WO2010037337A1 - 一种无线接入设备获取管理地址的方法和网络设备 - Google Patents

一种无线接入设备获取管理地址的方法和网络设备 Download PDF

Info

Publication number
WO2010037337A1
WO2010037337A1 PCT/CN2009/074138 CN2009074138W WO2010037337A1 WO 2010037337 A1 WO2010037337 A1 WO 2010037337A1 CN 2009074138 W CN2009074138 W CN 2009074138W WO 2010037337 A1 WO2010037337 A1 WO 2010037337A1
Authority
WO
WIPO (PCT)
Prior art keywords
address
wireless access
security gateway
access device
allocation unit
Prior art date
Application number
PCT/CN2009/074138
Other languages
English (en)
French (fr)
Inventor
文玉麟
张冠男
李伟
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2010037337A1 publication Critical patent/WO2010037337A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0806Configuration setting for initial configuration or provisioning, e.g. plug-and-play
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/34Signalling channels for network management communication
    • H04L41/344Out-of-band transfers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method and a network device for obtaining a management address by a wireless access device. Background technique
  • WiMAX Worldwide Interoperabiity for Microwave Access
  • IEEE802.16 Standard and a BWA (Broadband Wireless Access) standard.
  • the base station of WiMAX is mainly to solve the problem of metropolitan area network coverage.
  • micro base stations Pierocel l, Pico for short
  • femtocel l femtocel l.
  • the embodiment of the invention provides a method for acquiring a management address by a wireless access device and a network device, which can enable the wireless access device to complete automatic allocation of management addresses.
  • An embodiment of the present invention provides a method for a wireless access device to obtain a management address, including: sending, by using a pre-configured security gateway, a request message to an IP address allocation unit, to request the IP address allocation unit to allocate a management IP address;
  • the embodiment of the present invention further provides a method for a wireless access device to obtain a management address, including: sending, by using a pre-configured security gateway, a request message to an IP address allocation unit to request the IP address allocation unit to return a security gateway providing the service. Address information;
  • the embodiment of the present invention further provides a method for network matching, including:
  • the embodiment of the invention further provides a network device, including:
  • a first sending module configured to send, by using a pre-configured security gateway, a request message to the IP address allocation unit, to request the IP address allocation unit to allocate a management IP address;
  • the first receiving module is configured to receive response information that is returned by the IP address allocation unit, where the response information carries a management IP address assigned to the wireless access device.
  • the embodiment of the invention further provides a network device, including:
  • a second sending module configured to send, by using a pre-configured security gateway, a request message to the IP address allocation unit, to request the IP address allocation unit to return information of the security gateway address that provides the service;
  • a second receiving module configured to receive response information that is sent by the IP address allocation unit, where the information carries a security gateway IP address that is a service provided by the wireless access device, and obtains the The management IP address assigned by the security gateway of the service.
  • the embodiment of the invention further provides a network device, including:
  • An information receiving module configured to receive information from a network element management unit
  • the information judging module is configured to determine an application scenario according to the information received by the information receiving module, and the information processing module is configured to: determine, according to the corresponding signaling IP address of the application scenario, the wireless access device identification code and the wireless access device The binding relationship of the IP notifies the gateway, and the wireless access device is controlled by the gateway.
  • the embodiment of the invention further provides a network system, including:
  • a wireless access device configured to send, by using a pre-configured security gateway, a request message to the IP address allocation unit, to request the IP address allocation unit to allocate a management IP address, and receive response information replied by the IP address allocation unit, where the response information is Carrying a management IP address assigned to the wireless access device;
  • An IP address allocation unit configured to generate, according to the request message, response information that carries a management IP address
  • a pre-configured security gateway configured to send a request message of the wireless access device to the IP address allocation unit, and return the response information carrying the management IP address to the wireless access device.
  • the embodiment of the invention further provides a network system, including:
  • a wireless access device configured to send, by using a pre-configured security gateway, a request message to the IP address allocation unit, to request the IP address allocation unit to return information of the security gateway address that provides the service; and receive response information replied by the IP address allocation unit,
  • the information carries the IP address of the security gateway that provides the service for the wireless access device;
  • An IP address allocation unit configured to receive, from the wireless access device, information that returns a security gateway address for providing a service, and replies to the wireless access device with response information of an IP address of the security gateway that provides the service;
  • the pre-configured security gateway is configured to send a request message of the wireless access device to the IP address allocation unit, and return the response information of the IP address of the security gateway that provides the service Returning to the wireless access device;
  • the security gateway providing the service is configured to allocate a management IP address to the wireless access device.
  • the embodiment of the invention further provides a network system, including:
  • a network management unit configured to send information to the wireless access device
  • a wireless access device configured to receive information from the network element management unit; determine an application scenario according to the information; and set a wireless access device identification code and a wireless access device according to a signaling IP address corresponding to the application scenario
  • the binding relationship of the IP notifies the gateway, and the wireless access device is controlled by the gateway.
  • the method and the network device provided by the embodiment of the present invention send a request to allocate a management IP address according to the address of the pre-configured security gateway. Therefore, after the wireless access device is powered on, the management address is obtained and the automatically assigned address is obtained.
  • FIG. 1 is a flowchart of a method for a wireless access device to obtain a management address according to an embodiment of the present invention
  • FIG. 2 is a flowchart of a method for a wireless access device to obtain a management address according to another embodiment of the present invention
  • FIG. 3 is another embodiment of the present invention
  • FIG. 4 is a flowchart of a method for acquiring a management address by another wireless access device according to an embodiment of the present invention
  • FIG. 5 is a flowchart of a method for network matching according to an embodiment of the present invention; ;
  • FIG. 6 is a flowchart of allocating an address by an IP address allocation unit in the embodiment of the present invention
  • FIG. 7 is another flowchart of Embodiment 1 of the embodiment of the present invention.
  • FIG. 8 is a flow chart of allocating addresses through a security gateway in an embodiment of the present invention.
  • FIG. 9 is another flowchart of Embodiment 2 of the embodiment of the present invention.
  • 10 is a flowchart of a method for network matching in another embodiment of the present invention
  • 11 is a schematic structural diagram of a network device according to an embodiment of the present invention
  • FIG. 12 is a schematic structural diagram of a network device according to another embodiment of the present invention.
  • FIG. 13 is a schematic structural diagram of a network device according to another embodiment of the present invention.
  • FIG. 14 is a schematic diagram of a network system in an embodiment of the present invention.
  • Figure 15 is a schematic diagram of a network system in another embodiment of the present invention.
  • Figure 16 is a schematic diagram of a network system in another embodiment of the present invention. detailed description
  • the embodiment of the invention provides a method for acquiring a management address by a wireless access device and a network device.
  • the invention will be described in detail below with reference to the accompanying drawings.
  • the following network types of embodiments of the present invention include: a GSM network, a CDMA network, a WCDMA network, a Wimax network, a TD-SCDMA network, an LTE network, and the like.
  • the types of wireless access devices include: base stations, base station controllers, micro base stations Pico, UMTS APs, WiMAX Femto base stations, WiMAX macro base stations, and the like.
  • the embodiment of the invention provides a method and a device for acquiring a management address of a wireless access device, which can enable a wireless access device to obtain a management address and obtain an automatically assigned address after being powered on.
  • An embodiment of the present invention provides a method for a wireless access device to obtain a management address, as shown in FIG. 1 , including:
  • Step S101 Send a request message to the IP address allocation unit by using the pre-configured security gateway to request the IP address allocation unit to allocate a management IP address.
  • the pre-configured security gateway supports a Request For Comments (RFC) draft, which is capable of dynamically hosting a Dynamic Host Configuration protocol in an encrypted channel (eg, an IPSec encrypted channel). Protocol, DHCP)
  • RRC Request For Comments
  • DHCP Dynamic Host Configuration protocol
  • the broadcast message is transmitted to the IP address allocation unit, and the IP address allocation unit may include a DHCP server or an Element Management System (NMS).
  • NMS Element Management System
  • Step S102 Receive response information replied by the IP address allocation unit, where the response information carries a management IP address allocated for the wireless access device.
  • the method before the step S101, further includes: performing key exchange negotiation with the pre-configured security gateway according to an address of the pre-configured security gateway to establish a temporary encryption channel, where the step is In S101, a request message is sent to the IP address allocation unit by using a temporary encryption channel with the pre-configured security gateway.
  • the wireless access device sends a request for assigning a management IP address to the IP address allocation unit through an encrypted channel with the pre-configured security gateway, and receives a management IP address assigned by the IP address allocation unit. This achieves automatic acquisition of the IP address of the wireless access device, and has less dependence on the networking and flexible address allocation.
  • FIG. 2 is a flowchart of a method for acquiring a management address by another wireless access device according to an embodiment of the present invention, including:
  • Step S201 Perform key exchange negotiation with the pre-configured security gateway according to the pre-configured security gateway address, establish a temporary encryption channel, and obtain a temporary management IP address;
  • the type of the security gateway address includes: an IP address, a MAC address.
  • the address or the domain name address the wireless access device performs a key exchange negotiation with the configured security gateway according to the address, and obtains the temporary management IP address assigned by the configured security gateway.
  • the IP address allocation unit address pre-configured by the wireless access device is a domain name address
  • the address of the core network domain name server may also be obtained, and the IP address of the IP address allocation unit is queried in the core network domain name server according to the address;
  • the wireless access device When the wireless access device performs key exchange negotiation with the pre-configured security gateway, the wireless access device completes its own access authentication and establishes a temporary encrypted channel with the pre-configured security gateway;
  • Step S202 using the temporary management IP address as a source address, and using a pre-configured IP address allocation unit address as a destination address, sending information requesting to allocate a management IP address;
  • the address is a source address, and the pre-configured IP address allocation unit address is used as the destination address, and the information for requesting the management IP address is sent;
  • the information about the request management management IP address also carries the device serial number.
  • the IP address allocation unit (such as the dynamic host configuration protocol server) notifies the network element management system that the wireless access device requests to allocate the management IP address. And, the management address is notified to the network element management system, and on the other hand, the response is returned to the wireless access device according to the device serial number; the above IP address allocation unit may be a DHCP server.
  • Step S203 Receive response information replied by the IP address allocation unit, where the response information carries a management IP address allocated for the wireless access device;
  • the response information may also carry the IP address of the security gateway providing the service, and the security gateway providing the service is specified by the IP address allocation unit or the network element management system, and the allocation of the management IP address is performed under the premise of the security gateway of the designated service.
  • the response information also carries the signaling address or the service address of the wireless access device. When the network matches, the signaling address or the service address is used as the source address to communicate with the gateway.
  • the gateway in this embodiment may be connected. After accessing the service network-gateway (ASN-GW) or the media gateway, the wireless access device can remove the temporarily established encrypted channel and release the temporary management IP address. Then use the management IP address to perform key exchange negotiation with the security gateway providing the service, complete its own access authentication, and establish an encryption channel. If the security gateway providing the service is the same security gateway as the pre-configured security gateway, you can consider using the temporary encryption channel established in step S201 or you can remove the re-established encrypted tunnel.
  • ASN-GW service network-gateway
  • the wireless access device
  • the wireless access device sends a request for assigning a management IP address to the IP address allocation unit by using a temporary management IP address provided by the pre-configured security gateway, and receives the management IP assigned by the IP address allocation unit.
  • the address thereby realizing the automatic acquisition of the IP address of the wireless access device, and the dependence on the networking is small, and the address allocation is flexible.
  • the embodiment of the present invention further provides a method for a wireless access device to obtain a management address, as shown in FIG. 3 . As shown, including:
  • Step S301 Send a request message to the IP address allocation unit by using the pre-configured security gateway to request the IP address allocation unit to return information of the security gateway address providing the service.
  • Step S302 Receive response information replied by the IP address allocation unit, where the information carries a security gateway IP address of the service provided for the wireless access device.
  • the IP address allocation unit in this step can be ⁇ S.
  • Step S303 Obtain a management IP address from the security gateway that provides the service.
  • the method before the step S301, further includes: performing key exchange negotiation with the pre-configured security gateway according to an address of the pre-configured security gateway to establish a temporary encryption channel, where In step S301, a request message is sent to the IP address allocation unit by using a temporary encryption channel with the pre-configured security gateway.
  • step S303 the method further includes: performing key exchange negotiation with the security gateway providing the service, establishing an encryption channel, and acquiring the management IP address by using the encrypted channel.
  • the wireless access device sends a request for acquiring the security gateway providing the service to the IP address allocation unit through an encrypted channel with the pre-configured security gateway, and receives the IP address allocation unit for the same.
  • the security gateway providing the service obtains the management IP address by negotiating with the security gateway providing the service, thereby realizing the wireless access device automatically obtaining the IP address through the security gateway, and the method has little dependence on the networking.
  • FIG. 4 is a flowchart of a method for obtaining a management address by another wireless access device according to an embodiment of the present invention, including:
  • Step S401 Perform key exchange negotiation with the pre-configured security gateway according to the pre-configured security gateway address, establish a temporary encryption channel, and obtain a temporary management IP address.
  • the address of the pre-configured security gateway includes an IP address. Address or domain name address, the wireless access device performs key exchange negotiation with the pre-configured security gateway according to the address, and obtains the temporary management IP address assigned by the pre-configured security gateway; and performs key exchange negotiation with the pre-configured security gateway. Establish a temporary encrypted channel with the pre-configured security gateway. The key exchange negotiation is performed in the temporary encrypted channel, and the key is exchanged.
  • the negotiated wireless access device can also complete its own access authentication;
  • Step S402 The temporary management IP address is used as the source address, and the pre-configured IP address allocation unit address is used as the destination address, and information for requesting the security gateway address for providing the service is sent; the pre-configured network element management system address is also included.
  • the IP address or the domain name address, the information of the requesting service security gateway address further carries the device serial number, and the network element management system responds to the wireless access device according to the device serial number;
  • Step S403 Receive response information replied by the IP address allocation unit, where the information carries a security gateway IP address that is provided for the wireless access device, and the security gateway that provides the service is the network element management system according to the device sequence. Number and other related information (such as load sharing, etc.) A security gateway assigned to the wireless access device;
  • Step S404 Perform key exchange negotiation with the security gateway providing the service to obtain a management IP address.
  • the wireless access device performs key exchange negotiation with the security gateway providing the service, obtains a management IP address, and completes wireless connection. Enter the device's access authentication and establish an encrypted channel.
  • the wireless access device can remove the temporarily established encrypted channel and release the temporary management IP address.
  • the IP address allocation unit may be of a type such as a DHCP Server (Dynamic Host Configuration Protocol Server) or an AAA (Authentication, Authorization and Accounting, Authentication, authorization, accounting server) and BRAS (Broadband Remote Access Server), etc.
  • the first embodiment is assigned an IP address allocation unit 0M IP (Opera Management IP, Operation Management IP Address), IP address
  • the allocation unit can set the allocation principle according to the needs, and can also flexibly choose whether to contact the network management system, such as the S-device.
  • the IP address allocation unit of the process needs to use the ESN (Equipment Serial Number) corresponding to the wireless access device.
  • ESN Equipment Serial Number
  • the address allocation principle and the address of the security gateway providing the service are pre-planned, where the IP address allocation unit needs to identify the extended message of the Option; the second embodiment allocates the management IP address to the wireless access device by the security gateway providing the service,
  • the network element management system can actively connect with the wireless The device is connected to the device and the related configuration is delivered.
  • the network element management system delivers the pre-planned information to the wireless access device, and the wireless access device determines the application scenario selection and the gateway. The method of contacting, and then notifying the access service network-gateway of the binding relationship between the device serial number and the wireless access device IP.
  • the above two embodiments implement the process of automatically allocating the address of the wireless access device after the wireless access device is powered on, and the process of automatically transmitting the configuration of the wireless access device and automatically matching the application scenario of the wireless access device.
  • the gateway of this embodiment may also be a media gateway or the like.
  • the wireless access device sends a request for acquiring the security gateway providing the service to the IP address allocation unit by using the temporary management IP address provided by the pre-configured security gateway, and receives the IP address allocation unit for the request.
  • the security gateway that provides the service obtains a permanent management address by negotiating with the security gateway that provides the service, thereby realizing that the wireless access device automatically obtains the IP address through the security gateway, and the method has little dependence on the networking.
  • the embodiment of the present invention further provides a method for network matching. As shown in FIG.
  • Step S501 Receive information from a network element management unit; and the information sent by the network element management unit further includes: an application scenario, or Access service network-gateway address, or wireless access device identification code, or signaling address, or service address, or neighboring access service network-gateway GW ID or address;
  • the information to be sent also carries an indication that an encrypted channel needs to be established and a key that provides an encrypted channel when the encrypted channel is established. If the above information is carried, it may be considered that an encrypted channel needs to be established;
  • Step S502 Determine an application scenario according to the information
  • Step S503 Notifying, by the gateway, the binding relationship between the wireless access device identification code and the wireless access device IP according to the signaling IP address corresponding to the application scenario, where the wireless access device is controlled by the gateway; Determining, according to the information, that the application scenario is a user plane layout gateway, notifying the gateway according to the IP address assigned by the enterprise network; determining, according to the information, that the application scenario is a core domain layout gateway, according to a signaling address from the network element management system or The service address or management IP address informs the gateway.
  • the gateway is a gateway that controls unlimited access devices.
  • the information that is automatically sent by the network element management system is received, and the information includes the address and application scenario of the access service network-gateway;
  • the device determines the application scenario according to the information, and uses the signaling IP address corresponding to the application scenario to notify the access service network-the binding relationship between the device serial number controlled by the gateway and the wireless access device IP.
  • the above information also includes: BSID (Base Station Identity Code) of the wireless access device, signaling address, service address, and access service network of the neighboring cell - gateway GW ID and address, whether R6 needs to be established.
  • Encrypted channel (including the key to the encrypted channel if needed).
  • the wireless access device determines the application scenario according to the information delivered by the network element management unit, and performs different security policies and processing processes according to the application scenario, thereby making the wireless access device compatible with different Application scenarios, more flexibility.
  • the method for obtaining the management IP address of the wireless access device is described in detail below by using a specific embodiment. There are two ways to obtain the address of the wireless access device and the address of the security gateway providing the service. The specific process is as follows:
  • Step S601 the wireless access device obtains a preset security gateway (Provisioning-Security)
  • the address of the DHCP Server can be either a domain name address or an IP address.
  • Step S602 The wireless access device negotiates with the P-SeGW through an Internet Key Exchange (IKE) through an IP address provided by the internal DHCP server of the enterprise.
  • IKE Internet Key Exchange
  • Step S603 The wireless access device completes the access authentication by using the IKE negotiation.
  • the EAP-TLS extended authentication mode is required. If other authentication methods, such as the shared key, are used, the EAP is not required.
  • the authentication server for TLS is the AAA Server for WiMAX CSN.
  • Step S604 The wireless access device establishes a temporary IPSec tunnel by using the foregoing IKE negotiation; the message interaction between the subsequent wireless access device and the DHCP server is protected by IPSec.
  • Step S605 The wireless access device sends a broadcast message requesting to allocate a management IP address to the DHCP server by using the IPSec tunnel.
  • Step S606 the DHCP Server notifies the element management system (Element Management System, MN) that the wireless access device is requesting the OM IP address; if the MN needs to contact the wireless access device actively, the DHCP Server notifies the MN through the internal message.
  • the NMS subsequently attempts to connect to the wireless access device.
  • the time interval for attempting to connect can be defined according to the network conditions. It is recommended to use the interval calculation method of 2 n *T.
  • the NMS system can directly allocate the OM IP address to the wireless access device.
  • the Li S system and the DHCP Server can be in one device.
  • Step S607 The DHCP server carries the OM IP address assigned to the wireless access device in the response packet according to the ESN number, and carries the IP address of the serving security gateway (S-SeGW) in the DHCP Option.
  • the IP address in the step is re-allocated after the designated S-SeGW, and the IP address segment corresponding to each SeGW is different, thereby solving the routing problem between the network management device and the wireless access device; If necessary, the response message of the DHCP server can also be sent together with the signaling address and the service address of the wireless access device. If there is only one SeGW, the S-SeGW address is not sent.
  • Step S608 the wireless access device removes the temporary IPSec tunnel.
  • Step S609 and step S610 are the same as steps S602 and S603, and an IPSec tunnel is established.
  • the IPSec tunnel is an encrypted channel that is maintained while the wireless access device and the S-SeGW remain connected, and the access authentication is completed. No longer apply for an IP address. If the P-SeGW and the S-SeGW are the same, the process can be simplified, and the temporary IPSec tunnel established in step S602 and step S603 is directly used.
  • FIG. 7 Another flowchart of Embodiment 1 of the embodiment of the present invention, as shown in FIG. 7, includes:
  • Step S701 The wireless access device obtains an address of a preset security gateway (P-SeGW) and a DHCP server; the address may be a domain name address or an IP address.
  • P-SeGW preset security gateway
  • DHCP server a DHCP server
  • Step S702 The wireless access device performs IKE (Internet Key Exchange) negotiation with the P-SeGW through an IP address provided by the internal DHCP server of the enterprise to establish an IPSec. (IP Security Protocol) Tunnel.
  • IKE Internet Key Exchange
  • IP Security Protocol IP Security Protocol
  • the wireless access device obtains information such as the temporary 0M IP address. If the operator has a domain name server (DNS), the IKE process will use the core network domain name server (Core Network-Domain Name) inside the carrier. Server, CN—DNS)
  • DNS domain name server
  • the address is given to the wireless access device.
  • the wireless access device uses the CN-DNS address in the CN-DNS. Query the address of the DHCP server.
  • Step S703 The wireless access device completes the access authentication by using the IKE negotiation.
  • the EAP-TLS extended authentication mode is required. If other authentication methods, such as the shared key, are used, the EAP is not required.
  • the authentication server for TLS is the AAA Server for WiMAX CSN.
  • Step S704 The wireless access device establishes a temporary IPSec tunnel through the foregoing IKE negotiation; the message interaction between the subsequent wireless access device and the DHCP server is protected by IPSec.
  • Step S705 When the address preset in step S401 is a DHCP domain name, the temporary 0M IP address and the DHCP Server domain name preset by the wireless access device are used to query the internal CN-DNS of the carrier to query the address of the DHCP S rv r.
  • Step S706 The wireless access device sends a unicast message (which may be a DHCP Relay message) to the DHCP by using the preset DHCP Server IP address or the address queried by S705.
  • the source address of the unicast message is the temporary 0M IP address obtained in step S702
  • the destination address is the address of the DHCP server
  • the ESN number of the wireless access device is carried in the Option field of the DHCP message, and the request is 0M to the DHCP server. IP address.
  • Step S707 The DHCP server notifies the NMS (Element Management System) that the wireless access device is requesting a permanent 0M IP address. If the NMS is required to contact the wireless access device, the DHCP server notifies the user through the internal message. Next, the S is directly trying to connect to the wireless access device.
  • the time interval for attempting to connect can be defined according to the network conditions. It is recommended to use the interval calculation method of 2 n *T. It is also possible to directly assign the wireless access device to the permanent access device by IP system. Address, the NMS system and DHCP Server can be in one device.
  • Step S708 The DHCP server carries the OM IP address assigned to the wireless access device in the response packet according to the ESN number, and carries the IP address of the S-SeGW (Serving Security Gateway) in the DHCP Option.
  • the IP address in the step is re-allocated after the specified S_SeGW, and the IP address segment corresponding to each SeGW is different, thereby solving the routing problem between the network management device and the wireless access device;
  • the response message of the DHCP server can also be sent together with the signaling address and the service address of the wireless access device. If there is only one SeGW, the S-SeGW address is not sent.
  • Step S709 The radio access device releases the IP address assigned by the P-SeGW, and the temporary IPSec is removed. Step S710 and step S711, the same step S702 and step S703, establishing a permanent IPSec, completing the access authentication, and no longer applying for an IP address. If the P-SeGW and the S-SeGW are the same, the process can be simplified, and the IPSec established in step S702 and step S703 is directly used.
  • the wireless access device sends a request for assigning a management IP address to the DHCP by using a temporary management IP address provided by the pre-configured security gateway, and receives a management IP address assigned by the DHCP, thereby implementing the wireless access device.
  • the automatic acquisition of the IP address, and the use of DHCP to assign addresses is more flexible, and DHCP can also send information such as the signaling address of the wireless access device.
  • the address of the S-SeGW corresponding to the ESN number is pre-planned, including:
  • Steps S801 to S804 are the same as steps S601 to S604 in the above embodiment.
  • Step S805 The wireless access device sends a request message to the DHCP server requesting to allocate a temporary management IP address on the IPSec tunnel, and the request message is a broadcast message.
  • Step S806 the wireless access device actively sends a message requesting the S-SeGW address to the LSI system by using the temporary management IP address.
  • Step S807 the S system allocates the S-SeGW to the wireless access device according to the related information, and returns the address of the S-SeGW to the wireless access device; in the process, other configuration parameters, such as a usage scenario, may also be delivered.
  • ASN-GW Access Service Network-Gateway, Access Service Network-Net Off
  • Address and other information.
  • Step S808 The wireless access device performs key exchange negotiation with the allocated security gateway to obtain the OM IP address and establishes an IPSec tunnel. If the P_SeGW and the S_SeGW are the same, the process may be simplified, and the direct use step is used. S802 to step S804 ⁇ information is OK, there is no need to re-apply OM IP address.
  • Step S809 The wireless access device completes the access authentication by performing key exchange negotiation with the allocated security gateway providing the service.
  • Step S810 dismantling the temporary IPSec with the P-SeGW, and the P-SeGW recovers the temporary management IP address; the process may be performed simultaneously with steps S807 and S808.
  • FIG. 9 Another flowchart of the second mode of the embodiment of the present invention, as shown in FIG. 9, includes:
  • Steps S901 to S904 are the same as steps S701 to S704 in the above embodiment.
  • step S905 when the address preset in step S901 is the domain name of the MN, the temporary OM IP address and the MN domain name preset by the wireless access device are used to go to the operator internal CN-DNS query NMS. the address of.
  • Step S906 the wireless access device actively sends a message requesting the S-SeGW address to the LSI system.
  • Step S907 The S system allocates the S-SeGW to the wireless access device according to the related information, and restores the address of the S-SeGW to the wireless access device.
  • Other configuration parameters such as usage scenarios, may also be delivered in the process. , ASN-GW (Access Service Network-Gateway) address and other information.
  • Step S908 The wireless access device performs key exchange negotiation with the allocated security gateway to establish an IPSec tunnel to obtain an OM IP address. If the P_SeGW and the S_SeGW are the same, the process may be simplified, and the step S902 is directly used. In step S904, the information is OK, and there is no need to re-apply for the OM IP address. The S-SeGW assigns a management IP address to the wireless access device.
  • Step S909 the wireless access device completes the access authentication by performing key exchange negotiation with the allocated security gateway.
  • Step S910 releasing the IP address assigned by the P-SeGW, and removing the temporary IPSec; This can be done simultaneously with step S908 and step S909.
  • the wireless access device sends a request for obtaining the service providing security gateway to the LIS system by using the temporary management IP address provided by the pre-configured security gateway, and receives the security gateway for providing the service for the LIS system.
  • the permanent management address is obtained by negotiating with the security gateway providing the service, thereby realizing that the wireless access device automatically obtains the IP address through the security gateway, and the method has little dependence on the networking.
  • Step S1001 s S actively sends an ASN-GW address and the like to the wireless access device; after contacting the wireless access device in the above four manners, the MN actively sends the ASN-GW address and other information, and the information may be
  • the temporary IPSec transmission can also be transmitted in the permanent IPSec.
  • the process of sending the message can be included when the LIS system contacts the wireless access device for the first time, or can be sent to the wireless system through the multiple interactions. Access device.
  • the content of the information includes: the BSID of the wireless access device, the use scenario selection of the wireless access device (the user plane layout ASN-GW or the core domain layout ASN-GW, the former belongs to the enterprise application, and the latter belongs to the hotspot application and the signal supplementation application. Whether the IPSec of R6 (including the IPSec key is delivered), the ASN-GW address (which may also include the GWID and address of the neighboring ASN-GW), etc.; Signaling address and service address;
  • Step S1002 The wireless access device determines whether the IPSec needs to be established. If the information sent in step S601 carries the indication that the encrypted channel needs to be established and the key of the encrypted channel is provided when the encrypted channel is established, it is determined to establish an encrypted channel. If the ASN-GW is deployed on the user plane, choose whether to establish IPSec to meet the security requirements of different enterprises. If the ASN-GW is deployed in the core domain, you do not need to establish IPSec and use the temporarily established IPSec channel. The process is based on the field Judging from different enterprise needs, it is important to note that the selection of the IP address of the wireless access device signaling is determined according to the scene selection.
  • Step S1003 The wireless access device determines a usage scenario, and uses a different signaling IP address to contact the ASN-GW.
  • ASN-GW is deployed on the user plane, use the IP address assigned by the enterprise network to contact the ASN-GW. If the ASN-GW is deployed in the core domain, use the signaling address delivered by the S system. Contact the ASN-GW with the service address or 0M address of the access device.
  • the wireless access device can choose to construct a new message of R6 to contact the ASN-GW, and bring the binding relationship between the BSID and the BSIP of the wireless access device (you can also choose whether to bring the GWID and GW address of the neighboring area ASNGW. For information, you can also choose whether to bring the information of the neighbor BSID. After receiving the message, the ASN-GW records the binding relationship.
  • the subsequent messages can be forwarded to the BS on the GW. If the direct communication between the S system and the ASN-GW is possible, the NMS system can directly send a message to the ASN-GW to complete the configuration. After the process ends, the wireless access device can perform the subsequent steps of the automatic network planning network.
  • the method provided by the embodiment of the present invention is considered according to a compatibility scenario in which the ASN-GW is in the user plane or the core domain.
  • the ASN-GW is in the user plane and the enterprise application is mainly solved, the internal service flow of the enterprise can be directly routed back to the enterprise through the ASN-GW without the problem of traversing the Internet.
  • the ASN-GW is in the core domain, it mainly solves the problem that the ASN-GW uniformly manages the entire network wireless access equipment (including the macro base station and the small base station).
  • there can be multiple ASN-GWs in a network and these two scenarios can coexist at the same time.
  • the embodiment of the invention further provides a network device, as shown in FIG. 11, comprising:
  • the first sending module 1103 is configured to send a request message to the IP address allocation unit by using the pre-configured security gateway to request the IP address allocation unit to allocate a management IP address.
  • the first receiving module 1104 is configured to receive response information that is returned by the IP address allocation unit, where the response information carries a management IP address allocated for the wireless access device.
  • the network device can also include:
  • the first negotiation module 1101 is configured to perform a key exchange negotiation with the pre-configured security gateway according to the address of the pre-configured security gateway to establish a temporary encryption channel.
  • the first sending module 1103 sends a request message to the IP address allocating unit through a temporary encrypted channel with the pre-configured security gateway.
  • the first obtaining module 1102 is configured to obtain a temporary management IP address by using a key exchange negotiation performed by the first negotiation module 1101.
  • the first sending module 1103 is further configured to send, by using the temporary management IP address as a source address, a pre-configured IP address allocation unit address as a destination address, and send information requesting to allocate a management IP address.
  • the network device can also include:
  • the first release module 1105 is configured to release a temporary management IP address.
  • the first obtaining module 1102 is further configured to obtain an address of the core network domain name server when the pre-configured IP address allocation unit address is a domain name address.
  • the network device can also include:
  • the first encrypted channel removal module 1106 is configured to remove the temporary encrypted channel established by the first negotiation module 1101.
  • the packet received by the first receiving module 1104 further carries the IP address of the security gateway providing the service, and the security gateway providing the service is specified by the IP address allocation unit or the network element management system and assigned an IP address.
  • the above network device further includes:
  • the second negotiation module 1107 is configured to perform key exchange negotiation with the security gateway providing the service according to the address of the security gateway providing the service carried in the packet received by the first receiving module 1104, and establish an encryption channel.
  • the types of network devices provided by the embodiments of the present invention include: a base station or a base station controller.
  • the first sending module requests the IP address allocation unit to allocate a management IP address by using the temporary management IP address obtained by the first acquiring module, and receives the management of the reply of the ip address allocation unit by using the first receiving module.
  • the ip address thereby implementing the wireless access device to automatically obtain the management IP address by using the above module.
  • the embodiment of the invention further provides a network device, as shown in FIG. 12, including:
  • the second sending module 1203 is configured to send a request message to the IP address allocation unit by using the pre-configured security gateway to request the IP address allocation unit to return information of the security gateway address providing the service.
  • the second receiving module 1204 is configured to receive the response information that is sent by the IP address allocation unit, where the information carries the security gateway IP address of the service provided for the wireless access device, and obtains the security gateway allocation of the service provided. Management IP address.
  • the network device also includes:
  • the third negotiation module 1201 is configured to perform a key exchange negotiation with the pre-configured security gateway according to the address of the pre-configured security gateway to establish a temporary encryption channel.
  • the second sending module 1203 sends a request message to the IP address allocating unit through a temporary encrypted channel with the pre-configured security gateway.
  • the fourth negotiation module 1205 is configured to perform key exchange negotiation with the security gateway providing the service to establish an encryption channel.
  • the second obtaining module 1202 is configured to obtain a temporary management IP address by using a key exchange negotiation performed by the third negotiation module 1201.
  • the second sending module 1203 is further configured to send, by using the temporary management IP address as a source address, a pre-configured IP address allocation unit address as a destination address, and send information of a security gateway address requesting the service.
  • the network device also includes:
  • the second release module 1206 is configured to release a temporary management address.
  • the second obtaining module 1202 is further configured to obtain an address of the core network domain name server when the pre-configured IP address allocation unit address is a domain name address.
  • the network device also includes:
  • the second encrypted channel removal module 1207 is configured to remove the temporary encrypted channel established by the third negotiation module 1201.
  • the third sending module sends a request for obtaining the security gateway providing the service to the IP address allocation unit by using the temporary management IP address obtained by the third obtaining module, and receives the IP address allocation unit for the allocation thereof.
  • the security gateway that provides the service obtains the management address through negotiation with the security gateway that provides the service through the fourth negotiation module, thereby realizing that the wireless access device automatically obtains the IP address through the security gateway, and the method has little dependence on the networking.
  • the embodiment of the present invention further provides a network device, as shown in FIG. 13, including:
  • the information receiving module 1301 is configured to receive information from the network element management unit.
  • the information judging module 1302 is configured to determine an application scenario according to the information received by the information receiving module 1301.
  • the information processing module 1303 is configured to notify the gateway of the binding relationship between the wireless access device identification code and the wireless access device IP according to the corresponding signaling IP address of the application scenario, where the wireless access device is used by the gateway control.
  • the network device also includes:
  • the second information judging module 1304 is configured to determine, according to the information received by the information receiving module 1301, whether an encrypted channel needs to be established before the information judging module 1302 determines the application scenario;
  • the second information processing module 1305 is configured to establish an encrypted channel when the second information determining module 1304 determines that an encrypted channel needs to be established, and communication between the information processing module and the gateway is performed in the encrypted channel.
  • the types of network devices provided in the foregoing embodiments include: a base station or a base station controller.
  • the information judging module is connected according to the information receiving module.
  • the received information determines the application scenario, and then the information processing module performs different security policies and processing processes according to the application scenario, thereby enabling the wireless access device to be compatible with different application scenarios.
  • the embodiment of the invention further provides a network system, as shown in FIG. 14, comprising:
  • the wireless access device 1401 is configured to send a request message to the IP address allocating unit 1402 through the pre-configured security gateway to request the IP address allocating unit 1402 to allocate a management IP address, and receive the response information replied by the IP address allocating unit 1402. Carrying the response information as a wireless access device
  • the IP address allocating unit 1402 is configured to generate response information carrying the management IP address according to the request message.
  • a pre-configured security gateway 1403 configured to send a request message of the wireless access device 1401 to the IP address allocation unit 1402, and return the response information carrying the management IP address to the wireless access device 1401 .
  • the wireless access device 1401 may also obtain a temporary management IP address after establishing a temporary encryption channel with the pre-configured security gateway 1403; using the temporary management IP address as a source address, and allocating a unit address with a pre-configured IP address. For the destination address, information for requesting the assignment of the management IP address is transmitted to the IP address assignment unit 1020.
  • the wireless access device 1401 is further configured to perform a key exchange negotiation with the pre-configured security gateway 1403 according to an address of the pre-configured security gateway 1403 to establish a temporary encryption channel; A temporary encrypted channel with the pre-configured security gateway sends a request message to the IP address allocation unit.
  • the network system also includes:
  • the core network name server 1404 is configured to receive information from the wireless access device 1401 to obtain an IP address of the IP address allocation unit, and reply the wireless access device 1401 with an IP address of the IP address allocation unit.
  • a security gateway 1405 for providing a key exchange with the wireless access device 1401 Negotiating, completing access authentication of the wireless access device.
  • the pre-configured security gateway 1403 may be integrated with the serving security gateway 1405 or may be used as a separate entity; and the pre-configured security gateway 1403 or the serving security gateway 1405 may be integrated with the wireless access device 1401. Together.
  • the wireless access device obtains a temporary management IP address by negotiating with the pre-configured security gateway, and then requests the IP address allocation unit to allocate a management IP address by using the temporary management IP address as the source address, thereby realizing automatic acquisition of the wireless access device.
  • the IP address is managed, and the IP address allocation unit can also send information such as the wireless access device service address.
  • the embodiment of the invention further provides a network system, as shown in FIG. 15, comprising:
  • the wireless access device 1501 is configured to send a request message to the IP address allocating unit 1502 through the pre-configured security gateway to request the IP address assigning unit 1502 to return information of the security gateway address providing the service; and receive the IP address assigning unit 1502 to reply The response information, where the information carries the IP address of the security gateway assigned to the wireless access device.
  • the IP address allocating unit 1502 is configured to receive information from the wireless access device 1501 requesting to return the address of the security gateway 1505 providing the service, and reply the wireless access device 1501 with the response information of the IP address of the security gateway 1505 that provides the service. .
  • a pre-configured security gateway 1503 configured to send a request message of the wireless access device 1501 to the IP address allocation unit 1502, and return response information of the IP address of the security gateway 1505 providing the service to the wireless Access device 1501.
  • a security gateway 1505 is provided for allocating a management IP address to the wireless access device 1501.
  • the wireless access device 1501 is further configured to: perform a key exchange negotiation with the pre-configured security gateway 1503 according to an address of the pre-configured security gateway 1503, and establish a temporary encryption channel; and the pre-configured security gateway The temporary encrypted channel between them transmits a request message to the IP address allocating unit 1502. Also used for performing key exchange negotiation with the security gateway 1505 providing the service, establishing an addition Secret channel.
  • the network system also includes:
  • the core network name server 1504 is configured to receive information from the wireless access device 1501 to obtain the IP address of the IP address allocation unit, and reply the wireless access device 1501 with an IP address of the IP address allocation unit.
  • the pre-configured security gateway 1503 is configured to perform key exchange negotiation with the wireless access device 1501, and provide the temporary access IP address to the wireless access device 1501.
  • the pre-configured security gateway 1503 may be integrated with the serving security gateway 1505 or may be used as a separate entity; and the pre-configured security gateway 1503 or the serving security gateway 1505 may be integrated with the wireless access device 1501. Together.
  • the wireless access device obtains a temporary management IP address by negotiating with the pre-configured security gateway, and then requests the IP address allocation unit to allocate the address of the security gateway providing the service by using the temporary management IP address as the source address, and then The security gateway negotiates and obtains the management IP address, thereby realizing that the wireless access device automatically obtains the management IP address.
  • the pre-configured security gateway may be the security gateway that provides the service, and the temporary management IP address can be used as the management IP address.
  • the embodiment of the invention further provides a network system, as shown in FIG. 16, including
  • the network management unit 1602 is configured to send information to the wireless access device 1601.
  • a wireless access device 1601 configured to receive information from the network element management unit 1602; determine an application scenario according to the information; and connect the wireless access device identification code to the wireless device according to a signaling IP address corresponding to the application scenario.
  • the binding relationship of the incoming device IP is notified to the gateway, and the wireless access device 1601 is controlled by the gateway;
  • the network management unit 1602 is configured to send information to the wireless access device 1601.
  • the information delivered by the network management unit 1602 includes an application scenario, or an access service network-gateway address, or a wireless access device identifier, or a signaling address, or a service address, or an access service network of a neighboring cell.
  • GW ID and address if the information carries an indication that an encrypted channel needs to be established, And the key of the encrypted channel is provided when the encrypted channel is established, and the wireless access device establishes an encrypted channel.
  • the wireless access device determines the application scenario according to the information sent by the network element management unit, and performs different security policies and processes according to the application scenario, so that the wireless access device can be compatible with different application scenarios.
  • the method and the device provided by the embodiments of the present invention implement the process of automatically discovering the IP address of the plug-and-play function of the wireless access device in the case of the common networking, including P_SeGW, S-SeGW, M2000/DHCP Server, ASN-
  • the process of automatically discovering the address of the network element such as GW, and the process of obtaining the IP address of the own signaling network management system by the wireless access device is compatible with the two main usage scenarios of wireless access devices under the premise of plug and play.
  • the method provided by the embodiment of the present invention has less reliance on the networking, and has less requirements on devices other than the network management system of the WiMAX and the wireless access device, and is highly implementable. If the local party has no special requirements, even the ASN-GW and Devices such as AAA can automatically obtain the management address process without the unified management of the network management. Both signaling and data interaction can be encrypted by IPSec, and different encryption policies can be met for different enterprise users and hotspot users under the premise of plug-and-play wireless access devices. In this process, the authentication of the wireless access device can adopt the EAP-TLS method to meet the current status of WiMAX, and the subsequent terminal authentication can also be based on digital certificate authentication.
  • the automatic configuration of the WiMAX PICO and the automatic network planning network are also provided, which provides a prerequisite for the user under the wireless access device to implement automatic network access.
  • the method provided by the embodiment of the present invention can be applied to other access point devices to implement an automatic access network and an automatic configuration delivery process, such as a UMTS AP, a WiMAX Femto base station, and a WiMAX macro base station.
  • an automatic access network and an automatic configuration delivery process such as a UMTS AP, a WiMAX Femto base station, and a WiMAX macro base station.
  • the method and the network device provided by the embodiment of the present invention perform key exchange negotiation with the pre-configured security gateway according to the pre-configured security gateway address, and obtain the allocated temporary management IP address.
  • the temporary management IP address is used as the source. Address, with the pre-configured dynamic host configuration protocol server address as the destination address, send request to assign management IP address and service security gateway information, or use the temporary management IP address as the source address to pre-configure the network element management system address For the destination address, send information requesting the security gateway address of the service, and then request the distribution pipe to the security gateway of the service. IP address. Thereby, the automatically allocated management address can be obtained after the wireless access device is powered on.
  • the wireless access device After receiving the information sent by the network element management unit, the wireless access device determines the application scenario of the wireless access device according to the information, and then notifies the access service network-the wireless device controlled by the gateway by using the signaling IP address corresponding to the application scenario.
  • the binding relationship between the access device identifier and the IP address of the wireless access device so that the system can adopt different security policies and processes according to different application scenarios, so that the wireless access device is compatible with different application scenarios, and the flexibility is higher. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例公开了一种无线接入设备获取管理地址的方法和网络设备,该方法包括根据预配置的安全网关的地址,与所述预配置的安全网关进行密钥交换协商,建立临时加密通道;通过与所述预配置的安全网关的所述临时加密通道向 IP 地址分配单元发送请求消息,以请求 IP 地址分配单元分配管理 IP 地址;接收所述 IP 地址分配单元回复的响应信息,所述响应信息 中携带为无线接入设备分配的管理 IP 地址。通过本发明实施例提供的方法可 以使无线接入设备自动获得分配管理地址。

Description

一种无线接入设备获取管理地址的方法和网络设备
本申请要求于 2008 年 9 月 24 日提交中国专利局、 申请号为 200810211736. 8、 发明名称为 "一种无线接入设备获取管理地址的方法和网 络设备" 的中国专利申请的优先权, 其全部内容通过引用结合在本申请中。
技术领域 本发明实施例涉及通信技术领域, 尤其涉及一种无线接入设备获取管理 地址的方法和网络设备。 背景技术
WiMAX (Worldwide Interoperabi l ity for Microwave Access , 全球微 波互联接入) 是 IEEE802. 16标准, 也是 BWA (Broadband Wireless Access , 广带无线接入)标准。 WiMAX的基站主要是为了解决城域网覆盖的问题, 考虑 到作为热点地区的盲点补充和企业应用等场景, 出现了微型基站(Picocel l , 简称 Pico ) 和超微型基站 (femtocel l , 简称 femto ) 等小型基站的概念。
发明人在实现本发明的过程中, 发现现有技术至少存在以下问题: 小型 基站的管理地址需要手动配置, 而这类基站数量非常多, 导致效率低, 给运 营和维护造成困难。
发明内容
本发明实施例提供了一种无线接入设备获取管理地址的方法和网络设 备, 可以使无线接入设备完成管理地址的自动分配。 本发明实施例提供了一种无线接入设备获取管理地址的方法, 包括: 通过预配置的安全网关向 IP地址分配单元发送请求消息,以请求所述 IP 地址分配单元分配管理 IP地址;
接收所述 IP地址分配单元回复的响应信息, 所述响应信息中携带为无线 接入设备分配的管理 IP地址。
本发明实施例还提供了一种无线接入设备获取管理地址的方法, 包括: 通过预配置的安全网关向 IP地址分配单元发送请求消息,以请求所述 IP 地址分配单元返回提供服务的安全网关地址的信息;
接收所述 IP地址分配单元回复的响应信息, 所述信息中携带为无线接入 设备分配的提供服务的安全网关 IP地址;
从所述提供服务的安全网关获取管理 IP地址。
另一方面本发明实施例还提供了一种网络匹配的方法, 包括:
接收来自网元管理单元的信息;
根据所述信息判断应用场景;
根据所述应用场景相应的信令 IP地址, 将无线接入设备识别码与无线接 入设备 IP的绑定关系通知网关, 所述无线接入设备被所述网关所控制。
同时本发明实施例还提供了一种网络设备, 包括:
第一发送模块, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元分配管理 IP地址;
第一接收模块, 用于接收所述 IP地址分配单元回复的响应信息, 所述响 应信息中携带为无线接入设备分配的管理 ip地址。
本发明实施例还提供了一种网络设备, 包括:
第二发送模块, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元返回提供服务的安全网关地址的信息;
第二接收模块, 用于接收所述 IP地址分配单元回复的响应信息, 所述信 息中携带为无线接入设备分配的提供服务的安全网关 IP地址, 并获取所述提 供服务的安全网关分配的管理 IP地址。
本发明实施例还提供了一种网络设备, 包括:
信息接收模块, 用于接收来自网元管理单元的信息;
信息判断模块, 用于根据所述信息接收模块接收的信息, 判断应用场景; 信息处理模块, 用于根据所述应用场景相应的信令 IP地址, 将无线接入 设备识别码与无线接入设备 IP的绑定关系通知网关, 所述无线接入设备被所 述网关所控制。
本发明实施例还提供了一种网络系统, 包括:
无线接入设备, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元分配管理 IP地址; 接收所述 IP地址分配单元 回复的响应信息, 所述响应信息中携带为无线接入设备分配的管理 IP地址;
IP地址分配单元, 用于根据所述请求消息生成携带管理 IP地址的响应信 息;
预配置的安全网关, 用于将所述无线接入设备的请求消息发送给所述 IP 地址分配单元, 并将所述携带管理 IP地址的响应信息返回给所述无线接入设 备。
同时本发明实施例还提供了一种网络系统, 包括:
无线接入设备, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元返回提供服务的安全网关地址的信息; 接收所 述 IP地址分配单元回复的响应信息, 所述信息中携带为无线接入设备分配的 提供服务的安全网关 IP地址;
IP地址分配单元, 用于接收来自所述无线接入设备的请求返回提供服务 的安全网关地址的信息, 向所述无线接入设备回复携带提供服务的安全网关 I P地址的响应信息;
所述预配置的安全网关, 用于将所述无线接入设备的请求消息发送给所 述 IP地址分配单元, 并将所述携带提供服务的安全网关 IP地址的响应信息返 回给所述无线接入设备;
所述提供服务的安全网关, 用于为所述无线接入设备分配管理 IP地址。 同时本发明实施例还提供了一种网络系统, 包括:
网络管理单元, 用于向无线接入设备发送信息;
无线接入设备, 用于接收来自所述网元管理单元的信息; 根据所述信息 判断应用场景; 根据所述应用场景相应的信令 IP地址, 将无线接入设备识别 码与无线接入设备 IP的绑定关系通知网关, 所述无线接入设备被所述网关所 控制。
本发明实施例具有以下优点:
通过本发明实施例提供的方法和网络设备, 根据预配置的安全网关的地 址, 发送请求分配管理 IP地址。 由此可以使无线接入设备上电后实现获取管 理地址并获得自动分配的地址。 附图说明
此处所说明的附图用来提供对本发明的进一歩理解, 构成本申请的一部 分, 并不构成对本发明的限定。 在附图中:
图 1是本发明实施例中无线接入设备获取管理地址的方法流程图; 图 2是本发明另一实施例无线接入设备获取管理地址的方法流程图; 图 3是本发明另一实施例中无线接入设备获取管理地址的方法流程图; 图 4所示为本发明实施例另一无线接入设备获取管理地址的方法流程图; 图 5是本发明实施例中网络匹配的方法流程图;
图 6是本发明实施例中通过 IP地址分配单元分配地址的流程图; 图 7所示本发明实施例方式一的另一流程图;
图 8是本发明实施例中通过安全网关分配地址的流程图;
图 9所示本发明实施例方式二的另一流程图;
图 10是本发明另一实施例中网络匹配的方法流程图; 图 11是本发明实施例中网络设备的结构示意图;
图 12是本发明另一实施例中网络设备的结构示意图;
图 13是本发明另一实施例中网络设备的结构示意图;
图 14是本发明实施例中网络系统的示意图;
图 15是本发明另一实施例中网络系统的示意图;
图 16是本发明另一实施例中网络系统的示意图。 具体实施方式
为使本发明的目的、 技术方案和优点更加清楚明白, 下面结合实施方式 和附图, 对本发明做进一歩详细说明。 在此, 本发明的示意性实施方式及其 说明用于解释本发明, 但并不作为对本发明的限定。
本发明实施例提供一种无线接入设备获取管理地址的方法和网络设备。 以下结合附图对本发明进行详细说明。
以下本发明实施例的网络类型包括: GSM网络、 CDMA网络、 WCDMA网络、 W imax网络、 TD-SCDMA网络、 LTE网络等。 无线接入设备的类型包括: 基站、 基 站控制器、 微型基站 Pico、 UMTS AP, WiMAX Femto基站、 WiMAX宏基站等。
本发明实施例提供了一种无线接入设备获取管理地址的方法和装置, 可 以使无线接入设备上电后实现获取管理地址并获得自动分配的地址。
下面结合附图和具体实施例对本发明实施例提供的方法和装置进行详细 说明。
本发明实施例提供了一种无线接入设备获取管理地址的方法, 如图 1 所 示, 包括:
歩骤 S101 , 通过预配置的安全网关向 IP地址分配单元发送请求消息, 以 请求所述 IP地址分配单元分配管理 IP地址。 其中, 所述预配置的安全网关 支持请求注解 (Request For Comments , RFC) 草案, 其能够将处于加密通道 (例如 IPSec加密通道)中的动态主机配置协议(Dynamic Host Configuration Protocol , DHCP) 广播消息传送给 IP地址分配单元, 所述 IP地址分配单元 可以包括 DHCP服务器或者网元管理系统(Element Management System, NMS) 等。
歩骤 S102, 接收所述 IP地址分配单元回复的响应信息, 所述响应信息中 携带为无线接入设备分配的管理 IP地址。
作为本发明的一个实施例, 在所述歩骤 S101之前还包括, 根据预配置的 安全网关的地址, 与所述预配置的安全网关进行密钥交换协商, 建立临时加 密通道, 所述歩骤 S101中通过与所述预配置的安全网关之间的临时加密通道 向 IP地址分配单元发送请求消息。
通过上述实施例, 无线接入设备通过与预配置的安全网关之间的加密通 道, 向 IP地址分配单元发送分配管理 IP地址的请求, 并接收 IP地址分配单 元为其分配的管理 IP地址, 由此实现了无线接入设备 IP地址的自动获取, 而且对组网的依赖小, 地址分配灵活。
如图 2所示为本发明实施例另一无线接入设备获取管理地址的方法流程 图, 包括:
歩骤 S201、 根据预配置的安全网关的地址, 与所述预配置的安全网关进 行密钥交换协商, 建立临时加密通道, 获取临时管理 IP地址; 安全网关的地 址的类型包括: IP地址、 MAC地址或域名地址, 无线接入设备根据该地址与 与配置的安全网关进行密钥交换协商, 获取该与配置的安全网关分配的临时 管理 IP地址。 当无线接入设备预配置的 IP地址分配单元地址为域名地址时, 还可以获取核心网域名服务器的地址, 根据该地址在核心网域名服务器中查 询 IP地址分配单元的 IP地址;
无线接入设备与预配置的安全网关进行密钥交换协商时无线接入设备完 成自身的接入认证并建立与预配置的安全网关的临时加密通道;
歩骤 S202、 以所述临时管理 IP地址为源地址, 以预配置的 IP地址分配 单元地址为目的地址, 发送请求分配管理 IP地址的信息; 以所述临时管理 IP 地址为源地址, 以预配置的 IP地址分配单元地址为目的地址, 发送请求分配 管理 IP地址的信息;
上述请求分配管理 IP地址的信息中还携带了设备序列号, IP地址分配单 元 (如动态主机配置协议服务器) 接收到该信息后, 一方面通知网元管理系 统无线接入设备请求分配管理 IP地址, 并将管理地址告知网元管理系统, 另 一方面根据设备序列号向无线接入设备回复响应; 上述 IP地址分配单元可以 为 DHCP服务器。
歩骤 S203、接收所述 IP地址分配单元回复的响应信息, 所述响应信息中 携带为无线接入设备分配的管理 IP地址;
该响应信息中还可以携带提供服务的安全网关的 IP地址, 该提供服务的 安全网关由 IP地址分配单元或网元管理系统指定, 管理 IP地址的分配是在 指定服务的安全网关的前提下进行分配的; 该响应信息中还携带了无线接入 设备的信令地址或业务地址, 网络匹配时以该信令地址或业务地址为源地址 与网关进行通信, 本实施例中的网关可以是接入服务网络 -网关 (Access Service Network-Gateway, ASN-GW) 或媒体网关等; 无线接入设备获得永久 的管理地址后, 可以拆除临时建立的加密通道, 释放临时管理 IP地址。 再利 用管理 IP地址与提供服务的安全网关进行密钥交换协商, 完成自身的接入认 证, 并建立加密通道。 若提供服务的安全网关与预配置的安全网关为同一安 全网关, 则可以考虑使用歩骤 S201中建立的临时加密通道, 也可以拆除重建 加密隧道。
通过本发明实施例提供的方法, 无线接入设备利用预配置的安全网关提 供的临时管理 IP地址向 IP地址分配单元发送分配管理 IP地址的请求, 并接 收 IP地址分配单元为其分配的管理 IP地址, 由此实现了无线接入设备 IP地 址的自动获取, 而且对组网的依赖小, 地址分配灵活。 本发明实施例还提供了一种无线接入设备获取管理地址的方法, 如图 3 所示, 包括:
歩骤 S301 , 通过预配置的安全网关向 IP地址分配单元发送请求消息, 以 请求所述 IP地址分配单元返回提供服务的安全网关地址的信息。
歩骤 S302, 接收所述 IP地址分配单元回复的响应信息, 所述信息中携带 为无线接入设备分配的提供服务的安全网关 IP地址。 在本歩骤中的 IP地址 分配单元可以为丽 S。
歩骤 S303, 从所述提供服务的安全网关获取管理 IP地址。
作为本发明的一个实施例, 在所述歩骤 S301之前还包括, 根据预配置的 安全网关的地址, 与所述预配置的安全网关进行密钥交换协商, 建立临时加 密通道, 在所述歩骤 S301中, 通过与所述预配置的安全网关之间的临时加密 通道向 IP地址分配单元发送请求消息。
在歩骤 S303中还包括, 与所述提供服务的安全网关进行密钥交换协商, 建立加密通道, 通过所述加密通道获取所述管理 IP地址。
通过本发明实施例提供的方法, 无线接入设备通过与预配置的安全网关 之间的加密通道, 向 IP地址分配单元发送获取提供服务的安全网关的请求, 并接收 IP地址分配单元为其分配的提供服务的安全网关, 通过与该提供服务 的安全网关进行协商获得管理 IP地址, 由此实现了无线接入设备通过安全网 关自动获取 IP地址, 而且该方法对组网的依赖小。
如图 4所示为本发明实施例另一无线接入设备获取管理地址的方法流程 图, 包括:
歩骤 S401、 根据预配置的安全网关的地址, 与所述预配置的安全网关进 行密钥交换协商, 建立临时加密通道, 获取临时管理 IP地址; 具体的, 预配 置的安全网关的地址包括 IP地址或域名地址, 无线接入设备根据该地址与预 配置的安全网关进行密钥交换协商, 获取该预配置的安全网关分配的临时管 理 IP地址; 与预配置的安全网关进行密钥交换协商时, 建立与预配置的安全 网关的临时加密通道, 该密钥交换协商在临时加密通道中进行, 通过密钥交 换协商无线接入设备还可以完成自身的接入认证;
歩骤 S402、 以所述临时管理 IP地址为源地址, 以预配置的 IP地址分配 单元地址为目的地址, 发送请求分配提供服务的安全网关地址的信息; 预配 置的网元管理系统地址也包括 IP地址或域名地址, 上述请求服务安全网关地 址的信息中还携带了设备序列号, 网元管理系统根据该设备序列号向无线接 入设备回复响应;
歩骤 S403、接收所述 IP地址分配单元回复的响应信息, 所述信息中携带 为无线接入设备分配的提供服务的安全网关 IP地址, 该提供服务的安全网关 是网元管理系统根据设备序列号和其他相关信息 (如负荷分担等) 为无线接 入设备分配的安全网关;
歩骤 S404、 与所述提供服务的安全网关进行密钥交换协商, 获取管理 IP 地址; 无线接入设备与提供服务的安全网关进行密钥交换协商, 获取管理 IP 地址, 同时还完成了无线接入设备的接入认证并且建立加密通道。
无线接入设备获得永久的管理地址后, 可以拆除临时建立的加密通道, 释放临时管理 IP地址。
上述两个实施例中, IP地址分配单元可以为的类型可以是 DHCP Server (Dynamic Host Configuration Protocol Server , 动态主机酉己置协议月艮务 器)、 AAA月艮务器 (Authentication, Authorization and Accounting, 认证、 授权、 计费服务器) 和 BRAS (Broadband Remote Access Server, 宽带接入 服务器) 等等, 第一个实施例由 IP 地址分配单元分配 0M IP ( Operate Management IP, 操作管理 IP地址), IP地址分配单元可以根据需要自行设定 分配原则, 也可以灵活选择是否联系网元管理系统丽 S等设备, 该过程 IP地 址分配单元需要将 ESN (Equipment Serial Number, 设备序列号) 对应的无 线接入设备地址分配原则和提供服务的安全网关的地址预先规划好, 此处 IP 地址分配单元需要识别 Option的扩展消息; 第二个实施例由提供服务的安全 网关为无线接入设备分配管理 IP地址, 此处网元管理系统可以主动与无线接 入设备建立联系, 下发相关配置。 上述两个实施例中, 当无线接入设备与网 元管理系统建立联系后, 网元管理系统将预规划的信息下发到无线接入设备, 无线接入设备通过判断应用场景选择与网关进行联系的方式, 然后将设备序 列号和无线接入设备 IP 的绑定关系通知接入服务网络-网关。 上述两个实施 例都实现了无线接入设备上电后自动分配无线接入设备地址的过程, 还实现 了自动下发无线接入设备相关配置以及无线接入设备自动匹配应用场景的过 程。本实施例的网关除了是还可以接入服务网络-网关,还可以是媒体网关等。
通过本发明实施例提供的方法, 无线接入设备利用预配置的安全网关提 供的临时管理 IP地址向 IP地址分配单元发送获取提供服务的安全网关的请 求, 并接收 IP地址分配单元为其分配的提供服务的安全网关, 通过与该提供 服务的安全网关进行协商获得永久管理地址, 由此实现了无线接入设备通过 安全网关自动获取 IP地址, 而且该方法对组网的依赖小。 本发明实施例还提供了一种网络匹配的方法, 如图 5所示, 包括: 歩骤 S501、 接收来自网元管理单元的信息; 网元管理单元下发的信息还 包括: 应用场景、 或接入服务网络 -网关地址、 或无线接入设备识别码、 或信 令地址、 或业务地址、 或邻区的接入服务网络 -网关 GW ID或地址;
该下发的信息中还携带需要建立加密通道的指示以及在建立加密通道时 提供加密通道的密钥, 若携带上述信息, 则可认为需要建立加密通道;
歩骤 S502、 根据所述信息判断应用场景;
歩骤 S503、根据所述应用场景相应的信令 IP地址, 将无线接入设备识别 码与无线接入设备 IP的绑定关系通知网关, 所述无线接入设备被所述网关所 控制; 所述根据所述信息判断应用场景为用户面布置网关时, 根据企业网分 配的 IP地址通知网关; 根据所述信息判断应用场景为核心域布置网关时, 根 据来自网元管理系统的信令地址或业务地址或管理 IP地址通知网关。 该网关 为控制无限接入设备的网关。 本发明实施例中无线接入设备与网元管理系统等建立联系后, 接收网元 管理系统自动下发的信息, 该信息中携带包括接入服务网络-网关的地址和应 用场景; 无线接入设备根据该信息判断应用场景, 使用与应用场景相应的信 令 IP地址通知所述接入服务网络-网关所控制的设备序列号与无线接入设备 IP 的绑定关系。 上述信息还包括: 无线接入设备的 BSID ( Base Station Identity Code , 无线接入设备识别码)、 信令地址、 业务地址和邻区的接入 服务网络 -网关 GW ID和地址, 是否需要建立 R6的加密通道 (若需要还包括 加密通道的密钥)。
通过本发明实施例提供的方法, 无线接入设备根据网元管理单元下发的 信息判断应用场景, 并根据应用场景进行不同的安全策略和处理流程, 由此 可以使无线接入设备兼容不同的应用场景, 灵活性更高。 下面通过具体实施例对无线接入设备获取管理 IP地址的方法进行详细说 明, 获取无线接入设备地址和提供服务的安全网关的地址的方式有两种, 具 体过程如下:
方式一, 如图 6所示, 通过 DHCP Server分配地址, 包括:
歩骤 S601 , 无线接入设备获得预置的安全网关 (Provisioning-Security
Gateway, P-SeGW) 和 DHCP Server的地址; 该地址可以为域名地址, 也可以 为 IP地址。
歩骤 S602, 无线接入设备通过企业内部的 DHCP Server提供的 IP地址与 P-SeGW进行因特网密钥交换 (Internet Key Exchange, IKE) 协商。
歩骤 S603、 无线接入设备通过上述 IKE协商完成接入认证; 使用 EAP-TLS 扩展认证方式时, 需要此歩骤; 若使用其他认证方式如共享密钥的方式, 不 需要此歩骤, EAP-TLS的认证服务器为 WiMAX CSN的 AAA Server。
歩骤 S604、 无线接入设备通过上述 IKE协商建立临时 IPSec隧道; 后续无 线接入设备与 DHCP Server的消息交互受到 IPSec的保护。 歩骤 S605, 无线接入设备通过上述的 IPSec隧道向所述 DHCP服务器发送请 求分配管理 IP地址的广播消息。
歩骤 S606, DHCP Server通知网元管理系统 (Element Management System, 丽 S), 无线接入设备在请求 OM IP地址; 如果需要丽 S主动联系无线接入设备, 则 DHCP Server通过内部消息通知丽 S, NMS后续直接尝试连接无线接入设备, 尝试连接的时间间隔可以根据网络情况定义, 建议使用 2n*T的间隔计算方法; 也可以选择由 NMS系统直接为无线接入设备分配 OM IP地址, 该丽 S系统和 DHCP Server可以在一个设备中。
歩骤 S607、 DHCP Server根据 ESN号码, 在响应报文中携带分配给无线 接入设备的 OM IP 地址, 并在 DHCP Option 中携带服务的安全网关 (Serving-Security Gateway, S-SeGW) 的 IP地址; 该歩骤中的 IP地址是 在指定 S-SeGW之后再分配的, 并且每个 SeGW对应的 IP地址段是不相同的, 由此可以解决网管到无线接入设备之间的路由问题; 如果有需要, 该 DHCP Server的响应消息也可以将无线接入设备的信令地址、业务地址等一并下发。 如果只有一个 SeGW, 则 S-SeGW地址不用下发。
歩骤 S608, 无线接入设备拆除临时 IPSec隧道。
歩骤 S609和歩骤 S610相同于歩骤 S602和歩骤 S603 , 建立 IPSec隧道, 该 IPSec隧道是在该无线接入设备与 S-SeGW保持连接状态下一直保持的加密通 道, 完成接入认证, 不再申请 IP地址。 如果 P-SeGW和 S-SeGW是同一个, 该过 程可以选择简化, 直接使用歩骤 S602和歩骤 S603建立的临时 IPSec隧道。
如图 7所示本发明实施例方式一的另一流程图, 包括:
歩骤 S701、无线接入设备获得预置的安全网关(Provisioning-Security Gateway, P-SeGW) 和 DHCP Server的地址; 该地址可以为域名地址, 也可以 为 IP地址。
歩骤 S702、 无线接入设备通过企业内部的 DHCP Server提供的 IP地址与 P-SeGW进行 IKE ( Internet Key Exchange,因特网密钥交换)协商,建立 IPSec ( IP Security Protocol , IP安全协议) 隧道。
通过该协商过程无线接入设备获取临时 0M IP地址等信息, 如果运营商 内部有域名服务器 (Domain Name Server, DNS), 则 IKE过程会将运营商内 部的核心网域名服务器 (Core Network- Domain Name Server, CN— DNS ) 地 址带给无线接入设备, 用于当歩骤 S401 中无线接入设备预置的地址为 DHCP Server的域名时, 无线接入设备利用该 CN— DNS地址在 CN— DNS 中查询 DHCP Server的地址。
歩骤 S703、无线接入设备通过上述 IKE协商完成接入认证;使用 EAP-TLS 扩展认证方式时, 需要此歩骤; 若使用其他认证方式如共享密钥的方式, 不 需要此歩骤, EAP-TLS的认证服务器为 WiMAX CSN的 AAA Server。
歩骤 S704、 无线接入设备通过上述 IKE协商建立临时 IPSec隧道; 后续 无线接入设备与 DHCP Server的消息交互受到 IPSec的保护。
歩骤 S705、 当歩骤 S401中预置的地址为 DHCP的域名, 则使用临时 0M IP地 址和无线接入设备预置的 DHCP Server域名去运营商内部 CN-DNS查询 DHCP S rv r的地址。
歩骤 S706、 无线接入设备使用预置的 DHCP Server IP地址或歩骤 S705 查询的地址, 向 DHCP发送单播消息 (可以是 DHCP Relay消息)。 该单播消息 填充的源地址为歩骤 S702中获取的临时 0M IP地址, 目的地址为 DHCP Server 的地址, 并在 DHCP消息的 Option字段中携带无线接入设备的 ESN号码, 向 DHCP Server请求 0M IP地址。
歩骤 S707、 DHCP Server通知 NMS (Element Management System, 网元管 理系统), 无线接入设备在请求永久 0M IP地址; 如果需要 NMS主动联系无线接 入设备, 则 DHCP Server通过内部消息通知丽 S, 丽 S后续直接尝试连接无线接 入设备, 尝试连接的时间间隔可以根据网络情况定义, 建议使用 2n*T的间隔计 算方法; 也可以选择由丽 S系统直接为无线接入设备分配永久 0Μ IP地址, 该 NMS系统和 DHCP Server可以在一个设备中。 歩骤 S708、 DHCP Server根据 ESN号码, 在响应报文中携带分配给无线 接入设备的 OM IP地址, 并在 DHCP Option中携带 S-SeGW (Serving-Security Gateway, 服务的安全网关) 的 IP地址; 该歩骤中的 IP地址是在指定 S_SeGW 之后再分配的, 并且每个 SeGW对应的 IP地址段是不相同的, 由此可以解决 网管到无线接入设备之间的路由问题; 如果有需要, 该 DHCP Server 的响应 消息也可以将无线接入设备的信令地址、 业务地址等一并下发。 如果只有一 个 SeGW, 则 S-SeGW地址不用下发。
歩骤 S709、 无线接入设备释放 P-SeGW分配的 IP地址, 拆除临时 IPSec。 歩骤 S710和歩骤 S711、 同歩骤 S702和歩骤 S703, 建立永久的 IPSec , 完成 接入认证, 不再申请 IP地址。 如果 P-SeGW和 S-SeGW是同一个, 该过程可以选 择简化, 直接使用歩骤 S702和歩骤 S703建立的 IPSec。
通过上述歩骤, 无线接入设备利用预配置的安全网关提供的临时管理 IP 地址向 DHCP发送分配管理 IP地址的请求, 并接收 DHCP为其分配的管理 IP 地址, 由此实现了无线接入设备 IP地址的自动获取, 而且利用 DHCP分配地 址更为灵活, DHCP还可以下发无线接入设备的信令地址等信息。 方式二, 如图 8所示, 通过 SeGW分配地址, 该过程丽 S系统需要将 ESN 号对应的 S-SeGW的地址预先规划好, 包括:
歩骤 S801至歩骤 S804同上述实施例中的歩骤 S601至歩骤 S604。
歩骤 S805,无线接入设备在 IPSec隧道上向 DHCP服务器发送请求分配临 时管理 IP地址请的请求消息, 该请求消息为广播消息。
歩骤 S806,无线接入设备利用所述临时管理 IP地址主动向丽 S系统发出 请求 S-SeGW地址的消息。
歩骤 S807, 丽 S系统根据相关信息为无线接入设备分配 S-SeGW, 并将该 S-SeGW的地址回复到无线接入设备;该过程中也可以附带下发其他配置参数, 如使用场景, ASN-GW (Access Service Network-Gateway, 接入服务网络-网 关) 地址等信息。
歩骤 S808、 无线接入设备与上述分配的提供服务的安全网关进行密钥交 换协商, 获取 OM IP地址并建立 IPSec隧道; 如果 P_SeGW和 S_SeGW是同一 个, 该过程可以选择简化, 直接使用歩骤 S802至歩骤 S804歩信息就可以了, 不需要重新申请 OM IP地址。
歩骤 S809、 无线接入设备通过与分配的提供服务的安全网关进行密钥交 换协商完成接入认证。
歩骤 S810、拆除与 P-SeGW的临时 IPSec , P-SeGW回收临时管理 IP地址; 该过程可以和歩骤 S807、 歩骤 S808同时进行。
如图 9所示本发明实施例方式二的另一流程图, 包括:
歩骤 S901至歩骤 S904同上述实施例中的歩骤 S701至歩骤 S704。
作为可选的, 歩骤 S905 , 当歩骤 S901中预置的地址为丽 S的域名, 则使 用临时 OM IP地址和无线接入设备预置的丽 S域名去运营商内部 CN-DNS查询 NMS的地址。
歩骤 S906, 无线接入设备主动向丽 S系统发出请求 S-SeGW地址的消息。 歩骤 S907, 丽 S系统根据相关信息为无线接入设备分配 S-SeGW, 并将该 S-SeGW的地址回复到无线接入设备;该过程中也可以附带下发其他配置参数, 如使用场景, ASN-GW (Access Service Network-Gateway, 接入服务网络-网 关) 地址等信息。
歩骤 S908, 无线接入设备与上述分配的安全网关进行密钥交换协商, 建 立 IPSec隧道, 获取 OM IP地址; 如果 P_SeGW和 S_SeGW是同一个, 该过程 可以选择简化, 直接使用歩骤 S902至歩骤 S904歩信息就可以了, 不需要重 新申请 OM IP地址。 S-SeGW向无线接入设备分配管理 IP地址。
歩骤 S909, 无线接入设备通过与分配的安全网关进行密钥交换协商完成 接入认证;
歩骤 S910, 释放 P-SeGW分配的 IP地址, 需要拆除临时 IPSec; 该过程 可以和歩骤 S908、 歩骤 S909同时进行。
通过上述歩骤, 无线接入设备利用预配置的安全网关提供的临时管理 IP 地址向丽 S系统发送获取提供服务的安全网关的请求, 并接收丽 S系统为其 分配的提供服务的安全网关, 通过与该提供服务的安全网关进行协商获得永 久管理地址, 由此实现了无线接入设备通过安全网关自动获取 IP地址, 而且 该方法对组网的依赖小。 通过上述方式完成无线接入设备地址和安全网关地址的获取过程后, 还 可以进行网络自动匹配的过程, 该过程丽 S系统需要将 ESN号对应的无线接 入设备使用场景、 ASN-GW地址、 企业 IPSec 使用情况等预先规划好, 如图 10所示, 包括:
歩骤 S1001、 丽 S向无线接入设备主动下发 ASN-GW地址等信息; 丽 S通过上述四种方式联系无线接入设备到之后, 主动下发 ASN-GW地址 等信息,该信息可以在临时 IPSec里面传输也可以在永久的 IPSec里面传输, 消息下发的过程可以包含在丽 S系统第一次联系无线接入设备的时候, 也可 以通过多次交互最终由丽 S系统下发给无线接入设备。
信息的内容包括:无线接入设备的 BSID,无线接入设备使用场景选择(用 户面布置 ASN-GW还是核心域布置 ASN-GW, 前者属于企业应用, 后者属于热 点地区应用和信号补盲应用), 是否需要建立 R6 的 IPSec (是的话还包含 IPSec密钥下发), ASN-GW地址 (也可以包含邻区 ASN-GW的 GWID和地址) 等; 该过程也可以下发无线接入设备的信令地址和业务地址;
歩骤 S1002、 无线接入设备判断是否需要建立 IPSec; 如果歩骤 S601 中 下发的信息中是否携带需要建立加密通道的指示以及在建立加密通道时提供 加密通道的密钥, 则判断建立加密通道; 如果是用户面布置 ASN-GW的场景, 选择是否建立 IPSec可以满足不同企业的安全需求;如果是核心域布置 ASN-GW 的场景, 不需要建立 IPSec , 直接使用临时建立的 IPSec通道。 该过程根据场 景和不同的企业需求来判断, 特别需要注意的是无线接入设备信令 IP地址的 选择是根据场景选择来判断的。
歩骤 S1003、 无线接入设备判断使用场景, 使用不同的信令 IP地址去联 系 ASN- GW;
如果是用户面布置 ASN-GW 的场景, 使用企业网分配的 IP 地址联系 ASN-GW; 如果是核心域布置 ASN-GW的场景, 使用丽 S系统下发的信令地址 (该地址可以同无线接入设备的业务地址或 0M地址) 联系 ASN-GW。
在用户面布置 ASN-GW的场景下, 如果丽 S系统和 ASN-GW之间无法直接 通信(如 ASN-GW和 NMS系统属于不同厂商或者 NMS系统穿越公网管理 ASN-GW, 对组网要求太多), 则无线接入设备可以选择构造 R6新的消息联系 ASN-GW, 带上无线接入设备 BSID和 BSIP的绑定关系 (也可以选择是否需要带上邻区 ASNGW的 GWID和 GW地址等信息, 也可以选择是否带上邻区 BSID的信息), ASN-GW收到该消息后, 记录绑定关系, 后续消息在 GW上面可以正常转发到 BS。 如果丽 S系统和 ASN-GW之间可以直接通信, 则可以由 NMS系统直接下发 消息给 ASN-GW, 完成配置。 该过程结束后, 无线接入设备可以进行后续自动 网规网优等歩骤。
本发明实施例提供的方法按照 ASN-GW处于用户面还是核心域的兼容场景 来考虑。 当 ASN-GW处于用户面时, 主要解决企业应用时, 企业内部业务流直 接可以通过 ASN-GW路由回企业内部,不需要穿越 Internet的问题。当 ASN-GW 处于核心域时, 主要解决 ASN-GW统一管理整网无线接入设备(包括宏基站和 小型基站) 的问题。 并且, 在一个网络里面 ASN-GW可以是多个, 这两种场景 也是可以同时并存的。 本发明实施例还提供了一种网络设备, 如图 11所示, 包括:
第一发送模块 1103,用于通过预配置的安全网关向 IP地址分配单元发送 请求消息, 以请求 IP地址分配单元分配管理 IP地址。 第一接收模块 1104, 用于接收所述 IP地址分配单元回复的响应信息, 所 述响应信息中携带为无线接入设备分配的管理 IP地址。
该网络设备还可以包括:
第一协商模块 1101, 用于根据预配置的安全网关的地址, 与所述预配置 的安全网关进行密钥交换协商, 建立临时加密通道。 所述第一发送模块 1103 通过与所述预配置的安全网关之间的临时加密通道向 IP地址分配单元发送请 求消息。
第一获取模块 1102,用于通过所述第一协商模块 1101进行的密钥交换协 商, 获取临时管理 IP地址。
上述第一发送模块 1103还用于以所述临时管理 IP地址为源地址, 以预 配置的以预配置的 IP地址分配单元地址为目的地址, 发送请求分配管理 IP 地址的信息。
该网络设备还可以包括:
第一释放模块 1105, 用于释放临时管理 IP地址。
上述第一获取模块 1102还用于当预配置的 IP地址分配单元地址为域名 地址时, 获取核心网域名服务器的地址。
该网络设备还可以包括:
第一加密通道拆除模块 1106,用于拆除所述第一协商模块 1101建立的临 时加密通道。
上述第一接收模块 1104接收的报文中还携带提供服务的安全网关的 IP 地址, 所述提供服务的安全网关由 IP地址分配单元或网元管理系统指定并为 其分配 IP地址。
上述网络设备还包括:
第二协商模块 1107,用于根据所述第一接收模块 1104接收的报文中携带 的提供服务的安全网关的地址, 与所述提供服务的安全网关进行密钥交换协 商, 建立加密通道。 本发明实施例提供的网络设备的类型包括: 基站或基站控制器。
通过本发明实施例提供的网络设备, 第一发送模块利用第一获取模块获 取的临时管理 IP地址向 IP地址分配单元请求分配管理 IP地址, 并利用第一 接收模块接收 ip地址分配单元回复的管理 ip地址, 由此利用上述模块实现 了无线接入设备自动获取管理 IP地址。 本发明实施例还提供了一种网络设备, 如图 12所示, 包括:
第二发送模块 1203,用于通过预配置的安全网关向 IP地址分配单元发送 请求消息, 以请求 IP地址分配单元返回提供服务的安全网关地址的信息。
第二接收模块 1204, 用于接收所述 IP地址分配单元回复的响应信息, 所 述信息中携带为无线接入设备分配的提供服务的安全网关 IP地址, 并获取所 述提供服务的安全网关分配的管理 IP地址。
该网络设备还包括:
第三协商模块 1201, 用于根据预配置的安全网关的地址, 与所述预配置 的安全网关进行密钥交换协商, 建立临时加密通道。 所述第二发送模块 1203 通过与所述预配置的安全网关之间的临时加密通道向 IP地址分配单元发送请 求消息。
第四协商模块 1205,用于与所述提供服务的安全网关进行密钥交换协商, 建立加密通道。
第二获取模块 1202,用于通过所述第三协商模块 1201进行的密钥交换协 商, 获取临时管理 IP地址;
上述第二发送模块 1203还用于以所述临时管理 IP地址为源地址, 以预 配置的 IP地址分配单元地址为目的地址, 发送请求服务的安全网关地址的信 息。
该网络设备还包括:
第二释放模块 1206, 用于释放临时的管理地址。 上述第二获取模块 1202还用于当预配置的 IP地址分配单元地址为域名 地址时, 获取核心网域名服务器的地址。
该网络设备还包括:
第二加密通道拆除模块 1207,用于拆除所述第三协商模块 1201建立的临 时加密通道。
通过本发明实施例提供的网络设备, 第三发送模块利用第三获取模块获 取的临时管理 IP地址向 IP地址分配单元发送获取提供服务的安全网关的请 求, 并接收 IP地址分配单元为其分配的提供服务的安全网关, 通过第四协商 模块与该提供服务的安全网关进行协商获得管理地址, 由此实现了无线接入 设备通过安全网关自动获取 IP地址, 而且该方法对组网的依赖小。 本发明实施例还提供了一种网络设备, 如图 13所示, 包括:
信息接收模块 1301, 用于接收来自网元管理单元的信息;
信息判断模块 1302, 用于根据所述信息接收模块 1301接收的信息, 判断 应用场景;
信息处理模块 1303, 用于根据所述应用场景相应的信令 IP地址, 将无线 接入设备识别码与无线接入设备 IP的绑定关系通知网关, 所述无线接入设备 被所述网关所控制。
该网络设备还包括:
第二信息判断模块 1304,用于在所述信息判断模块 1302判断应用场景前, 根据所述信息接收模块 1301接收的信息判断是否需要建立加密通道;
第二信息处理模块 1305, 用于在所述第二信息判断模块 1304判断需要建 立加密通道时, 建立加密通道, 所述信息处理模块与网关之间的通信在所述 该加密通道中进行。
上述实施例中提供的网络设备的类型包括: 基站或基站控制器。
通过本发明实施例提供的网络设备, 信息判断模块根据信息接收模块接 收的信息判断应用场景, 然后信息处理模块根据应用场景进行不同的安全策 略和处理流程, 由此可以使无线接入设备兼容不同的应用场景。 本发明实施例还提供了一种网络系统, 如图 14所示, 包括:
无线接入设备 1401,用于通过预配置的安全网关向 IP地址分配单元 1402 发送请求消息, 以请求 IP地址分配单元 1402分配管理 IP地址; 接收所述 IP 地址分配单元 1402 回复的响应信息, 所述响应信息中携带为无线接入设备
1401分配的管理 IP地址。
IP地址分配单元 1402, 用于根据所述请求消息生成携带管理 IP地址的 响应信息。
预配置的安全网关 1403,用于将所述无线接入设备 1401的请求消息发送 给所述 IP地址分配单元 1402, 并将所述携带管理 IP地址的响应信息返回给 所述无线接入设备 1401。
其中, 所述无线接入设备 1401还可以在与预配置的安全网关 1403建立临 时加密通道后获取临时管理 IP地址; 以所述临时管理 IP地址为源地址, 以预 配置的 IP地址分配单元地址为目的地址, 向 IP地址分配单元 1020发送请求分 配管理 IP地址的信息。
作为本发明的一个实施例, 所述无线接入设备 1401还用于, 根据预配置 的安全网关 1403的地址, 与所述预配置的安全网关 1403进行密钥交换协商, 建立临时加密通道; 通过与所述预配置的安全网关之间的临时加密通道向 IP 地址分配单元发送请求消息。
该网络系统, 还包括:
核心网域名服务器 1404, 用于接收来自所述无线接入设备 1401获取所述 I P地址分配单元 IP地址的信息, 并向所述无线接入设备 1401回复所述 IP地址分 配单元的 IP地址;
提供服务的安全网关 1405, 用于与所述无线接入设备 1401进行密钥交换 协商, 完成所述无线接入设备的接入认证。
上述预配置的安全网关 1403与提供服务的安全网关 1405可以集成在一 起, 也可以作为独立的个体分离使用; 而且预配置的安全网关 1403或提供服 务的安全网关 1405可以与无线接入设备 1401集成在一起。
无线接入设备通过与预配置的安全网关进行协商获取临时管理 IP地址, 再以该临时管理 IP地址为源地址向 IP地址分配单元请求分配管理 IP地址, 由此实现了无线接入设备自动获取管理 IP地址, 而且 IP地址分配单元还可 以下发无线接入设备业务地址等信息。 本发明实施例还提供了一种网络系统, 如图 15所示, 包括:
无线接入设备 1501, 用于通过预配置的安全网关向 IP地址分配单元 1502 发送请求消息, 以请求 IP地址分配单元 1502返回提供服务的安全网关地址的 信息; 接收所述 IP地址分配单元 1502回复的响应信息, 所述信息中携带为无 线接入设备分配的提供服务的安全网关 IP地址。
IP地址分配单元 1502, 用于接收来自所述无线接入设备 1501的请求返回 提供服务的安全网关 1505地址的信息, 向所述无线接入设备 1501回复携带提 供服务的安全网关 1505IP地址的响应信息。
预配置的安全网关 1503, 用于将所述无线接入设备 1501的请求消息发送 给所述 IP地址分配单元 1502, 并将所述携带提供服务的安全网关 1505IP地址 的响应信息返回给所述无线接入设备 1501。
提供服务的安全网关 1505, 用于为所述无线接入设备 1501分配管理 IP地 址。
所述无线接入设备 1501还用于, 根据预配置的安全网关 1503的地址, 与 所述预配置的安全网关 1503进行密钥交换协商, 建立临时加密通道; 通过与 所述预配置的安全网关之间的临时加密通道向 IP地址分配单元 1502发送请求 消息。 还用于, 与所述提供服务的安全网关 1505进行密钥交换协商, 建立加 密通道。
该网络系统还包括:
核心网域名服务器 1504, 用于接收来自所述无线接入设备 1501获取所述 I P地址分配单元 IP地址的信息, 并向所述无线接入设备 1501回复所述 IP地址分 配单元的 IP地址;
预配置的安全网关 1503, 用于与所述无线接入设备 1501进行密钥交换协 商, 向所述无线接入设备 1501提供临时管理 IP地址。
上述预配置的安全网关 1503与提供服务的安全网关 1505可以集成在一 起, 也可以作为独立的个体分离使用; 而且预配置的安全网关 1503或提供服 务的安全网关 1505可以与无线接入设备 1501集成在一起。
无线接入设备通过与预配置的安全网关进行协商获取临时管理 IP地址, 再以该临时管理 IP地址为源地址向 IP地址分配单元请求分配提供服务的安 全网关的地址,然后通过与提供服务的安全网关进行协商,获取管理 IP地址, 由此实现了无线接入设备自动获取管理 IP地址。 预配置的安全网关有可能就 是提供服务的安全网关, 那么临时管理 IP地址即可作为管理 IP地址来使用。 本发明实施例还提供了一种网络系统, 如图 16所示, 包括
网络管理单元 1602, 用于向无线接入设备 1601发送信息;
无线接入设备 1601, 用于接收来自所述网元管理单元 1602的信息; 根据 所述信息判断应用场景; 根据所述应用场景相应的信令 IP地址, 将无线接入 设备识别码与无线接入设备 IP的绑定关系通知网关, 所述无线接入设备 1601 被所述网关所控制;
网络管理单元 1602, 用于向所述无线接入设备 1601下发信息。
上述网络管理单元 1602下发的信息中包括应用场景、 或接入服务网络-网 关地址、 或无线接入设备识别码、 或信令地址、 或业务地址、 或邻区的接入 服务网络 -网关 GW ID和地址; 若所述信息中携带需要建立加密通道的指示以 及在建立加密通道时提供加密通道的密钥, 则无线接入设备建立加密通道。 无线接入设备根据网元管理单元下发的信息判断应用场景, 并根据应用 场景进行不同的安全策略和处理流程, 由此可以使无线接入设备兼容不同的 应用场景。
通过本发明实施例提供的方法和装置实现了在常用组网情况下无线接入 设备即插即用功能的 IP地址自动发现的过程, 主要包括 P_SeGW、 S-SeGW, M2000/DHCP Server, ASN-GW等网元的地址自动发现的过程, 以及无线接入设 备获得自身信令网管等 IP地址的过程。 而且在即插即用的前提下可兼容无线 接入设备的两种主要使用场景。
本发明实施例提供的方法对组网的依赖较小, 对 WiMAX 的网管及无线接 入设备网元以外的设备要求少, 可实施性强, 如果局方没有特殊要求的话, 甚至 ASN-GW和 AAA等设备都可以不需要网管统一管理, 就能实现自动获取管 理地址过程。 信令和数据交互都可以采用 IPSec 加密, 并且在无线接入设备 即插即用前提下可以满足不同企业用户和热点地区用户的不同加密策略。 该 过程中无线接入设备的认证可以采用 EAP-TLS的方法, 满足 WiMAX的现状, 后续终端认证也可以是基于数字证书的认证。
本发明实施例提供的方法歩骤之后还可以进行 WiMAX PICO的自动配置、 自动网规网优等, 为无线接入设备下面的用户实现自动入网提供了先决条件。
本发明实施例提供的方法可应用于其他接入点设备实现自动接入网络和 自动配置下发的流程, 如 UMTS AP, WiMAX Femto基站、 WiMAX宏基站等设备。
通过本发明实施例提供的方法和网络设备, 根据预配置的安全网关的地 址, 与预配置的安全网关进行密钥交换协商, 获取分配的临时管理 IP地址; 以所述临时管理 IP地址为源地址, 以预先配置的动态主机配置协议服务器地 址为目的地址, 发送请求分配管理 IP地址和服务安全网关的信息, 或以所述 临时管理 IP地址为源地址, 以预先配置的网元管理系统地址为目的地址, 发 送请求分配服务的安全网关地址的信息, 而后向服务的安全网关请求分配管 理 IP地址。 由此可以使无线接入设备上电后获得自动分配的管理地址。
同时无线接入设备接收到网元管理单元下发的信息后, 根据信息判断无 线接入设备的应用场景, 然后使用与应用场景相应的信令 IP地址通知接入服 务网络-网关所控制的无线接入设备识别码与无线接入设备 IP 的绑定关系, 由此使系统可以根据不同的应用场景采取不同的安全策略和处理流程, 使无 线接入设备兼容不同的应用场景, 灵活性更高。
本领域普通技术人员可以理解: 实现上述方法实施例的全部或部分歩骤 可以通过程序指令相关的硬件来完成, 前述的程序可以存储于一计算机可读 取存储介质中, 该程序在执行时, 执行包括上述方法实施例的歩骤, 而前述 的存储介质包括: R0M、 RAM, 磁碟或者光盘等各种可以存储程序代码的介质。
以上所述的具体实施方式, 对本发明的目的、 技术方案和有益效果进行 了进一歩详细说明, 所应理解的是, 以上所述仅为本发明的具体实施方式而 已, 并不用于限定本发明的保护范围, 凡在本发明的精神和原则之内, 所做 的任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。

Claims

权 利 要 求 书
1、 一种无线接入设备获取管理地址的方法, 其特征在于, 包括: 通过预配置的安全网关向 IP地址分配单元发送请求消息,以请求所述 IP 地址分配单元分配管理 IP地址;
接收来自所述 ip地址分配单元的响应信息, 所述响应信息中携带为无线 接入设备分配的管理 IP地址。
2、 如权利要求 1所述的方法, 其特征在于, 所述通过预配置的安全网关 向 IP地址分配单元发送请求消息之前包括:
根据预配置的安全网关的地址, 与所述预配置的安全网关进行密钥交换 协商, 建立临时加密通道, 通过与所述预配置的安全网关之间的临时加密通 道向 IP地址分配单元发送请求消息。
3、 如权利要求 2所述的方法, 其特征在于, 所述发送的请求消息为请求 分配管理 IP地址的广播消息。
4、 如权利要求 2所述的方法, 其特征在于, 在所述建立临时加密通道后 还包括获取临时管理 IP地址;
所述通过与所述预配置的安全网关的所述临时加密通道向 IP地址分配单 元发送请求消息包括:
以所述临时管理 IP地址为源地址, 以预配置的 IP地址分配单元地址为 目的地址, 发送请求分配管理 IP地址的消息。
5、 如权利要求 4所述的方法, 其特征在于, 还包括:
获取核心网域名服务器的地址;
当预配置的 IP地址分配单元地址为域名地址时, 根据所述核心网域名服 务器地址查询所述预配置的 IP地址分配单元的 IP地址。
6、 如权利要求 3或 4所述的方法, 其特征在于, 在所述 IP地址分配单 元接收到所述请求分配管理 IP地址的消息之后, 通知网元管理系统为该请求 的无线接入设备分配管理 IP地址。
7、 如权利要求 3或 4所述的方法, 其特征在于, 所述来自 IP地址分配 单元的响应信息中还携带提供服务的安全网关的 IP地址, 所述提供服务的安 全网关由 IP地址分配单元或网元管理系统指定并为其分配 IP地址。
8、 如权利要求 3或 4所述的方法, 其特征在于, 所述预配置的 IP地址 分配单元回复的响应信息中还携带无线接入设备的信令地址或业务地址, 网 络匹配时以所述信令地址或业务地址为源地址与网关进行通信。
9、 一种无线接入设备获取管理地址的方法, 其特征在于, 包括: 通过预配置的安全网关向 IP地址分配单元发送请求消息,以请求所述 IP 地址分配单元返回提供服务的安全网关地址的信息;
接收来自所述 IP地址分配单元的响应信息, 所述信息中携带为无线接入 设备分配的提供服务的安全网关 IP地址;
从所述提供服务的安全网关获取管理 IP地址。
10、 如权利要求 9所述的方法, 其特征在于, 通过预配置的安全网关向 IP地址分配单元发送请求消息之前包括:
根据预配置的安全网关的地址, 在与所述预配置的安全网关进行密钥交 换协商, 建立临时加密通道, 通过与所述预配置的安全网关之间的临时加密 通道向 IP地址分配单元发送请求消息;
在从所述提供服务的安全网关获取管理 IP地址中还包括:
与所述提供服务的安全网关进行密钥交换协商, 建立加密通道。
11、 如权利要求 10所述的方法, 其特征在于, 通过与所述预配置的安全 网关之间的临时加密通道向 IP地址分配单元广播请求消息。
12、 如权利要求 10所述的方法, 其特征在于, 在根据预配置的安全网关 的地址, 与所述预配置的安全网关进行密钥交换协商, 建立临时加密通道之 后还包括, 获取临时管理 IP地址;
通过与所述预配置的安全网关的所述临时加密通道向 IP地址分配单元发 送请求消息中包括, 以所述临时管理 IP地址为源地址, 以预配置的 IP地址 分配单元地址为目的地址, 发送请求返回提供服务的安全网关地址的信息。
13、 如权利要求 12所述的方法, 其特征在于, 还包括:
获取核心网域名服务器的地址;
当预配置的 IP地址分配单元地址为域名地址时, 根据所述核心网域名服
14、 一种网络设备, 其特征在于, 包括:
第一发送模块, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元分配管理 IP地址;
第一接收模块, 用于接收所述 IP地址分配单元回复的响应信息, 所述响 应信息中携带为无线接入设备分配的管理 IP地址。
15、 如权利要求 14所述的网络设备, 其特征在于, 还包括: 第一协商模 块, 用于根据预配置的安全网关的地址, 与所述预配置的安全网关进行密钥 交换协商, 建立临时加密通道; 所述第一发送模块通过与所述预配置的安全 网关之间的临时加密通道向 IP地址分配单元发送请求消息。
16、 如权利要求 15所述的网络设备, 其特征在于, 还包括: 第一获取模 块, 用于在所述第一协商模块建立临时加密通道后获取临时管理 IP地址; 所述第一发送模块, 还用于以所述临时管理 IP地址为源地址, 以预配置 的以预配置的 IP地址分配单元地址为目的地址, 发送请求分配管理 IP地址 的信息。
17、 如权利要求 16所述的网络设备, 其特征在于, 所述第一获取模块还 用于当预配置的 IP地址分配单元地址为域名地址时, 获取核心网域名服务器 的地址。
18、 如权利要求 16所述的网络设备, 其特征在于, 所述第一接收模块接 收的报文中还携带提供服务的安全网关的 IP地址, 所述提供服务的安全网关 由 IP地址分配单元或网元管理系统指定并为其分配 IP地址。
19、 如权利要求 18所述的网络设备, 其特征在于, 还包括:
第二协商模块, 用于根据所述第一接收模块接收的报文中携带的提供服 务的安全网关的地址, 与所述提供服务的安全网关进行密钥交换协商, 建立 加密通道。
20、 一种网络设备, 其特征在于, 包括:
第二发送模块, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元返回提供服务的安全网关地址的信息;
第二接收模块, 用于接收所述 IP地址分配单元回复的响应信息, 所述信 息中携带为无线接入设备分配的提供服务的安全网关 IP地址, 并获取所述提 供服务的安全网关分配的管理 IP地址。
21、 如权利要求 20所述的网络设备, 其特征在于, 还包括: 第三协商模 块和第四协商模块;
所述第三协商模块, 用于根据预配置的安全网关的地址, 与所述预配置 的安全网关进行密钥交换协商, 建立临时加密通道; 所述第二发送模块通过 与所述预配置的安全网关之间的临时加密通道向 IP地址分配单元发送请求消 息;
所述第四协商模块, 用于与所述提供服务的安全网关进行密钥交换协商, 建立加密通道。
22、 如权利要求 21所述的网络设备, 其特征在于, 还包括: 第二获取模 块, 用于在所述第三协商模块建立临时加密通道后获取临时管理 IP地址; 所述第二发送模块, 还用于以所述临时管理 IP地址为源地址, 以预配置 的 IP地址分配单元地址为目的地址, 发送请求服务的安全网关地址的信息。
23、 如权利要求 22所述的网络设备, 其特征在于, 所述第二获取模块还 用于当预配置的 IP地址分配单元地址为域名地址时, 获取核心网域名服务器 的地址。
24、 一种网络设备, 其特征在于, 包括:
信息接收模块, 用于接收来自网元管理单元的信息;
信息判断模块, 用于根据所述信息接收模块接收的信息, 判断应用场景; 信息处理模块, 用于根据所述应用场景相应的信令 IP地址, 将无线接入 设备识别码与无线接入设备 IP的绑定关系通知网关, 所述无线接入设备被所 述网关所控制。
25、 如权利要求 24所述的网络设备, 其特征在于, 还包括:
第二信息判断模块, 用于在所述信息判断模块判断应用场景前, 根据所 述信息接收模块接收的信息判断是否需要建立加密通道;
第二信息处理模块, 用于在所述第二信息判断模块判断需要建立加密通 道时, 建立加密通道, 所述信息处理模块与网关之间的通信在所述该加密通 道中进行。
26、 一种网络系统, 其特征在于, 包括:
无线接入设备, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元分配管理 IP地址; 接收所述 IP地址分配单元 回复的响应信息, 所述响应信息中携带为无线接入设备分配的管理 IP地址;
IP地址分配单元, 用于根据所述请求消息生成携带管理 IP地址的响应信 息;
预配置的安全网关, 用于将所述无线接入设备的请求消息发送给所述 IP 地址分配单元, 将所述携带管理 IP地址的响应信息返回给所述无线接入设备。
27、 如权利要求 26所述的网络系统, 其特征在于, 所述无线接入设备还 用于, 根据预配置的安全网关的地址, 与所述预配置的安全网关进行密钥交 换协商, 建立临时加密通道; 通过与所述预配置的安全网关之间的临时加密 通道向 IP地址分配单元发送请求消息。
28、 如权利要求 27所述的网络系统, 其特征在于, 所述预配置的安全网 关, 还用于生成临时管理 IP地址返回给所述无线接入设备;
所述无线接入设备还用于以所述临时管理 IP地址为源地址, 以预配置的 I P地址分配单元地址为目的地址, 向 IP地址分配单元发送请求分配管理 IP地址 的消息。
29、 如权利要求 26所述的网络系统, 其特征在于, 还包括:
核心网域名服务器, 用于接收来自所述无线接入设备获取所述 IP地址分 配单元 IP地址的信息, 向所述无线接入设备回复所述 IP地址分配单元的 IP地 址;
提供服务的安全网关, 用于与所述无线接入设备进行密钥交换协商, 建 立加密通道, 完成所述无线接入设备的接入认证。
30、 一种网络系统, 其特征在于, 包括:
无线接入设备, 用于通过预配置的安全网关向 IP地址分配单元发送请求 消息, 以请求 IP地址分配单元返回提供服务的安全网关地址的信息; 接收所 述 IP地址分配单元回复的响应信息, 所述信息中携带为无线接入设备分配的 提供服务的安全网关 IP地址;
IP地址分配单元, 用于接收来自所述无线接入设备的请求返回提供服务 的安全网关地址的信息, 向所述无线接入设备回复携带提供服务的安全网关 I P地址的响应信息;
所述预配置的安全网关, 用于将所述无线接入设备的请求消息发送给所 述 IP地址分配单元, 并将所述携带提供服务的安全网关 IP地址的响应信息返 回给所述无线接入设备;
所述提供服务的安全网关, 用于为所述无线接入设备分配管理 IP地址。
31、 如权利要求 30所述的网络系统, 其特征在于, 还包括: 核心网域名服务器, 用于接收来自所述无线接入设备获取所述 IP地址分 配单元 IP地址的信息, 向所述无线接入设备回复所述 IP地址分配单元的 IP地 址。
32、 一种网络系统, 其特征在于, 包括:
网络管理单元, 用于向无线接入设备发送信息;
无线接入设备, 用于接收来自所述网元管理单元的信息; 根据所述信息 判断应用场景; 根据所述应用场景相应的信令 IP地址, 将无线接入设备识别 码与无线接入设备 IP的绑定关系通知网关, 所述无线接入设备被所述网关所 控制。
33、 如权利要求 32所述的网络系统, 其特征在于, 所述网络管理单元向 所述无线接入设备发送的信息包括: 应用场景、 或网关地址、 或无线接入设 备识别码、 或信令地址、 或业务地址、 或邻区的网关标识或地址。
PCT/CN2009/074138 2008-09-24 2009-09-23 一种无线接入设备获取管理地址的方法和网络设备 WO2010037337A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200810211736.8 2008-09-24
CN200810211736.8A CN101686266B (zh) 2008-09-24 2008-09-24 一种无线接入设备获取管理地址的方法和网络设备

Publications (1)

Publication Number Publication Date
WO2010037337A1 true WO2010037337A1 (zh) 2010-04-08

Family

ID=42049234

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/074138 WO2010037337A1 (zh) 2008-09-24 2009-09-23 一种无线接入设备获取管理地址的方法和网络设备

Country Status (2)

Country Link
CN (1) CN101686266B (zh)
WO (1) WO2010037337A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3310078A4 (en) * 2015-11-30 2018-05-30 Huawei Technologies Co., Ltd. Communication method, small cell base station, small cell base station controller, terminal and system

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2599257A1 (en) * 2010-07-30 2013-06-05 Hewlett-Packard Development Company, L.P. Systems and methods for credentialing
CN102752298B (zh) * 2012-06-29 2015-04-29 华为技术有限公司 安全通信方法、终端、服务器及系统
CN107317851A (zh) * 2017-06-20 2017-11-03 江苏科技大学 一种基于软件定义网络的安全通信方法
CN107864162B (zh) * 2017-12-22 2019-12-17 烽火通信科技股份有限公司 融合网关双系统及其通信安全保护方法
CN112333014B (zh) * 2020-10-26 2022-08-02 中国联合网络通信集团有限公司 设备管理方法及通信装置
CN114040514B (zh) * 2021-12-08 2024-01-12 中国联合网络通信集团有限公司 一种通信方法及设备
CN114244699A (zh) * 2021-12-16 2022-03-25 中国电信股份有限公司 用户面功能接入方法、服务器、系统和网络设备
CN114465985A (zh) * 2022-02-14 2022-05-10 中国电信股份有限公司 网络配置方法、装置、系统、电子设备及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2004075510A1 (en) * 2003-02-18 2004-09-02 Qualcomm Incorporated Provisioning server information in a mobile station
WO2005067265A1 (en) * 2003-12-31 2005-07-21 Intel Corporation Zero-configuring ip addresses for peer-to-peer networks
CN1780244A (zh) * 2004-11-18 2006-05-31 中兴通讯股份有限公司 基于动态主机配置协议加网络门户认证的安全接入方法
CN1937632A (zh) * 2005-09-23 2007-03-28 中兴通讯股份有限公司 一种应用于宽带无线接入系统中地址分配方法
CN101136946A (zh) * 2006-08-31 2008-03-05 华为技术有限公司 基站ip地址分配系统及方法、基站、接入服务网络网关

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008015880A (ja) * 2006-07-07 2008-01-24 Fuji Xerox Co Ltd ネットワークシステム、画像処理装置、およびコンピュータプログラム

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2004075510A1 (en) * 2003-02-18 2004-09-02 Qualcomm Incorporated Provisioning server information in a mobile station
WO2005067265A1 (en) * 2003-12-31 2005-07-21 Intel Corporation Zero-configuring ip addresses for peer-to-peer networks
CN1780244A (zh) * 2004-11-18 2006-05-31 中兴通讯股份有限公司 基于动态主机配置协议加网络门户认证的安全接入方法
CN1937632A (zh) * 2005-09-23 2007-03-28 中兴通讯股份有限公司 一种应用于宽带无线接入系统中地址分配方法
CN101136946A (zh) * 2006-08-31 2008-03-05 华为技术有限公司 基站ip地址分配系统及方法、基站、接入服务网络网关

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3310078A4 (en) * 2015-11-30 2018-05-30 Huawei Technologies Co., Ltd. Communication method, small cell base station, small cell base station controller, terminal and system

Also Published As

Publication number Publication date
CN101686266B (zh) 2014-07-09
CN101686266A (zh) 2010-03-31

Similar Documents

Publication Publication Date Title
WO2010037337A1 (zh) 一种无线接入设备获取管理地址的方法和网络设备
KR100907507B1 (ko) 무선 랜 단말의 bwa 네트워크 연동시 사용자 인증 방법및 그 시스템
JP4769815B2 (ja) 未知の無線端末のための制限付きwlanアクセス
CN106576242B (zh) 对于异构网络有效的用户设备标识
US20170026896A1 (en) Terminal device, relay terminal device, and communication control method
KR102164823B1 (ko) 통합 코어 망 서비스 이용방법과 이를 위한 통합 제어장치 및 그 시스템
US20120269162A1 (en) Method, radio system, mobile terminal and base station for providing local breakout service
CN108307391B (zh) 一种终端接入方法和系统
US20060285519A1 (en) Method and apparatus to facilitate handover key derivation
JP2012504898A (ja) ホーム基地局を備えた通信システムにおけるトラフィックの管理方法及び構成
CN1989756A (zh) 用于pana的独立于媒体的预认证支持的框架
JP2004266310A (ja) Wlan相互接続におけるサービス及びアドレス管理方法
TW201720216A (zh) 用於使用支援多個連線性和服務上下文的安全模型的無線通訊的方法和裝置
CN112788782B (zh) 一种小基站、小基站系统和小基站系统的开通方法
WO2009129707A1 (zh) 局域网之间发送、接收信息的方法和装置以及通信的系统
JP5536895B2 (ja) 複数のデバイスを含みインターネットに接続されたローカル・ネットワーク内でのipサブネット・アドレスの割当て
KR101727557B1 (ko) 무선통신시스템에서 엘비오 서비스를 제공하기 위한 방법 및 장치
WO2008095433A1 (fr) Procédé, dispositif et système assurant un service d'urgence
WO2016078375A1 (zh) 数据传送方法及装置
WO2018054272A1 (zh) 数据的发送方法和装置、计算机存储介质
WO2011026341A1 (zh) 一种移动ip业务的接入方法和系统
WO2007143950A1 (fr) Appareil et procédé de mise en œuvre de l'amorce du nœud en double pile d'un réseau hétérogène
CN101790146B (zh) 分配地址信息的方法、网络设备和网络系统
WO2008148348A1 (fr) Procédé de communication, système et station de base domestique
KR101065121B1 (ko) 인증과 보안 기능이 강화된 이동 중계 장치 및 이를 이용한패킷 데이터 송수신 방법 및 시스템

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09817251

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09817251

Country of ref document: EP

Kind code of ref document: A1