WO2011120464A2 - 控制用户设备接入网络的方法、装置及系统 - Google Patents

控制用户设备接入网络的方法、装置及系统 Download PDF

Info

Publication number
WO2011120464A2
WO2011120464A2 PCT/CN2011/073768 CN2011073768W WO2011120464A2 WO 2011120464 A2 WO2011120464 A2 WO 2011120464A2 CN 2011073768 W CN2011073768 W CN 2011073768W WO 2011120464 A2 WO2011120464 A2 WO 2011120464A2
Authority
WO
WIPO (PCT)
Prior art keywords
user equipment
identifier
request message
concentrator
network
Prior art date
Application number
PCT/CN2011/073768
Other languages
English (en)
French (fr)
Other versions
WO2011120464A3 (zh
Inventor
郭雅莉
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201180000528.3A priority Critical patent/CN102870485B/zh
Priority to PCT/CN2011/073768 priority patent/WO2011120464A2/zh
Publication of WO2011120464A2 publication Critical patent/WO2011120464A2/zh
Publication of WO2011120464A3 publication Critical patent/WO2011120464A3/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method, device, and system for controlling user equipment to access a network.
  • Machine Type Communications refers to network communication between one or more network elements without human intervention, such as traffic control and management, remote meter reading, remote monitoring, mobile payment, Location tracking, medical monitoring and other applications.
  • the 3rd Generation Partnership Project (3GPP) has introduced the MTC Gateway (GW) device, which acts as a normal user equipment ( The user equipment (UE) accesses the 3GPP network, and the MTC terminal (Device) can access the 3GPP network through the MTC gateway.
  • GW MTC Gateway
  • the user equipment (UE) accesses the 3GPP network
  • the MTC terminal (Device) can access the 3GPP network through the MTC gateway.
  • the MTC terminal and the MTC gateway are connected by a non-3GPP IP access system (hereinafter referred to as a non-3GPP system), for example, using Bluetooth, Zigbee, etc.
  • Distance communication technology MTC gateway and 3GPP access network are connected by 3GPP air interface technology.
  • 3GPP air interface technology 3GPP air interface technology.
  • a UE accesses a network's Mobile Management Entity (MME) through an evolved base station (eNodeB, eNB), and a monthly service gateway (Serving Gateway) , S-GW), and connected to the Packet Data Network (PDN) gateway (P-GW) via the S-GW.
  • MME Mobile Management Entity
  • eNodeB evolved base station
  • S-GW monthly service gateway
  • PDN Packet Data Network gateway
  • a UE in a Wideband Code Division Multiple Access (WCDMA) communication system, a UE is connected to a Radio Network Controller (RNC) through a base station (NodeB) and then accesses the network.
  • RNC Radio Network Controller
  • a serving node SGSN, Serving GPRS (General Packet Radio Service) Support Node
  • GGSN Gateway GPRS Support Node
  • the technology for introducing an MTC gateway device into the system so that the MTC terminal can access the network through the MTC gateway is not limited to the above-mentioned WCDMA communication system and Long Term Evolution (LTE) communication system, and can also be applied to other communication systems such as Global Interconnected Microwave Access ( Worldwide Interoperability for Microwave Access, WiMAX) communication system and Global System for Mobile communication (GSM), which are not listed here.
  • LTE Long Term Evolution
  • GSM Global System for Mobile communication
  • the MTC gateway accesses the carrier network as a common user equipment, and replaces the MTC terminal connected to it with the service server in the operator network, and the information sent by the MTC terminal carries the application layer service data of the MTC gateway. in the bag.
  • the MTC gateway communicates with the outside through the carrier network, but the MTC terminal connected to the MTC gateway is invisible. Therefore, as long as the MTC gateway successfully accesses the carrier network, any MTC terminal can access the carrier network through the MTC gateway to perform services, and the operator cannot control whether a specific MTC terminal is allowed to access the network, for example, one does not and the operator.
  • the contracted MTC terminal can also conduct services through the MTC gateway.
  • Embodiments of the present invention provide a method, device, and system for controlling user equipment to access a network.
  • a method for controlling user equipment access to a network comprising:
  • the session connection request message is used to request to establish a session connection for a user equipment connected to the user equipment concentrator;
  • a mobility management entity MME comprising:
  • a receiving module configured to receive a session connection request message sent by the user equipment concentrator, where the session connection request message is used to request to establish a session connection for a user equipment connected to the user equipment concentrator;
  • An acquiring module configured to acquire a user equipment identifier carried in the session connection request message
  • an access control module configured to control, according to the user equipment identifier, the user equipment to access the network.
  • a user equipment concentrator includes:
  • An obtaining module configured to obtain a user equipment identifier
  • a sending module configured to send a session connection request message to the mobility management entity MME, where the session connection request message carries the user equipment identifier.
  • a communication system comprising: a user equipment concentrator, and a user equipment and a mobility management entity MME respectively connected to the user equipment concentrator;
  • the user equipment is configured to send a user equipment identifier to the user equipment concentrator
  • the user equipment concentrator is configured to acquire a user equipment identifier, and send a session connection request message to the mobility management entity MME, where the session connection request message carries the user equipment identifier, and is used to request to establish a session connection for the user equipment;
  • the MME is configured to receive a session connection request message sent by the user equipment concentrator, obtain the user equipment identifier carried in the session connection request message, and control the user equipment to access the network according to the user equipment identifier.
  • the method provided by the embodiment of the present invention adopts a technical solution for acquiring a user equipment identifier by using a user equipment concentrator and controlling a user equipment to access the network according to the user equipment identifier.
  • the mobility management entity can obtain the user equipment identifier through the user equipment concentrator, and then control the user equipment to access the network according to the user equipment identifier, which solves the problem that the user equipment accessing the network through the MTC gateway cannot be distinguished and controlled in the prior art.
  • FIG. 1 is a schematic diagram of a network architecture of an existing 3GPP system
  • FIG. 2 is a schematic diagram of a network architecture of an existing SAE communication system
  • FIG. 3 is a schematic diagram of a network architecture of a conventional WCDMA communication system
  • FIG. 4 is a flowchart of a method for controlling a user equipment to access a network according to an embodiment of the present invention
  • FIG. 5 is a schematic diagram of an example of an application scenario according to an embodiment of the present invention
  • FIG. 6 is a schematic diagram of an example of another application scenario according to an embodiment of the present invention
  • FIG. 7 is a schematic diagram of a logical structure of a mobility management entity according to an embodiment of the present invention.
  • FIG. 8 is a schematic diagram of a logical structure of a user equipment concentrator according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram of a network architecture of a communication system according to an embodiment of the present invention.
  • An embodiment of the present invention provides a method for controlling a user equipment to access a network, and adopts a technical solution for acquiring a user equipment identifier by using a user equipment concentrator and controlling a user equipment to access the network according to the user equipment identifier.
  • the mobility management entity can obtain the user equipment identifier by using the user equipment concentrator, and then control the user equipment to access the network according to the user equipment identifier, which solves the problem in the prior art.
  • the user equipment of the MTC gateway accessing the network cannot distinguish the technical problems of the control.
  • Embodiments of the present invention also provide corresponding devices and systems. The details are described below separately.
  • an embodiment of the present invention provides a method for controlling a user equipment to access a network, where the user equipment is connected to a user equipment concentrator, and the user equipment concentrator has accessed the network and is connected to a mobility management entity in the network.
  • the method includes:
  • the mobility management entity receives a session connection request message sent by the user equipment concentrator, where the session connection request message is used to request to establish a session connection for the user equipment connected to the user equipment concentrator, and obtain the session connection request.
  • User equipment identifier carried by the message.
  • the user equipment concentrator is connected on the one hand to the user equipment on the user side, and on the other hand to the mobile management entity on the network side.
  • the mobility management entity obtains the identity of the user equipment by interacting with the message of the user equipment concentrator.
  • the user equipment concentrator may be an MTC gateway or a common gateway.
  • the MTC gateway is used as an example in this document.
  • the user equipment can be various types of terminals. In this paper, the MTC terminal is taken as an example for description.
  • the MTC gateway can connect to the MTC terminal through non-3GPP air interface technologies such as Bluetooth or Zigbee.
  • the MTC gateway can connect to the carrier network through 3GPP air interface technology. It can be seen that the MTC terminal can access the carrier network through the MTC gateway in different session connections, and the session connection can be a PDN connection or a service data flow granularity.
  • the MME can obtain the identifier of the MTC terminal by interacting with the message of the MTC gateway.
  • Control according to the user equipment identifier, the user equipment to access the network.
  • the MME can identify the specific user equipment, so that whether the user equipment is connected to the network can be controlled according to the user equipment identifier. For example, a specific MTC terminal is connected to the network, or the connection of the MTC terminal that has accessed the network to the network is disconnected. Further, it is also possible to perform differentiated charging or other control for a specific MTC terminal.
  • the MME may perform authentication on the user equipment according to the user equipment identifier.
  • the user equipment is controlled to access the network according to the authentication result, and: if the authentication is passed, the user equipment is connected to the network, and the authentication is performed. If it fails, the user equipment is denied access to the network.
  • the MTC terminal is network-authenticated according to the identifier of the MTC terminal acquired from the MTC gateway, and when the authentication is passed, the MTC terminal is connected to the network.
  • the PDN gateway connected to the MME in the network may also obtain the identifier of the MTC terminal from the MME, and then perform the network on the MTC terminal according to the identifier of the obtained MTC terminal.
  • Network authentication when the authentication is passed, the MTC terminal is connected to the network. This ensures that only legitimate MTC terminals can access the network.
  • the MME may establish a correspondence between the user equipment identifier and the session connection, so as to distinguish and control services of different user equipments according to the corresponding relationship. For example, the MME may disconnect the MTC terminal from the network according to the correspondence between the MTC terminal connected to the network and the session connection. For another example, the MME may issue an indication to the PDN gateway according to the correspondence to control the PDN gateway to disconnect the MTC terminal from the network. Of course, the PDN gateway can directly perform the operation of disconnecting the corresponding MTC terminal from the network according to the obtained correspondence.
  • the mobility management entity can obtain the user equipment identifier through the user equipment concentrator, so that the user equipment access network can be controlled according to the obtained user equipment identifier, and the prior art is adopted to pass the The user equipment of the MTC gateway accessing the network cannot distinguish the technical problems of the control.
  • the MME may also establish a correspondence between the user equipment identifier and the session connection, identify the accessed user equipment according to the correspondence, control the service of the accessed user equipment, and perform various control operations for the user equipment, for example, specific The MTC terminal accesses the network, or disconnects a specific MTC terminal from the network, and performs charging for a specific MTC terminal.
  • the MTC gateway as the user equipment concentrator may establish an independent PDN connection for each MTC terminal that is connected to the user equipment, and carry the acquired first identifier of the MTC terminal in the PDN connection establishment request.
  • the message is sent to the MME.
  • the MME obtains the first identifier of the MTC terminal by receiving the PDN connection establishment request message sent by the MTC gateway, and controls the MTC terminal to access the network according to the first identifier of the MTC terminal.
  • the MME may also establish a correspondence between the PDN connection and the MTC terminal, including: establishing a correspondence between the PDN connection and the acquired first identifier of the MTC terminal, establishing a PDN connection, and establishing an MTC terminal obtained by the MME from the device for authentication authentication. Correspondence of the second identifier.
  • the MME sends a setup session request message carrying the first or second identifier of the MTC terminal to the PDN gateway, so that the PDN gateway can also establish a correspondence between the PDN connection and the first or second identifier of the MTC terminal, and the PDN gateway can also Assign a temporary identity to the MTC terminal, and establish a correspondence between the PDN connection and the temporary identity.
  • the services of the MTC terminal can be controlled according to the corresponding relationship.
  • the MTC gateway as the user equipment concentrator may assign a specific port number to each MTC terminal connected to it as a user equipment, so that each MTC terminal corresponds to one
  • the service data flow information corresponding to the port of the MTC terminal and the port allocated by the MTC gateway for the MTC terminal is carried in the bearer resource modification request message and sent to the MME.
  • the MME obtains the first identifier of the MTC terminal by receiving the bearer resource modification request message sent by the MTC gateway. Controlling, by the first identifier of the MTC terminal, the MTC terminal accessing the network. Furthermore, the MME can also establish a correspondence between the service data flow information and the MTC terminal.
  • the MME sends a bearer resource command message carrying the first or second identifier of the MTC terminal to the PDN gateway, so that the PDN gateway can also establish a correspondence between the service data flow information and the first or second identifier of the MTC terminal, and the PDN gateway further
  • a temporary identity identifier may be allocated to the MTC terminal, and a correspondence between the service data flow information and the temporary identity identifier is established.
  • the PDN gateway may also bind the service data flow to the specific bearer; and establish a correspondence between the bearer ID (IDentity) and the first identifier or the second identifier or the temporary identifier of the MTC terminal. After the foregoing correspondence is established, various services of the MTC terminal can be controlled according to the corresponding relationship.
  • the SAE communication system includes an MME and a PDN gateway connected to the MME through the serving gateway, and may further include a device for authentication authentication, such as a Home Subscriber Server (HSS), or an Authentication Authorization Accounting (Authentication Authorization Accounting) , AAA), or Equipment Identity Register (EIR), etc.
  • HSS Home Subscriber Server
  • AAA Authentication Authorization Accounting
  • EIR Equipment Identity Register
  • the MTC gateway as the user equipment concentrator is attached to the carrier network as the UE.
  • the method of the embodiment of the present invention is executed. In order to establish an independent PDN connection for the MTC terminal, and control the MTC terminal to access the network. Proceed as follows:
  • the MTC gateway sends a PDN connection setup request message carrying an identifier of the MTC terminal to the MME.
  • the identifier of the MTC terminal may be an International Mobile Subscriber Identification Number (IMSI) or a Mobile Station Equipment Identity (ME identity) of the MTC terminal or may be a protocol configuration carried in the message.
  • IMSI International Mobile Subscriber Identification Number
  • ME identity Mobile Station Equipment Identity
  • PCO Protocol Configuration Options
  • the MME may perform network authentication on the MTC terminal according to the identifier of the received MTC terminal. For example, if the identifier of the received MTC terminal is an IMSI, the MME may send the IMSI to the HSS for authentication to determine whether the IMSI is allowed to access the network; and may also perform Authentication and Key Agreement (AKA). ; The process is connected for authentication.
  • the identifier of the MTC terminal of the MJ terminal is ME identity, and the MME can send the received ME identity to the EIR for checking to determine whether the ME identity is allowed to access the network. If the authentication succeeds, the subsequent steps are performed. If the authentication fails, the PDN connection failure message is returned to the MTC gateway. It should be noted that this step is not a necessary step.
  • the MME establishes a correspondence between the PDN connection and the MTC terminal identifier, and the identifier of the MTC terminal may be an IMSI or an ME identity. If the step 502 is performed, and the MME obtains the Mobile Subscriber International ISDN/PSTN number (MSISDN) of the MTC terminal from the HSS, the identifier of the terminal in the corresponding relationship may also be an MSISDN.
  • MSISDN Mobile Subscriber International ISDN/PSTN number
  • the MME carries the identifier of the MTC terminal in the setup session request message and sends it to the PDN gateway. If the MME receives the information such as the username and password carried in the PCO in step 501, the MME does not parse the PCO, and directly carries the PCO in the setup session request message and sends it to the PDN gateway.
  • the setup session request message can be relayed via the Serving Gateway (Serving GW).
  • the PDN gateway After receiving the session establishment request message, the PDN gateway establishes a correspondence between the PDN connection and the identifier of the MTC terminal, where the identifier of the MTC terminal may be IMSI, or ME identity or MSISDN. If the PDN gateway receives the username and password carried in the PCO, the PDN gateway can also send the username and password to the external Remote Authentication Dial In User Service (RADIUS) server for authentication. Then, the MTC terminal information carried in the PCO, that is, the correspondence between the user name and the password and the PDN connection is established; or the temporary identity identifier may be allocated to the MTC terminal according to the MTC terminal information carried in the PCO, and the correspondence between the temporary identity identifier and the PDN connection is established. relationship. The PDN gateway then returns a setup session response message to the MME.
  • the PDN gateway After receiving the session establishment request message, the PDN gateway establishes a correspondence between the PDN connection and the identifier of the MTC terminal, where the identifie
  • the MME After receiving the setup session response message returned by the PDN gateway, the MME returns a PDN connection setup response message to the MTC gateway, and allows the PDN connection to be established, so that the MTC terminal can access the network through the PDN connection.
  • the mapping between the MTC terminal and the PDN connection may be established, and according to the corresponding relationship, the MTC terminal may perform control of the distinguishing device, for example, initiate a process of disconnecting the PDN connection.
  • the corresponding MTC terminal is no longer connected to the network; or the PDN gateway performs the charging for distinguishing the MTC terminal according to the corresponding relationship, for example, according to the IP address of the data stream, it can distinguish which PDN connection the data stream belongs to, and further distinguish the data flow belongs to Which MTC terminal, in order to differentiate the billing of the MTC terminal.
  • the MME or the PDN gateway can perform network authentication on the MTC terminal to ensure that only the legal MTC terminal can access the carrier network.
  • the MTC gateway as the user equipment concentrator is attached to the carrier network as the UE.
  • the MTC gateway detects that the connected MTC terminal as the user equipment is started, the method of the embodiment of the present invention is executed. And controlling the MTC terminal to access the network. Proceed as follows:
  • the MTC gateway allocates a specific port number to the MTC terminal, so that the MTC terminal corresponds to one or more specific service data flows. Then, the MTC gateway sends a bearer resource modification request message to the MME, where the message carries the service data flow information and the identifier of the corresponding MTC terminal.
  • the identifier of the MTC terminal may be an International Mobile Subscriber Identity (IMSI) or ME identity of the MTC terminal or may be information such as a username and password carried in the PCO of the message.
  • IMSI International Mobile Subscriber Identity
  • ME identity may be information such as a username and password carried in the PCO of the message.
  • the MME may perform network authentication on the MTC terminal according to the identifier of the received MTC terminal. For example, if the identifier of the received MTC terminal is IMSI, the MME may send the IMSI to the HSS for authentication to determine whether the IMSI is allowed to access the network; or perform an AKA procedure for access authentication. If the identifier of the received MTC terminal is ME identity, the MME may send the received ME identity to the EIR for checking to determine whether the ME identity is allowed to access the network. If the authentication succeeds, the subsequent steps are performed. If the authentication fails, a bearer resource modification reject message is returned to the MTC gateway. It should be noted that this step is not a necessary step.
  • the MME establishes a correspondence between the service data flow information and the identifier of the MTC terminal, and the identifier of the MTC terminal may be an IMSI or an ME identity. If the step 602 is performed, and the MME obtains the mobile subscriber international number (MSISDN) of the MTC terminal from the HSS, the identifier of the terminal in the corresponding relationship may also be an MSISDN.
  • MSISDN mobile subscriber international number
  • the MME carries the service data flow information and the identifier of the corresponding MTC terminal in the bearer resource command message and sends the message to the PDN gateway. If the MME receives the information carried in the PCO in step 6 Information such as the account name and password, then the MME does not parse the PCO, and directly carries the PCO in the bearer resource command message and sends it to the PDN gateway.
  • the bearer resource command message may be relayed via a Serving Gateway (Serving GW).
  • the PDN gateway After receiving the resource command message, the PDN gateway establishes a correspondence between the service data flow information and the identifier of the MTC terminal, where the identifier of the MTC terminal may be IMSI, or ME identity or MSISDN. If the PDN gateway receives the username and password carried in the PCO, the PDN gateway can also send the username and password to the external Radius server for authentication. If the authentication is successful, the MTC terminal information carried in the PCO, that is, the username and password, is established. Corresponding relationship of the service data flow information; or the temporary identity identifier may be allocated to the MTC terminal according to the MTC terminal information carried in the PCO, and the correspondence between the temporary identity identifier and the PDN connection is established. Then, the PDN gateway initiates a bearer setup or modification procedure according to the received service data flow information, so as to access the MTC terminal to the network.
  • the PDN gateway initiates a bearer setup or modification procedure according to the received service data flow information, so as to access the MTC
  • the PDN gateway can also change the session connection information in the corresponding relationship.
  • the service data flow corresponding to one MTC terminal can be bound to a specific bearer according to the correspondence between the received service data flow information and the identifier of the MTC terminal.
  • the mapping between the bearer ID and the identifier of the MTC terminal is established, or the correspondence between the bearer ID and the temporary identity identifier allocated to the MTC terminal is established, and the corresponding relationship is carried in the bearer setup or modification message and sent to the MME.
  • the bearer setup or modification message can be relayed via a Serving Gateway (Serving GW).
  • Serving Gateway Serving Gateway
  • the MME and the PDN gateway on the network side can establish a correspondence between the service data flow information (or bearer ID) corresponding to the port allocated by the MTC terminal and the MTC terminal, and according to the corresponding relationship,
  • the MTC terminal performs the control of the distinguishing device.
  • the PDN gateway may delete the message of the specific service data flow (or the specific bearer) according to the request sent by the received MME, or modify the existing bearer or delete the existing bearer according to the corresponding relationship saved by itself. There is a bearer to delete a specific service data stream, so that the corresponding MTC terminal is no longer allowed to access the network.
  • the PDN gateway can also perform the charging of the MTC terminal according to the corresponding relationship.
  • the MTC terminal can be distinguished according to the traffic quantity information, so as to distinguish the charging of the MTC terminal.
  • the MME or the PDN can also perform network authentication on the MTC terminal to ensure that only the legitimate MTC terminal can access the carrier network.
  • the method of the embodiment of the present invention is not limited to use in an SAE communication system, and may also be used in other communication systems such as a universal mobile communication system (Universal Mobile Telecommunications). System, UMTS).
  • UMTS Universal Mobile Telecommunications
  • the network side device includes an SGSN corresponding to ⁇ in the LTE communication system and a GGSN corresponding to the PDN gateway, and may also include a Home Location Register (HLR) equivalent to the HSS, and the like.
  • HLR Home Location Register
  • an embodiment of the present invention further provides a mobility management entity MME, including: a receiving module 701, configured to receive a session connection request message sent by a user equipment concentrator, where the session connection request message is used to request a User equipment connected by the user equipment concentrator establishes a session connection;
  • a receiving module 701 configured to receive a session connection request message sent by a user equipment concentrator, where the session connection request message is used to request a User equipment connected by the user equipment concentrator establishes a session connection;
  • the obtaining module 702 is configured to obtain the user equipment identifier carried in the session connection request message, and the access control module 703 is configured to control the user equipment to access the network according to the user equipment identifier.
  • the access control module 703 can include:
  • An authentication unit configured to authenticate the user equipment according to the user equipment identifier; and an access control unit, configured to access the user equipment to the network if the authentication succeeds.
  • the access control module 703 can include:
  • a establishing unit configured to establish a correspondence between the user equipment identifier and the session connection
  • a service control unit configured to separately control services of different user equipments according to the corresponding relationship.
  • the receiving module 701 is specifically configured to receive a PDN connection setup request message sent by the user equipment concentrator;
  • the obtaining module 702 is specifically configured to acquire a first identifier of the user equipment carried in the PDN connection establishment request message.
  • the establishing unit may be specifically configured to establish a correspondence between the PDN connection and the user equipment.
  • the receiving module 701 is specifically configured to receive a bearer resource modification request message sent by the user equipment concentrator;
  • the obtaining module 702 is specifically configured to obtain the first identifier of the user equipment and the service data flow information corresponding to the port allocated by the MTC gateway to the user equipment.
  • the establishing unit may be specifically configured to establish the service data flow information and the user equipment. Correspondence.
  • the MME provided by the embodiment of the present invention can obtain the user equipment identifier by using the user equipment concentrator, and can control the user equipment to access the network according to the obtained user equipment identifier, and solve the problem that the user equipment accesses the network through the MTC gateway in the prior art. It is impossible to distinguish technical issues of control.
  • the MME may also establish a correspondence between the user equipment identifier and the session connection, identify the accessed user equipment according to the correspondence, control the service of the accessed user equipment, and perform various control operations for the user equipment, for example, specific The MTC terminal accesses the network, or disconnects a specific MTC terminal from the network, and performs charging for a specific MTC terminal.
  • an embodiment of the present invention further provides a user equipment concentrator, including:
  • the obtaining module 801 is configured to obtain a user equipment identifier.
  • the sending module 802 is configured to send a session connection request message to the mobility management entity MME, where the session connection request message carries the user equipment identifier.
  • the obtaining module 801 is specifically configured to acquire a first identifier of the user equipment.
  • the sending module 802 is specifically configured to send a PDN connection setup request message to the MME, where
  • the PDN connection setup request message carries the first identifier of the user equipment.
  • the obtaining module 801 is configured to obtain the first identifier of the user equipment and the service data flow information corresponding to the port allocated by the user equipment concentrator to the user equipment;
  • the sending module 802 is specifically configured to send a bearer resource modification request message to the MME, where the bearer resource modification request message carries a first identifier of the user equipment and a port corresponding to the port allocated by the user equipment concentrator to the user equipment.
  • Business data flow information is specifically configured to send a bearer resource modification request message to the MME, where the bearer resource modification request message carries a first identifier of the user equipment and a port corresponding to the port allocated by the user equipment concentrator to the user equipment.
  • the user equipment concentrator provided by the embodiment of the present invention can carry the identifier of the user equipment in the session connection request message and send the message to the MME, so that the MME can control the user equipment to access the network according to the obtained user equipment identifier, which solves the prior art.
  • the technical problem of the control cannot be distinguished for the user equipment accessing the network through the MTC gateway.
  • an embodiment of the present invention further provides a communication system, including:
  • the user equipment 900 is configured to send the user equipment identifier to the user equipment concentrator.
  • the user equipment concentrator 800 is configured to acquire the user equipment identifier, send a session connection request message to the MME 700, and the session connection request message is carried.
  • the user equipment identifier is used to request to establish a session connection for the user equipment;
  • the MME 700 is configured to receive a session connection request message sent by the user equipment concentrator 800, obtain a user equipment identifier carried in the session connection request message, and control the user equipment to access the network according to the user equipment identifier.
  • the mobility management entity can obtain the user equipment identifier by using the user equipment concentrator, so as to control the user equipment to access the network according to the obtained user equipment identifier, and solve the problem in the prior art for passing the MTC.
  • the user equipment that the gateway accesses the network cannot distinguish the technical problems of the control.
  • the MME may also establish a correspondence between the user equipment identifier and the session connection, identify the accessed user equipment according to the correspondence, control the service of the accessed user equipment, and perform various control operations for the user equipment, for example, specific
  • the MTC terminal accesses the network, or disconnects a specific MTC terminal from the network, and performs charging for a specific MTC terminal.
  • the embodiment of the present invention is not limited to the application in the MTC field, and the scenario in which the common user equipment accesses the network through the device concentrator is also applicable to the method provided by the present invention. That is, the user equipment can be used instead of the MTC terminal, and the user equipment concentrator can be used instead of the MTC concentrator.
  • the program may be stored in a computer readable storage medium, and the storage medium may include: Read only memory, random access memory, disk or optical disk, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

一种控制用户设备接入网络的方法,包括:移动管理实体接收用户设备集中器发送的会话连接请求消息,所述会话连接请求消息用于请求为一个与用户设备集中器连接的用户设备建立会话连接,获取所述会话连接请求消息携带的用户设备标识,根据所述用户设备标识控制所述用户设备接入网络。本发明实施例还提供相应的装置及系统。本发明实施例的技术方案中,移动管理实体可以通过用户设备集中器获取用户设备标识,从而根据用户设备标识控制用户设备接入网络,解决了现有技术中对通过用户设备集中器接入网络的用户设备无法区分控制的技术问题。

Description

控制用户设备接入网络的方法、 装置及系统
技术领域
本发明涉及通信技术领域, 具体涉及一种控制用户设备接入网络的方法、 装置及系统。
背景技术
机器类型通讯( Machine Type Communications, MTC )指的是一个或者多 个网元之间在不需要人为参与的情况下进行的网络通讯, 如交通控制与管理、 远程抄表、 远程监控、 移动支付、 定位跟踪、 医疗监护等应用。
MTC 的广泛应用使无线通信终端的数量迅速增加, 为此, 第三代合作伙 伴计划( 3rd Generation Partnership Project, 3 GPP )引入了 MTC网关( Gateway, GW )设备, MTC 网关作为一个普通用户设备 ( User Equipment, UE )接入 3GPP网络, 则 MTC终端 ( Device )可以通过 MTC网关接入 3GPP网络。 如 图 1所示, MTC终端与 MTC网关之间通过非 3GPP空口技术的接入( Non 3GPP IP Access ) 系统(以下筒称为非 3GPP 系统)相连, 例如采用蓝牙, 敫蜂 ( Zigbee )等短距离通信技术; MTC网关与 3GPP接入网之间则通过 3GPP空 口技术相连。 下面举例说明。
请参考图 2, 系统架构演进(System Architecture Evolution, SAE )通信系 统中, UE通过演进基站 (eNodeB, eNB )接入网络的移动管理实体(Mobile Management Entity, MME ) 以及月良务网关( Serving Gateway, S-GW ), 并经 过 S-GW连接到分组数据网 (Packet Data Network, PDN ) 的网关( P-GW )。
请参考图 3 , 宽带码分多址接入 ( Wideband Code Division Multiple Access ,WCDMA )通信系统中, UE经过基站( NodeB )连接到无线网络控制 器( Radio Network Controller, RNC )再接入网络的通用分组无线业务的服务 节点 ( SGSN, Serving GPRS ( General Packet Radio Service ) Support Node ), 并通过 SGSN连接到通用分组无线业务的网关节点 (GGSN, Gateway GPRS Support Node )。
在系统中引入 MTC网关设备,使 MTC终端可以通过 MTC网关接入网络 的技术并不局限于上述的 WCDMA 通信系统和长期演进 ( Long Term Evolution, LTE )通信系统, 还可以应用于其它通信系统如全球互联微波接入 ( Worldwide Interoperability for Microwave Access , WiMAX )通信系统和全 ί求 移动通信系统 ( Global System for Mobile communication, GSM ), 此处不再一 一列举。
在上述的应用中, MTC网关作为一个普通用户设备 UE接入运营商网络, 代替与其相连的 MTC终端与运营商网络中的业务服务器交互, MTC终端发送 的信息携带在 MTC网关的应用层业务数据包中。 对于运营商网络而言, 能看 到 MTC网关通过运营商网络与外部通信,但是, 与 MTC网关相连的 MTC终 端则是不可见的。 从而, 只要 MTC网关成功接入运营商网络, 任何 MTC终 端都可以通过该 MTC网关接入运营商网络进行业务, 运营商无法控制是否允 许特定的 MTC终端接入网络, 例如, 一个没有和运营商签约的 MTC终端也 可以通过 MTC网关进行业务。
发明内容
本发明实施例提供一种控制用户设备接入网络的方法、 装置及系统。
一种控制用户设备接入网络的方法, 包括:
接收所述用户设备集中器发送的会话连接请求消息,所述会话连接请求消 息用于请求为一个与用户设备集中器连接的用户设备建立会话连接;
获取所述会话连接请求消息携带的用户设备标识;
根据所述用户设备标识控制所述用户设备接入网络。
一种移动管理实体 MME, 包括:
接收模块, 用于接收用户设备集中器发送的会话连接请求消息, 所述会话 连接请求消息用于请求为一个与用户设备集中器连接的用户设备建立会话连 接;
获取模块, 用于获取所述会话连接请求消息携带的用户设备标识; 接入控制模块, 用于根据所述用户设备标识控制所述用户设备接入网络。 一种用户设备集中器, 包括:
获取模块, 用于获取用户设备标识;
发送模块, 用于发送会话连接请求消息给移动管理实体 MME, 所述会话 连接请求消息携带所述用户设备标识。
一种通信系统, 包括: 用户设备集中器,以及分别与所述用户设备集中器相连的用户设备和移动 管理实体 MME;
所述用户设备, 用于发送用户设备标识给所述用户设备集中器;
所述用户设备集中器, 用于获取用户设备标识,发送会话连接请求消息给 移动管理实体 MME, 所述会话连接请求消息携带所述用户设备标识, 用于请 求为所述用户设备建立会话连接;
所述 MME, 用于接收用户设备集中器发送的会话连接请求消息, 获取所 述会话连接请求消息携带的用户设备标识,根据所述用户设备标识控制所述用 户设备接入网络。
本发明实施例提供的方法, 采用通过用户设备集中器获取用户设备标识, 根据用户设备标识控制用户设备接入网络的技术方案。该技术方案中,移动管 理实体可以通过用户设备集中器获取用户设备标识,进而根据用户设备标识控 制用户设备接入网络, 解决了现有技术中对于通过 MTC网关接入网络的用户 设备无法区分控制的技术问题。
附图说明
图 1是现有的 3GPP系统的网络架构示意图;
图 2是现有的 SAE通信系统的网络架构示意图;
图 3是现有的 WCDMA通信系统的网络架构示意图;
图 4是本发明实施例提供的控制用户设备接入网络的方法的流程图; 图 5是本发明实施例提供的方法用于一个应用场景例的示意图;
图 6是本发明实施例提供的方法用于另一个应用场景例的示意图; 图 7是本发明实施例提供的移动管理实体的逻辑结构示意图;
图 8是本发明实施例提供的用户设备集中器的逻辑结构示意图;
图 9是本发明实施例提供的通信系统的网络架构示意图。
具体实施方式
本发明实施例提供一种控制用户设备接入网络的方法,采用通过用户设备 集中器获取用户设备标识,根据用户设备标识控制用户设备接入网络的技术方 案。该技术方案中,移动管理实体可以通过用户设备集中器获取用户设备标识, 进而根据用户设备标识控制用户设备接入网络, 解决了现有技术中对于通过 MTC网关接入网络的用户设备无法区分控制的技术问题。 本发明实施例还提 供相应的装置及系统。 以下分别进行详细说明。
请参考图 4, 本发明实施例提供一种控制用户设备接入网络的方法, 所述 用户设备与用户设备集中器连接,所述用户设备集中器已接入网络与网络中的 移动管理实体连接, 所述方法包括:
101、 移动管理实体(MME )接收用户设备集中器发送的会话连接请求消 息,所述会话连接请求消息用于请求为一个与用户设备集中器连接的用户设备 建立会话连接, 获取所述会话连接请求消息携带的用户设备标识。
用户设备集中器一方面与用户侧的用户设备连接,一方面与网络侧的移动 管理实体连接。移动管理实体通过与用户设备集中器的消息交互获取用户设备 的标识。 其中, 用户设备集中器可以是 MTC网关, 也可以是普通网关, 本文 中以 MTC网关为例进行说明。用户设备可以是各种类型的终端,本文中以 MTC 终端为例进行说明。
在用户侧, MTC网关可以通过非 3GPP空口技术例如蓝牙或微微蜂 ( Zigbee )等与 MTC终端相连; 在网络侧, MTC网关可以通过 3GPP空口技术 与运营商网络相连。 可见, MTC终端可以通过 MTC网关以不同的会话连接方 式接入运营商网络,所说的会话连接可以是 PDN连接,或者业务数据流粒度等。 MME可以通过与 MTC网关的消息交互获取 MTC终端的标识。
102、 根据用户设备标识控制用户设备接入网络。
MME获取用户设备标识后, 就可以识别特定的用户设备, 从而可以根据 用户设备标识控制是否将用户设备接入网络。 例如将特定的 MTC终端接入网 络, 或者将已经接入网络的 MTC终端与网络的连接断开等。 进而, 还可以对 特定 MTC终端进行区分计费或者其它控制。
在一种实施方式中, MME可以根据所述用户设备标识对所述用户设备进 行认证; 根据认证结果, 控制用户设备接入网络, 包括: 若认证通过, 将所述 用户设备接入网络, 认证未通过, 则拒绝将用户设备接入网络。 例如, 根据从 MTC网关获取的 MTC终端的标识对该 MTC终端进行网络认证,在认证通过时, 将 MTC终端接入网络。 并且, 网络中与 MME连接的 PDN网关也可以从 MME 获取 MTC终端的标识, 进而根据获取的 MTC终端的标识对该 MTC终端进行网 络认证, 在认证通过时, 将 MTC终端接入网络。 从而保证, 只有合法的 MTC 终端才可以接入网络。
在一种实施方式中, MME可以建立用户设备标识与会话连接的对应关系, 以便根据该对应关系区分控制不同用户设备的业务。 例如, MME可以根据已 接入网络的 MTC终端与会话连接的对应关系将 MTC终端与网络的连接断开。 再例如, MME可以根据所述对应关系发出指示给 PDN网关, 以控制 PDN网关 将 MTC终端与网络的连接断开。 当然, PDN网关也可以根据获取的所述对应 关系直接执行将对应的 MTC终端与网络的连接断开的操作。
采用本发明实施例的技术方案, 由于移动管理实体(MME ) 可以通过用 户设备集中器获取用户设备标识,从而可以根据获取的用户设备标识控制用户 设备接入网络, 解决了现有技术中对于通过 MTC网关接入网络的用户设备无 法区分控制的技术问题。 进而, MME还可以建立用户设备标识和会话连接的 对应关系,根据该对应关系识别接入的用户设备,控制接入的用户设备的业务, 执行针对用户设备的各种控制操作, 例如将特定的 MTC终端接入网络, 或者 将特定的 MTC终端与网络的连接断开, 以及对特定的 MTC终端进行计费等。
在一个实施例中, 作为用户设备集中器的 MTC网关可以为每个与其相连 的作为用户设备的 MTC终端建立一个独立的 PDN连接, 将获取到的 MTC终端 的第一标识携带在 PDN连接建立请求消息中发送给 MME。 MME则通过接收 MTC网关发送的 PDN连接建立请求消息, 获取 MTC终端的第一标识, 根据该 MTC终端的第一标识控制该 MTC终端接入网络。 进而, MME还可以建立 PDN 连接与 MTC终端的对应关系, 包括: 建立 PDN连接与获取的 MTC终端的第一 标识的对应关系, 建立 PDN连接与 MME从用于鉴权认证的设备获取的 MTC终 端的第二标识的对应关系。 MME将发送携带 MTC终端的第一或第二标识的建 立会话请求消息给 PDN网关, 从而 PDN网关也可以建立 PDN连接与 MTC终端 的第一或第二标识的对应关系, 并且, PDN网关还可以为 MTC终端分配临时 身份标识, 建立 PDN连接与临时身份标识的对应关系。 在 PDN连接与 MTC终 端的对应关系建立后, 即可根据该对应关系控制 MTC终端的各种业务。
在另一个实施例中, 作为用户设备集中器的 MTC 网关可以为每个与其相 连的作为用户设备的 MTC终端分配特定的端口号, 使得每个 MTC终端对应一 个或多个特定的业务数据流, 将 MTC终端的第一标识以及与 MTC网关为 MTC 终端分配的端口对应的业务数据流信息携带在承载资源修改请求消息发送给 MME。 MME则通过接收 MTC网关发送的承载资源修改请求消息, 获取 MTC 终端的第一标识。 根据该 MTC终端的第一标识控制该 MTC终端接入网络。 进 而, MME还可以建立业务数据流信息与 MTC终端的对应关系。 例如, 建立业 务数据流信息与 MTC终端的第一标识的对应关系; 或者建立业务数据流信息 与 MME从用于鉴权认证的设备获取的 MTC终端的第二标识的对应关系。 MME 将发送携带 MTC终端的第一或第二标识的承载资源命令消息给 PDN网关, 从 而 PDN网关也可以建立业务数据流信息与 MTC终端的第一或第二标识的对应 关系, 并且 PDN网关还可以为 MTC终端分配临时身份标识, 建立业务数据流 信息与临时身份标识的对应关系。进一步的, PDN网关还可以将业务数据流绑 定在特定承载上; 建立承载 ID ( IDentity )与 MTC终端的第一标识或第二标识 或临时身份标识的对应关系。上述对应关系建立后, 即可根据该对应关系控制 MTC终端的各种业务。
下面,以 SAE通信系统为例结合具体的应用场景例对本发明实施例提供的 方法做进一步说明。
SAE通信系统包括 MME以及通过服务网关与 MME连接的 PDN网关, 还可 以包括用于鉴权认证的设备, 例如归属用户服务器( Home Subscriber Server, HSS ), 或者认证授权和计费服务器 ( Authentication Authorization Accounting , AAA ), 或者设备标识寄存器(Equipment Identity Register, EIR ), 等。
请参考图 5所示的应用场景例, 作为用户设备集中器的 MTC网关作为 UE 附着在运营商网络, 当 MTC网关检测到相连的一个作为用户设备的 MTC终端 启动后, 执行本发明实施例方法, 以便为该 MTC终端建立独立的 PDN连接, 并控制该 MTC终端接入网络。 步骤如下:
501、 MTC网关向 MME发送携带 MTC终端的标识的 PDN连接建立请求消 息。 所说的 MTC终端的标识可以是 MTC终端的国际移动用户识别码 ( International Mobile Subscriber Identification Number, IMSI )或者移动设备标 识 ( Mobile station Equipment Identity, ME identity )或者也可以是携带在该消 息的协议配置项 (Protocol Configuration Options, PCO ) 中的用户名和密码等 信息。
502、 MME可以根据收到的 MTC终端的标识, 对 MTC终端进行网络认证。 例如, 如果收到的 MTC终端的标识是 IMSI, MME可以将 IMSI发到 HSS进行认 证, 以确定该 IMSI是否被允许接入网络; 也可以执行认证和密钥协商 ( Authentication and Key Agreement, AKA ) ;巟程进行接入认证。 :¾口果 4丈 J的 MTC终端的标识是 ME identity , MME可以将收到的 ME identity发给 EIR进行检 查, 以确定该 ME identity是否被允许接入网络。 如果认证成功, 则执行后续步 骤, 认证失败则返回建立 PDN连接失败消息给 MTC网关。 需要说明的是, 本 步骤并非必要步骤。
503、 MME建立 PDN连接和 MTC终端标识的对应关系, MTC终端的标识 可以是 IMSI或者 ME identity。 如果执行了步骤 502 , 且该步骤中 MME从 HSS获 得了 MTC终端的移动用户 国际号码 ( Mobile Subscriber International ISDN/PSTN number , MSISDN ) , 对应关系中的终端的标识也可以是 MSISDN。
MME将 MTC终端的标识携带在建立会话请求消息中发送给 PDN网关。 其 中, 如果 MME在步骤 501中收到的是携带在 PCO中的用户名和密码等信息, 那 么, MME不解析 PCO, 直接将 PCO携带在建立会话请求消息中发送给 PDN 网 关。 在 SAE网络中, 该建立会话请求消息可经服务网关 (Serving GW ) 中转。
504、 PDN网关收到建立会话请求消息后, 建立 PDN连接和 MTC终端的标 识的对应关系, 这里的 MTC终端的标识可以是 IMSI , 或者 ME identity或者 MSISDN。 如果 PDN网关收到的是携带在 PCO中的用户名和密码, PDN网关还 可以将用户名和密码发送给外部的远程用户拨号认证系统 ( Remote Authentication Dial In User Service, RADIUS )服务器进行认证, 如果通过认证 则建立 PCO中所携带的 MTC终端信息即用户名和密码与 PDN连接的对应关系; 或者可以根据 PCO中所携带的 MTC终端信息为 MTC终端分配临时身份标识, 建立该临时身份标识与 PDN连接的对应关系。 然后, PDN网关返回建立会话回 应消息给 MME。
505、 MME收到 PDN网关返回的建立会话回应消息后, 返回 PDN连接建立 回应消息给 MTC网关, 允许建立该 PDN连接, 使 MTC终端可以通过 PDN连接 接入网络。 网络侧 MME和 PDN网关获取了 MTC终端的标识后, 可以建立该 MTC终端 与 PDN连接的对应关系, 根据该对应关系, 可以对 MTC终端进行区分设备的 控制, 例如发起断开 PDN连接的流程, 使对应的 MTC终端不再接入网络; 或 者, PDN网关根据该对应关系, 进行区分 MTC终端的计费, 例如可以根据数 据流 IP地址区分该数据流属于哪个 PDN连接, 进一步区分出数据流属于哪个 MTC终端, 从而进行区分 MTC终端的计费。 另外, 在以上流程中 MME或 PDN 网关还可以执行对 MTC终端的网络认证, 以保证只有合法的 MTC终端才可以 接入运营商网给。
请参考图 6所示的应用场景例, 作为用户设备集中器的 MTC网关作为 UE 附着在运营商网络, 当 MTC网关检测到相连的一个作为用户设备的 MTC终端 启动后, 执行本发明实施例方法, 并控制该 MTC终端接入网络。 步骤如下:
601、 MTC网关为该 MTC终端分配特定的端口号,使得该 MTC终端对应一 个或多个特定的业务数据流。 然后, MTC网关向 MME发送承载资源修改请求 消息, 该消息中携带业务数据流信息及对应的 MTC终端的标识。 所说的 MTC 终端的标识可以是 MTC终端的国际移动用户识别码( IMSI )或者 ME identity 或者也可以是携带在该消息的 PCO中的用户名和密码等信息。
602、 MME可以根据收到的 MTC终端的标识, 对 MTC终端进行网络认证。 例如, 如果收到的 MTC终端的标识是 IMSI, MME可以将 IMSI发到 HSS进行认 证, 以确定该 IMSI是否被允许接入网络; 也可以执行 AKA流程进行接入认证。 如果收到的 MTC终端的标识是 ME identity, MME可以将收到的 ME identity发 给 EIR进行检查, 以确定该 ME identity是否被允许接入网络。 如果认证成功, 则执行后续步骤, 认证失败则返回承载资源修改拒绝消息给 MTC网关。 需要 说明的是, 本步骤并非必要步骤。
603、 MME建立业务数据流信息和 MTC终端的标识的对应关系, MTC终 端的标识可以是 IMSI或者 ME identity。 如果执行了步骤 602, 且该步骤中 MME 从 HSS获得了 MTC终端的移动用户国际号码(MSISDN ), 对应关系中的终端 的标识也可以是 MSISDN。
MME将业务数据流信息和对应的 MTC终端的标识携带在承载资源命令消 息中发送给 PDN网关。 其中, 如果 MME在步骤 6中收到的是携带在 PCO中的用 户名和密码等信息, 那么, MME不解析 PCO, 直接将 PCO携带在承载资源命 令消息中发送给 PDN 网关。 在 SAE网络中, 该承载资源命令消息可经服务网 关( Serving GW ) 中转。
604、 PDN网关收到承载资源命令消息后, 建立业务数据流信息和 MTC终 端的标识的对应关系, 这里的 MTC终端的标识可以是 IMSI, 或者 ME identity 或者 MSISDN。 如果 PDN网关收到的是携带在 PCO中的用户名和密码, PDN网 关还可以将用户名和密码发送给外部 Radius服务器进行认证, 如果通过认证则 建立 PCO中所携带的 MTC终端信息即用户名和密码与业务数据流信息的对应 关系; 或者可以根据 PCO中所携带的 MTC终端信息为 MTC终端分配临时身份 标识, 建立该临时身份标识与 PDN连接的对应关系。 然后, PDN网关根据收到 的业务数据流信息发起承载建立或修改流程, 以便将 MTC终端接入网络。
另外, PDN网关还可以更改对应关系中的会话连接信息, 例如, 可以根据 收到的业务数据流信息和 MTC终端的标识的对应关系, 将一个 MTC终端对应 的业务数据流绑定到一个特定承载上, 建立承载 ID与 MTC终端的标识的对应 关系, 或者建立承载 ID与为 MTC终端分配的临时身份标识的对应关系, 并将 该对应关系携带在承载建立或修改消息中发送给 MME。 在 LTE网络中, 该承 载建立或修改消息可经服务网关( Serving GW ) 中转。
网络侧的 MME和 PDN网关获取了 MTC终端与 MTC网关的标识后, 可以建 立为 MTC终端分配的端口对应的业务数据流信息 (或承载 ID ) 与 MTC终端的 对应关系,根据该对应关系, 可以对 MTC终端进行区分设备的控制, 例如 PDN 网关可以根据收到的 MME发送的请求删除特定业务数据流(或特定承载) 的 消息或者根据自身保存的所述对应关系,修改现有承载或者删除现有承载以删 除特定业务数据流, 使相应的 MTC终端不再被允许接入网络。 PDN网关还可 以根据该对应关系, 进行区分 MTC终端的计费, 例如可以根据业务数量流信 息区分该数据流属于哪个 MTC终端, 从而进行区分 MTC终端的计费。 另外, 在以上流程中 MME或 PDN还可以执行对 MTC终端的网络认证, 以保证只有合 法的 MTC终端才可以接入运营商网络。
当然, 本发明实施例方法并不局限于用在 SAE通信系统中, 也可以用在其 它通信系统例如通用移动通信系统 ( Universal Mobile Telecommunications System, UMTS )中。在 UMTS中, 网络侧设备包括相当于 LTE通信系统中 ΜΜΕ 的 SGSN和相当于 PDN网关的 GGSN,还可以包括相当于 HSS的归属位置寄存器 ( Home Location Register, HLR ), 等。 此处不再一一歹 'J举。
请参考图 7, 本发明实施例还提供一种移动管理实体 MME, 包括: 接收模块 701 , 用于接收用户设备集中器发送的会话连接请求消息, 所述 会话连接请求消息用于请求为一个与用户设备集中器连接的用户设备建立会 话连接;
获取模块 702, 用于获取所述会话连接请求消息携带的用户设备标识; 接入控制模块 703, 用于根据用户设备标识控制用户设备接入网络。
在一个实施例中, 接入控制模块 703可以包括:
认证单元, 用于根据所述用户设备标识对所述用户设备进行认证; 接入控制单元, 用于若认证通过, 将用户设备接入网络。
另一个实施例中, 接入控制模块 703可以包括:
建立单元, 用于建立所述用户设备标识与所述会话连接的对应关系; 业务控制单元, 用于根据所述对应关系区分控制不同用户设备的业务。 又一个实施例中:
所述接收模块 701 , 具体用于接收用户设备集中器发送的 PDN连接建立请 求消息;
所述获取模块 702, 具体用于获取所述 PDN连接建立请求消息携带的用户 设备的第一标识。
其中, 建立单元, 可以具体用于建立所述 PDN连接与所述用户设备的对应 关系。
再一个实施例中:
所述接收模块 701 , 具体用于接收用户设备集中器发送的承载资源修改请 求消息;
所述获取模块 702, 具体用于获取所述承载资源修改请求消息携带用户设 备的第一标识以及与所述 MTC网关为所述用户设备分配的端口对应的业务数 据流信息。
其中, 建立单元, 可以具体用于建立所述业务数据流信息与所述用户设备 的对应关系。
本发明实施例提供的 MME, 可以通过用户设备集中器获取用户设备标识, 从而可以根据获取的用户设备标识控制用户设备接入网络,解决了现有技术中 对于通过 MTC网关接入网络的用户设备无法区分控制的技术问题。进而, MME 还可以建立用户设备标识和会话连接的对应关系,根据该对应关系识别接入的 用户设备, 控制接入的用户设备的业务, 执行针对用户设备的各种控制操作, 例如将特定的 MTC终端接入网络,或者将特定的 MTC终端与网络的连接断开, 以及对特定的 MTC终端进行计费等。
请参考图 8, 本发明实施例还提供一种用户设备集中器, 包括:
获取模块 801 , 用于获取用户设备标识;
发送模块 802, 用于发送会话连接请求消息给移动管理实体 MME, 所述会 话连接请求消息携带所述用户设备标识。
在一个实施例中:
获取模块 801 , 具体用于获取用户设备的第一标识;
发送模块 802, 具体用于发送 PDN连接建立请求消息给所述 MME, 所述
PDN连接建立请求消息携带所述用户设备的第一标识。
在另一个实施例中:
获取模块 801 , 具体用于获取用户设备的第一标识以及所述用户设备集中 器为所述用户设备分配的端口对应的业务数据流信息;
发送模块 802, 具体用于发送承载资源修改请求消息给所述 MME, 所述承 载资源修改请求消息携带用户设备的第一标识以及与所述用户设备集中器为 所述用户设备分配的端口对应的业务数据流信息。
本发明实施例提供的用户设备集中器,可以将用户设备的标识携带在会话 连接请求消息中发送给 MME, 使 MME可以根据获取的用户设备标识控制用户 设备接入网络, 解决了现有技术中对于通过 MTC网关接入网络的用户设备无 法区分控制的技术问题。
请参考图 9, 本发明实施例还提供一种通信系统, 包括:
用户设备集中器 800 ,以及分别与用户设备集中器相连的用户设备 900和移 动管理实体 MME 700; 所述用户设备 900 , 用于发送用户设备标识给所述用户设备集中器; 所述用户设备集中器 800, 用于获取用户设备标识, 发送会话连接请求消 息给 MME700, 所述会话连接请求消息携带所述用户设备标识, 用于请求为所 述用户设备建立会话连接;
所述 MME 700, 用于接收用户设备集中器 800发送的会话连接请求消息, 获取所述会话连接请求消息携带的用户设备标识,根据所述用户设备标识控制 所述用户设备接入网络。
本发明实施例提供的通信系统, 移动管理实体(MME )可以通过用户设 备集中器获取用户设备标识,从而可以根据获取的用户设备标识控制用户设备 接入网络, 解决了现有技术中对于通过 MTC网关接入网络的用户设备无法区 分控制的技术问题。 进而, MME还可以建立用户设备标识和会话连接的对应 关系, 根据该对应关系识别接入的用户设备, 控制接入的用户设备的业务, 执 行针对用户设备的各种控制操作, 例如将特定的 MTC终端接入网络, 或者将 特定的 MTC终端与网络的连接断开, 以及对特定的 MTC终端进行计费等。
本发明实施例不限于应用在 MTC领域, 对于普通用户设备通过设备集中 器接入网络的场景同样适用于本发明提供的方法。也就是可以使用用户设备替 代 MTC终端, 使用用户设备集中器代替 MTC集中器。
本领域的技术人员可以理解上述实施例的各种方法中的全部或部分步骤 是可以通过程序来指令相关的硬件来完成,该程序可以存储于一计算机可读存 储介质中,存储介质可以包括: 只读存储器、 随机存取存储器、磁盘或光盘等。
以上对本发明实施例提供的控制用户设备接入网络的方法以及相应的装 置及通信系统进行了详细介绍,本文中应用了具体个例对本发明的原理及实施 方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心 思想, 不应理解为对本发明的限制。

Claims

权 利 要 求
1、 一种控制用户设备接入网络的方法, 包括:
所述移动管理实体接收用户设备集中器发送的会话连接请求消息,所述会 话连接请求消息用于请求为一个与用户设备集中器连接的用户设备建立会话 连接 ^
获取所述会话连接请求消息携带的用户设备标识;
根据所述用户设备标识控制所述用户设备接入网络。
2、根据权利要求 1所述的方法, 其特征在于, 所述根据所述用户设备标识 控制所述用户设备接入网络包括:
根据所述用户设备标识对所述用户设备进行认证;
若认证通过, 将所述用户设备接入网络。
3、 根据权利要求 2所述的方法, 其特征在于, 还包括:
建立所述用户设备标识与所述会话连接的对应关系;
根据所述对应关系区分控制不同用户设备的业务。
4、 根据权利要求 1至 3中任一所述的方法, 其特征在于, 所述接收用户设 备集中器发送的会话连接请求消息,获取所述会话连接请求消息携带的用户设 备标识包括:
接收用户设备集中器发送的分组数据网 PDN连接建立请求消息; 获取所述 PDN连接建立请求消息携带的用户设备的第一标识。
5、根据权利要求 4所述的方法, 其特征在于, 所述获取所述 PDN连接建立 请求消息携带的用户设备的第一标识之后还包括:
建立所述 PDN连接与所述用户设备的对应关系。
6、根据权利要求 5所述的方法, 其特征在于, 所述建立所述 PDN连接与所 述用户设备的对应关系包括:
建立所述 PDN连接与所述用户设备的第一标识的对应关系; 或者, 从用于鉴权认证的设备获取所述用户设备的第二标识,建立所述 PDN连接 与所述用户设备的第二标识的对应关系。
7、根据权利要求 6所述的方法, 其特征在于, 所述建立所述 PDN连接与所 述用户设备的对应关系还包括: 发送携带所用户设备的第一标识或第二标识的建立会话请求消息给 PDN 网关,以便所述 PDN网关建立所述 PDN连接与所述用户设备的第一标识或第二 标识或所述 PDN网关为所述用户设备分配的临时身份标识的对应关系。
8、 根据权利要求 1至 3中任一所述的方法, 其特征在于, 所述接收用户设 备集中器发送的会话连接请求消息,获取所述会话连接请求消息携带的用户设 备标识包括:
接收用户设备集中器发送的承载资源修改请求消息;
获取所述承载资源修改请求消息携带的用户设备的第一标识以及与所述 用户设备集中器为所述用户设备分配的端口对应的业务数据流信息。
9、根据权利要求 8所述的方法, 其特征在于, 所述获取所述承载资源修改 请求消息携带的用户设备的第一标识以及与所述用户设备集中器为所述用户 设备分配的端口对应的业务数据流信息之后还包括:
建立所述业务数据流信息与所述用户设备的对应关系。
10、 根据权利要求 9所述的方法, 其特征在于, 所述建立所述业务数据流 信息与所述用户设备的对应关系包括:
建立所述业务数据流信息与所述用户设备的第一标识的对应关系; 或者, 从用于鉴权认证的设备获取所述用户设备的第二标识,建立所述业务数据 流信息与所述用户设备的第二标识的对应关系。
11、 根据权利要求 10所述的方法, 其特征在于, 所述建立所述业务数据流 信息与所述用户设备的对应关系还包括:
发送携带所述用户设备的第一标识或第二标识的承载资源命令消息给 PDN网关,以便所述 PDN网关建立所述用户设备的第一标识或第二标识或所述 PDN网关为所述用户设备分配的临时身份标识与所述业务数据流信息或者所 述业务数据流信息对应的承载 ID的对应关系。
12、 一种移动管理实体 MME, 其特征在于, 包括:
接收模块, 用于接收用户设备集中器发送的会话连接请求消息, 所述会话 连接请求消息用于请求为一个与用户设备集中器连接的用户设备建立会话连 接;
获取模块, 用于获取所述会话连接请求消息携带的用户设备标识; 接入控制模块, 用于根据所述用户设备标识控制所述用户设备接入网络。
13、 根据权利要求 12所述的移动管理实体 MME, 其特征在于, 所述接入 控制模块包括:
认证单元, 用于根据所述用户设备标识对所述用户设备进行认证; 接入控制单元, 用于若认证通过, 将所述用户设备接入网络。
14、 根据权利要求 12所述的移动管理实体 MME, 其特征在于, 所述接入 控制模块包括:
建立单元, 用于建立所述用户设备标识与所述会话连接的对应关系; 业务控制单元, 用于根据所述对应关系区分控制不同用户设备的业务。
15、根据权利要求 12至 14中任一所述的移动管理实体 MME, 其特征在于: 所述接收模块,具体用于接收用户设备集中器发送的 PDN连接建立请求消 息;
所述获取模块,具体用于获取所述 PDN连接建立请求消息携带的用户设备 的第一标识。
16、 根据权利要求 15所述的移动管理实体 MME, 其特征在于, 所述接入 控制模块还包括:
建立单元, 用于建立所述 PDN连接与所述用户设备的对应关系。
17、根据权利要求 12至 14中任一所述的移动管理实体 MME, 其特征在于: 所述接收模块,具体用于接收用户设备集中器发送的承载资源修改请求消 息;
所述获取模块,具体用于获取所述承载资源修改请求消息携带用户设备的 第一标识以及与所述用户设备集中器为所述用户设备分配的端口对应的业务 数据流信息。
18、 根据权利要求 17所述的移动管理实体 MME, 其特征在于, 所述接入 控制模块包括:
建立单元, 用于建立所述业务数据流信息与所述用户设备的对应关系。
19、 一种用户设备集中器, 其特征在于, 包括:
获取模块, 用于获取用户设备标识;
发送模块, 用于发送会话连接请求消息给移动管理实体 MME, 所述会话 连接请求消息携带所述用户设备标识。
20、 根据权利要求 19所述的用户设备集中器, 其特征在于:
所述获取模块, 具体用于获取用户设备的第一标识;
所述发送模块, 具体用于发送 PDN连接建立请求消息给所述 MME, 所述 PDN连接建立请求消息携带所述用户设备的第一标识。
21、 根据权利要求 19所述的用户设备集中器, 其特征在于, 包括: 所述获取模块,具体用于获取用户设备的第一标识以及所述用户设备集中 器为所述用户设备分配的端口对应的业务数据流信息;
所述发送模块, 具体用于发送承载资源修改请求消息给所述 MME, 所述 承载资源修改请求消息携带所述用户设备的第一标识以及与所述用户设备集 中器为所述用户设备分配的端口对应的业务数据流信息。
22、 一种通信系统, 其特征在于, 包括:
用户设备集中器,以及分别与所述用户设备集中器相连的用户设备和移动 管理实体 MME;
所述用户设备, 用于发送用户设备标识给所述用户设备集中器; 所述用户设备集中器, 用于获取用户设备标识,发送会话连接请求消息给 移动管理实体 MME, 所述会话连接请求消息携带所述用户设备标识, 用于请 求为所述用户设备建立会话连接;
所述 MME, 用于接收用户设备集中器发送的会话连接请求消息, 获取所 述会话连接请求消息携带的用户设备标识,根据所述用户设备标识控制所述用 户设备接入网络。
PCT/CN2011/073768 2011-05-06 2011-05-06 控制用户设备接入网络的方法、装置及系统 WO2011120464A2 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201180000528.3A CN102870485B (zh) 2011-05-06 2011-05-06 控制用户设备接入网络的方法、装置及系统
PCT/CN2011/073768 WO2011120464A2 (zh) 2011-05-06 2011-05-06 控制用户设备接入网络的方法、装置及系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/073768 WO2011120464A2 (zh) 2011-05-06 2011-05-06 控制用户设备接入网络的方法、装置及系统

Publications (2)

Publication Number Publication Date
WO2011120464A2 true WO2011120464A2 (zh) 2011-10-06
WO2011120464A3 WO2011120464A3 (zh) 2012-04-12

Family

ID=44712675

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/073768 WO2011120464A2 (zh) 2011-05-06 2011-05-06 控制用户设备接入网络的方法、装置及系统

Country Status (2)

Country Link
CN (1) CN102870485B (zh)
WO (1) WO2011120464A2 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103621158A (zh) * 2012-06-26 2014-03-05 华为技术有限公司 网络接入方法、网络设备接入点装置以及移动性管理实体装置

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9763168B1 (en) * 2016-09-30 2017-09-12 T-Mobile Usa, Inc. Blocked device checking in roaming scenarios

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101521871A (zh) * 2008-02-26 2009-09-02 大唐移动通信设备有限公司 一种跟踪区更新的方法、装置和系统
CN101568097A (zh) * 2008-04-21 2009-10-28 大唐移动通信设备有限公司 一种用户终端的跟踪区更新方法、系统及装置
WO2010036011A2 (en) * 2008-09-25 2010-04-01 Samsung Electronics Co., Ltd. Access admission control method and system for mobile communcation systems

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101945485B (zh) * 2009-07-10 2014-09-10 中兴通讯股份有限公司 一种核心网进行接入控制判断的方法、装置及系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101521871A (zh) * 2008-02-26 2009-09-02 大唐移动通信设备有限公司 一种跟踪区更新的方法、装置和系统
CN101568097A (zh) * 2008-04-21 2009-10-28 大唐移动通信设备有限公司 一种用户终端的跟踪区更新方法、系统及装置
WO2010036011A2 (en) * 2008-09-25 2010-04-01 Samsung Electronics Co., Ltd. Access admission control method and system for mobile communcation systems

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103621158A (zh) * 2012-06-26 2014-03-05 华为技术有限公司 网络接入方法、网络设备接入点装置以及移动性管理实体装置
CN103621158B (zh) * 2012-06-26 2017-11-24 华为技术有限公司 网络接入方法、网络设备接入点装置以及移动性管理实体装置

Also Published As

Publication number Publication date
CN102870485B (zh) 2016-03-09
WO2011120464A3 (zh) 2012-04-12
CN102870485A (zh) 2013-01-09

Similar Documents

Publication Publication Date Title
KR101167781B1 (ko) 콘텍스트 전달을 인증하는 시스템 및 방법
US9473877B2 (en) Uplink/downlink transmission method for small amount of data, and corresponding terminal and mobility management unit
US20100048161A1 (en) Method, system and apparatuses thereof for realizing emergency communication service
US20130139221A1 (en) Web Authentication Support for Proxy Mobile IP
CN106031105B (zh) 针对epc的受信任wlan访问的过载控制
WO2013040978A1 (zh) 数据分流触发方法、网络侧设备和用户设备及网络系统
WO2013082984A1 (zh) 一种附着到e-utran的方法及移动性管理实体
JP5886438B2 (ja) Eapを用いて外部認証を行う装置、システム及び方法
WO2011116713A2 (zh) Mtc终端通过网关与网络通信的方法、设备及系统
US20150074761A1 (en) Method, device and communications system for network convergence
WO2013016968A1 (zh) 一种接入方法、系统及移动智能接入点
WO2011060709A1 (zh) 校验国际移动用户识别码与国际移动设备身份码绑定关系的方法和装置
WO2009152676A1 (zh) Aaa服务器、p-gw、pcrf、用户设备标识的获取方法和系统
WO2014005267A1 (zh) 接入移动网络的方法、装置及系统
WO2013131461A1 (zh) 一种用户设备接入融合控制网元的实现方法及装置
WO2011157189A2 (zh) 位置上报方法、设备和系统
WO2012126302A1 (zh) 一种支持双模双待终端同时通信的方法和系统
CN107277790B (zh) 一种为终端提供紧急号码的方法和装置
WO2014075534A1 (zh) 通信路径的切换方法及装置、切换处理装置及系统
WO2008095433A1 (fr) Procédé, dispositif et système assurant un service d'urgence
WO2017107739A1 (zh) 数据业务处理方法及装置
WO2011134102A1 (zh) 关联会话的方法、装置及系统
WO2010091589A1 (zh) 一种安全认证方法
WO2014047923A1 (zh) 接入网络的方法和装置
EP3574623B1 (en) Methods and devices for parameter exchange during emergency access

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201180000528.3

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11762038

Country of ref document: EP

Kind code of ref document: A2

NENP Non-entry into the national phase in:

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11762038

Country of ref document: EP

Kind code of ref document: A2