WO2013078678A1 - Procédé pour déterminer un mode d'accès d'un équipement d'utilisateur, et système et dispositif correspondants - Google Patents

Procédé pour déterminer un mode d'accès d'un équipement d'utilisateur, et système et dispositif correspondants Download PDF

Info

Publication number
WO2013078678A1
WO2013078678A1 PCT/CN2011/083375 CN2011083375W WO2013078678A1 WO 2013078678 A1 WO2013078678 A1 WO 2013078678A1 CN 2011083375 W CN2011083375 W CN 2011083375W WO 2013078678 A1 WO2013078678 A1 WO 2013078678A1
Authority
WO
WIPO (PCT)
Prior art keywords
user equipment
correspondence
security
information
access network
Prior art date
Application number
PCT/CN2011/083375
Other languages
English (en)
Chinese (zh)
Inventor
周伟
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201180003638.5A priority Critical patent/CN103250446B/zh
Priority to PCT/CN2011/083375 priority patent/WO2013078678A1/fr
Publication of WO2013078678A1 publication Critical patent/WO2013078678A1/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery

Definitions

  • the embodiments of the present invention relate to the field of communications technologies, and in particular, to a method, system, and device for determining a user equipment access mode. Background technique
  • SAE System Architecture Evolution
  • 3GPP 3rd Generation Partnership Projective
  • EPS Evolved Packet System
  • UE User Equipment
  • 3GPP organization proposes an Access Network Discovery and Selection Function (ANDSF) entity, which can formulate a set of policy rules based on the combination of wireless access network information and operator policies.
  • the policy rule can select a suitable access mode for the UE.
  • ANDSF Access Network Discovery and Selection Function
  • the ANDSF entity can set the UE to perform the File Transfer Protocol (FTP) service between 8:00 am and 8:00 pm to select the WiFi access mode, so that the UE can select between 8:00 am and 8:00 pm. WiFi access mode access.
  • FTP File Transfer Protocol
  • the technical solution for offloading the service flow of the UE is that the Policy Charging Rule Function (PCRF) entity interacts with the ANDSF entity to obtain a policy rule, and then generates a policy according to the policy rule. And the Policy and Charging Control (PCC) rule, and then the Packet Data Network Gateway (PDN-GW) selects the corresponding bearer according to the PCC rule and the application information of the UE, and performs the service flow of the UE.
  • PCRF Policy Charging Rule Function
  • PCN-GW Packet Data Network Gateway
  • the embodiment of the invention provides a method and a system for determining a user equipment access mode, and a packet data gateway, which is used to solve the defect that the access mode of the UE cannot be determined based on the application information in the security scenario in the prior art.
  • An embodiment of the present invention provides a method for determining a user equipment access mode, including: the data gateway acquiring the access network discovery and selection function policy information corresponding to the user equipment; the access network discovery and selection function policy information includes the user equipment Corresponding first correspondence, the first correspondence is a correspondence between application information and an access method;
  • the data gateway obtains a second correspondence corresponding to the user equipment, where the second correspondence is a correspondence between the application information and the security information;
  • the data gateway determines the access mode of the user equipment according to the first correspondence, the second correspondence, and the data packet that is to be sent to the user equipment for security protection processing.
  • the embodiment of the present invention further provides a method for determining a user equipment access mode, including: accessing a network discovery and selection function entity to obtain an access network discovery and selection function policy information corresponding to a user equipment; the access network discovery and selection function
  • the policy information includes a first correspondence corresponding to the user equipment, where the first correspondence is a correspondence between the application information and the access mode.
  • the access network discovery and selection function entity acquires a second correspondence relationship corresponding to the user equipment, where the second correspondence relationship is a correspondence between the application information and the security information;
  • the access network discovery and selection function entity sends the first correspondence relationship and the second correspondence relationship to the data gateway, so that the data gateway is sent to the user equipment according to the first correspondence relationship, the second correspondence relationship, and the The data packet processed by the security protection determines the access mode of the user equipment.
  • the embodiment of the invention further provides a data gateway, including:
  • the first obtaining module is configured to obtain the access network discovery and selection function policy information corresponding to the user equipment; the access network discovery and selection function policy information includes a first correspondence corresponding to the user equipment, where the first correspondence is Correspondence between application information and access methods; a second acquiring module, configured to acquire a second correspondence corresponding to the user equipment, where the second correspondence is a correspondence between the application information and the security information;
  • a determining module configured to determine, according to the first correspondence, the second correspondence, and the data packet to be sent to the user equipment, the access mode of the user equipment.
  • the embodiment of the present invention further provides an access network discovery and selection function entity, including: a first acquiring module, configured to acquire access network discovery and selection function policy information corresponding to the user equipment; and the access network discovery and selection function policy
  • the information includes a first correspondence corresponding to the user equipment, where the first correspondence is a correspondence between the application information and the access mode;
  • a second acquiring module configured to acquire a second correspondence corresponding to the user equipment, where the second corresponding relationship is a correspondence between the application information and the security information;
  • a sending module configured to send the first correspondence and the second correspondence to the data gateway, where the data gateway performs security protection processing according to the first correspondence, the second correspondence, and the user equipment to be sent to the user equipment
  • the data packet determines the access mode of the user equipment.
  • An embodiment of the present invention further provides a system for determining a user equipment access mode, including: a data gateway and an access network discovery and selection function entity;
  • the data gateway is configured to receive the access network discovery and selection function policy information corresponding to the user equipment;
  • the access network discovery and selection function policy information includes a first correspondence corresponding to the user equipment, where the first correspondence is an application Corresponding relationship between the information and the access mode; receiving a second correspondence corresponding to the user equipment, where the second correspondence is a correspondence between the application information and the security information; according to the first correspondence, the second correspondence, and Dedicating a data packet sent by the user equipment to the user equipment to determine an access mode of the user equipment;
  • the access network discovery and selection function entity is configured to obtain access network discovery and selection function policy information corresponding to the user equipment; acquire a second correspondence corresponding to the user equipment; and send the access network discovery and selection function policy information And the second correspondence to the data gateway.
  • the method and system for determining the access mode of the user equipment and the data gateway in the embodiment of the present invention can determine the access mode of the UE based on the application information in the security scenario, so that the service flow of the UE can be implemented. operating.
  • DRAWINGS The drawings used in the embodiments or the description of the prior art are briefly described. It is obvious that the drawings in the following description are some embodiments of the present invention, and are not creative to those skilled in the art. Other drawings can also be obtained from these drawings on the premise of labor.
  • FIG. 1 is a signaling diagram of a method for determining a UE's access mode according to an embodiment of the present invention
  • FIG. 2 is a flowchart of a method for determining a UE access mode according to an embodiment of the present invention
  • FIG. 4 is a flowchart of a method for determining a UE access mode according to another embodiment of the present invention
  • FIG. 5 is a determining UE according to another embodiment of the present invention.
  • FIG. 6 is a signaling diagram of a method for determining a user equipment access manner according to an embodiment of the present invention
  • FIG. 7 is a signaling diagram of a method for determining a user equipment access manner according to another embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of a data gateway according to an embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of a data gateway according to another embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of an ANDSF entity according to an embodiment of the present disclosure.
  • FIG. 1 is a schematic structural diagram of a system for determining a UE access mode according to an embodiment of the present invention.
  • the technical solutions in the embodiments of the present invention are clearly and completely described in the following with reference to the accompanying drawings in the embodiments of the present invention.
  • the embodiments are a part of the embodiments of the invention, and not all of the embodiments. All other embodiments obtained by a person of ordinary skill in the art based on the embodiments of the present invention without creative efforts are within the scope of the present invention.
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • OFDMA Frequency Division Multiple Access
  • SC-FDMA Single Carrier FDMA
  • a CDMA network can implement wireless technologies such as Universal Terrestrial Radio Access (UTRA) and CDMA2000.
  • UTRA can include variants of CDMA, WCDMA, and other CDMA.
  • CDMA2000 can cover the Interim Standard (IS) 2000 (IS-2000), IS-95 and IS-856 standards.
  • the TDMA network can implement wireless technologies such as Global System for Mobile Communication (GSM).
  • GSM Global System for Mobile Communication
  • An OFDMA network can implement such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash OFDMA. And other wireless technologies.
  • E-UTRA Evolved UTRA
  • UMB Ultra Mobile Broadband
  • Wi-Fi IEEE 802.11
  • WiMAX IEEE 802.16
  • IEEE 802.20 Flash OFDMA.
  • UTRA and E-UTRA are UMTS and UMTS evolved versions.
  • 3 GPP is a new version of UMTS that uses E-UTRA in Long Term Evolution (LTE) and LTE Advanced (LTE-A).
  • LTE Long Term Evolution
  • LTE-A LTE Advanced
  • UTRA, E-UTRA, UMTS, LTE, LTE-A and GSM are described in the documentation of the 3GPP
  • a base station may be a station that communicates with a User Equipment (UE) or other communication station, such as a relay station, and the base station may provide communication coverage of a specific physical area.
  • the base station may provide communication coverage for macro cells, pico cells, femto cells, and/or other types of cells.
  • the macro cell may cover a relatively large geographic area, such as a radius of a few kilometers, and allows unrestricted access by UEs that have subscribed to the service.
  • the Pico cell can cover a relatively small geographical area and can allow unrestricted access by UEs that have subscribed to the service.
  • the Femto cell covers a relatively small geographical area, such as a home, and allows UEs associated with the femto cell to restrict access.
  • the base station serving the macro cell may be referred to as a macro base station
  • the base station serving the pico cell may be referred to as a pico base station
  • the base station serving the femto cell may be referred to as a femto base station or a home base station.
  • a base station can support one or more cells.
  • UEs may be distributed throughout the wireless network, and each UE may be static or mobile.
  • a UE may be referred to as a terminal, a mobile station, a subscriber unit, a station, or the like.
  • the UE can be a cellular phone, a personal digital assistant (PDA), a wireless modem solution.
  • PDA personal digital assistant
  • a modem a wireless communication device, a handheld device, a laptop computer, a cordless phone, a Wireless Local Loop (WLL) station, and the like.
  • WLL Wireless Local Loop
  • the UE can communicate with a macro base station, a pico base station, a femto base station, and the like.
  • the ANDSF entity stores ANDSF policy information.
  • the ANDSF policy information includes a first correspondence corresponding to the UE, where the first correspondence includes a correspondence between the application information and the access mode, for example, "application information A, access mode B".
  • the AAA server is used to store the server of the second correspondence.
  • the second correspondence includes the correspondence between the security information and the application information, for example: "Encryption Algorithm C, Application Information A”.
  • the data gateway may be a PDN-GW, or may be a Gateway General Packet Radio Service (GPRS) Support Node (GGSN).
  • GPRS General Packet Radio Service
  • GGSN Gateway General Packet Radio Service Support Node
  • the application information may be an application identifier, which is used to distinguish different application categories.
  • the application information can be a content type, such as text or video, to distinguish between different content categories.
  • the application information may also be other information that needs to be obtained by parsing the data message and used to distinguish different data messages. The present invention does not limit the application information.
  • the data gateway is a PDN-GW.
  • FIG. 1 is a signaling diagram of offloading a service flow of a UE according to the prior art.
  • the method for offloading the service flow of the UE as shown in FIG. 1 may specifically include the following:
  • an attach request is initiated, so as to be attached to the core network.
  • the UE performs data transmission through the PDN-GW in the core network;
  • the UE reports application information to an application function (AF) server; for example, the UE can pass a specific signaling message, such as a session initiation protocol (Session).
  • AF application function
  • Session session initiation protocol
  • the Initiation Protocol (SIP) signaling reports the running application information to the AF server.
  • the application information is the same as the application information involved in the communication between the UE and the communication peer server.
  • the AF server generates session information, and sends the session information to the PCRF entity. For example, after receiving the application information sent by the UE, the AF server generates corresponding session information (in essence, the session information also carries information that can identify the application information of the UE), and establishes an Rx session with the PCRF entity, at the Rx. The session information is sent to the PCRF entity on the interface.
  • a connection is established between the PCRF entity and the ANDSF entity, and the ANDSF policy information corresponding to the application information of the UE is obtained from the ANDSF entity.
  • the PCRF entity generates a PCC rule according to the acquired ANDSF policy information, and sends a PCC rule to the PDN-GW.
  • the PCRF entity sends a PCC rule to the PDN-GW through the Gx interface.
  • the PCC rule is a PCC rule corresponding to the application information of the UE.
  • the PCC rule includes the correspondence between the application information of the UE and the access mode.
  • the following 105 proxy may be used.
  • the PDN-GW establishes a connection with the ANDSF entity, and the PDN-GW obtains corresponding ANDSF policy information from the ANDSF entity.
  • the PDN-GW can obtain the application information of the UE from the service flow, and then obtain the PCC rule corresponding to the UE according to the ANDSF policy information and the application information of the UE.
  • the method may further include:
  • the PDN-GW performs a corresponding bearer operation, for example, performing a corresponding bearer operation according to a PCC rule corresponding to the application information of the UE in the service flow that is sent to the UE, for example, adding, modifying, or deleting the corresponding bearer, thereby implementing
  • the traffic flow sent to the UE by the receiving communication peer server is offloaded.
  • the PDN-GW can determine the access mode of the UE according to the PCC rule, so that the corresponding bearer operation can be performed.
  • FIG. 2 is a flowchart of a method for determining an access mode of a UE according to an embodiment of the present invention.
  • the method for determining the UE access mode in this embodiment is the PDN-GW.
  • the method for determining the UE access mode in this embodiment includes the following:
  • the ANDSF policy information includes a first correspondence corresponding to the UE, where the first correspondence is a correspondence between the application information and the access mode.
  • the second correspondence in the embodiment is the correspondence between the application information and the security information. 202. Determine, according to the first correspondence, the second correspondence, and the data packet that is to be sent to the UE for security protection processing, determine an access mode of the UE.
  • the application scenario of this embodiment is that the UE is in a security scenario.
  • the security scenario indicates that a secure connection is established between the UE and the communication peer server, and the context data transmitted by the UE is protected by encryption, thereby protecting the data transmitted by the UE from external attacks.
  • the method for determining the access mode of the user equipment in this embodiment determines the UE by using the correspondence between the application information and the access mode, the correspondence between the application information and the security information, and the data packet to be sent to the UE for security protection processing. Access method.
  • the technical solution of the present embodiment can overcome the problem that the access mode of the UE cannot be determined based on the application information in the security scenario in the prior art, so that the service flow of the UE can be offloaded based on the application information in the security scenario.
  • the security information in the foregoing embodiment includes information such as a key certificate, a symmetric key, and a security algorithm.
  • FIG. 3 is a flowchart of a method for determining a UE access mode according to another embodiment of the present invention. As shown in FIG. 3, the method for determining the access mode of the UE in this embodiment is based on the foregoing embodiment shown in FIG. 2, and the technical solution of the present invention is introduced in more detail.
  • the method for determining the UE access mode in this embodiment includes the following:
  • the PDN-GW receives the data packet sent by the communication peer server.
  • the data packet is sent to the UE, and the data packet is subjected to security protection processing. 301.
  • the PDN-GW sends the ANDSF policy request information that carries the UE identifier to the ANDSF entity, where the ANDSF entity obtains the ANDSF policy information corresponding to the UE.
  • the identifier of the UE may specifically be an IP address of the UE.
  • the ANDSF policy information is the same as the embodiment shown in FIG. 2, and includes a first correspondence corresponding to the UE, where the first correspondence is closed.
  • the system includes the correspondence between application information and access methods.
  • the ANDSF entity obtains the ANDSF policy information corresponding to the UE, and the ANDSF entity may obtain the ANDSF policy information corresponding to the UE from the preset policy database.
  • the ANDSF policy information may also include a first correspondence corresponding to multiple UEs.
  • the application scenario of this embodiment is also in the security scenario of the UE.
  • the physical meaning of the security scenario is the same as that of the foregoing embodiment.
  • the UE may have interacted with the ANDSF entity with some requirement information for setting policy information, such as a UE identifier, application information of the UE, and a security information indicator, etc., where the UE identifier may be an IP address of the UE.
  • the security information indicator is used to identify that the UE is in a security scenario, and the data packet sent by the communication peer server that communicates with the UE to the UE is security-protected. Therefore, after receiving the ANDSF policy request information, the ANDSF entity may obtain the second correspondence corresponding to the UE from the security server. Or the ANDSF entity may obtain the second correspondence corresponding to the UE from the security server before 300.
  • the second correspondence includes the correspondence between the application information and the security information.
  • the PDN-GW receives the ANDSF policy information sent by the ANDSF entity and the second correspondence corresponding to the UE.
  • the second correspondence in this embodiment is the same as the embodiment shown in FIG. 2, and the second correspondence includes the correspondence between the application information and the security information.
  • the PDN-GW obtains application information of the data packet according to the second correspondence and the data packet that is to be sent to the UE for security protection processing.
  • the security information in the second correspondence is used to parse the security-protected data packet to be sent to the UE, and the application information of the data packet is obtained after parsing; and the data packet obtained after the parsing is determined.
  • the application information corresponds to the application information in the second correspondence relationship, and if the response is successful, the security information and the application information corresponding to the data packet are determined as the security information and the application information in the second correspondence relationship. If the correspondence is not successful, the analysis is not successful. If there is another second correspondence corresponding to the UE, the security information in the other second correspondence may continue to be used for analysis.
  • the security information in this embodiment may be a key certificate, a symmetric key, a security algorithm, and the like; for example, when the security information is a key certificate, the key certificate may be used on the certificate server. After the verification, the key information is obtained, and the data information is parsed by the key information. When the analysis is successful, the security information is determined to be the security information corresponding to the UE. Or, when the security information is a symmetric key, the symmetric message is used to parse the data packet. When the parsing is successful, the security information is determined to be the security information corresponding to the UE. Or when the security information is a security algorithm, the security algorithm is used to parse the data packet with the existing key information, and the security information is determined to be the security information corresponding to the UE. Other similar security information can be handled by referring to the above example.
  • the PDN-GW determines the access mode of the UE according to the obtained application information of the data packet and the first correspondence between the ANDSF policy request information corresponding to the UE.
  • the access mode corresponding to the application information of the data packet is obtained from the first corresponding relationship corresponding to the UE according to the determined application information of the data packet, that is, the access mode of the UE.
  • the PDN-GW obtains the application information of the data packet according to the correspondence between the application information and the security information, and the data packet that is to be sent to the UE for security protection processing. And determining the access mode of the UE according to the correspondence between the application information and the access mode.
  • the technical solution of the present embodiment can overcome the problem that the access mode of the UE is determined based on the application information in the security scenario in the prior art, so that the service flow of the UE can be offloaded based on the application information in the security scenario.
  • the security server in the foregoing embodiment may be an Authentication Authorization and Accounting (hereinafter referred to as AAA) server, a Home Subscriber Server (HSS), a certificate server or an application server, and the like.
  • AAA Authentication Authorization and Accounting
  • HSS Home Subscriber Server
  • certificate server or an application server, and the like.
  • FIG. 4 is a flowchart of a method for determining a UE access mode according to still another embodiment of the present invention. As shown in FIG. 4, the method for determining the access mode of the UE in this embodiment is based on the foregoing embodiment shown in FIG. 2, and the technical solution of the present invention is introduced in more detail.
  • the method for determining the UE access mode in this embodiment includes the following:
  • the PDN-GW sends the ANDSF policy request information that carries the UE identifier to the ANDSF entity, so that the ANDSF entity obtains the ANDSF policy information corresponding to the UE.
  • the ANDSF policy information is the same as the embodiment shown in FIG. 2 and FIG. 3, and includes a first correspondence corresponding to the UE, where the first correspondence includes a corresponding relationship between the application information and the access mode. Department.
  • the PDN-GW receives the ANDSF policy information sent by the ANDSF entity.
  • the PDN-GW receives the data packet sent by the communication peer server.
  • the data packet is sent to the UE, and the UE is in a security scenario, and the data packet is encrypted and protected.
  • the PDN-GW sends a security information request that carries the UE identifier to the security server, so that the security server obtains the second correspondence corresponding to the UE according to the UE identifier.
  • the second correspondence in this embodiment is the same as the embodiment shown in FIG. 2 and FIG. 3, and the second correspondence includes the correspondence between the application information and the security information.
  • the PDN-GW receives the second correspondence corresponding to the UE sent by the security server.
  • the PDN-GW can send the security of the UE identifier to the security server by using the PCRF entity. Information request.
  • the PDN-GW receives the second correspondence corresponding to the UE sent by the security server through the PCRF entity.
  • the PDN-GW obtains application information of the data packet according to the second correspondence and the data packet that is to be sent to the UE for security protection processing.
  • the PDN-GW determines the access mode of the UE according to the first correspondence between the application information of the data packet and the ANDSF policy request information corresponding to the UE.
  • the application scenario of the embodiment is still in the security scenario of the UE, and the UE establishes a secure connection with the communication peer server.
  • the physical meaning of the security scenario is the same as that of the related embodiment. For details, refer to the description of the foregoing embodiment. This is not to repeat.
  • the PDN-GW obtains the application information of the data packet according to the correspondence between the application information and the security information, and the data packet that is to be sent to the UE for security protection processing. And determining the access mode of the UE according to the correspondence between the application information and the access mode.
  • the technical solution of the present embodiment can overcome the problem that the access mode of the UE is determined based on the application information in the security scenario in the prior art, so that the service flow of the UE can be offloaded based on the application information in the security scenario.
  • FIG. 5 is a flowchart of a method for determining an access mode of a UE according to another embodiment of the present invention.
  • the execution body of the method for determining the UE access mode in this embodiment may be an ANDSF entity.
  • the method for determining the access mode of the UE in this embodiment may include the following steps: 500: Acquire access network discovery and selection function policy information corresponding to the UE;
  • the access network discovery and selection function policy information includes a first correspondence corresponding to the UE, where the first correspondence is a correspondence between the application information and the access mode;
  • the second correspondence relationship is a correspondence between the application information and the security information.
  • the ANDSF policy information in this embodiment is the same as the foregoing embodiment shown in FIG. 2 to FIG. 4, and includes a first correspondence corresponding to the UE, where the first correspondence includes a correspondence between the application information and the access mode.
  • the data packet in this embodiment may be a security-processed data packet that is sent to the UE, and the data packet is specifically sent by the communication peer server that communicates with the UE to the PDN-GW.
  • the application scenario of the embodiment is still in the security scenario of the UE, and the UE establishes a secure connection with the communication peer server.
  • the physical meaning of the security scenario is the same as that of the related embodiment. For details, refer to the description of the foregoing embodiment. This is not to repeat.
  • the method for determining the access mode of the user equipment in this embodiment is to send the corresponding relationship between the acquired application information and the access mode, and the correspondence between the application information and the security information to the data gateway, so that the data gateway determines the access of the UE.
  • the method can be used to overcome the problem that the access mode of the UE is determined based on the application information in the security scenario in the prior art, so that the service flow of the UE is offloaded based on the application information in the security scenario.
  • the 501 obtains the access network discovery and selection function policy information corresponding to the UE, and may specifically obtain the UE corresponding to the UE identifier from the preset policy database. ANDSF policy information.
  • the UE identifier, the UE application information, and the security information indicator sent by the UE may be received before the 501, and the ANDSF entity is
  • the access network discovery and selection function policy information corresponding to the application information of the UE may be obtained according to the identifier of the UE and the application information of the UE, and the ANDSF entity may further learn that the UE and the communication peer server are established according to the security information indicator.
  • the secure connection, the data packets transmitted between the UE and the communication peer server are protected by encryption.
  • the identifier of the UE, the application information of the UE, and the security information indicator may be reported by the UE to the ANDSF entity when the UE and the ANDSF entity exchange some requirement information for setting policy information.
  • the method is similar to the method for determining the access mode of the user equipment on the PDN-GW side shown in FIG. 3, in this embodiment, when the ANDSF entity receives the UE identifier sent by the UE, application information of the UE, and security. After the information indicator, the data message sent by the communication peer server to the UE is sent in the security scenario according to the security information indicator. At this time, the ANDSF entity may request the ANDSF from the PDN-GW to the ANDSF entity. Before or after the policy information, the second correspondence of the UE is obtained from the security server. The ANDSF entity may also send the acquired second correspondence to the PDN-GW. For example, you can refer to the following steps:
  • A2. Receive a second correspondence corresponding to the UE sent by the security server.
  • the foregoing A1 may be:
  • the ANDSF entity sends a security information request carrying the UE identifier to the security server through the PCRF entity.
  • the A2 may be a second correspondence between the UE and the UE that the security server sends through the PCRF entity.
  • the ANDSF entity may also send the acquired second correspondence to the PDN-GW along with the ANDSF policy information.
  • the method for determining the access mode of the user equipment can be used to overcome the problem that the access mode of the UE cannot be determined based on the application information in the security scenario in the prior art, so that the service flow of the UE based on the application information in the security scenario can be implemented. Diversion.
  • FIG. 6 is a signaling diagram of a method for determining a user equipment access mode according to an embodiment of the present invention. As shown in FIG. 6, the method for determining the access mode of the user equipment in this embodiment may specifically include the following: 600. After the UE is powered on, it is attached to the core network;
  • the UE establishes a secure connection with the communication peer server.
  • the data packet between the subsequent UE and the communication peer server will be transmitted in the security scenario.
  • the physical meaning of the security scenario is the same as that of the foregoing embodiment. For details, refer to the description of the foregoing embodiment, and details are not described herein.
  • the UE and the ANDSF entity exchange policy information, where the UE reports the UE's IP address, application information, and security information indicator to the ANDSF entity.
  • the ANDSF entity sends a security information request that carries the IP address and application information of the UE to the AAA server.
  • the AAA server obtains a second correspondence corresponding to the UE according to the security information request, and sends the second correspondence to the ANDSF entity.
  • the ANDSF entity in 603 sends a security information request carrying the IP address and application information of the UE to the AAA server through the PCRF entity.
  • the AAA server sends the second correspondence to the ANDSF entity by using the PCRF entity.
  • the ANDSF entity obtains the first correspondence in the preset policy database according to the IP address and the application information of the UE.
  • the first correspondence relationship and the second correspondence relationship in this embodiment are the same as the embodiment shown in Figs. 2 to 5 described above.
  • the first correspondence includes the correspondence between the application information access modes.
  • the second correspondence includes the correspondence between the application information and the security information.
  • the communication peer server sends, to the PDN-GW, a security-protected data packet to be sent to the UE.
  • the 606 may also be located between 601 and 602.
  • the PDN-GW sends an ANDSF policy request information to the ANDSF entity.
  • the ANDSF entity sends the ANDSF policy information and the second correspondence to the PDN-GW.
  • the ANDSF policy information is the same as the embodiment shown in FIG. 2-5.
  • the PDN-GW parses the security-protected data packet sent to the UE according to the security information in the second correspondence, and obtains the security-protected datagram sent to the UE and the application information in the second correspondence. Correspondingly, the PDN-GW determines according to the first correspondence The access mode of the UE.
  • Step 609 is the same as 303-304 in the embodiment shown in FIG. 3 above.
  • Step 609 is the same as 303-304 in the embodiment shown in FIG. 3 above.
  • the method provided by the embodiment of the present invention can determine the access mode of the UE based on the application information in a security scenario, and subsequently perform a new or modified bearer process according to the change of the access mode, and perform the traffic according to the determined access mode.
  • Data packets which enable data distribution in a security scenario.
  • the PDN-GW obtains the application information of the data packet according to the correspondence between the application information and the security information, and the data packet that is to be sent to the UE for security protection processing. And determining the access mode of the UE according to the correspondence between the application information and the access mode.
  • the technical solution of the present embodiment can overcome the problem that the access mode of the UE is determined based on the application information in the security scenario in the prior art, so that the service flow of the UE can be offloaded based on the application information in the security scenario.
  • FIG. 7 is a signaling diagram of a method for determining a user equipment access mode according to still another embodiment of the present invention. As shown in FIG. 7, the method for determining the access mode of the user equipment in this embodiment may specifically include the following:
  • the UE After the UE is powered on, it is attached to the core network;
  • the UE establishes a secure connection with the communication peer server.
  • the data packet between the subsequent UE and the communication peer server will be transmitted in the security scenario.
  • the physical meaning of the security scenario is the same as that of the foregoing embodiment. For details, refer to the description of the foregoing embodiment, and details are not described herein.
  • the PDN-GW sends an ANDSF policy request message carrying an IP address of the UE to the ANDSF entity.
  • the ANDSF entity obtains ANDSF policy information in a preset policy database according to the ANDSF policy request information.
  • the ANDSF policy information in this embodiment is the same as the embodiment shown in FIG. 2 to FIG. 6 above, and details are not described herein.
  • the ANDSF entity sends ANDSF policy information to the PDN-GW.
  • the communication peer server sends a security-protected data packet sent to the UE to the PDN-GW. 706.
  • the PDN-GW sends a security information request that carries the IP address of the UE to the AAA server.
  • the AAA server obtains a second correspondence corresponding to the UE according to the security information request, and sends the second correspondence to the PDN-GW.
  • the PDN-GW sends a security information request carrying the IP address of the UE to the AAA server through the PCRF entity.
  • the AAA server sends the second correspondence to the PDN-GW through the PCRF entity.
  • the PDN-GW parses the security-protected data packet sent to the UE according to the security information in the second correspondence, and obtains the security-protected datagram sent to the UE and the application information in the second correspondence. Correspondingly, the PDN-GW determines the access mode of the UE according to the first correspondence.
  • the step 708 is the same as the 303-304 in the embodiment shown in FIG. 3, and the details of the foregoing embodiment may be referred to, and details are not described herein again.
  • the method provided by the embodiment of the present invention may determine the access mode of the UE based on the application information in a security scenario, and subsequently perform a new or modified bearer process according to the change of the access mode, and according to the determined access mode. Divide data packets to implement data distribution in a security scenario.
  • the PDN-GW obtains the application information of the data packet according to the correspondence between the application information and the security information, and the data packet that is to be sent to the UE for security protection processing. And determining the access mode of the UE according to the correspondence between the application information and the access mode.
  • the technical solution of the present embodiment can overcome the problem that the access mode of the UE is determined based on the application information in the security scenario in the prior art, so that the service flow of the UE can be offloaded based on the application information in the security scenario.
  • FIG. 6 and FIG. 7 illustrate the technical solution of the embodiment of the present invention by using the security server as an AAA server.
  • the AAA server in the foregoing embodiment may adopt an HSS, a certificate server, an application server, or the like.
  • a server capable of storing security information and a second correspondence is replaced.
  • the corresponding relationship between the application information and the access mode in the correspondence relationship is a corresponding relationship, that is, one security information corresponds to one application information, and one application information corresponds to one access mode.
  • FIG. 8 is a schematic structural diagram of a data gateway according to an embodiment of the present invention. As shown in FIG. 8, the data gateway of this embodiment includes: a first acquiring module M10, a second acquiring module Mi1, and a determining module M12.
  • the first acquiring module M10 is configured to obtain the access network discovery and selection function policy information corresponding to the user equipment; the access network discovery and selection function policy information includes the first correspondence corresponding to the user equipment. Relationship, the first correspondence is a correspondence between the application information and the access mode; the second obtaining module Mi1 is configured to obtain a second correspondence corresponding to the user equipment, where the second correspondence is the application information and the security information Corresponding relationship; the determining module M12 is respectively connected to the first obtaining module M10 and the second acquiring module Mi l, and the determining module M12 is configured to perform security protection according to the first correspondence, the second correspondence, and the user equipment to be sent to the user equipment.
  • the processed data packet determines the access mode of the user equipment.
  • the implementation mechanism for determining the access mode of the UE by using the foregoing module is the same as the implementation of the foregoing related method embodiment.
  • the implementation mechanism for determining the access mode of the UE by using the foregoing module is the same as the implementation of the foregoing related method embodiment.
  • the data gateway of this embodiment can determine the access mode of the UE based on the application information in the security scenario by using the foregoing module, so that the service flow of the UE can be offloaded in the subsequent manner.
  • FIG. 9 is a schematic structural diagram of a data gateway according to another embodiment of the present invention. As shown in FIG. 9, the data gateway of this embodiment may further include the following in the foregoing embodiment of FIG.
  • the first obtaining module M10 may include a first sending unit U101 and a first receiving unit U102.
  • the first sending unit U101 is configured to send an ANDSF policy request information that carries the UE identifier to the ANDSF entity, where the ANDSF entity acquires the UE.
  • the ANDSF policy information includes a first correspondence corresponding to the UE.
  • the first receiving unit U102 is configured to receive ANDSF policy information sent by the ANDSF entity.
  • the corresponding determining module M12 is connected to the first receiving unit U102, and the determining module M12 is configured to use the second corresponding relationship acquired by the second acquiring module Mi1 and the UE corresponding to the ANDSF policy information received by the first receiving unit U102.
  • a correspondence relationship and a data packet to be sent to the UE for security protection processing determine the access mode of the UE.
  • the second acquiring module M11 may be configured to receive at least one security information corresponding to the UE that is sent by the ANDSF entity, and corresponding at least one second correspondence relationship; The at least one security information and the corresponding at least one second correspondence are obtained by the ANDSF entity from the security server.
  • the second obtaining module Mi l may further include a second sending unit U111 and a second receiving unit U112.
  • the second sending unit U111 is configured to send a security information request that carries the UE identifier to the security server, so that the security server obtains the second correspondence corresponding to the UE according to the UE identifier.
  • the second receiving unit U112 is configured to receive a second correspondence corresponding to the UE sent by the security server.
  • the determining module M12 is further connected to the second receiving unit U112, and the determining module M12 is configured to be used according to the second corresponding relationship received by the second receiving unit U112, and the first acquiring module M10.
  • the first receiving unit U102 obtains the first correspondence between the UE and the data packet to be sent to the UE in the ANDSF policy information, and determines the access mode of the UE.
  • the second sending unit U111 is specifically configured to send, by using the PCRF entity, a security information request that carries the UE identifier to the security server.
  • the second receiving unit U112 may be specifically configured to receive a second correspondence corresponding to the UE that is sent by the security server by using the PCRF entity.
  • the determining module M12 in the foregoing embodiment may further include: an obtaining unit U121 and a determining unit U122.
  • the obtaining unit U121 is connected to the second receiving unit U112, and the obtaining unit U121 is configured to parse the security-protected data packet sent to the user equipment according to the security information in the second correspondence received by the second receiving unit U112.
  • the determining unit U122 is respectively connected to the obtaining unit U121 and the second receiving unit U112 and the first receiving unit U102, and the determining unit U122 is configured to Number of security-protected processes sent to the user device And determining, according to the first correspondence corresponding to the UE in the ANDSF policy information received by the first receiving unit U102, the access mode of the user equipment, according to the application information of the message corresponding to the application information in the second corresponding relationship.
  • the data gateway of this embodiment may further include a receiving module M13.
  • the receiving module M13 is configured to receive the security-protected data packet sent by the communication peer server.
  • the receiving module M13 is connected to the acquiring unit U121, so that the acquiring unit U121 can be used for the second corresponding relationship received by the second receiving unit U112 and the data of the security protection process to be sent to the user equipment received by the receiving module M13.
  • a packet obtains application information of the data packet.
  • the data gateway of this embodiment implements the description of the method for determining the connection method of the UE by using the above-mentioned modules and units, and details are not described herein.
  • the data gateway of this embodiment can determine the access mode of the UE based on the application information in the security scenario by using the foregoing module, so that the service flow of the UE can be offloaded in the subsequent manner.
  • FIG. 10 is a schematic structural diagram of an access network discovery and selection function entity according to an embodiment of the present invention.
  • the ANDSF entity device of this embodiment includes: a first acquiring module M20, a second acquiring module M21, and a sending module M22.
  • the first acquiring module M20 is configured to obtain the access network discovery and selection function policy information corresponding to the user equipment; the access network discovery and selection function policy information includes the first corresponding to the user equipment.
  • the first correspondence is a correspondence between the application information and the access mode;
  • the second obtaining module M21 is configured to obtain a second correspondence corresponding to the user equipment, where the second correspondence is the application information and the security information Correspondence relationship.
  • the sending module M22 is respectively connected to the first obtaining module M20 and the second obtaining module M21.
  • the sending module M22 is configured to send the first correspondence and the second correspondence to the data gateway, so that the data gateway is based on the first correspondence.
  • the second correspondence and the content to be sent to the user The data packet processed by the security protection of the user equipment determines the access mode of the user equipment.
  • the ANDSF entity in this embodiment implements the description of the method for determining the access method of the UE by using the foregoing module, and is not described here.
  • the ANDSF entity of this embodiment can facilitate the data gateway to determine the access mode of the UE based on the application information in the security scenario by using the foregoing module, so that the service flow of the UE can be offloaded in the subsequent manner.
  • the first obtaining module M20 in the foregoing embodiment may obtain the ANDSF policy information of the UE corresponding to the UE identifier from the preset policy database.
  • the second obtaining module M21 may include an indication receiving unit, a sending unit, and a receiving unit.
  • the receiving unit is configured to receive the user equipment identifier and the security information indicator of the user equipment
  • the sending unit is configured to send, to the security server, a security information request that carries the user equipment identifier, where the security server obtains the user according to the user equipment identifier.
  • the second correspondence corresponding to the device; the receiving unit is configured to receive a second correspondence corresponding to the user equipment sent by the security server.
  • the ANDSF entity of the foregoing embodiment implements the description of the method for determining the access method of the UE by using the foregoing module, and details are not described herein.
  • the ANDSF entity of the foregoing embodiment can facilitate the data gateway to determine the access mode of the UE based on the application information in the security scenario by using the foregoing module, so that the service flow of the UE can be offloaded in the subsequent manner.
  • the security server in the above device embodiment may still be an AAA server, an HSS, a certificate server, an application server, or the like, which is capable of storing security information and a correspondence between the security information and the application information.
  • FIG. 11 is a schematic structural diagram of a system for determining a UE access mode according to an embodiment of the present invention.
  • the system for determining the access mode of the UE in this embodiment may include: a data gateway 30 and an ANDSF entity 40.
  • the data gateway 30 is configured to receive the access network discovery and selection function policy information corresponding to the user equipment; the access network discovery and selection function policy information includes a first correspondence corresponding to the user equipment, where the first correspondence is Correspondence between application information and access method; receiving the a second correspondence corresponding to the user equipment, where the second correspondence is a correspondence between the application information and the security information; according to the first correspondence, the second correspondence, and the security protection process to be sent to the user equipment Data packet, determining the access mode of the user equipment;
  • the ANDSF 40 is configured to obtain access network discovery and selection function policy information corresponding to the user equipment, obtain a second correspondence corresponding to the user equipment, and send the access network discovery and selection function policy information and the second correspondence to Data gateway.
  • the data gateway 30 is specifically configured to obtain the access network discovery and selection function policy information corresponding to the user equipment; the access network discovery and selection function policy information includes a first correspondence corresponding to the user equipment, and the first correspondence
  • the relationship is the correspondence between the application information and the access mode; the second correspondence corresponding to the user equipment is obtained, where the second correspondence is the correspondence between the application information and the security information; and the security information is parsed according to the second correspondence
  • the security-processed data packet sent to the user equipment obtains the application information of the security-protected data packet sent to the user equipment; and the security-protected data sent to the user equipment
  • the access mode of the user equipment is determined according to the first correspondence.
  • the ANDSF 40 is specifically configured to obtain the access network discovery and selection function policy information corresponding to the user equipment, receive the user equipment identifier and the security information indicator of the user equipment, and send a security information request that carries the user equipment identifier to the security server. And obtaining, by the security server, the second correspondence corresponding to the user equipment according to the user equipment identifier; receiving a second correspondence corresponding to the user equipment sent by the security server; sending the access network discovery and selection function policy information and The second correspondence is to the data gateway.
  • the system for determining the access mode of the UE in this embodiment is implemented by using the foregoing data gateway 30 and the ANDSF entity 40, and the implementation mechanism for determining the access mode of the UE is the same as that of the foregoing related method embodiment.
  • the record of the example is not mentioned here.
  • the data gateway 30 and the ANDSF entity 40 can determine the access mode of the UE based on the application information in the security scenario, so that the service flow of the UE can be offloaded in the subsequent manner. .
  • the various illustrative logic blocks, modules and circuits described in the embodiments of the invention may be implemented by general purpose processors, digital signal processors, application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic.
  • the device, discrete gate or transistor logic, discrete hardware components, or any combination of the above are designed to implement or operate the functions described.
  • the general purpose processor may be a microprocessor, which may alternatively be any conventional processor, controller, microcontroller or state machine.
  • the processor may also be implemented by a combination of computing devices, such as a digital signal processor and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a digital signal processor core, or any other similar configuration. achieve.
  • the steps of the method or algorithm described in the embodiments of the present invention may be directly embedded in hardware, a software module executed by a processor, or a combination of the two.
  • the software modules can be stored in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium in the art.
  • the storage medium can be coupled to the processor such that the processor can read information from the storage medium and can write information to the storage medium.
  • the storage medium can also be integrated into the processor.
  • the processor and the storage medium can be placed in an ASIC, and the ASIC can be placed in the user terminal.
  • the processor and the storage medium may also be provided in different components in the user terminal.
  • the above-described functions described in the embodiments of the present invention may be implemented in hardware, software, firmware, or any combination of the three. If implemented in software, these functions may be stored on a computer readable medium, or transmitted in a form or code, on a computer readable medium.
  • Computer readable media includes computer storage media and communication media that facilitates the transfer of computer programs from one place to another.
  • the storage medium can be any available media that any general purpose or special computer can access.
  • Such computer readable media can include, but is not limited to, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, disk storage Storage or other magnetic storage device, or any other medium that can be used to carry or store program code in the form of instructions or data structures and other forms that can be read by a general purpose or special computer, or general or special processor.
  • any connection can be appropriately defined as a computer readable medium, for example, if the software is from a website site, server or other remote resource through a coaxial cable, fiber optic computer, twisted pair, digital subscriber line (DSL) Or wirelessly transmitted in, for example, infrared, wireless, and microwave, is also included in a defined computer readable medium.
  • DSL digital subscriber line
  • the disks and discs include compact disks, laser disks, optical disks, DVDs, floppy disks, and Blu-ray disks. Disks typically replicate data magnetically, while disks typically optically replicate data with a laser. Combinations of the above may also be included in a computer readable medium.

Abstract

Dans ses modes de réalisation, la présente invention se rapporte à un procédé adapté pour déterminer un mode d'accès d'un équipement d'utilisateur (UE). L'invention se rapporte d'autre part à un système et à un dispositif correspondants. Le procédé selon l'invention comprend les étapes suivantes : une passerelle de données acquiert des données relatives à la stratégie d'une fonction de sélection et de recherche de réseau correspondant à un UE, les données relatives à la stratégie d'une fonction de sélection et de recherche de réseau comprenant une première correspondance qui correspond à l'UE, la première correspondance étant une correspondance entre des données d'application et un mode d'accès ; la passerelle de données acquiert une seconde correspondance qui correspond à l'UE, la seconde correspondance étant une correspondance entre les données d'application et des données de sécurité ; enfin, la passerelle de données détermine un mode d'accès de l'UE sur la base de la première correspondance, de la seconde correspondance et d'un paquet de données devant être envoyé à l'UE et qui est traité par un module de protection et de sécurité. La solution technique décrite dans la présente invention permet : de déterminer le mode d'accès de l'UE sur la base de données d'application dans le scénario de sécurité ; et, partant, de diviser un flux de services de l'UE.
PCT/CN2011/083375 2011-12-02 2011-12-02 Procédé pour déterminer un mode d'accès d'un équipement d'utilisateur, et système et dispositif correspondants WO2013078678A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201180003638.5A CN103250446B (zh) 2011-12-02 2011-12-02 确定用户设备接入方式的方法及系统、设备
PCT/CN2011/083375 WO2013078678A1 (fr) 2011-12-02 2011-12-02 Procédé pour déterminer un mode d'accès d'un équipement d'utilisateur, et système et dispositif correspondants

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/083375 WO2013078678A1 (fr) 2011-12-02 2011-12-02 Procédé pour déterminer un mode d'accès d'un équipement d'utilisateur, et système et dispositif correspondants

Publications (1)

Publication Number Publication Date
WO2013078678A1 true WO2013078678A1 (fr) 2013-06-06

Family

ID=48534650

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/083375 WO2013078678A1 (fr) 2011-12-02 2011-12-02 Procédé pour déterminer un mode d'accès d'un équipement d'utilisateur, et système et dispositif correspondants

Country Status (2)

Country Link
CN (1) CN103250446B (fr)
WO (1) WO2013078678A1 (fr)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109756919A (zh) * 2017-11-01 2019-05-14 华为技术有限公司 专有承载流的处理方法、装置及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101577909A (zh) * 2008-05-05 2009-11-11 大唐移动通信设备有限公司 非3gpp接入系统信任类型的获取方法、系统及装置
CN101599904A (zh) * 2009-06-26 2009-12-09 中国电信股份有限公司 一种虚拟拨号安全接入的方法和系统
CN101730192A (zh) * 2009-02-10 2010-06-09 中兴通讯股份有限公司 接入网策略信息的发送方法、装置及交互系统
CN101945456A (zh) * 2009-07-08 2011-01-12 中兴通讯股份有限公司 一种andsf提供接入网协议选择功能的方法和系统

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102223634A (zh) * 2010-04-15 2011-10-19 中兴通讯股份有限公司 一种用户终端接入互联网方式的控制方法及装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101577909A (zh) * 2008-05-05 2009-11-11 大唐移动通信设备有限公司 非3gpp接入系统信任类型的获取方法、系统及装置
CN101730192A (zh) * 2009-02-10 2010-06-09 中兴通讯股份有限公司 接入网策略信息的发送方法、装置及交互系统
CN101599904A (zh) * 2009-06-26 2009-12-09 中国电信股份有限公司 一种虚拟拨号安全接入的方法和系统
CN101945456A (zh) * 2009-07-08 2011-01-12 中兴通讯股份有限公司 一种andsf提供接入网协议选择功能的方法和系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109756919A (zh) * 2017-11-01 2019-05-14 华为技术有限公司 专有承载流的处理方法、装置及系统

Also Published As

Publication number Publication date
CN103250446B (zh) 2015-12-02
CN103250446A (zh) 2013-08-14

Similar Documents

Publication Publication Date Title
JP6185017B2 (ja) セキュアユーザプレーンロケーション(supl)システムにおける認証
US11051165B2 (en) Authentication failure handling for access to services through untrusted wireless networks
US20220272620A1 (en) Apparatus, system and method for enhancements to network slicing and the policy framework of a 5g network
US20220150699A1 (en) Efficient policy enforcement using network tokens for services - user-plane approach
US9819596B2 (en) Efficient policy enforcement using network tokens for services C-plane approach
CN110234070B (zh) 用于不可信网络环境中的位置报告的系统和方法
US9800563B2 (en) Method and device for processing data security channel
KR101216066B1 (ko) 캡슐화된 데이터 플로우들에 대한 정책 제어
CA3072968A1 (fr) Procede et systeme de caracteristiques de trafic d'un plan d'utilisateur et securite de reseau
US20200137672A1 (en) Handling a ue that is in the idle state
WO2016110093A1 (fr) Terminal, système et procédé de sécurité de découverte de mode b d2d et support d'informations
CN108464027A (zh) 对于未认证用户通过wlan接入3gpp演进分组核心支持紧急服务
WO2012167500A1 (fr) Procédé d'établissement d'un canal de données de sécurité destiné à un tunnel
JP2012531134A (ja) 発展型パケットシステムにおける端末のマルチアクセス方法及びシステム
WO2019219209A1 (fr) Établissement de nouvelles sa ipsec
JP2018518113A (ja) モバイル通信ネットワークのハンドオーバ機能を発見するための方法、モバイル通信ネットワークのハンドオーバ機能を発見するためのシステム、ユーザ装置、プログラム及びコンピュータプログラム製品
TW201108829A (en) Fixed mobile convergence (FMC) with PDIF and SIP gateway
CN104506406B (zh) 一种鉴权认证设备
WO2015018272A1 (fr) Méthode, appareil et système de mise à jour d'informations de pcf
US9264416B2 (en) UE access to circuit switched-based mobile telephony services using a fixed wireless terminal
US11729164B2 (en) Support of IMEI checking for WLAN access to a packet core of a mobile network
WO2015081784A1 (fr) Procédé, dispositif et système pour vérifier une capacité de sécurité
WO2015157981A1 (fr) Dispositif côté utilisateur de réseau local sans fil et procédé de traitement d'informations
WO2016183775A1 (fr) Procédé, appareil et dispositif d'appel d'urgence
WO2013078678A1 (fr) Procédé pour déterminer un mode d'accès d'un équipement d'utilisateur, et système et dispositif correspondants

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11876564

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11876564

Country of ref document: EP

Kind code of ref document: A1