WO2010135887A1 - 移动虚拟专用网通信的方法、装置及系统 - Google Patents

移动虚拟专用网通信的方法、装置及系统 Download PDF

Info

Publication number
WO2010135887A1
WO2010135887A1 PCT/CN2009/074976 CN2009074976W WO2010135887A1 WO 2010135887 A1 WO2010135887 A1 WO 2010135887A1 CN 2009074976 W CN2009074976 W CN 2009074976W WO 2010135887 A1 WO2010135887 A1 WO 2010135887A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
address
mobile
gateway
terminal
Prior art date
Application number
PCT/CN2009/074976
Other languages
English (en)
French (fr)
Inventor
朱泉
郭�东
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to JP2012512180A priority Critical patent/JP5412695B2/ja
Priority to EP20090845103 priority patent/EP2426885B9/en
Priority to KR1020117029643A priority patent/KR101313831B1/ko
Publication of WO2010135887A1 publication Critical patent/WO2010135887A1/zh
Priority to US13/302,860 priority patent/US9084108B2/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/26Network addressing or numbering for mobility support
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0272Virtual private networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • H04L61/5014Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W40/00Communication routing or communication path finding
    • H04W40/24Connectivity information management, e.g. connectivity discovery or connectivity update
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/16WPBX [Wireless Private Branch Exchange]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/16Gateway arrangements

Definitions

  • the present invention relates to the field of communications, and in particular, to a method, device and system for mobile virtual private network communication. Background technique
  • VPN Virtual Private Network
  • ISP Internet Service Provider
  • NSP Network Service Provider
  • Fixed network VPN uses a fixed communication network to provide users with VPN access
  • mobile VPN uses GPRS (General Packet Radio Service)
  • AVCDMA Wide-Broadband Code Division Multiplex Access
  • CDMA Code Division Multiplex Access
  • LTE-SAE Long Term Evolution-System Architecture Evolution, 3GPP Long Term Evolution - System Architecture Evolution
  • MS Mobile Subscriber, mobile terminal
  • MS Mobile Subscriber, mobile terminal
  • the Router serves a mobile VPN branch network.
  • the mobile packet gateway needs to obtain the network segment IP address information of the mobile VPN branch network served by the MS, and thus the IP address of the MS and The network segment IP address of the mobile VPN branch network is associated with the same PDP context (Packet Data Protocol Context), thereby enabling the MS and the mobile VPN. All hosts on the branch network exchange IP traffic with external devices through the associated PDP context using their respective IP addresses.
  • PDP context Packet Data Protocol Context
  • the mobile packet gateway obtains the IP address of the MS and the network segment IP address of the mobile VPN branch network served by the AAA Server (Authentication Authorization Accounting Server):
  • the MS moves when activated.
  • the packet gateway sends a Radius Access Request message to the AAA server according to a preset setting; the AAA server determines the IP address of the MS that is pre-stored after the MS is enabled with the MS Router function, and the mobile served by the MS.
  • the network segment IP address of the VPN branch network is added in the Radius Access Accept message and returned to the mobile packet gateway.
  • the mobile packet gateway obtains the IP address of the MS from the Radius Access Accept message, and the mobile VPN branch network. Network segment IP address.
  • the inventor has found that at least the following problems exist in the prior art: If the mobile VPN communication is performed by using the technical solution in the prior art, the network segment IP address of the mobile VPN branch network stored on the AAA server The information is pre-configured, and the mobile VPN branch network served by the MS often changes. Therefore, it is necessary to manually modify the network segment IP address information of the mobile VPN branch network stored on the AAA server in order to make the mobile packet gateway available according to the new Mobile VPN communication is performed on the network segment IP address of the mobile VPN branch network. Thus, network maintenance using prior art is less efficient.
  • Embodiments of the present invention provide a method, apparatus, and system for mobile virtual private network communication, which can improve network maintenance efficiency.
  • a method for mobile virtual private network communication comprising:
  • a device for mobile virtual private network communication comprising:
  • a network address obtaining unit configured to acquire a terminal network address and a gateway virtual interface network address, where the gateway virtual interface network address and the terminal network address belong to the same network segment;
  • An interface creation unit configured to create a virtual interface for a packet data protocol context of the mobile terminal according to the network address of the gateway virtual interface obtained by the network address obtaining unit;
  • a network address sending unit configured to send, to the mobile terminal, a terminal network address obtained by the network address obtaining unit
  • a branch address obtaining unit configured to create a mobile virtual private network communication by using the interface creation unit according to a dynamic routing protocol, including:
  • the gateway virtual interface network address and the terminal network address belong to the same network segment;
  • the network segment address of the served branch network is notified to the mobile packet gateway by a virtual interface having the gateway virtual interface network address according to a dynamic routing protocol.
  • a mobile terminal includes:
  • a terminal address obtaining unit configured to acquire a terminal network address from the mobile packet gateway
  • An interface address obtaining unit configured to acquire a gateway virtual interface network address of the mobile packet gateway according to the terminal network address obtained by the terminal address obtaining unit, where the gateway virtual interface network address and the terminal network address belong to the same network segment;
  • the branch address notification unit is configured to notify the mobile packet gateway of the network segment address of the served branch network by using a virtual interface having the gateway virtual interface network address according to the dynamic routing protocol.
  • a system for mobile virtual private network communication comprising at least one mobile terminal and a mobile packet gateway:
  • the mobile packet gateway is configured to obtain a terminal network address and a gateway virtual interface network address, where the gateway virtual interface network address and the terminal network address belong to the same network segment; a packet data protocol context of the mobile terminal creates a virtual interface; and sends the terminal network address to the mobile terminal; and the virtual terminal is used to obtain a terminal network address from the mobile packet gateway according to the dynamic routing protocol; And obtaining the gateway virtual interface network address of the mobile packet gateway, where the gateway virtual interface network address and the terminal network address belong to the same network segment; and the virtual interface network address of the gateway is adopted according to the dynamic routing protocol.
  • the virtual interface notifies the mobile packet gateway of the network segment address of the served branch network.
  • the method, the device and the system for the mobile virtual private network communication create a virtual interface for the packet data protocol context of the mobile terminal by using the mobile packet gateway, and the virtual interface and the mobile terminal are respectively configured with the same network segment.
  • the network packet address is obtained by the mobile packet gateway from the mobile terminal in real time through the virtual interface to obtain the latest network segment address of the branch network served by the mobile terminal. Therefore, the technical solution of the embodiment of the present invention solves the problem of manually modifying the network segment address of the branch network on the AAA Server when the network segment address of the mobile VPN branch network served by the MS changes, thereby improving the network. The effect of maintenance efficiency.
  • FIG. 1 is a flowchart of a method for mobile virtual private network communication according to an embodiment of the present invention
  • FIG. 2 is a flowchart of another method for mobile virtual private network communication according to an embodiment of the present invention
  • FIG. 4 is a flowchart of another method for mobile virtual private network communication according to an embodiment of the present invention
  • FIG. 5 is another mobile virtual specialization according to an embodiment of the present invention
  • FIG. 6 is a schematic structural diagram of a device for mobile virtual private network communication according to an embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of a mobile terminal according to an embodiment of the present disclosure.
  • FIG. 8 is a schematic structural diagram of another system for mobile virtual private network communication according to an embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of another system for mobile virtual private network communication according to an embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of another system for mobile virtual private network communication according to an embodiment of the present invention.
  • FIG. 11 is a networking diagram of a method for using a mobile virtual private network according to an embodiment of the present invention. detailed description
  • the embodiment of the present invention provides a method for the mobile virtual private network communication.
  • the method for the mobile virtual private network communication includes:
  • the mobile packet gateway obtains a terminal network address and a gateway virtual interface network address, where the gateway virtual interface network address and the terminal network address belong to the same network segment.
  • terminal network address refers to the network address assigned by the mobile packet gateway to the mobile terminal
  • gateway virtual interface network address refers to the mobile The network address assigned by the packet gateway to the created virtual interface
  • the mobile packet gateway may acquire the terminal network address and the gateway virtual interface network address at the same time, or first obtain the terminal network address and the MS service from the AAA server according to the prior art.
  • the network segment address of the branch network is obtained.
  • the network address of the gateway virtual interface belonging to the same network segment is obtained according to the obtained terminal network address.
  • the mobile packet gateway creates a virtual interface for the packet data protocol context of the mobile terminal according to the gateway virtual interface network address.
  • the mobile packet gateway sends the terminal network address to the mobile terminal.
  • Steps 102 and 103 may be performed simultaneously, or step 102 may be performed first and then step 103 may be performed. Alternatively, step 103 may be performed first and then step 102 may be performed.
  • the mobile packet gateway obtains, by the virtual interface, a network segment address of a branch network served by the mobile terminal from the mobile terminal according to a dynamic routing protocol.
  • the mobile packet gateway and the mobile terminal may pass the The virtual interface and the interface of the mobile terminal exchange dynamic routing protocol packets, where the dynamic routing protocol packet sent by the mobile terminal to the mobile packet gateway includes the network segment address of the branch network. Therefore, the mobile packet gateway can obtain the network segment address of the branch network from the dynamic routing protocol packet sent by the mobile terminal in real time. Therefore When the network segment address of the branch network changes, the dynamic routing protocol packet sent by the mobile terminal to the mobile packet gateway includes the network segment address of the branch network, and the mobile packet gateway can receive the mobile terminal through the virtual interface. The dynamic routing protocol packet sent by the terminal obtains the network segment address of the branch network after the change, so that the new network segment address of the branch network can be obtained in real time.
  • the mobile packet gateway Before the mobile packet gateway obtains the network segment address of the branch network from the MS through the virtual interface according to the dynamic routing protocol, the mobile packet gateway may send an activation response including the terminal network address to the MS, so that the MS uses the terminal network address.
  • the method for forwarding the IP traffic through the associated PDP context, and the method for the mobile virtual private network communication provided by the embodiment of the present invention obtains the branch from the mobile terminal through the virtual interface in real time by using the mobile packet gateway according to the dynamic routing protocol.
  • the technical solution of the latest network segment address of the network thus avoiding the problem of manually modifying the network segment address of the branch network on the AAA Server when the network segment address of the mobile VPN branch network served by the MS changes, thereby improving The effect of network maintenance efficiency.
  • the mobile packet gateway may simultaneously acquire the terminal network address and the gateway virtual interface network address by using at least the following three schemes: the mobile packet gateway obtains the terminal network address and the gateway virtual interface network address through the AAA server; the mobile packet gateway is locally Obtain the terminal network address and the gateway virtual interface network address; the mobile packet gateway obtains the terminal network address and the gateway virtual interface network address through a DHCP Server (Dynamic Host Configuration Protocol Server).
  • DHCP Server Dynamic Host Configuration Protocol Server
  • the mobile packet gateway obtains the terminal network address and the gateway virtual interface network to the address through the AAA server.
  • a method for moving a virtual private network communication includes:
  • the mobile terminal sends an activation request to the mobile packet gateway.
  • the activation request is a PDP context activation request.
  • the MS moves to a packet gateway (eg GGSN (Gateway GPRS Support Nodes, Gateway GPRS) Support node))
  • GGSN Gateway GPRS Support Nodes
  • Gateway GPRS Gateway GPRS Support node
  • the MS sends a PDP context activation request to the SGSN (Serving GPRS Support Nodes), and the activation request includes an APN (Access Point Name).
  • SGSN Server GPRS Support Nodes
  • APN Access Point Name
  • the SGSN determines the accessibility of the MS according to the APN, and obtains the corresponding GGSN address through the DNS Server (Domain Name System Server), and forwards the PDP context activation request of the MS to the GGSN.
  • DNS Server Domain Name System Server
  • the mobile packet gateway After receiving the activation request of the mobile terminal, the mobile packet gateway sends an address request message to the authentication authorization charging server.
  • the address request message can have multiple implementations, such as a Radius Access Request message.
  • the authentication authorization charging server sends an address response message to the mobile packet gateway.
  • the AAA server pre-stores the terminal network address, that is, the IP address of the MS and the network mask.
  • the AAA server also stores the corresponding gateway virtual interface network address.
  • the virtual interface network address of the gateway is one of the IP addresses of the mobile packet gateway, where the gateway virtual interface network address is used for The MS is interconnected, and a dynamic routing protocol is started, and the gateway virtual interface network address belongs to the same network segment as the terminal network address.
  • the AAA Server When the MS is enabled with the MS Router function, the AAA Server adds the stored terminal network address and the corresponding gateway virtual interface network address to the address response message, and sends the address response message to the mobile packet gateway. When the MS Router function is not enabled, the AAA Server adds the stored terminal network address to the address response message, and sends the address response message to the mobile packet gateway.
  • the address response message may be implemented in multiple manners. For example, when the address request message is implemented by a Radius Access Request message, the address response message may be implemented by a Radius Access Accept message.
  • information such as the IP address of the MS can be used in the Radius Access Accept message in multiple ways: You can use private extended attributes, such as "Vendor-Specific" defined in RFC2865. The attributes are customized to include information such as the IP address of the MS; you can also use the standard definitions already defined in RFC2865, the examples "Framed-IP-Address", "Framed-IP-Netmask" and
  • the IP address of the mobile terminal MS represented by "Framed-IP-Address" and "Framed-IP-Netmask” is in the same network segment.
  • the mobile packet gateway parses the address response message, and obtains the terminal network address and the gateway virtual interface network address from the address response message.
  • the mobile packet gateway parses the address response message, and when determining that the MS is enabled with the MS Router function, obtaining the terminal network address and the gateway virtual interface network address from the address response message, determining that the MS is not When the MS Router function is enabled, the terminal network address is obtained from the address response message.
  • the mobile packet gateway may determine whether the MS is enabled by the MS according to whether the address response message includes the gateway virtual interface network address. For example, when the gateway virtual interface network includes the "Gateway address" field in the "Framed-Route" address of the Radius Access Accept message, the mobile packet gateway determines the MS only when the Radius Access Accept message contains "Framed-Route". The MS Router function has been activated.
  • the mobile packet gateway may determine whether the MS is enabled by the MS according to whether the MS Router flag or the included MS Router flag is included in the address response message.
  • the mobile packet gateway creates a virtual interface for the packet data protocol context of the mobile terminal according to the gateway virtual interface network address.
  • the mobile packet gateway When the MS is enabled with the MS Router function, the mobile packet gateway obtains the PDP context associated with the terminal network address, that is, the PDP context of the MS.
  • the mobile packet gateway creates a virtual interface for the PDP context, and the network address of the virtual interface is the virtual interface network address of the gateway.
  • Moving point The group gateway encapsulates and decapsulates the user plane tunnel corresponding to the PDP context for the IP packets that enter and exit the virtual interface.
  • the mobile packet gateway sends an activation response to the mobile terminal, where the activation response includes the terminal network address.
  • the process of sending an activation response to the MS by the mobile packet gateway may be specifically:
  • the GGSN sends an activation response including the IP address of the MS and the network mask to the SGSN, and the SGSN forwards the activation response to the SGSN.
  • the MS may be specifically:
  • the GGSN sends an activation response including the IP address of the MS and the network mask to the SGSN, and the SGSN forwards the activation response to the SGSN.
  • the mobile terminal After receiving the activation response, the mobile terminal acquires the terminal network address from the activation response.
  • the network address of the gateway virtual interface belongs to the same network segment as the terminal network address.
  • the mobile terminal notifies the mobile packet gateway of the network segment address of the served branch network through a virtual interface having the gateway virtual interface network address according to a dynamic routing protocol.
  • Manner 1 The network segment address of the branch network can be pre-configured on the MS.
  • Mode 2 The dynamic routing protocol can also be started between the MS and the hosts of the mobile VPN branch network it serves. The MS can obtain the dynamic routing protocol according to the dynamic routing protocol.
  • the neighboring nodes exchange some dynamic routing protocol packets, and these dynamic routing protocol packets are exchanged. It includes routing information for the network. Therefore, the MS may exchange dynamic routing protocol packets with the hosts of the mobile VPN branch network that it serves, and obtain routing information of the branch network from the packets, where the routing information of the branch network includes the branches.
  • the network segment address of the network that is, the network segment IP address of the mobile VPN branch network.
  • the virtual interface created by the mobile packet gateway belongs to the same network segment as the terminal network address of the MS. Therefore, dynamic routing protocols can be started on the virtual interface and the interface of the MS respectively. For example, OSPF (Open Shortest Path First) or RIP (Routing Information Protocol). After that, the mobile packet gateway and the MS will respectively discover that they are neighboring nodes, so that the MS learns the gateway virtual interface network address through the dynamic protocol, and thus can exchange routing information.
  • OSPF Open Shortest Path First
  • RIP Rastered Information Protocol
  • the mobile packet gateway and the MS exchange dynamic routing protocol packets with the virtual interface and the MS interface, and obtain the dynamic routing protocol packet sent by the MS from the host of the mobile VPN branch network it serves or according to the pre-configuration.
  • the MS After the network segment address of the branch network, the MS includes the network segment address of the branch network in the dynamic routing protocol packet sent to the mobile packet gateway, so that the mobile packet gateway can obtain the network segment of the branch network from the packet. address.
  • the mobile packet gateway After obtaining the network segment address of the mobile VPN branch network served by the MS, the mobile packet gateway determines the PDP context associated with the network address of the MS, and associates the network segment address of the branch network with the PDP context. Therefore, the mobile packet gateway can transmit the traffic of the network segment address through the user plane tunnel corresponding to the PDP context associated with the mobile packet gateway, and implement VPN communication of the traffic of the network segment address.
  • the mobile routing gateway also encapsulates and decapsulates the user plane tunnel corresponding to the associated PDP context.
  • the mobile packet gateway can forward the IP traffic through the associated PDP context when the source address of the IP traffic is the IP address of the MS or the network segment IP address of the mobile VPN branch network during the uplink traffic forwarding process. And, in the downlink (Downlink) service traffic forwarding process, when the destination address of the allowed IP traffic is the IP address of the MS or the network segment IP address of the mobile VPN branch network, the IP traffic is forwarded through the associated PDP context.
  • Downlink Downlink
  • the VPN branch network and the headquarters network cannot know each other's network topology.
  • the embodiment of the present invention can further implement that the mobile VPN branch network and the headquarters network can respectively obtain network topologies of each other, so as to dynamically adjust the flow direction of the IP traffic.
  • the dynamic routing protocol can also be started between the mobile packet gateway and the mobile VPN headquarters network. In this way, the mobile packet gateway can obtain the network topology of the mobile VPN branch network from the dynamic routing protocol packet interacting with the MS, and the network topology will be obtained. The network topology of the mobile VPN branch network is notified to the mobile VPN headquarters network through dynamic routing protocol packets.
  • the mobile packet gateway can obtain the network topology of the mobile VPN headquarters network from the dynamic routing protocol packet that interacts with the mobile VPN headquarters network, and obtain the network topology of the mobile VPN headquarters network through the dynamic routing protocol packet notification.
  • the MS is notified to the mobile VPN branch network through the MS.
  • the mobile packet gateway may also interact with the mobile terminal to monitor network information through the virtual interface, and detect network quality between the mobile terminal and the mobile terminal according to the network monitoring information, where the mobile terminal is detected. When the network quality is poor, the corresponding adjustment can be made in time.
  • other standard, or non-standard, custom communications can also be initiated between the Mobile Packet Gateway and the MS for other information.
  • the changed address information may be configured on the MS or obtained by the MS according to the dynamic routing protocol. Further, the MS includes the changed network segment address of the branch network in the dynamic routing protocol sent to the mobile packet gateway, so that the mobile packet gateway can obtain the changed network segment address of the branch network from the packet. .
  • FIG. 11 is a networking diagram of a method for implementing mobile virtual private network communication according to an embodiment of the present invention.
  • the mobile packet gateway creates a virtual interface for the mobile terminal 1 and the mobile terminal 2 that activates the MS Router function, and the dynamic routing protocol packets between the mobile terminal 1 and the mobile terminal 2 and the mobile packet gateway respectively enter and exit the virtual interfaces respectively created, that is, The dynamic routing protocol is transmitted through the user plane tunnel of the PDP context of the mobile terminal 1 and the mobile terminal 2 respectively.
  • the mobile terminal can be connected to the mobile packet gateway through the radio access network.
  • the mobile packet gateway After the mobile terminal 1 sends the dynamic routing protocol message to the mobile packet gateway, the mobile packet gateway receives and parses the dynamic routing protocol message, and can learn that the destination IP address of the IP address received by the subsequent mobile packet gateway is located in the network segment of the branch network 1. When the ABCx is in the range, the mobile packet gateway knows that the next hop address of the IP address is the IP address assigned after the mobile terminal 1 is activated. And after the mobile terminal 2 sends the dynamic routing protocol message to the mobile packet gateway, the mobile packet gateway receives and parses the The dynamic routing protocol text can be learned that when the destination IP address of the IP packet received by the subsequent mobile packet gateway is within the DEFy range of the branch network 2, the mobile packet gateway learns that the next hop address of the IP document is the mobile terminal. 2 The IP address assigned after activation.
  • the mobile terminal 1 After the mobile packet gateway sends the dynamic routing protocol message to the mobile terminal 1, the mobile terminal 1 receives and parses the dynamic routing protocol message, and can learn that the destination IP address of the "3 ⁇ 4 text" received by the subsequent mobile terminal 1 is located at the headquarters network 1 When the network segment is within the range of the network segment, the mobile terminal 1 learns that the next hop address of the IP packet is the virtual interface IP address of the mobile packet gateway located on the same network segment as the network address of the mobile terminal 1. And, the mobile packet gateway sends the mobile packet to the mobile terminal 2.
  • the mobile terminal 2 receives and parses the dynamic routing protocol packet, and learns that when the destination IP address of the IP packet received by the subsequent mobile terminal 2 is within the network segment of the headquarters network 2, the mobile terminal 2 learns The next hop address of the IP packet is the virtual interface IP address of the mobile packet gateway located on the same network segment as the network address of the mobile terminal 2.
  • the mobile packet gateway After receiving the dynamic routing protocol packet sent by the mobile terminal 1 and the mobile terminal 2, the mobile packet gateway can respectively obtain the network segment IP address information ABCx and DEFy of the branch network 1 and the branch network 2 from the dynamic routing protocol packets, and After receiving the dynamic routing protocol packet sent by the mobile packet gateway, the mobile terminal 1 and the mobile terminal 2 can respectively obtain the network segment IP address information of the headquarters network 1 and the headquarters network 2 from the dynamic routing protocol packets. And other routing information.
  • the mobile terminal 1 and the router 1 of the headquarters network 1 can obtain routing information of each other by using the routing protocol message between the mobile terminal 1 and the mobile packet gateway, and between the mobile packet gateway and the router 1 of the headquarters network 1.
  • the routing information can be exchanged between the mobile terminal 1 and the router 1 of the headquarters network 1 to dynamically adjust the traffic flow.
  • the mobile terminal 2 and the router 2 of the headquarters network 2 can also exchange routing information with each other, thereby dynamically adjusting the traffic flow.
  • the mobile packet gateway After obtaining the routing information, the mobile packet gateway allows IP traffic with ABCx and dery as source addresses to be tunneled via the user plane of the PDP context of the mobile terminal 1 and the mobile terminal 2, respectively, and allows IP traffic with ABCx and DEFy as destination addresses.
  • the user plane tunneling of the PDP context of the mobile terminal 1 and the mobile terminal 2 respectively realizes normal forwarding of mobile VPN service traffic.
  • the mobile packet gateway obtains the terminal network address and the gateway virtual interface network address locally.
  • Step 401 is the same as step 301.
  • the mobile packet gateway After receiving the activation request of the mobile terminal, the mobile packet gateway acquires a network segment address from the local address pool when the mobile terminal activates the mobile router function.
  • the mobile packet gateway pre-stores whether the MS has the configuration information of the MS Router function. Therefore, after receiving the activation request of the MS, the mobile packet gateway determines whether the MS is activated by the MS Router function according to the stored configuration information, or when the user sends the AAA server to the AAA server. At the time of authentication, the mobile packet gateway learns from the AAA that the MS has activated the MS Router function.
  • the mobile packet gateway obtains a network segment IP address from the local address pool when the MS is enabled to perform the MS Router function. For example, under IPV4, the corresponding network segment mask length does not exceed 30, or the network segment mask length can be Pre-agreed.
  • the mobile packet gateway determines two network addresses from the obtained network segment addresses, and one of the network addresses is used as the terminal network address of the mobile terminal to the mobile terminal, and the other network address is used as the gateway virtual interface network address.
  • Steps 404 to 407 are the same as steps 305 to 308, and the principle and process of routing information exchange and normal forwarding of mobile VPN service traffic are the same.
  • the third scheme the mobile packet gateway obtains the terminal network address and the gateway virtual interface network address through the DHCP server.
  • Step 501 is the same as step 301.
  • the mobile packet gateway After receiving the activation request of the mobile terminal, the mobile packet gateway sends an address request message to the dynamic host allocation protocol server.
  • the address request message can have multiple implementations, such as an address assignment request (DHCP REQUEST) message.
  • DHCP REQUEST address assignment request
  • the dynamic host allocation protocol server sends an address response message to the mobile packet gateway.
  • the DHCP server pre-stores the terminal network address, that is, the IP address of the MS and the network mask.
  • the DHCP server also stores the corresponding gateway virtual interface network address, that is, the MS.
  • the IP address of the interconnected mobile packet gateway, and the gateway virtual interface network address belongs to the same network segment as the terminal network address.
  • the DHCP server When the MS Router function is enabled on the MS, the DHCP server adds the stored terminal network address and the corresponding gateway virtual interface network address to the address response message, and sends the address response message to the mobile packet gateway. When the MS Router function is not enabled in the MS, the DHCP server adds the stored terminal network address to the address response message, and sends the address response message to the mobile packet gateway.
  • the address response message may be implemented in multiple manners. For example, when the address request message is implemented by the address allocation request message, the address response message may be implemented by an address assignment response (DHCP OFFER/DHCP ACK) message. Moreover, the information such as the IP address of the MS may be included in the DHCP OFFER/DHCP ACK message. For example, the private extended attribute may be used, for example, the "OPTIONS" attribute defined in RFC2131 is customized to include the IP of the MS. Address and other information.
  • the mobile packet gateway parses the address response message, and obtains the terminal network address and the gateway virtual interface network address from the address response message.
  • the mobile packet gateway parses the address response message, and determines that the MS is activated by the MS Router And obtaining the terminal network address and the gateway virtual interface network address from the address response message, and obtaining the terminal network address from the address response message when determining that the MS does not activate the MS Router function.
  • the mobile packet gateway may determine, according to whether the gateway virtual interface network address is included in the address response message, whether the MS is enabled with the MS Router function, or whether the MS Router flag is included according to the address response message. Or the value of the MS Router flag included to determine whether the MS has enabled the MS Router function.
  • Steps 505 to 508 are the same as steps 305 to 308, and the routing information interaction and the principle and process of realizing the normal forwarding of the mobile VPN service flow are the same.
  • the mobile virtual private network communication method provided by the embodiment of the present invention adopts a technical solution that the mobile packet gateway obtains the latest network segment address of the branch network from the mobile terminal in real time through the virtual interface according to the dynamic routing protocol. Therefore, the problem of manually modifying the network segment address of the branch network on the AAA Server when the network segment address of the mobile VPN branch network served by the MS is changed is avoided, thereby improving the network maintenance efficiency.
  • the mobile packet gateway can obtain the latest network segment address of the branch network from the mobile terminal through the virtual interface at any time, and also solves the problem that the mobile packet gateway can only acquire a new branch network when the mobile terminal is activated again. The problem with the segment address. Therefore, the network maintenance operation can be further improved.
  • the technical solution of the dynamic routing protocol message between the mobile packet gateway and the MS, and between the mobile packet gateway and the mobile VPN headquarters network can be adopted, thereby solving the problem that the network topology cannot be changed in time according to the network topology.
  • the IP traffic flow between the mobile VPN branch network and the headquarters network is adjusted, resulting in an unreasonable traffic configuration. Therefore, the mobile VPN branch network and the headquarters network can dynamically adjust the flow of IP traffic according to the network topology obtained by each. Make the traffic configuration more reasonable.
  • the embodiment of the present invention provides another method for the mobile virtual private network communication.
  • the method for the mobile virtual private network communication includes:
  • the mobile terminal acquires a terminal network address from the mobile packet gateway.
  • the MS may send an activation request to the mobile packet gateway, and receive an activation response sent by the mobile packet gateway, including the terminal network address, and obtain the terminal network address from the activation response.
  • the network address of the gateway virtual interface belongs to the same network segment as the terminal network address.
  • the mobile terminal notifies the mobile packet gateway of the network segment address of the served branch network by using a virtual interface having the gateway virtual interface network address according to the dynamic routing protocol.
  • the method for the mobile virtual private network communication provided by the embodiment of the present invention is a technical solution for notifying the latest network segment address of the branch network to the corresponding mobile packet gateway in real time through the virtual interface according to the dynamic routing protocol. Therefore, the problem of manually modifying the network segment address of the branch network on the AAA Server when the network segment address of the mobile VPN branch network served by the MS is changed is avoided, thereby improving the network maintenance efficiency.
  • the embodiment of the present invention further provides a device for moving a virtual private network communication.
  • the device for moving a virtual private network communication includes:
  • the network address obtaining unit 601 is configured to obtain a terminal network address and a gateway virtual interface network address, where the gateway virtual interface network address and the terminal network address belong to the same network segment;
  • the network address obtaining unit 601 further includes: an address request sending subunit, configured to send an address request message to an authentication authorization charging server or a dynamic host allocation protocol server; and an address response receiving subunit, configured to receive the address Defining an address response message sent by the authentication authorization accounting server or the dynamic host allocation protocol server; a network address obtaining subunit, configured to parse the address response message received by the address response receiving subunit, from the address response message Obtaining the terminal network address and the gateway virtual interface network address.
  • the network address obtaining unit 601 further includes: a network segment address obtaining subunit, configured to acquire a network segment address from the local address pool when the mobile terminal activates the mobile router function; the network address determining subunit, a network for obtaining a subunit from the network segment address Two network addresses are determined in the segment address, one of the network addresses is used as the terminal network address, and the other network address is used as the gateway virtual interface network address.
  • the interface creation unit 602 is configured to create a virtual interface for the packet data protocol context of the mobile terminal according to the network address of the gateway virtual interface obtained by the network address obtaining unit 601;
  • a network address sending unit 603, configured to send the terminal network address acquired by the network address obtaining unit 601 to the mobile terminal;
  • the network address sending unit 603 further includes: a response sending subunit, configured to send an activation response to the mobile terminal, where the activation response includes a terminal network address acquired by the network address obtaining unit 601.
  • the branch address obtaining unit 604 is configured to create a unit network segment address by using the interface according to a dynamic routing protocol.
  • the branch address obtaining unit 604 further includes: a packet receiving subunit, configured to receive, by using the virtual interface, a dynamic routing protocol packet sent by the mobile terminal; and a network segment address obtaining subunit, configured to The network segment address of the branch network is obtained in the dynamic routing protocol packet received by the packet receiving subunit.
  • the branch address obtaining unit 604 further includes: a ground data protocol context association.
  • the device for moving the virtual private network communication further includes a request receiving unit, configured to receive an activation request of the mobile terminal.
  • the device for the mobile virtual private network communication further includes:
  • a branch topology obtaining unit configured to acquire, by the virtual interface, a network topology of the branch network from the mobile terminal according to a dynamic routing protocol.
  • the headquarters topology obtaining unit is configured to obtain a network topology of the headquarters network according to the dynamic routing protocol
  • the headquarters topology notification unit is configured to use the virtual interface to obtain the network extension obtained by the headquarters topology obtaining unit according to the dynamic routing protocol. Park informs the mobile terminal.
  • the device for the mobile virtual private network communication further includes:
  • a monitoring information acquiring unit configured to acquire network monitoring information from the mobile terminal by using the virtual interface
  • the network quality detecting unit is configured to detect network quality between the mobile terminal and the mobile terminal according to the network monitoring information acquired by the monitoring information acquiring unit.
  • the device for mobile virtual private network communication may be a mobile packet gateway, such as a GGSN.
  • the device for the mobile virtual private network communication provided by the embodiment of the present invention adopts a technical solution that the mobile packet gateway obtains the latest network segment address of the branch network from the mobile terminal through the virtual interface in real time according to the dynamic routing protocol. Therefore, the problem of manually modifying the network segment address of the branch network on the AAA Server when the network segment address of the mobile VPN branch network served by the MS is changed is avoided, thereby improving the network maintenance efficiency.
  • the mobile packet gateway can obtain the latest network segment address of the branch network from the mobile terminal through the virtual interface at any time, and also solves the problem that the mobile packet gateway can only acquire a new branch network when the mobile terminal is activated again. The problem with the segment address. Therefore, the network maintenance operation can be further improved.
  • the technical solution of the dynamic routing protocol message between the mobile packet gateway and the MS, and between the mobile packet gateway and the mobile VPN headquarters network can be adopted, thereby solving the problem that the network topology cannot be changed in time according to the network topology.
  • the IP traffic flow between the mobile VPN branch network and the headquarters network is adjusted, resulting in an unreasonable traffic configuration. Therefore, the mobile VPN branch network and the headquarters network can dynamically adjust the flow of IP traffic according to the network topology obtained by each. Make the traffic configuration more reasonable.
  • the embodiment of the present invention further provides a mobile terminal.
  • the device for moving the virtual private network according to the embodiment of the present invention includes:
  • the terminal address obtaining unit 701 is configured to obtain a terminal network address from the mobile packet gateway, and the interface address obtaining unit 702 is configured to obtain a gateway virtual interface network address of the mobile packet gateway according to the terminal network address acquired by the terminal address obtaining unit 701.
  • Gateway virtual interface network The network address belongs to the same network segment as the terminal network address;
  • the branch address notification unit 703 is configured to notify the mobile packet gateway of the network segment address of the served branch network by using a virtual interface having the gateway virtual interface network address according to the dynamic routing protocol.
  • the branch address notification unit 703 further includes: a branch address obtaining sub-unit, configured to acquire a network segment address of the branch network according to a dynamic routing protocol, or obtain a pre-configured network segment address of the branch network; An address adding subunit, configured to add a network segment address of the branch network in a dynamic routing protocol packet, and a message sending subunit, configured to send the dynamic routing protocol report to the mobile packet gateway by using the virtual interface Text.
  • the terminal address obtaining unit 701 further includes: a request sending unit, configured to send an activation request to the mobile packet gateway; and a response receiving unit, configured to receive an activation response sent by the mobile packet gateway, where the activation response includes The terminal network address.
  • the device for the mobile virtual private network communication may further include:
  • a branch topology obtaining unit configured to acquire a network segment address of the branch network according to a dynamic routing protocol
  • a branch topology notification unit configured to notify the mobile packet gateway of a network segment address of the branch network by using the virtual interface according to a dynamic routing protocol
  • the headquarters topology obtaining unit is configured to obtain, by using the virtual interface, the network topology of the headquarters network from the mobile packet gateway according to the dynamic routing protocol.
  • the device for the mobile virtual private network communication may further include:
  • a monitoring information acquiring unit configured to acquire network monitoring information from the mobile packet gateway by using the virtual interface
  • the network quality detecting unit is configured to detect network quality between the mobile packet gateway and the mobile packet gateway according to the network monitoring information acquired by the monitoring information acquiring unit.
  • the mobile terminal provided by the embodiment of the present invention notifies the latest network segment address of the branch network to the corresponding mobile packet through the virtual interface in real time by using the mobile terminal according to the dynamic routing protocol.
  • the technical solution of the gateway avoids the need to improve the network maintenance efficiency of the network segment of the mobile VPN branch network served by the MS.
  • the mobile terminal can notify the mobile network gateway of the latest network segment address of the branch network through the virtual interface at any time, and also solves the problem that the mobile packet gateway can only acquire the network segment of the new branch network when the mobile terminal is activated again. The problem with the address. Therefore, the operability of the network maintenance is further improved.
  • the technical solution of the dynamic routing protocol packet between the mobile packet gateway and the MS, and between the mobile packet gateway and the mobile VPN headquarters network can be adopted, which solves the problem that the network topology cannot be timely.
  • the change of the IP traffic flow between the mobile VPN branch network and the headquarters network adjusts the problem that the traffic configuration is unreasonable, so that the mobile VPN branch network and the headquarters network can dynamically adjust the IP traffic according to the network topology obtained by each. Flow direction makes the traffic configuration more reasonable.
  • a system for moving a virtual private network communication includes at least one mobile terminal 801 and a mobile packet gateway 802:
  • the mobile packet gateway 802 is configured to obtain a terminal network address and a gateway virtual interface network address, where the gateway virtual interface network address and the terminal network address belong to the same network segment; Creating a virtual interface by the packet data protocol context of the mobile terminal 801; and transmitting the terminal network address to the mobile terminal 801; acquiring the mobile terminal 801 from the mobile terminal 801 through the virtual interface according to a dynamic routing protocol The network segment address of the branch network of the service;
  • the mobile terminal 801 is configured to obtain a terminal network address from the mobile packet gateway 802.
  • the gateway virtual interface network address belongs to the same network segment as the terminal network address, and has the gateway according to a dynamic routing protocol.
  • the virtual interface of the virtual interface network address notifies the mobile packet gateway 802 of the network segment address of the served branch network.
  • the system for moving the virtual private network communication in the embodiment of the present invention may further include an authentication and authorization charging server 803, and storing the terminal network address and the gateway virtual interface network address;
  • the mobile packet gateway 802 is further configured to obtain the terminal network address and the gateway virtual interface network address from the authentication authorization charging server 803.
  • the system for moving the virtual private network communication in the embodiment of the present invention may further include a dynamic host allocation protocol server 804, configured to store the terminal network address and the gateway virtual interface network address;
  • the packet gateway 802 is further configured to obtain the terminal network address and the gateway virtual interface network address from the dynamic host allocation protocol server 804.
  • the mobile virtual private network communication system provided by the embodiment of the present invention adopts a technical solution that the mobile packet gateway obtains the latest network segment address of the branch network from the mobile terminal through the virtual interface in real time according to the dynamic routing protocol. Therefore, the problem of manually modifying the network segment address of the branch network on the AAA Server when the network segment address of the mobile VPN branch network served by the MS is changed is avoided, thereby improving the network maintenance efficiency.
  • the mobile packet gateway can obtain the latest network segment address of the branch network from the mobile terminal through the virtual interface at any time, and also solves the problem that the mobile packet gateway can only acquire a new branch network when the mobile terminal is activated again. The problem with the segment address. Therefore, the network maintenance operation can be further improved.
  • the technical solution of the dynamic routing protocol message between the mobile packet gateway and the MS, and between the mobile packet gateway and the mobile VPN headquarters network can be adopted, thereby solving the problem that the network topology cannot be changed in time according to the network topology.
  • the IP traffic flow between the mobile VPN branch network and the headquarters network is adjusted, resulting in an unreasonable traffic configuration. Therefore, the mobile VPN branch network and the headquarters network can dynamically adjust the flow of IP traffic according to the network topology obtained by each. Make the traffic configuration more reasonable.
  • the storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Description

移动虚拟专用网通信的方法、 装置及系统 本申请要求于 2009 年 05 月 27 日提交中国专利局、 申请号为 200910143618. 2、 发明名称为 "移动虚拟专用网通信的方法、 装置及系统" 的中国专利申请的优先权, 其全部内容通过引用结合在本申请中。 技术领域
本发明涉及通信领域, 尤其涉及一种移动虚拟专用网通信的方法、 装置 及系统。 背景技术
VPN ( Virtual Private Network, 虚拟专用网)是依靠 ISP ( Internet Service Provider, Internet服务提供商)和 NSP ( Network Service Provider, 网给服务 提供商), 在公用网络中建立专用的数据通信网络的技术。 按照组网类型, VPN可以分为固网 VPN、 移动 VPN等。 固网 VPN是使用固定通信网络为用 户提供 VPN接入, 而移动 VPN通过 GPRS ( General Packet Radio Service, 通用无线分组业务 ) AVCDMA ( Wide-brand Code Division Multiplex Access, 宽带码分多址)/CDMA( Code Division Multiplex Access,码分多址)/LTE-SAE ( Long Term Evolution-System Architecture Evolution , 3 GPP长期演进-系统架 构演进)等移动通信网络为用户提供 VPN接入。
在移动 VPN中, MS ( Mobile Subscriber, 移动终端 )可能需要作为 MS
Router (移动路由器)服务一个移动 VPN分支网络。 在此情况下, 移动分组 网关除了需要获得该 MS 的 IP地址(网络地址 )外, 还需要获得该 MS所服 务的移动 VPN分支网络的网段 IP地址信息, 因而可以将该 MS的 IP地址以 及该移动 VPN分支网络的网段 IP地址, 与同一个 PDP context ( Packet Data Protocol Context,分组数据协议上下文)关联,从而使该 MS以及该移动 VPN 分支网络的所有 Host, 分别使用各自的 IP地址通过相关联的 PDP context与 外部设备交互 IP流量。
现有技术中 ,移动分组网关通过 AAA Server ( Authentication Authorization Accounting Server, 鉴权授权计费服务器)获得 MS的 IP地址以及其所服务 的移动 VPN分支网络的网段 IP地址: MS在激活时, 移动分组网关根据预先 设定 ,向 AAA server发送鉴权请求 ( Radius Access Request )消息; AAA server 确定该 MS开通了 MS Router功能后, 将预先存储的该 MS的 IP地址, 以及 该 MS所服务的移动 VPN分支网络的网段 IP地址添加在鉴权响应 (Radius Access Accept ) 消息中, 并返回给移动分组网关; 移动分组网关从 Radius Access Accept消息中获得该 MS的 IP地址、 该移动 VPN分支网络的网段 IP 地址。
在实现移动 VPN通信的过程中,发明人发现现有技术中至少存在如下问 题: 利用现有技术中的技术方案进行移动 VPN通信的话, 由于 AAA Server 上存储的移动 VPN分支网络的网段 IP地址信息是预先配置好的, 而 MS所 服务的移动 VPN分支网络经常发生改变,因此,需要经常人工修改 AAA server 上存储的移动 VPN分支网络的网段 IP地址信息, 才能使移动分组网关可以 根据新的移动 VPN分支网络的网段 IP地址进行移动 VPN通信。 因而, 利用 现有技术的网络维护的效率较低。
发明内容
本发明的实施例提供一种移动虚拟专用网通信的方法、 装置及系统, 可 以提高网络维护的效率。
为达到上述目的, 本发明的实施例采用如下技术方案:
一种移动虚拟专用网通信的方法, 包括:
获取终端网络地址和网关虚接口网络地址, 所述网关虚接口网络地址与 所述终端网络地址属于同一网段;
根据所述网关虚接口网络地址为移动终端的分组数据协议上下文创建虚 接口;
将所述终端网络地址发送给所述移动终端;
根据动态路由协议通过所述虚接口从所述移动终端获取所述移动终端所 服务的分支网络的网段地址。
一种移动虚拟专用网通信的装置, 包括:
网络地址获取单元, 用于获取终端网络地址和网关虚接口网络地址, 所 述网关虚接口网络地址与所述终端网络地址属于同一网段;
接口创建单元, 用于根据所述网络地址获取单元获取的网关虚接口网络 地址, 为移动终端的分组数据协议上下文创建虚接口;
网络地址发送单元, 用于将所述网络地址获取单元获取的终端网络地址 发送给所述移动终端;
分支地址获取单元, 用于根据动态路由协议通过所述接口创建单元创建 一种移动虚拟专用网通信的方法, 包括:
从移动分组网关获取终端网络地址; 网关虚接口网络地址与所述终端网络地址属于同一网段;
根据动态路由协议通过具有所述网关虚接口网络地址的虚接口将所服务 的分支网络的网段地址通知所述移动分组网关。
一种移动终端, 包括:
终端地址获取单元, 用于从移动分组网关获取终端网络地址;
接口地址获取单元, 用于根据所述终端地址获取单元获取的终端网络地 址获取移动分组网关的网关虚接口网络地址, 所述网关虚接口网络地址与所 述终端网络地址属于同一网段; 分支地址通知单元, 用于根据动态路由协议通过具有所述网关虚接口网 络地址的虚接口将所服务的分支网络的网段地址通知所述移动分组网关。
一种移动虚拟专用网通信的系统, 包括至少一个移动终端和移动分组网 关:
其中, 所述移动分组网关, 用于获取终端网络地址和网关虚接口网络地 址, 所述网关虚接口网络地址与所述终端网络地址属于同一网段; 居所述 网关虚接口网络地址为所述移动终端的分组数据协议上下文创建虚接口; 并 将所述终端网络地址发送给所述移动终端; 根据动态路由协议通过所述虚接 所述移动终端, 用于从移动分组网关获取终端网络地址; 并 居所述终 端网络地址获取移动分组网关的网关虚接口网络地址, 所述网关虚接口网络 地址与所述终端网络地址属于同一网段; 并根据动态路由协议通过具有所述 网关虚接口网络地址的虚接口将所服务的分支网络的网段地址通知所述移动 分组网关。
本发明实施例提供的移动虚拟专用网通信的方法、 装置及系统, 通过移 动分组网关为移动终端的分组数据协议上下文创建虚接口, 并且所述虚接口 和所述移动终端分别配置同一网段的网络地址; 所述移动分组网关根据动态 路由协议, 可以实时地通过所述虚接口从所述移动终端获取所述移动终端所 服务的分支网络的最新的网段地址。 因此, 利用本发明实施例的技术方案, 解决了需要在 MS所服务的移动 VPN分支网络的网段地址变化时,人工修改 AAA Server上的分支网络的网段地址的问题, 进而达到了提高网络维护效率 的效果。 附图说明
为了更清楚地说明本发明实施例的技术方案, 下面将对实施例描述中所 需要使用的附图作一筒单地介绍, 显而易见地, 下面描述中的附图仅仅是本 发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动的 前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明实施例提供的移动虚拟专用网通信的方法流程图; 图 2为本发明实施例提供的另一种移动虚拟专用网通信的方法流程图; 图 3为本发明实施例提供的另一种移动虚拟专用网通信的方法流程图; 图 4为本发明实施例提供的另一种移动虚拟专用网通信的方法流程图; 图 5为本发明实施例提供的另一种移动虚拟专用网通信的方法流程图; 图 6 为本发明实施例提供的一种移动虚拟专用网通信的装置结构示意 图;
图 7为本发明实施例提供的一种移动终端结构示意图;
图 8为本发明实施例提供的另一种移动虚拟专用网通信的系统构成示意 图;
图 9为本发明实施例提供的另一种移动虚拟专用网通信的系统构成示意 图;
图 10 为本发明实施例提供的另一种移动虚拟专用网通信的系统构成示 意图;
图 11 为本发明实施例提供的移动虚拟专用网通信的方法采用第一种方 案时的组网图。 具体实施方式
下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案进行 清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实施例, 而 不是全部的实施例。 基于本发明中的实施例, 本领域普通技术人员在没有作 出创造性劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。 为了提高网络维护的效率, 本发明实施例提供了一种移动虚拟专用网通 信的方法, 如图 1所示, 本发明实施例移动虚拟专用网通信的方法, 包括:
101、移动分组网关获取终端网络地址和网关虚接口网络地址, 所述网关 虚接口网络地址与所述终端网络地址属于同一网段。
在此, 对在本发明实施例中用到的几个概念做一下描述, 其中 "终端网 络地址"是指移动分组网关为移动终端分配的网络地址, "网关虚接口网络地 址" 则是指移动分组网关为创建的虚接口分配的网络地址。
在此步骤中, 移动分组网关可以在接收由 MS发送的激活请求后, 同时 获取终端网络地址和网关虚接口网络地址, 也可以先按照现有技术从 AAA Server先获取终端网络地址以及 MS所服务的分支网络的网段地址, 在后续 过程中, 再根据获取的终端网络地址获取属于同一网段的网关虚接口网络地 址。
102、 移动分组网关根据所述网关虚接口网络地址, 为移动终端的分组数 据协议上下文创建虚接口。
103、 移动分组网关将所述终端网络地址发送给所述移动终端。
其中, 步骤 102和 103可以同时进行, 或者, 也可以先进行步骤 102再 进行步骤 103, 或者, 还可以先进行步骤 103再进行步骤 102。
104、移动分组网关根据动态路由协议通过所述虚接口从所述移动终端获 取所述移动终端所服务的分支网络的网段地址。
其中, 由于网关虚接口网络地址与终端网络地址属于同一网段, 故分别 在移动分组网关的虚接口以及移动终端的接口上启动动态路由协议后, 移动 分组网关与所述移动终端可以通过所述虚接口和所述移动终端的接口交互动 态路由协议报文, 其中, 所述移动终端向移动分组网关发送的动态路由协议 报文包括所述分支网络的网段地址。 因此, 移动分组网关可以实时的从所述 移动终端发送的动态路由协议报文中获取所述分支网络的网段地址。 故当分 支网络的网段地址有变化时, 移动终端向移动分组网关发送的动态路由协议 报文包括所述分支网络的网段地址也会随之变化, 而移动分组网关可以通过 所述虚接口接收移动终端发送的动态路由协议报文获取变化后分支网络的网 段地址, 从而可以实时获取分支网络的新的网段地址。
移动分组网关在根据动态路由协议通过所述虚接口从所述 MS获取分支 网络的网段地址前, 可以向所述 MS发送包括终端网络地址的激活响应, 使 所述 MS使用所述终端网络地址通过相关联的 PDP context转发 IP流量, 并 本发明实施例提供的移动虚拟专用网通信的方法, 由于采用了移动分组 网关根据动态路由协议, 实时地通过所述虚接口从所述移动终端获取分支网 络的最新的网段地址的技术方案, 因此避免了需要在 MS所服务的移动 VPN 分支网络的网段地址变化时,人工修改 AAA Server上的分支网络的网段地址 的问题, 进而达到了提高网络维护效率的效果。
在上述实施例中, 移动分组网关可以通过至少以下三种方案同时获取终 端网络地址和网关虚接口网络地址:移动分组网关通过 AAA Server获取终端 网络地址和网关虚接口网络地址; 移动分组网关在本地获取终端网络地址和 网关虚接口网络地址; 移动分组网关通过 DHCP Server ( Dynamic Host Configuration Protocol Server, 动态主机分配协议服务器)获取终端网络地址 和网关虚接口网络地址。 以下分别根据上述三种方案, 结合上述实施例进行 进一步详细描述。
第一种方案、移动分组网关通过 AAA Server获取终端网络地址和网关虚 接口网给地址。
如图 3所示, 本发明实施例移动虚拟专用网通信的方法, 包括:
301、 移动终端向移动分组网关发送激活请求。
所述激活请求, 即为 PDP context激活请求。 举例而言, 在实际应用中, MS向移动分组网关(例如 GGSN ( Gateway GPRS Support Nodes, 网关 GPRS 支持节点))发送激活请求的流程可以具体为:
( 1 ) MS向 SGSN ( Serving GPRS Support Nodes, 服务 GPRS支持节点) 发送 PDP context激活请求, 该激活请求中包括 APN(Access Point Name,接入点 名称)。
( 2 ) SGSN根据该 APN判断 MS的可接入性, 并通过 DNS Server ( Domain Name System Server, 域名系统服务器)得到相应的 GGSN地址, 并向 GGSN转 发该 MS的 PDP context激活请求。
302、移动分组网关接收所述移动终端的激活请求后, 向鉴权授权计费服 务器发送地址请求消息。
所述地址请求消息可以有多种实现方式, 例如 Radius Access Request消 息。
303、 鉴权授权计费服务器向移动分组网关发送地址响应消息。
在本发明实施例的方法中, AAA Server预先存储终端网络地址, 即所述 MS的 IP地址以及网络掩码。 当 MS开通了 MS Router功能时, AAA Server 还存储对应的网关虚接口网络地址, 该网关虚接口网络地址为移动分组网关 的 IP地址中其中一个地址,其中,该网关虚接口网络地址用于与该 MS互连, 并启动动态路由协议, 并且所述网关虚接口网络地址与所终端网络地址属于 同一网段。
在 MS开通了 MS Router功能时, AAA Server将存储的终端网络地址、 对应的网关虚接口网络地址添加在地址响应消息中, 向移动分组网关发送该 地址响应消息。 在 MS未开通 MS Router功能时, AAA Server将存储的终端 网络地址添加在地址响应消息中, 向移动分组网关发送该地址响应消息。
所述地址响应消息可以有多种实现方式,例如,地址请求消息通过 Radius Access Request消息实现时, 地址响应消息可以通过 Radius Access Accept消 息实现。 并且, MS的 IP地址等信息在 Radius Access Accept消息中有多种方 式: 可以使用私有扩展属性, 例如对 RFC2865 中定义的 "Vendor-Specific" 属性进行自定义来包含 MS的 IP地址等信息; 也可以使用 RFC2865中已经 定义的标准属生, 例 口 " Framed-IP- Address "、 " Framed- IP-Netmask " 和
"Framed- Route" 属性, 其中 " Framed- IP- Address,,、 "Framed- IP-Netmask" 分别包括 MS的 IP地址和网络掩码, "Framed-Route"中的 "Gateway address" 字段中 包含网 关虚接口 网络地址, 网 关虚接口 网络地址与
"Framed-IP- Address" , "Framed-IP-Netmask" 表示的移动终端 MS的 IP地 址在相同的网段中。
304、移动分组网关解析所述地址响应消息, 从所述地址响应消息中获取 所述终端网络地址和所述网关虚接口网络地址。
移动分组网关解析所述地址响应消息,在确定所述 MS开通了 MS Router 功能时, 从所述地址响应消息中获取所述终端网络地址和所述网关虚接口网 络地址, 在确定所述 MS未开通 MS Router功能时, 从所述地址响应消息中 获取终端网络地址。
在此步骤中, 移动分组网关可以根据所述地址响应消息中是否包括网关 虚接口网络地址, 来判断 MS是否开通了 MS Router功能。 例如, 网关虚接 口网给地址利用 Radius Access Accept消息的 "Framed-Route" 中的 "Gateway address"字段包含时 ,只有在 Radius Access Accept消息包含了 "Framed-Route" 时, 移动分组网关才判定 MS开通了 MS Router功能。
另外,所述移动分组网关也可以根据所述地址响应消息中是否包括了 MS Router标志或包括的 MS Router标志的值, 判断 MS是否开通了 MS Router 功能。
305、移动分组网关根据所述网关虚接口网络地址为移动终端的分组数据 协议上下文创建虚接口。
在 MS开通了 MS Router功能时, 移动分组网关获取与所述终端网络地 址相关联的 PDP context,即 MS的 PDP context。移动分组网关为该 PDP context 创建一个虚接口, 该虚接口的网络地址为所述网关虚接口网络地址。 移动分 组网关会对进出该虚接口的 IP报文, 进行该 PDP context所对应的用户面隧 道封装、 解封装处理。
306、移动分组网关向所述移动终端发送激活响应, 所述激活响应包括所 述终端网络地址。
举例而言, 在实际中, 移动分组网关 (例如 GGSN ) 向 MS发送激活响 应的流程可以具体为: GGSN向 SGSN发送包括 MS的 IP地址及网络掩码的 激活响应, SGSN将该激活响应转发给该 MS。
307、移动终端接收所述激活响应后, 从所述激活响应中获取所述终端网 络地址。 络地址, 所述网关虚接口网络地址与所述终端网络地址属于同一网段。 移动 终端根据动态路由协议通过具有所述网关虚接口网络地址的虚接口将所服务 的分支网络的网段地址通知所述移动分组网关。 方式一: 可以将分支网络的网段地址预先配置在 MS上; 方式二: 也可以在 MS 与其所服务的移动 VPN 分支网络的各主机之间启动动态路由协议, 则 MS可以根据动态路由协议获取所服务的分支网络的网段地址。对于方式二具 体来说, 由于 MS与其所服务的移动 VPN分支网络的各主机之间都启动动态 动态路由协议中, 相邻节点之间会交互一些动态路由协议报文, 这些动态路 由协议报文中包括网络的路由信息。 因此, MS会与其所服务的移动 VPN分 支网络的各主机交互动态路由协议报文, 并可以从所述报文中获得所述分支 网络的路由信息, 所述分支网络的路由信息包括所述分支网络的网段地址, 即移动 VPN分支网络的网段 IP地址。
2 )移动分组网关创建的虚接口与 MS的终端网络地址属于同一网段, 因 此, 可以在该虚接口以及 MS 的接口上分别启动动态路由协议, 例如, OSPF(Open Shortest Path First, 开放式最短路径优先)或者 RIP ( Routing information Protocol, 路由信息协议)。 之后, 移动分组网关与 MS将分别发 现彼此是相邻节点, 从而 MS通过动态协议获知网关虚接口网络地址, 进而 可以进行路由信息的交互。
移动分组网关与 MS之间通过创建的虚接口和 MS的接口交互动态路由 协议报文,在 MS从其服务的移动 VPN分支网络的主机发送的动态路由协议 报文中或者根据预先的配置获得该分支网络的网段地址后, MS在向移动分组 网关发送的动态路由协议报文中包括该分支网络的网段地址, 由此移动分组 网关可以从所述报文中获得该分支网络的网段地址。
移动分组网关在获得 MS所服务的移动 VPN分支网络的网段地址后,确 定已同该 MS的网络地址相关联的 PDP context, 将该分支网络的网段地址与 该 PDP context相关联。 由此, 移动分组网关可以对该网段地址的流量通过与 其关联的 PDP context所对应的用户面隧道传输, 实现该网段地址的流量的 VPN通信。 其中, 进出该虚接口的动态路由协议报文, 移动分组网关也会对 其进行相关联的 PDP context所对应的用户面隧道封装、 解封装处理。
因此, 移动分组网关可以在上行(Uplink ) 业务流量转发过程中, 允许 IP流量的源地址是 MS的 IP地址或者移动 VPN分支网络的网段 IP地址时, 通过相关联的 PDP context转发该 IP流量, 并且, 在下行(Downlink )业务 流量转发过程中, 允许 IP流量的目的地址是 MS的 IP地址或者移动 VPN分 支网络的网段 IP地址时, 通过相关联的 PDP context转发该 IP流量。
由于, 现有技术中移动 VPN分支网络的网段 IP地址信息是预先配置的, VPN分支网络和总部网络无法获知彼此的网络拓朴。 而本发明的实施例还可 以进一步实现移动 VPN分支网络和总部网络可以分别获得彼此的网络拓朴, 以便动态地调整 IP流量的流向。 其中, 具体为: 还可以在移动分组网关与移 动 VPN 总部网络之间也启动动态路由协议。 这样, 移动分组网关可以从与 MS交互的动态路由协议报文中, 获取移动 VPN分支网络的网络拓朴, 将获 取的移动 VPN分支网络的网络拓朴,通过动态路由协议报文通知给移动 VPN 总部网络。 并且, 移动分组网关可以从与移动 VPN总部网络交互的动态路由 协议报文中, 获取移动 VPN总部网络的网络拓朴, 将获取的移动 VPN总部 网络的网络拓朴,通过动态路由协议报文通知给 MS,进而通过 MS通知给移 动 VPN分支网络。
另外, 移动分组网关还可以通过所述虚接口与移动终端交互网络监测信 息, 根据所述网络监测信息, 检测与所述移动终端之间的网络质量, 在检测 到与所述移动终端之间的网络质量差时, 可以及时地进行相应的调整。 当然, 还可以在移动分组网关与 MS之间启动其它标准的、 或者非标准自定义的通 信, 用于传递其它信息。
在本实施例中, 当 VPN分支网络的 IP地址发生变化时, 可以将变化的 地址信息配置在 MS上或者由 MS根据动态路由协议获得该信息。 进一步的, MS 在向移动分组网关发送的动态路由协议 4艮文中包括该分支网络的变化后 网段地址, 由此移动分组网关可以从所述报文中获得该分支网络的变化后网 段地址。
图 11 是本发明实施例提供的移动虚拟专用网通信的方法采用上述第一 种方案实现时的组网图。 移动分组网关为开通 MS Router功能的移动终端 1 和移动终端 2分别创建一个虚接口, 移动终端 1和移动终端 2与移动分组网 关之间的动态路由协议报文分别进出各自创建的虚接口, 即所述动态路由协 议才艮文分别通过移动终端 1和移动终端 2的 PDP context的用户面隧道传输。 其中移动终端可以通过无线接入网与移动分组网关连接。
移动终端 1向移动分组网关发送动态路由协议 文后, 移动分组网关接 收并解析该动态路由协议 文, 可以获知当后续移动分组网关收到的 IP 4艮文 的目的 IP地址位于分支网络 1网段 A.B.C.x范围内时, 则移动分组网关获知 该 IP 文的下一跳地址是移动终端 1激活后分到的 IP地址。 并且, 移动终 端 2向移动分组网关发送动态路由协议报文后, 移动分组网关接收并解析该 动态路由协议 文, 可以获知当后续移动分组网关收到的 IP 4艮文的目的 IP 地址位于分支网络 2网段 D.E.F.y范围内时, 则移动分组网关获知该 IP 文 的下一跳地址是移动终端 2激活后分到的 IP地址。
移动分组网关向移动终端 1发送动态路由协议报文后, 移动终端 1接收 并解析该动态路由协议^¾文, 可以获知当后续移动终端 1收到的 "¾文的目 的 IP地址位于总部网络 1网段范围内时, 则移动终端 1获知该 IP报文的下 一跳地址是与移动终端 1 网络地址位于同网段的移动分组网关虚接口 IP地 址。 并且, 移动分组网关向移动终端 2发送动态路由协议 文后, 移动终端 2接收并解析该动态路由协议报文, 获知当后续移动终端 2收到的 IP报文的 目的 IP地址位于总部网络 2网段范围内时, 则移动终端 2获知该 IP报文的 下一跳地址是与移动终端 2网络地址位于同网段的移动分组网关虚接口 IP地 址。
移动分组网关分别接收到移动终端 1和移动终端 2发送的动态路由协议 报文后, 可以分别从这些动态路由协议报文中获取分支网络 1和分支网络 2 的网段 IP地址信息 A.B.C.x和 D.E.F.y以及其他路由信息; 而移动终端 1和 移动终端 2分别接收移动分组网关发送的动态路由协议报文后, 可以分别从 这些动态路由协议报文中获取总部网络 1和总部网络 2的网段 IP地址信息以 及其他路由信息。
并且, 通过移动终端 1与移动分组网关之间、 移动分组网关与总部网络 1的路由器 1之间交互路由协议报文, 移动终端 1和总部网络 1的路由器 1 可以分别获得彼此的路由信息, 因此, 如图中移动终端 1和路由器 1之间的 点划线所示, 在逻辑上移动终端 1和总部网络 1的路由器 1之间可以彼此交 换路由信息, 进而动态调整业务流向。 同理, 如图中移动终端 2和路由器 2 之间的虚线所示, 在逻辑上移动终端 2和总部网络 2的路由器 2之间也可以 彼此交换路由信息, 进而动态调整业务流向。 可以理解, 移动分组网关与总 部网络路由器之间交互路由协议报文完全是现有技术实现, 在此不再赘述。 在获得路由信息后, 移动分组网关允许以 A.B.C.x和 D.E.Ry为源地址的 IP流量分别经由移动终端 1和移动终端 2的 PDP context的用户面隧道传输, 并且允许以 A.B.C.x和 D.E.F.y为目的地址的 IP流量分别经由移动终端 1和 移动终端 2的 PDP context的用户面隧道传输, 实现移动 VPN业务流量的正 常转发。
可以理解, 按照现有的路由技术, 如果分支网络 1与分支网络 2属于同 一个 VPN, 那么它们的网段地址不能相同。 相应地, 移动终端 1和移动终端 2的 IP地址不在同一个网段。
第二种方案、 移动分组网关在本地获取终端网络地址和网关虚接口网络 地址。
如图 4所示, 本发明实施例移动虚拟专用网通信的方法, 包括: 步骤 401同步骤 301。
402、移动分组网关接收移动终端的激活请求后, 在所述移动终端开通移 动路由器功能时, 从本地地址池中获取一个网段地址。
移动分组网关预先存储了 MS是否开通了 MS Router功能的配置信息, 因此,移动分组网关接收 MS的激活请求后,根据存储的配置信息确定该 MS 是否开通了 MS Router功能, 或者当用户向 AAA服务器鉴权时, 移动分组网 关从 AAA获知 MS开通了 MS Router功能。
移动分组网关在确定 MS开通了 MS Router功能时, 从本地地址池中获 取一个网段 IP地址, 例如在 IPV4下, 相应的网段掩码长度一般不超过 30, 或者, 网段掩码长度可以预先约定。
403、移动分组网关从获取的网段地址中确定两个网络地址, 将其中一个 网络地址作为所述移动分组网关分配给移动终端的终端网络地址, 将另一个 网络地址作为网关虚接口网络地址。
步骤 404 ~ 407同步骤 305 ~ 308, 并且路由信息交互与实现移动 VPN业 务流量正常转发的原理及过程与方案一相同。 第三种方案、 移动分组网关通过 DHCP Server获取终端网络地址和网关 虚接口网络地址。
如图 5所示, 本发明实施例移动虚拟专用网通信的方法, 包括: 步骤 501同步骤 301。
502、移动分组网关接收移动终端的激活请求后, 向动态主机分配协议服 务器发送地址请求消息。
所述地址请求消息可以有多种实现方式, 例如, 地址分配请求 (DHCP REQUEST ) 消息。
503、 动态主机分配协议服务器向移动分组网关发送地址响应消息。
在本方法中, DHCP Server预先存储终端网络地址, 即所述 MS的 IP地 址以及网络掩码, 当 MS开通了 MS Router功能时, DHCP Server还存储对应 的网关虚接口网络地址, 即与该 MS互连的移动分组网关的 IP地址, 并且所 述网关虚接口网络地址与所终端网络地址属于同一网段。
在 MS开通了 MS Router功能时, DHCP Server将存储的终端网络地址、 对应的网关虚接口网络地址添加在地址响应消息中, 向移动分组网关发送该 地址响应消息。在 MS未开通 MS Router功能时, DHCP Server将存储的终端 网络地址添加在地址响应消息中, 向移动分组网关发送该地址响应消息。
所述地址响应消息可以有多种实现方式, 例如, 地址请求消息通过地址 分配请求消息实现时, 地址响应消息可以通过地址分配响应 ( DHCP OFFER/DHCP ACK ) 消息实现。 并且, MS 的 IP 地址等信息在 DHCP OFFER/DHCP ACK消息中有多种包含方式,举例而言, 可以使用私有扩展属 性, 例如对 RFC2131中定义的 "OPTIONS"属性进行自定义来包含 MS的 IP 地址等信息。
504、移动分组网关解析所述地址响应消息, 从所述地址响应消息中获取 所述终端网络地址和所述网关虚接口网络地址。
移动分组网关解析所述地址响应消息,在确定所述 MS开通了 MS Router 功能时, 从所述地址响应消息中获取所述终端网络地址和所述网关虚接口网 络地址, 在确定所述 MS未开通 MS Router功能时, 从所述地址响应消息中 获取终端网络地址。
在此步骤中, 移动分组网关可以根据所述地址响应消息中是否包括了网 关虚接口网络地址, 来判断 MS是否开通了 MS Router功能, 也可以根据所 述地址响应消息中是否包括了 MS Router标志或包括的 MS Router标志的值, 判断 MS是否开通了 MS Router功能。
步骤 505 ~步骤 508同步骤 305 ~ 308,并且路由信息交互与实现移动 VPN 业务流量正常转发的原理及过程与方案一相同。
本发明实施例提供的移动虚拟专用网通信的方法, 由于采用了移动分组 网关根据动态路由协议, 实时地通过所述虚接口从所述移动终端获取分支网 络的最新的网段地址的技术方案, 因此避免了需要在 MS所服务的移动 VPN 分支网络的网段地址变化时,人工修改 AAA Server上的分支网络的网段地址 的问题, 进而达到了提高网络维护效率的效果。
并且, 移动分组网关随时都可以通过所述虚接口从所述移动终端获取分 支网络的最新的网段地址, 也解决了移动分组网关仅能在移动终端再次激活 时, 获取新的分支网络的网段地址的问题。 从而进一步改善网络维护的操作 另外, 还可以采用移动分组网关和 MS之间、 移动分组网关与移动 VPN 总部网络之间交互动态路由协议报文的技术方案, 解决了无法及时根据网络 拓朴的变化而调整移动 VPN分支网络和总部网络之间的 IP流量流向, 导致 流量配置不合理的问题,从而达到了移动 VPN分支网络和总部网络可以根据 各自获得的网络拓朴, 动态调整 IP流量的流向, 使流量配置更加合理。
与上述实施例对应地, 本发明实施例提供了另一种移动虚拟专用网通信 的方法, 如图 2所示, 本发明实施例移动虚拟专用网通信的方法, 包括:
201、 移动终端从移动分组网关获取终端网络地址; MS可以向移动分组网关发送激活请求,并接收由所述移动分组网关发送 的、 包括终端网络地址的激活响应, 从所述激活响应中获取所述终端网络地 址。 络地址, 所述网关虚接口网络地址与所述终端网络地址属于同一网段。
203、移动终端根据动态路由协议通过具有所述网关虚接口网络地址的虚 接口将所服务的分支网络的网段地址通知所述移动分组网关。
本发明实施例提供的移动虚拟专用网通信的方法, 由于采用了移动终端 根据动态路由协议, 实时地通过所述虚接口将分支网络的最新的网段地址通 知给对应的移动分组网关的技术方案, 因此避免了需要在 MS所服务的移动 VPN分支网络的网段地址变化时, 人工修改 AAA Server上的分支网络的网 段地址的问题, 进而达到了提高网络维护效率的效果。
与上文描述的方法相对应地, 本发明实施例还提供了一种移动虚拟专用 网通信的装置, 如图 6所示, 本发明实施例移动虚拟专用网通信的装置, 包 括:
网络地址获取单元 601 , 用于获取终端网络地址和网关虚接口网络地址, 所述网关虚接口网络地址与所述终端网络地址属于同一网段;
其中, 所述网络地址获取单元 601进一步具体包括: 地址请求发送子单 元, 用于向鉴权授权计费服务器或动态主机分配协议服务器发送地址请求消 息; 地址响应接收子单元, 用于接收由所述鉴权授权计费服务器或所述动态 主机分配协议服务器发送的地址响应消息; 网络地址获取子单元, 用于解析 所述地址响应接收子单元接收的地址响应消息, 从所述地址响应消息中获取 所述终端网络地址和所述网关虚接口网络地址。
或者, 所述网络地址获取单元 601进一步具体包括: 网段地址获取子单 元, 用于在所述移动终端开通移动路由器功能时, 从本地地址池中获取一个 网段地址; 网络地址确定子单元, 用于从所述网段地址获取子单元获取的网 段地址中确定两个网络地址, 将其中一个网络地址作为所述终端网络地址, 将另一个网络地址作为所述网关虚接口网络地址。
接口创建单元 602, 用于根据所述网络地址获取单元 601获取的网关虚 接口网络地址, 为移动终端的分组数据协议上下文创建虚接口;
网络地址发送单元 603 , 用于将所述网络地址获取单元 601获取的终端 网络地址发送给所述移动终端;
其中, 所述网络地址发送单元 603进一步具体包括: 响应发送子单元, 用于向所述移动终端发送激活响应, 所述激活响应包括所述网络地址获取单 元 601获取的终端网络地址。
分支地址获取单元 604, 用于根据动态路由协议通过所述接口创建单元 网段地址。
其中, 所述分支地址获取单元 604进一步具体包括: 报文接收子单元, 用于通过所述虚接口接收由移动终端发送的动态路由协议报文; 网段地址获 取子单元, 用于从所述报文接收子单元接收的动态路由协议报文中获取所述 分支网络的网段地址。 另外, 所述分支地址获取单元 604进一步还包括: 地 数据协议上下文关联。
另外, 所述移动虚拟专用网通信的装置还包括请求接收单元, 用于接收 移动终端的激活请求
。 所述移动虚拟专用网通信的装置进一步还包括:
分支拓朴获取单元, 用于根据动态路由协议通过所述虚接口从所述移动 终端获取所述分支网络的网络拓朴。
总部拓朴获取单元, 用于根据动态路由协议获取总部网络的网络拓朴; 总部拓朴通知单元, 用于根据动态路由协议通过所述虚接口, 将所述总 部拓朴获取单元获取的网络拓朴通知所述移动终端。 所述移动虚拟专用网通信的装置进一步还包括:
监测信息获取单元, 用于通过所述虚接口从所述移动终端获取网络监测 信息;
网络质量检测单元, 用于根据所述监测信息获取单元获取的网络监测信 息, 检测与所述移动终端之间的网络质量。
本发明实施例提供的移动虚拟专用网通信的装置可以为移动分组网关, 例如 GGSN。
本发明实施例提供的移动虚拟专用网通信的装置, 由于采用了移动分组 网关根据动态路由协议, 实时地通过所述虚接口从所述移动终端获取分支网 络的最新的网段地址的技术方案, 因此避免了需要在 MS所服务的移动 VPN 分支网络的网段地址变化时,人工修改 AAA Server上的分支网络的网段地址 的问题, 进而达到了提高网络维护效率的效果。
并且, 移动分组网关随时都可以通过所述虚接口从所述移动终端获取分 支网络的最新的网段地址, 也解决了移动分组网关仅能在移动终端再次激活 时, 获取新的分支网络的网段地址的问题。 从而进一步改善网络维护的操作 另外, 还可以采用移动分组网关和 MS之间、 移动分组网关与移动 VPN 总部网络之间交互动态路由协议报文的技术方案, 解决了无法及时根据网络 拓朴的变化而调整移动 VPN分支网络和总部网络之间的 IP流量流向, 导致 流量配置不合理的问题,从而达到了移动 VPN分支网络和总部网络可以根据 各自获得的网络拓朴, 动态调整 IP流量的流向, 使流量配置更加合理。
与上文描述的装置相对应地, 本发明实施例还提供了一种移动终端, 如 图 7所示, 本发明实施例移动虚拟专用网通信的装置, 包括:
终端地址获取单元 701 , 用于从移动分组网关获取终端网络地址; 接口地址获取单元 702, 用于根据所述终端地址获取单元 701获取的终 端网络地址, 获取移动分组网关的网关虚接口网络地址, 所述网关虚接口网 络地址与所述终端网络地址属于同一网段;
分支地址通知单元 703 , 用于根据动态路由协议通过具有所述网关虚接 口网络地址的虚接口将所服务的分支网络的网段地址通知所述移动分组网 关。
其中, 所述分支地址通知单元 703进一步具体包括: 分支地址获取子单 元, 用于根据动态路由协议获取所述分支网络的网段地址, 或者, 获取预先 配置的所述分支网络的网段地址; 地址添加子单元, 用于在动态路由协议才艮 文中添加所述分支网络的网段地址; 报文发送子单元, 用于通过所述虚接口 向所述移动分组网关发送所述动态路由协议报文。
所述终端地址获取单元 701进一步具体包括: 请求发送单元, 用于向所 述移动分组网关发送激活请求; 响应接收单元, 用于接收由所述移动分组网 关发送的激活响应, 所述激活响应包括所述终端网络地址。
所述移动虚拟专用网通信的装置还可以包括:
分支拓朴获取单元, 用于根据动态路由协议获取所述分支网络的网段地 址;
分支拓朴通知单元, 用于根据动态路由协议通过所述虚接口将所述分支 网络的网段地址通知所述移动分组网关;
总部拓朴获取单元, 用于根据动态路由协议通过所述虚接口从所述移动 分组网关获取总部网络的网络拓朴。
所述移动虚拟专用网通信的装置还可以包括:
监测信息获取单元, 用于通过所述虚接口从所述移动分组网关获取网络 监测信息;
网络质量检测单元, 用于根据所述监测信息获取单元获取的网络监测信 息, 检测与所述移动分组网关之间的网络质量。
本发明实施例提供的移动终端,由于采用了移动终端根据动态路由协议, 实时地通过所述虚接口将分支网络的最新的网段地址通知给对应的移动分组 网关的技术方案, 因此避免了需要在 MS所服务的移动 VPN分支网络的网段 到了提高网络维护效率的效果。
并且, 移动终端随时都可以通过所述虚接口将分支网络的最新的网段地 址通知给移动分组网关,也解决了移动分组网关仅能在移动终端再次激活时, 获取新的分支网络的网段地址的问题。 从而进一步改善网络维护的操作性, 另外, 还可以采用移动分组网关和 MS之间、 移动分组网关与移动 VPN 总部网络之间交互动态路由协议报文的技术方案, 解决了无法及时根据网络 拓朴的变化而调整移动 VPN分支网络和总部网络之间的 IP流量流向, 导致 流量配置不合理的问题,从而达到了移动 VPN分支网络和总部网络可以根据 各自获得的网络拓朴, 动态调整 IP流量的流向, 使流量配置更加合理。
本发明实施例还提供了一种移动虚拟专用网通信的系统, 如图 8所示, 本发明实施例移动虚拟专用网通信的系统, 包括至少一个移动终端 801和移 动分组网关 802:
其中, 所述移动分组网关 802, 用于获取终端网络地址和网关虚接口网 络地址, 所述网关虚接口网络地址与所述终端网络地址属于同一网段; 居 所述网关虚接口网络地址为所述移动终端 801的分组数据协议上下文创建虚 接口; 并将所述终端网络地址发送给所述移动终端 801 ; 根据动态路由协议 通过所述虚接口从所述移动终端 801获取所述移动终端 801所服务的分支网 络的网段地址;
所述移动终端 801 , 用于从所述移动分组网关 802获取终端网络地址; 址, 所述网关虚接口网络地址与所述终端网络地址属于同一网段; 并根据动 态路由协议通过具有所述网关虚接口网络地址的虚接口将所服务的分支网络 的网段地址通知所述移动分组网关 802。 进一步地, 如图 9所示, 本发明实施例移动虚拟专用网通信的系统还可 以包括鉴权授权计费服务器 803 , 存储所述终端网络地址和所述网关虚接口 网络地址;
所述移动分组网关 802, 还用于从所述鉴权授权计费服务器 803获取所 述终端网络地址和所述网关虚接口网络地址。
进一步地, 如图 10所示, 本发明实施例移动虚拟专用网通信的系统还可 以包括动态主机分配协议服务器 804, 用于存储所述终端网络地址和所述网 关虚接口网络地址; 所述移动分组网关 802, 还用于从所述动态主机分配协议服务器 804获 取所述终端网络地址和所述网关虚接口网络地址。
本发明实施例提供的移动虚拟专用网通信的系统, 由于采用了移动分组 网关根据动态路由协议, 实时地通过所述虚接口从所述移动终端获取分支网 络的最新的网段地址的技术方案, 因此避免了需要在 MS所服务的移动 VPN 分支网络的网段地址变化时,人工修改 AAA Server上的分支网络的网段地址 的问题, 进而达到了提高网络维护效率的效果。
并且, 移动分组网关随时都可以通过所述虚接口从所述移动终端获取分 支网络的最新的网段地址, 也解决了移动分组网关仅能在移动终端再次激活 时, 获取新的分支网络的网段地址的问题。 从而进一步改善网络维护的操作 另外, 还可以采用移动分组网关和 MS之间、 移动分组网关与移动 VPN 总部网络之间交互动态路由协议报文的技术方案, 解决了无法及时根据网络 拓朴的变化而调整移动 VPN分支网络和总部网络之间的 IP流量流向, 导致 流量配置不合理的问题,从而达到了移动 VPN分支网络和总部网络可以根据 各自获得的网络拓朴, 动态调整 IP流量的流向, 使流量配置更加合理。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流 程, 是可以通过计算机程序来指令相关的硬件来完成, 所述的程序可存储于 一计算机可读取存储介质中, 该程序在执行时, 可包括如上述各方法的实施 例的流程。其中,所述的存储介质可为磁碟、光盘、只读存储记忆体( Read-Only Memory, ROM )或随机存^ ^己忆体 ( Random Access Memory, RAM )等。
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局限 于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易 想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护 范围应以权利要求的保护范围为准。

Claims

权 利 要 求
1、 一种移动虚拟专用网通信的方法, 其特征在于, 包括:
获取终端网络地址和网关虚接口网络地址, 所述网关虚接口网络地址与 所述终端网络地址属于同一网段;
根据所述网关虚接口网络地址为移动终端的分组数据协议上下文创建虚 接口;
将所述终端网络地址发送给所述移动终端;
根据动态路由协议通过所述虚接口从所述移动终端获取所述移动终端所 服务的分支网络的网段地址。
2、 根据权利要求 1所述的移动虚拟专用网通信的方法, 其特征在于, 所 述获取终端网络地址和网关虚接口网络地址的步骤之前包括:
接收移动终端的激活请求;
L终端网络地址发送给所述移动
向所述移动终端发送激活响应, 所述激活响应包括所述终端网络地址。
3、根据权利要求 1或 2所述的移动虚拟专用网通信的方法,其特征在于, 所述获取终端网络地址和网关虚接口网络地址包括:
向鉴权授权计费服务器或动态主机分配协议服务器发送地址请求消息; 接收由所述鉴权授权计费服务器或所述动态主机分配协议服务器发送的 地址响应消息;
解析所述地址响应消息, 从所述地址响应消息中获取所述终端网络地址 和所述网关虚接口网络地址。
4、根据权利要求 1或 2所述的移动虚拟专用网通信的方法,其特征在于, 所述获取终端网络地址和网关虚接口网络地址包括:
在所述移动终端开通移动路由器功能时, 从本地地址池中获取一个网段 地址;
从获取的网段地址中确定两个网络地址, 将其中一个网络地址作为所述 终端网络地址, 将另一个网络地址作为所述网关虚接口网络地址。
5、根据权利要求 1或 2所述的移动虚拟专用网通信的方法,其特征在于, 所述根据动态路由协议通过所述虚接口从所述移动终端获取所述移动终端所 服务的分支网络的网段地址包括:
通过所述虚接口接收由移动终端发送的动态路由协议报文;
从所述动态路由协议报文中获取所述分支网络的网段地址。
6、 根据权利要求 5所述的移动虚拟专用网通信的方法, 其特征在于, 所 括:
将所述分支网络的网段地址与所述分组数据协议上下文关联。
7、根据权利要求 1或 2所述的移动虚拟专用网通信的方法,其特征在于, 所述 居所述终端网络地址和所述网关虚接口网络地址为移动终端的分组数 据协议上下文创建虚接口的步骤之后还包括:
根据动态路由协议通过所述虚接口从所述移动终端获取所述分支网络的 网络拓朴; 或者,
根据动态路由协议获取总部网络的网络拓朴, 并根据动态路由协议通过 所述虚接口将所述总部网络的网络拓朴通知所述移动终端; 或者,
通过所述虚接口从所述移动终端获取网络监测信息, 并根据所述网络监 测信息, 检测与所述移动终端之间的网络质量。
8、 一种移动虚拟专用网通信的方法, 其特征在于, 包括:
从移动分组网关获取终端网络地址; 网关虚接口网络地址与所述终端网络地址属于同一网段;
根据动态路由协议通过具有所述网关虚接口网络地址的虚接口将获得的 所服务的分支网络的网段地址通知所述移动分组网关。
9、 根据权利要求 8所述的移动虚拟专用网通信的方法, 其特征在于, 所 述根据动态路由协议通过具有所述网关虚接口网络地址的虚接口将所服务的 分支网络的网段地址通知所述移动分组网关包括:
根据动态路由协议获取所述分支网络的网段地址, 或者, 获取预先配置 的所述分支网络的网段地址;
通过所述虚接口向所述移动分组网关发送动态路由协议报文, 所述报文 包括所述分支网络的网段地址。
10、 根据权利要求 8所述的移动虚拟专用网通信的方法, 其特征在于, 所述获取移动分组网关的网关虚接口网络地址的步骤之后还包括:
根据动态路由协议获取所述分支网络的网络拓朴, 并根据动态路由协议 通过所述虚接口将所述分支网络的网络拓朴通知所述移动分组网关; 或者, 根据动态路由协议通过所述虚接口从所述移动分组网关获取总部网络的 网络拓朴; 或者,
通过所述虚接口从所述移动分组网关获取网络监测信息, 并根据所述网 络监测信息, 检测与所述移动分组网关之间的网络质量。
11、 一种移动虚拟专用网通信的装置, 其特征在于, 包括:
网络地址获取单元, 用于获取终端网络地址和网关虚接口网络地址, 所 述网关虚接口网络地址与所述终端网络地址属于同一网段;
接口创建单元, 用于根据所述网络地址获取单元获取的网关虚接口网络 地址, 为移动终端的分组数据协议上下文创建虚接口;
网络地址发送单元, 用于将所述网络地址获取单元获取的终端网络地址 发送给所述移动终端;
分支地址获取单元, 用于根据动态路由协议通过所述接口创建单元创建
12、 根据权利要求 11所述的移动虚拟专用网通信的装置, 其特征在于, 还包括:
请求接收单元, 用于接收移动终端的激活请求; 则所述网络地址发送单元, 用于向所述移动终端发送激活响应, 所述激 活响应包括所述网络地址获取单元获取的终端网络地址。
13、 根据权利要求 11或 12所述的移动虚拟专用网通信的装置, 其特征 在于, 所述网络地址获取单元包括:
地址请求发送子单元, 用于向鉴权授权计费服务器或动态主机分配协议 服务器发送地址请求消息;
地址响应接收子单元, 用于接收由所述鉴权授权计费服务器或所述动态 主机分配协议服务器发送的地址响应消息;
网络地址获取子单元, 用于解析所述地址响应接收子单元接收的地址响 应消息, 从所述地址响应消息中获取所述终端网络地址和所述网关虚接口网 络地址。
14、 根据权利要求 11或 12所述的移动虚拟专用网通信的装置, 其特征 在于, 所述网络地址获取单元包括:
网段地址获取子单元, 用于在所述移动终端开通移动路由器功能时, 从 本地地址池中获取一个网段地址;
网络地址确定子单元, 用于从所述网段地址获取子单元获取的网段地址 中确定两个网络地址, 将其中一个网络地址作为所述终端网络地址, 将另一 个网络地址作为所述网关虚接口网络地址。
15、 根据权利要求 11或 12所述的移动虚拟专用网通信的装置, 其特征 在于, 所述分支地址获取单元包括:
报文接收子单元, 用于通过所述虚接口接收由移动终端发送的动态路由 协议报文;
网段地址获取子单元, 用于从所述报文接收子单元接收的动态路由协议 报文中获取所述分支网络的网段地址。
16、 根据权利要求 15所述的移动虚拟专用网通信的装置, 其特征在于, 所述分支地址获取单元还包括: 述分组数据协议上下文关联。
17、 根据权利要求 11或 12所述的移动虚拟专用网通信的装置, 其特征 在于, 还包括:
分支拓朴获取单元, 用于根据动态路由协议通过所述虚接口从所述移动 终端获取所述分支网络的网络拓朴; 或者,
总部拓朴获取单元, 用于根据动态路由协议获取总部网络的网络拓朴; 总部拓朴通知单元, 用于根据动态路由协议通过所述虚接口, 将所述总 部拓朴获取单元获取的网络拓朴通知所述移动终端; 或者,
监测信息获取单元, 用于通过所述虚接口从所述移动终端获取网络监测 信息;
网络质量检测单元, 用于根据所述监测信息获取单元获取的网络监测信 息, 检测与所述移动终端之间的网络质量。
18、 一种移动终端, 其特征在于, 包括:
终端地址获取单元, 用于从移动分组网关获取终端网络地址;
接口地址获取单元, 用于根据所述终端地址获取单元获取的终端网络地 址, 获取移动分组网关的网关虚接口网络地址, 所述网关虚接口网络地址与 所述终端网络地址属于同一网段;
分支地址通知单元, 用于根据动态路由协议通过具有所述网关虚接口网 络地址的虚接口将所服务的分支网络的网段地址通知所述移动分组网关。
19、 根据权利要求 18所述的移动终端, 其特征在于, 所述分支地址通知 单元包括:
分支地址获取子单元, 用于根据动态路由协议获取所述分支网络的网段 地址, 或者, 获取预先配置的所述分支网络的网段地址;
地址添加子单元, 用于在动态路由协议 4艮文中添加所述分支网络的网段 地址; 报文发送子单元, 用于通过所述虚接口向所述移动分组网关发送所述动 态路由协议报文。
20、 根据权利要求 18所述的移动终端, 其特征在于, 还包括: 分支拓朴获取单元, 用于根据动态路由协议获取所述分支网络的网段地 址;
分支拓朴通知单元, 用于根据动态路由协议通过所述虚接口将所述分支 网络的网段地址通知所述移动分组网关; 或者,
总部拓朴获取单元, 用于根据动态路由协议通过所述虚接口从所述移动 分组网关获取总部网络的网络拓朴; 或者,
监测信息获取单元, 用于通过所述虚接口从所述移动分组网关获取网络 监测信息;
网络质量检测单元, 用于根据所述监测信息获取单元获取的网络监测信 息, 检测与所述移动分组网关之间的网络质量。
21、 一种移动虚拟专用网通信的系统, 其特征在于, 包括至少一个移动 终端和移动分组网关:
其中, 所述移动分组网关, 用于获取终端网络地址和网关虚接口网络地 址, 所述网关虚接口网络地址与所述终端网络地址属于同一网段; 居所述 网关虚接口网络地址为所述移动终端的分组数据协议上下文创建虚接口; 并 将所述终端网络地址发送给所述移动终端; 根据动态路由协议通过所述虚接 所述移动终端, 用于从移动分组网关获取终端网络地址; 并 居所述终 端网络地址获取所述移动分组网关的网关虚接口网络地址, 所述网关虚接口 网络地址与所述终端网络地址属于同一网段; 并根据动态路由协议通过具有 所述网关虚接口网络地址的虚接口将所服务的分支网络的网段地址通知所述 移动分组网关。
22、 根据权利要求 21所述的移动虚拟专用网通信的系统, 其特征在于, 还包括鉴权授权计费服务器, 用于存储所述终端网络地址和所述网关虚接口 网络地址; 或者,
动态主机分配协议服务器, 用于存储所述终端网络地址和所述网关虚接 口网给地址;
所述移动分组网关, 还用于从所述鉴权授权计费服务器或者所述动态主 机分配协议服务器获取所述终端网络地址和所述网关虚接口网络地址。
PCT/CN2009/074976 2009-05-27 2009-11-17 移动虚拟专用网通信的方法、装置及系统 WO2010135887A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
JP2012512180A JP5412695B2 (ja) 2009-05-27 2009-11-17 モバイル仮想プライベートネットワーク通信のための方法、装置およびシステム
EP20090845103 EP2426885B9 (en) 2009-05-27 2009-11-17 Method, device and system for mobile virtual private network communication
KR1020117029643A KR101313831B1 (ko) 2009-05-27 2009-11-17 모바일 가상 사설망 통신을 위한 방법, 장치 및 시스템
US13/302,860 US9084108B2 (en) 2009-05-27 2011-11-22 Method, apparatus, and system for mobile virtual private network communication

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2009101436182A CN101562807B (zh) 2009-05-27 2009-05-27 移动虚拟专用网通信的方法、装置及系统
CN200910143618.2 2009-05-27

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US13/302,860 Continuation US9084108B2 (en) 2009-05-27 2011-11-22 Method, apparatus, and system for mobile virtual private network communication

Publications (1)

Publication Number Publication Date
WO2010135887A1 true WO2010135887A1 (zh) 2010-12-02

Family

ID=41221386

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/074976 WO2010135887A1 (zh) 2009-05-27 2009-11-17 移动虚拟专用网通信的方法、装置及系统

Country Status (6)

Country Link
US (1) US9084108B2 (zh)
EP (1) EP2426885B9 (zh)
JP (1) JP5412695B2 (zh)
KR (1) KR101313831B1 (zh)
CN (1) CN101562807B (zh)
WO (1) WO2010135887A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014060483A (ja) * 2012-09-14 2014-04-03 Hitachi Kokusai Electric Inc 通信システム及びその通信方法
TWI679866B (zh) * 2018-11-19 2019-12-11 中華電信股份有限公司 虛擬私有網路服務品質之量測系統及量測方法

Families Citing this family (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101562807B (zh) 2009-05-27 2011-04-20 华为技术有限公司 移动虚拟专用网通信的方法、装置及系统
US9246872B2 (en) * 2010-11-24 2016-01-26 Telefonaktiebolaget L M Ericsson (Publ) Methods and arrangements for enabling data transmission between a mobile device and a static destination address
US9231908B2 (en) * 2012-02-08 2016-01-05 Microsoft Technology Licensing, Llc Ensuring symmetric routing to private network
CN102769556B (zh) * 2012-06-01 2015-03-18 杭州华三通信技术有限公司 激活vlan的动态调整方法和装置
EP2919528B1 (en) * 2012-11-28 2018-01-10 Huawei Technologies Co., Ltd. Mobile network communication method, communication device and communication system
US9124525B2 (en) * 2013-06-24 2015-09-01 Cisco Technology, Inc. User-equipment-initiated framed routes on customer-premises equipment for wireless wide area networks
KR20150142218A (ko) * 2014-06-11 2015-12-22 삼성전자주식회사 전자 장치 및 전자 장치의 네트워크 연결방법
US10110702B2 (en) * 2015-04-16 2018-10-23 Hewlett Packard Enterprise Development Lp Dynamic download and enforcement of network access role based on network login context
US9942201B1 (en) 2015-12-16 2018-04-10 vIPtela Inc. Context specific keys
WO2017127972A1 (zh) * 2016-01-25 2017-08-03 华为技术有限公司 一种数据传输方法以及宿主机
WO2017206076A1 (zh) * 2016-05-31 2017-12-07 华为技术有限公司 一种多网关扩容方法及装置
CN111224857A (zh) 2016-06-29 2020-06-02 华为技术有限公司 用于实现组合虚拟专用网vpn的方法与装置
CN109067718B (zh) * 2018-07-23 2021-04-27 浙江吉利汽车研究院有限公司 车载多媒体主机与移动终端共享网络的方法、装置、系统
CN110881213A (zh) * 2019-07-31 2020-03-13 苏州星际靶战网络信息技术有限公司 一种网络测试过程信息的传输方法及系统
CN114787937A (zh) * 2019-12-09 2022-07-22 皇家飞利浦有限公司 用于基于家庭互联网业务模式来监测健康状况的系统和方法

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1835480A (zh) * 2005-03-15 2006-09-20 合勤科技股份有限公司 使用sip通信协议架构作为移动式vpn代理器的方法
CN101052207A (zh) * 2006-04-05 2007-10-10 华为技术有限公司 一种可移动虚拟专用网的实现方法及系统
CN101110745A (zh) * 2007-08-14 2008-01-23 华为技术有限公司 衔接二层网络和三层网络的方法、装置和系统
US20080102747A1 (en) * 2006-10-31 2008-05-01 Mohammed Didarul Alam SSL-Based Mobile Virtual Private Networking Solution
CN101562807A (zh) * 2009-05-27 2009-10-21 华为技术有限公司 移动虚拟专用网通信的方法、装置及系统

Family Cites Families (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100464374B1 (ko) 2000-11-01 2004-12-31 삼성전자주식회사 이동통신 단말기에 고정 주소를 할당하기 위한 시스템 및방법
CN1180583C (zh) 2001-09-03 2004-12-15 华为技术有限公司 一种宽带网络虚拟专用网的实现方法
US7380124B1 (en) * 2002-03-28 2008-05-27 Nortel Networks Limited Security transmission protocol for a mobility IP network
US7388844B1 (en) * 2002-08-28 2008-06-17 Sprint Spectrum L.P. Method and system for initiating a virtual private network over a shared network on behalf of a wireless terminal
US20060171402A1 (en) * 2003-03-06 2006-08-03 Moore John A Method and system for providing broadband multimedia services
FR2854521A1 (fr) * 2003-04-30 2004-11-05 Orange France Dispositif de communications pour vehicule terrestre
JP2005130049A (ja) * 2003-10-21 2005-05-19 Fujitsu Ltd ノード
CN1292565C (zh) * 2004-01-17 2006-12-27 华为技术有限公司 对网络地址转换虚地址的地址解析协议请求响应的方法
US20050213562A1 (en) 2004-03-24 2005-09-29 Heng-Chien Chen Telecommunication system and method for routing data of an ip-based pbx extension to a host
JP2005341084A (ja) 2004-05-26 2005-12-08 Nec Corp Vpnシステム、リモート端末及びそれらに用いるリモートアクセス通信方法
CN101052022B (zh) * 2006-04-05 2010-10-13 华为技术有限公司 一种虚拟专用网用户访问公网的系统和方法
CN100544286C (zh) * 2007-07-27 2009-09-23 中兴通讯股份有限公司 一种实现虚拟专用局域网服务网络备份链路的方法及系统
CN101399830B (zh) * 2007-09-29 2012-06-06 联想(北京)有限公司 虚拟机系统及其共享以太网点对点协议链接的方法
CN101227471A (zh) * 2008-02-18 2008-07-23 中兴通讯股份有限公司 同网段地址解析协议代理方法及内部处理板间通信方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1835480A (zh) * 2005-03-15 2006-09-20 合勤科技股份有限公司 使用sip通信协议架构作为移动式vpn代理器的方法
CN101052207A (zh) * 2006-04-05 2007-10-10 华为技术有限公司 一种可移动虚拟专用网的实现方法及系统
US20080102747A1 (en) * 2006-10-31 2008-05-01 Mohammed Didarul Alam SSL-Based Mobile Virtual Private Networking Solution
CN101110745A (zh) * 2007-08-14 2008-01-23 华为技术有限公司 衔接二层网络和三层网络的方法、装置和系统
CN101562807A (zh) * 2009-05-27 2009-10-21 华为技术有限公司 移动虚拟专用网通信的方法、装置及系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP2426885A4 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014060483A (ja) * 2012-09-14 2014-04-03 Hitachi Kokusai Electric Inc 通信システム及びその通信方法
TWI679866B (zh) * 2018-11-19 2019-12-11 中華電信股份有限公司 虛擬私有網路服務品質之量測系統及量測方法

Also Published As

Publication number Publication date
JP2012528492A (ja) 2012-11-12
CN101562807A (zh) 2009-10-21
KR101313831B1 (ko) 2013-10-01
EP2426885B9 (en) 2014-03-26
EP2426885A1 (en) 2012-03-07
JP5412695B2 (ja) 2014-02-12
EP2426885B1 (en) 2013-10-09
CN101562807B (zh) 2011-04-20
KR20120014586A (ko) 2012-02-17
US9084108B2 (en) 2015-07-14
US20120079113A1 (en) 2012-03-29
EP2426885A4 (en) 2012-08-01

Similar Documents

Publication Publication Date Title
WO2010135887A1 (zh) 移动虚拟专用网通信的方法、装置及系统
US9578548B2 (en) System and method for configuring multiple IP connections
JP6059365B2 (ja) ネットワークにアクセスするシステム及び方法
US9503881B2 (en) Method, device, and system for user equipment to access evolved packet core network
US20210359971A1 (en) Method and Apparatuses for Avoiding Paging Storm During ARP Broadcast for Ethernet Type PDU
JP5987122B2 (ja) デバイス固有のトラフィックフローステアリングのためのネットワークアドレス変換されたデバイスの特定
WO2012130085A1 (zh) 与网管系统建立连接的方法、设备及通信系统
CN110519863A (zh) 用于建立和使用pdn连接的方法和装置
WO2012171169A1 (zh) 一种通信方法及负载均衡器
WO2013107136A1 (zh) 终端接入认证的方法及用户端设备
WO2013131487A1 (zh) 融合的核心网及其接入方法
WO2011079782A1 (zh) 一种实现策略与计费控制的方法、网关和移动终端
WO2014067420A1 (zh) 分组数据网络类型的管理方法、装置及系统
WO2012130083A1 (zh) 一种配置地址解析协议arp表项的方法和装置
WO2016188110A1 (zh) 一种公共wlan架构下的数据隧道建立方法和ap
WO2014071685A1 (zh) 基于移动网络的租户网络业务实现方法、系统及网元
WO2008154874A1 (fr) Procédé et système permettant d'établir un tunnel dans le réseau en évolution
WO2012136006A1 (zh) 多归属站点内主机的路由选择方法和装置
WO2012071739A1 (zh) 不同网络间寻址的实现方法、路由代理网元及系统
WO2013174190A1 (zh) 路由选择方法及功能网元
WO2012100611A1 (zh) 接入演进分组系统的方法及系统
JP2016524383A (ja) 通信インタフェースを選択する方法およびデバイス
WO2011147332A1 (zh) 网络消息处理方法、装置和通信系统
WO2010091562A1 (zh) 用于固定网络与第三方网络或应用服务器交互的方法及装置
WO2013107243A1 (zh) 会话建立方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09845103

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2012512180

Country of ref document: JP

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2009845103

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 20117029643

Country of ref document: KR

Kind code of ref document: A