WO2011088653A1 - 一种分组数据服务节点的分配方法及系统 - Google Patents

一种分组数据服务节点的分配方法及系统 Download PDF

Info

Publication number
WO2011088653A1
WO2011088653A1 PCT/CN2010/073850 CN2010073850W WO2011088653A1 WO 2011088653 A1 WO2011088653 A1 WO 2011088653A1 CN 2010073850 W CN2010073850 W CN 2010073850W WO 2011088653 A1 WO2011088653 A1 WO 2011088653A1
Authority
WO
WIPO (PCT)
Prior art keywords
pdsn
terminal
information
base station
address
Prior art date
Application number
PCT/CN2010/073850
Other languages
English (en)
French (fr)
Inventor
魏铮
翟来国
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2011088653A1 publication Critical patent/WO2011088653A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities

Definitions

  • the present invention relates to a code division multiple access (CDMA) 2000 lxEV-DO system in the field of communications, and more particularly to a method and system for allocating packet data serving nodes (PDSN) in a CDMA2000 lxEV-DO system.
  • CDMA code division multiple access
  • PDSN packet data serving nodes
  • the connection establishment process of the data service in the CDMA2000 lxEV-DO system includes: an air interface connection establishment process and a point-to-point protocol (PPP) link establishment process, and the specific implementation process is as follows: The terminal dials up to start a data service, and then establishes an air interface connection with the base station, the base station Allocating radio resources to the terminal and establishing a physical bearer link with the terminal; after the air interface connection is established, the base station allocates the terminal
  • the PDSN establishes a PPP link between the terminal and the PDSN, completes the packet-switched data network to verify the validity of the terminal access, and assigns an IP address to the terminal to complete the establishment of the data service link.
  • the PDSN is a gateway device between the wireless network and the packet-switched data network.
  • the terminal accesses the wireless network through PPP and provides the next hop route for the packet data packet, thereby realizing data transmission between the wireless network and the packet-switched data network.
  • PPP Packet Control Protocol
  • the base station needs to allocate a PDSN to the terminal, which is specifically:
  • the wireless network is generally connected.
  • the multiple PDSNs are divided into multiple groups according to the priority, that is, the PDSNs of each group belong to the same priority.
  • the base station After the terminal accesses the wireless network and completes the establishment of the air interface connection, the base station allocates the PDSN group with the highest priority to the terminal. After all PDSNs in the highest PDSN group are overloaded, the terminal will be assigned a PDSN with a relatively lower priority. After the PDSN group is determined, the terminal's International Mobile Subscriber Identity (IMSI) is used for hash operation. The PDSN assigned to the terminal completes the establishment of a subsequent data service link. The existing base station allocates a PDSN to the terminal, and the PDSN to which the terminal is allocated is random, that is, in different data services, the terminal is allocated by the base station each time due to the priority of the PDSN.
  • IMSI International Mobile Subscriber Identity
  • each PDSN may be connected to different packet network entities or different charging systems, and the utility scope and policies of different packet network entities or different charging systems are not identical. Therefore, if the PDSNs corresponding to the terminals in different data services are randomly changed, it is not conducive to the operator performing various management operations such as charging on the terminal. Summary of the invention
  • the main purpose of the present invention is to provide a PDSN allocation method and system, so that a terminal can be allocated to a specific PDSN in different data services, which facilitates operator management of the terminal.
  • the present invention provides a method for allocating a PDSN, and the network authentication entity configures and stores the corresponding PDSN information for each terminal.
  • the method further includes:
  • the network authentication entity After the data service is started, the network authentication entity adds the retrieved PDSN information corresponding to the terminal to the authentication response message and returns it to the base station, and the base station allocates the corresponding PDSN to the terminal according to the received PDSN information.
  • the PDSN information is: a number of the PDSN or an IP address of the PDSN.
  • the method further includes: the base station configuring a corresponding number for each PDSN and storing the same.
  • the method for the network authentication entity to configure the corresponding PDSN information for each terminal is: the network authentication entity allocates the corresponding network access identifier NAI to the terminal, and configures the corresponding PDSN information for the terminal; or
  • the method for adding the PDSN information in the authentication response message is:
  • the character attribute in the RADIUS carries the PDSN information
  • the base station configures a corresponding number for each PDSN as: a corresponding number for each IP address of the PDSN;
  • the base station allocates the corresponding PDSN to the terminal according to the received PDSN information: after receiving the authentication response message returned by the network authentication entity, the base station parses the number of the PDSN in the message, and allocates the PDSN to the terminal at the base station.
  • the IP address of the corresponding PDSN is found in the stored configuration result according to the number of the PDSN in the authentication response message, and is allocated to the terminal.
  • the base station allocates the corresponding PDSN to the terminal according to the received PDSN information: After the base station receives the authentication response message returned by the network authentication entity, The IP address of the PDSN in the message is parsed. When the base station allocates the PDSN to the terminal, the PDSNo is allocated to the terminal according to the IP address of the parsed PDSN.
  • the present invention also provides a PDSN distribution system, the system comprising: a network authentication entity and a base station;
  • the network authentication entity is configured to configure corresponding PDSN information for each terminal, and store the configuration result. After the data service is started, add the retrieved PDSN information corresponding to the terminal and return the information in the authentication response message. To the base station;
  • the base station is configured to allocate a corresponding PDSN to the terminal according to the PDSN information sent by the network authentication entity.
  • the PDSN information is: a number of the PDSN or an IP address of the PDSN.
  • the base station when the PDSN information is a number of a PDSN, the base station is further used for each The PDSN configures the corresponding number and stores the configuration result.
  • the base station allocates the corresponding PDSN to the terminal according to the received PDSN information: after receiving the authentication response message returned by the network authentication entity, parsing the number of the PDSN in the message, when assigning the PDSN to the terminal, Finding an IP address of the corresponding PDSN in the stored configuration result according to the number of the PDSN in the authentication response message, and assigning the IP address to the terminal;
  • the base station allocates the corresponding PDSN to the terminal according to the received PDSN information: After receiving the authentication response message returned by the network authentication entity, parsing the IP of the PDSN in the message Address: When the PDSN is allocated to the terminal, the PDSN is allocated to the terminal according to the IP address of the parsed PDSN.
  • the method and system for allocating a PDSN provided by the present invention, the network authentication entity configuring corresponding PDSN information for each terminal and storing; after the data service is started, the network authentication entity adds the retrieved corresponding to the terminal in the authentication response message
  • the PDSN information is returned to the base station, and the base station allocates the corresponding PDSN to the terminal according to the received PDSN information.
  • the operator can configure the corresponding PDSN information for the different terminals through the network authentication entity according to the requirements of the network.
  • the network authentication entity can notify the base station of the PDSN information that has been stored for the terminal.
  • the base station allocates the corresponding PDSN to the terminal based on the PDSN information. It can be seen that, as long as the configuration information stored in the network authentication entity does not change, the PDSN allocated by the base station to the terminal in each data service is fixed. It is convenient for operators to manage terminals.
  • FIG. 1 is a schematic flowchart of an implementation method of a PDSN allocation method according to the present invention
  • FIG. 2 is a schematic diagram of a process for starting a data service to authenticate a terminal according to the present invention
  • FIG. 3 is a schematic diagram of a specific implementation process of a base station for allocating a PDSN to a terminal according to the present invention
  • FIG. 4 is a schematic structural diagram of a PDSN allocation system according to the present invention. detailed description
  • the basic idea of the present invention is: a network authentication entity configures corresponding PDSN information for each terminal and stores it; after the data service is started, the network authentication entity adds the retrieved PDSN information corresponding to the terminal in the authentication response message and Returning to the base station, the base station allocates the corresponding PDSN to the terminal according to the received PDSN information.
  • the PDSN information may be: a number of the PDSN or an IP address of the PDSN. If the PDSN information is the number of the PDSN, the method further includes: the base station configuring a corresponding number for each PDSN and storing the network authentication entity;
  • the existing system can be an access network authentication, authorization and accounting server (AN-AAA).
  • FIG. 1 is a schematic flowchart of an implementation method of a PDSN allocation method according to the present invention. As shown in FIG. 1, the implementation steps of the process are as follows:
  • Step 101 The base station configures a corresponding number for each PDSN and stores it, and the network authentication entity configures the corresponding PDSN number for each terminal and stores it.
  • the base station configures a corresponding number for each PDSN, and stores the configuration result.
  • the number corresponds to the IP address of each PDSN.
  • the network authentication entity such as AN-AAA, needs to configure a corresponding PDSN for each terminal. That is, the terminal corresponds to the number of the PDSN, and the configuration result is stored, and the method for configuring the corresponding number of the PDSN for each terminal may be: when the network authentication entity assigns a number to the terminal, the network access identifier is allocated to the terminal.
  • NAI the corresponding PDSN number
  • the corresponding PDSN number can be configured for the terminal at the same time; or, the corresponding PDSN number can be configured for the IMSI of each terminal; or, the corresponding domain name can be set for the NAI of different terminals, such as: ***@cheron. Com.ao, or ***@moninet.com.ao, etc., corresponding to different domain names and PDSN numbers, wherein the *** is a string information of the terminal, such as an electronic serial number (ESN), etc.
  • ESN electronic serial number
  • the network authentication entity when performing the authentication operation, can find the corresponding domain name according to the NAI of the terminal, and retrieve the number of the PDSN corresponding to the domain name.
  • the PDSN information is the IP address of the PDSN, the same method may be used to configure the IP address of the corresponding PDSN for each terminal.
  • the operator may configure a corresponding PDSN number for the terminal according to its own requirements, such as: a specific charging method is required for some terminals, so that the terminal is configured to be in the actual application process. Perform various management operations such as billing.
  • Step 102 After the data service is started, the network authentication entity adds the retrieved number of the PDSN corresponding to the terminal to the authentication response message and returns it to the base station.
  • the network authentication entity selects the number of the PDSN corresponding to the terminal in the number of the stored PDSN, and adds the number of the PDSN to the authentication response.
  • the message is sent to the base station.
  • the method for adding the number of the PDSN in the authentication response message may be: carrying a PDSN number, such as a RADIUS protocol, by using a character attribute in a remote user dialing authentication protocol (RADIUS) used in the existing authentication process.
  • a PDSN number such as a RADIUS protocol
  • RADIUS remote user dialing authentication protocol
  • the IP address of the PDSN can be added to the authentication response message in the same manner.
  • Step 103 The base station allocates the corresponding PDSN to the terminal according to the received number of the PDSN. Specifically, after receiving the authentication response message returned by the network authentication entity, the base station parses the number of the PDSN in the message, and allocates the number of the PDSN in the message to the terminal. In the case of the PDSN, the IP address of the corresponding PDSN is found in the stored configuration result according to the number of the PDSN in the authentication response message, and is allocated to the terminal.
  • the process of starting from the data service to authenticating the terminal in step 102 is as shown in FIG. 2, and includes the following steps:
  • Step 201 The terminal establishes a session with the base station, and establishes an air interface connection with the base station. Specifically, the terminal establishes a session connection with the base station after the terminal is powered on, and the terminal and the base station perform the configuration negotiation operation of the air interface attribute, and specify the protocol subtypes of each layer of the air interface and each Protocol related parameters, eventually Complete the establishment of the traffic channel. This step is prior art and will not be described in detail herein.
  • Step 202 The base station performs a PPP link establishment operation with the terminal, and performs a Challenge Handshake Authentication Protocol (CHP) authentication with the terminal.
  • CHP Challenge Handshake Authentication Protocol
  • the base station sends a link control protocol (LCP) configuration request to the terminal to perform CHAP authentication on the terminal.
  • LCP link control protocol
  • the base station After receiving the terminal, the base station also sends an LCP configuration request to the base station and responds to the LCP configuration request of the base station.
  • LCP negotiation After the two-way LCP negotiation is completed, The establishment of the chain is completed; the base station sends the CHAP message carrying the authentication code to the terminal, and the terminal parses the authentication code after receiving the packet, and encrypts the terminal password with the authentication code, and then carries the NAI and the encrypted password when the terminal is placed.
  • the CHAP response message is fed back to the base station. This step is prior art.
  • Step 203 The base station encodes the NAI and the encrypted password carried in the CHAP authentication response message sent by the terminal into an authentication request message, and sends the message to the network authentication entity.
  • the base station After receiving the CHAP authentication response message sent by the terminal, the base station parses the NAI and the encrypted password of the terminal carried in the message, and encodes the information together with the authentication code into an authentication request in a Radius packet format.
  • the message is sent to the network authentication entity.
  • the implementation of this step is prior art.
  • Step 204 The network authentication entity authenticates the terminal according to the NAI and the encrypted password in the authentication request message. If the authentication succeeds, the number of the PDSN corresponding to the terminal is retrieved, and the number of the PDSN is added to the authentication. Returning to the base station in the success response message; if the authentication fails, returning the authentication failure response message to the base station;
  • the network authentication entity parses the authentication request message, obtains the NAI and the encrypted password of the terminal, and retrieves the local or remote database according to the NAI and the encrypted password of the terminal, and determines When the terminal already exists and the encryption password is correct, that is, when the terminal passes the authentication, the number of the PDSN corresponding to the terminal NAI is selected in the number of the stored PDSN, and the numbers of the IMSI and the PDSN allocated for the terminal are combined into a reference.
  • the right success response message is returned to the base station; if the authentication fails, the authentication failure response message is returned to Base station.
  • the IMSI is information that has been carried in the response message returned by the network authentication entity in the prior art after the terminal passes the authentication.
  • the authentication process performed by the network authentication entity on the terminal is prior art.
  • Step 103 The process of the base station assigning the corresponding PDSN to the terminal is specifically as shown in FIG. 3, and includes the following steps:
  • Step 301 The base station determines that the authentication response message is received. If it is an authentication success response message, parses and saves the number of the IMSI and the PDSN carried in the message, and continues to perform step 302. If the authentication fails the response message, the step is performed. 304;
  • the base station determines the type of the authentication response message according to different signaling when the network authentication entity sends the authentication response message, and if it is the authentication success response message, parses the IMSI and the PDSN number carried in the message and saves; In order to authenticate the failure response message, the current PDSN allocation process is ended.
  • Step 302 The base station performs a PPP teardown operation with the terminal.
  • Step 303 The base station allocates the corresponding PDSN to the terminal according to the number of the parsed PDSN.
  • the base station finds the IP address of the corresponding PDSN in the stored configuration result according to the parsed PDSN number, and sends an All Registration Request message carrying the terminal IMSI to the PDSN according to the IP address of the found PDSN, that is, the completion is completed.
  • the process by which the base station allocates a PDSN to the terminal is completed.
  • Step 304 The PDSN allocation process ends.
  • the PDSN returns an All registration response message, so that the A10 link is established, the PDSN initiates a connection request for the PPP link to the terminal, performs a subsequent PPP link establishment process, and completes the establishment of the data service link.
  • the network authentication entity configures the corresponding PDSN information for each terminal to be the IP address of the PDSN, then the base station does not need to perform the configuration operation described in step 101 before the data service is started, after the data service is started, The network authentication entity adds the retrieved IP address of the PDSN corresponding to the terminal to the base station in the authentication response message, and returns the base station to the base station according to the received IP address of the PDSN.
  • the retrieval process after the base station receives the authentication response message is omitted, and the Al l registration request message carrying the terminal IMSI is directly sent to the PDSN.
  • the present invention further provides a PDSN distribution system.
  • the system includes: a network authentication entity and a base station;
  • the network authentication entity is configured to configure corresponding PDSN information for each terminal, and store the configuration result. After the data service is started, add the retrieved PDSN information corresponding to the terminal and return the information in the authentication response message. To the base station;
  • the network authentication entity configures the corresponding PDSN information for each terminal, and stores the configuration result.
  • the terminal authenticates the terminal after receiving the authentication request message sent by the base station. After the terminal is successfully authenticated, the PDSN information corresponding to the terminal is retrieved in the stored PDSN information, and the retrieved PDSN information is returned to the base station.
  • the base station is configured to allocate a corresponding PDSN to the terminal according to the PDSN information sent by the network authentication entity.
  • the base station first establishes an air interface connection with the terminal, and completes the PPP link establishment operation with the terminal, performs CHAP authentication with the terminal, and carries the NAI carried in the CHAP authentication response message sent by the terminal.
  • Encoding and encrypting the password into an authentication request message is sent to the network authentication entity; after receiving the PDSN information sent by the network authentication entity after determining the successful authentication of the terminal, first performing PPP de-linking operation with the terminal, and then according to the PDSN information
  • the corresponding PDSN is assigned to the terminal.
  • the base station is further configured to: configure a corresponding number for each PDSN, and store the configuration result, where the number corresponds to the IP address of each PDSN;
  • the base station allocates the corresponding PDSN to the terminal according to the received PDSN information, specifically:
  • the number of the PDSN in the message is parsed.
  • the PDSN is allocated to the terminal, the corresponding PDSN is found in the stored configuration result according to the number of the PDSN in the authentication response message. IP address, and assigned to the terminal;
  • the base station allocates the corresponding PDSN to the terminal according to the received PDSN information, specifically:
  • the IP address of the PDSN in the message is parsed.
  • the PDSNo is allocated to the terminal according to the IP address of the parsed PDSN.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种分组数据服务节点(PDSN)的分配方法,网络鉴权实体为各终端配置对应的PDSN信息并存储;还包括:数据业务启动后,网络鉴权实体在鉴权响应消息中添加检索到的与所述终端对应的PDSN信息并返回给基站,基站根据收到的PDSN信息将相应的PDSN分配给终端。本发明还同时公开了一种PDSN的分配系统,运用该方法和系统使得终端在不同的数据业务中可被分配到特定的PDSN,便于运营商对终端的管理。

Description

一种分组数据服务节点的分配方法及系统 技术领域
本发明涉及通信领域中的码分多址(CDMA ) 2000 lxEV-DO系统, 尤 其涉及一种 CDMA2000 lxEV-DO系统中分组数据服务节点 (PDSN ) 的分 配方法及系统。 背景技术
CDMA2000 lxEV-DO系统中数据业务的连接建立过程包括: 空口连接 建立过程和点到点协议(PPP )链路建立过程, 具体实现流程如下: 终端拨 号启动数据业务, 之后与基站建立空口连接, 基站为终端分配无线资源, 并建立与终端间的物理承载链路; 空口连接建立完成后, 基站为终端分配
PDSN, 终端与该 PDSN建立两者间的 PPP链路, 完成分组交换数据网对 终端接入合法性的校验、并为终端分配 IP地址,完成数据业务链路的建立。
PDSN是无线网络与分组交换数据网之间的网关设备, 通过 PPP将终 端接入无线网络并为分组数据报文提供下一跳的路由, 实现无线网络与分 组交换数据网间的数据传递。 在实际的网络结构中, 通常一个无线网络连 接多个 PDSN, 因此, 终端在接入分组交换数据网后, 基站需为终端分配 PDSN, 具体为: 在现有应用过程中, 一般将无线网络连接的多个 PDSN按 优先级分成多个组, 即每个组的 PDSN属于同一优先级, 终端在接入无线 网络并完成空口连接建立后, 基站将为终端分配优先级最高的 PDSN组, 当优先级最高的 PDSN组中所有 PDSN均过载后, 才会为终端分配优先级 相对较低的 PDSN组, 确定了 PDSN组后, 利用终端的国际移动用户识别 码(IMSI )进行哈希运算, 最终选定分配给该终端的 PDSN, 完成后续数 据业务链路的建立。 现有的上述基站为终端分配 PDSN的方法,将使终端被分配到的 PDSN 是随机的, 也就是说, 在不同的数据业务中, 由于 PDSN存在优先级的问 题, 使得终端每次被基站分配到的 PDSN不同, 而在实际商用过程中, 各 PDSN可能连接不同的分组网络实体或者不同的计费系统等,且不同的分组 网络实体或不同的计费系统的效用范围和策略并不完全相同, 因此, 如果 不同数据业务中终端对应的 PDSN是随机变化的, 则不利于运营商对终端 执行计费等多种管理操作。 发明内容
有鉴于此, 本发明的主要目的在于提供一种 PDSN的分配方法及系统, 使得终端在不同的数据业务中可被分配到特定的 PDSN,便于运营商对终端 的管理。
为达到上述目的, 本发明的技术方案是这样实现的:
本发明提供了一种 PDSN的分配方法, 网络鉴权实体为各终端配置对 应的 PDSN信息并存储; 该方法还包括:
数据业务启动后, 网络鉴权实体在鉴权响应消息中添加检索到的与所 述终端对应的 PDSN信息并返回给基站, 基站根据收到的 PDSN信息将相 应的 PDSN分配给终端。
其中, 所述 PDSN信息为: PDSN的编号或 PDSN的 IP地址。
其中, 所述 PDSN信息为 PDSN的编号时, 该方法进一步包括: 基站 为各 PDSN配置对应的编号并存储。
其中, 所述网络鉴权实体为各终端配置对应的 PDSN信息的方法为: 网络鉴权实体在为终端分配网络接入标识 NAI的同时, 为终端配置对 应的 PDSN信息; 或者,
为各终端的 IMSI配置对应的 PDSN的编号; 或者,
为各终端的 NAI设置对应的域名, 再令不同的域名与 PDSN信息相对 应。
其中, 所述在鉴权响应消息中添加 PDSN信息的方法为:
利用鉴权过程中采用的远程用户拨号认证协议 RADIUS中的字符属性 携带 PDSN信息; 或者,
通过自定义属性携带 PDSN信息。
上述方案中, 所述基站为各 PDSN配置对应的编号为: 为各 PDSN的 IP地址配置对应的编号;
相应的, 所述基站根据收到的 PDSN信息将相应的 PDSN分配给终端 为: 基站收到网络鉴权实体返回的鉴权响应消息后, 解析消息中的 PDSN 的编号, 在基站为终端分配 PDSN时, 根据鉴权响应消息中的 PDSN的编 号在已存储的配置结果中找到相应的 PDSN的 IP地址, 并分配给终端。
上述方案中, 所述 PDSN信息为 PDSN的 IP地址时, 相应的, 所述基站根据收到的 PDSN信息将相应的 PDSN分配给终端为: 基站 收到网络鉴权实体返回的鉴权响应消息后,解析消息中的 PDSN的 IP地址, 在基站为终端分配 PDSN时, 根据解析所得的 PDSN的 IP地址为终端分配 PDSNo
本发明还提供了一种 PDSN的分配系统, 该系统包括: 网络鉴权实体 和基站; 其中,
所述网络鉴权实体, 用于为各终端配置对应的 PDSN信息, 并将配置 结果存储, 在数据业务启动后, 在鉴权响应消息中添加检索到的与所述终 端对应的 PDSN信息并返回给基站;
所述基站, 用于根据网络鉴权实体所发的 PDSN信息将相应的 PDSN 分配给终端。
其中, 所述 PDSN信息为: PDSN的编号或 PDSN的 IP地址。
其中, 所述 PDSN信息为 PDSN的编号时, 所述基站进一步用于为各 PDSN配置对应的编号, 并将配置结果存储;
相应的, 所述基站根据收到的 PDSN信息将相应的 PDSN分配给终端 为: 收到网络鉴权实体返回的鉴权响应消息后, 解析消息中的 PDSN的编 号, 在为终端分配 PDSN时, 根据鉴权响应消息中的 PDSN的编号在已存 储的配置结果中找到相应的 PDSN的 IP地址, 并分配给终端;
所述 PDSN信息为 PDSN的 IP地址时, 所述基站根据收到的 PDSN信 息将相应的 PDSN分配给终端为: 收到网络鉴权实体返回的鉴权响应消息 后, 解析消息中的 PDSN的 IP地址, 在为终端分配 PDSN时, 根据解析所 得的 PDSN的 IP地址为终端分配 PDSN。
本发明提供的 PDSN的分配方法及系统, 网络鉴权实体为各终端配置 对应的 PDSN信息并存储; 数据业务启动后, 网络鉴权实体在鉴权响应消 息中添加检索到的与所述终端对应的 PDSN信息并返回给基站, 基站根据 收到的 PDSN信息将相应的 PDSN分配给终端。 本发明中, 运营商可根据 自身的需求通过网络鉴权实体为不同终端配置对应的 PDSN信息, 在后续 数据业务中, 网络鉴权实体可将自身已存储的为终端配置的 PDSN信息通 知基站, 基站以此 PDSN信息为依据为终端分配对应的 PDSN, 可见, 只要 网络鉴权实体内存储的配置信息不改变, 那么, 在每次数据业务中基站为 终端分配的 PDSN则是固定不变的, 便于运营商对终端的管理。 附图说明
图 1为本发明 PDSN的分配方法实现流程示意图;
图 2 为本发明所述从数据业务启动到对终端进行鉴权的流程实现示意 图;
图 3为本发明所述基站为终端分配 PDSN的具体实现流程示意图; 图 4为本发明 PDSN的分配系统结构示意图。 具体实施方式
本发明的基本思想是: 网络鉴权实体为各终端配置对应的 PDSN信息 并存储; 数据业务启动后, 网络鉴权实体在鉴权响应消息中添加检索到的 与所述终端对应的 PDSN信息并返回给基站, 基站根据收到的 PDSN信息 将相应的 PDSN分配给终端。
这里, 所述 PDSN信息可为: PDSN的编号或 PDSN的 IP地址, 如果 PDSN信息为 PDSN的编号时, 该方法进一步包括: 基站为各 PDSN配置 对应的编号并存储; 所述网络鉴权实体为现有系统, 可为接入网鉴权、 授 权与计帐服务器(AN-AAA )。
下面以 PDSN信息为 PDSN的编号为例对本发明作进一步详细说明。 图 1为本发明 PDSN的分配方法实现流程示意图, 如图 1所示, 该流 程的实现步驟如下:
步驟 101 : 基站为各 PDSN配置对应的编号并存储, 网络鉴权实体为各 终端配置对应的 PDSN的编号并存储;
具体为: 基站为各 PDSN配置对应的编号, 并将配置结果存储, 这里, 所述编号与各 PDSN的 IP地址对应; 此外, 网络鉴权实体, 如 AN- AAA 需为各终端配置对应的 PDSN, 即令终端与 PDSN的编号相对应,并存储配 置结果, 所述为各终端配置对应的 PDSN的编号的方法可为: 网络鉴权实 体在为终端放号时, 即为终端分配网络接入标识( NAI )时, 可同时为终端 配置对应的 PDSN的编号; 或者, 为各终端的 IMSI配置对应的 PDSN的编 号; 或者, 为不同终端的 NAI设置对应的域名, 如: ***@cheron.com.ao、 或 ***@moninet.com.ao等, 再将不同的域名和 PDSN的编号相对应, 其中, 所述 ***为终端的字符串信息, 如电子序列号 (ESN )等, 终端的字符串信 息和域名构成终端的 NAI, 这样, 网络鉴权实体在执行鉴权操作时, 可根 据终端的 NAI找到对应的域名, 并检索到域名对应的 PDSN的编号。 这里, 如果 PDSN信息为 PDSN的 IP地址时, 也可采用相同的方法为 各终端配置对应的 PDSN的 IP地址,
本发明中, 运营商可根据自身的需求, 如: 需对某些终端执行特定的 计费方法, 则通过网络鉴权实体为所述终端配置对应的 PDSN的编号, 以 便实际应用过程中对终端执行计费等多种管理操作。
步驟 102: 数据业务启动后, 网络鉴权实体在鉴权响应消息中添加检索 到的与所述终端对应的 PDSN的编号并返回给基站;
具体为: 数据业务启动后, 且在终端通过合法性鉴权后, 网络鉴权实 体在已存储的 PDSN 的编号中选择与终端对应的 PDSN 的编号, 并将该 PDSN的编号添加到鉴权响应消息中发送到基站。
其中, 所述在鉴权响应消息中添加 PDSN的编号的方法可为: 利用现 有鉴权过程中采用的远程用户拨号认证协议 ( RADIUS )中的某种字符属性 携带 PDSN的编号, 如 RADIUS协议中的 class属性或者 vendor specific属 性等; 或者, 运营商可自定义属性来携带 PDSN的编号。
这里, 如果 PDSN信息为 PDSN的 IP地址时, 可采用相同的方法将 PDSN的 IP地址添加在鉴权响应消息中。
步驟 103: 基站根据收到的 PDSN的编号将相应的 PDSN分配给终端; 具体为: 基站收到网络鉴权实体返回的鉴权响应消息后, 解析消息中 的 PDSN的编号,在基站为终端分配 PDSN时,根据鉴权响应消息中的 PDSN 的编号在已存储的配置结果中找到相应的 PDSN的 IP地址,并分配给终端。
其中, 步驟 102所述从数据业务启动到对终端进行鉴权的流程具体如 图 2所示, 包括以下步驟:
步驟 201 : 终端与基站建立会话, 并建立与基站间的空口连接; 具体为: 终端开机后与基站建立会话连接, 终端与基站执行空口属性 的配置协商操作, 指定空口各层协议子类型以及各协议的相关参数, 最终 完成业务信道的建立。 该步驟为现有技术, 此处不再详述。
步驟 202: 基站执行与终端间的 PPP建链操作, 并进行与终端间的挑 战握手认证协议 ( CHAP )鉴权;
具体为: 基站向终端发出链路控制协议(LCP )配置请求要求对终端进 行 CHAP鉴权,终端接收后,也向基站发出 LCP配置请求并应答基站的 LCP 配置请求,双向 LCP协商完成后,ΡΡΡ建链完成;基站将携带鉴权码的 CHAP 消息发送到终端, 终端收到后解析其中的鉴权码, 并用鉴权码对终端密码 进行加密, 之后将携带终端放号时的 NAI和加密密码的 CHAP响应消息反 馈给基站。 该步驟为现有技术。
步驟 203: 基站将终端所发的 CHAP鉴权响应消息中携带的 NAI和加 密密码编码成鉴权请求消息发送到网络鉴权实体;
具体为: 基站接收到终端所发的 CHAP鉴权响应消息后, 解析消息中 携带的终端的 NAI 和加密密码, 并将这些信息和所述鉴权码一同编码成 Radius报文格式的鉴权请求消息发送到网络鉴权实体。 该步驟的实现方法 为现有技术。
步驟 204: 网络鉴权实体根据鉴权请求消息中的 NAI和加密密码对终 端进行鉴权, 如果鉴权成功, 则检索与所述终端对应的 PDSN的编号, 并 将 PDSN的编号添加在鉴权成功响应消息中返回给基站; 如果鉴权失败, 则将鉴权失败响应消息返回给基站;
具体为: 网络鉴权实体接收到基站发送的鉴权请求消息后, 对鉴权请 求消息进行解析, 得到其中终端的 NAI和加密密码, 根据终端的 NAI和加 密密码检索本地或者异地数据库, 确定所述终端已存在, 且加密密码正确 时, 也就是终端通过鉴权时, 在已存储的 PDSN的编号中选择与终端 NAI 对应的 PDSN的编号,并将为终端分配的 IMSI和 PDSN的编号组合成鉴权 成功响应消息返回给基站; 如果鉴权失败, 则将鉴权失败响应消息返回给 基站。
其中, 所述 IMSI为现有技术中网络鉴权实体在终端通过鉴权后所返回 的响应消息中已携带的信息。
这里, 所述网络鉴权实体对终端执行的鉴权过程为现有技术。
步驟 103所述基站为终端分配相应 PDSN的流程具体如图 3所示, 包 括以下步驟:
步驟 301 : 基站判断接收到鉴权响应消息, 如果为鉴权成功响应消息, 则解析并保存消息中携带的 IMSI和 PDSN的编号, 继续执行步驟 302; 如 果为鉴权失败响应消息, 则执行步驟 304;
具体为: 基站根据网络鉴权实体发送鉴权响应消息时的不同信令判断 鉴权响应消息的类型,如果为鉴权成功响应消息,则解析消息中携带的 IMSI 和 PDSN的编号并保存; 如果为鉴权失败响应消息, 则结束当前 PDSN的 分配流程。
步驟 302: 基站执行与终端间的 PPP拆链操作;
这里, 所述 PPP拆链过程为现有技术, 不再详述。
步驟 303:基站根据解析所得的 PDSN的编号将相应的 PDSN分配给终 端;
具体为: 基站根据解析所得的 PDSN的编号在已存储的配置结果中找 到相应的 PDSN的 IP地址,并依据找到的 PDSN的 IP地址将携带终端 IMSI 的 All登记请求消息发送到 PDSN, 即完成了基站为终端分配 PDSN的过 程。
步驟 304: PDSN的分配流程结束。
此后, PDSN返回 All登记响应消息,这样, A10链路建立完成, PDSN 向终端发起 PPP链路的连接请求, 执行后续 PPP链路的建立流程, 完成数 据业务链路的建立。 本发明中, 如果网络鉴权实体在为各终端配置对应的 PDSN信息为 PDSN的 IP地址时, 那么基站在数据业务启动之前则不需执行步驟 101中 所述的配置操作, 数据业务启动后, 网络鉴权实体在鉴权响应消息中添加 检索到的与所述终端对应的 PDSN的 IP地址并返回给基站; 基站根据收到 的 PDSN的 IP地址, 直接将相应的 PDSN分配给终端, 也就省去了基站收 到鉴权响应消息后的检索过程,直接将携带终端 IMSI的 Al l登记请求消息 发送到 PDSN。
为实现上述方法, 本发明还提供了一种 PDSN的分配系统, 如图 4所 示, 该系统包括: 网络鉴权实体和基站; 其中,
所述网络鉴权实体, 用于为各终端配置对应的 PDSN信息, 并将配置 结果存储, 在数据业务启动后, 在鉴权响应消息中添加检索到的与所述终 端对应的 PDSN信息并返回给基站;
具体的,在数据业务启动前, 网络鉴权实体为各终端配置对应的 PDSN 信息, 并将配置结果存储; 数据业务启动后, 并在收到基站所发的鉴权请 求消息后对终端进行鉴权, 在终端被鉴权成功后, 在已存储的 PDSN信息 中检索与所述终端对应的 PDSN信息, 并将检索到的 PDSN信息返回给基 站。
所述基站, 用于根据网络鉴权实体所发的 PDSN信息将相应的 PDSN 分配给终端。
在实际应用过程中, 基站首先建立与终端间的空口连接, 并完成与终 端间的 PPP建链操作, 进行与终端间的 CHAP鉴权, 将终端所发的 CHAP 鉴权响应消息中携带的 NAI和加密密码编码成鉴权请求消息发送到网络鉴 权实体; 收到网络鉴权实体确定终端鉴权成功后所发的 PDSN信息后, 首 先执行与终端间的 PPP拆链操作, 之后根据 PDSN信息将相应的 PDSN分 配给终端。 所述 PDSN信息为 PDSN的编号时, 基站进一步用于: 为各 PDSN配 置对应的编号, 并将配置结果存储, 这里, 所述编号与各 PDSN的 IP地址 对应;
所述 PDSN信息为 PDSN的编号时, 所述基站根据收到的 PDSN信息 将相应的 PDSN分配给终端, 具体为:
收到网络鉴权实体返回的鉴权响应消息后, 解析消息中的 PDSN的编 号, 在为终端分配 PDSN时, 根据鉴权响应消息中的 PDSN的编号在已存 储的配置结果中找到相应的 PDSN的 IP地址, 并分配给终端;
所述 PDSN信息为 PDSN的 IP地址时, 所述基站根据收到的 PDSN信 息将相应的 PDSN分配给终端, 具体为:
收到网络鉴权实体返回的鉴权响应消息后, 解析消息中的 PDSN的 IP 地址, 在为终端分配 PDSN时, 根据解析所得的 PDSN的 IP地址为终端分 配 PDSNo
以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保 护范围, 凡在本发明的精神和原则之内所作的任何修改、 等同替换和改进 等, 均应包含在本发明的保护范围之内。

Claims

权利要求书
1、 一种分组数据服务节点 PDSN的分配方法, 其特征在于, 网络鉴权 实体为各终端配置对应的 PDSN信息并存储; 该方法还包括:
数据业务启动后, 网络鉴权实体在鉴权响应消息中添加检索到的与所 述终端对应的 PDSN信息并返回给基站, 基站根据收到的 PDSN信息将相 应的 PDSN分配给终端。
2、根据权利要求 1所述的 PDSN的分配方法,其特征在于,所述 PDSN 信息为: PDSN的编号或 PDSN的 IP地址。
3、根据权利要求 2所述的 PDSN的分配方法,其特征在于,所述 PDSN 信息为 PDSN的编号时, 该方法进一步包括: 基站为各 PDSN配置对应的 编号并存储。
4、 根据权利要求 1至 3任一所述的 PDSN的分配方法, 其特征在于, 所述网络鉴权实体为各终端配置对应的 PDSN信息的方法为:
网络鉴权实体在为终端分配网络接入标识 NAI的同时, 为终端配置对 应的 PDSN信息; 或者,
为各终端的 IMSI配置对应的 PDSN的编号; 或者,
为各终端的 NAI设置对应的域名, 再令不同的域名与 PDSN信息相对 应。
5、 根据权利要求 1至 3任一所述的 PDSN的分配方法, 其特征在于, 所述在鉴权响应消息中添加 PDSN信息的方法为:
利用鉴权过程中采用的远程用户拨号认证协议 RADIUS中的字符属性 携带 PDSN信息; 或者, 通过自定义属性携带 PDSN信息。
6、 根据权利要求 3所述的 PDSN的分配方法, 其特征在于, 所述基站 为各 PDSN配置对应的编号为: 为各 PDSN的 IP地址配置对应的编号; 相应的, 所述基站根据收到的 PDSN信息将相应的 PDSN分配给终端 为: 基站收到网络鉴权实体返回的鉴权响应消息后, 解析消息中的 PDSN 的编号, 在基站为终端分配 PDSN时, 根据鉴权响应消息中的 PDSN的编 号在已存储的配置结果中找到相应的 PDSN的 IP地址, 并分配给终端。
7、根据权利要求 2所述的 PDSN的分配方法,其特征在于,所述 PDSN 信息为 PDSN的 IP地址时,
相应的, 所述基站根据收到的 PDSN信息将相应的 PDSN分配给终端 为: 基站收到网络鉴权实体返回的鉴权响应消息后, 解析消息中的 PDSN 的 IP地址,在基站为终端分配 PDSN时,根据解析所得的 PDSN的 IP地址 为终端分配 PDSN。
8、 一种 PDSN的分配系统, 其特征在于, 该系统包括: 网络鉴权实体 和基站; 其中,
所述网络鉴权实体, 用于为各终端配置对应的 PDSN信息, 并将配置 结果存储, 在数据业务启动后, 在鉴权响应消息中添加检索到的与所述终 端对应的 PDSN信息并返回给基站;
所述基站, 用于根据网络鉴权实体所发的 PDSN信息将相应的 PDSN 分配给终端。
9、根据权利要求 8所述的 PDSN的分配系统,其特征在于,所述 PDSN 信息为: PDSN的编号或 PDSN的 IP地址。
10、根据权利要求 9所述的 PDSN的分配系统,其特征在于,所述 PDSN 信息为 PDSN的编号时, 所述基站进一步用于为各 PDSN配置对应的编号, 并将配置结果存储;
相应的, 所述基站根据收到的 PDSN信息将相应的 PDSN分配给终端 为: 收到网络鉴权实体返回的鉴权响应消息后, 解析消息中的 PDSN的编 号, 在为终端分配 PDSN时, 根据鉴权响应消息中的 PDSN的编号在已存 储的配置结果中找到相应的 PDSN的 IP地址, 并分配给终端; 所述 PDSN信息为 PDSN的 IP地址时, 所述基站根据收到的 PDSN信 息将相应的 PDSN分配给终端为: 收到网络鉴权实体返回的鉴权响应消息 后, 解析消息中的 PDSN的 IP地址, 在为终端分配 PDSN时, 根据解析所 得的 PDSN的 IP地址为终端分配 PDSN。
PCT/CN2010/073850 2010-01-21 2010-06-11 一种分组数据服务节点的分配方法及系统 WO2011088653A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201010034445.3 2010-01-21
CN201010034445A CN101790167A (zh) 2010-01-21 2010-01-21 一种分组数据服务节点的分配方法及系统

Publications (1)

Publication Number Publication Date
WO2011088653A1 true WO2011088653A1 (zh) 2011-07-28

Family

ID=42533165

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/073850 WO2011088653A1 (zh) 2010-01-21 2010-06-11 一种分组数据服务节点的分配方法及系统

Country Status (2)

Country Link
CN (1) CN101790167A (zh)
WO (1) WO2011088653A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109861897B (zh) * 2014-08-18 2023-09-01 华为技术有限公司 一种获得对应关系的方法、装置及系统
CN112860790B (zh) * 2021-01-14 2023-05-30 华控清交信息科技(北京)有限公司 数据管理方法、系统、装置

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1416655A (zh) * 2000-03-10 2003-05-07 艾利森电话股份有限公司 在分组数据网络中选择分组数据业务节点/外部代理的分组核心功能部件和方法
CN1535068A (zh) * 2003-04-02 2004-10-06 华为技术有限公司 根据用户标识进行分组业务监听的方法

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1416655A (zh) * 2000-03-10 2003-05-07 艾利森电话股份有限公司 在分组数据网络中选择分组数据业务节点/外部代理的分组核心功能部件和方法
CN1535068A (zh) * 2003-04-02 2004-10-06 华为技术有限公司 根据用户标识进行分组业务监听的方法

Also Published As

Publication number Publication date
CN101790167A (zh) 2010-07-28

Similar Documents

Publication Publication Date Title
US11716621B2 (en) Apparatus and method for providing mobile edge computing services in wireless communication system
CN110800331B (zh) 网络验证方法、相关设备及系统
RU2719447C1 (ru) Способ конфигурирования ключа, способ определения политики безопасности и устройство
JP3984993B2 (ja) アクセスネットワークを通じて接続を確立するための方法及びシステム
KR100442594B1 (ko) 무선통신 시스템의 패킷 데이터 서비스 방법 및 장치
US11553411B2 (en) End-to-end network slice selection and configuration
EP1552646B1 (en) Method and apparatus enabling reauthentication in a cellular communication system
KR100836028B1 (ko) 멀티캐스트 브로드캐스트 서비스 제공 방법
EP1860906B1 (en) A general authentication form and a method for implementing the authentication
US20060195893A1 (en) Apparatus and method for a single sign-on authentication through a non-trusted access network
WO2012130085A1 (zh) 与网管系统建立连接的方法、设备及通信系统
WO2009152749A1 (zh) 一种绑定认证的方法、系统和装置
WO2013107423A1 (zh) 一种网络接入的认证方法、系统和设备
WO2013040957A1 (zh) 单点登录的方法、系统和信息处理方法、系统
CN113541989A (zh) 一种网络切片检测方法、装置和存储介质
CN114070597B (zh) 一种专网跨网认证方法及装置
WO2009039746A1 (fr) Procédé et système de réalisation pour associer point d'accès et opérateur
WO2013067744A1 (zh) 一种终端组的服务网关选择方法及系统
WO2007003105A1 (fr) Procede, systeme et appareil pour la mise en relation d'informations associee a l'utilisateur dans un systeme nass
WO2011032478A1 (zh) 一种获取终端身份标识的方法、装置及终端
WO2011015091A1 (zh) 用于家用基站的接入方法、装置、系统及aaa服务器
WO2011120365A1 (zh) 多穴终端建立连接的方法和系统
WO2015100874A1 (zh) 家庭网关接入管理方法和系统
WO2011088653A1 (zh) 一种分组数据服务节点的分配方法及系统
WO2012142867A1 (zh) 一种认证通知方法及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10843693

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10843693

Country of ref document: EP

Kind code of ref document: A1