WO2025093029A1 - 数据传输方法及装置、计算机可读存储介质 - Google Patents

数据传输方法及装置、计算机可读存储介质 Download PDF

Info

Publication number
WO2025093029A1
WO2025093029A1 PCT/CN2024/129607 CN2024129607W WO2025093029A1 WO 2025093029 A1 WO2025093029 A1 WO 2025093029A1 CN 2024129607 W CN2024129607 W CN 2024129607W WO 2025093029 A1 WO2025093029 A1 WO 2025093029A1
Authority
WO
WIPO (PCT)
Prior art keywords
session
parameter
service
data
terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2024/129607
Other languages
English (en)
French (fr)
Inventor
韩鲁峰
丁昱
韩立锋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Ziguang Zhanrui Communication Technology Co Ltd
Original Assignee
Beijing Ziguang Zhanrui Communication Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Ziguang Zhanrui Communication Technology Co Ltd filed Critical Beijing Ziguang Zhanrui Communication Technology Co Ltd
Publication of WO2025093029A1 publication Critical patent/WO2025093029A1/zh
Anticipated expiration legal-status Critical
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/02Arrangements for optimising operational condition
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/04Arrangements for maintaining operational condition
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/26Network addressing or numbering for mobility support

Definitions

  • the first parameter multiplexes a second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service.
  • the action of processing the data using the first security parameter is performed at the business layer, or the action of processing the data using the first security parameter is performed at the protocol layer.
  • the data transmission method further includes: sending a second message, where the second message is used to request allocation of resources for the first session.
  • an embodiment of the present application also provides a data transmission method, including: receiving data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, the first parameters include a first security parameter and/or a first IP address; merging the received data and transmitting it to the next node.
  • the next node includes a core network.
  • the merging the received data and transmitting it to the next node includes: directly merging the received data and transmitting it to the next node.
  • the first security parameter is a third security parameter
  • the third security parameter does not reuse a second security parameter of a terminal related to the first session
  • the second security parameter is associated with services other than the first service.
  • the data transmission method also includes: acquiring the first security parameter from a core network.
  • the merging of the received data and transmitting to the next node includes: deprocessing the data using the first security parameter and merging to obtain deprocessed data; and transmitting the deprocessed data to the next node.
  • the action of processing the data using the first security parameter is performed at the business layer.
  • the first security parameter multiplexes a second security parameter of a terminal related to the first session, and the second security parameter is associated with services other than the first service.
  • the merging of the received data and transmitting to the next node includes: deprocessing the data using the first security parameter and merging to obtain deprocessed data; and transmitting the deprocessed data to the next node.
  • the action of processing the data using the first security parameter solution is performed at the protocol layer.
  • the data transmission method also includes: receiving a third message from the core network, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; sending a fourth message, the fourth message including the second security parameter of the target terminal, and the first security parameter multiplexing the second security parameter of the target terminal.
  • the first IP address reuses the second IP address of a terminal related to the first session, or the first IP address is a third IP address, the third IP address does not reuse the second IP address of the terminal related to the first session, and the second IP address is associated with a service other than the first service.
  • the embodiment of the present application also provides a data transmission method, comprising: sending a first parameter associated with a first session, the first parameter including a first security parameter and/or a first IP address, the first session being associated with a first service; receiving data of the first service transmitted by an access network, the data being transmitted through the first session; wherein All network elements related to the first session use the first parameters to transmit the data.
  • the data transmission method further includes: receiving first information, where the first information is used to request to obtain the first parameter.
  • the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
  • the first information is carried via a non-access layer message or an access layer message.
  • the data includes at least one of the following: Ethernet data packet; IP data packet.
  • sending the first parameter associated with the first session includes: sending a first message, where the first message includes the first parameter associated with the first session.
  • the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and/or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
  • the first message is carried by a non-access layer message or an access layer message.
  • the non-access layer message includes a session management message and/or a mobility management message.
  • the first parameter multiplexes a second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service.
  • the data transmission method further includes: processing the data using the first security parameter solution.
  • the data received from the access network is data processed using the first security parameter solution.
  • the data transmission method further includes: receiving a second message, where the second message is used to request allocation of resources for the first session; and configuring the resources.
  • the data transmission method also includes: sending a third message, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; receiving a fourth message, the fourth message including the second security parameter of the target terminal, the first parameter multiplexing the second security parameter.
  • the first parameter is preconfigured.
  • the first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
  • the first network element includes: a first service management function network element, integrated in the signaling plane of the core network; and/or a first service transmission function network element, integrated in the data plane of the core network.
  • the first network element is provided with a public interface for providing capability information and/or service information of the first service, and/or receiving demand information of the first service.
  • an embodiment of the present application also provides a data transmission device, including: an acquisition module, used to obtain a first parameter associated with a first session, the first parameter includes a first security parameter and/or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module, used to use the first parameter to transmit data of the first service through the first session; wherein, all terminals related to the first session use the first parameter to transmit the data.
  • the embodiment of the present application further provides a data transmission device, including: a receiving module, used to receive data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, the first parameters include a first security parameter and/or a first IP address; a transmission module, used to merge the received The data is then transmitted to the next node.
  • an embodiment of the present application also provides a data transmission device, including: a sending module, used to send a first parameter associated with a first session, the first parameter includes a first security parameter and/or a first IP address, and the first session is associated with a first service; a receiving module, used to receive data of the first service transmitted by an access network, and the data is transmitted through the first session; wherein, network elements related to the first session all use the first parameter to transmit the data.
  • an embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored, and when the computer program is run by a processor, the steps of the above method are executed.
  • an embodiment of the present application further provides a computer program product, which includes a computer program.
  • the computer program When the computer program is run on a computer, the computer executes the steps of the above method.
  • this embodiment enables the terminals participating in the first session to transmit the same data using the same first parameter, thereby ensuring that different terminals can send the same data when performing data transmission. Redundant transmission, thereby improving data transmission reliability and success rate.
  • FIG2 is a schematic diagram of a communication system protocol stack provided in an embodiment of the present application.
  • FIG3 is a schematic diagram of another communication system protocol stack provided in an embodiment of the present application.
  • FIG4 is a schematic diagram of another communication system protocol stack provided in an embodiment of the present application.
  • FIG. 5 is a schematic diagram of a service layer security architecture of a communication system in a first typical application scenario of the present invention
  • FIG6 is a diagram of service layer signaling interaction in the application scenario shown in FIG5 ;
  • FIG. 7 is a schematic diagram of a service layer security architecture of a communication system in a second typical application scenario of the present invention.
  • FIG8 is a diagram of service layer signaling interaction in the application scenario shown in FIG7;
  • FIG9 is a schematic diagram of the structure of a data transmission device provided in an embodiment of the present application.
  • FIG10 is a schematic diagram of the structure of another data transmission device provided in an embodiment of the present application.
  • FIG11 is a schematic diagram of the structure of another data transmission device provided in an embodiment of the present application.
  • FIG. 12 is a schematic diagram of the structure of another data transmission device provided in an embodiment of the present application.
  • the method provided in the embodiment of the present application involves a core network, an access network and a terminal.
  • the core network and the access network can be collectively referred to as the network side (referred to as the network), and the terminal and the equipment in the network (for example, the network equipment of the access network) perform uplink and downlink signal transmission.
  • the data transmitted from the terminal to the core network through the access network is further transmitted to the external network via the core network.
  • the terminal of the embodiment of the present application is a device with wireless communication function, which can be called terminal equipment, user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal equipment, vehicle-mounted terminal equipment, industrial control terminal equipment, UE unit, UE station, mobile station, remote station, remote terminal equipment, mobile equipment, UE terminal equipment, wireless communication equipment, UE agent or UE device, etc.
  • the terminal can be fixed or mobile. It should be noted that the terminal can support at least one wireless communication technology, such as Long Term Evolution (LTE), new radio (NR), etc.
  • LTE Long Term Evolution
  • NR new radio
  • the terminal can be a mobile phone, a tablet computer, a desktop computer, a laptop computer, an all-in-one computer, a vehicle-mounted terminal, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, etc.
  • VR virtual reality
  • AR augmented reality
  • the terminal may be a wireless terminal in a city, a wireless terminal in a smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a wearable device, a terminal device in a future mobile communication network, or a terminal device in a future evolved public mobile land network (PLMN), etc.
  • the terminal may also be a device with a transceiver function, such as a chip system.
  • the chip system may include a chip and may also include other discrete devices.
  • the access network of the embodiment of the present application may be, for example, a 5G access network (NG-RAN).
  • the network device of the embodiment of the present application is a device that provides a wireless communication function for a UE, and may also be referred to as The network device is an access network device, a radio access network (RAN) device, or an access network element.
  • the network device may support at least one wireless communication technology, such as LTE, NR, etc.
  • the network device includes, but is not limited to: a next generation base station (gNB), an evolved node B (eNB), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (e.g., home evolved node B, or home node B, HNB), a baseband unit (BBU), a transmitting and receiving point (TRP), a transmitting point (TP), a mobile switching center, etc. in the fifth generation mobile communication system (5th-generation, 5G).
  • gNB next generation base station
  • eNB evolved node B
  • RNC radio network controller
  • NB node B
  • BSC base station controller
  • BTS base transceiver station
  • a home base station e.g., home evolved node B, or home node B, HNB
  • BBU baseband unit
  • TRP transmitting and receiving point
  • TP transmitting point
  • 5G fifth generation mobile communication system
  • the network device may also be a wireless controller, a centralized unit (CU), and/or a distributed unit (DU) in a cloud radio access network (CRAN) scenario, or an access network device, and may be a relay station, an access point, a vehicle-mounted device, a terminal device, a wearable device, and a network device in future mobile communications or a network device in a future evolved PLMN, etc.
  • the network device may also be a device having a wireless communication function for a terminal, such as a chip system.
  • the chip system may include a chip and may also include other discrete devices.
  • the core network (CN) of the embodiment of the present application is composed of core network network elements.
  • the core network network element can also be called core network equipment, which is a network element deployed in the core network, such as a core network control plane network element or a core network user plane network element.
  • the core network of the embodiment of the present application can be an evolved packet core network (EPC), a 5G core network (5G Core Network), or a new core network in a future communication system.
  • EPC evolved packet core network
  • 5G Core Network 5G Core Network
  • the 5G core network is composed of a group of network elements, and implements access and mobility management functions (AMF) that implement functions such as mobility management, user plane functions (UPF) that provide functions such as packet routing and forwarding and QoS (Quality of Service) management, and session management functions (SMF) that provide functions such as session management, IP address allocation and management, etc.
  • AMF access and mobility management functions
  • UPF user plane functions
  • QoS Quality of Service
  • SMF session management functions
  • the EPC can be composed of a mobility management entity (MME) that provides functions such as mobility management and gateway selection, and a mobile management entity (MME) that provides functions such as packet forwarding.
  • MME mobility management entity
  • MME mobile management entity
  • the core network consists of a Serving Gateway (S-GW) and a PDN Gateway (P-GW) that provides terminal address allocation, rate control and other functions.
  • S-GW Serving Gateway
  • P-GW PDN Gateway
  • the core network can include several new network elements to implement functions such as data packet forwarding, MBS conference management, QoS management, and transmission mode switching (switching between unicast and multicast/broadcast transmission modes). Another way is that the functions can be implemented by existing core network elements.
  • the external network of the embodiment of the present application may also be referred to as an external data network (Data Network Name, DNN), which specifically refers to a device that accesses the network constructed by the core network and the access network to transmit data with the terminal.
  • the external network may, for example, include a server that provides AF/AS.
  • AF is the application function (Application Function), which refers to various services at the application layer. It can be an application within the operator such as voice AF (volte AF), or a third-party AF (such as a video server, a game server).
  • AS is the access layer (Access Stratum).
  • sensor-terminal 1-access network 1-core network 1-external network forms a transmission link
  • sensor-terminal 2-access network 2-core network 2-external network forms another completely independent transmission link.
  • two completely independent transmission links will cause a waste of optical fiber resources between the access network and the core network.
  • IP Internet Protocol
  • an embodiment of the present application provides a data transmission method, wherein a core network sends a first parameter associated with a first session, and correspondingly, a terminal receives the first parameter, the first parameter including a first security parameter and/or a first IP address, and the first session is associated with a first service; the terminal uses the first parameter to transmit data of the first service through the first session, and correspondingly, the access network receives the data transmitted by one or more terminals through the first session; the access network merges the received data and transmits it to the next node, and correspondingly, the core network directly or indirectly receives the data transmitted by the access network; wherein, the terminals and network elements related to the first session both use the first parameter to transmit the data.
  • the first service of the embodiment of the present application refers to an uplink convergence service (or an uplink transmission service performed in a convergence manner), or a service with the same or similar characteristics defined in a future protocol.
  • the characteristics (also called features) of the first service include: n (n is greater than or equal to 1) terminals send the same user plane (in user plane) data (hereinafter referred to as data), for example, sending the same uplink user plane data at the same time.
  • the same data can refer to the same data packet, that is, each bit in the data packet sent by each of the n terminals is the same.
  • terminals to transmit the data collected by the same sensor.
  • the two terminals transmit the same received data to the access network respectively.
  • the access network successfully receives the data sent by any of the terminals, it continues to transmit it to the next node until the data is successfully transmitted to the network data server as the external network.
  • terminal 2 can be regarded as A clone of terminal 1.
  • the first session in the embodiment of the present application is associated with the first service, specifically refers to a session established for performing the first service, and the first session is associated with a unique identifier (for example, a session ID).
  • the first session may also be referred to as an uplink aggregation session.
  • the first session may be associated with n terminals, that is, the n terminals transmit data of the first service to the network through the same first session.
  • the terminals associated with the same first session are respectively configured with the same session ID, and the n terminals configured with the same session ID use the same first parameters to send the same data on the same user plane.
  • the n terminals obtain the same data to be transmitted from the same sending end, where the sending end may be, for example, a sensor.
  • n terminals associated with the same first session may form a user group, and the user group is uniquely associated with a group identifier.
  • the terminal may be associated with multiple group identifiers, wherein each group identifier is associated with a corresponding first session, thereby the terminal may carry out multiple first services in parallel.
  • the second session of the embodiment of the present application refers to a session established for performing services other than the first service, and the second session is associated with a unique identifier.
  • the second session may be, for example, a protocol data unit (PDU) session (PUD session), or may be, for example, a 4G-PDN (4G-Public Data Network).
  • PDU protocol data unit
  • 4G-PDN 4G-Public Data Network
  • the second session may correspond one-to-one to the terminal, that is, each network accessing the network establishes its own second session, and transmits data of services other than the first service to the network through its own associated second session.
  • the terminal may establish the first session with the network.
  • the first parameter of the embodiment of the present application may refer to a parameter used when transmitting data of the first service through the first session, and the terminals and network elements (including core network elements and access network elements) related to the first session all use the same first parameter to transmit the same data.
  • the terminals and network elements including core network elements and access network elements
  • the terminals and network elements including core network elements and access network elements related to the first session all use the same first parameter to transmit the same data.
  • the terminals and network elements including core network elements and access network elements
  • the first parameter may include a first security parameter and/or a first IP address.
  • the first security parameter may include user-plane security parameters, keys and algorithms, encryption keys, integrity protection keys, encryption algorithms and integrity protection algorithms, etc.
  • the first security parameter is generated for use by the terminal during the first session establishment process.
  • the first security parameter is used to protect the user-plane data, such as encryption and integrity protection.
  • the first IP address may include a source IP address.
  • the network allocates the first IP address used by the terminal to the terminal.
  • the source IP address of the IP data packet sent by the terminal to the network through the first session uses the first IP address.
  • the second parameter of the embodiment of the present application may refer to a parameter used when transmitting data of a service other than the first service through a second session.
  • the second parameter may include a second security parameter and/or a second IP address.
  • the second security parameter may include a secret key, a security algorithm, etc., and the second security parameter used by the terminal is generated in the process of the terminal accessing the network.
  • the second security parameter is used to protect the user plane data, such as encryption and integrity protection.
  • the second IP address may include a source IP address. In the process of establishing the second session, the network assigns the terminal a second IP address used by the terminal, and the source IP address of the IP data packet sent by the terminal to the network through the second session uses the second IP address.
  • the first parameter may reuse a second parameter of a terminal associated with the first session.
  • the network configures the first parameter for the n terminals associated with the first session, it may select a second parameter that has been configured for one of the n terminals, and determine the second parameter of the selected terminal as the first parameter commonly used by the n terminals.
  • the terminal that reuses the second parameter among the n terminals is recorded as the target terminal.
  • the first parameter may be a third parameter, and the third parameter does not reuse the second parameter of the terminal associated with the first session.
  • the third parameter of the embodiment of the present application may refer to a new parameter configured specifically for the n terminals for the first service associated with the first session, and the new parameter is different from the second parameter that has been configured for each of the n terminals.
  • the first security parameter can reuse the second security parameter of a terminal associated with the first session.
  • the first IP address can reuse the second security parameter of a terminal associated with the first session.
  • the first security parameter and the first IP address may both reuse the second security parameter and the second IP address of a terminal related to the first session, wherein the second security parameter reused by the first security parameter and the second IP address reused by the first IP address may be associated with the same or different terminals.
  • the first security parameter may be the third security parameter, that is, the second security parameter of the terminal associated with the first session is not reused.
  • the first IP address may be the third IP address, that is, the second IP address of the terminal associated with the first session is not reused.
  • the first security parameter may be the third security parameter and the first IP address may be the third IP address.
  • the first security parameter may reuse the second security parameter of a terminal associated with the first session, and the first IP address may be the third IP address.
  • the first security parameter may be the third security parameter, and the first IP address may reuse the second IP address of a terminal associated with the first session.
  • FIG1 is a signaling interaction diagram of a data transmission method provided in an embodiment of the present application.
  • the action performed by the terminal can be performed by a chip with a data transmission function in the terminal, or by a baseband chip in the terminal.
  • the action performed by the access network can be performed by a chip with a data transmission function in a network device, or by a baseband chip in the network device.
  • the action performed by the core network can be performed by a chip with a data transmission function in a core network element, or by a baseband chip in a core network element.
  • the core network sends the first parameter to the terminal through the access network.
  • the core network may actively send the first parameter to the terminal to trigger the terminal to execute the first service.
  • the first parameter may be preconfigured.
  • it may be preconfigured in a ME (Mobile equipment) unit or a USIM (Universal Subscriber Identity Module) of the terminal.
  • the action of the core network in S101 may be omitted, and the terminal directly obtains the first parameter from its own ME or USIM.
  • the terminal sends first information to the core network, where the first information is used to request to obtain the first parameter.
  • the core network receives the first information from the terminal.
  • the first information may include at least one of the following: first indication information, used to indicate the execution of the first service; the identity of the terminal related to the first session; session information of the first session; capability information of the terminal to support the first service; group identifier of the group to which the terminal related to the first session belongs; and identifier of a second session of the terminal related to the first session.
  • the first indication information can indicate to the network that the terminal sending the first information needs to execute the first service.
  • the network does not know in advance the specific information of the n terminals associated with the first session (that is, it does not know that the n terminals are backed up for each other), so any of the n terminals can carry the identity identifiers of the other n-1 terminals and/or the group identifier of the group to which the n terminals belong in the first information. Accordingly, the core network can configure the same first parameter to the n terminals indicated by the first information.
  • the identity of the terminal related to the first session may be omitted in the first information, which is conducive to saving signaling overhead.
  • the session information of the first session may include: the external network corresponding to the first service
  • the network information such as the network name, network identifier, slice information, IP address, and port number of the external network.
  • the capability information may indicate whether the terminal supports or does not support a feature corresponding to the first service.
  • the core network sends a first message to the terminal, the first message including a first parameter.
  • the terminal receives the first message from the core network to obtain the first parameter.
  • the first message may further include at least one of the following: second indication information, used to indicate whether the terminal and/or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein part or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
  • the content carried in the first message may be collectively referred to as relevant information of the first service.
  • the terminal may carry its own capability information when sending the first message, and the network (eg, core network) may indicate whether the network has the capability of the first service through the second indication information when returning the first message.
  • the first message may also indicate the capability information of other terminals related to the first session.
  • the terminal type may include a basic terminal and an auxiliary terminal, wherein the basic terminal may initiate an application for user plane resources (ie, resources used for the first session), while the auxiliary terminal does not initiate an application for user plane resources.
  • the basic terminal may initiate an application for user plane resources (ie, resources used for the first session), while the auxiliary terminal does not initiate an application for user plane resources.
  • the service type may include a basic service and an auxiliary service. If the first message indicates that the first service associated with the terminal is a basic service, the terminal determines that it needs to initiate an application for user plane resources when executing the first service. If the first message indicates that the first service associated with the terminal is an auxiliary service, the terminal determines not to initiate an application for user plane resources when executing the first service.
  • the session type may include a basic session and an auxiliary session, wherein the terminal corresponding to the basic session may initiate an application for user plane resources, and the terminal corresponding to the auxiliary session may not initiate an application for user plane resources.
  • the core network can specify through the first message that a part of the n terminals initiate an application for user plane resources, and the remaining part does not initiate an application for user plane resources.
  • the resources for the first session requested by terminal 2 are shared by terminal 1 and terminal 2.
  • terminal type indicated in the first message received by terminal 1 is a basic terminal
  • terminal types indicated in the first messages received by terminal 2 and terminal 3 are all auxiliary terminals. Accordingly, terminal 1 requests allocation of resources for the first session when subsequently executing the first service, and terminal 2 and terminal 3 do not initiate resource applications.
  • Terminal 1, terminal 2, and terminal 3 all use the user plane resources applied for by terminal 1 to transmit the same data through the first session.
  • the terminal may request the network to allocate user plane resources, for example using a service request message (SERVICE REQUEST).
  • SERPTION REQUEST a service request message
  • the resource used for the first session may be a preconfigured periodic resource.
  • part or all of the terminal type, service type, and session type may be omitted in the first message to save signaling overhead.
  • the first information and/or the first message may be transmitted via an access network.
  • the first information may be carried by a non-access stratum (NAS) message.
  • the first message may be carried by a NAS message.
  • the first message carried by the NAS message may include the following information element (IE):
  • IE information element
  • the indication mark of the first service 1 feature (i.e., the first indication information or the second indication information) is used to indicate whether the terminal or the network supports the feature corresponding to the first service. It can be indicated by one or more bits, such as 0 represents that the feature corresponding to the first service is not supported, and 1 represents that the feature corresponding to the first service is supported;
  • Terminal type which can be identified by one or more bits: 0 represents a basic terminal, 1 represents an auxiliary terminal;
  • Session type which can be identified by one or more bits: 0 represents a basic session, and 1 represents an auxiliary session, that is, the terminal does not send a service request message (SERVICE REQUEST).
  • NAS messages may include session management messages (5GS session management messages).
  • the session management message includes the establishment/modification/release stages of the PDU session, wherein the modification is performed after the PDU session is established, and a corresponding session management message is sent at each stage.
  • the core network implementing this implementation scheme can receive the first information or send the first message through the session management message of the corresponding stage during or after the establishment of the second session.
  • the session management message that can carry the first information or the first message may include at least one of the following: PDU session establishment request PDU session establishment request, PDU session establishment accept PDU session establishment reject PDU session establishment reject, PDU session authentication command PDU session authentication command, PDU session authentication complete PDU session authentication result PDU session authentication result, PDU session modification request PDU session modification request, PDU session modification reject, PDU session modification command, PDU session modification complete, PDU session modification command reject, PDU session modification command reject, PDU session release request, PDU session release reject, PDU session release command, PDU session release complete, 5G session management status 5GSM status, Service-level authentication command, Service-level authentication complete, Remote UE report, Remote UE report response.
  • NAS messages may include mobility management messages (5GS mobility management messages).
  • the mobility management message that can carry the first information or the first message may include at least one of the following: Registration request, Registration accept, Registration complete, Registration reject, Deregistration request (UE originating), Deregistration accept (UE originating), Deregistration request (UE terminated), Deregistration accept (UE terminated), Service request, Service reject, Service accept, Control plane service request, Network slice-specific authentication command, Network slice-specific authentication complete, Network slice-specific authentication result, Configuration update command, Configuration update complete, Authentication request, Authentication response, Authentication reject, Authentication failure, Authentication result, Identity request, Identity response, and Security mode command.
  • the first information may be carried by an AS message.
  • the first message may be carried by an AS message.
  • the AS message that can carry the first information or the first message may include at least one of the following: quantity statistics CounterCheck, quantity statistics response CounterCheckResponse, dedicated system information block (System Information Block, SIB for short) request DedicatedSIBRequest, downlink dedicated message segment DLDedicatedMessageSegment, downlink information transmission DLInformationTransfer, multi-access dual link (Multi-RAT Dual Connectivity, MR-DC) downlink information transmission DLInformationTransferMRDC, failure information FailureInformation, integrated access and backhaul (Integrated access and backhaul, IAB) other information IAB OtherInformation, positioning measurement indication LocationMeasurementIndication, log measurement configuration LoggedMeasurementConfiguration, multicast broadcast service (Multicast Broadcast Services, MBS) broadcast configuration MBSBroadcastConfiguration, MBS interest indication MBSInterestIndication, master cell group (Master Cell Group, MCG) failure information MCGFailureInformation, measurement report MeasurementReport, application layer measurement report MeasurementReportAppLayer, master information block
  • the first message may be transmitted via a container.
  • the first message may be transmitted using resources allocated for the first session.
  • the data transmission method of this embodiment may further include the steps of:
  • S102 For a terminal that is instructed to request allocation of resources for a first session, The terminal sends a second message to the core network. Correspondingly, the core network receives the second message from the terminal.
  • the second message is used to request allocation of resources for the first session.
  • the core network determines whether the second message triggers resource allocation. For example, if the terminal type of the terminal sending the second message is a basic terminal, the core network determines that resources need to be configured for the first session. For another example, if the session type carried by the second message is an auxiliary session, the core network determines not to configure resources in response to the second message.
  • S102 is an optional step.
  • the second message may be transmitted to the core network via the access network.
  • the data transmission method of this embodiment may further include the steps of:
  • the terminal In response to acquiring the first parameter, the terminal transmits data of the first service to the access network through the first session using the first parameter. Accordingly, the access network receives data transmitted by one or more terminals through the first session.
  • S103 may be executed.
  • the terminal may process data using the first security parameter and transmit the processed data as an Ethernet data packet.
  • the data to be transmitted received by the terminal is a Media Access Control (MAC) packet, which begins with a MAC address.
  • MAC Media Access Control
  • the terminal does not use the first IP address when transmitting the Ethernet data packet, nor does it package the data into an IP data packet.
  • the action of the terminal using the first security parameter to process the Ethernet data packet may be performed at the application layer.
  • the terminal may process data using the first security parameter and transmit the processed data using the first IP address.
  • the terminal packages the received data into an IP data packet and transmits it using the first IP address.
  • the sensor can transmit the data of the first service according to the network instruction, and the user route selection policy (Route Selection Policy, URSP) of the identity card of the terminal receiving the data is configured with an application identifier (APP-ID) and a corresponding session attribute (used to configure whether the data transmitted by the corresponding application is processed in Ethernet or IP form). Accordingly, the sensor sends the data packaged in a corresponding form to the terminal according to the session attributes of the terminal. In response to receiving the data, the terminal executes S103 to process and transmit the data to the access network.
  • APP-ID application identifier
  • a corresponding session attribute used to configure whether the data transmitted by the corresponding application is processed in Ethernet or IP form
  • the terminal determines whether to package the received data into an IP data packet or an Ethernet data packet according to the pre-configured session attributes.
  • the data transmission method of this embodiment may further include the steps of:
  • the access network in response to receiving data transmitted by one or more terminals through the first session, merges the received data and transmits it to the next node. Accordingly, the next node receives the data transmitted by the access network.
  • FIG1 is exemplarily shown by taking the next node as the core network as an example, that is, the core network directly receives the data transmitted by the access network.
  • the next node may be, for example, another terminal, which acts as a relay node, and the core network indirectly receives data transmitted by the access network through at least one relay node.
  • the hardware processing capability similar to that of the base station may be enhanced so that the terminal as a relay node can perform actions similar to S104.
  • the access network in response to successfully receiving data of a first service transmitted by a terminal through a first session, the access network may execute S104.
  • the first security parameter may be a third security parameter, and the action of processing data using the first security parameter may be performed at the service layer (serving layer) of the terminal. Further, the first message sent by the core network includes the third security parameter, and the terminal and/or the access network determines the third security parameter as the first security parameter and uses it.
  • the service layer may include an IP layer and an application, and the MAC layer described in this example is a MAC layer within the 3GPP scope.
  • the first security parameter is carried by a NAS message.
  • the terminal uses the first security parameter to encrypt data at the service layer of its own protocol stack, and then transmits it layer by layer to the access network through the first session.
  • the data processed by the service layer e.g., IP layer
  • SDAP Service Data Adaptation Protocol
  • PDCP Packet Data Convergence Protocol
  • RLC Radio Link Control
  • the access network does not obtain and use the first security parameter, and accordingly, in S104, the access network transparently transmits the received data to the core network. For example, on the access network side, after receiving data transmitted by at least one terminal through the first session layer by layer via the MAC layer, the RLC layer, the PDCP layer, and the SDAP layer, the received data is directly merged and transmitted to the next node.
  • the core network may de-process the data using the first security parameter.
  • the de-processing may include operations such as decryption and de-protection.
  • an uplink convergence transmission function or a user plane function (UPF, User Plane Function) specially added by the core network may use the first security parameter to perform security operations on the data to obtain de-processed data.
  • UPF User Plane Function
  • scenario 1 there is no need to transmit the first security parameter using RRC signaling at the PDCP layer of the terminal and the access network, but the data is encrypted using the first security parameter directly from the IP layer on the terminal side to the PDCP layer. At this time, the data is directly transmitted to the core network through the access network, and the core network performs decryption operations using the first security parameter.
  • the decrypted and unprotected data can be further transmitted from the core network to the external network.
  • the first security parameter is carried by a NAS message.
  • the terminal uses the first security parameter to add a service layer of its own protocol stack.
  • the encrypted data is then transmitted layer by layer to the access network through the first session.
  • the data processed by the IP layer is transmitted to the access network via the SDAP layer, the PDCP layer, the RLC layer, and the MAC layer in sequence.
  • the data transmission method described in this embodiment may also include the step: S105, the access network obtains the first security parameter from the core network.
  • the access network may obtain the first security parameter from the core network through other channels.
  • the access network may obtain the first security parameter through the N2 interface between the access network and the AMF (Access and Mobility management Function) of the core network.
  • AMF Access and Mobility management Function
  • the access network uses the first security parameter to de-process the same data received from different terminals and merges them to obtain de-processed data, and then transmits the de-processed data to the next node, thereby improving the reliability of transmission.
  • the protocol stack of the access network in scenario 2 adds a service layer (e.g., IP layer), and the newly added IP layer has a decryption function.
  • the access network decrypts the data and transmits it in plain text to the next node (e.g., UPF of the core network).
  • the data received by the core network from the access network is processed using the first security parameter solution.
  • the action of using the first security parameter to process data may be performed at a service layer of the access network, specifically, at a newly added IP layer of the access network.
  • the first security parameter may reuse a second security parameter of a terminal associated with the first session, and the action of processing data using the first security parameter may be performed at a protocol layer of the terminal.
  • the protocol layer refers to a protocol within the 3GPP scope, such as SDAP, PDCP, RLC, MAC, MM, and SM.
  • the data transmission method described in this embodiment may further include the step: S106, the core network sends a third message to the access network.
  • the access network receives the third message from the core network.
  • the third message may include the identity of the target terminal and the identifier of the second session of the target terminal.
  • the target terminal specifically refers to the terminal that multiplexes the second security parameter among the n terminals related to the first session.
  • the data transmission method described in this embodiment may further include the step: S107, the access network sends a fourth message to the core network.
  • the core network receives the fourth message sent by the access network.
  • the fourth message may include the second security parameter of the target terminal.
  • the core network determines the second security parameter as the first security parameter, and sends the first security parameter to the terminal through an AS message by executing S101.
  • the core network sends the first security parameter to the access network through RRC signaling, and the access network obtains and sends the first security parameter to the terminal through the PDCP layer using RRC signaling.
  • the terminal uses the first security parameter to encrypt data at the PDCP layer and transmits the data to the access network layer by layer.
  • the access network uses the first security parameter to process and merge the same data received from different terminals at the protocol layer, and then transmits it to the next node in plain text.
  • the action of processing the data using the first security parameter can be performed at the PDCP layer of the access network.
  • the data received by the core network from the access network is data processed using the first security parameter solution.
  • the communication system ensures data transmission reliability through redundant transmission at the air interface, and after the redundantly transmitted data is successfully received at the access network side, the same optical fiber can be reused for further transmission.
  • optical fiber resources are saved, which is conducive to reducing the deployment cost of the communication system.
  • the communication system may include a terminal, an access network, a core network and an external network.
  • Figure 5 exemplifies the security architecture of each network component at the service layer, wherein the terminal includes UE1 and UE2, the access network includes NG-RAN, the core network includes AMF network element, SMF network element, first network element and UPF network element, and the external network includes AF/AS server.
  • the AMF network element is used to provide AMF
  • the SMF network element is used to provide SMF
  • the UPF network element is used to provide UPF.
  • the core network of the embodiment of the present application adds a first network element for processing the first service.
  • the first parameter can be configured by the first network element.
  • the first network element may include a first service management function network element for providing a first service management function.
  • the first network element may include a first service transmission function network element for providing a first service transmission function.
  • the AMF network element, the SMF network element and the first service management function network element can be integrated into the signaling plane of the core network.
  • the UPF network element and the first service transmission function network element can be integrated into the data plane of the core network.
  • the first network element may implement the following functions:
  • Manage e.g., determine, generate, allocate, update, release
  • resources related to the first service For example, session type, session ID, first parameter (including first IP address, first security parameter (e.g., key, algorithm)), etc.
  • This first parameter is used for the first service.
  • the first security parameter is used to protect the data, such as encryption and integrity protection.
  • the first IP address is used as the source IP address of the data packet sent by the terminal;
  • the first parameter may include a first security parameter and a first IP address.
  • the relevant information may be carried in a container, or the relevant information may be transmitted in a message (such as a NAS message, RRC signaling) or in user plane data;
  • the first security parameter of the first service e.g., user plane key
  • perform security operations such as decryption and deprotection, for example, decrypting and deprotecting user plane data packets from UE; after deprotection, they can be transmitted to the external network.
  • the first network element may be provided with a public interface for providing capability information of the first service.
  • the capability information may indicate whether the first service supports n terminals to send the same data on the same user plane.
  • the public interface may also provide service information of the first service, such as the start/end time of the first service, the communication status of the network, and the like.
  • the public interface may also provide requirement information for receiving the first service.
  • the public interface can be a physical/logical interface between the core network and the server of the external network, which is used to transmit relevant information of the first service.
  • the first service management function network element can set a public interface at the AF/AS server.
  • the first service transmission function network element can also set a public interface at the AF/AS server.
  • an information disclosure interface and a service management interface for the first service can be provided.
  • the execution time of the first service such as the start and end time, the geographical scope such as the tracking area, the cell; the information of the external network corresponding to the first service such as the network name, the IP address; the slice information corresponding to the first service; the service quality of the first service, the information of the terminal associated with the first service, such as the reachability of the terminal, the number of terminals n.
  • network elements other than the first network element of the core network can implement the following functions:
  • the relevant information may be obtained from a first service management function network element;
  • the request to execute the first service can be transmitted in a NAS message, such as an MM message or an SM message, or can be transmitted in a user plane;
  • the related session of the first service ie, the first session
  • managing the related session of the first service such as establishing, modifying, and releasing the first session associated with the first service based on a service request of the terminal or a service request of the application;
  • first parameters including first IP address, first security parameters
  • session ID including first IP address, first security parameters
  • session type including first IP address, session ID, session type, session quality, and policy information (such as URSP, session management policy);
  • policy information such as URSP, session management policy
  • the UPF network element can implement the following functions:
  • the access network may implement the following functions:
  • the aggregation includes: merging the same data packets from different terminals, which can improve the reliability of transmission.
  • a terminal may implement the following functions:
  • uplink data belonging to the first service can be identified, and the service layer data can be protected, for example, using the first security parameter to protect the IP packet, Ethernet packet, unstructured data, etc. sent by the terminal, such as encryption and integrity protection; the protection operation can be performed at the service layer of the terminal or at the PDCP; if the protection operation is performed at the service layer, the PDCP layer may not perform integrity protection on the data.
  • Security protection such as encryption, that is, the access network and the terminal do not perform security operations such as encryption of the user plane of the first service;
  • a base station such as NG-RAN
  • AMF network element/SMF network element/first network element where the first message includes first service request (such as activation, modification, release) information, and the first information may be carried in a NAS message, which may be an MM or SM message; the SM message may be a PDU session activation, modification, release, and other messages;
  • receiving relevant information of the first service for example, receiving relevant information of the first service from the base station/AMF network element/SMF network element/PCF network element/first network element, such as session ID, session type, session quality, policy information (such as URSP, session management policy), first parameters (including first security parameters, first IP address), etc.;
  • the first service may be implemented by existing network elements of the core network.
  • the first service management function can be integrated with the SMF.
  • the first service management function network element in FIG5 can be omitted, and the first service management function is implemented by the SMF.
  • the first service transmission function can be integrated with the UPF.
  • the first service transmission function network element in FIG5 can be omitted, and the first service transmission function is implemented by the UPF.
  • the first service management function and/or the first service transmission function may be implemented by a PCF of the core network, or may be implemented by a UDM function of the core network.
  • the first service may be implemented in an access network, that is, the access network may add a first network element to implement a first service management function and/or a first service transmission function.
  • the communication system shown in FIG5 can perform the above
  • the method shown in FIG1 is described to execute the first service at the service layer.
  • the specific process of each network component executing the first service is described in detail with reference to FIG1 to FIG6.
  • the function of the access network is performed by the base station gNB, which is equivalent to the NG-RAN shown in FIG5 above.
  • Step 0a UE1 completes registration by interacting with the AMF network element (or SMF network element) through the base station, and similarly, UE2 also completes registration with the network.
  • the registration message may indicate that the terminal or the network supports or does not support the first service.
  • UE1 and UE2 respectively establish a second session with the network, and the second session may be, for example, a PDU session.
  • the second session may be, for example, a PDU session.
  • UE1 requests data transmission from the network, and the network allocates data transmission resources to each network element and UE1, thereby completing the establishment of the second session.
  • UE1 and UE2 may establish a first session with the network.
  • Step 1 UE2 can send the first information to the AMF network element (or SMF network element) through the base station.
  • Step 1b the AMF network element (or SMF network element) transmits the first information to the first service management function network element to request relevant information of the first service, such as the first parameter.
  • the first service management function network element manages the first service, for example, obtains and determines relevant information of the first service, such as the first parameter.
  • the process of obtaining information can interact with the core network element, such as interacting with the UDM for contract information, interacting with the PCF for policy information, interacting with the SMF for session information, and interacting with the UPF for user plane information.
  • the interaction includes operations such as obtaining, providing, updating, releasing, and deleting.
  • the first parameter is the third parameter.
  • a core network user plane node such as a UPF network element or a first service transmission function network element may obtain relevant information of the first service, such as a first parameter, from a first service management function network element.
  • Step 3b the first service management function network element provides the AMF/SMF network element with relevant information of the first service, such as the first parameter.
  • Step 3c The first service management function network element provides the base station with relevant information of the first service, such as the first parameter.
  • Step 3c is an optional step.
  • the first parameter It can be forwarded to the base station by the AMF/SMF network element.
  • Step 4 The network sends a first message to UE2, where the first message includes the first parameter and other relevant information of the first service.
  • the first message may be received from any one of the AMF/SMF network element, the base station, and the first service management function network element.
  • Step 4' The network instructs UE1 to start executing the first service and sends a first message.
  • Step 5 UE2 saves the content of the received first message, such as saving the first parameter and other related information of the first service. Similarly, UE1 saves the content of the received first message.
  • Step 6 The application layer (such as a sensor) sends a data packet 1 to UE 2.
  • the data packet 1 is data of the first service.
  • Step 7 UE2 processes data packet 1 using the first security parameter at the service layer to obtain a processed data packet.
  • step 7 UE2 can use the first security parameter at the protocol layer to perform security processing on data packet 1.
  • the processed data packet is transmitted to the base station through the first session.
  • the resources used by UE2 to transmit data of the first service have been preconfigured.
  • the base station may execute step 8a to decrypt and deprotect the received data packet using the first security parameter acquired in step 3c.
  • the base station may also receive the same data packet from UE1, and also use the first security parameter to decrypt and deprotect the received data packet.
  • the base station may combine the data packets received from UE1 and UE2 and transmit the combined data packets to the core network.
  • UE2 in step 7, can use the first security parameter to securely process data packet 1 at the service layer (e.g., IP layer), and the protocol layer of UE2 (e.g., PDCP layer or SDAP layer) no longer securely processes the data.
  • the processed data packet is transmitted to the base station through the first session, and then transparently transmitted to the core network via the base station.
  • the service layer e.g., IP layer
  • the protocol layer of UE2 e.g., PDCP layer or SDAP layer
  • step 3c may be omitted.
  • the UPF network element or the first service transmission function network element executes step 8b to decrypt and deprotect the received data packet using the first security parameter.
  • the decrypted and deprotected data can then be transmitted to the external network.
  • the AMF network element is used to provide AMF
  • the SMF network element is used to provide SMF
  • the UPF network element is used to provide UPF.
  • the core network of the embodiment of the present application adds a first network element for processing the first service.
  • the first parameter can be configured by the first network element.
  • the first network element may include a first service management function network element for providing the first service management function.
  • the AMF network element, the SMF network element and the first service management function network element can be integrated into the signaling plane of the core network.
  • the UPF network element can be integrated into the data plane of the core network.
  • the terminal may implement the following functions:
  • the uplink data of the first service is securely protected, for example, the PDCP layer performs encryption and/or integrity protection;
  • the terminal determines whether to initiate a resource application based on at least part of the session type, terminal type and service type configured by the network.
  • a service request procedure SEQUEST procedure
  • the core network implements the following functions:
  • the core network manages and allocates resources required for the first service, which can be specifically performed in AMF, SMF, or other core network functions such as the first service management function.
  • the action of the core network managing and allocating resources required for the first service can be performed after the network receives a request from the terminal to execute the first service, for example, triggered by a request from the terminal. It can also be performed before the network receives a request from the terminal, for example, when the network triggers (Network originating, or Initiating) the execution of the first service, the network triggers the process required to execute the first service, such as the process of establishing a PDU session.
  • the core network provides relevant information of the first service, for example, the core network provides relevant information of the first service to the terminal, the access network, and the external network such as the application service, and the core network network elements provide relevant information of the first service;
  • the core network obtains part of the first service related information from the access network, such as the first security parameter.
  • the first parameter reuses the second parameter of a terminal related to the first session.
  • the access network may implement the following functions:
  • the access network may provide some or all of the relevant information of the first service to the core network. Further, the access network may provide some or all of the relevant information of the first service to the terminal.
  • the USIM of the terminal may store and provide information required for the first service, such as policy, service type, session type, application ID, etc.
  • the first network element may be provided with a public interface to provide at least a portion of capability information, service information and demand information of the first service.
  • the first service management function and the AF/AS server may communicate with each other through the public interface.
  • the communication system shown in FIG6 can execute the method shown in FIG1 to execute the first service at the service layer.
  • the specific process of each network component executing the first service is described in detail with reference to FIG1 to FIG4, FIG7 and FIG8.
  • the function of the access network is performed by the base station gNB, which is equivalent to the NG-RAN shown in FIG5.
  • step 0a and step 0b can refer to the relevant description in the application scenario 1 shown in FIG6 , which will not be described in detail here.
  • the base station obtains the second security parameter and the second IP address of UE1 during the registration process of UE1.
  • UE1 and UE2 each obtain their own second security parameters and second IP addresses, which are used in the protocol layer (e.g., PDCP layer) of the terminal, and UE1 and UE2 respectively inform the base station of the second security parameters and second IP addresses through RRC signaling.
  • the second security parameters of UE1 are different from the second security parameters of UE2, and the second IP address of UE1 is different from the second IP address of UE2.
  • Step 1 UE2 may send first information to an AMF network element (or SMF network element) through a base station. Further, the AMF network element (or SMF network element) transmits the first information to a first service management function network element to request relevant information of the first service, such as a first parameter.
  • AMF network element or SMF network element
  • a first service management function network element to request relevant information of the first service, such as a first parameter.
  • Step 2 The core network establishes a first session to process the first service, and allocates relevant information of the first service to the first session, such as the first IP address and first security parameter used by the terminal to send data, and the identifier of the first session.
  • the first IP address needs to reuse the second IP address of UE1, and the first security parameter reuses the second security parameter of UE1.
  • Step 3 The core network may request the access network for resource information required for the first service, such as the second IP address and/or the second security parameter of UE1. Accordingly, the access network provides the core network with the resource information required for the first service.
  • the AMF network element of the core network may The N2 interface sends a third message to the base station and receives a fourth message fed back by the base station to obtain the second IP address and/or second security parameter of UE1.
  • the third message and/or the fourth message may be carried by an AS message.
  • the resource information required for the first service provided by the access network to the core network may be a response to the resource information required for the first service requested by the core network to the access network, or may be triggered by the access network (e.g., originating, or Initiating) to provide the resource information required for the first service to the core network. For example, when the corresponding information in the access network changes, the corresponding information may be actively updated to the core network. Thus, through the subsequent interaction between the network and UE2, UE2 may use the second security parameter of UE1 to transmit data of the first service.
  • Step 4 The network sends a first message to UE2, where the first message includes the first parameter and other relevant information of the first service.
  • the first message may be received from an AMF/SMF network element.
  • the core network may provide the information in a NAS message, such as a mobility management message, a session management message, or may provide the information through a user plane.
  • part of the content in the first message e.g., the second security parameter of UE1
  • a radio resource management message e.g., RRC signaling
  • Step 4' the network (such as AMF/SMF network element) instructs UE1 to start executing the first service, and the first IP address of the first service is the second IP address of UE1. Further, the network can also send at least part of the content in the first message, such as the identifier of the first session.
  • the network such as AMF/SMF network element
  • Step 5 UE2 saves the content of the received first message, such as saving the second IP address and the second security parameter of UE1.
  • Step 6 The application layer data source (such as a sensor) sends data packet 1 to UE1 and UE2, where data packet 1 is data of the first service.
  • the source IP address of the transmission data packet 1 may be the first IP address.
  • UE1 sends a second message to request the network to allocate resources for the first session.
  • the terminal needs to request the network to allocate resources to the terminal when uploading data, including time and frequency resources of the air interface.
  • the source transmits the same data packet 1, so one of the terminals can request the network to allocate resources.
  • the AMF/SMF network element indicates that UE1 is a basic terminal in step 4', and UE1 determines in step 6 that it needs to send a second message to request the network to allocate resources for the first session.
  • UE2 determines that data packet 1 is data of the first service based on the source IP address used by data packet 1, and because the AMF/SMF network element indicates that UE2 is an auxiliary terminal in the first message sent to UE2 in step 4, UE2 does not initiate a resource allocation request in step 6.
  • UE1 may request resource allocation using a SERVICE REQUEST procedure. Further, the second message may carry an identifier of the first session.
  • the network allocates resources for the first service after the network receives the second message from the terminal, for example, triggered by a request from UE1. It can also be before the network receives the second message from the terminal, for example, when the network triggers (e.g., Network originating, or Initiating) to actively execute the first service.
  • the process of network triggering the execution of the first service can be implemented, for example, during the establishment of a PDU session.
  • the network may be a function of an access network.
  • a base station may respond to the second message and allocate resources for the first session to the first service.
  • the network may be a function of a core network, for example, an AMF network element or an SMF network element may respond to the second message and allocate resources for the first session to the first service.
  • the base station may notify UE1 that the resource establishment for the first session is completed.
  • the base station may also notify UE2 that the resource establishment for the first session is completed.
  • Step 7 UE1 and UE2 respectively use the relevant information of the first service to process data packet 1. Specifically, UE1 uses its own second security parameter as the first security parameter to process data packet 1, and uses its own second IP address as the first IP address to transmit the processed data through the first session. In parallel, UE2 uses UE1's second security parameter as the first security parameter to process data packet 1. The data packet 1 is processed with all parameters, and the processed data is transmitted through the first session using the second IP address of UE1 as the first IP address.
  • the second security parameter of UE1 may be used at the protocol layer to process data packet 1.
  • the base station may perform step 8a, decrypt and deprotect the received data packet using the second security parameter of UE1 obtained during the registration phase of UE1, and transmit the data packet to the core network after merging.
  • data packet 1 may be an Ethernet data packet. Accordingly, when UE1 and UE2 each process the received data packet 1 using the first security parameter, the processed data is packaged into an Ethernet data packet for transmission to the next node (e.g., a base station).
  • the next node e.g., a base station
  • UE2 can send a second message.
  • the network determines whether resources have been allocated for the first session based on the identifier of the first session in the second message. If resources have been allocated, the resource allocation request of UE2 is not responded to.
  • different terminals can obtain or preconfigure the same first IP address from the network for the terminal to send data of the first service. Further, different terminals can obtain or preconfigure the same first security parameter from the network for security processing when the terminal sends data of the first service.
  • the core network may manage resources related to the first service (eg, information related to the first service), such as generating a first IP address or a first security parameter, or obtaining a first security parameter (eg, a user plane key) from the access network.
  • resources related to the first service eg, information related to the first service
  • the first information/first message may carry relevant information of the first service/information indicating capability of the first service.
  • the network can provide a public interface related to the first service, such as information disclosure and capability disclosure.
  • a third-party server can propose a service requirement to the network: the power grid hopes When the first service starts, the core network can be informed of the demand information through the public interface, and the core network configures the relevant parameters to the access network and the terminal.
  • the operator server can inform the third-party server of the service information of the first service, such as the communication status of the network, through the public structure of the core network.
  • FIG9 is a schematic diagram of the structure of a data transmission device (denoted as data transmission device 2 ) provided in an embodiment of the present application.
  • the data transmission device 2 of this embodiment can be used to implement the methods described in the embodiments described in Figures 1 to 8.
  • the data transmission device 2 can be the terminal mentioned above.
  • the data transmission device 2 may include: an acquisition module 21, used to obtain a first parameter associated with a first session, the first parameter includes a first security parameter and/or a first Internet Protocol IP address, and the first session is associated with a first service; a transmission module 22, used to use the first parameter to transmit data of the first service through the first session; wherein, the terminals related to the first session all use the first parameter to transmit the data.
  • the data transmission device 2 may further include: a sending module (not shown) for sending first information, the first information being used to request the acquisition of the first parameter.
  • the acquisition module 21 includes: a receiving unit (not shown) for receiving the first parameter associated with the first session.
  • the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
  • the first information is carried via a non-access layer message or an access layer message.
  • the transmission module 22 may include: a first transmission unit (not shown) for processing the data using the first security parameter and transmitting the processed data as an Ethernet data packet; or a second transmission unit (not shown) for processing the data using the first security parameter and transmitting it using the first IP address.
  • the acquisition module 21 may include: a receiving unit (not shown), configured to receive a first message, where the first message includes a first parameter associated with the first session.
  • the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and/or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
  • the first message is carried via a non-access layer message or an access layer message.
  • the first parameter is preconfigured.
  • the first parameter multiplexes a second parameter of a terminal associated with the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal associated with the first session, and the second parameter is associated with a service other than the first service.
  • the action of processing the data using the first security parameter is performed at a service layer, or the action of processing the data using the first security parameter is performed at a protocol layer.
  • the above-mentioned data transmission device 2 may correspond to a chip with a data transmission function in a terminal, or to a chip with a data processing function, such as a system-on-a-chip (SOC for short), a baseband chip, etc.; or to a chip with a data transmission function in a terminal.
  • the end includes a chip module with a data transmission function chip; or corresponds to a chip module with a data processing function chip, or corresponds to a terminal.
  • FIG10 is a schematic diagram of the structure of another data transmission device (referred to as data transmission device 3) provided in an embodiment of the present application.
  • data transmission device 3 can be used to implement the methods described in the embodiments described in FIGS. 1 to 8 above.
  • the data transmission device 3 can be the access network mentioned above.
  • the data transmission device 3 may include: a receiving module 31, used to receive data transmitted by one or more terminals through a first session, the first session is associated with a first service, the data is data of the first service, and the terminals related to the first session all use first parameters to transmit the data, and the first parameters include a first security parameter and/or a first IP address; a transmission module 32, used to merge the received data and transmit it to the next node.
  • the first security parameter is a third security parameter
  • the third security parameter does not reuse the second security parameter of the terminal related to the first session
  • the second security parameter is associated with services other than the first service.
  • the data transmission device 3 may also include: an acquisition module (not shown) for acquiring the first security parameter from the core network.
  • the first security parameter multiplexes a second security parameter of a terminal related to the first session, and the second security parameter is associated with a service other than the first service.
  • the transmission module 32 may include: a processing unit (not shown) for deprocessing the data using the first security parameter and merging them to obtain deprocessed data; and a transmission unit (not shown) for transmitting the deprocessed data to the next node.
  • the action of de-processing the data using the first security parameter is performed at a service layer, or the action of de-processing the data using the first security parameter is performed at a protocol layer.
  • the data transmission device 3 may also include: a receiving unit (not shown in the figure), used to receive a third message from the core network, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; a sending unit (not shown in the figure), used to send a fourth message, the fourth message including the second security parameter of the target terminal, and the first security parameter multiplexes the second security parameter of the target terminal.
  • the above-mentioned data transmission device 3 may correspond to a chip with a data transmission function in a network device of an access network, or to a chip with a data processing function, such as a system-on-a-chip (SOC for short), a baseband chip, etc.; or to a chip module including a chip with a data transmission function in a network device of an access network; or to a chip module with a chip with a data processing function, or to a network device of an access network.
  • SOC system-on-a-chip
  • FIG11 is a schematic diagram of the structure of another data transmission device (referred to as data transmission device 4) provided in an embodiment of the present application.
  • data transmission device 4 can be used to implement the methods described in the embodiments described in FIGS. 1 to 8 above.
  • the data transmission device 4 can be the core network mentioned above.
  • the data transmission device 4 may include: a sending module 41, used to send a first parameter associated with a first session, the first parameter includes a first security parameter and/or a first IP address, and the first session is associated with a first service; a receiving module 42, used to receive data of the first service transmitted by an access network, and the data is transmitted through the first session; wherein, network elements related to the first session all use the first parameter to transmit the data.
  • the data transmission device 4 may further include: a first information receiving module (not shown) for receiving first information, where the first information is used to request to obtain the first parameter.
  • a first information receiving module (not shown) for receiving first information, where the first information is used to request to obtain the first parameter.
  • the sending module 41 may include: a sending unit (not shown), Used to send a first message, where the first message includes a first parameter associated with the first session.
  • the first information includes at least one of the following: first indication information, used to indicate the execution of the first service; an identity of a terminal related to the first session; session information of the first session; capability information of the terminal in supporting the first service; a group identifier of a group to which the terminal related to the first session belongs; an identifier of a second session of the terminal related to the first session, the second session being associated with services other than the first service.
  • the first message also includes at least one of the following: second indication information, used to indicate whether the terminal and/or network supports the first service; the identifier of the first session; the terminal type; the service type of the first service; the session type of the first session; wherein some or all of the terminal type, service type, and session type are used to indicate whether to request allocation of resources for the first session.
  • the first information is carried via a non-access layer message or an access layer message; and/or, the first message is carried via a non-access layer message or an access layer message.
  • the first parameter multiplexes the second parameter of a terminal related to the first session, or the first parameter is a third parameter, the third parameter does not multiplex the second parameter of the terminal related to the first session, and the second parameter is associated with a service other than the first service; and/or the data includes at least one of the following: Ethernet data packet; IP data packet.
  • the data transmission module 4 may further include: a processing module (not shown) configured to process the data using the first security parameter solution.
  • the data received from the access network is data processed using the first security parameter solution.
  • the data transmission module 4 may further include: a second message receiving unit (not shown) for receiving a second message for requesting allocation of resources for the first session; and a configuration unit (not shown) for configuring the resources.
  • the data transmission module 4 may also include: a third message sending module (not shown in the figure), used to send a third message, the third message including the identity of the target terminal and the identifier of the second session of the target terminal; a fourth message receiving module (not shown in the figure), used to receive a fourth message, the fourth message including the second security parameter of the target terminal, and the first parameter reuses the second security parameter.
  • a third message sending module (not shown in the figure), used to send a third message, the third message including the identity of the target terminal and the identifier of the second session of the target terminal
  • a fourth message receiving module not shown in the figure
  • the first parameter is configured by a first network element of a core network, and the first network element is used to process the first service.
  • the first network element is provided with a public interface for providing capability information and/or service information of the first service, and/or receiving demand information of the first service.
  • the above-mentioned data transmission device 4 may correspond to a chip with a data transmission function in a core network element, or to a chip with a data processing function, such as a system-on-a-chip (SOC for short), a baseband chip, etc.; or to a chip module in a core network element that includes a chip with a data transmission function; or to a chip module with a chip with a data processing function, or to a core network element.
  • SOC system-on-a-chip
  • each module/unit included in each device or product described in the above embodiments may be a software module/unit or a hardware module/unit, or may be partly a software module/unit and partly a hardware module/unit.
  • each module/unit contained therein may be implemented in the form of hardware such as circuits, or at least some of the modules/units may be implemented in the form of software programs, which run on a processor integrated inside the chip, and the remaining (if any) modules/units may be implemented in the form of hardware such as circuits; for each device or product applied to or integrated in a chip module, each module/unit contained therein may be implemented in the form of hardware such as circuits, and different modules/units may be located in the same component (such as a chip, circuit module, etc.) or different components of the chip module, or at least some of the modules/units may be implemented in the form of software programs.
  • the software program runs on the processor integrated inside the chip module, and the remaining (if any) modules/units can be implemented in hardware such as circuits; for various devices and products applied to or integrated in the terminal, the various modules/units contained therein can be implemented in hardware such as circuits, and different modules/units can be located in the same component (for example, chip, circuit module, etc.) or in different components in the terminal, or, at least some modules/units can be implemented in the form of a software program, which runs on the processor integrated inside the terminal, and the remaining (if any) modules/units can be implemented in hardware such as circuits.
  • An embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored.
  • a computer program is executed by a processor, the steps of the data transmission method provided in the embodiments shown in Figures 1 to 8 above are executed.
  • the storage medium may include a non-volatile memory or a non-transitory memory, and may also include an optical disk, a mechanical hard disk, a solid-state hard disk, etc.
  • FIG. 12 is a schematic diagram of the structure of another data transmission device provided in an embodiment of the present application.
  • the data transmission device may include a processor 51, the processor 51 and the memory 52 are coupled, and the memory 52 may be located inside the device or outside the device.
  • a transceiver 53 is also included.
  • the memory 52, the processor 51 and the transceiver 53 may be connected via a communication bus.
  • the memory 52 stores a computer program that can be run on the processor 51, and the processor 51 executes the steps of the data transmission method provided in the embodiments shown in FIGS. 1 to 8 when running the computer program, and the transceiver 53 may perform the sending and/or receiving actions mentioned above under the control of the processor 51.
  • the data transmission device may be the network device mentioned above, or may be a terminal, or may be a core network element.
  • the memory 52 includes a non-volatile memory or a non-transitory memory, and may also include an optical disk, a mechanical hard disk, a solid-state hard disk, etc.
  • the processor 51 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
  • CPU central processing unit
  • DSP digital signal processors
  • ASIC application-specific integrated circuits
  • FPGA field programmable gate arrays
  • a general-purpose processor may be a microprocessor or any conventional processor, etc.
  • each flow process and/or box in the flow chart and/or block diagram and the combination of the flow chart and/or box in the flow chart and/or block diagram can be realized by computer program instructions.
  • These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processing machine or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for realizing the function specified in one flow chart or multiple flows and/or one box or multiple boxes of the block diagram.
  • These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.
  • At least one refers to one or more, and “more than one” refers to two or more.
  • “And/or” describes the association relationship of associated objects, indicating that three relationships may exist.
  • a and/or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural.
  • the character “/” generally indicates that the previous and subsequent associated objects are in an “or” relationship.
  • At least one of the following” and similar expressions refer to any combination of these items, including any combination of single or plural items.
  • At least one of a, b and c can be represented by: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, c can be single or multiple.
  • the terms “include”, “comprises” or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device.
  • an element defined by the sentence “includes a " does not exclude the presence of other identical elements in the process, method, commodity or device including the element.
  • the present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules.
  • program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types.
  • the present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network.
  • program modules may be located in local and remote computer storage media, including storage devices.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请提供了一种数据传输方法及装置、计算机可读存储介质,涉及通信技术领域。该方法包括:核心网发送第一会话关联的第一参数,相应的,终端接收第一参数,所述第一参数包括第一安全参数和/或第一IP地址,所述第一会话关联第一业务;终端使用所述第一参数通过所述第一会话传输所述第一业务的数据,相应的,接入网接收一个或多个终端通过第一会话传输的所述数据;接入网合并接收到的所述数据并向下一节点传输,相应的,核心网直接或间接接收接入网传输的所述数据;其中,与所述第一会话相关的终端和网元均使用所述第一参数传输所述数据。通过本公开方案能够允许多个终端传输相同的数据,以实现空口端的冗余传输。

Description

数据传输方法及装置、计算机可读存储介质
本申请要求2023年11月3日提交中国专利局、申请号为202311460290.3、发明名称为“数据传输方法及装置、计算机可读存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,具体地涉及一种数据传输方法及装置、计算机可读存储介质。
背景技术
终端和网络进行无线通信期间,若两者之间的无线链路不稳定,可能造成数据传输失败。当终端发送的数据比较重要时,如果因链路不稳定而造成数据传输失败,将严重损害整个通信系统的通信质量。例如,在基于物联网的传感器数据传输场景中,传感器采集的数据通过终端经由无线链路传输至网络,再由网络传输至使用传感器数据的外部网络(例如,第三方服务器或运营商服务器),如果因终端和网络间的无线链路不稳定而造成传感器数据无法成功到达外部网络,将影响外部网络正常使用传感器数据。
现有一种解决方案是进行端到端的冗余传输,也即在发送端(例如,终端)和接收端(例如,外部网络)之间建立两条完全独立的传输链路,其中每一条传输链路均包括空口传输区段和光纤传输区段。这种解决方案虽然通过冗余传输提高数据到达外部网络侧的成功率,但是,实践中,数据传输的失败大多是由于空口传输区段的无线链路不稳定造成的,现有这种端到端的冗余传输方案增加了不必要的光纤资源,造成非常大的资源浪费。
发明内容
本申请解决的技术问题是如何允许多个终端传输相同的数据,以实现空口端的冗余传输。
为解决上述技术问题,本申请实施例提供一种数据传输方法,包括:获取第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一互联网协议IP地址,所述第一会话与第一业务关联;使用所述第一参数通过所述第一会话传输所述第一业务的数据;其中,与所述第一会话相关的终端均使用所述第一参数传输所述数据。
可选的,所述第一参数为预配置的。
可选的,所述数据传输方法还包括:发送第一信息,所述第一信息用于请求获取所述第一参数;所述获取第一会话关联的第一参数,包括:接收第一会话关联的第一参数。
可选的,所述第一信息包括以下至少一项:第一指示信息,用于指示执行所述第一业务;与所述第一会话相关的终端的身份标识;所述第一会话的会话信息;终端支持所述第一业务的能力信息;与所述第一会话相关的终端所属组的组标识;与所述第一会话相关的终端的第二会话的标识,所述第二会话关联除所述第一业务之外的业务。
可选的,所述第一信息通过非接入层消息或者接入层消息承载。
可选的,所述使用所述第一参数通过所述第一会话传输所述第一业务的数据包括:使用所述第一安全参数处理所述数据,并将处理后的所述数据作为以太网数据包传输。
可选的,所述使用所述第一参数通过所述第一会话传输所述第一业务的数据包括:使用所述第一安全参数处理所述数据,并使用所述第一IP地址传输。
可选的,所述获取第一会话关联的第一参数包括:接收第一消息,所述第一消息包括所述第一会话关联的第一参数。
可选的,所述第一消息还包括以下至少一项:第二指示信息,用 于指示终端和/或网络是否支持所述第一业务;所述第一会话的标识;终端类型;所述第一业务的业务类型;所述第一会话的会话类型;其中,所述终端类型、业务类型、会话类型中的部分或全部用于指示是否请求分配用于所述第一会话的资源。
可选的,所述第一消息通过非接入层消息或者接入层消息承载。
可选的,所述非接入层消息包括会话管理消息和/或移动性管理消息。
可选的,所述第一参数复用与所述第一会话相关的一个终端的第二参数,或者,所述第一参数为第三参数,所述第三参数不复用与所述第一会话相关的终端的第二参数,所述第二参数关联除所述第一业务之外的业务。
可选的,使用所述第一安全参数处理所述数据的动作在业务层执行,或者,使用所述第一安全参数处理所述数据的动作在协议层执行。
可选的,所述数据传输方法还包括:发送第二消息,所述第二消息用于请求为所述第一会话分配资源。
为解决上述技术问题,本申请实施例还提供一种数据传输方法,包括:接收一个或多个终端通过第一会话传输的数据,所述第一会话关联第一业务,所述数据为所述第一业务的数据,与所述第一会话相关的终端均使用第一参数传输所述数据,所述第一参数包括第一安全参数和/或第一IP地址;合并接收到的所述数据并向下一节点传输。
可选的,所述下一节点包括核心网。
可选的,所述合并接收到的所述数据并向下一节点传输包括:直接合并接收到的所述数据并向所述下一节点传输。
可选的,所述第一安全参数为第三安全参数,所述第三安全参数不复用与所述第一会话相关的终端的第二安全参数,所述第二安全参数关联除所述第一业务之外的业务。
可选的,所述数据传输方法还包括:从核心网获取所述第一安全参数。
可选的,所述合并接收到的所述数据并向下一节点传输包括:使用所述第一安全参数解处理所述数据并合并,得到解处理后的数据;向所述下一节点传输所述解处理后的数据。
可选的,使用所述第一安全参数解处理所述数据的动作在业务层执行。
可选的,所述第一安全参数复用与所述第一会话相关的一个终端的第二安全参数,所述第二安全参数关联除所述第一业务之外的业务。
可选的,所述合并接收到的所述数据并向下一节点传输包括:使用所述第一安全参数解处理所述数据并合并,得到解处理后的数据;向所述下一节点传输所述解处理后的数据。
可选的,使用所述第一安全参数解处理所述数据的动作在协议层执行。
可选的,所述数据传输方法还包括:从核心网接收第三消息,所述第三消息包括目标终端的身份标识和所述目标终端的第二会话的标识;发送第四消息,所述第四消息包括所述目标终端的第二安全参数,所述第一安全参数复用所述目标终端的第二安全参数。
可选的,所述第一IP地址复用与所述第一会话相关的一个终端的第二IP地址,或者,所述第一IP地址为第三IP地址,所述第三IP地址不复用与所述第一会话相关的终端的第二IP地址,所述第二IP地址关联除所述第一业务之外的业务。
为解决上述技术问题,本申请实施例还提供一种数据传输方法,包括:发送第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一IP地址,所述第一会话关联第一业务;接收接入网传输的所述第一业务的数据,所述数据通过所述第一会话传输;其中,与 所述第一会话相关的网元均使用所述第一参数传输所述数据。
可选的,所述数据传输方法还包括:接收第一信息,所述第一信息用于请求获取所述第一参数。
可选的,所述第一信息包括以下至少一项:第一指示信息,用于指示执行所述第一业务;与所述第一会话相关的终端的身份标识;所述第一会话的会话信息;终端支持所述第一业务的能力信息;与所述第一会话相关的终端所属组的组标识;与所述第一会话相关的终端的第二会话的标识,所述第二会话关联除所述第一业务之外的业务。
可选的,所述第一信息通过非接入层消息或接入层消息承载。
可选的,所述数据包括以下至少一项:以太网数据包;IP数据包。
可选的,所述发送第一会话关联的第一参数包括:发送第一消息,所述第一消息包括所述第一会话关联的第一参数。
可选的,所述第一消息还包括以下至少一项:第二指示信息,用于指示终端和/或网络是否支持所述第一业务;所述第一会话的标识;终端类型;所述第一业务的业务类型;所述第一会话的会话类型;其中,所述终端类型、业务类型、会话类型中的部分或全部用于指示是否请求分配用于所述第一会话的资源。
可选的,所述第一消息通过非接入层消息或者接入层消息承载。
可选的,所述非接入层消息包括会话管理消息和/或移动性管理消息。
可选的,所述第一参数复用与所述第一会话相关的一个终端的第二参数,或者,所述第一参数为第三参数,所述第三参数不复用与所述第一会话相关的终端的第二参数,所述第二参数关联除所述第一业务之外的业务。
可选的,所述数据传输方法还包括:使用所述第一安全参数解处理所述数据。
可选的,接收自所述接入网的数据为使用所述第一安全参数解处理后的数据。
可选的,所述数据传输方法还包括:接收第二消息,所述第二消息用于请求为所述第一会话分配资源;配置所述资源。
可选的,所述数据传输方法还包括:发送第三消息,所述第三消息包括目标终端的身份标识和所述目标终端的第二会话的标识;接收第四消息,所述第四消息包括所述目标终端的第二安全参数,所述第一参数复用所述第二安全参数。
可选的,所述第一参数为预配置的。
可选的,所述第一参数由核心网的第一网元配置,所述第一网元用于处理所述第一业务。
可选的,所述第一网元包括:第一业务管理功能网元,集成于所述核心网的信令面;和/或,第一业务传输功能网元,集成于所述核心网的数据面。
可选的,所述第一网元设置有公开接口,用于提供所述第一业务的能力信息和/或业务信息,和/或接收第一业务的需求信息。
为解决上述技术问题,本申请实施例还提供一种数据传输装置,包括:获取模块,用于获取第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一互联网协议IP地址,所述第一会话与第一业务关联;传输模块,用于使用所述第一参数通过所述第一会话传输所述第一业务的数据;其中,与所述第一会话相关的终端均使用所述第一参数传输所述数据。
为解决上述技术问题,本申请实施例还提供一种数据传输装置,包括:接收模块,用于接收一个或多个终端通过第一会话传输的数据,所述第一会话关联第一业务,所述数据为所述第一业务的数据,与所述第一会话相关的终端均使用第一参数传输所述数据,所述第一参数包括第一安全参数和/或第一IP地址;传输模块,用于合并接收到的 所述数据并向下一节点传输。
为解决上述技术问题,本申请实施例还提供一种数据传输装置,包括:发送模块,用于发送第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一IP地址,所述第一会话关联第一业务;接收模块,用于接收接入网传输的所述第一业务的数据,所述数据通过所述第一会话传输;其中,与所述第一会话相关的网元均使用所述第一参数传输所述数据。
为解决上述技术问题,本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质为非易失性存储介质或非瞬态存储介质,其上存储有计算机程序,所述计算机程序被处理器运行时执行上述方法的步骤。
为解决上述技术问题,本申请实施例还提供一种数据传输装置,包括存储器和处理器,所述存储器上存储有可在所述处理器上运行的计算机程序,所述处理器运行所述计算机程序时执行上述方法的步骤。
为解决上述技术问题,本申请实施例还提供一种计算机程序产品,所述计算机程序产品包括计算机程序,当所述计算机程序在计算机上运行时,使得所述计算机执行上述方法的步骤。
为解决上述技术问题,本申请实施例还提供一种通信系统,包括用于执行上述方法的核心网网元、网络设备和终端。
为解决上述技术问题,本申请实施例还提供一种芯片(或者说数据传输装置),该芯片上存储有计算机程序,在计算机程序被芯片执行时,实现上述方法的步骤。
与现有技术相比,本申请实施例的技术方案具有以下有益效果:
较之现有技术难以实现不同终端传输相同的数据,本实施方案通过使参与第一会话的终端使用相同的第一参数传输同一数据,确保不同的终端进行数据传输时能够发送相同的数据。由此,在空口端形成 冗余传输,从而提高数据传输可靠性和成功率。
进一步,相较于现有端到端的冗余传输方案,采用本实施方案的通信系统通过空口端的冗余传输确保数据传输可靠性,冗余传输的数据在接入网侧被成功接收后,接下来可以复用同一光纤继续传输。由此,节省光纤资源,有利于降低通信系统的部署成本。
附图说明
图1是本申请实施例提供的一种数据传输方法的信令交互图;
图2是本申请实施例提供的一种通信系统协议栈示意图;
图3是本申请实施例提供的另一种通信系统协议栈示意图;
图4是本申请实施例提供的又一种通信系统协议栈示意图;
图5是本发明第一个典型应用场景中通信系统的服务层安全架构示意图;
图6是图5所示应用场景中的服务层信令交互图;
图7是本发明第二个典型应用场景中通信系统的服务层安全架构示意图;
图8是图7所示应用场景中的服务层信令交互图;
图9是本申请实施例提供的一种数据传输装置的结构示意图;
图10是本申请实施例提供的另一种数据传输装置的结构示意图;
图11是本申请实施例提供的又一种数据传输装置的结构示意图;
图12是本申请实施例提供的又一种数据传输装置的结构示意图。
具体实施方式
本申请实施例提供的方法涉及核心网、接入网和终端,核心网和接入网可以统称为网络侧(简称网络),终端和网络中的设备(例如,接入网的网络设备)进行上下行信号的传输。进一步,终端通过接入网传输至核心网的数据,经由核心网进一步传输至外部网络。
本申请实施例的终端(terminal)是一种具有无线通信功能的设备,可以称为终端设备、用户设备(User Equipment,UE)、移动个(mobile station,MS)、移动终端(mobile terminal,MT)、接入终端设备、车载终端设备、工业控制终端设备、UE单元、UE站、移动站、远方站、远程终端设备、移动设备、UE终端设备、无线通信设备、UE代理或UE装置等。终端可以是固定的或者移动的。需要说明的是,终端可以支持至少一种无线通信技术,例如长期演进(Long Term Evolution,简称LTE)、新空口(new radio,NR)等。例如,终端可以是手机(mobile phone)、平板电脑(pad)、台式机、笔记本电脑、一体机、车载终端、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端、无人驾驶(self driving)中的无线终端、远程手术(remote medical surgery)中的无线终端、智能电网(smart grid)中的无线终端、运输安全(transportation safety)中的无线终端、智慧城市(smart city)中的无线终端、智慧家庭(smart home)中的无线终端、蜂窝电话、无绳电话、会话启动协议(session initiation protocol,SIP)电话、无线本地环路(wireless local loop,WLL)站、个人数字助理(personal digital assistant,PDA)、具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它处理设备、可穿戴设备、未来移动通信网络中的终端设备或者未来演进的公共移动陆地网络(public land mobile network,PLMN)中的终端设备等。在本申请的一些实施例中,终端还可以是具有收发功能的装置,例如芯片系统。其中,芯片系统可以包括芯片,还可以包括其它分立器件。
本申请实施例的接入网可以例如是5G接入网(NG-RAN),本申请实施例的网络设备是一种为UE提供无线通信功能的设备,也可称 之为接入网设备、无线接入网(radio access network,RAN)设备、或接入网网元等。其中,网络设备可以支持至少一种无线通信技术,例如LTE、NR等。示例的,网络设备包括但不限于:第五代移动通信系统(5th-generation,5G)中的下一代基站(generation nodeB,gNB)、演进型节点B(evolved node B,eNB)、无线网络控制器(radio network controller,RNC)、节点B(node B,NB)、基站控制器(base station controller,BSC)、基站收发个(base transceiver station,BTS)、家庭基站(例如,home evolved node B、或home node B,HNB)、基带单元(baseband unit,BBU)、收发点(transmitting and receiving point,TRP)、发射点(transmitting point,TP)、移动交换中心等。网络设备还可以是云无线接入网络(cloud radio access network,CRAN)场景下的无线控制器、集中单元(centralized unit,CU)、和/或分布单元(distributed unit,DU),或者接入网设备,可以为中继站、接入点、车载设备、终端设备、可穿戴设备以及未来移动通信中的网络设备或者未来演进的PLMN中的网络设备等。在一些实施例中,网络设备还可以为具有为终端提供无线通信功能的装置,例如芯片系统。示例的,芯片系统可以包括芯片,还可以包括其它分立器件。
本申请实施例的核心网(Core Network,CN)是由核心网网元组成的。其中,核心网网元又可以称之为核心网设备,为核心网中部署的网元,例如核心网控制面网元或核心网用户面网元。本申请实施例的核心网可以是演进型分组核心网(Evolved Packet Core,EPC)、5G核心网(5G Core Network),还可以是未来通信系统中的新型核心网。例如,5G核心网由一组网元组成,并实现移动性管理等功能的接入和移动性管理功能(Access and Mobility Management Function,AMF)、提供数据包路由转发和QoS(Quality of Service)管理等功能的用户面功能(User Plane Function,UPF)、提供会话管理、IP地址分配和管理等功能的会话管理功能(Session Management Function,SMF)等。EPC可由提供移动性管理、网关选择等功能的移动管理实体(Mobility Management Entity,MME)、提供数据包转发等功能的 Serving Gateway(S-GW)、提供终端地址分配、速率控制等功能的PDN Gateway(P-GW)组成。对于多播广播业务(Multicast Broadcast Service,MBS),核心网中可包含若干新的网元,来实现数据包的转发、MBS会议管理、QoS管理、传输模式切换(单播和组播/广播传输模式之间的切换)等功能。另一种方式是所述功能可以由现有的核心网网元来实现。
本申请实施例的外部网络也可称为外部数据网络(Data Network Name,DNN),具体是指接入核心网和接入网构建的网络以与终端进行数据传输的设备,外部网络可以例如包括提供AF/AS的服务器。其中,AF为应用功能(Application Function),指应用层的各种服务,可以是运营商内部的应用如语音AF(volte AF),还可以是第三方的AF(如视频服务器、游戏服务器)。AS为接入层(Access Stratum)。
如背景技术所言,现有技术为提高数据传输可靠性,通常采用端到端的冗余传输。例如,传感器-终端1-接入网1-核心网1-外部网络形成一条传输链路,传感器-终端2-接入网2-核心网2-外部网络形成另一条完全独立的传输链路。然而,完全独立的两条传输链路会造成接入网到核心网之间光纤资源的浪费。
本申请发明人经过分析发现,造成上述问题的原因之一在于,现有技术中不同的终端进行上行传输时,难以生成相同的上行数据包传输给同一个节点,导致现有技术无法实现空口冗余。具体而言,现有技术中不同终端在进行会话时使用的互联网协议(Internet Protocol,简称IP)头不同,生成的IP包也就不同,并且,不同终端使用的加密秘钥也不同。这就导致,即使两个终端接收到相同的数据,但经过终端内部各自处理生成的数据包也不同,进而两个终端最终向下一节点(例如,网络侧的接入网)传输的数据(在本实施中,具体指前述经过各终端各自处理生成的数据包)是不一样的。而如果想实现空口端的冗余传输,就必须确保不同终端传输相同的数据,现有技术显然无法实现这一点。
为解决上述技术问题,本申请实施例提供一种数据传输方法,核心网发送第一会话关联的第一参数,相应的,终端接收第一参数,所述第一参数包括第一安全参数和/或第一IP地址,所述第一会话关联第一业务;终端使用所述第一参数通过所述第一会话传输所述第一业务的数据,相应的,接入网接收一个或多个终端通过第一会话传输的所述数据;接入网合并接收到的所述数据并向下一节点传输,相应的,核心网直接或间接接收接入网传输的所述数据;其中,与所述第一会话相关的终端和网元均使用所述第一参数传输所述数据。
采用本实施方案,通过使参与第一会话的终端使用相同的第一参数传输同一数据,确保不同的终端进行数据传输时能够发送相同的数据。由此,在空口端形成冗余传输,从而提高数据传输可靠性和成功率。进一步,冗余传输的数据在接入网侧被成功接收后,接下来可以复用同一光纤继续传输。由此,节省光纤资源,有利于降低通信系统的部署成本。
本申请实施例的第一业务指上行汇聚业务(或以汇聚方式执行的上行传输业务),或者是未来协议中定义的具有相同或相似特点的业务。其中,第一业务的特点(也称特性)包括:n(n大于等于1)个终端发送相同的用户面(in user plane)数据(以下简称数据),例如同时发送相同的上行用户面数据。在本申请实施例中,相同的数据可以指相同的数据包,也即,n个终端各自发送的数据包中每个比特都一样。
以电网数据传输场景为例,电网传感器采集的数据需要经由终端传输到网络数据服务器,为避免单个终端不可靠(例如,数据丢失/破坏),采用本实施方案使用n个(例如,n=2)终端传输同一个传感器采集的数据,这两个终端将接收到的相同的数据分别传输给接入网。接入网成功接收到其中任一终端发送的数据就继续向下一节点传输,直至该数据成功传输至作为外部网络的网络数据服务器。在n=2的示例中,假设2个终端分别为终端1和终端2,则终端2可以视为 终端1的克隆。
本申请实施例的第一会话关联第一业务,具体指为进行第一业务建立的会话(session),第一会话关联唯一的标识(例如,会话ID)。第一会话也可称为上行汇聚会话。在一些实施例中,第一会话可以关联n个终端,也就是说,n个终端通过同一第一会话向网络传输第一业务的数据。例如,与同一第一会话相关的终端分别被配置同一会话ID,配置相同会话ID的n个终端使用相同的第一参数在相同的用户面发送相同的数据。进一步,n个终端从同一发送端获取同一待传输数据,其中,发送端可以例如是传感器。
在一些实施例中,关联相同第一会话(例如,相同的第一会话的标识)的n个终端可以形成用户组,用户组唯一关联组标识。对于每一终端,终端可以关联多个组标识,其中每一组标识关联对应的第一会话,由此,终端可以并行开展多个第一业务。
本申请实施例的第二会话指为进行除第一业务之外的业务建立的会话,第二会话关联唯一的标识。第二会话可以例如是协议数据单元(Protocol Data Unit,简称PDU)会话(简称PUD会话),还可以例如是4G-PDN(4G公用数据网,4G-Public Data Network)。在一些实施例中,第二会话可以和终端一一对应,也就是说,每个接入网络的网络分别建立各自的第二会话,并通过各自关联的第二会话与网络传输第一业务之外的业务的数据。
进一步,在建立第二会话的过程中,或者,在第二会话建立后,终端可以和网络建立第一会话。
本申请实施例的第一参数可以指通过第一会话传输第一业务的数据时使用的参数,与第一会话相关的终端和网元(包括核心网网元和接入网网元)均使用相同的第一参数传输相同的数据。在实际应用场景中,存在一个或多个终端因故障等非预期因素而无法传输数据的情形。此时,与第一会话相关的n个终端中的至少一个使用相同的第一参数传输数据。
在一些实施例中,第一参数可以包括第一安全参数和/或第一IP地址。其中,第一安全参数可以包括用户面的安全参数、密钥和算法、加密密钥、完整性保护密钥、加密算法和完整性保护算法等,第一会话建立过程中生成供终端使用的第一安全参数,终端在通过第一会话传输用户面数据时使用该第一安全参数对用户面数据进行保护,如加密、完整性保护。第一IP地址可以包括源IP地址,第一会话建立过程中网络给终端分配终端使用的第一IP地址,终端通过第一会话发送给网络的IP数据包的源IP地址就使用该第一IP地址。
本申请实施例的第二参数可以指通过第二会话传输除第一业务之外的业务的数据时使用的参数。具体而言,第二参数可以包括第二安全参数和/或第二IP地址。其中,第二安全参数可以包括秘钥、安全算法等,在终端接入到网络的过程中生成该终端使用的第二安全参数,终端通过第二会话传输除第一业务之外的业务的数据时使用第二安全参数对用户面数据进行保护,如加密、完整性保护。第二IP地址可以包括源IP地址,在建立第二会话过程中,网络给终端分配终端使用的第二IP地址,终端通过第二会话发送给网络的IP数据包的源IP地址就使用第二IP地址。
在一些实施例中,第一参数可以复用与第一会话相关的一个终端的第二参数。具体而言,网络在为第一会话关联的n个终端配置第一参数时,可以选择n个终端中的一个终端已经配置的第二参数,并将选择的终端的第二参数确定为n个终端共同使用的第一参数。在本申请实施例中,将n个终端中被复用第二参数的终端,记作目标终端。
在一些实施例中,第一参数可以为第三参数,第三参数不复用与第一会话相关的终端的第二参数。本申请实施例的第三参数可以指为进行第一会话关联的第一业务专门为n个终端配置的新参数,该新参数不同于n个终端各自已经被配置的第二参数。
例如,第一安全参数可以复用与第一会话相关的一个终端的第二安全参数。或者,第一IP地址可以复用与第一会话相关的一个终端 的第二IP地址。又或者,第一安全参数和第一IP地址可以均复用与第一会话相关的一个终端的第二安全参数和第二IP地址,其中,第一安全参数复用的第二安全参数和第一IP地址复用的第二IP地址可以关联相同或不同的终端。
又例如,第一安全参数可以为第三安全参数,也即不复用与第一会话相关的终端的第二安全参数。或者,第一IP地址可以为第三IP地址,也即不复用与第一会话相关的终端的第二IP地址。又或者,第一安全参数可以为第三安全参数并且第一IP地址为第三IP地址。
再例如,第一安全参数可以复用与第一会话相关的一个终端的第二安全参数,并且,第一IP地址可以为第三IP地址。或者,第一安全参数可以为第三安全参数,并且第一IP地址可以复用与第一会话相关的一个终端的第二IP地址。
为使本申请的上述目的、特征和有益效果能够更为明显易懂,下面结合附图对本申请的具体实施例做详细的说明。
图1是本申请实施例提供的一种数据传输方法的信令交互图。
在具体实施中,下述步骤(简称S)100至S107所提供的数据传输方法中,终端执行的动作,可以由终端中的具有数据传输功能的芯片执行,也可以由终端中的基带芯片执行。接入网执行的动作,可以由网络设备中的具有数据传输功能的芯片执行,也可以由网络设备中的基带芯片执行。核心网执行的动作,可以由核心网网元中的具有数据传输功能的芯片执行,也可以由核心网网元中的基带芯片执行。
具体地,参考图1,本实施方案所述数据传输方法可以包括如下步骤:
S101,核心网向终端发送第一会话关联的第一参数。相应的,终端从核心网接收第一参数。
在一些实施例中,核心网通过接入网向终端发送第一参数。
在一个具体实施中,核心网可以主动向终端发送第一参数,以触发终端执行第一业务。
在一个具体实施中,第一参数可以是预配置的。例如,可以预先配置在终端的ME(Mobile equipment,移动设备)单元或USIM(Universal Subscriber Identity Module,全球用户识别卡)中。在本示例中,S101中核心网的动作可以省略,终端直接从自身的ME或者USIM中获取第一参数。
在一个具体实施中,在S101之前还可以包括如下步骤:S100,终端向核心网发送第一信息,所述第一信息用于请求获取第一参数。相应的,核心网从终端接收第一信息。
具体地,第一信息可以包括以下至少一项:第一指示信息,用于指示执行第一业务;与第一会话相关的终端的身份标识;第一会话的会话信息;终端支持第一业务的能力信息;与第一会话相关的终端所属组的组标识;与第一会话相关的终端的第二会话的标识。
进一步,通过第一指示信息可以向网络指示发送第一信息的终端需要执行第一业务。
进一步,与第一会话相关的终端的身份标识可以例如是,n个终端中除了发送第一信息之外的终端的身份标识。仍以n=2为例,终端2发送第一信息时,可以在其中携带其克隆的终端1的身份标识。
在一些实施例中,在终端未与网络预先交互签约的场景中,网络预先不知道关联第一会话的n个终端的具体信息(也即,不知道n个终端互为备份),因而n个终端的任一个可以在第一信息中携带其他n-1个终端的身份标识和/或这n个终端所属组的组标识。相应的,核心网可以向第一信息指示的n个终端配置相同的第一参数。
在一些实施例中,在终端已与网络签约的场景中,第一信息中可以省略与第一会话相关的终端的身份标识。这有利于节省信令开销。
进一步,第一会话的会话信息可以包括:第一业务对应的外部网 络的信息。如外部网络的网络名称、网络标识、切片信息、IP地址以及端口号等。
进一步,能力信息可以指示终端支持或不支持第一业务对应的特性。
进一步,在S101中,核心网向终端发送第一消息,第一消息包括第一参数。相应的,终端从核心网接收第一消息以获取第一参数。
在一些实施例中,所述第一消息还可以包括以下至少一项:第二指示信息,用于指示终端和/或网络是否支持所述第一业务;所述第一会话的标识;终端类型;所述第一业务的业务类型;所述第一会话的会话类型;其中,所述终端类型、业务类型、会话类型中的部分或全部用于指示是否请求分配用于所述第一会话的资源。第一消息中携带的内容可以统称为第一业务的相关信息。
具体而言,终端发第一信息时可以携带自身能力信息,网络(例如,核心网)在返回第一消息时,通过第二指示信息指示网络是否具备第一业务的能力。进一步,第一消息中还可以指示和第一会话相关的其他终端的能力信息。
进一步,通过发送第一信息,终端可以向网络请求获取第一业务相关的信息,如第一业务的业务类型、第一会话的会话类型、第一IP地址、第一安全参数、与第一业务相关的终端的身份标识、外部数据网络的标识、网络切片标识、第一会话的标识等。
进一步,终端类型可以包括基础终端和辅助终端。其中,基础终端可以发起用户面资源(即,用于第一会话的资源)的申请,辅助终端不发起用户面资源的申请。
进一步,业务类型可以包括基础业务和辅助业务。若第一消息指示终端关联的第一业务为基础业务,则终端在执行第一业务时确定需要发起用户面资源的申请。若第一消息指示终端关联的第一业务为辅助业务,则终端在执行第一业务时确定不发起用户面资源的申请。
进一步,会话类型可以包括基础会话和辅助会话。其中,基础会话对应的终端可以发起用户面资源的申请,辅助会话对应的终端不发起用户面资源的申请。
在一些实施例中,当n个终端分别发送第一信息以请求共同执行第一业务时,核心网可以通过第一消息指定n个终端中的一部分发起用户面资源的申请,其中的剩余部分不发起用户面资源的申请。
仍以n=2为例,假设终端1接收到的第一消息中指示业务类型为辅助业务,则终端1在后续执行第一业务时不请求分配用于所述第一会话的资源,假设终端2接收到的第一消息中指示业务类型为基础业务,则终端2在后续执行第一业务时请求分配用于所述第一会话的资源。终端2请求的用于第一会话的资源被终端1和终端2共用。
假设n=3,终端1接收到的第一消息中指示终端类型为基础终端、终端2和终端3各自接收到的第一消息中指示终端类型均为辅助终端。相应的,终端1在后续执行第一业务时请求分配用于所述第一会话的资源,终端2和终端3则不发起资源的申请。终端1、终端2和终端3均使用终端1申请的用户面资源通过第一会话传输相同的数据。
在一些实施例中,终端可以例如使用服务请求消息(SERVICE REQUEST)请求网络分配用户面资源。
在一些实施例中,核心网可以将n个终端中,第二IP地址被复用为第一IP地址的终端,确定为需要请求分配用于第一会话的资源的终端。
在一个变化例中,用于第一会话的资源可以是预配置的周期性资源。在本变化例中,第一消息中可以省略终端类型、业务类型、会话类型中的部分或全部,以节省信令开销。
在一些实施例中,第一信息和/或第一消息可以经由接入网进行传输。
在一个具体实施中,第一信息可以通过非接入层(Non-access stratum,NAS)消息承载。类似的,第一消息可以通过NAS消息承载。
例如,通过NAS消息承载的第一消息可以包括如下信息元素(Information Element,IE):
1、第一业务1特性的指示标识(即,第一指示信息或第二指示信息),用于指示终端或网络是否支持第一业务对应的特性。可以用一个或几个比特(bit)标识,如0代表不支持第一业务对应的特性,1代表支持第一业务对应的特性;
2、终端类型,可以用一个或几个bit标识:0代表基础终端,1代表辅助终端;
3、会话类型,可以用一个或几个bit标识:0代表基础会话,1代表辅助会话即终端不发出服务请求消息(SERVICE REQUEST)。
在一些实施例中,NAS消息可以包括会话管理消息(5GS session management messages)。
具体而言,会话管理消息包括PDU会话的建立/修改/释放等阶段,其中,修改在PDU会话建立之后执行,每个阶段均会发送相应的会话管理消息。进一步,执行本实施方案的核心网可以在第二会话建立过程中或建立后,通过相应阶段的会话管理消息接收第一信息或发送第一消息发送。
例如,可以携带第一信息或第一消息的会话管理消息可以包括如下至少一项:PDU会话建立请求PDU session establishment request、PDU会话建立接受PDU session establishment accept、PDU会话建立拒绝PDU session establishment reject、PDU会话身份验证命令PDU session authentication command、PDU会话身份验证完成PDU session authentication complete、PDU会话身份验证结果PDU session authentication result、PDU会话修改请求PDU session modification  request、PDU会话修改拒绝PDU session modification reject、PDU会话修改命令PDU session modification command、PDU会话修改完成PDU session modification complete、PDU会话修改命令拒绝PDU session modification command reject、PDU会话释放请求PDU session release request、PDU会话释放拒绝PDU session release reject、PDU会话释放命令PDU session release command、PDU会话释放完成PDU session release complete、5G会话管理状态5GSM status、服务层身份验证命令Service-level authentication command、服务层身份验证完成Service-level authentication complete、远端UE报告Remote UE report、远端UE报告响应Remote UE report response。
在一些实施例中,NAS消息可以包括移动性管理消息(5GS mobility management messages)。
例如,可以携带第一信息或第一消息的移动性管理消息可以包括如下至少一项:注册请求Registration request、注册接受Registration accept、注册完成Registration complete、注册拒绝Registration reject、注销请求(UE发起)Deregistration request(UE originating)、注销接受(UE发起)Deregistration accept(UE originating)、注销请求(网络发起)Deregistration request(UE terminated)、注销接受(网络发起)Deregistration accept(UE terminated)、服务请求Service request、服务拒绝Service reject、服务接受Service accept、控制面服务请求Control plane service request、特定的网络切片身份验证命令Network slice-specific authentication command、特定的网络切片身份验证完成Network slice-specific authentication complete、特定的网络切片身份验证结果Network slice-specific authentication result、配置更新命令Configuration update command、配置更新完成Configuration update complete、身份验证请求Authentication request、身份验证响应Authentication response、身份验证拒绝Authentication reject、身份验证失败Authentication failure、身份验证结果Authentication result、身份请求Identity request、身份响应Identity response、安全模式命令 Security mode command、安全模式完成Security mode complete、安全模式拒绝Security mode reject、5G移动性管理状态5GMM status、通知Notification、通知响应Notification response、上行NAS传输UL NAS transport、下行NAS传输DL NAS transport、中继秘钥请求Relay key request、中继秘钥接受Relay key accept、中继秘钥拒绝Relay key reject、中继身份验证请求Relay authentication request以及中继身份验证响应Relay authentication response。
在一个具体实施中,第一信息可以通过AS消息承载。类似的,第一消息可以通过AS消息承载。
例如,可以携带第一信息或第一消息的AS消息可以包括如下至少一项:数量统计CounterCheck、数量统计响应CounterCheckResponse、专用系统信息块(System Information Block,简称SIB)请求DedicatedSIBRequest、下行专用消息段DLDedicatedMessageSegment、下行信息传输DLInformationTransfer、多接入双链接(Multi-RAT Dual Connectivity,MR-DC)下行信息传输DLInformationTransferMRDC、失败信息FailureInformation、集成接入和回程(Integrated access and backhaul,IAB)其他信息IABOtherInformation、定位测量指示LocationMeasurementIndication、日志测量配置LoggedMeasurementConfiguration、多播广播服务(Multicast Broadcast Services,MBS)广播配置MBSBroadcastConfiguration、MBS兴趣指示MBSInterestIndication、主小区组(Master Cell Group,MCG)失败信息MCGFailureInformation、测量报告MeasurementReport、应用层测量报告MeasurementReportAppLayer、主信息块(Master Information Block,MIB)、基于NR命令的移动性MobilityFromNRCommand、寻呼Paging、无线资源控制(Radio Resource Control,简称RRC)重建RRCReestablishment、RRC重建完成RRCReestablishmentComplete、RRC重建请求RRCReestablishmentRequest、RRC重配置RRCReconfiguration、RRC重配置完成RRCReconfigurationComplete、 RRC拒绝RRCReject、RRC释放RRCRelease、RRC恢复RRCResume、RRC恢复完成RRCResumeComplete、RRC恢复请求RRCResumeRequest、RRC恢复请求1RRCResumeRequest1、RRC建立RRCSetup、RRC建立完成RRCSetupComplete、RRC建立请求RRCSetupRequest、RRC系统信息请求RRCSystemInfoRequest、辅小区组(Secondary Cell Group,SCG)失败信息SCGFailureInformation、E-UTRA(Evolved UMTS Terrestrial Radio Access,演进的UMTS陆地无线接入网,其中,UMTS为通用移动通信系统(Universal Mobile Telecommunications System))SCG失败信息SCGFailureInformationEUTRA、安全模式命令SecurityModeCommand、安全模式完成SecurityModeComplete、安全模式失败SecurityModeFailure、系统信息块1SIB1、NR辅链路终端信息SidelinkUEInformationNR、系统信息SystemInformation、终端辅助信息UEAssistanceInformation、终端能力询问UECapabilityEnquiry、终端能力信息UECapabilityInformation、终端能力请求UEInformationRequest、终端能力响应UEInformationResponse、终端定位辅助信息UEPositioningAssistanceInfo、上行专用消息段ULDedicatedMessageSegment、上行信息传输ULInformationTransfer、异无线接入技术(Inter Radio Access Technology,IRAT)的上行信息传输ULInformationTransferIRAT、MR-DC上行信息传输ULInformationTransferMRDC。
在一个具体实施中,第一消息可以通过容器传输。
在一个具体实施中,第一消息可以通过分配的用于第一会话的资源传输。
在一个具体实施中,继续参考图1,本实施方案所述数据传输方法还可以包括步骤:
S102,对于被指示需要请求分配用于第一会话的资源的终端,该 终端向核心网发送第二消息。相应的,核心网从终端接收第二消息。
具体而言,第二消息用于请求为第一会话分配资源。
响应于接收到第二消息,核心网确定该第二消息是否触发资源分配。例如,若发送第二消息的终端的终端类型为基础终端,则核心网确定需要为第一会话配置资源。又例如,若第二消息携带的会话类型为辅助会话,则核心网确定不响应该第二消息配置资源。
在一些实施例中,对于未被指示需要请求分配用于第一会话的资源的终端,S102为可选步骤。
在一些实施例中,第二消息可以通过接入网传输至核心网。
在一个具体实施中,继续参考图1,本实施方案所述数据传输方法还可以包括步骤:
S103,响应于获取第一参数,终端使用第一参数通过第一会话向接入网传输第一业务的数据。相应的,接入网接收一个或多个终端通过第一会话传输的数据。
具体而言,对于第一会话相关的n个终端中的每一终端,均可以执行S103。
在一些实施例中,S103中,终端可以使用第一安全参数处理数据,并将处理后的数据作为以太网数据包传输。具体而言,本示例中,终端接收到的待传输的数据是媒体访问控制(Medium Access Control,MAC)包,其开头是MAC地址。进一步,S103中,终端传输以太网数据包时不使用第一IP地址,也不将数据打包成IP数据包。
进一步,终端使用第一安全参数处理以太网数据包的动作,可以在应用层执行。
在一些实施例中,S103中,终端可以使用第一安全参数处理数据,并使用第一IP地址传输处理后的数据。具体而言,本示例中, 终端将接收到的数据打包成IP数据包,并使用第一IP地址传输。
在传感器数据传输场景中,传感器可以根据网络指示传输第一业务的数据,接收该数据的终端的身份识别卡的用户路由选择策略(Route Selection Policy,URSP)里配置有应用标识(APP-ID)和对应的会话属性(用于配置对应的应用传输的数据采用以太网还是IP形式处理)。相应的,传感器根据终端的会话属性发送相应形式打包的数据给终端。响应于接收到该数据,终端执行S103以处理并向接入网传输该数据。
进一步,终端在执行S103时,根据预配置的会话属性确定将接收到的数据打包为IP数据包还是以太网数据包。
在一个具体实施中,继续参考图1,本实施方案所述数据传输方法还可以包括步骤:
S104,响应于接收到一个或多个终端通过第一会话传输的数据,接入网合并接收到的数据并向下一节点传输。相应的,下一节点接收接入网传输的数据。图1中以下一节点为核心网为例进行示例性展示,也即,核心网直接接收接入网传输的数据。
在一些实施例中,下一节点可以例如是另一终端,该另一终端作为中继节点,核心网通过至少一个中继节点间接接收接入网传输的数据。在本示例中,终端作为中继时,可以增强类似于基站的硬件处理能力,以使作为中继节点的终端可以执行类似于S104的动作。
在一些实施例中,响应于成功接收到一个终端通过第一会话传输的第一业务的数据,接入网即可执行S104。
在一个具体实施中,第一安全参数可以为第三安全参数,使用第一安全参数处理数据的动作可以在终端的业务层(serving layer)执行。进一步,核心网发送的第一消息包括第三安全参数,终端和/或接入网将第三安全参数确定为第一安全参数并使用。业务层可以包括IP层和应用程序,本示例所述的MAC层为3GPP范围的MAC层。
情形1:
结合图1和图2,第一安全参数通过NAS消息承载。响应于获取到第一安全参数,终端在自身协议栈的业务层使用第一安全参数加密数据,然后通过第一会话逐层传输至接入网。例如,在终端侧,业务层(例如,IP层)处理后的数据依次经由服务数据适配协议(Service Data Adaptation Protocol,SDAP)、分组数据汇聚协议(Packet Data Convergence Protocol,简称PDCP)层、无线链路控制(Radio Link Control,简称RLC)层以及MAC层传输至接入网。
进一步,接入网并不获取和使用第一安全参数,相应的,S104中,接入网透传接收到的数据至核心网。例如,在接入网侧,经由MAC层、RLC层、PDCP层和SDAP层逐层接收到至少一个终端通过第一会话传输的数据后,直接合并接收到的所述数据并向所述下一节点传输。
进一步,响应于接收到数据,核心网可以使用第一安全参数解处理所述数据。其中,解处理可以包括解密、解保护等操作。例如,可以由核心网专门新增的上行汇聚传输功能或者用户面功能(UPF,User Plane Function)使用第一安全参数对数据进行安全操作,得到解处理后的数据。
换言之,在情形1中,无需在终端和接入网各自的PDCP层用RRC信令传输第一安全参数,而是直接在终端侧的IP层到PDCP层时已经是使用第一安全参数加密好的数据。此时,数据直接通过接入网传输到核心网,由核心网使用第一安全参数进行解处理操作。
进一步,解密解保护后的数据,可以由核心网继续传输至外部网络。
情形2:
结合图1和图3,第一安全参数通过NAS消息承载。响应于获取到第一安全参数,终端在自身协议栈的业务层使用第一安全参数加 密数据,然后通过第一会话逐层传输至接入网。例如,在终端侧,IP层处理后的数据依次经由SDAP层、PDCP层、RLC层以及MAC层传输至接入网。
进一步,本实施方案所述数据传输方法还可以包括步骤:S105,接入网从核心网获取所述第一安全参数。在一些实施例中,接入网可以通过其他渠道从核心网获得第一安全参数。例如,接入网可以通过与核心网的AMF(Access and Mobility management Function接入和移动性管理功能)之间的N2接口获得第一安全参数。
响应于获取第一安全参数,在S104中,接入网使用第一安全参数解处理从不同终端处接收到的相同数据并合并,得到解处理后的数据,然后向下一节点传输解处理后的数据。由此,可以提高传输的可靠性。
换言之,相较于现有接入网的协议栈结构,情形2中接入网的协议栈新增业务层(例如,IP层),该新增的IP层具备解密功能,接入网解密数据后明文传输至下一节点(例如,核心网的UPF)。核心网接收自接入网的数据为使用第一安全参数解处理后的数据。
进一步,使用第一安全参数解处理数据的动作可以在接入网的业务层执行。具体地,可以在接入网新增的IP层执行。
在一个具体实施中,第一安全参数可以复用与第一会话相关的一个终端的第二安全参数,使用第一安全参数处理数据的动作可以在终端的协议层执行。具体而言,协议层指3GPP范围的协议,如SDAP、PDCP、RLC、MAC、MM和SM等。
具体而言,结合图1和图4,本实施方案所述数据传输方法还可以包括步骤:S106,核心网向接入网发送第三消息。相应的,接入网从核心网接收第三消息。其中,第三消息可以包括目标终端的身份标识和目标终端的第二会话的标识。目标终端具体指前述与第一会话相关的n个终端中被复用第二安全参数的那个终端。
进一步,本实施方案所述数据传输方法还可以包括步骤:S107,接入网向核心网发送第四消息。相应的,核心网接收接入网发送的第四消息。其中,第四消息可以包括目标终端的第二安全参数。
响应于获取被复用的目标终端的第二安全参数,核心网将该第二安全参数确定为第一安全参数,并通过执行S101将第一安全参数通过AS消息发送至终端。
例如,S101中,核心网通过RRC信令向接入网发送第一安全参数,接入网获取并通过PDCP层用RRC信令向终端发送第一安全参数。
进一步,S103中,终端在PDCP层使用第一安全参数加密数据并逐层传输至接入网。
进一步,在S104中,接入网在协议层使用第一安全参数解处理并合并从不同终端处接收到的相同的数据,然后明文传输至下一节点。例如,使用所述第一安全参数解处理数据的动作可以在接入网的PDCP层执行。
进一步,核心网接收自接入网的数据为使用第一安全参数解处理后的数据。
由上,采用本实施方案,通信系统通过空口端的冗余传输确保数据传输可靠性,冗余传输的数据在接入网侧被成功接收后,接下来可以复用同一光纤继续传输。由此,节省光纤资源,有利于降低通信系统的部署成本。
在第一个典型的应用场景(记作应用场景1)中,通信系统可以包括终端、接入网、核心网以及外部网络,图5示例性展示各网络组件在服务层的安全架构,其中,终端包括UE1和UE2,接入网包括NG-RAN,核心网包括AMF网元、SMF网元、第一网元以及UPF网元,外部网络包括AF/AS服务器。
具体而言,AMF网元用于提供AMF,SMF网元用于提供SMF, UPF网元用于提供UPF。
进一步,相较于现有核心网,本申请实施例的核心网新增第一网元,用于处理第一业务。例如,第一参数可以由第一网元配置。在一些实施例中,第一网元可以包括第一业务管理功能网元,用于提供第一业务管理功能。在一些实施例中,第一网元可以包括第一业务传输功能网元,用于提供第一业务传输功能。
进一步,AMF网元、SMF网元以及第一业务管理功能网元可以集成于核心网的信令面。
进一步,UPF网元和第一业务传输功能网元可以集成于核心网的数据面。
在一些实施例中,第一网元可以实现如下功能:
1)管理(例如确定、生成、分配、更新、释放)第一业务的相关资源。例如,会话类型,会话ID,第一参数(包括第一IP地址、第一安全参数(如密钥,算法))等。此第一参数用于第一业务,例如终端发送数据时使用该第一安全参数对数据进行保护,如加密、完整性保护,又例如第一IP地址被用作终端发送数据包的源IP地址;
2)接收执行第一业务的请求,如接收来自AMF、SMF、应用功能的业务请求;确定第一业务能否被执行、第一业务的相关资源,例如根据签约信息、终端和网络的能力、负载等信息进行确定;
3)提供第一业务的相关信息,如第一参数、会话类型,会话ID等,第一参数可以包括第一安全参数、第一IP地址,该相关信息可以在容器中被承载,或者,该相关信息可以在消息(如NAS消息,RRC信令)中或用户面数据中被传输;
4)向其他网络组件如AMF/SMF/UPF/UE等提供上述第一业务的相关信息;
5)使用第一业务的第一安全参数(例如,用户面密钥)对数据 进行安全操作,如解密、解保护,例如对来自UE的用户面数据包进行解密、解保护;解保护后可以再传输给外部网络。
进一步,第一网元可以设置有公开接口,用于提供第一业务的能力信息。例如,能力信息可以指示第一业务是否支持n个终端在同一用户面发相同的数据。
进一步,公开接口还可以提供第一业务的业务信息,如第一业务的开始/结束时间、网络的通信情况等。
进一步,公开接口还可以提供接收第一业务的需求信息。
公开接口可以是核心网和外部网络的服务器之间的物理/逻辑接口,用于传输第一业务的相关信息。例如,继续参考图5,第一业务管理功能网元在AF/AS服务器处可以设置公开接口,类似的,第一业务传输功能网元在AF/AS服务器处也可以设置公开接口。通过该开放接口,可以例如提供第一业务的信息公开接口、业务管理接口。通过该公开接口,可以提供如下信息中的至少一部分:第一业务的执行时间如起始结束时间,地理范围如跟踪区,小区;第一业务对应的外部网络的信息如网络名称,IP地址;第一业务对应的切片信息;第一业务的服务质量,第一业务关联的终端的信息,如终端的可达性、终端的数量n。
在一些实施例中,核心网的除第一网元之外的网元(如AMF网元、SMF网元、策略管理功能(Policy Control Function,PCF)网元、统一数据管理(Unified Data Management,UDM)功能网元)可以实现如下功能:
1)获取第一业务的相关信息,如第一安全参数,例如可以从第一业务管理功能网元处获取相关信息;
2)管理(例如确定、生成、传输、更新、释放)第一业务的相关信息,如第一IP地址,会话ID,会话类型,会话质量,策略信息(如URSP、会话管理策略);
3)接收终端执行第一业务的请求,参考签约信息,确定终端能或不能执行第一业务。该执行第一业务的请求可以在NAS消息中传输,如MM消息或SM消息,也可以在用户面传输;
4)管理第一业务的相关会话(即,第一会话),如基于终端的业务请求或基于应用的业务请求,建立、修改、释放第一业务关联的第一会话;
5)提供第一业务的相关信息,如第一参数(包括第一IP地址、第一安全参数)、会话ID、会话类型、会话质量、策略信息(如URSP、会话管理策略);
6)向终端、接入网、核心网其他节点提供第一业务的相关信息。
在一些实施例中,UPF网元可以实现如下功能:
1)使用第一业务的第一安全参数对数据进行解密、解保护,例如对终端发到UPF网元或第一业务传输功能网元的用户面数据包进行解密、解保护,再传输给外部网络。
在一些实施例中,接入网可以实现如下功能:
1)使用第一业务的第一安全参数对数据进行安全操作,如解密、解保护。例如对来自终端的用户面数据包进行解密、解保护;
2)对来自终端的数据,执行汇聚处理,所述汇聚包括:把来自不同终端的相同的数据包合并,可以提高传输的可靠性。
在一些实施例中,终端(例如,图5示出的UE1和UE2)可以实现如下功能:
1)使用第一业务相关的信息处理数据,具体地可以识别属于第一业务的上行数据,对业务层数据进行保护,例如使用第一安全参数对终端发送的IP包、以太包、非结构化数据等进行保护,如加密、完整性保护;该保护操作可以在终端的业务层执行,也可以在PDCP执行;若该保护操作在业务层执行,那么PDCP层可以不对数据进行 安全保护如加密,即接入网和终端之间不对第一业务进行用户面的加密等安全操作;
2)请求执行第一业务,例如向基站(如NG-RAN)/AMF网元/SMF网元/第一网元发送第一信息,第一信息包括第一业务请求(如激活、修改、释放)信息,第一信息可以在NAS消息中被携带,该NAS消息可以是MM或SM消息;SM消息可以是PDU会话激活、修改、释放等消息;
3)接收第一业务的相关信息,例如从基站/AMF网元/SMF网元/PCF网元/第一网元接收第一业务的相关信息,如会话ID、会话类型、会话质量、策略信息(如URSP、会话管理策略)、第一参数(包括第一安全参数、第一IP地址)等;
4)保存、更新、删除第一业务的相关信息;
5)被配置第一业务的相关信息。
在一个变化例中,第一业务可以由核心网的现有网元实现。
例如,第一业务管理功能可以和SMF集成在一起。在本示例中,图5中的第一业务管理功能网元可以被省略,由SMF实现第一业务管理功能。
又例如,第一业务传输功能可以和UPF集成在一起。在本示例中,图5中的第一业务传输功能网元可以被省略,由UPF实现第一业务传输功能。
再例如,第一业务管理功能和/或第一业务传输功能可以由核心网的PCF实现。或者,可以由核心网的UDM功能实现。
在一个变化例中,第一业务可以在接入网实现,也就是说,接入网可以新增第一网元,以实现第一业务管理功能和/或第一业务传输功能。
在应用场景1中,参考图6,上述图5所示通信系统可以执行上 述图1所示方法,以在服务层执行第一业务。接下来结合图1至图6对各网络组件执行第一业务的具体流程进行详细阐述。本示例中,接入网的功能由基站gNB执行,相当于上述图5所示的NG-RAN。
步骤0a,UE1通过基站与AMF网元(或SMF网元)交互完成注册,类似的,UE2也与网络完成注册。在一些实施例中,注册消息中可以指示终端、网络支持或不支持第一业务。
步骤0b,UE1和UE2分别与网络建立第二会话,第二会话可以例如是PDU会话。例如,UE1向网络请求数据传输,网络把数据传输的资源分配到各个网元和UE1,从而完成第二会话的建立。在第二会话建立过程中和建立后,UE1和UE2可以和网络建立第一会话。
步骤1,UE2可以通过基站向AMF网元(或SMF网元)发送第一信息。
步骤1b,AMF网元(或SMF网元)将第一信息传输至第一业务管理功能网元,以请求第一业务的相关信息,如第一参数。
步骤2,第一业务管理功能网元管理第一业务,例如获取和确定第一业务的相关信息,如第一参数。在一些实施例中,该获取信息的过程可以与核心网网元交互,如与UDM交互签约信息,与PCF交互策略信息,与SMF交互会话信息,与UPF交互用户面信息等。其中,交互包括获取、提供、更新、释放、删除等操作。在本应用场景中,第一参数为第三参数。
步骤3a,核心网用户面节点如UPF网元或第一业务传输功能网元可以从第一业务管理功能网元获取第一业务的相关信息,如第一参数。
步骤3b,第一业务管理功能网元向AMF/SMF网元提供第一业务的相关信息,如第一参数。
步骤3c,第一业务管理功能网元向基站提供第一业务的相关信息,如第一参数。步骤3c为可选步骤。在一个变化例中,第一参数 可以由AMF/SMF网元转发给基站。
步骤4,网络向UE2发送第一消息,第一消息包括第一参数以及第一业务的其他相关信息。在一些实施例中,第一消息可以从AMF/SMF网元、基站、第一业务管理功能网元中的任一个接收。
步骤4’,网络指示UE1第一业务开始执行,并发送第一消息。
步骤5,UE2保存接收到的第一消息中的内容,如保存第一参数等第一业务的相关信息。类似的,UE1保存接收到的第一消息中的内容。
步骤6,应用层(如传感器)发送数据包1到UE2。该数据包1为第一业务的数据。
步骤7,UE2在服务层使用第一安全参数处理数据包1,得到处理后的数据包。
在一个实施例中,步骤7中,UE2可以在协议层使用第一安全参数对数据包1进行安全处理。处理后的数据包通过第一会话传输至基站。在本应用场景中,UE2用于传输第一业务的数据的资源已经预配置。
响应于接收到UE2传输的数据包,基站可以执行步骤8a,使用在步骤3c获取的第一安全参数对接收到的数据包进行解密解保护。
进一步,基站还可能从UE1也接收到相同的数据包,并同样使用第一安全参数对接收到的数据包进行解密解保护。
然后,基站可以把接收自UE1和UE2的数据包合并后传输至核心网。
在一些实施例中,步骤7中,UE2可以在业务层(例如,IP层)使用第一安全参数对数据包1进行安全处理,UE2的协议层(例如,PDCP层或SDAP层)不再对数据进行安全处理,处理后的数据包通过第一会话传输至基站,再经由基站透传至核心网。
在本示例中,步骤3c可以被省略。
响应于接收到基站透传的数据包,UPF网元或第一业务传输功能网元执行步骤8b,使用第一安全参数对接收到的数据包进行解密解保护。解密解保护后的数据可以再传输给外部网络。
在第二个典型应用场景(记作应用场景2)中,通信系统可以包括终端、接入网、核心网以及外部网络,图7示例性展示各网络组件在服务层的安全架构,其中,终端包括UE1和UE2,接入网包括NG-RAN,核心网包括AMF网元、SMF网元、第一网元以及UPF网元,外部网络包括AF/AS服务器。
具体而言,AMF网元用于提供AMF,SMF网元用于提供SMF,UPF网元用于提供UPF。
进一步,相较于现有核心网,本申请实施例的核心网新增第一网元,用于处理第一业务。例如,第一参数可以由第一网元配置。在一些实施例中,第一网元可以包括第一业务管理功能网元,用于提供第一业务管理功能。
进一步,AMF网元、SMF网元以及第一业务管理功能网元可以集成于核心网的信令面。
进一步,UPF网元可以集成于核心网的数据面。
在一些实施例中,终端(例如,UE1、UE2)可以实现如下功能:
1)请求执行第一业务;
2)向网络请求执行第一业务的相关信息;
3)接收从网络获取的第一业务1的相关信息;
4)存储、更新、删除网络提供的第一业务的相关信息;
5)在UE(如ME或USIM)中,预配置第一业务的相关信息;
6)使用第一业务的相关信息处理数据,例如识别属于第一业务 的上行数据,对第一业务的上行数据进行安全保护,例如PDCP层执行加密和/或完整性保护;
7)申请用于第一业务的资源,例如执行服务请求过程(SERVICE REQUEST procedure),终端根据网络配置的会话类型、终端类型和业务类型中的至少一部分确定自己是否发起资源的申请。
在一些实施例中,核心网实现如下功能:
1)核心网管理和分配第一业务所需资源,具体可以在AMF、SMF、或其他核心网功能如第一业务管理功能中执行。核心网管理和分配第一业务所需资源的动作,可以是在网络收到终端执行第一业务的请求后执行的,例如由终端的请求触发。也可以在网络收到终端的请求前执行的,例如网络触发(Network originating,或Initiating)的执行第一业务时,网络触发执行第一业务所需的过程,例如PDU会话的建立过程。
2)核心网提供第一业务的相关信息,例如核心网向终端、接入网、外部网络如应用服务提供第一业务的相关信息,核心网网元之间提供第一业务的相关信息;
3)核心网从接入网获取部分第一业务的相关信息,例如第一安全参数。本应用场景中,第一参数的至少一部分复用与第一会话相关的一个终端的第二参数。
在一些实施例中,接入网可以实现如下功能:
1)提供部分或全部第一业务相关的信息,例如与第一会话相关的n个终端中被复用的终端的第二安全参数。具体地,接入网可以向核心网提供部分或全部第一业务的相关信息。进一步,接入网可以向终端提供部分或全部第一业务的相关信息。USIM
在一些实施例中,终端的USIM可以存储和提供第一业务所需的信息,如策略,业务类型,会话类型,应用ID等。
进一步,第一网元可以设置有公开接口,以提供第一业务的能力信息、业务信息和需求信息中的至少一部分。例如,第一业务管理功能和AF/AS服务器可以通过公开接口相通信。
在应用场景2中,参考图8,上述图6所示通信系统可以执行上述图1所示方法,以在服务层执行第一业务。接下来结合图1至图4、图7和图8对各网络组件执行第一业务的具体流程进行详细阐述。本示例中,接入网的功能由基站gNB执行,相当于上述图5所示的NG-RAN。
步骤0a和步骤0b的具体内容可以参考上述图6所示应用场景1中的相关描述,在此不予赘述。基站在UE1注册过程中获知UE1的第二安全参数和第二IP地址。
具体而言,在执行步骤0a和步骤0b后,UE1和UE2各自获得自己的第二安全参数和第二IP地址,该第二安全参数在终端的协议层(例如,PDCP层)使用,UE1和UE2分别通过RRC信令将第二安全参数和第二IP地址告知基站。UE1的第二安全参数不同于UE2的第二安全参数,UE1的第二IP地址不同于UE2的第二IP地址。
步骤1,UE2可以通过基站向AMF网元(或SMF网元)发送第一信息。进一步,AMF网元(或SMF网元)将第一信息传输至第一业务管理功能网元,以请求第一业务的相关信息,如第一参数。
步骤2,核心网建立第一会话处理第一业务,并为第一会话分配第一业务的相关信息,例如,终端发送数据时所使用的第一IP地址和第一安全参数,第一会话的标识。在本应用场景中,第一IP地址需要复用UE1的第二IP地址,第一安全参数复用UE1的第二安全参数。
步骤3,核心网可以向接入网请求第一业务所需的资源信息,例如UE1的第二IP地址和/或第二安全参数。相应的,接入网向核心网提供第一业务所需的资源信息。例如,核心网的AMF网元可以通过 N2接口向基站发送第三消息,并接收基站反馈的第四消息,以获得UE1的第二IP地址和/或第二安全参数。第三消息和/或第四消息可以通过AS消息承载。
在一些实施例中,接入网向核心网提供的第一业务所需的资源信息,可以是对核心网向接入网请求的第一业务所需的资源信息的响应,也可以是接入网触发(例如:originating,或Initiating)的向核心网提供第一业务所需的资源信息。例如,接入网中相应信息发生变更时可以主动向核心网更新相应信息。由此,通过后续网络和UE2的交互,可以使UE2使用UE1的第二安全参数传输第一业务的数据。
步骤4,网络向UE2发送第一消息,第一消息包括第一参数以及第一业务的其他相关信息。在一些实施例中,第一消息可以接收自AMF/SMF网元。例如,核心网可以在NAS消息中提供该信息,例如移动性管理消息,会话管理消息,也可以通过用户面提供该信息。在一些实施例中,第一消息中的部分内容(例如,UE1的第二安全参数)也可以通过接入网提供给UE,例如通过无线资源管理消息(如RRC信令)。
步骤4’,网络(如AMF/SMF网元)指示UE1第一业务开始执行,第一业务的第一IP地址为UE1的第二IP地址。进一步,网络还可以发送第一消息中的至少一部分内容,如第一会话的标识。
步骤5,UE2保存接收到的第一消息中的内容,如保存UE1的第二IP地址和第二安全参数。
步骤6,应用层数据源(如传感器)发送数据包1到UE1和UE2,该数据包1为第一业务的数据。传输数据包1的源IP地址可以为第一IP地址。响应于接收到数据包1,UE1发送第二消息,以请求网络分配用于第一会话的资源。
具体而言,终端上传数据需要请求网络给终端分配资源,包括空口的时频资源。在本申请实施例中,UE1和UE2使用相同的时频资 源传输相同的数据包1,因而由其中一个终端向网络请求分配资源即可。例如,AMF/SMF网元在步骤4’中指示UE1为基础终端,则UE1在步骤6中确定需要发送第二消息以请求网络分配用于第一会话的资源。
对于UE2,UE2根据数据包1使用的源IP地址确定该数据包1为第一业务的数据,并且由于AMF/SMF网元在步骤4中发送给UE2的第一消息中指示UE2为辅助终端,因而UE2在步骤6中不发起资源分配请求。
在一些实施例中,UE1可以使用服务请求(SERVICE REQUEST)过程请求资源分配。进一步,第二消息可以携带第一会话的标识。
在一些实施例中,网络为第一业务分配资源,可以是在网络收到终端的第二消息后,例如由UE1的请求触发的。也可以在网络收到终端的第二消息前,例如网络触发(例如:Network originating,或Initiating)的主动执行第一业务时。网络触发执行第一业务的过程,可以例如在PDU会话的建立过程中实现。
在一些实施例中,所述网络可以是接入网的功能,例如可以由基站响应第二消息并为第一业务分配用于第一会话的资源。
在一些实施例中,所述网络可以是核心网的功能,例如可以由AMF网元或SMF网元响应第二消息并为第一业务分配用于第一会话的资源。
进一步,资源分配完成后,基站可以通知UE1用于第一会话的资源建立完成。可选的,基站还可以通知UE2用于第一会话的资源建立完成。
步骤7,UE1和UE2分别使用第一业务的相关信息处理数据包1。具体而言,UE1使用自己的第二安全参数作为第一安全参数处理数据包1,并使用自己的第二IP地址作为第一IP地址通过第一会话传输处理后的数据。并行地,UE2使用UE1的第二安全参数作为第一安 全参数处理数据包1,并使用UE1的第二IP地址作为第一IP地址通过第一会话传输处理后的数据。
对于UE1和UE2中的任一终端,可以在协议层使用UE1的第二安全参数处理数据包1。响应于接收到UE2和UE1各自传输的相同的处理后的数据,基站可以执行步骤8a,使用在UE1注册阶段获取的UE1的第二安全参数对接收到的数据包进行解密解保护,并在合并后传输至核心网。
在上述应用场景1和应用场景2的一个共同变化例中,数据包1可以为以太网数据包,相应的,UE1和UE2各自用第一安全参数处理接收到的数据包1时,将处理后的数据打包为以太网数据包向下一节点(例如,基站)传输。
在上述应用场景1和应用场景2的一个共同变化例中,对于被指示不用请求用于第一会话的资源的终端(如UE2),UE2在从应用层接收到第一业务的数据后,可以发送第二消息。网络根据第二消息中的第一会话的标识,判断是否已经为第一会话分配资源。如果已经分配,则不响应UE2的资源分配请求。
由上,采用本实施方案,不同的终端可以从网络获取或预配置相同的第一IP地址,用于终端发送第一业务的数据。进一步,不同的终端可以从网络获取或预配置相同的第一安全参数,用于终端发送第一业务的数据时的安全处理。
进一步,核心网可以管理第一业务相关的资源(例如,第一业务的相关信息),例如产生第一IP地址或第一安全参数,或从接入网获取第一安全参数(如用户面密钥)。
进一步,可以在第一信息/第一消息中携带第一业务的相关信息/指示第一业务的能力信息。
进一步,网络可以提供第一业务相关的公开接口,如信息公开,能力公开。例如,第三方服务器可以向网络提出业务需求:电网希望 第一业务什么时候开始,此时,可以通过公开接口把该需求信息告诉核心网,核心网把相关参数配置给接入网和终端。又例如,运营商服务器可以核心网经由公开结构向第三方服务器告知第一业务的业务信息,如网络的通信情况。
图9是本申请实施例提供的一种数据传输装置(记为数据传输装置2)的结构示意图。
本领域技术人员理解,本实施例数据传输装置2可以用于实施上述图1至图8所述实施例中所述的方法。数据传输装置2可以为上文中的终端。
具体地,参考图9,数据传输装置2可以包括:获取模块21,用于获取第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一互联网协议IP地址,所述第一会话与第一业务关联;传输模块22,用于使用所述第一参数通过所述第一会话传输所述第一业务的数据;其中,与所述第一会话相关的终端均使用所述第一参数传输所述数据。
在一些实施例中,数据传输装置2还可以包括:发送模块(图未示),用于发送第一信息,所述第一信息用于请求获取所述第一参数。进一步,获取模块21包括:接收单元(图未示),用于接收第一会话关联的第一参数。
在一些实施例中,所述第一信息包括以下至少一项:第一指示信息,用于指示执行所述第一业务;与所述第一会话相关的终端的身份标识;所述第一会话的会话信息;终端支持所述第一业务的能力信息;与所述第一会话相关的终端所属组的组标识;与所述第一会话相关的终端的第二会话的标识,所述第二会话关联除所述第一业务之外的业务。
在一些实施例中,所述第一信息通过非接入层消息或者接入层消息承载。
在一些实施例中,传输模块22可以包括:第一传输单元(图未示),用于使用所述第一安全参数处理所述数据,并将处理后的所述数据作为以太网数据包传输;或者,第二传输单元(图未示),用于使用所述第一安全参数处理所述数据,并使用所述第一IP地址传输。
在一些实施例中,获取模块21可以包括:接收单元(图未示),用于接收第一消息,所述第一消息包括所述第一会话关联的第一参数。
在一些实施例中,所述第一消息还包括以下至少一项:第二指示信息,用于指示终端和/或网络是否支持所述第一业务;所述第一会话的标识;终端类型;所述第一业务的业务类型;所述第一会话的会话类型;其中,所述终端类型、业务类型、会话类型中的部分或全部用于指示是否请求分配用于所述第一会话的资源。
在一些实施例中,所述第一消息通过非接入层消息或者接入层消息承载。
在一些实施例中,所述第一参数为预配置的。
在一些实施例中,所述第一参数复用与所述第一会话相关的一个终端的第二参数,或者,所述第一参数为第三参数,所述第三参数不复用与所述第一会话相关的终端的第二参数,所述第二参数关联除所述第一业务之外的业务。
在一些实施例中,使用所述第一安全参数处理所述数据的动作在业务层执行,或者,使用所述第一安全参数处理所述数据的动作在协议层执行。
关于所述数据传输装置2的工作原理、工作方式的更多内容,可以参照上述图1至图8中的相关描述,这里不再赘述。
在具体实施中,上述的数据传输装置2可以对应于终端中具有数据传输功能的芯片,或者对应于具有数据处理功能的芯片,例如片上系统(System-On-a-Chip,简称SOC)、基带芯片等;或者对应于终 端中包括具有数据传输功能芯片的芯片模组;或者对应于具有数据处理功能芯片的芯片模组,或者对应于终端。
图10是本申请实施例提供的另一种数据传输装置(记为数据传输装置3)的结构示意图。本领域技术人员理解,本实施例所述数据传输装置3可以用于实施上述图1至图8所述实施例中所述的方法。数据传输装置3可以为上文中的接入网。
具体地,参考图10,数据传输装置3可以包括:接收模块31,用于接收一个或多个终端通过第一会话传输的数据,所述第一会话关联第一业务,所述数据为所述第一业务的数据,与所述第一会话相关的终端均使用第一参数传输所述数据,所述第一参数包括第一安全参数和/或第一IP地址;传输模块32,用于合并接收到的所述数据并向下一节点传输。
在一些实施例中,所述第一安全参数为第三安全参数,所述第三安全参数不复用与所述第一会话相关的终端的第二安全参数,所述第二安全参数关联除所述第一业务之外的业务,所述数据传输装置3还可以包括:获取模块(图未示),用于从核心网获取所述第一安全参数。
在一些实施例中,所述第一安全参数复用与所述第一会话相关的一个终端的第二安全参数,所述第二安全参数关联除所述第一业务之外的业务。
在一些实施例中,传输模块32可以包括:处理单元(图未示),用于使用所述第一安全参数解处理所述数据并合并,得到解处理后的数据;传输单元(图未示),用于向所述下一节点传输所述解处理后的数据。
在一些实施例中,使用所述第一安全参数解处理所述数据的动作在业务层执行,或者,使用所述第一安全参数解处理所述数据的动作在协议层执行。
在一些实施例中,数据传输装置3还可以包括:接收单元(图未示),用于从核心网接收第三消息,所述第三消息包括目标终端的身份标识和所述目标终端的第二会话的标识;发送单元(图未示),用于发送第四消息,所述第四消息包括所述目标终端的第二安全参数,所述第一安全参数复用所述目标终端的第二安全参数。
关于所述数据传输装置3的工作原理、工作方式的更多内容,可以参照上述图1至图8中的相关描述,这里不再赘述。
在具体实施中,上述的数据传输装置3可以对应于接入网的网络设备中具有数据传输功能的芯片,或者对应于具有数据处理功能的芯片,例如片上系统(System-On-a-Chip,简称SOC)、基带芯片等;或者对应于接入网的网络设备中包括具有数据传输功能芯片的芯片模组;或者对应于具有数据处理功能芯片的芯片模组,或者对应于接入网的网络设备。
图11是本申请实施例提供的另一种数据传输装置(记为数据传输装置4)的结构示意图。本领域技术人员理解,本实施例所述数据传输装置4可以用于实施上述图1至图8所述实施例中所述的方法。数据传输装置4可以为上文中的核心网。
具体地,参考图11,数据传输装置4可以包括:发送模块41,用于发送第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一IP地址,所述第一会话关联第一业务;接收模块42,用于接收接入网传输的所述第一业务的数据,所述数据通过所述第一会话传输;其中,与所述第一会话相关的网元均使用所述第一参数传输所述数据。
在一些实施例中,数据传输装置4还可以包括:第一信息接收模块(图未示),用于接收第一信息,所述第一信息用于请求获取所述第一参数。
在一些实施例中,发送模块41可以包括:发送单元(图未示), 用于发送第一消息,所述第一消息包括所述第一会话关联的第一参数。
在一些实施例中,所述第一信息包括以下至少一项:第一指示信息,用于指示执行所述第一业务;与所述第一会话相关的终端的身份标识;所述第一会话的会话信息;终端支持所述第一业务的能力信息;与所述第一会话相关的终端所属组的组标识;与所述第一会话相关的终端的第二会话的标识,所述第二会话关联除所述第一业务之外的业务。
在一些实施例中,所述第一消息还包括以下至少一项:第二指示信息,用于指示终端和/或网络是否支持所述第一业务;所述第一会话的标识;终端类型;所述第一业务的业务类型;所述第一会话的会话类型;其中,所述终端类型、业务类型、会话类型中的部分或全部用于指示是否请求分配用于所述第一会话的资源。
在一些实施例中,所述第一信息通过非接入层消息或接入层消息承载;和/或,所述第一消息通过非接入层消息或者接入层消息承载。
在一些实施例中,所述第一参数复用与所述第一会话相关的一个终端的第二参数,或者,所述第一参数为第三参数,所述第三参数不复用与所述第一会话相关的终端的第二参数,所述第二参数关联除所述第一业务之外的业务;和/或,所述数据包括以下至少一项:以太网数据包;IP数据包。
在一些实施例中,数据传输模块4还可以包括:处理模块(图未示),用于使用所述第一安全参数解处理所述数据。
在一些实施例中,接收自所述接入网的数据为使用所述第一安全参数解处理后的数据。
在一些实施例中,数据传输模块4还可以包括:第二消息接收单元(图未示),用于接收第二消息,所述第二消息用于请求为所述第一会话分配资源;配置单元(图未示),用于配置所述资源。
在一些实施例中,数据传输模块4还可以包括:第三消息发送模块(图未示),用于发送第三消息,所述第三消息包括目标终端的身份标识和所述目标终端的第二会话的标识;第四消息接收模块(图未示),用于接收第四消息,所述第四消息包括所述目标终端的第二安全参数,所述第一参数复用所述第二安全参数。
在一些实施例中,所述第一参数由核心网的第一网元配置,所述第一网元用于处理所述第一业务。
在一些实施例中,所述第一网元设置有公开接口,用于提供所述第一业务的能力信息和/或业务信息,和/或接收第一业务的需求信息。
关于所述数据传输装置4的工作原理、工作方式的更多内容,可以参照上述图1至图8中的相关描述,这里不再赘述。
在具体实施中,上述的数据传输装置4可以对应于核心网网元中具有数据传输功能的芯片,或者对应于具有数据处理功能的芯片,例如片上系统(System-On-a-Chip,简称SOC)、基带芯片等;或者对应于核心网网元中包括具有数据传输功能芯片的芯片模组;或者对应于具有数据处理功能芯片的芯片模组,或者对应于核心网网元。
在具体实施中,关于上述实施例中描述的各个装置、产品包含的各个模块/单元,其可以是软件模块/单元,也可以是硬件模块/单元,或者也可以部分是软件模块/单元,部分是硬件模块/单元。
例如,对于应用于或集成于芯片的各个装置、产品,其包含的各个模块/单元可以都采用电路等硬件的方式实现,或者,至少部分模块/单元可以采用软件程序的方式实现,该软件程序运行于芯片内部集成的处理器,剩余的(如果有)部分模块/单元可以采用电路等硬件方式实现;对于应用于或集成于芯片模组的各个装置、产品,其包含的各个模块/单元可以都采用电路等硬件的方式实现,不同的模块/单元可以位于芯片模组的同一组件(例如芯片、电路模块等)或者不同组件中,或者,至少部分模块/单元可以采用软件程序的方式实现, 该软件程序运行于芯片模组内部集成的处理器,剩余的(如果有)部分模块/单元可以采用电路等硬件方式实现;对于应用于或集成于终端的各个装置、产品,其包含的各个模块/单元可以都采用电路等硬件的方式实现,不同的模块/单元可以位于终端内同一组件(例如,芯片、电路模块等)或者不同组件中,或者,至少部分模块/单元可以采用软件程序的方式实现,该软件程序运行于终端内部集成的处理器,剩余的(如果有)部分模块/单元可以采用电路等硬件方式实现。
本申请实施例还提供了一种计算机可读存储介质,所述计算机可读存储介质为非易失性存储介质或非瞬态存储介质,其上存储有计算机程序,所述计算机程序被处理器运行时使得上述图1至图8所示实施例所提供的数据传输方法的步骤被执行。
在本申请实施例中,存储介质可以包括非挥发性存储器(non-volatile)或者非瞬态(non-transitory)存储器,还可以包括光盘、机械硬盘、固态硬盘等。
图12是本申请实施例提供的又一种数据传输装置的结构示意图。
具体地,参考图12,数据传输装置可以包括处理器51,处理器51和存储器52耦合,存储器52可以位于该装置内,也可以位于该装置外。可选的,还包括收发器53。存储器52、处理器51和收发器53可以通过通信总线连接。所述存储器52上存储有可在所述处理器51上运行的计算机程序,所述处理器51运行所述计算机程序时执行上述图1至图8所示实施例所提供的数据传输方法中的步骤,收发器53可以在处理器51的控制下执行上文中的发送和/或接收的动作。该数据传输装置可以为上文中的网络设备,也可以为终端,还可以为核心网网元。
本申请实施例中,存储器52包括非挥发性存储器(non-volatile)或者非瞬态(non-transitory)存储器,还可以包括光盘、机械硬盘、固态硬盘等。
本申请实施例中,所述处理器51可以为中央处理单元(central processing unit,CPU),该处理器51还可以是其他通用处理器、数字信号处理器(digital signal processor,DSP)、专用集成电路(application specific integrated circuit,ASIC)、现成可编程门阵列(field programmable gate array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。
本领域普通技术人员可以理解上述实施例的各种方法中的全部或部分步骤是可以通过程序来指示相关的硬件来完成,该程序可以存储于一计算机可读存储介质中,存储介质可以包括:ROM、RAM、磁盘或光盘等。
本申请中的实施例描述是参照根据本申请实施例的方法、设备(装置)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令 提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
还需要说明的是,本申请实施例中,“至少一个”是指一个或者多个,“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示单独存在A、同时存在A和B、单独存在B的情况。其中A,B可以是单数或者复数。字符“/”一般表示前后关联对象是一种“或”的关系。“以下至少一项”及其类似表达,是指的这些项中的任意组合,包括单项或复数项的任意组合。例如,a,b和c中的至少一项可以表示:a,b,c,a和b,a和c,b和c或a和b和c,其中a,b,c可以是单个,也可以是多个。
本申请实施例中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、商品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、商品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、商品或者设备中还存在另外的相同要素。
本申请可以在由计算机执行的计算机可执行指令的一般上下文中描述,例如程序模块。一般地,程序模块包括执行特定任务或实现特定抽象数据类型的例程、程序、对象、组件、数据结构等等。也可以在分布式计算环境中实践本申请,在这些分布式计算环境中,由通过通信网络而被连接的远程处理设备来执行任务。在分布式计算环境中,程序模块可以位于包括存储设备在内的本地和远程计算机存储介质中。
本申请中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于装置实施例而言,由于其基本相似于方 法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
本领域普通技术人员可以意识到,本申请实施例中描述的各单元及算法步骤,能够以电子硬件、计算机软件和电子硬件的结合来实现。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的装置、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
虽然本申请披露如上,但本申请并非限定于此。任何本领域技术人员,在不脱离本申请的精神和范围内,均可作各种更动与修改,因此本申请的保护范围应当以权利要求所限定的范围为准。

Claims (30)

  1. 一种数据传输方法,其特征在于,包括:
    获取第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一互联网协议IP地址,所述第一会话与第一业务关联;
    使用所述第一参数通过所述第一会话传输所述第一业务的数据;其中,与所述第一会话相关的终端均使用所述第一参数传输所述数据。
  2. 根据权利要求1所述的数据传输方法,其特征在于,还包括:
    发送第一信息,所述第一信息用于请求获取所述第一参数;
    所述获取第一会话关联的第一参数,包括:接收第一会话关联的第一参数。
  3. 根据权利要求2所述的数据传输方法,其特征在于,所述第一信息包括以下至少一项:第一指示信息,用于指示执行所述第一业务;与所述第一会话相关的终端的身份标识;所述第一会话的会话信息;终端支持所述第一业务的能力信息;与所述第一会话相关的终端所属组的组标识;与所述第一会话相关的终端的第二会话的标识,所述第二会话关联除所述第一业务之外的业务。
  4. 根据权利要求2或3所述的数据传输方法,其特征在于,所述第一信息通过非接入层消息或者接入层消息承载。
  5. 根据权利要求1至4中任一项所述的数据传输方法,其特征在于,所述使用所述第一参数通过所述第一会话传输所述第一业务的数据包括:
    使用所述第一安全参数处理所述数据,并将处理后的所述数据作为以太网数据包传输;或者
    使用所述第一安全参数处理所述数据,并使用所述第一IP地址传 输。
  6. 根据权利要求1至5中任一项所述的数据传输方法,其特征在于,所述获取第一会话关联的第一参数包括:
    接收第一消息,所述第一消息包括所述第一会话关联的第一参数。
  7. 根据权利要求6所述的数据传输方法,其特征在于,所述第一消息还包括以下至少一项:第二指示信息,用于指示终端和/或网络是否支持所述第一业务;所述第一会话的标识;终端类型;所述第一业务的业务类型;所述第一会话的会话类型;
    其中,所述终端类型、业务类型、会话类型中的部分或全部用于指示是否请求分配用于所述第一会话的资源。
  8. 根据权利要求6或7所述的数据传输方法,其特征在于,所述第一消息通过非接入层消息或者接入层消息承载。
  9. 根据权利要求1至8中任一项所述的数据传输方法,其特征在于,所述第一参数为预配置的;和/或,所述第一参数复用与所述第一会话相关的一个终端的第二参数,或者,所述第一参数为第三参数,所述第三参数不复用与所述第一会话相关的终端的第二参数,所述第二参数关联除所述第一业务之外的业务;和/或,使用所述第一安全参数处理所述数据的动作在业务层执行,或者,使用所述第一安全参数处理所述数据的动作在协议层执行。
  10. 一种数据传输方法,其特征在于,包括:
    接收一个或多个终端通过第一会话传输的数据,所述第一会话关联第一业务,所述数据为所述第一业务的数据,与所述第一会话相关的终端均使用第一参数传输所述数据,所述第一参数包括第一安全参数和/或第一IP地址;
    合并接收到的所述数据并向下一节点传输。
  11. 根据权利要求10所述的数据传输方法,其特征在于,所述第一安 全参数为第三安全参数,所述第三安全参数不复用与所述第一会话相关的终端的第二安全参数,所述第二安全参数关联除所述第一业务之外的业务,所述方法还包括:从核心网获取所述第一安全参数。
  12. 根据权利要求10所述的数据传输方法,其特征在于,所述第一安全参数复用与所述第一会话相关的一个终端的第二安全参数,所述第二安全参数关联除所述第一业务之外的业务。
  13. 根据权利要求10至12中任一项所述的数据传输方法,其特征在于,所述合并接收到的所述数据并向下一节点传输包括:
    使用所述第一安全参数解处理所述数据并合并,得到解处理后的数据;
    向所述下一节点传输所述解处理后的数据。
  14. 根据权利要求13所述的数据传输方法,其特征在于,使用所述第一安全参数解处理所述数据的动作在业务层执行,或者,使用所述第一安全参数解处理所述数据的动作在协议层执行。
  15. 根据权利要求10至14中任一项所述的数据传输方法,其特征在于,还包括:
    从核心网接收第三消息,所述第三消息包括目标终端的身份标识和所述目标终端的第二会话的标识;
    发送第四消息,所述第四消息包括所述目标终端的第二安全参数,所述第一安全参数复用所述目标终端的第二安全参数。
  16. 一种数据传输方法,其特征在于,包括:
    发送第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一IP地址,所述第一会话关联第一业务;
    接收接入网传输的所述第一业务的数据,所述数据通过所述第一 会话传输;
    其中,与所述第一会话相关的网元均使用所述第一参数传输所述数据。
  17. 根据权利要求16所述的数据传输方法,其特征在于,还包括:
    接收第一信息,所述第一信息用于请求获取所述第一参数;和/或
    所述发送第一会话关联的第一参数包括:发送第一消息,所述第一消息包括所述第一会话关联的第一参数。
  18. 根据权利要求17所述的数据传输方法,其特征在于,所述第一信息包括以下至少一项:第一指示信息,用于指示执行所述第一业务;与所述第一会话相关的终端的身份标识;所述第一会话的会话信息;终端支持所述第一业务的能力信息;与所述第一会话相关的终端所属组的组标识;与所述第一会话相关的终端的第二会话的标识,所述第二会话关联除所述第一业务之外的业务;和/或
    所述第一消息还包括以下至少一项:第二指示信息,用于指示终端和/或网络是否支持所述第一业务;所述第一会话的标识;终端类型;所述第一业务的业务类型;所述第一会话的会话类型;
    其中,所述终端类型、业务类型、会话类型中的部分或全部用于指示是否请求分配用于所述第一会话的资源。
  19. 根据权利要求17或18所述的数据传输方法,其特征在于,所述第一信息通过非接入层消息或接入层消息承载;和/或,所述第一消息通过非接入层消息或者接入层消息承载。
  20. 根据权利要求16至19中任一项所述的数据传输方法,其特征在于,所述第一参数复用与所述第一会话相关的一个终端的第二参数,或者,所述第一参数为第三参数,所述第三参数不复用与所述第一会话相关的终端的第二参数,所述第二参数关联除所述第一业务之外的业务;和/或,所述数据包括以下至少一项:以太网 数据包;IP数据包。
  21. 根据权利要求16至20中任一项所述的数据传输方法,其特征在于,还包括:使用所述第一安全参数解处理所述数据;或者,接收自所述接入网的数据为使用所述第一安全参数解处理后的数据。
  22. 根据权利要求16至21中任一项所述的数据传输方法,其特征在于,还包括:
    接收第二消息,所述第二消息用于请求为所述第一会话分配资源;
    配置所述资源。
  23. 根据权利要求16至22中任一项所述的数据传输方法,其特征在于,还包括:
    发送第三消息,所述第三消息包括目标终端的身份标识和所述目标终端的第二会话的标识;
    接收第四消息,所述第四消息包括所述目标终端的第二安全参数,所述第一参数复用所述第二安全参数。
  24. 根据权利要求16至23中任一项所述的数据传输方法,其特征在于,所述第一参数由核心网的第一网元配置,所述第一网元用于处理所述第一业务。
  25. 根据权利要求24所述的数据传输方法,其特征在于,所述第一网元设置有公开接口,用于提供所述第一业务的能力信息和/或业务信息,和/或接收第一业务的需求信息。
  26. 一种数据传输装置,其特征在于,包括:
    获取模块,用于获取第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一互联网协议IP地址,所述第一会话与第一业务关联;
    传输模块,用于使用所述第一参数通过所述第一会话传输所述第一业务的数据;
    其中,与所述第一会话相关的终端均使用所述第一参数传输所述数据。
  27. 一种数据传输装置,其特征在于,包括:
    接收模块,用于接收一个或多个终端通过第一会话传输的数据,所述第一会话关联第一业务,所述数据为所述第一业务的数据,与所述第一会话相关的终端均使用第一参数传输所述数据,所述第一参数包括第一安全参数和/或第一IP地址;
    传输模块,用于合并接收到的所述数据并向下一节点传输。
  28. 一种数据传输装置,其特征在于,包括:
    发送模块,用于发送第一会话关联的第一参数,所述第一参数包括第一安全参数和/或第一IP地址,所述第一会话关联第一业务;接收模块,用于接收接入网传输的所述第一业务的数据,所述数据通过所述第一会话传输;
    其中,与所述第一会话相关的网元均使用所述第一参数传输所述数据。
  29. 一种计算机可读存储介质,所述计算机可读存储介质为非易失性存储介质或非瞬态存储介质,其上存储有计算机程序,其特征在于,所述计算机程序被处理器运行时执行权利要求1至25中任一项所述方法的步骤。
  30. 一种数据传输装置,包括存储器和处理器,所述存储器上存储有可在所述处理器上运行的计算机程序,其特征在于,所述处理器运行所述计算机程序时执行权利要求1至25中任一项所述方法的步骤。
PCT/CN2024/129607 2023-11-03 2024-11-04 数据传输方法及装置、计算机可读存储介质 Pending WO2025093029A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202311460290.3A CN119946675A (zh) 2023-11-03 2023-11-03 数据传输方法及装置、计算机可读存储介质
CN202311460290.3 2023-11-03

Publications (1)

Publication Number Publication Date
WO2025093029A1 true WO2025093029A1 (zh) 2025-05-08

Family

ID=95538058

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/129607 Pending WO2025093029A1 (zh) 2023-11-03 2024-11-04 数据传输方法及装置、计算机可读存储介质

Country Status (2)

Country Link
CN (1) CN119946675A (zh)
WO (1) WO2025093029A1 (zh)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114430592A (zh) * 2020-10-29 2022-05-03 华为技术有限公司 一种通信方法及对应装置
CN115209398A (zh) * 2021-04-13 2022-10-18 华为技术有限公司 一种报文传输方法及装置
CN115734398A (zh) * 2021-08-25 2023-03-03 华为技术有限公司 一种通信方法及装置
CN116095667A (zh) * 2021-11-05 2023-05-09 华为技术有限公司 一种通信的方法和装置
CN116471549A (zh) * 2022-01-11 2023-07-21 华为技术有限公司 一种数据传输的方法、装置以及系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114430592A (zh) * 2020-10-29 2022-05-03 华为技术有限公司 一种通信方法及对应装置
CN115209398A (zh) * 2021-04-13 2022-10-18 华为技术有限公司 一种报文传输方法及装置
CN115734398A (zh) * 2021-08-25 2023-03-03 华为技术有限公司 一种通信方法及装置
CN116095667A (zh) * 2021-11-05 2023-05-09 华为技术有限公司 一种通信的方法和装置
CN116471549A (zh) * 2022-01-11 2023-07-21 华为技术有限公司 一种数据传输的方法、装置以及系统

Also Published As

Publication number Publication date
CN119946675A (zh) 2025-05-06

Similar Documents

Publication Publication Date Title
US12192589B2 (en) Multicast service transmission method and apparatus
US11722888B2 (en) Security context obtaining method and apparatus
CN109845300B (zh) 无线通信系统中支持用于cu-cp和cu-up的分离的安全性的方法和装置
US20230239940A1 (en) Data transmission method and apparatus
JP6700434B2 (ja) 無線通信方法及びデバイス
US20210058771A1 (en) Key generation method and related apparatus
US11259344B2 (en) Network architecture and information exchange method and apparatus
EP3735018B1 (en) Security negotiation method and apparatus
EP4319297B1 (en) Communication method and communications apparatus
CN109315008B (zh) 多连接通信方法和设备
JP2018526869A (ja) 暗号化されたクライアントデバイスコンテキストを用いたネットワークアーキテクチャおよびセキュリティ
CN110784434B (zh) 通信方法及装置
US20170244705A1 (en) Method of using converged core network service, universal control entity, and converged core network system
US12185395B2 (en) Communications method and apparatus to reduce a data transmission latency between an IAB node and IAB donor
JP2018537912A (ja) 複数の接続およびサービスコンテキストをサポートするためのセキュリティモデルを使用したワイヤレス通信のための方法および装置
CN109246696B (zh) 密钥处理方法以及相关装置
JP7652263B2 (ja) Iabの通信方法及び装置
CN116033464A (zh) 信息传输的方法和装置
CN115696408A (zh) 一种用户面功能容灾方法及通信装置
WO2023213209A1 (zh) 密钥管理方法及通信装置
TWI816295B (zh) 配置演進分組系統非接入層安全演算法的方法及相關裝置
US12615686B2 (en) Early data communication with preconfigured resources
WO2023246086A1 (zh) 一种基于物联网的无线接入、信息处理方法及网络系统
WO2025093029A1 (zh) 数据传输方法及装置、计算机可读存储介质
EP4369745A1 (en) Communication method and apparatus

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24885025

Country of ref document: EP

Kind code of ref document: A1