WO2011110007A1 - 隧道重协商的方法和系统、以及接入网关和终端 - Google Patents

隧道重协商的方法和系统、以及接入网关和终端 Download PDF

Info

Publication number
WO2011110007A1
WO2011110007A1 PCT/CN2010/076468 CN2010076468W WO2011110007A1 WO 2011110007 A1 WO2011110007 A1 WO 2011110007A1 CN 2010076468 W CN2010076468 W CN 2010076468W WO 2011110007 A1 WO2011110007 A1 WO 2011110007A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
identifier
processing module
service processing
access gateway
Prior art date
Application number
PCT/CN2010/076468
Other languages
English (en)
French (fr)
Inventor
蔡慧
熊志伟
郭有瑞
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN2010800052167A priority Critical patent/CN102396285A/zh
Priority to PCT/CN2010/076468 priority patent/WO2011110007A1/zh
Publication of WO2011110007A1 publication Critical patent/WO2011110007A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0272Virtual private networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/20Manipulation of established connections
    • H04W76/22Manipulation of transport tunnels

Definitions

  • the present invention relates to the field of network security, and in particular, to a method and system for tunnel renegotiation, and an access gateway and a terminal.
  • a secure tunnel connection needs to be established between the terminal and the access gateway. Then, the terminal uses the secure tunnel to perform services such as service application.
  • the tunnel establishment process includes an initial tunnel establishment process and a tunnel renegotiation process, and the terminal and the book during the initial tunnel establishment process.
  • a SA Security Association
  • the SA corresponding to the security tunnel expires. If the connection continues, the two parties need to renegotiate to establish a new SA. This process is called a tunnel renegotiation process.
  • the service distribution management module of the access gateway allocates a service processing module to the terminal, which is set as the service processing module 1, and the service processing module 1 sends the identifier to the terminal.
  • the service distribution management module of the access gateway After receiving the tunnel establishment request message sent by the terminal, the service distribution management module of the access gateway allocates a service processing module to the terminal, which is set as the service processing module 2, and the service processing module 2 sends an identifier to the terminal.
  • the terminal discovery identifier conflicts on different service processing modules, and the service processing module 1 allocated in the initial tunnel establishment process initiates a process of clearing user resources.
  • the user resource may be user context information.
  • the existing tunnel renegotiation method causes the garbage user resources of the terminal to exist on the access gateway, and an additional mechanism is needed to clean the garbage resources, thereby increasing the processing load of the access gateway.
  • the embodiment of the present invention provides a method and system for tunnel renegotiation, and an access gateway and a terminal.
  • the technical solution is as follows:
  • a method for tunnel renegotiation includes:
  • a method for tunnel renegotiation includes:
  • the terminal sends a first tunnel establishment request message to the access gateway, so that the access gateway allocates an identifier and a service processing module to the terminal, and establishes a mapping relationship between the identifier and the service processing module.
  • the terminal Receiving, by the terminal, a first tunnel setup response message that carries the identifier returned by the access gateway; the terminal sends a second tunnel setup request message carrying the identifier to the access gateway, so that the access
  • the gateway acquires the service processing module corresponding to the identifier according to the mapping relationship, and allocates the service processing module to the terminal.
  • An access gateway includes: a service distribution management module and at least one service processing module; the service distribution management module includes:
  • a first allocation unit configured to: after receiving the first tunnel establishment request message sent by the terminal, assign an identifier and a service processing module to the terminal;
  • An establishing unit configured to establish a mapping relationship between the identifier and the service processing module
  • a sending unit configured to return, to the terminal, a first tunnel establishment response message that carries the identifier
  • a receiving unit configured to receive a second tunnel establishment request message that is sent by the terminal and that carries the identifier, where the second allocation unit is configured to acquire, according to the mapping relationship, the service processing module corresponding to the identifier, and The service processing module is assigned to the terminal.
  • a terminal, the terminal includes:
  • a first sending module configured to send a first tunnel establishment request message to the access gateway, to enable the access gateway to allocate an identifier and a service processing module to the terminal, and establish a mapping between the identifier and the service processing module a receiving module, configured to receive a first tunnel setup response message that is sent by the access gateway and that carries the identifier, and a second sending module, configured to send, to the access gateway, a second tunnel that carries the identifier And requesting, by the access gateway, the service processing module corresponding to the identifier according to the mapping relationship, and assigning the service processing module to the terminal.
  • a system for tunnel renegotiation comprising: a terminal and an access gateway;
  • the terminal is configured to send a first tunnel establishment request message to the access gateway, receive a first tunnel setup response message that carries the identifier returned by the access gateway, and send the identifier that carries the identifier to the access gateway.
  • Second tunnel establishment Request message
  • the access gateway is configured to: after receiving the first tunnel establishment request message sent by the terminal, assign an identifier and a service processing module to the terminal; and establish a mapping relationship between the identifier and the service processing module; Receiving, by the terminal, a first tunnel establishment response message carrying the identifier, receiving a second tunnel establishment request message that is sent by the terminal and carrying the identifier, and acquiring the service processing module corresponding to the identifier according to the mapping relationship, And assigning the service processing module to the terminal.
  • the access gateway After receiving the first tunnel establishment request message sent by the terminal, the access gateway allocates an identifier and a service processing module to the terminal, and establishes a mapping relationship between the identifier and the service processing module, and returns a first tunnel establishment response message carrying the identifier to the terminal. Then, the second tunnel establishment request message carrying the identifier sent by the terminal is received, and the service processing module corresponding to the identifier is obtained according to the mapping relationship, and the service processing module is allocated to the terminal, so that one terminal allocates the same service in multiple tunnel negotiation.
  • the processing module eliminates the garbage user resources on the access gateway and reduces the processing load of the access gateway.
  • Embodiment 1 is a flowchart of a method for tunnel renegotiation provided by Embodiment 1 of the present invention
  • FIG. 2 is a flowchart of another method for tunnel renegotiation according to Embodiment 1 of the present invention.
  • Embodiment 3 is a flowchart of a method for tunnel renegotiation provided by Embodiment 2 of the present invention.
  • FIG. 4 is a schematic structural diagram of an access gateway according to Embodiment 3 of the present invention.
  • FIG. 5 is a schematic structural diagram of a terminal according to Embodiment 4 of the present invention.
  • FIG. 6 is a schematic diagram of a system for tunnel renegotiation according to Embodiment 5 of the present invention. detailed description
  • this embodiment provides a method for tunnel renegotiation.
  • the method includes:
  • 103a Return, to the terminal, a first tunnel establishment response message that carries the identifier; 104a: Receive a second tunnel establishment request message that carries the identifier sent by the terminal.
  • the embodiment further provides a method for tunnel renegotiation.
  • the method includes: 101b: The terminal sends a first tunnel establishment request message to the access gateway, so that the access gateway allocates an identifier to the terminal. And the business processing module, and establish a mapping relationship between the identifier and the business processing module;
  • the terminal receives a first tunnel setup response message that carries an identifier returned by the access gateway.
  • the terminal sends a second tunnel establishment request message carrying the identifier to the access gateway, so that the access gateway obtains the service processing module corresponding to the identifier according to the mapping relationship, and allocates the service processing module to the terminal.
  • the method provided in this embodiment after the access gateway receives the first tunnel establishment request message sent by the terminal, allocates an identifier and a service processing module to the terminal, and establishes a mapping relationship between the identifier and the service processing module, and returns the carrying identifier to the terminal.
  • the first tunnel establishes a response message, and then receives the second tunnel establishment request message that is sent by the terminal, and obtains the service processing module corresponding to the identifier according to the mapping relationship, and allocates the service processing module to the terminal, so that one terminal is in multiple tunnels.
  • the same service processing module is allocated in the negotiation, which eliminates the garbage user resources on the access gateway and reduces the processing load of the access gateway.
  • this embodiment provides a method for tunnel renegotiation, including an initial tunnel establishment process and a tunnel re-negotiation process.
  • the service distribution management module of the access gateway receives the first tunnel establishment request message sent by the terminal.
  • the service distribution management module of the access gateway allocates an identifier and a service processing module to the terminal.
  • the identifier may uniquely represent the service information of the terminal at the access gateway, such as a service processing module.
  • the identifier may be SPI (Security Parameter Index), the local IP address of the terminal, or the session identifier, etc., and is not limited in this embodiment.
  • the access gateway includes at least one service processing module, and usually includes multiple service processing modules.
  • the service processing module 1 and the service processing module 2 are used as an example.
  • the assigned service processing module is a service processing module.
  • the service distribution management module of the access gateway establishes a mapping relationship between the identifier and the service processing module.
  • the mapping relationship between the identifier and the service processing module 1 is established.
  • the service distribution management module of the access gateway returns a first tunnel establishment response message IKE_SA_INIT to the terminal.
  • RSP the message carries the assigned identifier.
  • the terminal may save the identifier, so that the terminal may be allocated to the same service processing module in subsequent multiple tunnel renegotiations.
  • the service distribution management module of the access gateway receives the second tunnel establishment request message sent by the terminal.
  • the message carries the assigned identifier
  • the service distribution management module of the access gateway obtains the service processing module corresponding to the identifier according to the mapping relationship.
  • the service processing module corresponding to the identifier is obtained as the service processing module 1 according to the mapping relationship, that is, the initial tunnel establishment process is The service processing module assigned by the terminal.
  • the service distribution management module of the access gateway allocates the acquired service processing module to the terminal.
  • the service distribution management module of the access gateway returns a second tunnel establishment response message to the terminal.
  • the second tunnel establishment response message may carry the assigned identifier, so that the terminal may be allocated to the same service processing module in the next tunnel re-negotiation process.
  • the second tunnel establishment response message may not carry the assigned identifier if the terminal saves the identifier in step 204.
  • the method provided in this embodiment after the access gateway receives the first tunnel establishment request message sent by the terminal, allocates an identifier and a service processing module to the terminal, and establishes a mapping relationship between the identifier and the service processing module, and returns the carrying identifier to the terminal.
  • the first tunnel establishes a response message, and then receives the second tunnel establishment request message that is sent by the terminal, and obtains the service processing module corresponding to the identifier according to the mapping relationship, and allocates the service processing module to the terminal, so that one terminal is in multiple tunnels.
  • the same service processing module is allocated in the negotiation, which eliminates the garbage user resources on the access gateway and reduces the processing load of the access gateway.
  • this embodiment provides an access gateway, including: a service distribution management module 401 and at least one service processing module 402;
  • the service distribution management module 401 includes:
  • a first allocation unit configured to receive a first tunnel establishment request message sent by the terminal, and allocate an identifier and a service processing module 402 to the terminal;
  • An establishing unit configured to establish a mapping relationship between the identifier and the service processing module 402;
  • a sending unit configured to return, to the terminal, a first tunnel establishment response message that carries the identifier
  • a receiving unit configured to receive, by the terminal, a second tunnel establishment request message that carries the identifier;
  • the second allocation unit is configured to obtain the service processing module 402 corresponding to the identifier according to the mapping relationship, and allocate the service processing module 402 to the terminal.
  • the identifier is the security parameter index SPI, the local IP address of the terminal, or the session identifier.
  • the access gateway provided in this embodiment is the same as the method embodiment, and the specific implementation process is described in detail in the method embodiment, and details are not described herein again.
  • the access gateway After receiving the first tunnel establishment request message sent by the terminal, the access gateway provided by the embodiment allocates an identifier and a service processing module to the terminal, and establishes a mapping relationship between the identifier and the service processing module, and returns the identifier carrying the identifier to the terminal.
  • a tunnel establishment response message is received, and then the second tunnel establishment request message carrying the identifier sent by the terminal is received, the service processing module corresponding to the identifier is obtained according to the mapping relationship, and the service processing module is allocated to the terminal, so that one terminal is negotiated multiple times.
  • the allocation to the same service processing module eliminates the garbage user resources on the access gateway and reduces the processing load of the access gateway.
  • this embodiment provides a terminal, where the terminal includes:
  • the first sending module 501 is configured to send a first tunnel establishment request message to the access gateway, so that the access gateway allocates an identifier and a service processing module to the terminal, and establish a mapping relationship between the identifier and the service processing module.
  • a receiving module configured to receive a first tunnel setup response message that carries an identifier returned by the access gateway
  • the second sending module 502 is configured to send a second tunnel establishment request message carrying the identifier to the access gateway, so that the access gateway obtains the service processing module corresponding to the identifier according to the mapping relationship, and allocates the service processing module to the terminal.
  • the identifier is the security parameter index SPI, the local IP address of the terminal, or the session identifier.
  • the terminal provided in this embodiment is the same as the method embodiment, and the specific implementation process is described in the method embodiment, and details are not described herein again.
  • the terminal provided in this embodiment sends a first tunnel establishment request message to the access gateway, so that the access gateway allocates an identifier and a service processing module to the terminal, and establishes a mapping relationship between the identifier and the service processing module, and receives the access gateway to return.
  • the first tunnel establishment response message carrying the identifier, the second tunnel establishment request message carrying the identifier is sent to the access gateway, so that the access gateway obtains the service processing module corresponding to the identifier according to the mapping relationship, and allocates the service processing module to the terminal. Therefore, a terminal is allocated to the same service processing module in multiple tunnel negotiation, which eliminates the garbage user resources on the access gateway and reduces the processing load of the access gateway.
  • the embodiment provides a tunnel renegotiation system, including: a terminal 601 and an access gateway 602;
  • the terminal 601 is configured to send a first tunnel establishment request message to the access gateway 602, receive a first tunnel establishment response message that carries the identifier returned by the access gateway 602, and send a second tunnel establishment request message that carries the identifier to the access gateway 602. ;
  • the access gateway 602 is configured to: after receiving the first tunnel establishment request message sent by the terminal 601, assign an identifier and a service processing module to the terminal 601; establish a mapping relationship between the identifier and the service processing module; and return the first identifier carrying the identifier to the terminal 601.
  • the tunnel establishment response message is received by the receiving terminal 601, and the service processing module corresponding to the identifier is obtained according to the mapping relationship, and the service processing module is allocated to the terminal 601.
  • the identifier is the security parameter index SPI, the local IP address of the terminal, or the session identifier.
  • the access gateway after receiving the first tunnel establishment request message sent by the terminal, allocates an identifier and a service processing module, and establishes a mapping relationship between the identifier and the service processing module, and returns the carrying identifier to the terminal.
  • the first tunnel establishes a response message, and then receives the second tunnel establishment request message that is sent by the terminal, and obtains the service processing module corresponding to the identifier according to the mapping relationship, and allocates the service processing module to the terminal, so that one terminal is in multiple tunnels.
  • the same service processing module is allocated in the negotiation, thereby eliminating the garbage user resources on the access gateway and reducing the processing load of the access gateway.
  • Embodiments of the invention may be implemented in software, and the corresponding software program may be stored in a readable storage medium, such as a hard disk, a cache, or an optical disk of a computer.
  • a readable storage medium such as a hard disk, a cache, or an optical disk of a computer.

Abstract

本发明实施例提供了一种隧道重协商的方法和系统、以及接入网关和终端,涉及网络安全领域,所述方法包括:接收终端发送的第一隧道建立请求消息后,为终端分配一个标识和业务处理模块;建立标识和业务处理模块的映射关系;向终端返回携带标识的第一隧道建立响应消息;接收终端发送的携带标识的第二隧道建立请求消息;根据映射关系获取标识对应的业务处理模块,并将业务处理模块分配给终端。本实施例还包括相应的接入网关、终端以及由二者组成的隧道重协商的系统。本发明通过上述方案,使一个终端在多次隧道协商中分配到相同的业务处理模块,消除了接入网关上的垃圾用户资源,减轻了接入网关的处理负担。

Description

隧道重协商的方法和系统、 以及接入网关和终端 技术领域
本发明涉及网络安全领域, 特别涉及一种隧道重协商的方法和系统、 以及接入网关和 终端。 说
背景技术
为了保障接入的安全性, 终端和接入网关之间需要建立安全的隧道连接, 然后, 终端 使用该安全隧道进行业务应用等操作。
隧道建立过程包括初始隧道建立过程和隧道重协商过程, 初始隧道建立过程中终端和 书
接入网关之间建立了 SA ( Security Association, 安全联盟), 由于安全隧道对应的 SA会 过期, 如果继续进行连接, 双方需要重新协商以建立新的 SA, 这个过程称为隧道重协商过 程。 下面结合终端的初始隧道建立过程, 介绍隧道重协商过程。
在初始隧道建立过程中, 接入网关的业务分发管理模块接收到终端发送的隧道建立请 求消息后, 为终端分配一个业务处理模块, 设为业务处理模块 1, 业务处理模块 1向终端发 送标识。
在隧道重协商过程中, 接入网关的业务分发管理模块接收到终端发送的隧道建立请求 消息后, 为终端分配一个业务处理模块, 设为业务处理模块 2, 业务处理模块 2向终端发送 标识。 终端发现标识在不同的业务处理模块上冲突, 向初始隧道建立过程中分配的业务处 理模块 1发起清除用户资源的过程。 其中, 用户资源可以是用户上下文信息。
在实现本发明的过程中, 发明人发现现有技术至少存在以下问题:
现有的隧道重协商方法造成接入网关上存在终端的垃圾用户资源, 需要额外的机制进 行垃圾资源的清理, 增加了接入网关的处理负担。 发明内容
为了消除接入网关上的垃圾用户资源, 从而减轻接入网关的处理负担, 本发明实施例 提供了一种隧道重协商的方法和系统、 以及接入网关和终端。 所述技术方案如下:
一种隧道重协商的方法, 所述方法包括:
接收终端发送的第一隧道建立请求消息后, 为所述终端分配一个标识和业务处理模块; 建立所述标识和所述业务处理模块的映射关系;
向所述终端返回携带所述标识的第一隧道建立响应消息;
接收所述终端发送的携带所述标识的第二隧道建立请求消息;
根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务处理模块分 配给所述终端。
一种隧道重协商的方法, 所述方法包括:
终端向接入网关发送第一隧道建立请求消息, 使所述接入网关为所述终端分配一个标 识和业务处理模块, 并建立所述标识和所述业务处理模块的映射关系;
所述终端接收所述接入网关返回的携带所述标识的第一隧道建立响应消息; 所述终端向所述接入网关发送携带所述标识的第二隧道建立请求消息, 使所述接入网 关根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务处理模块分配 给所述终端。
一种接入网关, 所述接入网关包括: 业务分发管理模块和至少一个业务处理模块; 所述业务分发管理模块包括:
第一分配单元, 用于接收终端发送的第一隧道建立请求消息后, 为所述终端分配一个 标识和业务处理模块;
建立单元, 用于建立所述标识和所述业务处理模块的映射关系;
发送单元, 用于向所述终端返回携带所述标识的第一隧道建立响应消息;
接收单元, 用于接收所述终端发送的携带所述标识的第二隧道建立请求消息; 第二分配单元, 用于根据所述映射关系获取所述标识对应的所述业务处理模块, 并将 所述业务处理模块分配给所述终端。
一种终端, 所述终端包括:
第一发送模块, 用于向接入网关发送第一隧道建立请求消息, 使所述接入网关为所述 终端分配一个标识和业务处理模块, 并建立所述标识和所述业务处理模块的映射关系; 接收模块, 用于接收所述接入网关返回的携带所述标识的第一隧道建立响应消息; 第二发送模块, 用于向所述接入网关发送携带所述标识的第二隧道建立请求消息, 使 所述接入网关根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务处 理模块分配给所述终端。
一种隧道重协商的系统, 所述系统包括: 终端和接入网关;
所述终端, 用于向所述接入网关发送第一隧道建立请求消息; 接收所述接入网关返回 的携带标识的第一隧道建立响应消息; 向所述接入网关发送携带所述标识的第二隧道建立 请求消息;
所述接入网关, 用于接收所述终端发送的第一隧道建立请求消息后, 为所述终端分配 一个标识和业务处理模块; 建立所述标识和所述业务处理模块的映射关系; 向所述终端返 回携带所述标识的第一隧道建立响应消息; 接收所述终端发送的携带所述标识的第二隧道 建立请求消息; 根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务 处理模块分配给所述终端。
本发明实施例提供的技术方案的有益效果是:
通过接入网关接收终端发送的第一隧道建立请求消息后, 为终端分配一个标识和业务 处理模块, 并建立标识和业务处理模块的映射关系, 向终端返回携带标识的第一隧道建立 响应消息, 然后接收终端发送的携带标识的第二隧道建立请求消息, 根据映射关系获取标 识对应的业务处理模块, 并将业务处理模块分配给终端, 从而使一个终端在多次隧道协商 中分配到相同的业务处理模块, 从而消除了接入网关上的垃圾用户资源, 减轻了接入网关 的处理负担。 附图说明
图 1是本发明实施例 1提供的隧道重协商的方法流程图;
图 2是本发明实施例 1提供的隧道重协商的另一方法流程图;
图 3是本发明实施例 2提供的隧道重协商的方法流程图;
图 4是本发明实施例 3提供的接入网关结构示意图;
图 5是本发明实施例 4提供的终端结构示意图;
图 6是本发明实施例 5提供的隧道重协商的系统示意图。 具体实施方式
为使本发明的目的、 技术方案和优点更加清楚, 下面将结合附图对本发明实施方式作 进一步地详细描述。
实施例 1
参见图 1, 本实施例提供了一种隧道重协商的方法, 对于接入网关, 包括:
101a: 接收终端发送的第一隧道建立请求消息后, 为终端分配一个标识和业务处理模 块;
102a: 建立标识和业务处理模块的映射关系;
103a: 向终端返回携带标识的第一隧道建立响应消息; 104a: 接收终端发送的携带标识的第二隧道建立请求消息;
105a: 根据映射关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端。 相应的, 参见图 2, 本实施例还提供了一种隧道重协商的方法, 对于终端, 包括: 101b: 终端向接入网关发送第一隧道建立请求消息, 使接入网关为终端分配一个标识 和业务处理模块, 并建立标识和业务处理模块的映射关系;
102b: 终端接收接入网关返回的携带标识的第一隧道建立响应消息;
103b: 终端向接入网关发送携带标识的第二隧道建立请求消息, 使接入网关根据映射 关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端。
本实施例提供的方法, 通过接入网关接收终端发送的第一隧道建立请求消息后, 为终 端分配一个标识和业务处理模块, 并建立标识和业务处理模块的映射关系, 向终端返回携 带标识的第一隧道建立响应消息, 然后接收终端发送的携带标识的第二隧道建立请求消息, 根据映射关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端, 从而使一个 终端在多次隧道协商中分配到相同的业务处理模块, 消除了接入网关上的垃圾用户资源, 减轻了接入网关的处理负担。 实施例 2
参见图 3, 本实施例提供了一种隧道重协商的方法, 包括初始隧道建立过程和隧道重协 商过程。
在初始隧道建立过程中,
201: 接入网关的业务分发管理模块接收终端发送的第一隧道建立请求消息
IKE—SA T REQ;
202: 接入网关的业务分发管理模块为终端分配一个标识和业务处理模块;
其中, 标识可以唯一表示该终端在该接入网关的业务信息, 如业务处理模块。 标识具 体可以 SPI ( Security Parameter Index , 安全参数索引)、 终端的本地 IP ( Internet Protocol , 互联网协议) 地址、 或会话标识等, 本实施例并不限定。
其中, 接入网关包括至少一个业务处理模块, 通常包括多个业务处理模块, 图 2 中仅 以业务处理模块 1和业务处理模块 2为例进行了标示。 此处, 设分配的业务处理模块为业 务处理模块 1
203: 接入网关的业务分发管理模块建立该标识和该业务处理模块的映射关系; 此处, 建立了该标识和业务处理模块 1的映射关系。
204: 接入网关的业务分发管理模块向终端返回第一隧道建立响应消息 IKE_SA_INIT RSP, 消息中携带分配的标识。
进一步的, 终端可以保存该标识, 从而使终端在后续的多次隧道重协商中可以分配到 相同的业务处理模块。
在隧道重协商过程中,
301: 接入网关的业务分发管理模块接收终端发送的第二隧道建立请求消息
IKE_SA_INIT REQ, 消息中携带分配的标识;
302: 接入网关的业务分发管理模块根据映射关系获取该标识对应的业务处理模块; 此处, 根据映射关系获取到该标识对应的业务处理模块为业务处理模块 1, 也即初始隧 道建立过程为该终端分配的业务处理模块。
303: 接入网关的业务分发管理模块为终端分配获取到的业务处理模块;
304: 接入网关的业务分发管理模块向终端返回第二隧道建立响应消息 IKE_SA_INIT
RSP;
进一步的, 第二隧道建立响应消息中可以携带分配的标识, 从而使终端在下一次隧道 重协商过程中可以分配到相同的业务处理模块。 另外, 如果步骤 204中终端保存了该标识, 则第二隧道建立响应消息中也可以不携带分配的标识。
本实施例提供的方法, 通过接入网关接收终端发送的第一隧道建立请求消息后, 为终 端分配一个标识和业务处理模块, 并建立标识和业务处理模块的映射关系, 向终端返回携 带标识的第一隧道建立响应消息, 然后接收终端发送的携带标识的第二隧道建立请求消息, 根据映射关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端, 从而使一个 终端在多次隧道协商中分配到相同的业务处理模块, 消除了接入网关上的垃圾用户资源, 减轻了接入网关的处理负担。 实施例 3
参见图 4, 本实施例提供了一种接入网关, 包括: 业务分发管理模块 401和至少一个业 务处理模块 402;
业务分发管理模块 401包括:
第一分配单元, 用于接收终端发送的第一隧道建立请求消息后, 为终端分配一个标识 和业务处理模块 402;
建立单元, 用于建立标识和业务处理模块 402的映射关系;
发送单元, 用于向终端返回携带标识的第一隧道建立响应消息;
接收单元, 用于接收终端发送的携带标识的第二隧道建立请求消息; 第二分配单元, 用于根据映射关系获取标识对应的业务处理模块 402, 并将业务处理模 块 402分配给终端。
其中, 标识是安全参数索引 SPI、 终端的本地 IP地址或会话标识。
本实施例提供的接入网关, 与方法实施例属于同一构思, 其具体实现过程详见方法实 施例, 这里不再赘述。
本实施例提供的接入网关, 通过接收终端发送的第一隧道建立请求消息后, 为终端分 配一个标识和业务处理模块, 并建立标识和业务处理模块的映射关系, 向终端返回携带标 识的第一隧道建立响应消息, 然后接收终端发送的携带标识的第二隧道建立请求消息, 根 据映射关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端, 从而使一个终 端在多次隧道协商中分配到相同的业务处理模块, 消除了接入网关上的垃圾用户资源, 减 轻了接入网关的处理负担。 实施例 4
参见图 5, 本实施例提供了一种终端, 该终端包括:
第一发送模块 501, 用于向接入网关发送第一隧道建立请求消息, 使接入网关为终端分 配一个标识和业务处理模块, 并建立标识和业务处理模块的映射关系;
接收模块, 用于接收接入网关返回的携带标识的第一隧道建立响应消息;
第二发送模块 502, 用于向接入网关发送携带标识的第二隧道建立请求消息, 使接入网 关根据映射关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端。
其中, 标识是安全参数索引 SPI、 终端的本地 IP地址或会话标识。
本实施例提供的终端, 与方法实施例属于同一构思, 其具体实现过程详见方法实施例, 这里不再赘述。
本实施例提供的终端, 通过向接入网关发送第一隧道建立请求消息, 使接入网关为终 端分配一个标识和业务处理模块, 并建立标识和业务处理模块的映射关系, 接收接入网关 返回的携带标识的第一隧道建立响应消息, 向接入网关发送携带标识的第二隧道建立请求 消息, 使接入网关根据映射关系获取标识对应的业务处理模块, 并将该业务处理模块分配 给终端, 从而使一个终端在多次隧道协商中分配到相同的业务处理模块, 消除了接入网关 上的垃圾用户资源, 减轻了接入网关的处理负担。 实施例 5
参见图 6, 本实施例提供了一种隧道重协商的系统, 包括: 终端 601和接入网关 602; 终端 601, 用于向接入网关 602发送第一隧道建立请求消息; 接收接入网关 602返回的 携带标识的第一隧道建立响应消息; 向接入网关 602 发送携带标识的第二隧道建立请求消 息;
接入网关 602, 用于接收终端 601发送的第一隧道建立请求消息后, 为终端 601分配一 个标识和业务处理模块; 建立标识和业务处理模块的映射关系; 向终端 601 返回携带标识 的第一隧道建立响应消息; 接收终端 601 发送的携带标识的第二隧道建立请求消息; 根据 映射关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端 601。
其中, 标识是安全参数索引 SPI、 终端的本地 IP地址或会话标识。
本实施例提供的系统, 与方法实施例属于同一构思, 其具体实现过程详见方法实施例, 这里不再赘述。
本实施例提供的系统, 通过接入网关接收终端发送的第一隧道建立请求消息后, 为终 端分配一个标识和业务处理模块, 并建立标识和业务处理模块的映射关系, 向终端返回携 带标识的第一隧道建立响应消息, 然后接收终端发送的携带标识的第二隧道建立请求消息, 根据映射关系获取标识对应的业务处理模块, 并将业务处理模块分配给终端, 从而使一个 终端在多次隧道协商中分配到相同的业务处理模块, 从而消除了接入网关上的垃圾用户资 源, 减轻了接入网关的处理负担。 本发明实施例可以利用软件实现, 相应的软件程序可以存储在可读取的存储介质中, 例如, 计算机的硬盘、 缓存或光盘中。 以上所述仅为本发明的较佳实施例, 并不用以限制本发明, 凡在本发明的精神和原则 之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。

Claims

权 利 要 求 书
1、 一种隧道重协商的方法, 其特征在于, 所述方法包括:
接收终端发送的第一隧道建立请求消息后, 为所述终端分配一个标识和业务处理模块; 建立所述标识和所述业务处理模块的映射关系;
向所述终端返回携带所述标识的第一隧道建立响应消息;
接收所述终端发送的携带所述标识的第二隧道建立请求消息;
根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务处理模块分配 给所述终端。
2、 如权利要求 1所述的方法, 其特征在于, 所述标识是安全参数索引 SPI、 所述终端的 本地 IP地址或会话标识。
3、 一种隧道重协商的方法, 其特征在于, 所述方法包括:
终端向接入网关发送第一隧道建立请求消息, 使所述接入网关为所述终端分配一个标识 和业务处理模块, 并建立所述标识和所述业务处理模块的映射关系;
所述终端接收所述接入网关返回的携带所述标识的第一隧道建立响应消息;
所述终端向所述接入网关发送携带所述标识的第二隧道建立请求消息, 使所述接入网关 根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务处理模块分配给所 述终端。
4、 如权利要求 3所述的方法, 其特征在于, 所述标识是安全参数索引 SPI、 所述终端的 本地 IP地址或会话标识。
5、 一种接入网关, 其特征在于, 所述接入网关包括: 业务分发管理模块和至少一个业务 处理模块;
所述业务分发管理模块包括:
第一分配单元, 用于接收终端发送的第一隧道建立请求消息后, 为所述终端分配一个标 识和业务处理模块;
建立单元, 用于建立所述标识和所述业务处理模块的映射关系;
发送单元, 用于向所述终端返回携带所述标识的第一隧道建立响应消息;
接收单元, 用于接收所述终端发送的携带所述标识的第二隧道建立请求消息; 第二分配单元, 用于根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所 述业务处理模块分配给所述终端。
6、 如权利要求 5所述的接入网关, 其特征在于, 所述标识是安全参数索引 SPI、 所述终 端的本地 IP地址或会话标识。
7、 一种终端, 其特征在于, 所述终端包括:
第一发送模块, 用于向接入网关发送第一隧道建立请求消息, 使所述接入网关为所述终 端分配一个标识和业务处理模块, 并建立所述标识和所述业务处理模块的映射关系;
接收模块, 用于接收所述接入网关返回的携带所述标识的第一隧道建立响应消息; 第二发送模块, 用于向所述接入网关发送携带所述标识的第二隧道建立请求消息, 使所 述接入网关根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务处理模 块分配给所述终端。
8、 如权利要求 7所述的终端, 其特征在于, 所述标识是安全参数索引 SPI、 所述终端的 本地 IP地址或会话标识。
9、 一种隧道重协商的系统, 其特征在于, 所述系统包括: 终端和接入网关; 所述终端, 用于向所述接入网关发送第一隧道建立请求消息; 接收所述接入网关返回的 携带标识的第一隧道建立响应消息; 向所述接入网关发送携带所述标识的第二隧道建立请求 消息;
所述接入网关, 用于接收所述终端发送的第一隧道建立请求消息后, 为所述终端分配一 个标识和业务处理模块; 建立所述标识和所述业务处理模块的映射关系; 向所述终端返回携 带所述标识的第一隧道建立响应消息; 接收所述终端发送的携带所述标识的第二隧道建立请 求消息; 根据所述映射关系获取所述标识对应的所述业务处理模块, 并将所述业务处理模块 分配给所述终端。
10、 如权利要求 9所述的系统, 其特征在于, 所述标识是安全参数索引 SPI、 所述终端 的本地 IP地址或会话标识。
PCT/CN2010/076468 2010-08-30 2010-08-30 隧道重协商的方法和系统、以及接入网关和终端 WO2011110007A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN2010800052167A CN102396285A (zh) 2010-08-30 2010-08-30 隧道重协商的方法和系统、以及接入网关和终端
PCT/CN2010/076468 WO2011110007A1 (zh) 2010-08-30 2010-08-30 隧道重协商的方法和系统、以及接入网关和终端

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2010/076468 WO2011110007A1 (zh) 2010-08-30 2010-08-30 隧道重协商的方法和系统、以及接入网关和终端

Publications (1)

Publication Number Publication Date
WO2011110007A1 true WO2011110007A1 (zh) 2011-09-15

Family

ID=44562836

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/076468 WO2011110007A1 (zh) 2010-08-30 2010-08-30 隧道重协商的方法和系统、以及接入网关和终端

Country Status (2)

Country Link
CN (1) CN102396285A (zh)
WO (1) WO2011110007A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101197664A (zh) * 2008-01-03 2008-06-11 杭州华三通信技术有限公司 一种密钥管理协议协商的方法、系统和装置
CN101527906A (zh) * 2009-03-31 2009-09-09 刘建 在扩展服务集中建立安全关联的方法和系统
WO2009132666A1 (en) * 2008-04-30 2009-11-05 Telecom Italia S.P.A. A method for network access, related network and computer program product therefor
CN101765228A (zh) * 2010-01-29 2010-06-30 杭州华三通信技术有限公司 一种capwap隧道的恢复方法及装置

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1728713B (zh) * 2004-07-27 2010-09-22 邓里文 一种数字视频传送方法
CN100512488C (zh) * 2005-03-24 2009-07-08 华为技术有限公司 无线局域网向呈现系统提供呈现信息的方法及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101197664A (zh) * 2008-01-03 2008-06-11 杭州华三通信技术有限公司 一种密钥管理协议协商的方法、系统和装置
WO2009132666A1 (en) * 2008-04-30 2009-11-05 Telecom Italia S.P.A. A method for network access, related network and computer program product therefor
CN101527906A (zh) * 2009-03-31 2009-09-09 刘建 在扩展服务集中建立安全关联的方法和系统
CN101765228A (zh) * 2010-01-29 2010-06-30 杭州华三通信技术有限公司 一种capwap隧道的恢复方法及装置

Also Published As

Publication number Publication date
CN102396285A (zh) 2012-03-28

Similar Documents

Publication Publication Date Title
WO2021164316A1 (zh) 应用于边缘计算场景的通信方法、存储介质及电子设备
EP2608491B1 (en) Method, apparatus and system for allocating public IP address
JP5711754B2 (ja) スマートクライアントルーティング
US8166538B2 (en) Unified architecture for remote network access
WO2011147353A1 (zh) 一种报文发送方法及装置
WO2009089780A1 (fr) Procédé d'établissement d'une connexion de données dans un réseau mobile, réseau mobile et entité de contrôle de politique
WO2012051915A1 (zh) 端口映射方法、装置与通信系统
JP2012515466A (ja) Stunを使用して作成されるセッションのためのポリシーサービスシステムアーキテクチャー
WO2011144154A1 (zh) 在nat穿越中分配外网互联网协议ip地址的方法及设备、系统
WO2018192179A1 (zh) Ip地址的分配方法及装置
WO2009129707A1 (zh) 局域网之间发送、接收信息的方法和装置以及通信的系统
US20120082110A1 (en) Method and terminal for transmitting service data
JP4355000B2 (ja) 拡張したavb予約プロトコル
WO2013071765A1 (zh) 为用户终端分配ip地址的方法、装置和系统
WO2011144083A2 (zh) 策略控制方法及设备
WO2011144152A1 (zh) 信息提供方法及家庭网关、家庭网络系统
WO2017059742A1 (zh) 用户侧设备、服务器、端口资源管理方法及系统
CN111711705B (zh) 基于代理节点作双向nat实现网络连接的方法和装置
US8705471B2 (en) Method and system for implementing ID/locator mapping
US20120300776A1 (en) Method for creating virtual link, communication network element, and ethernet network system
TW201414253A (zh) 網路位址轉換系統及方法
WO2011088703A1 (zh) 一种协商配置IPv6网络参数的系统及方法
WO2015124043A1 (zh) 策略执行方法、系统、策略执行设备及控制设备
WO2011120276A1 (zh) 一种终端实现连接建立的方法及系统
WO2012149745A1 (zh) 一种数据分路传输方法及装置、系统

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201080005216.7

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10847265

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10847265

Country of ref document: EP

Kind code of ref document: A1