WO2013091179A1 - 用户识别的方法、设备和系统 - Google Patents

用户识别的方法、设备和系统 Download PDF

Info

Publication number
WO2013091179A1
WO2013091179A1 PCT/CN2011/084308 CN2011084308W WO2013091179A1 WO 2013091179 A1 WO2013091179 A1 WO 2013091179A1 CN 2011084308 W CN2011084308 W CN 2011084308W WO 2013091179 A1 WO2013091179 A1 WO 2013091179A1
Authority
WO
WIPO (PCT)
Prior art keywords
identity
base station
network device
message
core network
Prior art date
Application number
PCT/CN2011/084308
Other languages
English (en)
French (fr)
Inventor
王志峰
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201180071128.1A priority Critical patent/CN103609153B/zh
Priority to PCT/CN2011/084308 priority patent/WO2013091179A1/zh
Publication of WO2013091179A1 publication Critical patent/WO2013091179A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • H04L63/205Network architectures or network communication protocols for network security for managing network security; network security policies in general involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved

Definitions

  • the present invention relates to the field of mobile communications, and more particularly to techniques for user identification.
  • a communication system for example, a Long Term Evolution (LTE) system
  • user information tracking and call history are often used to monitor and evaluate VIP (VIP) service quality, Handle complaints and locate problems.
  • VIP VIP
  • the UE needs to be identified when tracking the specified user equipment (User Equipment, English is called UE), and acquiring the call history of the UE, or counting the UE performance of different vendors.
  • the core network side network node such as the Mobility Management Entity (English called Mobility Management Entity), can identify the UE, but the non-access stratum (English is Non-Access Stratum, called NAS) message between the UE and the MME.
  • the interaction is performed, and the network nodes on the access network side, such as the base station and the relay station, can only transparently transmit the NAS message, and the encrypted NAS message cannot be parsed, so the UE cannot be identified, which is to locate the network side, solve the complaint, and monitor the network.
  • the quality of VIP business is very difficult.
  • the method before the base station sends the non-access stratum NAS message for the ciphering negotiation sent by the core network device to the user equipment UE, the method includes: sending, by the base station, an identity request message to the UE, where the identity request message is used. And requesting the user identifier of the UE; the base station receiving the identity response message sent by the UE, where the identity response message carries the user identifier of the UE.
  • the foregoing base station actively acquires the user identifier to identify the UE, and does not need to To cooperate with the core network.
  • Another aspect of an embodiment of the present invention provides a method for user identification.
  • the UE receives an identity request message, and the identity request message is sent by the base station before the base station sends the NAS message sent by the core network device for cryptographic negotiation, and the identity request message is used to request the UE.
  • a user identifier the user identifier is used by the base station to identify the UE; the UE sends an identity response message to the base station, where the identity response message carries the user identifier of the UE.
  • the foregoing UE may be actively identified by the foregoing base station, and does not need to cooperate with the core network device.
  • an access network device including: a transmitter, configured to send a message to a user equipment UE and/or a core network device; a receiver, where the receiver is configured to receive a message sent by the UE and/or the foregoing core network device; a processor, configured to control the transmitter to send an identity request message to the UE before sending the NAS message for the encryption negotiation to the UE, where the identity request message is used by the UE And the processor is further configured to: after the receiver receives the identity response message sent by the UE, control the NAS to send a NAS message for encryption negotiation to the UE, where the identity response is The message carries the identity of the UE.
  • a user equipment including: a receiver, configured to receive an identity request message sent by a base station, where the identity request message is used to request an identity of the user equipment. a transmitter, configured to send an identity response message to the base station after the receiver receives the identity request message, and the identity response message carries the identity identifier of the user equipment.
  • a communication system includes the above access network device and the above user equipment.
  • the communication system performs the above method of user identification.
  • the foregoing communication system is configured to enable the access network device to actively acquire the user identifier of the user equipment to identify the user equipment.
  • a computer program product is provided.
  • the computer program product includes a storage medium in which code for implementing the method of user identification described above is stored. Applying the above computer program product, the access network device can obtain the user identifier of the user equipment and identify the user equipment.
  • FIG. 2 is a schematic flowchart of a method for user identification according to Embodiment 1 of the present invention
  • FIG. 3 is a schematic diagram of user identification provided by Embodiment 2 of the present invention
  • FIG. 4 is a schematic flowchart of a user identification method according to Embodiment 3 of the present invention
  • FIG. 5 is a schematic structural diagram of an access network device according to Embodiment 4 to Embodiment 6 of the present invention
  • FIG. 6 is a schematic structural diagram of a user equipment according to Embodiment 7 of the present invention
  • DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The technical solutions in the embodiments of the present invention will be clearly and completely described in the following with reference to the accompanying drawings.
  • a base station for example, an evolved base station (e.g., an evolved Node B); and a core network device (for example, an MME)
  • the UE and the base station exchange information through an air interface, and the base station and the core
  • the information exchanges between the network devices through the S1 interface, and the information exchange between the base stations through the X2 interface.
  • the base station on the access network side is used to forward the NAS message.
  • a user identification method according to Embodiment 1 of the present invention is provided. The method is performed after the base station establishes a radio resource control connection with the UE, including:
  • the base station sends an identity request message to the UE.
  • the identity request message is used to request the user identity of the UE.
  • the foregoing base station receives an identity response message sent by the UE. After receiving the identity request message, the UE sends an identity response message to the base station.
  • the identity response message carries the user identity of the UE.
  • the base station parses and acquires the user identifier of the UE in the identity response message, and identifies the UE according to the user identifier. Optionally, the base station may also save the user identifier for subsequent use.
  • the base station sends, to the UE, a NAS message sent by the core network device for encryption negotiation.
  • the base station completes the process of querying the identity of the UE by the base station before sending the NAS message sent by the core network device to the base station for cryptographic negotiation (for example, steps S21 and S22).
  • a user identification method provided by Embodiment 2 of the present invention includes the following content.
  • the base station establishes an RRC connection with the UE.
  • the process of establishing an RRC connection between the base station and the UE in the prior art is applicable to this embodiment, and details are not described herein again.
  • the foregoing base station sends an identity request message to the UE.
  • the identity request message is used to request the user identity of the UE.
  • the identity request message can be a NAS message.
  • the foregoing base station receives an identity response message sent by the UE. After receiving the identity request message sent by the base station, the UE sends an identity response message to the base station.
  • the identity response message may be a NAS message.
  • the identity response message carries the user identity of the UE.
  • the user identifier is used by the base station to identify the UE.
  • the user identifier may be an international mobile subscriber identity (International Mobile Subscribe Identity, or IMSI), or may be an international mobile device identifier (English for International Mobile Equipment, IMEI), or IMSI and IMEI and so on.
  • the base station parses and acquires the user identifier of the UE in the identity response message, and identifies the UE.
  • the foregoing base station may also save the user identifier of the UE for subsequent use.
  • the base station may also discard the identity response message without sending it to the core network device, thereby saving network resources.
  • the foregoing base station sends a notification message to the core network device.
  • the notification message is used to notify the core network device to perform an initialization operation on the UE.
  • the initialization operation includes authentication, encryption, and quality of service (English Quality Of Service, QOS) control of the UE.
  • the notification message may be that the base station sends an initial user equipment message to the core network device through the S1 interface, where the initial user equipment message is used to notify the core network device that the UE accesses and initializes the UE.
  • the foregoing base station receives a NAS message sent by the core network device for encryption negotiation. After receiving the notification message sent by the base station, the core network device performs an initialization operation on the UE, and sends the NAS message for encryption negotiation to the base station.
  • the foregoing base station sends the NAS message used for the encryption negotiation sent by the core network device to the UE.
  • the base station sends the received NAS message for the encryption negotiation sent by the core network device to the UE through an air interface.
  • the UE and the core network device perform a strong secret on the NAS message that is subsequently exchanged between the UE and the core network device.
  • the foregoing base station may also construct multiple identity request messages to query the identity of the UE.
  • the foregoing base station sends multiple identity request messages until the base station successfully receives the identity response message sent by the UE and performs user identification.
  • the above base station can also be set.
  • the base station may further implement sending multiple identity request messages by setting a plurality of timers.
  • the base station After the base station sends one of the identity request messages, if the base station does not receive the information sent by the UE within the first timer duration, After the identity response message, that is, the base station fails to query the identity of the UE, the base station may send another identity request message to request the identity of the UE until the second timer expires.
  • the foregoing base station may actively identify the UE before the core network device and the UE perform the encrypted NAS information, and does not need to identify the UE through the core network device, so that the device is implemented.
  • the base station side can identify the UE by itself to meet the operation and maintenance requirements of the access network side, and does not need to coordinate the core network side.
  • the base station may perform the identity query on the UE, and may fully utilize the S30 and the S33. The inherent access delay between. The program realizes the order.
  • the foregoing base station uses the identity identifiers of the UE, for example, the IMSI and the IMEI to identify the UE, and does not need to identify the UE by identifying the interface identifier, so that the recognition accuracy of the UE is greatly improved, and the device is realized.
  • a user identification method provided in Embodiment 3 of the present invention includes the following content. 540.
  • the base station establishes an RRC connection with the UE.
  • the process of establishing an RRC connection between the base station and the UE in the prior art is applicable to this embodiment, and details are not described herein again.
  • the foregoing base station sends a notification message to the core network device.
  • the notification message is used to notify the core network device to perform an initialization operation on the UE.
  • the initialization operation includes authentication, encryption, QOS control, and the like for the UE.
  • the notification message may be an initial user equipment message sent by the base station to the core network device through the S1 interface, where the initial user equipment message is used to notify the core network device that the UE accesses and performs an initialization operation on the UE.
  • the foregoing base station sends an identity request message to the UE to request a user identifier of the UE.
  • the identity request message may be a NAS message.
  • the foregoing base station receives an identity response message sent by the UE. After receiving the identity request message sent by the base station, the UE sends an identity response message to the base station.
  • the identity response message can be a NAS message.
  • the identity response message carries the user identity of the UE.
  • the user identifier is used by the base station to identify the UE. As an example, the user identifier may be an IMSI , an IMEI, an IMSI , an IMEI, or the like.
  • the foregoing base station parses and acquires the user identifier of the UE in the identity response message to identify the UE.
  • the base station may also save the user identifier of the UE for subsequent use. Preferably, the base station may also discard the identity response message without sending it to the core network device, thereby saving network resources.
  • the foregoing base station receives the NAS message sent by the core network device for encryption negotiation. After receiving the notification message sent by the foregoing base station to notify the UE to initialize, the core network device performs an initialization operation on the accessed UE. During the encryption process of the initialization operation, the core network device sends a NAS message for encryption negotiation to the base station.
  • the base station transparently transmits the NAS message used for the encryption negotiation sent by the core network device to the UE. After the UE receives the NAS message for the encryption negotiation, the UE and the core network device encrypt the NAS message between the UE and the core network device.
  • the foregoing base station may construct a plurality of foregoing identity request messages to query a user identifier of the UE, for example, by setting a timer and/or a counter.
  • the base station before the receiving, by the base station, the NAS message for the encryption negotiation sent by the core network device, the base station actively completes the identification of the UE, and thus does not need to identify the UE through the core network device. , to achieve the single, can also avoid the coordination difficulties caused by different manufacturers to provide access network equipment and core network equipment.
  • the base station receives the NAS message for the encryption negotiation sent by the core network device in the foregoing S44 before receiving the identity response message sent by the UE, the base station saves the NAS message, and the base station saves the NAS message. It is not sent to the above UE.
  • the base station After the base station identifies the UE, the base station sends the NAS message for encryption negotiation sent by the core network device to the UE.
  • the base station controls the time that the NAS message used for the encryption negotiation is sent to the UE, and ensures that the base station identifies the UE before the encrypted NAS message interaction between the UE and the core network device, and also It does not increase the UE's access time delay to the core network.
  • the base station may also construct a plurality of identity request messages to query the identity of the UE. For details, refer to the related description in the foregoing Embodiment 2, and details are not described herein again. As shown in FIG.
  • Embodiment 4 of the present invention provides an access network device 50, including: a processor 501. Transmitter 502 and receiver 503.
  • the transmitter 502 is configured to send a message to a UE and/or a core network device.
  • the receiver 503 is configured to receive a message sent by the UE and/or the core network device.
  • the processor is configured to control, by the foregoing transmitter, an identity request message sent to the UE to request an identity of the UE, and send the identity sent by the UE to the receiver, before sending the NAS message for the encryption negotiation to the UE.
  • the transmitter is controlled to send a NAS message for encryption negotiation to the UE.
  • the identity response message carries the identity of the UE.
  • the access network device 50 provided in this embodiment may perform the operations performed by the base station in the method in the first embodiment of the present invention. For details, refer to the description in the foregoing method embodiments, and details are not described herein again.
  • the associated access network device 50 may also be provided with some structure for implementing the actions performed by the base station in the method embodiment. Non-limiting examples of such structures may include memory, a microprocessor, circuitry to transmit electronic signals, and the like.
  • Embodiment 5 of the present invention provides an access network device, where the access network device includes a transmitter, a receiver, and a processor.
  • the access network device provided in this embodiment is substantially the same as the access network device in the fourth embodiment.
  • the processor is further configured to: after the receiver receives the identity response message of the UE to the identity request message, send a notification message to the core network device, where the notification message is used to notify the core network device
  • the above UE performs an initialization operation.
  • the processor is further configured to control the receiver to receive the NAS message sent by the core network device for encryption negotiation, and send the NAS message to the UE.
  • the access network device provided in this embodiment may perform the operations performed by the base station in the method according to the second embodiment of the present invention. For details, refer to the description in the foregoing method embodiments, and details are not described herein again.
  • the access network device may further include the structure mentioned in the fourth embodiment.
  • Embodiment 6 of the present invention provides an access network device, where the access network device includes a transmitter, a receiver, and a processor.
  • the access network device provided in this embodiment is substantially the same as the access network device in the fourth embodiment.
  • the processor is further configured to: after the transmitter sends the identity request message, send a notification message to the core network device, where the notification message is used to notify the core network device to perform an initialization operation on the UE. .
  • the processor is further configured to control, after the receiver receives the identity response message, to send, to the UE, the NAS message that is sent by the receiver and sent by the core network device for encryption negotiation.
  • the access network device provided in Embodiment 6 of the present invention may perform the operations performed by the base station in the method according to Embodiment 3 of the present invention. For details, refer to the description in the foregoing method embodiments, and details are not described herein again.
  • the access network device may further include the structure mentioned in the fourth embodiment.
  • a seventh embodiment of the present invention provides a user equipment UE60, including: a receiver 601 and a transmitter 602.
  • the receiver 601 is configured to receive the identity request message sent by the base station.
  • the transmitter 602 is configured to send the identity response message to the base station after receiving the identity request message sent by the base station.
  • the user equipment 60 provided in the seventh embodiment of the present invention may perform the operations performed by the user equipment in the method according to any one of the first embodiment to the third embodiment of the present invention. Narration.
  • the UE may also be provided with some structures, non-limiting examples of which may include a memory, a microprocessor, a circuit that transmits an electronic signal, and the like.
  • the above-mentioned UE cartridge provided by the embodiment of the present invention can be easily implemented by the base station to identify the UE.
  • Embodiment 8 of the present invention further provides a communication system, which is similar to that shown in FIG.
  • the access network device according to any one of Embodiment 4 to Embodiment 6 of the present invention and the user equipment according to Embodiment 7 of the present invention.
  • the device of the communication system can perform the method in any one of the embodiments to the third embodiment of the present invention. For details, refer to the description in the foregoing method embodiments, and details are not described herein again.
  • the communication system provided in the eighth embodiment of the present invention can enable the access network device to actively acquire the user identifier of the user equipment to identify the user equipment without identifying the UE through the core network.
  • Embodiment 9 of the present invention provides a computer program product comprising a storage medium. The code of the method described in any one of Embodiments 1 to 3 is stored in the storage medium.
  • the communication system provided in the ninth embodiment of the present invention can enable the access network device to actively acquire the user identifier of the user equipment to identify the user equipment without identifying the UE through the core network.
  • well-known methods, interfaces, and device signaling techniques have not been described in detail to avoid obscuring the present invention in unnecessary detail.
  • a person skilled in the art may understand that all or part of the steps of implementing the above embodiments may be completed by a program indicating related hardware, and the program may be stored in a computer readable storage medium, the storage medium. Such as: Read-only memory (ROM) or Random Access Memory (RAM), disk, CD, etc.
  • ROM Read-only memory
  • RAM Random Access Memory

Abstract

本发明公开了一种用户识别的方法、设备及系统。该方法中,基站向UE发送由核心网设备发送的用于加密协商的非接入层NAS消息之前,包括:该基站将身份请求消息发送给该UE,该身份请求消息用于请求该UE的用户标识,该用户标识用于该基站识别该UE;该基站接收该UE发送的身份响应消息,该身份响应消息携带该UE的上述用户标识。应用本发明实施例提供的方法,基站可以主动获取UE的用户标识从而识别出UE。

Description

用户识别的方法、 i殳备和系统
技术领域 本发明涉及移动通信领域, 尤其涉及用户识别的技术。 背景技术 在通信系统 (例如对于长期演进(英文为 Long Term Evolution, 筒称 LTE )系统)的运营维护过程中, 用户信息跟踪和呼叫历史记录常被用来监 测和评价贵宾(VIP )服务质量、 处理投诉以及定位问题。 在跟踪指定的用 户设备(英文为 User Equipment, 筒称为 UE ) , 和获取所述 UE的呼叫历史 记录, 或者统计不同厂家的 UE性能等时, 都需要识别 UE。 核心网侧网络节 点, 如移动管理实体(英文为 Mobility Management Entity, 筒称为 MME )可 以识别 UE, 然而 UE和 MME之间通过非接入层(英文为 Non- Access Stratum, 筒称 NAS ) 消息进行交互, 而作为接入网侧网络节点, 如基站, 中继站等 只能透传 NAS消息, 对加密后 NAS消息无法解析, 故而无法识别 UE, 这对 于接入网络侧定位问题、 解决投诉以及监控 VIP业务质量造成很大困难。 发明内容 本发明实施例提供一种用户识别的方法、 设备和系统。 本发明实施例一方面提供一种用户识别的方法。 该方法中, 基站在向 用户设备 UE发送由核心网设备发送的用于加密协商的非接入层 NAS消息 之前, 包括: 上述基站将身份请求消息发送给所述 UE, 上述身份请求消息用于请求 上述 UE的用户标识; 上述基站接收上述 UE发送的身份响应消息, 上述身 份响应消息携带上述 UE的上述用户标识。 应用上述方法, 上述基站主动获取上述用户标识来识别上述 UE, 不需 要核心网配合。 本发明实施例另一方面, 提供一种用户识别的方法。 该方法中, UE接 收身份请求消息, 该身份请求消息是在该基站发送由核心网设备发送的用 于加密协商的 NAS消息之前由该基站所发送的, 该身份请求消息用于请求 该 UE的用户标识, 该用户标识用于该基站识别该 UE; 该 UE向该基站发 送身份响应消息, 该身份响应消息携带该 UE的用户标识。 应用本发明实施例提供的技术方案, 上述 UE可以被上述基站主动识 别, 不需要上述核心网设备配合。 本发明实施例另一方面, 提供一种接入网络设备, 包括: 发射机, 该发射机用于向用户设备 UE和 /或核心网设备发送消息; 接收机, 该接收机用于接收由上述 UE和 /或上述核心网设备发送的消 息; 处理器,该处理器用于控制该发射机在向上述 UE发送用于加密协商的 NAS消息之前, 向上述 UE发送身份请求消息, 该身份请求消息用于请求 所述 UE的身份标识;上述处理器还用于在上述接收机接收由上述 UE发送 的身份响应消息后,控制上述发射机在向上述 UE发送用于加密协商的 NAS 消息, 上述身份响应消息携带上述 UE的身份标识。 应用上述接入网络设备, 可以主动获取上述 UE的用户标识,从而识别 UE, 不需要核心网设备配合。 本发明实施例另一方面, 提供一种用户设备, 包括: 接收机, 该接收机用于接收由基站发送的身份请求消息, 该身份请求 消息用于请求上述用户设备的身份标识。 发射机, 该发射机用于在上述接收机接收到上述基站发送上述身份请 求消息后, 向上述基站发送身份响应消息, 该身份响应消息携带上述用户 设备的上述身份标识。
而识别出上述 UE, 不需要核心网设备配合。 本发明实施例另一方面, 提供一种通信系统。 该通信系统包括上述接 入网络设备和上述用户设备。 该通信系统执行上述用户识别的方法。 应用上述通信系统, 可以使得上述接入网络设备主动获取上述用户设 备的用户标识而识别出上述用户设备。 本发明实施例另一方面, 提供一种计算机程序产品。 该计算机程序产 品包括存储介质, 该存储介质中存储实现上述用户识别的方法的代码。 应用上述计算机程序产品, 可以使得上述接入网络设备主动获取上述 用户设备的用户标识而识别出上述用户设备。 附图说明 图 1为本发明实施例的系统架构示意图; 图 2为本发明实施例一提供的一种用户识别的方法的流程示意图; 图 3为本发明实施例二提供的一种用户识别的方法的的流程示意图; 图 4为本发明实施例三提供的一种用户识别的方法的的流程示意图; 图 5为本发明实施例四至实施例六提供的一种接入网络设备的结构示 意图; 图 6为本发明实施例七提供的一种用户设备的结构示意图; 具体实施方式 下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案进 行清楚、 完整地描述。 显然, 如下描述的具体实施例仅是本发明的一部分 实施例, 本发明还可以不拘泥于这些特定的细节的其它实施例来实施。 例 如, 本发明的技术方案是基于 LTE系统架构的进行描述的, 但本发明不限 于实施例中描述的通信系统架构, 本发明还可用于宽带码分多址接入(英 文为 Wideband Code Division Multiple Access, 筒称 WCDMA ) 系统, 以及 后续演进系统中。 图 1为本发明的实施例所基于的通信系统架构图。 UE、 基站 (例如演 进基站(英文为 evolution Node B , 筒称 eNB ) )和核心网设备 (例如 MME ) 组成的通信系统中,上述 UE与上述基站通过空口进行信息的交互,上述基 站与上述核心网设备之间通过 S1口进行信息的交互, 上述基站之间是通过 X2口进行信息的交互的。 在用户控制面, 上述 UE与上述核心网设备通过 NAS消息进行信息的传递时, 作为接入网侧的基站用于转发该 NAS消息。 如图 2所示, 本发明的实施例一提供的一种用户识别方法。 该方法是 在基站建立与 UE的无线资源控制连接后进行的, 包括:
521 , 基站发送身份请求消息给 UE。 该身份请求消息用于请求该 UE 的用户标识。
522, 上述基站接收该 UE发送的身份响应消息。 该 UE收到上述身份请求消息以后, 向上述基站发送身份响应消息。该 身份响应消息携带着该 UE的用户标识。上述基站解析并获取该身份响应消 息中的该 UE的用户标识, 并根据所述用户标识识别所述 UE。 可选地, 所 述基站也可以保存所述用户标识供后续使用。 S23 , 上述基站向上述 UE发送由核心网设备发送的用于加密协商的 NAS消息。 上述基站在向 UE发送由上述核心网设备发送给上述基站的用于加密 协商的 NAS消息前,完成上述基站查询该 UE身份的过程 (例如, 步骤 S21 和 S22 )。 应用本发明的实施例一提供的技术方案,在上述基站和上述 UE的 RRC 连接建立完成之后, 核心网设备和 UE加密协商 NAS消息之前, 完成基站 查询 UE的身份,可以使基站获取 UE的用户标识,而不依赖于核心网设备。 如图 3所示, 本发明的实施例二提供的一种用户识别方法, 包括以下 内容。
530, 基站建立与 UE的 RRC连接。 现有技术中基站和 UE建立 RRC连接的过程适用于本实施例, 此处不 再赘述。
531 , 上述基站发送身份请求消息给上述 UE。 该身份请求消息用于请 求该 UE的用户标识。作为一个例子,所述身份请求消息可以为 NAS消息。
532, 上述基站接收该 UE发送的身份响应消息。 该 UE收到上述基站发送的身份请求消息后,向上述基站发送身份响应 消息。 作为一个例子, 所述身份响应消息可以为 NAS消息。 该身份响应消 息携带着该 UE的用户标识。 所述用户标识用于所述基站识别所述 UE。 作 为一个例子, 所述用户标识可以是国际移动用户标识(英文为 International Mobile Subscribe Identity, 筒称 IMSI ), 也可以是国际移动设备标识(英文 为 International Mobile Equipment, 筒称 IMEI ),也可以 IMSI和 IMEI等等。 上述基站解析并获取该身份响应消息中的上述 UE的用户标识,识别出 上述 UE。 上述基站还可以保存上述 UE的用户标识供后续使用。 较佳地, 所述基站还可以将所述身份响应消息丟弃, 而不发给核心网 设备, 从而节省网络资源。
533 , 上述基站向核心网设备发送通知消息。 所述通知消息用于通知核心网设备对所述 UE进行初始化操作。所述初 始化操作包括对 UE进行鉴权、加密和服务质量(英文为 Quality Of Service, 筒称 QOS )控制等等。 作为一个例子, 该通知消息可以是基站通过 S1口向 核心网设备发送初始化用户设备消息, 该初始化用户设备消息用于通知上 述核心网设备有 UE接入并对该 UE进行初始化操作。
534, 上述基站接收由该核心网设备发送的用于加密协商的 NAS消息。 该核心网设备接收到基站发送的通知消息后, 该核心网设备对上述 UE 进行初始化操作, 并向上述基站发送该用于加密协商的 NAS消息。
535 , 上述基站将由核心网设备发送的该用于加密协商的 NAS 消息发 送给 UE。 上述基站将接收到的由核心网设备发送的该用于加密协商的 NAS 消 息, 通过空口发送给该 UE。 该 UE接收到该用于加密协商的 NAS消息后, 该 UE和该核心网设备对后续该 UE与该核心网设备之间交互的 NAS消息 进行力口密。 可选地,上述基站也可以构造多条上述身份请求消息查询 UE的身份标 识。 例如, 上述基站发送多条身份请求消息, 直到上述基站成功接收到上 述 UE发送的身份响应消息并进行用户识别为止。例如也可以设置上述基站 发送上述身份请求消息的次数门限, 在所述次数门限内, 如果上述基站收 到上述 UE发送的身份响应消息, 则不再发送身份请求消息;如果在次数门 限内,如果上述基站没有收到上述 UE发送的身份响应消息,则上述基站再 次发送身份请求消息给上述 UE, 直到发送次数达到所述次数门限。 如果上 述基站发送的身份请求消息达到次数门限,还没有收到上述 UE的身份响应 消息, 则视为 UE连接失败。 例如, 上述基站还可以通过设置多个定时器来 实现多条身份请求消息的发送, 当上述基站发送一条上述身份请求消息后, 如果在第一定时器时长内, 没有收到上述 UE发送回来的身份响应消息后, 也就是上述基站查询该 UE的身份失败,该基站可再发送一条上述身份请求 消息, 请求该 UE的身份标识, 直到所述第二定时器期满。 应用本发明的实施例二提供的技术方案, 上述基站可以在核心网设备 与 UE进行加密 NAS信息之前主动识别上述 UE, 而无需再通过核心网设 备来识别 UE, 使得实现筒单。 尤其对于当核心网设备与基站设备属于不同 厂家时对接困难时,基站侧可以自行识别 UE从而满足接入网络侧的运营维 护需求, 而无需再协调核心网络侧, 筒单易行。 进一步地, 本实施例中上述基站是在 RRC连接建立完成后, 且基站通 知核心网设备有上述 UE接入并进行初始化操作之前,对上述 UE的进行身 份查询, 可以充分利用了 S30与 S33之间的固有的接入时延。 方案实现筒 单。 进一步地,本实施例中上述基站利用 UE的身份标识,例如 IMSI和 IMEI 对 UE进行识别, 而无需通过识别接口标识来识别 UE , 使得对 UE的识别 准确度大大提高, 且实现筒单。 如图 4所示, 本发明的实施例三提供的一种用户识别方法, 包括以下 内容。 540, 基站与 UE建立 RRC连接。 现有技术中基站与 UE建立 RRC连接的过程适用于本实施例, 此处不 再赘述。
541 , 上述基站向核心网设备发送通知消息。 所述通知消息用于通知核心网设备对上述 UE进行初始化操作。所述初 始化操作包括对上述 UE进行鉴权、加密和 QOS控制等等。作为一个例子, 该通知消息可以是上述基站通过 S1口向核心网设备发送的初始化用户设备 消息, 该初始化用户设备消息用于通知上述核心网设备有 UE接入并对该 UE进行初始化操作。
542,上述基站发送身份请求消息给该 UE用于请求该 UE的用户标识。 作为一个例子, 所述身份请求消息可以为 NAS消息。
543 , 上述基站接收该 UE发送的身份响应消息。 该 UE在收到上述基站发送的身份请求消息后,向上述基站发送身份响 应消息。 作为一个例子所述身份响应消息可以为 NAS消息。 该身份响应消 息携带着该 UE的用户标识。 所述用户标识用于所述基站识别所述 UE。 作 为一个例子,所述用户标识可以 IMSI,也可以是 IMEI,也可以 IMSI和 IMEI 等等。 上述基站解析并获取该身份响应消息中的该 UE 的用户标识识别出所 述 UE。 所述基站还可以保存该 UE的用户标识供后续使用。 较佳地, 所述基站还可以将所述身份响应消息丟弃, 而不发给核心网 设备, 从而节省网络资源。
544, 上述基站接收由核心网设备发送的用于加密协商的 NAS消息。 该核心网设备接收到由上述基站发送来的用于通知对 UE进行初始化 的通知消息后,会对接入的 UE进行初始化操作。在进行初始化操作的加密 过程中, 该核心网设备会向上述基站发送用于加密协商的 NAS消息。
S45, 上述基站将该由核心网设备发送的该用于加密协商的 NAS 消息 透传给上述 UE。 上述 UE接收到该用于加密协商的 NAS消息后, 该 UE和该核心网设 备对后续该 UE与核心网设备之间的 NAS消息进行加密。 可选地, 类似与第二实施例中的 S31 , 上述基站可以构造多条上述身份 请求消息查询 UE的用户标识, 例如可以通过设置定时器和 /或记数器来实 现。 应用本发明实施例三提供的技术方案, 在上述基站在接收到所述核心 网设备发送的用于加密协商的 NAS消息之前, 主动完成对 UE的识别, 进 而无需再通过核心网设备来识别 UE, 实现筒单, 也可避免了因不同厂家提 供接入网设备及核心网设备而造成的协调上的困难。 作为一个例子, 如果上述基站在收到上述 UE发送的身份响应消息之 前, 上述基站接收到上述 S44中核心网设备发送的用于加密协商的 NAS消 息, 则上述基站对上述 NAS消息进行保存, 而暂不发送给上述 UE。 直到 上述基站识别出上述 UE以后,上述基站才将由核心网设备发送的该用于加 密协商的 NAS消息发送给上述 UE。 本实施例提供的技术方案中, 基站控 制用于加密协商的 NAS消息下发给 UE的时间, 可确保在 UE与核心网设 备间进行加密 NAS消息交互前, 实现基站对 UE进行识别, 而且也不会增 加 UE对核心网的接入时间延迟。 可选地, 在本实施例中所述基站也可以构造多条身份请求消息查询所 述 UE的身份标识, 具体可参照上述实施例二的相关描述, 在此不再赘述。 如图 5所示, 本发明的实施例四提供一种接入网络设备 50, 包括: 处理器 501、 发射机 502和接收机 503。 上述发射机 502用于向 UE和 /或核心网络设备发送消息。 上述接收机 503用于接收 UE和 /或核心网络设备发送的消息。上述处理器用于控制上述 发射机在向上述 UE发送用于加密协商的 NAS消息之前, 向上述 UE发送 身份请求消息用于请求上述 UE的身份标识,并且在上述接收机接收由上述 UE发送的身份响应消息后, 控制上述发射机在向上述 UE发送用于加密协 商的 NAS消息。 上述身份响应消息携带上述 UE的身份标识。 本实施例提供的接入网络设备 50可以执行本发明的实施例一中所述方 法中基站所执行的动作, 具体可参照上述方法实施例中的描述, 在此不再 赘述。所属接入网络设备 50除了上述发射机 502,接收机 503和处理器 501 之外, 为实现方法实施例中的基站所执行的动作, 也可以设置一些结构。 这类结构的非限制性示例可以包括存储器, 微处理器, 发送电子信号的电 路等等。 本发明的实施例五提供一种接入网络设备, 上述接入网络设备包括发 射机, 接收机和处理器。 本实施例中所提供的接入网络设备与实施例四中 的接入网络设备大致相同。 进一步地, 上述处理器还用于控制上述发射机 在上述接收机接收上述 UE对上述身份请求消息的身份响应消息后向上述 核心网设备发送通知消息, 该通知消息用于通知上述核心网络设备对上述 UE进行初始化操作。上述处理器还用于控制上述接收机接收上述核心网设 备发送的用于加密协商的 NAS消息, 并将该 NAS消息发送给上述 UE。 本 实施例提供的接入网络设备可以执行本发明的实施例二所述的方法中基站 所执行的动作, 具体可参照上述方法实施例中的描述, 在此不再赘述。 为 了实现方法实施例中的步骤, 所述接入网络设备还可以包括第四实施例中 所提到的结构。 本发明的实施例六提供一种接入网络设备, 上述接入网络设备包括发 射机, 接收机和处理器。 本实施例中所提供的接入网络设备与实施例四中 的接入网络设备大致相同。 进一步地, 所述处理器还用于控制上述发射机 在上述发射机机发送上述身份请求消息前, 向上述核心网络设备发送通知 消息,该通知消息用于通知上述核心网络设备对 UE进行初始化操作。所述 处理器还用于控制上述发射机在上述接收机接收到上述身份响应消息后, 向上述 UE发送上述接收机接收到的由上述核心网设备发送的用于加密协 商的 NAS消息。 本发明的实施例六提供的接入网络设备可以执行本发明的实施例三所 述方法中基站所执行的动作, 具体可参照上述方法实施例中的描述, 在此 不再赘述。 为了实现方法实施例中的步骤, 所述接入网络设备还可以包括 第四实施例中所提到的结构。 如图 6所示, 本发明的实施例七提供了一种用户设备 UE60, 包括: 接 收机 601和发射机 602。上述接收机 601用于接收由基站发送的上述身份请 求消息。 上述发射机 602用于上述接收机 601接收到由基站发送的上述身 份请求消息后, 向上述基站发送身份响应消息。 本发明的实施例七提供的用户设备 60可以执行本发明的实施例一至实 施例三任一个所述方法中用户设备所执行的动作, 具体可参照上述方法实 施例中的描述, 在此不再赘述。 为了实现方法实施例中的步骤, 所述 UE 还可以设置一些结构, 这些结构的非限制性示例可以包括存储器, 微处理 器, 发送电子信号的电路等等。 本发明实施例提供的上述 UE筒单, 可以配合基站识别该 UE, 易于实 现。 本发明实施例八还提供一种通信系统, 该通信系统与图 1 所示类似, 包括: 本发明的实施例四至实施例六任意一个所述的接入网络设备和本发 明的实施例七所述的用户设备。 该通信系统的设备可以执行本发明的实施 例一至实施例三任一实施例所述方法, 具体可参照上述方法实施例中的描 述, 在此不再赘述。 本发明实施例八提供的通信系统, 可以使得上述接入网络设备主动获 取上述用户设备的用户标识而识别出上述用户设备, 而无需通过核心网来 识别 UE。 本发明的实施例九提供一种计算机程序产品, 该计算机程序产品包含 存储介质。 该存储介质中存储实施例一至实施例三任意一个实施例所述的 方法的代码。 本发明实施例九提供的通信系统, 可以使得上述接入网络设备主动获 取上述用户设备的用户标识而识别出上述用户设备, 而无需通过核心网来 识别 UE。 在某些实施例中, 对于熟知的方法、 接口、 设备信令技术未进行具体 描述, 以免因不必要的细节使得本发明模糊。 本领域普通技术人员可以理 解实现上述实施例方法中的全部或者部分步骤是可以通过程序来指示相关 的硬件来完成, 所述的程序可以存储与一计算机可读存储介质中, 所述的 存储介质, 如: 只读存储记忆体(Read-only Memory, ROM )或随机存储 记忆体(Random Access Memory, RAM )、 磁碟、 光盘等。 以上所述的具体 实施方式, 对本发明的目的、 技术方案和有益效果进行了进一步详细说明, 所应理解的是, 以上所述仅为本发明的具体实施方式而已, 并不用于限定 本发明的保护范围, 本领域技术人员在不付出创造性劳动的基础上, 所做 的任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。

Claims

1、 一种用户识别的方法, 其特征在于, 基站在向用户设备 UE发送由 核心网设备发送的用于加密协商的非接入层 NAS消息之前, 包括: 所述基站向所述 UE发送身份请求消息,所述身份请求消息用于请求所 述 UE的用户标识; 所述基站接收所述 UE发送的身份响应消息,所述身份响应消息携带所 述 UE的所述用户标识。
2、 如权利要求 1所述的方法, 其特征在于, 所述基站接收所述 UE发 送的所述身份响应消息之后,所述基站在向所述 UE发送由所述核心网设备 发送的所述用于加密协商的 NAS消息之前, 还包括: 所述基站向所述核心网设备发送通知消息, 所述通知消息用于通知所 述核心网设备对所述 UE进行初始化操作。
3、 如权利要求 1所述的方法, 其特征在于, 所述基站将所述身份请求 消息发送给所述 UE之前, 还包括: 所述基站向所述核心网设备发送通知消息, 所述通知消息用于通知所 述核心网设备对所述 UE进行初始化操作。
4、 如权利要求 3所述的方法, 其特征在于, 所述基站向所述核心网设 备发送所述通知消息之后,所述基站向所述 UE发送由所述核心网设备发送 的用于加密协商的所述 NAS消息之前, 还包括: 所述基站接收所述核心网设备发送的用于加密协商的 NAS消息。
5、 如权利要求 1至 4任意一项所述的方法, 其特征在于, 当所述基站 在接收由所述 UE发送的身份响应消息之前,如果所述基站接收到由所述核 心网设备发送的用于加密协商的 NAS消息, 所述基站保存所述用于加密协 商的 NAS消息。
6、 如权利要求 1至 5任意一项所述的方法, 其特征在于, 所述用户标 识为所述 UE的国际移动用户标识 IMSI , 和 /或, 国际移动设备标识 IMEI。
7、 如权利要求 1至 6任意一项所述的方法, 其特征在于, 所述身份请 求消息和所述身份响应消息为 NAS消息。
8、 一种用户识别的方法, 其特征在于, 用户设备 UE接收基站发送的身份请求消息,所述身份请求消息是在所 述基站发送由核心网设备发送的用于加密协商的非接入层 NAS消息之前由 所述基站所发送的,所述身份请求消息用于请求所述 UE的用户标识,所述 用户标识用于所述基站识别所述 UE; 所述 UE 向所述基站发送身份响应消息, 所述身份响应消息携带所述 UE的所述用户标识。
9、 如权利要求 8所述的方法, 其特征在于, 所述用户标识为所述 UE 的国际移动用户标识 IMSI, 和 /或, 国际移动设备标识 IMEI。
10、 如权利要求 8或 9所述的方法, 其特征在于, 所述身份请求消息 和所述身份响应消息为 NAS消息。
11、 一种接入网络设备, 其特征在于, 包括: 发射机, 所述发射机用于向用户设备 UE和 /或核心网设备发送消息; 接收机, 所述接收机用于接收由所述 UE和 /或所述核心网设备发送的 消息; 处理器,所述处理器用于控制所述发射机在向所述 UE发送用于加密协 商的 NAS消息之前, 向所述 UE发送身份请求消息, 所述身份请求消息用 于请求所述 UE 的身份标识; 所述处理器还用于在所述接收机接收由所述 UE发送的身份响应消息后, 控制所述发射机在向所述 UE发送用于加密协 商的 NAS消息, 所述身份响应消息携带所述 UE的身份标识。
12、 如权利要求 11所述的接入网络设备, 其特征在于, 所述处理器还用于控制所述发射机在所述接收机接收所述 UE发送的 所述身份响应消息后, 向所述核心网设备发送通知消息, 所述通知消息用 于通知所述核心网设备对所述 UE进行初始化操作。
13、 如权利要求 12所述的接入网络设备, 其特征在于, 所述处理器还用于控制所述发射机在所述接收机接收所述 UE发送的 所述身份响应消息前, 向所述核心网设备发送通知消息, 所述通知消息用 于通知所述核心网设备对所述 UE进行初始化操作。
14、 如权利要求 13所述的接入网络设备, 其特征在于, 所述处理器还用于控制所述发射机在所述接收机接收到所述身份响应 消息后,向所述 UE发送所述接收机接收到的由上述核心网设备发送的所述 用于加密协商的 NAS消息。
15、 如权利要求 11至 14任意一项所述的接入网络设备, 其特征在于, 所述用户标识为所述用户设备的国际移动用户标识 IMSI, 和 /或, 国际移动 设备标识 IMEI。
16、 如权利要求 11至 15任意一项所述的接入网络设备, 其特征在于, 所述身份请求消息和所述身份响应消息为 NAS消息。
17、 一种用户设备, 其特征在于, 包括: 接收机, 所述接收机用于接收由基站发送的身份请求消息, 所述身份 请求消息用于请求所述用户设备的身份标识。 发射机, 所述发射机用于在所述接收机接收到所述基站发送所述身份 请求消息后, 向所述基站发送身份响应消息, 所述身份响应消息携带所述 用户设备的所述身份标识。
18、 一种通信系统, 其特征在于, 包括: 如权利要求 11至 16任一项 所述的接入网络设备和如权利要求 17所述的用户设备。
19、 一种计算机程序产品, 其特征在于, 包含: 存储介质, 所述存储 介质存储如权利要求 1至 10任意一项所述的方法的代码。
PCT/CN2011/084308 2011-12-21 2011-12-21 用户识别的方法、设备和系统 WO2013091179A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201180071128.1A CN103609153B (zh) 2011-12-21 2011-12-21 用户识别的方法、设备和系统
PCT/CN2011/084308 WO2013091179A1 (zh) 2011-12-21 2011-12-21 用户识别的方法、设备和系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/084308 WO2013091179A1 (zh) 2011-12-21 2011-12-21 用户识别的方法、设备和系统

Publications (1)

Publication Number Publication Date
WO2013091179A1 true WO2013091179A1 (zh) 2013-06-27

Family

ID=48667639

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/084308 WO2013091179A1 (zh) 2011-12-21 2011-12-21 用户识别的方法、设备和系统

Country Status (2)

Country Link
CN (1) CN103609153B (zh)
WO (1) WO2013091179A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105519040B (zh) 2014-11-05 2019-08-20 华为技术有限公司 用户设备管理方法、设备及系统
CN108024301B (zh) * 2016-11-04 2022-07-26 夏普株式会社 基站、用户设备及其执行的方法

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101473565A (zh) * 2006-06-21 2009-07-01 Lg电子株式会社 在无线移动通信系统中使用消息分离发送和接收无线电接入信息的方法
CN101945379A (zh) * 2009-07-10 2011-01-12 华为技术有限公司 获取用户永久标识的方法和接入网设备
WO2011139056A2 (ko) * 2010-05-03 2011-11-10 삼성전자 주식회사 이동 통신 시스템에서 단문 메시지 서비스 메시지 전달 방법 및 시스템

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101033556B1 (ko) * 2003-07-10 2011-05-11 엘지전자 주식회사 이동통신 시스템의 국제 이동국 식별자 및 그를 이용한 이동 네트워크 식별 방법
CN101765216B (zh) * 2008-12-23 2012-07-25 大唐移动通信设备有限公司 一种实现用户接入的控制方法、装置和系统
CN101945503B (zh) * 2010-09-06 2014-04-16 华为技术有限公司 获取用户标识的方法和基站控制器

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101473565A (zh) * 2006-06-21 2009-07-01 Lg电子株式会社 在无线移动通信系统中使用消息分离发送和接收无线电接入信息的方法
CN101945379A (zh) * 2009-07-10 2011-01-12 华为技术有限公司 获取用户永久标识的方法和接入网设备
WO2011139056A2 (ko) * 2010-05-03 2011-11-10 삼성전자 주식회사 이동 통신 시스템에서 단문 메시지 서비스 메시지 전달 방법 및 시스템

Also Published As

Publication number Publication date
CN103609153B (zh) 2017-12-15
CN103609153A (zh) 2014-02-26

Similar Documents

Publication Publication Date Title
US11889405B2 (en) Handling a UE that is in the idle state
JP6700434B2 (ja) 無線通信方法及びデバイス
RU2019124694A (ru) Пользовательское оборудование и базовая станция, участвующие в процедуре обновления сети с радиодоступом
US10798082B2 (en) Network authentication triggering method and related device
TWI664864B (zh) 處理系統間行動中的新無線連結的裝置及方法
JP2018523339A (ja) ワイヤレス通信ネットワークにおいて無線アクセスネットワーク(ran)コンテキスト情報を扱うためのネットワークノード、ワイヤレスデバイス及びそれらにおける方法
US10812973B2 (en) System and method for communicating with provisioned security protection
WO2016021817A1 (ko) 무선 통신 시스템에서 단말을 인증 하는 방법 및 이를 위한 장치
TWI657679B (zh) 處理系統間行動中的封包資料流的裝置及方法
EP3777280B1 (en) Security verification when resuming an rrc connection
WO2013181847A1 (zh) 一种无线局域网接入鉴权方法、设备及系统
WO2012109987A1 (zh) 一种连接建立方法及装置
WO2015089735A1 (zh) 一种用户设备能力获取方法及系统、设备
WO2013071829A1 (zh) 一种小区切换控制方法、相关设备以及通信系统
WO2016061735A1 (zh) 一种接入网络的方法以及相关装置
WO2018166338A1 (zh) 一种秘钥更新方法及装置
WO2013056676A1 (zh) 处理上下文的方法及设备
TWI531257B (zh) 無線通訊系統及其認證方法
WO2012003721A1 (zh) 基于网络共享资源管理的方法及系统
WO2017128306A1 (zh) 通信方法及设备
TWI650026B (zh) Data transmission method, first device and second device
WO2013091179A1 (zh) 用户识别的方法、设备和系统
WO2013044764A1 (zh) 上行信号的发送时间确定方法及设备
JPWO2021015502A5 (zh)
KR20100021690A (ko) 이동 통신 시스템의 인증과 비계층 프로토콜 보안 운영을 효율적으로 지원하는 관리 방법 및 시스템

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11877678

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11877678

Country of ref document: EP

Kind code of ref document: A1