WO2010012177A1 - 一种确定漫游用户终端移动性的方法及装置 - Google Patents

一种确定漫游用户终端移动性的方法及装置 Download PDF

Info

Publication number
WO2010012177A1
WO2010012177A1 PCT/CN2009/072075 CN2009072075W WO2010012177A1 WO 2010012177 A1 WO2010012177 A1 WO 2010012177A1 CN 2009072075 W CN2009072075 W CN 2009072075W WO 2010012177 A1 WO2010012177 A1 WO 2010012177A1
Authority
WO
WIPO (PCT)
Prior art keywords
access
terminal
network
mobility
classification attribute
Prior art date
Application number
PCT/CN2009/072075
Other languages
English (en)
French (fr)
Inventor
李波杰
卢磊
梁文亮
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP09802370.8A priority Critical patent/EP2217025B1/en
Publication of WO2010012177A1 publication Critical patent/WO2010012177A1/zh
Priority to US12/774,989 priority patent/US8467783B2/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/02Access restriction performed under specific conditions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security

Definitions

  • the present invention belongs to the field of communications technologies, and in particular, to a method and apparatus for determining mobility of a roaming user terminal. Background technique
  • WiMAX Worldwide Interoperabi lity for Microwave Access
  • WiMAX is a wireless metropolitan area network technology based on the IEEE 802.16 standard.
  • the wireless side of the WiMAX network is a wireless metropolitan area network access technology based on the IEEE802.16d/e standard, which employs OFDM (Orthogonal Frequency Division Multiplexing) and OFDM (OFDM) physics.
  • Layer technology effective against multipath fading. In the case of optimal channel fading, the transmission rate can approach 75 Mbps.
  • the entire WiMAX network consists of the following three parts:
  • Terminal It is an SS (Subscriber Station) or an MS (Mobile Station). The user uses the terminal to access the WiMAX network.
  • ASN is defined as a set of network functions that provide wireless access services for WiMAX terminals.
  • the ASN includes BS (Base Station) and ASN-GW (ASN Gateway) network elements.
  • the main functions of the BS network element are: providing L2 connection between the BS and the terminal, radio resource management, and the like; the main functions of the ASN-GW network element are: providing client functions for terminal authentication, authorization, and accounting functions, and providing the terminal with Relay function of L3 information (such as IP address allocation), switching within ASN, etc.
  • CSN Connectivity Service Network
  • WiMAX terminals provide IP connectivity services.
  • the CSN mainly includes a prepaid server and a logical entity such as an authentication, authorization, and accounting (AAA, Authentication. Authorization and Accounting).
  • AAA authentication, authorization, and accounting
  • the main functions provided are: IP address allocation of the terminal, Internet access, and AM proxy ( Proxy) or server (server), terminal-based authorization control, etc.
  • the mobility classification attribute is added to the user's subscription relationship, including: fixed, nomadic and mobile.
  • the mobile service refers to that the terminal can continuously use the data service of the network when the terminal moves at a certain speed within the coverage of the network side, and the network side supports the handover of the terminal, and ensures the continuity of the session during the handover process;
  • the terminal can access the network in different geographical locations.
  • the terminal is generally fixedly attached to an access network.
  • the nomadic service user terminal can initiate the re-attachment of the device, but does not necessarily need to ensure the continuity of the session;
  • the fixed service refers to the terminal can only access the network in a fixed area, perform data services, when leaving the When the area is fixed, you cannot access the network.
  • the inventor has found that, in the prior art, after the mobile user terminal roams to the mobility-restricted visited network, or after roaming from the mobility-limited network to the mobility-unrestricted network, for example, the mobile user terminal roams to only support. After the network of the fixed or nomadic user, or when the nomadic network user terminal roams to the mobile unrestricted network, the mobility type of the roaming user terminal cannot be determined, and the roaming user terminal may not be able to access the mobility restriction network, or Restricted network user terminals cannot access networks with unlimited mobility. Summary of the invention
  • the embodiment of the invention discloses a method and a device for determining the mobility of a roaming user terminal, so as to determine a mobility restriction type of the user terminal after the user terminal roams.
  • a method for determining mobility of a roaming user includes: The visited network AAA server receives the access permission message sent by the home network AAA server; determines the mobile classification attribute of the terminal according to the mobility restriction policy of the visited network connection service network CSN, and sends the access permission to the visited access service network authenticator.
  • the message, the access permission message carries a mobile classification attribute of the terminal.
  • a method for determining mobility of a roaming user includes:
  • the visited access service network authenticator receives the access permission message sent by the visited network AAA server, determines the mobile classification attribute of the terminal according to the mobility restriction policy of the visited access service network, and sends the mobile classification attribute of the terminal. To the base station.
  • a method for determining mobility of a roaming user comprising:
  • the home network AAA server receives an access request message from the visited network AAA server, where the access request message carries a mobility restriction policy of the visited access service network;
  • An AAA server including:
  • the receiving module is configured to receive an access permission message sent by the home network AAA server;
  • Determining a module determining a mobile classification attribute of the terminal according to a mobility restriction policy of the visited service network;
  • a sending module configured to send an access permission message to the visited access network service authenticator, where the access permission message carries a mobile classification attribute of the terminal, or carries a mobile classification attribute and a mobile of the terminal Limit related parameters.
  • An authenticator comprising:
  • the receiving module is configured to receive an access permission message sent by the visited network AAA server;
  • Determining a module determining a mobile classification attribute of the terminal according to a mobility restriction policy of the visited access service network;
  • the sending module is configured to send, to the base station, a mobile classification attribute of the terminal, or a mobile classification attribute and a mobility restriction related parameter of the terminal.
  • An AAA server including:
  • the receiving module is configured to receive an access request message from the visited network AAA server, where the access request message carries a mobility restriction policy of the visited access service network;
  • Determining module determining a mobile classification attribute of the terminal according to a mobility restriction policy of the visited access service network
  • the sending module is configured to send an access permission message to the visited network AAA server, where the access permission message carries the mobile classification attribute of the terminal, or carries the mobile classification attribute and the mobility restriction related parameter of the terminal.
  • the method and device for determining mobility of a roaming user terminal disclosed in the embodiment of the present invention after the user terminal roams to a mobility-limited visited network, or after the user terminal roams from a mobility-limited network to a network with unlimited mobility
  • the type of mobility restriction of the user terminal can be determined in time, and the mobility restriction information of the user terminal can be obtained by visiting the network.
  • FIG. 1 is a flowchart of a method for determining mobility of a roaming user terminal according to Embodiment 1 of the present invention
  • FIG. 2 is a flowchart of a method for determining mobility of a roaming user terminal according to Embodiment 2 of the present invention
  • FIG. 3 is determined according to Embodiment 3 of the present invention
  • FIG. 4 is a schematic diagram of an apparatus for determining mobility of a roaming user terminal according to an embodiment of the present invention. detailed description
  • the embodiment of the invention provides a method and a device for determining the mobility of a roaming user terminal, so as to determine a mobility restriction type of the user terminal after the user terminal roams, and the mobility restriction information of the user terminal can be obtained by the visited network; further, Smooth access to the user terminal.
  • Embodiment 1
  • the mobile network authentication and authorization charging server V-AAA determines the mobile classification attribute of the terminal MS/SS
  • a method for determining mobility of a roaming user terminal according to Embodiment 1 of the present invention includes:
  • the V-AAA sends the access request (Access-Request) message in step 202 to the home network AAA server H-AAA.
  • H-AAA allows the MS to access, send an Access-Accept message carrying the successful access indication to the V-AAA.
  • the V-AAA determines the mobile classification attribute of the MS according to the mobility restriction policy of the visited service network CSN, and carries the mobile classification attribute of the MS in an Access-Accept message to the Authenticator.
  • the Access-Accept message may further carry a mobility restriction related parameter of the MS;
  • the mobility restriction policy is saved in the visited access service network Authenticator, including: What kind of mobile classified users are supported by the visited access service network, for example: mobile, nomadic or fixed; the mobile mobility restriction related parameters of the MS and the MS Corresponding to the classification attribute, mainly for fixed or nomadic users, may include at least one of the following: allowed access area, re-attachment area limit, support session Continuity, etc.
  • the Authenticator sends an authentication relay EAP (AuthRelay-EAP-Transfer) message to the BS, where the message carries the mobile classification attribute of the MS, and may also carry the mobility restriction related parameter of the MS;
  • EAP authentication relay EAP
  • the Authenticator sends a terminal attach response (MS_Attachment-Rsp) message to the BS, where the message carries the mobile classification attribute of the MS, and may also carry the mobility restriction related parameter of the MS.
  • Steps 206 and 207 may be optional. Transmitting, by the message, the mobile classification attribute carrying the MS and the mobile restriction related parameter of the MS to the visited access service network BS;
  • the visited access service network BS knows the mobile classification attribute of the MS and the mobility restriction related parameters, and the terminal can perform the subsequent network access process.
  • the mobile classification attribute of the MS and the corresponding mobility restriction information are directly determined by the visited V-AAA, and are sent to the ASN.
  • Embodiment 2 :
  • the visited network Authenticator determines the mobile classification attribute of the MS
  • the flowchart of the method in the embodiment of the present invention is similar to that in the first embodiment. Referring to FIG. 2, the method includes:
  • the MS performs an initial network interaction process; similar to step 201;
  • V-AAA Access Request (Access-Request) message
  • the V-AAA sends the access request (Access-Request) message in step 302 to the H-AAA.
  • the V-AM sends an Access-Accept message received in step 304 to the Authen ticator.
  • the Authenticator determines the MS according to the mobility restriction policy of the visited access service network. Moving the classification attribute, and sending an AuthRelay-EAP-Transfer message to the BS, where the message carries the mobile classification attribute of the MS, and may also carry the mobility restriction related parameter of the MS;
  • the Authenticator sends a terminal attach response (MS_Attachment-Rsp) message to the BS, where the message carries the mobile classification attribute of the MS, and may also carry the mobility restriction related parameter of the MS; the mobility restriction policy is accessed at the visited place.
  • the service network is stored in the Authenticator, including: What kind of mobile classified users are supported by the visited access service network, for example: mobile, nomadic or fixed; the mobile mobility restriction related parameters of the MS correspond to the classified attributes of the MS, mainly for fixed or For nomadic users, at least one of the following may be included: an area that is allowed to access, a reattachment area limit, whether to support session continuity, and the like.
  • the visited access service network BS knows the mobile classification attribute of the MS and the mobility restriction related parameters, and the terminal can perform the subsequent network access process.
  • the mobile classification attribute of the MS and the corresponding mobility restriction information are determined by the visited ASN, and are sent to the BS.
  • the H-AAA server determines the mobile classification attribute of the MS
  • the method includes:
  • the access network Authenticator sends an access request (Access-Request) message to the visited network AAA server V-AAA, where the access request message carries the mobility restriction policy of the visited access service network, and may also carry the Describe the mobility limit related parameters of the MS;
  • the mobility restriction policy is stored in the visited access service network Authenticator, including: What kind of mobile classified users are supported by the visited access service network, for example: mobile, nomadic or fixed;
  • the mobile mobility restriction related parameter of the MS corresponds to the classification attribute of the MS, and is mainly for the fixed or nomadic user, and may include at least one of the following: an access allowed area, a reattachment area restriction, a session continuity, and the like;
  • the V-AAA receives the Access-Request message, and forwards the Access-Request message to the H-AAA.
  • the H-AAA determines the mobile classification attribute of the MS according to the mobility restriction policy of the visited access service network carried in the received Access-Request message, for example: whether it is a fixed user or a nomadic User; and the mobile classification attribute of the MS is included in the Access-Accept message and sent to V-AAA;
  • the Access-Accept message may further carry the mobility restriction related parameter of the MS; for example, the related parameters of the fixed or nomadic user, including the following at least One: the area allowed to access, the reattachment area restriction, whether to support session continuity, etc.;
  • the V-AAA receives the Access_Acc print message, and forwards the Access_Acc print message to the Authenticator.
  • the Authenticator sends an AuthRelay-EAP_Transfer message to the BS, where the message carries the mobile classification attribute of the MS, and further carries the mobility restriction related parameter of the MS.
  • the Authenticator sends an MS_Attachment-Rsp message to the BS, where the message carries the mobile classification attribute of the MS, and may also carry the mobility restriction related parameter of the MS.
  • the network mobility restriction is reported to the V-AAA by the visited ASN, and the V-AAA forwards it to the H-AAA, and the H-AAA determines the mobility of the MS according to the capability of the visited network.
  • the classification attribute and the corresponding mobility restriction information are sent to the visited network.
  • the embodiment of the present invention further provides an AAA server.
  • the method includes:
  • the receiving module is configured to receive an access permission message sent by the home network AAA server; Determining a module: determining a mobile classification attribute of the terminal according to a mobility restriction policy of the visited service network;
  • a sending module configured to send an access permission message to the visited access network service authenticator, where the access permission message carries a mobile classification attribute of the terminal, or carries a mobile classification attribute and a mobile of the terminal Limit related parameters.
  • an embodiment of the present invention further discloses an authenticator. Referring to FIG. 4, the method includes:
  • the receiving module is configured to receive an access permission message sent by the visited network AAA server;
  • Determining a module determining a mobile classification attribute of the terminal according to a mobility restriction policy of the visited service network;
  • the sending module is configured to send, to the base station, a mobile classification attribute of the terminal, or a mobile classification attribute and a mobility restriction related parameter of the terminal.
  • the embodiment of the present invention further discloses an AAA server.
  • the method includes:
  • the receiving module is configured to receive an access request message sent by the V-AAA, where the access request message carries a mobility restriction policy of the visited access service network;
  • Determining module determining a mobile classification attribute of the terminal according to a mobility restriction policy of the visited access service network
  • the sending module is configured to send an access permission message to the V-AAA, where the access permission message carries the mobile classification attribute of the terminal, or carries the mobile classification attribute and the mobility restriction related parameter of the terminal.
  • the mobility restriction type of the user terminal can be determined in time, and the mobility restriction information of the user terminal can be obtained by visiting the network base station; further, the network access of the user terminal can be smoothly implemented, and the mobile range of the roaming user terminal can be restricted after the network is accessed.
  • the technical solution of the present invention which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a readable storage medium, such as a floppy disk of a computer.
  • a hard disk or optical disk or the like includes instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to perform the methods described in various embodiments of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

一种确定漫游用户终端移动性的方法及装置 本申请要求 2008年 07月 29日提交中国专利局、 申请号为 200810142559. 2、 发明名称为 "一种确定漫游用户终端移动性的方法及装置" 的中国专利申请的 优先权, 其全部内容通过引用结合在本申请中。 技术领域
本发明属于通信技术领域, 尤其涉及一种确定漫游用户终端移动性的方法 及装置。 背景技术
WiMAX (Worldwide Interoperabi lity for Microwave Access , 全球接入 微波互操作性) 是一种基于 IEEE802. 16标准的无线城域网技术。 WiMAX网络无线 侧是基于 IEEE802. 16d/e标准的无线城域网接入技术, 采用 OFDM (Orthogonal Frequency Division Multiplexing, 正交频分复用技术)禾卩 0FDMA (OFDM Access, OFDM接入) 的物理层技术, 能有效的抗多径衰落。 最佳信道衰落情况下, 传输 速率可以逼近 75Mbps。
WiMAX整个网络主要由以下三部分组成:
( 1 )终端: 为 SS (Subscriber Station, 用户台)或 MS (Mobile Station, 移动台) , 用户使用该终端接入 WiMAX网络。
(2 ) 接入业务网 (ASN, Access Service Network) : ASN定义为 WiMAX终 端提供无线接入服务的网络功能集合。 ASN包含了 BS (Base Station, 基站) 和 ASN-GW (ASN Gateway, ASN网关) 网元。 其中 BS网元的主要功能为: 提供 BS 和终端的 L2连接、无线资源管理等等; ASN-GW网元的主要功能为:为终端认证、 授权和计费功能提供客户端功能, 为终端提供 L3信息的 Relay功能 (如 IP地 址分配) 、 ASN内切换等。
(3 ) 连接业务网 (CSN, Connectivity Service Network) : CSN定义为 WiMAX终端提供 IP连接服务。 CSN主要包括预付费服务器以及认证、 授权和计 费 (AAA, Authentication. Authorization and Accounting)月艮务器等逻辑实体, 所提供的主要功能为: 终端的 IP地址分配、 Internet接入、 AM代理 (proxy) 或者服务器 (server ) 、 基于终端的授权控制等。
为了实现终端的移动性限制, 在用户的签约关系中增加移动性分类属性, 包括: 固定, 游牧以及移动。 其中, 移动业务指的是终端在网络侧覆盖范围内 以一定速度移动时, 能够连续使用网络的数据业务, 网络侧支持终端的切换, 并且在切换过程中, 保证会话的连续性; 游牧业务指的是终端可以在不同的地 理位置接入网络, 在数据业务的会话过程中, 终端一般固定地附着在某个接入 网, 当终端移动到新的位置时, 需要重新接入网络, 进行新的数据业务会话, 因此, 游牧业务用户终端可以发起设备的重附着, 但不一定需要保证会话的连 续性; 固定业务指的是终端只能在固定区域接入网络, 进行数据业务, 当离开 该固定区域时, 则不能接入网络。
对于一些国家的某些运营商, 由于牌照的限制, 只能运营固定或游牧网络 业务, 因此, 对于固定和游牧的用户, 要求限制其终端的移动性。
发明人发现, 现有技术中, 移动用户终端漫游到移动性受限的拜访网络后, 或者, 从移动性受限网络漫游到移动性不受限制的网络后, 例如移动用户终端 漫游到只支持固定或游牧用户的网络后, 或者, 当游牧网络用户终端漫游到移 动不受限制网络后, 无法确定漫游用户终端的移动性类型, 进一步可能无法实 现漫游用户终端接入移动性限制网络, 或者, 限制性网络用户终端无法接入移 动性不受限制的网络。 发明内容
本发明实施例公开了一种确定漫游用户终端移动性的方法及装置, 以实现 用户终端漫游后, 确定用户终端的移动性限制类型。
本发明实施例采取技术方案为:
一种确定漫游用户移动性的方法, 包括: 拜访网络 AAA服务器接收家乡网络 AAA服务器发送的接入允许消息; 根据拜访网络连接业务网络 CSN 的移动性限制策略确定终端的移动分类属 性, 并向拜访地接入业务网络鉴权器发送接入允许消息, 所述接入允许消息中 携带有所述终端的移动分类属性。
一种确定漫游用户移动性的方法, 包括:
拜访地接入业务网络鉴权器接收拜访网络 AAA服务器发送的接入允许消息, 根据拜访地接入业务网络的移动性限制策略确定终端的移动分类属性, 并 将所述终端的移动分类属性发送给基站。
一种确定漫游用户移动性的方法, 其特征在于, 包括:
家乡网络 AAA服务器接收来自拜访网络 AAA服务器的接入请求消息, 所述 接入请求消息中携带有拜访地接入业务网络的移动性限制策略;
根据拜访地接入业务网络的移动性限制策略确定终端的移动分类属性; 向拜访网络 AAA服务器发送接入允许消息, 所述接入允许消息中携带有所 述终端的移动分类属性, 或携带有所述终端的移动分类属性和移动限制相关参 数。
一种 AAA服务器, 包括:
接收模块: 用于接收家乡网络 AAA服务器发送的接入允许消息;
确定模块: 根据拜访地连接业务网络的移动性限制策略确定终端的移动分 类属性;
发送模块: 用于向拜访地接入业务网络鉴权器发送接入允许消息, 所述接 入允许消息中携带有所述终端的移动分类属性, 或携带有所述终端的移动分类 属性和移动限制相关参数。
一种鉴权器, 包括:
接收模块: 用于接收拜访网络 AAA服务器发送的接入允许消息;
确定模块: 根据拜访地接入业务网络的移动性限制策略确定终端的移动分 类属性; 发送模块: 用于将所述终端的移动分类属性, 或所述终端的移动分类属性 和移动限制相关参数发送给基站。
一种 AAA服务器, 包括:
接收模块: 用于接收来自拜访网络 AAA服务器的接入请求消息, 所述接入 请求消息中携带有拜访地接入业务网络的移动性限制策略;
确定模块: 用于根据拜访地接入业务网络的移动性限制策略确定终端的移 动分类属性;
发送模块: 用于向拜访网络 AAA服务器发送接入允许消息, 所述接入允许 消息中携带有所述终端的移动分类属性, 或携带有所述终端的移动分类属性和 移动限制相关参数。
本发明实施例公开的确定漫游用户终端移动性的方法及装置, 用户终端漫 游到移动性受限的拜访网络后, 或者, 用户终端从移动性受限网络漫游到移动 性不受限制的网络后, 可以及时确定用户终端的移动性限制类型, 拜访网络可 获知用户终端的移动性限制信息。 附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实施 例描述中所需要使用的附图作简单地介绍, 显而易见地, 下面描述中的附图仅 仅是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳 动性的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明实施例一中确定漫游用户终端移动性的方法流程图; 图 2为本发明实施例二中确定漫游用户终端移动性的方法流程图; 图 3为本发明实施例三中确定漫游用户终端移动性的方法流程图; 图 4为本发明实施例确定漫游用户终端移动性的装置示意图。 具体实施方式
下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案进行清 楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实施例, 而不是 全部的实施例。 基于本发明中的实施例, 本领域普通技术人员在没有作出创造 性劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。
本发明实施例提供了一种确定漫游用户终端移动性的方法及装置, 以实现 用户终端漫游后, 确定用户终端的移动性限制类型, 拜访网络可获知用户终端 的移动性限制信息; 进一步的, 顺利实现用户终端的入网。 实施例一
本实施例中, 由拜访网络认证授权计费服务器 V-AAA决定终端 MS/SS的移 动分类属性;
参考图 1, 本发明实施例一所述的确定漫游用户终端移动性的方法包括:
201、 MS移动到拜访网络后,发起初始入网交互过程,该步骤属于现有技术, 不再赘述;
202、 拜访网络鉴权器 (Authenticator ) 向拜访网络认证授权计费服务器 V-AAA发送接入请求 (Access-Request ) 消息;
203、 V-AAA将步骤 202中的接入请求 (Access-Request ) 消息发送到家乡 网络 AAA服务器 H-AAA;
204、 如果 H-AAA允许 MS接入, 则发送携带成功接入指示的接入允许(Access -Accept ) 消息到 V-AAA;
205、 V-AAA根据拜访地连接业务网络 CSN的移动性限制策略决定 MS的移动 分类属性, 并将该 MS 的移动分类属性携带在接入允许 (Access-Accept ) 消息 中下发到 Authenticator;
所述 Access-Accept消息中还可携带 MS的移动限制相关参数;
移动性限制策略在拜访地接入业务网络 Authenticator 中保存, 包括: 拜 访地接入业务网络支持什么样的移动分类用户, 例如: 移动、 游牧或固定; 所 述 MS的移动限制相关参数与 MS的分类属性对应, 主要是针对固定或游牧用户 而言, 可包括以下至少一项: 允许接入的区域、 重附着区限制、 是否支持会话 连续性等;
206、 Authenticator向 BS发送鉴权中继 EAP传递(AuthRelay— EAP— Transfer) 消息, 所述消息中携带 MS的移动分类属性, 另外, 还可携带 MS的移动限制相 关参数;
或者
207、 Authenticator向 BS发送终端附着响应(MS— Attachment— Rsp)消息, 所述消息中携带 MS的移动分类属性, 另外, 还可携带 MS的移动限制相关参数; 步骤 206和 207可任选一个, 将所述消息中携带 MS的移动分类属性以及 MS 的移动限制相关参数发送到拜访地接入业务网络 BS即可;
拜访地接入业务网络 BS获知了 MS的移动分类属性以及移动限制相关参数, 终端便可进行后续的入网过程。
本实施例中是由拜访地 V-AAA直接决定 MS的移动分类属性及相应的移动性 限制信息, 并下发到 ASN。 实施例二:
本实施例中, 拜访网络 Authenticator决定 MS的移动分类属性;
本发明实施例所述的方法流程图与实施例一类似, 参考图 2, 包括:
301、 MS进行初始入网交互过程; 与步骤 201类似;
302、 拜访网络 Authenticator向发送 V-AAA接入请求 (Access-Request ) 消息;
303、 V-AAA将步骤 302中的接入请求 (Access-Request ) 消息发送到 H-AAA;
304、 如果 H-AAA允许 MS接入, 则发送携带成功接入指示的接入允许 (Access-Accept ) 消息到 V- AAA;
305、 V-AM将步骤 304收到的接入允许 (Access-Accept ) 消息发送 Authen ticator;
306、 Authenticator根据拜访地接入业务网络的移动性限制策略决定 MS的 移动分类属性, 并向 BS发送鉴权中继 EAP传递 (AuthRelay—EAP— Transfer) 消 息, 所述消息中携带 MS的移动分类属性, 另外, 还可携带 MS的移动限制相关 参数;
或者
307、 Authenticator向 BS发送终端附着响应(MS— Attachment— Rsp)消息, 所述消息中携带 MS的移动分类属性, 另外, 还可携带 MS的移动限制相关参数; 移动性限制策略在拜访地接入业务网络 Authenticator 中保存, 包括: 拜 访地接入业务网络支持什么样的移动分类用户, 例如: 移动、 游牧或固定; 所 述 MS的移动限制相关参数与 MS的分类属性对应, 主要是针对固定或游牧用户 而言, 可包括以下至少一项: 允许接入的区域、 重附着区限制、 是否支持会话 连续性等。
拜访地接入业务网络 BS获知了 MS的移动分类属性以及移动限制相关参数, 终端便可进行后续的入网过程。
本实施例中是由拜访地 ASN决定 MS的移动分类属性及相应的移动性限制信 息, 并下发到 BS。 实施例三
本实施例中, H-AAA服务器决定 MS的移动分类属性;
发明实施例所述的方法流程图与实施例一类似, 参考图 3, 包括:
401、 MS移动到拜访网络后,发起初始入网交互过程,该步骤属于现有技术, 不再赘述;
402、 拜访网络 Authenticator向拜访网络 AAA服务器 V-AAA发送接入请求 (Access-Request ) 消息, 所述接入请求消息中携带拜访地接入业务网络的移动 性限制策略, 另外, 还可携带所述 MS的移动性限制相关参数;
移动性限制策略在拜访地接入业务网络 Authenticator 中保存, 包括: 拜 访地接入业务网络支持什么样的移动分类用户, 例如: 移动、 游牧或固定; 所 述 MS的移动限制相关参数与 MS的分类属性对应, 主要是针对固定或游牧用户 而言, 可包括以下至少一项: 允许接入的区域、 重附着区限制、 是否支持会话 连续性等;
403、 V-AAA接收所述 Access-Request消息, 并将所述 Access-Request消 息转发到 H-AAA;
404、 如果 H-AAA允许 MS接入, 则 H-AAA根据接收的 Access-Request消息 中携带的拜访地接入业务网络的移动性限制策略决定 MS的移动分类属性,例如: 属于固定用户还是游牧用户; 并将该 MS的移动分类属性包含在接入允许(Access -Accept ) 消息中下发到 V-AAA;
如果步骤 402中, Access-Request消息中携带有 MS移动性限制相关参数, 该 Access-Accept消息中还可携带该 MS的移动性限制相关参数; 例如: 固定或 游牧用户的相关参数, 包括以下至少一种: 允许接入的区域、 重附着区限制、 是否支持会话连续性等;
405、 V-AAA接收所述 Access_Acc印 t消息, 并将所述 Access_Acc印 t消息 转发到 Authenticator;
406、 Authenticator向 BS发送 AuthRelay—EAP— Transfer消息, 所述消息 中携带 MS的移动分类属性, 另外, 还可携带 MS的移动限制相关参数;
或者
407、 Authenticator向 BS发送 MS— Attachment— Rsp消息, 所述消息中携带 MS的移动分类属性, 另外, 还可携带 MS的移动限制相关参数。
上述步骤可知, 本实施例中, 是由拜访地 ASN将网络移动性限制上报给 V-AAA, V-AAA将其转发给 H-AAA, 由 H-AAA根据拜访地网络的能力决定 MS的移 动分类属性以及相应的移动性限制信息, 并下发到拜访地网络。
针对实施例一中的 V-AAA, 本发明实施例还提供了一种 AAA服务器, 参考图 4, 包括:
接收模块: 用于接收家乡网络 AAA服务器发送的接入允许消息; 确定模块: 根据拜访地连接业务网络的移动性限制策略确定终端的移动分 类属性;
发送模块: 用于向拜访地接入业务网络鉴权器发送接入允许消息, 所述接 入允许消息中携带有所述终端的移动分类属性, 或携带有所述终端的移动分类 属性和移动限制相关参数。
针对实施例二中的鉴权器, 本发明实施例还公开了一种鉴权器, 参考图 4, 包括:
接收模块: 用于接收拜访网络 AAA服务器发送的接入允许消息;
确定模块: 根据拜访地接入业务网络的移动性限制策略确定终端的移动分 类属性;
发送模块: 用于将所述终端的移动分类属性, 或所述终端的移动分类属性 和移动限制相关参数发送给基站。
针对实施例三中的 H-AAA, 本发明实施例还公开了一种 AAA服务器, 参考图 4, 包括:
接收模块: 用于接收 V-AAA发送的接入请求消息, 所述接入请求消息中携 带有拜访地接入业务网络的移动性限制策略;
确定模块: 用于根据拜访地接入业务网络的移动性限制策略确定终端的移 动分类属性;
发送模块: 用于向 V-AAA发送接入允许消息, 所述接入允许消息中携带有 所述终端的移动分类属性, 或携带有所述终端的移动分类属性和移动限制相关 参数。
根据本发明如上实施例的确定漫游用户移动性的方法及装置, 用户终端漫 游到移动性受限的拜访网络后, 或者, 用户终端从移动性受限网络漫游到移动 性不受限制的网络后, 可以及时确定用户终端的移动性限制类型, 拜访网络基 站可获知用户终端的移动性限制信息; 进一步的, 顺利实现用户终端的入网, 并且入网后可限制漫游用户终端的移动范围。 通过以上的实施方式的描述, 所属领域的技术人员可以清楚地了解到本发 明可借助软件加必需的通用硬件平台的方式来实现, 当然也可以通过硬件, 但 很多情况下前者是更佳的实施方式。 基于这样的理解, 本发明的技术方案本质 上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来, 该计算 机软件产品存储在可读取的存储介质中, 如计算机的软盘, 硬盘或光盘等, 包 括若干指令用以使得一台计算机设备 (可以是个人计算机, 服务器, 或者网络 设备等) 执行本发明各个实施例所述的方法。
以上所述的具体实施例, 对本发明的目的、 技术方案和有益效果进行了进 一步详细说明, 所应理解的是, 以上所述仅为本发明的具体实施例而已, 并不 用于限定本发明的保护范围, 凡在本发明的精神和原则之内, 所做的任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。

Claims

权 利 要 求 书
1、 一种确定漫游用户移动性的方法, 其特征在于, 包括:
拜访地接入业务网络鉴权器接收拜访网络认证授权计费 AAA服务器发送的 接入允许消息;
根据拜访地接入业务网络的移动性限制策略确定终端的移动分类属性, 并 将所述终端的移动分类属性发送给基站。
2、 如权利要求 1所述的方法, 其特征在于, 所述接入允许消息中还携带有 终端的移动限制相关参数。
3、 如权利要求 2所述的方法, 其特征在于, 鉴权器将所述终端的移动分类属 性以及移动限制相关参数携带在 AuthRelay— EAP— Transfer消息或 MS— Attachment — Rsp消息中发送给基站。
4、 一种确定漫游用户移动性的方法, 其特征在于, 包括:
拜访网络认证授权计费 AAA服务器接收来自家乡网络认证授权计费 AAA服 务器的接入允许消息;
根据拜访网络连接业务网络 CSN 的移动性限制策略确定终端的移动分类属 性, 并向拜访地接入业务网络鉴权器发送接入允许消息, 所述接入允许消息中 携带有所述终端的移动分类属性。
5、 如权利要求 4所述的方法, 其特征在于, 所述接入允许消息中还携带有 终端的移动限制相关参数。
6、 如权利要求 4所述的方法, 其特征在于, 进一步包括: 所述鉴权器将所 述终端的移动分类属性及相关参数发送给基站。
7、 如权利要求 5所述的方法, 其特征在于, 鉴权器将所述终端的移动分类属 性以及移动限制相关参数携带在 AuthRelay— EAP— Transfer消息或 MS— Attachment —Rsp消息中发送给基站。
8、如权利要求 3或 7所述的方法,所述移动分类属性为固定、游牧或移动, 所述移动限制相关参数为固定或游牧用户相关参数, 包括以下至少一种: 允许 接入的区域、 重附着区域、 是否支持会话连续性。
9、 一种确定漫游用户移动性的方法, 其特征在于, 包括:
家乡网络认证授权计费 AAA服务器接收来自拜访网络认证授权计费 AAA服 务器的接入请求消息, 所述接入请求消息中携带有拜访地接入业务网络的移动 性限制策略;
根据拜访地接入业务网络的移动性限制策略确定终端的移动分类属性; 向拜访网络 AAA服务器发送接入允许消息, 所述接入允许消息中携带有所 述终端的移动分类属性, 或携带有所述终端的移动分类属性和移动限制相关参 数。
10、 一种认证授权计费 AAA服务器, 其特征在于, 包括:
接收模块: 用于接收家乡网络 AAA服务器发送的接入允许消息;
确定模块: 根据拜访地连接业务网络的移动性限制策略确定终端的移动分 类属性;
发送模块: 用于向拜访地接入业务网络鉴权器发送接入允许消息, 所述接 入允许消息中携带有所述终端的移动分类属性, 或携带有所述终端的移动分类 属性和移动限制相关参数。
11、 一种鉴权器, 其特征在于, 包括:
接收模块: 用于接收接入允许消息;
确定模块: 根据移动性限制确定终端的移动分类属性;
发送模块: 用于将所述终端的移动分类属性, 或所述终端的移动分类属性 和移动限制相关参数发送给基站。
12、 一种认证授权计费 AAA服务器, 其特征在于, 包括:
接收模块: 用于接收来自拜访网络 AAA服务器的接入请求消息, 所述接入 请求消息中携带有拜访地接入业务网络的移动性限制策略;
确定模块: 用于根据拜访地接入业务网络的移动性限制策略确定终端的移 发送模块: 用于向拜访网络 AAA服务器发送接入允许消息, 所述接入允许 消息中携带有所述终端的移动分类属性, 或携带有所述终端的移动分类属性和 移动限制相关参数。
PCT/CN2009/072075 2008-07-29 2009-06-01 一种确定漫游用户终端移动性的方法及装置 WO2010012177A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP09802370.8A EP2217025B1 (en) 2008-07-29 2009-06-01 Method and device for determining mobility of roaming user terminal
US12/774,989 US8467783B2 (en) 2008-07-29 2010-05-06 Method and device for determining mobility of roaming user terminal

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2008101425592A CN101640878B (zh) 2008-07-29 2008-07-29 一种确定漫游用户终端移动性的方法及装置
CN200810142559.2 2008-07-29

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US12/774,989 Continuation US8467783B2 (en) 2008-07-29 2010-05-06 Method and device for determining mobility of roaming user terminal

Publications (1)

Publication Number Publication Date
WO2010012177A1 true WO2010012177A1 (zh) 2010-02-04

Family

ID=41609941

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/072075 WO2010012177A1 (zh) 2008-07-29 2009-06-01 一种确定漫游用户终端移动性的方法及装置

Country Status (4)

Country Link
US (1) US8467783B2 (zh)
EP (1) EP2217025B1 (zh)
CN (1) CN101640878B (zh)
WO (1) WO2010012177A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011019417A1 (en) 2009-04-29 2011-02-17 Medivation Technologies, Inc. Pyrido [4, 3-b] indoles and methods of use

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8434132B2 (en) 2010-08-31 2013-04-30 Intel Corporation Roaming between networks employing different authentication protocols
US9167549B2 (en) * 2011-02-21 2015-10-20 Lg Electronics Inc. Method and apparatus for location update in a wireless communication system
ES2786003T3 (es) * 2012-09-18 2020-10-08 Alcatel Lucent Soporte de usuarios nómadas o fijos en una red móvil
US9692711B2 (en) * 2014-12-22 2017-06-27 Verizon Patent And Licensing Inc. DNS redirecting for data roaming offering
CN107690149B (zh) * 2016-08-04 2019-12-20 电信科学技术研究院 触发网络策略更新的方法、管理功能实体及核心网设备

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1610420A (zh) * 2003-10-20 2005-04-27 华为技术有限公司 一种进行漫游限制的方法
CN101094063A (zh) * 2006-07-19 2007-12-26 中兴通讯股份有限公司 一种游牧终端接入软交换网络系统的安全交互方法
CN101198186A (zh) * 2007-12-28 2008-06-11 华为技术有限公司 一种分组域漫游限制的方法、系统和设备

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4009136B2 (ja) * 2001-06-07 2007-11-14 富士通株式会社 課金システム
US7230951B2 (en) * 2003-04-16 2007-06-12 Nortel Networks Limited Policy based mobile IP
WO2006133720A1 (en) * 2005-06-11 2006-12-21 Telefonaktiebolaget Lm Ericson (Publ) Apparatus and method for selecting a visited network
CN100411480C (zh) * 2005-06-29 2008-08-13 华为技术有限公司 实现网络服务提供商选择的方法
CN101147413B (zh) 2005-08-30 2010-10-06 中兴通讯股份有限公司 一种在移动通信系统中实现基于业务的移动性限制的方法
GB2435149A (en) * 2006-02-08 2007-08-15 Siemens Ag Providing mobility information in a mobile communication system
CN101496387B (zh) * 2006-03-06 2012-09-05 思科技术公司 用于移动无线网络中的接入认证的系统和方法
CN100584093C (zh) * 2006-08-15 2010-01-20 华为技术有限公司 一种在移动通信系统中转移用户设备的方法及系统
CN101640919B (zh) 2008-07-29 2011-08-03 华为技术有限公司 一种用户终端接入网络的方法及装置

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1610420A (zh) * 2003-10-20 2005-04-27 华为技术有限公司 一种进行漫游限制的方法
CN101094063A (zh) * 2006-07-19 2007-12-26 中兴通讯股份有限公司 一种游牧终端接入软交换网络系统的安全交互方法
CN101198186A (zh) * 2007-12-28 2008-06-11 华为技术有限公司 一种分组域漫游限制的方法、系统和设备

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011019417A1 (en) 2009-04-29 2011-02-17 Medivation Technologies, Inc. Pyrido [4, 3-b] indoles and methods of use

Also Published As

Publication number Publication date
CN101640878B (zh) 2011-08-31
EP2217025A4 (en) 2011-05-04
EP2217025B1 (en) 2013-08-21
EP2217025A1 (en) 2010-08-11
US20110105115A1 (en) 2011-05-05
CN101640878A (zh) 2010-02-03
US8467783B2 (en) 2013-06-18

Similar Documents

Publication Publication Date Title
US11470204B2 (en) Manual roaming and data usage rights
US20100048161A1 (en) Method, system and apparatuses thereof for realizing emergency communication service
WO2007019771A1 (en) An access control method of the user altering the visited network, the unit and the system thereof
WO2019017837A1 (zh) 网络安全管理的方法及装置
US20060120171A1 (en) Seamless handoff of mobile terminal
EP2179628A2 (en) Heterogeneous wireless ad hoc network
WO2013016968A1 (zh) 一种接入方法、系统及移动智能接入点
WO2018058680A1 (zh) 一种本地业务授权方法及相关设备
WO2010003359A1 (zh) 区别用户计费规则的计费方法和系统
WO2010078785A1 (zh) 配置毫微接入点寻呼组和邻居小区列表的方法、服务器及系统
WO2010012177A1 (zh) 一种确定漫游用户终端移动性的方法及装置
WO2007137516A1 (fr) Procédé, équipement et réseau de communication pour la négociation de la capacité de mobile ip
WO2010012168A1 (zh) 一种固定或游牧用户终端接入网络的方法及装置
WO2010069202A1 (zh) 认证协商方法及系统、安全网关、家庭无线接入点
WO2018058365A1 (zh) 一种网络接入授权方法、相关设备及系统
WO2007033559A1 (fr) Procede de comptabilite dans un reseau a acces sans fil et son systeme correspondant
Huang et al. A fast authentication scheme for WiMAX–WLAN vertical handover
US8036222B1 (en) Method for obtaining a mobile internet protocol address
WO2011097989A1 (zh) 一种本地访问寻呼优化方法及装置
WO2010091589A1 (zh) 一种安全认证方法
WO2014169878A1 (zh) 移动网络接入方法、ue、安全服务网关、系统和存储介质
CN101640919B (zh) 一种用户终端接入网络的方法及装置
CN101459651B (zh) 一种促进QoS建立的方法、服务器及系统
WO2009129730A1 (zh) 一种通用业务接口系统注册的方法、装置与系统
CN102291709B (zh) 一种确定漫游用户终端移动性的方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09802370

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2009802370

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE