WO2018157754A1 - 一种业务管理方法及其装置 - Google Patents

一种业务管理方法及其装置 Download PDF

Info

Publication number
WO2018157754A1
WO2018157754A1 PCT/CN2018/076985 CN2018076985W WO2018157754A1 WO 2018157754 A1 WO2018157754 A1 WO 2018157754A1 CN 2018076985 W CN2018076985 W CN 2018076985W WO 2018157754 A1 WO2018157754 A1 WO 2018157754A1
Authority
WO
WIPO (PCT)
Prior art keywords
gateway
user equipment
policy
user plane
authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/076985
Other languages
English (en)
French (fr)
Inventor
胡翔
夏渊
朱泉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to KR1020197027599A priority Critical patent/KR102209599B1/ko
Priority to EP18761755.0A priority patent/EP3573311B1/en
Priority to JP2019542725A priority patent/JP6911263B2/ja
Publication of WO2018157754A1 publication Critical patent/WO2018157754A1/zh
Priority to US16/552,806 priority patent/US11265226B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/02Details
    • H04L12/14Charging, metering or billing arrangements specially adapted for data communications, e.g. authentication, authorisation and accounting [AAA] framework
    • H04L12/1403Architecture for metering, charging or billing
    • H04L12/1407Policy-and-charging control [PCC] architecture
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • H04L67/141Setup of application sessions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0894Policy-based network configuration management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/50Network service management, e.g. ensuring proper service fulfilment according to agreements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/20Traffic policing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1069Session establishment or de-establishment
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M15/00Arrangements for metering, time-control or time indication ; Metering, charging or billing arrangements for voice wireline or wireless communications, e.g. VoIP
    • H04M15/66Policy and charging system
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/24Accounting or billing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/18Selecting a network or a communication service

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a service management method and apparatus therefor.
  • DPI Deep Packet Inspection
  • GPRS General Packet Radio Service
  • GGSN GPRS Support Node
  • PGW Packet Data Network Gateway
  • TDF Traffic Detection Function
  • the PGW is a functional entity in an Evolved Packet Core (EPC) network, and is a user plane anchor between a 3rd Generation Partnership Project (3GPP) access network and a non-3GPP access network. It is an interface between the EPC core network packet switching domain and an external packet data network (PDN), and is used for the execution of the service data flow detection, charging, and control policies.
  • EPC Evolved Packet Core
  • 3GPP 3rd Generation Partnership Project
  • PDN packet data network
  • PGW as a policy and charging enforcement function (Policy and Charging Enforcement Function, PCEF ) It is connected to the Policy Charging and Rules Function (PCRF) through the Gx interface.
  • PCEF Policy Charging and Rules Function
  • the GGSN can be used as a PCEF in a second generation mobile communication (2 nd -Generation, 2G) network.
  • the PCEF supports the basic functions of the Policy and Charging Control (PCC), and implements policy and charging control through the policies delivered by the PCRF.
  • the PCEF supports the policy or local configuration policy delivered by the PCRF/Authentication, Authorization, and Accounting (AAA) server, and is responsible for service data flow detection, policy enforcement, and flow-based charging processing.
  • AAA Authentication, Authorization, and Accounting
  • Figure 1a shows the deployment of the gateway device in the 2G/3G/4G network architecture.
  • the service management is performed on the PGW/GGSN, for example, the sensing of all services, the policy matching, and the execution of the accounting and control policies.
  • User equipment User Equipment (User In the entire network function division, only the traffic flow template (TFT), the bearer level identifier, and the quality of service (QoS) delivered by the control device of the core network based on the signaling message are supported. And other related information, thereby implementing bearer selection and QoS policies for the uplink service flow.
  • TFT traffic flow template
  • QoS quality of service
  • Deployment schematic gateway user plane shown in FIG. 1b / separation control plane network architecture (e.g., a fifth-generation mobile communication (5 th -Generation, 5G) network architecture) under, centralized deployment backbone network gateways include a serving gateway (Service Gateway, SGW) and the functions of the control plane of the PGW, such as handover of mobile signaling plane anchor points between base stations, inter-operator roaming charging, access signaling processing, dedicated bearer creation signaling processing, address pool allocation User access authentication control, etc.; deploy distributed gateways in the metro core network, including user plane functions of SGW and PGW, such as handover mobile data description, user data forwarding, user charging information collection, charging, and Control strategy execution, business DPI processing, etc.
  • SGW Service Gateway
  • the centralized gateway/distributed gateway completes the functions of the Serving GateWay (SGW)/PGW.
  • SGW Serving GateWay
  • PGW Packet Control Function
  • the technical problem to be solved by the embodiments of the present invention is to provide a service management method and device thereof, which implements service management of the user equipment, can improve the participation of the user equipment, and improve the management capability of the user equipment.
  • a first aspect of the embodiments of the present invention provides a service management method, including:
  • the user equipment acquires a communication address of the gateway user plane, and establishes a communication link with the gateway user plane through the communication address;
  • the user equipment sends a session connection establishment request message to the gateway user plane through the communication link, where the session connection establishment request message includes authentication information of the gateway terminal module of the user equipment, and the gateway of the user equipment
  • the authentication information of the terminal module is used by the gateway user plane to trigger the gateway control plane to request the authentication server to authenticate the gateway terminal module of the user equipment;
  • the user equipment performs service management according to the service policy information sent by the gateway user plane through the communication link.
  • the user equipment establishes a communication link with the gateway user plane through the communication address of the gateway user plane, so that the user equipment performs the service policy information sent by the gateway user plane when the user equipment is authenticated.
  • the service management implements the service management of the user equipment, improves the participation of the user equipment, and improves the management capability of the user equipment.
  • the authentication information of the gateway terminal module of the user equipment includes information such as an identifier, a keyword information, and the like of the gateway terminal module of the user equipment, and is used by the authentication server to the gateway terminal of the user equipment.
  • the module performs authentication.
  • the service policy information includes a current at least one network slice connection policy, where the current at least one network slice connection policy is an initial at least one network slice connection policy or an updated at least one network a slice connection policy, where the network slice connection policy is used to indicate a session connection relationship between the application identifier and the network slice;
  • the process of performing service management by the user equipment according to the service policy information sent by the gateway user plane through the communication link is:
  • the user equipment acquires an application identifier of the current application
  • the user equipment searches for a network slice corresponding to the application identifier of the current application in the current at least one network slice connection policy sent by the gateway user plane through the communication link;
  • the user equipment establishes a session connection and performs service access according to the found network slice.
  • the possible implementation manner allows the user equipment to independently select the network slice for session connection and service access, reduce the processing pressure of the core network device, and improve the processing capability of the user equipment.
  • the current at least one network slice connection policy is the updated at least one network slice connection policy
  • the user equipment sends a session connection update response message to the gateway user plane through the communication link, and the session connection update is performed according to the service policy information sent by the gateway user plane through the communication link.
  • the response message is used to indicate that the user equipment has updated the initial at least one network slice connection policy, so that the gateway user plane knows the update condition of the user equipment.
  • the service policy information includes at least one service charging and control policy, where the service charging and control policy is used to indicate a correspondence between the application identifier and the charging and control policy;
  • the process of performing service management by the user equipment according to the service policy information sent by the gateway user plane through the communication link is:
  • the user equipment acquires an application identifier of a current application that accesses the data service
  • the user equipment searches for the charging and control policy corresponding to the application identifier of the current application in the at least one service charging and control policy sent by the gateway user plane through the communication link;
  • the user equipment performs statistics and access control of data traffic according to the found charging and control policy.
  • the possible implementation of the user equipment to perform statistics and access control on the data traffic of the current application, and improve the participation and processing capability of the user equipment.
  • the user equipment After the user equipment performs service management according to the service policy information sent by the gateway user plane through the communication link, periodically, the user equipment faces the gateway user through the communication link.
  • Sending a usage report request message where the usage report request message includes feature attribute information of the user equipment, application usage amount statistics information, and the usage report request message informs the gateway user of usage, for requesting the gateway
  • the user plane generates an online or offline bill and feeds back a report confirmation message, where the usage report confirmation message is used to indicate that the gateway user plane has confirmed the application usage statistics.
  • the user equipment acquires a communication address of the gateway user plane according to the attach response message sent by the access network gateway, where the attach response message includes a communication address of the gateway user plane, and is obtained according to the attach response message. No need to send a request specifically, it is simple and convenient.
  • the user equipment acquires a communication address of the gateway user plane according to the pre-configuration information of the user equipment, where the pre-configuration information is configured by the operator when the user equipment is customized, and is obtained according to the pre-configuration information. Will not change the existing activation process.
  • the user equipment acquires the communication address of the gateway user plane according to the configuration mode selected by the user, that is, the user equipment obtains by manual configuration, and does not change the existing activation process.
  • the user equipment before the user equipment establishes a communication link with the gateway user plane by using the communication address, detecting a gateway terminal module of the user equipment, rights of the user equipment, and Whether the network operating environment satisfies the preset condition, and if the detection result is yes, establish a communication link with the gateway user plane through the communication address. It is determined by a preset condition whether the user equipment can establish a communication link to ensure the security of the communication link.
  • the session connection establishment request message further includes feature attribute information of the user equipment, where the feature attribute information of the user equipment includes a mobile station integrated service digital network number MSISDN and an international mobile subscriber identity code. IMSI for identification of user equipment.
  • connection session establishment response message further includes feature attribute information of the user equipment to associate the user equipment with the authentication result.
  • the authentication information of the gateway terminal module of the user plane device is encrypted and transmitted in the communication link to prevent tampering and ensure the security of the transmission.
  • a second aspect of the embodiments of the present invention provides a service management method, including:
  • the gateway user plane receives the session connection establishment request message sent by the user equipment, where the session connection establishment request message includes the authentication information of the gateway terminal module of the user equipment, where the communication link is the user equipment Obtaining a link between the communication address of the gateway user plane and the user plane of the gateway;
  • the gateway user sends an authentication request message to the gateway control plane, where the authentication request message includes authentication information of the gateway terminal module of the user equipment, where the authentication request message is used to trigger the gateway control plane to request the authentication.
  • the right server authenticates the gateway terminal module of the user equipment;
  • the gateway user plane receives the service policy information sent by the gateway control plane, and sends the service policy information to the user equipment by using the communication link,
  • the service policy information is used by the user equipment to perform service management according to the service policy information.
  • the service policy information is sent to the user equipment through the communication link established with the user equipment, and the user equipment performs service management according to the service policy information, thereby reducing the core network.
  • the business management pressure of the device improves the business management capability of the user equipment.
  • the service policy information includes a current at least one network slice connection policy, where the current at least one network slice connection policy is an initial at least one network slice connection policy or an updated at least one network
  • the slice connection policy is used to indicate the session connection relationship between the application identifier and the network slice, so that the user equipment independently selects the network slice for session connection and service access, reduces the processing pressure of the core network device, and improves the user equipment. Processing capacity.
  • the gateway user plane receives the user equipment sending by using the communication link.
  • the session connection update response message is used to indicate that the user equipment has updated the initial at least one network slice connection policy to learn the update status of the user equipment.
  • the service policy information includes at least one service charging and control policy, where the service charging and control policy is used to indicate a correspondence between the application identifier and the charging and control policy, so as to implement the user.
  • the device collects statistics and access control on the data traffic of the current application, and improves the participation and processing capability of the user equipment.
  • the gateway user plane receives, by using the communication link, a usage report request message periodically sent by the user equipment, where the usage report request message includes feature attribute information of the user equipment, Applying usage statistics information; generating an online or offline CDR according to the usage report request message and feeding back a usage report confirmation message to the user equipment over the communication link, the usage report confirmation message is used to indicate the gateway user The application usage statistics have been confirmed.
  • the session connection establishment request message further includes feature attribute information of the user equipment, and the feature attribute information of the user equipment includes an MSISDN and an IMSI for identifying the user equipment.
  • the authentication response message, the connection session establishment response message further includes feature attribute information of the user equipment, and is used to associate the user equipment with the authentication result.
  • the authentication information of the gateway terminal module of the user plane device is encrypted and transmitted in the communication link to prevent tampering and ensure the security of the transmission.
  • a third aspect of the embodiments of the present invention provides a user equipment, including:
  • An obtaining unit configured to obtain a communication address of a gateway user plane
  • Establishing a unit configured to establish, by using the communication address, a communication link with the gateway user plane;
  • a sending unit configured to send, by using the communication link, a session connection establishment request message to the gateway user plane, where the session connection establishment request message includes authentication information of a gateway terminal module of the user equipment, where the user equipment is The authentication information of the gateway terminal module is used by the gateway user plane to trigger the gateway control plane to request the authentication server to authenticate the gateway terminal module of the user equipment;
  • a receiving unit configured to receive, by using the communication link, a session connection establishment response message sent by the gateway user plane, where the session connection establishment response message includes an authentication result;
  • the management unit is configured to perform service management according to the service policy information sent by the gateway user plane through the communication link, if the authentication result is successful.
  • the user equipment provided by the third aspect of the embodiments of the present invention is used to implement the functions performed by the user equipment in the service management method provided by the first aspect of the embodiments of the present invention.
  • a fourth aspect of the embodiments of the present invention provides a gateway user plane, including:
  • a receiving unit configured to receive, by using a communication link, a session connection establishment request message sent by the user equipment, where the session connection establishment request message includes authentication information of a gateway terminal module of the user equipment, where the communication link is the user The link between the device and the user plane of the gateway established by the device through the obtained communication address of the gateway user plane;
  • a sending unit configured to send an authentication request message to the gateway control plane, where the authentication request message includes authentication information of the gateway terminal module of the user equipment, where the authentication request message is used to trigger the gateway control plane request
  • the authentication server authenticates the gateway terminal module of the user equipment
  • the receiving unit is further configured to receive an authentication response message sent by the gateway control plane;
  • the sending unit is further configured to send a session connection establishment response message to the user equipment by using the communication link, where the authentication response message and the session connection establishment response message include an authentication result;
  • the receiving unit is further configured to: if the authentication result is successful, receive the service policy information sent by the gateway control plane;
  • the sending unit is further configured to send the service policy information to the user equipment by using the communication link, where the service policy information is used by the user equipment to perform service management according to the service policy information.
  • the gateway user plane provided by the fourth aspect of the embodiment of the present invention is used to implement the function performed by the gateway user plane in the service management method provided by the second aspect of the embodiment of the present invention.
  • a fifth aspect of the embodiments of the present invention provides another user equipment, including a processor and a transceiver.
  • the processor is configured to acquire a communication address of a gateway user plane, and establish a communication link with the gateway user plane by using the communication address;
  • the transceiver is configured to send, by using the communication link, a session connection establishment request message to the gateway user plane, where the session connection establishment request message includes authentication information of a gateway terminal module of the user equipment, where the user equipment is The authentication information of the gateway terminal module is used by the gateway user plane to trigger the gateway control plane to request the authentication server to authenticate the gateway terminal module of the user equipment;
  • the transceiver is further configured to receive, by using the communication link, a session connection establishment response message sent by the gateway user plane, where the session connection establishment response message includes an authentication result;
  • the processor is further configured to perform service management according to the service policy information sent by the gateway user plane through the communication link.
  • the user equipment provided by the fifth aspect of the embodiments of the present invention is used to implement the functions performed by the user equipment in the service management method provided by the first aspect of the embodiments of the present invention.
  • a sixth aspect of the embodiments of the present invention provides another gateway user plane, including a processor and a transceiver.
  • the transceiver is configured to receive, by using a communication link, a session connection establishment request message sent by a user equipment, where the session connection establishment request message includes authentication information of a gateway terminal module of the user equipment, where the communication link is the user The link between the device and the user plane of the gateway established by the device through the obtained communication address of the gateway user plane;
  • the transceiver is further configured to send an authentication request message to the gateway control plane, where the authentication request message includes authentication information of the gateway terminal module of the user equipment, where the authentication request message is used to trigger the gateway control
  • the surface request authentication server authenticates the gateway terminal module of the user equipment
  • the transceiver is further configured to receive an authentication response message sent by the gateway control plane, and send a session connection establishment response message to the user equipment by using the communication link, where the authentication response message, the session connection Establishing a response message including an authentication result;
  • the transceiver is further configured to receive the service policy information sent by the gateway control plane, and send the service policy information to the user equipment by using the communication link,
  • the service policy information is used by the user equipment to perform service management according to the service policy information.
  • the gateway user plane provided by the sixth aspect of the embodiment of the present invention is used to implement the function performed by the gateway user plane in the service management method provided by the second aspect of the embodiment of the present invention.
  • the user equipment acquires the communication address of the gateway user plane, establishes a communication link with the gateway user plane, and sends the authentication information of the gateway terminal module carrying the user equipment to the gateway user plane through the communication link.
  • the gateway user plane sends an authentication request message to the gateway control plane, which is used to trigger the gateway control plane to request the authentication server to authenticate the gateway terminal module of the user equipment.
  • the authentication server authenticates the gateway terminal module of the user equipment, and feeds the authentication result to the gateway control plane; when receiving the authentication result, the gateway control plane carries the authentication result in the authentication response message and sends it to the authentication response message.
  • the gateway user plane sends the authentication result to the user equipment in the session connection establishment response message by the gateway user plane; if the authentication result is successful, the gateway control sends the service policy information to the gateway user plane, and the gateway user plane
  • the service policy information is sent to the user equipment, and the user equipment performs the business according to the business policy information. Management, enabling users to manage their business equipment, can increase user engagement equipment, improve the user device management capabilities to the business.
  • FIG. 1a is a schematic diagram of deployment of a gateway device in a 2G/3G/4G network architecture
  • FIG. 1b is a schematic diagram of deployment of a gateway device in a user plane/control plane separated network structure
  • FIG. 2 is a schematic structural diagram of a service management system according to an embodiment of the present invention.
  • FIG. 3 is a schematic structural diagram of a user equipment according to an embodiment of the present disclosure.
  • FIG. 4 is a schematic structural diagram of a gateway user plane according to an embodiment of the present invention.
  • FIG. 5 is a schematic diagram of communication of a service management method according to Embodiment 1 of the present invention.
  • FIG. 6 is a schematic diagram of communication of a service management method according to Embodiment 2 of the present invention.
  • FIG. 7 is a schematic diagram of communication of a service management method according to Embodiment 3 of the present invention.
  • FIG. 8 is a schematic diagram of communication of a service management method according to Embodiment 4 of the present invention.
  • FIG. 9 is a schematic structural diagram of another user equipment according to an embodiment of the present disclosure.
  • FIG. 10 is a schematic structural diagram of another gateway user plane according to an embodiment of the present invention.
  • FIG. 2 is a schematic structural diagram of a service management system according to an embodiment of the present invention.
  • the service management system includes a user equipment (User Equipment, UE), an access network (Radio Access Network, RAN), and a gateway control.
  • Gateway Control Plane (GW-C) Gateway User Plane (GW-U) 1, Gateway User Plane 2, Internet (Internet) and Augmented Reality (AR) servers (Figure 2) Enterprise).
  • GW-C Gateway Control Plane
  • GW-U Gateway User Plane
  • Internet Internet
  • AR Augmented Reality
  • the UE has a gateway terminal (GW-T) module, and the module can implement functions such as authentication, policy interaction, and statistical information reporting with the GW-U through the data communication link, so as to assist the core network side. Dynamic deployment and selection of future network slices, statistical reporting of application data services, and policy control.
  • GW-T gateway terminal
  • the access network may be an access network under a 2G/3G/4G network architecture, an access network under a user plane/control plane separation network structure, or an access network under a future communication network architecture.
  • the gateway control plane is a gateway control plane function entity
  • the gateway user plane is a gateway user plane function entity.
  • the GW-C may be a Service Gateway-Control Plane (SGW-C) or a Packet Data Network Gateway-Control Plane (PGW-C), and may also integrate control planes in the core network device.
  • SGW-C Service Gateway-Control Plane
  • PGW-C Packet Data Network Gateway-Control Plane
  • the functions include, for example, the functions of the control planes of the SGW and the PGW; the GW-U may be a Service Gateway-User Plane (SGW-U) or a Packet Data Network Gateway-User Plane (Packet Data Network Gateway-User Plane, PGW-U) can also combine the functions of the user plane in the core network device, for example, the functions of the user plane including the SGW and the PGW.
  • GW-C and GW-U can be deployed together or separately. Further, for different application scenarios, the GW-U may be different. For example, the GW-U 1 application shown in FIG. 2 is used to access the Internet, and the GW-U 2 is applied to the scenario of accessing the AR service.
  • AR is to use technology to add content on the basis of reality.
  • the core technologies used include real object recognition, geographic location, and real-time calculus according to different scenarios.
  • the AR server may be different for different types of AR services.
  • the UE accesses the Internet through the dotted lines 1 and 2 shown in FIG. 2, the dotted line 1 indicates that the UE establishes a public network service session, and the dotted line 2 indicates that the GW-C notifies the GW-U 1 to establish an Sx bearer context; when the UE accesses the AR service,
  • the dashed lines 6 and 7 shown in Fig. 2 are implemented, the broken line 6 indicates that the UE establishes an AR service session, and the dashed line 7 indicates that the GW-C notifies the GW-U 2 to establish an Sx bearer context.
  • Sx represents a session connection between GW-C and GW-U. It can be seen that the current UE access service needs to be implemented by GW-C and GW-U.
  • the UE may establish a data communication link with the GW-U, specifically, the GW-T module of the UE may establish a data communication link with the GW-U, and the UE establishes the data communication. After the link, the service is directly accessed through the GW-U.
  • the solid line 4 indicates that the UE completes the authentication process for the GW-T module through the data communication link; the solid line 3 indicates that the UE accesses the Internet through the GW-U 1; the solid line 5 indicates the GW-U.
  • the service policy is delivered to the UE through the data communication link, and the service policy may include a network slice connection policy, a charging and control policy, and the like; the solid line 8 indicates that the UE accesses the AR service through the GW-U 2.
  • FIG. 2 may also include a server corresponding to the Internet of Things (IoT), telemedicine, and autopilot, and GW-U.
  • IoT Internet of Things
  • telemedicine Telemedicine
  • autopilot GW-U
  • SLAs Service-Level Agreements
  • the user equipment in the embodiment of the present invention may be an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user equipment.
  • the access terminal may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), with wireless communication.
  • SIP Session Initiation Protocol
  • WLL Wireless Local Loop
  • PDA Personal Digital Assistant
  • the user equipment in the embodiment of the present invention has a GW-T module, and the module may be a chip or a hardware module designed in the user equipment, or may be a system application installed in the user equipment. If the user device is not root, the application cannot be deleted, as the case may be. In other words, the user equipment in the embodiment of the present invention may be a customized user equipment provided by an operator.
  • FIG. 3 is a schematic structural diagram of a user equipment according to an embodiment of the present invention.
  • the user equipment 101 includes a processor 1011 and a transceiver 1012.
  • other components such as a power supply and a display module, may be included.
  • the processor 1011 may be a controller, a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), and an application-specific integrated circuit (ASIC).
  • FPGA Field Programmable Gate Array
  • Processor 1011 may also be a combination of computing functions, such as one or more microprocessor combinations, a combination of a DSP and a microprocessor, and the like.
  • the transceiver 1012 is configured to implement communication or data transmission between the user equipment 101 and a network device such as a base station or a satellite, and is used to implement communication or data transmission between the user equipment 101 and other user equipment, and is used in the embodiment of the present invention.
  • the transceiver 1012 is used for communication or data transmission between the user equipment 101 and the gateway user plane. If the GW-T module is a chip or a hardware module designed in the user equipment, the user equipment 101 shown in FIG. 3 further includes a GW-T module 1013 for implementing authentication and policy interaction with the gateway user plane.
  • the GW-T module 1013 may be integrated in the processor 1011 or the transceiver 1012, or it may be a module that is deployed independently.
  • FIG. 4 is a schematic structural diagram of a gateway user plane according to an embodiment of the present invention.
  • 102 includes a processor 1021 and a transceiver 1022.
  • the processor 1021 is used to implement or perform various exemplary logical blocks, modules and circuits described in connection with embodiments of the present invention.
  • the transceiver 1022 is configured to implement communication or data transmission between the gateway user plane 102 and the gateway control plane, user equipment, and other core network devices.
  • the gateway user plane 102 includes a communication address (GW-U IP Address for GW-T) for the GW-T module of the user equipment.
  • the gateway user plane includes multiple communication addresses, and the GW-U IP Address for GW-T is used.
  • the data communication link is established with the GW-T module of the user equipment, so that the gateway user plane 102 sends the service policy information to the user equipment.
  • the schematic diagram of the gateway user plane shown in FIG. 4 may also be a schematic structural diagram of the gateway control plane.
  • the embodiment of the present invention further relates to an authentication server, that is, an AAA server, for authenticating the GW-T module of the user equipment.
  • FIG. 5 to FIG. 8 are introduced from the perspective of user equipment and gateway user interaction.
  • the embodiment shown in FIG. 5 is a general introduction to a pair of service management methods, and the second embodiment and the third embodiment shown in FIG. 6 and FIG. 7 describe the network slice connection of the AR service, and FIG. 8
  • the fourth embodiment shows the charging and control of the data service.
  • FIG. 5 is a schematic diagram of communication of a service management method according to Embodiment 1 of the present invention, where the method includes but is not limited to the following steps:
  • Step S101 The user equipment acquires a communication address of the gateway user plane.
  • the user equipment before acquiring the communication address of the gateway user plane, the user equipment initiates an activation request message, and initiates activation according to the process defined in the 3GPP standard document 23401.
  • the specific process of initiating the activation request message is: the UE sends an attach request to the RAN; when the RAN receives the Attach Request, it sends a Mobility Management Entity (MME) to the Mobility Management Entity (MME).
  • MME Mobility Management Entity
  • MME Mobility Management Entity
  • Sending an Attach Request when receiving the Attach Request, the MME sends a Create Session Request to the SGW-C; when receiving the Create Session Request, the SGW-C sends a Create Session Request to the PGW-C; PGW-C Upon receiving the Create Session Request, the SGW-C sends a Create Session Response to the SGW-C; when receiving the Create Session Response, the SGW-C sends a Create Session Response to the MME; when the MME receives the Create Session Response, the MME The RAN sends an Attach Accept. When the RAN receives the Attach Accept, it sends an Attach Accept to the UE to complete the activation.
  • the SGW-C establishes the SGW-C and the SGW by sending an Sx Session Establishment Request to the SGW-U and an Sx Session Establishment Response sent by the SGW-U to the SGW-C.
  • the Sx session connection between Us can establish an Sx session connection between PGW-C and PGW-U.
  • the MME sends a Create Session Request to the GW-C; when receiving the Create Session Request, the GW-C sends a Create Session Response to the MME; the GW-C can also establish a GW-U with the GW-U.
  • the connection between the Sx sessions are examples of the Sx sessions.
  • the user equipment acquires a communication address of a gateway user plane according to an attach response message sent by the access network gateway, where the attach response message includes a communication address of the gateway user plane. That is, the user equipment obtains the communication address of the gateway user plane through the Attach Accept sent by the RAN, specifically, obtains the GW-U IP Address for GW-T.
  • the Create Session Response sent by the PGW-C to the SGW-C carries the GW-U IP Address for GW-T, and the GW-U can be represented by adding a cell to the Create Session Response.
  • the Create Session Response sent by the SGW-C to the MME carries the GW-U IP Address for GW-T
  • the Attach Accept sent by the MME to the RAN carries the GW-U IP Address for GW-T
  • the UE sends the GW-U IP Address for GW-T in the Attach Accept, so that the UE obtains the GW-U IP Address for GW-T through the Attach Accept sent by the RAN.
  • the user equipment acquires a communication address of a gateway user plane according to the pre-configuration information of the user equipment.
  • the pre-configuration information includes a communication address of the gateway user plane, and specifically includes a GW-U IP Address for GW-T.
  • the pre-configuration information may be configured by the operator when the user equipment is customized, or may be configured by the manufacturer of the user equipment, and may also be configured by the system of the user equipment, which is not limited herein.
  • the user equipment acquires a communication address of a gateway user plane according to a configuration mode selected by the user.
  • the user equipment provides several configurations for the user, and obtains the GW-U IP Address for GW-T according to the configuration mode selected by the user.
  • Step S102 The user equipment establishes a communication link with the gateway user plane.
  • the user equipment may establish a communication link with the gateway user plane, where the communication link is a data communication link, and the gateway may be used for the gateway.
  • the user sends service policy information to the user equipment, and the user equipment sends a usage report request message or the like to the gateway user plane.
  • the communication link may encrypt the transmitted content, or the communication link transmits the encrypted content.
  • the user equipment Before establishing the communication link, the user equipment detects whether the gateway terminal module of the user equipment, the authority of the user equipment, and the network running environment meet the preset condition, and if the detection result is yes, establish The communication link.
  • the preset conditions include that the UE has a GW-T module, the UE is not rooted, the operation authority has been acquired, and the network running environment is secure. If the user equipment does not have the gateway terminal module, the user equipment is rooted, the operation authority is not acquired, and the network operating environment is insecure, it is determined that the preset condition is not met.
  • the maximum privilege of the UE being changed by the root is changed.
  • the root privilege of the UE is the same as that of the factory. The highest privilege is not changed.
  • Obtaining the operation authority means that the UE is operable and can be used normally.
  • the communication link is a Hyper Text Transfer Protocol over Secure Socket Layer (HTTPS) transmission channel
  • HTTPS Hyper Text Transfer Protocol over Secure Socket Layer
  • the gateway user plane decrypts the preset key by receiving the request, and sends an HTTPS connection response to the user equipment, thereby implementing the user equipment and the The establishment of a communication link between the user planes of the gateway.
  • HTTPS Hyper Text Transfer Protocol over Secure Socket Layer
  • the communication link is another Secure Sockets Layer (SSL) transmission channel
  • the user equipment initiates a connection request with the GW-U IP Address for GW-T by using a preset key.
  • the gateway user plane decrypts the preset key and sends a connection response to the user equipment, so as to implement a communication chain between the user equipment and the gateway user plane. The establishment of the road.
  • SSL Secure Sockets Layer
  • HTTPS transmission channel and SSL transmission channel are safe and reliable transmission channels, and other safe and reliable transmission channels can also be adopted.
  • Step S103 The user equipment sends a session connection establishment request message to the gateway user plane through the communication link, where the session connection establishment request message includes authentication information of the gateway terminal module of the user equipment;
  • the user equipment sends a session connection establishment request message (Session Connection Create Request) to the gateway user plane through the communication link, where the session connection establishment request message includes a reference of the gateway terminal module of the user equipment.
  • the authentication information of the gateway terminal module of the user equipment includes information such as an identifier of the GW-T module, keyword information (authorization/authentication key), and the like, where the gateway user plane triggers the gateway control plane to request the authentication server.
  • the GW-T module of the user equipment performs authentication.
  • the session connection establishment request message further includes feature attribute information of the user equipment, and the feature attribute information of the user equipment includes a Mobile Subscriber International Integrated Service Digital Network/Public Switched Telephone Network number (MSISDN). And information such as the International Mobile Subscriber Identification Number (IMSI).
  • MSISDN Mobile Subscriber International Integrated Service Digital Network/Public Switched Telephone Network number
  • IMSI International Mobile Subscriber Identification Number
  • the authentication information of the gateway terminal module of the user equipment may be the binding of the feature attribute information of the user equipment, and whether the binding is set by the operator.
  • the user equipment encrypts the session connection establishment request message by using the preset key, or uses the preset key to authenticate information of the gateway terminal module of the user equipment,
  • the feature attribute information of the user equipment is encrypted to ensure transmission security.
  • Step S104 The gateway user plane receives the session connection establishment request message through the communication link;
  • the gateway user plane receives the session connection establishment request message through the communication link, parses the session connection establishment request message, and acquires authentication information of the gateway terminal module of the user equipment. If the session connection establishment request message is encrypted by using the preset key, the gateway user plane decrypts the session connection establishment request message by using the preset key, and parses the user equipment. The authentication information of the gateway terminal module; if the session connection establishment request message further includes the feature attribute information of the user equipment, parsing the same. If the authentication information of the gateway terminal module of the user equipment and the feature attribute information of the user equipment are encrypted by using the preset key, the gateway user plane decrypts by using the preset key. Analysis.
  • Step S105 The gateway user sends a first authentication request message to the gateway control plane, where the first authentication request message includes authentication information of the gateway terminal module of the user equipment;
  • the first authentication request message further includes a session identifier, where the session identifier is a session identifier of the Sx session, and is used to identify the Sx.
  • the gateway user plane and gateway control plane of the session In the system architecture shown in FIG. 2, there may be multiple gateway user planes and multiple gateway control planes, and the Sx session identifier is used to distinguish different gateway user planes connected to the gateway control plane.
  • the first authentication request message further includes feature attribute information of the user equipment.
  • Step S106 The gateway control plane receives the first authentication request message.
  • the gateway control plane receives the first authentication request message, and parses the first authentication request message.
  • Step S107 The gateway control sends a second authentication request message to the authentication server, where the second authentication request message includes authentication information of the gateway terminal module of the user equipment;
  • the gateway control plane constructs a second authentication request message according to the parsing result, and sends the second authentication request message to the authentication server, where the second authentication request message includes a gateway terminal of the user equipment. Authentication information of the module. And in the case that the gateway user plane is deployed separately from the gateway control plane, the second authentication request message further includes the session identifier.
  • the second authentication request message further includes feature attribute information of the user equipment.
  • Step S108 The authentication server receives the second authentication request message, and performs authentication on the gateway terminal module of the user equipment.
  • the authentication server receives the second authentication request message, and parses the second authentication request message to obtain authentication information of the gateway terminal module of the user equipment, according to the user equipment.
  • the authentication information of the gateway terminal module authenticates the gateway terminal module of the user equipment.
  • Step S109 The authentication server sends a second authentication response message to the gateway control plane, where the second authentication response message includes an authentication result.
  • the authentication server authenticates the gateway terminal module of the user equipment to obtain an authentication result, where the authentication result is an authentication success or an authentication failure. After obtaining the authentication result, the authentication server sends a second authentication response message to the gateway control plane, where the second authentication response message includes the authentication result.
  • the second authentication response message further includes feature attribute information of the user equipment.
  • Step S110 The gateway control plane receives the second authentication response message.
  • the gateway control plane receives the second authentication response message sent by the authentication server.
  • Step S111 The gateway control sends a first authentication response message to the gateway user plane, where the first authentication response message includes the authentication result;
  • the gateway control plane sends a first authentication response message carrying the authentication result to the gateway user plane, regardless of whether the authentication succeeds or the authentication fails.
  • the first authentication response message further includes feature attribute information of the user equipment.
  • Step S112 The gateway user plane receives the first authentication response message.
  • the gateway user plane receives the first authentication response message sent by the gateway control plane by using an Sx session connection.
  • Step S113 The gateway user sends a session connection establishment response message to the user equipment, where the session connection establishment response message includes the authentication result;
  • the gateway user plane sends a session connection establishment response message to the user equipment by using the communication link, where the session connection establishment response message includes the authentication result, and whether the user equipment is authenticated.
  • the authentication result or the session connection establishment response message is encrypted and sent.
  • the session connection establishment response message further includes feature attribute information of the user equipment.
  • Step S114 The user equipment receives the session connection establishment response message
  • the user equipment receives the session connection establishment response message sent by the gateway user plane through the communication link.
  • Step S115 If the authentication result is successful, the gateway control sends service policy information to the gateway user plane.
  • the gateway control plane sends the service policy information to the gateway user plane.
  • the service policy information may be carried in the first authentication response message, or may not be carried in the first authentication response message, that is, after the first authentication response message is sent, the service is sent.
  • Strategy information may be carried in the first authentication response message, or may not be carried in the first authentication response message, that is, after the first authentication response message is sent, the service is sent.
  • the service policy information includes a current at least one network slice connection policy, where the current at least one network slice connection policy is an initial at least one network slice connection policy or an updated at least one network
  • the slice connection policy is used to indicate a session connection relationship between the application identifier and the network slice.
  • the network slice connection policy includes the correspondence between the application identifier, the access type, and the access point name (APN), and reflects the session connection relationship between the application identifier and the network slice, that is, which application is used. Which access point is connected to the access type.
  • the service policy information includes at least one service charging and control policy, where the service charging and control policy is used to indicate a correspondence between the application identifier and the charging and control policy.
  • the service charging and control policy includes the correspondence between the application identifier and the service identifier, the rate group, and the quality of service (QoS), and reflects the correspondence between the application identifier and the charging and control policy, that is, Which application is used for billing and control.
  • the two types of policies included in the foregoing service policy information are not limited to the first embodiment of the present invention.
  • the foregoing service policy information may also include other types of policies.
  • step S115 can be performed simultaneously with step S111, that is, in the case that the gateway terminal module of the user equipment passes the authentication, the gateway control simultaneously sends the first authentication response to the gateway user plane.
  • the message and the service policy information, or the first control response message sent by the gateway to the user plane of the gateway simultaneously carries the authentication result and the service policy information.
  • Step S115 may also be performed after step S111, that is, the authentication response message is sent first, and the service policy information is sent when the gateway terminal module of the user equipment passes the authentication.
  • Step S116 The gateway user plane receives the service policy information.
  • the gateway user plane receives the service policy information sent by the gateway control plane, and caches the service policy information.
  • step S116 can be performed simultaneously with step S112.
  • Step S117 The gateway user sends the service policy information to the user equipment.
  • the gateway user plane sends the service policy information to the user equipment by using the communication link.
  • the service policy information is encrypted and sent.
  • step S117 can be performed simultaneously with step S113.
  • Step S118 The user equipment receives the service policy information.
  • the user equipment receives the service policy information sent by the gateway user plane.
  • step S118 can be performed simultaneously with step S114.
  • Step S119 The user equipment performs service management according to the service policy information.
  • the user equipment acquires an application identifier of a current application, and searches for the current at least one network slice connection policy sent by the gateway user plane through the communication link.
  • the application identifier of the application identifies a corresponding network slice, and establishes a session connection and performs service access according to the found network slice.
  • the current application of the user equipment is an application identifier of the Internet of Things
  • the corresponding network slice that is, the corresponding access type and the access point name
  • the type initiates a session connection to the access point name and makes a business access after establishing a session connection.
  • the possible implementation manner allows the UE to independently select the network slice for session connection and service access, reduce the processing pressure of the core network device, and improve the processing capability of the UE.
  • the user equipment acquires an application identifier of a current application that accesses a data service, and is in the at least one service charging and control policy sent by the gateway user plane through the communication link.
  • the billing and control policy corresponding to the application identifier of the current application is searched, and the data traffic statistics and access control are performed according to the found billing and control policy.
  • the access control includes QoS control, and a re-recording (Remark) of a differentiated service code point (DSCP) value for the uplink service packet.
  • DSCP differentiated service code point
  • the current application of the user equipment accessing the data service is a certain social application, obtaining an application identifier of the social application, and searching for the billing corresponding to the application identifier of the social application in the at least one service charging and control policy. And controlling the policy, and performing data traffic statistics and access control according to the charging and control policy, that is, counting how much traffic is used by the social application, and controlling according to usage.
  • the user equipment periodically sends a usage report request message to the gateway user plane through the communication link, where the usage report request message includes feature attribute information of the user equipment, and application usage statistics.
  • the usage report request message is used to request the gateway user plane to generate an online or offline CDR and feed back a usage report confirmation message, where the usage report confirmation message is used to indicate that the gateway user plane has confirmed the application usage statistics.
  • the application usage statistics include application usage statistics, service identifiers, and rate groups.
  • the user equipment When the service policy information includes other types of policies, the user equipment performs corresponding service management according to a specific policy.
  • the user equipment acquires the communication address of the gateway user plane, establishes a communication link with the gateway user plane, and sends a gateway terminal module carrying the user equipment to the gateway user plane through the communication link.
  • the session connection establishment request message of the authentication information when receiving the session connection establishment request message, the gateway user plane sends an authentication request message to the gateway control plane, which is used to trigger the gateway control plane to request the authentication server to the gateway terminal of the user equipment.
  • the module performs authentication; the authentication server authenticates the gateway terminal module of the user equipment, and feeds the authentication result to the gateway control plane; when receiving the authentication result, the gateway control plane carries the authentication result in the authentication response.
  • the message is sent to the gateway user plane, and the gateway user plane carries the authentication result in the session connection establishment response message and sends the message to the user equipment. If the authentication result is successful, the gateway controls the gateway user plane to send the service policy information.
  • the service policy information is sent to the user equipment by the gateway user plane, and the user equipment is based on the service policy information. Line of business management, enabling the user equipment to manage their business can increase user engagement equipment, improve the user device management capabilities to the business.
  • FIG. 6 is a schematic diagram of communication of a service management method according to Embodiment 2 of the present invention.
  • the AAA shown in Embodiment 2 is an authentication server, and the method includes but is not limited to the following steps:
  • Step S201 The UE acquires GW-U IP Address for GW-T;
  • Step S202 The UE establishes a communication link with the GW-U.
  • Step S203 The UE sends a session connection establishment request message (authentication information of the GW-T of the UE) to the GW-U;
  • the session connection establishment request message further includes feature attribute information of the UE, and the feature attribute information of the UE includes information such as an MSISDN, an IMSI, and keyword information.
  • Step S204 The GW-U receives the session connection establishment request message.
  • Step S205 The GW-U sends a first authentication request message (authentication information of the GW-T of the UE) to the GW-C;
  • the first authentication request message further includes feature attribute information of the UE.
  • Step S206 The GW-C receives the first authentication request message.
  • Step S207 The GW-C sends a second authentication request message (authentication information of the GW-T of the UE) to the AAA;
  • the second authentication request message further includes feature attribute information of the UE.
  • Step S208 The AAA receives the second authentication request message, and performs authentication on the GW-T module of the UE.
  • Step S209 The AAA sends a second authentication response message (authentication result) to the GW-C;
  • the second authentication response message further includes feature attribute information of the UE.
  • Step S210 The GW-C receives the second authentication response message.
  • Step S211 The GW-C sends a first authentication response message (authentication result) to the GW-U.
  • the first authentication response message further includes feature attribute information of the UE.
  • Step S212 The GW-U receives the first authentication response message.
  • Step S213 The GW-U sends a session connection establishment response message (authentication result) to the UE;
  • the session connection establishment response message further includes feature attribute information of the UE.
  • Step S214 The UE receives a session connection establishment response message.
  • Step S215 If the authentication result is successful, the GW-C sends at least one network slice connection policy to the GW-U.
  • the at least one network slice connection policy is the initial at least one network slice connection policy in the first embodiment.
  • the network slice connection policy is used to indicate the session connection relationship between the application identifier and the network slice.
  • the network slice connection policy includes the correspondence between the application identifier, the access type, and the APN, and reflects the session connection relationship between the application identifier and the network slice, that is, which application is connected to which access point.
  • Step S216 The GW-U receives at least one network slice connection policy.
  • Step S217 The GW-U sends at least one network slice connection policy to the UE.
  • Step S218 The UE receives at least one network slice connection policy.
  • the UE receives at least one network slice connection policy and caches.
  • Step S219 The UE acquires an application identifier of the current application.
  • the current application is an SLA application, such as an AR application, an Internet of Things application, a telemedicine application, and an autopilot application, which is currently running by the UE.
  • the UE acquires an application identifier of the current application, that is, determines an application identifier of the running application.
  • the current number of apps may be one or more, depending on the situation.
  • Step S220 The UE searches for a network slice corresponding to the application identifier of the current application in at least one network slice connection policy.
  • the UE searches for the network slice corresponding to the application identifier of the current application in the at least one network slice connection policy, that is, determines the access type and the APN corresponding to the current application identifier.
  • Step S221 The UE establishes a session connection according to the found network slice and performs service access.
  • the UE establishes a session connection with the APN and performs service access to the APN according to the access type and the APN corresponding to the current application.
  • the UE selects a network slice corresponding to the application identifier of the current application to establish a session connection and performs service access according to at least one network slice connection policy sent by the GW-U, so as to implement dynamic and autonomous network segmentation of the UE. Connection strategy to improve UE participation and processing power.
  • FIG. 7 is a schematic diagram of communication of a service management method according to Embodiment 3 of the present invention.
  • the application scenario of the third embodiment is that the UE has obtained the initial at least one network slice connection policy, GW-C. Based on the adjustment of the network slice deployment architecture, the initial at least one network slice connection policy is updated.
  • the method includes but is not limited to the following steps:
  • Step S301 The GW-C updates the initial at least one network slice connection policy to obtain the updated at least one network slice connection policy.
  • GW-C adjusts the network slice corresponding to some application identifiers.
  • Step S302 The GW-C sends a session modification request message to the GW-U (at least one network slice connection policy after the update);
  • the session update modification message (Sx Session Modification Request) further includes feature attribute information of the UE.
  • Step S303 The GW-U receives the session modification request message.
  • Step S304 The GW-U sends a session connection update request message (at least one network slice connection policy after the update) to the UE;
  • the session connection update request message (Session Connection Update Request) further includes feature attribute information and an authentication result of the UE.
  • Step S305 The UE receives a session connection update request message.
  • the UE receives the session connection update request message, and caches the updated at least one network slice connection policy.
  • Step S306 The UE sends a session connection update response message to the GW-U.
  • the session connection update response message (Session Connection Update Response) is used to notify the GW-U that the UE has updated the initial at least one network slice connection policy.
  • Step S307 The UE acquires an application identifier of the current application.
  • Step S308 The UE searches for the network slice corresponding to the application identifier of the current application by using the updated at least one network slice connection policy.
  • Step S309 The UE establishes a session connection according to the found network slice and performs service access.
  • the updated at least one network slice connection policy is sent to the GW-U, and is sent by the GW-U to the UE.
  • the UE performs service management according to the updated at least one network slice connection policy.
  • FIG. 8 is a schematic diagram of communication of a service management method according to Embodiment 4 of the present invention, where the method includes but is not limited to the following steps:
  • Step S401 The UE acquires GW-U IP Address for GW-T;
  • Step S402 The UE establishes a communication link with the GW-U.
  • Step S403 The UE sends a session connection establishment request message (authentication information of the GW-T of the UE) to the GW-U.
  • Step S404 The GW-U receives the session connection establishment request message.
  • Step S405 The GW-U sends a first authentication request message (authentication information of the GW-T of the UE) to the GW-C;
  • Step S406 The GW-C receives the first authentication request message.
  • Step S407 The GW-C sends a second authentication request message (a session identifier of the authentication information of the GW-T of the UE) to the AAA;
  • Step S408 The AAA receives the second authentication request message.
  • Step S409 The AAA sends a second authentication response message (authentication result) to the GW-C;
  • Step S410 The GW-C receives the second authentication response message.
  • Step S411 The GW-C sends a first authentication response message (authentication result) to the GW-U;
  • Step S412 The GW-U receives the first authentication response message.
  • Step S413 The GW-U sends a session connection establishment response message (authentication result) to the UE;
  • Step S414 The UE receives a session connection establishment response message.
  • Step S415 If the authentication result is successful, the GW-C sends at least one service charging and control policy to the GW-U.
  • the service charging and control policy includes a correspondence between the application identifier and the service identifier, the rate group, and the QoS, and reflects the correspondence between the application identifier and the charging and control policy, that is, which application is used. Policies for billing and control.
  • Step S416 The GW-U receives at least one service charging and control policy.
  • Step S417 The GW-U sends at least one service charging and control policy to the UE.
  • Step S418 The UE receives at least one service charging and control policy.
  • Step S419 The UE acquires an application identifier of the current application that accesses the data service.
  • the current application of the access data service is an application that the UE is currently running and needs to connect to the network or use data traffic, and may include a social application, a shopping application, an audio application, a video application, and the like.
  • Step S420 The UE searches for the charging and control policy corresponding to the application identifier of the current application in at least one service charging and control policy.
  • Step S421 The UE performs data traffic statistics and access control according to the found charging and control policy.
  • the GW-U periodically sends a usage report request message, where the usage report request message includes feature attribute information of the UE and application usage statistics.
  • the usage report request message is used to request the GW-U to generate an online or offline CDR for the UE and to feed back the usage report acknowledgment message, the usage report acknowledgment message is used to indicate that the GW-U has confirmed the application usage statistics.
  • the application usage statistics include application usage statistics, service identifiers, and rate groups.
  • the UE determines the service charging and control policy corresponding to the application identifier of the current application according to the at least one service charging and control policy sent by the GW-U, and performs statistics and access control of the data traffic.
  • the UE performs statistics and access control on data traffic, and improves UE participation and processing capability.
  • FIG. 5 to FIG. 8 describes the case where the gateway user plane and the gateway control plane are separately deployed. If the gateway user plane and the gateway control plane are deployed together, the gateway user plane and the gateway control plane are used. The interaction process between the two can be an internal operation of the unified deployment device, and the portion shown by the dotted line can not be embodied in the communication diagram.
  • FIG. 9 is a schematic structural diagram of another user equipment according to an embodiment of the present invention.
  • the user equipment 501 shown in FIG. 9 includes an obtaining unit 5011, an establishing unit 5012, a sending unit 5013, a receiving unit 5014, and a management unit. 5015.
  • the obtaining unit 5011 is configured to obtain a communication address of the gateway user plane.
  • An establishing unit 5012 configured to establish, by using the communication address, a communication link with the gateway user plane;
  • a sending unit 5013 configured to send, by using the communication link, a session connection establishment request message to the gateway user plane, where the session connection establishment request message includes authentication information of a gateway terminal module of the user equipment, where the user equipment is The authentication information of the gateway terminal module is used by the gateway user plane to trigger the gateway control plane to request the authentication server to authenticate the gateway terminal module of the user equipment;
  • the receiving unit 5014 is configured to receive, by using the communications link, a session connection setup response message sent by the gateway user plane, where the session connection setup response message includes an authentication result;
  • the management unit 5015 is configured to perform service management according to the service policy information sent by the gateway user plane through the communication link, if the authentication result is successful.
  • the obtaining unit 5011 is configured to perform step S101 in the first embodiment shown in FIG. 5; the establishing unit 5012 is configured to perform step S102 in the first embodiment shown in FIG. 5; the sending unit 5013 Step S103 for performing the first embodiment shown in FIG. 5; the receiving unit 5014 is configured to execute steps S114 and S118 in the first embodiment shown in FIG. 5; the management unit 5015 is configured to execute the method shown in FIG. Step S119 in the first embodiment.
  • the acquiring unit 5011, the establishing unit 5012, and the managing unit 5015 may be the processor 1011 of the user equipment shown in FIG. 3; the sending unit 5013 and the receiving unit 5014 may be the user equipment shown in FIG. Transceiver 1012.
  • FIG. 10 is a schematic structural diagram of another gateway user plane according to an embodiment of the present invention.
  • the gateway user plane 601 shown in FIG. 10 includes a receiving unit 6011 and a sending unit 6012.
  • the receiving unit 6011 is configured to receive, by using a communication link, a session connection establishment request message sent by the user equipment, where the session connection establishment request message includes authentication information of the gateway terminal module of the user equipment, where the communication link is a link established by the user equipment with the gateway user plane established by the obtained communication address of the gateway user plane;
  • the sending unit 6012 is configured to send an authentication request message to the gateway control plane, where the authentication request message includes authentication information of the gateway terminal module of the user equipment, where the authentication request message is used to trigger the gateway control plane. Requesting an authentication server to authenticate the gateway terminal module of the user equipment;
  • the receiving unit 6011 is further configured to receive an authentication response message sent by the gateway control plane;
  • the sending unit 6012 is further configured to send a session connection establishment response message to the user equipment by using the communication link, where the authentication response message and the session connection establishment response message include an authentication result;
  • the receiving unit 6011 is further configured to: if the authentication result is successful, receive the service policy information sent by the gateway control plane;
  • the sending unit 6012 is further configured to send the service policy information to the user equipment by using the communication link, where the service policy information is used by the user equipment to perform service management according to the service policy information.
  • the receiving unit 6011 is configured to perform steps S104, S112, and S116 in the first embodiment shown in FIG. 5;
  • the sending unit 6012 is configured to perform steps S105 and S113 in the first embodiment shown in FIG. , S117.
  • the receiving unit 6011 and the sending unit 6012 may be the transceiver 1022 of the gateway user plane shown in FIG.
  • the steps of the method or algorithm described in connection with the disclosure of the embodiments of the present invention may be implemented in a hardware manner, or may be implemented by a processor executing software instructions.
  • the software instructions may be composed of corresponding software modules, which may be stored in a random access memory (RAM), a flash memory, a read only memory (ROM), an erasable programmable read only memory ( Erasable Programmable ROM (EPROM), Electrically Erasable Programmable Read Only Memory (EEPROM), registers, hard disk, removable hard disk, read-only optical disk (CD-ROM) or any other form of storage medium known in the art.
  • An exemplary storage medium is coupled to the processor to enable the processor to read information from, and write information to, the storage medium.
  • the storage medium can also be an integral part of the processor.
  • the processor and the storage medium can be located in an ASIC.
  • the ASIC can be located in the first management unit or the second management unit.
  • the processor and the storage medium may also exist as discrete components in the first management unit or the second management unit.
  • the functions described in the embodiments of the present invention may be implemented in hardware, software, firmware, or any combination thereof.
  • the functions may be stored in a computer readable medium or transmitted as one or more instructions or code on a computer readable medium.
  • Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a general purpose or special purpose computer.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Business, Economics & Management (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Power Engineering (AREA)
  • General Business, Economics & Management (AREA)
  • Multimedia (AREA)
  • Accounting & Taxation (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例公开了一种业务管理方法及其装置,其中方法包括:用户设备获取网关用户面的通信地址,通过通信地址建立与网关用户面之间的通信链路;通过通信链路向网关用户面发送会话连接建立请求消息,会话连接建立请求消息包括用户设备的网关终端模块的鉴权信息,用户设备的网关终端模块的鉴权信息用于网关用户面触发网关控制面请求鉴权服务器对用户设备的网关终端模块进行鉴权;通过通信链路接收网关用户面发送的会话连接建立响应消息,会话连接建立响应消息包括鉴权结果,并在鉴权结果为鉴权成功的情况下,根据网关用户面通过通信链路发送的业务策略信息进行业务管理。本发明实施例能够提高用户设备的参与度,提高用户设备对业务的管理能力。

Description

一种业务管理方法及其装置
本申请要求于2017年2月28日提交中国专利局、申请号为201710113550.8、发明名称为“一种业务管理方法及其装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信技术领域,尤其涉及一种业务管理方法及其装置。
背景技术
随着移动宽带网络上基于深度报文检测(Deep Packet Inspection,DPI)的业务感知能力对业务的控制和计费需求日益增多,网关通用分组无线服务(General Packet Radio Service,GPRS)支持节点(Gateway GPRS Support Node,GGSN)/分组数据网网关(Packet Data Network Gateway,PGW)/流量监测功能(Traffic Detection Function,TDF)等分组核心网设备需要通过自身的DPI、内容计费和业务控制功能实现对业务流的感知、计费和控制,也支持对业务流路径和承载的选择功能。
PGW是演进分组核心(Evolved Packet Core,EPC)网络中的功能实体,是第三代合作伙伴计划(3rd Generation Partnership Project,3GPP)接入网络和非3GPP接入网络之间的用户面锚点,是EPC核心网分组交换域与外部分组数据网(Packet Data Network,PDN)连接的接口,用于业务数据流的检测、计费与控制策略的执行。在第四代移动通信(4 th-Generation,4G)网络与第三代移动通信(3 rd-Generation,3G)网络中,PGW可作为策略和计费执行功能(Policy and Charging Enforcement Function,PCEF),通过Gx接口与策略和计费规则功能(Policy Charging and Rules Function,PCRF)相连。
GGSN在第二代移动通信(2 nd-Generation,2G)网络中,可作为PCEF。
在2G/3G/4G网络架构中,PCEF支持策略与计费控制(Policy and Charging Control,PCC)基本功能,通过PCRF下发的策略来实现策略与计费控制。PCEF支持PCRF/认证、授权、统计(Authentication Authorization Accounting,AAA)服务器下发的策略或本地配置策略,负责业务数据流检测、策略执行和基于流的计费处理。
图1a所示的2G/3G/4G网络架构下的网关设备的部署示意图,业务管理在PGW/GGSN上完成,例如所有业务的感知、策略匹配以及计费与控制策略的执行,用户设备(User Equipment,UE)在整个网络功能划分中,仅支持基于核心网控制面设备通过信令消息下发的业务流模板(Traffic Flow Template,TFT)、承载级标识和质量服务(Quality of Service,QoS)等相关信息,从而实现对上行业务流的承载选择和QoS策略。
图1b所示的用户面/控制面分离网络结构(例如第五代移动通信(5 th-Generation,5G)网络架构)下的网关设备的部署示意图,在骨干网部署集中式网关,包括服务网关(Service Gateway,SGW)和PGW的控制面的功能,例如基站间切换移动信令面锚点、跨运营商漫游计费、接入信令的处理、专有承载创建信令处理、地址池分配、用户接入鉴权控制等;在城域核心网部署分布式网关,包括SGW和PGW的用户面的功能,例如基站间切换移动数据描述、用户数据转发、用户计费信息收集、计费与控制策略执行、业务DPI处理等。集中式网 关/分布式网关共同完成服务网关(Serving GateWay,SGW)/PGW的功能。虽然5G网络架构实现了用户面/控制面的分离,但是UE仍然不参与业务的感知、策略匹配以及计费与控制策略的执行,也不参与网络切片场景下的动态切片选择策略。
随着新的应用和业务场景的演进,UE的种类、可支持的业务场景、与服务器侧的加密传输能力等均会出现跳跃性的发展,当前网络架构下,业务管理在核心网网关设备上完成的难度会越来越高。
发明内容
本发明实施例所要解决的技术问题在于,提供一种业务管理方法及其装置,实现了用户设备进行业务管理,能够提高用户设备的参与度,提高用户设备对业务的管理能力。
本发明实施例第一方面提供了一种业务管理方法,包括:
用户设备获取网关用户面的通信地址,通过所述通信地址建立与所述网关用户面之间的通信链路;
所述用户设备通过所述通信链路向所述网关用户面发送会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述用户设备的网关终端模块的鉴权信息用于所述网关用户面触发网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
所述用户设备通过所述通信链路接收所述网关用户面发送的会话连接建立响应消息,所述会话连接建立响应消息包括鉴权结果;
若所述鉴权结果为鉴权成功,则所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理。
本发明实施例第一方面,用户设备通过网关用户面的通信地址建立与网关用户面之间的通信链路,以便用户设备在通过鉴权的情况下,根据网关用户面发送的业务策略信息进行业务管理,实现了用户设备进行业务管理,能够提高用户设备的参与度,提高用户设备对业务的管理能力。
在一种可能实现的方式中,所述用户设备的网关终端模块的鉴权信息包括所述用户设备的网关终端模块的标识、关键字信息等信息,用于鉴权服务器对用户设备的网关终端模块进行鉴权。
在一种可能实现的方式中,所述业务策略信息包括当前的至少一个网络切片连接策略,所述当前的至少一个网络切片连接策略为初始的至少一个网络切片连接策略或更新后的至少一个网络切片连接策略,网络切片连接策略用于指示应用标识与网络切片之间的会话连接关系;
所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理的过程为:
所述用户设备获取当前应用的应用标识;
所述用户设备在所述网关用户面通过所述通信链路发送的所述当前的至少一个网络切片连接策略中查找所述当前应用的应用标识对应的网络切片;
所述用户设备根据查找到的所述网络切片建立会话连接并进行业务访问。
该种可能实现的方式,可以让用户设备自主选择网络切片进行会话连接和业务访问,减少核心网设备的处理压力,提高用户设备的处理能力。
在一种可能实现的方式中,所述当前的至少一个网络切片连接策略为所述更新后的至少一个网络切片连接策略;
所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理之前,通过所述通信链路向所述网关用户面发送会话连接更新响应消息,所述会话连接更新响应消息用于指示所述用户设备已更新所述初始的至少一个网络切片连接策略,以便所述网关用户面知晓所述用户设备的更新情况。
在一种可能实现的方式中,所述业务策略信息包括至少一个业务计费与控制策略,业务计费与控制策略用于指示应用标识与计费与控制策略之间的对应关系;
所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理的过程为:
所述用户设备获取访问数据业务的当前应用的应用标识;
所述用户设备在所述网关用户面通过所述通信链路发送的所述至少一个业务计费与控制策略中查找所述当前应用的应用标识对应的计费与控制策略;
所述用户设备根据查找到的所述计费与控制策略进行数据流量的统计和访问控制。
该种可能实现的方式,实现用户设备对当前应用的数据流量的统计和访问控制,提高用户设备的参与度以及处理能力。
在一种可能实现的方式中,所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理之后,通过所述通信链路周期性地向所述网关用户面发送使用报告请求消息,所述使用报告请求消息包括所述用户设备的特征属性信息、应用使用量统计信息,所述使用报告请求消息向所述网关用户面告知使用情况,用于请求所述网关用户面生成在线或离线话单并反馈使用报告确认消息,所述使用报告确认消息用于指示所述网关用户面已确认所述应用使用量统计信息。
在一种可能实现的方式中,用户设备根据接入网网关发送的附着响应消息获取网关用户面的通信地址,所述附着响应消息包括所述网关用户面的通信地址,根据附着响应消息获取,无需专门发送请求,实现简单,方便。
在一种可能实现的方式中,用户设备根据所述用户设备的预配置信息获取网关用户面的通信地址,所述预配置信息可由运营商在定制所述用户设备时配置,根据预配置信息获取,不会改变现有的激活流程。
在一种可能实现的方式中,用户设备根据用户选择的配置方式获取网关用户面的通信地址,即用户设备通过手工配置获取,不会改变现有的激活流程。
在一种可能实现的方式中,所述用户设备通过所述通信地址建立与所述网关用户面之间的通信链路之前,检测所述用户设备的网关终端模块、所述用户设备的权限以及网络运行环境是否满足预设条件,并在检测结果为是的情况下,通过所述通信地址建立与所述网关用户面之间的通信链路。通过预设条件判断用户设备是否能建立通信链路,以确保通信链路的安全性。
在一种可能实现的方式中,所述会话连接建立请求消息还包括所述用户设备的特征属性信息,所述用户设备的特征属性信息包括移动台综合业务数字网号码MSISDN和国际移动用户识别码IMSI,用于标识用于用户设备。
在一种可能实现的方式中,所述连接会话建立响应消息还包括所述用户设备的特征属性信息,以便将用户设备与鉴权结果相关联。
在一种可能实现的方式中,所述用户面设备的网关终端模块的鉴权信息、所述鉴权结果、所述业务策略信息、所述用户设备的特征属性信息以及所述应用使用量统计信息在所述通信链路中加密传输,防止被篡改,确保传输的安全性。
本发明实施例第二方面提供了一种业务管理方法,包括:
网关用户面通过通信链路接收用户设备发送的会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述通信链路为所述用户设备通过获取的网关用户面的通信地址建立的与所述网关用户面之间的链路;
所述网关用户面向网关控制面发送鉴权请求消息,所述鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息,所述鉴权请求消息用于触发所述网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
所述网关用户面接收所述网关控制面发送的鉴权响应消息,并通过所述通信链路向所述用户设备发送会话连接建立响应消息,所述鉴权响应消息、所述会话连接建立响应消息包括鉴权结果;
若所述鉴权结果为鉴权成功,则所述网关用户面接收所述网关控制面发送的业务策略信息,并通过所述通信链路向所述用户设备发送所述业务策略信息,所述业务策略信息用于所述用户设备根据所述业务策略信息进行业务管理。
本发明实施例第二方面,在用户设备通过鉴权的情况下,通过与用户设备建立的通信链路向用户设备发送业务策略信息,由用户设备根据业务策略信息进行业务管理,可以减少核心网设备的业务管理压力,提高用户设备的业务管理能力。
在一种可能实现的方式中,所述业务策略信息包括当前的至少一个网络切片连接策略,所述当前的至少一个网络切片连接策略为初始的至少一个网络切片连接策略或更新后的至少一个网络切片连接策略,网络切片连接策略用于指示应用标识与网络切片之间的会话连接关系,以实现用户设备自主选择网络切片进行会话连接和业务访问,减少核心网设备的处理压力,提高用户设备的处理能力。
在一种可能实现的方式中,所述当前的至少一个网络切片连接策略为所述更新后的至少一个网络切片连接策略时,所述网关用户面通过所述通信链路接收所述用户设备发送的会话连接更新响应消息,所述会话连接更新响应消息用于指示所述用户设备已更新所述初始的至少一个网络切片连接策略,以获知所述用户设备的更新情况。
在一种可能实现的方式中,所述业务策略信息包括至少一个业务计费与控制策略,业务计费与控制策略用于指示应用标识与计费与控制策略之间的对应关系,以实现用户设备对当前应用的数据流量的统计和访问控制,提高用户设备的参与度以及处理能力。
在一种可能实现的方式中,所述网关用户面通过所述通信链路接收所述用户设备周期性发送的使用报告请求消息,所述使用报告请求消息包括所述用户设备的特征属性信息、应用使用量统计信息;根据所述使用报告请求消息生成在线或离线话单并通过所述通信链路向所述用户设备反馈使用报告确认消息,所述使用报告确认消息用于指示所述网关用户面已确认所述应用使用量统计信息。
在一种可能实现的方式中,所述会话连接建立请求消息还包括所述用户设备的特征属性信息,所述用户设备的特征属性信息包括MSISDN和IMSI,用于标识用户设备。
在一种可能实现的方式中,所述鉴权响应消息、所述连接会话建立响应消息还包括所述用户设备的特征属性信息,用于将用户设备与鉴权结果相关联。
在一种可能实现的方式中,所述用户面设备的网关终端模块的鉴权信息、所述鉴权结果、所述业务策略信息、所述用户设备的特征属性信息以及所述应用使用量统计信息在所述通信链路中加密传输,防止被篡改,确保传输的安全性。
本发明实施例第三方面提供了一种用户设备,包括:
获取单元,用于获取网关用户面的通信地址;
建立单元,用于通过所述通信地址建立与所述网关用户面之间的通信链路;
发送单元,用于通过所述通信链路向所述网关用户面发送会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述用户设备的网关终端模块的鉴权信息用于所述网关用户面触发网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
接收单元,用于通过所述通信链路接收所述网关用户面发送的会话连接建立响应消息,所述会话连接建立响应消息包括鉴权结果;
管理单元,用于若所述鉴权结果为鉴权成功,则根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理。
本发明实施例第三方面提供的用户设备用于实现本发明实施例第一方面提供的业务管理方法中用户设备所执行的功能。
本发明实施例第四方面提供了一种网关用户面,包括:
接收单元,用于通过通信链路接收用户设备发送的会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述通信链路为所述用户设备通过获取的网关用户面的通信地址建立的与所述网关用户面之间的链路;
发送单元,用于向网关控制面发送鉴权请求消息,所述鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息,所述鉴权请求消息用于触发所述网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
所述接收单元,还用于接收所述网关控制面发送的鉴权响应消息;
所述发送单元,还用于通过所述通信链路向所述用户设备发送会话连接建立响应消息,所述鉴权响应消息、所述会话连接建立响应消息包括鉴权结果;
所述接收单元,还用于若所述鉴权结果为鉴权成功,则接收所述网关控制面发送的业务策略信息;
所述发送单元,还用于通过所述通信链路向所述用户设备发送所述业务策略信息,所述业务策略信息用于所述用户设备根据所述业务策略信息进行业务管理。
本发明实施例第四方面提供的网关用户面用于实现本发明实施例第二方面提供的业务管理方法中网关用户面所执行的功能。
本发明实施例第五方面提供了另一种用户设备,包括处理器和收发器,
所述处理器用于获取网关用户面的通信地址,通过所述通信地址建立与所述网关用户面之间的通信链路;
所述收发器用于通过所述通信链路向所述网关用户面发送会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述用户设备的网关终端模块的鉴权信息用于所述网关用户面触发网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
所述收发器还用于通过所述通信链路接收所述网关用户面发送的会话连接建立响应消息, 所述会话连接建立响应消息包括鉴权结果;
若所述鉴权结果为鉴权成功,则所述处理器还用于根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理。
本发明实施例第五方面提供的用户设备用于实现本发明实施例第一方面提供的业务管理方法中用户设备所执行的功能。
本发明实施例第六方面提供了另一种网关用户面,包括处理器和收发器,
所述收发器用于通过通信链路接收用户设备发送的会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述通信链路为所述用户设备通过获取的网关用户面的通信地址建立的与所述网关用户面之间的链路;
所述收发器还用于向网关控制面发送鉴权请求消息,所述鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息,所述鉴权请求消息用于触发所述网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
所述收发器还用于接收所述网关控制面发送的鉴权响应消息,并通过所述通信链路向所述用户设备发送会话连接建立响应消息,所述鉴权响应消息、所述会话连接建立响应消息包括鉴权结果;
若所述鉴权结果为鉴权成功,则所述收发器还用于接收所述网关控制面发送的业务策略信息,并通过所述通信链路向所述用户设备发送所述业务策略信息,所述业务策略信息用于所述用户设备根据所述业务策略信息进行业务管理。
本发明实施例第六方面提供的网关用户面用于实现本发明实施例第二方面提供的业务管理方法中网关用户面所执行的功能。
在本发明实施例中,用户设备获取网关用户面的通信地址,建立与网关用户面之间的通信链路,并通过通信链路向网关用户面发送携带用户设备的网关终端模块的鉴权信息的会话连接建立请求消息;网关用户面在接收到会话连接建立请求消息时,向网关控制面发送鉴权请求消息,用于触发网关控制面请求鉴权服务器对用户设备的网关终端模块进行鉴权;鉴权服务器对用户设备的网关终端模块进行鉴权,并将鉴权结果反馈至网关控制面;网关控制面在接收到鉴权结果时,将鉴权结果携带在鉴权响应消息中发送至网关用户面,由网关用户面将鉴权结果携带在会话连接建立响应消息中发送至用户设备;若鉴权结果为鉴权成功,则网关控制面向网关用户面发送业务策略信息,由网关用户面将业务策略信息发送至用户设备,用户设备根据业务策略信息进行业务管理,从而实现了用户设备进行业务管理,能够提高用户设备的参与度,提高用户设备对业务的管理能力。
附图说明
为了更清楚地说明本发明实施例或背景技术中的技术方案,下面将对本发明实施例或背景技术中所需要使用的附图进行说明。
图1a是2G/3G/4G网络架构下的网关设备的部署示意图;
图1b是用户面/控制面分离网络结构下的网关设备的部署示意图;
图2是本发明实施例提供的一种业务管理系统的结构示意图;
图3是本发明实施例提供的一种用户设备的结构示意图;
图4是本发明实施例提供的一种网关用户面的结构示意图;
图5是本发明实施例一提供的业务管理方法的通信示意图;
图6是本发明实施例二提供的业务管理方法的通信示意图;
图7是本发明实施例三提供的业务管理方法的通信示意图;
图8是本发明实施例四提供的业务管理方法的通信示意图;
图9是本发明实施例提供的另一种用户设备的结构示意图;
图10是本发明实施例提供的另一种网关用户面的结构示意图。
具体实施方式
下面结合本发明实施例中的附图对本发明实施例进行描述。
请参见图2,图2是本发明实施例提供的一种业务管理系统的结构示意图,该业务管理系统包括用户设备(User Equipment,UE)、接入网(Radio Access Network,RAN)、网关控制面(Gateway Control Plane,GW-C)、网关用户面(Gateway User Plane,GW-U)1、网关用户面2、互联网(Internet)和增强现实(Augmented Reality,AR)服务器(即图2所示的Enterprise)。需要说明的是,图2所示的各元素的形态和数量并不构成对本发明实施例的限定。
其中,UE具有网关终端(Gateway Terminal,GW-T)模块,该模块可以通过数据通信链路实现与GW-U之间的鉴权、策略交互、统计信息上报等功能,以便协助核心网侧实现未来网络切片的动态部署和选择、应用数据业务的统计上报和策略控制等。
接入网可以是2G/3G/4G网络架构下的接入网,也可以是用户面/控制面分离网络结构下的接入网,还可以是未来通信网络架构下的接入网。
网关控制面是网关控制面功能实体,网关用户面是网关用户面功能实体。GW-C可以是服务网关控制面(Service Gateway-Control Plane,SGW-C)或分组数据网网关控制面(Packet Data Network Gateway-Control Plane,PGW-C),还可以融合核心网设备中控制面的功能,例如包括SGW和PGW的控制面的功能;GW-U可以是服务网关用户面(Service Gateway-User Plane,SGW-U)或分组数据网网关用户面(Packet Data Network Gateway-User Plane,PGW-U),还可以融合了核心网设备中用户面的功能,例如包括SGW和PGW的用户面的功能。GW-C和GW-U可以合一部署,也可以分开部署。进一步地,针对不同的应用场景,GW-U可以不同,例如图2所示的GW-U 1应用在访问互联网的场景,GW-U 2应用在访问AR业务的场景。
AR就是利用技术在现实的基础上增加内容,它所用的核心技术包括现实物体的识别,地理位置定位,以及根据场景不同所需要的即时演算等等。AR服务器针对不同类型的AR业务可能会有所不同。
目前,UE访问互联网时通过图2所示的虚线1和2实现,虚线1表示UE建立公网业务会话,虚线2表示GW-C通知GW-U 1建立Sx承载上下文;UE访问AR业务时通过图2所示的虚线6和7实现,虚线6表示UE建立AR业务会话,虚线7表示GW-C通知GW-U 2建立Sx承载上下文。其中,Sx表示GW-C与GW-U之间的会话连接。可见,目前UE访问业务需要通过GW-C和GW-U实现。
在本发明实施例中,UE可建立与GW-U之间的数据通信链路,具体为UE的GW-T模块可建立与GW-U之间的数据通信链路,UE在建立该数据通信链路后,直接通过GW-U进行业务访问。结合图2所示的示意图,实线4表示UE通过该数据通信链路完成对GW-T模块的鉴权过程;实线3表示UE通过GW-U 1访问互联网;实线5表示GW-U 1通过该数据通信链路向UE下发业务策略,业务策略可以包括网络切片连接策略、计费与控制策略等;实线8表示UE通过GW-U 2访问AR业务。
图2所示的访问互联网和AR业务的场景仅用于举例,实际应用中,图2还可以包括物联网(Internet of Things,IoT)、远程医疗、自动驾驶等业务对应的服务器和GW-U,实现UE对IoT、远程医疗、自动驾驶等业务的访问。AR、IoT、远程医疗、自动驾驶分别对应不同的服务等级协议(Service-Level Agreement,SLA)。
本发明实施例中的用户设备可以是接入终端、用户单元、用户站、移动站、移动台、远方站、远程终端、移动设备、用户终端、终端、无线通信设备、用户代理或用户装置。接入终端可以是蜂窝电话、无绳电话、会话启动协议(Session Initiation Protocol,SIP)电话、无线本地环路(Wireless Local Loop,WLL)站、个人数字处理(Personal Digital Assistant,PDA)、具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它处理设备、车载设备、可穿戴设备,未来无线通信网络中的用户设备等。需要说明的是,本发明实施例中的用户设备具有GW-T模块,该模块可以是设计在用户设备中的一个芯片或硬件模块,也可以是安装在用户设备中的一个系统应用程序(在用户设备未被root的情况下,该应用程序不可删除),视具体情况而定。换言之,本发明实施例中的用户设备可以为运营商提供的定制用户设备。
请参见图3,图3是本发明实施例提供的一种用户设备的结构示意图,用户设备101包括处理器1011和收发器1012,实际应用中,可能还包括其它部分,例如电源、显示模块、传感模块、音频模块等。其中,处理器1011可以是控制器、中央处理器(Central Processing Unit,CPU),通用处理器,数字信号处理器(Digital Signal Processor,DSP),专用集成电路(Application-Specific Integrated Circuit,ASIC),现场可编程门阵列(Field Programmable Gate Array,FPGA)或者其他可编程逻辑器件、晶体管逻辑器件、硬件部件或者其任意组合。其可以实现或执行结合本发明实施例所描述的各种示例性的逻辑方框,模块和电路。处理器1011也可以是实现计算功能的组合,例如包含一个或多个微处理器组合,DSP和微处理器的组合等等。收发器1012用于实现用户设备101与基站、卫星等网络设备之间的通信或数据传输,还用于实现用户设备101与其它用户设备之间的通信或数据传输,应用于本发明实施例中,收发器1012用于用户设备101与网关用户面之间的通信或数据传输。若GW-T模块是设计在用户设备中的一个芯片或硬件模块,那么图3所示的用户设备101还包括GW-T模块1013,用于实现与网关用户面之间的鉴权、策略交互、统计信息上报等功能,以便协助核心网侧实现未来网络切片的动态部署和选择、应用数据业务的统计上报和策略控制。GW-T模块1013可能集成在处理器1011或收发器1012中,也可能是独立部署的一个模块。
本发明实施例中的网关用户面实现SGW和/或PGW等核心网设备的用户面功能,请参见图4,图4是本发明实施例提供的一种网关用户面的结构示意图,网关用户面102包括处理器1021和收发器1022。其中,处理器1021用于实现或执行结合本发明实施例所描述的各种示例性的逻辑方框,模块和电路。收发器1022用于实现网关用户面102与网关控制面、用户设备和其它核心网设备之间的通信或数据传输。网关用户面102包括针对用户设备的GW-T模块的通信地址(GW-U IP Address for GW-T),实际应用中网关用户面包括多个通信地址,GW-U IP Address for GW-T用于与用户设备的GW-T模块建立数据通信链路,以便网关用户面102向用户设备下发业务策略信息。图4所示的网关用户面的结构示意图也可以为网关控制面的结构示意图。
本发明实施例中还涉及鉴权服务器,即AAA服务器,用于对用户设备的GW-T模块进行鉴权。
下面将结合附图5-附图8对本发明实施例提供的业务管理方法进行详细的介绍。需要说明的是,附图5-附图8从用户设备与网关用户面交互的角度进行介绍。其中,附图5所示的实施例一对业务管理方法进行总体介绍,附图6和附图7所示的实施例二和实施例三对AR业务的网络切片连接进行介绍,附图8所示的实施例四对数据业务的计费与控制进行介绍。
请参见图5,图5是本发明实施例一提供的业务管理方法的通信示意图,该方法包括但不限于如下步骤:
步骤S101:用户设备获取网关用户面的通信地址;
具体地,用户设备在获取网关用户面的通信地址之前,发起激活请求消息,按照3GPP标准文档23401中定义的流程发起激活。以网络架构中存在SGW和PGW为例,发起激活请求消息的具体过程为:UE向RAN发送附着请求(Attach Request);RAN在接收到Attach Request时,向移动性管理实体(Mobility Management Entity,MME)发送Attach Request;MME在接收到Attach Request时,向SGW-C发送建立会话请求(Create Session Request);SGW-C在接收到Create Session Request时,向PGW-C发送Create Session Request;PGW-C在接收到Create Session Request时,向SGW-C发送建立会话响应(Create Session Response);SGW-C在接收到Create Session Response时,向MME发送Create Session Response;MME在接收到Create Session Response时,向RAN发送附着同意(Attach Accept);RAN在接收到Attach Accept时,向UE发送Attach Accept,完成激活。在上述过程中,SGW-C通过向SGW-U发送Sx会话建立请求(Session Establishment Request)以及SGW-U向SGW-C发送的Sx会话建立响应(Session Establishment Response)来建立SGW-C与SGW-U之间的Sx会话连接,同理可建立PGW-C与PGW-U之间的Sx会话连接。对于存在用户面/控制面分离的网络架构,MME向GW-C发送Create Session Request;GW-C在接收到Create Session Request时,向MME发送Create Session Response;GW-C也可建立与GW-U之间的Sx会话连接。
在一种可能实现的方式中,所述用户设备根据接入网网关发送的附着响应消息获取网关用户面的通信地址,所述附着响应消息包括所述网关用户面的通信地址。即所述用户设备通过RAN发送的Attach Accept来获取网关用户面的通信地址,具体为获取GW-U IP Address for GW-T。以网络架构中存在SGW和PGW为例PGW-C向SGW-C发送的Create Session Response中携带GW-U IP Address for GW-T,可通过在Create Session Response中增加一个信元来表示GW-U IP Address for GW-T;SGW-C向MME发送的Create Session Response中携带GW-U IP Address for GW-T;MME向RAN发送的Attach Accept中携带GW-U IP Address for GW-T;RAN向UE发送Attach Accept中携带GW-U IP Address for GW-T,从而实现UE通过RAN发送的Attach Accept来获取GW-U IP Address for GW-T。
在一种可能实现的方式中,所述用户设备根据所述用户设备的预配置信息获取网关用户面的通信地址。所述预配置信息包括所述网关用户面的通信地址,具体包括GW-U IP Address for GW-T。所述预配置信息可由运营商在定制所述用户设备时配置,也可由所述用户设备的制造厂商配置,还可以由所述用户设备的系统配置,在此不作限定。
在一种可能实现的方式中,所述用户设备根据用户选择的配置方式获取网关用户面的通信地址。所述用户设备为用户提供几种配置方式,根据用户选择的配置方式获取GW-U IP Address for GW-T,即通过手工配置获取。
步骤S102:所述用户设备建立与所述网关用户面之间的通信链路;
具体地,所述用户设备在获取所述网关用户面的通信地址之后,可建立与所述网关用户面之间的通信链路,所述通信链路为数据通信链路,可用于所述网关用户面向所述用户设备发送业务策略信息,所述用户设备向所述网关用户面发送使用报告请求消息等。为了保证传输的安全性,防止传输的内容被篡改,所述通信链路可对传输的内容进行加密,或所述通信链路传输加密的内容。
在建立所述通信链路之前,所述用户设备检测所述用户设备的网关终端模块、所述用户设备的权限以及网络运行环境是否满足预设条件,并在检测结果为是的情况下,建立所述通信链路。其中预设条件包括UE具有GW-T模块、UE未被root、操作权限已获取、网络运行环境安全。若所述用户设备不具有网关终端模块、所述用户设备被root、未获取操作权限、网络运行环境不安全中至少一种情况存在,则确定不满足所述预设条件。其中,UE被root指UE的最高权限被更改,未被root指UE的权限与出厂的权限一致,最高权限未被更改。获取操作权限指UE可操作,能正常使用。
可选地,所述通信链路为超文本传输安全协议(Hyper Text Transfer Protocol over Secure Socket Layer,HTTPS)传输通道,所述用户设备采用预设的密钥发起与GW-U IP Address for GW-T的HTTPS连接请求,所述网关用户面在接收到该请求时,通过所述预设的密钥对其解密,并向所述用户设备发送HTTPS连接响应,从而实现所述用户设备与所述网关用户面之间的通信链路的建立。
可选地,所述通信链路为其它安全套接层(Secure Sockets Layer,SSL)传输通道,所述用户设备采用预设的密钥发起与GW-U IP Address for GW-T的连接请求,所述网关用户面在接收到该请求时,通过所述预设的密钥对其解密,并向所述用户设备发送连接响应,从而实现所述用户设备与所述网关用户面之间的通信链路的建立。
上述的HTTPS传输通道、SSL传输通道均为安全可靠的传输通道,还可以采用其它安全可靠的传输通道。
步骤S103:所述用户设备通过所述通信链路向所述网关用户面发送会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息;
具体地,所述用户设备通过所述通信链路向所述网关用户面发送会话连接建立请求消息(Session Connection Create Request),所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息。所述用户设备的网关终端模块的鉴权信息包括GW-T模块的标识、关键字信息(授权/鉴权关键字)等信息,用于所述网关用户面触发网关控制面请求鉴权服务器对所述用户设备的GW-T模块进行鉴权。
所述会话连接建立请求消息还包括所述用户设备的特征属性信息,所述用户设备的特征属性信息包括移动台综合业务数字网号码(Mobile Subscriber International Integrated Service Digital Network/Public Switched Telephone Network number,MSISDN)和国际移动用户识别码(International Mobile Subscriber Identification Number,IMSI)等信息。其中,MSISDN和IMSI用于标识所述用户设备。
所述用户设备的网关终端模块的鉴权信息可所述用户设备的特征属性信息与绑定,是否绑定由运行商设定。可选地,所述用户设备采用所述预设的密钥对所述会话连接建立请求消息进行加密,或采用所述预设的密钥对所述用户设备的网关终端模块的鉴权信息、所述用户设备的特征属性信息进行加密,以保证传输的安全性。
步骤S104:所述网关用户面通过所述通信链路接收所述会话连接建立请求消息;
具体地,所述网关用户面通过所述通信链路接收所述会话连接建立请求消息,对所述会话连接建立请求消息进行解析,获取所述用户设备的网关终端模块的鉴权信息。若所述会话连接建立请求消息采用所述预设的密钥进行加密,则所述网关用户面采用所述预设的密钥对所述会话连接建立请求消息进行解密,解析所述用户设备的网关终端模块的鉴权信息;若所述会话连接建立请求消息还包括所述用户设备的特征属性信息,则对其进行解析。若所述用户设备的网关终端模块的鉴权信息、所述用户设备的特征属性信息采用所述预设的密钥进行加密,则所述网关用户面采用所述预设的密钥进行解密,解析。
步骤S105:所述网关用户面向网关控制面发送第一鉴权请求消息,所述第一鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息;
具体地,在所述网关用户面与所述网关控制面分开部署的情况下,所述第一鉴权请求消息还包括会话标识,所述会话标识为Sx会话的会话标识,用于标识建立Sx会话的网关用户面和网关控制面。在图2所示的系统架构中,可能存在多个网关用户面、多个网关控制面,Sx会话标识用于区分与网关控制面相连接的不同的网关用户面。
所述第一鉴权请求消息还包括所述用户设备的特征属性信息。
步骤S106:所述网关控制面接收所述第一鉴权请求消息;
具体地,所述网关控制面接收所述第一鉴权请求消息,对所述第一鉴权请求消息进行解析。
步骤S107:所述网关控制面向鉴权服务器发送第二鉴权请求消息,所述第二鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息;
具体地,所述网关控制面根据解析结果构造第二鉴权请求消息,并向鉴权服务器发送所述第二鉴权请求消息,所述第二鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息。在所述网关用户面与所述网关控制面分开部署的情况下,所述第二鉴权请求消息还包括所述会话标识。
所述第二鉴权请求消息还包括所述用户设备的特征属性信息。
步骤S108:所述鉴权服务器接收所述第二鉴权请求消息,并对所述用户设备的网关终端模块进行鉴权;
具体地,所述鉴权服务器接收所述第二鉴权请求消息,对所述第二鉴权请求消息进行解析,得到所述用户设备的网关终端模块的鉴权信息,根据所述用户设备的网关终端模块的鉴权信息对所述用户设备的网关终端模块进行鉴权。
步骤S109:所述鉴权服务器向所述网关控制面发送第二鉴权响应消息,所述第二鉴权响应消息包括鉴权结果;
具体地,所述鉴权服务器对所述用户设备的网关终端模块进行鉴权得到鉴权结果,所述鉴权结果为鉴权成功或鉴权失败。在得到所述鉴权结果之后,所述鉴权服务器向所述网关控制面发送第二鉴权响应消息,所述第二鉴权响应消息包括所述鉴权结果。
所述第二鉴权响应消息还包括所述用户设备的特征属性信息。
步骤S110:所述网关控制面接收所述第二鉴权响应消息;
具体地,所述网关控制面接收所述鉴权服务器发送的所述第二鉴权响应消息。
步骤S111:所述网关控制面向所述网关用户面发送第一鉴权响应消息,所述第一鉴权响应消息包括所述鉴权结果;
具体地,不管鉴权成功还是鉴权失败,所述网关控制面均向所述网关用户面发送携带所 述鉴权结果的第一鉴权响应消息。
所述第一鉴权响应消息还包括所述用户设备的特征属性信息。
步骤S112:所述网关用户面接收所述第一鉴权响应消息;
具体地,在所述网关用户面与所述网关控制面分开部署的情况下,所述网关用户面通过Sx会话连接接收所述网关控制面发送的所述第一鉴权响应消息。
步骤S113:所述网关用户面向所述用户设备发送会话连接建立响应消息,所述会话连接建立响应消息包括所述鉴权结果;
具体地,所述网关用户面通过所述通信链路向所述用户设备发送会话连接建立响应消息,所述会话连接建立响应消息包括所述鉴权结果,告知所述用户设备是否通过鉴权。所述鉴权结果或所述会话连接建立响应消息加密后发送。
所述会话连接建立响应消息还包括所述用户设备的特征属性信息。
步骤S114:所述用户设备接收所述会话连接建立响应消息;
具体地,所述用户设备通过所述通信链路接收所述网关用户面发送的所述会话连接建立响应消息。
步骤S115:若所述鉴权结果为鉴权成功,则所述网关控制面向所述网关用户面发送业务策略信息;
具体地,在所述用户设备的网关终端模块通过鉴权的情况下,所述网关控制面才向所述网关用户面发送业务策略信息。所述业务策略信息可携带在所述第一鉴权响应消息中,也可不携带在所述第一鉴权响应消息中,即在发送了所述第一鉴权响应消息之后,发送所述业务策略信息。
在一种可能实现的方式中,所述业务策略信息包括当前的至少一个网络切片连接策略,所述当前的至少一个网络切片连接策略为初始的至少一个网络切片连接策略或更新后的至少一个网络切片连接策略,网络切片连接策略用于指示应用标识与网络切片之间的会话连接关系。网络切片连接策略包括应用标识、接入类型、接入点名称(Access Point Name,APN)三者之间的对应关系,反映应用标识与网络切片之间的会话连接关系,即哪个应用通过哪种接入类型连接哪个接入点。
在一种可能实现的方式中,所述业务策略信息包括至少一个业务计费与控制策略,业务计费与控制策略用于指示应用标识与计费与控制策略之间的对应关系。业务计费与控制策略包括应用标识与业务标识、费率组、服务质量(Quality of Service,QoS)等信息之间的对应关系,反映应用标识与计费与控制策略之间的对应关系,即哪个应用通过哪种策略进行计费与控制。
上述业务策略信息所包括的两种类型的策略并不构成对本发明实施例一的限定,上述业务策略信息还可以包括其它类型的策略。
需要说明的是,步骤S115可与步骤S111同时执行,即在所述用户设备的网关终端模块通过鉴权的情况下,所述网关控制面向所述网关用户面同时发送所述第一鉴权响应消息和所述业务策略信息,或者所述网关控制面向所述网关用户面发送的所述第一鉴权响应消息同时携带所述鉴权结果和所述业务策略信息。步骤S115也可在步骤S111之后执行,即先发送所述鉴权响应消息,并在所述用户设备的网关终端模块通过鉴权的情况下,发送所述业务策略信息。
步骤S116:所述网关用户面接收所述业务策略信息;
具体地,在所述鉴权结果为鉴权成功的情况下,所述网关用户面接收所述网关控制面发送的所述业务策略信息,并对所述业务策略信息进行缓存。
同理,在所述鉴权结果为鉴权成功的情况下,步骤S116可与步骤S112同时执行。
步骤S117:所述网关用户面向所述用户设备发送所述业务策略信息;
具体地,所述网关用户面通过所述通信链路向所述用户设备发送所述业务策略信息。所述业务策略信息加密后发送。
同理,在所述鉴权结果为鉴权成功的情况下,步骤S117可与步骤S113同时执行。
步骤S118:所述用户设备接收所述业务策略信息;
具体地,在所述鉴权结果为鉴权成功的情况下,所述用户设备才会接收到所述网关用户面发送的所述业务策略信息。
同理,在所述鉴权结果为鉴权成功的情况下,步骤S118可与步骤S114同时执行。
步骤S119:所述用户设备根据所述业务策略信息进行业务管理;
在一种可能实现的方式中,所述用户设备获取当前应用的应用标识,并在所述网关用户面通过所述通信链路发送的所述当前的至少一个网络切片连接策略中查找所述当前应用的应用标识对应的网络切片,根据查找到的所述网络切片建立会话连接并进行业务访问。例如,所述用户设备当前应用为物联网的应用标识,根据所述当前的至少一个网络切片连接策略中查找对应的网络切片,即对应的接入类型和接入点名称,并通过该接入类型发起对该接入点名称的会话连接,并在建立会话连接之后进行业务访问。该种可能实现的方式,可以让UE自主选择网络切片进行会话连接和业务访问,减少核心网设备的处理压力,提高UE的处理能力。
在一种可能实现的方式中,所述用户设备获取访问数据业务的当前应用的应用标识,并在所述网关用户面通过所述通信链路发送的所述至少一个业务计费与控制策略中查找所述当前应用的应用标识对应的计费与控制策略,根据查找到的所述计费与控制策略进行数据流量的统计和访问控制。其中,访问控制包括QoS控制、对上行业务报文进行差分服务代码点(Differentiated Services Code Point,DSCP)值的重记录(Remark)等等。例如,所述用户设备访问数据业务的当前应用为某个社交应用,获取该社交应用的应用标识,并在所述至少一个业务计费与控制策略中查找该社交应用的应用标识对应的计费与控制策略,并根据该计费与控制策略进行数据流量的统计和访问控制,即统计该社交应用使用了多少流量,并根据使用情况进行控制。统计之后,所述用户设备通过所述通信链路周期性地向所述网关用户面发送使用报告请求消息,所述使用报告请求消息包括所述用户设备的特征属性信息、应用使用量统计信息,所述使用报告请求消息用于请求所述网关用户面生成在线或离线话单并反馈使用报告确认消息,所述使用报告确认消息用于指示所述网关用户面已确认所述应用使用量统计信息。其中,所述应用使用量统计信息包括应用使用量统计结果、业务标识、费率组。
在所述业务策略信息包括其它类型的策略时,所述用户设备根据具体的策略进行相应的业务管理。
在图5所示的实施例一中,用户设备获取网关用户面的通信地址,建立与网关用户面之间的通信链路,并通过通信链路向网关用户面发送携带用户设备的网关终端模块的鉴权信息的会话连接建立请求消息;网关用户面在接收到会话连接建立请求消息时,向网关控制面发送鉴权请求消息,用于触发网关控制面请求鉴权服务器对用户设备的网关终端模块进行鉴权;鉴权服务器对用户设备的网关终端模块进行鉴权,并将鉴权结果反馈至网关控制面;网关控 制面在接收到鉴权结果时,将鉴权结果携带在鉴权响应消息中发送至网关用户面,由网关用户面将鉴权结果携带在会话连接建立响应消息中发送至用户设备;若鉴权结果为鉴权成功,则网关控制面向网关用户面发送业务策略信息,由网关用户面将业务策略信息发送至用户设备,用户设备根据业务策略信息进行业务管理,从而实现了用户设备进行业务管理,能够提高用户设备的参与度,提高用户设备对业务的管理能力。
请参见图6,图6是本发明实施例二提供的业务管理方法的通信示意图,实施例二所示的AAA即为鉴权服务器,该方法包括但不限于如下步骤:
步骤S201:UE获取GW-U IP Address for GW-T;
步骤S202:UE建立与GW-U之间的通信链路;
步骤S203:UE向GW-U发送会话连接建立请求消息(UE的GW-T的鉴权信息);
其中,会话连接建立请求消息还包括UE的特征属性信息,UE的特征属性信息包括MSISDN、IMSI、关键字信息等信息。
步骤S204:GW-U接收会话连接建立请求消息;
步骤S205:GW-U向GW-C发送第一鉴权请求消息(UE的GW-T的鉴权信息);
其中,第一鉴权请求消息还包括UE的特征属性信息。
步骤S206:GW-C接收第一鉴权请求消息;
步骤S207:GW-C向AAA发送第二鉴权请求消息(UE的GW-T的鉴权信息);
其中,第二鉴权请求消息还包括UE的特征属性信息。
步骤S208:AAA接收第二鉴权请求消息,并对UE的GW-T模块进行鉴权;
步骤S209:AAA向GW-C发送第二鉴权响应消息(鉴权结果);
其中,第二鉴权响应消息还包括UE的特征属性信息。
步骤S210:GW-C接收第二鉴权响应消息;
步骤S211:GW-C向GW-U发送第一鉴权响应消息(鉴权结果);
其中,第一鉴权响应消息还包括UE的特征属性信息。
步骤S212:GW-U接收第一鉴权响应消息;
步骤S213:GW-U向UE发送会话连接建立响应消息(鉴权结果);
其中,会话连接建立响应消息还包括UE的特征属性信息。
步骤S214:UE接收会话连接建立响应消息;
上述步骤S201-步骤S214的具体过程可参见图3所示实施例一中的步骤S101-步骤S114的具体描述,在此不再赘述。
步骤S215:若鉴权结果为鉴权成功,GW-C向GW-U发送至少一个网络切片连接策略;
其中,至少一个网络切片连接策略为实施例一中的初始的至少一个网络切片连接策略。网络切片连接策略用于指示应用标识与网络切片之间的会话连接关系。网络切片连接策略包括应用标识、接入类型、APN三者之间的对应关系,反映应用标识与网络切片之间的会话连接关系,即哪个应用通过哪种接入类型连接哪个接入点。
步骤S216:GW-U接收至少一个网络切片连接策略;
步骤S217:GW-U向UE发送至少一个网络切片连接策略;
步骤S218:UE接收至少一个网络切片连接策略;
具体地,UE接收至少一个网络切片连接策略并缓存。
步骤S219:UE获取当前应用的应用标识;
其中,当前应用为UE当前正在运行的AR应用、物联网应用、远程医疗应用、自动驾驶应用等SLA应用,UE获取当前应用的应用标识,即确定正在运行的应用的应用标识。当前应用的数量可能为一个,也可能为多个,视具体情况而定。
步骤S220:UE在至少一个网络切片连接策略查找当前应用的应用标识对应的网络切片;
具体地,UE在至少一个网络切片连接策略查找当前应用的应用标识对应的网络切片,即确定当前应用标识对应的接入类型、APN。
步骤S221:UE根据查找到的网络切片建立会话连接并进行业务访问;
具体地,UE根据查找到的当前应用对应的接入类型、APN,建立与该APN的会话连接并对该APN进行业务访问。
在图6所示的实施例二中,UE根据GW-U发送的至少一个网络切片连接策略选择当前应用的应用标识对应的网络切片建立会话连接并进行业务访问,实现UE动态、自主选择网络切片连接策略,提高UE的参与度以及处理能力。
请参见图7,图7是本发明实施例三提供的业务管理方法的通信示意图,实施例三的应用场景为UE已经通过了鉴权,获取了初始的至少一个网络切片连接策略,GW-C基于网络切片部署架构的调整,对初始的至少一个网络切片连接策略进行了更新。该方法包括但不限于如下步骤:
步骤S301:GW-C对初始的至少一个网络切片连接策略进行更新得到更新后的至少一个网络切片连接策略;
GW-C在更新过程中,对某些应用标识对应的网络切片进行了调整。
步骤S302:GW-C向GW-U发送会话修改请求消息(更新后的至少一个网络切片连接策略);
其中,会话更新修改消息(Sx Session Modification Request)还包括UE的特征属性信息。
步骤S303:GW-U接收会话修改请求消息;
步骤S304:GW-U向UE发送会话连接更新请求消息(更新后的至少一个网络切片连接策略);
其中,会话连接更新请求消息(Session Connection Update Request)还包括UE的特征属性信息、鉴权结果。
步骤S305:UE接收会话连接更新请求消息;
具体地,UE接收会话连接更新请求消息,并对更新后的至少一个网络切片连接策略进行缓存。
步骤S306:UE向GW-U发送会话连接更新响应消息;
其中,会话连接更新响应消息(Session Connection Update Response)用于告知GW-U,UE已更新初始的至少一个网络切片连接策略。
步骤S307:UE获取当前应用的应用标识;
步骤S308:UE在更新后的至少一个网络切片连接策略查找当前应用的应用标识对应的网络切片;
步骤S309:UE根据查找到的网络切片建立会话连接并进行业务访问;
在图7所示的实施例三中,在GW-C更新初始的至少一个网络切片连接策略之后将更新 后的至少一个网络切片连接策略发送至GW-U,由GW-U下发至UE,由UE根据更新后的至少一个网络切片连接策略进行业务管理。
请参见图8,图8是本发明实施例四提供的业务管理方法的通信示意图,该方法包括但不限于如下步骤:
步骤S401:UE获取GW-U IP Address for GW-T;
步骤S402:UE建立与GW-U之间的通信链路;
步骤S403:UE向GW-U发送会话连接建立请求消息(UE的GW-T的鉴权信息);
步骤S404:GW-U接收会话连接建立请求消息;
步骤S405:GW-U向GW-C发送第一鉴权请求消息(UE的GW-T的鉴权信息);
步骤S406:GW-C接收第一鉴权请求消息;
步骤S407:GW-C向AAA发送第二鉴权请求消息(UE的GW-T的鉴权信息的会话标识);
步骤S408:AAA接收第二鉴权请求消息;
步骤S409:AAA向GW-C发送第二鉴权响应消息(鉴权结果);
步骤S410:GW-C接收第二鉴权响应消息;
步骤S411:GW-C向GW-U发送第一鉴权响应消息(鉴权结果);
步骤S412:GW-U接收第一鉴权响应消息;
步骤S413:GW-U向UE发送会话连接建立响应消息(鉴权结果);
步骤S414:UE接收会话连接建立响应消息;
步骤S415:若鉴权结果为鉴权成功,GW-C向GW-U发送至少一个业务计费与控制策略;
具体地,业务计费与控制策略包括应用标识与业务标识、费率组、QoS等信息之间的对应关系,反映应用标识与计费与控制策略之间的对应关系,即哪个应用通过哪种策略进行计费与控制。
步骤S416:GW-U接收至少一个业务计费与控制策略;
步骤S417:GW-U向UE发送至少一个业务计费与控制策略;
步骤S418:UE接收至少一个业务计费与控制策略;
步骤S419:UE获取访问数据业务的当前应用的应用标识;
其中,访问数据业务的当前应用为UE当前正在运行的需要连接网络或使用数据流量的应用,可以包括社交应用、购物应用、音频应用、视频应用等。
步骤S420:UE在至少一个业务计费与控制策略查找当前应用的应用标识对应的计费与控制策略;
步骤S421:UE根据查找到的计费与控制策略进行数据流量的统计和访问控制;
具体地,在UE进行数据流量统计之后,周期性地GW-U发送使用报告请求消息,使用报告请求消息包括UE的特征属性信息、应用使用量统计信息。使用报告请求消息用于请求GW-U生成针对UE的在线或离线话单并反馈使用报告确认消息,使用报告确认消息用于指示GW-U已确认所述应用使用量统计信息。其中,应用使用量统计信息包括应用使用量统计结果、业务标识、费率组。
在图8所示的实施例三中,UE根据GW-U发送的至少一个业务计费与控制策略确定当前应用的应用标识对应的业务计费与控制策略,并进行数据流量的统计和访问控制,实现UE对数据流量的统计和访问控制,提高UE的参与度以及处理能力。
需要说明的是,图5-图8所示的实施例针对网关用户面和网关控制面分开部署的情况进行介绍,若网关用户面与网关控制面合一部署,则网关用户面与网关控制面之间的交互过程可为合一部署设备的内部操作,虚线所示部分可不在通信示意图中体现。
请参见图9,图9是本发明实施例提供的另一种用户设备的结构示意图,图9所示的用户设备501包括获取单元5011、建立单元5012、发送单元5013、接收单元5014和管理单元5015。
获取单元5011,用于获取网关用户面的通信地址;
建立单元5012,用于通过所述通信地址建立与所述网关用户面之间的通信链路;
发送单元5013,用于通过所述通信链路向所述网关用户面发送会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述用户设备的网关终端模块的鉴权信息用于所述网关用户面触发网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
接收单元5014,用于通过所述通信链路接收所述网关用户面发送的会话连接建立响应消息,所述会话连接建立响应消息包括鉴权结果;
管理单元5015,用于若所述鉴权结果为鉴权成功,则根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理。
需要说明的是,所述获取单元5011用于执行图5所示实施例一中的步骤S101;所述建立单元5012用于执行图5所示实施例一中的步骤S102;所述发送单元5013用于执行执行图5所示实施例一中的步骤S103;所述接收单元5014用于执行图5所示实施例一中的步骤S114和S118;所述管理单元5015用于执行图5所示实施例一中的步骤S119。所述获取单元5011、所述建立单元5012、所述管理单元5015可以为图3所示用户设备的处理器1011;所述发送单元5013和所述接收单元5014可以为图3所示用户设备的收发器1012。
请参见图10,图10是本发明实施例提供的另一种网关用户面的结构示意图,图10所示的网关用户面601包括接收单元6011、发送单元6012。
接收单元6011,用于通过通信链路接收用户设备发送的会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述通信链路为所述用户设备通过获取的网关用户面的通信地址建立的与所述网关用户面之间的链路;
发送单元6012,用于向网关控制面发送鉴权请求消息,所述鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息,所述鉴权请求消息用于触发所述网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
所述接收单元6011,还用于接收所述网关控制面发送的鉴权响应消息;
所述发送单元6012,还用于通过所述通信链路向所述用户设备发送会话连接建立响应消息,所述鉴权响应消息、所述会话连接建立响应消息包括鉴权结果;
所述接收单元6011,还用于若所述鉴权结果为鉴权成功,则接收所述网关控制面发送的业务策略信息;
所述发送单元6012,还用于通过所述通信链路向所述用户设备发送所述业务策略信息,所述业务策略信息用于所述用户设备根据所述业务策略信息进行业务管理。
需要说明的是,所述接收单元6011用于执行图5所示实施例一中的步骤S104、S112、S116;所述发送单元6012用于执行图5所示实施例一中的步骤S105、S113、S117。所述接 收单元6011和所述发送单元6012可以为图4所示网关用户面的收发器1022。
结合本发明实施例公开内容所描述的方法或者算法的步骤可以硬件的方式来实现,也可以是由处理器执行软件指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于随机存取存储器(Random Access Memory,RAM)、闪存、只读存储器(Read Only Memory,ROM)、可擦除可编程只读存储器(Erasable Programmable ROM,EPROM)、电可擦可编程只读存储器(Electrically EPROM,EEPROM)、寄存器、硬盘、移动硬盘、只读光盘(CD~ROM)或者本领域熟知的任何其它形式的存储介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于第一管理单元或第二管理单元中。当然,处理器和存储介质也可以作为分立组件存在于第一管理单元或第二管理单元中。
本领域技术人员应该可以意识到,在上述一个或多个示例中,本发明实施例所描述的功能可以用硬件、软件、固件或它们的任意组合来实现。当使用软件实现时,可以将这些功能存储在计算机可读介质中或者作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是通用或专用计算机能够存取的任何可用介质。
以上所述的具体实施方式,对本发明实施例的目的、技术方案和有益效果进行了进一步详细说明,所应理解的是,以上所述仅为本发明实施例的具体实施方式而已,并不用于限定本发明实施例的保护范围,凡在本发明实施例的技术方案的基础之上,所做的任何修改、等同替换、改进等,均应包括在本发明实施例的保护范围之内。

Claims (36)

  1. 一种业务管理方法,其特征在于,包括:
    用户设备获取网关用户面的通信地址,通过所述通信地址建立与所述网关用户面之间的通信链路;
    所述用户设备通过所述通信链路向所述网关用户面发送会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述用户设备的网关终端模块的鉴权信息用于所述网关用户面触发网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
    所述用户设备通过所述通信链路接收所述网关用户面发送的会话连接建立响应消息,所述会话连接建立响应消息包括鉴权结果;
    若所述鉴权结果为鉴权成功,则所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理。
  2. 如权利要求1所述的方法,其特征在于,所述业务策略信息包括当前的至少一个网络切片连接策略,所述当前的至少一个网络切片连接策略为初始的至少一个网络切片连接策略或更新后的至少一个网络切片连接策略,网络切片连接策略用于指示应用标识与网络切片之间的会话连接关系;
    所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理,包括:
    所述用户设备获取当前应用的应用标识;
    所述用户设备在所述网关用户面通过所述通信链路发送的所述当前的至少一个网络切片连接策略中查找所述当前应用的应用标识对应的网络切片;
    所述用户设备根据查找到的所述网络切片建立会话连接并进行业务访问。
  3. 如权利要求2所述的方法,其特征在于,所述当前的至少一个网络切片连接策略为所述更新后的至少一个网络切片连接策略;
    所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理之前,还包括:
    所述用户设备通过所述通信链路向所述网关用户面发送会话连接更新响应消息,所述会话连接更新响应消息用于指示所述用户设备已更新所述初始的至少一个网络切片连接策略。
  4. 如权利要求1所述的方法,其特征在于,所述业务策略信息包括至少一个业务计费与控制策略,业务计费与控制策略用于指示应用标识与计费与控制策略之间的对应关系;
    所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理,包括:
    所述用户设备获取访问数据业务的当前应用的应用标识;
    所述用户设备在所述网关用户面通过所述通信链路发送的所述至少一个业务计费与控制策略中查找所述当前应用的应用标识对应的计费与控制策略;
    所述用户设备根据查找到的所述计费与控制策略进行数据流量的统计和访问控制。
  5. 如权利要求4所述的方法,其特征在于,所述用户设备根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理之后,还包括:
    所述用户设备通过所述通信链路周期性地向所述网关用户面发送使用报告请求消息,所述使用报告请求消息包括所述用户设备的特征属性信息、应用使用量统计信息,所述使用报告请求消息用于请求所述网关用户面生成在线或离线话单并反馈使用报告确认消息,所述使用报告确认消息用于指示所述网关用户面已确认所述应用使用量统计信息。
  6. 如权利要求1所述的方法,其特征在于,所述用户设备获取网关用户面的通信地址,包括:
    用户设备根据接入网网关发送的附着响应消息获取网关用户面的通信地址,所述附着响应消息包括所述网关用户面的通信地址;
    或,用户设备根据所述用户设备的预配置信息获取网关用户面的通信地址;
    或,用户设备根据用户选择的配置方式获取网关用户面的通信地址。
  7. 如权利要求1所述的方法,其特征在于,所述用户设备通过所述通信地址建立与所述网关用户面之间的通信链路之前,还包括:
    所述用户设备检测所述用户设备的网关终端模块、所述用户设备的权限以及网络运行环境是否满足预设条件;
    若检测结果为是,则所述用户设备执行通过所述通信地址建立与所述网关用户面之间的通信链路的步骤。
  8. 如权利要求1-7任一项所述的方法,其特征在于,所述会话连接建立请求消息还包括所述用户设备的特征属性信息,所述用户设备的特征属性信息包括移动台综合业务数字网号码MSISDN和国际移动用户识别码IMSI。
  9. 如权利要求1-8任一项所述的方法,其特征在于,所述连接会话建立响应消息还包括所述用户设备的特征属性信息。
  10. 如权利要求1-9任一项所述的方法,其特征在于,所述用户面设备的网关终端模块的鉴权信息、所述鉴权结果、所述业务策略信息、所述用户设备的特征属性信息以及所述应用使用量统计信息在所述通信链路中加密传输。
  11. 一种业务管理方法,其特征在于,包括:
    网关用户面通过通信链路接收用户设备发送的会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述通信链路为所述用户设备通过获取的网关用户面的通信地址建立的与所述网关用户面之间的链路;
    所述网关用户面向网关控制面发送鉴权请求消息,所述鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息,所述鉴权请求消息用于触发所述网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
    所述网关用户面接收所述网关控制面发送的鉴权响应消息,并通过所述通信链路向所述用户设备发送会话连接建立响应消息,所述鉴权响应消息、所述会话连接建立响应消息包括鉴权结果;
    若所述鉴权结果为鉴权成功,则所述网关用户面接收所述网关控制面发送的业务策略信息,并通过所述通信链路向所述用户设备发送所述业务策略信息,所述业务策略信息用于所述用户设备根据所述业务策略信息进行业务管理。
  12. 如权利要求11所述的方法,其特征在于,所述业务策略信息包括当前的至少一个网络切片连接策略,所述当前的至少一个网络切片连接策略为初始的至少一个网络切片连接策略或更新后的至少一个网络切片连接策略,网络切片连接策略用于指示应用标识与网络切片 之间的会话连接关系。
  13. 如权利要求12所述的方法,其特征在于,所述当前的至少一个网络切片连接策略为所述更新后的至少一个网络切片连接策略;
    所述方法还包括:
    所述网关用户面通过所述通信链路接收所述用户设备发送的会话连接更新响应消息,所述会话连接更新响应消息用于指示所述用户设备已更新所述初始的至少一个网络切片连接策略。
  14. 如权利要求11所述的方法,其特征在于,所述业务策略信息包括至少一个业务计费与控制策略,业务计费与控制策略用于指示应用标识与计费与控制策略之间的对应关系。
  15. 如权利要求14所述的方法,其特征在于,所述方法还包括:
    所述网关用户面通过所述通信链路接收所述用户设备周期性发送的使用报告请求消息,所述使用报告请求消息包括所述用户设备的特征属性信息、应用使用量统计信息;
    所述网关用户面根据所述使用报告请求消息生成在线或离线话单并通过所述通信链路向所述用户设备反馈使用报告确认消息,所述使用报告确认消息用于指示所述网关用户面已确认所述应用使用量统计信息。
  16. 如权利要求11-15任一项所述的方法,其特征在于,所述会话连接建立请求消息还包括所述用户设备的特征属性信息,所述用户设备的特征属性信息包括MSISDN和IMSI。
  17. 如权利要求11-16任一项所述的方法,其特征在于,所述鉴权响应消息、所述连接会话建立响应消息还包括所述用户设备的特征属性信息。
  18. 如权利要求11-17任一项所述的方法,其特征在于,所述用户面设备的网关终端模块的鉴权信息、所述鉴权结果、所述业务策略信息、所述用户设备的特征属性信息以及所述应用使用量统计信息在所述通信链路中加密传输。
  19. 一种用户设备,其特征在于,包括处理器和收发器,
    所述处理器用于获取网关用户面的通信地址,通过所述通信地址建立与所述网关用户面之间的通信链路;
    所述收发器用于通过所述通信链路向所述网关用户面发送会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述用户设备的网关终端模块的鉴权信息用于所述网关用户面触发网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
    所述收发器还用于通过所述通信链路接收所述网关用户面发送的会话连接建立响应消息,所述会话连接建立响应消息包括鉴权结果;
    若所述鉴权结果为鉴权成功,则所述处理器还用于根据所述网关用户面通过所述通信链路发送的业务策略信息进行业务管理。
  20. 如权利要求19所述的用户设备,其特征在于,所述业务策略信息包括当前的至少一个网络切片连接策略,所述当前的至少一个网络切片连接策略为初始的至少一个网络切片连接策略或更新后的至少一个网络切片连接策略,网络切片连接策略用于指示应用标识与网络切片之间的会话连接关系;
    所述处理器具体用于获取当前应用的应用标识,在所述网关用户面通过所述通信链路发送的所述当前的至少一个网络切片连接策略中查找所述当前应用的应用标识对应的网络切片,根据查找到的所述网络切片建立会话连接并进行业务访问。
  21. 如权利要求20所述的用户设备,其特征在于,所述当前的至少一个网络切片连接策略为所述更新后的至少一个网络切片连接策略;
    所述收发器还用于通过所述通信链路向所述网关用户面发送会话连接更新响应消息,所述会话连接更新响应消息用于指示所述用户设备已更新所述初始的至少一个网络切片连接策略。
  22. 如权利要求19所述的用户设备,其特征在于,所述业务策略信息包括至少一个业务计费与控制策略,业务计费与控制策略用于指示应用标识与计费与控制策略之间的对应关系;
    所述处理器具体用于获取访问数据业务的当前应用的应用标识,在所述网关用户面通过所述通信链路发送的所述至少一个业务计费与控制策略中查找所述当前应用的应用标识对应的计费与控制策略,根据查找到的所述计费与控制策略进行数据流量的统计和访问控制。
  23. 如权利要求22所述的用户设备,其特征在于,
    所述收发器还用于通过所述通信链路周期性地向所述网关用户面发送使用报告请求消息,所述使用报告请求消息包括所述用户设备的特征属性信息、应用使用量统计信息,所述使用报告请求消息用于请求所述网关用户面生成在线或离线话单并反馈使用报告确认消息,所述使用报告确认消息用于指示所述网关用户面已确认所述应用使用量统计信息。
  24. 如权利要求19所述的用户设备,其特征在于,所述处理器具体用于根据接入网网关发送的附着响应消息获取网关用户面的通信地址,所述附着响应消息包括所述网关用户面的通信地址;或,根据所述用户设备的预配置信息获取网关用户面的通信地址;或,根据用户选择的配置方式获取网关用户面的通信地址。
  25. 如权利要求19所述的用户设备,其特征在于,
    所述处理器还用于检测所述用户设备的网关终端模块、所述用户设备的权限以及网络运行环境是否满足预设条件;
    若检测结果为是,则所述收发器执行通过所述通信地址建立与所述网关用户面之间的通信链路的步骤。
  26. 如权利要求19-25任一项所述的用户设备,其特征在于,所述会话连接建立请求消息还包括所述用户设备的特征属性信息,所述用户设备的特征属性信息包括移动台综合业务数字网号码MSISDN和国际移动用户识别码IMSI。
  27. 如权利要求19-26任一项所述的用户设备,其特征在于,所述连接会话建立响应消息还包括所述用户设备的特征属性信息。
  28. 如权利要求19-27任一项所述的用户设备,其特征在于,所述用户面设备的网关终端模块的鉴权信息、所述鉴权结果、所述业务策略信息、所述用户设备的特征属性信息以及所述应用使用量统计信息在所述通信链路中加密传输。
  29. 一种网关用户面,其特征在于,包括处理器和收发器,
    所述收发器用于通过通信链路接收用户设备发送的会话连接建立请求消息,所述会话连接建立请求消息包括所述用户设备的网关终端模块的鉴权信息,所述通信链路为所述用户设备通过获取的网关用户面的通信地址建立的与所述网关用户面之间的链路;
    所述收发器还用于向网关控制面发送鉴权请求消息,所述鉴权请求消息包括所述用户设备的网关终端模块的鉴权信息,所述鉴权请求消息用于触发所述网关控制面请求鉴权服务器对所述用户设备的网关终端模块进行鉴权;
    所述收发器还用于接收所述网关控制面发送的鉴权响应消息,并通过所述通信链路向所 述用户设备发送会话连接建立响应消息,所述鉴权响应消息、所述会话连接建立响应消息包括鉴权结果;
    若所述鉴权结果为鉴权成功,则所述收发器还用于接收所述网关控制面发送的业务策略信息,并通过所述通信链路向所述用户设备发送所述业务策略信息,所述业务策略信息用于所述用户设备根据所述业务策略信息进行业务管理。
  30. 如权利要求29所述的网关用户面,其特征在于,所述业务策略信息包括当前的至少一个网络切片连接策略,所述当前的至少一个网络切片连接策略为初始的至少一个网络切片连接策略或更新后的至少一个网络切片连接策略,网络切片连接策略用于指示应用标识与网络切片之间的会话连接关系。
  31. 如权利要求30所述的网关用户面,其特征在于,所述当前的至少一个网络切片连接策略为所述更新后的至少一个网络切片连接策略;
    所述收发器还用于通过所述通信链路接收所述用户设备发送的会话连接更新响应消息,所述会话连接更新响应消息用于指示所述用户设备已更新所述初始的至少一个网络切片连接策略。
  32. 如权利要求29所述的网关用户面,其特征在于,所述业务策略信息包括至少一个业务计费与控制策略,业务计费与控制策略用于指示应用标识与计费与控制策略之间的对应关系。
  33. 如权利要求32所述的网关用户面,其特征在于,
    所述收发器还用于通过所述通信链路接收所述用户设备周期性发送的使用报告请求消息,所述使用报告请求消息包括所述用户设备的特征属性信息、应用使用量统计信息;
    所述处理器用于根据所述使用报告请求消息生成在线或离线话单并通过所述通信链路向所述用户设备反馈使用报告确认消息,所述使用报告确认消息用于指示所述网关用户面已确认所述应用使用量统计信息。
  34. 如权利要求29-33任一项所述的网关用户面,其特征在于,所述会话连接建立请求消息还包括所述用户设备的特征属性信息,所述用户设备的特征属性信息包括MSISDN和IMSI。
  35. 如权利要求29-34任一项所述的网关用户面,其特征在于,所述鉴权响应消息、所述连接会话建立响应消息还包括所述用户设备的特征属性信息。
  36. 如权利要求29-35任一项所述的网关用户面,其特征在于,所述用户面设备的网关终端模块的鉴权信息、所述鉴权结果、所述业务策略信息、所述用户设备的特征属性信息以及所述应用使用量统计信息在所述通信链路中加密传输。
PCT/CN2018/076985 2017-02-28 2018-02-23 一种业务管理方法及其装置 Ceased WO2018157754A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
KR1020197027599A KR102209599B1 (ko) 2017-02-28 2018-02-23 서비스 관리 방법 및 그 장치
EP18761755.0A EP3573311B1 (en) 2017-02-28 2018-02-23 Service management method and device thereof
JP2019542725A JP6911263B2 (ja) 2017-02-28 2018-02-23 サービス管理方法およびその装置
US16/552,806 US11265226B2 (en) 2017-02-28 2019-08-27 Service management method and apparatus thereof

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710113550.8 2017-02-28
CN201710113550.8A CN108512878B (zh) 2017-02-28 2017-02-28 一种业务管理方法及其装置

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US16/552,806 Continuation US11265226B2 (en) 2017-02-28 2019-08-27 Service management method and apparatus thereof

Publications (1)

Publication Number Publication Date
WO2018157754A1 true WO2018157754A1 (zh) 2018-09-07

Family

ID=63369824

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/076985 Ceased WO2018157754A1 (zh) 2017-02-28 2018-02-23 一种业务管理方法及其装置

Country Status (6)

Country Link
US (1) US11265226B2 (zh)
EP (1) EP3573311B1 (zh)
JP (1) JP6911263B2 (zh)
KR (1) KR102209599B1 (zh)
CN (2) CN112910969B (zh)
WO (1) WO2018157754A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113259231A (zh) * 2021-05-12 2021-08-13 中移(上海)信息通信科技有限公司 网关设备、信息传输方法及装置
CN114286450A (zh) * 2020-09-27 2022-04-05 中国移动通信集团设计院有限公司 承载建立方法、装置、电子设备及存储介质

Families Citing this family (27)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3646664A1 (en) * 2017-06-29 2020-05-06 Nokia Solutions and Networks Oy Enhanced interfaces for network slice selection based on charging rules
CN111869242B (zh) * 2018-03-20 2021-11-12 诺基亚通信公司 用于移动边缘计算中的配额管理的系统、方法和介质
JP6623268B1 (ja) * 2018-09-26 2019-12-18 ソフトバンク株式会社 制御プレーン機器、プログラム、システム及び情報処理装置
CN110972198B (zh) * 2018-09-30 2023-10-10 中兴通讯股份有限公司 业务控制方法、网络设备、及存储介质
CN111010744B (zh) * 2018-10-08 2022-05-13 华为技术有限公司 建立会话的方法和装置以及发送报文的方法和装置
CN114363063A (zh) * 2018-11-01 2022-04-15 西安万像电子科技有限公司 数据传输方法、装置及系统
US11539847B2 (en) * 2018-11-12 2022-12-27 Telefonaktiebolaget Lm Ericsson (Publ) Method and apparatus for a chargeable party at a session management with required quality of service
CN111263346B (zh) * 2018-11-30 2023-05-02 中国电信股份有限公司 用户面选择方法、系统和接入控制网元
CN111278024B (zh) * 2018-12-04 2023-03-24 中兴通讯股份有限公司 本端gtpu节点信息上报方法、装置及存储介质
CN111917563B (zh) * 2019-05-07 2023-03-10 华为技术有限公司 一种路由规则的配置方法及通信装置
CN112867016B (zh) * 2019-11-26 2023-06-30 成都鼎桥通信技术有限公司 一种宽带集群通信的核心网设备及其部署方法和装置
CN113163468A (zh) * 2020-01-22 2021-07-23 中国电信股份有限公司 网络切片的接入方法、系统和终端
CN115299158A (zh) * 2020-03-30 2022-11-04 瑞典爱立信有限公司 无线电通信网络中的用户设备、核心网节点和方法
WO2021223103A1 (en) * 2020-05-06 2021-11-11 Nokia Shanghai Bell Co., Ltd. Method and apparatus for preventing network attacks in a network slice
CN113630821B (zh) * 2020-05-09 2023-03-10 华为技术有限公司 通信方法及装置
WO2021237391A1 (en) * 2020-05-25 2021-12-02 Qualcomm Incorporated Encrypting application identifiers
CN113939041B (zh) * 2020-07-13 2023-11-28 中国电信股份有限公司 用于建立协议数据单元会话的方法和系统
CN114363393B (zh) * 2020-09-30 2025-10-03 中兴通讯股份有限公司 Pfd管理方法、网元及计算机可读存储介质
CN114422619B (zh) * 2020-10-12 2023-11-10 中国移动通信集团广东有限公司 业务识别方法、装置、设备及存储介质
CN114521004A (zh) * 2020-11-19 2022-05-20 中国移动通信集团有限公司 数据发送方法、装置、设备及存储介质
CN114980034B (zh) 2021-02-26 2024-10-22 维沃移动通信有限公司 原生算力业务实现方法、装置、网络设备及终端
CN115915127A (zh) * 2021-09-30 2023-04-04 维沃移动通信有限公司 用户相关的数据服务的处理方法、装置及网元
US12457549B2 (en) * 2022-04-13 2025-10-28 T-Mobile Usa, Inc. Serving gateway selection based on packet data network type
CN117014972A (zh) * 2022-04-29 2023-11-07 大唐移动通信设备有限公司 通信方法、装置、设备及存储介质
WO2023228249A1 (ja) * 2022-05-23 2023-11-30 楽天モバイル株式会社 通信経路制御システム、通信端末、中継装置、通信経路制御方法及びプログラム
EP4425828B1 (en) * 2023-03-01 2025-11-26 Deutsche Telekom AG Techniques to provide network-related services
CN119402255B (zh) * 2024-10-29 2025-12-12 成都安准网络安全技术有限公司 基于ai大模型训练的信息化数据安全传输方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103731929A (zh) * 2012-10-11 2014-04-16 中兴通讯股份有限公司 承载管理方法、装置及系统
CN105828315A (zh) * 2016-03-11 2016-08-03 北京北方烽火科技有限公司 服务网关选择方法及系统
US20160344635A1 (en) * 2015-05-21 2016-11-24 Qualcomm Incorporated Efficient policy enforcement for downlink traffic using network access tokens - control-plane approach
WO2017021649A1 (fr) * 2015-08-05 2017-02-09 Orange Procedes et dispositifs d'identification d'un serveur d'authentification

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101378522B (zh) * 2007-08-31 2012-01-25 华为技术有限公司 分发策略的方法、系统和策略分发实体
CN101159923B (zh) * 2007-11-09 2010-12-08 华为技术有限公司 业务处理方法及系统、sip应用接入网关模块
JP5203780B2 (ja) * 2008-04-07 2013-06-05 株式会社日立製作所 移動無線通信システムおよびアクセスゲートウェイ
US8793758B2 (en) * 2009-01-28 2014-07-29 Headwater Partners I Llc Security, fraud detection, and fraud mitigation in device-assisted services systems
WO2013089660A1 (en) * 2011-11-30 2013-06-20 1/1Affirmed Networks, Inc. Distributed content management wireless network architecture
WO2014000219A1 (zh) * 2012-06-28 2014-01-03 华为技术有限公司 拥塞状态上报方法及接入网设备
PT2854475T (pt) * 2012-06-29 2019-02-04 Huawei Tech Co Ltd Sistema de gateway, dispositivo e método de comunicação
US9253810B2 (en) * 2013-11-21 2016-02-02 Cisco Technology, Inc. Localizing a mobile data path in a radio access network under control of a mobile packet core in a network environment
CN105101136B (zh) * 2014-04-08 2019-01-11 华为技术有限公司 一种数据业务的计费方法、装置及系统
CN111246527B (zh) * 2015-08-17 2023-11-17 华为技术有限公司 一种更新用户面网关的方法及装置
CN105260842B (zh) * 2015-10-12 2020-05-15 用友网络科技股份有限公司 异构erp系统之间的通信方法和系统
US10897507B2 (en) * 2016-04-01 2021-01-19 Qualcomm Incorporated Mechanism to enable connectivity sessions and IP session establishment
US20170289791A1 (en) * 2016-04-05 2017-10-05 Electronics And Telecommunications Research Institute Communication method and apparatus using network slice
CN105933246B (zh) * 2016-06-28 2019-02-22 北京邮电大学 一种基于sdn的核心网系统及其使用方法
US10666458B2 (en) * 2016-09-30 2020-05-26 Huawei Technologies Co., Ltd Method and apparatus for data transmission involving tunneling in wireless communication networks
US10448239B2 (en) * 2017-02-06 2019-10-15 Qualcomm Incorporated Mechanism to enable optimized user plane anchoring for minimization of user plane relocation due to user equipment mobility
US20180241635A1 (en) * 2017-02-21 2018-08-23 Huawei Technologies Co., Ltd. Method for enabling automation of management and orchestration of network slices
CN109104394B (zh) * 2017-06-20 2022-01-21 华为技术有限公司 会话处理方法和设备
US10951427B2 (en) * 2017-10-09 2021-03-16 Comcast Cable Communications, Llc Ethernet type packet data unit session communications
US11330547B2 (en) * 2017-11-20 2022-05-10 Lenovo (Singapore) Pte. Ltd. Mobile network policy freshness
US10708318B2 (en) * 2018-03-21 2020-07-07 Ofinno, Llc Supporting termination access domain selection for a dual registered wireless device

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103731929A (zh) * 2012-10-11 2014-04-16 中兴通讯股份有限公司 承载管理方法、装置及系统
US20160344635A1 (en) * 2015-05-21 2016-11-24 Qualcomm Incorporated Efficient policy enforcement for downlink traffic using network access tokens - control-plane approach
WO2017021649A1 (fr) * 2015-08-05 2017-02-09 Orange Procedes et dispositifs d'identification d'un serveur d'authentification
CN105828315A (zh) * 2016-03-11 2016-08-03 北京北方烽火科技有限公司 服务网关选择方法及系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3573311A4

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114286450A (zh) * 2020-09-27 2022-04-05 中国移动通信集团设计院有限公司 承载建立方法、装置、电子设备及存储介质
CN114286450B (zh) * 2020-09-27 2023-09-19 中国移动通信集团设计院有限公司 承载建立方法、装置、电子设备及存储介质
CN113259231A (zh) * 2021-05-12 2021-08-13 中移(上海)信息通信科技有限公司 网关设备、信息传输方法及装置

Also Published As

Publication number Publication date
EP3573311A4 (en) 2020-01-01
US20190386894A1 (en) 2019-12-19
EP3573311A1 (en) 2019-11-27
CN108512878A (zh) 2018-09-07
US11265226B2 (en) 2022-03-01
CN108512878B (zh) 2021-01-29
CN112910969A (zh) 2021-06-04
JP6911263B2 (ja) 2021-07-28
EP3573311B1 (en) 2021-05-26
KR20190113985A (ko) 2019-10-08
KR102209599B1 (ko) 2021-01-28
CN112910969B (zh) 2022-07-29
JP2020509666A (ja) 2020-03-26

Similar Documents

Publication Publication Date Title
CN108512878B (zh) 一种业务管理方法及其装置
KR101854095B1 (ko) 액세스 및 트래픽 차등화를 위한 다수의 크리렌셜의 이용
EP4683423A2 (en) Method for implementing user plane security policy, apparatus, and system
CN105828413B (zh) 一种d2d模式b发现的安全方法、终端和系统
CN109792597B (zh) 一种本地业务授权方法及相关设备
CN111226452B (zh) 一种业务策略创建方法及装置
RU2009138223A (ru) Профиль пользователя, политика и распределение ключей pmip в сети беспроводной связи
CN107251522A (zh) 将网络令牌用于服务控制面办法的高效策略实施
US20150110044A1 (en) Third party interface for provisioning bearers according to a quality of service subscription
CN103313239B (zh) 一种用户设备接入融合核心网的方法及系统
CN111869182A (zh) 无线通信网络认证
WO2017173941A9 (zh) 服务质量QoS策略的处理方法、装置及系统
CN105611533B (zh) 完整性校验码mic检查方法及装置
EP3509265B1 (en) Network access authorization method, and related device and system
CN116210252A (zh) 接收用于边缘计算的用户同意的网络操作
US9647935B2 (en) Inter-layer quality of service preservation
CN115918113B (zh) 用户设备系连策略
WO2018058691A1 (zh) 一种建立公用数据网连接的方法及相关设备
CN116235526A (zh) 一种数据分析方法及装置
US11606303B1 (en) Device initiated quality of service
US12414005B2 (en) Systems and methods for selectable application-specific quality of service parameters in a wireless network
EP4677815A1 (en) Multiple vpn tunnels and ursp traffic categories
CN102572932A (zh) 一种实现家庭基站网络资源区分管理控制的方法和系统
CN116235515A (zh) 对用于边缘计算的用户同意的安全保护
WO2014110923A1 (zh) 一种网络信息处理方法、装置和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18761755

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2019542725

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2018761755

Country of ref document: EP

Effective date: 20190819

ENP Entry into the national phase

Ref document number: 20197027599

Country of ref document: KR

Kind code of ref document: A