WO2012152185A1 - 一种选择网关的方法及装置 - Google Patents

一种选择网关的方法及装置 Download PDF

Info

Publication number
WO2012152185A1
WO2012152185A1 PCT/CN2012/074666 CN2012074666W WO2012152185A1 WO 2012152185 A1 WO2012152185 A1 WO 2012152185A1 CN 2012074666 W CN2012074666 W CN 2012074666W WO 2012152185 A1 WO2012152185 A1 WO 2012152185A1
Authority
WO
WIPO (PCT)
Prior art keywords
user equipment
gateway
information
epdg
ikev2
Prior art date
Application number
PCT/CN2012/074666
Other languages
English (en)
French (fr)
Inventor
周星月
朱春晖
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2012152185A1 publication Critical patent/WO2012152185A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W36/00Hand-off or reselection arrangements
    • H04W36/12Reselecting a serving backbone network switching or routing node
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0433Key management protocols

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method and an apparatus for selecting a gateway. Background technique
  • EPS 3rd Generation Partnership Project
  • Evolved Packet System Evolved Packet System
  • E-UTRAN Evolved Universal Terrestrial Radio Access Network
  • MME Mobile Management Unit
  • S-GW Serving Gateway
  • P-GW or PDN GW Packet Data Network Gateway
  • HSS Home Subscriber Server
  • PCRF Policy and Charging Rules Function
  • the EPS system supports interworking with non-3GPP systems.
  • the interworking with non-3GPP systems is implemented through the S2a/S2b/S2c interface, and the anchor point between the 3GPP and non-3GPP systems is P-GW.
  • Non-3GPP systems are classified into trusted non-3GPP IP access and untrusted non-3GPP IP access.
  • Trusted non-3GPP IP access can be directly connected to the P-GW through the S2a interface; untrusted non-3GPP IP access needs to be connected to the PDN GW through an evolved Packet Data Gateway (ePDG), between the ePDG and the PDN GW
  • ePDG evolved Packet Data Gateway
  • the interface is S2b, S2c provides user plane-related control and mobility support between the UE and the P-GW, and the supported mobility management protocol is dual-stack mobile IPv6 (DSMIPv6, Mobile IPv6 Support for Dual Stack Hosts). And Routers).
  • the MME mobility management unit is responsible for control planes such as mobility management, non-access stratum signaling processing, and user mobility management context management; and the S-GW is an access gateway device connected to the E-UTRAN. Forwarding data between E-UTRAN and P-GW, and responsible for buffering paging waiting data; P-GW is a border gateway between EPS and Packet Data Network (PDN), responsible for PDN access and The function of forwarding data between the EPS and the PDN; the PCRF is a functional entity of the policy and charging rules, which receives the interface Rx and the carrier network association. (IP, Internet Protocol) The service network is connected to obtain service information.
  • IP Internet Protocol
  • the gateway device in the network through the Gx/Gxa/Gxc interface, and is responsible for initiating the establishment of the IP bearer to ensure the service quality of the service data (QoS, Quality). Of Service ) and perform billing control.
  • the UE needs to select an appropriate ePDG before connecting to the Evolved Packet Core (EPC) through the untrusted access system.
  • EPC Evolved Packet Core
  • the current technology UE selects the ePDG in two ways: One is that the UE passes the local configuration information. Look for ePDG, which is to query the ePDG address through DNS. When the UE queries the ePDG address through the DNS, the current PLMN ID is used to form an FQDN as the query request content of the DNS. In this case, the ePDG address in the corresponding PLMN range can be obtained.
  • the selection accuracy of the current ePDG is only guaranteed within one PLMN range, and the distance from the UE may be far away, which may cause problems such as routing detours.
  • the ePDG selected by the UE in Jiangsuzhou is located in Beijing, and the PDN GW is located in Shanghai.
  • the data of the UE located in Jiangsu will be sent to the ePDG in Beijing and then to the PDN GW in Shanghai. It is also possible to have a problem when selecting the PDN GW, because the current PDN GW performs DNS query through the FQDN constructed by the APN, regardless of the location factor.
  • the UE can connect to the wireless core network through the fixed network access system.
  • the network determines whether the fixed network access system is a trusted access network or an untrusted access network.
  • the UE accesses the home gateway (RG, Residential Gateway) through the WiFi access point (WiFiAP), and passes through the AN (Access Note) [eg, digital subscriber line access multiplexing device (DSLAM, Digital Subscriber Line). Access Multiplexer)], Broadband Access Server (BRAS), Broadband Network Gateway (BNG), where the IP address of the UE is assigned by the RG and the IP address of the RG is BRAS/BNG. Allocation, in order to save the address space, the address assigned by the UE may be a private address, in which case the RG performs NAT translation on the IP address of the UE.
  • RG Residential Gateway
  • WiFiAP WiFi access point
  • AN Access Note
  • DSLAM digital subscriber line access multiplexing device
  • BRAS Broadband Access Server
  • BNG Broadband Network Gateway
  • Allocation in order to save the address space, the address assigned by the UE may be a private address, in which case the RG performs NAT translation on the IP address of the UE.
  • the UE accesses through the WiFi AP and accesses the BRAS/BNG through the AN.
  • the IP address of the UE is allocated by BRAS/BNG.
  • the IP address assigned by the BRAS/BNG to the UE or the RG may also be a private IP address, and the BRAS/BNG also performs NAT translation on the IP address of the UE.
  • the technical problem to be solved by the present invention is to provide a method and apparatus for selecting a gateway to avoid the problem of route detour.
  • the present invention uses the following technical solutions:
  • a method of selecting a gateway including:
  • the network element In the process of the user equipment accessing the Evolved Packet Core Network (EPC) and performing the Internet Key Exchange Protocol (IKEv2) interaction, the network element reselects the support device IKEv2 close to the user equipment according to the location information of the user equipment.
  • the gateway of the protocol In the process of the user equipment accessing the Evolved Packet Core Network (EPC) and performing the Internet Key Exchange Protocol (IKEv2) interaction, the network element reselects the support device IKEv2 close to the user equipment according to the location information of the user equipment.
  • the gateway of the protocol The gateway of the protocol.
  • the network element includes a first evolved packet data gateway (ePDG), and the reselected gateway supporting the IKEv2 protocol includes a second ePDG;
  • ePDG evolved packet data gateway
  • the reselected gateway supporting the IKEv2 protocol includes a second ePDG
  • the method further includes: after the network element reselects the gateway supporting the IKEv2 protocol of the user equipment, the first ePDG sends the reselected second to the user equipment, according to the location information of the user equipment, The identifier information of the ePDG and the indication information, where the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second ePDG.
  • the network element includes a first packet data network gateway (PDN GW), and the reselected gateway supporting the IKEv2 protocol includes a second PDN GW;
  • PDN GW packet data network gateway
  • the reselected gateway supporting the IKEv2 protocol includes a second PDN GW;
  • the method further includes: after the network element reselects the gateway supporting the IKEv2 protocol of the user equipment, the first PDN GW sends the reselected to the user equipment, according to the location information of the user equipment, The identifier information of the second PDN GW and the indication information, the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second PDN GW.
  • the network element includes a 3GPP AAA server, and the reselected gateway supporting the IKEv2 protocol includes an ePDG or a PDN GW;
  • the method further includes: after the network element reselects, according to the user equipment location information, the gateway that supports the IKEv2 protocol of the user equipment, the 3GPP AAA server sends the reselected to the current gateway of the user equipment.
  • the identifier information of the gateway after the current gateway of the user equipment receives the identifier information of the reselected gateway, sends the identifier information to the user equipment.
  • the indication information is used to indicate that the user equipment initiates IKEv2 authentication to the reselected gateway.
  • the location information includes any one of the following information:
  • the current local IP address of the user equipment is allocated by the local access network or the ePDG, the IP network segment address to which the current local IP address of the user equipment belongs, and the identifier of the access network where the user equipment is located .
  • the identifier of the access network where the user equipment is located includes any one of the following identifiers:
  • SSID service set identifier
  • An apparatus for selecting a gateway where the device has a pre-configured gateway list, where the gateway list stores location information and a gateway supporting the IKEv2 protocol corresponding to the location indicated by the location information corresponding to the location information
  • the apparatus includes a first unit and a second unit, where: the first unit is configured to: in a process in which a user equipment accesses an evolved packet core network (EPC) and performs an Internet Key Exchange Protocol (IKEv2) interaction, Obtaining location information of the user equipment;
  • EPC evolved packet core network
  • IKEv2 Internet Key Exchange Protocol
  • the second unit is configured to: after the first unit acquires the location information of the user equipment, reselect a gateway supporting the IKEv2 protocol of the user equipment close to the user equipment according to the location information.
  • the device is a first evolved packet data gateway (ePDG), and the reselected gateway supporting the IKEv2 protocol is a second ePDG;
  • ePDG evolved packet data gateway
  • the reselected gateway supporting the IKEv2 protocol is a second ePDG
  • the device further includes a third unit, configured to: after the second unit reselects the gateway supporting the IKEv2 protocol of the user equipment according to the location information, sending a reselection to the user equipment
  • the identifier information of the second ePDG and the indication information where the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second ePDG.
  • the device is a first packet data network gateway (PDN GW), reselected
  • PDN GW packet data network gateway
  • the gateway supporting the IKEv2 protocol is the second PDN GW;
  • the device further includes a third unit, configured to: after the second unit reselects the gateway supporting the IKEv2 protocol of the user equipment according to the location information, sending a reselection to the user equipment
  • the identification information of the second PDN GW and the indication information the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second PDN GW.
  • the device is a 3GPP AAA server, and the reselected gateway supporting the IKEv2 protocol includes an ePDG or a PDN GW;
  • the device further includes a third unit, configured to: after the second unit reselects the gateway supporting the IKEv2 protocol of the user equipment according to the location information, to the current gateway of the user equipment Sending the identifier information of the reselected gateway, so that the current gateway of the user equipment carries the identifier information of the reselected gateway and the indication information in the message sent to the user equipment, where the indication information is used to indicate The user equipment initiates IKEv2 authentication to the reselected gateway.
  • the location information includes any one of the following information:
  • the current local IP address of the user equipment is allocated by the local access network or the ePDG, the IP network segment address to which the current local IP address of the user equipment belongs, and the identifier of the access network where the user equipment is located ;
  • the current local IP address of the user equipment is allocated by the local access network or the ePDG.
  • an appropriate gateway is selected for the user equipment, avoiding the problem of routing detour, improving system performance, and improving the selection precision of the ePDG/PDN GW.
  • 1 is an interworking architecture diagram of an EPS system supporting and a non-3GPP system
  • FIG. 2 is a flow chart of Embodiment 1 of the present invention.
  • Figure 3 is a flow chart of Embodiment 2 of the present invention
  • Figure 4 is a flow chart of Embodiment 3 of the present invention
  • FIG. 5 is a flow chart of Embodiment 4 of the present invention.
  • FIG. 6 is a flow chart of Embodiment 5 of the present invention.
  • Figure 7 is a flow chart of Embodiment 6 of the present invention.
  • Figure 8 is a flow chart showing Embodiment 7 of the present invention.
  • the present invention provides the following technical solutions:
  • the network element with the pre-configured gateway list obtains the location information of the user equipment, and uses the pre-configured gateway list as the user equipment.
  • the gateway supporting the IKEv2 protocol is re-selected, and the gateway list stores location information and a gateway supporting the IKEv2 protocol corresponding to the location indicated by the location information corresponding to the location information.
  • the foregoing network element with a pre-configured gateway list includes an ePDG, and the reselected gateway supporting the IKEv2 protocol includes an ePDG; or
  • the network element with the pre-configured gateway list includes the PDN GW, and the reselected gateway supporting the IKEv2 protocol includes the PDN GW; or
  • the network element with the pre-configured gateway list includes a 3GPP AAA server, and the reselected gateway supporting the IKEv2 protocol includes an ePDG or a PDN GW.
  • the gateway supporting the IKEv2 protocol adjacent to the location indicated by the location information means that the difference between the location of the gateway and the location indicated by the location information is less than a predetermined threshold.
  • the gateway with the smallest difference in location is, that is, optionally, the gateway that supports the IKEv2 protocol closest to the user equipment is reselected for the user equipment according to the gateway list.
  • the ePDG close to the user equipment can be selected for the user equipment according to the current location information of the user equipment.
  • the pre-configured gateway list network element (eg, ePDG or PDN GW) sends identification information of the reselection gateway and the indication to the user equipment.
  • the information is used to indicate that the user equipment initiates IKEv2 authentication to the reselected gateway.
  • the network element with the pre-configured gateway list is a 3GPP AAA server, it first sends the identifier information of the reselected gateway to the current gateway (ePDG or PDN GW) of the user equipment, and the current gateway of the user equipment receives the reselected gateway.
  • the indication information is constructed to instruct the user equipment to initiate IKEv2 authentication to the reselected gateway.
  • the location information includes any one of the following information: the current IP address of the user equipment, the IP network segment address to which the current IP address of the user equipment belongs, and the identifier of the access network where the user equipment is located.
  • the identifier of the access network where the user equipment is located includes any one of the following identifiers: a Service Set Identifier (SSID) of the access network, and identifier information of the macro station where the user equipment is located, where the user equipment is located.
  • SSID Service Set Identifier
  • the geographical location information of the access network for example, the zip code of the area
  • the address information of the access gateway that governs the user equipment for example, the IP address of the BRAS/BNG.
  • the network element with the pre-configured gateway list can obtain the location information of the user equipment through the user equipment or through the access system equipment (for example, the AP, AC of the WLAN access network). If the network element with the pre-configured gateway list is a 3GPP AAA server, then it can be obtained from the BNG or BRAS (see Embodiment 3 and Embodiment 6), and the user equipment location information can also be obtained through the ePDG or PDN GW, ePDG Or the PDN GW may notify the 3GPP AAA server of the location information of the user equipment by using an interaction message with the 3GPP AAA server after acquiring the location information of the user equipment.
  • the network element with the pre-configured gateway list is a 3GPP AAA server, then it can be obtained from the BNG or BRAS (see Embodiment 3 and Embodiment 6), and the user equipment location information can also be obtained through the ePDG or PDN GW, ePDG Or the PDN GW may notify the 3GPP AAA server of
  • the apparatus for implementing the above method should have a pre-configured gateway list, where the gateway list stores location information and a gateway supporting the IKEv2 protocol corresponding to the location indicated by the location information corresponding to the location information, and the apparatus includes the first Unit and second unit, where:
  • the first unit is configured to acquire location information of the user equipment during the process of the user equipment accessing the EPC and performing the IKEv2 interaction;
  • the second unit is configured to: after the first unit acquires the location information of the user equipment, reselect the gateway supporting the IKEv2 protocol for the user equipment according to the gateway list.
  • the device is a first ePDG
  • the reselected gateway supporting the IKEv2 protocol is a second ePDG
  • the device may further include a third unit, configured to: after the second unit selects a gateway supporting the IKEv2 protocol for the user equipment according to the gateway list, send the identifier of the reselected second e PDG to the user equipment.
  • the information and the indication information are used to instruct the user equipment to initiate IKEv2 authentication to the reselected second ePDG.
  • the device is a first PDN GW
  • the reselected gateway supporting the IKEv2 protocol is a second PDN GW.
  • the apparatus may further include: a third unit, configured to: after the second unit selects a gateway supporting the IKEv2 protocol for the user equipment according to the gateway list, send the identifier information of the reselected second PDN GW to the user equipment, and Instructions.
  • a third unit configured to: after the second unit selects a gateway supporting the IKEv2 protocol for the user equipment according to the gateway list, send the identifier information of the reselected second PDN GW to the user equipment, and Instructions.
  • the device is a 3GPP AAA server
  • the reselected gateway supporting the IKEv2 protocol includes an ePDG or a PDN GW.
  • the device may further include a third unit, configured to: after the second unit selects a gateway supporting the IKEv2 protocol for the user equipment according to the gateway list, send the identifier information of the reselected gateway to the current gateway of the user equipment, Transmitting, by the current gateway of the user equipment, the identifier information of the reselected gateway and the indication information in the message sent to the user equipment, where the indication information is used to indicate the user equipment to the reselected gateway Initiate IKEv2 authentication.
  • a third unit configured to: after the second unit selects a gateway supporting the IKEv2 protocol for the user equipment according to the gateway list, send the identifier information of the reselected gateway to the current gateway of the user equipment, Transmitting, by the current gateway of the user equipment, the identifier information of the reselected gateway and the indication information in the message sent to the user equipment, where the indication information is used to indicate the user equipment to the reselected gateway Initiate IKEv2 authentication.
  • a method of selecting a gateway including:
  • the network element reselects the user equipment to support the user equipment according to the location information of the user equipment.
  • the gateway of the IKEv2 protocol The gateway of the IKEv2 protocol.
  • the network element includes a first evolved packet data gateway (ePDG), and the reselected gateway supporting the IKEv2 protocol includes a second ePDG;
  • ePDG evolved packet data gateway
  • the reselected gateway supporting the IKEv2 protocol includes a second ePDG
  • the method further includes: after the network element reselects the gateway supporting the IKEv2 protocol of the user equipment, the first ePDG sends the reselected second to the user equipment, according to the location information of the user equipment, The identifier information of the ePDG and the indication information, where the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second ePDG.
  • the network element includes a first packet data network gateway (PDN GW), and is reselected.
  • the gateway supporting the IKEv2 protocol includes a second PDN GW;
  • the method further includes: after the network element reselects the gateway supporting the IKEv2 protocol of the user equipment, the first PDN GW sends the reselected to the user equipment, according to the location information of the user equipment, The identifier information of the second PDN GW and the indication information, the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second PDN GW.
  • the network element includes a 3GPP AAA server, and the reselected gateway supporting the IKEv2 protocol includes an ePDG or a PDN GW;
  • the method further includes: after the network element reselects, according to the user equipment location information, the gateway that supports the IKEv2 protocol of the user equipment, the 3GPP AAA server sends the reselected to the current gateway of the user equipment.
  • the identifier information of the gateway after the current gateway of the user equipment receives the identifier information of the reselected gateway, the identifier information and the indication information of the reselected gateway are carried in the message sent to the user equipment, where The indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected gateway.
  • the location information includes any one of the following information:
  • the current local IP address of the user equipment the IP network segment address to which the current local IP address of the user equipment belongs, and the identifier of the access network where the user equipment is located;
  • the current local IP address of the user equipment is allocated by the local access network or the ePDG.
  • the identifier of the access network where the user equipment is located includes any one of the following identifiers:
  • SSID service set identifier
  • An apparatus for selecting a gateway where the device has a pre-configured gateway list, where the gateway list stores location information and a gateway supporting the IKEv2 protocol corresponding to the location indicated by the location information corresponding to the location information
  • the apparatus includes a first unit and a second unit, where: the first unit is configured to: access the evolved packet core network (EPC), into the user equipment, Obtaining location information of the user equipment during an Internet Key Exchange Protocol (IKEv2) interaction;
  • EPC evolved packet core network
  • IKEv2 Internet Key Exchange Protocol
  • the second unit is configured to: after the first unit acquires the location information of the user equipment, reselect a gateway supporting the IKEv2 protocol of the user equipment close to the user equipment according to the location information.
  • the device is a first evolved packet data gateway (ePDG), and the reselected gateway supporting the IKEv2 protocol is a second ePDG;
  • ePDG evolved packet data gateway
  • the reselected gateway supporting the IKEv2 protocol is a second ePDG
  • the device further includes a third unit, configured to: after the second unit reselects the gateway supporting the IKEv2 protocol of the user equipment according to the location information, sending a reselection to the user equipment
  • the identifier information of the second ePDG and the indication information where the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second ePDG.
  • the device is a first packet data network gateway (PDN GW), and the reselected gateway supporting the IKEv2 protocol is a second PDN GW;
  • PDN GW packet data network gateway
  • the reselected gateway supporting the IKEv2 protocol is a second PDN GW;
  • the device further includes a third unit, configured to: after the second unit reselects the gateway supporting the IKEv2 protocol of the user equipment according to the location information, sending a reselection to the user equipment
  • the identification information of the second PDN GW and the indication information the indication information is used to instruct the user equipment to initiate IKEv2 authentication to the reselected second PDN GW.
  • the device is a 3GPP AAA server, and the reselected gateway supporting the IKEv2 protocol includes an ePDG or a PDN GW;
  • the device further includes a third unit, configured to: after the second unit reselects the gateway supporting the IKEv2 protocol of the user equipment according to the location information, to the current gateway of the user equipment Sending the identifier information of the reselected gateway, so that the current gateway of the user equipment carries the identifier information of the reselected gateway and the indication information in the message sent to the user equipment, where the indication information is used to indicate The user equipment initiates IKEv2 authentication to the reselected gateway.
  • the location information includes any one of the following information:
  • the current local IP address of the user equipment where the current local IP address of the user equipment belongs IP network segment address, the identifier of the access network where the user equipment is located;
  • the current local IP address of the user equipment is allocated by the local access network or the ePDG.
  • the UE first establishes an IKEv2 security association with the ePDG to complete the establishment of the IPSec tunnel, thereby ensuring that IKEv2 is defined in the IETF when traversing the untrusted access system.
  • Redirect Mechanism for the IKEv2 RFC5685 which can be implemented in the IKE SA INIT (Internet Key Exchange Protocol Security Association Initialization), IKE-AUTH (Internet Key Exchange Authentication) process or after the IKEv2 session is established. Redirection of IKEv2 Server.
  • the ePDG redirects the UE to another ePDG.
  • it can be regarded as a PDN GW (HA) to redirect the UE to another PDN GW (HA).
  • the UE is connected to the EPC through an untrusted non-3GPP access system, in which the UE and the evolved packet data gateway (ePDG) are in the process of creating an Internet Key Exchange Protocol (IKEv2) tunnel, and the ePDG is based on the UE.
  • the IP address of the IP address or the IP network segment address to which the UE belongs to the UE selects a neighboring ePDG, and then the ePDG redirects the UE to the corresponding ePDG through the IKEv2 redirection mechanism.
  • Step 201 The UE is connected to the non-3GPP access system, and optionally performs the authentication authorization of the non-3GPP access.
  • the 3GPP AAA server may send the related policy information and the subscription information of the operator to the access network.
  • Step 202 The UE and the ePDG exchange the first pair of messages.
  • the IKE-SA-INIT negotiates an encryption algorithm, performs exchange of random numbers, and the like.
  • Step 203 The UE performs the interaction of the identity authentication information by using the ePDG and the AAA server.
  • Step 204 The UE sends an Internet Key Exchange Authentication (IKE_AUTH) request message including the EAP message to the ePDG, and receives the response during the identity authentication interaction. Certification challenge;
  • Step 205 The ePDG selects a neighboring ePDG for the UE according to the IP address of the UE or the IP network segment address to which the IP address of the UE belongs and the pre-configured gateway list.
  • IKE_AUTH Internet Key Exchange Authentication
  • the selected ePDG is the current ePDG, you do not need to perform redirection and continue to execute according to the normal process.
  • the pre-configured gateway list on the ePDG includes at least the IP address and the identifier information of the ePDG corresponding to the IP addresses corresponding to the IP addresses; if the IP address according to the IP address of the UE is specified If the network segment selects a new gateway, the pre-configured gateway list on the ePDG includes at least the IP network segment information and the identifier information of the ePDG corresponding to the network segment corresponding to each IP network segment. If the basis for selecting the new gateway is not specified, the ePDG is configured.
  • a gateway list including the IP address, the IP network segment information, and the ePDG identification information may be configured to ensure that the ePDG can be selected for the user equipment according to any obtained information.
  • the ePDG that is close to the IP address or close to the IP network segment is preferably the ePDG that is closest to the IP address or the IP network segment. If there are multiple gateways with the closest distance, the ePDG may be selected by polling or randomly selected. Way to choose.
  • Step 206 The ePDG sends an Internet Key Exchange Authentication (IKE AUTH) response message to the UE through IKEv2.
  • IKE-AUTH response message includes carrying the redirect indication information (REDIRECT) New_GW_ID, Ni_data, and new ePDG identity information. It can be an IPv4 or IPv6 address of the ePDG or a Fully Qualified Domain Name (FQDN).
  • Step 207 The UE initiates an IKEv2 authentication to the new ePDG according to the redirection indication information to establish an IPSec (IP Security) tunnel.
  • IPSec IP Security
  • the UE is connected to the EPC through an untrusted non-3GPP access system.
  • the UE and the evolved packet data gateway (ePDG) are in the process of creating an Internet Key Exchange Protocol (IKEv2) tunnel, and the ePDG is based on the UE.
  • IKEv2 Internet Key Exchange Protocol
  • the provided location related information selects a neighboring ePDG for the UE, and then the ePDG redirects the UE to the corresponding ePDG through the IKEv2 redirection mechanism.
  • Step 301 The UE is connected to the non-3GPP access system, and optionally performs the authentication and authorization of the non-3GPP access.
  • the 3GPP AAA server may check the relevant policy information of the operator. The information is sent to the access network;
  • Step 302 The UE and the ePDG exchange the first pair of messages.
  • the IKE-SA-INIT negotiates an encryption algorithm, performs exchange of random numbers, and the like;
  • Step 303 The UE performs the interaction of the identity authentication information by using the ePDG and the AAA server.
  • EAP Extensible Authentication Protocol
  • the Internet Key Exchange Authentication (IKE-AUTH) request message of the message is sent to the ePDG in response to the authentication challenge received during the identity authentication interaction, and the UE includes the identity information of the access network as the location information in the message.
  • IKE-AUTH Internet Key Exchange Authentication
  • the foregoing access network identification information includes, but is not limited to, a macro base station identifier corresponding to the area where the UE is located, or an SSID of the WLAN network, or a zip code of the area, and how the UE obtains location-related information. .
  • Step 305 The ePDG selects a neighboring ePDG for the UE according to the location information provided by the UE and the pre-configured gateway list.
  • the pre-configured gateway list on the ePDG includes location information provided by the UE and identifier information of the ePDG adjacent to the location indicated by the location information.
  • the gateway list may be configured according to the content of the location information that is specified by the user equipment, or a large-capacity gateway list may be configured, and the user equipment may select the location information regardless of the location information sent by the user equipment. To the close ePDG.
  • Step 306 The ePDG sends an Internet Key Exchange Authentication (IKE AUTH) response message to the UE through IKEv2.
  • IKE-AUTH response message includes carrying the redirect indication information (REDIRECT) New_GW_ID, Ni_data, and new ePDG identity information.
  • REDIRECT redirect indication information
  • New_GW_ID the redirect indication information
  • Ni_data the redirect indication information
  • new ePDG identity information can be an IPv4 or IPv6 address of the ePDG, or an FQDN;
  • Step 307 The UE initiates IKEv2 authentication to establish a IPSec tunnel to the new ePDG according to the redirection indication information.
  • the ePDG may also obtain location related information of the UE from a network side (such as a 3GPP AAA server).
  • a network side such as a 3GPP AAA server.
  • the UE is connected to the non-3GPP access system to perform the authentication authorization for the non-3GPP access, and the non-3GPP access network may report the location information of the access network where the UE is located to the non-3GPP AAA server.
  • FIG. 4 is a flow chart of the user equipment connecting to the EPC to obtain ePDG information through the WLAN access system.
  • the figure shows the WLAN system's WiFi AP/Access Controller (AC, Access Controller), RG, and access to BRAS/BNG and other major equipment network elements.
  • This embodiment assumes that the BRAS/BNG in the WLAN access system acts as an authentication network element of the non-3GPP access system.
  • the specific process is as follows.
  • Step 401 The user equipment establishes a wireless connection to the WLAN access system, establishes a three-layer connection, and the BRAS/BNG allocates an IP address to the user equipment.
  • Step 402 The UE performs authentication for non-3GPP access through the WLAN access system.
  • the 3GPP AAA server may send the relevant policy information and subscription information of the operator to the BRAS/BNG, and the 3GPP AAA Server may also BNG or BRAS (abbreviated as BNG/BRAS) obtains location information of the access system where the UE is located;
  • BNG/BRAS BNG or BRAS
  • Step 403 The UE and the ePDG exchange the first pair of messages.
  • the IKE-SA-INIT negotiates an encryption algorithm, performs exchange of random numbers, and the like;
  • Step 404 The UE performs the interaction of the identity authentication information by using the ePDG and the AAA server.
  • IKE AUTH Internet Key Exchange Authentication
  • Step 406 The ePDG sends an EAP-Response response message (with AKA challenge information) to the 3GPP AAA server.
  • Step 407 The 3GPP AAA server selects a neighboring ePDG for the UE according to the location information of the access system where the current UE is located and the pre-configured gateway list.
  • the pre-configured gateway list on the 3GPP AAA includes the location information provided by the UE and the identifier information of the ePDG adjacent to the location indicated by the location information, preferably the closest ePDG.
  • Step 408 The 3GPP AAA server returns an authentication response to the ePDG, where the authentication response carries the identifier information of the selected ePDG, for example, an IPv4 or IPv6 address of the ePDG, or an FQDN.
  • Step 409 The ePDG sends an Internet Key Exchange Authentication (IKE AUTH) to the UE through IKEv2.
  • IKE AUTH response message includes carrying the redirect indication information (REDIRECT) New_GW_ID, Ni_data, and new ePDG identity information received from the 3GPP AAA server; the ePDG determines that the authentication response carries the identifier of the ePDG The information, the configuration redirection indication information is carried in the IKE-AUTH response message, and the new ePDG identification information is also sent to the user equipment through the IKE-AUTH response message.
  • the redirect indication information REDIRECT
  • New_GW_ID N_data
  • new ePDG identity information received from the 3GPP AAA server
  • Step 410 The UE initiates an IKEv2 authentication to the new ePDG according to the redirection indication information to establish an IPSec tunnel.
  • the UE uses the DSMIPv6 dual-stack IPv6 mobility management protocol to pass the trusted non-
  • the 3GPP access system is initially connected to the EPC, and the UE must perform a DSMIPv6 initiation procedure.
  • the UE and the packet data network gateway (PDN GW) are required to create an Internet Key Exchange Protocol (IKEv2) tunnel, and the PDN GW is based on the UE.
  • IKEv2 Internet Key Exchange Protocol
  • the IP address or IP network segment address reselects a PDN GW that is closer to the UE for the UE, and then the PDN GW redirects the UE to the corresponding PDN GW through the IKEv2 redirection mechanism.
  • the PDN GW selection redirection is only applicable to the scenario of the initial attached connection. In the handover scenario, the PDN GW is not used as the connection anchor point for redirection optimization.
  • the specific process is as follows.
  • Step 501 The UE is connected to the non-3GPP access system, and optionally performs the authentication authorization of the non-3GPP access.
  • the 3GPP AAA server may send the related policy information and the subscription information of the operator to the access network.
  • Step 502 The UE obtains the IP address of the local access network, establishes a Layer 3 connection, and selects a PDN GW to be connected according to the DNS query result (a PDN GW with Home Agent function);
  • Step 503 The UE and the PDN GW exchange the first pair of messages.
  • Step 504 The UE performs interaction of identity authentication information by using the PDN GW and the 3GPP AAA server.
  • Step 505 The UE sends an Internet Key Exchange Authentication (IKE_AUTH) request message including an EAP message to the PDN GW, and responds to the authentication challenge received during the identity authentication interaction process;
  • IKE_AUTH Internet Key Exchange Authentication
  • the pre-configured gateway list on the PDN GW includes at least an IP address and identifier information of the PDN GWs corresponding to the IP addresses corresponding to the IP addresses; if the IP address according to the IP address of the UE is specified If the network segment address is selected, the pre-configured gateway list on the PDN GW includes at least the network segment information and the identifier information of the PDN GW corresponding to the network segment corresponding to each IP network segment; if the content according to the selected network is not selected, the PDN GW is configured.
  • a gateway list including the IP address, the network segment information, and the PDN GW identification information may be configured to ensure that a new PDN GW can be selected for all user equipments.
  • Step 507 The PDN GW sends an Internet key exchange authentication to the UE through IKEv2.
  • the IKE-AUTH response message includes carrying redirection indication information ( REDIRECT ) New_GW_ID, Ni_data and new PDN GW identity information, which may be an IPv4 or IPv6 address of the PDN GW, or may be an FQDN of the PDN GW;
  • REDIRECT redirection indication information
  • New_GW_ID N_data
  • new PDN GW identity information which may be an IPv4 or IPv6 address of the PDN GW, or may be an FQDN of the PDN GW;
  • Step 508 The UE initiates IKEv2 authentication and authorization to the new PDN GW according to the redirection indication information to establish an MIPv6 security association.
  • FIG. 6 is a flow chart of the user equipment connecting to the EPC through the WLAN access system using DSMIP as the mobility management protocol.
  • the figure shows the WiFi AP/AC, RG and access to the main device NEs such as BRAS/BNG.
  • This embodiment assumes that the BRAS/BNG in the WLAN access system acts as an authentication network element of the non-3GPP access system.
  • the PDN GW selection redirection is only applicable to the scenario of the initial attached connection. In the handover scenario, the PDN GW is not used as the connection anchor for redirection optimization.
  • the specific process is as follows.
  • Step 601 The UE is connected to the non-3GPP access system, and optionally performs the authentication authorization for the non-3GPP access.
  • the 3GPP AAA server may send the relevant policy information and subscription information of the operator to the access network, BRAS. /BNG assigns a local IP address to the UE;
  • Step 602 The UE performs authentication for non-3GPP access through the WLAN access system.
  • the 3GPP AAA server may send the related policy information and subscription information of the operator to BRAS/BNG;
  • Step 603 The UE initiates an establishment of an SA to the ePDG, and establishes an IPSec tunnel to ensure the security of the packets between the UE and the ePDG.
  • Step 604 The UE sends an Internet Key Exchange Authentication (IKE AUTH) request message including an EAP message to the PDN GW, and responds to the authentication challenge received during the identity authentication interaction, and the UE sets the IP address of the BRAS/BNG or the WLAN network. Location information (such as SSID) is included in the message;
  • IKE AUTH Internet Key Exchange Authentication
  • Step 605 The PDN GW queries the PDN GW that is closest to the UE according to the received location information. If it finds that it is not the closest PDN GW to the UE, it is ready to redirect the UE to the corresponding PDN GW through the IKEv2 redirection function.
  • Step 606 The PDN GW sends an Internet Key Exchange Authentication (IKE AUTH) response message to the UE by using IKEv2.
  • IKE-AUTH response message includes carrying redirection indication information (REDIRECT) New_GW_ID, Ni_data, and new PDN GW identity information, which may be a PDN.
  • REDIRECT redirection indication information
  • New_GW_ID N_data
  • new PDN GW identity information which may be a PDN.
  • the IPv4 or IPv6 address of the GW may also be the FQDN of the PDN GW;
  • Step 607 The UE initiates IKEv2 authentication and authorization to the new PDN GW according to the redirection indication information, so as to establish an MIPv6 security association.
  • FIG. 7 is a flow chart of the user equipment connecting to the EPC through the WLAN access system using DSMIP as the mobility management protocol.
  • the figure shows the WiFi AP/AC, RG and access to the main device NEs such as BRAS/BNG.
  • This embodiment assumes that the BRAS/BNG in the WLAN access system acts as an authentication network element of the non-3GPP access system.
  • the PDN GW selection redirection is only applicable to the scenario of the initial attached connection. In the handover scenario, the PDN GW is not used as the connection anchor for redirection optimization.
  • the specific process is as follows.
  • Step 701 The UE is connected to the non-3GPP access system, and optionally performs the authentication authorization of the non-3GPP access.
  • the 3GPP AAA server may send the relevant policy information and subscription information of the operator to the access network, BRAS. /BNG assigns a local IP address to the UE;
  • Step 702 The UE performs authentication and authorization for non-3GPP access through the WLAN access system, where The 3GPP AAA server may send the relevant policy information and subscription information of the operator to the BRAS/BNG, and the BRAS/BNG sends the location information of the WLAN access network to the AAA server.
  • Step 703 The UE initiates establishment of a security association to the ePDG, and establishes The IPSec tunnel ensures the security of packets between the UE and the ePDG.
  • Step 704 The UE sends an Internet key exchange authentication including an EAP message to the PDN GW.
  • IKE AUTH (IKE AUTH) request message, responding to the authentication challenge received during the identity authentication interaction;
  • Step 705 The PDN GW sends an EAP-Response response message (with AKA challenge information) to the 3GPP AAA server.
  • Step 706 The 3GPP AAA server selects a new PDN GW for the UE according to the location information of the access system where the current UE is located and the pre-configured gateway list.
  • the pre-configured gateway list on the 3GPP AAA server includes location related information of the WLAN where the UE is located and identification information of the PDN GW adjacent to the location.
  • Step 707 The 3GPP AAA server returns an authentication response to the PDN GW, where the authentication response carries the identifier information of the selected new PDN GW, for example, an IPv4 or IPv6 address of the PDN GW, or an FQDN.
  • Step 708 The PDN GW sends an Internet Key Exchange Authentication (IKE AUTH) response message to the UE by using IKEv2.
  • the IKE-AUTH response message includes carrying redirection indication information (REDIRECT) New_GW_ID, Ni_data, and new PDN GW identity information, which may be a PDN.
  • the IPv4 or IPv6 address of the GW may also be the FQDN full domain name of the PDN GW.
  • FIG. 8 is a flow chart of the user equipment connecting to the EPC to obtain ePDG information through the WLAN access system.
  • the figure shows the WiFi AP/AC, RG and access to the main device NEs such as BRAS/BNG.
  • This embodiment assumes that the BRAS/BNG in the WLAN access system acts as an authentication network element of the non-3GPP access system.
  • the specific process is as follows.
  • Step 801 The user equipment establishes a wireless connection to the WLAN access system, and establishes a three-layer connection.
  • BRAS/BNG assigns an IP address to the user equipment;
  • Step 802 The UE performs authentication for non-3GPP access through the WLAN access system, where the 3GPP AAA server may send the relevant policy information and subscription information of the operator to the BRAS/BNG.
  • Step 803 The UE and the ePDG exchange the first pair of messages.
  • the IKE-SA-INIT negotiates an encryption algorithm, performs exchange of random numbers, and the like;
  • Step 804 The UE performs the interaction of the identity authentication information by using the ePDG and the AAA server.
  • the UE sends the IP address of the BRAS/BNG to the ePDG in the message.
  • IKE AUTH Internet Key Exchange Authentication
  • Step 806 The ePDG sends an EAP-Response response message (with AKA challenge information) to the 3GPP AAA server, where the message includes the IP address of the BNG/BRAS in step 805 as the current location information of the UE is sent to the 3GPP AAA server;
  • Step 807 The 3GPP AAA server selects a neighboring ePDG for the UE according to the location information of the access system where the current UE is located and the pre-configured gateway list.
  • the pre-configured gateway list on the 3GPP AAA includes the location information provided by the UE and the identifier information of the ePDG adjacent to the location indicated by the location information, preferably the closest ePDG.
  • Step 808 The 3GPP AAA server returns an authentication response to the ePDG, where the authentication response carries the identifier information of the selected ePDG, for example, an IPv4 or IPv6 address of the ePDG, or an FQDN.
  • Step 809 The ePDG sends an Internet Key Exchange Authentication (IKE AUTH) response message to the UE through IKEv2.
  • the IKE-AUTH response message includes carrying the redirect indication information (REDIRECT) New_GW_ID, Ni_data, and receiving from the 3GPP AAA server.
  • the new ePDG identity information is obtained; the ePDG determines that the authentication response carries the identifier information of the ePDG, and the configuration redirection indication information is carried in the IKE-AUTH response message, and the new ePDG identification information is also passed the IKE AUTH response message. Sent to the user device.
  • Step 810 The UE initiates IKEv2 authentication establishment to the new ePDG according to the redirection indication information. IPSec tunnel.
  • an appropriate gateway is selected for the user equipment, avoiding the problem of routing detour, improving system performance, and improving the selection precision of the ePDG/PDN GW. Therefore, the present invention has a strong industrial applicability.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种选择网关的方法及装置,避免出现路由迂回的问题。所述方法包括:在用户设备接入分组核心网(EPC)、进行因特网密钥交换协议(IKEv2)交互的过程中,具有预配置的网关列表的网元在获取到用户设备的位置信息后,根据所述网关列表为所述用户设备重新选择支持IKEv2协议的网关,所述网关列表中保存有位置信息以及与所述位置信息对应的邻近所述位置信息所指示位置的支持IKEv2协议的网关。通过上述技术方案,为用户设备选择合适的网关,避免出现路由迂回的问题,提高系统性能,提高了分组数据网关(ePDG)/分组数据网络网关(PDNGW)的选择精度。

Description

一种选择网关的方法及装置
技术领域
本发明涉及通信技术领域, 尤其涉及一种选择网关的方法及装置。 背景技术
第三代合作伙伴计划(3GPP, 3rd Generation Partnership Project )演进的 分组系统( EPS , Evolved Packet System ) 由演进的通用移动通信系统陆地无 线接入网( E-UTRAN, Evolved Universal Terrestrial Radio Access Network )、 移动管理单元 ( MME, Mobility Management Entity ) 、 服务网关 ( S-GW, Serving Gateway ) 、 分组数据网络网关 ( P-GW或者 PDN GW, Packet Data Network Gateway), 归属用户服务器(HSS, Home Subscriber Server ) 、 策略 和计费规则功能 (PCRF, Policy and Charging Rules Function ) 实体及其他支 撑节点组成。
如图 1所示, EPS系统支持与非 3GPP系统的互通, 其中, 与非 3GPP 系统的互通通过 S2a/S2b/S2c接口实现, 3GPP与非 3GPP 系统间的锚点为 P-GW。非 3GPP系统被分为可信任非 3GPP IP接入和不可信任非 3GPP IP接 入。 可信任非 3GPP IP接入可直接通过 S2a接口与 P-GW连接; 不可信任非 3GPP IP 接入需经过演进的分组数据网关 (ePDG, Evolved Packet Data Gateway )与 PDN GW相连, ePDG与 PDN GW间的接口为 S2b, S2c提供 了 UE与 P-GW之间的用户面相关的控制和移动性支持, 其支持的移动性管 理协议为支持双栈的移动 IPv6 (DSMIPv6, Mobile IPv6 Support for Dual Stack Hosts and Routers)。
图 1 中, MME移动管理单元负责移动性管理、 非接入层信令的处理和 用户移动管理上下文的管理等控制面的相关工作; S-GW是与 E-UTRAN相 连的接入网关设备, 在 E-UTRAN和 P-GW之间转发数据, 并且负责对寻呼 等待数据进行緩存; P-GW 则是 EPS 与分组数据网络(PDN, Packet Data Network ) 的边界网关, 负责 PDN的接入及在 EPS与 PDN间转发数据等功 能; PCRF是策略和计费规则功能实体, 它通过接收接口 Rx和运营商网络协 议 ( IP , Internet Protocol ) 业务网络相连, 获取业务信息, 此外, 它通过 Gx/Gxa/Gxc接口与网络中的网关设备相连, 负责发起 IP承载的建立, 保证 业务数据的服务质量(QoS, Quality of Service ) , 并进行计费控制。
UE在通过不信任的接入系统连接到演进的分组核心网 (EPC, Evolved Packet Core )需要先选择一个合适的 ePDG, 当前技术 UE选择 ePDG的方式 包括两种: 一种是 UE通过本地配置信息查找 ePDG, —种是通过 DNS查询 ePDG地址。 UE通过 DNS方式查询 ePDG地址时 , 釆用的是当前 PLMN ID 构成一个 FQDN作为 DNS的查询请求内容, 此时可以获得对应 PLMN范围 内的 ePDG地址。 由此可见 , 当前 ePDG的选择精度只保证在一个 PLMN范 围内, 可能相对 UE的距离会很远, 可能会带来路由迂回等问题。 比如, 位 于江苏省的 UE选择的 ePDG位于北京 , 而 PDN GW处于上海, 这样位于江 苏的 UE的数据就要先发往北京的 ePDG再到上海的 PDN GW转发。 同样选 择 PDN GW时也有可能有相关问题,因为当前 PDN GW是通过 APN构造的 FQDN进行 DNS查询, 不考虑位置因素。
在实际网络部署方案中,UE可以通过固网接入系统连接到无线核心网, 在接入认证过程中网络会决定固网接入系统是信任的接入网络还是不信任的 接入网络。 实际部署可能有两种情形:
1、 UE通过 WiFi接入点( WiFiAP, Wireless Fidelity Access Point )接入 家庭网关 (RG, Residential Gateway ) , 通过 AN ( Access Note ) [例如: 数 字用户线接入复用设备( DSLAM , Digital Subscriber Line Access Multiplexer )] , 宽带接入服务器 ( BRAS, Broadband Remote Access Server ) /宽带网络网关 ( BNG, Broadband Network Gateway ) ,此时 UE的 IP地址是由 RG分配的, 而 RG的 IP地址由 BRAS/BNG分配, 为节约地址空间, UE分得的地址可能 是的私有地址, 在此情况下 RG要对 UE的 IP地址进行 NAT转换。
2、 UE通过 WiFi AP接入, 通过 AN接入 BRAS/BNG, 此时 UE的 IP 地址是有 BRAS/BNG分配的。 同样为节约地址空间, BRAS/BNG为 UE或 是 RG分配的 IP地址也可能是私有 IP地址, 此时 BRAS/BNG也对 UE的 IP 地址进行 NAT转换。
在上述两种情形下, 同样存在如前所述的路由迂回问题。 发明内容
本发明要解决的技术问题是提供一种选择网关的方法及装置, 避免出现 路由迂回的问题。
为解决上述技术问题, 本发明釆用如下技术方案:
一种选择网关的方法, 包括:
在用户设备接入演进分组核心网 (EPC ) 、 进行因特网密钥交换协议 ( IKEv2 ) 交互的过程中, 网元根据所述用户设备的位置信息为所述用户设 备重新选择靠近用户设备的支持 IKEv2协议的网关。
可选地, 所述网元包括第一演进的分组数据网关(ePDG ) , 重新选择的 支持 IKEv2协议的网关包括第二 ePDG;
所述方法还包括: 网元根据所述用户设备的位置信息为所述用户设备重 新选择靠近用户设备的支持 IKEv2协议的网关之后, 所述第一 ePDG向所述 用户设备发送重新选择的第二 ePDG的标识信息以及指示信息, 所述指示信 息用于指示所述用户设备向重新选择的第二 ePDG发起 IKEv2认证。
可选地, 所述网元包括第一分组数据网络网关 (PDN GW ) , 重新选择 的支持 IKEv2协议的网关包括第二 PDN GW;
所述方法还包括, 网元根据所述用户设备的位置信息为所述用户设备重 新选择靠近用户设备的支持 IKEv2协议的网关之后, 所述第一 PDN GW向 所述用户设备发送重新选择的第二 PDN GW的标识信息以及指示信息,所述 指示信息用于指示所述用户设备向重新选择的第二 PDN GW发起 IKEv2认 证。
可选地, 所述网元包括 3GPP AAA服务器, 所述重新选择的支持 IKEv2 协议的网关包括 ePDG或者 PDN GW;
所述方法还包括, 网元根据所述用户设备位置信息为所述用户设备重新 选择靠近用户设备的支持 IKEv2协议的网关之后,所述 3GPP AAA服务器向 所述用户设备的当前网关发送重新选择的网关的标识信息, 所述用户设备的 当前网关接收到所述重新选择的网关的标识信息后, 在向所述用户设备发送 的消息中携带所述重新选择的网关的标识信息以及指示信息, 所述指示信息 用于指示所述用户设备向所述重新选择的网关发起 IKEv2认证。
可选地, 所述位置信息包括以下信息中的任意一种:
所述用户设备当前的本地 IP 地址, 该本地 IP 地址由本地接入网或者 ePDG分配,所述用户设备当前本地 IP地址所属的 IP网段地址,所述用户设 备所处的接入网络的标识。
可选地, 所述用户设备所处的接入网络的标识包括以下标识中的任意一 种:
接入网络的服务集标识( SSID ) ,所述用户设备所处的宏站的标识信息, 所述用户设备所处的接入网络的地理位置信息, 管辖所述用户设备的接入网 关的地址信息。
一种选择网关的装置, 所述装置上具有预配置的网关列表, 所述网关列 表中保存有位置信息以及与所述位置信息对应的邻近所述位置信息所指示位 置的支持 IKEv2协议的网关, 所述装置包括第一单元和第二单元, 其中: 所述第一单元设置成: 在用户设备接入演进的分组核心网 (EPC ) 、 进 行因特网密钥交换协议(IKEv2 ) 交互的过程中, 获取所述用户设备的位置 信息;
所述第二单元设置成: 在所述第一单元获取到所述用户设备的所述位置 信息后, 根据所述位置信息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关。
可选地, 所述装置为第一演进的分组数据网关(ePDG ) , 重新选择的支 持 IKEv2协议的网关为第二 ePDG;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备发送重新选择的第二 ePDG的标识信息以及指示信息, 所述指 示信息用于指示所述用户设备向重新选择的第二 ePDG发起 IKEv2认证。
可选地, 所述装置为第一分组数据网络网关 (PDN GW ) , 重新选择的 支持 IKEv2协议的网关为第二 PDN GW;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备发送重新选择的第二 PDN GW的标识信息以及指示信息,所述 指示信息用于指示所述用户设备向重新选择的第二 PDN GW发起 IKEv2认 证。
可选地, 所述装置为 3GPP AAA服务器, 所述重新选择的支持 IKEv2 协议的网关包括 ePDG或者 PDN GW;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备的当前网关发送重新选择的网关的标识信息, 以使所述用户设 备的当前网关在向所述用户设备发送的消息中携带所述重新选择的网关的标 识信息以及指示信息, 所述指示信息用于指示所述用户设备向所述重新选择 的网关发起 IKEv2认证。
可选地, 所述位置信息包括以下信息中的任意一种:
所述用户设备当前的本地 IP 地址, 该本地 IP 地址由本地接入网或者 ePDG分配,所述用户设备当前本地 IP地址所属的 IP网段地址,所述用户设 备所处的接入网络的标识;
其中, 所述用户设备当前的本地 IP地址由本地接入网或者 ePDG分配。
通过上述技术方案, 为用户设备选择合适的网关, 避免出现路由迂回的 问题, 提高系统性能, 提高了 ePDG/PDN GW的选择精度。 附图概述
图 1是 EPS系统支持与非 3GPP系统的互通架构图;
图 2是本发明实施例 1的流程图;
图 3是本发明实施例 2的流程图; 图 4是本发明实施例 3的流程图;
图 5是本发明实施例 4的流程图;
图 6是本发明实施例 5的流程图;
图 7是本发明实施例 6的流程图;
图 8是本发明实施例 7的流程图。
本发明的较佳实施方式
为解决前述技术问题, 本发明提供如下技术方案:
在用户设备接入 EPC、 进行因特网密钥交换协议(IKEv2 ) 交互的过程 中, 具有预配置的网关列表的网元在获取到用户设备的位置信息后, 根据预 配置的网关列表为该用户设备重新选择支持 IKEv2协议的网关, 所述网关列 表中保存有位置信息以及与所述位置信息对应的邻近所述位置信息所指示位 置的支持 IKEv2协议的网关。
上述具有预配置的网关列表的网元包括 ePDG, 重新选择的支持 IKEv2 协议的网关包括 ePDG; 或者
具有预配置的网关列表的网元包括 PDN GW,重新选择的支持 IKEv2协 议的网关包括 PDN GW; 或者
具有预配置的网关列表的网元包括 3GPP AAA服务器,重新选择的支持 IKEv2协议的网关包括 ePDG或者 PDN GW。
上述邻近所述位置信息所指示位置的支持 IKEv2协议的网关是指: 该网 关的位置与该位置信息所指示的位置之差小于一预设的门限值。 优选为位置 之差最小的网关, 也就是说, 可选地, 根据该网关列表为用户设备重新选择 距离该用户设备最近的支持 IKEv2协议的网关。
通过上述方法可以根据用户设备当前的位置信息为该用户设备选择一个 靠近该用户设备的 ePDG。
在为所述用户设备重新选择网关之后,该具有预配置的网关列表网元(例 如 ePDG或 PDN GW )向该用户设备发送重新选择网关的标识信息以及指示 信息, 所述指示信息用于指示所述用户设备向重新选择的网关发起 IKEv2认 证。 当具有预配置的网关列表的网元为 3GPP AAA服务器时, 其先向用户设 备当前的网关 ( ePDG或 PDN GW )发送重新选择的网关的标识信息, 用户 设备当前网关收到该重新选择的网关标识信息后, 构造指示信息, 以指示用 户设备向重新选择的网关发起 IKEv2认证。
上述位置信息包括以下信息中的任意一种: 用户设备当前的 IP地址, 用 户设备当前 IP地址所属的 IP网段地址, 用户设备所处的接入网络的标识。 用户设备所处的接入网络的标识包括以下标识中的任意一种: 接入网络的服 务集标识 (SSID, Service Set Identifier), 用户设备所处的宏站的标识信息, 用户设备所处的接入网络的地理位置信息 (例如所处区域的邮政编码), 管辖 用户设备的接入网关的地址信息 (例如 BRAS/BNG的 IP地址 ) 。
具有预配置的网关列表的网元可通过用户设备或者通过接入系统设备 (例如 WLAN接入网的 AP、 AC )获取到用户设备的位置信息。 如果具有预 配置的网关列表的网元为 3GPP AAA服务器, 那么其除了可以从 BNG或 BRAS处获得 (参见实施例 3和实施例 6 ) , 还可以通过 ePDG或 PDN GW 获取用户设备位置信息, ePDG或 PDN GW可以在自身获取到用户设备的位 置信息后, 通过与 3GPP AAA服务器之间的交互消息, 将用户设备的位置信 息通知给该 3GPP AAA服务器。
实现上述方法的装置上应具有预配置的网关列表, 该网关列表中保存有 位置信息以及与所述位置信息对应的邻近所述位置信息所指示位置的支持 IKEv2协议的网关, 该装置包括第一单元和第二单元, 其中:
所述第一单元设置成:在用户设备接入 EPC、进行 IKEv2交互的过程中, 获取用户设备的位置信息;
所述第二单元设置成: 在所述第一单元获取到用户设备的位置信息后, 根据所述网关列表为所述用户设备重新选择支持 IKEv2协议的网关。
可选地, 该装置为第一 ePDG, 该重新选择的支持 IKEv2协议的网关为 第二 ePDG。 此时, 该装置还可包括一第三单元, 其设置成: 在所述第二单元根据网 关列表为用户设备选择支持 IKEv2协议的网关之后, 向用户设备发送重新选 择的第二 ePDG的标识信息以及指示信息, 该指示信息用于指示所述用户设 备向重新选择的第二 ePDG发起 IKEv2认证。
可选地, 该装置为第一 PDN GW, 该重新选择的支持 IKEv2协议的网关 为第二 PDN GW。
此时, 该装置还可包括一第三单元, 其设置成: 在第二单元根据网关列 表为用户设备选择支持 IKEv2协议的网关之后, 向用户设备发送重新选择的 第二 PDN GW的标识信息以及指示信息。
可选地, 该装置为 3GPP AAA服务器, 该重新选择的支持 IKEv2协议的 网关包括 ePDG或者 PDN GW。
此时, 该装置还可包括一第三单元, 其设置成: 在第二单元根据网关列 表为用户设备选择支持 IKEv2协议的网关之后, 向用户设备的当前网关发送 重新选择的网关的标识信息, 以使所述用户设备的当前网关在向所述用户设 备发送的消息中携带所述重新选择的网关的标识信息以及指示信息, 该指示 信息用于指示所述用户设备向所述重新选择的网关发起 IKEv2认证。
一种选择网关的方法, 包括:
在用户设备接入演进的分组核心网 (EPC ) 、 进行因特网密钥交换协议 ( IKEv2 ) 交互的过程中, 网元根据所述用户设备的位置信息为所述用户设 备重新选择靠近用户设备的支持 IKEv2协议的网关。
可选地, 所述网元包括第一演进的分组数据网关(ePDG ) , 重新选择的 支持 IKEv2协议的网关包括第二 ePDG;
所述方法还包括: 网元根据所述用户设备的位置信息为所述用户设备重 新选择靠近用户设备的支持 IKEv2协议的网关之后, 所述第一 ePDG向所述 用户设备发送重新选择的第二 ePDG的标识信息以及指示信息, 所述指示信 息用于指示所述用户设备向重新选择的第二 ePDG发起 IKEv2认证。
可选地, 所述网元包括第一分组数据网络网关 (PDN GW ) , 重新选择 的支持 IKEv2协议的网关包括第二 PDN GW;
所述方法还包括, 网元根据所述用户设备的位置信息为所述用户设备重 新选择靠近用户设备的支持 IKEv2协议的网关之后, 所述第一 PDN GW向 所述用户设备发送重新选择的第二 PDN GW的标识信息以及指示信息,所述 指示信息用于指示所述用户设备向重新选择的第二 PDN GW发起 IKEv2认 证。
可选地, 所述网元包括 3GPP AAA服务器, 所述重新选择的支持 IKEv2 协议的网关包括 ePDG或者 PDN GW;
所述方法还包括, 网元根据所述用户设备位置信息为所述用户设备重新 选择靠近用户设备的支持 IKEv2协议的网关之后,所述 3GPP AAA服务器向 所述用户设备的当前网关发送重新选择的网关的标识信息, 所述用户设备的 当前网关接收到所述重新选择的网关的标识信息后, 在向所述用户设备发送 的消息中携带所述重新选择的网关的标识信息以及指示信息, 所述指示信息 用于指示所述用户设备向所述重新选择的网关发起 IKEv2认证。
可选地, 所述位置信息包括以下信息中的任意一种:
所述用户设备当前的本地 IP地址, 所述用户设备当前本地 IP地址所属 的 IP网段地址, 所述用户设备所处的接入网络的标识;
其中, 所述用户设备当前的本地 IP地址由本地接入网或者 ePDG分配。 可选地, 所述用户设备所处的接入网络的标识包括以下标识中的任意一 种:
接入网络的服务集标识( SSID ) ,所述用户设备所处的宏站的标识信息, 所述用户设备所处的接入网络的地理位置信息, 管辖所述用户设备的接入网 关的地址信息。
一种选择网关的装置, 所述装置上具有预配置的网关列表, 所述网关列 表中保存有位置信息以及与所述位置信息对应的邻近所述位置信息所指示位 置的支持 IKEv2协议的网关, 所述装置包括第一单元和第二单元, 其中: 所述第一单元设置成: 在用户设备接入演进的分组核心网 (EPC ) 、 进 行因特网密钥交换协议(IKEv2 ) 交互的过程中, 获取所述用户设备的位置 信息;
所述第二单元设置成: 在所述第一单元获取到所述用户设备的所述位置 信息后, 根据所述位置信息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关。
可选地, 所述装置为第一演进的分组数据网关(ePDG ) , 重新选择的支 持 IKEv2协议的网关为第二 ePDG;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备发送重新选择的第二 ePDG的标识信息以及指示信息, 所述指 示信息用于指示所述用户设备向重新选择的第二 ePDG发起 IKEv2认证。
可选地, 所述装置为第一分组数据网络网关 (PDN GW ) , 重新选择的 支持 IKEv2协议的网关为第二 PDN GW;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备发送重新选择的第二 PDN GW的标识信息以及指示信息,所述 指示信息用于指示所述用户设备向重新选择的第二 PDN GW发起 IKEv2认 证。
可选地, 所述装置为 3GPP AAA服务器, 所述重新选择的支持 IKEv2 协议的网关包括 ePDG或者 PDN GW;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备的当前网关发送重新选择的网关的标识信息, 以使所述用户设 备的当前网关在向所述用户设备发送的消息中携带所述重新选择的网关的标 识信息以及指示信息, 所述指示信息用于指示所述用户设备向所述重新选择 的网关发起 IKEv2认证。
可选地, 所述位置信息包括以下信息中的任意一种:
所述用户设备当前的本地 IP地址, 所述用户设备当前本地 IP地址所属 的 IP网段地址 , 所述用户设备所处的接入网络的标识;
其中, 所述用户设备当前的本地 IP地址由本地接入网或者 ePDG分配。
为使本发明的目的、 技术方案和优点更加清楚明白, 下文中将结合附图 对本发明的实施例进行详细说明。 需要说明的是, 在不冲突的情况下, 本申 请中的实施例及实施例中的特征可以相互任意组合。
为完成网关重定向, 当 UE通过非信任的 3GPP接入 EPC时, UE首先 会和 ePDG建立 IKEv2安全联盟完成 IPSec隧道的建立, 从而确保穿越非信 任的接入系统的时候在 IETF 定义了 IKEv2 的重定向机制 ( Redirect Mechanism for the IKEv2 ) RFC5685 , 通过该机制可以在 IKE SA INIT (因 特网密钥交换协议安全联盟初始化 ) , IKE— AUTH (因特网密钥交换认证 )过 程中或者 IKEv2会话建立完成后实现 IKEv2 Server的重定向。 在 3GPP场景 下, 可以看做 ePDG把 UE重定向到另外一个 ePDG; 在 3GPP S2c场景下, 可以看做 PDN GW(HA)把 UE重定向到另外一个 PDN GW(HA)。
实施例 1
如图 2所示, UE通过非信任的非 3GPP接入系统连接到 EPC ,该流程中, UE和演进分组数据网关 (ePDG )在创建因特网密钥交换协议(IKEv2 ) 隧 道过程中, ePDG根据 UE的 IP地址或 UE的 IP地址所属的 IP网段地址为 UE选择一个靠近的 ePDG,接着 ePDG通过 IKEv2重定向机制将 UE重定向 到对应的 ePDG。
步骤 201: UE连接到非 3GPP接入系统, 可选地进行非 3GPP接入的认 证授权, 在此过程中, 3GPP AAA服务器可以将运营商的相关策略信息和签 约信息发送给接入网络;
步骤 202: UE和 ePDG交换第一对消息 IKE— SA— INIT协商加密算法, 进行随机数的交换等。
步骤 203: UE通过 ePDG和 AAA服务器进行的身份认证信息的交互; 步骤 204: UE发送包含 EAP消息的因特网密钥交换认证 ( IKE— AUTH ) 请求消息到 ePDG, 响应身份认证交互过程中收到的认证挑战; 步骤 205: ePDG根据 UE的 IP地址或 UE的 IP地址所属的 IP网段地址 以及预先配置的网关列表为 UE选择一个靠近的 ePDG;
如果所选择的 ePDG即为当前的 ePDG, 则不用再进行重定向, 按正常 流程继续执行即可。
如果规定根据 UE的 IP地址选择新网关, 则 ePDG上预配置的网关列表 至少包括 IP地址以及各 IP地址对应的靠近该些 IP地址的 ePDG的标识信息; 如果规定根据 UE的 IP地址所属的 IP网段选择新网关, 则 ePDG上预配置 的网关列表至少包括 IP网段信息以及每个 IP网段对应的靠近该网段的 ePDG 的标识信息; 如果没有规定选择新网关的依据, 则 ePDG上可以配置包括 IP 地址、 IP网段信息以及 ePDG标识信息三者对应关系的网关列表, 以保证能 根据所获得的任何信息为用户设备选择 ePDG。
上述靠近 IP地址或靠近 IP网段的 ePDG优选为与该 IP地址或 IP网段距 离最近的 ePDG,如果有多个距离最近的网关,则可以通过轮询的方式选择, 或者釆用随机选择的方式进行选择。
步骤 206: ePDG通过 IKEv2向 UE发送因特网密钥交换认证( IKE AUTH ) 响应消息, IKE— AUTH 响应消息包含携带重定向指示信息 (REDIRECT ) New— GW— ID、 Ni— data和新的 ePDG身份信息,可以是 ePDG的 IPv4或 IPv6 地址, 也可以是完全限定域名 (FQDN, Fully Qualified Domain Name ) 。
步骤 207 : UE根据重定向指示信息向新的 ePDG发起 IKEv2认证建立 IPSec ( IP安全 ) 隧道。
实施例 2
如图 3所示, UE通过非信任的非 3GPP接入系统连接到 EPC ,该流程中, UE和演进分组数据网关 (ePDG )在创建因特网密钥交换协议(IKEv2 ) 隧 道过程中, ePDG根据 UE提供的位置相关信息为 UE选择一个靠近的 ePDG, 接着 ePDG通过 IKEv2重定向机制将 UE重定向到对应的 ePDG。
步骤 301: UE连接到非 3GPP接入系统, 可选地进行非 3GPP接入的认 证授权, 在此过程中, 3GPP AAA服务器可以将运营商的相关策略信息和签 约信息发送给接入网络;
步骤 302: UE和 ePDG交换第一对消息 IKE— SA— INIT协商加密算法, 进行随机数的交换等;
步骤 303: UE通过 ePDG和 AAA服务器进行的身份认证信息的交互; 步骤 304 : UE 发送包含可扩展的身份验证协议 (EAP , Extension
Authentication Protocol ) 消息的因特网密钥交换认证( IKE— AUTH )请求消 息到 ePDG, 响应身份认证交互过程中收到的认证挑战, 同时 UE将所处接 入网络的标识信息作为位置信息包含在该消息中;
上述接入网标识信息包含但不限于: UE 所处地区对应的宏基站标识, 或者所处 WLAN网络的 SSID,或者所处区域的邮政编码等, UE如何获得位 置相关信息本发明不#文限制。
步骤 305: ePDG根据 UE提供的位置信息以及预配置的网关列表为 UE 选择一个靠近的 ePDG;
在本实施例中, ePDG上预配置的网关列表包括 UE提供的位置信息以 及与该位置信息所指示位置邻近的 ePDG的标识信息。 如实施例 1中所述, 可以根据规定用户设备发送的位置信息的内容来配置网关列表, 也可以配置 一个大容量网关列表, 不论用户设备发送具体哪种位置信息, 均可为该用户 设备选择到靠近的 ePDG。
步骤 306: ePDG通过 IKEv2向 UE发送因特网密钥交换认证( IKE AUTH ) 响应消息, IKE— AUTH 响应消息包含携带重定向指示信息 (REDIRECT ) New— GW— ID、 Ni— data和新的 ePDG身份信息,可以是 ePDG的 IPv4或 IPv6 地址, 也可以是 FQDN;
步骤 307: UE根据重定向指示信息向新的 ePDG发起 IKEv2认证建立 IPSec隧道。
在其他实施例中, ePDG也可从网络侧(如 3GPPAAA服务器 )获取 UE 的位置相关信息。 例如, 步骤 301 中, UE连接到非 3GPP接入系统进行非 3GPP接入的认证授权的过程中,非 3GPP接入网可以将 UE所处的接入网的 位置信息上报给非 3GPP AAA服务器。 实施例 3
图 4为用户设备通过 WLAN接入系统连接到 EPC获取 ePDG信息的流 程图。 这里图中显示了 WLAN 系统的 WiFi AP/接入控制器 (AC, Access Controller) , RG以及接入 BRAS/BNG等主要设备网元。本实施例假设 WLAN 接入系统中的 BRAS/BNG作为非 3GPP接入系统的认证网元。具体流程如下。
步骤 401:用户设备建立到 WLAN接入系统的无线连接,建立三层连接, BRAS/BNG为用户设备分配 IP地址;
步骤 402: UE通过 WLAN接入系统进行非 3GPP接入的认证授权, 这 里, 3GPP AAA服务器可以将运营商的相关策略信息和签约信息发送给 BRAS/BNG, 3GPP AAA Server在此流程中也可以从 BNG或 BRAS (简写为 BNG/BRAS )处获取 UE所处的接入系统的位置信息;
步骤 403: UE和 ePDG交换第一对消息 IKE— SA— INIT协商加密算法, 进行随机数的交换等;
步骤 404: UE通过 ePDG和 AAA服务器进行的身份认证信息的交互; 步骤 405: UE发送包含 EAP消息的因特网密钥交换认证 ( IKE AUTH ) 请求消息到 ePDG, 响应身份认证交互过程中收到的认证挑战;
步骤 406: ePDG将 EAP-Response响应消息 (带 AKA挑战信息 )发送 给 3GPP AAA服务器;
步骤 407: 3GPP AAA服务器根据当前 UE所处的接入系统的位置信息 以及预配置的网关列表为 UE选择一个靠近的 ePDG;
在本实施例中, 3GPP AAA上预配置的网关列表包括 UE提供的位置信 息以及与该位置信息所指示位置邻近的 ePDG的标识信息, 优选为距离最近 ePDG„
步骤 408, 3GPP AAA服务器向 ePDG返回认证回答, 在该认证回答中 携带所选择的 ePDG的标识信息, 例如可以是 ePDG的 IPv4或 IPv6地址, 也可以是 FQDN;
步骤 409: ePDG通过 IKEv2向 UE发送因特网密钥交换认证( IKE AUTH ) 响应消息, IKE— AUTH 响应消息包含携带重定向指示信息 (REDIRECT ) New— GW— ID、 Ni— data和从 3GPP AAA服务器收到的新的 ePDG身份信息; ePDG判断认证回答中携带有 ePDG的标识信息, 则构造重定向指示信 息携带在 IKE— AUTH响应消息中, 同时还将该新的 ePDG的标识信息通过 IKE— AUTH响应消息发送给用户设备。
步骤 410: UE根据重定向指示信息向新的 ePDG发起 IKEv2认证建立 IPSec隧道。
实施例 4
如图 5所示, UE使用 DSMIPv6双栈 IPv6移动管理协议通过信任的非
3GPP接入系统初始连接到 EPC, UE须执行 DSMIPv6的启动流程, 在该流 程中, UE须和分组数据网络网关 (PDN GW )在创建因特网密钥交换协议 ( IKEv2 )隧道, PDN GW根据 UE的 IP地址或 IP网段地址为 UE重新选择 一个距离 UE更近的 PDN GW, 接着 PDN GW通过 IKEv2重定向机制将 UE 重定向到对应的 PDN GW。 需要说明的是, PDN GW的选择重定向只适用于 初始附着连接的场景, 切换场景下, PDN GW作为连接锚点不会进行重定向 优化。 具体流程如下。
步骤 501: UE连接到非 3GPP接入系统, 可选地进行非 3GPP接入的认 证授权, 在此过程中, 3GPP AAA服务器可以将运营商的相关策略信息和签 约信息发送给接入网络;
步骤 502: UE获取本地接入网的 IP地址, 建立三层连接, 根据 DNS查 询结果选择要连接的 PDN GW (具有 Home Agent功能的 PDN GW ) ;
步骤 503: UE和 PDN GW交换第一对消息 IKE— S A— INIT协商加密算法, 进行随机数的交换等;
步骤 504: UE通过 PDN GW和 3GPP AAA服务器进行的身份认证信息 的交互;
步骤 505: UE向 PDN GW发送包含 EAP消息的因特网密钥交换认证 ( IKE— AUTH )请求消息, 响应身份认证交互过程中收到的认证挑战; 步骤 506: PDN GW根据 UE的 IP地址或 UE的 IP地址所属的 IP网段 地址以及预先配置的网关列表为 UE选择一个靠近的新的 PDN GW;
如果规定根据 UE的 IP地址选择, 则 PDN GW上预配置的网关列表至 少包括 IP地址以及各 IP地址对应的靠近该些 IP地址的 PDN GW的标识信 息; 如果规定根据 UE的 IP地址所属的 IP网段地址选择, 则 PDN GW上预 配置的网关列表至少包括网段信息以及每个 IP 网段对应的靠近该网段的 PDN GW的标识信息; 如果没有选择所依据的内容, 则 PDN GW上可以配 置包括 IP地址、网段信息以及 PDN GW标识信息三者对应关系的网关列表, 以保证能够为所有用户设备选择新的 PDN GW。
步骤 507 : PDN GW 通过 IKEv2 向 UE 发送因特网密钥交换认证
( IKE AUTH ) 响应消息, IKE— AUTH 响应消息包含携带重定向指示信息 ( REDIRECT ) New_GW_ID、 Ni_data和新的 PDN GW身份信息, 可以是 PDN GW的 IPv4或 IPv6地址, 也可以是 PDN GW的 FQDN;
步骤 508: UE根据重定向指示信息向新的 PDN GW发起 IKEv2认证进 行认证授权, 以建立 MIPv6安全联盟。
实施例 5
图 6为用户设备使用 DSMIP作为移动管理协议通过 WLAN接入系统连 接到 EPC的流程图。 这里图中显示了 WLAN系统的 WiFi AP/AC , RG以及 接入 BRAS/BNG 等主要设备网元。 本实施例假设 WLAN接入系统中的 BRAS/BNG作为非 3GPP接入系统的认证网元。 需要说明的是, PDN GW的 选择重定向只适用于初始附着连接的场景, 切换场景下, PDN GW作为连接 锚点不会进行重定向优化。 具体流程如下。
步骤 601: UE连接到非 3GPP接入系统, 可选地进行非 3GPP接入的认 证授权, 在此过程中, 3GPP AAA服务器可以将运营商的相关策略信息和签 约信息发送给接入网络, BRAS/BNG向 UE分配本地 IP地址;
步骤 602: UE通过 WLAN接入系统进行非 3GPP接入的认证授权, 这 里, 3GPP AAA服务器可以将运营商的相关策略信息和签约信息发送给 BRAS/BNG;
步骤 603: UE向 ePDG发起建立安全联盟, 建立 IPSec隧道, 确保 UE 到 ePDG之间的报文的安全;
步骤 604: UE向 PDN GW发送包含 EAP消息的因特网密钥交换认证 ( IKE AUTH )请求消息, 响应身份认证交互过程中收到的认证挑战, UE 将 BRAS/BNG的 IP地址或所处 WLAN网络的位置信息 (例如 SSID ) 包含 在该报文中;
步骤 605: PDN GW根据收到的位置信息查询距离 UE最近的 PDN GW, 如果发现本身不是距离 UE最近的 PDN GW, 则准备通过 IKEv2重定向功能 将 UE重新导向对应的 PDN GW;
步骤 606 : PDN GW 通过 IKEv2 向 UE 发送因特网密钥交换认证 ( IKE AUTH ) 响应消息, IKE— AUTH 响应消息包含携带重定向指示信息 ( REDIRECT ) New_GW_ID、 Ni_data和新的 PDN GW身份信息, 可以是 PDN GW的 IPv4或 IPv6地址, 也可以是 PDN GW的 FQDN;
步骤 607: UE根据重定向指示信息向新的 PDN GW发起 IKEv2认证进 行认证授权 , 以建立 MIPv6安全联盟。
实施例 6
图 7为用户设备使用 DSMIP作为移动管理协议通过 WLAN接入系统连 接到 EPC的流程图。 这里图中显示了 WLAN系统的 WiFi AP/AC , RG以及 接入 BRAS/BNG 等主要设备网元。 本实施例假设 WLAN接入系统中的 BRAS/BNG作为非 3GPP接入系统的认证网元。 需要说明的是, PDN GW的 选择重定向只适用于初始附着连接的场景, 切换场景下, PDN GW作为连接 锚点不会进行重定向优化。 具体流程如下。
步骤 701: UE连接到非 3GPP接入系统, 可选地进行非 3GPP接入的认 证授权, 在此过程中, 3GPP AAA服务器可以将运营商的相关策略信息和签 约信息发送给接入网络, BRAS/BNG向 UE分配本地 IP地址;
步骤 702: UE通过 WLAN接入系统进行非 3GPP接入的认证授权, 这 里, 3GPP AAA服务器可以将运营商的相关策略信息和签约信息发送给 BRAS/BNG, BRAS/BNG将 WLAN接入网的位置信息发送给 AAA服务器; 步骤 703: UE向 ePDG发起建立安全联盟, 建立 IPSec隧道, 确保 UE 到 ePDG之间的报文的安全;
步骤 704: UE向 PDN GW发送包含 EAP消息的因特网密钥交换认证
( IKE AUTH )请求消息, 响应身份认证交互过程中收到的认证挑战;
步骤 705: PDN GW将 EAP-Response响应消息(带 AKA挑战信息 )发 送给 3GPP AAA服务器;
步骤 706: 3GPP AAA服务器根据当前 UE所处的接入系统的位置信息 以及预配置的网关列表为 UE选择一个靠近的新的 PDN GW;
在本实施例中, 3GPP AAA服务器上预配置的网关列表包括 UE所处的 WLAN的位置相关信息和邻近该位置的 PDN GW的标识信息。
步骤 707, 3GPP AAA服务器向 PDN GW返回认证回答, 在该认证回答 中携带所选择的新的 PDN GW的标识信息,例如可以是 PDN GW的 IPv4或 IPv6地址, 也可以是 FQDN;
步骤 708 : PDN GW 通过 IKEv2 向 UE 发送因特网密钥交换认证 ( IKE AUTH ) 响应消息, IKE— AUTH 响应消息包含携带重定向指示信息 ( REDIRECT ) New_GW_ID、 Ni_data和新的 PDN GW身份信息, 可以是 PDN GW的 IPv4或 IPv6地址, 也可以是 PDN GW的 FQDN完全域名; 步骤 709: UE根据重定向指示信息向新的 PDN GW发起 IKEv2认证进 行认证授权 , 以建立 MIPv6安全联盟。
实施例 7
图 8为用户设备通过 WLAN接入系统连接到 EPC获取 ePDG信息的流 程图。这里图中显示了 WLAN系统的 WiFi AP/AC , RG以及接入 BRAS/BNG 等主要设备网元。 本实施例假设 WLAN接入系统中的 BRAS/BNG作为非 3GPP接入系统的认证网元。 具体流程如下。
步骤 801 :用户设备建立到 WLAN接入系统的无线连接,建立三层连接, BRAS/BNG为用户设备分配 IP地址;
步骤 802: UE通过 WLAN接入系统进行非 3GPP接入的认证授权, 这 里, 3GPP AAA服务器可以将运营商的相关策略信息和签约信息发送给 BRAS/BNG;
步骤 803: UE和 ePDG交换第一对消息 IKE— SA— INIT协商加密算法, 进行随机数的交换等;
步骤 804: UE通过 ePDG和 AAA服务器进行的身份认证信息的交互; 步骤 805: UE发送包含 EAP消息的因特网密钥交换认证 ( IKE AUTH ) 请求消息到 ePDG , 响应身份认证交互过程中收到的认证挑战, UE 将 BRAS/BNG的 IP地址包含在该报文中发送给 ePDG;
步骤 806: ePDG将 EAP-Response响应消息 (带 AKA挑战信息 )发送 给 3GPP AAA服务器, 消息中包含了步骤 805中的 BNG/BRAS的 IP地址作 为 UE当前位置信息发送给 3GPP AAA服务器;
步骤 807: 3GPP AAA服务器根据当前 UE所处的接入系统的位置信息 以及预配置的网关列表为 UE选择一个靠近的 ePDG;
在本实施例中, 3GPP AAA上预配置的网关列表包括 UE提供的位置信 息以及与该位置信息所指示位置邻近的 ePDG的标识信息, 优选为距离最近 ePDG„
步骤 808, 3GPP AAA服务器向 ePDG返回认证回答, 在该认证回答中 携带所选择的 ePDG的标识信息, 例如可以是 ePDG的 IPv4或 IPv6地址, 也可以是 FQDN;
步骤 809: ePDG通过 IKEv2向 UE发送因特网密钥交换认证( IKE AUTH ) 响应消息, IKE— AUTH 响应消息包含携带重定向指示信息 (REDIRECT ) New— GW— ID、 Ni— data和从 3GPP AAA服务器收到的新的 ePDG身份信息; ePDG判断认证回答中携带有 ePDG的标识信息, 则构造重定向指示信 息携带在 IKE— AUTH响应消息中, 同时还将该新的 ePDG的标识信息通过 IKE AUTH响应消息发送给用户设备。
步骤 810: UE根据重定向指示信息向新的 ePDG发起 IKEv2认证建立 IPSec隧道。
本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序 来指令相关硬件完成, 所述程序可以存储于计算机可读存储介质中, 如只读 存储器、 磁盘或光盘等。 可选地, 上述实施例的全部或部分步骤也可以使用 一个或多个集成电路来实现。 相应地, 上述实施例中的各模块 /单元可以釆用 硬件的形式实现, 也可以釆用软件功能模块的形式实现。 本发明不限制于任 何特定形式的硬件和软件的结合。
当然, 本发明还可有其他多种实施例, 在不背离本发明精神及其实质的 但这些相应的改变和变形都应属于本发明所附的权利要求的保护范围。
工业实用性
通过上述技术方案, 为用户设备选择合适的网关, 避免出现路由迂回的 问题, 提高系统性能, 提高了 ePDG/PDN GW的选择精度。 因此本发明具有 4艮强的工业实用性。

Claims

权 利 要 求 书
1、 一种选择网关的方法, 包括:
在用户设备接入演进分组核心网 (EPC ) 、 进行因特网密钥交换协议 ( IKEv2 ) 交互的过程中, 网元根据所述用户设备的位置信息为所述用户设 备重新选择靠近所述用户设备的支持 IKEv2协议的网关。
2、 如权利要求 1所述的方法, 其中:
所述网元包括第一演进的分组数据网关( ePDG ),重新选择的支持 IKEv2 协议的网关包括第二 ePDG;
所述方法还包括: 网元根据所述用户设备的位置信息为所述用户设备重 新选择靠近用户设备的支持 IKEv2协议的网关之后, 所述第一 ePDG向所述 用户设备发送重新选择的第二 ePDG的标识信息以及指示信息, 所述指示信 息用于指示所述用户设备向重新选择的第二 ePDG发起 IKEv2认证。
3、 如权利要求 1所述的方法, 其中:
所述网元包括第一分组数据网络网关 (PDN GW ) , 重新选择的支持 IKEv2协议的网关包括第二 PDN GW;
所述方法还包括, 网元根据所述用户设备的位置信息为所述用户设备重 新选择靠近用户设备的支持 IKEv2协议的网关之后, 所述第一 PDN GW向 所述用户设备发送重新选择的第二 PDN GW的标识信息以及指示信息,所述 指示信息用于指示所述用户设备向重新选择的第二 PDN GW发起 IKEv2认 证。
4、 如权利要求 1所述的方法, 其中:
所述网元包括 3GPP AAA服务器,所述重新选择的支持 IKEv2协议的网 关包括 ePDG或者 PDN GW;
所述方法还包括, 网元根据所述用户设备位置信息为所述用户设备重新 选择靠近用户设备的支持 IKEv2协议的网关之后,所述 3GPP AAA服务器向 所述用户设备的当前网关发送重新选择的网关的标识信息, 所述用户设备的 当前网关接收到所述重新选择的网关的标识信息后, 在向所述用户设备发送 的消息中携带所述重新选择的网关的标识信息以及指示信息, 所述指示信息 用于指示所述用户设备向所述重新选择的网关发起 IKEv2认证。
5、 如权利要求 1-4中任一项所述的方法, 其中, 所述位置信息包括以下 信息中的任意一种:
所述用户设备当前的本地 IP地址, 所述用户设备当前本地 IP地址所属 的 IP网段地址, 所述用户设备所处的接入网络的标识;
其中, 所述用户设备当前的本地 IP地址由本地接入网或者 ePDG分配。
6、如权利要求 5所述的方法, 其中, 所述用户设备所处的接入网络的标 识包括以下标识中的任意一种:
接入网络的服务集标识( SSID ) ,所述用户设备所处的宏站的标识信息, 所述用户设备所处的接入网络的地理位置信息, 管辖所述用户设备的接入网 关的地址信息。
7、 一种选择网关的装置, 所述装置上具有预配置的网关列表, 所述网关 列表中保存有位置信息以及与所述位置信息对应的邻近所述位置信息所指示 位置的支持 IKEv2协议的网关, 所述装置包括第一单元和第二单元, 其中: 所述第一单元设置成: 在用户设备接入演进分组核心网 (EPC ) 、 进行 因特网密钥交换协议( IKEv2 ) 交互的过程中, 获取所述用户设备的位置信 息;
所述第二单元设置成: 在所述第一单元获取到所述用户设备的所述位置 信息后, 根据所述位置信息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关。
8、 如权利要求 7所述的装置, 其中:
所述装置为第一演进的分组数据网关(ePDG ) , 重新选择的支持 IKEv2 协议的网关为第二 ePDG;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备发送重新选择的第二 ePDG的标识信息以及指示信息, 所述指 示信息用于指示所述用户设备向重新选择的第二 ePDG发起 IKEv2认证。
9、 如权利要求 7所述的装置, 其中: 所述装置为第一分组数据网络网关( PDN GW ) ,重新选择的支持 IKEv2 协议的网关为第二 PDN GW;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备发送重新选择的第二 PDN GW的标识信息以及指示信息,所述 指示信息用于指示所述用户设备向重新选择的第二 PDN GW发起 IKEv2认 证。
10、 如权利要求 7所述的装置, 其中:
所述装置为 3GPP AAA服务器,所述重新选择的支持 IKEv2协议的网关 包括 ePDG或者 PDN GW;
所述装置还包括第三单元, 其设置成: 在所述第二单元根据所述位置信 息为所述用户设备重新选择靠近用户设备的支持 IKEv2协议的网关之后, 向 所述用户设备的当前网关发送重新选择的网关的标识信息, 以使所述用户设 备的当前网关在向所述用户设备发送的消息中携带所述重新选择的网关的标 识信息以及指示信息, 所述指示信息用于指示所述用户设备向所述重新选择 的网关发起 IKEv2认证。
11、 如权利要求 7-10中任一项所述的装置, 其中, 所述位置信息包括以 下信息中的任意一种:
所述用户设备当前的本地 IP地址, 所述用户设备当前本地 IP地址所属 的 IP网段地址, 所述用户设备所处的接入网络的标识;
其中, 所述用户设备当前的本地 IP地址由本地接入网或者 ePDG分配。
PCT/CN2012/074666 2011-05-10 2012-04-25 一种选择网关的方法及装置 WO2012152185A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201110120066.0 2011-05-10
CN201110120066.0A CN102781004B (zh) 2011-05-10 2011-05-10 一种选择网关的方法及装置

Publications (1)

Publication Number Publication Date
WO2012152185A1 true WO2012152185A1 (zh) 2012-11-15

Family

ID=47125733

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/074666 WO2012152185A1 (zh) 2011-05-10 2012-04-25 一种选择网关的方法及装置

Country Status (2)

Country Link
CN (1) CN102781004B (zh)
WO (1) WO2012152185A1 (zh)

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103841590B (zh) * 2012-11-27 2018-05-18 中兴通讯股份有限公司 网络监测和节能控制方法与系统、终端及分组接入网关
MX2015008696A (es) * 2013-01-04 2016-02-25 Huawei Tech Co Ltd Metodo, aparato y sistema para seleccionar compuerta pdn.
CN104429128B (zh) * 2013-06-24 2018-02-23 华为技术有限公司 无线接入处理方法、装置及系统
US9179436B1 (en) * 2014-08-22 2015-11-03 Cisco Technology, Inc. System and method for location reporting in an untrusted network environment
US10237795B2 (en) * 2015-10-11 2019-03-19 Qualcomm Incorporated Evolved packet data gateway (EPDG) reselection
EP3387835A1 (en) 2015-12-11 2018-10-17 VID SCALE, Inc. Scheduling multiple-layer video segments
CN107959970B (zh) * 2016-10-17 2020-08-18 中国电信股份有限公司 获取VoWiFi用户的位置信息的方法、系统以及相关设备
CN106412148A (zh) * 2016-12-09 2017-02-15 中国联合网络通信集团有限公司 一种选择ePDG的方法及装置
WO2020034378A1 (en) * 2018-10-12 2020-02-20 Zte Corporation Location reporting for mobile devices
CN109040145B (zh) * 2018-10-23 2021-01-26 长沙裕邦软件开发有限公司 一种局域网安全接入的方法、存储介质及应用服务器
CN112312426B (zh) * 2019-07-31 2023-07-21 中国移动通信集团吉林有限公司 核心网网关的选择方法、移动性管理实体和网关设备
CN110662180B (zh) * 2019-10-25 2022-06-10 维沃移动通信有限公司 一种数据传输方法及设备

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030137991A1 (en) * 2002-01-23 2003-07-24 Doshi Parag M. Apparatus and method for enabling optimized gateway selection for inter-working between circuit-switched and internet telephony
CN101330740A (zh) * 2007-06-22 2008-12-24 中兴通讯股份有限公司 一种无线网络中的网关选择方法
CN101420762A (zh) * 2007-10-23 2009-04-29 中国移动通信集团公司 接入网关的选择方法、系统及网关选择执行节点
CN101572855A (zh) * 2008-04-30 2009-11-04 华为技术有限公司 一种为终端选择网关的方法及装置
CN101651977A (zh) * 2009-08-28 2010-02-17 华为技术有限公司 一种基于多连接的网络选择方法及装置

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8510812B2 (en) * 2006-03-15 2013-08-13 Fortinet, Inc. Computerized system and method for deployment of management tunnels
CN101365228B (zh) * 2007-08-07 2012-08-15 华为技术有限公司 移动终端接入网络的方法及锚点管理设备
US7839874B2 (en) * 2007-10-31 2010-11-23 Marvell World Trade Ltd. System and method for reselection of a packet data network gateway when establishing connectivity

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030137991A1 (en) * 2002-01-23 2003-07-24 Doshi Parag M. Apparatus and method for enabling optimized gateway selection for inter-working between circuit-switched and internet telephony
CN101330740A (zh) * 2007-06-22 2008-12-24 中兴通讯股份有限公司 一种无线网络中的网关选择方法
CN101420762A (zh) * 2007-10-23 2009-04-29 中国移动通信集团公司 接入网关的选择方法、系统及网关选择执行节点
CN101572855A (zh) * 2008-04-30 2009-11-04 华为技术有限公司 一种为终端选择网关的方法及装置
CN101651977A (zh) * 2009-08-28 2010-02-17 华为技术有限公司 一种基于多连接的网络选择方法及装置

Also Published As

Publication number Publication date
CN102781004A (zh) 2012-11-14
CN102781004B (zh) 2017-05-24

Similar Documents

Publication Publication Date Title
WO2012152185A1 (zh) 一种选择网关的方法及装置
JP6385337B2 (ja) 無線通信デバイス、通信システム並びに無線通信デバイスと第1のアクセス・ネットワークとの間のデータ接続性を確立するための方法
US9577984B2 (en) Network initiated alerts to devices using a local connection
US10432632B2 (en) Method for establishing network connection, gateway, and terminal
US20130139221A1 (en) Web Authentication Support for Proxy Mobile IP
US9113436B2 (en) Method and system for information transmission
US9629060B2 (en) Flexible routing policy for Wi-Fi offloaded cellular data
WO2012006909A1 (zh) 一种上报固网接入信息的方法及系统
WO2013189217A1 (zh) 分组网关标识信息的更新方法、aaa服务器和分组网关
US20150016418A1 (en) Allowing access to services delivered by a service delivery platform in a 3gpp hplmn, to an user equipment connected over a trusted non-3gpp access network
EP3174336A1 (en) Method and device for implementing flow mobility triggering, and storage medium
WO2013131487A1 (zh) 融合的核心网及其接入方法
EP2884802B1 (en) Method and system for notifying access network position information
Naik LTE WLAN interworking for Wi-Fi hotspots
WO2008154874A1 (fr) Procédé et système permettant d'établir un tunnel dans le réseau en évolution
WO2012126291A1 (zh) 一种数据路由方法及系统
WO2014106318A1 (zh) 选择分组数据网关的方法、装置及系统
JP5872066B2 (ja) 非3gppによってコアネットワークにアクセスする方法、装置及びシステム
WO2015024394A1 (zh) 网络地址的处理方法、装置、系统、wlan及ue
US9838214B2 (en) Wi-Fi offload of cellular data
WO2012100611A1 (zh) 接入演进分组系统的方法及系统
WO2012068837A1 (zh) 接入网关选择方法和装置
WO2013037273A1 (zh) 一种对用户设备能力进行处理的方法和系统
WO2014048191A1 (zh) 一种选择vplmn的方法、系统及分组数据网络网关
WO2013107243A1 (zh) 会话建立方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12782192

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12782192

Country of ref document: EP

Kind code of ref document: A1