TWI668976B

Method and device for efficient policy enforcement using network tokens for services-user-plane approach

Abstract

One aspect involves initiating a connection with an application server via the device, the application server being associated with one or more application services. The gateway obtains the uplink network token and/or the downlink network token. The token is provided to the device and/or application server via the user plane. The symbol is included in the uplink packet and/or the downlink packet, respectively. Another aspect involves receiving data packets at the gateway. The gateway determines the demand for network tokens based on the packet. The gateway obtains the network token based on the equipment customized profile maintained by the network. The network token can be sent with the packet to the destination address associated with the packet. Packets containing network tokens can be received at the gateway. The gateway can verify the network token, and if the verification succeeds, it sends the data packet to the application server or device.

TWI668976B, drawing sheet 1
Sheet 1 of 21

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

43 claims: 21 independent, 22 dependent

  1. 1
    A method operable at a device includes the steps of:initiating a connection with an application server via the device, the application server being associated with one or more application services;and in response to initiating the connection, obtaining a connection Network token, where the network token is obtained by a function through a gateway separated from the device and the application server. The function has a set of input parameters, and the set of input parameters includes the device unknown and A key unknown to the application server is associated with a first stream in a set of one or more streams, associated with a first application service in the one or more application services, and via one or more A user plane message is provided to the device;and in the user plane, the network token is sent from the device to the application server along with the same or multiple uplink (UL) packets. 一種可在一設備處操作的方法,包括以下步驟:經由該設備發起與一應用伺服器的一連接,該應用伺服器與一或多個應用服務相關聯;及回應於發起該連接,獲得一網路符記,其中該網路符記:是經由與該設備及該應用伺服器分離的一閘道藉一函數取得的,該函數具有一組輸入參數,該組輸入參數包括該設備未知且該應用伺服器未知的一金鑰,與一或多個流的一集合中的一第一流相關聯,與該一或多個應用服務中的一第一應用服務相關聯,以及經由一或多個使用者平面訊息提供給該設備;及在該使用者平面中,將該網路符記連同一或多個上行鏈路(UL)封包從該設備一起發送到該應用伺服器。
  2. 7
    Such as the method of request 1, wherein initiating the connection includes sending a packet indicating an implicit request for the network token. 如請求項1之方法,其中發起該連接包括發送用於表示對該網路符記的一隱式請求的一封包。
  3. 8
    Such as the method of request item 7, wherein the implicit request is expressed by sending a first packet to the application server. 如請求項7之方法,其中該隱式請求是經由向該應用伺服器發送一第一封包來表示的。
  4. 12
    Such as the method of request item 1, wherein the network identifier is transmitted from the device to a packet data network (PDN) in an Internet Protocol (IP) extension header as defined in IP version 6 (IPv6) Gateway (P-GW). 如請求項1之方法,其中該網路符記是在如IP版本6(IPv6)中定義的一網際網路協定(IP)擴展標頭中從該設備傳輸到一封包資料網路(PDN)閘道(P-GW)的。
  5. 14
    A device for network communication includes:a network communication interface configured to communicate via a wireless network;and a processing circuit coupled to the network communication interface, the processing circuit configured to: use User plane messaging is used to initiate a connection with an application server that is associated with one or more application services;in response to initiating the connection, obtain a network token from the application server, where the Network token: It is obtained through a function through a gateway separate from the device and the application server. The function has a set of input parameters. The set of input parameters includes one that is unknown to the device and unknown to the application server. The key is associated with a first flow in a set of one or more flows, is associated with a first application service in the one or more application services, and is provided to one or more user plane messages via one or more user plane messages The device;and in the user plane, the network token is sent from the device to the application server together with the same or multiple uplink (UL) packets. 一種用於網路通訊的設備,包括:一網路通訊介面,其被配置為經由一無線網進行通訊;及一處理電路,其耦合到該網路通訊介面,該處理電路被配置為:使用使用者平面訊息傳遞來發起與一應用伺服器的一連接,該應用伺服器與一或多個應用服務相關聯;回應於發起該連接,從該應用伺服器獲得一網路符記,其中該網路符記:是經由與該設備及該應用伺服器分離的一閘道藉一函數取得的,該函數具有一組輸入參數,該組輸入參數包括該設備未知且該應用伺服器未知的一金鑰,與一或多個流的一集合中的一第一流相關聯,與該一或多個應用服務中的一第一應用服務相關聯,以及經由一或多個使用者平面訊息提供給該設備;及在該使用者平面中,將該網路符記連同一或多個上行鏈路(UL)封包從該設備一起發送到該應用伺服器。
  6. 15
    A method that can be operated at a gateway device in a network includes the following steps:receiving a first data packet via a user plane at the gateway device;determining whether to request or not by evaluating the first data packet A network token;if the network token is requested, the network token is obtained, where the network token is based on a device customized profile maintained by the network in the gateway device If the network token is requested, use the first data packet to include the network token;and send the first data packet and the network token to a destination. 一種可在一網路中的一閘道設備處操作的方法,包括以下步驟:在該閘道設備處經由一使用者平面接收一第一資料封包;經由評估該第一資料封包來決定是否請求了一網路符記;若請求了該網路符記,則獲得該網路符記,其中該網路符記是基於由該網路維護的一設備訂制簡檔在該閘道設備本端取得的;若請求了該網路符記,則利用該第一資料封包來包括該網路符記;及將該第一資料封包和網路符記發送到一目的地。
  7. 22
    Such as the method of request item 15, wherein the first packet includes an explicit request for the network token. 如請求項15之方法,其中該第一封包包括對該網路符記的一顯式請求。
  8. 23
    Like the method of request item 15, the first packet represents an implicit request for the network token. 如請求項15之方法,該第一封包表示對該網路符記的一隱式請求。
  9. 25
    Such as the method of request item 15, wherein the network token is obtained using a function with a set of input parameters, the input parameters including:a key known by the gateway device, a type index, and a source Internet Network protocol (IP) address, source port number, destination IP address, destination port number, protocol identifier (ID), application ID, priority order and/or a quality of service class identifier (QCI). 如請求項15之方法,其中該網路符記是使用具有一組輸入參數的一函數來取得的,該等輸入參數包括:該閘道設備已知的一金鑰、一類索引、一源網際網路協定(IP)位址、源埠號、目的IP位址、目的埠號、協定辨識符(ID)、應用ID、優先順序及/或一服務品質類別辨識符(QCI)。
  10. 26
    Such as the method of request item 25, in which this type of index defines a field for obtaining network tokens. 如請求項25之方法,其中該類索引定義用於網路符記取得的欄位。
  11. 27
    Such as the method of request item 25, wherein the network token is a concatenation of the type index and an output of the function. 如請求項25之方法,其中該網路符記是該類索引和該函數的一輸出的一串聯。
  12. 28
    A gateway device includes:a network communication interface configured to communicate via a wireless network;a processing circuit coupled to the network communication interface, and the processing circuit is configured to: at the gateway device Receive a packet to be sent to an application server via a user plane;determine whether to request a network token by evaluating the packet;if the network token is requested, obtain the network token, The network token is obtained at the local end of the gateway device based on a device customization profile;if the network token is requested, the packet is used to include the network token;and the packet and The network token is sent to the application server. 一種閘道設備,包括:一網路通訊介面,其被配置為經由一無線網進行通訊;一處理電路,其耦合到該網路通訊介面,該處理電路被配置為:在該閘道設備處經由一使用者平面接收要被發送到一應用伺服器的一封包;經由評估該封包來決定是否請求了一網路符記;若請求了該網路符記,則獲得該網路符記,其中該網路符記是基於一設備訂制簡檔在該閘道設備本端取得的;若請求了該網路符記,則利用該封包來包括該網路符記;及將該封包和網路符記發送到該應用伺服器。
  13. 29
    A method that can be operated at a gateway device includes the following steps:in response to a request for a first network token sent from a device to an application server, borrow a first network token from the gateway device The function obtains the first network token, the application server is associated with one or more application services;at the gateway device, a data packet from the device is received, and the data packet includes at least the data packet corresponding to the application server Corresponding to a destination address prefix, and the data packet includes a second network token;verifying the second network token, wherein the verification step includes reacquiring the first network by the first function A copy of the token;if the verification is unsuccessful, the data packet is discarded;and if the verification is successful, the data packet is sent to the application server. 一種可在一閘道設備處操作的方法,包括以下步驟:回應於從一設備發送到一應用伺服器的對一第一網路符記的一請求,在該閘道設備處藉一第一函數取得該第一網路符記,該應用伺服器與一或多個應用服務相關聯;在該閘道設備處接收來自該設備的一資料封包,該資料封包至少包括與該應用伺服器相對應的一目的位址首碼,並且該資料封包包括一第二網路符記;校驗該第二網路符記,其中該校驗步驟包括藉該第一函數重新取得該第一網路符記的一複件;若該校驗不成功,則丟棄該資料封包;及若該校驗成功,則將該資料封包發送到該應用伺服器。
  14. 30
    Such as the method of request item 29, wherein the data packet is received in a user plane message. 如請求項29之方法,其中該資料封包是在一使用者平面訊息中接收的。
  15. 34
    Such as the method of request item 29, wherein the second network token is transmitted from the device to the gateway device in an IP extension header defined in Internet Protocol (IP) version 6 (IPv6). 如請求項29之方法,其中該第二網路符記是在網際網路協定(IP)版本6(IPv6)中定義的一IP擴展標頭中從該設備傳輸到該閘道設備的。
  16. 36
    A gateway device includes:a network communication interface configured to communicate via a wireless network;a processing circuit coupled to the network communication interface, the processing circuit configured to respond to a transmission from a device A request to an application server for a first network token, the first network token is obtained by a first function, and the application server is associated with one or more application services;receiving from the device A data packet, the data packet includes at least a destination address prefix corresponding to the application server, and the data packet includes a second network token;verify the second network token, wherein the calibration The verification step includes using the first function to retrieve a copy of the first network token;if the verification is unsuccessful, discarding the data packet;and if the verification is successful, sending the data packet to the application server . 一種閘道設備,包括:一網路通訊介面,其被配置為經由一無線網進行通訊;一處理電路,其耦合到該網路通訊介面,該處理電路被配置為:回應於從一設備發送到一應用伺服器的對一第一網路符記的一請求,藉一第一函數取得該第一網路符記,該應用伺服器與一或多個應用服務相關聯;從該設備接收一資料封包,該資料封包至少包括與該應用伺服器相對應的一目的位址首碼,並且該資料封包包括一第二網路符記;校驗該第二網路符記,其中該校驗步驟包括藉該第一函數重新取得該第一網路符記的一複件;若校驗不成功,則丟棄該資料封包;及若校驗成功,將該資料封包發送到該應用伺服器。
  17. 37
    A method operable at an application server includes the following steps:sending a request for initiating a first application service with a device via the application server associated with one or more application services;responding to Send the request for initiating the first application service to obtain a network token, where the network token is obtained through a function through a gateway separate from the device and the application server, the function Has a set of input parameters, the set of input parameters includes a key unknown to the device and unknown to the application server, associated with a first stream in a set of one or more streams, and associated with the first application service , And sent to the device via one or more user plane messages;and in the user plane, the network token along with one or more downlink (DL) packets sent from the application server Send to the device. 一種可在一應用伺服器處操作的方法,包括以下步驟:經由與一或多個應用服務相關聯的該應用伺服器發送用於發起與一設備的一第一應用服務的一請求;回應於發送該用於發起該第一應用服務的請求,獲得一網路符記,其中該網路符記:是經由與該設備及該應用伺服器分離的一閘道藉一函數取得的,該函數具有一組輸入參數,該組輸入參數包括該設備未知且該應用伺服器未知的一金鑰,與一或多個流的一集合中的一第一流相關聯,與該第一應用服務相關聯,以及經由一或多個使用者平面訊息發送到該設備;及在該使用者平面中,將該網路符記連同從該應用伺服器發送的一或多個下行鏈路(DL)封包一起發送到該設備。
  18. 38
    Such as the method of request item 37, wherein the network token is obtained through a gateway device of a core network. 如請求項37之方法,其中該網路符記是經由一核心網路的一閘道設備取得的。
  19. 41
    Such as the method of request item 37, wherein the request for initiating the first application service includes an explicit request for the network token. 如請求項37之方法,其中該用於發起該第一應用服務的請求包括對該網路符記的一顯式請求。
  20. 42
    Such as the method of request item 37, wherein sending the request for initiating the first application service includes sending a packet indicating an implicit request for the network token. 如請求項37之方法,其中發送該用於發起該第一應用服務的請求包括發送用於表示對該網路符記的一隱式請求的一封包。
  21. 43
    An application server includes:a network communication interface;a processing circuit coupled to the network communication interface, the processing circuit is configured to: send a request for initiating an application service with a device;respond to Send the request for initiating the application service with the device to obtain a network token, where the network token is obtained through a function through a gateway separate from the device and the application server, The function has a set of input parameters, the set of input parameters includes a key unknown to the device and unknown to the application server, and is associated with a first stream in a set of one or more streams;and the one or more The application service is associated with a first application service;and sent to the device via one or more user plane messages. 一種應用伺服器,包括:一網路通訊介面;一處理電路,其耦合到該網路通訊介面,該處理電路被配置為:發送用於發起與一設備的一應用服務的一請求;回應於發送該用於發起與該設備的該應用服務的請求,獲得一網路符記,其中該網路符記:是經由與該設備及該應用伺服器分離的一閘道藉一函數取得的,該函數具有一組輸入參數,該組輸入參數包括該設備未知且該應用伺服器未知的一金鑰,與一或多個流的一集合中的一第一流相關聯;與該一或多個應用服務中的一第一應用服務相關聯;及經由一或多個使用者平面訊息發送到該設備。
Independent claims21