WO2011134134A1 - Wifi网络与wimax网络互通的方法、装置及系统 - Google Patents

Wifi网络与wimax网络互通的方法、装置及系统 Download PDF

Info

Publication number
WO2011134134A1
WO2011134134A1 PCT/CN2010/072180 CN2010072180W WO2011134134A1 WO 2011134134 A1 WO2011134134 A1 WO 2011134134A1 CN 2010072180 W CN2010072180 W CN 2010072180W WO 2011134134 A1 WO2011134134 A1 WO 2011134134A1
Authority
WO
WIPO (PCT)
Prior art keywords
user terminal
wifi
home agent
wimax
aaa
Prior art date
Application number
PCT/CN2010/072180
Other languages
English (en)
French (fr)
Inventor
熊志伟
倪慧
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201080001608.6A priority Critical patent/CN102308622B/zh
Priority to PCT/CN2010/072180 priority patent/WO2011134134A1/zh
Publication of WO2011134134A1 publication Critical patent/WO2011134134A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W36/00Hand-off or reselection arrangements
    • H04W36/0005Control or signalling for completing the hand-off
    • H04W36/0011Control or signalling for completing the hand-off for data sessions of end-to-end connection
    • H04W36/0033Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W36/00Hand-off or reselection arrangements
    • H04W36/14Reselecting a network or an air interface
    • H04W36/144Reselecting a network or an air interface over a different radio air interface technology
    • H04W36/1446Reselecting a network or an air interface over a different radio air interface technology wherein at least one of the networks is unlicensed

Definitions

  • the present invention relates to the field of communications, and in particular, to a method, device and system for interworking a WiFi network and a WiMAX network.
  • WiFi Wireless Fidelity
  • IEEE 802.11 Institute of Electrical and Electronic Engineers
  • WiMAX Worldwide Interoperability for Microwave Access
  • IEEE 802.16 wireless access technology as an extension of wireless broadband access technology, has the advantages of high bandwidth and wide coverage, and can provide users with high speed.
  • the data transmission capability has received wide attention and has been deployed in many countries and regions.
  • Mobile WiMAX networks increase support for terminal mobility, enabling mobile terminals to maintain business continuity when switching between different wireless access points and roaming, thus meeting the needs of commercial mobile communication services.
  • the embodiment of the present invention provides a method, device, and system for interworking between a WiMAX network and a WiMAX network, so that the user terminal can switch between a WiF i network that does not support the EAP authentication mode and a WiMAX network that supports the EAP authentication mode. Keep the continuity of the conversation.
  • a method for interworking a WiFi network with a WiMAX network including:
  • the global access authentication, authorization, and accounting server WiMAX AAA receives the home agent request message sent by the interworking function entity WIF to obtain the home agent address of the user terminal, where the home agent request message includes the user terminal on the wireless fidelity WiFi side.
  • the home agent request message includes the user terminal on the wireless fidelity WiFi side.
  • the WiMAX AAA is configured according to the user identifier of the user terminal on the WiFi side or the user identifier on the WiMAX side.
  • the user terminal allocates a home agent
  • a method for interworking a WiFi network with a WiMAX network including:
  • the home address request message for obtaining the home address sent by the user terminal is received, where the home address request message includes the user identifier of the user terminal on the WiFi side. ;
  • a WiMAX AAA that includes:
  • the home agent request message receiving unit is configured to receive a home agent request message that is sent by the interworking function entity WIF and obtain a home agent address of the user terminal, where the home agent request message includes a user identifier of the user terminal on the WiFi side or a user on the WiMAX side.
  • a home agent address allocation unit configured to: after the authentication and authorization of the user terminal by the WiFi AAA is successful, according to the user identifier of the user terminal or the user on the WiMAX side received by the home agent request message receiving unit Identifying, assigning a home agent to the user terminal;
  • the home agent response message sending unit is configured to send the address of the home agent assigned by the home agent address allocation unit to the user terminal to the WIF in the home agent response message.
  • a WiFi receiving network includes:
  • the home address request message receiving unit is configured to: after the user terminal uses the WiFi subscription certificate to perform authentication authentication and authorization by the WiFi AAA, receive a home address request message that is sent by the user terminal to obtain a home address, where the home address request message is The WiMAX network identifier and the user identifier of the user terminal on the WiFi side are included;
  • a determining unit configured to determine whether the user terminal has passed the authentication of the WiFi AAA
  • a home agent request message sending unit configured to send, to the WIF, a home agent request message for acquiring a home agent address of the user terminal, when the determining unit determines that the user terminal has passed the authentication of the WiFi AAA,
  • the home agent request message includes a user identifier of the user terminal on the WiFi side or a user identifier on the WiMAX side.
  • a system for interworking a network with a WiMAX network including:
  • the interworking function entity WIF is configured to receive a home agent request message that is sent by the WiFi access network and obtain a home agent address of the user terminal, and send the home agent request message to the WiMAX AAA, where the home agent request message includes the user terminal User ID on the WiFi side or user ID on the WiMAX side;
  • WiMAX AAA configured to receive the home agent request message sent by the WIF, and in WiFi AAA After the authentication of the user terminal 4 is successfully performed, the user identifier of the user terminal on the WiFi side or the user identifier on the WiMAX side allocates a home agent to the user terminal; carrying the address of the assigned home agent in the The home agent response message is sent to the WIF;
  • the WIF is further configured to receive a home agent response message sent by the WiMAX AAA, and obtain a home address of the user terminal from the home agent according to the address of the home agent.
  • the user terminal accesses the WiFi network that does not support the EAP authentication authentication mode
  • the user terminal passes the interworking function.
  • the entity sends a request message to the WiMAX AAA requesting to allocate a home address
  • the WiMAX AAA allocates an address of the home agent to the user terminal according to the user identifier of the user terminal on the WiMAX side, and the home agent allocates a address for the user.
  • the WiMAX AAA When the user terminal accesses the WiMAX network that supports the EAP authentication authentication mode, the WiMAX AAA also assigns the same home address to the user terminal according to the user identifier of the user terminal on the WiMAX side, thereby implementing The interworking between the WiFi network that does not support the EAP authentication authentication method and the WiMAX network that supports the EAP authentication authentication mode enables the user terminal to switch between the WiFi network that does not support the EAP authentication mode and the WiMAX network that supports the EAP authentication mode. , can maintain the continuity of the session.
  • FIG. 1 is a flowchart of a method for interworking between a WiFi network on a WiMAX AAA side and a WiMAX network according to Embodiment 1 of the present invention
  • FIG. 2 is a flowchart of a method for interworking between a WiFi network and a WiMAX network on an interworking function entity side according to Embodiment 1 of the present invention
  • FIG. 3 is a communication between a WiFi network on a WiFi access network side and a WiMAX network according to Embodiment 1 of the present invention; Flow chart of the method;
  • FIG. 4 is a flow chart of the interaction between the WiFi network and the WiMAX network in the second embodiment of the present invention
  • FIG. 5 is a flow chart of the interaction between the WiFi network and the WiMAX network in the third embodiment of the present invention
  • FIG. 7 is a block diagram showing the composition of a WiMAX AAA according to Embodiment 5 of the present invention
  • FIG. 8 is a block diagram showing the composition of another WiMAX AAA in Embodiment 5 of the present invention.
  • Embodiment 9 is a block diagram showing the composition of an interworking function entity in Embodiment 5 of the present invention.
  • FIG. 10 is a structural block diagram of a WiFi access network according to Embodiment 5 of the present invention.
  • FIG. 11 is a structural block diagram of another WiFi access network according to Embodiment 5 of the present invention.
  • FIG. 12 is a structural block diagram of a WiFi network and a WiMAX network interworking system according to Embodiment 5 of the present invention.
  • the technical solutions in the embodiments of the present invention are clearly and completely described in the following with reference to the accompanying drawings in the embodiments of the present invention. It is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. example. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts are within the scope of the present invention.
  • An embodiment of the present invention provides a method for interworking between a WiFi network and a WiMAX network, where the method is a WiMAX AAA (Authentication, Authorization, Accounting, Accounting) side, as shown in FIG.
  • Methods include:
  • the WiMAX AAA receives a home agent request message sent by the WiMAX Interworking Functation (WIF) to obtain a home agent address of the user terminal, where the home agent request message includes the user identifier of the user terminal on the WiFi side or on the WiMAX side.
  • WIF WiMAX Interworking Functation
  • the WiMAX AAA allocates a home agent to the user terminal according to the user identifier of the user terminal on the WiF i side or the user identifier on the WiMAX side.
  • the WiMAX AAA may assign a home agent to the user terminal according to the user identifier of the user terminal on the WiFi side or the user identifier on the WiMAX side, and may include:
  • the request message includes the user identifier of the user terminal on the WiMAX side, and directly assigns a home agent to the user terminal according to the user identifier of the user terminal on the WiMAX side; if the home agent request message includes the user terminal.
  • the user identifier on the WiFi side obtains the terminal user identifier of the user terminal on the WiMAX side according to the subscription association relationship between the WiFi network and the WiMAX network, and the user terminal obtained according to the WiMAX side
  • the user ID assigns a home agent to the user terminal.
  • the WiMAX AAA sends the address of the assigned home agent to the WIF in a home agent response message, so that the WIF obtains the user terminal from the home agent according to the address of the home agent. Home address.
  • the embodiment of the present invention further provides a method for interworking between a WiFi network and a WiMAX network.
  • the method is a method on the WIF side. As shown in FIG. 2, the method includes:
  • the WIF receives the home agent request message sent by the WiFi access network to obtain the home agent address of the user terminal, and sends the home agent request message to the WiMAX AAA, where the home agent request message includes the user identifier of the user terminal on the WiFi side. Or the user ID on the WiMAX side.
  • the WIF receives the home agent response message sent by the WiMAX AAA, where the home agent response message includes the user identifier of the WiMAX AAA according to the user terminal on the WiFi side or the user of the user terminal on the WiMAX side. Identifies the address of the home agent assigned to the end user.
  • the WIF obtains the home address of the user terminal from the home agent according to the address of the home agent.
  • the obtaining, by the WIF, the home address of the user terminal from the home agent according to the address of the home agent may include: sending, by the WIF, the address to the home agent according to the address of the home agent Transmitting a MIP registration request message of the IP registration, and receiving a MIP registration response message sent by the home agent, where the MIP registration response message includes a home address allocated by the home agent to the user terminal.
  • the embodiment of the invention further provides a method for interworking between a WiFi network and a WiMAX network, and the method is The method of the WiFi (Aces s Network) side, as shown in FIG. 3, the method includes:
  • the home address request message for obtaining the home address sent by the user terminal is received, where the home address request message includes the user terminal on the WiFi side.
  • User ID the Home address request message includes the user terminal on the WiFi side.
  • 302. Determine whether the user terminal has passed the authentication of the WiFi AAA, and if yes, send a home agent request message for acquiring a home agent address of the user terminal to the WIF, where the home agent request message includes the user terminal.
  • a user identity on the WiFi side or a user identity on the WiMAX side to cause the WIF to forward the home agent request message to the WiMAX AAA.
  • the user terminal accesses the WiFi network that does not support the EAP authentication authentication mode, after the user obtains the authentication authentication authorization by the WiFi AAA through the WiFi subscription certificate, the user terminal passes the interworking function entity to the WiMAX.
  • the AAA sends a request message for requesting the assignment of the home address, and the WiMAX AAA allocates an address of the home agent to the user terminal according to the user identifier of the user terminal on the WiMAX side, and the home agent assigns a home address to the user;
  • the WiMAX AAA also assigns the same home address to the user terminal according to the user identifier of the user terminal on the WiMAX side, thus implementing the support is not supported.
  • Interworking between the Wi-Fi network in the EAP authentication mode and the WiMAX network in the EAP authentication mode enables the user terminal to perform between the WiFi network that does not support the EAP authentication mode and the WiMAX network that supports the EAP authentication mode. When switching, you can maintain the continuity of the session.
  • An embodiment of the present invention provides a method for interworking between a WiFi network and a WiMAX network. As shown in FIG. 4, the method includes:
  • the user terminal establishes a connection with a WiFi access network (WiFi Acces s Network, WiFi AN).
  • WiFi access network WiFi Acces s Network, WiFi AN.
  • WiFi AN WiFi Acces s Network
  • the user terminal After the user terminal establishes a contact with the WiFi AN, the user terminal sends an authentication authentication request message to the WiFi AAA by using the WiFi AN, where the authentication authentication request message includes the use a WiFi subscription certificate of the user terminal, so that the WiFi AAA implements authentication and authentication of the user terminal according to the WiFi subscription certificate.
  • the WiFi AAA After the WiFi AAA successfully authenticates the user terminal according to the WiFi subscription certificate, the user terminal is assigned an authorization token, and the authorization token is sent to the user terminal.
  • the sending the authorization token to the user terminal may be sent to the user terminal by using an authentication authentication request response message; or the authorization token may be sent to the user terminal by creating a new message, as shown in the figure.
  • the authorization token is sent to the user terminal by using other information, which is not limited in this embodiment of the present invention.
  • the authorization token is assigned by the WiF i AAA to the user terminal, and the WiFi AAA can determine whether the user terminal has authenticated through the WiFi network according to the user identifier of the WiFi side and the token, and it can be a
  • the encrypted key can also be a random number.
  • the WiFi AAA may notify the WiMAX AAA of the authentication result of the user terminal in the WiFi network by using a notification message.
  • the message includes the user identifier of the user terminal on the WiFi side, and after receiving the notification message, the WiMAX AAA returns a response to the WiFi kkk.
  • the notification message may include the subscription association relationship information of the user terminal and the authorization token information allocated by the WiFi AAA to the terminal; if there is no subscription association relationship in the WiFi network, the notification message The user identification information of the terminal on the WiFi side and the authorization token information allocated by the WiFi AAA to the terminal may be included.
  • the home address request message may be, but not limited to, a DHCP (Dynamic Host Configuration Protocol) request message.
  • DHCP Dynamic Host Configuration Protocol
  • the access identifier includes user identification information of the user terminal on the WiFi side and network identification information of the WiMAX network to be accessed, which may be a parameter of a combination of the two types of information, or may be two independent parameters. 404.
  • the WiFi AN After receiving the home address request message, the WiFi AN forwards the home address request message to the WIF according to the WiMAX network identifier information in the access identifier.
  • the WiMAX network identification information is that the WiFi AN can forward the home address request message to the correct WIF identification information according to the identification information, and may be a WiMAX network domain name or an WiMAX network identifier.
  • the WIF After receiving the home address request message, the WIF sends a home agent request message for obtaining the home agent address of the user terminal to the WiMAX AAA, and requests the user terminal to allocate a home agent, where the address acquisition message carries the WiFi side.
  • the WiMAX AAA receives the home agent request message sent by the WIF, and detects whether the user terminal has passed the authentication of the WiF i AAA. If the user terminal has passed the authentication of the WiFi AAA, Obtaining, according to the user identifier of the user terminal on the WiFi side, the user identifier of the user terminal on the WiMAX side; and assigning a home agent to the user terminal according to the obtained user identifier of the user terminal on the WiMAX side. In the process of allocating a home agent to the user terminal, if the user terminal is a newly accessed user terminal, a new home agent is assigned to the user terminal, and if the user terminal is switched, The user terminal allocates a home agent that was originally assigned to the user terminal.
  • the method for detecting whether the user terminal has passed the authentication of the WiFi AAA may use the following method, specifically: if the WiMAX AAA is from the WiFi before detecting whether the user terminal has passed the authentication of the WiFi AAA.
  • the AAA obtains the authorization token that the user terminal has passed the authentication, and then queries whether the user terminal has passed the authentication of the WiFi AAA according to the authorization token obtained from the WiFi AAA; if the user is detected Before the terminal has passed the authentication of the WiF i AAA, the WiMAX AAA does not obtain the authorization token that the user terminal has passed the authentication authentication from the WiFi AAA, and sends an authentication query request message to the WiFi AAA.
  • the right query request message includes a user identifier and an authorization token of the user terminal on the WiFi side, so that the WiFi AAA queries whether the user terminal has passed the WiFi AAA according to the authorization token acquired from the WiFi AAA.
  • the WiMAX AAA acquires the detection result of the WiFi AAA.
  • the querying, according to the authorization token obtained from the WiFi AAA, whether the user terminal has passed the authentication of the WiFi AAA, may specifically be: the authorization token included in the home agent request message and the slave WiFi
  • the authorization tokens obtained by the AAA are compared. If the two are consistent, the user terminal has passed the authentication of the W i F i AAA.
  • the obtaining, by the user terminal, the user identifier of the user terminal on the WiMAX side according to the user identifier of the user terminal on the WiMAX side includes: according to the subscription association relationship between the WiFi terminal and the WiMAX network of the user terminal, and the user terminal is on the WiFi side
  • the user identifier is obtained, and the user identifier of the user terminal on the WiMAX side is obtained. Since the subscription association can be stored in WiMAX AAA, it can also be stored in
  • WiFi AAA therefore, before acquiring the user identity of the user terminal on the WiMAX side according to the subscription association relationship between the WiFi network and the WiMAX network of the user terminal, and the user identity of the user terminal on the WiFi side, Declaring an association relationship; obtaining the contract association relationship specifically includes:
  • the subscription association relationship is directly extracted from the WiMAX AAA.
  • the subscription association relationship stored in the WiMAX AAA may be directly stored or may be The WiFi AAA is obtained by the embodiment of the present invention. If the WiMAX AAA does not store the subscription association relationship, the WiMAX AAA sends an authentication query request to the WiFi AAA to obtain the subscription. connection relation.
  • the WiMAX AAA sends the address of the home agent assigned to the user terminal to the WIF in the home agent response message.
  • the WIF initiates a MIP registration for mobile IP registration to the home agent, and obtains a home address of the user terminal. That is, after the WIF obtains the home agent address of the user terminal, the MIP registration request message for mobile IP registration is sent to the home agent according to the address of the home agent, and the home agent receives the MIP registration request message. Assigning a home address to the user terminal, and transmitting the home address assigned to the user terminal in the MIP registration response message to the WIF.
  • the The home agent will assign the user terminal a home address used by the user terminal for the initial access according to the user identity of the user terminal on the WiMAX side.
  • the WIF After obtaining the home address of the user terminal, that is, after the MIP registration is completed, the WIF sends the home address assigned to the terminal to the mobile terminal by using a DHCP message.
  • the user terminal when the user terminal accesses the WiFi network that does not support the EAP authentication authentication mode, after the user successfully obtains the authentication authorization by the WiFi AAA through the WiFi subscription certificate, the user terminal passes the interworking function entity to the WiMAX AAA.
  • the WiMAX AAA assigns an address of the home agent to the user terminal according to the user identifier of the user terminal on the WiMAX side, and the home agent assigns a home address to the user;
  • the WiMAX AAA also assigns the same home address to the user terminal according to the user identifier of the user terminal on the WiMAX side, thus implementing the E support is not supported.
  • Interworking between the Wi-Fi network of the AP authentication and authentication mode and the WiMAX network supporting the EAP authentication mode enables the user terminal to switch between the WiFi network that does not support the EAP authentication mode and the WiMAX network that supports the EAP authentication mode. When you can maintain the continuity of the session.
  • the embodiment of the invention provides a method for interworking between a WiFi network and a WiMAX network. As shown in FIG. 5, the method includes:
  • the user terminal establishes a connection with a WiFi access network (WiFi Acces s Network, WiFi AN).
  • WiFi access network WiFi Acces s Network, WiFi AN.
  • WiFi AN WiFi Acces s Network
  • the user terminal After the user terminal establishes contact with the WiFi AN, the user terminal sends an authentication authentication request message to the WiFi AAA by using the WiFi AN, where the authentication authentication request message includes the WiFi subscription certificate of the user terminal. So that the WiFi AAA implements authentication authentication of the user terminal according to the WiFi subscription certificate. After the WiFi AAA successfully authenticates the user terminal according to the WiFi subscription certificate, the user identifier of the user terminal on the WiFi side is sent to the user terminal.
  • the WiFi AAA verifies the result of the user terminal authentication, and the subscription association relationship notification For WiMAX AAA, as shown in steps lc, Id in Figure 5.
  • the home address request message includes an access identifier.
  • the home address request message may be, but not limited to, a DHCP (Dynamic Hosting Protocol) request message.
  • the access identifier includes user identification information of the user terminal on the WiFi side and network identification information of the WiMAX network to be accessed.
  • the access identifier may be a parameter of a combination of the two types of information, or may be two independent parameters.
  • the WiFi AN After receiving the home address request message, the WiFi AN checks whether the user terminal has passed the authentication of the WiFi AAA. If it is detected that the user terminal has passed the authentication of the WiFi AAA, the step is performed. 505.
  • the WiFi AN checks whether the user terminal has passed the authentication of the WiFi AAA, and can detect that the user included in the home address request message is identified on the WiFi side, and that the user terminal passes the WiFi AAA. After the authentication is authenticated, whether the user sent by the WiFi AAA to the WiFi AN is consistently implemented on the WiFi side, if the user included in the home address request message is identified on the WiFi side, If the user sent by the WiFi AAA to the WiFi AN is consistent on the Wii F i side, it indicates that the user terminal has passed the authentication of the WiFi AAA.
  • the WiFi AN sends the home address request message to the WIF according to the WiMAX network identifier information in the access identifier carried in the home address request message, where the home address request message carries the user identifier of the WiFi side.
  • the WIF After receiving the home address request message, the WIF sends a home agent request message to the WiMAX AAA to obtain a home agent address of the user terminal, where the home agent request message carries a user identifier of the user terminal on the WiFi side.
  • the WiMAX AAA After receiving the home agent request message, the WiMAX AAA obtains a user identifier of the user terminal on the WiMAX side according to the user identifier of the user terminal on the WiFi side; and according to the acquired user terminal, on the WiMAX side. User ID, assigning a home agent to the user terminal.
  • the WiMAX AAA is used in the process of allocating a home agent to the user terminal. If the user terminal is a newly accessed user terminal, a new home agent is assigned to the user terminal. If it is a handover of the user terminal, the user terminal is assigned a home agent originally assigned to the user terminal.
  • the obtaining the user identifier of the user terminal on the WiMAX side according to the user identifier of the user terminal on the WiFi side comprises: according to the subscription association relationship between the WiFi network and the WiMAX network, and the user terminal is in the WiF i
  • the user identifier of the side obtains the user identifier of the user terminal on the WiMAX side. Since the subscription association relationship may be stored in the WiMAX AAA, it may also be stored in the WiFi AAA, and therefore obtained according to the subscription association relationship between the WiFi network and the WiMAX network according to the user terminal, and the user identifier of the user terminal on the WiFi side.
  • the user terminal needs to acquire the subscription association relationship before the user identifier of the WiMAX side, and the acquiring the association relationship includes:
  • the subscription association relationship is directly extracted from the WiMAX AAA, where the subscription association relationship stored in the WiMAX AAA may be directly stored or may be The WiFi AAA is obtained by the embodiment of the present invention. If the WiMAX AAA does not store the subscription association relationship, the WiMAX AAA sends an authentication query request to the WiFi AAA to obtain the subscription association. relationship.
  • the WiMAX AAA sends the address of the home agent assigned to the user terminal to the WIF in the home agent response message.
  • the WIF initiates a MIP registration for mobile IP registration to the home agent and obtains a home address of the user terminal. That is, after the WIF obtains the home agent address of the user terminal, the address of the home agent sends a MIP registration request message for mobile IP registration to the home agent, and the home agent receives the MIP registration request message.
  • the user terminal allocates a home address, and the home address assigned to the user terminal is carried in the MIP registration corresponding response message and sent to the WIF.
  • the home agent may allocate the user terminal to the user terminal according to the user identifier of the user terminal on the WiMAX side.
  • the WIF After obtaining the home address of the user terminal, that is, after the MIP registration is completed, the WIF sends the home address assigned to the terminal to the mobile terminal by using a DHCP message.
  • the user terminal accesses the WiFi network that does not support the EAP authentication authentication mode
  • the user obtains the WiFi AAA successful authentication and authorization through the WiFi subscription certificate
  • the user terminal passes the interworking function.
  • the entity sends a request message to the WiMAX AAA requesting to allocate a home address
  • the WiMAX AAA allocates a home agent address to the user terminal according to the user identifier of the user terminal on the WiMAX side, and the home agent assigns a hometown to the user.
  • the WiMAX AAA When the user terminal accesses the WiMAX network that supports the EAP authentication authentication mode, the WiMAX AAA also assigns the same home address to the user terminal according to the user identifier of the user terminal on the WiMAX side, thereby implementing Interworking between a WiFi network that does not support the EAP authentication method and a WiMAX network that supports the EAP authentication mode, so that when the user terminal switches between a WiFi network that does not support the EAP authentication mode and a WiMAX network that supports the EAP authentication mode, You can maintain the continuity of the session.
  • the WiFi AN before the WiFi AN sends the home address request message to the WIF, the WiFi AN detects whether the user terminal that sends the home address request message has passed the authentication of the W i F i AAA, and the user terminal has passed the WiFi. After the authentication of the AAA, the home address request message is sent to the WIF, and the WiFi AAA and the WiMAX AAA do not need to use the token mechanism to prevent the user terminal from impersonating, thereby simplifying the process of the WiMAX network assigning the home address to the user terminal.
  • the embodiment of the invention provides a method for interworking between a WiFi network and a WiMAX network. As shown in FIG. 6, the method includes:
  • the user terminal establishes a connection with a WiFi access network (WiFi Acces s Network, WiFi AN).
  • WiFi access network WiFi Acces s Network, WiFi AN.
  • WiFi AN WiFi Acces s Network
  • the user terminal After the user terminal establishes contact with the WiFi AN, the user terminal sends an authentication authentication request message to the WiFi AAA by using the WiFi AN, where the authentication authentication request message includes the foregoing.
  • a WiFi subscription certificate of the user terminal so that the WiFi AAA implements authentication and authentication of the user terminal according to the WiFi subscription certificate.
  • the WiFi AAA sends the result of the WiFi AAA authentication and authentication to the user terminal after the user terminal successfully authenticates the user terminal according to the WiFi subscription certificate.
  • the WiFi AAA obtains the subscription association relationship, and sends the subscription association relationship to the WiFi AN, as shown in step le in FIG. 6, so that the WiFi AN is configured according to the
  • the subscription association acquires the user identifier of the user terminal on the WiMAX side.
  • the contract association relationship may be stored in the WiMAX AAA, and may be stored in the WiFi AAA. Therefore, if the subscription association relationship is stored in the WiFi AAA, the subscription association relationship is directly extracted from the WiFi AAA; The WiFi AAA does not store the subscription association relationship, and the WiFi AAA sends an authentication query request to the WiMAX AAA to obtain the subscription association relationship, as shown in steps lc and Id in FIG. 6 .
  • the WiFi AAA authentication 4 After the user terminal is authorized by the WiFi AAA authentication 4, send a home address request message for obtaining the home address of the user terminal to the WiFi AN, where the home address request message carries WiMAX network identification information, optionally carrying WiMAX. User identification information on the side.
  • the WiFi AN After receiving the home address request message, the WiFi AN checks whether the user has passed the WiFi AAA authentication. If it is detected that the user terminal has passed the authentication of the WiFi AAA, step 605 is performed. The WiFi AN checks whether the user terminal has passed the authentication of the WiFi AAA, and can detect that the user included in the home address request message is identified on the WiFi side, and that the user terminal passes the WiFi AAA. After the authentication is authenticated, whether the user sent by the WiFi AAA to the WiFi AN is consistently implemented on the WiFi side, if the user included in the home address request message is identified on the WiFi side, If the user sent by the WiFi AAA to the WiFi AN is consistent on the Wii F i side, it indicates that the user terminal has passed the authentication of the WiFi AAA.
  • the WiFi AN obtains the foregoing according to the subscription association relationship received in step 602. User ID of the user terminal on the WiMAX side.
  • the WiFi AN sends a home address request message for acquiring a home address of the user terminal to the WIF, where the home address request message includes a user identifier of the user terminal on a WiMAX side.
  • the WIF After receiving the home address request message, the WIF sends a home agent request message requesting to obtain a home agent address of the user terminal to the WiMAX AAA, where the home agent request message carries the user identifier of the user terminal on the WiMAX side. .
  • the WiMAX AAA After receiving the home agent request message, the WiMAX AAA allocates a home agent to the user terminal according to the user identifier of the user terminal obtained on the WiMAX side according to the address. The WiMAX AAA allocates a home agent to the user terminal, and if the user terminal is a newly accessed user terminal, assigns a new home agent to the user terminal. If the user terminal switches, the side will be The user terminal allocates a home agent that was originally assigned to the user terminal.
  • the WiMAX AAA sends the address of the home agent assigned to the user terminal to the WIF in the home agent response message.
  • the WIF initiates a MIP registration for mobile IP registration to the home agent and obtains a home address of the user terminal. That is, after the WIF obtains the home agent address of the user terminal, the address of the home agent sends a MIP registration request message for mobile IP registration to the home agent, and the home agent receives the MIP registration request message.
  • the user terminal allocates a home address, and carries the home address assigned to the user terminal in the MIP registration response message and sends the message to the WIF.
  • the home agent may allocate the user terminal to the user terminal according to the user identifier of the user terminal on the WiMAX side.
  • the WIF After obtaining the home address of the user terminal, that is, after the MIP registration is completed, the WIF sends the home address assigned to the terminal to the user terminal by using a DHCP message.
  • the user terminal when the user terminal accesses the WiFi network that does not support the EAP authentication authentication mode, after the user obtains the WiFi AAA successful authentication and authorization through the WiFi subscription certificate, the user terminal sends the WiMAX AAA to the WiMAX AAA through the interworking function entity. Requesting a request message for allocating a home address, the WiMAX AAA assigning a one to the user terminal according to the user identifier of the user terminal on the WiMAX side The address of the home agent, and the home agent assigns a home address to the user; when the user terminal accesses through the WiMAX network supporting the EAP authentication method, the WiMAX AAA is also based on the user terminal on the WiMAX side.
  • the user identifier is used to allocate the same home address to the user terminal, so that the Wi 2 network that does not support the E AP authentication authentication mode and the WiMAX network that supports the E AP authentication authentication mode are implemented, so that the user terminal is in the When switching between a WiFi network that does not support EAP authentication mode and a WiMAX network that supports EAP authentication mode, session continuity can be maintained.
  • the WiFi AN before the WiFi AN sends the received home address request message for obtaining the home address of the user terminal to the WIF, it is detected whether the user terminal that sends the home address request message has passed the authentication of the WiFi AAA. After the authentication of the WiFi AAA is detected, the user identity of the user terminal on the WiMAX side is obtained and sent to the WiMAX AAA according to the obtained subscription association relationship, so that the WiMAX AAA receives the request for obtaining the home agent address of the user terminal.
  • the embodiment of the present invention provides a WiMAX AAA.
  • the WiMAX AAA includes: a home agent request message receiving unit 71, a home agent address assigning unit 71, and a home agent response message sending unit 73.
  • the home agent request message receiving unit 71 is configured to receive a home agent request message that is sent by the interworking function entity WIF and obtain a home agent address of the user terminal, where the home agent request message includes the user identifier of the user terminal on the WiFi side or on the WiMAX side. User ID.
  • the home agent address allocation unit 72 is configured to allocate a home agent to the user terminal according to the user identifier of the user terminal on the Wi F i side or the user identifier on the WiMAX side received by the home agent request message receiving unit 71. So that the WIF obtains the home address of the user terminal from the home agent according to the address of the home agent.
  • the home agent response message sending unit 73 is configured to send the address of the home agent assigned by the home agent address assigning unit 72 to the user terminal to the home agent response message, and send the message to the home agent response message. WIF.
  • the home agent address allocation unit 72 includes: a home agent address allocation module 721 and an identity acquisition module 722.
  • the home agent address allocation module 721 is configured to: when the home agent request message received by the home agent request message receiving unit 71 includes the user identifier of the user terminal on the WiMAX side, according to the user terminal on the WiMAX side The user identifier is assigned a home agent for the user terminal; the identifier obtaining module 722 is configured to include the user identifier of the user terminal on the WiFi side in the home agent request message received by the home agent request message receiving unit 71.
  • the home agent address allocation module 721 is further configured to: according to the identifier obtaining module 722 The acquired user identifier of the user terminal on the WiMAX side allocates a home agent to the user terminal.
  • the WiMAX AAA further includes: a subscription association acquiring unit 74 and an authentication authentication detecting unit 75.
  • the subscription association obtaining unit 74 is configured to acquire the user terminal in the WiF i before acquiring the user identifier of the user terminal on the WiMAX side according to the subscription association relationship between the WiF i network and the WiMAX network of the user terminal according to the subscription association relationship between the WiF i network and the WiMAX network. Signing association between network and WiMAX network.
  • the contract association relationship may be stored in the WiMAX AAA, and may also be stored in the WiFi AAA.
  • the contract association relationship may include: when the subscription association relationship stores WiMAX AAA, the contract association relationship obtaining unit 74 is configured to acquire the subscription association relationship stored by the WiMAX AAA itself; when the approximate association relationship is stored in the WiFi AAA, the user terminal is authenticated and authenticated in the WiFi AAA.
  • the contract association relationship acquiring unit 74 is configured to receive the result of the user terminal authentication authentication sent by the WiFi AAA and the contract association relationship; the contract association relationship acquiring unit 74 is further used to The WiFi AAA sends an authentication query request, and receives the subscription association relationship returned by the WiFi AAA according to the authentication query request.
  • the authentication authentication detecting unit 75 is configured to: when the home agent request message received by the home agent request message receiving unit 71 includes the user identifier of the user terminal and the authorization token of the user terminal, the authentication The right authentication detecting unit 75 detects, according to the user identifier of the user terminal on the WiFi side and the 4 authorized token of the user terminal, whether the user terminal has passed the authentication of the WiFi AAA; wherein, the authentication authentication is detected.
  • the unit 75 detects whether the user terminal has passed the authentication of the WiFi AAA, if the user terminal has detected the authentication of the WiFi AAA, the WiMAX AAA obtains the user terminal from the WiFi AAA.
  • the authenticating token of the right authentication the detecting unit 75 queries whether the user terminal has passed the authentication of the WiFi AAA according to the authorization token acquired from the WiFi AAA; if it is detecting whether the user terminal has passed the WiFi Before the authentication of the AAA, the WiMAX AAA does not obtain the authorization token that the user terminal has passed the authentication authentication from the WiFi AAA, and the check is performed.
  • the detecting unit 75 sends an authentication query request message to the WiFi AAA, where the authentication query request message includes a user identifier and an authorization token of the user terminal on the WiFi side, so that the WiFi AAA is based on the WiFi.
  • the authorization token obtained by the AAA queries whether the user terminal has passed the authentication of the WiFi AAA.
  • the querying, according to the authorization token obtained from the WiFi AAA, whether the user terminal has passed the authentication of the WiFi AAA, may specifically be: the authorization token included in the home agent request message and the slave WiFi
  • the authorization tokens obtained by the AAA are compared. If the two are consistent, the user terminal has passed the authentication of the W i F i AAA.
  • the embodiment of the present invention further provides a WIF. As shown in FIG. 9, the WIF includes: a first receiving unit.
  • the first transmitting unit 82, the second receiving unit 83, and the obtaining unit 84 The first transmitting unit 82, the second receiving unit 83, and the obtaining unit 84.
  • the first receiving unit 81 is configured to receive a home agent request message that is sent by the WiFi access network and obtain a home agent address of the user terminal, where the home agent request message includes a user identifier of the user terminal on the WiFi side or a user identifier on the WiMAX side. .
  • the first sending unit 82 is configured to send the home agent request message to the WiMAX AAA.
  • a second receiving unit 83 configured to receive a home agent response message sent by the WiMAX AAA, where the home agent response message includes the WiMAX AAA according to the user terminal on a WiMAX side
  • the user ID is the address of the home agent assigned to the end user.
  • the obtaining unit 84 is configured to obtain, according to the address of the home agent received by the second receiving unit 83, the home address of the user terminal from the home agent.
  • the obtaining, by the obtaining unit 84, the home address of the user terminal from the home agent according to the address of the home agent received by the second receiving unit 83 may be: according to the address of the home agent
  • the home agent sends a MIP registration request message for mobile IP registration, and receives a MIP registration response message sent by the home agent.
  • the MIP registration response message includes a home address assigned by the home agent to the user terminal.
  • the WiFi access network includes: a home address request message receiving unit 91, a determining unit 92, and a home agent request message sending unit 93.
  • the home address request message receiving unit 91 is configured to: after the user terminal uses the WiFi subscription certificate to perform authentication authentication and authorization by the WiFi AAA, receive a home address request message that is sent by the user terminal to obtain a home address, and the home address request message
  • the WiMAX network identifier and the user identifier of the user terminal on the WiFi side are included.
  • the determining unit 92 is configured to determine whether the user terminal has passed the authentication of the WiFi AAA.
  • the determining unit 92 determines whether the user terminal has passed the authentication of the WiFi AAA, and can detect the home address.
  • the user included in the request message is identified on the WiFi side, and after the user terminal passes the authentication of the WiFi AAA, whether the user sent by the WiFi AAA to the WiFi AN is consistent on the WiFi side If it is checked that the user included in the home address request message is identified on the WiFi side, and the user sent by the WiFi AAA to the WiFi AN is consistent on the WiFi side, it indicates that the user terminal has already Authentication by WiFi AAA.
  • the home agent request message sending unit 93 is configured to determine, at the determining unit 92, the user end When the terminal has passed the authentication of the WiF i AAA, the home agent request message for acquiring the home agent address of the user terminal is sent to the WIF, so that the WIF forwards the home agent request message to the WiMAX AAA.
  • the home agent request message includes a user identifier of the user terminal on the WiF i side or a user identifier on the WiMAX side.
  • the home agent request message sending unit 93 is further configured to: include the user identifier of the user terminal on the WiF i side and the user terminal in the home address request message received by the home address request message receiving unit 91 And transmitting, in the home agent request message, the user identifier of the user terminal on the WiF i side and the authorization token of the user terminal to the WIF, so that the WIF is The WiMAX AAA forwards the home agent request message.
  • the WiF i access network further includes a subscription association detecting unit 94 and an identifier obtaining unit 95.
  • the subscription association detecting unit 94 is configured to detect, after the determining unit 92 determines that the user terminal has passed the authentication of the WiF i AAA, whether the WiF i access network itself stores the user terminal. Signing association relationship between WiF i network and WiMAX network.
  • the identifier obtaining unit 95 is configured to: when the subscription association detecting unit 94 detects that the subscription association relationship exists in the WiF i access network, according to the user identifier on the WiF i side, and the user terminal is in the a subscription relationship between the WiF i network and the WiMAX network, acquiring the user terminal
  • the home agent request message sending unit 93 is configured to send the user identifier of the user terminal acquired by the identifier obtaining unit 95 on the WiMAX side to the home agent request message for acquiring the home agent address of the user terminal, and send the WIF to the WIF, so that The WIF to the WiMAX
  • the AAA forwards the home agent request message.
  • the home agent request message sending unit 93 is further configured to: when the subscription association detecting unit detects 94 that the subscription relationship does not exist in the WiF i access network, the user terminal is on the WiF i side.
  • the user identifier is sent to the WIF in a home agent request message that obtains the home agent proxy address of the user terminal, so that the WIF forwards the home agent request message to the WiMAX AAA.
  • the embodiment of the present invention further provides a system for interworking between a WiF i network and a WiMAX network. As shown in FIG. 12, the system includes: an interworking function entity 1001 and a WiMAX AAA1002 o.
  • the interworking function entity WIF1001 is configured to receive a home agent request message sent by the WiFi access network to obtain a home agent proxy address of the user terminal, and send the home agent request message to the WiMAX
  • the home agent request message includes a user identifier of the user terminal on the WiFi side or
  • the WiMAX AAA1002 is configured to receive the home agent request message sent by the WIF 1001, and after the authentication of the user terminal of the WiFi AAA is successfully authorized, according to the user identity of the user terminal on the WiFi side or on the WiMAX side.
  • the user identifier is assigned to the user terminal by the home agent; and the address of the assigned home agent is sent to the WIF 1001 in the home agent response message.
  • the WIF 1001 is further configured to receive a home agent response message sent by the WiMAX AAA 1002, and obtain an address of the home agent from the home agent to obtain a home address of the user terminal.
  • the user terminal accesses the WiFi network that does not support the EAP authentication authentication mode, after the user obtains the WiFi AAA successful authentication and authorization through the WiFi subscription certificate, the user terminal sends the WiMAX AAA to the WiMAX AAA through the interworking function entity.
  • the WiMAX AAA assigns an address of the home agent to the user terminal according to the user identifier of the user terminal on the WiMAX side, and the home agent assigns a home address to the user;
  • the WiMAX AAA also allocates the same home address to the user terminal according to the user identifier of the user terminal on the WiMAX side, thereby implementing the EAP not supported.
  • Interworking between the Wii F i network in the authentication mode and the WiMAX network supporting the E AP authentication mode enables the user terminal to switch between the WiFi network that does not support the EAP authentication mode and the WiMAX network that supports the EAP authentication mode. , can maintain the continuity of the session; and the interworking of the above two networks is through Assign a home address for the user terminal to achieve, there is no increase in the cost of additional operators.
  • the WiFi AN before the WiFi AN sends the home address request message to the WIF, the WiFi AN detects whether the user terminal that sends the home address request message has passed the authentication of the W i F i AAA, and after the user terminal has passed the authentication of the WiFi AAA, sends a home address request message to the WIF, WiFi AAA and WiMAX AAA does not need to use a token mechanism to prevent user terminal counterfeiting, thereby simplifying the process of assigning a home address to a user terminal by a WiMAX network.
  • the WiF i AN detects that the user terminal has passed the authentication of the WiF i AAA
  • the user identity of the user terminal on the WiMAX side is obtained and sent to the WiMAX AAA according to the acquired subscription association relationship.
  • the WiMAX AAA directly allocates a corresponding home agent to the user terminal according to the user identifier of the WiMAX side, thereby avoiding that the WiMAX AAA needs to acquire WiMAX for the user terminal that allocates the home agent.
  • the user identification on the side further simplifies the process of WiMAX AAA assigning home addresses to user terminals.
  • the present invention can be implemented by means of software plus necessary general hardware, and of course, by hardware, but in many cases, the former is a better implementation. .
  • the technical solution of the present invention which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a readable storage medium, such as a floppy disk of a computer.
  • a hard disk or optical disk or the like includes instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to perform the methods described in various embodiments of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种WiFi网络与WiMAX网络互通的方法、装置及系统,涉及通信领域,使用户终端在不支持EAP鉴权方式的WiFi网络与支持EAP鉴权方式的WiMAX网络间进行切换时,可以保持会话的连续性。本发明包括:用户终端通过WiFi认证授权后,发送为该用户终端分配家乡地址的请求消息;在检查该用户终端已通过WiFi鉴权认证后,WiMAX获得用户终端在WiMAX侧中的用户标识,并根据该用户标识为该用户终端分配家乡代理,并由该家乡代理为该用户终端分配家乡地址。本发明主要用于用户终端通过不支持EAP鉴权方式的WiFi接入网接入到WiMAX核心网的过程中。

Description

WiFi网络与 WiMAX网络互通的方法、 装置及系统 技术领域
本发明涉及通信领域,尤其涉及一种 WiFi网络与 WiMAX网络互通的方法、 装置及系统。
背景技术
基于 IEEE 802.11 ( Institute of Electrical and Electronic Engineers , 电气电子工程师学会) 的无线接入技术的 WiFi (Wireless Fidelity, 无线保 真) 网络, 由于其高速率传输及便捷的部署, 目前已在酒店、 社区、 校园及 企业广泛应用。 但由于 WiFi网络的接入点存在覆盖范围小、 部署数量多、 管 理复杂等原因, WiFi网络对终端的移动性支持相对较差。 同样, 基于 IEEE 802.16的无线接入技术的 WiMAX( Worldwide Interoperability for Microwave Access , 微波存取全球互通) 网络, 作为无线宽带接入技术的扩展, 具有高 带宽、 广覆盖等优势, 能够为用户提供高速的数据传输能力, 受到了广泛的 关注,在许多国家、地区已部署。移动 WiMAX网络增加了对终端移动性的支持, 使得移动终端在不同无线接入点间切换和漫游时能够保持业务连续性, 从而 满足商用移动通信业务的需求。
目前部署的 WiFi无线接入网络, 除了空口连接部分已经在 IEEE标准定义 外, 网络侧由于实现方式多样以及标准进展等原因, 已部署的网络绝大部分 在网络侧的实现方式并未统一, 尤其在安全性方面实现方式多种多样, 据调 查统计, 目前已部署的 WiFi网络中, 有 95%的网络使用非 EAP ( Extensible Authentication Protocol, 可扩展认证协议) 的认证鉴权方式, 如用户名和 密码的方式, 而只有约 5%的 WiFi网络支持 EAP的认证鉴权方式。 但是目前的 WiMAX网络中使用了 IETF ( Internet Engineering Task Force, 互连网工程 任务组)定义的 EAP认证鉴权方式, 因此用户终端无法实现在支持 EAP的 WiMAX 网络和不支持 EAP的 WiFi接入网络间切换时, 保持用户会话的连续性。 如果升 级已部署的 WiFi接入网使其支持 WiMAX的 EAP鉴权方式, 对于运营商来说, 代 价高昂。
发明内容
本发明的实施例提供一种 WiFi网络与 WiMAX网络互通的方法、 装置及系 统, 使用户终端在不支持 EAP鉴权方式的 WiF i 网络与支持 EAP鉴权方式的 WiMAX网络间进行切换时, 可以保持会话的连续性。
为达到上述目的, 本发明的实施例釆用如下技术方案:
一种 WiFi网络与 WiMAX网络互通的方法, 包括:
微波存取全球互通认证、 授权、 计费服务器 WiMAX AAA接收互通功能实 体 WIF发送的获取用户终端家乡代理地址的家乡代理请求消息, 所述家乡代 理请求消息中包括用户终端在无线保真 WiFi侧的用户标识或在 WiMAX侧的用 户标识;
在无线保真认证、 授权、 计费服务器 WiFi AAA对所述用户终端的认证授 权成功后 ,所述 WiMAX AAA根据所述用户终端在 WiFi侧的用户标识或在 WiMAX 侧的用户标识, 为所述用户终端分配家乡代理;
所述 WiMAX AAA将所述分配的家乡代理的地址携带在家乡代理响应消息 中发送给所述 WIF ,以使得所述 WIF才艮据所述家乡代理的地址从所述家乡代理 获取所述用户终端的家乡地址。
一种 WiFi网络与 WiMAX网络互通的方法, 包括:
在用户终端使用 WiFi签约证书到 WiFi AAA执行鉴权认证后, 接收所述 用户终端发送的获取家乡地址的家乡地址请求消息, 所述家乡地址请求消息 中包括所述用户终端在 WiFi侧的用户标识;
判断所述用户终端是否已通过所述 WiFi AAA的鉴权认证, 若是, 则向所 述 WIF发送获取用户终端家乡代理地址的家乡代理请求消息, 所述家乡代理 请求消息中包括用户终端在 WiFi侧的用户标识或在 WiMAX侧的用户标识, 以 使得所述 WIF向所述 WiMAX AAA转发所述家乡代理请求消息。。 一种 WiMAX AAA, 包括:
家乡代理请求消息接收单元, 用于接收互通功能实体 WIF发送的获取用 户终端家乡代理地址的家乡代理请求消息, 所述家乡代理请求消息中包括用 户终端在 WiFi侧的用户标识或在 WiMAX侧的用户标识;
家乡代理地址分配单元, 用于在 WiFi AAA对所述用户终端的认证授权成 功后, 根据所述家乡代理请求消息接收单元接收到的所述用户终端在 WiFi侧 的用户标识或在 WiMAX侧的用户标识, 为所述用户终端分配家乡代理;
家乡代理响应消息发送单元, 用于将所述家乡代理地址分配单元为所述 用户终端分配的家乡代理的地址携带在家乡代理响应消息中发送给所述 WIF。
一种 WiFi接收网, 包括:
家乡地址请求消息接收单元,用于在用户终端使用 WiFi签约证书到 WiFi AAA执行鉴权认证并授权后,接收所述用户终端发送的获取家乡地址的家乡地 址请求消息, 所述家乡地址请求消息中包括 WiMAX 网络标识和所述用户终端 在 WiFi侧的用户标识;
判断单元, 用于判断所述用户终端是否已经通过所述 WiFi AAA的鉴权认 证;
家乡代理请求消息发送单元, 用于在所述判断单元判定所述用户终端已 经通过所述 WiFi AAA的鉴权认证时, 向所述 WIF发送获取用户终端家乡代理 地址的家乡代理请求消息, 所述家乡代理请求消息中包括用户终端在 WiFi侧 的用户标识或在 WiMAX侧的用户标识。
一种网络与 WiMAX网络互通的系统, 包括:
互通功能实体 WIF, 用于接收 WiFi接入网发送的获取用户终端家乡代理 地址的家乡代理请求消息, 并将所述家乡代理请求消息发送给 WiMAX AAA, 所 述家乡代理请求消息中包含用户终端在 WiFi侧的用户标识或在 WiMAX侧的用 户标识;
WiMAX AAA, 用于接收 WIF发送的所述家乡代理请求消息, 并在 WiFi AAA 对所述用户终端的认证 4受权成功后, 居所述用户终端在 WiFi侧的用户标识 或在 WiMAX侧的用户标识为所述用户终端分配家乡代理; 将所述分配的家乡 代理的地址携带在家乡代理响应消息中发送给所述 W I F;
所述 WIF还用于, 接收所述 WiMAX AAA发送的家乡代理响应消息, 并根 据所述家乡代理的地址从所述家乡代理获取所述用户终端的家乡地址。
釆用本发明实施例的技术方案后, 当用户终端通过不支持 EAP鉴权认证 方式的 WiFi网络接入时, 在用户通过 WiFi签约证书得到 WiFi AAA成功认证 授权后, 所述用户终端通过互通功能实体向 WiMAX AAA发送请求分配家乡地 址的请求消息, WiMAX AAA根据所述用户终端在 WiMAX侧的用户标识, 为所述 用户终端分配一个家乡代理的地址, 并由该家乡代理为所述用户分配一个家 乡地址; 由于用户终端通过支持 EAP鉴权认证方式的 WiMAX网络接入时, 所 述 WiMAX AAA同样根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终 端分配同一个家乡地址, 因此实现了不支持 EAP鉴权认证方式的 WiFi网络和 支持 EAP鉴权认证方式的 WiMAX网络的互通, 使用户终端在不支持 EAP鉴权 方式的 WiFi网络与支持 EAP鉴权方式的 WiMAX网络间进行切换时, 可以保持 会话的连续性。
附图说明 为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实 施例或现有技术描述中所需要使用的附图作简单地介绍, 显而易见地, 下面 描述中的附图仅仅是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明实施例 1中 WiMAX AAA侧的 WiFi网络与 WiMAX网络互通的 方法的流程图;
图 2为本发明实施例 1中互通功能实体侧的 WiFi网络与 WiMAX网络互通 的方法的流程图;
图 3为本发明实施例 1中 WiFi 接入网侧的 WiFi网络与 WiMAX网络互通 的方法的流程图;
图 4为本发明实施例 2中 WiFi网络与 WiMAX网络互通方法交互流程图; 图 5为本发明实施例 3中 WiFi网络与 WiMAX网络互通方法交互流程图; 图 6为本发明实施例 4中 WiFi网络与 WiMAX网络互通方法交互流程图; 图 7为本发明实施例 5中一种 WiMAX AAA的组成框图;
图 8为本发明实施例 5中另一种 WiMAX AAA的组成框图;
图 9为本发明实施例 5中互通功能实体的组成框图;
图 10为本发明实施例 5中一种 WiFi接入网的组成框图;
图 11为本发明实施例 5中另一种 WiFi接入网的组成框图;
图 12为本发明实施例 5中 WiFi网络与 WiMAX网络互通系统的组成框图。 具体实施方式 下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案进行 清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实施例, 而 不是全部的实施例。 基于本发明中的实施例, 本领域普通技术人员在没有作 出创造性劳动前提下所获得的所有其他实施例 , 都属于本发明保护的范围。
实施例 1
本发明实施例提供一种 WiFi 网络与 WiMAX 网络互通的方法, 该方法为 WiMAX AAA ( Authent icat ion Author izat ion Account ing , 认证、 授权、 计 费服务器)侧的方法, 如图 1所示, 该方法包括:
101、 WiMAX AAA接收互通功能实体(WIF, WiMAX Interworking Funct ion ) 发送的获取用户终端家乡代理地址的家乡代理请求消息, 所述家乡代理请求 消息中包括用户终端在 WiFi侧的用户标识或在 WiMAX侧的用户标识。
102、 在 WiFi AAA对所述用户终端的认证授权成功后, 所述 WiMAX AAA 根据所述用户终端在 WiF i侧的用户标识或在 WiMAX侧的用户标识, 为所述用 户终端分配家乡代理。
其中,所述 WiMAX AAA根据所述用户终端在 WiFi侧的用户标识或在 WiMAX 侧的用户标识为所述用户终端分配家乡代理, 可以包括: 若所述家乡代理请 求消息中包括所述用户终端在 WiMAX侧的用户标识, 则直接根据所述用户终 端在 WiMAX侧的用户标识为所述用户终端分配家乡代理; 若所述家乡代理请 求消息中包括所述用户终端在 WiFi 侧的用户标识, 则根据所述用户终端在 WiFi网络和 WiMAX网络的签约关联关系, 获取所述用户终端在 WiMAX侧的终 端用户标识, 并才艮据所述获取的用户终端在 WiMAX侧的用户标识为所述用户 终端分配家乡代理。
103、 所述 WiMAX AAA将所述分配的家乡代理的地址携带在家乡代理响应 消息中发送给所述 WIF,以使得所述 WIF根据所述家乡代理的地址从所述家乡 代理获取所述用户终端的家乡地址。
本发明实施例还提供一种 WiFi网络与 WiMAX网络互通的方法, 该方法为 WIF侧的方法, 如图 2所示, 该方法包括:
20 WIF接收 WiFi接入网发送的获取用户终端家乡代理地址的家乡代理 请求消息, 并将所述家乡代理请求消息发送给 WiMAX AAA, 所述家乡代理请求 消息中包含用户终端在 WiFi侧的用户标识或在 WiMAX侧的用户标识。
202、 所述 WIF接收所述 WiMAX AAA发送的家乡代理响应消息, 所述家乡 代理响应消息中包含所述 WiMAX AAA根据所述用户终端在 WiFi侧的用户标识 或所述用户终端在 WiMAX侧的用户标识为所述终端用户分配的家乡代理的地 址。
203、 所述 WIF才艮据所述家乡代理的地址从所述家乡代理获取所述用户终 端的家乡地址。
其中, 所述 WIF根据所述家乡代理的地址从所述家乡代理获取所述用户 终端的家乡地址, 可以包括: 所述 WIF才艮据所述家乡代理的地址, 向所述家 乡代理发送用于移动 IP注册的 MIP注册请求消息, 并接收所述家乡代理发送 的 MIP注册响应消息, 所述 MIP注册响应消息中包括所述家乡代理为所述用 户终端分配的家乡地址。
本发明实施例还提供一种 WiFi网络与 WiMAX网络互通的方法, 该方法为 WiFi AN ( Acces s Network, 接入网)侧的方法, 如图 3所示, 该方法包括:
301、 在用户终端使用 WiFi签约证书到 WiFi AAA执行鉴权认证后, 接收 所述用户终端发送的获取家乡地址的家乡地址请求消息, 所述家乡地址请求 消息中包括所述用户终端在 WiFi侧的用户标识。
302、 判断所述用户终端是否已通过所述 WiFi AAA 的鉴权认证, 若是, 则向所述 WIF发送获取用户终端家乡代理地址的家乡代理请求消息, 所述家 乡代理请求消息中包括用户终端在 WiFi侧的用户标识或在 WiMAX侧的用户标 识, 以使得所述 WIF向所述 WiMAX AAA转发所述家乡代理请求消息。 本发明实施例中, 当用户终端通过不支持 EAP鉴权认证方式的 WiFi网络 接入时, 在用户通过 WiFi签约证书得到 WiFi AAA执行认证成功认证授权后, 所述用户终端通过互通功能实体向 WiMAX AAA发送请求分配家乡地址的请求 消息, WiMAX AAA根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端 分配一个家乡代理的地址, 并由该家乡代理为所述用户分配一个家乡地址; 由于用户终端通过支持 EAP鉴权认证方式的 WiMAX网络接入时,所述 WiMAX AAA 同样根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配同一个 家乡地址, 因此实现了不支持 E AP鉴权认证方式的 W i F i网络和支持 E AP鉴权 认证方式的 WiMAX网络的互通, 使用户终端在不支持 EAP鉴权方式的 WiFi网 络与支持 EAP鉴权方式的 WiMAX网络间进行切换时, 可以保持会话的连续性。
实施例 2
本发明实施例提供一种 WiFi网络与 WiMAX网络互通的方法,如图 4所示, 该方法包括:
401、 用户终端与 WiFi 接入网 (WiFi Acces s Network, WiFi AN )建立 联系。 在用户终端通过 WiFi网络入网时, 首先需要用户终端与 WiFi AN建立 联系。
402、在所述用户终端与 WiFi AN建立联系后,所述用户终端通过所述 WiFi AN向 WiFi AAA发送鉴权认证请求消息, 所述鉴权认证请求消息中包含所述用 户终端的 WiFi签约证书 , 以便所述 WiFi AAA根据所述 WiFi签约证书实现对 所述用户终端的鉴权认证。 WiFi AAA才艮据所述 WiFi签约证书对所述用户终端 认证成功后, 为所述用户终端分配一个授权令牌, 并将所述授权令牌发送给 所述用户终端。
其中, 将所述授权令牌发送给所述用户终端可以通过鉴权认证请求响应 消息发送给所述用户终端; 也可以通过新建一条消息将所述授权令牌发送给 所述用户终端, 如图 4中步骤 le所示; 还可以通过其他信息将所述授权令牌 发送给所述用户终端,本发明实施例对此不进行限制。所述的授权令牌是 WiF i AAA分配给所述用户终端的, WiFi AAA能够才艮据 WiFi侧的用户标识和该令牌 判断该用户终端是否已经通过 WiFi网络的鉴权, 它可以是一个加密的密钥, 也可以是一个随机数。
可选地如图 4中虚线的 lc、 Id所示, 在所述用户终端鉴权认证成功后, WiFi AAA可以将用户终端在 WiFi网络的鉴权结果通过通知消息通知给 WiMAX AAA,所述通知消息中包括所述用户终端在 WiFi侧的用户标识,所述 WiMAX AAA 接收到所述通知消息后, 返回应答给 WiFi kkk。
进一步, 如果 WiFi网络中有签约关联关系, 则通知消息中可以包括所述 用户终端的签约关联关系信息和 WiFi AAA分配给终端的授权令牌信息; 如果 WiFi网络中没有签约关联关系,则通知消息中可以包括终端在 WiFi侧的用户 标识信息和 WiFi AAA分配给终端的授权令牌信息。
403、 用户终端通过 WiFi认证 4受权后, 向所述 WiFi AN发送获取所述用 户终端家乡地址的家乡地址请求消息, 所述家乡地址请求消息中包括接入标 识和 WiFi AAA分配给终端的授权令牌。 所述家乡地址请求消息可以为但不局 艮于 DHCP (Dynamic Host Configuration Protocol, 动态主机西己置协议)请 求消息。
其中, 所述接入标识包括用户终端在 WiFi侧的用户标识信息和所要接入 WiMAX网络的网络标识信息, 其可以是两种信息的组合的一个参数, 也可以是 两个独立的参数。 404、 WiFi AN 收到所述家乡地址请求消息后, 根据所述接入标识中的 WiMAX网络标识信息, 将所述家乡地址请求消息转发给 WIF。
其中, 所述 WiMAX网络标识信息, 是 WiFi AN能够根据该标识信息将家 乡地址请求消息转发至正确的 WIF的标识信息, 它可以是一个 WiMAX网络的 域名, 也可以是一个 WiMAX网络的标识符。
405、 WIF收到所述家乡地址请求消息后, 发送获取用户终端的家乡代理 地址的家乡代理请求消息到 WiMAX AAA, 请求为所述用户终端分配家乡代理, 所述地址获取消息中携带 WiFi侧的用户标识和 WiF i AAA分配给终端的 4受权 令牌。
406、 所述 WiMAX AAA接收所述 WIF发送的所述家乡代理请求消息, 并检 测所述用户终端是否已通过 WiF i AAA 的鉴权认证, 若所述用户终端已通过 WiFi AAA的鉴权认证, 则根据所述用户终端在 WiFi侧的用户标识获取所述用 户终端在 WiMAX侧的用户标识; 并根据所述获取的所述用户终端在 WiMAX侧 的用户标识为所述用户终端分配家乡代理。 其中, 所述 WiMAX AAA为所述用 户终端分配家乡代理的过程中, 若该用户终端为新接入的用户终端, 则给其 新分配一个家乡代理, 如果是用户终端的切换, 则将为所述用户终端分配一 个原来分配给所述用户终端的家乡代理。
其中, 所述检测所述用户终端是否已通过 WiFi AAA的鉴权认证可以釆用 以下的方法, 具体包括: 如果在检测所述用户终端是否已经通过 WiFi AAA的 鉴权认证之前, WiMAX AAA从 WiFi AAA获取了所述用户终端已通过鉴权认证 的授权令牌, 则根据所述从 WiFi AAA获取的授权令牌查询所述用户终端是否 已经通过 WiFi AAA的鉴权认证;若在检测所述用户终端是否已经通过 WiF i AAA 的鉴权认证之前, WiMAX AAA没有从 WiFi AAA获取所述用户终端已通过鉴权 认证的授权令牌, 则向所述 WiFi AAA发送鉴权查询请求消息, 所述鉴权查询 请求消息中包括所述用户终端在 WiFi侧的用户标识和授权令牌, 以便由所述 WiFi AAA根据所述从 WiFi AAA获取的授权令牌查询所述用户终端是否已经通 过 WiFi AAA的鉴权认证, 所述 WiMAX AAA获取所述 WiFi AAA的检测结果。 其中, 所述根据所述从 WiFi AAA获取的授权令牌查询所述用户终端是否已经 通过 WiFi AAA的鉴权认证, 具体可以为, 将所述家乡代理请求消息中包含的 授权令牌与从 WiFi AAA获取的授权令牌进行比较, 若两者一致, 则表明所述 用户终端已经通过 W i F i AAA的鉴权认证。
其中,所述根据用户终端在 WiFi侧的用户标识获取所述用户终端在 WiMAX 侧的用户标识包括: 根据所述用户终端在 WiFi网络和 WiMAX网络的签约关联 关系, 以及所述用户终端在 WiFi侧的用户标识, 获取所述用户终端在 WiMAX 侧的用户标识。 由于所述签约关联关系可以存储在 WiMAX AAA, 也可以存储在
WiFi AAA, 因此在根据所述用户终端在 WiFi网络和 WiMAX网络的签约关联关 系, 以及所述用户终端在 WiFi侧的用户标识, 获取所述用户终端在 WiMAX侧 的用户标识之前, 需要先获取所述签约关联关系; 获取所述签约关联关系具 体包括:
若所述 WiMAX AAA中存储有签约关联关系, 则直接从所述 WiMAX AAA 自 身中提取所述签约关联关系, 其中所述 WiMAX AAA 中存储的签约关联关系, 可以是直接存储的, 也可以是从所述 WiFi AAA中获取的, 本发明实施例对此 不进行限制; 若所述 WiMAX AAA中没有存储签约关联关系, 则所述 WiMAX AAA 向所述 WiFi AAA发送鉴权查询请求要求获取所述签约关联关系。
407、 所述 WiMAX AAA将为所述用户终端分配的家乡代理的地址携带在家 乡代理响应消息中发送给所述 WIF。
408、 WIF向所述家乡代理发起用于移动 IP注册的 MIP注册, 并获得所述 用户终端的家乡地址。 即 WIF获得所述用户终端的家乡代理地址后, 才艮据所 述家乡代理的地址向所述家乡代理发送用于移动 IP 注册的 MIP 注册请求消 息, 所述家乡代理收到 MIP 注册请求消息后为所述用户终端分配家乡地址, 并将为所述用户终端分配的家乡地址携带在所述 MIP 注册响应消息中发送给 所述 WIF。
其中, 若所述用户终端接入的过程为切换的过程而非初次接入, 则所述 家乡代理会才艮据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配 一个所述用户终端初次接入时使用的家乡地址。
409、 在获取所述用户终端的家乡地址后, 即 MIP注册完成后, WIF通过 DHCP消息将分配给终端的家乡地址发送给移动终端。
本发明实施例中, 当用户终端通过不支持 EAP鉴权认证方式的 WiFi网络 接入时, 在用户通过 WiFi签约证书得到 WiFi AAA成功执行认证授权后, 所 述用户终端通过互通功能实体向 WiMAX AAA发送请求分配家乡地址的请求消 息, WiMAX AAA根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分 配一个家乡代理的地址, 并由该家乡代理为所述用户分配一个家乡地址; 由 于用户终端通过支持 EAP鉴权认证方式的 WiMAX网络接入时, 所述 WiMAX AAA 同样根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配同一个 家乡地址, 因此实现了不支持 E AP鉴权认证方式的 W i F i网络和支持 E AP鉴权 认证方式的 WiMAX网络的互通, 使用户终端在不支持 EAP鉴权方式的 WiFi网 络与支持 EAP鉴权方式的 WiMAX网络间进行切换时, 可以保持会话的连续性。
实施例 3
本发明实施例提供一种 WiFi网络与 WiMAX网络互通的方法,如图 5所示, 该方法包括:
501、 用户终端与 WiFi 接入网 (WiFi Acces s Network, WiFi AN )建立 联系。 在用户终端通过 WiFi网络入网时, 首先需要用户终端与 WiFi AN建立 联系。
502、在所述用户终端与 WiFi AN建立联系后,所述用户终端通过所述 WiFi AN向 WiFi AAA发送鉴权认证请求消息, 所述鉴权认证请求消息中包含所述用 户终端的 WiFi签约证书, 以便所述 WiFi AAA根据所述 WiFi签约证书实现对 所述用户终端的鉴权认证。 WiFi AAA才艮据所述 WiFi签约证书对所述用户终端 认证成功后, 将所述用户终端在 WiFi侧的用户标识发送给所述用户终端。
可选的, 在所述用户终端鉴权认证成功后, 如果 WiFi网络中有签约关联 关系, 则 WiFi AAA将所述用户终端认证的结果, 以及所述签约关联关系通知 给 WiMAX AAA, 如图 5中的步骤 lc、 Id所示。
503、 所述用户终端通过 WiFi AAA认证 4受权后, 向所述 WiFi AN发送获 取所述用户终端家乡地址的家乡地址请求消息, 所述家乡地址请求消息中包 括接入标识。 所述家乡地址请求消息可以为但不局限于 DHCP ( Dynamic Hos t Conf igura t ion Protocol , 动态主机配置协议)请求消息。 所述接入标识包 括用户终端在 WiFi 侧的用户标识信息和所要接入 WiMAX 网络的网络标识信 息, 其可以是两种信息的组合的一个参数, 也可以是两个独立的参数。
504、 所述 WiFi AN收到所述家乡地址请求消息后, 检查所述用户终端是 否已经通过 WiFi AAA的鉴权认证, 若检测到所述用户终端已经通过 WiFi AAA 的鉴权认证, 则执行步骤 505。
其中, 所述 WiFi AN检查所述用户终端是否已经通过 WiFi AAA的鉴权认 证, 可以通过检测所述家乡地址请求消息中包含的所述用户在 WiFi侧标识, 与在所述用户终端通过 WiFi AAA的鉴权认证后,由所述 WiFi AAA向所述 WiFi AN发送的所述用户在 WiFi侧标识是否一致实现,若所述家乡地址请求消息中 包含的所述用户在 WiFi侧标识, 与由所述 WiFi AAA向所述 WiFi AN发送的 所述用户在 W i F i侧标识一致, 则表明所述用户终端已经通过 W i F i AAA的鉴 权认证。
505、 所述 WiFi AN根据家乡地址请求消息中携带的接入标识中的 WiMAX 网络标识信息, 将所述家乡地址请求消息发送给 WIF, 所述家乡地址请求消息 中携带 WiFi侧的用户标识。
506、 所述 WIF收到所述家乡地址请求消息后, 向所述 WiMAX AAA发送获 取用户终端家乡代理地址的家乡代理请求消息, 所述家乡代理请求消息中携 带用户终端在 WiFi侧的用户标识。
507、 所述 WiMAX AAA接收到所述家乡代理请求消息后, 根据所述用户终 端在 WiFi侧的用户标识获取所述用户终端在 WiMAX侧的用户标识; 并根据获 取的所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配家乡代理。
其中, 所述 WiMAX AAA 为所述用户终端分配家乡代理的过程中, 若该用 户终端为新接入的用户终端, 则给其新分配一个家乡代理, 如果是用户终端 的切换, 侧将为所述用户终端分配一个原来分配给所述用户终端的家乡代理。
其中,所述根据用户终端在 WiFi侧的用户标识获取所述用户终端在 WiMAX 侧的用户标识包括: 根据所述用户终端在 WiFi网络和 WiMAX网络的签约关联 关系, 以及所述用户终端在 WiF i侧的用户标识, 获取所述用户终端在 WiMAX 侧的用户标识。 由于所述签约关联关系可以存储在 WiMAX AAA, 也可以存储在 WiFi AAA, 因此在根据所述用户终端在 WiFi网络和 WiMAX网络的签约关联关 系, 以及所述用户终端在 WiFi侧的用户标识, 获取所述用户终端在 WiMAX侧 的用户标识之前, 需要先获取所述签约关联关系; 获取所述签约关联关系具 体包括:
若所述 WiMAX AAA中存储有签约关联关系, 则直接从所述 WiMAX AAA中 提取所述签约关联关系, 其中所述 WiMAX AAA 中存储的签约关联关系, 可以 是直接存储的, 也可以是从所述 WiFi AAA中获取的, 本发明实施例对此不进 行限制; 若所述 WiMAX AAA中没有存储签约关联关系, 则所述 WiMAX AAA向 所述 WiFi AAA发送鉴权查询请求要求获取所述签约关联关系。
508、 所述 WiMAX AAA将为所述用户终端分配的家乡代理的地址携带在家 乡代理响应消息中发送给所述 WIF。
509、 WIF向所述家乡代理发起用于移动 IP注册的 MIP注册并获得所述用 户终端的家乡地址。 即 WIF获得所述用户终端的家乡代理地址后, 居所述 家乡代理的地址向所述家乡代理发送用于移动 IP注册的 MIP注册请求消息, 所述家乡代理收到 MIP 注册请求消息后为所述用户终端分配家乡地址, 并将 为所述用户终端分配的家乡地址携带在 MIP 注册相应响应消息中发送给所述 WIF。
其中, 若所述用户终端接入的过程为切换的过程而非初次接入, 则所述 家乡代理会才艮据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配 一个所述用户终端初次接入时使用的家乡地址。 510、 在获取所述用户终端的家乡地址后, 即 MIP注册完成后, WIF通过 DHCP消息将分配给终端的家乡地址发送给移动终端。
本发明实施例中, 当用户终端通过不支持 EAP鉴权认证方式的 WiFi网络 接入时, 在用户通过 WiFi签约证书得到 WiFi AAA成功认证授权后; 在认证 成功后, 所述用户终端通过互通功能实体向 WiMAX AAA发送请求分配家乡地 址的请求消息, WiMAX AAA根据所述用户终端在 WiMAX侧的用户标识, 为所述 用户终端分配一个家乡代理地址, 并由该家乡代理为所述用户分配一个家乡 地址; 由于用户终端通过支持 EAP鉴权认证方式的 WiMAX网络接入时, 所述 WiMAX AAA同样根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分 配同一个家乡地址, 因此实现了不支持 EAP鉴权认证方式的 WiFi网络和支持 EAP鉴权认证方式的 WiMAX网络的互通,使用户终端在不支持 EAP鉴权方式的 WiFi网络与支持 EAP鉴权方式的 WiMAX网络间进行切换时, 可以保持会话的 连续性。
并且, 本发明实施例中, 在 WiFi AN向 WIF发送家乡地址请求消息之前, WiFi AN检测发送家乡地址请求消息的用户终端是否已经通过 W i F i AAA的鉴 权认证, 在用户终端已经通过 WiFi AAA的鉴权认证后, 向所述 WIF发送家乡 地址请求消息, WiFi AAA和 WiMAX AAA不需使用令牌机制来预防用户终端假 冒, 从而使 WiMAX网络为用户终端分配家乡地址的过程简单化。
实施例 4
本发明实施例提供一种 WiFi网络与 WiMAX网络互通的方法,如图 6所示, 该方法包括:
601、 用户终端与 WiFi 接入网 (WiFi Acces s Network, WiFi AN )建立 联系。 在用户终端通过 WiFi网络入网时, 首先需要用户终端与 WiFi AN建立 联系。
602、在所述用户终端与 WiFi AN建立联系后,所述用户终端通过所述 WiFi AN向 WiFi AAA发送鉴权认证请求消息, 所述鉴权认证请求消息中包含所述用 户终端的 WiFi签约证书, 以便所述 WiFi AAA根据所述 WiFi签约证书实现对 所述用户终端的鉴权认证。 WiFi AAA才艮据所述 WiFi签约证书对所述用户终端 认证成功后, 将所述用户终端通过 WiFi AAA鉴权认证的结果发送给所述用户 终端。
并且, 在所述用户终端通过 WiFi AAA鉴权认证后, WiFi AAA获取签约关 联关系, 并将所述签约关联关系发送给 WiFi AN, 如图 6中的步骤 le所示, 以便 WiFi AN根据所述签约关联关系获取所述用户终端在 WiMAX侧的用户标 识。 由于所述签约关联关系可以存储在 WiMAX AAA, 也可以存储在 WiFi AAA, 因此若所述 WiFi AAA中存储有签约关联关系, 则直接从所述 WiFi AAA中提 取所述签约关联关系;若所述 WiFi AAA中没有存储签约关联关系 ,则所述 WiFi AAA向所述 WiMAX AAA发送鉴权查询请求要求获取所述签约关联关系, 具体如 图 6中的步骤 lc、 Id所示。
603、 所述用户终端通过 WiFi AAA认证 4受权后, 向所述 WiFi AN发送获 取所述用户终端家乡地址的家乡地址请求消息, 所述家乡地址请求消息携带 WiMAX网络标识信息, 可选地携带 WiMAX侧的用户标识信息。
604、 WiFi AN收到家乡地址请求消息息后,检查该用户是否已经通过 WiFi AAA的认证, 若检测到所述用户终端已经通过 WiFi AAA的鉴权认证, 则执行 步骤 605。 其中, 所述 WiFi AN检查所述用户终端是否已经通过 WiFi AAA的鉴权认 证, 可以通过检测所述家乡地址请求消息中包含的所述用户在 WiFi侧标识, 与在所述用户终端通过 WiFi AAA的鉴权认证后,由所述 WiFi AAA向所述 WiFi AN发送的所述用户在 WiFi侧标识是否一致实现,若所述家乡地址请求消息中 包含的所述用户在 WiFi侧标识, 与由所述 WiFi AAA向所述 WiFi AN发送的 所述用户在 W i F i侧标识一致, 则表明所述用户终端已经通过 W i F i AAA的鉴 权认证。
605、 所述 WiFi AN根据在步骤 602中接收的所述签约关联关系获得所述 用户终端在 WiMAX侧的用户标识。
606、 所述 WiFi AN向所述 WIF发送获取用户终端家乡地址的家乡地址请 求消息, 所述家乡地址请求消息中包括所述用户终端在 WiMAX侧的用户标识。
607、 所述 WIF收到所述家乡地址请求消息后, 向所述 WiMAX AAA发送请 求获取用户终端家乡代理地址的家乡代理请求消息, 所述家乡代理请求消息 中携带用户终端在 WiMAX侧的用户标识。
608、 所述 WiMAX AAA接收到所述家乡代理请求消息后, 根据所述地址获 取的所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配家乡代理。 其中, 所述 WiMAX AAA 为所述用户终端分配家乡代理的过程中, 若该用户终 端为新接入的用户终端, 则给其新分配一个家乡代理, 如果是用户终端的切 换, 侧将为所述用户终端分配一个原来分配给所述用户终端的家乡代理。
609、 所述 WiMAX AAA将为所述用户终端分配的家乡代理的地址携带在家 乡代理响应消息中发送给所述 WIF。
610、 WIF向所述家乡代理发起用于移动 IP注册的 MIP注册并获得所述用 户终端的家乡地址。 即 WIF获得所述用户终端的家乡代理地址后, 居所述 家乡代理的地址向所述家乡代理发送用于移动 IP注册的 MIP注册请求消息, 所述家乡代理收到 MIP 注册请求消息后为所述用户终端分配家乡地址, 并将 为所述用户终端分配的家乡地址携带在 MIP注册响应消息中发送给所述 WIF。
其中, 若所述用户终端接入的过程为切换的过程而非初次接入, 则所述 家乡代理会才艮据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配 一个所述用户终端初次接入时使用的家乡地址。
611、 在获取所述用户终端的家乡地址后, 即 MIP注册完成后, WIF通过 DHCP消息将分配给终端的家乡地址发送给用户终端。
本发明实施例中, 当用户终端通过不支持 EAP鉴权认证方式的 WiFi网络 接入时, 在用户通过 WiFi签约证书得到 WiFi AAA成功认证授权后, 所述用 户终端通过互通功能实体向 WiMAX AAA发送请求分配家乡地址的请求消息, WiMAX AAA根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配一 个家乡代理的地址, 并由该家乡代理为所述用户分配一个家乡地址; 由于用 户终端通过支持 EAP鉴权认证方式的 WiMAX网络接入时, 所述 WiMAX AAA同 样根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配同一个家 乡地址, 因此实现了不支持 E AP鉴权认证方式的 W i F i网络和支持 E AP鉴权认 证方式的 WiMAX网络的互通, 使用户终端在不支持 EAP鉴权方式的 WiFi网络 与支持 EAP鉴权方式的 WiMAX网络间进行切换时, 可以保持会话的连续性。
并且, 本发明实施例中, 在 WiFi AN将接收到的获取用户终端家乡地址 的家乡地址请求消息发送给 WIF之前, 检测发送家乡地址请求消息的用户终 端是否已经通过 WiFi AAA的鉴权认证, 在检测到通过 WiFi AAA的鉴权认证 后, 根据获取的签约关联关系, 获取用户终端在 WiMAX侧的用户标识并发送 给 WiMAX AAA,使所述 WiMAX AAA接收到获取用户终端家乡代理地址的请求时, 直接根据所述 WiMAX侧的用户标识为用户终端分配相应的家乡代理, 避免了 所述 WiMAX AAA需要对分配家乡代理的用户终端的鉴权认证和获取 WiMAX侧 的用户标识, 使 WiMAX AAA为用户终端分配家乡地址的过程进一步简单化。
实施例 5
本发明实施例提供一种 WiMAX AAA, 如图 7所示, 该 WiMAX AAA包括: 家 乡代理请求消息接收单元 71、家乡代理地址分配单元 71和家乡代理响应消息 发送单元 73。
家乡代理请求消息接收单元 71 , 用于接收互通功能实体 WIF发送的获取 用户终端家乡代理地址的家乡代理请求消息, 所述家乡代理请求消息中包括 用户终端在 WiFi侧的用户标识或在 WiMAX侧的用户标识。
家乡代理地址分配单元 72 , 用于根据所述家乡代理请求消息接收单元 71 接收到的所述用户终端在 Wi F i侧的用户标识或在 WiMAX侧的用户标识, 为所 述用户终端分配家乡代理, 以使得所述 WIF才艮据所述家乡代理的地址从所述 家乡代理获取所述用户终端的家乡地址。 家乡代理响应消息发送单元 73 ,用于将所述家乡代理地址分配单元 72为 所述用户终端分配的家乡代理的地址携带在家乡代理响应消息中发送给所述 WIF。
如图 8所示, 所述家乡代理地址分配单元 72包括: 家乡代理地址分配模 块 721和标识获取模块 722。
家乡代理地址分配模块 721 , 用于在所述家乡代理请求消息接收单元 71 接收到的家乡代理请求消息中包括所述用户终端在 WiMAX侧的用户标识时, 才艮据所述用户终端在 WiMAX侧的用户标识为所述用户终端分配家乡代理; 标识获取模块 722 , 用于在所述家乡代理请求消息接收单元 71接收到的 所述家乡代理请求消息中包括所述用户终端在 WiFi侧的用户标识时, 根据所 述用户终端在 WiFi网络和 WiMAX网络的签约关联关系, 获取所述用户终端在 WiMAX侧的终端用户标识; 所述家乡代理地址分配模块 721还用于, 根据所述 标识获取模块 722获取的用户终端在 WiMAX侧的用户标识为所述用户终端分 配家乡代理。
如图 8所示, 该 WiMAX AAA还包括: 签约关联关系获取单元 74和鉴权认 证检测单元 75
签约关联关系获取单元 74 , 用于在所述标识获取模块 722根据用户终端 在 WiF i网络和 WiMAX网络的签约关联关系, 获取所述用户终端在 WiMAX侧的 用户标识之前, 获取用户终端在 WiF i网络和 WiMAX网络的签约关联关系。 其 中, 由于所述签约关联关系可以存储在 WiMAX AAA, 也可以存储在 WiFi AAA, 因此所述签约关联关系获取单元 74在获取所述签约关联关系时, 可以包括: 当所述签约关联关系存储 WiMAX AAA, 则所述签约关联关系获取单元 74用于 获取所述 WiMAX AAA 自身存储的所述签约关联关系; 当所述约关联关系存储 在 WiFi AAA时, 在 WiFi AAA对所述用户终端鉴权认证成功后, 所述签约关 联关系获取单元 74用于接收所述 WiFi AAA发送的对所述用户终端鉴权认证 的结果以及所述签约关联关系; 所述签约关联关系获取单元 74还用于向所述 WiFi AAA发送鉴权查询请求, 并接收所述 WiFi AAA根据所述鉴权查询请求返 回的所述签约关联关系。 鉴权认证检测单元 75 ,用于在所述家乡代理请求消息接收单元 71接收到 的所述家乡代理请求消息中包括用户终端在 WiFi侧的用户标识和用户终端的 授权令牌时, 所述鉴权认证检测单元 75根据所述用户终端在 WiFi侧的用户 标识和所述用户终端的 4受权令牌检测所述用户终端是否已经通过 WiFi AAA的 鉴权认证; 其中, 在所述鉴权认证检测单元 75检测所述用户终端是否已通过 WiFi AAA的鉴权认证时, 如果在检测所述用户终端是否已经通过 WiFi AAA的 鉴权认证之前, WiMAX AAA从 WiFi AAA获取了所述用户终端已通过鉴权认证 的授权令牌, 则所述检测单元 75根据所述从 WiFi AAA获取的授权令牌查询 所述用户终端是否已经通过 WiFi AAA的鉴权认证; 如果在检测所述用户终端 是否已经通过 WiFi AAA的鉴权认证之前, WiMAX AAA没有从 WiFi AAA获取所 述用户终端已通过鉴权认证的授权令牌, 则所述检测单元 75向所述 WiFi AAA 发送鉴权查询请求消息, 所述鉴权查询请求消息中包括所述用户终端在 WiFi 侧的用户标识和授权令牌, 以便由所述 WiFi AAA根据所述从 WiFi AAA获取 的授权令牌查询所述用户终端是否已经通过 WiFi AAA的鉴权认证。 其中, 所 述根据所述从 WiFi AAA获取的授权令牌查询所述用户终端是否已经通过 WiFi AAA的鉴权认证, 具体可以为, 将所述家乡代理请求消息中包含的授权令牌与 从 WiFi AAA获取的授权令牌进行比较, 若两者一致, 则表明所述用户终端已 经通过 W i F i AAA的鉴权认证。 本发明实施例还提供一种 WIF, 如图 9所示, 该 WIF包括: 第一接收单元
81、 第一发送单元 82、 第二接收单元 83和获取单元 84。
第一接收单元 81 ,用于接收 WiFi接入网发送的获取用户终端家乡代理地 址的家乡代理请求消息, 所述家乡代理请求消息中包含用户终端在 WiFi侧的 用户标识或在 WiMAX侧的用户标识。
第一发送单元 82 , 用于将所述家乡代理请求消息发送给 WiMAX AAA 。 第二接收单元 83 , 用于接收所述 WiMAX AAA发送的家乡代理响应消息, 所述家乡代理响应消息中包含所述 WiMAX AAA根据所述用户终端在 WiMAX侧 的用户标识为所述终端用户分配的家乡代理的地址。
获取单元 84,用于根据所述第二接收单元 83接收到的所述家乡代理的地 址从所述家乡代理获取所述用户终端的家乡地址。 其中, 所述获取单元 84根 据所述第二接收单元 83接收到的所述家乡代理的地址从所述家乡代理获取所 述用户终端的家乡地址可以为: 根据所述家乡代理的地址向所述家乡代理发 送用于移动 IP注册的 MIP注册请求消息, 并接收所述家乡代理发送的 MIP注 册响应消息所述 MIP 注册响应消息中包括所述家乡代理为所述用户终端分配 的家乡地址。
进一步, 在获取所述用户终端的家乡地址后, 将所述家乡地址发送给所 述用户终端。 本发明实施例还提供一种 WiFi接入网,如图 10所示, 该 WiFi接入网包 括: 家乡地址请求消息接收单元 91、判断单元 92和家乡代理请求消息发送单 元 93。
家乡地址请求消息接收单元 91, 用于在用户终端使用 WiFi 签约证书到 WiFi AAA执行鉴权认证并授权后, 接收所述用户终端发送的获取家乡地址的 家乡地址请求消息, 所述家乡地址请求消息中包括 WiMAX 网络标识和所述用 户终端在 WiFi侧的用户标识。 判断单元 92, 用于判断所述用户终端是否已经通过所述 WiFi AAA的鉴权 认证; 其中, 判断单元 92判断所述用户终端是否已经通过 WiFi AAA的鉴权 认证,可以通过检测所述家乡地址请求消息中包含的所述用户在 WiFi侧标识, 与在所述用户终端通过 WiFi AAA的鉴权认证后,由所述 WiFi AAA向所述 WiFi AN发送的所述用户在 WiFi侧标识是否一致实现,若检查到所述家乡地址请求 消息中包含的所述用户在 WiFi侧标识, 与由所述 WiFi AAA向所述 WiFi AN 发送的所述用户在 WiFi侧标识一致, 则表明所述用户终端已经通过 WiFi AAA 的鉴权认证。
家乡代理请求消息发送单元 93,用于在所述判断单元 92判定所述用户终 端已经通过所述 WiF i AAA的鉴权认证时, 向所述 WIF发送获取用户终端家乡 代理地址的家乡代理请求消息, 以使得所述 WIF向所述 WiMAX AAA转发所述 家乡代理请求消息, 所述家乡代理请求消息中包括用户终端在 WiF i侧的用户 标识或在 WiMAX侧的用户标识。 进一步, 所述家乡代理请求消息发送单元 93还用于, 在家乡地址请求消 息接收单元 91 接收到的所述家乡地址请求消息中包括所述用户终端在 WiF i 侧的用户标识和所述用户终端的授权令牌时, 将所述用户终端在 WiF i侧的用 户标识和所述用户终端的授权令牌携带在所述家乡代理请求消息中发送给所 述 WIF , 以使得所述 WIF向所述 WiMAX AAA转发所述家乡代理请求消息。
进一步, 如图 11所示, 该 WiF i接入网还包括签约关联关系检测单元 94 和标识获取单元 95。
签约关联关系检测单元 94 ,用于在所述判断单元 92判定所述用户终端已 通过所述 WiF i AAA的鉴权认证之后, 检测所述 WiF i接入网自身是否存储有 所述用户终端在 WiF i网络和 WiMAX网络的签约关联关系。
标识获取单元 95 ,用于在所述签约关联关系检测单元 94检测到所述 WiF i 接入网中存在所述签约关联关系时, 根据所述 WiF i侧的用户标识, 以及所述 用户终端在 WiF i 网络和 WiMAX 网络的签约关联关系, 获取所述用户终端在
WiMAX侧的用户标识。 所述家乡代理请求消息发送单元 93用于将所述标识获 取单元 95获取的所述用户终端在 WiMAX侧的用户标识携带在获取用户终端家 乡代理地址的家乡代理请求消息中发送给 WIF , 以使得所述 WIF向所述 WiMAX
AAA转发所述家乡代理请求消息。 所述家乡代理请求消息发送单元 93还用于, 在所述签约关联关系检测单 元检测 94到所述 WiF i接入网中不存在所述签约关联关系时, 将所述用户终 端在 WiF i侧的用户标识携带在获取所述用户终端家乡代理地址的家乡代理请 求消息中发送给 WIF , 以使得所述 WIF向所述 WiMAX AAA转发所述家乡代理请 求消息。 本发明实施例还提供一种 WiF i 网络与 WiMAX网络互通的系统, 如图 12 所示, 该系统包括: 互通功能实体 1001和 WiMAX AAA1002 o
互通功能实体 WIF1001 , 用于接收 WiFi接入网发送的获取用户终端家乡 代理地址的家乡代理请求消息, 并将所述家乡代理请求消息发送给 WiMAX
AAA1002 , 所述家乡代理请求消息中包含用户终端在 WiFi 侧的用户标识或在
WiMAX侧的用户标识。
WiMAX AAA1002 , 用于接收 WIF1001发送的所述家乡代理请求消息, 并在 WiFi AAA对所述用户终端的认证 4受权成功后, 才艮据所述用户终端在 WiFi侧的 用户标识或在 WiMAX侧的用户标识为所述用户终端分配家乡代理; 将所述分 配的家乡代理的地址携带在家乡代理响应消息中发送给所述 WIF1001。
所述 WIF1001还用于, 接收所述 WiMAX AAA1002发送的家乡代理响应消 息, 并 居所述家乡代理的地址从所述家乡代理获取所述用户终端的家乡地 址。 本发明实施例中, 当用户终端通过不支持 EAP鉴权认证方式的 WiFi网络 接入时, 在用户通过 WiFi签约证书得到 WiFi AAA成功认证授权后, 所述用 户终端通过互通功能实体向 WiMAX AAA发送请求分配家乡地址的请求消息, WiMAX AAA根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配一 个家乡代理的地址, 并由该家乡代理为所述用户分配一个家乡地址; 由于用 户终端通过支持 EAP鉴权认证方式的 WiMAX网络接入时, 所述 WiMAX AAA同 样根据所述用户终端在 WiMAX侧的用户标识, 为所述用户终端分配同一个家 乡地址, 因此实现了不支持 E AP鉴权认证方式的 W i F i网络和支持 E AP鉴权认 证方式的 WiMAX网络的互通, 使用户终端在不支持 EAP鉴权方式的 WiFi网络 与支持 EAP鉴权方式的 WiMAX网络间进行切换时, 可以保持会话的连续性; 并且上述两种网络的互通是通过为用户终端分配一家乡地址实现的, 没有增 加运营商额外代价。
并且, 本发明实施例中, 在 WiFi AN向 WIF发送家乡地址请求消息之前, WiFi AN检测发送家乡地址请求消息的用户终端是否已经通过 W i F i AAA的鉴 权认证, 在用户终端已经通过 WiFi AAA的鉴权认证后, 向所述 WIF发送家乡 地址请求消息, WiFi AAA和 WiMAX AAA不需使用令牌机制来预防用户终端假 冒, 从而使 WiMAX 网络为用户终端分配家乡地址的过程简单化。
进一步, 本发明实施例中, 在 WiF i AN检测到用户终端已通过 WiF i AAA 的鉴权认证后, 根据获取的签约关联关系, 获取用户终端在 WiMAX侧的用户 标识并发送给 WiMAX AAA, 使所述 WiMAX AAA接收到获取用户终端家乡代理地 址的请求时, 直接根据所述 WiMAX侧的用户标识为用户终端分配相应的家乡 代理, 避免了所述 WiMAX AAA需要对分配家乡代理的用户终端获取 WiMAX侧 的用户标识, 使 WiMAX AAA为用户终端分配家乡地址的过程进一步简单化。
通过以上的实施方式的描述, 所属领域的技术人员可以清楚地了解到本 发明可借助软件加必需的通用硬件的方式来实现, 当然也可以通过硬件, 但 很多情况下前者是更佳的实施方式。 基于这样的理解, 本发明的技术方案本 质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来, 该 计算机软件产品存储在可读取的存储介质中, 如计算机的软盘, 硬盘或光盘 等, 包括若干指令用以使得一台计算机设备(可以是个人计算机, 服务器, 或者网络设备等)执行本发明各个实施例所述的方法。
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局限 于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易 想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护 范围应以所述权利要求的保护范围为准。

Claims

权 利 要求 书
1、 一种 WiFi网络与 WiMAX网络互通的方法, 其特征在于, 包括: 微波存取全球互通认证、授权、计费服务器 WiMAX AAA接收互通功能实体 WIF 发送的获取用户终端家乡代理地址的家乡代理请求消息, 所述家乡代理请求消 息中包括用户终端在无线保真 WiFi侧的用户标识或在 WiMAX侧的用户标识;
在无线保真认证、 授权、 计费服务器 WiFi AAA对所述用户终端的认证授权 成功后, 所述 WiMAX AAA根据所述用户终端在 WiFi侧的用户标识或在 WiMAX侧 的用户标识, 为所述用户终端分配家乡代理;
所述 WiMAX AAA将所述分配的家乡代理的地址携带在家乡代理响应消息中 发送给所述 WIF,以使得所述 WIF才艮据所述家乡代理的地址从所述家乡代理获取 所述用户终端的家乡地址。
2、根据权利要求 1所述的方法,其特征在于,所述根据所述用户终端在 WiFi 侧的用户标识或在 WiMAX侧的用户标识为所述用户终端分配家乡代理包括: 若所述家乡代理请求消息中包括所述用户终端在 WiMAX侧的用户标识, 则 直接根据所述用户终端在 WiMAX侧的用户标识为所述用户终端分配家乡代理; 若所述家乡代理请求消息中包括所述用户终端在 WiFi侧的用户标识, 则根 据所述用户终端在 WiFi网络和 WiMAX网络的签约关联关系, 获取所述用户终端 在 WiMAX侧的用户标识, 并根据所述获取的用户终端在 WiMAX侧的用户标识为 所述用户终端分配家乡代理。
3、 根据权利要求 2所述的方法, 其特征在于, 在根据用户终端在 WiFi 网 络和 WiMAX网络的签约关联关系获取所述用户终端在 WiMAX侧的用户标识之前, 该方法还包括:
获取用户终端在 WiFi网络和 WiMAX网络的签约关联关系。
4、 根据权利要求 3 所述的方法, 其特征在于, 所述获取用户终端在 WiFi 网络和 WiMAX网络的签约关联关系包括:
获取所述 WiMAX AAA自身存储的所述签约关联关系; 或 在 WiFi AAA对所述用户终端鉴权认证成功后,所述 WiMAX AAA接收所述 WiFi AAA发送的对所述用户终端鉴权认证的结果以及所述签约关联关系; 或
所述 WiMAX AAA向所述 WiFi AAA发送鉴权查询请求, 并接收所述 WiFi AAA 根据所述鉴权查询请求返回的所述签约关联关系。
5、 根据权利要求 1所述的方法, 其特征在于, 所述 WIF根据所述家乡代理 的地址从所述家乡代理获取所述用户终端的家乡地址包括:
所述 WIF接收所述 WiMAX AAA发送的家乡代理的地址, 并根据所述家乡代 理的地址, 向所述家乡代理发送用于移动 IP注册的 MIP注册请求消息;
所述 WIF接收所述家乡代理发送的 MIP注册响应消息, 所述 MIP注册响应 消息中包括所述家乡代理为所述用户终端分配的家乡地址。
6、 根据权利要求 1或 5所述的方法, 其特征在于, 在所述 WIF根据所述家 乡代理的地址从所述家乡代理获取所述用户终端的家乡地址之后, 该方法还包 括:
所述 WIF将所述家乡地址发送给所述用户终端。
7、 根据权利要求 1-5任一所述的方法, 其特征在于, 在 WiMAX AAA接收互 通功能实体 WIF发送的获取用户终端家乡代理地址的家乡代理请求消息之前, 该方法还包括:
在 WiFi AAA对所述用户终端的认证授权成功后, WiFi接入网 WiFi AN接收 所述用户终端发送的所述家乡地址请求消息;
WiFi AN判断所述用户终端是否已通过所述 WiFi AAA的鉴权认证, 若是, 则向所述 WIF发送家乡代理请求消息, 所述家乡代理请求消息中包括用户终端 在 WiFi侧的用户标识或在 WiMAX侧的用户标识, 以使得所述 WIF向所述 WiMAX AAA转发所述家乡代理请求消息。
8、 根据权利要求 7所述的方法, 其特征在于, 所述 WiFi AN判断所述用户 终端是否已通过所述 WiFi AAA的鉴权认证, 若是, 则向所述 WIF发送家乡代理 请求消息包括: 所述 W i F i AN判断所述用户终端是否已通过所述 WiF i AAA的鉴权认证, 若 是, 则检测其自身是否存储有所述用户终端在 WiF i网络和 WiMAX网络的签约关 联关系;
若检测到所述 WiF i AN中存储有所述签约关联关系, 则根据所述 WiF i侧的 用户标识, 以及用户终端在 WiF i网络和 WiMAX网络的签约关联关系, 获取所述 用户终端在 WiMAX侧的用户标识, 并将所述用户终端在 WiMAX侧的用户标识携 带在所述家乡代理请求消息中发送给互通功能实体 WIF , 以便由所述 WIF将所述 家乡代理请求消息转发给 WiMAX AAA;
若检测到所述 WiF i AN 中没有存储所述签约关联关系, 将所述用户终端在 WiF i侧的用户标识携带在所述家乡代理请求消息中发送给 WIF , 以便由所述 WIF 将所述家乡代理请求消息转发给 WiMAX AAA。
9、 根据权利要求 1-5任一所述的方法, 其特征在于, 当所述家乡代理请求 消息中包括用户终端在 WiF i 侧的用户标识和用户终端的授权令牌时, 在所述 WiMAX AAA接收互通功能实体 WIF发送的获取用户终端家乡代理地址的家乡代理 请求消息之后, 该方法还包括:
所述 WiMAX AAA根据所述用户终端在 WiF i侧的用户标识和所述用户终端的 授权令牌检测所述用户终端是否已经通过 WiF i AAA的鉴权认证。
10、 根据权利要求 9所述的方法, 其特征在于, 所述 WiMAX AAA根据所述 用户终端在 WiF i侧的用户标识和所述用户终端的授权令牌检测所述用户终端是 否已经通过 W i F i AAA的鉴权认证包括:
若所述 WiF i AAA在对所述用户终端认证 4受权成功时, 将所述用户终端的 4受 权令牌和所述用户终端在 WiF i 侧的用户标识发送给所述 WiMAX AAA , 则所述 WiMAX AAA将所述家乡代理请求消息中的所述用户终端的授权令牌和所述用户终 端在 WiF i侧的用户标识, 与从 WiF i AAA获取的所述用户终端的授权令牌和所 述用户终端在 WiF i 侧的用户标识进行比较, 检测所述用户终端是否已经通过 WiF i AAA的鉴权认证; 若所述 WiF i AAA在对所述用户终端认证授权成功时, 没有将所述用户终端 的授权令牌和所述用户终端在 WiFi侧的用户标识发送给所述 WiMAX AAA, 则所 述 WiMAX AAA向所述 WiFi AAA发送鉴权查询请求消息, 所述鉴权查询请求消息 中包括所述家乡代理请求消息中的所述用户终端的授权令牌和所述用户终端在 WiFi侧的用户标识, 以便所述 WiFi AAA根据所述家乡代理请求消息中的所述用 户终端的授权令牌和所述用户终端在 WiFi侧的用户标识, 检测所述用户终端是 否已经通过 WiFi AAA的鉴权认证, 所述 WiMAX AAA获取所述 WiFi AAA的检测 结果。
11、 一种 WiFi网络与 WiMAX网络互通的方法, 其特征在于, 包括: 在用户终端使用 WiFi签约证书到 WiFi AAA执行鉴权认证后, 接收所述用 户终端发送的获取家乡地址的家乡地址请求消息, 所述家乡地址请求消息中包 括所述用户终端在 WiFi侧的用户标识;
判断所述用户终端是否已通过所述 WiFi AAA的鉴权认证, 若是, 则向所述 WIF发送获取用户终端家乡代理地址的家乡代理请求消息,所述家乡代理请求消 息中包括用户终端在 WiFi侧的用户标识或在 WiMAX侧的用户标识, 以使得所述 WIF向所述 WiMAX AAA转发所述家乡代理请求消息。
12、 一种 WiMAX AAA, 其特征在于, 包括:
家乡代理请求消息接收单元, 用于接收互通功能实体 WIF发送的获取用户 终端家乡代理地址的家乡代理请求消息, 所述家乡代理请求消息中包括用户终 端在 WiFi侧的用户标识或在 WiMAX侧的用户标识;
家乡代理地址分配单元, 用于在 WiFi AAA对所述用户终端的认证授权成功 后, 根据所述家乡代理请求消息接收单元接收到的所述用户终端在 WiFi侧的用 户标识或在 W iMAX侧的用户标识, 为所述用户终端分配家乡代理;
家乡代理响应消息发送单元, 用于将所述家乡代理地址分配单元为所述用 户终端分配的家乡代理的地址携带在家乡代理响应消息中发送给所述 WIF,以使 得所述 WIF才艮据所述家乡代理的地址从所述家乡代理获取所述用户终端的家乡 地址。
13、 根据权利要求 12所述的 WiMAX AAA, 其特征在于, 所述家乡代理地址 分配单元包括:
家乡代理地址分配模块, 用于在所述家乡代理请求消息接收单元接收到的 家乡代理请求消息中包括所述用户终端在 WiMAX侧的用户标识时, 直接根据所 述用户终端在 WiMAX侧的用户标识为所述用户终端分配家乡代理;
标识获取模块, 用于在所述家乡代理请求消息接收单元接收到的所述家乡 代理请求消息中包括所述用户终端在 WiFi侧的用户标识时, 根据所述用户终端 在 WiF i网络和 WiMAX网络的签约关联关系获取所述用户终端在 WiMAX侧的用户 标识;
所述家乡代理地址分配模块还用于, 根据所述标识获取模块获取的用户终 端在 WiMAX侧的用户标识为所述用户终端分配家乡代理。
14、 根据权利要求 12所述的 WiMAX AAA, 其特征在于, 该 WiMAX AAA还包 括:
签约关联关系获取单元, 用于在所述标识获取模块根据用户终端在 WiFi网 络和 WiMAX网络的签约关联关系获取所述用户终端在 WiMAX侧的用户标识之前, 获取用户终端在 WiFi网络和 WiMAX网络的签约关联关系。
15、 根据权利要求 14所述的 WiMAX AAA, 其特征在于,
所述签约关联关系获取单元具体用于获取所述 WiMAX AAA 自身存储的所述 签约关联关系; 或
所述签约关联关系获取单元具体用于在 WiFi AAA对所述用户终端鉴权认证 成功后, 接收所述 WiFi AAA发送的对所述用户终端鉴权认证的结果以及所述签 约关联关系; 或
所述签约关联关系获取单元具体用于向所述 WiF i AAA发送鉴权查询请求, 并接收所述 WiF i AAA根据所述鉴权查询请求返回的所述签约关联关系。
16、 根据权利要求 12所述的 WiMAX AAA, 其特征在于, 该 WiMAX AAA还包 括:
鉴权认证检测单元, 用于当所述家乡代理请求消息接收单元接收到的所述 家乡代理请求消息中包括用户终端在 WiFi侧的用户标识和用户终端的授权令牌 时, 居所述用户终端在 WiF i侧的用户标识和所述用户终端的 4受权令牌检测所 述用户终端是否已经通过 WiFi AAA的鉴权认证。
17、 一种 WiFi接入网, 其特征在于, 包括:
家乡地址请求消息接收单元, 用于在用户终端使用 WiFi 签约证书到 WiFi AAA执行鉴权认证并授权后,接收所述用户终端发送的获取家乡地址的家乡地址 请求消息, 所述家乡地址请求消息中包括所述用户终端在 WiFi侧的用户标识; 判断单元,用于判断所述用户终端是否已经通过所述 WiFi AAA的鉴权认证; 家乡代理请求消息发送单元, 用于在所述判断单元判定所述用户终端已经 通过所述 WiFi AAA的鉴权认证时, 向所述 WIF发送获取用户终端家乡代理地址 的家乡代理请求消息, 所述家乡代理请求消息中包括用户终端在 WiFi侧的用户 标识或在 WiMAX侧的用户标识。
18、 根据权利要求 17所述 WiFi接入网, 其特征在于, 还包括:
签约关联关系检测单元, 用于在所述判断单元判定所述用户终端已通过所 述 WiFi AAA的鉴权认证之后, 检测所述 WiFi接入网自身是否存储有所述用户 终端在 WiFi网络和 WiMAX网络的签约关联关系;
标识获取单元, 用于在所述签约关联关系检测单元检测到所述 WiFi接入网 中存在所述签约关联关系时, 根据所述 WiFi侧的用户标识, 以及所述用户终端 在 WiFi网络和 WiMAX网络的签约关联关系, 获取所述用户终端在 WiMAX侧的用 户标识; 终端在 WiMAX侧的用户标识携带在获取用户终端家乡代理地址的家乡代理请求 消息中发送给 WIF;
所述家乡代理请求消息发送单元还用于, 在所述签约关联关系检测单元检 测到所述 WiFi 接入网中不存在所述签约关联关系时, 将所述用户终端在 WiFi 侧的用户标识携带在获取所述用户终端家乡代理地址的家乡代理请求消息中发 送给 WIF。
19、 根据权利要求 17所述的 WiFi接入网, 其特征在于,
所述家乡代理请求消息发送单元还用于, 在所述家乡地址请求消息中包括 所述用户终端在 WiFi侧的用户标识和所述用户终端的 4受权令牌时, 将所述用户 终端在 WiFi侧的用户标识和所述用户终端的授权令牌携带在所述家乡代理请求 消息中发送给所述 WIF, 以使得所述 WIF向所述 WiMAX AAA转发所述家乡代理请 求消息。
20、 一种网络与 WiMAX网络互通的系统, 其特征在于, 包括:
互通功能实体 WIF , 用于接收 WiFi接入网发送的获取用户终端家乡代理地 址的家乡代理请求消息, 并将所述家乡代理请求消息发送给 WiMAX AAA, 所述家 乡代理请求消息中包含用户终端在 WiF i 侧的用户标识或在 WiMAX侧的用户标 识;
WiMAX AAA, 用于接收 WIF发送的所述家乡代理请求消息, 并在 WiFi AAA 对所述用户终端的认证 4受权成功后, 居所述用户终端在 WiFi侧的用户标识或 在 WiMAX侧的用户标识为所述用户终端分配家乡代理; 将所述分配的家乡代理 的地址携带在家乡代理响应消息中发送给所述 WIF;
所述 WIF还用于, 接收所述 WiMAX AAA发送的家乡代理响应消息, 并根据 所述家乡代理的地址从所述家乡代理获取所述用户终端的家乡地址。
PCT/CN2010/072180 2010-04-26 2010-04-26 Wifi网络与wimax网络互通的方法、装置及系统 WO2011134134A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201080001608.6A CN102308622B (zh) 2010-04-26 2010-04-26 WiFi网络与WiMAX网络互通的方法、装置及系统
PCT/CN2010/072180 WO2011134134A1 (zh) 2010-04-26 2010-04-26 Wifi网络与wimax网络互通的方法、装置及系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2010/072180 WO2011134134A1 (zh) 2010-04-26 2010-04-26 Wifi网络与wimax网络互通的方法、装置及系统

Publications (1)

Publication Number Publication Date
WO2011134134A1 true WO2011134134A1 (zh) 2011-11-03

Family

ID=44860748

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/072180 WO2011134134A1 (zh) 2010-04-26 2010-04-26 Wifi网络与wimax网络互通的方法、装置及系统

Country Status (2)

Country Link
CN (1) CN102308622B (zh)
WO (1) WO2011134134A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100056A (zh) * 2015-06-05 2015-11-25 北京奇虎科技有限公司 应用数据处理方法与系统

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103813330A (zh) 2012-11-15 2014-05-21 中兴通讯股份有限公司 一种通信终端、系统以及权限管理方法
EP2749329A1 (en) * 2012-12-26 2014-07-02 Disney Enterprises, Inc. Linking token detection at a single computing platform with a user identification to unlock content and/or effectuate modifications in virtual space instances presented via multiple computing platforms
US8909920B2 (en) 2012-12-26 2014-12-09 Disney Enterprises, Inc. Linking token detection at a single computing platform with a user identification to effectuate modifications in virtual space instances presented via multiple computing platforms

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101075870A (zh) * 2006-05-16 2007-11-21 华为技术有限公司 一种移动ip密钥的产生及分发方法
CN101662757A (zh) * 2009-06-30 2010-03-03 华为技术有限公司 一种用户接入控制方法、家庭基站网关及系统

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101447978B (zh) * 2008-02-20 2012-09-05 中兴通讯股份有限公司 在WiMAX网络中拜访AAA服务器获取正确的HA-RK Context的方法
CN101516092B (zh) * 2009-03-31 2010-09-29 华为技术有限公司 一种WiMAX网络的认证方法和装置

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101075870A (zh) * 2006-05-16 2007-11-21 华为技术有限公司 一种移动ip密钥的产生及分发方法
CN101662757A (zh) * 2009-06-30 2010-03-03 华为技术有限公司 一种用户接入控制方法、家庭基站网关及系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100056A (zh) * 2015-06-05 2015-11-25 北京奇虎科技有限公司 应用数据处理方法与系统

Also Published As

Publication number Publication date
CN102308622B (zh) 2013-10-02
CN102308622A (zh) 2012-01-04

Similar Documents

Publication Publication Date Title
CN110800331B (zh) 网络验证方法、相关设备及系统
JP6117441B2 (ja) 初期リンクセットアップの間の低減された待ち時間のためのシステムおよび方法
KR100442594B1 (ko) 무선통신 시스템의 패킷 데이터 서비스 방법 및 장치
US20080295154A1 (en) Method and system for managing mobility of access terminal using proxy mobile internet protocol in a mobile communication system, and method for allocating home address of access terminal for the same
WO2007106620A2 (en) Method for authenticating a mobile node in a communication network
TWI516151B (zh) 通訊方法與通訊系統
WO2010000157A1 (zh) 接入设备的配置方法、装置及系统
EP3226594B1 (en) Method, device and system for obtaining local domain name
WO2011134134A1 (zh) Wifi网络与wimax网络互通的方法、装置及系统
WO2014079265A1 (zh) 释放ip地址的方法、装置及接入设备
WO2015100874A1 (zh) 家庭网关接入管理方法和系统
WO2014201783A1 (zh) 一种自组网的加密鉴权方法、系统及终端
WO2014047923A1 (zh) 接入网络的方法和装置
JP4371250B1 (ja) 通信システム、サーバ装置、情報通知方法、プログラム
TW201134147A (en) WiFi and WiMAX internetworking
KR20050060638A (ko) 휴대 인터넷 망에서의 인터넷 프로토콜 주소 관리 장치 및그 방법
CN108540493B (zh) 认证方法、用户设备、网络实体以及业务侧服务器
KR101588646B1 (ko) 무선통신시스템의 인증 방법 및 시스템
KR20050053145A (ko) 무선 패킷 데이터 시스템 및 이 시스템에서의 망간 로밍사용자에 대한 동적 dns 갱신 방법
KR100625926B1 (ko) 인증기능이 개선된 ccoa 방식의 이동 ip 제공 방법및 그 시스템
KR100687721B1 (ko) 모바일 IPv 6를 지원하는 다이아미터 AAA프로토콜의 확장 방법
WO2013026294A1 (zh) 标识网中获取位置信息的方法和接入服务路由器
KR100667699B1 (ko) 휴대 인터넷 시스템의 dhcp 릴레이 장치 및 그방법과, 그 장치를 포함하는 패킷 접속 라우터
KR100461538B1 (ko) 다이어메터 서버에 의한 동적 아이피 주소 할당/해제 방법
JP4371249B1 (ja) 通信システム、サーバ装置、情報通知方法、プログラム

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201080001608.6

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10850467

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10850467

Country of ref document: EP

Kind code of ref document: A1