Core network access method and system, and electronic device

By generating interactive information and signaling interactions through trusted wireless LAN access devices and using hardware identification to generate a mapping subscription permanent identifier, the problem of SIM-free devices being unable to access the 5G core network is solved, and low-cost access without modification is achieved.

WO2025200832A1PCT designated stage Publication Date: 2025-10-02LENOVO (BEIJING) LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/077141
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2025-02-13
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

In the existing technology, terminal devices must carry SIM cards to support EAP-AKA authentication to access WLAN and 5G core networks, resulting in the inability to support Wi-Fi devices without SIM cards, especially increasing costs in the transformation of enterprise private networks.

Method used

Generate interactive information through the trusted wireless LAN access device, enable the terminal device to access the trusted wireless LAN, and perform signaling interaction with the core network. Use the hardware identifier to generate a mapping subscription permanent identifier, complete core network registration and session creation, and realize SIM-free access of the terminal device.

Benefits of technology

There is no need to modify the wireless environment, which reduces the cost of terminal equipment accessing the 5G core network and enables devices that do not support the first wireless communication function to operate through the first wireless communication function.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025077141_02102025_PF_FP_ABST
    Figure CN2025077141_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention provides a core network access method and system, and an electronic device. The method comprises: in response to an access request of a terminal device not supporting a first wireless communication function, a trusted wireless local area network access device generates interaction information, such that the terminal device accesses a trusted wireless local area network; and on the basis of the access request of the terminal device, the trusted wireless local area network access device performs signaling interaction with a core network, such that the terminal device accesses the core network by means of the first wireless communication function.
Need to check novelty before this filing date? Find Prior Art

Description

Core network access method, system and electronic equipment

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on March 29, 2024, with application number 2024103832291 and invention name “Core Network Access Method, System and Electronic Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present disclosure relates to the field of wireless communication technologies, and in particular to a core network access method, system, and electronic device. Background Art

[0003] Currently, the convergence of wireless local area network (WLAN) access and 5G core network access, leveraging the 3rd Generation Partnership Project (3GPP) standard and existing market solutions, requires terminals to rely on a Subscriber Identity Module (SIM) card and use the Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) authentication method supported by the SIM card to facilitate access authentication between the WLAN and core network. This requires terminals to carry a 5G Subscription Permanent Identifier (SUPI) or a Globally Unique Temporary UEI (GUTI), which is unavailable for most SIM-free Wi-Fi devices on the market. This inability to accommodate a wider range of terminals, particularly those in enterprise private networks, results in high costs for 5G private network transformation. Summary of the Invention

[0004] The present disclosure provides a core network access method, system and electronic device to at least solve the above technical problems existing in the prior art.

[0005] According to a first aspect of the present disclosure, a core network access method is provided, the method comprising:

[0006] In response to an access request from a terminal device that does not support the first wireless communication function, the trusted wireless local area network access device generates interaction information so that the terminal device accesses the trusted wireless local area network;

[0007] Based on the access request of the terminal device, the trusted wireless local area network access device performs signaling interaction with the core network, so that the terminal device accesses the core network through the first wireless communication function.

[0008] In one possible implementation manner, the trusted wireless local area network access device includes a first module, and the trusted wireless local area network access device generates interaction information so that the terminal device accesses the trusted wireless local area network; including:

[0009] The first module of the trusted wireless local area network access device generates interaction information so that the terminal device accesses the trusted wireless local area network, including:

[0010] Acquire the hardware identification of the terminal device through a first module of the trusted wireless local area network access device, and generate a mapping subscription permanent identifier based on the hardware identification;

[0011] Based on the mapping subscription permanent identifier, the network management interface of the core network is called to sign a contract and open an account;

[0012] After signing the contract and opening the account, the terminal device is connected to the trusted wireless local area network.

[0013] In one possible implementation manner, the trusted wireless local area network access device further includes a second module and a third module, and the trusted wireless local area network access device performs signaling interaction with the core network, including:

[0014] The second module obtains a mapping subscription permanent identifier from the first module;

[0015] Performing core network registration with a mobility management function entity of the core network based on the mapping subscription permanent identifier;

[0016] After the core network registration is completed, the second module establishes a connection with the core network;

[0017] After receiving the registration completion information, the first module interacts with the terminal device and initiates a session creation notification to the second module;

[0018] The second module receives the session creation notification sent by the first module, and creates a session based on the session creation notification; wherein the session creation notification is generated by the first module;

[0019] After the session is established, the second module sends the received session resource initialization request information to the first module for processing; the session resource initialization request information is sent by the core network;

[0020] The first module processes the session resource initialization request information;

[0021] The second module receives the session resource initialization request information processed by the first module, and sends session resource initialization response information to the receiving session management network element of the core network.

[0022] In one possible implementation, performing core network registration with a mobility management function entity of the core network based on the mapping subscription permanent identifier includes:

[0023] Based on the mapped subscription permanent identifier, the second module sends a registration authentication request to the mobility management function entity of the core network according to a preset policy, and receives registration completion information.

[0024] In one possible implementation, after receiving the registration completion information, the first module interacts with the terminal device, including:

[0025] The first module sends a handshake message to the terminal device through the third module according to the registration completion information;

[0026] After the handshake message is sent successfully, the first module generates a session key; the session key is used to encrypt communication data generated between the first module and the terminal device.

[0027] In one embodiment, it further includes:

[0028] In response to an IP address allocation request from a terminal device, the core network allocates an IP address to the terminal device; the IP address allocation request is generated by the first module receiving a dynamic host configuration protocol request from the terminal device.

[0029] In one possible implementation, the first module processes the session resource initialization request information, including:

[0030] Re-encapsulating the IP address and responding to a dynamic host configuration protocol request, and sending the result to the terminal device;

[0031] Bind core network session information, generate downlink tunnel information and feed it back to the core network;

[0032] The uplink tunnel information, downlink tunnel information and uplink interface information are sent to the data plane processing unit of the trusted wireless local area network access device to complete the encapsulation and decapsulation of the data message.

[0033] In one possible implementation manner, the first module adopts a trusted wireless local area network controller, the second module adopts a trusted wireless local area network intercommunication network element, and the third module adopts a trusted wireless local area access point.

[0034] According to a second aspect of the present disclosure, a core network access system is provided, the system comprising:

[0035] A responding unit, configured to generate interaction information by the trusted wireless local area network access device in response to an access request from a terminal device that does not support the first wireless communication function, so that the terminal device accesses the trusted wireless local area network;

[0036] An access unit is configured to perform signaling interaction between the trusted wireless local area network access device and the core network based on an access request of the terminal device, so that the terminal device accesses the core network through a first wireless communication function.

[0037] According to a third aspect of the present disclosure, there is provided an electronic device, including:

[0038] at least one processor; and

[0039] a memory communicatively connected to the at least one processor; wherein,

[0040] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the method described in the present disclosure.

[0041] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute the method described in the present disclosure.

[0042] The disclosed core network access method, system, and electronic device utilize a trusted wireless local area network access device as a conversion tool. After accessing a terminal device, the device interacts with a core network that has a first wireless communication function, thereby enabling a terminal device that does not support the first wireless communication function to access the core network through the first wireless communication function. This enables terminal devices that do not support the first wireless communication function to operate using the first wireless communication function. The technical solution of this application enables terminal devices to access the core network through the trusted wireless local area network access device, eliminating the need to modify the wireless environment and reducing costs.

[0043] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] The above and other objects, features and advantages of the exemplary embodiments of the present disclosure will become readily understood by reading the detailed description below with reference to the accompanying drawings, in which several embodiments of the present disclosure are shown by way of example and not limitation, wherein:

[0045] In the drawings, the same or corresponding reference numerals denote the same or corresponding parts.

[0046] FIG1 shows a schematic diagram of a first implementation flow of a core network access method according to an embodiment of the present disclosure;

[0047] FIG2 shows a second schematic diagram of the implementation process of the core network access method according to an embodiment of the present disclosure;

[0048] FIG3 shows a schematic diagram of the structure of the core network access system according to an embodiment of the present disclosure;

[0049] FIG4 shows a schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0050] To make the purposes, features, and advantages of the present disclosure more apparent and understandable, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present disclosure without creative work shall fall within the scope of protection of the present disclosure.

[0051] The core network access method, system and electronic device provided by this application are introduced below with reference to the accompanying drawings.

[0052] As shown in FIG1 , an embodiment of the present application provides a core network access method, the method comprising:

[0053] S101, in response to an access request from a terminal device that does not support a first wireless communication function, a trusted wireless local area network access device generates interaction information so that the terminal device accesses a trusted wireless local area network;

[0054] Among them, the first wireless communication function can be 5G, the second wireless communication function can be a wireless communication network such as WIFI, and the terminal device can be a smart phone, tablet computer, laptop computer, virtual reality device, etc. that can access the Internet through a wireless communication network.

[0055] As shown in Figure 2, the trusted wireless LAN access device in the present application can be a trusted WLAN access network (Trusted WLAN Access Networ, TWAN). It can be understood that the TWAN in the present application includes multiple modules, among which the trusted wireless LAN access device may include a trusted WLAN controller (Trusted WLAN Access Controlle, TWAC). In the present application, the TWAC of the TWAN interacts with the terminal device. For example, the TWAC can obtain the hardware identification of the terminal device, generate a mapping identifier, or connect the terminal device to the trusted wireless LAN access device through a wireless communication network.

[0056] It should be noted that a terminal device that does not support the first wireless communication function can access a trusted wireless LAN access device through a second wireless communication function. For example, if the first wireless communication function is 5G and the second wireless communication function is WIFI, the terminal device can access the trusted wireless LAN access device through WIFI.

[0057] For example, a terminal device that does not support the first wireless communication function is a WLAN device that does not support 5G access capability (Non-5G-Capable over WLAN, N5CW). After the N5CW enters the wireless local area network area of ​​the trusted WLAN access device TWAN, the trusted WLAN controller TWAC of TWAN can obtain the hardware identification of the N5CW, generate a mapping identifier, or connect the N5CW to the TWAN through the wireless communication network. Among them, whether it is generating a mapping identifier or connecting the N5CW to the TWAN, the N5CW is associated with the TWAN. It should be noted that there is no subscriber identity module (SIM) in the N5CW device in this application, so the 5G network is not supported.

[0058] S102: Based on the access request of the terminal device, the trusted wireless local area network access device performs signaling interaction with the core network, so that the terminal device accesses the core network through the first wireless communication function.

[0059] It can be understood that in this application, signaling interaction is performed between the trusted wireless LAN access device and the core network supporting the first wireless communication function to obtain signaling interaction information, which ultimately enables the terminal device to access the core network. Subsequently, data can be efficiently transmitted through the data channel between the TWAN data plane and the data plane of the core network. Specifically, in this application, the trusted wireless LAN access device is divided into a control plane and a data plane. The control plane is used to access and open up the data path between the terminal and the core network, and the data plane is used for the transmission of data traffic of the terminal device through the core network.

[0060] Among them, the core network in this application is the 5G core network, which includes the access and mobility management network element (Access and Mobility Function, AMF), the authentication service network element (Authentication Server Function, AUSF), the unified data management network element (Unified Data Repository, UDM) and the session management network element (Session Management Function, SMF). Among them, AMF is responsible for user access and mobility management, AUSF is responsible for authenticating user 3GPP and non-3GPP access, UDM is responsible for user contract data management, and SMF is responsible for user session management.

[0061] For example, the core network supporting the first wireless communication function is the 5G core network, which interacts with the 5G core network through a trusted wireless LAN access device, and then N5CW accesses the 5G core network, thereby realizing the transmission of data traffic of N5CW through the 5G core network.

[0062] The core network access device provided by this application first accesses a terminal device that does not support the first wireless communication function through the first module of the trusted wireless LAN access device, and then performs signaling interaction with the core network that supports the first wireless communication function through the second module of the trusted wireless LAN access device, thereby finally enabling the terminal device to access the core network. Subsequently, data can be efficiently transmitted through the data channel between the data plane of the trusted wireless LAN access device and the data plane of the core network. This application enables the terminal device to access the core network through the trusted wireless LAN access device without modifying the wireless environment, thereby reducing the modification cost.

[0063] In some optional embodiments, the trusted wireless local area network access device includes a first module, wherein the trusted wireless local area network access device generates interaction information so that the terminal device accesses the trusted wireless local area network; including:

[0064] The first module of the trusted wireless local area network access device generates interaction information so that the terminal device accesses the trusted wireless local area network, including:

[0065] Acquire the hardware identification of the terminal device through a first module of the trusted wireless local area network access device, and generate a mapping subscription permanent identifier based on the hardware identification;

[0066] Based on the mapping subscription permanent identifier, the network management interface of the core network is called to sign a contract and open an account;

[0067] After signing the contract and opening the account, the terminal device is connected to the trusted wireless local area network.

[0068] Specifically, as shown in Figure 2, in this application, the first module can be a trusted WLAN controller, and the hardware identifier of the terminal device can be a hardware identifier such as the terminal's Media Access Control (MAC). The MAC address can be used to confirm the location of the network device. The MAC address is unique worldwide. The first module can then map the MAC address to a subscription permanent identifier (SUPI). The SUPI is a 5G globally unique subscription permanent identifier assigned to each user and is defined in 3GPP specification TS23.501. The SUPI value is stored in the UDM or other storage network element of the 5G core network. The SUPI is typically a string of 15 decimal digits. The first three digits represent the mobile country code, and the next two or three digits represent the mobile network code, which identifies the network operator. The remaining nine or ten digits are called the mobile user identification number, which represents an individual user of that specific operator. The first module then uses the SUPI to call the core network's network management interface to sign up with the UDM to open an account. After the signing and account opening are completed, the terminal device can be connected to the trusted wireless local area network.

[0069] For example, after the N5CW device that needs to access the 5G core network enters the wireless LAN area of ​​TWAN, TWAN's TWAC obtains the MAC address of the N5CW device and generates SUPI based on the MAC address. At this time, TWAC sends a station addition configuration networking message to TWAN's trusted wireless access point (Trusted WLAN Access Controller, TWAP), adds the station to TWAP, and then TWAC calls the network management interface to sign and open an account in the UDM of the 5G core network. After signing and opening the account, the N5CW device is connected to the wireless LAN provided by TWAN.

[0070] As an embodiment, when there are multiple N5CW devices that need to access the 5G core network, TWAC can determine whether to select a group, thereby obtaining the group information or the MAC address of the device, generating a mapped SUPI, and then TWAC calls the network management interface to sign a contract and open an account in the UDM of the 5G core network. After signing the contract and opening the account, the N5CW device is connected to the wireless LAN provided by TWAN.

[0071] In some optional embodiments, the trusted wireless local area network access device further includes a second module and a third module, and the trusted wireless local area network access device performs signaling interaction with the core network, including:

[0072] The second module obtains a mapping subscription permanent identifier from the first module;

[0073] Performing core network registration with a mobility management function entity of the core network based on the mapping subscription permanent identifier;

[0074] After the core network registration is completed, the second module establishes a connection with the core network;

[0075] After receiving the registration completion information, the first module interacts with the terminal device and initiates a session creation notification to the second module;

[0076] The second module receives the session creation notification sent by the first module, and creates a session based on the session creation notification; wherein the session creation notification is generated by the first module;

[0077] After the session is established, the second module sends the received session resource initialization request information to the first module for processing; the session resource initialization request information is sent by the core network;

[0078] The first module processes the session resource initialization request information;

[0079] The second module receives the session resource initialization request information processed by the first module, and sends session resource initialization response information to the receiving session management network element of the core network.

[0080] It is understandable that in the present application, the second module may be a trusted WLAN controller, and the third module, as an access point of a wireless local area network access device, performs information access and transmission with the terminal device. In the present application, the second module can obtain the SUPI from the first module. Then, the second module registers with the AMF of the core network via a jump interface based on the SUPI on behalf of the N5CW device. After registration is complete, the second module sends a completion signal to the first module. The first module further exchanges data with the core network. After receiving the registration completion message, the first module exchanges information with the terminal device and initiates a session creation notification to the second module. The second module receives the session creation notification sent by the first module and creates a session based on the session creation notification. After the session is established, the second module sends the received session resource initialization request information to the first module for processing. The session resource initialization request information is sent by the core network. The first module processes the session resource initialization request information. The second module receives the processed session resource initialization request information from the first module and sends a session resource initialization response information to the receiving session management network element of the core network, enabling the terminal device to access the core network.

[0081] For example, after TWAC signs a contract and opens an account, TWIF obtains SUPI from TWAC. Then, TWIF, on behalf of the N5CW device, goes to the AFM of the 5G core network through the jump interface based on SUPI to perform the registration and authentication process. After the registration and authentication are completed, TWIF notifies TWAC that the core network registration is completed. TWIF then interacts with the core network further, such as handshaking and requesting IP address allocation, and finally obtains the processed session resource initialization request information. Specifically, in this application, the terminal device sends a Dynamic Host Configuration Protocol (DHCP) request to the first module. The first module processes the DHCP request and initiates a session creation notification to the second module. The second module then performs a session creation process with the core network on behalf of the terminal device. After the session is established, the second module receives a session resource initialization request message from the core network and sends it to the first module. The first module processes the IP address in the session resource initialization request message and sends it to the terminal device. After the session resource initialization request and session resource initialization response are exchanged, the TWAC obtains the uplink direction, i.e., the tunnel endpoint identifier (TEID) of the GTPU assigned by the core network, which is the UP tunnel identification ID. The core network also obtains the TEID of the GTPU assigned in the TWAN. After the terminal device accesses the core network, the terminal device's data traffic is transmitted through the GTPU tunnel between the first module and the core network.

[0082] For example, the N5CW device sends a DHCP request to TWAC, TWAC processes the DHCP request of the N5CW device and initiates a session creation notification to TWIF; TWIF performs a session creation process with the core network on behalf of the N5CW device, and TWIF receives the session resource initialization request information sent by the core network, extracts the preset information and sends it to TWAC. After receiving the preset information, TWAC re-processes and encapsulates the IP address through the DHCP module and sends it to the terminal device, and sends the TEID allocated by the core network to the data plane for encapsulating the GTPU data message in the uplink direction. At the same time, a local TEID will be generated and replied to the core network in the session resource initialization response. The core network is used to encapsulate the GTPU data message in the downlink direction, so that the terminal device can access the core network through the first wireless communication function, thereby realizing the transmission of data traffic between the terminal device and the core network.

[0083] It should be noted that in this application, TWIF and TWAC are used to complete signaling interaction with the core network to realize the transmission of terminal device data between the terminal device and the core network. In this application, the control plane of the trusted wireless LAN access device is used to open the data path between the terminal device and the core network, thereby realizing the data traffic transmission between the terminal device and the core network through the data path.

[0084] In some optional embodiments, performing core network registration with a mobility management function entity of the core network based on the mapping subscription permanent identifier includes:

[0085] Based on the mapped subscription permanent identifier, the second module sends a registration authentication request to the mobility management function entity of the core network according to a preset policy, and receives registration completion information.

[0086] In some optional embodiments, after receiving the registration completion information, the first module interacts with the terminal device, including:

[0087] The first module sends a handshake message to the terminal device through the third module according to the registration completion information;

[0088] After the handshake message is sent successfully, the first module generates a session key; the session key is used to encrypt communication data generated between the first module and the terminal device.

[0089] It is understood that after the second module sends the registration and authentication process to the AMF, and after successful registration, the first module initiates a four-way handshake with the terminal device through the third module. After the handshake is successful, the first module generates a session key and sends it to the third module. The session key encrypts the communication data between the first module and the terminal device.

[0090] For example, the third module in this application is TWAP of TWAN. TWIF sends a registration and authentication process to AMF. After successful registration, TWAC initiates an air interface four-way handshake to the N5CW device through TWAP. It can be understood that if the registration is unsuccessful, the handshake message cannot be initiated. Similarly, after the handshake is successful, TWAC generates a session key and sends it to TWAP to encrypt the communication data between TWAP and the terminal device. In this application, TWIF is used to represent N5CW in the core network for registration and authentication.

[0091] In some optional embodiments, the method further includes:

[0092] In response to an IP address allocation request from a terminal device, the core network allocates an IP address to the terminal device; the IP address allocation request is generated by the first module receiving a dynamic host configuration protocol request from the terminal device.

[0093] In this application, after the handshake is successful, the terminal device sends an IP address allocation request to the first module, and the core network allocates an IP address to the terminal device, so that the terminal device can transmit data with the core network.

[0094] For example, the N5CW device requests an IP address from TWAC through TWAP based on a DHCP request. The TWACIP is assigned to the terminal device by the core network. After the terminal device obtains the IP address, it is used for subsequent data traffic transmission.

[0095] In some optional embodiments, the first module processes the session resource initialization request information, including:

[0096] Re-encapsulating the IP address and responding to a dynamic host configuration protocol request, and sending the result to the terminal device;

[0097] Bind core network session information, generate downlink tunnel information and feed it back to the core network;

[0098] The uplink tunnel information, downlink tunnel information and uplink interface information are sent to the data plane processing unit of the trusted wireless local area network access device to complete the encapsulation and decapsulation of the data message.

[0099] Specifically, the session resource initialization request information in this application includes: an IP address, uplink tunnel information, uplink interface information, and a user device identifier. After receiving the session resource initialization request information, the first module first re-processes and encapsulates the IP address via the DHCP module and sends it to the terminal device. The first module then binds the core network session information, generates downlink tunnel information, and sends the uplink and downlink tunnel information and uplink interface information (N3IP) to the VPP, assisting the VPP data plane in encapsulating and decapsulating GTPU data packets. The first module thus transmits data traffic through the data path between the terminal device and the core network, thus enabling the transmission of terminal device data between the data plane of the trusted wireless LAN access device and the core network.

[0100] For example, TWIF performs a session creation process on behalf of the N5CW device and the core network. TWIF receives the session resource initialization request information from the core network, extracts the terminal IP address, uplink GTPU TEID, uplink N3IP, PDUID, etc., and sends it to TWAC. After receiving it, TWAC first re-processes and encapsulates the IP address through the DHCP module and sends it to the N5CW device. TWAC binds the core network session information, generates downlink tunnel information, sends the uplink and downlink tunnel information and N3IP to VPP, and assists the VPP data plane in encapsulating and decapsulating the GTPU data message. TWAC replies to TWIF with downlink tunnel information, and TWIF performs protocol conversion and transfers the downlink tunnel information to the core network. In this application, TWIF can be used as the control plane of the wireless LAN access device, responsible for identity authentication with the core network, forming a data channel, and sending it to the data plane, thereby realizing the transmission of data traffic between the terminal device and the core network.

[0101] In some optional embodiments, the first module adopts a trusted wireless local area network controller, the second module adopts a trusted wireless local area network intercommunication network element, and the third module adopts a trusted wireless local area access point.

[0102] Specifically, in this application, the first module adopts a trusted wireless LAN controller TWAC, the second module adopts TWIF, and the third module adopts TWAP.

[0103] As shown in FIG3 , the present application provides a core network access system, wherein the system includes:

[0104] A response module 301 is configured to generate interaction information by a trusted wireless local area network access device in response to an access request from a terminal device that does not support a first wireless communication function, so that the terminal device can access the trusted wireless local area network;

[0105] The access module 302 is configured to perform signaling interaction between the trusted wireless local area network access device and the core network based on the access request of the terminal device, so that the terminal device accesses the core network through the first wireless communication function.

[0106] In some optional embodiments, the trusted wireless local area network access device includes a first module, and the response module 301 includes:

[0107] The first acquisition unit is configured to generate interaction information for the first module of the trusted wireless local area network access device so that the terminal device can access the trusted wireless local area network, including:

[0108] A mapping unit, configured to obtain a hardware identification of the terminal device through a first module of a trusted wireless local area network access device, and generate a mapping subscription permanent identifier based on the hardware identification;

[0109] A signing unit, configured to call a network management interface of a core network to sign a contract and open an account based on the mapped subscription permanent identifier;

[0110] The first access unit is used to connect the terminal device to a trusted wireless local area network after signing a contract and opening an account.

[0111] In some optional embodiments, the trusted wireless local area network access device further includes a second module and a third module, and the access module 302 includes:

[0112] The second module obtains a mapping subscription permanent identifier from the first module;

[0113] Performing core network registration with a mobility management function entity of the core network based on the mapping subscription permanent identifier;

[0114] After the core network registration is completed, the second module establishes a connection with the core network;

[0115] An interaction unit, configured for the first module to interact with the terminal device after receiving the registration completion information, and to initiate a session creation notification to the second module;

[0116] a session creation unit, configured for the second module to receive a session creation notification sent by the first module and to create a session based on the session creation notification; wherein the session creation notification is generated by the first module;

[0117] A first sending unit is configured to send, after the session is established, the received session resource initialization request information by the second module to the first module for processing; the session resource initialization request information is sent by the core network;

[0118] An initialization unit, configured for the first module to process the session resource initialization request information;

[0119] The second sending unit is used for the second module to receive the session resource initialization request information processed by the first module and send the session resource initialization response information to the receiving session management network element of the core network

[0120] In some optional embodiments, the registration unit includes:

[0121] The registration subunit is configured to subscribe to a permanent identifier based on the mapping, and the second module sends a registration authentication request to the mobility management function entity of the core network according to a preset policy, and receives registration completion information.

[0122] In some optional embodiments, the interaction unit includes:

[0123] A first sending subunit, configured for the first module to send a handshake message to the terminal device through a third module according to the registration completion information;

[0124] The encryption subunit is used for the first module to generate a session key after the handshake message is successfully sent; the session key is used to encrypt the communication data generated between the first module and the terminal device.

[0125] Some optional embodiments further include:

[0126] The response subunit is used to respond to the IP address allocation request of the terminal device, and the core network allocates an IP address to the terminal device; the IP address allocation request is generated by the first module receiving the dynamic host configuration protocol request of the terminal device.

[0127] In some optional embodiments, the first module processes the session resource initialization request information, including:

[0128] Re-encapsulating the IP address and responding to a dynamic host configuration protocol request, and sending the result to the terminal device;

[0129] Bind core network session information, generate downlink tunnel information and feed it back to the core network;

[0130] The uplink tunnel information, downlink tunnel information and uplink interface information are sent to the data plane processing unit of the trusted wireless local area network access device to complete the encapsulation and decapsulation of the data message.

[0131] In some optional embodiments, the first module adopts a trusted wireless local area network controller, the second module adopts a trusted wireless local area network intercommunication network element, and the third module adopts a trusted wireless local area access point.

[0132] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device and a readable storage medium.

[0133] FIG4 shows a schematic block diagram of an example electronic device 400 that can be used to implement an embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0134] As shown in Figure 4, device 400 includes a computing unit 401, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 404 into a random access memory (RAM) 403. Various programs and data required for the operation of device 400 can also be stored in RAM 403. Computing unit 401, ROM 402, and RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to bus 404.

[0135] Multiple components in device 400 are connected to I / O interface 405, including: input unit 406, such as a keyboard, mouse, etc.; output unit 407, such as various types of displays, speakers, etc.; storage unit 404, such as a magnetic disk, optical disk, etc.; and communication unit 409, such as a network card, modem, wireless communication transceiver, etc. Communication unit 409 allows device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0136] The computing unit 401 may be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 401 performs the various methods and processes described above, such as the core network access method. For example, in some embodiments, the core network access method may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 404. In some embodiments, part or all of the computer program may be loaded and / or installed onto the device 400 via the ROM 402 and / or the communication unit 409. When the computer program is loaded into the RAM 403 and executed by the computing unit 401, one or more steps of the core network access method described above may be performed. Alternatively, in other embodiments, the computing unit 401 may be configured to perform the core network access method in any other appropriate manner (e.g., via firmware).

[0137] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0138] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0139] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0140] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0141] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0142] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.

[0143] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not a limitation herein.

[0144] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one such feature. Throughout the present disclosure, "plurality" means two or more, unless otherwise specifically defined.

[0145] The above description is merely a specific embodiment of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this disclosure should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

1. A core network access method, wherein: The method comprises: In response to an access request from a terminal device that does not support the first wireless communication function, the trusted wireless local area network access device generates interaction information so that the terminal device accesses the trusted wireless local area network; Based on the access request of the terminal device, the trusted wireless local area network access device performs signaling interaction with the core network, so that the terminal device accesses the core network through the first wireless communication function.

2. The method according to claim 1, wherein The trusted wireless local area network access device includes a first module, and the trusted wireless local area network access device generates interaction information so that the terminal device can access the trusted wireless local area network; including: The first module of the trusted wireless local area network access device generates interaction information so that the terminal device accesses the trusted wireless local area network, including: Acquire the hardware identification of the terminal device through a first module of the trusted wireless local area network access device, and generate a mapping subscription permanent identifier based on the hardware identification; Based on the mapping subscription permanent identifier, the network management interface of the core network is called to sign a contract and open an account; After signing the contract and opening the account, the terminal device is connected to the trusted wireless local area network.

3. The method according to claim 2, wherein: The trusted wireless local area network access device further includes a second module and a third module, and the trusted wireless local area network access device performs signaling interaction with the core network, including: The second module obtains a mapping subscription permanent identifier from the first module; Performing core network registration with a mobility management function entity of the core network based on the mapping subscription permanent identifier; After the core network registration is completed, the second module establishes a connection with the core network; After receiving the registration completion information, the first module interacts with the terminal device and initiates a session creation notification to the second module; The second module receives the session creation notification sent by the first module, and creates a session based on the session creation notification; wherein the session creation notification is generated by the first module; After the session is established, the second module sends the received session resource initialization request information to the first module for processing; the session resource initialization request information is sent by the core network; The first module processes the session resource initialization request information; The second module receives the session resource initialization request information processed by the first module, and sends session resource initialization response information to the receiving session management network element of the core network.

4. The method according to claim 3, wherein: Performing core network registration with a mobility management function entity of the core network based on the mapping subscription permanent identifier includes: Based on the mapped subscription permanent identifier, the second module sends a registration authentication request to the mobility management function entity of the core network according to a preset policy, and receives registration completion information.

5. The method according to claim 3, wherein After receiving the registration completion information, the first module interacts with the terminal device, including: The first module sends a handshake message to the terminal device through the third module according to the registration completion information; After the handshake message is sent successfully, the first module generates a session key; the session key is used to encrypt communication data generated between the first module and the terminal device.

6. The method according to claim 5, wherein: Also includes: In response to the IP address allocation request of the terminal device, the core network allocates an IP address to the terminal device; The IP address allocation request is generated by the first module receiving a dynamic host configuration protocol request from the terminal device.

7. The method according to claim 6, wherein: The first module processes the session resource initialization request information, including: Re-encapsulating the IP address and responding to a dynamic host configuration protocol request, and sending the result to the terminal device; Bind core network session information, generate downlink tunnel information and feed it back to the core network; The uplink tunnel information, downlink tunnel information and uplink interface information are sent to the data plane processing unit of the trusted wireless local area network access device to complete the encapsulation and decapsulation of the data message.

8. The method according to claim 3, wherein: The first module adopts a trusted wireless local area network controller, the second module adopts a trusted wireless local area network intercommunication network element, and the third module adopts a trusted wireless local area access point.

9. A core network access system, wherein: The system comprises: a responding unit, configured to, in response to an access request from a terminal device that does not support the first wireless communication function, generate interaction information by the first module of the trusted wireless local area network access device, so that the terminal device accesses the trusted wireless local area network; An access unit is configured to perform signaling interaction between the trusted wireless local area network access device and the core network based on an access request of the terminal device, so that the terminal device accesses the core network through a first wireless communication function.

10. An electronic device, wherein: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method and system for accessing WIFI user to core network

    CN114339769A

  • Authentication method and trusted wireless local area network interaction function equipment

    CN115065970A

  • Method and system for accessing terminal to 5G core network

    CN116321520A

  • Core network access method and system and electronic equipment

    CN118354312A

  • Connecting IMSI-less devices to the epc

    US20180227840A1