WO2009135371A1 - Network connection mode determining method - Google Patents

Network connection mode determining method Download PDF

Info

Publication number
WO2009135371A1
WO2009135371A1 PCT/CN2008/073555 CN2008073555W WO2009135371A1 WO 2009135371 A1 WO2009135371 A1 WO 2009135371A1 CN 2008073555 W CN2008073555 W CN 2008073555W WO 2009135371 A1 WO2009135371 A1 WO 2009135371A1
Authority
WO
WIPO (PCT)
Prior art keywords
public land
land mobile
network
mobile network
3gpp access
Prior art date
Application number
PCT/CN2008/073555
Other languages
French (fr)
Chinese (zh)
Inventor
朱春晖
宗在峰
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2009135371A1 publication Critical patent/WO2009135371A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/123Applying verification of the received information received data contents, e.g. message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/105Multiple levels of security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/126Applying verification of the received information the source of the received data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/04Interfaces between hierarchically different network devices
    • H04W92/10Interfaces between hierarchically different network devices between terminal device and access point, i.e. wireless air interface

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method for determining a network connection manner.
  • 3GPP 3rd Generation Partnership Project
  • the standardization working group is currently working on the next-generation evolution of the core network system, the Evolved Packet Core (EPC), which aims to provide users with higher transmission rates and shorter transmission delays.
  • EPC Evolved Packet Core
  • FIG. 1 is a schematic diagram of a non-3GPP radio access network accessing a Home Public Land Mobile Network (Home PLMN, referred to as HPLMN) by visiting a Public Land Mobile Network (VPLMN), as shown in FIG.
  • the network elements involved are: Packet Data Network Gateway (P-GW), which is responsible for the gateway function of the UE accessing the Packet Data Network (PDN); Home Subscriber Server (Home Subscriber Server) , referred to as HSS), is located in the user's home network, and is used to permanently store user subscription data and security data.
  • P-GW Packet Data Network Gateway
  • HSS Home Subscriber Server
  • Non-3GPP radio access networks include the following two types:
  • Trusted Non 3 GPP Access trusted non-3GPP access network
  • the non-3GPP access system can directly access the P-GW through S2a.
  • Untrusted Non 3GPP Access Untrusted non-3GPP access network
  • the Evolved Packet Data Gateway (ePDG) of the 3GPP network is connected to the P-GW through S2b.
  • ePDG Evolved Packet Data Gateway
  • a secure tunnel is established between the UE and the ePDG to ensure data transmission security between the UE and the 3GPP network.
  • a trust relationship may be established between HPLMN and VPLMN and Non 3GPP Access. For example, both HPLMN and VPLMN consider the Non 3 GPP Access to be trusted, or either of HPLMN and VPLMN may -3 GPP Access is considered untrustworthy.
  • the PLMN and the Non-3GPP Access are trusted relationships; otherwise, if the PLMN and the Non-3GPP Access are not trusted, then The mobile terminal accessed by the Non-3GPP Access must pass through the security gateway ePDG to access the PDN GW of the PLMN.
  • the trust relationship between HPLMN and Non-3GPP Access is determined by the HPLMN, but when the user accesses the VPLMN from Non-3GPP Access, the PDN of the monthly service is provided for the user according to the location of the service provided.
  • the GW may be located in the HPLMN or in the VPLMN.
  • the present invention has been made in view of the problem in the prior art that the user equipment cannot determine the connection mode of accessing the VPLMN through Non-3GPP Access when roaming, and it is therefore an object of the present invention to provide a solution to the above problem. solution.
  • a method of determining a network connection manner is provided. The user equipment (UE) roams access to the non-3GPP access network, and the non-3GPP access network ⁇ !
  • the method for determining the foregoing network connection manner includes: Step 1: The AAA Server determines that the belonging public land mobile network and the non-3GPP access network are in a trust relationship, and the trust relationship information and the user belonging to the public land mobile network and the non-3GPP access network are used. The subscription information is sent to the AAA Proxy. Step 2: The AAA Proxy reports the trust relationship information sent by the AAA Server, the user subscription information, the trust relationship information between the public land mobile network and the non-3GPP access network, and whether the public land mobile network is visited. Is there an evolved packet data gateway, can you provide access to public land mobile networks?
  • the service information determines the network connection method used.
  • the foregoing method may further include: Step 3: The AAA Proxy sends the determined network connection mode to the non-3GPP access network; Step 4: If the network connection mode is required to connect to the evolved packet data gateway, Then the non-3GPP access network informs the UE to establish a connection between the UE and the evolved packet data gateway.
  • the trust relationship information and the user subscription information of the public land mobile network and the non-3GPP access network are any one of the following: Case 1: The user subscription information is an indication that all services are provided by the public land mobile network, belonging to The public land mobile network and the non-3GPP access network are in a trust relationship; Case 2: the user subscription information is an indication that all services are provided by the public land mobile network, and the public land mobile network and the non-3GPP access network are not trusted; III: The user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the belonging public land mobile network and the non-3GPP access network are not trusted.
  • the AAA Server sends information to the AAA Proxy to allow the public land mobile network to provide services
  • the AAA Proxy decides whether to provide the UE with the public land mobile network service according to the configuration in the visited public land mobile network, if not Providing any access to public land mobile network services, it is considered that services must be provided by the home public land mobile network.
  • the UE does not need to connect to the network through the evolved packet data gateway.
  • the AAA Proxy considers that the UE's network connection does not require an evolved packet data gateway.
  • the AAA Proxy determines that the network connection of the UE needs to pass through the evolved packet data gateway.
  • the user subscription information is an indication that the service can be provided by visiting the public land mobile network
  • the AAA Proxy decides to provide the full service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, if the public land is visited
  • the mobile network and the non-3GPP access network are in a trusted relationship, and the AAA Proxy determines that the UE's network connection does not need to be connected to evolve.
  • 3 P23432 Packet data gateway 3 P23432 Packet data gateway.
  • the user subscription information is an indication that the service can be provided by visiting the public land mobile network
  • the AAA Proxy decides to provide the full service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, if the public land is visited
  • the mobile network and the non-3GPP access network are in an untrusted relationship, and the AAA Proxy determines that the UE's network connection needs to connect to the evolved packet data gateway.
  • the AAA Proxy decides to provide partial service monthly service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land.
  • the mobile network and the non-3GPP access network have a trust relationship. If the AAA server sends the AAA Proxy a message indicating that the home public land mobile network and the non-3GPP access network have a trust relationship, the AAA Proxy determines that the UE's network connection does not need to be connected. Evolved packet data gateway.
  • the AAA Proxy decides to provide a partial service monthly service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land.
  • the mobile network and the non-3GPP access network are trusted. If the home public land mobile network and the non-3GPP access network are in an untrusted relationship, and the public land mobile network does not have an evolved packet data gateway, the AAA Proxy determines the UE. The network connection does not require connection to an evolved packet data gateway.
  • the AAA Proxy decides to provide partial service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land mobile.
  • the network and the non-3GPP access network are trusted. If the home public land mobile network and the non-3GPP access network are in an untrusted relationship, if there is an evolved packet data gateway in the public land mobile network, the AAA Proxy determines the UE. The network connection needs to connect to the evolved packet data gateway.
  • the AAA Proxy decides to provide partial service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land mobile.
  • the network and the non-3GPP access network are in an untrusted relationship, and the AAA Proxy determines that the UE's network connection needs to connect to the evolved packet data gateway.
  • a method of determining a network connection manner is also provided.
  • the user equipment UE roams access to the non-3GPP access network, and the non-3GPP access network sends the user information of the UE to the authentication 4 authorized charging AAA system, and the non-3GPP access network and the AAA system authenticate and authorize the UE.
  • the method includes: determining, by the AAA system, the adopted network connection manner according to the predetermined information, where the predetermined information includes: trust relationship information belonging to a trust relationship between the public land mobile network and the non-3GPP access network, user subscription information, and visiting the public land mobile network and The trust relationship information of the non-3GPP access network, whether the public land mobile network accesses the evolved packet data gateway, and whether the public land mobile network can provide service information.
  • the foregoing AAA system includes an authentication 4 authorized charging proxy AAA Proxy and a home subscriber monthly server HSS/authentication 4 authorized charging server AAA Server.
  • the foregoing AAA system determines the adopted network connection manner according to the predetermined information, including: The AAA server determines that the home public land mobile network and the non-3GPP access network are in a trust relationship, and sends the trust relationship information and the user subscription information indicating the trust relationship between the home public land mobile network and the non-3GPP access network to the AAA Proxy. Second, the AAA Proxy determines the network connection method to be used according to the predetermined information. With at least one of the above technical solutions, the present invention provides for determining that a user equipment is roaming when roaming
  • FIG. 1 is a schematic diagram of an EPC architecture accessed by Non 3 GPP Access when a user roams in the related art
  • FIG. 2 is a flowchart of the AAA Server determining a trust relationship between the HPLMN and the Non-3 GPP Access and notifying the AAA Proxy
  • the AAA Proxy determines the decision logic diagram of the network connection mode.
  • Figure 4 is a flow chart of the AAA Server's decision to adopt the S2b access mode.
  • Figure 5 is a flow chart of the AAA Server's decision to adopt the S2a access mode.
  • Figure 6 is the AAA Proxy decision. A flow chart using the connection method of S2b.
  • a user equipment UE roams into a non-3GPP access network, and a non-3GPP access network sends user information of the UE to an authentication 4 authorized charging agent AAA Proxy and Home subscriber server HSS/authentication 4 authorized billing server AAA Server, non-3GPP access network, AAA Proxy and HSS/AAA authenticate the UE and 4 are authorized, when the AAA Server determines the home public land mobile network and non-3GPP access
  • the network is a trust relationship
  • the trust relationship information and the user subscription information of the public land mobile network and the non-3GPP access network are sent to the AAA Proxy, and then the AAA Proxy accesses the public land mobile network according to the trust relationship information, the user subscription information, and
  • the trust relationship information of the non-3GPP access network, whether the public land mobile network accesses the evolved packet data gateway, and whether the public land mobile network can provide the service information determines the network connection mode.
  • the user subscription information stored in the HSS includes the following indication information: Whether to allow the user to roam to the VPLMN to provide the service service by the VPLMN.
  • the user subscription information is sent from the HSS to the AAA Server of the HPLMN, and the AAA Server determines whether the PDN GW serving the user can be located in the VPLMN according to the subscription information of the user, if not located.
  • VPLMN Home Routed must be provided by the PLM of the HPLMN
  • the AAA Server determines whether there is a trust relationship between the HPLMN and the user's current Non-3GPP Access.
  • the AAA Server determines according to its own configuration, there is no trust relationship between the HPLMN and the user's current Non-3 GPP Access (eg, the port, the HPLMN and the Non- If the 3GPP Access is not signed, the AAA Server notifies the AAA Proxy of the VPLMN to the untrusted relationship, and informs the AAA Proxy that all services must be served by the PDN GW of the HPLMN.
  • the AAA Proxy receives the information from the AAA Server, the information indicates HPLMN and Non-3GPP.
  • the AAA Proxy determines whether the ePDG is deployed on the VPLMN. If there is an ePDG, the AAA Proxy determines that the network connection of the UE must pass the ePDG. Otherwise, the eAPG is not deployed. The AAA Proxy determines the VPLMN and the Non- according to its configuration. Trust relationship between 3GPP, if there is a trust relationship between the VPLMN and the Non-3GPP, and the VPLMN allows chain access
  • Baye AAA Proxy decided to use chained access, if there is no trust relationship, Baye AAA
  • the Proxy determines that the UE cannot access the EPC through the Non-3GPP Access.
  • the above chained connection method is a connection mode in which Non 3GPP Access connects to the P-GW1 of the HPLMN through a monthly service gateway (Serving Gateway, S-GW) in the VPLMN.
  • the AAA Proxy determines the use of the connection mode when the user accesses the authentication and the 4 ⁇ right. After the AAA Proxy decides to use the connection mode, the AAA Proxy selects the S-GW in the VPLMN and selects the S-GW in the authentication process.
  • the GW address is sent to Non 3GPP Access, which is saved by Non 3 GPP Access.
  • the AAA Proxy sends the APN sent by the user at the time of access and the address of the corresponding P-GW1 selected by the network to the selected S-GW, and the subscription information of the user (such as signing the contract). APN, etc.), after that, the S-GW saves the above information.
  • the Non-3GPP Access is in the above-mentioned information sending proxy binding update message to the S-GW, and after receiving the above message, the S-GW establishes a tunnel connection with the P-GW; when the tunnel connection between the S-GW and the P-GW is established After that, the S-GW sends a proxy binding acknowledgement message to the Non 3GPP Access to complete the establishment of a tunnel between the Non 3 GPP Access and the S-GW. Finally, the Non 3GPP Access notifies the UE of the configuration information required by the UE.
  • Step 21 After the AAA Server obtains the subscription information of the user from the HSS, the AAA server The server first determines whether there is an indication that all services of the user must be served by the HPLMN.
  • Step 22 when the subscription information of the user includes the above-mentioned provided by the HPLMN
  • the AAA Server judges the HPLMN and the Non-3GPP Access trust relationship according to the configuration, and the identity information of the Non-3GPP Access is obtained from the Non-3GPP Access through the user authentication process, if the HPLMN and If Non-3GPP Access is trusted, proceed to step 23, otherwise proceed to step 24;
  • Step 23 AAA Server is configured to indicate that HPLMN and Non-3GPP Access are trusted, and all services of the user must be served by HPLMN The AAA Proxy is notified by the indication;
  • the AAA Server is configured to indicate HPLMN and Non-3GPP Access
  • FIG. 3 is a logic diagram for determining the network connection mode determined by the AAA Proxy according to the information sent by the AAA Server in Figure 2.
  • the AAA Proxy indicates whether the user is based on the information sent by the AAA Server. All services are provided by HPLMN to judge: If all services are required to be provided by HPLMN, then the network of the user is determined according to the trust relationship between HPLMN and Non-3GPP Access indicated in the above information and whether there is ePDG in the VPLMN. Whether the connection needs to pass ePDG: If HPLMN and Non-3GPP Access are trusted, the user's network connection does not need to connect to ePDG; if HPLMN and Non-3GPP Access are untrusted, and if there is no ePDG in VPLMN, Bay AAA Proxy It is considered that the network connection of the UE does not require ePDG.
  • the chain access method may be selected, or the user access failure may be determined; if the ePDG is in the VPLMN, the network connection of the UE needs to pass the ePDG; Both are provided by HPLMN, and the information sent by the AAA Server indicates that VPLMN is allowed to provide services.
  • the configuration of the 'J AAA Proxy is determined according to the configuration in the VPLMN.
  • VPLMN service Whether to provide the VPLMN service to the user, if it is unable to provide any VPLMN service, it is considered that the service must be provided by the HPLMN, and the subsequent judgment process is as shown in the above steps (that is, the operation in the case where all services are required to be provided by the HPLMN); If the VPLMN service is allowed, then further judgment is needed to provide some or all of the VPLMN services:
  • the AAA Proxy determines that the user network connection does not need to connect to the ePDG. If the VPLMN and the Non-3GPP Access are not trusted, then the AAA Proxy determines that the user network connection needs to connect to the ePDG;
  • the Bell's AAA Proxy decides The network connection of the UE does not need to be connected to the ePDG. If the HPLMN and the Non-3GPP Access are untrusted, and there is no ePDG in the VPLMN, then the AAA Proxy determines that the UE's network connection does not need to be connected to the ePDG (in this case, the AAA Proxy can The chain access method is selected.
  • FIG. 4 is a flow chart of determining the access mode of the S2b when the subscription information of the user indicates that the UE must be provided by the HPLMN and the AAA Server is not trusted according to the HPLMN and the user's roaming access to the Non 3GPP Access. As shown in FIG.
  • Step 401 The UE accesses Non 3GPP Access, and sends information such as user identity to Non 3 GPP Access, and the Non 3 GPP Access user The information is sent to the AAA Proxy and the HSS/AAA, and the above-mentioned network elements (ie, Non 3GPP Access, AAA Proxy, and HSS/AAA) authenticate the user and 4 are authorized.
  • Step 401 The UE accesses Non 3GPP Access, and sends information such as user identity to Non 3 GPP Access, and the Non 3 GPP Access user The information is sent to the AAA Proxy and the HSS/AAA, and the above-mentioned network elements (ie, Non 3GPP Access, AAA Proxy, and HSS/AAA) authenticate the user and 4 are authorized.
  • the above-mentioned network elements ie, Non 3GPP Access, AAA Proxy, and HSS/AAA
  • the AAA Server, AAA Proxy and/or Non 3GPP Access determine the APN information sent by the UE and the user subscription information stored in the HSS (the information indicates that the user must be provided by the HPLMN)
  • the service is provided by the HPLMN, and the AAA Server decides to adopt the access mode of the S2b, and notifies the UE through the Non 3 GPP Access in the process of authentication and 4 authorization.
  • Step 402 The UE searches for the IP address of the ePDG in the VPLMN. Specifically, the UE may perform the search according to the internal configuration of the UE or according to the information provided by the DNS system.
  • the UE initiates a secure tunnel connection with the ePDG, and sends the APN to the APN.
  • the ePDG During the process of establishing the tunnel, the ePDG interacts with the HSS/AAA server and the AAA Proxy to obtain the IP address of the P-GW1 that can access the PDN service corresponding to the APN and some subscription information including the APN subscribed by the user.
  • Step 404 The ePDG notifies the UE of the address or address prefix.
  • the UE connects to the P-GW1 through the ePDG and establishes a connection of the IP service provided by the HPLMN.
  • FIG. 5 is a flow chart of determining the access mode of the S2a when the subscription information of the user indicates that the user must be provided by the HPLMN and the AAA Server is trusted according to the HPLMN and the user's roaming access to the Non 3GPP Access. As shown in FIG.
  • Step 501 The UE accesses Non 3GPP Access, and sends information such as user identity to Non 3 GPP Access, and the Non 3 GPP Access user
  • the information is sent to the AAA Proxy and the HSS/AAA, and the above-mentioned network elements (ie, Non 3GPP Access, AAA Proxy, and HSS/AAA) authenticate the user and 4 are authorized.
  • the AAA Server, AAA Proxy and/or Non 3GPP Access determine the APN information sent by the UE and the user subscription information stored in the HSS (the information indicates that the user must be provided by the HPLMN)
  • the service is provided by HPLMN.
  • the AAA Server trusts the Non-3GPP Access between the HPLMN and the user roaming access, and determines that the Non 3GPP Access uses the S2a access mode for access, and in the process of authentication and 4 authorization, Sending the IP address of the P-GW1 that can provide the PDN connection service and the subscription information of all the subscription APNs of the user corresponding to the APN sent by the user to the Non 3GPP Access, Step 502, Non 3GPP Access initiates the proxy binding to update Establishing a tunnel connection with the P-GW1, the message bound by the proxy includes the identity of the user and the APN sent by the user, and the P-GW1 assigns an IP address or an address prefix to the UE, and in the proxy binding confirmation message.
  • the IP address or address prefix assigned by the P-GW1 to the UE is notified to the Non 3 GPP Access, and in step 503, the Non 3GPP Access notifies the UE of the above address or address prefix.
  • the UE connects to the P-GW1 through Non 3 GPP Access to establish a connection to the IP service provided by the HPLMN.
  • 6 is a connection mode of the Non 3GPP Access adopting S2b when the subscription information of the user indicates that the user can provide the service monthly service by the VPLMN and the VLPMN and the Non 3 GPP Access are not trusted, the 3GPP AAA Proxy in the VPLMN determines the connection mode of the Non 3GPP Access by using the S2b.
  • Step 601 The UE accesses the Non 3GPP Access, and sends the information such as the user identity to the Non 3 GPP Access.
  • the Non 3GPP Access sends the information of the user to the AAA Proxy and the HSS/AAA.
  • the network element Non 3GPP Access, AAA Proxy
  • HSS/AAA HSS/AAA
  • the AAA Proxy is sent from the HSS/AAA Server.
  • the AAA Proxy determines that the Non 3 GPP Access uses the S2b connection mode to access. And notify the UE through Non 3 GPP Access in the authentication and 4 authorization process. Step « 602, and the above steps « 402, 403, 404 are the same, the UE is connected to the ePDG and passes
  • the P-GW accesses the IP service provided by the UE, where the P-GW can be the P-GW1 of the HPLMN or the P-GW2 of the VPLMN.
  • the AAA server, the AAA Proxy, and/or the ePDG are only based on the APN sent by the UE.
  • the information and the user subscription information stored in the HSS (which indicates that the user can be provided by VPLMN) is determined.
  • a method for determining a network connection manner is further provided, where the user equipment UE roams to a non-3GPP access network, and the non-3GPP access network sends the user information of the UE to the authentication 4 authorized charging.
  • the AAA system, the non-3GPP access network, and the AAA system perform authentication and authorization on the UE.
  • the method specifically includes: determining, by the AAA system, the adopted network connection manner according to the predetermined information, where the predetermined information includes: the home public land mobile network and the non-3GPP interface Trust relationship information of the trust relationship entering the network, user subscription information, access to the trust relationship information of the public land mobile network and the non-3GPP access network, whether the public land mobile network accesses the evolved packet data gateway, and whether the public land mobile network is visited Provide service information.
  • the AAA system includes an authentication 4 authorized charging proxy AAA Proxy and a home subscriber server HSS/authentication authorization accounting server AAA Server.
  • the AAA system determines, according to the predetermined information, the adopted network connection manner, including: Step one, the AAA Server determines The belonging public land mobile network and the non-3GPP access network are in a trust relationship, and the trust relationship information and the user subscription information indicating the trust relationship between the public land mobile network and the non-3GPP access network are sent to the AAA Proxy; Step 2, the AAA Proxy is based on The predetermined information determines the network connection method used.
  • the embodiments of the present invention enable the user to determine the connection mode of accessing the EPC network through Non 3 GPP Access when roaming, which solves the problems in the prior art.
  • modules or steps of the present invention can be implemented by a general-purpose computing device, which can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device, such that they may be stored in the storage device by the computing device, or they may be separately fabricated into individual integrated circuit modules, or they may be Multiple modules or steps are made into a single integrated circuit module. Thus, the invention is not limited to any particular hardware and software.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

A network connection mode determining method comprises the following steps: step 1), an Authentication Authorization and Accounting (AAA) Server determines that the relationship between the Home Public Land Mobile Network (HPLMN) and the Non 3GPP Access Network is trustworthy, and then sends the trust relationship information of the HPLMN and the Non 3GPP Access Network, and the user signature information to the AAA Proxy, and, step 2), the AAA Proxy determines the network connection mode according to the trust relationship above, the user signature information, the trust relationship of the Visited Public Land Mobile Network (VPLMN) and the Non 3GPP Access Network, whether the VPLMN has an Evolved Packet Data Gateway (ePDG), and whether the VPLMN can provide a service information. The present invention provides a method for determining the connection mode about how to access the Evolved Packet Core (EPC) Network through a Non 3GPP Access Network while a user's end (UE) is roaming.

Description

网络连接方式的确定方法  Method for determining network connection method
技术领域 本发明涉及通信技术领域, 尤其涉及一种网络连接方式的确定方法。 背景技术 为了保持第三代移动通信系统在移动通信领域的竟争力,需要提高其网 络性能和降低网络建设和运营成本, 因此, 第三代合作伙伴计划 ( 3rd Generation Partnership Project, 简称为 3GPP ) 的标准化工作组目前正致力研 究核心网系统下一代演进——演进的分组核心网( Evolved Packet Core, 简称 为 EPC ), 目的是能够为用户提供更高的传输速率、 更短的传输延时。 EPC 系统支持非 3GPP无线接入网的接入。 图 1是非 3GPP无线接入网通过拜访 公共陆地移动网络 ( Visited Public Land Mobile Network, 简称为 VPLMN ) 接入归属公共陆地移动网络 ( Home PLMN, 简称为 HPLMN ) 的示意图, 如 图 1所示, 其中涉及的网元有: 分组数据网网关( Packet Data Network Gateway , 简称为 P-GW ), 负责 UE接入分组数据网 ( Packet Data Network , 简称为 PDN ) 的网关功能; 归属用户服务器 ( Home Subscriber Server, 简称为 HSS ), 位于用户的 归属网络, 用于永久保存用户签约数据和安全数据; 为了支持非 3GPP接入系统接入 EPC , 认证 4受权计费 (Authentication Authorization and Accounting, 简称为 AAA ) 系统还包括认证 4受权计费月 务 器 (简称为 AAA Server ) 和认证 4受权计费代理 (简称为 AAA Proxy )。 非 3 GPP无线接入网包括如下两种类型: The present invention relates to the field of communications technologies, and in particular, to a method for determining a network connection manner. BACKGROUND OF THE INVENTION In order to maintain the competitiveness of the third generation mobile communication system in the field of mobile communication, it is necessary to improve its network performance and reduce network construction and operation costs. Therefore, the 3rd Generation Partnership Project (3GPP) is referred to as 3GPP. The standardization working group is currently working on the next-generation evolution of the core network system, the Evolved Packet Core (EPC), which aims to provide users with higher transmission rates and shorter transmission delays. The EPC system supports access to non-3GPP radio access networks. 1 is a schematic diagram of a non-3GPP radio access network accessing a Home Public Land Mobile Network (Home PLMN, referred to as HPLMN) by visiting a Public Land Mobile Network (VPLMN), as shown in FIG. The network elements involved are: Packet Data Network Gateway (P-GW), which is responsible for the gateway function of the UE accessing the Packet Data Network (PDN); Home Subscriber Server (Home Subscriber Server) , referred to as HSS), is located in the user's home network, and is used to permanently store user subscription data and security data. In order to support non-3GPP access system access to EPC, Authentication Authorization and Accounting (AAA) system It also includes an authentication 4 authorized charging server (referred to as AAA Server for short) and an authentication 4 authorized charging agent (referred to as AAA Proxy for short). Non-3GPP radio access networks include the following two types:
Trusted Non 3 GPP Access (信任的非 3GPP接入网), 3GPP网络和该非 3GPP接入系统之间存在信任关系,非 3GPP接入系统可以直接通过 S2a接入 P-GW。 Trusted Non 3 GPP Access (trusted non-3GPP access network), there is a trust relationship between the 3GPP network and the non-3GPP access system, and the non-3GPP access system can directly access the P-GW through S2a.
Untrusted Non 3GPP Access (不信任的非 3GPP接入网), 3GPP网络和 该非 3GPP接入系统之间不存在信任关系, 非 3GPP接入系统必须首先接入 Untrusted Non 3GPP Access (untrusted non-3GPP access network), there is no trust relationship between the 3GPP network and the non-3GPP access system, and the non-3GPP access system must first access
1 P23432 3GPP 网络的演进的分组数据网关 (Evolved Packet Data Gateway, 简称为 ePDG ), 再通过 S2b接入 P-GW。 这时 UE与 ePDG之间建立一个安全隧道, 保证 UE与 3GPP网络之间的数据传输安全。 在图 1中, HPLMN和 VPLMN与 Non 3GPP Access之间可能分别建立 了信任关系, 例如, HPLMN和 VPLMN都认为该 Non 3 GPP Access是可信 任, 或者 HPLMN和 VPLMN中的任何一方都可能将该 Non-3 GPP Access看 成是不可信任的。 当允许移动终端从 Non-3GPP Access直接接入一个 PLMN 的 PDN GW时, 该 PLMN和该 Non-3GPP Access间是可信任关系; 否则, 若 PLMN和 Non-3GPP Access间是不可信任关系, 则从该 Non-3GPP Access 接入的移动终端必须经过安全网关 ePDG才能接入该 PLMN的 PDN GW。在 非漫游时, HPLMN和 Non-3GPP Access之间的信任关系由 HPLMN决定, 但当用户从 Non-3GPP Access接入 VPLMN时, 才艮据提供业务的位置不同, 为该用户提供月 务的 PDN GW可能位于 HPLMN, 也可能位于 VPLMN, 但 是, 目前, 还没有 Non 3GPP Access此时采用哪种连接方式的确定方法。 发明内容 针对现有技术中存在的在用户设备在漫游时无法确定通过 Non-3GPP Access接入 VPLMN的连接方式的问题而提出本发明, 为此, 本发明的目的 在于提供一种针对上述问题的解决方案。 为了实现上述目的, 才艮据本发明的一个方面, 提供了一种网络连接方式 的确定方法。 其中, 用户设备 ( UE ) 漫游接入非 3GPP接入网, 非 3GPP接入网 ^!夺 UE的用户信息发给认证 4受权计费代理 AAA Proxy和归属用户服务器 HSS/ 认证 4受权计费月 务器 AAA Server,非 3GPP接入网、 AAA Proxy和 HSS/AAA 对 UE进行认证与 4受权, 上述网络连接方式的确定方法包括: 步骤一, AAA Server决定归属公共陆地移动网络与非 3GPP接入网为信 任关系, 将归属公共陆地移动网络与非 3GPP接入网的信任关系信息以及用 户签约信息发送给 AAA Proxy; 步骤二, AAA Proxy才艮据 AAA Server发来的信任关系信息、 用户签约 信息、 拜访公共陆地移动网络与非 3GPP接入网的信任关系信息、 拜访公共 陆地移动网络是否有演进的分组数据网关、 拜访公共陆地移动网络能否提供 1 P23432 The Evolved Packet Data Gateway (ePDG) of the 3GPP network is connected to the P-GW through S2b. At this time, a secure tunnel is established between the UE and the ePDG to ensure data transmission security between the UE and the 3GPP network. In Figure 1, a trust relationship may be established between HPLMN and VPLMN and Non 3GPP Access. For example, both HPLMN and VPLMN consider the Non 3 GPP Access to be trusted, or either of HPLMN and VPLMN may -3 GPP Access is considered untrustworthy. When the mobile terminal is allowed to directly access the PDN GW of a PLMN from Non-3GPP Access, the PLMN and the Non-3GPP Access are trusted relationships; otherwise, if the PLMN and the Non-3GPP Access are not trusted, then The mobile terminal accessed by the Non-3GPP Access must pass through the security gateway ePDG to access the PDN GW of the PLMN. When non-roaming, the trust relationship between HPLMN and Non-3GPP Access is determined by the HPLMN, but when the user accesses the VPLMN from Non-3GPP Access, the PDN of the monthly service is provided for the user according to the location of the service provided. The GW may be located in the HPLMN or in the VPLMN. However, at present, there is no method for determining which connection method the Non 3GPP Access adopts at this time. SUMMARY OF THE INVENTION The present invention has been made in view of the problem in the prior art that the user equipment cannot determine the connection mode of accessing the VPLMN through Non-3GPP Access when roaming, and it is therefore an object of the present invention to provide a solution to the above problem. solution. In order to achieve the above object, according to an aspect of the present invention, a method of determining a network connection manner is provided. The user equipment (UE) roams access to the non-3GPP access network, and the non-3GPP access network ^! User information of the UE is sent to the authentication 4 authorized charging agent AAA Proxy and the home subscriber server HSS/authentic 4 authorized charging server AAA Server, non-3GPP access network, AAA Proxy and HSS/AAA to authenticate the UE and 4 The method for determining the foregoing network connection manner includes: Step 1: The AAA Server determines that the belonging public land mobile network and the non-3GPP access network are in a trust relationship, and the trust relationship information and the user belonging to the public land mobile network and the non-3GPP access network are used. The subscription information is sent to the AAA Proxy. Step 2: The AAA Proxy reports the trust relationship information sent by the AAA Server, the user subscription information, the trust relationship information between the public land mobile network and the non-3GPP access network, and whether the public land mobile network is visited. Is there an evolved packet data gateway, can you provide access to public land mobile networks?
2 P23432 服务信息决定采用的网络连接方式。 在步骤二之后, 上述的方法优选地还可以包括: 步骤三, AAA Proxy将确定的网络连接方式发送给非 3GPP接入网; 步骤四,若网络连接方式为需要连接到演进的分组数据网关,则非 3GPP 接入网通知 UE建立 UE与演进的分组数据网关的连接。 其中, 步骤一中, 归属公共陆地移动网络与非 3GPP接入网信任关系信 息以及用户签约信息为以下任意一种: 情况一: 用户签约信息为全部业务由归属公共陆地移动网络提供的指 示, 归属公共陆地移动网络与非 3GPP接入网为信任关系; 情况二: 用户签约信息为全部业务由归属公共陆地移动网络提供的指 示, 归属公共陆地移动网络与非 3GPP接入网为不信任关系; 情况三: 用户签约信息为业务可由拜访公共陆地移动网络提供的指示, 归属公共陆地移动网络与非 3GPP接入网为不信任关系。 上述的方法, 其中, AAA Server向 AAA Proxy发送允许拜访公共陆地 移动网络提供业务的信息, AAA Proxy才艮据拜访公共陆地移动网络中的配置 决定是否向 UE提供拜访公共陆地移动网络服务, 若不提供任何拜访公共陆 地移动网络服务, 则认为必须由归属公共陆地移动网络提供服务。 上述的方法, 在情况一时, UE不需要通过演进的分组数据网关连接网 络。 上述的方法, 在情况二时, 若拜访公共陆地移动网络中没有演进的分组 数据网关, 则 AAA Proxy认为 UE的网络连接不需要演进的分组数据网关。 上述的方法, 在情况二时, 若拜访公共陆地移动网络中有演进的分组数 据网关, 则 AAA Proxy决定 UE的网络连接需要经过演进的分组数据网关。 上述的方法, 其中, 用户签约信息为业务可由拜访公共陆地移动网络提 供的指示, AAA Proxy根据拜访公共陆地移动网络中的配置决定由拜访公共 陆地移动网络向 UE提供全部业务服务,若拜访公共陆地移动网络与非 3GPP 接入网为可信任关系, 贝l AAA Proxy决定 UE的网络连接不需要连接演进的 2 P23432 The service information determines the network connection method used. After the second step, the foregoing method may further include: Step 3: The AAA Proxy sends the determined network connection mode to the non-3GPP access network; Step 4: If the network connection mode is required to connect to the evolved packet data gateway, Then the non-3GPP access network informs the UE to establish a connection between the UE and the evolved packet data gateway. In the first step, the trust relationship information and the user subscription information of the public land mobile network and the non-3GPP access network are any one of the following: Case 1: The user subscription information is an indication that all services are provided by the public land mobile network, belonging to The public land mobile network and the non-3GPP access network are in a trust relationship; Case 2: the user subscription information is an indication that all services are provided by the public land mobile network, and the public land mobile network and the non-3GPP access network are not trusted; III: The user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the belonging public land mobile network and the non-3GPP access network are not trusted. The above method, wherein the AAA Server sends information to the AAA Proxy to allow the public land mobile network to provide services, and the AAA Proxy decides whether to provide the UE with the public land mobile network service according to the configuration in the visited public land mobile network, if not Providing any access to public land mobile network services, it is considered that services must be provided by the home public land mobile network. In the above method, in case 1, the UE does not need to connect to the network through the evolved packet data gateway. In the above method, in case 2, if there is no evolved packet data gateway in the public land mobile network, the AAA Proxy considers that the UE's network connection does not require an evolved packet data gateway. In the above method, in case 2, if there is an evolved packet data gateway in the public land mobile network, the AAA Proxy determines that the network connection of the UE needs to pass through the evolved packet data gateway. The above method, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the AAA Proxy decides to provide the full service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, if the public land is visited The mobile network and the non-3GPP access network are in a trusted relationship, and the AAA Proxy determines that the UE's network connection does not need to be connected to evolve.
3 P23432 分组数据网关。 上述的方法, 其中, 用户签约信息为业务可由拜访公共陆地移动网络提 供的指示, AAA Proxy根据拜访公共陆地移动网络中的配置决定由拜访公共 陆地移动网络向 UE提供全部业务服务,若拜访公共陆地移动网络与非 3GPP 接入网为不信任关系, 则 AAA Proxy决定 UE的网络连接需要连接演进的分 组数据网关。 上述的方法, 其中, 用户签约信息为业务可由拜访公共陆地移动网络提 供的指示, AAA Proxy根据拜访公共陆地移动网络中的配置决定由拜访公共 陆地移动网络向 UE提供部分业务月 务, 拜访公共陆地移动网络与非 3GPP 接入网为信任关系, 若 AAA Server向 AAA Proxy发送表明归属公共陆地移 动网络与该非 3GPP接入网为信任关系的信息, 贝l AAA Proxy决定 UE的网 络连接不需要连接演进的分组数据网关。 上述的方法, 其中, 用户签约信息为业务可由拜访公共陆地移动网络提 供的指示, AAA Proxy根据拜访公共陆地移动网络中的配置决定由拜访公共 陆地移动网络向 UE提供部分业务月 务,拜访公共陆地移动网络与该非 3GPP 接入网是信任的, 若归属公共陆地移动网络与该非 3GPP接入网为不信任关 系, 且拜访公共陆地移动网络中没有演进的分组数据网关, 则 AAA Proxy决 定 UE的网络连接不需要连接演进的分组数据网关。 上述的方法, 其中, 用户签约信息为业务可由拜访公共陆地移动网络提 供的指示, AAA Proxy根据拜访公共陆地移动网络中的配置决定由拜访公共 陆地移动网络向 UE提供部分业务服务,拜访公共陆地移动网络与该非 3GPP 接入网是信任的, 若归属公共陆地移动网络与该非 3GPP接入网为不信任关 系, 如果拜访公共陆地移动网络中有演进的分组数据网关, 贝l AAA Proxy决 定 UE的网络连接需要连接演进的分组数据网关。 上述的方法, 其中, 用户签约信息为业务可由拜访公共陆地移动网络提 供的指示, AAA Proxy根据拜访公共陆地移动网络中的配置决定由拜访公共 陆地移动网络向 UE提供部分业务服务,拜访公共陆地移动网络与该非 3GPP 接入网为不信任关系, AAA Proxy决定 UE的网络连接需要连接演进的分组 数据网关。 3 P23432 Packet data gateway. The above method, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the AAA Proxy decides to provide the full service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, if the public land is visited The mobile network and the non-3GPP access network are in an untrusted relationship, and the AAA Proxy determines that the UE's network connection needs to connect to the evolved packet data gateway. The above method, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the AAA Proxy decides to provide partial service monthly service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land. The mobile network and the non-3GPP access network have a trust relationship. If the AAA server sends the AAA Proxy a message indicating that the home public land mobile network and the non-3GPP access network have a trust relationship, the AAA Proxy determines that the UE's network connection does not need to be connected. Evolved packet data gateway. The above method, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the AAA Proxy decides to provide a partial service monthly service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land. The mobile network and the non-3GPP access network are trusted. If the home public land mobile network and the non-3GPP access network are in an untrusted relationship, and the public land mobile network does not have an evolved packet data gateway, the AAA Proxy determines the UE. The network connection does not require connection to an evolved packet data gateway. The above method, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the AAA Proxy decides to provide partial service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land mobile. The network and the non-3GPP access network are trusted. If the home public land mobile network and the non-3GPP access network are in an untrusted relationship, if there is an evolved packet data gateway in the public land mobile network, the AAA Proxy determines the UE. The network connection needs to connect to the evolved packet data gateway. The above method, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the AAA Proxy decides to provide partial service service to the UE by visiting the public land mobile network according to the configuration in the visited public land mobile network, and visits the public land mobile. The network and the non-3GPP access network are in an untrusted relationship, and the AAA Proxy determines that the UE's network connection needs to connect to the evolved packet data gateway.
4 P23432 才艮据本发明的另一方面, 还提供了一种网络连接方式的确定方法。 其中, 用户设备 UE漫游接入非 3GPP接入网, 非 3GPP接入网将 UE 的用户信息发送给认证 4受权计费 AAA系统, 非 3GPP接入网、 AAA系统对 UE进行认证与授权, 该方法包括: AAA系统根据预定信息确定采用的网络 连接方式, 其中, 预定信息包括: 归属公共陆地移动网络与非 3GPP接入网 的信任关系的信任关系信息、 用户签约信息、 拜访公共陆地移动网络与非 3GPP 接入网的信任关系信息、 拜访公共陆地移动网络是否有演进的分组数 据网关、 拜访公共陆地移动网络能否提供服务信息。 上述 AAA 系统包括认证 4受权计费代理 AAA Proxy和归属用户月 务器 HSS/认证 4受权计费月 务器 AAA Server, 因此, 上述 AAA系统才艮据预定信息 确定采用的网络连接方式包括: 步骤一, AAA Server确定归属公共陆地移动 网络与非 3GPP接入网为信任关系,将表示归属公共陆地移动网络与非 3GPP 接入网的信任关系的信任关系信息以及用户签约信息发送给 AAA Proxy; 步 骤二, AAA Proxy根据预定信息确定采用的网络连接方式。 借助于上述技术方案至少之一,本发明提供了用户设备漫游时确定通过4 P23432 According to another aspect of the present invention, a method of determining a network connection manner is also provided. The user equipment UE roams access to the non-3GPP access network, and the non-3GPP access network sends the user information of the UE to the authentication 4 authorized charging AAA system, and the non-3GPP access network and the AAA system authenticate and authorize the UE. The method includes: determining, by the AAA system, the adopted network connection manner according to the predetermined information, where the predetermined information includes: trust relationship information belonging to a trust relationship between the public land mobile network and the non-3GPP access network, user subscription information, and visiting the public land mobile network and The trust relationship information of the non-3GPP access network, whether the public land mobile network accesses the evolved packet data gateway, and whether the public land mobile network can provide service information. The foregoing AAA system includes an authentication 4 authorized charging proxy AAA Proxy and a home subscriber monthly server HSS/authentication 4 authorized charging server AAA Server. Therefore, the foregoing AAA system determines the adopted network connection manner according to the predetermined information, including: The AAA server determines that the home public land mobile network and the non-3GPP access network are in a trust relationship, and sends the trust relationship information and the user subscription information indicating the trust relationship between the home public land mobile network and the non-3GPP access network to the AAA Proxy. Second, the AAA Proxy determines the network connection method to be used according to the predetermined information. With at least one of the above technical solutions, the present invention provides for determining that a user equipment is roaming when roaming
Non 3 GPP Access接入 EPC网络的连接方式的方法。 附图说明 图 1是相关技术中的用户漫游时通过 Non 3 GPP Access接入 EPC架构 图; 图 2是 AAA Server判断 HPLMN与 Non-3 GPP Access信任关系以及通 知 AAA Proxy的流程图; 图 3是 AAA Proxy决定采用网络连接方式的判断逻辑图; 图 4是 AAA Server决定采用 S2b的接入方式的流程图; 图 5是 AAA Server决定采用 S2a的接入方式的流程图; 图 6是 AAA Proxy决定采用 S2b的连接方式的流程图。 The method by which Non 3 GPP Access accesses the connection mode of the EPC network. BRIEF DESCRIPTION OF DRAWINGS FIG. 1 is a schematic diagram of an EPC architecture accessed by Non 3 GPP Access when a user roams in the related art; FIG. 2 is a flowchart of the AAA Server determining a trust relationship between the HPLMN and the Non-3 GPP Access and notifying the AAA Proxy; The AAA Proxy determines the decision logic diagram of the network connection mode. Figure 4 is a flow chart of the AAA Server's decision to adopt the S2b access mode. Figure 5 is a flow chart of the AAA Server's decision to adopt the S2a access mode. Figure 6 is the AAA Proxy decision. A flow chart using the connection method of S2b.
5 P23432 具体实施方式 功能相克述 在本实施例提供的技术方案中, 在用户设备 UE漫游接入非 3GPP接入 网, 非 3GPP接入网将 UE的用户信息发给认证 4受权计费代理 AAA Proxy和 归属用户服务器 HSS/认证 4受权计费月 务器 AAA Server, 非 3GPP接入网、 AAA Proxy和 HSS/AAA对 UE进行认证与 4受权, 当 AAA Server确定归属公 共陆地移动网络与非 3GPP接入网为信任关系时, 将归属公共陆地移动网络 与非 3GPP接入网的信任关系信息以及用户签约信息发送给 AAA Proxy, 然 后, AAA Proxy根据信任关系信息、 用户签约信息、 拜访公共陆地移动网络 与非 3GPP接入网的信任关系信息、 拜访公共陆地移动网络是否有演进的分 组数据网关、 拜访公共陆地移动网络能否提供服务信息确定采用的网络连接 方式。 本发明实施例提出的一种漫游时网络连接方式的确定方法中, 在 HSS 保存的用户签约信息中包含如下指示信息: 是否允许用户漫游到 VPLMN的 时候由 VPLMN提供业务服务。 在用户接入认证和授权过程中, 上述用户签 约信息从 HSS发送给 HPLMN的 AAA Server, AAA Server才艮据该用户的签 约信息确定为该用户提供业务的 PDN GW是否可以位于 VPLMN, 若不能位 于 VPLMN(即家乡路由( Home Routed )必须由 HPLMN的 P-GW提供业务 ), 贝l AAA Server判断 HPLMN与用户当前所在 Non-3GPP Access间是否存在信 任关系, 若 HPLMN与 Non-3GPP间存在信任关系, 则给该 UE提供服务的 网络连接不需经过 ePDG; 若 AAA Server才艮据自己的配置判断 HPLMN与用 户当前所在 Non-3 GPP Access 间不存在信任关系 (例 ¾口, HPLMN 与该 Non-3GPP Access未签约),则 AAA Server将该不信任关系通知位于 VPLMN 的 AAA Proxy, 并告知 AAA Proxy所有业务必须由 HPLMN的 PDN GW为 用户提供服务。 当 AAA Proxy从 AAA Server接^:到的信息指示 HPLMN与 Non-3GPP5 P23432 DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS In the technical solution provided by this embodiment, a user equipment UE roams into a non-3GPP access network, and a non-3GPP access network sends user information of the UE to an authentication 4 authorized charging agent AAA Proxy and Home subscriber server HSS/authentication 4 authorized billing server AAA Server, non-3GPP access network, AAA Proxy and HSS/AAA authenticate the UE and 4 are authorized, when the AAA Server determines the home public land mobile network and non-3GPP access When the network is a trust relationship, the trust relationship information and the user subscription information of the public land mobile network and the non-3GPP access network are sent to the AAA Proxy, and then the AAA Proxy accesses the public land mobile network according to the trust relationship information, the user subscription information, and The trust relationship information of the non-3GPP access network, whether the public land mobile network accesses the evolved packet data gateway, and whether the public land mobile network can provide the service information determines the network connection mode. In the method for determining the network connection mode during roaming, the user subscription information stored in the HSS includes the following indication information: Whether to allow the user to roam to the VPLMN to provide the service service by the VPLMN. In the user access authentication and authorization process, the user subscription information is sent from the HSS to the AAA Server of the HPLMN, and the AAA Server determines whether the PDN GW serving the user can be located in the VPLMN according to the subscription information of the user, if not located. VPLMN (Home Routed must be provided by the PLM of the HPLMN), and the AAA Server determines whether there is a trust relationship between the HPLMN and the user's current Non-3GPP Access. If there is a trust relationship between the HPLMN and the Non-3GPP, The network connection that provides the service to the UE does not need to pass the ePDG; if the AAA Server determines according to its own configuration, there is no trust relationship between the HPLMN and the user's current Non-3 GPP Access (eg, the port, the HPLMN and the Non- If the 3GPP Access is not signed, the AAA Server notifies the AAA Proxy of the VPLMN to the untrusted relationship, and informs the AAA Proxy that all services must be served by the PDN GW of the HPLMN. When the AAA Proxy receives the information from the AAA Server, the information indicates HPLMN and Non-3GPP.
Access为非信任关系, 且所有业务均需由 HPLMN的 PDN GW提供月 务时,Access is an untrusted relationship, and all services need to be provided by HPLMN's PDN GW.
AAA Proxy判断 VPLMN是否部署了 ePDG, 若有 ePDG, 贝l AAA Proxy决 定该 UE的网络连接必须经过 ePDG; 否则(即没有部署 ePDG ), AAA Proxy 才艮据自己的配置判断该 VPLMN与该 Non-3GPP间的信任关系,若该 VPLMN 与该 Non-3GPP 间存在可信任关系, 并且 VPLMN 允许采用链式方式接入The AAA Proxy determines whether the ePDG is deployed on the VPLMN. If there is an ePDG, the AAA Proxy determines that the network connection of the UE must pass the ePDG. Otherwise, the eAPG is not deployed. The AAA Proxy determines the VPLMN and the Non- according to its configuration. Trust relationship between 3GPP, if there is a trust relationship between the VPLMN and the Non-3GPP, and the VPLMN allows chain access
HPLMN,贝l AAA Proxy决定采用链式方式接入,若不存在信任关系,贝l AAA HPLMN, Baye AAA Proxy decided to use chained access, if there is no trust relationship, Baye AAA
6 P23432 Proxy决定该 UE不能经过该 Non-3GPP Access接入 EPC。 上述链式 (chained ) 连接方式是漫游情况下, Non 3GPP Access 通过 VPLMN 中的月 务网关 (Serving Gateway, 简称为 S-GW ) 连接到 HPLMN 的 P-GW1的一种连接方式。 AAA Proxy在用户接入认证与 4吏权时决定该连 接方式的使用, 当 AAA Proxy决定采用该连接方式后, AAA Proxy选择一个 VPLMN中的 S-GW, 并在认证过程中将其选择的 S-GW地址发给 Non 3GPP Access, Non 3 GPP Access保存该地址。 在用户认证与 4受权过程完成后, AAA Proxy向选择的上述 S-GW发送用户在接入时发来的 APN以及网络选择的对 应的 P-GW1的地址, 还有用户的签约信息 (如签约 APN等), 之后, S-GW 保存上述信息。 Non 3GPP Access 居上述信息发送代理绑定更新消息给 S-GW, S-GW接收到上述消息后, 建立与 P-GW的隧道连接; 当上述 S-GW 与 P-GW 之间的隧道连接建好之后, S-GW 发送代理绑定确认消息给 Non 3GPP Access, 完成 Non 3 GPP Access与 S-GW之间隧道的建立; 最后, Non 3GPP Access将 UE需要的配置信息通知 UE。 下面结合附图对发明的方法进一步做详细介绍。 需要说明的是, 如果不 沖突, 本申请中的实施例以及实施例中的特征可以相互组合。 图 2是 AAA Server判断 HPLMN与 Non-3 GPP Access信任关系以及通 知 AAA Proxy的流程图, 如图 2所示, 包括如下步骤: 步骤 21 , 当 AAA Server从 HSS获取到用户的签约信息后, AAA Server 首先判断其中是否含有该用户的所有业务必须由 HPLMN提供服务的指示, 如果判断为是, 则进行到步骤 22, 否则, 进行到步骤 25; 步骤 22 , 当用户的签约信息包含上述由 HPLMN提供服务的指示时, AAA Server才艮据自身配置的 HPLMN与 Non-3GPP Access信任关系进行判 断, 其中, Non-3GPP Access 的身份信息通过用户的鉴权认证过程从 Non-3GPP Access得到, 如果 HPLMN与 Non-3GPP Access是信任的, 则进 行到步骤 23 , 否则进行到步骤 24; 步骤 23 , AAA Server进行配置, 以表明 HPLMN与 Non-3GPP Access 是信任的, 该用户的所有业务必须由 HPLMN 提供服务的指示通知 AAA Proxy; 步骤 24 , AAA Server进行配置, 以表明 HPLMN与 Non-3GPP Access 6 P23432 The Proxy determines that the UE cannot access the EPC through the Non-3GPP Access. The above chained connection method is a connection mode in which Non 3GPP Access connects to the P-GW1 of the HPLMN through a monthly service gateway (Serving Gateway, S-GW) in the VPLMN. The AAA Proxy determines the use of the connection mode when the user accesses the authentication and the 4 吏 right. After the AAA Proxy decides to use the connection mode, the AAA Proxy selects the S-GW in the VPLMN and selects the S-GW in the authentication process. The GW address is sent to Non 3GPP Access, which is saved by Non 3 GPP Access. After the user authentication and the 4 authorization process are completed, the AAA Proxy sends the APN sent by the user at the time of access and the address of the corresponding P-GW1 selected by the network to the selected S-GW, and the subscription information of the user (such as signing the contract). APN, etc.), after that, the S-GW saves the above information. The Non-3GPP Access is in the above-mentioned information sending proxy binding update message to the S-GW, and after receiving the above message, the S-GW establishes a tunnel connection with the P-GW; when the tunnel connection between the S-GW and the P-GW is established After that, the S-GW sends a proxy binding acknowledgement message to the Non 3GPP Access to complete the establishment of a tunnel between the Non 3 GPP Access and the S-GW. Finally, the Non 3GPP Access notifies the UE of the configuration information required by the UE. The method of the invention will be further described in detail below with reference to the accompanying drawings. It should be noted that the embodiments in the present application and the features in the embodiments may be combined with each other if they do not conflict. 2 is a flow chart of the AAA Server determining the trust relationship between the HPLMN and the Non-3 GPP Access and notifying the AAA Proxy. As shown in FIG. 2, the method includes the following steps: Step 21: After the AAA Server obtains the subscription information of the user from the HSS, the AAA server The server first determines whether there is an indication that all services of the user must be served by the HPLMN. If the determination is yes, proceed to step 22, otherwise, proceed to step 25; Step 22, when the subscription information of the user includes the above-mentioned provided by the HPLMN When the service is instructed, the AAA Server judges the HPLMN and the Non-3GPP Access trust relationship according to the configuration, and the identity information of the Non-3GPP Access is obtained from the Non-3GPP Access through the user authentication process, if the HPLMN and If Non-3GPP Access is trusted, proceed to step 23, otherwise proceed to step 24; Step 23, AAA Server is configured to indicate that HPLMN and Non-3GPP Access are trusted, and all services of the user must be served by HPLMN The AAA Proxy is notified by the indication; Step 24, the AAA Server is configured to indicate HPLMN and Non-3GPP Access
P23432 是不信任的 (该不信任可以由配置表明或者配置中没有信任关系表明), 该 UE的所有业务必须由 HPLMN提供月^务的指示通知 AAA Proxy; 步骤 25 , 当用户的签约信息表明该用户的业务可以由 VPLMN提供服 务时, AAA Server将上述信息以及由 AAA Server才艮据配置决定的 HPLMN 与 Non-3 GPP Access是不信任的 (该不信任可以由配置表明或者配置中没有 信任关系表明) 等信息通知 AAA Proxy。 图 3是 AAA Proxy才艮据图 2中 AAA Server发来的信息决定采用网络连 接方式的判断逻辑图, 如图 3所示, AAA Proxy才艮据 AAA Server发来的信 息所表明的是否该用户的所有业务由 HPLMN提供来进行判断: 如果要求所有业务都由 HPLMN提供业务,则此时根据上述信息中表明 的 HPLMN与 Non-3GPP Access的信任关系以及 VPLMN中是否有 ePDG来 决定该用户的网络连接是否需要通过 ePDG: 如果 HPLMN 与 Non-3GPP Access 是信任的, 该用户的网络连接不需要连接 ePDG; 如果 HPLMN 与 Non-3GPP Access是不信任的, 且如果 VPLMN中没有 ePDG, 贝l AAA Proxy 认为该 UE的网络连接不需要 ePDG, 这时, 可以选择链式接入方法, 或者, 决定用户接入失败; 如果 VPLMN中有 ePDG, 则该 UE的网络连接需要经 过 ePDG; 如果没有要求所有业务都由 HPLMN提供业务, 并且 AAA Server发来 的信息中表明允许 VPLMN提供业务,贝 'J AAA Proxy才艮据 VPLMN中的配置 决定是否向该用户提供 VPLMN服务, 如果不能提供任何 VPLMN服务, 则 认为必须由 HPLMN提供服务, 则后续判断流程见上面的步骤 (即上述在要 求所有业务都由 HPLMN提供业务的情况下的操作);如果允许提供 VPLMN 服务, 则需要进一步判断是提供部分还是全部的 VPLMN服务: P23432 Is not trusted (the untrusted can be indicated by the configuration or there is no trust relationship in the configuration), all services of the UE must be notified by the HPLMN to provide an indication of the AAA Proxy; Step 25, when the user's subscription information indicates the user When the service can be served by the VPLMN, the AAA Server will not trust the above information and the HPLMN and Non-3 GPP Access determined by the AAA Server configuration. (The mistrust can be indicated by the configuration or there is no trust relationship in the configuration. ) inform the AAA Proxy and other information. Figure 3 is a logic diagram for determining the network connection mode determined by the AAA Proxy according to the information sent by the AAA Server in Figure 2. As shown in Figure 3, the AAA Proxy indicates whether the user is based on the information sent by the AAA Server. All services are provided by HPLMN to judge: If all services are required to be provided by HPLMN, then the network of the user is determined according to the trust relationship between HPLMN and Non-3GPP Access indicated in the above information and whether there is ePDG in the VPLMN. Whether the connection needs to pass ePDG: If HPLMN and Non-3GPP Access are trusted, the user's network connection does not need to connect to ePDG; if HPLMN and Non-3GPP Access are untrusted, and if there is no ePDG in VPLMN, Bay AAA Proxy It is considered that the network connection of the UE does not require ePDG. In this case, the chain access method may be selected, or the user access failure may be determined; if the ePDG is in the VPLMN, the network connection of the UE needs to pass the ePDG; Both are provided by HPLMN, and the information sent by the AAA Server indicates that VPLMN is allowed to provide services. The configuration of the 'J AAA Proxy is determined according to the configuration in the VPLMN. Whether to provide the VPLMN service to the user, if it is unable to provide any VPLMN service, it is considered that the service must be provided by the HPLMN, and the subsequent judgment process is as shown in the above steps (that is, the operation in the case where all services are required to be provided by the HPLMN); If the VPLMN service is allowed, then further judgment is needed to provide some or all of the VPLMN services:
(一) 由 VPLMN提供所有业务 此时, 如果 AAA Proxy 才艮据自身配置决定 VPLMN 与该 Non-3GPP(1) All services provided by VPLMN At this time, if AAA Proxy decides VPLMN and the Non-3GPP according to its own configuration
Access 是信任的, 则此时由 AAA Proxy 决定该用户网络连接不需要连接 ePDG ,如果 VPLMN与该 Non-3GPP Access是不信任的,则此时由 AAA Proxy 决定该用户网络连接需要连接 ePDG; Access is trusted, then the AAA Proxy determines that the user network connection does not need to connect to the ePDG. If the VPLMN and the Non-3GPP Access are not trusted, then the AAA Proxy determines that the user network connection needs to connect to the ePDG;
8 P23432 (二) 由 VPLMN提供部分业务 此时, 如果 VPLMN与该 Non-3GPP Access是信任的, 且 AAA Server 发给 AAA Proxy的信息表明 HPLMN与该 Non-3GPP Access是信任的, 贝 'J AAA Proxy 决定该 UE 的网络连接不需要连接 ePDG, 如果 HPLMN与该 Non-3GPP Access是不信任的, 且 VPLMN中没有 ePDG , 则此时 AAA Proxy 决定该 UE的网络连接不需要连接 ePDG (这时 AAA Proxy可以选择链式接 入方法), 但是, 如果 VPLMN中有 ePDG, 那么 AAA Proxy决定该用户网 络连接需要连接 ePDG。 图 4是当用户的签约信息表明该 UE必须由 HPLMN提供业务服务、 AAA Server才艮据 HPLMN与用户漫游接入的 Non 3GPP Access之间是不信任 的, 决定采用 S2b的接入方式的流程图, 如图 4所示, 该流程包括如下步骤 (步骤 401—步骤 404 ): 步骤 401、 UE接入 Non 3GPP Access ,将用户身份等信息发给 Non 3 GPP Access, Non 3 GPP Access将该用户的信息发给 AAA Proxy和 HSS/AAA, 上 述网元(即 Non 3GPP Access、 AAA Proxy和 HSS/AAA )对该用户进行认证 与 4受权。 在认证与 4受权过程中, AAA Server, AAA Proxy 和 /或 Non 3GPP Access根据 UE发来的 APN信息以及保存在 HSS中的用户签约信息 (该信 息表明该用户必须由 HPLMN提供业务服务 ) 决定该业务由 HPLMN提供, AAA Server决定采用 S2b的接入方式,并在认证与 4受权过程中通过 Non 3 GPP Access通知 UE。 步骤 402、 UE查找在 VPLMN的 ePDG的 IP地址, 具体地, 可以才艮据 UE的内部配置或者根据 DNS 系统提供的信息来进行查找; UE发起建立与 ePDG的安全隧道连接, 同时将 APN发给该 ePDG。 在建立隧道的过程中, ePDG与 HSS/AAA Server和 AAA Proxy进行交互, 获取可以接入上述 APN 对应的 PDN业务的 P-GW1的 IP地址以及包括用户签约的 APN的一些签约 信息。 步骤 403、 ePDG发起代理绑定, 以更新与 P-GW1之间建立隧道连接, 在上述代理绑定的消息中包含用户的身份, P-GW1 为该 UE分配 IP地址或 地址前缀, 并在代理绑定确认消息中将 P-GW 1为该 UE分配的 IP地址或地 址前缀通知给 ePDG。 8 P23432 (2) Part of the service provided by the VPLMN. At this time, if the VPLMN and the Non-3GPP Access are trusted, and the information sent by the AAA Server to the AAA Proxy indicates that the HPLMN and the Non-3GPP Access are trusted, the Bell's AAA Proxy decides The network connection of the UE does not need to be connected to the ePDG. If the HPLMN and the Non-3GPP Access are untrusted, and there is no ePDG in the VPLMN, then the AAA Proxy determines that the UE's network connection does not need to be connected to the ePDG (in this case, the AAA Proxy can The chain access method is selected. However, if there is an ePDG in the VPLMN, the AAA Proxy determines that the user network connection needs to connect to the ePDG. FIG. 4 is a flow chart of determining the access mode of the S2b when the subscription information of the user indicates that the UE must be provided by the HPLMN and the AAA Server is not trusted according to the HPLMN and the user's roaming access to the Non 3GPP Access. As shown in FIG. 4, the process includes the following steps (step 401 - step 404): Step 401: The UE accesses Non 3GPP Access, and sends information such as user identity to Non 3 GPP Access, and the Non 3 GPP Access user The information is sent to the AAA Proxy and the HSS/AAA, and the above-mentioned network elements (ie, Non 3GPP Access, AAA Proxy, and HSS/AAA) authenticate the user and 4 are authorized. In the authentication and 4 authorization process, the AAA Server, AAA Proxy and/or Non 3GPP Access determine the APN information sent by the UE and the user subscription information stored in the HSS (the information indicates that the user must be provided by the HPLMN) The service is provided by the HPLMN, and the AAA Server decides to adopt the access mode of the S2b, and notifies the UE through the Non 3 GPP Access in the process of authentication and 4 authorization. Step 402: The UE searches for the IP address of the ePDG in the VPLMN. Specifically, the UE may perform the search according to the internal configuration of the UE or according to the information provided by the DNS system. The UE initiates a secure tunnel connection with the ePDG, and sends the APN to the APN. The ePDG. During the process of establishing the tunnel, the ePDG interacts with the HSS/AAA server and the AAA Proxy to obtain the IP address of the P-GW1 that can access the PDN service corresponding to the APN and some subscription information including the APN subscribed by the user. Step 403: The ePDG initiates a proxy binding to update a tunnel connection with the P-GW1, where the message bound by the proxy includes the identity of the user, and the P-GW1 allocates an IP address or an address prefix to the UE, and is in the proxy. The IP address or address prefix assigned by the P-GW 1 to the UE is notified to the ePDG in the binding acknowledgement message.
9 P23432 步骤 404、 ePDG将上述地址或地址前缀通知给 UE。 UE通过 ePDG连 接到 P-GW1 , 并建立 HPLMN提供的 IP业务的连接。 图 5是当用户的签约信息表明该用户必须由 HPLMN提供业务月 务、 AAA Server才艮据 HPLMN与用户漫游接入的 Non 3GPP Access之间是信任的, 决定采用 S2a的接入方式的流程图, 如图 5所示, 该流程包括如下步骤(步 骤 501—步骤 503 ): 步骤 501、 UE接入 Non 3GPP Access ,将用户身份等信息发给 Non 3 GPP Access, Non 3 GPP Access将该用户的信息发给 AAA Proxy和 HSS/AAA, 上 述网元(即 Non 3GPP Access, AAA Proxy和 HSS/AAA )对该用户进行认证 与 4受权。 在认证与 4受权过程中, AAA Server, AAA Proxy 和 /或 Non 3GPP Access根据 UE发来的 APN信息以及保存在 HSS中的用户签约信息 (该信 息表明该用户必须由 HPLMN提供业务服务 ) 决定该业务由 HPLMN提供, AAA Server才艮据 HPLMN与用户漫游接入的 Non 3GPP Access之间是信任的, 决定该 Non 3GPP Access采用 S2a的接入方式进行接入, 并在认证与 4受权过 程中, 将用户发来的 APN对应的可提供 PDN连接业务的 P-GW1的 IP地址 以及包括用户的所有签约 APN的一些签约信息发给 Non 3GPP Access, 步骤 502、 Non 3GPP Access发起代理绑定, 以更新与 P-GW1之间建立 隧道连接, 在上述代理绑定的消息中包含用户的身份以及用户发来的 APN, P-GW1为该 UE分配 IP地址或地址前缀,并在代理绑定确认消息中将 P-GW1 为该 UE分配的 IP地址或地址前缀通知给 Non 3 GPP Access, 步骤 503、 Non 3GPP Access将上述地址或地址前缀通知 UE。 UE通过 Non 3 GPP Access连接到 P-GW1 , 建立到 HPLMN提供的 IP业务的连接。 图 6是当用户的签约信息表明该用户可以由 VPLMN提供业务月 务、而 VPLMN与 Non 3 GPP Access之间是不信任时, 由 VPLMN中的 3GPP AAA Proxy决定该 Non 3GPP Access采用 S2b的连接方式的流程图, 如图 6所示, 该流程包括如下步骤 (步骤 601—步骤 602 )。 步骤 601、 UE接入 Non 3GPP Access ,将用户身份等信息发给 Non 3 GPP Access, Non 3GPP Access将该用户的信息发给 AAA Proxy和 HSS/AAA, 上 述网元(即 Non 3GPP Access, AAA Proxy和 HSS/AAA )对该用户进行认证 与 4受权。 在认证与 4受权过程中, AAA Proxy才艮据从 HSS/AAA Server发来的 9 P23432 Step 404: The ePDG notifies the UE of the address or address prefix. The UE connects to the P-GW1 through the ePDG and establishes a connection of the IP service provided by the HPLMN. FIG. 5 is a flow chart of determining the access mode of the S2a when the subscription information of the user indicates that the user must be provided by the HPLMN and the AAA Server is trusted according to the HPLMN and the user's roaming access to the Non 3GPP Access. As shown in FIG. 5, the process includes the following steps (step 501 - step 503): Step 501: The UE accesses Non 3GPP Access, and sends information such as user identity to Non 3 GPP Access, and the Non 3 GPP Access user The information is sent to the AAA Proxy and the HSS/AAA, and the above-mentioned network elements (ie, Non 3GPP Access, AAA Proxy, and HSS/AAA) authenticate the user and 4 are authorized. In the authentication and 4 authorization process, the AAA Server, AAA Proxy and/or Non 3GPP Access determine the APN information sent by the UE and the user subscription information stored in the HSS (the information indicates that the user must be provided by the HPLMN) The service is provided by HPLMN. The AAA Server trusts the Non-3GPP Access between the HPLMN and the user roaming access, and determines that the Non 3GPP Access uses the S2a access mode for access, and in the process of authentication and 4 authorization, Sending the IP address of the P-GW1 that can provide the PDN connection service and the subscription information of all the subscription APNs of the user corresponding to the APN sent by the user to the Non 3GPP Access, Step 502, Non 3GPP Access initiates the proxy binding to update Establishing a tunnel connection with the P-GW1, the message bound by the proxy includes the identity of the user and the APN sent by the user, and the P-GW1 assigns an IP address or an address prefix to the UE, and in the proxy binding confirmation message. The IP address or address prefix assigned by the P-GW1 to the UE is notified to the Non 3 GPP Access, and in step 503, the Non 3GPP Access notifies the UE of the above address or address prefix. The UE connects to the P-GW1 through Non 3 GPP Access to establish a connection to the IP service provided by the HPLMN. 6 is a connection mode of the Non 3GPP Access adopting S2b when the subscription information of the user indicates that the user can provide the service monthly service by the VPLMN and the VLPMN and the Non 3 GPP Access are not trusted, the 3GPP AAA Proxy in the VPLMN determines the connection mode of the Non 3GPP Access by using the S2b. The flow chart, as shown in FIG. 6, includes the following steps (step 601 - step 602). Step 601: The UE accesses the Non 3GPP Access, and sends the information such as the user identity to the Non 3 GPP Access. The Non 3GPP Access sends the information of the user to the AAA Proxy and the HSS/AAA. The network element (Non 3GPP Access, AAA Proxy) And HSS/AAA) authenticate the user and 4 are authorized. In the process of authentication and 4 authorization, the AAA Proxy is sent from the HSS/AAA Server.
10 P23432 用户签约信息, 如果才艮据该用户签约信息决定该业务可以由 VPLMN提供, 并且 VPLMN与 Non 3GPP Access之间是不信任的, 贝l AAA Proxy决定该 Non 3 GPP Access采用 S2b的连接方式接入,并在认证与 4受权过程中通过 Non 3 GPP Access通知 UE。 步 « 602、 和上述步 « 402、 403、 404 目同, UE连接到 ePDG, 并通过10 P23432 User subscription information, if it is determined according to the user subscription information that the service can be provided by the VPLMN, and the VPLMN and the Non 3GPP Access are not trusted, the AAA Proxy determines that the Non 3 GPP Access uses the S2b connection mode to access. And notify the UE through Non 3 GPP Access in the authentication and 4 authorization process. Step « 602, and the above steps « 402, 403, 404 are the same, the UE is connected to the ePDG and passes
P-GW接入运营商提供的 IP业务, 其中, P-GW可以是 HPLMN的 P-GW1 或者 VPLMN的 P-GW2 , 具体由 AAA Server, AAA Proxy和 /或 ePDG才艮据 UE发来的 APN信息以及保存在 HSS中的用户签约信息(该信息表明该用户 可以由 VPLMN提供业务服务) 决定。 根据本发明实施例, 还提供了一种网络连接方式的确定方法, 应用于用 户设备 UE漫游接入到非 3GPP接入网,非 3GPP接入网将 UE的用户信息发 送给认证 4受权计费 AAA系统, 非 3GPP接入网、 AAA系统对 UE进行认证 与授权,该方法具体包括: AAA系统根据预定信息确定采用的网络连接方式, 其中, 预定信息包括: 归属公共陆地移动网络与非 3GPP接入网的信任关系 的信任关系信息、 用户签约信息、 拜访公共陆地移动网络与非 3GPP接入网 的信任关系信息、 拜访公共陆地移动网络是否有演进的分组数据网关、 拜访 公共陆地移动网络能否提供服务信息。 上述 AAA 系统包括认证 4受权计费代理 AAA Proxy和归属用户月 务器 HSS/认证授权计费服务器 AAA Server, 因此, 上述 AAA系统根据预定信息 确定采用的网络连接方式包括: 步骤一, AAA Server确定归属公共陆地移动 网络与非 3GPP接入网为信任关系,将表示归属公共陆地移动网络与非 3GPP 接入网的信任关系的信任关系信息以及用户签约信息发送给 AAA Proxy; 步 骤二, AAA Proxy根据预定信息确定采用的网络连接方式。 综上所述,通过本发明实施例,使得用户漫游时可以确定通过 Non 3 GPP Access接入 EPC网络的连接方式, 解决了现有技术中的问题。 显然, 本领域的技术人员应该明白, 上述的本发明的各模块或各步骤可 以用通用的计算装置来实现, 它们可以集中在单个的计算装置上, 或者分布 在多个计算装置所组成的网络上, 可选地, 它们可以用计算装置可执行的程 序代码来实现, 从而, 可以将它们存储在存储装置中由计算装置来执行, 或 者将它们分别制作成各个集成电路模块, 或者将它们中的多个模块或步骤制 作成单个集成电路模块来实现。 这样, 本发明不限制于任何特定的硬件和软 The P-GW accesses the IP service provided by the UE, where the P-GW can be the P-GW1 of the HPLMN or the P-GW2 of the VPLMN. The AAA server, the AAA Proxy, and/or the ePDG are only based on the APN sent by the UE. The information and the user subscription information stored in the HSS (which indicates that the user can be provided by VPLMN) is determined. According to an embodiment of the present invention, a method for determining a network connection manner is further provided, where the user equipment UE roams to a non-3GPP access network, and the non-3GPP access network sends the user information of the UE to the authentication 4 authorized charging. The AAA system, the non-3GPP access network, and the AAA system perform authentication and authorization on the UE. The method specifically includes: determining, by the AAA system, the adopted network connection manner according to the predetermined information, where the predetermined information includes: the home public land mobile network and the non-3GPP interface Trust relationship information of the trust relationship entering the network, user subscription information, access to the trust relationship information of the public land mobile network and the non-3GPP access network, whether the public land mobile network accesses the evolved packet data gateway, and whether the public land mobile network is visited Provide service information. The AAA system includes an authentication 4 authorized charging proxy AAA Proxy and a home subscriber server HSS/authentication authorization accounting server AAA Server. Therefore, the AAA system determines, according to the predetermined information, the adopted network connection manner, including: Step one, the AAA Server determines The belonging public land mobile network and the non-3GPP access network are in a trust relationship, and the trust relationship information and the user subscription information indicating the trust relationship between the public land mobile network and the non-3GPP access network are sent to the AAA Proxy; Step 2, the AAA Proxy is based on The predetermined information determines the network connection method used. In summary, the embodiments of the present invention enable the user to determine the connection mode of accessing the EPC network through Non 3 GPP Access when roaming, which solves the problems in the prior art. Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general-purpose computing device, which can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device, such that they may be stored in the storage device by the computing device, or they may be separately fabricated into individual integrated circuit modules, or they may be Multiple modules or steps are made into a single integrated circuit module. Thus, the invention is not limited to any particular hardware and software.
11 P23432 件结合。 以上所述仅为本发明的优选实施例而已, 并不用于限制本发明, 对于本 领域的技术人员来说, 本发明可以有各种更改和变化。 凡在本发明的精神和 原则之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明的保护 范围之内。 11 P23432 Piece combination. The above is only the preferred embodiment of the present invention, and is not intended to limit the present invention, and various modifications and changes can be made to the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and scope of the present invention are intended to be included within the scope of the present invention.
12 P23432 12 P23432

Claims

权 利 要 求 书 Claim
1. 一种网络连接方式的确定方法,用户设备 UE漫游接入非 3GPP接入网, 非 3 GPP接入网将 UE的用户信息发送给认证 4受权计费代理 AAA Proxy 和归属用户服务器 HSS/认证 4受权计费服务器 AAA Server, 非 3 GPP接 入网、 AAA Proxy和 HSS/AAA对所述 UE进行认证与 4受权, 其特征在 于, 所述方法包括: 步骤一, AAA Server确定归属公共陆地移动网络与非 3GPP接入 网为信任关系, 将表示归属公共陆地移动网络与非 3GPP接入网的信 任关系的信任关系信息以及用户签约信息发送给 AAA Proxy; 步骤二, AAA Proxy根据预定信息确定采用的网络连接方式, 其 中, 所述预定信息包括: 所述信任关系信息、 用户签约信息、 拜访公 共陆地移动网络与非 3GPP接入网的信任关系信息、 拜访公共陆地移 动网络是否有演进的分组数据网关、 拜访公共陆地移动网络能否提供 服务信息。 A method for determining a network connection manner, a user equipment UE roaming access to a non-3GPP access network, and a non-3GPP access network transmitting user information of the UE to an authentication 4 authorized charging proxy AAA Proxy and a home subscriber server HSS/ The authentication 4 authorized accounting server AAA Server, the non-3GPP access network, the AAA Proxy, and the HSS/AAA perform authentication and authorization on the UE, and the method includes the following steps: Step 1: The AAA server determines the attribution to the public land. The mobile network and the non-3GPP access network are in a trust relationship, and the trust relationship information and the user subscription information indicating the trust relationship between the public land mobile network and the non-3GPP access network are sent to the AAA Proxy. Step 2: The AAA Proxy determines according to the predetermined information. The network connection mode, where the predetermined information includes: the trust relationship information, the user subscription information, the trust relationship information of the public land mobile network and the non-3GPP access network, and whether the public land mobile network visits the evolved group Data gateways, visits to public land mobile networks can provide service information.
2. 根据权利要求 1 所述的方法, 其特征在于, 在所述步骤二之后, 所述 方法还包括: : 步骤三, AAA Proxy将确定的网络连接方式发送给非 3GPP接入 网; The method according to claim 1, wherein after the step 2, the method further includes: Step 3: The AAA Proxy sends the determined network connection manner to the non-3GPP access network;
步骤四, 若所述确定的网络连接方式为需要连接到演进的分组数 据网关,则非 3GPP接入网通知 UE建立 UE与演进的分组数据网关的 连接。  Step 4: If the determined network connection mode is that it needs to connect to the evolved packet data gateway, the non-3GPP access network notifies the UE to establish a connection between the UE and the evolved packet data gateway.
3. 根据权利要求 1 所述的方法, 其特征在于, 在所述步骤一中, 归属公 共陆地移动网络与非 3GPP接入网信任关系信息以及用户签约信息为 以下任一种: 情况一: 用户签约信息为全部业务由归属公共陆地移动网络提供 的指示, 归属公共陆地移动网络与非 3GPP接入网为信任关系; 情况二: 用户签约信息为全部业务由归属公共陆地移动网络提供 的指示, 归属公共陆地移动网络与非 3GPP接入网为不信任关系; The method according to claim 1, wherein in the step 1, the trust relationship information and the user subscription information of the home public land mobile network and the non-3GPP access network are any of the following: Case 1: User The subscription information is an indication that all services are provided by the public land mobile network, and the public land mobile network and the non-3GPP access network are trusted; Case 2: the user subscription information is an indication that all services are provided by the public land mobile network, belonging The public land mobile network and the non-3GPP access network are untrusted;
13 P23432 情况三: 用户签约信息为业务可由拜访公共陆地移动网络提供的 指示, 归属公共陆地移动网络与非 3GPP接入网为不信任关系。 13 P23432 Case 3: The user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the belonging public land mobile network and the non-3GPP access network are not trusted.
4. 才艮据权利要求 3所述的方法, 其特征在于, AAA Server向 AAA Proxy 发送允许拜访公共陆地移动网络提供业务的信息, AAA Proxy根据拜 访公共陆地移动网络中的配置, 决定是否向所述 UE提供拜访公共陆 地移动网络服务, 若不提供任何拜访公共陆地移动网络服务, 则认为 必须由归属公共陆地移动网络提供服务。 4. The method according to claim 3, wherein the AAA Server sends information to the AAA Proxy to allow the public land mobile network to provide services, and the AAA Proxy determines whether to go to the public land mobile network according to the configuration in the visited public land mobile network. The UE provides access to the public land mobile network service, and if it does not provide any access to the public land mobile network service, it is considered that the service must be provided by the home public land mobile network.
5. 根据权利要求 3或 4所述的方法, 其特征在于, 对于所述情况一, 所 述 UE不需要通过演进的分组数据网关连接网络。 The method according to claim 3 or 4, wherein, for the first case, the UE does not need to connect to the network through the evolved packet data gateway.
6. 根据权利要求 5所述的方法, 其特征在于, 对于所述情况二, 若拜访 公共陆地移动网络中没有演进的分组数据网关, 则 AAA Proxy认为该 用户网络连接不需要演进的分组数据网关; The method according to claim 5, wherein, in the second case, if there is no evolved packet data gateway in the public land mobile network, the AAA Proxy considers that the user network connection does not require an evolved packet data gateway. ;
7. 根据权利要求 5所述的方法, 其特征在于, 对于所述情况二, 若拜访 公共陆地移动网络中有演进的分组数据网关, 则 AAA Proxy决定所述 UE的网络连接需要经过演进的分组数据网关。 The method according to claim 5, wherein, in case 2, if there is an evolved packet data gateway in the public land mobile network, the AAA Proxy determines that the network connection of the UE needs an evolved packet. Data gateway.
8. 根据权利要求 3所述的方法, 其特征在于, 用户签约信息为业务可由 拜访公共陆地移动网络提供的指示, AAA Proxy 居拜访公共陆地移 动网络中的配置决定由拜访公共陆地移动网络向所述 UE提供全部业 务服务, 若拜访公共陆地移动网络与非 3GPP接入网为可信任关系, 贝l AAA Proxy决定所述 UE的网络连接不需要连接演进的分组数据网 关。 8. The method according to claim 3, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the configuration decision of the AAA Proxy to visit the public land mobile network is determined by visiting the public land mobile network. The UE provides all service services. If the public land mobile network and the non-3GPP access network are trusted, the AAA Proxy determines that the network connection of the UE does not need to connect to the evolved packet data gateway.
9. 才艮据权利要求 8所述的方法, 其特征在于, 用户签约信息为业务可由 拜访公共陆地移动网络提供的指示, AAA Proxy 居拜访公共陆地移 动网络中的配置决定由拜访公共陆地移动网络向所述 UE提供全部业 务服务, 若拜访公共陆地移动网络与非 3GPP接入网为不信任关系, 则 AAA Proxy决定所述 UE的网络连接需要连接演进的分组数据网关。 9. The method according to claim 8, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the configuration decision of the AAA Proxy in the public land mobile network is visited by the public land mobile network. Providing all the service services to the UE. If the public land mobile network and the non-3GPP access network are in an untrusted relationship, the AAA Proxy determines that the network connection of the UE needs to connect to the evolved packet data gateway.
10. 才艮据权利要求 8所述的方法, 其特征在于, 用户签约信息为业务可由 拜访公共陆地移动网络提供的指示, AAA Proxy 居拜访公共陆地移 动网络中的配置决定由拜访公共陆地移动网络向所述 UE提供部分业 务服务,拜访公共陆地移动网络与非 3GPP接入网为信任关系,若 AAA 10. The method according to claim 8, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the configuration decision of the AAA Proxy in the public land mobile network is visited by the public land mobile network. Providing a partial service service to the UE, and accessing the public land mobile network and the non-3GPP access network as a trust relationship, if AAA
14 P23432 Server向 AAA Proxy发送表明归属公共陆地移动网络与该非 3GPP接 入网为信任关系的信息, 则 AAA Proxy决定所述 UE的网络连接不需 要连接演进的分组数据网关。 14 P23432 The server sends information indicating that the home public land mobile network and the non-3GPP access network have a trust relationship to the AAA Proxy, and the AAA Proxy determines that the network connection of the UE does not need to connect to the evolved packet data gateway.
11. 才艮据权利要求 8所述的方法, 其特征在于, 用户签约信息为业务可由 拜访公共陆地移动网络提供的指示, AAA Proxy 居拜访公共陆地移 动网络中的配置决定由拜访公共陆地移动网络向所述 UE提供部分业 务服务, 拜访公共陆地移动网络与该非 3GPP接入网为信任关系, 若 归属公共陆地移动网络与该非 3GPP接入网为不信任关系, 且拜访公 共陆地移动网络中没有演进的分组数据网关, 则 AAA Proxy决定所述 UE的网络连接不需要连接演进的分组数据网关。 11. The method according to claim 8, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the configuration decision of the AAA Proxy in the public land mobile network is visited by the public land mobile network. Providing a partial service service to the UE, accessing the public land mobile network and the non-3GPP access network as a trust relationship, if the home public land mobile network and the non-3GPP access network are in an untrusted relationship, and visiting the public land mobile network Without an evolved packet data gateway, the AAA Proxy determines that the UE's network connection does not require connection to an evolved packet data gateway.
12. 才艮据权利要求 11所述的方法, 其特征在于, 用户签约信息为业务可由 拜访公共陆地移动网络提供的指示, AAA Proxy 居拜访公共陆地移 动网络中的配置决定由拜访公共陆地移动网络向所述 UE提供部分业 务服务, 拜访公共陆地移动网络与该非 3GPP接入网为信任关系, 当 归属公共陆地移动网络与该非 3GPP接入网为不信任关系, 如果拜访 公共陆地移动网络中有演进的分组数据网关, 则 AAA Proxy决定所述 UE的网络连接需要连接演进的分组数据网关。 12. The method according to claim 11, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the configuration decision of the AAA Proxy in the public land mobile network is visited by the public land mobile network. Providing a partial service service to the UE, accessing the public land mobile network and the non-3GPP access network as a trust relationship, when the home public land mobile network and the non-3GPP access network are in a distrust relationship, if visiting the public land mobile network With an evolved packet data gateway, the AAA Proxy determines that the network connection of the UE needs to connect to the evolved packet data gateway.
13. 根据权利要求 11所述的方法, 其特征在于, 用户签约信息为业务可由 拜访公共陆地移动网络提供的指示, AAA Proxy 居拜访公共陆地移 动网络中的配置决定由拜访公共陆地移动网络向所述 UE提供部分业 务服务, 如果拜访公共陆地移动网络与该非 3GPP接入网为不信任关 系, 则 AAA Proxy决定所述 UE的网络连接需要连接演进的分组数据 网关。 13. The method according to claim 11, wherein the user subscription information is an indication that the service can be provided by visiting the public land mobile network, and the configuration decision of the AAA Proxy to visit the public land mobile network is determined by visiting the public land mobile network. The UE provides a part of the service service. If the visited public land mobile network and the non-3GPP access network are in an untrusted relationship, the AAA Proxy determines that the network connection of the UE needs to connect to the evolved packet data gateway.
14. 一种网络连接方式的确定方法,用户设备 UE漫游接入非 3GPP接入网, 所述非 3GPP接入网将 UE的用户信息发送给认证授权计费 AAA系统, 所述非 3GPP接入网、 所述 AAA系统对所述 UE进行认证与 4受权, 其 特征在于, 所述方法包括: 所述 AAA系统根据预定信息确定采用的网络连接方式, 其中, 所述预定信息包括: 归属公共陆地移动网络与非 3GPP接入网的信任 关系的信任关系信息、 用户签约信息、 拜访公共陆地移动网络与非 3GPP接入网的信任关系信息、拜访公共陆地移动网络是否有演进的分 A method for determining a network connection mode, the user equipment UE roaming accesses a non-3GPP access network, and the non-3GPP access network sends the user information of the UE to the authentication and authorization charging AAA system, where the non-3GPP access The network, the AAA system performs authentication and authorization on the UE, and the method includes: the AAA system determines, according to the predetermined information, a network connection mode to be adopted, where the predetermined information includes: Trust relationship information of the trust relationship between the mobile network and the non-3GPP access network, user subscription information, access to the trust relationship information of the public land mobile network and the non-3GPP access network, and whether the public land mobile network has an evolutionary point
15 P23432 组数据网关、 拜访公共陆地移动网络能否提供服务信息。 根据权利要求 14所述的方法, 所述 AAA系统包括认证授权计费代理 AAA Proxy和归属用户月^务器 HSS/认证 4受权计费月 务器 AAA Server, 其特征在于,所述 AAA系统才艮据预定信息确定采用的网络连接方式包 括: 步骤一, 所述 AAA Server确定所述归属公共陆地移动网络与所 述非 3GPP接入网为信任关系, 将表示所述归属公共陆地移动网络与 所述非 3GPP接入网的信任关系的信任关系信息以及所述用户签约信 息发送给所述 AAA Proxy; 步骤二,所述 AAA Proxy根据所述预定信息确定采用的网络连接 方式。 15 P23432 Group data gateways, visits to public land mobile networks can provide service information. The method according to claim 14, wherein the AAA system comprises an authentication and authorization charging proxy AAA Proxy and a home subscriber server HSS/authentication 4 authorized charging server AAA Server, wherein the AAA system is Determining the adopted network connection manner according to the predetermined information includes: Step 1: The AAA Server determines that the home public land mobile network and the non-3GPP access network are in a trust relationship, and represents the home public land mobile network and the The trust relationship information of the trust relationship of the non-3GPP access network and the user subscription information are sent to the AAA Proxy. Step 2: The AAA Proxy determines the adopted network connection manner according to the predetermined information.
16 P23432 16 P23432
PCT/CN2008/073555 2008-05-04 2008-12-17 Network connection mode determining method WO2009135371A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2008100964158A CN101472263B (en) 2008-05-04 2008-05-04 Method for deciding network connection mode
CN200810096415.8 2008-05-04

Publications (1)

Publication Number Publication Date
WO2009135371A1 true WO2009135371A1 (en) 2009-11-12

Family

ID=40829315

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2008/073555 WO2009135371A1 (en) 2008-05-04 2008-12-17 Network connection mode determining method

Country Status (2)

Country Link
CN (1) CN101472263B (en)
WO (1) WO2009135371A1 (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011127774A1 (en) * 2010-04-15 2011-10-20 中兴通讯股份有限公司 Method and apparatus for controlling mode for user terminal to access internet
EP2276281A4 (en) * 2008-05-05 2017-07-12 China Academy of Telecommunications Technology Method, system and device for obtaining a trust type of a non-3gpp access system

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101815296A (en) * 2009-02-23 2010-08-25 华为技术有限公司 Method, device and system for performing access authentication
CN102045690A (en) * 2009-10-09 2011-05-04 中兴通讯股份有限公司 Method for obtaining signing information of internet of things equipment and server in internet of things
JP5851034B2 (en) * 2011-08-10 2016-02-03 テレフオンアクチーボラゲット エル エム エリクソン(パブル) HSS failure recovery in non-3GPP access
CN103024738A (en) * 2011-09-26 2013-04-03 中兴通讯股份有限公司 Seaming service shunt control implementation method and system
CN103200628B (en) 2012-01-09 2018-05-15 中兴通讯股份有限公司 A kind of method and system by non-3 GPP access core net
CN107371157A (en) * 2016-05-13 2017-11-21 北京旅信顺捷软件科技有限公司 Operator ePDG gateway accessings system and the method for realizing mobile communication
CN108282775B (en) * 2017-12-22 2021-01-01 中国科学院信息工程研究所 Dynamic additional authentication method and system for mobile private network
CN110602765B (en) * 2019-10-11 2021-10-01 中国联合网络通信集团有限公司 Network selection method and device

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1984021A (en) * 2006-06-02 2007-06-20 华为技术有限公司 System and method for accessing 3GPP deductive network by non-3GPP technology
CN101141822A (en) * 2007-09-30 2008-03-12 中兴通讯股份有限公司 Gateway selecting method of wireless network

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1984021A (en) * 2006-06-02 2007-06-20 华为技术有限公司 System and method for accessing 3GPP deductive network by non-3GPP technology
CN101141822A (en) * 2007-09-30 2008-03-12 中兴通讯股份有限公司 Gateway selecting method of wireless network

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2276281A4 (en) * 2008-05-05 2017-07-12 China Academy of Telecommunications Technology Method, system and device for obtaining a trust type of a non-3gpp access system
WO2011127774A1 (en) * 2010-04-15 2011-10-20 中兴通讯股份有限公司 Method and apparatus for controlling mode for user terminal to access internet

Also Published As

Publication number Publication date
CN101472263B (en) 2011-12-28
CN101472263A (en) 2009-07-01

Similar Documents

Publication Publication Date Title
WO2009135371A1 (en) Network connection mode determining method
US8276189B2 (en) Method, system and apparatus for indirect access by communication device
EP1693988B1 (en) A method of the subscriber terminal selecting the packet data gateway in the wireless local network
CN101141822B (en) Gateway selecting method of wireless network
EP1693995B1 (en) A method for implementing access authentication of wlan user
EP2858418B1 (en) Method for updating identity information about packet gateway, aaa server and packet gateway
JP5008395B2 (en) Flexible WLAN access point architecture that can accommodate different user equipment
JP2020506588A (en) Interworking function using unreliable network
EP3154306B1 (en) Establishment of network connection
WO2009000124A1 (en) A method for selecting the gateway in the wireless network
WO2007019771A1 (en) An access control method of the user altering the visited network, the unit and the system thereof
WO2010012174A1 (en) Management method, device and system for user to access network
WO2013016968A1 (en) Access method,system and mobile intelligent access point
WO2005039110A1 (en) A method of analyzing the accessing process of the selected service in the wireless local area network
CN101106812B (en) Access method for communication network and user device
EP2774402A1 (en) Securing data communications in a communications network
US20130094487A1 (en) Method and System for Information Transmission
WO2009152676A1 (en) Aaa server, p-gw, pcrf, method and system for obtaining the ue's id
WO2010108352A1 (en) Method for sending access network policies and home access network discovery and support functions unit
WO2010086029A1 (en) Method and radio communication system for establishing an access to a mobile network domain
WO2014048197A1 (en) Method, system and device for user equipment to select visited public land mobile network
WO2008099254A2 (en) Authorizing n0n-3gpp ip access during tunnel establishment
CN101472262A (en) Method for implementing access network
WO2013107243A1 (en) Session establishing method and device
CN101472261B (en) Method for customer equipment to access business network

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 08874165

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 08874165

Country of ref document: EP

Kind code of ref document: A1