WO2019208943A1 - Allocation method for application dedicated network, method for providing third-party billing service through same, and communication network system and user terminal implementing same - Google Patents

Allocation method for application dedicated network, method for providing third-party billing service through same, and communication network system and user terminal implementing same Download PDF

Info

Publication number
WO2019208943A1
WO2019208943A1 PCT/KR2019/003669 KR2019003669W WO2019208943A1 WO 2019208943 A1 WO2019208943 A1 WO 2019208943A1 KR 2019003669 W KR2019003669 W KR 2019003669W WO 2019208943 A1 WO2019208943 A1 WO 2019208943A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
network
data
party
policy
Prior art date
Application number
PCT/KR2019/003669
Other languages
French (fr)
Korean (ko)
Inventor
장호준
강성균
이종경
이진근
정치욱
조원창
Original Assignee
주식회사 케이티
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 주식회사 케이티 filed Critical 주식회사 케이티
Publication of WO2019208943A1 publication Critical patent/WO2019208943A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/16Central resource management; Negotiation of resources or communication parameters, e.g. negotiating bandwidth or QoS [Quality of Service]
    • H04W28/24Negotiating SLA [Service Level Agreement]; Negotiating QoS [Quality of Service]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/24Accounting or billing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/60Subscription-based services using application servers or record carriers, e.g. SIM application toolkits

Definitions

  • the present invention relates to a wireless communication network system and a data communication service thereof.
  • the user is given a certain amount of data every month according to the carrier billing plan, and the amount of data is deducted each time data is transmitted and received through the communication network. Since the user runs the application in the terminal and uses the content provided by the remote server, the user bears the communication network fee for using the content. That is, even if a user purchases a paid application or purchases paid content in the application, the user must pay the communication network fee.
  • the telecommunications company registers 5 tuples to specify the charging support target of the content provider in the core network, and changes the charging for all traffic corresponding to the registered 5 tuples to the third party content provider.
  • the P-GW needs to recognize the content server address of the packet to separate the user charge and the content provider charge, all destination information of the remote host used by the application must be provided to the carrier.
  • frequent links between applications make it difficult to determine billing targets based on content server addresses.
  • the user Since the user is forced to use the data service depending on the plan, even if the content provider wants to provide a differentiated content service, the user depends on the QoS of the communication network to which the user subscribes. Therefore, the content development of the content provider is forced to rely on the communication network.
  • the application usage depends on the user's network plan and QoS. Telcos can increase the network usage if the content provider bears the charges for traffic generated by a specific application, but it is not easy to classify the traffic used by users in the core network into personal billing and content provider billing.
  • the problem to be solved by the present invention is to allocate a dedicated network for a specific application, to provide a method for controlling access to the dedicated network of the application, and to provide a communication network system and a user terminal implementing the same.
  • the problem to be solved by the present invention is to provide a third party billing service for a specific application, in particular a method of controlling the third party billing by reflecting the third party's data billing burden policy in real time, and a communication network implementing the same It is to provide a system and a user terminal.
  • An object of the present invention is to provide a routing management method for allocating a dedicated APN or a common APN to an application under a control of a data policy controller in a terminal supporting a plurality of access point names (APNs). To provide.
  • the problem to be solved by the present invention is to provide a user interface that allows the user to simply and intuitively control the application-specific access network changes or the use of third-party billing services.
  • a method for providing a third party billing service by interworking with a core network and a terminal by a data policy controlling device the third party's data charge burden policy for a specific application, and for transmitting and receiving traffic of the specific application
  • the third party's data charge burden policy for a specific application Managing dedicated network information allocated to a core network, controlling access to a dedicated network of the specific applications installed in terminals based on the data charge burden policy, and data used for transmitting and receiving traffic of the specific application in the dedicated network; Charging the amount to the third party.
  • Each terminal installed with the specific application transmits the traffic of the specific application to the dedicated network or to the public network under the control of the data policy control device.
  • the controlling of the access to the dedicated network of the specific application may allow access to the private network so that traffic of the specific application is transmitted to the dedicated network when the data charge burden policy is valid.
  • the terminal allowed to access the dedicated network may set a first routing policy for transmitting traffic of the specific application to the dedicated network using the dedicated network access information.
  • the dedicated network access information may be an access point name (APN) of a dedicated network allocated to the core network.
  • APN access point name
  • the data charge burden policy may include the purchase data amount of the third party.
  • the controlling of access to the private network of the specific application may include: terminals that are granted access to the private network for the specific application when the amount of data charged to the third party reaches the purchase data amount of the third party. Authentication may be instructed. Each terminal deauthenticated may change to a second routing policy for transmitting traffic of the specific application to the public network.
  • the controlling of the specific network access of the specific application may include transmitting dedicated network access information allocated to the specific application to the terminals, and receiving an authentication request for access to the specific network of the specific application from any of the terminals. And authenticating a dedicated network access to the specific application based on the application authentication policy set by the third party and granting the dedicated network access to the arbitrary terminal. Traffic of the specific application executed in the arbitrary terminal may be transmitted to the dedicated network corresponding to the dedicated network access information.
  • the application authentication policy may include an identifier and integrity information of the specific application.
  • the specific application may be an enterprise-specific application connected to a corporate internal network or an application connected to a content server through an internet network.
  • the third party billing service providing method includes monitoring the remaining amount of the purchase data amount of the third party that is changed according to the transmission / reception of traffic in the dedicated network, notifying the remaining amount to the third party, and data from the third party. If the addition is requested, the method may further include updating the data charge burden policy.
  • the traffic transmitted and received on the dedicated network may be classified by application and charged to a third party corresponding to each application. have.
  • a method for routing traffic of an application to a designated network by a terminal comprising: requesting a data policy control device for authentication for a specific network connection to a specific application; Receiving an authorization result to permit, and setting a routing policy for transmitting traffic of the specific application to the dedicated network assigned to the specific application. Traffic of the specific application is delivered to the dedicated network generated in the core network based on the dedicated network access information while the authentication for the dedicated network access is valid.
  • the data policy controller may request authentication for access to the private network of the specific application.
  • the dedicated network access is allowed from the data policy control device, the specific application is located in the specific area, and if the dedicated network access is not permitted from the data policy control device, the specific application may be located outside the specific area.
  • the data policy control device In the requesting of the authentication for accessing the dedicated network, when an execution request for the specific application located in the specific area is input, the data policy control device requests authentication for accessing the dedicated network of the specific application, and the data policy control. If a dedicated network connection is not allowed from the device, the specific application may be moved out of the specific area.
  • the routing method may further include receiving, from the data policy control device, deauthentication for a dedicated network connection to the specific application, and changing to a routing policy for transmitting traffic of the specific application to a public network. .
  • the setting of the routing policy may set the routing policy of the specific application by mapping the specific application that is allowed to access the dedicated network to the routing container to which the virtual network interface is assigned.
  • the virtual network interface may be connected to a first network interface connecting to the private network.
  • Applications not mapped to the routing container may have a routing policy connected to a second network interface connecting to the public network.
  • the specific application When the specific application is a third party billing application that a third party charges for data, the specific application may indicate that the third party billing application is displayed on the user interface screen while the authentication for accessing the dedicated network is valid.
  • the setting of the routing policy may include managing first network access information for public network access and at least one second network access information for at least one private network access, and if the private network access of the specific application is allowed, The second network access information corresponding to the dedicated network may be mapped to the specific application, and if the dedicated network access of the specific application is not permitted, the first network access information may be mapped to the specific application.
  • the specific application may be an enterprise-only application or a third party billing application that a third party charges for data.
  • a third party billing application As a method of installing a third party billing application by a terminal according to another embodiment, downloading and installing installation information including a third party billing application and billing network information from an application market, and in the billing network information Accessing the instructed data policy controlling device to notify installation of the third party billing application; and setting a routing policy for mapping dedicated network access information received from the data policy controlling device to the third party billing application. Include. Traffic of the third party billing application is delivered to the dedicated network corresponding to the dedicated network access information while authentication for the dedicated network access is valid.
  • the setting of the routing policy may include requesting an authentication for access to the private network of the third party billing application to the data policy controlling device, and receiving an authentication result including access to the private network from the data policy controlling device. You can set the policy.
  • the third party billing application installation method may further include receiving an authentication release for a dedicated network access to the third party billing application from the data policy control device, and sharing the private network access information mapped to the third party billing application.
  • the method may further include setting a routing policy for changing the connection information.
  • the terminal since the terminal may additionally set the network connection information (for example, dedicated APN) different from the public network for the application connected to the private network, there is no need to change the currently set network connection information according to the application to be executed. .
  • network access information of general applications and security applications eg, enterprise applications
  • general applications and security applications can be used at the same time, and the traffic of general applications is internal to the enterprise. It can prevent the inflow into a network (intranet) and the like.
  • the internal network, etc. may be set as a target PDN (Packet Data Network) when configuring a dedicated network of the application, tunneling (VPN) for network packet security is not required.
  • PDN Packet Data Network
  • the third party may be charged for specific application traffic, thereby enabling the use of the content of the application and consequently increasing the traffic.
  • the third party may change his or her data charging burden policy in real time, and the data policy controller may reflect the third party's data charging burden policy on the terminal in real time.
  • various subjects can bear the communication network usage fee of a specific application, thereby providing various types of data network convergence applications and distributing contents.
  • traffic transmission paths of a general application charged to a user and a third party charging application may be separated.
  • the core network can charge a third party for traffic sent to a designated dedicated network without having to separate user charging and third party charging through the content server address.
  • the QoS-guaranteed private network can be assigned to a specific application, a user can use content such as a video, AR / VR game, etc. in the QoS-guaranteed private network.
  • the content provider may promote the use of the application (for example, free of data usage fee) or sell the communication network usage fee for the application as a separate product based on the amount of data / QoS purchased from the carrier. .
  • the user can easily and intuitively control the application-specific access network change or the third party billing service use request through the folder / box type container displayed on the terminal screen.
  • various subjects may pay for content distribution through the communication network as desired.
  • a communication service such as QoS optimized for the content without having to rely on the user plan.
  • 1 is a communication network system that provides a third party billing service for each application according to an exemplary embodiment.
  • FIG. 2 is a diagram illustrating an example of charging for an application according to an exemplary embodiment.
  • FIG. 3 is a view illustrating an interworking structure of a data policy control apparatus according to an embodiment.
  • FIG. 4 is a flowchart illustrating a data charging burden service providing method according to an exemplary embodiment.
  • FIG. 5 is a flowchart of a method of controlling, by a data policy control apparatus, a real-time data billing burden service according to an embodiment.
  • FIG. 6 is a flowchart illustrating a method of controlling, by a data policy control apparatus, a real-time data charging service according to another embodiment.
  • FIG. 7 is a diagram conceptually illustrating a routing container based application routing control structure according to an embodiment.
  • FIG. 8 is a diagram conceptually illustrating a routing policy management based application routing control structure according to another embodiment.
  • FIG. 9 is a diagram illustrating a dedicated network connection in a routing container based terminal structure according to an embodiment.
  • FIG. 10 is an example of a terminal interface screen including an application container according to an embodiment.
  • 11 is an example of a terminal interface screen displaying a third party billing application according to an embodiment.
  • FIG. 12 is a flowchart of a method of installing a third party billing application, according to an exemplary embodiment.
  • FIG. 13 is a diagram illustrating a method for providing a CP center dedicated network service according to an embodiment.
  • FIG. 14 is a diagram illustrating a user-selectable dedicated network service providing method according to an embodiment.
  • the devices described in the present invention are composed of hardware including at least one processor, a memory device, a communication device, and the like, and a program executed in combination with the hardware is stored in a designated place.
  • the hardware has the configuration and performance to implement the method of the present invention.
  • the program includes instructions implementing the method of operation of the present invention described with reference to the drawings, and executes the present invention in combination with hardware such as a processor and a memory device.
  • the terminal may be a mobile station (MS), a mobile terminal (MT), a subscriber station (SS), a portable subscriber station (PSS), or a user equipment (UE). It may also refer to an access terminal (AT) and the like, and may include all or some functions of a mobile station, a mobile terminal, a subscriber station, a portable subscriber station, a user device, an access terminal, and the like.
  • MS mobile station
  • MT mobile terminal
  • SS subscriber station
  • PSS portable subscriber station
  • UE user equipment
  • AT access terminal
  • the terminal may include a base station (BS), an access point (AP), a radio access station (RAS), a node B (Node B), an advanced node B (evolved NodeB, eNodeB), and a transmission / reception base station (
  • a network device such as a base transceiver station (BTS), a mobile multihop relay (MMR) -BS, a 5G NB (gNB), or the like may be connected to a remote server.
  • BTS base transceiver station
  • MMR mobile multihop relay
  • gNB 5G NB
  • the terminal may be a mobile terminal such as a smartphone, a tablet terminal such as a smart pad and a tablet PC, a computer, a television, and various types of communication terminals, and may include a plurality of communication interfaces.
  • the communication interface may vary.
  • the communication interface may be a short-range wireless network interface such as Wi-Fi / WLAN / Bluetooth, and a mobile terminal such as 3G / Long Term Evolution (LTE) / Long Term Evolution-Advanced (LTE-A) / 5G.
  • LTE Long Term Evolution
  • LTE-A Long Term Evolution-Advanced
  • the LTE EPC (Evolved Packet Core) is mainly described as an example, but may be equally applied to 5G core.
  • the public network and the private network means separate traffic paths, and are not necessarily physically separated.
  • public and private networks may be different bearers created on the same physical path.
  • the "third party billing service” is a third party pays for the user's data usage on behalf of the user, and the contract of the telecommunication company and the third party may vary.
  • the description mainly assumes that a third party purchases data from the carrier and pays for individual users within the purchased data limit, but may also be billed for post-payment of data usage without a data limit.
  • the amount of data given to the user is not deducted, it can be referred to as an unpaid / zero-rating service or a sponsored service in that a third party supports the user network fee.
  • the "third party" is sufficient to be a subject that can subscribe to the carrier product providing the third party billing service.
  • a third party may be a company that provides enterprise-specific applications connected to an internal network or a content provider (CP) that provides content applications connected to a specific content server. It does not need to be limited to the company or CP that it distributes.
  • CP content provider
  • a third party may bear data charging for the application for content (eg, a specific channel) distributed through a specific application (eg, an Oletv mobile application).
  • a third-party billing application is described as an application to which a private network is assigned as an example.
  • the dedicated network is not necessarily assigned only to the third-party billing application, and a specific application (for example, QoS guarantee is required even if user billing is required). Application, etc.) may be assigned a dedicated network.
  • the application of the present invention can be referred to as a network convergence application, data convergence application because the dedicated network is assigned and charging and QoS are controlled through it.
  • FIG. 1 is a communication network system that provides a third party billing service for each application according to an embodiment
  • FIG. 2 is a diagram illustrating an application billing according to an embodiment.
  • a communication network system includes a content provider (CP) device 100, a data policy control device 200 of a communication network, and a data policy control device that are responsible for data charging for a third party billing application. And a terminal 300 for setting a routing policy of the third party billing application under the control of 200.
  • the data policy control apparatus 200 allocates a dedicated network (dedicated data network) to a specific application designated by a CP or a user among a plurality of applications installed in the terminal, and thereby separates traffic path separation, QoS differential, and charging separation for each application. can do.
  • the CP device 100 is operated for each CP and may communicate with the data policy control device 200.
  • the CP device 100 may designate a third party billing application and transmit a data charge burden policy for the third party billing application to the data policy control device 200.
  • the CP device 100 sets and manages a data charging policy, a third party charging application authentication policy, a data charging subscriber list, and the like through an interface provided by the data policy control apparatus 200, and uses the amount of data purchased. Inquiries can be made.
  • the CP device 100 receives a report of the application state of the data charge burden policy including the remaining amount of data from the data policy control device 200.
  • the CP device 100 receives notification of the remaining amount below the standard and the restriction of the third party billing service due to reaching the contract limit. Can be.
  • the CP does not necessarily transmit a data charge burden policy, etc. to the data policy control device 200 through the CP device 100, and does not need to subscribe to the product through the data policy control device 200. That is, the CP may subscribe to the data charge burden product at the online product subscription page or the offline branch office provided by the telecommunication company, and the data charge burden policy may be transmitted to the data policy control apparatus 200.
  • the data policy control apparatus 200 may reflect the data charging burden policy of the CP to the terminal 300 in real time in association with various devices of the core network.
  • the companion devices may vary depending on the network. Typically, the companion devices may interwork with the policy and charging control device 10 and the charging device 20.
  • the policy and charging control apparatus 10 may be a Policy and Charging Control Function (PCRF) / Policy and Charging Enforcement Function (PCEF) that performs a Policy and Charging Control (PCC) function for managing policy charging information.
  • PCRF Policy and Charging Control Function
  • PCEF Policy and Charging Enforcement Function
  • PCC Policy and Charging Control
  • the policy and charging control device 10 configures a dedicated network corresponding to the data charging burden policy of the CP, and distributes dedicated network information such as a dedicated network configuration policy to the data policy control device 200 and the P-GW 33. can do.
  • the billing device 20 is a device for calculating data usage, which may vary depending on the core network.
  • the charging apparatus 20 collects data usage (CDR) from the packet data gateway (P-GW) 33.
  • Charging System Charging System
  • OCS Online Charging System
  • the P-GW 33 delivers a call detailed record (CDR) indicating a data usage amount to a charging device 20.
  • the P-GW 33 may classify an application based on information included in the CDR.
  • the data policy control apparatus 200 may request a CP dedicated network configuration from the core network and obtain CP dedicated network information from the core network.
  • the CP may subscribe to the data billing product through the sales office of the telecommunication company.
  • the data policy control apparatus 200 may obtain CP dedicated network information from the core network.
  • the data charging product may be a kind of dedicated network product.
  • the data policy control apparatus 200 manages dedicated network information of a CP that has registered a data charging burden policy.
  • the CP dedicated network information may include a dedicated network configuration policy, dedicated network access information assigned to a third party billing application of the CP, and may be transmitted from the policy and charging control device 10.
  • the data policy control apparatus 200 may transmit the private network access information to the terminal 300 to request preparation for access to the private network.
  • the third party billing application and the dedicated network access information are mapped in the terminal 300 according to the control of the data policy control apparatus 200, so that the traffic of the third party billing application may be transmitted to the dedicated network.
  • the dedicated network access information may be, for example, an access point name (APN) in an LTE network or a data network name (DNN) in a 5G network. Information for specifying.
  • APN access point name
  • DNN data network name
  • the APN is described as an example of network access information.
  • the terminal 300 Upon receiving the dedicated APN, the terminal 300 creates a virtual network interface to prepare for access to the private network.
  • the time point when the data policy control apparatus 200 transmits the dedicated APN to the terminal 300 depends on a dedicated APN allocation and delivery rule. can be different.
  • the dedicated APN may be transmitted to the terminal 300 after the configuration of the dedicated network for the data charging burden policy of the CP is completed or after the dedicated network access to the third party charging application designated by the CP is authenticated.
  • the dedicated APN may be delivered to a user terminal (eg, a GiGA Cube subscriber terminal, which is a dedicated network product) accessible to the dedicated network in a state in which the dedicated network configuration is completed in the core network.
  • a user terminal eg, a GiGA Cube subscriber terminal, which is a dedicated network product
  • the dedicated APN may be stored in advance in the routing profile of the terminal.
  • the data policy control apparatus 200 receives a third party billing (dedicated network access) for the third party billing application from the terminal 300, the terminal is based on the stored data billing burden policy / third party billing application authentication policy.
  • the third party billing application may be controlled to always be charged to the CP (third party) according to the data charge burden policy set by the CP, or charged to the CP while authentication by the data policy control apparatus 200 is valid.
  • the terminal 300 sets the public network connection information (for example, the public APN) even if the third party billing application, Treat it as a general application that is billed by the user.
  • the public network connection information for example, the public APN
  • the terminal 300 may set the dedicated APN for the third party billing application authenticated by the data policy control apparatus 200 to transmit traffic generated in the third party billing application to the dedicated network designated in the dedicated APN.
  • the access request message including the dedicated APN is transmitted to the mobility management entity (MME) 31 via the base station 30.
  • MME 31 checks the dedicated network configuration policy of the dedicated APN included in the access request message, and uses a dedicated network (dedicated bearer for transmitting and receiving traffic of the third-party charging application through the S-GW 32 and the P-GW 33). ). Through this, traffic of the third party charging application is transmitted and received through the P-GW 33 of the dedicated network allocated to the dedicated APN, and the amount of data transmitted and received in the dedicated network is collected by the charging device 20.
  • the data policy control apparatus 200 charges the CP of the data usage of each third party charging application obtained from the charging apparatus 20.
  • the data policy control apparatus 200 checks the data limit purchased by the CP (contracted), and controls the free data usage of the plurality of terminals in real time according to the remaining amount of data. For example, when the data usage of a specific CP reaches the contract limit, the data policy control apparatus 200 checks the third party billing application contracted by the specific CP, and uses the terminal 300 to check the third party billing application. May inform and indicate that the use of free data is restricted.
  • the data policy control device 200 may notify the CP device 100 of the data remaining amount to induce the purchase of additional data.
  • the data policy control apparatus 200 determines that the dedicated APN usage authority of the third party billing application is terminated when an end event such as the amount of purchase data of the CP or the contract with the CP is terminated occurs. In addition, the data policy control apparatus 200 transmits, to the terminal 300, authentication release information indicating the release of the dedicated APN connection of the third party billing application. Then, the terminal 300 changes the network access information of the third party billing application from the dedicated APN to the public APN. Since the third party billing application mapped to the public APN is connected to the public network like a general application, data usage is charged to the user.
  • a dedicated APN APN1
  • CP1 application third party billing application
  • Map them a third party billing application
  • the terminal 300 requests a connection to the APN1 from the core network according to a routing rule.
  • the CP1 may be charged for the traffic transmitted from the dedicated network.
  • the general application (CP2 APP) is connected to the public network, which is set by default to which the public APN (APN1) is mapped. The user pays for the traffic transmitted on the public network.
  • APN public APN
  • the data charge burden policy allows the CP to be subtracted from the amount of data purchased by the CP, instead of the data given to the individual user, even if the individual user uses the communication network. Through this, the customer can use the content free of charge through the third party billing application, within the data billing burden of CP.
  • the data charge burden policy may be determined as a product to which the CP subscribes to a telecommunication company, and the data policy control apparatus 200 may receive a product subscription including a data charge burden policy from the CP device 100.
  • the CP may subscribe to a dedicated network product and provide a third party billing service to customers using the third party billing application. Meanwhile, the data charging burden policy may be partially paid by the third party CP, but may be partially charged by the third party billing for the amount of data used by the individual user through the third party charging application.
  • the data charge burden policy may be variously determined according to charges and control conditions, such as a personal plan.
  • the data charge burden policy may include the amount of data purchased by the CP (eg 1 Tbyte / month), the amount of individual data the CP will provide to each customer (eg 200 Mbytes / month per customer), and the CP is charged. List of customers to be charged for, the application identifier to be charged by the CP, the content server information of the application to be charged by the CP, the time zone when the CP is charged, the QoS level, and the term of the contract (eg, one month, one week, etc.) And so on.
  • the data charge burden policy may further include an application authentication policy.
  • the data policy control apparatus 200 manages dedicated network products, policy contents, and dedicated network setting information for each CP as shown in Table 1, for example.
  • the QoS may include, for example, a guaranteed bit rate (GBR), a maximum bit rate (MBR), a QoS class identifier (QCI), and the like.
  • GBR guaranteed bit rate
  • MRR maximum bit rate
  • QCI QoS class identifier
  • the data policy control apparatus 200 may store a 5-tuple for generating a QoS policy of a product subscribed to a corresponding CP.
  • the data policy control apparatus 200 may include a CP policy management unit 210 interworking with the CP apparatus 100. And a terminal authentication unit 230 and a profile storage unit 250 interworking with the terminal 300.
  • the CP policy manager 210 and the terminal authenticator 230 may interwork with each other and manage the profile storage 250.
  • the CP policy manager 210 is described as communicating with the core network, the connection relationship between the core network and the data policy control apparatus 200 may be variously designed.
  • the CP policy management unit 210 registers the subscription of the data billing product received from the CP device 100 by interworking with the core network devices of the telecommunications company, configures a dedicated network of the data billing policy, and the third party billing application.
  • the CP may be charged for the associated data usage.
  • Core network devices to which the CP policy management unit 210 interoperates are determined according to the network. For example, the CP policy management unit 210 interworks with a business support system (BSS) for subscription of data billing products. can do.
  • BSS business support system
  • the CP policy management unit 210 may interwork with a PCRF / PCEF that performs a PCC function in order to apply the network configuration policy of the data billing product.
  • the CP policy management unit 210 may link the data usage with the OCS / OFCS.
  • the CP policy management unit 210 may check a user profile by interworking with a home subscriber server (HSS).
  • HSS home subscriber server
  • the terminal authenticator 230 authenticates access to the private network of the third party billing application installed in the terminals based on the application authentication policy specified by the CP.
  • the application authentication policy may include third party billing application information (application identifier), integrity information (Signiture), and user information to which the private network is allocated.
  • the terminal authentication unit 230 may perform application authentication in association with the application market.
  • the CP data subscription products may not be eligible for immediate payment.
  • the CP may sell the third party billing application to the individual user and generate an application authentication policy based on the user information on which the third party billing application is purchased (installed).
  • the CP device 100 may share an authentication policy by transferring an application authentication policy to the data policy control device 200.
  • the application authentication policy may be generated in the CP device 100.
  • the terminal authenticator 230 executes the third party billing application on the terminal 300 or receives a dedicated network access request (third party billing request) for the third party billing application, the terminal authentication unit 230 based on the application authentication policy specified by the CP Authenticate the private network connection to the application.
  • the authenticated third party billing application is mapped to routing information from the terminal 300 to the dedicated network.
  • the dedicated network access information (dedicated APN) may be transmitted together with the authentication for the dedicated network access request (third party billing request) or may be stored in the terminal before authentication.
  • the dedicated network access information may be previously stored in the terminal profile when the third party billing application is installed or when the exclusive network information is requested from the terminal.
  • the terminal 300 may create a virtual network interface in a routing container capable of collectively mapping the authenticated applications, and may prepare a dedicated network connection by connecting the virtual network interface to a network interface configured with a dedicated APN (FIG. 9).
  • the profile storage unit 250 stores and manages data charging burden policy, application authentication policy, dedicated network information, etc. for each CP, and is referred to by the CP policy management unit 210 and the terminal authentication unit 230.
  • the CP may directly set and manage a data charging policy, a data charging subscriber list, and the like through the CP device 100 interoperating with the data policy control apparatus 200 and inquire a data usage inquiry.
  • the CP may receive a report on the application state of the data charge burden policy including the data burden / data remaining amount through the CP device 100. Through this, CP can immediately apply the data network policy to the service provider and can grasp the usage status in real time.
  • FIG. 4 is a flowchart illustrating a data charging burden service providing method according to an exemplary embodiment.
  • the data policy control apparatus 200 receives a data charging burden product for a specific application from a CP (S110).
  • the subscription may include various data charging policies including purchase data amount, contract period, QoS, and the like.
  • the data policy control apparatus 200 registers a data charging burden product in the core network and requests a dedicated network allocation according to the data charging burden policy (S120). For example, the PCRF creates a dedicated network configuration policy and distributes the dedicated network configuration policy to the P-GW. If the P-GW is connected to the internal network rather than the public network, physical network interworking may be performed together.
  • the data policy control apparatus 200 is informed of the completion of the dedicated network configuration for the data charging burden service of the CP from the core network (S122).
  • the dedicated network configuration completion notification message includes information on a dedicated network allocated to the CP, and if the dedicated network is allocated for each CP, it may include a CP dedicated APN.
  • the data policy control apparatus 200 stores a data charging burden policy of the CP and dedicated network information allocated to the CP.
  • the data policy control apparatus 200 notifies the CP apparatus 100 of the completion of the dedicated network configuration for the data charging burden product subscribed to (S124). In other words, the data policy control apparatus 200 notifies completion of the dedicated network use of the third party billing application.
  • the data policy control apparatus 200 receives an authentication policy of a charging burden target application from the CP apparatus 100 (S130).
  • the application authentication policy may include third party billing application information (application identifier), integrity information (Signiture), and user information. If the application authentication policy requires user information on installing the corresponding application, it may be updated every time the application is installed. According to the application authentication policy, the application authentication policy may be included in the data charge burden policy and contracted.
  • the data policy control apparatus 200 receives an authentication request for access to a dedicated network of a specific application from the terminal 300 (S140).
  • the authentication may be requested by an individual application according to a method designated by an individual application or by an operation of moving an application to an application container on a display screen.
  • the data policy control apparatus 200 authenticates the application identifier included in the authentication request based on the application authentication policy and permits the terminal 300 to access the private network when the data charge burden policy is valid (data remaining amount, etc.). (S142).
  • the terminal 300 maps a specific application permitted to access the private network and dedicated network access information (dedicated APN) (S150). That is, the terminal 300 changes the routing policy so that a specific application is connected to the private network.
  • the routing policy change may use the routing container described with reference to FIG. 7 or the access network discovery and selection function (ANDSF) described with reference to FIG. 8.
  • the terminal 300 displays the user to know that the third party is charged.
  • the terminal 300 accesses the dedicated network according to the routing policy (S160).
  • the terminal 300 accesses a content server of a specific application through a dedicated network and transmits and receives traffic.
  • the dedicated network is allocated according to the data charge burden policy, and a QoS different from that of the public network can be set, and the dedicated network configuration policy is distributed to core network devices such as P-GW.
  • the data policy control apparatus 200 receives CP charging information from the charging apparatus of the core network in operation S170.
  • the dedicated network is allocated for each CP, the data usage through the dedicated network is charged to the CP as it is. If a plurality of CPs having different billing subjects are allocated one dedicated network, the amount of data to be charged by each CP may be calculated based on an identifier of a third party billing application designated by each CP.
  • the data policy control apparatus 200 reports the application state of the data charging burden policy including the remaining amount of data to the CP apparatus 100 (S180).
  • the data policy control apparatus 200 may obtain a data charge burden policy including an application authentication policy when receiving the data charge burden product of the CP.
  • the data policy control apparatus 200 when the data policy control apparatus 200 is informed of the completion of the dedicated network configuration for the data charging product of the CP from the core network, the data policy control apparatus 200 starts authentication for the dedicated network connection (third party charging) for the application designated by the CP.
  • a method of delivering a dedicated APN to a terminal has not been described in detail, but a method of delivering a dedicated APN to a terminal may be variously implemented according to the number of APNs supported by the terminal and the number of dedicated networks to which the terminal may access. Can be.
  • a dedicated network may be allocated for each CP and an APN for each dedicated network may be allocated.
  • the CP dedicated network access information (dedicated APN) can be provided to the terminal.
  • the dedicated APN and the public APN may be distinguished according to the number of APNs. If the terminal supports two APNs, the terminal creates network interfaces in the operating system (OS) kernel as a common APN (default APN) for accessing the public network and a dedicated APN for accessing the dedicated network, and accesses the dedicated network. You can prepare. Thereafter, the terminal may map the authenticated third party charging application to the dedicated APN network interface to route traffic of the third party charging application to the dedicated network. In this case, the CPs share the private network.
  • OS operating system
  • default APN default APN
  • the terminal may map the authenticated third party charging application to the dedicated APN network interface to route traffic of the third party charging application to the dedicated network.
  • the CPs share the private network.
  • FIG. 5 is a flowchart illustrating a method of controlling a real-time data billing service by a data policy controlling device according to an embodiment
  • FIG. 6 is a flowchart of a method of controlling a real-time data charging service by a data policy controlling device according to another embodiment. to be.
  • the data policy control apparatus 200 monitors a data remaining amount changed according to traffic transmission / reception in a CP dedicated network (S210).
  • the data policy control device 200 When the data remaining amount of the specific CP reaches the contract limit, the data policy control device 200 notifies the corresponding CP device of the data exhaustion schedule (S220).
  • the data policy control device 200 receives a request for data addition from the CP device (S230).
  • the data policy control apparatus 200 updates the data charge burden policy of the CP (S240).
  • the data policy control device 200 informs the CP device of the data charge burden policy update (S250).
  • the data policy control apparatus 200 monitors the amount of data remaining changed according to traffic transmission / reception in a CP dedicated network (S310).
  • the data policy control device 200 When the data remaining amount of the specific CP reaches the contract limit, the data policy control device 200 notifies the corresponding CP device of the data exhaustion schedule (S320).
  • the data policy control apparatus 200 deletes the dedicated network information allocated to the third party billing application of the CP from the application authentication policy. (S330).
  • the data policy control apparatus 200 instructs terminals that are permitted to access the private network to the third party billing application and instructs release of authentication for the dedicated network connection of the corresponding application (S340).
  • the data policy control apparatus 200 determines that the exclusive network use authority of the third party billing application has expired when an event such as a case where the contract data amount is exhausted or the contract with the CP is terminated occurs.
  • the data policy control apparatus 200 transmits to the terminal 300 authentication release information indicating that the third party billing application does not have a right to use a dedicated network.
  • the terminal 300 notified of the authentication release changes the routing policy so that the third party charging application accesses the network to the public APN charged to the user (S350). That is, the routing policy of the third party billing application is changed from the dedicated APN to the public APN.
  • the terminal 300 may respond to the authentication release notification to the data policy control apparatus 200.
  • the terminal 300 indicates that the third party billing application is changed to a general application for which the user is billed (S360).
  • the terminal 300 changes the routing policy from the CP dedicated APN to the common APN charged to the user, and then displays the state change to the general application. For example, the terminal 300 may delete the third party billing display displayed on the application icon or delete the corresponding application from the routing container included in the third party billing applications.
  • an application for specifying a network interface of a terminal operating system (OS) is separately included in the application.
  • PDN Select API for specifying a network interface of a terminal operating system (OS) is separately included in the application.
  • OS terminal operating system
  • the terminal 300 may connect a network interface allocated with a dedicated APN to an application designated by a third party or connect a network interface assigned with a common APN under the control of the data policy control apparatus 200.
  • specific application traffic may be transmitted to a dedicated network / public network under the control of the data policy control apparatus 200, and may activate a data charging service of a third party (CP).
  • CP third party
  • FIG. 7 is a diagram conceptually illustrating a routing container based application routing control structure according to an embodiment
  • FIG. 8 is a diagram conceptually illustrating a routing policy management based application routing control structure according to another embodiment.
  • the terminal 300 in order to branch (routing) the traffic of the application authenticated from the data policy control apparatus 200 to the dedicated network, the terminal 300 routes the application authenticated to the dedicated network to the dedicated APN. Function is required
  • the routing function may be implemented according to an application framework and an operating system (OS) of the terminal.
  • the terminal 300a communicates with the data policy control apparatus 200 to establish a dedicated network connection for a specific application.
  • Routing Authentication 310 for authenticating or deauthenticating Routing management unit 330a for integrating routing rules for applications, and Routing container 350 for managing dedicated network access information for specific authenticated applications.
  • the routing manager 330a manages not only a routing rule (general routing rule) for the public network connection, but also a routing rule (dedicated routing rule) for the routing container 350.
  • the general routing rule may include a routing rule that connects App1 / App2 to the public APN.
  • the routing authentication unit 310 When the routing authentication unit 310 receives a request for a dedicated network access to the app 3 / app 4 from the user, the routing authentication unit 310 requests the data policy control device 200 to authenticate the access to the dedicated network of the app 3 / app 4. The routing authentication unit 310 receives an authentication result for the dedicated network connection from the data policy control apparatus 200.
  • the routing manager 330a sets a dedicated routing rule for mapping the App 3 / App 4 to the dedicated APN. That is, the routing manager 330a manages a dedicated routing rule so that App3 / App4 is connected to the dedicated APN through the routing container 350.
  • the routing container 350 is assigned a virtual network interface for connecting an application group authenticated by the data policy control apparatus 200 to a private network according to a dedicated routing rule.
  • a common APN (default APN) for accessing the public network and a dedicated APN for accessing the dedicated network may be configured.
  • the dedicated APN is an intranet APN assigned to an enterprise dedicated network connected to an intranet of a specific company as shown in FIG. 7A, or a CP dedicated network connected to a content server of a specific CP as shown in FIG. 7B. It may be an assigned sponsor APN.
  • the data policy control apparatus 200 configures a corporate dedicated network and configures a dedicated network for delivering traffic generated in the App 3 and the App 4 to an internal network of a specific company.
  • the routing container 350 may be a container for a specific enterprise-specific application.
  • the routing authenticator 310 receives the authentication deactivation of the app 3 / app 4 from the data policy control device 200, the routing manager 330a maps the app 3 / app 4 to the general routing rule. Then, the App 3 / App 4 is connected to the public APN according to the general routing rules instead of the routing container 350 connected to the dedicated APN.
  • the data policy control apparatus 200 configures a CP dedicated network allocation and a dedicated network for delivering traffic generated in App 3 and App 4 to a specific content server.
  • Dedicated network access authentication and private network access method for the sponsor application is similar to the enterprise-specific application described in Figure 7 (a). Even though the destination PDN of the dedicated APN and the public APN are the same Internet network, the traffic paths are separated according to the APN.
  • App 3 and App 4 is not necessarily a sponsor application provided by the same CP. That is, when App3 and App4 using the same dedicated network are charged to different CPs, the charging device may classify the applications based on the application identifier or the destination address, thereby charging data usage for each application.
  • the terminal 300b may map specific authenticated applications to the routing container 350 to route them. Can not.
  • ISMP inter-system mobility policy
  • ISRP inter-system routing
  • ANDSF access network discovery and selection function
  • the ANDSF management unit 370 may further define application-specific APNs according to the extended management object (MO).
  • the extended MO is an extension of the MO defining the APN and the access network to the application and is defined so that the application-APN access network can be routed as a full set.
  • the extended MO may be further implemented in the ANDSF related model implemented in the terminal. In this way, the ANDSF management unit 370 may provide the authentication information of the dedicated network and the application required by the ISRP through the extended MO.
  • the algorithm in which the ANDSF management unit 370 adds / deletes / updates an application-based routing policy may follow a standard of OMA-DM (Device Management).
  • the routing authentication unit 310 when the routing authentication unit 310 authenticates the dedicated network connection of the app 1 from the data policy control device 200, the routing authentication unit 310 transmits the exclusive network access information (dedicated APN) of the app 1 to the ANDSF management unit 370. Then, the ANDSF management unit 370 reflects the dedicated network access information (dedicated APN) of the App 1 to the routing management unit 330b.
  • the routing manager 330b When the app 1 is executed, the routing manager 330b is connected to the dedicated network through the dedicated APN according to the routing rule mapped to the app 1.
  • the ANDSF management unit 370 changes the APN of the App 1 to the public APN and reflects it to the routing management unit 330b. .
  • FIG. 9 is a diagram illustrating a dedicated network connection in a routing container based terminal structure according to an embodiment.
  • the terminal 300 communicates with the data policy control apparatus 200 to prepare a dedicated network connection, and manages network access information (APN) and network interface through a profile as shown in Table 2.
  • the terminal 300 is a subscriber terminal capable of accessing a dedicated network, and may be a subscriber of a dedicated network product or a third party billing application subscriber.
  • the terminal 300 in order to access a dedicated network based on a routing container, the terminal 300 provides a dedicated APN (Special.lte.kt.com) to a dedicated network (wireless network # 2) network interface rmnet2. Assign.
  • the terminal 300 may update the dedicated APN under the control of the data policy control apparatus 200.
  • the terminal 300 connects the virtual network interface vEthernet1 and the network interface rmnet2 of the routing container.
  • the virtual network interface vEthernet1 may be connected to the global network interface of the terminal at the L2 level. If the terminal supports a plurality of APN settings, a plurality of routing containers may be created corresponding to APNs for each dedicated network.
  • the terminal 300 accesses the virtual network interface of the routing container with respect to the app 3 / app 4.
  • App 1 / App 2 has a routing rule for accessing the public network (wireless network # 1) is set, can be authenticated for access to the private network from the data policy control device 200. Then, App 1 / App 2 is also subject to the routing rules connected to the virtual network interface (vEthernet1) of the routing container.
  • an application container for applications connected to the virtual network interface vEthernet1 of the routing container may be created in the application layer.
  • the terminal distinguishes and displays a third party billing application (or a private network access application) and a general application (or a public network access application) charged to an individual user through an application container, and describes a method of authenticating a private network connection. do.
  • FIG. 10 is an example of a terminal interface screen including an application container according to an embodiment.
  • an application container 400 is used as a user interface for distinguishing between an application charged to a third party and an application charged to an individual user.
  • the application container 400 may be in the form of a folder / box, and an authenticated third party billing application may be located in the application container 400.
  • the user moves an application located outside the application container into the application container by various methods such as drag and drop, and the terminal 300 transmits the third party billing of the corresponding application to the data policy control device 200. May request certification.
  • the dedicated network may not be used by moving out of the application container.
  • the application container 400 may be managed and protected by a mobile device management (MDM) solution.
  • MDM mobile device management
  • the terminal 300 places only applications authenticated by the data policy control apparatus 200 in the application container 400.
  • the terminal 300 changes routing information so that applications located in the application container 400 can access a private network instead of a public network. If the application located in the application container moves out, the terminal 300 changes the routing information so that the application can access the public network instead of the private network.
  • the routing authentication unit 310 recognizes the application moved to the application container 400, requests authentication to the data policy control device 200, and manages the application to be included in the application container 400 according to the authentication result.
  • An application located in the application container 400 may have a dedicated APN mapped by the routing container 350 as shown in FIG. 7, or a dedicated APN mapped by the ANDSF management unit 370 as shown in FIG. 8.
  • an application authenticated by the data policy control apparatus 200 and granted access to a private network is finally moved out of an application container. If the application is finally located outside the application container, the application cannot connect to the private network.
  • the data policy control apparatus 200 does not permit access to the private network, if the application requested for authentication is not an application of a CP that provides a third party billing service.
  • the data policy control apparatus 200 may not permit access to the private network according to the data charging burden policy even if the application for which authentication is requested is an application of a CP that provides a third party billing service.
  • the data policy control apparatus 200 may not permit access to a private network that the CP charges for an application for which authentication is required when the remaining amount of the total amount of data purchased by the CP is less than or equal to the reference value.
  • the data policy control apparatus 200 may not permit access to a dedicated network charged by the CP to an application requesting authentication outside the contract time period.
  • the terminal 300 may request authentication from the data policy control apparatus 200.
  • the terminal 300 When the terminal 300 receives an authentication release for a specific application located in the container from the data policy control device 200, the terminal 300 moves the released application out of the application container.
  • the terminal 300 stores the authentication deactivation condition, the application that satisfies the deauthentication condition may be moved out of the application container.
  • the data policy control apparatus 200 may notify the terminal 300 of the release of authentication for a specific application located in the container.
  • the data policy control apparatus 200 may notify the terminal 300 of the release of authentication for a specific application located in the container after the contract time period passes.
  • the user may intuitively distinguish the third-party billing application and the user billing application through the application container, and may simply request authentication by moving the application to the application container.
  • the terminal 300 manages routing information of applications included in the application container 400 by connecting the routing container 350 that sets the virtual network interface for the dedicated network connection to the application container 400 of the application layer. can do.
  • the data policy control apparatus 200 may put an application in the application container or remove the application from the application container by reflecting the data charge burden policy of the CP in real time.
  • 11 is an example of a terminal interface screen displaying a third party billing application according to an embodiment.
  • an application icon displayed on the terminal interface screen may distinguish a third party billing application from a general application.
  • the free badge may be attached to the icon or the icon design may be different.
  • the icon of the third party billing application may visually display the consumption / remaining amount of the allocated data amount.
  • the icons 500 and 510 of the third party billing application may include a gradation and additionally display the consumption / remaining amount of the data amount as the gradient concentration.
  • an interface screen for checking the consumption amount, remaining amount, and QoS of the data amount of each application may be provided.
  • the third party billing may be displayed on the icon.
  • the terminal 300 removes the authenticated application. It is possible to change the display (for example, to attach a free badge or to display a gradation) by a third party billing application.
  • the terminal 300 may change an icon displayed as a third party billed application to a general application icon.
  • FIG. 12 is a flowchart of a method of installing a third party billing application, according to an exemplary embodiment.
  • the user downloads and installs a third party billing application from the application market, and then the terminal 300 interworks with the data policy control apparatus 200 to transfer traffic of the application to a dedicated network or to a public network.
  • the third party billing application may be similar to the installation method of a general application, but a CP or a company that distributes the application may subscribe only to a specific telecommunication company's dedicated network product, or the product promised by the telecommunication company may differ. Therefore, a network registration procedure is added when installing a third party billing application as follows.
  • the application market 600 registers a third party billing application and billing network information (for example, kt) (S410).
  • the billing network information is the network information that CP subscribes to the product that third party billing, and in some cases, the CP subscribes to only some of the carrier products of a plurality of carriers and provides the third party billing service only to some carrier subscribers. can do.
  • the terminal 300 downloads installation information including the third party billing application and billing communication network information from the application market 600 (S420).
  • the installation information may further include meta information for confirming the integrity of the installed third party billing application.
  • the terminal 300 checks the billing network information of the third party billing application, accesses the data policy control device 200 indicated by the billing network information, and notifies the third party billing application installation (S430). If, as a result of checking the charging burden network information, the terminal cannot use the communication network that the CP subscribed to the product paying the third party billing (for example, a third party subscriber), the third party charging application is the same as the general application. The communication step with the data policy control apparatus 200 is omitted.
  • the data policy control apparatus 200 registers a third party billing application installation of the terminal 300 in operation S440. Meanwhile, the data policy control device 200 may receive terminal information on which the third party billing application is installed from the application market 600 or the CP device 100.
  • the data policy control apparatus 200 authenticates the third party charging application of the terminal 300 according to the third party charging application authentication policy specified by the CP, and authenticates the third party with the terminal 300 that has been authenticated.
  • the dedicated network access information for the billing application may be transferred (S450).
  • the terminal 300 may map the third party billing application that is permitted to access the dedicated network and the dedicated network access information (S460). This may allow the CP to unlimitedly charge the third party billing application, for example, in the case of an enterprise-only application, and permit access to the private network at the same time as the installation registration.
  • the CP may provide an application capable of third party charging, but may not be able to charge the third party according to the data charge burden policy. Therefore, after registering the installation of the third party billing application, the data policy control apparatus 200 may check the CP data charging burden policy and then transmit the dedicated network access information of the CP after receiving the request for access to the dedicated network from the terminal 300. Alternatively, the data policy control apparatus 200 transmits the dedicated network access information of the CP to the terminal 300 after registering the installation of the third party billing application, and when the private network access request is received from the terminal 300, the CP data charging burden policy is confirmed. After that, the CP can be granted access to the private network.
  • the terminal 300 has linked to the data policy control apparatus 200 to route to a dedicated network on an application basis, and based on this, a service in which a third party bears a charge for traffic generated in the dedicated network has been described.
  • various communication services using the dedicated network allocation method for each application will be further described.
  • FIG. 13 is a diagram illustrating a method for providing a CP center dedicated network service according to an embodiment.
  • the CP purchases a large amount of data that can be used by a plurality of applications from a carrier.
  • the data policy control apparatus 200 may configure a dedicated network for a plurality of applications designated by the CP and configure a network, and provide dedicated network access information to the terminal.
  • the terminal may generate an application container for each CP.
  • the user may download a CP application container including applications designated by a specific CP or add applications designated to the CP application container.
  • the CP may purchase a large amount of data that can be used by a plurality of applications from the telecommunications company, and sell a product that bears the data charge of the customer. This can be called a B2B2C service. That is, the CP may sell content through an application or an in-app purchase, and may also sell a communication network (dedicated network) product for the application.
  • a communication network dedicated network
  • the CP subscribes to a carrier-only network product and purchases a large amount of data from a carrier for use by many applications.
  • the CP may design at least one CP product (including a rate, a QoS level, etc.) that can accommodate a plurality of applications, and provide the same to a customer. That is, instead of the individual user subscribing to the telecommunication company's dedicated network product, the CP may subscribe to the telecommunication company's dedicated network product and provide the private network service to the applications of the CP.
  • the data policy control apparatus 200 controls the authenticated terminals to access the private network according to various data charging burden policies of the CPs, and controls to transmit and receive traffic of applications designated by the corresponding CP in the private network in the purchase data limit of each CP. .
  • the method of designing the amount of data and quality of service (QoS) contracted with a carrier and providing it to customers can be designed for various purposes such as marketing.
  • CP may sell CP goods to customers for a fee.
  • the CP may provide a CP product to the customer free of charge, or may be charged for data usage issued by the customer using the application.
  • CP dedicated network products may include the amount of data and / or QoS levels available for the dedicated network.
  • the user subscribes to a CP-only network product and uses the dedicated network free of charge when using a specified application (CP pays for data usage), or uses a QoS-guaranteed dedicated network (charge for data usage is paid by an individual or CP. )can do.
  • CP-only network products can be variously designed by the CP.
  • FIG. 14 is a view illustrating a user-selectable dedicated network service according to an embodiment. It is a figure explaining a method.
  • a user subscribes to a single plan and uses a communication network within a data limit contracted by the plan.
  • a user can subscribe to a private network plan for accessing a private network, in addition to the public network plan for accessing a public network.
  • the user can select the amount of data available on the private network.
  • the data policy control apparatus 200 may provide a user interface for easily selecting a data amount as illustrated in FIG. 14A.
  • the terminal provides an application container (eg, a GiGA cube) on a display screen, and a user includes an application in which the application container desires to transmit and receive traffic through a dedicated network. Then, as described above, the terminal sets the routing information so that applications contained in the application container can access the private network. To this end, the terminal obtains dedicated network access information (for example, dedicated network APN) from the data policy control apparatus 200 and sets a network interface. Applications located outside the application container connect to the public network.
  • dedicated network access information for example, dedicated network APN
  • a user may subscribe to a dedicated network plan for an application requiring QoS and put the application in an application container to use the content. If the dedicated private network data amount is exhausted, the user can increase the data amount in the user interface as shown in FIG.
  • the data policy control apparatus 200 monitors the dedicated network usage and, when the contracted dedicated network data amount is exhausted, releases the authentication of the applications contained in the application container by the routing authentication unit 310 of the terminal to control the access to the dedicated network. Can be. In this case, routing information is changed so that applications contained in the application container move out of the application container and access to the public network.
  • the embodiments of the present invention described above are not only implemented through the apparatus and the method, but may be implemented through a program for realizing a function corresponding to the configuration of the embodiments of the present invention or a recording medium on which the program is recorded.

Abstract

Disclosed is a method for providing a third-party billing service by interworking a data policy control device with a core network and a terminal, the method comprising the steps of: storing a data billing policy for a third party for an application and dedicated network information allocated to the core network for transmitting and receiving traffic of the specific application; controlling access to the dedicated network of the application installed on the terminal on the basis of the data billing policy; and billing the third party for the amount of data used to transmit and receive traffic of the application in the dedicated network. Each terminal with the application installed thereon transmits traffic of the application to the dedicated network or to a public network under control of the data policy control device.

Description

어플리케이션 전용망 할당 방법, 이를 통한 제3자 과금 서비스 제공 방법, 그리고 이를 구현한 통신망 시스템 및 사용자 단말Application dedicated network allocation method, third party billing service providing method, and communication network system and user terminal implementing the same
본 발명은 무선 통신망 시스템 및 이의 데이터 통신 서비스에 관한 것이다.The present invention relates to a wireless communication network system and a data communication service thereof.
사용자는 통신사 요금제에 따라 매월 일정 데이터량을 부여받고, 통신망을 통해 데이터를 송수신할 때마다 데이터량이 차감된다. 사용자는 단말에서 어플리케이션을 실행하여 원격의 서버에서 제공하는 콘텐츠를 이용하므로, 콘텐츠 이용을 위한 통신망 이용료를 부담한다. 즉, 사용자는 유료 어플리케이션을 구매하거나, 어플리케이션 내 유료 콘텐츠를 구매하여도, 통신망 이용료는 사용자가 지불해야 한다. The user is given a certain amount of data every month according to the carrier billing plan, and the amount of data is deducted each time data is transmitted and received through the communication network. Since the user runs the application in the terminal and uses the content provided by the remote server, the user bears the communication network fee for using the content. That is, even if a user purchases a paid application or purchases paid content in the application, the user must pay the communication network fee.
한편, 일부 콘텐츠 제공사는 시장 확장 등의 다양한 목적을 위해 고객의 통신망 이용료를 대신 지불하기도 한다. 이 경우, 통신사는 콘텐츠 제공사의 과금 지원 대상을 특정하기 위한 5 튜플(tuple)을 코어망에 등록하고, 등록된 5 튜플에 해당하는 모든 트래픽에 대한 과금을 제3자인 콘텐츠 제공사로 변경한다. 이때, P-GW가 패킷의 콘텐츠 서버 주소를 인지하여 사용자 과금 및 콘텐츠 제공사 과금을 분리해야 하기 때문에, 어플리케이션이 이용하는 원격 호스트의 모든 목적지 정보가 통신사에게 제공되어야 한다. 게다가 어플리케이션들 사이의 연계가 빈번하여 콘텐츠 서버 주소로 과금 대상을 판단하는 것이 쉽지 않다. 또한, 발생한 트래픽에 대한 과금 대상이 콘텐츠 제공사로 일괄 변경되는 만큼, 콘텐츠 제공사가 과금되는 데이터량을 미리 결정하기 어렵고, 과금 제어가 어려우며, 일정 데이터 사용량에 대해서 과금 부담하는 다양한 과금 서비스 적용이 불가하다. On the other hand, some content providers may pay customers' network fees for various purposes such as market expansion. In this case, the telecommunications company registers 5 tuples to specify the charging support target of the content provider in the core network, and changes the charging for all traffic corresponding to the registered 5 tuples to the third party content provider. At this time, since the P-GW needs to recognize the content server address of the packet to separate the user charge and the content provider charge, all destination information of the remote host used by the application must be provided to the carrier. In addition, frequent links between applications make it difficult to determine billing targets based on content server addresses. In addition, as the billing target for the generated traffic is collectively changed to the content provider, it is difficult to determine the amount of data charged by the content provider in advance, it is difficult to control the billing, and it is not possible to apply various billing services that charge for certain data usage. .
사용자는 요금제에 의존하여 데이터 서비스를 이용할 수 밖에 없으므로, 콘텐츠 제공사가 차별화된 콘텐츠 서비스를 제공하고자 하더라도, 사용자가 가입한 통신망의 QoS에 의존하게 된다. 따라서 콘텐츠 제공사의 콘텐츠 개발이 통신망에 의존할 수 밖에 없다.Since the user is forced to use the data service depending on the plan, even if the content provider wants to provide a differentiated content service, the user depends on the QoS of the communication network to which the user subscribes. Therefore, the content development of the content provider is forced to rely on the communication network.
이처럼, 콘텐츠 제공사는 어플리케이션 마켓을 통해 단말에 어플리케이션을 배포하더라도, 어플리케이션 이용이 사용자의 통신망 요금제와 QoS에 의존하게 된다. 통신사는 특정 어플리케이션에서 발생한 트래픽에 대한 과금을 콘텐츠 제공사가 부담한다면 통신망 이용량을 늘릴 수 있으나, 코어망에서 사용자가 이용하는 트래픽을 개인 과금과 콘텐츠 제공사 과금으로 분류하는 것이 쉽지 않다.As such, even if the content provider distributes the application to the terminal through the application market, the application usage depends on the user's network plan and QoS. Telcos can increase the network usage if the content provider bears the charges for traffic generated by a specific application, but it is not easy to classify the traffic used by users in the core network into personal billing and content provider billing.
지금까지는 어플리케이션 이용을 위한 통신망 이용료를 개인 사용자가 부담하는 것이 당연하였으나, 모든 사물들이 통신망을 통해 연결되어 콘텐츠를 소비하는 시대에서, 다양한 주체가 통신망을 통한 콘텐츠 유통 비용을 부담할 수 있는 기술이 요구된다. Until now, it has been natural for individual users to pay the communication network fee for using an application. However, in an age in which all things are connected through a communication network and consume content, a technology that enables various subjects to bear the cost of distributing content through a communication network is required. do.
본 발명이 해결하고자 하는 과제는 특정 어플리케이션을 위한 전용망을 할당하고, 어플리케이션의 전용망 접속을 제어하는 방법, 그리고 이를 구현한 통신망 시스템 및 사용자 단말을 제공하는 것이다.The problem to be solved by the present invention is to allocate a dedicated network for a specific application, to provide a method for controlling access to the dedicated network of the application, and to provide a communication network system and a user terminal implementing the same.
본 발명이 해결하고자 하는 과제는 특정 어플리케이션에 대한 제3자 과금 서비스를 제공하고, 특히 제3자의 데이터 과금 부담 정책을 실시간으로 단말에 반영하여 제3자 과금을 제어하는 방법, 그리고 이를 구현한 통신망 시스템 및 사용자 단말을 제공하는 것이다.The problem to be solved by the present invention is to provide a third party billing service for a specific application, in particular a method of controlling the third party billing by reflecting the third party's data billing burden policy in real time, and a communication network implementing the same It is to provide a system and a user terminal.
본 발명이 해결하고자 하는 과제는 복수의 접속점 이름(Access Point name, APN) 설정을 지원하는 단말에서, 데이터 정책 제어 장치의 제어에 따라 어플리케이션에 전용 APN을 할당하거나 공용 APN을 할당하는 라우팅 관리 방법을 제공하는 것이다. An object of the present invention is to provide a routing management method for allocating a dedicated APN or a common APN to an application under a control of a data policy controller in a terminal supporting a plurality of access point names (APNs). To provide.
또한, 본 발명이 해결하고자 하는 과제는 사용자가 어플리케이션별 접속망 변경이나 제3자 과금 서비스 이용을 간편하고 직관적으로 제어할 수 있는 사용자 인터페이스를 제공하는 것이다.In addition, the problem to be solved by the present invention is to provide a user interface that allows the user to simply and intuitively control the application-specific access network changes or the use of third-party billing services.
한 실시예에 따른 데이터 정책 제어 장치가 코어망 및 단말과 연동하여 제3자 과금 서비스를 제공하는 방법으로서, 특정 어플리케이션에 대한 제3자의 데이터 과금 부담 정책, 그리고 상기 특정 어플리케이션의 트래픽 송수신을 위해 상기 코어망에 할당된 전용망 정보를 관리하는 단계, 상기 데이터 과금 부담 정책을 기초로, 단말들에 설치된 상기 특정 어플리케이션의 전용망 접속을 제어하는 단계, 그리고 상기 전용망에서 상기 특정 어플리케이션의 트래픽 송수신에 사용된 데이터량을 상기 제3자에게 과금하는 단계를 포함한다. 상기 특정 어플리케이션을 설치한 각 단말은 상기 데이터 정책 제어 장치의 제어에 따라 상기 특정 어플리케이션의 트래픽을 상기 전용망으로 전송하거나 공용망으로 전송한다.A method for providing a third party billing service by interworking with a core network and a terminal by a data policy controlling device according to an embodiment, the third party's data charge burden policy for a specific application, and for transmitting and receiving traffic of the specific application Managing dedicated network information allocated to a core network, controlling access to a dedicated network of the specific applications installed in terminals based on the data charge burden policy, and data used for transmitting and receiving traffic of the specific application in the dedicated network; Charging the amount to the third party. Each terminal installed with the specific application transmits the traffic of the specific application to the dedicated network or to the public network under the control of the data policy control device.
상기 특정 어플리케이션의 전용망 접속을 제어하는 단계는 상기 데이터 과금 부담 정책이 유효한 경우, 상기 특정 어플리케이션의 트래픽이 상기 전용망으로 전송되도록 전용망 접속을 허가할 수 있다. 전용망 접속이 허가된 단말은 전용망 접속 정보를 이용하여 상기 특정 어플리케이션의 트래픽을 상기 전용망으로 전송하는 제1 라우팅 정책을 설정할 수 있다.The controlling of the access to the dedicated network of the specific application may allow access to the private network so that traffic of the specific application is transmitted to the dedicated network when the data charge burden policy is valid. The terminal allowed to access the dedicated network may set a first routing policy for transmitting traffic of the specific application to the dedicated network using the dedicated network access information.
상기 전용망 접속 정보는 상기 코어망에 할당된 전용망의 접속점 이름(Access Point Name, APN)일 수 있다.The dedicated network access information may be an access point name (APN) of a dedicated network allocated to the core network.
상기 데이터 과금 부담 정책은 상기 제3자의 구매 데이터량을 포함할 수 있다. 상기 특정 어플리케이션의 전용망 접속을 제어하는 단계는 상기 제3자에게 과금된 데이터량이 상기 제3자의 구매 데이터량에 도달한 경우, 상기 특정 어플리케이션에 대해 전용망 접속을 허가받은 단말들로, 전용망 접속에 대한 인증 해제를 지시할 수 있다. 인증 해제된 각 단말은 상기 특정 어플리케이션의 트래픽을 공용망으로 전송하는 제2 라우팅 정책으로 변경할 수 있다.The data charge burden policy may include the purchase data amount of the third party. The controlling of access to the private network of the specific application may include: terminals that are granted access to the private network for the specific application when the amount of data charged to the third party reaches the purchase data amount of the third party. Authentication may be instructed. Each terminal deauthenticated may change to a second routing policy for transmitting traffic of the specific application to the public network.
상기 특정 어플리케이션의 전용망 접속을 제어하는 단계는 상기 특정 어플리케이션에 할당된 전용망 접속 정보를 상기 단말들로 전송하는 단계, 상기 단말들 중 임의 단말로부터 상기 특정 어플리케이션의 전용망 접속을 위한 인증 요청을 수신하는 단계, 그리고 상기 제3자가 설정한 어플리케이션 인증 정책을 기초로 상기 특정 어플리케이션에 대한 전용망 접속을 인증하고, 상기 임의 단말로 전용망 접속을 허가하는 단계를 포함할 수 있다. 상기 임의 단말에서 실행된 상기 특정 어플리케이션의 트래픽은 상기 전용망 접속 정보에 해당하는 전용망으로 전송될 수 있다.The controlling of the specific network access of the specific application may include transmitting dedicated network access information allocated to the specific application to the terminals, and receiving an authentication request for access to the specific network of the specific application from any of the terminals. And authenticating a dedicated network access to the specific application based on the application authentication policy set by the third party and granting the dedicated network access to the arbitrary terminal. Traffic of the specific application executed in the arbitrary terminal may be transmitted to the dedicated network corresponding to the dedicated network access information.
상기 어플리케이션 인증 정책은 상기 특정 어플리케이션의 식별자 그리고 무결성 정보를 포함할 수 있다.The application authentication policy may include an identifier and integrity information of the specific application.
상기 특정 어플리케이션은 기업 사내망으로 연결되는 기업 전용 어플리케이션이거나 인터넷망을 통해 콘텐츠 서버에 연결되는 어플리케이션일 수 있다.The specific application may be an enterprise-specific application connected to a corporate internal network or an application connected to a content server through an internet network.
상기 제3자 과금 서비스 제공 방법은 상기 전용망에서의 트래픽 송수신에 따라 변동되는 상기 제3자의 구매 데이터량의 잔여량을 모니터링하고, 상기 제3자에게 잔여량을 통보하는 단계, 그리고 상기 제3자로부터 데이터 추가를 요청받으면, 상기 데이터 과금 부담 정책을 갱신하는 단계를 더 포함할 수 있다.The third party billing service providing method includes monitoring the remaining amount of the purchase data amount of the third party that is changed according to the transmission / reception of traffic in the dedicated network, notifying the remaining amount to the third party, and data from the third party. If the addition is requested, the method may further include updating the data charge burden policy.
상기 제3자에게 과금하는 단계는 복수의 제3자들에게 과금할 트래픽이 상기 전용망에서 함께 송수신되는 경우, 상기 전용망에서 송수신되는 트래픽을 어플리케이션별로 구분하여 각 어플리케이션에 대응하는 제3자에게 과금할 수 있다.In the charging of the third party, when traffic to be charged to a plurality of third parties is transmitted and received together on the dedicated network, the traffic transmitted and received on the dedicated network may be classified by application and charged to a third party corresponding to each application. have.
다른 실시예에 따른 단말이 어플리케이션의 트래픽을 지정된 망으로 라우팅하는 방법으로서, 데이터 정책 제어 장치로 특정 어플리케이션의 전용망 접속을 위한 인증을 요청하는 단계, 상기 데이터 정책 제어 장치로부터 상기 특정 어플리케이션의 전용망 접속을 허가하는 인증 결과를 수신하는 단계, 그리고 상기 특정 어플리케이션의 트래픽을 상기 특정 어플리케이션에 할당된 전용망으로 전송하는 라우팅 정책을 설정하는 단계를 포함한다. 상기 특정 어플리케이션의 트래픽은 전용망 접속을 위한 인증이 유효한 동안 전용망 접속 정보를 기초로 코어망에 생성된 상기 전용망으로 전달된다.A method for routing traffic of an application to a designated network by a terminal according to another embodiment, the method comprising: requesting a data policy control device for authentication for a specific network connection to a specific application; Receiving an authorization result to permit, and setting a routing policy for transmitting traffic of the specific application to the dedicated network assigned to the specific application. Traffic of the specific application is delivered to the dedicated network generated in the core network based on the dedicated network access information while the authentication for the dedicated network access is valid.
상기 전용망 접속을 위한 인증을 요청하는 단계는 사용자 인터페이스 화면에 표시된 상기 특정 어플리케이션을 특정 영역 안으로 움직이는 사용자 동작이 입력되면, 상기 데이터 정책 제어 장치로 상기 특정 어플리케이션의 전용망 접속을 위한 인증을 요청할 수 있다. 상기 데이터 정책 제어 장치로부터 전용망 접속이 허가되면, 상기 특정 어플리케이션은 상기 특정 영역 안에 위치하고, 상기 데이터 정책 제어 장치로부터 전용망 접속이 허가되지 않으면, 상기 특정 어플리케이션은 상기 특정 영역 밖에 위치할 수 있다.In the request for authentication for access to the private network, when a user operation of moving the specific application displayed on a user interface screen into a specific area is input, the data policy controller may request authentication for access to the private network of the specific application. When the dedicated network access is allowed from the data policy control device, the specific application is located in the specific area, and if the dedicated network access is not permitted from the data policy control device, the specific application may be located outside the specific area.
상기 전용망 접속을 위한 인증을 요청하는 단계는 상기 특정 영역 안에 위치한 상기 특정 어플리케이션에 대한 실행 요청이 입력되면, 상기 데이터 정책 제어 장치로 상기 특정 어플리케이션의 전용망 접속을 위한 인증을 요청하고, 상기 데이터 정책 제어 장치로부터 전용망 접속이 허가되지 않으면, 상기 특정 어플리케이션을 상기 특정 영역 밖으로 이동할 수 있다.In the requesting of the authentication for accessing the dedicated network, when an execution request for the specific application located in the specific area is input, the data policy control device requests authentication for accessing the dedicated network of the specific application, and the data policy control. If a dedicated network connection is not allowed from the device, the specific application may be moved out of the specific area.
상기 라우팅 방법은 상기 데이터 정책 제어 장치로부터 상기 특정 어플리케이션에 대한 전용망 접속에 대한 인증 해제를 수신하는 단계, 그리고 상기 특정 어플리케이션의 트래픽을 공용망 으로 전송하는 라우팅 정책으로 변경하는 단계를 더 포함할 수 있다.The routing method may further include receiving, from the data policy control device, deauthentication for a dedicated network connection to the specific application, and changing to a routing policy for transmitting traffic of the specific application to a public network. .
상기 라우팅 정책을 설정하는 단계는 가상 네트워크 인터페이스가 할당된 라우팅 컨테이너에 전용망 접속 허가된 상기 특정 어플리케이션을 매핑하여 상기 특정 어플리케이션의 라우팅 정책을 설정할 수 있다. 상기 가상 네트워크 인터페이스는 상기 전용망으로 접속하는 제1 네트워크 인터페이스에 연결될 수 있다. 상기 라우팅 컨테이터에 매핑되지 않은 어플리케이션들은 공용망에 접속하는 제2 네트워크 인터페이스에 연결되는 라우팅 정책이 설정될 수 있다.The setting of the routing policy may set the routing policy of the specific application by mapping the specific application that is allowed to access the dedicated network to the routing container to which the virtual network interface is assigned. The virtual network interface may be connected to a first network interface connecting to the private network. Applications not mapped to the routing container may have a routing policy connected to a second network interface connecting to the public network.
상기 특정 어플리케이션이 제3자가 데이터 과금 부담하는 제3자 과금 어플리케이션인 경우, 상기 특정 어플리케이션은 전용망 접속을 위한 인증이 유효한 동안 사용자 인터페이스 화면에서 상기 제3자 과금 어플리케이션임을 표시할 수 있다.When the specific application is a third party billing application that a third party charges for data, the specific application may indicate that the third party billing application is displayed on the user interface screen while the authentication for accessing the dedicated network is valid.
상기 라우팅 정책을 설정하는 단계는 공용망 접속을 위한 제1 망 접속 정보 그리고 적어도 하나의 전용망 접속을 위한 적어도 하나의 제2 망 접속 정보를 관리하고, 상기 특정 어플리케이션의 전용망 접속이 허가되면, 허가된 전용망에 해당하는 제2 망 접속 정보를 상기 특정 어플리케이션에 매핑하고, 상기 특정 어플리케이션의 전용망 접속이 허가되지 않으면, 상기 제1 망 접속 정보를 상기 특정 어플리케이션에 매핑할 수 있다.The setting of the routing policy may include managing first network access information for public network access and at least one second network access information for at least one private network access, and if the private network access of the specific application is allowed, The second network access information corresponding to the dedicated network may be mapped to the specific application, and if the dedicated network access of the specific application is not permitted, the first network access information may be mapped to the specific application.
상기 특정 어플리케이션은 기업 전용 어플리케이션 또는 제3자가 데이터 과금 부담하는 제3자 과금 어플리케이션일 수 있다.The specific application may be an enterprise-only application or a third party billing application that a third party charges for data.
또 다른 실시예에 따른 단말이 제3자 과금 어플리케이션을 설치하는 방법으로서, 어플리케이션 마켓에서 제3자 과금 어플리케이션과 과금 부담 통신망 정보를 포함하는 설치 정보를 다운로드하여 설치하는 단계, 상기 과금 부담 통신망 정보에서 지시하는 데이터 정책 제어 장치에 접속하여 상기 제3자 과금 어플리케이션 설치를 통보하는 단계, 그리고 상기 데이터 정책 제어 장치로부터 수신한 전용망 접속 정보를 상기 제3자 과금 어플리케이션에 매핑하는 라우팅 정책을 설정하는 단계를 포함한다. 상기 제3자 과금 어플리케이션의 트래픽은 전용망 접속을 위한 인증이 유효한 동안 상기 전용망 접속 정보에 대응된 전용망으로 전달된다.As a method of installing a third party billing application by a terminal according to another embodiment, downloading and installing installation information including a third party billing application and billing network information from an application market, and in the billing network information Accessing the instructed data policy controlling device to notify installation of the third party billing application; and setting a routing policy for mapping dedicated network access information received from the data policy controlling device to the third party billing application. Include. Traffic of the third party billing application is delivered to the dedicated network corresponding to the dedicated network access information while authentication for the dedicated network access is valid.
상기 라우팅 정책을 설정하는 단계는 상기 데이터 정책 제어 장치로 상기 제3자 과금 어플리케이션의 전용망 접속을 위한 인증을 요청하고, 상기 데이터 정책 제어 장치로부터 전용망 접속 허가를 포함하는 인증 결과를 수신하면, 상기 라우팅 정책을 설정할 수 있다.The setting of the routing policy may include requesting an authentication for access to the private network of the third party billing application to the data policy controlling device, and receiving an authentication result including access to the private network from the data policy controlling device. You can set the policy.
상기 제3자 과금 어플리케이션 설치 방법은 상기 데이터 정책 제어 장치로부터 상기 제3자 과금 어플리케이션에 대한 전용망 접속에 대한 인증 해제를 수신하는 단계, 그리고 상기 제3자 과금 어플리케이션에 매핑된 전용망 접속 정보를 공용망 접속 정보로 변경하는 라우팅 정책을 설정하는 단계를 더 포함할 수 있다.The third party billing application installation method may further include receiving an authentication release for a dedicated network access to the third party billing application from the data policy control device, and sharing the private network access information mapped to the third party billing application. The method may further include setting a routing policy for changing the connection information.
실시예에 따르면, 단말이 전용망으로 접속하는 어플리케이션을 위해 공용망과 다른 망 접속 정보(예를 들면, 전용 APN)를 추가로 설정할 수 있으므로, 실행되는 어플리케이션에 따라 현재 설정된 망 접속 정보를 변경할 필요 없다. 특히 일반 어플리케이션들과 보안성이 요구되는 보안 어플리케이션들(예를 들면, 기업용 어플리케이션)의 망 접속 정보를 구분하여 설정할 수 있으므로, 일반 어플리케이션과 보안 어플리케이션을 동시에 사용할 수 있고, 일반 어플리케이션의 트래픽이 기업 내부망(사내망)(intranet) 등으로 유입되는 것을 방지할 수 있다. 또한, 실시예에 따르면, 어플리케이션의 전용망 구성 시 사내망 등을 목적 PDN(Packet Data Network)으로 설정하면 되므로, 네트워크 패킷 보안을 위한 터널링(VPN)이 필요 없다.According to the embodiment, since the terminal may additionally set the network connection information (for example, dedicated APN) different from the public network for the application connected to the private network, there is no need to change the currently set network connection information according to the application to be executed. . In particular, since network access information of general applications and security applications (eg, enterprise applications) requiring security can be distinguished and set, general applications and security applications can be used at the same time, and the traffic of general applications is internal to the enterprise. It can prevent the inflow into a network (intranet) and the like. In addition, according to the embodiment, since the internal network, etc., may be set as a target PDN (Packet Data Network) when configuring a dedicated network of the application, tunneling (VPN) for network packet security is not required.
실시예에 따르면, 특정 어플리케이션 트래픽에 대한 과금을 제3자가 부담할 수 있어서 어플리케이션의 콘텐츠 이용을 활성화하고, 결과적으로 트래픽을 늘릴 수 있다. 특히, 제3자는 자신의 데이터 과금 부담 정책을 실시간으로 변경할 수 있고, 데이터 정책 제어 장치는 제3자의 데이터 과금 부담 정책을 실시간으로 단말에 반영할 수 있다. 또한, 특정 어플리케이션의 통신망 이용료를 다양한 주체들이 부담할 수 있어 다양한 형태의 데이터망 융합 어플리케이션 제공 및 콘텐츠 유통이 가능하다.According to an embodiment, the third party may be charged for specific application traffic, thereby enabling the use of the content of the application and consequently increasing the traffic. In particular, the third party may change his or her data charging burden policy in real time, and the data policy controller may reflect the third party's data charging burden policy on the terminal in real time. In addition, various subjects can bear the communication network usage fee of a specific application, thereby providing various types of data network convergence applications and distributing contents.
실시예에 따르면, 어플리케이션별로 망 접속 정보를 다르게 할당함으로써 사용자에게 과금되는 일반 어플리케이션과 제3자 과금 어플리케이션의 트래픽 전송 경로를 분리할 수 있다. 따라서, 코어망은 콘텐츠 서버 주소를 통해 사용자 과금 및 제3자 과금을 분리할 필요 없이, 지정된 전용망으로 전송된 트래픽에 대해 제3자에게 과금할 수 있다.According to an embodiment, by differently assigning network access information for each application, traffic transmission paths of a general application charged to a user and a third party charging application may be separated. Thus, the core network can charge a third party for traffic sent to a designated dedicated network without having to separate user charging and third party charging through the content server address.
실시예에 따르면, QoS 보장된 전용망을 특정 어플리케이션에 할당할 수 있으므로, 사용자는 동영상, AR/VR 게임 등의 콘텐츠를 QoS 보장된 전용망에서 이용할 수 있다.According to the embodiment, since the QoS-guaranteed private network can be assigned to a specific application, a user can use content such as a video, AR / VR game, etc. in the QoS-guaranteed private network.
실시예에 따르면, 콘텐츠 제공사는 통신사로부터 구매한 데이터량/QoS를 기초로, 어플리케이션 이용을 촉진(예를 들면, 데이터 이용료 무료)하거나, 어플리케이션을 위한 통신망 이용료를 별도 상품으로 고객에게 판매할 수 있다.According to an embodiment, the content provider may promote the use of the application (for example, free of data usage fee) or sell the communication network usage fee for the application as a separate product based on the amount of data / QoS purchased from the carrier. .
실시예에 따르면, 단말 화면에 표시되는 폴더/박스 형태의 컨테이너를 통해, 사용자는 어플리케이션별 접속망 변경이나 제3자 과금 서비스 이용 요청을 간편하고 직관적으로 제어할 수 있다.According to the embodiment, the user can easily and intuitively control the application-specific access network change or the third party billing service use request through the folder / box type container displayed on the terminal screen.
실시예에 따르면, 단말에 설치된 어플리케이션, 어플리케이션을 통해 콘텐츠를 제공하는 콘텐츠 제공사, 트래픽을 송수신하는 통신망을 융합함으로써, 다양한 주체가 원하는 대로 통신망을 통한 콘텐츠 유통 비용을 부담할 수 있다. 결과적으로, 사용자의 콘텐츠 이용을 늘리고, 사용자 요금제에 의존할 필요 없이, 콘텐츠에 최적화된 QoS 등의 통신 서비스를 제공할 수 있다.According to an embodiment, by fusing an application installed in a terminal, a content provider that provides content through the application, and a communication network that transmits and receives traffic, various subjects may pay for content distribution through the communication network as desired. As a result, it is possible to increase the user's use of the content and provide a communication service such as QoS optimized for the content without having to rely on the user plan.
도 1은 한 실시예에 따른 어플리케이션별 제3자 과금 서비스를 제공하는 통신망 시스템이다.1 is a communication network system that provides a third party billing service for each application according to an exemplary embodiment.
도 2는 한 실시예에 따른 어플리케이션별 과금을 예시적으로 설명하는 도면이다.2 is a diagram illustrating an example of charging for an application according to an exemplary embodiment.
도 3은 한 실시예에 따른 데이터 정책 제어 장치의 연동 구조를 설명하는 도면이다.3 is a view illustrating an interworking structure of a data policy control apparatus according to an embodiment.
도 4는 한 실시예에 따른 데이터 과금 부담 서비스 제공 방법의 흐름도이다. 4 is a flowchart illustrating a data charging burden service providing method according to an exemplary embodiment.
도 5는 한 실시예에 따른 데이터 정책 제어 장치가 실시간 데이터 과금 부담 서비스를 제어하는 방법의 흐름도이다.5 is a flowchart of a method of controlling, by a data policy control apparatus, a real-time data billing burden service according to an embodiment.
도 6은 다른 실시예에 따른 데이터 정책 제어 장치가 실시간 데이터 과금 부담 서비스를 제어하는 방법의 흐름도이다.6 is a flowchart illustrating a method of controlling, by a data policy control apparatus, a real-time data charging service according to another embodiment.
도 7은 한 실시예에 따른 라우팅 컨테이너 기반 어플리케이션 라우팅 제어 구조를 개념적으로 설명하는 도면이다.7 is a diagram conceptually illustrating a routing container based application routing control structure according to an embodiment.
도 8은 다른 실시예에 따른 라우팅 정책 관리 기반 어플리케이션 라우팅 제어 구조를 개념적으로 설명하는 도면이다.8 is a diagram conceptually illustrating a routing policy management based application routing control structure according to another embodiment.
도 9는 한 실시예에 따른 라우팅 컨테이너 기반 단말 구조에서의 전용망 접속을 설명하는 도면이다.9 is a diagram illustrating a dedicated network connection in a routing container based terminal structure according to an embodiment.
도 10은 한 실시예에 따른 어플리케이션 컨테이너를 포함하는 단말 인터페이스 화면의 예시이다. 10 is an example of a terminal interface screen including an application container according to an embodiment.
도 11은 한 실시예에 따른 제3자 과금 어플리케이션을 표시하는 단말 인터페이스 화면의 예시이다. 11 is an example of a terminal interface screen displaying a third party billing application according to an embodiment.
도 12는 한 실시예에 따른 제3자 과금 어플리케이션 설치 방법의 흐름도이다. 12 is a flowchart of a method of installing a third party billing application, according to an exemplary embodiment.
도 13은 한 실시예에 따른 CP 중심 전용망 서비스 제공 방법을 설명하는 도면이다.13 is a diagram illustrating a method for providing a CP center dedicated network service according to an embodiment.
도 14는 한 실시예에 따른 사용자 선택형 전용망 서비스 제공 방법을 설명하는 도면이다.14 is a diagram illustrating a user-selectable dedicated network service providing method according to an embodiment.
아래에서는 첨부한 도면을 참고로 하여 본 발명의 실시예에 대하여 본 발명이 속하는 기술 분야에서 통상의 지식을 가진 자가 용이하게 실시할 수 있도록 상세히 설명한다. 그러나 본 발명은 여러 가지 상이한 형태로 구현될 수 있으며 여기에서 설명하는 실시예에 한정되지 않는다. 그리고 도면에서 본 발명을 명확하게 설명하기 위해서 설명과 관계없는 부분은 생략하였으며, 명세서 전체를 통하여 유사한 부분에 대해서는 유사한 도면 부호를 붙였다.DETAILED DESCRIPTION Hereinafter, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings so that those skilled in the art may easily implement the present invention. As those skilled in the art would realize, the described embodiments may be modified in various different ways, all without departing from the spirit or scope of the present invention. In the drawings, parts irrelevant to the description are omitted in order to clearly describe the present invention, and like reference numerals designate like parts throughout the specification.
명세서 전체에서, 어떤 부분이 어떤 구성요소를 "포함"한다고 할 때, 이는 특별히 반대되는 기재가 없는 한 다른 구성요소를 제외하는 것이 아니라 다른 구성요소를 더 포함할 수 있는 것을 의미한다. 또한, 명세서에 기재된 "…부", "…기", "모듈" 등의 용어는 적어도 하나의 기능이나 동작을 처리하는 단위를 의미하며, 이는 하드웨어나 소프트웨어 또는 하드웨어 및 소프트웨어의 결합으로 구현될 수 있다.Throughout the specification, when a part is said to "include" a certain component, it means that it can further include other components, without excluding other components unless specifically stated otherwise. In addition, the terms “… unit”, “… unit”, “module”, etc. described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware or software or a combination of hardware and software. have.
본 발명에서 설명하는 장치들은 적어도 하나의 프로세서, 메모리 장치, 통신 장치 등을 포함하는 하드웨어로 구성되고, 지정된 장소에 하드웨어와 결합되어 실행되는 프로그램이 저장된다. 하드웨어는 본 발명의 방법을 실행할 수 있는 구성과 성능을 가진다. 프로그램은 도면들을 참고로 설명한 본 발명의 동작 방법을 구현한 명령어(instructions)를 포함하고, 프로세서와 메모리 장치 등의 하드웨어와 결합하여 본 발명을 실행한다. The devices described in the present invention are composed of hardware including at least one processor, a memory device, a communication device, and the like, and a program executed in combination with the hardware is stored in a designated place. The hardware has the configuration and performance to implement the method of the present invention. The program includes instructions implementing the method of operation of the present invention described with reference to the drawings, and executes the present invention in combination with hardware such as a processor and a memory device.
본 발명에서 단말은 이동국(Mobile Station, MS), 이동 단말(Mobile Terminal, MT), 가입자국(Subscriber Station, SS), 휴대 가입자국(Portable Subscriber Station, PSS), 사용자 장치(User Equipment, UE), 접근 단말(Access Terminal, AT) 등을 지칭할 수도 있고, 이동국, 이동 단말, 가입자국, 휴대 가입자국, 사용자 장치, 접근 단말 등의 전부 또는 일부의 기능을 포함할 수도 있다. In the present invention, the terminal may be a mobile station (MS), a mobile terminal (MT), a subscriber station (SS), a portable subscriber station (PSS), or a user equipment (UE). It may also refer to an access terminal (AT) and the like, and may include all or some functions of a mobile station, a mobile terminal, a subscriber station, a portable subscriber station, a user device, an access terminal, and the like.
단말은 기지국(base station, BS), 접근점(Access Point, AP), 무선 접근국(Radio Access Station, RAS), 노드B(Node B), 고도화 노드B(evolved NodeB, eNodeB), 송수신 기지국(Base Transceiver Station, BTS), MMR(Mobile Multihop Relay)-BS, 5G NB(gNB) 등과 같은 네트워크 장치에 접속하여 원격의 서버에 연결될 수 있다.The terminal may include a base station (BS), an access point (AP), a radio access station (RAS), a node B (Node B), an advanced node B (evolved NodeB, eNodeB), and a transmission / reception base station ( A network device such as a base transceiver station (BTS), a mobile multihop relay (MMR) -BS, a 5G NB (gNB), or the like may be connected to a remote server.
단말은 스마트폰과 같은 모바일 단말, 스마트패드와 태블릿PC와 같은 태블릿 단말, 컴퓨터, 텔레비전 등 다양한 형태의 통신 단말로서, 복수의 통신 인터페이스를 구비할 수 있다. 통신 인터페이스는 다양할 수 있다. 예를 들면, 통신 인터페이스는 와이파이(WiFi)/WLAN/블루투스(bluetooth) 등의 근거리 무선망 인터페이스, 그리고 3G/LTE(Long Term Evolution)/LTE-A(Long Term Evolution-Advanced)/5G 등의 이동통신망 인터페이스를 포함할 수 있고, 단말 제조사가 다양한 통신 인터페이스를 추가할 수 있다. The terminal may be a mobile terminal such as a smartphone, a tablet terminal such as a smart pad and a tablet PC, a computer, a television, and various types of communication terminals, and may include a plurality of communication interfaces. The communication interface may vary. For example, the communication interface may be a short-range wireless network interface such as Wi-Fi / WLAN / Bluetooth, and a mobile terminal such as 3G / Long Term Evolution (LTE) / Long Term Evolution-Advanced (LTE-A) / 5G. The network interface may be included, and the terminal manufacturer may add various communication interfaces.
본 발명에서, 주로 LTE EPC(Evolved Packet Core)를 예로 들어 설명하나, 5G 코어에도 동일하게 적용될 수 있다.In the present invention, the LTE EPC (Evolved Packet Core) is mainly described as an example, but may be equally applied to 5G core.
본 발명에서, 공용망과 전용망은 분리된 트래픽 경로를 의미하고, 반드시 물리적으로 분리될 필요는 없다. 예를 들어, 공용망과 전용망은 동일한 물리적 경로에 생성된 서로 다른 베어러일 수 있다.In the present invention, the public network and the private network means separate traffic paths, and are not necessarily physically separated. For example, public and private networks may be different bearers created on the same physical path.
본 발명에서, "제3자 과금 서비스"는 사용자를 대신하여 제3자가 사용자의 데이터 사용량에 대한 과금을 부담하는 것으로서, 통신사와 제3자의 계약은 다양할 수 있다. 설명에서는 주로 제3자가 통신사로부터 데이터를 구매하고, 구매한 데이터 한도 내에서 개인 사용자들의 과금을 부담하는 것을 가정하나, 데이터 한도 없이 데이터 사용량에 대해 후불로 청구될 수도 있다. 사용자에게 부여된 데이터량이 차감되지 않는다는 점에서 무과금/제로 레이팅(zero-rating) 서비스라고 하거나, 제3자가 개인 사용자의 통신망 사용료를 지원하는 점에서 스폰서 서비스라고 할 수 있다.In the present invention, the "third party billing service" is a third party pays for the user's data usage on behalf of the user, and the contract of the telecommunication company and the third party may vary. The description mainly assumes that a third party purchases data from the carrier and pays for individual users within the purchased data limit, but may also be billed for post-payment of data usage without a data limit. In the sense that the amount of data given to the user is not deducted, it can be referred to as an unpaid / zero-rating service or a sponsored service in that a third party supports the user network fee.
본 발명에서, "제3자"는 제3자 과금 부담 서비스를 제공하는 통신사 상품에 가입할 수 있는 주체이면 충분하다. 예를 들면, 제3자는 사내망에 연결되는 기업 전용 어플리케이션들을 제공하는 기업, 특정 콘텐츠 서버에 연결되는 콘텐츠 어플리케이션들을 제공하는 콘텐츠 제공사(Content Provider, CP)일 수 있는데, 반드시 제3자 과금 어플리케이션을 배포한 기업이나 CP로 한정될 필요는 없다. 예를 들어, 제3자는 특정 어플리케이션(예를 들면, 올레tv모바일 어플리케이션)을 통해 유통되는 콘텐츠(예를 들면, 특정 채널)를 위해 해당 어플리케이션에 대한 데이터 과금을 부담할 수 있다.In the present invention, the "third party" is sufficient to be a subject that can subscribe to the carrier product providing the third party billing service. For example, a third party may be a company that provides enterprise-specific applications connected to an internal network or a content provider (CP) that provides content applications connected to a specific content server. It does not need to be limited to the company or CP that it distributes. For example, a third party may bear data charging for the application for content (eg, a specific channel) distributed through a specific application (eg, an Oletv mobile application).
본 발명에서, 전용망이 할당되는 어플리케이션으로서 제3자 과금 어플리케이션을 예로 들어 설명하나, 반드시 제3자 과금 어플리케이션에만 전용망이 할당되는 것은 아니고, 사용자 과금이라도 특정 어플리케이션(예를 들면, QoS 보장이 요구되는 어플리케이션 등)에 전용망이 할당될 수 있다. In the present invention, a third-party billing application is described as an application to which a private network is assigned as an example. However, the dedicated network is not necessarily assigned only to the third-party billing application, and a specific application (for example, QoS guarantee is required even if user billing is required). Application, etc.) may be assigned a dedicated network.
본 발명의 어플리케이션은 전용망이 할당되어 이를 통해 과금 및 QoS가 제어되므로, 망 융합 어플리케이션, 데이터 융합 어플리케이션이라고 부를 수 있다. The application of the present invention can be referred to as a network convergence application, data convergence application because the dedicated network is assigned and charging and QoS are controlled through it.
도 1은 한 실시예에 따른 어플리케이션별 제3자 과금 서비스를 제공하는 통신망 시스템이고, 도 2는 한 실시예에 따른 어플리케이션별 과금을 예시적으로 설명하는 도면이다.1 is a communication network system that provides a third party billing service for each application according to an embodiment, and FIG. 2 is a diagram illustrating an application billing according to an embodiment.
도 1을 참고하면, 통신망 시스템은 제3자 과금 어플리케이션에 대한 데이터 과금을 부담하는 콘텐츠 제공사(Content Provider, CP) 장치(100), 통신망의 데이터 정책 제어 장치(200), 그리고 데이터 정책 제어 장치(200)의 제어에 따라 제3자 과금 어플리케이션의 라우팅 정책을 설정하는 단말(300)을 포함한다. 데이터 정책 제어 장치(200)는 단말에 설치된 다수의 어플리케이션들 중에서 CP나 사용자에 의해 지정된 특정 어플리케이션에 전용망(전용 데이터망)을 할당하고, 이를 통해 어플리케이션별 트래픽 경로 분리, QoS 차등, 그리고 과금 분리를 할 수 있다. Referring to FIG. 1, a communication network system includes a content provider (CP) device 100, a data policy control device 200 of a communication network, and a data policy control device that are responsible for data charging for a third party billing application. And a terminal 300 for setting a routing policy of the third party billing application under the control of 200. The data policy control apparatus 200 allocates a dedicated network (dedicated data network) to a specific application designated by a CP or a user among a plurality of applications installed in the terminal, and thereby separates traffic path separation, QoS differential, and charging separation for each application. can do.
CP 장치(100)는 CP별로 운용되며, 데이터 정책 제어 장치(200)와 통신할 수 있다. CP 장치(100)는 제3자 과금 어플리케이션을 지정하고, 제3자 과금 어플리케이션에 대한 데이터 과금 부담 정책을 데이터 정책 제어 장치(200)에게 전달할 수 있다. CP 장치(100)는 데이터 정책 제어 장치(200)가 제공하는 인터페이스를 통해 데이터 과금 부담 정책, 제3자 과금 어플리케이션 인증 정책, 데이터 과금 부담 가입자 목록 등을 설정 및 관리하고, 구매 데이터량에 대한 사용량 조회 등을 할 수 있다. CP 장치(100)는 데이터 정책 제어 장치(200)로부터 데이터 잔여량을 포함하는 데이터 과금 부담 정책의 적용 상태를 보고받는데, 기준 미만의 잔여량, 계약 한도 도달에 따른 제3자 과금 서비스 제한 등을 통보받을 수 있다. The CP device 100 is operated for each CP and may communicate with the data policy control device 200. The CP device 100 may designate a third party billing application and transmit a data charge burden policy for the third party billing application to the data policy control device 200. The CP device 100 sets and manages a data charging policy, a third party charging application authentication policy, a data charging subscriber list, and the like through an interface provided by the data policy control apparatus 200, and uses the amount of data purchased. Inquiries can be made. The CP device 100 receives a report of the application state of the data charge burden policy including the remaining amount of data from the data policy control device 200. The CP device 100 receives notification of the remaining amount below the standard and the restriction of the third party billing service due to reaching the contract limit. Can be.
한편, CP는 반드시 CP 장치(100)를 통해 데이터 과금 부담 정책 등을 데이터 정책 제어 장치(200)로 전송하고, 데이터 정책 제어 장치(200)를 통해 상품 청약할 필요는 없다. 즉, CP는 통신사가 제공하는 온라인 상품 가입 페이지 또는 오프라인 영업점에서 데이터 과금 부담 상품을 가입할 수 있고, 이에 따른 데이터 과금 부담 정책 등이 데이터 정책 제어 장치(200)로 전달되면 충분하다.On the other hand, the CP does not necessarily transmit a data charge burden policy, etc. to the data policy control device 200 through the CP device 100, and does not need to subscribe to the product through the data policy control device 200. That is, the CP may subscribe to the data charge burden product at the online product subscription page or the offline branch office provided by the telecommunication company, and the data charge burden policy may be transmitted to the data policy control apparatus 200.
데이터 정책 제어 장치(200)는 코어망의 각종 장치들과 연동하여 CP의 데이터 과금 부담 정책을 실시간으로 단말(300)에 반영할 수 있다. 연동 장치들은 망에 따라 달라질 수 있는데, 대표적으로, 정책 및 과금 제어 장치(10) 그리고 과금 장치(20)와 연동할 수 있다. 정책 및 과금 제어 장치(10)는 정책 과금 정보를 관리하는 PCC(Policy and Charging Control) 기능을 수행하는 PCRF(Policy and Charging Control Function)/PCEF(Policy and Charging Enforcement Function) 등일 수 있다. 구체적으로, 정책 및 과금 제어 장치(10)는 CP의 데이터 과금 부담 정책에 해당하는 전용망을 구성하고, 전용망 구성 정책 등의 전용망 정보를 데이터 정책 제어 장치(200) 및 P-GW(33)에 배포할 수 있다. 과금 장치(20)는 데이터 사용량을 계산하는 장치로서, 코어망에 따라 다를 수 있으나, 예를 들면, P-GW(Packet data gateway)(33)에서의 데이터 사용량(CDR)을 수집하는 OFCS(offline Charging System)/OCS(Online Charging System) 등일 수 있다. P-GW(33)는 데이터 사용량을 나타내는 CDR(Call detailed record, call data record, charged data record)을 과금 장치(20)로 전달하는데, CDR에 포함된 정보로 어플리케이션을 구분할 수도 있다.The data policy control apparatus 200 may reflect the data charging burden policy of the CP to the terminal 300 in real time in association with various devices of the core network. The companion devices may vary depending on the network. Typically, the companion devices may interwork with the policy and charging control device 10 and the charging device 20. The policy and charging control apparatus 10 may be a Policy and Charging Control Function (PCRF) / Policy and Charging Enforcement Function (PCEF) that performs a Policy and Charging Control (PCC) function for managing policy charging information. In detail, the policy and charging control device 10 configures a dedicated network corresponding to the data charging burden policy of the CP, and distributes dedicated network information such as a dedicated network configuration policy to the data policy control device 200 and the P-GW 33. can do. The billing device 20 is a device for calculating data usage, which may vary depending on the core network. For example, the charging apparatus 20 collects data usage (CDR) from the packet data gateway (P-GW) 33. Charging System) / Online Charging System (OCS). The P-GW 33 delivers a call detailed record (CDR) indicating a data usage amount to a charging device 20. The P-GW 33 may classify an application based on information included in the CDR.
데이터 정책 제어 장치(200)가 CP 장치(100)로부터 데이터 과금 부담 상품 청약을 받는 경우, 코어망으로 CP 전용망 구성을 요청하고, 코어망으로부터 CP 전용망 정보를 획득할 수 있다. 또는 CP가 통신사의 영업 지점을 통해 데이터 과금 부담 상품을 청약할 수 있는데, 이 경우, 데이터 정책 제어 장치(200)는 코어망으로부터 CP 전용망 정보를 획득할 수 있다. 데이터 과금 부담 상품은 일종의 전용망 상품일 수 있다.When the data policy control apparatus 200 receives a data charge burden product subscription from the CP apparatus 100, the data policy control apparatus 200 may request a CP dedicated network configuration from the core network and obtain CP dedicated network information from the core network. Alternatively, the CP may subscribe to the data billing product through the sales office of the telecommunication company. In this case, the data policy control apparatus 200 may obtain CP dedicated network information from the core network. The data charging product may be a kind of dedicated network product.
데이터 정책 제어 장치(200)는 데이터 과금 부담 정책을 등록한 CP의 전용망 정보를 관리한다. CP 전용망 정보는 전용망 구성 정책, CP의 제3자 과금 어플리케이션에 할당된 전용망 접속 정보 등을 포함할 수 있고, 정책 및 과금 제어 장치(10)로부터 전달될 수 있다. 단말(300)이 전용망 접속 가능 상태가 아닌 경우, 데이터 정책 제어 장치(200)는 전용망 접속 정보를 단말(300)로 전달하여 전용망 접속 준비를 요청할 수 있다. 이렇게 데이터 정책 제어 장치(200)의 제어에 따라 단말(300)에서 제3자 과금 어플리케이션과 전용망 접속 정보가 매핑되어, 제3자 과금 어플리케이션의 트래픽이 전용망으로 전송될 수 있다. 전용망 접속 정보는 예를 들면, LTE 네트워크에서의 접속점 이름(Access Point Name, APN)이나 5G 네트워크에서의 데이터 네트워크 이름(Data Network Name, DNN)일 수 있는데, 망 구조에 따라 CP에 할당된 전용망을 특정하기 위한 정보이다. 본 발명에서는 APN을 망 접속 정보의 예로 설명한다. The data policy control apparatus 200 manages dedicated network information of a CP that has registered a data charging burden policy. The CP dedicated network information may include a dedicated network configuration policy, dedicated network access information assigned to a third party billing application of the CP, and may be transmitted from the policy and charging control device 10. When the terminal 300 is not in the exclusive network access state, the data policy control apparatus 200 may transmit the private network access information to the terminal 300 to request preparation for access to the private network. As described above, the third party billing application and the dedicated network access information are mapped in the terminal 300 according to the control of the data policy control apparatus 200, so that the traffic of the third party billing application may be transmitted to the dedicated network. The dedicated network access information may be, for example, an access point name (APN) in an LTE network or a data network name (DNN) in a 5G network. Information for specifying. In the present invention, the APN is described as an example of network access information.
전용 APN을 수신한 단말(300)은 가상 네트워크 인터페이스를 생성하여 전용망 접속을 준비하는데, 데이터 정책 제어 장치(200)가 전용 APN을 단말(300)로 전송하는 시점은 전용 APN 할당 및 전달 규칙에 따라 다를 수 있다. 한 실시예에 따르면, 전용 APN은 CP의 데이터 과금 부담 정책을 위한 전용망 구성이 완료된 후, 또는 CP가 지정한 제3자 과금 어플리케이션에 대한 전용망 접속이 인증된 후에, 단말(300)로 전송될 수 있다. 다른 실시예에 따르면, 전용 APN은 코어망에서 전용망 구성이 완료된 상태에서, 전용망 접근이 가능한 사용자 단말(예를 들면, 전용망 상품인 GiGA Cube 가입자 단말)로 전달될 수 있다. 또 다른 실시예에 따르면, 전용 APN은 단말의 라우팅 프로파일에 미리 저장될 수 있다. 데이터 정책 제어 장치(200)는 단말(300)로부터 제3자 과금 어플리케이션에 대한 제3자 과금(전용망 접속)을 요청받는 경우, 저장된 데이터 과금 부담 정책/제3자 과금 어플리케이션 인증 정책을 기초로 단말(300)에 설치된 제3자 과금 어플리케이션의 전용망 접속을 인증한다. 제3자 과금 어플리케이션은 CP가 설정한 데이터 과금 부담 정책에 따라 항상 CP(제3자)에게 과금되거나, 데이터 정책 제어 장치(200)에 의한 인증이 유효한 동안 CP에게 과금되도록 제어될 수 있다. 즉, 데이터 정책 제어 장치(200)에 의한 전용망 접속 인증 전이나 인증 만료된 경우라면, 단말(300)은 제3자 과금 어플리케이션이라고 하더라도 공용망 접속 정보(예를 들면, 공용 APN)를 설정하여, 사용자 과금되는 일반 어플리케이션으로 취급한다. Upon receiving the dedicated APN, the terminal 300 creates a virtual network interface to prepare for access to the private network. The time point when the data policy control apparatus 200 transmits the dedicated APN to the terminal 300 depends on a dedicated APN allocation and delivery rule. can be different. According to an embodiment, the dedicated APN may be transmitted to the terminal 300 after the configuration of the dedicated network for the data charging burden policy of the CP is completed or after the dedicated network access to the third party charging application designated by the CP is authenticated. . According to another embodiment, the dedicated APN may be delivered to a user terminal (eg, a GiGA Cube subscriber terminal, which is a dedicated network product) accessible to the dedicated network in a state in which the dedicated network configuration is completed in the core network. According to another embodiment, the dedicated APN may be stored in advance in the routing profile of the terminal. When the data policy control apparatus 200 receives a third party billing (dedicated network access) for the third party billing application from the terminal 300, the terminal is based on the stored data billing burden policy / third party billing application authentication policy. Authenticate the dedicated network access of the third party billing application installed in 300. The third party billing application may be controlled to always be charged to the CP (third party) according to the data charge burden policy set by the CP, or charged to the CP while authentication by the data policy control apparatus 200 is valid. That is, if the private network connection authentication by the data policy control device 200 or when the authentication has expired, the terminal 300 sets the public network connection information (for example, the public APN) even if the third party billing application, Treat it as a general application that is billed by the user.
단말(300)은 데이터 정책 제어 장치(200)에 의해 인증된 제3자 과금 어플리케이션에 대해 전용 APN을 설정함으로써, 제3자 과금 어플리케이션에서 발생된 트래픽을 전용 APN에 지정된 전용망으로 전송할 수 있다. 단말(300)의 제3자 과금 어플리케이션에서 패킷이 생성되면, 전용 APN을 포함하는 접속 요청 메시지가 기지국(30)을 거쳐 이동성 관리 장치(Mobility Management Entity, MME)(31)로 전달된다. MME(31)는 접속 요청 메시지에 포함된 전용 APN의 전용망 구성 정책을 확인하고, S-GW(32), P-GW(33)를 통해 제3자 과금 어플리케이션의 트래픽 송수신을 위한 전용망(전용 베어러)을 설정한다. 이를 통해, 제3자 과금 어플리케이션의 트래픽은 전용 APN에 할당된 전용망의 P-GW(33)를 통해 송수신되고, 전용망에서 송수신된 데이터량이 과금 장치(20)에서 수집된다.The terminal 300 may set the dedicated APN for the third party billing application authenticated by the data policy control apparatus 200 to transmit traffic generated in the third party billing application to the dedicated network designated in the dedicated APN. When the packet is generated in the third party charging application of the terminal 300, the access request message including the dedicated APN is transmitted to the mobility management entity (MME) 31 via the base station 30. The MME 31 checks the dedicated network configuration policy of the dedicated APN included in the access request message, and uses a dedicated network (dedicated bearer for transmitting and receiving traffic of the third-party charging application through the S-GW 32 and the P-GW 33). ). Through this, traffic of the third party charging application is transmitted and received through the P-GW 33 of the dedicated network allocated to the dedicated APN, and the amount of data transmitted and received in the dedicated network is collected by the charging device 20.
데이터 정책 제어 장치(200)는 과금 장치(20)로부터 획득한 각 제3자 과금 어플리케이션의 데이터 사용량을 해당 CP에 과금한다. 그리고 데이터 정책 제어 장치(200)는 CP가 구매한(계약한) 데이터 한도를 확인하고, 데이터 잔여량에 따라 복수 단말들의 무료 데이터 사용을 실시간 제어한다. 예를 들어, 특정 CP의 데이터 사용량이 계약 한도에 다다른 경우, 데이터 정책 제어 장치(200)는 특정 CP가 계약한 제3자 과금 어플리케이션을 확인하고, 단말(300)로 해당 제3자 과금 어플리케이션을 통한 무료 데이터 사용이 제한됨을 통보 및 표시할 수 있다. 데이터 정책 제어 장치(200)는 CP 장치(100)로 데이터 잔여량을 통보하여 데이터 추가 구입을 유도할 수 있다.The data policy control apparatus 200 charges the CP of the data usage of each third party charging application obtained from the charging apparatus 20. The data policy control apparatus 200 checks the data limit purchased by the CP (contracted), and controls the free data usage of the plurality of terminals in real time according to the remaining amount of data. For example, when the data usage of a specific CP reaches the contract limit, the data policy control apparatus 200 checks the third party billing application contracted by the specific CP, and uses the terminal 300 to check the third party billing application. May inform and indicate that the use of free data is restricted. The data policy control device 200 may notify the CP device 100 of the data remaining amount to induce the purchase of additional data.
데이터 정책 제어 장치(200)는 CP의 구매 데이터량이 소진되거나 CP와의 계약이 해지되는 등의 종료 이벤트가 발생하면, 제3자 과금 어플리케이션의 전용 APN 사용 권한이 소멸된 것으로 판단한다. 그리고, 데이터 정책 제어 장치(200)는 제3자 과금 어플리케이션의 전용 APN 접속 해제를 지시하는 인증 해제 정보를 단말(300)로 전송한다. 그러면, 단말(300)은 제3자 과금 어플리케이션의 망 접속 정보를 전용 APN에서 공용 APN으로 변경한다. 공용 APN에 매핑된 제3자 과금 어플리케이션은 일반 어플리케이션과 같이 공용망에 접속하므로, 데이터 사용량이 사용자에게 과금된다.The data policy control apparatus 200 determines that the dedicated APN usage authority of the third party billing application is terminated when an end event such as the amount of purchase data of the CP or the contract with the CP is terminated occurs. In addition, the data policy control apparatus 200 transmits, to the terminal 300, authentication release information indicating the release of the dedicated APN connection of the third party billing application. Then, the terminal 300 changes the network access information of the third party billing application from the dedicated APN to the public APN. Since the third party billing application mapped to the public APN is connected to the public network like a general application, data usage is charged to the user.
도 2를 참고하면, 단말(300)이 복수의 APN(multi-APN) 설정을 할 수 있는 경우, 데이터 정책 제어 장치(200)로부터 수신한 전용 APN(APN1)과 제3자 과금 어플리케이션(CP1 어플리케이션들)을 매핑한다. 단말(300)은 CP1 어플리케이션들이 실행되면, 라우팅 정책(routing rule)에 따라 코어망에 APN1으로의 연결을 요청한다. 이때, 전용망에서 전송되는 트래픽에 대한 과금은 CP1이 부담할 수 있다.Referring to FIG. 2, when the terminal 300 may configure a plurality of APNs, a dedicated APN (APN1) and a third party billing application (CP1 application) received from the data policy control apparatus 200 may be used. Map them). When the CP1 applications are executed, the terminal 300 requests a connection to the APN1 from the core network according to a routing rule. In this case, the CP1 may be charged for the traffic transmitted from the dedicated network.
일반 어플리케이션(CP2 APP)은 공용 APN(APN1)이 매핑되어 디폴트로 설정된 공용망으로 접속한다. 공용망에서 전송되는 트래픽에 대한 과금은 사용자가 부담한다.The general application (CP2 APP) is connected to the public network, which is set by default to which the public APN (APN1) is mapped. The user pays for the traffic transmitted on the public network.
이처럼, 데이터 과금 부담 정책은 개인 사용자가 통신망을 사용하더라도, 개인 사용자에 부여된 데이터가 차감되는 대신, CP가 구매한 데이터량에서 차감되도록 한다. 이를 통해, 고객은 CP의 데이터 과금 부담 범위 내에서, 제3자 과금 어플리케이션을 통해 무료로 콘텐츠를 이용할 수 있다. As such, the data charge burden policy allows the CP to be subtracted from the amount of data purchased by the CP, instead of the data given to the individual user, even if the individual user uses the communication network. Through this, the customer can use the content free of charge through the third party billing application, within the data billing burden of CP.
데이터 과금 부담 정책은 CP가 통신사에 가입한 상품으로 결정될 수 있고, 데이터 정책 제어 장치(200)는 CP 장치(100)로부터 데이터 과금 부담 정책이 포함된 상품 청약을 받을 수 있다. CP는 전용망 상품에 가입하고, 제3자 과금 어플리케이션을 이용하는 고객들에게 제3자 과금 서비스를 제공할 수 있다. 한편, 데이터 과금 부담 정책은 개인 사용자들이 제3자 과금 어플리케이션을 통해 일정 기간 사용한 데이터량에 대한 과금을 제3자인 CP가 전부 부담할 수 있지만, 일부 부담할 수 있다. The data charge burden policy may be determined as a product to which the CP subscribes to a telecommunication company, and the data policy control apparatus 200 may receive a product subscription including a data charge burden policy from the CP device 100. The CP may subscribe to a dedicated network product and provide a third party billing service to customers using the third party billing application. Meanwhile, the data charging burden policy may be partially paid by the third party CP, but may be partially charged by the third party billing for the amount of data used by the individual user through the third party charging application.
데이터 과금 부담 정책은, 개인 요금제와 같이, 요금 및 제어 조건에 따라 다양하게 결정될 수 있다. 예를 들면, 데이터 과금 부담 정책은 CP가 구매한 데이터량(예를 들면, 1Tbyte/월), CP가 각 고객에게 제공할 개인별 데이터량(예를 들면, 고객당 200Mbyte/월), CP가 과금을 부담할 고객 목록, CP가 과금을 부담할 어플리케이션 식별자, CP가 과금을 부담할 어플리케이션의 콘텐츠 서버 정보, CP가 과금을 부담하는 시간대, QoS 수준, 계약 기간(예를 들면, 한달, 일주일 등) 등 다양할 수 있다. 데이터 과금 부담 정책은 어플리케이션 인증 정책을 더 포함할 수 있다.The data charge burden policy may be variously determined according to charges and control conditions, such as a personal plan. For example, the data charge burden policy may include the amount of data purchased by the CP (eg 1 Tbyte / month), the amount of individual data the CP will provide to each customer (eg 200 Mbytes / month per customer), and the CP is charged. List of customers to be charged for, the application identifier to be charged by the CP, the content server information of the application to be charged by the CP, the time zone when the CP is charged, the QoS level, and the term of the contract (eg, one month, one week, etc.) And so on. The data charge burden policy may further include an application authentication policy.
데이터 정책 제어 장치(200)는 예를 들면, 표 1과 같이 CP별 전용망 상품, 정책 내용, 그리고 전용망 설정 정보를 관리한다. QoS는 예를 들면, GBR(Guaranteed Bit Rate), MBR(Maximum Bit Rate), QCI(QoS Class Identifier) 등을 포함할 수 있다. 전용 베어러(Dedicated Bearer)에 적용 가능한 상위 QCI 일 경우, 데이터 정책 제어 장치(200)는 해당 CP가 가입한 상품의 QoS 정책 생성을 위한 5-튜플을 저장할 수 있다.The data policy control apparatus 200 manages dedicated network products, policy contents, and dedicated network setting information for each CP as shown in Table 1, for example. The QoS may include, for example, a guaranteed bit rate (GBR), a maximum bit rate (MBR), a QoS class identifier (QCI), and the like. In the case of a higher QCI applicable to a dedicated bearer, the data policy control apparatus 200 may store a 5-tuple for generating a QoS policy of a product subscribed to a corresponding CP.
CP명CP name 상품IDProduct ID 구매 데이터량Purchase data amount 기간term QoSQoS 5튜플5 tuples
ktkt 2000020000 무제한 unlimited 계약기간Term GBR, MBR, QCIGBR, MBR, QCI --
카카오cacao 2000120001 200 TB200 TB 소진 시When exhausted GBR, MBR, QCIGBR, MBR, QCI --
네이버Naver 2000220002 200 TB200 TB 소진 시When exhausted GBR, MBR, QCIGBR, MBR, QCI --
도 3은 한 실시예에 따른 데이터 정책 제어 장치의 연동 구조를 설명하는 도면이다.도 3을 참고하면, 데이터 정책 제어 장치(200)는 CP 장치(100)와 연동하는 CP 정책 관리부(210), 단말(300)과 연동하는 단말 인증부(230), 프로파일 저장부(250)를 포함한다. CP 정책 관리부(210)와 단말 인증부(230)는 서로 연동하고, 프로파일 저장부(250)를 관리할 수 있다. CP 정책 관리부(210)가 코어망과 통신하는 것으로 설명하나, 코어망과 데이터 정책 제어 장치(200)의 연결 관계는 다양하게 설계될 수 있다.3 is a view illustrating an interworking structure of a data policy control apparatus according to an embodiment. Referring to FIG. 3, the data policy control apparatus 200 may include a CP policy management unit 210 interworking with the CP apparatus 100. And a terminal authentication unit 230 and a profile storage unit 250 interworking with the terminal 300. The CP policy manager 210 and the terminal authenticator 230 may interwork with each other and manage the profile storage 250. Although the CP policy manager 210 is described as communicating with the core network, the connection relationship between the core network and the data policy control apparatus 200 may be variously designed.
CP 정책 관리부(210)는 통신사의 코어망 장치들과 연동하여 CP 장치(100)로부터 수신한 데이터 과금 부담 상품의 청약을 등록하고, 데이터 과금 부담 정책의 전용망을 구성하며, 제3자 과금 어플리케이션에 관계된 데이터 사용량을 CP에게 과금할 수 있다. CP 정책 관리부(210)가 연동하는 코어망 장치들은 망에 따라 결정되는데, 예를 들면, CP 정책 관리부(210)는 데이터 과금 부담 상품의 청약을 위해 영업지원시스템(Business Support System, BSS)과 연동할 수 있다. CP 정책 관리부(210)는 데이터 과금 부담 상품의 망 구성 정책을 적용하기 위해 PCC 기능을 수행하는 PCRF/PCEF와 연동할 수 있다. CP 정책 관리부(210)는 데이터 사용량을 OCS/OFCS와 연동할 수 있다. CP 정책 관리부(210)는 가입자 서버(Home Subscriber Server, HSS)와 연동하여 사용자 프로파일을 확인할 수 있다.The CP policy management unit 210 registers the subscription of the data billing product received from the CP device 100 by interworking with the core network devices of the telecommunications company, configures a dedicated network of the data billing policy, and the third party billing application. The CP may be charged for the associated data usage. Core network devices to which the CP policy management unit 210 interoperates are determined according to the network. For example, the CP policy management unit 210 interworks with a business support system (BSS) for subscription of data billing products. can do. The CP policy management unit 210 may interwork with a PCRF / PCEF that performs a PCC function in order to apply the network configuration policy of the data billing product. The CP policy management unit 210 may link the data usage with the OCS / OFCS. The CP policy management unit 210 may check a user profile by interworking with a home subscriber server (HSS).
단말 인증부(230)는 CP가 지정한 어플리케이션 인증 정책을 기초로, 단말들에 설치된 제3자 과금 어플리케이션의 전용망 접속을 인증한다. 어플리케이션 인증 정책은 전용망이 할당된 제3자 과금 어플리케이션 정보(어플리케이션 식별자), 무결성 정보(Signiture), 사용자 정보를 포함할 수 있다. 단말 인증부(230)는 어플리케이션 마켓과 연동하여 어플리케이션 인증을 할 수 있다.The terminal authenticator 230 authenticates access to the private network of the third party billing application installed in the terminals based on the application authentication policy specified by the CP. The application authentication policy may include third party billing application information (application identifier), integrity information (Signiture), and user information to which the private network is allocated. The terminal authentication unit 230 may perform application authentication in association with the application market.
CP가 가입한 데이터 과금 부담 상품은 청약 즉시 적용 대상이 특정되지 않을 수 있다. CP는 개인 사용자에게 제3자 과금 어플리케이션을 판매하고, 제3자 과금 어플리케이션을 구입(설치)한 사용자 정보를 기초로 어플리케이션 인증 정책을 생성할 수 있다. CP 장치(100)는 데이터 정책 제어 장치(200)로 어플리케이션 인증 정책을 전달하여 인증 정책을 공유할 수 있다. 한편, 어플리케이션 인증 정책은 CP 장치(100)에서 생성될 수 있다.CP data subscription products may not be eligible for immediate payment. The CP may sell the third party billing application to the individual user and generate an application authentication policy based on the user information on which the third party billing application is purchased (installed). The CP device 100 may share an authentication policy by transferring an application authentication policy to the data policy control device 200. On the other hand, the application authentication policy may be generated in the CP device 100.
단말 인증부(230)는 단말(300)에서 제3자 과금 어플리케이션을 실행하거나, 제3자 과금 어플리케이션에 대한 전용망 접속 요청(제3자 과금 요청)을 받는 경우, CP가 지정한 어플리케이션 인증 정책을 기초로 해당 어플리케이션에 대해 전용망 접속을 인증한다. When the terminal authenticator 230 executes the third party billing application on the terminal 300 or receives a dedicated network access request (third party billing request) for the third party billing application, the terminal authentication unit 230 based on the application authentication policy specified by the CP Authenticate the private network connection to the application.
인증된 제3자 과금 어플리케이션은 단말(300)에서 전용망으로의 라우팅 정보가 매핑된다. 한편, 전용망 접속 정보(전용 APN)는 전용망 접속 요청(제3자 과금 요청)에 대한 인증과 함께 전달될 수 있고, 또는 인증 전에 미리 단말에 저장될 수 있다. 예를 들면, 전용망 접속 정보는 제3자 과금 어플리케이션 설치 시, 또는 단말에서의 전용망 정보 요청 시 단말 프로파일에 미리 저장될 수 있다. 이때, 단말(300)은 인증된 어플리케이션들을 일괄적으로 매핑할 수 있는 라우팅 컨테이너에 가상 네트워크 인터페이스를 생성하고, 가상 네트워크 인터페이스를 전용 APN이 설정된 네트워크 인터페이스에 연결하여 전용망 접속을 준비할 수 있다(도 9 참고). The authenticated third party billing application is mapped to routing information from the terminal 300 to the dedicated network. Meanwhile, the dedicated network access information (dedicated APN) may be transmitted together with the authentication for the dedicated network access request (third party billing request) or may be stored in the terminal before authentication. For example, the dedicated network access information may be previously stored in the terminal profile when the third party billing application is installed or when the exclusive network information is requested from the terminal. In this case, the terminal 300 may create a virtual network interface in a routing container capable of collectively mapping the authenticated applications, and may prepare a dedicated network connection by connecting the virtual network interface to a network interface configured with a dedicated APN (FIG. 9).
프로파일 저장부(250)는 CP별 데이터 과금 부담 정책, 어플리케이션 인증 정책, 전용망 정보 등을 저장 및 관리하고, CP 정책 관리부(210) 및 단말 인증부(230)에 의해 참조된다.The profile storage unit 250 stores and manages data charging burden policy, application authentication policy, dedicated network information, etc. for each CP, and is referred to by the CP policy management unit 210 and the terminal authentication unit 230.
이처럼, CP는 데이터 정책 제어 장치(200)와 연동하는 CP 장치(100)를 통해 데이터 과금 부담 정책, 데이터 과금 부담 가입자 목록 등을 직접 설정 및 관리하고, 데이터 사용량 조회 등을 조회할 수 있다. CP는 CP 장치(100)를 통해 데이터 부담량/데이터 잔여량을 포함하는 데이터 과금 부담 정책의 적용 상태를 보고받을 수 있다. 이를 통해 CP는 통신사에 데이터망 정책을 즉시 반영할 수 있고, 사용 현황을 실시간으로 파악할 수 있다.As such, the CP may directly set and manage a data charging policy, a data charging subscriber list, and the like through the CP device 100 interoperating with the data policy control apparatus 200 and inquire a data usage inquiry. The CP may receive a report on the application state of the data charge burden policy including the data burden / data remaining amount through the CP device 100. Through this, CP can immediately apply the data network policy to the service provider and can grasp the usage status in real time.
도 4는 한 실시예에 따른 데이터 과금 부담 서비스 제공 방법의 흐름도이다. 4 is a flowchart illustrating a data charging burden service providing method according to an exemplary embodiment.
도 4를 참고하면, 데이터 정책 제어 장치(200)는 CP로부터 특정 어플리케이션에 대한 데이터 과금 부담 상품을 청약받는다(S110). 청약 내용은 구매 데이터량, 계약 기간, QoS 등을 포함하는 각종 데이터 과금 부담 정책을 포함할 수 있다. Referring to FIG. 4, the data policy control apparatus 200 receives a data charging burden product for a specific application from a CP (S110). The subscription may include various data charging policies including purchase data amount, contract period, QoS, and the like.
데이터 정책 제어 장치(200)는 코어망에 데이터 과금 부담 상품을 등록하고, 데이터 과금 부담 정책에 따른 전용망 할당을 요청한다(S120). 예를 들어, PCRF는 전용망 구성 정책을 생성하고, P-GW에 전용망 구성 정책을 배포한다. P-GW에 공중망이 아닌 사내망이 연결되는 경우, 물리적 망 연동 작업이 함께 수행될 수 있다.The data policy control apparatus 200 registers a data charging burden product in the core network and requests a dedicated network allocation according to the data charging burden policy (S120). For example, the PCRF creates a dedicated network configuration policy and distributes the dedicated network configuration policy to the P-GW. If the P-GW is connected to the internal network rather than the public network, physical network interworking may be performed together.
데이터 정책 제어 장치(200)는 코어망으로부터 CP의 데이터 과금 부담 서비스를 위한 전용망 구성 완료를 통보받는다(S122). 전용망 구성 완료 통보 메시지는 CP에 할당된 전용망 정보를 포함하는데, CP별로 전용망이 할당되는 경우라면 CP 전용 APN을 포함할 수 있다. 데이터 정책 제어 장치(200)는 CP의 데이터 과금 부담 정책, CP에 할당된 전용망 정보를 저장한다.The data policy control apparatus 200 is informed of the completion of the dedicated network configuration for the data charging burden service of the CP from the core network (S122). The dedicated network configuration completion notification message includes information on a dedicated network allocated to the CP, and if the dedicated network is allocated for each CP, it may include a CP dedicated APN. The data policy control apparatus 200 stores a data charging burden policy of the CP and dedicated network information allocated to the CP.
데이터 정책 제어 장치(200)는 CP 장치(100)로 청약한 데이터 과금 부담 상품을 위한 전용망 구성 완료를 통보한다(S124). 즉, 데이터 정책 제어 장치(200)는 제3자 과금 어플리케이션의 전용망 사용 준비 완료를 통보한다. The data policy control apparatus 200 notifies the CP apparatus 100 of the completion of the dedicated network configuration for the data charging burden product subscribed to (S124). In other words, the data policy control apparatus 200 notifies completion of the dedicated network use of the third party billing application.
데이터 정책 제어 장치(200)는 CP 장치(100)로부터 과금 부담 대상 어플리케이션의 인증 정책을 수신한다(S130). 어플리케이션 인증 정책은 제3자 과금 어플리케이션 정보(어플리케이션 식별자), 무결성 정보(Signiture), 사용자 정보를 포함할 수 있다. 어플리케이션 인증 정책이 해당 어플리케이션을 설치한 사용자 정보를 요구하는 경우, 어플리케이션 설치 시마다 갱신될 수 있다. 어플리케이션 인증 정책에 따라, 어플리케이션 인증 정책이 데이터 과금 부담 정책에 포함되어 계약될 수 있다. The data policy control apparatus 200 receives an authentication policy of a charging burden target application from the CP apparatus 100 (S130). The application authentication policy may include third party billing application information (application identifier), integrity information (Signiture), and user information. If the application authentication policy requires user information on installing the corresponding application, it may be updated every time the application is installed. According to the application authentication policy, the application authentication policy may be included in the data charge burden policy and contracted.
데이터 정책 제어 장치(200)는 단말(300)로부터 특정 어플리케이션의 전용망 접속을 위한 인증 요청을 수신한다(S140). 인증은 개별 어플리케이션이 지정한 방법을 따르거나, 사용자가 디스플레이 화면에서 어플리케이션을 어플리케이션 컨테이너로 옮기는 동작에 의해 인증 요청할 수 있다.The data policy control apparatus 200 receives an authentication request for access to a dedicated network of a specific application from the terminal 300 (S140). The authentication may be requested by an individual application according to a method designated by an individual application or by an operation of moving an application to an application container on a display screen.
데이터 정책 제어 장치(200)는 데이터 과금 부담 정책이 유효한 경우(데이터 잔여량 존재 등), 어플리케이션 인증 정책을 기초로 인증 요청에 포함된 어플리케이션 식별자에 대해 인증하고, 단말(300)로 전용망 접속을 허가한다(S142).The data policy control apparatus 200 authenticates the application identifier included in the authentication request based on the application authentication policy and permits the terminal 300 to access the private network when the data charge burden policy is valid (data remaining amount, etc.). (S142).
단말(300)은 전용망 접속이 허가된 특정 어플리케이션과 전용망 접속 정보(전용 APN)를 매핑한다(S150). 즉, 단말(300)은 특정 어플리케이션이 전용망으로 접속하도록 라우팅 정책을 변경한다. 라우팅 정책 변경은 도 7에서 설명하는 라우팅 컨테이너를 사용하거나, 도 8에서 설명하는 접속망 발견 및 선택 기능(Access Network Discovery and Selection Function, ANDSF)을 사용할 수 있다. 단말(300)은 특정 어플리케이션과 전용망 접속 정보가 매핑 완료된 경우, 사용자가 제3자 과금됨을 알 수 있도록 표시한다. The terminal 300 maps a specific application permitted to access the private network and dedicated network access information (dedicated APN) (S150). That is, the terminal 300 changes the routing policy so that a specific application is connected to the private network. The routing policy change may use the routing container described with reference to FIG. 7 or the access network discovery and selection function (ANDSF) described with reference to FIG. 8. When the specific application and the dedicated network access information are mapped, the terminal 300 displays the user to know that the third party is charged.
단말(300)은 특정 어플리케이션이 실행되면, 라우팅 정책에 따라 전용망에 접속한다(S160). 단말(300)은 전용망을 통해 특정 어플리케이션의 콘텐츠 서버에 접속하고, 트래픽을 송수신한다. 전용망은 데이터 과금 부담 정책에 따라 할당되고, 공용망과 다른 QoS가 설정될 수 있으며, 전용망 구성 정책은 P-GW 등의 코어망 장치들에 배포된다.When the specific application is executed, the terminal 300 accesses the dedicated network according to the routing policy (S160). The terminal 300 accesses a content server of a specific application through a dedicated network and transmits and receives traffic. The dedicated network is allocated according to the data charge burden policy, and a QoS different from that of the public network can be set, and the dedicated network configuration policy is distributed to core network devices such as P-GW.
데이터 정책 제어 장치(200)는 코어망의 과금 장치로부터 CP 과금정보를 수신한다(S170). CP별로 전용망을 할당하는 경우, 전용망을 통한 데이터 사용량이 그대로 CP에게 과금된다. 만약, 과금 주체가 다른 복수의 CP들이 하나의 전용망을 할당받는 경우, 각 CP가 지정한 제3자 과금 어플리케이션의 식별자를 기초로 각 CP가 부담할 데이터 사용량이 계산될 수 있다.The data policy control apparatus 200 receives CP charging information from the charging apparatus of the core network in operation S170. When the dedicated network is allocated for each CP, the data usage through the dedicated network is charged to the CP as it is. If a plurality of CPs having different billing subjects are allocated one dedicated network, the amount of data to be charged by each CP may be calculated based on an identifier of a third party billing application designated by each CP.
데이터 정책 제어 장치(200)는 CP 장치(100)로 데이터 잔여량을 포함하는 데이터 과금 부담 정책의 적용 상태를 보고한다(S180). The data policy control apparatus 200 reports the application state of the data charging burden policy including the remaining amount of data to the CP apparatus 100 (S180).
한편, 데이터 정책 제어 장치(200)는 CP의 데이터 과금 부담 상품을 청약받을 때, 어플리케이션 인증 정책을 포함하는 데이터 과금 부담 정책을 획득할 수 있다. 이 경우, 데이터 정책 제어 장치(200)는 코어망으로부터 CP의 데이터 과금 부담 상품을 위한 전용망 구성 완료를 통보받으면, CP가 지정한 어플리케이션에 대한 전용망 접속(제3자 과금)을 위한 인증을 시작한다.Meanwhile, the data policy control apparatus 200 may obtain a data charge burden policy including an application authentication policy when receiving the data charge burden product of the CP. In this case, when the data policy control apparatus 200 is informed of the completion of the dedicated network configuration for the data charging product of the CP from the core network, the data policy control apparatus 200 starts authentication for the dedicated network connection (third party charging) for the application designated by the CP.
도 4에서, 단말로 전용 APN을 전달하는 방법에 대해서 구체적으로 설명하지 않았으나, 단말로 전용 APN을 전달하는 방법은 단말에서 지원하는 APN 수, 단말이 접속할 수 있는 전용망의 수 등에 따라 다양하게 구현될 수 있다. In FIG. 4, a method of delivering a dedicated APN to a terminal has not been described in detail, but a method of delivering a dedicated APN to a terminal may be variously implemented according to the number of APNs supported by the terminal and the number of dedicated networks to which the terminal may access. Can be.
예를 들어, 단말에서 지원하는 APN의 수가 한정되지 않은 경우, CP마다 전용망을 할당하고, 전용망별 APN을 할당할 수 있다. 이 경우에는 데이터 과금 부담 상품에 가입하는 CP가 있을 때마다, CP용 전용망 접속 정보(전용 APN)를 단말에 제공할 수 있다. For example, when the number of APNs supported by the terminal is not limited, a dedicated network may be allocated for each CP and an APN for each dedicated network may be allocated. In this case, whenever there is a CP that subscribes to the data billing product, the CP dedicated network access information (dedicated APN) can be provided to the terminal.
다만, 단말에서 지원하는 APN의 수가 한정되는 경우, APN의 수에 맞춰 전용 APN과 공용 APN을 구분해 둘 수 있다. 만약, 단말이 두 개의 APN을 지원한다면, 단말은 공용망 접속을 위한 공용 APN(디폴트 APN)과 전용망 접속을 위한 전용 APN으로 단말 운영체제(Operating System, OS) 커널에 네트워크 인터페이스들을 생성하여, 전용망 접속을 준비할 수 있다. 이후 단말은 인증된 제3자 과금 어플리케이션을 전용 APN 네트워크 인터페이스에 매핑하여 제3자 과금 어플리케이션의 트래픽을 전용망으로 라우팅할 수 있다. 이 경우, CP들이 전용망을 공유한다. However, when the number of APNs supported by the terminal is limited, the dedicated APN and the public APN may be distinguished according to the number of APNs. If the terminal supports two APNs, the terminal creates network interfaces in the operating system (OS) kernel as a common APN (default APN) for accessing the public network and a dedicated APN for accessing the dedicated network, and accesses the dedicated network. You can prepare. Thereafter, the terminal may map the authenticated third party charging application to the dedicated APN network interface to route traffic of the third party charging application to the dedicated network. In this case, the CPs share the private network.
도 5는 한 실시예에 따른 데이터 정책 제어 장치가 실시간 데이터 과금 부담 서비스를 제어하는 방법의 흐름도이고, 도 6은 다른 실시예에 따른 데이터 정책 제어 장치가 실시간 데이터 과금 부담 서비스를 제어하는 방법의 흐름도이다.FIG. 5 is a flowchart illustrating a method of controlling a real-time data billing service by a data policy controlling device according to an embodiment, and FIG. 6 is a flowchart of a method of controlling a real-time data charging service by a data policy controlling device according to another embodiment. to be.
도 5를 참고하면, 데이터 정책 제어 장치(200)는 CP 전용망에서의 트래픽 송수신에 따라 변동되는 데이터 잔여량을 모니터링한다(S210).Referring to FIG. 5, the data policy control apparatus 200 monitors a data remaining amount changed according to traffic transmission / reception in a CP dedicated network (S210).
데이터 정책 제어 장치(200)는 특정 CP의 데이터 잔여량이 계약 한도에 다다른 경우, 해당 CP 장치로 데이터 소진 예정을 알린다(S220).When the data remaining amount of the specific CP reaches the contract limit, the data policy control device 200 notifies the corresponding CP device of the data exhaustion schedule (S220).
데이터 정책 제어 장치(200)는 해당 CP 장치로부터 데이터 추가를 요청받는다(S230).The data policy control device 200 receives a request for data addition from the CP device (S230).
데이터 정책 제어 장치(200)는 CP의 데이터 과금 부담 정책을 갱신한다(S240).The data policy control apparatus 200 updates the data charge burden policy of the CP (S240).
데이터 정책 제어 장치(200)는 데이터 과금 부담 정책 갱신을 해당 CP 장치로 알린다(S250).The data policy control device 200 informs the CP device of the data charge burden policy update (S250).
도 6을 참고하면, 데이터 정책 제어 장치(200) CP 전용망에서의 트래픽 송수신에 따라 변동되는 데이터 잔여량을 모니터링한다(S310).Referring to FIG. 6, the data policy control apparatus 200 monitors the amount of data remaining changed according to traffic transmission / reception in a CP dedicated network (S310).
데이터 정책 제어 장치(200)는 특정 CP의 데이터 잔여량이 계약 한도에 다다른 경우, 해당 CP 장치로 데이터 소진 예정을 알린다(S320).When the data remaining amount of the specific CP reaches the contract limit, the data policy control device 200 notifies the corresponding CP device of the data exhaustion schedule (S320).
데이터 정책 제어 장치(200)는 해당 CP의 데이터 과금 부담 정책이 갱신(데이터 추가)되지 않고, 데이터 잔여량이 소진되면, 어플리케이션 인증 정책에서 해당 CP의 제3자 과금 어플리케이션에 할당된 전용망 정보를 삭제한다(S330).If the data charge burden policy of the CP is not updated (data added) and the data remaining amount is exhausted, the data policy control apparatus 200 deletes the dedicated network information allocated to the third party billing application of the CP from the application authentication policy. (S330).
데이터 정책 제어 장치(200)는 제3자 과금 어플리케이션에 대해 전용망 접속을 허가받은 단말들로, 해당 어플리케이션의 전용망 접속에 대한 인증 해제를 지시한다(S340). 데이터 정책 제어 장치(200)는 계약 데이터량이 소진되거나 CP와의 계약이 해지되는 경우 등의 이벤트가 발생하면, 제3자 과금 어플리케이션의 전용망 사용 권한이 소멸된 것으로 판단한다. 그리고, 데이터 정책 제어 장치(200)는 제3자 과금 어플리케이션의 전용망 사용 권한 없음을 나타내는 인증 해제 정보를 단말(300)로 전송한다.The data policy control apparatus 200 instructs terminals that are permitted to access the private network to the third party billing application and instructs release of authentication for the dedicated network connection of the corresponding application (S340). The data policy control apparatus 200 determines that the exclusive network use authority of the third party billing application has expired when an event such as a case where the contract data amount is exhausted or the contract with the CP is terminated occurs. In addition, the data policy control apparatus 200 transmits to the terminal 300 authentication release information indicating that the third party billing application does not have a right to use a dedicated network.
인증 해제를 통보받은 단말(300)은 제3자 과금 어플리케이션이 사용자에게 과금되는 공용 APN으로 망 접속하도록 라우팅 정책을 변경한다(S350). 즉, 제3자 과금 어플리케이션의 라우팅 정책이 전용 APN에서 공용 APN으로 변경된다. 단말(300)은 데이터 정책 제어 장치(200)로 인증 해제 통보에 대해 응답할 수 있다. The terminal 300 notified of the authentication release changes the routing policy so that the third party charging application accesses the network to the public APN charged to the user (S350). That is, the routing policy of the third party billing application is changed from the dedicated APN to the public APN. The terminal 300 may respond to the authentication release notification to the data policy control apparatus 200.
단말(300)은 제3자 과금 어플리케이션이 사용자 과금되는 일반 어플리케이션으로 변경됨을 표시한다(S360). 단말(300)은 CP 전용 APN에서 사용자에게 과금되는 공용 APN으로 라우팅 정책을 변경한 후, 일반 어플리케이션으로의 상태 변경을 표시한다. 예를 들면, 단말(300)은 어플리케이션 아이콘에 표시된 제3자 과금 표시를 삭제하거나, 제3자 과금 어플리케이션들이 포함하는 라우팅 컨테이너에서 해당 어플리케이션을 삭제할 수 있다.The terminal 300 indicates that the third party billing application is changed to a general application for which the user is billed (S360). The terminal 300 changes the routing policy from the CP dedicated APN to the common APN charged to the user, and then displays the state change to the general application. For example, the terminal 300 may delete the third party billing display displayed on the application icon or delete the corresponding application from the routing container included in the third party billing applications.
한편, 어플리케이션과 특정 APN을 매핑하기 위해, 어플리케이션에 단말 운영체제(OS)의 네트워크 인터페이스를 특정할 수 있는 API(PDN Select API)를 개별적으로 포함시켰다. 하지만, 이러한 방법은 어플리케이션이 PDN Select API를 포함해야 하고, 데이터 과금 부담 정책이나 인증 정책의 변경에 따라 라우팅 정보를 실시간으로 변경하기 어렵다.Meanwhile, in order to map an application and a specific APN, an application (PDN Select API) for specifying a network interface of a terminal operating system (OS) is separately included in the application. However, this method requires the application to include the PDN Select API, and it is difficult to change the routing information in real time according to the data charging policy or the authentication policy.
다음에서 어플리케이션 수정 없이, 데이터 정책 제어 장치(200)의 제어에 따라 단말이 어플리케이션별 망 접속 정보(전용 APN, 공용 APN)를 변경하는 방법에 대해 설명한다. 이를 통해 단말(300)이 데이터 정책 제어 장치(200)의 제어에 따라 제3자가 지정한 어플리케이션에 전용 APN이 할당된 네트워크 인터페이스를 연결하거나, 공용 APN이 할당된 네트워크 인터페이스를 연결할 수 있다. 이를 통해, 특정 어플리케이션 트래픽이 데이터 정책 제어 장치(200)의 제어에 따라 전용망/공용망으로 전송될 수 있고, 제3자(CP)의 데이터 과금 부담 서비스를 활성화할 수 있다.Next, a method of changing the application-specific network access information (dedicated APN, public APN) according to the control of the data policy control apparatus 200 will be described. Through this, the terminal 300 may connect a network interface allocated with a dedicated APN to an application designated by a third party or connect a network interface assigned with a common APN under the control of the data policy control apparatus 200. Through this, specific application traffic may be transmitted to a dedicated network / public network under the control of the data policy control apparatus 200, and may activate a data charging service of a third party (CP).
도 7은 한 실시예에 따른 라우팅 컨테이너 기반 어플리케이션 라우팅 제어 구조를 개념적으로 설명하는 도면이고, 도 8은 다른 실시예에 따른 라우팅 정책 관리 기반 어플리케이션 라우팅 제어 구조를 개념적으로 설명하는 도면이다.7 is a diagram conceptually illustrating a routing container based application routing control structure according to an embodiment, and FIG. 8 is a diagram conceptually illustrating a routing policy management based application routing control structure according to another embodiment.
도 7과 도 8을 참고하면, 단말(300)은 데이터 정책 제어 장치(200)로부터 인증된 어플리케이션의 트래픽을 전용망으로 분기(라우팅)하기 위해, 전용망 접속이 인증된 어플리케이션을 전용 APN으로 라우팅하는 라우팅 기능이 필요하다. 라우팅 기능은 단말의 어플리케이션 프레임워크(Application Framework)와 운영 체제(OS)에 따라 구현될 수 있다.Referring to FIGS. 7 and 8, in order to branch (routing) the traffic of the application authenticated from the data policy control apparatus 200 to the dedicated network, the terminal 300 routes the application authenticated to the dedicated network to the dedicated APN. Function is required The routing function may be implemented according to an application framework and an operating system (OS) of the terminal.
먼저 도 7을 참고하면, 단말(300a)의 어플리케이션 프레임워크와 운영 체제에서 어플리케이션 단위 라우팅 기능을 제공하는 경우, 단말(300a)은 데이터 정책 제어 장치(200)와 통신하여 특정 어플리케이션에 대한 전용망 접속을 인증받거나 인증 해제하는 라우팅 인증부(Routing Authentication)(310), 어플리케이션들에 대한 라우팅 룰을 통합 관리하는 라우팅 관리부(330a), 그리고 인증된 특정 어플리케이션들에 대한 전용망 접속 정보를 관리하는 라우팅 컨테이너(350)를 포함한다. 라우팅 관리부(330a)는 공용망 접속을 위한 라우팅 룰(일반 라우팅 룰)뿐만 아니라, 라우팅 컨테이너(350)를 위한 라우팅 룰(전용 라우팅 룰)을 관리한다. 일반 라우팅 룰은 앱1/앱2를 공용 APN으로 연결하는 라우팅 룰을 포함할 수 있다.First, referring to FIG. 7, when the application framework of the terminal 300a and the operating system provide the application unit routing function, the terminal 300a communicates with the data policy control apparatus 200 to establish a dedicated network connection for a specific application. Routing Authentication 310 for authenticating or deauthenticating, Routing management unit 330a for integrating routing rules for applications, and Routing container 350 for managing dedicated network access information for specific authenticated applications. ). The routing manager 330a manages not only a routing rule (general routing rule) for the public network connection, but also a routing rule (dedicated routing rule) for the routing container 350. The general routing rule may include a routing rule that connects App1 / App2 to the public APN.
라우팅 인증부(310)가 사용자로부터 앱3/앱4에 대한 전용망 접속을 요청받는 경우, 데이터 정책 제어 장치(200)로 앱3/앱4의 전용망 접속을 위한 인증을 요청한다. 라우팅 인증부(310)는 데이터 정책 제어 장치(200)로부터 전용망 접속에 대한 인증 결과를 수신한다. When the routing authentication unit 310 receives a request for a dedicated network access to the app 3 / app 4 from the user, the routing authentication unit 310 requests the data policy control device 200 to authenticate the access to the dedicated network of the app 3 / app 4. The routing authentication unit 310 receives an authentication result for the dedicated network connection from the data policy control apparatus 200.
앱3/앱4의 전용망 접속이 허가된 경우, 라우팅 관리부(330a)는 앱3/앱4를 전용 APN에 매핑하는 전용 라우팅 룰을 설정한다. 즉, 라우팅 관리부(330a)는 앱3/앱4가 라우팅 컨테이너(350)를 통해 전용 APN에 연결되도록 전용 라우팅 룰을 관리한다. If the dedicated network connection of the App 3 / App 4 is permitted, the routing manager 330a sets a dedicated routing rule for mapping the App 3 / App 4 to the dedicated APN. That is, the routing manager 330a manages a dedicated routing rule so that App3 / App4 is connected to the dedicated APN through the routing container 350.
라우팅 컨테이너(350)는 전용 라우팅 룰에 따라 데이터 정책 제어 장치(200)에 의해 인증된 어플리케이션 그룹을 전용망으로 접속시키는 가상 네트워크 인터페이스가 할당된다. The routing container 350 is assigned a virtual network interface for connecting an application group authenticated by the data policy control apparatus 200 to a private network according to a dedicated routing rule.
단말에서 두 개의 APN 설정이 가능한 경우, 공용망 접속을 위한 공용 APN(디폴트 APN)과 전용망 접속을 위한 전용 APN을 설정할 수 있다. 전용 APN은 도 7의 (a)와 같이 특정 기업의 사내망(intranet)으로 연결되는 기업 전용망에 할당된 인트라넷 APN이거나, 도 7의 (b)와 같이 특정 CP의 컨텐츠 서버에 연결되는 CP 전용망에 할당된 스폰서 APN일 수 있다.If two APNs are configured in the terminal, a common APN (default APN) for accessing the public network and a dedicated APN for accessing the dedicated network may be configured. The dedicated APN is an intranet APN assigned to an enterprise dedicated network connected to an intranet of a specific company as shown in FIG. 7A, or a CP dedicated network connected to a content server of a specific CP as shown in FIG. 7B. It may be an assigned sponsor APN.
도 7의 (a)를 참고하면, 단말(300a)에 복수의 어플리케이션들이 설치되어 있고, 이 중 앱3 및 앱4가 특정 기업의 사내망에 연결되는 특정 기업 전용 어플리케이션이라고 가정한다. 특정 기업 전용 어플리케이션에서 사용한 데이터량은 특정 기업이 부담한다고 가정한다. 이 경우, 데이터 정책 제어 장치(200)는 앱3 및 앱4에서 발생한 트래픽을 특정 기업의 사내망으로 전달하기 위한 기업 전용망 할당 및 전용망 구성을 한다. Referring to (a) of FIG. 7, it is assumed that a plurality of applications are installed in the terminal 300a, and among these, the app 3 and the app 4 are specific company-specific applications connected to a corporate network of a specific company. It is assumed that the amount of data used in a specific company-specific application is borne by the specific company. In this case, the data policy control apparatus 200 configures a corporate dedicated network and configures a dedicated network for delivering traffic generated in the App 3 and the App 4 to an internal network of a specific company.
라우팅 인증부(310)가 데이터 정책 제어 장치(200)로부터 앱3/앱4의 전용망 접속을 허가받으면, 앱3/앱4는 전용 APN에 연결된 라우팅 컨테이너(350)에 매핑된다. 이를 통해 앱3/앱4는 전용망 접속 가능한 상태가 된다. 라우팅 컨테이너(350)는 특정 기업 전용 어플리케이션을 위한 컨테이너일 수 있다. When the routing authentication unit 310 is authorized to access the dedicated network of the app 3 / app 4 from the data policy control device 200, the app 3 / app 4 is mapped to the routing container 350 connected to the dedicated APN. This makes App3 / App4 accessible to the private network. The routing container 350 may be a container for a specific enterprise-specific application.
앱3/앱4가 실행되면, 앱3/앱4의 트래픽은 전용 APN을 통해 연결된 전용망으로 전송된다.When App3 / App4 is running, traffic from App3 / App4 is sent to a dedicated network connected via a dedicated APN.
만약, 라우팅 인증부(310)가 데이터 정책 제어 장치(200)로부터 앱3/앱4의 인증 해제를 수신하면, 라우팅 관리부(330a)는 앱3/앱4를 일반 라우팅 룰에 매핑한다. 그러면, 앱3/앱4는 전용 APN에 연결된 라우팅 컨테이너(350) 대신 일반 라우팅 룰에 따라 공용 APN으로 접속하게 된다. If the routing authenticator 310 receives the authentication deactivation of the app 3 / app 4 from the data policy control device 200, the routing manager 330a maps the app 3 / app 4 to the general routing rule. Then, the App 3 / App 4 is connected to the public APN according to the general routing rules instead of the routing container 350 connected to the dedicated APN.
도 7의 (b)를 참고하면, 단말(300a)에 복수의 어플리케이션들이 설치되어 있고, 앱3 및 앱4가 특정 CP가 제3자 과금 서비스를 제공하는 스폰서 어플리케이션이라고 가정한다. 스폰서 어플리케이션에서 사용한 데이터량은 특정 CP가 부담한다고 가정한다. 이 경우, 데이터 정책 제어 장치(200)는 앱3 및 앱4에서 발생한 트래픽을 특정 컨텐츠 서버로 전달하기 위한 CP 전용망 할당 및 전용망 구성을 한다. Referring to FIG. 7B, it is assumed that a plurality of applications are installed in the terminal 300a, and the app 3 and the app 4 are sponsored applications in which a specific CP provides a third party billing service. It is assumed that the amount of data used in the sponsor application is borne by a specific CP. In this case, the data policy control apparatus 200 configures a CP dedicated network allocation and a dedicated network for delivering traffic generated in App 3 and App 4 to a specific content server.
스폰서 어플리케이션에 대한 전용망 접속 인증 및 전용망 접속 방법은 도 7의 (a)에서 설명한 기업 전용 어플리케이션과 유사하다. 전용 APN과 공용 APN의 목적지 PDN이 동일 인터넷망이라고 하더라도, APN에 따라 트래픽 경로가 분리된다. Dedicated network access authentication and private network access method for the sponsor application is similar to the enterprise-specific application described in Figure 7 (a). Even though the destination PDN of the dedicated APN and the public APN are the same Internet network, the traffic paths are separated according to the APN.
한편, 앱3 및 앱4가 반드시 동일 CP가 제공하는 스폰서 어플리케이션일 필요는 없다. 즉, 동일 전용망을 사용하는 앱3 및 앱4가 서로 다른 CP에 과금되는 경우, 과금 장치는 어플리케이션 식별자나 목적지 주소 등을 기초로 어플리케이션을 구분할 수 있어서, 어플리케이션별로 데이터 사용량을 과금할 수 있다.On the other hand, App 3 and App 4 is not necessarily a sponsor application provided by the same CP. That is, when App3 and App4 using the same dedicated network are charged to different CPs, the charging device may classify the applications based on the application identifier or the destination address, thereby charging data usage for each application.
도 8을 참고하면, 단말(300b)의 어플리케이션 프레임워크와 운영체제(OS)에서 어플리케이션 단위 라우팅 기능을 제공하지 못하는 경우, 단말(300b)은 인증된 특정 어플리케이션들을 라우팅 컨테이너(350)에 매핑하여 라우팅할 수 없다. Referring to FIG. 8, when the application framework of the terminal 300b and the operating system (OS) do not provide an application-specific routing function, the terminal 300b may map specific authenticated applications to the routing container 350 to route them. Can not.
이를 위해, 단말(300b)은 어플리케이션 단위 라우팅 기능을 제공하지 못하기 때문에, 접속망 발견 및 선택 기능(Access Network Discovery and Selection Function, ANDSF)의 ISMP(Inter-System Mobility Policy)/ISRP(Inter-System Routing Policy)를 이용할 수 있다. ISMP는 LTE/WiFi 중 접속 선호망을 정의하고, ISRP는 목적 데이터망(PDN)의 APN에 따라 접속 선호망을 정의할 수 있다. 다만, ISMP/ISRP는 출발지/목적지(Source/Destination) 기반의 IP 흐름 라우팅 정책(IP Flow Routing Rule)만 존재하므로, 어플리케이션 기반 라우팅 정책을 설정하는 ANDSF 관리부(370)를 추가한다. To this end, since the terminal 300b does not provide an application-specific routing function, an inter-system mobility policy (ISMP) / inter-system routing (ISRP) of an access network discovery and selection function (ANDSF). Policy) can be used. ISMP may define a connection preference network among LTE / WiFi, and ISRP may define a connection preference network according to the APN of a destination data network (PDN). However, since ISMP / ISRP has only an IP flow routing rule based on a source / destination, an ANDSF management unit 370 for setting an application based routing policy is added.
ANDSF 관리부(370)는 확장된 MO(Management Object)에 따라 어플리케이션별 APN을 추가로 정의할 수 있다. 여기서, 확장된 MO는 APN과 접속망을 정의하는 MO를 어플리케이션까지 확장한 것으로서, 어플리케이션-APN-접속망을 한 세트(full set)로 라우팅할 수 있도록 정의한다. 확장된 MO는 단말에 구현된 ANDSF 관련 모델에 추가 구현될 수 있다. 이렇게, ANDSF 관리부(370)가 확장된 MO를 통해 ISRP에서 요구하는 전용망 및 어플리케이션의 인증 정보를 제공할 수 있다. ANDSF 관리부(370)가 어플리케이션 기반 라우팅 정책을 추가/삭제/갱신하는 알고리즘은 OMA- DM(Device Management)의 규격을 따를 수 있다.The ANDSF management unit 370 may further define application-specific APNs according to the extended management object (MO). Here, the extended MO is an extension of the MO defining the APN and the access network to the application and is defined so that the application-APN access network can be routed as a full set. The extended MO may be further implemented in the ANDSF related model implemented in the terminal. In this way, the ANDSF management unit 370 may provide the authentication information of the dedicated network and the application required by the ISRP through the extended MO. The algorithm in which the ANDSF management unit 370 adds / deletes / updates an application-based routing policy may follow a standard of OMA-DM (Device Management).
라우팅 인증부(310)가 도 7에서와 같이, 데이터 정책 제어 장치(200)로부터 앱1의 전용망 접속을 인증받으면, ANDSF 관리부(370)로 앱1의 전용망 접속 정보(전용 APN)를 전달한다. 그러면, ANDSF 관리부(370)가 앱1의 전용망 접속 정보(전용 APN)를 라우팅 관리부(330b)에 반영한다. As shown in FIG. 7, when the routing authentication unit 310 authenticates the dedicated network connection of the app 1 from the data policy control device 200, the routing authentication unit 310 transmits the exclusive network access information (dedicated APN) of the app 1 to the ANDSF management unit 370. Then, the ANDSF management unit 370 reflects the dedicated network access information (dedicated APN) of the App 1 to the routing management unit 330b.
앱1이 실행되면, 라우팅 관리부(330b)에서 앱1에 매핑된 라우팅 룰에 따라, 전용 APN을 통해 전용망에 연결된다.When the app 1 is executed, the routing manager 330b is connected to the dedicated network through the dedicated APN according to the routing rule mapped to the app 1.
만약, 라우팅 인증부(310)가 데이터 정책 제어 장치(200)로부터 앱1의 인증 해제를 수신하면, ANDSF 관리부(370)가 앱1의 APN을 공용 APN으로 변경하여 라우팅 관리부(330b)에 반영한다.If the routing authenticator 310 receives the authentication deactivation of the App 1 from the data policy control device 200, the ANDSF management unit 370 changes the APN of the App 1 to the public APN and reflects it to the routing management unit 330b. .
도 9는 한 실시예에 따른 라우팅 컨테이너 기반 단말 구조에서의 전용망 접속을 설명하는 도면이다.9 is a diagram illustrating a dedicated network connection in a routing container based terminal structure according to an embodiment.
도 9를 참고하면, 단말(300)은 데이터 정책 제어 장치(200)와 통신하여 전용망 접속을 준비하는데, 표 2와 같은 프로파일을 통해 망 접속 정보(APN)와 네트워크 인터페이스를 관리한다. 단말(300)은 전용망 접속이 가능한 가입자 단말로서, 전용망 상품 가입자이거나, 제3자 과금 어플리케이션 가입자일 수 있다.Referring to FIG. 9, the terminal 300 communicates with the data policy control apparatus 200 to prepare a dedicated network connection, and manages network access information (APN) and network interface through a profile as shown in Table 2. The terminal 300 is a subscriber terminal capable of accessing a dedicated network, and may be a subscriber of a dedicated network product or a third party billing application subscriber.
서비스 유형Service type APNAPN 네트워크 인터페이스Network interface 가상 인터페이스Virtual interface
일반LTE(무선망#1)General LTE (Wireless Network # 1) lte.kt.comlte.kt.com rmnet0rmnet0 --
MMSMMS lte.kt.comlte.kt.com rmnet0rmnet0 --
IMSIMS ims.kt.comims.kt.com rmnet1rmnet1 --
전용LTE(무선망#2)Dedicated LTE (Wireless Network # 2) special.lte.kt.comspecial.lte.kt.com rmnet2rmnet2 vEthernet1vEthernet1
도 9의 (a)를 참고하면, 라우팅 컨테이너 기반으로 전용망에 접속하기 위해, 단말(300)은 전용망(무선망#2) 네트워크 인터페이스(rmnet2)에 전용 APN(Special.lte.kt.com)을 할당한다. 단말(300)은 데이터 정책 제어 장치(200)의 제어에 따라 전용 APN을 갱신할 수 있다.그리고, 단말(300)은 라우팅 컨테이너의 가상 네트워크 인터페이스(vEthernet1)와 네트워크 인터페이스(rmnet2)를 연결한다. 가상 네트워크 인터페이스(vEthernet1)는 단말의 글로벌 네트워크 인터페이스와 L2 레벨로 연결될 수 있다. 만약, 단말에서 복수의 APN 설정을 지원하는 경우, 전용망별 APN에 대응하여 복수의 라우팅 컨테이너가 생성될 수 있다.Referring to (a) of FIG. 9, in order to access a dedicated network based on a routing container, the terminal 300 provides a dedicated APN (Special.lte.kt.com) to a dedicated network (wireless network # 2) network interface rmnet2. Assign. The terminal 300 may update the dedicated APN under the control of the data policy control apparatus 200. The terminal 300 connects the virtual network interface vEthernet1 and the network interface rmnet2 of the routing container. The virtual network interface vEthernet1 may be connected to the global network interface of the terminal at the L2 level. If the terminal supports a plurality of APN settings, a plurality of routing containers may be created corresponding to APNs for each dedicated network.
도 9의 (b)를 참고하면, 데이터 정책 제어 장치(200)에 의해 앱3/앱4의 전용망 접속이 허가된 경우, 단말(300)은 앱3/앱4에 대해서 라우팅 컨테이너의 가상 네트워크 인터페이스(vEthernet1)로 연결되는 라우팅 룰을 설정한다. 가상 네트워크 인터페이스(vEthernet1)는 전용망(무선망#2) 네트워크 인터페이스(rmnet2)에 일대일로 매핑되어 있으므로, 앱3/앱4의 트래픽은 전용망(무선망#2) 네트워크 인터페이스(rmnet2)로 라우팅된다. 앱1/앱2는 공용망(무선망#1)에 접속하는 라우팅 룰이 설정되어 있는데, 데이터 정책 제어 장치(200)로부터 전용망 접속을 위한 인증을 받을 수 있다. 그러면, 앱1/앱2 역시 라우팅 컨테이너의 가상 네트워크 인터페이스(vEthernet1)로 연결되는 라우팅 룰을 적용받는다.Referring to FIG. 9B, when the data policy control apparatus 200 permits access to a dedicated network of the app 3 / app 4, the terminal 300 accesses the virtual network interface of the routing container with respect to the app 3 / app 4. Set the routing rule that connects to (vEthernet1). Since the virtual network interface vEthernet1 is mapped one-to-one to the dedicated network (wireless network # 2) network interface rmnet2, the traffic of App3 / App4 is routed to the dedicated network (wireless network # 2) network interface rmnet2. App 1 / App 2 has a routing rule for accessing the public network (wireless network # 1) is set, can be authenticated for access to the private network from the data policy control device 200. Then, App 1 / App 2 is also subject to the routing rules connected to the virtual network interface (vEthernet1) of the routing container.
한편, 어플리케이션 계층에 라우팅 컨테이너의 가상 네트워크 인터페이스(vEthernet1)에 연결되는 어플리케이션들을 위한 어플리케이션 컨테이너가 생성될 수 있다. 다음에서, 단말이 어플리케이션 컨테이너를 통해 제3자 과금 어플리케이션(또는 전용망 접속 어플리케이션)과 개인 사용자에게 과금되는 일반 어플리케이션(또는 공용망 접속 어플리케이션)을 구분하여 표시하고, 전용망 접속을 인증하는 방법에 대해서 설명한다.Meanwhile, an application container for applications connected to the virtual network interface vEthernet1 of the routing container may be created in the application layer. In the following, the terminal distinguishes and displays a third party billing application (or a private network access application) and a general application (or a public network access application) charged to an individual user through an application container, and describes a method of authenticating a private network connection. do.
도 10은 한 실시예에 따른 어플리케이션 컨테이너를 포함하는 단말 인터페이스 화면의 예시이다. 10 is an example of a terminal interface screen including an application container according to an embodiment.
도 10의 (a)를 참고하면, 제3자에게 과금되는 어플리케이션과 개인 사용자에게 과금되는 어플리케이션을 구분하기 위한 사용자 인터페이스로서 어플리케이션 컨테이너(400)가 있다. 어플리케이션 컨테이너(400)는 폴더 형태/박스 형태로서, 인증된 제3자 과금 어플리케이션이 어플리케이션 컨테이너(400)에 위치할 수 있다. 이때, 사용자가 어플리케이션 컨테이너 외부에 위치한 어플리케이션을 드래그앤드롭(drag and drop) 등의 다양한 방법으로 어플리케이션 컨테이너 안으로 옮기며, 단말(300)은 데이터 정책 제어 장치(200)로 해당 어플리케이션의 제3자 과금을 위한 인증을 요청할 수 있다. 또한, 어플리케이션 컨테이너 밖으로 옮기는 동작에 의해 전용망을 사용하지 않을 수 있다. 어플리케이션 컨테이너(400)는 모바일 단말 관리(Mobile Device Management, MDM) 솔루션에 의해 관리 및 보호될 수 있다. Referring to FIG. 10A, an application container 400 is used as a user interface for distinguishing between an application charged to a third party and an application charged to an individual user. The application container 400 may be in the form of a folder / box, and an authenticated third party billing application may be located in the application container 400. In this case, the user moves an application located outside the application container into the application container by various methods such as drag and drop, and the terminal 300 transmits the third party billing of the corresponding application to the data policy control device 200. May request certification. In addition, the dedicated network may not be used by moving out of the application container. The application container 400 may be managed and protected by a mobile device management (MDM) solution.
단말(300)은 데이터 정책 제어 장치(200)로부터 인증된 어플리케이션만 어플리케이션 컨테이너(400) 안에 위치시킨다. 단말(300)은 어플리케이션 컨테이너(400) 안에 위치한 어플리케이션들이 공용망이 아닌 전용망에 접속할 수 있도록 라우팅 정보를 변경한다. 만약, 어플리케이션 컨테이너 안에 위치한 어플리케이션이 밖으로 이동한다면, 단말(300)은 어플리케이션이 전용망이 아닌 공용망에 접속할 수 있도록 라우팅 정보를 변경한다.The terminal 300 places only applications authenticated by the data policy control apparatus 200 in the application container 400. The terminal 300 changes routing information so that applications located in the application container 400 can access a private network instead of a public network. If the application located in the application container moves out, the terminal 300 changes the routing information so that the application can access the public network instead of the private network.
이를 위해, 라우팅 인증부(310)는 어플리케이션 컨테이너(400)으로 이동한 어플리케이션을 인지하고, 데이터 정책 제어 장치(200)로 인증요청하며, 인증 결과에 따라 어플리케이션 컨테이너(400)에 포함될 어플리케이션을 관리한다. 어플리케이션 컨테이너(400)에 위치한 어플리케이션은 도 7과 같이 라우팅 컨테이너(350)에 의해 전용 APN이 매핑되거나, 도 8과 같이 ANDSF 관리부(370)에 의해 전용 APN이 매핑될 수 있다.To this end, the routing authentication unit 310 recognizes the application moved to the application container 400, requests authentication to the data policy control device 200, and manages the application to be included in the application container 400 according to the authentication result. . An application located in the application container 400 may have a dedicated APN mapped by the routing container 350 as shown in FIG. 7, or a dedicated APN mapped by the ANDSF management unit 370 as shown in FIG. 8.
도 10의 (b)를 참고하면, 데이터 정책 제어 장치(200)에 의해 인증되어 전용망 접속이 허가된 어플리케이션은 최종적으로 어플리케이션 컨테이너 밖에서 안으로 옮겨진다. 만약, 어플리케이션이 최종적으로 어플리케이션 컨테이너 밖에 위치하는 경우, 전용망 접속을 할 수 없는 어플리케이션이다. Referring to FIG. 10B, an application authenticated by the data policy control apparatus 200 and granted access to a private network is finally moved out of an application container. If the application is finally located outside the application container, the application cannot connect to the private network.
한편, 데이터 정책 제어 장치(200)는 인증 요청된 어플리케이션이 제3자 과금 서비스를 제공하는 CP의 어플리케이션이 아닌 경우라면, 당연히 전용망 접속을 허가하지 않는다. On the other hand, the data policy control apparatus 200 does not permit access to the private network, if the application requested for authentication is not an application of a CP that provides a third party billing service.
또한, 데이터 정책 제어 장치(200)는 인증 요청된 어플리케이션이 제3자 과금 서비스를 제공하는 CP의 어플리케이션이라도, 데이터 과금 부담 정책에 따라 전용망 접속을 허가하지 않을 수 있다. 예를 들어, 데이터 정책 제어 장치(200)는 CP가 구매한 총데이터량 중 잔여량이 기준값 이하인 경우, 인증 요청된 어플리케이션에 대해 CP가 과금 부담하는 전용망 접속을 허가하지 않을 수 있다. 또는 데이터 정책 제어 장치(200)는 CP가 특정 시간대에만 과금 부담하는 경우, 계약 시간대 이외에서 인증을 요청한 어플리케이션에 대해 CP가 과금 부담하는 전용망 접속을 허가하지 않을 수 있다.In addition, the data policy control apparatus 200 may not permit access to the private network according to the data charging burden policy even if the application for which authentication is requested is an application of a CP that provides a third party billing service. For example, the data policy control apparatus 200 may not permit access to a private network that the CP charges for an application for which authentication is required when the remaining amount of the total amount of data purchased by the CP is less than or equal to the reference value. Alternatively, when the CP charges only during a specific time period, the data policy control apparatus 200 may not permit access to a dedicated network charged by the CP to an application requesting authentication outside the contract time period.
도 10의 (c)를 참고하면, 사용자가 컨테이너 안에 위치한 어플리케이션을 실행하는 경우, 단말(300)은 데이터 정책 제어 장치(200)에 인증 요청할 수 있다. Referring to FIG. 10C, when a user executes an application located in a container, the terminal 300 may request authentication from the data policy control apparatus 200.
단말(300)은 데이터 정책 제어 장치(200)로부터 컨테이너 안에 위치한 특정 어플리케이션에 대한 인증 해제를 수신하면, 인증 해제된 어플리케이션을 어플리케이션 컨테이너 밖으로 이동시킨다. 단말(300)이 인증 해제 조건을 저장하는 경우, 인증 해제 조건을 만족하는 어플리케이션을 어플리케이션 컨테이너 밖으로 이동시킬 수 있다.When the terminal 300 receives an authentication release for a specific application located in the container from the data policy control device 200, the terminal 300 moves the released application out of the application container. When the terminal 300 stores the authentication deactivation condition, the application that satisfies the deauthentication condition may be moved out of the application container.
데이터 정책 제어 장치(200)는 CP가 구매한 총데이터량이 소진된 경우, 컨테이너 안에 위치한 특정 어플리케이션에 대한 인증 해제를 단말(300)로 통보할 수 있다. 또는 데이터 정책 제어 장치(200)는 CP가 특정 시간대에만 과금 부담하는 경우, 계약 시간대가 지나면 컨테이너 안에 위치한 특정 어플리케이션에 대한 인증 해제를 단말(300)로 통보할 수 있다.When the total amount of data purchased by the CP has been exhausted, the data policy control apparatus 200 may notify the terminal 300 of the release of authentication for a specific application located in the container. Alternatively, when the CP charges only during a specific time period, the data policy control apparatus 200 may notify the terminal 300 of the release of authentication for a specific application located in the container after the contract time period passes.
이처럼, 사용자는 어플리케이션 컨테이너를 통해 제3자 과금 어플리케이션과 사용자 과금 어플리케이션을 직관적으로 구분할 수 있고, 어플리케이션 컨테이너로의 어플리케이션 이동 동작으로 간단히 인증 요청할 수 있다. 또한, 단말(300)은, 전용망 접속을 위한 가상 네트워크 인터페이스를 설정한 라우팅 컨테이너(350)와 어플리케이션 레이어의 어플리케이션 컨테이너(400)를 연결하여, 어플리케이션 컨테이너(400)에 포함된 어플리케이션들의 라우팅 정보를 관리할 수 있다.As such, the user may intuitively distinguish the third-party billing application and the user billing application through the application container, and may simply request authentication by moving the application to the application container. In addition, the terminal 300 manages routing information of applications included in the application container 400 by connecting the routing container 350 that sets the virtual network interface for the dedicated network connection to the application container 400 of the application layer. can do.
데이터 정책 제어 장치(200)는 CP의 데이터 과금 부담 정책을 실시간 반영하여 어플리케이션 컨테이너에 어플리케이션을 넣거나, 어플리케이션 컨테이너에서 어플리케이션을 뺄 수 있다.The data policy control apparatus 200 may put an application in the application container or remove the application from the application container by reflecting the data charge burden policy of the CP in real time.
도 11은 한 실시예에 따른 제3자 과금 어플리케이션을 표시하는 단말 인터페이스 화면의 예시이다. 11 is an example of a terminal interface screen displaying a third party billing application according to an embodiment.
도 11을 참고하면, 어플리케이션별로 제3자 과금되는 어플리케이션이 구분되도록 표시할 수 있다. 단말 인터페이스 화면에 표시되는 어플리케이션 아이콘으로 제3자 과금 어플리케이션과 일반 어플리케이션을 구분할 수 있다. 구분하는 방법은 제3자 과금 어플리케이션인 경우 무료 뱃지를 아이콘에 부착하거나, 아이콘 디자인을 다르게 할 수 있다. Referring to FIG. 11, it may be displayed so that applications charged by third parties are classified for each application. An application icon displayed on the terminal interface screen may distinguish a third party billing application from a general application. In the case of the third-party billing application, the free badge may be attached to the icon or the icon design may be different.
특히, CP가 각 고객에게 개인별 데이터량(예를 들면, 고객당 200Mbyte/월)을 제공하는 경우, 제3자 과금 어플리케이션의 아이콘은 할당된 데이터량의 소모량/잔여량을 시각적으로 표시할 수 있다. 예를 들어, 제3자 과금 어플리케이션의 아이콘(500, 510)은 그라데이션을 포함하고, 그라데이션 농도로 데이터량의 소모량/잔여량을 추가로 표시할 수 있다. In particular, when the CP provides individual data amount (eg, 200 Mbytes / month per customer) to each customer, the icon of the third party billing application may visually display the consumption / remaining amount of the allocated data amount. For example, the icons 500 and 510 of the third party billing application may include a gradation and additionally display the consumption / remaining amount of the data amount as the gradient concentration.
어플리케이션 목록(520)에서 각 어플리케이션의 데이터량의 소모량/잔여량/QoS 등을 확인할 수 있는 인터페이스 화면을 제공할 수 있다.In the application list 520, an interface screen for checking the consumption amount, remaining amount, and QoS of the data amount of each application may be provided.
제3자 과금 서비스 대상인 어플리케이션이라도 인증 전인 경우, 제3자 과금이 가능함을 아이콘에 표시할 수 있다. 그리고 사용자가 지정된 인증 동작(예를 들면, 아이콘을 롱터치, 어플리케이션 컨테이너로 이동 등)을 하여 데이터 정책 제어 장치(200)에 의해 전용망 접속이 허가된 경우, 단말(300)은 인증된 어플리케이션을 제3자 과금되는 어플리케이션으로 표시 변경(예를 들면, 무료 뱃지 부착 또는 그라데이션 표시)할 수 있다. 데이터 정책 제어 장치(200)에 의해 인증 해제된 경우, 단말(300)은 제3자 과금되는 어플리케이션으로 표시된 아이콘을 일반 어플리케이션 아이콘으로 변경할 수 있다.Even if the application is the target of the third party billing service, before the authentication, the third party billing may be displayed on the icon. When the user is authorized to access the private network by the data policy control apparatus 200 by performing a designated authentication operation (for example, moving an icon to a long touch or moving to an application container), the terminal 300 removes the authenticated application. It is possible to change the display (for example, to attach a free badge or to display a gradation) by a third party billing application. When the authentication is released by the data policy control apparatus 200, the terminal 300 may change an icon displayed as a third party billed application to a general application icon.
도 12는 한 실시예에 따른 제3자 과금 어플리케이션 설치 방법의 흐름도이다. 12 is a flowchart of a method of installing a third party billing application, according to an exemplary embodiment.
도 12를 참고하면, 사용자는 어플리케이션 마켓에서 제3자 과금 어플리케이션을 다운로드하여 설치하고, 이후 단말(300)이 데이터 정책 제어 장치(200)와 연동하여 어플리케이션의 트래픽을 전용망으로 전달하거나 공용망으로 경로를 변경한다. 따라서, 제3자 과금 어플리케이션은 일반 어플리케이션의 설치 방법과 유사할 수 있으나, 어플리케이션을 배포하는 CP나 기업이 특정 통신사의 전용망 상품에만 가입하거나, 통신사별로 약정한 상품이 다를 수 있다. 따라서, 다음과 같이 제3자 과금 어플리케이션 설치 시 통신망 등록 절차가 추가된다. Referring to FIG. 12, the user downloads and installs a third party billing application from the application market, and then the terminal 300 interworks with the data policy control apparatus 200 to transfer traffic of the application to a dedicated network or to a public network. Change Therefore, the third party billing application may be similar to the installation method of a general application, but a CP or a company that distributes the application may subscribe only to a specific telecommunication company's dedicated network product, or the product promised by the telecommunication company may differ. Therefore, a network registration procedure is added when installing a third party billing application as follows.
어플리케이션 마켓(600)은 제3자 과금 어플리케이션과 과금 부담 통신망 정보(예를 들면, kt)를 등록한다(S410). 과금 부담 통신망 정보는 CP가 제3자 과금을 부담하는 상품에 가입한 통신망 정보로서, 경우에 따라서 CP는 복수의 통신사 중 일부의 통신사 상품에만 가입하여 일부 통신사 가입자들에게만 제3자 과금 서비스를 제공할 수 있다. The application market 600 registers a third party billing application and billing network information (for example, kt) (S410). The billing network information is the network information that CP subscribes to the product that third party billing, and in some cases, the CP subscribes to only some of the carrier products of a plurality of carriers and provides the third party billing service only to some carrier subscribers. can do.
단말(300)은 어플리케이션 마켓(600)에서 제3자 과금 어플리케이션과 과금 부담 통신망 정보를 포함하는 설치 정보를 다운로드한다(S420). 설치 정보는 설치된 제3자 과금 어플리케이션의 무결성을 확인할 수 있는 메타 정보를 더 포함할 수 있다.The terminal 300 downloads installation information including the third party billing application and billing communication network information from the application market 600 (S420). The installation information may further include meta information for confirming the integrity of the installed third party billing application.
단말(300)은 제3자 과금 어플리케이션의 과금 부담 통신망 정보를 확인하고, 과금 부담 통신망 정보에서 지시하는 데이터 정책 제어 장치(200)에 접속하여 제3자 과금 어플리케이션 설치를 통보한다(S430). 만약, 과금 부담 통신망 정보를 확인한 결과, 단말이 CP가 3자 과금을 부담하는 상품에 가입한 통신망을 이용할 수 없는 경우(예를 들면, 타사 가입자), 제3자 과금 어플리케이션은 일반 어플리케이션과 동일하게 데이터 정책 제어 장치(200)와의 통신 단계가 생략된다.The terminal 300 checks the billing network information of the third party billing application, accesses the data policy control device 200 indicated by the billing network information, and notifies the third party billing application installation (S430). If, as a result of checking the charging burden network information, the terminal cannot use the communication network that the CP subscribed to the product paying the third party billing (for example, a third party subscriber), the third party charging application is the same as the general application. The communication step with the data policy control apparatus 200 is omitted.
데이터 정책 제어 장치(200)는 단말(300)의 제3자 과금 어플리케이션 설치를 등록한다(S440). 한편, 데이터 정책 제어 장치(200)는 제3자 과금 어플리케이션을 설치한 단말 정보를 어플리케이션 마켓(600)이나 CP 장치(100)로부터 수신할 수 있다. The data policy control apparatus 200 registers a third party billing application installation of the terminal 300 in operation S440. Meanwhile, the data policy control device 200 may receive terminal information on which the third party billing application is installed from the application market 600 or the CP device 100.
한 실시예에 따르면, 데이터 정책 제어 장치(200)는 CP가 지정한 제3자 과금 어플리케이션 인증 정책에 따라 단말(300)의 제3자 과금 어플리케이션을 인증하고, 인증 완료된 단말(300)로 제3자 과금 어플리케이션을 위한 전용망 접속 정보를 전달할 수 있다(S450). 그러면, 단말(300)은 전용망 접속이 허가된 제3자 과금 어플리케이션과 전용망 접속 정보를 매핑할 수 있다(S460). 이는 CP가 무제한으로 제3자 과금 어플리케이션에 대한 과금을 부담하는 경우, 예를 들면, 기업 전용 어플리케이션인 경우에는 설치 등록과 동시에 전용망 접속을 허가할 수 있다.According to an embodiment, the data policy control apparatus 200 authenticates the third party charging application of the terminal 300 according to the third party charging application authentication policy specified by the CP, and authenticates the third party with the terminal 300 that has been authenticated. The dedicated network access information for the billing application may be transferred (S450). Then, the terminal 300 may map the third party billing application that is permitted to access the dedicated network and the dedicated network access information (S460). This may allow the CP to unlimitedly charge the third party billing application, for example, in the case of an enterprise-only application, and permit access to the private network at the same time as the installation registration.
다른 실시예에 따르면, CP가 제3자 과금이 가능한 어플리케이션을 제공하되, 데이터 과금 부담 정책에 따라 제3자 과금을 하지 못할 수 있다. 따라서, 데이터 정책 제어 장치(200)는 3자 과금 어플리케이션 설치를 등록한 후, 단말(300)로부터 전용망 접속을 요청받으면, CP 데이터 과금 부담 정책을 확인한 후, CP의 전용망 접속 정보를 전달할 수 있다. 또는 데이터 정책 제어 장치(200)는 3자 과금 어플리케이션 설치를 등록한 후, 단말(300)로 CP의 전용망 접속 정보를 전달하되, 단말(300)로부터 전용망 접속을 요청받으면, CP 데이터 과금 부담 정책을 확인한 후, CP의 전용망 접속을 허가할 수 있다.According to another embodiment, the CP may provide an application capable of third party charging, but may not be able to charge the third party according to the data charge burden policy. Therefore, after registering the installation of the third party billing application, the data policy control apparatus 200 may check the CP data charging burden policy and then transmit the dedicated network access information of the CP after receiving the request for access to the dedicated network from the terminal 300. Alternatively, the data policy control apparatus 200 transmits the dedicated network access information of the CP to the terminal 300 after registering the installation of the third party billing application, and when the private network access request is received from the terminal 300, the CP data charging burden policy is confirmed. After that, the CP can be granted access to the private network.
지금까지 단말(300)이 데이터 정책 제어 장치(200)와 연동하여 어플리케이션 단위로 전용망으로 라우팅하고, 이를 기반으로 전용망에서 발생한 트래픽에 대한 과금을 제3자가 부담하는 서비스에 대해 설명하였다. 다음에서 어플리케이션별 전용망 할당 방법을 이용한 다양한 통신 서비스에 대해 더 설명한다.So far, the terminal 300 has linked to the data policy control apparatus 200 to route to a dedicated network on an application basis, and based on this, a service in which a third party bears a charge for traffic generated in the dedicated network has been described. Next, various communication services using the dedicated network allocation method for each application will be further described.
도 13은 한 실시예에 따른 CP 중심 전용망 서비스 제공 방법을 설명하는 도면이다.13 is a diagram illustrating a method for providing a CP center dedicated network service according to an embodiment.
도 13을 참고하면, CP는 통신사로부터 다수의 어플리케이션들이 사용할 수 있는 데이터를 대량 구매한다. 데이터 정책 제어 장치(200)는 CP가 지정한 복수의 어플리케이션들을 위한 전용망 할당 및 망 구성을 하고, 전용망 접속 정보를 단말에 제공할 수 있다. 이때, 단말은 CP별로 어플리케이션 컨테이너를 생성할 수 있다. 사용자는 특정 CP가 지정한 어플리케이션들을 포함하는 CP 어플리케이션 컨테이너를 다운로드하거나, CP 어플리케이션 컨테이너에 지정된 어플리케이션들을 추가할 수 있다.Referring to FIG. 13, the CP purchases a large amount of data that can be used by a plurality of applications from a carrier. The data policy control apparatus 200 may configure a dedicated network for a plurality of applications designated by the CP and configure a network, and provide dedicated network access information to the terminal. In this case, the terminal may generate an application container for each CP. The user may download a CP application container including applications designated by a specific CP or add applications designated to the CP application container.
한편, CP는 통신사로부터 다수의 어플리케이션들이 사용할 수 있는 데이터를 대량 구매하고, 고객의 데이터 과금을 부담하는 상품을 판매할 수 있다. 이를 B2B2C 서비스라고 부를 수 있다. 즉, CP는 어플리케이션이나 어플리케이션 내 구매를 통해 콘텐츠를 판매할 수 있고, 또한, 어플리케이션을 위한 통신망(전용망) 상품도 판매할 수 있다. On the other hand, the CP may purchase a large amount of data that can be used by a plurality of applications from the telecommunications company, and sell a product that bears the data charge of the customer. This can be called a B2B2C service. That is, the CP may sell content through an application or an in-app purchase, and may also sell a communication network (dedicated network) product for the application.
예를 들어, CP는 통신사 전용망 상품에 가입하여 통신사로부터 다수의 어플리케이션들이 사용할 수 있는 데이터를 대량 구매한다. 그리고, CP는 복수의 어플리케이션들을 수용할 수 있는 적어도 하나의 CP 상품(요율, QoS 레벨 등을 포함)을 설계하고, 이를 고객에게 제공할 수 있다. 즉, 개인 사용자가 통신사의 전용망 상품에 가입하는 대신, CP가 통신사의 전용망 상품에 가입하고, CP의 어플리케이션들에 전용망 서비스를 제공할 수 있다. For example, the CP subscribes to a carrier-only network product and purchases a large amount of data from a carrier for use by many applications. The CP may design at least one CP product (including a rate, a QoS level, etc.) that can accommodate a plurality of applications, and provide the same to a customer. That is, instead of the individual user subscribing to the telecommunication company's dedicated network product, the CP may subscribe to the telecommunication company's dedicated network product and provide the private network service to the applications of the CP.
데이터 정책 제어 장치(200)는 CP들의 다양한 데이터 과금 부담 정책에 따라, 인증된 단말들이 전용망에 접속하도록 제어하고, 각 CP의 구매 데이터 한도에서 해당 CP가 지정한 어플리케이션들의 트래픽을 전용망에서 송수신하도록 제어한다.The data policy control apparatus 200 controls the authenticated terminals to access the private network according to various data charging burden policies of the CPs, and controls to transmit and receive traffic of applications designated by the corresponding CP in the private network in the purchase data limit of each CP. .
CP가 통신사와 계약한 데이터량 및 QoS을 상품으로 설계하여 고객에게 제공하는 방법은 마케팅 등 다양한 목적에 따라 설계될 수 있다. 예를 들어, CP는 고객에게 유료로 CP 상품을 판매할 수 있다. 또한, CP는 고객에게 CP 상품을 무료 제공하거나, 고객이 어플리케이션을 이용하면서 발행한 데이터 사용량에 대한 과금을 부담할 수 있다. The method of designing the amount of data and quality of service (QoS) contracted with a carrier and providing it to customers can be designed for various purposes such as marketing. For example, CP may sell CP goods to customers for a fee. In addition, the CP may provide a CP product to the customer free of charge, or may be charged for data usage issued by the customer using the application.
예를 들어, CP 전용망 상품은 전용망을 이용할 수 있는 데이터량 및/또는 QoS 레벨을 포함할 수 있다. 사용자는 CP 전용망 상품에 가입하여, 지정된 어플리케이션 이용 시 전용망을 무료로 이용(CP가 데이터 사용량에 대해 과금 부담)하거나, QoS 보장된 전용망을 이용(데이터 사용량에 대한 과금은 개인이 부담하거나 CP가 부담)할 수 있다. 표 3과 같이, CP 전용망 상품은 CP에 의해 다양하게 설계될 수 있다.For example, CP dedicated network products may include the amount of data and / or QoS levels available for the dedicated network. The user subscribes to a CP-only network product and uses the dedicated network free of charge when using a specified application (CP pays for data usage), or uses a QoS-guaranteed dedicated network (charge for data usage is paid by an individual or CP. )can do. As shown in Table 3, CP-only network products can be variously designed by the CP.
CP명CP name 어플리케이션application 데이터량/QoSData amount / QoS 시간time 요금제Plan
CP1CP1 CP1 지정 어플리케이션CP1 Designated Application 5GB, QoS 레벨5 GB, QoS level 데이터 소진 시까지Until data is exhausted oooo원/월oooowon / month
3GB, QoS 레벨3 GB, QoS level oooo원/월oooowon / month
1GB, QoS 레벨1 GB, QoS level oooo원/월oooowon / month
CP2CP2 CP2 지정 어플리케이션CP2 Designated Application QoS 레벨QoS level 이벤트 시Event 무료free
결과적으로 사용자는 CP 어플리케이션 컨테이너에 지정된 어플리케이션을 이용하는 경우, 통신망 비용을 CP에 직접 지불하는 것이고, CP가 통신사와 약정한 QoS를 보장받을 수 있다.도 14는 한 실시예에 따른 사용자 선택형 전용망 서비스 제공 방법을 설명하는 도면이다.As a result, when the user uses an application designated in the CP application container, the user pays the network cost directly to the CP, and the CP can be guaranteed the QoS contracted with the carrier. FIG. 14 is a view illustrating a user-selectable dedicated network service according to an embodiment. It is a figure explaining a method.
도 14를 참고하면, 지금까지의 사용자는 단일 요금제를 가입하고, 요금제에서 약정한 데이터 한도 내에서 통신망을 이용한다. 본 발명에 따르면, 사용자는 공용망에 접속하는 공용망 요금제 이외에, 전용망에 접속하는 전용망 요금제를 가입할 수 있다. 사용자는 전용망을 사용할 수 있는 데이터량을 선택할 수 있다. 데이터 정책 제어 장치(200)는 도 14의 (a)와 같이 데이터량을 손쉽게 선택할 수 있는 사용자 인터페이스를 단말에 제공할 수 있다. Referring to FIG. 14, so far, a user subscribes to a single plan and uses a communication network within a data limit contracted by the plan. According to the present invention, a user can subscribe to a private network plan for accessing a private network, in addition to the public network plan for accessing a public network. The user can select the amount of data available on the private network. The data policy control apparatus 200 may provide a user interface for easily selecting a data amount as illustrated in FIG. 14A.
도 14의 (b)를 참고하면, 단말은 디스플레이 화면에 어플리케이션 컨테이너(예를 들면, GiGA cube)를 제공하고, 사용자는 어플리케이션 컨테이너에 전용망을 통한 트래픽 송수신을 희망하는 어플리케이션을 담는다. 그러면, 단말은 앞서 설명한 바와 같이, 어플리케이션 컨테이너에 담긴 어플리케이션들이 전용망에 접속할 수 있도록 라우팅 정보를 설정한다. 이를 위해 단말은 데이터 정책 제어 장치(200)로부터 전용망 접속 정보(예를 들면, 전용망 APN)를 획득하여 네트워크 인터페이스를 설정해 둔다. 어플리케이션 컨테이너 외부에 위치하는 어플리케이션들은 공용망에 접속한다.Referring to (b) of FIG. 14, the terminal provides an application container (eg, a GiGA cube) on a display screen, and a user includes an application in which the application container desires to transmit and receive traffic through a dedicated network. Then, as described above, the terminal sets the routing information so that applications contained in the application container can access the private network. To this end, the terminal obtains dedicated network access information (for example, dedicated network APN) from the data policy control apparatus 200 and sets a network interface. Applications located outside the application container connect to the public network.
예를 들면, 사용자는 QoS가 요구되는 어플리케이션을 위해 전용망 요금제에 가입하고, 해당 어플리케이션을 어플리케이션 컨테이너에 담아서 해당 콘텐츠를 이용할 수 있다. 만약 약정한 전용망 데이터량을 소진한 경우, 사용자는 도 14의 (a)와 같은 사용자 인터페이스에서 데이터량을 늘릴 수 있다. 또한, 데이터 정책 제어 장치(200)는 전용망 사용량을 모니터링하고, 약정한 전용망 데이터량을 소진한 경우, 단말의 라우팅 인증부(310)로 어플리케이션 컨테이너에 담긴 어플리케이션들의 인증을 해제하여 전용망 접속을 제어할 수 있다. 이 경우, 어플리케이션 컨테이너에 담긴 어플리케이션들이 어플리케이션 컨테이너 밖으로 이동하고, 공용망으로 접속하도록 라우팅 정보가 변경된다.For example, a user may subscribe to a dedicated network plan for an application requiring QoS and put the application in an application container to use the content. If the dedicated private network data amount is exhausted, the user can increase the data amount in the user interface as shown in FIG. In addition, the data policy control apparatus 200 monitors the dedicated network usage and, when the contracted dedicated network data amount is exhausted, releases the authentication of the applications contained in the application container by the routing authentication unit 310 of the terminal to control the access to the dedicated network. Can be. In this case, routing information is changed so that applications contained in the application container move out of the application container and access to the public network.
이상에서 설명한 본 발명의 실시예는 장치 및 방법을 통해서만 구현이 되는 것은 아니며, 본 발명의 실시예의 구성에 대응하는 기능을 실현하는 프로그램 또는 그 프로그램이 기록된 기록 매체를 통해 구현될 수도 있다.The embodiments of the present invention described above are not only implemented through the apparatus and the method, but may be implemented through a program for realizing a function corresponding to the configuration of the embodiments of the present invention or a recording medium on which the program is recorded.
이상에서 본 발명의 실시예에 대하여 상세하게 설명하였지만 본 발명의 권리범위는 이에 한정되는 것은 아니고 다음의 청구범위에서 정의하고 있는 본 발명의 기본 개념을 이용한 당업자의 여러 변형 및 개량 형태 또한 본 발명의 권리범위에 속하는 것이다.Although the embodiments of the present invention have been described in detail above, the scope of the present invention is not limited thereto, and various modifications and improvements of those skilled in the art using the basic concepts of the present invention defined in the following claims are also provided. It belongs to the scope of rights.

Claims (20)

  1. 데이터 정책 제어 장치가 코어망 및 단말과 연동하여 제3자 과금 서비스를 제공하는 방법으로서,A method of providing a third party billing service by a data policy controlling device interworking with a core network and a terminal,
    특정 어플리케이션에 대한 제3자의 데이터 과금 부담 정책, 그리고 상기 특정 어플리케이션의 트래픽 송수신을 위해 상기 코어망에 할당된 전용망 정보를 관리하는 단계, Managing a third party data charge burden policy for a specific application, and dedicated network information allocated to the core network for transmitting and receiving traffic of the specific application;
    상기 데이터 과금 부담 정책을 기초로, 단말들에 설치된 상기 특정 어플리케이션의 전용망 접속을 제어하는 단계, 그리고Controlling access to a dedicated network of the specific application installed in terminals based on the data charge burden policy; and
    상기 전용망에서 상기 특정 어플리케이션의 트래픽 송수신에 사용된 데이터량을 상기 제3자에게 과금하는 단계를 포함하고,Charging the third party with the amount of data used to transmit and receive traffic of the specific application in the dedicated network;
    상기 특정 어플리케이션을 설치한 각 단말은 상기 데이터 정책 제어 장치의 제어에 따라 상기 특정 어플리케이션의 트래픽을 상기 전용망으로 전송하거나 공용망으로 전송하는, 제3자 과금 서비스 제공 방법.Each terminal installed with the specific application transmits the traffic of the specific application to the dedicated network or to the public network under the control of the data policy control device.
  2. 제1항에서,In claim 1,
    상기 특정 어플리케이션의 전용망 접속을 제어하는 단계는Controlling access to the dedicated network of the specific application
    상기 데이터 과금 부담 정책이 유효한 경우, 상기 특정 어플리케이션의 트래픽이 상기 전용망으로 전송되도록 전용망 접속을 허가하고,If the data charge burden policy is valid, permit access to a private network so that traffic of the specific application is transmitted to the private network,
    전용망 접속이 허가된 단말은 전용망 접속 정보를 이용하여 상기 특정 어플리케이션의 트래픽을 상기 전용망으로 전송하는 제1 라우팅 정책을 설정하는, 제3자 과금 서비스 제공 방법.The terminal authorized to access the dedicated network sets a first routing policy for transmitting traffic of the specific application to the dedicated network using the dedicated network access information.
  3. 제2항에서,In claim 2,
    상기 전용망 접속 정보는The dedicated network connection information is
    상기 코어망에 할당된 전용망의 접속점 이름(Access Point Name, APN)인, 제3자 과금 서비스 제공 방법.And an access point name (APN) of the dedicated network assigned to the core network.
  4. 제1항에서,In claim 1,
    상기 데이터 과금 부담 정책은 상기 제3자의 구매 데이터량을 포함하고, The data charge burden policy includes the amount of purchase data of the third party,
    상기 특정 어플리케이션의 전용망 접속을 제어하는 단계는Controlling access to the dedicated network of the specific application
    상기 제3자에게 과금된 데이터량이 상기 제3자의 구매 데이터량에 도달한 경우, 상기 특정 어플리케이션에 대해 전용망 접속을 허가받은 단말들로, 전용망 접속에 대한 인증 해제를 지시하며,When the amount of data charged to the third party reaches the purchase data amount of the third party, the terminal is authorized to access the dedicated network for the specific application, and instructs to release authentication for the dedicated network connection.
    인증 해제된 각 단말은 상기 특정 어플리케이션의 트래픽을 공용망으로 전송하는 제2 라우팅 정책으로 변경하는, 제3자 과금 서비스 제공 방법.Each deauthenticated terminal changes to a second routing policy for transmitting traffic of the specific application to a public network.
  5. 제1항에서,In claim 1,
    상기 특정 어플리케이션의 전용망 접속을 제어하는 단계는Controlling access to the dedicated network of the specific application
    상기 특정 어플리케이션에 할당된 전용망 접속 정보를 상기 단말들로 전송하는 단계,Transmitting dedicated network access information allocated to the specific application to the terminals;
    상기 단말들 중 임의 단말로부터 상기 특정 어플리케이션의 전용망 접속을 위한 인증 요청을 수신하는 단계, 그리고Receiving an authentication request for access to a dedicated network of the specific application from any one of the terminals, and
    상기 제3자가 설정한 어플리케이션 인증 정책을 기초로 상기 특정 어플리케이션에 대한 전용망 접속을 인증하고, 상기 임의 단말로 전용망 접속을 허가하는 단계를 포함하며,Authenticating a dedicated network connection to the specific application based on the application authentication policy set by the third party, and allowing the dedicated terminal to access the private network;
    상기 임의 단말에서 실행된 상기 특정 어플리케이션의 트래픽은 상기 전용망 접속 정보에 해당하는 전용망으로 전송되는, 제3자 과금 서비스 제공 방법.Traffic of the specific application executed in the arbitrary terminal is transmitted to the private network corresponding to the dedicated network access information, the third party billing service providing method.
  6. 제5항에서,In claim 5,
    상기 어플리케이션 인증 정책은The application authentication policy is
    상기 특정 어플리케이션의 식별자 그리고 무결성 정보를 포함하는, 제3자 과금 서비스 제공 방법.And an identifier and integrity information of the specific application.
  7. 제1항에서,In claim 1,
    상기 특정 어플리케이션은 기업 사내망으로 연결되는 기업 전용 어플리케이션이거나 인터넷망을 통해 콘텐츠 서버에 연결되는 어플리케이션인, 제3자 과금 서비스 제공 방법.The specific application is a method for providing a third party billing service, which is an enterprise-only application connected to a corporate internal network or an application connected to a content server through an internet network.
  8. 제1항에서,In claim 1,
    상기 전용망에서의 트래픽 송수신에 따라 변동되는 상기 제3자의 구매 데이터량의 잔여량을 모니터링하고, 상기 제3자에게 잔여량을 통보하는 단계, 그리고Monitoring the remaining amount of the purchase data amount of the third party that varies with the transmission and reception of traffic in the dedicated network, and notifying the remaining amount to the third party; and
    상기 제3자로부터 데이터 추가를 요청받으면, 상기 데이터 과금 부담 정책을 갱신하는 단계Updating the data charge burden policy when requested to add data from the third party;
    를 더 포함하는 제3자 과금 서비스 제공 방법.The third party billing service providing method further comprising.
  9. 제1항에서,In claim 1,
    상기 제3자에게 과금하는 단계는Charging to the third party
    복수의 제3자들에게 과금할 트래픽이 상기 전용망에서 함께 송수신되는 경우, 상기 전용망에서 송수신되는 트래픽을 어플리케이션별로 구분하여 각 어플리케이션에 대응하는 제3자에게 과금하는, 제3자 과금 서비스 제공 방법.When traffic to be charged to a plurality of third parties is transmitted and received together in the dedicated network, the traffic transmitted and received in the dedicated network is billed to a third party corresponding to each application by classifying each application, the third party billing service providing method.
  10. 단말이 어플리케이션의 트래픽을 지정된 망으로 라우팅하는 방법으로서,A method for a terminal to route traffic of an application to a designated network,
    데이터 정책 제어 장치로 특정 어플리케이션의 전용망 접속을 위한 인증을 요청하는 단계,Requesting authentication for access to a private network of a specific application to a data policy control device;
    상기 데이터 정책 제어 장치로부터 상기 특정 어플리케이션의 전용망 접속을 허가하는 인증 결과를 수신하는 단계, 그리고Receiving an authentication result from the data policy control device to permit access to the private network of the specific application; and
    상기 특정 어플리케이션의 트래픽을 상기 특정 어플리케이션에 할당된 전용망으로 전송하는 라우팅 정책을 설정하는 단계를 포함하고,Setting a routing policy for transmitting traffic of the specific application to a dedicated network assigned to the specific application;
    상기 특정 어플리케이션의 트래픽은 전용망 접속을 위한 인증이 유효한 동안 전용망 접속 정보를 기초로 코어망에 생성된 상기 전용망으로 전달되는, 라우팅 방법.Traffic of the specific application is delivered to the dedicated network generated in the core network based on the dedicated network access information while authentication for the dedicated network connection is valid.
  11. 제10항에서,In claim 10,
    상기 전용망 접속을 위한 인증을 요청하는 단계는The requesting authentication for accessing the private network may include
    사용자 인터페이스 화면에 표시된 상기 특정 어플리케이션을 특정 영역 안으로 움직이는 사용자 동작이 입력되면, 상기 데이터 정책 제어 장치로 상기 특정 어플리케이션의 전용망 접속을 위한 인증을 요청하고,When a user action of moving the specific application displayed on a user interface screen into a specific area is inputted, the data policy control device requests authentication for access to the private network of the specific application.
    상기 데이터 정책 제어 장치로부터 전용망 접속이 허가되면, 상기 특정 어플리케이션은 상기 특정 영역 안에 위치하고, 상기 데이터 정책 제어 장치로부터 전용망 접속이 허가되지 않으면, 상기 특정 어플리케이션은 상기 특정 영역 밖에 위치하는, 라우팅 방법.If the private network access is granted from the data policy controlling device, the specific application is located in the specific area; and if the private network access is not permitted from the data policy controlling device, the specific application is located outside the specific area.
  12. 제11항에서,In claim 11,
    상기 전용망 접속을 위한 인증을 요청하는 단계는The requesting authentication for accessing the private network may include
    상기 특정 영역 안에 위치한 상기 특정 어플리케이션에 대한 실행 요청이 입력되면, 상기 데이터 정책 제어 장치로 상기 특정 어플리케이션의 전용망 접속을 위한 인증을 요청하고, 상기 데이터 정책 제어 장치로부터 전용망 접속이 허가되지 않으면, 상기 특정 어플리케이션을 상기 특정 영역 밖으로 이동하는, 라우팅 방법.When the execution request for the specific application located in the specific area is input, request the authentication for the dedicated network access of the specific application to the data policy control device, and if the private network access is not permitted from the data policy control device, A routing method for moving an application out of the specific area.
  13. 제10항에서,In claim 10,
    상기 데이터 정책 제어 장치로부터 상기 특정 어플리케이션에 대한 전용망 접속에 대한 인증 해제를 수신하는 단계, 그리고Receiving an authentication release from the data policy control device for a dedicated network connection to the specific application; and
    상기 특정 어플리케이션의 트래픽을 공용망 으로 전송하는 라우팅 정책으로 변경하는 단계Changing to a routing policy for transmitting traffic of the specific application to a public network
    를 더 포함하는 라우팅 방법.Routing method further comprising.
  14. 제10항에서,In claim 10,
    상기 라우팅 정책을 설정하는 단계는Setting the routing policy
    가상 네트워크 인터페이스가 할당된 라우팅 컨테이너에 전용망 접속 허가된 상기 특정 어플리케이션을 매핑하여 상기 특정 어플리케이션의 라우팅 정책을 설정하며,A routing policy of the specific application is set by mapping the specific application that is allowed to access the dedicated network to a routing container to which a virtual network interface is assigned.
    상기 가상 네트워크 인터페이스는 상기 전용망으로 접속하는 제1 네트워크 인터페이스에 연결되고,The virtual network interface is connected to the first network interface to connect to the private network,
    상기 라우팅 컨테이터에 매핑되지 않은 어플리케이션들은 공용망에 접속하는 제2 네트워크 인터페이스에 연결되는 라우팅 정책이 설정되는, 라우팅 방법.Applications that are not mapped to the routing container have a routing policy set to a second network interface that connects to a public network.
  15. 제10항에서,In claim 10,
    상기 특정 어플리케이션이 제3자가 데이터 과금 부담하는 제3자 과금 어플리케이션인 경우, 상기 특정 어플리케이션은 전용망 접속을 위한 인증이 유효한 동안 사용자 인터페이스 화면에서 상기 제3자 과금 어플리케이션임을 표시하는, 라우팅 방법.And when the specific application is a third party charging application in which a third party charges data, the specific application indicates that the third party charging application is displayed on a user interface screen while authentication for a dedicated network connection is valid.
  16. 제10항에서,In claim 10,
    상기 라우팅 정책을 설정하는 단계는Setting the routing policy
    공용망 접속을 위한 제1 망 접속 정보 그리고 적어도 하나의 전용망 접속을 위한 적어도 하나의 제2 망 접속 정보를 관리하고, 상기 특정 어플리케이션의 전용망 접속이 허가되면, 허가된 전용망에 해당하는 제2 망 접속 정보를 상기 특정 어플리케이션에 매핑하고, 상기 특정 어플리케이션의 전용망 접속이 허가되지 않으면, 상기 제1 망 접속 정보를 상기 특정 어플리케이션에 매핑하는, 라우팅 방법.Managing first network access information for public network access and at least one second network access information for at least one private network access, and if the private network access of the specific application is permitted, a second network connection corresponding to the authorized private network; Mapping information to the specific application, and mapping the first network connection information to the specific application if the private network connection of the specific application is not permitted.
  17. 제10항에서,In claim 10,
    상기 특정 어플리케이션은 기업 전용 어플리케이션 또는 제3자가 데이터 과금 부담하는 제3자 과금 어플리케이션인, 라우팅 방법.The specific application is an enterprise-specific application or a third party billing application that the third party charges data charge.
  18. 단말이 제3자 과금 어플리케이션을 설치하는 방법으로서,As a method for the terminal to install a third party billing application,
    어플리케이션 마켓에서 제3자 과금 어플리케이션과 과금 부담 통신망 정보를 포함하는 설치 정보를 다운로드하여 설치하는 단계,Downloading and installing installation information including third party billing applications and billing network information from the application marketplace;
    상기 과금 부담 통신망 정보에서 지시하는 데이터 정책 제어 장치에 접속하여 상기 제3자 과금 어플리케이션 설치를 통보하는 단계, 그리고Notifying the installation of the third party billing application by accessing a data policy control device indicated by the billing network information; and
    상기 데이터 정책 제어 장치로부터 수신한 전용망 접속 정보를 상기 제3자 과금 어플리케이션에 매핑하는 라우팅 정책을 설정하는 단계를 포함하고,Setting a routing policy for mapping the private network access information received from the data policy control device to the third party billing application;
    상기 제3자 과금 어플리케이션의 트래픽은 전용망 접속을 위한 인증이 유효한 동안 상기 전용망 접속 정보에 대응된 전용망으로 전달되는, 제3자 과금 어플리케이션 설치 방법.And the traffic of the third party billing application is delivered to the private network corresponding to the dedicated network access information while the authentication for the private network access is valid.
  19. 제18항에서,The method of claim 18,
    상기 라우팅 정책을 설정하는 단계는Setting the routing policy
    상기 데이터 정책 제어 장치로 상기 제3자 과금 어플리케이션의 전용망 접속을 위한 인증을 요청하고, 상기 데이터 정책 제어 장치로부터 전용망 접속 허가를 포함하는 인증 결과를 수신하면, 상기 라우팅 정책을 설정하는, 제3자 과금 어플리케이션 설치 방법.A third party that requests the data policy controlling device for authentication for access to the private network of the third party billing application, and sets the routing policy upon receiving an authentication result including a dedicated network access permission from the data policy controlling device; How to install the billing application.
  20. 제18항에서,The method of claim 18,
    상기 데이터 정책 제어 장치로부터 상기 제3자 과금 어플리케이션에 대한 전용망 접속에 대한 인증 해제를 수신하는 단계, 그리고Receiving, from the data policy control device, an authorization release for a dedicated network connection to the third party billing application; and
    상기 제3자 과금 어플리케이션에 매핑된 전용망 접속 정보를 공용망 접속 정보로 변경하는 라우팅 정책을 설정하는 단계Setting a routing policy for changing the private network access information mapped to the third party billing application to the public network access information;
    를 더 포함하는 제3자 과금 어플리케이션 설치 방법.Third party billing application installation method further comprising a.
PCT/KR2019/003669 2018-01-08 2019-03-28 Allocation method for application dedicated network, method for providing third-party billing service through same, and communication network system and user terminal implementing same WO2019208943A1 (en)

Applications Claiming Priority (5)

Application Number Priority Date Filing Date Title
KR20180002456 2018-01-08
KR1020180049387A KR102147832B1 (en) 2018-01-08 2018-04-27 Method for allocating dedicated network of application, method for providing third parties billing service, and telecommunicatin system and user terminal implementing the methods
KR10-2018-0049387 2018-04-27
KR10-2018-0067740 2018-06-12
KR1020180067740A KR102162870B1 (en) 2018-01-08 2018-06-12 Method for allocating dedicated network of application, method for providing user selectabe dedicated network service, and telecommunication system and user terminal implementing the methods

Publications (1)

Publication Number Publication Date
WO2019208943A1 true WO2019208943A1 (en) 2019-10-31

Family

ID=67512962

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2019/003669 WO2019208943A1 (en) 2018-01-08 2019-03-28 Allocation method for application dedicated network, method for providing third-party billing service through same, and communication network system and user terminal implementing same

Country Status (2)

Country Link
KR (2) KR102147832B1 (en)
WO (1) WO2019208943A1 (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102465325B1 (en) * 2019-10-22 2022-11-10 주식회사 케이티 Terminal based dynamic network policy control method on 5g network, terminal and network system implementing the same method
KR102392809B1 (en) * 2019-11-29 2022-04-29 주식회사 케이티 Method and system for zero-rating service
KR102424075B1 (en) * 2021-12-02 2022-07-25 (주)소만사 System and method for forwarding traffic in container environment

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090003368A1 (en) * 2007-06-27 2009-01-01 Novell, Inc. System and method for graphically representing and managing computer network connections
US20130132854A1 (en) * 2009-01-28 2013-05-23 Headwater Partners I Llc Service Plan Design, User Interfaces, Application Programming Interfaces, and Device Management
US20140120867A1 (en) * 2010-12-16 2014-05-01 Syniverse Technologies, Inc. Providing toll free data in a wireless system
US20140372293A1 (en) * 2013-06-12 2014-12-18 Kent K. Leung Client App Service on Mobile Network
WO2016190672A1 (en) * 2015-05-26 2016-12-01 엘지전자 주식회사 Method and terminal for performing attach procedure for sponsored connectivity in wireless communication system
US9736699B1 (en) * 2015-07-28 2017-08-15 Sanjay K. Rao Wireless Communication Streams for Devices, Vehicles and Drones

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090003368A1 (en) * 2007-06-27 2009-01-01 Novell, Inc. System and method for graphically representing and managing computer network connections
US20130132854A1 (en) * 2009-01-28 2013-05-23 Headwater Partners I Llc Service Plan Design, User Interfaces, Application Programming Interfaces, and Device Management
US20140120867A1 (en) * 2010-12-16 2014-05-01 Syniverse Technologies, Inc. Providing toll free data in a wireless system
US20140372293A1 (en) * 2013-06-12 2014-12-18 Kent K. Leung Client App Service on Mobile Network
WO2016190672A1 (en) * 2015-05-26 2016-12-01 엘지전자 주식회사 Method and terminal for performing attach procedure for sponsored connectivity in wireless communication system
US9736699B1 (en) * 2015-07-28 2017-08-15 Sanjay K. Rao Wireless Communication Streams for Devices, Vehicles and Drones

Also Published As

Publication number Publication date
KR102147832B1 (en) 2020-10-14
KR20190084843A (en) 2019-07-17
KR102162870B1 (en) 2020-10-07
KR20190084845A (en) 2019-07-17

Similar Documents

Publication Publication Date Title
WO2019208943A1 (en) Allocation method for application dedicated network, method for providing third-party billing service through same, and communication network system and user terminal implementing same
WO2016076628A2 (en) Method and device for providing data service through mobile communication network
US10673618B2 (en) Provisioning network resources in a wireless network using a native blockchain platform
WO2017176013A1 (en) Method for processing access request from ue, and network node
WO2020197288A1 (en) Method and device for providing connectivity to terminal in order to use edge computing service
WO2018174373A1 (en) Session management method and smf node
WO2016208960A1 (en) Method and apparatus for subscribing electronic device in mobile communication system
KR101439534B1 (en) Web Redirect Authentication Method and Apparatus of WiFi Roaming Based on AC-AP Association
WO2018038490A1 (en) Method and system for regional data network configuration in wireless communication network
US9084175B2 (en) Access control according to a policy defined for a group of associated electronic devices comprising a cellular modem
WO2012102590A2 (en) Method and apparatus for providing qos-based service in wireless communication system
WO2014129802A1 (en) Method for modifying m2m service setting and apparatus therefor
WO2021091307A1 (en) Apparatus and method for establishing mbs service session for mbs service provision in wireless communication system
WO2011085543A1 (en) Charging method, device and system
WO2013085314A1 (en) Method and system for providing sponsored service on ims-based mobile communication network
WO2019031912A1 (en) Manual roaming and data usage rights
WO2016068548A1 (en) Method for processing notification message in wireless communication system and apparatus therefor
JP2004186749A (en) Wireless lan communication method and system
WO2015199340A1 (en) Network device and terminal for multi-path communication, operation method thereof, and program implementing operation method
WO2021054781A1 (en) Method and device for management and access control of network slice in wireless communication system
US20030100302A1 (en) User controlled home location register
WO2019199053A1 (en) Data sharing device and method, advertisement service providing method using same, and device therefor
WO2017082506A1 (en) Method for processing notification reception stop request in wireless communication system and device therefor
WO2017014381A1 (en) Method for maintaining synchronization of resources in wireless communication system, and apparatus therefor
WO2020166927A1 (en) Method and device for subscribing and notifying

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19792881

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19792881

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 19792881

Country of ref document: EP

Kind code of ref document: A1