WO2016169003A1 - 接入点名称授权的方法、装置及系统 - Google Patents

接入点名称授权的方法、装置及系统 Download PDF

Info

Publication number
WO2016169003A1
WO2016169003A1 PCT/CN2015/077177 CN2015077177W WO2016169003A1 WO 2016169003 A1 WO2016169003 A1 WO 2016169003A1 CN 2015077177 W CN2015077177 W CN 2015077177W WO 2016169003 A1 WO2016169003 A1 WO 2016169003A1
Authority
WO
WIPO (PCT)
Prior art keywords
apn
access network
authorized
network type
subscription data
Prior art date
Application number
PCT/CN2015/077177
Other languages
English (en)
French (fr)
Inventor
于游洋
高荣春
李华
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2015/077177 priority Critical patent/WO2016169003A1/zh
Priority to EP15889492.3A priority patent/EP3277006B1/en
Priority to BR112017022545-0A priority patent/BR112017022545B1/pt
Priority to JP2017555362A priority patent/JP6577052B2/ja
Priority to CN201580071236.7A priority patent/CN107113612B/zh
Publication of WO2016169003A1 publication Critical patent/WO2016169003A1/zh
Priority to US15/789,359 priority patent/US10893049B2/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/101Access control lists [ACL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/107Network architectures or network communication protocols for network security for controlling access to devices or network resources wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/084Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/17Selecting a data network PoA [Point of Attachment]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/164Implementing security features at a particular protocol layer at the network layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • H04L67/143Termination or inactivation of sessions, e.g. event-controlled end of session
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/16Discovering, processing access restriction or access information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W56/00Synchronisation arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/26Network addressing or numbering for mobility support
    • H04W8/265Network addressing or numbering for mobility support for initial activation of new user

Definitions

  • the embodiments of the present invention relate to communication technologies, and in particular, to a method, an apparatus, and a system for authorizing an Access Point Name (APN).
  • API Access Point Name
  • Non 3rd Generation Partnership Project Non 3rd Generation Partnership Project
  • access network type can be CDMA (Code Division Multiple Access) 2000, Worldwide Interoperability for Microwave Access (WiMAX) ), Wireless Local Area Network (WLAN), etc.
  • CDMA Code Division Multiple Access 2000
  • WiMAX Worldwide Interoperability for Microwave Access
  • WLAN Wireless Local Area Network
  • the Non 3GPP access network is further divided into a trusted Non 3GPP access network and an untrusted Non 3GPP access network.
  • a user equipment UE, User Equipment
  • a Non 3GPP access network for example, an untrusted Non 3GPP access network
  • an untrusted Non 3GPP access gateway eg, an evolved packet data gateway (ePDG, Evolved Packet
  • the data gateway sends an authentication and authorization request to the AAA (Authentication, Authorization, and Accounting) server (wherein the authentication and authorization request may include the APN requested by the UE, if authentication and authorization)
  • the AAA server obtains the subscription data of the UE from the Home Subscriber System (HSS) (the subscription data includes the APN allowed by the UE)
  • HSS Home Subscriber System
  • the AAA server determines whether the APN requested by the UE is authorized according to the subscription data of the UE and the APN that the
  • the embodiment of the invention provides a method, a device and a system for authorizing an access point name, which are used to solve the problem that the operator cannot authorize the UE when performing the APN authorization judgment in the prior art.
  • APN has reasonable control issues.
  • an embodiment of the present invention provides a method for APN authorization, including:
  • the network device determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
  • the network device is configured according to an access network type currently accessed by the UE and an authorized access network type corresponding to the target APN of the UE.
  • Information, determining whether the target APN of the UE is authorized including:
  • the network device is determined according to the information of the authorized access network type corresponding to the target APN of the UE. It is determined that the target APN of the UE is not authorized.
  • the network device is configured according to an access network type that the UE is currently accessing, and
  • the information of the authorized access network type corresponding to the target APN of the UE, before determining whether the target APN of the UE is authorized further includes:
  • the network device determines that the subscription data of the UE includes a target APN of the UE.
  • the method further includes:
  • the network device sends an authorization failure reason to the UE, and the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
  • the network device acquires a target APN corresponding to the UE Information on authorized access network types, including:
  • the network device receives the subscription data of the UE sent by the user home system HSS, and the subscription data of the UE includes information of an authorized access network type corresponding to the target APN of the UE.
  • the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE. Ways include:
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
  • the network device is an AAA server, or is Non 3GPP Access gateway.
  • the network device receives an Before the UE's subscription data, it also includes:
  • the network device sends an authentication failure reason of the UE to the UE.
  • an embodiment of the present invention provides a method for APN authorization, including:
  • the HSS sends the subscription data of the user equipment UE to the network device, where the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE, so that the network device corresponds to the target APN of the UE.
  • the authorized access network type information and the access network type currently accessed by the UE determine whether the target APN of the UE is authorized.
  • the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
  • an embodiment of the present invention provides a method for APN authorization, including:
  • the HSS determines an access network type currently accessed by the user equipment UE
  • the HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
  • the subscription data of the UE includes at least one APN and the foregoing.
  • the updated subscription data includes information of the authorized APN of the UE under the currently accessed access network type;
  • the HSS sends the updated subscription data to a network device.
  • the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the at least one APN includes:
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
  • the APN corresponding to the APN configuration parameter is authorized or not authorized.
  • an embodiment of the present invention provides a method for APN authorization, including:
  • the network device receives the updated subscription data sent by the user home system HSS;
  • the updated subscription data includes information of the authorized APN of the user equipment UE under the currently accessed access network type;
  • an embodiment of the present invention provides a method for APN authorization, including:
  • the UE Transmitting, by the UE, a first connection request message to a gateway of an access network that the UE is currently accessing; the first connection request message includes an APN requested by the UE, and the APN requested by the UE is different from the target APN .
  • the method further includes:
  • an authentication failure reason of the UE that is sent by the network device includes: the public land mobile network VPLMN that the access network type does not allow or access is not allowed;
  • the UE sends a second connection request message to a gateway different from a gateway of the access network currently accessed by the UE.
  • the embodiment of the present invention provides an APN authorized device, where the device is a network device, and the device includes:
  • a determining module configured to determine a target APN of the UE and an access network type currently accessed by the UE
  • An acquiring module configured to acquire information about an authorized access network type corresponding to the target APN of the UE
  • the determining module is further configured to determine whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
  • the processing module is specifically configured to:
  • Target APN is authorized
  • Determining the UE if it is determined that the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, according to the information of the authorized access network type corresponding to the target APN of the UE.
  • the target APN is not authorized.
  • the determining module is further configured to determine that the subscription data of the UE includes the UE Target APN.
  • the device further includes: a first sending module
  • the determining module determines that the target APN of the UE is not authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE
  • the first And a sending module configured to send an authorization failure reason to the UE, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
  • the acquiring module is specifically configured to:
  • the subscription data of the UE sent by the user home system HSS is received, and the subscription data of the UE includes information of an authorized access network type corresponding to the target APN of the UE.
  • the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE. Ways include:
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
  • the network device is an AAA server, or is a Non 3GPP Access gateway.
  • the device further includes a second sending module
  • the acquiring module is further configured to receive an authentication response message sent by the HSS, where the authentication response message includes an authentication failure reason of the UE;
  • the second sending module is configured to send an authentication failure reason of the UE to the UE.
  • the embodiment of the present invention provides an APN authorized device, where the device is an HSS, and the device includes:
  • a sending module configured to send the subscription data of the user equipment UE to the network device, where the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE, so that And determining, by the network device, whether the target APN of the UE is authorized according to the authorized access network type information corresponding to the target APN of the UE and the access network type currently accessed by the UE.
  • the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
  • an embodiment of the present invention provides an apparatus for authorizing an APN, where the apparatus is an HSS, and the apparatus includes:
  • a determining module configured to determine an access network type currently accessed by the user equipment UE
  • an update module configured to update the subscription data of the UE according to the type of the access network that the UE is currently accessing, to obtain the updated subscription data, where the subscription data of the UE includes at least one APN and Information of the authorized access network type corresponding to the at least one APN; the updated subscription data includes information of the authorized APN of the UE under the currently accessed access network type;
  • a sending module configured to send the updated subscription data to the network device.
  • the manner that the subscription data of the UE includes the information of the authorized access network type corresponding to the at least one APN includes:
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
  • the APN corresponding to the APN configuration parameter is authorized or not authorized.
  • a ninth aspect the embodiment of the present invention provides an APN authorized device, where the device is a network device, and the device includes:
  • a receiving module configured to receive the updated subscription data sent by the user home system HSS;
  • the updated subscription data includes information of the authorized APN of the user equipment UE in the currently accessed access network type;
  • a determining module configured to determine, according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type, whether the target APN of the UE is authorized.
  • the embodiment of the present invention provides an APN authorized device, where the device is a UE, and the device includes:
  • a receiving module configured to receive an authorization failure reason sent by the network device, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE;
  • a sending module configured to send a first connection request message to a gateway of an access network that the UE is currently accessing; the first connection request message includes an APN requested by the UE, and the APN requested by the UE and the target APN is different.
  • the receiving module is further configured to receive, by the network device, an authentication failure reason of the UE, where the authentication failure cause includes : Public land mobile network VPLMN not allowed or accessed by the access network type is not allowed;
  • the sending module is further configured to send a second connection request message to a gateway different from a gateway of the access network currently accessed by the UE.
  • An eleventh aspect the embodiment of the present invention provides a system for granting an APN, comprising: the network device, the seventh aspect, or the seventh aspect of any one of the first to seventh aspects of the sixth aspect or the sixth aspect The first described HSS and UE.
  • the UE in conjunction with the eleventh aspect, in a first possible implementation manner of the eleventh aspect, is as described in the first aspect of the tenth aspect or the tenth aspect.
  • the embodiment of the present invention provides a system for granting an APN, comprising: the HSS according to the first aspect of the eighth aspect, or the network device and the UE according to the ninth aspect.
  • the UE is as described in the eighth aspect or the first aspect of the eighth aspect.
  • the present invention provides a method, an apparatus, and a system for granting an access point name, by using the network device according to an access network type currently accessed by the UE and an authorized connection corresponding to the target APN of the UE. Determining whether the target APN of the UE is authorized, and determining that the UE is currently connected according to the authorized access network type information corresponding to the target APN of the UE when performing the APN authorization determination.
  • the network device can simultaneously consider the target APN of the UE and the access network type currently accessed by the UE when performing the APN authorization determination;
  • the APN that the UE can access in the access network type that is currently accessed by the UE can be controlled according to the access network type that the UE is currently accessing.
  • the operator cannot allow the UE to be allowed. The problem of reasonable control of the accessed APN.
  • FIG. 1 is a schematic diagram of an application scenario of an APN authorization method according to the present invention.
  • FIG. 2 is a schematic diagram of another application scenario of a method for APN authorization according to the present invention.
  • Embodiment 3 is a flowchart of Embodiment 1 of a method for APN authorization according to the present invention
  • Embodiment 4 is a flowchart of Embodiment 2 of a method for APN authorization according to the present invention.
  • FIG. 5 is a flowchart of Embodiment 3 of a method for granting an APN according to the present invention.
  • Embodiment 4 is a flowchart of Embodiment 4 of a method for granting an APN according to the present invention
  • Embodiment 7 is a flowchart of Embodiment 5 of a method for granting an APN according to the present invention.
  • Embodiment 8 is a flowchart of Embodiment 6 of a method for granting an APN according to the present invention.
  • Embodiment 9 is a schematic structural diagram of Embodiment 1 of an APN authorized device according to the present invention.
  • Embodiment 2 is a schematic structural diagram of Embodiment 2 of an APN authorized device according to the present invention.
  • FIG. 11 is a schematic structural diagram of Embodiment 3 of an apparatus for granting an APN according to the present invention.
  • Embodiment 4 is a schematic structural diagram of Embodiment 4 of an apparatus for granting an APN according to the present invention.
  • FIG. 13 is a schematic structural diagram of Embodiment 5 of an apparatus for granting an APN according to the present invention.
  • Embodiment 6 is a schematic structural diagram of Embodiment 6 of an APN authorized device according to the present invention.
  • Embodiment 7 is a schematic structural diagram of Embodiment 7 of an APN authorized device according to the present invention.
  • FIG. 16 is a schematic structural diagram of Embodiment 8 of an apparatus for granting an APN according to the present invention.
  • FIG. 1 is a schematic diagram of an application scenario of an APN authorization method according to the present invention
  • the application scenario includes: a UE, an ePDG, an AAA server, and an HSS.
  • the ePDG sends an authentication and authorization request message to the AAA server (where the authentication and authorization request message may include the APN requested by the UE to be accessed; if not included, the ePDG may be used.
  • the default APN in the subscription data of the UE the AAA server obtains the subscription data of the UE from the HSS, and the subscription data includes the APN allowed by the UE; when the subscription data includes the target APN of the UE (when the authentication is performed)
  • the APN is included in the authorization request message, the APN is used as the target APN of the UE; when the APN is not included, the default APN in the subscription data is used as the target APN of the UE), the AAA server determines that the target APN of the UE is authorized; Otherwise, the AAA server determines that the target APN of the UE is not authorized.
  • the subscription data of the UE includes only the APN that the UE is allowed to access, the relationship between the APN that the UE is allowed to access and the access network type is not reflected; therefore, when the AAA server performs the APN authorization judgment, The operator cannot properly control the APN that the UE is allowed to access.
  • the application scenario includes: a UE, a trusted WLAN access network (TWAN), an AAA server, and an HSS.
  • TWAN trusted WLAN access network
  • AAA server AAA server
  • HSS HSS
  • the TWAN obtains the subscription data of the UE from the HSS, where the subscription data includes the APN allowed by the UE; when the subscription data includes the target APN of the UE, the TWAN It is determined that the target APN of the UE is authorized; otherwise, the TWAN determines that the target APN of the UE is not authorized.
  • the subscription data of the UE includes only the APN that the UE is allowed to access, the relationship between the APN that the UE is allowed to access and the access network type is not reflected; therefore, when the TWAN performs the APN authorization judgment, The operator cannot properly control the APN that the UE is allowed to access.
  • FIG. 1 and FIG. 2 are only the method of the present invention in the non-3GPP access network type.
  • Schematic diagram of untrusted WLAN and trusted WALN; the method of the present invention can be applied to any non-3GPP access network type, such as CDMA2000, WiMAX, and the like.
  • the non-3GPP access network type is CDMA2000
  • the corresponding application scenario is to replace the TWAN network element shown in FIG. 2 with a High Rate Packet Data (HRPD) service gateway (HS-GW, HRPD Serving Gateway).
  • HRPD High Rate Packet Data
  • HS-GW High Rate Packet Data
  • HRPD Serving Gateway HRPD Serving Gateway
  • the Non 3GPP access gateway may include an ePDG, a TWAN, an HS-GW, and the like.
  • FIG. 3 is a flowchart of Embodiment 1 of an APN authorization method according to the present invention. As shown in FIG. 3, the method in this embodiment may include:
  • Step 301 The network device determines a target APN of the user equipment UE and an access network type currently accessed by the UE.
  • the network device may be an AAA server or a Non 3GPP access gateway.
  • Step 302 The network device acquires information about an authorized access network type corresponding to the target APN of the UE.
  • the authorized access network type is an access network type that allows the UE to access.
  • Step 303 The network device determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
  • step 303 can be specifically:
  • the network device is determined according to the information of the authorized access network type corresponding to the target APN of the UE. It is determined that the target APN of the UE is not authorized.
  • the subscription data of the UE includes the APN that the UE is allowed to access; when the subscription data of the UE includes the target APN of the UE, it is determined that the target APN of the UE is authorized; otherwise, the UE is determined.
  • the target APN is not authorized.
  • the network device is configured according to an access network type currently accessed by the UE and an authorized access network type corresponding to the target APN of the UE. Information determining whether the target APN of the UE is authorized.
  • the subscription data of the UE includes only the APN (that is, the authorized APN) that the UE is allowed to access, but does not reflect the APN between the AP and the access network type that the UE is allowed to access. Relationship; therefore, there is a problem that the operator cannot properly control the APN that the UE is allowed to access when performing the APN authorization judgment.
  • the network device determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE;
  • the network device can determine, according to the authorized access network type information corresponding to the target APN of the UE, whether the target APN of the UE is authorized by the UE under the currently accessed access network type;
  • the network device can simultaneously consider the target APN of the UE and the access network type currently accessed by the UE; thereby enabling the operator to access the UE according to the access network type currently accessed by the UE.
  • the access network allows access to the APN to control the access network. In the prior art, when the APN authorization judgment is performed, the operator cannot properly control the APN allowed to be accessed by the UE.
  • Embodiment 2 of an APN authorization method according to the present invention. As shown in FIG. 4, the method in this embodiment may include:
  • Step 401 The HSS determines an access network type currently accessed by the UE.
  • Step 402 The HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
  • the subscription data of the UE includes at least one APN and Information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes information of an authorized APN of the UE under the currently accessed access network type;
  • the authorized APN is an APN that allows the UE to access.
  • Step 403 The HSS sends the updated subscription data to a network device.
  • the network device may be an AAA server or a Non 3GPP access gateway.
  • the subscription data of the UE stored by the HSS includes the APN that the UE is allowed to access, and the HSS sends the subscription data to the network device, so that the network device performs the APN authorization judgment.
  • the HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
  • the subscription data of the UE includes at least one APN. And information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes an authorized APN of the UE under the currently accessed access network type Information; the HSS sends the updated subscription data to a network device.
  • the HSS updates the subscription data of the UE according to the type of the access network that the UE is currently accessing, and obtains the updated subscription data.
  • the subscription data of the UE includes at least one of the subscription data.
  • the APN and the information about the authorized APN of the UE in the currently accessed access network type determine whether the target APN of the UE is authorized. If the APN authorization judgment is performed in the prior art, the operator cannot Allows access to the APN to be properly controlled.
  • FIG. 5 is a flowchart of Embodiment 3 of a method for granting an APN according to the present invention. As shown in FIG. 5, the method in this embodiment may include:
  • Step 501 The UE sends an IKE (Internet Key Exchange) authentication request message (IKE_AUTH request message) to the ePDG.
  • IKE Internet Key Exchange
  • the IKE authentication request message may include the target APN of the UE; or the IKE authentication request message may not include the target APN of the UE.
  • the AAA server uses the default APN in the subscription data of the UE as the target APN of the UE.
  • the UE may further include the IKE initial request message (IKE_SA_INIT request message) sent by the UE to the ePDG.
  • IKE_SA_INIT request message the IKE initial request message sent by the UE to the ePDG.
  • Step 502 The ePDG sends an authentication and authorization request (Authentication and authorization request) message to the AAA server.
  • the authentication and authorization request message may include an access network type currently accessed by the UE, an identifier of the UE, and a network identifier.
  • the identifier of the UE may be a Network Access ID (NAI).
  • NAI includes an International Mobile Subscriber Identity (IMSI) of the UE; and the network identifier may be a Visited Public Land Mobile Network (VPLMN) information.
  • IMSI International Mobile Subscriber Identity
  • VPN Visited Public Land Mobile Network
  • the access network type currently accessed by the UE may be acquired by the ePDG, and the ePDG may be a non-3GPP access gateway of the non-trusted WLAN, so the access network type currently accessed by the UE Can be a non-trusted WLAN or WLAN.
  • Step 503 The AAA server sends an Authentication Request message to the HSS.
  • the authentication request message may include an IMSI of the UE, a network identifier, and an access network type currently accessed by the UE.
  • the AAA server may further determine, according to the IMSI of the UE included in the authentication and authorization request message, whether the Context information of the UE is stored in the AAA server (including signing the contract). If the AAA server determines that the context information of the UE has been stored, the authentication request message is not sent to the HSS (ie, step 503 is not executed), and step 509 is directly performed.
  • Step 504 The HSS performs an authentication judgment according to the authentication request message.
  • the authentication determination may include: 1) determining whether the subscription data of the UE exists; 2) determining whether the UE is allowed to access the current network, that is, whether the access network type currently accessed by the UE is subject to The network type is limited; 3) determining whether the network indicated by the VPLMN allows the UE to access; 4) whether there is Non3GPP subscription data and the like related to the UE.
  • Step 505 The HSS returns an Authentication Response message to the AAA server.
  • the authentication response message includes an authentication vector of the UE. Otherwise, the authentication response message includes an authentication failure reason of the UE.
  • the reason for the failure of the authentication may be “the user does not exist”, and the corresponding authentication failure cause value may be “DIAMETER_ERROR_USER_UNKNOWN”;
  • the corresponding authentication failure reason may be “access”.
  • Type is not allowed, and the corresponding authentication failure cause value can be "DIAMETER_ERROR_RAT_TYPE_NOT_ALLOWED";
  • the corresponding authentication failure reason may be “VPLMN not allowed”, and the corresponding authentication failure cause value may be “DIAMETER_ERROR_ROAMING_NOT_ALLOWED”;
  • the corresponding authentication failure reason may be “Non 3GPP subscription data does not exist”, and the corresponding authentication failure cause value may be “DIAMETER_ERROR_USER_NO_NON_3GPP_SUBSCRIPTON”.
  • the subscription data may include Non 3GPP subscription data.
  • Step 506 When the authentication response message indicates that the UE fails to be authenticated, the AAA server sends the authentication failure reason of the UE to the UE.
  • the AAA server may use the Extensible Authentication Protocol (EAP)-Authentication and Key Agreement Protocol (AKA) or EAP-AKA' message to determine the reason for the UE's authentication failure. Sent to the UE.
  • EAP Extensible Authentication Protocol
  • AKA Access and Key Agreement Protocol
  • EAP-AKA or EAP-AKA' message may be sent by the AAA server to the ePDG through an Authentication and Authorization Answer message, and then sent by the ePDG through an IKEv2 message.
  • the authentication and authorization response message and IKEv2 contain EAP-AKA or EAP-AKA' messages.
  • the reason for the authentication failure of the UE may also be sent by the ePDG to the UE by adding a cause value in the IKEv2 message. That is, the authentication and authorization response message sent by the AAA server to the ePDG carries the authentication failure reason of the UE acquired by the AAA server from the HSS, and then the ePDG authenticates the UE. The reason for the failure is sent to the UE through the new cause value in the IKEv2 message.
  • the IKE_AUTH request message is sent to the access gateway different from the ePDG. .
  • IKE_AUTH request message may be considered as a connection request message.
  • Step 507 When the authentication response message indicates that the UE is successfully authenticated, the AAA server Sending a Non 3GPP IP Access Registration request message to the HSS;
  • the Non 3GPP Access Registration Request message includes an IMSI of the UE.
  • the AAA server may perform the interaction with the UE according to the authentication vector included in the authentication response.
  • the authentication process of the UE may be performed before the sending, by the AAA server, the Non 3GPP access registration request to the HSS.
  • Step 508 The HSS returns a Non 3GPP IP Access Registration response (Non 3GPP IP Access Registration response) message to the AAA server.
  • the Non 3GPP Access Registration Response message includes subscription data of the UE.
  • the HSS searches for the subscription data of the UE according to the IMSI of the UE included in the Non 3GPP access registration request message, and returns a subscription of the UE to the AAA server by using a Non 3GPP access registration response message. data.
  • the subscription data of the UE includes information about a target APN of the UE and an authorized access network type corresponding to the target APN of the UE.
  • the manner in which the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
  • the authorized access network type is an access network type that allows the UE to access;
  • the unlicensed access network type is an access network type that does not allow the UE to access.
  • the access network type in the APN configuration parameter may include at least one of the following access network types:
  • WLAN trusted WLAN
  • untrusted WLAN CDMA2000, WiMAX
  • UTRAN UMTS Terrestrial Radio Access Network
  • GERAN GSM EDGE Radio Access Network
  • EUTRAN evolved Evolved Universal Terrestrial Radio Access Network
  • the WLAN access network type may further include: a trusted WLAN and an untrusted WLAN.
  • the scheme that the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE is as follows:
  • the APN configuration parameter (APN-Configuration) corresponding to the target APN of the UE includes an authorized access network type (RAT-Permission); when there is more than one authorized access network type, it is an authorized access network type list.
  • RAT-Permission authorized access network type
  • APN-Configuration:: ⁇ AVP header:1430 10415>
  • the Context-Identifier is a file identifier corresponding to the target APN of the UE; the RAT-Permission may include an authorized access network type corresponding to the APN (ie, the target APN) identified by the Context-Identifier; When the RAT-Permission includes the access network type currently accessed by the UE, it is determined that the target APN of the UE is authorized.
  • the "RAT-Permission” may include a "match-all” indication, indicating that the target APN is authorized under any access network type; or, when the configuration parameter does not include “RAT-Permission", it indicates that it is connected at any time.
  • the target APN is authorized under the network access type.
  • the APN configuration parameter corresponding to the target APN of the UE includes an unlicensed access network type (RAT-Forbidden), and the implementation manner is as follows:
  • APN-Configuration:: ⁇ AVP header:1430 10415>
  • the Context-Identifier is a file identifier corresponding to the target APN of the UE; the RAT-Forbidden may include an unlicensed connection corresponding to the APN (that is, the target APN of the UE) identified by the Context-Identifier.
  • the network access type is determined. When the RAT-Forbidden corresponding to the target APN of the UE does not include the access network type currently accessed by the UE, it is determined that the target APN of the UE is authorized.
  • the configuration parameter does not include “RAT-Forbidden”, it indicates that the target APN of the UE is authorized under any access network type.
  • the APN configuration parameter corresponding to the target APN of the UE includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate an access network currently accessed by the UE.
  • the target APN of the UE is authorized or not authorized, and the implementation manner is as follows:
  • APN-Configuration:: ⁇ AVP header:1430 10415>
  • the "Context-Identifier” is the file identifier corresponding to the target APN of the UE; the “Vowifi-Permission” is the current access of the APN (that is, the target APN of the UE) identified by the “Context-Identifier”.
  • the authorization identifier of the WLAN access network type for example, when the "Vowifi-Permission" corresponding to the target AP of the UE is 1, it indicates that the target APN of the UE is authorized under the currently accessed WLAN access network type.
  • the "Vowifi-Permission" corresponding to the target APN of the UE is 0, it indicates that the target APN of the UE is not authorized under the currently accessed WLAN access network type.
  • Vowifi-Permission in the scheme 3 is the authorization identifier corresponding to the WLAN.
  • the access network type currently accessed by the UE is other access network types, other authorization identifiers may also be corresponding. Its role is similar to “Vowifi-Permission" and will not be described here.
  • Step 509 The AAA server determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
  • the target APN of the UE is an IP Multimedia Subsystem (IMS)
  • the RAT-Permission in the APN-configuration of the IMS includes the WLAN access network type, or RAT- If the WLAN access network type is not included in the forbidden, or the vowifi-Permission indication is allowed under the WLAN access network type, it is determined that the IMS is authorized (that is, the authorization is successful); otherwise, it is determined that the IMS is not authorized (ie, the network The side rejects the UE from using IMS voice service under WLAN access).
  • IMS IP Multimedia Subsystem
  • the method may further include:
  • step 509 is performed to further determine whether the target APN of the UE is authorized under the access network type currently accessed by the UE;
  • step 509 is performed to further determine the target APN of the UE. (or wild card APN) Whether it is authorized under the access network type currently accessed by the UE.
  • Step 510 The AAA server returns an authentication and authorization answer (Authentication and authorization answer) message to the ePDG.
  • the authentication and authorization response message when the target APN of the UE is authorized, includes indication information that the target APN of the UE is allowed; otherwise, the authentication and authorization response message includes an authorization failure reason. the reason.
  • the authorization failure reason is used to indicate that the target APN authorization of the UE fails or that the target APN of the UE fails to be authorized under the currently accessed access network type.
  • the corresponding authorization failure reason is used to indicate that the target APN authorization of the UE fails; and the subscription data of the UE includes the The target APN of the UE, but the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, and the corresponding authorization failure reason is used to indicate that the target APN of the UE is in the The authorization fails under the access network type currently accessed by the UE.
  • Step 511 The ePDG sends an IKEV2 message to the UE according to the authentication and authorization response message.
  • the ePDG forwards an authorization failure reason to the UE by using the IKEV2 message.
  • the UE after the UE receives the authorization failure reason for indicating that the target APN of the UE fails to be authorized in the access network type currently accessed by the UE, sending, by the UE, another IKE_AUTH to the ePDG.
  • the request message, the IKE_AUTH request message includes the APN requested by the UE, and the APN requested by the UE is different from the target APN.
  • the Non 3GPP access registration response message is returned to the AAA server by using the HSS, where the Non 3GPP access registration response message includes subscription data of the UE, and the subscription data of the UE includes the UE Information of the authorized access network type corresponding to the target APN; the AAA server determines the UE according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE. Whether the target APN is authorized; the AAA server can simultaneously consider the target APN of the UE and the access network type currently accessed by the UE when performing the APN authorization judgment; and solve the operation in the prior art when performing APN authorization judgment The quotient cannot properly control the APN that the UE is allowed to access.
  • FIG. 6 is a flowchart of Embodiment 4 of an APN authorization method according to the present invention. As shown in FIG. 6, the method in this embodiment may include:
  • Step 601 The UE sends a connection request message for requesting a connection to the TWAN to the TWAN.
  • connection request message is an existing message between the UE and the TWAN, and details are not described herein again.
  • Step 602 The TWAN sends an authentication and authorization request message to the AAA server.
  • step 602 is similar to step 502, and details are not described herein again.
  • Step 603 The AAA server sends an authentication request message to the HSS.
  • step 603 is similar to step 503, and details are not described herein again.
  • Step 604 The HSS performs an authentication judgment according to the authentication request message.
  • step 604 is similar to step 504, and details are not described herein again.
  • Step 605 The HSS returns an authentication response message to the AAA server.
  • step 605 is similar to step 505, and details are not described herein again.
  • Step 606 When the authentication response message indicates that the UE fails to authenticate, the AAA server sends the authentication failure reason of the UE to the UE.
  • the AAA server may send the authentication failure reason of the UE to the UE by using an EAP-AKA or EAP-AKA' message.
  • the reason for the authentication failure of the UE may also be sent by the TWAN to the UE by adding a cause value in a message between the TWAN and the UE.
  • step 606 is similar to step 506, and details are not described herein again.
  • Step 607 When the authentication response message indicates that the UE is successfully authenticated, the AAA server sends a Non 3GPP access registration request message to the HSS.
  • the AAA server may perform an interaction with the UE according to the authentication vector included in the authentication response.
  • the authentication process of the UE may be performed before the sending, by the AAA server, the Non 3GPP access registration request message to the HSS.
  • step 607 is similar to step 507, and details are not described herein again.
  • Step 608 The HSS returns a Non 3GPP access registration response message to the AAA server.
  • step 608 is similar to step 508, and details are not described herein again.
  • Step 609 The AAA server returns an authentication and authorization response message to the TWAN.
  • the authentication and authorization response message includes subscription data of the UE.
  • Step 610 The UE sends a PDN CONNECTIVITY REQUEST message to the TWAN.
  • the PDN connection request message may include a target APN of the UE; or may not include the target APN of the UE.
  • the TWAN uses the default APN in the subscription data of the UE as the target APN of the UE.
  • the UE may perform an authentication interaction with the TWAN, and after the authentication succeeds, send the PDN connection request message to the TWAN. .
  • Step 611 The TWAN determines whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
  • the method for determining whether the target APN of the UE is authorized in the step 611 is similar to the method for determining whether the target APN of the UE is authorized in the step 509, and details are not described herein.
  • Step 612 The TWAN sends a PDN Connection Acceptance (CONNECTIVITY ACCEPT) message or a PDN CONNECTIVITY REJECT message to the UE.
  • CONNECTIVITY ACCEPT PDN Connection Acceptance
  • PDN CONNECTIVITY REJECT PDN CONNECTIVITY REJECT
  • the message when the TWAN sends a PDN connection reject message to the UE, the message includes an authorization failure reason, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the currently accessed access network type.
  • the UE receives the connection that is used to indicate that the target APN of the UE is currently accessed. And sending, by the TWAN, another PDN CONNECTIVITY REQUEST message, where the PDN CONNECTIVITY REQUEST message includes the APN requested by the UE, the APN requested by the UE, and the target APN. different.
  • the authentication and authorization response message is returned to the TWAN by the AAA server, where the authentication and authorization response message includes the subscription data of the UE, and the subscription data of the UE includes the target APN of the UE.
  • the TWAN determines whether the target APN of the UE is based on the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE Authorized; enables the TWAN to consider both the target APN of the UE and the access network type currently accessed by the UE when performing the APN authorization judgment; and solve the problem that the operator cannot perform the UE when performing the APN authorization judgment in the prior art. Allows access to the APN to be properly controlled.
  • FIG. 7 is a flowchart of Embodiment 5 of a method for granting an APN according to the present invention. As shown in FIG. 7, the method in this embodiment may include:
  • Step 701 The UE sends an IKE authentication request message to the ePDG.
  • step 701 is similar to step 501, and details are not described herein again.
  • Step 702 The ePDG sends an authentication and authorization request message to the AAA server.
  • step 702 is similar to step 502, and details are not described herein again.
  • Step 703 The AAA server sends an authentication request message to the HSS.
  • step 703 is similar to step 503, and details are not described herein again.
  • Step 704 The HSS performs an authentication judgment according to the authentication request message.
  • step 704 is similar to step 504, and details are not described herein again.
  • Step 705 The HSS returns an authentication response message to the AAA server.
  • step 705 is similar to step 505, and details are not described herein again.
  • Step 706 When the authentication response message indicates that the UE fails to be authenticated, the AAA server sends the authentication failure reason of the UE to the UE.
  • step 706 is similar to step 506, and details are not described herein again.
  • Step 707 When the authentication response message indicates that the UE is successfully authenticated, the AAA server sends a Non 3GPP access registration request message to the HSS.
  • step 707 is similar to step 507, and details are not described herein again.
  • Step 708 The HSS performs the UE according to an access network type currently accessed by the UE.
  • the subscription data is updated to obtain updated subscription data;
  • the subscription data of the UE includes at least one APN and information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes an access network type currently accessed by the UE. Information about authorized APNs.
  • the HSS may determine the subscription data of the UE according to the IMSI of the UE included in the Non 3GPP Access Registration Request message.
  • the manner in which the subscription data of the UE includes information about an authorized access network type corresponding to the at least one APN includes:
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
  • the APN corresponding to the APN configuration parameter is authorized or not authorized.
  • the scheme that the subscription data of the UE includes information of an authorized access network type corresponding to the at least one APN is as follows:
  • the APN configuration parameter (APN-Configuration) corresponding to each APN in the at least one APN includes an authorized access network type (RAT-Permission); when the authorized access network type is more than one, the authorization may be List of access network types.
  • RAT-Permission authorized access network type
  • the implementation is as follows:
  • APN-Configuration:: ⁇ AVP header:1430 10415>
  • the Context-Identifier is a file identifier corresponding to an APN; the RAT-Permission may include an authorized access network type corresponding to the APN identified by the Context-Identifier.
  • the "RAT-Permission” may include a "match-all” indication, indicating that the APN identified by the “Context-Identifier” is authorized under any access network type; or, when the configuration parameter When “RAT-Permission” is not included, it means that the APN identified by "Context-Identifier” under any access network type is authorized.
  • the APN configuration parameter corresponding to each APN of the at least one APN includes an unlicensed access network type (RAT-Forbidden), and the implementation manner is as follows:
  • APN-Configuration:: ⁇ AVP header:1430 10415>
  • the Context-Identifier is a file identifier corresponding to the APN.
  • the RAT-Forbidden may include the unlicensed access network type corresponding to the APN identified by the Context-Identifier.
  • RAT-Forbidden When RAT-Forbidden is not included in the configuration parameters, it means that the APN identified by the Context-Identifier is authorized under any access network type.
  • the scheme A the APN configuration parameter corresponding to each APN of the at least one APN includes an authorization identifier corresponding to the access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently accessed.
  • the APN corresponding to the APN configuration parameter is authorized or not authorized.
  • APN-Configuration:: ⁇ AVP header:1430 10415>
  • the Context-Identifier is a file identifier corresponding to the APN; the Vowifi-Permission is the corresponding authorization identifier of the currently accessed WLAN access network type of the APN identified by the Context-Identifier.
  • schemes A, B, and C are similar to the schemes 1, 2, and 3 in the method embodiment shown in FIG. 5, except that the schemes 1, 2, and 3 are directed to the target APN, and the scheme A is , B, and C are described for each of the at least one APN.
  • the updating according to the type of the access network that the UE is currently accessing, the subscription data of the UE, and obtaining the updated subscription data, including:
  • the HSS enters the subscription data of the UE according to the access network type currently accessed by the UE. After the screening, the updated subscription data is obtained, so that the updated subscription data only includes the information of the authorized APN of the UE under the currently accessed access network type.
  • the HSS may obtain an access network type that the UE currently accesses according to the authentication request sent by the AAA server to the HSS in step 703; or, in step 707, the AAA server sends
  • the Non 3GPP access registration request may also include an access network type currently accessed by the UE.
  • Step 709 The HSS returns a Non 3GPP access registration response message to the AAA server, where the Non 3GPP access registration response message includes the updated subscription data.
  • Step 710 The AAA server determines whether the target APN of the UE is authorized according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type.
  • the target APN of the UE belongs to the authorized APN of the access network type currently accessed by the UE, according to the information about the authorized APN of the UE in the currently accessed access network type, Determining, by the AAA server, that the target APN of the UE is authorized; or determining that the target APN of the UE does not belong to the UE according to the information of the authorized APN of the UE in the currently accessed access network type
  • the AAA server determines that the target APN of the UE is not authorized.
  • the authorized access network type corresponding to the at least one APN in step 708 does not include the access network type currently accessed by the UE, the UE included in the updated subscription data The information of the authorized APN in the currently accessed access network type is empty;
  • the updated subscription data is included in the updated subscription data.
  • the information about the authorized APN of the UE that is currently accessing the access network type is not empty (including the APN in the at least one APN), but does not include the target APN of the UE;
  • the information of the authorized APN of the UE that is included in the currently accessed access network type is not empty, and includes the target APN of the UE.
  • Step 711 The AAA server returns an authentication and authorization response message to the ePDG.
  • step 711 is similar to step 510, and details are not described herein again.
  • Step 712 The ePDG sends an IKEV2 message to the UE according to the authentication and authorization response message.
  • step 712 is similar to step 511, and details are not described herein again.
  • the Non 3GPP access registration response message is returned to the AAA server by the HSS, where the Non 3GPP access registration response message includes the contracted data after the UE is updated, and the updated subscription data includes the The information of the authorized APN of the UE in the currently accessed access network type; the AAA server determines the location according to the target APN of the UE and the authorized APN information of the UE in the currently accessed access network type. Whether the target APN of the UE is authorized or not; the problem that the operator cannot perform reasonable control on the APN allowed to be accessed by the UE when the APN authorization judgment is performed in the prior art is solved.
  • FIG. 8 is a flowchart of Embodiment 6 of a method for granting an APN according to the present invention. As shown in FIG. 8, the method in this embodiment may include:
  • Step 801 The UE sends a connection request message to the TWAN.
  • step 801 is similar to step 601, and details are not described herein again.
  • Step 802 The TWAN sends an authentication and authorization request message to the AAA server.
  • step 802 is similar to step 602, and details are not described herein again.
  • Step 803 The AAA server sends an authentication request message to the HSS.
  • step 803 is similar to step 603, and details are not described herein again.
  • Step 804 The HSS performs an authentication judgment according to the authentication request message.
  • step 804 is similar to step 604, and details are not described herein again.
  • Step 805 The HSS returns an authentication response message to the AAA server.
  • step 805 is similar to step 605, and details are not described herein again.
  • Step 806 When the authentication response message indicates that the UE fails to authenticate, the AAA server sends the authentication failure reason of the UE to the UE.
  • step 806 is similar to step 606, and details are not described herein again.
  • Step 807 When the authentication response message indicates that the UE is successfully authenticated, the AAA server sends a Non 3GPP access registration request message to the HSS.
  • step 807 is similar to step 607, and details are not described herein again.
  • Step 808 The HSS performs the UE according to an access network type currently accessed by the UE.
  • the subscription data is updated to obtain updated subscription data;
  • step 808 is similar to step 708, and details are not described herein again.
  • Step 809 The HSS returns a Non 3GPP access registration response message to the AAA server, where the Non 3GPP access registration response message includes the updated subscription data.
  • step 809 is similar to step 709, and details are not described herein again.
  • Step 810 The AAA server returns an authentication and authorization response message to the TWAN.
  • the authentication and authorization response message includes the updated subscription data.
  • Step 811 The UE sends a PDN CONNECTIVITY REQUEST message to the TWAN.
  • step 811 is similar to step 610, and details are not described herein again.
  • Step 812 The TWAN determines whether the target APN of the UE is authorized according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type.
  • the method for determining whether the target APN of the UE is authorized in the step 812 is similar to the method for determining whether the target APN of the UE is authorized in the step 710, and details are not described herein.
  • Step 813 The TWAN sends a PDN connection accept message or a PDN connection reject message to the UE.
  • step 813 is similar to step 612, and details are not described herein again.
  • the authentication and authorization response message is returned to the TWAN by the AAA server, where the authentication and authorization response message includes the updated subscription data of the UE, and the updated subscription data includes the UE
  • the TWAN determines the UE according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type. Whether the target APN is authorized or not; the problem that the operator cannot perform reasonable control on the APN that the UE is allowed to access when the APN authorization judgment is performed in the prior art is solved.
  • FIG. 9 is a schematic structural diagram of Embodiment 1 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 9, the device in this embodiment may include: a determining module 901 and an obtaining module 902.
  • the determining module 901 is configured to determine a target APN of the user equipment UE and an access network type currently accessed by the UE, and the acquiring module 902 is configured to obtain information about an authorized access network type corresponding to the target APN of the UE.
  • the determining module 901 is further configured to: according to the access network class currently accessed by the UE And the information of the authorized access network type corresponding to the target APN of the UE, determining whether the target APN of the UE is authorized.
  • the network device is an AAA server, or is a Non 3GPP access gateway.
  • the determining module 901 is specifically configured to:
  • Target APN is authorized
  • Determining the UE if it is determined that the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, according to the information of the authorized access network type corresponding to the target APN of the UE.
  • the target APN is not authorized.
  • the determining module 901 is further configured to determine that the subscription data of the UE includes a target APN of the UE.
  • the device may further include a first sending module 903;
  • the determining module 901 determines that the target APN of the UE is not authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE, the first sending module 903 And the reason for the authorization failure is sent to the UE, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
  • the obtaining module 902 is specifically configured to receive the subscription data of the UE sent by the user home system HSS, where the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE.
  • the manner in which the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
  • the device may further include: a second sending module 904;
  • the obtaining module 902 is further configured to receive an authentication response message sent by the HSS, where the authentication response message includes an authentication failure reason of the UE;
  • the second sending module 904 is configured to send an authentication failure reason of the UE to the UE.
  • the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 3, the method AAA side of the method embodiment shown in FIG. 5, and the TWAN side of the method embodiment shown in FIG. 6.
  • the implementation principle and the technical effect are similar. I won't go into details here.
  • FIG. 10 is a schematic structural diagram of Embodiment 2 of an APN-authorized device according to the present invention; the device is an HSS; as shown in FIG. 10, the device in this embodiment may include: a determining module 1001, an updating module 1002, and a sending module 1003.
  • the determining module 1001 is configured to determine an access network type that the user equipment UE is currently accessing, and the updating module 1002 is configured to update the subscription data of the UE according to the access network type currently accessed by the UE, Obtaining updated subscription data, where the subscription data of the UE includes at least one APN and information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes that the UE is currently The information about the authorized APN in the accessed access network type; the sending module 1003, configured to send the updated subscription data to the network device.
  • the manner in which the subscription data of the UE includes information about an authorized access network type corresponding to the at least one APN includes:
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
  • the APN corresponding to the APN configuration parameter is authorized or not authorized.
  • the device in this embodiment can be used to implement the technical solution of the method embodiment shown in FIG. 4 and the HSS side of the method embodiment shown in FIG. 7 and FIG. 8.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • FIG. 11 is a schematic structural diagram of Embodiment 3 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 11, the device in this embodiment may include: a receiving module 1101 and a determining module.
  • Block 1102. The receiving module 1101 is configured to receive updated subscription data sent by the user home system HSS, where the updated subscription data includes information about the authorized APN of the user equipment UE in the currently accessed access network type; 1102. Determine whether the target APN of the UE is authorized according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type.
  • the determining module 1102 is specifically configured to:
  • Determining if the target APN of the UE belongs to the authorized APN of the UE in the currently accessed access network type, according to the information of the authorized APN of the UE in the currently accessed access network type, The target APN of the UE is authorized; or if the target APN of the UE does not belong to the access network currently accessed by the UE according to the information of the authorized APN of the UE under the currently accessed access network type
  • the authorized APN under the type determines that the target APN of the UE is not authorized.
  • the device in this embodiment may be used to implement the technical solution on the network device side of the method embodiment shown in FIG. 7 to FIG. 8.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • FIG. 12 is a schematic structural diagram of Embodiment 4 of an APN-authorized device according to the present invention; the device is a UE; as shown in FIG. 12, the device in this embodiment may include: a receiving module 1201 and a sending module 1202.
  • the receiving module 1201 is configured to receive an authorization failure reason sent by the network device, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized in the access network type currently accessed by the UE; and the sending module 1202 And sending, by the gateway of the access network that the UE is currently accessing, a first connection request message, where the first connection request message includes an APN requested by the UE, and the APN requested by the UE is different from the target APN. .
  • the receiving module 1201 is further configured to receive an authentication failure reason of the UE sent by the network device, where the authentication failure reason includes: the public land mobile network VPLMN that the access network type does not allow or access
  • the sending module 1202 is further configured to send a second connection request message to a gateway different from a gateway of the access network currently accessed by the UE.
  • the device in this embodiment may be used to implement the technical solution on the UE side of the method embodiment shown in FIG. 5 to FIG. 8.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • the present invention also provides an APN-authorized system, including the network device and the UE described in Embodiment 1 of the APN-authorized device.
  • the UE may be the UE described in Embodiment 4 of the APN authorized device.
  • the system of the present embodiment can be used to implement the technical solution of the method embodiment shown in FIG. 5 or FIG. 6.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • the present invention further provides another APN-licensed system, including the network device and the UE described in Embodiment 3 of the device that is authorized by the APN-authorized device.
  • the UE may be the UE described in Embodiment 4 of the APN authorized device.
  • the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 7 or FIG. 8.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • FIG. 13 is a schematic structural diagram of Embodiment 5 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 13, the device in this embodiment may include: a processor 1301 and a receiver 1302.
  • the processor 1301 is configured to determine a target APN of the user equipment UE and an access network type that the UE currently accesses, and a receiver 1302, configured to acquire information about an authorized access network type corresponding to the target APN of the UE.
  • the processor 1301 is further configured to determine whether the target APN of the UE is authorized according to the access network type currently accessed by the UE and the information of the authorized access network type corresponding to the target APN of the UE.
  • the network device is an AAA server, or is a Non 3GPP access gateway.
  • the processor 1301 is specifically configured to:
  • Target APN is authorized
  • Determining the UE if it is determined that the access network type currently accessed by the UE does not belong to the authorized access network type corresponding to the target APN of the UE, according to the information of the authorized access network type corresponding to the target APN of the UE.
  • the target APN is not authorized.
  • the processor 1301 is further configured to determine that the subscription data of the UE includes a target APN of the UE.
  • the device may further include a transmitter 1303;
  • the transmitter 1303 uses The reason for the failure of the authorization is sent to the UE, and the reason for the failure of the authorization is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE.
  • the receiver 1302 is configured to receive the subscription data of the UE sent by the user home system HSS, where the subscription data of the UE includes information about an authorized access network type corresponding to the target APN of the UE.
  • the manner in which the subscription data of the UE includes the information of the authorized access network type corresponding to the target APN of the UE includes:
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorized access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to the target APN of the UE in the subscription data includes an authorization identifier corresponding to the access network type currently accessed by the UE, and the authorization identifier is used to indicate that the UE is currently connected to the access identifier. Under the network access type, the target APN of the UE is authorized or not authorized.
  • the receiver 1302 is further configured to receive an authentication response message sent by the HSS, where the authentication response message includes an authentication failure reason of the UE.
  • the transmitter 1303 is further configured to send, to the UE, an authentication failure reason of the UE.
  • the device in this embodiment may be used to implement the technical solution of the method embodiment shown in FIG. 3, the method AAA side of the method embodiment shown in FIG. 5, and the TWAN side of the method embodiment shown in FIG. 6.
  • the implementation principle and the technical effect are similar. I won't go into details here.
  • FIG. 14 is a schematic structural diagram of Embodiment 6 of an APN-authorized device according to the present invention; the device is an HSS; as shown in FIG. 14, the device in this embodiment may include: a processor 1401 and a transmitter 1402.
  • the processor 1401 is configured to determine an access network type that the user equipment UE is currently accessing, and the processor 1401 is further configured to update the subscription data of the UE according to the access network type currently accessed by the UE.
  • the subscription data of the UE includes at least one APN and information of an authorized access network type corresponding to the at least one APN; the updated subscription data includes the UE The information of the authorized APN in the access network type that is currently accessed; the sender 1402 is configured to send the updated subscription data to the network device.
  • the manner in which the subscription data of the UE includes information about an authorized access network type corresponding to the at least one APN includes:
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data contains the authorized access network type; or,
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an unlicensed access network type
  • the APN configuration parameter corresponding to each APN of the at least one APN in the subscription data includes an authorization identifier corresponding to an access network type currently accessed by the UE, where the authorization identifier is used to indicate that the UE is currently connected.
  • the APN corresponding to the APN configuration parameter is authorized or not authorized.
  • the device in this embodiment can be used to implement the technical solution of the method embodiment shown in FIG. 4 and the HSS side of the method embodiment shown in FIG. 7 and FIG. 8.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • FIG. 15 is a schematic structural diagram of Embodiment 7 of an APN-authorized device according to the present invention; the device is a network device; as shown in FIG. 15, the device in this embodiment may include: a receiver 1501 and a processor 1502.
  • the receiver 1501 is configured to receive updated subscription data sent by the user home system HSS, where the updated subscription data includes information about the authorized APN of the user equipment UE in the currently accessed access network type; 1502. Determine, according to the target APN of the UE and the information of the authorized APN of the UE in the currently accessed access network type, whether the target APN of the UE is authorized.
  • the processor 1502 is specifically configured to:
  • Determining if the target APN of the UE belongs to the authorized APN of the UE in the currently accessed access network type, according to the information of the authorized APN of the UE in the currently accessed access network type, The target APN of the UE is authorized; or if the target APN of the UE does not belong to the access network currently accessed by the UE according to the information of the authorized APN of the UE under the currently accessed access network type
  • the authorized APN under the type determines that the target APN of the UE is not authorized.
  • the device in this embodiment may be used to implement the technical solution on the network device side of the method embodiment shown in FIG. 7 to FIG. 8.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • FIG. 16 is a schematic structural diagram of Embodiment 8 of an APN-authorized device according to the present invention; the device is a UE; as shown in FIG. 16, the device in this embodiment may include: a receiver 1601, a processor 1602, and a transmitter 1603.
  • the receiver 1601 is configured to receive an authorization failure reason sent by the network device, where the authorization failure reason is used to indicate that the target APN of the UE fails to be authorized under the access network type currently accessed by the UE; and the processor 1602 For the reason for the authorization failure received by the receiver 1601, Generating a first connection request message, where the first connection request message includes an APN requested by the UE, the APN requested by the UE is different from the target APN, and a transmitter 1603, configured to generate the A connection request message is sent to the gateway of the access network currently accessed by the UE.
  • the receiver 1601 is further configured to receive, by the network device, an authentication failure reason of the UE, where the authentication failure reason includes: the public land mobile network VPLMN that the access network type does not allow or access
  • the processor 1602 is further configured to generate a second connection request message according to the authentication failure reason of the UE received by the receiver 1601, and the transmitter 1603 is further configured to use the second connection request generated by the processor 1602.
  • the message is sent to a gateway different from the gateway of the access network to which the UE is currently accessing.
  • the device in this embodiment may be used to implement the technical solution on the UE side of the method embodiment shown in FIG. 5 to FIG. 8.
  • the implementation principle and technical effects are similar, and details are not described herein again.
  • the aforementioned program can be stored in a computer readable storage medium.
  • the program when executed, performs the steps including the foregoing method embodiments; and the foregoing storage medium includes various media that can store program codes, such as a ROM, a RAM, a magnetic disk, or an optical disk.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例提供一种接入点名称授权的方法、装置及系统。一种APN授权的方法,包括:网络设备确定用户设备UE的目标APN及所述UE当前接入的接入网类型;所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息;所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。本发明解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。

Description

接入点名称授权的方法、装置及系统 技术领域
本发明实施例涉及通信技术,尤其涉及一种接入点名称(APN,Access Point Name)授权的方法、装置及系统。
背景技术
非第三代合作伙伴计划(Non 3GPP,Non 3rd Generation Partnership Project)接入网类型可以为码分多址(CDMA,Code Division Multiple Access)2000、全球微波互联接入(WiMAX,Worldwide Interoperability for Microwave Access)、无线局域网(WLAN,Wireless Local Area Network)等。
从接入网是否可信的角度进行划分,Non 3GPP接入网又被分为可信Non 3GPP接入网和非可信Non 3GPP接入网。当用户设备(UE,User Equipment)接入Non 3GPP接入网(例如,非可信Non 3GPP接入网)时,非可信Non 3GPP接入网关(例如演进的分组数据网关(ePDG,Evolved Packet Data Gateway)向鉴权与授权计费(AAA,Authentication,Authorization,and Accounting)服务器发送鉴权与授权请求(其中,鉴权与授权请求可以包括该UE请求接入的APN,若鉴权与授权请求中未包括APN时,使用该UE的签约数据中的默认APN);AAA服务器从归属签约服务器(HSS,Home Subscriber System)获取该UE的签约数据(签约数据中包括了该UE允许授权的APN);AAA服务器根据UE的签约数据及UE请求接入的APN,确定该UE请求接入的APN是否被授权;具体的,当签约数据中包括了UE请求接入的APN时,则确定UE请求接入的APN被授权。
但是,现有技术中,存在在进行APN授权判断时,运营商无法对UE允许授权的APN进行合理控制的问题。
发明内容
本发明实施例提供一种接入点名称授权的方法、装置及系统;用以解决现有技术中存在的在进行APN授权判断时,运营商无法对UE允许授权的 APN进行合理控制的问题。
第一方面,本发明实施例提供一种APN授权的方法,包括:
网络设备确定UE的目标APN及所述UE当前接入的接入网类型;
所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息;
所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
结合第一方面,在第一方面的第一种可能实现的方式中,所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权,包括:
如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN被授权;
或者,
如果根据所述UE的目标APN对应的授权接入网类型的信息确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN不被授权。
结合第一方面或第一方面的第一种可能实现的方式,在第一方面的第二种可能实现的方式中,所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权之前,还包括:
所述网络设备确定所述UE的签约数据包括所述UE的目标APN。
结合第一方面或第一方面的第一种至第二种任一种可能实现的方式,在第一方面的第三种可能实现的方式中,如果所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,所述方法还包括:
所述网络设备将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
结合第一方面或第一方面的第一种至第三种任一种可能实现的方式,在第一方面的第四种可能实现的方式中,所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息,包括:
所述网络设备接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
结合第一方面的第四种可能实现的方式,在第一方面的第五种可能实现的方式中,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
结合第一方面或第一方面的第一种至第五种任一种可能实现的方式,在第一方面的第六种可能实现的方式中,所述网络设备为AAA服务器,或者为Non 3GPP接入网关。
结合第一方面的第四种或第五种可能实现的方式,在第一方面的第七种可能实现的方式中,若所述网络设备为AAA服务器,则所述网络设备接收HSS发送的所述UE的签约数据之前,还包括:
所述网络设备接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;
所述网络设备将所述UE的鉴权失败原因发送至所述UE。
第二方面,本发明实施例提供一种APN授权的方法,包括:
HSS将用户设备UE的签约数据发送至网络设备,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息,以便所述网络设备根据所述UE的目标APN对应的授权接入网类型信息和所述UE当前接入的接入网类型,确定所述UE的目标APN是否被授权。
结合第二方面,在第二方面的第一种可能实现的方式中,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
第三方面,本发明实施例提供一种APN授权的方法,包括:
HSS确定用户设备UE当前接入的接入网类型;
所述HSS根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;
所述HSS将所述更新后的签约数据发送至网络设备。
结合第三方面,在第三方面的第一种可能实现的方式中,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
第四方面,本发明实施例提供一种APN授权的方法,包括:
网络设备接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN的信息;
所述网络设备根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
第五方面,本发明实施例提供一种APN授权的方法,包括:
UE接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述 UE的目标APN在所述UE当前接入的接入网类型下授权失败;
所述UE向所述UE当前接入的接入网的网关发送第一连接请求消息;所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
结合第五方面,在第五方面的第一种可能实现的方式中,还包括:
所述UE接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;
所述UE向与所述UE当前接入的接入网的网关不同的网关发送第二连接请求消息。
第六方面,本发明实施例提供一种APN授权的装置,所述装置为网络设备,所述装置包括:
确定模块,用于确定UE的目标APN及所述UE当前接入的接入网类型;
获取模块,用于获取所述UE的目标APN对应的授权接入网类型的信息;
所述确定模块,还用于根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
结合第六方面,在第六方面的第一种可能实现的方式中,所述处理模块具体用于:
如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN被授权;
或者,
如果根据所述UE的目标APN对应的授权接入网类型的信息确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN不被授权。
结合第六方面或第六方面的第一种可能实现的方式,在第六方面的第二种可能实现的方式中,所述确定模块还用于确定所述UE的签约数据包括所述UE的目标APN。
结合第六方面或第六方面的第一种至第二种任一种可能实现的方式,在第六方面的第三种可能实现的方式中,所述装置还包括:第一发送模块;
如果所述确定模块根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,则所述第一发送模块,用于将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
结合第六方面或第六方面的第一种至第三种任一种可能实现的方式,在第六方面的第四种可能实现的方式中,所述获取模块具体用于:
接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
结合第六方面的第四种可能实现的方式,在第六方面的第五种可能实现的方式中,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
结合第六方面或第六方面的第一种至第五种任一种可能实现的方式,在第六方面的第六种可能实现的方式中,所述网络设备为AAA服务器,或者为Non 3GPP接入网关。
结合第六方面的第四种或第五种可能实现的方式,在第六方面的第七种可能实现的方式中,所述装置还包括第二发送模块;
若所述网络设备为AAA服务器,则所述获取模块还用于接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;
所述第二发送模块,用于将所述UE的鉴权失败原因发送至所述UE。
第七方面,本发明实施例提供一种APN授权的装置,所述装置为HSS,所述装置包括:
发送模块,用于将用户设备UE的签约数据发送至网络设备,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息,以便 所述网络设备根据所述UE的目标APN对应的授权接入网类型信息和所述UE当前接入的接入网类型,确定所述UE的目标APN是否被授权。
结合第七方面,在第七方面的第一种可能实现的方式中,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
第八方面,本发明实施例提供一种APN的授权的装置,所述装置为HSS,所述装置包括:
确定模块,用于确定用户设备UE当前接入的接入网类型;
更新模块,用于根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;
发送模块,用于将所述更新后的签约数据发送至网络设备。
结合第八方面,在第八方面的第一种可能实现的方式中,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
第九方面,本发明实施例提供一种APN授权的装置,所述装置为网络设备,所述装置包括:
接收模块,用于接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN的信息;
确定模块,用于根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
第十方面,本发明实施例提供一种APN授权的装置,所述装置为UE,所述装置包括:
接收模块,用于接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败;
发送模块,用于向所述UE当前接入的接入网的网关发送第一连接请求消息;所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
结合第十方面,在第十方面的第一种可能实现的方式中,所述接收模块,还用于接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;
所述发送模块,还用于向与所述UE当前接入的接入网的网关不同的网关发送第二连接请求消息。
第十一方面,本发明实施例提供一种APN授权的系统,包括:第六方面或第六方面的第一种至第七种任一种所述的网络设备、第七方面或第七方面的第一种所述的HSS以及UE。
结合第十一方面,在第十一方面的第一种可能实现的方式中,所述UE如第十方面或第十方面的第一种所述。
第十二方面,本发明实施例提供一种APN授权的系统,包括:第八方面或第八方面的第一种所述的HSS、第九方面所述的网络设备及UE。
结合第十二方面,在第十二方面的第一种可能实现的方式中,所述UE如第八方面或第八方面的第一种中所述。
本发明提供一种接入点名称授权的方法、装置及系统,通过所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接 入网类型的信息,确定所述UE的目标APN是否被授权;使得网络设备在进行APN授权判断时,能够根据所述UE的目标APN对应的授权接入网类型信息,确定所述UE在当前接入的接入网类型下所述UE的目标APN是否被授权;使得网络设备在进行APN授权判断时能够同时考虑UE的目标APN及所述UE当前接入的接入网类型;从而使得运营商能够根据UE当前接入的接入网类型对UE在当前接入的接入网类型下允许接入的APN进行控制;解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本发明APN授权的方法的一应用场景的示意图;
图2为本发明APN授权的方法的另一应用场景的示意图;
图3为本发明APN授权的方法实施例一的流程图;
图4为本发明APN授权的方法实施例二的流程图;
图5为本发明APN授权的方法实施例三的流程图;
图6为本发明APN授权的方法实施例四的流程图;
图7为本发明APN授权的方法实施例五的流程图;
图8为本发明APN授权的方法实施例六的流程图;
图9为本发明APN授权的装置实施例一的结构示意图;
图10为本发明APN授权的装置实施例二的结构示意图;
图11为本发明APN授权的装置实施例三的结构示意图;
图12为本发明APN授权的装置实施例四的结构示意图;
图13为本发明APN授权的装置实施例五的结构示意图;
图14为本发明APN授权的装置实施例六的结构示意图;
图15为本发明APN授权的装置实施例七的结构示意图;
图16为本发明APN授权的装置实施例八的结构示意图。
具体实施方式
为使本发明实施例的目的、技术方案和优点更加清楚,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
图1为本发明APN授权的方法的一应用场景的示意图;如图1所示,该应用场景包括:UE、ePDG、AAA服务器及HSS。当UE接入非可信WLAN接入网时,ePDG向AAA服务器发送鉴权与授权请求消息(其中,鉴权与授权请求消息可以包括该UE请求接入的APN;若未包括时,可以使用该UE的签约数据中的默认APN);AAA服务器从HSS获得该UE的签约数据,该签约数据中包括了该UE允许授权的APN;当该签约数据中包括了该UE目标APN(当鉴权与授权请求消息中包括APN时,将该APN作为UE的目标APN;当未包括APN时,将签约数据中的默认APN作为UE的目标APN)时,AAA服务器确定该UE的目标APN被授权;否则,AAA服务器确定该UE的目标APN不被授权。由于该UE的签约数据中仅包括了该UE允许接入的APN,而未体现出该UE允许接入的APN与接入网类型之间的关系;因此,存在AAA服务器在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
图2为本发明APN授权的方法的另一应用场景的示意图;如图2所示,该应用场景包括:UE、可信的WLAN接入网络(TWAN,Trusted WLAN Access Network)、AAA服务器及HSS。当UE接入可信WLAN接入网时,TWAN从HSS获得该UE的签约数据,该签约数据中包括了该UE允许授权的APN;当该签约数据中包括了该UE的目标APN时,TWAN确定该UE的目标APN被授权;否则,TWAN确定该UE的目标APN不被授权。由于该UE的签约数据中仅包括了该UE允许接入的APN,而未体现出该UE允许接入的APN与接入网类型之间的关系;因此,存在TWAN在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
需要说明的是,图1及图2仅为本发明的方法在非3GPP接入网类型为 非可信WLAN及可信WALN下的示意图;本发明的方法可以应用于任何非3GPP接入网类型,如CDMA2000,WiMAX等。例如当非3GPP接入网类型为CDMA2000时,其对应的应用场景为将图2所示的TWAN网元替换为高速分组数据(HRPD,High Rate Packet Data)服务网关(HS-GW,HRPD Serving Gateway),由HS-GW进行APN授权判断。
需要说明的是,本发明中Non 3GPP接入网关可以包括ePDG、TWAN、HS-GW等。
图3为本发明APN授权的方法实施例一的流程图,如图3所示,本实施例的方法可以包括:
步骤301、网络设备确定用户设备UE的目标APN及所述UE当前接入的接入网类型;
可选的,所述网络设备可以为AAA服务器、或Non 3GPP接入网关。
步骤302、所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息;
需要说明的是,授权接入网类型为允许UE接入的接入网类型。
步骤303、所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
可选的,步骤303具体可以为:
如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN被授权;
或者,
如果根据所述UE的目标APN对应的授权接入网类型的信息确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN不被授权。
现有技术中,UE的签约数据中包括了该UE允许接入的APN;当UE的签约数据中包括了该UE的目标APN时,则确定该UE的目标APN被授权;否则,确定该UE的目标APN不被授权。本发明中,所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的 信息,确定所述UE的目标APN是否被授权。
现有技术中,由于UE的签约数据中仅包括了该UE允许接入的APN(也即,被授权的APN),而未体现出该UE允许接入的APN与接入网类型之间的关系;因此存在在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。本发明中,通过所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权;使得网络设备在进行APN授权判断时,能够根据所述UE的目标APN对应的授权接入网类型信息,确定所述UE在当前接入的接入网类型下所述UE的目标APN是否被授权;使得网络设备在进行APN授权判断时能够同时考虑UE的目标APN及所述UE当前接入的接入网类型;从而使得运营商能够根据UE当前接入的接入网类型对UE在当前接入的接入网类型下允许接入的APN进行控制;解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
图4为本发明APN授权的方法实施例二的流程图,如图4所示,本实施例的方法可以包括:
步骤401、HSS确定UE当前接入的接入网类型;
步骤402、所述HSS根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;
需要说明的是,所述授权APN为允许UE接入的APN。
步骤403、所述HSS将所述更新后的签约数据发送至网络设备。
可选的,所述网络设备可以为AAA服务器、或Non 3GPP接入网关。
现有技术中,HSS存储的UE的签约数据中包括了所述UE允许接入的APN,HSS将签约数据发送至网络设备,以使网络设备进行APN授权判断。本发明中,所述HSS根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的 信息;所述HSS将所述更新后的签约数据发送至网络设备。
现有技术中,由于UE的签约数据中仅包括了所述UE允许接入的APN,而未体现出该UE允许接入的APN与接入网类型之间的关系;因此存在在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。本发明中,通过所述HSS根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;所述HSS将所述更新后的签约数据发送至网络设备;使得HSS发送至网络设备的签约数据中包括了UE在当前接入的接入网类型下的授权APN的信息;使得网络设备能够根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权;解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
图5为本发明APN授权的方法实施例三的流程图,如图5所示,本实施例的方法可以包括:
步骤501、UE向ePDG发送因特网密钥交换(IKE,Internet Key Exchange)鉴权请求消息(IKE_AUTH request message);
其中,所述IKE鉴权请求消息可以包括所述UE的目标APN;或者,所述IKE鉴权请求消息也可以不包括所述UE的目标APN。当所述IKE鉴权请求消息不包括UE的目标APN时,AAA服务器将该UE的签约数据中的默认APN作为所述UE的目标APN。
可选的,在所述UE向ePDG发送IKE鉴权请求消息之前,还可以包括所述UE向所述ePDG发送IKE初始请求消息(IKE_SA_INIT request message)。
步骤502、所述ePDG向AAA服务器发送鉴权与授权请求(Authentication and authorization request)消息;
其中,所述鉴权与授权请求消息可以包括UE当前接入的接入网类型、所述UE的标识及网络标识。
可选的,所述UE的标识可以为网络接入标识(NAI,Network Access ID), 所述NAI中包含所述UE的用户永久标识(IMSI,International Mobile Subscriber Identity);网络标识可以为访问的公共陆地移动网络(VPLMN,Visited Public Land Mobile Network)信息。
需要说明的是,所述UE当前接入的接入网类型可以由所述ePDG获取,由于ePDG可以为非可信WLAN的非3GPP接入网关,所以所述UE当前接入的接入网类型可以为非可信WLAN或WLAN。
步骤503、所述AAA服务器向HSS发送鉴权请求(Authentication request)消息;
其中,所述鉴权请求消息可以包括所述UE的IMSI、网络标识、所述UE当前接入的接入网类型。
需要说明的是,AAA服务器向HSS发送鉴权请求之前还可以包括:AAA服务器根据鉴权与授权请求消息中包括的UE的IMSI,判断AAA服务器中是否存储了所述UE的上下文信息(包括签约数据及鉴权向量);若AAA服务器确定自身已存储了所述UE的上下文信息,则不再向HSS发送鉴权请求消息(即,不再执行步骤503),而直接执行步骤509。
步骤504、所述HSS根据所述鉴权请求消息进行鉴权判断;
其中,所述鉴权判断可以包括:1)判断所述UE的签约数据是否存在;2)判断是否允许所述UE接入当前网络,即所述UE当前接入的接入网类型是否为受限的网络类型;3)判断VPLMN指示的网络是否允许所述UE接入;4)是否存在所述UE相关的Non 3GPP签约数据等。
步骤505,所述HSS向所述AAA服务器返回鉴权响应(Authentication response)消息;
若所述HSS鉴权成功(例如,所述UE的签约数据存在,允许所述UE接入当前网络,允许所述UE接入VPLMN,且所述UE的Non 3GPP签约数据存在),则所述鉴权响应消息包括所述UE的鉴权向量。否则,所述鉴权响应消息包括所述UE的鉴权失败原因。
其中,当判定所述UE的签约数据不存在时,对应的鉴权失败原因可以为“用户不存在”,相应的鉴权失败原因值可以为“DIAMETER_ERROR_USER_UNKNOWN”;
当判定不允许UE接入当前网络时,对应的鉴权失败原因可以为“接入 类型不允许”,相应的鉴权失败原因值可以为“DIAMETER_ERROR_RAT_TYPE_NOT_ALLOWED”;
当判定不允许所述UE接入VPLMN时,对应的鉴权失败原因可以为“VPLMN不允许”,相应的鉴权失败原因值可以为“DIAMETER_ERROR_ROAMING_NOT_ALLOWED”;
当判定所述UE的Non 3GPP签约数据不存在时,对应的鉴权失败原因可以为“Non 3GPP签约数据不存在”,相应的鉴权失败原因值可以为“DIAMETER_ERROR_USER_NO_NON_3GPP_SUBSCRIPTON”。
需要说明的是,签约数据可以包括Non 3GPP签约数据。
步骤506、当鉴权响应消息指示所述UE鉴权失败时,则所述AAA服务器将所述UE的鉴权失败原因发送至所述UE。
可选的,AAA服务器可以通过可扩展认证协议(EAP,Extensible Authentication Protocol)-认证和密钥协商协议(AKA,Authentication and Key Agreement Protocol)或EAP-AKA’消息将所述UE的鉴权失败原因发送至所述UE。
需要说明的是,所述EAP-AKA或EAP-AKA’消息可以是所述AAA服务器通过鉴权与授权响应(Authentication and Authorization Answer)消息发送至所述ePDG,再由所述ePDG通过IKEv2消息发送至所述UE。即,鉴权与授权响应消息及IKEv2中包含EAP-AKA或EAP-AKA’消息。
可选的,所述UE的鉴权失败原因也可以通过在IKEv2消息中新增原因值的方式由所述ePDG发送至所述UE。即,所述AAA服务器向所述ePDG发送的鉴权与授权响应消息中携带所述AAA服务器从所述HSS获取的所述UE的鉴权失败原因,然后所述ePDG将所述UE的鉴权失败原因通过IKEv2消息中新增的原因值发送给所述UE。
所述UE接收到所述UE的鉴权失败原因后,当所述鉴权失败原因为接入网类型不允许或VPLMN不允许时,则向不同于所述ePDG的接入网关发送IKE_AUTH request消息。
需要说明的是,IKE_AUTH request message消息可以被认为是连接请求消息。
步骤507、当鉴权响应消息指示所述UE鉴权成功时,所述AAA服务器 向所述HSS发送Non 3GPP访问注册请求(Non 3GPP IP Access Registration request)消息;
其中,所述Non 3GPP访问注册请求消息包括所述UE的IMSI。
可选的,所述AAA服务器向所述HSS发送Non 3GPP访问注册请求之前,还可以包括:所述AAA服务器根据所述鉴权响应中包括的鉴权向量,与所述UE交互完成对所述UE的鉴权过程。
步骤508、所述HSS向所述AAA服务器返回Non 3GPP访问注册响应(Non 3GPP IP Access Registration response)消息;
其中,所述Non 3GPP访问注册响应消息包括所述UE的签约数据。
具体的,所述HSS根据所述Non 3GPP访问注册请求消息中包括的所述UE的IMSI查找所述UE的签约数据,并通过Non 3GPP访问注册响应消息向所述AAA服务器返回所述UE的签约数据。
可选的,所述UE的签约数据包括所述UE的目标APN及所述UE的目标APN对应的授权接入网类型的信息。
可选的,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
需要说明的是,授权接入网类型为允许UE接入的接入网类型;非授权接入网类型为不允许UE接入的接入网类型。
可选的,所述APN配置参数中的接入网类型,可以包括下述接入网类型中的至少一个:
WLAN、可信WLAN、非可信WLAN、CDMA2000、WiMAX、UMTS地面无线接入网(UTRAN,UMTS Terrestrial Radio Access Network)、GSM EDGE无线接入网(GERAN,GSM EDGE Radio Access Network),演进的 通用陆基无线接入网(EUTRAN,Evolved Universal Terrestrial Radio Access Network)。
可选的,WLAN接入网类型还可以包括:可信WLAN和非可信WLAN。
例如,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方案如下:
方案1:所述UE的目标APN对应的APN配置参数(APN-Configuration)中包含授权接入网类型(RAT-Permission);当授权接入网类型不止一个时,为授权接入网类型列表。实现方式如下:
APN-Configuration::=<AVP header:1430 10415>
{Context-Identifier}  //文件标识
{PDN-Type}            //PDN类型
[RAT-Permission]
其中,“Context-Identifier”为所述UE的目标APN对应的文件标识;“RAT-Permission”可以包括“Context-Identifier”标识的APN(也即目标APN)对应的授权接入网类型;当“RAT-Permission”中包含所述UE当前接入的接入网类型时,则确定所述UE的目标APN被授权。
或者,“RAT-Permission”中可以包括“match-all”指示,表示在任何接入网类型下目标APN都被授权;或者,当配置参数中不包括“RAT-Permission”时,表示在任何接入网类型下目标APN都被授权。
方案2:所述UE的目标APN对应的APN配置参数中包含非授权接入网类型(RAT-Forbidden),实现方式如下:
APN-Configuration::=<AVP header:1430 10415>
{Context-Identifier}  //文件标识
{PDN-Type}            //PDN类型
[RAT-Forbidden]
其中,“Context-Identifier”为所述UE的目标APN对应的文件标识;“RAT-Forbidden”可以包括该“Context-Identifier”标识的APN(也即所述UE的目标APN)对应的非授权接入网类型;当所述UE的目标APN对应的“RAT-Forbidden”中不包含所述UE当前接入的接入网类型时,确定所述UE的目标APN被授权。
可选的,当配置参数中不包括“RAT-Forbidden”时,表示在任何接入网类型下UE的目标APN都被授权。
方案3:所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权,实现方式如下:
APN-Configuration::=<AVP header:1430 10415>
{Context-Identifier}  //文件标识
{PDN-Type}            //PDN类型
[Vowifi-Permission]
其中,“Context-Identifier”为所述UE的目标APN对应的文件标识;“Vowifi-Permission”为该“Context-Identifier”标识的APN(也即,所述UE的目标APN)的当前接入的WLAN接入网类型下的授权标识;例如,当所述UE的目标AP对应的“Vowifi-Permission”为1时,表示所述UE的目标APN在当前接入的WLAN接入网类型下被授权;当所述UE的目标APN对应的“Vowifi-Permission”为0时,表示所述UE的目标APN在当前接入的WLAN接入网类型下不被授权。
需要说明的是,方案3中“Vowifi-Permission”为WLAN对应的授权标识,在方案3中当UE当前接入的接入网类型为其他接入网类型时,也可以对应其他的授权标识,其作用与“Vowifi-Permission”类似,在此不再赘述。
步骤509、所述AAA服务器根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权;
例如,若UE当前接入网类型为WLAN、所述UE的目标APN为IP多媒体系统(IMS,IP Multimedia Subsystem),且IMS的APN-configuration中RAT-Permission包括WLAN接入网类型,或RAT-forbidden中不包括WLAN接入网类型,或vowifi-Permission指示在WLAN接入网类型下被允许,则确定IMS被授权(也即,授权成功);否则,确定IMS不被授权(也即,网络侧拒绝所述UE从在WLAN接入下使用IMS语音服务)。
需要说明的是,步骤509之前还可以包括:
当确定所述UE的目标APN不包括在所述UE的签约数据中时,则直接确定所述UE的目标APN不被授权,并不再执行步骤509,转而执行步骤510;当所述UE的签约数据包括所述UE的目标APN时,则执行步骤509进一步确定所述UE的目标APN在UE当前接入的接入网类型下是否被授权;
或者,当确定所述UE的目标APN不包括在所述UE的签约数据中且签约数据中也不包含野卡(wild card)APN时,则直接确定所述UE的目标APN不被授权,并不再执行步骤509,转而执行步骤510;当所述UE的签约数据包括所述UE的目标APN(或签约数据中包含wild card APN)时,则执行步骤509进一步确定所述UE的目标APN(或wild card APN)在UE当前接入的接入网类型下是否被授权。
步骤510、所述AAA服务器向所述ePDG返回鉴权与授权响应(Authentication and authorization answer)消息;
其中,当所述UE的目标APN被授权时,则所述鉴权与授权响应消息包括所述UE的目标APN被允许的指示信息;否则,所述鉴权与授权响应消息包括授权失败原因的原因。
可选的,所述授权失败原因用于指示所述UE的目标APN授权失败或者所述UE的目标APN在当前接入的接入网类型下授权失败。
可选的,当所述UE的签约数据中不包括所述UE的目标APN时,对应的授权失败原因用于指示所述UE的目标APN授权失败;当所述UE的签约数据中包括所述UE的目标APN,但是所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型时,对应的授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
步骤511、所述ePDG根据所述鉴权及授权响应消息向所述UE发送IKEV2消息。
当所述鉴权及授权响应消息包括所述UE的目标APN授权失败原因时,所述ePDG通过所述IKEV2消息将授权失败原因转发至所述UE。
可选的,所述UE接收到所述用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败的授权失败原因后,则向所述ePDG发送另一IKE_AUTH request消息,该IKE_AUTH request消息中包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
本实施例中,通过HSS向所述AAA服务器返回Non 3GPP访问注册响应消息;其中,所述Non 3GPP访问注册响应消息包括所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息;所述AAA服务器根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权;使得AAA服务器在进行APN授权判断时,能够同时考虑UE的目标APN及所述UE当前接入的接入网类型;解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
图6为本发明APN授权的方法实施例四的流程图,如图6所示,本实施例的方法可以包括:
步骤601、UE向TWAN发送用于向TWAN请求连接的连接请求消息;
需要说明的是,该连接请求消息为所述UE与所述TWAN之间的现有消息,在此不再赘述。
步骤602、所述TWAN向AAA服务器发送鉴权与授权请求消息;
需要说明的是,步骤602与步骤502类似,在此不再赘述。
步骤603、所述AAA服务器向HSS发送鉴权请求消息;
需要说明的是,步骤603与步骤503类似,在此不再赘述。
步骤604、所述HSS根据所述鉴权请求消息进行鉴权判断;
需要说明的是,步骤604与步骤504类似,在此不再赘述。
步骤605,所述HSS向所述AAA服务器返回鉴权响应消息;
需要说明的是,步骤605与步骤505类似,在此不再赘述。
步骤606、当鉴权响应消息指示所述UE鉴权失败时,则所述AAA服务器将所述UE的鉴权失败原因发送至所述UE;
可选的,AAA服务器可以通过EAP-AKA或EAP-AKA’消息将所述UE的鉴权失败原因发送至所述UE。
可选的,所述UE的鉴权失败原因也可以通过在TWAN与UE之间的消息中新增原因值的方式由所述TWAN发送至所述UE。
需要说明的是,步骤606与步骤506类似,在此不再赘述。
步骤607、当鉴权响应消息指示所述UE鉴权成功时,所述AAA服务器向所述HSS发送Non 3GPP访问注册请求消息;
可选的,所述AAA服务器向所述HSS发送Non 3GPP访问注册请求消息之前,还可以包括:所述AAA服务器根据所述鉴权响应中包括的鉴权向量,与所述UE交互完成对所述UE的鉴权过程。
需要说明的是,步骤607与步骤507类似,在此不再赘述。
步骤608、所述HSS向所述AAA服务器返回Non 3GPP访问注册响应消息;
需要说明的是,步骤608与步骤508类似,在此不再赘述。
步骤609、所述AAA服务器向所述TWAN返回鉴权与授权响应消息;
其中,所述鉴权与授权响应消息包括所述UE的签约数据。
步骤610、所述UE向所述TWAN发送公用数据网(PDN,Public Data Network)连接请求(PDN CONNECTIVITY REQUEST)消息;
可选的,所述PDN连接请求消息可以包括UE的目标APN;或者,也可以不包括所述UE的目标APN。当所述PDN连接请求中不包括所述UE的目标APN时,所述TWAN将该UE的签约数据中的默认APN作为所述UE的目标APN。
需要说明的是,步骤610与步骤607~步骤609之间并没有先后顺序关系,所述UE可以在与所述TWAN进行鉴权交互,鉴权成功后向所述TWAN发送所述PDN连接请求消息。
步骤611、所述TWAN根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权;
需要说明的是,步骤611中TWAN确定所述UE的目标APN是否被授权的方法,与步骤509中AAA服务器确定所述UE的目标APN是否被授权的方法类似,在此不再赘述。
步骤612、所述TWAN向所述UE发送PDN连接接受(CONNECTIVITY ACCEPT)消息或PDN连接拒绝(PDN CONNECTIVITY REJECT)消息;
可选的,当TWAN向UE发送PDN连接拒绝消息时,该消息中包括授权失败原因,所述授权失败原因用于指示所述UE的目标APN在当前接入的接入网类型下授权失败。
可选的,所述UE接收到用于指示所述UE的目标APN在当前接入的接 入网类型下授权失败的所述授权失败原因后,向所述TWAN发送另一PDN CONNECTIVITY REQUEST消息,该PDN CONNECTIVITY REQUEST消息中包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
本实施例中,通过AAA服务器向TWAN返回鉴权与授权响应消息;其中,所述鉴权与授权响应消息包括所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息;所述TWAN根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权;使得TWAN在进行APN授权判断时,能够同时考虑UE的目标APN及所述UE当前接入的接入网类型;解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
图7为本发明APN授权的方法实施例五的流程图,如图7所示,本实施例的方法可以包括:
步骤701、UE向ePDG发送IKE鉴权请求消息;
需要说明的是,步骤701与步骤501类似,在此不再赘述。
步骤702、所述ePDG向AAA服务器发送鉴权与授权请求消息;
需要说明的是,步骤702与步骤502类似,在此不再赘述。
步骤703、所述AAA服务器向HSS发送鉴权请求消息;
需要说明的是,步骤703与步骤503类似,在此不再赘述。
步骤704、所述HSS根据所述鉴权请求消息进行鉴权判断;
需要说明的是,步骤704与步骤504类似,在此不再赘述。
步骤705,所述HSS向所述AAA服务器返回鉴权响应消息;
需要说明的是,步骤705与步骤505类似,在此不再赘述。
步骤706、当鉴权响应消息指示所述UE鉴权失败时,则所述AAA服务器将所述UE的鉴权失败原因发送至所述UE。
需要说明的是,步骤706与步骤506类似,在此不再赘述。
步骤707、当鉴权响应消息指示所述UE鉴权成功时,所述AAA服务器向所述HSS发送Non 3GPP访问注册请求消息;
需要说明的是,步骤707与步骤507类似,在此不再赘述。
步骤708、所述HSS根据所述UE当前接入的接入网类型,对所述UE 的签约数据进行更新,获得更新后的签约数据;
其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息。
可选的,所述HSS可以根据所述Non 3GPP访问注册请求消息中包括的所述UE的IMSI确定所述UE的签约数据。
可选的,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
例如,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方案如下:
方案A:所述至少每一个APN中的每一个APN对应的APN配置参数(APN-Configuration)中包含授权接入网类型(RAT-Permission);当授权接入网类型不止一个时,可以为授权接入网类型列表。实现方式如下:
APN-Configuration::=<AVP header:1430 10415>
{Context-Identifier}  //文件标识
{PDN-Type}            //PDN类型
[RAT-Permission]
其中,“Context-Identifier”为一个APN对应的文件标识;“RAT-Permission”可以包括“Context-Identifier”标识的APN对应的授权接入网类型。
或者,“RAT-Permission”中可以包括“match-all”指示,表示在任何接入网类型下“Context-Identifier”标识的APN都被授权;或者,当配置参数 中不包括“RAT-Permission”时,表示在任何接入网类型下“Context-Identifier”标识的APN都被授权。
方案B:所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型(RAT-Forbidden),实现方式如下:
APN-Configuration::=<AVP header:1430 10415>
{Context-Identifier}  //文件标识
{PDN-Type}            //PDN类型
[RAT-Forbidden]
其中,“Context-Identifier”为一个APN对应的文件标识;“RAT-Forbidden”可以包括该“Context-Identifier”标识的APN对应的非授权接入网类型。
当配置参数中不包括“RAT-Forbidden”时,表示在任何接入网类型下该“Context-Identifier”标识的APN都被授权。
方案C:所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权,实现方式如下:
APN-Configuration::=<AVP header:1430 10415>
{Context-Identifier}  //文件标识
{PDN-Type}            //PDN类型
[Vowifi-Permission]
其中,“Context-Identifier”为一个APN对应的文件标识;“Vowifi-Permission”为该“Context-Identifier”标识的APN的当前接入的WLAN接入网类型下对应的授权标识。
需要说明的是,方案A、B、C与图5所示方法实施例中的方案1、2、3类似,区别仅在于方案1、2、3针对的是目标APN进行说明的,而方案A、B、C是针对至少一个APN中的每一个APN进行说明的。
可选的,所述根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据,包括:
所述HSS根据所述UE当前接入的接入网类型对所述UE的签约数据进 行筛选,得到更新后的签约数据,使得更新后的签约数据仅包括所述UE在当前接入的接入网类型下的授权APN的信息。
需要说明的是,所述HSS可以根据步骤703中所述AAA服务器向所述HSS发送的鉴权请求,获得所述UE当前接入的接入网类型;或者,步骤707中所述AAA服务器发送的Non 3GPP访问注册请求中也可以包括所述UE当前接入的接入网类型。
步骤709、所述HSS向所述AAA服务器返回Non 3GPP访问注册响应消息;其中,所述Non 3GPP访问注册响应消息包括所述更新后的签约数据。
步骤710、所述AAA服务器根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权;
具体的,如果根据所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN属于所述UE在当前接入的接入网类型下的授权APN,则所述AAA服务器确定所述UE的目标APN被授权;或者,如果根据所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN不属于所述UE在当前接入的接入网类型下的授权APN,则所述AAA服务器确定所述UE的目标APN不被授权。
需要说明的是,当步骤708中与所述至少一个APN对应的授权接入网类型不包括所述UE当前接入的接入网类型时,所述更新后的签约数据中包括的所述UE在当前接入的接入网类型下的授权APN的信息为空;
当与所述至少一个APN对应的授权接入网类型包括所述UE当前接入的接入网类型、所述至少一个APN不包括所述UE的目标APN时,所述更新后的签约数据中包括的所述UE在当前接入的接入网类型下的授权APN的信息不为空(包括所述至少一个APN中的APN),但是并不包括所述UE的目标APN;
当所述至少一个APN包括所述UE的目标APN、且与所述UE的目标APN对应的授权接入网类型包括所述UE当前接入的接入网类型时,所述更新后的签约数据中包括的所述UE在当前接入的接入网类型下的授权APN的信息不为空,且包括所述UE的目标APN。
步骤711、所述AAA服务器向所述ePDG返回鉴权与授权响应消息;
需要说明的是,步骤711与步骤510类似,在此不再赘述。
步骤712、所述ePDG根据所述鉴权及授权响应消息向所述UE发送IKEV2消息。
需要说明的是,步骤712与步骤511类似,在此不再赘述。
本实施例中,通过HSS向所述AAA服务器返回Non 3GPP访问注册响应消息;其中,所述Non 3GPP访问注册响应消息包括所述UE更新后的签约数据,所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;所述AAA服务器根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权;解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
图8为本发明APN授权的方法实施例六的流程图,如图8所示,本实施例的方法可以包括:
步骤801、UE向TWAN发送连接请求消息;
需要说明的是,步骤801与步骤601类似,在此不再赘述。
步骤802、所述TWAN向AAA服务器发送鉴权与授权请求消息;
需要说明的是,步骤802与步骤602类似,在此不再赘述。
步骤803、所述AAA服务器向HSS发送鉴权请求消息;
需要说明的是,步骤803与步骤603类似,在此不再赘述。
步骤804、所述HSS根据所述鉴权请求消息进行鉴权判断;
需要说明的是,步骤804与步骤604类似,在此不再赘述。
步骤805,所述HSS向所述AAA服务器返回鉴权响应消息;
需要说明的是,步骤805与步骤605类似,在此不再赘述。
步骤806、当鉴权响应消息指示所述UE鉴权失败时,则所述AAA服务器将所述UE的鉴权失败原因发送至所述UE;
需要说明的是,步骤806与步骤606类似,在此不再赘述。
步骤807、当鉴权响应消息指示所述UE鉴权成功时,所述AAA服务器向所述HSS发送Non 3GPP访问注册请求消息;
需要说明的是,步骤807与步骤607类似,在此不再赘述。
步骤808、所述HSS根据所述UE当前接入的接入网类型,对所述UE 的签约数据进行更新,获得更新后的签约数据;
需要说明的是,步骤808与步骤708类似,在此不再赘述。
步骤809、所述HSS向所述AAA服务器返回Non 3GPP访问注册响应消息;其中,所述Non 3GPP访问注册响应消息包括所述更新后的签约数据;
需要说明的是,步骤809与步骤709类似,在此不再赘述。
步骤810、所述AAA服务器向所述TWAN返回鉴权与授权响应消息;
其中,所述鉴权与授权响应消息包括所述更新后的签约数据。
步骤811、所述UE向所述TWAN发送PDN连接请求(PDN CONNECTIVITY REQUEST)消息;
需要说明的是,步骤811与步骤610类似,在此不再赘述。
步骤812、所述TWAN根据所述UE的目标APN及所述UE在当前接入的接入网类型的授权APN的信息,确定所述UE的目标APN是否被授权;
需要说明的是,步骤812中TWAN确定所述UE的目标APN是否被授权的方法,与步骤710中AAA服务器确定所述UE的目标APN是否被授权的方法类似,在此不再赘述。
步骤813、所述TWAN向所述UE发送PDN连接接受消息或PDN连接拒绝消息;
需要说明的是,步骤813与步骤612类似,在此不再赘述。
本实施例中,通过AAA服务器向TWAN返回鉴权与授权响应消息;其中,所述鉴权与授权响应消息包括所述UE的更新后签约数据,所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;所述TWAN根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权;解决了现有技术中在进行APN授权判断时,运营商无法对UE允许接入的APN进行合理控制的问题。
图9为本发明APN授权的装置实施例一的结构示意图;所述装置为网络设备;如图9所示,本实施例的装置可以包括:确定模块901和获取模块902。其中,确定模块901,用于确定用户设备UE的目标APN及所述UE当前接入的接入网类型;获取模块902,用于获取所述UE的目标APN对应的授权接入网类型的信息;确定模块901,还用于根据所述UE当前接入的接入网类 型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
可选的,所述网络设备为AAA服务器,或者为Non 3GPP接入网关。
可选的,确定模块901具体用于:
如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN被授权;
或者,
如果根据所述UE的目标APN对应的授权接入网类型的信息确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN不被授权。
可选的,确定模块901,还用于确定所述UE的签约数据包括所述UE的目标APN。
可选的,所述装置还可以包括第一发送模块903;
如果确定模块901根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,则第一发送模块903,用于将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
可选的,获取模块902,具体用于接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
可选的,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
进一步可选的,所述装置还可以包括:第二发送模块904;
若所述网络设备为AAA服务器,则获取模块902还用于接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;
第二发送模块904,用于将所述UE的鉴权失败原因发送至所述UE。
本实施例的装置,可以用于执行图3所示方法实施例、图5所示方法实施例AAA侧、图6所示方法实施例TWAN侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
图10为本发明APN授权的装置实施例二的结构示意图;所述装置为HSS;如图10所示,本实施例的装置可以包括:确定模块1001、更新模块1002和发送模块1003。其中,确定模块1001,用于确定用户设备UE当前接入的接入网类型;更新模块1002,用于根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;发送模块1003,用于将所述更新后的签约数据发送至网络设备。
可选的,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
本实施例的装置,可以用于执行图4所示方法实施例、图7及图8所示方法实施例HSS侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
图11为本发明APN授权的装置实施例三的结构示意图;所述装置为网络设备;如图11所示,本实施例的装置可以包括:接收模块1101和确定模 块1102。其中,接收模块1101,用于接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN的信息;确定模块1102,用于根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
可选的,确定模块1102,具体用于:
如果根据所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN属于所述UE在当前接入的接入网类型下的授权APN,则确定所述UE的目标APN被授权;或者,如果根据所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN不属于所述UE在当前接入的接入网类型下的授权APN,则确定所述UE的目标APN不被授权。
本实施例的装置,可以用于执行图7~图8所示方法实施例网络设备侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
图12为本发明APN授权的装置实施例四的结构示意图;所述装置为UE;如图12所示,本实施例的装置可以包括:接收模块1201和发送模块1202。其中,接收模块1201,用于接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败;发送模块1202,用于向所述UE当前接入的接入网的网关发送第一连接请求消息;所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
可选的,接收模块1201,还用于接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;发送模块1202,还用于向与所述UE当前接入的接入网的网关不同的网关发送第二连接请求消息。
本实施例的装置,可以用于执行图5~图8所示方法实施例UE侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
本发明还提供一种APN授权的系统,包括APN授权的装置实施例一所述的网络设备及UE。
可选的,所述UE可以为APN授权的装置实施例四中所述的UE。
本实施例的系统,可以用于执行图5或图6所示方法实施例的技术方案,其实现原理和技术效果类似,此处不再赘述。
本发明还提供另一种APN授权的系统,包括APN授权的装置实施例二所述的HSS、APN授权的装置实施例三所述的网络设备及UE。
可选的,所述UE可以为APN授权的装置实施例四中所述的UE。
本实施例的装置,可以用于执行图7或图8所示方法实施例技术方案,其实现原理和技术效果类似,此处不再赘述。
图13为本发明APN授权的装置实施例五的结构示意图;所述装置为网络设备;如图13所示,本实施例的装置可以包括:处理器1301和接收器1302。其中,处理器1301,用于确定用户设备UE的目标APN及所述UE当前接入的接入网类型;接收器1302,用于获取所述UE的目标APN对应的授权接入网类型的信息;处理器1301,还用于根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
可选的,所述网络设备为AAA服务器,或者为Non 3GPP接入网关。
可选的,处理器1301具体用于:
如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN被授权;
或者,
如果根据所述UE的目标APN对应的授权接入网类型的信息确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN不被授权。
可选的,处理器1301,还用于确定所述UE的签约数据包括所述UE的目标APN。
可选的,所述装置还可以包括发送器1303;
如果处理器1301根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,则发送器1303,用于将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
可选的,接收器1302,具体用于接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
可选的,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
进一步可选的,若所述网络设备为AAA服务器,则接收器1302还用于接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;
发送器1303,还用于将所述UE的鉴权失败原因发送至所述UE。
本实施例的装置,可以用于执行图3所示方法实施例、图5所示方法实施例AAA侧、图6所示方法实施例TWAN侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
图14为本发明APN授权的装置实施例六的结构示意图;所述装置为HSS;如图14所示,本实施例的装置可以包括:处理器1401和发送器1402。其中,处理器1401,用于确定用户设备UE当前接入的接入网类型;处理器1401,还用于根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;发送器1402,用于将所述更新后的签约数据发送至网络设备。
可选的,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参 数中包含授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型;或者,
所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
本实施例的装置,可以用于执行图4所示方法实施例、图7及图8所示方法实施例HSS侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
图15为本发明APN授权的装置实施例七的结构示意图;所述装置为网络设备;如图15所示,本实施例的装置可以包括:接收器1501和处理器1502。其中,接收器1501,用于接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN的信息;处理器1502,用于根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
可选的,处理器1502,具体用于:
如果根据所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN属于所述UE在当前接入的接入网类型下的授权APN,则确定所述UE的目标APN被授权;或者,如果根据所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN不属于所述UE在当前接入的接入网类型下的授权APN,则确定所述UE的目标APN不被授权。
本实施例的装置,可以用于执行图7~图8所示方法实施例网络设备侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
图16为本发明APN授权的装置实施例八的结构示意图;所述装置为UE;如图16所示,本实施例的装置可以包括:接收器1601、处理器1602和发送器1603。其中,接收器1601,用于接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败;处理器1602,用于根据接收器1601接收的授权失败原因, 生成第一连接请求消息,所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同;发送器1603,用于将处理器1602生成的所述第一连接请求消息发送至所述UE当前接入的接入网的网关。
可选的,接收器1601,还用于接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;处理器1602,还用于根据接收器1601接收的所述UE的鉴权失败原因,生成第二连接请求消息;发送器1603,还用于将处理器1602生成的所述第二连接请求消息发送至与所述UE当前接入的接入网的网关不同的网关。
本实施例的装置,可以用于执行图5~图8所示方法实施例UE侧的技术方案,其实现原理和技术效果类似,此处不再赘述。
本领域普通技术人员可以理解:实现上述各方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成。前述的程序可以存储于一计算机可读取存储介质中。该程序在执行时,执行包括上述各方法实施例的步骤;而前述的存储介质包括:ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。
最后应说明的是:以上各实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述各实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分或者全部技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的范围。

Claims (29)

  1. 一种接入点名称APN授权的方法,其特征在于,包括:
    网络设备确定用户设备UE的目标APN及所述UE当前接入的接入网类型;
    所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息;
    所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
  2. 根据权利要求1所述的方法,其特征在于,所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权,包括:
    如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN被授权;
    或者,
    如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则所述网络设备确定所述UE的目标APN不被授权。
  3. 根据权利要求1或2所述的方法,其特征在于,所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权之前,还包括:
    所述网络设备确定所述UE的签约数据包括所述UE的目标APN。
  4. 根据权利要求1-3任一项所述的方法,其特征在于,如果所述网络设备根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,所述方法还包括:
    所述网络设备将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
  5. 根据权利要求1-4任一项所述的方法,其特征在于,所述网络设备获取所述UE的目标APN对应的授权接入网类型的信息,包括:
    所述网络设备接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
  6. 根据权利要求5所述的方法,其特征在于,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
    所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
    所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
    所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
  7. 根据权利要求1-6任一项所述的方法,其特征在于,所述网络设备为鉴权与授权计费AAA服务器,或者为非第三代合作伙伴计划Non 3GPP接入网关。
  8. 根据权利要求5或6所述的方法,其特征在于,若所述网络设备为AAA服务器,则所述网络设备接收HSS发送的所述UE的签约数据之前,还包括:
    所述网络设备接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;
    所述网络设备将所述UE的鉴权失败原因发送至所述UE。
  9. 一种接入点名称APN授权的方法,其特征在于,包括:
    用户归属系统HSS确定用户设备UE当前接入的接入网类型;
    所述HSS根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;
    所述HSS将所述更新后的签约数据发送至网络设备。
  10. 根据权利要求9所述的方法,其特征在于,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:
    所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,
    所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参 数中包含非授权接入网类型;或者,
    所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
  11. 一种接入点名称APN授权的方法,其特征在于,包括:
    网络设备接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN的信息;
    所述网络设备根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
  12. 一种接入点名称APN授权的方法,其特征在于,包括:
    用户设备UE接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败;
    所述UE向所述UE当前接入的接入网的网关发送第一连接请求消息;所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
  13. 根据权利要求12所述的方法,其特征在于,还包括:
    所述UE接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;
    所述UE向与所述UE当前接入的接入网的网关不同的网关发送第二连接请求消息。
  14. 一种接入点名称APN授权的装置,所述装置为网络设备,其特征在于,所述装置包括:
    确定模块,用于确定用户设备UE的目标APN及所述UE当前接入的接入网类型;
    获取模块,用于获取所述UE的目标APN对应的授权接入网类型的信息;
    所述确定模块,还用于根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN是否被授权。
  15. 根据权利要求14所述的装置,其特征在于,所述确定模块具体用于:
    如果根据所述UE的目标APN对应的授权接入网类型的信息,确定所述UE当前接入的接入网类型属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN被授权;
    或者,
    如果根据所述UE的目标APN对应的授权接入网类型的信息确定所述UE当前接入的接入网类型不属于所述UE的目标APN对应的授权接入网类型,则确定所述UE的目标APN不被授权。
  16. 根据权利要求14或15所述的装置,其特征在于,所述确定模块还用于确定所述UE的签约数据包括所述UE的目标APN。
  17. 根据权利要求14-16任一项所述的装置,其特征在于,所述装置还包括:第一发送模块;
    如果所述确定模块根据所述UE当前接入的接入网类型及所述UE的目标APN对应的授权接入网类型的信息,确定所述UE的目标APN不被授权,则所述第一发送模块,用于将授权失败原因发送给所述UE,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败。
  18. 根据权利要求14-17任一项所述的装置,其特征在于,所述获取模块具体用于:
    接收用户归属系统HSS发送的所述UE的签约数据,所述UE的签约数据中包括所述UE的目标APN对应的授权接入网类型的信息。
  19. 根据权利要求18所述的装置,其特征在于,所述UE的签约数据包括所述UE的目标APN对应的授权接入网类型的信息的方式包括:
    所述签约数据中所述UE的目标APN对应的APN配置参数中包含授权接入网类型;或者,
    所述签约数据中所述UE的目标APN对应的APN配置参数中包含非授权接入网类型;或者,
    所述签约数据中所述UE的目标APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示在所述UE当前接入的接入网类型下,所述UE的目标APN被授权或者不被授权。
  20. 根据权利要求14-19任一项所述的装置,其特征在于,所述网络设 备为鉴权与授权计费AAA服务器,或者为非第三代合作伙伴计划Non 3GPP接入网关。
  21. 根据权利要求18或19所述的装置,其特征在于,所述装置还包括第二发送模块;
    若所述网络设备为AAA服务器,则所述获取模块还用于接收所述HSS发送的鉴权响应消息,所述鉴权响应消息包括所述UE的鉴权失败原因;
    所述第二发送模块,用于将所述UE的鉴权失败原因发送至所述UE。
  22. 一种接入点名称APN的授权的装置,所述装置为用户归属系统HSS,其特征在于,所述装置包括:
    确定模块,用于确定用户设备UE当前接入的接入网类型;
    更新模块,用于根据所述UE当前接入的接入网类型,对所述UE的签约数据进行更新,获得更新后的签约数据;其中,所述UE的签约数据中包括至少一个APN及与所述至少一个APN对应的授权接入网类型的信息;所述更新后的签约数据包括所述UE在当前接入的接入网类型下的授权APN的信息;
    发送模块,用于将所述更新后的签约数据发送至网络设备。
  23. 根据权利要求22所述的装置,其特征在于,所述UE的签约数据包括与所述至少一个APN对应的授权接入网类型的信息的方式包括:
    所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含授权接入网类型;或者,
    所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含非授权接入网类型;或者,
    所述签约数据中所述至少一个APN中的每一个APN对应的APN配置参数中包含所述UE当前接入的接入网类型对应的授权标识,所述授权标识用于指示所述UE当前接入的接入网类型下,所述APN配置参数对应的APN被授权或者不被授权。
  24. 一种接入点名称APN授权的装置,所述装置为网络设备,其特征在于,所述装置包括:
    接收模块,用于接收用户归属系统HSS发送的更新后的签约数据;所述更新后的签约数据包括用户设备UE在当前接入的接入网类型下的授权APN 的信息;
    确定模块,用于根据所述UE的目标APN及所述UE在当前接入的接入网类型下的授权APN的信息,确定所述UE的目标APN是否被授权。
  25. 一种接入点名称APN授权的装置,所述装置为用户设备UE,其特征在于,所述装置包括:
    接收模块,用于接收网络设备发送的授权失败原因,所述授权失败原因用于指示所述UE的目标APN在所述UE当前接入的接入网类型下授权失败;
    发送模块,用于向所述UE当前接入的接入网的网关发送第一连接请求消息;所述第一连接请求消息包括所述UE请求的APN,所述UE请求的APN与所述目标APN不同。
  26. 根据权利要求25所述的装置,其特征在于,所述接收模块,还用于接收所述网络设备发送的所述UE的鉴权失败原因;所述鉴权失败原因包括:接入网类型不允许或访问的公共陆地移动网络VPLMN不允许;
    所述发送模块,还用于向与所述UE当前接入的接入网的网关不同的网关发送第二连接请求消息。
  27. 一种接入点名称APN授权的系统,其特征在于,包括:权利要求14-21任一项所述的网络设备及用户设备UE。
  28. 根据权利要求27所述的系统,其特征在于,所述UE如权利要求25或26所述。
  29. 一种接入点名称APN授权的系统,其特征在于,包括:权利要求22或23所述的用户归属系统HSS、权利要求24所述的网络设备以及用户设备UE。
PCT/CN2015/077177 2015-04-22 2015-04-22 接入点名称授权的方法、装置及系统 WO2016169003A1 (zh)

Priority Applications (6)

Application Number Priority Date Filing Date Title
PCT/CN2015/077177 WO2016169003A1 (zh) 2015-04-22 2015-04-22 接入点名称授权的方法、装置及系统
EP15889492.3A EP3277006B1 (en) 2015-04-22 2015-04-22 Method, apparatus and system for authorizing access point name
BR112017022545-0A BR112017022545B1 (pt) 2015-04-22 2015-04-22 Método, aparelho, e sistema de autorização de nome de ponto de acesso
JP2017555362A JP6577052B2 (ja) 2015-04-22 2015-04-22 アクセスポイント名許可方法、アクセスポイント名許可装置、およびアクセスポイント名許可システム
CN201580071236.7A CN107113612B (zh) 2015-04-22 2015-04-22 接入点名称授权的方法、装置及系统
US15/789,359 US10893049B2 (en) 2015-04-22 2017-10-20 Access point name authorization method, apparatus, and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/077177 WO2016169003A1 (zh) 2015-04-22 2015-04-22 接入点名称授权的方法、装置及系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/789,359 Continuation US10893049B2 (en) 2015-04-22 2017-10-20 Access point name authorization method, apparatus, and system

Publications (1)

Publication Number Publication Date
WO2016169003A1 true WO2016169003A1 (zh) 2016-10-27

Family

ID=57143649

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/077177 WO2016169003A1 (zh) 2015-04-22 2015-04-22 接入点名称授权的方法、装置及系统

Country Status (6)

Country Link
US (1) US10893049B2 (zh)
EP (1) EP3277006B1 (zh)
JP (1) JP6577052B2 (zh)
CN (1) CN107113612B (zh)
BR (1) BR112017022545B1 (zh)
WO (1) WO2016169003A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112468315A (zh) * 2020-11-03 2021-03-09 上海中觅通信技术有限公司 一种apn配置方法和设备

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108537662A (zh) * 2018-03-09 2018-09-14 深圳市富途网络科技有限公司 一种实现股票交易持仓和交易记录共享的方法及系统
US10772062B1 (en) * 2019-04-15 2020-09-08 T-Mobile Usa, Inc. Network-function monitoring and control

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1627842A (zh) * 2003-12-12 2005-06-15 华为技术有限公司 一种无线局域网用户终端选择分组数据关口的方法
CN101248640A (zh) * 2005-01-24 2008-08-20 艾利森电话股份有限公司 用于选择分组交换电信网络中移动终端的接入点名称(apn)的方法
CN103415044A (zh) * 2013-08-05 2013-11-27 南京邮电大学 一种WLAN网络中3GPP用户获取QoS签约的方法
CN103517378A (zh) * 2012-06-30 2014-01-15 华为终端有限公司 分组数据网连接建立方法和设备
CN103517252A (zh) * 2012-06-21 2014-01-15 中兴通讯股份有限公司 分组网关标识信息的更新方法、aaa服务器和分组网关

Family Cites Families (26)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7324489B1 (en) * 2003-02-18 2008-01-29 Cisco Technology, Inc. Managing network service access
CN101170808B (zh) * 2006-10-25 2011-03-30 华为技术有限公司 异种接入系统间的切换方法及切换系统
US7809003B2 (en) * 2007-02-16 2010-10-05 Nokia Corporation Method for the routing and control of packet data traffic in a communication system
US8621570B2 (en) * 2008-04-11 2013-12-31 Telefonaktiebolaget L M Ericsson (Publ) Access through non-3GPP access networks
CN101286915B (zh) * 2008-06-11 2012-05-09 中兴通讯股份有限公司 分组数据网络的接入控制方法和系统、pcrf实体
EP2166724A1 (en) * 2008-09-23 2010-03-24 Panasonic Corporation Optimization of handovers to untrusted non-3GPP networks
CN101730267B (zh) 2008-10-21 2012-11-07 华为技术有限公司 接入控制方法、装置和通信系统
US8607309B2 (en) * 2009-01-05 2013-12-10 Nokia Siemens Networks Oy Trustworthiness decision making for access authentication
JPWO2010092764A1 (ja) * 2009-02-13 2012-08-16 パナソニック株式会社 ゲートウェイ接続方法及びゲートウェイ接続制御システム並びに移動端末
US8595796B2 (en) * 2009-10-12 2013-11-26 Qualcomm Incorporated Apparatus and method for authorization for access point name (APN) usage in a specific access
KR101388315B1 (ko) * 2009-11-02 2014-04-29 엘지전자 주식회사 로컬 ip 접속을 위한 상관 id
US8477724B2 (en) * 2010-01-11 2013-07-02 Research In Motion Limited System and method for enabling session context continuity of local service availability in local cellular coverage
EP2664192B1 (en) * 2011-01-13 2016-06-15 Telefonaktiebolaget LM Ericsson (publ) Roaming control for ims apn
EP2664100B1 (en) * 2011-01-14 2018-12-05 Nokia Solutions and Networks Oy External authentication support over an untrusted network
WO2013003653A1 (en) * 2011-06-28 2013-01-03 Huawei Technologies Co., Ltd. System and method for communications network configuration
US9049562B2 (en) * 2011-08-10 2015-06-02 Telefonaktiebolaget Lm Ericsson (Publ) HSS fault recovery for non-3GPP access
WO2013041574A1 (en) * 2011-09-19 2013-03-28 Telefonaktiebolaget L M Ericsson (Publ) Deferred address allocation of ipv4 or ipv6 in case of interworking between non-3gpp access and evolved packet core
US9521145B2 (en) * 2011-10-17 2016-12-13 Mitel Mobility Inc. Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network
US20130121322A1 (en) 2011-11-10 2013-05-16 Motorola Mobility, Inc. Method for establishing data connectivity between a wireless communication device and a core network over an ip access network, wireless communication device and communicatin system
CN103200628B (zh) * 2012-01-09 2018-05-15 中兴通讯股份有限公司 一种通过非3gpp接入核心网的方法和系统
JP2013219635A (ja) * 2012-04-10 2013-10-24 Ntt Docomo Inc 移動局、通信システム及び通信方法
US9521077B2 (en) * 2013-07-22 2016-12-13 Verizon Patent And Licensing Inc. Network connection via a proxy device using a generic access point name
US9220118B1 (en) * 2013-08-07 2015-12-22 Sprint Spectrum L.P. Method and system for establishing a default bearer in accordance with a substitute packet data policy
US20150350912A1 (en) * 2014-05-28 2015-12-03 Telefonaktiebolaget L M Ericsson (Publ) Residential service delivery based on unique residential apn
CN106664550B (zh) * 2014-07-22 2019-11-15 意大利电信股份公司 管理移动电信网络中的用户的订阅的方法
EP3278497A4 (en) * 2015-03-31 2019-03-06 Telefonaktiebolaget LM Ericsson (publ) METHODS AND DEVICES FOR FACILITATING EMERGENCY CALLS ON WIRELESS COMMUNICATION SYSTEMS

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1627842A (zh) * 2003-12-12 2005-06-15 华为技术有限公司 一种无线局域网用户终端选择分组数据关口的方法
CN101248640A (zh) * 2005-01-24 2008-08-20 艾利森电话股份有限公司 用于选择分组交换电信网络中移动终端的接入点名称(apn)的方法
CN103517252A (zh) * 2012-06-21 2014-01-15 中兴通讯股份有限公司 分组网关标识信息的更新方法、aaa服务器和分组网关
CN103517378A (zh) * 2012-06-30 2014-01-15 华为终端有限公司 分组数据网连接建立方法和设备
CN103415044A (zh) * 2013-08-05 2013-11-27 南京邮电大学 一种WLAN网络中3GPP用户获取QoS签约的方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112468315A (zh) * 2020-11-03 2021-03-09 上海中觅通信技术有限公司 一种apn配置方法和设备

Also Published As

Publication number Publication date
BR112017022545B1 (pt) 2024-03-05
CN107113612B (zh) 2020-06-26
CN107113612A (zh) 2017-08-29
EP3277006A1 (en) 2018-01-31
EP3277006A4 (en) 2018-03-28
EP3277006B1 (en) 2020-07-08
US10893049B2 (en) 2021-01-12
BR112017022545A2 (zh) 2018-07-17
JP2018514166A (ja) 2018-05-31
JP6577052B2 (ja) 2019-09-18
US20180041903A1 (en) 2018-02-08

Similar Documents

Publication Publication Date Title
US8990925B2 (en) Security for a non-3GPP access to an evolved packet system
TWI616084B (zh) 使用現有身份碼的到蜂巢網路的受贊助連接
JP6628295B2 (ja) 認証されていないユーザのための3gpp進化型パケットコアへのwlanアクセスを介した緊急サービスのサポート
US8776184B2 (en) Method, system and apparatus for accessing a visited network
US10171998B2 (en) User profile, policy, and PMIP key distribution in a wireless communication network
US20120284785A1 (en) Method for facilitating access to a first access nework of a wireless communication system, wireless communication device, and wireless communication system
US20100064135A1 (en) Secure Negotiation of Authentication Capabilities
MX2014005668A (es) Metodo para establecer conectividad de datos entre un dispositivo de comunicacion inalambrica y una red nucleo sobre una red de acceso ip, dispositivo de comunicacion inalambrica y sistema de comunicacion.
CN111726228B (zh) 使用互联网密钥交换消息来配置活动性检查
US10893049B2 (en) Access point name authorization method, apparatus, and system
US11729164B2 (en) Support of IMEI checking for WLAN access to a packet core of a mobile network
JP2024517897A (ja) Nswoサービスの認証のための方法、デバイス、および記憶媒体
KR102103320B1 (ko) 이동 단말기, 네트워크 노드 서버, 방법 및 컴퓨터 프로그램
WO2017132906A1 (zh) 获取、发送用户设备标识的方法及设备
WO2016101267A1 (zh) 用户设备的非可信无线局域网接入控制方法、设备和系统
WO2018103732A1 (zh) 一种紧急号码的配置、获取方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15889492

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2017555362

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112017022545

Country of ref document: BR

ENP Entry into the national phase

Ref document number: 112017022545

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20171019