WO2009143745A1 - Method, mobility management network element and mobile communication system for providing security context, - Google Patents

Method, mobility management network element and mobile communication system for providing security context, Download PDF

Info

Publication number
WO2009143745A1
WO2009143745A1 PCT/CN2009/071822 CN2009071822W WO2009143745A1 WO 2009143745 A1 WO2009143745 A1 WO 2009143745A1 CN 2009071822 W CN2009071822 W CN 2009071822W WO 2009143745 A1 WO2009143745 A1 WO 2009143745A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobility management
network element
management network
target
security context
Prior art date
Application number
PCT/CN2009/071822
Other languages
French (fr)
Chinese (zh)
Inventor
胡伟华
张艳平
吴问付
周汉
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2009143745A1 publication Critical patent/WO2009143745A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W36/00Hand-off or reselection arrangements
    • H04W36/0005Control or signalling for completing the hand-off
    • H04W36/0011Control or signalling for completing the hand-off for data sessions of end-to-end connection
    • H04W36/0033Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information
    • H04W36/0038Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information of security context information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/35Protecting application or service provisioning, e.g. securing SIM application provisioning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/08Mobility data transfer
    • H04W8/12Mobility data transfer between location registers or mobility servers

Definitions

  • the present invention relates to the field of communications, and in particular, to a method for providing a security context, a mobility management network element, and a mobile communication system.
  • the core network of the wireless evolution network mainly includes three logical functions: a mobility management unit (MME), a serving gateway (SG), and a packet data network gateway (PDN Gateway).
  • MME mobility management unit
  • SG serving gateway
  • PDN Gateway packet data network gateway
  • the Serving GPRS Support Node (SGSN) is a core network device in a Universal Mobile Telecommunications System (UMTS) and a General Packet Radio Service (GPRS) system.
  • UMTS Universal Mobile Telecommunications System
  • GPRS General Packet Radio Service
  • the user equipment When the user equipment (UE, User Equipment) is in the Global System For Mobile Communication (GSM) or the EDGE (Enhanced Data for GSM Evolution) radio access network (GERAN, GSM/EDGE Radio Access Network) / Universal Mobile Telecommunications System (UTRAN, UMTS Territorial Radio Access Network) network and Evolved Universal Mobile Telecommunications System (E-UTRAN, Evolved UMTS Territorial Radio Access Network)
  • GSM Global System For Mobile Communication
  • EDGERAN Enhanced Data for GSM Evolution radio access network
  • UTRAN Universal Mobile Telecommunications System
  • E-UTRAN Evolved Universal Mobile Telecommunications System
  • the UE initiates a tracking area update process or a routing area update process to register to the target network.
  • the SGSN and the MME are independent functional entities, wherein the MME can support access of the E-UTRAN wireless access system.
  • the UE when the UE is attached to the GERAN/UTRAN network or the E-UTRAN network, the UE first performs an attach procedure:
  • the source-side mobility management network element is found according to the temporary identifier of the user sent by the target-side mobility management network element.
  • the user's International Mobile Subscriber Identity (IMSI), and the security context and the IMSI are returned to the target-side mobility management network element together with the identity response message.
  • IMSI International Mobile Subscriber Identity
  • the UE When the UE moves from the GERAN/UTRAN network to the E-UTRAN network, the UE sends a message to the MME.
  • the tracking area update request message initiates a tracking area update process: when receiving the tracking area update request message sent by the UE, the target side MME sends a context request message request context information to the source side SGSN, and receives the context carrying the context information returned by the source side SGSN. In response to the message, a Tracking Area Update Accept message is returned to the UE.
  • the UE when the UE moves from the E-UTRAN network to the GERAN/UTRAN network, the UE initiates a routing area update procedure by sending a Routing Area Update Request message to the SGSN.
  • the two functions can be implemented in one physical entity, and the physical entity is a unified device, which has the functions of the SGSN and the MME.
  • the unified device obtains the security context of the UE on the GERAN/UTRAN network and the E-UTRAN network from the HSS.
  • the tracking area update process or the routing area update process needs to be initiated.
  • the target-side mobility management network element needs to obtain the context information of the UE from the unified device on the source side.
  • the source-side mobility management network element Since the source-side mobility management network element simultaneously stores the security contexts in the GERAN/UTRAN network and the E-UTRAN network, the source-side mobility management network element cannot provide a suitable security context when the target-side mobility management network element acquires the context.
  • the target-side mobility management network element does not have a security context or does not have a suitable security context, the target-side mobility management network element needs to interact with the HSS to obtain a security context, which increases the interaction load with the HSS.
  • the source-side mobility management network element cannot provide a suitable security context for the target-side mobility management network element
  • the embodiment of the present invention provides a method for providing a security context, a mobility management network element, and a mobile communication system.
  • the source side mobility management network element to provide a suitable security context to the target side mobility management network element.
  • a method of providing a security context comprising:
  • a mobility management network element includes:
  • a first receiving module configured to receive a request message that is sent by the target side mobility management network element and carries the indication information
  • the first sending module (43) is configured to send, to the target side mobility management network element, a security context of the user equipment corresponding to the indication information.
  • a mobility management network element includes: a second sending module (51), configured to send a request message carrying the indication information to the source-side mobility management network element, where the second receiving module (53) is configured to receive the source-side mobility management network element Corresponding to the security context of the user equipment of the indication information.
  • a mobile communication system comprising: a source side mobility management network element (61) and a target side mobility management network element (63);
  • the source-side mobility management network element (61) is configured to receive a request message that is sent by the target-side mobility management network element (63) and that carries the indication information, to the target-side mobility management network element ( 63) transmitting a security context of the user equipment corresponding to the indication information;
  • the target-side mobility management network element (63) is configured to send a request message carrying the indication information to the source-side mobility management network element (61), and receive the source-side mobility management network element (61) a security context sent by the user equipment corresponding to the indication information.
  • the request message sent by the target-side mobility management network element to the source-side mobility management network element carries the indication information, so that the source-side mobility management network element can follow the indication information in the request message. Transmitting the corresponding security context to the target-side mobility management network element, thereby avoiding the process of the target-side mobility management network element interacting with the home network server (HSS, Home Subscriber Server) to obtain the security context, and reducing the interaction with the HSS load.
  • HSS Home Subscriber Server
  • FIG. 1 is a schematic structural diagram of a wireless evolved network in a non-roaming scenario
  • FIG. 2 is a flowchart of a method for providing a security context according to Embodiment 1 of the present invention
  • FIG. 3 is a flowchart of a method for providing a security context according to Embodiment 2 of the present invention.
  • FIG. 4 is a schematic structural diagram of a mobility management network element according to Embodiment 3 of the present invention.
  • FIG. 5 is a schematic structural diagram of a mobility management network element according to Embodiment 4 of the present invention.
  • FIG. 6 is a schematic structural diagram of a mobile communication system according to Embodiment 5 of the present invention. detailed description
  • FIG. 1 is a schematic diagram of an architecture of a wireless evolved network in a non-roaming scenario.
  • the MME has the functions of network-attached storage (NAS, Network-Attached Storage) and NAS signaling encryption, roaming, tracking, etc., and assigns user temporary identity, security function, etc., which corresponds to the control plane part of the current UMTS internal SGSN.
  • Serving The Gateway is responsible for local mobility anchors and mobility anchors within the 3GPP system as well as lawful interception related information.
  • the PDN Gateway is responsible for policy enforcement and billing as well as lawful interception related functions.
  • the HSS is used to store user subscription information.
  • the Policy and Charging Rules Function (PCRF) is responsible for formulating control and accounting policies.
  • the SGSN supports access to GERAN and UTRAN systems and is responsible for mobility management and forwarding of user data.
  • PCRF Policy and Charging Rules Function
  • the source side mobility management network when the UE initiates the routing area update process or the tracking area update process, the source side mobility management network is in the context transfer process between the source side mobility management network element and the target side mobility management network element.
  • the element transmits the security context of the appropriate UE according to the target side mobility management network element device type or according to the type of required security context indicated by the target side mobility management network element.
  • the security context described in the embodiment of the present invention may be a security parameter, and may be a security parameter such as an authentication vector or a security key.
  • the target-side mobility management network element acquires the IMSI and the security context from the source-side mobility management network element, and the source-side mobility management network element manages the network element device type according to the target-side mobility or according to the target.
  • Embodiment 1 illustrates a method for providing a security context by using a UE to initiate a routing area update process or a tracking area update process.
  • routing area update or the tracking area update in the first embodiment is collectively referred to as location area update.
  • the UE first attaches to the source-side mobility management network element, and the source-side mobility management network element simultaneously stores the security contexts in the GERAN/UTRAN network and the E-UTRAN network.
  • the target side mobility management network element may be in the context request message during the context transfer process between the source side mobility management network element and the target side mobility management network element.
  • the device carries a message indicating the type of the device, for example, a supported radio access type (Supported RAT, Supported Radio Access Type), and informs the source-side mobility management network element of the device type, so that the source-side mobility management network element is based on the target side.
  • a supported radio access type Service RAT, Supported Radio Access Type
  • the mobility management network element device type delivers the security context of the corresponding UE; or the target side mobility management network element carries the source side by other means, for example, carrying a message indicating the type of the security context to be acquired in the context request message.
  • the mobility management network element delivers the security context of the appropriate UE according to the target side mobility management network element device type.
  • the method for providing a security context provided by this embodiment is described in detail below with reference to FIG. 2, the method mainly includes the following steps:
  • Step 101 Send a location area update request message to the target side mobility management network element after the UE moves to the target side network.
  • the UE-side mobility management network element functional entity is the MME.
  • the target side mobility management network element functional entity is the SGSN. It can be understood that the target-side mobility management network element may be a SGSN and MME-integrated device regardless of the network.
  • the location area update is an overview of the routing area update and the tracking area update;
  • the location area update request message includes: a tracking area update request message and a routing area update request message.
  • the UE moves to the E-UTRAN network, the UE initiates a tracking area update procedure, and the UE sends a tracking area update request message to the target side mobility management network element; when the UE moves to the GERAN/UTRAN network, the UE initiates the routing area.
  • the UE sends a routing area update request message to the target side mobility management network element.
  • Step 102 The target-side mobility management network element sends a context request message to the source-side mobility management network element, and adds information indicating the target-side mobility management network element device type to the message.
  • the target-side mobility management network element requests the source-side mobility management network element to acquire the context information of the UE, including the security context of the UE, by sending the foregoing context request message.
  • the Supported RAT value is 0;
  • the target-side mobility management network element is a separate functional entity of the SGSN, the Supported RAT value is 1;
  • the supported RAT value is 2.
  • the value of the Supported RAT can be set by software.
  • Step 103 The source-side mobility management network element returns a context response message to the target-side mobility management network element, and returns the context information of the UE by using the message, including the security context of the UE.
  • the return context response message corresponding to the three situations in step 102 specifically includes the following situations: 1) When the supported RAT value is 0, the security context returned by the source side mobility management network element in the context response message is The security context of the UE in the E-UTRAN network;
  • the security context that the source-side mobility management network element needs to return in the context response message is the security context of the UE in the GERAN/UTRAN network;
  • the security context that the source-side mobility management network element needs to return in the context response message is the security context of the UE in the E-UTRAN network and the GERAN/UTRAN network.
  • Step 104 The target side mobility management network element sends a context confirmation message to the source side mobility management network element.
  • Step 105 The target side mobility management network element returns a location area update accept message to the UE.
  • a security indication that needs to be acquired may also be added to the context request message.
  • Information about the type of the text such as the Authentication Type. E.g:
  • the Authentication Type value is 0;
  • the Authentication Type value is 1;
  • the Authentication Type value is 2.
  • the returning the context response message specifically includes the following cases:
  • the security context returned by the source-side mobility management network element in the context response message is the security context of the UE in the E-UTRAN network;
  • the security context returned by the source-side mobility management network element in the context response message is the security context of the UE in the GERAN/UTRAN network;
  • the security context that the source-side mobility management network element needs to return in the context response message is the security context of the UE in the E-UTRAN network and the GERAN/UTRAN network.
  • the embodiment of the present invention does not limit the form of the indication information, such as the information indicating the type of the target side mobility management network element device, and may further extend the cell to carry the target side mobility management network element device.
  • the type name for example, when the target-side mobility management network element is an SGSN, the cell can be set to "SGSN". When the target-side mobility management network element is an MME, the cell can be set to "MME". When the target-side mobility management network element is a unified device of the SGSN and the MME, the cell may be set to "combined SGSN/MME".
  • the source-side mobility management network element may be configured according to the indication information.
  • the indicated target-side mobility management network element device type sends its corresponding security context to the target-side mobility management network element in the context response message.
  • the source-side mobility management network element may be a unified device of the SGSN and the MME, so that when the UE is attached to the unified device for the first time, the unified device will use the UE in the GERAN/UTRAN network and the E-UTRAN network.
  • the security context of the source is obtained from the HSS.
  • the source-side mobility management network element may also be a separate SGSN or MME. Since the user is attached to a single device before being registered to a separate SGSN or MME, the unified device obtains The security context of the user in the E-UTRAN network and the GERAN/UTRAN network.
  • the individual SGSN or MME When a user initiates a routing area update or a tracking area update is registered to a separate SGSN or MME, the individual SGSN or MME requests the user from the starting unified device.
  • Security context at this time, the unified device will send all the security contexts of the user in the E-UTRAN network and the GERAN/UTRAN network to a separate SGSN or MME.
  • the SGSN or MME not only stores the user in the GERAN/UTRAN network.
  • the security context also preserves the security of the user on the E-UTRAN network. Text.
  • the source side mobility management network element When the single SGSN or the MME is again used as the source mobility management network element, since the source side mobility management network element also stores the security context of the GERAN/UTRAN network and the E-UTRAN network, it may also be based on the target side mobility.
  • the indication information in the request message sent by the management network element is sent to the target mobility management network element.
  • the source-side mobility management network element determines different device types of the target-side mobility management network element according to the indication information in the request message, or indicates the target-side mobility management network element according to the request message.
  • the type of the security context that needs to be obtained returns the security context corresponding to the appropriate UE, so that the interaction between the target-side mobility management network element and the HSS can be avoided to obtain the security context, and the interaction load with the HSS is reduced.
  • Embodiment 2 illustrates a method for providing a security context by taking a UE-initiated attach procedure as an example.
  • the UE first attaches to the source-side mobility management network element, and the source-side mobility management network element simultaneously stores the security contexts in the GERAN/UTRAN network and the E-UTRAN network.
  • the UE needs to perform an attach procedure, and sends an attach request message to the target-side mobility management network element, where the message carries the temporary identifier of the UE, and the target side
  • the mobility management network element needs to obtain the IMSI and the security context from the source-side mobility management network element, and the source-side mobility management network element needs to deliver different UE security contexts according to the target-side mobility management network element device type.
  • the method for providing a security context provided by this embodiment is described in detail below with reference to FIG. 3, the method mainly includes the following steps:
  • Step 201 When the UE performs the attach procedure, the UE sends an attach request message to the target mobility management network element.
  • the UE is attached to the source-side mobility management network element before being separated;
  • the attach request message includes the temporary identifier of the UE or the international mobile subscriber identity IMSI. If the UE only carries its temporary identity, the target-side mobility management network element needs to request the IMSI and the security context from the source-side mobility management network element.
  • the temporary identifier carried by the UE in the attach request message is a packet temporary mobile subscriber identity (P-TMSI, Packet Temporary Mobile Subscriber Identity) and a routing area identifier i (RAI, Routeing Area). Identity ).
  • P-TMSI Packet Temporary Mobile Subscriber Identity
  • RAI Routeing Area
  • the UE carried in the attach request message is a global unique temporary identity temporary identity (GUTI, Globally Unique Temporary Identity) 0
  • Step 202 The target-side mobility management network element sends an identifier request message to the source-side mobility management network element, and adds information indicating the target-side mobility management network element device type to the message.
  • the target-side mobility management network element requests the source-side mobility management network element to acquire the IMSI of the user and its security context by using the temporary identifier of the user in the identifier request message.
  • Step 203 The source-side mobility management network element returns an identifier response message to the target-side mobility management network element, where the message includes the IMSI of the user and the corresponding security context.
  • the security context returned by the source-side mobility management network element in the identity response message is the security context of the UE in the E-UTRAN network;
  • the security context returned by the source-side mobility management network element in the identity response message is the security context of the UE in the GERAN/UTRAN network;
  • the security context returned by the source-side mobility management network element in the identity response message is the security context of the UE in the E-UTRAN network and the GERAN/UTRAN network.
  • Step 204 The target side mobility management network element returns an attach accept message to the UE.
  • the information about the type of the security context to be acquired may be added to the identifier request message. Accordingly, the source-side mobility management network element needs to return in the identifier response message.
  • the security context is also divided into three cases, and the specific content is similar to that described in Embodiment 1, and details are not described herein again.
  • the embodiment of the present invention does not limit the form of the indication information, such as the information indicating the type of the target side mobility management network element device, and may further extend the cell to carry the target side.
  • the type name of the mobility management network element device for example, when the target-side mobility management network element is an SGSN, the cell may be set to "SGSN", and when the target-side mobility management network element is an MME, the cell It can be set to "MME".
  • the target-side mobility management network element is a unified device of the SGSN and the MME, the cell can be set to "Combined SGSN/MME".
  • the source-side mobility management is performed.
  • the network element may send its corresponding security context to the target side mobility management network element in the identity response message according to the target-side mobility management network element device type indicated by the indication information.
  • the source-side mobility management network element may be a unified device of the SGSN and the MME, so that when the UE is attached to the unified device for the first time, the unified device will use the UE in the GERAN/UTRAN network and the E-UTRAN network.
  • the security context of the source is obtained from the HSS.
  • the source-side mobility management network element may also be a separate SGSN or MME. Since the user is attached to a single device before attaching to the SGSN or MME, the unified device obtains The security context of the user in the E-UTRAN network and the GERAN/UTRAN network is attached to the user when the attach process is performed.
  • the separate SGSN or MME will request the user security context from the starting unifying device. At this time, the unified device will send all the security contexts of the user on the E-UTRAN network and the GERAN/UTRAN network.
  • the SGSN or MME not only stores the security context of the user in the GERAN/UTRAN network but also the security context of the user in the E-UTRAN network.
  • the single SGSN or MME is again used as the source mobility management network element, since the source side mobility management network element also stores the security context of the GERAN/UTRAN network and the E-UTRAN network, it may also be based on the target side mobility.
  • the indication information in the request message sent by the management network element is sent to the target mobility management network element.
  • the UE is first attached to the source-side mobility management network element.
  • the UE needs to perform an attach procedure, in the process, by using the identifier request message.
  • Different information is added to enable the source-side mobility management network element to return a security context corresponding to the appropriate UE according to the target-side mobility management network element device type, so that the interaction between the target-side mobility management network element and the HSS can be avoided to obtain security.
  • the context of the process reduces the interaction load with the HSS.
  • this embodiment provides a mobility management network element, where the mobility management network element includes:
  • the first receiving module 41 is configured to receive a request message that is sent by the target-side mobility management network element and that carries the indication information.
  • the first sending module 43 is configured to send, to the target side mobility management network element, a security context of the user equipment corresponding to the indication information.
  • the indication information in the request message includes information indicating a device type of the target side mobility management network element or information indicating a security context type of the user equipment that the target side mobility management network element needs to acquire.
  • the first sending module 43 includes:
  • a first sending unit configured to: when the device type indicating the target side mobility management network element in the indication information is the SGSN or the security context type of the user equipment that the target side mobility management network element needs to acquire, the security context in the GERAN/UTRAN network Sending a security context in the GERAN/UTRAN network to the target-side mobility management network element.
  • the second sending unit is configured to indicate, in the indication information, that the device type of the target-side mobility management network element is the MME or the target-side mobility management.
  • the security context type of the user equipment that the network element needs to acquire is the security context in the E-UTRAN network
  • the security context in the E-UTRAN network is sent to the target side mobility management network element;
  • a third sending unit configured to: when the device type indicating the target side mobility management network element is the MME and the SGSN, or the target side mobility management network element, the security context type of the user equipment to be acquired is E- Sending the security context of the UTRAN network and the GERAN/UTRAN network to the target-side mobility management network element Security context for E-UTRAN networks and GERAN/UTRAN networks.
  • the embodiment provides a mobility management network element, where the mobility management network element includes:
  • the second sending module 51 is configured to send, to the source-side mobility management network element, a request message that carries the indication information, where the request message may be a context request message or an identifier request message.
  • a request message that carries the indication information
  • the request message may be a context request message or an identifier request message.
  • the second receiving module 53 is configured to receive a security context of the user equipment corresponding to the indication information sent by the source side mobility management network element.
  • the second sending module 51 includes:
  • a first indication unit configured to add indication information indicating a device type of the target side mobility management network element to the request message, and send a request message carrying the indication information to the source side mobility management network element;
  • a second indication unit configured to add, in the request message, indication information indicating a security context type of the user equipment that the target side mobility management network element needs to acquire, and send the indication to the source side mobility management network element Request message for information.
  • the mobility management network element may be an SGSN device in the GERAN/UTRAN network or a unified device of the SGSN and the MME, or may be an MME device in the E-UTRAN network or a unified device of the SGSN and the MME.
  • the second sending module 51 adds the indication information to the request message to distinguish the different device types or the security context of the corresponding user equipment that needs to be obtained by the different devices.
  • the source-side mobility management network element determines, according to the indication information in the request message, different device types of the target-side mobility management network element or indicates in the request message according to the target-side mobility management network element.
  • the type of required security context provides a corresponding security context, thereby avoiding the process of the target-side mobility management network element interacting with the HSS to obtain a security context, and reducing the interaction load with the HSS.
  • this embodiment provides a mobile communication system, including: a source side mobility management network element 61 and a target side mobility management network element 63.
  • the source-side mobility management network element 61 is configured to receive the request message carrying the indication information sent by the target-side mobility management network element 63, and send the user equipment corresponding to the indication information to the target-side mobility management network element 63.
  • the target-side mobility management network element 63 is configured to send a request message carrying the indication information to the source-side mobility management network element 61, and receive the user corresponding to the indication information sent by the source-side mobility management network element 61.
  • the security context of the device is configured to send a request message carrying the indication information to the source-side mobility management network element 61, and receive the user corresponding to the indication information sent by the source-side mobility management network element 61.
  • the request message may be a context request message or an identifier request message, as described in the method embodiment. Bright.
  • the source side mobility management network element 61 includes:
  • the first receiving module 41 is configured to receive the message carrying the indication information sent by the target-side mobility management network element 63.
  • the first sending module 43 is configured to send the security context of the user equipment corresponding to the indication information to the target side mobility management network element 63.
  • the indication information in the request message includes information indicating the device type of the target side mobility management network element 63 or information indicating the security context type of the user equipment that the target side mobility management network element 63 needs to acquire. Therefore, the first sending module 43 includes:
  • a first sending unit configured to indicate, in the indication information, that the device type of the target-side mobility management network element 63 is the SGSN or the target-side mobility management network element 63 needs to acquire the security context type of the user equipment in the GERAN/UTRAN network.
  • the security context in the GERAN/UTRAN network is sent to the target side mobility management network element 63;
  • a second sending unit configured to indicate, in the indication information, that the device type of the target-side mobility management network element 63 is the MME or the target-side mobility management network element 63 needs to acquire the security context type of the user equipment in the E-UTRAN network.
  • the security context in the E-UTRAN network is sent to the target side mobility management network element 63;
  • the third sending unit is configured to: when the indication information indicates that the device type of the target side mobility management network element 63 is the MME and the SGSN, or the target side mobility management network element 63, the security context type of the user equipment that needs to be acquired is When the security context of the E-UTRAN network and the GERAN/UTRAN network, the security context of the E-UTRAN network and the GERAN/UTRAN network is transmitted to the target side mobility management network element 63.
  • the target side mobility management network element 63 includes:
  • the second sending module 51 is configured to send the indication information request message to the source side mobility management network element 61
  • the second receiving module 53 is configured to receive the indication sent by the source side mobility management network element 61 corresponding to the indication.
  • the security context of the user device of the information is configured to send the indication information request message to the source side mobility management network element 61.
  • the second sending module 51 includes:
  • the first indication unit is configured to add indication information indicating a device type of the target side mobility management network element 63 to the request message, and send a request message carrying the indication information to the source side mobility management network element 61. ;
  • a second indication unit configured to add, in the request message, indication information indicating a security context type of the user equipment that the target-side mobility management network element 63 needs to acquire, and send the information to the source-side mobility management network element 61 A request message indicating the information.
  • the target side mobility management network element 63 may be an SGSN device in the GERAN/UTRAN network or The unifying device of the SGSN and the MME may also be an MME device in the E-UTRAN network or a unified device of the SGSN and the MME.
  • the source side mobility management network element 61 determines different device types of the target side mobility management network element 63 according to the indication information in the request message or according to the target side mobility management network element 63 indicated in the request message.
  • the type of security context required provides a corresponding security context, thereby avoiding the process of the target-side mobility management network element 63 interacting with the HSS to obtain a security context, and reducing the interaction load with the HSS.
  • the embodiments of the present invention can be implemented by software, and the corresponding software can be stored in a readable storage medium, such as a hard disk, an optical disk or a floppy disk of a computer.

Abstract

A method, a mobility management network element and a mobile communication system for providing security context are provided, belong to the communication field. The method includes the following steps: receiving a request message sent by a mobility management network element on the destination side, which carries an indication information; sending a security context of a user equipment corresponding to the indication information to the mobility management network element on the destination side. In the embodiment of the present invention, the request message sent from the mobility management network element on the destination side to the mobility management network element on the source side carries the indication information, so that the mobility management network element on the source side can send the security context corresponding to the indication information to the mobility management network element on the destination side according to the indication information within the request message, then the flow that the mobility management network element on the destination side makes interaction with the Home Subscriber Server (HSS) to obtain the security context is avoided, and the load of interaction with HSS is reduced.

Description

提供安全上下文的方法、 移动性管理网元及移动通信系统 本申请要求于 2008年 5月 30日提交中国专利局、 申请号为 200810114117. 7、 发明名 称为 "提供安全上下文的方法、 移动性管理网元及移动通信系统" 的中国专利申请的优先 权, 其全部内容通过引用结合在本申请中。  Method for providing security context, mobility management network element and mobile communication system The application claims to be submitted to the Chinese Patent Office on May 30, 2008, and the application number is 200810114117. 7. The invention is entitled "Method of Providing Security Context, Mobility Management" The priority of the Chinese Patent Application for the Network Element and the Mobile Communication System, the entire contents of which is incorporated herein by reference.
 Say
技术领域 Technical field
本发明涉及通信领域, 特别涉及一种提供安全上下文的方法、 移动性管理网元及移动 通信系统。  The present invention relates to the field of communications, and in particular, to a method for providing a security context, a mobility management network element, and a mobile communication system.
 Book
背景技术 Background technique
无线演进网络的核心网主要包含移动性管理单元(MME, Mobility Management Entity ) 服务网关(SG, Serving Gateway ) 分组数据网络网关(PDN Gateway, Packet Data Network Gateway)三个逻辑功能体。服务通用分组无线业务支持节点(SGSN, Serving GPRS Support Node)是通用移动通信系统(UMTS, Universal Mobile Telecommunications System)和通用 分组无线服务 (GPRS, General Packet Radio Service) 系统中的核心网设备。  The core network of the wireless evolution network mainly includes three logical functions: a mobility management unit (MME), a serving gateway (SG), and a packet data network gateway (PDN Gateway). The Serving GPRS Support Node (SGSN) is a core network device in a Universal Mobile Telecommunications System (UMTS) and a General Packet Radio Service (GPRS) system.
现有技术中, 当用户设备 (UE, User Equipment)在全球移动通信系统 (GSM, Global System For Mobile Communication)或全球移动通信演进系统 (EDGE, Enhanced Data for GSM Evolution) 无线接入网 (GERAN, GSM/EDGE Radio Access Network) /通用移动通信系统 陆地无线接入网(UTRAN, UMTS Territorial Radio Access Network)网络和演进的通用移动 通信系统陆地无线接入网 (E-UTRAN, Evolved UMTS Territorial Radio Access Network) 之 间移动的时候, UE会发起跟踪区更新流程或者路由区更新流程来注册到目标网络。 在现有 技术中, SGSN和 MME是独立的功能实体, 其中 MME可支持 E-UTRAN无线接入系统的 接入。  In the prior art, when the user equipment (UE, User Equipment) is in the Global System For Mobile Communication (GSM) or the EDGE (Enhanced Data for GSM Evolution) radio access network (GERAN, GSM/EDGE Radio Access Network) / Universal Mobile Telecommunications System (UTRAN, UMTS Territorial Radio Access Network) network and Evolved Universal Mobile Telecommunications System (E-UTRAN, Evolved UMTS Territorial Radio Access Network) When moving between, the UE initiates a tracking area update process or a routing area update process to register to the target network. In the prior art, the SGSN and the MME are independent functional entities, wherein the MME can support access of the E-UTRAN wireless access system.
现有技术中, 当 UE在 GERAN/UTRAN网络或者 E-UTRAN网络附着的时候, UE首先 要执行附着流程: 源侧移动性管理网元根据目标侧移动性管理网元发送的用户的临时标识 找到用户的国际移动用户标识 (IMSI, International Mobile Subscriber Identification), 并且将 安全上下文和 IMSI在标识响应消息中一并返给目标侧移动性管理网元。  In the prior art, when the UE is attached to the GERAN/UTRAN network or the E-UTRAN network, the UE first performs an attach procedure: The source-side mobility management network element is found according to the temporary identifier of the user sent by the target-side mobility management network element. The user's International Mobile Subscriber Identity (IMSI), and the security context and the IMSI are returned to the target-side mobility management network element together with the identity response message.
当 UE从 GERAN/UTRAN网络移动到 E-UTRAN网络的时候, UE通过向 MME发送跟 踪区更新请求消息发起跟踪区更新流程: 目标侧 MME在接收到 UE发送的跟踪区更新请求 消息时向源侧 SGSN发送上下文请求消息索要上下文信息, 并接收源侧 SGSN返回的携带 上下文信息的上下文响应消息, 向 UE返回跟踪区更新接受消息。同理,当 UE从 E-UTRAN 网络移动到 GERAN/UTRAN网络时, UE通过向 SGSN发送路由区更新请求消息发起路由 区更新流程。 When the UE moves from the GERAN/UTRAN network to the E-UTRAN network, the UE sends a message to the MME. The tracking area update request message initiates a tracking area update process: when receiving the tracking area update request message sent by the UE, the target side MME sends a context request message request context information to the source side SGSN, and receives the context carrying the context information returned by the source side SGSN. In response to the message, a Tracking Area Update Accept message is returned to the UE. Similarly, when the UE moves from the E-UTRAN network to the GERAN/UTRAN network, the UE initiates a routing area update procedure by sending a Routing Area Update Request message to the SGSN.
在实现本发明的过程中, 发明人发现:  In the process of implementing the present invention, the inventors discovered that:
由于 SGSN和 MME功能接近,在实现的过程中,可以将这两个功能置于一个物理实体 中实现, 此物理实体为合一设备, 其同时具备 SGSN和 MME的功能。 UE第一次在合一设 备附着的时候, 合一设备会将 UE在 GERAN/UTRAN网络和 E-UTRAN网络的安全上下文 都从 HSS获取得到。 当后续 UE从一个合一设备切换到目标侧移动性管理网元时, 需要发 起跟踪区更新流程或者路由区更新流程。 在跟踪区更新流程或者路由区更新流程中, 目标 侧移动性管理网元需要从源侧的合一设备获取 UE的上下文信息。由于源侧移动性管理网元 同时保存了 GERAN/UTRAN网络和 E-UTRAN网络中的安全上下文, 目标侧移动性管理网 元在获取上下文时, 源侧移动性管理网元无法提供合适的安全上下文, 当目标侧移动性管 理网元没有安全上下文或没有合适的安全上下文时, 目标侧移动性管理网元都需要与 HSS 进行交互从而获取安全上下文, 增加了与 HSS的交互负荷。 发明内容  Since the functions of the SGSN and the MME are close to each other, in the implementation process, the two functions can be implemented in one physical entity, and the physical entity is a unified device, which has the functions of the SGSN and the MME. The first time the UE attaches to the unified device, the unified device obtains the security context of the UE on the GERAN/UTRAN network and the E-UTRAN network from the HSS. When the subsequent UE switches from the one-to-one device to the target-side mobility management network element, the tracking area update process or the routing area update process needs to be initiated. In the tracking area update process or the routing area update process, the target-side mobility management network element needs to obtain the context information of the UE from the unified device on the source side. Since the source-side mobility management network element simultaneously stores the security contexts in the GERAN/UTRAN network and the E-UTRAN network, the source-side mobility management network element cannot provide a suitable security context when the target-side mobility management network element acquires the context. When the target-side mobility management network element does not have a security context or does not have a suitable security context, the target-side mobility management network element needs to interact with the HSS to obtain a security context, which increases the interaction load with the HSS. Summary of the invention
为了解决现有技术中源侧移动性管理网元无法为目标侧移动性管理网元提供合适的安 全上下文, 本发明实施例提供了提供安全上下文的方法、 移动性管理网元及移动通信系统, 以使源侧移动性管理网元可以向目标侧移动性管理网元提供合适的安全上下文。 所述技术 方案如下:  In order to solve the problem in the prior art, the source-side mobility management network element cannot provide a suitable security context for the target-side mobility management network element, and the embodiment of the present invention provides a method for providing a security context, a mobility management network element, and a mobile communication system. In order for the source side mobility management network element to provide a suitable security context to the target side mobility management network element. The technical solution is as follows:
一种提供安全上下文的方法, 该方法包括:  A method of providing a security context, the method comprising:
接收由目标侧移动性管理网元发送的携带有指示信息的请求消息;  Receiving a request message that is sent by the target side mobility management network element and carrying the indication information;
向所述目标侧移动性管理网元发送相应于所述指示信息的用户设备的安全上下文。 一种移动性管理网元, 该移动性管理网元包括:  And transmitting, to the target-side mobility management network element, a security context of the user equipment corresponding to the indication information. A mobility management network element, the mobility management network element includes:
第一接收模块 (41 ), 用于接收由目标侧移动性管理网元发送的携带有指示信息的请求 消息;  a first receiving module (41), configured to receive a request message that is sent by the target side mobility management network element and carries the indication information;
第一发送模块 (43 ), 用于向所述目标侧移动性管理网元发送相应于所述指示信息的用 户设备的安全上下文。  The first sending module (43) is configured to send, to the target side mobility management network element, a security context of the user equipment corresponding to the indication information.
一种移动性管理网元, 该移动性管理网元包括: 第二发送模块 (51 ), 用于向源侧移动性管理网元发送携带有指示信息的请求消息; 第二接收模块 (53 ), 用于接收由所述源侧移动性管理网元发送的相应于所述指示信息 的用户设备的安全上下文。 A mobility management network element, the mobility management network element includes: a second sending module (51), configured to send a request message carrying the indication information to the source-side mobility management network element, where the second receiving module (53) is configured to receive the source-side mobility management network element Corresponding to the security context of the user equipment of the indication information.
一种移动通信系统, 该系统包括: 源侧移动性管理网元 (61 ) 和目标侧移动性管理网 元 (63 );  A mobile communication system, the system comprising: a source side mobility management network element (61) and a target side mobility management network element (63);
所述源侧移动性管理网元 (61 ), 用于接收由所述目标侧移动性管理网元 (63 ) 发送的 携带有指示信息的请求消息, 向所述目标侧移动性管理网元 (63 ) 发送相应于所述指示信 息的用户设备的安全上下文;  The source-side mobility management network element (61) is configured to receive a request message that is sent by the target-side mobility management network element (63) and that carries the indication information, to the target-side mobility management network element ( 63) transmitting a security context of the user equipment corresponding to the indication information;
所述目标侧移动性管理网元 (63 ), 用于向所述源侧移动性管理网元 (61 ) 发送携带有 指示信息的请求消息, 并接收所述源侧移动性管理网元 (61 ) 发送的相应于所述指示信息 的用户设备的安全上下文。  The target-side mobility management network element (63) is configured to send a request message carrying the indication information to the source-side mobility management network element (61), and receive the source-side mobility management network element (61) a security context sent by the user equipment corresponding to the indication information.
本发明实施例中, 由于在目标侧移动性管理网元向源侧移动性管理网元发送的请求消 息中携带了指示信息, 从而使得源侧移动性管理网元可以根据请求消息中的指示信息, 向 目标侧移动性管理网元发送相应的安全上下文, 从而避免了目标侧移动性管理网元与归属 网络服务器 (HSS, Home Subscriber Server) 进行交互获取安全上下文的流程, 减少了与 HSS的交互负荷。 附图说明  In the embodiment of the present invention, the request message sent by the target-side mobility management network element to the source-side mobility management network element carries the indication information, so that the source-side mobility management network element can follow the indication information in the request message. Transmitting the corresponding security context to the target-side mobility management network element, thereby avoiding the process of the target-side mobility management network element interacting with the home network server (HSS, Home Subscriber Server) to obtain the security context, and reducing the interaction with the HSS load. DRAWINGS
图 1是无线演进网络在非漫游场景中的架构示意图;  1 is a schematic structural diagram of a wireless evolved network in a non-roaming scenario;
图 2是本发明实施例 1提供的提供安全上下文的方法流程图;  2 is a flowchart of a method for providing a security context according to Embodiment 1 of the present invention;
图 3是本发明实施例 2提供的提供安全上下文的方法流程图;  3 is a flowchart of a method for providing a security context according to Embodiment 2 of the present invention;
图 4是本发明实施例 3提供的移动性管理网元结构示意图;  4 is a schematic structural diagram of a mobility management network element according to Embodiment 3 of the present invention;
图 5是本发明实施例 4提供的移动性管理网元结构示意图;  FIG. 5 is a schematic structural diagram of a mobility management network element according to Embodiment 4 of the present invention; FIG.
图 6是本发明实施例 5提供的移动通信系统结构示意图。 具体实施方式  FIG. 6 is a schematic structural diagram of a mobile communication system according to Embodiment 5 of the present invention. detailed description
为使本发明的目的、 技术方案和优点更加清楚, 下面将结合附图对本发明实施方式作 进一步地详细描述。  The embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
如图 1所示, 为无线演进网络在非漫游场景中的架构示意图。 其中, MME具有网络附 加存储 (NAS, Network-Attached Storage)和 NAS信令加密以及漫游、跟踪等功能, 分配用户 临时身份标识、 安全功能等, 它对应于当前 UMTS 内部 SGSN 的控制平面部分。 Serving Gateway 负责本地的移动性锚点和 3GPP 系统内部的移动性锚点以及合法监听相关信息。 PDN Gateway则负责策略执行和计费以及合法监听相关功能。 HSS用于存储用户签约信息。 控制和计费策略 (PCRF, Policy and Charging Rules Function, ) 负责制定控制和计费策略。 SGSN可支持 GERAN和 UTRAN系统的接入, 负责移动性管理、 用户数据的转发等功能。 FIG. 1 is a schematic diagram of an architecture of a wireless evolved network in a non-roaming scenario. The MME has the functions of network-attached storage (NAS, Network-Attached Storage) and NAS signaling encryption, roaming, tracking, etc., and assigns user temporary identity, security function, etc., which corresponds to the control plane part of the current UMTS internal SGSN. Serving The Gateway is responsible for local mobility anchors and mobility anchors within the 3GPP system as well as lawful interception related information. The PDN Gateway is responsible for policy enforcement and billing as well as lawful interception related functions. The HSS is used to store user subscription information. The Policy and Charging Rules Function (PCRF) is responsible for formulating control and accounting policies. The SGSN supports access to GERAN and UTRAN systems and is responsible for mobility management and forwarding of user data.
本发明实施例中, 当 UE发起路由区更新流程或者跟踪区更新流程时, 在源侧移动性管 理网元和目标侧移动性管理网元之间的上下文传递过程中, 源侧移动性管理网元根据目标 侧移动性管理网元设备类型或者根据目标侧移动性管理网元指示的所需安全上下文的类 型, 传递合适的 UE的安全上下文。  In the embodiment of the present invention, when the UE initiates the routing area update process or the tracking area update process, the source side mobility management network is in the context transfer process between the source side mobility management network element and the target side mobility management network element. The element transmits the security context of the appropriate UE according to the target side mobility management network element device type or according to the type of required security context indicated by the target side mobility management network element.
需要说明的是, 本发明实施例所述的安全上下文可以为安全参数, 具体可以是鉴权向量 或安全密钥等安全参数。  It should be noted that the security context described in the embodiment of the present invention may be a security parameter, and may be a security parameter such as an authentication vector or a security key.
另外, 当 UE执行附着流程时, 目标侧移动性管理网元从源侧移动性管理网元获取 IMSI 和安全上下文, 源侧移动性管理网元根据目标侧移动性管理网元设备类型或者根据目标侧 移动性管理网元指示的所需安全上下文的类型, 传递合适的 UE的安全上下文。  In addition, when the UE performs the attach procedure, the target-side mobility management network element acquires the IMSI and the security context from the source-side mobility management network element, and the source-side mobility management network element manages the network element device type according to the target-side mobility or according to the target. The type of required security context indicated by the side mobility management network element, delivering the security context of the appropriate UE.
下述实施例 1以 UE发起路由区更新流程或者跟踪区更新流程为例说明提供安全上下文 的方法。  The following Embodiment 1 illustrates a method for providing a security context by using a UE to initiate a routing area update process or a tracking area update process.
需要说明的是, 为了方便描述, 实施例 1 中将路由区更新或者跟踪区更新统称为位置 区更新。  It should be noted that, for convenience of description, the routing area update or the tracking area update in the first embodiment is collectively referred to as location area update.
实施例 1  Example 1
本实施例中, UE 首先附着在源侧移动性管理网元, 源侧移动性管理网元同时保存了 GERAN/UTRAN网络和 E-UTRAN网络中的安全上下文。 当 UE发起路由区更新流程或者 跟踪区更新流程时, 在源侧移动性管理网元和目标侧移动性管理网元之间的上下文传递过 程中, 目标侧移动性管理网元可以在上下文请求消息中携带一个指示设备类型的信息, 例 如支持无线接入类型(Supported RAT, Supported Radio Access Type), 将自身的设备类型告 知源侧移动性管理网元, 使源侧移动性管理网元根据目标侧移动性管理网元设备类型传递 对应的 UE的安全上下文; 或者目标侧移动性管理网元通过其他方式,例如在上下文请求消 息中携带一个指示需要获取的安全上下文的类型的信息等, 使源侧移动性管理网元根据目 标侧移动性管理网元设备类型传递合适的 UE的安全上下文。  In this embodiment, the UE first attaches to the source-side mobility management network element, and the source-side mobility management network element simultaneously stores the security contexts in the GERAN/UTRAN network and the E-UTRAN network. When the UE initiates the routing area update process or the tracking area update process, the target side mobility management network element may be in the context request message during the context transfer process between the source side mobility management network element and the target side mobility management network element. The device carries a message indicating the type of the device, for example, a supported radio access type (Supported RAT, Supported Radio Access Type), and informs the source-side mobility management network element of the device type, so that the source-side mobility management network element is based on the target side. The mobility management network element device type delivers the security context of the corresponding UE; or the target side mobility management network element carries the source side by other means, for example, carrying a message indicating the type of the security context to be acquired in the context request message. The mobility management network element delivers the security context of the appropriate UE according to the target side mobility management network element device type.
以下根据图 2对本实施例提供的提供安全上下文的方法进行详细描述。 如图 2所示, 该方法主要包括以下步骤:  The method for providing a security context provided by this embodiment is described in detail below with reference to FIG. As shown in FIG. 2, the method mainly includes the following steps:
步骤 101 : 当 UE移动到目标侧网络后向目标侧移动性管理网元发送位置区更新请求消 息。 其中, UE在源侧移动性管理网元附着后, 当 UE移动到 E-UTRAN网络时, 目标侧移 动性管理网元功能实体是 MME。 当 UE移动到 GERAN/UTRAN网络时, 目标侧移动性管 理网元功能实体是 SGSN。可以理解的是, 不论在何种网络, 目标侧移动性管理网元也可以 是 SGSN与 MME合一设备。 Step 101: Send a location area update request message to the target side mobility management network element after the UE moves to the target side network. After the UE moves to the E-UTRAN network, the UE-side mobility management network element functional entity is the MME. When the UE moves to the GERAN/UTRAN network, the target side mobility management network element functional entity is the SGSN. It can be understood that the target-side mobility management network element may be a SGSN and MME-integrated device regardless of the network.
其中, 位置区更新是对路由区更新与跟踪区更新的综述; 位置区更新请求消息包括: 跟踪区更新请求消息和路由区更新请求消息。具体地, 当 UE移动到 E-UTRAN网络时, UE 发起跟踪区更新流程, UE向目标侧移动性管理网元发送跟踪区更新请求消息; 当 UE移动 到 GERAN/UTRAN网络时, UE发起路由区更新流程, UE向目标侧移动性管理网元发送路 由区更新请求消息。  The location area update is an overview of the routing area update and the tracking area update; the location area update request message includes: a tracking area update request message and a routing area update request message. Specifically, when the UE moves to the E-UTRAN network, the UE initiates a tracking area update procedure, and the UE sends a tracking area update request message to the target side mobility management network element; when the UE moves to the GERAN/UTRAN network, the UE initiates the routing area. In the update process, the UE sends a routing area update request message to the target side mobility management network element.
步骤 102: 目标侧移动性管理网元向源侧移动性管理网元发送上下文请求消息, 在该消 息中增加指示目标侧移动性管理网元设备类型的信息。  Step 102: The target-side mobility management network element sends a context request message to the source-side mobility management network element, and adds information indicating the target-side mobility management network element device type to the message.
其中, 目标侧移动性管理网元通过发送上述上下文请求消息, 从而向源侧移动性管理 网元请求获取 UE的上下文信息, 包括 UE的安全上下文。  The target-side mobility management network element requests the source-side mobility management network element to acquire the context information of the UE, including the security context of the UE, by sending the foregoing context request message.
其中, 在上下文请求消息中增加一个指示目标侧移动性管理网元设备类型的信息, 例 如 Supported RAT。 具体包括以下情况:  And adding, in the context request message, information indicating the type of the target side mobility management network element device, such as a Supported RAT. Specifically includes the following:
1)如果目标侧移动性管理网元是一个 MME单独功能实体, Supported RAT值为 0; 1) If the target-side mobility management network element is a MME separate functional entity, the Supported RAT value is 0;
2)如果目标侧移动性管理网元是一个 SGSN单独功能实体, Supported RAT值为 1 ;2) If the target-side mobility management network element is a separate functional entity of the SGSN, the Supported RAT value is 1;
3)如果目标侧移动性管理网元是一个 SGSN与 MME合一设备, Supported RAT值为 2。 其中 Supported RAT的值可以通过软件进行设置。 3) If the target-side mobility management network element is a SGSN and MME-integrated device, the supported RAT value is 2. The value of the Supported RAT can be set by software.
步骤 103 : 源侧移动性管理网元向目标侧移动性管理网元返回上下文响应消息, 通过此 消息返回 UE的上下文信息, 包括 UE的安全上下文。  Step 103: The source-side mobility management network element returns a context response message to the target-side mobility management network element, and returns the context information of the UE by using the message, including the security context of the UE.
其中, 与步骤 102中的三种情况对应的, 返回上下文响应消息具体包括以下情况: 1) 当 Supported RAT值为 0时,源侧移动性管理网元需要在上下文响应消息中返回的安 全上下文是 UE在 E-UTRAN网络的安全上下文;  The return context response message corresponding to the three situations in step 102 specifically includes the following situations: 1) When the supported RAT value is 0, the security context returned by the source side mobility management network element in the context response message is The security context of the UE in the E-UTRAN network;
2) 当 Supported RAT值为 1时,源侧移动性管理网元需要在上下文响应消息中返回的安 全上下文是 UE在 GERAN/UTRAN网络的安全上下文;  2) When the Supported RAT value is 1, the security context that the source-side mobility management network element needs to return in the context response message is the security context of the UE in the GERAN/UTRAN network;
3) 当 Supported RAT值为 2时,源侧移动性管理网元需要在上下文响应消息中返回的安 全上下文是 UE在 E-UTRAN网络和 GERAN/UTRAN网络全部的安全上下文。  3) When the Supported RAT value is 2, the security context that the source-side mobility management network element needs to return in the context response message is the security context of the UE in the E-UTRAN network and the GERAN/UTRAN network.
步骤 104: 目标侧移动性管理网元向源侧移动性管理网元发送上下文确认消息。  Step 104: The target side mobility management network element sends a context confirmation message to the source side mobility management network element.
步骤 105 : 目标侧移动性管理网元向 UE返回位置区更新接受消息。  Step 105: The target side mobility management network element returns a location area update accept message to the UE.
在本实施例步骤 102中,也可以在上下文请求消息中增加一个指示需要获取的安全上下 文的类型的信息, 例如鉴权向量类型 (Authentication Type )。 例如: In step 102 of this embodiment, a security indication that needs to be acquired may also be added to the context request message. Information about the type of the text, such as the Authentication Type. E.g:
1)如果目标侧移动性管理网元仅需要 UE 在 E-UTRAN 网络的安全上下文时, Authentication Type值为 0;  1) If the target-side mobility management network element only needs the security context of the UE in the E-UTRAN network, the Authentication Type value is 0;
2)如果目标侧移动性管理网元仅需要 UE在 GERAN/UTRAN 网络的安全上下文时, Authentication Type值为 1;  2) If the target-side mobility management network element only needs the security context of the UE in the GERAN/UTRAN network, the Authentication Type value is 1;
3)如果目标侧移动性管理网元需要 UE在 E-UTRAN网络和 GERAN/UTRAN网络的全 部安全上下文时, Authentication Type值为 2。  3) If the target-side mobility management network element requires the UE's full security context on the E-UTRAN network and the GERAN/UTRAN network, the Authentication Type value is 2.
与上述三种情况对应地, 在本实施例步骤 103中, 返回上下文响应消息具体包括以下情 况:  Corresponding to the above three cases, in step 103 of this embodiment, the returning the context response message specifically includes the following cases:
1) 当 Authentication Type值为 0时,源侧移动性管理网元需要在上下文响应消息中返回 的安全上下文是 UE在 E-UTRAN网络的安全上下文;  1) When the Authentication Type value is 0, the security context returned by the source-side mobility management network element in the context response message is the security context of the UE in the E-UTRAN network;
2) 当 Authentication Type值为 1时,源侧移动性管理网元需要在上下文响应消息中返回 的安全上下文是 UE在 GERAN/UTRAN网络的安全上下文;  2) When the Authentication Type value is 1, the security context returned by the source-side mobility management network element in the context response message is the security context of the UE in the GERAN/UTRAN network;
3) 当 Authentication Type值为 2时,源侧移动性管理网元需要在上下文响应消息中返回 的安全上下文是 UE在 E-UTRAN网络和 GERAN/UTRAN网络全部的安全上下文。  3) When the Authentication Type value is 2, the security context that the source-side mobility management network element needs to return in the context response message is the security context of the UE in the E-UTRAN network and the GERAN/UTRAN network.
需要说明的是, 本发明实施例不限定表示指示信息的形式, 比如指示目标侧移动性管理 网元设备类型的信息, 也可以再通过扩展一个信元, 携带目标侧移动性管理网元设备的类 型名称, 比如当目标侧移动性管理网元是一个 SGSN时, 该信元可以设置为 " SGSN", 当 目标侧移动性管理网元是一个 MME时, 该信元可以设置为 " MME", 当目标侧移动性管理 网元是 SGSN与 MME的合一设备, 该信元可以设置为 " Combined SGSN/MME", 此时, 在步骤 103 中, 源侧移动性管理网元可以根据这个指示信息所指示的目标侧移动性管理网 元设备类型, 在上下文响应消息中将其相应的安全上下文发送至目标侧移动性管理网元。  It should be noted that, the embodiment of the present invention does not limit the form of the indication information, such as the information indicating the type of the target side mobility management network element device, and may further extend the cell to carry the target side mobility management network element device. The type name, for example, when the target-side mobility management network element is an SGSN, the cell can be set to "SGSN". When the target-side mobility management network element is an MME, the cell can be set to "MME". When the target-side mobility management network element is a unified device of the SGSN and the MME, the cell may be set to "combined SGSN/MME". In this case, in step 103, the source-side mobility management network element may be configured according to the indication information. The indicated target-side mobility management network element device type sends its corresponding security context to the target-side mobility management network element in the context response message.
上述实施例中源侧移动性管理网元可以是 SGSN与 MME的合一设备, 这样 UE第一次 在合一设备附着的时候, 合一设备会将 UE在 GERAN/UTRAN网络和 E-UTRAN网络的安 全上下文都从 HSS获取得到;另外,源侧移动性管理网元也可以是单独的 SGSN或者 MME, 由于在用户注册到单独的 SGSN或者 MME之前附着在一个合一设备,该合一设备获取了用 户在 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文, 当用户发生路由区更新或者跟 踪区更新注册到了单独的 SGSN或者 MME时,该单独的 SGSN或者 MME会向开始的合一 设备索取用户安全上下文, 此时合一设备会将用户在 E-UTRAN网络和 GERAN/UTRAN网 络的所有的安全上下文都发给单独的 SGSN或者 MME, 此时 SGSN或者 MME不仅保存有 用户在 GERAN/UTRAN网络的安全上下文同时也保存有用户在 E-UTRAN网络的安全上下 文。当单独的 SGSN或者 MME再次作为源测移动性管理网元时, 由于该源侧移动性管理网 元也保存有 GERAN/UTRAN网络和 E-UTRAN网络的安全上下文, 其也可以根据目标侧移 动性管理网元发送的请求消息中的指示信息, 将对应的安全上下文发送至目标移动性管理 网元。 In the foregoing embodiment, the source-side mobility management network element may be a unified device of the SGSN and the MME, so that when the UE is attached to the unified device for the first time, the unified device will use the UE in the GERAN/UTRAN network and the E-UTRAN network. The security context of the source is obtained from the HSS. In addition, the source-side mobility management network element may also be a separate SGSN or MME. Since the user is attached to a single device before being registered to a separate SGSN or MME, the unified device obtains The security context of the user in the E-UTRAN network and the GERAN/UTRAN network. When a user initiates a routing area update or a tracking area update is registered to a separate SGSN or MME, the individual SGSN or MME requests the user from the starting unified device. Security context, at this time, the unified device will send all the security contexts of the user in the E-UTRAN network and the GERAN/UTRAN network to a separate SGSN or MME. At this time, the SGSN or MME not only stores the user in the GERAN/UTRAN network. The security context also preserves the security of the user on the E-UTRAN network. Text. When the single SGSN or the MME is again used as the source mobility management network element, since the source side mobility management network element also stores the security context of the GERAN/UTRAN network and the E-UTRAN network, it may also be based on the target side mobility. The indication information in the request message sent by the management network element is sent to the target mobility management network element.
本实施例中, 在 UE首先附着在源侧移动性管理网元的情况下, 当 UE发起路由区更新 流程或者跟踪区更新流程时, 在源侧移动性管理网元和目标侧移动性管理网元之间上下文 传递的过程中, 源侧移动性管理网元根据请求消息中的指示信息判断目标侧移动性管理网 元的不同的设备类型, 或者根据请求消息中指示目标侧移动性管理网元需要获取的安全上 下文的类型返回对应合适的 UE的安全上下文,从而可以避免目标侧移动性管理网元和 HSS 的交互来获取安全上下文的流程, 减少了与 HSS交互负荷。  In this embodiment, when the UE first attaches to the source-side mobility management network element, when the UE initiates the routing area update process or the tracking area update process, the source-side mobility management network element and the target-side mobility management network In the process of context transfer between the elements, the source-side mobility management network element determines different device types of the target-side mobility management network element according to the indication information in the request message, or indicates the target-side mobility management network element according to the request message. The type of the security context that needs to be obtained returns the security context corresponding to the appropriate UE, so that the interaction between the target-side mobility management network element and the HSS can be avoided to obtain the security context, and the interaction load with the HSS is reduced.
下述实施例 2以 UE发起的附着流程为例说明提供安全上下文的方法。  The following Embodiment 2 illustrates a method for providing a security context by taking a UE-initiated attach procedure as an example.
实施例 2  Example 2
本实施例中, UE 首先附着在源侧移动性管理网元, 源侧移动性管理网元同时保存了 GERAN/UTRAN网络和 E-UTRAN网络中的安全上下文。 当 UE与源侧移动性管理网元分 离要改变附着对象时, UE需执行附着流程, 向目标侧移动性管理网元发送附着请求消息, 该消息中携带有 UE的临时标识,此时目标侧移动性管理网元需要从源侧移动性管理网元获 取 IMSI和安全上下文, 源侧移动性管理网元需要根据目标侧移动性管理网元设备类型传递 不同的 UE的安全上下文。  In this embodiment, the UE first attaches to the source-side mobility management network element, and the source-side mobility management network element simultaneously stores the security contexts in the GERAN/UTRAN network and the E-UTRAN network. When the UE is separated from the source-side mobility management network element to change the attached object, the UE needs to perform an attach procedure, and sends an attach request message to the target-side mobility management network element, where the message carries the temporary identifier of the UE, and the target side The mobility management network element needs to obtain the IMSI and the security context from the source-side mobility management network element, and the source-side mobility management network element needs to deliver different UE security contexts according to the target-side mobility management network element device type.
以下根据图 3对本实施例提供的提供安全上下文的方法进行详细描述。 如图 3所示, 该方法主要包括以下步骤:  The method for providing a security context provided by this embodiment is described in detail below with reference to FIG. As shown in FIG. 3, the method mainly includes the following steps:
步骤 201 : UE执行附着流程时, 向目标侧移动性管理网元发送附着请求消息。  Step 201: When the UE performs the attach procedure, the UE sends an attach request message to the target mobility management network element.
其中, UE在分离之前附着在源侧移动性管理网元;  The UE is attached to the source-side mobility management network element before being separated;
在附着请求消息中, 包含了 UE的临时标识或者国际移动用户标识 IMSI。 如果 UE只 携带了其临时标识, 那么目标侧移动性管理网元需要向源侧移动性管理网元索要 IMSI和安 全上下文。 当目标侧移动性管理单元是 SGSN时, UE在附着请求消息中携带的临时标识是 分组临时移动用户身份标识 (P-TMSI, Packet Temporary Mobile Subscriber Identity)和路由 区标 i只 (RAI, Routeing Area Identity )。  The attach request message includes the temporary identifier of the UE or the international mobile subscriber identity IMSI. If the UE only carries its temporary identity, the target-side mobility management network element needs to request the IMSI and the security context from the source-side mobility management network element. When the target-side mobility management unit is the SGSN, the temporary identifier carried by the UE in the attach request message is a packet temporary mobile subscriber identity (P-TMSI, Packet Temporary Mobile Subscriber Identity) and a routing area identifier i (RAI, Routeing Area). Identity ).
当目标侧移动性管理网元是 MME时,那么 UE在附着请求消息中携带的临时标识是全 球唯一临时标识 (GUTI, Globally Unique Temporary Identity )0 When the target-side mobility management network element is a MME, the UE carried in the attach request message is a global unique temporary identity temporary identity (GUTI, Globally Unique Temporary Identity) 0
步骤 202: 目标侧移动性管理网元向源侧移动性管理网元发送标识请求消息, 在该消息 中增加指示目标侧移动性管理网元设备类型的信息。 其中, 目标侧移动性管理网元通过标识请求消息中的用户的临时标识向源侧移动性管 理网元请求获取用户的 IMSI和其安全上下文。 Step 202: The target-side mobility management network element sends an identifier request message to the source-side mobility management network element, and adds information indicating the target-side mobility management network element device type to the message. The target-side mobility management network element requests the source-side mobility management network element to acquire the IMSI of the user and its security context by using the temporary identifier of the user in the identifier request message.
其中, 在上下文请求消息中增加一个指示目标侧移动性管理网元设备类型的信息, 例 如 Supported RAT。具体包括的情况与实施例 1步骤 102中的三种情况相似,此处不再赘述。  And adding, in the context request message, information indicating the type of the target side mobility management network element device, such as a Supported RAT. The specific situation is similar to the three cases in step 102 of Embodiment 1, and details are not described herein again.
步骤 203 : 源侧移动性管理网元向目标侧移动性管理网元返回标识响应消息, 该消息中 包含了用户的 IMSI和对应的安全上下文。  Step 203: The source-side mobility management network element returns an identifier response message to the target-side mobility management network element, where the message includes the IMSI of the user and the corresponding security context.
具体地, 包括以下三种情况:  Specifically, the following three situations are included:
1) 当 Supported RAT值为 0时,源侧移动性管理网元需要在标识响应消息中返回的安全 上下文是 UE在 E-UTRAN网络的安全上下文;  1) When the supported RAT value is 0, the security context returned by the source-side mobility management network element in the identity response message is the security context of the UE in the E-UTRAN network;
2) 当 Supported RAT值为 1时,源侧移动性管理网元需要在标识响应消息中返回的安全 上下文是 UE在 GERAN/UTRAN网络的安全上下文;  2) When the supported RAT value is 1, the security context returned by the source-side mobility management network element in the identity response message is the security context of the UE in the GERAN/UTRAN network;
3) 当 Supported RAT值为 2时,源侧移动性管理网元需要在标识响应消息中返回的安全 上下文是 UE在 E-UTRAN网络和 GERAN/UTRAN网络全部的安全上下文。  3) When the Supported RAT value is 2, the security context returned by the source-side mobility management network element in the identity response message is the security context of the UE in the E-UTRAN network and the GERAN/UTRAN network.
步骤 204: 目标侧移动性管理网元向 UE返回附着接受消息。  Step 204: The target side mobility management network element returns an attach accept message to the UE.
在本实施例步骤 202中,还可以通过在标识请求消息中增加一个指示需要获取的安全上 下文的类型的信息, 例如 Authentication Type; 相应地, 源侧移动性管理网元需要在标识响 应消息中返回的安全上下文也分为三种情况, 具体包括的内容与实施例 1 中所述相似, 此 处不再赘述。  In the step 202 of the embodiment, the information about the type of the security context to be acquired, for example, the Authentication Type, may be added to the identifier request message. Accordingly, the source-side mobility management network element needs to return in the identifier response message. The security context is also divided into three cases, and the specific content is similar to that described in Embodiment 1, and details are not described herein again.
需要说明的是, 同实施例 1相似的, 本发明实施例不限定表示指示信息的形式, 比如指 示目标侧移动性管理网元设备类型的信息, 也可以再通过扩展一个信元, 携带目标侧移动 性管理网元设备的类型名称, 比如当目标侧移动性管理网元是一个 SGSN时, 该信元可以 设置为 " SGSN", 当目标侧移动性管理网元是一个 MME时, 该信元可以设置为 " MME", 当目标侧移动性管理网元是 SGSN 与 MME 的合一设备, 该信元可以设置为 " Combined SGSN/MME", 此时, 在步骤 203中, 源侧移动性管理网元可以根据这个指示信息所指示的 目标侧移动性管理网元设备类型, 在标识响应消息中将其相应的安全上下文发送至目标侧 移动性管理网元。  It should be noted that, similar to the first embodiment, the embodiment of the present invention does not limit the form of the indication information, such as the information indicating the type of the target side mobility management network element device, and may further extend the cell to carry the target side. The type name of the mobility management network element device, for example, when the target-side mobility management network element is an SGSN, the cell may be set to "SGSN", and when the target-side mobility management network element is an MME, the cell It can be set to "MME". When the target-side mobility management network element is a unified device of the SGSN and the MME, the cell can be set to "Combined SGSN/MME". At this time, in step 203, the source-side mobility management is performed. The network element may send its corresponding security context to the target side mobility management network element in the identity response message according to the target-side mobility management network element device type indicated by the indication information.
上述实施例中源侧移动性管理网元可以是 SGSN与 MME的合一设备, 这样 UE第一次 在合一设备附着的时候, 合一设备会将 UE在 GERAN/UTRAN网络和 E-UTRAN网络的安 全上下文都从 HSS获取得到;另外,源侧移动性管理网元也可以是单独的 SGSN或者 MME, 由于在用户附着到单独的 SGSN或者 MME之前附着在一个合一设备,该合一设备获取了用 户在 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文, 当用户执行附着流程附着到了 单独的 SGSN或者 MME时,该单独的 SGSN或者 MME会向开始的合一设备索取用户安全 上下文, 此时合一设备会将用户在 E-UTRAN网络和 GERAN/UTRAN网络的所有的安全上 下文都发给单独的 SGSN 或者 MME, 此时 SGSN 或者 MME 不仅保存有用户在 GERAN/UTRAN网络的安全上下文同时也保存有用户在 E-UTRAN网络的安全上下文。 当 单独的 SGSN或者 MME再次作为源测移动性管理网元时,由于该源侧移动性管理网元也保 存有 GERAN/UTRAN网络和 E-UTRAN网络的安全上下文, 其也可以根据目标侧移动性管 理网元发送的请求消息中的指示信息, 将对应的安全上下文发送至目标移动性管理网元。 In the foregoing embodiment, the source-side mobility management network element may be a unified device of the SGSN and the MME, so that when the UE is attached to the unified device for the first time, the unified device will use the UE in the GERAN/UTRAN network and the E-UTRAN network. The security context of the source is obtained from the HSS. In addition, the source-side mobility management network element may also be a separate SGSN or MME. Since the user is attached to a single device before attaching to the SGSN or MME, the unified device obtains The security context of the user in the E-UTRAN network and the GERAN/UTRAN network is attached to the user when the attach process is performed. In the case of a separate SGSN or MME, the separate SGSN or MME will request the user security context from the starting unifying device. At this time, the unified device will send all the security contexts of the user on the E-UTRAN network and the GERAN/UTRAN network. For a separate SGSN or MME, the SGSN or MME not only stores the security context of the user in the GERAN/UTRAN network but also the security context of the user in the E-UTRAN network. When the single SGSN or MME is again used as the source mobility management network element, since the source side mobility management network element also stores the security context of the GERAN/UTRAN network and the E-UTRAN network, it may also be based on the target side mobility. The indication information in the request message sent by the management network element is sent to the target mobility management network element.
本实施例中, UE首先附着在源侧移动性管理网元, 当 UE与该源侧移动性管理网元分 离要改变附着对象时, UE需执行附着流程, 在此过程中通过在标识请求消息中增加不同信 息,使源侧移动性管理网元能够根据目标侧移动性管理网元设备类型返回对应合适的 UE的 安全上下文,从而可以避免目标侧移动性管理网元和 HSS的交互来获取安全上下文的流程, 减少了与 HSS交互负荷。 实施例 3  In this embodiment, the UE is first attached to the source-side mobility management network element. When the UE is separated from the source-side mobility management network element to change the attached object, the UE needs to perform an attach procedure, in the process, by using the identifier request message. Different information is added to enable the source-side mobility management network element to return a security context corresponding to the appropriate UE according to the target-side mobility management network element device type, so that the interaction between the target-side mobility management network element and the HSS can be avoided to obtain security. The context of the process reduces the interaction load with the HSS. Example 3
参见图 4, 本实施例提供一种移动性管理网元, 该移动性管理网元包括:  Referring to FIG. 4, this embodiment provides a mobility management network element, where the mobility management network element includes:
第一接收模块 41, 用于接收由目标侧移动性管理网元发送的携带有指示信息的请求消 息;  The first receiving module 41 is configured to receive a request message that is sent by the target-side mobility management network element and that carries the indication information.
第一发送模块 43, 用于向目标侧移动性管理网元发送相应于所述指示信息的用户设备 的安全上下文。  The first sending module 43 is configured to send, to the target side mobility management network element, a security context of the user equipment corresponding to the indication information.
其中,请求消息中的指示信息包括指示目标侧移动性管理网元的设备类型的信息或者指 示目标侧移动性管理网元需要获取的用户设备的安全上下文类型的信息。  The indication information in the request message includes information indicating a device type of the target side mobility management network element or information indicating a security context type of the user equipment that the target side mobility management network element needs to acquire.
其中, 第一发送模块 43包括:  The first sending module 43 includes:
第一发送单元, 用于当指示信息中指示目标侧移动性管理网元的设备类型为 SGSN或 者目标侧移动性管理网元需要获取的用户设备的安全上下文类型为 GERAN/UTRAN网络中 的安全上下文时, 向目标侧移动性管理网元发送 GERAN/UTRAN网络中的安全上下文; 第二发送单元,用于当指示信息中指示目标侧移动性管理网元的设备类型为 MME或者 目标侧移动性管理网元需要获取的用户设备的安全上下文类型为 E-UTRAN 网络中的安全 上下文时, 向目标侧移动性管理网元发送 E-UTRAN网络中的安全上下文;  a first sending unit, configured to: when the device type indicating the target side mobility management network element in the indication information is the SGSN or the security context type of the user equipment that the target side mobility management network element needs to acquire, the security context in the GERAN/UTRAN network Sending a security context in the GERAN/UTRAN network to the target-side mobility management network element. The second sending unit is configured to indicate, in the indication information, that the device type of the target-side mobility management network element is the MME or the target-side mobility management. When the security context type of the user equipment that the network element needs to acquire is the security context in the E-UTRAN network, the security context in the E-UTRAN network is sent to the target side mobility management network element;
第三发送单元, 用于当指示信息中指示目标侧移动性管理网元的设备类型为 MME和 SGSN 的合一设备或者目标侧移动性管理网元需要获取的用户设备的安全上下文类型为 E-UTRAN 网络和 GERAN/UTRAN 网络的安全上下文时, 向目标侧移动性管理网元发送 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文。 a third sending unit, configured to: when the device type indicating the target side mobility management network element is the MME and the SGSN, or the target side mobility management network element, the security context type of the user equipment to be acquired is E- Sending the security context of the UTRAN network and the GERAN/UTRAN network to the target-side mobility management network element Security context for E-UTRAN networks and GERAN/UTRAN networks.
实施例 4  Example 4
参见图 5, 本实施例提供一种移动性管理网元, 该移动性管理网元包括:  Referring to FIG. 5, the embodiment provides a mobility management network element, where the mobility management network element includes:
第二发送模块 51, 用于向源侧移动性管理网元发送携带有指示信息的请求消息, 所述 请求消息可以为上下文请求消息或标识请求消息, 具体可参见方法实施例中的说明;  The second sending module 51 is configured to send, to the source-side mobility management network element, a request message that carries the indication information, where the request message may be a context request message or an identifier request message. For details, refer to the description in the method embodiment.
第二接收模块 53, 用于接收由源侧移动性管理网元发送的相应于所述指示信息的用户 设备的安全上下文。  The second receiving module 53 is configured to receive a security context of the user equipment corresponding to the indication information sent by the source side mobility management network element.
其中, 第二发送模块 51包括:  The second sending module 51 includes:
第一指示单元, 用于在所述请求消息中增加指示目标侧移动性管理网元的设备类型的 指示信息, 并向源侧移动性管理网元发送携带有所述指示信息的请求消息; 或  a first indication unit, configured to add indication information indicating a device type of the target side mobility management network element to the request message, and send a request message carrying the indication information to the source side mobility management network element; or
第二指示单元, 用于在所述请求消息中增加指示目标侧移动性管理网元需要获取的用 户设备的安全上下文类型的指示信息, 并向源侧移动性管理网元发送携带有所述指示信息 的请求消息。  a second indication unit, configured to add, in the request message, indication information indicating a security context type of the user equipment that the target side mobility management network element needs to acquire, and send the indication to the source side mobility management network element Request message for information.
本实施例中, 移动性管理网元可以是 GERAN/UTRAN网络中的 SGSN设备或者 SGSN 与 MME的合一设备, 也可以是 E-UTRAN网络中的 MME设备或者 SGSN与 MME的合一 设备, 通过第二发送模块 51在请求消息中增加指示信息, 区别上述不同的设备类型或者区 别上述不同设备需要获取的相应的用户设备的安全上下文。  In this embodiment, the mobility management network element may be an SGSN device in the GERAN/UTRAN network or a unified device of the SGSN and the MME, or may be an MME device in the E-UTRAN network or a unified device of the SGSN and the MME. The second sending module 51 adds the indication information to the request message to distinguish the different device types or the security context of the corresponding user equipment that needs to be obtained by the different devices.
在上述实施例 3~4中,源侧移动性管理网元根据请求消息中的指示信息判断目标侧移动 性管理网元的不同的设备类型或者根据目标侧移动性管理网元在请求消息中指示的所需安 全上下文的类型, 提供对应的安全上下文, 从而避免了目标侧移动性管理网元与 HSS进行 交互获取安全上下文的流程, 减少了与 HSS的交互负荷。  In the foregoing embodiments 3 to 4, the source-side mobility management network element determines, according to the indication information in the request message, different device types of the target-side mobility management network element or indicates in the request message according to the target-side mobility management network element. The type of required security context provides a corresponding security context, thereby avoiding the process of the target-side mobility management network element interacting with the HSS to obtain a security context, and reducing the interaction load with the HSS.
实施例 5  Example 5
参见图 6, 本实施例提供了一种移动通信系统, 包括: 源侧移动性管理网元 61和目标 侧移动性管理网元 63,  Referring to FIG. 6, this embodiment provides a mobile communication system, including: a source side mobility management network element 61 and a target side mobility management network element 63.
源侧移动性管理网元 61,用于接收由目标侧移动性管理网元 63发送的携带有指示信息 的请求消息, 向目标侧移动性管理网元 63发送相应于所述指示信息的用户设备的安全上下 文;  The source-side mobility management network element 61 is configured to receive the request message carrying the indication information sent by the target-side mobility management network element 63, and send the user equipment corresponding to the indication information to the target-side mobility management network element 63. Security context
目标侧移动性管理网元 63,用于向源侧移动性管理网元 61发送携带有指示信息的请求 消息, 并接收由源侧移动性管理网元 61发送的相应于所述指示信息的用户设备的安全上下 文。  The target-side mobility management network element 63 is configured to send a request message carrying the indication information to the source-side mobility management network element 61, and receive the user corresponding to the indication information sent by the source-side mobility management network element 61. The security context of the device.
所述请求消息可以为上下文请求消息或标识请求消息, 具体可参见方法实施例中的说 明。 The request message may be a context request message or an identifier request message, as described in the method embodiment. Bright.
其中, 源侧移动性管理网元 61包括:  The source side mobility management network element 61 includes:
第一接收模块 41,用于接收由目标侧移动性管理网元 63发送的携带有指示信息请求消 息;  The first receiving module 41 is configured to receive the message carrying the indication information sent by the target-side mobility management network element 63.
第一发送模块 43,用于向目标侧移动性管理网元 63发送相应于所述指示信息的用户设 备的安全上下文。  The first sending module 43 is configured to send the security context of the user equipment corresponding to the indication information to the target side mobility management network element 63.
其中, 请求消息中的指示信息包括指示目标侧移动性管理网元 63的设备类型的信息或 者指示目标侧移动性管理网元 63需要获取的用户设备的安全上下文类型的信息。 因此, 第一发送模块 43包括:  The indication information in the request message includes information indicating the device type of the target side mobility management network element 63 or information indicating the security context type of the user equipment that the target side mobility management network element 63 needs to acquire. Therefore, the first sending module 43 includes:
第一发送单元, 用于当指示信息中指示目标侧移动性管理网元 63的设备类型为 SGSN 或者目标侧移动性管理网元 63 需要获取的用户设备的安全上下文类型为 GERAN/UTRAN 网络中的安全上下文时, 向目标侧移动性管理网元 63发送 GERAN/UTRAN网络中的安全 上下文;  a first sending unit, configured to indicate, in the indication information, that the device type of the target-side mobility management network element 63 is the SGSN or the target-side mobility management network element 63 needs to acquire the security context type of the user equipment in the GERAN/UTRAN network. In the security context, the security context in the GERAN/UTRAN network is sent to the target side mobility management network element 63;
第二发送单元, 用于当指示信息中指示目标侧移动性管理网元 63 的设备类型为 MME 或者目标侧移动性管理网元 63需要获取的用户设备的安全上下文类型为 E-UTRAN网络中 的安全上下文时, 向目标侧移动性管理网元 63发送 E-UTRAN网络中的安全上下文;  a second sending unit, configured to indicate, in the indication information, that the device type of the target-side mobility management network element 63 is the MME or the target-side mobility management network element 63 needs to acquire the security context type of the user equipment in the E-UTRAN network. In the security context, the security context in the E-UTRAN network is sent to the target side mobility management network element 63;
第三发送单元, 用于当指示信息中指示目标侧移动性管理网元 63 的设备类型为 MME 和 SGSN的合一设备或者目标侧移动性管理网元 63需要获取的用户设备的安全上下文类型 为 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文时, 向目标侧移动性管理网元 63 发送 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文。  The third sending unit is configured to: when the indication information indicates that the device type of the target side mobility management network element 63 is the MME and the SGSN, or the target side mobility management network element 63, the security context type of the user equipment that needs to be acquired is When the security context of the E-UTRAN network and the GERAN/UTRAN network, the security context of the E-UTRAN network and the GERAN/UTRAN network is transmitted to the target side mobility management network element 63.
目标侧移动性管理网元 63包括:  The target side mobility management network element 63 includes:
第二发送模块 51, 用于向源侧移动性管理网元 61发送携带有指示信息请求消息; 第二接收模块 53, 用于接收由源侧移动性管理网元 61发送的相应于所述指示信息的用 户设备的安全上下文。  The second sending module 51 is configured to send the indication information request message to the source side mobility management network element 61, and the second receiving module 53 is configured to receive the indication sent by the source side mobility management network element 61 corresponding to the indication. The security context of the user device of the information.
其中, 第二发送模块 51包括:  The second sending module 51 includes:
第一指示单元, 用于在所述请求消息中增加指示目标侧移动性管理网元 63的设备类型 的指示信息, 并向源侧移动性管理网元 61发送携带有所述指示信息的请求消息; 或  The first indication unit is configured to add indication information indicating a device type of the target side mobility management network element 63 to the request message, and send a request message carrying the indication information to the source side mobility management network element 61. ; or
第二指示单元, 用于在所述请求消息中增加指示目标侧移动性管理网元 63需要获取的 用户设备的安全上下文类型的指示信息, 并向源侧移动性管理网元 61发送携带有所述指示 信息的请求消息。  a second indication unit, configured to add, in the request message, indication information indicating a security context type of the user equipment that the target-side mobility management network element 63 needs to acquire, and send the information to the source-side mobility management network element 61 A request message indicating the information.
其中, 目标侧移动性管理网元 63 可以是 GERAN/UTRAN 网络中的 SGSN设备或者 SGSN与 MME的合一设备, 也可以是 E-UTRAN网络中的 MME设备或者 SGSN与 MME 的合一设备。 The target side mobility management network element 63 may be an SGSN device in the GERAN/UTRAN network or The unifying device of the SGSN and the MME may also be an MME device in the E-UTRAN network or a unified device of the SGSN and the MME.
本实施例中, 源侧移动性管理网元 61根据请求消息中的指示信息判断目标侧移动性管 理网元 63 的不同的设备类型或者根据目标侧移动性管理网元 63在请求消息中指示的所需 安全上下文的类型, 提供相应的安全上下文, 从而避免了目标侧移动性管理网元 63与 HSS 进行交互获取安全上下文的流程, 减少了与 HSS的交互负荷。 本发明实施例可以通过软件实现, 相应的软件可以存储在可读取的存储介质中, 例如 计算机的硬盘、 光盘或软盘中。  In this embodiment, the source side mobility management network element 61 determines different device types of the target side mobility management network element 63 according to the indication information in the request message or according to the target side mobility management network element 63 indicated in the request message. The type of security context required provides a corresponding security context, thereby avoiding the process of the target-side mobility management network element 63 interacting with the HSS to obtain a security context, and reducing the interaction load with the HSS. The embodiments of the present invention can be implemented by software, and the corresponding software can be stored in a readable storage medium, such as a hard disk, an optical disk or a floppy disk of a computer.
以上所述仅为本发明的较佳实施例, 并不用以限制本发明, 凡在本发明的精神和原则 之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。  The above is only the preferred embodiment of the present invention, and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., which are within the spirit and scope of the present invention, should be included in the protection of the present invention. Within the scope.

Claims

权 利 要 求 书 Claim
1.一种提供安全上下文的方法, 其特征在于, 所述方法包括:  A method for providing a security context, the method comprising:
接收由目标侧移动性管理网元发送携带指示信息的请求消息;  Receiving, by the target-side mobility management network element, a request message that carries the indication information;
向所述目标侧移动性管理网元发送相应于所述指示信息的用户设备的安全上下文。  And transmitting, to the target-side mobility management network element, a security context of the user equipment corresponding to the indication information.
2.根据权利要求 1 所述的提供安全上下文的方法, 其特征在于, 所述请求消息为上下文 请求消息或标识请求消息。 The method for providing a security context according to claim 1, wherein the request message is a context request message or an identification request message.
3.根据权利要求 1或 2所述的提供安全上下文的方法, 其特征在于, 所述请求消息中的 指示信息包括指示所述目标侧移动性管理网元的设备类型的信息或者指示所述目标侧移动性 管理网元需要获取的用户设备的安全上下文类型的信息。 The method for providing a security context according to claim 1 or 2, wherein the indication information in the request message includes information indicating a device type of the target-side mobility management network element or indicates the target The information about the security context type of the user equipment that the side mobility management network element needs to acquire.
4.根据权利要求 3 所述的提供安全上下文的方法, 其特征在于, 所述向所述目标侧移动 性管理网元发送相应于所述指示信息的用户设备的安全上下文包括: The method for providing a security context according to claim 3, wherein the transmitting the security context of the user equipment corresponding to the indication information to the target mobility management network element comprises:
当所述指示信息中指示目标侧移动性管理网元的设备类型为服务通用分组无线业务支持 节点(SGSN)或者所述目标侧移动性管理网元需要获取的用户设备的安全上下文的类型为无 线接入网 (GERAN) /通用移动通信系统陆地无线接入网 (UTRAN) 网络中的安全上下文时, 则向所述目标侧移动性管理网元发送 GERAN/UTRAN网络中的安全上下文;  When the device type indicating the target side mobility management network element in the indication information is the serving general packet radio service support node (SGSN) or the type of the security context of the user equipment that needs to be acquired by the target side mobility management network element is wireless When the security context in the access network (GERAN)/Universal Mobile Telecommunications System Terrestrial Radio Access Network (UTRAN) network is sent to the target side mobility management network element, the security context in the GERAN/UTRAN network is sent;
当所述指示信息中指示目标侧移动性管理网元的设备类型为移动性管理单元(MME)或 者所述目标侧移动性管理网元需要获取的用户设备的安全上下文类型为陆地无线接入网 (E-UTRAN) 网络中的安全上下文时, 则向所述目标侧移动性管理网元发送 E-UTRAN网络 中的安全上下文;  When the device type indicating that the target-side mobility management network element is the mobility management unit (MME) or the target-side mobility management network element needs to acquire the security context type of the user equipment is the terrestrial radio access network (E-UTRAN), when the security context in the network is sent, the security context in the E-UTRAN network is sent to the target-side mobility management network element;
当所述指示信息中指示目标侧移动性管理网元的设备类型为 MME和 SGSN的合一设备 或者所述目标侧移动性管理网元需要获取的用户设备的安全上下文类型为 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文时, 则向所述目标侧移动性管理网元发送 E-UTRAN网络 和 GERAN/UTRAN网络的安全上下文。  When the indication information indicates that the device type of the target-side mobility management network element is the MME and the SGSN, or the target-side mobility management network element needs to acquire the security context type of the user equipment, the E-UTRAN network and The security context of the GERAN/UTRAN network then transmits the security context of the E-UTRAN network and the GERAN/UTRAN network to the target-side mobility management network element.
5.如权利要求 1 所述的提供安全上下文的方法, 其特征在于, 所述安全上下文为安全参 数。 5. The method of providing a security context according to claim 1, wherein the security context is a security parameter.
6.—种移动性管理网元, 其特征在于, 所述移动性管理网元包括: 6. A mobility management network element, wherein the mobility management network element comprises:
第一接收模块(41 ), 用于接收由目标侧移动性管理网元发送的携带有指示信息的请求消 息;  a first receiving module (41), configured to receive a request message that is sent by the target side mobility management network element and carries the indication information;
第一发送模块(43 ), 用于向所述目标侧移动性管理网元发送相应于所述指示信息的用户 设备的安全上下文。  The first sending module (43) is configured to send, to the target-side mobility management network element, a security context of the user equipment corresponding to the indication information.
7.根据权利要求 6所述的移动性管理网元, 其特征在于, 所述第一发送模块 (43 ) 包括: 第一发送单元, 用于当所述指示信息中指示目标侧移动性管理网元的设备类型为服务通 用分组无线业务支持节点(SGSN)或者所述目标侧移动性管理网元需要获取的用户设备的安 全上下文类型为无线接入网 (GERAN) /通用移动通信系统陆地无线接入网 (UTRAN) 网络 中的安全上下文时, 向所述目标侧移动性管理网元发送 GERAN/UTRAN 网络中的安全上下 文; The mobility management network element according to claim 6, wherein the first sending module (43) comprises: a first sending unit, configured to indicate a target side mobility management network in the indication information The device type of the service is the serving general packet radio service support node (SGSN) or the security context type of the user equipment that the target side mobility management network element needs to acquire is the radio access network (GERAN) / universal mobile communication system terrestrial wireless connection Transmitting a security context in the GERAN/UTRAN network to the target-side mobility management network element when a security context in the network (UTRAN) network is used;
第二发送单元, 用于当所述指示信息中指示目标侧移动性管理网元的设备类型为移动性 管理单元(MME)或者所述目标侧移动性管理网元需要获取的用户设备的安全上下文类型为 陆地无线接入网 (E-UTRAN) 网络中的安全上下文时, 向所述目标侧移动性管理网元发送 E-UTRAN网络中的安全上下文;  a second sending unit, configured to: when the device type indicating the target-side mobility management network element in the indication information is a mobility management unit (MME) or a security context of the user equipment that needs to be acquired by the target-side mobility management network element When the type is a security context in a terrestrial radio access network (E-UTRAN) network, the security context in the E-UTRAN network is sent to the target side mobility management network element;
第三发送单元, 用于当所述指示信息中指示目标侧移动性管理网元的设备类型为 MME 和 SGSN的合一设备或者所述目标侧移动性管理网元需要获取的用户设备的安全上下文类型 为 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文时,向所述目标侧移动性管理网元发 送 E-UTRAN网络和 GERAN/UTRAN网络的安全上下文。  a third sending unit, configured to: when the indication information indicates that the device type of the target-side mobility management network element is a unified device of the MME and the SGSN, or the security context of the user equipment that the target-side mobility management network element needs to acquire When the security context of the E-UTRAN network and the GERAN/UTRAN network is of type, the security context of the E-UTRAN network and the GERAN/UTRAN network is transmitted to the target-side mobility management network element.
8.—种移动性管理网元, 其特征在于, 所述移动性管理网元包括: 8. A mobility management network element, wherein the mobility management network element comprises:
第二发送模块 (51 ), 用于向源侧移动性管理网元发送携带有指示信息的请求消息; 第二接收模块(53 ), 用于接收由所述源侧移动性管理网元发送的相应于所述指示信息的 用户设备的安全上下文。  a second sending module (51), configured to send a request message carrying the indication information to the source-side mobility management network element, where the second receiving module (53) is configured to receive the source-side mobility management network element Corresponding to the security context of the user equipment of the indication information.
9.根据权利要求 8所述的移动性管理网元, 其特征在于, 所述第二发送模块 (51 ) 包括: 第一指示单元, 用于在所述请求消息中增加指示目标侧移动性管理网元的设备类型的指 示信息, 并向所述源侧移动性管理网元发送携带有所述指示信息的请求消息; The mobility management network element according to claim 8, wherein the second sending module (51) comprises: a first indication unit, configured to add a target side mobility management to the request message And indicating, by the device type of the network element, a request message carrying the indication information to the source side mobility management network element;
或 第二指示单元, 用于在所述请求消息中增加指示目标侧移动性管理网元需要获取的用户 设备的安全上下文类型的指示信息, 并向所述源侧移动性管理网元发送携带有所述指示信息 的请求消息。 Or a second indicating unit, configured to add, in the request message, indication information indicating a security context type of the user equipment that the target side mobility management network element needs to acquire, and send the carrying information to the source side mobility management network element A request message indicating the information.
10.—种移动通信系统, 其特征在于, 所述系统包括: 源侧移动性管理网元 (61 ) 和目标 侧移动性管理网元 (63 ); 10. A mobile communication system, the system comprising: a source side mobility management network element (61) and a target side mobility management network element (63);
所述源侧移动性管理网元(61 ), 用于接收由所述目标侧移动性管理网元(63 )发送的携 带有指示信息的请求消息, 向所述目标侧移动性管理网元 (63 ) 发送相应于所述指示信息的 用户设备的安全上下文;  The source-side mobility management network element (61) is configured to receive a request message that is sent by the target-side mobility management network element (63) and that carries the indication information, to the target-side mobility management network element ( 63) transmitting a security context of the user equipment corresponding to the indication information;
所述目标侧移动性管理网元(63 ), 用于向所述源侧移动性管理网元(61 )发送携带有指 示信息的请求消息, 并接收所述源侧移动性管理网元 (61 ) 发送的相应于所述指示信息的用 户设备的安全上下文。  The target-side mobility management network element (63) is configured to send a request message carrying the indication information to the source-side mobility management network element (61), and receive the source-side mobility management network element (61) a security context sent by the user equipment corresponding to the indication information.
11.根据权利要求 10所述的移动通信系统,其特征在于,所述目标侧移动性管理网元(63 ) 包括: The mobile communication system according to claim 10, wherein the target-side mobility management network element (63) comprises:
第二发送模块, 用于向所述源侧移动性管理网元(61 )发送携带有指示信息的请求消息; 第二接收模块, 用于接收由所述源侧移动性管理网元 (61 ) 发送的相应于所述指示信息 的用户设备的安全上下文。  a second sending module, configured to send a request message carrying the indication information to the source-side mobility management network element (61), and a second receiving module, configured to receive, by the source-side mobility management network element (61) The security context of the user equipment corresponding to the indication information sent.
12.根据权利要求 11所述的移动通信系统, 其特征在于, 所述第二发送模块包括: 第一指示单元, 用于在所述请求消息中增加指示所述目标侧移动性管理网元 (63 ) 的设 备类型的指示信息, 并向所述源侧移动性管理网元 (61 ) 发送携带有所述指示信息的请求消 息; The mobile communication system according to claim 11, wherein the second sending module comprises: a first indicating unit, configured to add, in the request message, the target side mobility management network element ( 63) indicating the device type, and transmitting, to the source-side mobility management network element (61), a request message carrying the indication information;
 Or
第二指示单元, 用于在所述请求消息中增加指示所述目标侧移动性管理网元 (63 ) 需要 获取的用户设备的安全上下文类型的指示信息, 并向所述源侧移动性管理网元 (61 ) 发送携 带有所述指示信息的请求消息。  a second indication unit, configured to add, in the request message, indication information indicating a security context type of the user equipment that the target-side mobility management network element (63) needs to acquire, and to the source-side mobility management network The element (61) transmits a request message carrying the indication information.
PCT/CN2009/071822 2008-05-30 2009-05-15 Method, mobility management network element and mobile communication system for providing security context, WO2009143745A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200810114117.7 2008-05-30
CN2008101141177A CN101594608B (en) 2008-05-30 2008-05-30 Method for providing security context, mobile management network element and mobile communication system

Publications (1)

Publication Number Publication Date
WO2009143745A1 true WO2009143745A1 (en) 2009-12-03

Family

ID=41376599

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/071822 WO2009143745A1 (en) 2008-05-30 2009-05-15 Method, mobility management network element and mobile communication system for providing security context,

Country Status (2)

Country Link
CN (1) CN101594608B (en)
WO (1) WO2009143745A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107567018A (en) * 2016-07-01 2018-01-09 中兴通讯股份有限公司 Message treatment method and device, terminal, message handling system

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102348201B (en) * 2010-08-05 2014-02-19 华为技术有限公司 Method and device for acquiring security context
CN102754460B (en) * 2010-08-20 2015-12-16 华为技术有限公司 The indicating means of information and mobile management net element
CN102076085B (en) * 2011-01-19 2017-12-19 中兴通讯股份有限公司 A kind of method and system for obtaining position information of user's terminal
CN102883297B (en) * 2011-07-12 2017-09-12 中兴通讯股份有限公司 A kind of method and system of activated terminals
CN103118415B (en) * 2011-11-16 2016-06-29 华为终端有限公司 The processing method of a kind of service request and device
WO2015061951A1 (en) * 2013-10-28 2015-05-07 华为技术有限公司 Method and device for providing and acquiring security context
CN105228124B (en) * 2014-06-24 2021-04-06 中兴通讯股份有限公司 Method for processing ProSe service authorization change, first network element and second network element
CN107809776B (en) * 2016-09-09 2021-06-15 中兴通讯股份有限公司 Information processing method, device and network system
WO2022148469A1 (en) * 2021-01-11 2022-07-14 华为技术有限公司 Security protection method, apparatus and system

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1567757A (en) * 2003-06-13 2005-01-19 北京三星通信技术研究有限公司 Method for updating route area using UE of MBMS service in communication system
CN1697394A (en) * 2004-05-12 2005-11-16 华为技术有限公司 Method for updating routing area in operation of multimedia broadcast/multicast service
CN1997212A (en) * 2006-01-05 2007-07-11 华为技术有限公司 Method for location update in the wireless communication network
US20070213057A1 (en) * 2006-03-08 2007-09-13 Interdigital Technology Corporation Method and apparatus for supporting routing area update procedures in a single tunnel gprs-based wireless communication system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1567757A (en) * 2003-06-13 2005-01-19 北京三星通信技术研究有限公司 Method for updating route area using UE of MBMS service in communication system
CN1697394A (en) * 2004-05-12 2005-11-16 华为技术有限公司 Method for updating routing area in operation of multimedia broadcast/multicast service
CN1997212A (en) * 2006-01-05 2007-07-11 华为技术有限公司 Method for location update in the wireless communication network
US20070213057A1 (en) * 2006-03-08 2007-09-13 Interdigital Technology Corporation Method and apparatus for supporting routing area update procedures in a single tunnel gprs-based wireless communication system

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107567018A (en) * 2016-07-01 2018-01-09 中兴通讯股份有限公司 Message treatment method and device, terminal, message handling system

Also Published As

Publication number Publication date
CN101594608B (en) 2012-08-22
CN101594608A (en) 2009-12-02

Similar Documents

Publication Publication Date Title
WO2009143745A1 (en) Method, mobility management network element and mobile communication system for providing security context,
EP2870826B1 (en) Adding service set identifier or access point name to wlan to cellular signalling messages
EP2858418B1 (en) Method for updating identity information about packet gateway, aaa server and packet gateway
US10104603B2 (en) Apparatus, system and method for dedicated core network
US20110164566A1 (en) Method, Apparatus and System for Enabling to Release PDN Connections
WO2010012174A1 (en) Management method, device and system for user to access network
WO2011054299A1 (en) Method and system for obtaining information of machine type communication terminal
WO2014032570A1 (en) Method, user equipment and remote management platform for switching operator network
EP2480022B1 (en) Bearer processing method and mobile management device
WO2008138259A1 (en) Method and system and device for registering process .
WO2010015133A1 (en) Deleting method for session information in dra
WO2011157055A1 (en) Method and device for machine type communication monitoring processing
WO2011153750A1 (en) Method and system for synchronizing user data
WO2010048834A1 (en) Method for updating radio capability, equipment and system thereof
US20130094487A1 (en) Method and System for Information Transmission
WO2009117879A1 (en) Method for indicating the bearer management of the service gateway
WO2013060225A1 (en) System and method for acquiring user location through user bearer identifier
WO2011157189A2 (en) Method, device and system for reporting location
WO2010015170A1 (en) Processing method, system and apparatus for mobility management
WO2018113536A1 (en) Method and system for achieving multi-device connected communication
WO2010139285A1 (en) Information synchronization method, communication system and devices thereof
CN101166296A (en) A reattach method, system and user device
WO2009097730A1 (en) A method for deleting mobility management entity's information and device thereof
EP3086580B1 (en) Accessibility management method and device for m2m terminal/terminal peripheral
WO2009076814A1 (en) An updating method and device for pcc rule

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09753463

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09753463

Country of ref document: EP

Kind code of ref document: A1