WO2011075884A1 - 一种向移动用户设备提供网络服务方法及其装置 - Google Patents

一种向移动用户设备提供网络服务方法及其装置 Download PDF

Info

Publication number
WO2011075884A1
WO2011075884A1 PCT/CN2009/075821 CN2009075821W WO2011075884A1 WO 2011075884 A1 WO2011075884 A1 WO 2011075884A1 CN 2009075821 W CN2009075821 W CN 2009075821W WO 2011075884 A1 WO2011075884 A1 WO 2011075884A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
access
mobile
user equipment
access token
Prior art date
Application number
PCT/CN2009/075821
Other languages
English (en)
French (fr)
Other versions
WO2011075884A8 (zh
Inventor
温海波
宾梵翔
Original Assignee
上海贝尔股份有限公司
阿尔卡特朗讯
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 上海贝尔股份有限公司, 阿尔卡特朗讯 filed Critical 上海贝尔股份有限公司
Priority to US13/513,241 priority Critical patent/US8880026B2/en
Priority to EP09852434.1A priority patent/EP2518968B1/en
Priority to CN200980160776.7A priority patent/CN102474500B/zh
Priority to PCT/CN2009/075821 priority patent/WO2011075884A1/zh
Publication of WO2011075884A1 publication Critical patent/WO2011075884A1/zh
Publication of WO2011075884A8 publication Critical patent/WO2011075884A8/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0807Network architectures or network communication protocols for network security for authentication of entities using tickets, e.g. Kerberos
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/084Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/12Setup of transport tunnels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/16Discovering, processing access restriction or access information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/04Large scale networks; Deep hierarchical networks
    • H04W84/042Public Land Mobile systems, e.g. cellular systems
    • H04W84/045Public Land Mobile systems, e.g. cellular systems using private Base Stations, e.g. femto Base Stations, home Node B

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method and apparatus for providing network services to mobile user equipment based on the Haowei cellular technology. Background technique
  • the communication based on the macro cell is poor due to the penetration characteristics of the radio frequency used by the building, and thus the indoor service quantity is reduced, and the burden of the wireless channel is becoming increasingly tense; More than 50% of voice traffic using wireless communications and more than 70% of data traffic comes from indoors.
  • Femtocel l nocell
  • Some Femtoce ll base stations for home and small business units will be mobile user equipment (UE).
  • Internet (Internet) service access is provided through existing fixed access networks (such as DSL or cable TV high-speed networks).
  • FIG. 1 is a typical example of a network service system based on a micro-base station providing a backhaul access mode.
  • the UE may access the mobile core network through a terrestrial radio access network (UTRAN), and the UTRAN includes a radio base station (NodeB). And a radio network controller (RNC) that enables user terminal equipment such as mobile phones, portable computers, etc. to provide connectivity to the mobile core network; and when the UE moves into the coverage of the Femtoce ll base station in its home network, it can be fixed
  • the broadband connection provided by the access network realizes the connection to the mobile core network through the FGW in the manner of IP security tunnel, and realizes the access of the Internet through the mobile core network.
  • the backhaul between Femt oce ll and FGW utilizes its broadband access connection, especially as mobile users grow their applications for high-speed data services, and their bandwidth Resources are more expensive, but it does not benefit.
  • FIG. 2 is a typical local bypass solution based on a ⁇ micro base station providing an ISP system structure.
  • a UE moves into the coverage of a Femtoce ll base station in its home network, it attaches and establishes a PDP with Femtoce ll. (Packet Data Protocol) Context, which in turn gets its assigned local private IP address, can access other home devices, or access Interne t through a fixed access network, thereby reducing the backhaul to the mobile core network through the IP security tunnel Data Flow.
  • PDP Packet Data Protocol
  • the solution has the following problems: 1) Since the local private IP address of Femtoce l l is hidden behind the home gateway, how can the UEs behind the hidden home gateway be legally intercepted? 2), the UE can not enjoy the established service policy, and it is not easy to expand to obtain differentiated services in the fixed access network; 3) This is not conducive to an open access scheme, and the operators of the fixed access network usually follow each
  • the DSL broadband connection charges a specific service such as HIS, so that it cannot obtain the network resource information provided by the UE and then charges.
  • the present invention is directed to solving one or more of the foregoing technical problems, and provides a technical solution for providing a network service to a mobile user equipment based on a micro-cellular technology, where the micro-base station establishes a resource of a fixed access network for the attached mobile user equipment. Configuration, the mobile user equipment can understand the resource configuration to establish an IP connection, and achieve a local bypass access through a fixed access network. According to an aspect of the present invention, a method for providing a network service to a mobile user equipment is provided.
  • the mobile user equipment is connected to a fixed access network by using a micro base station, and then connected to the mobile core network, and includes the following steps:
  • the mobile core device provides an access token to the femto base station;
  • the femto base station requests the fixed access network to perform network resource configuration for the mobile user equipment by using the access token;
  • C) the mobile user equipment according to the network Resource configuration establishes a network service connection.
  • a communication device in a mobile core network comprising: receiving means for receiving a specific request message from a client, the request message including an identifiable one corresponding to a fixed access network And the processing device, requesting, according to the request message, an access token to the authentication server in the fixed access network, where the access token is used for the client to obtain the network resource configuration of the fixed access network; the sending device to the client The access token is provided by the end.
  • a micro base station device comprising: an obtaining device, obtaining an access token for accessing a fixed access network for a mobile user equipment; and requesting the device, according to a context request of the mobile user equipment And the access token, for which a fixed access network resource is requested and configured, and a corresponding network connection is established.
  • an authentication server in a fixed access network comprising: a distribution device, configured to allocate an access token for configuring a local network resource according to a request from a mobile core network; The device receives the request from the client in the local network, verifies the carried access token, and configures the network resource for the client.
  • the mobile user equipment Due to the network resources allocated by the fixed access network used by the mobile user equipment, for example, using its IP address as its PDP address for network access, the mobile user equipment is visible to the fixed network operator, and is technically guaranteed to be effective Implementing the lawful interception of the bypass service.
  • different access modes are implemented according to the service attributes of the mobile user equipment.
  • the services accessed through the local bypass mode can be in the fixed access network.
  • Service quality assurance can be obtained through corresponding technical means; further, fixed access network
  • the operator of the network can realize the commercial tariff sharing with the operator of the mobile core network according to the resources and possession (allocation and release) allocated for the mobile user equipment.
  • FIG. 1 is a structure based on a femto base station network service providing system (prior art);
  • FIG. 2 is a second embodiment of a network service providing system based on a femto base station (prior art);
  • FIG. 3 is a network based on a femto base station according to the present invention.
  • FIG. 4 is a flowchart of a method for providing a network service based on a nano base station according to the present invention;
  • FIG. 3 is a schematic diagram of a network structure of the present invention, which includes a user network 31, a fixed access network 32, and a mobile core network 33.
  • the mobile user equipment UE 311 in the user network 31 is suitable for CDMA (Code Division Multiple Access).
  • CDMA Code Division Multiple Access
  • Various standards such as GSM (Global System for Mobile Communications), UMTS (Universal Mobile Telecommunications System), and products supporting 2G, 2. 5G, and 3G, and other mobile carriers of the carrier, in the same frequency band, UE 311 can pass macro cell UTRAN (Global Onshore Radio Access)
  • the connection to the mobile core network 33 is achieved, and the connection to the mobile core network 33 can also be achieved by the IP secure tunneling between the microcell Femtoce 111 and the HGW 331.
  • HGW 331 In addition to providing the security gateway function and establishing a secure tunnel between Femtoce ll and HGW, HGW 331 actually acts as a virtual RNC that aggregates all the traffic controlled by it, and presents it to the traditional mobile core core network 33. Standard interface features.
  • Femtoce ll 312 implements the local GGSN (Gateway GPRS Support Node) function and the local SGSN (Serving GPRS Support Node) function (of course, in another case, the non-access layer signaling proxy NAS proxy is implemented at Femtoce ll, and the SGSN function is all mobile. Processing in the core network), the local service bypass is directly accessed through the fixed access network 32.
  • GGSN Global GPRS Support Node
  • SGSN Server GPRS Support Node
  • a mobile user equipment UE 311 is When moving into the coverage of Femtocel l 312 in its home network and attempting to attach to the Femtocel l, the user can perform user authentication, location update, etc. through the aforementioned IP security tunnel, and Femtocel l can carry it in its uplink request message.
  • Relevant network parameter information in the fixed access network such as its IP address in the fixed access network 32, etc., related network element devices in the mobile core network 33, such as HLR/AuC (Home Location Register/Authentication Center) can pass
  • HLR/AuC Home Location Register/Authentication Center
  • the foregoing operation example performs authentication, service registration, mobility management, and the like on the user identity of the UE 311, and in combination with the fixed access network information provided by the Femtocel l, it may further request a fixed access network 32 corresponding to the Femtoce ll.
  • the access token is sent to the UE 311 in a specific manner through the foregoing IP security tunnel, and the Femtocel 312 can obtain the access token therein, and the Femtocel 312 requests the authentication server 322 in the fixed access network 32 with the access token as Forgive the UE for local network resource configuration, such that the IP address in a fixed access network 32 available to the UE is used as its PDP. Group data protocol)
  • the address is directly connected to the Internet through the fixed access network 32 to implement local bypass access.
  • the UE 311 uses the IP address assigned by the fixed access network 32 as its PDP address, the UE 311 is visible to the fixed access network operator, and the legal interception implementation is technically guaranteed.
  • Femtocel l can set the priority indication, and the quality of service can be guaranteed in the fixed access network.
  • the service data through the IP security tunnel is in the fixed network transmission process. Data streams cannot receive the corresponding quality of service guarantee.
  • the operator of the fixed access network 32 can implement the mobile core network 32 according to the resources and possession conditions allocated by the UE 311, such as IP address lease time, network bandwidth, and service type guarantee. The operator's commercial cost sharing.
  • the Femtocel l 312 provides a standard air interface for the mobile user equipment UE311.
  • the specific implementation may be a separate device or integrated with a Home GW.
  • the function may also include an RNC (letter).
  • GGSN function of session management, billing interface, etc.
  • GGSN functions such as GGSN's session management, billing interface
  • SGSN related functions authentication authentication, session management, accounting, signaling, user plane mobility, etc.
  • Femtocel 312 implements a local SGSN function.
  • a UE When receiving an attach request from a UE, it requests the UE to provide its identity information and to the mobile core network through the established IP secure tunnel.
  • Femtocel 312 may attach network parameter information of its own device in the fixed access network 32 in the uplink related user authentication or location update message, for example The IP address in the fixed access network 32, etc., so that the related device in the mobile core network 33 can access the authentication server in the corresponding fixed access network 32 across the domain and obtain an access token allocated for the UE; After that, the Femtocel 312 will establish an MM Context (Mobile Management Context) according to the information about the UE obtained from the mobile core network 33, and the related information will include IMSI (International Mobile Subscriber Identity), the requested service, etc.
  • MM Context Mobile Management Context
  • FemoCel 312 When establishing an IP connection and requesting a specific service, FemoCel 312 will decide which access mode (local bypass or IP secure tunnel connection) to take according to the UE's active PDP context request, the aforementioned ⁇ Context, etc., if local bypass is adopted. In a manner, it will provide the access token to the local fixed access network 32, request fixed access network resources and configuration information for the UE, and obtain an IP address in a fixed access network 32 for the UE, thereby the UE The specific service requested will no longer be transmitted back to the mobile core network through the IP security tunnel, but bypassed directly in Femtocel.
  • access mode local bypass or IP secure tunnel connection
  • the access token can be obtained by the At tach Accept message in the downlink of the mobile core network 33, and then the specific external data network to be connected is determined according to the APN provided by the UE. Or the mobile service, if the local bypass mode is adopted, it will provide the access token to the local fixed access network 32, request fixed access network resources and configuration information for the UE.
  • the HLR/AuC server 332 which is a mobile core management core database for the mobile core network system, stores user data of all mobile users in the HLR control area, for example, Information about the user and information about the user's current location;
  • the Authentication Center (AuC) is a device that is typically located in the HLR of a mobile core network system to authenticate attempts to connect to the network (usually when the phone is turned on) For each mobile user device (via its SIM card), to authenticate the identity of the mobile user and the functional entity that generates the corresponding authentication parameters, once this authentication is successful, the HLR is allowed to manage the SIM and the services described above.
  • the mobile user equipment UE 311 when attaching the Femtocel 312 for authentication, provides an authentication request message to the mobile core network 33 side, and the Femtocel 312 further attaches the message to the message.
  • the network parameter information of the own device in the fixed access network 32 such as its IP address in the fixed access network 32, and the like.
  • the AuC may check whether the message carries the network parameter information of the Femtocel in the fixed access network (for example, its IP address in the fixed access network 32, etc.), and may further Confirm the service attributes of the subscription (for example: HSI service through local bypass access mode); then, AuC requests the fixed access network 32 where Femtocel is located to allocate an access token for the UE to access the fixed access network.
  • the AuC 332 can interact with the authentication server in the fixed access network 32 using the standard Radius/Di ameter protocol: The AuC 332 provides the authentication server with the IP address of the Femtoce ll in the fixed access network 32 and obtains the access order.
  • AuC 332 then directly or indirectly provide the access token to Feratoce, for example: a related authentication protocol alert message, or a user saved to the local SGSN in Femtoce ll by the HLR in the Inser t Subscr iber Data mode. Management of the data, the related information will include one of the aforementioned access tokens.
  • a mobile user equipment UE 311 provides a location update request message to the mobile core network 33 side when attaching the Femtocel 312 for location update operation, and the Femtocel 312 further The network parameter information of its own device in the fixed access network, such as its IP address in the fixed access network 32, is attached to the message.
  • the HLR 332 checks whether the message carries the Femtoce ll, in addition to the normal operation of sending the canceled Locat i on signaling to notify the old SGSN to delete the UE related settings, etc.
  • Network parameter information in a fixed access network (eg, it is in the fixed access network 32)
  • the IP address, etc. further requests the fixed access network 32 where the Femtocell is located to allocate an access token for the UE to access the fixed access network, and the HLR 332 can directly or indirectly provide the Femtocell with the access in a specific manner.
  • the token for example: It feeds back related information of the UE to the management of the user data saved by the local SGSN in the FemoCell through Insert Subscriber Data signaling, and the related information will include one of the foregoing access tokens.
  • the SGSN function is all processed in the mobile core network, and when the AuC/HLR performs the authentication or location update operation, the fixed access network 32 is requested to allocate a UE for accessing the fixed access network. After the access token, send the access token to its client via Insert Subscriber Data signaling
  • the authentication server 322 is generally used to authenticate whether the client in the network has the right to access and provide network resources such as an IP address for the authenticated user.
  • the authentication server allocates an available client device for the specified client device according to the request from the mobile core network.
  • the access token for configuring the local network resource when the client device will provide the access token to the authentication server in the fixed access network, the authentication server verifies the read access token and configures the network resource for the client device .
  • the AAA authentication server will allocate a request message to the client Femtocell in the designated fixed access network 32 for the request message from the relevant network element device of the mobile core network 33.
  • the mobile user equipment UE 311 accesses the access token of the fixed access network 32.
  • the AAA server After receiving the resource request of the Femtocell, the AAA server authenticates the access token in the request message, and allocates an IP address and related network parameter configuration in the fixed access network, specifically,
  • the AAA server receives the Access-Request protocol generated by the client Femtocell, and the protocol can include the Femtocell IP address, the access token, etc.; the AAA server authenticates the user. If the authentication is successful, the AAA server sends the client
  • the Femtocell sends an Access-Accept protocol packet, otherwise it sends Access-Reject (Access Denied) protocol packet, the Access-Accept packet includes the newly allocated IP address and related network parameters and other network resource configurations.
  • the client sends Access-Accept protocol packet, otherwise it sends Access-Reject (Access Denied) protocol packet, the Access-Accept packet includes the newly allocated IP address and related network parameters and other network resource configurations.
  • the Femtocell After receiving the read protocol packet, the Femtocell can use the network resource configuration to establish a local bypass network service for the mobile user equipment UE 311.
  • the flow chart of the method for providing HSI network service based on the ⁇ micro base station according to the present invention with reference to FIG.
  • Step S401 the mobile user equipment UE moves into its home network 31.
  • the UE When the Femtocell (except for the special description, the Femtocell refers to the local SGSN function), the UE first sends an Attach request Femtocell, and the Femtocell requests the UE to provide IMSI through Identity Request signaling.
  • Step S402 the Femtocell sends a user authentication request and an Update Location request to update the SGSN address recorded by the UE in the HLR, and the Femtocel 1 can further add the corresponding fixed access network 32 information in the foregoing request message, for example:
  • the IP address of the FemoCell in the fixed access network 32 is attached to the uplink request message.
  • Step S403 the related network element device (HLR/AuC) in the mobile core network 33 obtains an access token that is available for the UE to obtain the resource configuration of the fixed access network 32 for network access from the authentication server in the fixed access network 32.
  • HLR/AuC related network element device
  • the AuC in the mobile core network 33 can further fix the fixed access by parsing the fixed access network information set by the Femtocell in the request message.
  • the authentication server in network 32 requests an access token that can be used by the UE to obtain the resource configuration of fixed access network 32 for network access.
  • the HLR in the mobile core network 33 further authenticates to the fixed access network 32 by parsing the fixed access network information set by the Femt oce 11 in the request message.
  • the server requests an access token, which can be used by the UE to obtain the resource configuration of the fixed access network 32 for network access. ask.
  • the AuC and HLR in the foregoing embodiment may interact with the authentication server in the fixed access network 32 using the standard Radius/Diameter protocol, and the AuC and HLR provide the authentication server with the IP address of the Femtocell in the fixed access network 32 and obtain the location.
  • the access token may be used to communicate with the authentication server in the fixed access network 32 using the standard Radius/Diameter protocol, and the AuC and HLR provide the authentication server with the IP address of the Femtocell in the fixed access network 32 and obtain the location.
  • the access token may interact with the authentication server in the fixed access network 32 using the standard Radius/Diameter protocol, and the AuC and HLR provide the authentication server with the IP address of the Femtocell in the fixed access network 32 and obtain the location. The access token.
  • Step S404 after obtaining the access token, the AuC/HLR may feed back related information of the UE to FemoCel 1 through the Insert Subscriber Data signaling, so that
  • FeraoCell establishes the MM Context.
  • FeraoCel 1 sends back an Insert Subscriber Data AC message to AuC/HLR for confirmation.
  • the related information of ⁇ includes one of the aforementioned access tokens in addition to the IMSI, the requested service, and the like.
  • Step S405 Femotocell agrees to register successfully and replies to the Attach Accept message to the UE.
  • the PS domain data service connection can be established to use the mobile data service, and the GMM mobility management program in the PS domain is also started. .
  • the Femtocell can intercept the Attach Accept message from the corresponding SGSN in the mobile core network 33 by implementing the NAS proxy, and the message carries the assigned access token.
  • Step S411 the establishment of the connection between the UE and the FemoCell and the transmission of the data packet are all performed by the PDP context request.
  • the UE first sends an activation PDP context request to open a new PDP context request to the FemoCell.
  • the request message includes: PDP Type, PDP Address, APN, QoS Reques ted and other parameter information, where the PDP Type parameter is used to indicate the connection of the data.
  • the IP type is IPv4 or IPv6.
  • the PDP Address parameter can be used to indicate the configuration of the IP address: When not set, it indicates that the IP address will be dynamically assigned by the network; otherwise, it is statically assigned.
  • the Femocell can use the APN provided by the UE to specify a specific external data network or mobile service to be connected.
  • the FemoCell local bypass service can be used, and the SGSN Proxy is implemented on the Femocell.
  • the APN of the NAS signaling is used to activate the bypass service.
  • the HSI service is used as an example. It can also be extended to, for example, ⁇ .
  • Step S412 A radio access bearer is set up, and different telecommunication services and bearer services require different radio bearers, and the UE initiates a request for establishing a radio access bearer.
  • Step S413, the Femtocell performs a mobile domain check.
  • the Femtocell determines that the mobile user equipment UE or its requested service can pass the local bypass, it will request the UE to secure the network resources of the access network 32, specifically
  • the RADIUS protocol sends an access request (Access Request) message to the authentication server in the fixed access network 32.
  • the access request message includes: an access token, an IP address of the Femtocell, and the like;
  • the AN access node
  • Step S414 After receiving the access request message, the authentication server in the fixed access network 31 checks the access token carried by the authentication server and the access location port information, and compares and verifyes the user information in the authentication server. After the authentication is passed, it sends an Access Accept message to its client Femtocell. The message includes: Deciding to assign an IP address.
  • the Femtocell request for the mobile access device UE to perform the fixed access network resource and the response process thereof may also be performed by using the DHCP protocol.
  • Step S415 the last Femtocell replies to the UE with a PDP context activation message, and the message includes: PDP Type, PDP Address, QoS Negotiated, and the like, wherein the PDP Address is an IP address in the configured fixed access network 32.
  • the UE enters the PDP. Activation status.
  • Step S421 after the UE enters the PDP activation state, it can access the service or external network resources through the fixed access network 32.
  • the UE enjoys the service that can be directly bypassed to the fixed access network at the Femtocell, the UE is visible to the fixed access network at the IP level, and the network operator can perform lawful interception or access to the fixed connection.
  • the HSI service provided by the network in addition, the quality of the service transmitted by the fixed access network can also be treated differently and guaranteed.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

一种向移动用户设备提供网络服务方法及其装置 技术领域
本发明涉及通信技术领域, 尤其涉及一种基于豪微蜂窝技术向移 动用户设备提供网络服务的方法及其装置。 背景技术
在目前无线通信技术中, 基于宏蜂窝小区的通信由于其所用无线 频率对建筑物的穿透特性较差, 因而会导致室内服务 ^量的下降, 而 且无线信道的负担也日趋紧张; 而且研究表明, 使用无线通信百分之 五十以上的语音业务和百分之七十以上的数据业务流量来自室内。
由此而来, 基于 Femtocel l (毫微蜂窝) 及其他类似技术的固定 移动融合网络的研究在业界成为了一个热点,一些针对家用和小型商 业单位应用的 Femtoce l l基站将移动用户设备 ( UE )通过现有的固定 接入网 (如 DSL或有线电视高速网络)提供 Internet (互联网络)服 务接入, 其接入方式有两种: (1 ) 业务数据流通过 Femtocel l 及其 专用网关 FGW之间的 IP安全隧道回传至移动核心网, 进而接再入到 Internet; ( 2 ) UE的一些特定业务数据流从 Femtocel 1处直接旁路 出, 通过固定接入网接入到 In t erne ts 下面我们将结合图例 1、 2进 行进一步说明。
图 1为一种典型的基于亳微基站提供网络服务系统结构例一回传 接入方式, UE—方面可通过陆地无线接入网(UTRAN)的接入移动核心 网络, UTRAN 包括无线基站 (NodeB ) 和无线网络控制器 ( RNC ) , 实现用户终端设备如移动电话、便携式计算机等提供到移动核心网络 的连接; 而当 UE移动进入其家庭网络中 Femtoce l l基站的覆盖范围 时, 它可通过固定接入网络所提供的宽带连接以 IP安全隧道的方式 通过 FGW 实现到移动核心网的连接, 进而通过移动核心网络实现 Internet的访问。 但是该解决方案存在如下的问题: 随着这些 Femt oce l l基站的大 量部署, 由于 UE所有的业务数据通过 IP安全隧道和 FGW回传至移动 核心网。对移动运营而言,虽然业务数据流量从宏蜂窝无线接入卸下, 但却没有成功地从移动核心网络中卸载掉, 随着移动用户对高速数据 业务 (例如: IPTV、 HS I等) 的需求增长, 所带来的数据流量对移动 核心网络是个问题,以 HNG为例, 它作为沟通 Femt oce l l与移动核心 网的门户, 它需要处理大量加密通道和管理用户进 /出 Femt oce l l 的 切换等;而对固定接入网絡得网络运营而言, Femt oce l l与 FGW之间的 回传利用了其宽带接入连接, 尤其是随着移动用户对高速数据业务的 应用增长, 对其带宽资源消耗更大, 而它却没有因此受益。
图 2为一种典型的基于亳微基站提供互联网服务系统结构例一本 地旁路解决方案, 当 UE移动进入其家庭网络中 Femtoce l l基站的覆 盖范围时, 它附着并与 Femtoce l l建立了一个 PDP (分组数据协议) 上下文, 进而得到其分配的本地私有 IP地址, 可访问其他家用设备、 或通过固定接入网络实现 Interne t的访问, 由此可减少通过 IP安全 隧道回传至移动核心网络的数据流量。
但是该解决方案存在如下的问题: 1)、 由于 得到 Femtoce l l 的本地私有 IP地址、 它隐藏在家庭网关后面, 如何对这些隐藏在家 庭网关后的 UE做合法侦听? 2)、 UE不能享受既定的服务策略, 不容 易扩展以在固定接入网络中莸得有差别的服务; 3)、 这不利于开放的 访问方案, 固定接入网络的运营商通常按照每个 DSL宽带连接对 HIS 等特定业务进行计费, 如此它不能获得为 UE所提供的网络资源信息 进而进行资费。 发明内容
本发明旨在解决前述一个或多个技术问题, 提供一种基于亳微蜂 窝技术向移动用户设备提供网络服务的技术方案, 亳微基站为所附着 的移动用户设备建立一个固定接入网絡的资源配置, 移动用户设备可 以谅资源配置建立 IP连接、通过固定接入网络来实现本地旁路访问。 根据本发明的一个方面,这里提供一种向移动用户设备提供网络 服务的方法, 移动用户设备通过亳微基站与一固定接入网络相连, 进 而连接至移动核心网, 包括如下步骤: al)、 移动核心网络向毫微基 站提供一个访问令牌; b)、 毫微基站以所述访问令牌请求固定接入网 絡为该移动用户设备进行网络资源配置; C)、 移动用户设备根据所述 网络资源配置建立网络服务连接。
根据本发明的另外一个方面,这里提供一种移动核心网络中的通 信设备, 包括: 接收装置,接收来自客户端的特定请求消息, 所述请 求消息包含其对应于固定接入网络中的一个可识別信息; 处理装置, 根据所述请求消息向固定接入网络中的认证服务器请求一个访问令 牌, 所述访问令牌可用于客户端获得固定接入网络的网络资源配置; 发送装置,向客户端提供所述访问令牌。
根据本发明的另外一个方面,这里提供一种亳微基站设备, 包括: 获取装置, 为移动用户设备获得一个可用于访问固定接入网絡的访问 令牌; 请求装置, 根据移动用户设备的上下文请求及所述访问令牌, 为其请求并配置固定接入网络资源并建立相应网络连接。
根据本发明的另外一个方面,这里提供一种固定接入网络中的认 证服务器, 包括: 分配装置, 根据来自移动核心网絡的请求, 为其分 配一个可用于配置本地网络资源的访问令牌; 认证装置, 接收来自本 地网络中客户端的请求, 对所携带的访问令牌进行验证并为所述客户 端进行网络资源配置。 本发明具有如下技术优势:
由于移动用户设备使用的固定接入网络所分配的网络资源, 例如 使用其 IP地址作为其 PDP地址, 进行网絡访问, 该移动用户设备对 固网运营商是可见的, 从技术上可保障有效地对旁路业务进行合法侦 听实现; 另外一方面, 根据移动用户设备业务属性的不同, 来实现不 同的访问接入方式, 其中, 通过本地旁路方式接入的业务可在固定接 入网络中可通过相应技术手段得到服务质量保障; 再者, 固定接入网 络的运营商可根据其为移动用户设备所分配的资源及占有(分配和释 放) 情况, 可实现与移动核心网的运营商在商业上的资费分摊。 附图说明
通过下面提出的结合附图的详细描述,本发明的特征、 性质和优 点将变得更加明显, 附图中相同的元件具有相同的标识, 其中:
图 1为基于毫微基站网络服务提供系统结构例一 (现有技术) ; 图 2为基于亳微基站网络服务提供系统结构例二 (现有技术) ; 图 3为本发明基于毫微基站网络服务提供系统结构实施例; 图 4为本发明基于毫微基站提供网络服务的方法流程实施例; 具体实施方式
下面结合附图, 对本发明的优选实施方式进行详细的说明。
如图 3所示意的本发明网络结构示意图, 它包括用户网络 31、 固定接入网络 32、 移动核心网络 33, 用户网络 31中的移动用户设备 UE 311有适用于 CDMA (码分多址)、 GSM (全球移动通信)、 UMTS (通用 移动通信系统) 等各种标准和支持 2G、 2. 5G、 3G的产品, 与运营商 的其它移动基站同制式、 同频段, UE 311可通过宏蜂窝 UTRAN (全球 陆上无线接入) 实现到移动核心网络 33的连接, 也可通过亳微蜂窝 Femtoce l l 312与 HGW 331之间的 IP安全隧道方式实现到移动核心网 络 33的连接。 HGW 331除了提供安全网关的功能、 建立 Femtoce l l 和 HGW之间的安全隧道, 它事实上扮演了一个虚拟的 RNC, 汇聚所有 受它控制的 Feratoce l l的流量, 向传统得移动核心核心网 33呈现标 准的接口功能。 Femtoce l l 312实现本地 GGSN (网关 GPRS支持节点) 功能以及本地 SGSN (服务 GPRS支持节点)功能(当然另外一种情形, 在 Femtoce l l处实现非接入层信令代理 NAS proxy, SGSN功能全在移 动核心网中处理) , 实现本地业务旁路直接通过固定接入网络 32进 行业务访问。
根据本发明所提供的一种实施例, 一个移动用户设备 UE 311在 移动进入其家庭网络中 Femtocel l 312的覆盖范围并试图附着在这 Femtocel l上时, 可通过前述 IP安全隧道进行用户认证、位置更新等 操作, Femtocel l可在其上行的请求消息中携带其于固定接入网络中 相关网络参数信息, 例如其在固定接入网络 32中的 IP地址等, 移动 核心网络 33中的相关网元设备, 例如 HLR /AuC (归属位置寄存器 / 鉴权中心) 可通过前述操作例对该 UE 311的用户身份进行认证、 业 务登记、 移动性管理等, 并结合 Femtocel l所提供的固定接入网络信 息, 它可进一步向 Femtoce l l所对应的固定接入网络 32请求一个访 问令牌并通过前述 IP安全隧道以特定方式发送给 UE 311 , Femtocel l 312即可获取其中的访问令牌, Femtocel l 312以所述访问令牌请求 固定接入网络 32中的认证服务器 322为谅 UE进行本地网络资源配置, 如此 UE可获得的一个固定接入网络 32中的 IP地址作为其 PDP(分组 数据协议) 地址通过固定接入网络 32直接接入到 Internet , 实现本 地旁路访问接入方式。
由于 UE 311使用固定接入网络 32所分配的 IP地址作为其 PDP 地址, 该 UE 311对固定接入网运营商是可见的, 从技术上可保障合 法侦听实现。 另外一方面, 根据业务属性的不同, Femtocel l可设置 优先级指示, 其服务质量可在固定接入网絡中可得到一定的保障; 相 反, 通过 IP安全隧道的业务数据在固定网络传送过程中的数据流则 不能得到相应的服务质量保障。 再者, 固定接入网络 32的运营商可 才艮据其为 UE311所分配的资源及占有情况, 例如: IP地址租赁时间、 网络带宽、 业务类型保证等因素, 来实现与移动核心网 32的运营商 在商业上的资费分摊。
下面我们将分别对本发明所提供的 Femtocel l 312、 HLR/AuC 服 务器 332、 认证服务器 322作进一步描述:
Femtocel l 312作为一个 NodeB,为移动用户设备 UE311提供标准 的空中接口,具体实现上可以为单独的设备,也可以和家庭网关( Home GW ) 集成在一起, 从功能上它还可包括 RNC (信令、 无线资源管理、 用户面移动性等功能)、 GGSN ( GGSN的会话管理、 计费接口等功能)、 以及 SGSN相关功能 (SGSN的鉴权认证、 会话管理、 计费、 信令、 用 户面移动性等功能) 等。
根据本发明所提供的一种 Femtocel l实施方式, Femtocel l 312 实现本地 SGSN功能, 它在收到 UE的附着请求时, 它要求 UE提供其 身份信息并通过所建立的 IP安全隧道向移动核心网络 33进行用户认 证请求, 如果认证成功, 它将进一步执行位置更新操作, Femtocel l 312可在上行的相关用户认证、 或位置更新消息附着其自身设备于固 定接入网络 32中的网络参数信息,例如其在固定接入网络 32中的 IP 地址等, 如此, 移动核心网络 33中相关设备可跨域访问相应的固定 接入网络 32中的认证服务器并荻得为该 UE分配的一个访问令牌; 之 后, Femtocel l 312将根据从移动核心网络 33获得 UE的相关信息建 立 MM Context (移动管理上下文), 相关信息在包括 IMSI (国际移动 用户识別码)、 所申请的服务等之外, 还将包括一个该 UE可用于访问 固定接入网络 32的访问令牌, 在 UE建立 IP连接、 请求特定业务时, FemoCel l 312将根据 UE的激活 PDP上下文请求、 前述匪 Context 等来决定采取何种访问接入方式 (本地旁路或 IP安全隧道连接) , 如果采取本地旁路方式, 它将向本地的固定接入网络 32提供该访问 令牌、 为该 UE请求固定接入网络资源及配置信息, 为该 UE获得的一 个固定接入网络 32中的 IP地址, 由此 UE所请求的特定业务将不再 通过 IP安全隧道回传到移动核心网, 而直接在 Femtocel l本地旁路 掉。
这里, 当 Femtocel l处实现 MS proxy, 可由其通过移动核心网 络 33下行的附着接受 (At tach Accept ) 消息获得访问令牌, 它再根 据 UE提供的 APN来决定其欲衔接的特定外部数据网路或者移动服务, 如果采取本地旁路方式, 它将向本地的固定接入网络 32提供该访问 令牌、 为该 UE请求固定接入网络资源及配置信息。
HLR/AuC服务器 332, HLR是移动核心网络系统的用于移动用户管 理核心数据库,存储着 HLR控制区内所有移动用户的用户数据, 例如, 有关用户的参数和有关用户目前所处位置的信息; 认证中心(AuC)是 一种设备, 通常位于一个移动核心网络系统的 HLR 中, 来鉴别试图 连接到该网络(通常当电话是开启时)的每个移动用户设备(可通过 其 SIM 卡) , 为认证移动用户的身份和产生相应鉴权参数的功能实 体, 一旦这个鉴定成功, HLR 被允许管理这个 SIM 和上述的服务。
根据本发明所提供的另外一种 AuC实施例,移动用户设备 UE 311 在附着 Femtocel l 312进行认证时, 它向移动核心网络 33侧提供一个 认证请求消息, Femtocel l 312进一步在该消息中附着其自身设备于 固定接入网络 32中的网络参数信息,例如其在固定接入网絡 32中的 IP地址等。 AuC在收到移动用户设备的认证请求消息时可检查该消息 是否携带 Femtocel l于固定接入网络中的网络参数信息(例如: 其在 固定接入网络 32中的 IP地址等) , 还可进一步确认其订购的业务属 性 (例如: 可通过本地旁路访问方式的 HSI业务) ; 之后, AuC请求 Femtocel l所在的固定接入网络 32为该 UE分配一个可用于访问固定 接入网络的访问令牌, AuC 332可使用标准的 Rad ius/Di ameter协议 与固定接入网络 32中的认证服务器进行交互: AuC 332向认证服务器 提供 Femtoce l l 于固定接入网络 32中的 IP地址并获得所述访问令 牌; AuC 332再通过特定方式直接或间接地向 Feratoce l l供所述访问令 牌, 例如:相关认证协议响症消息、或通过 HLR以 Inser t Subscr iber Data方式对 Femtoce l l 中本地 SGSN保存的用户数据的管理, 相关信 息将包括一个前述访问令牌。
根据本发明所提供的另外一种 HLR实施例, 一个移动用户设备 UE 311在附着 Femtocel l 312进行位置更新操作时, 它向移动核心网 络 33侧提供一个位置更新请求消息, Femtocel l 312进一步在该消息 中附着其自身设备于固定接入网络中的网络参数信息,例如其在固定 接入网络 32中的 IP地址等。 HLR 332在收到该位置更新请求消息时, 除了更新 SGSN位址外、 送出取消 Locat i on信令通知旧的 SGSN删除 UE的相关设定等常规操作之外, 它检查该消息是否携带 Femtoce l l 于固定接入网络中的网络参数信息 (例如: 其在固定接入网络 32中 的 IP地址等) , 进一步请求 Femtocell所在的固定接入网络 32为该 UE分配一个可用于访问固定接入网络的访问令牌, HLR 332可再通过 特定方式直接或间接地向 Femtocell供所述访问令牌, 例如: 它通过 Insert Subscriber Data信令将 UE的相关信息反馈给 FemoCell中本 地 SGSN保存的用戶数据的管理, 相关信息将包括一个前述访问令牌。
这里, 当 Femtocell处实现 NAS proxy, SGSN功能全在移动核心 网中处理, AuC/HLR在进行认证或位置更新操作时, 在请求固定接入 网络 32为该 UE分配一个可用于访问固定接入网络的访问令牌之后, 通过 Insert Subscriber Data信令将访问令牌发送至其客户端
- SGSN, SGSN通过附着接受 (Attach Accept ) 消息将访问令牌进一 步转发给 UE, Femtocell 中的 NAS proxy截获该 At ch Accept消息 种的访问令牌。 认证服务器 322, 通常用来认证网络中客户端是否有权接入并为 认证用户提供 IP地址等网络资源, 这里, 认证服务器根据来自移动 核心网络的请求, 为其指定的客户端设备分配一个可用于配置本地网 络资源的访问令牌; 当客户端设备将向固定接入网络中的认证服务器 提供该访问令牌, 认证服务器对读访问令牌进行验证并为所述客户 端设备进行网络资源配置。
根据本发明所提供的一种 AAA认证服务器实施例, 它将对来自移 动核心网络 33的相关网元设备的请求消息, 为指定的本固定接入网 32中的客户端 Femtocell分配一个可用于其移动用户设备 UE311 访问固定接入网络 32的访问令牌。 之后, AAA服务器在接收到该 Femtocell的资源请求时, 对请求消息中的访问令牌进行认证, 并为 其分配一个固定接入网絡中的 IP地址及相关网絡参数配置, 具体地,
AAA月良务器在收到客户端 Femtocell产生的 Access-Request (接入请 求) 协议4艮文, 该协议 ·ί艮文可包 Femtocell IP地址、 访问令牌等; AAA服务器对用户进行认证, 若认证成功, AAA服务器向客户端
Femtocell发送 Access- Accept (接入接受) 协议报文, 否则发送 Access-Reject (接入拒绝 )协议报文, Access-Accept报文中包括新 分配的 IP地址及相关网络参数等网络资源配置, 如此, 客户端
Femtocell在接收到读协议报文后, 可利用其中的网络资源配置为移 动用户设备 UE 311建立本地旁路网络服务。 下面我们将结合图 4对本发明基于亳微基站提供 HSI网络服务的 方法流程例进一步说明。
1、 UE附着 (Attach) 和认证
步骤 S401, 移动用户设备 UE在移动进入其家庭网絡 31中
Femtocell (除特殊说明外, 这里所指的 Femtocell实现本地 SGSN功 能)的覆盖范围时, UE首先发送 Attach 请求 Femtocell, Femtocell 通过身份请求 ( Identity Request )信令要求 UE提供 IMSI.
步骤 S402, Femtocell送出用户认证请求和位置更新 (Update Location)请求以更新 UE在 HLR记录的 SGSN位址, Femtocel 1可进一 步在前述请求消息中将其对应的固定接入网络 32信息, 例如:
FemoCell在固定接入网络 32中的 IP地址等附加在上行的请求消息 中。
步骤 S403, 移动核心网络 33中的相关网元设备(HLR/AuC) 从 固定接入网络 32中的认证服务器取得可用于 UE获得固定接入网絡 32 的资源配置以进行网络访问的访问令牌。
一种实施方式, 由移动核心网络 33中的 AuC在收到来自用户侧 的用户认证请求消息后,它通过解析请求消息中的 Femtocell设置的 固定接入网络信息, 可进一步向相应的固定接入网络 32中的认证服 务器请求访问令牌, 该访问令牌可用于 UE获得固定接入网络 32的资 源配置以进行网络访问。
一种实施方式, 由移动核心网络 33中的 HLR在收到用户位置更 新消息后,它通过解析请求消息中的 Femt oce 11设置的固定接入网络 信息, 进一步向固定接入网络 32中的认证服务器请求访问令牌, 该 访问令牌可用于 UE获得固定接入网络 32的资源配置以进行网络访 问。
前述实施方式中的 AuC、 HLR可使用标准的 Radius/Diameter协 议与固定接入网络 32中的认证服务器进行交互, AuC、 HLR向认证服 务器提供 Femtocell 于固定接入网络 32中的 IP地址并获得所述访问 令牌。
步骤 S404, 在获得所述访问令牌后, AuC/HLR可通过 Insert Subscriber Data信令将 UE的相关信息反馈给 FemoCel 1 , 以便
FeraoCell据此建立 MM Context, FeraoCel 1在建立该 UE的 MM Context 之后,回传一个 Insert Subscriber Data AC 讯息给 AuC/HLR进行 确认。 这里, ϋΕ的相关信息除了包括 IMSI、 所申请的服务等之外, 还包括一个前述访问令牌。
步骤 S405, Femotocell 同意注册成功并回复附着接受 (Attach Accept ) 消息至 UE, 完成 Attach后, 便可开始建立 PS领域数据 服务连线来使用移动数据服务,同时也开始执行 PS领域的 GMM移动管 理程序。
值得说明的是, 如果 Femtocell上不具有本地 SGSN功能, 它可 通过实现 NAS proxy截获来自移动核心网络 33中相应 SGSN的 Attach Accept消息, 由该消息中携带分配的访问令牌。
2. 启动 PDP上下文激活过程
步骤 S411, UE和 FemoCell之间连接的建立和数据包的传送都是 通过 PDP上下文请求来进行的。 UE首先发送激活 PDP上下文请求打开 一个到 FemoCell的新的 PDP上下文请求,请求消息包含: PDP Type, PDP Address, APN、 QoS Reques ted等参数信息, 其中, PDP Type参 数用来指示此数据连线的 IP型态为 IPv4或 IPv6, PDP Address参数 可用来指示 IP位址的配置方式: 当未设定时,表示将由网路动态指配 IP位址; 反之,则为静态指配方式。
根据本发明一实施方式, Femocell可藉 UE提供的 APN来指定欲 衔接的特定外部数据网路或者移动服务,例如,使用 ' HSI' APN将可使 用 FemoCell本地旁路服务, 在 Femocell上实现 SGSN Proxy以其识 别 NAS信令中有关激活旁路业务的 APN, 这里以 HSI服务为例说明, 也可以扩展到比如 ΙΠΎ等。
步骤 S412, 无线接入承载(Radio Access Bearer)建立, 不同的 电信业务和承载业务需要不同无线承载,UE发起的建立无线接入承载 的请求。
步骤 S413, Femtocell执行移动域检查,根据前述的 MM Context, 如果 Femtocell判断移动用户设备 UE或其所请求的服务可通过本地 旁路, 它将为 UE请求固定接入网络 32的网络资源, 具体地, 它以 RADIUS协议方式发送接入请求( Access Request )报文给固定接入网 络 32中的认证服务器,该接入请求报文中包括:访问令牌、 Femtocell 的 IP地址等信息; 网络侧的 AN (接入节点) 可以进一步在所述接入 请求报文中插入端口信息以向认证服务器提供准确的接入位置信息。
步骤 S414, 固定接入网络 31中的认证服务器在收到接入请求报 文后, 检查其携带的访问令牌、 以及接入位置端口信息等, 与认证服 务器中的用户信息进行对比验证, 在认证通过后, 它发送接入接受 ( Access Accept ) ^艮文给其客户端 Femtocell, 所述 4艮文包括: 决定 分配 IP地址。
值得说明的是, 前述步骤 313、 314中 Femtocell为移动用户设 备 UE进行固定接入网络资源请求及其响应过程也可以使用 DHCP协议 方式进行。
步骤 S415,最后 Femtocell以 PDP上下文激活消息回复 UE,其消 息包括: PDP Type, PDP Address, QoS Negotiated等参数, 其中的 PDP Address为所配置的固定接入网络 32中的 IP位址. UE进入 PDP 激活状态。
3. HSI网络服务提供
步骤 S421, UE 进入 PDP激活状悉之后, 它就可以通过固定接入 网络 32来存取服务或外部的网络资源。 如此, UE在 Femtocell处享 受能够直接旁路到固定接入网的业务时, UE对固定接入网在 IP层面 来说是可见的, 网络运营商可对其进行合法监听, 也可访问固定接入
II 网络提供的 HSI业务,另外, 其在固定接入网络的传送的业务质量也 可以区别对待, 得到保障。
尽管上述说明为本发明提供了一些实施例, 并非用来限定本发明 的保护范围, 本技术领域的专业人员可以在不脱离本发明的范围和精 神的前提下, 对实施例进行各种修改, 这种修改均属于本发明的范围 内。

Claims

权 利 要 求 书
1、 一种向移动用户设备提供网络服务的方法, 所述移动用户设 备通过毫微基站与一固定接入网络相连, 进而连接至移动核心网, 其 特征在于包括如下步骤:
al)、 移动核心网络向毫微基站提供一个访问令牌;
b)、 毫微基站以所述访问令牌请求固定接入网络为该移动用户设 备进行网络资源配置;
c)、 移动用户设备根椐所述网络资源配置建立网络服务连接。
2、 如权利要求 1所述的方法, 其特征在于所述步骤 a)进一步包 括: a O)移动核心网络基于来自用户侧的特定请求消息, 所述请求消 息包含一个对应于固定接入网络中的可识别信息 , 移动核心网络向固 定接入网络请求访问令牌。
3、 如权利要求 2所述的方法, 其特征在于所述步骤 aO)中移动核 心网络在收到移动用户设备认证请求消息时向固定接入网络请求访 问令牌。
4、 如权利要求 2所述的方法, 其特征在于所述步骤 a O)中移动核 心网络在收到移动用户设备位置更新请求消息时向固定接入网络请 求访问令牌。
5、 如权利要求 2所述的方法, 其特征在于所述步骤 al)中, 毫微 基站实现本地 SGSN功能, 移动核心网络通过插入用户数据方式将所 述访问令牌发送给亳微基站。
6、 如权利要求 1所述的方法, 其特征在于所述步骤 b)中所述网 络资源配置包括 IP地址分配及其相关网络参数配置。
7、 一种移动核心网络中的通信设备, 其特征在于包括: 接收装置: 接收来自客户端的特定请求消息, 所述请求消息包含 其对应于固定接入网絡中的一个可识别信息;
处理装置: 根据所述请求消息向固定接入网络中的认证服务器请 求一个访问令牌, 所述访问令牌可用于客户端获得固定接入网络的网 络资源配置;
发送装置: 向客户端提供所述访问令牌。
8、 如权利要求 7 所述的通信设备, 其特征在于所述接收装置所 接收的特定请求消息为用户认证请求消息、 用户位置位置更新请求消 息。
9、 如权利要求 7或 8所述的通信设备, 其特征在于所述发送装 置将所迷访问令牌以插入用户数据方式提供给客户端。
10、 如权利要求 7所述的通信设备, 其特征在于所述通信设备为 移动鉴权中心 (AuC ) 或归属位置寄存器 (HLR ) 。
11、 一种亳微基站设备, 其特征在于包括:
获取装置: 为移动用户设备获得一个可用于访问固定接入网络的 访问令牌;
请求装置: 根据移动用户设备的上下文请求及所述访问令牌, 为 其请求并配置固定接入网络资源并建立相应网络连接。
12、 如权利要求 11 任一权利要求所述的亳微基站设备, 其特征 在于所述获取装置进一步在移动用户设备上行请求消息中设置其于 固定接入网络中的网络参数信息。
13、 如权利要求 11或 12所述的亳微基站设备, 其特征在于所述 获取装置在移动用户设备进行用户认证请求时, 从移动核心网络获得 所述访问令牌。
14、 如权利要求 11或 12所述的毫微基站设备, 其特征在于所述 获取装置在移动用户设备进行位置更新请求时, 从移动核心网絡获得 所述访问令牌。
15、 一种固定接入网络中的认证服务器, 其特征在于包括: 分配装置: 根据来自移动核心网络的请求, 为其分配一个可用于 配置本地网络资源的访问令牌;
认证装置: 接收来自本地网络中客户端的请求, 对所携带的访问 令牌进行验证并为所述客户端进行网络资源配置。
PCT/CN2009/075821 2009-12-22 2009-12-22 一种向移动用户设备提供网络服务方法及其装置 WO2011075884A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
US13/513,241 US8880026B2 (en) 2009-12-22 2009-12-22 Method and apparatus for providing network services to a mobile user equipment
EP09852434.1A EP2518968B1 (en) 2009-12-22 2009-12-22 Method and devices for providing network service to a mobile user equipment
CN200980160776.7A CN102474500B (zh) 2009-12-22 2009-12-22 一种向移动用户设备提供网络服务方法及其装置
PCT/CN2009/075821 WO2011075884A1 (zh) 2009-12-22 2009-12-22 一种向移动用户设备提供网络服务方法及其装置

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2009/075821 WO2011075884A1 (zh) 2009-12-22 2009-12-22 一种向移动用户设备提供网络服务方法及其装置

Publications (2)

Publication Number Publication Date
WO2011075884A1 true WO2011075884A1 (zh) 2011-06-30
WO2011075884A8 WO2011075884A8 (zh) 2011-11-24

Family

ID=44194901

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/075821 WO2011075884A1 (zh) 2009-12-22 2009-12-22 一种向移动用户设备提供网络服务方法及其装置

Country Status (4)

Country Link
US (1) US8880026B2 (zh)
EP (1) EP2518968B1 (zh)
CN (1) CN102474500B (zh)
WO (1) WO2011075884A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104135541A (zh) * 2014-08-15 2014-11-05 宇龙计算机通信科技(深圳)有限公司 资源共享方法和资源共享系统

Families Citing this family (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8625487B2 (en) * 2007-11-15 2014-01-07 Ubeeairwalk, Inc. System, method, and computer-readable medium for mobile-originated voice call processing for a mobile station attached with an IP-femtocell system
US8547859B2 (en) * 2007-11-15 2013-10-01 Ubeeairwalk, Inc. System, method, and computer-readable medium for authentication center-initiated authentication procedures for a mobile station attached with an IP-femtocell system
US8705442B2 (en) * 2007-11-15 2014-04-22 Ubeeairwalk, Inc. System, method, and computer-readable medium for mobile station authentication and registration via an IP-femtocell
EP2194739B1 (en) * 2008-12-04 2015-03-25 Alcatel Lucent Conditional provision of location information by a femto cell
KR101453155B1 (ko) * 2012-05-30 2014-10-23 모다정보통신 주식회사 M2m 통신에서 리소스 접근 권한 설정 방법
KR101453154B1 (ko) * 2012-05-30 2014-10-23 모다정보통신 주식회사 M2m 통신에서 리소스 접근 권한 설정 방법
EP2878114B1 (en) * 2012-07-27 2020-06-03 Assa Abloy Ab Presence-based credential updating
CN102938940A (zh) * 2012-11-02 2013-02-20 中兴通讯股份有限公司 一种无线数据终端及其支持IPv4/IPv6双栈的方法
US9130904B2 (en) * 2013-05-08 2015-09-08 Texas Instruments Incorporated Externally and internally accessing local NAS data through NSFV3 and 4 interfaces
US20150350912A1 (en) * 2014-05-28 2015-12-03 Telefonaktiebolaget L M Ericsson (Publ) Residential service delivery based on unique residential apn
CN105992392B (zh) * 2015-01-28 2019-12-03 北京佰才邦技术有限公司 回传链路建立方法及装置
CN108307683B (zh) * 2015-11-30 2020-07-28 华为技术有限公司 通讯方法、微基站、微基站控制器、终端和系统
CN107656934B (zh) * 2016-07-25 2021-09-07 腾讯科技(深圳)有限公司 一种预加载方法、装置、设备
CN108377532B (zh) * 2016-11-16 2019-08-06 华为技术有限公司 一种数据连接方法、控制面节点以及用户设备
EP3550780B1 (en) * 2016-12-30 2021-04-14 Huawei Technologies Co., Ltd. Verification method and apparatus for key requester
CN112702244A (zh) 2018-04-09 2021-04-23 华为技术有限公司 接入服务网络的方法和通信装置
CN112135293B (zh) * 2019-06-24 2022-05-31 华为技术有限公司 通过固定接入设备接入移动核心网的方法
CN114040398A (zh) * 2020-07-21 2022-02-11 中国电信股份有限公司 服务质量保障提供方法、系统、网络设备和存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101136826A (zh) * 2007-09-30 2008-03-05 中兴通讯股份有限公司 一种通过核心网控制终端接入家庭基站覆盖区域的方法
US20080305772A1 (en) * 2007-06-07 2008-12-11 Qualcomm Incorporated Home base station
CN101340701A (zh) * 2007-07-02 2009-01-07 上海华为技术有限公司 毫微微小区的接入控制方法及基站

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030139180A1 (en) * 2002-01-24 2003-07-24 Mcintosh Chris P. Private cellular network with a public network interface and a wireless local area network extension
DE602007013701D1 (de) * 2007-04-17 2011-05-19 Alcatel Lucent Verfahren zur Verkoppelung eines Femto-Zellengeräts mit einem mobilen Kernnetzwerk
DE102007044972A1 (de) * 2007-09-19 2009-06-18 T-Mobile Internationale Ag Verfahren zur Herstellung einer Datenverbindung zwischen einem Mobilfunkendgerät und einem Computernetzwerk
JP2009253431A (ja) * 2008-04-02 2009-10-29 Alcatel-Lucent Usa Inc Iuインターフェースを有するUMTSフェムトセル解法においてPSトラフィックをオフロードする方法。
US8179847B2 (en) * 2008-05-13 2012-05-15 At&T Mobility Ii Llc Interactive white list prompting to share content and services associated with a femtocell
JP2009290282A (ja) * 2008-05-27 2009-12-10 Softbank Bb Corp 認証システム、認証方法
CN101316446B (zh) * 2008-07-30 2012-01-11 中国电信股份有限公司 移动用户在固定网络接入下鉴权认证的实现方法和系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080305772A1 (en) * 2007-06-07 2008-12-11 Qualcomm Incorporated Home base station
CN101340701A (zh) * 2007-07-02 2009-01-07 上海华为技术有限公司 毫微微小区的接入控制方法及基站
CN101136826A (zh) * 2007-09-30 2008-03-05 中兴通讯股份有限公司 一种通过核心网控制终端接入家庭基站覆盖区域的方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104135541A (zh) * 2014-08-15 2014-11-05 宇龙计算机通信科技(深圳)有限公司 资源共享方法和资源共享系统

Also Published As

Publication number Publication date
CN102474500B (zh) 2015-06-17
EP2518968A1 (en) 2012-10-31
US20120238247A1 (en) 2012-09-20
CN102474500A (zh) 2012-05-23
EP2518968B1 (en) 2020-01-22
EP2518968A4 (en) 2015-01-21
US8880026B2 (en) 2014-11-04
WO2011075884A8 (zh) 2011-11-24

Similar Documents

Publication Publication Date Title
WO2011075884A1 (zh) 一种向移动用户设备提供网络服务方法及其装置
KR101545879B1 (ko) 이용자 엔티티에 네트워크 액세스를 제공하기 위한 방법 및 장치
US9549317B2 (en) Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network
KR101899182B1 (ko) Eps의 이동 라우터
US20110111767A1 (en) Method of call admission control for home femtocells
WO2013016968A1 (zh) 一种接入方法、系统及移动智能接入点
US9241297B2 (en) Method and apparatus for providing local breakout service in wireless communication system
WO2010015188A1 (zh) 接入点接入移动核心网的方法、设备及系统
WO2015196396A1 (zh) 建立网络连接的方法、网关及终端
WO2010130174A1 (zh) 一种实现本地访问控制的方法及相应的通信系统
KR102362078B1 (ko) 1차 단말을 통하여 전용망에 접속하는 2차 단말의 전용망 접속을 제어하는 서버 및 그 1차 단말
WO2014005267A1 (zh) 接入移动网络的方法、装置及系统
JP2018512788A (ja) トラフィックフロー分割方法およびトラフィックフロー分割装置
TW202234940A (zh) 與第三層無線傳輸/接收單元到網路相關認證及授權
WO2013174190A1 (zh) 路由选择方法及功能网元
WO2018058691A1 (zh) 一种建立公用数据网连接的方法及相关设备
WO2008095433A1 (fr) Procédé, dispositif et système assurant un service d'urgence
WO2012130133A1 (zh) 一种接入点及终端接入方法
KR101727557B1 (ko) 무선통신시스템에서 엘비오 서비스를 제공하기 위한 방법 및 장치
WO2012171430A1 (zh) 隧道信息获取方法、安全网关及演进家庭基站/家庭基站
WO2010091562A1 (zh) 用于固定网络与第三方网络或应用服务器交互的方法及装置
WO2012024997A1 (zh) 一种控制业务接纳的方法及系统
WO2012152102A1 (zh) 一种用户信息的通知方法及系统
WO2014121613A1 (zh) 一种位置信息的获取方法及相应装置
CN113498055B (zh) 接入控制方法及通信设备

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200980160776.7

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09852434

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 13513241

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2009852434

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE