WO2013131483A1 - 一种WiFi终端接入分组数据PS业务域的方法和可信网关 - Google Patents

一种WiFi终端接入分组数据PS业务域的方法和可信网关 Download PDF

Info

Publication number
WO2013131483A1
WO2013131483A1 PCT/CN2013/072277 CN2013072277W WO2013131483A1 WO 2013131483 A1 WO2013131483 A1 WO 2013131483A1 CN 2013072277 W CN2013072277 W CN 2013072277W WO 2013131483 A1 WO2013131483 A1 WO 2013131483A1
Authority
WO
WIPO (PCT)
Prior art keywords
wifi terminal
connection
address
trusted gateway
pdp context
Prior art date
Application number
PCT/CN2013/072277
Other languages
English (en)
French (fr)
Inventor
李建
王兵
郑磊斌
李嫒霞
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to JP2014560236A priority Critical patent/JP5903728B2/ja
Priority to EP13757311.9A priority patent/EP2816863B1/en
Publication of WO2013131483A1 publication Critical patent/WO2013131483A1/zh
Priority to US14/478,576 priority patent/US9736157B2/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/02Details
    • H04L12/14Charging, metering or billing arrangements for data wireline or wireless communications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M15/00Arrangements for metering, time-control or time indication ; Metering, charging or billing arrangements for voice wireline or wireless communications, e.g. VoIP
    • H04M15/80Rating or billing plans; Tariff determination aspects
    • H04M15/8027Rating or billing plans; Tariff determination aspects based on network load situation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M15/00Arrangements for metering, time-control or time indication ; Metering, charging or billing arrangements for voice wireline or wireless communications, e.g. VoIP
    • H04M15/82Criteria or parameters used for performing billing operations
    • H04M15/8214Data or packet based
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M15/00Arrangements for metering, time-control or time indication ; Metering, charging or billing arrangements for voice wireline or wireless communications, e.g. VoIP
    • H04M15/93Arrangements for metering, time-control or time indication ; Metering, charging or billing arrangements for voice wireline or wireless communications, e.g. VoIP using near field or similar technologies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/24Accounting or billing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/12Setup of transport tunnels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • H04L61/5014Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method and a trusted gateway for a WiFi terminal to access a packet data PS service domain. Background technique
  • WLANs Wireless Local Access Network
  • 3GPP R6 TS23.234 defined access to the carrier-owned PS (Packet Switch) service domain through WLAN, but in this scheme, the WiFi terminal needs to establish a special tunnel with the packet data gateway, and The user first performs two authentications, including authentication of the radio access network and authentication of the packet data gateway. In this way, the WiFi terminal must support a scheme of establishing a tunnel with the packet data gateway, thereby increasing the load on the WiFi terminal, increasing the cost of the WiFi terminal, and the operation of the WiFi terminal is complicated. Summary of the invention
  • the embodiments of the present invention provide a method for a WiFi terminal to access a packet data PS service domain and a trusted gateway, which are used to solve the problem that the WiFi terminal is overloaded and the WiFi terminal cost is too high in the prior art.
  • embodiments of the present invention use the following technical solutions:
  • a method for a WiFi terminal to access a packet data PS service domain is applied to a trusted gateway, where the trusted gateway communicates with a wireless local area network and a communication device in a PS service domain, and the method includes:
  • the trusted gateway After receiving the charging request message or the DHCP request message, according to the attribute information of the WiFi terminal, the trusted gateway establishes a first packet data protocol PDP context connection or a first group with the PS service domain.
  • Data network PDN connection making the WiFi terminal Ending, by the WLAN server, the trusted gateway and the established first PDP context connection or the first PDN connection to access the PS service domain; wherein, the attribute information of the WiFi terminal is obtained from the AAA server,
  • the first PDP context connection or the first PDN connection between the PS service domain and the PS service domain is established by the trusted gateway for the WiFi terminal to access the PS service domain.
  • a trusted terminal of a WiFi terminal accessing a packet data PS service domain the trusted gateway communicating with a wireless local area network and a communication device in a PS service domain, where the trusted gateway includes: a receiving unit, configured to receive authentication and authorization And an accounting request message sent by the accounting AAA server or a dynamic host setting protocol DHCP request message sent by the WiFi terminal;
  • a connection establishing unit configured to: after receiving the charging request message or the DHCP request message, the trusted gateway establishes a first packet data protocol PDP according to the attribute information of the WiFi terminal, and the PS service domain a context connection or a first packet data network PDN connection, such that the WiFi terminal accesses the PS service domain through the wireless local area network, the trusted gateway, and the established first PDP context connection or the first PDN connection;
  • the attribute information of the WiFi terminal is obtained from the AAA server, and is used by the trusted gateway to establish a first PDP context connection or a first PDN connection between the PS service domain and the PS service domain.
  • the method for accessing the PS service domain by the WiF terminal provided by the embodiment of the present invention and the trusted gateway, where the trusted gateway receives the AAA (Authentication, Authorization, Accounting, Authentication, Authorization, and Accounting) server Establishing a first PDP (Packet Data Protocol) connection or a first PDN (Packet Data Network) after the fee request message or the DHCP (Dynamic Host Configuration Protocol) request message sent by the WiFi terminal , the packet data network is connected, so that the trusted gateway is used as an access point for accessing the PS service domain, and the WiFi terminal can access the PS service domain through a wireless local area network, a trusted gateway, and an established PDP context connection or a PDN connection.
  • the WiFi terminal does not need to perform two authentications, which reduces the load of the WiFi terminal and reduces the complexity and cost of the operation of the WiFi terminal.
  • FIG. 1 is a flowchart of a method for a WiFi terminal to access a PS service domain according to Embodiment 1 of the present invention
  • FIG. 2 is a flowchart of a method for a WiFi terminal to access a PS service domain according to Embodiment 2 of the present invention
  • FIG. 3 is a flowchart of another method for a WiFi terminal to access a PS service domain according to Embodiment 3 of the present invention
  • FIG. 4 is a flowchart of still another method for a WiFi terminal to access a PS service domain according to Embodiment 4 of the present invention
  • FIG. 5 is a flowchart of a method for accessing a PS service domain by a WiFi terminal according to Embodiment 5 of the present invention
  • FIG. 6 is a structural block diagram of a trusted gateway for accessing a PS service domain by a WiFi terminal according to Embodiment 6 of the present invention; ;
  • FIG. 7 is a structural block diagram of another trusted gateway of a WiFi terminal accessing a PS service domain according to Embodiment 6 of the present invention.
  • FIG. 8 is a structural block diagram of another trusted gateway for accessing a PS service domain by a WiFi terminal according to Embodiment 6 of the present invention.
  • FIG. 9 is a structural block diagram of another trusted gateway for accessing a PS service domain by a WiFi terminal according to Embodiment 6 of the present invention.
  • the embodiment of the invention provides a method for a WiFi terminal to access a PS service domain, which is applied to a trusted gateway, wherein the trusted gateway communicates with a wireless local area network and a communication device in the PS service domain.
  • the method includes:
  • the trusted gateway receives the accounting request message sent by the AAA server or the dynamic host setting protocol DHCP request message sent by the WiFi terminal.
  • the trusted gateway After authenticating the WiFi terminal, the trusted gateway receives the charging request message sent by the AAA server or the DHCP request message sent by the WiFi terminal.
  • the charging request message or the DHCP request message is used to trigger the trusted gateway to establish a first PDP context connection or a first PDN connection with the P S service domain.
  • the trusted gateway After receiving the charging request message or the DHCP request message, the trusted gateway establishes a first packet data protocol PDP context connection or the first data packet according to the attribute information of the WiFi terminal. a packet data network PDN connection, such that the WiFi terminal accesses the PS service domain through the wireless local area network, the trusted gateway, and the established first PDP context connection or the first PDN connection; wherein, the WiFi terminal
  • the attribute information is obtained from the AAA server, and is used by the trusted gateway to establish a first PDP context connection or a first PDN connection between the PS service domain and the PS service domain.
  • Attribute information of the WiFi terminal may include: a second terminal of the IP address of the WiFi, IMSI (International Mobile Subscriber Identification, international mobile subscriber identification code further 1 J), first the APN (Name Access Point Name, an access point), The WiFi terminal QOS (quality of service), the NAS-ID (Network Access Server-Identity) of the AC (Access Controller) that manages the WiFi terminal.
  • IMSI International Mobile Subscriber Identification, international mobile subscriber identification code further 1 J
  • APN Name Access Point Name, an access point
  • the WiFi terminal QOS quality of service
  • the NAS-ID Network Access Server-Identity
  • AC Access Controller
  • the first APN or the QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection or the first PDN connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the trusted gateway In the second generation or the third generation communication network, after the trusted gateway receives the charging request message or the DHCP request message, according to the attribute information of the WiFi terminal, the trusted gateway establishes and The first PDP context connection of the first GGSN (Gateway GPRS Support Node, Gateway General Packet Radio Service Support Node) corresponding to the first APN.
  • the trusted gateway In the LTE communication network, after the trusted network receives the charging request message or the DHCP request message, the trusted gateway establishes a corresponding to the first APN according to the attribute information of the WiFi terminal.
  • the first PDN connection of a P-GW PDN Gateway, Packet Data Network Gateway).
  • the method for accessing the PS service domain by the W i F i terminal and the trusted gateway provided by the embodiment of the present invention, the trusted gateway receiving the charging request message sent by the AAA server or the DHCP request sent by the WiFi terminal
  • the first GPSN corresponding to the first access point name establishes a first PDP context connection or establishes a first PDN connection with the P-GW corresponding to the first access point name, and obtains the first The first IP address assigned by the GGSN or the first P-GW to the WiFi terminal, so that the trusted gateway serves as an access point for accessing the PS service domain, and the WiFi terminal can be established through a wireless local area network, a trusted gateway, and
  • the PDP context connection or the PDN connection accesses the PS service domain, so that there is no need to establish a special tunnel between the terminal and the trusted gateway, and the WiFi terminal does not need to perform two authentications, which reduces the load of the WiFi terminal and reduces the WiFi terminal.
  • the second embodiment or the third generation communication network is taken as an example, as shown in FIG. 2, the method for accessing the PS service domain by the WiFi terminal provided by the embodiment of the present invention is as follows: As shown, the trusted gateway receives the charging request message sent by the AAA server, and the trusted gateway establishes a first PDP context connection with the first GGSN, which specifically includes:
  • the AC authenticates the WiFi terminal, and allocates a second IP address in the wireless local area network to the WiFi terminal.
  • the WiFi terminal accesses the AC from the AP (Access Point, the wireless access point), and the AC requests the AAA server to authenticate the WiFi terminal.
  • the specific authentication mode may be EAP-SIM. /AKA certification or Portal certification.
  • the AC requests the BRAS (Broadband Remote Access Server) or other IP address allocation server to allocate the second IP address in the wireless local area network to the WiFi terminal.
  • BRAS Broadband Remote Access Server
  • the trusted gateway receives the charging request message sent by the AAA server, where the charging request message carries the attribute information of the WiFi terminal.
  • the AC After allocating the second IP address to the WiFi terminal, the AC is directed to the AAA
  • the server sends an accounting request message, requesting the AAA server to start charging the WiFi terminal.
  • the AAA server opens the CDR (call detail records) in response to the charging request message sent by the AC.
  • the AAA server then carries the attribute information of the WiFi terminal in the charging request message, and sends the charging request message carrying the attribute information of the WiFi terminal to the trusted gateway.
  • the AAA server may directly forward the charging request message sent by the AC to the trusted gateway, and the attribute information of the WiFi terminal is pre-configured in the trusted gateway.
  • the attribute information of the WiFi terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a WiFi terminal QOS information, and a NAS-ID that manages an AC of the WiFi terminal.
  • the first APN or the QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the trusted gateway establishes a first PDP context connection with the first GGSN corresponding to the first access point name, and obtains a first IP address that is allocated by the first GGSN or the first P-GW to the WiFi terminal. .
  • the trusted gateway is triggered to establish a first PDP context connection with the first GGSN corresponding to the first APN.
  • the trusted gateway addresses the corresponding GGSN based on the first APN information.
  • the first APN is specifically CMNET, and the trusted gateway is addressed to the GGSN accessing the Internet.
  • the trusted gateway then sends a first PDP activation request message to the GGSN accessing the Internet to establish a first PDP context connection between the WiFi terminal and the GGSN accessing the Internet.
  • the first PDP activation request message carries the attribute information of the WiFi terminal, and is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GGSN After receiving the first activation request message sent by the trusted gateway, the first GGSN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS service domain.
  • the first GGSN then returns a first PDP activation response message to the trusted gateway, where the first PDP activation response message carries the first IP address allocated by the first GGSN.
  • the trusted gateway Receiving, by the trusted gateway, the first PDP activation response message returned by the first GGSN, and establishing, according to the first IP address carried in the first PDP activation response message, session information of the WiFi terminal in the wireless local area network and the Corresponding relationship of the PS service domain session information of the WiFi terminal, that is, the session information of the wireless local area network includes: a second IP address of the WiFi terminal, a NAS-ID that manages an AC of the WiFi terminal, and the like;
  • the PS service domain session information includes the first IP address, GTP tunnel information bound between the trusted gateway establishing the first PDP context connection and the first GGSN.
  • the downlink data service flows sent by the domain to the WiFi terminal are respectively routed to the corresponding PS service domain or WiFi terminal according to the corresponding relationship.
  • the AAA server After the first PDP context connection is established, the AAA server sends a charging request response message to the access controller AC, where the charging request response message carries the first IP address. And enabling the WiFi terminal to access the PS service domain through a wireless local area network.
  • the trusted gateway After the trusted gateway establishes a connection with the first PDP context of the first GGSN, the trusted gateway sends a charging request response message to the AAA server, and the AAA server forwards the charging request response message to the The AC is such that the WiFi terminal can access the PS service domain through the wireless local area network.
  • the trusted gateway After the trusted gateway establishes the first PDP context connection, when the trusted gateway receives the uplink data service flow initiated by the WiFi terminal to access the PS service domain, the trusted The gateway converts the second IP address carried in the data packet carrying the uplink data service flow into the first IP address; the trusted gateway according to the destination address of the uplink data service flow and the first An IP address is sent to the corresponding PS service domain by using the first PDP context connection to send the data packet carrying the uplink data service flow.
  • the AC receives the uplink data service flow initiated by the WiFi terminal to access the Internet service, and then forwards the uplink data service flow to the trusted gateway, where the trusted gateway And the carrying the data packet carrying the uplink data service flow according to the correspondence between the session information of the wireless local area network of the WiFi terminal and the PS service domain session information of the WiFi terminal established in the trusted gateway
  • the second IP address is converted to the first IP address.
  • the trusted gateway sends the data packet carrying the uplink data service flow to the corresponding PS service by using the first PDP context connection. area.
  • the method further includes: the trusted gateway to carry the downlink data service flow The first IP address carried in the data packet is converted into the second IP address; the trusted gateway sends a data packet carrying the downlink data service flow to the WiFi terminal.
  • the trusted gateway will carry data of the downlink data service flow according to the correspondence between the session information of the wireless local area network of the WiFi terminal and the PS service domain session information of the WiFi terminal established in the trusted gateway.
  • the first IP address carried in the packet is converted into the second IP address.
  • the trusted gateway sends a data packet carrying the downlink data service flow to the WiFi terminal according to the second IP address.
  • the trusted gateway when the trusted gateway receives the uplink data service flow initiated by the WiFi terminal to access the PS service domain, the trusted gateway is configured according to the trusted gateway. Determining, by the destination address of the uplink data service flow, a second access point name of the uplink data service flow, if the second GGSN corresponding to the second access point name is not the same device as the first GGSN, The trusted gateway establishes a second PDP context connection with the second GGSN, and acquires a third IP address that the second GGSN allocates to the WiFi terminal to access the PS service domain.
  • the trusted gateway converts the second IP address carried in the data packet carrying the uplink data service flow into the third IP address; and the trusted gateway according to the destination address of the uplink data service flow And the third IP address, the data packet carrying the uplink data service flow is sent to the corresponding PS service domain by using the second PDP context connection.
  • the trusted gateway After the trusted gateway establishes the second PDP context connection, when the trusted gateway receives the downlink data service flow sent by the PS service domain to the WiFi terminal by using the second PDP context connection, the trusted The gateway converts the third IP address carried in the data packet carrying the downlink data service flow into the second IP address, and the trusted gateway carries the downlink data service according to the second IP address.
  • the streamed data message is sent to the WiFi terminal.
  • the AC monitors the situation in which the WiFi terminal accesses the PS service domain, and periodically performs the WiFi terminal. Access information such as traffic and duration of the PS service domain.
  • the AAA server updates the CDR according to the information of the traffic and duration reported by the AC, and sends a charging response message to the AC.
  • the WiFi terminal initiates the offline request message or the WiFi terminal disconnects the communication with the AC in the case that the signal is weak
  • the AC sends an accounting termination message to the AAA
  • the AAA server The CDR file is closed, and in response to the charging termination message, an accounting termination message is sent to the trusted gateway.
  • the trusted gateway deletes the first PDP context connection between the trusted gateway and the first GG SN.
  • the trusted gateway establishes the second PDP context connection, after the trusted gateway receives the charging termination message, the second PDP context connection is also deleted.
  • a GRE (Generic Routing Encapsulation) tunnel or a bearer network tunnel may be established between the trusted gateway and the AC in order to ensure that the WiFi terminal accesses the security of the PS service domain of the operator.
  • the method for accessing the PS service domain by the WiFi terminal provided by the embodiment of the present invention, after the AC requests the AAA server to authenticate the WiFi terminal, the AC sends an accounting request message to the AAA server.
  • the trusted gateway Sending, by the AAA server, the charging request message to the trusted gateway, to trigger the trusted gateway to establish a first PDP context connection with the first GGSN, or the trusted gateway establishes a first PDN connection with the first P-GW, so that the The trusted gateway is used as an access point for accessing the PS service domain, and the WiFi terminal can access the PS service domain through a wireless local area network, a trusted gateway, and an established PDP context connection or a PDN connection, so that the terminal and the trusted gateway are not needed.
  • a dedicated tunnel is established, and the WiFi terminal does not need to perform two authentications, which reduces the load on the WiFi terminal and reduces the complexity and cost of the operation of the WiFi terminal.
  • Embodiment 3 The embodiment of the present invention provides a method for a WiFi terminal to access a PS service domain.
  • the following detailed description takes a second-generation or third-generation communication network as an example, as shown in FIG. 3, where the trusted The gateway receives the dynamic host setup protocol DHCP request message sent by the WiFi terminal, where the DHCP request message triggers the trusted gateway to establish a first PDP context connection with the first GG SN, where the method specifically includes:
  • the trusted gateway receives the DHCP request message sent by the WiFi terminal.
  • the WiFi terminal is before the WiFi terminal sends a DHCP request message to the gateway through the AC.
  • the WiFi terminal needs to be attached to the WLAN, and the AAA server is requested to authenticate the WiFi terminal through the AC.
  • the WiFi terminal may send a DHCP request message to the trusted gateway by using the AC, and encapsulate the identification number of the WiFi terminal, such as a WiFi terminal, in the DHCP request message sent by the WiFi terminal.
  • a MAC (Media Access Control) address or a NAI (Network Access Identifier) for identifying a WiFi terminal.
  • the trusted gateway sends an access request message to the AAA server.
  • the trusted gateway receives the DHCP request message sent by the WiFi terminal through the AC, and the DHCP request message triggers the trusted gateway to establish a PDP context connection with the corresponding GGSN.
  • the trusted gateway first needs to obtain the attribute information of the WiFi terminal from the AAA server, and the trusted gateway sends an access request message to the AAA server to obtain the attribute information of the WiFi terminal.
  • the trusted gateway receives an access response message sent by the AAA server, where the access response message carries the attribute information of the WiFi terminal.
  • the AAA server receives the access request message sent by the trusted gateway, and responds to the access request message, and sends an access response message to the trusted gateway, where the access response message carries the WiFi terminal. Attribute information.
  • the attribute information of the WiFi terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a QOS information of the WiFi terminal, and a NAS-ID of an AC managing the WiFi terminal.
  • the first APN or the QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first GGSN corresponding to the first access point name establishes a first PDP context connection, and obtains a first IP address that is allocated by the first GGSN or the first P-GW to the WiFi terminal.
  • the trusted gateway After receiving the access response message sent by the AAA server, the trusted gateway determines the specific needs of the trusted gateway according to the first APN of the WiFi terminal carried in the access response message. Which GGSN is connected with, and then sends a first PDP activation request message to the first GGSN corresponding to the first APN.
  • the first PDP activation request message carries the attribute information of the WiFi terminal, and the attribute information of the WiFi terminal is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GG SN After receiving the first PDP activation request message sent by the trusted gateway, the first GG SN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS service domain. The first GGSN then returns a first PDP activation response message to the trusted gateway, where the first PDP activation response message carries the first IP address allocated by the first GGSN. Specifically, the first GGSN allocates a corresponding IP address to the WiFi terminal according to the networking. For example, if the AC has a routing function, the first IP address assigned by the first GGSN to the WiFi terminal is the same network segment as the AC managing the WiFi terminal; if the AC has no routing function, the first GGSN may not be limited.
  • the trusted gateway After the first PDP context connection is established, the trusted gateway sends a DHCP response message to the WiFi terminal, where the DHCP response message carries the first IP address.
  • the trusted gateway sends a DHCP response message to the WiFi terminal
  • the trusted gateway sends an accounting request message to the AAA server, instructing the AAA server to perform charging on the WiFi terminal.
  • the AAA server responds to the charging request message, Open the CDR.
  • the WiFi terminal may access the PS service domain through the wireless local area network.
  • the method further includes:
  • PS business domain Sending, by the trusted gateway, the data packet carrying the uplink data service flow to the corresponding data by using the first PDP context connection according to the destination address of the uplink data service flow and the first IP address.
  • the AC receives the data packet sent by the WiFi terminal and carries the uplink data service flow that accesses the Internet service, and then forwards the data packet to the trusted gateway.
  • the data packet carries information such as a destination address of the uplink data service flow, the first IP address, and a NAS-ID of the AC managing the WiFi terminal.
  • the trusted gateway After receiving the data packet carrying the uplink data service flow, the trusted gateway, according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the PS service domain session information of the WiFi terminal The corresponding relationship sends the data packet to the first GGSN, so that the WiFi terminal accesses the corresponding PS service domain.
  • the method further includes: the trusted gateway carrying the downlink data according to the first IP address A data packet of the service flow is sent to the WiFi terminal.
  • the trusted gateway is configured according to the The first IP address sends the data packet carrying the downlink data service flow to the WiFi terminal, and the first IP address is the same network segment as the IP address of the AC that manages the WiFi terminal. If the AC has no routing function, the trusted gateway sends the data packet carrying the downlink data service flow to the WiFi according to the first IP address and the NAS-ID in the WiFi terminal attribute information. terminal.
  • the trusted gateway when the trusted gateway receives the uplink data service flow initiated by the WiFi terminal to access the PS service domain, the trusted gateway is configured according to the trusted gateway. Determining, by the destination address of the uplink data service flow, a second access point name of the uplink data service flow, if the second GGSN corresponding to the second access point name is not the same device as the first GGSN, Establishing, by the trusted gateway, a second PDP context connection with the second GGSN, and acquiring, by the second GGSN, the WiFi terminal Accessing a third IP address of the PS service domain; the trusted gateway, according to the destination address of the uplink data service flow and the third IP address, connecting the uplink data by using the second PDP context connection The data packet of the service flow is sent to the corresponding PS service domain.
  • the trusted gateway After the trusted gateway establishes the second PDP context connection, when the trusted gateway receives the downlink data service flow sent by the PS service domain to the WiFi terminal by using the second PDP context connection, the trusted The gateway sends the data packet carrying the downlink data service flow to the WiFi terminal according to the second IP address.
  • the AC is used to monitor the situation in which the WiFi terminal accesses the PS service domain, and periodically accesses the traffic of the PS service domain by the WiFi terminal.
  • Information such as duration.
  • the AAA server updates the CDR according to the information such as the traffic and duration reported by the AC, and sends a charging response message to the AC.
  • the WiFi terminal initiates the offline request message or the WiFi terminal disconnects the communication with the AC in the case that the signal is weak
  • the AC sends an accounting termination message to the AAA
  • the AAA server The CDR file is closed, and the charging termination message is sent to the trusted gateway.
  • the trusted gateway deletes the first PDP context connection.
  • the trusted gateway establishes the second PDP context connection, after the trusted gateway receives the charging termination message, the second PDP context connection is also deleted.
  • a GRE tunnel or a bearer network tunnel may be established between the trusted gateway and the AC in order to ensure the security of the WiFi terminal to access the PS service domain.
  • the method for the WiFi terminal to access the PS service domain is provided by the embodiment of the present invention. After the WiFi terminal is authenticated, the DHCP request message is sent to the trusted gateway.
  • the DHCP request message triggers the trusted gateway to establish a first PDP context connection with the corresponding first GGSN or the trusted gateway establishes a first PDN connection with the corresponding first P-GW, so that the trusted gateway acts as Accessing the access point of the PS service domain, the WiFi terminal can access the PS service domain through the wireless local area network, the trusted gateway, and the established PDP context connection or PDN connection, so that there is no need to establish a special between the terminal and the trusted gateway.
  • the WiFi terminal does not need to perform two authentications, which reduces the load on the WiFi terminal and reduces the complexity and cost of the operation of the WiFi terminal.
  • Embodiment 4 An embodiment of the present invention provides a method for a WiFi terminal to access a PS service domain, and a specific description of the following method uses a second-generation or third-generation communication network as an example, as shown in FIG. 4, where the trusted gateway receives the location
  • the dynamic host setting protocol DHCP request message sent by the WiFi terminal is used to trigger the trusted gateway to establish a first PDP context connection with the first GGSN.
  • a second-generation or third-generation communication network as an example, as shown in FIG. 4, where the trusted gateway receives the location
  • the dynamic host setting protocol DHCP request message sent by the WiFi terminal is used to trigger the trusted gateway to establish a first PDP context connection with the first GGSN.
  • the trusted gateway sends an authentication request message to the AAA server, requesting the AAA server to authenticate the WiFi terminal.
  • the trusted gateway is further configured to request the AAA server to authenticate the WiFi terminal.
  • the WiFi terminal is attached to the WLAN, and the AC of the wireless local area network requests the trusted gateway to perform authentication.
  • the trusted gateway sends an authentication request message to the AAA server, requesting the AAA server to authenticate the WiFi terminal.
  • the trusted gateway After authenticating the WiFi terminal, the trusted gateway sends an access request message to the AAA server.
  • the trusted gateway receives the access response message sent by the AAA server, where the access response message carries the attribute information of the WiFi terminal.
  • the AAA server receives the access request message sent by the trusted gateway, and responds to the access request message, and sends an access response message to the trusted gateway, where the access response message carries the WiFi terminal. Attribute information.
  • the attribute information of the WiFi terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a QOS information of the WiFi terminal, and a NAS-ID of an AC managing the WiFi terminal.
  • the first APN or the QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the trusted gateway receives a dynamic host setup protocol DHCP request message sent by the WiFi terminal.
  • the trusted gateway After obtaining the attribute information of the WiFi terminal, the trusted gateway receives the DHCP request message sent by the WiFi terminal, and the identifier of the WiFi terminal is encapsulated in the DHCP request message. For example, the MAC address or NAI of the terminal is used to identify the WiFi terminal.
  • the first GPSN corresponding to the first access point name establishes a first PDP context connection, and obtains a first IP address that is allocated by the first GGSN or the first P-GW to the WiFi terminal.
  • the trusted gateway receives the DHCP request message sent by the WiFi terminal, and the DHCP request message triggers the trusted gateway to establish a first PDP context connection with the first GG SN.
  • the trusted gateway determines, according to the first APN, which GGSN the trusted gateway needs to establish a connection with, and then sends a first PDP activation request message to the first GGSN corresponding to the first APN.
  • the first PDP activation request message carries the attribute information of the WiFi terminal, and the attribute information of the WiFi terminal is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GGSN After receiving the activation request message sent by the trusted gateway, the first GGSN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS service domain. The first GGSN then returns a first PDP activation response message to the trusted gateway, where the first PDP activation response message carries the first IP address assigned by the first GGSN to the trusted gateway. Specifically, determining, according to the networking, the first GGSN allocates a corresponding IP address to the WiFi terminal.
  • the first IP address assigned by the first GGSN to the WiFi terminal is the same network segment as the AC managing the WiFi terminal; if the AC has no routing function, the first GGSN may not be limited to The same network segment of the AC that manages the WiFi terminal allocates a first IP address to the WiFi terminal.
  • the trusted gateway Receiving, by the trusted gateway, the first PDP activation response message returned by the first GGSN, and establishing, according to the first IP address carried in the first PDP activation response message, session information of the WiFi terminal in the wireless local area network and the Corresponding relationship of the PS service domain session information of the WiFi terminal, that is, the session information of the wireless local area network includes: a NAS-ID that manages the AC of the WiFi terminal, and the PS service domain session information of the WiFi terminal includes: An IP address, GTP tunnel information bound between the trusted gateway and the first GGSN that establishes a first PDP context connection.
  • the downlink data service flows of the WiFi terminal are respectively routed to the corresponding PS service domain or WiFi terminal according to the corresponding relationship.
  • the trusted gateway After the trusted gateway establishes a first PDP context connection with the PS service domain, the trusted gateway sends a DHCP response message to the WiFi terminal, where the DHCP response message carries the first IP address. Further, after the trusted gateway sends a DHCP response message to the WiFi terminal, the trusted gateway sends an accounting request message to the AAA server, instructing the AAA server to perform charging on the WiFi terminal.
  • the AAA server opens the CDR in response to the charging request message. Specifically, when the WiFi terminal accesses the PS service domain, the trusted gateway monitors the situation in which the WiFi terminal accesses the PS service domain, and periodically reports the WiFi terminal access to the AAA server. Information such as traffic and duration of the PS service domain. The AAA server charges the WiFi terminal according to the information such as the traffic and duration reported by the trusted gateway, updates the CDR, and sends an accounting response message to the trusted gateway.
  • the WiFi terminal may access the PS service domain through the wireless local area network.
  • the method further includes:
  • the AC receives the data packet sent by the WiFi terminal and carries the uplink data service flow that accesses the Internet service, and then forwards the data packet to the trusted gateway.
  • the data packet carries information such as a destination address of the uplink data service flow, the first IP address, and a NAS-ID of the AC managing the WiFi terminal.
  • the trusted gateway After receiving the data packet carrying the uplink data service flow, the trusted gateway, according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the PS service domain session information of the WiFi terminal The corresponding relationship sends the data packet to the first GGSN, so that the WiFi terminal accesses the corresponding PS service domain.
  • the method further includes: The trusted gateway sends the data carrying the downlink data service flow to the WiFi terminal according to the first IP address.
  • the trusted gateway is configured according to the The first IP address sends the data packet carrying the downlink data service flow to the WiFi terminal, and the first IP address is the same network segment as the IP address of the AC that manages the WiFi terminal. If the AC has no routing function, the trusted gateway sends the data packet carrying the downlink data service flow to the WiFi according to the first IP address and the NAS-ID in the WiFi terminal attribute information. terminal.
  • the trusted gateway when the trusted gateway receives the uplink data service flow initiated by the WiFi terminal to access the PS service domain, the trusted gateway is configured according to the trusted gateway. Determining, by the destination address of the uplink data service flow, a second access point name of the uplink data service flow, if the second GGSN corresponding to the second access point name is not the same device as the first GGSN, The trusted gateway establishes a second PDP context connection with the second GGSN, and acquires a third IP address that is allocated by the second GGSN to the WiFi terminal to access the PS service domain; the trusted gateway is configured according to the uplink data. The destination address of the service flow and the third IP address are sent to the corresponding PS service domain by using the second PDP context connection to send the data packet carrying the uplink data service flow.
  • the trusted gateway After the trusted gateway establishes the second PDP context connection, when the trusted gateway receives the downlink data service flow sent by the PS service domain to the WiFi terminal by using the second PDP context connection, the trusted The gateway sends the data packet carrying the downlink data service flow to the WiFi terminal according to the second IP address.
  • the trusted gateway sends the charging to the AAA.
  • the AAA server closes the CDR file and responds to the charging termination message.
  • the first PDP context connection is deleted.
  • the trusted gateway establishes the second PDP context connection, after the trusted gateway sends the charging termination message to the AAA, the second PDP context connection is also deleted.
  • the CAPWAP Control And Provisioning of Wireless Access Points Protocol
  • the CAPWAP can be configured between the AP and the AC to ensure that the WiFi terminal accesses the security of the PS service domain.
  • Specification, control and monitoring protocol specification of the wireless access point) tunnel transmission, the AP and the trusted gateway are transmitted through the GRE tunnel or the use of the bearer network tunnel.
  • the method for accessing a PS service domain by a WiFi terminal according to an embodiment of the present invention, the trusted gateway requesting an AAA server to perform authentication on the WiFi terminal. After the authentication is completed, the trusted gateway acquires the attribute information of the WiFi terminal from the AAA server.
  • the trusted gateway After the trusted gateway receives the DHCP request message sent by the WiFi terminal, the trusted gateway establishes a first PDP context connection with the first GGSN, or the trusted gateway establishes a first PDN connection with the first P-GW, so that The trusted gateway is used as an access point for accessing the PS service domain, and the WiFi terminal can access the PS service domain through a wireless local area network, a trusted gateway, and an established PDP context connection or a PDN connection, so that the terminal and the trusted gateway are not needed.
  • a dedicated tunnel is established, and the WiFi terminal does not need to perform two authentications, which reduces the load on the WiFi terminal and reduces the complexity and cost of the operation of the WiFi terminal.
  • Embodiment 5 The embodiment of the present invention further provides a method for a WiFi terminal to access a PS service domain.
  • the following detailed description uses a second-generation or third-generation communication network as an example, as shown in FIG. 5, where the The gateway receives the dynamic host setup protocol DHCP request message sent by the WiFi terminal, and is used to trigger the trusted gateway to establish a first PDP context connection with the PS service domain.
  • the gateway receives the dynamic host setup protocol DHCP request message sent by the WiFi terminal, and is used to trigger the trusted gateway to establish a first PDP context connection with the PS service domain.
  • DHCP request message sent by the WiFi terminal
  • the trusted gateway to establish a first PDP context connection with the PS service domain.
  • the trusted gateway forwards an authentication request message that the access controller AC requests the AAA server to authenticate the WiFi terminal to the AAA server.
  • the trusted gateway in this implementation acts as a relay of the AC and the AAA server.
  • the WiFi terminal is attached to the WLAN, and accesses the wireless access point AP of the wireless local area network, and the AC sends an authentication request message to the AAA server.
  • the trusted gateway forwards, as a relay, an authentication request message sent by the AC to the AAA server.
  • the trusted gateway forwards the authentication response message that the AAA server authenticates the WiFi terminal to the AC, and the authentication response message carries the attribute information of the WiFi terminal.
  • the AAA server After the AAA server successfully authenticates the WiFi terminal, the AAA server sends an authentication response message to the AC. After receiving the authentication response message sent by the AAA server, the trusted gateway forwards the authentication response message to the AC. The authentication response message carries The attribute information of the WiFi terminal is described.
  • the trusted gateway acquires the attribute information of the WiFi terminal from the authentication response message.
  • the trusted gateway After receiving the authentication response message sent by the AAA server, the trusted gateway parses the authentication response message sent by the AAA server, and obtains the attribute information of the WiFi terminal from the authentication response message.
  • the attribute information of the WiFi terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a WiFi terminal QOS, and a NAS-ID.
  • the first APN or the QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the trusted gateway receives a dynamic host setup protocol DHCP request message sent by the WiFi terminal.
  • the AC After obtaining the attribute information of the WiFi terminal, the AC sends a DHCP request message sent by the WiFi terminal to the trusted gateway, where the DHCP request message encapsulates the identification number of the WiFi terminal, such as the MAC address of the terminal or the NAI, Identify the WiFi terminal.
  • the first GGSN corresponding to the first access point name establishes a first PDP context connection, and obtains a first IP address allocated by the first GGSN or the first P-GW to the WiFi terminal.
  • the trusted gateway After receiving the DHCP request message sent by the WiFi terminal, the trusted gateway determines, according to the first APN in the WiFi terminal attribute information, which GG SN needs to establish a connection with the GG SN, and then corresponds to the first APN.
  • the first GGSN sends a first PDP activation request message.
  • the first PDP activation request message carries the attribute information of the WiFi terminal, and the attribute information of the WiFi terminal is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GGSN After receiving the activation request message sent by the trusted gateway, the first GGSN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS. Business domain. The first GGSN then returns a first PDP activation response message to the trusted gateway, where the first PDP activation response message carries the first IP address assigned by the first GGSN to the trusted gateway. Specifically, determining, according to the networking, the first GGSN allocates a corresponding IP address to the WiFi terminal.
  • the first IP address assigned by the first GGSN to the WiFi terminal is the same network segment as the AC managing the WiFi terminal; if the AC has no routing function, the first GGSN may not be limited to The same network segment of the AC that manages the WiFi terminal allocates a first IP address to the WiFi terminal.
  • the trusted gateway Receiving, by the trusted gateway, the first PDP activation response message returned by the first GGSN, and establishing, according to the first IP address carried in the first PDP activation response message, session information of the WiFi terminal in the wireless local area network and the Corresponding relationship of the PS service domain session information of the WiFi terminal, that is, the session information of the wireless local area network includes: a NAS-ID that manages the AC of the WiFi terminal, and the PS service domain session information of the WiFi terminal includes: An IP address, GTP tunnel information bound between the trusted gateway and the first GGSN that establishes a first PDP context connection.
  • the PS service domain session information of the WiFi terminal further includes: establishing the trusted gateway of the first PDP context connection and the GTP tunnel information bound between the first GGSNs.
  • the trusted gateway After the trusted gateway establishes a first PDP context connection with the PS service domain, the trusted gateway sends a DHCP response message to the WiFi terminal, where the DHCP response message carries the first IP address.
  • the WiFi terminal can access the PS service domain through the wireless local area network.
  • the method further includes:
  • the AC receives the WiFi terminal and sends the WiFi terminal. Transmitting the data packet of the uplink data service flow that is sent to the Internet service, and forwarding the data packet to the trusted gateway, where the data packet carries the destination address of the uplink data service flow, The first IP address and the information such as the NAS-ID of the AC managing the WiFi terminal.
  • the trusted gateway After receiving the data packet carrying the uplink data service flow, the trusted gateway, according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the PS service domain session information of the WiFi terminal The corresponding relationship sends the data packet to the first GGSN, so that the WiFi terminal accesses the corresponding PS service domain.
  • the method further includes:
  • the trusted gateway sends the data carrying the downlink data service flow to the WiFi terminal according to the first IP address.
  • the trusted gateway is configured according to the The first IP address sends the data packet carrying the downlink data service flow to the WiFi terminal, and the first IP address is the same network segment as the IP address of the AC that manages the WiFi terminal. If the AC has no routing function, the trusted gateway sends the data packet carrying the downlink data service flow to the WiFi according to the first IP address and the NAS-ID in the WiFi terminal attribute information. terminal.
  • the trusted gateway when the trusted gateway receives the uplink data service flow initiated by the WiFi terminal to access the PS service domain, the trusted gateway is configured according to the trusted gateway. Determining, by the destination address of the uplink data service flow, a second access point name of the uplink data service flow, if the second GGSN corresponding to the second access point name is not the same device as the first GGSN, The trusted gateway establishes a second PDP context connection with the second GGSN, and acquires a third IP address that is allocated by the second GGSN to the WiFi terminal to access the PS service domain; the trusted gateway is configured according to the uplink data. The destination address of the service flow and the third IP address are sent to the corresponding PS service domain by using the second PDP context connection to send the data packet carrying the uplink data service flow.
  • the trusted gateway After the trusted gateway establishes the second PDP context connection, when the trusted gateway receives the downlink data service flow sent by the PS service domain to the WiFi terminal by using the second PDP context connection, the trusted The gateway sends the data packet carrying the downlink data service flow to the WiFi terminal according to the second IP address. Further, when the WiFi terminal accesses the PS service domain, the AC monitors the situation in which the WiFi terminal accesses the PS service domain, and periodically reports the WiFi terminal access to the PS service domain to the AAA server. Information such as traffic and duration. The trusted gateway forwards information such as the traffic and duration reported by the AC to the AAA server. The AAA server updates the CDR according to the information of the traffic and duration reported by the AC, and sends a charging response message to the AC.
  • the AC sends a charging termination message to the AAA, where the The gateway gateway forwards the charging termination message sent by the AC to the AAA server.
  • the trusted gateway deletes the first PDP context connection between the trusted gateway and the GGSN according to the charging termination message.
  • the AAA server closes the CDR file in response to the charging termination message.
  • the trusted gateway further deletes the second PDP context connection according to the charging termination message.
  • the information between the trusted gateway and the AP needs to be transmitted through the GRE tunnel or the bearer network tunnel.
  • the method for accessing the PS service domain by the WiFi terminal provided by the embodiment of the present invention, the trusted gateway serving as the relay of the AC and the AAA server, acquiring the authentication response message sent by the AAA server to the WiFi terminal of the AC
  • the attribute information of the WiFi terminal is described.
  • the trusted gateway After obtaining the attribute information of the WiFi terminal, the trusted gateway receives the DHCP request message sent by the WiFi terminal, and establishes a first PDP context connection or a first PDN connection between the trusted gateway and the PS service domain, thereby The trusted gateway is used as an access point for accessing the PS service domain, and the WiFi terminal can access the PS service domain through a wireless local area network, a trusted gateway, and an established PDP context connection or a PDN connection, so that the terminal and the trusted gateway are not needed.
  • a special tunnel is established to reduce the load on the WiFi terminal and reduce the complexity and cost of the operation of the WiFi terminal.
  • the second, third, fourth, and fifth embodiments of the present invention describe the method for accessing the PS service domain provided by the WiFi terminal provided by the present invention under the second generation or third generation communication network system.
  • the methods provided in the second, third, fourth, and fifth embodiments of the present invention are equally applicable. It is applied to the LTE communication network system, but the trusted gateway establishes a first PDN connection with the first P-GW after receiving the charging request message or the DHCP request message, and obtains the first PDN to be allocated to the WiFi terminal. The first IP address of the PS service domain.
  • the process of establishing a PDN connection between the trusted gateway and the first P-GW is a prior art, and the present invention is not described herein again.
  • the WiFi terminal preferentially accesses the PS service domain of the operator through the wireless local area network, and the application on the WiFi terminal needs to send the default access point name type or the application on the WiFi terminal to the WiFi terminal.
  • the program does not send an access point name to the WiFi terminal, and the WiFi terminal preferentially accesses the PS service domain through the wireless local area network according to a default access point name type.
  • Embodiment 6 The embodiment of the present invention provides a trusted gateway 60 for a WiFi terminal to access a PS service domain. As shown in FIG. 6, the receiving unit 61 and the connection establishing unit 62 are included.
  • the receiving unit 61 is configured to receive an accounting request message sent by the authentication, authorization, and accounting AAA server or a dynamic host setting protocol DHCP request message sent by the WiFi terminal.
  • the connection establishing unit 62 is configured to: after receiving the charging request message or the DHCP request message, according to the attribute information of the WiFi terminal, the trusted gateway establishes a first packet data protocol PDP context connection or The first packet data network PDN is connected, so that the trusted gateway is used as an access point for accessing the PS service domain, and the WiFi terminal can pass the trusted channel after accessing the trusted gateway through the wireless local area network.
  • the gateway accesses the PS service domain.
  • the trusted gateway 70 further includes: an address conversion unit 73, a sending unit 74, and a connection deleting unit 75.
  • the WiFi terminal accesses the AC from the AP, and the AC requests the AAA server to authenticate the WiFi terminal.
  • the specific authentication mode may be EAP-SIM/AKA authentication or Portal authentication.
  • the AC requests the BRAS or other IP address allocation server to allocate the second IP address in the wireless local area network to the WiFi terminal.
  • the AC After allocating the second IP address to the WiFi terminal, the AC is to the The AAA server sends an accounting request message, requesting the AAA server to start charging the WiFi terminal.
  • the AAA server opens the CDR (call detail records) in response to the charging request message sent by the AC.
  • the AAA server carries the attribute information of the WiFi terminal in the charging request message, and sends the charging request message carrying the attribute information of the WiFi terminal to the receiving unit of the trusted gateway. 61.
  • the attribute information of the WiFi terminal is carried in the charging request message.
  • the attribute information of the WiFi terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a WiFi terminal QOS information, and a NAS-ID.
  • the first APN or the QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection or the first PDN connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the connection establishing unit 62 is configured to: establish a first PDP context connection by using the first GGSN corresponding to the first access point name, or establish a first PDN connection by using a P-GW corresponding to the first access point name, And obtaining a first IP address that is allocated by the first GGSN or the first P-GW to the WiFi terminal.
  • the sending unit 74 is configured to send, by the AAA server, a charging request response message to the access controller AC after the connection establishing unit 62 establishes the first PDP context connection or the first PDN connection, where The charging request response message carries the first IP address, so that the WiFi terminal can access the PS service domain through a wireless local area network.
  • the connection establishing unit 62 is specifically configured to send a first PDP activation request message to the first GGSN corresponding to the first access point name; a first PDP activation response message returned by the GGSN, where the first PDP activation response message carries the first IP address allocated by the first GGSN to the WiFi terminal to access the PS service domain.
  • the trusted gateway is triggered to establish a first PDP context connection with the first GGSN.
  • the connection establishing unit 62 of the trusted gateway addresses the corresponding first GGSN according to the first APN information.
  • the first APN is specifically CMNET
  • the trusted gateway is addressed to the GGSN accessing the Internet.
  • the connection establishing unit 62 then sends the first to the first GGSN.
  • the PDP activation request message establishes a first PDP context connection between the WiFi terminal and the first GGSN.
  • the first PDP activation request message carries the attribute information of the WiFi terminal, and is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GGSN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS service domain.
  • the first GGSN then returns a first PDP activation response message to the trusted gateway, where the first PDP activation response message carries the first IP address allocated by the first GGSN.
  • the connection establishing unit 62 receives the first PDP activation response message returned by the first GGSN, the trusted gateway establishes the session of the WiFi terminal in the wireless local area network according to the first IP address carried in the first PDP activation response message.
  • Corresponding relationship between the information and the PS service domain session information of the WiFi terminal that is, the session information of the wireless local area network includes: a second IP address of the WiFi terminal, a NAS-ID that manages an AC of the WiFi terminal, and the like;
  • the PS service domain session information of the WiFi terminal includes the first IP address, GTP tunnel information bound between the trusted gateway and the first GGSN that establishes a first PDP context connection.
  • Corresponding relationship between the session information of the wireless local area network and the PS service area session information of the WiFi terminal established by the trusted gateway, and used to send the uplink data service flow or the PS service initiated by the WiFi terminal The downlink data service flows sent by the domain to the WiFi terminal are respectively routed to the corresponding PS service domain or WiFi terminal according to the corresponding relationship.
  • the address conversion unit 73 is configured to convert the second IP address carried in the data packet carrying the uplink data service flow initiated by the WiFi terminal into the The first IP address is further configured to convert the first IP address carried in the data packet of the downlink data service flow that is sent by the PS service domain to the WiFi terminal to the second IP address, where the second The IP address is an IP address in the wireless local area network allocated by the access controller AC to the WiFi terminal after authenticating the WiFi terminal;
  • the sending unit 74 is further configured to: according to the destination address of the uplink data service flow and the first IP address, carry the uplink data service by using the first PDP context connection or the first PDN connection
  • the data packet of the flow is sent to the corresponding PS service domain; and is further configured to send the data packet carrying the downlink data service flow to the WiFi terminal according to the second IP address.
  • the AC when the WiFi accesses the Internet service, the AC receives the uplink number of the Internet service initiated by the WiFi terminal. Forwarding the uplink data service flow to the trusted gateway according to the service flow, the address conversion unit 73, according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the PS service of the WiFi terminal The correspondence between the domain session information converts the second IP address carried in the uplink data service flow into the first IP address. Then, the sending unit 74 sends the data packet carrying the uplink data service flow to the corresponding PS service domain by using the first PDP context connection according to the destination address of the uplink data service and the first IP address.
  • the address conversion unit 73 is configured according to the wireless local area network of the WiFi terminal established in the trusted gateway. Corresponding relationship between the session information and the PS service domain session information of the WiFi terminal, and converting the first IP address carried in the data packet carrying the downlink data service flow into the second IP address. And sending, by the sending unit, the data packet carrying the downlink data service flow to the WiFi terminal according to the second IP address and/or the user access server number.
  • the connection establishing unit 62 determines, according to the destination address of the uplink data service flow, a second access point name corresponding to the uplink data service flow, if The first PGSN corresponding to the second GGSN and the first GGSN or the second access point name are not the same device, and the second GGSN is established. And the second PDP context connection is connected to the second PDN of the second P-GW, and obtains a third IP address that is allocated by the second GGSN or the second P-GW to the WiFi terminal to access the PS service domain.
  • the address translation unit 73 is further configured to: after the trusted gateway establishes the second PDP context connection or the second PDN connection, the second IP address carried in the data packet carrying the uplink data service flow Converting to the third IP address; and converting the third IP address carried in the data packet carrying the downlink data service flow to the second IP address.
  • the sending unit 74 is further configured to: according to the destination address of the uplink data service flow and the third IP address, carry the uplink data service by using the second PDP context connection or the second PDN connection Transmitting a data packet of the stream to the corresponding PS service domain; and transmitting, by the second PDP context connection or the PS service domain received by the second PDN connection, the downlink data service to the WiFi terminal according to the second IP address
  • the streamed data message is sent to the WiFi terminal.
  • the receiving unit 61 is further configured to connect Receiving the charging termination message sent by the AAA server.
  • the connection deletion unit 75 is configured to delete the first PDP context connection or the first PDN connection after the receiving unit 61 receives the charging termination message.
  • the AC monitors the situation in which the WiFi terminal accesses the PS service domain, and periodically accesses the traffic and duration of the PS service domain in the WiFi terminal. information.
  • the AAA server updates the CDR according to the information such as the traffic and duration reported by the AC, and sends a charging response message to the AC.
  • the WiFi terminal initiates the offline request message or the WiFi terminal disconnects the communication with the AC in the case that the signal is weak
  • the AC sends an accounting termination message to the AAA
  • the AAA server closes the CDR file.
  • sending a charging termination message sending a charging termination message to the trusted gateway.
  • the receiving unit 61 deletes the first PDP context connection or the first PDN connection by the connection deleting unit 75.
  • the connection deleting unit 75 also deletes the A second PDP context connection or a second PDN connection.
  • the receiving unit 61 receives the DHCP request message sent by the WiFi terminal, as shown in FIG. 8, the trusted gateway 80 further includes a sending unit 83 and a connection deleting unit 84.
  • the WiFi terminal Before the WiFi terminal sends a DHCP request message to the trusted gateway through the AC, the WiFi terminal first needs to attach to the WLAN and authenticate the AAA server through the AC. After the WiFi terminal authentication is completed, the WiFi terminal may request a DHCP request message to the trusted gateway through the AC.
  • the AC sends the DHCP request message to the trusted gateway, and encapsulates the identification number of the WiFi terminal, such as the MAC (Media Access Control) address or the NAI of the WiFi terminal, in the DHCP request message sent by the WiFi terminal. (Network Access Identifier), used to identify the WiFi terminal.
  • MAC Media Access Control
  • NAI Network Access Identifier
  • the sending unit 83 is configured to send an access request message to the AAA server after the receiving unit 61 receives the DHCP request message.
  • the receiving unit 61 of the trusted gateway receives the DHCP request message sent by the WiFi terminal through the AC, and the DHCP request message triggers the trusted gateway to establish a first PDP context connection or a first PDN connection with the PS service domain. .
  • the trusted gateway first needs
  • the attribute information of the WiFi terminal is obtained from the AAA server, and the specific sending unit 83 sends an access request message to the AAA server to obtain the attribute information of the WiFi terminal.
  • the receiving unit 61 is further configured to receive an access response message sent by the AAA server, where the access response message carries the attribute information of the WiFi terminal.
  • the AAA server receives the access request message sent by the trusted gateway, and responds to the access request message, and sends an access response message to the trusted gateway, where the access response message carries the WiFi terminal. Attribute information.
  • the attribute information of the WiFi terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a QOS information of the WiFi terminal, and a NAS-ID of an AC managing the WiFi terminal.
  • the first APN or the QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection or the first PDN connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the connection establishing unit 62 is configured to: establish a first PDP context connection by using the first GGSN corresponding to the first access point name, or establish a first PDN connection by using a P-GW corresponding to the first access point name, And obtaining a first IP address that is allocated by the first GGSN or the first P-GW to the WiFi terminal.
  • the sending unit 83 is configured to send a DHCP response message to the WiFi terminal after the connection establishing unit 62 establishes the first PDP context connection or the first PDN connection, where the DHCP response message carries the An IP address.
  • the connection establishing unit 62 is specifically configured to correspond to the first access point name.
  • Receiving, by the first GGSN, a first PDP activation request message, and receiving a first PDP activation response message returned by the first GGSN, where the first PDP activation response message carries the first GGSN and is allocated to the WiFi terminal for accessing The first IP address of the PS service domain.
  • the trusted gateway determines, according to the first APN, which GGSN the trusted gateway needs to establish a connection, and then sends a first PDP activation request message to the first GGSN corresponding to the first APN.
  • the first PDP activation request message carries the WiFi.
  • the attribute information of the terminal, the attribute information of the WiFi terminal is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GGSN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS service domain.
  • the first GGSN then returns a first PDP activation response message to the trusted gateway, where the first PDP activation response message carries the first IP address allocated by the first GGSN.
  • the first GGSN allocates a corresponding IP address to the WiFi terminal according to the networking.
  • the first IP address assigned by the first GGSN to the WiFi terminal is the same network segment as the AC managing the WiFi terminal; if the AC has no routing function, the first GGSN may not be limited. Assigning a first IP address to the WiFi terminal on the same network segment as the AC managing the WiFi terminal.
  • the connection establishing unit 62 receives the first PDP activation response message returned by the first GGSN, and the trusted gateway establishes the session information of the WiFi terminal in the wireless local area network according to the first IP address carried in the first PDP activation response message.
  • Corresponding relationship with the PS service domain session information of the WiFi terminal that is, the session information of the wireless local area network includes: a NAS-ID that manages the AC of the WiFi terminal, and the like; The first IP address, the GTP tunnel information bound between the trusted gateway and the first GGSN that establishes the first PDP context connection.
  • the correspondence between the session information of the wireless local area network of the WiFi terminal and the PS service domain session information of the WiFi terminal established by the trusted gateway is used to send the uplink data service flow or the PS service initiated by the WiFi terminal
  • the downlink data service flows sent by the domain to the WiFi terminal are respectively routed to the corresponding PS service domain or WiFi terminal according to the corresponding relationship.
  • the sending unit 83 is further configured to send an accounting request message to the AAA server, indicating the AAA server. Charging the WiFi terminal.
  • the sending unit 83 is further configured to be used according to the bearer
  • the destination address of the uplink data service flow and the first IP address carried in the data packet of the uplink data service flow initiated by the WiFi terminal, and the first PDP context connection or the first PDN connection The data packet of the uplink data service flow is sent to the corresponding PS service domain, and is further configured to send, according to the first IP address, the data packet that is sent by the PS service domain to the downlink data service flow of the WiFi terminal. To the WiFi terminal.
  • the AC when the WiFi accesses the Internet service, the AC receives the data packet sent by the WiFi terminal and carries the uplink data service flow that accesses the Internet service.
  • the data packet is forwarded to the trusted gateway, where the data packet carries the destination address of the uplink data service flow, the first IP address, and the NAS-ID of the AC managing the WiFi terminal. And other information.
  • the sending unit 83 is configured according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the WiFi terminal. Corresponding relationship of the PS service domain session information sends the data packet route to the first GGSN, so that the WiFi terminal accesses the corresponding PS service domain.
  • the trusted gateway when the trusted gateway receives the downlink data service flow sent by the PS service domain to the WiFi terminal, according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the WiFi Corresponding relationship of the PS service domain session information of the terminal, if the AC has a routing function, the sending unit 83 sends a data packet carrying the downlink data service flow to the WiFi terminal according to the first IP address.
  • the first IP address is the same network segment as the IP address of the AC managing the WiFi terminal. If the AC does not have a routing function, the sending unit 83 sends a data packet carrying the downlink data service flow to the WiFi according to the first IP address and the NAS-ID in the WiFi terminal attribute information. terminal.
  • the connection establishing unit 62 is further configured to determine, according to the destination address of the uplink data service flow, a second access point name corresponding to the uplink data service flow, If the second GGSN corresponding to the second GGSN and the first GGSN or the second P-GW corresponding to the second access point name are not the same device as the first P-GW, The second PDP context connection of the second GGSN is connected to the second PDN of the second P-GW, and the third GGSN or the second P-GW is allocated to the third terminal of the PS terminal to access the PS service domain. IP address.
  • the sending unit 83 is further configured to: send, according to the destination address of the uplink data service flow and the third IP address, a data packet that carries the uplink data service flow by using the second PDP context connection Corresponding PS service domain; further configured to send, according to the third IP address, data of a downlink data service flow that is sent by the PS service domain received by the second PDP context connection or the second PDN connection to the WiFi terminal The message is sent to the WiFi terminal.
  • the receiving unit 61 is further configured to receive The charging termination message sent by the AAA server.
  • the connection deletion unit 84 is configured to delete the first PDP context connection or the first PDN connection after the receiving unit 61 receives the charging termination message.
  • the connection deleting unit 84 also deletes the A second PDP context connection or a second PDN connection.
  • the AC when the WiFi terminal accesses the PS service domain, the AC is used to monitor the situation in which the WiFi terminal accesses the PS service domain, and periodically accesses the traffic of the PS service domain by the WiFi terminal. Information such as duration.
  • the AAA server updates the CDR according to the information such as the traffic and duration reported by the AC, and sends a charging response message to the AC.
  • the WiFi terminal initiates the offline request message or the WiFi terminal disconnects the communication with the AC when the signal is weak
  • the AC sends an accounting termination message to the AAA
  • the AAA server closes the CDR file. And corresponding to the charging termination message, sending a charging termination message to the trusted gateway.
  • the receiving unit 61 of the trusted gateway deletes the first PDP context connection or the first PDN connection.
  • the sending unit 83 is configured to send an authentication request message to the AAA server, requesting the AAA server.
  • the WiFi terminal is authenticated.
  • the receiving unit 61 is further configured to receive an access response message sent by the AAA server, where the access response message carries attribute information of the WiFi terminal.
  • the AAA server receives the access request message sent by the sending unit 83, and responds to the access request message, and sends an access response message to the trusted gateway, where the access response message carries the WiFi terminal. Attribute information.
  • the attribute information of the WiFi terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a QOS information of the WiFi terminal, and a NAS-ID of an AC managing the WiFi terminal.
  • the first APN or QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the subscription information agreed upon when the WiFi terminal signs the contract with the operator. If the APN and QoS information are not agreed upon when the WiFi terminal signs an agreement with the operator, the default APN and the QoS default value may also be used in the trusted gateway.
  • the WiFi terminal accesses the PS service domain to establish a first PDP context connection or a first PDN connection with the PS service domain.
  • the receiving unit 61 After acquiring the attribute information of the WiFi terminal, the receiving unit 61 receives the DHCP request message sent by the WiFi terminal through the AC.
  • the AC sends the DHCP request message to the trusted gateway, where the DHCP request message encapsulates the identification number of the WiFi terminal, such as the MAC address or NAI of the terminal.
  • the trusted gateway After receiving the DHCP request message, the trusted gateway is triggered to establish a first PDP context connection or a first PDN connection.
  • the connection establishing unit 62 is configured to: establish a first PDP context connection by using the first GGSN corresponding to the first access point name, or establish a first PDN connection by using a P-GW corresponding to the first access point name, And obtaining a first IP address that is allocated by the first GGSN or the first P-GW to the WiFi terminal.
  • the sending unit 83 is further configured to send a DHCP response message to the WiFi terminal after the connection establishing unit establishes a first PDP context connection or a first PDN connection, where the DHCP response message carries the first IP address .
  • the connection establishing unit 62 is specifically configured to send a first PDP activation request message to the first GGSN corresponding to the first access point name, and receive the first GGSN. And returning a first PDP activation response message, where the first PDP activation response message carries a first IP address that is allocated by the first GGSN to the WiFi terminal to access a PS service domain.
  • the connection establishing unit 62 determines, according to the first APN, which GGSN the trusted gateway needs to establish a connection, and then sends a first PDP activation request message to the first GGSN corresponding to the first APN, where the first PDP
  • the activation request message carries the attribute information of the WiFi terminal, and the attribute information of the WiFi terminal is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GGSN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS service domain.
  • the first GGSN then returns a first PDP activation response message to the trusted gateway, where the PDP activation response message carries the first IP address assigned by the first GGSN to the trusted gateway. Specifically, determining, according to the networking, the first GGSN allocates a corresponding IP address to the WiFi terminal. For example, if the AC has a routing function, the first IP address assigned by the first GGSN to the WiFi terminal is the same network segment as the AC managing the WiFi terminal; if the AC has no routing function, the GGSN may not be limited to and managed. The same network segment of the AC of the WiFi terminal allocates a first IP address to the WiFi terminal.
  • the connection establishing unit 62 receives the first PDP activation response message returned by the first GGSN,
  • the trusted gateway establishes, according to the first IP address carried in the first PDP activation response message, a correspondence between the session information of the WiFi terminal in the wireless local area network and the PS service domain session information of the WiFi terminal, that is, the wireless
  • the session information of the local area network includes: a NAS-ID that manages the AC of the WiFi terminal, and the like;
  • the PS service domain session information of the WiFi terminal includes: the first IP address, and the trusted gateway that establishes a first PDP context connection GTP tunnel information bound to the first GGSN.
  • the downlink data service flows sent by the domain to the WiFi terminal are respectively routed to the corresponding PS service domain or WiFi terminal according to the corresponding relationship.
  • the sending unit 83 is further configured to send an accounting request message to the AAA server, indicating the AAA server. Charging the WiFi terminal.
  • the trusted gateway monitors the situation in which the WiFi terminal accesses the PS service domain, and periodically reports the WiFi terminal access to the AAA server. Information such as traffic and duration of the PS service domain.
  • the AAA server charges the WiFi terminal according to the information such as the traffic and duration reported by the trusted gateway, updates the CDR, and sends an accounting response message to the trusted gateway.
  • the sending unit 83 when the WiFi terminal accesses the PS service domain, the sending unit 83: the destination address and the location of the uplink data service flow carried in the data packet carrying the uplink data service flow initiated by the WiFi terminal Transmitting, by the first PDP context connection or the first PDN connection, the data packet carrying the uplink data service flow to the corresponding PS service domain; and further, according to the first IP address Sending, by the data terminal, the data packet of the downlink data service flow that is sent by the PS service domain to the WiFi terminal to the WiFi terminal.
  • the AC when the WiFi terminal accesses the Internet service, the AC receives the data message sent by the WiFi terminal and carries the uplink data service flow that accesses the Internet service.
  • the data packet is forwarded to the trusted gateway, where the data packet carries a destination address of the uplink data service flow, the first IP address, and the NAS that manages the AC of the WiFi terminal. ID and other information.
  • the sending unit 83 of the trusted gateway is configured according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway. Corresponding relationship of PS service domain session information of the WiFi terminal will be the data message road And sent to the first GGSN, so that the WiFi terminal accesses the corresponding PS service domain.
  • the trusted gateway when the trusted gateway receives the downlink data service flow sent by the PS service domain to the WiFi terminal, according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the WiFi Corresponding relationship of the PS service domain session information of the terminal, if the AC has a routing function, the sending unit 83 sends a data packet carrying the downlink data service flow to the WiFi terminal according to the first IP address.
  • the first IP address is the same network segment as the IP address of the AC managing the WiFi terminal. If the AC does not have a routing function, the sending unit 83 sends a data packet carrying the downlink data service flow to the WiFi according to the first IP address and the NAS-ID in the WiFi terminal attribute information. terminal.
  • the connection establishing unit 62 is further configured to determine, according to the destination address of the uplink data service flow, a second access point name corresponding to the uplink data service flow, If the second GGSN corresponding to the second GGSN and the first GGSN or the second P-GW corresponding to the second access point name are not the same device as the first P-GW, The second PDP context connection of the second GGSN is connected to the second PDN of the second P-GW, and the third GGSN or the second P-GW is allocated to the third terminal of the PS terminal to access the PS service domain. IP address.
  • the sending unit 83 is further configured to: according to the destination address of the uplink data service flow and the third IP address, carry the uplink data service flow by using the second PDP context connection or the second PDN connection.
  • the data packet is sent to the corresponding PS service domain; and is further configured to send, according to the third IP address, a downlink that is sent by the second PDP context connection or the second PDN connection to the WiFi terminal.
  • a data message of the data service flow is sent to the WiFi terminal.
  • the sending unit 83 is further configured to send a charging termination message to the AAA server when the WiFi terminal goes offline.
  • the connection deletion unit 84 is configured to delete the first PDP context connection or the first PDN connection after the sending unit sends the charging termination message to the AAA server.
  • the connection deleting unit 84 also deletes The second PDP context connection or the second PDN connection.
  • the trusted gateway 90 further includes: a sending unit 93, an obtaining unit 94, and a connection deleting unit 95.
  • the sending unit 93 is configured to forward an authentication request message that the access controller AC requests the AAA server to authenticate the WiFi terminal to the AAA server, and is further configured to use the AAA server to the WiFi terminal.
  • the authentication response message is forwarded to the AC, and the authentication response message carries the attribute information of the WiFi terminal.
  • the trusted gateway in this implementation acts as a relay of the AC and the AAA server.
  • the WiFi terminal is attached to the WLAN and accesses the wireless access point of the wireless local area network, and the AC sends an authentication request message to the AAA server.
  • the trusted gateway is configured as a relay, and the sending unit 93 of the trusted gateway forwards the authentication request message sent by the AC to the AAA server.
  • the AAA server After the AAA server successfully authenticates the WiFi terminal, it sends an authentication response message to the AC. After the receiving unit 61 of the trusted gateway receives the authentication response message sent by the AAA server, the sending unit 93 forwards the authentication response message to the AC.
  • the authentication response message carries attribute information of the WiFi terminal.
  • the obtaining unit 94 is configured to obtain attribute information of the WiFi terminal from the authentication response message.
  • the obtaining unit 94 of the trusted gateway parses the authentication response message sent by the AAA server, and obtains the WiFi from the authentication response message.
  • the attribute information of the terminal includes: a second IP address of the WiFi terminal, an IMSI, a first APN, a WiFi terminal QOS, and a NAS-ID.
  • the first APN or QoS attribute information in the attribute information of the WiFi terminal may be obtained by the trusted gateway from the AAA server, and the AAA server stores the WiFi terminal and the operator. Signing information agreed upon at the time of signing. If the APN and the QoS information are not agreed upon when the WiFi terminal signs the contract with the operator, the default APN may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the first PDP context connection or the first PDN connection may be used in the trusted gateway, and the default value of the QoS is between the establishment of the WiFi service domain and the PS service domain.
  • the connection establishing unit 62 is configured to: establish a first PDP context connection by using the first GGSN corresponding to the first access point name, or establish a first PDN connection by using a P-GW corresponding to the first access point name, And obtaining a first IP address that is allocated by the first GGSN or the first P-GW to the WiFi terminal.
  • the sending unit 83 is further configured to send a DHCP response message to the WiFi terminal after the connection establishing unit establishes a first PDP context connection or a first PDN connection, where the DHCP response message carries the first IP address .
  • the connection establishing unit 62 is specifically configured to send a first PDP activation request message to the first GGSN corresponding to the first access point name, and receive the first GGSN. Returning a first PDP activation response message, where the first PDP activation response message carries a first IP address assigned by the first GGSN to the WiFi terminal to access a PS service domain; and sends a DHCP response message to the WiFi terminal The DHCP response message carries the first IP address.
  • the connection establishing unit 62 determines, according to the first APN, which GGSN the trusted gateway needs to establish a connection, and then sends a first PDP activation request message to the first GGSN corresponding to the first APN, where the first PDP
  • the activation request message carries the attribute information of the WiFi terminal, and the attribute information of the WiFi terminal is used by the first GGSN to establish a first PDP context connection with the trusted gateway.
  • the first GGSN allocates a first IP address to the WiFi terminal, where the first IP address is used by the WiFi terminal to access the PS service domain.
  • the first GGSN then returns a first PDP activation response message to the trusted gateway, where the PDP activation response message carries the first IP address assigned by the first GGSN to the trusted gateway.
  • the home network determines that the first GGSN allocates a corresponding IP address to the WiFi terminal. For example, if the AC has a routing function, the first IP address assigned by the first GGSN to the WiFi terminal is the same network segment as the AC managing the WiFi terminal; if the AC has no routing function, the GGSN may not be limited to and managed. The same network segment of the AC of the WiFi terminal allocates a first IP address to the WiFi terminal.
  • the connection establishing unit 62 receives the first PDP activation response message returned by the first GGSN, and the trusted gateway establishes the session information of the WiFi terminal in the wireless local area network according to the first IP address carried in the first PDP activation response message.
  • the session information of the wireless local area network includes: a NAS-ID that manages the AC of the WiFi terminal, and the like;
  • the PS service domain session information of the WiFi terminal includes: the first The IP address, the GTP tunnel information bound between the trusted gateway and the first GGSN that establishes the first PDP context connection.
  • the downlink data service flows sent by the domain to the WiFi terminal are respectively routed to the corresponding PS service domain or WiFi terminal according to the corresponding relationship.
  • the sending unit 93 according to the bearer of the WiFi terminal
  • the destination address of the uplink data service flow carried in the data packet of the initiating uplink data service flow and the first IP address, and the uplink data is carried by the first PDP context connection or the first PDN connection.
  • the data packet of the service flow is sent to the corresponding PS service domain, and is further configured to send, according to the first IP address, a data packet that is sent by the PS service domain to the downlink data service flow of the WiFi terminal, to the WiFi terminal.
  • the AC when the WiFi accesses the Internet service, the AC receives the data packet sent by the WiFi terminal and carries the uplink data service flow that accesses the Internet service.
  • the data packet is forwarded to the trusted gateway, where the data packet carries the destination address of the uplink data service flow, the first IP address, and the NAS-ID of the AC managing the WiFi terminal. And other information.
  • the sending unit 93 is configured according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the WiFi terminal. Corresponding relationship of the PS service domain session information sends the data packet route to the first GGSN, so that the WiFi terminal accesses the corresponding PS service domain.
  • the trusted gateway when the trusted gateway receives the downlink data service flow sent by the PS service domain to the WiFi terminal, according to the session information of the wireless local area network of the WiFi terminal established in the trusted gateway, and the WiFi Corresponding relationship of the PS service domain session information of the terminal, if the AC has a routing function, the sending unit 93 sends a data packet carrying the downlink data service flow to the WiFi terminal according to the first IP address.
  • the first IP address is the same network segment as the IP address of the AC managing the WiFi terminal. If the AC does not have a routing function, the sending unit 93 is configured according to the first IP address and the WiFi terminal attribute.
  • the NAS-ID in the information sends a data packet carrying the downlink data service flow to the WiFi terminal.
  • the connection establishing unit 62 is further configured to determine, according to the destination address of the uplink data service flow, a second access point name corresponding to the uplink data service flow, If the second GGSN corresponding to the second GGSN and the first GGSN or the second P-GW corresponding to the second access point name are not the same device as the first P-GW, The second PDP context connection of the second GGSN is connected to the second PDN of the second P-GW, and the third GGSN or the second P-GW is allocated to the third terminal of the PS terminal to access the PS service domain. IP address.
  • the sending unit 93 is further configured to: according to the destination address of the uplink data service flow and the third IP address, carry the uplink data service flow by using the second PDP context connection or the second PDN connection.
  • the data packet is sent to the corresponding PS service domain; and is further configured to send, according to the third IP address, a downlink that is sent by the second PDP context connection or the second PDN connection to the WiFi terminal.
  • a data message of the data service flow is sent to the WiFi terminal.
  • the sending unit 93 is further configured to send an accounting request message to the AAA server, indicating the AAA server. Charging the WiFi terminal.
  • the AC monitors the situation in which the WiFi terminal accesses the PS service domain, and periodically reports the WLAN server to the AAA server to access the PS service domain.
  • Information such as traffic and duration.
  • the sending unit 93 forwards information such as the traffic and duration reported by the AC to the AAA server.
  • the AAA server updates the CDR according to the information such as the traffic and duration reported by the AC, and sends a charging response message to the AC.
  • the sending unit 93 is further configured to forward the charging termination message sent by the AC to the AAA server.
  • the connection deletion unit 95 is configured to delete the trusted gateway first PDP context connection or the first PDN connection according to the charging termination message forwarded by the sending unit 93.
  • the connection deletion unit 95 also deletes the charging termination message according to the forwarding unit 93.
  • the WiFi terminal initiates a offline request message or the WiFi terminal is After the communication with the AC is disconnected, the AC sends a charging termination message to the AAA, and the sending unit 93 forwards the charging termination message sent by the AC to the AAA server.
  • the connection deletion unit 95 deletes the trusted gateway first PDP context connection or the first PDN connection according to the charging termination message.
  • the AAA server closes the CDR file in response to the charging termination message.
  • the WiFi terminal provided by the embodiment of the present invention accesses the trusted gateway of the PS service domain, and triggers the trusted gateway to establish a first PDP context connection or a first PDN by using the charging request message or the DHCP request message received by the receiving unit.
  • the trusted gateway is used as an access point for accessing the PS service domain, and the WiFi terminal can access the PS service domain through a wireless local area network, a trusted gateway, and an established PDP context connection or a PDN connection, so that the terminal does not need to be trusted.
  • a special tunnel is established between the gateways, and the WiFi terminal does not need to perform two authentications, which reduces the load on the WiFi terminal and reduces the complexity and cost of the operation of the WiFi terminal.
  • the trusted gateways involved in the embodiments of the present invention may be deployed on the existing network elements, such as the GGSN, the PDG, or the P-GW.
  • the existing network elements such as the GGSN, the PDG, or the P-GW.
  • the foregoing program may be stored in a computer readable storage medium, and the program is executed when executed.
  • the foregoing steps include the steps of the foregoing method embodiments; and the foregoing storage medium includes: a medium that can store program codes, such as a ROM, a RAM, a magnetic disk, or an optical disk.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明实施例提供了一种WiFi终端接入PS业务域的方法和可信网关,能够减轻WiFi终端的负荷,降低WiFi终端操作的复杂度和成本。该方法包括:接收验证、授权和记账AAA服务器发送的计费请求消息或WiFi终端发送的动态主机设置协议DHCP请求消息;在接收到计费请求消息或DHCP请求消息后,根据WiFi终端的属性信息,可信网关与PS业务域建立第一包数据协议PDP上下文连接或第一分组数据网络PDN连接,使得WiFi终端通过无线局域网,可信网关以及建立的第一PDP上下文连接或第一PDN连接接入PS业务域;其中,WiFi终端的属性信息从AAA服务器中获得,用于可信网关为WiFi终端接入PS业务域建立与PS业务域之间的第一PDP上下文连接或第一PDN连接。

Description

一种 WiFi终端接入分组数据 PS业务域的方法和可信网关
技术领域 本发明涉及通信技术领域, 尤其涉及一种 WiFi 终端接入分组数据 PS业务域的方法和可信网关。 背景技术
移动通信网络与 WLAN ( Wireless Local Access Network, 无线局域 网) 的融合有着广泛的需求, 国内外运营商非常关注。 运营商希望通过 WLAN用户可以访问运营商自营 PS业务域, 如游戏、 门户网站等。
2004年 3GPP R6 TS23.234曾定义了通过 WLAN访问运营商自营 PS ( Packet Switch, 分组交换) 业务域, 但在这个方案中 WiFi终端需要建 立与分组数据网关之间建立一条专门的隧道, 且用户首先进行两次认证, 包括无线接入网的认证和分组数据网关的认证。 这样 WiFi终端必须支持 与分组数据网关之间建立隧道的方案, 从而加重了 WiFi终端的负荷, 增 加了 WiFi终端的成本, 且 WiFi终端操作复杂。 发明内容
本发明的实施例提供一种 WiFi终端接入分组数据 PS业务域的方法 和可信网关, 用于解决现有技术存在着的 WiFi 终端的负荷过重, WiFi 终端成本过高的问题。 为达到上述目的, 本发明的实施例釆用如下技术方案:
一种 WiFi终端接入分组数据 PS业务域的方法, 应用于可信网关, 所述可信网关与无线局域网以及 PS业务域中的通信设备通信, 所述方法 包括:
接收验证、授权和记账 AAA服务器发送的计费请求消息或所述 WiFi 终端发送的动态主机设置协议 DHCP请求消息;
在接收到所述计费请求消息或所述 DHCP 请求消息后, 根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS 业务域建立第一包数据 协议 PDP上下文连接或第一分组数据网络 PDN连接, 使得所述 WiFi终 端通过所述无线局域网, 所述可信网关以及建立的第一 PDP上下文连接 或第一 PDN连接接入所述 PS业务域; 其中, 所述 WiFi终端的属性信息 从所述 AAA服务器中获得,用于可信网关为所述 WiFi终端接入 PS业务 域建立与 PS业务域之间的第一 PDP上下文连接或第一 PDN连接。
一种 WiFi终端接入分组数据 PS业务域的可信网关, 所述可信网关 与无线局域网以及 PS业务域中的通信设备通信, 所述可信网关包括: 接收单元, 用于接收验证、授权和记账 AAA服务器发送的计费请求 消息或所述 WiFi终端发送的动态主机设置协议 DHCP请求消息;
连接建立单元, 用于在接收到所述计费请求消息或所述 DHCP请求 消息后, 根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS业务 域建立第一包数据协议 PDP上下文连接或第一分组数据网络 PDN连接, 使得所述 WiFi终端通过所述无线局域网, 所述可信网关以及建立的第一 PDP上下文连接或第一 PDN连接接入所述 PS业务域; 其中, 所述 WiFi 终端的属性信息从所述 AAA服务器中获得, 用于可信网关为所述 WiFi 终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接或第一 PDN连接。 本发明实施例提供的 W i F i终端接入 P S业务域的方法和可信网关, 在可信网关接收到所述 AAA ( Authentication, Authorization, Accounting, 验证、 授权和记账)服务器发送的计费请求消息或所述 WiFi终端发送的 所述 DHCP ( Dynamic Host Configuration Protocol, 动态主机设置协议 ) 请求消息后, 建立第一 PDP ( Packet Data Protocol, 包数据协议 ) 连接或 第一 PDN ( Packet Data Network, 分组数据网络)连接, 使得所述可信网 关作为接入 PS业务域的接入点, 所述 WiFi终端能够通过无线局域网、 可信网关以及建立的 PDP上下文连接或 PDN连接访问 PS业务域, 这样 无需在终端以及可信网关之间建立一条专门的隧道, 所述 WiFi终端也不 需要进行两次认证, 减轻了 WiFi终端的负荷, 降低 WiFi终端操作的复 杂度和成本。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将 对实施例或现有技术描述中所需要使用的附图作简单地介绍, 显而易见 地, 下面描述中的附图仅仅是本发明的一些实施例, 对于本领域普通技 术人员来讲, 在不付出创造性劳动的前提下, 还可以根据这些附图获得 其他的附图。 图 1为本发明实施例一提供的一种 WiFi终端接入 PS业务域的方法 流程图;
图 2为本发明实施例二提供的一种 WiFi终端接入 PS业务域的方法 流程图;
图 3为本发明实施例三提供的另一种 WiFi终端接入 PS业务域的方 法流程图; 图 4为本发明实施例四提供的又一种 WiFi终端接入 PS业务域的方 法流程图; 图 5为本发明实施例五提供的又一种 WiFi终端接入 PS业务域的方 法流程图; 图 6为本发明实施例六提供的一种 WiFi终端接入 PS业务域的可信 网关结构框图;
图 7为本发明实施例六提供的另一种 WiFi终端接入 PS业务域的可 信网关结构框图;
图 8为本发明实施例六提供的又一种 WiFi终端接入 PS业务域的可 信网关结构框图;
图 9为本发明实施例六提供给的又一种 WiFi终端接入 PS业务域的 可信网关结构框图。
具体实施方式 下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案 进行清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实 施例, 而不是全部的实施例。 基于本发明中的实施例, 本领域普通技术 人员在没有做出创造性劳动前提下所获得的所有其他实施例, 都属于本 发明保护的范围。
实施一、
本发明实施例提供了一种 WiFi终端接入 PS业务域的方法, 应用于 可信网关,所述可信网关与无线局域网以及 PS业务域中的通信设备通信 , 如图 1所示, 该方法包括:
5101、可信网关接收验证、授权和记账 AAA服务器发送的计费请求 消息或所述 WiFi终端发送的动态主机设置协议 DHCP请求消息。
在对所述 WiFi终端进行认证后, 可信网关接收 AAA服务器发送的 计费请求消息或 WiFi 终端发送的 DHCP请求消息。 该计费请求消息或 DHCP请求消息用于触发所述可信网关与所述 P S业务域建立第一 PDP上 下文连接或第一 PDN连接。
5102、 在接收到所述计费请求消息或所述 DHCP请求消息后, 根据 所述 WiFi终端的属性信息, 所述可信网关与所述 PS业务域建立第一包 数据协议 PDP上下文连接或第一分组数据网络 PDN连接 ,使得所述 WiFi 终端通过所述无线局域网, 所述可信网关以及建立的第一 PDP上下文连 接或第一 PDN连接接入所述 PS业务域; 其中, 所述 WiFi终端的属性信 息从所述 AAA服务器中获得,用于可信网关为所述 WiFi终端接入 PS业 务域建立与 PS业务域之间的第一 PDP上下文连接或第一 PDN连接。
所述 WiFi 终端的属性信息可以包括: WiFi 终端的第二 IP地址、 IMSI(International Mobile Subscriber Identification,国际移动用户识另1 J码)、 第一 APN ( Access Point Name,接入点的名称)、 WiFi终端 QOS ( quality of service ,服务质量 M言息、管理所述 WiFi终端的 AC( Access Controller, 接入控制器) 的 NAS-ID ( Network Access Server-Identity, 用户接入服务 器编号) 。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接或 第一 PDN连接。
在第二代或第三代通信网络中, 当可信网关接收到所述计费请求消 息或所述 DHCP请求消息后, 根据所述 WiFi终端的属性信息, 所述可信 网关建立与所述第一 APN 对应的第一 GGSN ( Gateway GPRS Support Node, 网关通用分组无线服务支持节点) 的第一 PDP上下文连接。 在 LTE 通信网络中, 当可信网络接收到所述计费请求消息或所述 DHCP请求消息后, 根据所述 WiFi终端的属性信息, 所述可信网关建立 与所述第一 APN对应的第一 P-GW ( PDN Gateway, 分组数据网络网关) 的第一 PDN连接。 本发明实施例提供的 W i F i终端接入 P S业务域的方法和可信网关, 在可信网关接收到所述 AAA服务器发送的计费请求消息或所述 WiFi终 端发送的所述 DHCP 请求消息后, 与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW 建立第一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址, 使得所述可信网关作为接入 PS业务域的接入 点, 所述 WiFi终端能够通过无线局域网、可信网关以及建立的 PDP上下 文连接或 PDN连接访问 PS业务域, 这样无需在终端以及可信网关之间 建立一条专门的隧道, 所述 WiFi 终端也不需要进行两次认证, 减轻了 WiFi终端的负荷, 降低 WiFi终端操作的复杂度和成本。
实施例二、 本发明实施例提供的 WiFi终端接入 PS业务域的方法, 该方法的执 行主体为可信网关, 以下的具体描述以第二代或第三代通信网络为例, 如图 2所示, 其中所述可信网关接收 AAA服务器发送的计费请求消息, 所述可信网关与第一 GGSN建立第一 PDP上下文连接, 具体包括:
S201、 所述 AC对所述 WiFi终端进行认证, 并向所述 WiFi终端分 配所述无线局域网内的第二 IP地址。
在所述 WiFi终端接入无线局域网过程中 , WiFi终端从 AP ( Access Point, 无线接入点 )接入到 AC , AC请求 AAA服务器对该 WiFi终端进 行认证, 具体的认证方式可以是 EAP-SIM/AKA认证或 Portal认证。 认证 完成后, AC请求 BRAS ( Broadband Remote Access Server, 宽带远程接 入服务器) 或其它的 IP地址分配服务器向所述 WiFi终端分配无线局域 网内的第二 IP地址。
S202、可信网关接收 AAA服务器发送的计费请求消息, 所述计费请 求消息中携带有所述 WiFi终端的属性信息。
在对所述 WiFi终端分配完所述第二 IP地址后,所述 AC向所述 AAA 服务器发送计费请求消息, 请求所述 AAA服务器对开始对所述 WiFi终 端进行计费。 所述 AAA服务器响应所述 AC发送的计费请求消息, 打开 CDR ( calling detail records, 呼叫详细记录) 。 然后所述 AAA服务器在 所述计费请求消息中携带有所述 WiFi终端的属性信息, 将所述携带有所 述 WiFi终端的属性信息的计费请求消息发送给所述可信网关。 当然所述 AAA服务器也可以直接将所述 AC发送的计费请求消息转 发给所述可信网关, 可信网关中预设有 WiFi终端的属性信息。 其中所述 WiFi 终端的属性信息包括: WiFi 终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端 QOS信息、 管理所述 WiFi终端的 AC的 NAS-ID。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接。
S203、 可信网关与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi 终端的第一 IP地址。 该可信网关接收到 AAA服务器发送的计费请求消息后 ,被触发与所 述第一 APN对应的第一 GGSN建立第一 PDP上下文连接。 首先可信网 关根据所述第一 APN 信息寻址相应的 GGSN。 如第一 APN 具体为 CMNET, 可信网关寻址到访问 Internet的 GGSN。 然后可信网关向该访 问 Internet的 GGSN发送第一 PDP激活请求消息,建立 WiFi终端与访问 Internet的 GGSN的第一 PDP上下文连接。
其中第一 PDP激活请求消息中携带有所述 WiFi终端的属性信息, 用于所述第一 GGSN与所述可信网关建立第一 PDP上下文连接。 该第一 GGSN在接收到可信网关发送的第一激活请求消息后, 向所 述 WiFi终端分配第一 IP地址, 该第一 IP地址用于所述 WiFi终端访问 PS业务域。 然后该第一 GGSN向可信网关返回第一 PDP激活响应消息, 所述第一 PDP激活响应消息中携带有第一 GGSN分配的第一 IP地址。 可信网关接收所述第一 GGSN返回的第一 PDP激活响应消息,并根 据所述第一 PDP激活响应消息中携带的第一 IP地址, 建立所述 WiFi终 端在无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对 应关系, 即所述无线局域网的会话信息包括: 所述 WiFi 终端的第二 IP 地址、 管理所述 WiFi终端的 AC的 NAS-ID等; 所述 WiFi终端的 PS业 务域会话信息包括所述第一 IP地址、建立第一 PDP上下文连接的所述可 信网关与所述第一 GGSN之间绑定的 GTP隧道信息。 所述可信网关建立 的所述 WiFi终端在无线局域网的会话信息与所述 WiFi终端的 PS业务域 会话信息的对应关系, 用于将所述 WiFi终端发起的上行数据业务流或所 述 PS业务域发送给所述 WiFi终端的下行数据业务流根据所述对应关系 分别路由到相应的 PS业务域或 WiFi终端。
S204、在所述可信网关建立第一 PDP上下文连接后,通过所述 AAA 服务器向接入控制器 AC发送计费请求响应消息,所述计费请求响应消息 中携带有所述第一 IP地址, 使得所述 WiFi终端可以通过无线局域网访 问所述 PS业务域。
在所述可信网关建立与所述第一 GGSN的第一 PDP上下文连接后, 可信网关向所述 AAA服务器发送计费请求响应消息, 所述 AAA服务器 将所述计费请求响应消息转发给所述 AC , 从而使得所述 WiFi终端可以 通过无线局域网访问 PS业务域。
进一步的, 在所述可信网关建立所述第一 PDP上下文连接后, 在所 述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据 业务流时, 所述可信网关将承载所述上行数据业务流的数据报文中携带 的所述第二 IP地址转换为所述第一 IP地址;所述可信网关根据所述上行 数据业务流的目的地址和所述第一 IP地址,通过所述第一 PDP上下文连 接 ,将所述承载所述上行数据业务流的数据报文发送给相应的 PS业务域。
例如, 所述 WiFi访问 Internet业务时, AC接收到所述 WiFi终端发 起的访问所述 Internet 业务的上行数据业务流后将所述上行数据业务流 转发给所述可信网关, 所述可信网关根据可信网关中建立的所述 WiFi终 端的无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对 应关系, 将承载所述上行数据业务流的数据报文中携带的所述第二 IP地 址转换为所述第一 IP地址。 然后所述上行数据业务流的目的地址和所述第一 IP地址, 所述可信 网关通过所述第一 PDP上下文连接, 将承载所述上行数据业务流的数据 报文发送给相应的 PS业务域。
相应的, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的承载下行数据业务流的数据报文时, 还包括: 所述可信网关将承载 所述下行数据业务流的数据报文中携带的所述第一 IP地址转换为所述第 二 IP地址;所述可信网关根据所述第二 IP地址将承载所述下行数据业务 流的数据报文发送给所述 WiFi终端。
具体的,根据可信网关中建立的所述 WiFi终端的无线局域网的会话 信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 所述可信网关 将承载所述下行数据业务流的数据报文中携带的所述第一 IP地址转换为 所述第二 IP地址。所述可信网关根据所述第二 IP地址将承载所述下行数 据业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述可信网关建立所述第一 PDP上下文连接后, 在所 述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据 业务流时, 可信网关根据所述上行数据业务流的目的地址确定所述上行 数据业务流的第二接入点名称,若所述第二接入点名称对应的第二 GGSN 与所述第一 GGSN不是同一设备, 所述可信网关建立与所述第二 GGSN 的第二 PDP上下文连接, 并获取所述第二 GGSN分配给所述 WiFi终端 访问 PS业务域的第三 IP地址。
所述可信网关将承载所述上行数据业务流的数据报文中携带的所述 第二 IP地址转换为所述第三 IP地址;所述可信网关根据所述上行数据业 务流的目的地址和所述第三 IP地址, 通过所述第二 PDP上下文连接, 将 所述承载所述上行数据业务流的数据报文发送给相应的 PS业务域。
在所述可信网关建立第二 PDP上下文连接后, 在所述可信网关通过 所述第二 PDP上下文连接接收到 PS业务域发送给所述 WiFi终端的下行 数据业务流时, 所述可信网关将承载所述下行数据业务流的数据报文中 携带的所述第三 IP地址转换为所述第二 IP地址,所述可信网关根据所述 第二 IP地址将承载所述下行数据业务流的数据报文发送给所述 WiFi终 端。
进一步的, 在所述 WiFi终端访问所述 PS业务域时, 所述 AC监控 所述 WiFi终端访问所述 PS业务域的情况,并周期性上 所述 WiFi终端 访问 PS业务域的流量和时长等信息。 AAA服务器根据所述 AC上报的流 量和时长的等信息, 更新 CDR, 并向所述 AC发送计费响应消息。
进一步的, 在所述 WiFi终端发起下线请求消息时或所述 WiFi终端 在信号较弱的情况下断开与所述 AC的通信后, 所述 AC向 AAA发送计 费终止消息后, AAA服务器关闭 CDR文件, 并响应该计费终止消息, 向所述可信网关发送计费终止消息。 所述可信网关在接收到所述计费终 止消息后,删除所述可信网关与所述第一 GG SN的第一 PDP上下文连接。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接, 在所 述可信网关在接收到所述计费终止消息后, 同时也删除所述第二 PDP上 下文连接。
其中, 为了保证 WiFi终端访问运营商 PS业务域的安全, 所述可信 网关与所述 AC之间可以建立 GRE ( Generic Routing Encapsulation, 通用 路由封装) 隧道或承载网隧道。 本发明实施例提供的 WiFi终端接入 PS业务域的方法, 所述 AC请 求所述 AAA服务器对所述 WiFi终端进行认证后, 所述 AC向所述 AAA 服务器发送计费请求消息。 所述 AAA服务器将所述计费请求消息发送给 可信网关, 从而触发可信网关与第一 GGSN建立第一 PDP上下文连接或 可信网关与第一 P-GW建立第一 PDN连接, 使得所述可信网关作为接入 PS 业务域的接入点, 所述 WiFi终端能够通过无线局域网、 可信网关以 及建立的 PDP上下文连接或 PDN连接访问 PS业务域, 这样无需在终端 以及可信网关之间建立一条专门的隧道, 所述 WiFi终端也不需要进行两 次认证, 减轻了 WiFi终端的负荷, 降低 WiFi终端操作的复杂度和成本。
实施例三、 本发明实施例提供了一种 WiFi终端接入 PS业务域的方法, 以下的 具体描述以第二代或第三代通信网络为例, 如图 3 所示, 其中所述可信 网关接收所述 WiFi终端发送的动态主机设置协议 DHCP请求消息,所述 DHCP请求消息触发所述可信网关与所述第一 GG SN建立第一 PDP上下 文连接, 该方法具体包括:
S301、 可信网关接收所述 WiFi终端发送的所述 DHCP请求消息。 在 WiFi终端通过 AC向网关发送 DHCP请求消息前, WiFi终端首 先需要附着到 WLAN, 并通过 AC请求 AAA服务器对所述 WiFi终端进 行认证。 在对 WiFi终端认证完成后, 所述 WiFi终端可以通过所述 AC 向所述可信网关 DHCP请求消息, 并在该 WiFi终端发送的所述 DHCP 请求消息中封装 WiFi终端的标识号 ,如 WiFi终端的 MAC( Media Access Control, 媒体接入控制)地址或 NAI ( Network Access Identifier, 网络访 问标识符) , 用于对 WiFi终端进行标识。
5302、 可信网关向 AAA服务器发送接入请求消息。 所述可信网关接收到所述 WiFi终端通过 AC发送的 DHCP请求消 息, 该 DHCP请求消息触发所述可信网关建立与相应的 GGSN建立 PDP 上下文连接。 这样所述可信网关首先需要向 AAA服务器获取所述 WiFi 终端的属性信息, 具体的所述可信网关向 AAA服务器发送接入请求消息 获取所述 WiFi终端的属性信息。
5303、可信网关接收 AAA服务器发送的接入响应消息, 所述接入响 应消息中携带有所述 WiFi终端的属性信息。 该 AAA服务器接收到所述可信网关发送的接入请求消息 ,对所述接 入请求消息进行响应, 向所述可信网关发送接入响应消息, 其中接入响 应消息中携带有 WiFi终端的属性信息。
其中所述 WiFi 终端的属性信息包括: WiFi 终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端的 QOS信息和管理所述 WiFi终端的 AC的 NAS-ID。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接。
5304、与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下 文连接,并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第 一 IP地址。 所述可信网关在接收到 AAA服务器发送的接入响应消息后 ,根据接 入响应消息中携带的 WiFi终端的第一 APN,确定所述可信网关具体需要 与哪个 GGSN建立连接,然后向与所述第一 APN对应的第一 GGSN发送 第一 PDP激活请求消息。
其中第一 PDP激活请求消息中携带有 WiFi终端的属性信息,该 WiFi 终端的属性信息用于所述第一 GGSN与所述可信网关建立第一 PDP上下 文连接。
该第一 GG SN在接收到可信网关发送的第一 PDP激活请求消息后, 向所述 WiFi终端分配第一 IP地址, 该第一 IP地址用于所述 WiFi终端 访问 PS业务域。 然后第一 GGSN向可信网关返回第一 PDP激活响应消 息,所述第一 PDP激活响应消息中携带有第一 GGSN分配的第一 IP地址。 具体的, 根据组网来确定, 第一 GGSN向所述 WiFi终端分配相应的 IP 地址。 例如, 若 AC具有路由功能, 第一 GGSN向所述 WiFi终端分配的 第一 IP地址与管理该 WiFi终端的 AC为同一网段; 若所述 AC无路由功 能, 则第一 GGSN可以不局限于与管理所述 WiFi终端的 AC同一网段向 所述 WiFi终端分配第一 IP地址。 可信网关接收所述第一 GGSN返回的第一 PDP激活响应消息,并根 据所述第一 PDP激活响应消息中携带的第一 IP地址, 建立所述 WiFi终 端在无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对 应关系, 即所述无线局域网的会话信息包括: 管理所述 WiFi终端的 AC 的 NAS-ID等; 所述 WiFi终端的 PS业务域会话信息包括: 所述第一 IP 地址、 建立第一 PDP上下文连接的所述可信网关与所述第一 GGSN之间 绑定的 GTP隧道信息。 所述可信网关建立的所述 WiFi终端的无线局域 网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 用于 将所述 WiFi 终端发起的上行数据业务流或所述 PS 业务域发送给所述 WiFi终端的下行数据业务流根据所述对应关系分别路由到相应的 PS 业 务域或 WiFi终端。
S305、 在所述可信网关建立第一 PDP上下文连接后, 向所述 WiFi 终端发送 DHCP响应消息,所述 DHCP响应消息携带有所述第一 IP地址。
进一步的,在所述可信网关向所述 WiFi终端发送 DHCP响应消息后 , 所述可信网关向所述 AAA服务器发送计费请求消息, 指示所述 AAA服 务器对所述 WiFi终端进行计费, AAA服务器响应所述计费请求消息, 打开 CDR。
进一步的, 所述可信网关建立第一 PDP 上下文连接后, 所述 WiFi 终端可以通过无线局域网访问 PS 业务域。 在所述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据业务流时, 还包括:
所述可信网关根据所述上行数据业务流的目的地址和所述第一 IP地 址, 通过所述第一 PDP上下文连接, 将所述承载所述上行数据业务流的 数据报文发送给相应的 PS业务域。
例如, 所述 WiFi访问 Internet业务时, AC接收到所述 WiFi终端发 送的承载访问所述 Internet 业务的上行数据业务流的数据报文后将所述 数据报文转发给所述可信网关, 所述数据报文中携带有所述上行数据业 务流的目的地址、 所述第一 IP地址和所述管理所述 WiFi终端的 AC的 NAS-ID等信息。 所述可信网关接收到所述承载所述上行数据业务流的数 据报文后, 根据可信网关中建立的所述 WiFi终端的无线局域网的会话信 息与所述 WiFi终端的 PS业务域会话信息的对应关系将所述数据报文路 由发送给所述第一 GGSN, 从而使得所述 WiFi终端接入到相应的 PS业 务域。
相应的, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的下行数据业务流时, 还包括: 所述可信网关根据所述第一 IP地址将 承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
具体的,根据可信网关中建立的所述 WiFi终端的无线局域网的会话 信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 若所述 AC具 有路由功能, 则所述可信网关根据所述第一 IP地址将承载所述下行数据 业务流的数据报文发送给所述 WiFi终端, 所述第一 IP地址与管理所述 WiFi终端的 AC的 IP地址为同一网段。 若所述 AC没有路由功能, 则所 述可信网关根据所述第一 IP地址和所述 WiFi终端属性信息中的 NAS-ID 将承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述可信网关建立所述第一 PDP上下文连接后, 在所 述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据 业务流时, 可信网关根据所述上行数据业务流的目的地址确定所述上行 数据业务流的第二接入点名称,若所述第二接入点名称对应的第二 GGSN 与所述第一 GGSN不是同一设备, 所述可信网关建立与所述第二 GGSN 的第二 PDP上下文连接, 并获取所述第二 GGSN分配给所述 WiFi终端 访问 PS业务域的第三 IP地址; 所述可信网关根据所述上行数据业务流 的目的地址和所述第三 IP地址, 通过所述第二 PDP上下文连接, 将所述 承载所述上行数据业务流的数据报文发送给相应的 PS业务域。
在所述可信网关建立第二 PDP上下文连接后, 在所述可信网关通过 所述第二 PDP上下文连接接收到 PS业务域发送给所述 WiFi终端的下行 数据业务流时, 所述可信网关根据所述第二 IP地址将承载所述下行数据 业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述 WiFi终端访问所述 PS业务域时, 所述 AC用于 监控所述 WiFi终端访问所述 PS业务域的情况, 并周期性上 所述 WiFi 终端访问 PS业务域的流量和时长等信息。 AAA服务器根据所述 AC上报 的流量和时长的等信息, 更新 CDR, 并向所述 AC发送计费响应消息。
进一步的, 在所述 WiFi终端发起下线请求消息时或所述 WiFi终端 在信号较弱的情况下断开与所述 AC的通信后, 所述 AC向 AAA发送计 费终止消息后, AAA服务器关闭 CDR文件, 并相应该计费终止消息, 向所述可信网关发送计费终止消息。 所述可信网关在接收到所述计费终 止消息后, 删除所述第一 PDP上下文连接。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接, 在所 述可信网关在接收到所述计费终止消息后, 同时也删除所述第二 PDP上 下文连接。
其中, 为了保证 WiFi终端访问 PS业务域的安全, 所述可信网关与 所述 AC之间可以建立 GRE隧道或承载网隧道。 本发明实施例提供的 WiFi终端接入 PS 业务域的方法, 所述 WiFi 终端认证完成后, 向所述可信网关发送 DHCP请求消息。 所述 DHCP请 求消息触发所述可信网关与相应的第一 GGSN建立第一 PDP上下文连接 或所述可信网关与相应的第一 P-GW建立第一 PDN连接, 使得所述可信 网关作为接入 PS业务域的接入点, 所述 WiFi终端能够通过无线局域网、 可信网关以及建立的 PDP上下文连接或 PDN连接访问 PS业务域, 这样 无需在终端以及可信网关之间建立一条专门的隧道, 所述 WiFi终端也不 需要进行两次认证, 减轻了 WiFi终端的负荷, 降低 WiFi终端操作的复 杂度和成本。
实施例四、 本发明实施例提供了一种 WiFi终端接入 PS业务域的方法, 以下方 法的具体描述以第二代或第三代通信网络为例, 如图 4 所示, 其中所述 可信网关接收所述 WiFi终端发送的动态主机设置协议 DHCP请求消息, 用于触发所述可信网关与所述第一 GGSN建立第一 PDP上下文连接。 具 体包括:
5401、 可信网关向所述 AAA 服务器发送认证请求消息, 请求所述 AAA服务器对所述 WiFi终端进行认证。 在该方法中, 所述可信网关还用于请求 AAA服务器对 WiFi终端进 行认证。 首先 WiFi终端附着到 WLAN, 通过无线局域网的 AC请求可信 网关进行认证。 可信网关向所述 AAA服务器发送认证请求消息, 请求所 述 AAA服务器对所述 WiFi终端进行认证。
5402、 在对所述 WiFi终端进行认证后, 所述可信网关向所述 AAA 服务器发送接入请求消息。
5403、可信网关接收所述 AAA服务器发送的接入响应消息, 所述接 入响应消息中携带有所述 WiFi终端的属性信息。 该 AAA服务器接收到所述可信网关发送的接入请求消息 ,对所述接 入请求消息进行响应, 向所述可信网关发送接入响应消息, 其中接入响 应消息中携带有 WiFi终端的属性信息。
其中所述 WiFi 终端的属性信息包括: WiFi 终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端的 QOS信息和管理所述 WiFi终端的 AC的 NAS-ID。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接。
5404、可信网关接收所述 WiFi终端发送的动态主机设置协议 DHCP 请求消息。
在获取到 WiFi终端的属性信息后, 所述可信网关接收 WiFi终端发 送的 DHCP请求消息, 所述 DHCP请求消息中封装 WiFi终端的标识号, 如终端的 MAC地址或 NAI, 用于对 WiFi终端进行标识。
S405、与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下 文连接,并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第 一 IP地址。 所述可信网关接收到所述 WiFi 终端发送的 DHCP 请求消息, 该 DHCP请求消息触发所述可信网关建立与第一 GG SN建立第一 PDP上下 文连接。 这样可信网关根据所述第一 APN, 确定可信网关具体需要与哪 个 GGSN建立连接,然后向与所述第一 APN对应的第一 GGSN发送第一 PDP激活请求消息。 其中第一 PDP激活请求消息中携带有 WiFi终端的属性信息,该 WiFi 终端的属性信息用于所述第一 GGSN与所述可信网关建立第一 PDP上下 文连接。
该第一 GGSN 在接收到可信网关发送的激活请求消息后, 向所述 WiFi终端分配第一 IP地址, 该第一 IP地址用于所述 WiFi终端访问 PS 业务域。 然后第一 GGSN向可信网关返回第一 PDP激活响应消息, 所述 第一 PDP激活响应消息中携带有第一 GGSN分配给可信网关的第一 IP 地址。 具体的, 根据组网来确定, 第一 GGSN向所述 WiFi终端分配相应 的 IP地址。 例如, 若 AC具有路由功能, 第一 GGSN向所述 WiFi终端 分配的第一 IP地址与管理该 WiFi终端的 AC为同一网段; 若所述 AC无 路由功能, 则第一 GGSN可不局限于与管理所述 WiFi终端的 AC同一网 段向所述 WiFi终端分配第一 IP地址。 可信网关接收所述第一 GGSN返回的第一 PDP激活响应消息,并根 据所述第一 PDP激活响应消息中携带的第一 IP地址, 建立所述 WiFi终 端在无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对 应关系, 即所述无线局域网的会话信息包括: 管理所述 WiFi终端的 AC 的 NAS-ID等; 所述 WiFi终端的 PS业务域会话信息包括: 所述第一 IP 地址、 建立第一 PDP上下文连接的所述可信网关与所述第一 GGSN之间 绑定的 GTP隧道信息。 所述可信网关建立的所述 WiFi终端在无线局域 网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 用于 将所述 WiFi 终端发起的上行数据业务流或所述 PS 业务域发送给所述 WiFi终端的下行数据业务流根据所述对应关系分别路由到相应的 PS 业 务域或 WiFi终端。
S406、 在所述可信网关与所述 PS业务域建立第一 PDP上下文连接 后, 可信网关向所述 WiFi终端发送 DHCP响应消息, 所述 DHCP响应消 息携带有所述第一 IP地址。 进一步的,在所述可信网关向所述 WiFi终端发送 DHCP响应消息后 , 所述可信网关向所述 AAA服务器发送计费请求消息, 指示所述 AAA服 务器对所述 WiFi终端进行计费, AAA服务器响应所述计费请求消息, 打开 CDR。 具体的, 在所述 WiFi终端访问所述 PS业务域时, 所述可信网关监 控所述 WiFi终端访问所述 PS业务域的情况,并周期性的向所述 AAA服 务器上报所述 WiFi终端访问所述 PS业务域的流量和时长等信息。 AAA 服务器根据所述可信网关上报的流量和时长等信息对所述 WiFi终端进行 计费, 更新 CDR, 并向所述可信网关发送计费响应消息。
进一步的, 所述可信网关建立第一 PDP 上下文连接后, 所述 WiFi 终端可以通过无线局域网访问 PS 业务域。 在所述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据业务流时, 还包括:
所述可信网关根据所述上行数据业务流的目的地址和所述第一 IP地 址, 通过所述第一 PDP上下文连接, 将承载所述上行数据业务流的数据 报文发送给相应的 PS业务域。
例如, 所述 WiFi终端访问 Internet业务时, AC接收到所述 WiFi终 端发送的承载访问所述 Internet 业务的上行数据业务流的数据报文后将 所述数据报文转发给所述可信网关, 所述数据报文中携带有所述上行数 据业务流的目的地址、 所述第一 IP地址和所述管理所述 WiFi终端的 AC 的 NAS -ID等信息。所述可信网关接收到所述承载所述上行数据业务流的 数据报文后, 根据可信网关中建立的所述 WiFi终端的无线局域网的会话 信息与所述 WiFi终端的 PS业务域会话信息的对应关系将所述数据报文 路由发送给所述第一 GGSN, 从而使得所述 WiFi终端接入到相应的 PS 业务域。
相应的, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的下行数据业务流时, 还包括: 所述可信网关根据所述第一 IP地址将承载所述下行数据业务流的数 据才艮文发送给所述 WiFi终端。
具体的,根据可信网关中建立的所述 WiFi终端的无线局域网的会话 信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 若所述 AC具 有路由功能, 则所述可信网关根据所述第一 IP地址将承载所述下行数据 业务流的数据报文发送给所述 WiFi终端, 所述第一 IP地址与管理所述 WiFi终端的 AC的 IP地址为同一网段。 若所述 AC没有路由功能, 则所 述可信网关根据所述第一 IP地址和所述 WiFi终端属性信息中的 NAS-ID 将承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述可信网关建立所述第一 PDP上下文连接后, 在所 述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据 业务流时, 可信网关根据所述上行数据业务流的目的地址确定所述上行 数据业务流的第二接入点名称,若所述第二接入点名称对应的第二 GGSN 与所述第一 GGSN不是同一设备, 所述可信网关建立与所述第二 GGSN 的第二 PDP上下文连接, 并获取所述第二 GGSN分配给所述 WiFi终端 访问 PS业务域的第三 IP地址; 所述可信网关根据所述上行数据业务流 的目的地址和所述第三 IP地址, 通过所述第二 PDP上下文连接, 将所述 承载所述上行数据业务流的数据报文发送给相应的 PS业务域。
在所述可信网关建立第二 PDP上下文连接后, 在所述可信网关通过 所述第二 PDP上下文连接接收到 PS业务域发送给所述 WiFi终端的下行 数据业务流时, 所述可信网关根据所述第二 IP地址将承载所述下行数据 业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述 WiFi终端发起下线请求消息时或所述 WiFi终端 在信号较弱的情况下断开与所述可信网关的通信后, 所述可信网关向所 述 AAA发送计费终止消息后, 所述 AAA服务器关闭 CDR文件, 并响应 该计费终止消息。 同时, 删除所述第一 PDP上下文连接。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接, 在所 述可信网关向所述 AAA发送计费终止消息后, 同时也删除所述第二 PDP 上下文连接。
其中, 为了保证 WiFi终端访问 PS业务域的安全, 在 AP与所述可 信网关之间还可以配置隧道, 其中 AP与 AC之间的信息通过 CAPWAP ( Control And Provisioning of Wireless Access Points Protocol Specification, 无线接入点的控制和监控协议规范)隧道传递, AP与可信 网关之间通过 GRE隧道或釆用承载网隧道传递。 本发明实施例提供的 WiFi终端接入 PS业务域的方法, 所述可信网 关请求 AAA服务器对所述 WiFi终端进行认证。 在认证完成后, 可信网 关从所述 AAA服务器获取所述 WiFi终端的属性信息。 然后在可信网关 接收到所述 WiFi终端发送的 DHCP请求消息后, 可信网关与第一 GGSN 建立第一 PDP上下文连接或可信网关与所述第一 P-GW建立第一 PDN连 接, 使得所述可信网关作为接入 PS业务域的接入点, 所述 WiFi终端能 够通过无线局域网、可信网关以及建立的 PDP上下文连接或 PDN连接访 问 PS业务域, 这样无需在终端以及可信网关之间建立一条专门的隧道, 所述 WiFi终端也不需要进行两次认证, 减轻了 WiFi终端的负荷, 降低 WiFi终端操作的复杂度和成本。
实施例五、 本发明实施例还提供了一种 WiFi终端接入 PS业务域的方法, 以下 的具体描述以第二代或第三代通信网络为例, 如图 5 所示, 其中所述可 信网关接收所述 WiFi终端发送的动态主机设置协议 DHCP请求消息,用 于触发所述可信网关与所述 PS业务域建立第一 PDP上下文连接。 具体 包括:
S501、可信网关将接入控制器 AC请求所述 AAA服务器对所述 WiFi 终端进行认证的认证请求消息转发给所述 AAA服务器。
本实施中所述可信网关作为所述 AC和所述 AAA服务器的中继。首 先 WiFi终端附着到 WLAN, 接入到无线局域网的无线接入点 AP, 所述 AC向所述 AAA服务器发送认证请求消息。 所述可信网关作为中继将所 述 AC发送的认证请求消息转发给所述 AAA服务器。
S502、 可信网关将所述 AAA服务器对所述 WiFi终端进行认证的认 证响应消息转发给所述 AC , 所述认证响应消息中携带有所述 WiFi终端 的属性信息。
AAA服务器对所述 WiFi终端进行认证成功后, 向所述 AC发送认 证响应消息。 所述可信网关接收到所述 AAA服务器发送的认证响应消息 后, 将所述认证响应消息转发给所述 AC。 所述认证响应消息中携带有所 述 WiFi终端的属性信息。
S503、可信网关从所述认证响应消息中获取所述 WiFi终端的属性信 息。
所述可信网关在接收到所述 AAA服务器发送的认证响应消息后,可 信网关解析 AAA服务器发送的认证响应消息,从所述认证响应消息中获 取所述 WiFi终端的属性信息。 其中所述 WiFi 终端的属性信息包括: WiFi 终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端 QOS、 NAS-ID。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接。
5504、可信网关接收所述 WiFi终端发送的动态主机设置协议 DHCP 请求消息。
在获取到 WiFi 终端的属性信息后, 所述 AC 将 WiFi 终端发送的 DHCP请求消息发送到可信网关, 所述 DHCP请求消息中封装 WiFi终端 的标识号, 如终端的 MAC地址或 NAI , 用于对 WiFi终端进行标识。
5505、与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下 文连接,并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第 一 IP地址。 在接收到 WiFi终端发送的 DHCP请求消息后, 所述可信网关根据 WiFi终端属性信息中的第一 APN , 确定可信网关具体需要与哪个 GG SN 建立连接, 然后向与所述第一 APN对应的第一 GGSN发送第一 PDP激 活请求消息。 其中第一 PDP激活请求消息中携带有 WiFi终端的属性信息,该 WiFi 终端的属性信息用于所述第一 GGSN与所述可信网关建立第一 PDP上下 文连接。
该第一 GGSN 在接收到可信网关发送的激活请求消息后, 向所述 WiFi终端分配第一 IP地址, 该第一 IP地址用于所述 WiFi终端访问 PS 业务域。 然后第一 GGSN向可信网关返回第一 PDP激活响应消息, 所述 第一 PDP激活响应消息中携带有第一 GGSN分配给可信网关的第一 IP 地址。 具体的, 根据组网来确定, 第一 GGSN向所述 WiFi终端分配相应 的 IP地址。 例如, 若 AC具有路由功能, 第一 GGSN向所述 WiFi终端 分配的第一 IP地址与管理该 WiFi终端的 AC为同一网段; 若所述 AC无 路由功能, 则第一 GGSN可不局限于与管理所述 WiFi终端的 AC同一网 段向所述 WiFi终端分配第一 IP地址。 可信网关接收所述第一 GGSN返回的第一 PDP激活响应消息,并根 据所述第一 PDP激活响应消息中携带的第一 IP地址, 建立所述 WiFi终 端在无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对 应关系, 即所述无线局域网的会话信息包括: 管理所述 WiFi终端的 AC 的 NAS-ID等; 所述 WiFi终端的 PS业务域会话信息包括: 所述第一 IP 地址、 建立第一 PDP上下文连接的所述可信网关与所述第一 GGSN之间 绑定的 GTP隧道信息。 所述可信网关建立的所述 WiFi终端在无线局域 网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 用于 将所述 WiFi 终端发起的上行数据业务流或所述 PS 业务域发送给所述 WiFi终端的下行数据业务流根据所述对应关系分别路由到相应的 PS 业 务域或 WiFi终端。 进一步的, 若所述可信网关和所述第一 GGSN之间建立 GTP隧道, 则所述 WiFi终端的 PS业务域会话信息还包括: 建立第一 PDP上下文连 接的所述可信网关与所述第一 GGSN之间绑定的 GTP隧道信息。
S506、 在所述可信网关与所述 PS业务域建立第一 PDP上下文连接 后, 可信网关向所述 WiFi终端发送 DHCP响应消息, 所述 DHCP响应消 息携带有所述第一 IP地址。
所述可信网关建立第一 PDP上下文连接后, 所述 WiFi终端可以通 过无线局域网访问 PS业务域。 在所述可信网关接收到所述 WiFi终端发 起的访问所述 PS业务域的上行数据业务流时, 还包括:
所述可信网关根据所述上行数据业务流的目的地址和所述第一 IP地 址, 通过所述第一 PDP上下文连接, 将承载所述上行数据业务流的数据 报文发送给相应的 PS业务域。
例如, 所述 WiFi访问 Internet业务时, AC接收到所述 WiFi终端发 送的承载访问所述 Internet 业务的上行数据业务流的数据报文后将所述 数据报文转发给所述可信网关, 所述数据报文中携带有所述上行数据业 务流的目的地址、 所述第一 IP地址和所述管理所述 WiFi终端的 AC的 NAS-ID等信息。 所述可信网关接收到所述承载所述上行数据业务流的数 据报文后, 根据可信网关中建立的所述 WiFi终端的无线局域网的会话信 息与所述 WiFi终端的 PS业务域会话信息的对应关系将所述数据报文路 由发送给所述第一 GGSN, 从而使得所述 WiFi终端接入到相应的 PS业 务域。
相应的, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的下行数据业务流时, 还包括:
所述可信网关根据所述第一 IP地址将承载所述下行数据业务流的数 据才艮文发送给所述 WiFi终端。
具体的,根据可信网关中建立的所述 WiFi终端的无线局域网的会话 信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 若所述 AC具 有路由功能, 则所述可信网关根据所述第一 IP地址将承载所述下行数据 业务流的数据报文发送给所述 WiFi终端, 所述第一 IP地址与管理所述 WiFi终端的 AC的 IP地址为同一网段。 若所述 AC没有路由功能, 则所 述可信网关根据所述第一 IP地址和所述 WiFi终端属性信息中的 NAS-ID 将承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述可信网关建立所述第一 PDP上下文连接后, 在所 述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据 业务流时, 可信网关根据所述上行数据业务流的目的地址确定所述上行 数据业务流的第二接入点名称,若所述第二接入点名称对应的第二 GGSN 与所述第一 GGSN不是同一设备, 所述可信网关建立与所述第二 GGSN 的第二 PDP上下文连接, 并获取所述第二 GGSN分配给所述 WiFi终端 访问 PS业务域的第三 IP地址; 所述可信网关根据所述上行数据业务流 的目的地址和所述第三 IP地址, 通过所述第二 PDP上下文连接, 将所述 承载所述上行数据业务流的数据报文发送给相应的 PS业务域。
在所述可信网关建立第二 PDP上下文连接后, 在所述可信网关通过 所述第二 PDP上下文连接接收到 PS业务域发送给所述 WiFi终端的下行 数据业务流时, 所述可信网关根据所述第二 IP地址将承载所述下行数据 业务流的数据报文发送给所述 WiFi终端。 进一步的, 在所述 WiFi终端访问所述 PS业务域时, 所述 AC监控 所述 WiFi终端访问所述 PS业务域的情况,并周期性向所述 AAA服务器 上报所述 WiFi终端访问 PS业务域的流量和时长等信息。 所述可信网关 将所述 AC上报的所述流量和时长等信息转发给所述 AAA服务器。 AAA 服务器根据所述 AC上报的流量和时长的等信息, 更新 CDR, 并向所述 AC发送计费响应消息。
进一步的, 在所述 WiFi终端发起下线请求消息时或所述 WiFi终端 在信号较弱的情况下断开与所述 AC的通信后, 所述 AC向 AAA发送计 费终止消息, 所述可信网关将所述 AC 发送的计费终止消息转发给所述 AAA服务器。 同时, 所述可信网关根据所述计费终止消息删除所述可信 网关与所述 GGSN的第一 PDP上下文连接。 所述 AAA服务器接收到所 述可信网关转发的所述计费终止消息后, 响应所述计费终止消息, 关闭 CDR文件。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接, 在所 述可信网关根据所述计费终止消息同时也删除所述第二 PDP 上下文连 接。
其中, 为了保证 WiFi终端访问 PS业务域的安全, 可信网关与 AP 之间的信息需要通过 GRE隧道或釆用承载网隧道传递。 本发明实施例提供的 WiFi终端接入 PS业务域的方法, 可信网关作 为 AC和 AAA服务器的中继, 从所述 AAA服务器发送给所述 AC的所 述 WiFi终端的认证响应消息中获取所述 WiFi终端的属性信息。 在获取 了所述 WiFi 终端的属性信息后, 可信网关接收所述 WiFi 终端发送的 DHCP请求消息,建立可信网关与所述 PS业务域的第一 PDP上下文连接 或第一 PDN连接, 从而使得所述可信网关作为接入 PS业务域的接入点, 所述 WiFi终端能够通过无线局域网、可信网关以及建立的 PDP上下文连 接或 PDN连接访问 PS业务域, 这样无需在终端以及可信网关之间建立 一条专门的隧道, 减轻了 WiFi终端的负荷, 降低 WiFi终端操作的复杂 度和成本。
进一步的, 本发明提供的实施例二、 三、 四、 五都以在第二代或第 三代通信网络系统下对本发明提供的 WiFi终端接入 PS业务域的方法进 行了说明。 当然对于本发明实施例二、 三、 四、 五提供的方法同样可以 是应用在 LTE通信网络系统中, 只是可信网关在接收到计费请求消息或 DHCP请求消息后, 与第一 P-GW之间建立第一 PDN连接, 并获得第一 PDN分配给 WiFi终端访问 PS业务域的第一 IP地址。至于可信网关与第 一 P-GW之间建立 PDN 连接的过程为现有技术, 本发明在此不再赘述。
进一步的, WiFi终端要优先通过无线局域网访问运营商的 PS业务 域, 所述 WiFi终端上的应用程序需要向所述 WiFi终端下发缺省的接入 点名称类型或所述 WiFi终端上的应用程序不向所述 WiFi终端下发接入 点名称, 所述 WiFi终端根据缺省的接入点名称类型优先通过所述无线局 域网接入所述 PS业务域。
实施例六、 本发明实施例提供了一种 WiFi终端接入 PS业务域的可信网关 60 , 如图 6所示, 包括接收单元 61和连接建立单元 62。
所述接收单元 61 , 用于接收验证、 授权和记账 AAA服务器发送的 计费请求消息或所述 WiFi 终端发送的动态主机设置协议 DHCP请求消 息。
所述连接建立单元 62 , 用于在接收到所述计费请求消息或所述 DHCP请求消息后, 根据所述 WiFi终端的属性信息, 所述可信网关建立 第一包数据协议 PDP上下文连接或第一分组数据网络 PDN连接,以使得 所述可信网关作为接入 PS业务域的接入点, 所述 WiFi终端可以通过无 线局域网无隧道接入到所述可信网关后通过所述可信网关访问 PS 业务 域。
其中, 若所述接收单元 61接收的是所述 AAA服务器发送的计费请 求消息, 该计费请求消息用于触发所述可信网关与所述 P S业务域建立第 一 PDP上下文连接或第一 PDN连接。 如图 7所示, 所述可信网关 70还 包括: 地址转换单元 73、 发送单元 74和连接删除单元 75。 在所述 WiFi终端接入无线局域网过程中, WiFi终端从 AP接入到 AC , AC请求 AAA服务器对该 WiFi终端进行认证, 具体的认证方式可 以是 EAP-SIM/AKA认证或 Portal认证。 认证完成后, AC请求 BRAS或 其它的 IP地址分配服务器向所述 WiFi终端分配无线局域网内的第二 IP 地址。 在对所述 WiFi终端分配完所述第二 IP地址后, 所述 AC向所述 AAA服务器发送计费请求消息,请求所述 AAA服务器对开始对所述 WiFi 终端进行计费。 所述 AAA服务器响应所述 AC发送的计费请求消息, 打 开 CDR ( calling detail records, 呼叫详细记录) 。 然后所述 AAA服务器 在所述计费请求消息中携带有所述 WiFi终端的属性信息, 将所述携带有 所述 WiFi终端的属性信息的计费请求消息发送给所述可信网关的接收单 元 61。 在所述计费请求消息中携带有所述 WiFi终端的属性信息。
其中所述 WiFi 终端的属性信息包括: WiFi 终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端 QOS信息和 NAS-ID。 所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接或 第一 PDN连接。
所述连接建立单元 62 用于: 与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW 建立第一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址。
所述发送单元 74 , 用于在所述连接建立单元 62建立所述第一 PDP 上下文连接或第一 PDN连接后,通过所述 AAA服务器向接入控制器 AC 发送计费请求响应消息, 所述计费请求响应消息中携带有所述第一 IP地 址, 使得所述 WiFi终端可以通过无线局域网访问所述 PS业务域。
具体的, 在第二代或第三代通信网络中, 所述连接建立单元 62具体 用于向所述第一接入点名称对应的第一 GGSN发送第一 PDP激活请求消 息; 接收所述第一 GGSN返回的第一 PDP激活响应消息, 所述第一 PDP 激活响应消息中携带有所述第一 GGSN分配给所述 WiFi终端访问 PS业 务域的第一 IP地址。 例如, 该可信网关的接收单元 61接收到 AAA服务 器发送的计费请求消息后,该可信网关被触发与第一 GGSN建立第一 PDP 上下文连接。 首先可信网关的连接建立单元 62根据所述第一 APN信息 寻址相应的第一 GGSN。 如第一 APN具体为 CMNET , 可信网关寻址到 访问 Internet的 GGSN。 然后连接建立单元 62向该第一 GGSN发送第一 PDP激活请求消息, 建立 WiFi终端与第一 GGSN的第一 PDP上下文连 接。 其中第一 PDP激活请求消息中携带有所述 WiFi终端的属性信息, 用 于所述第一 GGSN 与所述可信网关建立第一 PDP 上下文连接。 该第一 GGSN 在接收到连接建立单元 62 发送的第一激活请求消息后, 向所述 WiFi终端分配第一 IP地址, 该第一 IP地址用于所述 WiFi终端访问 PS 业务域。 然后该第一 GGSN向可信网关返回第一 PDP激活响应消息, 所 述第一 PDP激活响应消息中携带有第一 GGSN分配的第一 IP地址。连接 建立单元 62接收所述第一 GGSN返回的第一 PDP激活响应消息后, 可 信网关根据所述第一 PDP激活响应消息中携带的第一 IP地址,建立所述 WiFi终端在无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信 息的对应关系, 即所述无线局域网的会话信息包括: 所述 WiFi终端的第 二 IP地址、 管理所述 WiFi终端的 AC的 NAS-ID等; 所述 WiFi终端的 PS业务域会话信息包括所述第一 IP地址、 建立第一 PDP上下文连接的 所述可信网关与所述第一 GGSN之间绑定的 GTP隧道信息。 所述可信网 关建立的所述 WiFi终端在无线局域网的会话信息与所述 WiFi终端的 PS 业务域会话信息的对应关系, 用于将所述 WiFi终端发起的上行数据业务 流或所述 PS业务域发送给所述 WiFi终端的下行数据业务流根据所述对 应关系分别路由到相应的 PS业务域或 WiFi终端。
进一步的, 在所述 WiFi终端访问 PS业务域时, 所述地址转换单元 73 : 用于将承载所述 WiFi终端发起的上行数据业务流的数据报文中携带 的第二 IP地址转换为所述第一 IP地址; 还用于将承载所述 PS业务域发 送给所述 WiFi终端的下行数据业务流的数据报文中携带的第一 IP地址 转换为所述第二 IP地址, 所述第二 IP地址为接入控制器 AC在对所述 WiFi终端进行认证后向所述 WiFi终端分配的所述无线局域网内的 IP地 址;
所述发送单元 74: 还用于根据所述上行数据业务流的目的地址和所 述第一 IP地址, 通过所述第一 PDP上下文连接或第一 PDN连接, 将所 述承载所述上行数据业务流的数据报文发送给相应的 PS业务域; 还用于 根据所述第二 IP地址将承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
例如, 在第二代或第三代通信网络系统中, 所述 WiFi访问 Internet 业务时, AC接收到所述 WiFi终端发起的访问所述 Internet业务的上行数 据业务流后将所述上行数据业务流转发给所述可信网关, 所述地址转换 单元 73根据可信网关中建立的所述 WiFi终端的无线局域网的会话信息 与所述 WiFi终端的 PS业务域会话信息的对应关系将所述上行数据业务 流中携带的所述第二 IP地址转换为所述第一 IP地址。 然后发送单元 74 根据所述上行数据业务的目的地址和所述第一 IP 地址, 通过所述第一 PDP 上下文连接, 将承载所述上行数据业务流的数据报文发送给相应的 PS业务域。
相应的, 当在所述可信网关接收到所述 PS业务域发送给所述 WiFi 终端的下行数据业务流时, 所述地址转换单元 73根据可信网关中建立的 所述 WiFi终端的无线局域网的会话信息与所述 WiFi终端的 PS业务域会 话信息的对应关系, 将承载所述下行数据业务流的数据报文中携带的所 述第一 IP地址转换为所述第二 IP地址。 所述发送单元根据所述第二 IP 地址和 /或所述用户接入服务器编号将承载所述下行数据业务流的数据报 文发送给所述 WiFi终端。
进一步的, 在所述 WiFi终端访问 PS业务域时, 所述连接建立单元 62 , 根据所述上行数据业务流的目的地址确定所述上行数据业务流对应 的第二接入点名称, 若所述第二接入点名称对应的第二 GGSN与所述第 一 GGSN或所述第二接入点名称对应的第一 P-GW与第二 P-GW不是同 一设备, 建立与所述第二 GGSN的第二 PDP上下文连接或与第二 P-GW 的第二 PDN连接,并获取所述第二 GGSN或第二 P-GW分配给所述 WiFi 终端访问 PS业务域的第三 IP地址。
所述地址转换单元 73 ,还用于在所述可信网关建立第二 PDP上下文 连接或第二 PDN连接后, 将承载所述上行数据业务流的数据报文中携带 的所述第二 IP地址转换为所述第三 IP地址;还用于将承载所述下行数据 业务流的数据报文中携带的所述第三 IP地址转换为所述第二 IP地址。
所述发送单元 74 : 还用于根据所述上行数据业务流的目的地址和所 述第三 IP地址, 通过所述第二 PDP上下文连接或第二 PDN连接, 将所 述承载所述上行数据业务流的数据报文发送给相应的 PS业务域; 根据所 述第二 IP地址将通过所述第二 PDP上下文连接或第二 PDN连接接收到 的 PS业务域发送给所述 WiFi终端的下行数据业务流的数据报文发送给 所述 WiFi终端。 进一步的, 在所述 WiFi终端下线后, 所述接收单元 61 , 还用于接 收所述 AAA服务器发送的计费终止消息。 所述连接删除单元 75 , 用于在 所述接收单元 61接收到所述计费终止消息后删除所述第一 PDP上下文连 接或第一 PDN连接。
具体的, 在所述 WiFi终端访问所述 PS业务域时, 所述 AC监控所 述 WiFi终端访问所述 PS业务域的情况,并周期性上 所述 WiFi终端访 问 PS业务域的流量和时长等信息。 AAA服务器根据所述 AC上报的流量 和时长的等信息, 更新 CDR, 并向所述 AC发送计费响应消息。 当所述 WiFi 终端发起下线请求消息时或所述 WiFi 终端在信号较弱的情况下断 开与所述 AC的通信后, 所述 AC向 AAA发送计费终止消息后, AAA服 务器关闭 CDR文件, 并响应该计费终止消息, 向所述可信网关发送计费 终止消息。 所述接收单元 61在接收到所述计费终止消息后, 连接删除单 元 75删除所述第一 PDP上下文连接或第一 PDN连接。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接或第二 PDN连接, 在所述接收单元 61在接收到所述计费终止消息后, 连接删除 单元 75同时也删除所述第二 PDP上下文连接或第二 PDN连接。 其中,若所述接收单元 61接收的是所述 WiFi终端发送的所述 DHCP 请求消息, 如图 8所示, 所述可信网关 80还包括发送单元 83、 连接删除 单元 84。 在 WiFi终端通过 AC向可信网关发送 DHCP请求消息前, WiFi终 端首先需要附着到 WLAN, 并通过 AC请求 AAA服务器对其进行认证。 在对 WiFi终端认证完成后, 所述 WiFi终端可以通过所述 AC向所述可 信网关 DHCP请求消息。 AC将该 DHCP请求消息发送到可信网关, 并在 该 WiFi终端发送的所述 DHCP请求消息中封装 WiFi终端的标识号, 如 WiFi终端的 MAC ( Media Access Control, 媒体接入控制 ) 地址或 NAI ( Network Access Identifier, 网络访问标识符) , 用于对 WiFi终端进行 标识。
所述发送单元 83 , 用于在所述接收单元 61接收到所述 DHCP请求 消息后, 向所述 AAA服务器发送接入请求消息。
所述可信网关的接收单元 61接收到所述 WiFi终端通过 AC发送的 DHCP请求消息, 该 DHCP请求消息触发所述可信网关与所述 PS业务域 建立第一 PDP上下文连接或第一 PDN连接。这样所述可信网关首先需要 从 AAA服务器获取所述 WiFi终端的属性信息, 具体的发送单元 83 向 AAA服务器发送接入请求消息获取所述 WiFi终端的属性信息。
所述接收单元 61还用于接收 AAA服务器发送的接入响应消息, 所 述接入响应消息中携带有所述 WiFi终端的属性信息。 该 AAA服务器接收到所述可信网关发送的接入请求消息 ,对所述接 入请求消息进行响应, 向所述可信网关发送接入响应消息, 其中接入响 应消息中携带有 WiFi终端的属性信息。
其中所述 WiFi 终端的属性信息包括: WiFi 终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端的 QOS信息和管理所述 WiFi终端的 AC的 NAS-ID。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接或 第一 PDN连接。
所述连接建立单元 62 用于: 与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW 建立第一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址。
所述发送单元 83 , 用于在所述连接建立单元 62建立所述第一 PDP 上下文连接或第一 PDN连接后, 向所述 WiFi终端发送 DHCP响应消息, 所述 DHCP响应消息携带有所述第一 IP地址。
具体的, 在第二代或第三代通信网络中, 所述接收单元 61在接收到 AAA服务器发送的接入响应消息后,连接建立单元 62具体用于向所述第 一接入点名称对应的第一 GGSN发送第一 PDP激活请求消息; 接收所述 第一 GGSN返回的第一 PDP激活响应消息,所述第一 PDP激活响应消息 中携带有所述第一 GGSN分配给所述 WiFi终端访问 PS业务域的第一 IP 地址。 例如, 可信网关根据接所述第一 APN, 确定所述可信网关具体需 要与哪个 GGSN建立连接,然后向与所述第一 APN对应的第一 GGSN发 送第一 PDP激活请求消息。 其中第一 PDP激活请求消息中携带有 WiFi 终端的属性信息,该 WiFi终端的属性信息用于所述第一 GGSN与所述可 信网关建立第一 PDP上下文连接。 该第一 GGSN在接收到可信网关发送 的第一 PDP激活请求消息后, 向所述 WiFi终端分配第一 IP地址, 该第 一 IP地址用于所述 WiFi终端访问 PS业务域。然后该第一 GGSN向可信 网关返回第一 PDP激活响应消息, 所述第一 PDP激活响应消息中携带有 该第一 GGSN分配的第一 IP地址。具体的,根据组网来确定,第一 GGSN 向所述 WiFi终端分配相应的 IP地址。 例如, 若 AC具有路由功能, 该第 一 GGSN向所述 WiFi终端分配的第一 IP地址与管理该 WiFi终端的 AC 为同一网段; 若所述 AC无路由功能, 则第一 GGSN可以不局限于与管 理所述 WiFi终端的 AC同一网段向所述 WiFi终端分配第一 IP地址。 连 接建立单元 62接收所述第一 GGSN返回的第一 PDP激活响应消息, 可 信网关根据所述第一 PDP激活响应消息中携带的第一 IP地址,建立所述 WiFi终端在无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信 息的对应关系, 即所述无线局域网的会话信息包括: 管理所述 WiFi终端 的 AC的 NAS-ID等; 所述 WiFi终端的 PS业务域会话信息包括: 所述第 一 IP地址、建立第一 PDP上下文连接的所述可信网关与所述第一 GGSN 之间绑定的 GTP隧道信息。 所述可信网关建立的所述 WiFi终端的无线 局域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 用于将所述 WiFi终端发起的上行数据业务流或所述 PS业务域发送给所 述 WiFi终端的下行数据业务流根据所述对应关系分别路由到相应的 PS 业务域或 WiFi终端。
进一步的, 在所述连接建立单元 62建立所述第一 PDP上下文连接 或第一 PDN连接后, 所述发送单元 83 , 还用于向所述 AAA服务器发送 计费请求消息, 指示所述 AAA服务器对所述 WiFi终端进行计费。
进一步的, 所述可信网关与所述 PS业务域建立第一 PDP上下文连 接或第一 PDN连接后, 在所述 WiFi终端访问 PS业务域时, 所述发送单 元 83 :还用于根据承载所述 WiFi终端发起的上行数据业务流的数据报文 中携带的所述上行数据业务流的目的地址和所述第一 IP地址, 通过所述 第一 PDP上下文连接或第一 PDN连接,将承载所述上行数据业务流的数 据报文发送给相应的 PS业务域; 还用于根据所述第一 IP地址将承载所 述 PS业务域发送给所述 WiFi终端的下行数据业务流的数据报文发送给 所述 WiFi终端。 例如, 在第二代或第三代通信网络系统中, 所述 WiFi访问 Internet 业务时, AC接收到所述 WiFi终端发送的承载访问所述 Internet业务的上 行数据业务流的数据报文后将所述数据报文转发给所述可信网关, 所述 数据报文中携带有所述上行数据业务流的目的地址、 所述第一 IP地址和 所述管理所述 WiFi终端的 AC的 NAS-ID等信息。 所述可信网关接收到 所述承载所述上行数据业务流的数据报文后, 所述发送单元 83根据可信 网关中建立的所述 WiFi终端的无线局域网的会话信息与所述 WiFi终端 的 PS 业务域会话信息的对应关系将所述数据报文路由发送给所述第一 GGSN, 从而使得所述 WiFi终端接入到相应的 PS业务域。
相应的, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的下行数据业务流时, 根据可信网关中建立的所述 WiFi终端的无线局 域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 若 所述 AC具有路由功能,则所述发送单元 83根据所述第一 IP地址将承载 所述下行数据业务流的数据报文发送给所述 WiFi终端, 所述第一 IP地 址与管理所述 WiFi终端的 AC的 IP地址为同一网段。若所述 AC没有路 由功能, 则所述发送单元 83根据所述第一 IP地址和所述 WiFi终端属性 信息中的 NAS-ID 将承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述 WiFi终端访问 PS业务域时, 所述连接建立单元 62 , 还用于根据所述上行数据业务流的目的地址确定所述上行数据业务 流对应的第二接入点名称, 若所述第二接入点名称对应的第二 GGSN与 所述第一 GGSN 或所述第二接入点名称对应的第二 P-GW 与所述第一 P-GW不是同一设备, 建立与所述第二 GGSN的第二 PDP上下文连接或 与第二 P-GW的第二 PDN连接,并获取所述第二 GGSN或第二 P-GW分 配给所述 WiFi终端访问 PS业务域的第三 IP地址。
所述发送单元 83 , 还用于根据所述上行数据业务流的目的地址和所 述第三 IP地址, 通过所述第二 PDP上下文连接, 将承载所述上行数据业 务流的数据报文发送给相应的 PS业务域; 还用于根据所述第三 IP地址 将承载通过所述第二 PDP上下文连接或第二 PDN连接接收到的 PS业务 域发送给所述 WiFi 终端的下行数据业务流的数据报文发送给所述 WiFi 终端。
进一步的, 在所述 WiFi终端下线后, 所述接收单元 61 , 还用接收 所述 AAA服务器发送的计费终止消息。 所述连接删除单元 84 , 用于在所 述接收单元 61接收到所述计费终止消息后删除所述第一 PDP上下文连接 或第一 PDN连接。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接或第二 PDN连接, 在所述接收单元 61在接收到所述计费终止消息后, 连接删除 单元 84同时也删除所述第二 PDP上下文连接或第二 PDN连接。
具体的, 在所述 WiFi终端访问所述 PS业务域时, 所述 AC用于监 控所述 WiFi 终端访问所述 PS 业务域的情况, 并周期性上 所述 WiFi 终端访问 PS业务域的流量和时长等信息。 AAA服务器根据所述 AC上报 的流量和时长的等信息, 更新 CDR, 并向所述 AC发送计费响应消息。 在所述 WiFi终端发起下线请求消息时或所述 WiFi终端在信号较弱的情 况下断开与所述 AC的通信后, 所述 AC向 AAA发送计费终止消息后, AAA服务器关闭 CDR文件, 并相应该计费终止消息, 向所述可信网关 发送计费终止消息。 所述可信网关的接收单元 61在接收到所述计费终止 消息后, 连接删除单元 84删除所述第一 PDP上下文连接或第一 PDN连 接。
其中, 所述接收单元 61接收的是所述 WiFi终端发送的 DHCP请求 消息时, 如图 8所示, 所述发送单元 83 , 用于向所述 AAA服务器发送认 证请求消息, 请求所述 AAA服务器对所述 WiFi终端进行认证。 所述接收单元 61 , 还用于接收所述 AAA服务器发送的接入响应消 息, 所述接入响应消息中携带有所述 WiFi终端的属性信息。
该 AAA服务器接收到所述发送单元 83发送的接入请求消息, 对所 述接入请求消息进行响应, 向所述可信网关发送接入响应消息, 其中接 入响应消息中携带有 WiFi终端的属性信息。
其中所述 WiFi 终端的属性信息包括: WiFi 终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端的 QOS信息和管理所述 WiFi终端的 AC的 NAS-ID。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接或 第一 PDN连接。
在获取到 WiFi终端的属性信息后, 所述接收单元 61 通过所述 AC 接收 WiFi终端发送的 DHCP请求消息。所述 AC将该 DHCP请求消息发 送到可信网关, 所述 DHCP请求消息中封装 WiFi终端的标识号, 如终端 的 MAC地址或 NAI。可信网关接收到该 DHCP请求消息后,被触发建立 第一 PDP上下文连接或第一 PDN连接。
所述连接建立单元 62 用于: 与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW 建立第一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址。
所述发送单元 83 ,还用于在所述连接建立单元建立第一 PDP上下文 连接或第一 PDN 连接后向所述 WiFi 终端发送 DHCP 响应消息, 所述 DHCP响应消息携带有所述第一 IP地址。
具体的, 在第二代或第三代通信网络中, 连接建立单元 62具体用于 向所述第一接入点名称对应的第一 GGSN发送第一 PDP激活请求消息; 接收所述第一 GGSN返回的第一 PDP激活响应消息,所述第一 PDP激活 响应消息中携带有所述第一 GGSN分配给所述 WiFi终端访问 PS业务域 的第一 IP地址。 例如, 连接建立单元 62根据所述第一 APN, 确定可信 网关具体需要与哪个 GGSN建立连接, 然后向与所述第一 APN对应的第 一 GGSN发送第一 PDP激活请求消息,其中第一 PDP激活请求消息中携 带有 WiFi终端的属性信息,该 WiFi终端的属性信息用于所述第一 GGSN 与所述可信网关建立第一 PDP上下文连接。 该第一 GGSN在接收到可信 网关发送的激活请求消息后, 向所述 WiFi终端分配第一 IP地址, 该第 一 IP地址用于所述 WiFi终端访问 PS业务域。然后该第一 GGSN向可信 网关返回第一 PDP激活响应消息, 所述 PDP激活响应消息中携带有该第 一 GGSN分配给可信网关的第一 IP地址。 具体的, 根据组网来确定, 第 一 GGSN向所述 WiFi终端分配相应的 IP地址。 例如, 若 AC具有路由 功能, 该第一 GGSN向所述 WiFi终端分配的第一 IP地址与管理该 WiFi 终端的 AC为同一网段; 若所述 AC无路由功能, 则 GGSN可不局限于 与管理所述 WiFi终端的 AC同一网段向所述 WiFi终端分配第一 IP地址。 连接建立单元 62接收所述第一 GGSN返回的第一 PDP激活响应消息, 可信网关根据所述第一 PDP激活响应消息中携带的第一 IP地址,建立所 述 WiFi终端在无线局域网的会话信息与所述 WiFi终端的 PS业务域会话 信息的对应关系, 即所述无线局域网的会话信息包括: 管理所述 WiFi终 端的 AC的 NAS-ID等; 所述 WiFi终端的 PS业务域会话信息包括: 所述 第一 IP 地址、 建立第一 PDP 上下文连接的所述可信网关与所述第一 GGSN之间绑定的 GTP隧道信息。所述可信网关建立的所述 WiFi终端在 无线局域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关 系, 用于将所述 WiFi终端发起的上行数据业务流或所述 PS业务域发送 给所述 WiFi终端的下行数据业务流根据所述对应关系分别路由到相应的 PS业务域或 WiFi终端。
进一步的, 在所述连接建立单元 62建立所述第一 PDP上下文连接 或第一 PDN连接后, 所述发送单元 83 , 还用于向所述 AAA服务器发送 计费请求消息, 指示所述 AAA服务器对所述 WiFi终端进行计费。 具体的, 在所述 WiFi终端访问所述 PS业务域时, 所述可信网关监 控所述 WiFi终端访问所述 PS业务域的情况,并周期性的向所述 AAA服 务器上报所述 WiFi终端访问所述 PS业务域的流量和时长等信息。 AAA 服务器根据所述可信网关上报的流量和时长等信息对所述 WiFi终端进行 计费, 更新 CDR, 并向所述可信网关发送计费响应消息。
进一步的, 在所述 WiFi终端访问 PS业务域时, 所述发送单元 83 : 根据承载所述 WiFi终端发起的上行数据业务流的数据报文中携带的所述 上行数据业务流的目的地址和所述第一 IP地址,通过所述第一 PDP上下 文连接或第一 PDN连接, 将承载所述上行数据业务流的数据报文发送给 相应的 PS业务域; 还用于根据所述第一 IP地址将承载所述 PS业务域发 送给所述 WiFi终端的下行数据业务流的数据报文发送给所述 WiFi终端。
例如, 在第二代或第三代通信网络系统中, 所述 WiFi 终端访问 Internet业务时, AC接收到所述 WiFi终端发送的承载访问所述 Internet 业务的上行数据业务流的数据报文后将所述数据报文转发给所述可信网 关, 所述数据报文中携带有所述上行数据业务流的目的地址、 所述第一 IP地址和所述管理所述 WiFi终端的 AC的 NAS-ID等信息。 所述可信网 关接收到所述承载所述上行数据业务流的数据报文后, 该可信网关的发 送单元 83根据可信网关中建立的所述 WiFi终端的无线局域网的会话信 息与所述 WiFi终端的 PS业务域会话信息的对应关系将所述数据报文路 由发送给所述第一 GGSN, 从而使得所述 WiFi终端接入到相应的 PS业 务域。
相应的, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的下行数据业务流时, 根据可信网关中建立的所述 WiFi终端的无线局 域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 若 所述 AC具有路由功能,则所述发送单元 83根据所述第一 IP地址将承载 所述下行数据业务流的数据报文发送给所述 WiFi终端, 所述第一 IP地 址与管理所述 WiFi终端的 AC的 IP地址为同一网段。若所述 AC没有路 由功能, 则所述发送单元 83根据所述第一 IP地址和所述 WiFi终端属性 信息中的 NAS-ID 将承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述 WiFi终端访问 PS业务域时, 所述连接建立单元 62 , 还用于根据所述上行数据业务流的目的地址确定所述上行数据业务 流对应的第二接入点名称, 若所述第二接入点名称对应的第二 GGSN与 所述第一 GGSN 或所述第二接入点名称对应的第二 P-GW 与所述第一 P-GW不是同一设备, 建立与所述第二 GGSN的第二 PDP上下文连接或 与第二 P-GW的第二 PDN连接,并获取所述第二 GGSN或第二 P-GW分 配给所述 WiFi终端访问 PS业务域的第三 IP地址。
所述发送单元 83 , 还用于根据所述上行数据业务流的目的地址和所 述第三 IP地址, 通过所述第二 PDP上下文连接或第二 PDN连接, 将承 载所述上行数据业务流的数据报文发送给相应的 PS业务域; 还用于根据 所述第三 IP地址将承载通过所述第二 PDP上下文连接或第二 PDN连接 接收到的 PS业务域发送给所述 WiFi终端的下行数据业务流的数据报文 发送给所述 WiFi终端。
进一步的, 所述发送单元 83 , 还用于当所述 WiFi终端下线时, 向 所述 AAA服务器发送计费终止消息。
所述连接删除单元 84 , 用于在所述发送单元向所述 AAA服务器发 送所述计费终止消息后,删除所述第一 PDP上下文连接或第一 PDN连接。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接或第二 PDN连接, 在所述发送单元 83向所述 AAA发送计费终止消息后, 所述 连接删除单元 84同时也删除所述第二 PDP上下文连接或第二 PDN连接。
具体的, 在所述 WiFi终端发起下线请求消息时或所述 WiFi终端在 信号较弱的情况下断开与所述可信网关的通信后, 所述发送单元 83向所 述 AAA发送计费终止消息后, 所述 AAA服务器关闭 CDR文件, 并响应 该计费终止消息。 同时, 连接删除单元 84删除所述第一 PDP上下文连接 或第一 PDN连接。 其中, 所述接收单元 61接收的是所述 WiFi终端发送的 DHCP请求 消息时,该 DHCP请求消息用于触发所述可信网关与所述 PS业务域建立 第一 PDP上下文连接或第一 PDN连接。 如图 9所示, 所述可信网关 90 还包括: 发送单元 93、 获取单元 94和连接删除单元 95。 所述发送单元 93 : 用于将接入控制器 AC请求所述 AAA服务器对 所述 WiFi终端进行认证的认证请求消息转发给所述 AAA服务器; 还用 于将所述 AAA服务器对所述 WiFi终端进行认证的认证响应消息转发给 所述 AC, 所述认证响应消息中携带有所述 WiFi终端的属性信息。 本实施中所述可信网关作为所述 AC和所述 AAA服务器的中继。首 先 WiFi终端附着到 WLAN , 接入到无线局域网的无线接入点, 所述 AC 向所述 AAA服务器发送认证请求消息。 所述可信网关作为中继, 所述可 信网关的发送单元 93 将所述 AC发送的认证请求消息转发给所述 AAA 服务器。
AAA服务器对所述 WiFi终端进行认证成功后, 向所述 AC发送认 证响应消息。 所述可信网关的接收单元 61接收到所述 AAA服务器发送 的认证响应消息后, 发送单元 93将所述认证响应消息转发给所述 AC。 所述认证响应消息中携带有所述 WiFi终端的属性信息。 所述获取单元 94 , 用于从所述认证响应消息中获取所述 WiFi终端 的属性信息。
所述可信网关的接收单元 61在接收到所述 AAA服务器发送的认证 响应消息后, 可信网关的获取单元 94解析 AAA服务器发送的认证响应 消息, 从所述认证响应消息中获取所述 WiFi终端的属性信息。 其中所述 WiFi终端的属性信息包括: WiFi终端的第二 IP地址、 IMSI、 第一 APN、 WiFi终端 QOS , NAS-ID。
所述 WiFi 终端的属性信息中的第一 APN、 或 QoS属性信息可以是 可信网关从 AAA服务器中获取, AAA服务器存储了 WiFi终端与运营商 签约时约定的签约信息。 若 WiFi终端与运营商签约时没有约定 APN和 QoS 信息时, 可信网关中也可以釆用预设 APN、 QoS 的缺省值为所述 WiFi终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接或 第一 PDN连接。
所述连接建立单元 62 用于: 与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW 建立第一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址。
所述发送单元 83 ,还用于在所述连接建立单元建立第一 PDP上下文 连接或第一 PDN 连接后向所述 WiFi 终端发送 DHCP 响应消息, 所述 DHCP响应消息携带有所述第一 IP地址。
具体的, 在第二代或第三代通信网络中, 连接建立单元 62具体用于 向所述第一接入点名称对应的第一 GGSN发送第一 PDP激活请求消息; 接收所述第一 GGSN返回的第一 PDP激活响应消息,所述第一 PDP激活 响应消息中携带有所述第一 GGSN分配给所述 WiFi终端访问 PS业务域 的第一 IP地址; 向所述 WiFi终端发送 DHCP响应消息, 所述 DHCP响 应消息携带有所述第一 IP地址。 例如, 连接建立单元 62根据所述第一 APN, 确定可信网关具体需要与哪个 GGSN建立连接, 然后向与所述第 一 APN对应的第一 GGSN发送第一 PDP激活请求消息, 其中第一 PDP 激活请求消息中携带有 WiFi终端的属性信息, 该 WiFi终端的属性信息 用于所述第一 GGSN与所述可信网关建立第一 PDP上下文连接。 该第一 GGSN在接收到可信网关发送的激活请求消息后, 向所述 WiFi终端分配 第一 IP地址, 该第一 IP地址用于所述 WiFi终端访问 PS业务域。 然后 该第一 GGSN向可信网关返回第一 PDP激活响应消息,所述 PDP激活响 应消息中携带有该第一 GGSN分配给可信网关的第一 IP地址。 具体的, 居组网来确定, 第一 GGSN向所述 WiFi终端分配相应的 IP地址。 例 如, 若 AC具有路由功能, 该第一 GGSN向所述 WiFi终端分配的第一 IP 地址与管理该 WiFi终端的 AC为同一网段; 若所述 AC无路由功能, 则 GGSN可不局限于与管理所述 WiFi终端的 AC同一网段向所述 WiFi终 端分配第一 IP地址。 连接建立单元 62接收所述第一 GGSN返回的第一 PDP激活响应消息, 可信网关根据所述第一 PDP激活响应消息中携带的 第一 IP地址, 建立所述 WiFi终端在无线局域网的会话信息与所述 WiFi 终端的 PS业务域会话信息的对应关系, 即所述无线局域网的会话信息包 括: 管理所述 WiFi终端的 AC的 NAS-ID等; 所述 WiFi终端的 PS业务 域会话信息包括: 所述第一 IP地址、 建立第一 PDP上下文连接的所述可 信网关与所述第一 GGSN之间绑定的 GTP隧道信息。 所述可信网关建立 的所述 WiFi终端在无线局域网的会话信息与所述 WiFi终端的 PS业务域 会话信息的对应关系, 用于将所述 WiFi终端发起的上行数据业务流或所 述 PS业务域发送给所述 WiFi终端的下行数据业务流根据所述对应关系 分别路由到相应的 PS业务域或 WiFi终端。
进一步的, 所述可信网关与所述 PS业务域建立第一 PDP上下文连 接或第一 PDN连接后, 在所述 WiFi终端访问 PS业务域时, 所述发送单 元 93 :根据承载所述 WiFi终端发起的上行数据业务流的数据报文中携带 的所述上行数据业务流的目的地址和所述第一 IP 地址, 通过所述第一 PDP上下文连接或第一 PDN连接, 将承载所述上行数据业务流的数据报 文发送给相应的 PS业务域; 还用于根据所述第一 IP地址将承载所述 PS 业务域发送给所述 WiFi 终端的下行数据业务流的数据报文发送给所述 WiFi终端。
例如, 在第二代或第三代通信网络系统中, 所述 WiFi访问 Internet 业务时, AC接收到所述 WiFi终端发送的承载访问所述 Internet业务的上 行数据业务流的数据报文后将所述数据报文转发给所述可信网关, 所述 数据报文中携带有所述上行数据业务流的目的地址、 所述第一 IP地址和 所述管理所述 WiFi终端的 AC的 NAS-ID等信息。 所述可信网关接收到 所述承载所述上行数据业务流的数据报文后, 所述发送单元 93根据可信 网关中建立的所述 WiFi终端的无线局域网的会话信息与所述 WiFi终端 的 PS 业务域会话信息的对应关系将所述数据报文路由发送给所述第一 GGSN, 从而使得所述 WiFi终端接入到相应的 PS业务域。
相应的, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的下行数据业务流时, 根据可信网关中建立的所述 WiFi终端的无线局 域网的会话信息与所述 WiFi终端的 PS业务域会话信息的对应关系, 若 所述 AC具有路由功能,则所述发送单元 93根据所述第一 IP地址将承载 所述下行数据业务流的数据报文发送给所述 WiFi终端, 所述第一 IP地 址与管理所述 WiFi终端的 AC的 IP地址为同一网段。若所述 AC没有路 由功能, 则所述发送单元 93根据所述第一 IP地址和所述 WiFi终端属性 信息中的 NAS-ID 将承载所述下行数据业务流的数据报文发送给所述 WiFi终端。
进一步的, 在所述 WiFi终端访问 PS业务域时, 所述连接建立单元 62 , 还用于根据所述上行数据业务流的目的地址确定所述上行数据业务 流对应的第二接入点名称, 若所述第二接入点名称对应的第二 GGSN与 所述第一 GGSN 或所述第二接入点名称对应的第二 P-GW 与所述第一 P-GW不是同一设备, 建立与所述第二 GGSN的第二 PDP上下文连接或 与第二 P-GW的第二 PDN连接,并获取所述第二 GGSN或第二 P-GW分 配给所述 WiFi终端访问 PS业务域的第三 IP地址。
所述发送单元 93 , 还用于根据所述上行数据业务流的目的地址和所 述第三 IP地址, 通过所述第二 PDP上下文连接或第二 PDN连接, 将承 载所述上行数据业务流的数据报文发送给相应的 PS业务域; 还用于根据 所述第三 IP地址将承载通过所述第二 PDP上下文连接或第二 PDN连接 接收到的 PS业务域发送给所述 WiFi终端的下行数据业务流的数据报文 发送给所述 WiFi终端。
进一步的, 在所述连接建立单元 62建立所述第一 PDP上下文连接 或第一 PDN连接后, 所述发送单元 93 , 还用于向所述 AAA服务器发送 计费请求消息, 指示所述 AAA服务器对所述 WiFi终端进行计费。
具体的, 在所述 WiFi终端访问所述 PS业务域时, 所述 AC监控所 述 WiFi终端访问所述 PS业务域的情况,并周期性向所述 AAA服务器上 报所述 WiFi终端访问 PS业务域的流量和时长等信息。 所述发送单元 93 将所述 AC上报的所述流量和时长等信息转发给所述 AAA服务器。 AAA 服务器根据所述 AC上报的流量和时长的等信息, 更新 CDR, 并向所述 AC发送计费响应消息。
进一步的, 在所述 WiFi终端下线时, 所述发送单元 93还用于将所 述 AC发送的计费终止消息转发给所述 AAA服务器。
所述连接删除单元 95 , 用于根据所述发送单元 93 转发的所述计费 终止消息删除所述可信网关第一 PDP上下文连接或第一 PDN连接。
进一步的, 若所述可信网关建立了所述第二 PDP上下文连接或第二 PDN连接, 在所述连接删除单元 95根据所述发送单元 93转发的所述计 费终止消息同时也删除所述第二 PDP上下文连接或第二 PDN连接。
具体的, 在所述 WiFi终端发起下线请求消息时或所述 WiFi终端在 信号较弱的情况下断开与所述 AC的通信后, 所述 AC向 AAA发送计费 终止消息, 所述发送单元 93将所述 AC发送的计费终止消息转发给所述 AAA服务器。 同时, 所述连接删除单元 95根据所述计费终止消息删除所 述可信网关第一 PDP上下文连接或第一 PDN连接。 所述 AAA服务器接 收到所述可信网关转发的所述计费终止消息后, 响应所述计费终止消息, 关闭 CDR文件。 本发明实施例提供的 WiFi终端接入 PS业务域的可信网关, 通过接 收单元接收到的计费请求消息或 DHCP请求消息, 触发所述可信网关建 立第一 PDP上下文连接或第一 PDN, 使得所述可信网关作为接入 PS业 务域的接入点, 所述 WiFi终端能够通过无线局域网、 可信网关以及建立 的 PDP上下文连接或 PDN连接访问 PS业务域, 这样无需在终端以及可 信网关之间建立一条专门的隧道,所述 WiFi终端也不需要进行两次认证, 减轻了 WiFi终端的负荷, 降低 WiFi终端操作的复杂度和成本。
进一步的, 本发明实施例中涉及到的可信网关具体可以单独部署, 也可以部署在已有的网元上, 如 GGSN、 PDG或 P-GW上。 本领域普通技术人员可以理解: 实现上述方法实施例的全部或部分 步骤可以通过程序指令相关的硬件来完成, 前述的程序可以存储于一计 算机可读取存储介质中, 该程序在执行时, 执行包括上述方法实施例的 步骤; 而前述的存储介质包括: ROM、 RAM, 磁碟或者光盘等各种可 以存储程序代码的介质。
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局 限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可 轻易想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明 的保护范围应以所述权利要求的保护范围为准。

Claims

权 利 要 求 书
1、 一种 WiFi终端接入分组数据 PS业务域的方法, 其特征在于, 应 用于可信网关, 所述可信网关与无线局域网以及 PS业务域中的通信设备 通信, 所述方法包括:
接收验证、授权和记账 AAA服务器发送的计费请求消息或所述 WiFi 终端发送的动态主机设置协议 DHCP请求消息;
在接收到所述计费请求消息或所述 DHCP 请求消息后, 根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS 业务域建立第一包数据 协议 PDP上下文连接或第一分组数据网络 PDN连接, 使得所述 WiFi终 端通过所述无线局域网, 所述可信网关以及建立的第一 PDP上下文连接 或第一 PDN连接接入所述 PS业务域; 其中, 所述 WiFi终端的属性信息 从所述 AAA服务器中获得,用于可信网关为所述 WiFi终端接入 PS业务 域建立与 PS业务域之间的第一 PDP上下文连接或第一 PDN连接。
2、根据权利要求 1所述的方法, 其特征在于, 所述接收的所述 AAA 服务器发送的计费请求消息中携带有所述 WiFi终端的属性信息, 所述属 性信息包括第一接入点名称;
根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS业务域建 立第一 PDP上下文连接或第一 PDN连接包括:
与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接 或与所述第一接入点名称对应的分组数据网络网关 P-GW建立第一 PDN 连接,并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址;
在所述可信网关与所述 PS业务域建立第一 PDP上下文连接或第一 PDN连接后, 还包括:
通过所述 AAA服务器向接入控制器 AC发送计费请求响应消息, 所 述计费请求响应消息中携带有所述第一 IP地址。
3、 根据权利要求 2所述的方法, 其特征在于, 在所述接收 AAA服 务器发送的计费请求消息前, 还包括: 所述 AC对所述 WiFi终端进行认 证, 并向所述 WiFi终端分配所述无线局域网内的第二 IP地址;
在所述可信网关建立所述第一 PDP上下文连接或第一 PDN连接后, 在所述可信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行 数据业务流时, 还包括: 所述可信网关将承载所述上行数据业务流的数据报文中携带的所述 第二 IP地址转换为所述第一 IP地址;
所述可信网关根据所述上行数据业务流的目的地址和所述第一 IP地 址, 通过所述第一 PDP上下文连接或第一 PDN连接, 将承载所述上行数 据业务流的数据报文发送给相应的 PS业务域;
在所述可信网关与所述 PS业务域建立第一 PDP上下文连接或第一 PDN连接后, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终 端的下行数据业务流时, 还包括:
所述可信网关将承载所述下行数据业务流的数据报文中携带的所述 第一 IP地址转换为所述第二 IP地址;
所述可信网关根据所述第二 IP地址将承载所述下行数据业务流的数 据才艮文发送给所述 WiFi终端。
4、 根据权利要求 2所述的方法, 其特征在于, 在所述接收 AAA服 务器发送的计费请求消息前, 还包括: 所述 AC对所述 WiFi终端进行认 证, 并向所述 WiFi终端分配无线局域网内的第二 IP地址;
在所述可信网关与所述 PS业务域建立第一 PDP上下文连接或第一 PDN连接后, 在所述可信网关接收到所述 WiFi终端发起的访问所述 PS 业务域的上行数据业务流时, 还包括:
根据所述上行数据业务流的目的地址确定所述上行数据业务流的第 二接入点名称, 若所述第二接入点名称对应的第二 GGSN 与所述第一 GGSN或所述第二接入点名称对应的第一 P-GW与第二 P-GW不是同一 设备, 所述可信网关建立与所述第二 GGSN的第二 PDP上下文连接或与 第二 P-GW的第二 PDN连接,并获取所述第二 GGSN或第二 P-GW分配 给所述 WiFi终端访问 PS业务域的第三 IP地址;
所述可信网关将承载所述上行数据业务流的数据报文中携带的所述 第二 IP地址转换为所述第三 IP地址;
所述可信网关根据所述上行数据业务流的目的地址和所述第三 IP地 址, 通过所述第二 PDP上下文连接或第二 PDN连接, 将承载所述上行数 据业务流的数据报文发送给相应的 PS业务域;
在所述可信网关建立第二 PDP上下文连接或第二 PDN连接后, 在 所述可信网关通过所述第二 PDP上下文连接或第二 PDN连接接收到 PS 业务域发送给所述 WiFi终端的下 行数据业务流时, 还包括: 所述可信网关将承载所述下行数据业务流的数据报文中携带的所述 第三 IP地址转换为所述第二 IP地址;
所述可信网关根据所述第二 IP地址将承载所述下行数据业务流的数 据才艮文发送给所述 WiFi终端。
5、 根据权利要求 1所述的方法, 其特征在于, 在所述接收所述 WiFi 终端发送的 DHCP请求消息后, 还包括:
向所述 AAA服务器发送接入请求消息;
接收所述 AAA服务器发送的接入响应消息,所述接入响应消息中携 带有所述 WiF i终端的属性信息, 所述属性信息包括第一接入点名称; 所述根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS业务 域建立第一 PDP上下文连接或第一 PDN连接包括:
与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接 或与所述第一接入点名称对应的 P-GW建立第一 PDN连接, 并获得所述 第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址;
在所述可信网关与所述 PS业务域建立第一 PDP上下文连接或第一 PDN连接后, 还包括:
向所述 WiFi终端发送 DHCP响应消息, 所述 DHCP响应消息携带 有所述第一 IP地址。
6、 根据权利要求 1-5任一项所述的方法, 其特征在于, 在所述可信 网关建立所述第一 PDP上下文连接或第一 PDN连接后, 还包括:
在所述 WiFi终端下线后, 所述可信网关接收所述 AAA服务器发送 的计费终止消息;
所述可信网关删除所述第一 PDP上下文连接或第一 PDN连接。
7、根据权利要求 1所述的方法, 其特征在于, 在所述接收所述 WiFi 终端发送的 DHCP请求消息前, 还包括:
向所述 AAA服务器发送认证请求消息, 请求所述 AAA服务器对所 述 WiFi终端进行认证;
在所述 WiFi终端完成认证后, 所述可信网关向所述 AAA服务器发 送接入请求消息;
接收所述 AAA服务器发送的接入响应消息,所述接入响应消息中携 带有所述 WiF i终端的属性信息, 所述属性信息包括第一接入点名称; 根据所述 WiFi终端的属性信 息,所述可信网关与所述 PS业务域建 立第一 PDP上下文连接或第一 PDN连接包括:
与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接 或与所述第一接入点名称对应的 P-GW建立第一 PDN连接, 并获得所述 第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址;
在所述可信网关与所述 PS业务域建立第一 PDP上下文连接或第一 PDN连接后, 还包括:
向所述 WiFi终端发送 DHCP响应消息, 所述 DHCP响应消息携带 有所述第一 IP地址。
8、 根据权利要求 7所述的方法, 其特征在于, 在所述可信网关建立 所述第一 PDP上下文连接或第一 PDN连接后, 还包括:
当所述 WiFi终端下线时, 所述可信网关向所述 AAA服务器发送计 费终止消息;
删除所述第一 PDP上下文连接或第一 PDN连接。
9、 根据权利要求 1所述的方法, 其特征在于, 在所述可信网关接收 所述 WiFi终端发送的 DHCP请求消息前, 还包括:
将接入控制器 AC请求所述 AAA服务器对所述 WiFi终端进行认证 的认证请求消息转发给所述 AAA服务器;
将所述 AAA服务器对所述 WiFi终端进行认证的认证响应消息转发 给所述 AC , 所述认证响应消息中携带有所述 WiFi终端的属性信息; 从所述认证响应消息中获取所述 WiFi终端的属性信息,所述属性信 息包括第一接入点名称;
根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS业务域建 立第一 PDP上下文连接或第一 PDN连接包括:
与所述第一接入点名称对应的第一 GGSN建立第一 PDP上下文连接 或与所述第一接入点名称对应的 P-GW建立第一 PDN连接, 并获得所述 第一 GGSN或第一 P-GW分配给所述 WiFi终端的第一 IP地址;
在所述可信网关与所述 PS业务域建立第一 PDP上下文连接或第一 PDN连接后, 还包括:
向所述 WiFi终端发送 DHCP响应消息, 所述 DHCP响应消息携带 有所述第一 IP地址。
10、 根据权利要求 9所述的方法, 其特征在于, 在所述可信网关建 立所述第一 PDP上下文连接或第 一 PDN连接后, 还包括: 在所述 WiFi终端下线时, 所述可信网关将所述 AC发送的计费终止 消息转发给所述 AAA服务器;
根据所述计费终止消息后删除所述第一 PDP上下文连接或第一 PDN 连接。
11、 根据权利要求 5、 7-10 任一项所述的方法, 其特征在于, 在所 述可信网关建立所述第一 PDP上下文连接或第一 PDN连接后,在所述可 信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据业务 流时, 还包括:
根据所述上行数据业务流的目的地址和所述第一 IP地址, 通过所述 第一 PDP上下文连接或第一 PDN连接,将承载所述上行数据业务流的数 据报文发送给相应的 PS业务域;
在所述可信网关建立所述第一 PDP上下文连接或第一 PDN连接后, 在所述可信网关接收到所述 PS业务域发送给所述 WiFi终端的下行数据 业务流时, 还包括:
根据所述第一 IP地址将承载所述下行数据业务流的数据报文发送给 所述 WiFi终端。
12、 根据权利要求 5、 7-10 任一项所述的方法, 其特征在于, 在所 述可信网关建立所述第一 PDP上下文连接或第一 PDN连接后,在所述可 信网关接收到所述 WiFi终端发起的访问所述 PS业务域的上行数据业务 流时, 还包括:
根据所述上行数据业务流的目的地址确定所述上行数据业务流的类 型确定的第二接入点名称, 若所述第二接入点名称对应的第二 GGSN与 所述第一 GGSN 或所述第二接入点名称对应的第二 P-GW 与所述第一 P-GW不是同一设备, 建立与所述第二 GGSN的第二 PDP上下文连接或 与第二 P-GW的第二 PDN连接, 并获取所述第二 GGSN或第二 P-GW分 配给所述 WiFi终端访问 PS业务域的第三 IP地址;
根据所述上行数据业务流的目的地址和所述第三 IP地址, 通过所述 第二 PDP上下文连接或第二 PDN连接,将所述承载所述上行数据业务流 的数据报文发送给相应的 PS业务域;
在所述可信网关建立第二 PDP上下文连接或第二 PDN连接后, 在 所述可信网关通过所述第二 PDP上下文连接或第二 PDN连接接收到 PS 业务域发送给所述 WiFi终端的下 行数据业务流时, 还包括: 根据所述第二 IP地址将承载所述下行数据业务流的数据报文发送给 所述 WiFi终端。
13、 根据权利要求 5、 7-10 任一项所述的方法, 其特征在于, 在所 述根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS业务域建立 第一 PDP上下文连接或第一 PDN连接后, 还包括:
向所述 AAA服务器发送计费请求消息, 指示所述 AAA服务器对所 述 WiFi终端进行计费。
14、 根据权利要求 1所述的方法, 其特征在于, 所述 WiFi终端通过 应用程序在访问所述 PS业务域时, 所述 WiFi终端上的应用程序向所述 WiFi 终端下发缺省的接入点名称类型或所述 WiFi 终端上的应用程序不 向所述 WiFi终端下发接入点名称, 所述 WiFi终端根据缺省的接入点名 称类型优先通过所述无线局域网接入所述 PS业务域。
15、 一种 WiFi终端接入分组数据 PS业务域的可信网关, 其特征在 于, 所述可信网关与无线局域网以及 PS业务域中的通信设备通信, 所述 可信网关包括:
接收单元, 用于接收验证、 授权和记账 AAA服务器发送的计费请求 消息或所述 WiFi终端发送的动态主机设置协议 DHCP请求消息;
连接建立单元, 用于在接收到所述计费请求消息或所述 DHCP请求 消息后, 根据所述 WiFi终端的属性信息, 所述可信网关与所述 PS业务 域建立第一包数据协议 PDP上下文连接或第一分组数据网络 PDN连接, 使得所述 WiFi终端通过所述无线局域网, 所述可信网关以及建立的第一 PDP上下文连接或第一 PDN连接接入所述 PS业务域; 其中, 所述 WiFi 终端的属性信息从所述 AAA服务器中获得, 用于可信网关为所述 WiFi 终端接入 PS业务域建立与 PS业务域之间的第一 PDP上下文连接或第一 PDN连接。
16、 根据权利要求 15所述的网关, 其特征在于, 还包括: 发送单元; 所述接收单元接收的所述 AAA服务器发送的计费请求消息中携带有所述 WiFi终端的属性信息, 所述属性信息包括第一接入点名称;
所述连接建立单元用于: 与所述第一接入点名称对应的第一 GGSN 建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW建立第 一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终 端的第一 IP地址; 所述发送单元, 用于在所述连接建立单元建立所述第一 PDP上下文 连接或第一 PDN连接后, 通过所述 AAA服务器向接入控制器 AC发送 计费请求响应消息, 所述计费请求响应消息中携带有所述第一 IP地址, 使得所述 WiFi终端可以通过无线局域网访问所述 PS业务域。
17、 根据权利要求 16所述的网关, 其特征在于, 所述网关还包括: 地址转换单元;
所述地址转换单元用于: 将承载所述 WiFi终端发起的上行数据业务 流的数据报文中携带的第二 IP地址转换为所述第一 IP地址;
将承载所述 PS业务域发送给所述 WiFi终端的下行数据业务流的数 据报文中携带的第一 IP地址转换为所述第二 IP地址, 所述第二 IP地址 为接入控制器 AC在对所述 WiFi终端进行认证后向所述 WiFi终端分配 的所述无线局域网内的 IP地址;
所述发送单元用于: 根据所述上行数据业务流的目的地址和所述第 一 IP地址, 通过所述第一 PDP上下文连接或第一 PDN连接, 将所述承 载所述上行数据业务流的数据报文发送给相应的 PS业务域;
根据所述第二 IP地址将承载所述下行数据业务流的数据报文发送给 所述 WiFi终端。
18、根据权利要求 17所述的网关, 其特征在于, 所述连接建立单元, 还用于根据所述上行数据业务流的目的地址确定所述上行数据业务流对 应的第二接入点名称, 若所述第二接入点名称对应的第二 GGSN与所述 第一 GGSN或所述第二接入点名称对应的第一 P-GW与第二 P-GW不是 同一设备,建立与所述第二 GGSN的第二 PDP上下文连接或与第二 P-GW 的第二 PDN连接,并获取所述第二 GGSN或第二 P-GW分配给所述 WiFi 终端访问 PS业务域的第三 IP地址;
所述地址转换单元还用于: 将承载所述上行数据业务流的数据报文 中携带的所述第二 IP地址转换为所述第三 IP地址;
将承载所述下行数据业务流的数据报文中携带的所述第三 I P地址转 换为所述第二 IP地址;
所述发送单元还用于: 根据所述上行数据业务流的目的地址和所述 第三 IP地址, 通过所述第二 PDP上下文连接或第二 PDN连接, 将所述 承载所述上行数据业务流的数据报文发送给相应的 PS业务域;
根据所述第二 IP地址将通过 所述第二 PDP上下文连接或第二 PDN 连接接收到的 PS业务域发送给所述 WiFi终端的下行数据业务流的数据 才艮文发送给所述 WiFi终端。
19、 根据权利要求 15所述的网关, 其特征在于, 所述接收单元, 用 于接收所述 WiFi终端发送的所述 DHCP请求消息;
所述网关还包括发送单元, 用于在所述接收单元接收到所述 DHCP 请求消息后, 向所述 AAA服务器发送接入请求消息;
所述接收单元还用于接收 AAA服务器发送的接入响应消息,所述接 入响应消息中携带有所述 WiFi终端的属性信息, 所述属性信息包括第一 接入点名称;
所述连接建立单元用于: 与所述第一接入点名称对应的第一 GGSN 建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW建立第 一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终 端的第一 IP地址;
所述发送单元, 还用于在所述连接建立单元建立所述第一 PDP上下 文连接或第一 PDN连接后 , 向所述 WiFi终端发送 DHCP响应消息 , 所 述 DHCP响应消息携带有所述第一 IP地址。
20、 根据权利要求 15-19 任一项所述的网关, 其特征在于, 所述接 收单元, 还用在所述 WiFi终端下线后, 接收所述 AAA服务器发送的计 费终止消息;
所述网关还包括连接删除单元, 用于在所述接收单元接收到所述计 费终止消息后删除所述第一 PDP上下文连接或第一 PDN连接。
21、 根据权利要求 15所述的网关, 其特征在于, 所述接收单元, 用 于接收所述 WiFi终端发送的 DHCP请求消息;所述网关还包括发送单元; 所述发送单元, 用于向所述 AAA服务器发送认证请求消息, 请求所 述 AAA服务器对所述 WiFi终端进行认证;
所述接收单元, 还用于接收所述 AAA服务器发送的接入响应消息, 所述接入响应消息中携带有所述 WiFi终端的属性信息, 所述属性信息包 括第一接入点名称;
所述连接建立单元用于: 与所述第一接入点名称对应的第一 GGSN 建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW建立第 一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终 端的第一 IP地址; 所述发送单元, 还用于在所述连接建立单元建立第一 PDP上下文连 接或第一 PDN连接后向所述 WiFi终端发送 DHCP响应消息 ,所述 DHCP 响应消息携带有所述第一 IP地址。
22、 根据权利要求 21所述的网关, 其特征在于, 还包括连接删除单 元;
所述发送单元, 还用于当所述 WiFi终端下线时, 向所述 AAA服务 器发送计费终止消息;
所述连接删除单元,用于在所述发送单元向所述 AAA服务器发送所 述计费终止消息后, 删除所述第一 PDP上下文连接或第一 PDN连接。
23、 根据权利要求 15所述的网关, 其特征在于, 还包括发送单元和 获取单元;
所述发送单元用于: 将接入控制器 AC请求所述 AAA服务器对所述 WiFi终端进行认证的认证请求消息转发给所述 AAA服务器;
将所述 AAA服务器对所述 WiFi终端进行认证的认证响应消息转发 给所述 AC , 所述认证响应消息中携带有所述 WiFi终端的属性信息; 所述获取单元,用于从所述认证响应消息中获取所述 WiFi终端的属 性信息, 所述属性信息包括第一接入点名称;
所述连接建立单元用于: 与所述第一接入点名称对应的第一 GGSN 建立第一 PDP上下文连接或与所述第一接入点名称对应的 P-GW建立第 一 PDN连接, 并获得所述第一 GGSN或第一 P-GW分配给所述 WiFi终 端的第一 IP地址;
所述发送单元, 还用于在所述可信网关与所述 PS 业务域建立第一 PDP上下文连接或第一 PDN连接后向所述 WiFi终端发送 DHCP响应消 息, 所述 DHCP响应消息携带有所述第一 IP地址。
24、 根据权利要求 23所述的网关, 其特征在于, 所述发送单元, 还 用于在所述 WiFi终端下线时, 将所述 AC发送的计费终止消息转发给所 述 AAA服务器;
所述网关还包括连接删除单元, 用于根据所述发送单元转发的所述 计费终止消息删除所述第一 PDP上下文连接或第一 PDN连接。
25、 根据权利要求 19 , 21-24 任一项所述的方法, 其特征在于, 所 述发送单元还用于:
根据承载所述 WiFi终端发起 的上行数据业务流的数据报文中携带 的所述上行数据业务流的目的地址和所述第一 IP 地址, 通过所述第一 PDP上下文连接或第一 PDN连接, 将承载所述上行数据业务流的数据报 文发送给相应的 PS业务域;
根据所述第一 IP地址将承载所述 PS业务域发送给所述 WiFi终端的 下行数据业务流的数据报文发送给所述 WiFi终端。
26、 根据权利要求 25任一项所述的网关, 其特征在于, 所述连接建 立单元, 还用于根据所述上行数据业务流的目的地址确定所述上行数据 业务流对应的第二接入点名称,若所述第二接入点名称对应的第二 GGSN 与所述第一 GGSN或所述第二接入点名称对应的第二 P-GW与所述第一 P-GW不是同一设备, 建立与所述第二 GGSN的第二 PDP上下文连接或 与第二 P-GW的第二 PDN连接, 并获取所述第二 GGSN或第二 P-GW分 配给所述 WiFi终端访问 PS业务域的第三 IP地址;
所述发送单元还用于: 根据所述上行数据业务流的目的地址和所述 第三 IP地址, 通过所述第二 PDP上下文连接或第二 PDN连接, 将承载 所述上行数据业务流的数据报文发送给相应的 PS业务域;
根据所述第三 IP地址将承载通过所述第二 PDP上下文连接或第二 PDN连接接收到的 PS业务域发送给所述 WiFi终端的下行数据业务流的 数据报文发送给所述 WiFi终端。
27、 根据权利要求 19 , 21-24 所述的网关, 其特征在于, 所述发送 单元, 还用于在所述连接建立单元建立所述第一 PDP上下文连接或第一 PDN连接后, 向所述 AAA服务器发送计费请求消息, 指示所述 AAA服 务器对所述 WiFi终端进行计费。
PCT/CN2013/072277 2012-03-07 2013-03-07 一种WiFi终端接入分组数据PS业务域的方法和可信网关 WO2013131483A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
JP2014560236A JP5903728B2 (ja) 2012-03-07 2013-03-07 Wifi端末がパケットデータpsサービスドメインにアクセスするための方法およびトラステッドゲートウェイ
EP13757311.9A EP2816863B1 (en) 2012-03-07 2013-03-07 Method and trusted gateway for wifi terminal to access packet data ps service domain
US14/478,576 US9736157B2 (en) 2012-03-07 2014-09-05 Method and trusted gateway for WiFi terminal accessing to packet data PS service domain

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210058651.7A CN103313317B (zh) 2012-03-07 2012-03-07 一种WiFi终端接入分组数据PS业务域的方法和可信网关
CN201210058651.7 2012-03-07

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US14/478,576 Continuation US9736157B2 (en) 2012-03-07 2014-09-05 Method and trusted gateway for WiFi terminal accessing to packet data PS service domain

Publications (1)

Publication Number Publication Date
WO2013131483A1 true WO2013131483A1 (zh) 2013-09-12

Family

ID=49115948

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/072277 WO2013131483A1 (zh) 2012-03-07 2013-03-07 一种WiFi终端接入分组数据PS业务域的方法和可信网关

Country Status (5)

Country Link
US (1) US9736157B2 (zh)
EP (1) EP2816863B1 (zh)
JP (1) JP5903728B2 (zh)
CN (1) CN103313317B (zh)
WO (1) WO2013131483A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10432632B2 (en) 2014-06-25 2019-10-01 Huawei Technologies Co., Ltd. Method for establishing network connection, gateway, and terminal
CN112492574A (zh) * 2016-06-28 2021-03-12 华为技术有限公司 一种负载迁移方法、装置及系统

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2844005A4 (en) * 2012-04-26 2015-06-03 Huawei Tech Co Ltd METHOD FOR ACCESSING PACKET NETWORK, WLAN ACCESS SYSTEM AND USER DEVICE
CN104684038A (zh) * 2013-12-02 2015-06-03 中国移动通信集团江苏有限公司 一种切换方法和相关装置
US9629060B2 (en) * 2014-06-06 2017-04-18 Oracle International Corporation Flexible routing policy for Wi-Fi offloaded cellular data
US9191865B1 (en) * 2015-02-09 2015-11-17 Sprint Communications Company L.P. Long term evolution (LTE) communications over trusted hardware
US10341300B2 (en) * 2015-03-01 2019-07-02 Cisco Technology, Inc. System, method, apparatus and machine-readable media for enterprise wireless calling
EP3099046B1 (en) * 2015-05-25 2018-07-04 EXFO Oy Arrangement, computer program code and method for call data record processing
CN106937315B (zh) * 2015-12-30 2020-01-17 中移(苏州)软件技术有限公司 数据收发方法及装置
US10762559B2 (en) * 2016-04-15 2020-09-01 Adp, Llc Management of payroll lending within an enterprise system
CN110278558B (zh) * 2019-07-25 2022-09-13 迈普通信技术股份有限公司 报文的交互方法及wlan系统
CN110769482B (zh) * 2019-09-16 2022-03-01 浙江大华技术股份有限公司 无线设备进行网络连接的方法、装置和无线路由器设备
US11032743B1 (en) * 2019-11-30 2021-06-08 Charter Communications Operating, Llc Methods and apparatus for supporting devices of different types using a residential gateway

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102148878A (zh) * 2010-02-05 2011-08-10 中国移动通信集团公司 Ip地址分配方法、系统和设备
WO2012006448A1 (en) * 2010-07-09 2012-01-12 Stoke, Inc. Method and system for interworking a wlan into a wwan for session and mobility management
CN102917356A (zh) * 2011-08-03 2013-02-06 华为技术有限公司 将用户设备接入演进的分组核心网络的方法、设备和系统

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1663166B (zh) 2002-06-21 2010-12-01 汤姆森许可贸易公司 把wlan注册为umts路由区的方法和设备
DE60208382T2 (de) 2002-10-17 2006-06-22 Alcatel Hybrides UMTS/WLAN Telekommunikationssystem
CN1277393C (zh) 2003-12-12 2006-09-27 华为技术有限公司 一种无线局域网用户终端选择分组数据关口的方法
EP1646189A1 (en) * 2004-10-06 2006-04-12 Matsushita Electric Industrial Co., Ltd. WLAN radio access network to UMTS radio access network handover with network requested packet data protocol context activation
FR2904914B1 (fr) 2006-08-09 2008-09-26 Alcatel Sa Procede de gestion d'interfonctionnement pour le transfert de sessions de service d'un reseau local sans fil vers un reseau mobile, et noeuds sgsn correspondants
CN101472314B (zh) * 2007-11-02 2010-05-12 华为技术有限公司 一种数据处理方法和设备
CN101867909B (zh) * 2009-04-20 2013-10-16 中兴通讯股份有限公司 一种实现有限策略计费控制的方法及系统
CN101984724B (zh) 2010-11-19 2014-08-13 中兴通讯股份有限公司 一种融合网络中隧道建立的方法及系统
WO2013126918A1 (en) * 2012-02-24 2013-08-29 Ruckus Wireless, Inc. Wireless services gateway

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102148878A (zh) * 2010-02-05 2011-08-10 中国移动通信集团公司 Ip地址分配方法、系统和设备
WO2012006448A1 (en) * 2010-07-09 2012-01-12 Stoke, Inc. Method and system for interworking a wlan into a wwan for session and mobility management
CN102917356A (zh) * 2011-08-03 2013-02-06 华为技术有限公司 将用户设备接入演进的分组核心网络的方法、设备和系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
LTE: "3GPP system to Wireless Local Area Network (WLAN) interworking; System description", 3GPPTS 23.234 VERSION 10.0.0 RELEASE 10, 31 March 2011 (2011-03-31), XP050476487 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10432632B2 (en) 2014-06-25 2019-10-01 Huawei Technologies Co., Ltd. Method for establishing network connection, gateway, and terminal
EP3154306B1 (en) * 2014-06-25 2020-02-26 Huawei Technologies Co., Ltd. Establishment of network connection
CN112492574A (zh) * 2016-06-28 2021-03-12 华为技术有限公司 一种负载迁移方法、装置及系统
US11496913B2 (en) 2016-06-28 2022-11-08 Huawei Technologies Co., Ltd. Load migration method, apparatus, and system

Also Published As

Publication number Publication date
US9736157B2 (en) 2017-08-15
EP2816863A4 (en) 2015-03-04
JP2015515773A (ja) 2015-05-28
CN103313317B (zh) 2016-09-28
US20140380434A1 (en) 2014-12-25
EP2816863B1 (en) 2019-05-22
CN103313317A (zh) 2013-09-18
JP5903728B2 (ja) 2016-04-13
EP2816863A1 (en) 2014-12-24

Similar Documents

Publication Publication Date Title
JP5903728B2 (ja) Wifi端末がパケットデータpsサービスドメインにアクセスするための方法およびトラステッドゲートウェイ
US10009758B2 (en) WiFi fixed wireless personal services
US10432632B2 (en) Method for establishing network connection, gateway, and terminal
JP5982690B2 (ja) ネットワークコンバージェンスの方法、デバイス、および通信システム
US20190394647A1 (en) Communication system, connection control apparatus, mobile terminal, base station control method, service request method, and program
WO2013040978A1 (zh) 数据分流触发方法、网络侧设备和用户设备及网络系统
WO2011035473A1 (zh) 一种网络流量分流方法、设备及系统
WO2013170897A1 (en) Routing of traffic in a multi-domain network
CN102695236B (zh) 一种数据路由方法及系统
WO2012051897A1 (zh) 一种融合固定网络与移动网络的系统及方法
WO2013131487A1 (zh) 融合的核心网及其接入方法
WO2012003770A1 (zh) 一种用户设备接入移动网络的系统、设备及方法
US20190223013A1 (en) Method for establishing public data network connection and related device
WO2014005267A1 (zh) 接入移动网络的方法、装置及系统
WO2014101755A1 (zh) 业务数据分流方法及系统
CN101707773A (zh) Wlan接入网关、移动网与无线宽带网的融合方法和系统
CN107277790B (zh) 一种为终端提供紧急号码的方法和装置
WO2014063530A1 (zh) 移动用户固网的接入方法及系统
KR101727557B1 (ko) 무선통신시스템에서 엘비오 서비스를 제공하기 위한 방법 및 장치
US9838214B2 (en) Wi-Fi offload of cellular data
KR101954397B1 (ko) Lte 이동통신 시스템에서 패킷 차단 방법 및 패킷 차단 시스템
CN103582159A (zh) 一种固定移动网络融合场景下的多连接建立方法及系统
WO2014032542A9 (zh) 多连接建立的方法及系统
WO2014059823A1 (zh) 分组数据网络(pdn)业务的实现方法、系统及网元
WO2013152640A1 (zh) 地址分配方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13757311

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2014560236

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2013757311

Country of ref document: EP