WO2010139285A1 - 一种信息同步方法及通讯系统以及相关设备 - Google Patents

一种信息同步方法及通讯系统以及相关设备 Download PDF

Info

Publication number
WO2010139285A1
WO2010139285A1 PCT/CN2010/073593 CN2010073593W WO2010139285A1 WO 2010139285 A1 WO2010139285 A1 WO 2010139285A1 CN 2010073593 W CN2010073593 W CN 2010073593W WO 2010139285 A1 WO2010139285 A1 WO 2010139285A1
Authority
WO
WIPO (PCT)
Prior art keywords
network element
apn
request message
constraint information
aggregation
Prior art date
Application number
PCT/CN2010/073593
Other languages
English (en)
French (fr)
Inventor
王宁沈
胡颖
陈中平
戚彩霞
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2010139285A1 publication Critical patent/WO2010139285A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security

Definitions

  • the present invention relates to the field of communications, and in particular, to an information synchronization method, a communication system, and related devices. Background technique
  • the user terminal accesses the mobile communication network through the local wireless access network, and the user terminal carries an access point name (APN, Access Point Name) to the access node when accessing a packet data network.
  • APN Access Point Name
  • the access node uses the APN in the user terminal subscription information or provides a locally configured APN.
  • the access node selects a suitable data gateway for the user terminal and accesses the packet data network.
  • APNs are classified into different types, namely public network type and private network type, when user terminals are connected simultaneously.
  • APN Restriction An APN Restriction mechanism is introduced, and the APN is checked by the Maximum APN Restriction (Max APN Restriction), and the APN is determined according to a combination relationship between certain APN Restriction values.
  • APN access An APN Restriction (APN Restriction) mechanism is introduced, and the APN is checked by the Maximum APN Restriction (Max APN Restriction), and the APN is determined according to a combination relationship between certain APN Restriction values.
  • the user terminal can simultaneously access the packet data network through different access technologies, for example, simultaneously accessing a wireless local area network (WLAN) network and Long Term Evolution (LTE) network.
  • WLAN wireless local area network
  • LTE Long Term Evolution
  • the maximum APN constraint is calculated according to the APN constraint information corresponding to the APN of the connected connection established by the user terminal in the network, and the multi-access technology is used in the user terminal.
  • the user terminal establishes a connection in different access networks, and the access network calculates a maximum APN constraint according to the APN corresponding APN constraint information of the connected APN of the user terminal on the access network, respectively, for the same user in different access networks.
  • the maximum APN constraint may be different, so that different access networks may have different APN restrictions for user terminals.
  • the user terminal may establish a public network type APN connection on one access network, and another connection. A connection to the APN of the private network type is established on the network. This type of access may bring security risks to the private network that is connected. Summary of the invention
  • Embodiments of the present invention provide an information synchronization method, a communication system, and related devices, which can improve network security.
  • the information synchronization method provided by the embodiment of the present invention is applied to the multiple access technology, and the method includes: the aggregation network element receives the request message sent by the first network element, where the request message carries the access point name APN; The request message updates the APN constraint information in the aggregation network element; the aggregation network element sends the updated APN constraint information to the second network element.
  • the information synchronization method provided by the embodiment of the present invention is applied to the multiple access technology, and the method includes: the aggregation network element receives the request message sent by the first network element, where the request message carries the access point name APN; the aggregation network element The second request message is sent to the second network element, so that the second network element updates the APN constraint information in the second network element according to the second request message; the APN in the second request message and the request message The APN in the same is the same.
  • the communication system provided by the embodiment of the present invention is applied to a multiple access technology, including: a first network element, configured to send a request message, where the request message carries an APN; and an aggregation network element, configured to receive the first network element to send The request message is configured to update the APN constraint information in the aggregation network element according to the request message, and send the updated APN constraint information.
  • the second network element is configured to receive the APN constraint information sent by the aggregation network element.
  • the communication system provided by the embodiment of the present invention is applied to a multiple access technology, including: a first network element, configured to send a request message, where the request message carries an APN; and an aggregation network element, configured to receive the first network element to send a request message, sending a second request message to the second network element, where the APN in the second request message is the same as the APN in the request message, and the second network element is configured to receive the first sent by the aggregation network element
  • the second request message updates the APN constraint information in the second network element according to the second request message.
  • the aggregation network element provided by the embodiment of the present invention is applied to the multiple access technology, and includes: a receiving unit, configured to receive a request message sent by the first network element, where the request message carries an APN; and an update unit, configured to The request message is used to update the APN constraint information in the aggregation network element, and the sending unit is configured to send the updated APN constraint information to the second network element.
  • the aggregation network element provided by the embodiment of the present invention is applied to the multiple access technology, and includes: a second receiving unit, configured to receive a request message sent by the first network element, where the request message carries an APN; Sending a second request message to the second network element, so that the second network element updates the APN constraint information in the second network element according to the second request message; the APN in the second request message and the request The APN in the message is the same.
  • Figure 1 is a logical architecture diagram of a next generation mobile communication network
  • 2 is a schematic diagram of an embodiment of an information synchronization method according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram of another embodiment of an information synchronization method according to an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of another embodiment of an information synchronization method according to an embodiment of the present invention.
  • FIG. 5 is a schematic diagram of another embodiment of an information synchronization method according to an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of another embodiment of an information synchronization method according to an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of another embodiment of an information synchronization method according to an embodiment of the present invention.
  • FIG. 8 is a schematic diagram of another embodiment of an information synchronization method according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram of an embodiment of a communication system according to an embodiment of the present invention.
  • FIG. 10 is a schematic diagram of another embodiment of a communication system according to an embodiment of the present invention.
  • FIG. 11 is a schematic diagram of an embodiment of an aggregation network element according to an embodiment of the present invention.
  • FIG. 12 is a schematic diagram of another embodiment of an aggregation network element according to an embodiment of the present invention. detailed description
  • Embodiments of the present invention provide an information synchronization method, a communication system, and related devices, which are used to improve network security.
  • the embodiment of the present invention can be applied to a next-generation mobile communication system as shown in FIG. 1.
  • a user terminal accesses a mobile communication network through a local wireless access network, and the access node is an access network.
  • the convergence point is responsible for access technology related connection management and data forwarding.
  • the data gateway is a gateway for accessing the packet data network, and is responsible for the data connection management and data forwarding of the user terminal accessing the packet data network, and also provides the anchor point of the mobile service for the user terminal.
  • an embodiment of the information synchronization method in the embodiment of the present invention is applied to multiple access technologies, and specifically includes:
  • the first network element sends a request message to the aggregation network element.
  • the request message sent by the first network element to the aggregation network element carries the APN.
  • the aggregation network element updates the local data according to the request message sent by the first network element.
  • the aggregation network element may update the APN constraint information in the aggregation network element according to the content of the request message.
  • the aggregation network element sends the updated APN constraint information to the second network element.
  • the first network element and the second network element are respectively network elements of different access networks accessed by the same user terminal, and the second network element is at least one, if the user terminal accesses two accesses at the same time.
  • the second network element is one. If the user terminal accesses three access networks at the same time, the second network element is two, and so on.
  • the aggregation network element updates the local APN constraint information
  • the updated APN constraint information can be sent. To the second network element.
  • the aggregation network element may update the APN constraint information in the aggregation network element according to the request message, and at the same time, the user terminal can be queried.
  • the second network element of the other access network, the second network element is at least one, and the updated APN constraint information may be sent to the second network element, so that different access networks use the same APN constraint information to obtain the maximum
  • the APN constraint controls the access of the APN, thereby improving network security.
  • the first network element may first calculate the maximum APN constraint before sending the request message to the aggregation network element, and send the maximum APN constraint to the data gateway to perform APN access control.
  • the maximum APN constraint may be calculated before sending the request message to the aggregation network element, and send the maximum APN constraint to the data gateway to perform APN access control.
  • FIG. 3 Another embodiment of the information synchronization method in the embodiment is applied to a multiple access technology, specifically including -
  • the first network element obtains APN constraint information activated by the user terminal.
  • the first network element may obtain the APN constraint information activated by the user terminal in a network from the aggregation network element or other network element.
  • the first network element calculates a maximum APN constraint according to the APN constraint information activated by the user terminal. After the first network element obtains the APN constraint information activated by the user terminal, the maximum APN constraint may be calculated, and the specific calculation process is The common knowledge of those skilled in the art is not limited herein.
  • the data gateway receives the maximum APN constraint sent by the first network element and the APN.
  • the first network element calculates the maximum APN constraint
  • the maximum APN constraint and the APN can be sent to the data gateway.
  • the data gateway in this embodiment may be a packet data network gateway (PGW), and may also be a gateway with similar functions to the PGW, which is not limited herein.
  • PGW packet data network gateway
  • the data gateway sends an allow access message to the first network element.
  • the data gateway After receiving the maximum APN constraint and the APN sent by the first network element, the data gateway can determine whether the APN is allowed to access according to the maximum APN constraint, and if allowed, send the permission access message to the first network element, if not allowed, Sending a reject message including the cause value to the first network element, so that the first network element feeds back the cause value to the user terminal.
  • the first network element sends a request message to the aggregation network element.
  • the request message may be sent to the aggregation network element, where the request message carries the APN, which may be the APN requested by the user terminal. Or the APN requested by the user terminal to be deleted.
  • the APN in this embodiment may be identified by an APN ID (APN ID or APN Identifier). If a context identifier (Context ID or Context Identifier) appears in the request message, the APN may also be identified by the context. To identify.
  • APN ID APN ID or APN Identifier
  • the HSS may check whether the first network element identifier saved in the HSS matches the first network element identifier in the request message, and if yes, Then perform the operation of data update.
  • the aggregation network element updates the local data according to the request message sent by the first network element.
  • the aggregation network element can update the APN and the APN constraint information in the aggregation network element according to the content of the request message.
  • the aggregation network element can simultaneously aggregate the network element.
  • the APN and APN constraint information are updated, and only the APN constraint information can be updated.
  • the specific update process can be divided into two cases: adding and deleting according to the content of the request message.
  • the aggregation network element can determine which update is specifically performed by the following method:
  • the aggregation network element determines whether the APN constraint information exists in the request message, if yes (ie, If the request message includes the APN and the APN constraint information, the aggregation process determines that the aggregation process saves the APN and the APN constraint information. If the request message includes only the APN and does not include the APN constraint information, the deletion process is determined. The aggregation network element deletes the APN constraint information corresponding to the APN locally.
  • update information for example, updating the PGW information, or updating the APN information, or updating the APN constraint information
  • the aggregation network element saves the APN and the APN constraint information in the request message, and if the indication information in the request message indicates the deletion information, determining After the deletion process is performed, the aggregation network element locally deletes the APN constraint information corresponding to the APN in the request message.
  • the manner in which the aggregation network element determines which update process is specifically used according to the request message is not limited to the two methods mentioned above. In actual applications, more methods can also be used for judgment. Make a limit.
  • the indication information in the request message of this embodiment may specifically be Server Assignment Type indication information.
  • the aggregation network element sends the updated APN and the APN constraint information to the second network element.
  • the first network element and the second network element are respectively network elements of different access networks accessed by the same user terminal, and the second network element is at least one, if the user terminal accesses two accesses at the same time.
  • the second network element is one. If the user terminal accesses three access networks at the same time, the second network element is two, and so on.
  • the aggregation network element updates the local APN and the APN constraint information
  • the updated APN and the APN constraint information may be sent to the second network element.
  • the aggregation network element may further feed back a response message to the first network element, and the second network element receives the update sent by the aggregation network element. After the APN and the APN constraint information, the response message can be fed back to the aggregation network element.
  • the specific process is not limited here.
  • the aggregation network element may update the APN and the APN constraint information in the aggregation network element according to the request message, and can query the user at the same time.
  • the second network element of the other access network that is accessed by the terminal, the second network element is at least one, and the updated APN and the APN constraint information may be sent to the second network element, where the first network element passes the aggregation network element.
  • the APN constraint information is updated to the second network element, so that different access networks use the same APN constraint information to obtain the maximum APN constraint to control access of the APN, thereby improving network security.
  • the user terminal has access to the Non-3GPP network and initiates the 3GPP network access scheme:
  • the aggregation network element is a Home Subscriber Server (HSS)
  • the first network element is an access node
  • the second network element is an authentication-accounting-authorization server (AAA Server)
  • the data gateway is PGW.
  • the AAA Server in this embodiment may be a 3GPP AAA Server in actual application.
  • the access node in this embodiment is described by using a Mobility Management Entity (MME) as an example. It can be understood that, in an actual application, the access node may also be a serving general packet radio service support node (SGSN). , Serving General Packet Radio Service Support Node), or other network elements, not limited here.
  • MME Mobility Management Entity
  • SGSN serving general packet radio service support node
  • SGSN Serving General Packet Radio Service Support Node
  • other network elements not limited here.
  • another embodiment of the information synchronization method in the embodiment of the present invention includes:
  • the user terminal accesses the Non-3GPP network.
  • the user terminal initiates an attach request to the network.
  • the MME selects a default APN for the user terminal.
  • the MME sends a location update request Update Location Request message to the HSS, and updates the location information of the user in the HSS.
  • the HSS feeds back to the MME a location update confirmation message Update Location Ack;
  • the location update request sent by the MME to the HSS carries the related information of the user terminal, and the HSS can obtain the APN and APN constraint information activated by the user terminal in the Non-3GPP network, and the information is updated by the location.
  • the confirmation message is fed back to the MME.
  • the MME sends a default bearer request message to the serving gateway (SGW, Serving Gateway). Create Default Bearer Request;
  • the MME can calculate the maximum APN constraint according to the information, and the specific calculation process is known to those skilled in the art. Common sense, not limited here.
  • the APN constraint and the APN are carried in the Create Default Bearer Request message and sent to the SGW to request the SGW to forward the maximum APN constraint and the APN to the PGW.
  • the SGW sends a default bearer request message to the PGW. Create Default Bearer Request;
  • the message is a proxy binding update Proxy Binding Update message.
  • the message sent by the SGW to the PGW carries the maximum APN constraint calculated by the MME and the APN.
  • the PGW sends a default bearer response message to the SGW. Create Default Bearer Response;
  • the message is a proxy binding confirmation Proxy Binding Ack message.
  • the PGW After receiving the message sent by the SGW, the PGW reads the maximum APN constraint and the APN from the message, and determines whether to allow the APN access according to the maximum APN constraint. If allowed, the PGW carries the allowed access information in the message sent to the SGW. If not allowed, the rejection message is carried in the message sent to the SGW.
  • the SGW sends a default bearer response message to the MME.
  • the MME sends an attach accept message to the user terminal.
  • the user terminal sends an attach complete message to the MME.
  • the MME updates the bearer information on the SGW
  • the SGW updates the bearer information on the PGW.
  • the MME sends a notification request message to the HSS, Notify Request;
  • the MME if the MME receives the allowed access information from the SGW, the MME sends the notification request message to the HSS, or may further carry the APN constraint information, if the MME receives the information from the SGW.
  • the MME carries the rejection information, and the MME directly feeds back the rejection information carrying the reason value to the user terminal, and ends the process.
  • the HSS after receiving the notification request message sent by the MME, the HSS updates the APN and APN constraint information in the HSS according to the message, and sends the updated APN and APN constraint information to the 3GPP AAA through the user information update request.
  • the HSS may check whether the MME identifier stored in the HSS matches the MME identifier in the request message, and if yes, perform an operation of updating the data.
  • the HSS sends a notification response message to the MME. Notify Response 0
  • the 3GPP AAA Server may also send the APN and the APN constraint information to the access gateway by inserting the subscription data message Insert Subscriber Data, and the access gateway in this embodiment.
  • It can be an EPLG (Evolved Packet Data Gateway) or a Trusted Non-3GPP IP Access (trusted Non-3GPP IP Access).
  • the Non-3GPP network can calculate the maximum APN constraint according to the APN constraint information, and use the maximum APN constraint to request the user terminal to access the non-3GPP network.
  • the MME updates the APN constraint information to the 3GPP AAA Server through the HSS, so that the same maximum APN constraint can be used in different access networks of the same user terminal to perform APN access control, thereby Improve network security.
  • the user terminal has access to the 3GPP network and initiates a Non-3GPP network access solution:
  • the aggregation network element in this embodiment is an HSS
  • the first network element is an AAA server
  • the second network element is an access node
  • the data gateway is a PGW.
  • the AAA Server in this embodiment may be a 3GPP AAA Server in actual application.
  • the access node in this embodiment is described by using the MME as an example. It can be understood that, in an actual application, the access node may also be an SGSN or other network element, which is not limited herein.
  • the access gateway in this embodiment may be an ePDG or a Trusted Non-3GPP IP Access.
  • another embodiment of the information synchronization method in the embodiment of the present invention includes:
  • the user terminal accesses to a 3GPP network.
  • the Non-3GPP performs an access related L2 process.
  • the user terminal and the network authenticate each other;
  • the access gateway obtains the information of the user terminal from the HSS in the process of authenticating the user terminal and the network, and includes the APN and APN constraint information activated by the user terminal in the 3GPP network.
  • the access gateway calculates the maximum APN constraint according to the APN and APN constraint information activated by the user terminal in the 3GPP network.
  • the specific calculation process is not limited by the common knowledge of the person skilled in the art.
  • the user terminal initiates multiple access, and initiates an attach request to the access gateway.
  • the access gateway selects a default APN for the user terminal.
  • the gateway controls a session establishment process.
  • the access gateway sends a proxy binding update message to the PGW, Proxy Binding Update;
  • the access gateway calculates the maximum APN constraint
  • the maximum APN constraint and the APN are obtained. It is sent to the PGW in the proxy binding update message.
  • the PGW initiates an IP-Can Session establishment process of a Policy Control and Charging Rules Function (PCRF);
  • PCRF Policy Control and Charging Rules Function
  • the PGW sends an update PGW address request message to the HSS. Update PGW Address Request;
  • the PGW reads the maximum APN constraint and the APN from the message sent by the access gateway, and determines whether to allow the APN access according to the maximum APN constraint. If the access is allowed, the 3GPP AAA Server is notified, and thus the 3GPP AAA Server The APN and the APN constraint information are sent to the HSS, and the HSS updates the APN and APN constraint information in the HSS, and sends the updated APN and APN constraint information to the MME.
  • the HSS may check whether the 3GPP AAA Server identifier stored in the HSS matches the 3GPP AAA Server identifier in the request message. Then perform the operation of data update.
  • the 3GPP AAA Server may send the APN and APN constraint information to the HSS through a non-3GPP Internet Access Registration Request message.
  • the HSS can send the updated APN and APN constraint information to the MME by inserting an Insert Subscriber Data message.
  • the HSS sends an update PGW address response Update PGW Address Response message to the PGW.
  • the PGW sends a proxy binding acknowledgement message to the access gateway.
  • Proxy Binding Update Ack
  • the PGW determines that the APN is allowed to access, the PGW sends an APN Restriction message to the access gateway through the proxy binding acknowledgement message, and the access gateway saves the APN and APN Restriction information, thereby calculating the maximum APN constraint.
  • the PGW determines that the APN is not allowed to access, the PGW notifies the access gateway of the rejection information and carries the cause value.
  • the gateway-controlled session modification process that may be initiated by the PCRF updates the QoS information in the AGW.
  • the access gateway sends the rejection information carrying the cause value to the user terminal.
  • the MME calculates the maximum APN constraint according to the APN constraint information sent by the HSS, and sends the maximum APN constraint to the PGW.
  • the PGW can use the maximum APN constraint to check the new APN requested by the user terminal in the 3GPP network.
  • the 3GPP AAA Server updates the APN constraint information to the MME through the HSS, so that different access networks (3GPP network and Non-3GPP network) use the same APN Restriction information to obtain The Max APN Restriction value is used to perform access check on the APN requested by the user, thus improving network security.
  • the user terminal simultaneously accesses the 3GPP network and the Non-3GPP network, and the user terminal deletes the PDN connection scheme on the 3GPP network:
  • the aggregation network element is an HSS
  • the first network element is an access node
  • the second network element is an AAA server.
  • the AAA server in this embodiment may be a 3GPP AAA Server in actual application.
  • the access node in this embodiment is described by using the MME as an example. It can be understood that, in an actual application, the access node may also be an SGSN or other network element, which is not limited herein.
  • another embodiment of the information synchronization method in the embodiment of the present invention includes:
  • the user terminal accesses the Non-3GPP network.
  • the user terminal sends a delete PDN connection request message to the MME.
  • the MME sends a delete PDN connection request message to the SGW, and the SGW sends a delete PDN connection request message to the PGW, and the PGW sends a delete PDN connection response message to the SGW, and the SGW sends a delete PDN connection response message to the MME.
  • the MME sends a deactivated bearer request message to an Evolved Universal Mobile Telecommunications System Territorial Radio Access Network (E-UTRAN).
  • E-UTRAN Evolved Universal Mobile Telecommunications System Territorial Radio Access Network
  • RRC Radio Resource Control
  • the E-UTRAN sends a deactivation bearer response message to the MME.
  • the MME sends a notification request message to the HSS, Notify Request;
  • the notification request message sent by the MME to the HSS carries the APN.
  • the MME when the PDN connection is deleted, the MME does not necessarily send the Notify to the HSS.
  • the MME does not send the message, and other request messages can be used to carry the APN.
  • the HSS may check whether the MME identifier stored in the HSS matches the MME identifier in the request message, and if yes, perform an operation of updating the data.
  • the HSS sends a notification response message Notify Response to the MME.
  • the HSS After receiving the notification request message sent by the MME, the HSS reads the APN from the ASN and deletes the APN in the HSS. Corresponding APN constraint information, and then transmitting the locally updated APN and APN constraint information to the 3GPP AAA Server through the user information update request, the Non-3GPP network calculates the maximum APN constraint according to the APN constraint information sent by the HSS, and uses the maximum APN constraint.
  • the MME updates the APN constraint information to the 3GPP AAA Server through the HSS, thereby implementing different access networks (3GPP network and Non-).
  • the 3GPP network uses the same APN Restriction information to obtain the Max APN Restriction value, and performs access check on the APN requested by the user, thereby improving network security.
  • the user terminal simultaneously accesses the 3GPP network and the Non-3GPP network, and the user terminal deletes the PDN connection scheme in the Non-3GPP network:
  • the aggregation network element is an HSS
  • the first network element is an AAA server
  • the second network element is an access node.
  • the AAA Server in this embodiment may be a 3GPP AAA Server in actual application.
  • the access node in this embodiment is described by using the MME as an example. It can be understood that, in an actual application, the access node may also be an SGSN or other network element, which is not limited herein.
  • another embodiment of the information synchronization method in the embodiment of the present invention includes:
  • the user terminal accesses in a 3GPP network.
  • the user terminal sends a delete PDN connection request message to the access gateway.
  • the access gateway sends a proxy binding update message to the PGW, Proxy Binding Update;
  • the PGW sends an update PGW address request message to the 3GPP AAA Server, an Update PGW Address Request.
  • the 3GPP AAA Server may send the APN to the HSS, and the HSS deletes the APN constraint information corresponding to the APN in the HSS, and then sends the locally updated APN and APN constraint information to the MME. .
  • the HSS may check whether the 3GPP AAA Server identifier stored in the HSS matches the 3GPP AAA Server identifier in the request message, and if yes, perform data update. Operation.
  • the 3GPP AAA Server can access the registration request through the non-3GPP Internet Protocol (Non-3GPP).
  • Non-3GPP Internet Protocol
  • the IP Access Registration Request message sends the APN to the HSS.
  • the HSS can send the updated APN and APN constraint information to the MME by inserting an Insert Subscriber Data message.
  • the 3GPP AAA Server sends an update PGW address response message to the PGW. Update PGW Address Response; 706.
  • the PGW sends a proxy binding acknowledgement message Proxy Binding Ack to the AGW.
  • the MME calculates the maximum APN constraint according to the APN constraint information sent by the HSS, and sends the maximum APN constraint to the PGW.
  • the PGW uses the maximum APN constraint to check the new APN that the user terminal requests to access in the 3GPP network.
  • the 3GPP AAA Server updates the APN constraint information to the MME through the HSS, thereby implementing different access networks (the 3GPP network and the Non-3GPP network M use the same APN Restriction information to obtain the Max APN Restriction value, and the APN requested by the user is connected. Checking in, thus improving network security.
  • the aggregation network element updates the APN constraint information in the aggregation network element according to the request message, and sends the updated APN constraint information to the second network element.
  • the aggregation network element can also directly
  • the request message sent by the first network element is forwarded to the second network element, and the second network element updates the APN constraint information in the second network element according to the request message.
  • FIG. 8 the information synchronization method in the embodiment of the present invention.
  • Another embodiment is applied to multiple access technologies, and specifically includes:
  • the aggregation network element receives the request message sent by the first network element.
  • the request message sent by the first network element to the aggregation network element carries the APN.
  • the request message may further carry the APN constraint information.
  • the aggregation network element sends the second request message to the second network element.
  • the aggregation network element may send a second request message to the second network element, where the APN in the second request message is sent with the request message sent by the first network element.
  • the APN in the same is the same.
  • the second network element updates the APN constraint information in the second network element according to the second request message.
  • the manner in which the specific second network element is updated may be:
  • the second network element deletes the APN constraint information in the second network element corresponding to the APN in the second request message.
  • the second network element saves the APN constraint information carried in the second request message
  • the second network element deletes the APN constraint information in the second network element corresponding to the APN in the second request message;
  • the second network element saves the APN constraint information carried in the second request message.
  • the network element specified by the first network element and the second network element is consistent with the description in the foregoing embodiment, and the first network element sends a request to the aggregation network element.
  • the flow of the message, the aggregation network element to the second The flow of the NE forwarding request message is also consistent with the description in the foregoing embodiment, and details are not described herein again.
  • the aggregation network element after receiving the request message from the first network element, the aggregation network element sends the second request message to the second network element, so that the second network element can be in the second network element according to the second request message.
  • the APN constraint information is updated, so that different access networks use the same APN Restriction information to obtain a Max APN Restriction value, and perform access check on the APN requested by the user, thereby improving network security.
  • an embodiment of the communication system in the embodiment of the present invention is applied to multiple access technologies, and specifically includes:
  • the first network element 901 is configured to send a request message to the aggregation network element 902, where the request message carries
  • the aggregation network element 902 is configured to receive the request message sent by the first network element 901, update the APN constraint information in the aggregation network element according to the request message, and send the updated APN constraint information to the second network element 903. ;
  • the second network element 903 is configured to receive APN constraint information sent by the aggregation network element 902.
  • the second network element 903 is at least one, and the second network element 903 and the first network element 901 belong to different access networks accessed by the same user terminal.
  • the aggregation network element 902 in this embodiment may also update the APN in the aggregation network element 902 according to the request message, and may also send the updated APN to the second network element 903.
  • another embodiment of the communication system in the embodiment of the present invention is applied to multiple access technologies, and specifically includes: a first network element 1001, an aggregation network element 1002, and a second network element 1003;
  • the first network element 1001 is configured to send a request message to the aggregation network element 1002, where the request message carries
  • the aggregation network element 1002 is configured to receive the request message sent by the first network element 1001, update the APN and APN constraint information in the aggregation network element 1002 according to the request message, and send the updated APN and APN constraint information to the a second network element 1003;
  • the second network element 1003 is configured to receive the APN and the APN constraint information sent by the aggregation network element 1002.
  • the second network element 1003 is at least one, the second network element 1003 and the first network element 1001. Different access networks belonging to the same user terminal respectively.
  • the first network element 1001 in this embodiment is further configured to acquire APN constraint information activated by the user terminal, and calculate a maximum APN constraint according to the APN constraint information activated by the user terminal;
  • the communication system in this embodiment further includes:
  • the data gateway 1004 is configured to receive the maximum APN constraint and the APN calculated by the first network element 1001. If the APN is allowed to access according to the maximum APN constraint, the first network element 1001 is triggered to the aggregation network element 1002. Sending a request message including the APN and the APN constraint information, if it is determined that the APN does not allow access according to the maximum APN constraint, sending a reject message including the cause value to the first network element 1001.
  • the aggregation network element 1002 in this embodiment is an HSS
  • the first network element 1001 is an access node
  • the second network element 1003 is a 3GPP AAA Server
  • the data gateway 1004 is a PGW
  • the aggregation network element 1002 is an HSS
  • the first network element 1001 is a 3GPP AAA Server
  • the second network element 1003 is an access node
  • the data gateway 1004 is a PGW.
  • the access node in this embodiment is an MME or an SGSN.
  • the access gateway in this embodiment is an evolved packet data gateway or a trusted non-3GPP internet protocol access node.
  • the first network element 1001 obtains APN constraint information activated by the user terminal;
  • the first network element 1001 may obtain the APN constraint information activated by the user terminal in a certain network from the aggregation network element 1002 or other network elements.
  • the maximum APN constraint can be calculated.
  • the specific calculation process is common knowledge of those skilled in the art, and is not limited herein.
  • the first network element 1001 calculates the maximum APN constraint, the maximum APN constraint and the APN can be sent to the data gateway 1004.
  • the data gateway 1004 can determine whether the APN is allowed to access according to the maximum APN constraint, and if allowed, send an allow access message to the first network element 1001. If not, the reject message containing the cause value is sent to the first network element 1001, so that the first network element 1001 feeds back the cause value to the user terminal.
  • the request message may be sent to the aggregation network element 1002, where the request message carries the APN, and the user terminal may request the access. APN, or APN requested by the user terminal to delete.
  • the aggregation network 1002 After receiving the request message from the first network element 1001, the aggregation network 1002 can update the APN and APN constraint information in the aggregation network element 1002 according to the content of the request message.
  • the aggregation network element 1002 updates the local APN and APN constraint information
  • the updated APN can be updated.
  • the APN constraint information is sent to the second network element 1003.
  • the aggregation network element 1002 can update the APN and APN constraint information in the aggregation network element 1002 according to the request message, and can query at the same time. Go to the second network element 1003 of the other access network that is accessed by the user terminal, and send the updated APN and APN constraint information to the second network element 1003, so that different access networks use the same APN constraint information to obtain the maximum APN.
  • the constraint controls the access of the APN, thereby improving network security.
  • the communication system in this embodiment includes:
  • the first network element 901 is configured to send a request message to the aggregation network element 902, where the request message carries an APN;
  • the aggregation network element 902 is configured to send a second request message to the second network element 903, where the APN in the second request message is the same as the APN in the request message sent by the first network element 901;
  • the second network element 903 is configured to receive the second request message sent by the aggregation network element 902, and update the APN constraint information in the second network element 903 according to the second request message.
  • the aggregation network element 902 after receiving the request message from the first network element 901, the aggregation network element 902 sends the second request message to the second network element 903, so that the second network element 903 can be configured according to the second request message.
  • the APN constraint information in the second network element 903 is updated, so that different access networks use the same APN Restriction information to obtain the Max APN Restriction value, and perform access check on the APN requested by the user, thereby improving network security.
  • the aggregation network element in the embodiment of the present invention is applied to multiple access technologies, and specifically includes: a receiving unit 1101, configured to receive the first network element to send a request message, the request message carries an APN; the updating unit 1102 is configured to update the APN constraint information in the aggregation network element according to the request message received by the receiving unit 1101;
  • the sending unit 1103 is configured to send the updated APN constraint information of the update unit 1102 to the second network element, where the second network element is at least one, and the second network element and the first network element respectively belong to the same Different access networks accessed by user terminals.
  • the update unit 1102 in this embodiment may also update the APN in the aggregation network element according to the request message, and the sending unit 1103 may also send the updated APN to the second network element.
  • the updating unit 1102 may update the APN and the APN constraint information in the aggregation network element according to the request message, and the sending unit 1103
  • the updated APN and the APN constraint information may be sent to the second network element, so that different access networks use the same APN constraint information to obtain the maximum APN constraint to control access of the APN, thereby improving network security.
  • another embodiment of an aggregation network element in the embodiment of the present invention is applied to a multiple access technology, and specifically includes: a second receiving unit 1201, configured to receive a request message sent by a first network element, where the request message is The forwarding unit 1202 is configured to send a second request message to the second network element, so that the second network element updates the APN constraint information in the second network element according to the second request message.
  • the APN in the second request message is the same as the APN in the request message sent by the first network element.
  • the forwarding unit 1202 may send the second request message to the second network element, so that the second network element is configured according to the second network element.
  • the second request message updates the APN constraint information in the second network element. Therefore, the embodiment of the present invention can implement different APN constraints to obtain access to the APN by using different APN constraint information, thereby improving network security. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

一种信息同步方法及通讯系统以及相关设备 本申请要求 2009年 6月 5日递交的申请号为 200910146975.4、 发明名称为"一种信息 同步方法及通讯系统以及相关设备"的中国专利申请的优先权, 其全部内容通过引用结合在 本申请中。
技术领域
本发明涉及通讯领域, 尤其涉及一种信息同步方法及通讯系统以及相关设备。 背景技术
在下一代移动通信网络中, 用户终端通过本地的无线接入网络接入移动通信网络, 用 户终端访问一个报文数据网络时会携带一个接入点名称(APN, Access Point Name)给接入 节点, 若用户终端没有提供 APN, 则接入节点会使用用户终端签约信息中的 APN或者提供 一个本地配置的 APN, 接入节点为用户终端选择合适的数据网关, 接入到报文数据网络。
在第三代合作伙伴计划(3GPP, 3rd Generation Partnership Project) 网络中, 根据报文 数据网络的不同类型, APN被划分成不同的类型, 分别为公网类型以及私网类型, 当用户 终端同时接入公网类型的网络和私网类型的网络时, 可能会给私网类型的网络带来安全隐 患。 因此在 3GPP网络中, 引入了 APN约束 (APN Restriction)机制, 利用最大 APN约束 (Maximum APN Restriction简称 Max APN Restriction)对 APN进行校验,根据一定的 APN Restriction值之间的组合关系, 决定是否允许 APN接入。
随着网络的发展, 目前兴起一种多接入技术, 即用户终端可以同时通过不同的接入技 术接入到报文数据网络, 例如同时接入无线局域网 (WLAN, Wireless Local Area Network) 网络和长期演进(LTE, Long Term Evolution) 网络。
但是,现有技术中, 用户终端接入到某一网络时,最大 APN约束是根据用户终端在该 网络建立的连接的 APN对应的 APN约束信息计算得到的,而在用户终端使用多接入技术时, 用户终端在不同的接入网都建立有连接, 接入网分别根据用户终端在该接入网上的连接的 APN对应 APN约束信息计算最大 APN约束,对于相同用户在不同的接入网的最大 APN约 束可能不同, 这样不同接入网对用户终端请求的 APN的限制标准就会不同, 用户终端就有 可能在某一个接入网建立了公网类型的 APN的连接, 而在另一个接入网建立了私网类型的 APN的连接, 这种接入方式有可能会给接入的私网带来安全隐患。 发明内容
本发明实施例提供了一种信息同步方法及通讯系统以及相关设备, 能够提高网络安全 性。
本发明实施例提供的信息同步方法, 应用于多接入技术, 包括: 汇聚网元接收第一网 元发送的请求消息, 所述请求消息中携带有接入点名称 APN; 汇聚网元根据所述请求消息 对汇聚网元内的 APN约束信息进行更新; 汇聚网元将更新后的 APN约束信息发送至第二 网元。
本发明实施例提供的信息同步方法, 应用于多接入技术, 包括: 汇聚网元接收第一网 元发送的请求消息, 所述请求消息中携带有接入点名称 APN; 汇聚网元将第二请求消息发 送至第二网元, 以便于所述第二网元根据所述第二请求消息更新第二网元内的 APN约束信 息; 所述第二请求消息中的 APN与所述请求消息中的 APN相同。
本发明实施例提供的通讯系统, 应用于多接入技术, 包括: 第一网元, 用于发送请求 消息, 所述请求消息中携带有 APN; 汇聚网元, 用于接收第一网元发送的请求消息, 根据 所述请求消息对汇聚网元内的 APN约束信息进行更新, 发送更新后的 APN约束信息; 第 二网元, 用于接收所述汇聚网元发送的 APN约束信息。
本发明实施例提供的通讯系统, 应用于多接入技术, 包括: 第一网元, 用于发送请求 消息, 所述请求消息中携带有 APN; 汇聚网元, 用于接收第一网元发送的请求消息, 向第 二网元发送第二请求消息,所述第二请求消息中的 APN与所述请求消息中的 APN相同;第 二网元,用于接收所述汇聚网元发送的第二请求消息,根据所述第二请求消息对第二网元内 的 APN约束信息进行更新。
本发明实施例提供的汇聚网元, 应用于多接入技术, 包括: 接收单元, 用于接收第一 网元发送的请求消息, 所述请求消息中携带有 APN; 更新单元, 用于根据所述请求消息对 汇聚网元内的 APN约束信息进行更新; 发送单元, 用于将更新后的 APN约束信息发送至 第二网元。
本发明实施例提供的汇聚网元, 应用于多接入技术, 包括: 第二接收单元, 用于接收 第一网元发送的请求消息, 所述请求消息中携带有 APN; 转发单元, 用于向第二网元发送 第二请求消息, 以便于所述第二网元根据所述第二请求消息更新第二网元内的 APN约束信 息; 所述第二请求消息中的 APN与所述请求消息中的 APN相同。 附图说明
图 1为下一代移动通信网络的逻辑架构图; 图 2为本发明实施例中信息同步方法一个实施例示意图;
图 3为本发明实施例中信息同步方法另一实施例示意图;
图 4为本发明实施例中信息同步方法另一实施例示意图;
图 5为本发明实施例中信息同步方法另一实施例示意图;
图 6为本发明实施例中信息同步方法另一实施例示意图;
图 7为本发明实施例中信息同步方法另一实施例示意图;
图 8为本发明实施例中信息同步方法另一实施例示意图;
图 9为本发明实施例中通讯系统一个实施例示意图;
图 10为本发明实施例中通讯系统另一实施例示意图;
图 11为本发明实施例中汇聚网元一个实施例示意图;
图 12为本发明实施例中汇聚网元另一实施例示意图。 具体实施方式
本发明实施例提供了一种信息同步方法及通讯系统以及相关设备, 用于提高网络安全 性。
本发明实施例可以应用于如图 1所示的下一代移动通信系统中, 在下一代移动通信网 络中,用户终端通过本地的无线接入网络接入移动通信网络,接入节点是接入网络的汇聚点, 负责接入技术相关的连接管理与数据转发。数据网关是访问报文数据网络的网关,负责用户 终端访问报文数据网络的数据连接管理与数据转发, 同时也为用户终端提供移动服务的锚 点。
请参阅图 2, 本发明实施例中信息同步方法一个实施例应用于多接入技术, 具体包括:
201、 第一网元向汇聚网元发送请求消息;
本实施例中, 第一网元向汇聚网元发送的请求消息中携带有 APN。
202、 汇聚网元根据第一网元发送的请求消息更新本地数据;
汇聚网元从第一网元接收到请求消息之后, 即可根据该请求消息的内容对汇聚网元内 的 APN约束信息进行更新。
203、 汇聚网元将更新后的 APN约束信息发送至第二网元。
本实施例中,第一网元与第二网元分别为同一个用户终端接入的不同的接入网的网元, 第二网元至少为一个, 若用户终端同时接入两个接入网, 则第二网元为一个, 若用户终端同 时接入三个接入网, 则第二网元为两个, 依次类推。
汇聚网元对本地的 APN约束信息进行更新之后, 即可将更新后的 APN约束信息发送 至第二网元。
本实施例中,汇聚网元在获取到第一网元发送的携带有 APN的请求消息之后,可以根 据该请求消息对汇聚网元内的 APN约束信息进行更新, 同时能够查询到该用户终端接入的 其他接入网的第二网元, 该第二网元至少为一个, 随后可以将更新后的 APN约束信息发送 至第二网元, 使得不同接入网使用相同的 APN约束信息得到最大 APN约束对 APN的接入 进行控制, 从而提高了网络安全性。
本实施例中, 第一网元在向汇聚网元发送请求消息之前还可以首先计算最大 APN约 束, 并将该最大 APN约束发送至数据网关进行 APN接入控制, 具体请参阅图 3, 本发明实 施例中信息同步方法另一实施例应用于多接入技术, 具体包括-
301、 第一网元获取用户终端激活的 APN约束信息;
本实施例中, 第一网元可以从汇聚网元或其他网元中获取到用户终端在某网络中激活 的 APN约束信息。
302、 第一网元根据所述用户终端激活的 APN约束信息计算最大 APN约束; 第一网元获取到用户终端激活的 APN约束信息之后, 即可计算得到最大 APN约束, 具体的计算过程为本领域技术人员的公知常识, 此处不做限定。
303、 数据网关接收第一网元发送的所述最大 APN约束以及 APN;
第一网元计算得到最大 APN约束之后,即可将该最大 APN约束以及 APN发送至数据 网关。
本实施例中的数据网关可以为分组数据网络网关 (PGW, Packet Data Network Gateway) , 还可以为其他与 PGW具有类似功能的网关, 具体此处不做限定。
304、 数据网关向第一网元发送允许接入消息;
数据网关在接收到第一网元发送的最大 APN约束以及 APN之后, 即可根据最大 APN 约束判断 APN是否允许接入, 若允许, 则向第一网元发送允许接入消息, 若不允许, 则向 第一网元发送包含原因值的拒绝消息, 以便于第一网元向用户终端反馈该原因值。
305、 第一网元向汇聚网元发送请求消息;
本实施例中, 当第一网元从数据网关接收到允许接入消息时, 即可向汇聚网元发送请 求消息, 该请求消息中携带有 APN, 具体可以是用户终端请求接入的 APN, 或者是用户终 端请求删除的 APN。
本实施例中的 APN可以由 APN标识( APN ID或者 APN Identifier)来标识, 如果请 求消息中出现上下文标识(Context ID或者 Context Identifier) , APN也可以由上下文标识 来标识。
需要说明的是, 本实施例中, 第一网元将请求消息发送至 HSS之后, HSS可以检查 HSS 中保存的第一网元标识与请求消息中的第一网元标识是否匹配, 如果匹配, 则执行数 据更新的操作。
306、 汇聚网元根据第一网元发送的请求消息更新本地数据;
汇聚网元从第一网元接收到请求消息之后, 即可根据该请求消息的内容对汇聚网元内 的 APN以及 APN约束信息进行更新,本实施例中,汇聚网元可以同时对汇聚网元内的 APN 以及 APN约束信息进行更新, 也可以只更新 APN约束信息。
具体的更新过程根据请求消息的内容可以分为增添和删除两种情况, 汇聚网元可以采 用如下方式判断具体执行哪种更新:
( 1 )若请求消息中的指示信息指示为更新信息(例如更新 PGW信息, 或者更新 APN 信息, 或者更新 APN约束信息) , 则汇聚网元判断请求消息中是否存在 APN约束信息, 若 存在(即请求消息中包含 APN以及 APN约束信息) , 则确定进行增添过程, 则汇聚网元保 存该 APN以及 APN约束信息;若请求消息中只包含 APN而不包含 APN约束信息,则确定 进行删除过程, 则汇聚网元在本地删除该 APN对应的 APN约束信息。
(2)若请求消息中的指示信息指示为增添信息, 则确定进行增添过程, 则汇聚网元保 存请求消息中的 APN以及 APN约束信息,若请求消息中的指示信息指示为删除信息,则确 定进行删除过程, 则汇聚网元在本地删除请求消息中的 APN对应的 APN约束信息。
需要说明的是, 汇聚网元根据请求消息判断具体采用何种更新过程的方式并不限于上 述提到的两种方式, 在实际应用中, 同样还可以采用更多的方式进行判断, 此处不做限定。
本实施例的请求消息中的指示信息具体可以为 Server Assignment Type指示信息。
307、 汇聚网元将更新后的 APN以及 APN约束信息发送至第二网元。
本实施例中,第一网元与第二网元分别为同一个用户终端接入的不同的接入网的网元, 第二网元至少为一个, 若用户终端同时接入两个接入网, 则第二网元为一个, 若用户终端同 时接入三个接入网, 则第二网元为两个, 依次类推。
汇聚网元若对本地的 APN以及 APN约束信息都进行了更新, 则可以将更新后的 APN 以及 APN约束信息发送至第二网元。
需要说明的是, 本实施例中, 汇聚网元在接收到第一网元发送的请求消息之后, 还可 以向第一网元反馈响应消息,第二网元在接收到汇聚网元发送的更新后的 APN以及 APN约 束信息之后, 同样可以向汇聚网元反馈响应消息, 具体过程此处不做限定。 本实施例中,汇聚网元在获取到第一网元发送的携带有 APN的请求消息之后,可以根 据该请求消息对汇聚网元内的 APN以及 APN约束信息进行更新, 同时能够查询到该用户 终端接入的其他接入网的第二网元, 该第二网元至少为一个, 随后可以将更新后的 APN以 及 APN约束信息发送至第二网元,第一网元通过汇聚网元将 APN约束信息更新到第二网元, 使得不同接入网使用相同的 APN约束信息得到最大 APN约束对 APN的接入进行控制, 从 而提高了网络安全性。
为便于理解, 下面以一些具体实例对上述的信息同步方法实施例进行说明:
一、 用户终端已接入 Non-3GPP网络, 又发起 3GPP网络接入的方案:
本实施例中, 汇聚网元为归属用户服务器(HSS, Home Subscriber Server) , 第一网 元为接入节点, 第二网元为鉴权 -计费 -授权服务器(AAA Server) , 数据网关为 PGW。
本实施例中的 AAA Server在实际应用中具体可以为 3GPP AAA Server。
本实施例中的接入节点以移动性管理实体(MME, Mobility Management Entity) 为例 进行说明, 可以理解的是,在实际应用中,接入节点还可以为服务通用分组无线业务支持节 点(SGSN, Serving General Packet Radio Service Support Node) , 或者是其他网元, 此处不 做限定。
请参阅图 4, 本发明实施例中信息同步方法另一实施例包括:
401、 用户终端接入到 Non-3GPP网络;
402、 用户终端向网络发起附着请求 Attach Request;
本实施例中,若用户终端在附着请求中没有携带 APN信息,则 MME为用户终端选择 一个缺省的 APN。
403、 MME向 HSS发送位置更新请求 Update Location Request消息, 更新用户在 HSS 中的位置信息;
404、 HSS向 MME反馈位置更新确认消息 Update Location Ack;
本实施例中, MME发送给 HSS的位置更新请求中携带有用户终端的相关信息,则 HSS 可以获取该用户终端在 Non-3GPP网络中激活的 APN及 APN约束信息, 并将这些信息通 过位置更新确认消息反馈至 MME。
405、 MME向服务网关(SGW, Serving Gateway)发送建立缺省承载请求消息 Create Default Bearer Request;
本实施例中, MME获取到用户终端在 Non-3GPP网络中激活的 APN及 APN约束信 息之后, 即可根据这些信息计算最大 APN约束, 具体的计算过程为本领域技术人员的公知 常识, 此处不做限定。
MME计算得到最大 APN约束之后, 即可将该最大 APN约束以及 APN携带于建立缺 省承载请求消息中发送至 SGW, 以请求 SGW将该最大 APN约束以及 APN转发至 PGW。
406、 SGW向 PGW发送建立缺省承载请求消息 Create Default Bearer Request;
需要说明的是, 如果 SGW与 PGW之间使用 PMIP协议进行信令交互, 该消息为代理 绑定更新 Proxy Binding Update消息。
本实施例中, SGW向 PGW发送的消息中携带有 MME计算得到的最大 APN约束以 及 APN。
407、 PGW向 SGW发送建立缺省承载响应消息 Create Default Bearer Response;
需要说明的是, 如果 SGW与 PGW之间使用 PMIP协议进行信令交互, 该消息为代理 绑定确认 Proxy Binding Ack消息。
PGW接收到 SGW发送的消息之后, 从该消息中读取最大 APN约束以及 APN, 并根 据最大 APN约束判断是否允许该 APN接入, 如果允许, 则在发给 SGW的消息中携带允许 接入信息, 如果不允许, 则在发给 SGW的消息中携带拒绝信息。
408、 SGW向 MME发送建立缺省承载响应消息;
409、 MME向用户终端发送附着接受消息 Attach Accept;
410、 用户终端向 MME发送附着完成消息 Attach Complete;
411、 MME更新 SGW上的承载信息, SGW更新 PGW上的承载信息;
412、 MME向 HSS发送通知请求消息 Notify Request;
本实施例中,若 MME从 SGW接收到的消息中携带有允许接入信息,则 MME向 HSS 发送的通知请求消息中携带有 APN,或者还可以进一步携带 APN约束信息,若 MME从 SGW 接收到的消息中携带有拒绝信息, 则 MME直接向用户终端反馈该携带原因值的拒绝信息, 并结束流程。
本实施例中, HSS接收到 MME发送的通知请求消息之后, 根据该消息对 HSS 内的 APN以及 APN约束信息进行更新, 并将更新后的 APN以及 APN约束信息通过用户信息更 新请求发送至 3GPP AAA Server
需要说明的是, 本实施例中, MME将请求消息发送至 HSS之后, HSS可以检查 HSS 中保存的 MME标识与请求消息中的 MME标识是否匹配, 如果匹配, 则执行数据更新的操 作。
413、 HSS向 MME发送通知响应消息 Notify Response 0 本实施例中, 3GPP AAA Server接收到 HSS发送的 APN以及 APN约束信息之后, 还 可以通过插入签约数据消息 Insert Subscriber Data将 APN以及 APN约束信息发送至接入网 关,本实施例中的接入网关可以为演进分组数据网关( ePDG, Evolved Packet Data Gateway ), 或者是可信非 3GPP互联网协议接入节点 ( Trusted Non-3GPP IP Access ) 。
3GPP AAA Server接收到 HSS发送的 APN以及 APN约束信息之后, Non-3GPP网络 即可根据该 APN约束信息计算最大 APN约束, 并利用该最大 APN约束对用户终端在非 3GPP网络中请求接入的新的 APN进行校验, 本实施例中, MME通过 HSS将 APN约束信 息更新到 3GPP AAA Server,因此能够实现同一个用户终端的不同接入网中使用相同的最大 APN约束进行 APN接入控制, 从而提高了网络安全性。
二、 用户终端已接入 3GPP网络, 又发起 Non-3GPP网络接入的方案:
本实施例中的汇聚网元为 HSS, 第一网元为 AAA Server, 第二网元为接入节点, 数据 网关为 PGW。
本实施例中的 AAA Server在实际应用中具体可以为 3GPP AAA Server。
本实施例中的接入节点以 MME为例进行说明, 可以理解的是, 在实际应用中, 接入 节点还可以为 SGSN, 或者是其他网元, 此处不做限定。
本实施例中的接入网关可以为 ePDG, 或者是 Trusted Non-3GPP IP Access。
请参阅图 5, 本发明实施例中信息同步方法另一实施例包括:
501、 用户终端接入到 3GPP网络;
502、 Non-3GPP执行接入相关的 L2流程;
503、 用户终端与网络之间互相进行认证;
本实施例中,接入网关在用户终端与网络进行认证的过程中从 HSS获得用户终端的信 息, 其中包含用户终端在 3GPP网络中激活的 APN及 APN约束信息。
接入网关根据用户终端在 3GPP网络中激活的 APN及 APN约束信息计算最大 APN约 束, 具体的, 具体的计算过程为本领域技术人员的公知常识, 此处不做限定。
504、 用户终端发起多接入, 向接入网关发起附着请求;
本实施例中,如果用户终端发起的附着请求中没有携带 APN信息,则接入网关会为用 户终端选择缺省的 APN。
505、 网关控制会话建立流程;
506、 接入网关向 PGW发送代理绑定更新消息 Proxy Binding Update;
本实施例中,接入网关计算得到最大 APN约束之后,即可将该最大 APN约束以及 APN 携带于代理绑定更新消息中发送至 PGW。
507、 PGW发起与策略控制计费规则功能实体(PCRF, Policy Control and Charging Rules Function) 的 IP-Can Session建立流程;
508、 PGW向 HSS发送更新 PGW地址请求消息 Update PGW Address Request;
本实施例中, PGW从接入网关发送的消息中读取最大 APN约束以及 APN, 并根据最 大 APN约束判断是否允许该 APN接入, 如果允许接入, 则通知 3GPP AAA Server, 从而 3GPP AAA Server将 APN以及 APN约束信息发送至 HSS, HSS对 HSS内的 APN以及 APN 约束信息进行更新, 并将更新后的 APN以及 APN约束信息发送至 MME。
需要说明的是,本实施例中, 3GPP AAA Server将 APN以及 APN约束信息发送至 HSS 之后, HSS可以检查 HSS中保存的 3GPP AAA Server标识与请求消息中的 3GPP AAA Server 标识是否匹配, 如果匹配, 则执行数据更新的操作。
本实施例中, 3GPP AAA Server可以通过非 3GPP互联网协议接入注册请求 (Non-3GPP IP Access Registration Request) 消息将 APN以及 APN约束信息发送至 HSS。
HSS可以通过插入签约数据 (Insert Subscriber Data) 消息将更新后的 APN以及 APN 约束信息发送至 MME。
509、 HSS向 PGW发送更新 PGW地址响应 Update PGW Address Response消息;
510、 PGW向接入网关发送代理绑定确认消息 Proxy Binding Update Ack;
本实施例中, 若 PGW确定允许 APN接入, PGW会通过代理绑定确认消息向接入网 关发送 APN Restriction信息, 接入网关会保存 APN和 APN Restriction信息, 从而计算得到 最大 APN约束。
若 PGW确定不允许 APN接入, 则 PGW通知接入网关拒绝信息, 并携带原因值。
511、 PGW与接入网关之间的 PMIP隧道建立;
512、 PCRF可能发起的网关控制的会话修改流程更新 AGW中的 QoS信息;
513、 L3附着完成。
若 PGW确定不允许 APN接入, 则在该步骤中, 接入网关将携带原因值的拒绝信息发 送至用户终端。
MME根据 HSS发送的 APN约束信息计算最大 APN约束,并将最大 APN约束发送至 PGW, 则 PGW可以利用该最大 APN约束对用户终端在 3GPP网络中请求接入的新的 APN 进行校验, 本实施例中, 3GPP AAA Server通过 HSS将 APN约束信息更新到 MME, 从而 实现了不同接入网络 (3GPP网络和 Non-3GPP网络) 使用相同的 APN Restriction信息得到 Max APN Restriction值, 对用户请求的 APN进行接入校验, 因此提高了网络安全性。
三、用户终端同时接入 3GPP网络和 Non-3GPP网络,用户终端在 3GPP网络删除 PDN 连接的方案:
本实施例中, 汇聚网元为 HSS, 第一网元为接入节点, 第二网元为 AAA Server 本实施例中的 AAA Server在实际应用中具体可以为 3GPP AAA Server。
本实施例中的接入节点以 MME为例进行说明, 可以理解的是, 在实际应用中, 接入 节点还可以为 SGSN, 或者是其他网元, 此处不做限定。
请参阅图 6, 本发明实施例中信息同步方法另一实施例包括:
601、 用户终端接入到 Non-3GPP网络;
602、 用户终端向 MME发送删除 PDN连接请求消息;
603、 MME向 SGW发送删除 PDN连接请求消息, SGW向 PGW发送删除 PDN连接 请求消息, PGW向 SGW发送删除 PDN连接响应消息, SGW向 MME发送删除 PDN连接 响应消息;
604、 MME向演进通用移动通信系统陆地无线接入网 (E-UTRAN, Evolved Universal mobile telecommunications system Territorial Radio Access Network)发送去激活承载请求消 息;
605、更新用户终端与 E-UTRAN之间的无线资源控制(RRC, Radio Resource Control) 连接;
606、 E-UTRAN向 MME发送去激活承载响应消息;
607、 MME向 HSS发送通知请求消息 Notify Request;
本实施例中, MME向 HSS发送的通知请求消息中携带有 APN。
需要说明的是, 本实施例中, PDN连接删除时 MME并不一定会向 HSS发送 Notify
Request消息, 当被删除的 PDN连接对应的 APN还有激活的 PDN连接时, 无论该激活的
PDN连接与被删除的 PDN连接是否在相同的接入网, MME均不会发送该消息, 而可以采 用其他的请求消息携带 APN。
需要说明的是, 本实施例中, MME将请求消息发送至 HSS之后, HSS可以检查 HSS 中保存的 MME标识与请求消息中的 MME标识是否匹配, 如果匹配, 则执行数据更新的操 作。
608、 HSS向 MME发送通知响应消息 Notify Response。
HSS接收到 MME发送的通知请求消息之后,从中读取出 APN,删除 HSS内的该 APN 对应的 APN约束信息, 之后将本地更新后的 APN以及 APN约束信息通过用户信息更新请 求发送至 3GPP AAA Server,则 Non-3GPP网络根据 HSS发送的 APN约束信息计算最大 APN 约束, 并利用最大 APN约束对用户终端在非 3GPP网络中请求接入的新的 APN进行校验, 本实施例中, MME通过 HSS将 APN约束信息更新到 3GPP AAA Server, 从而实现了不同 接入网络 (3GPP网络和 Non-3GPP网络) 使用相同的 APN Restriction信息得到 Max APN Restriction值, 对用户请求的 APN进行接入校验, 因此提高了网络安全性。
四、 用户终端同时接入 3GPP网络和 Non-3GPP网络, 用户终端在 Non-3GPP网络删 除 PDN连接的方案:
本实施例中, 汇聚网元为 HSS, 第一网元为 AAA Server, 第二网元为接入节点。 本实施例中的 AAA Server在实际应用中具体可以为 3GPP AAA Server。
本实施例中的接入节点以 MME为例进行说明, 可以理解的是, 在实际应用中, 接入 节点还可以为 SGSN, 或者是其他网元, 此处不做限定。
请参阅图 7, 本发明实施例中信息同步方法另一实施例包括:
701、 用户终端在 3GPP网络接入;
702、 用户终端向接入网关发送删除 PDN连接请求消息;
703、 接入网关向 PGW发送代理绑定更新消息 Proxy Binding Update;
704、 PGW向 3GPP AAA Server发送更新 PGW地址请求消息 Update PGW Address Request;
本实施例中, 3GPP AAA Server接收到该请求消息之后, 即可以将 APN发送至 HSS, HSS删除 HSS内的该 APN对应的 APN约束信息, 之后将本地更新后的 APN以及 APN约 束信息发送至 MME。
需要说明的是, 本实施例中, 3GPP AAA Server将 APN发送至 HSS之后, HSS可以 检查 HSS中保存的 3GPP AAA Server标识与请求消息中的 3GPP AAA Server标识是否匹配, 如果匹配, 则执行数据更新的操作。
本实施例中, 3GPP AAA Server可以通过非 3GPP互联网协议接入注册请求 (Non-3GPP
IP Access Registration Request) 消息将 APN发送至 HSS。
HSS可以通过插入签约数据 (Insert Subscriber Data) 消息将更新后的 APN以及 APN 约束信息发送至 MME。
705、 3GPP AAA Server向 PGW发送更新 PGW地址响应消息 Update PGW Address Response; 706、 PGW向 AGW发送代理绑定确认消息 Proxy Binding Ack。
707、 相关的资源释放流程。
MME根据 HSS发送的 APN约束信息计算最大 APN约束,并将最大 APN约束发送至 PGW,则 PGW利用最大 APN约束对用户终端在 3GPP网络中请求接入的新的 APN进行校 验, 本实施例中, 3GPP AAA Server通过 HSS将 APN约束信息更新到 MME, 从而实现了 不同接入网络( 3GPP网络和 Non-3GPP网络 M吏用相同的 APN Restriction信息得到 Max APN Restriction值, 对用户请求的 APN进行接入校验, 因此提高了网络安全性。
上面介绍了汇聚网元根据请求消息对汇聚网元内的 APN约束信息进行更新,并将更新 后的 APN约束信息发送至第二网元的方案, 在实际应用中, 汇聚网元同样还可以直接将第 一网元发送的请求消息转发至第二网元, 由第二网元根据该请求消息更新第二网元内的 APN约束信息,具体请参阅图 8,本发明实施例中信息同步方法另一实施例应用于多接入技 术, 具体包括:
801、 汇聚网元接收第一网元发送的请求消息;
本实施例中, 第一网元向汇聚网元发送的请求消息中携带有 APN, 在实际应用中, 该 请求消息中还可以进一步携带 APN约束信息。
802、 汇聚网元将第二请求消息发送至第二网元;
本实施例中, 汇聚网元在接收到第一网元发送的请求消息之后, 可以向第二网元发送 第二请求消息, 该第二请求消息中的 APN与第一网元发送的请求消息中的 APN相同。
803、 第二网元根据第二请求消息更新第二网元内的 APN约束信息。
本实施例中, 具体第二网元进行更新的方式可以为:
若第二请求消息中未携带 APN约束信息, 则第二网元对第二请求消息中的 APN对应 的第二网元内的 APN约束信息进行删除;
若第二请求消息中携带 APN约束信息, 则第二网元保存第二请求消息中携带的 APN 约束信息;
若第二请求消息中携带删除信息指示,则第二网元对第二请求消息中的 APN对应的第 二网元内的 APN约束信息进行删除;
若第二请求消息中携带增加信息指示,则第二网元保存第二请求消息中携带的 APN约 束信息。
需要说明的是, 本实施例中的汇聚网元, 第一网元, 第二网元具体所指代的网络实体 与前述实施例中的描述一致,且第一网元向汇聚网元发送请求消息的流程,汇聚网元向第二 网元转发请求消息的流程也与前述实施例中的描述一致, 此处不再赘述。
本实施例中, 汇聚网元在从第一网元接收到请求消息之后, 将第二请求消息发送至第 二网元, 使得第二网元可以根据该第二请求消息对第二网元内的 APN约束信息进行更新, 从而实现了不同接入网络使用相同的 APN Restriction信息得到 Max APN Restriction值, 对 用户请求的 APN进行接入校验, 因此提高了网络安全性。
下面对本发明实施例中的通讯系统实施例进行描述, 请参阅图 9, 本发明实施例中的 通讯系统一个实施例应用于多接入技术, 具体包括:
第一网元 901, 汇聚网元 902以及第二网元 903;
所述第一网元 901 用于向所述汇聚网元 902发送请求消息, 所述请求消息中携带有
APN;
所述汇聚网元 902用于接收第一网元 901发送的请求消息, 根据所述请求消息对汇聚 网元内的 APN约束信息进行更新, 将更新后的 APN约束信息发送至第二网元 903;
所述第二网元 903用于接收所述汇聚网元 902发送的 APN约束信息;
所述第二网元 903至少为一个, 所述第二网元 903与所述第一网元 901分别属于相同 的用户终端接入的不同接入网。
本实施例中的汇聚网元 902还可以根据请求消息对汇聚网元 902内的 APN同时进行更 新, 则也可以将更新后的 APN—并发送至第二网元 903。
请参阅图 10, 本发明实施例中的通讯系统另一实施例应用于多接入技术, 具体包括: 第一网元 1001, 汇聚网元 1002以及第二网元 1003;
所述第一网元 1001用于向所述汇聚网元 1002发送请求消息, 所述请求消息中携带有
APN;
所述汇聚网元 1002用于接收第一网元 1001发送的请求消息, 根据所述请求消息对汇 聚网元 1002内的 APN以及 APN约束信息进行更新,将更新后的 APN以及 APN约束信息 发送至第二网元 1003;
所述第二网元 1003用于接收所述汇聚网元 1002发送的 APN以及 APN约束信息; 所述第二网元 1003至少为一个,所述第二网元 1003与所述第一网元 1001分别属于相 同的用户终端接入的不同接入网。
本实施例中的第一网元 1001还用于获取用户终端激活的 APN约束信息, 根据所述用 户终端激活的 APN约束信息计算最大 APN约束;
本实施例中的通讯系统还包括: 数据网关 1004,用于接收第一网元 1001计算得到的最大 APN约束以及 APN,若根据 所述最大 APN约束确定 APN允许接入, 则触发所述第一网元 1001 向所述汇聚网元 1002 发送包含 APN以及 APN约束信息的请求消息,若根据所述最大 APN约束确定 APN不允许 接入, 则向所述第一网元 1001发送包含原因值的拒绝消息。
本实施例中的汇聚网元 1002为 HSS, 第一网元 1001为接入节点, 第二网元 1003为 3GPP AAA Server, 数据网关 1004为 PGW;
或,
汇聚网元 1002为 HSS,第一网元 1001为 3GPP AAA Server,第二网元 1003为接入节 点, 数据网关 1004为 PGW。
本实施例中的接入节点为 MME或 SGSN, 本实施例中的接入网关为演进分组数据网 关或可信非 3GPP互联网协议接入节点。
为便于理解, 下面以一具体应用场景对本发明实施例中的通讯系统进行说明: 第一网元 1001获取用户终端激活的 APN约束信息;
本实施例中, 第一网元 1001可以从汇聚网元 1002或其他网元中获取到用户终端在某 网络中激活的 APN约束信息。
第一网元 1001获取到用户终端激活的 APN约束信息之后,即可计算得到最大 APN约 束, 具体的计算过程为本领域技术人员的公知常识, 此处不做限定。
第一网元 1001计算得到最大 APN约束之后, 即可将该最大 APN约束以及 APN发送 至数据网关 1004。
数据网关 1004在接收到第一网元 1001发送的最大 APN约束以及 APN之后, 即可根 据最大 APN约束判断 APN是否允许接入,若允许,则向第一网元 1001发送允许接入消息, 若不允许,则向第一网元 1001发送包含原因值的拒绝消息, 以便于第一网元 1001向用户终 端反馈该原因值。
本实施例中, 当第一网元 1001从数据网关 1004接收到允许接入消息时, 即可向汇聚 网元 1002发送请求消息,该请求消息中携带有 APN,具体可以是用户终端请求接入的 APN, 或者是用户终端请求删除的 APN。
汇聚网 1002元从第一网元 1001接收到请求消息之后, 即可根据该请求消息的内容对 汇聚网元 1002内的 APN以及 APN约束信息进行更新。
具体的更新过程与前述方法实施例中描述的更新过程一致, 此处不再赘述。
汇聚网元 1002对本地的 APN以及 APN约束信息进行更新之后,即可将更新后的 APN 以及 APN约束信息发送至第二网元 1003。
本实施例中,汇聚网元 1002在获取到第一网元 1001发送的携带有 APN的请求消息之 后, 可以根据该请求消息对汇聚网元 1002内的 APN以及 APN约束信息进行更新, 同时能 够查询到该用户终端接入的其他接入网的第二网元 1003, 并将更新后的 APN以及 APN约 束信息发送至第二网元 1003, 使得不同接入网使用相同的 APN约束信息得到最大 APN约 束对 APN的接入进行控制, 从而提高了网络安全性。
本发明实施例中通讯系统另一实施例应用于多接入技术, 具体同样请参阅图 9, 本实 施例中的通讯系统包括:
第一网元 901, 汇聚网元 902以及第二网元 903;
第一网元 901用于向汇聚网元 902发送请求消息, 请求消息中携带有 APN;
汇聚网元 902用于向第二网元 903发送第二请求消息,该第二请求消息中的 APN与第 一网元 901发送的请求消息中的 APN相同;
第二网元 903用于接收汇聚网元 902发送的第二请求消息, 根据第二请求消息对第二 网元 903内的 APN约束信息进行更新。
本实施例中, 汇聚网元 902在从第一网元 901接收到请求消息之后, 将第二请求消息 发送至第二网元 903,使得第二网元 903可以根据该第二请求消息对第二网元 903内的 APN 约束信息进行更新, 从而实现了不同接入网络使用相同的 APN Restriction信息得到 Max APN Restriction值, 对用户请求的 APN进行接入校验, 因此提高了网络安全性。
下面对本发明实施例中的汇聚网元进行描述, 请参阅图 11, 本发明实施例中的汇聚网 元应用于多接入技术, 具体包括- 接收单元 1101, 用于接收第一网元发送的请求消息, 所述请求消息中携带有 APN; 更新单元 1102,用于根据接收单元 1101接收到的请求消息对汇聚网元内的 APN约束 信息进行更新;
发送单元 1103, 用于将更新单元 1102更新后的 APN约束信息发送至第二网元, 所述 第二网元至少为一个,所述第二网元与所述第一网元分别属于相同的用户终端接入的不同接 入网。
本实施例中的更新单元 1102还可以根据请求消息对汇聚网元内的 APN同时进行更新, 则发送单元 1103也可以将更新后的 APN—并发送至第二网元。
本实施例中的汇聚网元各单元具体所执行的功能与前述方法实施例中描述的汇聚网元 的功能一致, 此处不再赘述。 本实施例中, 接收单元 1101在获取到第一网元发送的携带有 APN的请求消息之后, 更新单元 1102可以根据该请求消息对汇聚网元内的 APN以及 APN约束信息进行更新,发 送单元 1103可以将更新后的 APN以及 APN约束信息发送至第二网元, 使得不同接入网使 用相同的 APN约束信息得到最大 APN约束对 APN的接入进行控制, 从而提高了网络安全 性。
请参阅图 12, 本发明实施例中的汇聚网元另一实施例应用于多接入技术, 具体包括: 第二接收单元 1201,用于接收第一网元发送的请求消息,所述请求消息中携带有 APN; 转发单元 1202, 用于向第二网元发送第二请求消息, 以便于所述第二网元根据该第二 请求消息更新第二网元内的 APN约束信息;
第二请求消息中的 APN与第一网元发送的请求消息中的 APN相同。
本实施例中, 第二接收单元 1201在获取到第一网元发送的携带有 APN的请求消息之 后, 转发单元 1202可以将第二请求消息发送至第二网元, 以便于第二网元根据第二请求消 息更新第二网元内的 APN约束信息, 因此本发明实施例能够实现不同接入网使用相同的 APN约束信息得到最大 APN约束对 APN的接入进行控制, 从而提高了网络安全性。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分步骤是可以通过程 序来指令相关的硬件完成,所述的程序可以存储于一种计算机可读存储介质中,上述提到的 存储介质可以是只读存储器, 磁盘或光盘等。
以上对本发明所提供的一种信息同步方法及通讯系统以及相关设备进行了详细介绍, 对于本领域的一般技术人员,依据本发明实施例的思想,在具体实施方式及应用范围上均会 有改变之处, 综上所述, 本说明书内容不应理解为对本发明的限制。

Claims

权利要求
1、 一种信息同步方法, 应用于多接入技术, 其特征在于, 包括- 汇聚网元接收第一网元发送的请求消息, 所述请求消息中携带有接入点名称 APN; 汇聚网元根据所述请求消息对汇聚网元内的 APN约束信息进行更新;
汇聚网元将更新后的 APN约束信息发送至第二网元。
2、 根据权利要求 1所述的方法, 其特征在于, 所述汇聚网元接收第一网元发送的请 求消息之前包括:
第一网元获取用户终端激活的 APN以及 APN约束信息;
第一网元根据所述用户终端激活的 APN以及 APN约束信息计算最大 APN约束, 并将 所述最大 APN约束以及用户终端发送的 APN发送至数据网关;
若数据网关根据所述最大 APN约束确定所述用户终端发送的 APN允许接入, 则触发 所述第一网元向所述汇聚网元发送包含所述用户终端发送的 APN的请求消息。
3、 根据权利要求 2所述的方法, 其特征在于,
若数据网关根据所述最大 APN约束确定所述用户终端发送的 APN不允许接入, 则所 述数据网关向所述第一网元发送包含原因值的拒绝消息;
所述第一网元向用户终端反馈所述原因值。
4、 根据权利要求 1所述的方法, 其特征在于, 所述汇聚网元根据所述请求消息对汇 聚网元内的 APN约束信息进行更新包括:
若所述请求消息中未携带 APN约束信息, 则汇聚网元对所述请求消息中的 APN对应 的汇聚网元内的 APN约束信息进行删除;
或者,
若所述请求消息中携带 APN约束信息, 则汇聚网元保存所述 APN约束信息; 或者,
若所述请求消息中携带删除信息指示, 则汇聚网元对所述请求消息中的 APN对应的 汇聚网元内的 APN约束信息进行删除;
或者,
若所述请求消息中携带增加信息指示, 则汇聚网元保存所述请求消息中携带的 APN 约束信息。
5、 根据权利要求 1所述的方法, 其特征在于, 所述汇聚网元接收第一网元发送的请 求消息之后包括:
汇聚网元判断发送所述请求消息的第一网元的标识与汇聚网元中保存的第一网元的 标识是否匹配, 若匹配, 则触发根据请求消息对汇聚网元内的 APN约束信息进行更新的 步骤。
6、 根据权利要求 1至 5中任一项所述的方法, 其特征在于,
所述汇聚网元为归属用户服务器 HSS,所述第一网元为接入节点,所述第二网元为鉴 权 -计费 -授权服务器 AAA Server;
所述方法包括:
HSS接收接入节点发送的请求消息, 所述请求消息中携带有 APN以及 APN约束信息; HSS根据所述请求消息对 HSS内的 APN约束信息进行更新;
HSS将所述更新后的 APN约束信息发送至 AAA Server。
7、 根据权利要求 1至 5中任一项所述的方法, 其特征在于,
所述汇聚网元为 HSS, 所述第一网元为 AAA Server, 所述第二网元为接入节点; 所述方法包括:
HSS接收 AAA Server发送的请求消息, 所述请求消息中携带有 APN以及 APN约束信 息;
HSS根据所述请求消息对 HSS内的 APN约束信息进行更新;
HSS将所述更新后的 APN约束信息发送至接入节点。
8、 根据权利要求 1至 5中任一项所述的方法, 其特征在于,
所述汇聚网元为 HSS, 所述第一网元为接入节点, 所述第二网元为 AAA Server; 所述方法包括:
HSS接收接入节点发送的请求消息, 所述请求消息中携带有 APN;
HSS根据所述请求消息对 HSS内的 APN约束信息进行更新;
HSS将更新后的 APN约束信息发送至 AAA Server。
9、 根据权利要求 1至 5中任一项所述的方法, 其特征在于,
所述汇聚网元为 HSS, 所述第一网元为 AAA Server, 所述第二网元为接入节点; HSS接收 AAA Server发送的请求消息, 所述请求消息中携带有 APN;
HSS根据所述请求消息对 HSS内的 APN约束信息进行更新;
HSS将所述更新后的 APN约束信息发送至接入节点。
10、 根据权利要求 6所述的方法, 其特征在于, 所述 HSS将所述更新后的 APN约束 信息发送至 AAA Server之后包括:
AAA Server将所述更新后的 APN约束信息发送至接入网关;
所述接入网关为演进分组数据网关或可信非 3GPP互联网协议接入节点。
11、 根据权利要求 8所述的方法, 其特征在于, 所述 HSS将所述更新后的 APN约束 信息发送至 AAA Server之后包括:
AAA Server将所述更新后的 APN约束信息发送至接入网关;
所述接入网关为演进分组数据网关或可信非 3GPP互联网协议接入节点。
12、 一种信息同步方法, 应用于多接入技术, 其特征在于, 包括- 汇聚网元接收第一网元发送的请求消息, 所述请求消息中携带有接入点名称 APN; 汇聚网元将第二请求消息发送至第二网元, 以便于所述第二网元根据所述第二请求 消息更新第二网元内的 APN约束信息;
所述第二请求消息中的 APN与所述请求消息中的 APN相同。
13、 根据权利要求 12所述的方法, 其特征在于, 所述汇聚网元接收第一网元发送的 请求消息之后包括:
汇聚网元判断发送所述请求消息的第一网元的标识与汇聚网元中保存的第一网元的 标识是否匹配, 若匹配, 则触发汇聚网元将第二请求消息发送至第二网元的步骤。
14、 根据权利要求 12所述的方法, 其特征在于, 所述汇聚网元接收第一网元发送的 请求消息之前包括:
第一网元获取用户终端激活的 APN以及 APN约束信息;
第一网元根据所述用户终端激活的 APN以及 APN约束信息计算最大 APN约束, 并将 所述最大 APN约束以及用户终端发送的 APN发送至数据网关;
若数据网关根据所述最大 APN约束确定所述用户终端发送的 APN允许接入, 则触发 所述第一网元向所述汇聚网元发送包含所述用户终端发送的 APN的请求消息。
15、 根据权利要求 14所述的方法, 其特征在于,
若数据网关根据所述最大 APN约束确定所述用户终端发送的 APN不允许接入, 则所 述数据网关向所述第一网元发送包含原因值的拒绝消息;
所述第一网元向用户终端反馈所述原因值。
16、 根据权利要求 12至 15中任一项所述的方法, 其特征在于, 所述方法还包括: 若所述第二请求消息中未携带 APN约束信息, 则第二网元对所述第二请求消息中的
APN对应的第二网元内的 APN约束信息进行删除;
或者,
若所述第二请求消息中携带 APN约束信息, 则第二网元保存所述 APN约束信息; 或者,
若所述第二请求消息中携带删除信息指示,则第二网元对所述第二请求消息中的 APN 对应的第二网元内的 APN约束信息进行删除;
或者,
若所述第二请求消息中携带增加信息指示, 则第二网元保存所述第二请求消息中携 带的 APN约束信息。
17、 一种通讯系统, 应用于多接入技术, 其特征在于, 包括:
第一网元, 用于发送请求消息, 所述请求消息中携带有 APN;
汇聚网元, 用于接收第一网元发送的请求消息, 根据所述请求消息对汇聚网元内的 APN约束信息进行更新, 发送更新后的 APN约束信息;
第二网元, 用于接收所述汇聚网元发送的 APN约束信息。
18、 根据权利要求 17所述的通讯系统, 其特征在于, 所述汇聚网元为 HSS, 所述第 一网元为接入节点, 所述第二网元为 AAA Server;
或,
所述汇聚网元为 HSS, 所述第一网元为 AAA Server, 所述第二网元为接入节点。
19、 根据权利要求 18所述的通讯系统, 其特征在于, 所述接入节点为 MME或 SGSN。
20、 一种通讯系统, 应用于多接入技术, 其特征在于, 包括:
第一网元, 用于发送请求消息, 所述请求消息中携带有 APN;
汇聚网元, 用于接收第一网元发送的请求消息, 向第二网元发送第二请求消息, 所 述第二请求消息中的 APN与所述请求消息中的 APN相同;
第二网元, 用于接收所述汇聚网元发送的第二请求消息, 根据所述第二请求消息对 第二网元内的 APN约束信息进行更新。
21、 一种汇聚网元, 应用于多接入技术, 其特征在于, 包括:
接收单元, 用于接收第一网元发送的请求消息, 所述请求消息中携带有 APN;
更新单元, 用于根据所述请求消息对汇聚网元内的 APN约束信息进行更新; 发送单元, 用于将更新后的 APN约束信息发送至第二网元。
22、 一种汇聚网元, 应用于多接入技术, 其特征在于, 包括:
第二接收单元, 用于接收第一网元发送的请求消息, 所述请求消息中携带有 APN; 转发单元, 用于向第二网元发送第二请求消息, 以便于所述第二网元根据所述第二 请求消息更新第二网元内的 APN约束信息;
所述第二请求消息中的 APN与所述请求消息中的 APN相同。
PCT/CN2010/073593 2009-06-05 2010-06-07 一种信息同步方法及通讯系统以及相关设备 WO2010139285A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2009101469754A CN101909275B (zh) 2009-06-05 2009-06-05 一种信息同步方法及通讯系统以及相关设备
CN200910146975.4 2009-06-05

Publications (1)

Publication Number Publication Date
WO2010139285A1 true WO2010139285A1 (zh) 2010-12-09

Family

ID=43264563

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/073593 WO2010139285A1 (zh) 2009-06-05 2010-06-07 一种信息同步方法及通讯系统以及相关设备

Country Status (2)

Country Link
CN (1) CN101909275B (zh)
WO (1) WO2010139285A1 (zh)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103024876B (zh) * 2011-09-27 2016-02-03 华为技术有限公司 接入控制方法、网关及系统
WO2012149793A1 (zh) * 2011-09-30 2012-11-08 华为技术有限公司 多接入场景下执行分组数据网连接的方法
US10033769B2 (en) * 2013-09-27 2018-07-24 Telefonaktiebolaget Lm Ericsson (Publ) Lawful interception in a WI-FI/packet core network access
WO2016155011A1 (zh) * 2015-04-03 2016-10-06 华为技术有限公司 一种分组数据网关的选择方法、相关装置及系统
CN105959274B (zh) * 2016-04-26 2020-01-10 华为技术有限公司 通信方法和通信方法中使用的网元
WO2018058691A1 (zh) * 2016-09-30 2018-04-05 华为技术有限公司 一种建立公用数据网连接的方法及相关设备
CN110399573A (zh) * 2018-04-16 2019-11-01 中国移动通信有限公司研究院 一种信息处理方法、装置、设备及计算机可读存储介质

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007039432A1 (en) * 2005-09-20 2007-04-12 Telefonaktiebolaget Lm Ericsson (Publ) Implicit secondary pdp context activation method
WO2009056938A2 (en) * 2007-10-29 2009-05-07 Nokia Corporation System and method for authenticating a context transfer

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007039432A1 (en) * 2005-09-20 2007-04-12 Telefonaktiebolaget Lm Ericsson (Publ) Implicit secondary pdp context activation method
WO2009056938A2 (en) * 2007-10-29 2009-05-07 Nokia Corporation System and method for authenticating a context transfer

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
"3 GPP, 3r Generation Partnership Project; Technical Specification Group Services and System Aspects; General Packet Radio Service (GPRS); Service description; Stage 2 (Release 9)", 3GPP TS 23.060 V9.0.0, March 2009 (2009-03-01), pages 174, 177 - 175, 178 *

Also Published As

Publication number Publication date
CN101909275B (zh) 2012-07-04
CN101909275A (zh) 2010-12-08

Similar Documents

Publication Publication Date Title
US11606734B2 (en) Handover method in wireless communication system and apparatus therefor
ES2927540T3 (es) Control de brecha de servicio para un dispositivo inalámbrico
JP5793812B2 (ja) データオフロードをトリガするための方法、ネットワーク側デバイス、ユーザ機器、およびネットワークシステム
WO2014056445A1 (zh) 一种路由转发的方法、系统及控制器
WO2009094916A1 (fr) Procédé, système et dispositif de commande pour redémarrage après défaillance dans le domaine circuit
WO2011000315A1 (zh) 群组管理方法、网络设备和网络系统
US9113436B2 (en) Method and system for information transmission
WO2009149642A1 (zh) 分组数据网络的接入控制方法和系统、pcrf实体
WO2009036690A1 (fr) Procédé, système et dispositif pour accueillir l'adressage de l'adresse ip statique d'utilisateur dans un système d'évolution à long terme
WO2010121511A1 (zh) 多网接入控制方法、通讯系统以及相关设备
WO2011095100A1 (zh) 一种对本地ip连接的建立进行控制的方法和系统
WO2013063783A1 (zh) 一种数据安全通道的处理方法及设备
WO2013189217A1 (zh) 分组网关标识信息的更新方法、aaa服务器和分组网关
WO2011140884A1 (zh) Mtc组选择分组数据网网关的方法及移动性管理网元
WO2012094957A1 (zh) 一种对mtc终端进行移动性管理的方法和系统
WO2013016968A1 (zh) 一种接入方法、系统及移动智能接入点
WO2010139285A1 (zh) 一种信息同步方法及通讯系统以及相关设备
WO2013017098A1 (zh) 将用户设备接入演进的分组核心网络的方法、设备和系统
WO2009117879A1 (zh) 一种指示服务网关承载管理的方法
WO2011015140A1 (zh) 一种移动通信寻呼方法、系统及装置
WO2012126302A1 (zh) 一种支持双模双待终端同时通信的方法和系统
WO2011054149A1 (zh) 负载控制方法和设备及通信系统
US9629179B2 (en) Method and device for processing local access connection
JP6191768B2 (ja) 移動無線通信装置からのデータ転送
WO2011017979A1 (zh) 支持ip分流的通信系统中资源管理方法与装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10782989

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10782989

Country of ref document: EP

Kind code of ref document: A1