WO2022268166A1 - 通信系统、方法、装置、第一设备及存储介质 - Google Patents

通信系统、方法、装置、第一设备及存储介质 Download PDF

Info

Publication number
WO2022268166A1
WO2022268166A1 PCT/CN2022/100809 CN2022100809W WO2022268166A1 WO 2022268166 A1 WO2022268166 A1 WO 2022268166A1 CN 2022100809 W CN2022100809 W CN 2022100809W WO 2022268166 A1 WO2022268166 A1 WO 2022268166A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
access
information
policy
party
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2022/100809
Other languages
English (en)
French (fr)
Inventor
唐小勇
尚宇翔
韩延涛
朱磊
罗柯
游正朋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
China Mobile Chengdu ICT Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
China Mobile Chengdu ICT Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd, China Mobile Chengdu ICT Co Ltd filed Critical China Mobile Communications Group Co Ltd
Publication of WO2022268166A1 publication Critical patent/WO2022268166A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • H04W28/08Load balancing or load distribution
    • H04W28/09Management thereof
    • H04W28/0925Management thereof using policies
    • H04W28/0933Management thereof using policies based on load-splitting ratios
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • H04W28/10Flow control between communication endpoints
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • H04W28/08Load balancing or load distribution
    • H04W28/084Load balancing or load distribution among network function virtualisation [NFV] entities; among edge computing entities, e.g. multi-access edge computing

Definitions

  • the present application relates to the communication field, and in particular to a communication system, method, device, first device and storage medium.
  • the fifth-generation mobile communication technology has many advantages such as large bandwidth, low latency, high reliability, high connection, ubiquitous network, etc., thereby promoting the rapid development and change of vertical industries, such as smart medical, The rise of smart education and smart agriculture.
  • multi-access edge computing (MEC) technology is a general information technology (IT) platform with wireless network information application programming interface (API) interaction capabilities, as well as computing, storage, and analysis functions; relying on MEC
  • IT information technology
  • API application programming interface
  • the technology can pull traditional external applications into the operator's interior, provide users with localized application services, and be closer to users, thereby improving user experience and giving full play to the value of edge networks.
  • the combination of 5G and MEC technology can introduce different technology combinations for different industry demand scenarios, such as quality of service (QoS), end-to-end network slicing, network capability exposure, edge cloud, etc., so as to provide customized solutions.
  • QoS quality of service
  • end-to-end network slicing network capability exposure
  • edge cloud etc.
  • the solutions for combining 5G and MEC technologies mainly include:
  • the user plane function In order to enable low-latency, high-bandwidth, and high-reliability edge applications in vertical industries, the user plane function (UPF) is lowered to the industrial customer campus, close to the MEC edge server (also called the MEC platform (MEP)), through the UPF
  • MEC edge server also called the MEC platform (MEP)
  • the local distribution technology that is, the uplink filter/IPv6 branch point (UL-CL/IPv6 BP, Uplink Classifier/IPv6 Branching Point) forwards the data to the MEP;
  • the application function (AF, Application Function) in the core network is lowered to the MEP side to provide better data flow control strategies (such as coding strategies, QoS strategies, routing strategies, etc.) for applications deployed on the MEP.
  • embodiments of the present application provide a communication system, method, device, first device, and storage medium.
  • An embodiment of the present application provides a communication system, including: at least one first device, at least one second device, and at least one UPF; wherein,
  • Each first device is connected to at least one second device; each first device is connected to at least one UPF;
  • the first device is configured to allocate a corresponding second device for the service traffic of the edge network sent by the UPF, so as to offload the service traffic of the edge network to the corresponding second device, and provide secure access for applications provided by the second device control function.
  • the first device is further configured to perform access authentication on the connected second device.
  • system further includes: a third device; wherein,
  • the second device is configured to send access authentication information to the first device; receive authentication response information returned by the first device;
  • the first device is configured to receive the access authentication information sent by the second device, send the access authentication information to the third device, receive the authentication response information returned by the third device, and send the The second device returns authentication response information;
  • the third device is configured to receive the access authentication information sent by the first device, use the access authentication information to perform access authentication on the second device, and return authentication response information to the first device .
  • the access authentication information includes the characteristics of the second device.
  • the features include at least one of the following:
  • IP Internet Protocol
  • the first device is further configured to control the second device's access to the network capability.
  • the third device is further configured to send the first policy to the first device
  • the first device is further configured to receive a first policy sent by the third device, provide a security access control function for an application provided by the second device based on the first policy, and/or, based on the first policy Access to network capabilities by the second device is controlled.
  • the system further includes: at least one third-party network; wherein,
  • the third-party network is configured to provide network access for the terminal
  • the first device is further configured to select a corresponding second device for the terminal, and provide the application provided by the corresponding second device to the terminal through the third-party network.
  • the first device is further configured to perform access authentication on the third-party network.
  • system further includes: a third device; wherein,
  • the third-party network is configured to send access authentication information to the first device; and receive authentication response information returned by the first device;
  • the first device is configured to receive the access authentication information sent by the third-party network, send the access authentication information to the third device, receive the authentication response information returned by the third device, and send the The third-party network returns authentication response information;
  • the third device is configured to receive the access authentication information sent by the first device, use the access authentication information to perform access authentication on the third-party network, and return authentication response information to the first device .
  • the access authentication information includes characteristics of the third-party network.
  • the features include at least one of the following:
  • the first device is configured to perform data transmission with the third-party network based on a security mechanism after the access authentication is passed.
  • the first device is further configured to control the access capability of the third-party network.
  • the third device is further configured to send a second policy to the first device
  • the first device is further configured to receive a second policy sent by the third device, and control the access capability of the third-party network based on the second policy.
  • the second strategy includes one of the following:
  • a first access control policy is aimed at a single third-party network
  • a second access control strategy is aimed at a type of third-party network
  • a third access control policy is aimed at all third-party networks.
  • the first device is configured to send first information to the third-party network, where the first information is used to indicate the access capability of the third-party network;
  • the third-party network is configured to receive the first information sent by the first device, and use the first information to adjust its own access capability.
  • system further includes: at least one fourth device; wherein,
  • the fourth device is configured to provide network capability information for the first device.
  • the first device is further configured to perform access authentication on the fourth device.
  • system further includes: a third device; wherein,
  • the fourth device is further configured to send access authentication information to the first device; receive authentication response information returned by the first device;
  • the first device is configured to receive the access authentication information sent by the fourth device, send the access authentication information to the third device, receive the authentication response information returned by the third device, and send the The fourth device returns authentication response information;
  • the third device is configured to use the access authentication information to perform access authentication on the fourth device, and return authentication response information to the first device.
  • the first device is further configured to control the access capability of the fourth device.
  • the first device is configured to send second information to the fourth device, where the second information is used to indicate the access capability of the fourth device;
  • the fourth device is configured to receive the second information sent by the first device, and use the second information to adjust its access capability.
  • the third device is further configured to send a third policy to the first device
  • the first device is further configured to receive a third policy sent by the third device, and control the access capability of the fourth device based on the third policy.
  • the first device is configured to route and forward the service flow of the terminal through at least one other first device, so that the terminal obtains an application provided by a second device connected to at least one other first device.
  • system further includes: a third device configured to control the at least one first device.
  • the third device is further configured to authenticate the at least one first device.
  • the first device is configured to send authentication information to the third device; and receive authentication response information returned by the third device;
  • the third device is configured to receive the authentication information sent by the first device, use the authentication information to authenticate the first device, and return authentication response information to the first device.
  • the first device is further configured to monitor network traffic and/or network status; and report at least one of the following information to the third device:
  • the embodiment of the present application also provides a communication method applied to the first device, including:
  • the method also includes:
  • Access to network capabilities by the second device is controlled.
  • the access authentication for the connected second device includes:
  • the access authentication information includes the characteristics of the second device.
  • the features include at least one of the following:
  • the method also includes:
  • the method also includes:
  • a corresponding second device is selected for the terminal accessing the third-party network, and the application provided by the corresponding second device is provided to the terminal through the third-party network.
  • the method also includes:
  • the access authentication for the third-party network includes:
  • the access authentication information includes characteristics of the third-party network.
  • the features include at least one of the following:
  • data transmission is performed with the third-party network based on a security mechanism.
  • the method also includes:
  • the method also includes:
  • the second strategy includes one of the following:
  • a first access control policy is aimed at a single third-party network
  • a second access control strategy is aimed at a type of third-party network
  • a third access control policy is aimed at all third-party networks.
  • the controlling the access capability of the third-party network includes:
  • the method also includes:
  • the method also includes:
  • the controlling the access capability of the fourth device includes:
  • the method also includes:
  • the performing access authentication on the fourth device includes:
  • the method also includes:
  • the service flow of the terminal is routed and forwarded through at least one other first device, so that the terminal acquires an application provided by a second device connected to at least one other first device.
  • the method also includes:
  • the embodiment of the present application also provides a communication device, which is set on the first device, including:
  • the processing unit is configured to assign a corresponding second device to the service flow of the edge network sent by the UPF, so as to offload the service flow of the edge network to the corresponding second device, and provide a security access control function for the application provided by the second device.
  • the embodiment of the present application also provides a first device, including: a processor and a communication interface; wherein,
  • the processor is configured to assign a corresponding second device to the service flow of the edge network sent by the UPF, so as to offload the service flow of the edge network to the corresponding second device, and provide security access control for the application provided by the second device Function.
  • the embodiment of the present application also provides a first device, including: a processor and a memory configured to store a computer program that can run on the processor,
  • the processor is configured to execute the steps of any one of the above methods when running the computer program.
  • the embodiment of the present application also provides a storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of any one of the above methods are implemented.
  • the communication system includes: at least one first device, at least one second device, and at least one UPF; wherein, each first device is connected to At least one second device; each first device is connected to at least one UPF; the first device allocates the corresponding second device for the service flow of the edge network sent by the UPF, so as to divert the service flow of the edge network to the corresponding second device, and provide security access control functions for applications provided by the second device.
  • the first device realizes the service agent of the network capability opening between the UPF and the second device (such as MEP); in this way, the data security of the communication system can be guaranteed, and the network security capability of the communication system can be improved. Thereby improving user experience.
  • Figure 1 is a schematic diagram of a system structure combining 5G and MEC technology in related technologies
  • FIG. 2 is a schematic structural diagram of a communication system according to an embodiment of the present application.
  • FIG. 3 is a schematic flowchart of a communication method in an embodiment of the present application.
  • FIG. 4 is a schematic structural diagram of a system structure of 5G industry cloud-network integration in an application embodiment of the present application
  • FIG. 5 is a schematic diagram of the network capability open architecture of the 5G industry cloud-network integration of the application embodiment of the present application;
  • FIG. 6 is a schematic structural diagram of the system structure of the 5G industry cloud-network integration in the interface form of the application embodiment
  • FIG. 7 is a schematic flow diagram of an application embodiment of the present application to realize the access authentication function and access control function of the industry gateway to the third-party network;
  • FIG. 8 is a schematic flow diagram of an application embodiment of the present application to realize the access authentication function and access control function of the third-party network capabilities of the industry gateway;
  • FIG. 9 is a schematic flow diagram of an application embodiment of the present application to realize the access authentication function and access control function of an industry gateway to a MEP;
  • FIG. 10 is a schematic flow diagram of implementing the MEP-oriented network capability exposure function and the self-service network security management and control function in the application embodiment of the present application;
  • FIG. 11 is a schematic structural diagram of a communication device according to an embodiment of the present application.
  • Fig. 12 is a schematic structural diagram of the first device according to the embodiment of the present application.
  • UPF and MEP are logically separated in function, but they can be deployed in two ways, namely: merged deployment and separate deployment; among them, merged deployment refers to deploying UPF and MEP in the same computer room or even on the same physical device ; Separate deployment refers to deploying UPF and MEP in different equipment rooms.
  • the combined deployment method is not suitable for vertical industries (such as smart medical care, smart education, smart agriculture, etc.), because: if UPF and MEP are combined and deployed in the operator's computer room, it violates the requirements of industry customers for their application.
  • UPF and MEP should be deployed separately. Specifically, UPF can be deployed in operator computer rooms, and MEP can be deployed in industry customer campus computer rooms. However, in the scenario where UPF and MEP are deployed separately, the data security between UPF and MEP cannot be guaranteed, and there are security risks.
  • the architecture shown in Figure 1 does not involve access and data transmission of non-5G networks.
  • related technologies do not provide access solutions for non-5G networks when 5G and MEC technologies are combined.
  • 5G it also includes fourth-generation mobile communication technology (4G), WiFi, Bluetooth (Bluetooth), Zigbee (Zigbee), narrowband Internet of Things (NB-IoT), Wireline, etc.
  • Terminal data connected to these non-5G networks may not be transmitted to the MEP through the 5G network, making it impossible for the MEP to perform access control, traffic control, and security monitoring on terminal data To ensure the network and data security of MEP, there are security risks.
  • the network exposure function of the MEP is realized by connecting the AF on the MEP with the network exposure function (NEF, Network Exposure Function) of the 5G core network (5GC) (English can be expressed as Service Capability Exposure Function, abbreviated as SCEF).
  • NEF Network Exposure Function
  • 5GC 5G core network
  • SCEF Service Capability Exposure Function
  • MEP can only obtain network capabilities from 5GC, and the network capabilities that 5GC can provide cannot fully meet and accurately cover the business needs of vertical industries, for example, it cannot provide location information for non-5G network access terminals.
  • MEP network capabilities can be obtained from various data sources, including 5GC, radio access network (RAN), and third-party systems, but related technologies lack solutions for unified certification, unified supervision, and unified settlement of network capabilities.
  • the data forwarding from the terminal to the local MEP relies on the UL-CL/IPv6 BP technology of UPF, which implements local distribution based on the IP quintuple or prefix of the message.
  • UPF UL-CL/IPv6 BP technology
  • UPF only supports a protocol data unit (PDU, Protocol Data Unit) session from a terminal to a data network (DN, Data Network), and does not support a connection from a DN to a DN.
  • PDU Protocol Data Unit
  • DN Data Network
  • UPF only supports the data connection between terminals and MEPs, and does not support the interconnection between MEPs.
  • a first device (may be referred to as a gateway) is set, and through the first device, a service proxy for network capability opening between the UPF and the second device (such as MEP) is realized; thus , which can guarantee the data security of the communication system, improve the network security capability of the communication system, and thereby improve the user experience.
  • a service proxy for network capability opening between the UPF and the second device (such as MEP) is realized; thus , which can guarantee the data security of the communication system, improve the network security capability of the communication system, and thereby improve the user experience.
  • the embodiment of the present application provides a communication system, as shown in Figure 2, the system includes: at least one first device 201, at least one second device 202, at least one UPF 203; wherein,
  • Each first device 201 is connected to at least one second device 202; each first device 201 is connected to at least one UPF 203;
  • the first device 201 is configured to allocate the corresponding second device 202 for the service traffic of the edge network sent by the UPF 203, so as to offload the service traffic of the edge network to the corresponding second device 202, and provide the second device 202 with
  • the application provides security access control functions.
  • the first device 201 is set between the UPF 203 and the second device 202, and the first device 201 may be called a gateway or an industry gateway.
  • the name of a device 201 is not limited, as long as the function of the first device 201 can be realized.
  • the second device 202 may be a device in the MEC network, such as a MEP, that is to say, the second device 202 may be called an MEP or an MEC server.
  • the second device 202 The name of the device is not limited, as long as the function of the second device 202 can be realized.
  • the applications provided by the second device 202 may be understood as application services or application programs.
  • the first device 201 allocates the service traffic of the edge network sent by the UPF 203 to the corresponding second device 202, which is the same as the above-mentioned UPF-dependent UL-CL/IPv6 Compared with the BP technology, it can avoid the exposure of the IP address information of the second device 202 on the public network caused by using the UL-CL/IPv6 BP technology for local distribution, thereby improving the network security capability of the communication system; Compared with the solution of setting a dedicated DNN for the MEP, there is no need for a large number of DNN configurations on the core network; moreover, for the scenario where a terminal accesses multiple MEPs, the user does not need to continuously switch the DNN on the terminal, thereby improving user experience.
  • the first device 201 needs to perform access authentication on the second device 202 to determine the identity of the second device 202 .
  • the first device 201 may also be configured as:
  • the second device 202 can actively or passively trigger the access authentication process, and the access authentication process can be implemented by using Remote Authentication Dial In User Service (RADIUS).
  • RADIUS Remote Authentication Dial In User Service
  • the second device 202 may interact with the operator's management system through the first device 201 to implement access authentication.
  • the system may further include: a third device; wherein,
  • the second device 202 may be configured to send access authentication information to the first device 201; receive authentication response information returned by the first device 201;
  • the first device 201 may be configured to receive the access authentication information sent by the second device 202, send the access authentication information to the third device, and receive the authentication response information returned by the third device , and returning authentication response information to the second device 202;
  • the third device may be configured to receive the access authentication information sent by the first device 201, use the access authentication information to perform access authentication on the second device 202, and report to the second device 202 A device returns authentication response information.
  • the third device may be called the operator's management system, for example, specifically, it may be a Business Support System (BSS, Business Support System) or an Operation Support System (OSS, Operation Support System).
  • BSS Business Support System
  • OSS Operation Support System
  • the embodiment of the present application does not limit the name of the third device, as long as the function of the third device is realized.
  • the access authentication information may include the characteristics of the second device 202 .
  • the features may include at least one of the following:
  • IP address segment i.e. IP address range
  • each first device 201 may be connected to multiple second devices 202, and the multiple second devices 202 can receive and send network data through the corresponding first device 201; correspondingly, the first The device 201 may perform resource scheduling on the plurality of second devices 202 according to the service priority of each second device 202 in the plurality of connected second devices 202, for example, provide the second device 202 with a high service priority For a higher bandwidth, for another example, when the network is congested, the data of the second device 202 whose source device or destination device has a high service priority is preferentially forwarded.
  • the service priority of the second device 202 can be represented by the field "high”, “medium” or “low”; or, the service priority can also be represented by a number, the larger the number, the higher the service priority. high.
  • the access authentication information of the second device 202 may also include the user name corresponding to the second device 202 (that is, the user name having the registration authority of the second device 202), the key corresponding to the user name, and the like.
  • the authentication response information of the second device 202 may include an authentication result; when the authentication result indicates that the authentication is successful, the authentication response information may also include the identity of the corresponding second device 202; when the authentication result indicates that the authentication has failed In the case of , the authentication response information may also include the reason for the authentication failure.
  • the first device 201 is further configured to control access of the second device 202 to network capabilities.
  • the first device 201 may provide security access control functions for applications provided by the second device 202 based on locally preset policies, and/or control the second device 202's access to network capabilities based on locally preset policies or, the first device 201 may also obtain from the third device a policy for providing security access control functions for applications provided by the second device 202 and/or controlling access of the second device 202 to network capabilities.
  • the third device may also be configured to send the first policy to the first device 201;
  • the first device 201 may also be configured to receive the first policy sent by the third device, and provide a security access control function for the application provided by the second device 202 based on the first policy, and/or, Access to network capabilities by the second device 202 is controlled based on the first policy.
  • the communication system may also include a third-party network; the first device 201 may also implement a service proxy for network capability opening between the third-party network and the second device 202 .
  • system may further include: at least one third-party network; wherein,
  • the third-party network may be configured to provide network access for the terminal
  • the first device 201 may also be configured to select a corresponding second device 202 for the terminal, and provide the application provided by the corresponding second device 202 to the terminal through the third-party network.
  • the third-party network can be understood as a non-5G network, such as 4G, WiFi, Bluetooth, Zigbee, NB-IoT, Wireline, etc.
  • the terminal may be called user equipment (UE, User Equipment), or may be called a user.
  • UE user equipment
  • User Equipment User Equipment
  • the first device 201 may specifically provide the application provided by the second device 202 with security access control functions for the core network and the third-party network based on the first policy, and/or, based on the first A policy controls access of the second device 202 to network capabilities of the core network and the third-party network.
  • the first policy may include the identity of the first device 201, the corresponding identity of the second device 202, the encryption policy of the transmission channel between the first device 201 and the second device 202, the corresponding The network capability type list that the second device 202 is allowed to access, the corresponding network capability API list that the second device 202 is allowed to access, the corresponding maximum number of times the second device 202 calls the network capability API, and the corresponding second device 202 allowed access
  • the encryption strategy may include: a virtual private network (VPN, Virtual Private Network) technology for remote access using an Internet Protocol Security (IPSec, Internet Protocol Security) protocol.
  • VPN Virtual Private Network
  • IPSec Internet Protocol Security
  • the first device 201 may perform data transmission with the second device 202 through a first tunnel, and the first tunnel may be an encrypted tunnel implemented by using the IPSec protocol to realize remote access VPN technology.
  • the first device 201 when the first device 201 controls the second device 202 to access network capabilities based on the first policy, it may specifically send third information to the corresponding second device 202 based on the first policy , the third information is used to indicate that the corresponding second device 202 has access to network capabilities; correspondingly, the second device 202 may be configured to receive the third information sent by the first device 201, and use the first 3. Information regulates its own access to network capabilities.
  • the third information may include the identity of the corresponding second device 202, the list of network capability APIs that the corresponding second device 202 is allowed to access, the list of self-service network security control APIs that the corresponding second device 202 is allowed to access, and the corresponding The second device 202 is connected to the first device 201 such as an on or off indication. It can be understood that, after receiving the third information, the second device 202 may enable or disable the connection with the corresponding first device 201 according to the opening or closing indication of the connection to the first device 201 contained in the third information. .
  • the APIs in the network capability API list and the self-service network security management and control API list are open APIs (Open APIs), and the first device 201 can connect to at least one second device through these Open APIs.
  • the devices 202 interact to provide resource domain authority control and security access functions for different user categories in each second device 202 (that is, provide security access functions for applications provided by the second device 202), and at the same time realize the user's access to the network, computing Operations at levels such as self-service management of resources.
  • the second device 202 can operate the self-service management functions of the connected first device 201 through the Open API, such as network partition authority management, network performance requirements, service routing policies, network slicing templates, location area size and location, Access to functions such as user identification.
  • the second device 202 may send corresponding management function information to the first device 201 to realize the self-service management function.
  • network partition rights management refers to selecting different network access methods (such as 4G, 5G, WiFi, Bluetooth, Zigbee, NB-IoT, Wireline, etc.) for different second devices 202, for example, the second device with high priority
  • the device 202 only allows the network access method of Wireline, and the second device 202 with a lower priority may allow network access methods such as WiFi and Bluetooth.
  • the network performance requirement can be understood as the bandwidth requirement of the second device 202
  • the function of the network slice template refers to the agent for the network slice template
  • the terminals in which areas to enter; the access user identifier may include a mobile phone number, a user name or an application identification (ID).
  • the second device 202 can obtain the network capability open data from the connected first device 201 through the network capability API in the network capability API list, and the obtained network capability open data conforms to the definition of the corresponding network capability API
  • the network capability opening data may include: positioning capability tags (such as 5G, WiFi, Bluetooth or Global Positioning System (GPS), etc.), positioning data, access user information, third-party network access list, network slicing capability data, QoS capability data, etc.
  • the second device 202 may also obtain network capability open data from the connected first device 201 through the self-service network security control API in the self-service network security control API list, and open the data based on the network capability Send a first instruction to the connected first device 201;
  • the first instruction is used to indicate self-service network security management and control, that is, the first instruction indicates corresponding management function information;
  • the first instruction complies with the corresponding self-service network security Control API definition
  • the first instruction may include network partition authority management, network performance requirements, service routing strategy, network slicing template configuration, positioning area size and location configuration, access user ID configuration (such as mobile phone number, user name or Application ID), etc.
  • the first device 201 can perform data transmission with the connected second device 202 through its own first interface; for example, the first device 201 can receive the second device 202, and return authentication response information to the second device 202 through the first interface; as another example, the first interface may bear the services provided by the second device 202 for the user.
  • the first device 201 needs to perform access authentication on the third-party network.
  • the first device 201 may also be configured to perform access authentication for a third-party network.
  • the third-party network may interact with the operator's management system through the first device 201 to implement access authentication.
  • the third-party network may be configured to send access authentication information to the first device 201; and receive authentication response information returned by the first device 201;
  • the first device 201 may be configured to receive the access authentication information sent by the third-party network, send the access authentication information to the third device, and receive the authentication response information returned by the third device, and returning authentication response information to the third-party network;
  • the third device may be configured to receive the access authentication information sent by the first device 201, use the access authentication information to perform access authentication on the third-party network, and send the first Device 201 returns authentication response information.
  • the access authentication information may include characteristics of the third-party network.
  • the features may include at least one of the following:
  • each first device 201 may be connected to multiple third-party networks, and the multiple third-party networks may receive and send network data through the corresponding first device 201 and the corresponding second device 202; correspondingly , the first device 201 may perform resource scheduling on the plurality of connected third-party networks according to the service priority of each third-party network in the plurality of connected third-party networks, for example, a third-party network with a high service priority Provide higher bandwidth. For example, when the network is congested, the data of the third-party network with high business priority is preferentially forwarded.
  • the service priority of the third-party network can be represented by the field "high”, “medium” or “low”; or, the service priority can also be represented by a number, the larger the number, the higher the service priority .
  • the access authentication information of the third-party network may also include the user name corresponding to the third-party network (that is, the user name with the registration authority of the third-party network), the key corresponding to the user name, and the key used to represent the network type (such as 4G , WiFi, Bluetooth, Zigbee, NB-IoT, Wireline, etc.) network identification and other content.
  • the authentication response information of the third-party network may include an authentication result; when the authentication result indicates that the authentication is successful, the authentication response information may also include an identity corresponding to the corresponding third-party network; when the authentication result indicates that the authentication failed In some cases, the authentication response information may also include reasons for authentication failure.
  • the first device 201 may perform data transmission with the third-party network based on a security mechanism.
  • the first device 201 may be configured to perform data transmission with the third-party network based on a security mechanism after the access authentication is passed.
  • the first device 201 can also implement functions such as access management, control, operation and maintenance of different networks based on the network identifiers of the connected third-party networks .
  • the first device 201 may also be configured to control the access capability of the third-party network.
  • the first device 201 can control the access capability of the third-party network based on a locally preset policy; or, the first device 201 can also obtain the Policies for access capabilities of third-party networks.
  • the third device may also be configured to send the second policy to the first device 201;
  • the first device 201 may also be configured to receive the second policy sent by the third device, and control the access capability of the third-party network based on the second policy.
  • the second strategy may include one of the following:
  • a first access control policy is aimed at a single third-party network
  • a second access control strategy is aimed at a type of third-party network
  • a third access control policy is aimed at all third-party networks.
  • the first device 201 may control the capability of the corresponding third-party network based on the first access control policy; the first access control policy may include the identity corresponding to the corresponding third-party network, the corresponding first The identity of the device 201, the maximum access bandwidth of the corresponding third-party network, the maximum network traffic of the corresponding third-party network, the longest access time of the corresponding third-party network, the maximum number of access users of the corresponding third-party network, the corresponding third-party Information such as network billing policies, and indications of opening or closing the corresponding third-party network access.
  • the first access control policy may include the identity corresponding to the corresponding third-party network, the corresponding first The identity of the device 201, the maximum access bandwidth of the corresponding third-party network, the maximum network traffic of the corresponding third-party network, the longest access time of the corresponding third-party network, the maximum number of access users of the corresponding third-party network, the corresponding third-party Information such as network billing policies, and indications of opening or closing the corresponding third
  • the first device 201 may control the capability of a corresponding type of third-party network based on the second access control policy;
  • the second access control policy may include a network identifier of a corresponding type of third-party network, The identity of the corresponding first device 201, the maximum access bandwidth of the corresponding type of third-party network, the maximum network traffic of the corresponding type of third-party network, the longest access duration of the corresponding type of third-party network, the corresponding type of third-party Information such as the maximum number of users accessing the network, the charging policy of the corresponding type of third-party network, and the opening or closing indication of the corresponding type of third-party network access.
  • the first device 201 may control the capabilities of all third-party networks based on the third access control policy; the third access control policy may include the identity of the corresponding first device 201, the corresponding first The maximum access bandwidth of all third-party networks connected to the device 201, the maximum network traffic of all third-party networks connected to the corresponding first device 201, the longest access duration of all third-party networks connected to the corresponding first device 201, and the corresponding The maximum number of access users of all third-party networks connected to a device 201, the charging policy of all third-party networks connected to the corresponding first device 201, and the opening or closing of all third-party network accesses connected to the corresponding first device 201 instructions and other information.
  • the third access control policy may include the identity of the corresponding first device 201, the corresponding first The maximum access bandwidth of all third-party networks connected to the device 201, the maximum network traffic of all third-party networks connected to the corresponding first device 201, the longest access duration of all third-party networks connected to the corresponding first device 201
  • the charging policy of the third-party network may include at least one of the following:
  • Billing based on third-party network broadband (that is, the maximum bandwidth value); such as billing by bandwidth subscription, billing by bandwidth usage time, and other billing modes;
  • Billing based on the traffic of the third-party network that is, the total amount of data actually transmitted by the third-party network
  • the QoS billing based on the third-party network may include data transmission rate, delay, jitter, reliability, etc.;
  • Billing is based on the number of users connected to the third-party network; for example, billing is based on the maximum number of users accessing the monthly or annual subscription, and billing is based on the actual number of users accessing the network.
  • the first device 201 needs to indicate the access capability of the third-party network, so as to be able to control the access capability of the third-party network.
  • the first device 201 may be configured to send first information to the third-party network, where the first information is used to indicate the access capability of the third-party network;
  • the third-party network may be configured to receive the first information sent by the first device 201, and use the first information to adjust its own access capability.
  • the first information may include the identity corresponding to the corresponding third-party network, an indication of enabling or disabling the corresponding third-party network access, a list of network capabilities when the third-party network access is enabled, and the like.
  • the network capability list when the third-party network access is enabled may include bandwidth, bandwidth control granularity, number of access users, and the like.
  • the first device 201 can perform data transmission with the connected third-party network through its second interface; for example, the first device 201 can receive the data sent by the third-party network through the second interface. access authentication information, and return authentication response information to the third-party network through the second interface; for another example, the first device 201 may send the first device 201 to the third-party network through the second interface a message.
  • the first device 201 can perform data transmission with the third-party network through the second tunnel, and the second tunnel can implement secondary encapsulation of access network data to ensure data security, unify protocol analysis and Adaptation and other functions.
  • the first device 201 may also obtain network information of various networks (such as 5G networks and/or third-party networks) to provide to required devices, such as sending to MEC Orchestrator (MEO, MEC Orchestrator ) (also may be called MEC Application Orchestrator (MEAO, MEC Application Orchestrator), so that MEO can at least use the network information of the at least one network to orchestrate the applications and available resources on the second device 202.
  • MEC Orchestrator MEC Orchestrator
  • MEAO MEC Application Orchestrator
  • MEC Application Orchestrator MEC Application Orchestrator
  • the first device needs to acquire network capability information of various networks (for example, including 5G networks and/or third-party networks).
  • various networks for example, including 5G networks and/or third-party networks.
  • the system further includes: at least one fourth device; wherein,
  • the fourth device is configured to provide the first device 201 with network capability information.
  • the fourth device may be called a network capability platform.
  • the fourth device may also be called a third-party network capability platform.
  • the name of the device is not limited, as long as the function of the fourth device can be realized.
  • the fourth device may include network elements of the core network, such as AF; Devices can include management devices for third-party networks.
  • the fourth device may also obtain the network capability information of the 5G network from the network device or network element of the core network, and/or obtain the network capability information of the third-party network from the management device of the third-party network, and use the obtained
  • the network capability information of at least one network is sent to the first device 201 .
  • the first device 201 needs to perform access authentication on the fourth device.
  • the first device 201 may also be configured to perform access authentication for the fourth device.
  • the fourth device may interact with the operator's management system through the first device 201, so as to implement access authentication.
  • the fourth device may also be configured to send access authentication information to the first device 201; receive authentication response information returned by the first device 201;
  • the first device 201 may be configured to receive the access authentication information sent by the fourth device, send the access authentication information to the third device, and receive the authentication response information returned by the third device, and returning authentication response information to the fourth device;
  • the third device may be configured to use the access authentication information to perform access authentication on the fourth device, and return authentication response information to the first device 201 .
  • the access authentication information of the fourth device may include the user name corresponding to the fourth device (that is, the user name with the third-party network capability registration authority), the key corresponding to the user name, and the key used to represent the user name of the fourth device.
  • the type of network capability list that the fourth device can provide such as NEF/Policy and Charging Rules Function (PCRF, Policy and Charging Rules Function)/network capability opening function, positioning capability, communication service management function (CSMF, Communication Service Management Function), the network capability identifier of the network slicing capability, etc.
  • PCRF Network Engineering Task Force
  • CSMF Communication Service Management Function
  • the network capability API list that the fourth device can provide and the like.
  • the authentication response information of the fourth device may include an authentication result; when the authentication result indicates that the authentication is successful, the authentication response information may also include the identity of the fourth device; In the case where the authentication result represents an authentication failure, the authentication response information may further include an authentication failure reason.
  • the first device 201 may control the access capability of the fourth device.
  • the first device 201 may also be configured to control the access capability of the fourth device.
  • the first device 201 may instruct the third-party network device to adjust its own access capability by sending indication information to the fourth device.
  • the first device 201 may be configured to send second information to the fourth device, where the second information is used to indicate the access capability of the fourth device;
  • the fourth device may be configured to receive the second information sent by the first device 201, and use the second information to adjust its access capability.
  • the second information may include the identity of the fourth device and an indication of enabling or disabling the access of the fourth device.
  • the second information may be used to indicate to enable or disable the connection between the fourth device and the first device 201 .
  • the first device 201 can perform data transmission with the fourth device through its third interface; for example, the first device 201 can receive the fourth device's transmission through the third interface. access authentication information, and return authentication response information to the fourth device through the third interface; for another example, the first device 201 may send the first device 201 to the fourth device through the third interface Two information.
  • the first device 201 can also obtain network capability information (such as maximum bandwidth, bandwidth control granularity, number of access users, etc.) The network capabilities are open.
  • the first device 201 may control the access capability of the fourth device based on a locally preset policy; or, the first device 201 may also obtain from the third device the A policy for the access capability of the fourth device.
  • the third device may be further configured to send a third policy to the first device
  • the first device 201 may also be configured to receive the third policy sent by the third device, and control the access capability of the fourth device based on the third policy.
  • the third strategy may include one of the following:
  • a fourth access control strategy is aimed at a single fourth device
  • a fifth access control strategy is aimed at a type of fourth device
  • a sixth access control policy is aimed at all fourth devices.
  • the first device 201 may control the access capability of the corresponding fourth device based on the fourth access control policy; the fourth access control policy may include the identity of the corresponding fourth device, the corresponding The identity of a device 201, the maximum number of invocations of the network capability API provided by the corresponding fourth device, the longest access duration of the corresponding fourth device, the charging policy of the corresponding fourth device, and the opening of the corresponding fourth device's access or turn off instructions and other information.
  • the first device 201 may control the access capability of the corresponding type of fourth device based on the fifth access control strategy; the fifth control strategy may include the network capability identifier of the corresponding type of fourth device , the identity of the corresponding first device 201, the maximum number of calls of the network capability API provided by the fourth device of the corresponding type, the longest access duration of the fourth device of the corresponding type, the charging policy of the fourth device of the corresponding type, And information such as an indication of opening or closing of the corresponding type of fourth device access.
  • the first device 201 may control the access capabilities of all fourth devices connected to the corresponding first device 201 based on the sixth access control policy; the sixth access control policy may include the corresponding first The identity of the device 201, the maximum number of calls of the network capability API provided by all the fourth devices connected to the corresponding first device 201, the longest access duration of all the fourth devices connected to the corresponding first device 201, the corresponding first device 201 Information such as billing policies of all connected fourth devices, indications of opening or closing access of all fourth devices connected to the corresponding first device 201, and the like.
  • the charging policy of the fourth device may include at least one of the following:
  • Billing based on the actual number of calls of the network capability API provided by the fourth device
  • Billing based on the traffic of the fourth device that is, the total amount of data actually transmitted by the network capability provided by the fourth device
  • Charging based on the type of network capability list that the fourth device can provide that is, specifying different charging modes and prices for different types of network capability lists;
  • Charging based on data sources of network capabilities provided by the fourth device that is, specifying different charging modes and prices for data sources of different network capabilities.
  • Step 201 routes and forwards the service flow of the terminal.
  • the first device 201 can be configured to route and forward the service flow of the terminal through at least one other first device 201, so that the terminal obtains at least one other first device 201 An application provided by the connected second device 202 .
  • the at least two first devices 201 may form a wide area transmission network to realize network interconnection and intercommunication among various campuses/organizations, so as to carry business collaboration between multiple second devices 202 .
  • the first device 201 can perform data transmission with at least one other first device 201 through its own fourth interface; the fourth interface can be based on a software-defined wide area network (SD-WAN, Software Defined Wide Area Network ) function is realized.
  • SD-WAN Software Defined Wide Area Network
  • At least one first device 201 needs to be managed and controlled.
  • the third device may also be configured to control the at least one first device 201 .
  • the third device needs to authenticate the first device 201 .
  • the third device may be further configured to authenticate the at least one first device 201 .
  • the first device 201 may be configured to send authentication information to the third device; and receive authentication response information returned by the third device;
  • the third device is configured to receive the authentication information sent by the first device 201, use the authentication information to authenticate the first device 201, and return an authentication response to the first device 201 information.
  • the authentication information of the first device 201 may include the username corresponding to the first device 201 (that is, the username with the registration authority of the first device 201), the key corresponding to the username, the A list of network types supported by a device 201, a list of network capability types supported by the first device 201, maximum bandwidth capacity supported by the first device 201, bandwidth control granularity supported by the first device 201, etc. content.
  • the authentication response information of the first device 201 may include an authentication result; when the authentication result indicates that the authentication is successful, the authentication response information may also include the identity of the first device 201; In the case where the authentication result indicates an authentication failure, the authentication response information may further include an authentication failure reason.
  • the first device 201 needs to monitor network traffic and/or network status, and report the monitored information to the third device 201.
  • Three devices In actual application, in order for the third device to realize the charging and operation of the communication system, the first device 201 needs to monitor network traffic and/or network status, and report the monitored information to the third device 201. Three devices.
  • the first device 201 may also be configured to monitor network traffic and/or network status; and report at least one of the following information to the third device:
  • the monitoring information of the network state may include the identity of the first device 201, the statistical time period corresponding to the current network state monitoring, the statistical information of the third-party network state, the statistical information of the fourth device state, Statistical information of the status of the second device 202, billing details, and other content.
  • the statistical information of the third-party network status can be understood as monitoring statistical information of the status of each third-party network in all third-party networks connected to the first device 201; the statistical information of the third-party network status can be Including the identity of the third-party network, the network identifier of the third-party network, the throughput rate of the third-party network, the traffic of the third-party network, the access time of the third-party network, etc.
  • the statistical information of the status of the fourth device can be understood as the monitoring statistical information of the status of each fourth device among all the fourth devices connected to the first device 201; the statistical information of the status of the fourth device may include the status of the fourth device.
  • the statistical information of the state of the second device 202 can be understood as the monitoring statistical information of the state of each second device 202 among all the second devices 202 connected to the first device 201; the statistics of the state of the second device 202
  • the information may include the identity of the second device 202, the throughput rate of the second device 202, the traffic of the second device 202, the number of times the second device 202 calls the network capability API, the access duration of the second device 202, and the like.
  • the billing details may be calculated and generated according to the billing policy of the third-party network and the billing policy of the fourth device.
  • the first device 201 can perform data transmission with the third device through its own fifth interface; for example, the first device 201 can send data to the third device through the fifth interface authentication information, and receive the authentication response information returned by the third device through the fifth interface; for another example, the first device 201 may receive the policy sent by the third device through the fifth interface (that is, the the first strategy, the second strategy, and the third strategy).
  • the first device 201 may also report information (that is, network traffic, billing information, network status monitoring information, network capability usage information, second device status) to the third device through the fifth interface. monitoring information, etc.).
  • the system may further include a fifth device configured to organize applications and available resources on the second device 202; correspondingly, the first device 201 may acquire each network information of a third-party network, and obtain the network information of the 5G network from the network equipment or network elements (such as AF, UPF, etc.) of the core network, and send the obtained network information of the 5G network or the third-party network to the fifth device.
  • the fifth device receives the network information of at least one network (which may include a 5G network and/or a third-party network) sent by the first device 201, and at least uses the network information of the at least one network to program the second Applications and available resources on device 202 .
  • the fifth device may be called MEO or MEAO, and the embodiment of the present application does not limit the name of the fifth device, as long as the functions of the fifth device can be realized.
  • the first device 201 can obtain network information of a third-party network through the second interface, obtain network information of the 5G network from a network device or network element of the core network through its own sixth interface, and can obtain network information of the 5G network through the sixth interface.
  • the seventh interface of its own sends the obtained network information of the 5G network and/or third-party network to the fifth device; after the fifth device receives the network information of at least one network, it can at least use the network information of the at least one network network information, reasonably and effectively arrange the applications and available resources on the second device 202; the reasonable and effective arrangement can be understood as: the fifth device can, based on the network information of the at least one network, Network load balancing is realized when arranging the applications and available resources on the second device 202, for example, when the operating status of the WiFi network is poor, the fifth device can automatically switch the applications running on the WiFi network to those running well running on the 5G network.
  • the network information may include network type (i.e. network identifier), network operation status, network tariff information, network operation and maintenance information, etc.;
  • the network tariff information may include network charging rules, network Billing details, network shared quota policy, network terminal binding policy, network speed limit policy, network limit policy, etc.;
  • the network operation and maintenance information may include network bandwidth limit information, network bandwidth utilization rate , network uplink and/or downlink traffic usage, traffic balance, etc.
  • the embodiment of the present application also provides a communication method, which is applied to the first device, as shown in FIG. 3 , the method includes:
  • Step 301 Allocate the corresponding second device for the service traffic of the edge network sent by the UPF, so as to offload the service traffic of the edge network to the corresponding second device, and provide a security access control function for the application provided by the second device.
  • the method may further include:
  • Step 302 Perform access authentication on the connected second device.
  • the method may also include:
  • Access to network capabilities by the second device is controlled.
  • the performing access authentication on the connected second device may include:
  • the access authentication information may include characteristics of the second device.
  • the features may include at least one of the following:
  • the method may also include:
  • the method may also include:
  • a corresponding second device is selected for the terminal accessing the third-party network, and the application provided by the corresponding second device is provided to the terminal through the third-party network.
  • the method may also include:
  • the performing access authentication on the third-party network may include:
  • the access authentication information may include characteristics of the third-party network.
  • the features may include at least one of the following:
  • the first device may perform data transmission with the third-party network based on a security mechanism.
  • the method may also include:
  • the method may also include:
  • the second strategy may include one of the following:
  • a first access control policy is aimed at a single third-party network
  • a second access control strategy is aimed at a type of third-party network
  • a third access control policy is aimed at all third-party networks.
  • controlling the access capability of the third-party network may include:
  • the method may also include:
  • the method may also include:
  • controlling the access capability of the fourth device may include:
  • the method may also include:
  • the performing access authentication on the fourth device may include:
  • the method may also include:
  • the service flow of the terminal is routed and forwarded through at least one other first device, so that the terminal obtains an application provided by a second device connected to at least one other first device.
  • the method may also include:
  • the first device allocates the corresponding second device for the service traffic of the edge network sent by the UPF, so as to offload the service traffic of the edge network to the corresponding second device, and assign the service traffic of the edge network to the corresponding second device.
  • the application provided by the device provides security access control functions.
  • the first device realizes the service agent of the network capability opening between the UPF and the second device (such as MEP); in this way, the data security of the communication system can be guaranteed, and the network security capability of the communication system can be improved. Thereby improving user experience.
  • the first device is called an industry gateway (it can be expressed as iGW in English); the second device is called an MEP; the third device is called a BSS or OSS system, or BSS/OSS for short; the fourth device is called a Three-party network capabilities.
  • the industry gateway is deployed between UPF and MEP, and has at least one of the following five functions:
  • the third generation partnership project (3GPP) mobile network such as 4G, 5G, NB-IoT, etc.
  • non-3GPP (non-3GPP) mobile network such as WiFi, Bluetooth, Zigbee, etc.
  • fixed networks such as Wireline, optical fiber, Slicing Packet Network (SPN, Slicing Packet Network), Optical Transport Network (OTN, Optical Transport Network), etc.
  • SPN Slicing Packet Network
  • OTN Optical Transport Network
  • This function has the following key properties:
  • Multi-standard network access capability that is, the industry gateway supports the access capability of different standard networks such as 3GPP mobile network, non-3GPP mobile network and fixed network.
  • Multi-standard network access identification and labeling functions that is, the industry gateway can perform access authentication on networks of different standards, and add network labels (ie, the above-mentioned network identification) to networks of different standards after completing the access authentication , to identify network types corresponding to networks of different standards (such as 3GPP mobile network, non-3GPP mobile network, fixed network, etc.).
  • the industry gateway can also implement functions such as access management, control, operation and maintenance of networks of different standards based on the network label.
  • Multi-standard network connection establishment and release functions that is, the industry gateway can integrate network labels, unified authentication, and network capabilities (such as bandwidth, bandwidth control granularity, and access user numbers) on the basis of IP protocols in related technologies. etc.) list, network access status (on status (On)/close status (off)) and other information, to establish connections with networks of different standards, and to have the function of releasing network connections of different standards.
  • multiple industry gateways can form a wide-area transmission network to realize network interconnection among parks/organizations to carry business collaboration between multiple MEPs.
  • This function has the following key properties:
  • Intelligent routing function that is, on the basis of technologies such as SD-WAN and Network Function Virtualization Infrastructure solutions (NFVI, Network Function Virtualization Infrastructure), increase the information interaction between the industry gateway and UE, and the information exchanged Including service routing address, service transmission QoS requirements, etc., to realize intelligent service access from UE to different MEC edge clouds.
  • the service routing address may include content such as the DNN and the IP address of the destination MEC.
  • the MEC entity function is similar to UE-based; that is, through the industry gateway MEC can access the wired network and 5GC through the access and mobility management function (AMF, Access and Mobility Management Function), process management function (SMF, Session Management Function), PCRF
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • PCRF PCRF
  • the industry gateway can connect to the network capabilities of 5GC, RAN, and third-party networks (ie, non-5G networks, such as 4G, WiFi, Bluetooth, Zigbee, NB-IoT, Wireline, etc.), through a unified API (ie, Open API ) is open to MEPs to use, and conducts unified monitoring and settlement of network capacity usage, realizing the access and opening functions of ubiquitous network capabilities.
  • a unified API ie, Open API
  • This function has the following key properties:
  • Multi-type network capability access that is, the industry gateway can support the access of capabilities such as NEF, PCRF, network capability exposure function (SCEF), positioning capability, CSMF, and network slicing.
  • capabilities such as NEF, PCRF, network capability exposure function (SCEF), positioning capability, CSMF, and network slicing.
  • Multi-type network capability opening that is, the industry gateway can open positioning capability, access user information, multi-standard network access list, network slicing capability, QoS and other capabilities to MEP through Open API.
  • the industry gateway can be used as a comprehensive access device for ubiquitous fully connected networks, and can monitor networks of different standards in real time (that is, different types of networks, such as 5G, 4G, WiFi, Bluetooth, Zigbee, NB-IoT, Wireline, etc. ) traffic and network usage, realize the billing function and report to BSS/OSS in real time, so as to realize billing and operation strategies based on different dimensions.
  • networks of different standards in real time that is, different types of networks, such as 5G, 4G, WiFi, Bluetooth, Zigbee, NB-IoT, Wireline, etc.
  • This function has the following key properties:
  • Multi-dimensional traffic and network monitoring that is, the industry gateway can support separate traffic statistics and network monitoring for networks of different standards, and report to OSS through signaling that integrates network labels, traffic data, and network status;
  • Multi-dimensional billing dimension that is, the industry gateway can support billing based on different types of network traffic, multi-type network capability call times or scheduling duration, MEP capabilities and other information, and through the integration of billing dimension tags The signaling with the specific charging value is reported to the BSS/OSS.
  • the industry gateway can interact with the MEP through the Open API, while providing resource domain authority control and security access control functions for different user categories in the MEP, and realizing self-service management of network, computing and other resources by users. Operation at the level; that is, the MEP can operate the network partition authority management, network performance requirements (such as bandwidth), service routing policy, network slicing template (that is, the proxy function of the network slicing template), location area size and Location, access user ID (such as mobile phone number, user name or application ID) and other functions.
  • network performance requirements such as bandwidth
  • service routing policy such as bandwidth
  • network slicing template that is, the proxy function of the network slicing template
  • location area size and Location access user ID (such as mobile phone number, user name or application ID) and other functions.
  • network partition rights management means that different MEPs have different network access rights. For example, MEPs with high priority only allow access to wired networks, while MEPs with low priority allow access to networks such as WiFi and Bluetooth.
  • the location area size And location refers to which areas each MEP can configure to allow terminals to access.
  • the industry gateway actually acts as a link between MEP and RAN, between MEP and 5GC, and between MEP and third-party systems (which may include third-party networks and third-party network capabilities) ) between the agent role of the network capability opening, on the basis of the industry gateway opening the network capability through the proxy mode, the industry gateway can also indirectly open the network capability to the MEP in the form of a report after processing.
  • the interface between the industry gateway and other functional entities is newly defined.
  • the industry gateway implements the above functions through interfaces I1 to I5.
  • Interface I1 is the communication interface between the industry gateway and the third-party network, and is used to realize the access authentication function of the third-party network, and is used to bear the data transmission between the industry gateway and the third-party network.
  • interface I1 the key functions supported by interface I1 include:
  • Access authentication of the third-party network can actively or passively trigger the access authentication process to realize functions such as secure access to the third-party network, identification distinction of the access network (that is, the above-mentioned network label and network identification).
  • the industry gateway can control whether to allow third-party network access, and can actively cut off functions such as data transmission with the third-party network.
  • the industry gateway can realize the data transmission function with the third-party network through a dedicated tunnel (that is, the second tunnel above), and the tunnel realizes secondary encapsulation of access network data to ensure data security, unify protocol analysis and adaptation Matching and other functions.
  • Interface I2 is the communication interface between the industry gateway and the third-party network capability, and is used to realize the access and authentication functions of the third-party network capability, and is used to bear the data transmission between the industry gateway and the third-party network capability, For example, obtain network capability data from third-party network capabilities.
  • interface I2 the key functions supported by interface I2 include:
  • the third-party network capability can actively or passively trigger the access authentication process, so as to realize the secure access of the third-party network capability and the identification distinction of the accessed network capability (that is, the above-mentioned network capability identification, which can represent NEF/PCRF/ CSMF, positioning capability, CSMF, network slicing and other capabilities) and other functions.
  • the industry gateway can control whether to allow third-party network capability access through the network capability access status indication (On/Off), and can obtain the network capability list of the third-party network capability (which can include bandwidth, bandwidth control granularity, access information such as the number of users).
  • the industry gateway can obtain the network capability API according to the network capability data provided by the third-party network capability, so as to realize the function of obtaining the third-party network capability data.
  • the interface I3 is the communication interface between the industry gateway and the BSS/OSS, and is used to support the policy configuration function and the operation status monitoring function.
  • interface I3 the key functions supported by interface I3 include:
  • the industry gateway can actively or passively trigger the access authentication process;
  • the information exchanged between the industry gateway and the BSS/OSS can include: the industry gateway device ID (that is, the identity of the first device 201), the access network supported by the industry gateway Capability list, whether to allow industry gateway access, etc.
  • the BSS/OSS can issue the access policy of the third-party network to the industry gateway; the information exchanged between the industry gateway and the BSS/OSS can include: network type label (that is, the above-mentioned network label and network identification), network authentication information, bandwidth, Traffic, billing control, network access status indication (On/Off), etc.
  • network type label that is, the above-mentioned network label and network identification
  • network authentication information that is, the above-mentioned network label and network identification
  • bandwidth bandwidth
  • Traffic billing control
  • network access status indication On/Off
  • the BSS/OSS can issue the third-party network capability access policy to the industry gateway; the information exchanged between the industry gateway and the BSS/OSS can include: network capability type label (that is, the above-mentioned network capability identification), network capability authentication information, network Access status indication (On/Off) and other content.
  • network capability type label that is, the above-mentioned network capability identification
  • network capability authentication information that is, the above-mentioned network capability authentication information
  • Network Access status indication On/Off
  • the information exchanged between the industry gateway and the BSS/OSS may include: the MEP access encryption policy, the list of network capabilities allowed to be opened, etc., so as to realize the function of the industry gateway to access the MEP.
  • the industry gateway can monitor the current network status in real time; the information exchanged between the industry gateway and BSS/OSS can include: operation and maintenance monitoring information that integrates network labels, traffic data, and network status, and integrates billing dimension labels and specific The billing data information of the billing value.
  • Interface I4 is the communication interface between the industry gateway and the MEP, which is used to carry the data transmission between the industry gateway and the MEP, and realize the MEP-oriented network capability exposure and self-service network security management and control functions.
  • interface I4 the key functions supported by interface I4 include:
  • MEP can actively or passively trigger the access authentication process; the access authentication process can be implemented based on technologies such as RADIUS.
  • the industry gateway can realize the data transmission function with the MEP through IPSec/VPN (that is, the VPN technology that uses the IPSec protocol to realize remote access) encrypted tunnel (that is, the above-mentioned first tunnel) and other methods.
  • IPSec/VPN that is, the VPN technology that uses the IPSec protocol to realize remote access
  • encrypted tunnel that is, the above-mentioned first tunnel
  • the signaling for industry gateways to interact with MEPs may include positioning capability tags (such as 5G, WiFi, Bluetooth, GPS, etc.), positioning data, access user information, multi-standard network access lists, network slicing capabilities, QoS capabilities, and other information .
  • positioning capability tags such as 5G, WiFi, Bluetooth, GPS, etc.
  • MEP MEP-oriented self-service network security control function.
  • MEP can operate the industry gateway's network partition authority management, network performance requirements, service routing strategy, network slicing template, positioning area size and location, access user ID (mobile phone number, user name or application ID) and other aspects through the Open API function.
  • Interface I5 is a communication interface between an industry gateway and other industry gateways, and is used to realize the wide-area interconnection function between industry gateways.
  • interface I5 can be implemented based on SD-WAN functions, or by enabling edge computing MEP UE-like, MEP can be realized through General Packet Radio Service (GPRS) Tunneling Protocol (GTP) User Plane (GTP-U) tunnels
  • GPRS General Packet Radio Service
  • GTP General Packet Radio Service
  • GTP-U User Plane
  • the interfaces I1 to I5 carry information about the interaction between the industry gateway and other functional entities when supporting the above functions.
  • the information carried by the interfaces I1 to I5 will be described in detail below.
  • the third-party network can report the access authentication information to the industry gateway through the interface I1; the content contained in the access authentication information is shown in Table 1; wherein, as As shown in Table 2, the network type identifier (that is, the above-mentioned network identifier) can be represented by a variety of different data types.
  • the industry gateway After the industry gateway completes the access authentication of the third-party network, it can return the authentication response information to the third-party network through the interface I1; the content contained in the authentication response information is shown in Table 3; wherein, as shown in Table 4, the network identity Can be represented by a number of different data types.
  • the industry gateway can send network access control information (that is, the above-mentioned first information) to the third-party network through the interface I1, so as to realize the access control of the third-party network Function; the content contained in the network access control information is shown in Table 5.
  • the industry gateway can also send a self-service network security management and control instruction (ie, the first instruction above) to a third-party network through the interface I1, so as to realize the MEP-oriented self-service network security management and control function.
  • a self-service network security management and control instruction ie, the first instruction above
  • the third-party network capability can report the access authentication information to the industry gateway through the interface I1; the content contained in the access authentication information is shown in Table 6; where , as shown in Table 7, the network capability type identifier (that is, the above-mentioned network capability identifier) can be represented by multiple different data types; as shown in Table 8, the network capability API list can also be represented by multiple different data types.
  • the industry gateway After the industry gateway completes the access authentication of the third-party network capability, it can return the authentication response information to the third-party network capability through the interface I1; the contents of the authentication response information are shown in Table 9; where, as shown in Table 10, the network Capability identities can be represented by a number of different data types.
  • lists i.e. List of String and List of Number
  • lists can be understood as one-dimensional arrays for storing a series of data of the same type.
  • lists can be static or dynamically changing.
  • the industry gateway can send access control information (that is, the above-mentioned second information) to the third-party network capability through the interface I2 to realize the access to the third-party network capability
  • access control information that is, the above-mentioned second information
  • the industry gateway can also obtain network capability data from third-party network capabilities through the interface I2, so as to realize MEP-oriented network capability opening.
  • the industry gateway can send identity authentication information to the BSS/OSS through the interface I3; the content contained in the identity authentication information is shown in Table 12; wherein, as shown in Table 13
  • the network type list can be represented by multiple different data types; as shown in Table 14, the network capability type list can also be represented by multiple different data types.
  • the BSS/OSS After the BSS/OSS completes the access authentication of the industry gateway, it can return the authentication response information to the industry gateway through the interface I3; the contents of the authentication response information are shown in Table 15; where, as shown in Table 16, the industry gateway identity Can be represented by a number of different data types.
  • parameter name type of data illustrate username String Username with industry gateway registration authority key String The key corresponding to the username List of network types As shown in Table 13 List of network types supported by industry gateways List of Network Capability Types As shown in Table 14 List of network capability types supported by industry gateways maximum bandwidth Number The maximum bandwidth capacity supported by the industry gateway Bandwidth Control Granularity Number Bandwidth control granularity supported by industry gateways
  • BSS/OSS can send a single third-party network access control policy (namely the above-mentioned first access control policy) to the industry gateway through interface I3 to realize the control of the industry
  • a single third-party network access control policy namely the above-mentioned first access control policy
  • the access control function of a single third-party network connected to the gateway; the content contained in the single third-party network access control policy is shown in Table 17.
  • BSS/OSS can also send a single-type third-party network access control policy (that is, the above-mentioned second access control policy) to the industry gateway through the interface I3, so as to realize the access to the single-type third-party network on the industry gateway.
  • a single-type third-party network access control policy that is, the above-mentioned second access control policy
  • Access control function the content contained in the single-type third-party network access control policy is shown in Table 18.
  • BSS/OSS can also send the overall third-party network access control policy (that is, the above-mentioned third access control policy) to the industry gateway through the interface I3, so as to realize the access control function of all third-party networks on the industry gateway ;
  • the content contained in the overall third-party network access control policy is shown in Table 19.
  • the charging policy of the third-party network may include at least one of the following:
  • Billing by bandwidth that is, billing is based on the maximum bandwidth value of the third-party network, such as billing by bandwidth subscription, billing by bandwidth usage time, and other billing modes;
  • Billing by traffic that is, billing is based on the total amount of data actually transmitted by the third-party network
  • Billing by network slice that is, billing is based on the type and quantity of third-party network slices used;
  • QoS Charge according to QoS; that is, charge according to the QoS provided by the third-party network, such as data transmission rate, delay, jitter, reliability, etc.;
  • Billing based on the number of access users that is, billing is based on the number of users connected to the third-party network, such as monthly and annual billing based on the maximum number of access users, and billing based on the actual number of access users.
  • BSS/OSS can send a single third-party network capability access control policy (that is, the fourth access control policy above) to the industry gateway through interface I3 to realize The access control function of a single third-party network capability on the industry gateway; the content contained in the single third-party network capability access control policy is shown in Table 20.
  • BSS/OSS can also send a single-type third-party network capability access control policy (that is, the fifth access control policy above) to the industry gateway through interface I3 to realize the single-type third-party network capability on the industry gateway.
  • access control function the content contained in the single-type third-party network capability access control policy is shown in Table 21.
  • BSS/OSS can also send the overall third-party network capability access control policy (that is, the sixth access control policy above) to the industry gateway through interface I3 to realize access to all third-party network capabilities on the industry gateway Control function; the content contained in the overall third-party network capability access control policy is shown in Table 22.
  • the overall third-party network capability access control policy that is, the sixth access control policy above
  • the charging policy of the third-party network capability may include at least one of the following:
  • Billing is based on the actual number of calls to the API of the third-party network capability
  • Billing is based on the data traffic of the third-party network capacity; that is, it is billed according to the total amount of network capacity data actually transmitted;
  • Billing according to the type of third-party network capabilities that is, specifying different billing modes and prices for different types of third-party network capabilities
  • the BSS/OSS can send the MEP access control strategy (namely the above-mentioned first strategy) to the industry gateway through the interface I3 to realize the access control function of the MEP;
  • the content contained in the MEP access control policy is shown in Table 23; among them, as shown in Table 24, the MEP identity can be represented by a variety of different data types; as shown in Table 25, the self-service network security control API list can also be Represented by a number of different data types.
  • the industry gateway can send network status monitoring information to the BSS/OSS through the interface I3 to realize the network status monitoring function; the content contained in the network status monitoring information is shown in Table 26; Wherein, as shown in Table 27, the statistical information of the third-party network status, the statistical information of the third-party network capability status and the statistical information of the MEP status can be represented by different data types.
  • the MEP can send the MEP access authentication information to the industry gateway through the interface I4; the content contained in the MEP access authentication information is shown in Table 28.
  • the industry gateway After the industry gateway completes the authentication of the MEP, it can return the MEP access authentication response information through the interface I4; the content contained in the MEP access authentication response information is shown in Table 29.
  • the industry gateway can send the MEP access control information (that is, the third information above) to the MEP through the interface I4, so as to realize the access control function of the MEP;
  • the content contained in the input control information is shown in Table 30.
  • the MEP can obtain the network capability exposure data through the network capability API opened by the industry gateway; at this time, the content contained in the information exchanged between the MEP and the industry gateway is shown in Table 31 Show. .
  • the MEP can obtain network capability open data through the self-service network security control API opened by the industry gateway; at this time, the information contained in the interaction between the MEP and the industry gateway The content is shown in Table 32.
  • interconnection channels can be established between different industry gateways through SD-WAN, the Internet, enterprise dedicated lines, wireless networks, etc., to realize the wide-area interconnection function.
  • the functions supported by the industry gateway are subject to the unified management and control of the BSS/OSS, which is realized through the linkage (ie, combination) of the interface I3 and other interfaces.
  • the following describes the flow of interface I3 linkage with other interfaces to realize corresponding functions with reference to FIG. 7 to FIG. 10 .
  • the access authentication function and access control function of the industry gateway to the third-party network can be realized.
  • the process of realizing the access authentication function of the industry gateway to the third-party network Specifically, the following steps may be included:
  • Step 7101 The third-party network sends third-party network access authentication information to the industry gateway through interface I1; then execute step 7102;
  • Step 7102 The industry gateway sends the third-party network access authentication information to the BSS/OSS through the interface I3; then execute step 7103;
  • Step 7103 BSS/OSS implements access authentication to the third-party network; then execute step 7104;
  • Step 7104 BSS/OSS sends the third-party network access authentication response information including the authentication result to the industry gateway through interface I3; then execute step 7105;
  • Step 7105 The industry gateway sends the third-party network access authentication response information to the third-party network through the interface I1.
  • the process of realizing the access control function of the industry gateway to the third-party network may specifically include the following steps:
  • Step 7201 BSS/OSS sends the third-party network access control policy to the industry gateway through interface I3; then execute step 7202;
  • Step 7202 The industry gateway implements access control to the third-party network according to the third-party network access control strategy (ie, the second strategy above); then execute step 7203;
  • the third-party network access control strategy ie, the second strategy above
  • the access control of the third-party network implemented by the industry gateway may include bandwidth restrictions, restrictions on the number of access users, opening or closing of third-party network access, billing, etc.;
  • Step 7203 The industry gateway sends the third-party network access control information (that is, the above-mentioned first information) to the third-party network through the interface I1.
  • the third-party network access control information that is, the above-mentioned first information
  • the access authentication function and access control function of the industry gateway to the third-party network capability can be realized.
  • the access authentication function of the industry gateway to the third-party network capability can be realized The process can specifically include the following steps:
  • Step 8101 The third-party network capability sends the third-party network capability access authentication information to the industry gateway through the interface I2; then execute step 8102;
  • Step 8102 The industry gateway sends the third-party network capability access authentication information to the BSS/OSS through interface I3; then execute step 8103;
  • Step 8103 BSS/OSS implements access authentication for third-party network capabilities; then execute step 8104;
  • Step 8104 BSS/OSS sends the third-party network capability access authentication response information including the authentication result to the industry gateway through interface I3; then execute step 8105;
  • Step 8105 The industry gateway sends the third-party network capability access authentication response information to the third-party network capability through the interface I2.
  • the process of realizing the access control function of the industry gateway to the third-party network capability may specifically include the following steps:
  • Step 8201 BSS/OSS sends the third-party network capability access control policy (namely the above-mentioned third policy) to the industry gateway through interface I3; then execute step 8202;
  • the third-party network capability access control policy namely the above-mentioned third policy
  • Step 8202 The industry gateway implements access control to third-party network capabilities according to the third-party network capability access control policy; then execute step 8203;
  • the access control of the third-party network capabilities implemented by the industry gateway may include the limitation of the number of network capability API calls, the opening or closing of third-party network capability access, billing, etc.;
  • Step 8203 The industry gateway sends the third-party network capability access control information (that is, the above-mentioned second information) to the third-party network capability through the interface I2.
  • the third-party network capability access control information that is, the above-mentioned second information
  • the access authentication function and access control function of the industry gateway to the MEP can be realized.
  • the process of realizing the access authentication function of the industry gateway to the MEP can include The following steps:
  • Step 9101 MEP sends MEP access authentication information to the industry gateway through interface I4; then execute step 9102;
  • Step 9102 The industry gateway sends the MEP access authentication information to the BSS/OSS through interface I3; then execute step 9103;
  • Step 9103 BSS/OSS implements access authentication to MEP; then execute step 9104;
  • Step 9104 BSS/OSS sends the MEP access authentication response information containing the authentication result to the industry gateway through interface I3; then execute step 9105;
  • Step 9105 The industry gateway sends the MEP access authentication response information to the MEP through the interface I4.
  • the process of realizing the access control function of the industry gateway to the MEP may specifically include the following steps:
  • Step 9201 BSS/OSS sends the MEP access control strategy (i.e. the first strategy above) to the industry gateway through the interface I3; then execute step 9202;
  • MEP access control strategy i.e. the first strategy above
  • Step 9202 The industry gateway implements access control to the MEP according to the MEP access control policy; then execute step 9203;
  • the access control to the MEP implemented by the industry gateway may include network capacity restriction, bandwidth restriction, billing, etc. that allow access;
  • Step 9103 The industry gateway sends MEP access control information (that is, the third information above) to the MEP through the interface I4.
  • MEP access control information that is, the third information above
  • the MEP-oriented network capability exposure function and self-service network security management and control functions can be realized.
  • the realization of the MEP-oriented network capability exposure function may specifically include the following steps:
  • Step 1011 BSS/OSS sends the MEP access control policy (namely the above-mentioned first policy) to the industry gateway through interface I3; then execute step 1012;
  • MEP access control policy namely the above-mentioned first policy
  • the MEP access control policy includes a control policy related to MEP-oriented network capability exposure
  • Step 1012 MEP invokes the network capability exposure API of the industry gateway through interface I4; then execute step 1013;
  • Step 1013 The industry gateway verifies the request of the MEP according to the MEP access control strategy. After the verification is passed, the industry gateway sends a request for obtaining network capability data to the third-party network capability through the interface I2; then execute step 1014;
  • the industry gateway can verify whether the MEP's request does not belong to the network capabilities allowed by the corresponding MEP; or, can verify whether the MEP's request exceeds the network capability open API times allowed by the corresponding MEP;
  • Step 1014 The third-party network capability sends network capability data to the industry gateway through the interface I2; then execute step 1015;
  • Step 1015 The industry gateway sends the network capability data to the MEP through the interface I4.
  • the process of realizing the MEP-oriented self-service network security management and control function may specifically include the following steps:
  • Step 1011 BSS/OSS sends the MEP access control policy to the industry gateway through interface I3; then execute step 1021;
  • the MEP access control strategy includes a control strategy related to MEP-oriented self-service network security management and control;
  • Step 1021 MEP invokes the self-service network security control API of the industry gateway through interface I4; then execute step 1022;
  • Step 1022 The industry gateway verifies the request of the MEP according to the MEP access control policy. After the verification is passed, the industry gateway sends a self-service network control instruction (ie, the first instruction above) to the third-party network through the interface I1; then execute the steps 1023;
  • a self-service network control instruction ie, the first instruction above
  • the industry gateway can check whether the request of the MEP does not belong to the self-service network security control API that the MEP allows access to;
  • the self-service network control command can be a network security control command;
  • Step 1023 The third-party network sends the self-service network control result to the industry gateway through the interface I1; then execute step 1024;
  • the self-service network management and control instruction is a network security management and control instruction
  • the self-service network management and control result is a network security management and control result
  • Step 1024 The industry gateway sends the self-service network management and control response information to the MEP through the interface I4.
  • the solution provided by this application example on the basis of related technologies, introduces industry gateways (which can be network devices or network elements) into the communication system, deploys them between UPF and MEP, and accepts the management and control of BSS/OSS;
  • the gateway should at least have the functions of multi-standard network access control, network intelligent wide-area interconnection, multi-type network capability access and openness, multi-standard network monitoring and billing, and self-service resource management; at the same time, based on the newly defined five
  • the interfaces (interfaces I1 to I5) realize the above functions; among them, the interface I1 is connected to the multi-standard access network (that is, the third-party network); the interface I2 is connected to the access of multi-type network capabilities (that is, the third-party network capability); the interface I3 is connected to the BSS/OSS; interface I4 connects to MEP; interface I5 connects to other industry gateways.
  • the communication system provided by this application embodiment (that is, the 5G industry cloud-network integration system) is operable, safer, implementable, and evolving, and better meets the needs of vertical industry customers.
  • the communication system provided by this application example on the one hand, it can solve the network and computing problems caused by the separate deployment of UPF and MEC that exist in the implementation of related technologies (that is, the combination of 5G and MEC technology shown in Figure 1) in the industry.
  • Resource security issues, access and unified management issues that do not support multi-standard networks such as 4G, 5G, WiFi, Bluetooth, Zigbee, NB-IoT, optical fiber, Wireline, etc.
  • multi-standard networks such as 4G, 5G, WiFi, Bluetooth, Zigbee, NB-IoT, optical fiber, Wireline, etc.
  • local distribution defects, and interconnection between MEPs and other issues on the other hand, it can meet users' needs for diversified network capability exposure and self-service resource management capabilities.
  • the embodiment of the present application also provides a communication device, which is set on the first device, as shown in FIG. 11 , the device includes:
  • the processing unit 1101 is configured to assign a corresponding second device to the service flow of the edge network sent by the UPF, so as to offload the service flow of the edge network to the corresponding second device, and provide a security access control function for the application provided by the second device .
  • processing unit 1101 is further configured to perform access authentication on the connected second device.
  • the apparatus further includes a control unit 1102 configured to control the second device's access to the network capability.
  • processing unit 1101 is configured to:
  • processing unit 1101 is further configured to:
  • the processing unit 1101 is further configured to select a corresponding second device for a terminal accessing a third-party network, and provide an application provided by the corresponding second device to the terminal through the third-party network.
  • processing unit 1101 is further configured to perform access authentication on the third-party network.
  • processing unit 1101 is configured to:
  • the processing unit 1101 is further configured to perform data transmission with the third-party network based on a security mechanism after the access authentication is passed.
  • control unit 1102 is further configured to control the access capability of the third-party network.
  • control unit 1102 is configured to:
  • the processing unit 1101 is configured to send first information to the third-party network, where the first information is used to indicate the access capability of the third-party network.
  • the processing unit 1101 is further configured to receive network capability information sent by the fourth device.
  • control unit 1102 is further configured to control the access capability of the fourth device.
  • the processing unit 1101 is further configured to perform access authentication on the fourth device.
  • the processing unit 1101 is configured to send second information to the fourth device, where the second information is used to indicate the access capability of the fourth device.
  • control unit 1102 is configured to:
  • processing unit 1101 is configured to:
  • the processing unit 1101 is further configured to route and forward the service flow of the terminal through at least one other first device, so as to enable the terminal to obtain the information provided by the second device connected to at least one other first device.
  • processing unit 1101 is further configured to monitor network traffic and/or network status; and report at least one of the following information to the third device:
  • the apparatus further includes an acquisition unit configured to acquire network information of at least one network (including 5G network and/or third-party network) to provide to required equipment (such as MEAO).
  • an acquisition unit configured to acquire network information of at least one network (including 5G network and/or third-party network) to provide to required equipment (such as MEAO).
  • the obtaining unit is configured to obtain the network information of the third-party network from the management device of the third-party network, and/or obtain the network information of the 5G network from the management device of the 5G network.
  • processing unit 1101, the control unit 1102 and the acquiring unit may be implemented by a processor in a communication device combined with a communication interface.
  • the embodiment of the present application also provides a first device, as shown in Figure 12, the first device 1200 includes: a processor 1202 and a communication interface 1201; where,
  • the processor 1202 is configured to allocate a corresponding second device for the service traffic of the edge network sent by the UPF, so as to offload the service traffic of the edge network to the corresponding second device, and provide secure access to the application provided by the second device control function.
  • processor 1202 is further configured to:
  • Access to network capabilities by the second device is controlled.
  • the processor 1202 is configured to:
  • the processor 1202 is further configured to:
  • the processor 1202 is further configured to select a corresponding second device for a terminal accessing a third-party network, and provide an application provided by the corresponding second device to the terminal through the third-party network.
  • the processor 1202 is further configured to perform access authentication on the third-party network.
  • the processor 1202 is configured to:
  • the processor 1202 is further configured to perform data transmission with the third-party network based on a security mechanism after the access authentication is passed.
  • the processor 1202 is further configured to control the access capability of the third-party network.
  • the processor 1202 is further configured to:
  • the processor 1202 is configured to send first information to the third-party network through the communication interface 1201, where the first information is used to indicate the access capability of the third-party network.
  • the processor 1202 is further configured to receive the network capability information sent by the fourth device through the communication interface 1201 .
  • the processor 1202 is further configured to:
  • the processor 1202 is configured to send second information to the fourth device through the communication interface 1201, where the second information is used to indicate the access capability of the fourth device.
  • the processor 1202 is further configured to:
  • the processor 1202 is configured to:
  • the processor 1202 is further configured to route and forward the service flow of the terminal through at least one other first device, so as to enable the terminal to obtain the information provided by the second device connected to at least one other first device.
  • the processor 1202 is further configured to monitor network traffic and/or network status; and report at least one of the following information to the third device through the communication interface 1201:
  • the processor 1202 is further configured to obtain network information of at least one network (including 5G network and/or third-party network) through the communication interface 1201, so as to provide it to the required equipment (such as MEAO) .
  • network information of at least one network including 5G network and/or third-party network
  • MEAO required equipment
  • the processor 1202 is configured to obtain the network information of the third-party network from the management device of the third-party network through the communication interface 1201, and/or obtain the network information of the third-party network from the management device of the 5G network through the communication interface 1201 Get network information for 5G networks.
  • bus system 1204 various components in the first device 1200 are coupled together through the bus system 1204 .
  • the bus system 1204 is used to realize connection and communication between these components.
  • the bus system 1204 also includes a power bus, a control bus and a status signal bus.
  • the various buses are labeled as bus system 1204 in FIG. 12 for clarity of illustration.
  • the memory 1203 in the embodiment of the present application is used to store various types of data to support the operation of the first device 1200 .
  • Examples of such data include: any computer programs for operating on the first device 1200 .
  • the methods disclosed in the foregoing embodiments of the present application may be applied to the processor 1202 or implemented by the processor 1202 .
  • the processor 1202 may be an integrated circuit chip, which has a signal processing capability. In the implementation process, each step of the above method may be completed by an integrated logic circuit of hardware in the processor 1202 or instructions in the form of software.
  • the aforementioned processor 1202 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and the like.
  • DSP Digital Signal Processor
  • the processor 1202 may implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application.
  • a general purpose processor may be a microprocessor or any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present application may be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor.
  • the software module may be located in a storage medium, and the storage medium is located in the memory 1203, and the processor 1202 reads the information in the memory 1203, and completes the steps of the foregoing method in combination with its hardware.
  • the first device 1200 may be implemented by one or more Application Specific Integrated Circuit (ASIC, Application Specific Integrated Circuit), DSP, Programmable Logic Device (PLD, Programmable Logic Device), complex programmable logic device (CPLD, Complex Programmable Logic Device), field-programmable gate array (FPGA, Field-Programmable Gate Array), general-purpose processor, controller, microcontroller (MCU, Micro Controller Unit), microprocessor (Microprocessor), or others Electronic components are implemented for performing the aforementioned methods.
  • ASIC Application Specific Integrated Circuit
  • DSP Programmable Logic Device
  • PLD Programmable Logic Device
  • CPLD Complex Programmable Logic Device
  • FPGA Field-Programmable Gate Array
  • controller controller
  • microcontroller MCU, Micro Controller Unit
  • microprocessor Microprocessor
  • the memory 1203 in this embodiment of the present application may be a volatile memory or a nonvolatile memory, and may also include both volatile and nonvolatile memories.
  • the non-volatile memory can be read-only memory (ROM, Read Only Memory), programmable read-only memory (PROM, Programmable Read-Only Memory), erasable programmable read-only memory (EPROM, Erasable Programmable Read-Only Memory) Only Memory), Electrically Erasable Programmable Read-Only Memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), Magnetic Random Access Memory (FRAM, ferromagnetic random access memory), Flash Memory (Flash Memory), Magnetic Surface Memory , CD, or CD-ROM (Compact Disc Read-Only Memory); magnetic surface storage can be disk storage or tape storage.
  • the volatile memory may be random access memory (RAM, Random Access Memory), which is used as an external cache.
  • RAM random access memory
  • RAM Random Access Memory
  • many forms of RAM are available, such as Static Random Access Memory (SRAM, Static Random Access Memory), Synchronous Static Random Access Memory (SSRAM, Synchronous Static Random Access Memory), Dynamic Random Access Memory Memory (DRAM, Dynamic Random Access Memory), synchronous dynamic random access memory (SDRAM, Synchronous Dynamic Random Access Memory), double data rate synchronous dynamic random access memory (DDRSDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), enhanced Synchronous Dynamic Random Access Memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), Synchronous Link Dynamic Random Access Memory (SLDRAM, SyncLink Dynamic Random Access Memory), Direct Memory Bus Random Access Memory (DRRAM, Direct Rambus Random Access Memory ).
  • SRAM Static Random Access Memory
  • SSRAM Synchronous Static Random Access Memory
  • DRAM Dynamic Random Access Memory
  • SDRAM Synchronous Dynamic Random Access Memory
  • the embodiment of the present application also provides a storage medium, that is, a computer storage medium, specifically a computer-readable storage medium, for example, including a memory 1203 storing a computer program.
  • the processor 1202 executes to complete the steps in the foregoing method.
  • the computer-readable storage medium can be memories such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disk, or CD-ROM.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请公开了一种通信系统、方法、装置、第一设备及存储介质。其中,通信系统包括:至少一个第一设备、至少一个第二设备、至少一个用户面功能(UPF);每个第一设备连接至少一个第二设备;每个第一设备连接至少一个UPF;所述第一设备,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。

Description

通信系统、方法、装置、第一设备及存储介质
相关申请的交叉引用
本申请基于申请号为202110703927.1、申请日为2021年06月24日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此引入本申请作为参考。
技术领域
本申请涉及通信领域,尤其涉及一种通信系统、方法、装置、第一设备及存储介质。
背景技术
第五代移动通信技术(5G)作为新一代通信技术,具有大带宽、低时延、高可靠、高连接、泛在网等诸多优势,从而推动垂直行业的快速发展与更迭,比如智慧医疗、智慧教育、智慧农业等方向的崛起。
多接入边缘计算(MEC)技术作为5G演进的关键技术之一,是具备无线网络信息应用程序接口(API)交互能力,以及计算、存储、分析功能的信息技术(IT)通用平台;依托MEC技术,可将传统外部应用拉入运营商内部,为用户提供本地化的应用服务,更贴近用户,从而提升用户体验,发挥边缘网络的更多价值。
将5G和MEC技术结合,可以面向不同的行业需求场景,引入不同的技术组合,比如服务质量(QoS)、端到端网络切片、网络能力开放、边缘云等,从而提供定制化的解决方案。
相关技术中,如图1所示,5G与MEC技术结合的方案主要包括:
1)为了使能垂直行业低时延、高带宽、高可靠边缘应用,用户面功能(UPF)下沉到行业客户园区,靠近MEC边缘服务器(也可以称为MEC平台(MEP)),通过UPF的本地分流技术(即上行过滤器/IPv6分支点(UL-CL/IPv6 BP,Uplink Classifier/IPv6 Branching Point))将数据转发到MEP;
2)核心网中的应用功能(AF,Application Function)下沉到MEP侧,为部署于MEP上的应用提供更好的数据流控制策略(比如编码策略、QoS策略、路由策略等)。
然而,上述5G与MEC技术结合的方案存在安全风险。
发明内容
为解决相关技术问题,本申请实施例提供一种通信系统、方法、装置、第一设备及存储介质。
本申请实施例的技术方案是这样实现的:
本申请实施例提供了一种通信系统,包括:至少一个第一设备、至少一个第二设备、至少一个UPF;其中,
每个第一设备连接至少一个第二设备;每个第一设备连接至少一个UPF;
所述第一设备,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
上述方案中,所述第一设备,还配置为对连接的第二设备进行接入认证。
上述方案中,所述系统还包括:第三设备;其中,
所述第二设备,配置为向所述第一设备发送接入认证信息;接收所述第一设备返回的认证响应信息;
所述第一设备,配置为接收所述第二设备发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第二设备返回认证响应信息;
所述第三设备,配置为接收所述第一设备发送的接入认证信息,利用所述接入认证信息对所述第二设备进行接入认证,并向所述第一设备返回认证响应信息。
上述方案中,所述接入认证信息包含所述第二设备的特征。
上述方案中,所述特征包含以下至少之一:
网际互连协议(IP)地址段;
承载的应用;
业务优先级。
上述方案中,所述第一设备,还配置为控制第二设备对网络能力的访问。
上述方案中,
所述第三设备,还配置为向所述第一设备发送第一策略;
所述第一设备,还配置为接收所述第三设备发送的第一策略,基于所述第一策略为第二设备提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备对网络能力的访问。
上述方案中,所述系统还包括:至少一个第三方网络;其中,
所述第三方网络,配置为为终端提供网络接入;
所述第一设备,还配置为为所述终端选择对应的第二设备,并将对应 第二设备提供的应用通过所述第三方网络提供给所述终端。
上述方案中,所述第一设备,还配置为对第三方网络进行接入认证。
上述方案中,所述系统还包括:第三设备;其中,
所述第三方网络,配置为向所述第一设备发送接入认证信息;并接收所述第一设备返回的认证响应信息;
所述第一设备,配置为接收所述第三方网络发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第三方网络返回认证响应信息;
所述第三设备,配置为接收所述第一设备发送的接入认证信息,利用所述接入认证信息对所述第三方网络进行接入认证,并向所述第一设备返回认证响应信息。
上述方案中,所述接入认证信息包含第三方网络的特征。
上述方案中,所述特征包含以下至少之一:
最大带宽;
带宽控制粒度;
IP地址段;
业务优先级;
承载的应用。
上述方案中,所述第一设备,配置为接入认证通过后,基于安全机制与所述第三方网络进行数据传输。
上述方案中,所述第一设备,还配置为控制所述第三方网络的接入能力。
上述方案中,
所述第三设备,还配置为向所述第一设备发送第二策略;
所述第一设备,还配置为接收所述第三设备发送的第二策略,基于所述第二策略控制所述第三方网络的接入能力。
上述方案中,所述第二策略包含以下之一:
第一接入控制策略;所述第一接入控制策略针对单个第三方网络;
第二接入控制策略;所述第二接入控制策略针对一种类型的第三方网络;
第三接入控制策略;所述第三接入控制策略针对所有第三方网络。
上述方案中,所述第一设备,配置为向所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力;
所述第三方网络,配置为接收所述第一设备发送的第一信息,利用所述第一信息调整自身的接入能力。
上述方案中,所述系统还包括:至少一个第四设备;其中,
所述第四设备,配置为为所述第一设备提供网络能力信息。
上述方案中,所述第一设备,还配置为对第四设备进行接入认证。
上述方案中,所述系统还包括:第三设备;其中,
所述第四设备,还配置为向所述第一设备发送接入认证信息;接收所述第一设备返回的认证响应信息;
所述第一设备,配置为接收所述第四设备发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第四设备返回认证响应信息;
所述第三设备,配置为利用所述接入认证信息对所述第四设备进行接入认证,并向所述第一设备返回认证响应信息。
上述方案中,
所述第一设备,还配置为控制所述第四设备的接入能力。
上述方案中,所述第一设备,配置为向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力;
所述第四设备,配置为接收所述第一设备发送的第二信息,利用所述第二信息调整自身的接入能力。
上述方案中,
所述第三设备,还配置为向所述第一设备发送第三策略;
所述第一设备,还配置为接收所述第三设备发送的第三策略,并基于所述第三策略控制所述第四设备的接入能力。
上述方案中,所述第一设备,配置为通过至少一个其他第一设备,将终端的业务流进行路由转发,以实现所述终端获取至少一个其他第一设备连接的第二设备提供的应用。
上述方案中,所述系统还包括:第三设备,配置为控制所述至少一个第一设备。
上述方案中,所述第三设备,还配置为对所述至少一个第一设备进行认证。
上述方案中,
所述第一设备,配置为向所述第三设备发送认证信息;并接收所述第三设备返回的认证响应信息;
所述第三设备,配置为接收所述第一设备发送的认证信息,并利用所述认证信息对所述第一设备进行认证,并向所述第一设备返回认证响应信息。
上述方案中,所述第一设备,还配置为监控网络的流量和/或网络状态;并向所述第三设备上报以下信息至少之一:
网络的流量;
计费信息;
网络状态的监控信息;
网络能力的使用信息;
第二设备状态的监控信息。
本申请实施例还提供了一种通信方法,应用于第一设备,包括:
为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
上述方案中,所述方法还包括:
对连接的第二设备进行接入认证;
和/或,
控制第二设备对网络能力的访问。
上述方案中,所述对连接的第二设备进行接入认证,包括:
接收所述第二设备发送的接入认证信息;
将所述接入认证信息发送给第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第二设备返回认证响应信息。
上述方案中,所述接入认证信息包含所述第二设备的特征。
上述方案中,所述特征包含以下至少之一:
IP地址段;
承载的应用;
业务优先级。
上述方案中,所述方法还包括:
接收第三设备发送的第一策略;
基于所述第一策略为第二设备提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备对网络能力的访问。
上述方案中,所述方法还包括:
为接入第三方网络的终端选择对应的第二设备,将对应第二设备提供的应用通过所述第三方网络提供给所述终端。
上述方案中,所述方法还包括:
对所述第三方网络进行接入认证。
上述方案中,所述对所述第三方网络进行接入认证,包括:
接收所述第三方网络发送的接入认证信息;
将所述接入认证信息发送给所述第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第三方网络返回认证响应信息。
上述方案中,所述接入认证信息包含第三方网络的特征。
上述方案中,所述特征包含以下至少之一:
最大带宽;
带宽控制粒度;
IP地址段;
业务优先级;
承载的应用。
上述方案中,
接入认证通过后,基于安全机制与所述第三方网络进行数据传输。
上述方案中,所述方法还包括:
控制所述第三方网络的接入能力。
上述方案中,所述方法还包括:
接收第三设备发送的第二策略;
基于所述第二策略控制所述第三方网络的接入能力。
上述方案中,所述第二策略包含以下之一:
第一接入控制策略;所述第一接入控制策略针对单个第三方网络;
第二接入控制策略;所述第二接入控制策略针对一种类型的第三方网络;
第三接入控制策略;所述第三接入控制策略针对所有第三方网络。
上述方案中,所述控制所述第三方网络的接入能力,包括:
向所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力。
上述方案中,所述方法还包括:
接收第四设备发送的网络能力信息。
上述方案中,所述方法还包括:
控制所述第四设备的接入能力;
和/或,
对第四设备进行接入认证。
上述方案中,所述控制所述第四设备的接入能力,包括:
向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力。
上述方案中,所述方法还包括:
接收所述第三设备发送的第三策略;
基于所述第三策略控制所述第四设备的接入能力。
上述方案中,所述对第四设备进行接入认证,包括:
接收所述第四设备发送的接入认证信息;
将所述接入认证信息发送给第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第四设备返回认证响应信息。
上述方案中,所述方法还包括:
通过至少一个其他第一设备,将终端的业务流进行路由转发,以实现所述终端获取至少一个其他第一设备连接的第二设备提供的应用。
上述方案中,所述方法还包括:
监控网络的流量和/或网络状态;并向第三设备上报以下信息至少之一:
网络的流量;
计费信息;
网络状态的监控信息;
网络能力的使用信息;
第二设备状态的监控信息。
本申请实施例还提供了一种通信装置,设置在第一设备上,包括:
处理单元,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
本申请实施例还提供了一种第一设备,包括:处理器及通信接口;其中,
所述处理器,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
本申请实施例还提供了一种第一设备,包括:处理器及和配置为存储能够在处理器上运行的计算机程序的存储器,
其中,所述处理器配置为运行所述计算机程序时,执行上述任一方法的步骤。
本申请实施例还提供了一种存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现上述任一方法的步骤。
本申请实施例提供的通信系统、方法、装置、第一设备及存储介质,所述通信系统包括:至少一个第一设备、至少一个第二设备、至少一个UPF;其中,每个第一设备连接至少一个第二设备;每个第一设备连接至少一个UPF;所述第一设备为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。本申请实施例的方案,通过第一设备,实现UPF与第二设备(比如MEP)之间的网络能力开放的业务代理;如此,能够保障通信系统的数据安全,提高通信系统的网络安全能力,从而提升用户体验。
附图说明
图1为相关技术中5G与MEC技术结合的系统结构示意图;
图2为本申请实施例通信系统结构示意图;
图3为本申请实施例通信方法的流程示意图;
图4为本申请应用实施例5G行业云网融合的系统结构示意图;
图5为本申请应用实施例5G行业云网融合的网络能力开放架构示意图;
图6为本申请应用实施例接口形式的5G行业云网融合的系统结构示意图;
图7为本申请应用实施例实现行业网关对第三方网络的接入认证功能和接入控制功能的流程示意图;
图8为本申请应用实施例实现行业网关对第三方网络能力的接入认证功能和接入控制功能的流程示意图;
图9为本申请应用实施例实现行业网关对MEP的接入认证功能和接入控制功能的流程示意图;
图10为本申请应用实施例实现面向MEP的网络能力开放功能和自服务网络安全管控功能的流程示意图;
图11为本申请实施例通信装置结构示意图;
图12为本申请实施例第一设备结构示意图。
具体实施方式
下面结合附图及实施例对本申请再作进一步详细的描述。
相关技术中,图1所示的5G与MEC技术结合的方案具体存在以下安全风险:
第一,UPF与MEP的部署位置导致的安全风险。
具体地,UPF与MEP在功能逻辑上是分开的,但可以通过两种方式部署,分别是:合并部署与分离部署;其中,合并部署是指将UPF与MEP部署在同一机房甚至同一物理设备上;分离部署是指将UPF与MEP部署在不同机房。实际应用时,合并部署方式并不适用于垂直行业(比如智慧医疗、智慧教育、智慧农业等),这是因为:如果将UPF与MEP合并部署在运营商机房,则违背了行业客户对其应用数据不能出园区的安全要求;而如果将UPF与MEP合并部署在行业客户园区机房,则非常不利于运营商的运维,且会提升针对整个核心网的安全风险。因此,对于垂直行业应用,UPF与MEP应分离部署,具体地,可以将UPF部署于运营商机房,并将MEP部署于行业客户园区机房。然而,在UPF与MEP分离部署的场景下,无法保障UPF与MEP之间的数据安全,存在安全风险。
第二,泛在网络接入导致的安全风险。
具体地,图1所示的架构并未涉及非5G网络的接入和数据传输,换句话说,相关技术并未给出5G与MEC技术结合时非5G网络的接入方案。而垂直行业的终端的接入技术类型繁多,除5G外,还包括第四代移动通信技术(4G)、WiFi、蓝牙(Bluetooth)、紫蜂(Zigbee)、窄带物联网(NB-IoT)、有线网络(Wireline)等,这些非5G网络接入的终端数据可能无法通过5G网络传输到MEP,使MEP无法对各种接入技术类型的终端数据进行接入控制、流量管控和安全监控,无法保障MEP的网络与数据安全,存在安全风 险。
第三,网络能力开放导致的安全风险。
具体地,如图1所示,相关技术中,通过MEP上的AF与5G核心网(5GC)的网络开放功能(NEF,Network Exposure Function)对接来实现MEP的网络能力开放功能(英文可以表示为Service Capability Exposure Function,缩写为SCEF)。然而,由于每个MEP上的安全等级不统一,当MEP向外开放网络能力时,可能因为某个MEP上的网络能力应用存在安全漏洞或是某个MEP本身的安全机制问题,导致核心网遭受攻击,存在安全风险。
另外,相关技术中,MEP只能从5GC获取网络能力,而5GC所能提供的网络能力不能完全满足及精准覆盖垂直行业的业务需求,比如不能提供非5G网络接入的终端的位置信息。同时,MEP网络能力获取数据源多样,包括5GC、无线接入网(RAN)以及第三方系统等,但相关技术中缺少对网络能力的统一认证、统一监管和统一结算的方案。
第四,本地分流导致的安全风险。
具体地,如图1所示,相关技术中,终端到本地MEP的数据转发依赖于UPF的UL-CL/IPv6 BP技术,该技术基于报文的IP五元组或前缀来实现本地分流。实际应用时,对于垂直行业,使用UL-CL/IPv6 BP技术进行本地分流,会在公网上暴露行业用户的MEP的IP地址信息,不仅有用户隐私数据泄露的风险,而且可能会导致针对MEP IP地址的网络攻击,存在网络安全风险。
其中,实际应用时,为了避免使用UL-CL/IPv6 BP技术进行本地分流导致的网络安全风险,还可以考虑采用为MEP设置专用数据网络名称(DNN,Data Network Name)的方式来实现本地分流。然而,这种方式需要为每个MEP都配置一个单独的DNN,需要在核心网进行大量的DNN配置。并且,针对一个终端访问多个MEP的场景,用户需要在终端上不断的切换DNN,严重影响用户体验。
另外,实际应用时,在垂直行业应用场景中,除本地分流的需求外,还存在MEP之间广域互联的需求,比如不同医院之间的数据共享、远程协同诊断等场景。然而,相关技术中,UPF只支持终端到数据网络(DN,Data Network)的协议数据单元(PDU,Protocol Data Unit)会话,不支持DN到DN的连接。换句话说,UPF只支持终端到MEP的数据连接,不支持MEP之间的互联。
基于此,在本申请的各种实施例中,设置第一设备(可以称为网关),通过第一设备,实现UPF与第二设备(比如MEP)之间的网络能力开放的业务代理;如此,能够保障通信系统的数据安全,提高通信系统的网络安全能力,从而提升用户体验。
本申请实施例提供一种通信系统,如图2所示,该系统包括:至少一 个第一设备201、至少一个第二设备202、至少一个UPF 203;其中,
每个第一设备201连接至少一个第二设备202;每个第一设备201连接至少一个UPF 203;
所述第一设备201,配置为为UPF 203发送的边缘网络的业务流量分配对应的第二设备202,以将边缘网络的业务流量分流至对应的第二设备202,并为第二设备202提供的应用提供安全访问控制功能。
其中,实际应用时,所述第一设备201设置在UPF 203与第二设备202之间,所述第一设备201可以称为网关,也可以称为行业网关,本申请实施例对所述第一设备201的名称不作限定,只要能实现所述第一设备201的功能即可。
所述第二设备202可以是MEC网络中的设备,比如MEP,也就是说,所述第二设备202可以称为MEP,也可以称为MEC服务器,本申请实施例对所述第二设备202的名称不作限定,只要能实现所述第二设备202的功能即可。
实际应用时,所述第二设备202提供的应用可以理解为应用服务或应用程序。
实际应用时,针对同一DNN内包含多个MEP的本地分流,由第一设备201为UPF 203发送的边缘网络的业务流量分配对应的第二设备202,与上述的依赖UPF的UL-CL/IPv6 BP技术相比,能够避免使用UL-CL/IPv6 BP技术进行本地分流导致的第二设备202的IP地址信息在公网上的暴露,从而提高通信系统的网络安全能力;另一方面,与采用为MEP设置专用DNN的方案相比,无需在核心网进行大量的DNN配置;并且,针对一个终端访问多个MEP的场景,也无需用户在终端上不断的切换DNN,从而能够提升用户体验。
实际应用时,所述第一设备201需要对所述第二设备202进行接入认证,以确定所述第二设备202的身份。
基于此,在一实施例中,所述第一设备201,还可以配置为:
对连接的第二设备202进行接入认证。
实际应用时,可以由所述第二设备202主动或被动地触发接入认证流程,所述接入认证流程可以利用远程用户拨号认证服务(RADIUS,Remote Authentication Dial In User Service)实现。
实际应用时,所述第二设备202可以通过所述第一设备201与运营商的管理系统进行交互,以实现接入认证。
基于此,在一实施例中,所述系统还可以包括:第三设备;其中,
所述第二设备202,可以配置为向所述第一设备201发送接入认证信息;接收所述第一设备201返回的认证响应信息;
所述第一设备201,可以配置为接收所述第二设备202发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回 的认证响应信息,以及向所述第二设备202返回认证响应信息;
相应地,所述第三设备,可以配置为接收所述第一设备201发送的接入认证信息,利用所述接入认证信息对所述第二设备202进行接入认证,并向所述第一设备返回认证响应信息。
这里,所述第三设备可以称为运营商的管理系统,比如具体可以是业务支撑系统(BSS,Business Support System)或运营支撑系统(OSS,Operation Support System)。本申请实施例对所述第三设备的名称不作限定,只要实现所述第三设备的功能即可。
在一实施例中,所述接入认证信息可以包含所述第二设备202的特征。
其中,所述特征可以包含以下至少之一:
IP地址段(即IP地址范围);
承载的应用;
业务优先级。
实际应用时,每个第一设备201可能连接多个第二设备202,所述多个第二设备202可以通过对应的第一设备201进行网络数据的接收与发送;相应地,所述第一设备201可以根据连接的多个第二设备202中每个第二设备202的业务优先级,对所述多个第二设备202进行资源调度,比如,为业务优先级高的第二设备202提供更高的带宽,再比如,在网络拥塞时优先转发源设备或目的设备为业务优先级高第二设备202的数据。
实际应用时,第二设备202的业务优先级可以利用字段“高”、“中”或“低”来表示;或者,所述业务优先级也可以用数字表示,数字越大,业务优先级越高。
实际应用时,第二设备202的接入认证信息还可以包含第二设备202对应的用户名(即具有第二设备202注册权限的用户名)、用户名对应的密钥等内容。第二设备202的认证响应信息可以包含认证结果;在所述认证结果表征认证成功的情况下,所述认证响应信息还可以包含相应第二设备202的身份标识;在所述认证结果表征认证失败的情况下,所述认证响应信息还可以包含认证失败原因。
在一实施例中,所述第一设备201,还配置为控制第二设备202对网络能力的访问。
实际应用时,所述第一设备201可以基于本地预设的策略为第二设备202提供的应用提供安全访问控制功能,和/或基于本地预设的策略控制第二设备202对网络能力的访问;或者,所述第一设备201也可以从所述第三设备获取用于为第二设备202提供的应用提供安全访问控制功能和/或控制第二设备202对网络能力的访问的策略。
基于此,在一实施例中,所述第三设备,还可以配置为向所述第一设备201发送第一策略;
相应地,所述第一设备201,还可以配置为接收所述第三设备发送的第 一策略,基于所述第一策略为第二设备202提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备202对网络能力的访问。
实际应用时,为了满足垂直行业的业务需求,所述通信系统还可以包括第三方网络;所述第一设备201还可以实现第三方网络与第二设备202之间的网络能力开放的业务代理。
基于此,在一实施例中,所述系统还可以包括:至少一个第三方网络;其中,
所述第三方网络,可以配置为为终端提供网络接入;
所述第一设备201,还可以配置为为所述终端选择对应的第二设备202,并将对应第二设备202提供的应用通过所述第三方网络提供给所述终端。
实际应用时,所述第三方网络可以理解为非5G网络,比如4G、WiFi、Bluetooth、Zigbee、NB-IoT、Wireline等。
实际应用时,所述终端可以称为用户设备(UE,User Equipment),也可以称为用户。
实际应用时,所述第一设备201具体可以基于所述第一策略为第二设备202提供的应用提供核心网和所述第三方网络的安全访问控制功能,和/或,基于所述第一策略控制第二设备202对所述核心网和所述第三方网络的网络能力的访问。
实际应用时,所述第一策略可以包含所述第一设备201的身份标识、对应的第二设备202的身份标识、第一设备201与第二设备202之间的传输通道的加密策略、对应的第二设备202允许访问的网络能力类型列表、对应的第二设备202允许访问的网络能力API列表、对应的第二设备202对网络能力API的最大调用次数、对应的第二设备202允许访问的自服务网络安全管控API列表、对应的第二设备202连接第一设备201的开启或关闭指示、第一设备201与第二设备202之间的传输通道的最大带宽、第一设备201与第二设备202之间的传输通道的最大流量等信息。
实际应用时,所述加密策略可以包括:采用互联网协议安全(IPSec,Internet Protocol Security)协议实现远程接入的虚拟专用网络(VPN,Virtual Private Network)技术。具体地,所述第一设备201可以通过第一隧道与所述第二设备202进行数据传输,所述第一隧道可以是采用IPSec协议实现远程接入的VPN技术实现的加密隧道。
实际应用时,所述第一设备201基于所述第一策略控制第二设备202对网络能力的访问时,具体可以基于所述第一策略,向对应的所述第二设备202发送第三信息,所述第三信息用于指示相应第二设备202对网络能力的访问;相应地,所述第二设备202,可以配置为接收所述第一设备201发送的第三信息,利用所述第三信息调整自身对网络能力的访问。
实际应用时,所述第三信息可以包含相应第二设备202的身份标识、相应第二设备202允许访问的网络能力API列表、相应第二设备202允许 访问的自服务网络安全管控API列表、相应第二设备202连接第一设备201的开启或关闭指示等内容。可以理解,所述第二设备202接收到所述第三信息后,可以根据所述第三信息包含的连接第一设备201的开启或关闭指示,开启或关闭与对应的第一设备201的连接。
实际应用时,所述网络能力API列表和所述自服务网络安全管控API列表中的API是开放的API(Open API),所述第一设备201可以通过这些Open API与连接的至少一个第二设备202进行交互,在为各第二设备202中的不同用户类别提供资源域权限控制与安全访问功能(即为第二设备202提供的应用提供安全访问功能)的同时,实现用户对网络、计算等资源的自服务管理等层面的操作。
具体地,所述第二设备202可以通过Open API操作连接的第一设备201的自服务管理功能,比如网络分区权限管理、网络性能要求、业务路由策略、网络切片模板、定位区域大小及位置、接入用户标识等方面的功能。这里,所述第二设备202可以向所述第一设备201发送对应的管理功能信息,来实现自服务管理功能。其中,网络分区权限管理是指为不同的第二设备202选择不同的网络接入方式(比如4G、5G、WiFi、Bluetooth、Zigbee、NB-IoT、Wireline等),比如,优先级高的第二设备202只允许Wireline的网络接入方式,优先级低的第二设备202可以允许WiFi、Bluetooth等网络接入方式。实际应用时,网络性能要求可以理解为第二设备202对带宽的要求;网络切片模板的功能是指对网络切片模板的代理;定位区域大小及位置的功能用于供第二设备202确定允许接入哪些区域内的终端;所述接入用户标识可以包括手机号码、用户名或应用身份标识(ID)。
实际应用时,所述第二设备202可以通过所述网络能力API列表中的网络能力API,从连接的第一设备201获取网络能力开放数据,获取的网络能力开放数据符合相应网络能力API的定义;所述网络能力开放数据可以包括:定位能力标签(比如5G、WiFi、Bluetooth或全球定位系统(GPS)等)、定位数据、接入用户信息、第三方网络接入列表、网络切片能力数据、QoS能力数据等。
实际应用时,所述第二设备202还可以通过所述自服务网络安全管控API列表中的自服务网络安全管控API,从连接的第一设备201获取网络能力开放数据,并基于网络能力开放数据向连接的第一设备201发送第一指令;所述第一指令用于指示自服务网络安全管控,即所述第一指令指示对应的管理功能信息;所述第一指令符合相应自服务网络安全管控API的定义,所述第一指令可以包含网络分区权限管理、网络性能要求、业务路由策略、网络切片模板配置、定位区域大小及位置配置、接入用户ID配置(比如手机号码、用户名或者应用ID)等内容。
实际应用时,所述第一设备201可以通过自身的第一接口,与连接的第二设备202进行数据传输;比如,所述第一设备201可以通过所述第一 接口接收所述第二设备202发送的接入认证信息,并通过所述第一接口向所述第二设备202返回认证响应信息;再比如,所述第一接口可以承载所述第二设备202为用户提供的服务。
实际应用时,所述第一设备201需要对所述第三方网络进行接入认证。
基于此,在一实施例中,所述第一设备201,还可以配置为对第三方网络进行接入认证。
实际应用时,所述第三方网络可以通过所述第一设备201与运营商的管理系统进行交互,以实现接入认证。
基于此,在一实施例中,所述第三方网络,可以配置为向所述第一设备201发送接入认证信息;并接收所述第一设备201返回的认证响应信息;
所述第一设备201,可以配置为接收所述第三方网络发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第三方网络返回认证响应信息;
相应地,所述第三设备,可以配置为接收所述第一设备201发送的接入认证信息,利用所述接入认证信息对所述第三方网络进行接入认证,并向所述第一设备201返回认证响应信息。
这里,在一实施例中,所述接入认证信息可以包含第三方网络的特征。
其中,所述特征可以包含以下至少之一:
最大带宽;
带宽控制粒度;
IP地址段;
业务优先级;
承载的应用。
实际应用时,每个第一设备201可以连接多个第三方网络,所述多个第三方网络可以通过相应的第一设备201与对应的第二设备202进行网络数据的接收和发送;相应地,所述第一设备201可以根据连接的多个第三方网络中每个第三方网络的业务优先级,对所述多个第三方网络进行资源调度,比如,为业务优先级高的第三方网络提供更高的带宽,再比如,在网络拥塞时优先转发业务优先级高的第三方网络的数据。
实际应用时,第三方网络的业务优先级可以利用字段“高”、“中”或“低”来表示;或者,所述业务优先级也可以用数字表示,数字越大,业务优先级越高。
实际应用时,第三方网络的接入认证信息还可以包含第三方网络对应的用户名(即具有第三方网络注册权限的用户名)、用户名对应的密钥、用于表征网络类型(比如4G、WiFi、Bluetooth、Zigbee、NB-IoT、Wireline等)的网络标识等内容。第三方网络的认证响应信息可以包含认证结果;在所述认证结果表征认证成功的情况下,所述认证响应信息还可以包含相应第三方网络对应的身份标识;在所述认证结果表征认证失败的情况下, 所述认证响应信息还可以包含认证失败原因。
这里,第三方网络的接入认证通过后,所述第一设备201可以基于安全机制与所述第三方网络进行数据传输。
基于此,在一实施例中,所述第一设备201,可以配置为接入认证通过后,基于安全机制与所述第三方网络进行数据传输。
实际应用时,第三方网络的接入认证通过后,所述第一设备201还可以基于连接的各个第三方网络的网络标识,实现对不同网络的接入管理、控制、运营与运维等功能。
基于此,在一实施例中,所述第一设备201,还可以配置为控制所述第三方网络的接入能力。
实际应用时,所述第一设备201可以基于本地预设的策略控制所述第三方网络的接入能力;或者,所述第一设备201也可以从所述第三设备获取用于控制所述第三方网络的接入能力的策略。
基于此,在一实施例中,所述第三设备,还可以配置为向所述第一设备201发送第二策略;
所述第一设备201,还可以配置为接收所述第三设备发送的第二策略,基于所述第二策略控制所述第三方网络的接入能力。
其中,所述第二策略可以包含以下之一:
第一接入控制策略;所述第一接入控制策略针对单个第三方网络;
第二接入控制策略;所述第二接入控制策略针对一种类型的第三方网络;
第三接入控制策略;所述第三接入控制策略针对所有第三方网络。
实际应用时,所述第一设备201可以基于所述第一接入控制策略控制相应第三方网络的能力;所述第一接入控制策略可以包含相应第三方网络对应的身份标识、相应第一设备201的身份标识、相应第三方网络的最大接入带宽、相应第三方网络的最大网络流量、相应第三方网络的最长接入时长、相应第三方网络的最大接入用户数、相应第三方网络的计费策略、以及相应第三方网络接入的开启或关闭指示等信息。
实际应用时,所述第一设备201可以基于所述第二接入控制策略控制相应类型的第三方网络的能力;所述第二接入控制策略可以包含相应类型的第三方网络的网络标识、相应第一设备201的身份标识、相应类型的第三方网络的最大接入带宽、相应类型的第三方网络的最大网络流量、相应类型的第三方网络的最长接入时长、相应类型的第三方网络的最大接入用户数、相应类型的第三方网络的计费策略、以及相应类型的第三方网络接入的开启或关闭指示等信息。
实际应用时,所述第一设备201可以基于所述第三接入控制策略控制所有第三方网络的能力;所述第三接入控制策略可以包含相应第一设备201的身份标识、相应第一设备201连接的所有第三方网络的最大接入带宽、 相应第一设备201连接的所有第三方网络的最大网络流量、相应第一设备201连接的所有第三方网络的最长接入时长、相应第一设备201连接的所有第三方网络的最大接入用户数、相应第一设备201连接的所有第三方网络的计费策略、以及相应第一设备201连接的所有第三方网络接入的开启或关闭指示等信息。
其中,所述第三方网络的计费策略,可以包含以下至少之一:
基于第三方网络的宽带(即最大带宽值)计费;比如按带宽包年包月计费、按带宽使用时长计费等计费模式;
基于第三方网络的流量(即第三方网络实际传输的数据总量)计费;
基于第三方网络的网络切片的类型和数量计费;
基于第三方网络的QoS计费;所述第三方网络的QoS可以包含数据传输的速率、时延、抖动、可靠性等;
基于第三方网络接入的用户数计费;比如按最大接入用户数包月包年计费、按实际接入用户数计费等计费模式。
实际应用时,所述第一设备201需要指示所述第三方网络的接入能力,以便能够控制第三方网络的接入能力。
基于此,在一实施例中,所述第一设备201,可以配置为向所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力;
相应地,所述第三方网络,可以配置为接收所述第一设备201发送的第一信息,利用所述第一信息调整自身的接入能力。
实际应用时,所述第一信息可以包含相应第三方网络对应的身份标识以及相应第三方网络接入的开启或关闭指示、第三方网络接入开启时网络能力列表等内容。这里,所述第三方网络接入开启时网络能力列表可以包含带宽、带宽控制粒度、接入用户数等。
实际应用时,所述第一设备201可以通过自身的第二接口,与连接的第三方网络进行数据传输;比如,所述第一设备201可以通过所述第二接口接收所述第三方网络发送的接入认证信息,并通过所述第二接口向所述第三方网络返回认证响应信息;再比如,所述第一设备201可以通过所述第二接口向所述第三方网络发送所述第一信息。
实际应用时,所述第一设备201可以通过第二隧道与所述第三方网络进行数据传输,所述第二隧道可以实现对接入网络数据的二次封装以保障数据安全、统一协议解析与适配等功能。
实际应用时,所述第一设备201还可以获取各种网络(比如包含5G网络和/或第三方网络)的网络信息,以提供给需要的设备,比如发送给MEC编排器(MEO,MEC Orchestrator)(也可以称为MEC应用编排器(MEAO,MEC Application Orchestrator),使得MEO至少可以利用所述至少一个网络的网络信息编排所述第二设备202上的应用和可用资源。示例性地,所述第一设备201可以从第三方网络的管理设备获得第三方网络的网络信息, 可以从5G的管理设备获得5G网络的网络信息。
实际应用时,所述第一设备需要获取各种网络(比如包含5G网络和/或第三方网络)的网络能力信息。
基于此,在一实施例中,所述系统还包括:至少一个第四设备;其中,
所述第四设备,配置为为所述第一设备201提供网络能力信息。
实际应用时,所述第四设备可以称为网络能力平台,针对除5G网络外的第三方网络,所述第四设备也可以称为第三方网络能力平台,本申请实施例对所述第四设备的名称不作限定,只要能实现所述第四设备的功能即可。
实际应用时,在需要获取5G网络的网络能力的情况下,所述第四设备可以包含核心网的网元,比如AF等;在需要获取第三方网络的网络能力的情况下,所述第四设备可以包含第三方网络的管理设备。当然,所述第四设备也可以从核心网的网络设备或网元获取5G网络的网络能力信息,和/或,从第三方网络的管理设备获取第三方网络的网络能力信息,并将获取的至少一个网络的网络能力信息发送至所述第一设备201。
实际应用时,所述第一设备201需要对所述第四设备进行接入认证。
基于此,在一实施例中,所述第一设备201,还可以配置为对第四设备进行接入认证。
实际应用时,所述第四设备可以通过所述第一设备201与运营商的管理系统进行交互,以实现接入认证。
基于此,在一实施例中,所述第四设备,还可以配置为向所述第一设备201发送接入认证信息;接收所述第一设备201返回的认证响应信息;
所述第一设备201,可以配置为接收所述第四设备发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第四设备返回认证响应信息;
相应地,所述第三设备,可以配置为利用所述接入认证信息对所述第四设备进行接入认证,并向所述第一设备201返回认证响应信息。
实际应用时,所述第四设备的接入认证信息可以包含所述第四设备对应的用户名(即具有第三方网络能力注册权限的用户名)、用户名对应的密钥、用于表征所述第四设备可提供的网络能力列表的类型(比如NEF/策略与计费规则功能(PCRF,Policy and Charging Rules Function)/网络能力开放功能、定位能力、通信服务管理功能(CSMF,Communication Service Management Function)、网络切片能力等)的网络能力标识、所述第四设备可提供的网络能力API列表等内容。
实际应用时,所述第四设备的认证响应信息可以包含认证结果;在所述认证结果表征认证成功的情况下,所述认证响应信息还可以包含所述第四设备的身份标识;在所述认证结果表征认证失败的情况下,所述认证响应信息还可以包含认证失败原因。
实际应用时,所述第四设备的接入认证通过后,所述第一设备201可以控制所述第四设备的接入能力。
基于此,在一实施例中,所述第一设备201,还可以配置为控制所述第四设备的接入能力。
实际应用时,所述第一设备201可以通过向所述第四设备发送指示信息来指示所述第三方网络设备调整自身的接入能力。
基于此,在一实施例中,所述第一设备201,可以配置为向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力;
相应地,所述第四设备,可以配置为接收所述第一设备201发送的第二信息,利用所述第二信息调整自身的接入能力。
实际应用时,所述第二信息可以包含所述第四设备的身份标识以及所述第四设备接入的开启或关闭指示。换句话说,所述第二信息可以用于指示开启或关闭所述第四设备与所述第一设备201的连接。
实际应用时,所述第一设备201可以通过自身的第三接口,与所述第四设备进行数据传输;比如,所述第一设备201可以通过所述第三接口接收所述第四设备发送的接入认证信息,并通过所述第三接口向所述第四设备返回认证响应信息;再比如,所述第一设备201可以通过所述第三接口向所述第四设备发送所述第二信息。当然,所述第一设备201还可以通过所述第三接口,从所述第四设备获取网络能力信息(比如最大带宽、带宽控制粒度、接入用户数等),以实现面向第二设备202的网络能力开放。
实际应用时,所述第一设备201可以基于本地预设的策略控制所述第四设备的接入能力;或者,所述第一设备201也可以从所述第三设备获取用于控制所述第四设备的接入能力的策略。
基于此,在一实施例中,所述第三设备,还可以配置为向所述第一设备发送第三策略;
相应地,所述第一设备201,还可以配置为接收所述第三设备发送的第三策略,并基于所述第三策略控制所述第四设备的接入能力。
其中,所述第三策略可以包含以下之一:
第四接入控制策略;所述第四接入控制策略针对单个第四设备;
第五接入控制策略;所述第五接入控制策略针对一种类型的第四设备;
第六接入控制策略;所述第六接入控制策略针对所有第四设备。
实际应用时,所述第一设备201可以基于所述第四接入控制策略控制相应第四设备的接入能力;所述第四接入控制策略可以包含相应第四设备的身份标识、相应第一设备201的身份标识、相应第四设备提供的网络能力API的最大调用次数、相应第四设备的最长接入时长、相应第四设备的计费策略、以及相应第四设备接入的开启或关闭指示等信息。
实际应用时,所述第一设备201可以基于所述第五接入控制策略控制相应类型的第四设备的接入能力;所述第五控制策略可以包含相应类型的 第四设备的网络能力标识、相应第一设备201的身份标识、相应类型的第四设备提供的网络能力API的最大调用次数、相应类型的第四设备的最长接入时长、相应类型的第四设备的计费策略、以及相应类型的第四设备接入的开启或关闭指示等信息。
实际应用时,所述第一设备201可以基于所述第六接入控制策略控制相应第一设备201连接的所有第四设备的接入能力;所述第六接入控制策略可以包含相应第一设备201的身份标识、相应第一设备201连接的所有第四设备提供的网络能力API的最大调用次数、相应第一设备201连接的所有第四设备的最长接入时长、相应第一设备201连接的所有第四设备的计费策略、以及相应第一设备201连接的所有第四设备接入的开启或关闭指示等信息。
其中,所述第四设备的计费策略,可以包含以下至少之一:
基于第四设备提供的网络能力API的实际调用次数计费;
基于第四设备的流量(即第四设备提供的网络能力实际传输的数据总量)计费;
基于第四设备可提供的网络能力列表的类型计费;即针对不同的网络能力列表的类型指定不同计费模式及价格;
基于第四设备提供的网络能力的数据来源计费;即针对不同的网络能力的数据来源指定不同计费模式及价格。
实际应用时,在所述通信系统包括至少两个第一设备201的情况下,所述至少两个第一设备201之间需要建立连接,以使每个第一设备201可以通过其他第一设备201将终端的业务流进行路由转发。
基于此,在一实施例中,所述第一设备201,可以配置为通过至少一个其他第一设备201,将终端的业务流进行路由转发,以实现所述终端获取至少一个其他第一设备201连接的第二设备202提供的应用。
实际应用时,所述至少两个第一设备201可以组成广域传输网络,实现各园区/组织之间的网络互联互通,以承载多个第二设备202之间的业务协同。
实际应用时,所述第一设备201可以通过自身的第四接口,与至少一个其他第一设备201进行数据传输;所述第四接口可以基于软件定义广域网(SD-WAN,Software Defined Wide Area Network)功能实现。
实际应用时,需要对至少一个第一设备201进行管理和控制。
基于此,在一实施例中,所述第三设备,还可以配置为控制所述至少一个第一设备201。
实际应用时,所述第三设备需要对所述第一设备201进行认证。
基于此,在一实施例中,所述第三设备,还可以配置为对所述至少一个第一设备201进行认证。
具体地,在一实施例中,所述第一设备201,可以配置为向所述第三设 备发送认证信息;并接收所述第三设备返回的认证响应信息;
相应地,所述第三设备,配置为接收所述第一设备201发送的认证信息,并利用所述认证信息对所述第一设备201进行认证,并向所述第一设备201返回认证响应信息。
实际应用时,所述第一设备201的认证信息可以包含所述第一设备201对应的用户名(即具有第一设备201的注册权限的用户名)、用户名对应的密钥、所述第一设备201支持接入的网络类型列表、所述第一设备201支持接入的网络能力类型列表、所述第一设备201支持的最大带宽容量、所述第一设备201支持的带宽控制粒度等内容。
实际应用时,所述第一设备201的认证响应信息可以包含认证结果;在所述认证结果表征认证成功的情况下,所述认证响应信息还可以包含所述第一设备201的身份标识;在所述认证结果表征认证失败的情况下,所述认证响应信息还可以包含认证失败原因。
实际应用时,为了使所述第三设备实现所述通信系统的计费和运营,所述第一设备201需要监控网络的流量和/或网络状态,并将监控到的信息上报给所述第三设备。
基于此,在一实施例中,所述第一设备201,还可以配置为监控网络的流量和/或网络状态;并向所述第三设备上报以下信息至少之一:
网络的流量;
计费信息;
网络状态的监控信息;
网络能力的使用信息;
第二设备状态的监控信息。
实际应用时,所述网络状态的监控信息可以包含所述第一设备201的身份标识、本次网络状态监控对应的统计时间周期、第三方网络状态的统计信息、第四设备状态的统计信息、第二设备202状态的统计信息、以及计费明细等内容。
其中,所述第三方网络状态的统计信息,可以理解为所述第一设备201连接的所有第三方网络中每个第三方网络的状态的监控统计信息;所述第三方网络状态的统计信息可以包含第三方网络的身份标识、第三方网络的网络标识、第三方网络的吞吐率、第三方网络的流量、第三方网络的接入时长等内容。
所述第四设备状态的统计信息,可以理解为所述第一设备201连接的所有第四设备中每个第四设备的状态的监控统计信息;所述第四设备状态的统计信息可以包含第四设备的身份标识、第四设备的网络能力标识、第四设备提供的网络能力API的调用次数、第四设备的流量、第四设备的接入时长等内容。
所述第二设备202状态的统计信息,可以理解为所述第一设备201连 接的所有第二设备202中每个第二设备202的状态的监控统计信息;所述第二设备202状态的统计信息可以包含第二设备202的身份标识、第二设备202的吞吐率、第二设备202的流量、第二设备202对网络能力API的调用次数、第二设备202的接入时长等内容。
实际应用时,所述计费明细,可以根据第三方网络的计费策略及第四设备的计费策略计算生成。
实际应用时,所述第一设备201可以通过自身的第五接口,与所述第三设备进行数据传输;比如,所述第一设备201可以通过所述第五接口向所述第三设备发送认证信息,并通过所述第五接口接收所述第三设备返回的认证响应信息;再比如,所述第一设备201可以通过所述第五接口接收所述第三设备发送的策略(即所述第一策略、所述第二策略和所述第三策略)。当然,所述第一设备201还可以通过所述第五接口向所述第三设备上报信息(即网络的流量、计费信息、网络状态的监控信息、网络能力的使用信息、第二设备状态的监控信息等)。
实际应用时,所述系统还可以包括第五设备,配置为编排所述第二设备202上的应用和可用资源;相应地,所述第一设备201可以从连接的至少一个第三方网络获取每个第三方网络的网络信息,并从核心网的网络设备或网元(比如AF、UPF等)获取5G网络的网络信息,向所述第五设备发送得到的5G网络或第三方网络的网络信息;所述第五设备接收所述第一设备201发送的至少一个网络(可以包含5G网络和/或第三方网络)的网络信息,至少可以利用所述至少一个网络的网络信息编排所述第二设备202上的应用和可用资源。
实际应用时,所述第五设备可以称为MEO或MEAO,本申请实施例对所述第五设备的名称不作限定,只要能实现所述第五设备的功能即可。
实际应用时,所述第一设备201可以通过所述第二接口获取第三方网络的网络信息,通过自身的第六接口从核心网的网络设备或网元获取5G网络的网络信息,并可以通过自身的第七接口向所述第五设备发送得到的5G网络和/或第三方网络的网络信息;所述第五设备接收到至少一个网络的网络信息后,至少可以利用所述至少一个网络的网络信息,对所述第二设备202上的应用和可用资源进行合理、有效地编排;所述合理、有效地编排可以理解为:所述第五设备可以基于所述至少一个网络的网络信息,在编排第二设备202上的应用和可用资源时实现网络的负载均衡,比如,当WiFi网络的运行状态较差时,所述第五设备可以自动将运行在WiFi网络中的应用切换到运行良好的5G网络中运行。
实际应用时,所述网络信息可以包含网络类型(即网络标识)、网络运行状态、网络资费信息、网络的运营维护信息等内容;所述网络资费信息,可以包含网络的计费规则、网络的计费明细、网络的共享配额策略、网络的终端绑定策略、网络的限速策略、网络的限量策略等内容;所述网络的 运营维护信息可以包含网络的带宽限制信息、网络的带宽利用率、网络的上行和/或下行流量的使用情况、流量余额等内容。
基于上述系统架构,本申请实施例还提供了一种通信方法,应用于第一设备,如图3所示,该方法包括:
步骤301:为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
其中,在一实施例中,如图3所示,所述方法还可以包括:
步骤302:对连接的第二设备进行接入认证。
在一实施例中,所述方法还可以包括:
控制第二设备对网络能力的访问。
在一实施例中,所述对连接的第二设备进行接入认证,可以包括:
接收所述第二设备发送的接入认证信息;
将所述接入认证信息发送给第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第二设备返回认证响应信息。
在一实施例中,所述接入认证信息可以包含所述第二设备的特征。
其中,所述特征可以包含以下至少之一:
IP地址段;
承载的应用;
业务优先级。
在一实施例中,所述方法还可以包括:
接收第三设备发送的第一策略;
基于所述第一策略为第二设备提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备对网络能力的访问。
在一实施例中,所述方法还可以包括:
为接入第三方网络的终端选择对应的第二设备,将对应第二设备提供的应用通过所述第三方网络提供给所述终端。
在一实施例中,所述方法还可以包括:
对所述第三方网络进行接入认证。
在一实施例中,所述对所述第三方网络进行接入认证,可以包括:
接收所述第三方网络发送的接入认证信息;
将所述接入认证信息发送给所述第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第三方网络返回认证响应信息。
在一实施例中,所述接入认证信息可以包含第三方网络的特征。
其中,所述特征可以包含以下至少之一:
最大带宽;
带宽控制粒度;
IP地址段;
业务优先级;
承载的应用。
在一实施例中,接入认证通过后,所述第一设备可以基于安全机制与所述第三方网络进行数据传输。
在一实施例中,所述方法还可以包括:
控制所述第三方网络的接入能力。
在一实施例中,所述方法还可以包括:
接收第三设备发送的第二策略;
基于所述第二策略控制所述第三方网络的接入能力。
其中,所述第二策略可以包含以下之一:
第一接入控制策略;所述第一接入控制策略针对单个第三方网络;
第二接入控制策略;所述第二接入控制策略针对一种类型的第三方网络;
第三接入控制策略;所述第三接入控制策略针对所有第三方网络。
在一实施例中,所述控制所述第三方网络的接入能力,可以包括:
向所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力。
在一实施例中,所述方法还可以包括:
接收第四设备发送的网络能力信息。
在一实施例中,所述方法还可以包括:
控制所述第四设备的接入能力;
和/或,
对第四设备进行接入认证。
在一实施例中,所述控制所述第四设备的接入能力,可以包括:
向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力。
在一实施例中,所述方法还可以包括:
接收所述第三设备发送的第三策略;
基于所述第三策略控制所述第四设备的接入能力。
在一实施例中,所述对第四设备进行接入认证,可以包括:
接收所述第四设备发送的接入认证信息;
将所述接入认证信息发送给第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第四设备返回认证响应信息。
在一实施例中,所述方法还可以包括:
通过至少一个其他第一设备,将终端的业务流进行路由转发,以实现 所述终端获取至少一个其他第一设备连接的第二设备提供的应用。
在一实施例中,所述方法还可以包括:
监控网络的流量和/或网络状态;并向第三设备上报以下信息至少之一:
网络的流量;
计费信息;
网络状态的监控信息;
网络能力的使用信息;
第二设备状态的监控信息。
本申请实施例提供的通信系统和通信方法,第一设备为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。本申请实施例的方案,通过第一设备,实现UPF与第二设备(比如MEP)之间的网络能力开放的业务代理;如此,能够保障通信系统的数据安全,提高通信系统的网络安全能力,从而提升用户体验。
下面结合应用实施例对本申请再作进一步详细的描述。
在本应用实施例中,第一设备称为行业网关(英文可以表示为iGW);第二设备为MEP;第三设备称为BSS或OSS系统,简称为BSS/OSS;第四设备称为第三方网络能力。
在本应用实施例中,如图4所示,通过引入行业网关,解决相关技术中5G与MEC技术结合的方案中存在的技术问题。所述行业网关部署在UPF与MEP之间,具备以下五个功能中的至少一种功能:
第一,多制式网络接入控制功能。
具体地,通过所述行业网关,可以实现第三代合作伙伴计划(3GPP)移动网络(比如4G、5G、NB-IoT等)、非3GPP(non-3GPP)移动网络(比如WiFi、Bluetooth、Zigbee等)以及固定网络(比如Wireline、光纤、切片分组网(SPN,Slicing Packet Network)、光传送网(OTN,Optical Transport Network)等)等网络的统一接入与管理。
该功能具有以下关键特性:
1)多制式网络接入能力;即所述行业网关支持3GPP移动网络、non-3GPP移动网络以及固定网络等不同制式的网络的接入能力。
2)多制式网络接入识别与标签功能;即所述行业网关可以对不同制式的网络进行接入认证,并在完成接入认证后,为不同制式的网络添加网络标签(即上述网络标识),以识别不同制式的网络对应的网络类型(比如3GPP移动网络、non-3GPP移动网络以及固定网络等)。所述行业网关还可以基于所述网络标签,实现对不同制式的网络的接入管理、控制、运营及运维等功能。
3)多制式网络的连接建立与释放功能;即所述行业网关可以在相关技术中的IP协议的基础上,融合网络标签、统一认证、网络能力(比如带宽、 带宽控制粒度、接入用户数等)列表、网络接入状态(开启状态(On)/关闭状态(Off))等信息,建立与不同制式的网络的连接,并具备不同制式的网络连接的释放功能。
第二,网络广域互联功能。
具体地,多个行业网关可以组成广域传输网络,实现各园区/组织之间的网络互联互通,以承载多个MEP之间的业务协同。
该功能具有以下关键特性:
1)智能路由功能;即在SD-WAN、网络功能虚拟化基础设施解决方案(NFVI,Network Function Virtualization Infrastructure)等技术的基础上,增加所述行业网关与UE之间的信息交互,交互的信息包括业务路由地址、业务传输QoS要求等内容,以实现从UE到不同MEC边缘云的智能业务访问。其中,所述业务路由地址可以包含DNN和目的MEC的IP地址等内容。
2)MEC实体功能类似UE化;即通过行业网关MEC可以通过有线网络与5GC的接入及移动性管理功能(AMF,Access and Mobility Management Function)、进程管理功能(SMF,Session Management Function)、PCRF等网元直接连接,使得MEC的功能类似于UE,从而通过行业网关,实现了将UE与固定MEC之间的通信、MEC与MEC之间的通信均统一到5GC的接入与管理流程中。
第三,多类型网络能力接入与开放功能。
具体地,所述行业网关可以对接5GC、RAN、第三方网络(即非5G网络,比如4G、WiFi、Bluetooth、Zigbee、NB-IoT、Wireline等)的网络能力,通过统一的API(即Open API)开放给MEP使用,并对网络能力使用情况进行统一监控与结算,实现泛在网络能力的接入与开放功能。
该功能具有以下关键特性:
1)多类型网络能力接入;即所述行业网关可以支持NEF、PCRF、网络能力开放功能(SCEF)、定位能力、CSMF、网络切片等能力的接入。
2)多类型网络能力开放;即所述行业网关可以通过Open API向MEP开放定位能力、接入用户信息、多制式网络接入列表、网络切片能力、QoS等能力。
第四,多制式网络流量监控与计费功能。
具体地,所述行业网关可以作为泛在全连接网络的综合接入设备,实时监控不同制式的网络(即不同类型的网络,比如5G、4G、WiFi、Bluetooth、Zigbee、NB-IoT、Wireline等)的流量与网络使用情况,实现计费功能并实时上报给BSS/OSS,从而实现基于不同量纲的计费与运营策略。
该功能具有以下关键特性:
1)多维度流量与网络监控;即所述行业网关可以支持对不同制式的网络的单独流量统计与网络监控,并通过融合了网络标签、流量数据、网络状态的信令上报给OSS;
2)多维度计费量纲;即所述行业网关可以支持基于不同种类的网络流量、多类型网络能力调用次数或者调度时长、MEP能力等信息进行计费,并通过融合了计费量纲标签和具体的计费数值的信令上报给BSS/OSS。
第五,自服务资源管理功能。
具体地,所述行业网关可以通过Open API与MEP进行交互,在为MEP中的不同用户类别提供资源域权限控制与安全访问控制功能的同时,实现用户对网络、计算等资源的自服务管理等层面的操作;即MEP可以通过Open API操作所述行业网关的网络分区权限管理、网络性能要求(比如带宽)、业务路由策略、网络切片模板(即网络切片模板的代理功能)、定位区域大小及位置、接入用户ID(比如手机号码、用户名或者应用ID)等方面的功能。
其中,网络分区权限管理是指不同的MEP具有不同的网络接入权限,比如优先级高的MEP只允许有线网络接入,优先级低的MEP可以允许WiFi、Bluetooth等网络接入;定位区域大小及位置是指每个MEP可以配置允许哪些区域内的终端接入。
在本应用实施例中,如图5所示,所述行业网关实际上充当了MEP与RAN之间、MEP与5GC之间、以及MEP与第三方系统(可以包括第三方网络和第三方网络能力)之间的网络能力开放的代理角色,在所述行业网关通过代理方式进行网络能力开放的基础上,所述行业网关还可以将网络能力经过处理后,以报告的形式间接开放给MEP。
在本应用实施例中,对所述行业网关与其他功能实体之间的接口进行了全新定义,如图6所示,所述行业网关通过接口I1至I5实现上述功能。
首先,对接口I1(即上述第二接口)的功能进行详细说明。
接口I1是所述行业网关与第三方网络的通信接口,用于实现第三方网络的接入认证功能,并用于承载所述行业网关与所述第三方网络之间的数据传输。
具体地,接口I1支持的关键功能包括:
1)第三方网络的接入认证。这里,第三方网络可以主动或被动地触发接入认证流程,以实现第三方网络的安全接入、接入网络的标识区分(即上述网络标签和网络标识)等功能。
2)第三方网络的接入控制。这里,所述行业网关可以控制是否允许第三方网络接入,并可以主动切断与第三方网络的数据传输等功能。
3)第三方网络的数据传输。这里,所述行业网关可以通过专用的隧道(即上述第二隧道)实现与第三方网络的数据传输功能,该隧道实现对接入网络数据的二次封装以保障数据安全、统一协议解析与适配等功能。
其次,对接口I2(即上述第三接口)的功能进行详细说明。
接口I2是所述行业网关与第三方网络能力的通信接口,用于实现第三方网络能力的接入与认证功能,并用于承载所述行业网关与所述第三方网 络能力之间的数据传输,比如从第三方网络能力获取网络能力数据。
具体地,接口I2支持的关键功能包括:
1)第三方网络能力的接入认证。这里,第三方网络能力可以主动或被动地触发接入认证流程,以实现第三方网络能力的安全接入、接入的网络能力的标识区分(即上述的网络能力标识,可以表征NEF/PCRF/CSMF、定位能力、CSMF、网络切片等能力)等功能。
2)第三方网络能力的接入规则与控制。这里,所述行业网关可以通过网络能力接入状态指示(On/Off)控制是否允许第三方网络能力接入,并可以获取第三方网络能力的网络能力列表(可以包含带宽、带宽控制粒度、接入用户数等信息)。
3)第三方网络能力数据获取。这里,所述行业网关可以根据第三方网络能力提供的网络能力数据获取网络能力API,实现第三方网络能力数据的获取功能。
第三,对接口I3(即上述第五接口)的功能进行详细说明。
接口I3是所述行业网关与BSS/OSS的通信接口,用于支持策略配置功能与运行状态监控功能。
具体地,接口I3支持的关键功能包括:
1)行业网关的接入认证。这里,行业网关可以主动或被动地触发接入认证流程;行业网关与BSS/OSS交互的信息可以包括:行业网关设备ID(即上述第一设备201的身份标识)、行业网关支持的接入网络能力列表、是否允许行业网关接入等内容。
2)第三方网络的接入控制。这里,BSS/OSS可以向行业网关下发第三方网络的接入策略;行业网关与BSS/OSS交互的信息可以包括:网络类型标签(即上述网络标签和网络标识)、网络认证信息、带宽、流量、计费控制、网络接入状态指示(On/Off)等内容。
3)第三方网络能力的接入控制。这里,BSS/OSS可以向行业网关下发第三方网络能力的接入策略;行业网关与BSS/OSS交互的信息可以包括:网络能力类型标签(即上述网络能力标识)、网络能力认证信息、网络接入状态指示(On/Off)等内容。
4)MEP的接入控制。这里,行业网关与BSS/OSS交互的信息可以包括:MEP接入加密策略、允许开放的网络能力列表等内容,从而实现行业网关接入MEP的功能。
5)网络状态监控功能。这里,行业网关可以实时监控当前的网络状态;行业网关与BSS/OSS交互的信息可以包括:融合了网络标签、流量数据、网络状态的运维监控信息,以及融合了计费量纲标签和具体计费数值的计费数据信息。
第四,对接口I4(即上述第一接口)的功能进行详细说明。
接口I4是行业网关与MEP的通信接口,用于承载行业网关与MEP之 间的数据传输,并实现面向MEP的网络能力开放以及自服务网络安全管控功能。
具体地,接口I4支持的关键功能包括:
1)MEP的接入认证。这里,MEP可以主动或被动地触发接入认证流程;所述接入认证流程可以基于RADIUS等技术实现。
2)行业网关与MEP之间的数据传输。这里,行业网关可以通过IPSec/VPN(即采用IPSec协议实现远程接入的VPN技术)加密隧道(即上述第一隧道)等方式实现与MEP之间的数据传输功能。
3)面向MEP的网络能力开放功能。这里,行业网关与MEP交互的信令可以包括定位能力标签(比如5G、WiFi、Bluetooth、GPS等)、定位数据、接入用户信息、多制式网络接入列表、网络切片能力、QoS能力等信息。
4)面向MEP的自服务网络安全管控功能。这里,MEP可以通过Open API操作行业网关的网络分区权限管理、网络性能要求、业务路由策略、网络切片模板、定位区域大小及位置、接入用户ID(手机号码、用户名或者应用ID)等方面的功能。
第五,对接口I5(即上述第四接口)的功能进行详细说明。
接口I5是行业网关与其他行业网关之间的通信接口,用于实现行业网关之间的广域互联功能。实际应用时,接口I5可以基于SD-WAN功能实现,也可通过使能边缘计算MEP类UE化,通过通用无线分组业务(GPRS)隧道传输协议(GTP)用户平面(GTP-U)隧道实现MEP与MEP之间的通信并统一到5GC的接入与管理流程中。
在本应用实施例中,接口I1至I5在支持上述功能时承载了所述行业网关与其他功能实体之间交互的信息,下面对接口I1至I5承载的信息进行详细说明。
首先,对接口I1承载的信息进行详细说明。
1)基于接口I1实现第三方网络的接入认证功能时,第三方网络可以通过接口I1向行业网关上报接入认证信息;所述接入认证信息包含的内容如表1所示;其中,如表2所示,网络类型标识(即上述网络标识)可以通过多种不同的数据类型表示。行业网关完成第三方网络的接入认证后,可以通过接口I1向第三方网络返回认证响应信息;所述认证响应信息包含的内容如表3所示;其中,如表4所示,网络身份标识可以通过多种不同的数据类型表示。
Figure PCTCN2022100809-appb-000001
Figure PCTCN2022100809-appb-000002
表1
Figure PCTCN2022100809-appb-000003
表2
Figure PCTCN2022100809-appb-000004
表3
Figure PCTCN2022100809-appb-000005
表4
2)基于接口I1实现第三方网络的接入控制功能时,行业网关可以通过接口I1向第三方网络发送网络接入控制信息(即上述第一信息),以实现对第三方网络的接入控制功能;所述网络接入控制信息包含的内容如表5所示。
Figure PCTCN2022100809-appb-000006
Figure PCTCN2022100809-appb-000007
表5
3)行业网关还可以通过接口I1向第三方网络发送自服务网络安全管控指令(即上述第一指令),以实现面向MEP的自服务网络安全管控功能。
其次,对接口I2承载的信息进行详细说明。
1)基于接口I2实现第三方网络能力的接入认证功能时,第三方网络能力可以通过接口I1向行业网关上报接入认证信息;所述接入认证信息包含的内容如表6所示;其中,如表7所示,网络能力类型标识(即上述网络能力标识)可以通过多种不同的数据类型表示;如表8所示,网络能力API列表也可以通过多种不同的数据类型表示。行业网关完成第三方网络能力的接入认证后,可以通过接口I1向第三方网络能力返回认证响应信息;所述认证响应信息包含的内容如表9所示;其中,如表10所示,网络能力身份标识可以通过多种不同的数据类型表示。
Figure PCTCN2022100809-appb-000008
表6
Figure PCTCN2022100809-appb-000009
表7
Figure PCTCN2022100809-appb-000010
Figure PCTCN2022100809-appb-000011
表8
Figure PCTCN2022100809-appb-000012
表9
Figure PCTCN2022100809-appb-000013
表10
实际应用时,列表(即List of String和List of Number)可以理解为一维数组,用于存储同种类型的一系列数据。在不同编程语言中,列表可以是静态的,也可以是动态变化的。
2)基于接口I2实现第三方网络能力的接入控制功能时,行业网关可以通过接口I2向第三方网络能力发送接入控制信息(即上述第二信息),以实现对第三方网络能力的接入控制功能;所述接入控制信息包含的内容如表11所示。
Figure PCTCN2022100809-appb-000014
表11
3)行业网关还可以通过接口I2从第三方网络能力获取网络能力数据,以实现面向MEP的网络能力开放。
第三,对接口I3承载的信息进行详细说明。
1)基于接口I3实现行业网关的接入认证功能时,行业网关可以通过接口I3向BSS/OSS发送身份认证信息;所述身份认证信息包含的内容如表 12所示;其中,如表13所示,网络类型列表可以通过多种不同的数据类型表示;如表14所示,网络能力类型列表也可以通过多种不同的数据类型表示。BSS/OSS完成行业网关的接入认证后,可以通过接口I3向行业网关返回认证响应信息;所述认证响应信息包含的内容如表15所示;其中,如表16所示,行业网关身份标识可以通过多种不同的数据类型表示。
参数名 数据类型 说明
用户名 String 具有行业网关注册权限的用户名
密钥 String 用户名对应的密钥
网络类型列表 如表13所示 行业网关支持接入的网络类型列表
网络能力类型列表 如表14所示 行业网关支持接入的网络能力类型列表
最大带宽 Number 行业网关所支持的最大带宽容量
带宽控制粒度 Number 行业网关所支持的带宽控制粒度
表12
Figure PCTCN2022100809-appb-000015
表13
Figure PCTCN2022100809-appb-000016
表14
Figure PCTCN2022100809-appb-000017
表15
Figure PCTCN2022100809-appb-000018
表16
2)基于接口I3实现第三方网络的接入控制功能时,BSS/OSS可以通过接口I3向行业网关发送单个第三方网络接入控制策略(即上述第一接入控制策略),以实现对行业网关连接的单个第三方网络的接入控制功能;所述单个第三方网络接入控制策略包含的内容如表17所示。
Figure PCTCN2022100809-appb-000019
表17
实际应用时,BSS/OSS也可以通过接口I3向行业网关发送单类型第三方网络接入控制策略(即上述第二接入控制策略),以实现对行业网关上单类型的第三方网络的接入控制功能;所述单类型第三方网络接入控制策略包含的内容如表18所示。
Figure PCTCN2022100809-appb-000020
Figure PCTCN2022100809-appb-000021
表18
实际应用时,BSS/OSS还可以通过接口I3向行业网关发送整体第三方网络接入控制策略(即上述第三接入控制策略),以实现对行业网关上所有第三方网络的接入控制功能;所述整体第三方网络接入控制策略包含的内容如表19所示。
Figure PCTCN2022100809-appb-000022
表19
在本应用实施例中,所述第三方网络的计费策略可以包含以下至少之 一:
按带宽计费;即按照第三方网络的最大带宽值计费,比如按带宽包年包月计费、按带宽使用时长计费等计费模式;
按流量计费;即按照第三方网络实际传输的数据总量计费;
按网络切片计费;即按照所使用的第三方网络切片的类型和数量计费;
按QoS计费;即按照第三方网络提供的QoS计费,比如数据传输速率、时延、抖动、可靠性等;
按接入用户数计费;即按照第三方网络接入的用户数计费,比如按最大接入用户数包月包年计费、按实际接入用户数计费等计费模式。
3)基于接口I3实现第三方网络能力的接入控制功能时,BSS/OSS可以通过接口I3向行业网关发送单个第三方网络能力接入控制策略(即上述第四接入控制策略),以实现对行业网关上单个第三方网络能力的接入控制功能;所述单个第三方网络能力接入控制策略包含的内容如表20所示。
Figure PCTCN2022100809-appb-000023
表20
实际应用时,BSS/OSS也可以通过接口I3向行业网关发送单类型第三方网络能力接入控制策略(即上述第五接入控制策略),以实现对行业网关上单类型的第三方网络能力的接入控制功能;所述单类型第三方网络能力接入控制策略包含的内容如表21所示。
Figure PCTCN2022100809-appb-000024
Figure PCTCN2022100809-appb-000025
表21
实际应用时,BSS/OSS还可以通过接口I3向行业网关发送整体第三方网络能力接入控制策略(即上述第六接入控制策略),以实现对行业网关上所有第三方网络能力的接入控制功能;所述整体第三方网络能力接入控制策略包含的内容如表22所示。
Figure PCTCN2022100809-appb-000026
表22
在本应用实施例中,所述第三方网络能力的计费策略可以包含以下至少之一:
按第三方网络能力的API的实际调用次数计费;
按第三方网络能力的数据流量计费;即按照实际传输的网络能力数据总量计费;
按第三方网络能力的类型计费;即针对不同的第三方网络能力的类型,指定不同的计费模式及价格;
按第三方网络能力的数据来源计费;即针对不同的第三方网络能力的数据来源,指定不同的计费模式及价格;
4)基于接口I3实现MEP的接入控制功能时,BSS/OSS可以通过接口I3向行业网关发送MEP接入控制策略(即上述第一策略),以实现对MEP的接入控制功能;所述MEP接入控制策略包含的内容如表23所示;其中,如表24所示,MEP身份标识可以通过多种不同的数据类型表示;如表25 所示,自服务网络安全管控API列表也可以通过多种不同的数据类型表示。
Figure PCTCN2022100809-appb-000027
表23
Figure PCTCN2022100809-appb-000028
表24
Figure PCTCN2022100809-appb-000029
Figure PCTCN2022100809-appb-000030
表25
5)基于接口I3实现网络状态监控功能时,行业网关可以通过接口I3向BSS/OSS发送网络状态监控信息,以实现网络状态监控功能;所述网络状态监控信息包含的内容如表26所示;其中,如表27所示,第三方网络状态统计信息、第三方网络能力状态统计信息和MEP状态统计信息可以通过多种不同的数据类型表示。
Figure PCTCN2022100809-appb-000031
表26
Figure PCTCN2022100809-appb-000032
表27
第四,对接口I4承载的信息进行详细说明。
1)基于接口I4实现MEP的接入认证功能时,MEP可以通过接口I4向行业网关发送MEP接入认证信息;所述MEP接入认证信息包含的内容如表28所示。行业网关完成对MEP的认证后,可以通过接口I4返回MEP接入认证响应信息;所述MEP接入认证响应信息包含的内容如表29所示。
Figure PCTCN2022100809-appb-000033
Figure PCTCN2022100809-appb-000034
表28
Figure PCTCN2022100809-appb-000035
表29
2)基于接口I4实现MEP的接入控制功能时,行业网关可以通过接口I4向MEP发送MEP接入控制信息(即上述第三信息),以实现对MEP的接入控制功能;所述MEP接入控制信息包含的内容如表30所示。
Figure PCTCN2022100809-appb-000036
表30
4)基于接口I4实现面向MEP的网络能力开放功能时,MEP可以通过行业网关开放的网络能力API,获取网络能力开放数据;此时,MEP与行业网关交互的信息所包含的内容如表31所示。。
Figure PCTCN2022100809-appb-000037
表31
5)基于接口I4实现面向MEP的自服务网络安全管控功能时,MEP可 以通过行业网关开放的自服务网络安全管控API,获取网络能力开放数据;此时,MEP与行业网关交互的信息所包含的内容如表32所示。
Figure PCTCN2022100809-appb-000038
表32
第五,对接口I5承载的信息进行详细说明。
基于接口I5实现行业网关之间的广域互联功能时,不同行业网关之间可以通过SD-WAN、互联网、企业专线、无线网络等方式建立互联通道,实现广域互联功能。
在本应用实施例中,行业网关支持的功能接受BSS/OSS的统一管控,该管控通过接口I3与其他接口的联动(即结合)来实现。下面结合图7至图10描述接口I3与其他接口联动实现相应功能的流程。
首先,基于接口I3与接口I1的联动,可以实现行业网关对第三方网络的接入认证功能和接入控制功能,如图7所示,实现行业网关对第三方网络的接入认证功能的过程具体可以包括以下步骤:
步骤7101:第三方网络通过接口I1向行业网关发送第三方网络接入认证信息;之后执行步骤7102;
步骤7102:行业网关通过接口I3将第三方网络接入认证信息发送到BSS/OSS;之后执行步骤7103;
步骤7103:BSS/OSS实施对第三方网络的接入认证;之后执行步骤7104;
步骤7104:BSS/OSS通过接口I3向行业网关发送包含认证结果的第三方网络接入认证响应信息;之后执行步骤7105;
步骤7105:行业网关通过接口I1向第三方网络发送第三方网络接入认证响应信息。
实现行业网关对第三方网络的接入控制功能的过程具体可以包括以下步骤:
步骤7201:BSS/OSS通过接口I3向行业网关发送第三方网络接入控制策略;之后执行步骤7202;
步骤7202:行业网关根据第三方网络接入控制策略(即上述第二策略),实施对第三方网络的接入控制;之后执行步骤7203;
这里,行业网关实施的对第三方网络的接入控制,可以包括带宽限制、接入用户数限制、第三方网络接入的开启或关闭、计费等;
步骤7203:行业网关通过接口I1向第三方网络发送第三方网络接入控制信息(即上述第一信息)。
其次,基于接口I3与接口I2的联动,可以实现行业网关对第三方网络能力的接入认证功能和接入控制功能,如图8所示,实现行业网关对第三方网络能力的接入认证功能的过程具体可以包括以下步骤:
步骤8101:第三方网络能力通过接口I2向行业网关发送第三方网络能力接入认证信息;之后执行步骤8102;
步骤8102:行业网关将第三方网络能力接入认证信息通过接口I3发送到BSS/OSS;之后执行步骤8103;
步骤8103:BSS/OSS实施对第三方网络能力的接入认证;之后执行步骤8104;
步骤8104:BSS/OSS通过接口I3向行业网关发送包含认证结果的第三方网络能力接入认证响应信息;之后执行步骤8105;
步骤8105:行业网关通过接口I2向第三方网络能力发送第三方网络能力接入认证响应信息。
实现行业网关对第三方网络能力的接入控制功能的过程具体可以包括以下步骤:
步骤8201:BSS/OSS通过接口I3向行业网关发送第三方网络能力接入控制策略(即上述第三策略);之后执行步骤8202;
步骤8202:行业网关根据第三方网络能力接入控制策略,实施对第三方网络能力的接入控制;之后执行步骤8203;
这里,行业网关实施的对第三方网络能力的接入控制可以包括网络能力API调用次数限制、第三方网络能力接入的开启或关闭、计费等;
步骤8203:行业网关通过接口I2向第三方网络能力发送第三方网络能力接入控制信息(即上述第二信息)。
第三,基于接口I3与接口I4的联动,可以实现行业网关对MEP的接入认证功能和接入控制功能,如图9所示,实现行业网关对MEP的接入认证功能的过程具体可以包括以下步骤:
步骤9101:MEP通过接口I4向行业网关发送MEP接入认证信息;之后执行步骤9102;
步骤9102:行业网关将MEP接入认证信息通过接口I3发送到BSS/OSS;之后执行步骤9103;
步骤9103:BSS/OSS实施对MEP的接入认证;之后执行步骤9104;
步骤9104:BSS/OSS通过接口I3向行业网关发送包含认证结果的MEP接入认证响应信息;之后执行步骤9105;
步骤9105:行业网关通过接口I4向MEP发送MEP接入认证响应信息。
实现行业网关对MEP的接入控制功能的过程具体可以包括以下步骤:
步骤9201:BSS/OSS通过接口I3向行业网关发送MEP接入控制策略 (即上述第一策略);之后执行步骤9202;
步骤9202:行业网关根据MEP接入控制策略,实施对MEP的接入控制;之后执行步骤9203;
这里,行业网关实施的对MEP的接入控制可以包括允许访问的网络能力限制、带宽限制、计费等;
步骤9103:行业网关通过接口I4向MEP发送MEP接入控制信息(即上述第三信息)。
第四,基于接口I3、接口I4、接口I1和接口I2的联动,可以实现面向MEP的网络能力开放功能和自服务网络安全管控功能,如图10所示,实现面向MEP的网络能力开放功能的过程具体可以包括以下步骤:
步骤1011:BSS/OSS通过接口I3向行业网关下发MEP接入控制策略(即上述第一策略);之后执行步骤1012;
这里,所述MEP接入控制策略包含面向MEP的网络能力开放相关的控制策略;
步骤1012:MEP通过接口I4调用行业网关的网络能力开放API;之后执行步骤1013;
步骤1013:行业网关根据MEP接入控制策略对MEP的请求进行校验,校验通过后,行业网关通过接口I2向第三方网络能力发送获取网络能力数据的请求;之后执行步骤1014;
这里,行业网关可以校验MEP的请求是否不属于相应MEP允许访问的网络能力;或者,可以校验MEP的请求是否超出了相应MEP允许调用的网络能力开放API次数等;
步骤1014:第三方网络能力通过接口I2向行业网关发送网络能力数据;之后执行步骤1015;
步骤1015:行业网关通过接口I4将网络能力数据发送给MEP。
实现面向MEP的自服务网络安全管控功能的过程具体可以包括以下步骤:
步骤1011:BSS/OSS通过接口I3向行业网关下发MEP接入控制策略;之后执行步骤1021;
这里,所述MEP接入控制策略包含面向MEP的自服务网络安全管控相关的控制策略;
步骤1021:MEP通过接口I4调用行业网关的自服务网络安全管控API;之后执行步骤1022;
步骤1022:行业网关根据MEP接入控制策略对MEP的请求进行校验,校验通过后,行业网关通过接口I1向第三方网络发送自服务网络管控指令(即上述第一指令);之后执行步骤1023;
这里,行业网关可以校验MEP的请求是否不属于MEP允许访问的自服务网络安全管控API;所述自服务网络管控指令可以是网络安全管控指 令;
步骤1023:第三方网络通过接口I1向行业网关发送自服务网络管控结果;之后执行步骤1024;
这里,在所述自服务网络管控指令是网络安全管控指令的情况下,所述自服务网络管控结果为网络安全管控结果;
步骤1024:行业网关通过接口I4将自服务网络管控响应信息发送给MEP。
本应用实施例提供的方案,具有以下优点:
本应用实施例提供的方案,在相关技术的基础上,将行业网关(可以是网络设备或网元)引入通信系统,部署在UPF与MEP之间,并接受BSS/OSS的管理与控制;行业网关至少具备多制式网络接入控制、网络智能广域互联、多类型网络能力接入与开放、多制式网络监控与计费、自服务资源管理等方面的功能;同时,基于全新定义的5个接口(接口I1至I5)实现了上述功能;其中,接口I1对接多制式接入网络(即第三方网络);接口I2对接多类型网络能力的接入(即第三方网络能力);接口I3对接BSS/OSS;接口I4对接MEP;接口I5对接其他的行业网关。
基于所述行业网关的应用,本应用实施例提供的通信系统(即5G行业云网融合的系统)可运营、更安全、可落地、可演进,更加贴合垂直行业客户需求。具体地,通过本应用实施例提供的方案,一方面,能够解决相关技术(即图1所示的5G与MEC技术结合方案)在行业落地中存在的UPF与MEC分离部署带来的网络和计算资源安全问题、不支持多制式网络(比如4G、5G、WiFi、Bluetooth、Zigbee、NB-IoT、光纤、Wireline等)的接入与统一管理问题、本地分流的缺陷问题和MEP之间的互联互通等问题;另一方面,能够满足用户对多样化的网络能力开放和自服务资源管理能力等方面的需求。
为了实现本申请实施例的方法,本申请实施例还提供了一种通信装置,设置在第一设备上,如图11所示,该装置包括:
处理单元1101,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
其中,在一实施例中,所述处理单元1101,还配置为对连接的第二设备进行接入认证。
在一实施例中,如图11所示,该装置还包括控制单元1102,配置为控制第二设备对网络能力的访问。
在一实施例中,所述处理单元1101,配置为:
接收所述第二设备发送的接入认证信息;
将所述接入认证信息发送给第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第二设备返回认 证响应信息。
在一实施例中,所述处理单元1101,还配置为:
接收第三设备发送的第一策略;
基于所述第一策略为第二设备提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备对网络能力的访问。
在一实施例中,所述处理单元1101,还配置为为接入第三方网络的终端选择对应的第二设备,将对应第二设备提供的应用通过所述第三方网络提供给所述终端。
在一实施例中,所述处理单元1101,还配置为对所述第三方网络进行接入认证。
在一实施例中,所述处理单元1101,配置为:
接收所述第三方网络发送的接入认证信息;
将所述接入认证信息发送给所述第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第三方网络返回认证响应信息。
在一实施例中,所述处理单元1101,还配置为在接入认证通过后,基于安全机制与所述第三方网络进行数据传输。
在一实施例中,所述控制单元1102,还配置为控制所述第三方网络的接入能力。
在一实施例中,所述控制单元1102,配置为:
接收第三设备发送的第二策略;
基于所述第二策略控制所述第三方网络的接入能力。
在一实施例中,所述处理单元1101,配置为向所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力。
在一实施例中,所述处理单元1101,还配置为接收第四设备发送的网络能力信息。
在一实施例中,所述控制单元1102,还配置为控制所述第四设备的接入能力。
在一实施例中,所述处理单元1101,还配置为对第四设备进行接入认证。
在一实施例中,所述处理单元1101,配置为向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力。
在一实施例中,所述控制单元1102,配置为:
接收所述第三设备发送的第三策略;
基于所述第三策略控制所述第四设备的接入能力。
在一实施例中,所述处理单元1101,配置为:
接收所述第四设备发送的接入认证信息;
将所述接入认证信息发送给第三设备;
接收到所述第三设备返回的认证响应信息后,向所述第四设备返回认证响应信息。
在一实施例中,所述处理单元1101,还配置为通过至少一个其他第一设备,将终端的业务流进行路由转发,以实现所述终端获取至少一个其他第一设备连接的第二设备提供的应用。
在一实施例中,所述处理单元1101,还配置为监控网络的流量和/或网络状态;并向第三设备上报以下信息至少之一:
网络的流量;
计费信息;
网络状态的监控信息;
网络能力的使用信息;
第二设备状态的监控信息。
在一实施例中,该装置还包括获取单元,配置为获取至少一个网络(包含5G网络和/或第三方网络)的网络信息,以提供给需要的设备(比如MEAO)。
在一实施例中,所述获取单元,配置为从第三方网络的管理设备获得第三方网络的网络信息,和/或,从5G的管理设备获得5G网络的网络信息。
实际应用时,所述处理单元1101、所述控制单元1102及所述获取单元可由通信装置中的处理器结合通信接口实现。
需要说明的是:上述实施例提供的通信装置在进行通信时,仅以上述各程序模块的划分进行举例说明,实际应用中,可以根据需要而将上述处理分配由不同的程序模块完成,即将装置的内部结构划分成不同的程序模块,以完成以上描述的全部或者部分处理。另外,上述实施例提供的通信装置与通信方法实施例属于同一构思,其具体实现过程详见方法实施例,这里不再赘述。
基于上述程序模块的硬件实现,且为了实现本申请实施例的方法,本申请实施例还提供了一种第一设备,如图12所示,该第一设备1200包括:处理器1202及通信接口1201;其中,
所述处理器1202,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
其中,在一实施例中,所述处理器1202,还配置为:
对连接的第二设备进行接入认证;
和/或,
控制第二设备对网络能力的访问。
在一实施例中,所述处理器1202,配置为:
通过所述通信接口1201接收所述第二设备发送的接入认证信息;
通过所述通信接口1201将所述接入认证信息发送给第三设备;
通过所述通信接口1201接收到所述第三设备返回的认证响应信息后,通过所述通信接口1201向所述第二设备返回认证响应信息。
在一实施例中,所述处理器1202,还配置为:
通过所述通信接口1201接收第三设备发送的第一策略;
基于所述第一策略为第二设备提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备对网络能力的访问。
在一实施例中,所述处理器1202,还配置为为接入第三方网络的终端选择对应的第二设备,将对应第二设备提供的应用通过所述第三方网络提供给所述终端。
在一实施例中,所述处理器1202,还配置为对所述第三方网络进行接入认证。
在一实施例中,所述处理器1202,配置为:
通过所述通信接口1201接收所述第三方网络发送的接入认证信息;
通过所述通信接口1201将所述接入认证信息发送给所述第三设备;
通过所述通信接口1201接收到所述第三设备返回的认证响应信息后,通过所述通信接口1201向所述第三方网络返回认证响应信息。
在一实施例中,所述处理器1202,还配置为在接入认证通过后,基于安全机制与所述第三方网络进行数据传输。
在一实施例中,所述处理器1202,还配置为控制所述第三方网络的接入能力。
在一实施例中,所述处理器1202,还配置为:
通过所述通信接口1201接收第三设备发送的第二策略;
基于所述第二策略控制所述第三方网络的接入能力。
在一实施例中,所述处理器1202,配置为通过所述通信接口1201向所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力。
在一实施例中,所述处理器1202,还配置为通过所述通信接口1201接收第四设备发送的网络能力信息。
在一实施例中,所述处理器1202,还配置为:
控制所述第四设备的接入能力;
和/或,
对第四设备进行接入认证。
在一实施例中,所述处理器1202,配置为通过所述通信接口1201向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力。
在一实施例中,所述处理器1202,还配置为:
通过所述通信接口1201接收所述第三设备发送的第三策略;
基于所述第三策略控制所述第四设备的接入能力。
在一实施例中,所述处理器1202,配置为:
通过所述通信接口1201接收所述第四设备发送的接入认证信息;
通过所述通信接口1201将所述接入认证信息发送给第三设备;
通过所述通信接口1201接收到所述第三设备返回的认证响应信息后,通过所述通信接口1201向所述第四设备返回认证响应信息。
在一实施例中,所述处理器1202,还配置为通过至少一个其他第一设备,将终端的业务流进行路由转发,以实现所述终端获取至少一个其他第一设备连接的第二设备提供的应用。
在一实施例中,所述处理器1202,还配置为监控网络的流量和/或网络状态;并通过所述通信接口1201向第三设备上报以下信息至少之一:
网络的流量;
计费信息;
网络状态的监控信息;
网络能力的使用信息;
第二设备状态的监控信息。
在一实施例中,所述处理器1202,还配置为通过所述通信接口1201获取至少一个网络(包含5G网络和/或第三方网络)的网络信息,以提供给需要的设备(比如MEAO)。
在一实施例中,所述处理器1202,配置为通过所述通信接口1201从第三方网络的管理设备获得第三方网络的网络信息,和/或,通过所述通信接口1201从5G的管理设备获得5G网络的网络信息。
需要说明的是:所述通信接口1201和所述处理器1202的具体处理过程可参照上述方法理解。
当然,实际应用时,第一设备1200中的各个组件通过总线系统1204耦合在一起。可理解,总线系统1204用于实现这些组件之间的连接通信。总线系统1204除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图12中将各种总线都标为总线系统1204。
本申请实施例中的存储器1203用于存储各种类型的数据以支持第一设备1200的操作。这些数据的示例包括:用于在第一设备1200上操作的任何计算机程序。
上述本申请实施例揭示的方法可以应用于所述处理器1202中,或者由所述处理器1202实现。所述处理器1202可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过所述处理器1202中的硬件的集成逻辑电路或者软件形式的指令完成。上述的所述处理器1202可以是通用处理器、数字信号处理器(DSP,Digital Signal Processor),或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。所述处理器1202可以实现或者执行本申请实施例中的公开的各方法、步骤 及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合本申请实施例所公开的方法的步骤,可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于存储介质中,该存储介质位于存储器1203,所述处理器1202读取存储器1203中的信息,结合其硬件完成前述方法的步骤。
在示例性实施例中,第一设备1200可以被一个或多个应用专用集成电路(ASIC,Application Specific Integrated Circuit)、DSP、可编程逻辑器件(PLD,Programmable Logic Device)、复杂可编程逻辑器件(CPLD,Complex Programmable Logic Device)、现场可编程门阵列(FPGA,Field-Programmable Gate Array)、通用处理器、控制器、微控制器(MCU,Micro Controller Unit)、微处理器(Microprocessor)、或者其他电子元件实现,用于执行前述方法。
可以理解,本申请实施例中的存储器1203可以是易失性存储器或者非易失性存储器,也可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(ROM,Read Only Memory)、可编程只读存储器(PROM,Programmable Read-Only Memory)、可擦除可编程只读存储器(EPROM,Erasable Programmable Read-Only Memory)、电可擦除可编程只读存储器(EEPROM,Electrically Erasable Programmable Read-Only Memory)、磁性随机存取存储器(FRAM,ferromagnetic random access memory)、快闪存储器(Flash Memory)、磁表面存储器、光盘、或只读光盘(CD-ROM,Compact Disc Read-Only Memory);磁表面存储器可以是磁盘存储器或磁带存储器。易失性存储器可以是随机存取存储器(RAM,Random Access Memory),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(SRAM,Static Random Access Memory)、同步静态随机存取存储器(SSRAM,Synchronous Static Random Access Memory)、动态随机存取存储器(DRAM,Dynamic Random Access Memory)、同步动态随机存取存储器(SDRAM,Synchronous Dynamic Random Access Memory)、双倍数据速率同步动态随机存取存储器(DDRSDRAM,Double Data Rate Synchronous Dynamic Random Access Memory)、增强型同步动态随机存取存储器(ESDRAM,Enhanced Synchronous Dynamic Random Access Memory)、同步连接动态随机存取存储器(SLDRAM,SyncLink Dynamic Random Access Memory)、直接内存总线随机存取存储器(DRRAM,Direct Rambus Random Access Memory)。本申请实施例描述的存储器旨在包括但不限于这些和任意其它适合类型的存储器。
在示例性实施例中,本申请实施例还提供了一种存储介质,即计算机存储介质,具体为计算机可读存储介质,例如包括存储计算机程序的存储器1203,上述计算机程序可由第一设备1200的处理器1202执行,以完成前述方法所述步骤。计算机可读存储介质可以是FRAM、ROM、PROM、 EPROM、EEPROM、Flash Memory、磁表面存储器、光盘、或CD-ROM等存储器。
需要说明的是:“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。
另外,本申请实施例所记载的技术方案之间,在不冲突的情况下,可以任意组合。
以上所述,仅为本申请的较佳实施例而已,并非用于限定本申请的保护范围。

Claims (55)

  1. 一种通信系统,包括:至少一个第一设备、至少一个第二设备、至少一个用户面功能UPF;其中,
    每个第一设备连接至少一个第二设备;每个第一设备连接至少一个UPF;
    所述第一设备,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
  2. 根据权利要求1所述的系统,其中,所述第一设备,还配置为对连接的第二设备进行接入认证。
  3. 根据权利要求2所述的系统,其中,所述系统还包括:第三设备;其中,
    所述第二设备,配置为向所述第一设备发送接入认证信息;接收所述第一设备返回的认证响应信息;
    所述第一设备,配置为接收所述第二设备发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第二设备返回认证响应信息;
    所述第三设备,配置为接收所述第一设备发送的接入认证信息,利用所述接入认证信息对所述第二设备进行接入认证,并向所述第一设备返回认证响应信息。
  4. 根据权利要求3所述的系统,其中,所述接入认证信息包含所述第二设备的特征。
  5. 根据权利要求4所述的系统,其中,所述特征包含以下至少之一:
    IP地址段;
    承载的应用;
    业务优先级。
  6. 根据权利要求3所述的系统,其中,所述第一设备,还配置为控制第二设备对网络能力的访问。
  7. 根据权利要求6所述的系统,其中,
    所述第三设备,还配置为向所述第一设备发送第一策略;
    所述第一设备,还配置为接收所述第三设备发送的第一策略,基于所述第一策略为第二设备提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备对网络能力的访问。
  8. 根据权利要求1所述的系统,其中,所述系统还包括:至少一个第三方网络;其中,
    所述第三方网络,配置为为终端提供网络接入;
    所述第一设备,还配置为为所述终端选择对应的第二设备,并将对应第二设备提供的应用通过所述第三方网络提供给所述终端。
  9. 根据权利要求8所述的系统,其中,所述第一设备,还配置为对第三方网络进行接入认证。
  10. 根据权利要求9所述的系统,其中,所述系统还包括:第三设备;其中,
    所述第三方网络,配置为向所述第一设备发送接入认证信息;并接收所述第一设备返回的认证响应信息;
    所述第一设备,配置为接收所述第三方网络发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第三方网络返回认证响应信息;
    所述第三设备,配置为接收所述第一设备发送的接入认证信息,利用所述接入认证信息对所述第三方网络进行接入认证,并向所述第一设备返回认证响应信息。
  11. 根据权利要求10所述的系统,其中,所述接入认证信息包含第三方网络的特征。
  12. 根据权利要求11所述的系统,其中,所述特征包含以下至少之一:
    最大带宽;
    带宽控制粒度;
    IP地址段;
    业务优先级;
    承载的应用。
  13. 根据权利要求9所述的系统,其中,所述第一设备,配置为接入认证通过后,基于安全机制与所述第三方网络进行数据传输。
  14. 根据权利要求10所述的系统,其中,所述第一设备,还配置为控制所述第三方网络的接入能力。
  15. 根据权利要求14所述的系统,其中,
    所述第三设备,还配置为向所述第一设备发送第二策略;
    所述第一设备,还配置为接收所述第三设备发送的第二策略,基于所述第二策略控制所述第三方网络的接入能力。
  16. 根据权利要求15所述的系统,其中,所述第二策略包含以下之一:
    第一接入控制策略;所述第一接入控制策略针对单个第三方网络;
    第二接入控制策略;所述第二接入控制策略针对一种类型的第三方网络;
    第三接入控制策略;所述第三接入控制策略针对所有第三方网络。
  17. 根据权利要求14所述的系统,其中,所述第一设备,配置为向 所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力;
    所述第三方网络,配置为接收所述第一设备发送的第一信息,利用所述第一信息调整自身的接入能力。
  18. 根据权利要求1所述的系统,其中,所述系统还包括:至少一个第四设备;其中,
    所述第四设备,配置为为所述第一设备提供网络能力信息。
  19. 根据权利要求18所述的系统,其中,所述第一设备,还配置为对第四设备进行接入认证。
  20. 根据权利要求19所述的系统,其中,所述系统还包括:第三设备;其中,
    所述第四设备,还配置为向所述第一设备发送接入认证信息;接收所述第一设备返回的认证响应信息;
    所述第一设备,配置为接收所述第四设备发送的接入认证信息,将所述接入认证信息发送给所述第三设备,接收所述第三设备返回的认证响应信息,以及向所述第四设备返回认证响应信息;
    所述第三设备,配置为利用所述接入认证信息对所述第四设备进行接入认证,并向所述第一设备返回认证响应信息。
  21. 根据权利要求20所述的系统,其中,
    所述第一设备,还配置为控制所述第四设备的接入能力。
  22. 根据权利要求21所述的系统,其中,所述第一设备,配置为向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力;
    所述第四设备,配置为接收所述第一设备发送的第二信息,利用所述第二信息调整自身的接入能力。
  23. 根据权利要求20所述的系统,其中,
    所述第三设备,还配置为向所述第一设备发送第三策略;
    所述第一设备,还配置为接收所述第三设备发送的第三策略,并基于所述第三策略控制所述第四设备的接入能力。
  24. 根据权利要求1所述的系统,其中,所述第一设备,配置为通过至少一个其他第一设备,将终端的业务流进行路由转发,以实现所述终端获取至少一个其他第一设备连接的第二设备提供的应用。
  25. 根据权利要求1至24任一项所述的系统,其中,所述系统还包括:第三设备,配置为控制所述至少一个第一设备。
  26. 根据权利要求25所述的系统,其中,所述第三设备,还配置为对所述至少一个第一设备进行认证。
  27. 根据权利要求26所述的系统,其中,
    所述第一设备,配置为向所述第三设备发送认证信息;并接收所述 第三设备返回的认证响应信息;
    所述第三设备,配置为接收所述第一设备发送的认证信息,并利用所述认证信息对所述第一设备进行认证,并向所述第一设备返回认证响应信息。
  28. 根据权利要求25所述的系统,其中,所述第一设备,还配置为监控网络的流量和/或网络状态;并向所述第三设备上报以下信息至少之一:
    网络的流量;
    计费信息;
    网络状态的监控信息;
    网络能力的使用信息;
    第二设备状态的监控信息。
  29. 一种通信方法,应用于第一设备,包括:
    为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
  30. 根据权利要求29所述的方法,其中,所述方法还包括:
    对连接的第二设备进行接入认证;
    和/或,
    控制第二设备对网络能力的访问。
  31. 根据权利要求30所述的方法,其中,所述对连接的第二设备进行接入认证,包括:
    接收所述第二设备发送的接入认证信息;
    将所述接入认证信息发送给第三设备;
    接收到所述第三设备返回的认证响应信息后,向所述第二设备返回认证响应信息。
  32. 根据权利要求31所述的方法,其中,所述接入认证信息包含所述第二设备的特征。
  33. 根据权利要求32所述的方法,其中,所述特征包含以下至少之一:
    IP地址段;
    承载的应用;
    业务优先级。
  34. 根据权利要求30所述的方法,其中,所述方法还包括:
    接收第三设备发送的第一策略;
    基于所述第一策略为第二设备提供的应用提供安全访问控制功能,和/或,基于所述第一策略控制第二设备对网络能力的访问。
  35. 根据权利要求29所述的方法,其中,所述方法还包括:
    为接入第三方网络的终端选择对应的第二设备,将对应第二设备提供的应用通过所述第三方网络提供给所述终端。
  36. 根据权利要求35所述的方法,其中,所述方法还包括:
    对所述第三方网络进行接入认证。
  37. 根据权利要求36所述的方法,其中,所述对所述第三方网络进行接入认证,包括:
    接收所述第三方网络发送的接入认证信息;
    将所述接入认证信息发送给所述第三设备;
    接收到所述第三设备返回的认证响应信息后,向所述第三方网络返回认证响应信息。
  38. 根据权利要求37所述的方法,其中,所述接入认证信息包含第三方网络的特征。
  39. 根据权利要求38所述的方法,其中,所述特征包含以下至少之一:
    最大带宽;
    带宽控制粒度;
    IP地址段;
    业务优先级;
    承载的应用。
  40. 根据权利要求37所述的方法,其中,
    接入认证通过后,基于安全机制与所述第三方网络进行数据传输。
  41. 根据权利要求35所述的方法,其中,所述方法还包括:
    控制所述第三方网络的接入能力。
  42. 根据权利要求41所述的方法,其中,所述方法还包括:
    接收第三设备发送的第二策略;
    基于所述第二策略控制所述第三方网络的接入能力。
  43. 根据权利要求42所述的方法,其中,所述第二策略包含以下之一:
    第一接入控制策略;所述第一接入控制策略针对单个第三方网络;
    第二接入控制策略;所述第二接入控制策略针对一种类型的第三方网络;
    第三接入控制策略;所述第三接入控制策略针对所有第三方网络。
  44. 根据权利要求41所述的方法,其中,所述控制所述第三方网络的接入能力,包括:
    向所述第三方网络发送第一信息,所述第一信息用于指示所述第三方网络的接入能力。
  45. 根据权利要求29所述的方法,其中,所述方法还包括:
    接收第四设备发送的网络能力信息。
  46. 根据权利要求45所述的方法,其中,所述方法还包括:
    控制所述第四设备的接入能力;
    和/或,
    对第四设备进行接入认证。
  47. 根据权利要求46所述的方法,其中,所述控制所述第四设备的接入能力,包括:
    向所述第四设备发送第二信息,所述第二信息用于指示所述第四设备的接入能力。
  48. 根据权利要求46所述的方法,其中,所述方法还包括:
    接收所述第三设备发送的第三策略;
    基于所述第三策略控制所述第四设备的接入能力。
  49. 根据权利要求46所述的方法,其中,所述对第四设备进行接入认证,包括:
    接收所述第四设备发送的接入认证信息;
    将所述接入认证信息发送给第三设备;
    接收到所述第三设备返回的认证响应信息后,向所述第四设备返回认证响应信息。
  50. 根据权利要求29所述的方法,其中,所述方法还包括:
    通过至少一个其他第一设备,将终端的业务流进行路由转发,以实现所述终端获取至少一个其他第一设备连接的第二设备提供的应用。
  51. 根据权利要求29至50任一项所述的方法,其中,所述方法还包括:
    监控网络的流量和/或网络状态;并向第三设备上报以下信息至少之一:
    网络的流量;
    计费信息;
    网络状态的监控信息;
    网络能力的使用信息;
    第二设备状态的监控信息。
  52. 一种通信装置,设置在第一设备上,包括:
    处理单元,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
  53. 一种第一设备,包括:处理器及通信接口;其中,
    所述处理器,配置为为UPF发送的边缘网络的业务流量分配对应的第二设备,以将边缘网络的业务流量分流至对应的第二设备,并为第二设备提供的应用提供安全访问控制功能。
  54. 一种第一设备,包括:处理器及和配置为存储能够在处理器上 运行的计算机程序的存储器,
    其中,所述处理器配置为运行所述计算机程序时,执行权利要求29至51任一项所述方法的步骤。
  55. 一种存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现权利要求29至51任一项所述方法的步骤。
PCT/CN2022/100809 2021-06-24 2022-06-23 通信系统、方法、装置、第一设备及存储介质 Ceased WO2022268166A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110703927.1 2021-06-24
CN202110703927.1A CN115529631B (zh) 2021-06-24 2021-06-24 通信系统、方法、装置、第一设备及存储介质

Publications (1)

Publication Number Publication Date
WO2022268166A1 true WO2022268166A1 (zh) 2022-12-29

Family

ID=84544124

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/100809 Ceased WO2022268166A1 (zh) 2021-06-24 2022-06-23 通信系统、方法、装置、第一设备及存储介质

Country Status (2)

Country Link
CN (1) CN115529631B (zh)
WO (1) WO2022268166A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116546044A (zh) * 2023-04-18 2023-08-04 浙江大华技术股份有限公司 一种摄像设备的控制方法及相关装置

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116017454A (zh) * 2022-12-30 2023-04-25 中国联合网络通信集团有限公司 基于业务访问的认证方法、装置、设备及存储介质
CN116455641A (zh) * 2023-04-21 2023-07-18 上海电力设计院有限公司 防止网络入侵的单设备电力mec终端

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100109A (zh) * 2015-08-19 2015-11-25 华为技术有限公司 一种部署安全访问控制策略的方法及装置
CN109889586A (zh) * 2019-02-02 2019-06-14 腾讯科技(深圳)有限公司 通信处理方法、装置、计算机可读介质及电子设备
CN110198363A (zh) * 2019-05-10 2019-09-03 深圳市腾讯计算机系统有限公司 一种移动边缘计算节点的选择方法、装置及系统
US20200120446A1 (en) * 2018-10-16 2020-04-16 Cisco Technology, Inc. Methods and apparatus for selecting network resources for ue sessions based on locations of multi-access edge computing (mec) resources and applications
CN111083737A (zh) * 2018-10-19 2020-04-28 大唐移动通信设备有限公司 一种边缘mec中数据的分流方法和装置
CN111787069A (zh) * 2020-06-09 2020-10-16 中移雄安信息通信科技有限公司 业务接入请求的处理方法、装置、设备及计算机存储介质

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110896553B (zh) * 2018-09-12 2022-11-11 中国电信股份有限公司 多接入边缘计算方法和平台、通信系统
CN111565404B (zh) * 2020-04-15 2022-10-25 中国联合网络通信集团有限公司 一种数据分流方法和装置
CN112671571B (zh) * 2020-12-16 2024-04-16 腾讯科技(深圳)有限公司 网络切片的选择方法、装置、设备及存储介质

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100109A (zh) * 2015-08-19 2015-11-25 华为技术有限公司 一种部署安全访问控制策略的方法及装置
US20200120446A1 (en) * 2018-10-16 2020-04-16 Cisco Technology, Inc. Methods and apparatus for selecting network resources for ue sessions based on locations of multi-access edge computing (mec) resources and applications
CN111083737A (zh) * 2018-10-19 2020-04-28 大唐移动通信设备有限公司 一种边缘mec中数据的分流方法和装置
CN109889586A (zh) * 2019-02-02 2019-06-14 腾讯科技(深圳)有限公司 通信处理方法、装置、计算机可读介质及电子设备
CN110198363A (zh) * 2019-05-10 2019-09-03 深圳市腾讯计算机系统有限公司 一种移动边缘计算节点的选择方法、装置及系统
CN111787069A (zh) * 2020-06-09 2020-10-16 中移雄安信息通信科技有限公司 业务接入请求的处理方法、装置、设备及计算机存储介质

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116546044A (zh) * 2023-04-18 2023-08-04 浙江大华技术股份有限公司 一种摄像设备的控制方法及相关装置

Also Published As

Publication number Publication date
CN115529631B (zh) 2024-05-28
CN115529631A (zh) 2022-12-27

Similar Documents

Publication Publication Date Title
US11659390B2 (en) Integrating CBRS-enabled devices and intent-based networking
US10129108B2 (en) System and methods for network management and orchestration for network slicing
CN111770545B (zh) 一种业务流路由控制方法、装置及系统
CN114651477B (zh) 用于用户面处理的系统和方法
RU2725625C2 (ru) Эксплуатация сетей с фрагментацией
US9408177B2 (en) System and method for resource management for operator services and internet
CN104255046B (zh) 可定制的移动宽带网络系统和定制移动宽带网络的方法
US9119015B2 (en) Mobile device application analysis
WO2022268166A1 (zh) 通信系统、方法、装置、第一设备及存储介质
WO2021223507A1 (zh) 一种通信方法、装置及芯片
US20250267023A1 (en) Deterministic Networks
CN111726839A (zh) 一种网络切片选择方法及装置
CN116866881A (zh) 一种通信方法及装置
CN114365454B (zh) 无状态安全功能的分布
CN113765874B (zh) 一种基于5g移动通信技术的专网及双模式组网方法
CN111371664B (zh) 一种虚拟专用网络接入方法及设备
CN110519786B (zh) 业务服务质量监测方法、设备及系统
WO2022052798A1 (zh) QoS控制方法、装置及处理器可读存储介质
WO2023116355A1 (zh) 通信方法、装置、相关设备及存储介质
CN110138685B (zh) 一种通信方法及装置
JP2017518717A (ja) 動的なデータ中継としてのプロキシ装置の使用
CN115529589B (zh) 一种能力开放方法、装置、通信设备和存储介质
US11606303B1 (en) Device initiated quality of service
US20240298242A1 (en) Relay device, relay method, and communication system
WO2024032178A1 (zh) 一种通信方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22827658

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 22827658

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 22827658

Country of ref document: EP

Kind code of ref document: A1

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 10/06/2024)

122 Ep: pct application non-entry in european phase

Ref document number: 22827658

Country of ref document: EP

Kind code of ref document: A1