WO2008125062A1 - Procédé de détermination d'admission et de radiomessagerie d'utilisateur dans un système de communication mobile, système et dispositif apparentés - Google Patents

Procédé de détermination d'admission et de radiomessagerie d'utilisateur dans un système de communication mobile, système et dispositif apparentés Download PDF

Info

Publication number
WO2008125062A1
WO2008125062A1 PCT/CN2008/070726 CN2008070726W WO2008125062A1 WO 2008125062 A1 WO2008125062 A1 WO 2008125062A1 CN 2008070726 W CN2008070726 W CN 2008070726W WO 2008125062 A1 WO2008125062 A1 WO 2008125062A1
Authority
WO
WIPO (PCT)
Prior art keywords
imsi
msisdn
admission
list
information
Prior art date
Application number
PCT/CN2008/070726
Other languages
English (en)
French (fr)
Inventor
Guojie Hu
Xianguo Chen
Bo Chen
Tao Qian
Original Assignee
Huawei Technologies Co., Ltd.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CNA2007100969265A external-priority patent/CN101043755A/zh
Application filed by Huawei Technologies Co., Ltd. filed Critical Huawei Technologies Co., Ltd.
Publication of WO2008125062A1 publication Critical patent/WO2008125062A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W68/00User notification, e.g. alerting and paging, for incoming communication, change of service or the like

Definitions

  • the present invention relates to mobile communication technologies, and in particular, to a method, system and apparatus for admitting and locating users in a mobile communication system. Background of the invention
  • a network structure and a corresponding network entity are disclosed, which can provide a capability for a user terminal to directly access the Internet.
  • the network is connected to a Universal Mobile Telecommunications System (UMTS) in the prior art.
  • the access point (AP, Access Point) directly accesses the logical structure of the Internet.
  • This logical structure adds two network entities to the original UMTS network structure: UMTS Access Gateway (AG, Access Gateway) and UMTS AP, and other network entities and interfaces remain unchanged.
  • the UMTS AG network entity completes the Gateway General Packet Radio Service Node (GGSN), the Serving GPRS Support Node (SGSN) control plane function, and the radio network controller. (RNC, Radio Network Controller) Control plane part function, and provides UMTS control plane interface with GGSN/SGSN.
  • RNC Radio Network Controller
  • UMTS AG is similar to RNC function and provides complete voice access function. Specifically, UMTS AG has the following functions: network access control, control plane processing in packet message routing and forwarding, voice conversion and forwarding, mobility management, AP management, billing management, short message service, mobile network enhancement CAMEL (Customized Application for Mobile network Enhanced Logic) business, and network management.
  • the interfaces provided by UMTS AG include: Ga, Gb, Gd, Ge, Gf, Gn control Faces, Gr and Gs, these interfaces use the same protocol stack as the UMTS 3G network and are not described here.
  • the UMTS AP network entity In addition to all the functions of the UMTS responsible for wireless receiving and transmitting, and the RNC part control function, the UMTS AP network entity also has the GGSN, SGSN, and RNC user plane functions for the packet domain. Specifically, the functions of the UMTS AP are as follows: radio access control, user plane processing in packet message routing and forwarding, voice codec, radio resource management, and network management.
  • the UMTS AP provides Gi and Gn user planes externally, and provides the same protocol stack as the existing UMTS 3G network, which will not be described here.
  • Figure 1 is a logical structure diagram of an AP directly accessing the Internet in a UMTS network, similarly,
  • UMTS AG and UMTS AP are also applicable to General Packet Radio Service (GPRS) networks, Code Division Multiple Access (CDMA) networks, Time Division-synchronous Code Division Multiple Access (TD-CDMAD).
  • GPRS General Packet Radio Service
  • CDMA Code Division Multiple Access
  • TD-CDMAD Time Division-synchronous Code Division Multiple Access
  • the Time Division - Synchronize Code Division Multiple Access network can add two network entities, AGs and APs, to the mobile communication system such as GPRS network, CDMA2000 network, and TD-CDMAD network, so that the AP can directly access the Internet.
  • the user equipment (UE, User Equipment) entering the AP cell can directly access the mobile communication system through the AP and the AG.
  • the prior art does not perform admission determination and restriction on the UE that enters the AP cell, and the unlicensed UE accesses the mobile communication system.
  • the network side pages the UE the paging to the unlicensed UE cannot be restricted.
  • the prior art has the following disadvantages: From the user's point of view, the AP is a private device, and does not want others to use it without permission; from the perspective of the operator, the tariff under the AP coverage is greater than the macro network, and it is desirable for the UE using the AP. Limit it. Summary of the invention
  • Embodiments of the present invention provide a method for admission determination in a mobile communication system, which can prevent access by an unlicensed UE.
  • Embodiments of the present invention provide a system for admission determination in a mobile communication system, which can prevent access by unauthorized UEs.
  • the embodiment of the present invention further provides a system for admission determination in a mobile communication system, which is capable of preventing access by an unlicensed UE.
  • An embodiment of the present invention provides an admission determination apparatus for admission determination in a mobile communication system, and the admission determination apparatus can prevent access by an unauthorized UE.
  • the embodiment of the present invention further provides an admission determining device for admission determination in the mobile communication system, and the admission determining device can prevent access by the unlicensed UE.
  • the embodiment of the invention provides a conversion module for admission determination in a mobile communication system, and the conversion module can prevent access by an unlicensed UE.
  • Embodiments of the present invention provide a method for paging a user in a mobile communication system, which can prevent paging to an unlicensed UE.
  • Embodiments of the present invention provide a device for paging a user in a mobile communication system, which system can prevent paging to an unauthorized UE.
  • Embodiments of the present invention provide a device for paging a user in a mobile communication system, which is capable of preventing paging to an unauthorized UE.
  • Embodiments of the present invention provide a device for paging a user in a mobile communication system, which system can prevent paging to an unauthorized UE.
  • a method for admission determination in a mobile communication system comprising:
  • the user identification information access list Obtaining, in the user identification information access list, the user identification information of the user terminal UE that accesses the access point AP of the mobile communication system, whether the obtained user identification information exists, if If yes, the UE is allowed to access, otherwise, the UE is denied access.
  • a system for admission determination in a mobile communication system comprising an admission determination module on the network side and a conversion module on the network side;
  • the admission determination module is configured to query, in the MSISDN admission list, whether there is MSISDN information of the user terminal transmitted by the conversion module, and if yes, allow the user terminal to access; otherwise, the user terminal is denied access;
  • the conversion module is configured to receive IMSI information transmitted by the user terminal, and convert the IMSI information transmitted by the user terminal into MSISDN information of the user terminal.
  • a system for admission determination in a mobile communication system comprising an admission determination module on the network side, configured to receive IMSI information sent by the user terminal, and query in the IMSI admission list whether there is an IMSI transmitted by the user terminal, if present , the user terminal is allowed to access, and the user terminal is denied access.
  • An admission determination device for admission determination in a mobile communication system, the admission determination device comprising a receiving submodule and an admission determination submodule;
  • the receiving submodule is configured to receive MSISDN information of the user terminal transmitted by the conversion submodule, and send the information to the admission judging submodule;
  • the admission judging sub-module is configured to query, in the MSISDN access list, whether the MSISDN information of the user terminal exists, and if yes, allow the user terminal to access, otherwise, the user terminal is denied access.
  • An admission determination device for admission determination in a mobile communication system, the admission determination device comprising a receiving submodule and an admission determination submodule;
  • the receiving submodule is configured to receive an IMSI transmitted by the user terminal, and send the IMSI to the admission determining submodule;
  • the admission determination sub-module is configured to query, in the IMSI admission list, whether an IMSI transmitted by the receiving sub-module exists, and if yes, allow the user terminal to access, otherwise, reject The user terminal is accessed.
  • a conversion device for admission determination in a mobile communication system comprising a receiving sub-module and a conversion sub-module;
  • the receiving submodule is configured to receive IMSI information transmitted by the user terminal, and send the information to the conversion submodule;
  • the conversion submodule is configured to convert the IMSI information of the user terminal into MSISDN information of the user terminal, and send the information to the admission determination submodule for admission determination.
  • Embodiments of the present invention provide a method for paging a user in a mobile communication system, where the method includes:
  • the paging list includes a correspondence between the AP and the IMSI information of the user terminal that is allowed to access the AP, and receives a paging message that is transmitted by the CN side and includes IMSI information;
  • An embodiment of the present invention provides a device for paging a user in a mobile communication system, where the device includes a paging judgment module and a paging message forwarding module;
  • the paging determining module is configured to receive a paging message that includes the IMSI information sent by the CN side, and query, in the paging list, whether the IMSI information exists, where the paging list includes an AP and an IMSI information that allows access to the AP. Corresponding relationship, if yes, transmitting a paging message to the paging message forwarding module, otherwise, not transmitting a paging message to the paging message forwarding module; the paging message forwarding module, configured to send the paging message User paging is performed on the AP corresponding to the IMSI information included in the paging message.
  • Embodiments of the present invention provide a device for paging a user in a mobile communication system, and the device package Including an IMSI information sending module and a paging module;
  • the IMSI information sending module is configured to send the IMSI information of the user terminal that is allowed to access the AP to the AG, to generate a paging list, where the paging list includes the AP and a user terminal that allows access to the AP Correspondence between IMSIs;
  • the paging module is configured to: after receiving, by the AG, the IMSI information included in the paging message in the paging list, send the paging message; and correspond to the IMSI information included in the paging message.
  • the user terminal performs paging.
  • An embodiment of the present invention provides an apparatus for paging a user in a mobile communication system, where the apparatus includes an IMSI admission list sending module and a paging module;
  • the IMSI admission list sending module is configured to send an IMSI admission list to an AG, to generate a paging list, where the paging list includes a correspondence between an AP and an IMSI of a user terminal that allows access to the AP. Relationship
  • the paging module is configured to receive, after the UE queries, in the paging list, the IMSI information included in the presence paging message, send the paging message; and the user terminal corresponding to the IMSI information included in the paging message Paging.
  • the embodiment of the present invention queries whether the obtained user identification information exists in the user identification information admission list, and if yes, allows The UE accesses, otherwise, the UE access is denied.
  • the AG generates a paging list according to the correspondence between the AP and the IMSI information of the user terminal that is allowed to access the AP, and implements paging of the authorized UE in the AP cell by using the paging list.
  • FIG. 1 is a logical structural diagram of an AP directly accessing the Internet in a UMTS network in the prior art
  • FIG. 2 is a flowchart of a method for determining admission in a mobile communication system according to an embodiment of the present invention
  • FIG. 3 is an admission of a mobile communication system according to an embodiment of the present invention
  • FIG. 4 is a flowchart of a method for determining admission in a mobile communication system according to an embodiment of the present invention
  • FIG. 5 is a flowchart of a method for determining admission in a mobile communication system according to an embodiment of the present invention
  • FIG. 6 is a flowchart 5 of a method for determining admission in a mobile communication system according to an embodiment of the present invention
  • FIG. 7 is a schematic structural diagram of a system for admission determination in a mobile communication system according to an embodiment of the present invention.
  • FIG. 7b is a schematic structural diagram of a system for admission determination in a mobile communication system according to an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of an admission determination apparatus for admission determination in a mobile communication system according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram showing the structure of an apparatus for performing admission determination in a mobile communication system according to an embodiment of the present invention.
  • FIG. 10 is an exemplary flowchart of a method for paging a user in a mobile communication system according to an embodiment of the present invention.
  • FIG. 11 is a flowchart of a first embodiment of generating a paging list in step 1001.
  • FIG. 12 is a flowchart of a second embodiment of generating a paging list in step 1001.
  • FIG. 13 is a flowchart of a mobile communication system according to an embodiment of the present invention.
  • Flowchart example of the method of AP authentication 14 is a flowchart of a method for authenticating an AP in a mobile communication system according to an embodiment of the present invention;
  • FIG. 15 is a schematic diagram of a digital certificate issuance structure;
  • Figure 16 is a working principle diagram of a digital certificate
  • FIG. 17 is a schematic structural diagram of a system for paging a user in a mobile communication system according to an embodiment of the present invention. Mode for carrying out the invention
  • the basic idea of the present invention is to query, in the user identification information access list, whether there is user identification information of the user terminal UE accessing the access point AP of the mobile communication system, and if so, allow the UE to access, otherwise, reject The UE is connected.
  • the user identification information access list is an MSISDN admission list
  • the user identification information is MSISDN information
  • the user identification information admission list is an IMSI admission list
  • the user identification information is IMSI information.
  • the method first stores an MSISDN (Mobile Station International ISDN Number) access on the AP side.
  • MSISDN admission list contains the MSISDNs of all the UEs that are allowed to access the AP.
  • the AP side can change the MSISDN admission list as needed.
  • the method includes the following steps:
  • the AP side modifies the MSISDN admission list, and the access control list update message (Access Control List Update) is transmitted to the core network (CN, Core Network) side network element by the AG, and the message includes the MSISDN modified by the AP side.
  • the CN side network element saves the MSISDN admission list after receiving the message.
  • the CN side network element described in this embodiment may be a visitor location register/Mobile Switching Centre Server (VLR/MSC) or an SGSN on the CN side.
  • Control List Update Rsp indicating that the MSISIDN admission list transmitted by the AP side has been saved.
  • Step 203 After the UE that enters the AP cell establishes a wireless connection with the AP, sends an attach request message (Attach Request) to the CN side network element, where the message includes the IMSI information of the UE.
  • Attach Request an attach request message
  • Step 204 The CN side network element receives the Attach Request sent by the UE, and obtains the IMSI information, and then initiates a location update process to the HLR. After the location update process ends, the CN side network element obtains the MSISDN information of the UE from the HLR.
  • the location update process is: the CN side network element sends a location update message (Update Location) to the HLR, where the message includes the IMSI information of the UE, and is used to query the MSISDN information corresponding to the IMSI according to the IMSI information; After receiving the IMSI information, the HLR queries the MSISDN information corresponding to the IMSI of the UE, and returns an Insert Subscriber Data message to the CN side network element, where the message includes the MSISDN information of the UE; After receiving the Insert Subscriber Data, the HLR sends an Insert Subscriber Data Response message (Incoming Subscriber Data Rsp) to notify the IMSI information. The HLR sends a Location Update Confirmation message (Update Location Cnf) to the CN side network element, indicating that the location update process ends. .
  • Update Location Cnf Location Update Confirmation message
  • Step 205 The CN side network element determines, according to the MSISDN information of the UE acquired from the HLR, and the MSISDN admission list saved in step 201, whether to allow access of the UE, and correspondingly sends an attach reception message/attachment rejection to the UE side.
  • Message (Attach Accept/Attach Rej ect ).
  • the method for determining whether to allow the UE to access is: the CN side network element queries the access list of the MSISDN to check whether there is an MSISDN of the UE received from the HLR, and if yes, allows the UE to access, otherwise , reject the UE access.
  • the AG and CN side network element devices in this embodiment may be divided into two devices as shown in FIG. 2, or may be integrated into one device.
  • the method first saves an MSISDN admission list on an AP side, where the MSISDN admission list includes all UEs that are allowed to access the AP. On the MSISDN, the AP side can change the MSISDN access list as needed.
  • the method includes the following steps:
  • Step 301 After establishing a wireless connection with the AP, the UE sends an Init UE Message (Attach Request) to the AP.
  • An Init UE Message (Attach Request)
  • Step 302 After receiving the Init UE Message (Attach Request), the AP sends a User Identity Request message ( Identity Request) to the UE to obtain the IMSI of the UE.
  • Identity Request a User Identity Request message
  • the user IMSI is the IMSI of the UE camping in the AP cell.
  • Step 303 The UE returns a user identity response message (ID Response) to the AP, where the message includes the IMSI information of the UE.
  • ID Response user identity response message
  • Step 304 The AP acquires the IMSI information of the UE, and sends an MSISDN query request message (Query MSISDN Request) to the AG, where the message includes the IMSI information of the UE, and is used to query the MSISDN information of the UE according to the IMSI of the UE.
  • Query MSISDN Request MSISDN query request message
  • the AP side has saved the MSISDN-based access list, but there is no MSISDN -
  • the IMSI corresponds to the relationship, so the AP sends a Query MSISDN Request message to the AG to obtain the IMSI-MSISDN correspondence according to the IMSI of the user.
  • Step 305 The AG initiates a location update process to the HLR according to the received IMSI information of the UE. After the location update process ends, the AG acquires an IMSI-MSISDN correspondence.
  • the location update process is:
  • the AG sends a location update request to the HLR.
  • Update message the message includes the IMSI information of the UE, and is used to query the MSISDN information corresponding to the IMSI according to the IMSI information;
  • the HLR receives the Update Location, and obtains the MSISDN information corresponding to the IMSI of the UE after acquiring the IMSI information.
  • the Insert Subscriber Data message is returned to the AG, and the message includes the IMSI-MSISDN correspondence relationship;
  • the AG receives the Insert Subscriber Data and sends the Insertion Contract Data Response message to the HLR (Insert Subscriber Data) Rsp), indicating that the IMSI information has been obtained;
  • the HLR sends a Location Update Confirmation message (Update Location Cnf) to the AG side, indicating that the location update process ends.
  • Step 306 The AG returns an MSISDN Query Response message (Query MSISDN Response) to the AP, where the IMSMS-MSISDN correspondence relationship is included.
  • Step 307 After obtaining the IMSI-MSISDN correspondence, the AP determines whether to allow the UE to access according to the saved MSISDN admission list and the IMSI of the UE obtained in step 303. If the UE is not allowed to access, the AP sends an attachment to the UE. Reject the message, reject the access of the UE, and end the process; otherwise, the user message (Attachment Receive) is initialized by the AG to the CN side network element, and the CN side network element receives the Init UE Message (Attach Request) After that, the direct transfer (Attachment Accept) is transmitted to the UE, and the access of the UE is received.
  • the user message (Attachment Receive) is initialized by the AG to the CN side network element, and the CN side network element receives the Init UE Message (Attach Request)
  • the direct transfer (Attachment Accept) is transmitted to the UE, and the access of the UE is received.
  • the CN side network element described in this embodiment may be a VLR/MSC or an SGSN.
  • the method for determining whether to allow the UE to access according to the saved MSISDN admission list and the IMSI of the UE obtained in step 303 is: According to the IMSI-MSISDN correspondence relationship, The MSISDN information corresponding to the IMSI of the UE is obtained. If the obtained MSISDN information of the UE is queried in the MSISDN admission list saved by the AP, the UE is allowed to access, otherwise the UE is denied access.
  • the AP may further include the acquired IMSI-MSISDN correspondence relationship.
  • the AP receives the Init UE Message (Attach Request) sent by the UE next time, the AP can Steps 304-306 are omitted, and the process directly proceeds to step 307 to determine whether access of the UE is allowed.
  • the step may further include: for the UE that is not allowed to access, the AP side keeps the IMSI-MSISDN correspondence information of the UE in the blacklist. When these UEs access the AP again next time, steps 304-306 may be omitted, and the AP directly rejects these UEs.
  • the method first saves an MSISDN admission list on an AP side, where the MSISDN admission list includes all UEs that are allowed to access the AP.
  • the AP side can change the MSISDN access list as needed. The method includes the following steps:
  • Step 401 After establishing a wireless connection with the AP, the UE sends an Init UE Message (Attach Request) to the AP.
  • Init UE Message (Attach Request)
  • Step 402 After receiving the Init UE Message (Attach Request), the AP sends a User Identity Request message ( Identity Request) to the UE to obtain the IMSI of the UE.
  • Identity Request a User Identity Request message
  • the user IMSI is the IMSI of the UE camping in the AP cell.
  • Step 403 The UE returns a user identity response message (ID Response) to the AP, where the message includes the IMSI information of the UE.
  • ID Response user identity response message
  • Step 404 The AP acquires the IMSI information of the UE, and sends an MSISDN query request message (Query MSISDN Request) to the AG, where the message includes the IMSI information of the UE, and is used to query the MSISDN information of the UE according to the IMSI of the UE.
  • Query MSISDN Request MSISDN query request message
  • the MSISDN-based access list has been saved on the AP. However, the MSISDN-IMSI mapping is not available. Therefore, the AP sends a Query MSISDN Request message to the AG to obtain the IMSI-MSISDN correspondence based on the user's IMSI.
  • Step 405 The AG sends a Gr interface MSISDN query request message (Gr Query MSISDN Request) to the HLR according to the received IMSI information of the UE, and uses the Gr between the AG and the HLR, where the message includes the IMSI information of the UE, where The MSISDN information corresponding to the IMSI is queried according to the IMSI information.
  • Step 406 After receiving the Gr Query MSISDN Request sent by the AG, the HLR queries the MSISDN information corresponding to the IMSI of the UE, that is, the IMSI-MSISDN correspondence, and returns a Gr interface MSISDN query response message (Gr Query MSISDN Response) to the AG.
  • the message contains the IMSI - MSISDN correspondence.
  • Step 407 After obtaining the IMSI-MSISDN correspondence, the AG returns an MSISDN Query Response message (Query MSISDN Response), which includes the queried IMSI-MSISDN correspondence.
  • Query MSISDN Response MSISDN Query Response message
  • Step 408 After obtaining the IMSI-MSISDN correspondence, the AP determines whether to allow the UE to access according to the saved MSISDN admission list and the IMSI of the UE obtained in step 403. If the UE is not allowed to access, the AP sends an attachment to the UE. Reject the message, reject the access of the UE, and end the process; otherwise, the user message (Attachment Receive) is initialized by the AG to the CN side network element, and the CN side network element receives the Init UE Message (Attach Request) After that, the direct transfer (Attachment Accept) is transmitted to the UE, and the access of the UE is received.
  • the user message (Attachment Receive) is initialized by the AG to the CN side network element, and the CN side network element receives the Init UE Message (Attach Request)
  • the direct transfer (Attachment Accept) is transmitted to the UE, and the access of the UE is received.
  • the CN side network element described in this embodiment may be a VLR/MSC or an SGSN.
  • the method for determining whether to allow the UE to access according to the saved MSISDN admission list and the IMSI of the UE obtained in step 403 is: According to the IMSI-MSISDN correspondence relationship, The MSISDN information corresponding to the IMSI of the UE is obtained. If the obtained MSISDN information of the UE is queried in the MSISDN admission list saved by the AP, the UE is allowed to access, otherwise the UE is denied access.
  • the AP may further include the acquired IMSI-MSISDN correspondence relationship.
  • the AP may omit the steps 404 to 407, and directly proceeds to step 408 to determine whether the UE is allowed to access.
  • This step may further include: for the UE that is not allowed to access, The AP side keeps the IMSI-MSISDN correspondence information of the UE in the blacklist. When these UEs are connected from the AP next time, At the time of entry, steps 404 - 407 may be omitted, and the AP directly rejects these UEs.
  • the method first saves an MSISDN admission list on an AP side, where the MSISDN admission list includes all UEs that are allowed to access the AP. On the MSISDN, the AP side can change the MSISDN access list as needed.
  • the method includes the following steps:
  • Step 501 The AP sends an IMSI Query Request message (Query IMSI Request) to the AG, where the message includes the MSISDN information of the MSISDN admission list stored in the AP, and is used to query the correspondence between the MSISDN and the IMSI, that is, the query and the MSISDN standard.
  • the IMSI information corresponding to the MSISDN information of the list.
  • Step 502 The AG sends a Gr interface IMSI query request message (GrQuery Query IMSI Request) to the HLR according to the received MSISDN information, and uses the message interface Gr between the AG and the HLR, where the message includes the MSISDN information of the MSISDN admission list. It is used to query the IMSI information corresponding to the MSISDN information according to the MSISDN information.
  • Gr interface IMSI query request message GrQuery Query IMSI Request
  • Step 503 After receiving the Gr Query IMSI Request sent by the AG, the HLR queries the IMSI information corresponding to the MSISDN information, that is, the IMSI-MSISDN correspondence, and returns a Gr Interface IMSI Query Response message (Gr Query IMSI Response) to the AG.
  • the IMSI-MSISDN correspondence is included.
  • Step 504 After obtaining the IMSI-MSISDN correspondence, the AG returns an IMSI query response message (Query IMSI Response), which includes the queried IMSI-MSISDN correspondence relationship, and after receiving the IMSI-MSISDN correspondence relationship, the UE is based on the IMSI- The MSISDN correspondence generates an IMSI-based admission list.
  • Query IMSI Response IMSI query response message
  • Step 505 After establishing a wireless connection with the AP, the UE sends an Init UE Message (Attach Request) to the AP.
  • Step 506 The AP sends a User Identity Request message ( Identity Request) to the UE to obtain the IMSI of the UE.
  • Identity Request a User Identity Request message
  • the user IMSI is the IMSI of the UE camping in the AP cell.
  • Step 507 The UE returns an identifier request response message (Identity Request Response) to the AP, where the message includes the IMSI information of the UE.
  • Step 508 The AP determines whether to access the user according to the IMSI admission list generated in step 504 and the IMSI of the UE obtained in step 507. If the UE is not allowed to access, the AP sends an attach rejection message to the UE, rejecting the UE. If the Init UE message (Attach Request) is forwarded to the CN side NE, the CN side NE receives the Init UE Message (Attach Request), and then goes to the UE. The terminal sends a direct transfer (Attach Accept) to receive the access of the UE.
  • the CN side network element described in this embodiment may be a VLR/MSC or an SGSN.
  • the method configures and stores an IMSI admission list corresponding to each AP on an AG, or an AP home register (AHR, AP).
  • the IMSI admission list corresponding to each AP is configured in the home register, and the AG obtains and stores an IMSI admission list corresponding to each AP from the AHR, where the IMSI admission list includes IMSIs of all UEs that are allowed to access the AP.
  • the method includes the following steps:
  • Step 601 After the UE establishes a wireless connection with the AP, the UE sends an Init UE message (Attach Request) to the AP. After receiving the Init UE Message (Attach Request), the AP forwards the message to the AG.
  • Attach Request Init UE message
  • Step 602 After receiving the Init UE Message ( Attach Request), the AG sends the message to the UE.
  • a user identification request message ( Identity Request) is sent to obtain the IMSI of the UE.
  • the user IMSI is the IMSI of the UE camping in the AP cell.
  • Step 603 The UE returns a user identity response message (ID Response) to the AG, where the message includes the IMSI information of the UE.
  • ID Response user identity response message
  • Step 604 The AG determines whether to access the user according to the saved IMSI admission list and the obtained IMSI of the UE. If the UE is not allowed to access, the AG sends an attach reject message to the UE, rejects the access of the UE, and ends the process. Otherwise, the Init UE Message (Attach Request) is sent to the CN side network element. After receiving the Init UE Message (Attach Request), the CN side network element sends a direct transmission message to the UE (attached reception). (Direct Transfer ( Attach Accept)), receiving access from the UE.
  • the CN side network element described in this embodiment may be a VLR/MSC or an SGSN.
  • the IMSI admission list can be saved on the AP side to directly implement user admission.
  • the method first saves an IMSI admission list in the AP.
  • the IMSI admission list includes the IMSI of all UEs that are allowed to access the AP.
  • the AP side can change the IMSI admission list as needed.
  • the method includes the following steps: After the UE establishes a wireless connection with the AP, the UE sends an Init UE Message (Attach Request) to the AP.
  • the AP sends a User Identity Request message ( Identity Request) to the UE to obtain the UE.
  • the AP determines whether to access the user according to the IMSI admission list and the obtained IMSI of the UE. If the UE is not allowed to access, the AP sends an attach reject message to the UE, rejects the access of the UE, and ends the process; otherwise, the process is initialized.
  • the user message (Attach Request) is forwarded to the CN side network element by the AG. After receiving the Init UE Message (Attach Request), the CN side network element returns a direct transmission message to the UE (attached reception). (Direct Transfer (Attach Accept)), receiving access of the UE.
  • FIG. 7A is a schematic structural diagram of a system for admission determination in a mobile communication system according to an embodiment of the present invention.
  • the system includes an admission determination module on the network side, a conversion module on the network side, and a UE.
  • the admission determination module is configured to query, in the MSISDN admission list, whether there is an MSISDN of the UE transmitted by the conversion module, and if yes, allow the UE to access, otherwise, the UE is denied access.
  • a conversion module configured to convert the IMSI information transmitted by the UE into the MSISDN of the UE.
  • the UE is configured to transmit the IMSI information of the UE to the admission conversion module.
  • the UE is a UE that enters the AP cell of the mobile communication system
  • the admission determination module is set in the admission determination network element
  • the admission determination network element may be the CN side network element or the AP, and the network element is determined according to the admission.
  • the system shown in Figure 7a is divided into the following three cases:
  • the first case is a first case:
  • the admission determination module is set in the CN side network element, and the conversion module is set in the HLR.
  • the system can further include an AP and an AG.
  • the MSISDN admission list information is stored in the AP.
  • the MSISDN admission list contains the MSISDNs of all the UEs that are allowed to access the AP.
  • the AP side can change the MSISDN admission list as needed.
  • the AP side sends the MSISDN admission list update message. It is transmitted to the admission determination module via the AG, and the message includes the MSISDN admission list information.
  • the conversion module is configured to: after obtaining the IMSI information of the UE from the admission determination module, query the MSISDN information corresponding to the IMSI of the UE, and return an insertion subscription data message to the admission determination module, where the message includes the MSISDN information of the UE.
  • the admission determination module is configured to save the MSISDN admission list information transmitted from the AP, and send a location update message to the conversion module, where the message includes the IMSI information of the UE;
  • the MSISDN information of the UE transmitted by the module is queried in the MSISDN admission list to check whether the MSISDN of the UE exists. If yes, the UE is allowed to access. Otherwise, the UE is denied access.
  • the above AG and CN side network elements can be two devices or integrated into one combined device.
  • the CN side network element can be a VLR/MSC or an SGSN.
  • the second case is a first case
  • the admission determination module is set in the AP, and the conversion module is set in the HLR.
  • the MSISDN access list is stored in the AP and contains MSISDNs of all UEs that are allowed to access the AP.
  • the AP side can change this MSISDN admission list as needed.
  • the system can further include an AG and a CN side network element.
  • An AG configured to send a location update request message to the conversion module according to the IMSI information of the UE that is sent by the admission determination module, where the message includes the IMSI information of the UE; and after receiving the insertion subscription data message that is returned by the conversion module and including the IMSI-MSISDN correspondence relationship, And transmitting, to the admission determination module, an MSISDN query response message including the IMSI-MSISDN correspondence.
  • the conversion module is configured to receive the location update request message that is sent by the AG and includes the IMSI information of the UE. After obtaining the IMSI information, query the MSISDN information corresponding to the IMSI of the UE, that is, the IMSI-MSISDN correspondence, and return the insertion subscription data to the AG. Message, the message contains the IMSI-MSISDN correspondence.
  • the CN side network element is configured to receive an initial user message transmitted by the access judgment module after receiving the information of the UE, and then receive the access of the UE; otherwise, the UE is denied access.
  • the admission determination module makes a judgment, the specific process of initializing the user message is transmitted to the CN side network element by the AG, and the description at step 307 is performed.
  • the above CN side network element may be a VLR/MSC or an SGSN.
  • the admission determination module can save the acquired IMSI-MSISDN correspondence.
  • the admission determination module can directly judge Whether the access of the UE is allowed to be disconnected does not need to query the AG for the IMSI-MSISDN correspondence.
  • the admission determination module may also retain the IMSI-MSISDN correspondence information of the UEs that are not allowed to access in the blacklist.
  • the admission determination module directly rejects the UEs, and does not need to The AG queries the IMSI - MSISDN correspondence.
  • the third case is a first case.
  • the admission determination module is set in the AP, and the conversion module is set in the HLR.
  • the MSISDN access list is stored in the AP and contains MSISDNs of all UEs that are allowed to access the AP.
  • the AP side can change this MSISDN admission list as needed.
  • the system can further include an AG and a CN side network element.
  • An AG configured to send a Gr interface MSISDN query request message to the conversion module according to the IMSI information of the UE that is sent by the admission determination module, where the message includes the IMSI information of the UE; and the Gr interface that includes the IMSI-MSISDN correspondence returned by the conversion module After the MSISDN query response message, the MSISDN query response message including the IMSI-MSISDN correspondence relationship is transmitted to the admission determination module;
  • the conversion module is configured to receive the Gr interface MSISDN query request message that is sent by the AG and includes the IMSI information of the UE. After obtaining the IMSI information, query the MSISDN information corresponding to the IMSI of the UE, that is, the IMSI-MSISDN correspondence, and return the Gr to the AG.
  • the interface MSISDN queries the response message, and the message includes the IMSI-MSISDN correspondence.
  • the CN side network element is configured to receive an initial user message that is sent by the access determining module and that includes the information about receiving the UE, and then receive the access of the UE; otherwise, the UE is denied access.
  • the admission determination module performs the judgment, the specific process of initializing the user message is transmitted to the CN side network element by the AG, and the description at step 408 is performed.
  • the above CN side network element may be a VLR/MSC or an SGSN.
  • the admission determination module can save the acquired IMSI-MSISDN correspondence.
  • the admission determination module can directly judge Whether the access of the UE is allowed to be disconnected does not need to query the AG for the IMSI-MSISDN correspondence.
  • the admission determination module may further retain the IMSI-MSISDN correspondence information of the UEs that are not allowed to access in the blacklist.
  • the admission determination module directly rejects the UEs, and does not need to The AG queries the IMSI - MSISDN correspondence.
  • FIG. 7B is a schematic diagram showing a schematic diagram of a structure of a system for admission determination in a mobile communication system according to an embodiment of the present invention, where the system includes an admission determination module and a UE on the network side;
  • the admission determination module is configured to query, in the IMSI admission list, whether there is an IMSI of the UE transmitted by the UE, and if yes, allow the UE to access, otherwise, the UE is denied access.
  • the UE is configured to transmit the IMSI information of the UE to the admission determination module.
  • the UE is a UE that enters the AP cell of the mobile communication system, and the admission determination module is set in the AP.
  • the system shown in Fig. 7b includes the fourth, fifth and sixth cases of the admission determination system in the mobile communication system of the embodiment of the invention:
  • the MSISDN admission list is stored in the AP.
  • the MSISDN admission list contains the MSISDNs of all UEs that are allowed to access the AP.
  • the AP side can change the MSISDN admission list as needed.
  • the system can further include an AG, an HLR, and a CN side network element.
  • An AG configured to receive an IMSI query request message that includes the MSISDN information of the MSISDN admission list sent by the admission determination module, and send a Gr interface IMSI query request message that includes the MSISDN information to the HLR; and receive the IMIR-MSISDN returned by the HLR. Corresponding relationship of the Gr interface IMSI query response message; sending an IMSI query response message including the IMSI-MSISDN correspondence to the admission determination module.
  • the HLR is configured to receive the IMSI query request message of the MSISDN information of the MSISDN access list, and obtain the IMSI information corresponding to the MSISDN information, that is, the IMSI-MSISDN corresponding to the MSISDN information of the MSISDN access list.
  • the device returns a Gr interface IMSI query response message to the AG through the Gr interface between the HLR and the AG, where the message includes the IMSI-MSISDN correspondence.
  • the CN side network element is configured to receive an initial user message transmitted by the access judgment module after receiving the information of the UE, and then receive the access of the UE; otherwise, the UE is denied access.
  • the admission judgment module makes a judgment, the specific process of initializing the user message is transmitted to the CN side network element by the AG, and the description at step 508 is performed.
  • the admission determination module is configured to generate an IMSI-based admission list according to the IMSI-MSISDN correspondence transmitted by the AG. See the description at step 504 for its specific generation.
  • the above CN side network element may be a VLR/MSC or an SGSN.
  • the IMSI admission list is stored in the AG. This IMSI admission list contains the IMSI of all UEs that are allowed to access the AP.
  • the system may further include a CN side network element.
  • the CN side network element is configured to receive an initial user message that is sent by the admission determination module and that includes the information about the UE, and then receive the access of the UE; otherwise, the UE is denied access.
  • the above CN side network element may be a VLR/MSC or an SGSN.
  • the IMSI admission list is stored in the AP.
  • This IMSI admission list contains the IMSI of all UEs that are allowed to access the AP.
  • the AP side can change this IMSI admission list as needed.
  • the system may further include an AG and a CN side network element.
  • the CN side network element is configured to receive an initial user message transmitted by the access judgment module after receiving the information of the UE, and then receive the access of the UE; otherwise, the UE is denied access.
  • the above CN side network element may be a VLR/MSC or an SGSN.
  • FIG. 8 is a schematic structural diagram of an admission determination apparatus for admission determination in a mobile communication system according to an embodiment of the present invention.
  • the admission determination apparatus includes a receiving submodule and an admission determination submodule;
  • the receiving submodule is configured to receive MSISDN information of the user terminal transmitted by the conversion submodule, and transmit the information to the admission judging submodule.
  • the admission judging sub-module is configured to query, in the MSISDN admission list, whether there is MSISDN information of the user terminal transmitted by the receiving sub-module, and if yes, allow the user terminal to access, otherwise, the user terminal is denied access.
  • the admission judgment sub-module can be set in the CN side network element.
  • the admission judging means is equivalent to the admission judging module in the first case described in relation to Fig. 7a.
  • the admission determination sub-module may also be set in the access point, and the MSISDN admission list is stored in the admission determination sub-module.
  • the admission determination means corresponds to the admission determination module in the second and third cases of Fig. 7a.
  • the admission judging means is the same as the structure diagram shown in FIG. 8, and the admission judging means includes a receiving sub-module and an admission judging sub-module.
  • the receiving submodule is configured to receive the IMSI transmitted by the user terminal, and send the IMSI to the admission determining submodule.
  • the admission determination sub-module is configured to query, in the IMSI admission list, whether there is an IMSI transmitted by the receiving sub-module, and if yes, allow the user terminal to access, otherwise, the user terminal is denied access.
  • the admission determination sub-module may be set in the access point to generate the IMSI admission list according to the saved MSISDN admission list and the IMSI-MSISDN correspondence transmitted by the AG.
  • the admission judging means is specifically equivalent to the admission judging module in the fourth case described in relation to Fig. 7b.
  • the conversion apparatus includes a receiving submodule and a conversion submodule.
  • the receiving submodule is configured to receive the IMSI information transmitted by the user terminal and transmit the information to the conversion submodule.
  • the conversion submodule is configured to convert the IMSI information of the user terminal into MSISDN information of the user terminal, and send the information to the admission determination submodule for admission determination.
  • the conversion sub-module can be placed in the HLR.
  • the conversion means is equivalent to the conversion modules in the first, second, and third cases described in relation to Fig. 7a.
  • the above solution of the embodiment of the present invention is applicable to a mobile communication system such as a UMTS network, a GPRS network, a CDMA2000 network or a TD-SCDMA network in which a network entity AP is added.
  • a mobile communication system such as a UMTS network, a GPRS network, a CDMA2000 network or a TD-SCDMA network in which a network entity AP is added.
  • the admission determining network element obtains the IMSI information of the UE from the UE accessing the AP cell of the mobile communication system, and determines whether to allow the UE to access according to the admission list and the IMSI information, so that the system is enabled.
  • the access of the unlicensed UE is rejected, and the AP user does not have to pay the communication fee caused by the misuse of the unlicensed UE, and also implements the limitation of the operator to the UE using the AP.
  • the prior art not only does not provide an admission determination for the UE entering the AP cell, but also does not provide a user paging scheme when the AG receives the paging message sent by the CN side.
  • the MSC when the MSC pages the user, the MSC sends a paging message to the RNC, and carries the IMSI and the location area identification code (LAI) in the paging message.
  • LAI location area identification code
  • the RNC determines whether the UE corresponding to the IMSI has other CN domains.
  • the signaling connection for example, establishes a signaling connection with the SGSN, and if so, pages the user directly on the signaling connection; otherwise, the RNC sends a broadcast message within the location area or routing area to page the user.
  • FIG. 10 it is an exemplary flowchart of a method for paging a user in a mobile communication system according to an embodiment of the present invention.
  • the method includes the following steps:
  • Step 1001 The AG generates a paging list, and receives the IMSI information transmitted by the CN side.
  • the paging message includes the correspondence between the AP and the IMSI information of the user terminal that is allowed to access the AP.
  • Step 1002 The UE determines whether the UE corresponding to the IMSI information included in the paging message has a signaling connection with another CN domain, and if so, directly pages the user on the signaling connection; otherwise, performs steps 1003. This step is optional.
  • Step 1003 The AG queries, in the paging list, whether the IMSI information included in the paging message exists, and if yes, transmits the paging message to the IMSI information corresponding to the IMSI information included in the paging message.
  • the AP performs paging of the user; otherwise, the paging message is refused to be transmitted to the AP corresponding to the IMSI information included in the paging message, and the user is paged, and the process ends.
  • the AP when the AP performs paging, the AP broadcasts a paging message within its coverage, and pages the user with the IMSI information included in the paging message.
  • a flowchart of a specific implementation manner 1 of generating a paging list in step 1001 includes the following steps:
  • Step 1101 After the UE that enters the AP cell establishes a wireless connection with the AP, it sends an RRC Initial Resource Transfer (RRC) message to the AP, where the message includes a location area update request. ( LA/RA Update Request ).
  • RRC RRC Initial Resource Transfer
  • Step 1102 The AP sends an RRC Direct Transfer message to the UE, where the message includes an identity request ( Identity Request).
  • Step 1103 After receiving the RRC Direct Transfer sent by the AP, the UE sends an RRC Direct Response Transfer message (RRC Direct Response Transfer) to the AP, where the message includes an Identity Response (ID Response), where the identifier response includes the IMSI information of the UE.
  • RRC Direct Response Transfer RRC Direct Response Transfer message
  • ID Response Identity Response
  • Steps 1101 to 1103 are procedures for the AP to obtain the IMSI information of the UE.
  • Step 1104 The AP determines whether access of the UE is allowed, and if allowed, sends the message to the AG. Send an IMSI Association Update message (IMSI Association Update), which contains the IMSI information of the UE.
  • IMSI Association Update IMSI Association Update
  • Step 1105 The AG receives the IMSI information transmitted by the AP, and saves the correspondence between the IMSI information and the AP that transmits the IMSI information, that is, generates a paging list.
  • FIG. 12 is a flow chart of the second embodiment of generating a paging list in step 1001
  • the following steps are performed:
  • Step 1201 The AP sends an IMSI association update indication message to the AG (IMSI Association)
  • the message contains the latest IMSI access list saved.
  • Step 1202 The AG saves the correspondence between the IMSI information in the received IMSI admission list and the AP that sends the IMSI admission list, that is, generates a new paging list, and returns an IMSI association update confirmation message to the AP ( IMSI Association Update ACK) indicates that the AG has received an updated IMSI admission list.
  • the AG When the AG detects that the AP is powered off, it deletes the paging list.
  • steps 1201 to 1202 are performed.
  • the AG does not delete the IMSI admission list.
  • steps 1201 ⁇ 1202 can be replaced by:
  • the AG When the AG checks that the IMSI admission list saved by the AP changes, the AG sends an association synchronization request message (IMSI Association Sync Request) to the AP;
  • IMSI Association Sync Request an association synchronization request message
  • the AP After receiving the IMSI Association Sync Request, the AP transmits the IMSI access list updated by the AP to the AG;
  • the AG saves the correspondence between the IMSI information in the received IMSI admission list and the AP that sends the IMSI admission list, that is, generates a new paging list; returns an IMSI Association Update Confirmation message to the AP (IMSI Association Update ACK) ), indicating that the AG has received an updated IMSI admission list.
  • the method for paging a user in the mobile communication system in the embodiment of the present invention may also be: when the AP accesses the mobile communication system by the AG, the location area or routing area information of the AP is transmitted to the AG; the AG receives the IMSI information transmitted by the CN side. Paging message, the paging message further includes location area or routing area information corresponding to the IMSI information, that is, location area or routing area information of the UE that needs to be paged; the AG transmits and receives the paging message to and includes The user is paged in the location area or the AP corresponding to the routing area information in the paging message. It should be noted that the same location area or routing area information may correspond to multiple APs.
  • the process of authenticating the AP may be included before the admission determination or before the paging user.
  • the following describes the AP authentication method in the mobile communication system according to the embodiment of the present invention.
  • FIG. 13 is a flowchart of a method for authenticating an AP in a mobile communication system according to an embodiment of the present invention, the method includes the following steps:
  • Step 1301 The AP sends an AP Authentication Initialization Request message to the AG, and requests the AG to authenticate the AP.
  • the message includes the UMTS Subscriber Identity Module (USIM) card number.
  • USIM UMTS Subscriber Identity Module
  • the USIM card number includes an AP identifier, and one AP identifier corresponds to one AP.
  • Step 1302 The AG sends an Authentication Info Request message to the HLR, requesting to obtain an authentication set from the HLR, where the Authentication Info Request includes an AP identifier.
  • the authentication set may be a five-yuan authentication group or a ternary authentication group.
  • Five yuan authentication The parameters included in the group are random number ( RAND , Random Number ), authentication token (AUTN , Authentication Token ), expected response (XRES , Expectation Response ), encryption key ( CK, Ciphering Key ), and integrity key ( IK, Integrity Key), the ternary authentication group includes parameters RAND, encryption key (KC, Ciphering Key) and XRES.
  • the interface for transmitting messages between the AG and the HLR can use the standard interface in the 3GPP 29.002 protocol.
  • Each set of parameters of the authentication set corresponds to an AP identifier.
  • Step 1303 The AG receives an authentication data response message (Authentication Info response) returned by the HLR, where the message includes an authentication set response, where the response may include a five-member authentication group, and may also include a ternary authentication group.
  • the message may include a message that the authentication set fails to be obtained. If the authentication set response includes a five-member authentication group or a ternary authentication group, step 1304 is performed, if the authentication set response includes a message that the authentication set fails to be obtained. , then the process ends.
  • Step 1304 the AG sends an ⁇ authentication request message to the ( (AP Authentication)
  • the AP authentication request message includes RAND and AUTN parameters, and if the authentication set in step 1303 includes a ternary authentication group, the AP The REN parameter is included in the right request message.
  • Step 1305 After receiving the AP Authentication Request, the AP sends the message to the AG.
  • AP Authentication Response which contains the authentication response (RES, Response) parameter.
  • the step may further include: if the AP sends an AP Authentication Response timeout to the AG, the AG sends an AP authentication initialization confirmation message to the AP (AP Authentication).
  • Step 1306 the AG compares whether the received RES parameter transmitted by the AP is the same as the XRES parameter included in the authentication set acquired from the HLR in step 1302. If they are the same, The authentication succeeds by sending an AP Authentication Initialization Acknowledge to the AP, where the message carries the cause value indicating that the authentication succeeds; if not, the authentication fails, and the AP Authentication Initialization Acknowledge is sent to the AP, and the message carries the cause value indicating that the authentication fails.
  • the AP is a rogue AP and sends an Authentication Failure Report to the HLR.
  • the above is the process of authenticating the AP to the AP through the USIM card of the AP.
  • the USIM card of the AP can also implement the authentication of the AP by the AP.
  • the process is similar and will not be described here.
  • the AP may also use the Subscriber Identity Module (SIM) to implement the authentication of the AP by the AG.
  • SIM Subscriber Identity Module
  • the authentication process is similar to that of FIG. 13, except that the authentication set involved in steps 1302, 1303, and 1304 is involved. It can only be a ternary authentication group.
  • the advantage of the SIM card is that the price is cheaper than the USIM card.
  • the disadvantage is that the SIM card cannot support the AP to authenticate the AG.
  • an AP name register (AHR, AP Home register) stores a user name of an AP that allows authentication.
  • the password includes the following steps: Step 1401: The AP sends an AP Authentication Initialization Request message to the AG, and requests the AG to authenticate the AP.
  • the message includes the AP identifier.
  • the AP identifies the username and password corresponding to the AP.
  • Step 1402 The AG sends an Authentication Data Request message to the AHR, where the message includes an AP identifier, and requests the AHR to authenticate the AP.
  • Step 1403 After receiving the Authentication data request including the AP identifier, the AHR queries the user name and password corresponding to the AP identifier, and returns an authentication data response message (AG) to the AG, where the message includes the query. Username and password.
  • AG authentication data response message
  • Step 1404 The AG sends an AP Authentication Request message to the AP, requesting the AP to return the AP username and password.
  • Step 1405 The AP sends an AP authentication response message (AP Authentication Response) to the AG, where the message includes the username and password of the user.
  • AP Authentication Response AP Authentication Response
  • Step 1406 compares the received AP by the AP transmitted user name and password, step 1403 is the same from AHR acquired AP user name and password, if the same, beta 1 J authentication by sending AP Authentication Initialization to the AP Acknowledge, the message carrying the cause value indicates that the authentication succeeds; if not, the authentication fails, and the AP Authentication Initialization Acknowledge is sent to the AP, and the message carries the cause value indicating that the authentication fails, and the AP is an illegal AP.
  • the method may include: if the AG determines, go to step 1404, and then, step 1406 is the AG compares the received AP username and password sent by the AP, and the AP username and password saved by the AG; otherwise, step 1402 is performed.
  • the AP authentication initialization request message sent by the AP to the AG in step 1301 or step 1401 further includes request authentication.
  • Type that is, USIM authentication or password authentication
  • the password authentication is the authentication method shown in FIG.
  • the method includes: determining, by the AG, whether the authentication type supported by the AG is consistent with the request authentication type included in the authentication initialization request message sent by the AP, and if yes, performing step 1302 or 1402; Sending an AP Authentication Initialization Acknowledge message to the AP, where the reason is indicated by the message.
  • the authentication type is not supported.
  • the embodiment of the present invention further provides a method for authenticating an AP by using a digital certificate, including: the AP obtains a digital certificate issued by the digital certificate issuing authority; and the AP authenticates the digital certificate in the AG through the digital certificate.
  • a certificate is issued by the certificate issuing organization on the CN side for each legal AP. See Figure 15 for the schematic diagram of the digital certificate issuance structure.
  • the Digital Certification Authority sends the following digital certificates to the AHR, security gateway, AP, and Enhanced Management System (EMS):
  • CA sends the EMS digital certificate
  • IPSec Internet Key Exchange
  • IPSec Internet Protocol Security
  • the working principle of the digital certificate is shown in Figure 16.
  • the external entity (EE, external entity) requests the digital certificate through the Registration Authority (RA).
  • RA Registration Authority
  • the CA issues the certificate and publishes the certificate to the online certificate status.
  • Protocol OSP, Online Certificate State Protocol
  • LDAP Lightweight Directory Access Protocol
  • Devices that receive a digital certificate issued by a CA can be authenticated by a digital certificate.
  • the EE of the digital certificate of the two devices participating in the authentication respectively verifies the legality of the digital certificate of the other party, and then verifies the security of the digital certificate, specifically: EE is signed by the private key, and the other party authenticates with the public key in the EE certificate. After the verification is passed, the EE is considered to be legal, that is, the device corresponding to the EE is legal.
  • a digital certificate to a device including an AP in a mobile communication system, authentication between the AP and other devices that receive the digital certificate can be achieved through the digital certificate.
  • the 17 is a schematic structural diagram of a system for paging a user in a mobile communication system according to an embodiment of the present invention.
  • the system includes a paging message sending module set on the CN side, a paging judgment module disposed in the AG, and paging message forwarding.
  • the module is configured to send an IMSI information sending module and a paging module in the AP.
  • the paging message sending module is configured to send a paging message including IMSI information to the paging determining module.
  • the paging determining module is configured to query, in the paging list, whether the IMSI information in the paging message exists, where the paging list includes a correspondence between an AP and an IMSI information of a user terminal that is allowed to access the AP. If yes, the paging message is transmitted to the paging message forwarding module, otherwise, the paging message is not transmitted to the paging message forwarding module.
  • the paging judgment module includes a paging list generation submodule for generating the paging list.
  • the paging message forwarding module is configured to send a paging message to the AP corresponding to the IMSI information included in the paging message for user paging.
  • the IMSI information sending module is configured to send the IMSI information of the user terminal that is allowed to access the AP to the paging determining module, to generate a paging list.
  • the IMSI information sending module may be replaced by an IMSI admission list sending module for transmitting an IMSI admission list to the AG for generating a paging list.
  • the paging module is configured to receive a paging message sent by the paging message forwarding module, and perform paging on the user terminal corresponding to the IMSI information included in the paging message.
  • An authentication module may be configured in the AG for authenticating the AP. If the authentication is passed, the paging message determining module sends a start command to start the paging message determining module.
  • an accepting authentication module may be set in the AP for accepting authentication of the authentication module.
  • the method for admitting the judgment and paging the user in the mobile communication system provided by the embodiment of the present invention
  • the access of the unlicensed UE is denied, and the paging to the unlicensed UE is prevented.
  • the AP user does not have to pay the communication fee caused by the misuse of the unauthorized user terminal, and the operator also uses the AP.
  • User terminal restrictions are not limited to:

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

移动通信系统中准入判断和寻呼用户的方法、 系统及装置 技术领域
本发明涉及移动通信技术, 具体涉及移动通信系统中准入判断和寻 呼用户的方法、 系统及装置。 发明背景
现有技术中, 公开了一种网络结构和相应的网络实体, 能够提供用 户终端直接访问 Internet的能力,参见图 1 , 为现有技术通用移动通讯系 统(UMTS, Universal Mobile Telecommunications System ) 网络中接入 点(AP, Access Point )直接访问 Internet的逻辑结构图。 该逻辑结构在 原有的 UMTS网络结构中增加两个网络实体: UMTS接入网关 (AG, Access Gateway )和 UMTS AP, 其他网络实体和接口保持不变。
UMTS AG网络实体对分组域来讲, 完成网关通用分组无线服务支 持节点(GGSN, Gateway GPRS Support Node ),服务通用分组无线服务 支持节点(SGSN, Serving GPRS Support Node )控制面功能以及无线网 络控制器( RNC , Radio Network Controller )控制面部分功能, 同时提 供和 GGSN/SGSN—样的 UMTS控制面接口;对电路域来讲, UMTS AG 类似于 RNC功能, 提供完整的语音接入功能。 具体地, UMTS AG有如 下的功能: 网络接入控制、 分组报文路由和转发中控制面处理、 语音的 转换和转发、 移动性管理、 AP 管理、 计费管理、 短消息业务、 移动网 络增强逻辑定制应用 (CAMEL , Customised Application for Mobile network Enhanced Logic )业务、 以及网络管理。
UMTS AG对外提供的接口包括: Ga、 Gb、 Gd、 Ge、 Gf、 Gn控制 面、 Gr和 Gs , 这些接口和 UMTS 3G网络使用相同的协议栈, 这里不再 叙述。
UMTS AP网络实体除了具备 UMTS负责无线接收和发送的逻辑节 点(NodeB )全部功能和 RNC部分控制功能外, 对分组域来讲, 还具备 GGSN、 SGSN、 RNC用户面功能。 具体地, UMTS AP的功能如下: 无 线接入控制、 分组报文路由和转发中用户面处理、 语音编解码、 无线资 源管理、 以及网络管理。
UMTS AP对外提供 Gi和 Gn用户面,和现有的 UMTS 3G网络提供 相同的协议栈, 这里不再叙述。
图 1是 UMTS网络中 AP直接访问 Internet的逻辑结构图, 类似地,
UMTS AG和 UMTS AP同样适用于通用分组无线服务( GPRS, General Packet Radio Service ) 网络、 码分多址( CDMA, Code Division Multiple Access ) 2000 网络、 时分-同步码分多址接入 ( TD-CDMAD , Time Division - Synchronize Code Division Multiple Access )网络,可以在 GPRS 网络、 CDMA2000网络、 TD-CDMAD网络等移动通信系统中增加两个 网络实体, AG和 AP , 使 AP直接访问 Internet。
现有技术中, 进入 AP小区的用户终端 (UE, User Equipment )可 以通过 AP和 AG, 直接接入移动通信系统。 但是在接入时, 现有技术 未对进入 AP小区的 UE进行准入判断和限制,导致非授权 UE接入移动 通信系统, 当网络侧寻呼 UE时无法限制对非授权 UE的寻呼, 使 AP 用户交纳非授权 UE误用而引起的通信资费。 现有技术存在以下缺点: 从用户角度看, AP是私人设备, 未经允许, 不希望其他人使用; 从运 营商角度来看, AP覆盖下的资费比宏网络优惠, 希望对使用 AP的 UE 加以限制。 发明内容
本发明实施例提供一种移动通信系统中准入判断的方法, 该方法能 够防止非授权 UE的接入。
本发明实施例提供一种移动通信系统中准入判断的系统, 该系统能 够防止非授权 UE的接入。
本发明实施例还提供又一种移动通信系统中准入判断的系统, 该系 统能够防止非授权 UE的接入。
本发明实施例提供一种移动通信系统中准入判断的准入判断装置, 该准入判断装置能够防止非授权 UE的接入。
本发明实施例还提供又一种移动通信系统中准入判断的准入判断装 置, 该准入判断装置能够防止非授权 UE的接入。
本发明实施例提供一种移动通信系统中准入判断的转换模块, 该转 换模块能够防止非授权 UE的接入。
本发明实施例提供一种移动通信系统中用户寻呼的方法, 该方法能 够防止对非授权 UE的寻呼。
本发明实施例提供一种移动通信系统中用户寻呼的装置, 该系统能 够防止对非授权 UE的寻呼。
本发明实施例提供又一种移动通信系统中用户寻呼的装置, 该系统 能够防止对非授权 UE的寻呼。
本发明实施例提供再一种移动通信系统中用户寻呼的装置, 该系统 能够防止对非授权 UE的寻呼。
一种移动通信系统中准入判断的方法, 该方法包括:
获取接入移动通信系统的接入点 AP的用户终端 UE的用户标识信 在用户标识信息准入列表中查询是否存在获取的用户标识信息, 若 存在, 则允许该 UE接入, 否则, 拒绝该 UE接入。
一种移动通信系统中准入判断的系统, 该系统包括网络侧的准入判 断模块和网络侧的转换模块;
所述准入判断模块,用于在 MSISDN准入列表中查询是否存在转换 模块传送的用户终端的 MSISDN信息,若存在,则允许该用户终端接入, 否则, 拒绝该用户终端接入;
所述转换模块, 用于接收用户终端传送的 IMSI信息, 将用户终端 传送的 IMSI信息转换为用户终端的 MSISDN信息。
一种移动通信系统中准入判断的系统, 该系统包括网络侧的准入判 断模块, 用于接收用户终端发送的 IMSI信息, 在 IMSI准入列表中查询 是否存在用户终端传送的 IMSI,若存在,则允许该用户终端接入,否贝 ij , 拒绝该用户终端接入。
一种移动通信系统中准入判断的准入判断装置, 该准入判断装置包 括接收子模块和准入判断子模块;
所述接收子模块, 用于接收转换子模块传送的用户终端的 MSISDN 信息, 传送给准入判断子模块;
所述准入判断子模块,用于在 MSISDN准入列表中查询是否存在所 述用户终端的 MSISDN信息, 若存在, 则允许该用户终端接入, 否则, 拒绝该用户终端接入。
一种移动通信系统中准入判断的准入判断装置, 该准入判断装置包 括接收子模块和准入判断子模块;
所述接收子模块, 用于接收用户终端传送的 IMSI, 传送给所述准入 判断子模块;
所述准入判断子模块, 用于在 IMSI准入列表中查询是否存在所述 接收子模块传送的 IMSI, 若存在, 则允许该用户终端接入, 否则, 拒绝 该用户终端接入。
一种移动通信系统中准入判断的转换装置, 该转换装置包括接收子 模块和转换子模块;
所述接收子模块, 用于接收用户终端传送的 IMSI信息, 传送给所 述转换子模块;
所述转换子模块, 用于将所述用户终端的 IMSI信息转换为用户终 端的 MSISDN信息, 传送给准入判断子模块进行准入判断。
本发明实施例提供一种移动通信系统中寻呼用户的方法, 该方法包 括:
生成寻呼列表, 所述寻呼列表包括 AP与允许接入 AP的用户终端 的 IMSI信息之间的对应关系,接收由 CN侧传送的包括 IMSI信息的寻 呼消息;
在寻呼列表中查询是否存在所述寻呼消息中的 IMSI信息, 若是, 则将寻呼消息传送给与所述寻呼消息中的 IMSI信息对应的 AP进行用户 寻呼, 否则, 拒绝对与所述寻呼消息中的 IMSI信息对应的用户进行寻 呼。
本发明实施例提供一种移动通信系统中寻呼用户的装置, 该装置包 括寻呼判断模块和寻呼消息转发模块;
所述寻呼判断模块,用于接收 CN侧发送的包括 IMSI信息的寻呼消 息, 在寻呼列表中查询是否存在所述 IMSI信息, 所述寻呼列表包括 AP 与允许接入 AP的 IMSI信息之间的对应关系,若是,则将寻呼消息传送 给寻呼消息转发模块, 否则, 不向寻呼消息转发模块传送寻呼消息; 所述寻呼消息转发模块, 用于将寻呼消息发送给与所述包括在寻呼 消息中的 IMSI信息对应的 AP进行用户寻呼。
本发明实施例提供一种移动通信系统中寻呼用户的装置, 该装置包 括 IMSI信息发送模块和寻呼模块;
所述 IMSI信息发送模块, 用于将允许接入 AP的用户终端的 IMSI 信息发送给 AG, 用以生成寻呼列表, 所述寻呼列表包括所述 AP与允 许接入所述 AP的用户终端的 IMSI之间的对应关系;
所述寻呼模块, 用于接收由 AG在所述寻呼列表中查询出存在寻呼 消息包含的 IMSI信息后, 发送所述寻呼消息; 对与所述寻呼消息包含 的 IMSI信息对应的用户终端进行寻呼。
本发明实施例提供一种移动通信系统中寻呼用户的装置, 该装置包 括 IMSI准入列表发送模块和寻呼模块;
所述 IMSI准入列表发送模块, 用于将 IMSI准入列表发送给 AG, 用以生成寻呼列表, 所述寻呼列表包括 AP与允许接入所述 AP的用户 终端的 IMSI之间的对应关系;
所述寻呼模块, 用于接收由 AG在寻呼列表中查询出存在寻呼消息 包含的 IMSI信息后,发送所述寻呼消息;对与所述寻呼消息包含的 IMSI 信息对应的用户终端进行寻呼。
从上述方案可以看出, 本发明实施例获取接入移动通信系统的 AP 小区的 UE的用户标识信息后, 在用户标识信息准入列表中查询是否存 在获取的用户标识信息, 若存在, 则允许该 UE接入, 否则, 拒绝该 UE 接入。 AG根据 AP与允许接入 AP的用户终端的 IMSI信息之间的对应 关系生成寻呼列表, 通过所述寻呼列表实现对 AP小区内授权 UE的寻 呼。 这样, 拒绝了非授权 UE的接入, 防止了对非授权 UE的寻呼, AP 用户不必交纳因非授权 UE的误用而导致的通信资费, 也实现了运营商 对使用 AP的 UE的限制。 附图简要说明
图 1为现有技术 UMTS网络中 AP直接访问 Internet的逻辑结构图; 图 2 为本发明实施例移动通信系统中准入判断的方法的流程图例 图 3 为本发明实施例移动通信系统中准入判断的方法的流程图例 图 4 为本发明实施例移动通信系统中准入判断的方法的流程图例 图 5 为本发明实施例移动通信系统中准入判断的方法的流程图例 四;
图 6 为本发明实施例移动通信系统中准入判断的方法的流程图例 五;
图 7a 为本发明实施例移动通信系统中准入判断的系统的结构示意 图例一;
图 7b 为本发明实施例移动通信系统中准入判断的系统的结构示意 图例二;
图 8为本发明实施例移动通信系统中准入判断的准入判断装置的结 构示意图;
图 9为本发明实施例移动通信系统中准入判断的转换装置的结构示 意图;
图 10 为本发明实施例移动通信系统中寻呼用户方法的示例性流程 图;
图 11为步骤 1001中生成寻呼列表的具体实施方式一的流程图; 图 12为步骤 1001中生成寻呼列表的具体实施方式二的流程图; 图 13为本发明实施例移动通信系统中对 AP鉴权的方法的流程图例 图 14为本发明实施例移动通信系统中对 AP鉴权的方法的流程图例 图 15为数字证书发放结构的示意图;
图 16为数字证书的工作原理图;
图 17为本发明实施例移动通信系统中寻呼用户的系统结构示意图。 实施本发明的方式
为使本发明的目的、 技术方案和优点更加清楚明白, 下面结合实施 例和附图, 对本发明进一步详细说明。
本发明的基本思想是, 在用户标识信息准入列表中查询是否存在接 入移动通信系统的接入点 AP的用户终端 UE的用户标识信息, 若存在, 则允许该 UE接入, 否则, 拒绝该 UE接入。 其中, 用户标识信息准入 列表为 MSISDN准入列表时, 用户标识信息为 MSISDN信息; 用户标 识信息准入列表为 IMSI准入列表时, 用户标识信息为 IMSI信息。 下面 是对该思想下各种情况的具体说明。
参见图 2, 为本发明实施例移动通信系统中准入判断的方法的流程 图例一, 该方法首先在 AP侧保存有移动台国际综合业务数字网络号码 ( MSISDN, Mobile Station International ISDN Number ) 准入列表, 此 MSISDN准入列表包含了允许接入 AP的所有 UE的 MSISDN, AP侧可 根据需要对此 MSISDN准入列表进行更改, 该方法包括以下步骤:
步骤 201 , AP侧修改 MSISDN准入列表, 同时将准入列表更新消 息( Access Control List Update )经 AG传送给核心网( CN, Core Network ) 侧网元, 该消息中包含 AP侧修改后的 MSISDN准入列表信息, CN侧 网元接收该消息后保存 MSISDN准入列表。 本实施例中描述的 CN侧网元可以为, CN侧的拜访位置寄存器 /移 动交换中心服务器( VLR/MSC, Visitor Location Register/Server Mobile Switching Centre Server )或 SGSN。 Control List Update Rsp ), 告之已经保存 AP侧传送的 MSISIDN准入列 表。
步骤 203, 进入 AP小区的 UE建立与 AP之间的无线连接后, 向 CN侧网元发送附着请求消息( Attach Request ),该消息包含 UE的 IMSI 信息。
步骤 204, CN侧网元接收 UE传送的 Attach Request, 获取 IMSI信 息后, 向 HLR发起位置更新流程, 位置更新流程结束后, CN侧网元从 HLR获取 UE的 MSISDN信息。
本步骤中, 所述的位置更新流程为: CN侧网元向 HLR发送位置更 新消息( Update Location ), 该消息中包含 UE的 IMSI信息, 用于根据 IMSI信息查询出与 IMSI对应的 MSISDN信息; HLR接收 Update Location, 获取 IMSI信息后, 查询出与 UE的 IMSI对应的 MSISDN信 息, 向 CN侧网元返回插入签约数据消息(Insert Subscriber Data ), 该消 息中包含 UE的 MSISDN信息; CN侧网元接收 Insert Subscriber Data后 向 HLR在发送插入签约数据响应消息( Insert Subscriber Data Rsp ), 告 之已获取 IMSI信息; HLR向 CN侧网元发送位置更新确认消息( Update Location Cnf ), 表明位置更新流程结束。
步骤 205 , CN侧网元根据从 HLR获取的 UE的 MSISDN信息, 以 及在步骤 201中保存的 MSISDN准入列表, 判断是否允许 UE的接入, 并相应地向 UE 侧发送附着接收消息 /附着拒绝消息 ( Attach Accept/Attach Rej ect )。 本步骤中, 所述判断是否允许 UE接入的方法为: CN 侧网元在 MSISDN的准入列表中查询是否存在从 HLR接收到的 UE的 MSISDN, 若存在, 则允许该 UE接入, 否则, 拒绝该 UE接入。
本实施例中的 AG和 CN侧网元设备可以如图 2所示, 分开为两个 设备, 也可以集成在一个设备中。
参见图 3, 为本发明实施例移动通信系统中准入判断的方法的流程 图例二, 该方法首先在 AP侧保存 MSISDN准入列表, 此 MSISDN准入 列表包含了允许接入 AP的所有 UE的 MSISDN, AP侧可根据需要对此 MSISDN准入列表进行更改, 该方法包括以下步骤:
步骤 301 , UE建立与 AP之间的无线连接后, 向 AP发送初始化用 户消息 (附着请求)( Init UE Message(Attach Request) )。
步骤 302, AP接收 Init UE Message( Attach Request)后, 向 UE传送 用户标识请求消息( Identity Request ), 以获取该 UE的 IMSI。
所述用户 IMSI为在 AP小区中驻留的 UE的 IMSI。
步骤 303 , UE向 AP返回用户标识响应消息( Identity Response ), 该消息包含该 UE的 IMSI信息。
步骤 304, AP获取 UE的 IMSI信息, 向 AG发送 MSISDN查询请 求消息 ( Query MSISDN Request ) , 该消息包含 UE的 IMSI信息, 用于 根据 UE的 IMSI查询 UE的 MSISDN信息。
AP侧已经保存了基于 MSISDN的准入列表, 但尚没有 MSISDN -
IMSI对应关系, 因此 AP向 AG发送 Query MSISDN Request消息, 以 根据用户的 IMSI获取 IMSI - MSISDN对应关系。
步骤 305 , AG根据接收到的 UE的 IMSI信息, 向 HLR发起位置更 新流程, 位置更新流程结束后, AG获取 IMSI - MSISDN对应关系。
本步骤中, 所述位置更新流程为: AG向 HLR发送位置更新请求消 息 ( Update Location ), 该消息中包含 UE的 IMSI信息, 用于根据 IMSI 信息查询出与 IMSI对应的 MSISDN信息; HLR接收 Update Location, 获取 IMSI信息后, 查询出与 UE的 IMSI对应的 MSISDN信息, 也就是 IMSI - MSISDN 对应关系, 向 AG 返回插入签约数据消息 ( Insert Subscriber Data ), 该消息中包含 IMSI - MSISDN对应关系; AG接收 Insert Subscriber Data后向 HLR在发送插入签约数据响应消息(Insert Subscriber Data Rsp ), 告之已获取 IMSI信息; HLR向 AG侧发送位置 更新确认消息 ( Update Location Cnf ), 表明位置更新流程结束。
步骤 306, AG向 AP返回 MSISDN查询响应消息 ( Query MSISDN Response ) , 其中包含了查询到的 IMSI - MSISDN对应关系。
步骤 307 , AP 获取 IMSI - MSISDN 对应关系后, 根据保存的 MSISDN准入列表和在步骤 303中获取的 UE的 IMSI判断是否允许该 UE接入, 如果不允许该 UE接入, 则向 UE发送附着拒绝消息, 拒绝该 UE 的接入, 结束流程; 否则将初始化用户消息 (附着接收) Unit UE Message ( Attach Request ) )经 AG转发给 CN侧网元, CN侧网元接收 Init UE Message(Attach Request)后, 向 UE端传送直传消息(附着接收 ) ( Direct Transfer( Attach Accept) ), 接收该 UE的接入。
本实施例中描述的 CN侧网元可以为, VLR/MSC或者 SGSN。
本步骤中, 所述 AP获取 IMSI - MSISDN对应关系后, 根据保存的 MSISDN准入列表和在步骤 303中获取的 UE的 IMSI判断是否允许该 UE接入的方法为: 根据 IMSI - MSISDN对应关系可获得与 UE的 IMSI 对应的 MSISDN信息,若在 AP保存的 MSISDN准入列表中查询出获得 的该 UE的 MSISDN信息, 则允许该 UE接入, 否则拒绝该 UE接入。
本步骤中, 可以进一步包括 AP保存获取的 IMSI - MSISDN对应关 系。 当 AP下次接收 UE发送的 Init UE Message(Attach Request)后,可以 省略步骤 304 - 306, 直接进入步骤 307判断是否允许该 UE的接入。 本 步骤还可以进一步包括, 对于不允许接入的 UE, AP侧将该 UE的 IMSI - MSISDN对应关系信息保留在黑名单中。 当这些 UE下次再从 AP接 入时, 可以省略步骤 304 - 306, AP直接拒绝这些 UE。
参见图 4, 为本发明实施例移动通信系统中准入判断的方法的流程 图例三, 该方法首先在 AP侧保存 MSISDN准入列表, 此 MSISDN准入 列表包含了允许接入 AP的所有 UE的 MSISDN, AP侧可根据需要对此 MSISDN准入列表进行更改, 该方法包括以下步骤:
步骤 401 , UE建立与 AP之间的无线连接后, 向 AP发送初始化用 户消息(附着请求)( Init UE Message(Attach Request) )。
步骤 402, AP接收 Init UE Message( Attach Request)后, 向 UE传送 用户标识请求消息( Identity Request ), 以获取该 UE的 IMSI。
所述用户 IMSI为在 AP小区中驻留的 UE的 IMSI。
步骤 403 , UE向 AP返回用户标识响应消息( Identity Response ), 该消息包含该 UE的 IMSI信息。
步骤 404, AP获取 UE的 IMSI信息, 向 AG发送 MSISDN查询请 求消息 ( Query MSISDN Request ) , 该消息包含 UE的 IMSI信息, 用于 根据 UE的 IMSI查询 UE的 MSISDN信息。
AP侧已经保存了基于 MSISDN的准入列表, 但尚没有 MSISDN - IMSI对应关系, 因此 AP向 AG发送 Query MSISDN Request消息, 以 根据用户的 IMSI获取 IMSI - MSISDN对应关系。
步骤 405 , AG根据接收到的 UE的 IMSI信息, 采用 AG与 HLR之 间的 Gr,向 HLR发送 Gr接口 MSISDN查询请求消息( Gr Query MSISDN Request ), 该消息中包含了 UE的 IMSI信息, 用于根据 IMSI信息查询 出与 IMSI对应的 MSISDN信息。 步骤 406, HLR接收 AG发送的 Gr Query MSISDN Request后, 查 询出与 UE的 IMSI对应的 MSISDN信息, 也就是 IMSI - MSISDN对应 关系, 向 AG返回 Gr接口 MSISDN查询响应消息 ( Gr Query MSISDN Response ), 该消息中包含 IMSI - MSISDN对应关系。
步骤 407 , AG获取 IMSI - MSISDN对应关系后,向 AP返回 MSISDN 查询响应消息 ( Query MSISDN Response ), 其中包含了查询到的 IMSI - MSISDN对应关系。
步骤 408 , AP 获取 IMSI - MSISDN 对应关系后, 根据保存的 MSISDN准入列表和在步骤 403中获取的 UE的 IMSI判断是否允许该 UE接入, 如果不允许该 UE接入, 则向 UE发送附着拒绝消息, 拒绝该 UE 的接入, 结束流程; 否则将初始化用户消息 (附着接收) Unit UE Message ( Attach Request ) )经 AG转发给 CN侧网元, CN侧网元接收 Init UE Message(Attach Request)后, 向 UE端传送直传消息(附着接收 ) ( Direct Transfer( Attach Accept) ), 接收该 UE的接入。
本具体实施例中描述的 CN侧网元可以为, VLR/MSC或者 SGSN。 本步骤中, 所述 AP获取 IMSI - MSISDN对应关系后, 根据保存的 MSISDN准入列表和在步骤 403中获取的 UE的 IMSI判断是否允许该 UE接入的方法为: 根据 IMSI - MSISDN对应关系可获得与 UE的 IMSI 对应的 MSISDN信息,若在 AP保存的 MSISDN准入列表中查询出获得 的该 UE的 MSISDN信息, 则允许该 UE接入, 否则拒绝该 UE接入。
本步骤中, 可以进一步包括 AP保存获取的 IMSI - MSISDN对应关 系。 当 AP下次接收 UE发送 Init UE Message(Attach Request后, 可以省 略步骤 404 ~ 407, 直接进入步骤 408判断是否允许该 UE的接入。 本步 骤还可以进一步包括, 对于不允许接入的 UE, AP侧将该 UE的 IMSI - MSISDN对应关系信息保留在黑名单中。 当这些 UE下次再从 AP接 入时, 可以省略步骤 404 - 407, AP直接拒绝这些 UE。
参见图 5, 为本发明实施例移动通信系统中准入判断的方法的流程 图例四, 该方法首先在 AP侧保存 MSISDN准入列表, 此 MSISDN准入 列表包含了允许接入 AP的所有 UE的 MSISDN, AP侧可根据需要对此 MSISDN准入列表进行更改, 该方法包括以下步骤:
步骤 501 , AP 侧向 AG发送 IMSI 查询请求消息 (Query IMSI Request ), 该消息包括 AP侧内保存的 MSISDN准入列表的 MSISDN信 息, 用于查询 MSISDN - IMSI的对应关系, 也就是查询与 MSISDN准 入列表的 MSISDN信息对应的 IMSI信息。
步骤 502, AG根据接收到的 MSISDN信息, 采用 AG与 HLR之间 的消息接口 Gr,向 HLR发送 Gr接口 IMSI查询请求消息( Gr Query IMSI Request ) , 该消息中包含 MSISDN准入列表的 MSISDN信息, 用于根据 MSISDN信息查询出与 MSISDN信息对应的 IMSI信息。
步骤 503 , HLR接收 AG发送的 Gr Query IMSI Request后, 查询出 与 MSISDN信息对应的 IMSI信息, 也就是 IMSI - MSISDN对应关系, 向 AG返回 Gr接口 IMSI查询响应消息( Gr Query IMSI Response ), 该 消息中包含 IMSI - MSISDN对应关系。
步骤 504, AG获取 IMSI - MSISDN对应关系后,向 AP返回 IMSI 查询响应消息 ( Query IMSI Response ), 其中包含了查询到的 IMSI - MSISDN对应关系 ,ΑΡ侧接收 IMSI - MSISDN对应关系后, 根据 IMSI - MSISDN对应关系生成基于 IMSI的准入列表。
本步骤中, AP获取的 IMSI - MSISDN对应关系中的 IMSI信息与 AP侧保存的 MSISDN准入列表的 MSISDN信息——对应关系, 获取 IMSI - MSISDN对应关系中 IMSI信息便得到基于 IMSI的准入列表,此 IMSI准入列表包含了允许接入 AP的所有 UE的 IMSI。 步骤 505, UE建立与 AP之间的无线连接后, 向 AP发送初始化用 户消息 (附着请求)( Init UE Message(Attach Request) )。
步骤 506, AP向 UE发送用户标识请求消息( Identity Request ), 以 获取该 UE的 IMSI。
所述用户 IMSI为在 AP小区中驻留的 UE的 IMSI。
步骤 507 , UE 向 AP 返回用户标识响应消息 (Identity Request Response ) , 该消息包含该 UE的 IMSI信息。
步骤 508, AP根据步骤 504中生成的 IMSI准入列表和步骤 507中 获得的 UE的 IMSI, 判断是否接入用户, 如果不允许该 UE接入, 则向 UE发送附着拒绝消息, 拒绝该 UE的接入, 结束流程; 否则将初始化用 户消息 (附着接收 ) ( Init UE Message ( Attach Request ) )经 AG转发给 CN侧网元, CN侧网元收到 Init UE Message( Attach Request)后, 向 UE 端发送直传消息(附着接收)(Direct Transfer(Attach Accept) ), 接收该 UE的接入。
本实施例中描述的 CN侧网元可以为, VLR/MSC或者 SGSN。
参见图 6, 为本发明实施例移动通信系统中准入判断的方法的流程 图例五, 该方法在 AG上配置并保存对应每个 AP的 IMSI准入列表, 或 者, AP归属寄存器(AHR, AP Home register ) 中配置了对应每个 AP 的 IMSI准入列表, AG从 AHR中获取并保存对应每个 AP的 IMSI准入 列表, 所述 IMSI准入列表包含了允许接入 AP的所有 UE的 IMSI, 该 方法包括以下步骤:
步骤 601 , UE建立与 AP之间的无线连接后, 向 AP发送初始化用 户消息(附着请求 ) ( Init UE Message( Attach Request ) ), AP接收 Init UE Message(Attach Request)后, 转发给 AG。
步骤 602, AG接收 Init UE Message ( Attach Request )后, 向 UE发 送用户标识请求消息 ( Identity Request ), 以获取该 UE的 IMSI。
所述用户 IMSI为在 AP小区中驻留的 UE的 IMSI。
步骤 603 , UE向 AG返回用户标识响应消息 ( Identity Response ), 该消息包含该 UE的 IMSI信息。
步骤 604, AG根据保存的 IMSI准入列表和获得的 UE的 IMSI, 判 断是否接入用户, 如果不允许该 UE接入, 则向 UE发送附着拒绝消息, 拒绝该 UE的接入,结束流程; 否则将初始化用户消息(附着接收 ) ( Init UE Message( Attach Request ) )发送给 CN侧网元, CN侧网元收到 Init UE Message(Attach Request)后, 向 UE端发送直传消息(附着接收 ) ( Direct Transfer( Attach Accept) ) , 接收该 UE的接入。
本实施例中描述的 CN侧网元可以为, VLR/MSC或者 SGSN。
除上述五种移动通信系统中准入判断的方法外, 还可以在 AP侧保 存 IMSI准入列表, 直接实现用户准入。 该方法首先在 AP中保存 IMSI 准入列表, 此 IMSI准入列表包含了允许接入 AP的所有 UE的 IMSI, AP侧可根据需要对此 IMSI准入列表进行更改, 该方法包括以下步骤: 首先, UE建立与 AP之间的无线连接后, 向 AP发送初始化用户消 息 (附着请求 ) ( Init UE Message(Attach Request) ); AP向 UE发送用户 标识请求消息 ( Identity Request ), 以获取该 UE的 IMSI; UE向 AP返 回用户标识响应消息( Identity Request Response ) , 该消息包含该 UE的 IMSI信息。
然后, AP根据 IMSI准入列表和获得的 UE的 IMSI, 判断是否接入 用户, 如果不允许该 UE接入, 则向 UE发送附着拒绝消息, 拒绝该 UE 的接入,结束流程;否则将初始化用户消息(附着接收 ) ( Init UE Message ( Attach Request ) ) 经 AG转发给 CN侧网元, CN侧网元收到 Init UE Message(Attach Request)后, 向 UE端返回直传消息(附着接收 ) ( Direct Transfer( Attach Accept) ), 接收该 UE的接入。
本实施例中描述的 CN侧网元可以为, VLR/MSC或者 SGSN。 参见图 7a, 为本发明实施例移动通信系统中准入判断的系统的结构 示意图例一, 该系统包括网络侧的准入判断模块、 网络侧的转换模块和 UE;
准入判断模块,用于在 MSISDN准入列表中查询是否存在转换模块 传送的 UE的 MSISDN, 若存在, 则允许该 UE接入, 否则, 拒绝该 UE 接入。
转换模块, 用于将 UE传送的 IMSI信息转换为 UE的 MSISDN。 UE, 用于向准入转换模块传送该 UE的 IMSI信息。
以上描述中, UE为进入移动通信系统的 AP小区的 UE, 准入判断 模块设置在准入判断网元内,准入判断网元可以为 CN侧网元或 AP,根 据准入判断网元的不同, 将图 7a所示的系统分为如下三种情况:
第一种情况:
准入判断模块设置在 CN侧网元内, 转换模块设置在 HLR内。 该系统可以进一步包括 AP和 AG。
AP内保存有 MSISDN准入列表信息, 此 MSISDN准入列表包含了 允许接入 AP的所有 UE的 MSISDN, AP侧可根据需要对此 MSISDN准 入列表进行更改; AP侧将 MSISDN准入列表更新消息经 AG传送给准 入判断模块, 该消息中包含 MSISDN准入列表信息。
转换模块, 用于从准入判断模块获取 UE的 IMSI信息后, 查询出与 UE的 IMSI对应的 MSISDN信息, 向准入判断模块返回插入签约数据 消息, 该消息中包含 UE的 MSISDN信息。
准入判断模块, 用于保存从 AP传送的 MSISDN准入列表信息, 向 转换模块发送位置更新消息,该消息中包含 UE的 IMSI信息;接收转换 模块传送的 UE的 MSISDN信息,在 MSISDN准入列表中查询是否存在 该 UE的 MSISDN, 若存在, 则允许该 UE接入, 否则, 拒绝该 UE接 入。
上述的 AG和 CN侧网元可以为两个设备, 也可以集成在一个合并 设备中。 CN侧网元可以为, VLR/MSC或者 SGSN。
第二种情况:
准入判断模块设置在 AP内, 转换模块设置在 HLR内。 MSISDN准 入列表保存在 AP内, 包含了允许接入 AP的所有 UE的 MSISDN, AP 侧可根据需要对此 MSISDN准入列表进行更改。
该系统可以进一步包括 AG和 CN侧网元。
AG, 用于根据准入判断模块传送的 UE的 IMSI信息向转换模块发 送位置更新请求消息,该消息中包含 UE的 IMSI信息;接收转换模块返 回的包含 IMSI - MSISDN对应关系的插入签约数据消息后,向准入判断 模块传送包含所述 IMSI - MSISDN对应关系的 MSISDN查询响应消息。
转换模块,用于接收 AG传送的包含 UE的 IMSI信息的位置更新请 求消息,获取 IMSI信息后,查询出与 UE的 IMSI对应的 MSISDN信息, 也就是 IMSI - MSISDN对应关系, 向 AG返回插入签约数据消息, 该消 息中包含 IMSI - MSISDN对应关系。
CN侧网元,用于接收准入判断模块经 AG传送的包含接收该 UE的 信息的初始化用户消息后, 接收该 UE的接入; 否则拒绝该 UE接入。 准入判断模块进行判断后经 AG向 CN侧网元传送初始化用户消息的具 体过程, 参见步骤 307处的描述。
上述的 CN侧网元可以为, VLR/MSC或者 SGSN。
准入判断模块可以保存获取的 IMSI - MSISDN对应关系。 当 UE下 次再向准入判断模块发起初始化用户消息时, 准入判断模块可以直接判 断是否允许该 UE的接入,无需再向 AG查询 IMSI - MSISDN对应关系。 准入判断模块还可以将不允许接入的 UE的 IMSI - MSISDN对应关系信 息保留在黑名单中, 当这些 UE下次再从 AP接入时, 准入判断模块直 接拒绝这些 UE, 无需再向 AG查询 IMSI - MSISDN对应关系。
第三种情况:
准入判断模块设置在 AP内, 转换模块设置在 HLR内。 MSISDN准 入列表保存在 AP内, 包含了允许接入 AP的所有 UE的 MSISDN, AP 侧可根据需要对此 MSISDN准入列表进行更改。
该系统可以进一步包括 AG和 CN侧网元。
AG, 用于根据准入判断模块传送的 UE的 IMSI信息, 向转换模块 发送 Gr接口 MSISDN查询请求消息, 该消息中包含 UE的 IMSI信息; 接收转换模块返回的包含 IMSI - MSISDN对应关系的 Gr接口 MSISDN 查询响应消息后,向准入判断模块传送包含所述 IMSI - MSISDN对应关 系的 MSISDN查询响应消息;
转换模块, 用于接收 AG传送的包含 UE的 IMSI信息的 Gr接口 MSISDN查询请求消息, 获取 IMSI信息后, 查询出与 UE的 IMSI对应 的 MSISDN信息, 也就是 IMSI - MSISDN对应关系, 向 AG返回 Gr接 口 MSISDN查询响应消息, 该消息中包含 IMSI - MSISDN对应关系。
CN侧网元, 用于接收准入判断模块经所述 AG传送的包含接收该 UE的信息的初始化用户消息后, 接收该 UE的接入; 否则拒绝该 UE接 入。 准入判断模块进行判断后经 AG向 CN侧网元传送初始化用户消息 的具体过程, 参见步骤 408处的描述。
上述的 CN侧网元可以为, VLR/MSC或者 SGSN。
准入判断模块可以保存获取的 IMSI - MSISDN对应关系。 当 UE下 次再向准入判断模块发起初始化用户消息时, 准入判断模块可以直接判 断是否允许该 UE的接入,无需再向 AG查询 IMSI - MSISDN对应关系。 准入判断模块还可以将不允许接入的 UE的 IMSI - MSISDN对应关系信 息保留在黑名单中,当这些 UE下次再从 AP接入时, 准入判断模块直接 拒绝这些 UE,无需再向 AG查询 IMSI - MSISDN对应关系。
参见图 7b, 为本发明实施例移动通信系统中准入判断的系统的结构 示意图例二, 该系统包括网络侧的准入判断模块和 UE;
准入判断模块, 用于在 IMSI准入列表中查询是否存在 UE传送的 UE的 IMSI, 若存在, 则允许该 UE接入, 否则, 拒绝该 UE接入。
UE, 用于向准入判断模块传送该 UE的 IMSI信息。
以上描述中, UE为进入移动通信系统的 AP小区的 UE, 准入判断 模块设置在 AP内。图 7b所示的系统包括了本发明实施例移动通信系统 中准入判断的系统的第四、 五和六种情况:
第四种情况:
AP内保存有 MSISDN准入列表, 此 MSISDN准入列表包含了允许 接入 AP的所有 UE的 MSISDN, AP侧可根据需要对此 MSISDN准入列 表进行更改。
该系统可以进一步包括 AG、 HLR和 CN侧网元。
AG , 用于接收准入判断模块传送的包括 MSISDN 准入列表的 MSISDN信息的 IMSI查询请求消息后, 向 HLR发送包含所述 MSISDN 信息的 Gr接口 IMSI 查询请求消息; 接收 HLR返回的包含 IMSI - MSISDN对应关系的 Gr接口 IMSI查询响应消息; 向所述准入判断模块 发送包含所述 IMSI - MSISDN对应关系的 IMSI查询响应消息。
HLR,用于接收 AG传送的包括 MSISDN准入列表的 MSISDN信息 的 IMSI查询请求消息, 获取 MSISDN准入列表的 MSISDN信息后, 查 询出与 MSISDN信息对应的 IMSI信息,也就是 IMSI - MSISDN对应关 系, 通过 HLR与 AG之间的 Gr接口向 AG返回 Gr接口 IMSI查询响应 消息, 该消息中包含了 IMSI - MSISDN对应关系。
CN侧网元,用于接收准入判断模块经 AG传送的包含接收该 UE的 信息的初始化用户消息后, 接收该 UE的接入; 否则拒绝该 UE接入。 准入判断模块进行判断后经 AG向 CN侧网元传送初始化用户消息的具 体过程, 参见步骤 508处的描述。
准入判断模块,用于根据 AG传送的 IMSI - MSISDN对应关系生成 基于 IMSI的准入列表。 其具体生成参见步骤 504处的描述。
上述的 CN侧网元可以为, VLR/MSC或者 SGSN。
第五种情况:
AG内保存有 IMSI准入列表,此 IMSI准入列表包含了允许接入 AP 的所有 UE的 IMSI。
该系统还可以进一步包括 CN侧网元。
CN侧网元,用于接收准入判断模块发送的包含接收该 UE的信息的 初始化用户消息后, 接收该 UE的接入; 否则拒绝该 UE接入。
上述的 CN侧网元可以为, VLR/MSC或者 SGSN。
第六种情况:
IMSI准入列表保存在 AP内。此 IMSI准入列表包含了允许接入 AP 的所有 UE的 IMSI, AP侧可根据需要对此 IMSI准入列表进行更改。
该系统还可以进一步包括 AG和 CN侧网元。
CN侧网元,用于接收准入判断模块经 AG传送的包含接收该 UE的 信息的初始化用户消息后, 接收该 UE的接入; 否则拒绝该 UE接入。
上述的 CN侧网元可以为, VLR/MSC或者 SGSN。
参见图 8, 为本发明实施例移动通信系统中准入判断的准入判断装 置的结构示意图, 该准入判断装置包括接收子模块和准入判断子模块; 接收子模块,用于接收转换子模块传送的用户终端的 MSISDN信息, 传送给准入判断子模块。
准入判断子模块,用于在 MSISDN准入列表中查询是否存在接收子 模块传送的用户终端的 MSISDN信息,若存在,则允许该用户终端接入, 否则, 拒绝该用户终端接入。
准入判断子模块可以设置在 CN侧网元内。 此时, 准入判断装置相 当于图 7a相关描述的第一种情况中的准入判断模块。
准入判断子模块也可以设置在接入点内,所述 MSISDN准入列表保 存在准入判断子模块内。 此时, 准入判断装置相当于图 7a的第二、 三种 情况中的准入判断模块。
下面对移动通信系统中准入判断的准入判断装置的另外两种情况进 行说明, 也就是相当于图 7b相关描述的第四、 五和六种情况中的准入 判断模块, 此时的准入判断装置与图 8所述的结构示意图相同, 该准入 判断装置包括接收子模块和准入判断子模块。
所述接收子模块, 用于接收用户终端传送的 IMSI, 传送给所述准入 判断子模块。
所述准入判断子模块, 用于在 IMSI准入列表中查询是否存在所述 接收子模块传送的 IMSI, 若存在, 则允许该用户终端接入, 否则, 拒绝 该用户终端接入。
准入判断子模块可以设置在接入点内,根据保存的 MSISDN准入列 表和由 AG传送的 IMSI - MSISDN对应关系生成所述 IMSI准入列表。 此时, 准入判断装置具体相当于图 7b相关描述的第四种情况中的准入 判断模块。
参见图 9, 为本发明实施例移动通信系统中准入判断的转换装置的 结构示意图, 该转换装置包括接收子模块和转换子模块。 接收子模块, 用于接收用户终端传送的 IMSI信息, 传送给转换子 模块。
转换子模块, 用于将所述用户终端的 IMSI信息转换为用户终端的 MSISDN信息, 传送给准入判断子模块进行准入判断。
该转换子模块可以设置在 HLR内。 此时, 转换装置相当于图 7a相 关描述的第一、 二、 三种情况中的转换模块。
上述本发明实施例的方案适用于增加了网络实体 AP 的 UMTS 网 络、 GPRS网络、 CDMA2000网络或 TD-SCDMA网络等移动通信系统。
本发明实施例的方案中, 准入判断网元从接入移动通信系统的 AP 小区的 UE获取该 UE的 IMSI信息, 根据准入列表和 IMSI信息判断是 否允许该 UE接入, 这样, 使系统拒绝了非授权 UE的接入, AP用户不 必交纳非授权 UE的误用而导致的通信资费,也实现了运营商对使用 AP 的 UE的限制。
现有技术不仅没有对进入 AP小区的 UE进行准入判断, 在 AG接 收到 CN侧发送的寻呼消息时,也没有提供用户寻呼方案。 以图 1为例, 在没有增加 AP和 AG的 UMTS网络中, 当 MSC寻呼用户时, MSC向 RNC下发寻呼消息,在所述寻呼消息中携带 IMSI、位置区标识码( LAI , Location Area Identity )或路由区标" i只码 ( RAI, Routing Area Identity ) 等参数。 RNC收到由 MSC下发的寻呼消息后, 判断与所述 IMSI对应 的 UE是否有与其它 CN域的信令连接,例如与 SGSN建立有信令连接, 如果有, 则直接在该信令连接上寻呼用户; 否则, RNC在位置区或路由 区范围内发送广播消息, 寻呼用户。
参见图 10, 为本发明实施例移动通信系统中寻呼用户方法的示例性 流程图, 该方法包括以下步骤:
步骤 1001 , AG生成寻呼列表,接收由 CN侧传送的包括 IMSI信息 的寻呼消息, 所述寻呼列表包括 AP与允许接入 AP的用户终端的 IMSI 信息之间的对应关系。
步骤 1002, AG判断与所述包括在寻呼消息中的 IMSI信息对应的 UE是否有同其它 CN域的信令连接, 如果有, 则直接在该信令连接上 寻呼用户; 否则, 执行步骤 1003。 本步骤可选。
步骤 1003 , AG在所述寻呼列表中查询是否存在所述包括在寻呼消 息中的 IMSI信息, 若存在, 则将寻呼消息传送给与所述包括在寻呼消 息中的 IMSI信息对应的 AP, 进行用户寻呼; 否则, 拒绝将寻呼消息传 送给与所述包括在寻呼消息中的 IMSI信息对应的 AP , 进行用户寻呼, 结束流程。
本步骤中, AP进行用户寻呼时, 在其覆盖范围内广播寻呼消息, 对 与所述包括在寻呼消息中的 IMSI信息的用户进行寻呼。
参见图 11 , 为步骤 1001 中生成寻呼列表的具体实施方式一的流程 图, 包括以下步骤:
步骤 1101 , 进入 AP小区的 UE建立与 AP之间的无线连接后, 向 AP发送无线资源控制( RRC, Radio Resource Control )初始化直传消息 ( RRC Initial Direct Transfer ), 该消息中包含位置区更新请求( LA/RA Update Request )。
步骤 1102, AP向 UE发送 RRC直传消息( RRC Direct Transfer ), 该消息中包含标识请求( Identity Request )。
步骤 1103 , UE接收由 AP传送的 RRC Direct Transfer后, 向 AP发 送 RRC直传响应消息( RRC Direct Response Transfer ),该消息中包含标 识响应 ( Identity Response ), 该标识响应中包含 UE的 IMSI信息。
步骤 1101 ~ 1103为 AP获得 UE的 IMSI信息过程。
步骤 1104, AP判断是否允许该 UE的接入, 如果允许, 则向 AG发 送 IMSI关联更新消息( IMSI Association Update ), 该消息中包含该 UE 的 IMSI信息。
本步骤中所述 AP判断是否允许该 UE的接入的方法, 参见前述本 发明实施例提供的移动通信系统中准入判断方案的相应描述。
步骤 1105, AG接收 AP传送的 IMSI信息, 保存 IMSI信息与传送 该 IMSI信息的 AP之间的对应关系, 也就是生成寻呼列表。
参见图 12, 为步骤 1001 中生成寻呼列表的具体实施方式二的流程 图, 本实施例在 AP开机以及 AP保存的 IMSI准入列表发生变化时, 执 行以下步骤:
步骤 1201 , AP向 AG发送 IMSI关联更新指示消息( IMSI Association
Update Indication ) , 该消息中包含 ΑΡ保存的最新的 IMSI准入列表。
步骤 1202, AG保存接收到的 IMSI准入列表中的 IMSI信息与发送 该 IMSI准入列表的 AP之间的对应关系, 也就是, 生成新的寻呼列表; 向 AP返回 IMSI关联更新确认消息( IMSI Association Update ACK ),表 示 AG已接收到更新的 IMSI准入列表。
AG检测到 AP关机时, 删除寻呼列表。
AP保存的 IMSI准入列表发生变化时, 执行步骤 1201 ~ 1202, 在 AP关 机时, AG不删除 IMSI准入列表。
生成寻呼列表的具体实施方法二和三中,步骤 1201 ~ 1202可以替换 为:
AG核查到 AP保存的 IMSI准入列表发生变化时, 向 AP发送关联 同步请求消息 ( IMSI Association Sync Request );
AP接收到 IMSI Association Sync Request后, 将 AP更新的 IMSI准 入列表传送给 AG; AG保存接收到的 IMSI准入列表中的 IMSI信息与发送该 IMSI准入 列表的 AP之间的对应关系,也就是生成新的寻呼列表;向 AP返回 IMSI 关联更新确认消息( IMSI Association Update ACK ), 表示 AG已接收到 更新的 IMSI准入列表。
本发明实施例移动通信系统中寻呼用户的方法还可以为: AP通过 AG接入移动通信系统时, 将 AP的位置区或路由区信息传送给 AG; AG接收由 CN侧传送的包括 IMSI信息的寻呼消息,所述寻呼消息还 包括与所述 IMSI信息对应的位置区或路由区信息, 也就是需要寻呼 的 UE的位置区或路由区信息; AG将寻呼消息传送给与包括在寻呼 消息中的位置区或路由区信息对应的 AP, 进行用户寻呼。 需要说明 的是, 同一条位置区或路由区信息可能对应多个 AP。
本发明实施例中, 在进行准入判断之前或寻呼用户之前, 可以包 括对 AP鉴权的过程, 下面对本发明实施例移动通信系统中对 AP鉴 权方法进行说明。
参见图 13 , 为本发明实施例移动通信系统中对 AP鉴权的方法的 流程图例一, 该方法包括以下步骤:
步骤 1301 , AP 向 AG 发送 AP 鉴权初始化请求消息 ( AP Authentication Initialization Request ) , 请求 AG对该 AP进行鉴权, 该消息中包含 UMTS 用户身份标识模块 (USIM, UMTS Subscriber Identity Module ) 卡号。
所述 USIM卡号包含了 AP标识, 一个 AP标识对应一个 AP。 步骤 1302, AG向 HLR发送鉴权数据请求消息 (Authentication Info Request ) , 请求从 HLR获取鉴权集, 所述 Authentication Info Request包含 AP标识。
所述鉴权集可以为五元鉴权组, 也可以为三元鉴权组。 五元鉴权 组包括的参数为随机数 ( RAND , Random Number ) 、 鉴权标记 ( AUTN , Authentication Token ) 、 期望响应 (XRES , Expectation Response )、加密密钥( CK, Ciphering Key )和完整性密钥( IK, Integrity Key ) , 三元鉴权组包括的参数为 RAND、 加密密钥 (KC, Ciphering Key )和 XRES。 AG与 HLR之间传输消息的接口可采用 3GPP 29.002 协议中的标准接口。 鉴权集每组参数对应一个 AP标识。
步骤 1303 , AG 接收由 HLR 返回的鉴权数据响应消息 ( Authentication Info response ) , 该消息中包含鉴权集响应, 该响应 中可能包括五元鉴权组, 也可能包括三元鉴权组, 还可能包括获取鉴 权集失败的消息; 若该鉴权集响应中包括五元鉴权组或三元鉴权组, 则执行步骤 1304, 若该鉴权集响应中包含获取鉴权集失败的消息, 则结束流程。
步骤 1304, AG向 ΑΡ发送 ΑΡ鉴权请求消息( AP Authentication
Request ) 。 若步骤 1303中的鉴权集包括五元鉴权组, 则所述 AP鉴 权请求消息中包含 RAND和 AUTN参数,若步骤 1303中的鉴权集包 括三元鉴权组, 则所述 AP鉴权请求消息中包含 RAND参数。
步骤 1305 , AP接收 AP Authentication Request后, 向 AG发送
AP鉴权响应消息 ( AP Authentication Response ) , 该消息中包含了鉴 权响应 ( RES , Response ) 参数。
本步骤还可以包括:若 AP向 AG发送 AP Authentication Response 超时, 则 AG向 AP发送 AP鉴权初始化确认消息( AP Authentication
Initialization Acknowledge ) , 该消息中携带原因值表明鉴权失败, 结 束流程。
步骤 1306, AG比较接收到的由 AP传送的 RES参数与步骤 1302 中从 HLR获取的鉴权集中包含的 XRES参数是否相同, 若相同, 则 鉴权通过, 向 AP发送 AP Authentication Initialization Acknowledge , 该消息中携带原因值表明鉴权成功; 若不相同, 则鉴权失败, 向 AP 发送 AP Authentication Initialization Acknowledge,该消息中携带原因 值表明鉴权失败, 该 AP为非法 AP, 并向 HLR发送鉴权失败报告消 息 ( Authentication Failure Report ) 。
上述为通过 AP的 USIM卡实现 AG对 AP的鉴权的流程, 通过 AP的 USIM卡还可以实现 AP对 AG的鉴权, 其流程类似, 这里不 再赘述。
AP 也可是采用用户身份标识模块 ( SIM , Subscriber Identity Module )实现 AG对 AP的鉴权, 此时, 鉴权流程与图 13类似, 不同 的是步骤 1302、 1303和 1304中的涉及的鉴权集只能是三元鉴权组。 SIM卡的优点是价格比 USIM卡便宜,缺点是 SIM卡不能支持 AP对 AG的鉴权。
参见图 14, 为本发明实施例移动通信系统中对 AP鉴权的方法的 流程图例二, 本实施例在 AP归属寄存器 ( AHR , AP Home register ) 中保存有允许通过鉴权的 AP的用户名和密码,该方法包括以下步骤: 步骤 1401 , AP 向 AG 发送 AP 鉴权初始化请求消息 ( AP Authentication Initialization Request ) , 请求 AG对该 AP进行鉴权, 该消息中包含 AP标识。
所述 AP标识对应该 AP的用户名和密码。
步骤 1402, AG向 AHR发送鉴权数据请求消息 (Authentication data request ) ,该消息中包含 AP标识,请求 AHR对该 AP进行鉴权。
步骤 1403 , AHR接收包含 AP标识的 Authentication data request 后, 查询出与该 AP标识对应的用户名和密码, 向 AG返回鉴权数据 响应消息( Authentication data response ) , 该消息中包含查询出的 ΑΡ 的用户名和密码。
步骤 1404, AG向 AP发送 AP鉴权请求消息( AP Authentication Request ) , 请求 AP返回 AP的用户名和密码。
步骤 1405 , AP向 AG发送 AP鉴权响应消息( AP Authentication Response ) , 该消息中包含 ΑΡ的用户名和密码。
步骤 1406, AG比较接收到的由 AP传送的 AP的用户名和密码, 与步骤 1403中从 AHR获取的 AP的用户名和密码是否相同,若相同, 贝1 J鉴权通过,向 AP发送 AP Authentication Initialization Acknowledge, 该消息中携带原因值表明鉴权成功; 若不相同, 则鉴权失败, 向 AP 发送 AP Authentication Initialization Acknowledge,该消息中携带原因 值表明鉴权失败, 该 AP为非法 AP。
图 14所述的流程中, 若 AG网元中也可以保存允许通过鉴权的 AP的用户名和密码, 则步骤 1401之后, 该方法可以包括: AG判断 若是, 则执行步骤 1404, 相应地, 步骤 1406为 AG比较接收到的由 AP传送的 AP用户名和密码, 与 AG保存的该 AP的用户名和密码; 否则, 执行步骤 1402。
若移动通信系统中提供了图 13所示和图 14所示的两种对 AP鉴 权的方法, 则步骤 1301或步骤 1401中 AP向 AG发送的 AP鉴权初 始化请求消息中还包括请求鉴权类型, 也就是 USIM 鉴权或口令鉴 权, 所述口令鉴权为图 14所示的鉴权方法。 并且, 步骤 1301或步骤 1401之后, 包括: AG判断 AG支持的鉴权类型与 AP发送的鉴权初 始化请求消息包含的请求鉴权类型是否一致, 若一致, 则执行步骤 1302或 1402; 若不一致, 则向 AP发送 AP鉴权初始化确认消息( AP Authentication Initialization Acknowledge ) , 该消息中携带原因表明 鉴权类型不支持。
本发明实施例还提供了通过数字证书实现对 AP鉴权的方法, 包 括: AP获得由数字证书发放机构发放的数字证书; AP通过所述数字证 书与 AG中的数字证书进行鉴权。
由 CN侧的证书发放机构为每个合法的 AP发放一张数字证书, 数字证书发放结构的示意图参见图 15。图中,数字证书认证中心( CA, Certification Authority)向 AHR、安全网关、 AP和增强管理系统( EMS , Enhancement Management System )发送如下数字证书:
- CARootCert: CA的自身根证书;
- AHRCert: CA发送给 AHR的数字证书;
- EMSCert: CA发送给 EMS数字证书;
- SGWCert: CA 发送给安全网关的用于 Internet 协议安全性 ( IPSec, Internet protocol security )的 Internet密钥交换 ( IKE, Internet Key Exchange ) 过程的数字证书;
- UMTS APCert: CA发送给 AP的数字证书。
数字证书的工作原理见图 16 , 外部实体(EE, external entity ) , 通过注册鉴权(RA, Registration Authority)申请数字证书, 经过审核 后, CA进行签发证书,并将该证书发布至在线证书状态协议( OCSP, Online Certificate State Protocol ) 和轻量级目录访问十办议 ( LDAP, Lightweight Directory Access Protocol)。
接收到由 C A发放的数字证书的设备之间可以通过数字证书进行 鉴权。 参与鉴权的双方设备的数字证书的 EE分别验证对方数字证书 的合法性, 再验证数字证书的安全性, 具体为: EE通过私钥进行签 名, 对方以该 EE证书中的公钥进行验证, 验证通过后, 则认为该 EE 合法, 也就是与该 EE对应的设备合法。 对移动通信系统中的包括 AP在内的设备发放数字证书, 就可以 通过数字证书实现 AP与其它接收到数字证书的设备之间的鉴权。
参见图 17,为本发明实施例移动通信系统中寻呼用户的系统结构 示意图, 该系统包括设置在 CN侧的寻呼消息下发模块、 设置在 AG内 的寻呼判断模块和寻呼消息转发模块,设置在 AP内的 IMSI信息发送模 块和寻呼模块。
所述寻呼消息下发模块, 用于向寻呼判断模块发送包括 IMSI信息 的寻呼消息。
所述寻呼判断模块, 用于在寻呼列表中查询是否存在所述寻呼消息 中的 IMSI信息, 所述寻呼列表包括 AP与允许接入 AP的用户终端的 IMSI信息之间的对应关系, 若是, 则将寻呼消息传送给寻呼消息转发模 块, 否则, 不向寻呼消息转发模块传送寻呼消息。 寻呼判断模块中包括 寻呼列表生成子模块, 用于生成所述寻呼列表。
寻呼消息转发模块, 用于将寻呼消息发送给与包括在寻呼消息中的 IMSI信息对应的 AP进行用户寻呼。
所述 IMSI信息发送模块, 用于将允许接入 AP的用户终端的 IMSI 信息发送给寻呼判断模块, 用以生成寻呼列表。 IMSI信息发送模块可以 替换为 IMSI准入列表发送模块, 用于将 IMSI准入列表发送给 AG, 用 以生成寻呼列表。
所述寻呼模块, 用于接收寻呼消息转发模块发送的寻呼消息, 对与 所述寻呼消息包含的 IMSI信息对应的用户终端进行寻呼。
AG内还可以设置鉴权模块, 用于对 AP进行鉴权, 若鉴权通过, 则 向寻呼消息判断模块发送启动指令, 启动寻呼消息判断模块。 相应地, AP内可以设置接受鉴权模块, 用于接受鉴权模块的鉴权。
本发明实施例提供的移动通信系统中准入判断和寻呼用户的方 案, 拒绝了非授权 UE的接入, 防止了对非授权 UE的寻呼, 这样, AP 用户不必因交纳非授权用户终端的误用而导致的通信资费,也实现了运 营商对使用 AP的用户终端的限制。
以上所述的具体实施例, 对本发明的目的、 技术方案和有益效果进 行了进一步详细说明, 所应理解的是, 以上所述仅为本发明的具体实施 例而已, 并不用于限定本发明的保护范围, 凡在本发明的精神和原则之 内, 所做的任何修改、 等同替换、 改进等, 均应包含在本发明的保护范 围之内。

Claims

权利要求书
1、一种移动通信系统中准入判断的方法,其特征在于,该方法包括: 获取接入移动通信系统的接入点的用户终端的用户标识信息; 在用户标识信息准入列表中查询是否存在获取的用户标识信息, 若 存在, 则允许该用户终端接入, 否则, 拒绝该用户终端接入。
2、如权利要求 1所述的方法, 其特征在于, 所述用户标识信息准入 列表为移动台国际综合业务数字网络号码 MSISDN准入列表;所述用户 标识信息为 MSISDN信息。
3、 如权利要求 2所述的方法, 其特征在于, 获取所述 MSISDN信 息的方法包括:
核心网 CN侧网元向归属位置寄存器 HLR发送位置更新消息,该消 息中包含用户终端发送的附着请求包含的国际移动台用户识别号 IMSI 信息; CN侧网元接收 HLR根据所述位置更新消息, 获取用户终端的 IMSI信息, 并查询出与用户终端的 IMSI对应的 MSISDN信息之后, 返 回的插入签约数据消息, 该插入签约数据消息中包含用户终端的 MSISDN信息;
所述在用户标识信息准入列表中查询是否存在获取的用户标识信息 之前, 该方法包括获取所述 MSISDN准入列表的方法: CN侧网元经接 入网关 AG接收接入点发送的 MSISDN准入列表更新消息,该消息中包 含接入点保存的 MSISDN 准入列表信息, CN 侧网元保存接收到的 MSISDN准入列表;
所述在用户标识信息准入列表中查询是否存在获取的用户标识信息 为: CN侧网元在保存的 MSISDN准入列表中查询是否存在获取的用户 终端的 MSISDN信息。
4、 如权利要求 2所述的方法, 其特征在于, 所述 MSISDN准入列 表保存在接入点内;
所述在用户标识信息准入列表中查询是否存在获取的用户标识信息 为:接入点在保存的 MSISDN准入列表中查询是否存在获取的用户终端 的 MSISDN信息;
获取所述 MSISDN信息的方法为:
接入点向 AG发送 MSISDN查询请求消息, 该消息包含用户终端的 IMSI信息;
接入点接收 AG在根据所述用户终端的 IMSI信息, 获取 IMSI - MSISDN对应关系之后, 返回的包含所述 IMSI - MSISDN对应关系的 MSISDN查询响应消息;
接入点根据接收到的 IMSI - MSISDN对应关系获得与用户终端的 IMSI对应的 MSISDN信息。
5、 如权利要求 4 所述的方法, 其特征在于, 所述获取 IMSI - MSISDN对应关系的方法为:
AG向 HLR发送位置更新请求消息,该消息中包含用户终端的 IMSI 信息;
HLR获取 IMSI信息后, 查询出 IMSI - MSISDN对应关系, 向 AG 返回插入签约数据消息, 该消息中包含 IMSI - MSISDN对应关系。
6、如权利要求 4所述的方法,其特征在于,所述获取 IMSI - MSISDN 对应关系的方法为:
AG根据接收到的用户终端的 IMSI信息, 向 HLR发送 Gr接口 MSISDN查询请求消息, 该消息中包含用户终端的 IMSI信息;
HLR接收 AG发送的 Gr接口 MSISDN查询请求消息后,查询出 IMSI - MSISDN对应关系, 向 AG返回包含 IMSI - MSISDN对应关系的 Gr 接口 MSISDN查询响应消息。
7、 如权利要求 5或 6所述的方法, 其特征在于, 所述 AG向接入点 返回包含所述 IMSI - MSISDN对应关系的 MSISDN查询响应消息之后, 该方法进一步包括:
接入点保存接收到的 IMSI - MSISDN对应关系; 或 /和接入点根据 接收到的 IMSI - MSISDN对应关系将不允许接入用户终端的 IMSI - MSISDN对应关系信息保留在设置的黑名单中。
8、如权利要求 1所述的方法, 其特征在于, 所述用户标识信息准入 列表为 IMSI准入列表; 所述用户标识信息为 IMSI信息。
9、 如权利要求 8所述的方法, 其特征在于, 所述 IMSI准入列表的 获取方法为:
接入点向 AG发送 IMSI查询请求消息, 该消息包括接入点内保存 的 MSISDN准入列表的 MSISDN信息;
AG根据接收到的 MSISDN信息, 向 HLR发送 Gr接口 IMSI查询 请求消息, 该消息中包含 MSISDN准入列表的 MSISDN信息;
HLR接收 Gr接口 IMSI查询请求消息后, 查询出 IMSI - MSISDN 对应关系, 向 AG返回包含 IMSI - MSISDN对应关系的 Gr接口 IMSI 查询响应消息;
AG向接入点发送包含 IMSI - MSISDN对应关系的 IMSI查询响应 消息, 接入点根据 IMSI - MSISDN对应关系生成 IMSI准入列表。
10、 如权利要求 8所述的方法, 其特征在于, 所述 IMSI准入列表 保存在接入点或 AG内;
所述在用户标识信息准入列表中查询是否存在获取的用户标识信息 为: 接入点或 AG在 IMSI准入列表中查询是否存在获取的用户终端的 IMSI信息。
11、 一种移动通信系统中准入判断的系统, 其特征在于, 该系统包 括网络侧的准入判断模块和网络侧的转换模块;
所述准入判断模块,用于在 MSISDN准入列表中查询是否存在转换 模块传送的用户终端的 MSISDN信息,若存在,则允许该用户终端接入, 否则, 拒绝该用户终端接入;
所述转换模块, 用于接收用户终端传送的 IMSI信息, 将用户终端 传送的 IMSI信息转换为用户终端的 MSISDN信息。
12、 如权利要求 11所述的系统, 其特征在于, 所述准入判断模块设 置在 CN侧网元内;所述转换模块设置在 HLR内;
该系统进一步包括接入点和 AG ;
所述接入点, 用于保存 MSISDN准入列表, 将 MSISDN准入列表 更新消息经所述 AG传送给准入判断模块,该消息中包含 MSISDN准入 列表信息;
所述转换模块, 用于获取用户终端的 IMSI信息后, 查询出与用户 终端的 IMSI对应的 MSISDN信息, 向准入判断模块返回插入签约数据 消息, 该消息中包含用户终端的 MSISDN信息;
所述准入判断模块, 用于保存接收到的 MSISDN准入列表, 向转换 模块发送位置更新消息, 该消息中包含用户终端的 IMSI信息; 接收转 换模块传送的用户终端的 MSISDN信息。
13、 如权利要求 12所述的系统, 其特征在于, 所述 AG和 CN侧网 元集成在同一设备中。
14、 如权利要求 11所述的系统, 其特征在于, 所述准入判断模块设 置在接入点内; 所述 MSISDN准入列表保存在所述准入判断模块内; 所 述转换模块设置在 HLR内;
所述准入判断模块进一步用于将用户终端的 IMSI信息传送给 AG; 该系统进一步包括 AG和 CN侧网元;
所述 AG,用于根据准入判断模块传送的用户终端的 IMSI信息向转 换模块发送位置更新请求消息, 该消息中包含用户终端的 IMSI信息; 接收转换模块返回的包含 IMSI - MSISDN对应关系的插入签约数据消 息,向准入判断模块返回包含所述 IMSI - MSISDN对应关系的 MSISDN 查询响应消息;
所述转换模块,用于向 AG传送包含 IMSI - MSISDN对应关系的插 入签约数据消息;
所述 CN侧网元, 用于接收准入判断模块经 AG传送的包含接收该 用户终端的信息的初始化用户消息后, 接收该用户终端的接入; 否则拒 绝该用户终端接入。
15、 如权利要求 11所述的系统, 其特征在于, 所述准入判断模块设 置在接入点内; 所述 MSISDN准入列表保存在所述准入判断模块内; 所 述转换模块设置在 HLR内;
所述准入判断模块进一步用于将用户终端的 IMSI信息传送给 AG; 该系统进一步包括 AG和 CN侧网元;
所述 AG,用于根据准入判断模块传送的用户终端的 IMSI信息向转 换模块发送 Gr接口 MSISDN查询请求消息, 该消息中包含用户终端的 IMSI 信息; 接收转换模块返回的包含 IMSI - MSISDN 对应关系的 MSISDN 查询响应消息, 向所述准入判断模块返回包含所述 IMSI - MSISDN对应关系的 MSISDN查询响应消息;
所述转换模块,用于向所述 AG传送包含 IMSI - MSISDN对应关系 的 Gr接口 MSISDN查询响应消息;
所述 CN侧网元, 用于接收所述准入判断模块经所述 AG传送的包 含接收该用户终端的信息的初始化用户消息后, 接收该用户终端的接 入; 否则拒绝该用户终端接入。
16、 一种移动通信系统中准入判断的系统, 其特征在于, 该系统包 括网络侧的准入判断模块,用于接收用户终端发送的 IMSI信息,在 IMSI 准入列表中查询是否存在用户终端传送的 IMSI, 若存在, 则允许该用户 终端接入, 否则, 拒绝该用户终端接入。
17、如权利要求 16所述的系统, 其特征在于, 所述准入判断模块设 置在接入点内; 所述准入判断模块根据保存的 MSISDN 准入列表和由 AG传送的 IMSI - MSISDN对应关系生成所述 IMSI准入列表;
该系统进一步包括 AG、 HLR和 CN侧网元;
所述 AG, 用于接收所述准入判断模块传送的包含 MSISDN准入列 表的 MSISDN信息的 IMSI查询请求消息后,向 HLR发送包含 MSISDN 信息的 Gr接口 IMSI 查询请求消息; 接收 HLR返回的包含 IMSI - MSISDN对应关系 Gr接口 IMSI查询响应消息; 向准入判断模块发送包 含所述 IMSI - MSISDN对应关系的 IMSI查询响应消息;
所述 HLR,用于查询与所述 AG发送的 Gr接口 IMSI查询请求消息 中包含的 MSISDN信息对应的 IMSI信息, 向所述 AG传送包含 IMSI - MSISDN对应关系的 Gr接口 IMSI查询响应消息;
所述 CN侧网元, 用于接收准入判断模块经 AG传送的包含接收该 用户终端的信息的初始化用户消息后, 接收该用户终端的接入; 否则拒 绝该用户终端接入。
18、如权利要求 16所述的系统, 其特征在于, 所述准入判断模块设 置在接入点或 AG内。
19、 一种移动通信系统中准入判断的准入判断装置, 其特征在于, 该准入判断装置包括接收子模块和准入判断子模块;
所述接收子模块, 用于接收转换子模块传送的用户终端的 MSISDN 信息, 传送给准入判断子模块;
所述准入判断子模块,用于在 MSISDN准入列表中查询是否存在所 述用户终端的 MSISDN信息, 若存在, 则允许该用户终端接入, 否则, 拒绝该用户终端接入。
20、如权利要求 19所述的准入判断装置, 其特征在于, 所述准入判 断子模块设置在 CN侧网元内; 所述 MSISDN准入列表保存在所述准入 判断子模块内。
21、如权利要求 19所述的准入判断装置, 其特征在于, 所述准入判 断子模块设置在接入点内;所述 MSISDN准入列表保存在所述准入判断 子模块内。
22、 一种移动通信系统中准入判断的准入判断装置, 其特征在于, 该准入判断装置包括接收子模块和准入判断子模块;
所述接收子模块, 用于接收用户终端传送的 IMSI, 传送给所述准入 判断子模块;
所述准入判断子模块, 用于在 IMSI准入列表中查询是否存在所述 接收子模块传送的 IMSI, 若存在, 则允许该用户终端接入, 否则, 拒绝 该用户终端接入。
23、如权利要求 22所述的准入判断装置, 其特征在于, 所述准入判 断子模块设置在接入点内;所述准入判断子模块根据保存的 MSISDN准 入列表和由 AG传送的 IMSI - MSISDN对应关系生成所述 IMSI准入列 表。
24、如权利要求 22所述的准入判断装置, 其特征在于, 所述准入判 断子模块设置在接入点或 AG内。
25、 一种移动通信系统中准入判断的转换装置, 其特征在于, 该转 换装置包括接收子模块和转换子模块; 所述接收子模块, 用于接收用户终端传送的 IMSI信息, 传送给所 述转换子模块;
所述转换子模块, 用于将所述用户终端的 IMSI信息转换为用户终 端的 MSISDN信息, 传送给准入判断子模块进行准入判断。
26、 如权利要求 25所述的转换装置, 其特征在于, 所述转换子模块 设置在 HLR内。
27、 一种移动通信系统中寻呼用户的方法, 其特征在于, 该方法包 括:
生成寻呼列表, 所述寻呼列表包括 AP与允许接入 AP的用户终端 的 IMSI信息之间的对应关系,接收由 CN侧传送的包括 IMSI信息的寻 呼消息;
在寻呼列表中查询是否存在所述寻呼消息中的 IMSI信息, 若是, 则将寻呼消息传送给与所述寻呼消息中的 IMSI信息对应的 AP进行用户 寻呼, 否则, 拒绝对与所述寻呼消息中的 IMSI信息对应的用户进行寻 呼。
28、 如权利要求 27 所述的方法, 其特征在于, 所述生成寻呼列表 的方法为:
AP向 AG传送允许接入的 UE的 IMSI信息;
AG根据 AP与所述允许接入的 IMSI信息之间的对应关系, 生成所 述寻呼列表。
29、 如权利要求 27 所述的方法, 其特征在于, 所述生成寻呼列表 的方法为:
AP将 IMSI准入列表传送给 AG;
AG根据 AP与所述 IMSI准入列表中的 IMSI信息之间的对应关系, 生成所述寻呼列表。
30、 如权利要求 27 所述的方法, 其特征在于, 所述生成寻呼列表 的方法为:
AG检查到 AP的 IMSI准入列表发生变化时, 从 AP获得更新后的 IMSI准入列表;
AG根据 AP与所述 IMSI准入列表中的 IMSI信息之间的对应关系, 生成所述寻呼列表。
31、如权利要求 27所述的方法, 其特征在于, 所述生成寻呼列表之 前, 该方法包括:
AG接收由 AP传送的 AP标识,从 HLR获得与所述 AP标识对应的 鉴权集, 从 AP生成与所述 AP标识对应的鉴权响应参数;
AG 比较所述鉴权集中的鉴权参数与所述鉴权响应参数是否一致, 若一致, 则鉴权通过, 执行所述 AG生成寻呼列表的步骤, 否则, 不执 行所述生成寻呼列表的步骤。
32、如权利要求 31所述的方法, 其特征在于, 所述鉴权集为五元鉴 权组或三元鉴权组。
33、如权利要求 27所述的方法, 其特征在于, 所述生成寻呼列表之 前, 该方法包括:
AG接收由 AP传送的用户名和密码,查询与 AG中保存的允许通过 鉴权的 AP的用户名和密码是否一致, 若一致, 则鉴权通过, 执行所述 AG生成寻呼列表的步骤, 否则, 不执行所述生成寻呼列表的步骤。
34、如权利要求 27所述的方法, 其特征在于, 所述生成寻呼列表之 前, 该方法包括:
AG接收由 AP发送的 AP标识和 AP的用户名和密码,根据所述 AP 标识从 AHR获得允许通过鉴权的与 AP标识对应的用户名和密码;
AG比较由 AP发送的所述 AP的用户名和密码, 与从 AHR获得的 所述 AP的用户名和密码是否一致, 若一致, 则鉴权通过,执行所述 AG 生成寻呼列表的步骤, 否则, 不执行所述生成寻呼列表的步骤。
35、 如权利要求 27所述的方法, 其特征在于, 所述生成寻呼列表之 前, 该方法包括:
AP获得由数字证书发放机构发放的数字证书;
AP通过所述数字证书与 AG中的数字证书进行鉴权后,执行所述生 成寻呼列表的步骤。
36、 一种移动通信系统中寻呼用户的装置, 其特征在于, 该装置包 括寻呼判断模块和寻呼消息转发模块;
所述寻呼判断模块,用于接收 CN侧发送的包括 IMSI信息的寻呼消 息, 在寻呼列表中查询是否存在所述 IMSI信息, 所述寻呼列表包括 AP 与允许接入 AP的 IMSI信息之间的对应关系,若是,则将寻呼消息传送 给寻呼消息转发模块, 否则, 不向寻呼消息转发模块传送寻呼消息; 所述寻呼消息转发模块, 用于将寻呼消息发送给与所述包括在寻呼 消息中的 IMSI信息对应的 AP进行用户寻呼。
37、如权利要求 36所述的装置, 其特征在于, 所述寻呼判断模块中 包括寻呼列表生成子模块, 用于生成所述寻呼列表。
38、 如权利要求 36或 37所述的装置, 其特征在于, 该装置还包括 鉴权模块, 用于对 AP进行鉴权, 若鉴权通过, 则向寻呼消息判断模块 发送启动指令, 启动寻呼消息判断模块。
39、 一种移动通信系统中寻呼用户的装置, 其特征在于, 该装置包 括 IMSI信息发送模块和寻呼模块;
所述 IMSI信息发送模块, 用于将允许接入 AP的用户终端的 IMSI 信息发送给 AG, 用以生成寻呼列表, 所述寻呼列表包括所述 AP与允 许接入所述 AP的用户终端的 IMSI之间的对应关系; 所述寻呼模块, 用于接收由 AG在所述寻呼列表中查询出存在寻呼 消息包含的 IMSI信息后, 发送所述寻呼消息; 对与所述寻呼消息包含 的 IMSI信息对应的用户终端进行寻呼。
40、 如权利要求 39所述的装置, 其特征在于, 该装置包括接受鉴权 模块, 用于接受 AG的鉴权。
41、 一种移动通信系统中寻呼用户的装置, 其特征在于, 该装置包 括 IMSI准入列表发送模块和寻呼模块;
所述 IMSI准入列表发送模块, 用于将 IMSI准入列表发送给 AG, 用以生成寻呼列表, 所述寻呼列表包括 AP与允许接入所述 AP的用户 终端的 IMSI之间的对应关系;
所述寻呼模块, 用于接收由 AG在寻呼列表中查询出存在寻呼消息 包含的 IMSI信息后,发送所述寻呼消息;对与所述寻呼消息包含的 IMSI 信息对应的用户终端进行寻呼。
42、 如权利要求 41所述的装置, 其特征在于, 该装置包括接受鉴权 模块, 用于接受 AG的鉴权。
PCT/CN2008/070726 2007-04-16 2008-04-16 Procédé de détermination d'admission et de radiomessagerie d'utilisateur dans un système de communication mobile, système et dispositif apparentés WO2008125062A1 (fr)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
CNA2007100969265A CN101043755A (zh) 2007-04-16 2007-04-16 移动通信系统中准入判断的方法、系统及装置
CN200710096926.5 2007-04-16
CN200710128478.2 2007-07-26
CN2007101284782A CN101111075B (zh) 2007-04-16 2007-07-26 移动通信系统中准入判断和寻呼用户的方法、系统及装置

Publications (1)

Publication Number Publication Date
WO2008125062A1 true WO2008125062A1 (fr) 2008-10-23

Family

ID=39042929

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2008/070726 WO2008125062A1 (fr) 2007-04-16 2008-04-16 Procédé de détermination d'admission et de radiomessagerie d'utilisateur dans un système de communication mobile, système et dispositif apparentés

Country Status (2)

Country Link
CN (1) CN101111075B (zh)
WO (1) WO2008125062A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021212398A1 (en) * 2020-04-23 2021-10-28 Qualcomm Incorporated Mobile terminated (mt) paging procedure for ip multimedia subsystem (ims) calls

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101111075B (zh) * 2007-04-16 2010-12-15 华为技术有限公司 移动通信系统中准入判断和寻呼用户的方法、系统及装置
CN101500233A (zh) * 2008-01-31 2009-08-05 华为技术有限公司 寻呼方法、家用基站、家用基站网关和通信系统
CN101646253A (zh) * 2008-08-07 2010-02-10 华为技术有限公司 寻呼方法、网元、管理网元和通信系统
CN103813452B (zh) * 2008-08-07 2017-10-24 华为技术有限公司 寻呼方法、网元、管理网元和通信系统
CN101827427B (zh) * 2009-03-06 2015-04-01 株式会社Ntt都科摩 一种传输封闭用户组信息的方法及装置
CN101895855B (zh) * 2009-05-18 2013-06-26 中国移动通信集团公司 移动终端的接入方法、基站及接入系统
CN101925180B (zh) * 2009-06-15 2014-01-08 华为技术有限公司 一种emc场景下寻呼的处理方法、ue及核心管理网元
CN101707604B (zh) * 2009-11-20 2013-01-09 杭州华三通信技术有限公司 一种防恶意攻击的方法、系统及装置
CN109963281B (zh) * 2017-12-25 2021-05-11 华为技术有限公司 一种鉴权方法、设备及系统
CN114246007B (zh) * 2021-11-25 2024-04-19 北京小米移动软件有限公司 信息传输方法、装置、通信设备和存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1642349A (zh) * 2004-06-25 2005-07-20 华为技术有限公司 一种管理本地终端设备接入网络的方法
CN1852595A (zh) * 2005-12-02 2006-10-25 华为技术有限公司 一种无线通信终端接入鉴权方法
CN101043755A (zh) * 2007-04-16 2007-09-26 华为技术有限公司 移动通信系统中准入判断的方法、系统及装置
CN101111075A (zh) * 2007-04-16 2008-01-23 华为技术有限公司 移动通信系统中准入判断和寻呼用户的方法、系统及装置

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100579011C (zh) * 2004-04-22 2010-01-06 华为技术有限公司 一种限制用户上网区域的方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1642349A (zh) * 2004-06-25 2005-07-20 华为技术有限公司 一种管理本地终端设备接入网络的方法
CN1852595A (zh) * 2005-12-02 2006-10-25 华为技术有限公司 一种无线通信终端接入鉴权方法
CN101043755A (zh) * 2007-04-16 2007-09-26 华为技术有限公司 移动通信系统中准入判断的方法、系统及装置
CN101111075A (zh) * 2007-04-16 2008-01-23 华为技术有限公司 移动通信系统中准入判断和寻呼用户的方法、系统及装置

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021212398A1 (en) * 2020-04-23 2021-10-28 Qualcomm Incorporated Mobile terminated (mt) paging procedure for ip multimedia subsystem (ims) calls

Also Published As

Publication number Publication date
CN101111075B (zh) 2010-12-15
CN101111075A (zh) 2008-01-23

Similar Documents

Publication Publication Date Title
WO2008125062A1 (fr) Procédé de détermination d'admission et de radiomessagerie d'utilisateur dans un système de communication mobile, système et dispositif apparentés
JP7035163B2 (ja) ネットワークセキュリティ管理方法および装置
RU2304856C2 (ru) Способ и система, предназначенные для установления соединения через сеть доступа
US9515850B2 (en) Non-validated emergency calls for all-IP 3GPP IMS networks
TWI293844B (en) A system and method for performing application layer service authentication and providing secure access to an application server
CA2530891C (en) Apparatus and method for a single sign-on authentication through a non-trusted access network
KR101682388B1 (ko) 무선 통신 시스템에서 미인증/미등록 단말에게 통신 서비스를 제공하는 방법 및 이를 위한 장치
WO2019017840A1 (zh) 网络验证方法、相关设备及系统
US20090282467A1 (en) Method and system for controlling access to networks
US8611859B2 (en) System and method for providing secure network access in fixed mobile converged telecommunications networks
WO2005096644A1 (fr) Procede d'etablissement d'une association de securite entre l'abonne itinerant et le serveur du reseau visite
CN104836787A (zh) 用于认证客户端站点的系统和方法
CN110476397B (zh) 用户鉴权方法和装置
CN108886674B (zh) 通过通信网络中继数据的系统和方法
KR20060067263A (ko) Wlan-umts 연동망 시스템과 이를 위한 인증 방법
WO2007091699A2 (en) Method, system and apparatus for indirect access by communication device
WO2007019771A1 (en) An access control method of the user altering the visited network, the unit and the system thereof
WO2015089996A1 (zh) 一种安全认证方法及鉴权认证服务器
WO2010130118A1 (zh) 一种对家用基站用户实施鉴权的系统及方法
JP2005536122A (ja) ホーム・ロケーション・レジスタの改良による移動端末の個人情報保護
JP4280235B2 (ja) 移動体無線端末の識別方法
TWI428031B (zh) 區域網協存取網路元件與終端設備的認證方法與裝置
WO2006079953A1 (en) Authentication method and device for use in wireless communication system
WO2008092317A1 (fr) Procédé de connexion de réseau
WO2010124569A1 (zh) 用户接入控制方法和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 08734084

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 08734084

Country of ref document: EP

Kind code of ref document: A1