WO2011127774A1 - 一种用户终端接入互联网方式的控制方法及装置 - Google Patents

一种用户终端接入互联网方式的控制方法及装置 Download PDF

Info

Publication number
WO2011127774A1
WO2011127774A1 PCT/CN2011/071584 CN2011071584W WO2011127774A1 WO 2011127774 A1 WO2011127774 A1 WO 2011127774A1 CN 2011071584 W CN2011071584 W CN 2011071584W WO 2011127774 A1 WO2011127774 A1 WO 2011127774A1
Authority
WO
WIPO (PCT)
Prior art keywords
internet
authentication
user equipment
indication information
access
Prior art date
Application number
PCT/CN2011/071584
Other languages
English (en)
French (fr)
Inventor
周星月
朱春晖
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2011127774A1 publication Critical patent/WO2011127774A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method and an apparatus for controlling a UE to access an internet through a wireless local area network. Background technique
  • WLAN AN Wireless Local Area Network Access Network
  • an evolved packet core network an interactive wireless local area network
  • a microwave access global interworking network an interactive wireless local area network
  • a code Multiple access to the network, etc.
  • I-WLAN Interworking Wireless Local Area Network
  • 3GPP Third Generation Partnership Project
  • the purpose of the interaction is to enable the WLAN access technology to cooperate with the General Packet Radio Service (GPRS) core network infrastructure so that the WLAN user equipment can access the GPRS packet service through the WLAN access network.
  • GPRS General Packet Radio Service
  • the following includes: an I-WLAN core network, a user equipment (User Equipment, UE), a WLAN AN, and an IP service provided by an operator.
  • the I-WLAN core network further includes a Packet Data Gateway (PDG), a 3GPP AAA Server, and a Home Subscriber Server (HSS), where the HSS is used to store users.
  • PGW Packet Data Gateway
  • HSS Home Subscriber Server
  • EPC Evolved Packet Core network
  • the EPC includes: Evolved Packet Data Gateway (ePDG), Packet Data Network GateWay (P-GW), 3GPP AAA Server, HSS, where HSS is used to store user data and in the process of user access authentication Generate a vector for authentication.
  • ePDG Evolved Packet Data Gateway
  • P-GW Packet Data Network GateWay
  • HSS 3GPP AAA Server
  • the EPC can communicate with the non-3GPP network.
  • the P-GW is the border gateway between the EPC and the Packet Data Network (PDN). It is responsible for PDN access and is responsible for forwarding data between the EPC and the PDN.
  • PDN Packet Data Network
  • the WLAN AN can be directly connected to the P-GW; when the operator considers that the WLAN AN is untrustworthy, the WLAN AN needs to be connected to the ePDG. Therefore, the above method can ensure the security and confidentiality of data transmission between the UE and the ePDG.
  • the UE can access the EPC through other access networks, including the radio access network defined by the 3GPP itself.
  • FIG. 3 is an interaction flowchart of performing access authentication when a user equipment accesses a wireless local area access network according to the related art. As shown in FIG. 3, the method includes the following steps S302 to S303:
  • Step S301 The user equipment establishes a WLAN wireless connection.
  • Step S302 The WLAN AN sends an Extensible Authentication Protocol ( ⁇ ) request/identity message to the UE, requesting the UE to provide an identity to the network, and after receiving the ⁇ request/identity message, the UE will use the corresponding network access identifier (Network Access). Identification, NAI) is sent to the WLAN AN through an EAP reply message.
  • Extensible Authentication Protocol
  • NAI Network Access
  • Step S303 The user equipment and the authentication, authorization, and accounting (AAA) server perform an access authentication process such as algorithm key negotiation.
  • AAA authentication, authorization, and accounting
  • the UE can access the Internet (Intranet/Internet) through two paths.
  • One path is to access the Internet directly through the WLAN AN, and the other path is to access the Internet through the 3GPP core network.
  • the user equipment accesses the Internet through the core network by default. Since the operator cannot indicate whether the user equipment passes through the 3GPP core network when accessing the Internet through the wireless LAN, when the third-party application and Internet access requirements increase, the pressure on the core network of the operator increases and even the core network traffic is congested, and the user cannot be groomed. The traffic that the device accesses the Internet cannot meet the needs of users to use enough bandwidth to access the Internet. Summary of the invention
  • the main purpose of the present invention is to provide a method and a device for controlling a user terminal to access the Internet, and to solve the technical problem that the operator cannot control whether the user equipment passes through the 3GPP core network when accessing the Internet through the wireless local area network. .
  • a method for controlling a user terminal to access an Internet includes:
  • the authentication and authorization charging server sends the user equipment (UE) to the user equipment to access the Internet.
  • the user equipment determines the access mode for accessing the Internet service according to the indication information.
  • the authentication and authorization charging server sends the indication information of the user equipment accessing the Internet to the user equipment, which is specifically:
  • the authentication and authorization charging server includes the indication information that the user equipment accesses the Internet mode via the WLAN AN. Send to the UE.
  • the authentication and authorization charging server encapsulates the indication information of the UE accessing the Internet into the Diameter packet containing the EAP-Success message, and sends the EAP-Success message to the UE by the WLAN AN;
  • the indication information is located in a Diameter-Specific-Application-Id AVP field of the Diameter message.
  • the authentication and authorization charging server sends the indication information of the user equipment accessing the Internet to the user equipment, which is specifically:
  • the authentication authorization charging server When the user equipment initially connects to the EPC through the WLAN AN, in the process of creating an Internet Key Exchange Protocol (IKEv2) tunnel by the user equipment and the packet data gateway (PDG), the authentication authorization charging server indicates that the UE accesses the Internet mode. The information is sent to the UE via the PDG. Further, the authentication and authorization charging server includes the indication information of the UE accessing the Internet mode in the authorization response message and sends the indication information to the PDG; the PDG sends the Internet key exchange authentication that carries the indication information of the UE accessing the Internet mode through the IKEv2 tunnel. A response message is sent to the UE.
  • IKEv2 Internet Key Exchange Protocol
  • the authentication and authorization charging server sends the indication information of the user equipment accessing the Internet to the user equipment, which is specifically:
  • the authentication and authorization accounting server After the user equipment has been connected to the EPC network through the WLAN AN, in the re-authentication process, the authentication and authorization accounting server includes the indication information of the UE accessing the Internet in the re-authentication request message and sends the indication information to the UE.
  • the authentication and authorization charging server sends the indication information of the user equipment to access the Internet mode to the user equipment, which is specifically:
  • the authentication and authorization accounting server sends the indication information of the UE accessing the Internet to the UE via the P-GW.
  • the present invention further provides a control device for accessing an Internet by a user terminal, the device comprising:
  • the sending module is located at the authentication and authorization accounting server, and is configured to send, to the user equipment, indication information that the user equipment accesses the Internet mode;
  • the receiving module is located at the UE, and is configured to receive indication information that the user equipment that is sent by the sending module accesses the Internet manner;
  • the access module is located at the UE, and is configured to determine, according to the indication information, an access mode for accessing the Internet service.
  • the sending module includes the indication information of the UE accessing the Internet in the re-authentication request message and sends the indication information to the receiving module.
  • the device further includes a forwarding module, located in the WLAN AN, for transmitting, in an authentication process that the user equipment is initially connected to the EPC, forwarding an indication that the UE sent by the sending module to the receiving module accesses the Internet mode information.
  • the device further comprises a forwarding module:
  • the forwarding module is located in the PDG, and is configured to: in a process of the user equipment that is initially connected to the EPC by the user equipment and the PDG to create an IKEv2 tunnel, forward the indication information that the UE sent by the sending module to the receiving module accesses the Internet mode. .
  • IKEv2 tunnel forwards the indication information that the UE sent by the sending module to the receiving module accesses the Internet mode.
  • the forwarding module is located in the P-GW, and is used by the sending module to send the receiving module to the receiving module when the UE and the P-GW establish a security association and the authentication and authorization charging server and the P-GW perform authentication and authorization.
  • the authentication and authorization accounting server of the present invention sends an indication information to the user equipment to indicate that the user equipment accesses the Internet.
  • the user equipment can select to directly access the Internet or connect through the wireless local area network according to the indication information. Access the Internet to the core network.
  • the core network can control the access mode of the UE to access the Internet by using the indication information, so that the user terminal can directly access the Internet without accessing the core network when accessing through the wireless local area network, so that the user equipment is in some situations ( For example, when the core network traffic load is too large, sufficient access bandwidth is obtained to improve the user experience.
  • FIG. 1 is a schematic diagram of a network architecture of a related art non-3GPP network accessing an I-WLAN
  • FIG. 2 is a schematic diagram of a network architecture of a related art non-3GPP network access EPC
  • FIG. 3 is a related art user equipment accessing a wireless local area connection An interactive flow chart for performing access authentication when entering the network;
  • FIG. 4 is a flowchart of a method for controlling a UE to access an Internet through a wireless local area network according to Embodiment 1 of the present invention
  • FIG. 6 is a flowchart of a method for controlling a UE to access an Internet through a wireless local area network according to Embodiment 3 of the present invention
  • FIG. 7 is a flowchart of a method for controlling a UE to access an Internet through a wireless local area network according to Embodiment 4 of the present invention.
  • FIG. 8 is a schematic structural diagram of a control apparatus for accessing an Internet by a user terminal according to the present invention. detailed description
  • FIG. 4 is a flowchart of a method for controlling a UE to access an Internet through a wireless local area network according to Embodiment 1 of the present invention.
  • a user equipment is initially connected to an EPC network through a WLAN AN.
  • the authentication and authorization charging server is configured according to The policy sends the indication information directly connected to the Internet to the UE via the WLAN AN to achieve the purpose of controlling the manner in which the UE accesses the Internet through the wireless local area network.
  • the indication information sent by the authentication and authorization accounting server to the UE is required to request the UE to access the Internet through the WLAN AN without going through the core network when accessing the Internet service.
  • the UE uses the corresponding routing method. Policy access to Internet services.
  • the specific steps of the process are:
  • Step 401 The user equipment establishes a WLAN wireless connection.
  • Step 402 The WLAN AN establishes a wireless connection with the UE, and the WLAN AN sends an EAP Request/Identity message to the UE, requesting the UE to provide identity information to the network for access authentication.
  • Step 403 After receiving the EAP request message, the UE sends the UE identity information to the WLAN AN through the EAP reply message.
  • Step 404 The WLAN AN sends an AAA carrying the UE identity information to the AAA server. And requesting a message (Diameter message), where the AAA request message further carries an access type and an access network identifier;
  • Step 405 The AAA server and the HSS exchange EAP-AKA, algorithm authentication information, and perform user algorithm authentication;
  • Step 406 The AAA server extracts key information.
  • Step 407 The AAA server sends an AAA/AKA' challenge message to the WLAN AN, and performs algorithm negotiation, AAA/AKA, and the challenge message carries the EAP request and the challenge information including the message authentication code.
  • Step 408 The WLAN AN sends an EAP Request/AKA' Challenge message containing the message authentication code to the user equipment.
  • Step 409 The user equipment receives the EAP request /AKA, and runs the AKA algorithm to generate key related information after the challenge message;
  • Step 410 The user equipment encapsulates the AKA calculation result into the EAP and sends an EAP response/AKA' 4 war message to the WLAN.
  • Step 411 The WLAN AN encapsulates the received EAP response message including the algorithm negotiation information into the Diameter message and forwards the message to the AAA server.
  • Step 412 The AAA server checks the received message authentication code information, and performs algorithm information verification and the like;
  • Step 413 The AAA server determines, according to the policy, the Internet connection mode of the UE is an access mode that does not directly access the Internet through the EPC core network, and encapsulates the indication information including the access mode into a successful EAP-Success message including the extended authentication protocol.
  • the Diameter message is sent to the WLAN AN.
  • the WLAN AN needs to know the decision of the core network about the UE accessing the Internet access mode (for example, for some security policy considerations), the extended field reserved by the Diameter message ( Vendor-Specific-Application-Id AVP, The device specifies the application identification attribute value pair field.
  • the AVP field is hereinafter referred to as carrying the indication information;
  • Step 414 The WLAN AN forwards the EAP Success message to the UE. If the indication information is included in the Vendor-Specific-Application-Id AVP field, the WLAN AN may parse the Diameter packet, and then forward the EAP message to the UE after extracting the indication of the Internet connection mode.
  • FIG. 5 is a flowchart of a method for controlling a UE to access an Internet through a wireless local area network according to Embodiment 2 of the present invention.
  • a user equipment has been connected to an EPC network through a WLAN AN, and in a case where re-authentication needs to be initiated, such as a core
  • the AAA server sends the indication information of the UE accessing the Internet to the UE in the re-authentication process in the re-authentication process.
  • Figure 5 takes the Fast Re-Authentication Procedure as an example.
  • the instruction information is carried in the re-authentication request (Re-Auth-Request) message sent by the AAA server: Step 501: The authentication and authorization charging server sends a re-authentication request (Re-Auth-Request) message to the user equipment, where In the message, the AVP field carries the indication information of the Internet access mode determined by the core network for the UE;
  • Step 502 The user equipment sends a Re-Auth-Response message to the authentication and authorization accounting server, where the message includes a fast re-authentication identity identifier.
  • Step 503 After the authentication and authorization accounting server receives the fast re-authentication identity identifier, the server recognizes and approves the fast re-authentication process;
  • Step 504 The user equipment and the authorized charging server perform a fast re-authentication process.
  • FIG. 6 is a flowchart of a method for controlling a UE to access an Internet through a wireless local area network according to Embodiment 3 of the present invention.
  • a user equipment is initially connected to an EPC network through a WLAN AN, and a user equipment and a packet data gateway (PDG) are created.
  • PDG packet data gateway
  • IKEv2 Internet Key Exchange Protocol
  • the AAA server passes the indication information of the Internet access mode of the UE in the authorization message.
  • Step 601 The UE and the PDG exchange the first pair of messages.
  • the IKE-SA-INIT negotiates an encryption algorithm, performs exchange of random numbers, and the like.
  • Step 602 The UE performs the interaction of the identity authentication information by using the PDG and the AAA server.
  • Step 603 The UE sends an Internet Key Exchange Authentication (IKE AUTH) request message including an EAP message to the PDG to the PDG, and responds to the authentication challenge received during the identity authentication interaction.
  • IKE AUTH Internet Key Exchange Authentication
  • Step 604 The PDG sends an EAP-Response response message (with AKA challenge information) to the AAA server.
  • Step 605 The AAA server sends an authentication response containing the EAP-Success and the key information to the PDG after the verification succeeds.
  • Step 606 The PDG sends an authorization request including the empty AVP and the WLAN Access Point Name (W-APN) information to the AAA server.
  • W-APN WLAN Access Point Name
  • Step 607 The AAA server verifies whether the user information allows the tunnel to be established.
  • the AAA server determines the manner in which the UE accesses the Internet according to the network policy (where the AAA server may control the change of the UE accessing the Internet according to its own policy control or the network gateway system notification), and the indication information including the UE accessing the Internet mode is authorized in the next step. Delivered in the response message.
  • Step 608 The AAA server sends an authorization response (AA-Ask) message to the PDG, where the indication information of the UE accessing the Internet mode is included.
  • AAA-Ask authorization response
  • Step 609 The PDG calculates and generates an authentication parameter (AUTH payload) information according to the key information.
  • AUTH payload an authentication parameter
  • Step 610 The PDG sends an Internet Key Exchange Authentication (IKE AUTH) response message to the UE through the IKEv2, and the IKE-AUTH response message includes an EAP Success/Failure message carrying the indication information of the UE accessing the Internet.
  • IKE AUTH Internet Key Exchange Authentication
  • FIG. 7 is a flowchart of a method for controlling a UE to access an Internet through a wireless local area network according to Embodiment 4 of the present invention.
  • the UE and the UE The P-GW establishes a security association, and the AAA server and the P-GW perform authentication and authorization.
  • the AAA server transmits the indication information of the UE accessing the Internet mode to the UE via the P-GW.
  • the UE accesses the network through DSMIPv6 (Dual Stack Mobile IPv6 Protocol). Specific steps are as follows:
  • Step 701 The UE initiates an IKEv2 tunnel process to perform security tunnel authentication and authorization.
  • the process of establishing an IPSec tunnel is similar to that of Embodiment 3, and is not described here.
  • Step 702 The evolved packet data gateway returns an IKEv2 configuration message carrying an IP address allocated to the UE for the IPSec tunnel to the UE.
  • Step 703 After the IPSec tunnel is successfully established between the UE and the evolved packet data gateway, the UE and the P-GW establish an SA in the IKEv2 protocol to ensure the security of the signaling message.
  • the P-GW and the AAA server authenticate through the EAP method.
  • Authorization in this process, the AAA server sends the indication information of the UE accessing the Internet to the UE via the P-GW, for example, by using an authorization response message, where the process is similar to the process of Embodiment 3, and details are not described herein again.
  • Step 704 The UE sends a binding update message to the P-GW, and transmits a mobility management protocol signaling message.
  • Step 705 The P-GW sends a binding update acknowledgement message to the UE, and completes the DSMIPv6 address binding.
  • the DSMIPv6 tunnel between the UE and the P-GW is completed, and thus, the UE completes the IP connection with the network.
  • FIG. 8 is a schematic structural diagram of a device for controlling a user terminal to access an Internet according to the present invention.
  • the device includes at least: a sending module, a receiving module, and an access module.
  • the sending module is located at the authentication and authorization accounting server, and is used to deliver the user equipment to the user equipment.
  • the accessing module is located at the UE, and is configured to receive the indication information that the user equipment that is sent by the sending module is connected to the Internet, and the access module is configured to determine, according to the indication information, the access to the Internet service. Access method.
  • the sending module includes the indication information of the UE accessing the Internet in the re-authentication request message and sends the indication information to the receiving module.
  • the device further includes a forwarding module, and the forwarding module is located in different network elements according to different implementation manners.
  • the forwarding module may be located in the WLAN AN, and used in the authentication process that the user equipment is initially connected to the EPC, and forwards the indication information that the UE sent by the sending module to the receiving module accesses the Internet mode. .
  • the forwarding module may be located in the PDG, and used in the process of the user equipment that is initially connected to the EPC by the user equipment and the PDG to create an IKEv2 tunnel, and forwards the UE that is sent by the sending module to the receiving module. Instructions for entering the Internet mode.
  • the forwarding module may be located in the P-GW, and is used in the process of establishing a security association and the authentication and authorization accounting server and the P-GW for authenticating and authorizing the UE and the P-GW, and the forwarding is delivered by the sending module.
  • the UE of the receiving module accesses the indication information of the Internet mode.
  • the present invention provides an access method for the problem that the operator cannot control whether the user equipment passes through the 3GPP core network of the operator when accessing the Internet through the wireless local area network, and the authentication and authorization charging server sends the core network to the user equipment.
  • the indication information of the access mode determined by the user equipment to access the Internet so as to achieve the purpose of controlling the access mode of the UE to access the Internet according to a certain control policy by the core network, so that the user can directly access the Internet, thereby obtaining sufficient Access bandwidth and improve the user experience.

Description

一种用户终端接入互联网方式的控制方法及装置 技术领域
本发明涉及通信技术领域,尤其涉及一种 UE通过无线局域网接入互联 网方式的控制方法及装置。 背景技术
通常, 用户设备需要通过无线局域网接入网络( Wireless Local Area Network Access Network, WLAN AN )接入到以下无线核心网: 演进的分 组核心网、 交互的无线局域网络、 微波存取全球互通网络、 码分多址接入 网络等。
图 1 是根据相关技术的非 3GPP 网络接入交互的无线局域网络 ( Interworking Wireless Local Area Network, I-WLAN )的网络架构示意图, 其中, I-WLAN是指一个与第三代合作伙伴计划( 3rd Generation Partnership Project, 3GPP ) 网络交互的 WLAN网络。 交互目的是使 WLAN接入技术 能够与通用分组无线业务( General Packet Radio Service, GPRS )核心网基 础设施合作,以便 WLAN的用户设备能够通过 WLAN接入网络接入 GPRS 分组服务。如图 1所示,包括: I-WLAN核心网、用户设备(User Equipment, UE )、 WLAN AN、 以及运营商提供的 IP业务。 其中, I -WLAN核心网进 一步包括分组数据网关( Packet Data Gateway, PDG )、 3GPP认证授权计费 服务器(3GPP AAA Server ), 归属用户服务器(Home Subscriber Server, HSS ), 其中, HSS用于存储用户数据以及在用户接入认证过程中生成认证 用的向量。
图 2 是根据相关技术的非 3GPP 网络接入演进分组核心网 (Evolved Packet Core network, EPC ) 的网络架构示意图, 如图 2所示, EPC包括: 演进分组数据网关 ( Evolved Packet Data Gateway, ePDG )、 分组数据网络 网关( Packet Data Network GateWay, P-GW )、 3GPP AAA Server, HSS, 其 中, HSS用于存储用户数据以及在用户接入认证过程中生成认证用的向量。
图 2中, EPC可以与非 3GPP网络互通, P-GW是 EPC与分组数据网 ( Packet Data Network , PDN ) 的边界网关, 负责 PDN的接入, 并负责在 EPC与 PDN间转发数据等功能。 当运营商认为 WLAN网络为可信任时, WLAN AN可以直接与 P-GW相连; 当运营商认为 WLAN AN不可信任时, WLAN AN需要与 ePDG相连。 因此, 上述方法可以确保 UE与 ePDG之间 数据传输的安全性及保密性。 此外 UE还可以通过其他接入网络接入 EPC, 包括 3GPP自身定义的无线接入网络。
图 3是根据相关技术的用户设备接入无线局域接入网时执行接入认证 的交互流程图, 如图 3所示, 包括如下的步骤 S302至步骤 S303:
步骤 S301 , 用户设备建立 WLAN无线连接。
步骤 S302 , WLAN AN 向 UE 发送扩展认证协议 ( Extensible Authentication Protocol , ΕΑΡ )请求 /身份消息, 请求 UE提供身份给网络, UE在接收到 ΕΑΡ请求 /身份消息之后, 将相应的网络访问标识(Network Access Identification, NAI )通过 EAP回复消息发送给 WLAN AN。
步骤 S303 ,用户设备和认证授权计费( Authentication、 Authorization and Accounting, AAA )服务器之间进行算法密钥协商等接入认证流程。
如图 1 或图 2 所示的系统, UE 可通过两条路径访问互联网 ( Intranet/Internet ) , 一条路径是直接通过 WLAN AN访问互联网, 另一条 路径是通过 3GPP核心网访问互联网,现有技术中,用户设备默认通过核心 网访问互联网。 由于运营商无法指示用户设备通过无线局域网访问互联网 时是否通过运营商 3GPP核心网, 所以当第三方应用和互联网访问需求增 加, 导致运营商核心网络压力增大甚至核心网流量拥塞时, 无法疏导用户 设备访问 Internet的流量, 不能满足用户使用足够的带宽访问互联网络的需 求。 发明内容
有鉴于此, 本发明的主要目的在于提供一种用户终端接入互联网方式 的控制方法及装置, 用于解决运营商无法控制用户设备通过无线局域网访 问互联网时是否通过运营商 3GPP核心网的技术问题。
为了实现上述目的, 根据本发明的一个方面, 提供了一种用户终端接 入互联网方式的控制方法, 该方法包括:
认证授权计费服务器向用户设备 ( UE ) 下发用户设备接入互联网方式 的指示信息, 所述用户设备根据所述指示信息决定访问互联网业务的接入 方式。
优选地, 所述认证授权计费服务器向用户设备下发用户设备接入互联 网方式的指示信息, 具体为:
在用户设备通过无线局域网接入网络( WLAN AN )初始连接到演进分 组核心网(EPC )的认证流程中, 所述认证授权计费服务器将包含用户设备 接入互联网方式的指示信息经由 WLAN AN下发给 UE。
进一步地,所述认证授权计费服务器将 UE接入互联网方式的指示信息 封装到包含 EAP-Success 消息的 Diameter报文中发送给 WLAN AN, 由 WLAN AN将所述 EAP-Success消息转发给 UE;所述指示信息位于 Diameter 报文 Vendor-Specific-Application-Id AVP字段中。
优选地, 所述认证授权计费服务器向用户设备下发用户设备接入互联 网方式的指示信息, 具体为:
用户设备通过 WLAN AN初始连接到 EPC时, 在用户设备和分组数据 网关( PDG )创建因特网密钥交换协议( IKEv2 )隧道的流程中, 所述认证 授权计费服务器将 UE接入互联网方式的指示信息经由 PDG下发给 UE。 进一步地,所述认证授权计费服务器将 UE接入互联网方式的指示信息 包含在授权响应消息中下发给 PDG; PDG通过 IKEv2隧道发送携带 UE接 入互联网方式的指示信息的因特网密钥交换认证响应消息给所述 UE。
优选地, 所述认证授权计费服务器向用户设备下发用户设备接入互联 网方式的指示信息, 具体为:
在用户设备已经通过 WLAN AN连接到 EPC网络后 ,在重认证流程中 , 所述认证授权计费服务器将 UE接入互联网方式的指示信息包含在重认证 请求消息中下发给 UE。
进一步地, 所述认证授权计费服务器向用户设备下发用户设备接入互 联网方式的指示信息, 具体为:
用户设备和演进分组数据网关( ePDG )完成 IPSec隧道建立后, 在 UE 和分组数据网络网关(P-GW )建立安全联盟及所述认证授权计费服务器和 P-GW进行认证授权的过程中,所述认证授权计费服务器将 UE接入互联网 方式的指示信息经由 P-GW下发给 UE。
基于本发明所述方法, 本发明还提出一种用户终端接入互联网方式的 控制装置, 该装置包括:
发送模块, 位于认证授权计费服务器, 用于向用户设备下发用户设备 接入互联网方式的指示信息;
接收模块, 位于 UE, 用于接收所述发送模块下发的用户设备接入互联 网方式的指示信息;
接入模块, 位于 UE, 用于根据所述指示信息决定访问互联网业务的接 入方式。
优选地, 在用户设备已经通过 WLAN AN连接到 EPC网络后的重认证 流程中,所述发送模块将 UE接入互联网方式的指示信息包含在重认证请求 消息中下发给所述接收模块。 优选地, 所述装置还包括转发模块,位于 WLAN AN, 用于在用户设备 初始连接到 EPC的认证流程中, 转发由所述发送模块下发给所述接收模块 的 UE接入互联网方式的指示信息。
优选地, 所述装置还包括转发模块:
所述转发模块位于 PDG, 用于在用户设备初始连接到 EPC的用户设备 和 PDG创建 IKEv2隧道的流程中,转发由所述发送模块下发给所述接收模 块的 UE接入互联网方式的指示信息。 或,
所述转发模块位于 P-GW,用于在 UE和 P-GW建立安全联盟及认证授 权计费服务器和 P-GW进行认证授权的过程中, 转发由所述发送模块下发 给所述接收模块的 UE接入互联网方式的指示信息。
本发明釆用认证授权计费服务器向用户设备发送一种指示信息, 用来 指示用户设备接入互联网方式, 用户设备可以依据所述指示信息在通过无 线局域网接入时选择直接访问互联网或者通过连接到核心网访问互联网。 通过本发明,核心网能够通过指示信息控制 UE接入互联网的接入方式,从 而使用户终端在通过无线局域网接入时能够直接接入互联网而不经过核心 网, 使得用户设备在一些情形下 (比如核心网流量负载过大时)获得足够 的访问带宽, 从而提高用户体验。 附图说明
图 1为相关技术的非 3GPP网络接入 I-WLAN的网络架构示意图; 图 2为相关技术的非 3GPP网络接入 EPC的网络架构示意图; 图 3 为相关技术的用户设备接入无线局域接入网时执行接入认证的交 互流程图;
图 4为本发明实施例 1的 UE通过无线局域网接入互联网方式的控制方 法的流程图;
图 5为本发明实施例 2的 UE通过无线局域网接入互联网方式的控制方 法的流程图;
图 6为本发明实施例 3的 UE通过无线局域网接入互联网方式的控制方 法的流程图;
图 7为本发明实施例 4的 UE通过无线局域网接入互联网方式的控制方 法的流程图;
图 8为本发明用户终端接入互联网方式的控制装置的结构示意图。 具体实施方式
为使本发明的目的、 技术方案和优点更加清楚明白, 以下举实施例并 参照附图, 对本发明进一步详细说明。
实施例 1
图 4为本发明实施例 1的 UE通过无线局域网接入互联网方式的控制方 法的流程图, 该流程中, 用户设备通过 WLAN AN初始连接到 EPC网络, 在认证流程中, 认证授权计费服务器根据策略将直接连入互联网的指示信 息经由 WLAN AN发送给 UE , 以达到控制 UE通过无线局域网接入互联网 的方式的发明目的。本实施例中,认证授权计费服务器发送给 UE的指示信 息, 要求 UE在访问互联网业务时, 不经过核心网络直接通过 WLAN AN 访问互联网, UE收到该指示信息后, 釆用对应的选路策略访问 Internet业 务。 该流程具体步骤为:
步骤 401: 用户设备建立 WLAN无线连接;
步骤 402: WLAN AN建立与 UE的无线连接, WLAN AN向 UE发送 EAP请求( EAP Request/Identity )消息, 请求 UE提供身份信息给网络, 用 于接入认证;
步骤 403: UE收到 EAP请求消息后, 通过 EAP回复消息将 UE身份 信息发送给 WLAN AN;
步骤 404: WLAN AN向 AAA服务器发送携带 UE身份信息的 AAA请 求消息 (Diameter消息 ), 所述 AAA请求消息中还携带有接入类型和接入 网标识;
步骤 405: AAA服务器和 HSS交互 EAP-AKA,算法认证信息, 进行用 户算法认证;
步骤 406: AAA服务器提取密钥信息;
步骤 407: AAA服务器向 WLAN AN发送 AAA/AKA'挑战消息 , 进行 算法协商 , AAA/AKA,挑战消息中携带包含消息认证码的 EAP请求及 ΑΚΑ' 挑战信息;
步骤 408: WLAN AN 向用户设备发送包含消息认证码的 EAP请求 /AKA'挑战消息;
步骤 409: 用户设备收到 EAP请求 /AKA,挑战消息后运行 AKA算法生 成密钥相关信息;
步骤 410:用户设备将 AKA计算结果封装到 EAP中向 WLAN发送 EAP 响应 /AKA' 4 战消息;
步骤 411 : WLAN AN将收到的包含算法协商信息的 EAP响应消息封 装到 Diameter报文中转发给 AAA服务器;
步骤 412: AAA服务器检查收到的消息认证码信息, 对其进行算法信 息验证等处理;
步骤 413: AAA服务器根据策略确定 UE的互联网连接方式为不经过 EPC 核心网直接接入互联网的接入方式, 并将包含该接入方式的指示信息 封装到包含扩展认证协议成功 EAP-Success消息的 Diameter报文中发送给 WLAN AN。
如果需要 WLAN AN知道核心网关于 UE接入互联网接入方式的这个 决策(例如出于某种安全策略的考虑), 可以利用 Diameter报文预留的扩展 字段( Vendor-Specific-Application-Id AVP,设备指定应用标识属性值对字段, 以下简称 AVP字段)携带所述指示信息;
步骤 414: WLAN AN将 EAP Success消息转发给 UE。 如果所述指示 信息包含在 Vendor-Specific-Application-Id AVP字段中, 则 WLAN AN可以 对该 Diameter报文进行解析,提取互联网连接方式的指示后再将 EAP消息 转发给 UE。
实施例 2
图 5为本发明实施例 2的 UE通过无线局域网接入互联网方式的控制方 法的流程图 , 该流程中, 用户设备已经通过 WLAN AN连接到 EPC网络 , 在需要发起重认证的情况下, 如核心网流量压力过大或运营商策略变化等, AAA服务器在重认证流程中将 UE接入互联网方式的指示信息下发给 UE, 图 5以快速重认证流程为例 (Fast Re-Authentication Procedure ), 在 AAA Server发送的重认证请求 ( Re-Auth-Request ) 消息中携带所述指示信息: 步骤 501 : 认证授权计费服务器向用户设备发送重认证请求 ( Re-Auth-Request ) 消息, 其中, 在该消息中通过 AVP字段携带核心网为 UE确定的互联网接入方式的指示信息;
步骤 502 : 用户设备向认证授权计费服务器发送重认证响应 ( Re-Auth-Response ) 消息, 消息中包含快速重认证身份标识;
步骤 503: 认证授权计费服务器收到快速重认证身份标识后进行识别, 认可进行快速重认证流程;
步骤 504: 用户设备和授权计费服务器进行快速重认证流程。
实施例 3
图 6为本发明实施例 3的 UE通过无线局域网接入互联网方式的控制方 法的流程图, 该流程中, 用户设备通过 WLAN AN初始连接到 EPC网络, 用户设备和分组数据网关(PDG )在创建因特网密钥交换协议(IKEv2 )隧 道过程中, AAA服务器在授权消息中将 UE的互联网接入方式指示信息经 由 PDG下发给 UE的实施例流程图。 具体步骤为:
步骤 601 : UE和 PDG交换第一对消息 IKE— SA— INIT协商加密算法, 进行随机数的交换等。
步骤 602: UE通过 PDG和 AAA服务器进行的身份认证信息的交互。 步骤 603 : UE 向 PDG发送包含 EAP 消息的因特网密钥交换认证 ( IKE AUTH )请求消息到 PDG, 响应身份认证交互过程中收到的认证挑 战。
步骤 604: PDG将 EAP-Response响应消息 (带 AKA挑战信息)发送 给 AAA服务器。
步骤 605: AAA服务器在验证成功后向 PDG发送包含 EAP-Success和 密钥信息的认证回答。
步骤 606: PDG向 AAA服务器发送包含空 AVP和 WLAN接入点名称 ( W-APN )信息的授权请求。
步骤 607: AAA服务器验证用户信息是否允许建立隧道。 AAA服务器 根据网络策略 (这里 AAA服务器可能根据自己的策略控制或者网络网关系 统通知改变 UE接入互联网的方式)决策 UE接入互联网的方式, 并将包含 UE接入互联网方式的指示信息在下一步授权响应消息中下发。
步骤 608: AAA服务器向 PDG发送授权响应 ( AA- Answer )消息 , 其 中包含 UE接入互联网方式的指示信息。
步骤 609: PDG根据密钥信息计算生成认证参数 ( AUTH payload )信 息。
步骤 610 : PDG 通过 IKEv2 向 UE 发送因特网密钥交换认证 ( IKE AUTH )响应消息, IKE— AUTH响应消息包含携带 UE接入互联网 方式的指示信息的 EAP Success/Failure消息。
上述流程成功, UE完成和 PDG之间的 IP安全( IPSec ) 隧道的建立。 实施例 4
图 7为本发明实施例 4的 UE通过无线局域网接入互联网方式的控制方 法的流程图,该流程中,用户设备和演进分组数据网关(ePDG )完成 IKEv2 消息协商、 IPSec隧道建立后, UE和 P-GW建立安全联盟, AAA服务器和 P-GW进行认证授权, 在此过程中 AAA服务器将 UE接入互联网方式的指 示信息经由 P-GW传递给 UE的。 这里 UE通过 DSMIPv6 (双栈移动 IPv6 协议)接入网络。 具体步骤如下:
步骤 701 : UE发起建立 IKEv2隧道流程进行安全隧道认证授权。 这里 类似实施例 3的 IPSec Tunnel隧道建立流程, 这里不再赘述;
步骤 702: 演进分组数据网关将携带分配给 UE用于 IPSec隧道的 IP 地址的 IKEv2配置消息返回给 UE;
步骤 703: 在 UE和演进分组数据网关成功建立 IPSec隧道后, UE和 P-GW之间通过 IKEv2 协议流程建立安全联盟以保障信令消息的安全, P-GW和 AAA服务器通过 EAP方法进行认证和授权, 在此过程中 AAA服 务器将 UE接入互联网方式的指示信息经由 P-GW下发给 UE, 例如通过授 权响应消息, 这里流程与实施例 3流程类似, 这里不再赘述。
步骤 704: UE向 P-GW发送绑定更新消息, 传递移动管理协议信令消 息;
步骤 705: P-GW向 UE发送绑定更新确认消息, 完成 DSMIPv6地址 绑定。 UE和 P-GW之间的 DSMIPv6隧道建成, 至此, UE完成与网络之间 的 IP连接。
实施例 5
图 8为本发明用户终端接入互联网方式的控制装置的结构示意图, 该 装置至少包括: 发送模块、 接收模块和接入模块。
发送模块, 位于认证授权计费服务器, 用于向用户设备下发用户设备 接入互联网方式的指示信息; 接收模块, 位于 UE, 用于接收所述发送模块 下发的用户设备接入互联网方式的指示信息; 接入模块, 用于根据所述指 示信息决定访问互联网业务的接入方式。
优选地, 在用户设备已经通过 WLAN AN连接到 EPC网络后的重认证 流程中,所述发送模块将 UE接入互联网方式的指示信息包含在重认证请求 消息中下发给所述接收模块。
优选地, 所述装置还包括转发模块, 所述转发模块依据不同的实现方 式, 位于不同的网元中。
与图 4相对应, 转发模块可位于 WLAN AN中, 用于在用户设备初始 连接到 EPC的认证流程中,转发由所述发送模块下发给所述接收模块的 UE 接入互联网方式的指示信息。
与图 6相对应, 转发模块可位于 PDG中, 用于在用户设备初始连接到 EPC的用户设备和 PDG创建 IKEv2隧道的流程中,转发由所述发送模块下 发给所述接收模块的 UE接入互联网方式的指示信息。
与图 7相对应, 转发模块可位于 P-GW, 用于在 UE和 P-GW建立安全 联盟及认证授权计费服务器和 P-GW进行认证授权的过程中, 转发由所述 发送模块下发给所述接收模块的 UE接入互联网方式的指示信息。
本发明针对相关技术中运营商无法控制用户设备通过无线局域网访问 互联网时是否通过运营商 3GPP核心网的问题,提供了一种接入方法,釆用 认证授权计费服务器向用户设备发送核心网为用户设备确定的接入互联网 的接入方式的指示信息,以达到由核心网根据一定的控制策略控制 UE接入 互联网的接入方式的发明目的, 以使得用户可以直接接入互联网, 从而获 得足够的访问带宽, 并提高用户体验。
以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保 护范围。

Claims

权利要求书
1、 一种用户终端接入互联网方式的控制方法, 其特征在于, 该方法包 括:
认证授权计费服务器向用户设备 ( UE ) 下发用户设备接入互联网方式 的指示信息, 所述用户设备根据所述指示信息决定访问互联网业务的接入 方式。
2、 根据权利要求 1所述的方法, 其特征在于, 所述认证授权计费服务 器向用户设备下发用户设备接入互联网方式的指示信息的方法为:
在用户设备通过无线局域网接入网络( WLAN AN )初始连接到演进分 组核心网(EPC )的认证流程中, 所述认证授权计费服务器将包含用户设备 接入互联网方式的指示信息经由 WLAN AN下发给 UE。
3、 根据权利要求 2所述的方法, 其特征在于, 所述认证授权计费服务 器将 UE 接入互联网方式的指示信息封装到包含 EAP-Success 消息的 Diameter报文中发送给 WLAN AN,由 WLAN AN将所述 EAP-Success消息 转发给 UE;
所述指示信息位于 Diameter 报文设备指定应用标识属性值对 ( Vendor-Specific-Application-Id AVP ) 字段中。
4、 根据权利要求 1所述的方法, 其特征在于, 所述认证授权计费服务 器向用户设备下发用户设备接入互联网方式的指示信息, 具体为:
用户设备通过 WLAN AN初始连接到 EPC时, 在用户设备和分组数据 网关( PDG )创建因特网密钥交换协议( IKEv2 )隧道的流程中, 所述认证 授权计费服务器将 UE接入互联网方式的指示信息经由 PDG下发给 UE。
5、 根据权利要求 4所述的方法, 其特征在于, 所述认证授权计费服务 器将 UE接入互联网方式的指示信息包含在授权响应消息中下发给 PDG; PDG通过 IKEv2隧道发送携带 UE接入互联网方式的指示信息的因特网密 钥交换认证响应消息给所述 UE。
6、 根据权利要求 1所述的方法, 其特征在于, 所述认证授权计费服务 器向用户设备下发用户设备接入互联网方式的指示信息, 具体为:
在用户设备已经通过 WLAN AN连接到 EPC网络后 ,在重认证流程中 , 所述认证授权计费服务器将 UE接入互联网方式的指示信息包含在重认证 请求消息中下发给 UE。
7、 根据权利要求 1所述的方法, 其特征在于, 所述认证授权计费服务 器向用户设备下发用户设备接入互联网方式的指示信息, 具体为:
用户设备和演进分组数据网关( ePDG )完成 IPSec隧道建立后, 在 UE 和分组数据网络网关(P-GW )建立安全联盟及所述认证授权计费服务器和 P-GW进行认证授权的过程中,所述认证授权计费服务器将 UE接入互联网 方式的指示信息经由 P-GW下发给 UE。
8、 一种用户终端接入互联网方式的控制装置, 其特征在于, 该装置包 括:
发送模块, 位于认证授权计费服务器, 用于向用户设备下发用户设备 接入互联网方式的指示信息;
接收模块, 位于 UE, 用于接收所述发送模块下发的用户设备接入互联 网方式的指示信息;
接入模块, 位于 UE, 用于根据所述指示信息决定访问互联网业务的接 入方式。
9、 根据权利要求 8 所述的装置, 其特征在于, 在用户设备已经通过 WLAN AN连接到 EPC网络后的重认证流程中, 所述发送模块将 UE接入 互联网方式的指示信息包含在重认证请求消息中下发给所述接收模块。
10、 根据权利要求 8所述的装置, 其特征在于, 所述装置还包括转发 模块, 位于 WLAN AN, 用于在用户设备初始连接到 EPC的认证流程中, 转发由所述发送模块下发给所述接收模块的 UE接入互联网方式的指示信 息。
11、 根据权利要求 8所述的装置, 其特征在于, 所述装置还包括: 转发模块, 位于 PDG, 用于在用户设备初始连接到 EPC的用户设备和 PDG创建 IKEv2隧道的流程中, 转发由所述发送模块下发给所述接收模块 的 UE接入互联网方式的指示信息。
12、 根据权利要求 8所述的装置, 其特征在于, 所述装置还包括: 转发模块, 位于 P-GW, 用于在 UE和 P-GW建立安全联盟及认证授权 计费服务器和 P-GW进行认证授权的过程中, 转发由所述发送模块下发给 所述接收模块的 UE接入互联网方式的指示信息。
PCT/CN2011/071584 2010-04-15 2011-03-07 一种用户终端接入互联网方式的控制方法及装置 WO2011127774A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2010101497691A CN102223634A (zh) 2010-04-15 2010-04-15 一种用户终端接入互联网方式的控制方法及装置
CN201010149769.1 2010-04-15

Publications (1)

Publication Number Publication Date
WO2011127774A1 true WO2011127774A1 (zh) 2011-10-20

Family

ID=44780033

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/071584 WO2011127774A1 (zh) 2010-04-15 2011-03-07 一种用户终端接入互联网方式的控制方法及装置

Country Status (2)

Country Link
CN (1) CN102223634A (zh)
WO (1) WO2011127774A1 (zh)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103067342B (zh) * 2011-10-20 2018-01-19 中兴通讯股份有限公司 一种使用eap进行外部认证的设备、系统及方法
CN103250446B (zh) * 2011-12-02 2015-12-02 华为技术有限公司 确定用户设备接入方式的方法及系统、设备
CN103220817A (zh) * 2012-01-20 2013-07-24 中兴通讯股份有限公司 会话建立方法及装置
EP2844005A4 (en) * 2012-04-26 2015-06-03 Huawei Tech Co Ltd METHOD FOR ACCESSING PACKET NETWORK, WLAN ACCESS SYSTEM AND USER DEVICE
CN103379591B (zh) * 2012-04-26 2019-03-01 中兴通讯股份有限公司 用户设备接入模式的选择方法及装置
PL2887594T3 (pl) 2013-12-19 2020-07-13 Alcatel Lucent Sterowanie przeciążeniem dla dostępu zaufanej WLAN do EPC
CN106302376A (zh) * 2015-06-29 2017-01-04 中兴通讯股份有限公司 重认证识别方法、演进分组数据网关及系统
CN106686589B (zh) * 2015-11-09 2020-04-28 中国电信股份有限公司 一种实现VoWiFi业务的方法、系统及AAA服务器
CN107371157A (zh) * 2016-05-13 2017-11-21 北京旅信顺捷软件科技有限公司 运营商ePDG网关接入系统及实现移动通信的方法
CN106301809A (zh) * 2016-08-22 2017-01-04 广东工业大学 一种用户自定义的epc数据并发传输方法
CN107070922B (zh) * 2017-04-18 2020-02-04 北京思特奇信息技术股份有限公司 一种加快消息生成的方法及装置

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141822A (zh) * 2007-09-30 2008-03-12 中兴通讯股份有限公司 一种无线网络的网关选择方法
WO2009135371A1 (zh) * 2008-05-04 2009-11-12 中兴通讯股份有限公司 网络连接方式的确定方法

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1715625A1 (en) * 2005-04-22 2006-10-25 Alcatel Apparatuses for controlling service delivery using access-dependent information in a system comprising a core network subsystem
US20070201430A1 (en) * 2005-12-29 2007-08-30 Telefonaktiebolaget Lm Ericsson (Publ) Implicit secondary PDP context activation method

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141822A (zh) * 2007-09-30 2008-03-12 中兴通讯股份有限公司 一种无线网络的网关选择方法
WO2009135371A1 (zh) * 2008-05-04 2009-11-12 中兴通讯股份有限公司 网络连接方式的确定方法

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
HYERAN MUN ET AL.: "3G-WLAN Interworking: Security Analysis and New Authentication and Key Agreement Based on EAP-AKA", WIRELESS TELECOMMUNICATIONS SYMPOSIUM, April 2009 (2009-04-01), pages 1 - 8, ISSN: 1934-5070, Retrieved from the Internet <URL:http://ieeexplore.ieee.org/xpls/abs_all.jsp?arnumber=5068983> *
IRFAN ALI ET AL.: "LTE-3GPP RELEASE 8, Network-Based Mobility Management in the Evolved 3GPP Core Network", IEEE COMMUNICATIONS MAGAZINE, vol. 47, February 2009 (2009-02-01), pages 58 - 66, ISSN: 0163-6804, Retrieved from the Internet <URL:http://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=4785381> *

Also Published As

Publication number Publication date
CN102223634A (zh) 2011-10-19

Similar Documents

Publication Publication Date Title
WO2011127774A1 (zh) 一种用户终端接入互联网方式的控制方法及装置
EP2445143B1 (en) Method and system for accessing a 3rd generation network
EP1597866B1 (en) Fast re-authentication with dynamic credentials
US8561200B2 (en) Method and system for controlling access to communication networks, related network and computer program therefor
CA2755142C (en) Method for user terminal authentication and authentication server and user terminal thereof
EP2432265B1 (en) Method and apparatus for sending a key on a wireless local area network
EP1693995B1 (en) A method for implementing access authentication of wlan user
KR101002799B1 (ko) 이동통신 네트워크 및 상기 이동통신 네트워크에서 이동 노드의 인증을 수행하는 방법 및 장치
KR102390380B1 (ko) 비인증 사용자에 대한 3gpp 진화된 패킷 코어로의 wlan 액세스를 통한 긴급 서비스의 지원
EP1672945A1 (en) UMTS-WLAN interworking system and authentication method therefor
US9226153B2 (en) Integrated IP tunnel and authentication protocol based on expanded proxy mobile IP
WO2018170617A1 (zh) 一种基于非3gpp网络的入网认证方法、相关设备及系统
WO2005055518A1 (fr) Procede d&#39;etablissement de tunnel de services dans un reseau wlan
EP3275149B1 (en) Configuration of liveness check timeout using ike messages
US7979901B2 (en) Controlling the number of internet protocol security (IPsec) security associations
WO2006135217A1 (en) System and method for otimizing tunnel authentication procedure over a 3g-wlan interworking system
WO2015100974A1 (zh) 一种终端认证的方法、装置及系统
WO2016023198A1 (zh) 异构网络之间的切换方法及切换系统
WO2009152676A1 (zh) Aaa服务器、p-gw、pcrf、用户设备标识的获取方法和系统
WO2008110099A1 (fr) Procédé, système et dispositif associé pour accès d&#39;un appareil d&#39;authentification à un réseau de communication
WO2010069202A1 (zh) 认证协商方法及系统、安全网关、家庭无线接入点
WO2014063530A1 (zh) 移动用户固网的接入方法及系统
WO2013037273A1 (zh) 一种对用户设备能力进行处理的方法和系统
JP2020505845A (ja) 緊急アクセス中のパラメータ交換のための方法およびデバイス
WO2017000620A1 (zh) 重认证识别方法、演进分组数据网关及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11768386

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11768386

Country of ref document: EP

Kind code of ref document: A1