WO2016169003A1 - 接入点名称授权的方法、装置及系统 - Google Patents
接入点名称授权的方法、装置及系统 Download PDFInfo
- Publication number
- WO2016169003A1 WO2016169003A1 PCT/CN2015/077177 CN2015077177W WO2016169003A1 WO 2016169003 A1 WO2016169003 A1 WO 2016169003A1 CN 2015077177 W CN2015077177 W CN 2015077177W WO 2016169003 A1 WO2016169003 A1 WO 2016169003A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- apn
- access network
- authorized
- network type
- subscription data
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 80
- 238000013475 authorization Methods 0.000 claims abstract description 151
- 238000010586 diagram Methods 0.000 description 21
- 230000000694 effects Effects 0.000 description 10
- 230000003993 interaction Effects 0.000 description 3
- 101100113067 Rattus norvegicus Cfi gene Proteins 0.000 description 1
- 238000004891 communication Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 238000012216 screening Methods 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/107—Network architectures or network communication protocols for network security for controlling access to devices or network resources wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
- H04W12/084—Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/17—Selecting a data network PoA [Point of Attachment]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0892—Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/164—Implementing security features at a particular protocol layer at the network layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/14—Session management
- H04L67/143—Termination or inactivation of sessions, e.g. event-controlled end of session
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/16—Discovering, processing access restriction or access information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W56/00—Synchronisation arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/26—Network addressing or numbering for mobility support
- H04W8/265—Network addressing or numbering for mobility support for initial activation of new user
Definitions
- the embodiments of the present invention relate to communication technologies, and in particular, to a method, an apparatus, and a system for authorizing an Access Point Name (APN).
- API Access Point Name
- Non 3rd Generation Partnership Project Non 3rd Generation Partnership Project
- access network type can be CDMA (Code Division Multiple Access) 2000, Worldwide Interoperability for Microwave Access (WiMAX) ), Wireless Local Area Network (WLAN), etc.
- CDMA Code Division Multiple Access 2000
- WiMAX Worldwide Interoperability for Microwave Access
- WLAN Wireless Local Area Network
- the Non 3GPP access network is further divided into a trusted Non 3GPP access network and an untrusted Non 3GPP access network.
- a user equipment UE, User Equipment
- a Non 3GPP access network for example, an untrusted Non 3GPP access network
- an untrusted Non 3GPP access gateway eg, an evolved packet data gateway (ePDG, Evolved Packet
- the data gateway sends an authentication and authorization request to the AAA (Authentication, Authorization, and Accounting) server (wherein the authentication and authorization request may include the APN requested by the UE, if authentication and authorization)
- the AAA server obtains the subscription data of the UE from the Home Subscriber System (HSS) (the subscription data includes the APN allowed by the UE)
- HSS Home Subscriber System
- the AAA server determines whether the APN requested by the UE is authorized according to the subscription data of the UE and the APN that the
- the embodiment of the invention provides a method, a device and a system for authorizing an access point name, which are used to solve the problem that the operator cannot authorize the UE when performing the APN authorization judgment in the prior art.
- APN has reasonable control issues.
- an embodiment of the present invention provides a method for APN authorization, including:
- the network device determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
- the network device is configured according to an access network type currently accessed by the UE and an authorized access network type corresponding to the target APN of the UE.
- Information, determining whether the target APN of the UE is authorized including:
- the network device is determined according to the information of the authorized access network type corresponding to the target APN of the UE. It is determined that the target APN of the UE is not authorized.
- the network device is configured according to an access network type that the UE is currently accessing, and
- the information of the authorized access network type corresponding to the target APN of the UE, before determining whether the target APN of the UE is authorized further includes:
- the network device determines that the subscription data of the UE includes a target APN of the UE.
- the method further includes:
- the network device sends an authorization failure reason to the UE, and the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
- the network device acquires a target APN corresponding to the UE Information on authorized access network types, including:
- the network device receives the subscription data of the UE sent by the user home system HSS, and the subscription data of the UE includes information of an authorized access network type corresponding to the target APN of the UE.
- the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE. Ways include:
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
- the network device is an AAA server, or is Non 3GPP Access gateway.
- the network device receives an Before the UE's subscription data, it also includes:
- the network device sends an authentication failure reason of the UE to the UE.
- an embodiment of the present invention provides a method for APN authorization, including:
- the HSS sends the subscription data of the user equipment UE to the network device, where the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE, so that the network device corresponds to the target APN of the UE.
- the authorized access network type information and the access network type currently accessed by the UE determine whether the target APN of the UE is authorized.
- the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
- an embodiment of the present invention provides a method for APN authorization, including:
- the HSS determines an access network type currently accessed by the user equipment UE
- the HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
- the subscription data of the UE includes at least one APN and the foregoing.
- the updated subscription data includes information of the authorized APN of the UE under the currently accessed access network type;
- the HSS sends the updated subscription data to a network device.
- the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the at least one APN includes:
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
- the APN corresponding to the APN configuration parameter is authorized or not authorized.
- an embodiment of the present invention provides a method for APN authorization, including:
- the network device receives the updated subscription data sent by the user home system HSS;
- the updated subscription data includes information of the authorized APN of the user equipment UE under the currently accessed access network type;
- an embodiment of the present invention provides a method for APN authorization, including:
- the UE Transmitting, by the UE, a first connection request message to a gateway of an access network that the UE is currently accessing; the first connection request message includes an APN requested by the UE, and the APN requested by the UE is different from the target APN .
- the method further includes:
- an authentication failure reason of the UE that is sent by the network device includes: the public land mobile network VPLMN that the access network type does not allow or access is not allowed;
- the UE sends a second connection request message to a gateway different from a gateway of the access network currently accessed by the UE.
- the embodiment of the present invention provides an APN authorized device, where the device is a network device, and the device includes:
- a determining module configured to determine a target APN of the UE and an access network type currently accessed by the UE
- An acquiring module configured to acquire information about an authorized access network type corresponding to the target APN of the UE
- the determining module is further configured to determine whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
- the processing module is specifically configured to:
- Target APN is authorized
- Determining the UE if it is determined that the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, according to the information of the authorized access network type corresponding to the target APN of the UE.
- the target APN is not authorized.
- the determining module is further configured to determine that the subscription data of the UE includes the UE Target APN.
- the device further includes: a first sending module
- the determining module determines that the target APN of the UE is not authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE
- the first And a sending module configured to send an authorization failure reason to the UE, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
- the acquiring module is specifically configured to:
- the subscription data of the UE sent by the user home system HSS is received, and the subscription data of the UE includes information of an authorized access network type corresponding to the target APN of the UE.
- the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE. Ways include:
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
- the network device is an AAA server, or is a Non 3GPP Access gateway.
- the device further includes a second sending module
- the acquiring module is further configured to receive an authentication response message sent by the HSS, where the authentication response message includes an authentication failure reason of the UE;
- the second sending module is configured to send an authentication failure reason of the UE to the UE.
- the embodiment of the present invention provides an APN authorized device, where the device is an HSS, and the device includes:
- a sending module configured to send the subscription data of the user equipment UE to the network device, where the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE, so that And determining, by the network device, whether the target APN of the UE is authorized according to the authorized access network type information corresponding to the target APN of the UE and the access network type currently accessed by the UE.
- the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
- an embodiment of the present invention provides an apparatus for authorizing an APN, where the apparatus is an HSS, and the apparatus includes:
- a determining module configured to determine an access network type currently accessed by the user equipment UE
- an update module configured to update the subscription data of the UE according to the type of the access network that the UE is currently accessing, to obtain the updated subscription data, where the subscription data of the UE includes at least one APN and Information of the authorized access network type corresponding to the at least one APN; the updated subscription data includes information of the authorized APN of the UE under the currently accessed access network type;
- a sending module configured to send the updated subscription data to the network device.
- the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the at least one APN includes:
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
- the APN corresponding to the APN configuration parameter is authorized or not authorized.
- a ninth aspect the embodiment of the present invention provides an APN authorized device, where the device is a network device, and the device includes:
- a receiving module configured to receive the updated subscription data sent by the user home system HSS;
- the updated subscription data includes information of the authorized APN of the user equipment UE in the currently accessed access network type;
- a determining module configured to determine, according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type, whether the target APN of the UE is authorized.
- the embodiment of the present invention provides an APN authorized device, where the device is a UE, and the device includes:
- a receiving module configured to receive an authorization failure reason sent by the network device, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE;
- a sending module configured to send a first connection request message to a gateway of an access network that the UE is currently accessing; the first connection request message includes an APN requested by the UE, and the APN requested by the UE and the target APN is different.
- the receiving module is further configured to receive, by the network device, an authentication failure reason of the UE, where the authentication failure cause includes : Public land mobile network VPLMN not allowed or accessed by the access network type is not allowed;
- the sending module is further configured to send a second connection request message to a gateway different from a gateway of the access network currently accessed by the UE.
- An eleventh aspect the embodiment of the present invention provides a system for granting an APN, comprising: the network device, the seventh aspect, or the seventh aspect of any one of the first to seventh aspects of the sixth aspect or the sixth aspect The first described HSS and UE.
- the UE in conjunction with the eleventh aspect, in a first possible implementation manner of the eleventh aspect, is as described in the first aspect of the tenth aspect or the tenth aspect.
- the embodiment of the present invention provides a system for granting an APN, comprising: the HSS according to the first aspect of the eighth aspect, or the network device and the UE according to the ninth aspect.
- the UE is as described in the eighth aspect or the first aspect of the eighth aspect.
- the present invention provides a method, an apparatus, and a system for granting an access point name, by using the network device according to an access network type currently accessed by the UE and an authorized connection corresponding to the target APN of the UE. Determining whether the target APN of the UE is authorized, and determining that the UE is currently connected according to the authorized access network type information corresponding to the target APN of the UE when performing the APN authorization determination.
- the network device can simultaneously consider the target APN of the UE and the access network type currently accessed by the UE when performing the APN authorization determination;
- the APN that the UE can access in the access network type that is currently accessed by the UE can be controlled according to the access network type that the UE is currently accessing.
- the operator cannot allow the UE to be allowed. The problem of reasonable control of the accessed APN.
- FIG. 1 is a schematic diagram of an application scenario of an APN authorization method according to the present invention.
- FIG. 2 is a schematic diagram of another application scenario of a method for APN authorization according to the present invention.
- Embodiment 3 is a flowchart of Embodiment 1 of a method for APN authorization according to the present invention
- Embodiment 4 is a flowchart of Embodiment 2 of a method for APN authorization according to the present invention.
- FIG. 5 is a flowchart of Embodiment 3 of a method for granting an APN according to the present invention.
- Embodiment 4 is a flowchart of Embodiment 4 of a method for granting an APN according to the present invention
- Embodiment 7 is a flowchart of Embodiment 5 of a method for granting an APN according to the present invention.
- Embodiment 8 is a flowchart of Embodiment 6 of a method for granting an APN according to the present invention.
- Embodiment 9 is a schematic structural diagram of Embodiment 1 of an APN authorized device according to the present invention.
- Embodiment 2 is a schematic structural diagram of Embodiment 2 of an APN authorized device according to the present invention.
- FIG. 11 is a schematic structural diagram of Embodiment 3 of an apparatus for granting an APN according to the present invention.
- Embodiment 4 is a schematic structural diagram of Embodiment 4 of an apparatus for granting an APN according to the present invention.
- FIG. 13 is a schematic structural diagram of Embodiment 5 of an apparatus for granting an APN according to the present invention.
- Embodiment 6 is a schematic structural diagram of Embodiment 6 of an APN authorized device according to the present invention.
- Embodiment 7 is a schematic structural diagram of Embodiment 7 of an APN authorized device according to the present invention.
- FIG. 16 is a schematic structural diagram of Embodiment 8 of an apparatus for granting an APN according to the present invention.
- FIG. 1 is a schematic diagram of an application scenario of an APN authorization method according to the present invention
- the application scenario includes: a UE, an ePDG, an AAA server, and an HSS.
- the ePDG sends an authentication and authorization request message to the AAA server (where the authentication and authorization request message may include the APN requested by the UE to be accessed; if not included, the ePDG may be used.
- the default APN in the subscription data of the UE the AAA server obtains the subscription data of the UE from the HSS, and the subscription data includes the APN allowed by the UE; when the subscription data includes the target APN of the UE (when the authentication is performed)
- the APN is included in the authorization request message, the APN is used as the target APN of the UE; when the APN is not included, the default APN in the subscription data is used as the target APN of the UE), the AAA server determines that the target APN of the UE is authorized; Otherwise, the AAA server determines that the target APN of the UE is not authorized.
- the subscription data of the UE includes only the APN that the UE is allowed to access, the relationship between the APN that the UE is allowed to access and the access network type is not reflected; therefore, when the AAA server performs the APN authorization judgment, The operator cannot properly control the APN that the UE is allowed to access.
- the application scenario includes: a UE, a trusted WLAN access network (TWAN), an AAA server, and an HSS.
- TWAN trusted WLAN access network
- AAA server AAA server
- HSS HSS
- the TWAN obtains the subscription data of the UE from the HSS, where the subscription data includes the APN allowed by the UE; when the subscription data includes the target APN of the UE, the TWAN It is determined that the target APN of the UE is authorized; otherwise, the TWAN determines that the target APN of the UE is not authorized.
- the subscription data of the UE includes only the APN that the UE is allowed to access, the relationship between the APN that the UE is allowed to access and the access network type is not reflected; therefore, when the TWAN performs the APN authorization judgment, The operator cannot properly control the APN that the UE is allowed to access.
- FIG. 1 and FIG. 2 are only the method of the present invention in the non-3GPP access network type.
- Schematic diagram of untrusted WLAN and trusted WALN; the method of the present invention can be applied to any non-3GPP access network type, such as CDMA2000, WiMAX, and the like.
- the non-3GPP access network type is CDMA2000
- the corresponding application scenario is to replace the TWAN network element shown in FIG. 2 with a High Rate Packet Data (HRPD) service gateway (HS-GW, HRPD Serving Gateway).
- HRPD High Rate Packet Data
- HS-GW High Rate Packet Data
- HRPD Serving Gateway HRPD Serving Gateway
- the Non 3GPP access gateway may include an ePDG, a TWAN, an HS-GW, and the like.
- FIG. 3 is a flowchart of Embodiment 1 of an APN authorization method according to the present invention. As shown in FIG. 3, the method in this embodiment may include:
- Step 301 The network device determines a target APN of the user equipment UE and an access network type currently accessed by the UE.
- the network device may be an AAA server or a Non 3GPP access gateway.
- Step 302 The network device acquires information about an authorized access network type corresponding to the target APN of the UE.
- the authorized access network type is an access network type that allows the UE to access.
- Step 303 The network device determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
- step 303 can be specifically:
- the network device is determined according to the information of the authorized access network type corresponding to the target APN of the UE. It is determined that the target APN of the UE is not authorized.
- the subscription data of the UE includes the APN that the UE is allowed to access; when the subscription data of the UE includes the target APN of the UE, it is determined that the target APN of the UE is authorized; otherwise, the UE is determined.
- the target APN is not authorized.
- the network device is configured according to an access network type currently accessed by the UE and an authorized access network type corresponding to the target APN of the UE. Information determining whether the target APN of the UE is authorized.
- the subscription data of the UE includes only the APN (that is, the authorized APN) that the UE is allowed to access, but does not reflect the APN between the AP and the access network type that the UE is allowed to access. Relationship; therefore, there is a problem that the operator cannot properly control the APN that the UE is allowed to access when performing the APN authorization judgment.
- the network device determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE;
- the network device can determine, according to the authorized access network type information corresponding to the target APN of the UE, whether the target APN of the UE is authorized by the UE under the currently accessed access network type;
- the network device can simultaneously consider the target APN of the UE and the access network type currently accessed by the UE; thereby enabling the operator to access the UE according to the access network type currently accessed by the UE.
- the access network allows access to the APN to control the access network. In the prior art, when the APN authorization judgment is performed, the operator cannot properly control the APN allowed to be accessed by the UE.
- Embodiment 2 of an APN authorization method according to the present invention. As shown in FIG. 4, the method in this embodiment may include:
- Step 401 The HSS determines an access network type currently accessed by the UE.
- Step 402 The HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
- the subscription data of the UE includes at least one APN and Information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes information of an authorized APN of the UE under the currently accessed access network type;
- the authorized APN is an APN that allows the UE to access.
- Step 403 The HSS sends the updated subscription data to a network device.
- the network device may be an AAA server or a Non 3GPP access gateway.
- the subscription data of the UE stored by the HSS includes the APN that the UE is allowed to access, and the HSS sends the subscription data to the network device, so that the network device performs the APN authorization judgment.
- the HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
- the subscription data of the UE includes at least one APN. And information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes an authorized APN of the UE under the currently accessed access network type Information; the HSS sends the updated subscription data to a network device.
- the HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
- the subscription data of the UE includes at least one of the subscription data.
- the APN and the information about the authorized APN of the UE in the currently accessed access network type determine whether the target APN of the UE is authorized. If the APN authorization judgment is performed in the prior art, the operator cannot Allows access to the APN to be properly controlled.
- FIG. 5 is a flowchart of Embodiment 3 of a method for granting an APN according to the present invention. As shown in FIG. 5, the method in this embodiment may include:
- Step 501 The UE sends an IKE (Internet Key Exchange) authentication request message (IKE_AUTH request message) to the ePDG.
- IKE Internet Key Exchange
- the IKE authentication request message may include the target APN of the UE; or the IKE authentication request message may not include the target APN of the UE.
- the AAA server uses the default APN in the subscription data of the UE as the target APN of the UE.
- the UE may further include the IKE initial request message (IKE_SA_INIT request message) sent by the UE to the ePDG.
- IKE_SA_INIT request message the IKE initial request message sent by the UE to the ePDG.
- Step 502 The ePDG sends an authentication and authorization request (Authentication and authorization request) message to the AAA server.
- the authentication and authorization request message may include an access network type currently accessed by the UE, an identifier of the UE, and a network identifier.
- the identifier of the UE may be a Network Access ID (NAI).
- NAI includes an International Mobile Subscriber Identity (IMSI) of the UE; and the network identifier may be a Visited Public Land Mobile Network (VPLMN) information.
- IMSI International Mobile Subscriber Identity
- VPN Visited Public Land Mobile Network
- the access network type currently accessed by the UE may be acquired by the ePDG, and the ePDG may be a non-3GPP access gateway of the non-trusted WLAN, so the access network type currently accessed by the UE Can be a non-trusted WLAN or WLAN.
- Step 503 The AAA server sends an Authentication Request message to the HSS.
- the authentication request message may include an IMSI of the UE, a network identifier, and an access network type currently accessed by the UE.
- the AAA server may further determine, according to the IMSI of the UE included in the authentication and authorization request message, whether the Context information of the UE is stored in the AAA server (including signing the contract). If the AAA server determines that the context information of the UE has been stored, the authentication request message is not sent to the HSS (ie, step 503 is not executed), and step 509 is directly performed.
- Step 504 The HSS performs an authentication judgment according to the authentication request message.
- the authentication determination may include: 1) determining whether the subscription data of the UE exists; 2) determining whether the UE is allowed to access the current network, that is, whether the access network type currently accessed by the UE is subject to The network type is limited; 3) determining whether the network indicated by the VPLMN allows the UE to access; 4) whether there is Non3GPP subscription data and the like related to the UE.
- Step 505 The HSS returns an Authentication Response message to the AAA server.
- the authentication response message includes an authentication vector of the UE. Otherwise, the authentication response message includes an authentication failure reason of the UE.
- the reason for the failure of the authentication may be “the user does not exist”, and the corresponding authentication failure cause value may be “DIAMETER_ERROR_USER_UNKNOWN”;
- the corresponding authentication failure reason may be “access”.
- Type is not allowed, and the corresponding authentication failure cause value can be "DIAMETER_ERROR_RAT_TYPE_NOT_ALLOWED";
- the corresponding authentication failure reason may be “VPLMN not allowed”, and the corresponding authentication failure cause value may be “DIAMETER_ERROR_ROAMING_NOT_ALLOWED”;
- the corresponding authentication failure reason may be “Non 3GPP subscription data does not exist”, and the corresponding authentication failure cause value may be “DIAMETER_ERROR_USER_NO_NON_3GPP_SUBSCRIPTON”.
- the subscription data may include Non 3GPP subscription data.
- Step 506 When the authentication response message indicates that the UE fails to be authenticated, the AAA server sends the authentication failure reason of the UE to the UE.
- the AAA server may use the Extensible Authentication Protocol (EAP)-Authentication and Key Agreement Protocol (AKA) or EAP-AKA' message to determine the reason for the UE's authentication failure. Sent to the UE.
- EAP Extensible Authentication Protocol
- AKA Access and Key Agreement Protocol
- EAP-AKA or EAP-AKA' message may be sent by the AAA server to the ePDG through an Authentication and Authorization Answer message, and then sent by the ePDG through an IKEv2 message.
- the authentication and authorization response message and IKEv2 contain EAP-AKA or EAP-AKA' messages.
- the reason for the authentication failure of the UE may also be sent by the ePDG to the UE by adding a cause value in the IKEv2 message. That is, the authentication and authorization response message sent by the AAA server to the ePDG carries the authentication failure reason of the UE acquired by the AAA server from the HSS, and then the ePDG authenticates the UE. The reason for the failure is sent to the UE through the new cause value in the IKEv2 message.
- the IKE_AUTH request message is sent to the access gateway different from the ePDG. .
- IKE_AUTH request message may be considered as a connection request message.
- Step 507 When the authentication response message indicates that the UE is successfully authenticated, the AAA server Sending a Non 3GPP IP Access Registration request message to the HSS;
- the Non 3GPP Access Registration Request message includes an IMSI of the UE.
- the AAA server may perform the interaction with the UE according to the authentication vector included in the authentication response.
- the authentication process of the UE may be performed before the sending, by the AAA server, the Non 3GPP access registration request to the HSS.
- Step 508 The HSS returns a Non 3GPP IP Access Registration response (Non 3GPP IP Access Registration response) message to the AAA server.
- the Non 3GPP Access Registration Response message includes subscription data of the UE.
- the HSS searches for the subscription data of the UE according to the IMSI of the UE included in the Non 3GPP access registration request message, and returns a subscription of the UE to the AAA server by using a Non 3GPP access registration response message. data.
- the subscription data of the UE includes information about a target APN of the UE and an authorized access network type corresponding to the target APN of the UE.
- the manner in which the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
- the authorized access network type is an access network type that allows the UE to access;
- the unlicensed access network type is an access network type that does not allow the UE to access.
- the access network type in the APN configuration parameter may include at least one of the following access network types:
- WLAN trusted WLAN
- untrusted WLAN CDMA2000, WiMAX
- UTRAN UMTS Terrestrial Radio Access Network
- GERAN GSM EDGE Radio Access Network
- EUTRAN evolved Evolved Universal Terrestrial Radio Access Network
- the WLAN access network type may further include: a trusted WLAN and an untrusted WLAN.
- the scheme that the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE is as follows:
- the APN configuration parameter (APN-Configuration) corresponding to the target APN of the UE includes an authorized access network type (RAT-Permission); when there is more than one authorized access network type, it is an authorized access network type list.
- RAT-Permission authorized access network type
- APN-Configuration:: ⁇ AVP header:1430 10415>
- the Context-Identifier is a file identifier corresponding to the target APN of the UE; the RAT-Permission may include an authorized access network type corresponding to the APN (ie, the target APN) identified by the Context-Identifier; When the RAT-Permission includes the access network type currently accessed by the UE, it is determined that the target APN of the UE is authorized.
- the "RAT-Permission” may include a "match-all” indication, indicating that the target APN is authorized under any access network type; or, when the configuration parameter does not include “RAT-Permission", it indicates that it is connected at any time.
- the target APN is authorized under the network access type.
- the APN configuration parameter corresponding to the target APN of the UE includes an unlicensed access network type (RAT-Forbidden), and the implementation manner is as follows:
- APN-Configuration:: ⁇ AVP header:1430 10415>
- the Context-Identifier is a file identifier corresponding to the target APN of the UE; the RAT-Forbidden may include an unlicensed connection corresponding to the APN (that is, the target APN of the UE) identified by the Context-Identifier.
- the network access type is determined. When the RAT-Forbidden corresponding to the target APN of the UE does not include the access network type currently accessed by the UE, it is determined that the target APN of the UE is authorized.
- the configuration parameter does not include “RAT-Forbidden”, it indicates that the target APN of the UE is authorized under any access network type.
- the APN configuration parameter corresponding to the target APN of the UE includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate an access network currently accessed by the UE.
- the target APN of the UE is authorized or not authorized, and the implementation manner is as follows:
- APN-Configuration:: ⁇ AVP header:1430 10415>
- the "Context-Identifier” is the file identifier corresponding to the target APN of the UE; the “Vowifi-Permission” is the current access of the APN (that is, the target APN of the UE) identified by the “Context-Identifier”.
- the authorization identifier of the WLAN access network type for example, when the "Vowifi-Permission" corresponding to the target AP of the UE is 1, it indicates that the target APN of the UE is authorized under the currently accessed WLAN access network type.
- the "Vowifi-Permission" corresponding to the target APN of the UE is 0, it indicates that the target APN of the UE is not authorized under the currently accessed WLAN access network type.
- Vowifi-Permission in the scheme 3 is the authorization identifier corresponding to the WLAN.
- the access network type currently accessed by the UE is other access network types, other authorization identifiers may also be corresponding. Its role is similar to “Vowifi-Permission" and will not be described here.
- Step 509 The AAA server determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
- the target APN of the UE is an IP Multimedia Subsystem (IMS)
- the RAT-Permission in the APN-configuration of the IMS includes the WLAN access network type, or RAT- If the WLAN access network type is not included in the forbidden, or the vowifi-Permission indication is allowed under the WLAN access network type, it is determined that the IMS is authorized (that is, the authorization is successful); otherwise, it is determined that the IMS is not authorized (ie, the network The side rejects the UE from using IMS voice service under WLAN access).
- IMS IP Multimedia Subsystem
- the method may further include:
- step 509 is performed to further determine whether the target APN of the UE is authorized under the access network type currently accessed by the UE;
- step 509 is performed to further determine the target APN of the UE. (or wild card APN) Whether it is authorized under the access network type currently accessed by the UE.
- Step 510 The AAA server returns an authentication and authorization answer (Authentication and authorization answer) message to the ePDG.
- the authentication and authorization response message when the target APN of the UE is authorized, includes indication information that the target APN of the UE is allowed; otherwise, the authentication and authorization response message includes an authorization failure reason. the reason.
- the authorization failure reason is used to indicate that the target APN authorization of the UE fails or that the target APN of the UE fails to be authorized under the currently accessed access network type.
- the corresponding authorization failure reason is used to indicate that the target APN authorization of the UE fails; and the subscription data of the UE includes the The target APN of the UE, but the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, and the corresponding authorization failure reason is used to indicate that the target APN of the UE is in the The authorization fails under the access network type currently accessed by the UE.
- Step 511 The ePDG sends an IKEV2 message to the UE according to the authentication and authorization response message.
- the ePDG forwards an authorization failure reason to the UE by using the IKEV2 message.
- the UE after the UE receives the authorization failure reason for indicating that the target APN of the UE fails to be authorized in the access network type currently accessed by the UE, sending, by the UE, another IKE_AUTH to the ePDG.
- the request message, the IKE_AUTH request message includes the APN requested by the UE, and the APN requested by the UE is different from the target APN.
- the Non 3GPP access registration response message is returned to the AAA server by using the HSS, where the Non 3GPP access registration response message includes subscription data of the UE, and the subscription data of the UE includes the UE Information of the authorized access network type corresponding to the target APN; the AAA server determines the UE according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE. Whether the target APN is authorized; the AAA server can simultaneously consider the target APN of the UE and the access network type currently accessed by the UE when performing the APN authorization judgment; and solve the operation in the prior art when performing APN authorization judgment The quotient cannot properly control the APN that the UE is allowed to access.
- FIG. 6 is a flowchart of Embodiment 4 of an APN authorization method according to the present invention. As shown in FIG. 6, the method in this embodiment may include:
- Step 601 The UE sends a connection request message for requesting a connection to the TWAN to the TWAN.
- connection request message is an existing message between the UE and the TWAN, and details are not described herein again.
- Step 602 The TWAN sends an authentication and authorization request message to the AAA server.
- step 602 is similar to step 502, and details are not described herein again.
- Step 603 The AAA server sends an authentication request message to the HSS.
- step 603 is similar to step 503, and details are not described herein again.
- Step 604 The HSS performs an authentication judgment according to the authentication request message.
- step 604 is similar to step 504, and details are not described herein again.
- Step 605 The HSS returns an authentication response message to the AAA server.
- step 605 is similar to step 505, and details are not described herein again.
- Step 606 When the authentication response message indicates that the UE fails to authenticate, the AAA server sends the authentication failure reason of the UE to the UE.
- the AAA server may send the authentication failure reason of the UE to the UE by using an EAP-AKA or EAP-AKA' message.
- the reason for the authentication failure of the UE may also be sent by the TWAN to the UE by adding a cause value in a message between the TWAN and the UE.
- step 606 is similar to step 506, and details are not described herein again.
- Step 607 When the authentication response message indicates that the UE is successfully authenticated, the AAA server sends a Non 3GPP access registration request message to the HSS.
- the AAA server may perform an interaction with the UE according to the authentication vector included in the authentication response.
- the authentication process of the UE may be performed before the sending, by the AAA server, the Non 3GPP access registration request message to the HSS.
- step 607 is similar to step 507, and details are not described herein again.
- Step 608 The HSS returns a Non 3GPP access registration response message to the AAA server.
- step 608 is similar to step 508, and details are not described herein again.
- Step 609 The AAA server returns an authentication and authorization response message to the TWAN.
- the authentication and authorization response message includes subscription data of the UE.
- Step 610 The UE sends a PDN CONNECTIVITY REQUEST message to the TWAN.
- the PDN connection request message may include a target APN of the UE; or may not include the target APN of the UE.
- the TWAN uses the default APN in the subscription data of the UE as the target APN of the UE.
- the UE may perform an authentication interaction with the TWAN, and after the authentication succeeds, send the PDN connection request message to the TWAN. .
- Step 611 The TWAN determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
- the method for determining whether the target APN of the UE is authorized in the step 611 is similar to the method for determining whether the target APN of the UE is authorized in the step 509, and details are not described herein.
- Step 612 The TWAN sends a PDN Connection Acceptance (CONNECTIVITY ACCEPT) message or a PDN CONNECTIVITY REJECT message to the UE.
- CONNECTIVITY ACCEPT PDN Connection Acceptance
- PDN CONNECTIVITY REJECT PDN CONNECTIVITY REJECT
- the message when the TWAN sends a PDN connection reject message to the UE, the message includes an authorization failure reason, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the currently accessed access network type.
- the UE receives the connection that is used to indicate that the target APN of the UE is currently accessed. And sending, by the TWAN, another PDN CONNECTIVITY REQUEST message, where the PDN CONNECTIVITY REQUEST message includes the APN requested by the UE, the APN requested by the UE, and the target APN. different.
- the authentication and authorization response message is returned to the TWAN by the AAA server, where the authentication and authorization response message includes the subscription data of the UE, and the subscription data of the UE includes the target APN of the UE.
- the TWAN determines whether the target APN of the UE is based on the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE Authorized; enables the TWAN to consider both the target APN of the UE and the access network type currently accessed by the UE when performing the APN authorization judgment; and solve the problem that the operator cannot perform the UE when performing the APN authorization judgment in the prior art. Allows access to the APN to be properly controlled.
- FIG. 7 is a flowchart of Embodiment 5 of a method for granting an APN according to the present invention. As shown in FIG. 7, the method in this embodiment may include:
- Step 701 The UE sends an IKE authentication request message to the ePDG.
- step 701 is similar to step 501, and details are not described herein again.
- Step 702 The ePDG sends an authentication and authorization request message to the AAA server.
- step 702 is similar to step 502, and details are not described herein again.
- Step 703 The AAA server sends an authentication request message to the HSS.
- step 703 is similar to step 503, and details are not described herein again.
- Step 704 The HSS performs an authentication judgment according to the authentication request message.
- step 704 is similar to step 504, and details are not described herein again.
- Step 705 The HSS returns an authentication response message to the AAA server.
- step 705 is similar to step 505, and details are not described herein again.
- Step 706 When the authentication response message indicates that the UE fails to be authenticated, the AAA server sends the authentication failure reason of the UE to the UE.
- step 706 is similar to step 506, and details are not described herein again.
- Step 707 When the authentication response message indicates that the UE is successfully authenticated, the AAA server sends a Non 3GPP access registration request message to the HSS.
- step 707 is similar to step 507, and details are not described herein again.
- Step 708 The HSS performs the UE according to an access network type currently accessed by the UE.
- the subscription data is updated to obtain updated subscription data;
- the subscription data of the UE includes at least one APN and information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes an access network type currently accessed by the UE. Information about authorized APNs.
- the HSS may determine the subscription data of the UE according to the IMSI of the UE included in the Non 3GPP Access Registration Request message.
- the manner in which the subscription data of the UE includes information about an authorized access network type corresponding to the at least one APN includes:
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
- the APN corresponding to the APN configuration parameter is authorized or not authorized.
- the scheme that the subscription data of the UE includes information of an authorized access network type corresponding to the at least one APN is as follows:
- the APN configuration parameter (APN-Configuration) corresponding to each APN in the at least one APN includes an authorized access network type (RAT-Permission); when the authorized access network type is more than one, the authorization may be List of access network types.
- RAT-Permission authorized access network type
- the implementation is as follows:
- APN-Configuration:: ⁇ AVP header:1430 10415>
- the Context-Identifier is a file identifier corresponding to an APN; the RAT-Permission may include an authorized access network type corresponding to the APN identified by the Context-Identifier.
- the "RAT-Permission” may include a "match-all” indication, indicating that the APN identified by the “Context-Identifier” is authorized under any access network type; or, when the configuration parameter When “RAT-Permission” is not included, it means that the APN identified by "Context-Identifier” under any access network type is authorized.
- the APN configuration parameter corresponding to each APN of the at least one APN includes an unlicensed access network type (RAT-Forbidden), and the implementation manner is as follows:
- APN-Configuration:: ⁇ AVP header:1430 10415>
- the Context-Identifier is a file identifier corresponding to the APN.
- the RAT-Forbidden may include the unlicensed access network type corresponding to the APN identified by the Context-Identifier.
- RAT-Forbidden When RAT-Forbidden is not included in the configuration parameters, it means that the APN identified by the Context-Identifier is authorized under any access network type.
- the scheme A the APN configuration parameter corresponding to each APN of the at least one APN includes an authorization identifier corresponding to the access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently accessed.
- the APN corresponding to the APN configuration parameter is authorized or not authorized.
- APN-Configuration:: ⁇ AVP header:1430 10415>
- the Context-Identifier is a file identifier corresponding to the APN; the Vowifi-Permission is the corresponding authorization identifier of the currently accessed WLAN access network type of the APN identified by the Context-Identifier.
- schemes A, B, and C are similar to the schemes 1, 2, and 3 in the method embodiment shown in FIG. 5, except that the schemes 1, 2, and 3 are directed to the target APN, and the scheme A is , B, and C are described for each of the at least one APN.
- the updating according to the type of the access network that the UE is currently accessing, the subscription data of the UE, and obtaining the updated subscription data, including:
- the HSS enters the subscription data of the UE according to the access network type currently accessed by the UE. After the screening, the updated subscription data is obtained, so that the updated subscription data only includes the information of the authorized APN of the UE under the currently accessed access network type.
- the HSS may obtain an access network type that the UE currently accesses according to the authentication request sent by the AAA server to the HSS in step 703; or, in step 707, the AAA server sends
- the Non 3GPP access registration request may also include an access network type currently accessed by the UE.
- Step 709 The HSS returns a Non 3GPP access registration response message to the AAA server, where the Non 3GPP access registration response message includes the updated subscription data.
- Step 710 The AAA server determines whether the target APN of the UE is authorized according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type.
- the target APN of the UE belongs to the authorized APN of the access network type currently accessed by the UE, according to the information about the authorized APN of the UE in the currently accessed access network type, Determining, by the AAA server, that the target APN of the UE is authorized; or determining that the target APN of the UE does not belong to the UE according to the information of the authorized APN of the UE in the currently accessed access network type
- the AAA server determines that the target APN of the UE is not authorized.
- the authorized access network type corresponding to the at least one APN in step 708 does not include the access network type currently accessed by the UE, the UE included in the updated subscription data The information of the authorized APN in the currently accessed access network type is empty;
- the updated subscription data is included in the updated subscription data.
- the information about the authorized APN of the UE that is currently accessing the access network type is not empty (including the APN in the at least one APN), but does not include the target APN of the UE;
- the information of the authorized APN of the UE that is included in the currently accessed access network type is not empty, and includes the target APN of the UE.
- Step 711 The AAA server returns an authentication and authorization response message to the ePDG.
- step 711 is similar to step 510, and details are not described herein again.
- Step 712 The ePDG sends an IKEV2 message to the UE according to the authentication and authorization response message.
- step 712 is similar to step 511, and details are not described herein again.
- the Non 3GPP access registration response message is returned to the AAA server by the HSS, where the Non 3GPP access registration response message includes the contracted data after the UE is updated, and the updated subscription data includes the The information of the authorized APN of the UE in the currently accessed access network type; the AAA server determines the location according to the target APN of the UE and the authorized APN information of the UE in the currently accessed access network type. Whether the target APN of the UE is authorized or not; the problem that the operator cannot perform reasonable control on the APN allowed to be accessed by the UE when the APN authorization judgment is performed in the prior art is solved.
- FIG. 8 is a flowchart of Embodiment 6 of a method for granting an APN according to the present invention. As shown in FIG. 8, the method in this embodiment may include:
- Step 801 The UE sends a connection request message to the TWAN.
- step 801 is similar to step 601, and details are not described herein again.
- Step 802 The TWAN sends an authentication and authorization request message to the AAA server.
- step 802 is similar to step 602, and details are not described herein again.
- Step 803 The AAA server sends an authentication request message to the HSS.
- step 803 is similar to step 603, and details are not described herein again.
- Step 804 The HSS performs an authentication judgment according to the authentication request message.
- step 804 is similar to step 604, and details are not described herein again.
- Step 805 The HSS returns an authentication response message to the AAA server.
- step 805 is similar to step 605, and details are not described herein again.
- Step 806 When the authentication response message indicates that the UE fails to authenticate, the AAA server sends the authentication failure reason of the UE to the UE.
- step 806 is similar to step 606, and details are not described herein again.
- Step 807 When the authentication response message indicates that the UE is successfully authenticated, the AAA server sends a Non 3GPP access registration request message to the HSS.
- step 807 is similar to step 607, and details are not described herein again.
- Step 808 The HSS performs the UE according to an access network type currently accessed by the UE.
- the subscription data is updated to obtain updated subscription data;
- step 808 is similar to step 708, and details are not described herein again.
- Step 809 The HSS returns a Non 3GPP access registration response message to the AAA server, where the Non 3GPP access registration response message includes the updated subscription data.
- step 809 is similar to step 709, and details are not described herein again.
- Step 810 The AAA server returns an authentication and authorization response message to the TWAN.
- the authentication and authorization response message includes the updated subscription data.
- Step 811 The UE sends a PDN CONNECTIVITY REQUEST message to the TWAN.
- step 811 is similar to step 610, and details are not described herein again.
- Step 812 The TWAN determines whether the target APN of the UE is authorized according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type.
- the method for determining whether the target APN of the UE is authorized in the step 812 is similar to the method for determining whether the target APN of the UE is authorized in the step 710, and details are not described herein.
- Step 813 The TWAN sends a PDN connection accept message or a PDN connection reject message to the UE.
- step 813 is similar to step 612, and details are not described herein again.
- the authentication and authorization response message is returned to the TWAN by the AAA server, where the authentication and authorization response message includes the updated subscription data of the UE, and the updated subscription data includes the UE
- the TWAN determines the UE according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type. Whether the target APN is authorized or not; the problem that the operator cannot perform reasonable control on the APN that the UE is allowed to access when the APN authorization judgment is performed in the prior art is solved.
- FIG. 9 is a schematic structural diagram of Embodiment 1 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 9, the device in this embodiment may include: a determining module 901 and an obtaining module 902.
- the determining module 901 is configured to determine a target APN of the user equipment UE and an access network type currently accessed by the UE, and the acquiring module 902 is configured to obtain information about an authorized access network type corresponding to the target APN of the UE.
- the determining module 901 is further configured to: according to the access network class currently accessed by the UE And the information of the authorized access network type corresponding to the target APN of the UE, determining whether the target APN of the UE is authorized.
- the network device is an AAA server, or is a Non 3GPP access gateway.
- the determining module 901 is specifically configured to:
- Target APN is authorized
- Determining the UE if it is determined that the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, according to the information of the authorized access network type corresponding to the target APN of the UE.
- the target APN is not authorized.
- the determining module 901 is further configured to determine that the subscription data of the UE includes a target APN of the UE.
- the device may further include a first sending module 903;
- the determining module 901 determines that the target APN of the UE is not authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE, the first sending module 903 And the reason for the authorization failure is sent to the UE, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
- the obtaining module 902 is specifically configured to receive the subscription data of the UE sent by the user home system HSS, where the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE.
- the manner in which the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
- the device may further include: a second sending module 904;
- the obtaining module 902 is further configured to receive an authentication response message sent by the HSS, where the authentication response message includes an authentication failure reason of the UE;
- the second sending module 904 is configured to send an authentication failure reason of the UE to the UE.
- the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 3, the method AAA side of the method embodiment shown in FIG. 5, and the TWAN side of the method embodiment shown in FIG. 6.
- the implementation principle and the technical effect are similar. I won't go into details here.
- FIG. 10 is a schematic structural diagram of Embodiment 2 of an APN-authorized device according to the present invention; the device is an HSS; as shown in FIG. 10, the device in this embodiment may include: a determining module 1001, an updating module 1002, and a sending module 1003.
- the determining module 1001 is configured to determine an access network type that the user equipment UE is currently accessing, and the updating module 1002 is configured to update the subscription data of the UE according to the access network type currently accessed by the UE, Obtaining updated subscription data, where the subscription data of the UE includes at least one APN and information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes that the UE is currently The information about the authorized APN in the accessed access network type; the sending module 1003, configured to send the updated subscription data to the network device.
- the manner in which the subscription data of the UE includes information about an authorized access network type corresponding to the at least one APN includes:
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
- the APN corresponding to the APN configuration parameter is authorized or not authorized.
- the device in this embodiment can be used to implement the technical solution of the method embodiment shown in FIG. 4 and the HSS side of the method embodiment shown in FIG. 7 and FIG. 8.
- the implementation principle and technical effects are similar, and details are not described herein again.
- FIG. 11 is a schematic structural diagram of Embodiment 3 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 11, the device in this embodiment may include: a receiving module 1101 and a determining module.
- Block 1102. The receiving module 1101 is configured to receive updated subscription data sent by the user home system HSS, where the updated subscription data includes information about the authorized APN of the user equipment UE in the currently accessed access network type; 1102. Determine whether the target APN of the UE is authorized according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type.
- the determining module 1102 is specifically configured to:
- Determining if the target APN of the UE belongs to the authorized APN of the UE in the currently accessed access network type, according to the information of the authorized APN of the UE in the currently accessed access network type, The target APN of the UE is authorized; or if the target APN of the UE does not belong to the access network currently accessed by the UE according to the information of the authorized APN of the UE under the currently accessed access network type
- the authorized APN under the type determines that the target APN of the UE is not authorized.
- the device in this embodiment may be used to implement the technical solution on the network device side of the method embodiment shown in FIG. 7 to FIG. 8.
- the implementation principle and technical effects are similar, and details are not described herein again.
- FIG. 12 is a schematic structural diagram of Embodiment 4 of an APN-authorized device according to the present invention; the device is a UE; as shown in FIG. 12, the device in this embodiment may include: a receiving module 1201 and a sending module 1202.
- the receiving module 1201 is configured to receive an authorization failure reason sent by the network device, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized in the access network type currently accessed by the UE; and the sending module 1202 And sending, by the gateway of the access network that the UE is currently accessing, a first connection request message, where the first connection request message includes an APN requested by the UE, and the APN requested by the UE is different from the target APN. .
- the receiving module 1201 is further configured to receive an authentication failure reason of the UE sent by the network device, where the authentication failure reason includes: the public land mobile network VPLMN that the access network type does not allow or access
- the sending module 1202 is further configured to send a second connection request message to a gateway different from a gateway of the access network currently accessed by the UE.
- the device in this embodiment may be used to implement the technical solution on the UE side of the method embodiment shown in FIG. 5 to FIG. 8.
- the implementation principle and technical effects are similar, and details are not described herein again.
- the present invention also provides an APN-authorized system, including the network device and the UE described in Embodiment 1 of the APN-authorized device.
- the UE may be the UE described in Embodiment 4 of the APN authorized device.
- the system of the present embodiment can be used to implement the technical solution of the method embodiment shown in FIG. 5 or FIG. 6.
- the implementation principle and technical effects are similar, and details are not described herein again.
- the present invention further provides another APN-licensed system, including the network device and the UE described in Embodiment 3 of the device that is authorized by the APN-authorized device.
- the UE may be the UE described in Embodiment 4 of the APN authorized device.
- the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 7 or FIG. 8.
- the implementation principle and technical effects are similar, and details are not described herein again.
- FIG. 13 is a schematic structural diagram of Embodiment 5 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 13, the device in this embodiment may include: a processor 1301 and a receiver 1302.
- the processor 1301 is configured to determine a target APN of the user equipment UE and an access network type that the UE currently accesses, and a receiver 1302, configured to acquire information about an authorized access network type corresponding to the target APN of the UE.
- the processor 1301 is further configured to determine whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
- the network device is an AAA server, or is a Non 3GPP access gateway.
- the processor 1301 is specifically configured to:
- Target APN is authorized
- Determining the UE if it is determined that the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, according to the information of the authorized access network type corresponding to the target APN of the UE.
- the target APN is not authorized.
- the processor 1301 is further configured to determine that the subscription data of the UE includes a target APN of the UE.
- the device may further include a transmitter 1303;
- the transmitter 1303 uses The reason for the failure of the authorization is sent to the UE, and the reason for the failure of the authorization is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
- the receiver 1302 is configured to receive the subscription data of the UE sent by the user home system HSS, where the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE.
- the manner in which the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
- the receiver 1302 is further configured to receive an authentication response message sent by the HSS, where the authentication response message includes an authentication failure reason of the UE.
- the transmitter 1303 is further configured to send, to the UE, an authentication failure reason of the UE.
- the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 3, the method AAA side of the method embodiment shown in FIG. 5, and the TWAN side of the method embodiment shown in FIG. 6.
- the implementation principle and the technical effect are similar. I won't go into details here.
- FIG. 14 is a schematic structural diagram of Embodiment 6 of an APN-authorized device according to the present invention; the device is an HSS; as shown in FIG. 14, the device in this embodiment may include: a processor 1401 and a transmitter 1402.
- the processor 1401 is configured to determine an access network type that the user equipment UE is currently accessing, and the processor 1401 is further configured to update the subscription data of the UE according to the access network type currently accessed by the UE.
- the subscription data of the UE includes at least one APN and information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes the UE The information of the authorized APN in the access network type that is currently accessed; the sender 1402 is configured to send the updated subscription data to the network device.
- the manner in which the subscription data of the UE includes information about an authorized access network type corresponding to the at least one APN includes:
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data contains the authorized access network type; or,
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
- the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
- the APN corresponding to the APN configuration parameter is authorized or not authorized.
- the device in this embodiment can be used to implement the technical solution of the method embodiment shown in FIG. 4 and the HSS side of the method embodiment shown in FIG. 7 and FIG. 8.
- the implementation principle and technical effects are similar, and details are not described herein again.
- FIG. 15 is a schematic structural diagram of Embodiment 7 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 15, the device in this embodiment may include: a receiver 1501 and a processor 1502.
- the receiver 1501 is configured to receive updated subscription data sent by the user home system HSS, where the updated subscription data includes information about the authorized APN of the user equipment UE in the currently accessed access network type; 1502. Determine, according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type, whether the target APN of the UE is authorized.
- the processor 1502 is specifically configured to:
- Determining if the target APN of the UE belongs to the authorized APN of the UE in the currently accessed access network type, according to the information of the authorized APN of the UE in the currently accessed access network type, The target APN of the UE is authorized; or if the target APN of the UE does not belong to the access network currently accessed by the UE according to the information of the authorized APN of the UE under the currently accessed access network type
- the authorized APN under the type determines that the target APN of the UE is not authorized.
- the device in this embodiment may be used to implement the technical solution on the network device side of the method embodiment shown in FIG. 7 to FIG. 8.
- the implementation principle and technical effects are similar, and details are not described herein again.
- FIG. 16 is a schematic structural diagram of Embodiment 8 of an APN-authorized device according to the present invention; the device is a UE; as shown in FIG. 16, the device in this embodiment may include: a receiver 1601, a processor 1602, and a transmitter 1603.
- the receiver 1601 is configured to receive an authorization failure reason sent by the network device, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE; and the processor 1602 For the reason for the authorization failure received by the receiver 1601, Generating a first connection request message, where the first connection request message includes an APN requested by the UE, the APN requested by the UE is different from the target APN, and a transmitter 1603, configured to generate the A connection request message is sent to the gateway of the access network currently accessed by the UE.
- the receiver 1601 is further configured to receive, by the network device, an authentication failure reason of the UE, where the authentication failure reason includes: the public land mobile network VPLMN that the access network type does not allow or access
- the processor 1602 is further configured to generate a second connection request message according to the authentication failure reason of the UE received by the receiver 1601, and the transmitter 1603 is further configured to use the second connection request generated by the processor 1602.
- the message is sent to a gateway different from the gateway of the access network to which the UE is currently accessing.
- the device in this embodiment may be used to implement the technical solution on the UE side of the method embodiment shown in FIG. 5 to FIG. 8.
- the implementation principle and technical effects are similar, and details are not described herein again.
- the aforementioned program can be stored in a computer readable storage medium.
- the program when executed, performs the steps including the foregoing method embodiments; and the foregoing storage medium includes various media that can store program codes, such as a ROM, a RAM, a magnetic disk, or an optical disk.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (29)
- 一种接入点名称APN授权的方法,其特征在于,包括:网络设备确定用户设备UE的目标APN及所述UE当前接入的接入网类型;所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息;所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
- 根据权利要求1所述的方法,其特征在于,所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权,包括:如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN被授权;或者,如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN不被授权。
- 根据权利要求1或2所述的方法,其特征在于,所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权之前,还包括:所述网络设备确定所述UE的签约数据包括所述UE的目标APN。
- 根据权利要求1-3任一项所述的方法,其特征在于,如果所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,所述方法还包括:所述网络设备将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
- 根据权利要求1-4任一项所述的方法,其特征在于,所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息,包括:所述网络设备接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
- 根据权利要求5所述的方法,其特征在于,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
- 根据权利要求1-6任一项所述的方法,其特征在于,所述网络设备为鉴权与授权计费AAA服务器,或者为非第三代合作伙伴计划Non 3GPP接入网关。
- 根据权利要求5或6所述的方法,其特征在于,若所述网络设备为AAA服务器,则所述网络设备接收HSS发送的所述UE的签约数据之前,还包括:所述网络设备接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;所述网络设备将所述UE的鉴权失败原因发送至所述UE。
- 一种接入点名称APN授权的方法,其特征在于,包括:用户归属系统HSS确定用户设备UE当前接入的接入网类型;所述HSS根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;所述HSS将所述更新后的签约数据发送至网络设备。
- 根据权利要求9所述的方法,其特征在于,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参 数中包含非授权接入网类型;或者,所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
- 一种接入点名称APN授权的方法,其特征在于,包括:网络设备接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN的信息;所述网络设备根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
- 一种接入点名称APN授权的方法,其特征在于,包括:用户设备UE接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败;所述UE向所述UE当前接入的接入网的网关发送第一连接请求消息;所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
- 根据权利要求12所述的方法,其特征在于,还包括:所述UE接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;所述UE向与所述UE当前接入的接入网的网关不同的网关发送第二连接请求消息。
- 一种接入点名称APN授权的装置,所述装置为网络设备,其特征在于,所述装置包括:确定模块,用于确定用户设备UE的目标APN及所述UE当前接入的接入网类型;获取模块,用于获取所述UE的目标APN对应的授权接入网类型的信息;所述确定模块,还用于根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
- 根据权利要求14所述的装置,其特征在于,所述确定模块具体用于:如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN被授权;或者,如果根据所述UE的目标APN对应的授权接入网类型的信息确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN不被授权。
- 根据权利要求14或15所述的装置,其特征在于,所述确定模块还用于确定所述UE的签约数据包括所述UE的目标APN。
- 根据权利要求14-16任一项所述的装置,其特征在于,所述装置还包括:第一发送模块;如果所述确定模块根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,则所述第一发送模块,用于将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
- 根据权利要求14-17任一项所述的装置,其特征在于,所述获取模块具体用于:接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
- 根据权利要求18所述的装置,其特征在于,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
- 根据权利要求14-19任一项所述的装置,其特征在于,所述网络设 备为鉴权与授权计费AAA服务器,或者为非第三代合作伙伴计划Non 3GPP接入网关。
- 根据权利要求18或19所述的装置,其特征在于,所述装置还包括第二发送模块;若所述网络设备为AAA服务器,则所述获取模块还用于接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;所述第二发送模块,用于将所述UE的鉴权失败原因发送至所述UE。
- 一种接入点名称APN的授权的装置,所述装置为用户归属系统HSS,其特征在于,所述装置包括:确定模块,用于确定用户设备UE当前接入的接入网类型;更新模块,用于根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;发送模块,用于将所述更新后的签约数据发送至网络设备。
- 根据权利要求22所述的装置,其特征在于,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型;或者,所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
- 一种接入点名称APN授权的装置,所述装置为网络设备,其特征在于,所述装置包括:接收模块,用于接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN 的信息;确定模块,用于根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
- 一种接入点名称APN授权的装置,所述装置为用户设备UE,其特征在于,所述装置包括:接收模块,用于接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败;发送模块,用于向所述UE当前接入的接入网的网关发送第一连接请求消息;所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
- 根据权利要求25所述的装置,其特征在于,所述接收模块,还用于接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;所述发送模块,还用于向与所述UE当前接入的接入网的网关不同的网关发送第二连接请求消息。
- 一种接入点名称APN授权的系统,其特征在于,包括:权利要求14-21任一项所述的网络设备及用户设备UE。
- 根据权利要求27所述的系统,其特征在于,所述UE如权利要求25或26所述。
- 一种接入点名称APN授权的系统,其特征在于,包括:权利要求22或23所述的用户归属系统HSS、权利要求24所述的网络设备以及用户设备UE。
Priority Applications (6)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/CN2015/077177 WO2016169003A1 (zh) | 2015-04-22 | 2015-04-22 | 接入点名称授权的方法、装置及系统 |
EP15889492.3A EP3277006B1 (en) | 2015-04-22 | 2015-04-22 | Method, apparatus and system for authorizing access point name |
BR112017022545-0A BR112017022545B1 (pt) | 2015-04-22 | 2015-04-22 | Método, aparelho, e sistema de autorização de nome de ponto de acesso |
JP2017555362A JP6577052B2 (ja) | 2015-04-22 | 2015-04-22 | アクセスポイント名許可方法、アクセスポイント名許可装置、およびアクセスポイント名許可システム |
CN201580071236.7A CN107113612B (zh) | 2015-04-22 | 2015-04-22 | 接入点名称授权的方法、装置及系统 |
US15/789,359 US10893049B2 (en) | 2015-04-22 | 2017-10-20 | Access point name authorization method, apparatus, and system |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/CN2015/077177 WO2016169003A1 (zh) | 2015-04-22 | 2015-04-22 | 接入点名称授权的方法、装置及系统 |
Related Child Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US15/789,359 Continuation US10893049B2 (en) | 2015-04-22 | 2017-10-20 | Access point name authorization method, apparatus, and system |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2016169003A1 true WO2016169003A1 (zh) | 2016-10-27 |
Family
ID=57143649
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2015/077177 WO2016169003A1 (zh) | 2015-04-22 | 2015-04-22 | 接入点名称授权的方法、装置及系统 |
Country Status (6)
Country | Link |
---|---|
US (1) | US10893049B2 (zh) |
EP (1) | EP3277006B1 (zh) |
JP (1) | JP6577052B2 (zh) |
CN (1) | CN107113612B (zh) |
BR (1) | BR112017022545B1 (zh) |
WO (1) | WO2016169003A1 (zh) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN112468315A (zh) * | 2020-11-03 | 2021-03-09 | 上海中觅通信技术有限公司 | 一种apn配置方法和设备 |
Families Citing this family (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108537662A (zh) * | 2018-03-09 | 2018-09-14 | 深圳市富途网络科技有限公司 | 一种实现股票交易持仓和交易记录共享的方法及系统 |
US10772062B1 (en) * | 2019-04-15 | 2020-09-08 | T-Mobile Usa, Inc. | Network-function monitoring and control |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1627842A (zh) * | 2003-12-12 | 2005-06-15 | 华为技术有限公司 | 一种无线局域网用户终端选择分组数据关口的方法 |
CN101248640A (zh) * | 2005-01-24 | 2008-08-20 | 艾利森电话股份有限公司 | 用于选择分组交换电信网络中移动终端的接入点名称(apn)的方法 |
CN103415044A (zh) * | 2013-08-05 | 2013-11-27 | 南京邮电大学 | 一种WLAN网络中3GPP用户获取QoS签约的方法 |
CN103517378A (zh) * | 2012-06-30 | 2014-01-15 | 华为终端有限公司 | 分组数据网连接建立方法和设备 |
CN103517252A (zh) * | 2012-06-21 | 2014-01-15 | 中兴通讯股份有限公司 | 分组网关标识信息的更新方法、aaa服务器和分组网关 |
Family Cites Families (26)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7324489B1 (en) * | 2003-02-18 | 2008-01-29 | Cisco Technology, Inc. | Managing network service access |
CN101170808B (zh) * | 2006-10-25 | 2011-03-30 | 华为技术有限公司 | 异种接入系统间的切换方法及切换系统 |
US7809003B2 (en) * | 2007-02-16 | 2010-10-05 | Nokia Corporation | Method for the routing and control of packet data traffic in a communication system |
US8621570B2 (en) * | 2008-04-11 | 2013-12-31 | Telefonaktiebolaget L M Ericsson (Publ) | Access through non-3GPP access networks |
CN101286915B (zh) * | 2008-06-11 | 2012-05-09 | 中兴通讯股份有限公司 | 分组数据网络的接入控制方法和系统、pcrf实体 |
EP2166724A1 (en) * | 2008-09-23 | 2010-03-24 | Panasonic Corporation | Optimization of handovers to untrusted non-3GPP networks |
CN101730267B (zh) | 2008-10-21 | 2012-11-07 | 华为技术有限公司 | 接入控制方法、装置和通信系统 |
US8607309B2 (en) * | 2009-01-05 | 2013-12-10 | Nokia Siemens Networks Oy | Trustworthiness decision making for access authentication |
JPWO2010092764A1 (ja) * | 2009-02-13 | 2012-08-16 | パナソニック株式会社 | ゲートウェイ接続方法及びゲートウェイ接続制御システム並びに移動端末 |
US8595796B2 (en) * | 2009-10-12 | 2013-11-26 | Qualcomm Incorporated | Apparatus and method for authorization for access point name (APN) usage in a specific access |
KR101388315B1 (ko) * | 2009-11-02 | 2014-04-29 | 엘지전자 주식회사 | 로컬 ip 접속을 위한 상관 id |
US8477724B2 (en) * | 2010-01-11 | 2013-07-02 | Research In Motion Limited | System and method for enabling session context continuity of local service availability in local cellular coverage |
EP2664192B1 (en) * | 2011-01-13 | 2016-06-15 | Telefonaktiebolaget LM Ericsson (publ) | Roaming control for ims apn |
EP2664100B1 (en) * | 2011-01-14 | 2018-12-05 | Nokia Solutions and Networks Oy | External authentication support over an untrusted network |
WO2013003653A1 (en) * | 2011-06-28 | 2013-01-03 | Huawei Technologies Co., Ltd. | System and method for communications network configuration |
US9049562B2 (en) * | 2011-08-10 | 2015-06-02 | Telefonaktiebolaget Lm Ericsson (Publ) | HSS fault recovery for non-3GPP access |
WO2013041574A1 (en) * | 2011-09-19 | 2013-03-28 | Telefonaktiebolaget L M Ericsson (Publ) | Deferred address allocation of ipv4 or ipv6 in case of interworking between non-3gpp access and evolved packet core |
US9521145B2 (en) * | 2011-10-17 | 2016-12-13 | Mitel Mobility Inc. | Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network |
US20130121322A1 (en) | 2011-11-10 | 2013-05-16 | Motorola Mobility, Inc. | Method for establishing data connectivity between a wireless communication device and a core network over an ip access network, wireless communication device and communicatin system |
CN103200628B (zh) * | 2012-01-09 | 2018-05-15 | 中兴通讯股份有限公司 | 一种通过非3gpp接入核心网的方法和系统 |
JP2013219635A (ja) * | 2012-04-10 | 2013-10-24 | Ntt Docomo Inc | 移動局、通信システム及び通信方法 |
US9521077B2 (en) * | 2013-07-22 | 2016-12-13 | Verizon Patent And Licensing Inc. | Network connection via a proxy device using a generic access point name |
US9220118B1 (en) * | 2013-08-07 | 2015-12-22 | Sprint Spectrum L.P. | Method and system for establishing a default bearer in accordance with a substitute packet data policy |
US20150350912A1 (en) * | 2014-05-28 | 2015-12-03 | Telefonaktiebolaget L M Ericsson (Publ) | Residential service delivery based on unique residential apn |
CN106664550B (zh) * | 2014-07-22 | 2019-11-15 | 意大利电信股份公司 | 管理移动电信网络中的用户的订阅的方法 |
EP3278497A4 (en) * | 2015-03-31 | 2019-03-06 | Telefonaktiebolaget LM Ericsson (publ) | METHODS AND DEVICES FOR FACILITATING EMERGENCY CALLS ON WIRELESS COMMUNICATION SYSTEMS |
-
2015
- 2015-04-22 JP JP2017555362A patent/JP6577052B2/ja active Active
- 2015-04-22 BR BR112017022545-0A patent/BR112017022545B1/pt active IP Right Grant
- 2015-04-22 CN CN201580071236.7A patent/CN107113612B/zh active Active
- 2015-04-22 WO PCT/CN2015/077177 patent/WO2016169003A1/zh unknown
- 2015-04-22 EP EP15889492.3A patent/EP3277006B1/en active Active
-
2017
- 2017-10-20 US US15/789,359 patent/US10893049B2/en active Active
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1627842A (zh) * | 2003-12-12 | 2005-06-15 | 华为技术有限公司 | 一种无线局域网用户终端选择分组数据关口的方法 |
CN101248640A (zh) * | 2005-01-24 | 2008-08-20 | 艾利森电话股份有限公司 | 用于选择分组交换电信网络中移动终端的接入点名称(apn)的方法 |
CN103517252A (zh) * | 2012-06-21 | 2014-01-15 | 中兴通讯股份有限公司 | 分组网关标识信息的更新方法、aaa服务器和分组网关 |
CN103517378A (zh) * | 2012-06-30 | 2014-01-15 | 华为终端有限公司 | 分组数据网连接建立方法和设备 |
CN103415044A (zh) * | 2013-08-05 | 2013-11-27 | 南京邮电大学 | 一种WLAN网络中3GPP用户获取QoS签约的方法 |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN112468315A (zh) * | 2020-11-03 | 2021-03-09 | 上海中觅通信技术有限公司 | 一种apn配置方法和设备 |
Also Published As
Publication number | Publication date |
---|---|
BR112017022545B1 (pt) | 2024-03-05 |
CN107113612B (zh) | 2020-06-26 |
CN107113612A (zh) | 2017-08-29 |
EP3277006A1 (en) | 2018-01-31 |
EP3277006A4 (en) | 2018-03-28 |
EP3277006B1 (en) | 2020-07-08 |
US10893049B2 (en) | 2021-01-12 |
BR112017022545A2 (zh) | 2018-07-17 |
JP2018514166A (ja) | 2018-05-31 |
JP6577052B2 (ja) | 2019-09-18 |
US20180041903A1 (en) | 2018-02-08 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US8990925B2 (en) | Security for a non-3GPP access to an evolved packet system | |
TWI616084B (zh) | 使用現有身份碼的到蜂巢網路的受贊助連接 | |
JP6628295B2 (ja) | 認証されていないユーザのための3gpp進化型パケットコアへのwlanアクセスを介した緊急サービスのサポート | |
US8776184B2 (en) | Method, system and apparatus for accessing a visited network | |
US10171998B2 (en) | User profile, policy, and PMIP key distribution in a wireless communication network | |
US20120284785A1 (en) | Method for facilitating access to a first access nework of a wireless communication system, wireless communication device, and wireless communication system | |
US20100064135A1 (en) | Secure Negotiation of Authentication Capabilities | |
MX2014005668A (es) | Metodo para establecer conectividad de datos entre un dispositivo de comunicacion inalambrica y una red nucleo sobre una red de acceso ip, dispositivo de comunicacion inalambrica y sistema de comunicacion. | |
CN111726228B (zh) | 使用互联网密钥交换消息来配置活动性检查 | |
US10893049B2 (en) | Access point name authorization method, apparatus, and system | |
US11729164B2 (en) | Support of IMEI checking for WLAN access to a packet core of a mobile network | |
JP2024517897A (ja) | Nswoサービスの認証のための方法、デバイス、および記憶媒体 | |
KR102103320B1 (ko) | 이동 단말기, 네트워크 노드 서버, 방법 및 컴퓨터 프로그램 | |
WO2017132906A1 (zh) | 获取、发送用户设备标识的方法及设备 | |
WO2016101267A1 (zh) | 用户设备的非可信无线局域网接入控制方法、设备和系统 | |
WO2018103732A1 (zh) | 一种紧急号码的配置、获取方法及装置 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15889492 Country of ref document: EP Kind code of ref document: A1 |
|
ENP | Entry into the national phase |
Ref document number: 2017555362 Country of ref document: JP Kind code of ref document: A |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
REG | Reference to national code |
Ref country code: BR Ref legal event code: B01A Ref document number: 112017022545 Country of ref document: BR |
|
ENP | Entry into the national phase |
Ref document number: 112017022545 Country of ref document: BR Kind code of ref document: A2 Effective date: 20171019 |