UE 130e. At S801, the UE 130e sends a transmission request to the SMSC 129 to send an SMS message. The transmission request received by the SMSC 129 includes the subscriber identification information of the UE 130e (e.g., the IMSI stored in the UE 130e or the telephone number (e.g., MSISDN) assigned to the UE 130e) and the body of the SMS message.
[0077] At S802, the SMSC 129 queries the HSS / HLR 124 to determine whether the subscriber who made the transmission request is authorized to send SMS messages. This query includes the subscriber identification information (e.g., MSISDN) of the UE 130e. At S803, the HSS / HLR 124 determines whether the subscriber identified by the subscriber identification information included in the query is authorized to send SMS messages. The HSS / HLR 124 further queries the session manager 125 to determine whether the sending of SMS messages is restricted for the subscriber identification information included in the query. This query includes the subscriber identification information (e.g., MSISDN) of the UE 130e. The session manager 125 references column 503 of the forwarding information 500 to determine whether the sending of SMS messages is restricted for the subscriber identification information (column 501) to be processed included in the query from the HSS / HLR 124.
[0078] The subsequent processing differs depending on whether the target UE 130e is restricted from sending SMS messages. First, a case will be described where the target UE 130e is not restricted from sending SMS messages. In S810, the session manager 125 notifies the HSS / HLR 124 that the target UE 130e is not restricted from sending SMS messages. In S811, if the UE 130e is authorized to send SMS messages, the HSS / HLR 124 authorizes the SMSC 129 to send the SMS message. If the UE 130e is not authorized to send SMS messages, the processing proceeds to S821, which will be described later.
[0079] In S812, the SMSC 129 transfers the SMS message sent from the UE 130e to the SMSC 141 by SMPP (Short Message Peer to Peer). In S813, the SMSC 141 returns an ACK to the SMSC 129. In S815, the SMSC 141 transmits the SMS message to the UE 130f, the destination of the SMS message. In S816, the UE 130f, which has received the SMS message, transmits a reception report to the SMSC 141. In S817, the SMSC 141 transfers this reception report to the SMSC 129. In S818, the SMSC 129 notifies the UE 130e that transmission of the SMS message has been completed. In this example, the destination of the SMS message is the UE 130 (UE 130f in the example of FIG. 8), but the destination of the SMS message may also be a server.
[0080] Next, a case where the target UE 130e is restricted from sending SMS messages will be described. In S820, the session manager 125 notifies the HSS / HLR 124 that the target UE 130e is restricted from sending SMS messages. In S821, the HSS / HLR 124 instructs the SMSC 129 to reject the transmission of the SMS message. In S822, the SMSC 129 discards the SMS message sent from the UE 130e and notifies the UE 130e that the transmission of the SMS message failed.
[0081] 8 illustrates the case where UE 130e sends an SMS message. Communication system 120 may receive an SMS message intended for UE 130e and discard the SMS message if UE 130e is restricted from using the SMS service. In this manner, communication system 120 restricts communication in the messaging service of the restricted user equipment. As described above, the sending and receiving of SMS messages may be restricted independently. Furthermore, the sending or receiving of SMS messages may be restricted or permitted only for specific destinations.
[0082] Next, the overall operation of the communication system 120 for communicating a USSD message will be described with reference to Fig. 9. In the following description, processing for one specific UE 130 will be described. Unless otherwise specified, the UE 130 represents the same UE throughout Fig. 9. In the description of Fig. 9, it is assumed that authentication of the user of the UE 130 has been completed in the same manner as in S701 to S706 of Fig. 7A.
[0083] At S901, the UE 130 calls a dedicated telephone number assigned to the GMSC 126 to send a USSD message. The call includes the subscriber identity (e.g., IMSI) of the UE 130, the telephone number (e.g., MSISDN) assigned to the UE 130, and the body of the USSD message, which may be a request for information from the application server 128.
[0084] At S902, GMSC 126 sends a USSD message requesting information to USSD gateway 127. At S903, USSD gateway 127 queries session manager 125 to determine whether the sending of USSD messages is restricted for the subscriber identity information included in the USSD message. This query includes the subscriber identity information (e.g., IMSI) of UE 130. Session manager 125 references column 504 of forwarding information 500 to determine whether the sending of USSD messages is restricted for the subscriber identity information (column 501) to be processed included in the query from USSD gateway 127.
[0085] The subsequent processing differs depending on whether the target UE 130 is restricted from sending USSD messages. First, a case will be described where the target UE 130 is not restricted from sending USSD messages. In S910, the session manager 125 notifies the USSD gateway 127 that the target UE 130 is not restricted from sending USSD messages. In S911, the USSD gateway 127 forwards the USSD message sent from the UE 130 to the application server 128. In S912, the application server 128 responds with the information requested in the USSD message. In S913, the USSD gateway 127 forwards this information to the GMSC 126. In S914, the GMSC 126 forwards this information to the UE 130.
[0086] Next, a case where the target UE 130 is restricted from sending USSD messages will be described. At S920, the session manager 125 notifies the USSD gateway 127 that the target UE 130 is restricted from sending USSD messages. At S921, the USSD gateway 127 discards the USSD message sent from the UE 130 and rejects the transmission of the USSD message to the GMSC 126. At S922, the GMSC 126 notifies the UE 130 that the transmission of the USSD message has failed.
[0087] The invention is not limited to the above-described embodiment, and various modifications and variations are possible within the scope of the gist of the invention.
[0088] This application claims priority based on Japanese Patent Application No. 2024-011230, filed January 29, 2024, the entire contents of which are incorporated herein by reference.
Claims
1. A communication system comprising: a communication means for performing processing related to communications of user equipment; and a management means for managing subscriber identification information that is subject to communication restriction, wherein the communication means restricts communications of the user equipment that is subject to restriction and is associated with the subscriber identification information that is managed as subject to communication restriction.
2. The communication system according to claim 1, wherein said communication means restricts communication in the user plane of said restricted user equipment.
3. The communication system according to claim 2, wherein said communication means does not restrict communication in the control plane of said restricted user equipment.
4. A communication system according to any one of claims 1 to 3, wherein the communication means includes: a first server that receives packets transmitted by user equipment; and a plurality of second servers that receive the packets forwarded from the first server, wherein the plurality of second servers include: a forwarding server that forwards the packets forwarded from the first server to an external network; and a restriction server that discards at least some of the packets forwarded from the first server, wherein the first server forwards to the forwarding server packets transmitted by user equipment associated with subscriber identification information whose packet communication is not restricted, and forwards to the restriction server packets transmitted by user equipment associated with subscriber identification information whose packet communication is restricted.
5. The communication system according to claim 4, wherein the restriction server discards all packets forwarded from the first server.
6. A communication system as described in claim 4 or 5, wherein the first server inquires of the management means as to which of the plurality of second servers to forward packets for the subscriber identification information to be processed, the management means identifies one of the plurality of second servers based on whether packet communication is restricted for the subscriber identification information to be processed, the first server stores the address of the second server identified by the management means, and the first server forwards packets sent from user equipment associated with the subscriber identification information to the stored address.
7. A communication system as described in claim 6, wherein, in response to receiving a session generation request including the subscriber identification information to be processed from a user equipment, the first server inquires of the management means as to which of the plurality of second servers to forward packets for the subscriber identification information to be processed.
8. A communication system according to any one of claims 1 to 7, wherein said management means updates the communication restriction settings based on an instruction from an external entity.
9. The communication system according to claim 8, wherein, when an instruction to restrict or lift the restriction on packet communication of a specific user equipment is received, if a session is established between the specific user equipment and the communication means, the communication means disconnects the session.
10. The communication system according to claim 4, wherein the plurality of second servers include: a low-speed server that discards only a portion of packets forwarded from the first server; and a blocking server that discards all packets forwarded from the first server.
11. A communication system according to any one of claims 1 to 10, wherein the communication means restricts communication in a messaging service of the user equipment to be restricted.
12. The communication system according to claim 11, wherein said communication means discards messages sent from said restricted user equipment.
13. The communication system of claim 12, wherein the message is an SMS message or a USSD message.
14. A communication system according to any one of claims 1 to 13, wherein the management means manages subscriber identification information that is subject to communication restrictions separately for packet communication and messaging services.
15. A program for causing one or more computers to function as each means of the communication system according to any one of claims 1 to 14.
16. A control method for a communication system, comprising: a communication step for performing processing related to communications of user equipment; and a management step for managing subscriber identification information that is subject to communication restriction, wherein the communication step includes restricting communications of the user equipment that is subject to restriction and associated with the subscriber identification information that is managed as subject to communication restriction.
Citation Information
Patent Citations
Congestion control system for short message service in mobile object communication and control method therefor
JP2000102071A
Communication control apparatus and communication control method
JP2013243476A
Traffic management server and management program
JP2015220559A
Control apparatus for gateway in mobile communication system
WO2017056201A1