WO2014089804A1 - 近距离服务的认证与授权的方法及设备 - Google Patents

近距离服务的认证与授权的方法及设备 Download PDF

Info

Publication number
WO2014089804A1
WO2014089804A1 PCT/CN2012/086541 CN2012086541W WO2014089804A1 WO 2014089804 A1 WO2014089804 A1 WO 2014089804A1 CN 2012086541 W CN2012086541 W CN 2012086541W WO 2014089804 A1 WO2014089804 A1 WO 2014089804A1
Authority
WO
WIPO (PCT)
Prior art keywords
server
application
authorization
identifier
response message
Prior art date
Application number
PCT/CN2012/086541
Other languages
English (en)
French (fr)
Inventor
周卫华
郭雅莉
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201280036016.7A priority Critical patent/CN104012035B/zh
Priority to PCT/CN2012/086541 priority patent/WO2014089804A1/zh
Publication of WO2014089804A1 publication Critical patent/WO2014089804A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • Embodiments of the present invention relate to communication technologies, and in particular, to a method and device for authentication and authorization of a short-range service. Background technique
  • Proximity Service is becoming more and more important.
  • UEs user equipment
  • UEs that support the short-range service function are first registered in the network before using the short-range service. Only when the UE obtains successful authentication and authorization of the network using the short-distance service for the UE, the application on the UE can use the close-range service, such as a social application, an advertisement application, and the like.
  • the user wants to be able to know when a friend appears or leaves around.
  • social applications can make people's lives and work more convenient. For example, when the user arrives at the office, through the close-up discovery function, he can immediately find out which colleagues have reached the office in the social application.
  • the network device can only perform authentication and authorization for the UE for short-distance service, that is, the network device only authenticates whether the UE has purchased and signed a close-range service from the operator. If the UE has subscribed to the close-range service, the UE is allowed to use the short-range service, otherwise the UE is denied to use the close-range service.
  • the network device only authenticates and authorizes whether the UE can use the short-range service, and does not support the network device to authenticate and authorize the application using the short-distance service.
  • the network device cannot control various applications using the short-distance service, so that the operator cannot refine the application of the UE using the short-distance service.
  • the embodiments of the present invention provide a method and a device for authenticating and authorizing a short-distance service, which are used to solve the problem that an operator cannot refine the use of a short-range service in a UE in the prior art.
  • a method for authentication and authorization of a short-range service including: after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, the MME receives a first authorization request sent by the UE, where the first authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the MME sends a second authorization request to the proximity server according to the first authorization request, where the second authorization request includes an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the second authorization request is used to enable the proximity server to search for the stored subscription information of the UE according to the identifier of the UE, whether there is an identifier corresponding to the application in the UE and a user identifier corresponding to the application.
  • Authorization information for close-range services includes an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the MME receives the second-party authorization according to the proximity server.
  • the method before the step of receiving, by the MME, the first authorization request sent by the UE, the method further includes:
  • a first registration request that is sent by the UE to register with a proximity server, where the first registration request includes: an identifier of the UE;
  • the MME sends a second registration request to the proximity server according to the first registration request, where the second registration request includes: an identifier of the UE, where the second registration request is used to make the proximity server according to the location
  • the identifier of the UE determines whether there is authorization information of the UE that uses the proximity service corresponding to the identifier of the UE in the subscription information of the UE corresponding to the identifier of the UE;
  • the MME receives a registration pass response message sent by the proximity server, where the registration pass response message includes: Determining, by the proximity server, a first identifier for the UE that uses the proximity service and a second identifier of the proximity server;
  • the pass response message includes: the first identifier and the second identifier.
  • the method before the step of the MME receiving the first authorization request sent by the UE, the method further includes:
  • a first registration request that is sent by the UE to register with a proximity server, where the first registration request includes: an identifier of the UE;
  • the MME determines that the UE corresponding to the identifier of the UE uses the authorization information of the proximity service in the subscription information of the UE, the MME sends a third registration request to the proximity server, where the third registration is performed.
  • the request includes: an identifier of the UE and subscription information of the UE;
  • the MME receives a registration pass response message sent by the proximity server according to the third registration request, where the registration pass response message includes: the short-distance server allocates the short-distance service to the UE. An identifier and a second identifier of the proximity server;
  • the method further includes: if the proximity server determines that the subscription information of the UE does not include the authorization information, the MME receives the close distance a response message of the denial of authorization sent by the server according to the second authorization request;
  • the MME sends a reject response message to the UE according to the acknowledgement message of the denial of authorization.
  • the first registration request is carried in one of the following messages:
  • a method for authentication and authorization of a short-range service including: an application server receiving an authentication request sent by a UE, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, and a location a user identifier of the application, a first identifier of the proximity server using the proximity service and a second identifier of the proximity server allocated by the proximity server Identifier
  • the application server sends a first confirmation request to the proximity server according to the second identifier, where the first confirmation request includes: an identifier of the UE, an identifier applied by the UE, and a user of the application. And the first identifier, the first confirmation request is used to enable the proximity server to determine, according to the identifier of the UE, whether the identifier of the application is in the subscription information of the UE corresponding to the identifier of the UE. And the user identifier of the application and the UE corresponding to the first identifier use authorization information of the proximity service;
  • the application server receives an acknowledgement response that is sent by the proximity server;
  • the method further includes: if the proximity server determines, according to the identifier of the UE, that the subscription information does not include the authorization information, the application server Receiving a reject message sent by the proximity server, and the application server sends an authentication reject message to the UE according to the reject message.
  • the third aspect provides a method for the authentication and authorization of the short-range service, including: after the proximity server authenticates the UE where the application is located, when the application on the UE starts to use the proximity service, the proximity server receives a second authorization request sent by the MME, where the second authorization request is sent by the MME after receiving the first authorization request sent by the UE, and the second authorization request includes: an identifier of the UE, the UE The identifier of the application, the user identifier of the application;
  • the proximity server searches for the stored subscription information of the UE according to the identifier of the UE, whether the identifier of the application in the UE and the authorization identifier of the application that uses the proximity service corresponding to the application identifier of the application are included;
  • the proximity server sends an authorization response message to the MME to And causing the MME to send a pass response message to the UE by using a response message according to the authorization.
  • the proximity server receives
  • the method further includes:
  • the second registration request sent by the MME receives, by the MME, the second registration request sent by the MME, where the second registration request is sent by the MME after receiving the first registration request sent by the UE, where the second registration request includes: The identifier of the UE;
  • the proximity server determines, according to the identifier of the UE, that the subscription information is authorized by the UE to use the proximity service, and sends a registration response message to the MME, where the registration response message includes: Determining, by the proximity server, a first identifier of the short-range service and a second identifier of the proximity server allocated by the UE, to enable the MME to send the first identifier and the The pass response message of the second identifier.
  • the method before the step of receiving, by the proximity server, the second authorization request sent by the MME, the method further includes:
  • the short-range server receives a third registration request sent by the MME, where the third registration request includes: an identifier of the UE and subscription information of the UE;
  • the third registration request is that the MME receives the first registration request sent by the UE, and acquires subscription information of the UE from the HSS according to the identifier of the UE in the first registration request, and determines that the subscription information is included in the subscription information.
  • the UE corresponding to the identifier of the UE is sent after using the authorization information of the short-distance service;
  • the short-distance server stores the subscription information of the UE, and sends a registration pass response message to the MME according to the third registration request, where the registration pass response message includes: the short-range server allocates the UE Using the first identifier of the proximity service and the second identifier of the proximity server to cause the MME to send a response message including the first identifier and the second identifier to the UE.
  • the method further includes: if the proximity server determines that the identifier of the UE and the user identifier of the application are not included in the subscription information of the UE Corresponding to the authorization information of using the short-distance service, sending a response message of rejecting the authorization of the second authorization request to the MME, so that the MME root Sending a reject response message to the UE according to the response message rejecting the authorization.
  • the fourth aspect provides a method for authentication and authorization of a short-range service, including: after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, The UE sends a first authorization request to the MME, where the first authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application; the first authorization request is used to enable the MME Determining, by the proximity server, the stored subscription information of the UE according to the identifier of the UE, whether there is an identifier of the application in the UE and authorization information of the user identifier of the application;
  • the UE receives the response message sent by the MME, and the The response message is sent by the MME after receiving the authorization request message sent by the proximity server;
  • the UE After receiving the response message, the UE sends an authentication request to the application server, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a proximity server. Determining, by the UE, a first identifier using the proximity service and a second identifier of the proximity server;
  • the method further includes:
  • the first registration request includes: an identifier of the UE, to enable the MME to be near according to the first registration request Determining, by the server, whether the UE has the authorization information of the proximity service in the subscription information of the UE;
  • the UE receives a response message sent by the MME, and the response message is used by the MME to receive the
  • the registration sent by the proximity server is sent after the response message, and the response message includes: the short-range server allocates the UE Using the first identifier of the proximity service and the second identifier of the proximity server.
  • the first registration request is carried in one of the following messages:
  • a mobility management entity including:
  • a receiving unit configured to: after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, receive the first authorization request sent by the UE, the first authorization request
  • the method includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • a sending unit configured to send a second authorization request to the proximity server according to the first authorization request received by the receiving unit, where the second authorization request includes: an identifier of the UE, and an identifier applied by the UE And the user identifier of the application; the second authorization request is used to enable the proximity server to search for the stored subscription information of the UE according to the identifier of the UE, whether there is an identifier and a location of the application in the UE.
  • the authorization information of the proximity service is corresponding to the user identifier of the application;
  • the receiving unit configured to: after the sending unit sends the second authorization request, determine, by the proximity server, the identifier of the UE and the user identifier of the application in the subscription information of the UE. Corresponding authorization information, receiving an authorization pass response message sent by the proximity server according to the second authorization request;
  • the sending unit is configured to send, by the response message, a pass response message to the UE according to the authorization received by the receiving unit, so that the UE initiates an authentication request to the application server according to the pass response message.
  • the receiving unit is further configured to: before receiving the first authorization request, receive, by the UE, a first one for registering with a proximity server a registration request, the first registration request includes: an identifier of the UE; the sending unit is further configured to send a second registration request to the proximity server according to the first registration request received by the receiving unit, where the second The registration request includes: an identifier of the UE, where the second registration request is used to enable the proximity server to determine, according to the identifier of the UE, whether the subscription information of the UE corresponding to the identifier of the UE is related to the UE.
  • the receiving unit is further configured to: when the proximity server determines that the authorization information is included in the subscription information according to the identifier of the UE, receive a registration pass response message sent by the proximity server, where the registration is passed
  • the response message includes: a first identifier that is used by the proximity server to use the proximity service and a second identifier of the proximity server that is allocated to the UE;
  • the sending unit is further configured to send a response message to the UE according to the registration and response message received by the receiving unit, where the response message includes: the first identifier and the second identifier .
  • the receiving unit is further configured to: before receiving the first authorization request, receive, by the UE, a first one for registering with a proximity server a registration request, the first registration request includes: an identifier of the UE; the mobility management entity further includes:
  • An acquiring unit configured to acquire, after the receiving unit receives the first registration request, the subscription information of the UE corresponding to the identifier of the UE, according to the identifier of the UE, to the HSS;
  • a determining unit configured to determine, in the subscription information of the UE, whether the UE corresponding to the identifier of the UE uses the authorization information of the short-distance service
  • the sending unit is further configured to: after the determining unit determines that the UE corresponding to the identifier of the UE uses the authorization information of the proximity service, the third registration request is sent to the proximity server.
  • the third registration request includes: an identifier of the UE and subscription information of the UE;
  • the receiving unit is configured to: after the sending unit sends the third registration request, receive a registration pass response message sent by the proximity server according to the third registration request, where the registration pass response message includes: Determining, by the proximity server, a first identifier for the UE that uses the proximity service and a second identifier of the proximity server;
  • the sending unit is configured to send a pass response message to the UE according to the registration pass response message received by the receiving unit, where the pass response message includes the first identifier and the second identifier.
  • the receiving unit is further configured to: when the proximity server determines that the subscription information of the UE does not include the authorization information, receive the proximity server a reply message rejecting the authorization sent according to the second authorization request;
  • the sending unit is further configured to send a reject response message to the UE according to the acknowledgement message of the denial of authorization received by the receiving unit.
  • the first registration request is carried in one of the following messages:
  • an application server including:
  • a receiving unit configured to receive an authentication request sent by the UE, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a usage of a short-range server allocated to the UE a first identifier of the distance service and a second identifier of the proximity server;
  • a sending unit configured to send, by the receiving unit, the first confirmation request to the proximity server according to the second identifier, where the first confirmation request includes: the identifier of the UE, the The identifier of the application, the user identifier of the application, and the first identifier, where the first confirmation request is used to enable the proximity server to determine, according to the identifier of the UE, a UE corresponding to the identifier of the UE. Whether the identifier of the application, the user identifier of the application, and the authorization information of the UE using the proximity service corresponding to the first identifier are included in the subscription information;
  • the receiving unit is further configured to: after the sending unit sends the first confirmation request, and when the proximity server determines, according to the identifier of the UE, that the authorization information is included in the subscription information, receiving the location Determining the acknowledgement of the authorization sent by the proximity server;
  • the sending unit is further configured to: after the receiving unit receives the acknowledgement response of the authorization, send an authentication pass message to the UE according to the acknowledgement response that the authorization passes, so that the UE passes the message according to the authentication
  • the application uses the proximity service.
  • the receiving unit is further configured to: after the sending unit sends the first confirmation request, and according to the identifier of the UE in the short-range server When it is determined that the authorization information is not included in the subscription information, receiving a rejection message sent by the proximity server;
  • the sending unit is further configured to: after the receiving unit receives the reject message, send an authentication reject message to the UE according to the reject message.
  • a proximity server including: a receiving unit, configured to receive a second authorization request sent by the MME when the application on the UE starts to use the short-distance service, and the second authorization request is received by the MME And the second authorization request is sent by the UE, and the second authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • a search unit configured to: after the receiving unit receives the second authorization request, search for the stored subscription information of the UE according to the identifier of the UE, whether the identifier of the application in the UE and the application are Authorization information corresponding to the user identity using the proximity service;
  • a sending unit configured to send, by the searching unit, the subscription information of the UE, the identifier of the application in the UE and the authorization information of the proximity service corresponding to the user identifier of the application, and send the information to the MME Authorizing the response message, so that the MME sends a pass response message to the UE by using a response message according to the authorization.
  • the receiving unit is further configured to: before receiving the second authorization request, further receive a second registration request sent by the MME, where the second registration is The request is sent by the MME after receiving the first registration request sent by the UE, where the second registration request includes: an identifier of the UE;
  • the proximity server further includes:
  • an acquiring unit configured to acquire, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE, according to the identifier of the UE, after the receiving unit receives the second registration request;
  • a determining unit configured to determine, according to the identifier of the UE, that the subscription information has authorization information that the UE authorizes using the proximity service, after the acquiring unit acquires the subscription information of the UE;
  • the sending unit is further configured to: when the determining unit determines the authorization information, send a registration pass response message to the MME, where the registration pass response message includes: the short-range server allocates the UE Using the first identifier of the proximity service and the second identifier of the proximity server to cause the MME to send a response message including the first identifier and the second identifier to the UE.
  • the receiving unit is further configured to: before receiving the second authorization request, receive a third registration request sent by the MME, where the third registration request is The method includes: an identifier of the UE and subscription information of the UE;
  • the registration request is that the MME receives the first registration request sent by the UE, and acquires subscription information of the UE from the HSS according to the identifier of the UE in the first registration request, and determines that the subscription information includes the UE. Identifying that the corresponding UE is sent after using the authorization information of the proximity service;
  • the proximity server further includes:
  • a storage unit configured to store subscription information of the UE after the receiving unit receives the third registration request
  • a sending unit configured to send a registration pass response message to the MME according to the third registration request after the storing unit stores the subscription information of the UE, where the registration pass response message includes: the proximity server is a first identifier of the proximity service and a second identifier of the proximity server allocated by the UE, to enable the MME to send the first identifier and the second identifier to a UE By responding to the message.
  • the sending unit is further configured to: in the subscription information that the searching unit does not find the UE, the identifier that is applied by the UE and the user of the application And the MME sends a response message of the second authorization request to the MME, so that the MME sends a reject response to the UE according to the acknowledgement message of the denial of authorization. Message.
  • a user equipment including:
  • a sending unit configured to send a first authorization request to the MME after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, where the first authorization request includes: The identifier of the UE, the identifier of the application in the UE, and the user identifier of the application, where the first authorization request is used to enable the MME to search for a stored subscription of the UE according to the identifier of the UE to a proximity server. In the information, whether there is an identifier of an application in the UE and authorization information of a user identifier of the application;
  • a receiving unit configured to: after the sending unit sends the first authorization request, and in the contract information that the proximity server determines that the UE has an identifier applied in the UE and a user identifier of the application Receiving, by the authorization information, a response message sent by the MME, where the response message is sent by the MME after receiving the authorization response message sent by the proximity server;
  • the sending unit is further configured to: after the receiving unit receives the pass response message, Initiating an authentication request to the application server, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a first use of the proximity service allocated by the proximity server for the UE An identifier and a second identifier of the proximity server;
  • the receiving unit is further configured to: after the sending unit sends the authentication request, receive an authentication pass message sent by the application server, where the authentication pass message is the application server according to the authentication request and the near Interacting with the server and confirming that the application of the UE can be sent after using the proximity service;
  • the sending unit is further configured to send, by the MME, a first registration for registering with a proximity server, before sending the first authorization request
  • the request, the first registration request includes: the identifier of the UE, to enable the MME to determine, according to the first registration request, whether the UE uses the proximity service in the subscription information of the UE to the proximity server.
  • Authorization information includes: the identifier of the UE, to enable the MME to determine, according to the first registration request, whether the UE uses the proximity service in the subscription information of the UE to the proximity server.
  • the receiving unit is further configured to: after the sending unit sends the first registration request, and after the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information,
  • the UE receives the response message sent by the MME, and the response message is sent by the MME after receiving the registration response message sent by the proximity server, where the response message includes: the proximity server is Determining, by the UE, a first identifier that uses the proximity service and a second identifier of the proximity server.
  • the first registration request is carried in one of the following messages:
  • a mobility management entity including:
  • a receiver configured to: after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, receive the first authorization request sent by the UE, the first authorization request
  • the method includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • a transmitter configured to send a second authorization request to the proximity server according to the first authorization request received by the receiver, where the second authorization request includes: an identifier of the UE, and an identifier applied in the UE And a user identifier of the application; the second authorization request is for causing the The proximity server searches for the stored subscription information of the UE according to the identifier of the UE, whether the identifier of the application in the UE and the user identifier of the application correspond to the authorization information of using the proximity service;
  • the receiver configured to: after the transmitter sends the second authorization request, determine, by the proximity server, the identifier of the application in the UE and the user identifier of the application in the subscription information of the UE In the case of the corresponding authorization information, receiving an authorization pass response message sent by the proximity server according to the second authorization request;
  • the transmitter is configured to send a pass response message to the UE according to the authorization received by the receiver by using a response message, so that the UE initiates an authentication request to the application server according to the pass response message.
  • the receiver is further configured to receive, before receiving the first authorization request, a first one that is sent by the UE to register with a proximity server.
  • a registration request the first registration request includes: an identifier of the UE;
  • the transmitter is further configured to send a second registration request to the proximity server according to the first registration request received by the receiver, where the second registration request includes: an identifier of the UE, where the second registration request is used by And determining, by the proximity server, whether the UE corresponding to the identifier of the UE uses the authorization information of the short-distance service in the subscription information of the UE corresponding to the identifier of the UE according to the identifier of the UE;
  • the receiver is further configured to: when the proximity server determines that the authorization information is included in the subscription information according to the identifier of the UE, receive a registration pass response message sent by the proximity server, where the registration is The response message includes: the first identifier allocated by the short-range server for the UE using the proximity service and the second identifier of the proximity server;
  • the transmitter is further configured to send a response message to the UE according to the registration and response message received by the receiver, where the response message includes: the first identifier and the second identifier .
  • the receiver is further configured to receive, before receiving the first authorization request, a first one that is sent by the UE to register with a proximity server.
  • a registration request the first registration request includes: an identifier of the UE;
  • the mobility management entity further includes: a processor, after the receiver receives the first registration request, according to the
  • the transmitter is further configured to: when the processor determines the subscription information of the UE,
  • the third registration request is sent to the short-range server, where the third registration request includes: the identifier of the UE and the subscription information of the UE;
  • the receiver is configured to: after the transmitter sends the third registration request, receive a registration pass response message sent by the proximity server according to the third registration request, where the registration pass response message includes: Determining, by the proximity server, a first identifier for the UE that uses the proximity service and a second identifier of the proximity server;
  • the transmitter is configured to send a response message to the UE according to the registration response message received by the receiver, where the response message includes the first identifier and the second identifier.
  • the receiver is further configured to: when the proximity server determines that the subscription information of the UE does not include the authorization information, receive the proximity server a reply message rejecting the authorization sent according to the second authorization request;
  • the transmitter is further configured to send a reject response message to the UE according to the acknowledgement message of the denial of authorization received by the receiver.
  • the first registration request is carried in one of the following messages: a network attach message, a location update message, a Access layer messages, and access layer messages.
  • an application server including:
  • a receiver configured to receive an authentication request sent by the UE, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a usage near the server allocated by the proximity server a first identifier of the distance service and a second identifier of the proximity server;
  • a transmitter configured to send a first confirmation request to the proximity server according to the second identifier, after the receiver receives the authentication request, where the first confirmation request includes: The identifier of the UE, the identifier of the application in the UE, the user identifier of the application, and the first identifier, where the first confirmation request is used to determine, by the proximity server, the identifier according to the UE Whether the identifier of the application, the user identifier of the application, and the authorization information of the UE corresponding to the first identifier using the proximity service are included in the subscription information of the UE corresponding to the identity of the UE;
  • the receiver is further configured to: after the transmitter sends the first confirmation request, and when the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, receiving the location Determining the acknowledgement of the authorization sent by the proximity server;
  • the transmitter is further configured to: after the receiver receives the acknowledgement response of the authorization, send an authentication pass message to the UE according to the acknowledgement response of the authorization, so that the UE passes the message according to the authentication
  • the application uses the proximity service.
  • the receiver is further configured to: after the sending, by the transmitter, the first acknowledgement request, and at the short-range server, according to the identifier of the UE When it is determined that the authorization information is not included in the subscription information, receiving a rejection message sent by the proximity server;
  • the transmitter is further configured to send an authentication reject message to the UE according to the reject message after the receiver receives the reject message.
  • a proximity server comprising:
  • a receiver configured to receive a second authorization request sent by the MME when the application on the UE starts to use the short-distance service, and the second authorization request is received by the MME And the second authorization request is sent by the UE, and the second authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • a processor configured to: after the receiver receives the second authorization request, search for the stored subscription information of the UE according to the identifier of the UE, whether the identifier of the application in the UE and the application are Authorization information corresponding to the user identity using the proximity service;
  • the receiver is further configured to: before receiving the second authorization request, receive a second registration request sent by the MME, where the second The registration request is sent by the MME after receiving the first registration request sent by the UE, where the second registration request includes: an identifier of the UE;
  • the processor is configured to: after the receiver receives the second registration request, obtain, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE, and determine, according to the identifier of the UE,
  • the contract information includes the authorization information that the UE authorizes to use the proximity service;
  • the transmitter is further configured to: when the processor determines the authorization information, send a registration pass response message to the MME, where the registration pass response message includes: the short-range server allocates the UE Using the first identifier of the proximity service and the second identifier of the proximity server to cause the MME to send a response message including the first identifier and the second identifier to the UE.
  • the receiver is further configured to: before receiving the second authorization request, receive a third registration request sent by the MME, where the third registration is The request includes: the identifier of the UE and the subscription information of the UE; the third registration request is a first registration request sent by the MME by the MME, and according to the identifier of the UE in the first registration request Acquiring the subscription information of the UE to the HSS, and determining that the UE corresponding to the identifier of the UE is sent by using the authorization information of the proximity service in the subscription information;
  • the processor configured to store subscription information of the UE after the receiver receives the third registration request
  • the transmitter configured to send a registration pass response message to the MME according to the third registration request after the processor stores the subscription information of the UE, where the registration pass response message includes: the close distance a first identifier of the short-range service and a second identifier of the short-range server allocated by the server for the UE, so that the MME sends the first identifier and the second to the UE The identifier's pass response message.
  • the transmitter is further configured to: in the subscription information that the processor does not find the UE, the identifier that is applied in the UE and the identifier If the application user identifier corresponding to the application uses the authorization information of the proximity service, the MME is sent to the MME. Sending a response message of the second authorization request rejecting the authorization, so that the MME sends a reject response message to the UE according to the acknowledgement request message.
  • a user equipment including:
  • a transmitter configured to send a first authorization request to the MME after the UE where the application is located is authenticated by the proximity server, and when the application on the UE initiates the use of the proximity service, the first authorization request includes: The identifier of the UE, the identifier of the application in the UE, and the user identifier of the application, where the first authorization request is used to enable the MME to search for a stored subscription of the UE according to the identifier of the UE to a proximity server. In the information, whether there is an identifier of an application in the UE and authorization information of a user identifier of the application;
  • a receiver after the transmitter sends the first authorization request, and the proximity server determines that the subscription information of the UE has an identifier of an application in the UE and a user identifier of the application.
  • the transmitter is further configured to: after the receiver receives the pass response message, initiate an authentication request to the application server, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, a first identifier of the proximity server using the proximity service and a second identifier of the proximity server allocated by the proximity server;
  • the receiver is further configured to: after the transmitter sends the authentication request, receive an authentication pass message sent by the application server, where the authentication pass message is the application server according to the authentication request and the near Interacting with the server and confirming that the application of the UE can be sent after using the proximity service;
  • the processor causes the application to use the proximity service according to an authentication pass message received by the receiver.
  • the transmitter is further configured to send, to the MME, a first one for registering with a proximity server before sending the first authorization request a registration request, the first registration request includes: an identifier of the UE, to enable the MME to determine, according to the first registration request, whether the UE uses the proximity service in the subscription information of the UE to the proximity server.
  • Authorization information includes: an identifier of the UE, to enable the MME to determine, according to the first registration request, whether the UE uses the proximity service in the subscription information of the UE to the proximity server.
  • the receiver is further configured to: after the transmitter sends the first registration request, and The proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, and the UE receives a response message sent by the MME, where the response message is used by the MME to receive the near message.
  • the response message includes: the first identifier used by the proximity server for the UE to use the proximity service and the second identifier of the proximity server Identifier.
  • the first registration request is carried in one of the following messages:
  • the method and device for authenticating and authorizing the proximity service after the UE is authenticated by the proximity server, when the application on the UE uses the proximity server, the MME is used to the proximity server.
  • the short-distance server sends a response message to the UE through the MME, so that the UE initiates an authentication request to the application server according to the response message, which solves the problem that the operator cannot refine the application of the proximity service in the UE in the prior art.
  • FIG. 1 is a schematic flow chart of a method for authentication and authorization of a short-range service according to an embodiment of the present invention
  • FIG. 2 is a schematic flow chart of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention
  • FIG. 3 is a schematic flow chart of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention.
  • FIG. 4 is a schematic flowchart diagram of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention
  • FIG. 5 is a schematic flowchart diagram of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention
  • FIG. 4 is a schematic flowchart diagram of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention
  • FIG. 5 is a schematic flowchart diagram of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention.
  • FIG. 6 is a schematic flow chart of a method for providing authentication and authorization of a proximity service according to another embodiment of the present invention.
  • FIG. 7 is a schematic flowchart of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention.
  • FIG. 8A and FIG. 8B are schematic flowcharts of a method for providing authentication and authorization of a short-range service according to another embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of a mobility management entity according to another embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of an application server according to another embodiment of the present invention.
  • FIG. 11 is a schematic structural diagram of a proximity server according to another embodiment of the present invention.
  • FIG. 12 is a schematic structural diagram of a user equipment according to another embodiment of the present disclosure.
  • FIG. 13 is a schematic structural diagram of a mobility management entity according to another embodiment of the present invention.
  • FIG. 14 is a schematic structural diagram of an application server according to another embodiment of the present invention.
  • FIG. 15 is a schematic structural diagram of a proximity server according to another embodiment of the present invention.
  • FIG. 16 is a schematic structural diagram of a user equipment according to another embodiment of the present invention.
  • the technical solutions of the present invention will be clearly and completely described in the following with reference to the accompanying drawings in the embodiments of the present invention. It will be apparent that the various embodiments described below are merely exemplary embodiments of the invention. Based on the following various embodiments of the present invention, those skilled in the art can obtain other technical features that can solve the technical problems of the present invention and achieve the technical effects of the present invention by equivalently transforming some or even all of the technical features without creative work. The various embodiments of the invention are apparent from the scope of the invention as disclosed.
  • FIG. 1 is a schematic flowchart of a method for authentication and authorization of a short-range service according to an embodiment of the present invention. As shown in FIG. 1, the method for authentication and authorization of a short-range service in this embodiment is as follows.
  • the Mobility Management Entity receives the first authorization sent by the UE.
  • the request, the first authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application.
  • the user identifier of the application may be the user name of the application used by the user; the identifier of the application in the UE may be the code or identifier of the application.
  • the MME sends a second authorization request to the short-range server according to the first authorization request, where the second authorization request includes an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the second authorization request is used to enable the proximity server to search for the stored subscription information of the UE according to the identifier of the UE, whether there is an identifier corresponding to the application in the UE and a user identifier corresponding to the application.
  • Authorization information for close-range services includes an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the MME receives the proximity server according to the first 2.
  • the authorization sent by the authorization request passes the response message;
  • step 103 the proximity server determines the
  • the MME receives the response message of the denial of authorization sent by the short-range server according to the second authorization request, and the MME receives the authorization information corresponding to the identifier of the application and the application identifier of the application.
  • the MME sends a reject response message to the UE according to the acknowledgement message of the denial of authorization.
  • the method for authentication and authorization of the short-range service in this embodiment is, after the UE is authenticated by the proximity server, and the application on the UE uses the proximity server, the MME confirms the request to the proximity server.
  • the close-range Server sends a response message to the UE, so that the UE initiates an authentication request to the application server according to the response message, which solves the problem that the operator in the prior art cannot refine the application of the short-distance service in the UE.
  • the method for authenticating and authorizing the proximity service further includes the following steps: as shown in picture 2.
  • the MME receives a first registration request that is sent by the UE to register with a proximity server, where the first registration request includes: an identifier of the UE.
  • the first registration request is carried in the network attach message, or is carried in the location update message, or carried in the non-access stratum message, or carried in the access layer message.
  • the MME sends a second registration request to the proximity server according to the first registration request, where the second registration request includes: an identifier of the UE, where the second registration request is used to make the proximity server according to the location
  • the identifier of the UE determines whether there is authorization information of the UE that uses the proximity service corresponding to the identifier of the UE in the subscription information of the UE corresponding to the identifier of the UE.
  • the subscription information of the UE includes related authorization information of whether the UE can use the short-distance service.
  • the MME receives a registration pass response message sent by the proximity server, where the registration pass response message is included. : the first identifier of the short-range service that is allocated by the short-range server to the UE, and the second identifier of the proximity server.
  • the first identifier may be an International Mobile Subscriber Identification Number (IMSI), a Mobile Subscriber International ISDN/PSTN number (MSISDN), a broadcast code (ProSe Code), or a The other identifiers assigned by the proximity server to the UE.
  • IMSI International Mobile Subscriber Identification Number
  • MSISDN Mobile Subscriber International ISDN/PSTN number
  • ProSe Code broadcast code
  • the second identifier may be routing information of a close-range server, such as a uniform resource locator
  • URL Uniform I Universal Resource Locator
  • IP Internet Protocol
  • the first identifier and the second identifier described above may be in the form of:
  • the first identifier @second identifier such as the form of the device d2d id@proximityserver URL.
  • the MME sends a response message to the UE, where the response message includes: a first identifier and the second identifier.
  • step S03 determines, according to the identifier of the UE, that the UE corresponding to the identifier of the UE does not use the authorization information of the proximity service in the subscription information of the UE, Determining, by the MME, a response message sent by the proximity server to reject the transmission;
  • the method for authenticating and authorizing the proximity service further includes the following steps: As shown in Figure 3.
  • the MME receives a first registration request that is sent by the UE and is used to register with a proximity server, where the first registration request includes: an identifier of the UE.
  • the first registration request is carried in the network attach message, or is carried in the location update message, or carried in the non-access stratum message, or carried in the access layer message.
  • the MME obtains, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE to the Home Subscriber Server (HSS);
  • HSS Home Subscriber Server
  • the MME determines that the UE corresponding to the identifier of the UE uses the authorization information of the proximity service in the subscription information of the UE, the MME sends a third registration request to the proximity server, where the The three registration request includes: an identifier of the UE and subscription information of the UE;
  • the MME receives a registration pass response message sent by the proximity server according to the third registration request, where the registration pass response message includes: the short-distance server allocates the short-distance service to the UE. An identifier and a second identifier of the proximity server.
  • the MME sends a response message to the UE according to the registration response message, where the response message includes the first identifier and the second identifier.
  • the MME in step R03 is based on the identifier of the UE Determining, in the subscription information of the UE, that the UE corresponding to the identifier of the UE uses the authorization information of the short-distance service, the MME sends an unauthorized response message to the UE.
  • FIG. 4 is a schematic flowchart of a method for authentication and authorization of a short-range service according to an embodiment of the present invention. As shown in FIG. 4, the method for authentication and authorization of a short-range service in this embodiment is as follows.
  • the application server receives an authentication request sent by the UE, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a close-range used by the proximity server for the UE.
  • the first identifier and the second identifier can be in the form of an integral email.
  • the application server sends a first confirmation request to the proximity server according to the second identifier, where the first confirmation request includes: an identifier of the UE, an identifier applied by the UE, and the application.
  • the user identifier and the first identifier, the first confirmation request is used to enable the proximity server to determine, according to the identifier of the UE, whether the application has the application in the subscription information of the UE corresponding to the identifier of the UE.
  • the first confirmation request sent by the application server to the proximity server needs to carry the identifier of the application in the U E and the user identifier of the application.
  • the first confirmation request sent by the application server to the proximity server may not carry the identifier of the application in the UE and the user identifier of the application.
  • the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, the application server receives an acknowledgement response that is sent by the proximity server.
  • the application server sends an authentication pass message to the UE according to the acknowledgement response passed by the authorization, so that the UE causes the application to use the proximity service according to the authentication pass message.
  • the proximity server in step 403 is based on the UE And determining, by the application server, the proximity server that the identifier of the application, the user identifier of the application, and the authorization information of the UE corresponding to the first identifier are used in the subscription information. a rejected message sent;
  • the application server sends an authentication reject message to the UE according to the reject message.
  • the method for authenticating and authorizing the short-distance service in the embodiment can solve the problem that the operator cannot refine the application of using the proximity service in the UE in the prior art, and implements the proximity server pair.
  • FIG. 5 is a schematic flowchart of a method for authentication and authorization of a short-range service according to an embodiment of the present invention. As shown in FIG. 5, the method for authentication and authorization of a short-range service in this embodiment is as follows.
  • the proximity server After the proximity server authenticates the UE where the application is located, when the application on the UE starts to use the proximity service, the proximity server receives the second authorization request sent by the MME, where the second authorization request is the MME. After receiving the first authorization request sent by the UE, the second authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application.
  • the application on the UE starts to use the proximity service, specifically: each time after the application is launched, the process shown in FIG. 5 needs to be executed when starting to use the proximity server; It is only offline, but the application is not closed. When the application is back online, the application uses the proximity service and the process described in Figure 5 is no longer needed.
  • the proximity server searches, according to the identifier of the UE, whether the stored identity information of the UE and the authorization information of the user identifier of the application are included in the subscription information of the UE.
  • the subscription information of the UE stored in the short-range server may be that the proximity server can directly obtain device-related information, including the signed application and the user identifier, by establishing an interface with the HSS.
  • the proximity server sends an authorization response message to the MME. So that the MME sends a response message to the UE by using a response message according to the authorization.
  • step 503 if there is no application in the UE in the subscription information of the UE, The identifier and the user identifier of the application correspond to the authorization information of the proximity service, and the proximity server sends a response message rejecting the authorization to the MME, so that the MME sends the response message according to the rejection authorization.
  • the UE sends a reject response message.
  • the method for authenticating and authorizing the proximity service further includes the following steps, as shown in the following steps. 6 is shown.
  • the proximity server receives the second registration request sent by the MME, where the second registration request is sent by the MME after receiving the first registration request sent by the UE, where the second registration request includes: The identity of the UE.
  • the proximity server acquires, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE to the HSS.
  • the short-distance server determines, according to the identifier of the UE, that the subscription information is authorized by the UE to use the proximity service, and sends a registration response message to the MME, where the registration response message includes: Determining, by the proximity server, a first identifier of the short-range service and a second identifier of the short-range server allocated by the UE, to enable the MME to send, according to the registration, a response message, to the UE, including the first A pass response message of an identifier and the second identifier.
  • the short-range server determines, according to the identifier of the UE, that the UE does not have the authorization information of the proximity service of the UE corresponding to the identifier of the UE, And sending, by the MME, a response message that is rejected, so that the MME sends an unauthorized response message to the UE according to the response message that the rejection is passed.
  • the method for authenticating and authorizing the proximity service further includes the following steps, as shown in the following steps. 7 is shown.
  • the short-distance server receives the third registration request sent by the MME, where the third registration request includes: the identifier of the UE and the subscription information of the UE;
  • the third registration request is that the MME receives the first registration request sent by the UE, and acquires subscription information of the UE from the HSS according to the identifier of the UE in the first registration request, and determines that the subscription information is included in the subscription information.
  • the short-range server stores the subscription information of the UE, and sends a registration pass response message to the MME according to the third registration request, where the registration pass response message includes: the short-range server allocates the UE Using the first identifier of the proximity service and the second identifier of the proximity server to cause the MME to send a response message including the first identifier and the second identifier to the UE.
  • the MME determines that the UE corresponding to the identifier of the UE does not use the authorization information of the proximity service in the subscription information of the UE, the MME does not send the third registration request to the proximity server.
  • FIG. 8A is a schematic flowchart of a method for authentication and authorization of a short-distance service according to an embodiment of the present invention. As shown in FIG. 8A, a method for authentication and authorization of a short-range service in this embodiment is as follows.
  • the UE After the UE where the application is located is authenticated by the proximity server, and the application on the UE initiates the use of the proximity service, the UE sends a first authorization request to the MME, where the first authorization request includes: An identifier of the UE, an identifier of the application in the UE, and a user identifier of the application; the first authorization request is used to enable the MME to search for a stored subscription of the UE according to the identifier of the UE to a proximity server. In the information, whether there is an identifier of an application in the UE and authorization information of a user identifier of the application;
  • the UE receives the response message sent by the MME. Transmitting, by the response message, the MME after receiving the authorization request message sent by the proximity server;
  • the UE After receiving the response message, the UE sends an authentication request to the application server, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a proximity server. Determining, by the UE, a first identifier using the proximity service and a second identifier of the proximity server;
  • the UE receives an authentication pass message sent by the application server, where the authentication pass message is that the application server interacts with the proximity server according to the authentication request, and confirms that the application of the UE can use the proximity service.
  • Sent is that the application server interacts with the proximity server according to the authentication request, and confirms that the application of the UE can use the proximity service.
  • the UE causes the application to use the proximity service according to the authentication pass message.
  • the method for authenticating and authorizing the proximity service may further include a method not shown in the following figure. step.
  • the UE sends a first registration request for registering with a proximity server to the MME, where the first registration request includes: an identifier of the UE, so that the MME is configured according to the first registration request. Determining, to the proximity server, whether the UE has the authorization information of the proximity service in the subscription information of the UE.
  • the first registration request is carried in the network attach message, or is carried in the location update message, or carried in the non-access stratum message, or carried in the access layer message.
  • the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, the UE receives a response message sent by the MME, where the response message is received by the MME.
  • the registration sent by the proximity server is sent after the response message, and the response message includes: the first identifier used by the proximity server for the UE to use the proximity service and the proximity server The second logo is paid.
  • the network can not only authenticate and authorize the UE for short-distance service, but also authenticate and authorize the application of the short-distance service on the UE.
  • the method enables the network operator to not only provide users with close-range services based on the granularity of the UE, but also fine-grained application-based close-range services for users, which greatly enriches the management mode of the operators.
  • FIG. 8B is a schematic flowchart of a method for authentication and authorization of a short-range service according to an embodiment of the present invention. As shown in FIG. 8B, the method for authentication and authorization of a short-range service in this embodiment is as follows.
  • the UE sends a first registration request for registering with the MME to the MME, where the first registration request includes: an identifier of the UE.
  • the first registration request is carried in one of the following messages: a network attach message, a location update message, a non-access stratum message, an access stratum message, and the like.
  • the MME After receiving the first registration request, the MME sends a second registration request to the proximity server according to the first registration request, where the second registration request includes: an identifier of the UE, where the second registration request is used. And causing the short-range server to determine the location and the location according to the identifier of the UE Whether the UE corresponding to the identifier of the UE uses the authorization information of the short-distance service in the subscription information of the UE corresponding to the identifier of the UE.
  • the proximity server After receiving the second registration request, acquires, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE, to the HSS.
  • the proximity server stores the subscription information of the UE after acquiring the subscription information of the UE.
  • the proximity server can establish an interface with the HSS, and the proximity server can obtain the subscription information of the UE from the HSS.
  • the proximity server determines, according to the identifier of the UE, whether the UE has authorized information for using the proximity service by the UE, and if yes, performing step 815; otherwise, performing step 815.
  • the proximity server determines, according to the identifier of the UE, that the UE has authorized information for using the proximity service in the subscription information of the UE, and sends a registration response message to the MME, where the registration is
  • the message includes: a first identifier of the proximity service and a second identifier (such as a ProSe ID) of the short-range server allocated by the proximity server to the UE.
  • the first identifier can be a broadcast code, such as a ProSe Code.
  • the registration and response message may further include: routing information of the proximity server, and the like.
  • the routing information may be a server identifier of a proximity server such as, but not limited to, a URI, or an IP address or the like.
  • the proximity server determines, according to the identifier of the UE, that the UE does not have authorization information for the UE to use the proximity service, and sends a reject registration message to the MME, and the MME receives the rejection. After registering the message, a registration failure message is sent to the UE.
  • the MME After the MME receives the registration pass response message sent by the proximity server, the MME sends a response message to the UE according to the registration response message, where the response message includes: the first identifier and the second Identifier.
  • the response message can be carried in the non-access stratum message or carried in the access layer message.
  • the UE sends the first to the MME.
  • the authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application.
  • the application on the UE may be WeChat, or Weibo, and the like.
  • the user ID of the application may be information such as the account number of the user using the application.
  • the MME After receiving the first authorization request, the MME sends a second authorization request to the proximity server according to the first authorization request, where the second authorization request includes an identifier of the UE, and an identifier applied by the UE. a user identifier of the application; the second authorization request is used to enable the proximity server to search for the stored subscription information of the UE according to the identifier of the UE, whether the identifier of the application in the UE is The user ID of the application corresponds to the authorization information of the proximity service.
  • the proximity server After receiving the second authorization request, the proximity server, if it is determined that the subscription information of the UE obtained in step 813 has the identifier applied by the UE and the authorization information corresponding to the user identifier of the application, sends an authorization response to the MME. Message.
  • the MME After receiving the authorization-passing response message sent by the short-range server according to the second authorization request, the MME sends a response message to the UE according to the authorization, so that the UE responds according to the response.
  • the message initiates an authentication request to the application server.
  • the UE After receiving the response message sent by the MME, the UE sends an authentication request to the application server, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a proximity server. A first identifier for the UE that uses the proximity service and a second identifier for the proximity server.
  • the first identifier and the second identifier in the step are sent by the MME to the UE in step 816.
  • the authentication request at the location may further include routing information of the proximity server received by the UE, so that the application server establishes a connection with the proximity server according to the routing information of the proximity server.
  • the application server After receiving the authentication request, the application server sends a first confirmation request to the proximity server according to the second identifier, where the first confirmation request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application and the first identifier, where the first confirmation request is used to enable the proximity server to determine, according to the identifier of the UE, whether the subscription information of the UE corresponding to the identifier of the UE is included.
  • the identifier of the application, the user of the application And identifying, by the UE corresponding to the first identifier, authorization information of the proximity service.
  • the proximity server After receiving the first acknowledgment request sent by the application server, the proximity server determines, according to the identifier of the UE, the authorization information in the subscription information of the stored UE, and sends an acknowledgment response to the application server.
  • the application server After receiving the acknowledgement response sent by the proximity server, the application server
  • the UE After receiving the authentication pass message sent by the application server, the UE enables the application to use the proximity service according to the authentication pass message.
  • the network can not only authenticate and authorize the UE for short-distance service, but also authenticate and authorize the application of the short-distance service on the UE.
  • the method enables the network operator to not only provide users with close-range services based on the granularity of the UE, but also fine-grained application-based close-range services for users, which greatly enriches the management mode of the operators.
  • an embodiment of the present invention further provides a mobility management entity.
  • the mobility management entity in this embodiment includes: a receiving unit 91 and a sending unit 92;
  • the receiving unit 91 is configured to: after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, receive the first authorization request sent by the UE, where the first The authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the sending unit 92 is configured to send a second authorization request to the proximity server according to the first authorization request received by the receiving unit 91, where the second authorization request includes: an identifier of the UE, and an application in the UE And the user identifier of the application; the second authorization request is used to enable the proximity server to search for the stored subscription information of the UE according to the identifier of the UE, whether the identifier of the application in the UE is The user identifier of the application corresponds to the authorization information of using the proximity service;
  • the receiving unit 91 is configured to: after the sending unit 92 sends the second authorization request, determine, by the proximity server, the identifier of the UE and the user of the application in the subscription information of the UE. Identifying the corresponding authorization information, and receiving an authorization pass response message sent by the proximity server according to the second authorization request;
  • the sending unit 92 is configured to respond according to the authorization received by the receiving unit 91.
  • the message sends a response message to the UE, so that the UE initiates an authentication request to the application server according to the response message.
  • the receiving unit 91 is further configured to: before receiving the first authorization request, receive a first registration request sent by the UE to register with a proximity server, where The first registration request includes: an identifier of the UE;
  • the sending unit 92 is further configured to send a second registration request to the proximity server according to the first registration request received by the receiving unit 91, where the second registration request includes: an identifier of the UE, the second registration request And determining, by the proximity server, whether the UE corresponding to the identifier of the UE uses the authorization information of the short-distance service in the subscription information of the UE corresponding to the identifier of the UE according to the identifier of the UE;
  • the receiving unit 91 is further configured to: when the proximity server determines that the authorization information is included in the subscription information according to the identifier of the UE, receive a registration pass response message sent by the proximity server, where the registration is passed
  • the response message includes: a first identifier that is used by the proximity server to use the proximity service and a second identifier of the proximity server that is allocated to the UE;
  • the sending unit 92 is further configured to send a response message to the UE according to the registration and response message received by the receiving unit 91, where the response message includes: the first identifier and the second identifier. symbol.
  • the receiving unit 91 is further configured to: before receiving the first authorization request, receive a first registration request sent by the UE for registering with a proximity server, where The first registration request includes: an identifier of the UE;
  • the first registration request is carried in the network attach message, or is carried in the location update message, or carried in the non-access stratum message, or carried in the access layer message.
  • the mobility management entity further includes an obtaining unit 93 and a determining unit 94 not shown in the figure;
  • the obtaining unit 93 is configured to: after the receiving unit 91 receives the first registration request, acquire, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE, according to the identifier of the UE;
  • the determining unit 94 is configured to determine whether the subscription information of the UE acquired by the acquiring unit 93 is The UE corresponding to the identifier of the UE uses the authorization information of the proximity service;
  • the sending unit 92 is further configured to: after the determining unit 94 determines that the UE corresponding to the identifier of the UE uses the authorization information of the proximity service, the third registration is sent to the proximity server.
  • the request, the third registration request includes: an identifier of the UE and subscription information of the UE;
  • the receiving unit 91 is configured to receive, after the sending unit 92 sends the third registration request, a registration pass response message sent by the proximity server according to the third registration request, where the registration pass response message includes: a first identifier of the proximity service and a second identifier of the proximity server allocated by the proximity server to the UE;
  • the sending unit 92 is configured to send a pass response message to the UE according to the registration pass response message received by the receiving unit 91, where the pass response message includes the first identifier and the second identifier.
  • the receiving unit 91 is further configured to: when the proximity server determines that the subscription information of the UE does not have the authorization information, receive the proximity server to send according to the second authorization request. A reply message rejecting the authorization;
  • the sending unit 92 is further configured to send a reject response message to the UE according to the acknowledgement message of the denial of authorization received by the receiving unit 91.
  • the mobility management entity implements the interaction between the UE and the proximity server by forwarding the message of the UE to the proximity server, or forwarding the message of the proximity server to the UE, so that the proximity server can use the short-distance service on the UE.
  • the application is controlled separately.
  • an embodiment of the present invention further provides an application server.
  • the application server in this embodiment includes: a receiving unit 1001 and a sending unit 1002.
  • the receiving unit 1001 is configured to receive The authentication request sent by the UE, the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a first identifier used by the proximity server to use the proximity service for the UE And a second identifier of the proximity server;
  • the sending unit 1002 is configured to send a first confirmation request to the proximity server according to the second identifier, after the receiving unit 1001 receives the authentication request, where the first confirmation request includes: an identifier, a location of the UE Determining an identifier of the application in the UE, a user identifier of the application, and the first identifier, where the first confirmation request is used to enable the proximity server according to the Determining, by the identifier of the UE, whether the identifier of the application, the user identifier of the application, and the authorization information of the UE corresponding to the first identifier using the proximity service are included in the subscription information of the UE corresponding to the identifier of the UE;
  • the receiving unit 1001 is further configured to: after the sending unit 1002 sends the first confirmation request, and when the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, receive The acknowledgment response sent by the proximity server; the sending unit 1002 is further configured to: after the receiving unit 1001 receives the acknowledgment response of the authorization, send the authentication to the UE according to the acknowledgment response passed by the authorization a message, wherein the UE causes the application to use the proximity service according to the authentication pass message.
  • the receiving unit 1001 is further configured to: after the sending unit 1002 sends the first confirmation request, and where the proximity server determines, according to the identifier of the UE, that the subscription information is not Receiving the rejection message sent by the proximity server when authorizing the information;
  • the sending unit 1002 is further configured to: after the receiving unit 1001 receives the reject message, send an authentication reject message to the UE according to the reject message.
  • the above application server interacts with the proximity server to achieve the purpose of separately controlling the application of the proximity service on a device by using the proximity server.
  • an embodiment of the present invention further provides a proximity server.
  • the proximity server in this embodiment includes: a receiving unit 1101, a searching unit 1102, and a sending unit 1103;
  • the receiving unit 1101 is configured to: after the proximity server selects the UE where the application is located, when the application on the UE starts to use the proximity service, the second authorization request sent by the MME is received, where the second authorization request is the And after the MME receives the first authorization request sent by the UE, and the second authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the searching unit 1102 is configured to: after the receiving unit 1101 receives the second authorization request, search for the stored identifier information of the UE according to the identifier of the UE, whether the identifier of the application in the UE and the application are User identification corresponding to the authorization information using the proximity service;
  • the sending unit 1103 is configured to search for the subscription information of the UE in the searching unit 1102. Sending an authorization pass response message to the MME, where the MME sends an authorization pass response message corresponding to the identifier of the application in the UE and the application identifier of the application, so that the MME sends a response message according to the authorization.
  • the UE sends a pass response message.
  • the sending unit 1103 is further configured to: in the subscription information that the searching unit 1102 does not find the UE, the identifier that is applied by the UE and the user identifier that is used by the application are used in a short-distance service.
  • the authorization information is sent to the MME, and the MME rejects the response message of the second authorization request, so that the MME sends a reject response message to the UE according to the acknowledgement request message.
  • the receiving unit 1101 is further configured to: before receiving the second authorization request, further receive a second registration request sent by the MME, where the second registration request is that the MME is at the receiving station.
  • the second registration request includes: an identifier of the UE;
  • the proximity server further includes an obtaining unit 1104 and a determining unit 1105 not shown in the figure;
  • the obtaining unit 1104 is configured to: after the receiving unit 1101 receives the second registration request, acquire, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE according to the identifier of the UE;
  • the determining unit 1105 is configured to: after the acquiring unit 1104 acquires the subscription information of the UE, determine, according to the identifier of the UE, that the subscription information is authorized by the UE to use the proximity service;
  • the sending unit 1103 is further configured to: when the determining unit 1105 determines that the authorization information is available, send a registration pass response message to the MME, where the registration pass response message includes: the short-range server allocates the UE Using the first identifier of the proximity service and the second identifier of the proximity server to cause the MME to send a response message including the first identifier and the second identifier to the UE .
  • the receiving unit 1101 is further configured to: before receiving the second authorization request, receive a third registration request sent by the MME, where the third registration request includes: The identifier of the UE and the subscription information of the UE; the third registration request is that the MME receives the first registration request sent by the UE, and acquires the UE from the HSS according to the identifier of the UE in the first registration request. Signing information and determining that the signing information is The UE corresponding to the identifier of the UE is sent after using the authorization information of the proximity service; correspondingly, the proximity server further includes a storage unit 1106 not shown in the figure;
  • the storage unit 1106 is configured to store the subscription information of the UE after the receiving unit 1101 receives the third registration request.
  • the sending unit 1103 is configured to send a registration pass response message to the MME according to the third registration request after the storage unit 1106 stores the subscription information of the UE, where the registration pass response message includes: the proximity server a first identifier for the UE that uses the proximity service and a second identifier of the proximity server to cause the MME to send the first identifier and the second identifier to the UE Pass the response message.
  • the above-mentioned close-range server achieves the purpose of refining and managing applications using close-range services on a certain device.
  • an embodiment of the present invention further provides a user equipment.
  • the user equipment in this embodiment includes: a sending unit 1201, a receiving unit 1202, and a using unit 1203;
  • the sending unit 1201 is configured to send a first authorization request to the MME after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, where the first authorization request includes The identifier of the UE, the identifier of the application in the UE, and the user identifier of the application, where the first authorization request is used to enable the MME to search for the stored UE according to the identifier of the UE to a proximity server. Whether the identification information of the application in the UE and the authorization information of the user identifier of the application are included in the subscription information;
  • the receiving unit 1202 is configured to: after the sending unit 1201 sends the first authorization request, and in the contract information that the proximity server determines that the UE has an identifier applied in the UE and a user identifier of the application. Receiving, by the MME, a response message sent by the MME, where the response message is sent by the MME after receiving the authorization response message sent by the proximity server;
  • the sending unit 1201 is further configured to: after the receiving unit 1202 receives the pass response message, initiate an authentication request to the application server, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, a first identifier of the proximity server using the proximity service and a second identifier of the proximity server allocated by the proximity server;
  • the receiving unit 1202 is further configured to: after the sending unit 1201 sends the authentication request, receive an authentication pass message sent by the application server, where the authentication pass message is the application server according to the authentication request and the Proximity server interaction, and confirming that the application of the UE can be sent after using the proximity service;
  • the application is caused to use the proximity service.
  • the sending unit 1201 is further configured to send, to the MME, a first registration request for registering with a proximity server, before the sending the first authorization request, the first registration
  • the request includes: the identifier of the UE, to enable the MME to determine, according to the first registration request, whether the UE has the authorization information of the proximity service in the subscription information of the UE to the proximity server;
  • the receiving unit 1202 is further configured to: after the sending unit 1201 sends the first registration request, and after the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, The UE receives the response message sent by the MME, and the response message is sent by the MME after receiving the registration response message sent by the proximity server, where the response message includes: The UE assigns a first identifier using the proximity service and a second identifier of the proximity server.
  • the foregoing first registration request may be carried in the network attachment message, or may be carried in the location update message, or may be carried in the non-access stratum message, or may be carried in the access layer message.
  • the foregoing user equipment implements the detailed management of the application of the short-distance service in the user equipment by the operator, and improves the experience of the user using the user equipment.
  • each functional unit is merely an example. In actual applications, the above may be considered according to requirements, such as configuration requirements of corresponding hardware or convenience of implementation of software.
  • the function assignment is performed by different functional units, that is, the internal structure of the user equipment is divided into different functional units to perform all or part of the functions described above.
  • the corresponding functional units in this embodiment may be implemented by corresponding hardware, or may be executed by corresponding hardware to execute corresponding software.
  • the foregoing use unit may be capable of executing a corresponding computer program to complete.
  • the foregoing receiving unit may be hardware having a function of executing the foregoing receiving unit, such as a receiver, or a general processor or other hardware device capable of executing a corresponding computer program to perform the foregoing functions.
  • a receiver or a general processor or other hardware device capable of executing a corresponding computer program to perform the foregoing functions.
  • an embodiment of the present invention further provides a mobility management entity.
  • the mobility management entity includes: a receiver 1301 and a transmitter 1302.
  • the receiver 1301 is configured to: after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, receive the first authorization request sent by the UE, where the first The authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the transmitter 1302 is configured to send a second authorization request to the proximity server according to the first authorization request received by the receiver 1301, where the second authorization request includes: an identifier of the UE, and an application in the UE And the user identifier of the application; the second authorization request is used to enable the proximity server to search for the stored subscription information of the UE according to the identifier of the UE, whether the identifier of the application in the UE is The user identifier of the application corresponds to the authorization information of using the proximity service;
  • the receiver 1301 is configured to, after the transmitter 1302 sends the second authorization request, determine, in the subscription information of the UE, the identifier of the application in the UE and the user of the application, in the proximity server Identifying the corresponding authorization information, and receiving an authorization pass response message sent by the proximity server according to the second authorization request;
  • the transmitter 1302 is configured to send a pass response message to the UE according to the authorization received by the receiver 1301 by using a response message, so that the UE initiates an authentication request to the application server according to the pass response message.
  • the receiver 1301 is further configured to: before receiving the first authorization request, receive a first registration request sent by the UE to register with a proximity server, where the first registration is The request includes: an identifier of the UE;
  • the transmitter 1302 is further configured to send a second registration request to the proximity server according to the first registration request received by the receiver 1301, where the second registration request includes: the identifier of the UE, the second registration request And determining, by the proximity server, whether the subscription information of the UE corresponding to the identifier of the UE corresponds to the identifier of the UE according to the identifier of the UE.
  • the UE uses the authorization information of the proximity service;
  • the receiver 1301 is further configured to: when the proximity server determines that the authorization information is included in the subscription information according to the identifier of the UE, receive a registration pass response message sent by the proximity server, where the registration is passed
  • the response message includes: a first identifier that is used by the proximity server to use the proximity service and a second identifier of the proximity server that is allocated to the UE;
  • the transmitter 1302 is further configured to send a response message to the UE according to the registration and response message received by the receiver 1301, where the response message includes: the first identifier and the second identifier symbol.
  • the receiver 1301 is further configured to: before receiving the first authorization request, receive a first registration request sent by the UE to register with a proximity server, where the first The registration request includes: an identifier of the UE;
  • the first registration request is carried in the network attach message, or is carried in the location update message, or carried in the non-access stratum message, or carried in the access layer message.
  • the mobility management entity further includes a processor 1303 not shown in the figure;
  • the processor 1303 is configured to: after the receiver 1301 receives the first registration request, acquire, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE, and determine the UE Whether the UE corresponding to the identifier of the UE uses the authorization information of the proximity service in the subscription information;
  • the transmitter 1302 is further configured to: after the processor 1303 determines that the UE corresponding to the identifier of the UE uses the authorization information of the proximity service, the third registration is sent to the proximity server.
  • the request, the third registration request includes: an identifier of the UE and subscription information of the UE;
  • the receiver 1301 is configured to receive, after the transmitter 1302 sends the third registration request, a registration pass response message sent by the proximity server according to the third registration request, where the registration pass response message includes:
  • the short-range server allocates a first identifier of the short-range service and a second identifier of the short-range server allocated to the UE;
  • the transmitter 1302 is configured to receive according to the receiver 1301 Transmitting, by using a response message, a response message to the UE, where the response message includes the first identifier And the second identifier.
  • the receiver 1301 is further configured to: when the proximity server determines that the subscription information of the UE does not have the authorization information, receive the proximity server according to the second authorization request. A reply message sent by the rejected authorization;
  • the transmitter 1302 is further configured to send a reject response message to the UE according to the reject authorization response message received by the receiver 1301.
  • the mobility management entity implements the interaction between the UE and the proximity server by forwarding the message of the UE to the proximity server, or forwarding the message of the proximity server to the UE, so that the proximity server can use the short-distance service on the UE.
  • the application is controlled separately.
  • an embodiment of the present invention further provides an application server, as shown in the figure.
  • the application server includes: a receiver 1401 and a transmitter 1402;
  • the receiver 1401 is configured to receive an authentication request sent by the UE, where the authentication request includes: an identifier of the UE, an identifier applied by the UE, a user identifier of the application, and a short-range server allocated to the UE. Using a first identifier of the proximity service and a second identifier of the proximity server;
  • the transmitter 1402 is configured to send, after the receiver 1401 receives the authentication request, a first confirmation request to the proximity server according to the second identifier, where the first confirmation request includes: an identifier, a location of the UE An identifier of the application, the user identifier of the application, and the first identifier, where the first confirmation request is used to determine, by the proximity server, the identifier corresponding to the identifier of the UE according to the identifier of the UE. Whether the identifier of the application, the user identifier of the application, and the authorization information of the UE corresponding to the first identifier using the proximity service are included in the subscription information of the UE;
  • the receiver 1401 is further configured to: after the transmitter 1402 sends the first confirmation request, and when the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, receive An acknowledgement response sent by the proximity server;
  • the transmitter 1402 is further configured to: after the receiver 1401 receives the acknowledgement response of the authorization, send an authentication pass message to the UE according to the acknowledgement response of the authorization, so that the UE passes the message according to the authentication.
  • the application is caused to use the proximity service.
  • the receiver 1401 is further configured to: after the transmitter 1402 sends the first confirmation request, and determine, in the subscription information, the proximity server according to the identifier of the UE. Receiving the rejection message sent by the proximity server when the authorization information is not available; the transmitter 1402 is further configured to send the authentication to the UE according to the rejection message after the receiver 1401 receives the rejection message Reject the message.
  • the above application server interacts with the proximity server to achieve the purpose of separately controlling the application of the proximity service on a device by using the proximity server.
  • an embodiment of the present invention further provides a proximity server.
  • the proximity server includes: a receiver 1501, a processor 1502, and a transmitter 1503.
  • the receiver 1501 is configured to: Receiving, by the proximity server, the second authorization request sent by the MME, when the application on the UE starts to use the short-range service, where the second authorization request is sent by the MME to the MME.
  • the second authorization request is sent after the first authorization request, and the second authorization request includes: an identifier of the UE, an identifier applied by the UE, and a user identifier of the application;
  • the processor 1502 is configured to: after the receiver 1501 receives the second authorization request, search for the stored identifier information of the UE according to the identifier of the UE, whether the identifier of the application in the UE and the application are The user identifier corresponding to the authorization information of the proximity service is used by the transmitter 1503, and the identifier of the application in the UE and the user identifier of the application corresponding to the identifier information of the UE in the processor 1502. And using the authorization information of the short-range service, sending an authorization-passing response message to the MME, so that the MME sends a response-message message to the UE by using a response message according to the authorization.
  • the receiver 1501 is further configured to: before receiving the second authorization request, further receive a second registration request sent by the MME, where the second registration request is the MME After receiving the first registration request sent by the UE, the second registration request includes: an identifier of the UE;
  • the processor 1502 is configured to acquire the subscription information of the UE corresponding to the identifier of the UE, and determine, according to the identifier of the UE, the subscription information of the UE corresponding to the identifier of the UE, according to the identifier of the UE, after the receiver 1501 receives the second registration request.
  • the subscription information includes authorization information that the UE authorizes to use the proximity service;
  • the transmitter 1503 is further configured to: when the processor 1502 determines that the authorization information is available, send a registration pass response message to the MME, where the registration pass response message includes: the proximity server allocates the UE Using the first identifier of the proximity service and the a second identifier of the proximity server to cause the MME to send a pass response message including the first identifier and the second identifier to the UE.
  • the receiver 1501 is further configured to: before receiving the second authorization request, receive a third registration request sent by the MME, where the third registration request includes: The identifier of the UE and the subscription information of the UE; the third registration request is that the MME receives the first registration request sent by the UE, and acquires the UE from the HSS according to the identifier of the UE in the first registration request. Signing the information, and determining that the subscription information is sent by the UE corresponding to the identifier of the UE after using the authorization information of the proximity service;
  • the processor 1502 is configured to store subscription information of the UE after the receiver 1501 receives the third registration request.
  • the transmitter 1503 is configured to send a registration pass response message to the MME according to the third registration request after the processor 1502 stores the subscription information of the UE, where the registration pass response message includes: the near a first identifier of the short-range service and a second identifier of the short-range server allocated by the server for the UE, so that the MME sends the first identifier and the first The second identifier passes the response message.
  • the foregoing transmitter 1503 is further configured to: in the subscription information that the processor 1502 does not find the UE, the identifier of the application in the UE and the user identifier of the application are corresponding to the subscription information of the UE. And using the authorization information of the short-distance service, sending a response message of the second authorization request to the MME, so that the MME sends a reject response message to the UE according to the acknowledgement request message.
  • the above-mentioned short-distance server realizes the purpose of fine-grained management of the application of the short-distance service on a certain device, and at the same time realizes the purpose of the operator's application habit management of using the close-range service on a certain device, so that the operator can give the user Provide more flexible services.
  • an embodiment of the present invention further provides a user equipment.
  • the user equipment in this embodiment includes: a transmitter 1601, a receiver 1602, and a processor 1603.
  • the transmitter 1601 is configured to send a first authorization request to the MME after the UE where the application is located is authenticated by the proximity server, and when the application on the UE starts to use the proximity service, where the first authorization request includes The identifier of the UE, the identifier of the application in the UE, and the user identifier of the application, where the first authorization request is used to make the MME close to the UE
  • the server searches for the stored subscription information of the UE according to the identifier of the UE, whether there is an identifier of the application in the UE and authorization information of the user identifier of the application;
  • the receiver 1602 is configured to: after the transmitter 1601 sends the first authorization request, and in the contract information that the proximity server determines the UE, have an identifier applied in the UE and a user identifier of the application. Receiving, by the MME, a response message sent by the MME, where the response message is sent by the MME after receiving the authorization response message sent by the proximity server;
  • the transmitter 1601 is further configured to: after the receiver 1602 receives the pass response message, initiate an authentication request to the application server, where the authentication request includes: an identifier of the UE, an identifier of the application in the UE, a user identifier of the application, a first identifier of the short-range service allocated by the proximity server for the UE, and a second identifier of the proximity server; the receiver 1602 is further configured to be at the transmitter 1601 After the sending the authentication request, receiving an authentication pass message sent by the application server, the authentication pass message is that the application server interacts with the proximity server according to the authentication request, and confirms that the application of the UE can be used. Sent after a close service;
  • the processor 1603 causes the application to use the proximity service based on the authentication pass message received by the receiver 1602.
  • the transmitter 1601 is further configured to send, to the MME, a first registration request for registering with a proximity server, before the sending the first authorization request, the first registration request. And including: the identifier of the UE, to enable the MME to determine, according to the first registration request, whether the UE has the authorization information of the proximity service in the subscription information of the UE to the proximity server;
  • the receiver 1602 is further configured to: after the transmitter 1601 sends the first registration request, and after the proximity server determines, according to the identifier of the UE, that the subscription information has the authorization information, The UE receives the response message sent by the MME, and the response message is sent by the MME after receiving the registration response message sent by the proximity server, where the response message includes: The UE assigns a first identifier using the proximity service and a second identifier of the proximity server.
  • the first registration request is carried in the network attach message, or is carried in the location update message, or carried in the non-access stratum message, or carried in the access layer Interest.
  • the foregoing user equipment implements the detailed management of the application of the short-distance service in the user equipment by the operator, and improves the experience of the user using the user equipment.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本发明提供一种近距离服务的认证与授权的方法及设备,所述包括:UE通过近距离服务器的认证之后,MME接收UE发送的第一授权请求,向近距离服务器发送第二授权请求,第二授权请求用于使近距离服务器根据UE的标识查找存储的UE的签约信息中是否有UE中应用的标识和应用的用户标识的授权信息;若近距离服务器确定UE的签约信息中有所述授权信息,则MME接收近距离服务器根据第二授权请求发送的授权通过应答消息;MME根据授权通过应答消息向UE发送通过应答消息,以使UE根据通过应答消息向应用服务器发起认证请求。上述方法解决了现有技术中运营商无法细化管理UE中使用近距离服务的应用的问题。

Description

近距离服务的认证与授权的方法及设备 技术领域 本发明实施例涉及通信技术, 尤其涉及一种近距离服务的认证与授权 的方法及设备。 背景技术
随着社交类应用的广泛应用, 近距离服务( Proximity Service )越来越 重要。 为了实现网络对近距离服务的控制, 如用户设备( User Equipment, 简称 UE ) 近距离发现和近距离通信, 要求支持近距离服务功能的 UE在 使用近距离服务之前首先注册到网络中。 只有当该 UE获得网络对该 UE 使用近距离服务的成功认证与授权后, 该 UE上的应用才可以使用近距离 服务, 如社交应用、 广告应用等等。
例如, 用户希望能够及时了解好友在周围出现或者离开。 基于近距离 服务提供的发现功能, 社交应用能够使人们的生活和工作变的更加方便。 再如, 当用户到达办公室以后, 通过近距离发现功能, 能够在社交应用上 马上了解到哪些同事也经达到办公室。
当前, 网络设备只能够对 UE进行近距离服务的认证与授权, 即网络 设备只认证该 UE是否已经从运营商购买并签约了近距离服务。如果该 UE 已经签约了近距离服务, 则允许该 UE使用近距离服务, 否则拒绝该 UE 使用近距离服务。
上述方法中网络设备只对 UE是否能够使用近距离服务进行认证与授 权, 并不支持网络设备对使用近距离服务的应用进行认证与授权。 由此, 导致网络设备无法对使用近距离服务的各个应用进行控制, 使得运营商无 法细化管理 UE中使用近距离服务的应用。 发明内容
有鉴于此, 本发明实施例提供一种近距离服务的认证与授权的方法及设 备, 用以解决现有技术中运营商无法细化管理 UE中使用近距离服务的应 用的问题。
第一方面, 提供了一种近距离服务的认证与授权的方法, 包括: 在应用所在的 UE通过近距离服务器的认证之后, 且在所述 UE上的 应用启动使用近距离服务时, MME接收所述 UE发送的第一授权请求, 所述第一授权请求包括: 所述 UE的标识, 所述 UE中应用的标识, 所述 应用的用户标识;
所述 MME根据所述第一授权请求向所述近距离服务器发送第二授权 请求, 所述第二授权请求包括所述 UE的标识、 所述 UE中应用的标识, 所述应用的用户标识; 所述第二授权请求用于使所述近距离服务器根据所 述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用 的标识和所述应用的用户标识对应的使用近距离服务的授权信息;
若所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用 的标识和所述应用的用户标识对应的授权信息, 则所述 MME接收所述近 距离服务器根据所述第二授权请求发送的授权通过应答消息;
所述 MME根据所述授权通过应答消息向所述 UE发送通过应答消息 , 以使所述 UE根据所述通过应答消息向应用服务器发起认证请求。
结合第一方面,在第一种可能的实现方式中,所述 MME接收所述 UE 发送的第一授权请求的步骤之前, 还包括:
所述 MME接收所述 UE发送的用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述 MME根据所述第一注册请求向近距离服务器发送第二注册请 求, 所述第二注册请求包括: 所述 UE的标识, 所述第二注册请求用于使 所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE 的签约信息中是否有与所述 UE的标识对应的 UE使用近距离服务的授权 信息;
若所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 授权信息,则所述 MME接收所述近距离服务器发送的注册通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所 述近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述 MME根据所述注册通过响应消息向所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一标识符和所述第二标识符。
结合第一方面,在第二种可能的实现方式中,所述 MME接收所述 UE 发送的第一授权请求的步骤之前, 还包括:
所述 MME接收所述 UE发送的用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述 MME根据所述 UE的标识 , 向 HSS获取与所述 UE的标识对应 的 UE的签约信息;
若所述 MME确定所述 UE的签约信息中有所述 UE的标识对应的 UE 使用近距离服务的授权信息; 则所述 MME向所述近距离服务器发送第三 注册请求, 所述第三注册请求包括: 所述 UE的标识和所述 UE的签约信 息;
所述 MME接收所述近距离服务器根据所述第三注册请求发送的注册 通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述近距离服务器的第二 标识符;
所述 MME根据所述注册通过响应消息向所述 UE发送通过响应消息 , 所述通过响应消息包括所述第一标识符和所述第二标识符。
结合第一方面, 在第三种可能的实现方式中, 所述方法还包括: 若所述近距离服务器确定所述 UE的签约信息中无所述授权信息, 则 所述 MME接收所述近距离服务器根据所述第二授权请求发送的拒绝授权 的应答消息;
所述 MME根据所述拒绝授权的应答消息向所述 UE发送拒绝应答消 息。
结合第一方面及第一种、 第二种可能的实现方式中, 在第四种可能的 实现方式中, 所述第一注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
第二方面, 提供了一种近距离服务的认证与授权的方法, 包括: 应用服务器接收 UE发送的认证请求, 所述认证请求包括: 所述 UE 的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务器为 所述 UE分配的使用近距离服务的第一标识符和所述近距离服务器的第二 标识符;
所述应用服务器根据所述第二标识符向所述近距离服务器发送第一 确认请求, 所述第一确认请求包括: 所述 UE的标识、 所述 UE中应用的 标识、 所述应用的用户标识和所述第一标识符, 所述第一确认请求用于使 所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE 的签约信息中是否有所述应用的标识、 所述应用的用户标识和所述第一标 识符对应的 UE使用近距离服务的授权信息;
若所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 授权信息, 所述应用服务器接收所述近距离服务器发送的授权通过的确认 应答;
所述应用服务器根据所述授权通过的确认应答向所述 UE发送认证通 过消息, 以使所述 UE根据所述认证通过消息使所述应用使用所述近距离 服务。
结合第二方面, 在第一种可能的实现方式中, 所述方法还包括: 若所述近距离服务器根据所述 UE的标识确定所述签约信息中无所述 授权信息, 则所述应用服务器接收所述近距离服务器发送的拒绝消息, 所 述应用服务器根据所述拒绝消息向所述 UE发送认证拒绝消息。
第三方面, 提供了一种近距离服务的认证与授权的方法, 包括: 近距离服务器对应用所在的 UE认证之后, 所述 UE上的应用启动使 用近距离服务时, 所述近距离服务器接收 MME发送的第二授权请求, 所 述第二授权请求为所述 MME接收所述 UE发送的第一授权请求之后发送 的, 且所述第二授权请求包括: 所述 UE的标识, 所述 UE中应用的标识, 所述应用的用户标识;
所述近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信 息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近 距离服务的授权信息;
若所述 UE的签约信息中有所述 UE中应用的标识和所述应用的用户 标识对应的使用近距离服务的授权信息, 则所述近距离服务器向所述 MME发送授权通过应答消息, 以使所述 MME根据所述授权通过应答消 息向所述 UE发送通过应答消息。 结合第三方面, 在第一种可能的实现方式中, 所述近距离服务器接收
MME发送的第二授权请求的步骤之前, 还包括:
所述近距离服务器接收所述 MME发送的第二注册请求, 所述第二注 册请求为所述 MME在接收所述 UE发送的第一注册请求之后发送的, 所 述第二注册请求包括: 所述 UE的标识;
所述近距离服务器根据所述 UE的标识向 HSS获取所述 UE的标识对 应的 UE的签约信息;
所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 UE授权使用近距离服务的授权信息; 则向所述 MME发送注册通过响应 消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的 使用所述近距离服务的第一标识符和所述近距离服务器的第二标识符, 以 使所述 MME向 UE发送包括所述第一标识符和所述第二标识符的通过响 应消息。
结合第三方面, 在第二种可能的实现方式中, 所述近距离服务器接收 MME发送的第二授权请求的步骤之前, 还包括:
所述近距离服务器接收所述 MME发送的第三注册请求, 所述第三注 册请求包括: 所述 UE的标识和所述 UE的签约信息;
所述第三注册请求为所述 MME在接收所述 UE发送的第一注册请求 , 且根据所述第一注册请求中 UE的标识向 HSS获取 UE的签约信息, 并确 定所述签约信息中有所述 UE的标识对应的 UE使用近距离服务的授权信 息之后发送的;
所述近距离服务器存储所述 UE的签约信息, 并根据所述第三注册请 求向所述 MME发送注册通过响应消息, 所述注册通过响应消息包括: 所 述近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所 述近距离服务器的第二标识符, 以使所述 MME向 UE发送包括所述第一 标识符和第二标识符的通过响应消息。
结合第三方面, 在第三种可能的实现方式中, 所述方法还包括: 若所述近距离服务器确定所述 UE的签约信息中无所述 UE中应用的 标识和所述应用的用户标识对应使用近距离服务的授权信息, 则向所述 MME发送所述第二授权请求的拒绝授权的应答消息, 以使所述 MME根 据所述拒绝授权的应答消息向所述 UE发送拒绝应答消息。
第四方面, 提供了一种近距离服务的认证与授权的方法, 包括: 在应用所在的 UE通过近距离服务器的认证之后, 且在所述 UE上的 应用启动使用近距离服务时, 所述 UE向 MME发送第一授权请求, 所述 第一授权请求包括: 所述 UE的标识, 所述 UE中应用的标识和所述应用 的用户标识; 所述第一授权请求用于使所述 MME向近距离服务器根据所 述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用 的标识和所述应用的用户标识的授权信息;
若所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用 的标识和所述应用的用户标识的授权信息, 则所述 UE接收所述 MME发 送的通过应答消息, 所述通过应答消息为所述 MME接收所述近距离服务 器发送授权通过应答消息之后发送的;
所述 UE在接收所述应答消息之后, 向应用服务器发起认证请求, 所 述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的 用户标识、 近距离服务器为所述 UE分配的使用近距离服务的第一标识符 和所述近距离服务器的第二标识符;
所述 UE接收所述应用服务器发送的认证通过消息, 所述认证通过消 息为所述应用服务器根据所述认证请求和所述近距离服务器交互, 并确认 所述 UE的应用能够使用近距离服务之后发送的;
所述 UE根据所述认证通过消息使所述应用使用所述近距离服务。 结合第四方面, 在第一种可能的实现方式中, 所述 UE向 MME发送 第一授权请求的步骤之前, 还包括:
所述 UE向所述 MME发送用于向近距离服务器进行注册的第一注册 请求, 所述第一注册请求包括: 所述 UE的标识; 以使所述 MME根据所 述第一注册请求向近距离服务器确定所述 UE的签约信息中是否有所述 UE使用近距离服务的授权信息;
若所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 授权信息, 则所述 UE接收所述 MME发送的通过响应消息, 所述通过响 应消息为所述 MME接收所述近距离服务器发送的注册通过响应消息之后 发送的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分配的使 用所述近距离服务的第一标识符和所述近距离服务器的第二标识符。
结合第四方面及第一种可能的实现方式, 在第二种可能的实现方式 中, 所述第一注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
第五方面, 提供了一种移动性管理实体, 包括:
接收单元, 用于在应用所在的 UE通过近距离服务器的认证之后, 且 在所述 UE上的应用启动使用近距离服务时, 接收所述 UE发送的第一授 权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应用的标 识和所述应用的用户标识;
发送单元, 用于根据所述接收单元所接收的第一授权请求向所述近距 离服务器发送第二授权请求, 所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述应用的用户标识; 所述第二授权请求用于使 所述近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服 务的授权信息;
所述接收单元, 用于在所述发送单元发送所述第二授权请求之后, 在 所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识 和所述应用的用户标识对应的授权信息, 则接收所述近距离服务器根据所 述第二授权请求发送的授权通过应答消息;
所述发送单元, 用于根据所述接收单元接收的所述授权通过应答消息 向所述 UE发送通过应答消息, 以使所述 UE根据所述通过应答消息向应 用服务器发起认证请求。
结合第五方面, 在第一种可能的实现方式中, 所述接收单元, 还用于 在接收所述第一授权请求之前, 接收所述 UE发送的用于向近距离服务器 进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识; 所述发送单元, 还用于根据所述接收单元接收的第一注册请求向近距 离服务器发送第二注册请求, 所述第二注册请求包括: 所述 UE的标识, 所述第二注册请求用于使所述近距离服务器根据所述 UE的标识确定与所 述 UE的标识对应的 UE的签约信息中是否有与所述 UE的标识对应的 UE 使用近距离服务的授权信息; 所述接收单元, 还用于在所述近距离服务器根据所述 UE的标识确定 所述签约信息中有所述授权信息时, 接收所述近距离服务器发送的注册通 过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE 分配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标 识符;
所述发送单元, 还用于根据所述接收单元接收的所述注册通过响应消 息向所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一标识 符和所述第二标识符。
结合第五方面, 在第二种可能的实现方式中, 所述接收单元, 还用于 在接收所述第一授权请求之前, 接收所述 UE发送的用于向近距离服务器 进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识; 所述移动性管理实体还包括:
获取单元, 用于在所述接收单元接收所述第一注册请求之后, 根据所 述 UE的标识向 HSS获取与所述 UE的标识对应的 UE的签约信息;
确定单元, 用于确定所述 UE的签约信息中是否有所述 UE的标识对 应的 UE使用近距离服务的授权信息;
所述发送单元, 还用于在所述确定单元确定所述 UE的签约信息中有 所述 UE的标识对应的 UE使用近距离服务的授权信息之后, 向所述近距 离服务器发送第三注册请求, 所述第三注册请求包括: : 所述 UE的标识 和所述 UE的签约信息;
所述接收单元, 用于在所述发送单元发送所述第三注册请求之后, 接 收所述近距离服务器根据所述第三注册请求发送的注册通过响应消息, 所 述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述 近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述发送单元, 用于根据所述接收单元接收的所述注册通过响应消息 向所述 UE发送通过响应消息, 所述通过响应消息包括所述第一标识符和 所述第二标识符。
结合第五方面, 在第三种可能的实现方式中, 所述接收单元, 还用于 在所述近距离服务器确定所述 UE的签约信息中无所述授权信息, 则接收 所述近距离服务器根据所述第二授权请求发送的拒绝授权的应答消息; 所述发送单元, 还用于根据所述接收单元接收的所述拒绝授权的应答 消息向所述 UE发送拒绝应答消息。
结合第五方面及第一种、 第二种可能的实现方式, 在第四种可能的实 现方式中, 所述第一注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
第六方面, 提供了一种应用服务器, 包括:
接收单元, 用于接收 UE发送的认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务 器为所述 UE分配的使用近距离服务的第一标识符和所述近距离服务器的 第二标识符;
发送单元, 用于在接收单元接收所述认证请求之后, 根据所述第二标 识符向所述近距离服务器发送第一确认请求, 所述第一确认请求包括: 所 述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识和所述第一 标识符, 所述第一确认请求用于使所述近距离服务器根据所述 UE的标识 确定与所述 UE的标识对应的 UE的签约信息中是否有所述应用的标识、 所述应用的用户标识和所述第一标识符对应的 UE使用近距离服务的授权 信息;
所述接收单元, 还用于在所述发送单元发送所述第一确认请求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授 权信息时, 接收所述近距离服务器发送的授权通过的确认应答;
所述发送单元, 还用于在接收单元接收所述授权通过的确认应答之 后, 根据所述授权通过的确认应答向所述 UE发送认证通过消息, 以使所 述 UE根据所述认证通过消息使所述应用使用所述近距离服务。
结合第六方面, 在第一种可能的实现方式中, 所述接收单元, 还用于 在所述发送单元发送所述第一确认请求之后, 且在所述近距离服务器根据 所述 UE的标识确定所述签约信息中无所述授权信息时, 接收所述近距离 服务器发送的拒绝消息;
所述发送单元, 还用于在所述接收单元接收所述拒绝消息之后, 根据 所述拒绝消息向所述 UE发送认证拒绝消息。
第七方面, 提供了一种近距离服务器, 包括: 接收单元,用于在近距离服务器对应用所在的 UE认证之后,所述 UE 上的应用启动使用近距离服务时, 接收 MME发送的第二授权请求, 所述 第二授权请求为所述 MME接收所述 UE发送的第一授权请求之后发送的 , 且所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所 述应用的用户标识;
查找单元, 用于在所述接收单元接收所述第二授权请求之后, 根据所 述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用 的标识和所述应用的用户标识对应的使用近距离服务的授权信息;
发送单元, 用于在所述查找单元查找到所述 UE的签约信息中有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务的授权信 息, 则向所述 MME发送授权通过应答消息, 以使所述 MME根据所述授 权通过应答消息向所述 UE发送通过应答消息。
结合第七方面, 在第一种可能的实现方式中, 所述接收单元, 还用于 在接收所述第二授权请求之前, 还接收所述 MME发送的第二注册请求, 所述第二注册请求为所述 MME在接收所述 UE发送的第一注册请求之后 发送的, 所述第二注册请求包括: 所述 UE的标识;
所述近距离服务器还包括:
获取单元, 用于在所述接收单元接收所述第二注册请求之后, 根据所 述 UE的标识向 HSS获取所述 UE的标识对应的 UE的签约信息;
确定单元, 用于在所述获取单元获取所述 UE的签约信息之后, 根据 所述 UE的标识确定所述签约信息中有所述 UE授权使用近距离服务的授 权信息;
所述发送单元, 还用于在所述确定单元确定有所述授权信息时, 向所 述 MME发送注册通过响应消息, 所述注册通过响应消息包括: 所述近距 离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述近距 离服务器的第二标识符, 以使所述 MME向 UE发送包括所述第一标识符 和所述第二标识符的通过响应消息。
结合第七方面, 在第二种可能的实现方式中, 所述接收单元, 还用于 在接收所述第二授权请求之前, 接收所述 MME发送的第三注册请求, 所 述第三注册请求包括: 所述 UE的标识和所述 UE的签约信息; 所述第三 注册请求为所述 MME在接收所述 UE发送的第一注册请求 , 且根据所述 第一注册请求中 UE的标识向 HSS获取 UE的签约信息, 并确定所述签约 信息中有所述 UE的标识对应的 UE使用近距离服务的授权信息之后发送 的;
所述近距离服务器, 还包括:
存储单元, 用于在所述接收单元接收所述第三注册请求之后, 存储所 述 UE的签约信息;
发送单元, 用于在所述存储单元存储所述 UE的签约信息之后, 根据 所述第三注册请求向所述 MME发送注册通过响应消息, 所述注册通过响 应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的 第一标识符和所述近距离服务器的第二标识符, 以使所述 MME向 UE发 送包括所述第一标识符和所述第二标识符的通过响应消息。
结合第七方面, 在第三种可能的实现方式中, 发送单元, 还用于在所 述查找单元未查找到所述 UE的签约信息中有所述 UE中应用的标识和所 述应用的用户标识对应的使用近距离服务的授权信息, 则向所述 MME发 送所述第二授权请求的拒绝授权的应答消息, 以使所述 MME根据所述拒 绝授权的应答消息向所述 UE发送拒绝应答消息。
第八方面, 提供了一种用户设备, 包括:
发送单元, 用于在应用所在的 UE通过近距离服务器的认证之后, 且 在所述 UE上的应用启动使用近距离服务时,向 MME发送第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述 应用的用户标识, 所述第一授权请求用于使所述 MME向近距离服务器根 据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中 应用的标识和所述应用的用户标识的授权信息;
接收单元, 用于在所述发送单元发送所述第一授权请求之后, 且在所 述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识和 所述应用的用户标识的授权信息 ,则接收所述 MME发送的通过应答消息 , 所述通过应答消息为所述 MME接收所述近距离服务器发送授权通过应答 消息之后发送的;
所述发送单元, 还用于在所述接收单元接收所述通过应答消息之后, 向应用服务器发起认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务器为所述 UE分配 的使用近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述接收单元, 还用于在所述发送单元发送所述认证请求之后, 接收 所述应用服务器发送的认证通过消息, 所述认证通过消息为所述应用服务 器根据所述认证请求和所述近距离服务器交互, 并确认所述 UE的应用能 够使用近距离服务之后发送的;
使用单元, 根据所述认证通过消息使所述应用使用所述近距离服务。 结合第八方面, 在第一种可能的实现方式中, 所述发送单元, 还用于 在发所述第一授权请求之前, 向所述 MME发送用于向近距离服务器进行 注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识; 以使所 述 MME根据所述第一注册请求向近距离服务器确定所述 UE的签约信息 中是否有所述 UE使用近距离服务的授权信息;
所述接收单元, 还用于在所述发送单元发送所述第一注册请求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授 权信息, 则所述 UE接收所述 MME发送的通过响应消息, 所述通过响应 消息为所述 MME接收所述近距离服务器发送的注册通过响应消息之后发 送的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分配的使用 所述近距离服务的第一标识符和所述近距离服务器的第二标识符。
结合第八方面及第一种可能的实现方式, 在第二种可能的实现方式 中, 所述第一注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
第九方面, 提供了一种移动性管理实体, 包括:
接收器, 用于在应用所在的 UE通过近距离服务器的认证之后, 且在 所述 UE上的应用启动使用近距离服务时, 接收所述 UE发送的第一授权 请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应用的标识 和所述应用的用户标识;
发射器, 用于根据所述接收器所接收的第一授权请求向所述近距离服 务器发送第二授权请求, 所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述应用的用户标识; 所述第二授权请求用于使所述 近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是 否有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务 的授权信息;
所述接收器, 用于在所述发射器发送所述第二授权请求之后, 在所述 近距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识和所 述应用的用户标识对应的授权信息的情况下, 接收所述近距离服务器根据 所述第二授权请求发送的授权通过应答消息;
所述发射器, 用于根据所述接收器接收的所述授权通过应答消息向所 述 UE发送通过应答消息, 以使所述 UE根据所述通过应答消息向应用服 务器发起认证请求。
结合第九方面, 在第一种可能的实现方式中, 所述接收器, 还用于在 接收所述第一授权请求之前, 接收所述 UE发送的用于向近距离服务器进 行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述发射器, 还用于根据所述接收器接收的第一注册请求向近距离服 务器发送第二注册请求, 所述第二注册请求包括: 所述 UE的标识, 所述 第二注册请求用于使所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE的签约信息中是否有与所述 UE的标识对应的 UE使 用近距离服务的授权信息;
所述接收器, 还用于在所述近距离服务器根据所述 UE的标识确定所 述签约信息中有所述授权信息时, 接收所述近距离服务器发送的注册通过 响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分 配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标识 付;
所述发射器, 还用于根据所述接收器接收的所述注册通过响应消息向 所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一标识符和 所述第二标识符。
结合第九方面, 在第二种可能的实现方式中, 所述接收器, 还用于在 接收所述第一授权请求之前, 接收所述 UE发送的用于向近距离服务器进 行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述移动性管理实体还包括: 处理器, 用于在所述接收器接收所述第一注册请求之后, 根据所述
UE的标识向 HSS获取与所述 UE的标识对应的 UE的签约信息, 并确定 所述 UE的签约信息中是否有所述 UE的标识对应的 UE使用近距离服务 的授权信息;
所述发射器, 还用于在所述处理器确定所述 UE的签约信息中有所述
UE的标识对应的 UE使用近距离服务的授权信息之后, 向所述近距离服 务器发送第三注册请求, 所述第三注册请求包括: 所述 UE的标识和所述 UE的签约信息;
所述接收器, 用于在所述发射器发送所述第三注册请求之后, 接收所 述近距离服务器根据所述第三注册请求发送的注册通过响应消息, 所述注 册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距 离服务的第一标识符和所述近距离服务器的第二标识符;
所述发射器, 用于根据所述接收器接收的所述注册通过响应消息向所 述 UE发送通过响应消息, 所述通过响应消息包括所述第一标识符和所述 第二标识符。
结合第九方面, 在第三种可能的实现方式中, 所述接收器, 还用于在 所述近距离服务器确定所述 UE的签约信息中无所述授权信息, 则接收所 述近距离服务器根据所述第二授权请求发送的拒绝授权的应答消息;
所述发射器, 还用于根据所述接收器接收的所述拒绝授权的应答消息 向所述 UE发送拒绝应答消息。
结合第九方面及第一种或第二种可能的实现方式, 在第四种可能的实 现方式中, 所述第一注册请求携带在以下消息之一中: 网络附着消息、 位 置更新消息、 非接入层消息、 和接入层消息。
第十方面, 提供了一种应用服务器, 包括:
接收器, 用于接收 UE发送的认证请求, 所述认证请求包括: 所述 UE 的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务器为 所述 UE分配的使用近距离服务的第一标识符和所述近距离服务器的第二 标识符;
发射器, 用于在接收器接收所述认证请求之后, 根据所述第二标识符 向所述近距离服务器发送第一确认请求, 所述第一确认请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识和所述第一标 识符, 所述第一确认请求用于使所述近距离服务器根据所述 UE的标识确 定与所述 UE的标识对应的 UE的签约信息中是否有所述应用的标识、 所 述应用的用户标识和所述第一标识符对应的 UE使用近距离服务的授权信 息;
所述接收器, 还用于在所述发射器发送所述第一确认请求之后, 且在 所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授权信 息时, 接收所述近距离服务器发送的授权通过的确认应答;
所述发射器, 还用于在接收器接收所述授权通过的确认应答之后, 根 据所述授权通过的确认应答向所述 UE发送认证通过消息, 以使所述 UE 根据所述认证通过消息使所述应用使用所述近距离服务。
结合第十方面, 在第一种可能的实现方式中, 所述接收器, 还用于在 所述发射器发送所述第一确认请求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中无所述授权信息时, 接收所述近距离服务 器发送的拒绝消息;
所述发射器, 还用于在所述接收器接收所述拒绝消息之后, 根据所述 拒绝消息向所述 UE发送认证拒绝消息。
第十一方面, 提供了一种近距离服务器, 包括:
接收器, 用于在近距离服务器对应用所在的 UE认证之后, 所述 UE 上的应用启动使用近距离服务时, 接收 MME发送的第二授权请求, 所述 第二授权请求为所述 MME接收所述 UE发送的第一授权请求之后发送的 , 且所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所 述应用的用户标识;
处理器, 用于在所述接收器接收所述第二授权请求之后, 根据所述 UE的标识查找存储的所述 UE的签约信息中,是否有所述 UE中应用的标 识和所述应用的用户标识对应的使用近距离服务的授权信息;
发射器, 用于在所述处理器查找到所述 UE的签约信息中有所述 UE 中应用的标识和所述应用的用户标识对应的使用近距离服务的授权信息, 则向所述 MME发送授权通过应答消息, 以使所述 MME根据所述授权通 过应答消息向所述 UE发送通过应答消息。 结合第十一方面, 在第一种可能的实现方式中, 所述接收器, 还用于 在接收所述第二授权请求之前, 还接收所述 MME发送的第二注册请求, 所述第二注册请求为所述 MME在接收所述 UE发送的第一注册请求之后 发送的, 所述第二注册请求包括: 所述 UE的标识;
所述处理器, 用于在所述接收器接收所述第二注册请求之后, 根据所 述 UE的标识向 HSS获取所述 UE的标识对应的 UE的签约信息, 根据所 述 UE的标识确定所述签约信息中有所述 UE授权使用近距离服务的授权 信息;
所述发射器, 还用于在所述处理器确定有所述授权信息时, 向所述 MME发送注册通过响应消息, 所述注册通过响应消息包括: 所述近距离 服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述近距离 服务器的第二标识符, 以使所述 MME向 UE发送包括所述第一标识符和 所述第二标识符的通过响应消息。
结合第十一方面, 在第二种可能的实现方式中, 所述接收器, 还用于 在接收所述第二授权请求之前, 接收所述 MME发送的第三注册请求, 所 述第三注册请求包括: 所述 UE的标识和所述 UE的签约信息; 所述第三 注册请求为所述 MME在接收所述 UE发送的第一注册请求, 且根据所述 第一注册请求中 UE的标识向 HSS获取 UE的签约信息, 并确定所述签约 信息中有所述 UE的标识对应的 UE使用近距离服务的授权信息之后发送 的;
所述处理器, 用于在所述接收器接收所述第三注册请求之后, 存储所 述 UE的签约信息;
所述发射器, 用于在所述处理器存储所述 UE的签约信息之后, 根据 所述第三注册请求向所述 MME发送注册通过响应消息, 所述注册通过响 应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的 第一标识符和所述近距离服务器的第二标识符, 以使所述 MME向 UE发 送包括所述第一标识符和所述第二标识符的通过响应消息。
结合第十一方面, 在第三种可能的实现方式中, 所述发射器, 还用于 在所述处理器未查找到所述 UE的签约信息中有所述 UE中应用的标识和 所述应用的用户标识对应的使用近距离服务的授权信息, 则向所述 MME 发送所述第二授权请求的拒绝授权的应答消息 , 以使所述 MME根据所述 拒绝授权的应答消息向所述 UE发送拒绝应答消息。
第十二方面, 提供了一种用户设备, 包括:
发射器, 用于在应用所在的 UE通过近距离服务器的认证之后, 且在 所述 UE上的应用启动使用近距离服务时, 向 MME发送第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述 应用的用户标识, 所述第一授权请求用于使所述 MME向近距离服务器根 据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中 应用的标识和所述应用的用户标识的授权信息;
接收器, 用于在所述发射器发送所述第一授权请求之后, 且在所述近 距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识和所述 应用的用户标识的授权信息, 则接收所述 MME发送的通过应答消息, 所 述通过应答消息为所述 MME接收所述近距离服务器发送授权通过应答消 息之后发送的;
所述发射器, 还用于在所述接收器接收所述通过应答消息之后, 向应 用服务器发起认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE 中应用的标识、 所述应用的用户标识、 近距离服务器为所述 UE分配的使 用近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述接收器, 还用于在所述发射器发送所述认证请求之后, 接收所述 应用服务器发送的认证通过消息, 所述认证通过消息为所述应用服务器根 据所述认证请求和所述近距离服务器交互, 并确认所述 UE的应用能够使 用近距离服务之后发送的;
处理器, 根据所述接收器所接收的认证通过消息使所述应用使用所述 近距离服务。
结合第十二方面, 在第一种可能的实现方式中, 所述发射器, 还用于 在发所述第一授权请求之前, 向所述 MME发送用于向近距离服务器进行 注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识; 以使所 述 MME根据所述第一注册请求向近距离服务器确定所述 UE的签约信息 中是否有所述 UE使用近距离服务的授权信息;
所述接收器, 还用于在所述发射器发送所述第一注册请求之后, 且在 所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授权信 息, 则所述 UE接收所述 MME发送的通过响应消息, 所述通过响应消息 为所述 MME接收所述近距离服务器发送的注册通过响应消息之后发送 的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所 述近距离服务的第一标识符和所述近距离服务器的第二标识符。
结合第十二方面或第一种可能的实现方式, 在第二种可能的实现方式 中, 所述第一注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
由上述技术方案可知, 本发明实施例的近距离服务的认证与授权的方 法及设备, 在 UE通过近距离服务器的认证之后, 在 UE上的应用使用近 距离服务器时, 通过 MME向近距离服务器确认所述 UE上的应用和应用 的用户标识是否可以使用近距离服务, 若近距离服务器确定所述 UE的签 约信息中具有所述 UE中应用的标识和所述应用的用户标识的授权信息, 则近距离服务器通过 MME向 UE发送通过应答消息, 使得所述 UE根据 通过应答消息向应用服务器发起认证请求, 解决了现有技术中运营商无法 细化管理 UE中使用近距离服务的应用的问题。 附图说明 为了更清楚地说明本发明的技术方案, 下面将对实施例中所需要使用的 附图作一简单地介绍, 显而易见地: 下面附图只是本发明的一些实施例的附 图, 对于本领域普通技术人员来讲, 在不付出创造性劳动性的前提下, 还可 以根据这些附图获得同样能实现本发明技术方案的其它附图。
图 1为本发明一实施例提供的近距离服务的认证与授权的方法的流程示 意图;
图 2为本发明另一实施例提供近距离服务的认证与授权的方法的流程示 意图;
图 3为本发明另一实施例提供近距离服务的认证与授权的方法的流程示 意图;
图 4为本发明另一实施例提供近距离服务的认证与授权的方法的流程示 意图; 图 5为本发明另一实施例提供近距离服务的认证与授权的方法的流程示 意图;
图 6为本发明另一实施例提供近距离服务的认证与授权的方法的流程示 意图;
图 7为本发明另一实施例提供近距离服务的认证与授权的方法的流程示 意图;
图 8A和图 8B为本发明另一实施例提供近距离服务的认证与授权的方法 的流程示意图;
图 9为本发明另一实施例提供的移动性管理实体的结构示意图; 图 10为本发明另一实施例提供的应用服务器的结构示意图;
图 11为本发明另一实施例提供的近距离服务器的结构示意图;
图 12为本发明另一实施例提供的用户设备的结构示意图;
图 13为本发明另一实施例提供的移动性管理实体的结构示意图; 图 14为本发明另一实施例提供的应用服务器的结构示意图;
图 15为本发明另一实施例提供的近距离服务器的结构示意图;
图 16为本发明另一实施例提供的用户设备的结构示意图。 具体实施方式 为使本发明的目的、 技术方案和优点更加清楚, 下面将结合本发明实 施例中的附图, 对本发明的技术方案进行清楚、 完整地描述。 显然, 下述 的各个实施例都只是本发明一部分的实施例。 基于本发明下述的各个实施 例, 本领域普通技术人员即使没有作出创造性劳动, 也可以通过等效变换 部分甚至全部的技术特征, 而获得能够解决本发明技术问题, 实现本发明 技术效果的其它实施例, 而这些变换而来的各个实施例显然并不脱离本发 明所公开的范围。
本发明实施例以长期演进( Long Term Evolution, 简称 LTE ) 通信系 统为例进行举例说明,其它通信系统(如系统架构演进( System Architecture Evolution, 简称 SAE ) 通信系统、 宽带码分多址接入( Wideband Code Division Multiple Access , 简称 WCDMA ) 通信系统、 全球互联微波接入 通信系统、全球移动通信系统)可以进行类似网元的替代, 不再——详述。 图 1示出了本发明一实施例提供的近距离服务的认证与授权的方法的 流程示意图, 如图 1所示, 本实施例中的近距离服务的认证和授权的方法 如下所述。
101、 在应用所在的 UE通过近距离服务器的认证之后, 且在所述 UE 上的应用使用近距离服务器时, 移动性管理实体( Mobility Management Entity, 简称 MME )接收所述 UE发送的第一授权请求, 所述第一授权请 求包括: 所述 UE的标识, 所述 UE中应用的标识, 所述应用的用户标识。
举例来说, 应用的用户标识可为用户使用该应用的用户名; 所述 UE 中应用的标识可为应用的代码或识别码。
102、 MME根据所述第一授权请求向所述近距离服务器发送第二授权 请求, 所述第二授权请求包括所述 UE的标识、 所述 UE中应用的标识, 所述应用的用户标识; 所述第二授权请求用于使所述近距离服务器根据所 述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用 的标识和所述应用的用户标识对应的使用近距离服务的授权信息;
103、若所述近距离服务器确定所述 UE的签约信息中具有所述 UE中 应用的标识和所述应用的用户标识对应的授权信息, 则所述 MME接收所 述近距离服务器根据所述第二授权请求发送的授权通过应答消息;
所述 MME根据所述授权通过应答消息向所述 UE发送通过应答消息 , 以使所述 UE根据所述通过应答消息向应用服务器发起认证请求。
当然, 在实际应用中, 若步骤 103中, 所述近距离服务器确定所述
UE的签约信息中无所述 UE中应用的标识和所述应用的用户标识对应的 授权信息, 则所述 MME接收所述近距离服务器根据所述第二授权请求发 送的拒绝授权的应答消息;
所述 MME根据所述拒绝授权的应答消息向所述 UE发送拒绝应答消 息。
由上述实施例可知, 本实施例的近距离服务的认证与授权的方法, 在 UE通过近距离服务器的认证之后, 在 UE上的应用使用近距离服务器时, 通过 MME向近距离服务器确认所述 UE上的应用和应用的用户标识是否 可以使用近距离服务, 若近距离服务器确定所述 UE的签约信息中具有所 述 UE中应用的标识和所述应用的用户标识的授权信息, 则近距离服务器 通过 MME向 UE发送应答消息, 使得所述 UE根据所述应答消息向应用 服务器发起认证请求, 解决了现有技术中运营商无法细化管理 UE中使用 近距离服务的应用的问题。
在图 1所示的实施例的基础上, 在步骤 101中的" MME接收所述 UE 发送的第一授权请求"的步骤之前, 上述近距离服务的认证与授权的方法 还包括如下的步骤, 如图 2所示。
501、 MME接收所述 UE发送的用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识。
举例来说, 第一注册请求携带在网络附着消息中, 或者, 携带在位置 更新消息中, 或者, 携带在非接入层消息中, 或者, 携带在接入层消息中。
502、 MME根据所述第一注册请求向近距离服务器发送第二注册请 求, 所述第二注册请求包括: 所述 UE的标识, 所述第二注册请求用于使 所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE 的签约信息中是否有与所述 UE的标识对应的 UE使用近距离服务的授权 信息。
在本实施例中, UE的签约信息中包括该 UE是否可以使用近距离服 务的相关授权信息。
503、 若所述近距离服务器根据所述 UE的标识确定所述签约信息中 有所述授权信息, 则所述 MME接收所述近距离服务器发送的注册通过响 应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配 的使用所述近距离服务的第一标识符, 所述近距离服务器的第二标识符。
举例来说, 第一标识符可以是国际移动用户识别码 ( International Mobile Subscriber Identification Number, 简称 IMSI )、移动识别码 ( Mobile Subscriber International ISDN/PSTN number,简称 MSISDN ) ,广播码( ProSe Code ) 或者所述近距离服务器为所述 UE分配的其他标识符。
第二标识符可以是近距离服务器的路由信息, 如统一资源定位符
( Uniform I Universal Resource Locator, 简称 URL ) 形式, 或者互联网协 议 ( Internet Protocol , 简称 IP ) 形式的路由信息。
在其他实施例中, 上述的第一标识符和第二标识符可以组成如下的形 式: 第一标识符@第二标识符 , 如 device d2d id@proximityserver URL的 形式。
S04、 MME向所述 UE发送通过响应消息 , 所述通过响应消息包括: 第一标识符和所述第二标识符。
当然, 在实际应用中, 若步骤 S03中所述近距离服务器根据所述 UE 的标识确定所述 UE的签约信息中无与所述 UE的标识对应的 UE使用近 距离服务的授权信息, 则所述 MME接收所述近距离服务器发送的拒绝通 过的响应消息;
所述 MME根据所述拒绝通过的响应消息向所述 UE发送未授权的响 应消息。
在图 1所示的实施例的基础上, 在步骤 101中的" MME接收所述 UE 发送的第一授权请求"的步骤之前, 上述近距离服务的认证与授权的方法 还包括如下的步骤, 如图 3所示。
R01、 MME接收所述 UE发送的用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识。
举例来说, 第一注册请求携带在网络附着消息中, 或者, 携带在位置 更新消息中, 或者, 携带在非接入层消息中, 或者, 携带在接入层消息中。
R02、 MME根据所述 UE的标识,向归属用户服务器( Home Subscriber Server, 简称 HSS ) 获取与所述 UE的标识对应的 UE的签约信息;
R03、若所述 MME确定所述 UE的签约信息中有所述 UE的标识对应 的 UE使用近距离服务的授权信息; 则所述 MME向所述近距离服务器发 送第三注册请求, 所述第三注册请求包括: 所述 UE的标识和所述 UE的 签约信息;
R04、 MME接收所述近距离服务器根据所述第三注册请求发送的注册 通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述近距离服务器的第二 标识符。
R05、 MME才艮据所述注册通过响应消息向所述 UE发送通过响应消息 , 所述通过响应消息包括所述第一标识符和所述第二标识符。
当然, 在实际应用中, 若步骤 R03中所述 MME根据所述 UE的标识 确定所述 UE的签约信息中无与所述 UE的标识对应的 UE使用近距离服 务的授权信息, 则所述 MME向所述 UE发送未授权的响应消息。
图 4示出了本发明一实施例提供的近距离服务的认证与授权的方法的 流程示意图, 如图 4所示, 本实施例中的近距离服务的认证与授权的方法 如下所述。
401、 应用服务器接收 UE发送的认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务 器为所述 UE分配的使用近距离服务的第一标识符和所述近距离服务器的 第二标识符。
举例来说, 第一标识符和所述第二标识符可以组成一个整体的 Email 的形式。
402、 所述应用服务器根据所述第二标识符向所述近距离服务器发送 第一确认请求, 所述第一确认请求包括: 所述 UE的标识、 所述 UE中应 用的标识、 所述应用的用户标识和所述第一标识符, 所述第一确认请求用 于使所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE的签约信息中是否有所述应用的标识、 所述应用的用户标识和所述第 一标识符对应的 UE使用近距离服务的授权信息。
举例来说, 在应用服务器为多个时, 应用服务器向近距离服务器发送 的第一确认请求中需要携带所述 U E中应用的标识和所述应用的用户标 识。
特别地, 在应用服务器为一个时, 应用服务器向近距离服务器发送的 第一确认请求中可以不携带所述 UE中应用的标识和所述应用的用户标 识。
403、若所述近距离服务器根据所述 UE的标识确定所述签约信息中有 所述授权信息, 所述应用服务器接收所述近距离服务器发送的授权通过的 确认应答。
404、应用服务器根据所述授权通过的确认应答向所述 UE发送认证通 过消息, 以使所述 UE根据所述认证通过消息使所述应用使用所述近距离 服务。
当然, 在实际应用中, 若步骤 403中所述近距离服务器根据所述 UE 的标识确定所述签约信息中无所述应用的标识、 所述应用的用户标识、 所 述第一标识符对应的 UE使用近距离服务的授权信息, 则所述应用服务器 接收所述近距离服务器发送的拒绝消息;
所述应用服务器根据所述拒绝消息向所述 UE发送认证拒绝消息。 由上述实施例可知, 本实施例的近距离服务的认证与授权的方法, 能 够解决现有技术中运营商无法细化管理 UE中使用近距离服务的应用的问 题, 同时实现了近距离服务器对某个设备上的使用近距离服务的应用分别 控制的目的。
图 5示出了本发明一实施例提供的近距离服务的认证与授权的方法的 流程示意图, 如图 5所示, 本实施例中的近距离服务的认证与授权的方法 如下所述。
501、 近距离服务器对应用所在的 UE认证之后, 所述 UE上的应用启 动使用近距离服务时,所述近距离服务器接收 MME发送的第二授权请求, 所述第二授权请求为所述 MME接收所述 UE发送的第一授权请求之后发 送的, 且所述第二授权请求包括: 所述 UE的标识, 所述 UE中应用的标 识, 所述应用的用户标识。
举例来说, 本实施例中 UE上的应用启动使用近距离服务, 具体为: 每一次应用在推出之后, 再启动使用近距离服务器时都需要执行该图 5所示的流程; 但是, 若应用仅仅是离线, 但是该应用没有关闭, 在应用 重新上线时, 此时应用使用近距离服务则无需再执行图 5所述的流程。
502、近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信 息中, 是否有所述 UE中应用的标识和所述应用的用户标识的授权信息。
举例来说, 近距离服务器中存储的 UE的签约信息可以为近距离服务 器可以通过与 HSS建立接口, 从 HSS直接获取设备相关信息, 包括所签 约的应用以及用户标识等信息。
503、若所述 UE的签约信息中有所述 UE中应用的标识和所述应用的 用户标识对应使用近距离服务的授权信息, 则所述近距离服务器向所述 MME发送授权通过应答消息, 以使所述 MME根据所述授权通过应答消 息向所述 UE发送通过应答消息。
当然, 在步骤 503中, 若所述 UE的签约信息中无所述 UE中应用的 标识和所述应用的用户标识对应使用近距离服务的授权信息, 则所述近距 离服务器向所述 MME发送拒绝授权的应答消息, 以使所述 MME根据所 述拒绝授权的应答消息向所述 UE发送拒绝应答消息。
在一种可选的应用场景中, 在步骤 501中的"近距离服务器接收 MME 发送的第二授权请求"的步骤之前, 上述近距离服务的认证与授权的方法 还包括如下的步骤, 如图 6所示。
M01、 近距离服务器接收所述 MME发送的第二注册请求, 所述第二 注册请求为所述 MME在接收所述 UE发送的第一注册请求之后发送的, 所述第二注册请求包括: 所述 UE的标识。
M02、 近距离服务器根据所述 UE的标识向 HSS获取所述 UE的标识 对应的 UE的签约信息。
M03、 近距离服务器根据所述 UE的标识确定所述签约信息中有所述 UE授权使用近距离服务的授权信息; 则向所述 MME发送注册通过响应 消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的 使用所述近距离服务的第一标识符和所述近距离服务器的第二标识符, 以 使所述 MME根据注册通过响应消息向 UE发送包括所述第一标识符和所 述第二标识符的通过响应消息。
当然, 在实际应用中, 若上述步骤 M03中, 近距离服务器根据所述 UE的标识确定所述 UE的签约信息中无与所述 UE的标识对应的 UE使用 近距离服务的授权信息, 则向所述 MME发送拒绝通过的响应消息, 以使 所述 MME根据所述拒绝通过的响应消息向所述 UE发送未授权的响应消 息。
在一种可选的应用场景中, 在步骤 501中的"近距离服务器接收 MME 发送的第二授权请求"的步骤之前, 上述近距离服务的认证与授权的方法 还包括如下的步骤, 如图 7所示。
N01、 近距离服务器接收所述 MME发送的第三注册请求, 所述第三 注册请求包括: 所述 UE的标识和所述 UE的签约信息;
所述第三注册请求为所述 MME在接收所述 UE发送的第一注册请求 , 且根据所述第一注册请求中 UE的标识向 HSS获取 UE的签约信息, 并确 定所述签约信息中有所述 UE的标识对应的 UE使用近距离服务的授权信 息之后发送的;
N02、 近距离服务器存储所述 UE的签约信息, 并根据所述第三注册 请求向所述 MME发送注册通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和 所述近距离服务器的第二标识符, 以使所述 MME向 UE发送包括所述第 一标识符和第二标识符的通过响应消息。
当然, 在实际应用中, 若所述 MME确定所述 UE的签约信息中无所 述 UE的标识对应的 UE使用近距离服务的授权信息, 则 MME不会向近 距离服务器发送第三注册请求。
图 8A示出了本发明一实施例提供的近距离服务的认证与授权的方法 的流程示意图, 如图 8A所示, 本实施例中的近距离服务的认证与授权的 方法如下所述。
801、 在应用所在的 UE通过近距离服务器的认证之后, 且在所述 UE 上的应用启动使用近距离服务时, 所述 UE向 MME发送第一授权请求, 所述第一授权请求包括: 所述 UE的标识, 所述 UE中应用的标识和所述 应用的用户标识; 所述第一授权请求用于使所述 MME向近距离服务器根 据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中 应用的标识和所述应用的用户标识的授权信息;
802、若所述近距离服务器确定所述 UE的签约信息中具有所述 UE中 应用的标识和所述应用的用户标识的授权信息 ,则所述 UE接收所述 MME 发送的通过应答消息, 所述通过应答消息为所述 MME接收所述近距离服 务器发送授权通过应答消息之后发送的;
803、 UE在接收所述应答消息之后, 向应用服务器发起认证请求, 所 述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的 用户标识、 近距离服务器为所述 UE分配的使用近距离服务的第一标识符 和所述近距离服务器的第二标识符;
804、 UE接收所述应用服务器发送的认证通过消息, 所述认证通过消 息为所述应用服务器根据所述认证请求和所述近距离服务器交互, 并确认 所述 UE的应用能够使用近距离服务之后发送的;
805、 UE根据所述认证通过消息使所述应用使用所述近距离服务。 在一种可选的应用场景中, 在步骤 801中的" UE向 MME发送第一授 权请求"的步骤之前, 上述近距离服务的认证与授权的方法还可包括如下 的图中未示出的步骤。
P81、所述 UE向所述 MME发送用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识; 以使所述 MME根 据所述第一注册请求向近距离服务器确定所述 UE的签约信息中是否有所 述 UE使用近距离服务的授权信息。
举例来说, 第一注册请求携带在网络附着消息中, 或者, 携带在位置 更新消息中, 或者, 携带在非接入层消息中, 或者, 携带在接入层消息中。
P82、 若所述近距离服务器根据所述 UE的标识确定所述签约信息中 有所述授权信息, 则所述 UE接收所述 MME发送的通过响应消息, 所述 通过响应消息为所述 MME接收所述近距离服务器发送的注册通过响应消 息之后发送的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分 配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标识 付。
上述方法, 网络不但能够对 UE进行近距离服务的认证与授权, 还能 够对 UE上使用近距离服务的应用进行认证与授权。 该方法使得网络运营 商不但能够为用户提供基于 UE的粒度的近距离服务, 还为用户提细粒度 的基于应用的近距离服务, 大大丰富运营商的管理模式。
图 8B示出了本发明一实施例提供的近距离服务的认证与授权的方法 的流程示意图, 如图 8B所示, 本实施例中的近距离服务的认证与授权的 方法如下所述。
811、 UE向 MME发送用于向近距离服务器进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识。
举例来说, 所述第一注册请求了携带在以下消息之一中: 如网络附着 消息、 位置更新消息、 非接入层消息和接入层消息等等。
812、 MME接收所述第一注册请求之后, 根据所述第一注册请求向近 距离服务器发送第二注册请求, 所述第二注册请求包括: 所述 UE的标识, 所述第二注册请求用于使所述近距离服务器根据所述 UE的标识确定与所 述 UE的标识对应的 UE的签约信息中是否有与所述 UE的标识对应的 UE 使用近距离服务的授权信息。
813、 近距离服务器接收所述第二注册请求之后,根据所述 UE的标识 向 HSS获取所述 UE的标识对应的 UE的签约信息。
可选地, 近距离服务器在获取到 UE的签约信息之后, 存储 UE的签 约信息。
举例来说, 近距离服务器可以与 HSS建立接口, 进而近距离服务器可 以向 HSS获取 UE的签约信息。
814、近距离服务器根据所述 UE的标识确定所述 UE的签约信息中是 否有所述 UE授权使用近距离服务的授权信息, 若有, 执行步骤 815; 否 则, 执行步骤 815,。
815、 在步骤 814中, 近距离服务器根据所述 UE的标识确定所述 UE 的签约信息中有所述 UE授权使用近距离服务的授权信息, 向 MME发送 注册通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所 述 UE分配的使用所述近距离服务的第一标识符和所述近距离服务器的第 二标识符 (如 ProSe ID ) 。
举例来说, 第一标识符可为广播码, 如 ProSe Code。
可选地,注册通过响应消息中还可包括:近距离服务器的路由信息等。 路由信息可以是近距离服务器的服务器标识例如但不限于 URI, 也可以是 IP地址等。
815,、 在步骤 814中, 近距离服务器根据所述 UE的标识确定所述 UE 的签约信息中无所述 UE授权使用近距离服务的授权信息, 向所述 MME 发送拒绝注册消息, MME接收拒绝注册消息之后, 向 UE发送注册失败 消息。
816、 MME接收近距离服务器发送的注册通过响应消息之后, MME 根据所述注册通过响应消息向所述 UE发送通过响应消息, 所述通过响应 消息包括: 所述第一标识符和所述第二标识符。
举例来说, 通过响应消息可以携带在非接入层消息中, 或者携带在接 入层消息中。
817、 在 UE上的应用启动使用近距离服务时, UE向 MME发送第一 授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应用的 标识和所述应用的用户标识。
举例来说, UE 上的应用可以是微信, 或者微博等。 应用的用户标识 可以是用户使用该应用的账号等信息。
818、 MME接收第一授权请求之后, 根据所述第一授权请求向所述近 距离服务器发送第二授权请求, 所述第二授权请求包括所述 UE的标识、 所述 UE中应用的标识, 所述应用的用户标识; 所述第二授权请求用于使 所述近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服 务的授权信息。
819、 近距离服务器接收第二授权请求之后, 若确定步骤 813 中获取 的 UE的签约信息中具有所述 UE中应用的标识和所述应用的用户标识对 应的授权信息, 向 MME发送授权通过应答消息。
820、 MME接收所述近距离服务器根据所述第二授权请求发送的授权 通过应答消息之后, 根据所述授权通过应答消息向所述 UE发送通过应答 消息, 以使所述 UE根据所述通过应答消息向应用服务器发起认证请求。
821、 UE在接收 MME发送的通过应答消息之后, 向应用服务器发起 认证请求 , 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务器为所述 UE分配的使用近距离服务的 第一标识符和所述近距离服务器的第二标识符。
该步骤中的第一标识符和第二标识符为步骤 816中 MME向 UE发送 的。
可选地, 该处的认证请求中还可包括所述 UE接收到的近距离服务器 的路由信息, 以使应用服务器根据所述近距离服务器的路由信息与所述近 距离服务器建立连接。
822、 应用服务器接收认证请求之后, 根据所述第二标识符向所述近 距离服务器发送第一确认请求, 所述第一确认请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识和所述第一标识符, 所述第 一确认请求用于使所述近距离服务器根据所述 UE的标识确定与所述 UE 的标识对应的 UE的签约信息中是否有所述应用的标识、 所述应用的用户 标识和所述第一标识符对应的 UE使用近距离服务的授权信息。
823、 近距离服务器接收应用服务器发送的第一确认请求之后, 根据 所述 UE的标识确定所述存储的 UE的签约信息中有所述授权信息, 向应 用服务器发送授权通过的确认应答。
824、 应用服务器在接收近距离服务器发送的确认应答之后, 根据所
825、 UE接收所述应用服务器发送的认证通过消息之后, 根据所述认 证通过消息使所述应用使用近距离服务。
上述方法, 网络不但能够对 UE进行近距离服务的认证与授权, 还能 够对 UE上使用近距离服务的应用进行认证与授权。 该方法使得网络运营 商不但能够为用户提供基于 UE的粒度的近距离服务, 还为用户提细粒度 的基于应用的近距离服务, 大大丰富运营商的管理模式。
根据本发明的另一方面, 本发明实施例还提供一种移动性管理实体, 如图 9所示, 本实施例中的移动性管理实体包括: 接收单元 91和发送单 元 92;
其中,接收单元 91用于在应用所在的 UE通过近距离服务器的认证之 后, 且在所述 UE上的应用启动使用近距离服务时, 接收所述 UE发送的 第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应 用的标识和所述应用的用户标识;
发送单元 92用于根据所述接收单元 91所接收的第一授权请求向所述 近距离服务器发送第二授权请求, 所述第二授权请求包括: 所述 UE的标 识、 所述 UE中应用的标识和所述应用的用户标识; 所述第二授权请求用 于使所述近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信 息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近 距离服务的授权信息;
所述接收单元 91用于在所述发送单元 92发送所述第二授权请求之 后, 在所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用 的标识和所述应用的用户标识对应的授权信息, 则接收所述近距离服务器 根据所述第二授权请求发送的授权通过应答消息;
所述发送单元 92用于根据所述接收单元 91接收的所述授权通过应答 消息向所述 UE发送通过应答消息, 以使所述 UE根据所述通过应答消息 向应用服务器发起认证请求。
在一种可选的应用场景中, 所述接收单元 91还用于在接收所述第一 授权请求之前, 接收所述 UE发送的用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述发送单元 92还用于根据所述接收单元 91接收的第一注册请求向 近距离服务器发送第二注册请求, 所述第二注册请求包括: 所述 UE的标 识, 所述第二注册请求用于使所述近距离服务器根据所述 UE的标识确定 与所述 UE的标识对应的 UE的签约信息中是否有与所述 UE的标识对应 的 UE使用近距离服务的授权信息;
所述接收单元 91还用于在所述近距离服务器根据所述 UE的标识确定 所述签约信息中有所述授权信息时, 接收所述近距离服务器发送的注册通 过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE 分配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标 识符;
所述发送单元 92还用于根据所述接收单元 91接收的所述注册通过响 应消息向所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一 标识符和所述第二标识符。
在另一种可选的应用场景中, 所述接收单元 91还用于在接收所述第 一授权请求之前, 接收所述 UE发送的用于向近距离服务器进行注册的第 一注册请求, 所述第一注册请求包括: 所述 UE的标识;
举例来说, 所述第一注册请求携带在网络附着消息中, 或者, 携带在 位置更新消息中, 或者, 携带在非接入层消息中, 或者, 携带在接入层消 息中。
相应地, 所述移动性管理实体还包括图中未示出的获取单元 93和确 定单元 94;
其中, 获取单元 93用于在所述接收单元 91接收所述第一注册请求之 后, 根据所述 UE的标识向 HSS获取与所述 UE的标识对应的 UE的签约 信息;
确定单元 94用于确定所述获取单元 93获取的 UE的签约信息中是否 有所述 UE的标识对应的 UE使用近距离服务的授权信息;
所述发送单元 92还用于在所述确定单元 94确定所述 UE的签约信息 中有所述 UE的标识对应的 UE使用近距离服务的授权信息之后, 向所述 近距离服务器发送第三注册请求, 所述第三注册请求包括: : 所述 UE的 标识和所述 UE的签约信息;
所述接收单元 91用于在所述发送单元 92发送所述第三注册请求之 后, 接收所述近距离服务器根据所述第三注册请求发送的注册通过响应消 息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使 用所述近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述发送单元 92用于根据所述接收单元 91接收的所述注册通过响应 消息向所述 UE发送通过响应消息, 所述通过响应消息包括所述第一标识 符和所述第二标识符。
当然, 在实际应用中, 所述接收单元 91还用于在所述近距离服务器 确定所述 UE的签约信息中无所述授权信息, 则接收所述近距离服务器根 据所述第二授权请求发送的拒绝授权的应答消息;
所述发送单元 92还用于根据所述接收单元 91接收的所述拒绝授权的 应答消息向所述 UE发送拒绝应答消息。
上述移动性管理实体通过将 UE的消息转发至近距离服务器, 或者, 将近距离服务器的消息转发至 UE, 实现了 UE和近距离服务器的交互, 进而使得近距离服务器可以对 UE上使用近距离服务的应用分别控制。
根据本发明的另一方面, 本发明实施例还提供一种应用服务器, 如图 10所示,本实施例中的应用服务器包括:接收单元 1001和发送单元 1002; 其中,接收单元 1001用于接收 UE发送的认证请求, 所述认证请求包 括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近 距离服务器为所述 UE分配的使用近距离服务的第一标识符和所述近距离 服务器的第二标识符;
发送单元 1002用于在接收单元 1001接收所述认证请求之后, 根据所 述第二标识符向所述近距离服务器发送第一确认请求, 所述第一确认请求 包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识和 所述第一标识符, 所述第一确认请求用于使所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE的签约信息中是否有所述应用 的标识、 所述应用的用户标识和所述第一标识符对应的 UE使用近距离服 务的授权信息;
所述接收单元 1001还用于在所述发送单元 1002发送所述第一确认请 求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中 有所述授权信息时, 接收所述近距离服务器发送的授权通过的确认应答; 所述发送单元 1002还用于在接收单元 1001接收所述授权通过的确认 应答之后, 根据所述授权通过的确认应答向所述 UE发送认证通过消息, 以使所述 UE根据所述认证通过消息使所述应用使用所述近距离服务。
当然, 在实际应用中, 接收单元 1001还用于在所述发送单元 1002发 送所述第一确认请求之后, 且在所述近距离服务器根据所述 UE的标识确 定所述签约信息中无所述授权信息时, 接收所述近距离服务器发送的拒绝 消息;
相应地, 所述发送单元 1002还用于在所述接收单元 1001接收所述拒 绝消息之后, 根据所述拒绝消息向所述 UE发送认证拒绝消息。
上述应用服务器与近距离服务器交互, 实现了近距离服务器对某一设 备上的使用近距离服务的应用分别控制的目的。
根据本发明的另一方面, 本发明实施例还提供一种近距离服务器, 如 图 11所示, 本实施例中的近距离服务器包括: 接收单元 1101、 查找单元 1102和发送单元 1103 ;
其中,接收单元 1101用于在近距离服务器对应用所在的 UE认证之后 , 所述 UE上的应用启动使用近距离服务时, 接收 MME发送的第二授权请 求, 所述第二授权请求为所述 MME接收所述 UE发送的第一授权请求之 后发送的, 且所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用 的标识和所述应用的用户标识;
查找单元 1102用于在所述接收单元 1101接收所述第二授权请求之 后, 根据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务的授权信 息;
发送单元 1103用于在所述查找单元 1102查找到所述 UE的签约信息 中有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务 的授权信息, 则向所述 MME发送授权通过应答消息, 以使所述 MME根 据所述授权通过应答消息向所述 UE发送通过应答消息。
当然, 在实际应用中, 发送单元 1103还用于在所述查找单元 1102未 查找到所述 U E的签约信息中有所述 U E中应用的标识和所述应用的用户 标识对应的使用近距离服务的授权信息, 则向所述 MME发送所述第二授 权请求的拒绝授权的应答消息, 以使所述 MME根据所述拒绝授权的应答 消息向所述 UE发送拒绝应答消息。
在一种应用场景中, 所述接收单元 1101还用于在接收所述第二授权 请求之前, 还接收所述 MME发送的第二注册请求, 所述第二注册请求为 所述 MME在接收所述 UE发送的第一注册请求之后发送的, 所述第二注 册请求包括: 所述 UE的标识;
此时, 所述近距离服务器还包括图中未示出的获取单元 1104和确定 单元 1105;
其中, 获取单元 1104用于在所述接收单元 1101接收所述第二注册请 求之后, 根据所述 UE的标识向 HSS获取所述 UE的标识对应的 UE的签 约信息;
确定单元 1105用于在所述获取单元 1104获取所述 UE的签约信息之 后, 根据所述 UE的标识确定所述签约信息中有所述 UE授权使用近距离 服务的授权信息;
所述发送单元 1103还用于在所述确定单元 1105确定有所述授权信息 时, 向所述 MME发送注册通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和 所述近距离服务器的第二标识符, 以使所述 MME向 UE发送包括所述第 一标识符和所述第二标识符的通过响应消息。
在另一种可选的应用场景中, 所述接收单元 1101还用于在接收所述 第二授权请求之前, 接收所述 MME发送的第三注册请求, 所述第三注册 请求包括: 所述 UE的标识和所述 UE的签约信息; 所述第三注册请求为 所述 MME在接收所述 UE发送的第一注册请求, 且根据所述第一注册请 求中 UE的标识向 HSS获取 UE的签约信息, 并确定所述签约信息中有所 述 UE的标识对应的 UE使用近距离服务的授权信息之后发送的; 相应地, 所述近距离服务器还包括图中未示出的存储单元 1106;
其中, 存储单元 1106用于在所述接收单元 1101接收所述第三注册请 求之后, 存储所述 UE的签约信息;
发送单元 1103用于在所述存储单元 1106存储所述 UE的签约信息之 后, 根据所述第三注册请求向所述 MME发送注册通过响应消息, 所述注 册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距 离服务的第一标识符和所述近距离服务器的第二标识符, 以使所述 MME 向 UE发送包括所述第一标识符和所述第二标识符的通过响应消息。
上述近距离服务器实现了对某一设备上使用近距离服务的应用细化 管理的目的。
根据本发明的另一方面, 本发明实施例还提供一种用户设备, 如图 12 所示, 本实施例中的用户设备包括: 发送单元 1201、 接收单元 1202和使 用单元 1203;
其中,发送单元 1201用于在应用所在的 UE通过近距离服务器的认证 之后, 且在所述 UE上的应用启动使用近距离服务时, 向 MME发送第一 授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应用的 标识和所述应用的用户标识, 所述第一授权请求用于使所述 MME向近距 离服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有 所述 UE中应用的标识和所述应用的用户标识的授权信息;
接收单元 1202用于在所述发送单元 1201发送所述第一授权请求之 后, 且在所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应 用的标识和所述应用的用户标识的授权信息, 则接收所述 MME发送的通 过应答消息, 所述通过应答消息为所述 MME接收所述近距离服务器发送 授权通过应答消息之后发送的;
所述发送单元 1201还用于在所述接收单元 1202接收所述通过应答消 息之后, 向应用服务器发起认证请求, 所述认证请求包括: 所述 UE的标 识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务器为所述 UE分配的使用近距离服务的第一标识符和所述近距离服务器的第二标识 符; 所述接收单元 1202还用于在所述发送单元 1201发送所述认证请求之 后, 接收所述应用服务器发送的认证通过消息, 所述认证通过消息为所述 应用服务器根据所述认证请求和所述近距离服务器交互, 并确认所述 UE 的应用能够使用近距离服务之后发送的;
使用单元 1203 , 根据所述接收单元 1202接收认证通过消息之后, 使 所述应用使用所述近距离服务。
在一种可选的应用场景中, 发送单元 1201还用于在发所述第一授权 请求之前, 向所述 MME发送用于向近距离服务器进行注册的第一注册请 求, 所述第一注册请求包括: 所述 UE的标识; 以使所述 MME根据所述 第一注册请求向近距离服务器确定所述 UE的签约信息中是否有所述 UE 使用近距离服务的授权信息;
所述接收单元 1202还用于在所述发送单元 1201发送所述第一注册请 求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中 有所述授权信息, 则所述 UE接收所述 MME发送的通过响应消息, 所述 通过响应消息为所述 MME接收所述近距离服务器发送的注册通过响应消 息之后发送的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分 配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标识 付。
举例来说, 上述的第一注册请求可携带在网络附着消息中, 或者, 可 携带在位置更新消息中, 或者, 可携带在非接入层消息中, 或者, 可携带 在接入层消息中。
上述用户设备实现了运营商对用户设备中使用近距离服务的应用的 细化管理, 同时提高了用户使用用户设备的体验性。
应了解的是, 以上任一设备或服务器的实施例中, 各功能单元的划分 仅是举例说明, 实际应用中可以根据需要, 例如相应硬件的配置要求或者 软件的实现的便利考虑, 而将上述功能分配由不同的功能单元完成, 即将 所述用户设备的内部结构划分成不同的功能单元, 以完成以上描述的全部 或者部分功能。 而且, 实际应用中, 本实施例中的相应的功能单元可以是 由相应的硬件实现, 也可以由相应的硬件执行相应的软件完成, 例如, 前 述的使用单元可以是能够执行相应计算机程序从而完成前述功能的一般 处理器或者其他硬件设备; 再如, 前述的接收单元, 可以是具有执行前述 接收单元功能的硬件, 例如接收器, 也可以是能够执行相应计算机程序从 而完成前述功能的一般处理器或者其他硬件设备; (本说明书提供的各个 实施例都可应用上述描述原则) 。
根据本发明的另一方面, 本发明实施例还提供一种移动性管理实体, 如图 13所示, 移动性管理实体包括: 接收器 1301和发射器 1302;
其中,接收器 1301用于在应用所在的 UE通过近距离服务器的认证之 后, 且在所述 UE上的应用启动使用近距离服务时, 接收所述 UE发送的 第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应 用的标识和所述应用的用户标识;
发射器 1302用于根据所述接收器 1301所接收的第一授权请求向所述 近距离服务器发送第二授权请求, 所述第二授权请求包括: 所述 UE的标 识、 所述 UE中应用的标识和所述应用的用户标识; 所述第二授权请求用 于使所述近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信 息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近 距离服务的授权信息;
所述接收器 1301用于在所述发射器 1302发送所述第二授权请求之 后, 在所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用 的标识和所述应用的用户标识对应的授权信息, 则接收所述近距离服务器 根据所述第二授权请求发送的授权通过应答消息;
所述发射器 1302用于根据所述接收器 1301接收的所述授权通过应答 消息向所述 UE发送通过应答消息, 以使所述 UE根据所述通过应答消息 向应用服务器发起认证请求。
在一种应用场景中, 所述接收器 1301还用于在接收所述第一授权请 求之前, 接收所述 UE发送的用于向近距离服务器进行注册的第一注册请 求, 所述第一注册请求包括: 所述 UE的标识;
所述发射器 1302还用于根据所述接收器 1301接收的第一注册请求向 近距离服务器发送第二注册请求, 所述第二注册请求包括: 所述 UE的标 识, 所述第二注册请求用于使所述近距离服务器根据所述 UE的标识确定 与所述 UE的标识对应的 UE的签约信息中是否有与所述 UE的标识对应 的 UE使用近距离服务的授权信息;
所述接收器 1301还用于在所述近距离服务器根据所述 UE的标识确定 所述签约信息中有所述授权信息时, 接收所述近距离服务器发送的注册通 过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE 分配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标 识符;
所述发射器 1302还用于根据所述接收器 1301接收的所述注册通过响 应消息向所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一 标识符和所述第二标识符。
在另一种应用场景中, 所述接收器 1301还用于在接收所述第一授权 请求之前, 接收所述 UE发送的用于向近距离服务器进行注册的第一注册 请求, 所述第一注册请求包括: 所述 UE的标识;
举例来说, 所述第一注册请求携带在网络附着消息中, 或者, 携带在 位置更新消息中, 或者, 携带在非接入层消息中, 或者, 携带在接入层消 息中。
所述移动性管理实体还包括图中未示出的处理器 1303 ;
其中, 处理器 1303用于在所述接收器 1301接收所述第一注册请求之 后, 根据所述 UE的标识向 HSS获取与所述 UE的标识对应的 UE的签约 信息, 并确定所述 UE的签约信息中是否有所述 UE的标识对应的 UE使 用近距离服务的授权信息;
所述发射器 1302还用于在所述处理器 1303确定所述 UE的签约信息 中有所述 UE的标识对应的 UE使用近距离服务的授权信息之后, 向所述 近距离服务器发送第三注册请求, 所述第三注册请求包括: : 所述 UE的 标识和所述 UE的签约信息;
所述接收器 1301用于在所述发射器 1302发送所述第三注册请求之 后, 接收所述近距离服务器根据所述第三注册请求发送的注册通过响应消 息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使 用所述近距离服务的第一标识符和所述近距离服务器的第二标识符; 所述发射器 1302用于根据所述接收器 1301接收的所述注册通过响应 消息向所述 UE发送通过响应消息, 所述通过响应消息包括所述第一标识 符和所述第二标识符。
在第三种应用场景中, 所述接收器 1301还用于在所述近距离服务器 确定所述 UE的签约信息中无所述授权信息, 则接收所述近距离服务器根 据所述第二授权请求发送的拒绝授权的应答消息;
所述发射器 1302还用于根据所述接收器 1301接收的所述拒绝授权的 应答消息向所述 UE发送拒绝应答消息。
上述移动性管理实体通过将 UE的消息转发至近距离服务器, 或者, 将近距离服务器的消息转发至 UE, 实现了 UE和近距离服务器的交互, 进而使得近距离服务器可以对 UE上使用近距离服务的应用分别控制。
根据本发明的另一方面, 本发明实施例还提供一种应用服务器, 如图
14所示, 应用服务器包括: 接收器 1401和发射器 1402;
其中,接收器 1401用于接收 UE发送的认证请求,所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离 服务器为所述 UE分配的使用近距离服务的第一标识符和所述近距离服务 器的第二标识符;
发射器 1402用于在接收器 1401接收所述认证请求之后, 根据所述第 二标识符向所述近距离服务器发送第一确认请求, 所述第一确认请求包 括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识和所 述第一标识符, 所述第一确认请求用于使所述近距离服务器根据所述 UE 的标识确定与所述 UE的标识对应的 UE的签约信息中是否有所述应用的 标识、 所述应用的用户标识和所述第一标识符对应的 UE使用近距离服务 的授权信息;
所述接收器 1401还用于在所述发射器 1402发送所述第一确认请求之 后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中有所 述授权信息时, 接收所述近距离服务器发送的授权通过的确认应答;
所述发射器 1402还用于在接收器 1401接收所述授权通过的确认应答 之后, 根据所述授权通过的确认应答向所述 UE发送认证通过消息, 以使 所述 UE根据所述认证通过消息使所述应用使用所述近距离服务。
可选地, 接收器 1401还用于在所述发射器 1402发送所述第一确认请 求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中 无所述授权信息时, 接收所述近距离服务器发送的拒绝消息; 所述发射器 1402还用于在所述接收器 1401接收所述拒绝消息之后, 根据所述拒绝消息向所述 UE发送认证拒绝消息。
上述应用服务器与近距离服务器交互, 实现了近距离服务器对某一设 备上的使用近距离服务的应用分别控制的目的。
根据本发明的另一方面, 本发明实施例还提供一种近距离服务器, 如 图 15所示,近距离服务器包括:接收器 1501、处理器 1502和发射器 1503; 其中, 接收器 1501用于在近距离服务器对应用所在的 UE认证之后, 所述 UE上的应用启动使用近距离服务时, 接收 MME发送的第二授权请 求, 所述第二授权请求为所述 MME接收所述 UE发送的第一授权请求之 后发送的, 且所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用 的标识和所述应用的用户标识;
处理器 1502用于在所述接收器 1501接收所述第二授权请求之后, 根 据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中 应用的标识和所述应用的用户标识对应的使用近距离服务的授权信息; 发射器 1503用于在所述处理器 1502查找到所述 UE的签约信息中有 所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务的授 权信息, 则向所述 MME发送授权通过应答消息, 以使所述 MME根据所 述授权通过应答消息向所述 UE发送通过应答消息。
在一种可选的应用场景中, 所述接收器 1501还用于在接收所述第二 授权请求之前, 还接收所述 MME发送的第二注册请求, 所述第二注册请 求为所述 MME在接收所述 UE发送的第一注册请求之后发送的, 所述第 二注册请求包括: 所述 UE的标识;
所述处理器 1502用于在所述接收器 1501接收所述第二注册请求之 后, 根据所述 UE的标识向 HSS获取所述 UE的标识对应的 UE的签约信 息, 根据所述 UE的标识确定所述签约信息中有所述 UE授权使用近距离 服务的授权信息;
所述发射器 1503还用于在所述处理器 1502确定有所述授权信息时, 向所述 MME发送注册通过响应消息, 所述注册通过响应消息包括: 所述 近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述 近距离服务器的第二标识符, 以使所述 MME向 UE发送包括所述第一标 识符和所述第二标识符的通过响应消息。
在另一种可选的应用场景中, 所述接收器 1501还用于在接收所述第 二授权请求之前, 接收所述 MME发送的第三注册请求, 所述第三注册请 求包括: 所述 UE的标识和所述 UE的签约信息; 所述第三注册请求为所 述 MME在接收所述 UE发送的第一注册请求, 且根据所述第一注册请求 中 UE的标识向 HSS获取 UE的签约信息, 并确定所述签约信息中有所述 UE的标识对应的 UE使用近距离服务的授权信息之后发送的;
所述处理器 1502用于在所述接收器 1501接收所述第三注册请求之 后, 存储所述 UE的签约信息;
所述发射器 1503用于在所述处理器 1502存储所述 UE的签约信息之 后, 根据所述第三注册请求向所述 MME发送注册通过响应消息, 所述注 册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距 离服务的第一标识符和所述近距离服务器的第二标识符, 以使所述 MME 向 UE发送包括所述第一标识符和所述第二标识符的通过响应消息。
在另一可选的应用场景中, 上述的发射器 1503还用于在所述处理器 1502未查找到所述 UE的签约信息中有所述 UE中应用的标识和所述应用 的用户标识对应的使用近距离服务的授权信息, 则向所述 MME发送所述 第二授权请求的拒绝授权的应答消息, 以使所述 MME根据所述拒绝授权 的应答消息向所述 UE发送拒绝应答消息。
上述近距离服务器实现了对某一设备上使用近距离服务的应用细化 管理的目的, 同时实现了运营商对某一设备上使用近距离服务的应用习惯 管理的目的, 使得运营商可以给用户提供更灵活的服务。
根据本发明的另一方面, 本发明实施例还提供一种用户设备, 如图 16 所示, 本实施例中的用户设备包括: 发射器 1601、 接收器 1602和处理器 1603;
其中,发射器 1601用于在应用所在的 UE通过近距离服务器的认证之 后, 且在所述 UE上的应用启动使用近距离服务时, 向 MME发送第一授 权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应用的标 识和所述应用的用户标识, 所述第一授权请求用于使所述 MME向近距离 服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所 述 UE中应用的标识和所述应用的用户标识的授权信息;
接收器 1602用于在所述发射器 1601发送所述第一授权请求之后, 且 在所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标 识和所述应用的用户标识的授权信息, 则接收所述 MME发送的通过应答 消息, 所述通过应答消息为所述 MME接收所述近距离服务器发送授权通 过应答消息之后发送的;
所述发射器 1601还用于在所述接收器 1602接收所述通过应答消息之 后, 向应用服务器发起认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务器为所述 UE 分配的使用近距离服务的第一标识符和所述近距离服务器的第二标识符; 所述接收器 1602还用于在所述发射器 1601发送所述认证请求之后, 接收所述应用服务器发送的认证通过消息, 所述认证通过消息为所述应用 服务器根据所述认证请求和所述近距离服务器交互, 并确认所述 UE的应 用能够使用近距离服务之后发送的;
处理器 1603根据所述接收器 1602所接收的认证通过消息使所述应用 使用所述近距离服务。
在一种应用场景中, 所述发射器 1601还用于在发所述第一授权请求 之前, 向所述 MME发送用于向近距离服务器进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识; 以使所述 MME根据所述第一 注册请求向近距离服务器确定所述 UE的签约信息中是否有所述 UE使用 近距离服务的授权信息;
所述接收器 1602还用于在所述发射器 1601发送所述第一注册请求之 后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中有所 述授权信息, 则所述 UE接收所述 MME发送的通过响应消息, 所述通过 响应消息为所述 MME接收所述近距离服务器发送的注册通过响应消息之 后发送的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分配的 使用所述近距离服务的第一标识符和所述近距离服务器的第二标识符。
举例来说, 所述第一注册请求携带在网络附着消息中, 或者, 携带在 位置更新消息中, 或者, 携带在非接入层消息中, 或者, 携带在接入层消 息中。
上述用户设备实现了运营商对用户设备中使用近距离服务的应用的 细化管理, 同时提高了用户使用用户设备的体验性。
本领域普通技术人员可以理解: 附图只是一个实施例的示意图, 附图 中的模块或流程并不一定是实施本发明所必须的。
本领域普通技术人员可以理解: 实现上述方法实施例的全部或部分步 骤可以通过程序指令相关的硬件来完成, 前述程序可以存储于一计算机可 读取存储介质中, 该程序在执行时, 执行包括上述方法实施例的步骤; 而 前述的存储介质包括: ROM、 RAM, 磁碟或者光盘等各种可以存储程序 代码的介质。
最后应说明的是: 以上各实施例仅用以说明本发明的技术方案, 而非 对其限制; 尽管参照前述各实施例对本发明进行了详细的说明, 本领域的 普通技术人员应当理解: 其依然可以对前述各实施例所记载的技术方案进 行修改, 或者对其中部分或者全部技术特征进行等同替换; 而这些修改或 者替换, 并不使相应技术方案的本质脱离本发明各实施例技术方案的范 围。

Claims

权 利 要 求 书
1、 一种近距离服务的认证与授权的方法, 其特征在于, 包括: 在应用所在的用户设备 UE通过近距离服务器的认证之后, 且在所述 UE上的应用启动使用近距离服务时, 移动性管理实体 MME接收所述 UE 发送的第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE 中应用的标识和所述应用的用户标识;
所述 MME根据所述第一授权请求向所述近距离服务器发送第二授权 请求, 所述第二授权请求包括所述 UE的标识、 所述 UE中应用的标识, 所述应用的用户标识; 所述第二授权请求用于使所述近距离服务器根据所 述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用 的标识和所述应用的用户标识对应的使用近距离服务的授权信息;
若所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用 的标识和所述应用的用户标识对应的授权信息, 则所述 MME接收所述近 距离服务器根据所述第二授权请求发送的授权通过应答消息;
所述 MME根据所述授权通过应答消息向所述 UE发送通过应答消息 , 以使所述 UE根据所述通过应答消息向应用服务器发起认证请求。
2、 根据权利要求 1所述的方法, 其特征在于, 所述 MME接收所述 UE发送的第一授权请求的步骤之前, 还包括:
所述 MME接收所述 UE发送的用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述 MME根据所述第一注册请求向近距离服务器发送第二注册请 求, 所述第二注册请求包括: 所述 UE的标识, 所述第二注册请求用于使 所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE 的签约信息中是否有与所述 UE的标识对应的 UE使用近距离服务的授权 信息;
若所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 授权信息,则所述 MME接收所述近距离服务器发送的注册通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所 述近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述 MME根据所述注册通过响应消息向所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一标识符和所述第二标识符。
3、 根据权利要求 1所述的方法, 其特征在于, 所述 MME接收所述 UE发送的第一授权请求的步骤之前, 还包括:
所述 MME接收所述 UE发送的用于向近距离服务器进行注册的第一 注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述 MME根据所述 UE的标识, 向归属用户服务器 HSS获取与所述 UE的标识对应的 UE的签约信息;
若所述 MME确定所述 UE的签约信息中有所述 UE的标识对应的 UE 使用近距离服务的授权信息; 则所述 MME向所述近距离服务器发送第三 注册请求, 所述第三注册请求包括: 所述 UE的标识和所述 UE的签约信 息;
所述 MME接收所述近距离服务器根据所述第三注册请求发送的注册 通过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述近距离服务器的第二 标识符;
所述 MME根据所述注册通过响应消息向所述 UE发送通过响应消息 , 所述通过响应消息包括所述第一标识符和所述第二标识符。
4、 根据权利要求 1所述的方法, 其特征在于, 还包括:
若所述近距离服务器确定所述 UE的签约信息中无所述授权信息, 则 所述 MME接收所述近距离服务器根据所述第二授权请求发送的拒绝授权 的应答消息;
所述 MME根据所述拒绝授权的应答消息向所述 UE发送拒绝应答消 息。
5、 根据权利要求 2或 3所述的方法, 其特征在于, 所述第一注册请 求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
6、 一种近距离服务的认证与授权的方法, 其特征在于, 包括: 应用服务器接收用户设备 UE发送的认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离 服务器为所述 UE分配的使用近距离服务的第一标识符和所述近距离服务 器的第二标识符;
所述应用服务器根据所述第二标识符向所述近距离服务器发送第一 确认请求, 所述第一确认请求包括: 所述 UE的标识、 所述 UE中应用的 标识、 所述应用的用户标识和所述第一标识符, 所述第一确认请求用于使 所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE 的签约信息中是否有所述应用的标识、 所述应用的用户标识和所述第一标 识符对应的 UE使用近距离服务的授权信息;
若所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 授权信息, 所述应用服务器接收所述近距离服务器发送的授权通过的确认 应答;
所述应用服务器根据所述授权通过的确认应答向所述 UE发送认证通 过消息, 以使所述 UE根据所述认证通过消息使所述应用使用所述近距离 服务。
7、 根据权利要求 6所述的方法, 其特征在于, 还包括:
若所述近距离服务器根据所述 UE的标识确定所述签约信息中无所述 授权信息, 则所述应用服务器接收所述近距离服务器发送的拒绝消息, 所 述应用服务器根据所述拒绝消息向所述 UE发送认证拒绝消息。
8、 一种近距离服务的认证与授权的方法, 其特征在于, 包括: 近距离服务器对应用所在的用户设备 UE认证之后, 所述 UE上的应 用启动使用近距离服务时, 所述近距离服务器接收移动性管理实体 MME 发送的第二授权请求, 所述第二授权请求为所述 MME接收所述 UE发送 的第一授权请求之后发送的,且所述第二授权请求包括: 所述 UE的标识, 所述 UE中应用的标识, 所述应用的用户标识;
所述近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信 息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近 距离服务的授权信息;
若所述 UE的签约信息中有所述 UE中应用的标识和所述应用的用户 标识对应的使用近距离服务的授权信息, 则所述近距离服务器向所述 MME发送授权通过应答消息, 以使所述 MME根据所述授权通过应答消 息向所述 UE发送通过应答消息。
9、 根据权利要求 8所述的方法, 其特征在于, 所述近距离服务器接 收 MME发送的第二授权请求的步骤之前, 还包括:
所述近距离服务器接收所述 MME发送的第二注册请求, 所述第二注 册请求为所述 MME在接收所述 UE发送的第一注册请求之后发送的, 所 述第二注册请求包括: 所述 UE的标识;
所述近距离服务器根据所述 UE的标识向归属用户服务器 HSS获取所 述 UE的标识对应的 UE的签约信息;
所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 UE授权使用近距离服务的授权信息; 则向所述 MME发送注册通过响应 消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的 使用所述近距离服务的第一标识符和所述近距离服务器的第二标识符, 以 使所述 MME向 UE发送包括所述第一标识符和所述第二标识符的通过响 应消息。
10、 根据权利要求 8所述的方法, 其特征在于, 所述近距离服务器接 收 MME发送的第二授权请求的步骤之前, 还包括:
所述近距离服务器接收所述 MME发送的第三注册请求, 所述第三注 册请求包括: 所述 UE的标识和所述 UE的签约信息;
所述第三注册请求为所述 MME在接收所述 UE发送的第一注册请求 , 且根据所述第一注册请求中 UE的标识向 HSS获取 UE的签约信息, 并确 定所述签约信息中有所述 UE的标识对应的 UE使用近距离服务的授权信 息之后发送的;
所述近距离服务器存储所述 UE的签约信息, 并根据所述第三注册请 求向所述 MME发送注册通过响应消息, 所述注册通过响应消息包括: 所 述近距离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所 述近距离服务器的第二标识符, 以使所述 MME向 UE发送包括所述第一 标识符和第二标识符的通过响应消息。
11、 根据权利要求 8所述的方法, 其特征在于, 还包括:
若所述近距离服务器确定所述 UE的签约信息中无所述 UE中应用的 标识和所述应用的用户标识对应使用近距离服务的授权信息, 则向所述 MME发送所述第二授权请求的拒绝授权的应答消息, 以使所述 MME根 据所述拒绝授权的应答消息向所述 UE发送拒绝应答消息。
12、 一种近距离服务的认证与授权的方法, 其特征在于, 包括: 在应用所在的用户设备 UE通过近距离服务器的认证之后, 且在所述 UE上的应用启动使用近距离服务时,所述 UE向移动性管理实体 MME发 送第一授权请求, 所述第一授权请求包括: 所述 UE的标识, 所述 UE中 应用的标识和所述应用的用户标识; 所述第一授权请求用于使所述 MME 向近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用的标识和所述应用的用户标识的授权信息;
若所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用 的标识和所述应用的用户标识的授权信息, 则所述 UE接收所述 MME发 送的通过应答消息, 所述通过应答消息为所述 MME接收所述近距离服务 器发送授权通过应答消息之后发送的;
所述 UE在接收所述通过应答消息之后,向应用服务器发起认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用 的用户标识、 近距离服务器为所述 UE分配的使用近距离服务的第一标识 符和所述近距离服务器的第二标识符;
所述 UE接收所述应用服务器发送的认证通过消息, 所述认证通过消 息为所述应用服务器根据所述认证请求和所述近距离服务器交互, 并确认 所述 UE的应用能够使用近距离服务之后发送的;
所述 UE根据所述认证通过消息使所述应用使用所述近距离服务。
13、 根据权利要求 12所述的方法, 其特征在于, 所述 UE向 MME发 送第一授权请求的步骤之前, 还包括:
所述 UE向所述 MME发送用于向近距离服务器进行注册的第一注册 请求, 所述第一注册请求包括: 所述 UE的标识; 以使所述 MME根据所 述第一注册请求向近距离服务器确定所述 UE的签约信息中是否有所述 UE使用近距离服务的授权信息;
若所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述 授权信息, 则所述 UE接收所述 MME发送的通过响应消息, 所述通过响 应消息为所述 MME接收所述近距离服务器发送的注册通过响应消息之后 发送的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分配的使 用所述近距离服务的第一标识符和所述近距离服务器的第二标识符。
14、 根据权利要求 12或 13所述的方法, 其特征在于, 所述第一注册 请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
15、 一种移动性管理实体, 其特征在于, 包括:
接收单元, 用于在应用所在的用户设备 UE通过近距离服务器的认证 之后, 且在所述 UE上的应用启动使用近距离服务时, 接收所述 UE发送 的第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中 应用的标识和所述应用的用户标识;
发送单元, 用于根据所述接收单元所接收的第一授权请求向所述近距 离服务器发送第二授权请求, 所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述应用的用户标识; 所述第二授权请求用于使 所述近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服 务的授权信息;
所述接收单元, 用于在所述发送单元发送所述第二授权请求之后, 在 所述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识 和所述应用的用户标识对应的授权信息的情况下, 接收所述近距离服务器 根据所述第二授权请求发送的授权通过应答消息;
所述发送单元, 用于根据所述接收单元接收的所述授权通过应答消息 向所述 UE发送通过应答消息, 以使所述 UE根据所述通过应答消息向应 用服务器发起认证请求。
16、 根据权利要求 15所述的移动性管理实体, 其特征在于, 所述接 收单元, 还用于在接收所述第一授权请求之前, 接收所述 UE发送的用于 向近距离服务器进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述发送单元, 还用于根据所述接收单元接收的第一注册请求向近距 离服务器发送第二注册请求, 所述第二注册请求包括: 所述 UE的标识, 所述第二注册请求用于使所述近距离服务器根据所述 UE的标识确定与所 述 UE的标识对应的 UE的签约信息中是否有与所述 UE的标识对应的 UE 使用近距离服务的授权信息;
所述接收单元, 还用于在所述近距离服务器根据所述 UE的标识确定 所述签约信息中有所述授权信息时, 接收所述近距离服务器发送的注册通 过响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE 分配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标 识符;
所述发送单元, 还用于根据所述接收单元接收的所述注册通过响应消 息向所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一标识 符和所述第二标识符。
17、 根据权利要求 15所述的移动性管理实体, 其特征在于, 所述接 收单元, 还用于在接收所述第一授权请求之前, 接收所述 UE发送的用于 向近距离服务器进行注册的第一注册请求, 所述第一注册请求包括: 所述
UE的标识;
所述移动性管理实体还包括:
获取单元, 用于在所述接收单元接收所述第一注册请求之后, 根据所 述 UE的标识向归属用户服务器 HSS获取与所述 UE的标识对应的 UE的 签约信息;
确定单元, 用于确定所述 UE的签约信息中是否有所述 UE的标识对 应的 UE使用近距离服务的授权信息;
所述发送单元, 还用于在所述确定单元确定所述 UE的签约信息中有 所述 UE的标识对应的 UE使用近距离服务的授权信息之后, 向所述近距 离服务器发送第三注册请求, 所述第三注册请求包括: : 所述 UE的标识 和所述 UE的签约信息;
所述接收单元, 用于在所述发送单元发送所述第三注册请求之后, 接 收所述近距离服务器根据所述第三注册请求发送的注册通过响应消息, 所 述注册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述 近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述发送单元, 用于根据所述接收单元接收的所述注册通过响应消息 向所述 UE发送通过响应消息, 所述通过响应消息包括所述第一标识符和 所述第二标识符。
18、 根据权利要求 15所述的移动性管理实体, 其特征在于, 所述接收单元, 还用于在所述近距离服务器确定所述 UE的签约信息 中无所述授权信息, 则接收所述近距离服务器根据所述第二授权请求发送 的拒绝授权的应答消息;
所述发送单元, 还用于根据所述接收单元接收的所述拒绝授权的应答 消息向所述 UE发送拒绝应答消息。
19、 根据权利要求 16或 17所述的移动性管理实体, 其特征在于, 所 述第一注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
20、 一种应用服务器, 其特征在于, 包括:
接收单元, 用于接收用户设备 UE发送的认证请求, 所述认证请求包 括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近 距离服务器为所述 UE分配的使用近距离服务的第一标识符和所述近距离 服务器的第二标识符;
发送单元, 用于在接收单元接收所述认证请求之后, 根据所述第二标 识符向所述近距离服务器发送第一确认请求, 所述第一确认请求包括: 所 述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识和所述第一 标识符, 所述第一确认请求用于使所述近距离服务器根据所述 UE的标识 确定与所述 UE的标识对应的 UE的签约信息中是否有所述应用的标识、 所述应用的用户标识和所述第一标识符对应的 UE使用近距离服务的授权 信息;
所述接收单元, 还用于在所述发送单元发送所述第一确认请求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授 权信息时, 接收所述近距离服务器发送的授权通过的确认应答;
所述发送单元, 还用于在接收单元接收所述授权通过的确认应答之 后, 根据所述授权通过的确认应答向所述 UE发送认证通过消息, 以使所 述 UE根据所述认证通过消息使所述应用使用所述近距离服务。
21、 根据权利要求 20所述的应用服务器, 其特征在于,
所述接收单元, 还用于在所述发送单元发送所述第一确认请求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中无所述授 权信息时, 接收所述近距离服务器发送的拒绝消息;
所述发送单元, 还用于在所述接收单元接收所述拒绝消息之后, 根据 所述拒绝消息向所述 UE发送认证拒绝消息。
22、 一种近距离服务器, 其特征在于, 包括:
接收单元 ,用于在近距离服务器对应用所在的用户设备 UE认证之后 , 所述 UE上的应用启动使用近距离服务时, 接收移动性管理实体 ΜΜΕ发 送的第二授权请求, 所述第二授权请求为所述 ΜΜΕ接收所述 UE发送的 第一授权请求之后发送的, 且所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述应用的用户标识;
查找单元, 用于在所述接收单元接收所述第二授权请求之后, 根据所 述 UE的标识查找存储的所述 UE的签约信息中, 是否有所述 UE中应用 的标识和所述应用的用户标识对应的使用近距离服务的授权信息;
发送单元, 用于在所述查找单元查找到所述 UE的签约信息中有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务的授权信 息, 则向所述 ΜΜΕ发送授权通过应答消息, 以使所述 ΜΜΕ根据所述授 权通过应答消息向所述 UE发送通过应答消息。
23、 根据权利要求 22所述的近距离服务器, 其特征在于, 所述接收 单元, 还用于在接收所述第二授权请求之前, 还接收所述 ΜΜΕ发送的第 二注册请求, 所述第二注册请求为所述 ΜΜΕ在接收所述 UE发送的第一 注册请求之后发送的, 所述第二注册请求包括: 所述 UE的标识;
所述近距离服务器还包括:
获取单元, 用于在所述接收单元接收所述第二注册请求之后, 根据所 述 UE的标识向归属用户服务器 HSS获取所述 UE的标识对应的 UE的签 约信息;
确定单元, 用于在所述获取单元获取所述 UE的签约信息之后, 根据 所述 UE的标识确定所述签约信息中有所述 UE授权使用近距离服务的授 权信息;
所述发送单元, 还用于在所述确定单元确定有所述授权信息时, 向所 述 ΜΜΕ发送注册通过响应消息, 所述注册通过响应消息包括: 所述近距 离服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述近距 离服务器的第二标识符, 以使所述 MME向 UE发送包括所述第一标识符 和所述第二标识符的通过响应消息。
24、 根据权利要求 22所述的近距离服务器, 其特征在于, 所述接收 单元, 还用于在接收所述第二授权请求之前, 接收所述 MME发送的第三 注册请求, 所述第三注册请求包括: 所述 UE的标识和所述 UE的签约信 息;所述第三注册请求为所述 MME在接收所述 UE发送的第一注册请求, 且根据所述第一注册请求中 UE的标识向 HSS获取 UE的签约信息, 并确 定所述签约信息中有所述 UE的标识对应的 UE使用近距离服务的授权信 息之后发送的;
所述近距离服务器, 还包括:
存储单元, 用于在所述接收单元接收所述第三注册请求之后, 存储所 述 UE的签约信息;
发送单元, 用于在所述存储单元存储所述 UE的签约信息之后, 根据 所述第三注册请求向所述 MME发送注册通过响应消息, 所述注册通过响 应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的 第一标识符和所述近距离服务器的第二标识符, 以使所述 MME向 UE发 送包括所述第一标识符和所述第二标识符的通过响应消息。
25、 根据权利要求 22所述的近距离服务器, 其特征在于,
发送单元, 还用于在所述查找单元未查找到所述 UE的签约信息中有 所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务的授 权信息, 则向所述 MME发送所述第二授权请求的拒绝授权的应答消息, 以使所述 MME根据所述拒绝授权的应答消息向所述 UE发送拒绝应答消 息。
26、 一种用户设备, 其特征在于, 包括:
发送单元, 用于在应用所在的用户设备 UE通过近距离服务器的认证 之后, 且在所述 UE上的应用启动使用近距离服务时, 向移动性管理实体 MME发送第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所 述 UE中应用的标识和所述应用的用户标识, 所述第一授权请求用于使所 述 MME向近距离服务器根据所述 UE的标识查找存储的所述 UE的签约 信息中,是否有所述 UE中应用的标识和所述应用的用户标识的授权信息; 接收单元, 用于在所述发送单元发送所述第一授权请求之后, 且在所 述近距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识和 所述应用的用户标识的授权信息 ,则接收所述 MME发送的通过应答消息 , 所述通过应答消息为所述 MME接收所述近距离服务器发送授权通过应答 消息之后发送的;
所述发送单元, 还用于在所述接收单元接收所述通过应答消息之后, 向应用服务器发起认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离服务器为所述 UE分配 的使用近距离服务的第一标识符和所述近距离服务器的第二标识符;
所述接收单元, 还用于在所述发送单元发送所述认证请求之后, 接收 所述应用服务器发送的认证通过消息, 所述认证通过消息为所述应用服务 器根据所述认证请求和所述近距离服务器交互, 并确认所述 UE的应用能 够使用近距离服务之后发送的;
使用单元, 根据所述认证通过消息使所述应用使用所述近距离服务。
27、 根据权利要求 26所述的用户设备, 其特征在于,
所述发送单元, 还用于在发所述第一授权请求之前, 向所述 MME发 送用于向近距离服务器进行注册的第一注册请求, 所述第一注册请求包 括: 所述 UE的标识; 以使所述 MME根据所述第一注册请求向近距离服 务器确定所述 UE的签约信息中是否有所述 UE使用近距离服务的授权信 息;
所述接收单元, 还用于在所述发送单元发送所述第一注册请求之后, 且在所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授 权信息, 则所述 UE接收所述 MME发送的通过响应消息, 所述通过响应 消息为所述 MME接收所述近距离服务器发送的注册通过响应消息之后发 送的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分配的使用 所述近距离服务的第一标识符和所述近距离服务器的第二标识符。
28、 根据权利要求 26或 27所述的用户设备, 其特征在于, 所述第一 注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
29、 一种移动性管理实体, 其特征在于, 包括:
接收器, 用于在应用所在的用户设备 UE通过近距离服务器的认证之 后, 且在所述 UE上的应用启动使用近距离服务时, 接收所述 UE发送的 第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所述 UE中应 用的标识和所述应用的用户标识;
发射器, 用于根据所述接收器所接收的第一授权请求向所述近距离服 务器发送第二授权请求, 所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述应用的用户标识; 所述第二授权请求用于使所述 近距离服务器根据所述 UE的标识查找存储的所述 UE的签约信息中, 是 否有所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务 的授权信息;
所述接收器, 用于在所述发射器发送所述第二授权请求之后, 在所述 近距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识和所 述应用的用户标识对应的授权信息的情况下, 接收所述近距离服务器根据 所述第二授权请求发送的授权通过应答消息;
所述发射器, 用于根据所述接收器接收的所述授权通过应答消息向所 述 UE发送通过应答消息, 以使所述 UE根据所述通过应答消息向应用服 务器发起认证请求。
30、 根据权利要求 29所述的移动性管理实体, 其特征在于, 所述接 收器, 还用于在接收所述第一授权请求之前, 接收所述 UE发送的用于向 近距离服务器进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述发射器, 还用于根据所述接收器接收的第一注册请求向近距离服 务器发送第二注册请求, 所述第二注册请求包括: 所述 UE的标识, 所述 第二注册请求用于使所述近距离服务器根据所述 UE的标识确定与所述 UE的标识对应的 UE的签约信息中是否有与所述 UE的标识对应的 UE使 用近距离服务的授权信息;
所述接收器, 还用于在所述近距离服务器根据所述 UE的标识确定所 述签约信息中有所述授权信息时, 接收所述近距离服务器发送的注册通过 响应消息, 所述注册通过响应消息包括: 所述近距离服务器为所述 UE分 配的使用所述近距离服务的第一标识符和所述近距离服务器的第二标识 付;
所述发射器, 还用于根据所述接收器接收的所述注册通过响应消息向 所述 UE发送通过响应消息, 所述通过响应消息包括: 所述第一标识符和 所述第二标识符。
31、 根据权利要求 29所述的移动性管理实体, 其特征在于, 所述接 收器, 还用于在接收所述第一授权请求之前, 接收所述 UE发送的用于向 近距离服务器进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识;
所述移动性管理实体还包括:
处理器, 用于在所述接收器接收所述第一注册请求之后, 根据所述 UE的标识向归属用户服务器 HSS获取与所述 UE的标识对应的 UE的签 约信息, 并确定所述 UE的签约信息中是否有所述 UE的标识对应的 UE 使用近距离服务的授权信息;
所述发射器, 还用于在所述处理器确定所述 UE的签约信息中有所述
UE的标识对应的 UE使用近距离服务的授权信息之后, 向所述近距离服 务器发送第三注册请求, 所述第三注册请求包括: 所述 UE的标识和所述 UE的签约信息;
所述接收器, 用于在所述发射器发送所述第三注册请求之后, 接收所 述近距离服务器根据所述第三注册请求发送的注册通过响应消息, 所述注 册通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距 离服务的第一标识符和所述近距离服务器的第二标识符;
所述发射器, 用于根据所述接收器接收的所述注册通过响应消息向所 述 UE发送通过响应消息, 所述通过响应消息包括所述第一标识符和所述 第二标识符。
32、 根据权利要求 29所述的移动性管理实体, 其特征在于, 所述接收器, 还用于在所述近距离服务器确定所述 UE的签约信息中 无所述授权信息, 则接收所述近距离服务器根据所述第二授权请求发送的 拒绝授权的应答消息;
所述发射器, 还用于根据所述接收器接收的所述拒绝授权的应答消息 向所述 UE发送拒绝应答消息。
33、 根据权利要求 30或 31所述的移动性管理实体, 其特征在于, 所 述第一注册请求携带在以下消息之一中: 网络附着消息、 位置更新消息、 非接入层消息、 和接入层消息。
34、 一种应用服务器, 其特征在于, 包括:
接收器,用于接收用户设备 UE发送的认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE中应用的标识、 所述应用的用户标识、 近距离 服务器为所述 UE分配的使用近距离服务的第一标识符和所述近距离服务 器的第二标识符;
发射器, 用于在接收器接收所述认证请求之后, 根据所述第二标识符 向所述近距离服务器发送第一确认请求, 所述第一确认请求包括: 所述
UE的标识、 所述 UE中应用的标识、 所述应用的用户标识和所述第一标 识符, 所述第一确认请求用于使所述近距离服务器根据所述 UE的标识确 定与所述 UE的标识对应的 UE的签约信息中是否有所述应用的标识、 所 述应用的用户标识和所述第一标识符对应的 UE使用近距离服务的授权信 息;
所述接收器, 还用于在所述发射器发送所述第一确认请求之后, 且在 所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授权信 息时, 接收所述近距离服务器发送的授权通过的确认应答;
所述发射器, 还用于在接收器接收所述授权通过的确认应答之后, 根 据所述授权通过的确认应答向所述 UE发送认证通过消息, 以使所述 UE 根据所述认证通过消息使所述应用使用所述近距离服务。
35、 根据权利要求 34所述的应用服务器, 其特征在于,
所述接收器, 还用于在所述发射器发送所述第一确认请求之后, 且在 所述近距离服务器根据所述 UE的标识确定所述签约信息中无所述授权信 息时, 接收所述近距离服务器发送的拒绝消息;
所述发射器, 还用于在所述接收器接收所述拒绝消息之后, 根据所述 拒绝消息向所述 UE发送认证拒绝消息。
36、 一种近距离服务器, 其特征在于, 包括:
接收器, 用于在近距离服务器对应用所在的用户设备 UE认证之后, 所述 UE上的应用启动使用近距离服务时, 接收移动性管理实体 MME发 送的第二授权请求, 所述第二授权请求为所述 MME接收所述 UE发送的 第一授权请求之后发送的, 且所述第二授权请求包括: 所述 UE的标识、 所述 UE中应用的标识和所述应用的用户标识;
处理器, 用于在所述接收器接收所述第二授权请求之后, 根据所述
UE的标识查找存储的所述 UE的签约信息中,是否有所述 UE中应用的标 识和所述应用的用户标识对应的使用近距离服务的授权信息;
发射器, 用于在所述处理器查找到所述 UE的签约信息中有所述 UE 中应用的标识和所述应用的用户标识对应的使用近距离服务的授权信息, 则向所述 MME发送授权通过应答消息, 以使所述 MME根据所述授权通 过应答消息向所述 UE发送通过应答消息。
37、 根据权利要求 36所述的近距离服务器, 其特征在于, 所述接收 器, 还用于在接收所述第二授权请求之前, 还接收所述 MME发送的第二 注册请求, 所述第二注册请求为所述 MME在接收所述 UE发送的第一注 册请求之后发送的, 所述第二注册请求包括: 所述 UE的标识;
所述处理器, 用于在所述接收器接收所述第二注册请求之后, 根据所 述 UE的标识向归属用户服务器 HSS获取所述 UE的标识对应的 UE的签 约信息, 根据所述 UE的标识确定所述签约信息中有所述 UE授权使用近 距离服务的授权信息;
所述发射器, 还用于在所述处理器确定有所述授权信息时, 向所述
MME发送注册通过响应消息, 所述注册通过响应消息包括: 所述近距离 服务器为所述 UE分配的使用所述近距离服务的第一标识符和所述近距离 服务器的第二标识符, 以使所述 MME向 UE发送包括所述第一标识符和 所述第二标识符的通过响应消息。
38、 根据权利要求 36所述的近距离服务器, 其特征在于, 所述接收 器, 还用于在接收所述第二授权请求之前, 接收所述 MME发送的第三注 册请求, 所述第三注册请求包括: 所述 UE的标识和所述 UE的签约信息; 所述第三注册请求为所述 MME在接收所述 UE发送的第一注册请求, 且 根据所述第一注册请求中 UE的标识向 HSS获取 UE的签约信息, 并确定 所述签约信息中有所述 UE的标识对应的 UE使用近距离服务的授权信息 之后发送的;
所述处理器, 用于在所述接收器接收所述第三注册请求之后, 存储所 述 UE的签约信息;
所述发射器, 用于在所述处理器存储所述 UE的签约信息之后, 根据 所述第三注册请求向所述 MME发送注册通过响应消息, 所述注册通过响 应消息包括: 所述近距离服务器为所述 UE分配的使用所述近距离服务的 第一标识符和所述近距离服务器的第二标识符, 以使所述 MME向 UE发 送包括所述第一标识符和所述第二标识符的通过响应消息。
39、 根据权利要求 36所述的近距离服务器, 其特征在于,
所述发射器, 还用于在所述处理器未查找到所述 UE的签约信息中有 所述 UE中应用的标识和所述应用的用户标识对应的使用近距离服务的授 权信息, 则向所述 MME发送所述第二授权请求的拒绝授权的应答消息, 以使所述 MME根据所述拒绝授权的应答消息向所述 UE发送拒绝应答消 息。
40、 一种用户设备, 其特征在于, 包括:
发射器, 用于在应用所在的用户设备 UE通过近距离服务器的认证之 后, 且在所述 UE上的应用启动使用近距离服务时, 向移动性管理实体 MME发送第一授权请求, 所述第一授权请求包括: 所述 UE的标识、 所 述 UE中应用的标识和所述应用的用户标识, 所述第一授权请求用于使所 述 MME向近距离服务器根据所述 UE的标识查找存储的所述 UE的签约 信息中,是否有所述 UE中应用的标识和所述应用的用户标识的授权信息; 接收器, 用于在所述发射器发送所述第一授权请求之后, 且在所述近 距离服务器确定所述 UE的签约信息中具有所述 UE中应用的标识和所述 应用的用户标识的授权信息, 则接收所述 MME发送的通过应答消息, 所 述通过应答消息为所述 MME接收所述近距离服务器发送授权通过应答消 息之后发送的;
所述发射器, 还用于在所述接收器接收所述通过应答消息之后, 向应 用服务器发起认证请求, 所述认证请求包括: 所述 UE的标识、 所述 UE 中应用的标识、 所述应用的用户标识、 近距离服务器为所述 UE分配的使 用近距离服务的第一标识符和所述近距离服务器的第二标识符; 所述接收器, 还用于在所述发射器发送所述认证请求之后, 接收所述 应用服务器发送的认证通过消息, 所述认证通过消息为所述应用服务器根 据所述认证请求和所述近距离服务器交互, 并确认所述 UE的应用能够使 用近距离服务之后发送的;
处理器, 根据所述接收器所接收的认证通过消息使所述应用使用所述 近距离服务。
41、 根据权利要求 40所述的用户设备, 其特征在于,
所述发射器, 还用于在发所述第一授权请求之前, 向所述 MME发送 用于向近距离服务器进行注册的第一注册请求, 所述第一注册请求包括: 所述 UE的标识; 以使所述 MME根据所述第一注册请求向近距离服务器 确定所述 UE的签约信息中是否有所述 UE使用近距离服务的授权信息; 所述接收器, 还用于在所述发射器发送所述第一注册请求之后, 且在 所述近距离服务器根据所述 UE的标识确定所述签约信息中有所述授权信 息, 则所述 UE接收所述 MME发送的通过响应消息, 所述通过响应消息 为所述 MME接收所述近距离服务器发送的注册通过响应消息之后发送 的, 所述通过响应消息包括: 所述近距离服务器为所述 UE分配的使用所 述近距离服务的第一标识符和所述近距离服务器的第二标识符。
42、 根据权利要求 40或 41所述的用户设备, 其特征在于, 所述第一 注册请求携带在以下消息之一中:
网络附着消息、 位置更新消息、 非接入层消息和接入层消息。
PCT/CN2012/086541 2012-12-13 2012-12-13 近距离服务的认证与授权的方法及设备 WO2014089804A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201280036016.7A CN104012035B (zh) 2012-12-13 2012-12-13 近距离服务的认证与授权的方法及设备
PCT/CN2012/086541 WO2014089804A1 (zh) 2012-12-13 2012-12-13 近距离服务的认证与授权的方法及设备

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2012/086541 WO2014089804A1 (zh) 2012-12-13 2012-12-13 近距离服务的认证与授权的方法及设备

Publications (1)

Publication Number Publication Date
WO2014089804A1 true WO2014089804A1 (zh) 2014-06-19

Family

ID=50933715

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/086541 WO2014089804A1 (zh) 2012-12-13 2012-12-13 近距离服务的认证与授权的方法及设备

Country Status (2)

Country Link
CN (1) CN104012035B (zh)
WO (1) WO2014089804A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2524497A (en) * 2014-03-24 2015-09-30 Vodafone Ip Licensing Ltd User equipment proximity requests
WO2015196704A1 (zh) * 2014-06-24 2015-12-30 中兴通讯股份有限公司 处理prose业务授权变化的方法、第一网元、第二网元

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016045132A1 (zh) * 2014-09-28 2016-03-31 华为技术有限公司 Ue授权验证方法、近距离业务功能实体、服务器及系统
CN113748694A (zh) * 2019-04-26 2021-12-03 瑞典爱立信有限公司 用于服务发现的方法和装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101478405A (zh) * 2009-02-02 2009-07-08 中国网络通信集团公司 认证授权方法、服务器及系统
CN102595373A (zh) * 2011-01-14 2012-07-18 中兴通讯股份有限公司 一种对mtc终端进行移动性管理的方法和系统
CN102655637A (zh) * 2011-03-01 2012-09-05 中兴通讯股份有限公司 一种移动通信系统和组网方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101478405A (zh) * 2009-02-02 2009-07-08 中国网络通信集团公司 认证授权方法、服务器及系统
CN102595373A (zh) * 2011-01-14 2012-07-18 中兴通讯股份有限公司 一种对mtc终端进行移动性管理的方法和系统
CN102655637A (zh) * 2011-03-01 2012-09-05 中兴通讯股份有限公司 一种移动通信系统和组网方法

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2524497A (en) * 2014-03-24 2015-09-30 Vodafone Ip Licensing Ltd User equipment proximity requests
WO2015196704A1 (zh) * 2014-06-24 2015-12-30 中兴通讯股份有限公司 处理prose业务授权变化的方法、第一网元、第二网元
CN105228124A (zh) * 2014-06-24 2016-01-06 中兴通讯股份有限公司 处理ProSe业务授权变化的方法、第一网元、第二网元
CN105228124B (zh) * 2014-06-24 2021-04-06 中兴通讯股份有限公司 处理ProSe业务授权变化的方法、第一网元、第二网元

Also Published As

Publication number Publication date
CN104012035A (zh) 2014-08-27
CN104012035B (zh) 2017-02-01

Similar Documents

Publication Publication Date Title
JP7062020B2 (ja) サービスインターフェースを個人化および/または調整するためのシステムおよび方法
CN110800331B (zh) 网络验证方法、相关设备及系统
US8275355B2 (en) Method for roaming user to establish security association with visited network application server
TWI645724B (zh) 用於使用特定於應用的網路存取身份碼來進行到無線網路的受贊助連接的設備和方法(二)
WO2015101125A1 (zh) 网络接入控制方法和设备
US9113332B2 (en) Method and device for managing authentication of a user
EP2534864B1 (en) Seamless mobile subscriber identification
EP2571204B1 (en) Method for accessing instant messaging service system store server and instant messaging service system
US20090319611A1 (en) Method and System for Facilitating Exchange of A Data Between Applications Using a Communication Platform
WO2019042378A1 (zh) 提供用户身份信息的方法、系统及存储介质
EP2534889B1 (en) Method and apparatus for redirecting data traffic
CN105981345B (zh) Wi-fi/分组核心网接入的合法侦听
JP2007180998A (ja) 無線網制御装置及び無線網制御システム
KR101929868B1 (ko) 연결 확립 방법, 장치, 및 시스템
WO2015032253A1 (zh) 业务权限确定方法和装置
WO2014005267A1 (zh) 接入移动网络的方法、装置及系统
TWI516151B (zh) 通訊方法與通訊系統
WO2014089804A1 (zh) 近距离服务的认证与授权的方法及设备
US11171927B2 (en) Method for enabling establishment of a direct connection
WO2011131002A1 (zh) 身份管理方法及系统
WO2015021842A1 (zh) 访问ott应用、服务器推送消息的方法及装置
EP2640032A1 (en) Method and system for user authentication over a communication network
US20080141343A1 (en) Method, system and apparatus for access control
JP5445753B2 (ja) 通信システムにおけるネットワーク接続方法、管理方法および装置
WO2024021137A1 (zh) Api调用者认证方法以及装置、通信设备及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12889953

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12889953

Country of ref document: EP

Kind code of ref document: A1