WO2011023070A1 - Dsn认证信息请求、存储方法、sn-c节点及系统 - Google Patents

Dsn认证信息请求、存储方法、sn-c节点及系统 Download PDF

Info

Publication number
WO2011023070A1
WO2011023070A1 PCT/CN2010/076042 CN2010076042W WO2011023070A1 WO 2011023070 A1 WO2011023070 A1 WO 2011023070A1 CN 2010076042 W CN2010076042 W CN 2010076042W WO 2011023070 A1 WO2011023070 A1 WO 2011023070A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication information
node
user
authentication
dsn
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2010/076042
Other languages
English (en)
French (fr)
Inventor
齐旻鹏
朱红儒
吴琦
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Original Assignee
China Mobile Communications Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Corp filed Critical China Mobile Communications Corp
Priority to US13/392,983 priority Critical patent/US8763083B2/en
Publication of WO2011023070A1 publication Critical patent/WO2011023070A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/12Shortest path evaluation

Definitions

  • the present invention relates to a DSN (Distributed Service Network) technology, and in particular, to a DSN authentication information request, storage method, SN-C node, and DSN authentication system.
  • DSN Distributed Service Network
  • the single-key authentication mechanism in the communication network is mainly based on AKA (authentication and key agreement) authentication, and the user and the corresponding home server HLR (Home Location Register, The home location server (HSS) stores the pre-shared key K; the user accesses the VLR (Visitor Location Register) / MME (Mobility Management Entity) Network; VLR/MME detects the user access to the I ILR/IISS application authentication vector; HLR/HSS generates the authentication vector and feeds back to the VLR/MME; VI R/MMH uses the authentication vector to authenticate the user.
  • AKA authentication and key agreement
  • HLR Home Location Register
  • the home location server (HSS) stores the pre-shared key K
  • the user accesses the VLR (Visitor Location Register) / MME (Mobility Management Entity) Network
  • VLR/MME detects the user access to the I ILR/IISS application authentication vector
  • HLR/HSS generates the authentication vector and feeds back
  • the main drawbacks of the prior art ⁇ authentication scheme are: The user can only generate and send the authentication vector by the specific IIIJ IISS at the time of authentication, and the user authentication fails when the HLR/HSS fails.
  • the existing AKA mechanism does not apply to P2P (Peer to Peer) distributed network environments. Summary of the invention
  • a first object of the present invention is to provide a DSN authentication information request method, which reduces the risk of failure to authenticate and operate due to a failure of a single authentication server.
  • a second object of the present invention is to provide a DSN authentication information storage method that reduces the risk of failure to authenticate and operate due to a failure of a single authentication server.
  • a third object of the present invention is to provide a core network control SN-C (Super Node-Core) node, which reduces the risk of failure to authenticate and operate due to a failure of a single authentication server.
  • SN-C Super Node-Core
  • a fourth object of the present invention is to provide a DSN authentication system that reduces the risk of failure to authenticate and operate a single authentication server due to a failure.
  • a DSN authentication information requesting method including: determining, according to a received user access request, whether a local SN-C node stores authentication information of the user; when the local SN-C node saves When the user has the authentication information of the user, the authentication process is directly initiated. When the local SN-C node does not save the authentication information of the user, the authentication information is requested from other SN-C nodes that store the user authentication information.
  • a DSN authentication information storage method including: determining a need according to a maximum delay allowed by a DSN, an average delay generated by a neighboring SN-C node during transmission, and a network load and usage.
  • the maximum number of intervals between two SN-C nodes that store the same user authentication information; the authentication information of the same user is stored on the corresponding SN-C node according to the maximum interval number.
  • an SN-C node including: a receiving module, configured to receive an access request of a user; a storage module, configured to store authentication information of the user, and store the same user authentication information The information of the SN-C node, the determining module, configured to determine, according to the user access request, whether the storage module stores the authentication information of the user, and the authentication module, configured to: when the storage module saves the user When the authentication information is used, the authentication process is directly initiated.
  • the requesting module is configured to request authentication information from other SN-C nodes that store the user authentication information when the local node does not save the authentication information of the user.
  • a DSN authentication system including: a plurality of SN-C nodes configured by a loop, configured to determine, according to a received user access request, whether a local SN-C node stores the user Authentication information; when the local SN-C node holds the user's When the authentication information is used, the authentication process is directly initiated. When the local SN-C node does not save the authentication information of the user, the authentication information is requested from other SN-C nodes that store the user authentication information.
  • the DSN authentication information request, the storage method, the SN-C node and the DSN authentication system of the present invention are distributed and authenticated by the user's authentication information, so that when one of the SN-C nodes fails, the other SN-
  • the C node obtains the authentication information, reduces the interval between the SN-C nodes that store the same authentication information, and ensures that the time required for the authentication process does not exceed the maximum delay allowed by the DSN, reducing the authentication caused by the authentication timeout.
  • the failure situation improves the user experience.
  • FIG. 1 is a flow chart of an embodiment of a DSN authentication information storage method according to the present invention.
  • Embodiment 1 of a DSN authentication information request method according to the present invention
  • Embodiment 3 is a flowchart of Embodiment 2 of a method for requesting DSN authentication information according to the present invention
  • Embodiment 1 of an SN-C node device of the present invention is a structural diagram of Embodiment 1 of an SN-C node device of the present invention.
  • Figure 5 is a second and third structural diagram of the SN-C node device of the present invention.
  • FIG. 6 is a structural diagram of the DSN authentication system of the present invention. detailed description
  • the DSN authentication information storage method embodiment of the present invention includes the following steps: Step 22: Calculate a maximum number of intervals between two SN-C nodes that need to save the same user authentication information.
  • Step 22 calculates a maximum number of intervals between two SN-C nodes that need to save the same user authentication information.
  • the maximum interval n between the DSNs for example, the maximum delay T allowed by the DSN is 200ms, and the average delay t generated by the neighboring SN-C nodes during transmission is 30ms, and the network load and usage are normal, that is, the DSN is single.
  • the user node connects to any SN-C node, it can guarantee that the interval of finding the nearest SN-C holding its authentication information will not exceed (200ms/30ms/2) « the number of 3 nodes.
  • Step 24 Store the authentication information of the user on the corresponding SN-C node according to the maximum interval, until the distance between the SN-C nodes in the entire routing ring that stores the authentication information of the same user is not greater than At the selected interval, for example, as shown in FIG. 6, the same user authentication information is stored on the nodes SN-CB and SN-CH.
  • the authentication information of the user is distributed and stored in the routing ring.
  • the related authentication server includes the user authentication information and the neighbor authentication server includes the user authentication information. Therefore, when the UE performs authentication, it does not need to go.
  • the corresponding access NC A is responsible for initiating a request to other SN-C nodes that hold user authentication information, for example, preferably by the corresponding access SN-C A , to the nearest and saved
  • the SN-C node with the user authentication information initiates the request, or the corresponding access SN-C A is responsible for initiating a request to the SN-C node that holds the user authentication information and is online and relatively close.
  • the authentication information can also be obtained from other SN-C nodes, which reduces the risk of failure to authenticate and operate due to a failure of the single authentication server. And because the interval between the SN-C nodes storing the same authentication information is set, the time required for the authentication process does not exceed the maximum delay allowed by the DSN, and is reduced. The authentication failure is caused by the authentication timeout, which improves the user experience.
  • the method for requesting the DSN authentication information first determines whether the local SN-C node stores the authentication information of the user according to the received user access request, and if the determination result is yes, directly initiates the authentication process; If not, the authentication information is requested from the SN-C node that stores the user authentication information.
  • the authentication information may be directly requested from the SN-C node that is closest to the local node and stores the user authentication information; or may be from the local node
  • the authentication information is requested by the SN-C node that is located in the online SN-C node with the routing distance and the user authentication information to improve the success rate of the authentication information acquisition.
  • the following is a detailed description of the first embodiment of the request method and the second embodiment of the request method.
  • the first embodiment of the DSN authentication information requesting method of the present invention specifically includes the following steps:
  • the SN-CA directly initiates the authentication process and authenticates the UE
  • SN-C B returns the authentication information to SN-C A ;
  • SN-C A initiates an authentication request to the UE according to the authentication information
  • the UE performs authentication according to the authentication request and generates an authentication response to be sent to the SN-C A ,
  • the SN-C A authenticates the UE according to the authentication response.
  • the distributed authentication of the user's authentication information in the routing ring is performed in the UE.
  • the corresponding access SN-C A is responsible for initiating a request to the SN-C node that holds the user authentication information closest to it.
  • the authentication information can also be obtained from other SN-C nodes, which reduces the risk of failure to authenticate and operate due to a failure of the single authentication server.
  • the second embodiment of the DSN authentication information requesting method of the present invention specifically includes the following steps:
  • ⁇ (3) is the same as the first embodiment of the request method, and will not be described here;
  • the SN-C A determines whether the other SN-C node that stores the user authentication information closest to the local node routing distance is online, for example, the node that stores the user authentication information closest to the local node in the present embodiment.
  • SN-C B judge whether SN-C B is online, if online, perform step (5); if not online, perform step (6);
  • the SN-CA determines whether the other SN-C node storing the user authentication information is closest to the local node routing distance, for example, the SN-C H in this embodiment, if not online, continues to search for the depository.
  • the other SN-C node that describes the user authentication information until the SN-C node that is close to the local node and stores the authentication information of the user and the online SN-C node is requested to request the authentication information; if online, step (7) is performed;
  • SN-C A requests authentication information from SN-C H ;
  • SN-C H returns the authentication information to SN-C A ;
  • SN-C A initiates an authentication request to the UE according to the authentication information; (10) The UE performs authentication according to the authentication request and generates an authentication response, which is sent to the SN-C A , and the SN-C A authenticates the UE according to the authentication response.
  • the SN-C node that stores the user authentication information is in-line detected to avoid requesting the authentication information from the offline SN-C node, thereby reducing the delay caused by the unnecessary operations.
  • Request method embodiment three
  • the third embodiment of the DSN authentication information requesting method of the present invention further includes: counting the process of requesting the entire SN-C node to request the authentication information, and exceeding the maximum time delay allowed by the DSN, discarding the authentication process, and the authentication fails.
  • the first embodiment of the SN-C node device of the present invention includes:
  • the receiving module 302 is configured to receive an access request of the user.
  • the storage module 304 is configured to store authentication information of the user and information of other SN-C nodes that store the same user authentication information;
  • the determining module 306 is configured to determine, according to the user access request, whether the storage module stores the authentication information of the user;
  • the authentication module 308 is configured to directly initiate an authentication process when the storage module saves the authentication information of the user;
  • the requesting module 310 is configured to request authentication information from other SN-C nodes that store the user authentication information when the local node does not save the authentication information of the user.
  • the requesting module 310 is specifically configured to: when the local node does not save the user When the authentication information is obtained, the route distance from the local node is the closest and the user authentication information is stored.
  • the authentication information is requested in the SN-C node.
  • the request module 310 in the first embodiment of the device includes:
  • the online detection sub-module 310A is configured to detect whether the SN-C node that is closest to the local node and that stores the authentication information of the user is online;
  • the requesting sub-module 310B is configured to: when the routing information is closest to the local node and the authentication information SN-C node storing the user is online, send the SN-C node request that is closest to the local node and stores the user authentication information. Authentication information; when the SN-C node that is closest to the local node and the user authentication information is not online, select the next SN-C node that is closest to the local node and stores the user authentication information. And instructing the online detection sub-module to detect the online state, until the online detection sub-module detects that the SN-C node that stores the user authentication information and is online is selected from the selected SN-C node. Request authentication information.
  • the SN-C node that stores the user authentication information is in-line detected to avoid requesting the authentication information from the offline SN-C node, thereby reducing the delay caused by the unnecessary operations.
  • the third embodiment of the SN-C node device of the present invention further includes:
  • timing module 314 for timing the entire authentication process
  • the comparison module 316 is configured to compare the time of the entire authentication process with the maximum delay allowed by the DSN;
  • the authentication module 308 is further configured to return the authentication failure information when the usage of the entire authentication process exceeds a maximum time delay allowed by the DSN.
  • the DSN authentication system embodiment of the present invention includes
  • the SN-C node determines, according to the received user access request, whether the local SN-C node stores the user's authentication information; and the local SN-C node stores the user's authentication information.
  • the other SN-C section stores the user authentication information. Click for authentication information.
  • the DSN authentication system in this embodiment distributes and authenticates the authentication information of the user, so that when one of the SN-C nodes fails, the authentication information can be obtained from other SN-C nodes, and the single authentication server is reduced. Risk of failure to authenticate and operate due to a failure. Moreover, since the interval between the SN-C nodes storing the same authentication information is set, the time required for the authentication process does not exceed the maximum delay allowed by the DSN, and the authentication failure due to the authentication timeout is reduced, and the user is improved. Experience.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Telephonic Communication Services (AREA)

Description

DSN认证信息请求、 存储方法、 SN-C节点及系统 技术领域
本发明涉及一种 DSN( Distributed Service Network,分布式业务网络) 技术, 尤其涉及一种 DSN认证信息请求、 存储方法、 SN-C节点及 DSN认 证系统。 背景技术
现有技术中, 通信网络中单钥认证机制方案主要为基于 AKA ( authentication and key agreement,认证和密铜寸办商 )进4亍认证的方案 , 用户 与对应的归属服务器 HLR ( Home Location Register, 归属位置寄存器) /HSS ( Home Subscriber Server, 归属用户服务器)中保存预共享的密钥 K; 用户通 过 VLR ( Visitor Location Register , 访问位置寄存器) /MME ( Mobility management entity, 移动管理实体)等接入网络; VLR/MME探知用户接入时 向 I ILR/IISS申请认证向量; HLR/HSS产生认证向量并反馈给 VLR/MME; VI R/MMH利用认证向量对用户进行认证。
现有技术的 ΛΚΑ认证方案的主要缺陷是: 用户在认证时只能由特定的 IIIJ IISS生成并发送认证向量, 当 HLR/HSS失效时会导致用户认证失败。 另外 , 现有 AKA机制不适用于 P2P ( Peer to Peer, 点对点) 的分布式网络环 境。 发明内容
本发明的第一目的在于, 提供一种 DSN认证信息请求方法, 降低单 一认证服务器由于故障而引起的无法认证和运行的风险。
本发明的第二目的在于, 提供一种 DSN认证信息存储方法, 降低单 一认证服务器由于故障而引起的无法认证和运行的风险。 本发明的第三目的在于, 提供一种核心网控制 SN-C ( Super Node-Core, 核心超级节点)节点, 降低单一认证服务器由于故障而引起 的无法认证和运行的风险。
本发明的第四目的在于, 提供一种 DSN认证系统, 降低单一认证服 务器由于故障而引起的无法认证和运行的风险。
根据本发明的第一目的, 提供一种 DSN认证信息请求方法, 包括: 根据接收到的用户接入请求判断本地 SN-C节点是否保存有所述用户的 认证信息; 当本地 SN-C 节点保存有所述用户的认证信息时, 直接发起 认证过程; 当本地 SN-C节点没有保存所述用户的认证信息时, 从存放 所述用户认证信息的其他 SN-C节点中请求认证信息。
根据本发明的第二目的, 提供一种 DSN认证信息存储方法, 包括: 根据 DSN允许的最大时延、 相邻 SN-C节点在传输时产生的平均时延以 及网络负载与使用情况, 确定需要保存相同用户认证信息的两个 SN-C 节点之间的最大间隔数; 根据所述最大间隔数在相应的 SN-C 节点上存 储相同用户的认证信息。
根据本发明的第三目的, 提供一种 SN- C 节点, 包括: 接收模块, 用于接收用户的接入请求; 存储模块, 用于存储用户的认证信息, 以及 与其存储相同的用户认证信息的 SN-C 节点的信息; 判断模块, 用于根 据所述用户接入请求判断所述存储模块是否保存有所述用户的认证信 息; 认证模块, 用于当所述存储模块保存有所述用户的认证信息时, 直 接发起认证过程; 请求模块, 用于当本地节点没有保存所述用户的认证 信息时, 从存放所述用户认证信息的其他 SN-C节点中请求认证信息。
根据本发明的第四目的, 提供一种 DSN认证系统, 包括: 环路设置 的若干 SN-C节点,用于根据接收到的用户接入请求判断本地 SN-C节点 是否保存有所述用户的认证信息; 当本地 SN-C 节点保存有所述用户的 认证信息时, 直接发起认证过程; 当本地 SN-C 节点没有保存所述用户 的认证信息时, 从存放所述用户认证信息的其他 SN-C 节点中请求认证 信息。
本发明的 DSN认证信息请求、存储方法、 SN-C节点及 DSN认证系 统, 通过对用户的认证信息分布式存储及认证, 使得当其中一个 SN-C 节点出现故障, 还可以从其他的 SN- C 节点获取到认证信息, 降低了单 储相同认证信息的 SN-C 节点之间的间隔进行设定, 保证认证过程所需 要的时间不超过 DSN允许的最大时延,减少由于认证超时而造成认证失 败的情况, 提高了用户体验。 附图说明
图 1是本发明 DSN认证信息存储方法实施例流程图;
图 2是本发明 DSN认证信息请求方法实施例一流程图;
图 3是本发明 DSN认证信息请求方法实施例二流程图;
图 4是本发明 SN- C节点装置实施例一结构图;
图 5是本发明 SN-C节点装置实施例二、 三结构图;
图 6是本发明 DSN认证系统结构图。 具体实施方式
以下结合附图对本发明进行详细说明。
存储方法实施例
如图 1所示, 本发明 DSN认证信息存储方法实施例包括以下步骤: 步骤 22, 计算需要保存相同用户认证信息的两个 SN-C节点之间的 最大间隔数。 本实施例根据 DSN允许的最大时延 T和相邻 SN-C节点在传输时产 生的平均时延 t, 以及网络负载与使用情况, 确定需要保存相同用户认证 信息的两个 SN-C节点之间的最大间隔数 n, 例如, DSN允许的最大时 延 T为 200ms, 相邻 SN-C节点在传输时产生的平均时延 t为 30ms, 且 网络负载与使用情况正常,即在 DSN中单次认证平均 n=2次就能查找到 保存有用户认证信息的在线 SN-C节点, 则计算最大间隔数 n为
( T/t/n ) *2-l=(200ms/30ms/2)*2-l « 5,
从而使得用户节点连接任意 SN-C节点的时候, 能够保证找到最近 的一个保存有其认证信息的 SN-C的间隔不会超过( 200ms/30ms/2 ) « 3 个节点的数量。
步骤 24, 根据所述最大间隔数在相应的 SN-C节点上存储所述用户 的认证信息, 直到整个路由环中的保存有相同用户的认证信息的 SN-C 节点之间的距离都不大于选定的间隔为止, 例如, 如图 6所示, 在节点 SN-CB、 SN-CH上存储相同的用户认证信息。
本实施例, 通过在路由环中对用户的认证信息分布式存储, 相关认 证服务器包含用户认证信息和邻居认证服务器包含用户认证信息是严格 一致的, 因此在 UE进行认证的时候, 并不需要去寻找特定的归属服务 器, 而是由对应的接入 N-CA负责向保存有用户认证信息的其他 SN-C 节点发起请求, 例如优选地由对应的接入 SN-CA负责向与其距离最近且 保存有用户认证信息的 SN-C节点发起请求,或者, 由对应的接入 SN-CA 负责向保存有用户认证信息且在线且距离较近的 SN-C节点发起请求。
这样, 当其中一个 SN-C节点出现故障,还可以从其他的 SN-C节点 获取到认证信息, 降低了单一认证服务器由于故障而引起的无法认证和 运行的风险。 并且由于对存储相同认证信息的 SN-C节点之间的间隔进 行设定, 保证认证过程所需要的时间不超过 DSN允许的最大时延, 减少 由于认证超时而造成认证失败的情况, 提高了用户体验。
本发明提供的 DSN认证信息请求方法中, 首先根据接收到的用户 接入请求判断本地 SN-C节点是否保存有该用户的认证信息, 若判断结 果为是, 则直接发起认证过程; 若判断结果为否, 则从存放该用户认证 信息的 SN-C节点中请求认证信息。其中,从存放该用户认证信息的 SN-C 节点中请求认证信息时, 可以直接从与本地节点路由距离最近且存放该 用户认证信息的 SN- C节点中请求认证信息; 也可以从与本地节点路由 距离较近且存放该用户认证信息的且在线的 SN-C节点中请求认证信息, 以提高认证信息获取的成功率。 以下分别通过请求方法实施例一以及请 求方法实施例二进行详细说明。
请求方法实施例一
如图 2所示, 本发明 DSN认证信息请求方法实施例一具体包括以 下步驟:
( 1 ) UL:在接入网络时进行接入请求, 并将归属服务器网络信息 发送给相连的 SN-CA;
( 2 ) SN-CA判断本地是否保存用户的认证信息, 如果是, 执行步 骤 (3 ); 如果否, 执行步骤 (4 );
( 3 ) SN-CA直接发起认证过程, 对 UE进行认证;
( 4 ) 向与本地节点路由距离最近的存放所述用户认证信息的 SN-C 节点 SN-CB请求认证信息;
( 5 ) SN-CB返回认证信息至 SN-CA;
( 6 ) SN-CA根据认证信息向 UE发起认证请求;
( 7 ) UE根据认证请求进行认证并生成认证响应发送到 SN-CA,
SN- CA根据认证响应对 UE进行认证。
本实施例, 通过在路由环中对用户的认证信息分布式认证, 在 UE 进行认证的时候, 并不需要去寻找特定的归属服务器, 而是由对应的接 入 SN- CA负责向与其距离最近的保存有用户认证信息的 SN-C节点发起 请求。 这样, 当其中一个 SN-C节点出现故障, 还可以从其他的 SN-C节 点获取到认证信息, 降低了单一认证服务器由于故障而引起的无法认证 和运行的风险。 并且由于对存储相同认证信息的 SN-C节点之间的间隔 进行设定, 保证认证过程所需要的时间不超过 DSN允许的最大时延, 减 少由于认证超时而造成认证失败的情况, 提高了用户体验。 请求方法实施例二
如图 3所示,本发明 DSN认证信息请求方法实施例二具体包括以下 步骤:
( 1 ) 〜(3 ) 与请求方法实施例一相同, 在此不再赘述;
( 4 ) SN-CA判断与本地节点路由距离最近的存放所述用户认证信 息的其他 SN- C节点是否在线, 例如本实施例中与本地节点路由距离最 近的存放所述用户认证信息的节点为 SN-CB, 判断 SN-CB是否在线, 如 果在线, 执行步骤(5 ); 如果不在线, 执行步驟(6 );
( 5 ) 向 SN-CB请求认证信息;
( 6 ) SN-CA判断与本地节点路由距离次近的存放所述用户认证信息 的其他 SN-C节点是否在线, 例如本实施例中的 SN-CH, 如果不在线, 则继续查找存放所述用户认证信息的其他 SN-C节点, 直至查找到与本 地节点路由距离较近且存放该用户的认证信息且在线的 SN-C节点以请 求认证信息; 如果在线, 则执行步骤(7 );
( 7 ) SN-CA向 SN-CH请求认证信息;
( 8 ) SN-CH返回认证信息至 SN-CA;
( 9 ) SN-CA根据认证信息向 UE发起认证请求; ( 10 ) UE根据认证请求进行认证并生成认证响应发送到 SN-CA, SN-CA根据认证响应对 UE进行认证。
本实施例中, 通过对存储用户认证信息的 SN-C节点进行在线检测, 避免对不在线的 SN-C节点请求认证信息, 降低了这些不必要操作所造 成的时延。 请求方法实施例三
本发明 DSN认证信息请求方法实施例三还包括: 对整个查找 SN-C 节点请求认证信息的过程进行计时, 当超过 DSN允许的最大时延时, 放 弃认证过程, 认证失败。
本实施例通过对认证过程时间的限制, 避免认证时间过长对网络运 行造成影响及对用户体验度产生的影响。 装置实施例一
如图 4所示, 本发明 SN-C节点装置实施例一包括:
接收模块 302, 用于接收用户的接入请求;
存储模块 304, 用于存储用户的认证信息以及与其存储相同的用户 认证信息的其他 SN-C节点的信息;
判断模块 306, 用于根据所述用户接入请求判断所述存储模块是否 保存有所述用户的认证信息;
认证模块 308, 用于当所述存储模块保存有所述用户的认证信息时, 直接发起认证过程;
请求模块 310, 用于当本地节点没有保存所述用户的认证信息时, 从存放所述用户认证信息的其他 SN-C节点中请求认证信息。
优选地, 该请求模块 310, 具体用于当本地节点没有保存所述用户 的认证信息时, 从与本地节点路由距离最近且存放所述用户认证信息的
SN-C节点中请求认证信息。
本实施例, 通过在路由环中对用户的认证信息分布式认证, 在 UE 进行认证的时候, 并不需要去寻找特定的归属服务器, 而是由对应的接 入 SN-C负责向与其距离最近的保存有用户认证信息的其他 SN-C节点发 起请求。 这样, 当其中一个 SN- C节点出现故障, 还可以从其他的 SN-C 节点获取到认证信息, 降低了单一认证服务器由于故障而引起的无法认 证和运行的风险。 并且由于对存储相同认证信息的 SN-C节点之间的间 隔进行设定, 保证认证过程所需要的时间不超过 DSN允许的最大时延, 减少由于认证超时而造成认证失败的情况, 提高了用户体验。
本实施例装置的具体认证过程已在请求方法实施例中详细描述, 在 此不再赘述。 装置实施例二
如图 5所示, 本发明 SN-C节点装置实施例二中, 上述装置实施例 一中的请求模块 310, 具体包括:
在线检测子模块 310A,用于检测与本地节点路由距离最近且存放该 用户的认证信息的 SN-C节点是否在线;
请求子模块 310B,用于当与本地节点路由距离最近且存放该用户的 认证信息 SN-C节点在线, 则向所述与本地节点路由距离最近且存放所 述用户认证信息的 SN- C节点请求认证信息; 当所述与本地节点路由距 离最近且存放所述用户认证信息的 SN-C节点不在线, 则选取下一个与 本地节点路由距离次近且存放所述用户认证信息的 SN-C节点并指示在 线检测子模块检测其在线状态, 直至所述在线检测子模块检测选取出存 放所述用户认证信息且在线的 SN-C节点,从选取出的所述 SN-C节点中 请求认证信息。
本实施例中, 通过对存储用户认证信息的 SN-C节点进行在线检测, 避免对不在线的 SN-C 节点请求认证信息, 降低了这些不必要操作所造 成的时延。
本实施例装置的具体认证过程已在请求方法实施例中详细描述, 在 此不再赘述。 装置实施例三
如图 5所示, 本发明 SN-C节点装置实施例三还包括:
计时模块 314, 用于对整个认证过程进行计时;
比较模块 316, 用于比较整个认证过程的用时与 DSN允许的最大时 延;
认证模块 308, 还用于当所述整个认证过程的用时超过所述 DSN允 许的最大时延时, 返回认证失败信息。
本实施例通过对认证过程时间的限制, 避免认证时间过长对网絡运 行造成影响及对用户体验度产生的影响。
本实施例装置的具体认证过程已在请求方法实施例中详细描述, 在 此不再赘述。 系统实施例
如图 6所示, 本发明 DSN认证系统实施例包括
环路设置的若干 SN-C节点, SN-C节点根据接收到的用户接入请求 判断本地 SN-C节点是否保存有用户的认证信息; 当本地 SN-C节点保存 有所述用户的认证信息时, 直接发起认证过程; 当本地 SN-C节点没有 保存所述用户的认证信息时, 从存放所述用户认证信息的其他 SN-C节 点请求认证信息。
本实施例系统的具体认证过程已在请求方法实施例中详细描述, 在 此不再赘述。
本实施例的 DSN认证系统,通过对用户的认证信息分布式存储及认 证, 使得当其中一个 SN-C节点出现故障,还可以从其他的 SN-C节点获 取到认证信息, 降低了单一认证服务器由于故障而引起的无法认证和运 行的风险。 并且由于对存储相同认证信息的 SN-C节点之间的间隔进行 设定, 保证认证过程所需要的时间不超过 DSN允许的最大时延, 减少由 于认证超时而造成认证失败的情况, 提高了用户体验。
应说明的是: 以上实施例仅用以说明本发明而非限制, 本发明也并 不仅限于上述举例, 一切不脱离本发明的精神和范围的技术方案及其改 进, 其均应涵盖在本发明的权利要求范围中。

Claims

权 利 要 求
1、 一种分布式业务网络 DSN认证信息请求方法, 其特征在于, 包 括:
根据接收到的用户接入请求判断本地核心超级节点 SN-C 节点是否 保存有所述用户的认证信息;
当本地 SN-C 节点保存有所述用户的认证信息时, 直接发起认证过 程;
当本地 SN-C 节点没有保存所述用户的认证信息时, 从存放所述用 户认证信息的其他 SN-C节点中请求认证信息。
2、 根据权利要求 1所述的 DSN认证信息请求方法, 其特征在于, 所述从存放所述用户认证信息的其他 SN-C节点中请求认证信息, 具体 包括:
从与本地节点路由距离最近且存放所述用户认证信息的 SN-C 节点 中请求认证信息。
3、 根据权利要求 1所述的 DSN认证信息请求方法, 其特征在于, 所述从存放所述用户认证信息的其他 SN-C节点中请求认证信息, 具体 包括:
测试与本地节点路由距离最近且存放所述用户认证信息的 SN-C 节 点是否在线;
当所述与本地节点路由距离最近且存放所述用户认证信息的 SN-C 节点在线, 则从所述与本地节点路由距离最近且存放所述用户认证信息 的 SN- C节点中请求认证信息;
当所述与本地节点路由距离最近且存放所述用户认证信息的 SN- C 节点不在线, 则选取与本地节点路由距离次近且存放所述用户认证信息 的 SN-C 节点并测试其是否在线, 直至选取出存放所述用户认证信息且 在线的 SN-C节点, 从选取出的所述 SN-C节点中请求认证信息。
4、 根据权利要求 3所述的 DSN认证信息请求方法, 其特征在于, 当在 DSN允许的最大时延内没有获得所述认证信息, 则认证失败。
5、 一种分布式业务网络 DSN认证信息存储方法, 其特征在于, 包 括:
根据 DSN允许的最大时延、 相邻核心超级节点 SN-C节点在传输时 产生的平均时延以及网络负载与使用情况 , 确定需要保存相同用户认证 信息的两个 SN- C节点之间的最大间隔数;
根据所述最大间隔数在相应的 SN-C节点上存储相同用户的认证信 息。
6、 根据权利要求 5所述的 DSN认证信息存储方法, 其特征在于, 存储相同用户认证信息的相应的 SN-C节点之间的间隔小于或等于所述 最大间隔数。
7、 根据权利要求 5所述的 DSN认证信息存储方法, 其特征在于, 所述每个 SN-C节点上还保存有与其存储相同的用户认证信息的 SN-C节 点的信息。
8、 一种核心超级节点 SN-C节点, 其特征在于, 包括:
接收模块, 用于接收用户的接入请求;
存储模块, 用于存储用户的认证信息以及与其存储相同的用户认证 信息的 SN-C节点的信息;
判断模块, 用于根据所述用户接入请求判断所述存储模块是否保存 有所述用户的认证信息;
认证模块, 用于当所述存储模块保存有所述用户的认证信息时, 直 接发起认证过程;
请求模块, 用于当本地节点没有保存所述用户的认证信息时, 从存 放所述用户认证信息的其他 SN-C节点中请求认证信息。
9、根据权利要求 8所述的 SN-C节点, 其特征在于, 所述清求模块, 具体用于:
当本地节点没有保存所述用户的认证信息时, 从与本地节点路由距 离最近且存放所述用户认证信息的 SN-C节点中请求认证信息。
10、 根据权利要求 8所述的 SN-C节点, 其特征在于, 所述请求模 块, 具体包括:
在线检测子模块, 用于检测与本地节点路由距离最近且存放所述用 户认证信息的 SN-C节点是否在线;
请求子模块, 用于当所述在线检测子模块检测与本地节点路由距离 最近且存放所述用户认证信息的 SN-C节点在线, 则向所述与本地节点 路由距离最近且存放所述用户认证信息的 SN-C 节点请求认证信息; 当 所述与本地节点路由距离最近且存放所述用户认证信息的 SN-C 节点不 在线, 则选取下一个与本地节点路由距离次近且存放所述用户认证信息 的 SN- C 节点并指示在线检测子模块检测其在线状态, 直至所述在线检 测子模块检测选取出存放所述用户认证信息且在线的 SN- C节点, 从选 取出的所述 SN-C节点中请求认证信息。
11、 根据权利要求 8所述的 SN-C节点, 其特征在于, 还包括: 计时模块, 用于对整个认证过程进行计时;
比较模块, 用于比较整个认证过程的用时与 DSN允许的最大时延; 所述认证模块,还用于当所述整个认证过程的用时超过所述 DSN允 许的最大时延时, 返回认证失败信息。
12、 一种分布式业务网络 DSN认证系统, 其特征在于, 包括: 环路设置的若干核心超级节点 SN-C节点, 用于根据接收到的用户 接入请求判断本地 SN- C 节点是否保存有所述用户的认证信息; 当本地 SN-C 节点保存有所述用户的认证信息时, 直接发起认证过程; 当本地 SN-C节点没有保存所述用户的认证信息时,从存放所述用户认证信息的 其他 SN-C节点中请求认证信息。
PCT/CN2010/076042 2009-08-28 2010-08-17 Dsn认证信息请求、存储方法、sn-c节点及系统 Ceased WO2011023070A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US13/392,983 US8763083B2 (en) 2009-08-28 2010-08-17 Method, super node-core (SN-C) node and system for requesting and storing distributed service network (DSN) authentication information

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200910091817.3 2009-08-28
CN200910091817.3A CN101997825B (zh) 2009-08-28 2009-08-28 Dsn网络认证信息请求、存储方法、sn-c节点及系统

Publications (1)

Publication Number Publication Date
WO2011023070A1 true WO2011023070A1 (zh) 2011-03-03

Family

ID=43627247

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/076042 Ceased WO2011023070A1 (zh) 2009-08-28 2010-08-17 Dsn认证信息请求、存储方法、sn-c节点及系统

Country Status (3)

Country Link
US (1) US8763083B2 (zh)
CN (1) CN101997825B (zh)
WO (1) WO2011023070A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130298194A1 (en) * 2012-05-07 2013-11-07 Canon Kabushiki Kaisha Communication apparatus and control method

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102256252A (zh) * 2011-07-14 2011-11-23 南京邮电大学 移动互联网中接入认证的安全模型实现方法
CN108063748B (zh) * 2016-11-09 2021-06-29 中国移动通信有限公司研究院 一种用户认证方法、装置及系统
CN110519632B (zh) * 2019-07-30 2021-08-20 华为技术有限公司 投屏方法及设备

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1822548A (zh) * 2006-03-24 2006-08-23 南京邮电大学 基于对等网络的分布式流量管理方法
CN101159745A (zh) * 2007-11-08 2008-04-09 中国传媒大学 具有版权管理功能的p2p应用的智能节点弹性重叠网
CN101183943A (zh) * 2007-12-04 2008-05-21 中兴通讯股份有限公司 用户认证方法
CN101197753A (zh) * 2007-12-26 2008-06-11 北京理工大学 基于全局最小访问代价的副本选择方法

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7106706B1 (en) * 2001-06-27 2006-09-12 Sprint Spectrum L.P. Method and system for providing dial-up data sessions
US7617524B2 (en) * 2005-06-14 2009-11-10 Nokia Corporation Protection against denial-of-service attacks
KR100831327B1 (ko) * 2006-09-28 2008-05-22 삼성전자주식회사 무선 메쉬 네트워크의 인증 처리 방법 및 그 장치
US7768923B2 (en) * 2007-02-09 2010-08-03 Cisco Technology, Inc. Packet aging in a wireless network
US8160496B2 (en) * 2007-06-25 2012-04-17 Panasonic Corporation Wireless communication unit, mobile terminal, and wireless authentication control method
JP4845057B2 (ja) * 2008-04-14 2011-12-28 京セラ株式会社 携帯電子機器及びプログラム

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1822548A (zh) * 2006-03-24 2006-08-23 南京邮电大学 基于对等网络的分布式流量管理方法
CN101159745A (zh) * 2007-11-08 2008-04-09 中国传媒大学 具有版权管理功能的p2p应用的智能节点弹性重叠网
CN101183943A (zh) * 2007-12-04 2008-05-21 中兴通讯股份有限公司 用户认证方法
CN101197753A (zh) * 2007-12-26 2008-06-11 北京理工大学 基于全局最小访问代价的副本选择方法

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130298194A1 (en) * 2012-05-07 2013-11-07 Canon Kabushiki Kaisha Communication apparatus and control method
US9344886B2 (en) * 2012-05-07 2016-05-17 Canon Kabushiki Kaisha Communication apparatus and control method

Also Published As

Publication number Publication date
CN101997825A (zh) 2011-03-30
US20120204226A1 (en) 2012-08-09
CN101997825B (zh) 2015-03-11
US8763083B2 (en) 2014-06-24

Similar Documents

Publication Publication Date Title
US20040107252A1 (en) Group judgment device
US8516252B2 (en) Method and apparatus for authenticating a sensor node in a sensor network
JP2012080418A (ja) ネットワーク認証における端末接続状態管理
CN103457967B (zh) 服务节点切换方法及系统
CN101621374A (zh) 一种网络认证的方法、装置、系统及服务器
TW201006272A (en) Method and apparatus for maintaining communications connections over a distributed wireless network
JP4129216B2 (ja) グループ判定装置
JP2013510459A (ja) 分離的なパス計算アルゴリズム
CN103369529A (zh) 身份认证方法、访问点及访问控制器
JP5527216B2 (ja) 識別情報管理システム、識別情報の生成方法及び管理方法、端末、並びに生成及び管理プログラム
WO2011023070A1 (zh) Dsn认证信息请求、存储方法、sn-c节点及系统
US20170118652A1 (en) Method and Arrangement for Providing a Wireless Mesh Network
JP2013132021A (ja) 負荷分散装置、負荷分散方法、プログラム、およびシステム
US10270747B2 (en) Methods and devices having a key distributor function for improving the speed and quality of a handover
US10999379B1 (en) Liveness detection for an authenticated client session
US9106572B2 (en) Immobilization module for security on a communication system
US9936380B2 (en) Predictive pairwise master key caching
JP2008071156A (ja) 負荷分散システム、方法、及び、プログラム
CN101599878A (zh) 重认证方法、系统及鉴权装置
JP6272274B2 (ja) ネットワーク装置、認証システムおよび認証方法
WO2015018301A1 (zh) 一种网络中路径建立的方法及装置
CN109391601A (zh) 一种授予终端网络权限的方法、装置及设备
JP2010165105A (ja) 通信装置及びその制御プログラム
Hof et al. Design of a secure distributed service directory for wireless sensornetworks
JP2019213131A (ja) 中央処理装置、検針システムおよび不正アクセス検出方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10811230

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 13392983

Country of ref document: US

122 Ep: pct application non-entry in european phase

Ref document number: 10811230

Country of ref document: EP

Kind code of ref document: A1