WO2010130118A1 - 一种对家用基站用户实施鉴权的系统及方法 - Google Patents

一种对家用基站用户实施鉴权的系统及方法 Download PDF

Info

Publication number
WO2010130118A1
WO2010130118A1 PCT/CN2009/073818 CN2009073818W WO2010130118A1 WO 2010130118 A1 WO2010130118 A1 WO 2010130118A1 CN 2009073818 W CN2009073818 W CN 2009073818W WO 2010130118 A1 WO2010130118 A1 WO 2010130118A1
Authority
WO
WIPO (PCT)
Prior art keywords
base station
home base
user
access
authentication
Prior art date
Application number
PCT/CN2009/073818
Other languages
English (en)
French (fr)
Inventor
霍玉臻
周娜
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2010130118A1 publication Critical patent/WO2010130118A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/104Grouping of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/082Access security using revocation of authorisation

Definitions

  • the present invention relates to the field of mobile communications, and in particular, to a system and method for performing authentication on a user of a home base station.
  • the home base station is a small, low-power base station deployed in indoor places such as homes and offices.
  • the main purpose is to provide users with higher service rates and lower the cost of using high-speed services, while making up for existing distributed Insufficient coverage of cellular wireless communication systems.
  • the advantages of home base stations are affordability, convenience, low power output, plug and play, and more.
  • the home base station system is already in the 3GPP, 3rd Generation Partnership Project, 3GPP2, 3rd Generation Partnership Project 2 and Worldwide Interoperability for Microwave Access (WiMAX) The research is carried out in the three major standards.
  • the network architecture of the home base station system in each standard organization is basically the same. This paper uses WiMAX as an example to illustrate the network architecture of the home base station.
  • the home base station system is shown in Figure 1.
  • a security gateway between the home base station and the access gateway.
  • the home base station gateway is introduced.
  • the main functions of the home base station gateway are: verifying the security of the home base station, processing the registration of the home base station, performing operation and maintenance management on the home base station, and configuring and controlling the home base station according to the operator's requirements. , responsible for exchanging data between the core network and the home base station.
  • the home base station can access the access gateway of the core network through the home base station gateway, and at this time, the security gateway and the home base station gateway are combined.
  • the home base station may also directly access the access gateway of the core network without using the home base station gateway.
  • the security gateway may be combined with the access gateway or may be separately configured.
  • an access gateway refers to an ASN GW (Access Service Network Gateway).
  • Self-organizing network server is used to discover/extract a series of operation and maintenance parameters of the home base station without manual intervention, such as the geographical location of the home base station, the wireless environment surrounding the home base station, etc.
  • Providing initialization parameter configuration for the home base station supporting bootstrapping initialization of the home base station, for example, using a certain frequency planning algorithm to provide candidate working frequency points to the home base station, Providing an accessible access gateway and the like for the home base station.
  • the self-organizing network server can also be used to support failure recovery of the home base station and the like.
  • the Closed Subscriber Group is a new concept introduced after the introduction of a home base station.
  • a user or a user inside an enterprise forms a closed user group.
  • the user can access the home base station corresponding to multiple closed user groups by signing with the operator, such as the user's office, home, and the like.
  • the CSG user server is configured to store subscription information of the home base station, such as a user allowed to access the home base station, that is, CSG related information, and provide a stored home base station subscription for the home base station and/or the authentication authorization server. information.
  • home base stations There are three usage modes for home base stations: closed access mode, hybrid access mode, and open mode.
  • closed access mode only the CSG subscription user to which the home base station belongs can access the base station and enjoy the services provided by the base station.
  • the home base station is in the open mode, any carrier subscriber can access the base station, and the home base station at this time is equivalent to the macro base station.
  • the home base station is in the hybrid access mode, any operator subscription or roaming user is also allowed to access, but different levels are classified according to whether the user subscribes to the CSG, that is, the user who signs the CSG is using the hybrid.
  • it has a higher service priority and enjoys better service quality and service categories.
  • the home base station can obtain a list of closed subscriber groups that are allowed to access through the CSG subscriber server on the network side, or the administrator of the home base station can directly modify the list of closed subscriber groups allowed to access on the home base station.
  • the home base station in the closed access mode uses the list to perform access control on the user, and rejects the user who is not authorized to access the closed access mode home base station; the home base station in the hybrid access mode according to the list pair
  • User categories eg, CSG users, non-CSG users
  • the home base station judges whether the user belongs to the CSG list is collectively referred to as access control.
  • the home base station checks whether the user belongs to the CSG list according to the user identifier sent by the terminal.
  • the home base station gateway and the access gateway are combined as an example to describe the home base station performing the access control procedure.
  • the method for performing the access control of the home base station is shown in FIG. 2, and the method specifically includes the following steps:
  • Step 201 Perform air interface parameter synchronization and ranging between the terminal and the home base station.
  • Step 202 The terminal requests to negotiate an authentication capability, such as an authentication policy of the user, and completes capability negotiation with the home base station and the access gateway.
  • Step 203 The access gateway starts an EAP authentication process, and sends a user identity request to the home base station, where the home base station forwards the request to the terminal.
  • Step 204 After receiving the user identification request message, the terminal returns a response message to the home base station, and carries the user identification information.
  • the user identification information is a Network Access Identifier (NAI), an International Mobile Subscriber Identification Number (IMSI), or a Media Access Control (MAC) ID.
  • NAI Network Access Identifier
  • IMSI International Mobile Subscriber Identification Number
  • MAC Media Access Control
  • Step 205 The home base station performs access control on the user according to the user identification information.
  • the closed access mode home base station checks whether the user exists in the CSG list, and if so, allows the user to access, and proceeds to step 206; otherwise, the user access is denied, and the user release process can be initiated.
  • the hybrid access mode home base station checks whether the user exists in the CSG list, and if so, informs the access gateway that the user is a CSG user in the subsequent process. If not, the access gateway is notified to the access gateway in the subsequent process. Non-CSG users.
  • Step 206 The home base station returns a user identifier to the access gateway.
  • This step and step 205 are in no particular order and can occur in parallel with them.
  • Step 207 Perform an access authentication process between the terminal and the authentication authority server.
  • the authentication and authorization server completes the audit of the user's legality and authorizes the user to conduct business.
  • Step 208 After the access authentication process is successfully completed, continue to perform other processes related to user access.
  • the home base station checks whether the user belongs to the CSG list according to the user identifier carried by the terminal (step 205), but in the response replied by the terminal in step 204, the terminal may encapsulate the user's real identity by the authentication protocol in view of security considerations.
  • the home base station needs to parse the authentication encapsulation protocol, resulting in an increase in the operational burden of the base station node, and the efficiency is reduced; in the case where the terminal encrypts and transmits the real identity, the home base station is The user identification information is not parsed and obtained; even if the terminal transmits the user identifier in plain text and is not encapsulated by the authentication message, the user identifier is not verified by the authentication authority server, and thus the correctness of the user identifier cannot be guaranteed, and the air interface is frequently Clear text The real identity of the transmitted user is easily stolen by others, and there is a security risk in the wireless communication system.
  • Encryption Authentication Protocol Encryption Authentication Protocol
  • the technical problem to be solved by the present invention is to provide a system and method for performing authentication on a user of a home base station, which can avoid frequent transmission of the user's real identity in the air interface, reduce the burden on the home base station, and reduce the security risks of the home base station system.
  • the present invention provides a method for authenticating a user of a home base station, the method comprising:
  • the access gateway sends the user identification information, the home base station identifier, and the home base station mode to the authentication authorization server, or the authentication is performed.
  • the authorization server sends to the closed subscriber group CSG subscriber server;
  • the authentication authorization server or the CSG user server determines whether the terminal is allowed to access the home base station, and returns the determination result to the office through the access gateway.
  • a home base station when the home base station is in a hybrid access mode, the authentication authority server or the CSG user server determines user category information of the terminal, and returns the user category information to the access gateway through the access gateway The home base station.
  • the manner in which the authentication authorization server determines whether to allow the terminal to access the home base station or determine the user category information of the terminal is: the authentication authorization server according to the user identification information, the home base station identifier Determining, by the home base station mode, the subscription information that is saved by itself or downloaded from the CSG user server, whether the terminal is allowed to access the home base station or determine the user category information of the terminal;
  • the manner in which the CSG user server determines whether to allow the terminal to access the home base station or determine the user category information of the terminal is: the CSG user server according to the user identification information, the home base station identifier, the home base station The mode and the self-supplied subscription information determine whether the terminal is allowed to access the home base station or determine the user category information of the terminal.
  • the user category information is a CSG user or a non-CSG user.
  • the subscription information is subscription information of a home base station user or subscription information of a home base station. Further, in the step B, when the home base station is in the closed access mode, the authentication authorization server or the CSG user server determines whether the terminal is allowed to access the home base station by:
  • the authentication authorization server determines that the subscription information that is saved by itself or downloaded from the CSG user server is the subscription information of the user of the home base station, if the subscription information includes the home base station identifier, the terminal is allowed to access the home base station. If the subscription information is included in the subscription information, Allowing the terminal to access the home base station, otherwise the terminal is not allowed to access the home base station;
  • the CSG user server determines that the subscription information saved by itself is the subscription information of the home base station user, if the subscription information includes the home base station identifier, the terminal is allowed to access the home base station, otherwise the terminal is not allowed to access the home station.
  • the base station when the CSG user server determines that the subscription information saved by itself is the subscription information of the home base station, if the subscription information includes the user identifier, the terminal is allowed to access the home base station, otherwise the terminal is not allowed to access the home station. Base station.
  • the manner in which the authentication authorization server or the CSG user server determines the user category information of the terminal is: the authentication authorization server determines When the subscription information that is saved by itself or downloaded from the CSG user server is the subscription information of the home base station user, if the subscription information includes the home base station identifier, the user category information is the CSG user, otherwise the user category information.
  • the authentication authorization server determines that the subscription information that is saved by itself or downloaded from the CSG user server is the subscription information of the home base station, if the subscription information includes the user identifier, the user category The information is the CSG user, otherwise the user category information is the non-CSG user; when the CSG user server determines that the subscription information saved by itself is the subscription information of the home base station user, if the subscription information includes the home base station identifier, The user category information is the CSG user, otherwise the user category information is the When the CSG user server determines that the subscription information saved by itself is the subscription information of the home base station, if the subscription information includes the user identifier, the user category information is the CSG user, otherwise the user category information. For the non-CSG user. Further, in the step B, when the home base station is in the closed access mode, the step of the authentication authorization server returning the determination result to the home base station by using the access gateway includes:
  • the authentication authorization server sends a user access accept message to the access gateway after completing the user authentication, and the access gateway accepts according to the user access.
  • the message is forwarded to the home base station by the extended authentication protocol EAP forwarding message, and the home base station forwards the authentication success message to the terminal; or the access gateway forwards the message through the EAP
  • the authentication success message is forwarded to the terminal by the home base station, and sends a key change indication message to the home base station, to notify the user of the home base station that the authentication is successful;
  • the authentication authorization server sends an access reject message to the access gateway, and the access gateway performs the access according to the access
  • the refusal message forwards the authentication failure message to the home base station by using the EAP forwarding message, and the home base station forwards the authentication failure message to the terminal.
  • the step of the authentication authorization server returning the user category information to the home base station by using the access gateway includes: :
  • the authentication authorization server sends a user access accept message carrying the user category information to the access gateway; the access gateway forwards the message according to the user access accept message through the EAP forwarding message. And the right success message is forwarded to the home base station, and the home base station parses the authentication success message and saves the user category information, and then forwards the authentication success message to the terminal by using an EAP forwarding message; or And the gateway forwards the authentication success message to the terminal by using the EAP forwarding message according to the user access accept message, and sends a key change indication message carrying the user category information to the home base station, to notify the The home base station user is successfully authenticated, and the home base station saves the user category information.
  • the step of the CSG user server returning the determination result to the home base station by using the access gateway includes: If the result of the determination indicates that the terminal is allowed to access the home base station, the CSG user server returns an acknowledgement message to the authentication authority server, and the authentication authority server sends the user to the access gateway after completing the user authentication.
  • the access accepting message is forwarded to the home base station by using the EAP forwarding message according to the user access accept message, and the home base station forwards the authentication success message to the home base station Or the access gateway forwards the authentication success message to the terminal through the EAP forwarding message according to the user access accept message, and sends a key change indication message to the home base station, and notifies the The home base station user authentication succeeds;
  • the CSG user server returns a rejection message to the authentication authorization server, and the authentication authorization server terminates the authentication process to the access gateway.
  • the access gateway forwards the authentication failure message to the terminal via the EAP forwarding message according to the access reject message.
  • the step of the CSG user server returning the user category information to the home base station by using the access gateway includes:
  • the CSG user server returns an acknowledgement message carrying the user category information to the authentication authorization server, and the authentication authorization server sends the user access that carries the user category information to the access gateway after completing the user authentication. Accept the message;
  • the access gateway forwards the authentication success message to the home base station by using an EAP forwarding message, where the home base station parses the authentication success message and saves the user category information, and then successfully performs the authentication by using an EAP forwarding message.
  • the message is forwarded to the terminal; or
  • the access gateway forwards the authentication success message to the terminal through the EAP forwarding message, and sends a key change indication message carrying the user category information to the home base station to notify the home base station user If the right is successful, the home base station parses the key change indication message, and saves the user category information.
  • An authentication and authorization server that performs authentication on a user of a home base station, where
  • the authentication authorization server is configured to receive user identification information, a base station identifier, and a home base station sent by the access gateway in the process of the terminal accessing the closed base access mode or the hybrid access mode of the home base station.
  • the authentication authorization server is further configured to: when the home base station is in the closed access mode, determine whether the terminal is allowed to access the home base station, and return the determination result to the home base station by using the access gateway;
  • the authentication authorization server is further configured to determine user category information of the terminal when the home base station is in the hybrid access mode, and return the user category information to the home base station through the access gateway.
  • the authentication authorization server is further configured to: when the home base station is in the closed access mode, download according to the user identification information, the home base station identifier, the home base station mode, and the self-storage or download from the CSG user server.
  • the subscription information determines whether the terminal is allowed to access the home base station, and returns a determination result to the home base station through the access gateway;
  • the authentication authorization server is further configured to: when the home base station is in the hybrid access mode, save or download from the CSG user server according to the user identity information, the home base station identity, the home base station mode, and the self-base station mode
  • the subscription information determines user category information of the terminal, and returns the user category information to the home base station through the access gateway.
  • the authentication authorization server is further configured to determine that the subscription information that is saved by itself or downloaded from the CSG user server is the subscription information of the user of the home base station, if the subscription information includes the home base station identifier, the terminal is allowed to connect. Entering the home base station, otherwise the terminal is not allowed to access the home base station; if it is determined that the subscription information that is saved by itself or downloaded from the CSG user server is the subscription information of the home base station, if the subscription information includes the user identifier, The terminal is allowed to access the home base station, otherwise the terminal is not allowed to access the home base station.
  • the authentication authorization server is further configured to determine that the subscription information that is saved by itself or downloaded from the CSG user server is the subscription information of the home base station user, if the subscription information includes the home base station identifier, the user category The information is the CSG user, otherwise the user category information is the non-CSG user; if it is determined that the subscription information saved by the CSG user server is the subscription information of the home base station, if the subscription information includes the user And the user category information is the CSG user, otherwise the user category information is the non-CSG user. Further, the authentication authorization server is further configured to pass the determination result by the following manner Returning the access gateway to the home base station:
  • the authentication authorization server sends a user access accept message to the access gateway after completing the user authentication, and the access gateway accepts according to the user access.
  • the message is forwarded to the home base station by the extended authentication protocol EAP forwarding message, and the home base station forwards the authentication success message to the terminal; or the access gateway forwards the message through the EAP
  • the authentication success message is forwarded to the terminal by the home base station, and sends a key change indication message to the home base station, to notify the user of the home base station that the authentication is successful;
  • the authentication authorization server sends an access reject message to the access gateway, and the access gateway performs the access according to the access The refusal message forwards the authentication failure message to the home base station by using the EAP forwarding message, and the home base station forwards the authentication failure message to the terminal.
  • the authentication authorization server is further configured to return the user category information to the home base station through the access gateway by:
  • the authentication authorization server sends a user access accept message carrying the user category information to the access gateway; the access gateway forwards the message according to the user access accept message through the EAP forwarding message. And the right success message is forwarded to the home base station, and the home base station parses the authentication success message and saves the user category information, and then forwards the authentication success message to the terminal by using an EAP forwarding message; or And the gateway forwards the authentication success message to the terminal by using the EAP forwarding message according to the user access accept message, and sends a key change indication message carrying the user category information to the home base station, to notify the The home base station user is successfully authenticated, and the home base station saves the user category information.
  • a system for authenticating a user of a home base station comprising: an authentication authorization server as described above.
  • a CSG user server for authenticating a user of a home base station wherein
  • the CSG user server is configured to receive user identification information, a home base station identifier, and a home base station mode sent by the authentication authorization server in the process of the home base station that the access gateway requests to access the closed access mode or the hybrid access mode;
  • the CSG user server is further configured to: when the home base station is in the closed access mode, determine whether the terminal is allowed to access the home base station, and return the determination result to the home base station by using the access gateway;
  • the CSG user server is further configured to determine user category information of the terminal when the home base station is in a hybrid access mode, and return the user category information to the home base station through the access gateway.
  • the CSG user server is further configured to determine, according to the user identification information, the home base station identifier, the home base station mode, and the self-supplied subscription information, whether the terminal is allowed to be connected when the home base station is in the closed access mode. Entering the home base station, and returning the judgment result to the home base station through the access gateway;
  • the CSG user server is further configured to determine a user of the terminal according to the user identification information, the home base station identifier, the home base station mode, and the subscription information saved by the home base station when the home base station is in a hybrid access mode. Class information, and returning the user category information to the home base station through the access gateway.
  • the CSG user server is further configured to: when the subscription information saved by the user is a subscription information of the home base station user, if the subscription information includes the home base station identifier, the terminal is allowed to access the home base station, otherwise The terminal accesses the home base station; when the subscription information saved by the terminal is the subscription information of the home base station, if the subscription information includes the user identifier, the terminal is allowed to access the home base station, otherwise the terminal is not allowed to access the Home base station.
  • the CSG user server is further configured to determine that the subscription information saved by itself is the subscription information of the home base station user, if the subscription information includes the home base station identifier, the user category information is the CSG user, otherwise The user category information is the non-CSG user; when it is determined that the subscription information saved by itself is the subscription information of the home base station, if the subscription information includes the user identifier, the user category information is the CSG user, otherwise The user category information is the non-CSG user. Further, the CSG user server is further configured to return the determination result to the home base station through the access gateway by:
  • the CSG user service If the judgment result indicates that the terminal is allowed to access the home base station, the CSG user service The device returns an acknowledgment message to the authentication authorization server, and the authentication authorization server sends a user access accept message to the access gateway after completing the user authentication; the access gateway passes the EAP according to the user access accept message.
  • the forwarding message forwards the authentication success message to the home base station, and the home base station forwards the authentication success message to the terminal; or the access gateway forwards the message according to the user access accept message through EAP Sending, by the home base station, the message to the terminal, and transmitting a key change indication message to the home base station, to notify the user of the home base station that the authentication is successful;
  • the CSG user server If the judgment result indicates that the terminal is not allowed to access the home base station, the CSG user server returns a rejection message to the authentication authorization server, and the authentication authorization server terminates the authentication process to the access gateway. Sending an access reject message, the access gateway forwards the authentication failure message to the terminal via the EAP forwarding message according to the access reject message. Further, the CSG user server is further configured to return the user category information to the home base station through the access gateway by:
  • the CSG user server returns an acknowledgement message carrying the user category information to the authentication authorization server, and the authentication authorization server sends the user access that carries the user category information to the access gateway after completing the user authentication. Accept the message;
  • the access gateway forwards the authentication success message to the home base station by using an EAP forwarding message, where the home base station parses the authentication success message and saves the user category information, and then successfully performs the authentication by using an EAP forwarding message.
  • the message is forwarded to the terminal; or
  • the access gateway forwards the authentication success message to the terminal through the EAP forwarding message, and sends a key change indication message carrying the user category information to the home base station to notify the home base station user If the right is successful, the home base station parses the key change indication message, and saves the user category information.
  • a system for authenticating a user of a home base station comprising: an authentication authorization server as described above.
  • the present invention provides a system and method for performing authentication on a user of a home base station, and whether the user is allowed to access the home base station system and the access authentication of the user is unified.
  • FIG. 1 is a schematic diagram of a network connection of a home base station in the prior art
  • FIG. 2 is a flow chart of a method for accessing a home base station user in the prior art
  • FIG. 3 is a first embodiment of a method for performing authentication by a user of a home base station according to the present invention
  • FIG. 4 is a second embodiment of a home base station user performing authentication according to the present invention.
  • FIG. 5 is a third embodiment of a method for performing authentication by a user of a home base station according to the present invention.
  • FIG. 6 is a fourth embodiment of the method for performing authentication of a user of a home base station according to the present invention.
  • FIG. 7 is a fifth embodiment of a method for performing authentication of a user of a home base station according to the present invention.
  • FIG. 8 is a sixth embodiment of the method for performing authentication by a user of a home base station according to the present invention. Preferred embodiment of the invention
  • the present invention is directed to a system and method for performing authentication on a user of a home base station, and whether the check for allowing the user to access the home base station and the access authentication of the user are unified, and the authentication authorization server or the home located at the core network
  • the base station subscription information server that is, the CSG user server, completes the authentication result and returns only the authentication result to the home base station, thereby avoiding frequent transmission of the user's real identity in the air interface and the analysis of the user identity by the home base station, thereby providing correctness of the user identity.
  • the processing burden of the home base station network element is reduced, and the security risk of the home base station system is reduced.
  • a system for authenticating a user of a home base station includes: a terminal, a home base station, an access gateway, an authentication authority server, and a CSG user server;
  • the access gateway is configured to send the user identification information and the home base station information to the authentication authorization server during the process of the terminal accessing the closed access mode or the hybrid access mode of the home base station;
  • the authentication authorization server is configured to determine whether the user is allowed to access the home base station when the home base station is in the closed access mode, and return the determination result to the home base station through the access gateway; and set to be when the home base station is hybrid.
  • the user category information is determined when entering the mode, and the user category information is returned to the home base station through the access gateway.
  • the authentication authorization server is configured to determine whether the user is allowed to access the home base station when the home base station is in the closed access mode, and the authentication authorization server determines according to the subscription information, the user identification information, the home base station identifier, and the home base station mode. Whether the user is allowed to access the home base station; the authentication authorization server is further configured to complete the authentication of the user when the user is allowed to access the home base station, and send the user to the access gateway after the authentication succeeds. Accessing the acceptance message; and terminating the authentication process when the judgment result is that the user is not allowed to access the home base station, and sending an access rejection message to the access gateway;
  • the access gateway is configured to: after receiving the access reject message, forwarding the message through the EAP, the authentication failure message (the authentication failure message may be embedded in the EAP forwarding message) is forwarded to the terminal by the home base station;
  • the access gateway is further configured to forward the authentication success message to the home base station by using the EAP forwarding message after receiving the user access accept message, and the home base station is configured to parse the message after forwarding the EAP forwarding message and forward the EAP forwarding message to the terminal;
  • the access gateway may be configured to forward the authentication success message to the home base station by using the EAP forwarding message, and then send a key change indication message to the home base station to notify the home base station user that the authentication succeeds; and the home base station is configured to forward the received EAP message. Receiving a key change indication message after forwarding to the terminal.
  • the authentication authorization server is configured to determine the user category information when the home base station is in the hybrid access mode, and the authentication authorization server determines the user category information according to the subscription information, the user identification information, the home base station identifier, and the home base station mode;
  • the authentication authorization server is further configured to send a user access accept message to the access gateway after the user's authentication authentication is completed, where the user category information is carried;
  • the access gateway is further configured to: after receiving the user access accept message, forward the authentication success message to the home base station by using the EAP forwarding message, where the user class information is carried; the home base station is configured to parse the message after receiving the EAP forwarding message.
  • the access gateway may further be configured to: after receiving the user access accept message, forward the authentication success message to the home base station by using the EAP forwarding message, and send a key change indication message to the home base station, to notify the home base station user that the authentication succeeds, wherein the User category information; the home base station is configured to forward the received EAP forwarding message to the terminal, and parse the received key change indication message, and save the user category information.
  • the subscription information may be subscription information of the home base station user or subscription information of the home base station; the authentication authorization server may also be configured to save the subscription information, or
  • the CSG user server is configured to save the subscription information
  • the authentication authority server is configured to download the subscription information from the CSG user server.
  • a method for performing authentication on a user of a home base station is as shown in FIG. 3 to FIG. 5.
  • the authentication authorization server determines whether the user can access the home when the home base station is in the closed access mode.
  • the base station and when the home base station is in the hybrid access mode, determines the user category information; as shown in FIG. 3, the authentication authorization server notifies the access gateway of the judgment result or the user category information, and the access gateway further notifies the message through the EAP forwarding message.
  • the specific method is as follows: Step 301: The air interface parameter synchronization and ranging are completed between the terminal and the home base station.
  • Step 302 The terminal requests to negotiate an authentication capability, such as an authentication policy of the user, and completes the capability negotiation work with the home base station and the access gateway.
  • an authentication capability such as an authentication policy of the user
  • Step 303 The access gateway starts an EAP authentication process, and sends a user identity request to the home base station, and the home base station forwards the request to the terminal.
  • Step 304 After receiving the user identification request message, the terminal returns a response message to the home base station, and carries the user identification information.
  • the home base station transparently transmits the message to the access gateway.
  • the user identification information carried in the response response message may be a real identifier of the user or a pseudo identifier of the user.
  • Step 305 After receiving the response message, the access gateway sends an access request message to the authentication authorization server, where the message carries the user identification information, the home base station mode, and the home base station identifier.
  • the home base station mode may be saved directly at the access gateway, or the home base station may send a message. Knowing the access gateway's own home base station mode, the present invention does not limit the messages used.
  • the subscription information may be obtained from the CSG user server and downloaded to the authentication authorization server, or may be directly saved on the authentication authorization server.
  • the authentication authorization server needs to obtain the information from the CSG user server. That is, steps 306-307 need to be performed; otherwise, step 308 is directly executed.
  • Step 306 When the authentication authorization server receives the access request message, and the message carries the home base station mode, the authentication authorization server sends a subscription information request message to the CSG user server, and carries the user identifier and/or the home base station in the message. logo.
  • the terminal After the access authorization server receives the access request message, if the user cannot find the real identifier of the user according to the user's pseudo-identity in the message, the terminal can interact with the terminal through the EAP message to obtain the real identifier of the user, and the real identifier and the pseudo-identity.
  • the process of the association is the same as that of the prior art, and the process is not described here.
  • the subscription information may be the subscription information of the user of the home base station, that is, the list of the home base stations that the user is allowed to access; or the subscription information of the home base station, that is, the list of users allowed to be accessed by the home base station.
  • the request message sent by the authentication authorization server to the CSG user server at least carries the user identifier (may also carry the home base station identifier); when the subscription information is the subscription information of the home base station, The request message sent by the authentication authorization server to the CSG user server at least carries the home base station identifier (which may also carry the user identifier).
  • the subscription information may be the subscription information of the user of the home base station, that is, the list of the home base stations that the user is allowed to access; or the subscription information of the home base station, that is, the list of users allowed to be accessed by the home base station.
  • Step 308 The authentication authorization server determines whether the user can access the home base station when the closed access mode is determined according to the subscription information, the home base station identifier, the home base station mode, and the user identifier, and determines the user category information in the mixed access mode.
  • the authentication authorization server needs to determine whether the user can When the subscription information is the subscription information of the home base station user, if the subscription information includes the home base station identifier, the user is allowed to access the user base station, otherwise the user is not allowed to access the user base station; When the subscription information is the subscription information of the home base station, if the subscription information includes the user identifier, the user is allowed to access the user base station, otherwise the user is not allowed to access the user base station; when the user is allowed to access, step 309 is performed. If the user is not allowed to access, the authentication process is terminated. For the specific process, refer to the process description in the third embodiment.
  • the authentication authorization server needs to check whether the user exists in the allowed access list.
  • the subscription information is the subscription information of the home base station user, if the subscription information includes the home base station identifier, the identifier
  • the user category information is a CSG user, otherwise the user category information is a non-CSG user
  • the subscription information is the subscription information of the home base station, if the subscription information includes the user identifier, the user category information is identified as a CSG user, otherwise the identifier
  • the user category information is a non-CSG user; then step 309 is performed.
  • steps 306 to 308 may not be performed, and the home base station mode information may not be carried in the access request message.
  • Step 309 The access authentication process is continued between the terminal and the authentication and authorization server.
  • the order of the above steps 309 and 306 308 may have different settings.
  • Step 310 After the user authentication is completed, the authentication authorization server sends a user access accept message to the access gateway. If the home base station is in the hybrid access mode, the message carries the user category information.
  • the user category information is not required to be carried, and the information carried in this time is the same as the prior art, and details are not described herein again.
  • Step 311 The access gateway forwards the authentication success message to the home base station by using the EAP forwarding message, and the home base station carries the user category information from the authentication authorization server when the hybrid access mode is used.
  • Step 312 After receiving the EAP forwarding message, the home base station parses the message. If the home base station is in the hybrid access mode, it also needs to obtain the user category information carried by the message, and save the user category information.
  • Step 313 The home base station forwards the authentication success message to the terminal by using the EAP forwarding message.
  • step 314 the other processes related to user access are continued.
  • the access control function for the home base station user can be completed without requiring the home base station to perform the user access control separately.
  • FIG. 4 is a variant of the embodiment.
  • the authentication authorization server notifies the access gateway of the judgment result or the user category information, and the access gateway sends the message to the terminal through the EAP forwarding message through the EAP, and changes the key through the key.
  • the indication message is notified to the home base station; the specific method is as follows:
  • Steps 401-410 the same as steps 301-310, will not be repeated here.
  • Step 411 The access gateway forwards the authentication success message to the home base station by using the EAP forwarding message, and then forwards the message to the terminal by the home base station.
  • the user category information from the authentication authorization server is not carried in the message, and the user category information is only saved in the access gateway.
  • Step 412 The access gateway sends a key change indication message to the home base station to notify the home base station that the authentication is successful.
  • the user category information is carried in this message.
  • the home base station in the closed access mode directly performs step 414.
  • the home base station in the hybrid access mode performs step 413.
  • Step 413 The home base station in the hybrid access mode parses the key change indication message, obtains user category information carried in the message, and saves the user category information.
  • Step 414 continuing to perform other processes related to user access.
  • the access control function for the home base station user can be completed without requiring the home base station to perform the user access control separately.
  • the authentication authorization server determines that the user cannot access the home base station and directly rejects the user access process, and the specific method is as follows: Steps 501-507, the same Steps 301-307 will not be repeated here.
  • Step 508 The authentication authorization server is configured according to the subscription information, the home base station identifier, and the home base station module. And the user identifier determines whether the user can access the home base station when the closed access mode is used, and mix the user category information in the access mode. For the closed access mode home base station, the authentication authorization server needs to determine whether the user can access the home base station, and if the user is not allowed to access, the authentication process is terminated.
  • Step 509 The authentication authorization server terminates the authentication process, and sends an access rejection message to the access gateway.
  • Step 510 The access gateway forwards the authentication failure message to the terminal through the home base station by using the EAP forwarding message.
  • Step 511 The access gateway initiates a user revocation process.
  • This embodiment is applicable to a closed access mode home base station.
  • a system for authenticating a user of a home base station includes: a terminal, a home base station, an access gateway, an authentication authority server, and a CSG user server;
  • the access gateway is configured to send the user identification information and the home base station information to the CSG user server through the authentication authorization server during the process of the home base station in which the terminal accesses the closed access mode or the hybrid access mode;
  • the CSG user server is configured to determine whether the user is allowed to access the home base station when the home base station is in the closed access mode, and return the determination result to the home base station through the authentication authority server and the access gateway; and set to be when the home base station is mixed.
  • the user category information is determined in the access mode, and the user category information is returned to the home base station through the authentication authority server and the access gateway.
  • the CSG user server is configured to determine whether the user is allowed to access the home base station when the home base station is in the closed access mode, and the CSG user server determines whether to allow the user according to the user identification information, the home base station identifier, the home base station mode, and the subscription information.
  • the user accesses the home base station, and the CSG user server is further configured to: when the judgment result is that the user is allowed to access the home base station, return an acknowledgement message to the authentication authorization server, and when the determination result is that the user is not allowed to access
  • the home base station returns a reject message to the authentication authority server;
  • the authentication authorization server is configured to complete the user's authentication and authentication after receiving the confirmation message, and access the
  • the gateway sends the user to accept the access message, and after receiving the reject message, ends the user's authentication authentication, and sends a reject access message to the access gateway;
  • the access gateway is configured to forward the authentication failure message to the terminal through the home base station after receiving the reject access message and forwarding the message through the EAP;
  • the access gateway is further configured to forward the authentication success message to the home base station by using the EAP forwarding message after receiving the access message, and the home base station is configured to parse the message after receiving the EAP forwarding message, and forward the message to the terminal; or
  • the access gateway may be configured to forward the authentication success message to the home base station by using the EAP forwarding message after receiving the access message, and send a key change indication message to the home base station to notify the home base station user that the authentication succeeds; It is set to forward the received EAP forwarding message to the terminal, and parse the received key change indication message.
  • the CSG user server is configured to determine the user category information when the home base station is in the hybrid access mode, and the CSG user server determines the user category information according to the user identification information, the home base station identifier, the home base station mode, and the subscription information, and returns the information to the authentication authority server. Confirmation message, carrying user category information;
  • the authentication authorization server is configured to complete the authentication authentication of the user after receiving the confirmation message, and send the user accepting the access message to the access gateway, carrying the user category information;
  • the access gateway is configured to forward the authentication success message to the home base station by using the EAP forwarding message after receiving the access message, and carry the user category information;
  • the home base station is configured to parse the EAP forwarding message, save the user category information, and forward the information through the EAP. The message forwards the authentication success message to the terminal; or
  • the access gateway may be configured to forward the authentication success message to the home base station by using the EAP forwarding message after receiving the access message, and send a key change indication message to the home base station, to notify the home base station user that the authentication succeeds, and the user category is carried.
  • the home base station may be configured to forward the received EAP forwarding message to the terminal, and parse the received key change indication message to save the user category information.
  • the CSG user server determines whether the user can access the home base station when the home base station is in the closed access mode, and determines the user category information when the home base station is in the hybrid access mode; as shown in FIG. 6, the CSG user The server determines whether the user can access the home base station when the home base station is in the closed access mode, determines user category information when the home base station is in the hybrid access mode, and notifies the authentication authorization server of the determination result or the user category information.
  • the EAP forwards the message to the home base station and the terminal.
  • the specific method is as follows:
  • Step 601 Perform air interface parameter synchronization and ranging between the terminal and the home base station.
  • Step 602 The terminal requests to negotiate an authentication capability, such as an authentication policy of the user, and completes the capability negotiation work with the home base station and the access gateway.
  • an authentication capability such as an authentication policy of the user
  • Step 603 The access gateway starts an EAP authentication process, and sends a user identity request to the home base station, and the home base station forwards the request to the terminal.
  • Step 604 After receiving the user identification request message, the terminal returns a response message to the home base station, and carries the user identification information.
  • the home base station transparently transmits the message to the access gateway.
  • the user identification information carried in the response response message may be a real identifier of the user or a pseudo identifier of the user.
  • Step 605 After receiving the response message, the access gateway sends an access request message to the authentication authority server, where the message carries the user identification information, the home base station mode, and the home base station identifier.
  • the home base station mode may be saved in the access gateway, or the home base station sends a message to notify the access gateway of its own home base station mode, and the present invention does not limit the message used.
  • Step 606 When the authentication authorization server receives the access request message, and the message carries the home base station mode, the authentication authorization server sends a request message to the CSG user server, and carries the user identifier, the home base station identifier, and the home base station in the message. mode.
  • the terminal After the access authorization server receives the access request message, if the user cannot find the real identifier of the user according to the user's pseudo-identity in the message, the terminal can interact with the terminal through the EAP message to obtain the real identifier of the user, and the real identifier and the pseudo-identity.
  • the process of the association is the same as that of the prior art, and the process is not described here.
  • Step 607 The CSG user server receives the request message, and determines whether the user can access the closed access mode according to the subscription information, the home base station identifier, the home base station mode, and the user identifier.
  • the home base station determines the user category information when the hybrid access mode is used.
  • the subscription information here is the subscription information about the home base station on the CSG subscriber server.
  • the subscription information may be subscription information of the home base station user, that is, a list of home base stations that the user is allowed to access; or may be subscription information of the home base station, that is, a list of users allowed to be accessed by the home base station.
  • the CSG user server needs to determine whether the user can access the home base station.
  • the subscription information is the subscription information of the home base station user
  • the subscription information includes the home base station identifier
  • the user is allowed to connect. If the subscriber information is included in the subscriber base station, if the subscription information is the subscription information of the home base station, if the subscriber information is included in the subscription information, the user is allowed to access the subscriber base station, otherwise the subscriber is not allowed.
  • the user accesses the user base station; if the user is allowed to access, the authentication process is continued, and step 608 is performed; otherwise, the authentication process is terminated.
  • the specific process refer to the process description shown in FIG. 8;
  • the authentication authorization server needs to determine the user category information.
  • the subscription information is the subscription information of the home base station user, if the subscription information includes the home base station identifier, the user category information is identified as a CSG user. Otherwise, the user category information is identified as a non-CSG user; when the subscription information is the subscription information of the home base station, if the subscription information includes the user identifier, the user category information is identified as a CSG user, otherwise the user category information is identified as a non-CSG.
  • User then step 608 is performed.
  • Step 608 The CSG user server returns an acknowledgement message to the authentication authority server.
  • the user category information needs to be carried.
  • the user category information is a CSG user or a non-CSG user.
  • steps 606 to 608 may not be performed, and the home base station mode information may not be carried in the access request message.
  • Step 609 The access authentication process is continued between the terminal and the authentication and authorization server.
  • the sequence of steps 609 and 606 608 may have different settings.
  • Step 610 After the user authentication is completed, the authentication authorization server sends a user access accept message to the access gateway. If the base station is a hybrid access mode home base station, the message carries the user category information. Step 611: The access gateway forwards the authentication success message to the home base station by using the EAP forwarding message, and the hybrid access mode carries the user category information from the authentication authorization server.
  • the home base station in the closed access mode directly performs step 613, and after receiving the EAP forwarding message, the home base station in the hybrid access mode performs step 613;
  • Step 612 The home base station in the hybrid access mode parses the EAP forwarding message, obtains the user category information carried in the message, and saves the user category information.
  • Step 613 The home base station forwards the authentication success message to the terminal by using the EAP forwarding message. Step 614, continuing to perform other processes related to user access.
  • the access control function for the home base station user can be completed without requiring the home base station to perform the user access control separately.
  • FIG. 7 is a variant of the embodiment.
  • the CSG user server determines whether the user can access the home base station when the closed access mode is determined, the user category information is determined when the hybrid access mode is determined, and the determination result or the user category information is notified.
  • the authentication authorization server sends the EAP forwarding message to the terminal through the EAP after the user authentication is completed, and notifies the home base station by using the key change indication message; the specific method is as follows:
  • Steps 701-710 the same as steps 601-610, will not be repeated here.
  • Step 711 The access gateway forwards the authentication success message to the home base station by using the EAP forwarding message, and then forwards the message to the terminal by the home base station.
  • the user category information from the authentication authorization server is not carried in the message, and the user category information is only saved in the access gateway.
  • Step 712 The access gateway sends a key change indication message to the home base station to notify the home base station that the authentication is successful.
  • the user category information is carried in this message.
  • the home base station in the closed access mode directly performs step 714, and after receiving the key change indication message, the home base station in the hybrid access mode performs step 713;
  • Step 713 The home base station in the hybrid access mode parses the key change indication message, obtains user category information carried in the message, and saves the user category information. Step 714, continuing to perform other processes related to user access.
  • the access control function for the home base station user can be completed without requiring the home base station to perform the user access control separately.
  • the CSG user server determines that the user cannot access the home base station and directly rejects the user access process.
  • the specific method is as follows: Steps 801-806, the same steps 601-606, no longer repeat here.
  • Step 807 The CSG user server determines whether the user can access the home base station when the closed access mode is determined according to the subscription information, the home base station identifier, the home base station mode, and the user identifier, and determines the user category information when the hybrid access mode is used. For the closed access mode home base station, the CSG user server needs to determine whether the user can access the home base station. If the user is not allowed to access, the authentication process is terminated, and step 808 is performed.
  • Step 808 The CSG user server sends a rejection message to the authentication authority server.
  • Step 809 The authentication authorization server terminates the authentication process, and sends an access rejection message to the access gateway.
  • Step 810 The access gateway forwards the authentication failure message to the terminal through the home base station by using the ⁇ forwarding message.
  • Step 811 The access gateway initiates a user revocation process.
  • This embodiment is applicable to a closed access mode home base station.
  • the foregoing process provides a method for authenticating a user of a home base station, and whether the user is allowed to access the home base station system and the access authentication of the user is unified, and the authentication authorization server or the home base station located in the core network signs the contract.
  • the information server completes and returns only the authentication result to the home base station. Therefore, the user's real identity is frequently transmitted in the air interface, and the base station analyzes the user identity. Therefore, the user identity correctness guarantee is provided, the processing burden of the home base station network element is reduced, and the security risk of the home base station system is reduced.
  • the foregoing embodiment directly connects the home base station without using the home base station gateway.
  • the application scenario of the gateway and the security gateway is set up as an example to illustrate how the home base station implements emergency services.
  • the home base station does not access the access gateway through the home base station gateway, and the security gateway is separately set, or the home base station accesses the access gateway through the home base station gateway, and the foregoing processes in FIG. 3 to FIG. 8 are also applicable.
  • the message between the home base station and the access gateway needs to be forwarded through the network element (security gateway, home base station gateway) existing in the middle, and does not affect the description of the present invention, so the description is not repeated here.
  • the present invention provides a system and method for performing authentication on a user of a home base station, and whether the user is allowed to access the home base station system and the access authentication of the user is unified, and the authentication is performed on the core network.
  • the server or the home base station subscribes to the information server to complete, and only returns the authentication result to the home base station, thereby avoiding frequent transmission of the user's real identity in the air interface and the resolution of the user identity by the home base station, thereby providing correctness of the user identity and reducing the home.
  • the processing burden of the base station network element reduces the security risks of the home base station system, and therefore the present invention has strong industrial applicability.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

一种对家用基站用户实施鉴权的系统及方法
技术领域
本发明涉及移动通信领域, 具体涉及一种对家用基站用户实施鉴权的系 统及方法。
背景技术
家用基站是一种小型、低功率的基站, 部署在家庭及办公室等室内场所, 主要作用是为了给用户提供更高的业务速率并降低使用高速率服务所需要的 费用, 同时弥补已有分布式蜂窝无线通信系统覆盖的不足。 家用基站的优点 是实惠、 便捷、 低功率输出、 即插即用等。 家用基站系统已经在第三代合作 伙伴计划 ( 3GPP , 3rd Generation Partnership Project )、 第三代合作伙伴计划 2( 3GPP2, 3rd Generation Partnership Project 2 )和微波接入全球互通( WiMAX, Worldwide Interoperability for Microwave Access )三大标准中进行研究 , 各个 标准组织中家用基站系统釆用的网络架构都大体相同, 本文以 WiMAX为例 来说明家用基站的网络架构。
家用基站系统如图 1所示。 为保障家用基站和接入网关之间链路安全, 家用基站和接入网关之间可能存在一个安全网关。 为了便于对家用基站进行 管理, 引入家用基站网关, 家用基站网关主要功能为: 验证家用基站的安全 性, 处理家用基站的注册, 对家用基站进行运行维护管理, 根据运营商要求 配置和控制家用基站, 负责交换核心网和家用基站的数据。 家用基站可以通 过家用基站网关接入核心网的接入网关, 此时, 安全网关和家用基站网关合 设。 家用基站也可以不通过家用基站网关直接接入核心网的接入网关, 此时, 安全网关可以和接入网关合设, 也可以分设。 在 WiMAX系统中, 接入网关 是指 ASN GW ( Access Service Network Gateway ) 。
自组织网络服务器, 如图 1所示, 其作用是在无需人工干预的情况下, 发现 /提取家用基站的一系列运行维护参数, 如家用基站所处的地理位置, 家 用基站周边的无线环境等; 为家用基站提供初始化参数配置, 支持家用基站 的自举初始化, 如使用一定的频率规划算法给家用基站提供候选工作频点, 为家用基站提供可接入的候选接入网关等。 此外, 自组织网络服务器还可用 以支持家用基站的故障恢复等。 闭合用户组(CSG, Closed Subscriber Group ) 是引入家用基站后提出的新概念。 通常一个家庭或者一个企业内部的用户组 成一个闭合用户组, 用户通过与运营商签约可以接入到多个闭合用户组所对 应的家用基站, 例如用户的办公场所、 家庭等。
CSG用户服务器, 如图 1所示, 其作用在于存储家用基站的签约信息, 如家用基站允许接入的用户, 即 CSG相关信息, 为家用基站和 /或鉴权授权 服务器提供存储的家用基站签约信息。
家用基站的使用模式分为三种: 闭合接入模式、 混合接入模式和开放模 式。 当家用基站是闭合接入模式的时候, 只有该家用基站所属 CSG签约用户 可以接入该基站并享受基站提供的业务。 当家用基站是开放模式的时候, 任 何运营商签约用户都可以接入该基站, 此时的家用基站等同于宏基站使用。 当家用基站是混合接入模式的时候, 同样允许任何运营商签约用户或者漫游 用户接入使用, 但是要根据用户是否签约 CSG的信息区分不同的级别, 也就 是说签约该 CSG 的用户在使用混合型家用基站的时候具有更高的业务优先 级, 享受更好的服务质量和业务类别。
家用基站可以通过网络侧的 CSG用户服务器获得允许接入的闭合用户 组列表, 也可以由家用基站的管理者在家用基站上直接修改允许接入的闭合 用户组列表。 用户接入时, 闭合接入模式的家用基站会利用该列表对用户进 行接入控制, 并拒绝未授权接入该闭合接入模式家用基站的用户; 混合接入 模式的家用基站根据该列表对用户类别(如, CSG用户、 非 CSG用户)进行 区分, 便于实施差异化计费、 服务质量授权等操作。 为了简化描述, 以下将 家用基站判断用户是否属于 CSG列表的操作统称为接入控制。
家用基站根据终端发送的用户标识检查该用户是否属于 CSG列表,以图 1 家用基站网关与接入网关合设为例描述家用基站执行接入控制流程。 家用 基站执行接入控制的方法流程如图 2所示, 该方法具体包括以下步骤:
步骤 201 , 终端与家用基站之间完成空口参数同步及测距;
步骤 202 , 终端请求协商认证能力, 如用户的认证策略等, 并与家用基 站、 接入网关完成能力协商工作; 步骤 203 ,接入网关启动 EAP鉴权流程, 向家用基站发送用户标识请求, 家用基站将该请求转发给终端;
步骤 204, 在收到用户标识请求消息后, 终端向家用基站回复响应消息, 携带用户标识信息。
这里, 用户标识信息为网络接入标识( NAI , Network Access Identifier ) 、 国际移动客户识别码 ( IMSI , International Mobile Subscriber Identification Number )或介质访问控制 (MAC, Media Access Control ) ID等。
步骤 205 , 家用基站根据该用户标识信息对用户进行接入控制。
闭合接入模式家用基站检查该用户是否存在于 CSG列表中, 如果存在, 则允许用户接入, 继续步骤 206; 否则拒绝用户接入, 可以发起用户释放流 程。
混合接入模式家用基站检查该用户是否存在于 CSG列表中, 如果存在, 则在后续流程中告知接入网关该用户为 CSG用户, 如果不存在, 则在后续流 程中告知接入网关该用户为非 CSG用户。
步骤 206, 家用基站向接入网关返回用户标识。
该步骤与步骤 205不分先后顺序, 可以与其并列发生。
步骤 207 , 终端与鉴权授权服务器之间进行接入鉴权流程。 鉴权授权服 务器完成对用户合法性的审核, 并授权用户进行业务。
步骤 208 , 接入鉴权流程成功结束后, 继续执行用户接入相关的其他流 程。
从上述流程可见, 家用基站根据终端携带的用户标识检查该用户是否属 于 CSG列表(步骤 205 ) , 但是在步骤 204终端回复的响应中, 鉴于安全考 虑, 终端可能将用户真实标识进行认证协议封装, 如扩展认证协议(ΕΑΡ, Extensible Authentication Protocol )封装, 此时家用基站需要解析认证封装协 议, 导致基站节点运作负担增加、 效率降低; 在终端对真实身份标识进行加 密传送的情况下, 家用基站更是无从解析并获取用户标识信息; 即便终端通 过明文传送用户标识, 不经认证消息封装, 则该用户标识未经过鉴权授权服 务器的验证, 从而无法保证该用户标识的正确性, 而且在空口频繁地用明文 传输用户真实标识容易被他人窃取, 存在无线通信系统安全隐患。 发明内容
本发明要解决的技术问题是提供一种对家用基站用户实施鉴权的系统及 方法, 可避免在空口频繁传递用户真实标识, 减少家用基站的负担, 降低家 用基站系统的安全隐患。 为了解决上述问题,本发明提供了一种对家用基站用户实施鉴权的方法, 该方法包括:
A、 在终端请求接入闭合接入模式或混合接入模式的家用基站过程中, 接入网关将用户标识信息、 家用基站标识及家用基站模式发送至鉴权授权服 务器, 或经所述鉴权授权服务器发送至闭合用户组 CSG用户服务器;
B、当所述家用基站为闭合接入模式时,所述鉴权授权服务器或所述 CSG 用户服务器判断是否允许终端接入所述家用基站, 并将判断结果通过所述接 入网关返回至所述家用基站; 当所述家用基站为混合接入模式时, 所述鉴权 授权服务器或所述 CSG用户服务器确定终端的用户类别信息,并将所述用户 类别信息通过所述接入网关返回至所述家用基站。
进一步地, 所述鉴权授权服务器判断是否允许终端接入所述家用基站或 确定终端的所述用户类别信息的方式为: 所述鉴权授权服务器根据所述用户 标识信息、 所述家用基站标识、 所述家用基站模式及自身保存或从所述 CSG 用户服务器下载的签约信息判断是否允许终端接入所述家用基站或确定终端 的所述用户类别信息;
所述 CSG用户服务器判断是否允许终端接入所述家用基站或确定终端 的所述用户类别信息的方式为:所述 CSG用户服务器根据所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存的签约信息判断是否允许 终端接入所述家用基站或确定终端的所述用户类别信息。
进一步地, 所述用户类别信息为 CSG用户或非 CSG用户。
进一步地, 所述签约信息为家用基站用户的签约信息或家用基站的签约 信息。 进一步地, 所述步骤 B中, 当所述家用基站为闭合接入模式时, 所述鉴 权授权服务器或所述 CSG用户服务器判断是否允许终端接入所述家用基站的 方式为:
所述鉴权授权服务器确定自身保存或从所述 CSG用户服务器下载的签 约信息是家用基站用户的签约信息时,若签约信息中包含所述家用基站标识, 则允许终端接入所述家用基站, 否则不允许终端接入所述家用基站; 所述鉴 权授权服务器确定自身保存或从所述 CSG用户服务器下载的签约信息是家用 基站的签约信息时, 若签约信息中包含所述用户标识, 则允许终端接入所述 家用基站, 否则不允许终端接入所述家用基站;
所述 CSG用户服务器确定自身保存的签约信息是家用基站用户的签约 信息时, 若签约信息中包含所述家用基站标识, 则允许终端接入所述家用基 站, 否则不允许终端接入所述家用基站; 所述 CSG用户服务器确定自身保存 的签约信息是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则 允许终端接入所述家用基站, 否则不允许终端接入所述家用基站。
进一步地, 所述步骤 B中, 当所述家用基站为混合接入模式时, 所述鉴 权授权服务器或所述 CSG用户服务器确定终端的用户类别信息的方式为: 所述鉴权授权服务器确定自身保存或从所述 CSG用户服务器下载的签 约信息是家用基站用户的签约信息时, 若签约信息中包含该家用基站标识, 则所述用户类别信息为所述 CSG用户,否则所述用户类别信息为所述非 CSG 用户; 所述鉴权授权服务器确定自身保存或从所述 CSG用户服务器下载的签 约信息是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则所述 用户类别信息为所述 CSG用户, 否则所述用户类别信息为所述非 CSG用户; 所述 CSG用户服务器确定自身保存的签约信息是家用基站用户的签约 信息时,若签约信息中包含该家用基站标识,则所述用户类别信息为所述 CSG 用户, 否则所述用户类别信息为所述非 CSG用户; 所述 CSG用户服务器确 定自身保存的签约信息是家用基站的签约信息时, 若签约信息中包含所述用 户标识, 则所述用户类别信息为所述 CSG用户, 否则所述用户类别信息为所 述非 CSG用户。 进一步地, 所述步骤 B中, 当所述家用基站为闭合接入模式时, 所述鉴 权授权服务器将判断结果通过所述接入网关返回至所述家用基站的所述步骤 包括:
若所述判断结果表示允许终端接入所述家用基站, 所述鉴权授权服务器 完成用户认证后向所述接入网关发送用户接入接受消息, 所述接入网关根据 所述用户接入接受消息通过扩展认证协议 EAP转发消息将鉴权成功消息转发 给所述家用基站, 所述家用基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关通过 EAP转发消息将所述鉴权成功消息经所述家用基站 转发给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站 用户鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站, 则终止鉴权流程, 所述鉴权授权服务器向所述接入网关发送接入拒绝消息, 所述接入网关根据 所述接入拒绝消息通过 EAP转发消息将鉴权失败消息转发给所述家用基站, 所述家用基站将所述鉴权失败消息转发给终端。 进一步地, 所述步骤 B中, 当所述家用基站为混合接入模式时, 所述鉴 权授权服务器将所述用户类别信息通过所述接入网关返回至所述家用基站的 所述步骤包括:
所述鉴权授权服务器在完成用户认证后向所述接入网关发送携带所述用 户类别信息的用户接入接受消息; 所述接入网关根据所述用户接入接受消息 通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析 所述鉴权成功消息并保存所述用户类别信息后通过 EAP转发消息将所述鉴权 成功消息转发给终端; 或者, 所述接入网关根据所述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发给终端; 并向所述家用基 站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户 鉴权成功, 所述家用基站保存所述用户类别信息。 进一步地,所述步骤 B中,当所述家用基站为闭合接入模式时,所述 CSG 用户服务器将判断结果通过所述接入网关返回至所述家用基站的所述步骤包 括: 若所述判断结果表示允许终端接入所述家用基站,则所述 CSG用户服务 器向所述鉴权授权服务器返回确认消息, 所述鉴权授权服务器完成用户认证 后向所述接入网关发送用户接入接受消息; 所述接入网关根据所述用户接入 接受消息通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用 基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关根据所 述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发 给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站用户 鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站,则所述 CSG用户服 务器向所述鉴权授权服务器返回拒绝消息, 所述鉴权授权服务器终止鉴权流 程, 向所述接入网关发送接入拒绝消息, 所述接入网关根据所述接入拒绝消 息通过 EAP转发消息将鉴权失败消息经所述家用基站转发给终端。 进一步地,所述步骤 B中,当所述家用基站为混合接入模式时,所述 CSG 用户服务器将所述用户类别信息通过所述接入网关返回至所述家用基站的所 述步骤包括:
所述 CSG用户服务器向所述鉴权授权服务器返回携带所述用户类别信 息的确认消息, 所述鉴权授权服务器完成用户认证后向所述接入网关发送携 带所述用户类别信息的用户接入接受消息;
所述接入网关通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析所述鉴权成功消息并保存所述用户类别信息后通过 EAP转 发消息将所述鉴权成功消息转发给终端; 或者
所述接入网关通过 EAP转发消息将鉴权成功消息经所述家用基站转发给 终端, 并向所述家用基站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户鉴权成功,所述家用基站解析所述密钥改变指示消息, 保存所述用户类别信息。
一种对家用基站用户实施鉴权的鉴权授权服务器, 其中,
所述鉴权授权服务器设置成接收接入网关在终端接入闭合接入模式或混 合接入模式的家用基站的过程中发来的用户标识信息、 基站标识及家用基站 模式;
所述鉴权授权服务器还设置成当家用基站为闭合接入模式时, 判断是否 允许终端接入所述家用基站, 并将判断结果通过所述接入网关返回至所述家 用基站;
所述鉴权授权服务器还设置成当所述家用基站为混合接入模式时, 确定 终端的用户类别信息, 并将所述用户类别信息通过所述接入网关返回至所述 家用基站。
进一步地,所述鉴权授权服务器还设置成当家用基站为闭合接入模式时, 根据所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存 或从 CSG用户服务器下载的签约信息判断是否允许终端接入所述家用基站, 并将判断结果通过所述接入网关返回至所述家用基站;
所述鉴权授权服务器还设置成当所述家用基站为混合接入模式时, 根据 所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存或从 所述 CSG用户服务器下载的所述签约信息确定终端的用户类别信息,并将所 述用户类别信息通过所述接入网关返回至所述家用基站。
进一步地,所述鉴权授权服务器还设置成确定自身保存或从所述 CSG用 户服务器下载的签约信息是家用基站用户的签约信息时, 若签约信息中包含 所述家用基站标识, 则允许终端接入所述家用基站, 否则不允许终端接入所 述家用基站;确定自身保存或从所述 CSG用户服务器下载的签约信息是家用 基站的签约信息时, 若签约信息中包含所述用户标识, 则允许终端接入所述 家用基站, 否则不允许终端接入所述家用基站。
进一步地,所述鉴权授权服务器还设置成确定自身保存或从所述 CSG用 户服务器下载的签约信息是家用基站用户的签约信息时, 若签约信息中包含 该家用基站标识, 则所述用户类别信息为所述 CSG用户, 否则所述用户类别 信息为所述非 CSG用户; 确定自身保存或从所述 CSG用户服务器下载的签 约信息是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则所述 用户类别信息为所述 CSG用户, 否则所述用户类别信息为所述非 CSG用户。 进一步地, 所述鉴权授权服务器还设置成通过以下方式将判断结果通过 所述接入网关返回至所述家用基站:
若所述判断结果表示允许终端接入所述家用基站, 所述鉴权授权服务器 完成用户认证后向所述接入网关发送用户接入接受消息, 所述接入网关根据 所述用户接入接受消息通过扩展认证协议 EAP转发消息将鉴权成功消息转发 给所述家用基站, 所述家用基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关通过 EAP转发消息将所述鉴权成功消息经所述家用基站 转发给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站 用户鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站, 则终止鉴权流程, 所述鉴权授权服务器向所述接入网关发送接入拒绝消息, 所述接入网关根据 所述接入拒绝消息通过 EAP转发消息将鉴权失败消息转发给所述家用基站, 所述家用基站将所述鉴权失败消息转发给终端。 进一步地, 所述鉴权授权服务器还设置成通过以下方式将所述用户类别 信息通过所述接入网关返回至所述家用基站:
所述鉴权授权服务器在完成用户认证后向所述接入网关发送携带所述用 户类别信息的用户接入接受消息; 所述接入网关根据所述用户接入接受消息 通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析 所述鉴权成功消息并保存所述用户类别信息后通过 EAP转发消息将所述鉴权 成功消息转发给终端; 或者, 所述接入网关根据所述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发给终端; 并向所述家用基 站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户 鉴权成功, 所述家用基站保存所述用户类别信息。
一种对家用基站用户实施鉴权的系统, 该系统包括: 如上所述的鉴权授 权服务器。
一种对家用基站用户实施鉴权的 CSG用户服务器, 其中,
所述 CSG用户服务器设置成接收接入网关在终端请求接入闭合接入模 式或混合接入模式的家用基站过程中经鉴权授权服务器发送过来的用户标识 信息、 家用基站标识及家用基站模式; 所述 CSG用户服务器还设置成当家用基站为闭合接入模式时,判断是否 允许终端接入所述家用基站, 并将判断结果通过所述接入网关返回至所述家 用基站;
所述 CSG用户服务器还设置成当所述家用基站为混合接入模式时,确定 终端的用户类别信息, 并将所述用户类别信息通过所述接入网关返回至所述 家用基站。
进一步地, 所述 CSG用户服务器还设置成当家用基站为闭合接入模式 时, 根据所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身 保存的签约信息判断是否允许终端接入所述家用基站, 并将判断结果通过所 述接入网关返回至所述家用基站;
所述 CSG用户服务器还设置成当所述家用基站为混合接入模式时,根据 所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存的所 述签约信息确定终端的用户类别信息, 并将所述用户类别信息通过所述接入 网关返回至所述家用基站。
进一步地,所述 CSG用户服务器还设置成确定自身保存的签约信息是家 用基站用户的签约信息时, 若签约信息中包含所述家用基站标识, 则允许终 端接入所述家用基站, 否则不允许终端接入所述家用基站; 确定自身保存的 签约信息是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则允 许终端接入所述家用基站, 否则不允许终端接入所述家用基站。
进一步地,所述 CSG用户服务器还设置成确定自身保存的签约信息是家 用基站用户的签约信息时, 若签约信息中包含该家用基站标识, 则所述用户 类别信息为所述 CSG用户, 否则所述用户类别信息为所述非 CSG用户; 确 定自身保存的签约信息是家用基站的签约信息时, 若签约信息中包含所述用 户标识, 则所述用户类别信息为所述 CSG用户, 否则所述用户类别信息为所 述非 CSG用户。 进一步地,所述 CSG用户服务器还设置成通过以下方式将判断结果通过 所述接入网关返回至所述家用基站:
若所述判断结果表示允许终端接入所述家用基站,则所述 CSG用户服务 器向所述鉴权授权服务器返回确认消息, 所述鉴权授权服务器完成用户认证 后向所述接入网关发送用户接入接受消息; 所述接入网关根据所述用户接入 接受消息通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用 基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关根据所 述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发 给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站用户 鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站,则所述 CSG用户服 务器向所述鉴权授权服务器返回拒绝消息, 所述鉴权授权服务器终止鉴权流 程, 向所述接入网关发送接入拒绝消息, 所述接入网关根据所述接入拒绝消 息通过 EAP转发消息将鉴权失败消息经所述家用基站转发给终端。 进一步地,所述 CSG用户服务器还设置成通过以下方式将所述用户类别 信息通过所述接入网关返回至所述家用基站:
所述 CSG用户服务器向所述鉴权授权服务器返回携带所述用户类别信 息的确认消息, 所述鉴权授权服务器完成用户认证后向所述接入网关发送携 带所述用户类别信息的用户接入接受消息;
所述接入网关通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析所述鉴权成功消息并保存所述用户类别信息后通过 EAP转 发消息将所述鉴权成功消息转发给终端; 或者
所述接入网关通过 EAP转发消息将鉴权成功消息经所述家用基站转发给 终端, 并向所述家用基站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户鉴权成功,所述家用基站解析所述密钥改变指示消息, 保存所述用户类别信息。
一种对家用基站用户实施鉴权的系统, 该系统包括: 如上所述的鉴权授 权服务器。
综上所述, 本发明提供了一种对家用基站用户实施鉴权的系统及方法, 将是否允许用户接入家用基站系统的检查与用户的接入鉴权统一进行, 由位 于核心网的鉴权授权服务器或家用基站签约信息服务器来完成, 只将认证结 果返回给家用基站。 从而避免了在空口频繁传递用户真实标识以及家用基站 对用户标识的解析, 因此提供了用户标识正确性保障, 减轻了家用基站网元 的处理负担, 降低了家用基站系统的安全隐患。 附图概述
图 1为现有技术中家用基站网络连接示意;
图 2为现有技术中家用基站用户接入方法流程图;
图 3为本发明的家用基站用户实施鉴权的实施例一;
图 4为本发明的家用基站用户实施鉴权的实施例二;
图 5为本发明的家用基站用户实施鉴权的实施例三;
图 6为本发明的家用基站用户实施鉴权的实施例四;
图 7为本发明的家用基站用户实施鉴权的实施例五;
图 8为本发明的家用基站用户实施鉴权的实施例六。 本发明的较佳实施方式
本发明旨在提供一种对家用基站用户实施鉴权的系统及方法, 将是否允 许用户接入家用基站的检查与用户的接入鉴权统一进行, 由位于核心网的鉴 权授权服务器或家用基站签约信息服务器, 即 CSG用户服务器来完成, 只将 认证结果返回给家用基站, 从而避免了在空口频繁传递用户真实标识, 和家 用基站对用户标识的解析, 因此提供了用户标识正确性保障, 减轻了家用基 站网元的处理负担, 降低了家用基站系统的安全隐患。
以下将结合附图来对本发明的具体实施作进一步详细的说明。
实施例一
本发明的一种对家用基站用户实施鉴权的系统, 如图 1所示, 包括: 终 端、 家用基站、 接入网关、 鉴权授权服务器及 CSG用户服务器;
接入网关设置成当终端接入闭合接入模式或混合接入模式的家用基站过 程中将用户标识信息及家用基站信息发送至鉴权授权服务器; 鉴权授权服务器设置成当家用基站为闭合接入模式时判断是否允许所述 用户接入所述家用基站, 并将判断结果通过接入网关返回至家用基站; 以及 设置成当家用基站为混合接入模式时确定用户类别信息, 并将用户类别信息 通过接入网关返回至家用基站。
鉴权授权服务器设置成当家用基站为闭合接入模式时判断是否允许所述 用户接入所述家用基站是指, 鉴权授权服务器根据签约信息、 用户标识信息、 家用基站标识及家用基站模式判断是否允许所述用户接入所述家用基站; 鉴权授权服务器还设置成当判断结果为允许用户接入所述家用基站时完 成用户的鉴权认证, 并于认证成功后向接入网关发送用户接入接受消息; 以 及当判断结果为不允许用户接入所述家用基站时终止鉴权流程, 并向接入网 关发送接入拒绝消息;
接入网关设置成收到接入拒绝消息后通过 EAP转发消息将鉴权失败消息 (鉴权失败消息可嵌入到 EAP转发消息中)经家用基站转发给终端;
接入网关还设置成收到用户接入接受消息后通过 EAP转发消息将鉴权成 功消息转发给家用基站, 家用基站设置成收到 EAP转发消息后解析该消息并 将 EAP转发消息转发至终端; 或者
接入网关还可以设置成通过 EAP转发消息将鉴权成功消息转发给家用基 站后向家用基站发送密钥改变指示消息, 通知家用基站用户鉴权成功; 家用 基站设置成将收到的 EAP转发消息转发至终端后接收密钥改变指示消息。
鉴权授权服务器设置成当所述家用基站为混合接入模式时确定用户类别 信息指, 鉴权授权服务器根据签约信息、 用户标识信息、 家用基站标识及家 用基站模式确定用户类别信息;
鉴权授权服务器还设置成完成用户的鉴权认证后向接入网关发送用户接 入接受消息, 其中携带用户类别信息;
接入网关还设置成收到用户接入接受消息后通过 EAP转发消息将鉴权成 功消息转发给家用基站, 其中携带用户类别信息; 所述家用基站设置成收到 EAP转发消息后解析该消息, 以及保存用户类别信息, 并通过 EAP转发消息 将鉴权成功消息转发给终端; 或者 接入网关还可以设置成收到用户接入接受消息后通过 EAP转发消息将鉴 权成功消息转发给家用基站, 并向家用基站发送密钥改变指示消息, 通知家 用基站用户鉴权成功, 其中携带用户类别信息; 所述家用基站设置成将收到 的 EAP转发消息转发至终端, 以及解析收到的密钥改变指示消息, 并保存用 户类别信息。
签约信息可以为家用基站用户的签约信息或家用基站的签约信息; 鉴权授权服务器还可以设置成保存签约信息, 或者
CSG用户服务器设置成保存签约信息,鉴权授权服务器设置成从 CSG用 户服务器下载签约信息。
本发明的一种对家用基站用户实施鉴权的方法, 如图 3至图 5所示, 该 实施例中均由鉴权授权服务器判断家用基站为闭合接入模式时用户是否可以 接入该家用基站, 以及当家用基站为混合接入模式时确定用户类别信息; 如图 3所示, 鉴权授权服务器将判断结果或用户类别信息通知给接入网 关, 接入网关再通过 EAP转发消息通知给家用基站及终端, 具体方法如下: 步骤 301 , 终端与家用基站之间完成空口参数同步及测距。
步骤 302 , 终端请求协商认证能力, 如用户的认证策略等, 并与家用基 站、 接入网关完成能力协商工作。
步骤 303 ,接入网关启动 EAP鉴权流程, 向家用基站发送用户标识请求, 家用基站将该请求转发给终端。
步骤 304, 在收到用户标识请求消息后, 终端向家用基站回复响应消息, 携带用户标识信息。 家用基站将该消息透传给接入网关。
该回复响应消息中携带的用户标识信息可以是用户的真实标识, 也可以 是用户的伪标识。
步骤 305 , 接入网关收到该响应消息后, 给鉴权授权服务器发送接入请 求消息, 并在消息中携带用户标识信息、 家用基站模式和家用基站标识。
这里, 可以直接在接入网关保存家用基站模式, 或家用基站发送消息通 知接入网关自己的家用基站模式, 本发明对所釆用的消息不作限制。
签约信息可以从 CSG用户服务器下载到鉴权授权服务器获得,也可以是 直接保存在鉴权授权服务器上的; 当鉴权授权服务器上没有签约信息时, 鉴 权授权服务器需要向 CSG用户服务器获取, 即需要执行步骤 306-307 , 否则, 直接执行步骤 308。
步骤 306 , 鉴权授权服务器收到接入请求消息, 且消息中携带有家用基 站模式时, 鉴权授权服务器向 CSG用户服务器发送签约信息请求消息, 并在 消息中携带用户标识和 /或家用基站标识。
鉴权授权服务器收到接入请求消息后, 如果无法根据该消息中的用户伪 标识找到用户的真实标识, 则可以和终端通过 EAP消息交互, 获取用户的真 实标识, 并将真实的标识与伪标识关联起来, 其与终端通过 EAP消息交互的 过程与现有技术相同, 在此不再赘述。
其中, 签约信息可以是家用基站用户的签约信息, 即该用户所允许接入 的家用基站列表; 也可以是家用基站的签约信息, 即该家用基站所允许接入 的用户列表。
当签约信息是家用基站用户的签约信息时,鉴权授权服务器向 CSG用户 服务器发送的请求消息中至少要携带用户标识(还可以携带家用基站标识); 当签约信息是家用基站的签约信息时,鉴权授权服务器向 CSG用户服务器发 送的请求消息中至少要携带家用基站标识(还可以携带用户标识) 。 步骤 307 , CSG用户服务器将签约信息通过确认消息返回给鉴权授权服 务器。
其中, 上述签约信息可以是家用基站用户的签约信息, 即该用户所允许 接入的家用基站列表; 也可以是家用基站的签约信息, 即该家用基站所允许 接入的用户列表。
步骤 308 , 鉴权授权服务器根据签约信息、 家用基站标识、 家用基站模 式及用户标识判断闭合接入模式时该用户是否可以接入该家用基站, 确定混 合接入模式时用户类别信息。
对于闭合接入模式家用基站, 鉴权授权服务器需要判断该用户是否可以 接入该家用基站, 当签约信息是家用基站用户的签约信息时, 若签约信息中 包含该家用基站标识, 说明允许该用户接入该用户基站, 否则不允许该用户 接入该用户基站; 当签约信息是家用基站的签约信息时, 若签约信息中包含 该用户标识, 说明允许该用户接入该用户基站, 否则不允许该用户接入该用 户基站; 当允许该用户接入时执行步骤 309, 当不允许该用户接入时否则终 止鉴权流程, 具体流程可参考实施例三的流程描述;
对于混合接入模式家用基站, 鉴权授权服务器需要检查该用户是否存在 于允许接入的列表中, 当签约信息是家用基站用户的签约信息时, 若签约信 息中包含该家用基站标识, 则标识该用户类别信息为 CSG用户, 否则标识该 用户类别信息为非 CSG用户; 当签约信息是家用基站的签约信息时, 若签约 信息中包含该用户标识, 标识该用户类别信息为 CSG用户, 否则标识该用户 类别信息为非 CSG用户; 然后执行步骤 309。
对于开放接入模式, 可以不用执行步骤 306至 308, 且接入请求消息中 可以不携带家用基站模式信息。
步骤 309, 终端与鉴权授权服务器之间继续进行接入鉴权流程。
上述步骤 309与步骤 306 308的先后顺序可以有不同的设定。
步骤 310 , 鉴权授权服务器完成用户认证后, 向接入网关发送用户接入 接受消息, 如果家用基站是混合接入模式, 则在该消息中携带用户类别信息。
这里, 如果是闭合模式, 则不需要携带用户类别信息, 此时携带的信息 与现有技术相同, 在此不再赘述。
步骤 311 ,接入网关通过 EAP转发消息将鉴权成功消息转发给家用基站, 家用基站为混合接入模式时携带来自鉴权授权服务器的用户类别信息。
这里, 如果是闭合模式, 则不需要携带携带用户类别信息, 此时携带的 信息与现有技术相同, 在此不再赘述。
步骤 312, 家用基站收到 EAP转发消息后, 解析该消息, 若为混合接入 模式的家用基站, 还需要获取消息携带的用户类别信息, 并保存该用户类别 信息。
这里, 如果是闭合模式, 继续现有流程, 在此不再赘述。 步骤 313 , 家用基站通过 EAP转发消息将鉴权成功消息转发给终端。 步骤 314 , 继续执行用户接入相关的其他流程。
在此流程中, 不需要家用基站再单独执行用户接入控制, 即可完成对家 用基站用户的接入控制功能。
图 4所示是本实施例的一个变例, 鉴权授权服务器将判断结果或用户类 别信息通知给接入网关,接入网关再通过 EAP转发消息经家用基站发送至终 端, 并通过密钥改变指示消息通知给家用基站; 具体方法如下:
步骤 401-410, 同步骤 301-310, 在此不再赘述。
步骤 411 ,接入网关通过 EAP转发消息将鉴权成功消息转发给家用基站, 再由家用基站转发给终端。 对于混合接入模式家用基站, 由于此时家用基站 不解析 EAP转发消息, 所以此实施例中在该消息中不携带来自鉴权授权服务 器的用户类别信息, 只在接入网关保存用户类别信息。
步骤 412 , 接入网关给家用基站发送密钥改变指示消息, 通知家用基站 鉴权成功。 对于混合接入模式家用基站, 则在此消息中携带用户类别信息。
闭合接入模式的家用基站收到密钥改变指示消息后, 直接执行步骤 414, 混合接入模式的家用基站收到密钥改变指示消息后, 执行步骤 413。
步骤 413 , 混合接入模式的家用基站解析密钥改变指示消息, 获取消息 中携带的用户类别信息, 并保存该用户类别信息。
步骤 414, 继续执行用户接入相关的其他流程。
在此流程中, 不需要家用基站再单独执行用户接入控制, 即可完成对家 用基站用户的接入控制功能。
如图 5所示, 当家用基站为闭合接入模式时, 鉴权授权服务器判定该用 户不可以接入该家用基站, 直接拒绝用户的接入的流程, 具体方法如下: 步骤 501-507 , 同步骤 301-307 , 在此不再赘述。
步骤 508 , 鉴权授权服务器根据签约信息、 家用基站标识、 家用基站模 式及用户标识判断闭合接入模式时该用户是否可以接入该家用基站, 混合接 入模式时用户类别信息。 对于闭合接入模式家用基站, 鉴权授权服务器需要 判断该用户是否可以接入该家用基站, 如果不允许用户接入, 则终止鉴权流 程。
步骤 509 , 鉴权授权服务器终止鉴权流程, 给接入网关发送接入拒绝消 息。
步骤 510, 接入网关通过 EAP转发消息将鉴权失败消息通过家用基站转 发给终端。
步骤 511 , 接入网关发起用户退网流程。
此实施例适用于闭合接入模式家用基站。
实施例二
本发明的一种对家用基站用户实施鉴权的系统, 如图 1所示, 包括: 终 端、 家用基站、 接入网关、 鉴权授权服务器及 CSG用户服务器;
接入网关设置成当终端接入闭合接入模式或混合接入模式的家用基站过 程中将用户标识信息及家用基站信息经鉴权授权服务器发送至 CSG用户服务 器;
CSG用户服务器设置成当家用基站为闭合接入模式时判断是否允许用户 接入该家用基站, 并将判断结果通过鉴权授权服务器及接入网关返回至家用 基站; 以及设置成当家用基站为混合接入模式时确定用户类别信息, 并将用 户类别信息通过鉴权授权服务器及接入网关返回至家用基站。
CSG用户服务器设置成当所述家用基站为闭合接入模式时判断是否允许 用户接入所述家用基站指, CSG用户服务器根据用户标识信息、 家用基站标 识、家用基站模式及签约信息判断是否允许所述用户接入所述家用基站, CSG 用户服务器还设置成当判断结果为允许所述用户接入所述家用基站时向鉴权 授权服务器返回确认消息, 当判断结果为不允许所述用户接入所述家用基站 时向鉴权授权服务器返回拒绝消息;
鉴权授权服务器设置成收到确认消息后完成用户的鉴权认证, 并向接入 网关发送用户接受接入消息, 以及收到拒绝消息后结束用户的鉴权认证, 并 向接入网关发送拒绝接入消息;
接入网关设置成收到拒绝接入消息后通过 EAP转发消息将鉴权失败消息 经家用基站转发给终端;
接入网关还设置成收到用户接受接入消息后通过 EAP转发消息将鉴权成 功消息转发给家用基站, 家用基站设置成收到 EAP转发消息后解析该消息, 并将其转发给终端; 或者
接入网关还可以设置成收到用户接受接入消息后通过 EAP转发消息将鉴 权成功消息转发给家用基站, 并向家用基站发送密钥改变指示消息, 通知家 用基站用户鉴权成功; 家用基站设置成将收到的 EAP转发消息转发给终端, 以及解析收到的密钥改变指示消息。
CSG用户服务器设置成当家用基站为混合接入模式时确定用户类别信息 指, CSG用户服务器根据用户标识信息、 家用基站标识、 家用基站模式及签 约信息确定用户类别信息, 并向鉴权授权服务器返回确认消息, 携带用户类 别信息;
鉴权授权服务器设置成收到确认消息后完成用户的鉴权认证, 并向接入 网关发送用户接受接入消息, 携带用户类别信息;
接入网关设置成收到用户接受接入消息后通过 EAP转发消息将鉴权成功 消息转发给家用基站, 携带用户类别信息; 家用基站设置成解析 EAP转发消 息后保存用户类别信息, 并通过 EAP转发消息将鉴权成功消息转发给终端; 或者
接入网关可以设置成收到用户接受接入消息后通过 EAP转发消息将鉴权 成功消息转发给家用基站, 并向家用基站发送密钥改变指示消息, 通知家用 基站用户鉴权成功, 携带用户类别信息; 家用基站可以设置成将收到的 EAP 转发消息转发给终端, 以及解析收到的密钥改变指示消息, 保存用户类别信 息。
本发明的一种对家用基站用户实施鉴权的方法, 如图 6至图 8所示, 该 实施例中均由 CSG用户服务器判断当家用基站为闭合接入模式时用户是否可 以接入该家用基站, 以及当家用基站为混合接入模式时确定用户类别信息; 如图 6所示, CSG用户服务器判断当家用基站为闭合接入模式时该用户 是否可以接入该家用基站,确定当家用基站为混合接入模式时用户类别信息, 将判断结果或用户类别信息通知鉴权授权服务器, 当鉴权授权服务器完成用 户认证后通过 EAP转发消息通知给家用基站及终端; 具体方法如下:
步骤 601 , 终端与家用基站之间完成空口参数同步及测距。
步骤 602 , 终端请求协商认证能力, 如用户的认证策略等, 并与家用基 站、 接入网关完成能力协商工作。
步骤 603 ,接入网关启动 EAP鉴权流程, 向家用基站发送用户标识请求, 家用基站将该请求转发给终端。
步骤 604, 在收到用户标识请求消息后, 终端向家用基站回复响应消息, 携带用户标识信息。 家用基站将该消息透传给接入网关。
该回复响应消息中携带的用户标识信息可以是用户的真实标识, 也可以 是用户的伪标识。
步骤 605 , 接入网关收到该响应消息后, 给鉴权授权服务器发送接入请 求消息, 并在消息中携带用户标识信息、 家用基站模式和家用基站标识。
可以在接入网关保存家用基站模式, 或家用基站发送消息通知接入网关 自己的家用基站模式, 本发明对所釆用的消息不作限制。
步骤 606 , 鉴权授权服务器收到接入请求消息, 且消息中携带有家用基 站模式时, 鉴权授权服务器向 CSG用户服务器发送请求消息, 并在消息中携 带用户标识、 家用基站标识及家用基站模式。
鉴权授权服务器收到接入请求消息后, 如果无法根据该消息中的用户伪 标识找到用户的真实标识, 则可以和终端通过 EAP消息交互, 获取用户的真 实标识, 并将真实的标识与伪标识关联起来, 其与终端通过 EAP消息交互的 过程与现有技术相同, 在此不再赘述。
步骤 607 , CSG用户服务器收到上述请求消息, 根据签约信息、 家用基 站标识、 家用基站模式及用户标识判断闭合接入模式时该用户是否可以接入 该家用基站, 确定混合接入模式时该用户类别信息。
这里的签约信息是在 CSG用户服务器上的有关家用基站的签约信息。 签约信息可以是家用基站用户的签约信息, 即该用户所允许接入的家用 基站列表; 也可以是家用基站的签约信息, 即该家用基站所允许接入的用户 列表。
对于闭合接入模式家用基站, CSG用户服务器需要判断该用户是否可以 接入该家用基站, 当签约信息是家用基站用户的签约信息时, 若签约信息中 包含该家用基站标识, 说明允许该用户接入该用户基站, 否则不允许该用户 接入该用户基站; 当签约信息是家用基站的签约信息时, 若签约信息中包含 该用户标识, 说明允许该用户接入该用户基站, 否则不允许该用户接入该用 户基站; 如果允许用户接入, 则继续鉴权流程, 执行步骤 608, 否则终止鉴 权流程, 具体流程可参考如图 8所示的流程描述;
对于混合接入模式家用基站,鉴权授权服务器需要判断该用户类别信息, 当签约信息是家用基站用户的签约信息时, 若签约信息中包含该家用基站标 识,则标识该用户类别信息为 CSG用户, 否则标识该用户类别信息为非 CSG 用户; 当签约信息是家用基站的签约信息时, 若签约信息中包含该用户标识, 标识该用户类别信息为 CSG用户, 否则标识该用户类别信息为非 CSG用户; 然后执行步骤 608。
步骤 608, CSG用户服务器返回确认消息给鉴权授权服务器, 对于混合 接入模式家用基站, 还需要携带用户类别信息。 其中, 用户类别信息是 CSG 用户或非 CSG用户。
对于开放接入模式, 可以不用执行步骤 606至 608, 且接入请求消息中 可以不携带家用基站模式信息。
步骤 609 , 终端与鉴权授权服务器之间继续进行接入鉴权流程。
步骤 609与步骤 606 608的先后顺序可以有不同的设定。
步骤 610 , 鉴权授权服务器完成用户认证后, 给接入网关发送用户接入 接受消息, 如果基站是混合接入模式家用基站, 则在该消息中携带用户类别 信息。 步骤 611 ,接入网关通过 EAP转发消息将鉴权成功消息转发给家用基站, 混合接入模式时携带来自鉴权授权服务器的用户类别信息。
闭合接入模式的家用基站收到 EAP转发消息后, 直接执行步骤 613 , 混 合接入模式的家用基站收到 EAP转发消息后, 执行步骤 613;
步骤 612, 混合接入模式的家用基站解析 EAP转发消息, 获取消息中携 带的用户类别信息, 并保存该用户类别信息。
步骤 613 , 家用基站通过 EAP转发消息将鉴权成功消息转发给终端。 步骤 614 , 继续执行用户接入相关的其他流程。
在此流程中, 不需要家用基站再单独执行用户接入控制, 即可完成对家 用基站用户的接入控制功能。
图 7所示是本实施例的一个变例, CSG用户服务器判断闭合接入模式时 该用户是否可以接入该家用基站, 确定混合接入模式时用户类别信息, 将判 断结果或用户类别信息通知鉴权授权服务器, 当鉴权授权服务器完成用户认 证后通过 EAP转发消息经家用基站发送至终端, 并通过密钥改变指示消息通 知给家用基站; 具体方法如下:
步骤 701-710, 同步骤 601-610, 在此不再赘述。
步骤 711 ,接入网关通过 EAP转发消息将鉴权成功消息转发给家用基站, 再由家用基站转发给终端。 对于混合接入模式家用基站, 由于此时家用基站 不解析 EAP转发消息, 所以此实施例中在该消息中不携带来自鉴权授权服务 器的用户类别信息, 只在接入网关保存用户类别信息。
步骤 712 , 接入网关给家用基站发送密钥改变指示消息, 通知家用基站 认证成功。 对于混合接入模式家用基站, 则在此消息中携带用户类别信息。
闭合接入模式的家用基站收到密钥改变指示消息后, 直接执行步骤 714, 混合接入模式的家用基站收到密钥改变指示消息后, 执行步骤 713;
步骤 713 , 混合接入模式的家用基站解析密钥改变指示消息, 获取消息 中携带的用户类别信息, 并保存用户类别信息。 步骤 714 , 继续执行用户接入相关的其他流程。
在此流程中, 不需要家用基站再单独执行用户接入控制, 即可完成对家 用基站用户的接入控制功能。
如图 8所示, 当家用基站为闭合接入模式时, CSG用户服务器判定该用 户不可以接入该家用基站, 直接拒绝用户的接入的流程, 具体方法如下: 步骤 801-806, 同步骤 601-606, 在此不再赘述。
步骤 807 , CSG用户服务器根据签约信息、 家用基站标识、 家用基站模 式及用户标识判断闭合接入模式时该用户是否可以接入该家用基站, 确定混 合接入模式时该用户类别信息。 对于闭合接入模式家用基站, CSG用户服务 器需要判断该用户是否可以接入该家用基站, 如果不允许用户接入, 则终止 鉴权流程, 执行步骤 808。
步骤 808, CSG用户服务器给鉴权授权服务器发送拒绝消息。
步骤 809 , 鉴权授权服务器终止鉴权流程, 给接入网关发送接入拒绝消 息。
步骤 810, 接入网关通过 ΕΑΡ转发消息将鉴权失败消息通过家用基站转 发给终端。
步骤 811 , 接入网关发起用户退网流程。
此实施例适用于闭合接入模式家用基站。
上述流程提供了一种对家用基站用户实施鉴权的方法, 将是否允许用户 接入家用基站系统的检查与用户的接入鉴权统一进行, 由位于核心网的鉴权 授权服务器或家用基站签约信息服务器来完成, 只将认证结果返回给家用基 站。 从而避免了在空口频繁传递用户真实标识, 和基站对用户标识的解析, 因此提供了用户标识正确性保障, 减轻了家用基站网元的处理负担, 降低了 家用基站系统的安全隐患。
为了简化描述, 上述实施例以家用基站不通过家用基站网关直接接入接 入网关, 且安全网关与接入网关合设这一应用场景为例来说明家用基站实现 紧急业务的方式。 其他实现场景, 如家用基站不通过家用基站网关接入接入 网关, 且安全网关单独设置, 或家用基站通过家用基站网关接入接入网关等 场景, 上述图 3至图 8的流程同样适用, 只是, 在家用基站和接入网关之间 的消息需要通过中间存在的网元(安全网关、 家用基站网关)进行转发, 不 会对阐述本发明造成影响, 故在此不再重复描述。
以上所述仅为本发明的较佳实施方式而已, 并非用于限定本发明。 本领 域技术人员根据本发明所作的任何修饰和变更, 均不脱离本发明所附带的权 利要求的保护范围。
工业实用性 本发明提供了一种对家用基站用户实施鉴权的系统及方法, 将是否允许 用户接入家用基站系统的检查与用户的接入鉴权统一进行, 由位于核心网的 鉴权授权服务器或家用基站签约信息服务器来完成, 只将认证结果返回给家 用基站, 从而避免了在空口频繁传递用户真实标识以及家用基站对用户标识 的解析, 因此提供了用户标识正确性保障, 减轻了家用基站网元的处理负担, 降低了家用基站系统的安全隐患, 因此本发明具有很强的工业实用性。

Claims

权 利 要 求 书
1、 一种对家用基站用户实施鉴权的方法, 该方法包括:
A、 在终端请求接入闭合接入模式或混合接入模式的家用基站过程中, 接入网关将用户标识信息、 家用基站标识及家用基站模式发送至鉴权授权服 务器, 或经所述鉴权授权服务器发送至闭合用户组 CSG用户服务器;
B、当所述家用基站为闭合接入模式时,所述鉴权授权服务器或所述 CSG 用户服务器判断是否允许终端接入所述家用基站, 并将判断结果通过所述接 入网关返回至所述家用基站; 当所述家用基站为混合接入模式时, 所述鉴权 授权服务器或所述 CSG用户服务器确定终端的用户类别信息,并将所述用户 类别信息通过所述接入网关返回至所述家用基站。
2、 如权利要求 1所述的方法, 其中:
所述鉴权授权服务器判断是否允许终端接入所述家用基站或确定终端的 所述用户类别信息的方式为: 所述鉴权授权服务器根据所述用户标识信息、 所述家用基站标识、所述家用基站模式及自身保存或从所述 CSG用户服务器 下载的签约信息判断是否允许终端接入所述家用基站或确定终端的所述用户 类别信息;
所述 CSG用户服务器判断是否允许终端接入所述家用基站或确定终端 的所述用户类别信息的方式为:所述 CSG用户服务器根据所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存的签约信息判断是否允许 终端接入所述家用基站或确定终端的所述用户类别信息。
3、 如权利要求 1或 2所述的方法, 其中:
所述用户类别信息为 CSG用户或非 CSG用户。
4、 如权利要求 1或 2所述的方法, 其中: 所述签约信息为家用基站用户 的签约信息或家用基站的签约信息。
5、 如权利要求 4所述的方法, 其中: 所述步骤 B中, 当所述家用基站为 闭合接入模式时,所述鉴权授权服务器或所述 CSG用户服务器判断是否允许 终端接入所述家用基站的方式为: 所述鉴权授权服务器确定自身保存或从所述 CSG用户服务器下载的签 约信息是家用基站用户的签约信息时,若签约信息中包含所述家用基站标识, 则允许终端接入所述家用基站, 否则不允许终端接入所述家用基站; 所述鉴 权授权服务器确定自身保存或从所述 CSG用户服务器下载的签约信息是家用 基站的签约信息时, 若签约信息中包含所述用户标识, 则允许终端接入所述 家用基站, 否则不允许终端接入所述家用基站;
所述 CSG用户服务器确定自身保存的签约信息是家用基站用户的签约 信息时, 若签约信息中包含所述家用基站标识, 则允许终端接入所述家用基 站, 否则不允许终端接入所述家用基站; 所述 CSG用户服务器确定自身保存 的签约信息是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则 允许终端接入所述家用基站, 否则不允许终端接入所述家用基站。
6、 如权利要求 3所述的方法, 其中: 所述步骤 B中, 当所述家用基站为 混合接入模式时,所述鉴权授权服务器或所述 CSG用户服务器确定终端的用 户类别信息的方式为:
所述鉴权授权服务器确定自身保存或从所述 CSG用户服务器下载的签 约信息是家用基站用户的签约信息时, 若签约信息中包含该家用基站标识, 则所述用户类别信息为所述 CSG用户,否则所述用户类别信息为所述非 CSG 用户; 所述鉴权授权服务器确定自身保存或从所述 CSG用户服务器下载的签 约信息是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则所述 用户类别信息为所述 CSG用户, 否则所述用户类别信息为所述非 CSG用户; 所述 CSG用户服务器确定自身保存的签约信息是家用基站用户的签约 信息时,若签约信息中包含该家用基站标识,则所述用户类别信息为所述 CSG 用户, 否则所述用户类别信息为所述非 CSG用户; 所述 CSG用户服务器确 定自身保存的签约信息是家用基站的签约信息时, 若签约信息中包含所述用 户标识, 则所述用户类别信息为所述 CSG用户, 否则所述用户类别信息为所 述非 CSG用户。
7、 如权利要求 1或 2所述的方法, 其中: 所述步骤 B中, 当所述家用基 站为闭合接入模式时, 所述鉴权授权服务器将判断结果通过所述接入网关返 回至所述家用基站的所述步骤包括: 若所述判断结果表示允许终端接入所述家用基站, 所述鉴权授权服务器 完成用户认证后向所述接入网关发送用户接入接受消息, 所述接入网关根据 所述用户接入接受消息通过扩展认证协议 EAP转发消息将鉴权成功消息转发 给所述家用基站, 所述家用基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关通过 EAP转发消息将所述鉴权成功消息经所述家用基站 转发给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站 用户鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站, 则终止鉴权流程, 所述鉴权授权服务器向所述接入网关发送接入拒绝消息, 所述接入网关根据 所述接入拒绝消息通过 EAP转发消息将鉴权失败消息转发给所述家用基站, 所述家用基站将所述鉴权失败消息转发给终端。
8、 如权利要求 1或 2所述的方法, 其中: 所述步骤 B中, 当所述家用基 站为混合接入模式时, 所述鉴权授权服务器将所述用户类别信息通过所述接 入网关返回至所述家用基站的所述步骤包括:
所述鉴权授权服务器在完成用户认证后向所述接入网关发送携带所述用 户类别信息的用户接入接受消息; 所述接入网关根据所述用户接入接受消息 通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析 所述鉴权成功消息并保存所述用户类别信息后通过 EAP转发消息将所述鉴权 成功消息转发给终端; 或者, 所述接入网关根据所述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发给终端; 并向所述家用基 站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户 鉴权成功, 所述家用基站保存所述用户类别信息。
9、 如权利要求 1或 2所述的方法, 其中: 所述步骤 B中, 当所述家用基 站为闭合接入模式时,所述 CSG用户服务器将判断结果通过所述接入网关返 回至所述家用基站的所述步骤包括:
若所述判断结果表示允许终端接入所述家用基站,则所述 CSG用户服务 器向所述鉴权授权服务器返回确认消息, 所述鉴权授权服务器完成用户认证 后向所述接入网关发送用户接入接受消息; 所述接入网关根据所述用户接入 接受消息通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用 基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关根据所 述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发 给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站用户 鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站,则所述 CSG用户服 务器向所述鉴权授权服务器返回拒绝消息, 所述鉴权授权服务器终止鉴权流 程, 向所述接入网关发送接入拒绝消息, 所述接入网关根据所述接入拒绝消 息通过 EAP转发消息将鉴权失败消息经所述家用基站转发给终端。
10、 如权利要求 1或 2所述的方法, 其中: 所述步骤 B中, 当所述家用 基站为混合接入模式时,所述 CSG用户服务器将所述用户类别信息通过所述 接入网关返回至所述家用基站的所述步骤包括:
所述 CSG用户服务器向所述鉴权授权服务器返回携带所述用户类别信 息的确认消息, 所述鉴权授权服务器完成用户认证后向所述接入网关发送携 带所述用户类别信息的用户接入接受消息;
所述接入网关通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析所述鉴权成功消息并保存所述用户类别信息后通过 EAP转 发消息将所述鉴权成功消息转发给终端; 或者
所述接入网关通过 EAP转发消息将鉴权成功消息经所述家用基站转发给 终端, 并向所述家用基站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户鉴权成功,所述家用基站解析所述密钥改变指示消息, 保存所述用户类别信息。
11、 一种对家用基站用户实施鉴权的鉴权授权服务器, 其中,
所述鉴权授权服务器设置成接收接入网关在终端接入闭合接入模式或混 合接入模式的家用基站的过程中发来的用户标识信息、 基站标识及家用基站 模式;
所述鉴权授权服务器还设置成当家用基站为闭合接入模式时, 判断是否 允许终端接入所述家用基站, 并将判断结果通过所述接入网关返回至所述家 用基站;
所述鉴权授权服务器还设置成当所述家用基站为混合接入模式时, 确定 终端的用户类别信息, 并将所述用户类别信息通过所述接入网关返回至所述 家用基站。
12、 如权利要求 11所述的鉴权授权服务器, 其中,
所述鉴权授权服务器还设置成当家用基站为闭合接入模式时, 根据所述 用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存或从 CSG 用户服务器下载的签约信息判断是否允许终端接入所述家用基站, 并将判断 结果通过所述接入网关返回至所述家用基站;
所述鉴权授权服务器还设置成当所述家用基站为混合接入模式时, 根据 所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存或从 所述 CSG用户服务器下载的所述签约信息确定终端的用户类别信息,并将所 述用户类别信息通过所述接入网关返回至所述家用基站。
13、 如权利要求 11或 12所述的鉴权授权服务器, 其中,
所述鉴权授权服务器还设置成确定自身保存或从所述 CSG用户服务器 下载的签约信息是家用基站用户的签约信息时, 若签约信息中包含所述家用 基站标识, 则允许终端接入所述家用基站, 否则不允许终端接入所述家用基 站;确定自身保存或从所述 CSG用户服务器下载的签约信息是家用基站的签 约信息时, 若签约信息中包含所述用户标识, 则允许终端接入所述家用基站, 否则不允许终端接入所述家用基站。
14、 如权利要求 11或 12所述的鉴权授权服务器, 其中,
所述鉴权授权服务器还设置成确定自身保存或从所述 CSG用户服务器 下载的签约信息是家用基站用户的签约信息时, 若签约信息中包含该家用基 站标识, 则所述用户类别信息为所述 CSG用户, 否则所述用户类别信息为所 述非 CSG用户; 确定自身保存或从所述 CSG用户服务器下载的签约信息是 家用基站的签约信息时, 若签约信息中包含所述用户标识, 则所述用户类别 信息为所述 CSG用户, 否则所述用户类别信息为所述非 CSG用户。
15、 如权利要求 11或 12所述的鉴权授权服务器, 其中: 所述鉴权授权 服务器还设置成通过以下方式将判断结果通过所述接入网关返回至所述家用 基站:
若所述判断结果表示允许终端接入所述家用基站, 所述鉴权授权服务器 完成用户认证后向所述接入网关发送用户接入接受消息, 所述接入网关根据 所述用户接入接受消息通过扩展认证协议 EAP转发消息将鉴权成功消息转发 给所述家用基站, 所述家用基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关通过 EAP转发消息将所述鉴权成功消息经所述家用基站 转发给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站 用户鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站, 则终止鉴权流程, 所述鉴权授权服务器向所述接入网关发送接入拒绝消息, 所述接入网关根据 所述接入拒绝消息通过 EAP转发消息将鉴权失败消息转发给所述家用基站, 所述家用基站将所述鉴权失败消息转发给终端。
16、 如权利要求 11或 12所述的鉴权授权服务器, 其中: 所述鉴权授权 服务器还设置成通过以下方式将所述用户类别信息通过所述接入网关返回至 所述家用基站:
所述鉴权授权服务器在完成用户认证后向所述接入网关发送携带所述用 户类别信息的用户接入接受消息; 所述接入网关根据所述用户接入接受消息 通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析 所述鉴权成功消息并保存所述用户类别信息后通过 EAP转发消息将所述鉴权 成功消息转发给终端; 或者, 所述接入网关根据所述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发给终端; 并向所述家用基 站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户 鉴权成功, 所述家用基站保存所述用户类别信息。
17、 一种对家用基站用户实施鉴权的系统, 该系统包括: 权利要求 11-16 中任一项所述的鉴权授权服务器。
18、 一种对家用基站用户实施鉴权的 CSG用户服务器, 其中,
所述 CSG用户服务器设置成接收接入网关在终端请求接入闭合接入模 式或混合接入模式的家用基站过程中经鉴权授权服务器发送过来的用户标识 信息、 家用基站标识及家用基站模式;
所述 CSG用户服务器还设置成当家用基站为闭合接入模式时,判断是否 允许终端接入所述家用基站, 并将判断结果通过所述接入网关返回至所述家 用基站;
所述 CSG用户服务器还设置成当所述家用基站为混合接入模式时,确定 终端的用户类别信息, 并将所述用户类别信息通过所述接入网关返回至所述 家用基站。
19、 如权利要求 18所述的 CSG用户服务器, 其中,
所述 CSG用户服务器还设置成当家用基站为闭合接入模式时,根据所述 用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存的签约信 息判断是否允许终端接入所述家用基站, 并将判断结果通过所述接入网关返 回至所述家用基站;
所述 CSG用户服务器还设置成当所述家用基站为混合接入模式时,根据 所述用户标识信息、 所述家用基站标识、 所述家用基站模式及自身保存的所 述签约信息确定终端的用户类别信息, 并将所述用户类别信息通过所述接入 网关返回至所述家用基站。
20、 如权利要求 18或 19所述的 CSG用户服务器, 其中,
所述 CSG用户服务器还设置成确定自身保存的签约信息是家用基站用 户的签约信息时, 若签约信息中包含所述家用基站标识, 则允许终端接入所 述家用基站, 否则不允许终端接入所述家用基站; 确定自身保存的签约信息 是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则允许终端接 入所述家用基站, 否则不允许终端接入所述家用基站。
21、 如权利要求 18或 19所述的 CSG用户服务器, 其中:
所述 CSG用户服务器还设置成确定自身保存的签约信息是家用基站用 户的签约信息时, 若签约信息中包含该家用基站标识, 则所述用户类别信息 为所述 CSG用户, 否则所述用户类别信息为所述非 CSG用户; 确定自身保 存的签约信息是家用基站的签约信息时, 若签约信息中包含所述用户标识, 则所述用户类别信息为所述 CSG用户,否则所述用户类别信息为所述非 CSG 用户。
22、 如权利要求 18或 19所述的 CSG用户服务器, 其中: 所述 CSG用 户服务器还设置成通过以下方式将判断结果通过所述接入网关返回至所述家 用基站:
若所述判断结果表示允许终端接入所述家用基站,则所述 CSG用户服务 器向所述鉴权授权服务器返回确认消息, 所述鉴权授权服务器完成用户认证 后向所述接入网关发送用户接入接受消息; 所述接入网关根据所述用户接入 接受消息通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用 基站解析所述鉴权成功消息后将其转发给终端; 或者, 所述接入网关根据所 述用户接入接受消息通过 EAP转发消息将鉴权成功消息经所述家用基站转发 给终端, 并向所述家用基站发送密钥改变指示消息, 通知所述家用基站用户 鉴权成功;
若所述判断结果表示不允许终端接入所述家用基站,则所述 CSG用户服 务器向所述鉴权授权服务器返回拒绝消息, 所述鉴权授权服务器终止鉴权流 程, 向所述接入网关发送接入拒绝消息, 所述接入网关根据所述接入拒绝消 息通过 EAP转发消息将鉴权失败消息经所述家用基站转发给终端。
23、 如权利要求 18或 19所述的 CSG用户服务器, 其中: 所述 CSG用 户服务器还设置成通过以下方式将所述用户类别信息通过所述接入网关返回 至所述家用基站:
所述 CSG用户服务器向所述鉴权授权服务器返回携带所述用户类别信 息的确认消息, 所述鉴权授权服务器完成用户认证后向所述接入网关发送携 带所述用户类别信息的用户接入接受消息;
所述接入网关通过 EAP转发消息将鉴权成功消息转发给所述家用基站, 所述家用基站解析所述鉴权成功消息并保存所述用户类别信息后通过 EAP转 发消息将所述鉴权成功消息转发给终端; 或者
所述接入网关通过 EAP转发消息将鉴权成功消息经所述家用基站转发给 终端, 并向所述家用基站发送携带所述用户类别信息的密钥改变指示消息, 通知所述家用基站用户鉴权成功,所述家用基站解析所述密钥改变指示消息, 保存所述用户类别信息。
24、 一种对家用基站用户实施鉴权的系统, 该系统包括: 权利要求 18-23 中任一项所述的鉴权授权服务器。
PCT/CN2009/073818 2009-05-15 2009-09-08 一种对家用基站用户实施鉴权的系统及方法 WO2010130118A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200910140441.0 2009-05-15
CN2009101404410A CN101730102B (zh) 2009-05-15 2009-05-15 一种对家用基站用户实施鉴权的系统及方法

Publications (1)

Publication Number Publication Date
WO2010130118A1 true WO2010130118A1 (zh) 2010-11-18

Family

ID=42450126

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/073818 WO2010130118A1 (zh) 2009-05-15 2009-09-08 一种对家用基站用户实施鉴权的系统及方法

Country Status (2)

Country Link
CN (1) CN101730102B (zh)
WO (1) WO2010130118A1 (zh)

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120002637A1 (en) * 2010-06-18 2012-01-05 Interdigital Patent Holdings, Inc. Method and apparatus for supporting home node-b mobility
BR112013016808B1 (pt) * 2010-12-31 2021-08-10 Huawei Technologies Co., Ltd. Método de controle de acesso para um equipamento de usuário e elemento de rede de gerenciamento de mobilidade fonte
CN102655638B (zh) * 2011-03-02 2016-11-23 华为终端有限公司 小区接入处理方法和装置、通信系统
CN103391544B (zh) * 2012-05-10 2017-04-26 华为技术有限公司 基站接入控制方法、相应的装置以及系统
WO2017201756A1 (zh) * 2016-05-27 2017-11-30 华为技术有限公司 一种下载签约信息的方法、相关设备及系统
CN108738019B (zh) * 2017-04-25 2021-02-05 华为技术有限公司 融合网络中的用户认证方法及装置
CN109587687A (zh) * 2018-12-04 2019-04-05 西安佰才邦网络技术有限公司 基站侧设备及其组网方法
CN111770554B (zh) * 2019-03-30 2022-04-22 成都华为技术有限公司 一种网络接入的方法和装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007136339A2 (en) * 2006-05-19 2007-11-29 Telefonaktiebolaget Lm Ericsson (Publ) Access control in a mobile communication system
CN101136826A (zh) * 2007-09-30 2008-03-05 中兴通讯股份有限公司 一种通过核心网控制终端接入家庭基站覆盖区域的方法
CN101400106A (zh) * 2007-09-27 2009-04-01 华为技术有限公司 一种家用基站接入控制的方法
US20090097436A1 (en) * 2007-10-12 2009-04-16 Subramanian Vasudevan Methods for access control in femto system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007136339A2 (en) * 2006-05-19 2007-11-29 Telefonaktiebolaget Lm Ericsson (Publ) Access control in a mobile communication system
CN101400106A (zh) * 2007-09-27 2009-04-01 华为技术有限公司 一种家用基站接入控制的方法
CN101136826A (zh) * 2007-09-30 2008-03-05 中兴通讯股份有限公司 一种通过核心网控制终端接入家庭基站覆盖区域的方法
US20090097436A1 (en) * 2007-10-12 2009-04-16 Subramanian Vasudevan Methods for access control in femto system

Also Published As

Publication number Publication date
CN101730102A (zh) 2010-06-09
CN101730102B (zh) 2012-07-18

Similar Documents

Publication Publication Date Title
KR102345932B1 (ko) 네트워크 보안 관리 방법 및 장치
US20220225263A1 (en) Interworking function using untrusted network
US9571482B2 (en) Secure on-line sign-up and provisioning for Wi-Fi hotspots using a device management protocol
US8555345B2 (en) User authentication and authorisation in a communications system
EP1770940B1 (en) Method and apparatus for establishing a communication between a mobile device and a network
AU2005236981B2 (en) Improved subscriber authentication for unlicensed mobile access signaling
US20080026724A1 (en) Method for wireless local area network user set-up session connection and authentication, authorization and accounting server
WO2010130118A1 (zh) 一种对家用基站用户实施鉴权的系统及方法
WO2007019771A1 (en) An access control method of the user altering the visited network, the unit and the system thereof
WO2009000206A1 (fr) Procédé et système de commande d'accès de nœud initial b
JPWO2007097101A1 (ja) 無線アクセスシステムおよび無線アクセス方法
CN114503630A (zh) 激活5g用户的方法和装置
WO2008125062A1 (fr) Procédé de détermination d'admission et de radiomessagerie d'utilisateur dans un système de communication mobile, système et dispositif apparentés
US11523332B2 (en) Cellular network onboarding through wireless local area network
US20110003546A1 (en) System and Method for Communications Device and Network Component Operation
US9137661B2 (en) Authentication method and apparatus for user equipment and LIPA network entities
WO2010124569A1 (zh) 用户接入控制方法和系统
CN101990207B (zh) 接入控制方法、家用基站及家用基站授权服务器
WO2006079953A1 (en) Authentication method and device for use in wireless communication system
WO2011015091A1 (zh) 用于家用基站的接入方法、装置、系统及aaa服务器
WO2011035643A1 (zh) 家庭基站的接入方法、家庭基站系统和家庭基站接入点
WO2010102496A1 (zh) 一种实现wapi系统终端零干预计费的方法
KR20130009836A (ko) 무선 원격통신 네트워크, 및 메시지를 인증하는 방법
CN101483521B (zh) WiMAX网络的多主机接入认证方法及系统
WO2010124608A1 (zh) 紧急业务的实现方法及家用基站

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09844530

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09844530

Country of ref document: EP

Kind code of ref document: A1