WO2020093790A1 - 一种隧道协商建立方法及装置 - Google Patents

一种隧道协商建立方法及装置 Download PDF

Info

Publication number
WO2020093790A1
WO2020093790A1 PCT/CN2019/106122 CN2019106122W WO2020093790A1 WO 2020093790 A1 WO2020093790 A1 WO 2020093790A1 CN 2019106122 W CN2019106122 W CN 2019106122W WO 2020093790 A1 WO2020093790 A1 WO 2020093790A1
Authority
WO
WIPO (PCT)
Prior art keywords
control plane
user plane
session
lns
establishment
Prior art date
Application number
PCT/CN2019/106122
Other languages
English (en)
French (fr)
Inventor
陈刚
詹徐周
朱进磊
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2020093790A1 publication Critical patent/WO2020093790A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/12Setup of transport tunnels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management

Definitions

  • the present invention relates to the field of communications, and in particular, to a method and device for establishing a tunnel negotiation.
  • L2TP Layer 2 tunneling protocol
  • VPN Virtual Private Network
  • RFC Real-Fi Protected Fidelity
  • control plane of the PGW was responsible for the negotiation process of the L2TP tunnel, and the media plane of the PGW was responsible for the processing of L2TP tunnel user packets.
  • Embodiments of the present invention provide a tunnel negotiation establishment method and device to at least solve the problem that the mixed deployment of C-plane network elements (PGW-C or SMF) and U-plane network elements (PGW-U or UPF) of different manufacturers in related technologies cannot be applied L2TP VPN problem.
  • PGW-C or SMF C-plane network elements
  • PGW-U or UPF U-plane network elements
  • a tunnel negotiation establishment method including:
  • control plane includes: a packet data network gateway control plane PGW-C or a session management function SMF, and the user plane Including packet data network gateway user plane PGW-U or user plane function UPF; or,
  • the negotiation and establishment of the L2TP tunnel between the control plane and the user plane is completed through the user plane.
  • a tunnel negotiation establishment method including:
  • control plane includes: PGW-C or SMF
  • user plane includes PGW-U or UPF
  • a tunnel negotiation establishment device which is applied to the control plane and includes:
  • the first negotiation establishment module is configured to complete the negotiation establishment of the layer 2 tunneling protocol L2TP tunnel between the control plane and the user plane through the control plane, wherein the control plane includes: PGW-C or SMF, and the user plane includes PGW-U or UPF; or,
  • the second negotiation establishment module is configured to complete the negotiation establishment of the L2TP tunnel between the control plane and the user plane through the user plane.
  • a tunnel negotiation establishment device which is applied to the user plane including:
  • the third negotiation establishment module is configured to complete the negotiation establishment of the layer 2 tunneling protocol L2TP tunnel between the control plane and the user plane through the control plane, wherein the control plane includes: PGW-C or SMF, and the user plane includes PGW-U or UPF; or,
  • the fourth negotiation establishment module is configured to complete the negotiation establishment of the L2TP tunnel between the control plane and the user plane.
  • a storage medium in which a computer program is stored, wherein the computer program is configured to execute the steps in any one of the above method embodiments at runtime.
  • an electronic device including a memory and a processor, the memory stores a computer program, the processor is configured to run the computer program to perform any of the above The steps in the method embodiment.
  • the establishment of an L2TP tunnel between the C-plane network element and the U-plane network element can solve the problems of the C-plane network element (PGW-C or SMF) and the U-plane network element (PGW-U Or UPF) the problem that L2TP VPN cannot be applied in hybrid deployment, which achieves the effect that the L2TP deployment of C-plane and U-plane NEs of different manufacturers is not affected, saves the cost of operator interconnection, and improves the competitiveness of equipment vendors. .
  • FIG. 1 is a schematic diagram of a 4G mobile network CUPS architecture according to the related art
  • FIG. 2 is a schematic diagram of a 5G mobile network CUPS architecture according to the related art
  • FIG. 3 is a schematic diagram of establishment of an L2TP tunnel negotiation according to the related art
  • FIG. 4 is a flowchart of establishing an L2TP tunnel according to related art
  • FIG. 5 is a block diagram of a hardware structure of a mobile terminal of a method for establishing a tunnel negotiation according to an embodiment of the present invention
  • FIG. 6 is a flowchart 1 of a tunnel negotiation establishment method according to an embodiment of the present invention.
  • FIG. 7 is a flowchart 2 of a tunnel negotiation establishment method according to an embodiment of the present invention.
  • FIG. 9 is a flowchart 1 of the L2TP VPN establishment process under the 4G CUPS architecture according to an embodiment of the present invention.
  • FIG. 10 is a flowchart 1 of the L2TP VPN establishment process under the 5G CUPS architecture according to an embodiment of the present invention
  • 11 is a flowchart 2 of the L2TP VPN establishment process under the 4G CUPS architecture according to an embodiment of the present invention
  • FIG. 12 is a flowchart 2 of the L2TP VPN establishment process under the 5G CUPS architecture according to an embodiment of the present invention
  • FIG. 13 is a flow chart of the C-plane LAC actively negotiating L2TP tunnel teardown under the CUPS architecture according to an embodiment of the present invention
  • FIG. 14 is a flowchart of a C-plane LAC passively negotiating L2TP tunnel teardown according to the CUPS architecture according to an embodiment of the present invention
  • FIG. 16 is a flowchart of the U-plane LAC passively negotiating L2TP tunnel teardown under the CUPS architecture according to an embodiment of the present invention
  • 17 is a block diagram 1 of an apparatus for establishing a tunnel negotiation according to an embodiment of the present invention.
  • FIG. 18 is a block diagram 2 of an apparatus for establishing a tunnel negotiation according to an embodiment of the present invention.
  • FIG. 19 is a first schematic structural diagram of an optional electronic device according to an embodiment of the present invention.
  • 20 is a second schematic structural diagram of an optional electronic device according to an embodiment of the present invention.
  • FIG. 1 is a schematic diagram of the 4G mobile network CUPS architecture according to the related art.
  • the 4G core network packet data network gateway (Packet Data Network Gateway, referred to as PGW) network element is divided into groups Data network gateway control plane ((PacketDataNetworkGateway-C, referred to as PGW-C) and packet data network gateway user plane (PacketDataDataNetworkGateway-U, referred to as PGW-U), PGW-U is a 4G mobile network and PDN boundary;
  • Figure 2 is a schematic diagram of the 5G mobile network CUPS architecture according to the related art.
  • the 5G core network architecture includes a session management function (Session Management Function, SMF for short) and a network element user plane function (User Plane Function, referred to as UPF), where UPF is the border between 5G mobile network and DN.
  • SMF Session Management Function
  • UPF User Plane Function
  • Figure 3 is a schematic diagram of the negotiation and establishment of an L2TP tunnel according to the related art.
  • the inter-control plane is responsible for negotiation establishment and deletion of the L2TP tunnel, and the user plane is responsible for processing L2TP tunnel packets.
  • FIG. 4 is a flowchart of establishing a negotiated L2TP tunnel in the related art. As shown in FIG. 4, it includes:
  • Step 1 The LAC sends an SCCRQ (Start-Control-Connection-Request) message to the LNS;
  • SCCRQ Start-Control-Connection-Request
  • Step 2 The LAC receives the SCCRP (Start-Control-Connection-Reply) message returned by the LNS;
  • SCCRP Start-Control-Connection-Reply
  • Step 3 The LAC sends an SCCCN (Start-Control-Connection-Connected) message to the LNS;
  • SCCCN Start-Control-Connection-Connected
  • Step 4 the LAC receives the zero-length message (Zero-Length Body, ZLB for short) message returned by the LNS;
  • Step 5 The LAC sends an ICRQ (Incoming-Call-Request) message to the LNS;
  • Step 6 the LAC receives the ICRP (Incoming-Call-Reply) message returned by the LNS;
  • Step 7 The LAC sends an ICCN (Incoming-Call-Connected, Incoming-Call-Connected) message to the LNS;
  • ICCN Incoming-Call-Connected, Incoming-Call-Connected
  • Step 8 The LAC receives the ZLB message returned by the LNS
  • Step 9 The LAC sends a Point-to-Point Protocol (PPP for short) LCP (Link Control Protocol) configuration request to the LNS;
  • PPP Point-to-Point Protocol
  • LCP Link Control Protocol
  • Step 10 The LAC receives the PPP LCP configuration response returned by the LNS;
  • Step 11 the LAC sends a PPP authentication request to the LNS;
  • Step 12 the LAC receives the PPP authentication response returned by the LNS
  • Step 13 the LAC sends a PPP IPCP (IP Control Protocol) configuration request to the LNS;
  • PPP IPCP IP Control Protocol
  • step 14 the LAC receives the IPCP configuration response returned by the LNS.
  • FIG. 5 is a block diagram of a hardware structure of a mobile terminal according to an embodiment of the present invention.
  • the mobile terminal 10 may include one or more (FIG. 5 Only one is shown) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or programmable logic device FPGA) and a memory 104 for storing data, optionally, the mobile terminal may also It includes a transmission device 106 for communication functions and an input and output device 108.
  • a person of ordinary skill in the art may understand that the structure shown in FIG. 5 is merely an illustration, which does not limit the structure of the mobile terminal described above.
  • the mobile terminal 10 may further include more or fewer components than those shown in FIG. 5, or have a different configuration from that shown in FIG.
  • the memory 104 may be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the message receiving method in the embodiment of the present invention, and the processor 102 executes the computer program stored in the memory 104 to execute Various functional applications and data processing, namely to achieve the above method.
  • the memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory.
  • the memory 104 may further include memories remotely provided with respect to the processor 102, and these remote memories may be connected to the mobile terminal 10 through a network. Examples of the above network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.
  • the transmission device 106 is used to receive or send data via a network.
  • the specific example of the network described above may include a wireless network provided by a communication provider of the mobile terminal 10.
  • the transmission device 106 includes a network adapter (Network Interface CoTtroller, referred to as NIC for short), which can be connected to other network devices through the base station to communicate with the Internet.
  • the transmission device 106 may be a radio frequency (Radio FrequeNcy, RF for short) module, which is used to communicate with the Internet in a wireless manner.
  • Radio FrequeNcy Radio FrequeNcy, RF for short
  • FIG. 6 is a flowchart 1 of a tunnel negotiation establishment method according to an embodiment of the present invention. As shown in FIG. 6, the process includes the following steps:
  • Step S602 the negotiation and establishment of the layer 2 tunneling protocol L2TP tunnel between the control plane and the user plane is completed through the control plane.
  • the control plane includes: a packet data network gateway control plane PGW-C or a session management function SMF.
  • the user plane includes the user plane PGW-U of the packet data network gateway or the user plane function UPF; or,
  • Step S604 Complete the negotiation establishment of the L2TP tunnel between the control plane and the user plane through the user plane.
  • completing the negotiation and establishment of the L2TP tunnel between the control plane and the user plane through the control plane includes:
  • the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS is completed through the control plane.
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the control plane includes:
  • the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane is completed through the control plane;
  • control plane and the user plane When both the control plane and the user plane have L2TP tunnel negotiation capabilities, determine to use the control plane's L2TP tunnel negotiation capabilities, and complete the L2TP between the control plane and the user plane through the control plane Negotiation of tunnel negotiation capabilities.
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the control plane includes:
  • association establishment request message Sending an association establishment request message to the user plane, where the association establishment request message carries the L2TP tunnel negotiation capability of the control plane;
  • association establishment response message fed back by the user plane, where the association establishment response message carries the L2TP tunnel negotiation capability of the user plane.
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • completing the establishment of the L2TP tunnel between the user plane and the LNS through the control plane includes:
  • the forward network element includes a service gateway control plane SGW-C or an access and mobility function AMF;
  • PFCP session establishment request message for establishing a forwarding relationship to the user plane, where the PFCP session establishment request message carries the tunnel ID and session ID of the LAC and the LNS;
  • PFCP Packet Forwarding Control Protocol
  • a session establishment response message is returned to the forward network element, where the session establishment response message carries the IP address and DNS (Domain Name Server) address information allocated by the LNS.
  • IP address and DNS (Domain Name Server) address information allocated by the LNS.
  • DNS Domain Name Server
  • completing the L2TP tunnel establishment negotiation with the LNS through the LAC includes:
  • the method further includes:
  • deleting the established L2TP tunnel includes:
  • a forward network element receives a session deletion request message sent by a forward network element, where the forward network element includes a serving gateway control plane (Serving Gateway-C, abbreviated as SGW-C) or an access and mobility function AMF;
  • SGW-C serving gateway control plane
  • AMF access and mobility function AMF
  • Zero-length message (Zero-Length Body, ZLB for short) message returned by the LNS through the Sxb / N4 interface of the user plane;
  • deleting the established L2TP tunnel includes:
  • the forward network element includes the serving gateway control plane SGW-C or the access and mobility function AMF;
  • completing the negotiation and establishment of the L2TP tunnel between the control plane and the user plane through the user plane includes:
  • the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS is completed through the user plane.
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the user plane includes:
  • the user plane When only the user plane has L2TP tunnel negotiation capability, or both the control plane and the user plane have L2TP tunnel negotiation capability, it is determined to use the user plane L2TP tunnel negotiation capability, and the user plane is used Negotiation of L2TP tunnel negotiation capability between the control plane and the user plane.
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the user plane includes:
  • association establishment response message Return a message forwarding control protocol PFCP association establishment response message to the user plane, where the association establishment response message carries the L2TP tunnel negotiation capability of the control plane.
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • completing the establishment of the L2TP tunnel between the user plane and the LNS through the user plane includes:
  • the forward network element includes a service gateway control plane SGW-C or an access and mobility function AMF;
  • PFCP session establishment request message Sending a packet forwarding control protocol PFCP session establishment request message to the user plane, where the PFCP session establishment request message is used to instruct the user plane to complete negotiation of L2TP tunnel establishment with the LNS through the L2TP access concentrator LAC, And save the tunnel ID and session ID of the LAC and the LNS, as well as the IP address and DNS address information assigned by the LNS;
  • PFCP session establishment response message returned by the user plane after the establishment of the forwarding relationship is completed, where the PFCP session establishment response message carries the IP address and DNS address information allocated by the LNS;
  • a session establishment response message is returned to the forward network element, where the session establishment response message carries the IP address and DNS address information allocated by the LNS.
  • the PFCP session establishment request message carries at least one of the following information: Protocol Configuration Option (Protocol Configuration Option, PCO) is referred to as the username in PCO, PAP password in PCO, Challenge Handshake Authentication Protocol in PCO Handshake Authentication (CHAP for short) challenges the Challenge, and the CHAP challenge in the PCO responds to the challenge response.
  • PCO Protocol Configuration Option
  • CHAP challenge in the PCO responds to the challenge response.
  • the method further includes:
  • deleting the established L2TP tunnel includes:
  • PFCP session deletion response message is that the user plane is sending PPP to the LNS according to the PFCP session deletion request message Termination request message, receiving the PPP termination response message returned by the LNS after releasing the PPP session, sending a session unlink notification CDN message to the LNS, and returning after receiving the zero-length message body ZLB response message returned by the LNS;
  • deleting the established L2TP tunnel includes:
  • PFCP session report request message sent by the user plane, where the PFCP session report request message carries the indication information of the L2TP tunnel that has been established by the LNS request to disconnect or disconnect the link, and the PFCP session report request message is the
  • the user plane receives a PPP termination request message for releasing a PPP session from the LNS, returns a termination response message to the LNS after releasing the PPP session, receives a session unlink notification CDN message sent by the LNS, and returns 0 to the LNS Sent after the length message body ZLB message;
  • FIG. 7 is a flowchart 2 of a tunnel negotiation establishment method according to an embodiment of the present invention. As shown in FIG. 7, it includes:
  • Step S702 Complete the negotiation and establishment of the second layer tunneling protocol L2TP tunnel between the control plane and the user plane through the control plane, where the control plane includes: PGW-C or SMF, and the user plane includes PGW-U or UPF; or,
  • Step S704 completing the negotiation establishment of the L2TP tunnel between the control plane and the user plane.
  • completing the negotiation and establishment of the L2TP tunnel between the control plane and the user plane through the control plane includes:
  • the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS is completed through the control plane.
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the control plane includes:
  • the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane is completed through the control plane;
  • Both the control plane and the user plane have L2TP tunnel negotiation capabilities, and when the control plane determines the L2TP tunnel negotiation capabilities using the control plane, the control plane and the Negotiation of L2TP tunnel negotiation capabilities between user planes.
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the control plane includes:
  • association establishment response message fed back to the control plane, where the association establishment response message carries the L2TP tunnel negotiation capability of the user plane.
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • completing the establishment of the L2TP tunnel between the user plane and the LNS through the control plane includes:
  • the forward network element includes a service gateway control plane SGW-C or an access and mobility function AMF;
  • PFCP session establishment response message to notify the control plane that the establishment of the forwarding relationship is completed, wherein the PFCP session establishment response message is used to instruct the control to return a session establishment response message to the forward network element, wherein,
  • the session establishment response message carries the IP address and DNS address information allocated by the LNS.
  • the method further includes:
  • the L2TP VPN establishment request message sent by the control plane is forwarded to the LNS through the Sxb / N4 interface;
  • the L2TP VPN establishment response message sent by the LNS is forwarded to the control plane through the Sxb / N4 interface.
  • the method further includes:
  • deleting the established L2TP tunnel through the control plane includes:
  • the PPP termination request message is a session deletion sent by the control plane to the network element before receiving Sent after the message, where the forward network element includes the serving gateway control plane SGW-C or the access and mobility function AMF;
  • deleting the established L2TP tunnel includes:
  • a PFCP session deletion response message is returned to the control plane, where the PFCP session deletion response message is used to instruct the control plane to terminate service processing.
  • completing the negotiation and establishment of the L2TP tunnel between the control plane and the user plane includes:
  • the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS is completed.
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane includes:
  • completing the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane includes:
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • completing the establishment of the L2TP tunnel between the user plane and the LNS includes:
  • PFCP session establishment request message sent by the control plane, where the PFCP session establishment request message is sent by the control plane after receiving a session establishment request message sent by a forward network element, the forward network element Including service gateway control plane SGW-C or access and mobility functions AMF;
  • the L2TP access concentrator LAC and the LNS to complete the L2TP tunnel establishment negotiation, and save the LAC and the LNS tunnel ID, session ID, and the LNS assigned IP address and DNS address information of domain name server;
  • a PFCP session establishment response message is returned to the control plane, where the PFCP session establishment response message carries the IP address and DNS address information allocated by the LNS, and the PFCP session establishment response message is used Instructing the control to return a session establishment response message to the forward network element, where the session establishment response message carries the IP address and DNS address information allocated by the LNS.
  • the PFCP session establishment request message carries at least one of the following information: username in the PCO, PAP password in the PCO, CHAP challenge in the PCO, and CHAP challenge response in the PCO.
  • the method further includes:
  • deleting the established L2TP tunnel through the control plane includes:
  • PFCP session deletion request message sent by the control plane, where the PFCP session deletion request message is sent by the control plane after receiving a session deletion request message sent by a forward network element, the forward network element Including service gateway control plane SGW-C or access and mobility functions AMF;
  • a PFCP session deletion response message is returned to the control plane, where the PFCP session deletion response message is used to instruct the control plane to terminate service processing and return the session to the forward network element Delete the response message.
  • deleting the established L2TP tunnel includes:
  • PFCP session report request message Sending a PFCP session report request message to the control plane, where the PFCP session report request message carries the indication information of the L2TP tunnel established by the LNS requesting to disconnect or disconnect the link;
  • the embodiment of the present invention includes two modes: one is a control plane scheme (hereinafter referred to as the CP scheme), that is, L2TP tunnel negotiation is placed on the control plane; and two is a media plane scheme (hereinafter described as the UP scheme), that is, the L2TP tunnel The consultation is on the media.
  • CP scheme control plane scheme
  • UP scheme media plane scheme
  • L2TP tunnel negotiation related parameters are standardized through the Sxb and N4 interfaces, and the C plane (PGW-C / SMF)
  • the interaction with the U-plane (PGW-U / UPF) L2TP tunnel negotiation capability includes the following steps:
  • Step 1 When the association between the C and U planes is established, the respective L2TP tunnel negotiation capabilities are notified. If the C plane actively establishes the association, the association establishment request is carried in the Packet Forwarding Control Protocol (PFCP) Association. PFCP parameter field newly opened label function feature Function indicates the L2TP tunnel negotiation capability;
  • PFCP Packet Forwarding Control Protocol
  • Step 2 The U-plane returns the PFCP association establishment response Association, Setup Response, which carries the UP function features and indicates the L2TP tunnel negotiation capabilities;
  • Step 3 If the U-plane actively establishes the association, then the PFCP Association Settings Request carries UP Function to indicate the L2TP tunnel negotiation capability;
  • Step 4 The C-plane returns PFCP, Association, Setup, and Response to carry CP, Function, and Features to indicate the L2TP tunnel negotiation capability;
  • Step 5 If Plan C chooses the L2TP CP solution, you need to initiate Sx-U / N4-U tunnel establishment immediately.
  • the associated PDR / FAR indicates that the tunnel establishment is used for transparent transmission of L2TP negotiation messages.
  • Step 6 The U plane returns an Sx-U / N4-U tunnel establishment response.
  • FIG. 9 is a flowchart 1 of the L2TP VPN establishment process under the 4G CUPS architecture according to an embodiment of the present invention.
  • FIG. 10 It is a flowchart 1 of the L2TP VPN establishment process under the 5G CUPS architecture according to an embodiment of the present invention, as shown in FIGS. 9 and 10, including:
  • Step 1 Plan C (PGW-C / SMF) receives the session establishment request of the forward network element (SGW-C / AMF), which carries the relevant parameters of the session establishment (such as tunnel negotiation information, protocol configuration options (Protocol Configuration Option, referred to as PCO), etc.);
  • SGW-C / AMF forward network element
  • PCO Protocol Configuration Option
  • Step 2 Plan C instructs the current user according to local configuration (such as LNS address, tunnel name information, authentication method, etc.) or other policy sources (such as AAA-Authentication, Authorization, Accounting authorization LNS address, tunnel name, authentication method, etc.)
  • LNS address such as LNS address, tunnel name information, authentication method, etc.
  • policy sources such as AAA-Authentication, Authorization, Accounting authorization LNS address, tunnel name, authentication method, etc.
  • the L2TP tunnel needs to be established.
  • Plan C selects UPF / PGW-U, and initiates the L2TP tunnel negotiation establishment process to the LNS through the user plane User Sne of the Sxb / N4 interface with the UPF / PGW-U, and the LNS negotiation response message also passes through this Sxb / N4 User Plane. Supporting the L2TP tunnel negotiation process through the Sxb / N4 User Plane is unique to the embodiment of the present invention.
  • Step 3 The LAC on the C side completes the L2TP tunnel negotiation with the LNS.
  • the C side locally saves the Tunnel ID and Session Session ID parameters of the local and LNS peers, and the IP address and DNS parameters assigned by the LNS to the terminal;
  • the LAC function is forwarded by Sxb User Plane in PGW-C, and the negotiation message between LAC and LNS is forwarded; in steps 2 and 3 of Figure 10, the LAC function is between SMF, LAC and LNS Negotiation messages between them are forwarded through N4User Plane.
  • Step 4 Plane C informs Plane U (PGW-U / UPF) to establish a forwarding relationship for the current user, and sends a PFCP Session Establishment Request message, which carries the Tunnel ID and Session ID parameters of the local and peer ends. Carrying the Tunnel ID and Session ID parameters of the local end and the peer end through the PFCP Session Establishment Request is unique to the embodiment of the present invention.
  • Step 5 The U-plane returns PFCP Session Establishment Response to notify the establishment of the forwarding relationship.
  • Step 6 C returns a session establishment response to the forwarding network element, which carries the IP address assigned by the LNS and DNS address information of the domain name server.
  • FIG. 11 is a flowchart 2 of the L2TP VPN establishment process under the 4G CUPS architecture according to an embodiment of the present invention.
  • FIG. 12 It is a flowchart 2 of the L2TP VPN establishment process under the 5G CUPS architecture according to an embodiment of the present invention, as shown in FIGS. 11 and 12, including:
  • Step 1 The C-plane receives a session establishment request of the forwarding network element (SGW-C / AMF), which carries the relevant parameters for session establishment; and completes the relevant processing procedures such as policy and charging.
  • SGW-C / AMF forwarding network element
  • Step 2 Plan C instructs the current user to establish an L2TP tunnel based on local configuration or other policy sources (such as AAA).
  • a PFCP Session Establishment Request message to the U plane, carrying the relevant parameters required for L2TP negotiation, including one or a combination of the following information: Username in the PCO (Protocol ConfigurationOptio), PCO PAP password (carried only in PAP scenarios), CHAP (Challenge Handshake Authentication) Protocol in PCO Challenge (carried only in CHAP scenarios), CHAP challenge in PCO (response only in CHAP scenarios).
  • the PFCP Session Establishment Request message carries the relevant parameters required for L2TP negotiation.
  • Step 3 After receiving the above message, the U-plane combines the local configuration and immediately initiates the L2TP tunnel negotiation process.
  • the basic process is shown in FIG. 4.
  • Step 4 the U-plane completes the negotiation process of the L2TP tunnel, and locally saves the Tunnel ID and Session ID information of the local end and the peer end, and the IP address and DNS (Domain Name Server) information assigned by the LNS to the terminal.
  • the U plane completes the establishment of the current user's UPF / PGW-U uplink and downlink forwarding relationship.
  • steps 3 and 4 of Fig. 11 some of the negotiation parameters of the LAC function between PGW-U, LAC and LNS are transmitted through Sxb Control Plane; in steps 3 and 4 of Fig. 12, the function of LAC is in UPF, LAC and LNS Some of the negotiation parameters between are passed through N4Control Plane.
  • Step 5 The U-plane returns PFCP Session Establishment Response to notify the completion of the establishment of the forwarding relationship, and the message carries the terminal IP address and DNS information allocated by the LNS.
  • the PFCP Session Establishment Response carries the IP address and DNS information assigned by the LNS and is unique to the embodiment of the present invention.
  • Step 6 after receiving the above message, the C plane notifies the forward network element session establishment response message, and this message carries the terminal IP address and DNS information in the above step.
  • FIG. 13 is a flowchart of the C-plane LAC actively negotiating the L2TP tunnel de-linking under the CUPS architecture according to an embodiment of the present invention.
  • Step 1 Plane C (PGW-C / SMF) receives the session delete message from the forward network element.
  • Step 2 The C plane initiates the L2TP unlinking process. First, it sends a PPP termination request Terminate Request to the LNS through the User Plane of the Sxb or N4 interface.
  • Step 3 The LNS returns PPP Terminate Response and forwards it to the C plane via the User Plane of the Sxb or N4 interface.
  • Step 4 The C-plane continues to send a Call-Disconnect-Notify (CDN for short) message.
  • CDN Call-Disconnect-Notify
  • Step 5 The LNS returns a ZLB response and forwards it to the C plane via the User Plane of the Sxb or N4 interface.
  • Step 6 the C plane sends a PFCP Session Deletion Request message to notify the U plane (PGW-U / UPF) to delete the forwarding relationship of the current session;
  • Step 7 the U plane returns a PFCP session deletion response Session Deletion Response message to the C plane, and the C plane completes business processing such as charging stop and policy termination.
  • Step 8 The C plane returns a session deletion response to the forward network element (SGW-C / AMF).
  • FIG. 14 is a flow chart of the C-plane LAC passive negotiation of L2TP tunnel de-linking under the CUPS architecture according to an embodiment of the present invention.
  • Step 1 Plane C (PGW-C / SMF) receives the PPP Terminate Request delete message from the LNS via the User Plane of the Sxb or N4 interface.
  • Step 2 releases the PPP session and sends PPP Terminate Response to the LNS via the User Plane of the Sxb or N4 interface.
  • Step 3 Plane C receives the CDN message from the LNS via the User Plane of the Sxb or N4 interface.
  • Step 4 The C plane performs the L2TP session release and sends ZLB to the LNS via the User Plane of the Sxb or N4 interface.
  • step 5 C notifies the forward network element (SGW-C / AMF) of session deletion.
  • Step 6 C sends a PFCP Session Deletion Request to the U-plane (PGW-U / UPF) to notify the release of media plane resources.
  • Step 7 the U side returns a PFCP Session Deletion Response message to the C plane, and the C plane completes business processing such as billing stop and policy termination;
  • Step 8 the forwarding network element (SGW-C / AMF) returns a session deletion response, and the current user's L2TP tunnel teardown process ends.
  • FIG. 15 is a flowchart of the U-plane LAC actively negotiates the L2TP tunnel teardown under the CUPS architecture according to an embodiment of the present invention. As shown in FIG. 15, it includes:
  • Step 1 Plane C (PGW-C / SMF) receives the session deletion message from the forward network element (SGW-C / AMF).
  • Step 2 Plan C sends a PFCP Session Deletion Request message to notify Plan U (PGW-U / UPF) to delete the forwarding resources of the current session,
  • Step 3 After receiving the above message, the U-plane first sends a point-to-point protocol PPP (Point-to-Point Protocol) Terminate Request to the LNS.
  • PPP Point-to-Point Protocol
  • Step 4 The LNS returns PPP Terminate Response, and the PPP session is released.
  • Step 5 The U-plane continues to send CDN messages.
  • Step 6 The LNS returns a ZLB response.
  • Step 7 the U plane returns a PFCP Session Deletion Response message to notify the C plane that the forwarding resources of the current session have been deleted;
  • Step 8 After receiving the above message, the C plane completes the service processing such as charging stop and policy termination, and returns a session deletion response to the forward network element (SGW-C / AMF).
  • SGW-C / AMF forward network element
  • FIG. 16 is a flowchart of the U-plane LAC passively negotiating the L2TP tunnel unlinking under the CUPS architecture according to an embodiment of the present invention. As shown in FIG. 16, it includes:
  • Step 1 The U-plane (PGW-U / UPF) receives the PPP Terminate Request delete message from the LNS.
  • Step 2 The U-plane performs PPP session release and sends PPP Terminate Response to the LNS.
  • Step 3 The U-plane continues to receive CDN messages from the LNS.
  • Step 4 The U-plane performs L2TP session release and returns ZLB to the LNS.
  • Step 5 The U sends a PFCP Session Report report message to the C-plane (PGW-C / SMF), carrying the event type "LNS requests L2TP tunnel teardown or L2TP tunnel breakage".
  • the event type of "LNS requests L2TP tunnel teardown or L2TP tunnel breakage" carried in the PFCP Session Report message is unique to the embodiment of the present invention.
  • step 6 the C-plane returns to PFCP Session Report and Response after receiving it, triggering the process of releasing the current session.
  • Step 7 faces the forwarding network element (SGW-C / AMF) to trigger a session deletion message.
  • Step 8 the C-plane sends a PFCP Session Deletion Request to the media plane to notify the release of the media plane resources.
  • Step 9 U returns the PFCP Session Deletion Response message to the C plane, and the C plane completes the business processing such as billing stop and policy termination;
  • Step 10 The forwarding network element (SGW-C / AMF) returns a session deletion response, and the current user's L2TP tunnel teardown process ends.
  • An embodiment of the present invention also provides a device supporting L2TP VPN under a mobile network architecture with CU separation, including the following modules:
  • Control plane processing unit PGW-C or SMF
  • user plane processing unit PGW-U or UPF
  • the interface between CU Sxb between PGW-C and PGW-U
  • N4 between SMF and UPF
  • the CU interface protocol should support the carrying and standardization of L2TP related deployment parameters, but the current interface protocol is not defined.
  • the LAC component of L2TP VPN can be placed on the C plane (PGW-C / SMF) or U plane (PGW-U / UPF). Regardless of whether it is placed on the C surface or the U surface, it is necessary to inform the L2TP negotiation capabilities of the two parties through the Sxb and N4 interface CP, Function, Feature / UP Function Features field.
  • the embodiment of the present invention embeds the process of establishing and tearing down the L2TP tunnel in the current session activation and deactivation process.
  • the implementation of the control plane solution requires that the L2TP tunnel negotiation must be completed before the C plane notifies the U plane to establish the media plane forwarding resources. Address information, and Tunnel ID and Session ID information at the local and peer ends. At the same time, before the session deactivation process deletes the media plane, the L2TP tunnel must be unlinked.
  • the embodiment of the present invention embeds the process of establishing and tearing down the L2TP tunnel in the current session activation and deactivation process.
  • the implementation of the media plane solution requires that after the C plane notifies the U plane to establish the media plane forwarding resources, it must notify the media plane of the successful establishment after completing the L2TP tunnel negotiation, and at the same time notify the U plane to establish the media plane in the PFCP Session Session Establishment Request request message on the C plane.
  • PCO Protocol Configuration Option
  • PAP Password in PCO
  • CHAP Challenge Handshake Authentication Protocol in PCO (Challenge Handshake Authentication Protocol)
  • CHAP Challenge CHAP Challenge in PCO Response.
  • the terminal address and DNS information allocated by the LNS must be carried in the PFCP Session Establishment Response message.
  • the U plane sends a PFCP Session Report Request message C plane. This message must support the event type that carries the "LNS active request to remove the L2TP tunnel or the L2TP tunnel broken link".
  • the progress of standardization of L2TP negotiation parameters related to the Sxb and N4 interfaces in the CU separation deployment scenario is achieved, which achieves the effect that the L2TP deployment of C-plane network elements and U-plane network elements of different manufacturers is not affected, saving operator interconnection
  • the cost of interconnection has increased the competitiveness of equipment vendors.
  • a device for establishing a tunnel negotiation is also provided.
  • the device is used to implement the foregoing embodiments and preferred implementation modes, and descriptions that have already been described will not be repeated.
  • the term "module” may implement a combination of software and / or hardware that performs predetermined functions.
  • the devices described in the following embodiments are preferably implemented in software, implementation of hardware or a combination of software and hardware is also possible and conceived.
  • FIG. 17 is a block diagram 1 of an apparatus for establishing a tunnel negotiation according to an embodiment of the present invention. As shown in FIG. 17, it includes:
  • the first negotiation establishment module 172 is configured to complete the negotiation establishment of the layer 2 tunneling protocol L2TP tunnel between the control plane and the user plane through the control plane, where the control plane includes: PGW-C or SMF, and the user plane Including PGW-U or UPF; or,
  • the second negotiation establishment module 174 is configured to complete the negotiation establishment of the L2TP tunnel between the control plane and the user plane through the user plane.
  • the first negotiation establishment module 172 includes:
  • a first negotiation sub-module configured to complete the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the control plane;
  • the first establishment submodule is configured to complete the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS through the control plane.
  • the first negotiation submodule includes:
  • the first negotiation unit is configured to complete the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the control plane when only the control plane has the L2TP tunnel negotiation capability;
  • the second negotiation unit is configured to, when both the control plane and the user plane have L2TP tunnel negotiation capabilities, determine to use the control plane's L2TP tunnel negotiation capabilities, and complete the control plane with the control plane Negotiation of L2TP tunnel negotiation capabilities between the user planes.
  • the first negotiation sub-module is also set to
  • association establishment request message Sending an association establishment request message to the user plane, where the association establishment request message carries the L2TP tunnel negotiation capability of the control plane;
  • association establishment response message fed back by the user plane, where the association establishment response message carries the L2TP tunnel negotiation capability of the user plane.
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • the first establishment sub-module is also set to
  • the forward network element includes a service gateway control plane SGW-C or an access and mobility function AMF;
  • PFCP session establishment request message for establishing a forwarding relationship to the user plane, where the PFCP session establishment request message carries the tunnel ID and session ID of the LAC and the LNS;
  • a session establishment response message is returned to the forward network element, where the session establishment response message carries the IP address and DNS address information allocated by the LNS.
  • the first establishment submodule is further configured to complete the negotiation of establishing the L2TP tunnel through the LAC and the LNS including:
  • the device further includes:
  • the first deleting module is configured to delete the established L2TP tunnel.
  • the first deletion module is also set to
  • the forward network element includes a service gateway control plane SGW-C or an access and mobility function AMF;
  • the first deletion module is also set to
  • the forward network element includes the serving gateway control plane SGW-C or the access and mobility function AMF;
  • the second negotiation establishment module includes:
  • a second negotiation submodule configured to complete the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the user plane;
  • the second establishment submodule is configured to complete the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS through the user plane.
  • the second negotiation sub-module is also set to
  • the second negotiation sub-module is also set to
  • association establishment response message Return a message forwarding control protocol PFCP association establishment response message to the user plane, where the association establishment response message carries the L2TP tunnel negotiation capability of the control plane.
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • the second establishment sub-module is also set to
  • the forward network element includes a service gateway control plane SGW-C or an access and mobility function AMF;
  • PFCP session establishment request message Sending a packet forwarding control protocol PFCP session establishment request message to the user plane, where the PFCP session establishment request message is used to instruct the user plane to complete negotiation of L2TP tunnel establishment with the LNS through the L2TP access concentrator LAC, And save the tunnel ID and session ID of the LAC and the LNS, as well as the IP address and DNS address information assigned by the LNS;
  • PFCP session establishment response message returned by the user plane after the establishment of the forwarding relationship is completed, where the PFCP session establishment response message carries the IP address and DNS address information allocated by the LNS;
  • a session establishment response message is returned to the forward network element, where the session establishment response message carries the IP address and DNS address information allocated by the LNS.
  • the PFCP session establishment request message carries at least one of the following information: the user name in the protocol configuration option PCO, the PAP password in the PCO, the challenge handshake authentication protocol CHAP challenge in the PCO, and the CHAP challenge response in the PCO.
  • the device further includes:
  • the second deleting module is configured to delete the established L2TP tunnel.
  • the second deletion module is also set to
  • PFCP session deletion response message is that the user plane is sending PPP to the LNS according to the PFCP session deletion request message Termination request message, receiving the PPP termination response message returned by the LNS after releasing the PPP session, sending a session unlink notification CDN message to the LNS, and returning after receiving the zero-length message body ZLB response message returned by the LNS;
  • the second deletion module is also set to
  • PFCP session report request message sent by the user plane, where the PFCP session report request message carries the indication information of the L2TP tunnel that has been established by the LNS request to disconnect or disconnect the link, and the PFCP session report request message is the
  • the user plane receives a PPP termination request message for releasing a PPP session from the LNS, returns a termination response message to the LNS after releasing the PPP session, receives a session unlink notification CDN message sent by the LNS, and returns 0 to the LNS Sent after the length message body ZLB message;
  • the above modules can be implemented by software or hardware, and the latter can be implemented by the following methods, but not limited to this: the above modules are all located in the same processor; or, the above modules can be combined in any combination The forms are located in different processors.
  • a device for establishing a tunnel negotiation is also provided.
  • the device is used to implement the foregoing embodiments and preferred implementation modes, and descriptions that have already been described will not be repeated.
  • the term "module” may implement a combination of software and / or hardware that performs predetermined functions.
  • the devices described in the following embodiments are preferably implemented in software, implementation of hardware or a combination of software and hardware is also possible and conceived.
  • FIG. 18 is a block diagram 2 of an apparatus for establishing a tunnel negotiation according to an embodiment of the present invention. As shown in FIG. 18, it includes:
  • the third negotiation establishment module 182 is configured to complete the negotiation establishment of the layer 2 tunneling protocol L2TP tunnel between the control plane and the user plane through the control plane, where the control plane includes: PGW-C or SMF, and the user plane Including PGW-U or UPF; or,
  • the fourth negotiation establishment module 184 is configured to complete the negotiation establishment of the L2TP tunnel between the control plane and the user plane.
  • the third negotiation establishment module includes:
  • a third negotiation submodule configured to complete the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane through the control plane;
  • the third establishment submodule is configured to complete the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS through the control plane.
  • the third negotiation sub-module is also set to
  • the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane is completed through the control plane;
  • Both the control plane and the user plane have L2TP tunnel negotiation capabilities, and when the control plane determines the L2TP tunnel negotiation capabilities using the control plane, the control plane and the Negotiation of L2TP tunnel negotiation capabilities between user planes.
  • the third negotiation sub-module is also set to
  • association establishment response message fed back to the control plane, where the association establishment response message carries the L2TP tunnel negotiation capability of the user plane.
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • the third negotiation sub-module is also set to
  • the forward network element includes a service gateway control plane SGW-C or an access and mobility function AMF;
  • PFCP session establishment response message to notify the control plane that the establishment of the forwarding relationship is completed, wherein the PFCP session establishment response message is used to instruct the control to return a session establishment response message to the forward network element, wherein,
  • the session establishment response message carries the IP address and DNS address information allocated by the LNS.
  • the device further includes:
  • the sending submodule is configured to forward the L2TP VPN establishment request message sent by the control plane to the control plane through the Sxb / N4 interface during the process of completing L2TP tunnel establishment negotiation between the control plane and the LNS through the LAC LNS;
  • the forwarding submodule is configured to forward the L2TP VPN establishment response message sent by the LNS to the control plane through the Sxb / N4 interface.
  • the device further includes:
  • a third deletion module configured to delete the established L2TP tunnel through the control plane
  • the fourth deleting module is configured to delete the established L2TP tunnel.
  • the third deletion module is also set to
  • the PPP termination request message is a session deletion sent by the control plane to the network element before receiving Sent after the message, where the forward network element includes the serving gateway control plane SGW-C or the access and mobility function AMF;
  • the fourth deletion module is also set to
  • a PFCP session deletion response message is returned to the control plane, where the PFCP session deletion response message is used to instruct the control plane to terminate service processing.
  • the fourth negotiation establishment module is further configured to include:
  • the fourth negotiation submodule is configured to complete the negotiation of the L2TP tunnel negotiation capability between the control plane and the user plane;
  • the fourth establishment submodule is configured to complete the establishment of the L2TP tunnel between the user plane and the L2TP network server LNS.
  • the fourth negotiation sub-module is also set to
  • the fourth negotiation sub-module is also set to
  • the association establishment request message indicates the L2TP tunnel negotiation capability of the control plane through the carried functional characteristic parameter field;
  • the association establishment response message indicates the L2TP tunnel negotiation capability of the user plane through the carried functional characteristic parameter field.
  • the fourth establishment sub-module is also set to
  • PFCP session establishment request message sent by the control plane, where the PFCP session establishment request message is sent by the control plane after receiving a session establishment request message sent by a forward network element, the forward network element Including service gateway control plane SGW-C or access and mobility functions AMF;
  • the L2TP access concentrator LAC and the LNS to complete the L2TP tunnel establishment negotiation, and save the LAC and the LNS tunnel ID, session ID, and the LNS assigned IP address and DNS address information of domain name server;
  • a PFCP session establishment response message is returned to the control plane, where the PFCP session establishment response message carries the IP address and DNS address information allocated by the LNS, and the PFCP session establishment response message is used Instructing the control to return a session establishment response message to the forward network element, where the session establishment response message carries the IP address and DNS address information allocated by the LNS.
  • the PFCP session establishment request message carries at least one of the following information: the username in the PCO, the PAP password in the PCO, the CHAP challenge in the PCO, and the CHAP challenge response in the PCO.
  • the device further includes:
  • a fifth deleting module configured to delete the established L2TP tunnel through the control plane
  • the sixth deleting module is configured to delete the established L2TP tunnel.
  • the fifth deletion module is also set to
  • PFCP session deletion request message sent by the control plane, where the PFCP session deletion request message is sent by the control plane after receiving a session deletion request message sent by a forward network element, the forward network element Including service gateway control plane SGW-C or access and mobility functions AMF;
  • a PFCP session deletion response message is returned to the control plane, where the PFCP session deletion response message is used to instruct the control plane to terminate service processing and return the session to the forward network element Delete the response message.
  • the sixth deletion module is also set to
  • PFCP session report request message Sending a PFCP session report request message to the control plane, where the PFCP session report request message carries the indication information of the L2TP tunnel established by the LNS requesting to disconnect or disconnect the link;
  • the above modules can be implemented by software or hardware, and the latter can be implemented by the following methods, but not limited to this: the above modules are all located in the same processor; or, the above modules can be combined in any combination The forms are located in different processors.
  • An embodiment of the present invention further provides a storage medium in which a computer program is stored, wherein the computer program is configured to execute any of the steps in the above method embodiments during runtime.
  • the above storage medium may be set to store a computer program for performing the following steps:
  • S11 Complete the negotiation and establishment of the L2TP tunnel between the control plane and the user plane through the control plane;
  • the above storage medium may also be set to store a computer program for performing the following steps:
  • control plane completes the negotiation and establishment of the L2TP tunnel between the control plane and the user plane, where the control plane includes: PGW-C or SMF, and the user plane includes PGW-U or UPF; or,
  • the above storage medium may include, but is not limited to: a USB flash drive, a read-only memory (Read-ONly Memory, referred to as ROM), a random access memory (RaNdom Access Memory, referred to as RAM), Various media that can store computer programs, such as removable hard disks, magnetic disks, or optical disks.
  • ROM read-only memory
  • RAM random access memory
  • Various media that can store computer programs such as removable hard disks, magnetic disks, or optical disks.
  • An embodiment of the present invention also provides an electronic device. As shown in FIG. 19, it includes a memory 1902 and a processor 1904.
  • the memory 1902 stores a computer program.
  • the processor 1904 is configured to run the computer program to perform the above tasks. Steps in a method embodiment.
  • the electronic device may further include a transmission device 1906 and an input-output device, where the transmission device 1906 is connected to the processor 1904, and the input-output device is connected to the processor.
  • the above processor 1904 may be set to perform the following steps through a computer program:
  • S11 Complete the negotiation and establishment of the L2TP tunnel between the control plane and the user plane through the control plane;
  • the above-mentioned memory 1902 may, but is not limited to, the first negotiation establishment module 172 and the second negotiation establishment module 174 in the apparatus for acquiring media resources. In addition, it may also include, but is not limited to, other module units in the foregoing tunnel negotiation establishment device, and details are not repeated in this example.
  • the above-mentioned electronic device further includes: a display 1908 for displaying the above-mentioned media resource; and a connection bus 1910 for connecting each module component in the above-mentioned electronic device.
  • An embodiment of the present invention also provides an electronic device. As shown in FIG. 20, it includes a memory 1902 and a processor 1904.
  • the memory 1902 stores a computer program
  • the processor 1904 is configured to run the computer program to perform any of the above. Steps in a method embodiment.
  • the electronic device may further include a transmission device 1906 and an input-output device, where the transmission device 1906 is connected to the processor 1904, and the input-output device is connected to the processor.
  • the processor 1904 may also be configured to perform the following steps through a computer program:
  • control plane includes: PGW-C or SMF
  • user plane includes PGW-U or UPF
  • the above-mentioned memory 1902 may, but is not limited to, the third negotiation establishment module 182 and the fourth negotiation establishment module 184 in the above-mentioned media resource acquisition device. In addition, it may also include, but is not limited to, other module units in the foregoing tunnel negotiation establishment device, and details are not repeated in this example.
  • the above-mentioned electronic device further includes: a display 1908 for displaying the above-mentioned media resources; and a connection bus 1910 for connecting each module component in the above-mentioned electronic device.
  • modules or steps of the embodiments of the present invention described above can be implemented by a general-purpose computing device.
  • they can optionally be implemented with program code executable by the computing device, so that they can be stored in the storage device and executed by the computing device, and in some cases, can The steps shown or described are executed in the order of, or they are made into individual integrated circuit modules respectively, or multiple modules or steps among them are made into a single integrated circuit module to achieve.
  • the embodiments of the present invention are not limited to any specific combination of hardware and software.
  • an L2TP tunnel is established through negotiation between the C-plane network element and the U-plane network element, which can solve the C-plane network element (PGW-C or SMF) and the U-plane network element (PGW-U or UPF) of different manufacturers in related technologies.
  • PGW-C or SMF C-plane network element
  • PGW-U or UPF U-plane network element

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明提供了一种隧道协商建立方法及装置,其中,该方法包括:通过控制面完成所述控制面与用户面之间第二层隧道协议L2TP隧道的协商建立,或者,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。通过本发明,可以解决相关技术中不同厂家C面网元(PGW-C或SMF)和U面网元(PGW-U或UPF)混合部署无法应用L2TPVPN的问题,达到了不同厂家C面网元和U面网元对接L2TP部署不受影响的效果,节省了运营商互联互通的成本,提高了设备商设备竞争力。

Description

一种隧道协商建立方法及装置 技术领域
本发明涉及通信领域,具体而言,涉及一种隧道协商建立方法及装置。
背景技术
层二隧道协议(Level 2 tunnel protocol,简称为L2TP)虚拟专用网络(Virtual Private Network,简称为VPN)是一种应用广泛的VPN解决方案,它基于英特网工程任务组(Internet Engineering Task Force,简称为IETF)组织的协议编号(Request for Comments,简称为RFC)2661,建立L2TP隧道有比较复杂的协商流程,架构于移动网络的L2TP VPN还有一些特殊的额外的需求,那就是1)需要基于APN独立部署和开启L2TP VPN,不同的APN下建立不同的L2TP隧道,相同接入点名称(Access Point Name,简称为APN)下的用户共享L2TP隧道。2)部分场景L2TP隧道协商过程中的认证步骤需要使用终端携带的PCO(Protocol Configuration Option)认证参数。
在CU分离架构引入之前,PGW的控制面负责L2TP隧道的协商流程,PGW的媒体面负责L2TP隧道用户报文的处理。
当前的3GPP标准,还没有考虑到上述L2TP VPN部署场景,因此不同厂家的C面和U面网元对接,在L2TP VPN部署场景上存在问题。
针对相关技术中不同厂家C面网元(PGW-C或SMF)和U面网元(PGW-U或UPF)混合部署无法应用L2TP VPN的问题,尚未提出解决方案。
发明内容
本发明实施例提供了一种隧道协商建立方法及装置,以至少解决相关技术中不同厂家C面网元(PGW-C或SMF)和U面网元(PGW-U或UPF)混合部署无法应用L2TP VPN的问题。
根据本发明的一个实施例,提供了一种隧道协商建立方法,包括:
通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:分组数据网络网关控制面PGW-C或会话管理功能SMF,所述用户面包括分组数据网络网关用户面PGW-U或用户面功能UPF;或者,
通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。
根据本发明的又一个实施例,还提供了一种隧道协商建立方法,包括:
通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
完成所述控制面与所述用户面之间L2TP隧道的协商建立。
根据本发明的另一个实施例,还提供了一种隧道协商建立装置,应用于控制面,包括:
第一协商建立模块,设置为通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
第二协商建立模块,设置为通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。
根据本发明的另一个实施例,还提供了一种隧道协商建立装置,应用于用户面包括:
第三协商建立模块,设置为通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
第四协商建立模块,设置为完成所述控制面与所述用户面之间L2TP隧道的协商建立。
根据本发明的又一个实施例,还提供了一种存储介质,所述存储介质中存储有计算机程序,其中,所述计算机程序被设置为运行时执行上述任一项方法实施例中的步骤。
根据本发明的又一个实施例,还提供了一种电子装置,包括存储器和处理器,所述存储器中存储有计算机程序,所述处理器被设置为运行所述计算机程序以执行上述任一项方法实施例中的步骤。
通过本发明实施例,通过C面网元与U面网元之间协商建立L2TP隧道,可以解决相关技术中不同厂家C面网元(PGW-C或SMF)和U面网元(PGW-U或UPF)混合部署无法应用L2TP VPN的问题,达到了不同厂家C面网元和U面网元对接L2TP部署不受影响的效果,节省了运营商互联互通的成本,提高了设备商设备竞争力。
附图说明
此处所说明的附图用来提供对本发明实施例的进一步理解,构成本申请的一部分,本发明的示意性实施例及其说明用于解释本发明实施例,并不构成对本发明实施例的不当限定。在附图中:
图1是根据相关技术中的4G移动网络CUPS架构的示意图;
图2是根据相关技术中的5G移动网络CUPS架构的示意图;
图3是根据相关技术中的L2TP隧道的协商建立的示意图;
图4是根据相关技术中的L2TP隧道的协商建立的流程图;
图5是本发明实施例的一种隧道协商建立方法的移动终端的硬件结构框图;
图6是根据本发明实施例的一种隧道协商建立方法的流程图一;
图7是根据本发明实施例的一种隧道协商建立方法的流程图二;
图8是根据本发明实施例的CUPS架构中有关L2TP协商能力交互的流程图;
图9是根据本发明实施例的4G CUPS架构下L2TP VPN建立过程的流程图一;
图10是根据本发明实施例的5G CUPS架构下L2TP VPN建立过程的流程图一;
图11是根据本发明实施例的4G CUPS架构下L2TP VPN建立过程的流程图二;
图12是根据本发明实施例的5G CUPS架构下L2TP VPN建立过程的流程图二;
图13是根据本发明实施例的CUPS架构下C面LAC主动协商L2TP隧道拆链的流程图;
图14是根据本发明实施例的CUPS架构下C面LAC被动协商L2TP隧道拆链的流程图;
图15是根据本发明实施例的CUPS架构下U面LAC主动协商L2TP隧道拆链的流程图;
图16是根据本发明实施例的CUPS架构下U面LAC被动协商L2TP隧道拆链的流程图;
图17是根据本发明实施例的隧道协商建立装置的框图一;
图18是根据本发明实施例的隧道协商建立装置的框图二;
图19是根据本发明实施例的一种可选的电子装置的结构示意图一;
图20是根据本发明实施例的一种可选的电子装置的结构示意图二。
具体实施方式
下文中将参考附图并结合实施例来详细说明本发明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。
需要说明的是,本发明的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序 或先后次序。
实施例1
CU分离架构引入后,图1是根据相关技术中的4G移动网络CUPS架构的示意图,如图1所示,4G核心网分组数据网络网关(Packet Data Network Gateway,简称为PGW)网元分裂成分组数据网络网关控制面((Packet Data Network Gateway-C,简称为PGW-C)和分组数据网络网关用户面(Packet Data Network Gateway-U,简称为PGW-U),PGW-U是4G移动网络与PDN的边界;图2是根据相关技术中的5G移动网络CUPS架构的示意图,如图2所示,5G核心网架构,包括会话管理功能(Session Management Function,简称为SMF)和网元用户面功能(User Plane Function,简称为UPF),其中UPF是5G移动网络与DN的边界。
图3是根据相关技术中的L2TP隧道的协商建立的示意图,如图3所示,访问集中器(L2TP Access Concentrator–L2TP,简称为LAC)与L2TP网络服务器(L2TP Network Server,简称为LNS)之间控制面负责L2TP隧道的协商建立和删除,用户面负责L2TP隧道报文的处理。
图4是根据相关技术中的L2TP隧道的协商建立的流程图,如图4所示,包括:
步骤1,LAC向LNS发送SCCRQ(Start-Control-Connection-Request,打开控制连接请求)消息;
步骤2,LAC接收LNS返回的SCCRP(Start-Control-Connection-Reply,打开控制连接响应)消息;
步骤3,LAC向LNS发送SCCCN(Start-Control-Connection-Connected,打开控制连接完成)消息;
步骤4,LAC接收LNS返回的0长度消息体(Zero-Length Body,简称为ZLB)消息;
步骤5,LAC向LNS发送ICRQ(Incoming-Call-Request,来电呼叫请求)消息;
步骤6,LAC接收LNS返回的ICRP(Incoming-Call-Reply,来电呼叫响应)消息;
步骤7,LAC向LNS发送ICCN(Incoming-Call-Connected,,来电呼叫建立完成)消息;
步骤8,LAC接收LNS返回的ZLB消息;
步骤9,LAC向LNS发送点到点协议(Point-to-Point Protocol,简称为PPP)LCP(Link Control Protocol,链路控制协议)配置请求;
步骤10,LAC接收LNS返回的PPP LCP配置响应;
步骤11,LAC向LNS发送PPP鉴权请求;
步骤12,LAC接收LNS返回的PPP鉴权响应;
步骤13,LAC向LNS发送PPP IPCP(IP Control Protocol,IP控制协议)配置请求;
步骤14,LAC接收LNS返回的IPCP配置响应。
本申请实施例一所提供的方法实施例可以在移动终端、计算机终端或者类似的运算装置中执行。以运行在移动终端上为例,图5是本发明实施例的一种隧道协商建立方法的移动终端的硬件结构框图,如图5所示,移动终端10可以包括一个或多个(图5中仅示出一个)处理器102(处理器102可以包括但不限于微处理器MCU或可编程逻辑器件FPGA等的处理装置)和用于存储数据的存储器104,可选地,上述移动终端还可以包括用于通信功能的传输设备106以及输入输出设备108。本领域普通技术人员可以理解,图5所示的结构仅为示意,其并不对上述移动终端的结构造成限定。例如,移动终端10还可包括比图5中所示更多或者更少的组件,或者具有与图5所示不同的配置。
存储器104可用于存储计算机程序,例如,应用软件的软件程序以及模块,如本发明实施例中的报文接收方法对应的计算机程序,处理器102通过运行存储在存储器104内的计算机程序,从而执行各种功能应用以及 数据处理,即实现上述的方法。存储器104可包括高速随机存储器,还可包括非易失性存储器,如一个或者多个磁性存储装置、闪存、或者其他非易失性固态存储器。在一些实例中,存储器104可进一步包括相对于处理器102远程设置的存储器,这些远程存储器可以通过网络连接至移动终端10。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。
传输装置106用于经由一个网络接收或者发送数据。上述的网络具体实例可包括移动终端10的通信供应商提供的无线网络。在一个实例中,传输装置106包括一个网络适配器(Network INterface CoNtroller,简称为NIC),其可通过基站与其他网络设备相连从而可与互联网进行通讯。在一个实例中,传输装置106可以为射频(Radio FrequeNcy,简称为RF)模块,其用于通过无线方式与互联网进行通讯。
基于上述移动终端,本实施例提供了一种隧道协商建立方法,图6是根据本发明实施例的一种隧道协商建立方法的流程图一,如图6所示,该流程包括如下步骤:
步骤S602,通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:分组数据网络网关控制面PGW-C或会话管理功能SMF,所述用户面包括分组数据网络网关用户面PGW-U或用户面功能UPF;或者,
步骤S604,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。
可选地,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道的协商建立包括:
通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
通过所述控制面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
可选地,通过所述控制面完成所述控制面与用户面之间L2TP隧道协商能力的协商包括:
在仅所述控制面有L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
在所述控制面和所述用户面均有L2TP隧道协商能力的情况下,确定使用所述控制面的L2TP隧道协商能力,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
可选地,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
向所述用户面发送关联建立请求消息,其中,所述关联建立请求消息中携带有所述控制面的L2TP隧道协商能力;
接收所述用户面反馈的关联建立响应消息,其中,所述关联建立响应消息中携带有所述用户面的L2TP隧道协商能力。
可选地,所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立包括:
接收前向网元的会话建立请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述会话建立请求消息选择所述用户面;
通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
向所述用户面发送用于建立转发关系的报文转发控制协议PFCP会话 建立请求消息,其中,所述PFCP会话建立请求消息中携带有所述LAC和所述LNS的隧道ID和会话ID;
接收所述用户面返回的用于通知转发关系建立完成的PFCP(Packet Forwarding Control Protocol)会话建立响应消息;
向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS(Domain Name Server)地址信息。
可选地,通过所述LAC(L2TP Access Concentrator)与所述LNS完成L2TP隧道建立的协商包括:
通过所述用户面的Sxb/N4接口向所述LNS发送L2TP VPN建立请求消息;
通过所述用户面的Sxb/N4接口接收所述LNS发送的L2TP VPN建立响应消息。
可选地,在通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
删除已建立的所述L2TP隧道。
可选地,删除已建立的所述L2TP隧道包括:
接收前向网元发送的会话删除请求消息,其中,所述前向网元包括服务网关控制面(Serving Gateway-C,简称为SGW-C)或接入和移动性功能AMF;
通过所述用户面的Sxb/N4接口向所述LNS发送点到点协议PPP终结请求消息;
通过所述用户面的Sxb/N4接口接收所述LNS返回的PPP终结响应消息;
通过所述用户面的Sxb/N4接口向所述LNS发送会话拆链通知(Call-Disconnect-Notify,简称为CDN)消息;
通过所述用户面的Sxb/N4接口接收所述LNS返回的0长度消息体(Zero-Length Body,简称为ZLB)消息;
向所述用户面发送报文转发控制协议PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于指示所述用户面删除当前会话的转发关系;
接收所述用户面在删除当前会话的转发关系之后返回的PFCP会话删除响应消息;
根据所述PFCP会话删除响应消息终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,删除已建立的所述L2TP隧道包括:
通过所述用户面的Sxb/N4接口接收所述LNS发送的点到点协议PPP终结请求消息;
根据所述PPP终结请求消息释放PPP会话,并通过所述用户面的Sxb/N4接口向所述LNS返回PPP终结响应消息;
通过所述用户面的Sxb/N4接口接收所述LNS发送的会话拆链通知CDN消息;
通过所述用户面的Sxb/N4接口向所述LNS返回0长度消息体ZLB消息;
向前向网元发送会话删除通知消息,并向所述用户面发送报文转发控制协议PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于请求所述用户面删除当前会话的转发关系,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
接收所述用户面返回的PFCP会话删除响应消息;
根据所述PFCP会话删除响应消息终止业务处理;
接收所述前向网元在删除会话之后返回的会话删除响应消息。
可选地,通过所述用户面完成所述控制面与所述用户面之间L2TP隧 道的协商建立包括:
通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
通过所述用户面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
可选地,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
在仅所述用户面有L2TP隧道协商能力,或所述控制面和所述用户面均有L2TP隧道协商能力的情况下,确定使用所述用户面的L2TP隧道协商能力,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
可选地,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
接收所述用户面发送的PFCP关联建立请求消息,其中,所述关联建立请求消息中携带有所述用户面的L2TP隧道协商能力;
向所述用户面返回报文转发控制协议PFCP关联建立响应消息,其中,所述关联建立响应消息中携带有所述控制面的L2TP隧道协商能力。
可选地,所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,通过所述用户面完成所述用户面与所述LNS之间L2TP隧道的建立包括:
接收前向网元发送的会话建立请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述会话建立请求消息选择所述用户面;
向所述用户面发送报文转发控制协议PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息用于指示所述用户面通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
接收所述用户面在转发关系建立完成之后返回的PFCP会话建立响应消息,其中,所述PFCP会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息;
向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
可选地,所述PFCP会话建立请求消息携带以下信息至少之一:协议配置选项(Protocol Configuration Option,PCO)简称为中的用户名、PCO中的PAP密码、PCO中的挑战握手认证协议(Challenge Handshake Authentication Protocol,简称为CHAP)挑战Challenge,PCO中的CHAP挑战响应challenge response。
可选地,在通过所述用户面完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
删除已建立的所述L2TP隧道。
可选地,删除已建立的所述L2TP隧道包括:
接收所述前向网元发送的会话删除消息;
向所述用户面发送PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于指示所述用户面删除当前会话的转发关系;
接收所述用户面在删除当前会话的转发关系之后返回的PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息是所述用户面在根据所述PFCP会话删除请求消息向所述LNS发送PPP终结请求消息,接收所述LNS在释放PPP会话之后返回的PPP终结响应消息,向所述LNS发送会话拆链通知CDN消息,接收所述LNS返回的0长度消息体ZLB响应 消息之后返回的;
根据所述PFCP会话删除响应消息终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,删除已建立的所述L2TP隧道包括:
接收所述用户面发送的PFCP会话报告请求消息,其中,所述PFCP会话报告请求消息中携带有LNS请求拆链或断链已建立的L2TP隧道的指示信息,所述PFCP会话报告请求消息是所述用户面从LNS接收到用于释放PPP会话的PPP终止请求消息,释放PPP会话之后向所述LNS返回终止响应消息,接收所述LNS发送的会话拆链通知CDN消息,向所述LNS返回0长度消息体ZLB消息之后发送的;
向所述用户面返回PFCP会话报告响应消息;
向所述前向网元发送会话删除请求消息,同时向所述用户面发送用于指示所述用户面删除当前会话的转发关系的PFCP会话删除请求消息;
接收所述用户面返回的PFCP会话删除响应消息;
根据所述PFCP会话删除响应消息终止业务处理;
向所述前向网元返回会话删除响应消息。
实施例2
图7是根据本发明实施例的一种隧道协商建立方法的流程图二,如图7所示,包括:
步骤S702,通过控制面完成所述控制面与用户面之间第二层隧道协议L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
步骤S704,完成所述控制面与所述用户面之间L2TP隧道的协商建立。
可选地,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道的协商建立包括:
通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
通过所述控制面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
可选地,通过所述控制面完成所述控制面与用户面之间L2TP隧道协商能力的协商包括:
在仅所述控制面有L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
在所述控制面和所述用户面均有L2TP隧道协商能力,在所述控制面确定使用所述控制面的L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
可选地,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
接收所述控制面发送的关联建立请求消息,其中,所述关联建立请求消息中携带有所述控制面的L2TP隧道协商能力;
向所述控制面反馈的关联建立响应消息,其中,所述关联建立响应消息中携带有所述用户面的L2TP隧道协商能力。
可选地,所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立包括:
接收所述控制面发送的用于建立转发关系的PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息中携带有所述LAC和所述LNS的隧道ID和会话ID,所述PFCP会话建立请求消息是所述控制面接收前向网 元的会话建立请求消息,通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
向所述控制面返回用于通知转发关系建立完成的PFCP会话建立响应消息,其中,所述PFCP会话建立响应消息用于指示所述控制面向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
可选地,所述方法还包括:
在所述控制面通过所述LAC与所述LNS完成L2TP隧道建立的协商的过程中,通过Sxb/N4接口将所述控制面发送的L2TP VPN建立请求消息转发给所述LNS;
通过所述Sxb/N4接口将所述LNS发送的L2TP VPN建立响应消息转发给所述控制面。
可选地,在通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
通过所述控制面删除已建立的所述L2TP隧道;或者
删除已建立的所述L2TP隧道。
可选地,通过所述控制面删除已建立的所述L2TP隧道包括:
通过Sxb/N4接口将所述控制面发的点到点协议PPP终结请求消息转发给所述LNS,其中,所述PPP终结请求消息是所述控制面在接收到前向网元发送的会话删除消息之后发送的,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
通过所述Sxb/N4接口将所述LNS返回的PPP终结响应消息转发给所述控制面;
通过所述Sxb/N4接口将所述控制面发送的会话拆链通知CDN消息转 发给所述LNS;
通过所述Sxb/N4接口将所述LNS返回的0长度消息体ZLB消息转发给所述控制面;
接收所述控制面发送的PFCP会话删除请求消息;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,删除已建立的所述L2TP隧道包括:
通过Sxb/N4接口将所述LNS发送的点到点协议PPP终结请求消息转发给所述控制面,所述PPP终结请求消息用于指示所述控制面释放PPP会话;
通过所述Sxb/N4接口将所述控制面返回的PPP终结响应消息转发给所述LNS;
通过所述Sxb/N4接口将所述LNS发送的会话拆链通知CDN消息转发给所述控制面;
通过所述Sxb/N4接口将所述控制面返回的0长度消息体ZLB消息转发给所述LNS;
接收所述控制面发送的PFCP会话删除请求消息;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理。
可选地,完成所述控制面与所述用户面之间L2TP隧道的协商建立包括:
完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
可选地,完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
在仅所述用户面有L2TP隧道协商能力,或所述控制面和所述用户面均有L2TP隧道协商能力,所述控制面确定使用所述用户面的L2TP隧道协商能力的情况下,完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
可选地,完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
向所述控制面发送PFCP关联建立请求消息,其中,所述关联建立请求消息中携带有所述用户面的L2TP隧道协商能力;
接收所述控制面返回的PFCP关联建立响应消息,其中,所述关联建立响应消息中携带有所述控制面的L2TP隧道协商能力。
可选地,所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,完成所述用户面与所述LNS之间L2TP隧道的建立包括:
接收所述控制面发送的PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息是所述控制面在接收到前向网元发送的会话建立请求消息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述PFCP会话建立请求消息通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
在转发关系建立完成之后向所述控制面返回PFCP会话建立响应消息, 其中,所述PFCP会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息,所述PFCP会话建立响应消息用于指示所述控制面向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
可选地,所述PFCP会话建立请求消息携带以下信息至少之一:PCO中的用户名、PCO中的PAP密码、PCO中的CHAP挑战Challenge、PCO中的CHAP挑战响应challenge response。
可选地,在完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
通过所述控制面删除已建立的所述L2TP隧道;
删除已建立的所述L2TP隧道。
可选地,通过所述控制面删除已建立的所述L2TP隧道包括:
接收所述控制面发送的PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息是所述控制面在接收到前向网元发送的会话删除请求消息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
根据所述PFCP会话删除请求消息向所述LNS发送PPP终结请求消息;
接收所述LNS在释放PPP会话之后返回的PPP终结响应消息;
向所述LNS发送会话拆链通知CDN消息;
接收所述LNS返回的0长度消息体ZLB响应消息;
在删除当前会话的转发关系之后向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,删除已建立的所述L2TP隧道包括:
从所述LNS接收用于释放PPP会话的PPP终止请求消息;
在释放PPP会话之后向所述LNS返回终止响应消息;
接收所述LNS发送的会话拆链通知CDN消息;
向所述LNS返回0长度消息体ZLB消息;
向所述控制面发送PFCP会话报告请求消息,其中,所述PFCP会话报告请求消息中携带有LNS请求拆链或断链建立的L2TP隧道的指示信息;
接收所述控制面返回的PFCP会话报告响应消息;
向所述前向网元发送会话删除请求消息;
接收所述控制面发送的PFCP会话删除请求消息;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
本发明实施例包括两种方式:一为控制面方案(后面的描述简称CP方案),即L2TP隧道的协商放在控制面;二为媒体面方案(后面的描述简称UP方案),即L2TP隧道的协商放在媒体面。
图8是根据本发明实施例的CUPS架构中有关L2TP协商能力交互的流程图,如图8所示,通过所述Sxb和N4接口L2TP隧道协商相关参数标准化,C面(PGW-C/SMF)和U面(PGW-U/UPF)的L2TP隧道协商能力的交互包括以下步骤:
步骤1,C面和U面建立关联时通知各自的L2TP隧道协商能力,如果C面主动建立关联,则在报文转发控制协议(Packet Forwarding Control Protocol,简称为PFCP)关联建立请求Association Setup Request携带CP参数字段新开标记功能特性Function Features指示L2TP隧道协商能力;
步骤2,U面返回PFCP关联建立响应Association Setup Response携带UP功能特征Function Features指示L2TP隧道协商能力;
步骤3,如果U面主动建立关联,则在PFCP Association Setup Request携带UP Function Features指示L2TP隧道协商能力;
步骤4,C面返回PFCP Association Setup Response携带CP Function Features指示L2TP隧道协商能力;
步骤5,如果C面选择L2TP CP方案,则需要立即发起Sx-U/N4-U的隧道建立,关联的PDR/FAR指示此隧道建立用于透传L2TP协商报文。
步骤6,U面返回Sx-U/N4-U隧道建立响应。
需要说明的是,1)如果C面和U面都有L2TP隧道协商能力,则最终由C面决策使用C面的L2TP隧道协商能力还是U面的L2TP隧道协商能力;在CP Function Features/UP Function Features指示L2TP隧道协商能力。2)C面通过报文检测规则(Packet Detection Rule,简称为PDR)/转发活动规则(Forwarding Action Rule,简称为FAR)指示U面透传L2TP协商报文到控制面。
如果C面决策使用C面的L2TP协商能力,C面(PGW-C/SMF)L2TP隧道协商过程,图9是根据本发明实施例的4G CUPS架构下L2TP VPN建立过程的流程图一,图10是根据本发明实施例的5G CUPS架构下L2TP VPN建立过程的流程图一,如图9和10所示,包括:
步骤1,C面(PGW-C/SMF)收到前向网元(SGW-C/AMF)的会话建立请求,其中携带了会话建立的相关参数(如隧道协商信息,协议配置选项(Protocol Configuration Option,简称为PCO)等);
步骤2,C面根据本地配置(如LNS地址,隧道名称信息,鉴权方式等)或其他策略源(如AAA-Authentication,Authorization,Accounting授权LNS地址、隧道名称、鉴权方式等)指示当前用户需要建立L2TP隧道。C面选择UPF/PGW-U,通过与此UPF/PGW-U的接口Sxb/N4的用户面User Plane向LNS发起L2TP隧道协商建立过程,LNS的协商响应报文也通过此Sxb/N4的User Plane。通过Sxb/N4的User Plane来支持L2TP隧道协商过程为本发明实施例独创。
步骤3,C面的LAC与LNS完成L2TP隧道的协商,C面本地保存本端和LNS对端的隧道Tunnel ID和会话Session ID参数,以及LNS给终端分配的IP地址和DNS参数;
图9步骤2,3中,LAC功能体在PGW-C,LAC和LNS之间的协商报文通过Sxb User Plane转发;图10的步骤2,3中,LAC功能体在SMF,LAC和LNS之间的协商报文通过N4User Plane转发。
步骤4,C面通知U面(PGW-U/UPF)为当前用户建立转发关系,发送PFCP Session Establishment Request消息,其中携带本端和对端的Tunnel ID和Session ID参数。通过PFCP Session Establishment Request携带本端和对端的Tunnel ID和Session ID参数为本发明实施例独创。
步骤5,U面返回PFCP Session Establishment Response通知转发关系建立完成。
步骤6,C面向前向网元返回会话建立响应,其中携带LNS分配的IP地址和域名服务器DNS地址信息。
需要特殊说明的是:SGW-C和PGW-C之间的4G会话建立消息(图9的步骤1,6),AMF与SMF之间的5G会话建立消息(图10的步骤1,6),两种会话建立消息在3GPP协议中名称不同,作用类似,采用了合并描述的方式。
如果C面决策使用U面的L2TP协商能力,U面(PGW-U/UPF)L2TP隧道协商过程,图11是根据本发明实施例的4G CUPS架构下L2TP VPN建立过程的流程图二,图12是根据本发明实施例的5G CUPS架构下L2TP VPN建立过程的流程图二,如图11和12所示,包括:
步骤1,C面收到前向网元(SGW-C/AMF)的会话建立请求,其中携带了会话建立的相关参数;完成策略、计费等相关处理过程。
步骤2,C面根据本地配置或其他策略源(如AAA)指示当前用户需要建立L2TP隧道。C面完成UPF/PGW-U选择后,发送PFCP Session Establishment Request消息到U面,携带L2TP协商所需的相关参数,包 括如下信息之一或组合:PCO(Protocol Configuration Optio)中的Username、PCO中的PAP password(仅PAP场景携带)、PCO中的CHAP(Challenge Handshake Authentication Protocol)Challenge(仅CHAP场景携带)、PCO中的CHAP challenge response(仅CHAP场景携带)。此处PFCP Session Establishment Request消息携带L2TP协商所需的相关参数。
步骤3,U面收到上述消息后,再结合本地的配置,立即发起L2TP隧道的协商过程,基本过程如附图4所示。
步骤4,U面完成L2TP隧道的协商过程,本地保存本端和对端的Tunnel ID和Session ID信息,以及LNS给终端分配的IP地址和DNS(Domain Name Server)信息。此时U面完成当前用户在UPF/PGW-U上下行转发关系的建立。
图11的步骤3、4中,LAC功能体在PGW-U,LAC和LNS之间的部分协商参数通过Sxb Control Plane传递;图12的步骤3、4中,LAC功能体在UPF,LAC和LNS之间的部分协商参数通过N4Control Plane传递。
步骤5,U面返回PFCP Session Establishment Response通知转发关系建立完成,消息中携带LNS分配的终端IP地址和DNS信息。PFCP Session Establishment Response携带LNS分配的IP地址和DNS信息为本发明实施例独创。
步骤6,C面收到上述消息后,通知前向网元会话建立响应消息,此消息中携带上述步骤中的终端IP地址和DNS信息。
需要特殊说明的是:SGW-C和PGW-C之间的4G会话建立消息(图11的步骤1,6),AMF与SMF之间的5G会话建立消息(图12的步骤1,6),两种会话建立消息在3GPP协议中名称不同,但作用类似,采用了合并描述的方式。
C面(PGW-C/SMF)主动协商L2TP隧道拆链过程,图13是根据本发明实施例的CUPS架构下C面LAC主动协商L2TP隧道拆链的流程图,如图13所示,包括:
步骤1,C面(PGW-C/SMF)从前向网元收到会话删除消息。
步骤2,C面发起L2TP的拆链过程,首先通过Sxb或N4接口的User Plane向LNS发送PPP终结请求Terminate Request。
步骤3,LNS返回PPP Terminate Response,经由Sxb或N4接口的User Plane转发到C面。
步骤4,C面继续发送会话拆链通知(Call-Disconnect-Notify,简称为CDN)消息。
步骤5,LNS返回ZLB响应,经由Sxb或N4接口的User Plane转发到C面。
步骤6,C面发送PFCP Session Deletion Request消息通知U面(PGW-U/UPF)删除当前会话的转发关系;
步骤7,U面返回PFCP会话删除响应Session Deletion Response消息到C面,C面完成计费停止,策略终止等业务处理。
步骤8,C面返回会话删除响应到前向网元(SGW-C/AMF)。
C面(PGW-C/SMF)被动响应L2TP隧道拆链过程,图14是根据本发明实施例的CUPS架构下C面LAC被动协商L2TP隧道拆链的流程图,如图14所示,包括:
步骤1,C面(PGW-C/SMF)经由Sxb或N4接口的User Plane从LNS收到PPP Terminate Request会话删除消息。
步骤2,C面执行PPP会话释放,并经由Sxb或N4接口的User Plane向LNS发送PPP Terminate Response。
步骤3,C面经由Sxb或N4接口的User Plane从LNS收到CDN消息。
步骤4,C面执行L2TP会话释放,并经由Sxb或N4接口的User Plane向LNS发送ZLB。
步骤5,C面向前向网元(SGW-C/AMF)通知会话删除。
步骤6,C面向U面(PGW-U/UPF)发送PFCP Session Deletion Request通知释放媒体面资源。
步骤7,U面向C面返回PFCP Session Deletion Response消息,C面完成计费停止,策略终止等业务处理;
步骤8,前向网元(SGW-C/AMF)返回会话删除响应,当前用户的L2TP隧道拆链流程结束。
U面主动协商L2TP隧道拆链过程,图15是根据本发明实施例的CUPS架构下U面LAC主动协商L2TP隧道拆链的流程图,如图15所示,包括:
步骤1,C面(PGW-C/SMF)从前向网元(SGW-C/AMF)收到会话删除消息。
步骤2,C面发送PFCP Session Deletion Request消息通知U面(PGW-U/UPF)删除当前会话的转发资源,
步骤3,U面收到上述消息后,首先向LNS发送点对点协议PPP(Point-to-Point Protocol)Terminate Request。
步骤4,LNS返回PPP Terminate Response,PPP会话释放完成。
步骤5,U面继续发送CDN消息。
步骤6,LNS返回ZLB响应。
步骤7,U面返回PFCP Session Deletion Response消息通知C面已删除当前会话的转发资源;
步骤8,C面收到上述消息后,完成计费停止,策略终止等业务处理,并返回会话删除响应到前向网元(SGW-C/AMF)。
U面被动响应L2TP隧道拆链过程,图16是根据本发明实施例的CUPS架构下U面LAC被动协商L2TP隧道拆链的流程图,如图16所示,包括:
步骤1,U面(PGW-U/UPF)从LNS收到PPP Terminate Request会话删除消息。
步骤2,U面执行PPP会话释放,向LNS发送PPP Terminate Response。
步骤3,U面继续从LNS收到CDN消息。
步骤4,U面执行L2TP会话释放,向LNS返回ZLB。
步骤5,U面向C面(PGW-C/SMF)发送PFCP Session Report Request消息,携带“LNS请求L2TP隧道拆链或L2TP隧道断链”事件类型。在PFCP Session Report Request消息中携带“LNS请求L2TP隧道拆链或L2TP隧道断链”事件类型为本发明实施例独创。
步骤6,C面收到后返回PFCP Session Report Response,触发当前会话释放的流程。
步骤7,C面向前向网元(SGW-C/AMF)触发会话删除消息。
步骤8,C面同时向媒体面发送PFCP Session Deletion Request通知释放媒体面资源。
步骤9,U面向C面返回PFCP Session Deletion Response消息,C面完成计费停止,策略终止等业务处理;
步骤10,前向网元(SGW-C/AMF)返回会话删除响应,当前用户的L2TP隧道拆链流程结束。
本发明实施例还提供了一种CU分离的移动网络架构下支持L2TP VPN的装置,包括以下模块:
控制面处理单元(PGW-C或SMF),用户面处理单元(PGW-U或UPF),及CU之间的接口Sxb(PGW-C和PGW-U之间)和N4(SMF和UPF之间)接口协议。
CU接口协议应支持L2TP相关部署参数的携带与标准化,而当前的接口协议并没有定义。
整个L2TP业务流程,需要C面和U面的同时协作。
L2TP VPN的LAC组件可以放在C面(PGW-C/SMF),也可以放在U面(PGW-U/UPF)。无论放在C面或U面,都需要通过Sxb和N4接口CP Function Features/UP Function Features参数字段告知双方的L2TP协商 能力。
本发明实施例在当前的会话激活和去活过程中嵌入了L2TP隧道的建立和拆除的过程。控制面方案实施要求在C面通知U面建立媒体面转发资源之前,必须完成L2TP隧道的协商,在C面通知U面建立媒体面的PFCP Session Establishment Request消息中必须能够携带本端和对端的隧道地址信息,以及本端和对端的Tunnel ID和Session ID信息。同时在会话去活流程删除媒体面的动作之前,必须先完成L2TP隧道的拆链。
本发明实施例在当前的会话激活和去活过程中嵌入了L2TP隧道的建立和拆除的过程。媒体面方案实施要求在C面通知U面建立媒体面转发资源之后,必须在完成L2TP隧道的协商之后再通知媒体面建立成功,同时在C面通知U面建立媒体面的PFCP Session Establishment Request消息中必须能够携带L2TP隧道协商相关参数,包括但不限于协议配置选项(Protocol Configuration Option,简称为PCO),PCO中的用户名,PCO中的PAP Password,PCO中的挑战握手认证协议(Challenge Handshake Authentication Protocol,简称为CHAP)Challenge,PCO中的CHAP Challenge Response。在PFCP Session Establishment Response消息中必须携带LNS分配的终端地址和DNS信息。同时在LNS主动拆链时,U面发送PFCP Session Report Request消息C面,此消息必须支持携带“LNS主动请求拆除L2TP隧道或L2TP隧道断链”的事件类型。
本发明实施例,取得了CU分离部署场景Sxb和N4接口有关L2TP协商参数标准化的进步,达到了不同厂家C面网元和U面网元对接L2TP部署不受影响的效果,节省了运营商互联互通的成本,提高了设备商设备竞争力。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到根据上述实施例的方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本发明实施例的技术方案本质上或者说对现有技术做出贡献的部分可 以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,或者网络设备等)执行本发明各个实施例所述的方法。
实施例3
在本实施例中还提供了一种隧道协商建立装置,该装置用于实现上述实施例及优选实施方式,已经进行过说明的不再赘述。如以下所使用的,术语“模块”可以实现预定功能的软件和/或硬件的组合。尽管以下实施例所描述的装置较佳地以软件来实现,但是硬件,或者软件和硬件的组合的实现也是可能并被构想的。
图17是根据本发明实施例的隧道协商建立装置的框图一,如图17所示,包括:
第一协商建立模块172,设置为通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
第二协商建立模块174,设置为通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。
可选地,所述第一协商建立模块172包括:
第一协商子模块,设置为通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
第一建立子模块,设置为通过所述控制面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
可选地,所述第一协商子模块包括:
第一协商单元,设置为在仅所述控制面有L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能 力的协商;
第二协商单元,设置为在所述控制面和所述用户面均有L2TP隧道协商能力的情况下,确定使用所述控制面的L2TP隧道协商能力,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
可选地,所述第一协商子模块,还设置为
向所述用户面发送关联建立请求消息,其中,所述关联建立请求消息中携带有所述控制面的L2TP隧道协商能力;
接收所述用户面反馈的关联建立响应消息,其中,所述关联建立响应消息中携带有所述用户面的L2TP隧道协商能力。
可选地,
所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,所述第一建立子模块,还设置为
接收前向网元的会话建立请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述会话建立请求消息选择所述用户面;
通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
向所述用户面发送用于建立转发关系的报文转发控制协议PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息中携带有所述LAC和所述LNS的隧道ID和会话ID;
接收所述用户面返回的用于通知转发关系建立完成的PFCP会话建立响应消息;
向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
可选地,所述第一建立子模块,还设置为通过所述LAC与所述LNS完成L2TP隧道建立的协商包括:
通过所述用户面的Sxb/N4接口向所述LNS发送L2TP VPN建立请求消息;
通过所述用户面的Sxb/N4接口接收所述LNS发送的L2TP VPN建立响应消息。
可选地,所述装置还包括:
第一删除模块,设置为删除已建立的所述L2TP隧道。
可选地,所述第一删除模块,还设置为
接收前向网元发送的会话删除请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
通过所述用户面的Sxb/N4接口向所述LNS发送点到点协议PPP终结请求消息;
通过所述用户面的Sxb/N4接口接收所述LNS返回的PPP终结响应消息;
通过所述用户面的Sxb/N4接口向所述LNS发送会话拆链通知CDN消息;
通过所述用户面的Sxb/N4接口接收所述LNS返回的0长度消息体ZLB消息;
向所述用户面发送报文转发控制协议PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于指示所述用户面删除当前会话的转发关系;
接收所述用户面在删除当前会话的转发关系之后返回的PFCP会话删除响应消息;
根据所述PFCP会话删除响应消息终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,所述第一删除模块,还设置为
通过所述用户面的Sxb/N4接口接收所述LNS发送的点到点协议PPP终结请求消息;
根据所述PPP终结请求消息释放PPP会话,并通过所述用户面的Sxb/N4接口向所述LNS返回PPP终结响应消息;
通过所述用户面的Sxb/N4接口接收所述LNS发送的会话拆链通知CDN消息;
通过所述用户面的Sxb/N4接口向所述LNS返回0长度消息体ZLB消息;
向前向网元发送会话删除通知消息,并向所述用户面发送报文转发控制协议PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于请求所述用户面删除当前会话的转发关系,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
接收所述用户面返回的PFCP会话删除响应消息;
根据所述PFCP会话删除响应消息终止业务处理;
接收所述前向网元在删除会话之后返回的会话删除响应消息。
可选地,所述第二协商建立模块包括:
第二协商子模块,设置为通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
第二建立子模块,设置为通过所述用户面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
可选地,所述第二协商子模块,还设置为
在仅所述用户面有L2TP隧道协商能力,或所述控制面和所述用户面均有L2TP隧道协商能力的情况下,确定使用所述用户面的L2TP隧道协 商能力,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
可选地,所述第二协商子模块,还设置为
接收所述用户面发送的PFCP关联建立请求消息,其中,所述关联建立请求消息中携带有所述用户面的L2TP隧道协商能力;
向所述用户面返回报文转发控制协议PFCP关联建立响应消息,其中,所述关联建立响应消息中携带有所述控制面的L2TP隧道协商能力。
可选地,
所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,所述第二建立子模块,还设置为
接收前向网元发送的会话建立请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述会话建立请求消息选择所述用户面;
向所述用户面发送报文转发控制协议PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息用于指示所述用户面通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
接收所述用户面在转发关系建立完成之后返回的PFCP会话建立响应消息,其中,所述PFCP会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息;
向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
可选地,
所述PFCP会话建立请求消息携带以下信息至少之一:协议配置选项PCO中的用户名、PCO中的PAP密码、PCO中的挑战握手认证协议CHAP挑战Challenge,PCO中的CHAP挑战响应challenge response。
可选地,所述装置还包括:
第二删除模块,设置为删除已建立的所述L2TP隧道。
可选地,所述第二删除模块,还设置为
接收所述前向网元发送的会话删除消息;
向所述用户面发送PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于指示所述用户面删除当前会话的转发关系;
接收所述用户面在删除当前会话的转发关系之后返回的PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息是所述用户面在根据所述PFCP会话删除请求消息向所述LNS发送PPP终结请求消息,接收所述LNS在释放PPP会话之后返回的PPP终结响应消息,向所述LNS发送会话拆链通知CDN消息,接收所述LNS返回的0长度消息体ZLB响应消息之后返回的;
根据所述PFCP会话删除响应消息终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,所述第二删除模块,还设置为
接收所述用户面发送的PFCP会话报告请求消息,其中,所述PFCP会话报告请求消息中携带有LNS请求拆链或断链已建立的L2TP隧道的指示信息,所述PFCP会话报告请求消息是所述用户面从LNS接收到用于释放PPP会话的PPP终止请求消息,释放PPP会话之后向所述LNS返回终止响应消息,接收所述LNS发送的会话拆链通知CDN消息,向所述LNS返回0长度消息体ZLB消息之后发送的;
向所述用户面返回PFCP会话报告响应消息;
向所述前向网元发送会话删除请求消息,同时向所述用户面发送用于指示所述用户面删除当前会话的转发关系的PFCP会话删除请求消息;
接收所述用户面返回的PFCP会话删除响应消息;
根据所述PFCP会话删除响应消息终止业务处理;
向所述前向网元返回会话删除响应消息。
需要说明的是,上述各个模块是可以通过软件或硬件来实现的,对于后者,可以通过以下方式实现,但不限于此:上述模块均位于同一处理器中;或者,上述各个模块以任意组合的形式分别位于不同的处理器中。
实施例4
在本实施例中还提供了一种隧道协商建立装置,该装置用于实现上述实施例及优选实施方式,已经进行过说明的不再赘述。如以下所使用的,术语“模块”可以实现预定功能的软件和/或硬件的组合。尽管以下实施例所描述的装置较佳地以软件来实现,但是硬件,或者软件和硬件的组合的实现也是可能并被构想的。
图18是根据本发明实施例的隧道协商建立装置的框图二,如图18所示,包括:
第三协商建立模块182,设置为通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
第四协商建立模块184,设置为完成所述控制面与所述用户面之间L2TP隧道的协商建立。
可选地,所述第三协商建立模块包括:
第三协商子模块,设置为通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
第三建立子模块,设置为通过所述控制面完成所述用户面与L2TP网 络服务器LNS之间L2TP隧道的建立。
可选地,所述第三协商子模块,还设置为
在仅所述控制面有L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
在所述控制面和所述用户面均有L2TP隧道协商能力,在所述控制面确定使用所述控制面的L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
可选地,所述第三协商子模块,还设置为
接收所述控制面发送的关联建立请求消息,其中,所述关联建立请求消息中携带有所述控制面的L2TP隧道协商能力;
向所述控制面反馈的关联建立响应消息,其中,所述关联建立响应消息中携带有所述用户面的L2TP隧道协商能力。
可选地,
所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,所述第三协商子模块,还设置为
接收所述控制面发送的用于建立转发关系的PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息中携带有所述LAC和所述LNS的隧道ID和会话ID,所述PFCP会话建立请求消息是所述控制面接收前向网元的会话建立请求消息,通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
向所述控制面返回用于通知转发关系建立完成的PFCP会话建立响应 消息,其中,所述PFCP会话建立响应消息用于指示所述控制面向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
可选地,所述装置还包括:
发送子模块,设置为在所述控制面通过所述LAC与所述LNS完成L2TP隧道建立的协商的过程中,通过Sxb/N4接口将所述控制面发送的L2TP VPN建立请求消息转发给所述LNS;
转发子模块,设置为通过所述Sxb/N4接口将所述LNS发送的L2TP VPN建立响应消息转发给所述控制面。
可选地,所述装置还包括:
第三删除模块,设置为通过所述控制面删除已建立的所述L2TP隧道;或者
第四删除模块,设置为删除已建立的所述L2TP隧道。
可选地,所述第三删除模块,还设置为
通过Sxb/N4接口将所述控制面发的点到点协议PPP终结请求消息转发给所述LNS,其中,所述PPP终结请求消息是所述控制面在接收到前向网元发送的会话删除消息之后发送的,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
通过所述Sxb/N4接口将所述LNS返回的PPP终结响应消息转发给所述控制面;
通过所述Sxb/N4接口将所述控制面发送的会话拆链通知CDN消息转发给所述LNS;
通过所述Sxb/N4接口将所述LNS返回的0长度消息体ZLB消息转发给所述控制面;
接收所述控制面发送的PFCP会话删除请求消息;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,所述第四删除模块,还设置为
通过Sxb/N4接口将所述LNS发送的点到点协议PPP终结请求消息转发给所述控制面,所述PPP终结请求消息用于指示所述控制面释放PPP会话;
通过所述Sxb/N4接口将所述控制面返回的PPP终结响应消息转发给所述LNS;
通过所述Sxb/N4接口将所述LNS发送的会话拆链通知CDN消息转发给所述控制面;
通过所述Sxb/N4接口将所述控制面返回的0长度消息体ZLB消息转发给所述LNS;
接收所述控制面发送的PFCP会话删除请求消息;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理。
可选地,所述第四协商建立模块,还设置为包括:
第四协商子模块,设置为完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
第四建立子模块,设置为完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
可选地,所述第四协商子模块,还设置为
在仅所述用户面有L2TP隧道协商能力,或所述控制面和所述用户面均有L2TP隧道协商能力,所述控制面确定使用所述用户面的L2TP隧道协商能力的情况下,完成所述控制面与所述用户面之间L2TP隧道协商能 力的协商。
可选地,所述第四协商子模块,还设置为
向所述控制面发送PFCP关联建立请求消息,其中,所述关联建立请求消息中携带有所述用户面的L2TP隧道协商能力;
接收所述控制面返回的PFCP关联建立响应消息,其中,所述关联建立响应消息中携带有所述控制面的L2TP隧道协商能力。
可选地,
所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
可选地,所述第四建立子模块,还设置为
接收所述控制面发送的PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息是所述控制面在接收到前向网元发送的会话建立请求消息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述PFCP会话建立请求消息通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
在转发关系建立完成之后向所述控制面返回PFCP会话建立响应消息,其中,所述PFCP会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息,所述PFCP会话建立响应消息用于指示所述控制面向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
可选地,
所述PFCP会话建立请求消息携带以下信息至少之一:PCO中的用户 名、PCO中的PAP密码、PCO中的CHAP挑战Challenge、PCO中的CHAP挑战响应challenge response。
可选地,所述装置还包括:
第五删除模块,设置为通过所述控制面删除已建立的所述L2TP隧道;
第六删除模块,设置为删除已建立的所述L2TP隧道。
可选地,所述第五删除模块,还设置为
接收所述控制面发送的PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息是所述控制面在接收到前向网元发送的会话删除请求消息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
根据所述PFCP会话删除请求消息向所述LNS发送PPP终结请求消息;
接收所述LNS在释放PPP会话之后返回的PPP终结响应消息;
向所述LNS发送会话拆链通知CDN消息;
接收所述LNS返回的0长度消息体ZLB响应消息;
在删除当前会话的转发关系之后向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
可选地,所述第六删除模块,还设置为
从所述LNS接收用于释放PPP会话的PPP终止请求消息;
在释放PPP会话之后向所述LNS返回终止响应消息;
接收所述LNS发送的会话拆链通知CDN消息;
向所述LNS返回0长度消息体ZLB消息;
向所述控制面发送PFCP会话报告请求消息,其中,所述PFCP会话 报告请求消息中携带有LNS请求拆链或断链建立的L2TP隧道的指示信息;
接收所述控制面返回的PFCP会话报告响应消息;
向所述前向网元发送会话删除请求消息;
接收所述控制面发送的PFCP会话删除请求消息;
根据所述PFCP会话删除请求消息删除当前会话的转发关系;
向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
需要说明的是,上述各个模块是可以通过软件或硬件来实现的,对于后者,可以通过以下方式实现,但不限于此:上述模块均位于同一处理器中;或者,上述各个模块以任意组合的形式分别位于不同的处理器中。
实施例5
本发明的实施例还提供了一种存储介质,该存储介质中存储有计算机程序,其中,该计算机程序被设置为运行时执行上述任一项方法实施例中的步骤。
可选地,在本实施例中,上述存储介质可以被设置为存储用于执行以下步骤的计算机程序:
S11,通过控制面完成所述控制面与用户面之间L2TP隧道的协商建立;
S12,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。
可选地,在本实施例中,上述存储介质还可以被设置为存储用于执行以下步骤的计算机程序:
S21,通过控制面完成所述控制面与用户面之间L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U 或UPF;或者,
S22,完成所述控制面与所述用户面之间L2TP隧道的协商建立。
可选地,在本实施例中,上述存储介质可以包括但不限于:U盘、只读存储器(Read-ONly Memory,简称为ROM)、随机存取存储器(RaNdom Access Memory,简称为RAM)、移动硬盘、磁碟或者光盘等各种可以存储计算机程序的介质。
实施例6
本发明的实施例还提供了一种电子装置,如图19所示,包括存储器1902和处理器1904,该存储器1902中存储有计算机程序,该处理器1904被设置为运行计算机程序以执行上述任一项方法实施例中的步骤。
可选地,上述电子装置还可以包括传输设备1906以及输入输出设备,其中,该传输设备1906和上述处理器1904连接,该输入输出设备和上述处理器连接。
可选地,在本实施例中,上述处理器1904可以被设置为通过计算机程序执行以下步骤:
S11,通过控制面完成所述控制面与用户面之间L2TP隧道的协商建立;
S12,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。
作为一种示例,如图19所示,上述存储器1902中可以但不限于包括上述媒体资源的获取装置中的第一协商建立模块172、第二协商建立模块174。此外,还可以包括但不限于上述隧道协商建立装置中的其他模块单元,本示例中不再赘述。
此外,上述电子装置还包括:显示器1908,用于显示上述媒体资源;和连接总线1910,用于连接上述电子装置中的各个模块部件。
本发明的实施例还提供了一种电子装置,如图20所示,包括存储器1902和处理器1904,该存储器1902中存储有计算机程序,该处理器1904被设置为运行计算机程序以执行上述任一项方法实施例中的步骤。
可选地,上述电子装置还可以包括传输设备1906以及输入输出设备,其中,该传输设备1906和上述处理器1904连接,该输入输出设备和上述处理器连接。
可选地,在本实施例中,上述处理器1904还可以被设置为通过计算机程序执行以下步骤:
S21,通过控制面完成所述控制面与用户面之间L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
S22,完成所述控制面与所述用户面之间L2TP隧道的协商建立。
作为一种示例,如图20所示,上述存储器1902中可以但不限于包括上述媒体资源的获取装置中的第三协商建立模块182、第四协商建立模块184。此外,还可以包括但不限于上述隧道协商建立装置中的其他模块单元,本示例中不再赘述。
此外,上述电子装置还包括:显示器1908,用于显示上述媒体资源;和连接总线1910,用于连接上述电子装置中的各个模块部件。
可选地,本实施例中的具体示例可以参考上述实施例及可选实施方式中所描述的示例,本实施例在此不再赘述。
显然,本领域的技术人员应该明白,上述的本发明实施例的各模块或各步骤可以用通用的计算装置来实现,它们可以集中在单个的计算装置上,或者分布在多个计算装置所组成的网络上,可选地,它们可以用计算装置可执行的程序代码来实现,从而,可以将它们存储在存储装置中由计算装置来执行,并且在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤,或者将它们分别制作成各个集成电路模块,或者将它们中的多 个模块或步骤制作成单个集成电路模块来实现。这样,本发明实施例不限制于任何特定的硬件和软件结合。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
工业实用性
本发明实施例通过C面网元与U面网元之间协商建立L2TP隧道,可以解决相关技术中不同厂家C面网元(PGW-C或SMF)和U面网元(PGW-U或UPF)混合部署无法应用L2TP VPN的问题,达到了不同厂家C面网元和U面网元对接L2TP部署不受影响的效果,节省了运营商互联互通的成本,提高了设备商设备竞争力。

Claims (40)

  1. 一种隧道协商建立方法,包括:
    通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:分组数据网络网关控制面PGW-C或会话管理功能SMF,所述用户面包括分组数据网络网关用户面PGW-U或用户面功能UPF;或者,
    通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立。
  2. 根据权利要求1所述的方法,其中,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道的协商建立包括:
    通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
    通过所述控制面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
  3. 根据权利要求2所述的方法,其中,通过所述控制面完成所述控制面与用户面之间L2TP隧道协商能力的协商包括:
    在仅所述控制面有L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
    在所述控制面和所述用户面均有L2TP隧道协商能力的情况下,确定使用所述控制面的L2TP隧道协商能力,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
  4. 根据权利要求3所述的方法,其中,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
    向所述用户面发送关联建立请求消息,其中,所述关联建立请求消息中携带有所述控制面的L2TP隧道协商能力;
    接收所述用户面反馈的关联建立响应消息,其中,所述关联建立响应消息中携带有所述用户面的L2TP隧道协商能力。
  5. 根据权利要求4所述的方法,其中,
    所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
    所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
  6. 根据权利要求2所述的方法,其中,通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立包括:
    接收前向网元的会话建立请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    根据所述会话建立请求消息选择所述用户面;
    通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
    向所述用户面发送用于建立转发关系的报文转发控制协议PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息中携带有所述LAC和所述LNS的隧道ID和会话ID;
    接收所述用户面返回的用于通知转发关系建立完成的PFCP会话建立响应消息;
    向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
  7. 根据权利要求6所述的方法,其中,通过所述LAC与所述LNS完成L2TP隧道建立的协商包括:
    通过所述用户面的Sxb/N4接口向所述LNS发送L2TP VPN建立请求消息;
    通过所述用户面的Sxb/N4接口接收所述LNS发送的L2TP VPN建立响应消息。
  8. 根据权利要求2所述的方法,其中,在通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
    删除已建立的所述L2TP隧道。
  9. 根据权利要求8所述的方法,其中,所述删除已建立的所述L2TP隧道包括:
    接收前向网元发送的会话删除请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    通过所述用户面的Sxb/N4接口向所述LNS发送点到点协议PPP终结请求消息;
    通过所述用户面的Sxb/N4接口接收所述LNS返回的PPP终结响应消息;
    通过所述用户面的Sxb/N4接口向所述LNS发送会话拆链通知CDN消息;
    通过所述用户面的Sxb/N4接口接收所述LNS返回的0长度消息 体ZLB消息;
    向所述用户面发送报文转发控制协议PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于指示所述用户面删除当前会话的转发关系;
    接收所述用户面在删除当前会话的转发关系之后返回的PFCP会话删除响应消息;
    根据所述PFCP会话删除响应消息终止业务处理,并向所述前向网元返回会话删除响应消息。
  10. 根据权利要求8所述的方法,其中,所述删除已建立的所述L2TP隧道包括:
    通过所述用户面的Sxb/N4接口接收所述LNS发送的点到点协议PPP终结请求消息;
    根据所述PPP终结请求消息释放PPP会话,并通过所述用户面的Sxb/N4接口向所述LNS返回PPP终结响应消息;
    通过所述用户面的Sxb/N4接口接收所述LNS发送的会话拆链通知CDN消息;
    通过所述用户面的Sxb/N4接口向所述LNS返回0长度消息体ZLB消息;
    向前向网元发送会话删除通知消息,并向所述用户面发送报文转发控制协议PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于请求所述用户面删除当前会话的转发关系,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    接收所述用户面返回的PFCP会话删除响应消息;
    根据所述PFCP会话删除响应消息终止业务处理;
    接收所述前向网元在删除会话之后返回的会话删除响应消息。
  11. 根据权利要求1所述的方法,其中,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道的协商建立包括:
    通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
    通过所述用户面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
  12. 根据权利要求11所述的方法,其中,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
    在仅所述用户面有L2TP隧道协商能力,或所述控制面和所述用户面均有L2TP隧道协商能力的情况下,确定使用所述用户面的L2TP隧道协商能力,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
  13. 根据权利要求12所述的方法,其中,通过所述用户面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
    接收所述用户面发送的PFCP关联建立请求消息,其中,所述关联建立请求消息中携带有所述用户面的L2TP隧道协商能力;
    向所述用户面返回报文转发控制协议PFCP关联建立响应消息,其中,所述关联建立响应消息中携带有所述控制面的L2TP隧道协商能力。
  14. 根据权利要求13所述的方法,其中,
    所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
    所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
  15. 根据权利要求11所述的方法,其中,通过所述用户面完成所述用户面与所述LNS之间L2TP隧道的建立包括:
    接收前向网元发送的会话建立请求消息,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    根据所述会话建立请求消息选择所述用户面;
    向所述用户面发送报文转发控制协议PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息用于指示所述用户面通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
    接收所述用户面在转发关系建立完成之后返回的PFCP会话建立响应消息,其中,所述PFCP会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息;
    向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
  16. 根据权利要求15所述的方法,其中,
    所述PFCP会话建立请求消息携带以下信息至少之一:协议配置选项PCO中的用户名、PCO中的PAP密码、PCO中的挑战握手认证协议CHAP挑战Challenge,PCO中的CHAP挑战响应challenge  response。
  17. 根据权利要求11所述的方法,其中,在通过所述用户面完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
    删除已建立的所述L2TP隧道。
  18. 根据权利要求17所述的方法,其中,所述删除已建立的所述L2TP隧道包括:
    接收所述前向网元发送的会话删除消息;
    向所述用户面发送PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息用于指示所述用户面删除当前会话的转发关系;
    接收所述用户面在删除当前会话的转发关系之后返回的PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息是所述用户面在根据所述PFCP会话删除请求消息向所述LNS发送PPP终结请求消息,接收所述LNS在释放PPP会话之后返回的PPP终结响应消息,向所述LNS发送会话拆链通知CDN消息,接收所述LNS返回的0长度消息体ZLB响应消息之后返回的;
    根据所述PFCP会话删除响应消息终止业务处理,并向所述前向网元返回会话删除响应消息。
  19. 根据权利要求17所述的方法,其中,所述删除已建立的所述L2TP隧道包括:
    接收所述用户面发送的PFCP会话报告请求消息,其中,所述PFCP会话报告请求消息中携带有LNS请求拆链或断链已建立的L2TP隧道的指示信息,所述PFCP会话报告请求消息是所述用户面 从LNS接收到用于释放PPP会话的PPP终止请求消息,释放PPP会话之后向所述LNS返回终止响应消息,接收所述LNS发送的会话拆链通知CDN消息,向所述LNS返回0长度消息体ZLB消息之后发送的;
    向所述用户面返回PFCP会话报告响应消息;
    向所述前向网元发送会话删除请求消息,同时向所述用户面发送用于指示所述用户面删除当前会话的转发关系的PFCP会话删除请求消息;
    接收所述用户面返回的PFCP会话删除响应消息;
    根据所述PFCP会话删除响应消息终止业务处理;
    向所述前向网元返回会话删除响应消息。
  20. 一种隧道协商建立方法,包括:
    通过控制面完成所述控制面与用户面之间层二隧道协议L2TP隧道的协商建立,其中,所述控制面包括:PGW-C或SMF,所述用户面包括PGW-U或UPF;或者,
    完成所述控制面与所述用户面之间L2TP隧道的协商建立。
  21. 根据权利要求20所述的方法,其中,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道的协商建立包括:
    通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
    通过所述控制面完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
  22. 根据权利要求21所述的方法,其中,通过所述控制面完成所述控制面与用户面之间L2TP隧道协商能力的协商包括:
    在仅所述控制面有L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
    在所述控制面和所述用户面均有L2TP隧道协商能力,在所述控制面确定使用所述控制面的L2TP隧道协商能力的情况下,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
  23. 根据权利要求22所述的方法,其中,通过所述控制面完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
    接收所述控制面发送的关联建立请求消息,其中,所述关联建立请求消息中携带有所述控制面的L2TP隧道协商能力;
    向所述控制面反馈的关联建立响应消息,其中,所述关联建立响应消息中携带有所述用户面的L2TP隧道协商能力。
  24. 根据权利要求23所述的方法,其中,
    所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
    所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
  25. 根据权利要求21所述的方法,其中,通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立包括:
    接收所述控制面发送的用于建立转发关系的PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息中携带有所述LAC和所述LNS的隧道ID和会话ID,所述PFCP会话建立请求消息是所述控 制面接收前向网元的会话建立请求消息,通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    向所述控制面返回用于通知转发关系建立完成的PFCP会话建立响应消息,其中,所述PFCP会话建立响应消息用于指示所述控制面向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
  26. 根据权利要求25所述的方法,其中,所述方法还包括:
    在所述控制面通过所述LAC与所述LNS完成L2TP隧道建立的协商的过程中,通过Sxb/N4接口将所述控制面发送的L2TP VPN建立请求消息转发给所述LNS;
    通过所述Sxb/N4接口将所述LNS发送的L2TP VPN建立响应消息转发给所述控制面。
  27. 根据权利要求21所述的方法,其中,在通过所述控制面完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
    通过所述控制面删除已建立的所述L2TP隧道;或者
    删除已建立的所述L2TP隧道。
  28. 根据权利要求27所述的方法,其中,所述通过所述控制面删除已建立的所述L2TP隧道包括:
    通过Sxb/N4接口将所述控制面发的点到点协议PPP终结请求消 息转发给所述LNS,其中,所述PPP终结请求消息是所述控制面在接收到前向网元发送的会话删除消息之后发送的,其中,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    通过所述Sxb/N4接口将所述LNS返回的PPP终结响应消息转发给所述控制面;
    通过所述Sxb/N4接口将所述控制面发送的会话拆链通知CDN消息转发给所述LNS;
    通过所述Sxb/N4接口将所述LNS返回的0长度消息体ZLB消息转发给所述控制面;
    接收所述控制面发送的PFCP会话删除请求消息;
    根据所述PFCP会话删除请求消息删除当前会话的转发关系;
    向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
  29. 根据权利要求27所述的方法,其中,所述删除已建立的所述L2TP隧道包括:
    通过Sxb/N4接口将所述LNS发送的点到点协议PPP终结请求消息转发给所述控制面,所述PPP终结请求消息用于指示所述控制面释放PPP会话;
    通过所述Sxb/N4接口将所述控制面返回的PPP终结响应消息转发给所述LNS;
    通过所述Sxb/N4接口将所述LNS发送的会话拆链通知CDN消息转发给所述控制面;
    通过所述Sxb/N4接口将所述控制面返回的0长度消息体ZLB消息转发给所述LNS;
    接收所述控制面发送的PFCP会话删除请求消息;
    根据所述PFCP会话删除请求消息删除当前会话的转发关系;
    向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理。
  30. 根据权利要求20所述的方法,其中,所述完成所述控制面与所述用户面之间L2TP隧道的协商建立包括:
    完成所述控制面与所述用户面之间L2TP隧道协商能力的协商;
    完成所述用户面与L2TP网络服务器LNS之间L2TP隧道的建立。
  31. 根据权利要求30所述的方法,其中,所述完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
    在仅所述用户面有L2TP隧道协商能力,或所述控制面和所述用户面均有L2TP隧道协商能力,所述控制面确定使用所述用户面的L2TP隧道协商能力的情况下,完成所述控制面与所述用户面之间L2TP隧道协商能力的协商。
  32. 根据权利要求31所述的方法,其中,所述完成所述控制面与所述用户面之间L2TP隧道协商能力的协商包括:
    向所述控制面发送PFCP关联建立请求消息,其中,所述关联建立请求消息中携带有所述用户面的L2TP隧道协商能力;
    接收所述控制面返回的PFCP关联建立响应消息,其中,所述关联建立响应消息中携带有所述控制面的L2TP隧道协商能力。
  33. 根据权利要求32所述的方法,其中,
    所述关联建立请求消息通过携带的功能特性参数字段指示所述控制面的L2TP隧道协商能力;
    所述关联建立响应消息通过携带的功能特性参数字段指示所述用户面的L2TP隧道协商能力。
  34. 根据权利要求30所述的方法,其中,所述完成所述用户面与所述LNS之间L2TP隧道的建立包括:
    接收所述控制面发送的PFCP会话建立请求消息,其中,所述PFCP会话建立请求消息是所述控制面在接收到前向网元发送的会话建立请求消息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    根据所述PFCP会话建立请求消息通过L2TP访问集中器LAC与所述LNS完成L2TP隧道建立的协商,并保存所述LAC和所述LNS的隧道ID、会话ID,以及所述LNS分配的IP地址和域名服务器DNS地址信息;
    在转发关系建立完成之后向所述控制面返回PFCP会话建立响应消息,其中,所述PFCP会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息,所述PFCP会话建立响应消息用于指示所述控制面向所述前向网元返回会话建立响应消息,其中,所述会话建立响应消息中携带有所述LNS分配的IP地址和DNS地址信息。
  35. 根据权利要求34所述的方法,其中,
    所述PFCP会话建立请求消息携带以下信息至少之一:PCO中的用户名、PCO中的PAP密码、PCO中的CHAP挑战Challenge、PCO中的CHAP挑战响应challenge response。
  36. 根据权利要求30所述的方法,其中,在完成所述用户面与所述LNS之间L2TP隧道的建立之后,所述方法还包括:
    通过所述控制面删除已建立的所述L2TP隧道;
    删除已建立的所述L2TP隧道。
  37. 根据权利要求36所述的方法,其中,所述通过所述控制面删除已建立的所述L2TP隧道包括:
    接收所述控制面发送的PFCP会话删除请求消息,其中,所述PFCP会话删除请求消息是所述控制面在接收到前向网元发送的会话删除请求消息之后发送的,所述前向网元包括服务网关控制面SGW-C或接入和移动性功能AMF;
    根据所述PFCP会话删除请求消息删除当前会话的转发关系;
    根据所述PFCP会话删除请求消息向所述LNS发送PPP终结请求消息;
    接收所述LNS在释放PPP会话之后返回的PPP终结响应消息;
    向所述LNS发送会话拆链通知CDN消息;
    接收所述LNS返回的0长度消息体ZLB响应消息;
    在删除当前会话的转发关系之后向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
  38. 根据权利要求36所述的方法,其中,所述删除已建立的所述L2TP隧道包括:
    从所述LNS接收用于释放PPP会话的PPP终止请求消息;
    在释放PPP会话之后向所述LNS返回终止响应消息;
    接收所述LNS发送的会话拆链通知CDN消息;
    向所述LNS返回0长度消息体ZLB消息;
    向所述控制面发送PFCP会话报告请求消息,其中,所述PFCP会话报告请求消息中携带有LNS请求拆链或断链建立的L2TP隧道的指示信息;
    接收所述控制面返回的PFCP会话报告响应消息;
    向所述前向网元发送会话删除请求消息;
    接收所述控制面发送的PFCP会话删除请求消息;
    根据所述PFCP会话删除请求消息删除当前会话的转发关系;
    向所述控制面返回PFCP会话删除响应消息,其中,所述PFCP会话删除响应消息用于指示所述控制面终止业务处理,并向所述前向网元返回会话删除响应消息。
  39. 一种计算机可读的存储介质,所述存储介质中存储有计算机程序,其中,所述计算机程序被设置为运行时执行所述权利要求1至19、20至38任一项中所述的方法。
  40. 一种电子装置,包括存储器和处理器,所述存储器中存储有计算机程序,所述处理器被设置为运行所述计算机程序以执行所述权利要求1至19、20至38任一项中所述的方法。
PCT/CN2019/106122 2018-11-09 2019-09-17 一种隧道协商建立方法及装置 WO2020093790A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201811342188.2A CN111182657B (zh) 2018-11-09 2018-11-09 一种隧道协商建立方法及装置
CN201811342188.2 2018-11-09

Publications (1)

Publication Number Publication Date
WO2020093790A1 true WO2020093790A1 (zh) 2020-05-14

Family

ID=70611671

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/106122 WO2020093790A1 (zh) 2018-11-09 2019-09-17 一种隧道协商建立方法及装置

Country Status (2)

Country Link
CN (1) CN111182657B (zh)
WO (1) WO2020093790A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115426723A (zh) * 2022-10-28 2022-12-02 新华三技术有限公司 Vpn隧道建立方法、装置及电子设备
CN117042069A (zh) * 2023-09-28 2023-11-10 新华三技术有限公司 应用于5g核心网中的路径切换方法、装置及电子设备
US12010610B2 (en) 2022-10-07 2024-06-11 Ofinno, Llc Support for tunneling

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114039947B (zh) * 2020-07-21 2024-03-15 中国电信股份有限公司 终端地址分配方法、upf、系统以及存储介质
CN114615107A (zh) * 2020-11-23 2022-06-10 华为技术有限公司 建立通信的方法及装置
CN114650197B (zh) * 2022-03-31 2023-05-23 联想(北京)有限公司 通信方法、装置及用户面网元和存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103718640A (zh) * 2012-08-02 2014-04-09 华为技术有限公司 一种控制和转发解耦下协议处理方法及控制面设备、转发面设备
WO2014117376A1 (zh) * 2013-01-31 2014-08-07 华为技术有限公司 可定制的移动宽带网络系统和定制移动宽带网络的方法
WO2016198586A1 (en) * 2015-06-10 2016-12-15 Nokia Solutions And Networks Management International Gmbh Sdn security
CN108574969A (zh) * 2017-03-08 2018-09-25 华为技术有限公司 多接入场景中的连接处理方法和装置

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102111326B (zh) * 2009-12-25 2014-06-25 杭州华三通信技术有限公司 在二层隧道协议虚拟专用网实现移动的方法、系统和装置
CN103636283B (zh) * 2012-06-29 2018-06-05 华为技术有限公司 网关系统、设备和通信方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103718640A (zh) * 2012-08-02 2014-04-09 华为技术有限公司 一种控制和转发解耦下协议处理方法及控制面设备、转发面设备
WO2014117376A1 (zh) * 2013-01-31 2014-08-07 华为技术有限公司 可定制的移动宽带网络系统和定制移动宽带网络的方法
WO2016198586A1 (en) * 2015-06-10 2016-12-15 Nokia Solutions And Networks Management International Gmbh Sdn security
CN108574969A (zh) * 2017-03-08 2018-09-25 华为技术有限公司 多接入场景中的连接处理方法和装置

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12010610B2 (en) 2022-10-07 2024-06-11 Ofinno, Llc Support for tunneling
CN115426723A (zh) * 2022-10-28 2022-12-02 新华三技术有限公司 Vpn隧道建立方法、装置及电子设备
CN117042069A (zh) * 2023-09-28 2023-11-10 新华三技术有限公司 应用于5g核心网中的路径切换方法、装置及电子设备
CN117042069B (zh) * 2023-09-28 2024-02-27 新华三技术有限公司 应用于5g核心网中的路径切换方法、装置及电子设备

Also Published As

Publication number Publication date
CN111182657B (zh) 2023-09-22
CN111182657A (zh) 2020-05-19

Similar Documents

Publication Publication Date Title
WO2020093790A1 (zh) 一种隧道协商建立方法及装置
CN112584371B (zh) 漫游信令消息发送的方法、相关设备和通信系统
JP4230106B2 (ja) Gprs加入者による多数のインタネットサービスプロバイダの選択
EP3304980B1 (en) Multiple pdn connections over untrusted wlan access
US8091121B2 (en) Method and apparatus for supporting different authentication credentials
US9853937B1 (en) Internal packet steering within a wireless access gateway
EP2443885B1 (en) Methods and nodes for setting up multiple packet data connections of a user equipment toward an access point
JP6140372B2 (ja) 信頼できるワイヤレスローカルエリアネットワーク(wlan)アクセスのシナリオ
CN105393630B (zh) 建立网络连接的方法、网关及终端
WO2013107136A1 (zh) 终端接入认证的方法及用户端设备
WO2013082984A1 (zh) 一种附着到e-utran的方法及移动性管理实体
KR20020071874A (ko) 무선 원격통신 시스템내에서 인증을 하기 위한 방법 및 장치
JP2004519179A (ja) 無線アクセスネットワーク間のハンドオーバーをサポートする方法
WO2014067420A1 (zh) 分组数据网络类型的管理方法、装置及系统
CN102695236B (zh) 一种数据路由方法及系统
JP2020205520A (ja) Ue及びsmf
CN103200628B (zh) 一种通过非3gpp接入核心网的方法和系统
CN102076113B (zh) 一种终端从网络侧去附着的优化方法和系统及接入网关
EP3883298B1 (en) Method and apparatus for system interoperation
CN101778373B (zh) 一种选择分组数据网络的方法、装置与系统
US20060002329A1 (en) Method and system for providing backward compatibility between protocol for carrying authentication for network access (PANA) and point-to-point protocol (PPP) in a packet data network
CN106998552A (zh) 路由控制方法、装置及系统
EP2312893A1 (en) IP flow removal method for untrusted non-3GPP access points
EP4178158A1 (en) Inter-plmn communication
WO2012106984A1 (zh) 一种通过可信任的固网接入移动核心网络的方法和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19881249

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 27.09.2021)

122 Ep: pct application non-entry in european phase

Ref document number: 19881249

Country of ref document: EP

Kind code of ref document: A1