CN1671119A - Method and system for transparently and safely interconnecting WLAN radio access network with GPRS/GSM core network - Google Patents

Method and system for transparently and safely interconnecting WLAN radio access network with GPRS/GSM core network Download PDF

Info

Publication number
CN1671119A
CN1671119A CN 200410030456 CN200410030456A CN1671119A CN 1671119 A CN1671119 A CN 1671119A CN 200410030456 CN200410030456 CN 200410030456 CN 200410030456 A CN200410030456 A CN 200410030456A CN 1671119 A CN1671119 A CN 1671119A
Authority
CN
China
Prior art keywords
wlan
rlm
network
subscriber equipment
afterwards
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN 200410030456
Other languages
Chinese (zh)
Inventor
M·S·乔哈里
A·Z·阿梅德
N·坎特
C-H·A·常
M·W·里特
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
AZAR NETWORKS CORP
Original Assignee
AZAR NETWORKS CORP
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by AZAR NETWORKS CORP filed Critical AZAR NETWORKS CORP
Priority to CN 200410030456 priority Critical patent/CN1671119A/en
Publication of CN1671119A publication Critical patent/CN1671119A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Mobile Radio Communication Systems (AREA)

Abstract

A method and system for integrating WLAN wireless access network to GSM/GPRS core network, which contains gateway between two network for transparent transmitting business, safety authentication, two network unit containing radio link management (RLM) and radio access control (RAC), software application program containing multiple link customer program (MLC) which resided in user equipment, wherein the RAC providing protocol stack and intercommunication for permitting MLC dialoging with home location register (HLR). RLM and MLC establishing a tunnel, such as Ethernet based PPP(PPPOE), RLM transmitting all data grouping received in above mentioned tunnel to gateway GPRS supported node (GGSN) in another tunnel by GPRS Tunneling Protocol (GTP).

Description

Be used for transparent, safely with the method and system of WLAN radio access network and GPRS/GSM core network interconnects
Technical field
The present invention relates to the intercommunication of wireless lan (wlan) and cellular network, so that for cellular network provides the connectivity of Packet data service, the present invention relates to the cellular network based on GSM especially.The invention still further relates to the technology of adding fail safe and confidentiality for the network element that fail safe and confidentiality are not provided.
Background technology
Need a kind of solution that high-speed wireless data network is provided for the gsm service client.Hope is in the core network element of not revising arbitrary gsm service, especially disposed under the situation of the core network element that is used to support GSM DPRS (GPRS) and realized above-mentioned purpose.Owing to do not change core network, believe the cost that can reduce to GSM network interpolation high-speed wireless data network.
Must be as far as possible efficiently and add at low cost that thereby high-speed radio is professional to be competed with integrated service.The first step of realizing this purpose will be to use measured network element, for example but be not restricted to use the wlan device of IEEE 802.11b procotol.Yet these procotols are comparatively elementary, and the preceding two-layer standard that provides of the typical OSI(Open Systems Interconnection) that defined seven layer protocol stacks only is provided: physical layer and medium insert and control (MAC) layer.
Fig. 1 diagram is used for IEEE 802.11 and the applied conventional osi model of the Internet engineering duty group (IETF) protocol stack of wireless WLAN.In the past,, must provide application gateway in order on top or application layer, to make the interconnection of this protocol stack and gsm protocol stack.This is very difficult for the GSM/GPRS business provides the interface method with the compounding practice of wlan system, because the GSM/GPRS business is based on diverse standard, and provides the many features that do not have in IETF and IEEE802.11b protocol stack.For example, the IETF system needed function of gsm service that do not provide support.The IETF agreement is not provided for the secure authentication system with GSM right discriminating system compounding practice, the form difference of accounting feature, handle on the different layers that is distributed in network protocol stack of client IP address, roaming characteristics is incompatible, and IETF is not defined in little mobility handover agreement of specified in more detail among the GSM.In fact, when compounding practice IETF and gsm system, typical gsm service will only be disposed two independently systems, and merge accounts afterwards.This solution is unfavorable, because the GSM carrier is difficult to two diverse customer databases of management, be provided for two the different servers and the client computer of every kind of other business that their wish to dispose, and use different network management system to manage two kinds of diverse network systems.
Therefore, need provide one group of intercommunication network unit, be used on the WLAN radio access network transformation service or other business is provided.In addition, wish to provide a kind of structure that is used for interworking unit in the mode that needs hardly or needn't revise gsm system.
Carried out the deployment that multiple effort solved and improved the high-speed data service that has used WLAN.Some distributors provide a kind of like this method, and this method is used the interworking unit between WLAN and traditional the Internet service provider (ISP) core network.In this method, the WLAN access point (AP) that physical layer and MAC layer function are provided is connected to Internet protocol (IP) router that process is revised.These routers are supported Route Selection layer ietf standard usually, for example but be not restricted to Route Selection Internet protocol (RIP), their usually use authentication and accounting system based on ietf standard, these systems use such as but be not restricted to the agreement of long-range access dial-in customer business (RADIUS).
After recognizing these problems, a plurality of distributors (Cisco System Co. in California Sheng Kelaike city, the Service Factory company and the Lucent Technologies Inc. of Stockholm, SWE) have attempted interworking unit is provided so that handle above-mentioned every kind of fault and many other problems.For example, a plurality of distributors have added functional part on access point, thereby add higher Network layer function, for example authentication and fail safe.This method is unsatisfactory, and reason is the ietf standard that does not relate to this field now.Therefore, use the access point of customizations to require the GSM/GPRS business only to dispose the AP that those can support these specialized protocols.In addition, some in their WLAN client's hardware the distributors of built-in other functional part and function limited the type that the client can be used for being connected to the network of network interface card, thereby caused other incompatibility, if the user can't select to use the interface of personal customization, then not desirable.
After recognizing these problems, some distributors (the PC Tel company in the IP Unplugged of the Nokia of Finland, Cisco Systems Inc., Sweden and California Sheng Kelaike city) focus on energy by adding so-called charging gateway to provide the rear end solution to record keeping and supply system.These gateways will convert the professional employed dedicated system of GSM/GPRS from the billing record of standard I ETF system to.Because there is not billing system standard, so be difficult to guarantee the transparency to the modification of existing business in new and future.
After recognizing these problems, other distributors (the Interwave of Menlo Park of the Transat in Texas Houston city and California) has set up the independent GSM/GPRS system that uses that wlan device and client communicate, and is present in GSM/GPRS core network interior all core network function and performance thereby replaced.This system also is that people are undesirable, because the GSM/GPRS business must still use different management and configuration order and other hardware and software to operate two kinds of diverse networks, even it provides more known alternate network to the GSM carrier.
Therefore, need the intercommunicating system between a kind of WLAN radio access network and the GSM/GPRS core network, it makes gsm service link the user pellucidly on this new radio access network, simultaneously all business that provide the client to expect to GSM client.In addition, if hardly with revising or do not make amendment and just can expand this intercommunication network, thereby and support that (3G for example, 802.11a) or high performance radio local area network (LAN) (HIPERLAN), this will be very useful so for other radio access network.A kind of like this system will make and not need to revise the WLAN unit, and two networks that will interconnect on minimum as far as possible network layer, and other functional part is provided on alap network layer, thereby can use the GSM standard of having disposed best.Should provide these functional parts by network element independently.Like this, only just function can be added radio access network to other by work seldom.
Summary of the invention
According to the present invention, provide a kind of being used for that the WLAN radio access network is integrated into method and system in the GSM/GPRS core network, wherein add and be used between the gateway of transport service pellucidly such as two kinds of heterogeneous networks of WLAN and GSM.Another aspect of the present invention is a secure authentication.System according to the present invention has two network element, i.e. radio link manager (RLM) and radio access controller (RAC), and software application, i.e. and multilink CLIENT PROGRAM (MLC) is so that control integrated function.MLC resides on the subscriber equipment, and described subscriber equipment for example but be not restricted to notebook computer, PDA or cellular telephone.WLAN radio access network (RAN) comprising: client's wireless device, and it is built in usually in the client computing device or by pcmcia card and installs; And access point (AP), this access point will be transformed on the wired network protocol from the wireless signal of client's wireless device.The method according to this invention, for this RAN is connected to the GSM/GPRS core network, the radio link manager is positioned between AP and the core network (CN), and is provided for the end points from the safety connection of MLC software on the client computing device.RLM will be transmitted to RAC from the authentication message of MLC.Thereby RAC provides protocol stack and IWF to allow MLC and attaching position register (HLR) conversation, and described attaching position register (HLR) is the standard network unit of handling authentication in the GSM core network.After the authentication client, RLM and MLC use the PPP(Point-to-Point Protocol) (PPPOE) on the Ethernet to set up one " tunnel (tunnel) ", all packets that RLM will receive on this tunnel are transmitted to Gateway GPRS Support Node (GGSN), and this node is the standard network unit that provides in the GSM/GPRS network with the interconnection of the Internet or other packet data network.In order to carry out this forwarding, RLM uses GPRS tunneled protocol (GTP) to set up a tunnel from RLM to GGSN.Selectively, the data link tunnel can be from RLM to the internet gateway with tunnel ability and address assignment ability as a global packet data network part.The Ricochet tunneled protocol of IP in for example general routed encapsulation (GRE) agreement, the IP tunnelization, second layer host-host protocol (L2TP), mobile IP and the Metricom relevant with full rete mirabile mesh network.Also can there be equivalence but current other unpredictable example.
These two network collaborative works seamlessly allow the client to continue to receive current available all-network business among the GSM, and irrelevant with the radio access network that uses on special time.
By with reference to detailed description, will understand the present invention better below in conjunction with accompanying drawing.
Description of drawings
Fig. 1 diagram is used for the network stack of IEEE WLAN standard and is used for the network stack by the IETF regulation of Internet protocol, and itself and OSI network model are compared (prior art) mutually.
Fig. 2 diagram is according to the ipLAN that is used for the WLAN structure of the present invention.
The upgrading according to the present invention of Fig. 3 diagram is to support the GSM network of GPRS and WLAN.
Fig. 4 is shown in necessary user's set in the specific embodiment of the present invention.
The message that Fig. 5 is shown in each unit of ipRAN that is used for WLAN and transmits between the GSM/GPRS core network that is used for client's authentication.
Fig. 6 is shown between radio link manager and the radio access controller preferred embodiment of packet format in the RR agreement.
Embodiment
The present invention is connected to the method and apparatus that has the GSM cell phone system of GPRS ability after the upgrading with WLAN radio access network (WLAN RAN) a kind of being used for.For GPRS is provided ability, the GSM network must add Serving GPRS Support Node (SGSN) 304 and Gateway GPRS Support Node (GGSN) 326, as shown in Figure 3.
In order to understand the improvement of representative of the present invention, those unit known in the prior art of understanding are of great use earlier.Illustrate the standard network unit in the GSM/GPRS in the left side of Fig. 3.Before GPRS upgrading, the cellular system support is routed to mobile switching centre (MSC) 327 again to the voice call of public switched telephone network (PSTN) 329 from base station controller (BSC) 303.For the GPRS that supports data, the data connection is routed to SGSN 304 from BSC 303, arrives GGSN 326 then, arrives packet data network (PDN) 306 again.The aerial signal path that is used for GPRS is identical with the path that is used for audio call physically.Yet GPRS uses different agreements in all connections.In routine operation, subscriber equipment 301 is supported GPRS radio air link 313, and sends grouping to base station transmitter server (BTS) 302.BTS 302 uses frame relay or other agreement directly giving one of BSC 303 with these packet forward in the connection 14.BTS 302 and BSC 303 also handle needed all other the complexity of voice call and this business.Yet packet selects route to send to SGSN 304 by direct connection 315 all the time.SGSN 304 connects 317 by network then and selects route to send to GGSN 326 packet, typically uses the GTP of internet protocol-based.SGSN304 also adjusts service quality (QoS), number of packet and the duration that is connected that is connected with recorded data packets according to the definition in the GPRS agreement.SGSN 304 is directly sending to Charging Gateway Functionality 305 with this information in the connection 316, is user's charging thereby allow according to service quality (QoS).SGSN 304 also uses MAP (MAP) agreement to be relayed to attaching position register (HLR) 311 from the authentication protocol of the subscriber identification module (SIM) 417 (Fig. 4) in user's device (UE) 301 on the network 324 of No.7 signalling system (SS7) type.GGSN 326 uses Internet protocol to select route to send to public data network (PDN) 306, normally the Internet the packet on the network 319 usually.
According to the present invention, with reference now to Fig. 3 right side, the packet that sends from the UE 309 that supports WLAN sends to PDN 306 the most at last.On WLAN airlink 322, packet is sent to WLAN access point (AP) 308 from UE 309.AP 308 gives radio link manager (RLM) 307 with described packet forward on bridge coil 321, described bridge coil 321 is Ethernet normally, but also can be on DSL, optical fiber or other suitable physical medium.RLM307 is being transmitted to GGSN 326 with packet on the network 320 of use based on the GTP (GTP/IP) of Internet protocol usually.GGSN 326 is transmitted to packet data network 306 with these packets then in the network connection 319 of using Internet protocol usually.In the described here invention, the network element that is used for providing IWF to WLAN only will be divided into different network element with the control grouping from the packet of the agreement of UE 301 as required on RLM 307.Usually using RLM to the network connection 325 of RAC (RR) agreement, authentication packets to be selected to be routed to radio access controller (RAC) 310 based on Internet protocol.RAC 310 is transmitted to HLR 311 with authentication packets on the SS7 network 323 that uses MAP.Support to move authentication protocol on the UE of WLAN 309 using its SIM card by the multilink client software.In GPRS or WLAN, GGSN 326 is directly sending to Charging Gateway Functionality 305 with metering data in the connection 318.The Charging Gateway Functionality record is sent to the total connect hours and the quality of the packet of PDN 306 by UE 309 or 301.
Can provide the GPRS situation of the QoS on the airlink 313 different with BTS 302, under the situation of WLAN, not have QoS on the link 322 aloft.In GPRS, from SGSN 304 this information is write down and sends to Charging Gateway Functionality 305 by direct link 316.Under the situation of WLAN, do not need this information, therefore can ignore this information.
For the core network element of the GSM with GGSN 326 and Charging Gateway Functionality 305, WLAN connects simulation GPRS connection now.The connection of RLM 307 simulation SGSN 304 to GGSN 326.The connection of RAC 310 simulation SGSN 304 to HLR 311, and WLAN no longer needs the connection of SGSN 304 to Charging Gateway Functionality, because on the WLAN airlink, there is not the QoS ability.Like this, can make the WLAN business that provides for the specific user enter HLR 311 with the identical mode of entrance of user's gprs service.Also can in Charging Gateway Functionality 305, carry out charging with complete simulated mode.Thereby, the IWF that uses RLM 307 and RAC 310 to be provided, can not make amendment or, WLAN RAN is being connected to the GSM/GPRS core network not to being used in management on the described core network and providing under the situation that professional any program makes amendment to core network.
Referring to Fig. 2, illustrate the specific embodiment of realizing hardware cell of the present invention.For the technical staff of network field, other embodiment may be conspicuous, and is not precluded within outside this specification.Interworking unit between WLAN and the core GSM/GPRS network comprises: MLC (multilink CLIENT PROGRAM), and it is the software on the Client Hardware 201; RLM (radio link manager) 206, it is Route Selection and the control point that is used for authentication and data flow; And RAC (radio access controller) 207, it is to be used for authentication and the service intercommunication unit is provided.
User's set UE is the computing equipment that has the WLAN wireless device, for example but be not restricted to personal digital assistant (PDA) 202, cellular telephone 203 or notebook computer 204.The employed airlink 218 of WLAN wireless device that embeds in the computing equipment 202,203 or 204 can be based on IEEE 802.11b standard, perhaps can be based on being transformed into any other airlink on the bridge coil by access point (AP) 204.Other example of spendable airlink protocols and wireless device is other certain airlink that IEEE 802.11a or 802.11g standard, HIPERLAN standard maybe will be determined.In a preferred embodiment, unique requirement is that AP 204 supports IEEE 802.1D bridged protocol standard.Can use ethernet physical layer to move described agreement on network 214 by bridger or hub 205, described bridger or hub 205 be given RLM 206 with packet forward on network 215.Network 215 can also use Ethernet, but can use by copper twisted pairs 220 DSL (Digital Subscriber Line) modulator-demodulator 219 and the long-range DSLAM (Digital Subscriber Line access manager) 221 that connect are replaced bridger or hub 205, as long as be grouped in appearance on the network 215 as the appearance on network 214, and, occur as the bridge coil of going to RLM so that for both all be as long as two physical networks meet IEEE 802.1D bridged protocol standard between connecting 214 and 215.For the technical staff of network field, other method that AP 204 is connected to RLM 206 should be conspicuous.And for the technical staff of network field, the quantity of the AP 204 on the network 214 is not obviously fixed, and can reach the arbitrary number of redundant and the required use of capacity at most.
In Fig. 4 detailed icon UE 201,202 or 203.UE 201 has a device housings 414, wherein comprise CPU (CPU) 402, it is communicated by letter with nonvolatile memory 403 on a connection or bus 410, in nonvolatile memory 403, various programs are controlled a plurality of equipment 405,406,404 and 417 with the software instruction form, and by instruct the ground decipher to come in UE, to carry out their function one by one by CPU.The multilink client software also is stored in the UE nonvolatile memory 403.When powering up to UE, CPU 402 can arrive random access memory 401 with program copy by connection or bus 409, perhaps can be from nonvolatile memory 403 direct working procedures.User's set has usually but must not have output equipment 404, is for example connecting the screen or the loud speaker of communicating by letter with CPU 402 on 412.This output equipment 404 can be controlled by the program that resides in nonvolatile memory 403 or the random access memory 401.Equipment has usually but must not have input equipment 405, is for example connecting keyboard, mouse or the microphone of communicating by letter with CPU 402 on 413.This input equipment 405 can be controlled by the program that resides in nonvolatile memory 403 or the random access memory 401.UE equipment has WLAN wireless device 406 or equivalent of the apparatus usually, it connect or bus 411 on be connected to CPU 402 and be connected to antenna 407 on 408 with being connected, described equipment is usually but must be in device housings 414.In a preferred embodiment, described equipment has by connecting the 415 SIM readers 416 that are connected to CPU 402, and it can accept SIM card 417, and to its transmission with from its reception information.
In a particular embodiment, on connection or bus 415, this SIM card information is sent to CPU 402.SIM card reader 416 can be embedded in the device housings 414, perhaps can be arranged on device housings 414 outsides.
Can use a kind of suitable method on user's set 201,202 or 203, to call and operation is called the software program of MLC (multilink CLIENT PROGRAM), for example but be not limited in the equipment user and use mouse (input equipment 405) to click icon on the screen (output equipment 404), perhaps in optional embodiment, can identify the signal that sends to CPU 402 in connection 411 from WLAN wireless device 406 in preassembled program on the user's set, its this fact of notice MLC software: WLAN wireless device 406 can be connected to himself AP 204.
In a kind of optional embodiment, known as the technical staff in Computer Design and programming field, also can or use other someway by next button (input equipment 405).When notified should log-on data the connection, MLC attempt to as HLR 217 authentications of a core GSM network part himself.In a preferred embodiment of the invention, when the multilink client software uses when setting up a tunnel from UE 201,202 or 203 to RLM 206 based on the point-to-point protocol (PPPOE) of Ethernet, network 214 and 215 should be the Ethernet by bridger or hub 205 bridge joints.If in network 214 and 215, will use another kind of media, then can use different agreements to be encapsulated in the packet that sends on the airlink 218, described agreement comprises needed identical function: the ability of location RLM 206, but described RLM provides the tunnel server in a tunnel that begins of termination in MLC; And the ability that on described tunnel, sends grouping by AP 204.To be used for from UE 201,202 or 203 is second layer host-host protocol (L2TP) to RLM 206 through the example of another protocol method of tunnel transmission grouping.Other some examples are general routed encapsulation (GRE) agreements, with the Ricochet tunneled protocol of the IP (IPin IP tunneling) of IP tunnelization, mobile IP and the Metricom relevant with full rete mirabile mesh network.Also may exist equivalence but present other unpredictable example.
In this embodiment, the MLC on the UE 201,202 or 203 inserts the multilink CLIENT PROGRAM as L2TP, and network 214 and 215 is to use the routed network of Internet protocol.In this embodiment, set of router has been replaced bridger or hub 205, and is used for transmitting between AP 204 and RLM 206 grouping.RLM is as L2TP Network Server.Use the IP address of RLM 206 to dispose MLC.In a kind of alternate embodiments, MLC uses Domain Name Services (DNS) inquiry of standard to seek RLM 206.This inquiry provides needed function; It finds RLM 206, and allows will divide into groups to send RLM206 to from UE 201,202 or 203 tunnel.Being used for from UE 201,202,203 will be conspicuous for the technical staff of network field to other method of RLM 206 tunnel transmission grouping.This structure does not only limit to the user every network one or two RLM 206, but according to the needs of redundant and capacity, the RLM 206 of permission any amount.
In the specific embodiment that uses IEEE 802.11 agreements, APC 204 is as bridger, all packets on the airlink 218 are forwarded on the bridge coil 214, and will be transmitted to correct UE 201,202 or 203 from all packets of bridge coil 214.WLAN wireless device 406 in the user's set 201,202 or 203 sends grouping to antenna 407 in connection 408, described grouping is received by AP 204 through airlink 218.WLAN wireless device 406 uses IEEE 802.11 agreements so that be connected to one of AP 204.In case WLAN wireless device 406 is connected to AP 204, it is just connecting notice CPU 402 on 413, and notice resides in the device driver software in nonvolatile memory 403 or the random-access memory (ram) 401.Device driver software uses the standard signaling that access events is notified to MLC software by CPU 402 and bus 409 or 410.Then, MLC sends out PPPOE to device driver and effectively finds initialization (PADI) grouping, makes WLAN wireless device 406 send it to AP 204.AP 204 will give network 214 this PADI packet forward.Because this grouping is addressed to the broadcasting ethernet address on the bridge coil, so this grouping will be copied on network 215,214 and the airlink 218.
The RLM 206 that is hopeful to accept to connect effectively finds to provide (PADO) respond packet to respond described PADI grouping the clean culture PPPOE that use is addressed to UE 201,202 or 203.This PADO grouping will be received and be transmitted to MLC by UE 202,202 or 203.MLC registers to the device driver of WLAN wireless device 406, so that receive the duplicate of the grouping of all these types.The PADO grouping comprises the IEEE MAC Address of RLM 206.By this way, MLC can find the address of RLM 206.Now, MLC bridge coil 214 and 215 and airlink 218 on use this address to set up a PPPOE tunnel between himself and its selected RLM 206.MLC uses the PPP by the PPPOE protocol encapsulation, is connected thereby use the source address of PADO grouping to consult a PPP with RLM 206.
According to the present invention, MLC and RLM 206 uses extendible authentication protocol, for example PPP or 802.1X, and sending authentication SIM card 417 needed information to HLR 208, and to MLC authentication RLM 206.In case finish authentication, then provide the information of unique key form to RLM 208 and by SIM card 417 to MLC by HLR 208, so that setting up a safety between two equipment, they connect.Only use to the unique key known to RLM 206 and the MLC and encrypt each grouping.Then, MLC is used as the fire compartment wall of UE 201,202 or 203, and abandons all groupings except using the correct encrypted packets of unique key.RLM 206 abandons all groupings except use correct those groupings of encrypting of unique key from UE 202,202 or 203 also as fire compartment wall.This make UE 201,202 or 203 except by can't addressing AP 204 RLM 206, any other core network element of another user's set 201,202 or 203, bridger 205 or gsm system; described RLM 206 encapsulating packets also will divide into groups to be transmitted to GGSN 212 by core network; described GGSN 212 only gives the PDN210 the Internet with packet forward, has also protected all core network element to avoid any attack of UE 201,202 or 203 thus.In addition, because MLC has abandoned from all groupings beyond the PPPOE tunnel of RLM 206, any other UE 201,202 or 203 or all can't import the grouping that will be received by UE such as any equipment of hub or bridger 205, thereby guarantee that it can not be subjected to being connected to that core network connects 212, bridge coil 214 and 215 or any attack of any equipment of airlink 218, transmit for UE 201,202 or 203 provides safe public packet, and make the client need not worried UE 201,202 or 203 attack or abuse.
Referring to the stream of packets cardon of Fig. 5, transmit message between the various network elements in WLAN RAN and core GSM/GPRS network, so that the client's SIM card on HLR 523 authentication UE 520.These authorization of messages client can use WLAN and begin and charge, and comprises and be used to set up from UE 520 to RLM 521 with from the message of setting up in the end-to-end tunnel of RLM 521 to GGSN 524, receives and send data service in described tunnel.As mentioned above, UE 520 uses PPPOE to find to divide into groups to find RLM 521, and divides into groups so that transmit between UE 520 and RLM 521 with this protocol encapsulation PPP.Fig. 5 is shown in the packet communication between the network element of separation: UE 520, RLM 521, RAC 522, HLR 523 and the GGSN 524.Time increases progressively from the top down.Use one independently to number each grouping of mark or message, wherein the straight line of a band arrow begins and finishes in the network element that receives grouping from the network element of the grouping of starting.
Fig. 5 also illustrates the ordering of grouping.The grouping that more early sends is the closer to the top of this figure in time.Only for illustrative purpose, Fig. 5 also illustrates the title of employed selected agreement between UE 520 and RLM 521.In a specific embodiment, these equipment use PPP to send grouping forward and backward, and consult authentication and needed other network configuration so that UE520 becomes the network element of the abundant participation in the packet data network that is connected to GGSN 524.
Between UE 520 and RLM 521, can use the sub-protocol of a plurality of PPP.These agreements comprise LCP (LCP), contention authentication protocol (CHAP) and IP control protocol (IPCP).Also can use other agreement such as 802.1X.In order to illustrate, the mark that uses lower-left side among this figure with the grouping of every kind of agreement or message combinations together.
In a kind of specific embodiment, MLC on the UE 520 uses PPP to consult LCP config option type 0x20 and LCP config option type 0x21 by send PPP LCP config option grouping 501 to RLM 521, described LCP config option type 0x20 length is 18 and comprises international mobile subscriber identifier (IMSI), described LCP config option type 0x21 has the present length of 18 bytes, the random number of one 16 byte, this random number changes in each case as far as possible unpredictablely.
Another kind provides the method for this information to be to use special-purpose LCP collocation method of distributors and field.RLM 521 receives lcp option, and writes down present value (random number that is used for contention) so that use subsequently.Then, as shown in table 2 it in the connection request of RAC to RLM (RR) agreement grouping 502, IMSI is transmitted to RAC 522.Shown in Fig. 6 and table 1 in the specific embodiment, the RR agreement has the version number of 8 bits, be the message numbering of 8 bits afterwards, be the byte length of the Payload of message subsequently represented with 16 bit lengths afterwards, be 32 bit identifier of the UE 520 of RLM521 distribution afterwards, it comprises the unique identification that is used for UE 520 that the RLM 521 of RLM 521 unique identifications of 20 bits and 12 bits distributes, and then is message Payload itself.
Message ????ID
Connection request ????0x01
The authentication refusal ????0x02
Connect and accept ????0x04
Connection is finished ????0x03
Authentication request ????0x12
Authentication Response ????0x13
Table 1
In table 1, listed the message numbering in the RR agreement of each message that is used between RAC and the RLM.The Payload of the connection request grouping 502 that is used for RR agreement between RAC and the RLM has been described in table 2.
Field _ title Byte-sized Value Describe
????Auth_Type ????1 ????0x1 Assigned I MSI
????IMSI_Len ????1 0x07 extremely The word of IMSI
????0x10 Joint length
????IMSI ????IMSI_Le ????n ????IMSI The unique identifier that is used for the mobile subscriber
????Old_RAC ????8 Unique RAC identifier Be used for the handover information retrieval
Table 2
In typical method according to the present invention, RAC 522 is transmitted to HLR523 with connection request, all uses the MAP on the SS7 network to communicate.If for example the client do not pay he bill or the operator of client's cellular carrier and this network between do not have roaming agreement, then HLR 523 can use and connect refusal 516a and refuse this request; HLR 523 also can by send authentication request grouping 516 and signature response (SRES) come requirement SIM card authentication himself, described authentication request grouping 516 comprises that the GSM authentication protocol that uses the A8 type and one or more RAND (i.e. the random number of one 64 bit) only pass through a key as the secret parameter generation known to HLR and the SIM card, described signature response (SRES) can use the authentication protocol of A5 type to come authentication, it proves that HLR knows the secret of sharing with SIM card, and is used for providing to carrier network the authentication of SIM card.RAC 521 uses authentication request grouping 503 information in the forwarding authentication request grouping 516 between RAC and RLM of RR agreement, and its Payload is as shown in table 3, uses Internet protocol usually.
Field _ title Byte-sized Value Describe
????RAND_Len ????1 1 to 16 The byte length of RAND field
????RAND ????RAND_Le ????n Random number The current number that HLR generates
????SRES_Len ????1 1 to 4 The byte length of SRES field
????SRES ????SRES_Le ????n Use the signature response of the A3 GSM algorithm of RAND and Kc Generate by HLR
????Kc_Len ????1 1 to 8 The byte length of Kc field
????Kc ????Kc_Len The key that uses A5 GSM algorithm and RAND to generate Generate by HLR
Table 3
Alternatively, the information that RAC 521 also can use the authentication refusal grouping 503a of RR agreement will connect in the refusal grouping 516a is transmitted to RLM 521, shown in table 4 and table 5, uses Internet protocol usually.
Field _ title Byte-sized Value Describe
????Reject_Co ????de ????1 Reason For Denial As shown in table 5
Table 4
Reason For Denial Code
The IMSI of the unknown in the HLR ????0x02
Illegal user identifier ????0x03
Do not allow gprs service ????0x07
Can not determine user's status ????0x09
Separate in the dark ????0x0A
Table 5
The reason of table 5 diagram refusal connection request is connected the interior field value of Reject_Code field that refusal divides into groups with being placed on.If RLM receives authentication request 503, it is accepted message 504 with PPP LCP and is transmitted to UE 520, and this message allows the PPP client computer to continue its state machine and response authentication request.If RLM 521 receives authentication refuse information 503a, then it is transmitted to UE 520 with PPP LCP refuse information 504a, finishes this ppp negotiation subsequently.
After UE 520 sends PPP LCP message 504, in this preferred embodiment, thereby the ppp state machine on the RLM521 sends CHAP dialogue of contention packet 505 initialization by using LCP config option type 3 and the authentication protocol value 0xc223 that is used for CHAP.For algorithm field, we use the algorithm of specifying us based on the value 0x88 of SIM authentication, and are as described below.In the CHAP exchange process, send to the MAC_RAND of the signature form that random number, these two random numbers that contention word segment datas in the grouping 505 of UE 520 comprise two 16 bytes and currency make up, two Kc, IMSI and use shah-1 algorithm---a kind of two SRES of hashing algorithm from RLM 521.Also can use other hashing algorithm, for example MD-5.Can generate Kc by the MLC on the UE 520 according to each RAND in the message 503 that sends to RLM 521, by each RAND being sent to SIM card 417 and obtaining Kc, in CHAP contention message 505, it is transmitted to UE 520 as the response that GSM algorithm A8 generates.Then, use these key K c that is generated, UE 520 can verify whether the information in the message 505 is correctly signed; If be proved to be successful, then can talk with HLR 523, and know Kc, thereby checking RLM 521 be legal interworking units that are used for client operator to UE 520 proof RLM 521.MLC in the UE 520 uses CHAP response message 506 to respond, and described message comprises MAC_SRES, and it is to use two SRES that send to RLM521 in message 503 of shah-1 algorithm, the signature form of two Kc, currency and IMSI.UE 520 generates each SRES according to the RAND that sends to it in message 505, when SIM card 417 generates Kc, will transmit its value in the RAND field of authentication request grouping 503.When RLM 521 receives MAC_SRES, it verifies that MAC_SRES has obtained UE 520 and correctly signed, and prove that thus UE 520 has correct SIM card 417, then to the UE 520 of RLM 521 authentication user, perhaps correctly not signed by notice MAC_SRES, prove oneself can't authentication UE 520.Then, RLM 521 uses Authentication Responses grouping 507 that this authentication fact is transmitted to RAC 522, and its Payload is as shown in table 6.
Field _ title Byte-sized Value Describe
????Auth_Resp ????onse ????1 0x00 or 0x01 Be expressed as merit or failure
Table 6
Then, RAC 522 uses its connection of understanding the authentication fact of expression to accept message 508 and responds RLM 521.Suppose the authentication success, then RLM 521 sends a PDP environment to GGSN524 and activates message 509 on the GTP control protocol, so that notify to GGSN: should be UE 520 and set up a GTP tunnel, be connected to this packet data network to allow UE 520.Then, RLM521 sends CHAP success messages 510 to UE 520 and correctly finishes with the proof authentication, if failed authentication then send CHAP failed message 510a.Then, RLM 521 sends to connect to RAC 522 and finishes message 511 so that it can be finished its state machine and store the parameter that connects for the UE 520 that is used in the future handover.When GGSN 524 finished the activation GTP tunnel, it sent PDP environmental response message 512 to RLM 521, and RLM 521 sends the IP assignment information to UE 520 subsequently in message 513, sent IP grouping information necessary comprising UE 520 to PDN 306.The notice that RLM 521 successfully creates GTP tunnel is transmitted to RAC 522, thereby allows RAC 522 to upgrade its state machine, and stores the parameter in the tunnel of the UE520 that will be used for handover future.
Table 7 is described and is connected the Payload of accepting grouping.
Field _ title Byte-sized Value Describe
????RAC ????8 ????RAC?ID Unique indication of service RAC
????Auth_Resp ????onse ????1 0x00 or 0x01 Be expressed as merit or failure
Table 7
Table 8 is to connect the Payload of finishing grouping 511 to describe.
Field _ title Byte-sized Value Describe
????Auth_Resp ????onse ????1 0x00 or 0x01 Be expressed as merit or failure
Table 8
Now, UE 520 by this program by GSM/GPRS core network authentication successfully, and have an a pair of tunnel for its foundation, and the former is between MLC on the UE 520 and RLM 512 and use PPPOE, and the latter is between RLM 521 and GGSN 524 and use GTP.PPPOE has used in the tunnel default encryption, this default encryption is based on AES and has utilized unique shared key based on Kc, currency and IMSI, this grouping that has guaranteed that UE 520 sends can not be by anyone defrauds of on any network, these groupings are privately owned, and can not be defrauded of by any other people from the path of UE 520 to RLM521.RLM 521 obtains the IP grouping that receives from UE 520 on the PPPOE tunnel that success is decoded, and they are put into the GTP tunnel of GGSN 524.GGSN 524 obtains these groupings and they is sent to PDN 306.Receive the packet that is addressed to UE 520 by GGSN 524, GGSN is used to be connected to the packet data network of the Internet, and the common path of the IP address of distributing to UE 520 is notified in described packet.GGSN524 puts into GTP tunnel with these groupings, and they are sent to RLM 521.RLM 521 extracts these groupings, is encrypted and on the PPPOE tunnel it is transmitted to UE 520.MLC on the UE 520 is extracted in the grouping that receives on the PPPOE tunnel, after successful deciphering, send them on the UE 520 other and handle, thereby the packet data network that is provided to UE 520 connects normally Internet connection.By this way, by the core GSM/GPRS network of the operator that UE 520 that only has WLAN wireless device 416 and SIM card reader 416 and SIM card 417 do not made amendment, the preferred embodiments of the present invention provide the access of the secure authentication of packet data network.
The present invention has been described with reference to specific embodiment.For a person skilled in the art, other embodiment will be conspicuous.Therefore, the present invention is also non-limiting, and its scope is limited by appending claims.

Claims (13)

1. method that the core network that uses to support gsm protocol comes authentication WLAN radio user equipment in WLAN radio access network (WLAN RAN), this method may further comprise the steps:
Radio access controller (RAC), radio link manager (RLM) and WLAN access point (WLAN AP) are connected to the attaching position register (HLR) of described core network;
Set up communicating by letter of WLAN radio user equipment and WLAN AP and RLM;
The subscriber equipment that has multilink CLIENT PROGRAM (MLC) ability to the HLR authentication; Afterwards
By the first data link tunnel that connects from MLC to RLM described subscriber equipment is connected to core network system.
2. according to the process of claim 1 wherein that described authentication step also comprises: connect the second data link tunnel afterwards from RLM to the GGSN packet gateway that is used for the global packet data network.
3. according to the process of claim 1 wherein that described authentication step also comprises: connect afterwards from RLM to the second data link tunnel as the internet gateway of a global packet data network part with tunnel ability and address assignment ability.
4. according to the method for claim 3, wherein internet gateway is used second layer host-host protocol.
5. method that is used for WLAN radio access network (WLAN RAN) is interconnected to the GSM core network of supporting the GPRS packet oriented protocol, this method may further comprise the steps:
Radio access controller (RAC), radio link manager (RLM) and WLAN access point (WLAN AP) are connected to the attaching position register (HLR) of GPRS gateway service node (GGSN) and described core network;
Set up communicating by letter of WLAN radio user equipment and WLAN AP;
The subscriber equipment that has multilink CLIENT PROGRAM (MLC) ability to the HLR authentication; Afterwards
By the first data link tunnel that connects from MLC to RLM described subscriber equipment is connected to core network system.
6. according to the method for claim 5, wherein said authentication step also comprises: connect the second data link tunnel from RLM to the GGSN packet gateway that is used for the global packet data network afterwards.
7. according to the method for claim 5, wherein said authentication step also comprises: connect afterwards from RLM to the second data link tunnel as the internet gateway of a global packet data network part with tunnel ability and address assignment ability.
8. according to the method for claim 7, wherein internet gateway is used second layer host-host protocol.
9. one kind makes the method for subscriber equipment and GSM core network mutual authentication by WLAN radio access network (WLAN RAN), and described GSM core network is supported the GPRS packet oriented protocol, said method comprising the steps of:
Initialization is from the wireless connections request of subscriber equipment;
From subscriber equipment by Radio Link to the radio link manager send identification number (IMSI) and with subscriber-related up-to-date random number (currency); Afterwards
Use IMSI and currency to constitute a conventional connection request; Afterwards
Should send attaching position register to by the routine connection request;
On attaching position register, use 1) the shared key, 2 of subscriber equipment) IMSI and 3) currency generates conventional authentication request, and described conventional authentication request comprises the conventional digital signature as a unit; Afterwards
Send conventional authentication request to the radio link manager; Afterwards
All unit of use currency and conventional authentication request constitute first secure digital signature of described conventional authentication request on the radio link manager; Afterwards
Send first secure digital signature and the amended conventional authentication request of having deleted described conventional digital signature to subscriber equipment;
According to amended conventional authentication request, use and share key, IMSI and currency, candidate's duplicate of the conventional digital signature of structure on subscriber equipment;
On subscriber equipment, use 1) first secure digital signature, 2) candidate's duplicate and 3) amended conventional authentication request verifies candidate's duplicate and amended conventional authentication request, thereby to user equipment authority identification radio link manager; Afterwards
According to the conventional digital signature duplicate after the checking, the conventional authentication request of modification after key, IMSI, currency and the checking, structure second secure digital signature on subscriber equipment are shared in use; Afterwards
Report second secure digital signature to the radio link manager, so that to the authentication of radio link manager verifying user equipment.
10. according to the process of claim 1 wherein that described authentication step comprises:
Initialization is from the wireless connections request of subscriber equipment;
From subscriber equipment by Radio Link to the radio link manager send identification number (IMSI) and with subscriber-related up-to-date random number (currency); Afterwards
Constitute a conventional connection request; Afterwards
Use IMSI and currency to send attaching position register to by the routine connection request;
On attaching position register, use 1) the shared key, 2 of subscriber equipment) IMSI and 3) currency generates conventional authentication request, and described conventional authentication request comprises the conventional digital signature as a unit; Afterwards
Send conventional authentication request to the radio link manager; Afterwards
All unit of use currency and conventional authentication request constitute first secure digital signature of described conventional authentication request on the radio link manager; Afterwards
Send first secure digital signature and the amended conventional authentication request of having deleted described conventional digital signature to subscriber equipment;
According to amended conventional authentication request, use and share key, IMSI and currency, candidate's duplicate of the conventional digital signature of structure on subscriber equipment;
On subscriber equipment, use 1) first secure digital signature, 2) candidate's duplicate and 3) amended conventional authentication request verifies candidate's duplicate and amended conventional authentication request, thereby to user equipment authority identification radio link manager; Afterwards
On the subscriber equipment according to the conventional digital signature duplicate after the checking, the conventional authentication request of use sharing after key and the checking of modification is constructed second secure digital signature; Afterwards
Report second secure digital signature to the radio link manager, so that to the authentication of radio link manager verifying user equipment.
11., also comprise step: use the shared key of between subscriber equipment and HLR, sharing to set up the described first data link tunnel as secure data link tunnel according to the method for claim 1.
12. a system that is used to make WLAN radio access network (WLAN RAN) and supports the GSM core network interconnects of GPRS packet oriented protocol, this system comprises:
Radio access controller (RAC);
Radio link manager (RLM);
WLAN access point (WLAN AP);
GPRS gateway service node (GGSN);
The attaching position register of described core network (HLR);
At least one is used for the WLAN radio user equipment of communicating by letter with WLAN AP;
Be used for the device to HLR authentication user equipment, described subscriber equipment has multilink CLIENT PROGRAM (MLC) ability; With
Be used to use the first data link tunnel from MLC to RLM and to the second data link tunnel of the GGSN packet gateway that is used for the global packet data network subscriber equipment be connected to the device of core network system from RLM.
13. a system that is used to make WLAN radio access network (WLAN RAN) and GSM core network interconnects, this system comprises:
Radio access controller (RAC);
Radio link manager (RLM);
WLAN access point (WLAN AP);
The internet gateway node;
The attaching position register of described core network (HLR);
At least one is used for the WLAN radio user equipment of communicating by letter with WLAN AP;
Be used for the device to HLR authentication user equipment, described subscriber equipment has multilink CLIENT PROGRAM (MLC) ability; With
Be used to use the first data link tunnel from MLC to RLM and to the second data link tunnel of the internet gateway node that is used for the global packet data network subscriber equipment be connected to the device of core network system from RLM.
CN 200410030456 2004-03-15 2004-03-15 Method and system for transparently and safely interconnecting WLAN radio access network with GPRS/GSM core network Pending CN1671119A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN 200410030456 CN1671119A (en) 2004-03-15 2004-03-15 Method and system for transparently and safely interconnecting WLAN radio access network with GPRS/GSM core network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN 200410030456 CN1671119A (en) 2004-03-15 2004-03-15 Method and system for transparently and safely interconnecting WLAN radio access network with GPRS/GSM core network

Publications (1)

Publication Number Publication Date
CN1671119A true CN1671119A (en) 2005-09-21

Family

ID=35042190

Family Applications (1)

Application Number Title Priority Date Filing Date
CN 200410030456 Pending CN1671119A (en) 2004-03-15 2004-03-15 Method and system for transparently and safely interconnecting WLAN radio access network with GPRS/GSM core network

Country Status (1)

Country Link
CN (1) CN1671119A (en)

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101128041B (en) * 2006-08-15 2010-05-12 华为技术有限公司 Processing method and system after downlink data tunnel failure between access network and core network
CN101909074A (en) * 2010-06-17 2010-12-08 中兴通讯股份有限公司 Network access equipment and method for implementing data forwarding between different physical media
CN101202720B (en) * 2006-12-15 2012-01-18 中国电信股份有限公司 Method for establishing gateway equipment and method for processing data of gateway equipment
CN101394652B (en) * 2007-09-21 2012-12-05 上海摩波彼克半导体有限公司 Cellular network and method for realizing optimal resource management in public security wireless network
CN101370155B (en) * 2007-08-15 2013-03-06 上海摩波彼克半导体有限公司 Mutual-operating system and blocking rate confirming method for honeycomb network and public safety network
CN104091374A (en) * 2014-06-17 2014-10-08 东南大学常州研究院 Real-time attendance method adopting GSM/3G mobile phone perception technology
US8898221B2 (en) 2009-03-19 2014-11-25 Telefonaktiebolaget L M Ericsson (Publ) Optimized redirection for network architectures
WO2019047197A1 (en) * 2017-09-11 2019-03-14 Telefonaktiebolaget Lm Ericsson (Publ) Method and system to integrate fixed access into converged 5g core

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101128041B (en) * 2006-08-15 2010-05-12 华为技术有限公司 Processing method and system after downlink data tunnel failure between access network and core network
US10721780B2 (en) 2006-08-15 2020-07-21 Huawei Technologies Co., Ltd. Method, system and device for recovering invalid downlink data tunnel between networks
US9848450B2 (en) 2006-08-15 2017-12-19 Huawei Technologies Co., Ltd. Method, system and device for recovering invalid downlink data tunnel between networks
US8125889B2 (en) 2006-08-15 2012-02-28 Huawei Technologies Co., Ltd. Method, system and device for recovering invalid downlink data tunnel between networks
US8867339B2 (en) 2006-08-15 2014-10-21 Huawei Technologies Co., Ltd. Method, system and device for recovering invalid downlink data tunnel between networks
CN101202720B (en) * 2006-12-15 2012-01-18 中国电信股份有限公司 Method for establishing gateway equipment and method for processing data of gateway equipment
CN101370155B (en) * 2007-08-15 2013-03-06 上海摩波彼克半导体有限公司 Mutual-operating system and blocking rate confirming method for honeycomb network and public safety network
CN101394652B (en) * 2007-09-21 2012-12-05 上海摩波彼克半导体有限公司 Cellular network and method for realizing optimal resource management in public security wireless network
US8898221B2 (en) 2009-03-19 2014-11-25 Telefonaktiebolaget L M Ericsson (Publ) Optimized redirection for network architectures
CN102356616B (en) * 2009-03-19 2014-12-03 瑞典爱立信有限公司 Optimized redirection for network architectures
US9172554B2 (en) 2010-06-17 2015-10-27 Zte Corporation Method and network access device for enabling data forwarding between different physical mediums
WO2011156990A1 (en) * 2010-06-17 2011-12-22 中兴通讯股份有限公司 Method and network access device for enabling data forwarding between different physical media
CN101909074A (en) * 2010-06-17 2010-12-08 中兴通讯股份有限公司 Network access equipment and method for implementing data forwarding between different physical media
CN104091374A (en) * 2014-06-17 2014-10-08 东南大学常州研究院 Real-time attendance method adopting GSM/3G mobile phone perception technology
WO2019047197A1 (en) * 2017-09-11 2019-03-14 Telefonaktiebolaget Lm Ericsson (Publ) Method and system to integrate fixed access into converged 5g core

Similar Documents

Publication Publication Date Title
US9986426B2 (en) Service in WLAN inter-working, address management system, and method
US7155526B2 (en) Method and system for transparently and securely interconnecting a WLAN radio access network into a GPRS/GSM core network
CN1534921B (en) Method of public authentication and authorization between independent networks
EP1330073B1 (en) Method and apparatus for access control of a wireless terminal device in a communications network
CA2249830C (en) Inter-working function selection system in a network
JP4927939B2 (en) Automatic home agent selection
CN1859614B (en) Method, device and system for radio transmission
CN100397835C (en) Restricted WLAN access for unknown wireless terminal
JP2004507973A (en) Generic WLAN architecture
US20070183382A1 (en) Auto-discovery of a non-advertised public network address
CN102318381A (en) Method for secure network based route optimization in mobile networks
JPH11284666A (en) Mobile management system
CN103095654B (en) Virtual local area network (VLAN) configuration method, wireless access point and network control point
CN1579051A (en) Method and system for multicasting messages to select mobile recipients
JPH11275157A (en) Optimum routing system
KR20030019356A (en) Secure dynamic link allocation system for mobile data communication
CN100403714C (en) Wlan tight coupling solution
CN100435518C (en) A communication system and method of authentication therefor
US11316820B2 (en) Registration of data packet traffic for a wireless device
CN101345649A (en) Redundant network system and its processing method
CN1795656A (en) Secure traffic redirection in a mobile communication system
CN1671119A (en) Method and system for transparently and safely interconnecting WLAN radio access network with GPRS/GSM core network
CN1947455B (en) Supporting a network behind a wireless station
CN1643853A (en) Method and system for providing network services
CN1192565C (en) Internet access method based on radio block network gateway

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication