WO2013000285A1 - 接入设备接入ims网络方法及agcf和s-cscf - Google Patents

接入设备接入ims网络方法及agcf和s-cscf Download PDF

Info

Publication number
WO2013000285A1
WO2013000285A1 PCT/CN2012/071091 CN2012071091W WO2013000285A1 WO 2013000285 A1 WO2013000285 A1 WO 2013000285A1 CN 2012071091 W CN2012071091 W CN 2012071091W WO 2013000285 A1 WO2013000285 A1 WO 2013000285A1
Authority
WO
WIPO (PCT)
Prior art keywords
registration request
agcf
access device
cscf
access
Prior art date
Application number
PCT/CN2012/071091
Other languages
English (en)
French (fr)
Inventor
缪永生
杜成鹏
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2013000285A1 publication Critical patent/WO2013000285A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • H04L65/1016IP multimedia subsystem [IMS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • H04L65/1046Call controllers; Call servers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1073Registration or de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup

Definitions

  • Access device access IMS network method and AGCF and S-CSCF
  • the present invention relates to the field of mobile communications, and particularly relates to a method for an access device to access an IP Multimedia Subsystem (IMS) network through an Access Gateway Control Function (AGCF, Access Gateway Control Function), and an AGCF and a service call session.
  • IMS IP Multimedia Subsystem
  • AGCF Access Gateway Control Function
  • S-CSCF Serving call session control Function
  • IMS is the standard of the Next Generation Network (NGN) defined by the 3rd Generation Partnership Project (3GPP). Its distinctive feature is the use of the Session Initiation Protocol (SIP) system. Communication is independent of access. It can have multiple media service control functions and bearer separation, call and session separation, application and service separation, service and network separation, and mobile network and Internet service integration.
  • NTN Next Generation Network
  • 3GPP 3rd Generation Partnership Project
  • SIP Session Initiation Protocol
  • the proposal of IMS complies with the trend of communication network convergence development.
  • the main functional entities in the IMS system include: User Equipment (UE, User Equipment), Proxy call session control function (P-CSCF, Proxy call session control Function), and query call session control function entity (I-CSCF, Interrogating call session). Control Function), S-CSCF, Home Subscriber (HSS), and Application Server (AS, Application Server).
  • UE User Equipment
  • P-CSCF Proxy call session control function
  • I-CSCF query call session control function entity
  • Control Function S-CSCF, Home Subscriber (HSS), and Application Server (AS, Application Server).
  • Softswitch The concept of softswitch (SS, Soft Switch) was gradually developed on the basis of IP telephony in the late 1990s. It was gradually improved in the process of transition from narrowband to broadband, and from circuit switching to packet switching. Softswitch has been commercialized on the existing network. IMS is the target network for the convergence of fixed and mobile networks. The evolution of softswitch to IMS is an inevitable trend.
  • a traditional fixed network access device such as an access gateway (AG, Access Media Gateway) of the H.248/Media Gateway Control Protocol (MGCP), can access the IMS network through the AGCF to implement IMS-related services.
  • AGCF Access Media Gateway Control Protocol
  • the specific fixed terminal is connected to the fixed network access device, and the traditional fixed network access device, such as the AG/IAD, is connected to the AGCF; currently, the protocol standard supported by the AGCF is H.248/MGCP/323/V5, etc. For example, H.248, the AGCF receives a service change (ServiceChange) request;
  • ServiceChange ServiceChange
  • the AGCF completes the connection with the traditional fixed network access device. Taking H.248 as an example, the AGCF sends a service change reply (ServiceChange Reply) response for the ServiceChange request.
  • ServiceChange Reply ServiceChange Reply
  • the AGCF constructs a registration request (register) based on the SIP protocol, and the request message carries the public user identifier and the private user identifier, and forwards the registration request to the I-CSCF;
  • the I-CSCF sends a User-Authorization-Request (UAR) message to the HSS, requesting to allocate an S-CSCF;
  • UAR User-Authorization-Request
  • the HSS sends a User AAuthorization Response (UAA) message to the I-CSCF, and returns the assigned S-CSCF name or S-CSCF capability in the UAA;
  • UAA User AAuthorization Response
  • the I-CSCF sends a registration request message to the selected S-CSCF;
  • the S-CSCF needs to perform authentication authentication on the user, and needs to send a multimedia authentication request (MAR, Multimedia-Auth-Request) to the HSS to obtain a user authentication vector, and the AGCF user generally uses SIP Digest authentication;
  • MAR Multimedia-Auth-Request
  • the HSS sends a multimedia authentication response (MAA, Multimedia-Auth- Answer) to the S-CSCF, where the response message carries an authentication vector;
  • MAA Multimedia-Auth- Answer
  • the S-CSCF constructs a challenge request (401 Unauthorized message) according to the authentication vector information, and sends the challenge request to the I-CSCF;
  • the I-CSCF forwards the 401 Unauthorized message to the AGCF;
  • the AGCF constructs a challenge response registration message by using the locally saved user authentication key information, and sends the challenge response registration message to the I-CSCF, where the authentication key is generally configured locally or through an integrated service and operation support system (BOSS, Business & Operation Support System )
  • BOSS Business & Operation Support System
  • the I-CSCF after receiving the registration request message, the I-CSCF sends a UAR message to the HSS, requesting to allocate the S-CSCF; S226, the HSS sends a UAA message to the I-CSCF, and returns the assigned S-CSCF name in the UAA;
  • the I-CSCF sends a registration request message to the selected S-CSCF;
  • the S-CSCF After receiving the registration request message, the S-CSCF determines the validity of the user, completes the authentication of the user, and sends a user configuration data request (SAR, Server- Assignment-Request) to the HSS after the authentication is passed;
  • SAR Server- Assignment-Request
  • the HSS stores the S-CSCF information, and sends the subscription data and the charging address information of the user to the S-CSCF through a User Configuration Data Response (SAA, Server-Assignment- Answer) message;
  • SAA User Configuration Data Response
  • the S-CSCF constructs a registration success response message, such as 200 OK, and sends it to the I-CSCF;
  • S236 The AGCF receives the registration success response forwarded by the I-CSCF, and completes the user registration. It is necessary to improve the above registration process.
  • the technical problem to be solved by the present invention is to provide an access device access IMS network method and an AGCF and an S-CSCF, which simplify the registration process.
  • the present invention uses the following technical solutions:
  • a method for an access device to access an IP Multimedia Subsystem (IMS) network includes: in the process of accessing an IMS network by an access gateway control function (AGCF), the AGCF is completed and After the connection of the access device is described, the decision structure carries the authentication request through the indication, and the registration request is sent to the serving call session control function entity (S-CSCF) through the query call session control function entity (I-CSCF). The authentication is performed by the indication for the S-CSCF to decide whether to authenticate the access device.
  • AGCF access gateway control function
  • S-CSCF serving call session control function entity
  • I-CSCF query call session control function entity
  • the step of the AGCF decision structure carrying the registration request for the authentication pass indication includes: the AGCF according to the operation and maintenance policy of the operator, and/or whether the authentication key of the access user of the access device is locally saved. Information, if the decision needs to carry the authentication pass indication in the registration request, constructing the registration request carrying the authentication pass indication.
  • the method also includes:
  • the S-CSCF After receiving the registration request, the S-CSCF determines that the registration request carries The authentication passes the indication, and the following operations are performed:
  • the decision does not authenticate the access device.
  • the access device is authenticated according to the operator's operation and maintenance policy, and/or the network information of the AGCF.
  • the registration request includes an initial registration request, a refresh registration request, or a logout request.
  • the registration request is a SIP message, and the authentication is performed by indicating a SIP header field or a parameter placed in the registration request.
  • An access gateway control function (AGCF) entity configured to provide the access device to access an IP Multimedia Subsystem (IMS) network, where the AGCF includes a decision module, a constructing module, and a sending module, where:
  • the decision module is configured to: determine, in the process of accessing the IMS network by the access device, whether to construct a registration request carrying an authentication pass indication after completing the connection with the access device;
  • the constructing module is configured to: when the decision module determines to construct the registration request that carries the authentication pass indication, construct the registration request that carries the authentication pass indication;
  • the sending module is configured to: send the registration request constructed by the constructing module to a Serving Call Session Control Function Entity (S-CSCF) by using a query call session control function entity (I-CSCF), where the authentication pass indication And used by the S-CSCF to determine whether to authenticate the access device.
  • S-CSCF Serving Call Session Control Function Entity
  • I-CSCF query call session control function entity
  • the decision module is configured to decide whether to construct a registration request carrying the authentication through the indication in the following manner:
  • the decision is made according to the operator's operation and maintenance policy, and/or whether the local authentication key information of the access user of the access device is saved locally.
  • the registration request includes an initial registration request, a refresh registration request, or a logout request.
  • the registration request is a SIP message
  • the constructing module is configured to construct a registration request carrying an authentication pass indication in the following manner:
  • the authentication pass indication is placed in a SIP header field or parameter of the registration request.
  • a Serving Call Session Control Function (S-CSCF) entity configured to provide an access device to access an IP Multimedia Subsystem (IMS) network, where the S-CSCF includes a receiving module, a determining module, and a decision module Block, where:
  • the receiving module is configured to: receive a registration request sent by an access gateway control function (AGCF); the determining module is configured to: determine whether the registration request carries an authentication pass indication; the determining module is configured to: After the determining module determines that the registration request carries the authentication passing instruction, the determining unit performs any one of the following operations:
  • AGCF access gateway control function
  • the access device is not authenticated
  • the access device is authenticated according to the operator's operation and maintenance policy, and/or the network information of the AGCF.
  • the user authentication key information does not need to be saved on the AGCF, and the S-CSCF completes the authentication of the user by determining the authentication through the indication, which simplifies the registration of the user of the traditional fixed network access device accessing the IMS network through the AGCF. Process.
  • the AGCF does not need to save the authentication key, the operation and maintenance cost is reduced, and the key inconsistency between the AGCF and the HSS does not occur.
  • the fixed access of AG/IAD and AGCF in the current technology can ensure the security of users. The simplified method in this paper does not affect the security of access devices.
  • FIG. 1 is a schematic diagram of a fixed network user accessing an IMS network architecture
  • FIG. 3 is a flowchart of an implementation of AGCF accessing an IMS network user registration according to an embodiment of the present invention
  • FIG. 4 is a schematic structural diagram of an AGCF and an S-CSCF according to an embodiment of the present invention.
  • the process of registering the user registration of the IMS network with the AGCF is found.
  • the AGCF needs to save the authentication key of the IMS user to complete the user registration of the IMS network.
  • the AGCF needs to save the authentication key, which increases the operation and maintenance cost. This causes the keys on the AGCF and HSS to be inconsistent.
  • the AGCF user registration process is slightly complicated. Considering that the traditional fixed network access device accesses the IMS network through the AGCF, the security of the access user can be ensured. Therefore, the present invention provides an access device.
  • a simplified solution for accessing the IMS network including:
  • the decision construct carries the authentication request through the indication, and the registration request is sent to the S-CSCF through the I-CSCF. And determining, by the indication, for the S-CSCF to decide whether to authenticate the access device.
  • the registration request includes an initial registration request, a refresh registration request, or a logout request.
  • the AGCF may decide whether to carry the authentication in the registration request according to the operator's operation and maintenance policy, and/or whether the local authentication information of the access user of the access device is saved locally or the like.
  • the indication for example, if the AGCF does not locally store the authentication key information of the access user of the access device, the authentication pass indication is carried in the registration request.
  • the AGCF and the S-CSCF are generally deployed on the trusted network.
  • the S-CSCF may, after receiving the authentication pass indication, according to the operation and maintenance policy and/or Or accessing the network information (such as the network information of the AGCF), and deciding whether to authenticate the access device. If the decision needs to authenticate the access device, the authentication pass indication information is ignored, and the access device is still used. Perform authentication.
  • the registration request is a SIP message
  • the authentication may be placed in a SIP header field or a parameter of the registration request
  • the SIP header field may be an existing SIP header field or an extended SIP header field. Parameters can also be existing or extended.
  • the above method can be used not only for a fixed network access device but also for a mobile access device.
  • the process of this embodiment is as shown in FIG. 3, and includes the following steps:
  • a traditional fixed network access device such as an AG/IAD, is connected to the AGCF. Taking H.248 as an example, the AGCF receives a ServiceChange request.
  • the AGCF completes the connection with the traditional fixed network access device. Taking H.248 as an example, the AGCF sends a Reply response for the ServiceChange request. S306, the AGCF constructs a registration request based on the SIP protocol, and the AGCF determines the authentication key of the access user that does not have the access device locally, and the decision carries the authentication pass indication in the request message, and the S-CSCF is not authorized to authenticate the user;
  • the AGCF constructs a SIP-based registration request based on the prior art.
  • the AGCF decides whether to carry the authentication pass indication in the request message, and may also make a decision according to other operation and maintenance policies of the operator, if the operation and maintenance strategy If the authentication is performed on all the access devices, the AGCF does not carry the authentication pass indication in the request message. If the operation and maintenance policy stipulates that all access devices are not authenticated, the AGCF carries the request message. The authentication passes the indication, or the operation and maintenance policy can specify the conditions of the access device that needs to be authenticated. The AGCF decides whether to carry the authentication pass indication in the request message according to the provisions of the operation and maintenance policy.
  • Authentication can be used to indicate the existing SIP header field or parameter, or it can be an extended SIP header field or parameter, such as setting the integrity-protected parameter in the Authorization header to "auth-done". ".
  • the AGCF forwards the registration request to the I-CSCF, where the request message carries an authentication pass indication.
  • the I-CSCF sends a user authentication request UAR to the HSS, requesting to allocate an S-CSCF;
  • the HSS sends a user authentication response message to the I-CSCF, and the UAA returns the assigned S-CSCF name or the capability of the S-CSCF.
  • the I-CSCF forwards the registration request message to the selected S-CSCF, and the request message carries the authentication pass indication information, for example, the integrity-protected parameter information in the Authorization header needs to be transmitted to the S-CSCF;
  • S316 The S-CSCF parses and identifies the authentication pass indication information. If the integrity-protected parameter in the Authorization header is found to be "auth-done", the user authentication is considered to be passed, and the decision is not to authenticate the access device.
  • the S-CSCF may have the ability to ignore the authentication pass indication, and determine whether to authenticate the access device according to the operation and maintenance policy and/or the network information where the AGCF is located. For example, if the network information of the AGCF indicates that the AGCF is in an untrusted network, the S-CSCF may decide to authenticate the registration of the AGCF request. S318.
  • the S-CSCF sends a user configuration data request to the HSS.
  • the HSS stores the S-CSCF information, and sends the subscription data and the charging address information of the user to the S-CSCF through the SAA message;
  • the S-CSCF constructs a registration success response message, such as 200 OK, and sends it to the I-CSCF.
  • the AGCF receives the registration success response forwarded by the I-CSCF, and completes the user registration.
  • the AGCF for implementing the foregoing method for providing an access device to access an IMS network includes a decision module, a constructing module, and a sending module, where:
  • the decision module is configured to: determine, in the process of accessing the IMS network by the access device, whether to construct a registration request carrying the authentication pass indication after completing the connection with the access device;
  • the constructing module is configured to: when the decision module determines to construct a registration request carrying an authentication pass indication, construct a registration request carrying an authentication pass indication;
  • the sending module is configured to: send a registration request configured by the constructing module to the S-CSCF by using an I-CSCF, where the authentication is used by the S-CSCF to determine whether to authenticate the access device. .
  • the decision module is configured to determine whether to construct a registration request carrying the authentication pass indication in the following manner: according to the operation and maintenance policy of the operator, and/or whether the access user of the access device is saved locally. Key information for decision making.
  • the registration request is a SIP message
  • the constructing module is configured to construct a registration request carrying an authentication pass indication by placing the authentication pass indication in a SIP header field or parameter of the registration request.
  • the S-CSCF for providing the access device to the IMS network includes a receiving module, a determining module, and a decision module, where:
  • the receiving module is configured to: receive a registration request sent by an access gateway control function (AGCF); the determining module is configured to: determine whether the registration request carries an authentication pass indication; The decision module is configured to: when the determining module determines that the registration request carries an authentication pass indication, the decision performs any of the following operations:
  • AGCF access gateway control function
  • the access device is not authenticated
  • the access device is authenticated according to the operator's operation and maintenance policy, and/or the network information of the AGCF.
  • the AGCF for the traditional fixed network device access, the AGCF carries the authentication pass indication information in the registration request message, and the S-CSCF identifies the authentication pass indication information, and does not need to authenticate the user, and directly completes User registration.
  • the method simplifies the AGCF user registration process.
  • the AGCF does not need to save the user authentication key, which is easy to operate and maintain the IMS network.
  • the user authentication key information does not need to be saved on the AGCF, and the S-CSCF completes the authentication of the user by determining the authentication through the indication, which simplifies the registration of the user of the traditional fixed network access device accessing the IMS network through the AGCF. Process.
  • the AGCF does not need to save the authentication key, the operation and maintenance cost is reduced, and the key inconsistency between the AGCF and the HSS does not occur.
  • the fixed access of AG/IAD and AGCF in the current technology can ensure the security of users.
  • the simplified method in this paper does not affect the security of access devices. Therefore, the present invention has strong industrial applicability.

Landscapes

  • Engineering & Computer Science (AREA)
  • Multimedia (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Business, Economics & Management (AREA)
  • General Business, Economics & Management (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种接入设备接入IP多媒体子系统(IMS)网络的方法和一种接入网关控制功能(AGCF)实体及一种服务呼叫会话控制功能(S-CSCF)实体,该方法包括:所述接入设备在通过接入网关控制功能(AGCF)接入IMS网络的过程中,所述AGCF在完成与所述接入设备的连接后,决策构造携带鉴权通过指示的注册请求,将所述注册请求通过查询呼叫会话控制功能实体(I-CSCF)发送给服务呼叫会话控制功能实体(S-CSCF),所述鉴权通过指示用于供所述S-CSCF决策是否对所述接入设备进行鉴权。上述技术方案简化了传统的固网接入设备通过AGCF接入IMS网络的用户注册流程。

Description

接入设备接入 IMS网络方法及 AGCF和 S-CSCF
技术领域
本发明涉及移动通信领域, 具体涉及一种接入设备通过接入网关控制功 能 ( AGCF , Access Gateway Control Function )接入 IP多媒体子系统( IMS , IP Multimedia subsystem ) 网络的方法以及 AGCF和服务呼叫会话控制功能 ( S-CSCF, Serving call session control Function) 实体。
背景技术
IMS是第三代合作伙伴组织 (3GPP, 3rd Generation Partnership Project ) 定义的下一代网络(NGN, Next Genenation Network )的标准, 它的显著特点 是釆用了会话初始协议 (SIP, Session Initiation Protocol )体系, 通讯与接入无 关, 可以具备多种媒体业务控制功能与承载能力分离, 呼叫与会话分离, 应 用与服务分离, 业务与网络分离, 以及移动网与因特网业务融合等多种能力。
IMS的提出顺应了通讯网融合发展的趋势。 IMS体系中的主要功能实体 包括:用户设备(UE, User Equipment ) ,代理呼叫会话控制功能实体(P-CSCF, Proxy call session control Function), 查询呼叫会话控制功能实体(I-CSCF, Interrogating call session control Function) , S-CSCF, 归属用户月良务器 ( HSS, Home subscriber Server) , 以及应用月良务器 ( AS, Application Server ) 。
软交换( SS, Soft Switch ) 的概念是 20世纪 90年代后期在 IP电话基础 上逐步发展起来的, 是在通信网由窄带向宽带过渡, 由电路交换向分组交换 演进的过程中逐步完善的。 软交换已经在现网大规模商用, IMS作为固定网 和移动网融合的目标网络, 软交换向 IMS演进是必然趋势。 传统的固网接入 设备, 如 H.248/媒体网关控制协议(MGCP, Media Gateway Control Protocol ) 的接入网关( AG, Access Media Gateway ) , 可以通过 AGCF接入 IMS网络, 实现 IMS相关业务, 网络架构如图 1所示。
在 IMS 网络中, 传统的固网接入设备, 如 AG、 综合接入设备 ( IAD, Integrated Access Device )等, 通过 AGCF接入 IMS网络, 需要 AGCF代替用 户在 IMS网络进行注册。 目前 IMS系统中 AGCF实现用户注册的过程如图 2 所示, 包括以下步骤:
S202 , 具体的固定终端与固网接入设备相连, 传统的固网接入设备, 如 AG/IAD等与 AGCF相连;目前 AGCF支持的协议标准有 H.248/MGCP/323/V5 等, 以 H.248为例, AGCF收到服务变更(ServiceChange )请求;
S204, AGCF完成与传统的固网接入设备的连接, 以 H.248为例, AGCF 会针对 ServiceChange请求发送服务变更回复( ServiceChange Reply )响应;
S206, AGCF构造基于 SIP协议的注册请求(register ) , 请求消息中携 带公有用户标识和私有用户标识, 并将注册请求转发到 I-CSCF;
S208, I-CSCF向 HSS发送用户认证请求(User-Authorization-Request, 简称 UAR ) 消息, 请求分配 S-CSCF;
S210 , HSS 向 I-CSCF 发 送 用 户 认 证 响 应 ( UAA , User-Authorization-Answer )消息, UAA中返回分配的 S-CSCF名称或 S-CSCF 的能力;
S212, I-CSCF将注册请求消息发送到选定的 S-CSCF;
S214 , 出于安全考虑, S-CSCF 需要对用户进行认证鉴权, 需要向 HSS 发送多媒体认证请求(MAR, Multimedia- Auth-Request )获取用户认证向量, AGCF用户一般釆用 SIP Digest鉴权;
S216 , HSS 向 S-CSCF发送多媒体认证响应 (MAA, Multimedia-Auth- Answer ) , 响应消息中携带认证向量;
S218, S-CSCF根据认证向量信息, 构造挑战请求(401 Unauthorized消 息 ) , 并发送到 I-CSCF;
S220, I-CSCF将 401 Unauthorized消息转发至 AGCF;
S222, AGCF使用本地保存的用户的鉴权密钥信息, 构造挑战响应注册 消息, 并发送到 I-CSCF, 鉴权密钥一般通过本地配置或者通过综合业务和运 营支撑系统 ( BOSS, Business & Operation Support System )获取;
S224, I-CSCF收到注册请求消息后, 向 HSS发送 UAR消息, 请求分配 S-CSCF; S226, HSS向 I-CSCF发送 UAA消息, UAA中返回分配的 S-CSCF名称;
S228, I-CSCF将注册请求消息发送到选定的 S-CSCF;
S230, S-CSCF收到注册请求消息后, 判断用户的合法性, 完成对用户的 鉴权, 鉴权通过后向 HSS 发送用 户 配置数据请求 ( SAR , Server- Assignment-Request ) ;
S232, HSS存储 S-CSCF信息, 并将用户的签约数据、 计费地址信息通 过用户配置数据响应( SAA, Server-Assignment- Answer )消息发送到 S-CSCF;
S234, S-CSCF构建注册成功响应消息, 如 200OK, 并发送到 I-CSCF;
S236, AGCF收到 I-CSCF转发过来的注册成功响应, 完成用户注册。 有必要对上述注册流程加以改进。
发明内容
本发明要解决的技术问题是提供一种接入设备接入 IMS 网络方法及 AGCF和 S-CSCF, 简化注册流程。
为解决上述技术问题, 本发明釆用如下技术方案:
一种接入设备接入 IP多媒体子系统(IMS ) 网络的方法, 包括: 所述接入设备在通过接入网关控制功能(AGCF )接入 IMS 网络的过程 中, 所述 AGCF在完成与所述接入设备的连接后, 决策构造携带鉴权通过指 示的注册请求, 将所述注册请求通过查询呼叫会话控制功能实体(I-CSCF ) 发送给服务呼叫会话控制功能实体 ( S-CSCF ) , 所述鉴权通过指示用于供所 述 S-CSCF决策是否对所述接入设备进行鉴权。
其中, 所述 AGCF决策构造携带鉴权通过指示的注册请求的步骤包括: 所述 AGCF根据运营商的运维策略,和 /或本地是否保存所述接入设备的 接入用户的鉴权密钥信息, 如果决策需要在所述注册请求中携带所述鉴权通 过指示, 则构造携带所述鉴权通过指示的所述注册请求。
该方法还包括:
所述 S-CSCF接收到所述注册请求后, 如果判断所述注册请求中携带有 所述鉴权通过指示, 则执行以下操作:
决策不对所述接入设备进行鉴权; 或者
根据运营商的运维策略,和 /或所述 AGCF所在网络信息决策是否对所述 接入设备进行鉴权。
其中: 所述注册请求包括初始注册请求、 刷新注册请求或注销请求。 其中: 所述注册请求为 SIP消息, 所述鉴权通过指示置于所述注册请求 的 SIP头字段或参数中。
一种接入网关控制功能 (AGCF ) 实体, 用于提供所述接入设备接入 IP 多媒体子系统(IMS ) 网络, 所述 AGCF 包括决策模块、 构造模块和发送模 块, 其中:
所述决策模块设置成: 在所述接入设备通过所述 AGCF接入 IMS网络的 过程中, 在完成与所述接入设备的连接后, 决策是否构造携带鉴权通过指示 的注册请求;
所述构造模块设置成: 在所述决策模块决策构造携带所述鉴权通过指示 的所述注册请求时, 构造携带所述鉴权通过指示的所述注册请求;
所述发送模块设置成: 将所述构造模块构造的所述注册请求通过查询呼 叫会话控制功能实体( I-CSCF )发送给服务呼叫会话控制功能实体( S-CSCF ) , 所述鉴权通过指示用于供所述 S-CSCF决策是否对所述接入设备进行鉴权。
其中, 所述决策模块设置成釆用以下方式决策是否构造携带鉴权通过指 示的注册请求:
根据运营商的运维策略, 和 /或本地是否保存所述接入设备的接入用户的 鉴权密钥信息来进行决策。
其中:
所述注册请求包括初始注册请求、 刷新注册请求或注销请求。
其中, 所述注册请求为 SIP消息, 所述构造模块设置成釆用以下方式构 造携带鉴权通过指示的注册请求:
将所述鉴权通过指示置于所述注册请求的 SIP头字段或参数中。
一种服务呼叫会话控制功能(S-CSCF )实体, 用于提供接入设备接入 IP 多媒体子系统(IMS )网络, 所述 S-CSCF包括接收模块、 判断模块和决策模 块, 其中:
所述接收模块设置成:接收接入网关控制功能( AGCF )发送的注册请求; 所述判断模块设置成: 判断所述注册请求中是否携带有鉴权通过指示; 所述决策模块设置成: 在所述判断模块判断所述注册请求中携带有所述 鉴权通过指示后, 决策执行以下操作中的任一种:
不对所述接入设备进行鉴权;
根据运营商的运维策略,和 /或所述 AGCF所在网络信息决策是否对所述 接入设备进行鉴权。
通过上述方案, AGCF上无需保存用户鉴权密钥信息, S-CSCF通过判定 鉴权通过指示, 完成对用户的鉴权, 简化了传统的固网接入设备通过 AGCF 接入 IMS网络的用户注册流程。 同时, 由于 AGCF上无需保存鉴权密钥, 降 低了运维成本, 并且不会出现 AGCF和 HSS上密钥不一致的情况。 另外, 目 前技术中 AG/IAD与 AGCF的固定接入, 已经能够保证用户的安全性, 本文 的简化方法不会对接入设备的安全性造成影响。
附图概述
图 1为固网用户接入 IMS网络架构示意图;
图 2为 AGCF接入 IMS网络用户注册的流程图;
图 3为本发明实施例的 AGCF接入 IMS网络用户注册实现方案一流程图; 图 4为本发明实施例的 AGCF与 S-CSCF的结构示意图。
本发明的较佳实施方式
对 AGCF接入 IMS网络用户注册的流程分析发现,由于 AGCF需要保存 IMS用户的鉴权密钥方可完成 IMS网络的用户注册,一方面 AGCF需要保存 鉴权密钥, 增加了运维成本, 容易导致 AGCF和 HSS上密钥不一致; 另一方 面目前 AGCF用户注册流程略显复杂。考虑到传统的固网接入设备通过 AGCF 接入 IMS网络, 能保证接入用户的安全性, 因此, 本发明提供了一种接入设 备接入 IMS网络的简化方案, 包括:
接入设备在通过 AGCF接入 IMS网络的过程中, AGCF在完成与接入设 备的连接后, 决策构造携带鉴权通过指示的注册请求, 将所述注册请求通过 I-CSCF发送给 S-CSCF,所述鉴权通过指示用于供所述 S-CSCF决策是否对该 接入设备进行鉴权。
优选地, 上述注册请求包括初始注册请求、 刷新注册请求或注销请求。 为与现有技术兼容, AGCF可以根据运营商的运维策略, 和 /或本地是否 保存该接入设备的接入用户的鉴权密钥信息等条件来决策是否在注册请求中 携带鉴权通过指示, 例如, 如果 AGCF本地没有保存该接入设备的接入用户 的鉴权密钥信息, 则在注册请求中携带该鉴权通过指示。
AGCF和 S-CSCF—般部署在可信网络,但是对于非可信网络,为了防止 非可信网络中的欺骗行为, S-CSCF可以在接收到鉴权通过指示后,根据运维 策略和 /或拜访网络信息(如 AGCF的所在网络信息), 决策是否对该接入设 备进行鉴权, 如果决策需要对该接入设备进行鉴权, 则忽略鉴权通过指示信 息, 依旧对该接入设备进行鉴权。
优选地, 注册请求为 SIP消息, 该鉴权通过指示可置于注册请求的 SIP 头字段或参数中, 该 SIP头字段可以是已有的 SIP头字段, 也可以是扩展的 SIP头字段, 该参数也可以是现有参数或者是扩展参数。
上述方法不仅可以用于固网接入设备, 还可以用于移动接入设备。
下面结合附图和具体实施方式对本发明作进一步详细的说明。
为了简化传统的接入设备通过 AGCF接入 IMS网络的注册流程, 同时解 决 AGCF保存用户鉴权密钥的一致性问题, 本实施例流程如图 3所示, 包括 以下步骤:
S302, 传统的固网接入设备, 如 AG/IAD等与 AGCF相连。 以 H.248为 例, AGCF收到 ServiceChange请求;
S304, AGCF完成与传统的固网接入设备的连接, 以 H.248为例, AGCF 会针对 ServiceChange请求发送 Reply响应; S306, AGCF构造基于 SIP协议的注册请求, AGCF判断本地没有接入 设备的接入用户的鉴权密钥, 决策在请求消息中携带鉴权通过指示, 希望 S-CSCF对用户不鉴权;
AGCF基于现有技术构造基于 SIP协议的注册请求。
AGCF 除了判断本地是否保存接入设备的接入用户的鉴权密钥来决策是 否在请求消息中携带鉴权通过指示外, 还可以根据运营商的其他运维策略来 进行决策, 如果运维策略规定对所有的接入设备进行鉴权, 则 AGCF在请求 消息中均不携带鉴权通过指示, 如果运维策略规定对所有的接入设备均不进 行鉴权, 则 AGCF在请求消息中均携带鉴权通过指示, 或者运维策略可以规 定需要进行鉴权的接入设备的条件, AGCF根据运维策略的规定决策是否在 请求消息中携带鉴权通过指示。
鉴权通过指示可以利用已有 SIP头字段或者参数, 也可以是扩展的 SIP 头字段或者参数, 如将鉴权 ( Authorization ) 头部中完整性保护 ( integrity-protected )参数设置为" auth-done"。
S308, AGCF将注册请求转发到 I-CSCF,请求消息中携带鉴权通过指示;
S310, I-CSCF向 HSS发送用户认证请求 UAR, 请求分配 S-CSCF;
S312 , HSS向 I-CSCF发送用户认证响应消息, UAA中返回分配的 S-CSCF 名称或 S-CSCF的能力;
S314, I-CSCF将注册请求消息转发到选定的 S-CSCF, 请求消息中携带 鉴权通过指示信息, 如 Authorization头部中 integrity-protected参数信息需要 传递到 S-CSCF;
S316, S-CSCF解析并识别鉴权通过指示信息, 如发现 Authorization头部 中 integrity-protected参数为 "auth-done" , 则认为用户鉴权通过, 决策不对该接 入设备进行鉴权;
在其他实施例中, S-CSCF可以具有忽略该鉴权通过指示的能力, 而根据 运维策略和 /或 AGCF 所在网络信息决策是否对该接入设备进行鉴权。 例如 AGCF所在网络信息指示该 AGCF处于非可信网络, 则 S-CSCF可以决策对 该 AGCF请求的注册均进行鉴权。 S318, S-CSCF向 HSS发送用户配置数据请求;
S320, HSS存储 S-CSCF信息, 并将用户的签约数据、 计费地址信息通 过 SAA消息发送到 S-CSCF;
S322, S-CSCF构建注册成功响应消息, 如 200OK, 并发送到 I-CSCF; S324, AGCF收到 I-CSCF转发过来的注册成功响应, 完成用户注册。
实现上述方法的用于提供接入设备接入 IMS网络的 AGCF,如图 4所示, 包括决策模块、 构造模块和发送模块, 其中:
所述决策模块设置成: 在接入设备通过所述 AGCF接入 IMS网络的过程 中, 在完成与接入设备的连接后, 决策是否构造携带鉴权通过指示的注册请 求;
所述构造模块设置成: 在所述决策模块决策构造携带鉴权通过指示的注 册请求时, 构造携带鉴权通过指示的注册请求;
所述发送模块设置成:将所述构造模块构造的注册请求通过 I-CSCF发送 给 S-CSCF, 所述鉴权通过指示用于供所述 S-CSCF决策是否对该接入设备进 行鉴权。
其中, 所述决策模块设置成釆用以下方式决策是否构造携带鉴权通过指 示的注册请求: 根据运营商的运维策略, 和 /或本地是否保存所述接入设备的 接入用户的鉴权密钥信息来进行决策。
优选地, 注册请求为 SIP消息, 所述构造模块设置成釆用以下方式构造 携带鉴权通过指示的注册请求:将所述鉴权通过指示置于所述注册请求的 SIP 头字段或参数中。
实现上述方法的用于提供接入设备接入 IMS网络的 S-CSCF, 如图 4所 示, 包括接收模块、 判断模块和决策模块, 其中:
所述接收模块设置成:接收接入网关控制功能( AGCF )发送的注册请求; 所述判断模块设置成: 判断所述注册请求中是否携带有鉴权通过指示; 所述决策模块设置成: 在所述判断模块判断所述注册请求中携带有鉴权 通过指示时, 决策执行以下操作中的任一种:
不对所述接入设备进行鉴权;
根据运营商的运维策略,和 /或所述 AGCF所在网络信息决策是否对该接 入设备进行鉴权。
釆用本发明实施例方法, 对于传统的固网设备接入, AGCF在注册请求 消息中携带鉴权通过指示信息, S-CSCF识别鉴权通过指示信息, 无需再对用 户进行鉴权,直接完成用户注册。该方法一方面简化了 AGCF用户注册流程, 另一方面 AGCF无需保存用户鉴权密钥, 易于 IMS网络的运维。
本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序 来指令相关硬件完成, 所述程序可以存储于计算机可读存储介质中, 如只读 存储器、 磁盘或光盘等。 可选地, 上述实施例的全部或部分步骤也可以使用 一个或多个集成电路来实现。 相应地, 上述实施例中的各模块 /单元可以釆用 硬件的形式实现, 也可以釆用软件功能模块的形式实现。 本发明不限制于任 何特定形式的硬件和软件的结合。
当然, 本发明还可有其他多种实施例, 在不背离本发明精神及其实质的 但这些相应的改变和变形都应属于本发明所附的权利要求的保护范围。
工业实用性
通过上述方案, AGCF上无需保存用户鉴权密钥信息, S-CSCF通过判定 鉴权通过指示, 完成对用户的鉴权, 简化了传统的固网接入设备通过 AGCF 接入 IMS网络的用户注册流程。 同时, 由于 AGCF上无需保存鉴权密钥, 降 低了运维成本, 并且不会出现 AGCF和 HSS上密钥不一致的情况。 另外, 目 前技术中 AG/IAD与 AGCF的固定接入, 已经能够保证用户的安全性, 本文 的简化方法不会对接入设备的安全性造成影响。 因此本发明具有很强的工业 实用性。

Claims

权 利 要 求 书
1、 一种接入设备接入 IP多媒体子系统(IMS ) 网络的方法, 包括: 所述接入设备在通过接入网关控制功能(AGCF )接入 IMS 网络的过程 中, 所述 AGCF在完成与所述接入设备的连接后, 决策构造携带鉴权通过指 示的注册请求, 将所述注册请求通过查询呼叫会话控制功能实体(I-CSCF ) 发送给服务呼叫会话控制功能实体(S-CSCF ) , 所述鉴权通过指示用于供所 述 S-CSCF决策是否对所述接入设备进行鉴权。
2、如权利要求 1所述的方法, 其中, 所述 AGCF决策构造携带鉴权通过 指示的注册请求的步骤包括:
所述 AGCF根据运营商的运维策略,和 /或本地是否保存所述接入设备的 接入用户的鉴权密钥信息, 如果决策需要在所述注册请求中携带所述鉴权通 过指示, 则构造携带所述鉴权通过指示的所述注册请求。
3、 如权利要求 1或 2所述的方法, 该方法还包括:
所述 S-CSCF接收到所述注册请求后, 如果判断所述注册请求中携带有 所述鉴权通过指示, 则执行以下操作:
决策不对所述接入设备进行鉴权; 或者
根据运营商的运维策略,和 /或所述 AGCF所在网络信息决策是否对所述 接入设备进行鉴权。
4、 如权利要求 1所述的方法, 其中:
所述注册请求包括初始注册请求、 刷新注册请求或注销请求。
5、 如权利要求 1所述的方法, 其中:
所述注册请求为 SIP消息, 所述鉴权通过指示置于所述注册请求的 SIP 头字段或参数中。
6、 一种接入网关控制功能(AGCF ) 实体, 用于提供所述接入设备接入 IP多媒体子系统(IMS ) 网络, 所述 AGCF包括决策模块、 构造模块和发送 模块, 其中:
所述决策模块设置成: 在所述接入设备通过所述 AGCF接入 IMS网络的 过程中, 在完成与所述接入设备的连接后, 决策是否构造携带鉴权通过指示 的注册请求;
所述构造模块设置成: 在所述决策模块决策构造携带所述鉴权通过指示 的所述注册请求时, 构造携带所述鉴权通过指示的所述注册请求;
所述发送模块设置成: 将所述构造模块构造的所述注册请求通过查询呼 叫会话控制功能实体( I-CSCF )发送给服务呼叫会话控制功能实体( S-CSCF ) , 所述鉴权通过指示用于供所述 S-CSCF决策是否对所述接入设备进行鉴权。
7、如权利要求 6所述的 AGCF实体, 其中, 所述决策模块设置成釆用以 下方式决策是否构造携带鉴权通过指示的注册请求:
根据运营商的运维策略, 和 /或本地是否保存所述接入设备的接入用户的 鉴权密钥信息来进行决策。
8、 如权利要求 6或 7所述的 AGCF实体, 其中:
所述注册请求包括初始注册请求、 刷新注册请求或注销请求。
9、 如权利要求 6或 7所述的 AGCF实体, 其中, 所述注册请求为 SIP消 息, 所述构造模块设置成釆用以下方式构造携带鉴权通过指示的注册请求: 将所述鉴权通过指示置于所述注册请求的 SIP头字段或参数中。
10、 一种服务呼叫会话控制功能(S-CSCF ) 实体, 用于提供接入设备接 入 IP多媒体子系统(IMS ) 网络, 所述 S-CSCF包括接收模块、 判断模块和 决策模块, 其中:
所述接收模块设置成:接收接入网关控制功能(AGCF )发送的注册请求; 所述判断模块设置成: 判断所述注册请求中是否携带有鉴权通过指示; 所述决策模块设置成: 在所述判断模块判断所述注册请求中携带有所述 鉴权通过指示后, 决策执行以下操作中的任一种:
不对所述接入设备进行鉴权;
根据运营商的运维策略,和 /或所述 AGCF所在网络信息决策是否对所述 接入设备进行鉴权。
PCT/CN2012/071091 2011-06-27 2012-02-14 接入设备接入ims网络方法及agcf和s-cscf WO2013000285A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201110176011.1 2011-06-27
CN201110176011.1A CN102857900B (zh) 2011-06-27 2011-06-27 接入设备接入ims网络方法及agcf和s‑cscf

Publications (1)

Publication Number Publication Date
WO2013000285A1 true WO2013000285A1 (zh) 2013-01-03

Family

ID=47404023

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/071091 WO2013000285A1 (zh) 2011-06-27 2012-02-14 接入设备接入ims网络方法及agcf和s-cscf

Country Status (2)

Country Link
CN (1) CN102857900B (zh)
WO (1) WO2013000285A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9182759B2 (en) 2012-02-06 2015-11-10 Audi Ag Device for the automated driving of a motor vehicle, motor vehicle having such a device and method for operating a motor vehicle

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106341814A (zh) * 2015-07-08 2017-01-18 中兴通讯股份有限公司 语音业务注册方法及装置
CN112953718B (zh) * 2019-11-26 2024-05-28 中国移动通信集团安徽有限公司 Ims网络用户的鉴权方法及装置、呼叫会话控制功能实体

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1941933A (zh) * 2005-09-30 2007-04-04 华为技术有限公司 电路域用户接入ims域的方法及通信系统
CN101325759A (zh) * 2007-06-15 2008-12-17 华为技术有限公司 一种用户终端接入ims早期鉴权的方法及系统
CN102056154A (zh) * 2009-10-30 2011-05-11 华为技术有限公司 Ike认证方法、系统、ike响应设备和ike发起设备

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1941933A (zh) * 2005-09-30 2007-04-04 华为技术有限公司 电路域用户接入ims域的方法及通信系统
CN101325759A (zh) * 2007-06-15 2008-12-17 华为技术有限公司 一种用户终端接入ims早期鉴权的方法及系统
CN102056154A (zh) * 2009-10-30 2011-05-11 华为技术有限公司 Ike认证方法、系统、ike响应设备和ike发起设备

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
WANG SONG: "3GPP-based IMS network security research", CHINA MASTER'S THESES FULL-TEXT DATABASE, no. 7, 15 July 2010 (2010-07-15), pages 50 - 61 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9182759B2 (en) 2012-02-06 2015-11-10 Audi Ag Device for the automated driving of a motor vehicle, motor vehicle having such a device and method for operating a motor vehicle

Also Published As

Publication number Publication date
CN102857900A (zh) 2013-01-02
CN102857900B (zh) 2017-05-24

Similar Documents

Publication Publication Date Title
JP5139570B2 (ja) Ipマルチメディア・サブシステムにアクセスする方法および装置
US8514870B2 (en) Method for implementing IP multimedia subsystem registration
US7822407B2 (en) Method for selecting the authentication manner at the network side
JP4922397B2 (ja) マルチモード通信端末装置を多重登録する方法
WO2007036123A1 (fr) Procede et systeme de communication pour un utilisateur du domaine cs accedant au domaine ims
WO2011079522A1 (zh) 一种认证方法、系统和装置
WO2008095421A1 (fr) Système, dispositif et procédé de fourniture de service
EP1563654A2 (en) USER EQUIPMENT DEVICE ENABLED FOR SIP SIGNALLING TO PROVIDE MULTIMEDIA SERVICES WITH QoS
WO2006099815A1 (fr) Procede d'enregistrement d'un utilisateur dans le sous-systeme multimedia ip et systeme associe
WO2006102830A1 (fr) Procede destine a un terminal d’identification de commande de routage d’interaction de capacite pendant que ims et cs sont co-instantanes
WO2006010312A1 (fr) Procede d'information de la modification de capacite au terminal au reseau
US20080092226A1 (en) Pre-registration secure and authenticatedsession layer path establishment
WO2008138261A1 (fr) Sous-système multimédia ip, procédé de contrôle de conversion de codage et de décodage et dispositif de celui-ci
WO2008025280A1 (fr) Procédé et système d'authentification
JP5470464B2 (ja) Ipマルチメディア・サブシステム・ネットワークの緊急シグナリング
WO2007095795A1 (fr) Système et procédé de mise en oeuvre de services associés au sous-système multimédia ip
WO2009149667A1 (zh) 被叫接入的方法、装置和系统
EP2119178B1 (en) Method and apparatuses for the provision of network services offered through a set of servers in an ims network
WO2014201904A1 (zh) 用户终端接入ims网络的注册实现方法及ims
WO2006072219A1 (fr) Systeme d'authentification d'un reseau de sous-systeme multimedia ip et procede associe
WO2012155769A1 (zh) S-cscf容灾恢复倒回的方法及系统
WO2013000285A1 (zh) 接入设备接入ims网络方法及agcf和s-cscf
WO2008089699A1 (fr) Procédé et système d'authentification d'un terminal utilisateur dans un réseau ims
WO2007098669A1 (fr) Procédé, système et dispositif d'authentification de terminal d'utilisateur
WO2011029342A1 (zh) 一种识别pui类型的方法、设备及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12805022

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12805022

Country of ref document: EP

Kind code of ref document: A1