WO2011116598A1 - 一种对网关实现管理的方法及系统 - Google Patents

一种对网关实现管理的方法及系统 Download PDF

Info

Publication number
WO2011116598A1
WO2011116598A1 PCT/CN2010/077279 CN2010077279W WO2011116598A1 WO 2011116598 A1 WO2011116598 A1 WO 2011116598A1 CN 2010077279 W CN2010077279 W CN 2010077279W WO 2011116598 A1 WO2011116598 A1 WO 2011116598A1
Authority
WO
WIPO (PCT)
Prior art keywords
gateway
management
service
platform
security
Prior art date
Application number
PCT/CN2010/077279
Other languages
English (en)
French (fr)
Inventor
余万涛
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2011116598A1 publication Critical patent/WO2011116598A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0806Configuration setting for initial configuration or provisioning, e.g. plug-and-play

Definitions

  • the present invention relates to a wireless sensor network, and more particularly to a method and system for implementing management of a gateway in a wireless sensor network. Background technique
  • the wireless sensor network consists of a large number of miniature sensor nodes deployed in the monitoring area. Between these micro sensor nodes, a multi-hop self-organizing network system is formed by wireless communication, the purpose of which is to cooperatively perceive, collect and process the information of the sensing objects in the network coverage area, and send them to the aggregation node, and then aggregate The node then forwards this information to other networks through the gateway, eventually reaching the remote terminal, and the administrator can view, analyze, and process the information of the wireless sensor network on the remote terminal.
  • the manager is also sent to the sink node through the gateway, and then the sink node is sent to the designated sensor node in a multi-hop manner. Therefore, in a system in which a wireless sensor network is combined with other networks, the gateway is a central link device for data transmission.
  • wireless sensor networks use a wide range of communication technologies including: IEEE 802.15.4, 6LowPAN and Zigbee technologies. among them,
  • IEEE 802.15.4 is a low-speed wireless personal area network (WPAN) standard developed by IEEE. IEEE 802.15.4 specifies the physical layer and medium access control layer (MAC, Media Access Control) standards. The IEEE 802.15.4 compliant communication module features low cost, low power consumption, and small size.
  • WPAN wireless personal area network
  • IEEE 802.15.4 specifies the physical layer and medium access control layer (MAC, Media Access Control) standards.
  • MAC medium access control layer
  • the IEEE 802.15.4 compliant communication module features low cost, low power consumption, and small size.
  • the Zigbee Alliance is an organization dedicated to developing reliable, low-cost, low-power, wireless network connectivity monitoring and control products based on open global standards.
  • Zigbee standard physical layer and MAC layer use IEEE 802.15.4 technology, network layer, security management, application layer specification Fan and interoperability were developed by the Zigbee Alliance.
  • the Zigbee smart energy public applications profile and the Zigbee home automation public applications profile in the Zigbee standard are for business environment applications and home applications, respectively.
  • IPv6 over LR_PAN is a working group of the Internet Engineering Task Force (IETF). Like the Zigbee technology, the 6LowPAN technology also uses the physical layer and the MAC layer specified by IEEE 802.15.4. The difference is that the 6LowPAN technology uses the IPv6 function specified by the IETF and uses the IPv6 protocol stack. As a next-generation network protocol, IPv6 has the advantages of rich address resources, automatic address configuration, high security, and good mobility, which can meet the address and security requirements of wireless sensor networks.
  • IETF Internet Engineering Task Force
  • the wireless sensor nodes' micro-processing capabilities and wireless communication capabilities make wireless sensor networks a promising application for military applications, biological and environmental monitoring, health applications, home applications, industrial control and monitoring.
  • the data forwarding mode between the gateway and other networks may be wired or wireless.
  • the wired mode mainly includes two methods of Ethernet and public telephone network, and the information of the wireless sensor network is transmitted by using a network or a telephone line, which has high reliability, accuracy and real-time, but the connection mode is deployed.
  • the wireless method mainly utilizes a mobile communication network, broadband wireless access, satellite/microwave, and the like. Wireless mode has better adaptability to the geographical environment.
  • the telecommunication network can be utilized to monitor, manage, and complete the carrying and cooperation of the wireless sensor network and the services provided by the wireless sensor network. And expand the services provided by the wireless sensor network through the telecommunication network.
  • the gateways only have data forwarding functions.
  • the gateway is not securely managed and configured. Therefore, the management and control of the wireless sensor nodes in the wireless sensor network through the gateway is inevitably unsafe.
  • Such as wireless sensor networks and telecommunications networks When the network is connected, the attacker may use the forged wireless sensor network node to join the wireless sensor network to send the wrong service data, thereby interfering with the normal operation of the wireless sensor network service.
  • the main purpose of the present invention is to provide a method and system for implementing management of a gateway, which can perform security management and configuration on a gateway to ensure normal operation of the wireless sensor network service.
  • a method for implementing management of a gateway after the gateway accesses the telecommunication network, the method further includes: the gateway sending a registration request to the management platform;
  • the management platform creates registration information for the gateway, as well as security and management related parameters; and configures parameters for the gateway according to the created security and management related parameters.
  • the method further includes: after the gateway logs in to the management platform, sending a registration request to the service platform by using the management platform;
  • the service platform that receives the registration request creates registration information and parameters related to service security and service management for the gateway, and configures service parameters for the gateway according to the created parameters related to service security and service management.
  • the registration request carries identity information of the gateway, and user identity information.
  • the identity information of the gateway is a device number, or a uniformly defined device serial number, or information and symbols used to identify the identity of the gateway;
  • the user identity information is user identity information installed on the UICC in the gateway, or user identity information installed on a SIM card in the gateway.
  • the security and management related parameters created include: management related keys, digital certificates, and security algorithms.
  • the created service security and service management related parameters include: a service related key, a digital certificate, and a security algorithm.
  • the method further includes: the gateway feeding back an acknowledgement message to the management platform.
  • the method further includes: the gateway feeding back an acknowledgement message to the service platform via the management platform.
  • a system for implementing management of a gateway comprising at least a management platform, a telecommunication network, a gateway, and a wireless sensor network connected to the telecommunication network through a gateway, where
  • a management platform configured to receive a registration request from the gateway, create registration information and security and management related parameters for the gateway; perform parameter configuration on the gateway according to the created security and management related parameters;
  • the gateway as a terminal device of the telecommunication network, completes access authentication for accessing the telecommunication network and accesses the telecommunication network; after the gateway accesses the telecommunication network, sends a registration request to the management platform.
  • the gateway is further configured to feed back an acknowledgement message to the management platform.
  • the system also includes a business platform.
  • the gateway is further configured to log in to the management platform, and send a registration request to the service platform by using the management platform;
  • the service platform is configured to receive a registration request from the gateway, and create registration information and service security and service management related parameters for the gateway.
  • the service parameters are configured for the gateway according to the created service security and service management related parameters.
  • the gateway is further configured to feed back an acknowledgement message to the service platform via the management platform.
  • the telecommunications network is a mobile communication network, or a wireless broadband access network, or a satellite/microwave communication network, or other communication network.
  • the management platform is composed of a remote management server.
  • the gateway as the terminal device of the telecommunication network completes the access authentication of the access telecommunication network and accesses the telecommunication network, the gateway sends a registration request to the management platform, and the management platform creates the gateway. Registration information and security and management related parameters; parameter configuration of the gateway according to the created security and management related parameters.
  • the gateway can be further registered in the service platform.
  • the gateway sends a registration request to the service platform, and the service platform creates registration information and service security and management related parameters for the gateway; according to the created service security and Manage related parameters and configure parameters for the gateway.
  • These parameters of the management platform and the service platform configuration gateway will be used as the basic parameters of the gateway for subsequent wireless sensor network configuration and networking.
  • the parameters configuration and management of the gateway of the telecommunication network are realized, and these parameters will serve as basic parameters for the subsequent configuration and networking of the wireless sensor network by the gateway, thereby ensuring the normal operation of the wireless sensor network service.
  • FIG. 1 is a schematic diagram of a system for implementing a gateway in a wireless sensor network according to the present invention
  • FIG. 2 is a flowchart of a method for implementing device management for a gateway in a wireless sensor network according to the present invention
  • FIG. 3 is a schematic diagram of a gateway registered to a management platform according to the present invention. Flow chart of an embodiment
  • FIG. 4 is a flow chart of an embodiment of a gateway registration to a service platform according to the present invention. detailed description
  • FIG. 1 is a schematic diagram of a system for implementing a gateway in a wireless sensor network according to the present invention. As shown in FIG. 1, at least a management platform, a telecommunication network, a gateway, and a wireless sensor network are included.
  • the management platform is configured to receive a registration request from the gateway, create registration information for the gateway, and security and management related parameters; and configure parameters for the gateway according to the created security and management related parameters.
  • security and management related parameters include device management related keys, digital certificates and security algorithms.
  • a telecommunication network which includes a mobile communication network, such as a 2G, 3G network, etc., various types of digital subscriber line (xDSL), fiber access (FTTx), broadband wireless access, satellite/microwave, etc.
  • xDSL digital subscriber line
  • FTTx fiber access
  • the gateway as a terminal device of the telecommunication network, is used for connecting the wireless sensor network and the telecommunication network, completing access authentication of the access telecommunication network and accessing the telecommunication network; after the gateway accesses the telecommunication network, sending a registration request to the management platform;
  • the gateway has security management and control functions for nodes in the wireless sensor network.
  • Wireless sensor network connected to the telecommunications network through a gateway
  • the gateway is further configured to: after the parameter configuration of the gateway is completed by the management platform, feed back a confirmation message to the management platform, and complete the registration process of the gateway in the management platform.
  • the registration information and parameter configuration information of the gateway in the management platform are managed and maintained by the management platform.
  • the parameters of the management platform configuration gateway will be used as basic parameters for the gateway to perform wireless sensor network configuration and networking.
  • the gateway After the gateway completes the registration to the management platform, if it needs to perform service-related configuration, it needs to further register on the service platform.
  • the system of the present invention further includes a service platform, at this time,
  • the gateway is also used to log in to the management platform, and sends a registration request to the service platform through the management platform;
  • the service platform is configured to receive a registration request from the gateway, and create registration information and service security and service management related parameters for the gateway.
  • the service parameters are configured for the gateway according to the created service security and service management related parameters.
  • the parameters related to service security and service management include service-related keys, digital certificates, and security algorithms.
  • the gateway is further configured to: after the service platform configures the service parameters of the gateway, the management platform feeds back the confirmation message to the service platform, and completes the registration process of the gateway on the service platform.
  • the registration information and parameter configuration information of the gateway on the service platform are managed and maintained by the service platform.
  • these parameters of the management platform and the service platform configuration gateway will be used as the basic parameters for the gateway to perform wireless sensor network configuration and networking.
  • Both the management platform and the business platform are located in the telecommunications network.
  • the parameter configuration of the gateway of the telecommunication network is realized, and these configuration parameters will serve as basic parameters for the subsequent configuration and networking of the wireless sensor network by the gateway, thereby ensuring the normal operation of the wireless sensor network service.
  • FIG. 2 is a flowchart of a method for implementing device management on a gateway in a wireless sensor network according to the present invention. As shown in FIG. 2, the method includes the following steps:
  • Step 200 The gateway, as a terminal device of the telecommunication network, completes access authentication for accessing the telecommunication network and accesses the telecommunication network.
  • the specific implementation of this step is in accordance with the relevant standards, and is well known to those skilled in the art, and details are not described herein again.
  • the wireless sensor network is connected to the telecommunications network through a gateway.
  • the identity of the gateway is used to identify the identity information of the gateway.
  • the identity of the gateway can be a device number, or a uniformly defined device serial number, or other information and symbols that can be used to identify the identity of the gateway, such as a digital certificate.
  • the identity information of the gateway is used for secure booting and maintenance of the wireless sensor network, and is also used for security management and control of the gateway by the management platform and the service platform when the wireless sensor network is combined with the telecommunication network, such as for the gateway in the management platform. Registration management, or for the registration management of the gateway on the business platform.
  • the telecommunication network may be a mobile communication network, a wireless broadband access network, a satellite/microwave communication, etc., including a 2G mobile communication, 3G mobile communication, xDSL, FTTx, broadband wireless access, satellite/microwave, etc. kind or more.
  • Step 201 After the gateway accesses the telecommunication network, send a registration request to the management platform.
  • the management platform is an entity that implements management functions for wireless sensor networks and gateways in a telecommunication network.
  • the management platform is composed of a remote management server.
  • the remote management server implements management functions for wireless sensor networks and gateways over the telecommunications network.
  • the management platform provides management functions for wireless sensor networks and gateways for remote management terminals that monitor wireless sensor networks.
  • Step 202 The management platform creates registration information and security and management related parameters for the gateway.
  • the parameters are configured according to the created security and management related parameters.
  • the parameters that the management platform configures for the gateway may vary depending on the wireless sensor network technology.
  • Configuration parameters may include IP address related information, wireless sensor network identity information, gateway security management and authentication related information. For example, when the wireless sensor network uses the ZigBee technology, the wireless sensor network identity information may be included in the configuration parameters of the management platform to the gateway.
  • the identifier used to determine a particular wireless sensor network is referred to as the wireless sensor network identity.
  • the wireless sensor network identifier can be any information and symbol used to identify the identity of the sensor network, or it can be a digital certificate or the like.
  • identity information the wireless sensor network identity is managed and maintained by the management platform.
  • the management platform assigns a wireless sensor network identifier to it.
  • the wireless sensor network identifier is used as one of the configuration parameters, and the management platform configures the gateway.
  • the wireless sensor network identifier is used as one of the configuration parameters, and the wireless sensor node is configured by the gateway.
  • the method further includes: after the parameter configuration of the gateway is completed by the management platform, the gateway feeds back a confirmation message to the management platform, and completes the registration process of the gateway on the management platform.
  • the registration information and parameter configuration information of the gateway in the management platform are managed and maintained by the management platform.
  • the parameters of the management platform configuration gateway will be used as the basic parameters for the gateway to perform wireless sensor network configuration and networking.
  • the method of the present invention further includes: after the gateway logs in to the management platform, sends a registration request to the service platform through the management platform; the service platform that receives the registration request, creates registration information for the gateway, and relates the service security to the service management.
  • Parameters Configure the service parameters of the gateway according to the created service security and service management related parameters.
  • business security and industry Management related parameters include business related keys, digital certificates and security algorithms.
  • the method further includes: after the service platform performs the service parameter configuration on the gateway, the management platform feeds back the confirmation message to the service platform, and completes the registration process of the gateway on the service platform.
  • the registration information and parameter configuration information of the gateway on the service platform are managed and maintained by the service platform.
  • FIG. 3 is a flowchart of an embodiment of a gateway registration to a management platform according to the present invention.
  • a telecommunications network is used as a mobile communication network, and when the gateway is used for the first time, it needs to be registered on the management platform.
  • a Universal Integrated Circuit Card (UICC) card for accessing a mobile communication network is installed on the gateway.
  • the gateway uses a Subscriber Identity Module (SIM) card.
  • SIM Subscriber Identity Module
  • FIG. 3 only gives The situation where the gateway installs the UICC card is out.
  • the method for the gateway to register to the management platform includes:
  • Step 300 The gateway completes the access authentication process with the mobile communication network, and then the gateway accesses the mobile communication network.
  • the access authentication process of the gateway accessing the mobile communication network follows the standards of the mobile communication network, and is well known to those skilled in the art, and details are not described herein again.
  • Step 301 After the gateway accesses the mobile communication network, send a registration request to the management platform, where the registration request carries the identity information of the gateway, and the user identity information on the UICC, such as an International Mobile Subscriber Identity (IMSI).
  • IMSI International Mobile Subscriber Identity
  • Step 302 After receiving the registration request of the gateway, the management platform creates registration information for the gateway, for example, associating the gateway identity information with the user information and writing the database to the management platform, and generating security and management related parameters for the gateway.
  • Security and management related parameters include device management related keys, digital certificates and security algorithms.
  • Security and management related parameters such as keys
  • the security algorithm may be determined by the management platform, or through the management platform and the gateway.
  • the way of negotiation is determined.
  • the management platform performs security and management related parameter configuration on the gateway through the mobile communication network, for example, the gateway security and management related keys and digital certificates are delivered to the gateway, and are stored, managed, and used by the gateway.
  • Step 304 After the parameter configuration is completed, the gateway feeds back a confirmation message to the management platform.
  • FIG. 4 is a flowchart of an embodiment of a gateway registration to a service platform according to the present invention.
  • a telecommunications network is used as a mobile communication network.
  • the gateway When the gateway is used for the first time, registration between the management platform and the service platform may be required. In this case, the gateway needs to be further registered to the service platform after registering to the management platform through the process shown in Figure 3.
  • the UICC card used to access the mobile communication network is installed on the gateway.
  • the gateway uses the SIM card.
  • FIG. 4 only shows the case where the gateway installs the UICC card.
  • the method for the gateway to register to the service platform, as shown in Figure 4, includes:
  • Step 400 The gateway sends a login request to the management platform, where the login request carries the identity information of the gateway, and the user identity information on the UICC, such as IMSI.
  • Step 401 The management platform performs login authentication on the gateway.
  • Step 402 After the login authentication of the gateway is passed, the management platform sends a login confirmation message to the gateway.
  • Step 403 The gateway sends a registration service platform request to the service platform to the management platform, where the registration service platform request carries the identity information of the gateway, and the user identity information on the UICC, such as IMSI.
  • Step 404 After receiving the request of the registration service platform registered by the gateway to the service platform, the management platform forwards the received registration service platform request to the service platform.
  • Step 405 After receiving the registration service platform request of the gateway, the service platform creates registration information for the gateway, such as associating the gateway identity information with the user information and writing the data to the database of the service platform, and generating service security and service management related to the gateway.
  • Business security and business management related parameters include business related keys, digital certificates and security algorithms.
  • the service security and service management related parameters, such as the service key may be generated by the key distribution method selected by the service platform, or may be generated by other methods determined by the service platform; the security algorithm may be determined by the service platform, or through the service platform. Determined by the way the gateway negotiates.
  • Step 406 The service platform performs service security and service management related parameter configuration on the gateway through the management platform and the mobile communication network, for example, the gateway service security and management related key and digital certificate are sent to the gateway, and are stored by the gateway. Manage and use.
  • Step 407 After the parameter configuration is completed, the gateway returns a confirmation message to the service platform through the management platform and the mobile communication network.

Description

一种对网关实现管理的方法及系统 技术领域
本发明涉及无线传感器网络, 尤其涉及一种无线传感器网络中, 对网 关实现管理的方法及系统。 背景技术
无线传感器网络由部署在监测区域内的、 大量的微型传感器节点组成。 这些微型传感器节点之间, 通过无线通信方式形成一个多跳的自组织网络 系统, 其目的是协作地感知、 釆集和处理网络覆盖区域中感知对象的信息, 并发送至汇聚节点, 然后, 汇聚节点再通过网关将这些信息转发至其它网 络, 最终到达远程终端, 而管理人员可以在远程终端上查看、 分析以及处 理无线传感器网络的信息。 此外, 对于指定传感器节点下达的控制命令, 管理人员也是通过网关发送到汇聚节点, 然后, 汇聚节点再通过多跳方式 发送到指定传感器节点的。 因此, 在无线传感器网络与其它网络结合的系 统中, 网关是数据传输的中枢环节设备。
目前, 无线传感器网络使用比较广泛的通信技术包括: IEEE 802.15.4、 6LowPAN和 Zigbee技术。 其中,
IEEE 802.15.4 是由 IEEE 开发的低速无线个域网 (WPAN, Wireless Personal Area Network )标准。 IEEE 802.15.4规定了物理层和介质访问控制 层(MAC, Media Access Control )标准。 符合 IEEE 802.15.4标准的通信模 块具备低成本、 低耗电、 小尺寸等特点。
Zigbee联盟是一个致力于在开放的全球标准的基础上, 开发可靠的、 低成本、 低耗电、 无线网络连接的监测和控制产品的组织。 Zigbee 标准的 物理层和 MAC层釆用 IEEE 802.15.4技术, 网络层、 安全管理、 应用层规 范以及互通性由 Zigbee联盟开发。 Zigbee 标准中的 Zigbee smart energy public applications profile 和 Zigbee home automation public applications profile分别针对商业环境应用和家庭应用。
6LowPAN ( IPv6 over LR_PAN )是互联网工程任务组( IETF, Internet Engineering Task Force ) 的一个工作组。 同 Zigbee技术一样, 6LowPAN技 术也釆用的是 IEEE 802.15.4 规定的物理层和 MAC 层, 不同之处在于 6LowPAN技术使用 IETF规定的 IPv6功能, 釆用 IPv6协议栈。 IPv6作为 下一代网络协议, 具有地址资源丰富、 地址自动配置、 安全性高、 移动性 好等优点, 可以满足无线传感器网络在地址和安全方面的需求。
无线传感器节点的微处理能力和无线通信能力使无线传感器网络有广 阔的应用前景, 其应用包括军事应用、 生物和环境监测、 健康应用、 家庭应 用、 工业控制和监测等。
现有无线传感器网络中, 网关同其它网络之间的数据转发方式可以是 有线方式或无线方式两大类。 其中, 有线方式主要包括以太网和公共电话 网两种方式, 将无线传感器网络的信息利用网络或电话线传输, 具备较高 的可靠性、 准确性以及实时性, 但这种连接方式会受到部署环境的限制。 无线方式主要是利用移动通信网络、 宽带无线接入、 卫星 /微波等。 无线方 式对于地理环境具备较好的适应性。
当无线传感器网络与移动通信网络、 宽带无线接入、 公共电话网络等 电信网络结合时, 可以利用电信网络来对无线传感器网络及其提供的业务 进行监控、 管理及完成业务的承载与合作实施, 并通过电信网络扩展无线 传感器网络所提供的业务。
目前, 网关大多只具有数据转发功能, 而在网关接入时, 没有对网关 进行安全管理和配置, 这样, 通过网关对无线传感器网络中的无线传感器 节点进行的管理和控制必然是不安全的, 比如在无线传感器网络与电信网 络连接时, 攻击者可能釆用伪造的无线传感器网络节点加入到无线传感网 络, 以发送错误的业务数据, 从而干扰了无线传感器网络业务的正常运行。 发明内容
有鉴于此, 本发明的主要目的在于提供一种对网关实现管理的方法及 系统, 能够对网关进行安全管理和配置, 保证无线传感器网络业务的正常 运行。
为达到上述目的, 本发明的技术方案是这样实现的:
一种对网关实现管理的方法, 网关接入电信网络后, 该方法还包括: 网关向管理平台发送注册请求;
管理平台为网关创建注册信息, 以及安全与管理相关的参数; 并根据 创建的安全与管理相关的参数, 对网关进行参数配置。
该方法还包括: 当所述网关登录管理平台后, 通过所述管理平台向业 务平台发送注册请求;
收到注册请求的业务平台, 为网关创建注册信息及业务安全与业务管 理相关的参数, 根据创建的业务安全与业务管理相关的参数, 对网关进行 业务参数配置。
所述注册请求中携带有所述网关的身份信息, 以及用户身份信息。 所述网关的身份信息为设备号、 或统一定义的设备序列号、 或用于标 识网关身份的信息和符号;
所述用户身份信息为安装在所述网关中的 UICC上的用户身份信息,或 安装在所述网关中的 SIM卡上的用户身份信息。
所述创建的安全与管理相关的参数包括: 管理相关密钥, 数字证书和 安全算法。
所述创建的业务安全与业务管理相关的参数包括: 业务相关密钥, 数 字证书和安全算法。 该方法还包括: 所述网关向管理平台反馈确认消息。
该方法还包括: 所述网关经由所述管理平台向业务平台反馈确认消息。 一种对网关实现管理的系统, 至少包括管理平台, 电信网络, 网关和 通过网关与电信网络连接的无线传感器网络, 其中,
管理平台, 用于接收来自网关的注册请求, 为网关创建注册信息及安 全与管理相关的参数; 根据创建的安全与管理相关的参数, 对网关进行参 数配置;
网关, 作为电信网络的终端设备完成接入电信网络的接入认证并接入 电信网络; 网关接入电信网络后, 向管理平台发送注册请求。
所述网关, 还用于向所述管理平台反馈确认消息。
该系统还包括业务平台,
所述网关, 还用于登录管理平台, 并通过所述管理平台向业务平台发 送注册请求;
业务平台, 用于接收来自网关的注册请求, 为网关创建注册信息及业 务安全与业务管理相关的参数; 根据创建的业务安全与业务管理相关的参 数, 对网关进行业务参数配置。
所述网关, 还用于经由所述管理平台向业务平台反馈确认消息。
所述电信网络是移动通信网络, 或者无线宽带接入网络, 或者卫星 /微 波通信网络, 或其他通信网络。
所述管理平台由远程管理服务器组成。
从上述本发明提供的技术方案可以看出, 在网关作为电信网络的终端 设备完成接入电信网络的接入认证并接入电信网络后, 网关向管理平台发 送注册请求, 而管理平台为网关创建注册信息及安全与管理相关的参数; 根据创建的安全与管理相关的参数, 对网关进行参数配置。
进一步地, 如果网关在管理平台注册后还需要进行业务相关的配置, 那么, 网关在管理平台注册后, 可以进一步在业务平台注册, 此时, 网关 向业务平台发送注册请求, 而业务平台为网关创建注册信息及业务安全与 管理相关的参数; 根据创建的业务安全与管理相关的参数, 对网关进行参 数配置。 管理平台和业务平台配置网关的这些参数, 将作为网关在后续进 行无线传感器网络配置和组网的基本参数。
通过本发明, 实现了电信网络对网关的参数配置与管理, 而这些参数 将作为网关在后续进行无线传感器网络配置和组网的基本参数, 进而保证 了无线传感器网络业务的正常运行。 附图说明
图 1为本发明无线传感器网络中对网关实现管理的系统的组成示意图; 图 2为本发明无线传感器网络中对网关实现设备管理的方法的流程图; 图 3为本发明网关注册到管理平台的实施例的流程图;
图 4为本发明网关注册到业务平台的实施例的流程图。 具体实施方式
图 1为本发明无线传感器网络中对网关实现管理的系统的组成示意图, 如图 1 所示, 至少包括管理平台, 电信网络, 网关和无线传感器网络, 其 中,
管理平台, 用于接收来自网关的注册请求, 为网关创建注册信息, 以 及安全与管理相关的参数; 根据创建的安全与管理相关的参数, 对网关进 行参数配置。 这里, 安全与管理相关的参数包括设备管理相关密钥, 数字 证书和安全算法等。
电信网络, 所述电信网络是包括移动通信网络, 如 2G、 3G 网络等, 各种类型数字用户线路(xDSL ) 、 光纤接入(FTTx ) 、 宽带无线接入、 卫 星 /微波等远距离通信接入方式的一种或多种。 网关, 作为电信网络的终端设备用于无线传感器网络与电信网络的连 接, 完成接入电信网络的接入认证并接入电信网络; 网关接入电信网络后, 向管理平台发送注册请求; 另外, 网关对无线传感器网络中的节点具有安 全管理和控制功能。
无线传感器网络, 通过网关与电信网络连接,
进一步地, 网关还用于, 在管理平台对网关进行参数配置完成后, 向 管理平台反馈确认消息, 完成网关在管理平台的注册过程。 这里, 网关在 管理平台的注册信息和参数配置信息由管理平台管理和维护。
网关在完成到管理平台地注册后, 如果网关不需要进行业务相关配置, 那么管理平台配置网关的这些参数将作为网关在后续进行无线传感器网络 配置和组网的基本参数。
网关在完成到管理平台地注册后, 如果需要进行业务相关配置, 则需 要进一步在业务平台进行注册。 为此, 进一步地, 本发明系统还包括业务 平台, 此时,
网关, 还用于登录管理平台, 并通过管理平台向业务平台发送注册请 求;
业务平台, 用于接收来自网关的注册请求, 为网关创建注册信息及业 务安全与业务管理相关的参数; 根据创建的业务安全与业务管理相关的参 数, 对网关进行业务参数配置。 这里, 业务安全与业务管理相关的参数包 括业务相关密钥, 数字证书和安全算法等。
进一步地, 网关还用于, 在业务平台对网关进行业务参数配置完成后, 通过管理平台向业务平台反馈确认消息, 完成网关在业务平台的注册过程。 这里, 网关在业务平台的注册信息和参数配置信息由业务平台管理和维护。
在网关完成到业务平台的注册后, 管理平台和业务平台配置网关的这 些参数, 将作为网关在后续进行无线传感器网络配置和组网的基本参数。 管理平台和业务平台都在位于电信网络中。
通过本发明, 实现了电信网络对网关的参数配置, 而这些配置参数将 作为网关在后续进行无线传感器网络配置和组网的基本参数, 进而保证了 无线传感器网络业务的正常运行。
图 2为本发明无线传感器网络中对网关实现设备管理的方法的流程图, 如图 2所示, 包括以下步骤:
步骤 200: 网关作为电信网络的终端设备完成接入电信网络的接入认证 并接入电信网络。 本步骤的具体实现遵循相关标准, 属于本领域技术人员 公知技术, 这里不再赘述。
无线传感器网络通过网关与电信网络连接。 网关的身份标识用于标识 网关的身份信息。 网关的身份标识可以是设备号、 或统一定义的设备序列 号、 或其他可以用来标识网关身份的信息和符号如数字证书等。 网关的身 份信息用于无线传感器网络的安全引导和维护, 同时也用于在无线传感器 网络与电信网络结合时, 管理平台和业务平台对网关的安全管理和控制, 如用于网关在管理平台的注册管理, 或者用于网关在业务平台的注册管理。
电信网络可以是移动通信网络, 无线宽带接入网络, 卫星 /微波通信等, 包括 2G移动通信、 3G移动通信、 xDSL、 FTTx、 宽带无线接入、 卫星 /微 波等远距离通信接入方式的一种或多种。
步骤 201 : 网关接入电信网络后, 向管理平台发送注册请求。
管理平台是电信网络中对无线传感器网络及网关实施管理功能的实 体, 通常, 管理平台由远程管理服务器组成。 远程管理服务器通过电信网 络对无线传感器网络及网关实施管理功能。 另外, 管理平台还为监控无线 传感器网络的远程管理终端提供无线传感器网络及网关的管理功能。
步骤 202: 管理平台为网关创建注册信息及安全与管理相关的参数; 根 据创建的安全与管理相关的参数, 对网关进行参数配置。 管理平台对网关进行配置的参数可以根据无线传感器网络技术的不同 而不同。配置参数可以包括 IP地址相关信息,无线传感器网络身份标识信息, 网关安全管理与认证相关信息等。 例如无线传感器网络在使用 ZigBee技术 时, 在管理平台对网关的配置参数中可以包括无线传感器网络身份标识信 息。
用于确定一个具体的无线传感器网络的标识称为无线传感器网络身份 标识, 为了描述方便, 下文简称为无线传感网标识。 无线传感网标识可以 是任何用于标识传感器网络身份的信息和符号, 也可以是数字证书等。 作 为身份信息, 无线传感网标识由管理平台管理和维护。 当一个用于连接无 线传感器网络和电信网络的网关接入管理平台注册后, 管理平台会为其分 配一个无线传感网标识。 无线传感网标识作为配置参数之一, 由管理平台 对网关进行配置; 而在无线传感器组网时, 无线传感网标识作为配置参数 之一, 由网关对无线传感器节点进行配置。
本步骤之后还包括: 在管理平台对网关进行参数配置完成后, 网关向 管理平台反馈确认消息, 完成网关在管理平台的注册过程。 这里, 网关在 管理平台的注册信息和参数配置信息由管理平台管理和维护。
网关在完成到管理平台的注册后, 如果网关不需要进行业务相关配置, 那么管理平台配置网关的这些参数将作为网关在后续进行无线传感器网络 配置和组网的基本参数。
在网关完成到管理平台的注册后, 如果需要进行业务相关配置, 则网 关需要进一步在业务平台进行注册, 业务平台进一步对网关进行业务相关 参数配置。 在这种情况下, 本发明方法还包括: 当网关登录管理平台后, 通过管理平台向业务平台发送注册请求; 收到注册请求的业务平台, 为网 关创建注册信息及业务安全与业务管理相关的参数, 根据创建的业务安全 与业务管理相关的参数, 对网关进行业务参数配置。 这里, 业务安全与业 务管理相关的参数包括业务相关密钥, 数字证书和安全算法等。 其中, 进一步地, 本步骤之后还包括: 在业务平台对网关进行业务参数配置 完成后, 通过管理平台向业务平台反馈确认消息, 完成网关在业务平台的 注册过程。 这里, 网关在业务平台的注册信息和参数配置信息由业务平台 管理和维护。
下面结合实施例对本发明方法进行详细描述。
图 3 为本发明网关注册到管理平台的实施例的流程图, 本实施例以电 信网络为移动通信网络为例, 当网关初次使用时, 需要在管理平台进行注 册。 用于接入移动通信网络的通用集成电路卡(UICC )卡安装在网关上, 对于第二代移动通信网络, 网关使用用户识别模块(SIM )卡, 本实施例中 为了方便, 图 3只给出了网关安装 UICC卡的情况。 网关注册到管理平台的 方法, 如图 3所示, 包括:
步骤 300: 网关与移动通信网络完成接入认证过程,之后网关接入移动 通信网络。 网关接入移动通信网络的接入认证过程遵循移动通信网络标准 , 属于本领域技术人员公知技术, 这里不再赘述。
步骤 301 : 网关接入移动通信网络后, 向管理平台发送注册请求, 在注 册请求中携带有网关的身份信息,以及 UICC上的用户身份信息如国际移动 用户识别码(IMSI )等。
步骤 302: 收到网关的注册请求后, 管理平台为该网关创建注册信息, 如将网关身份信息和用户信息关联并写入管理平台的数据库, 并为该网关 生成安全与管理相关的参数。 安全与管理相关的参数包括设备管理相关密 钥, 数字证书和安全算法等。
其中, 安全与管理相关的参数, 如密钥可以通过管理平台选定的密钥 分散方法生成, 也可以通过管理平台确定的其他方式生成; 安全算法可以 由管理平台确定, 或者通过管理平台与网关协商的方式确定。 步骤 303:管理平台通过移动通信网络对网关进行安全与管理相关的参 数配置, 如将网关安全与管理相关的密钥和数字证书下发到网关, 并由网 关存储、 管理并使用。
步骤 304: 参数配置完成后, 网关向管理平台反馈确认消息。
图 4为本发明网关注册到业务平台的实施例的流程图, 本实施例以电 信网络为移动通信网络为例, 当网关初次使用时, 可能需要在管理平台和 业务平台都进行注册。 在这种情况下, 网关通过如图 3 所示的过程注册到 管理平台后, 需要进一步注册到业务平台。 用于接入移动通信网络的 UICC 卡安装在网关上, 对于第二代移动通信网络, 网关使用 SIM卡, 本实施例 中为了方便, 图 4只给出了网关安装 UICC卡的情况。 网关注册到业务平台 的方法, 如图 4所示, 包括:
步骤 400: 网关向管理平台发送登录请求, 在登录请求中携带有网关的 身份信息, 以及 UICC上的用户身份信息如 IMSI等。
步骤 401 : 管理平台对网关进行登录认证。
步骤 402: 管理平台对网关的登录认证通过后, 向网关发送登录确认消 息。
步骤 403: 网关向管理平台发送注册到业务平台的注册业务平台请求, 在注册业务平台请求中携带有网关的身份信息,以及 UICC上的用户身份信 息如 IMSI等。
步骤 404: 管理平台收到网关注册到业务平台的注册业务平台请求后 , 将接收到的注册业务平台请求转发给业务平台。
步骤 405: 业务平台收到网关的注册业务平台请求后, 为网关创建注册 信息, 如将网关身份信息和用户信息关联并写入业务平台的数据库, 并为 该网关生成业务安全与业务管理相关的参数。 业务安全与业务管理相关的 参数包括业务相关密钥, 数字证书和安全算法等。 其中, 业务安全与业务管理相关参数, 如业务密钥可以通过业务平台 选定的密钥分散方法生成, 也可以通过业务平台确定的其他方式生成; 安 全算法可以由业务平台确定, 或者通过业务平台与网关协商的方式确定。
步骤 406: 业务平台通过管理平台和移动通信网络,对网关进行业务安 全与业务管理相关的参数配置, 如将网关业务安全与管理相关的密钥和数 字证书下发到网关, 并由网关存储、 管理并使用。
步骤 407: 参数配置完成后, 网关通过管理平台和移动通信网络, 向业 务平台返回确认消息。
以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保 护范围, 凡在本发明的精神和原则之内所作的任何修改、 等同替换和改进 等, 均应包含在本发明的保护范围之内。

Claims

权利要求书
1、 一种对网关实现管理的方法, 网关接入电信网络后, 其特征在于, 该方法还包括:
网关向管理平台发送注册请求;
管理平台为网关创建注册信息, 以及安全与管理相关的参数; 并根据 创建的安全与管理相关的参数, 对网关进行参数配置。
2、 根据权利要求 1所述的方法, 其特征在于, 该方法还包括: 当所述 网关登录管理平台后, 通过所述管理平台向业务平台发送注册请求;
收到注册请求的业务平台, 为网关创建注册信息及业务安全与业务管 理相关的参数, 根据创建的业务安全与业务管理相关的参数, 对网关进行 业务参数配置。
3、 根据权利要求 1或 2所述的方法, 其特征在于, 所述注册请求中携 带有所述网关的身份信息, 以及用户身份信息。
4、 根据权利要求 3所述的方法, 其特征在于, 所述网关的身份信息为 设备号、 或统一定义的设备序列号、 或用于标识网关身份的信息和符号; 所述用户身份信息为安装在所述网关中的通用集成电路卡 UICC 上的 用户身份信息, 或安装在所述网关中的用户识别模块 SIM卡上的用户身份 信息。
5、 根据权利要求 1或 2所述的方法, 其特征在于, 所述创建的安全与 管理相关的参数包括: 管理相关密钥, 数字证书和安全算法。
6、 根据权利要求 2所述的方法, 其特征在于, 所述创建的业务安全与 业务管理相关的参数包括: 业务相关密钥, 数字证书和安全算法。
7、 根据权利要求 1或 2所述的方法, 其特征在于, 该方法还包括: 所 述网关向管理平台反馈确认消息。
8、 根据权利要求 2所述的方法, 其特征在于, 该方法还包括: 所述网 关经由所述管理平台向业务平台反馈确认消息。
9、 一种对网关实现管理的系统, 其特征在于, 至少包括管理平台, 电 信网络, 网关和通过网关与电信网络连接的无线传感器网络, 其中,
管理平台, 用于接收来自网关的注册请求, 为网关创建注册信息及安 全与管理相关的参数; 根据创建的安全与管理相关的参数, 对网关进行参 数配置;
网关, 作为电信网络的终端设备完成接入电信网络的接入认证并接入 电信网络; 网关接入电信网络后, 向管理平台发送注册请求。
10、 根据权利要求 9所述的系统, 其特征在于, 所述网关, 还用于向 所述管理平台反馈确认消息。
11、 根据权利要求 9或 10所述的系统, 其特征在于, 该系统还包括业 务平台,
所述网关, 还用于登录管理平台, 并通过所述管理平台向业务平台发 送注册请求;
业务平台, 用于接收来自网关的注册请求, 为网关创建注册信息及业 务安全与业务管理相关的参数; 根据创建的业务安全与业务管理相关的参 数, 对网关进行业务参数配置。
12、 根据权利要求 11所述的系统, 其特征在于, 所述网关, 还用于经 由所述管理平台向业务平台反馈确认消息。
13、 根据权利要求 9所述的系统, 其特征在于, 所述电信网络是移动 通信网络, 或者无线宽带接入网络, 或者卫星 /微波通信网络, 或其他通信 网络。
14、 根据权利要求 9或 10所述的系统, 其特征在于, 所述管理平台由 远程管理服务器组成。
PCT/CN2010/077279 2010-03-25 2010-09-25 一种对网关实现管理的方法及系统 WO2011116598A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201010141525.9A CN102202389B (zh) 2010-03-25 2010-03-25 一种对网关实现管理的方法及系统
CN201010141525.9 2010-03-25

Publications (1)

Publication Number Publication Date
WO2011116598A1 true WO2011116598A1 (zh) 2011-09-29

Family

ID=44662694

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/077279 WO2011116598A1 (zh) 2010-03-25 2010-09-25 一种对网关实现管理的方法及系统

Country Status (2)

Country Link
CN (1) CN102202389B (zh)
WO (1) WO2011116598A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111277499A (zh) * 2020-01-14 2020-06-12 浙江华云信息科技有限公司 基于gateway网关实时生效的动态路由方法

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104135459A (zh) * 2013-05-03 2014-11-05 北京优联实科信息科技有限公司 一种访问控制系统及其进行访问控制的方法
CN103888289B (zh) * 2014-02-20 2017-05-17 下一代互联网关键技术和评测北京市工程研究中心有限公司 一种网关的管控方法、网关、管控设备与系统
CN104158684B (zh) * 2014-08-15 2017-04-05 深圳市蜂联科技有限公司 基于开放式智能网关平台的网关设备状态跟踪方法
CN104202365B (zh) * 2014-08-15 2017-05-10 深圳市蜂联科技有限公司 一种集群式智能网关平台部署扩展业务应用的方法
CN107749806B (zh) * 2017-10-31 2021-01-29 普天东方通信集团有限公司 一种云平台的设备接入方法、装置及其使用的云平台
CN111327520A (zh) * 2020-01-16 2020-06-23 深圳市信锐网科技术有限公司 一种信号生成方法、信号控制系统和计算机可读存储介质
CN114980092B (zh) * 2021-02-18 2024-04-05 南宁富联富桂精密工业有限公司 安全接入方法、装置、系统及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001031842A2 (en) * 1999-10-26 2001-05-03 Telefonaktiebolaget Lm Ericsson (Publ) System and method for improved resource management in an integrated telecommunications network having a packet-switched network portion and a circuit-switched network portion
US20030033418A1 (en) * 2001-07-19 2003-02-13 Young Bruce Fitzgerald Method of implementing and configuring an MGCP application layer gateway
CN1581858A (zh) * 2003-08-05 2005-02-16 中兴通讯股份有限公司 媒体网关鉴权的方法
CN1964296A (zh) * 2006-11-24 2007-05-16 中兴通讯股份有限公司 家庭网关业务自动开通的方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001031842A2 (en) * 1999-10-26 2001-05-03 Telefonaktiebolaget Lm Ericsson (Publ) System and method for improved resource management in an integrated telecommunications network having a packet-switched network portion and a circuit-switched network portion
US20030033418A1 (en) * 2001-07-19 2003-02-13 Young Bruce Fitzgerald Method of implementing and configuring an MGCP application layer gateway
CN1581858A (zh) * 2003-08-05 2005-02-16 中兴通讯股份有限公司 媒体网关鉴权的方法
CN1964296A (zh) * 2006-11-24 2007-05-16 中兴通讯股份有限公司 家庭网关业务自动开通的方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111277499A (zh) * 2020-01-14 2020-06-12 浙江华云信息科技有限公司 基于gateway网关实时生效的动态路由方法

Also Published As

Publication number Publication date
CN102202389B (zh) 2016-03-30
CN102202389A (zh) 2011-09-28

Similar Documents

Publication Publication Date Title
US11627515B2 (en) Method for supporting lawful interception of remote ProSe UE in network
Sheng et al. Lightweight management of resource-constrained sensor devices in internet of things
US10187357B2 (en) Method and system for internetwork communication with machine devices
US10243954B2 (en) Access network assisted bootstrapping
US20190268310A1 (en) Communication system and method for machine data routing
WO2011116598A1 (zh) 一种对网关实现管理的方法及系统
CN102724175B (zh) 泛在绿色社区控制网络的远程通信安全管理架构与方法
KR101538424B1 (ko) 결제 및 원격 모니터링을 위한 사용자 단말
Zhao et al. Secure machine-type communications toward LTE heterogeneous networks
WO2011116617A1 (zh) 结合网络及无线传感器网络终端加入网络的方法
WO2011116589A1 (zh) 结合网络及无线传感器网络终端加入网络的方法
WO2010017281A2 (en) Device manager repository
CN102215560B (zh) 一种对m2m终端实现管理的方法及系统
WO2012065418A1 (zh) 一种无线传感器网络的接入方法及系统
CN102612033B (zh) 具有瘦无线接入点功能的手机以及其通信方法
WO2012075814A1 (zh) 一种mtc组设备的应用密钥管理方法及系统
WO2011113262A1 (zh) 无线传感器网络的接入方法及系统
Lai et al. Security issues on machine to machine communications
WO2014173086A1 (zh) 信息的发送、转发方法及装置
Cai et al. Design and implementation of a WiFi sensor device management system
KR101643334B1 (ko) 결제 및 원격 모니터링을 통한 제어용 m2m 보안 게이트웨이 장치 및 통신 시스템
WO2011116588A1 (zh) 结合网络及无线传感器网络终端加入网络的方法
WO2011103723A1 (zh) 一种用于管理传感器节点的方法及其装置
WO2011116591A1 (zh) 一种对无线传感器节点实现管理的方法及系统
Haseeb et al. Network Function Virtualization (NFV) based architecture to address connectivity, interoperability and manageability challenges in Internet of Things (IoT)

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10848260

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10848260

Country of ref document: EP

Kind code of ref document: A1