WO2016070410A1 - 一种建立连接的方法、设备及系统 - Google Patents

一种建立连接的方法、设备及系统 Download PDF

Info

Publication number
WO2016070410A1
WO2016070410A1 PCT/CN2014/090585 CN2014090585W WO2016070410A1 WO 2016070410 A1 WO2016070410 A1 WO 2016070410A1 CN 2014090585 W CN2014090585 W CN 2014090585W WO 2016070410 A1 WO2016070410 A1 WO 2016070410A1
Authority
WO
WIPO (PCT)
Prior art keywords
user equipment
group
identifier
service
network device
Prior art date
Application number
PCT/CN2014/090585
Other languages
English (en)
French (fr)
Inventor
杨艳梅
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to RU2017119025A priority Critical patent/RU2672570C1/ru
Priority to KR1020177013610A priority patent/KR101929868B1/ko
Priority to CN202010067633.XA priority patent/CN111277963B/zh
Priority to BR112017008928-9A priority patent/BR112017008928B1/pt
Priority to PCT/CN2014/090585 priority patent/WO2016070410A1/zh
Priority to AU2014410591A priority patent/AU2014410591B2/en
Priority to EP14905513.9A priority patent/EP3200486B1/en
Priority to CN201480079580.6A priority patent/CN106416321B/zh
Publication of WO2016070410A1 publication Critical patent/WO2016070410A1/zh
Priority to US15/588,496 priority patent/US10542433B2/en
Priority to US16/697,128 priority patent/US11096051B2/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/06Selective distribution of broadcast services, e.g. multimedia broadcast multicast service [MBMS]; Services to user groups; One-way selective calling services
    • H04W4/08User group management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/11Allocation or use of connection identifiers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/005Discovery of network devices, e.g. terminals
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/02Terminal devices
    • H04W88/04Terminal devices adapted for relaying to or from another terminal or user

Definitions

  • the present invention relates to the field of communications, and in particular, to a method, device, and system for establishing a connection.
  • some user equipment may exceed the network coverage.
  • the remote end when the user is in a place where the network signal is not good or there is no network signal coverage, the user equipment beyond the network coverage is called the remote end.
  • the user equipment in this case, in order to enable the remote user equipment that is not in the network coverage to maintain a communication connection with the network, in an implementation manner, as shown in FIG. 1, the remote device may be closer to the remote device.
  • the user equipment that can receive information with the remote device and is in the network coverage is used as the relay user equipment, and the data between the user and the network is forwarded by the relay user equipment.
  • the relay user equipment in the process of establishing a connection between the remote user equipment and the relay user equipment, when the relay user equipment opens the relay service function, when the user sends a registration request to the application server to register, the application server returns the The group member information, the relay user equipment can establish a connection with the user equipment that needs to relay the service according to the group member information, and provide a relay service for the user equipment.
  • the relay user equipment when the relay user equipment receives the group member information, after the relay service function is turned on, if the relay user equipment has been registered, and then the relay service function is turned on, the relay service cannot be provided, and After the user equipment can establish a connection with any user equipment, the security of the relay service function is poor.
  • the embodiments of the present invention provide a method, a device, and a system for establishing a connection, which can solve the problem that a relay user equipment can establish a connection with any user equipment, so that the security of the relay service function is poor.
  • an embodiment of the present invention provides a method for establishing a connection, including:
  • the first user equipment receives the discovery information sent by the second user equipment, where the discovery information includes an identifier of the second group and a relay service request, where the relay service request is used to request to provide a relay service, where the The identifier of the second group is used to indicate the group to which the second user equipment belongs or the group to which the user of the second user equipment belongs;
  • the first user equipment acquires a data link layer identity identifier of the second user equipment, according to the second user equipment a data link layer ID, establishing a connection between the first user equipment and the second user equipment.
  • the method further includes:
  • Receiving, by the first user equipment, the service object group identifier sent by the network device including:
  • the first user equipment receives a service authorization response sent by the network device, and the service authorization response carries the service object group identifier.
  • the method before the first user equipment receives the service object group identifier sent by the network device, the method further includes:
  • the discovery request information includes a group name of the service object
  • Receiving, by the first user equipment, the service object group identifier sent by the network device including:
  • the first user equipment receives discovery confirmation information sent by the network device, where the discovery confirmation information includes the service object group identifier.
  • the discovery information further includes a data link layer ID of the second user equipment
  • the data link layer identity identifier of the second user equipment including:
  • the first user equipment acquires a data link layer ID of the second user equipment from the discovery information.
  • the discovery information further includes a name of the second user equipment, and the name of the second user equipment is used to identify the second user equipment;
  • the method further includes:
  • the first user equipment sends the first verification information to the network device, where the first verification information carries the name of the second user equipment;
  • the data link layer identity identifier of the second user equipment including:
  • the first user equipment receives the first verification confirmation information sent by the network device, where the first verification confirmation information carries a data link layer ID of the second user equipment.
  • an embodiment of the present invention provides a method for establishing a connection, including:
  • the network device receives the first verification information sent by the first user equipment, where the first verification information includes an identifier of the second group, and the identifier of the second group is used to indicate the group to which the second user equipment belongs or the a group to which the user of the second user equipment belongs;
  • the network device sends first verification confirmation information, the first verification confirmation information, to the first user equipment. Used to indicate that the first user equipment is the second user
  • the home device provides a relay service.
  • the method further includes:
  • the embodiment of the present invention provides a first user equipment, including:
  • a receiving unit configured to receive a service object group identifier sent by the network device, where the service object group identifier is used to indicate that the first user equipment provides a group of service objects of the relay service;
  • the receiving unit is further configured to receive the discovery information sent by the second user equipment, where the discovery information includes an identifier of the second group and a relay service request, where the relay service request is used to request to provide a relay service.
  • the identifier of the second group is used to indicate the group to which the second user equipment belongs or the group to which the user of the second user equipment belongs;
  • connection unit configured to acquire, when the identifier of the second group received by the receiving unit is included in the service object group identifier, a data link layer identity identifier of the second user equipment, according to the A data link layer ID of the second user equipment establishes a connection between the first user equipment and the second user equipment.
  • the first user equipment further includes a sending unit, configured to send a service authorization request to the network device;
  • the receiving unit is further configured to receive a service authorization response sent by the network device, where the service authorization response carries the service object group identifier.
  • the receiving unit is further configured to receive a group name of a service object sent by the network device, where a group name of the service object corresponds to the service object group identifier;
  • the first user equipment further includes a sending unit, configured to send discovery request information to the network device, where the discovery request information includes a group name of the service object;
  • the receiving unit is further configured to receive discovery confirmation information sent by the network device,
  • the discovery confirmation information includes the service object group identifier.
  • the discovery information further includes a data link layer ID of the second user equipment
  • the connecting unit is specifically configured to acquire a data link layer ID of the second user equipment from the discovery information.
  • the discovery information further includes a name of the second user equipment, and the name of the second user equipment is used to identify the second user equipment;
  • the first user equipment further includes a sending unit, configured to send first verification information to the network device, where the first verification information carries a name of the second user equipment;
  • the receiving unit is further configured to receive first verification confirmation information sent by the network device, where the first verification confirmation information carries a data link layer ID of the second user equipment.
  • an embodiment of the present invention provides a network device, including:
  • a receiving unit configured to receive first verification information that is sent by the first user equipment, where the first verification information includes an identifier of the second group, and the identifier of the second group is used to indicate a group to which the second user equipment belongs Or a group to which the user of the second user equipment belongs;
  • An obtaining unit configured to acquire a service object group identifier of the first user equipment, where the service object group identifier of the first user equipment is used to indicate a group of service objects that provide the relay service by the first user equipment ;
  • a sending unit configured to send the first verification confirmation information to the first user equipment when the identifier of the second group received by the receiving unit is included in the service object group identifier acquired by the acquiring unit
  • the first verification confirmation information is used to indicate that the first user equipment provides a relay service for the second user equipment.
  • the sending unit is further configured to send, to the first user equipment, a data link layer identity identifier of the second user equipment, where a data link layer ID of the second user equipment is used by the first user
  • the device establishes a connection with the second user equipment.
  • an embodiment of the present invention provides a first user equipment, including a processor, a memory, a bus, and a receiver, where the processor, the memory, and the receiver pass The buses are connected to each other;
  • the receiver is configured to receive a service object group identifier that is sent by the network device, where the service object group identifier is used to indicate that the first user equipment provides a group of service objects of the relay service;
  • the receiver is further configured to receive discovery information sent by the second user equipment, where the discovery information includes an identifier of the second group and a relay service request, where the relay service request is used to request to provide a relay service.
  • the identifier of the second group is used to indicate the group to which the second user equipment belongs or the group to which the user of the second user equipment belongs;
  • the processor when the identifier of the second group received by the receiver is included in the service object group identifier, acquiring a data link layer identity identifier of the second user equipment, according to Establishing, by the data link layer ID of the second user equipment, a connection between the first user equipment and the second user equipment.
  • the first user equipment further includes a transmitter, configured to send a service authorization request to the network device;
  • the receiver is further configured to receive a service authorization response sent by the network device, where the service authorization response carries the service object group identifier.
  • the receiver is further configured to receive a group name of a service object sent by the network device, where a group name of the service object corresponds to the service object group identifier;
  • the first user equipment further includes a sender, configured to send discovery request information to the network device, where the discovery request information includes a group name of the service object;
  • the receiver is further configured to receive discovery confirmation information sent by the network device, where the discovery confirmation information includes the service object group identifier.
  • the discovery information further includes a data link layer ID of the second user equipment
  • the processor is specifically configured to acquire a data link layer ID of the second user equipment from the discovery information.
  • the discovery information further includes a name of the second user equipment, and the name of the second user equipment is used to identify the second user equipment;
  • the first user equipment further includes a transmitter, configured to send first verification information to the network device, where the first verification information carries a name of the second user equipment;
  • the receiver is further configured to receive first verification confirmation information sent by the network device, where the first verification confirmation information carries a data link layer ID of the second user equipment.
  • an embodiment of the present invention provides a network device, including a processor, a memory, a bus, a receiver, and the transmitter, where the processor, the memory, the receiver, and the transmitter pass through The buses are connected to each other;
  • a receiver configured to receive first verification information that is sent by the first user equipment, where the first verification information includes an identifier of the second group, and the identifier of the second group is used to indicate a group to which the second user equipment belongs Or a group to which the user of the second user equipment belongs;
  • a processor configured to acquire a service object group identifier of the first user equipment, where the service object group identifier of the first user equipment is used to indicate a group of service objects that provide the relay service by the first user equipment ;
  • a transmitter configured to: when the identifier of the second group received by the receiver is included in the service object group identifier acquired by the processor, send the first verification confirmation information to the first user equipment
  • the first verification confirmation information is used to indicate that the first user equipment provides a relay service for the second user equipment.
  • the transmitter is further configured to send, to the first user equipment, a data link layer identity identifier of the second user equipment, where a data link layer ID of the second user equipment is used by the first user
  • the device establishes a connection with the second user equipment.
  • the method, device, and system for establishing a connection are provided by the first embodiment of the present invention.
  • the first user equipment receives the service object group identifier sent by the network device, receives the discovery information sent by the second user equipment, and confirms the identifier of the second group.
  • the service object group identifier is included, the first user equipment is connected to the second user equipment according to the data link layer ID of the second user equipment, and the second user equipment is provided with a relay service, so that the first user equipment can only be
  • a group of specific service objects provides relay services, which improves the security of the relay service function. Sex.
  • FIG. 1 is a schematic diagram of a relay communication method provided by the prior art
  • FIG. 2 is a schematic structural diagram of a wireless network system according to an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of a method for establishing a connection according to an embodiment of the present invention
  • FIG. 4 is a schematic diagram of information interaction of a method for establishing a connection according to another embodiment of the present invention.
  • FIG. 5 is a schematic flowchart of another method for establishing a connection according to an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of information exchange of another method for establishing a connection according to another embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of a first user equipment according to an embodiment of the present disclosure.
  • FIG. 8 is a schematic structural diagram of a network device according to an embodiment of the present disclosure.
  • FIG. 9 is a schematic structural diagram of a first user equipment according to another embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of a network device according to another embodiment of the present invention.
  • FIG. 2 shows a wireless network system.
  • the wireless network system 20 shown in FIG. 2 includes a relay user equipment 201, a remote user equipment 202, and a first network server 203.
  • the wireless network system may further include The second network server 204, the HSS (Home Subscriber Server) 205, and the application layer server 206.
  • the wireless network system may belong to an LTE (Long Term Evolution) system.
  • the relay user equipment 201 is configured to provide a relay service for other user equipments.
  • the relay service in the present invention includes performing communication between other user equipments and the network side by forwarding other user equipments and information on the network side.
  • the remote user equipment 202 is a user equipment that is not in the coverage of the wireless network system, and needs other user equipment to provide a relay service for the user equipment.
  • the first web server 203 and the second web server 204 may be network side functional entities required for processing direct communication between terminal devices.
  • the HSS 205 is an important part of the control layer in the IMS (IP Multimedia Subsystem).
  • the HSS supports the primary user database of the IMS network entity used to process the invocation/session. It contains user profiles, performs user authentication and authorization, and provides information about the user's physical location.
  • An embodiment of the present invention provides a method for establishing a connection, which is applied to a first user equipment.
  • the method for establishing a connection provided in this embodiment may be applied to the wireless network system described in the embodiment corresponding to FIG. 2, optionally.
  • the first user equipment may be a relay user equipment in the wireless network system shown in FIG. 2.
  • the method for establishing a connection provided in this embodiment includes the following steps:
  • the first user equipment receives a service object group identifier sent by the network device.
  • the service object group identifier is used to indicate a group of service objects that the first user equipment provides the relay service, and the service object group identifier includes at least one group identifier.
  • the network device may first obtain the group name of the service object, and obtain the service object group identifier by using the network device according to the group name of the service object.
  • the group of the service objects that the first user equipment provides the relay service may be pre-assigned by the network side, and further optionally, in the OSI (Open System Interconnection) model, the service object
  • the group identifier may be a data link layer ID (IDentity) of the group of the service object, and the group name of the service object may be an application layer ID of the group of the service object.
  • the network The network device can be a first network server.
  • the service object of the first user equipment may be pre-assigned by the application layer management device, such that the object that the first user equipment provides the relay service is some user equipment belonging to a specific group, and not any user equipment may be the same.
  • a user equipment establishes a connection, which is equivalent to filtering the object that provides the relay service by the first user equipment, thereby improving the security of information interaction in the relay service process.
  • the first user equipment receives the discovery information sent by the second user equipment.
  • the discovery information includes the identifier of the second group and the relay service request, the relay service request is used to indicate that the second user equipment needs the relay service, and the identifier of the second group is used to indicate the group or the second user equipment belongs to The group to which the user of the two user equipment belongs.
  • the second user equipment may provide services for at least one user, and the user of the second user equipment may be one or more of the at least one user, which is not limited herein.
  • the second user equipment may be a remote user equipment in the wireless network system shown in FIG. 2.
  • the discovery information may be sent by using a broadcast, and the first user equipment may receive the discovery information.
  • the discovery information can also be received. In this embodiment, only the first user equipment is taken as an example for description.
  • step 301 and step 302 have no sequence.
  • the method further includes:
  • the first user equipment acquires a data link layer ID (Identity) of the second user equipment.
  • the discovery information may include a data link layer ID of the second user equipment, where the first user equipment may directly obtain the data link layer ID of the second user equipment.
  • the discovery information includes the name of the second user equipment, and the name of the second user equipment is used to identify the second user equipment.
  • the name of the second user equipment may be the discovery code of the second user equipment.
  • the first user equipment acquires the data link layer ID of the second user equipment from the network device according to the name of the second user equipment.
  • the first user equipment sends the first verification information to the network device, where the first verification information carries the second
  • the first user equipment receives the first verification confirmation information sent by the first network device, where the first verification confirmation information includes a data link layer ID of the second user equipment.
  • the name of the second user equipment may be a Group ProSe Code of the second user equipment.
  • the first user equipment can also obtain the data link layer ID of the second user equipment by other means.
  • the first user equipment establishes a connection between the first user equipment and the second user equipment according to the data link layer ID of the second user equipment.
  • the second user equipment can be provided with a relay service.
  • the first user equipment confirms whether the group identifier of the second user is included in the service object group identifier, and if the group identifier of the second user is not included in the service object group identifier, The second user equipment is not the object that the first user equipment can provide the relay service. If the identifier of the second group is included in the service object group identifier, the second user equipment belongs to the object that the first user equipment provides the relay service.
  • the first user equipment may establish a connection with the second user equipment according to the data link layer ID of the second user equipment.
  • the first user equipment establishes a D2D (Device to Device) connection with the second user equipment.
  • D2D Device to Device
  • the method for establishing a connection receives the discovery information sent by the second user equipment by receiving the service object group identifier sent by the network device, and confirms that the identifier of the second group is included in the service object group identifier, according to
  • the data link layer ID of the second user equipment establishes that the first user equipment is connected to the second user equipment and provides a relay service for the second user equipment, so that the first user equipment can only provide a relay for the group of the specific service object. Service improves the security of the relay service function.
  • another embodiment of the present invention provides a method for establishing a connection, which is preferably applied to the wireless network system described in the embodiment corresponding to FIG. 2, corresponding to the wireless network system shown in FIG.
  • the first user equipment may be a relay user equipment
  • the second user equipment may be a remote user equipment
  • the network equipment may be a first network server.
  • Wireless network system is The description of the example does not mean that the present invention is limited thereto.
  • the method for establishing a connection provided by this embodiment includes:
  • the first user equipment sends a service authorization request to the network device, where the service authorization request includes the indication information that the first user equipment requests to provide the relay service for the other user equipment, and the relay service includes forwarding the information of the other user equipment.
  • the other user equipment communicates with the network side, and the other user equipment includes the second user equipment; the first user equipment receives the service authorization response information sent by the network device.
  • the service authorization response information carries a group name of the first user equipment service object
  • the group name of the service object includes at least one group name
  • the group name of the service object may be a service.
  • the application layer ID of the group of objects, and the group name of the service object may be a group list (Group List).
  • the group name of the service object may also be sent to the first user equipment by other messages, or the network device sends a separate message carrying the group name of the service object to the first user equipment.
  • the invention is not limited.
  • the network device may obtain authorization for the first user equipment by sending a request to the HSS.
  • the first user equipment starts a relay service function according to the service authorization response information.
  • the first user equipment sends discovery request information to the network device.
  • the discovery request information includes a group name of the service object.
  • the discovery request information is used to request permission to obtain a listen group member (Mornitor Group Member).
  • the first user equipment receives the discovery confirmation information sent by the network device.
  • the discovery confirmation information includes a service object group identifier, where the service object group identifier includes at least one group identifier, and a group identifier corresponds to a group name in step 403, and a group identifier corresponds to a group name, preferably
  • the service object group identifier may be a data link layer ID of the group of the service object, or the service object group identifier may also be a group discovery code of the service object.
  • the service object group identifier may also carry The message is sent to the first user equipment in the service authorization response information of step 401. At this time, steps 403-404 can be skipped, and step 405 is directly executed.
  • the service object group identifier may also be carried in other information and sent to the first user equipment, or the network device sends a separate information carrying service object group identifier to the first user equipment. In this regard, the invention is not limited.
  • step 401 and step 402 are not performed, and step 403 is directly performed.
  • the network device receives the discovery request information sent by the first user equipment, the network device carries the discovery confirmation information.
  • the service object group identifier is sent and the discovery confirmation information is sent to the first user equipment.
  • the network device may send information to the HSS or the application layer server to obtain the service object group identifier.
  • the application layer server may be an MCPTT server (Mission Critical Push to talk over LTE LTE-based emergency communication walkie-talkie) business). Further, if the group name of the service object is obtained from the MCPTT server, the network device further needs to obtain the corresponding service object group identifier.
  • MCPTT server Mobility Critical Push to talk over LTE LTE-based emergency communication walkie-talkie
  • the network device needs to send a message to the network server to which the group belongs, thereby acquiring the data link of the group.
  • Layer ID the group name of the service object
  • the discovery confirmation information is used to indicate that the first user equipment obtains the right to listen to the group member, and may start listening.
  • the network device may send a message to the HSS or the application layer server to obtain the first user equipment. The permissions of the group members.
  • the first user equipment receives the discovery information sent by the second user equipment.
  • the discovery information includes the identifier of the second group and the relay service request, the relay service request is used to indicate that the second user equipment needs the relay service, and the identifier of the second group is used to indicate the group or the second user equipment belongs to A group to which the user of the user equipment belongs, wherein the second user equipment can provide services for at least one user.
  • the discovery information may further include a name of the second user equipment or a data link layer ID of the second user equipment, where the name of the second user equipment is used to identify the second user equipment.
  • the second user equipment sends the discovery information in a broadcast form, and the first user equipment receives the discovery information of the second user equipment by listening to the group member;
  • the first user equipment may confirm whether the second user equipment belongs to the group of the first user equipment service object according to whether the service object group identifier includes the identifier of the second group, if the service object group identifier includes the second group
  • the identifier indicates that the first user equipment can provide a relay service for the second user equipment.
  • step 405 and any of steps 401-404 are in no order. Further, step 406 may be performed.
  • the first user equipment may send broadcast information, where the broadcast information includes a data link layer ID and a relay service request of the first user equipment, and a service object group identifier authorized by the network, where the second user equipment receives After the broadcast information of the first user equipment, the first user equipment can determine whether the first user equipment can provide a relay service according to the service object group identifier broadcast by the first user equipment, and if yes, send a connection request to the first user equipment, and directly Go to step 408.
  • the broadcast information includes a data link layer ID and a relay service request of the first user equipment, and a service object group identifier authorized by the network
  • the second user equipment receives After the broadcast information of the first user equipment, the first user equipment can determine whether the first user equipment can provide a relay service according to the service object group identifier broadcast by the first user equipment, and if yes, send a connection request to the first user equipment, and directly Go to step 408.
  • the first user equipment sends the first verification information to the network device.
  • the first verification information may include a name of the second user equipment or a data link layer ID of the second user equipment.
  • the network device verifies whether the identity of the second user equipment is legal according to the name of the second user equipment or the data link layer ID of the second user equipment. If the second user equipment and the network device do not belong to the same network, the network device needs to send a message to the other network server. Specifically, the second network server and the second user equipment belong to the same network, thereby Verify the identity of the second user device.
  • the name of the second user equipment may be a discovery code of the second user equipment.
  • the first user equipment receives the first verification confirmation information sent by the network device.
  • the first verification confirmation information may further include a data link layer ID of the second user equipment. If the second user equipment and the network device do not belong to the same network, and the second network server belongs to the same network, the network device passes the The second network server sends a message to obtain a data link layer ID of the second user equipment.
  • the first verification confirmation information in step 407 may not carry the data link layer ID of the second user equipment.
  • the first user equipment can also obtain the number of the second user equipment by other means. According to the link layer ID.
  • steps 406 and 407 give a way for the network side to verify that the second user equipment is legitimate. This method is only a preferred solution, and it is not excluded that the first user authenticates the identity of the second user equipment in other ways.
  • the first user equipment establishes a connection between the first user equipment and the second user equipment according to the data link layer ID of the second user equipment.
  • the second user equipment can be provided with a relay service. Specifically, the first user equipment establishes a connection with the second user equipment according to the data link layer ID of the second user equipment. Preferably, the first user equipment establishes a D2D connection with the second user equipment.
  • the first user equipment sends the data link layer ID of the first user equipment and the identifier of the second group to the second user equipment in a broadcast form, and the first user equipment may also directly send the first user to the second user equipment.
  • the second user equipment After receiving the data link layer ID of the first user equipment and the identifier of the second group, the second user equipment establishes a connection with the first user equipment, and may send information verification to the network device. Whether the user equipment is legal, and then establish a connection with the first user equipment. It is worth noting that the method for verifying whether the first user equipment is legal by the network side is only a preferred solution. Otherwise, the second user is not excluded to verify the identity of the first user equipment by other means.
  • the second user equipment may receive a broadcast message sent by multiple relay user equipments. At this time, the second user equipment may select a relay user equipment to establish a connection with the second user equipment.
  • the method for establishing a connection receives the discovery information sent by the second user equipment by receiving the service object group identifier sent by the network device, and confirms that the identifier of the second group is included in the service object group identifier, according to
  • the data link layer ID of the second user equipment establishes that the first user equipment is connected to the second user equipment and provides a relay service for the second user equipment, so that the first user equipment can only provide a relay for the group of the specific service object. Service improves the security of the relay service function.
  • the embodiment of the present invention provides another method for establishing a connection, which is applied to a network device.
  • the method for establishing a connection provided in this embodiment may be applied to the description in the corresponding embodiment of FIG. 2 .
  • the wireless network system further optionally, the network device may be the first network server in the network system shown in FIG. 2.
  • the method for establishing a connection provided by this embodiment includes the following steps:
  • the network device receives the first verification information sent by the first user equipment.
  • the first verification information includes an identifier of the second group, where the identifier of the second group is used to indicate a group to which the second user equipment belongs or a group to which the user of the second user equipment belongs, where the second user equipment may be at least A user provides services.
  • the first user equipment may be a relay user equipment, and the second user equipment may be a remote user equipment.
  • the first user equipment after the first user equipment receives the discovery information of the second user equipment, the first user equipment sends the first verification information to the network device.
  • the network device does not need to go to the first A user equipment sends an identification of a service object.
  • the network device acquires a service object group identifier of the first user equipment.
  • the network device acquires a pre-stored service object group identifier, where the service object group identifier is an identifier of a group that provides a relay service for the first user equipment, and the service object group identifier includes at least one group identifier.
  • the service object group identifier may be a data link layer ID of a group of service objects.
  • the network device sends the first verification confirmation information to the first user equipment.
  • the first verification confirmation information is used to indicate that the first user equipment provides a relay service for the second user equipment.
  • the network device confirms that the first user equipment can provide a relay service for the second user equipment by confirming that the identifier of the second group is included in the service object group identifier.
  • the method for establishing a connection obtained by the embodiment of the present invention obtains a service object group identifier by receiving the first verification information sent by the first user equipment, and confirms that the identifier of the second group is included in the service object group identifier, and is first
  • the user equipment sends the first verification confirmation information, so that the first user equipment can only provide the relay service for the group of the specific service object, thereby improving The security of the relay service function.
  • another embodiment of the present invention provides another method for establishing a connection.
  • the method for establishing a connection in the embodiment corresponding to FIG. 4 is the same, except that the network device in this embodiment does not.
  • the group name of the service object and the service object group identifier need to be sent to the first user equipment, and the network device determines whether the first user equipment can provide the relay service for the second user equipment.
  • the wireless network system is applied to the corresponding embodiment of FIG. 2, corresponding to the wireless network system shown in FIG. 2, in this embodiment, the first user equipment may be a relay user equipment, and the second user equipment may be It is a remote user equipment, and the network equipment may be the first network server.
  • the method for establishing a connection includes:
  • the first user equipment receives the discovery information sent by the second user equipment.
  • the discovery information includes the identifier of the second group and the relay service request, the relay service request is used to indicate that the second user equipment needs the relay service, and the identifier of the second group is used to indicate the group or the second user equipment belongs to A group to which the user of the user equipment belongs, wherein the second user equipment can provide services for at least one user, and the user of the second user equipment can be one or more of the at least one user, which is not limited herein.
  • the discovery information may further include a name of the second user equipment or a data link layer ID of the second user equipment, where the name of the second user equipment is used to identify the second user equipment,
  • the second user equipment sends the discovery information in a broadcast form, and the first user equipment receives the discovery information of the second user equipment by listening to the group member; or, the first user equipment may send the broadcast information, the broadcast The information includes a data link layer ID of the first user equipment and a relay service request, and the second user equipment sends the discovery information to the first user equipment after receiving the broadcast information of the first user equipment.
  • the first user equipment sends the first verification information to the network device.
  • the first verification information includes an identification of the second group.
  • the identifier of the second group may be the data link layer ID of the group to which the second user equipment belongs, or may also be the discovery code of the group to which the second user equipment belongs.
  • the network device acquires a pre-stored service object group identifier, where the service object group identifier is an identifier of a group that provides a relay service for the first user equipment, and the service object group identifier includes at least one group identifier.
  • the service object group identifier may be a data link layer ID of a group of service objects.
  • the network device may obtain the service object group identifier by sending information to the HSS or MCPTT server.
  • the network device determines whether the service object group identifier includes the group identifier to which the second user equipment belongs, so as to confirm whether the first user equipment can provide a relay service for the second user equipment, if the service object group identifier includes the second user equipment
  • the associated group identifier indicates that the second user is the object that the first user equipment provides the relay service.
  • the first verification information may further include a name of the second user equipment or a data link layer ID of the second user equipment.
  • the network device verifies whether the identity of the second user equipment is legal according to the name of the second user equipment or the data link layer ID of the second user equipment. If the second user equipment and the network device do not belong to the same network and belong to the same network as the second network server, the network device needs to send a message to the second network server, thereby verifying the identity of the second user equipment.
  • the name of the second user equipment may be a discovery code of the second user equipment.
  • step 604 is performed.
  • the first user equipment receives the first verification confirmation information sent by the network device.
  • the first verification confirmation information may further include a data link layer ID of the second user equipment. If the second user equipment and the network device do not belong to the same network, and the second network server belongs to the same network, the network device passes the The second network server sends a message to obtain a data link layer ID of the second user equipment. In conjunction with step 601, if the information carries the data link layer ID of the second user equipment, the first verification confirmation information of step 605 may not carry the data link layer ID of the second user equipment.
  • the first user equipment establishes a connection between the first user equipment and the second user equipment according to the data link layer ID of the second user equipment.
  • the second user equipment can be provided with a relay service.
  • the first user equipment establishes a D2D connection with the second user equipment.
  • the first user equipment sends the data link layer ID of the first user equipment and the identifier of the second group to the second user equipment in a broadcast form, and the first user equipment may also directly send the first user to the second user equipment.
  • the second user equipment may send information to the network device to verify whether the first user equipment is legal, and then the first user The device establishes a connection.
  • the second user equipment may receive a broadcast message sent by multiple relay user equipments. At this time, the second user equipment may select a relay user equipment to establish a connection with the second user equipment.
  • the method for establishing a connection obtained by the embodiment of the present invention obtains a service object group identifier by receiving the first verification information sent by the first user equipment, and confirms that the identifier of the second group is included in the service object group identifier, and is first
  • the user equipment sends the first verification confirmation information, so that the first user equipment can only provide the relay service for the group of the specific service object, thereby improving the security of the relay service function.
  • the embodiment of the present invention provides a first user equipment, which is used to perform the method for establishing a connection described in the foregoing embodiment corresponding to FIG. 3 or FIG. 4, and preferably, may be Applicable to the wireless network system described in the embodiment corresponding to FIG. 2, in the network system shown in FIG. 2, the first user equipment may be a relay user equipment, as shown in FIG.
  • a user equipment 70 includes a receiving unit 701 and a connecting unit 702.
  • the receiving unit 701 is configured to receive a service object group identifier that is sent by the network device, where the service object group identifier is used to indicate that the first user equipment provides a group of service objects of the relay service.
  • the receiving unit 701 is further configured to receive the discovery information sent by the second user equipment, where the discovery information includes the identifier of the second group and the relay service request, where the relay service request is used to request to provide the relay service, and the identifier of the second group Used to indicate the group or the number to which the second user device belongs The group to which the user of the two user equipment belongs.
  • the second user equipment may provide services for at least one user, and the user of the second user equipment may be one or more of the at least one user, which is not limited herein.
  • the connecting unit 702 is configured to acquire a data link layer identity identifier of the second user equipment when the identifier of the second group received by the receiving unit 701 is included in the service group group identifier, according to the data link of the second user equipment
  • the layer ID establishes a connection between the first user equipment and the second user equipment.
  • the first user equipment may further include a sending unit 703.
  • the sending unit 703 is configured to send a service authorization request to the network device.
  • the receiving unit 701 is further configured to receive a service authorization response sent by the network device, where the service authorization response carries the service object group identifier.
  • the receiving unit 701 is further configured to receive a group name of the service object sent by the network device, where the group name of the service object corresponds to the service object group identifier.
  • the sending unit 703 is configured to send discovery request information to the network device, where the discovery request information includes a group name of the service object.
  • the receiving unit 701 is further configured to receive discovery confirmation information sent by the network device, where the discovery confirmation information includes a service object group identifier.
  • the discovery information also includes a data link layer ID of the second user equipment.
  • the connecting unit 702 is specifically configured to obtain a data link layer ID of the second user equipment from the discovery information.
  • the discovery information also includes the name of the second user device, and the name of the second user device is used to identify the second user device.
  • the first user equipment further includes a sending unit 703, configured to send first verification information to the network device, where the first verification information carries a name of the second user equipment.
  • the receiving unit 701 is further configured to receive first verification confirmation information sent by the network device, where The first verification confirmation information carries a data link layer ID of the second user equipment.
  • the first user equipment receives the discovery information sent by the second user equipment by receiving the service object group identifier sent by the network device, and confirms that the identifier of the second group is included in the service object group identifier, according to
  • the data link layer ID of the second user equipment establishes that the first user equipment is connected to the second user equipment and provides a relay service for the second user equipment, so that the first user equipment can only provide a relay for the group of the specific service object. Service improves the security of the relay service function.
  • the embodiment of the present invention provides a network device, which is used to perform the method for establishing a connection described in the foregoing embodiment corresponding to FIG. 5 or FIG. 6, and preferably, may be applied to
  • the wireless network system described in the corresponding embodiment of FIG. 2, in the network system shown in FIG. 2, the network device may be the first network server.
  • the first user equipment 80 is provided in this embodiment.
  • the receiving unit 801, the obtaining unit 802, and the transmitting unit 803 are included.
  • the receiving unit 801 is configured to receive first verification information that is sent by the first user equipment, where the first verification information includes an identifier of the second group, and the identifier of the second group is used to indicate the group to which the second user equipment belongs or The group to which the user of the second user device belongs.
  • the second user equipment may provide services for at least one user, and the user of the second user equipment may be one or more of the at least one user, which is not limited herein.
  • the obtaining unit 802 is configured to obtain a service object group identifier of the first user equipment, where the service object group identifier of the first user equipment is used to indicate that the first user equipment provides a group of service objects of the relay service.
  • the sending unit 803 is configured to: when the identifier of the second group received by the receiving unit 801 is included in the service object group identifier acquired by the obtaining unit 802, send the first verification confirmation information to the first user equipment, where the first verification confirmation information is used.
  • the first user equipment is instructed to provide a relay service for the second user equipment.
  • the sending unit 803 is further configured to send, to the first user equipment, a data link layer identity identifier of the second user equipment, where the data link layer ID of the second user equipment is used by the first user equipment and the second user The device establishes a connection.
  • the network device receives the first a verification information, obtaining a service object group identifier, and confirming that the identifier of the second group is included in the service object group identifier, sending the first verification confirmation information to the first user equipment, so that the first user equipment can only be a specific service
  • the group of objects provides relay services, which improves the security of the relay service function.
  • another embodiment of the present invention provides a first user equipment, which is used to perform the method for establishing a connection described in the foregoing embodiment corresponding to FIG. 3 or FIG. It can be applied to the wireless network system described in the embodiment corresponding to FIG. 2.
  • the first user equipment may be a relay user equipment.
  • the first user is used.
  • the device 90 includes a processor 901, a memory 902, a bus 903, and a receiver 904.
  • the processor 901, the memory 902, and the receiver 904 are connected by a bus 903 and complete communication with each other.
  • the bus 903 may be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus, or an EISA (Extended Industry Standard Architecture) bus.
  • the bus 903 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 9, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 902 is used to execute the application code of the inventive scheme, and the application code for executing the inventive scheme is stored in a memory and controlled by the processor 901 for execution.
  • the memory can be a read only memory ROM or other type of static storage device that can store static information and instructions, a random access memory RAM or other type of dynamic storage device that can store information and instructions, or can be electrically erasable or programmable.
  • These memories are connected to the processor via a bus.
  • the processor 901 may be a central processing unit 901 (Central Processing Unit, abbreviated as CPU) or a specific integrated circuit (Application Specific Integrated). Circuit, abbreviated as ASIC), or one or more integrated circuits configured to implement embodiments of the present invention.
  • CPU Central Processing Unit
  • ASIC Application Specific Integrated
  • the processor 901 is configured to call the program code in the memory 902. In a possible implementation manner, when the application program is executed by the processor 901, the following functions are implemented.
  • the receiver 904 is configured to receive a service object group identifier sent by the network device, where the service object group identifier is used to indicate a group of service objects that the first user equipment provides the relay service.
  • the receiver 904 is further configured to receive the discovery information sent by the second user equipment, where the discovery information includes the identifier of the second group and the relay service request, where the relay service request is used to request the relay service, and the identifier of the second group A group for indicating a group to which the second user equipment belongs or a user to which the second user equipment belongs.
  • the second user equipment may provide services for at least one user, and the user of the second user equipment may be one or more of the at least one user, which is not limited herein.
  • the processor 901 is configured to acquire, when the identifier of the second group received by the receiver 904 is included in the service object group identifier, the data link layer identity identifier of the second user equipment, according to the data link of the second user equipment.
  • the layer ID establishes a connection between the first user equipment and the second user equipment.
  • the first user equipment further includes a transmitter 905.
  • the transmitter 905 is configured to send a service authorization request to the network device.
  • the receiver 904 is further configured to receive a service authorization response sent by the network device, where the service authorization response carries the service object group identifier.
  • the receiver 904 is further configured to receive a group name of the service object sent by the network device, where the group name of the service object corresponds to the service object group identifier.
  • the sender 905 is configured to send discovery request information to the network device, where the discovery request information includes a group name of the service object.
  • the receiver 904 is further configured to receive the discovery confirmation information sent by the network device, and find that The identification information includes the service object group identifier.
  • the discovery information also includes a data link layer ID of the second user equipment.
  • the processor 901 is specifically configured to obtain a data link layer ID of the second user equipment from the discovery information.
  • the discovery information also includes the name of the second user device, and the name of the second user device is used to identify the second user device.
  • the sender 905 is configured to send first verification information to the network device, where the first verification information carries a name of the second user equipment.
  • the receiver 904 is further configured to receive first verification confirmation information sent by the network device, where the first verification confirmation information carries a data link layer ID of the second user equipment.
  • the first user equipment receives the discovery information sent by the second user equipment by receiving the service object group identifier sent by the network device, and confirms that the identifier of the second group is included in the service object group identifier, according to
  • the data link layer ID of the second user equipment establishes that the first user equipment is connected to the second user equipment and provides a relay service for the second user equipment, so that the first user equipment can only provide a relay for the group of the specific service object. Service improves the security of the relay service function.
  • the network device may be a first network server.
  • the network device 100 includes: a processor. 1001, a memory 1002, a bus 1003, a receiver 1004, and a transmitter 1005.
  • the processor 1001, the memory 1002, the receiver 1004, and the transmitter 1005 are connected by a bus 1003 and complete communication with each other.
  • the bus 1003 may be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus, or an EISA (Extended Industry Standard Architecture) bus.
  • the bus 1003 can be divided into an address bus, a data bus, and a control Bus, etc. For ease of representation, only one thick line is shown in FIG. 10, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 1002 is for executing application code of the inventive scheme, and the application code for executing the inventive scheme is stored in a memory and controlled by the processor 1001 for execution.
  • the memory can be a read only memory ROM or other type of static storage device that can store static information and instructions, a random access memory RAM or other type of dynamic storage device that can store information and instructions, or can be electrically erasable or programmable.
  • These memories are connected to the processor via a bus.
  • the processor 1001 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more configured to implement the embodiments of the present invention. Integrated circuits.
  • CPU central processing unit
  • ASIC application specific integrated circuit
  • the processor 1001 is configured to call the program code in the memory 1002. In a possible implementation manner, when the application program is executed by the processor 1001, the following functions are implemented.
  • the receiver 1004 is configured to receive first verification information that is sent by the first user equipment, where the first verification information includes an identifier of the second group, and the identifier of the second group is used to indicate a group or a second to which the second user equipment belongs. The group to which the user of the user device belongs.
  • the second user equipment may provide services for at least one user, and the user of the second user equipment may be one or more of the at least one user, which is not limited herein.
  • the processor 1001 is configured to obtain a service object group identifier of the first user equipment, where the service object group identifier of the first user equipment is used to indicate a group of service objects that the first user equipment provides the relay service.
  • the transmitter 1005 is configured to send the first to the first user equipment when the identifier of the second group received by the receiver 1004 is included in the service object group identifier acquired by the processor 1001.
  • the verification confirmation information is used to indicate that the first user equipment provides a relay service for the second user equipment.
  • the sender 1005 is further configured to send, to the first user equipment, a data link layer identity identifier of the second user equipment, where the data link layer ID of the second user equipment is used by the first user equipment and the second user The device establishes a connection.
  • the network device obtains the service object group identifier by receiving the first verification information sent by the first user equipment, and confirms that the identifier of the second group is included in the service object group identifier, and sends the identifier to the first user equipment.
  • the first verification confirmation information is sent, so that the first user equipment can only provide the relay service for the group of the specific service object, thereby improving the security of the relay service function.
  • An embodiment of the present invention provides a wireless network system, where the wireless network system includes a first user equipment, a second user equipment, and a network equipment.
  • the first user equipment is the first user equipment described in the embodiment corresponding to FIG. 7 or FIG. 8.
  • the network device is the network device described in the embodiment corresponding to FIG. 9 or FIG. 10.
  • the wireless network system receives the service object group identifier sent by the network device by using the first user equipment, and receives the discovery information sent by the second user equipment, and confirms that the identifier of the second group is included in the service object group identifier. Establishing, by the data link layer ID of the second user equipment, the first user equipment and the second user equipment, and providing the second user equipment with a relay service, so that the first user equipment can only be a group of specific service objects. Provide relay services to improve the security of the relay service function.
  • Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a computer.
  • a computer readable medium can Including RAM (Randam Access Memory), ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memary), CD-ROM (Campact Disc Read Only Memory) , ie read-only discs) or other disc storage, disk storage media or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also. Any connection may suitably be a computer readable medium.
  • the disc and the disc include a CD (Compact Disc), a laser disc, a compact disc, a DVD disc (Digital Versatile Disc), a floppy disc, and a Blu-ray disc, wherein the disc is usually magnetically copied, The disc uses a laser to optically replicate the data. Combinations of the above should also be included within the scope of the computer readable media.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Multimedia (AREA)
  • Databases & Information Systems (AREA)
  • Power Engineering (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)
  • Communication Control (AREA)

Abstract

一种建立连接的方法、设备及系统,能够解决现有技术中第一用户设备与任意用户设备连接,使得中继服务功能安全性差的问题。具体方案为:第一用户设备接收网络设备发送的服务对象群组标识(301),接收第二用户设备发送的发现信息(302),确认第二群组的标识包含于服务对象群组标识时,根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备连接(304)。

Description

一种建立连接的方法、设备及系统 技术领域
本发明涉及通信领域,尤其涉及一种建立连接的方法、设备及系统。
背景技术
在无线通信网络中,有些用户设备可能会超出网络覆盖范围,例如,当用户处于如在地下室等网络信号不好或者没有网络信号覆盖的地方,将这些超出网络覆盖范围的用户设备称为远端用户设备,此时,为了使这些没有处于网络覆盖范围内的远端用户设备也能够与网络保持通信连接,在一种实现方式中,如图1所示,可以将距离该远端设备比较近,能够与该远端设备互相接收信息且处于网络覆盖范围内的用户设备作为中继用户设备,通过该中继用户设备转发用户和网络之间的数据。
目前这种利用用户设备作为中继设备的技术建议已被用于公共安全等紧急业务的通信中用于解决某些无网络覆盖的用户的通信问题。
在现有技术里,远端用户设备与中继用户设备建立连接的过程中,当中继用户设备打开中继服务功能后,用户向应用服务器发送注册请求进行注册时,会收到应用服务器返回的组成员信息,中继用户设备可以根据组成员信息与需要中继服务的用户设备建立连接,为该用户设备提供中继服务。
在实现上述过程中,中继用户设备接收到组成员信息的时机是打开中继服务功能之后,如果中继用户设备已经注册完毕,再打开中继服务功能,则不能提供中继服务,而且中继用户设备可以与任意用户设备建立连接,中继服务功能的安全性较差。
发明内容
本发明的实施例提供一种建立连接的方法、设备及系统,能够解决中继用户设备可以与任意的用户设备建立连接,使得中继服务功能安全性较差的问题。
为达到上述目的,本发明的实施例采用如下技术方案:
第一方面,本发明实施例提供一种建立连接的方法,包括:
第一用户设备接收网络设备发送的服务对象群组标识,所述服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
所述第一用户设备接收第二用户设备发送的发现信息,所述发现信息包括第二群组的标识及中继服务请求,所述中继服务请求用于请求提供中继服务,所述第二群组的标识用于指示所述第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
若所述第二群组的标识包含于所述服务对象群组标识,则所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID,根据所述第二用户设备的数据链路层ID,建立所述第一用户设备与所述第二用户设备之间的连接。
结合第一方面,在第一方面的第一种可能的实现方式中,
所述第一用户设备接收网络设备发送的服务对象群组标识之前,还包括:
所述第一用户设备向所述网络设备发送业务授权请求;
所述第一用户设备接收网络设备发送的服务对象群组标识,包括:
所述第一用户设备接收所述网络设备发送的业务授权响应,所述业务授权响应携带所述服务对象群组标识。
结合第一方面,在第一方面的第二种可能的实现方式中,所述第一用户设备接收网络设备发送的服务对象群组标识之前,还包括:
所述第一用户设备接收所述网络设备发送的服务对象的群组名称,所述服务对象的群组名称与所述服务对象群组标识对应;
所述第一用户设备向所述网络设备发送发现请求信息,所述发现请求信息包括所述服务对象的群组名称;
所述第一用户设备接收网络设备发送的服务对象群组标识,包括:
所述第一用户设备接收所述网络设备发送的发现确认信息,所述发现确认信息包括所述服务对象群组标识。
结合第一方面,在第一方面的第三种可能的实现方式中,
所述发现信息还包括所述第二用户设备的数据链路层ID;
所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID,包括:
所述第一用户设备从所述发现信息中获取所述第二用户设备的数据链路层ID。
结合第一方面,在第一方面的第四种可能的实现方式中,
所述发现信息还包括所述第二用户设备的名称,所述第二用户设备的名称用于识别所述第二用户设备;
所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID之前,还包括:
所述第一用户设备向所述网络设备发送第一验证信息,所述第一验证信息携带所述所述第二用户设备的名称;
所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID,包括:
所述第一用户设备接收所述网络设备发送的第一验证确认信息,所述第一验证确认信息携带所述第二用户设备的数据链路层ID。
第二方面,本发明实施例提供一种建立连接的方法,包括:
网络设备接收第一用户设备发送的第一验证信息,所述第一验证信息包括第二群组的标识,所述第二群组的标识用于指示第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
所述网络设备获取所述第一用户设备的服务对象群组标识,所述第一用户设备的服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
若所述第二群组的标识包含于所述第一用户设备的服务对象群组标识,则所述网络设备向所述第一用户设备发送第一验证确认信息,所述第一验证确认信息用于指示所述第一用户设备为所述第二用 户设备提供中继服务。
结合第二方面,在第二方面的第一种可能的实现方式中,所述方法还包括:
所述网络设备向所述第一用户设备发送所述第二用户设备的数据链路层身份标识ID,所述第二用户设备的数据链路层ID用于所述第一用户设备与所述第二用户设备建立连接。
第三方面,本发明实施例提供一种第一用户设备,包括:
接收单元,用于接收网络设备发送的服务对象群组标识,所述服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
所述接收单元,还用于接收第二用户设备发送的发现信息,所述发现信息包括第二群组的标识及中继服务请求,所述中继服务请求用于请求提供中继服务,所述第二群组的标识用于指示所述第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
连接单元,用于当所述接收单元接收的所述第二群组的标识包含于所述服务对象群组标识时,获取所述第二用户设备的数据链路层身份标识ID,根据所述第二用户设备的数据链路层ID,建立所述第一用户设备与所述第二用户设备之间的连接。
结合第三方面,在第三方面的第一种可能的实现方式中,
所述第一用户设备还包括发送单元,用于向所述网络设备发送业务授权请求;
所述接收单元,还用于接收所述网络设备发送的业务授权响应,所述业务授权响应携带所述服务对象群组标识。
结合第三方面,在第三方面的第二种可能的实现方式中,
所述接收单元,还用于接收所述网络设备发送的服务对象的群组名称,所述服务对象的群组名称与所述服务对象群组标识对应;
所述第一用户设备还包括发送单元,用于向所述网络设备发送发现请求信息,所述发现请求信息包括所述服务对象的群组名称;
所述接收单元,还用于接收所述网络设备发送的发现确认信息, 所述发现确认信息包括所述服务对象群组标识。
结合第三方面,在第三方面的第三种可能的实现方式中,
所述发现信息还包括所述第二用户设备的数据链路层ID;
所述连接单元,具体用于从所述发现信息中获取所述第二用户设备的数据链路层ID。
结合第三方面,在第三方面的第四种可能的实现方式中,
所述发现信息还包括所述第二用户设备的名称,所述第二用户设备的名称用于识别所述第二用户设备;
所述第一用户设备还包括发送单元,用于向所述网络设备发送第一验证信息,所述第一验证信息携带所述所述第二用户设备的名称;
所述接收单元,还用于接收所述网络设备发送的第一验证确认信息,所述第一验证确认信息携带所述第二用户设备的数据链路层ID。
第四方面,本发明实施例提供一种网络设备,包括:
接收单元,用于接收第一用户设备发送的第一验证信息,所述第一验证信息包括第二群组的标识,所述第二群组的标识用于指示第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
获取单元,用于获取所述第一用户设备的服务对象群组标识,所述第一用户设备的服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
发送单元,用于当所述接收单元接收的所述第二群组的标识包含于所述获取单元获取的所述服务对象群组标识时,向所述第一用户设备发送第一验证确认信息,所述第一验证确认信息用于指示所述第一用户设备为所述第二用户设备提供中继服务。
结合第四方面,在第四方面的第一种可能的实现方式中,
所述发送单元,还用于向所述第一用户设备发送所述第二用户设备的数据链路层身份标识ID,所述第二用户设备的数据链路层ID用于所述第一用户设备与所述第二用户设备建立连接。
第五方面,本发明实施例提供一种第一用户设备,包括处理器、存储器、总线及接收器,所述处理器、所述存储器及所述接收器通过 所述总线相互连接;
其中,所述接收器,用于接收网络设备发送的服务对象群组标识,所述服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
所述接收器,还用于接收第二用户设备发送的发现信息,所述发现信息包括第二群组的标识及中继服务请求,所述中继服务请求用于请求提供中继服务,所述第二群组的标识用于指示所述第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
所述处理器,用于当所述接收器接收的所述第二群组的标识包含于所述服务对象群组标识时,获取所述第二用户设备的数据链路层身份标识ID,根据所述第二用户设备的数据链路层ID,建立所述第一用户设备与所述第二用户设备之间的连接。
结合第五方面,在第五方面的第一种可能的实现方式中,
所述第一用户设备还包括发送器,用于向所述网络设备发送业务授权请求;
所述接收器,还用于接收所述网络设备发送的业务授权响应,所述业务授权响应携带所述服务对象群组标识。
结合第五方面,在第五方面的第二种可能的实现方式中,
所述接收器,还用于接收所述网络设备发送的服务对象的群组名称,所述服务对象的群组名称与所述服务对象群组标识对应;
所述第一用户设备还包括发送器,用于向所述网络设备发送发现请求信息,所述发现请求信息包括所述服务对象的群组名称;
所述接收器,还用于接收所述网络设备发送的发现确认信息,所述发现确认信息包括所述服务对象群组标识。
结合第五方面,在第五方面的第三种可能的实现方式中,
所述发现信息还包括所述第二用户设备的数据链路层ID;
所述处理器,具体用于从所述发现信息中获取所述第二用户设备的数据链路层ID。
结合第五方面,在第五方面的第四种可能的实现方式中,
所述发现信息还包括所述第二用户设备的名称,所述第二用户设备的名称用于识别所述第二用户设备;
所述第一用户设备还包括发送器,用于向所述网络设备发送第一验证信息,所述第一验证信息携带所述所述第二用户设备的名称;
所述接收器,还用于接收所述网络设备发送的第一验证确认信息,所述第一验证确认信息携带所述第二用户设备的数据链路层ID。
第六方面,本发明实施例提供一种网络设备,包括处理器、存储器、总线、接收器及所述发送器,所述处理器、所述存储器、所述接收器及所述发送器通过所述总线相互连接;
接收器,用于接收第一用户设备发送的第一验证信息,所述第一验证信息包括第二群组的标识,所述第二群组的标识用于指示第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
处理器,用于获取所述第一用户设备的服务对象群组标识,所述第一用户设备的服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
发送器,用于当所述接收器接收的所述第二群组的标识包含于所述处理器获取的所述服务对象群组标识时,向所述第一用户设备发送第一验证确认信息,所述第一验证确认信息用于指示所述第一用户设备为所述第二用户设备提供中继服务。
结合第六方面,在第六方面的第一种可能的实现方式中,
所述发送器,还用于向所述第一用户设备发送所述第二用户设备的数据链路层身份标识ID,所述第二用户设备的数据链路层ID用于所述第一用户设备与所述第二用户设备建立连接。
本发明实施例提供的一种建立连接的方法、设备及系统,通过第一用户设备接收网络设备发送的服务对象群组标识,接收第二用户设备发送的发现信息,确认第二群组的标识包含于服务对象群组标识时,根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备连接并为第二用户设备提供中继服务,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全 性。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为现有技术提供的一种中继通信方式示意图;
图2为本发明实施例提供的一种无线网络系统结构示意图;
图3为本发明实施例提供的一种建立连接的方法流程示意图;
图4为本发明另一实施例提供的一种建立连接的方法信息交互示意图;
图5为本发明实施例提供的另一种建立连接的方法流程示意图;
图6为本发明另一实施例提供的另一种建立连接的方法信息交互示意图;
图7为本发明实施例提供的一种第一用户设备结构示意图;
图8为本发明实施例提供的一种网络设备结构示意图;
图9为本发明另一实施例提供的一种第一用户设备结构示意图;
图10为本发明另一实施例提供的一种网络设备结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
图2示出了一种无线网络系统,图2所示的无线网络系统20包括中继用户设备201、远端用户设备202及第一网络服务器203,可选的,该无线网络系统还可以包括第二网络服务器204、HSS(Home Subscriber Server,归属用户服务器)205、应用层服务器206。有限 的,该无线网络系统可以属于LTE(Long Term Evolution,长期演进)系统。
其中,中继用户设备201,用于为其他用户设备提供中继服务,优选的,本发明中的中继服务包括通过转发其他用户设备与网络侧的信息实现其他用户设备与网络侧的通信。
远端用户设备202为不处于无线网络系统覆盖范围内的用户设备,需要其他用户设备为其提供中继服务的用户设备。
第一网络服务器203和第二网络服务器204可以是用于处理终端设备之间直连通信所需的网络侧功能实体。
HSS205是IMS(IP Multimedia Subsystem,IP多媒体子系统)中控制层的重要组成部分。HSS支持用于处理调用/会话的IMS网络实体的主要用户数据库。它包含用户配置文件,执行用户的身份验证和授权,并可提供有关用户物理位置的信息。
本发明实施例提供一种建立连接的方法,应用于第一用户设备,优选的,本实施例提供的建立连接的方法可以应用于图2对应的实施例中所描述的无线网络系统,可选的,该第一用户设备可以是图2所示的无线网络系统中的中继用户设备,参照图3所示,本实施例提供的建立连接的方法包括以下步骤:
301、第一用户设备接收网络设备发送的服务对象群组标识。
服务对象群组标识用于指示第一用户设备提供中继服务的服务对象的群组,服务对象群组标识包括至少一个群组标识。可选的,网络设备可以先获取服务对象的群组名称,根据服务对象的群组名称通过网络设备获取服务对象群组标识。进一步可选的,第一用户设备提供中继服务的服务对象的群组可以是网络侧预先分配好的,进一步可选的,在OSI(Open System Interconnection,开放式系统互联)模型中,服务对象群组标识可以是服务对象的群组的数据链路层ID(IDentity,身份标识),服务对象的群组名称可以是服务对象的群组的应用层ID。
优选的,应用于图2对应的实施例所描述的无线网络系统,该网 络设备可以是第一网络服务器。第一用户设备的服务对象可以是应用层管理设备预先分配好的,这样,第一用户设备提供中继服务的对象就是一些属于特定群组的用户设备,并不是任意一个用户设备都可以与第一用户设备建立连接,相当于对第一用户设备提供中继服务的对象做了过滤,提高了中继服务过程中信息交互的安全性。
302、第一用户设备接收第二用户设备发送的发现信息。
发现信息包括第二群组的标识及中继服务请求,中继服务请求用于指示第二用户设备需要中继服务,第二群组的标识用于指示第二用户设备所属的群组或第二用户设备的用户所属的群组。
其中,第二用户设备可以为至少一个用户提供服务,第二用户设备的用户可以为所述至少一个用户中的一个或多个,此处不予限制。
优选的,应用于图2对应的实施例中所描述的无线网络系统,该第二用户设备可以是图2所示的无线网络系统中的远端用户设备。可选的,当第二用户设备需要其他用户设备为其提供中继服务时,可以通过广播的形式发送该发现信息,第一用户设备就可以接收到该发现信息。当然,如果无线网络系统中还有其他中继用户设备,也可以接收到该发现信息,本实施例中只是以第一用户设备为例进行说明。
可选的,步骤301及步骤302没有先后顺序。在步骤301及步骤302之后,还包括:
303、若第二群组的标识包含于服务对象群组标识,则第一用户设备获取第二用户设备的数据链路层ID(Identity,身份标识)。
可选的,发现信息中可以包含第二用户设备的数据链路层ID,第一用户设备可以直接从发现信息中获取第二用户设备的数据链路层ID。
或者,可选的,发现信息中包含第二用户设备的名称,第二用户设备的名称用于识别第二用户设备,优选的,第二用户设备的名称可以是第二用户设备的发现码。第一用户设备根据第二用户设备的名称向网络设备获取第二用户设备的数据链路层ID。进一步优选的,第一用户设备向网络设备发送第一验证信息,该第一验证信息携带第二 用户设备的名称,第一用户设备接收第一网络设备发送的第一验证确认信息,该第一验证确认信息包含第二用户设备的数据链路层ID。进一步可选的,第二用户设备的名称可以是第二用户设备的发现码(Group ProSe Code)。
当然,第一用户设备也可以通过其他方式获取第二用户设备的数据链路层ID。
304、第一用户设备根据第二用户设备的数据链路层ID,建立第一用户设备与第二用户设备之间的连接。
第一用户设备建立第一用户设备与第二用户设备之间的连接后,就可以为第二用户设备提供中继服务。可选的,第一用户设备接收到发现信息后,确认第二用户的群组标识是否包含于服务对象群组标识,如果第二用户的群组标识没有包含于服务对象群组标识,说明第二用户设备并不是第一用户设备可以提供中继服务的对象,如果第二群组的标识包含于服务对象群组标识,则说明第二用户设备属于第一用户设备提供中继服务的对象,第一用户设备根据第二用户设备的数据链路层ID与第二用户设备建立连接即可。
优选的,第一用户设备与第二用户设备建立D2D(Device to Device,终端直通)连接。
本发明实施例提供的建立连接的方法,通过接收网络设备发送的服务对象群组标识,接收第二用户设备发送的发现信息,确认第二群组的标识包含于服务对象群组标识时,根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备连接并为第二用户设备提供中继服务,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
基于上述图3对应的实施例,本发明另一实施例提供一种建立连接的方法,优选的,应用于图2对应的实施例所描述的无线网络系统,对应图2所示的无线网络系统,在本实施例中,第一用户设备可以是中继用户设备,第二用户设备可以是远端用户设备,网络设备可以是第一网络服务器,当然,本实施例只是以图2所示的无线网络系统为 例进行说明,并不代表本发明局限于此,参照图4所示,本实施例提供的建立连接的方法包括:
401、对第一用户设备进行业务授权。
具体可选的,第一用户设备向网络设备发送业务授权请求,业务授权请求包括第一用户设备请求为其他用户设备提供中继服务的指示信息,中继服务包括通过转发其他用户设备的信息实现其他用户设备与网络侧的通信,其他用户设备包括第二用户设备;第一用户设备接收网络设备发送的业务授权响应信息。
优选的,该业务授权响应信息携带有第一用户设备服务对象的群组名称,该服务对象的群组名称包括至少一个群组名称,进一步可选的,该服务对象的群组名称可以是服务对象的群组的应用层ID,该服务对象的群组名称可以是一个群组列表(Group List)。该服务对象的群组名称也可以通过其他消息携带发送至第一用户设备,或者,网络设备向第一用户设备发送一条单独的消息携带服务对象的群组名称。对此,本发明不做限制。
可选的,网络设备可以通过向HSS发送请求获得对第一用户设备的授权。
402、第一用户设备根据业务授权响应信息开启中继服务功能。
403、第一用户设备向网络设备发送发现请求信息。
具体可选的,发现请求信息包括服务对象的群组名称。可选的,该发现请求信息用于请求获得监听群组成员(Mornitor Group Member)的权限。
404、第一用户设备接收网络设备发送的发现确认信息。
具体可选的,发现确认信息包括服务对象群组标识,该服务对象群组标识包括至少一个群组标识,结合步骤403中服务对象的群组名称,一个群组标识对应一个群组名称,优选的,该服务对象群组标识可以是服务对象的群组的数据链路层ID,或者服务对象群组标识也可以是服务对象的群组发现码。
在一种具体的实施方式中,可选的,服务对象群组标识也可以携 带在步骤401的业务授权响应信息中发送至第一用户设备,此时,步骤403-404可以跳过,直接执行步骤405。当然,服务对象群组标识也可以携带在其他信息中发送至第一用户设备,或者网络设备向第一用户设备发送一条单独的信息携带服务对象群组标识。对此,本发明不做限制。
在另一种具体的实施方式中,可选的,可以不执行步骤401及步骤402,直接执行步骤403,当网络设备接收到第一用户设备发送的发现请求信息后,在发现确认信息中携带服务对象群组标识,并将发现确认信息发送至第一用户设备。进一步可选的,网络设备可以向HSS或应用层服务器发送信息以获取该服务对象群组标识,优选的,该应用层服务器可以是MCPTT服务器(Mission Critical push to talk over LTE基于LTE的紧急通信对讲机业务)。进一步可选的,如果从MCPTT服务器获取的是服务对象的群组名称,则网络设备还需要进一步获取对应的服务对象群组标识。
进一步可选的,如果服务对象的群组名称中的某些群组与网络设备不属于同一网络,则网络设备需要向这些群组所属的网络服务器发送消息,从而获取这些群组的数据链路层ID。
可选的,该发现确认信息用于指示第一用户设备获得监听群组成员的权限,可以开始监听,在一些应用场景中,网络设备可以向HSS或者应用层服务器发送消息获取第一用户设备监听群组成员的权限。
405、第一用户设备接收第二用户设备发送的发现信息。
发现信息包括第二群组的标识及中继服务请求,中继服务请求用于指示第二用户设备需要中继服务,第二群组的标识用于指示第二用户设备所属的群组或者第二用户设备的用户所属的群组,其中,第二用户设备可以为至少一个用户提供服务。可选的,发现信息还可以包括第二用户设备的名称或第二用户设备的数据链路层ID,第二用户设备的名称用于识别第二用户设备。
优选的,第二用户设备通过广播的形式发送该发现信息,第一用户设备通过监听群组成员接收到第二用户设备的发现信息;
优选的,第一用户设备可以根据服务对象群组标识是否包含第二群组的标识确认第二用户设备是否属于第一用户设备服务对象的群组,如果服务对象群组标识包含第二群组的标识,则证明第一用户设备可以为第二用户设备提供中继服务。
可选的,步骤405与步骤401-404中任一步骤无先后顺序,进一步的,可以执行步骤406。
或者,也可以是第一用户设备发送广播信息,该广播信息包含第一用户设备的数据链路层ID及中继服务请求,以及被网络授权的服务对象群组标识,第二用户设备接收到第一用户设备的广播信息后,根据第一用户设备广播的服务对象群组标识判断第一用户设备是否可以为其提供中继服务,如果可以,则向第一用户设备发送连接请求,并直接执行步骤408。
406、第一用户设备向网络设备发送第一验证信息。
优选的,结合步骤405,该第一验证信息可以包括第二用户设备的名称或第二用户设备的数据链路层ID。网络设备根据第二用户设备的名称或第二用户设备的数据链路层ID验证第二用户设备的身份是否合法。如果第二用户设备与网络设备不属于同一网络,则网络设备需要向其他网络服务器发送消息,具体的,可以向第二网络服务器发送消息,第二网络服务器与第二用户设备属于同一网络,从而验证第二用户设备的身份。
优选的,第二用户设备的名称可以是第二用户设备的发现码。
407、第一用户设备接收网络设备发送的第一验证确认信息。
优选的,第一验证确认信息还可以包括第二用户设备的数据链路层ID,如果第二用户设备与网络设备不属于同一网络,与第二网络服务器属于同一网络,则网络设备通过向第二网络服务器发送消息获取第二用户设备的数据链路层ID。可选的,结合步骤405,如果发现信息中携带第二用户设备的数据链路层ID,则步骤407中的第一验证确认信息可以不携带第二用户设备的数据链路层ID。
当然,第一用户设备也可以通过其他方式获取第二用户设备的数 据链路层ID。
值得指出的是406和407步骤给出了一种由网络侧验证第二用户设备是否合法的方法。这种方法只是一种优选方案,除此以外,也不排除第一用户采用其他方式验证第二用户设备的身份。
408、第一用户设备根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备之间的连接。
第一用户设备建立第一用户设备与第二用户设备之间的连接后,就可以为第二用户设备提供中继服务。具体可选的,第一用户设备根据第二用户设备的数据链路层ID与第二用户设备建立连接。优选的,第一用户设备与第二用户设备建立D2D连接。
优选的,第一用户设备通过广播形式向第二用户设备发送第一用户设备的数据链路层ID及第二群组的标识,第一用户设备也可以直接向第二用户设备发送第一用户设备的数据链路层ID及第二群组的标识的点对点消息。
第二用户设备接收到第一用户设备发送的第一用户设备的数据链路层ID及第二群组的标识后,与第一用户设备建立连接,并可以可以向网络设备发送信息验证第一用户设备是否合法,然后与第一用户设备建立连接。值得指出的是这种由网络侧验证第一用户设备是否合法的方法只是一种优选方案,除此以外,也不排除第二用户采用其他方式验证第一用户设备的身份。
进一步可选的,第二用户设备可以接收到多个中继用户设备发送的广播消息,此时,第二用户设备可以选择一个中继用户设备,与其建立连接。
本发明实施例提供的建立连接的方法,通过接收网络设备发送的服务对象群组标识,接收第二用户设备发送的发现信息,确认第二群组的标识包含于服务对象群组标识时,根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备连接并为第二用户设备提供中继服务,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
结合图3对应的实施例,本发明实施例提供另一种建立连接的方法,应用于网络设备,优选的,本实施例提供的建立连接的方法可以应用于图2对应的实施例中所描述的无线网络系统,进一步可选的,网络设备可以是图2所示的网络系统中的第一网络服务器。参照图5所示,本实施例提供的建立连接的方法包括以下步骤:
501、网络设备接收第一用户设备发送的第一验证信息。
第一验证信息包括第二群组的标识,第二群组的标识用于指示第二用户设备所属的群组或者第二用户设备的用户所属的群组,其中,第二用户设备可以为至少一个用户提供服务。优选的,应用于图2所示的无线网络系统中,第一用户设备可以是中继用户设备,第二用户设备可以是远端用户设备。结合图3对应的实施例,在第一用户设备接收到第二用户设备的发现信息后,向网络设备发送第一验证信息,与图3对应的实施例的区别在于,网络设备不需要向第一用户设备发送服务对象的标识。
502、网络设备获取第一用户设备的服务对象群组标识。
网络设备获取预先存储的服务对象群组标识,该服务对象群组标识为第一用户设备提供中继服务的群组的标识,服务对象群组标识包括至少一个群组标识。优选的,该服务对象群组标识可以是服务对象的群组的数据链路层ID。
503、若第二群组的标识包含于服务对象群组标识,则网络设备向第一用户设备发送第一验证确认信息。
第一验证确认信息用于指示第一用户设备为第二用户设备提供中继服务。本实施例中,由网络设备通过确认第二群组的标识包含于服务对象群组标识确认第一用户设备可以为第二用户设备提供中继服务。
本发明实施例提供的建立连接的方法,通过接收第一用户设备发送的第一验证信息,获取服务对象群组标识,确认第二群组的标识包含于服务对象群组标识时,向第一用户设备发送第一验证确认信息,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高 了中继服务功能的安全性。
基于上述图5对应的实施例,本发明另一实施例提供另一种建立连接的方法,与图4对应的实施例中建立连接的方法原理相同,其区别在于,本实施例中网络设备不需要向第一用户设备发送服务对象的群组名称及服务对象群组标识,由网络设备确认第一用户设备是否可以为第二用户设备提供中继服务。优选的,应用于图2对应的实施例所描述的无线网络系统,对应图2所示的无线网络系统,在本实施例中,第一用户设备可以是中继用户设备,第二用户设备可以是远端用户设备,网络设备可以是第一网络服务器,当然,本实施例只是以图2所示的无线网络系统为例进行说明,并不代表本发明局限于此,参照图6所示,当第一用户设备开启中继服务功能并且获得监听群组成员的权限之后,本实施例提供的建立连接的方法包括:
601、第一用户设备接收第二用户设备发送的发现信息。
发现信息包括第二群组的标识及中继服务请求,中继服务请求用于指示第二用户设备需要中继服务,第二群组的标识用于指示第二用户设备所属的群组或者第二用户设备的用户所属的群组,其中,第二用户设备可以为至少一个用户提供服务,第二用户设备的用户可以为所述至少一个用户中的一个或多个,此处不予限制。发现信息还可以包括第二用户设备的名称或第二用户设备的数据链路层ID,第二用户设备的名称用于识别第二用户设备,
优选的,第二用户设备通过广播的形式发送该发现信息,第一用户设备通过监听群组成员接收到第二用户设备的发现信息;或者,也可以是第一用户设备发送广播信息,该广播信息包含第一用户设备的数据链路层ID及中继服务请求,第二用户设备接收到第一用户设备的广播信息后向第一用户设备发送发现信息。
602、第一用户设备向网络设备发送第一验证信息。
第一验证信息包括第二群组的标识。优选的,第二群组的标识可以是第二用户设备所属群组的数据链路层ID,或者,也可以是第二用户设备所属群组的发现码。
603、判断第一用户设备是否能够为第二用户设备提供中继服务。
具体的,网络设备获取预先存储的服务对象群组标识,该服务对象群组标识为第一用户设备提供中继服务的群组的标识,服务对象群组标识包括至少一个群组标识。优选的,该服务对象群组标识可以是服务对象的群组的数据链路层ID。进一步可选的,在一种应用场景中,网络设备可以通过向HSS或MCPTT服务器发送信息以获取服务对象群组标识。
网络设备判断服务对象群组标识是否包含第二用户设备所属的群组标识,以此确认第一用户设备能否为第二用户设备提供中继服务,如果服务对象群组标识包含第二用户设备所属的群组标识,则说明第二用户是第一用户设备提供中继服务的对象。
进一步优选的,该第一验证信息还可以包括第二用户设备的名称或第二用户设备的数据链路层ID。网络设备根据第二用户设备的名称或第二用户设备的数据链路层ID验证第二用户设备的身份是否合法。如果第二用户设备与网络设备不属于同一网络,与第二网络服务器属于同一网络,则网络设备需要向第二网络服务器发送消息,从而验证第二用户设备的身份。
可选的,第二用户设备的名称可以是第二用户设备的发现码。
进一步的,当确认第二群组的标识包含于服务对象群组标识时,执行步骤604。
605、第一用户设备接收网络设备发送的第一验证确认信息。
优选的,第一验证确认信息还可以包括第二用户设备的数据链路层ID,如果第二用户设备与网络设备不属于同一网络,与第二网络服务器属于同一网络,则网络设备通过向第二网络服务器发送消息获取第二用户设备的数据链路层ID。结合步骤601,如果发现信息中携带第二用户设备的数据链路层ID,则步骤605的第一验证确认信息可以不携带第二用户设备的数据链路层ID。
606、第一用户设备根据第二用户设备的数据链路层ID,建立第一用户设备与第二用户设备之间的连接。
第一用户设备建立第一用户设备与第二用户设备之间的连接后,就可以为第二用户设备提供中继服务。优选的,第一用户设备与第二用户设备建立D2D连接。
优选的,第一用户设备通过广播形式向第二用户设备发送第一用户设备的数据链路层ID及第二群组的标识,第一用户设备也可以直接向第二用户设备发送第一用户设备的数据链路层ID及第二群组的标识。第二用户设备接收到第一用户设备发送的第一用户设备的数据链路层ID及第二群组的标识后,可以向网络设备发送信息验证第一用户设备是否合法,然后与第一用户设备建立连接。
进一步可选的,第二用户设备可以接收到多个中继用户设备发送的广播消息,此时,第二用户设备可以选择一个中继用户设备,与其建立连接。
本发明实施例提供的建立连接的方法,通过接收第一用户设备发送的第一验证信息,获取服务对象群组标识,确认第二群组的标识包含于服务对象群组标识时,向第一用户设备发送第一验证确认信息,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
基于上述图3和图4对应的实施例,本发明实施例提供一种第一用户设备,用于执行上述图3或图4对应的实施例中所描述的建立连接的方法,优选的,可以应用于图2对应的实施例中所描述的无线网络系统,在图2所示的网络系统中,该第一用户设备可以是中继用户设备,参照图7所示,本实施例提供的第一用户设备70包括接收单元701及连接单元702。
其中,接收单元701,用于接收网络设备发送的服务对象群组标识,服务对象群组标识用于指示第一用户设备提供中继服务的服务对象的群组。
接收单元701,还用于接收第二用户设备发送的发现信息,发现信息包括第二群组的标识及中继服务请求,中继服务请求用于请求提供中继服务,第二群组的标识用于指示第二用户设备所属的群组或第 二用户设备的用户所属的群组。
其中,第二用户设备可以为至少一个用户提供服务,第二用户设备的用户可以为所述至少一个用户中的一个或多个,此处不予限制。
连接单元702,用于当接收单元701接收的第二群组的标识包含于服务对象群组标识时,获取第二用户设备的数据链路层身份标识ID,根据第二用户设备的数据链路层ID,建立第一用户设备与第二用户设备之间的连接。
可选的,该第一用户设备还可以包括发送单元703。
可选的,在第一种应用场景中,
发送单元703,用于向网络设备发送业务授权请求。
接收单元701,还用于接收网络设备发送的业务授权响应,业务授权响应携带服务对象群组标识。
可选的,在第二种应用场景中,
接收单元701,还用于接收网络设备发送的服务对象的群组名称,服务对象的群组名称与服务对象群组标识对应。
发送单元703,用于向网络设备发送发现请求信息,发现请求信息包括服务对象的群组名称。
接收单元701,还用于接收网络设备发送的发现确认信息,发现确认信息包括服务对象群组标识。
可选的,在第三种应用场景中,
发现信息还包括第二用户设备的数据链路层ID。
连接单元702,具体用于从发现信息中获取第二用户设备的数据链路层ID。
可选的,在第四种应用场景中,
发现信息还包括第二用户设备的名称,第二用户设备的名称用于识别第二用户设备。
第一用户设备还包括发送单元703,用于向网络设备发送第一验证信息,第一验证信息携带第二用户设备的名称。
接收单元701,还用于接收网络设备发送的第一验证确认信息, 第一验证确认信息携带第二用户设备的数据链路层ID。
本发明实施例提供的第一用户设备,通过接收网络设备发送的服务对象群组标识,接收第二用户设备发送的发现信息,确认第二群组的标识包含于服务对象群组标识时,根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备连接并为第二用户设备提供中继服务,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
基于上述图5和图6对应的实施例,本发明实施例提供一种网络设备,用于执行上述图5或图6对应的实施例中所描述的建立连接的方法,优选的,可以应用于图2对应的实施例中所描述的无线网络系统,在图2所示的网络系统中,该网络设备可以是第一网络服务器,参照图8所示,本实施例提供的第一用户设备80包括接收单元801、获取单元802及发送单元803。
其中,接收单元801,用于接收第一用户设备发送的第一验证信息,第一验证信息包括第二群组的标识,第二群组的标识用于指示第二用户设备所属的群组或第二用户设备的用户所属的群组。
其中,第二用户设备可以为至少一个用户提供服务,第二用户设备的用户可以为所述至少一个用户中的一个或多个,此处不予限制。
获取单元802,用于获取第一用户设备的服务对象群组标识,第一用户设备的服务对象群组标识用于指示第一用户设备提供中继服务的服务对象的群组。
发送单元803,用于当接收单元801接收的第二群组的标识包含于获取单元802获取的服务对象群组标识时,向第一用户设备发送第一验证确认信息,第一验证确认信息用于指示第一用户设备为第二用户设备提供中继服务。
可选的,发送单元803,还用于向第一用户设备发送第二用户设备的数据链路层身份标识ID,第二用户设备的数据链路层ID用于第一用户设备与第二用户设备建立连接。
本发明实施例提供的网络设备,通过接收第一用户设备发送的第 一验证信息,获取服务对象群组标识,确认第二群组的标识包含于服务对象群组标识时,向第一用户设备发送第一验证确认信息,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
基于上述图3和图4对应的实施例,本发明另一实施例提供一种第一用户设备,用于执行上述图3或图4对应的实施例中所描述的建立连接的方法,优选的,可以应用于图2对应的实施例中所描述的无线网络系统,在图2所示的网络系统中,该第一用户设备可以是中继用户设备,参照图9所示,该第一用户设备90包括:处理器901、存储器902、总线903和接收器904,该处理器901、存储器902和接收器904通过总线903连接并完成相互间的通信。
该总线903可以是ISA(Industry Standard Architecture,工业标准体系结构)总线、PCI(Peripheral Component,外部设备互连)总线或EISA(Extended Industry Standard Architecture,扩展工业标准体系结构)总线等。该总线903可以分为地址总线、数据总线、控制总线等。为便于表示,图9中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。其中:
存储器902用于执行本发明方案的应用程序代码,执行本发明方案的应用程序代码保存在存储器中,并由处理器901来控制执行。
该存储器可以是只读存储器ROM或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器RAM或者可存储信息和指令的其他类型的动态存储设备,也可以是电可擦可编程只读存储器EEPROM、只读光盘CD-ROM或其他光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。这些存储器通过总线与处理器相连接。
处理器901可能是一个中央处理器901(Central Processing Unit,简称为CPU),或者是特定集成电路(Application Specific Integrated  Circuit,简称为ASIC),或者是被配置成实施本发明实施例的一个或多个集成电路。
处理器901,用于调用存储器902中的程序代码,在一种可能的实施方式中,当上述应用程序被所述处理器901执行时,实现如下功能。
接收器904,用于接收网络设备发送的服务对象群组标识,服务对象群组标识用于指示第一用户设备提供中继服务的服务对象的群组。
接收器904,还用于接收第二用户设备发送的发现信息,发现信息包括第二群组的标识及中继服务请求,中继服务请求用于请求提供中继服务,第二群组的标识用于指示第二用户设备所属的群组或第二用户设备的用户所属的群组。
其中,第二用户设备可以为至少一个用户提供服务,第二用户设备的用户可以为所述至少一个用户中的一个或多个,此处不予限制。
处理器901,用于当接收器904接收的第二群组的标识包含于服务对象群组标识时,获取第二用户设备的数据链路层身份标识ID,根据第二用户设备的数据链路层ID,建立第一用户设备与第二用户设备之间的连接。
可选的,第一用户设备还包括发送器905。
可选的,在第一种应用场景中,
发送器905,用于向网络设备发送业务授权请求。
接收器904,还用于接收网络设备发送的业务授权响应,业务授权响应携带服务对象群组标识。
可选的,在第二种应用场景中,
接收器904,还用于接收网络设备发送的服务对象的群组名称,服务对象的群组名称与服务对象群组标识对应。
发送器905,用于向网络设备发送发现请求信息,发现请求信息包括服务对象的群组名称。
接收器904,还用于接收网络设备发送的发现确认信息,发现确 认信息包括服务对象群组标识。
可选的,在第三种应用场景中,
发现信息还包括第二用户设备的数据链路层ID。
处理器901,具体用于从发现信息中获取第二用户设备的数据链路层ID。
可选的,在第四种应用场景中,
发现信息还包括第二用户设备的名称,第二用户设备的名称用于识别第二用户设备。
发送器905,用于向网络设备发送第一验证信息,第一验证信息携带第二用户设备的名称。
接收器904,还用于接收网络设备发送的第一验证确认信息,第一验证确认信息携带第二用户设备的数据链路层ID。
本发明实施例提供的第一用户设备,通过接收网络设备发送的服务对象群组标识,接收第二用户设备发送的发现信息,确认第二群组的标识包含于服务对象群组标识时,根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备连接并为第二用户设备提供中继服务,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
基于上述图5和图6对应的实施例,本发明另一实施例提供一种网络设备,用于执行上述图5或图6对应的实施例中所描述的建立连接的方法,优选的,可以应用于图2对应的实施例中所描述的无线网络系统,在图2所示的网络系统中,该网络设备可以是第一网络服务器,参照图10所示,该网络设备100包括:处理器1001、存储器1002、总线1003、接收器1004和发送器1005,该处理器1001、存储器1002、接收器1004和发送器1005通过总线1003连接并完成相互间的通信。
该总线1003可以是ISA(Industry Standard Architecture,工业标准体系结构)总线、PCI(Peripheral Component,外部设备互连)总线或EISA(Extended Industry Standard Architecture,扩展工业标准体系结构)总线等。该总线1003可以分为地址总线、数据总线、控制 总线等。为便于表示,图10中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。其中:
存储器1002用于执行本发明方案的应用程序代码,执行本发明方案的应用程序代码保存在存储器中,并由处理器1001来控制执行。
该存储器可以是只读存储器ROM或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器RAM或者可存储信息和指令的其他类型的动态存储设备,也可以是电可擦可编程只读存储器EEPROM、只读光盘CD-ROM或其他光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。这些存储器通过总线与处理器相连接。
处理器1001可能是一个中央处理器1001(Central Processing Unit,简称为CPU),或者是特定集成电路(Application Specific Integrated Circuit,简称为ASIC),或者是被配置成实施本发明实施例的一个或多个集成电路。
处理器1001,用于调用存储器1002中的程序代码,在一种可能的实施方式中,当上述应用程序被所述处理器1001执行时,实现如下功能。
接收器1004,用于接收第一用户设备发送的第一验证信息,第一验证信息包括第二群组的标识,第二群组的标识用于指示第二用户设备所属的群组或第二用户设备的用户所属的群组。
其中,第二用户设备可以为至少一个用户提供服务,第二用户设备的用户可以为所述至少一个用户中的一个或多个,此处不予限制。
处理器1001,用于获取第一用户设备的服务对象群组标识,第一用户设备的服务对象群组标识用于指示第一用户设备提供中继服务的服务对象的群组。
发送器1005,用于当接收器1004接收的第二群组的标识包含于处理器1001获取的服务对象群组标识时,向第一用户设备发送第一 验证确认信息,第一验证确认信息用于指示第一用户设备为第二用户设备提供中继服务。
可选的,发送器1005,还用于向第一用户设备发送第二用户设备的数据链路层身份标识ID,第二用户设备的数据链路层ID用于第一用户设备与第二用户设备建立连接。
本发明实施例提供的网络设备,通过接收第一用户设备发送的第一验证信息,获取服务对象群组标识,确认第二群组的标识包含于服务对象群组标识时,向第一用户设备发送第一验证确认信息,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
本发明实施例提供一种无线网络系统,该无线网络系统包括第一用户设备、第二用户设备及网络设备。
可选的,在第一种应用场景中,该第一用户设备为图7或图8对应的实施例中所描述的第一用户设备。
或者,在第二种应用场景中,该网络设备为图9或图10对应的实施例所描述的网络设备。
本发明实施例提供的无线网络系统,通过第一用户设备接收网络设备发送的服务对象群组标识,接收第二用户设备发送的发现信息,确认第二群组的标识包含于服务对象群组标识时,根据第二用户设备的数据链路层ID建立第一用户设备与第二用户设备连接并为第二用户设备提供中继服务,这样第一用户设备只能为特定的服务对象的群组提供中继服务,提高了中继服务功能的安全性。
通过以上的实施方式的描述,所属领域的技术人员可以清楚地了解到本发明可以用硬件实现,或固件实现,或它们的组合方式来实现。当使用软件实现时,可以将上述功能存储在计算机可读介质中或作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是计算机能够存取的任何可用介质。以此为例但不限于:计算机可读介质可以 包括RAM(Randam Access Memory,随机存储器)、ROM(Read Only Memory,只读内存)、EEPROM(Electrically Erasable Programmable Read Only Memary,电可擦可编程只读存储器)、CD-ROM(Campact Disc Read Only Memory,即只读光盘)或其他光盘存储、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质。此外。任何连接可以适当的成为计算机可读介质。例如,如果软件是使用同轴电缆、光纤光缆、双绞线、DSL(Digital Subscriber Line,数字用户专线)或者诸如红外线、无线电和微波之类的无线技术从网站、服务器或者其他远程源传输的,那么同轴电缆、光纤光缆、双绞线、DSL或者诸如红外线、无线和微波之类的无线技术包括在所属介质的定影中。如本发明所使用的,盘和碟包括CD(Compact Disc,压缩光碟)、激光碟、光碟、DVD碟(Digital Versatile Disc,数字通用光)、软盘和蓝光光碟,其中盘通常磁性的复制数据,而碟则用激光来光学的复制数据。上面的组合也应当包括在计算机可读介质的保护范围之内。
以上所述,仅为本发明的具体实施方式,但本发明的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本发明揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本发明的保护范围之内。因此,本发明的保护范围应所述以权利要求的保护范围为准。

Claims (21)

  1. 一种建立连接的方法,其特征在于,包括:
    第一用户设备接收网络设备发送的服务对象群组标识,所述服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
    所述第一用户设备接收第二用户设备发送的发现信息,所述发现信息包括第二群组的标识及中继服务请求,所述中继服务请求用于请求提供中继服务,所述第二群组的标识用于指示所述第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
    若所述第二群组的标识包含于所述服务对象群组标识,则所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID,根据所述第二用户设备的数据链路层ID,建立所述第一用户设备与所述第二用户设备之间的连接。
  2. 根据权利要求1所述的方法,其特征在于,
    所述第一用户设备接收网络设备发送的服务对象群组标识之前,还包括:
    所述第一用户设备向所述网络设备发送业务授权请求;
    所述第一用户设备接收网络设备发送的服务对象群组标识,包括:
    所述第一用户设备接收所述网络设备发送的业务授权响应,所述业务授权响应携带所述服务对象群组标识。
  3. 根据权利要求1所述的方法,其特征在于,所述第一用户设备接收网络设备发送的服务对象群组标识之前,还包括:
    所述第一用户设备接收所述网络设备发送的服务对象的群组名称,所述服务对象的群组名称与所述服务对象群组标识对应;
    所述第一用户设备向所述网络设备发送发现请求信息,所述发现请求信息包括所述服务对象的群组名称;
    所述第一用户设备接收网络设备发送的服务对象群组标识,包括:
    所述第一用户设备接收所述网络设备发送的发现确认信息,所述发现确认信息包括所述服务对象群组标识。
  4. 根据权利要求1所述的方法,其特征在于,
    所述发现信息还包括所述第二用户设备的数据链路层ID;
    所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID,包括:
    所述第一用户设备从所述发现信息中获取所述第二用户设备的数据链路层ID。
  5. 根据权利要求1所述的方法,其特征在于,
    所述发现信息还包括所述第二用户设备的名称,所述第二用户设备的名称用于识别所述第二用户设备;
    所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID之前,还包括:
    所述第一用户设备向所述网络设备发送第一验证信息,所述第一验证信息携带所述所述第二用户设备的名称;
    所述第一用户设备获取所述第二用户设备的数据链路层身份标识ID,包括:
    所述第一用户设备接收所述网络设备发送的第一验证确认信息,所述第一验证确认信息携带所述第二用户设备的数据链路层ID。
  6. 一种建立连接的方法,其特征在于,包括:
    网络设备接收第一用户设备发送的第一验证信息,所述第一验证信息包括第二群组的标识,所述第二群组的标识用于指示第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
    所述网络设备获取所述第一用户设备的服务对象群组标识,所述第一用户设备的服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
    若所述第二群组的标识包含于所述第一用户设备的服务对象群组标识,则所述网络设备向所述第一用户设备发送第一验证确认信息,所述第一验证确认信息用于指示所述第一用户设备为所述第二用 户设备提供中继服务。
  7. 根据权利要求6所述的方法,其特征在于,所述方法还包括:
    所述网络设备向所述第一用户设备发送所述第二用户设备的数据链路层身份标识ID,所述第二用户设备的数据链路层ID用于所述第一用户设备与所述第二用户设备建立连接。
  8. 一种第一用户设备,其特征在于,包括:
    接收单元,用于接收网络设备发送的服务对象群组标识,所述服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
    所述接收单元,还用于接收第二用户设备发送的发现信息,所述发现信息包括第二群组的标识及中继服务请求,所述中继服务请求用于请求提供中继服务,所述第二群组的标识用于指示所述第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
    连接单元,用于当所述接收单元接收的所述第二群组的标识包含于所述服务对象群组标识时,获取所述第二用户设备的数据链路层身份标识ID,根据所述第二用户设备的数据链路层ID,建立所述第一用户设备与所述第二用户设备之间的连接。
  9. 根据权利要求8所述的设备,其特征在于,
    所述第一用户设备还包括发送单元,用于向所述网络设备发送业务授权请求;
    所述接收单元,还用于接收所述网络设备发送的业务授权响应,所述业务授权响应携带所述服务对象群组标识。
  10. 根据权利要求8所述的设备,其特征在于,
    所述接收单元,还用于接收所述网络设备发送的服务对象的群组名称,所述服务对象的群组名称与所述服务对象群组标识对应;
    所述第一用户设备还包括发送单元,用于向所述网络设备发送发现请求信息,所述发现请求信息包括所述服务对象的群组名称;
    所述接收单元,还用于接收所述网络设备发送的发现确认信息,所述发现确认信息包括所述服务对象群组标识。
  11. 根据权利要求8所述的设备,其特征在于,
    所述发现信息还包括所述第二用户设备的数据链路层ID;
    所述连接单元,具体用于从所述发现信息中获取所述第二用户设备的数据链路层ID。
  12. 根据权利要求8所述的设备,其特征在于,
    所述发现信息还包括所述第二用户设备的名称,所述第二用户设备的名称用于识别所述第二用户设备;
    所述第一用户设备还包括发送单元,用于向所述网络设备发送第一验证信息,所述第一验证信息携带所述所述第二用户设备的名称;
    所述接收单元,还用于接收所述网络设备发送的第一验证确认信息,所述第一验证确认信息携带所述第二用户设备的数据链路层ID。
  13. 一种网络设备,其特征在于,包括:
    接收单元,用于接收第一用户设备发送的第一验证信息,所述第一验证信息包括第二群组的标识,所述第二群组的标识用于指示第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
    获取单元,用于获取所述第一用户设备的服务对象群组标识,所述第一用户设备的服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
    发送单元,用于当所述接收单元接收的所述第二群组的标识包含于所述获取单元获取的所述服务对象群组标识时,向所述第一用户设备发送第一验证确认信息,所述第一验证确认信息用于指示所述第一用户设备为所述第二用户设备提供中继服务。
  14. 根据权利要求13所述的设备,其特征在于,
    所述发送单元,还用于向所述第一用户设备发送所述第二用户设备的数据链路层身份标识ID,所述第二用户设备的数据链路层ID用于所述第一用户设备与所述第二用户设备建立连接。
  15. 一种第一用户设备,其特征在于,包括处理器、存储器、总线及接收器,所述处理器、所述存储器及所述接收器通过所述总线相互连接;
    其中,所述接收器,用于接收网络设备发送的服务对象群组标识,所述服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
    所述接收器,还用于接收第二用户设备发送的发现信息,所述发现信息包括第二群组的标识及中继服务请求,所述中继服务请求用于请求提供中继服务,所述第二群组的标识用于指示所述第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
    所述处理器,用于当所述接收器接收的所述第二群组的标识包含于所述服务对象群组标识时,获取所述第二用户设备的数据链路层身份标识ID,根据所述第二用户设备的数据链路层ID,建立所述第一用户设备与所述第二用户设备之间的连接。
  16. 根据权利要求15所述的设备,其特征在于,
    所述第一用户设备还包括发送器,用于向所述网络设备发送业务授权请求;
    所述接收器,还用于接收所述网络设备发送的业务授权响应,所述业务授权响应携带所述服务对象群组标识。
  17. 根据权利要求15所述的设备,其特征在于,
    所述接收器,还用于接收所述网络设备发送的服务对象的群组名称,所述服务对象的群组名称与所述服务对象群组标识对应;
    所述第一用户设备还包括发送器,用于向所述网络设备发送发现请求信息,所述发现请求信息包括所述服务对象的群组名称;
    所述接收器,还用于接收所述网络设备发送的发现确认信息,所述发现确认信息包括所述服务对象群组标识。
  18. 根据权利要求15所述的设备,其特征在于,
    所述发现信息还包括所述第二用户设备的数据链路层ID;
    所述处理器,具体用于从所述发现信息中获取所述第二用户设备的数据链路层ID。
  19. 根据权利要求15所述的设备,其特征在于,
    所述发现信息还包括所述第二用户设备的名称,所述第二用户设 备的名称用于识别所述第二用户设备;
    所述第一用户设备还包括发送器,用于向所述网络设备发送第一验证信息,所述第一验证信息携带所述所述第二用户设备的名称;
    所述接收器,还用于接收所述网络设备发送的第一验证确认信息,所述第一验证确认信息携带所述第二用户设备的数据链路层ID。
  20. 一种网络设备,其特征在于,包括处理器、存储器、总线、接收器及所述发送器,所述处理器、所述存储器、所述接收器及所述发送器通过所述总线相互连接;
    接收器,用于接收第一用户设备发送的第一验证信息,所述第一验证信息包括第二群组的标识,所述第二群组的标识用于指示第二用户设备所属的群组或所述第二用户设备的用户所属的群组;
    处理器,用于获取所述第一用户设备的服务对象群组标识,所述第一用户设备的服务对象群组标识用于指示所述第一用户设备提供中继服务的服务对象的群组;
    发送器,用于当所述接收器接收的所述第二群组的标识包含于所述处理器获取的所述服务对象群组标识时,向所述第一用户设备发送第一验证确认信息,所述第一验证确认信息用于指示所述第一用户设备为所述第二用户设备提供中继服务。
  21. 根据权利要求20所述的设备,其特征在于,
    所述发送器,还用于向所述第一用户设备发送所述第二用户设备的数据链路层身份标识ID,所述第二用户设备的数据链路层ID用于所述第一用户设备与所述第二用户设备建立连接。
PCT/CN2014/090585 2014-11-07 2014-11-07 一种建立连接的方法、设备及系统 WO2016070410A1 (zh)

Priority Applications (10)

Application Number Priority Date Filing Date Title
RU2017119025A RU2672570C1 (ru) 2014-11-07 2014-11-07 Способ, устройство и система установления соединения
KR1020177013610A KR101929868B1 (ko) 2014-11-07 2014-11-07 연결 확립 방법, 장치, 및 시스템
CN202010067633.XA CN111277963B (zh) 2014-11-07 2014-11-07 一种建立连接的方法、设备及系统
BR112017008928-9A BR112017008928B1 (pt) 2014-11-07 Método, dispositivo e sistema de estabelecimento de conexão
PCT/CN2014/090585 WO2016070410A1 (zh) 2014-11-07 2014-11-07 一种建立连接的方法、设备及系统
AU2014410591A AU2014410591B2 (en) 2014-11-07 2014-11-07 Connection establishment method, device, and system
EP14905513.9A EP3200486B1 (en) 2014-11-07 2014-11-07 Connection establishment method, device, and system
CN201480079580.6A CN106416321B (zh) 2014-11-07 2014-11-07 一种建立连接的方法、设备及系统
US15/588,496 US10542433B2 (en) 2014-11-07 2017-05-05 Connection establishment method, device, and system
US16/697,128 US11096051B2 (en) 2014-11-07 2019-11-26 Connection establishment method, device, and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2014/090585 WO2016070410A1 (zh) 2014-11-07 2014-11-07 一种建立连接的方法、设备及系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/588,496 Continuation US10542433B2 (en) 2014-11-07 2017-05-05 Connection establishment method, device, and system

Publications (1)

Publication Number Publication Date
WO2016070410A1 true WO2016070410A1 (zh) 2016-05-12

Family

ID=55908425

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/090585 WO2016070410A1 (zh) 2014-11-07 2014-11-07 一种建立连接的方法、设备及系统

Country Status (7)

Country Link
US (2) US10542433B2 (zh)
EP (1) EP3200486B1 (zh)
KR (1) KR101929868B1 (zh)
CN (2) CN106416321B (zh)
AU (1) AU2014410591B2 (zh)
RU (1) RU2672570C1 (zh)
WO (1) WO2016070410A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3468247A4 (en) * 2016-06-28 2019-05-29 Huawei Technologies Co., Ltd. DEVICE AND METHOD FOR TRANSMITTING DATA
CN112752239A (zh) * 2019-10-29 2021-05-04 大唐移动通信设备有限公司 一种直连通信方法及设备
CN113615314A (zh) * 2019-08-16 2021-11-05 Oppo广东移动通信有限公司 一种中继选择方法及装置、终端设备

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105284166B (zh) * 2013-06-28 2021-03-23 苹果公司 针对对等应用的网络辅助的设备对设备发现
KR101929868B1 (ko) * 2014-11-07 2018-12-17 후아웨이 테크놀러지 컴퍼니 리미티드 연결 확립 방법, 장치, 및 시스템
WO2016183748A1 (zh) * 2015-05-15 2016-11-24 华为技术有限公司 一种发现方法及设备
AU2016415048B2 (en) * 2016-07-15 2020-05-07 Huawei Technologies Co., Ltd. Method for applying for media transmission permission, and method and apparatus for canceling media transmission permission
EP4075918A4 (en) * 2020-01-06 2022-12-28 Huawei Technologies Co., Ltd. METHOD AND COMMUNICATION DEVICE
WO2022021198A1 (zh) * 2020-07-30 2022-02-03 华为技术有限公司 通信方法及其装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102469015A (zh) * 2010-11-17 2012-05-23 中兴通讯股份有限公司 实现中继选择的方法及装置、系统
CN102811497A (zh) * 2011-06-03 2012-12-05 中国移动通信集团公司 一种接入网络的方法、终端及系统
WO2014166440A1 (zh) * 2013-07-09 2014-10-16 中兴通讯股份有限公司 集群中继方法、装置、系统及存储介质

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101140150B1 (ko) * 2005-08-17 2012-05-02 에스케이 텔레콤주식회사 그룹 id를 이용하여 다수의 이동통신 단말기에 데이터전송을 제공하는 서버, 시스템 및 방법
EP2168366A4 (en) * 2007-07-09 2012-01-25 Nttm Name To Telephone Mapping Ltd METHOD FOR INITIATING A CONNECTION BETWEEN COMMUNICATION DEVICES OF AT LEAST TWO PARTS
US8116771B2 (en) * 2007-11-20 2012-02-14 Futurewei Technologies, Inc. Method and apparatus for efficient paging group updates in a wireless communication system including mobile relay stations
EP2071809A1 (en) 2007-12-13 2009-06-17 Alcatel Lucent Method of establishing a connection in a peer-to-peer network with network address translation (NAT)
CN101640887B (zh) * 2008-07-29 2012-10-03 上海华为技术有限公司 鉴权方法、通信装置和通信系统
CN101668325B (zh) * 2008-09-03 2012-03-28 中国移动通信集团上海有限公司 一种准入控制方法、设备及系统
WO2011140138A1 (en) * 2010-05-03 2011-11-10 Qualcomm Incorporated System, apparatus and method for downlink and uplink grant design in wireless communication systems
WO2012018130A1 (en) * 2010-08-05 2012-02-09 Nec Corporation Group security in machine-type communication
CN101931955B (zh) * 2010-09-03 2015-01-28 中兴通讯股份有限公司 认证方法、装置及系统
CN102724102B (zh) * 2011-03-29 2015-04-08 华为技术有限公司 与网管系统建立连接的方法、设备及通信系统
CN104902443B (zh) * 2014-03-05 2018-10-30 华为终端有限公司 一种通信的方法和设备
KR101929868B1 (ko) * 2014-11-07 2018-12-17 후아웨이 테크놀러지 컴퍼니 리미티드 연결 확립 방법, 장치, 및 시스템
US20180103417A1 (en) * 2015-05-18 2018-04-12 Samsung Electronics Co., Ltd. Method and apparatus for performing proximity service communications in wireless communication system

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102469015A (zh) * 2010-11-17 2012-05-23 中兴通讯股份有限公司 实现中继选择的方法及装置、系统
CN102811497A (zh) * 2011-06-03 2012-12-05 中国移动通信集团公司 一种接入网络的方法、终端及系统
WO2014166440A1 (zh) * 2013-07-09 2014-10-16 中兴通讯股份有限公司 集群中继方法、装置、系统及存储介质

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3468247A4 (en) * 2016-06-28 2019-05-29 Huawei Technologies Co., Ltd. DEVICE AND METHOD FOR TRANSMITTING DATA
CN113615314A (zh) * 2019-08-16 2021-11-05 Oppo广东移动通信有限公司 一种中继选择方法及装置、终端设备
CN112752239A (zh) * 2019-10-29 2021-05-04 大唐移动通信设备有限公司 一种直连通信方法及设备
WO2021083156A1 (zh) * 2019-10-29 2021-05-06 大唐移动通信设备有限公司 一种直连通信方法及设备
CN112752239B (zh) * 2019-10-29 2022-05-27 大唐移动通信设备有限公司 一种直连通信方法及设备

Also Published As

Publication number Publication date
KR101929868B1 (ko) 2018-12-17
AU2014410591A1 (en) 2017-05-25
CN106416321B (zh) 2020-02-14
BR112017008928A2 (zh) 2018-01-02
CN111277963A (zh) 2020-06-12
EP3200486B1 (en) 2021-01-13
CN106416321A (zh) 2017-02-15
CN111277963B (zh) 2022-05-13
EP3200486A4 (en) 2017-10-04
US20200100111A1 (en) 2020-03-26
KR20170071588A (ko) 2017-06-23
US20170245149A1 (en) 2017-08-24
AU2014410591B2 (en) 2018-07-12
RU2672570C1 (ru) 2018-11-16
EP3200486A1 (en) 2017-08-02
US11096051B2 (en) 2021-08-17
US10542433B2 (en) 2020-01-21

Similar Documents

Publication Publication Date Title
WO2016070410A1 (zh) 一种建立连接的方法、设备及系统
CN110800331B (zh) 网络验证方法、相关设备及系统
US11233817B2 (en) Methods and apparatus for end device discovering another end device
CA2972455C (en) Method and apparatus for providing access to local services and applications to multi-agency responders
WO2016054888A1 (zh) 一种创建订阅资源的方法和装置
WO2016188224A1 (zh) 一种业务授权方法、装置、系统及路由器
US8875270B2 (en) ID authentication system, ID authentication method, and non-transitory computer readable medium storing ID authentication program
WO2019056971A1 (zh) 一种鉴权方法及设备
JP2023080266A (ja) モビリティ管理ノード、ユーザ機器、及びこれらの方法
CN105357224A (zh) 一种智能家居网关注册、移除方法及系统
US9781753B2 (en) Proximity map request method, server and network entity using the same, proximity request validating method, and server and network entity using the same
JP2009118267A (ja) 通信ネットワークシステム、通信ネットワーク制御方法、通信制御装置、通信制御プログラム、サービス制御装置およびサービス制御プログラム
WO2015139442A1 (zh) 本地网络访问的控制方法及装置、计算机存储介质
CN113784277A (zh) 用于存储位置信息的系统、方法和装置
RU2568922C2 (ru) Удаленная проверка атрибутов в сети связи
CN114338062B (zh) 所有权转移方法和装置、物联网平台及可读存储介质
WO2011047587A1 (zh) 闭合用户组成员的管理方法及装置
CN116963057A (zh) 控制跨域设备的方法、控制终端、服务器及系统
CN111542055A (zh) 信息交互方法、装置、设备及计算机可读存储介质
CN117098124A (zh) 一种设备管理方法、系统、电子设备和存储介质
EP3065369A1 (en) Method and system for automatically authorizing communications based on location
BR112017008928B1 (pt) Método, dispositivo e sistema de estabelecimento de conexão

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14905513

Country of ref document: EP

Kind code of ref document: A1

REEP Request for entry into the european phase

Ref document number: 2014905513

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 20177013610

Country of ref document: KR

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 2014410591

Country of ref document: AU

Date of ref document: 20141107

Kind code of ref document: A

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112017008928

Country of ref document: BR

ENP Entry into the national phase

Ref document number: 2017119025

Country of ref document: RU

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 112017008928

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20170427