WO2015196396A1 - 建立网络连接的方法、网关及终端 - Google Patents

建立网络连接的方法、网关及终端 Download PDF

Info

Publication number
WO2015196396A1
WO2015196396A1 PCT/CN2014/080751 CN2014080751W WO2015196396A1 WO 2015196396 A1 WO2015196396 A1 WO 2015196396A1 CN 2014080751 W CN2014080751 W CN 2014080751W WO 2015196396 A1 WO2015196396 A1 WO 2015196396A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
connection
wlan
gateway
connection selection
Prior art date
Application number
PCT/CN2014/080751
Other languages
English (en)
French (fr)
Inventor
靳维生
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201480036140.2A priority Critical patent/CN105393630B/zh
Priority to EP14895709.5A priority patent/EP3154306B1/en
Priority to PCT/CN2014/080751 priority patent/WO2015196396A1/zh
Publication of WO2015196396A1 publication Critical patent/WO2015196396A1/zh
Priority to US15/388,069 priority patent/US10432632B2/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/25Mapping addresses of the same type
    • H04L61/2503Translation of Internet protocol [IP] addresses
    • H04L61/2592Translation of Internet protocol [IP] addresses using tunnelling or encapsulation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/18Selecting a network or a communication service
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery
    • H04W48/14Access restriction or access information delivery, e.g. discovery data delivery using user query or user detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/02Terminal devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/08Access point devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/16Gateway arrangements

Definitions

  • the present invention relates to the field of information technology, and in particular, to a method, a gateway, and a terminal for establishing a network connection. Background technique
  • WLAN Wireless Local Area Network
  • the first way is to establish an IPsec (Internet Protocol Security) tunnel for the terminal connected to the WLAN, and then establish an IPsec security association control plane IKEv2 (Internet Key Exchange, Internet Key Exchange Protocol) and a terminal interactive mobile network. Connect information to establish a network connection.
  • the second method is: obtaining a subscription of a terminal connected to the WLAN, and assigning a mobile network address according to the subscription terminal of the terminal, so that the terminal accesses the mobile network according to the allocated mobile network address, thereby establishing a network connection.
  • an embodiment of the present invention provides a method, a gateway, and a terminal for establishing a network connection.
  • the technical solution is as follows:
  • a method for establishing a network connection comprising:
  • connection selection request includes connection selection information
  • the method before the establishing, connecting, and the user plane of the terminal, the method further includes:
  • the method further includes:
  • the terminal When the terminal disconnects the first WLAN corresponding to the first WLAN AP and reselects the second WLAN corresponding to the second WLAN AP, the terminal is authenticated;
  • the terminal is authorized, and the second terminal address is sent to the terminal, so that the terminal accesses the second WLAN corresponding to the second WLAN AP, and the terminal and the first The data packet identified by the second terminal address is transmitted between the two WLANs.
  • the method further includes:
  • the general packet radio service supports the node GGSN and establishes a bearer to the PGW or GGSN;
  • the method further includes:
  • a data packet identified by the first terminal address and a data packet identified by a terminal address accessing the initial service network are transmitted between the terminal and the initial service network by network address translation or network address and port translation.
  • the method further includes:
  • a sixth possible implementation manner of the foregoing aspect after determining, according to the connection selection information in the connection selection request, the service network selected by the terminal, Also includes:
  • the step of establishing a connection between the terminal and the service network selected by the terminal is performed.
  • connection selection request sent by the terminal includes:
  • connection selection information including alternatives to the terminal through the established user plane connection Connecting information, and receiving, by the established user plane connection, a connection selection request sent by the terminal according to the connection information;
  • connection selection request sent by the terminal according to the pre-configured connection selection information is received through the established user plane connection.
  • the method further includes:
  • connection selection context includes at least an identifier of the terminal, a service network selected by the terminal, and connection information; and the connection selection context is saved.
  • the saving the connection selection context includes:
  • connection selection context is saved within a preset age period.
  • the establishing, by the determining, the connection between the terminal and the service network selected by the terminal includes: determining whether Preserving the connection selection context corresponding to the terminal;
  • connection selection context corresponding to the terminal is saved, the service network selected by the terminal is determined according to the connection selection context corresponding to the terminal, and a connection between the terminal and the service network selected by the terminal is established.
  • a method for establishing a network connection includes:
  • connection selection request Sending a connection selection request to the gateway through the established user plane connection, where the connection selection request includes connection selection information;
  • a connection between the service networks corresponding to the connection selection information in the connection selection request is established by the gateway.
  • the establishing and the gateway Before the user plane is connected also includes:
  • the accessing the first WLAN includes:
  • the sending, by using the established user plane connection, the connection selection request to the gateway includes:
  • a connection selection request containing connection selection information selected by the user is sent to the gateway through the established user plane connection.
  • the sending, by using the established user plane connection, the connection selection request to the gateway includes:
  • the pre-configured connection selection information is obtained through the user interface, and a connection selection request including pre-configured connection selection information is sent to the gateway through the established user plane connection.
  • the method further includes:
  • a gateway receives, by the gateway, the second WLAN corresponding to the second WLAN AP, and after the gateway performs the successful authentication and authorization, receiving the second terminal address sent by the gateway, and connecting through the associated second WLAN AP And entering a second WLAN corresponding to the second WLAN AP, and transmitting, by the second WLAN, a data packet identified by the second terminal address.
  • a gateway is provided, where the gateway includes:
  • a first connection module configured to establish a user plane connection with the terminal, the terminal accessing the first WLAN
  • a receiving module configured to receive, by using the established user plane connection, a connection selection request sent by the terminal, where the connection selection request is Include connection selection information
  • a first determining module configured to determine, according to the connection selection information in the connection selection request, the service network selected by the terminal
  • a second connection module configured to establish a connection between the terminal and a service network selected by the terminal.
  • the gateway further includes:
  • a first authentication module configured to authenticate a terminal that requests access to the first WLAN corresponding to the first WLAN AP;
  • a first authorization module configured to authorize the terminal when the authentication succeeds
  • a first sending module configured to send a first terminal address to the terminal, to enable the terminal to access a first WLAN corresponding to the first WLAN AP;
  • a first transmission module configured to transmit, by the terminal, the data packet identified by the first terminal address between the terminal and the first WLAN.
  • the gateway further includes:
  • a second authentication module configured to: when the terminal disconnects the first WLAN corresponding to the first WLAN AP, and reselects to access the second WLAN corresponding to the second WLAN AP, Right
  • a second authorization module configured to authorize the terminal when the authentication succeeds
  • a second sending module configured to send a second terminal address to the terminal, to enable the terminal to access a second WLAN corresponding to the second WLAN AP;
  • a second transmission module configured to transmit the second between the terminal and the second WLAN The packet identified by the terminal address.
  • the gateway further includes:
  • a first acquiring module configured to acquire, from an initial service network, a terminal address allocated to the terminal for accessing an initial service network
  • a selection module configured to select a PGW or a GGSN for the terminal according to the subscription information of the terminal;
  • a first establishing module configured to establish a bearer to the PGW or the GGSN; and a terminal address of the initial service network.
  • a third transmission module configured to transmit a data packet identified by the first terminal address and a terminal address used to access an initial service network between the terminal and the initial service network by using network address translation or network address and port translation The identified packet.
  • An allocating module configured to allocate, to the terminal, a terminal address of a service network selected by the terminal;
  • a fourth transmission module configured to transmit, by using a network address translation or a network address and port translation, a data packet identified by the first terminal address between the terminal and a service network selected by the terminal, and selecting by using the terminal The service network's terminal address identifies the packet.
  • a second determining module configured to determine, according to the subscription information or network configuration of the terminal, whether to accept the terminal to connect to the service network
  • a second connecting module configured to perform a step of establishing a connection between the terminal and a service network selected by the terminal when the terminal is connected to the service network.
  • the receiving module is used to establish The user plane connection sends the connection information including the alternative connection selection information to the terminal, and receives the connection selection request sent by the terminal according to the connection information through the established user plane connection; or, the receiving module uses The connection selection request sent by the terminal according to the pre-configured connection selection information is received through the established user plane connection.
  • a second establishing module configured to establish, according to the connection selection request, a connection selection context corresponding to the terminal, where the connection selection context includes at least an identifier of the terminal, a service network selected by the terminal, and connection information;
  • a save module is configured to save the connection selection context.
  • the saving module is configured to save the connection selection context within a preset aging period.
  • the second connecting module includes:
  • a determining unit configured to determine whether a connection selection context corresponding to the terminal is saved, and a determining unit, configured to determine, when the connection selection context corresponding to the terminal is saved, the terminal selection according to a connection selection context corresponding to the terminal Business network
  • a fourth aspect provides a terminal, where the terminal includes:
  • a first access module configured to access the first WLAN
  • a first connection module configured to establish a user plane connection with the gateway
  • a sending module configured to send a connection selection request to the gateway by using the established user plane connection, where
  • the connection selection request includes connection selection information
  • a second connection module configured to establish, by the gateway, a connection between the service networks corresponding to the connection selection information in the connection selection request.
  • the terminal further includes:
  • a first selection module configured to select a first WLAN AP
  • a first association module configured to establish an association with the first WLAN AP
  • a first requesting module configured to request, by the gateway, access to the first WLAN corresponding to the first WLAN AP;
  • a first receiving module configured to receive, after the gateway performs successful authentication and authorization, a first terminal address sent by the gateway
  • the first access module is configured to access the first WLAN corresponding to the first WLAN AP by using the associated first WLAN AP;
  • a first transmission module configured to transmit, by the first WLAN, a data packet identified by the first terminal address.
  • the sending module includes:
  • a receiving unit configured to receive connection information that is sent by the gateway through the established user plane connection, including the optional connection selection information
  • a display unit configured to display the received connection information on the user interface
  • the first obtaining unit is configured to obtain connection selection information selected by the user through the user interface
  • the first sending unit is configured to send, by using the established user plane connection, a connection selection request including connection selection information selected by the user.
  • the sending module includes:
  • a second acquiring unit configured to acquire pre-configured connection selection information through a user interface
  • the second sending unit is configured to send, by using the established user plane connection, a connection selection request including pre-configured connection selection information to the gateway.
  • the terminal further includes:
  • a second selection module configured to select a second WLAN AP
  • a second association module configured to establish an association with the second WLAN AP
  • a second requesting module configured to request, by the gateway, access to a second WLAN corresponding to the second WLAN AP
  • a second receiving module configured to receive, after the gateway performs successful authentication and authorization, a second terminal address sent by the gateway
  • a second access module configured to access the second WLAN corresponding to the second WLAN AP by using the associated second WLAN AP
  • a second transmission module configured to transmit, by the second WLAN, a data packet identified by the second terminal address.
  • the user plane connection established with the terminal is connected to the connection selection request sent by the terminal, including the connection selection information, and after determining the service network selected by the terminal according to the connection selection information, establishing a connection between the terminal and the service network selected by the terminal, thereby implementing the terminal. It can connect different service networks, make the network connection more flexible, simplify the interaction between the terminal and the gateway, and expand the network connection range.
  • 1 is a schematic structural diagram of a system according to an embodiment of the present invention
  • 2 is a schematic structural diagram of a system according to another embodiment of the present invention
  • FIG. 3 is a flowchart of a method for establishing a network connection according to another embodiment of the present invention
  • FIG. 4 is a flowchart of a method for establishing a network connection according to another embodiment of the present invention
  • FIG. 6 is a schematic diagram of a user interface provided by another embodiment of the present invention.
  • connection network 7 is a flowchart of a connection network according to another embodiment of the present invention.
  • FIG. 8 is a flowchart of a connection network according to another embodiment of the present invention.
  • FIG. 9 is a flowchart of a connection network according to another embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 11 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 12 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 13 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 14 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 15 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 16 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 17 is a schematic structural diagram of a gateway according to another embodiment of the present invention.
  • FIG. 18 is a schematic structural diagram of a second connection module according to another embodiment of the present invention.
  • FIG. 19 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • FIG. 20 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • FIG. 21 is a schematic structural diagram of a sending module according to another embodiment of the present invention.
  • FIG. 22 is a schematic structural diagram of a sending module according to another embodiment of the present invention.
  • FIG. 23 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • FIG. 24 is a schematic structural diagram of a system for establishing a network connection according to another embodiment of the present invention. detailed description
  • the embodiment of the invention provides a method for establishing a network connection, and the method is applicable to the system shown in FIG. 1 or FIG.
  • the system shown in FIG. 1 includes a terminal, a gateway, and other network side devices.
  • the terminal includes a UE (User Equipment) and a CSF (Connection Selection Function) Client (client); the gateway includes an AC (Access). Controller, Access Controller) /BNG (Broadband Network Gateway), CSF and TGW (Trusted Gateway, Authentication, Authorization, and Accounting), HSS (Home Subscriber Server, Home Subscriber Server)/HLR (Home Location Register, Home Location Register) and PGW (Packet Data Network Gateway) / GGSN (Gateway General Packet Radio Service Support Node).
  • HSS Home Subscriber Server, Home Subscriber Server
  • HLR Home Location Register, Home Location Register
  • PGW Packet Data Network Gateway
  • GGSN Gateway General Packet Radio Service Support Node
  • WLAN AP Access Point
  • PDN Packet Data Network
  • NSWO Non-Seamless Wireless Local Area Network Offload
  • TWAP Trusted Wireless Local Area Network Authentication Authorisation Accounting Proxy, Trusted Wireless LAN Authentication, 4 Authorized and "i account agent”
  • AC/BNG and TGW user plane management functions for UE correspond to TWAG off in TWAN).
  • the CSF can be located between the AC/BNG and the TGW, and there is an interface between the CSF and the TGW; the CSF can also be integrated with the AC/BNG or TGW. If AC/BNG is combined with TGW, it can be used as T WAG, and CSF is integrated in TWAG/TWAP.
  • the UE When the UE is connected to the NSWO, if the user plane data packet of the UE is routed by the AC/BNG, then There is an interface Sac between the CSF and the AC/BNG. When the UE is connected to the NSWO, if the user plane data packet of the UE is routed by the TGW, there may be no interface between the CSF and the AC/BNG.
  • the system shown in FIG. 2 includes a terminal, a gateway, and other network side devices; wherein the terminal includes a UE and a CSF client; the gateway includes AC/BNG, CSF, NAT (Network Address Translation), and TGW; other network side devices Includes AAA, HSS/HLR, and PGW/GGSN.
  • the NAT may be located in the TGW, or located in the AC/BNG, or between the TGW and the AC/BNG (in this embodiment, the NAT in FIG. 2 is located in the TGW).
  • the terminal After the terminal connects to the gateway through the WLAN AP, it can connect to PDN or NSWO through the gateway.
  • the method flow provided by this embodiment includes:
  • the method before establishing a user plane connection with the terminal, the method further includes:
  • the method further includes:
  • the data packet identified by the first terminal address and the data packet identified by the terminal address accessing the initial service network are transmitted between the terminal and the initial service network by network address translation or network address and port translation.
  • connection selection request sent by the terminal, where the connection selection request includes connection selection information
  • the method further includes:
  • the terminal When the terminal disconnects the first WLAN corresponding to the first WLAN AP and reselects the second WLAN corresponding to the second WLAN AP, the terminal is authenticated; If the authentication succeeds, the terminal is authorized, and the second terminal address is sent to the terminal, so that the terminal accesses the second WLAN corresponding to the second WLAN AP, and the second terminal address is transmitted between the terminal and the second WLAN. Packet.
  • the method further includes:
  • the terminal address assigned to the terminal for accessing the initial service network is obtained from the PGW or the GGSN.
  • the connection selection request sent by the receiving terminal by using the established user plane connection includes:
  • connection information including the optional connection selection information to the terminal through the established user plane connection, and connecting the connection selection request sent by the terminal according to the connection information through the established user plane connection; or connecting the receiving terminal through the established user plane connection according to The connection selection request sent by the pre-configured connection selection information.
  • the method further includes:
  • connection selection context includes at least an identifier of the terminal, a service network selected by the terminal, and connection information
  • saving the connection selection context includes:
  • connection selection context is saved within the preset aging period.
  • the method further includes:
  • the method further includes:
  • the data packet identified by the first terminal address and the data packet identified by the terminal address of the service network selected by the access terminal are transmitted between the terminal and the service network selected by the terminal by network address translation or network address and port conversion.
  • establishing a connection between the terminal and the service network selected by the terminal including: determining whether the connection selection context corresponding to the terminal is saved;
  • connection selection context corresponding to the terminal is saved, the service network selected by the terminal is determined according to the connection selection context corresponding to the terminal, and the connection between the terminal and the service network selected by the terminal is established.
  • the method of the method for establishing a network connection provided by the embodiment of the present invention is taken as an example.
  • the method process provided by the embodiment of the present invention includes:
  • the method before establishing a user plane connection with the gateway, the method further includes:
  • the first WLAN corresponding to the first WLAN AP is requested by the gateway, and after the gateway performs the successful authentication and authorization, the first terminal address sent by the gateway is received, and the associated first WLAN AP is connected to the first WLAN AP.
  • the first WLAN, and the data packet identified by the first terminal address is transmitted between the first WLAN and the first WLAN.
  • connection selection request Send a connection selection request to the gateway by using the established user plane connection, where the connection selection request includes connection selection information;
  • sending a connection selection request to the gateway through the established user plane connection includes: Receiving connection information sent by the gateway through the established user plane connection including the optional connection selection information;
  • a connection selection request containing connection selection information selected by the user is sent to the gateway through the established user plane connection.
  • sending a connection selection request to the gateway through the established user plane connection includes:
  • the pre-configured connection selection information is obtained through the user interface, and a connection selection request including pre-configured connection selection information is sent to the gateway through the established user plane connection.
  • the method further includes:
  • the second WLAN corresponding to the second WLAN AP is requested by the gateway, and after the gateway performs the successful authentication and authorization, the second terminal address sent by the gateway is received, and the second WLAN AP is connected to the second WLAN AP by the associated second WLAN AP. And transmitting, by the second WLAN, a data packet identified by the second terminal address with the second WLAN.
  • the method provided by the embodiment of the present invention connects the connection selection request including the connection selection information sent by the terminal with the user plane established by the terminal, and determines the service network selected by the terminal according to the connection selection information, and establishes the service network selected by the terminal and the terminal.
  • the connection between the terminals enables the terminal to connect to different service networks, which makes the network connection more flexible, simplifies the interaction between the terminal and the gateway, and expands the network connection range.
  • An embodiment of the present invention provides a method for establishing a network connection, and the system shown in FIG. 1 is taken as an example. The method provided by the embodiment of the present invention is explained in detail. Referring to FIG. 5, the method process includes: 501: A terminal accesses a first WLAN, and establishes a user plane connection with the gateway;
  • the terminal accesses the first WLAN, including but not limited to:
  • the gateway is requested to access the WLAN corresponding to the first WLAN AP, and after the gateway performs the successful authentication and authorization, the WLAN corresponding to the first WLAN AP is accessed by the associated first WLAN AP.
  • the gateway Before establishing a connection with the user plane of the gateway, the gateway performs a process of authenticating and authorizing the terminal to access the first WLAN, including but not limited to:
  • the terminal that accesses the first WLAN corresponding to the first WLAN AP is authenticated; if the authentication succeeds, the terminal is authorized to enable the terminal to access the first corresponding to the first WLAN AP.
  • the AC/BNG and the TGW authenticate and authorize the terminal that requests access to the first WLAN corresponding to the first WLAN AP
  • the authentication process includes but is not limited to: HSS/HLR Sending the subscription information of the UE to the TWAN through the AAA server, that is, the TGW and the AC/BNG for authenticating and authorizing the UE, and the AAA server also sends the ID (identification) of the UE to the TGW corresponding to the TWAN;
  • the ID of the UE may be IMSK International Mobile Subscriber Identification Number, International Mobile Subscriber Identity.
  • the AC/BNG determines whether to accept the request of the terminal to access the WLAN corresponding to the first WLAN AP according to the subscription information of the terminal; if it is determined that the terminal accepts the request of the WLAN corresponding to the first WLAN AP, the authentication succeeds. When the authentication succeeds, the terminal is authorized to enable the terminal to access the first WLAN corresponding to the first WLAN AP.
  • EAP Extensible Authentication Protocol
  • EAP-SIM Subscriber Identity Module
  • EAP-AKA Authentication and Key Agreement
  • EAP-PEAP Protected Extensible Authentication Protocol
  • PSK Pre-Shared Key
  • Portal a Portal
  • the method further includes the step of sending the first terminal address to the terminal, so that the data packet identified by the first terminal address may be transmitted between the terminal and the first WLAN.
  • a process of receiving the first terminal address sent by the gateway is further included, so that the data packet identified by the first terminal address is subsequently transmitted between the first WLAN and the first WLAN.
  • the first terminal address sent by the gateway to the terminal may be the terminal address allocated by the gateway, or may be the terminal address obtained by the gateway through the dynamic host configuration protocol (DHCP). The manner of the first terminal address is limited.
  • the first terminal address in the uplink direction of the terminal and the first WLAN, may be used as the source address of the data packet IP header, and the first terminal address is in the downlink direction of the terminal and the first WLAN. Can be used as the destination address of the packet IP header.
  • the method includes, but is not limited to, one of the following two optional steps:
  • Optional step 1 obtaining, from the initial service network, a terminal address allocated to the terminal for accessing the initial service network;
  • Optional step 2 Select a PGW or a GGSN for the terminal according to the subscription information of the terminal, and establish a bearer to the PGW or the GGSN; and obtain, from the PGW or the GGSN, a terminal address allocated to the terminal for accessing the initial service network.
  • the initial service network is not limited in this embodiment, and the initial service network may be a default service network or an initial service network selected by the gateway for the terminal.
  • the embodiment does not limit the manner in which the terminal address assigned to the terminal for accessing the initial service network is obtained from the initial service network.
  • the second optional step refer to the system shown in FIG. 1. After the gateway authorizes the terminal, the TGW selects the PGW/GGSN for the terminal according to the default APN (Access Point Name) in the terminal subscription information.
  • APN Access Point Name
  • the TGW When the TGW is connected to the PGW, the S2a tunnel between the TGW and the PGW is ⁇ GTP (General Packet Radio Service Tunnelling) Protocol, General Packet Radio Service Tunneling Protocol), the TGW sends a Create Session Request to the PGW, and the Create Session Request includes IMSI, APN, PCO (Protocol Configuration Option), RAT ( Radio Access Technology, type, TWAN TEID (Tunnel Endpoint ID) of the control plane, PDN Type, PDN Address, EPS (Evolved Packet System, Evolved Packet System) Bearer Identity, Default EPS Bearer QoS (default evolved packet system bearer quality of service), TWAN Address for the user plane, TWAN TEID of the user Plane (trusted WLAN access network tunnel endpoint identifier for user plane), APN-AMBR (Aggregate Maximum Bit Rate), Selection Mode, Dual Address Bearer Flag , Trace Information, Charging Characteristi Cs (charging characteristics), Additional parameters
  • the PGW returns a Create Session Response to the TGW, the Create Session Response including the PDN GW Address for the user plane, the PDN GW TEID of the user plane (packet data network of the user plane) Gateway Tunnel Endpoint Identifier), PDN GW TEID of the control plane, PCO, PDN Type, PDN Address, EPS Bearer Identity, EPS Bearer QoS, APN-AMBR, Additional parameters (additional parameters), Cause.
  • the PDN address is an IP address assigned to the terminal, and the PGW may initiate establishment of other dedicated bearers connected to the PDN according to a Policy Control and Charging (PCC) policy.
  • PCC Policy Control and Charging
  • the S2a tunnel between the TGW and the PGW can also be used in the PMIP (Proxy Mobile Internet Protocol) tunnel, and the MAG (Mobile Access Gateway) in the TGW is
  • the PGW sends a Proxy Binding Update, which carries the APN, PCO carried by the Create Session Request. PDN Type, RAT Type and other parameters.
  • the PGW returns a Proxy Binding Acknowledgement (Block Binding Confirmation) to the TGW, and carries parameters such as PDP (Packet Data Protocol) Type, PDP Address, and Protocol Configuration Options carried by the Create Session Response.
  • the TGW When the TGW connects to the GGSN, the TGW sends a Create PDP Context Request to the GGSN.
  • the Create PDP Context Request includes PDP Type, PDP Address, Access Point Name, QoS Negotiated, Negotiated Evolved ARP (Address Resolution Protocol), TEID, NSAPI (Network Service Access Point Identifier), MSI SDN (Mobile Station International Integrated Service Digital Network Number), Selection Mode, Charging Characteristics, Trace Reference ), Trace Type, Trigger Id, OMC (Operation and Maintenance Center) Identity, Protocol Configuration Options, serving network identity (Maximum APN Restriction) (Maximum access point name area i or) IMEISV (International Mobile Equipment Identity software version), CGI (Cell Global Identifier) / SAI (Server Availabil) ITY Index, Server Availability Index), RAT type, S-CDR (Serving General Packet Radio Service Support Node-Charging Data Recording Service General Packet Radio Service Support Node - Charging Data Recording) CAMEL (Customized Applications for Mobile Network Enhanced Logic, Mobile Network enhanced version
  • the gateway may receive the DHCP request sent by the authenticated UE to the gateway, and the gateway will be the terminal according to the DHCP request.
  • the terminal address of the allocated access initial service network is carried in the DHCP response and returned to the terminal, so that the terminal accesses the initial service network according to the terminal address of the access initial service network.
  • the process of the UE sending a DHCP request to the gateway may perform access authentication on the UE at the gateway, and select a PGW or a GGSN for the UE, and perform the process after the bearer is established to the PGW or the GGSN.
  • the UE may send a DHCP request to the gateway, trigger the gateway to select a PGW or a GGSN for the UE, establish a bearer to the PGW or the GGSN, and obtain an initial access allocated to the UE from the PGW or the GGSN.
  • the step of the terminal address of the service network when the terminal is connected to the initial service network, the UE can access the initial service network by using the terminal address assigned to the initial service network, that is, sending the uplink data packet or receiving the initial service to the initial service network. Downlink packets sent by the network.
  • the method is more flexible.
  • the method provided in this embodiment establishes a user plane connection between the terminal and the gateway, so that the terminal can select different connections according to the user plane connection through the procedure step, and access different service networks.
  • There are a plurality of ways for establishing a user connection which is not specifically limited in this embodiment. For example, the terminal establishes a user plane connection with the gateway through the connected service network, and the gateway establishes a user plane connection with the terminal through the connected service network, and the establishment process is:
  • the terminal sends an uplink IP packet to the gateway, the destination address is filled in with a specific address (for example, 192.168.254.254), and a specific UDP port (for example, 8008) can also be set.
  • the gateway performs an SPI (Serial Peripheral Interface), checks the uplink data packet, intercepts the IP data packet of the specific address, and then queries the TGW according to the source address of the IP data packet, and is associated with the terminal. Link comparison, verify the legitimacy of the IP packet (CSF connection establishment request). If the IP data packet is sent by the terminal that has passed the access authentication, the IP data packet is legal, and the subsequent steps may be continued; if the IP data packet is sent by the terminal that fails the access authentication, the IP data packet is sent. It is illegal to terminate the establishment process of the user plane connection.
  • SPI Serial Peripheral Interface
  • the gateway After verifying that the IP data packet is valid, the gateway sends a reply IP packet to the terminal. After receiving the reply IP packet, the terminal establishes a successful connection between the terminal and the gateway, that is, the user plane connection between the terminal and the gateway is successfully established.
  • the terminal may further carry the ID of the terminal in the sent uplink IP data packet in the process of interacting with the gateway, where the ID of the terminal includes, but is not limited to, the IMSI of the terminal.
  • the functions performed by the above gateway can be performed by the CSF.
  • the terminal sends a connection selection request to the gateway by using the established user plane connection, where the connection selection request includes connection selection information.
  • connection selection information included in the connection selection request sent by the terminal to the gateway through the established user plane connection is not specifically limited in this embodiment.
  • the gateway in order for the terminal to send a connection selection request to the gateway through the established user plane connection, the gateway sends the connection information to the terminal through the established user plane connection, where the connection information includes alternative connection selection information;
  • the connection sends a connection selection request including the connection selection information selected by the user to the gateway, so that the terminal sends a connection selection request to the gateway through the established user plane connection.
  • the gateway may send the connection information to the terminal through the established user plane connection, and may be terminated by the CSF.
  • the terminal sends the connection information, which may be obtained by the CSF from the TGW.
  • the connection information may include, but is not limited to, the current connection type (such as the PDN or the NSWO connection type), the currently connected service network name (such as the network name is APN or PDN ID/PDN name), the terminal-signed connection type, and the terminal-signed service network.
  • the name one or more of the connection type that can be connected by the terminal supported by the WLAN access, the service network name that can be connected by the terminal supported by the WLAN access, the default connection type, and the service network name of the default connection.
  • each information may also carry an icon or a text corresponding to the information.
  • the CSF client of the terminal may display the received connection information on the user interface to obtain the connection selection information selected by the user.
  • the connection information displayed by the user interface may include but is not limited to the connection type and the service network name; the current connection, the selectable connection, the non-selectable connection may be displayed differently (for example, displaying different colors, etc., the non-selectable connection is on the user interface) Can be displayed as not selectable).
  • the user default connection option can also be provided for each connection, and the user can set any connection as the user default connection, so that after the terminal connects to the network, the CSF client automatically selects the user default connection for the terminal, thereby improving the connection.
  • Modifications can also be provided to obtain APN information that the user manually modifies or adds through modification, such as adding APN, or modifying the APN, PCO, PDN Type/PDP Type of the existing connection information of the CSF client.
  • the CSF client carries one or more of the PDN connection, the NSWO, and the APN information (APN, PCO, PDN Type/PDP Type, etc.) of the connection as the connection selection information in the connection selection request and sends it to the CSF, thereby completing the gateway to the gateway.
  • the terminal in addition to the connection information of the connection selection information that is sent by the gateway to the terminal, the terminal obtains the connection selection information selected by the user, and the terminal may also obtain the pre-configured connection selection information through the user interface. And send a connection selection request containing pre-configured connection selection information to the gateway through the established user plane connection.
  • the gateway receives the connection selection request sent by the terminal by using the established user plane connection, and determines the service network selected by the terminal according to the connection selection information in the connection selection request.
  • the gateway connects the connection selection request sent by the terminal according to the connection information through the established user plane connection.
  • the connection selection request can be received by the CSF.
  • the gateway since the terminal carries the PDN connection, the NSWO, and one or more of the APN information (APN, PCO, PDN Type/PDP Type, etc.) of the connection as the connection selection information in the connection selection request, the gateway receives the terminal. After the sent connection selection request, the service network selected by the terminal may be determined according to the connection selection information in the connection selection request.
  • APN information APN, PCO, PDN Type/PDP Type, etc.
  • the method further includes, but is not limited to:
  • connection selection context includes at least an identifier of the terminal, a service network selected by the terminal, and connection information
  • connection selection context when the connection selection context is saved, the connection selection context may be saved within the preset expiration date, and when the preset expiration period is exceeded, the connection selection context will not be saved.
  • the length of the preset expiration date is not specifically limited in this embodiment.
  • the CSF When the terminal selects NSWO, and the NSWO packet is routed by the AC/BNG via the CSF but not routed through the TGW, the CSF notifies the AC/BNG that the terminal selects NSWO and carries the ID of the terminal.
  • the TGW or AC/BNG establishes a connection selection context for the terminal, records the ID of the terminal, the selected connection (connected to the PDN or NSWO), and the connection information (such as APN, PCO, PDN Type/PDP Type, etc.), and starts the connection selection timer.
  • the network connection is made within the time defined by the value of the connection selection timer.
  • connection selection timer may be locally configured by the TGW or the AC/BNG according to the operator policy, or may be sent by the CSF to the TGW or the AC/BNG. When sent by the CSF to the TGW, it can be sent to the CSF by the CSF client of the terminal when sending a connection selection request.
  • the gateway determines whether to accept the service network selected by the terminal connection terminal; This step is an optional step.
  • the manner in which the gateway determines whether to accept the service network selected by the terminal to connect to the terminal is not specifically limited in this embodiment.
  • the specific implementation includes, but is not limited to, determining whether to accept the service network selected by the terminal connection terminal according to the subscription information or the network configuration of the terminal; if accepting the service network selected by the terminal connection terminal, performing the subsequent steps.
  • the CSF can send the ID of the terminal and the connection selection information received in the connection selection request to the TGW.
  • the TGW is configured according to the subscription information of the terminal and the local network (for example, whether to support or allow the NSWO, whether Supporting, allowing connection to the terminal selected PDN) determining whether to accept the service network selected by the terminal connection terminal.
  • the gateway If it is determined that the service network selected by the terminal connection terminal is accepted, the gateway returns a connection selection confirmation response to the terminal;
  • This step is an optional step.
  • the gateway determines to accept the service network selected by the terminal connection terminal, the gateway returns a connection selection confirmation response to the terminal.
  • the user plane management of the terminal by the AC/BNG and the TGW corresponds to the TWAG.
  • the TGW or the AC/BNG sends a connection selection confirmation response to the CSF.
  • the terminal disconnects from the first WLAN, and accesses the second WLAN.
  • the terminal After receiving the connection selection confirmation response sent by the gateway, the terminal disconnects from the first WLAN and accesses the second WLAN. When the connected second WLAN is reselected, the terminal selects the second WLAN AP and associates with the second WLAN AP.
  • the terminal since the terminal is connected to the first WLAN corresponding to the first WLAN AP, the terminal may also disconnect the first WLAN corresponding to the connected first WLAN AP when connecting the second WLAN corresponding to the second WLAN AP. If the first WLAN corresponding to the first WLAN AP is disconnected, after the CSF sends a connection selection reply to the CSF client, the first WLAN corresponding to the connected first WLAN AP can be disconnected.
  • the last associated WLAN AP can be selected.
  • the last associated WLAN AP can be based on the BSSID (Basic Service Set Identification) saved by the CSF client.
  • the basic service set identifier), the MAC (Medium Access Control) address of the WLAN AP is obtained, that is, the second WLAN AP is the same as the first WLAN AP, and the second WLAN is the same as the first WLAN; optionally, the terminal may also be Select another WLAN AP with the same SSID (Service Set Identifier) of the WLAN corresponding to the WLAN AP that was associated with the last time.
  • BSSID Basic Service Set Identification
  • WLAN APs may be obtained according to the BSSID saved by the CSF client; or may be based on HESSID (Homogenous Extended Service)
  • HESSID Homogenous Extended Service
  • the Set Identifier which is the same as the other WLAN APs in the same WLAN AP group, is different from the first WLAN AP, and the second WLAN is different from the first WLAN.
  • the terminal may connect to the corresponding WLAN according to the identifier.
  • a WLAN identifier eg, SSID, BSSID, etc.
  • the terminal when the terminal accesses the second WLAN, the terminal requests the gateway to access the second WLAN corresponding to the second WLAN AP; the gateway authenticates the terminal; if the authentication succeeds, the gateway performs the terminal on the terminal. Authorization; the terminal accesses the WLAN corresponding to the second WLAN AP through the associated second WLAN AP.
  • the process of authenticating the terminal by the gateway is the same as the process of authenticating the terminal of the first WLAN corresponding to the first WLAN AP in the foregoing step 501.
  • the process of authenticating the terminal of the first WLAN corresponding to the first WLAN AP in the foregoing step 501 is the same as the process of authenticating the terminal of the first WLAN corresponding to the first WLAN AP in the foregoing step 501.
  • the method further includes the step of sending a second terminal address to the terminal, so that the data packet identified by the second terminal address may be transmitted between the terminal and the second WLAN.
  • a process of receiving the second terminal address sent by the gateway is further included, so that the data packet identified by the second terminal address is subsequently transmitted between the second WLAN and the second WLAN.
  • the data packet of the second terminal address identifier, in the uplink direction of the terminal and the second WLAN, the second terminal address may be used as the source address of the data packet IP header, in the downlink direction of the terminal and the second WLAN, the second The terminal address can be used as the destination address of the packet IP header.
  • the second terminal address sent by the gateway to the terminal may be allocated by the gateway.
  • the terminal address may also be the terminal address obtained by the gateway through the DHCP. This embodiment does not limit the manner in which the gateway obtains the second terminal address.
  • the second terminal address that is sent by the gateway to the terminal may be the same as the first terminal address, or may be different, which is not specifically limited in this embodiment.
  • the gateway establishes a connection between the terminal and the service network selected by the terminal.
  • the gateway can query the service selection network carried in the connection selection request sent by the terminal to determine the service network selected by the terminal.
  • the gateway may further determine whether the connection selection context corresponding to the terminal is saved. If the connection selection context corresponding to the terminal is saved, the service network selected by the terminal is determined according to the connection selection context corresponding to the terminal, and the connection between the terminal and the service network selected by the terminal is established.
  • the gateway may further allocate a terminal address of the service network selected by the terminal to the terminal, and select the service selected by the access terminal.
  • the terminal address of the network is returned to the terminal, so that the terminal accesses the service network selected by the terminal according to the terminal address of the service network selected by the access terminal.
  • the gateway may receive a DHCP request sent by the authenticated UE to the gateway, and the gateway carries the terminal address of the service network selected by the access terminal allocated for the terminal in the DHCP response to the terminal according to the DHCP request, so that the terminal returns the terminal according to the DHCP request.
  • the terminal address of the service network selected by the access terminal accesses the service network selected by the terminal.
  • the TGW selects the PGW/GGSN for the terminal according to the APN, sends a Create Session Request to the PGW, and sends the Create Session Request to the GGSN.
  • Create PDP Context Request APN fills in the APN of the terminal selection connection.
  • the TGW Before the TGW establishes a new PDN connection tunnel for the UE (the tunnel is located between the TGW and the PGW/GGSN), if the UE last connected to the PDN connection, the TGW can activate the tunnel of the last connected PDN connection and release the resources. (eg IP address, etc.). If the UE last connected to the NSWO, then The AC/BNG or TGW can release the NTWO resources (such as IP address, etc.) of the terminal.
  • the resources eg IP address, etc.
  • the AC/BNG allocates an IP address to the terminal, that is, the terminal accesses the service network selected by the terminal. Terminal address.
  • the AC/BNG returns the IP address assigned to the terminal to the terminal in the DHCP ACK, and the uplink data packet sent by the terminal after connecting to the service network selected by the terminal is directly sent from the AC/BNG through the CSF.
  • the TGW allocates an IP address to the terminal, that is, the terminal accesses the terminal address of the service network selected by the terminal.
  • the TGW returns to the terminal in the DHCP ACK, and the uplink packet sent by the terminal after connecting to the service network selected by the terminal is directly sent out from the TGW.
  • the TGW If the UE chooses to connect to the PDN, the TGW returns the PDN address or PDP address to the terminal in the DHCP ACK. When the PGW is accessed, the PDN address is returned; when the GGSN is accessed, the PDP address is returned.
  • the terminal After connecting the service network selected by the terminal, the terminal can send an uplink data packet to the service network selected by the terminal, and receive the downlink data packet sent by the service network selected by the terminal, so as to access the PDN service selected by the terminal or the service of NSWO.
  • the downlink IP data packet enters the network by AC/BNG and is sent to the terminal.
  • the NSWO is in the TGW
  • the downlink IP data packet is entered into the network by the TGW and sent to the terminal.
  • step 7 in FIG. 7 corresponds to the content of step 501
  • step 8 corresponds to the content of step 502
  • step 9 to step 11 corresponds to the content of step 503 to step 505
  • step 12 to step 1 correspond to step 506 and step 507.
  • the CSF may also be located in the PDN network. Or located in the NSWO network (such as the Internet).
  • the terminal queries the DNS (Domain Name Service) server through the domain name of the CSF, obtains the IP address of the CSF on the PDN or the Internet, and establishes a connection.
  • DNS Domain Name Service
  • the method provided in this embodiment is configured to connect, by using a user plane connected with the terminal, a connection selection request that is sent by the terminal, including connection selection information, and determine a service network selected by the terminal according to the connection selection information, and establish a service network selected by the terminal and the terminal.
  • the connection between the terminals enables the terminal to connect to different service networks, which makes the network connection more flexible, simplifies the interaction between the terminal and the gateway, and expands the network connection range.
  • the embodiment of the present invention provides a method for establishing a network connection, and the method provided in the embodiment of the present invention is explained in detail by using the system shown in FIG. Referring to Figure 8, the method flow includes:
  • the terminal accesses the first WLAN, and establishes a user plane connection with the gateway;
  • the terminal accesses the first WLAN and establishes a user plane connection with the gateway.
  • the terminal accesses the first WLAN, and establishes a content connected with the user plane of the gateway. No longer.
  • the TWAG allocates an IP address to the terminal, and the IP address may be a public network or a local network address belonging to the AC/BNG/TGW address domain, or may be established for the terminal.
  • the PDN address obtained for the terminal when the default PDN connection (or the first PDN connection).
  • the gateway since the system shown in FIG. 2 includes a NAT entity, after the gateway allocates the first terminal address to the terminal and accesses the terminal address of the initial service network, the gateway converts the terminal and the initial service network by using network address translation or network address and port. The data packet identified by the first terminal address and the data packet identified by the terminal address accessing the initial service network are transmitted.
  • the terminal sends a connection selection request to the gateway through the established user plane connection, where the connection selection request includes connection selection information;
  • the terminal sends a connection selection request to the gateway through the established user plane connection.
  • the terminal sends a connection selection to the gateway through the established user plane connection.
  • the implementation is the same. For details, refer to the content of step 502 in the previous embodiment, and details are not described herein again.
  • 803 The gateway connects the connection selection request sent by the terminal through the established user plane connection, and determines the service network selected by the terminal according to the connection selection information in the connection selection request.
  • the implementation of the step is the same as the implementation of the step 503 in the previous embodiment.
  • the gateway determines whether to accept the service network selected by the terminal connection terminal;
  • the implementation of the step is the same as the implementation of the step 504 in the previous embodiment.
  • the gateway If it is determined that the service network selected by the terminal connection terminal is accepted, the gateway returns a connection selection confirmation response to the terminal;
  • the implementation manner of the gateway returning the connection selection confirmation response to the terminal is the same as the implementation manner of the gateway returning the connection selection confirmation response to the terminal in the step 505 in the previous embodiment.
  • the implementation manner of the gateway returning the connection selection confirmation response to the terminal in the step 505 in the previous embodiment For details, refer to the content of step 505 in the previous embodiment. I won't go into details here.
  • the terminal in the step of the step 505 of the foregoing embodiment, after receiving the connection selection confirmation response returned by the gateway, the terminal does not need to disconnect the first WLAN.
  • the gateway establishes a connection between the terminal and the service network selected by the terminal.
  • the gateway can query the service selection network carried in the connection selection request sent by the terminal to determine the service network selected by the terminal.
  • the gateway may further determine whether the connection selection context corresponding to the terminal is saved. If the connection selection context corresponding to the terminal is saved, the service network selected by the terminal is determined according to the connection selection context corresponding to the terminal, and the connection between the terminal and the service network selected by the terminal is established.
  • the gateway may further allocate a terminal address of the service network selected by the terminal to the terminal, and select the service selected by the access terminal.
  • the terminal address of the network is returned to the terminal, so that the terminal is in accordance with the interview.
  • the terminal address of the service network selected by the terminal is requested to access the service network selected by the terminal.
  • the gateway may receive a DHCP request sent by the authenticated UE to the gateway, and the gateway carries the terminal address of the service network selected by the access terminal allocated for the terminal in the DHCP response to the terminal according to the DHCP request, so that the terminal returns the terminal according to the DHCP request.
  • the terminal address of the service network selected by the access terminal accesses the service network selected by the terminal.
  • the TGW According to the APN, the PGW/GGSN is selected for the terminal; if the PGW is selected, the Create Session Request is sent to the PGW; if the GGSN is selected, the Create PDP Context Request is sent to the GGSN; the APN in the request fills in the APN selected by the terminal to connect.
  • the PGW returns PDN addres by sending a Create Session Response to the TGW, and the GGSN sends a Create PDP Context Response to the TGW to return a PDP address.
  • the system structure provided in this embodiment further includes a NAT entity
  • the NAT entity when the terminal sends uplink data to the service network selected by the terminal, the NAT entity performs NAT/NAPT (Network Address Port Translation) for the terminal. Conversion) conversion (the address assigned to TWAG before conversion, the address assigned to PGW/GGSN after conversion), and sent to PGW/GGSN.
  • the NAT entity When the terminal sends downlink data, the NAT entity performs the reverse conversion for the terminal and sends it to the terminal.
  • the terminal chooses to connect to NSWO and the terminal subscription and carrier policy allow the terminal to connect to NSWO
  • the terminal assigns a public network address to the terminal
  • the AC/BNG or TGW directly sends the uplink data packet of the terminal.
  • TWAG allocates a local network address for the terminal
  • AC/BNG or TGW retrieves the data packet through the NAT entity in a similar manner to the PDN connection (the local network address assigned to the TWAG before conversion, converted to AC) /BNG or the address of the TGW address field), sends the upstream packet.
  • step 801 to step 806 described above may be re-executed, so that the service network selected by the terminal connection terminal is implemented.
  • step 1 to 7 in FIG. 9 correspond to the content of step 801
  • step 8 corresponds to the content of step 802
  • step 9 to step 11 corresponds to the content of step 803 to step 805
  • step 15 to step 16 correspond to the content of step 806.
  • the method provided by the embodiment of the present invention connects the connection selection request including the connection selection information sent by the terminal with the user plane established by the terminal, and determines the service network selected by the terminal according to the connection selection information, and establishes the service network selected by the terminal and the terminal.
  • the connection between the terminals enables the terminal to connect to different service networks, which makes the network connection more flexible, simplifies the interaction between the terminal and the gateway, and expands the network connection range.
  • an embodiment of the present invention provides a gateway, where the gateway is configured to perform a method performed by a gateway in a method for establishing a network connection provided by the foregoing embodiment shown in FIG. 3, FIG. 5 or FIG. :
  • the first connection module 1001 is configured to establish a user plane connection with the terminal, and the terminal accesses the first WLAN.
  • the receiving module 1002 is configured to connect, by using the established user plane, the connection selection request sent by the terminal, where the connection selection request includes the connection selection.
  • the first determining module 1003 is configured to determine, according to the connection selection information in the connection selection request, the service network selected by the terminal;
  • the second connection module 1004 is configured to establish a connection between the terminal and the service network selected by the terminal.
  • the gateway further includes:
  • the first authentication module 1005 is configured to authenticate a terminal that requests access to the first WLAN corresponding to the first WLAN AP;
  • the first authorization module 1006 is configured to authorize the terminal when the authentication succeeds
  • the first sending module 1007 is configured to send the first terminal address to the terminal, so that the terminal accesses the first a first WLAN corresponding to the WLAN AP;
  • the first transmission module 1008 is configured to transmit, by the terminal, the data packet identified by the first terminal address between the terminal and the first WLAN.
  • the gateway further includes:
  • the second authentication module 1009 is configured to: when the terminal disconnects the first WLAN corresponding to the first WLAN AP, and reselects to access the second WLAN corresponding to the second WLAN AP, the terminal is authenticated;
  • the second authorization module 1010 is configured to authorize the terminal when the authentication succeeds
  • the second sending module 1011 is configured to send a second terminal address to the terminal, so that the terminal accesses the second WLAN corresponding to the second WLAN AP;
  • the second transmission module 1012 is configured to transmit a data packet identified by the second terminal address between the terminal and the second WLAN.
  • the gateway further includes:
  • the first obtaining module 1013 is configured to obtain, from the initial service network, a terminal address allocated to the terminal for accessing the initial service network;
  • the selecting module 1014 is configured to select a PGW or a GGSN for the terminal according to the subscription information of the terminal.
  • the first establishing module 1015 is configured to establish a bearer to the PGW or the GGSN.
  • the second obtaining module 1016 is configured to obtain, from the PGW or the GGSN, a terminal address allocated to the terminal to access the initial service network.
  • the gateway further includes:
  • the third transmission module 1017 is configured to transmit the data packet identified by the first terminal address and the data packet identified by the terminal address of the access initial service network between the terminal and the initial service network by using network address translation or network address and port conversion.
  • the gateway further includes:
  • the distribution module 1018 is configured to allocate, to the terminal, a terminal address of the service network selected by the access terminal, and the fourth transmission module 1019 is configured to convert the network address or the network address and port in the terminal.
  • a data packet identified by the first terminal address and a data packet identified by the terminal address of the service network selected by the access terminal are transmitted between the service network selected by the terminal.
  • the gateway further includes:
  • the second determining module 1020 is configured to determine, according to the subscription information or the network configuration of the terminal, whether to accept the terminal connection service network;
  • the second connection module 1004 is configured to perform the step of establishing a connection between the terminal and the service network selected by the terminal when accepting the terminal to connect to the service network.
  • the receiving module 1002 is configured to send connection information including the optional connection selection information to the terminal through the established user plane connection, and connect the receiving terminal according to the connection information through the established user plane connection. Select request;
  • the receiving module 1002 is configured to connect, by using the established user plane, the connection selection request sent by the terminal according to the pre-configured connection selection information.
  • the gateway further includes:
  • the second establishing module 1021 is configured to establish a connection selection context corresponding to the terminal according to the connection selection request, where the connection selection context includes at least the identifier of the terminal, the service network selected by the terminal, and the connection information.
  • the saving module 1022 is configured to save the connection selection context.
  • the saving module 1022 is configured to save the connection selection context within a preset aging period.
  • the second connection module 1004 includes:
  • the determining unit 10041 is configured to determine whether the connection selection context corresponding to the terminal is saved, and the determining unit 10042 is configured to determine, according to the connection selection context corresponding to the terminal, the service network selected by the terminal, when the connection selection context corresponding to the terminal is saved;
  • the connecting unit 10043 is configured to establish a connection between the terminal and the service network selected by the terminal.
  • the gateway provided by the embodiment of the present invention connects the connection selection request including the connection selection information sent by the terminal through the user plane connection established by the terminal, and determines the service network selected by the terminal according to the connection selection information, and establishes the service network selected by the terminal and the terminal.
  • the connection between the terminals, so that the terminal can be connected Different service networks make the network connection more flexible, simplify the interaction between the terminal and the gateway, and expand the network connection range.
  • an embodiment of the present invention provides a terminal, where the terminal is configured to perform a method performed by a terminal in a method for establishing a network connection provided by the foregoing embodiment shown in FIG. 4, FIG. 5 or FIG. :
  • the first access module 1901 is configured to access the first WLAN.
  • a first connection module 1902 configured to establish a user plane connection with the gateway
  • the sending module 1903 is configured to send a connection selection request to the gateway by using the established user plane connection, where the connection selection request includes connection selection information;
  • the second connection module 1904 is configured to establish, by the gateway, a connection between the service networks corresponding to the connection selection information in the connection selection request.
  • the terminal further includes:
  • a first selection module 1905 configured to select a first WLAN AP
  • a first association module 1906 configured to establish an association with the first WLAN AP
  • the first requesting module 1907 is configured to request, by the gateway, access to the first WLAN corresponding to the first WLAN AP;
  • the first receiving module 1908 is configured to: after the gateway performs successful authentication and authorization, receive the first terminal address sent by the gateway;
  • the first access module 1901 is configured to access the first WLAN corresponding to the first WLAN AP by using the associated first WLAN AP;
  • the first transmission module 1909 is configured to transmit, by the first WLAN, a data packet identified by the first terminal address.
  • the sending module 1903 includes:
  • the receiving unit 19031 is configured to receive connection information that is sent by the gateway through the established user plane connection, and includes connection selection information that is selectable;
  • the display unit 19032 is configured to display the received connection information on the user interface.
  • the first obtaining unit 19033 is configured to acquire connection selection information selected by the user through the user interface.
  • the first sending unit 19034 is configured to connect through the established user plane. A connection selection request including connection selection information selected by the user is sent to the gateway.
  • the sending module 1903 includes:
  • the second obtaining unit 19035 is configured to obtain pre-configured connection selection information by using a user interface.
  • the second sending unit 19036 is configured to send, by using the established user plane connection, a connection selection request including pre-configured connection selection information.
  • the terminal further includes:
  • a second selection module 1910 configured to select a second WLAN AP
  • a second association module 1911 configured to establish an association with the second WLAN AP
  • a second requesting module 1912 configured to request, by the gateway, access to the second corresponding to the second WLAN AP
  • the second receiving module 1913 is configured to: after the gateway performs successful authentication and authorization, receive the second terminal address sent by the gateway;
  • the second access module 1914 is configured to access the second WLAN corresponding to the second WLAN AP by using the associated second WLAN AP;
  • the second transmission module 1915 is configured to transmit, by the second WLAN, a data packet identified by the second terminal address.
  • the terminal provided by the embodiment of the present invention sends a connection selection request including connection selection information to the gateway through the user plane connection established with the network side, so that the gateway determines the service network selected by the terminal according to the connection selection information, and establishes the service selected by the terminal and the terminal.
  • the connection between the networks enables the terminal to connect to different service networks, which makes the network connection more flexible, simplifies the interaction between the terminal and the gateway, and expands the network connection range.
  • An embodiment of the present invention provides a gateway for performing the foregoing FIG. 3, FIG. 5 or FIG.
  • the method performed by the gateway in the method for establishing a network connection provided by the illustrated embodiment includes a processor and a receiver.
  • the processor is configured to establish a user plane connection with the terminal, and the terminal accesses the first WLAN;
  • the receiver is configured to connect, by using the established user plane, the connection selection request sent by the terminal, where the connection selection request includes connection selection information;
  • a processor configured to determine, according to connection selection information in the connection selection request, a service network selected by the terminal;
  • the processor is configured to establish a connection between the terminal and the service network selected by the terminal.
  • the processor is further configured to: perform authentication on the terminal that requests to access the first WLAN corresponding to the first WLAN AP;
  • the processor is further configured to authorize the terminal if the authentication succeeds;
  • the gateway also includes a transmitter
  • a transmitter configured to send a first terminal address to the terminal, so that the terminal accesses the first WLAN corresponding to the first WLAN AP;
  • a processor configured to transmit, by the terminal, the data packet identified by the first terminal address between the terminal and the first WLAN.
  • the processor is further configured to: when the terminal disconnects the first WLAN corresponding to the first WLAN AP, and reselects the second WLAN corresponding to the second WLAN AP, Right
  • the processor is further configured to: if the authentication succeeds, authorize the terminal to enable the terminal to access the second WLAN corresponding to the second WLAN AP;
  • the transmitter is further configured to send the second terminal address to the terminal;
  • the processor is further configured to transmit the data packet identified by the second terminal address between the terminal and the second WLAN.
  • the processor is further configured to obtain, from the initial service network, a terminal address allocated to the terminal for accessing the initial service network; or,
  • the processor is further configured to select a PGW or a GGSN for the terminal according to the subscription information of the terminal, and establish a bearer to the PGW or the GGSN;
  • the processor is further configured to obtain, from the PGW or the GGSN, a terminal address allocated to the terminal for accessing the initial service network.
  • the processor is further configured to transmit, by using network address translation or network address and port translation, a data packet identified by the first terminal address and a terminal that accesses the initial service network between the terminal and the initial service network.
  • the packet identified by the address is further configured to transmit, by using network address translation or network address and port translation, a data packet identified by the first terminal address and a terminal that accesses the initial service network between the terminal and the initial service network. The packet identified by the address.
  • the processor is further configured to allocate, to the terminal, a terminal address of the service network selected by the access terminal;
  • the processor is further configured to transmit the data packet identified by the first terminal address and the data identified by the terminal address of the service network selected by the access terminal between the terminal and the service network selected by the terminal by using network address translation or network address and port translation. package.
  • the processor is further configured to determine, according to the subscription information or the network configuration of the terminal, whether to accept the terminal connection service network;
  • the processor is further configured to perform the step of establishing a connection between the terminal and the service network selected by the terminal when the terminal is connected to the service network.
  • the transmitter is further configured to send, by using the established user plane connection, connection information including the optional connection selection information to the terminal;
  • the receiver is further configured to connect, by using the established user plane, the connection selection request sent by the terminal according to the connection information;
  • the receiver is further configured to connect, by using the established user plane, the connection selection request sent by the terminal according to the pre-configured connection selection information.
  • the processor is further configured to establish, according to the connection selection request, a connection selection context corresponding to the terminal, where the connection selection context includes at least an identifier of the terminal, a service network selected by the terminal, and connection information.
  • the processor is also used to save the connection selection context.
  • the processor is further configured to save the connection selection context within a preset aging period.
  • the processor is further configured to determine whether a connection selection context corresponding to the terminal is saved
  • the processor is further configured to: when the connection selection context corresponding to the terminal is saved, determine a service network selected by the terminal according to the connection selection context corresponding to the terminal, and establish a connection between the terminal and the service network selected by the terminal.
  • the gateway provided by the embodiment, through the user plane connection established with the terminal, receives the connection selection request sent by the terminal, including the connection selection information, and determines the service network selected by the terminal according to the connection selection information, and establishes the service network selected by the terminal and the terminal.
  • the connection between the terminals enables the terminal to connect to different service networks, which makes the network connection more flexible, simplifies the interaction between the terminal and the gateway, and expands the network connection range.
  • the embodiment of the present invention provides a terminal, which is used to perform the method performed by the terminal in the method for establishing a network connection provided by the embodiment shown in FIG. 4, FIG. 5 or FIG. 8, and includes a processor and a transmitter.
  • the processor is configured to access the first WLAN, and establish a user plane connection with the gateway;
  • the transmitter is configured to send a connection selection request to the gateway by using the established user plane connection, where the connection selection request includes connection selection information;
  • a processor configured to establish, by the gateway, a connection between the service networks corresponding to the connection selection information in the connection selection request.
  • the processor is further configured to select a first WL AN AP to establish an association with the first WL AN AP;
  • the processor is further configured to request, by the gateway, access to the first WLAN corresponding to the first WLAN AP;
  • the terminal further includes a receiver; a receiver, configured to receive, by the gateway, a first terminal address sent by the gateway after performing successful authentication and authorization;
  • the processor is further configured to access the first WLAN corresponding to the first WLAN AP by using the associated first WLAN AP, and transmit the data packet identified by the first terminal address with the first WLAN.
  • the receiver is further configured to receive connection information that is sent by the gateway through the established user plane connection, including the optional connection selection information;
  • the processor is further configured to display the received connection information on the user interface, and obtain connection selection information selected by the user through the user interface;
  • the transmitter is further configured to send, by the established user plane connection, a connection selection request including connection selection information selected by the user to the gateway.
  • the processor is further configured to obtain pre-configured connection selection information through a user interface
  • the transmitter is further configured to send a connection selection request including pre-configured connection selection information to the gateway through the established user plane connection.
  • the processor is further configured to select a second WLAN AP and associate with the second WLAN AP;
  • the processor is further configured to request the gateway to access the second WLAN corresponding to the second WLAN AP, and the receiver is further configured to: after the gateway performs successful authentication and authorization, receive the second terminal address sent by the gateway;
  • the processor is further configured to access the second WLAN corresponding to the second WLAN AP by using the associated second WLAN AP, and transmit the data packet identified by the second terminal address with the second WLAN.
  • the terminal provided by the embodiment of the present invention establishes a user plane connection with the network side, and sends a connection selection request including connection selection information to the gateway through the user plane connection, so that the gateway determines the service network selected by the terminal according to the connection selection information, and establishes the terminal.
  • the connection with the service network selected by the terminal enables the terminal to connect to different service networks, which makes the network connection more flexible, simplifies the interaction between the terminal and the gateway, and expands the network connection range.
  • an embodiment of the present invention provides a system for establishing a network connection, where the system includes a gateway 2401 and at least one terminal 2402.
  • the gateway 2401 is a gateway as shown in any of the foregoing FIG. 10 to FIG.
  • the gateway 2401 is a gateway as shown in any of the foregoing FIG. 10 to FIG.
  • the system provided in this embodiment establishes a connection selection request including connection selection information sent by the terminal through a user plane connection established with the terminal, and determines a service network selected by the terminal according to the connection selection information, and establishes a service network selected by the terminal and the terminal.
  • the connection between the terminals enables the terminal to connect to different service networks, which makes the network connection more flexible, simplifies the interaction between the terminal and the gateway, and expands the network connection range. It should be noted that, when the network connection is provided, the terminal and the gateway provided by the foregoing embodiment are only illustrated by the division of the foregoing functional modules. In actual applications, the function distribution may be completed by different functional modules according to requirements.
  • the internal structure of the terminal and the gateway are divided into different functional modules to complete all or part of the functions described above.
  • the terminal, the gateway, and the system for establishing a network connection provided by the foregoing embodiments are in the same concept as the method for establishing a network connection.
  • the specific implementation process refer to the method embodiment, and details are not described herein again.
  • a person skilled in the art may understand that all or part of the steps of implementing the above embodiments may be completed by hardware, or may be instructed by a program to execute related hardware, and the program may be stored in a computer readable storage medium.
  • the storage medium mentioned may be a read only memory, a magnetic disk or an optical disk or the like.

Abstract

本发明公开了一种建立网络连接的方法、网关及终端,属于互联网技术领域。方法包括:建立和终端的用户面连接,终端接入第一WLAN;通过建立的用户面连接接收终端发送的连接选择请求,连接选择请求中包括连接选择信息;根据连接选择请求中的连接选择信息确定终端选择的业务网络;建立终端与终端选择的业务网络之间的连接。本发明通过和终端建立的用户面连接接收终端发送的包括连接选择信息的连接选择请求,并根据连接选择信息确定终端选择的业务网络后,建立终端与终端选择的业务网络之间的连接,从而实现终端可以连接不同的业务网络,使得网络连接的方式更加灵活,简化了终端和网关的交互,扩大了网络连接范围。

Description

建立网络连接的方法、 网关及终端 技术领域
本发明涉及信息技术领域, 特别涉及一种建立网络连接的方法、 网关及终 端。 背景技术
随着信息技术的不断发展, 移动网络承载的数据量越来越大, 这使得移动 网络经常超负荷运行。 而 WLAN ( Wireless Local Area Network, 无线局域网) 有较多的终端支持, 部署和运营的成本都比较低。 如何通过 WLAN连接移动 网络, 是人们关注的建立网络连接的方法。
目前, 有两种建立网络连接的方式。 第一种方式: 对连接 WLAN的终端 建立 IPsec ( Internet Protocol Security, 互联网协议安全性) 隧道, 再通过建立 IPsec安全关联的控制面 IKEv2 ( Internet Key Exchange , 因特网密钥交换协议) 和终端交互移动网络连接信息, 从而建立网络连接。 第二种方式: 获取连接 WLAN的终端的签约,根据终端的签约为终端分配移动网络地址,使终端根据 分配的移动网络地址访问移动网络, 从而建立网络连接。
在实现本发明的过程中, 发明人发现现有技术至少存在以下问题: 第一种方式中建立 IPSec隧道和 IKEv2数据交互的技术比较复杂,对终端 的要求较高, 缩小了建立网络的应用范围。 第二种方式根据终端的签约为终端 分配移动网络地址, 致使建立网络连接的方式不够灵活, 并且限制了终端连接 的网络范围。 发明内容 为了解决现有技术的问题, 本发明实施例提供了一种建立网络连接的方 法、 网关及终端。 所述技术方案如下:
第一方面, 提供了一种建立网络连接的方法, 所述方法包括:
建立和终端的用户面连接, 所述终端接入第一 WLAN;
通过建立的用户面连接接收所述终端发送的连接选择请求, 所述连接选择 请求中包括连接选择信息;
根据所述连接选择请求中的连接选择信息确定所述终端选择的业务网络; 建立所述终端与所述终端选择的业务网络之间的连接。
结合第一方面, 在第一方面的第一种可能的实现方式中, 所述建立和终端 的用户面连接之前, 还包括:
对请求接入第一 WLAN接入点 AP对应的第一 WLAN的终端进行鉴权; 若鉴权成功, 则对所述终端进行授权, 并向所述终端发送第一终端地址, 使所述终端接入所述第一 WLANAP对应的第一 WLAN,并在所述终端与所述 第一 WLAN之间传输用所述第一终端地址标识的数据包。
结合第一方面, 在第一方面的第二种可能的实现方式中, 所述通过建立的 用户面连接接收所述终端发送的连接选择请求之后, 还包括:
当所述终端断开与所述第一 WLAN AP对应的第一 WLAN的连接, 重新 选择接入第二 WLAN AP对应的第二 WLAN时 , 对所述终端进行鉴权;
若鉴权成功, 则对所述终端进行授权, 并向所述终端发送第二终端地址, 使所述终端接入所述第二 WLANAP对应的第二 WLAN,并在所述终端与所述 第二 WLAN之间传输用所述第二终端地址标识的数据包。
结合第一方面第一种或第二种可能的实现方式, 在第一方面的第三种可能 的实现方式中, 所述对所述终端进行授权之后, 还包括:
从初始业务网络获取为所述终端分配的访问初始业务网络的终端地址; 或,
根据所述终端的签约信息为所述终端选择分组数据网络网关 PGW或网关 通用分组无线服务支持节点 GGSN, 并建立到所述 PGW或 GGSN的承载; 址。
结合第一方面的第三种可能的实现方式, 在第一方面的第四种可能的实现 方式中, 所述向所述终端发送第一终端地址之后, 还包括:
通过网络地址转换或网络地址及端口转换在所述终端和所述初始业务网 络之间传输用所述第一终端地址标识的数据包和用访问初始业务网络的终端 地址标识的数据包。
结合第一方面的第一种可能的实现方式, 在第一方面的第五种可能的实现 方式中, 所述建立所述终端与所述终端选择的业务网络之间的连接之后, 还包 括:
为所述终端分配访问所述终端选择的业务网络的终端地址;
通过网络地址转换或网络地址及端口转换在所述终端和所述终端选择的 业务网络之间传输用所述第一终端地址标识的数据包和用访问所述终端选择 的业务网络的终端地址标识的数据包。
结合第一方面的第一种可能的实现方式, 在第一方面的第六种可能的实现 方式中, 所述根据所述连接选择请求中的连接选择信息确定所述终端选择的业 务网络之后, 还包括:
根据所述终端的签约信息或网络配置确定是否接受所述终端连接所述业 务网络;
如果接受所述终端连接所述业务网络 , 则执行建立所述终端与所述终端选 择的业务网络之间的连接的步骤。
结合第一方面至第一方面的第六种可能的实现方式中任一种可能的实现 方式, 在第一方面的第七种可能的实现方式中, 所述通过建立的用户面连接接 收所述终端发送的连接选择请求, 包括:
通过建立的用户面连接向所述终端发送包括可供选择的连接选择信息的 连接信息, 并通过建立的用户面连接接收所述终端根据所述连接信息发送的连 接选择请求;
或者,通过建立的用户面连接接收所述终端根据预先配置的连接选择信息 发送的连接选择请求。
结合第一方面的第七种可能的实现方式, 在第一方面的第八种可能的实现 方式中, 所述通过建立的用户面连接接收所述终端发送的连接选择请求之后, 还包括:
根据所述连接选择请求建立所述终端对应的连接选择上下文, 所述连接选 择上下文中至少包括所述终端的标识、 所述终端选择的业务网络及连接信息; 保存所述连接选择上下文。
结合第一方面的第八种可能的实现方式, 在第一方面的第九种可能的实现 方式中, 所述保存所述连接选择上下文, 包括:
在预设时效期限内保存所述连接选择上下文。
结合第一方面的第八种可能的实现方式, 在第一方面的第十种可能的实现 方式中, 所述建立所述终端与所述终端选择的业务网络之间的连接, 包括: 判断是否保存有所述终端对应的连接选择上下文;
若保存有所述终端对应的连接选择上下文, 则根据所述终端对应的连接选 择上下文确定所述终端选择的业务网络, 并建立所述终端与所述终端选择的业 务网络之间的连接。
第二方面, 提供了一种建立网络连接的方法, 所述方法包括:
接入第一 WLAN, 并建立和网关的用户面连接;
通过建立的用户面连接向所述网关发送连接选择请求, 所述连接选择请求 中包括连接选择信息;
通过所述网关建立与所述连接选择请求中的连接选择信息对应的业务网 络之间的连接。
结合第二方面, 在第二方面的第一种可能的实现方式中, 所述建立和网关 的用户面连接之前, 还包括:
所述接入第一 WLAN, 包括:
选择第一 WLAN AP , 与所述第一 WLAN AP建立关联;
向所述网关请求接入所述第一 WLANAP对应的第一 WLAN,并在所述网 关进行成功鉴权及授权后, 接收所述网关发送的第一终端地址, 通过关联的第 一 WLAN AP接入所述第一 WLAN AP对应的第一 WLAN, 并与所述第一 WLAN之间传输用所述第一终端地址标识的数据包。
结合第二方面, 在第二方面的第二种可能的实现方式中, 所述通过建立的 用户面连接向网关发送连接选择请求, 包括:
接收网关通过建立的用户面连接发送的包括可供选择的连接选择信息的 连接信息;
在用户界面上显示接收到的连接信息, 并获取用户通过用户界面选择的连 接选择信息;
通过建立的用户面连接向网关发送包含用户选择的连接选择信息的连接 选择请求。
结合第二方面, 在第二方面的第三种可能的实现方式中, 所述通过建立的 用户面连接向网关发送连接选择请求, 包括:
通过用户界面获取预先配置的连接选择信息, 并通过建立的用户面连接向 网关发送包含预先配置的连接选择信息的连接选择请求。
结合第二方面, 在第二方面的第四种可能的实现方式中, 所述通过建立的 用户面连接向所述网关发送连接选择请求之后, 还包括:
选择第二 WLAN AP, 并与所述第二 WLAN AP建立关联;
向所述网关请求接入所述第二 WLANAP对应的第二 WLAN,并在所述网 关进行成功鉴权及授权后, 接收所述网关发送的第二终端地址, 通过关联的第 二 WLAN AP接入所述第二 WLAN AP对应的第二 WLAN, 并与所述第二 WLAN之间传输用所述第二终端地址标识的数据包。 第三方面, 提供了一种网关, 所述网关包括:
第一连接模块,用于建立和终端的用户面连接,所述终端接入第一 WLAN; 接收模块, 用于通过建立的用户面连接接收所述终端发送的连接选择请 求, 所述连接选择请求中包括连接选择信息;
第一确定模块, 用于根据所述连接选择请求中的连接选择信息确定所述终 端选择的业务网络;
第二连接模块, 用于建立所述终端与所述终端选择的业务网络之间的连 接。
结合第三方面, 在第三方面的第一种可能的实现方式中, 所述网关, 还包 括:
第一鉴权模块, 用于对请求接入第一 WLAN AP对应的第一 WLAN的终 端进行鉴权;
第一授权模块, 用于当鉴权成功时, 对所述终端进行授权;
第一发送模块, 用于向所述终端发送第一终端地址, 使所述终端接入所述 第一 WLAN AP对应的第一 WLAN;
第一传输模块, 用于在所述终端与所述第一 WLAN之间传输用所述第一 终端地址标识的数据包。
结合第三方面, 在第三方面的第二种可能的实现方式中, 所述网关, 还包 括:
第二鉴权模块, 用于当所述终端断开与所述第一 WLAN AP对应的第一 WLAN的连接 , 重新选择接入第二 WLAN AP对应的第二 WLAN时 , 对所述 终端进行鉴权;
第二授权模块, 用于当鉴权成功时, 对所述终端进行授权;
第二发送模块, 用于向所述终端发送第二终端地址, 使所述终端接入所述 第二 WLAN AP对应的第二 WLAN;
第二传输模块, 用于在所述终端与所述第二 WLAN之间传输用所述第二 终端地址标识的数据包。
结合第三方面的第一种或第二种可能的实现方式, 在第三方面的第三种可 能的实现方式中, 所述网关, 还包括:
第一获取模块, 用于从初始业务网络获取为所述终端分配的访问初始业务 网络的终端地址;
或,
选择模块,用于根据所述终端的签约信息为所述终端选择 PGW或 GGSN; 第一建立模块, 用于建立到所述 PGW或 GGSN的承载; 始业务网络的终端地址。
结合第三方面的第三种可能的实现方式, 在第三方面的第四种可能的实现 方式中, 所述网关, 还包括:
第三传输模块, 用于通过网络地址转换或网络地址及端口转换在所述终端 和所述初始业务网络之间传输用所述第一终端地址标识的数据包和用访问初 始业务网络的终端地址标识的数据包。
结合第三方面的第一种可能的实现方式, 在第三方面的第五种可能的实现 方式中, 所述网关, 还包括:
分配模块, 用于为所述终端分配访问所述终端选择的业务网络的终端地 址;
第四传输模块, 用于通过网络地址转换或网络地址及端口转换在所述终端 和所述终端选择的业务网络之间传输用所述第一终端地址标识的数据包和用 访问所述终端选择的业务网络的终端地址标识的数据包。
结合第三方面的第一种可能的实现方式, 在第三方面的第六种可能的实现 方式中, 所述网关, 还包括:
第二确定模块, 用于根据所述终端的签约信息或网络配置确定是否接受所 述终端连接所述业务网络; 第二连接模块, 用于当接受所述终端连接所述业务网络时, 执行建立所述 终端与所述终端选择的业务网络之间的连接的步骤。
结合第三方面至第三方面的第六种可能的实现方式中的任一种可能的实 现方式, 在第三方面的第七种可能的实现方式中, 所述接收模块, 用于通过建 立的用户面连接向所述终端发送包括可供选择的连接选择信息的连接信息, 并 通过建立的用户面连接接收所述终端根据所述连接信息发送的连接选择请求; 或者, 所述接收模块, 用于通过建立的用户面连接接收所述终端根据预先 配置的连接选择信息发送的连接选择请求。
结合第三方面的第七种可能的实现方式, 在第三方面的第八种可能的实现 方式中, 所述网关, 还包括:
第二建立模块, 用于根据所述连接选择请求建立所述终端对应的连接选择 上下文, 所述连接选择上下文中至少包括所述终端的标识、 所述终端选择的业 务网络及连接信息;
保存模块, 用于保存所述连接选择上下文。
结合第三方面的第八种可能的实现方式, 在第三方面的第九种可能的实现 方式中, 所述保存模块, 用于在预设时效期限内保存所述连接选择上下文。
结合第三方面的第八种可能的实现方式, 在第三方面的第十种可能的实现 方式中, 所述第二连接模块, 包括:
判断单元, 用于判断是否保存有所述终端对应的连接选择上下文; 确定单元, 用于当保存有所述终端对应的连接选择上下文时, 根据所述终 端对应的连接选择上下文确定所述终端选择的业务网络;
连接单元, 用于建立所述终端与所述终端选择的业务网络之间的连接。 第四方面, 提供了一种终端, 所述终端包括:
第一接入模块, 用于接入第一 WLAN;
第一连接模块, 用于建立和网关的用户面连接;
发送模块, 用于通过建立的用户面连接向所述网关发送连接选择请求, 所 述连接选择请求中包括连接选择信息;
第二连接模块, 用于通过所述网关建立与所述连接选择请求中的连接选择 信息对应的业务网络之间的连接。
结合第四方面, 在第四方面的第一种可能的实现方式中, 所述终端, 还包 括:
第一选择模块, 用于选择第一 WLANAP;
第一关联模块, 用于与所述第一 WLANAP建立关联;
第一请求模块, 用于向所述网关请求接入所述第一 WLAN AP对应的第一 WLAN;
第一接收模块, 用于在所述网关进行成功鉴权及授权后, 接收所述网关发 送的第一终端地址;
所述第一接入模块 ,用于通过关联的第一 WLAN AP接入所述第一 WLAN AP对应的第一 WLAN;
第一传输模块, 用于与所述第一 WLAN之间传输用所述第一终端地址标 识的数据包。
结合第四方面, 在第四方面的第二种可能的实现方式中, 所述发送模块, 包括:
接收单元, 用于接收网关通过建立的用户面连接发送的包括可供选择的连 接选择信息的连接信息;
显示单元, 用于在用户界面上显示接收到的连接信息;
第一获取单元, 用于获取用户通过用户界面选择的连接选择信息; 第一发送单元, 用于通过建立的用户面连接向网关发送包含用户选择的连 接选择信息的连接选择请求。
结合第四方面, 在第四方面的第三种可能的实现方式中, 所述发送模块, 包括:
第二获取单元, 用于通过用户界面获取预先配置的连接选择信息; 第二发送单元, 用于通过建立的用户面连接向网关发送包含预先配置的连 接选择信息的连接选择请求。
结合第四方面, 在第四方面的第四种可能的实现方式中, 所述终端, 还包 括:
第二选择模块, 用于选择第二 WLANAP;
第二关联模块, 用于与所述第二 WLANAP建立关联;
第二请求模块, 用于向所述网关请求接入所述第二 WLAN AP对应的第二 WLAN;
第二接收模块, 用于在所述网关进行成功鉴权及授权后, 接收所述网关发 送的第二终端地址;
第二接入模块, 用于通过关联的第二 WLAN AP接入所述第二 WLAN AP 对应的第二 WLAN;
第二传输模块, 用于与所述第二 WLAN之间传输用所述第二终端地址标 识的数据包。
本发明实施例提供的技术方案带来的有益效果是:
通过和终端建立的用户面连接接收终端发送的包括连接选择信息的连接 选择请求, 并根据连接选择信息确定终端选择的业务网络后, 建立终端与终端 选择的业务网络之间的连接, 从而实现终端可以连接不同的业务网络, 使得网 络连接的方式更加灵活, 简化了终端和网关的交互, 扩大了网络连接范围。 附图说明
为了更清楚地说明本发明实施例中的技术方案, 下面将对实施例描述中所 需要使用的附图作简单地介绍, 显而易见地, 下面描述中的附图仅仅是本发明 的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下, 还可以根据这些附图获得其他的附图。
图 1是本发明一实施例提供的系统的结构示意图; 图 2是本发明另一实施例提供的系统的结构示意图;
图 3是本发明另一实施例提供的建立网络连接的方法的流程图; 图 4是本发明另一实施例提供的建立网络连接的方法的流程图; 图 5是本发明另一实施例提供的建立网络连接的方法的流程图; 图 6是本发明另一实施例提供的用户界面的示意图;
图 7是本发明另一实施例提供的连接网络的流程图;
图 8是本发明另一实施例提供的连接网络的流程图;
图 9是本发明另一实施例提供的连接网络的流程图;
图 10是本发明另一实施例提供的网关的结构示意图;
图 11是本发明另一实施例提供的网关的结构示意图;
图 12是本发明另一实施例提供的网关的结构示意图;
图 13是本发明另一实施例提供的网关的结构示意图;
图 14是本发明另一实施例提供的网关的结构示意图;
图 15是本发明另一实施例提供的网关的结构示意图;
图 16是本发明另一实施例提供的网关的结构示意图;
图 17是本发明另一实施例提供的网关的结构示意图;
图 18是本发明另一实施例提供的第二连接模块的结构示意图;
图 19是本发明另一实施例提供的终端的结构示意图;
图 20是本发明另一实施例提供的终端的结构示意图;
图 21是本发明另一实施例提供的发送模块的结构示意图;
图 22是本发明另一实施例提供的发送模块的结构示意图;
图 23是本发明另一实施例提供的终端的结构示意图;
图 24是本发明另一实施例提供的建立网络连接的系统的结构示意图。 具体实施方式
为使本发明的目的、 技术方案和优点更加清楚, 下面将结合附图对本发明 实施方式作进一步地详细描述。
针对通过 WLAN连接业务网络的方式, 本发明实施例提供了一种建立网 络连接的方法, 该方法适用于图 1或图 2所示的系统。
图 1所示的系统包括终端、 网关及其他网络侧设备; 其中, 终端包括 UE ( User Equipment, 用户设备 )和 CSF ( Connection Selection Function, 连接选 择功能 ) Client (客户端); 网关包括 AC ( Access Controller,接入控制器 ) /BNG ( Broadband Network Gateway,宽带网络网关)、 CSF和 TGW( Trusted Gateway, 鉴权、授权和记账 )、 HSS ( Home Subscriber Server,归属签约用户服务器)/HLR ( Home Location Register, 归属位置寄存器)及 PGW ( Packet Data Network Gateway, 分组数据网络网关) /GGSN ( Gateway General Packet Radio Service Support Node, 网关通用分组无线服务支持节点)。终端通过 WLANAP ( Access Point, 接入点 )连接网关后, 可通过网关连接 PDN ( Packet Data Network, 分 组数据网络)或 NSWO ( Non Seamless Wireless Local Area Network Offload, 非无缝无线局域网分流)。
Network, 可信无线局域网接入网络)时, AC/BNG与 TGW对 UE的鉴权和授 权功能对应于 TWAN 中的 TWAP ( Trusted Wireless Local Area Network Authentication Authorisation Accounting Proxy , 可信无线局域网鉴权、 4受权和 "i己 账代理 ) , AC/BNG与 TGW对 UE的用户面管理功能对应于 TWAN中的 TWAG 关)。
CSF可以位于 AC/BNG与 TGW之间, CSF与 TGW之间有接口 Set; CSF 还可以与 AC/BNG或 TGW合一。若 AC/BNG与 TGW合一,则可以作为 T WAG , 则 CSF集成在 TWAG/TWAP内。
当 UE连接 NSWO时, 如果 UE的用户面数据包由 AC/BNG路由出, 则 CSF与 AC/BNG之间有接口 Sac。 当 UE连接 NSWO时, 如果 UE的用户面数 据包由 TGW路由出, 则 CSF与 AC/BNG之间可以没有接口。
图 2所示的系统包括终端、 网关及其他网络侧设备; 其中, 终端包括 UE 和 CSF Client; 网关包括 AC/BNG、 CSF、 NAT ( Network Address Translation , 网络地址转换)和 TGW;其他网络侧设备包括 AAA、 HSS/HLR及 PGW/GGSN。 其中, NAT可以位于 TGW内, 或位于 AC/BNG内, 或位于 TGW与 AC/BNG 之间 (本实施例以图 2中的 NAT位于 TGW内为例)。 终端通过 WLAN AP连 接网关后, 可通过网关连接 PDN或 NSWO。 见图 3 , 本实施例提供的方法流程包括:
301 : 建立和终端的用户面连接, 终端接入第一 WLAN;
作为一种可选实施例, 建立和终端的用户面连接之前, 还包括:
对请求接入第一 WLANAP对应的第一 WLAN的终端进行鉴权; 若鉴权成功, 则对终端进行授权, 并向终端发送第一终端地址, 使终端接 入第一 WLAN AP对应的第一 WLAN , 并在终端与第一 WLAN之间传输用第 一终端地址标识的数据包。
作为一种可选实施例, 向终端发送第一终端地址之后, 还包括:
通过网络地址转换或网络地址及端口转换在终端和初始业务网络之间传 输用第一终端地址标识的数据包和用访问初始业务网络的终端地址标识的数 据包。
302: 通过建立的用户面连接接收终端发送的连接选择请求, 连接选择请 求中包括连接选择信息;
作为一种可选实施例, 通过建立的用户面连接接收终端发送的连接选择请 求之后, 还包括:
当终端断开与第一 WLAN AP对应的第一 WLAN的连接, 重新选择接入 第二 WLAN AP对应的第二 WLAN时 , 对终端进行鉴权; 若鉴权成功, 则对终端进行授权, 并向终端发送第二终端地址, 使终端接 入第二 WLAN AP对应的第二 WLAN , 并在终端与第二 WLAN之间传输用第 二终端地址标识的数据包。
作为一种可选实施例, 对终端进行授权之后, 还包括:
从初始业务网络获取为终端分配的访问初始业务网络的终端地址; 或,
根据终端的签约信息为终端选择 PGW或 GGSN,并建立到 PGW或 GGSN 的承载;
从 PGW或 GGSN获取为终端分配的访问初始业务网络的终端地址。 作为一种可选实施例, 通过建立的用户面连接接收终端发送的连接选择请 求, 包括:
通过建立的用户面连接向终端发送包括可供选择的连接选择信息的连接 信息, 并通过建立的用户面连接接收终端根据连接信息发送的连接选择请求; 或者,通过建立的用户面连接接收终端根据预先配置的连接选择信息发送 的连接选择请求。
作为一种可选实施例, 通过建立的用户面连接接收终端发送的连接选择请 求之后, 还包括:
根据连接选择请求建立终端对应的连接选择上下文, 连接选择上下文中至 少包括终端的标识、 终端选择的业务网络及连接信息;
保存连接选择上下文。
作为一种可选实施例, 保存连接选择上下文, 包括:
在预设时效期限内保存连接选择上下文。
303: 根据连接选择请求中的连接选择信息确定终端选择的业务网络; 作为一种可选实施例,根据连接选择请求中的连接选择信息确定终端选择 的业务网络之后, 还包括:
根据签约信息或网络配置确定是否接受终端连接业务网络; 如果接受终端连接业务网络, 则执行建立终端与终端选择的业务网络之间 的连接的步骤。
304: 建立终端与终端选择的业务网络之间的连接。
作为一种可选实施例, 建立终端与终端选择的业务网络之间的连接之后, 还包括:
为终端分配访问终端选择的业务网络的终端地址;
通过网络地址转换或网络地址及端口转换在终端和终端选择的业务网络 之间传输用第一终端地址标识的数据包和用访问终端选择的业务网络的终端 地址标识的数据包。
作为一种可选实施例,建立终端与终端选择的业务网络之间的连接,包括: 判断是否保存有终端对应的连接选择上下文;
若保存有终端对应的连接选择上下文, 则根据终端对应的连接选择上下文 确定终端选择的业务网络, 并建立终端与终端选择的业务网络之间的连接。
参见图 4, 以终端执行本发明实施例提供的建立网络连接的方法的角度为 例, 本发明实施例提供的方法流程包括:
401 : 接入第一 WLAN, 并建立和网关的用户面连接;
作为一种可选实施例, 建立和网关的用户面连接之前, 还包括:
选择第一 WLANAP, 与第一 WLANAP建立关联;
向网关请求接入第一 WLAN AP对应的第一 WLAN,并在网关进行成功鉴 权及授权后, 接收网关发送的第一终端地址, 通过关联的第一 WLAN AP接入 第一 WLAN AP对应的第一 WLAN, 并与第一 WLAN之间传输用第一终端地 址标识的数据包。
402: 通过建立的用户面连接向网关发送连接选择请求, 连接选择请求中 包括连接选择信息;
作为一种可选实施例, 通过建立的用户面连接向网关发送连接选择请求, 包括: 接收网关通过建立的用户面连接发送的包括可供选择的连接选择信息的 连接信息;
在用户界面上显示接收到的连接信息, 并获取用户通过用户界面选择的连 接选择信息;
通过建立的用户面连接向网关发送包含用户选择的连接选择信息的连接 选择请求。
作为一种可选实施例, 通过建立的用户面连接向网关发送连接选择请求, 包括:
通过用户界面获取预先配置的连接选择信息, 并通过建立的用户面连接向 网关发送包含预先配置的连接选择信息的连接选择请求。
作为一种可选实施例, 通过建立的用户面连接向网关发送连接选择请求之 后, 还包括:
选择第二 WLANAP, 并与第二 WLANAP建立关联;
向网关请求接入第二 WLAN AP对应的第二 WLAN,并在网关进行成功鉴 权及授权后, 接收网关发送的第二终端地址, 通过关联的第二 WLAN AP接入 第二 WLAN AP对应的第二 WLAN, 并与第二 WLAN之间传输用第二终端地 址标识的数据包。
403: 通过网关建立与连接选择请求中的连接选择信息对应的业务网络之 间的连接。
本发明实施例提供的方法,通过和终端建立的用户面连接接收终端发送的 包括连接选择信息的连接选择请求, 并根据连接选择信息确定终端选择的业务 网络后, 建立终端与终端选择的业务网络之间的连接, 从而实现终端可以连接 不同的业务网络, 使得网络连接的方式更加灵活, 简化了终端和网关的交互, 扩大了网络连接范围。 本发明实施例提供了一种建立网络连接的方法, 以图 1所示的系统为例, 对本发明实施例提供的方法进行详细地解释说明。 参见图 5, 方法流程包括: 501 : 终端接入第一 WLAN, 并建立和网关的用户面连接;
作为一种可选实施例, 终端接入第一 WLAN, 包括但不限于:
选择第一 WLAN AP, 并与第一 WLAN AP建立关联;
向网关请求接入第一 WLAN AP对应的 WLAN,并在网关进行成功鉴权及 授权后 , 通过关联的第一 WLAN AP接入第一 WLAN AP对应的 WLAN。
建立和网关的用户面连接之前, 网关对终端接入第一 WLAN进行鉴权及 授权的过程, 包括但不限于:
对请求接入第一 WLANAP对应的第一 WLAN的终端进行鉴权; 若鉴权成功, 则对终端进行授权, 使终端接入第一 WLANAP对应的第一
WLAN„
具体实施时, 参见图 1 所示的系统, AC/BNG及 TGW对请求接入第一 WLAN AP对应的第一 WLAN的终端进行鉴权和授权,鉴权的过程包括但不限 于: HSS/HLR将 UE的签约信息通过 AAA服务器发送给 TWAN, 即发送给用 于对 UE进行鉴权和授权的 TGW和 AC/BNG, 同时 AAA服务器还将 UE的 ID (标识)发送给 TWAN对应的 TGW;其中, UE的 ID可以为 IMSK International Mobile Subscriber Identification Number, 国际移动用户识别码)。 由 AC/BNG 根据终端的签约信息确定是否接受终端接入第一 WLAN AP对应的 WLAN的 请求; 若确定接受终端接入第一 WLAN AP对应的 WLAN的请求, 则鉴权成 功。 当鉴权成功时, 对终端进行授权, 使终端接入第一 WLANAP对应的第一 WLAN„
需要说明的是, 本实施例提供的方法以终端和网关之间进行 EAP ( Extensible Authentication Protocol , 可扩展鉴权协议 )鉴权的方式为例进行说 明。 当然, 除了 EAP ( EAP-SIM ( Subscriber Identity Module, 签约用户标识模 块)、 EAP-AKA ( Authentication and Key Agreement, 鉴权和密钥协定)、 EAP-AKA'、 EAP-PEAP ( Protected Extensible Authentication Protocol , 受保护的 可扩展鉴权协议) 等) 鉴权方式外, 还可以釆用其他鉴权方式, 例如 PSK ( Pre-Shared Key, 预共享密钥)、 Portal等, 本实施例对此不作具体限定。
此外, 网关对终端进行鉴权及授权时, 还包括向终端发送第一终端地址的 步骤, 从而后续可以在终端与第一 WLAN之间传输用第一终端地址标识的数 据包。 对于终端侧, 还包括接收网关发送的第一终端地址的过程, 从而后续与 第一 WLAN之间传输用第一终端地址标识的数据包。 其中, 网关向终端发送 的第一终端地址可以是网关分配的终端地址, 也可以是网关通过 DHCP ( Dynamic Host Configuration Protocol,动态主机配置协议 )的方式获取到的终 端地址, 本实施例不对网关获取第一终端地址的方式进行限定。 关于第一终端 地址标识的数据包, 在终端与第一 WLAN的上行方向上, 第一终端地址可以 作为数据包 IP包头的源地址, 在终端与第一 WLAN的下行方向上, 第一终端 地址可以作为数据包 IP包头的目的地址。
作为一种可选实施例, 网关对终端进行授权之后, 还包括但不限于如下两 个可选步骤中的一个可选步骤:
可选步骤一: 从初始业务网络获取为终端分配的访问初始业务网络的终端 地址;
可选步骤二: 根据终端的签约信息为终端选择 PGW或 GGSN, 并建立到 PGW或 GGSN的承载; 从 PGW或 GGSN获取为终端分配的访问初始业务网 络的终端地址。
其中, 本实施例不对初始业务网络进行限定, 该初始业务网络可以是默认 的业务网络,或是网关为终端选择的初始业务网络。针对上述第一种可选步骤, 本实施例不对从初始业务网络获取为终端分配的访问初始业务网络的终端地 址的方式进行限定。 针对上述第二种可选步骤, 参见图 1所示的系统, 网关对 终端进行授权之后, 由 TGW根据终端签约信息中的缺省 APN ( Access Point Name, 接入点名)为终端选择 PGW/GGSN, 当 TGW连接 PGW时, TGW与 PGW之间的 S2a隧道^ ^于 GTP ( General Packet Radio Service Tunnelling Protocol,通用分组无线服务隧道协议)隧道的 , TGW向 PGW发送 Create Session Request (创建会话请求), 该 Create Session Request中包含 IMSI, APN, PCO ( Protocol Configuration Option , 协议西己置选项 ) , RAT ( Radio Access Technology, 无线接入技术) type (类型), TWAN TEID ( Tunnel Endpoint ID, 隧道端点标识符 ) of the control plane (控制面), PDN Type, PDN Address (地 址), EPS ( Evolved Packet System,演进分组系统) Bearer Identity ( 载标识), Default EPS Bearer QoS (默认演进分组系统承载服务质量), TWAN Address for the user plane (用户面的可信无线局域网接入网络地址), TWAN TEID of the user plane (用户面的可信无线局域网接入网络隧道端点标识符), APN-AMBR ( Aggregate Maximum Bit Rate, 聚合最大比特速率), Selection Mode (选择模 式), Dual Address Bearer Flag (双重地址承载标志), Trace Information (跟踪 信息 ), Charging Characteristics (计费特征 ), Additional parameters (附力口参数 )。 其中, RAT type指示 WL AN接入。
PGW向 TGW返回 Create Session Response (创建会话响应), 该 Create Session Response 包含 PDN GW Address for the user plane (用户面的分组数据 网络网关地址), PDN GW TEID of the user plane (用户面的分组数据网络网关 隧道端点标识符), PDN GW TEID of the control plane (控制面的分组数据网络 网关隧道端点标识符), PCO, PDN Type, PDN Address, EPS Bearer Identity, EPS Bearer QoS, APN-AMBR, Additional parameters (附加参数), Cause (原 因)。其中, PDN address是为终端分配的 IP地址, PGW可能根据 PCC ( Policy Control and Charging, 策略控制和计费)策略发起该 PDN连接的其他多个专用 承载建立。
当 TGW连接 PGW时, TGW与 PGW之间的 S2a隧道还可以^ ^于 PMIP ( Proxy Mobile Internet Protocol, 代理移动互联网协议)隧道的, 则 TGW中的 MAG ( Mobile Access Gateway, 移动接入网关) 向 PGW发送 Proxy Binding Update (代理绑定更新), 携带 Create Session Request所携带的 APN, PCO, PDN Type , RAT Type 等参数。 PGW 向 TGW 返回 Proxy Binding Acknowledgement代理绑定确认),携带 Create Session Response所携带的 PDP ( Packet Data Protocol , 分组数据协议) Type , PDP Address , Protocol Configuration Options (协议西己置选项 )等参数。
当 TGW连接 GGSN时, TGW向 GGSN发送 Create PDP Context Request
(创建分组数据协议上下文请求), 该 Create PDP Context Request中包含 PDP Type, PDP Address, Access Point Name, QoS Negotiated (协商的服务质量), Negotiated Evolved ARP ( Address Resolution Protocol, 地址解析协议), TEID, NSAPI ( Network Service Access Point Identifier, 网络服务接入点标识符), MSI SDN ( Mobile Station International Integrated Service Digital Network Number , 移动台国际综合业务数字网号码), Selection Mode , Charging Characteristics , Trace Reference (跟踪参考), Trace Type (跟踪类型), Trigger Id (触发器标识), OMC ( Operations and Maintenance Center, 操作维护中心) Identity, Protocol Configuration Options, serving network identity (月良务网络标 i只 ), Maximum APN Restriction (最大接入点名区 i或 ) IMEISV ( International Mobile Equipment Identity software version,移动台识别码软件版本), CGI ( Cell Global Identifier, 全球小区识别码) /SAI ( Server Availability Index, 服务器可 用性指数), RAT type, S-CDR ( Serving General Packet Radio Service Support Node-Charging Data Recording服务通用分组无线服务支持节点-计费数据记录 ) CAMEL ( Customized Applications for Mobile Network Enhanced Logic, 移动网 络增强還辑的客户化应用) information, MS Info Change Reporting support indication(移动用户信息变更报告支持指示), NRSN, Dual Address Bearer Flag, APN-AMBR, max MBR/APN-AMBR„ 文响应),该 Create PDP Context Response中包含 TEID, PDP Type , PDP Address , Protocol Configuration Options , QoS Negotiated , Negotiated Evolved ARP , Charging Id (计费标识), Prohibit Payload Compression (禁止负载压缩), APN Restriction , Cause , MS Info Change Reporting Action (移动用户信息变更才艮告 动作) , CSG ( Closed Subscriber Grou , 闭合用户群) Information Reporting Action, BCM ( Basic Call Management, 基本呼叫管理), APN-AMBR。
需要说明的是, 无论釆用上述哪种可选步骤, 网关为终端分配访问初始业 务网络的终端地址之后, 可以接收通过鉴权的 UE向网关发送的 DHCP请求, 网关根据该 DHCP请求将为终端分配的访问初始业务网络的终端地址携带在 DHCP响应中返回给终端, 使终端根据该访问初始业务网络的终端地址访问初 始业务网络。 其中, UE向网关发送 DHCP请求的过程可以在网关对 UE进行 接入鉴权, 并为 UE选择 PGW或 GGSN, 建立到 PGW或 GGSN的承载之后 执行。 可选地 , 也可以在网关对 UE进行鉴权之后, UE向网关发送 DHCP请 求, 触发网关为 UE选择 PGW或 GGSN, 建立到 PGW或 GGSN的承载, 从 PGW或 GGSN获取为 UE分配的访问初始业务网络的终端地址的步骤。 无论 釆用哪种顺序, 当建立终端到初始业务网络连接后, UE 均可以使用为其分配 的访问初始业务网络的终端地址访问初始业务网络, 即向初始业务网络发送上 行数据包或接收初始业务网络发送的下行数据包。
进一步地, 由于初始业务网络为建立终端到初始业务网络连接后, 由于初 始业务网络为缺省的业务网络, 终端无法获知初始业务网络的类型, 对终端使 用业务产生障碍, 因此, 为了使连接网络的方式更加灵活, 本实施例提供的方 法在终端和网关之间建立用户面连接,从而通过手续步骤实现根据用户面连接 使终端可以选择不同的连接, 接入不同的业务网络。 其中, 建立用户连接的方 式可以有多种, 本实施例对此不作具体限定。 例如, 终端通过连接的业务网络 建立和网关的用户面连接, 网关通过连接的业务网络建立和终端的用户面连 接, 建立的过程为:
( 1 ) 终端向网关发送上行 IP数据包, 目的地址填写特定地址(例如, 192.168.254.254 ), 还可以设置特定 UDP端口 (例如, 8008 )。 ( 2 )网关执行 SPI ( Serial Peripheral Interface, 串行外设接口), 检查上行 数据包, 截获该特定地址的 IP数据包后, 根据该 IP数据包的源地址向 TGW 查询, 并与该终端的链路对比, 验证该 IP数据包(CSF连接建立请求) 的合 法性。 若该 IP数据包由已通过接入鉴权的终端发送, 则该 IP数据包合法, 可 继续执行后续步骤; 若该 IP数据包由未通过接入鉴权的终端发送, 则该 IP数 据包不合法, 终止用户面连接的建立过程。
( 3 )网关在验证 IP数据包合法后, 向终端发送回复 IP包, 终端在接收回 复 IP 包到后, 终端与网关的连接建立成功, 即终端和网关之间的用户面连接 的建立成功。
需要说明的是, 在建立连接的过程中, 终端和网关之间可能会进行多次交 互。 可选地, 为了便于网关对终端进行验证, 终端还可以在与网关交互的过程 中,在发送的上行 IP数据包中携带终端的 ID,该终端的 ID包括但不限于终端 的 IMSI等。 此外, 针对图 1所示的系统, 上述网关所执行的功能可以由 CSF 执行。
502: 终端通过建立的用户面连接向网关发送连接选择请求, 连接选择请 求中包括连接选择信息;
关于终端通过建立的用户面连接向网关发送的连接选择请求中包括的连 接选择信息的获取方式, 本实施例不作具体限定。 作为一种可选实施例, 为了 终端能够通过建立的用户面连接向网关发送连接选择请求, 网关通过建立的用 户面连接向终端发送连接信息, 连接信息包括可供选择的连接选择信息; 终端 接收网关通过建立的用户面连接发送的连接信息; 可选地, 终端还可在用户界 面上显示接收到的连接信息, 并获取用户通过用户界面选择的连接选择信息; 最后, 终端通过建立的用户面连接向网关发送包含用户选择的连接选择信息的 连接选择请求, 从而完成终端通过建立的用户面连接向网关发送连接选择请 求。
其中, 网关通过建立的用户面连接向终端发送连接信息时,可由 CSF向终 端发送连接信息, 该连接信息可以是 CSF从 TGW获取的。 连接信息可以包含 但不限于当前连接类型 (如 PDN或 NSWO连接类型)、 当前连接的业务网络 名称(如网络名称为 APN或 PDN ID/PDN name )、 终端签约的连接类型、 终端 签约的业务网络名称、 本 WLAN接入支持的可由终端连接的连接类型、 本 WLAN接入支持的可由终端连接的业务网络名称、缺省的连接类型、缺省连接 的业务网络名称中的一个或多个信息。 可选地, 为使终端侧的用户能够直观识 别连接信息中的信息, 每种信息还可携带该信息对应的图标或文字。
参见图 6所示的用户界面, 如果显示接收到的连接信息, 可由终端的 CSF 客户端将接收到的连接信息在用户界面上进行显示, 获取用户选择的连接选择 信息。 该用户界面显示的连接信息可以包括但不限于连接类型以及业务网络名 称; 当前连接、 可选择的连接、 不可选择的连接可以区别显示(例如显示不同 的颜色等, 不可选择的连接在用户界面上可以显示为不可选择)。 还可为每个 连接提供用户缺省连接选项, 用户可将任一连接设置为用户缺省连接, 从而在 终端连接到网络后, CSF客户端自动为终端选择该用户缺省连接, 从而提高连 接网络的效率。 另外还可提供修改项, 获取用户通过修改项手动修改或增加的 APN信息, 例如增加 APN, 或修改 CSF客户端已有连接信息的 APN、 PCO、 PDN Type/PDP Type等。
CSF客户端将 PDN连接、 NSWO以及该连接的 APN信息 (APN、 PCO、 PDN Type/PDP Type等) 中的一个或多个作为连接选择信息携带在连接选择请 求中发送给 CSF, 从而完成向网关发送连接选择请求。
作为一种可选实施例, 除了由网关向终端发送可供选择的连接选择信息的 连接信息, 终端据此获取用户选择的连接选择信息外, 终端还可以通过用户界 面获取预先配置的连接选择信息, 并通过建立的用户面连接向网关发送包含预 先配置的连接选择信息的连接选择请求。
503: 网关通过建立的用户面连接接收终端发送的连接选择请求, 并根据 连接选择请求中的连接选择信息确定终端选择的业务网络; 作为一种可选实施例, 若终端通过建立的用户面连接向网关发送包含用户 选择的连接信息的连接选择请求, 则网关通过建立的用户面连接接收终端根据 连接信息发送的连接选择请求。 具体实施时, 参见图 1所示的系统, 可由 CSF 接收连接选择请求。
此外 ,由于终端将 PDN连接、 NSWO以及该连接的 APN信息( APN、 PCO、 PDN Type/PDP Type等) 中的一个或多个信息作为连接选择信息携带在连接选 择请求中, 因而网关接收到终端发送的连接选择请求后, 可以根据连接选择请 求中的连接选择信息确定终端选择的业务网络。
作为一种可选实施例, 通过建立的用户面连接接收终端发送的连接选择请 求之后, 还包括但不限于:
根据连接选择请求建立终端对应的连接选择上下文, 连接选择上下文中至 少包括终端的标识、 终端选择的业务网络及连接信息;
保存连接选择上下文。
其中,保存连接选择上下文时,可在预设有效期限内保存连接选择上下文, 当超出该预设有效期限后, 将不再保存连接选择上下文。 关于预设有效期限的 长短, 本实施例不作具体限定。
当终端选择 NSWO时, 并且 NSWO的数据包是由 AC/BNG经 CSF,但不 经过 TGW路由出, 则 CSF通知 AC/BNG该终端选择 NSWO, 并携带该终端 的 ID。 TGW或 AC/BNG为终端建立连接选择上下文, 记录终端的 ID、 选择 的连接(连接 PDN或 NSWO )和连接信息(例如 APN、 PCO、 PDN Type/PDP Type等), 并启动连接选择定时器, 在连接选择定时器的值所限定的时间内进 行网络连接。
其中,连接选择定时器的值可根据运营商策略由 TGW或 AC/BNG本地配 置, 也可由 CSF发送给 TGW或 AC/BNG。 当由 CSF发送给 TGW时, 可以由 终端的 CSF客户端在发送连接选择请求时将发给 CSF。
504: 网关确定是否接受终端连接终端选择的业务网络; 该步骤为可选步骤, 关于网关确定是否接受终端连接终端选择的业务网络 的方式, 本实施例不作具体限定。 具体实施时, 包括但不限于根据终端的签约 信息或网络配置确定是否接受终端连接终端选择的业务网络; 如果接受终端连 接终端选择的业务网络, 则执行后续步骤。
参见图 1所示的系统, 可由 CSF将终端的 ID及接收到连接选择请求中的 连接选择信息发送给 TGW, 由 TGW根据终端的签约信息及本地网络配置(例 如, 是否支持、 允许 NSWO, 是否支持、 允许连接到终端选择的 PDN )确定 是否接受终端连接终端选择的业务网络。
505: 如果确定接受终端连接终端选择的业务网络, 则网关向终端返回连 接选择确认响应;
该步骤为可选步骤, 当网关在确定接受终端连接终端选择的业务网络后, 网关向终端返回连接选择确认响应。
需要说明的是, AC/BNG与 TGW对终端的用户面管理对应于 TWAG。 例 如, TGW或 AC/BNG在确定接受终端连接终端选择的业务网络后, 发送连接 选择确认响应给 CSF。
506: 终端断开与第一 WLAN的连接, 并接入第二 WLAN;
当终端接收到网关发送的连接选择确认响应后, 断开与第一 WLAN的连 接, 并接入第二 WLAN。 在重新选择连接的第二 WLAN 时, 终端选择第二 WLANAP, 并与第二 WLAN AP建立关联。
需要说明的是, 由于终端已连接第一 WLANAP对应的第一 WLAN, 则终 端在连接第二 WLAN AP对应的第二 WLAN时, 还可断开连接的第一 WLAN AP对应的第一 WLAN。 若断开连接的第一 WLANAP对应的第一 WLAN, 则 在 CSF向 CSF客户端发送连接选择回复后, 即可断开连接的第一 WLAN AP 对应的第一 WLAN。
本次终端重新连接 WLAN时, 可以选择上次关联的 WLANAP,上次关联 的 WLANAP可根据 CSF客户端保存的 BSSID( Basic Service Set Identification, 基本业务集标识), WLAN AP的 MAC ( Medium Access Control, 媒体访问控 制)地址获得, 即第二 WLAN AP 与第一 WLAN AP相同, 第二 WLAN与第 一 WLAN相同; 可选地, 终端还可以选择与上次关联的 WLAN AP对应的 WLAN的相同 SSID ( Service Set Identifier, 服务集标识) 的其他 WLAN AP, 其他 WLAN AP可根据 CSF客户端保存的 BSSID获得;还可以是根据 HESSID ( Homogenous Extended Service Set Identifier, 同源扩展业务集标识符 )对应的 同属一个 WLAN AP组中的其他 AP, 即第二 WLAN AP与第一 WLAN AP不 同, 第二 WLAN与第一 WLAN不同。
可选地,若 CSF向 CSF客户端发送连接选择回复中携带网络指示的 WLAN 标识(例如, SSID, BSSID等), 则终端可根据该标识连接对应的 WLAN。
本发明实施例提供的方法在终端接入第二 WLAN时, 由终端向网关请求 接入第二 WLAN AP对应的第二 WLAN; 网关对终端进行鉴权; 若鉴权成功, 则网关对终端进行授权; 终端通过关联的第二 WLAN AP接入第二 WLAN AP 对应的 WLAN。
网关对终端进行鉴权的过程与上述步骤 501 中网关对请求接入第一 WLANAP对应的第一 WLAN的终端进行鉴权的过程相同,具体详见上述步骤 501中的内容, 此处不再赘述。
此外, 网关对终端进行鉴权及授权时, 还包括向终端发送第二终端地址的 步骤, 从而后续可以在终端与第二 WLAN之间传输用第二终端地址标识的数 据包。 对于终端侧, 还包括接收网关发送的第二终端地址的过程, 从而后续与 第二 WLAN之间传输用第二终端地址标识的数据包。 其中, 关于第二终端地 址标识的数据包, 在终端与第二 WLAN的上行方向上, 第二终端地址可以作 为数据包 IP包头的源地址, 在终端与第二 WLAN的下行方向上, 第二终端地 址可以作为数据包 IP包头的目的地址。
需要说明的是, 其中, 网关向终端发送的第二终端地址可以是网关分配的 终端地址, 也可以是网关通过 DHCP的方式获取到的终端地址, 本实施例不对 网关获取第二终端地址的方式进行限定。 此外, 上述网关向终端发送的第二终 端地址与第一终端地址可以相同, 也可以不同, 本实施例对此不作具体限定。
507: 网关建立终端与终端选择的业务网络之间的连接。
关于网关建立终端与终端选择的业务网络之间的连接的方式, 本实施例不 作具体限定。 具体实施时, 网关除了可以查询终端发送的连接选择请求中携带 的连接选择信息来确定终端选择的业务网络, 作为一种可选实施例, 网关还可 以判断是否保存有终端对应的连接选择上下文; 若保存有终端对应的连接选择 上下文, 则根据终端对应的连接选择上下文确定终端选择的业务网络, 并建立 终端与终端选择的业务网络之间的连接。
网关建立终端与终端选择的业务网络之间的连接后, 为了能够使终端实现 访问业务网络, 网关还可以为终端分配访问终端选择的业务网络的终端地址的 步骤, 并将该访问终端选择的业务网络的终端地址返回给终端, 使终端根据访 问终端选择的业务网络的终端地址访问终端选择的业务网络。
关于网关为终端分配访问终端选择的业务网络的终端地址的方式, 本实施 例不做具体限定。 具体实施时, 网关可以接收通过鉴权的 UE 向网关发送的 DHCP请求, 网关根据该 DHCP请求将为终端分配的访问终端选择的业务网络 的终端地址携带在 DHCP响应中返回给终端,使终端根据该访问终端选择的业 务网络的终端地址访问终端选择的业务网络。
如果终端选择 PDN连接, 且终端的签约和运营商策略允许该终端接入选 择的 APN,即允许终端连接 PDN,则 TGW根据 APN为终端选择 PGW/GGSN, 向 PGW发送 Create Session Request,向 GGSN发送 Create PDP Context Request, APN填写终端选择连接的 APN。
在 TGW为 UE建立新的 PDN连接隧道(该隧道位于 TGW与 PGW/GGSN 之间)之前, 若 UE上次连接的是 PDN连接, 则 TGW可激活上次连接的 PDN 连接的隧道, 并释放资源 (例如 IP地址等)。 若 UE上次连接的是 NSWO, 则 AC/BNG或 TGW可释放终端的 NSWO资源 (例如 IP地址等)。
可选地, 如果 UE选择连接 NSWO, 且 NSWO的数据包是由 AC/BNG经 CSF, 但不经过 TGW路由出, 则由 AC/BNG为终端分配 IP地址, 即终端访问 终端选择的业务网络的终端地址。 AC/BNG在 DHCP ACK中将为终端分配的 IP地址返回给终端,并且该终端在连接终端选择的业务网络后发送的上行数据 包, 直接从 AC/BNG经过 CSF发出。
如果 UE选择连接 NSWO, 且 NSWO的数据包是由 TGW路由出, 则由 TGW为终端分配 IP地址, 即终端访问终端选择的业务网络的终端地址。 TGW 在 DHCP ACK中返回给终端, 并且该终端在连接终端选择的业务网络后发送 的上行数据包, 直接从 TGW送出。
如果 UE选择连接 PDN,则由 TGW将 PDN address或 PDP address在 DHCP ACK中返回给终端。 其中, 当接入 PGW时,返回 PDN address; 当接入 GGSN 时, 返回 PDP address。
在连接终端选择的业务网络后, 终端即可向终端选择的业务网络发送上行 数据包, 并接收终端选择的业务网络发送的下行数据包, 实现访问终端选择的 PDN的业务或 NSWO的业务。 其中, NSWO在 AC/BNG时, 下行 IP数据包 由 AC/BNG进入网络,发送给终端; NSWO在 TGW时,下行 IP数据包由 TGW 进入网络, 发送给终端。
需要说明的是, 如果终端需要再次选择连接选择信息, 以连接终端选择的 其他业务网络, 则可重新执行上述步骤 501至步骤 507的过程, 从而实现终端 连接终端选择的业务网络。
另外,针对图 1所示的系统中各个设备执行建立网络连接的过程可以对应 图 7所示的流程图。 其中, 图 7中的步骤 1至步骤 7对应步骤 501的内容, 步 骤 8对应步骤 502的内容, 步骤 9至步骤 11对应步骤 503至步骤 505的内容, 步骤 12至步骤 1对应步骤 506和步骤 507的内容。
作为一种可选实施例, 在图 1所示的系统中 CSF还可位于 PDN网络内, 或位于 NSWO网络内(例如 Internet )。终端通过 CSF的域名查询 DNS( Domain Name Service, 域名服务) server, 获取 CSF在该 PDN或 Internet中的 IP地 址, 并建立连接。
本实施例提供的方法, 通过和终端建立的用户面连接接收终端发送的包括 连接选择信息的连接选择请求, 并根据连接选择信息确定终端选择的业务网络 后, 建立终端与终端选择的业务网络之间的连接, 从而实现终端可以连接不同 的业务网络, 使得网络连接的方式更加灵活, 简化了终端和网关的交互, 扩大 了网络连接范围。 本发明实施例提供了一种建立网络连接的方法, 以图 2所示的系统对本发 明实施例提供的方法进行详细地解释说明。 参见图 8, 方法流程包括:
801 : 终端接入第一 WLAN, 并建立和网关的用户面连接;
该步骤中终端接入第一 WLAN,并建立和网关的用户面连接的实现方式可 参照上一实施例步骤 501中终端接入第一 WLAN,并建立和网关的用户面连接 的内容, 此处不再赘述。 与步骤 501不同的是, 终端在首次接入 TWAN时, TWAG为终端分配一个 IP地址, 该 IP地址可以是属于 AC/BNG/TGW地址域 的公网或者本地网络地址, 还可以是为终端建立的缺省 PDN连接(或第一个 PDN连接) 时, 为终端获取的 PDN地址。
此外, 由于图 2所示系统中包括 NAT实体, 因而网关为终端分配第一终 端地址及访问初始业务网络的终端地址后, 网关通过网络地址转换或网络地址 及端口转换在终端和初始业务网络之间传输用第一终端地址标识的数据包和 用访问初始业务网络的终端地址标识的数据包。
802: 终端通过建立的用户面连接向网关发送连接选择请求, 连接选择请 求中包括连接选择信息;
该步骤中终端通过建立的用户面连接向网关发送连接选择请求的实现方 式与上一实施例步骤 502中终端通过建立的用户面连接向网关发送连接选择请 求的实现方式相同,具体可参照上一实施例中步骤 502的内容,此处不再赘述。 803 : 网关通过建立的用户面连接接收终端发送的连接选择请求, 并根据 连接选择请求中的连接选择信息确定终端选择的业务网络;
该步骤的实现方式与上一实施例中步骤 503的实现方式相同, 具体可参照 上一实施例中步骤 503的内容, 此处不再赘述。
804: 网关确定是否接受终端连接终端选择的业务网络;
该步骤的实现方式与上一实施例中步骤 504的实现方式相同, 具体可参照 上一实施例中步骤 504的内容, 此处不再赘述。
805: 如果确定接受终端连接终端选择的业务网络, 则网关向终端返回连 接选择确认响应;
该步骤中网关向终端返回连接选择确认响应的实现方式与上一实施例中 步骤 505中网关向终端返回连接选择确认响应的实现方式相同, 具体可参照上 一实施例中步骤 505的内容, 此处不再赘述。
需要说明的是, 与上述实施例步骤 505的内容不同的是, 本实施例提供的 该步骤中, 终端在接收到网关返回的连接选择确认响应后, 无需断开与第一 WLAN的连接。
806: 网关建立终端与终端选择的业务网络之间的连接。
关于网关建立终端与终端选择的业务网络之间的连接的方式, 本实施例不 作具体限定。 具体实施时, 网关除了可以查询终端发送的连接选择请求中携带 的连接选择信息来确定终端选择的业务网络, 作为一种可选实施例, 网关还可 以判断是否保存有终端对应的连接选择上下文; 若保存有终端对应的连接选择 上下文, 则根据终端对应的连接选择上下文确定终端选择的业务网络, 并建立 终端与终端选择的业务网络之间的连接。
网关建立终端与终端选择的业务网络之间的连接后, 为了能够使终端实现 访问业务网络, 网关还可以为终端分配访问终端选择的业务网络的终端地址的 步骤, 并将该访问终端选择的业务网络的终端地址返回给终端, 使终端根据访 问终端选择的业务网络的终端地址访问终端选择的业务网络。
关于网关为终端分配访问终端选择的业务网络的终端地址的方式, 本实施 例不做具体限定。 具体实施时, 网关可以接收通过鉴权的 UE 向网关发送的 DHCP请求, 网关根据该 DHCP请求将为终端分配的访问终端选择的业务网络 的终端地址携带在 DHCP响应中返回给终端,使终端根据该访问终端选择的业 务网络的终端地址访问终端选择的业务网络。
参见图 2所示的系统, 若终端通过建立的用户面连接向网关发送的连接选 择信息是选择连接 PDN, 且终端签约和运营商策略允许该终端通过第一 APN 接入选择的 PDN,则 TGW根据 APN为终端选择 PGW/GGSN;如果选择 PGW, 则向 PGW发送 Create Session Request;如果选择 GGSN,则向 GGSN发送 Create PDP Context Request; 请求中的 APN填写终端选择连接的 APN。 PGW通过向 TGW发送 Create Session Response返回 PDN addres , GGSN向 TGW发送 Create PDP Context Response返回 PDP address。
需要说明的是, 由于本实施例提供的系统结构中还包括 NAT 实体, 因而 当终端向终端选择的业务网络发送上行数据时, NAT 实体为终端进行 NAT/NAPT ( Network Address Port Translation, 网络端口地址转换 )转换(转 换前为 TWAG 分配的地址, 转换后为 PGW/GGSN 分配的地址), 并发给 PGW/GGSN。 当终端发送下行数据时, NAT 实体为终端进行相反的转换, 并 发送给终端。
若终端选择连接 NSWO , 且终端签约和运营商策略允许该终端连接 NSWO, 当 TWAG为终端分配的是公网地址时, AC/BNG或 TGW直接发送终 端的上行数据包。当 TWAG为终端分配的是本地网络地址时, AC/BNG或 TGW 釆取与 PDN连接类似的方式, 将数据包经过 NAT实体进行地址转换(转换前 为 TWAG分配的本地网络地址, 转换后为 AC/BNG或 TGW地址域的地址), 发送上行数据包。
需要说明的是, 如果终端需要再次选择连接选择信息, 以连接终端选择的 其他业务网络, 则可重新执行上述步骤 801至步骤 806的过程, 从而实现终端 连接终端选择的业务网络。
另外,针对图 2所示的系统中各个设备执行建立网络连接的过程额可以对 应图 9所示连接网络的流程图。 其中, 图 9中的步骤 1至步骤 7对应步骤 801 的内容, 步骤 8对应步骤 802的内容, 步骤 9至步骤 11对应步骤 803至步骤 805的内容, 步骤 15至步骤 16对应步骤 806的内容。
本发明实施例提供的方法,通过和终端建立的用户面连接接收终端发送的 包括连接选择信息的连接选择请求, 并根据连接选择信息确定终端选择的业务 网络后, 建立终端与终端选择的业务网络之间的连接, 从而实现终端可以连接 不同的业务网络, 使得网络连接的方式更加灵活, 简化了终端和网关的交互, 扩大了网络连接范围。 参见图 10, 本发明实施例提供了一种网关, 该网关用于执行上述图 3、 图 5或图 8所示的实施例提供的建立网络连接的方法中网关所执行的方法, 该网 关包括:
第一连接模块 1001 ,用于建立和终端的用户面连接,终端接入第一 WLAN; 接收模块 1002 , 用于通过建立的用户面连接接收终端发送的连接选择请 求, 连接选择请求中包括连接选择信息;
第一确定模块 1003 ,用于根据连接选择请求中的连接选择信息确定终端选 择的业务网络;
第二连接模块 1004, 用于建立终端与终端选择的业务网络之间的连接。 作为一种可选实施例, 参见图 11 , 该网关, 还包括:
第一鉴权模块 1005 , 用于对请求接入第一 WLAN AP对应的第一 WLAN 的终端进行鉴权;
第一授权模块 1006, 用于当鉴权成功时, 对终端进行授权;
第一发送模块 1007 , 用于向终端发送第一终端地址, 使终端接入第一 WLAN AP对应的第一 WLAN;
第一传输模块 1008, 用于在终端与第一 WLAN之间传输用第一终端地址 标识的数据包。
作为一种可选实施例, 参见图 12, 该网关, 还包括:
第二鉴权模块 1009 ,用于当终端断开与第一 WLAN AP对应的第一 WLAN 的连接, 重新选择接入第二 WLAN AP对应的第二 WLAN时, 对终端进行鉴 权;
第二授权模块 1010, 用于当鉴权成功时, 对终端进行授权;
第二发送模块 1011 , 用于向终端发送第二终端地址, 使终端接入第二 WLAN AP对应的第二 WLAN;
第二传输模块 1012, 用于在终端与第二 WLAN之间传输用第二终端地址 标识的数据包。
作为一种可选实施例, 参见图 13 , 该网关, 还包括:
第一获取模块 1013,用于从初始业务网络获取为终端分配的访问初始业务 网络的终端地址;
或,选择模块 1014,用于根据终端的签约信息为终端选择 PGW或 GGSN; 第一建立模块 1015, 用于建立到 PGW或 GGSN的承载;
第二获取模块 1016,用于从 PGW或 GGSN获取为终端分配的访问初始业 务网络的终端地址。
作为一种可选实施例, 参见图 14, 该网关, 还包括:
第三传输模块 1017,用于通过网络地址转换或网络地址及端口转换在终端 和初始业务网络之间传输用第一终端地址标识的数据包和用访问初始业务网 络的终端地址标识的数据包。
作为一种可选实施例, 参见图 15, 网关, 还包括:
分配模块 1018, 用于为终端分配访问终端选择的业务网络的终端地址; 第四传输模块 1019,用于通过网络地址转换或网络地址及端口转换在终端 和终端选择的业务网络之间传输用第一终端地址标识的数据包和用访问终端 选择的业务网络的终端地址标识的数据包。
作为一种可选实施例, 参见图 16, 网关, 还包括:
第二确定模块 1020,用于根据终端的签约信息或网络配置确定是否接受终 端连接业务网络;
第二连接模块 1004,用于当接受终端连接业务网络时,执行建立终端与终 端选择的业务网络之间的连接的步骤。
作为一种可选实施例,接收模块 1002,用于通过建立的用户面连接向终端 发送包括可供选择的连接选择信息的连接信息, 并通过建立的用户面连接接收 终端根据连接信息发送的连接选择请求;
或者,接收模块 1002,用于通过建立的用户面连接接收终端根据预先配置 的连接选择信息发送的连接选择请求。
作为一种可选实施例, 参见图 17 , 网关, 还包括:
第二建立模块 1021 ,用于根据连接选择请求建立终端对应的连接选择上下 文,连接选择上下文中至少包括终端的标识、终端选择的业务网络及连接信息; 保存模块 1022, 用于保存连接选择上下文。
作为一种可选实施例,保存模块 1022,用于在预设时效期限内保存连接选 择上下文。
作为一种可选实施例, 参见图 18, 第二连接模块 1004 , 包括:
判断单元 10041 , 用于判断是否保存有终端对应的连接选择上下文; 确定单元 10042, 用于当保存有终端对应的连接选择上下文时, 根据终端 对应的连接选择上下文确定终端选择的业务网络;
连接单元 10043 , 用于建立终端与终端选择的业务网络之间的连接。
本发明实施例提供的网关,通过和终端建立的用户面连接接收终端发送的 包括连接选择信息的连接选择请求, 并根据连接选择信息确定终端选择的业务 网络后, 建立终端与终端选择的业务网络之间的连接, 从而实现终端可以连接 不同的业务网络, 使得网络连接的方式更加灵活, 简化了终端和网关的交互, 扩大了网络连接范围。 参见图 19, 本发明实施例提供了一种终端, 该终端用于执行上述图 4、 图 5或图 8所示的实施例提供的建立网络连接的方法中终端所执行的方法, 该终 端包括:
第一接入模块 1901 , 用于接入第一 WLAN;
第一连接模块 1902, 用于建立和网关的用户面连接;
发送模块 1903 ,用于通过建立的用户面连接向网关发送连接选择请求,连 接选择请求中包括连接选择信息;
第二连接模块 1904,用于通过网关建立与连接选择请求中的连接选择信息 对应的业务网络之间的连接。
作为一种可选实施例, 参见图 20, 该终端, 还包括:
第一选择模块 1905, 用于选择第一 WLANAP;
第一关联模块 1906, 用于与第一 WLANAP建立关联;
第一请求模块 1907 , 用于向网关请求接入第一 WLAN AP对应的第一 WLAN;
第一接收模块 1908,用于在网关进行成功鉴权及授权后,接收网关发送的 第一终端地址;
第一接入模块 1901 , 用于通过关联的第一 WLANAP接入第一 WLANAP 对应的第一 WLAN;
第一传输模块 1909, 用于与第一 WLAN之间传输用第一终端地址标识的 数据包。
作为一种可选实施例, 参见图 21 , 发送模块 1903, 包括:
接收单元 19031 , 用于接收网关通过建立的用户面连接发送的包括可供选 择的连接选择信息的连接信息; 显示单元 19032, 用于在用户界面上显示接收到的连接信息; 第一获取单元 19033 , 用于获取用户通过用户界面选择的连接选择信息; 第一发送单元 19034, 用于通过建立的用户面连接向网关发送包含用户选 择的连接选择信息的连接选择请求。
作为一种可选实施例, 参见图 22, 发送模块 1903, 包括:
第二获取单元 19035 , 用于通过用户界面获取预先配置的连接选择信息; 第二发送单元 19036, 用于通过建立的用户面连接向网关发送包含预先配 置的连接选择信息的连接选择请求。
作为一种可选实施例, 参见图 23 , 该终端, 还包括:
第二选择模块 1910, 用于选择第二 WLANAP;
第二关联模块 1911 , 用于与第二 WLANAP建立关联;
第二请求模块 1912 , 用于向网关请求接入第二 WLAN AP对应的第二
WLAN;
第二接收模块 1913,用于在网关进行成功鉴权及授权后,接收网关发送的 第二终端地址;
第二接入模块 1914, 用于通过关联的第二 WLANAP接入第二 WLANAP 对应的第二 WLAN;
第二传输模块 1915, 用于与第二 WLAN之间传输用第二终端地址标识的 数据包。
本发明实施例提供的终端,通过和网络侧建立的用户面连接向网关发送包 括连接选择信息的连接选择请求,使网关根据连接选择信息确定终端选择的业 务网络后, 建立终端与终端选择的业务网络之间的连接, 从而实现终端可以连 接不同的业务网络,使得网络连接的方式更加灵活,简化了终端和网关的交互, 扩大了网络连接范围。 本发明实施例提供了一种网关, 该网关用于执行上述图 3、 图 5或图 8所 示的实施例提供的建立网络连接的方法中网关所执行的方法, 包括处理器和接 收机。
其中, 处理器, 用于建立和终端的用户面连接, 终端接入第一 WLAN; 接收机, 用于通过建立的用户面连接接收终端发送的连接选择请求, 连接 选择请求中包括连接选择信息;
处理器, 用于根据连接选择请求中的连接选择信息确定终端选择的业务网 络;
处理器, 用于建立终端与终端选择的业务网络之间的连接。
作为一种可选实施例, 处理器, 还用于对请求接入第一 WLAN AP对应的 第一 WLAN的终端进行鉴权;
处理器, 还用于若鉴权成功, 则对终端进行授权;
所述网关还包括发射机;
发射机, 用于向终端发送第一终端地址, 使终端接入第一 WLAN AP对应 的第一 WLAN;
处理器, 用于在终端与第一 WLAN之间传输用第一终端地址标识的数据 包。
作为一种可选实施例, 处理器, 还用于当终端断开与第一 WLAN AP对应 的第一 WLAN的连接 , 重新选择接入第二 WLAN AP对应的第二 WLAN时 , 对终端进行鉴权;
处理器, 还用于若鉴权成功, 则对终端进行授权, 使终端接入第二 WLAN AP对应的第二 WLAN;
发射机, 还用于向终端发送第二终端地址;
处理器, 还用于在终端与第二 WLAN之间传输用第二终端地址标识的数 据包。
作为一种可选实施例, 处理器, 还用于从初始业务网络获取为终端分配的 访问初始业务网络的终端地址; 或,
处理器, 还用于根据终端的签约信息为终端选择 PGW或 GGSN, 并建立 到 PGW或 GGSN的承载;
处理器, 还用于从 PGW或 GGSN获取为终端分配的访问初始业务网络的 终端地址。
作为一种可选实施例, 处理器, 还用于通过网络地址转换或网络地址及端 口转换在终端和初始业务网络之间传输用第一终端地址标识的数据包和用访 问初始业务网络的终端地址标识的数据包。
作为一种可选实施例, 处理器, 还用于为终端分配访问终端选择的业务网 络的终端地址;
处理器,还用于通过网络地址转换或网络地址及端口转换在终端和终端选 择的业务网络之间传输用第一终端地址标识的数据包和用访问终端选择的业 务网络的终端地址标识的数据包。
作为一种可选实施例, 处理器, 还用于根据终端的签约信息或网络配置确 定是否接受终端连接业务网络;
处理器, 还用于当接受终端连接业务网络时, 执行建立终端与终端选择的 业务网络之间的连接的步骤。
作为一种可选实施例, 发射机, 还用于通过建立的用户面连接向终端发送 包括可供选择的连接选择信息的连接信息;
接收机,还用于通过建立的用户面连接接收终端根据连接信息发送的连接 选择请求;
或者, 接收机, 还用于通过建立的用户面连接接收终端根据预先配置的连 接选择信息发送的连接选择请求。
作为一种可选实施例, 处理器, 还用于根据连接选择请求建立终端对应的 连接选择上下文, 连接选择上下文中至少包括终端的标识、 终端选择的业务网 络及连接信息; 处理器, 还用于保存连接选择上下文。
作为一种可选实施例, 处理器, 还用于在预设时效期限内保存连接选择上 下文。
作为一种可选实施例, 处理器, 还用于判断是否保存有终端对应的连接选 择上下文;
处理器, 还用于当保存有终端对应的连接选择上下文时, 根据终端对应的 连接选择上下文确定终端选择的业务网络, 并建立终端与终端选择的业务网络 之间的连接。
本实施例提供的网关, 通过和终端建立的用户面连接接收终端发送的包括 连接选择信息的连接选择请求, 并根据连接选择信息确定终端选择的业务网络 后, 建立终端与终端选择的业务网络之间的连接, 从而实现终端可以连接不同 的业务网络, 使得网络连接的方式更加灵活, 简化了终端和网关的交互, 扩大 了网络连接范围。 本发明实施例提供了一种终端, 该终端用于执行上述图 4、 图 5或图 8所 示的实施例提供的建立网络连接的方法中终端所执行的方法, 包括处理器和发 射机。
其中, 处理器, 用于接入第一 WLAN, 并建立和网关的用户面连接; 发射机, 用于通过建立的用户面连接向网关发送连接选择请求, 连接选择 请求中包括连接选择信息;
处理器, 用于通过网关建立与连接选择请求中的连接选择信息对应的业务 网络之间的连接。
作为一种可选实施例,处理器,还用于选择第一 WL AN AP ,与第一 WL AN AP建立关联;
处理器, 还用于向网关请求接入第一 WLANAP对应的第一 WLAN; 该终端还包括接收机; 接收机, 用于在网关进行成功鉴权及授权后, 接收网关发送的第一终端地 址;
处理器, 还用于通过关联的第一 WLAN AP接入第一 WLAN AP对应的第 一 WLAN, 并与第一 WLAN之间传输用第一终端地址标识的数据包。
作为一种可选实施例, 接收机, 还用于接收网关通过建立的用户面连接发 送的包括可供选择的连接选择信息的连接信息;
处理器, 还用于在用户界面上显示接收到的连接信息, 并获取用户通过用 户界面选择的连接选择信息;
发射机,还用于通过建立的用户面连接向网关发送包含用户选择的连接选 择信息的连接选择请求。
作为一种可选实施例, 处理器, 还用于通过用户界面获取预先配置的连接 选择信息;
发射机,还用于通过建立的用户面连接向网关发送包含预先配置的连接选 择信息的连接选择请求。
作为一种可选实施例, 处理器, 还用于选择第二 WLAN AP, 并与第二 WLAN AP建立关联;
处理器, 还用于向网关请求接入第二 WLAN AP对应的第二 WLAN; 接收机, 还用于在网关进行成功鉴权及授权后, 接收网关发送的第二终端 地址;
处理器, 还用于通过关联的第二 WLAN AP接入第二 WLAN AP对应的第 二 WLAN, 并与第二 WLAN之间传输用第二终端地址标识的数据包。
本发明实施例提供的终端, 通过和网络侧建立用户面连接, 通过该用户面 连接向网关发送包括连接选择信息的连接选择请求,使网关根据连接选择信息 确定终端选择的业务网络后, 建立终端与终端选择的业务网络之间的连接, 从 而实现终端可以连接不同的业务网络, 使得网络连接的方式更加灵活, 简化了 终端和网关的交互, 扩大了网络连接范围。 参见图 24,本发明实施例提供了一种建立网络连接的系统,该系统包括网 关 2401和至少一个终端 2402; 其中,该网关 2401如上述图 10至图 17任一图 所示的网关, 该终端 2402如上述图 19、 图 20或图 23所示的终端, 具体详见 上述图 10至图 17所示的网关以及图 19、 图 20及图 23所示的终端,此处不再 赘述。
本实施例提供的系统, 通过和终端建立的用户面连接接收终端发送的包括 连接选择信息的连接选择请求, 并根据连接选择信息确定终端选择的业务网络 后, 建立终端与终端选择的业务网络之间的连接, 从而实现终端可以连接不同 的业务网络, 使得网络连接的方式更加灵活, 简化了终端和网关的交互, 扩大 了网络连接范围。 需要说明的是: 上述实施例提供的终端及网关在建立网络连接时, 仅以上 述各功能模块的划分进行举例说明, 实际应用中, 可以根据需要而将上述功能 分配由不同的功能模块完成, 即将终端及网关的内部结构划分成不同的功能模 块, 以完成以上描述的全部或者部分功能。 另外, 上述实施例提供的终端、 网 关、 建立网络连接的系统与建立网络连接的方法实施例属于同一构思, 其具体 实现过程详见方法实施例, 这里不再赘述。
上述本发明实施例序号仅仅为了描述, 不代表实施例的优劣。
本领域普通技术人员可以理解实现上述实施例的全部或部分步骤可以通 过硬件来完成, 也可以通过程序来指令相关的硬件完成, 所述的程序可以存储 于一种计算机可读存储介质中, 上述提到的存储介质可以是只读存储器, 磁盘 或光盘等。
以上所述仅为本发明的较佳实施例, 并不用以限制本发明, 凡在本发明的 精神和原则之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明的 保护范围之内。

Claims

权 利 要 求 书
1、 一种建立网络连接的方法, 其特征在于, 所述方法包括:
建立和终端的用户面连接, 所述终端接入第一无线局域网 WLAN;
通过建立的用户面连接接收所述终端发送的连接选择请求, 所述连接选择 请求中包括连接选择信息;
根据所述连接选择请求中的连接选择信息确定所述终端选择的业务网络; 建立所述终端与所述终端选择的业务网络之间的连接。
2、 根据权利要求 1所述的方法, 其特征在于, 所述建立和终端的用户面连 接之前, 还包括:
对请求接入第一 WLAN接入点 AP对应的第一 WLAN的终端进行鉴权; 若鉴权成功, 则对所述终端进行授权, 并向所述终端发送第一终端地址, 使所述终端接入所述第一 WLAN AP对应的第一 WLAN , 并在所述终端与所述 第一 WLAN之间传输用所述第一终端地址标识的数据包。
3、 根据权利要求 1所述的方法, 其特征在于, 所述通过建立的用户面连接 接收所述终端发送的连接选择请求之后, 还包括:
当所述终端断开与所述第一 WLANAP对应的第一 WLAN的连接, 重新选 择接入第二 WLAN AP对应的第二 WLAN时 , 对所述终端进行鉴权;
若鉴权成功, 则对所述终端进行授权, 并向所述终端发送第二终端地址, 使所述终端接入所述第二 WLAN AP对应的第二 WLAN , 并在所述终端与所述 第二 WLAN之间传输用所述第二终端地址标识的数据包。
4、 根据权利要求 2或 3所述的方法, 其特征在于, 所述对所述终端进行授 权之后, 还包括: 从初始业务网络获取为所述终端分配的访问初始业务网络的终端地址; 或,
根据所述终端的签约信息为所述终端选择分组数据网络网关 PGW或网关 通用分组无线服务支持节点 GGSN, 并建立到所述 PGW或 GGSN的承载; 从所述 PGW或 GGSN获取为所述终端分配的访问初始业务网络的终端地 址。
5、 根据权利要求 4所述的方法, 其特征在于, 所述向所述终端发送第一终 端地址之后, 还包括:
通过网络地址转换或网络地址及端口转换在所述终端和所述初始业务网络 之间传输用所述第一终端地址标识的数据包和用访问初始业务网络的终端地址 标识的数据包。
6、 根据权利要求 2所述的方法, 其特征在于, 所述建立所述终端与所述终 端选择的业务网络之间的连接之后, 还包括:
为所述终端分配访问所述终端选择的业务网络的终端地址;
通过网络地址转换或网络地址及端口转换在所述终端和所述终端选择的业 务网络之间传输用所述第一终端地址标识的数据包和用访问所述终端选择的业 务网络的终端地址标识的数据包。
7、 根据权利要求 2所述的方法, 其特征在于, 所述根据所述连接选择请求 中的连接选择信息确定所述终端选择的业务网络之后, 还包括:
根据所述终端的签约信息或网络配置确定是否接受所述终端连接所述业务 网络;
如果接受所述终端连接所述业务网络, 则执行建立所述终端与所述终端选 择的业务网络之间的连接的步骤。
8、 根据权利要求 1至 7中任一权利要求所述的方法, 其特征在于, 所述通 过建立的用户面连接接收所述终端发送的连接选择请求, 包括:
通过建立的用户面连接向所述终端发送包括可供选择的连接选择信息的连 接信息, 并通过建立的用户面连接接收所述终端根据所述连接信息发送的连接 选择请求;
或者, 通过建立的用户面连接接收所述终端根据预先配置的连接选择信息 发送的连接选择请求。
9、 根据权利要求 8所述的方法, 其特征在于, 所述通过建立的用户面连接 接收所述终端发送的连接选择请求之后, 还包括:
根据所述连接选择请求建立所述终端对应的连接选择上下文, 所述连接选 择上下文中至少包括所述终端的标识、 所述终端选择的业务网络及连接信息; 保存所述连接选择上下文。
10、 根据权利要求 9 所述的方法, 其特征在于, 所述保存所述连接选择上 下文, 包括:
在预设时效期限内保存所述连接选择上下文。
11、 根据权利要求 9 所述的方法, 其特征在于, 所述建立所述终端与所述 终端选择的业务网络之间的连接, 包括:
判断是否保存有所述终端对应的连接选择上下文;
若保存有所述终端对应的连接选择上下文, 则根据所述终端对应的连接选 择上下文确定所述终端选择的业务网络, 并建立所述终端与所述终端选择的业 务网络之间的连接。
12、 一种建立网络连接的方法, 其特征在于, 所述方法包括: 接入第一无线局域网 WLAN, 并建立和网关的用户面连接;
通过建立的用户面连接向所述网关发送连接选择请求, 所述连接选择请求 中包括连接选择信息;
通过所述网关建立与所述连接选择请求中的连接选择信息对应的业务网络 之间的连接。
13、 根据权利要求 12所述的方法, 其特征在于, 所述建立和网关的用户面 连接之前, 还包括:
选择第一无线局域网 WLAN接入点 AP , 与所述第一 WLAN AP建立关联; 向所述网关请求接入所述第一 WLAN AP对应的第一 WLAN, 并在所述网 关进行成功鉴权及授权后, 接收所述网关发送的第一终端地址, 通过关联的第 一 WLAN AP接入所述第一 WLAN AP对应的第一 WLAN,并与所述第一 WLAN 之间传输用所述第一终端地址标识的数据包。
14、 根据权利要求 12所述的方法, 其特征在于, 所述通过建立的用户面连 接向网关发送连接选择请求, 包括:
接收网关通过建立的用户面连接发送的包括可供选择的连接选择信息的连 接信息;
在用户界面上显示接收到的连接信息, 并获取用户通过用户界面选择的连 接选择信息;
通过建立的用户面连接向网关发送包含用户选择的连接选择信息的连接选 择请求。
15、 根据权利要求 12所述的方法, 其特征在于, 所述通过建立的用户面连 接向网关发送连接选择请求, 包括:
通过用户界面获取预先配置的连接选择信息, 并通过建立的用户面连接向 网关发送包含预先配置的连接选择信息的连接选择请求。
16、 根据权利要求 12所述的方法, 其特征在于, 所述通过建立的用户面连 接向所述网关发送连接选择请求之后, 还包括:
选择第二 WLAN AP, 并与所述第二 WLAN AP建立关联;
向所述网关请求接入所述第二 WLAN AP对应的第二 WLAN, 并在所述网 关进行成功鉴权及授权后, 接收所述网关发送的第二终端地址, 通过关联的第 二 WLAN AP接入所述第二 WLAN AP对应的第二 WLAN,并与所述第二 WLAN 之间传输用所述第二终端地址标识的数据包。
17、 一种网关, 其特征在于, 所述网关包括:
第一连接模块, 用于建立和终端的用户面连接, 所述终端接入第一无线局 域网 WLAN;
接收模块, 用于通过建立的用户面连接接收所述终端发送的连接选择请求, 所述连接选择请求中包括连接选择信息;
第一确定模块, 用于根据所述连接选择请求中的连接选择信息确定所述终 端选择的业务网络;
第二连接模块, 用于建立所述终端与所述终端选择的业务网络之间的连接。
18、 根据权利要求 17所述的网关, 其特征在于, 所述网关, 还包括: 第一鉴权模块, 用于对请求接入第一 WLAN接入点 AP对应的第一 WLAN 的终端进行鉴权;
第一授权模块, 用于当鉴权成功时, 对所述终端进行授权;
第一发送模块, 用于向所述终端发送第一终端地址, 使所述终端接入所述 第一 WLAN AP对应的第一 WLAN;
第一传输模块, 用于在所述终端与所述第一 WLAN之间传输用所述第一终 端地址标识的数据包。
19、 根据权利要求 17所述的网关, 其特征在于, 所述网关, 还包括: 第二鉴权模块, 用于当所述终端断开与所述第一 WLAN AP 对应的第一 WLAN的连接 , 重新选择接入第二 WLAN AP对应的第二 WLAN时 , 对所述终 端进行鉴权;
第二授权模块, 用于当鉴权成功时, 对所述终端进行授权;
第二发送模块, 用于向所述终端发送第二终端地址, 使所述终端接入所述 第二 WLAN AP对应的第二 WLAN;
第二传输模块, 用于在所述终端与所述第二 WLAN之间传输用所述第二终 端地址标识的数据包。
20、 根据权利要求 18或 19所述的网关, 其特征在于, 所述网关, 还包括: 第一获取模块, 用于从初始业务网络获取为所述终端分配的访问初始业务 网络的终端地址;
或,
选择模块, 用于根据所述终端的签约信息为所述终端选择分组数据网络网 关 PGW或网关通用分组无线服务支持节点 GGSN;
第一建立模块, 用于建立到所述 PGW或 GGSN的承载;
第二获取模块, 用于从所述 PGW或 GGSN获取为所述终端分配的访问初 始业务网络的终端地址。
21、 根据权利要求 20所述的网关, 其特征在于, 所述网关, 还包括: 第三传输模块, 用于通过网络地址转换或网络地址及端口转换在所述终端 和所述初始业务网络之间传输用所述第一终端地址标识的数据包和用访问初始 业务网络的终端地址标识的数据包。
22、 根据权利要求 18所述的网关, 其特征在于, 所述网关, 还包括: 分配模块, 用于为所述终端分配访问所述终端选择的业务网络的终端地址; 第四传输模块, 用于通过网络地址转换或网络地址及端口转换在所述终端 和所述终端选择的业务网络之间传输用所述第一终端地址标识的数据包和用访 问所述终端选择的业务网络的终端地址标识的数据包。
23、 根据权利要求 18所述的网关, 其特征在于, 所述网关, 还包括: 第二确定模块, 用于根据所述终端的签约信息或网络配置确定是否接受所 述终端连接所述业务网络;
第二连接模块, 用于当接受所述终端连接所述业务网络时, 执行建立所述 终端与所述终端选择的业务网络之间的连接的步骤。
24、 根据权利要求 17至 23 中任一权利要求所述的网关, 其特征在于, 所 述接收模块, 用于通过建立的用户面连接向所述终端发送包括可供选择的连接 选择信息的连接信息, 并通过建立的用户面连接接收所述终端根据所述连接信 息发送的连接选择请求;
或者, 所述接收模块, 用于通过建立的用户面连接接收所述终端根据预先 配置的连接选择信息发送的连接选择请求。
25、 根据权利要求 24所述的网关, 其特征在于, 所述网关, 还包括: 第二建立模块, 用于根据所述连接选择请求建立所述终端对应的连接选择 上下文, 所述连接选择上下文中至少包括所述终端的标识、 所述终端选择的业 务网络及连接信息;
保存模块, 用于保存所述连接选择上下文。
26、 根据权利要求 25所述的网关, 其特征在于, 所述保存模块, 用于在预 设时效期限内保存所述连接选择上下文。
27、根据权利要求 25所述的网关, 其特征在于, 所述第二连接模块, 包括: 判断单元, 用于判断是否保存有所述终端对应的连接选择上下文; 确定单元, 用于当保存有所述终端对应的连接选择上下文时, 根据所述终 端对应的连接选择上下文确定所述终端选择的业务网络;
连接单元, 用于建立所述终端与所述终端选择的业务网络之间的连接。
28、 一种终端, 其特征在于, 所述终端包括:
第一接入模块, 用于接入第一无线局域网 WLAN;
第一连接模块, 用于建立和网关的用户面连接;
发送模块, 用于通过建立的用户面连接向所述网关发送连接选择请求, 所 述连接选择请求中包括连接选择信息;
第二连接模块, 用于通过所述网关建立与所述连接选择请求中的连接选择 信息对应的业务网络之间的连接。
29、 根据权利要求 28所述的终端, 其特征在于, 所述终端, 还包括: 第一选择模块, 用于选择第一无线局域网 WLAN接入点 AP;
第一关联模块, 用于与所述第一 WLAN AP建立关联;
第一请求模块, 用于向所述网关请求接入所述第一 WLAN AP对应的第一 WLAN;
第一接收模块, 用于在所述网关进行成功鉴权及授权后, 接收所述网关发 送的第一终端地址;
所述第一接入模块, 用于通过关联的第一 WLAN AP接入所述第一 WLAN AP对应的第一 WLAN;
第一传输模块, 用于与所述第一 WLAN之间传输用所述第一终端地址标识 的数据包。
30、 根据权利要求 28所述的终端, 其特征在于, 所述发送模块, 包括: 接收单元, 用于接收网关通过建立的用户面连接发送的包括可供选择的连 接选择信息的连接信息;
显示单元, 用于在用户界面上显示接收到的连接信息;
第一获取单元, 用于获取用户通过用户界面选择的连接选择信息; 第一发送单元, 用于通过建立的用户面连接向网关发送包含用户选择的连 接选择信息的连接选择请求。
31、 根据权利要求 28所述的终端, 其特征在于, 所述发送模块, 包括: 第二获取单元, 用于通过用户界面获取预先配置的连接选择信息; 第二发送单元, 用于通过建立的用户面连接向网关发送包含预先配置的连 接选择信息的连接选择请求。
32、 根据权利要求 28所述的终端, 其特征在于, 所述终端, 还包括: 第二选择模块, 用于选择第二 WLANAP;
第二关联模块, 用于与所述第二 WLANAP建立关联;
第二请求模块, 用于向所述网关请求接入所述第二 WLAN AP对应的第二 WLAN;
第二接收模块, 用于在所述网关进行成功鉴权及授权后, 接收所述网关发 送的第二终端地址;
第二接入模块, 用于通过关联的第二 WLAN AP接入所述第二 WLAN AP 对应的第二 WLAN;
第二传输模块, 用于与所述第二 WLAN之间传输用所述第二终端地址标识 的数据包。
PCT/CN2014/080751 2014-06-25 2014-06-25 建立网络连接的方法、网关及终端 WO2015196396A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
CN201480036140.2A CN105393630B (zh) 2014-06-25 2014-06-25 建立网络连接的方法、网关及终端
EP14895709.5A EP3154306B1 (en) 2014-06-25 2014-06-25 Establishment of network connection
PCT/CN2014/080751 WO2015196396A1 (zh) 2014-06-25 2014-06-25 建立网络连接的方法、网关及终端
US15/388,069 US10432632B2 (en) 2014-06-25 2016-12-22 Method for establishing network connection, gateway, and terminal

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2014/080751 WO2015196396A1 (zh) 2014-06-25 2014-06-25 建立网络连接的方法、网关及终端

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/388,069 Continuation US10432632B2 (en) 2014-06-25 2016-12-22 Method for establishing network connection, gateway, and terminal

Publications (1)

Publication Number Publication Date
WO2015196396A1 true WO2015196396A1 (zh) 2015-12-30

Family

ID=54936463

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/080751 WO2015196396A1 (zh) 2014-06-25 2014-06-25 建立网络连接的方法、网关及终端

Country Status (4)

Country Link
US (1) US10432632B2 (zh)
EP (1) EP3154306B1 (zh)
CN (1) CN105393630B (zh)
WO (1) WO2015196396A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20170137347A (ko) * 2016-06-03 2017-12-13 주식회사 케이티 무선랜에서 동적 연결 변경 방법 및 장치
CN110475315A (zh) * 2019-08-19 2019-11-19 Oppo广东移动通信有限公司 网络连接控制方法及相关产品
CN111835485A (zh) * 2019-08-09 2020-10-27 维沃移动通信有限公司 网络设备信息接收方法、发送方法、终端和网络设备
CN114374667A (zh) * 2021-12-28 2022-04-19 中国电信股份有限公司 一种分配nat ip的方法、装置及存储介质

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10367689B2 (en) * 2014-10-24 2019-07-30 Comscore, Inc. Monitoring internet usage on home networks of panelist users
US10250491B2 (en) * 2016-05-09 2019-04-02 Qualcomm Incorporated In-flow packet prioritization and data-dependent flexible QoS policy
CN106604411B (zh) * 2016-11-11 2022-12-20 宇龙计算机通信科技(深圳)有限公司 基于邻域网的信息交互方法、信息交互装置和终端
US10944632B2 (en) * 2017-06-22 2021-03-09 Texas Instruments Incorporated Accelerated network reconnect using previous connection parameters
US11895033B2 (en) * 2017-11-17 2024-02-06 Huawei Technologies Co., Ltd. Method and apparatus for traffic routing and path optimization for peer-to-peer communications
TWI728901B (zh) * 2020-08-20 2021-05-21 台眾電腦股份有限公司 雙模式切換之阻斷網路連線的方法
US11425044B2 (en) * 2020-10-15 2022-08-23 Cisco Technology, Inc. DHCP layer 2 relay in VXLAN overlay fabric
JP7420061B2 (ja) * 2020-12-22 2024-01-23 トヨタ自動車株式会社 サーバ、電力管理方法

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102355746A (zh) * 2011-10-28 2012-02-15 大唐移动通信设备有限公司 一种wlan数据传输方法、无线终端及接入网设备
CN103298148A (zh) * 2013-06-28 2013-09-11 华为技术有限公司 移动终端通过固定网络连接到多个pdn网络的方法及相关装置
US20130265985A1 (en) * 2012-04-10 2013-10-10 Motorola Mobility, Inc. Wireless communication device, communication system and method for establishing data connectivity between a wireless communicaiton device and a first access network
CN103379547A (zh) * 2012-04-28 2013-10-30 电信科学技术研究院 一种分流连接建立方法和设备
WO2014040564A1 (en) * 2012-09-14 2014-03-20 Huawei Technologies Co., Ltd. System and method for a multiple ip interface control protocol

Family Cites Families (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100499536C (zh) * 2003-10-22 2009-06-10 华为技术有限公司 无线局域网中选定业务的解析接入处理方法
US7733824B2 (en) * 2005-06-23 2010-06-08 Nokia Corporation Fixed access point for a terminal device
US20080247346A1 (en) * 2006-12-29 2008-10-09 Nokia Corporation Communication node with multiple access support
EP2235969A4 (en) * 2008-01-15 2014-01-08 Ericsson Telefon Ab L M PREVIEW OF INPUT DATA FOR ACCESS NETWORK SELECTION
US8548428B2 (en) * 2009-01-28 2013-10-01 Headwater Partners I Llc Device group partitions and settlement platform
CN101686191A (zh) * 2008-09-24 2010-03-31 华为技术有限公司 访问分组数据网业务的方法及系统、网关和终端
SG176293A1 (en) * 2009-06-04 2012-01-30 Research In Motion Ltd Methods and apparatus for use in facilitating the communication of neighboring network information to a mobile terminal with use of a radius compatible protocol
WO2011094933A1 (en) * 2010-02-03 2011-08-11 Huawei Technologies Co., Ltd. System and method for managing an access network re-selection
US8615236B2 (en) * 2010-06-04 2013-12-24 Palm, Inc. System and method for dynamically managing connections using feature prioritization
WO2013089526A1 (ko) * 2011-12-16 2013-06-20 엘지전자 주식회사 무선 통신 시스템에서 ap 재선택 방법 및 이를 위한 장치
CN103313317B (zh) * 2012-03-07 2016-09-28 华为技术有限公司 一种WiFi终端接入分组数据PS业务域的方法和可信网关
WO2014023337A1 (en) * 2012-08-07 2014-02-13 Nokia Siemens Networks Oy Mechanism for controlling discovery and selection function of access points
WO2014058135A1 (ko) * 2012-10-08 2014-04-17 엘지전자 주식회사 무선 통신 시스템에서 패킷데이터네트워크 게이트웨이 선택 방법 및 장치
US9900832B2 (en) * 2012-11-07 2018-02-20 Lg Electronics Inc. Method and an apparatus for access network selection in a wireless communication system
US9253717B2 (en) * 2013-01-18 2016-02-02 Lg Electronics Inc. Method and terminal for selecting AP
US9386511B2 (en) * 2013-02-25 2016-07-05 Lg Electronics Inc. Method and an apparatus for access network selection in visited network in a wireless communication system
CN105144792B (zh) * 2013-03-27 2018-09-18 Lg电子株式会社 用于在无线通信系统中选择接入网络的方法及装置
WO2015000533A1 (en) * 2013-07-05 2015-01-08 Telefonaktiebolaget L M Ericsson (Publ) Connecting to radio access networks selected based on charging data for a subscription of a user
CN103338483B (zh) * 2013-07-24 2016-08-10 成都西加云杉科技有限公司 数据分流方法、数据分流设备及异构网络
WO2015047163A1 (en) * 2013-09-27 2015-04-02 Telefonaktiebolaget L M Ericsson (Publ) Managing selection of wlan
WO2015050342A1 (ko) * 2013-10-04 2015-04-09 엘지전자 주식회사 무선 통신 시스템에서 액세스 네트워크 선택 방법 및 장치
US10341911B2 (en) * 2014-05-05 2019-07-02 Lg Electronics Inc. Method for establishing plurality of PDN connections by means of CSIPTO
US9674733B2 (en) * 2014-05-27 2017-06-06 QUALCMM Incorporated Interworking link layer traffic aggregation with system level mobility
US10142894B2 (en) * 2014-06-03 2018-11-27 Intel Corporation Interworking/co-existence of integrated WLAN/3GPP RAT architectures with legacy WLAN/3GPP interworking solutions
KR102318735B1 (ko) * 2014-06-23 2021-10-28 콘비다 와이어리스, 엘엘씨 통합된 무선 네트워크에서의 시스템 간 이동성

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102355746A (zh) * 2011-10-28 2012-02-15 大唐移动通信设备有限公司 一种wlan数据传输方法、无线终端及接入网设备
US20130265985A1 (en) * 2012-04-10 2013-10-10 Motorola Mobility, Inc. Wireless communication device, communication system and method for establishing data connectivity between a wireless communicaiton device and a first access network
CN103379547A (zh) * 2012-04-28 2013-10-30 电信科学技术研究院 一种分流连接建立方法和设备
WO2014040564A1 (en) * 2012-09-14 2014-03-20 Huawei Technologies Co., Ltd. System and method for a multiple ip interface control protocol
CN103298148A (zh) * 2013-06-28 2013-09-11 华为技术有限公司 移动终端通过固定网络连接到多个pdn网络的方法及相关装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3154306A4 *

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20170137347A (ko) * 2016-06-03 2017-12-13 주식회사 케이티 무선랜에서 동적 연결 변경 방법 및 장치
KR102521545B1 (ko) * 2016-06-03 2023-04-12 주식회사 케이티 무선랜에서 동적 연결 변경 방법 및 장치
CN111835485A (zh) * 2019-08-09 2020-10-27 维沃移动通信有限公司 网络设备信息接收方法、发送方法、终端和网络设备
CN111835485B (zh) * 2019-08-09 2022-03-08 维沃移动通信有限公司 网络设备信息接收方法、发送方法、终端和网络设备
CN110475315A (zh) * 2019-08-19 2019-11-19 Oppo广东移动通信有限公司 网络连接控制方法及相关产品
CN114374667A (zh) * 2021-12-28 2022-04-19 中国电信股份有限公司 一种分配nat ip的方法、装置及存储介质
CN114374667B (zh) * 2021-12-28 2024-04-16 中国电信股份有限公司 一种分配nat ip的方法、装置及存储介质

Also Published As

Publication number Publication date
CN105393630A (zh) 2016-03-09
EP3154306A1 (en) 2017-04-12
CN105393630B (zh) 2019-07-23
EP3154306A4 (en) 2017-07-19
US10432632B2 (en) 2019-10-01
EP3154306B1 (en) 2020-02-26
US20170104758A1 (en) 2017-04-13

Similar Documents

Publication Publication Date Title
US10432632B2 (en) Method for establishing network connection, gateway, and terminal
US9549317B2 (en) Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network
US7899441B2 (en) Method for resolving and accessing selected service in wireless local area network
RU2556468C2 (ru) Способ аутентификации доступа терминала и оборудование, расположенное на территории абонента
US9167430B2 (en) Access method and system, and mobile intelligent access point
US10313323B2 (en) User equipment identity valid for heterogeneous networks
JP5903728B2 (ja) Wifi端末がパケットデータpsサービスドメインにアクセスするための方法およびトラステッドゲートウェイ
JP5982690B2 (ja) ネットワークコンバージェンスの方法、デバイス、および通信システム
WO2015013879A1 (zh) 网络切换方法、装置、设备及系统
WO2013017098A1 (zh) 将用户设备接入演进的分组核心网络的方法、设备和系统
WO2016155012A1 (zh) 一种无线通信网络中的接入方法、相关装置及系统
US9629065B2 (en) Local access point name for use in accessing packet data networks
WO2014005267A1 (zh) 接入移动网络的方法、装置及系统
WO2014101755A1 (zh) 业务数据分流方法及系统
WO2013174190A1 (zh) 路由选择方法及功能网元
WO2018058691A1 (zh) 一种建立公用数据网连接的方法及相关设备
WO2014063530A1 (zh) 移动用户固网的接入方法及系统
WO2012130133A1 (zh) 一种接入点及终端接入方法
WO2013174098A1 (zh) 基于capwap协议的网络接入方法、装置和系统
WO2017129101A1 (zh) 路由控制方法、装置及系统
WO2013097614A1 (zh) 为ue分配ip地址的方法、系统及tnan、ue
WO2012022212A1 (zh) 用户设备接入方法、装置及系统
WO2014032542A9 (zh) 多连接建立的方法及系统

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201480036140.2

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14895709

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

REEP Request for entry into the european phase

Ref document number: 2014895709

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2014895709

Country of ref document: EP