WO2017024671A1 - 一种网络切换方法及终端 - Google Patents

一种网络切换方法及终端 Download PDF

Info

Publication number
WO2017024671A1
WO2017024671A1 PCT/CN2015/091374 CN2015091374W WO2017024671A1 WO 2017024671 A1 WO2017024671 A1 WO 2017024671A1 CN 2015091374 W CN2015091374 W CN 2015091374W WO 2017024671 A1 WO2017024671 A1 WO 2017024671A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
authentication
terminal
message
multimedia subsystem
Prior art date
Application number
PCT/CN2015/091374
Other languages
English (en)
French (fr)
Inventor
张子敬
张晴
Original Assignee
宇龙计算机通信科技(深圳)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 宇龙计算机通信科技(深圳)有限公司 filed Critical 宇龙计算机通信科技(深圳)有限公司
Publication of WO2017024671A1 publication Critical patent/WO2017024671A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1073Registration or de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W36/00Hand-off or reselection arrangements
    • H04W36/14Reselecting a network or an air interface
    • H04W36/144Reselecting a network or an air interface over a different radio air interface technology
    • H04W36/1446Reselecting a network or an air interface over a different radio air interface technology wherein at least one of the networks is unlicensed

Definitions

  • the present invention relates to the field of communications, and in particular, to a network switching method and a terminal.
  • IMS IP Multimedia Subsystem
  • VoIP Voice over Long Term Evolution
  • VoIP-based Voice service refers to the voice service architecture on the carrier network, so that operators can provide a higher level of control and management for VoLTE.
  • VoWiFi Voice over Wireless Fidelity
  • WiFi Wireless Fidelity
  • VoWiFi accesses IMS through Wi-Fi and becomes universal access to another IMS network other than VoLTE. form.
  • IMS network registration includes initial registration and There are two processes for authentication registration, and the registration process is complicated. Therefore, adopting such a handover registration method will result in a large signaling load, and the steps of switching registration are cumbersome.
  • the embodiment of the invention provides a network switching method and a terminal, so that the terminal reduces the step of registering to the IMS network and reduces the signaling load when the network is switched.
  • a first aspect of the embodiments of the present invention provides a network switching method, including:
  • a second aspect of the embodiments of the present invention provides a terminal, including:
  • An extraction module configured to extract an authentication registration message when registering in a first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network;
  • a sending module configured to send an authentication verification request to the multimedia subsystem network by using the authentication registration message, if the terminal switches from the first network connection state to the second network connection state, where the authentication is performed
  • the verification request is used to request the multimedia subsystem network to perform authentication verification on the authentication registration message
  • the terminal extracts an authentication registration message when registering in the first network connection state, where the authentication registration message is used for the terminal to perform authentication registration on the multimedia subsystem network. And if the terminal switches from the first network connection state to the second network connection state, sending an authentication verification request to the multimedia subsystem network by using the authentication registration message, where the authentication verification request is used for And requesting the multimedia subsystem network to perform authentication verification on the authentication registration message; if the authentication verification is passed, receiving an acknowledgement message sent by the multimedia subsystem network, and requesting the multimedia subsystem network to The communication link information of the terminal is updated from the first network to the second network.
  • the authentication registration message By storing the authentication registration message when registering in the first network connection state, the authentication registration message is directly used for authentication registration when registering in the second network connection state, thereby eliminating the initial registration step, and the operation steps are greatly Simplification also reduces the signaling load registered during network switching.
  • the authentication registration is a ciphertext registration, thereby eliminating the initial registration step when the network is switched, thereby preventing leakage of user account privacy during initial registration, and improving the security of the registration process. Sex.
  • FIG. 1 is a schematic flowchart of a network switching method according to a first embodiment of the present invention
  • FIG. 1 is a schematic diagram of an interaction process of a terminal registering an IMS network in a network switching method according to an embodiment of the present disclosure
  • FIG. 1 is a network architecture diagram provided by an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a network switching method according to a second embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of a network switching method according to a third embodiment of the present invention.
  • FIG. 4 is a schematic structural diagram of a terminal according to a fourth embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of a terminal according to a fifth embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of a terminal according to a sixth embodiment of the present invention.
  • the embodiment of the invention provides a network switching method and a terminal, so that the terminal reduces the step of registering to the IMS network and reduces the signaling load when the network is switched.
  • a network switching method includes: extracting an authentication registration message when registering in a first network connection state, where the authentication registration message is used by a terminal to authenticate to a multimedia subsystem network Registration of the right; if the terminal switches from the first network connection state to the second network And establishing, by using the authentication registration message, an authentication verification request, where the authentication verification request is used to request the multimedia subsystem network to authenticate the authentication registration message. Verification; if the authentication verification is passed, receiving an acknowledgement message sent by the multimedia subsystem network, and requesting the multimedia subsystem network to update the communication link information of the terminal from the first network to the second network.
  • FIG. 1 is a schematic flowchart of a network switching method according to a first embodiment of the present invention
  • FIG. 1b is a terminal in a network switching method according to an embodiment of the present invention.
  • FIG. 1-c is a network architecture diagram provided by an embodiment of the present invention.
  • a network switching method provided by the first embodiment of the present invention may include:
  • the first network connection state refers to that the terminal currently uses the communication link of the first network to implement network communication
  • the terminal refers to the terminal with the network connection function, which can be a UE (user equipment) terminal or a wireless network interface card ( Station, STA) terminals, such as mobile phones, tablets, multimedia devices, etc., for example, when the user's mobile phone uses 4G (the 4th Generation mobile communication technology) network for network connection, the user's mobile phone is in the 4G network.
  • Connection Status can be a UE (user equipment) terminal or a wireless network interface card ( Station, STA) terminals, such as mobile phones, tablets, multimedia devices, etc.
  • the process when the terminal registers the IMS network includes initial registration and authentication registration.
  • the initial registration process is a registration process initiated by the terminal to the IMS network.
  • the registration message will pass through the eNodeB (Evolved Node B, base station), P-CSCF (Proxy Call Session Control Function), and I-CSCF (Interrogating).
  • the CSCF which queries the CSCF, is then sent to the S-CSCF (Serving CSCF, Serving CSCF) and authenticated by the HSS (Home Subscriber Server).
  • S-CSCF Serving CSCF
  • HSS Home Subscriber Server
  • the IMS network sends a 401 unauthorized response and carries an authentication verification parameter (RAND, AUTH) to challenge the terminal, and after receiving the response, the terminal performs an authentication response parameter according to the response.
  • RAND authentication verification parameter
  • the terminal performs an authentication response parameter according to the response.
  • the calculation obtains the response response and the authentication key, and then initiates the authentication registration process;
  • the authentication registration process is a process in which the terminal sends the response response and the authentication key to the IMS network, and the IMS network completes the authentication and key agreement process. And return a confirmation message 200 (OK) for successful registration.
  • the information that the terminal sends the initial registration request message carries the identity of the private user.
  • the private user identity is: username@reaml, where usename is the IMSI (International Mobile Subscriber Identification Number) number of the user, and reaml is the home network domain name.
  • IMSI International Mobile Subscriber Identification Number
  • the terminal and the S-CSCF can pass the AKA (Authentication and Key Agreement,
  • AKA Authentication and Key Agreement
  • the security key negotiated by the authentication and key agreement protocol of the third generation mobile communication network encrypts the transmission information, but the registration request message is sent before the terminal and the S-CSCF communicate, that is, It is sent when the security key has not been negotiated, so the message is not protected by any security but sent in clear text.
  • the authentication registration information refers to intermediate information used for authentication registration saved after the initial registration and before the authentication registration.
  • the authentication registration information may be an authentication response parameter according to a certain rule by using a 401 unauthorized response and an authentication verification parameter (RAND, AUTH) carried therein.
  • RAND authentication verification parameter
  • the authentication key and the response are obtained, so that after the initial registration registration information is extracted, the terminal may not need to perform initial authentication at the next registration, and the authentication registration may be directly performed.
  • the authentication registration information can be directly used for authentication registration when the network is switched, thereby eliminating the step of initial registration.
  • the switching of the terminal from the first network connection state to the second network connection state refers to that the terminal switches from a state in which network communication is performed using the first network communication link to a state in which network communication is performed using the second network communication link, such as a terminal.
  • the terminal Before using the 4G network for communication, and then entering the range of wireless Wi-Fi coverage, the terminal switched from the original 4G network communication to wireless communication using wireless Wi-Fi.
  • the authentication registration information sent by the terminal to the multimedia subsystem is an authentication key and an response response calculated by the terminal in response to the unauthorized response and using the authentication verification parameter.
  • the authentication verification request refers to an authentication verification request sent by the terminal to the IMS network when the authentication is registered, and requests the IMS network to perform authentication verification on the authentication registration information sent by the terminal.
  • the mobile phone when the first network is an LTE network and the second network is wireless Wi-Fi, the mobile phone uses an LTE network when it is outdoors, when the mobile phone enters indoor wireless Wi-Fi. After the coverage point, the connection network of the mobile phone is switched from the LTE network to the Wi-Fi network.
  • the authentication registration request is sent to the IMS network by using the authentication registration message, and the request is made. Authentication verification.
  • the confirmation message is an acknowledgement message sent to the terminal after the authentication and verification of the authentication registration information by the IMS network, and is used to notify the terminal that the authentication verification has passed, and the authentication registration is completed;
  • the communication link information refers to the network link between the terminal and the IMS network, and can be a network provided by the mobile operator.
  • the voice service provided by the IMS network can be accessed through the LTE network, that is, VoLTE.
  • the Wi-Fi accesses the voice service provided by the IMS network, that is, VoWiFi, and the communication link information may also be other network links.
  • the IMS network service is implemented based on the second network.
  • the IMS network updates the information related to the communication link, such as the IP address of the terminal.
  • the mobile phone when the first network is an LTE network, and the second network is wireless Wi-Fi, the mobile phone uses an LTE network when it is outdoors, and when the mobile phone enters the room, the mobile phone The connection network is switched from the LTE network to the Wi-Fi network.
  • an authentication verification request is sent to the IMS network by using an authentication registration message, requesting authentication verification, and After the right verification is passed, the IMS network sends a 200 confirmation message to the terminal, indicating that the wireless Wi-Fi based authentication registration is successful, and the terminal's IMS network can be performed based on the wireless Wi-Fi, so that the IMS network will update the terminal's IP address and the like.
  • Link-related information such as updating the IP address of the terminal from the IP address of the LTE network to the IP address of the wireless Wi-Fi.
  • the terminal extracts an authentication registration message when registering in the first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network;
  • the terminal switches from the first network connection state to the second network connection state, and uses the And the right registration message is sent to the multimedia subsystem network, where the authentication verification request is used to request the multimedia subsystem network to perform authentication verification on the authentication registration message; if the authentication verification is passed Receiving an acknowledgment message sent by the multimedia subsystem network, and requesting the multimedia subsystem network to update the communication link information of the terminal from the first network to the second network.
  • the authentication registration message By storing the authentication registration message when registering in the first network connection state, the authentication registration message is directly used for authentication registration when registering in the second network connection state, thereby eliminating the initial registration step, and the operation steps are greatly Simplification also reduces the signaling load registered during network switching.
  • the authentication registration is a ciphertext registration, thereby eliminating the initial registration step when the network is switched, thereby preventing leakage of user account privacy during initial registration, and improving the security of the registration process. Sex.
  • the registering in the first network connection state includes:
  • the authentication registration message is used to perform authentication registration.
  • the extracting the authentication registration message when registering in the first network connection state includes:
  • the authentication parameter carried by the unauthorized response is sent to the terminal by the IMS network, and is used by the terminal to generate an authentication registration message by using the verification parameter to negotiate with the two, and then the IMS network verifies whether the calculation of the authentication registration message is performed. Correct, so as to make a response to whether the authentication is successful.
  • the verification parameter includes two parameters (RAND, AUTH).
  • the response is calculated by the terminal using the IMS network to obtain an unauthorized response, and is used by the IMS to determine whether the authentication is successful by using the response response, so as to whether the authentication succeeds.
  • the authentication registration message further includes an authentication key carried by the response response.
  • the authentication key includes a secret key (CK) and an integrity key (IK).
  • the terminal when the terminal registers with the IMS network in the first network connection state, the terminal first sends an initial registration request to the IMS network, where the registration request includes the terminal private user identity information, because the IMS has not yet The identity is authenticated, so the IMS network responds to the initial registration request, returns an unauthorized response message to the terminal, and requests the terminal to perform further authentication verification. After receiving the unauthorized response message, the terminal generates the authentication by using the unauthorized response. Registering the message and then using the response response in the authentication registration message for authentication, it can be understood that the authentication registration message can be directly saved, so that the authentication registration message is used for further authentication registration, and the initial registration step can be omitted. You can also save the unauthorized response message and then use the unauthorized response message to generate the authentication registration message, which also saves the initial registration step.
  • the method further includes:
  • the terminal accesses the IMS network by using the second network communication link, and the first network communication link can be suspended. All work, that is, suspending the work of the first network access module of the terminal, and releasing the resources of the first network communication link by the IMS network, can save power consumption.
  • the mobile phone when the mobile phone is switched from the LTE network to the Wi-Fi network, and the mobile phone successfully registers with the IMS network through the Wi-Fi network, so that the mobile phone's IMS network can be based on the Wi-Fi network, the mobile phone can suspend its LTE network connection.
  • the operation of the module is entered, and the IMS network releases the LET network communication link resources, thereby saving resources and power consumption.
  • the method further includes:
  • the multimedia subsystem network is requested to switch the core network related session control resources.
  • the terminal when the terminal is successfully switched from the first network state to the second network state, after the terminal successfully registers with the IMS network, the terminal accesses the IMS network by using the second network communication link, and the IMS network associates the IMS service with the session.
  • the control resource is switched to the second network communication link so that the IMS service can be performed based on the second network.
  • the core network related session control resources include an I-CSCF, an S-CSCF, and other resources related to the IMS service.
  • the first network is a mobile network that provides voice services, a wireless local area network that provides voice services, or wireless fidelity that provides voice services;
  • the second network is a mobile network providing voice services, a wireless local area network providing voice services, or wireless fidelity providing voice services;
  • the first network is different from the second network.
  • the network switching method does not limit the network, and can switch between various networks.
  • the second network when the first network is LTE, the second network may be Wi-Fi or Wlan, so that switching from VoLTE to VoWiFi or VoWlan may be implemented.
  • the second network when the first network is Wi-Fi, the second network may be LTE, so that switching from VoWiFi to VoLTE may be implemented.
  • the voice communication when switching from VoLTE to VoWiFi, can be switched from VoWiFi to VoLTE in the same manner, and the authentication registration message may also be performed for the first time in VoLTE.
  • Initial registration and authentication registration messages saved during authentication registration.
  • FIG. 2 is a schematic flowchart of a network switching method according to a second embodiment of the present invention.
  • the second embodiment of the present invention provides a network switching method, which may include:
  • the terminal sends an initial registration request to the multimedia subsystem network.
  • the first network connection state refers to that the terminal currently uses the communication link of the first network to implement network communication
  • the terminal refers to the terminal with the network connection function, which can be a UE (user equipment) terminal or a wireless network interface card ( Station, STA) terminals, such as mobile phones, tablets, multimedia devices, etc., for example, when the user's mobile phone uses 4G (the 4th Generation mobile communication) Technology, the fourth generation mobile communication technology)
  • 4G the 4th Generation mobile communication
  • 4G the 4th Generation mobile communication
  • the process when the terminal registers the IMS network includes initial registration and authentication registration.
  • the initial registration process is a registration process initiated by the terminal to the IMS network.
  • the registration message will pass through the eNodeB (Evolved Node B, base station), P-CSCF (Proxy Call Session Control Function), and I-CSCF (Interrogating).
  • the right verification parameter (RAND, AUTH) challenges the terminal, and after receiving the response, the terminal obtains the response response and the authentication key according to the response of the response response parameter, and then initiates the authentication registration process; the authentication registration
  • the process is that the terminal sends the response response and the authentication key to the IMS network, and the IMS network completes the process of authentication and key agreement, and returns a confirmation message 200 (OK) for successful registration.
  • the initial registration request is information that carries the identity of the private user sent to the IMS network when the terminal performs initial registration.
  • an initial registration request is sent to the IMS network.
  • S202 Receive an unauthorized response message returned by the multimedia subsystem network, where the unauthorized response message includes an unauthorized response and an authentication parameter carried by the unauthorized response.
  • the authentication parameter carried by the unauthorized response is sent to the terminal by the IMS network, and is used by the terminal to generate an authentication registration message by using the verification parameter to negotiate with the two, and then the IMS network verifies whether the calculation of the authentication registration message is performed. Correct, so as to make a response to whether the authentication is successful.
  • the verification parameter includes two parameters (RAND, AUTH).
  • an initial registration request is sent to the IMS network, because the IMS network has not authenticated the identity of the terminal at this time, so the IMS The network responds to the initial registration request, returns an unauthorized response message to the terminal, and requests the terminal to perform further authentication verification.
  • the response is calculated by the terminal using the IMS network to obtain an unauthorized response, and is used by the IMS to determine whether the authentication is successful by using the response response, so as to whether the authentication succeeds.
  • the authentication registration message further includes an authentication key carried by the response response.
  • the authentication key includes a secret key (CK) and an integrity key (IK).
  • an initial registration request is sent to the IMS network, because the IMS network has not authenticated the identity of the terminal at this time, so the IMS The network responds to the initial registration request, returns an unauthorized response message to the terminal, and requests the terminal to perform further authentication verification, so that the terminal generates an authentication registration message by using the unauthorized response message.
  • the terminal when the terminal performs authentication registration by using the authentication registration message, the terminal sends an authentication registration message to the IMS network, and the IMS network performs authentication verification on the authentication registration message. When the verification is passed, the IMS returns an acknowledgement message and the authentication registration is completed.
  • the authentication registration message can be used for authentication registration, thereby completing the registration of the terminal to the IMS network.
  • the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network.
  • the authentication registration information refers to intermediate information used for authentication registration saved after the initial registration and before the authentication registration.
  • the authentication registration message may be configured to perform an authentication response parameter according to a certain rule by using a 401 unauthorized response and an authentication verification parameter (RAND, AUTH) carried therein.
  • RAND authentication verification parameter
  • the authentication key and the response are obtained, so that after the initial registration registration information is extracted, the terminal may not need to perform initial authentication at the next registration, and the authentication registration may be directly performed.
  • extracting an authentication registration message when registering in a first network connection state including:
  • the authentication registration information can be directly used for authentication registration when the network is switched, thereby eliminating the step of initial registration.
  • the switching of the terminal from the first network connection state to the second network connection state refers to that the terminal switches from a state in which network communication is performed using the first network communication link to a state in which network communication is performed using the second network communication link, such as a terminal.
  • the terminal Before using the 4G network for communication, and then entering the range of wireless Wi-Fi coverage, the terminal switched from the original 4G network communication to wireless communication using wireless Wi-Fi.
  • the authentication verification request refers to an authentication verification request sent by the terminal to the IMS network when the authentication is registered, and requests the IMS network to perform authentication verification on the authentication registration information sent by the terminal.
  • the authentication registration information sent by the terminal to the multimedia subsystem is an authentication key and an response response calculated by the terminal in response to the unauthorized response and using the authentication verification parameter.
  • the first network is a mobile network that provides voice services, a wireless local area network that provides voice services, or wireless fidelity that provides voice services;
  • the second network is a mobile network providing voice services, a wireless local area network providing voice services, or wireless fidelity providing voice services;
  • the first network is different from the second network.
  • the network switching method does not limit the network, and can switch between various networks.
  • the second network when the first network is LTE, the second network may be Wi-Fi or Wlan, so that switching from VoLTE to VoWiFi or VoWlan may be implemented.
  • the second network when the first network is Wi-Fi, the second network may be LTE, so that switching from VoWiFi to VoLTE may be implemented.
  • the voice communication when switching from VoLTE to VoWiFi, can be switched from VoWiFi to VoLTE in the same manner, and the authentication registration message may also be performed for the first time in VoLTE.
  • Initial registration and authentication registration messages saved during authentication registration.
  • the mobile phone when the first network is an LTE network and the second network is wireless Wi-Fi, the mobile phone uses an LTE network when it is outdoors, when the mobile phone enters indoor wireless Wi-Fi. After the coverage point, the connection network of the mobile phone is switched from the LTE network to the Wi-Fi network.
  • the authentication registration request is sent to the IMS network by using the authentication registration message, and the request is made. Authentication verification.
  • the confirmation message is an acknowledgement message sent to the terminal after the authentication and verification of the authentication registration information by the IMS network, and is used to notify the terminal that the authentication verification has passed, and the authentication registration is completed;
  • the communication link information refers to the network link between the terminal and the IMS network, and can be a network provided by the mobile operator.
  • the voice service provided by the IMS network can be accessed through the LTE network, that is, VoLTE.
  • the Wi-Fi accesses the voice service provided by the IMS network, that is, VoWiFi, and the communication link information may also be other network links.
  • the IMS network service is implemented based on the second network.
  • the IMS network updates the information related to the communication link, such as the IP address of the terminal.
  • the mobile phone when the first network is an LTE network, and the second network is wireless Wi-Fi, the mobile phone uses an LTE network when it is outdoors, and when the mobile phone enters the room, the mobile phone The connection network is switched from the LTE network to the Wi-Fi network.
  • an authentication verification request is sent to the IMS network by using an authentication registration message, requesting authentication verification, and After the right verification is passed, the IMS network sends a 200 confirmation message to the terminal, indicating that the wireless Wi-Fi based authentication registration is successful, and the terminal's IMS network can be performed based on the wireless Wi-Fi, so that the IMS network will update the terminal's IP address and the like.
  • Link-related information such as updating the IP address of the terminal from the IP address of the LTE network to the IP address of the wireless Wi-Fi.
  • the terminal when the terminal is successfully switched from the first network state to the second network state, after the terminal successfully registers with the IMS network, the terminal accesses the IMS network by using the second network communication link, and the IMS network associates the IMS service with the session. Controlling the resource switching to the second network communication link, thereby being based on the second network
  • the network performs IMS services.
  • the core network related session control resources include an I-CSCF, an S-CSCF, and other resources related to the IMS service.
  • the terminal accesses the IMS network by using the second network communication link, and the first network communication link can be suspended. All work, that is, suspending the work of the first network access module of the terminal, and releasing the resources of the first network communication link by the IMS network, can save power consumption.
  • the mobile phone when the mobile phone is switched from the LTE network to the Wi-Fi network, and the mobile phone successfully registers with the IMS network through the Wi-Fi network, so that the mobile phone's IMS network can be based on the Wi-Fi network, the mobile phone can suspend its LTE network connection.
  • the operation of the module is entered, and the IMS network releases the LET network communication link resources, thereby saving resources and power consumption.
  • the terminal extracts an authentication registration message when registering in the first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network; And the terminal is configured to send an authentication verification request to the multimedia subsystem network by using the authentication registration message, where the authentication verification request is used to request the multimedia.
  • the subsystem network performs authentication verification on the authentication registration message; if the authentication verification passes, receiving an acknowledgement message sent by the multimedia subsystem network, and requesting the multimedia subsystem network to communicate the terminal
  • the link information is updated from the first network to the second network.
  • the authentication registration message By storing the authentication registration message when registering in the first network connection state, the authentication registration message is directly used for authentication registration when registering in the second network connection state, thereby eliminating the initial registration step, and the operation steps are greatly Simplification also reduces the signaling load registered during network switching.
  • the authentication registration is a ciphertext registration, thereby eliminating the initial registration step when the network is switched, thereby preventing leakage of user account privacy during initial registration, and improving the security of the registration process. Sex.
  • FIG. 3 is a network switching method according to a third embodiment of the present invention.
  • a schematic diagram of a process, wherein, as shown in FIG. 3, a network switching provided by the third embodiment of the present invention may include:
  • the terminal sends an initial registration request to the multimedia subsystem network.
  • the mobile terminal when the user's mobile phone needs to register VoLTE under the LTE network, the mobile terminal sends an initial registration request to the IMS network.
  • the terminal receives an unauthorized response message returned by the multimedia subsystem network.
  • the unauthorised response message includes an unauthorized response and an authentication parameter carried by the unauthorized response.
  • the authentication parameter carried by the unauthorized response is sent to the terminal by the IMS network, and is used by the terminal to generate an authentication registration message by using the verification parameter to negotiate with the two, and then the IMS network verifies whether the calculation of the authentication registration message is performed. Correct, so as to make a response to whether the authentication is successful.
  • the verification parameter includes two parameters (RAND, AUTH).
  • an initial registration request is sent to the IMS network, because the IMS network has not authenticated the identity of the terminal at this time, so the IMS The network responds to the initial registration request, returns an unauthorized response message to the terminal, and requests the mobile terminal to perform further authentication verification.
  • the terminal generates an authentication registration message by using an unauthorized response message.
  • the authentication registration message includes an authentication response and an authentication key carried in the response response.
  • the authentication registration message further includes an authentication key carried by the response response.
  • the response is calculated by the terminal using the IMS network to obtain an unauthorized response, and is used by the IMS to determine whether the authentication is successful by using the response response, so as to whether the authentication succeeds.
  • the authentication key includes a secret key (CK) and an integrity key (IK).
  • an initial registration request is sent to the IMS network, because the IMS network has not authenticated the identity of the terminal at this time, so the IMS The network responds to the initial registration request, returns an unauthorized response message to the terminal, and requests the mobile terminal to perform further authentication verification, so that the mobile terminal generates an authentication registration message by using the unauthorized response message.
  • the terminal performs authentication registration by using an authentication registration message.
  • the terminal when the terminal performs authentication registration by using the authentication registration message, the terminal sends an authentication registration message to the IMS network, and the IMS network performs authentication verification on the authentication registration message. When the verification is passed, the IMS returns an acknowledgement message and the authentication registration is completed.
  • the authentication registration message is sent to the IMS network through LTE, and the IMS network performs the authentication registration message.
  • Authentication verification when the verification is passed, the IMS returns an acknowledgement message, and the authentication registration is completed, that is, VoLTE is implemented.
  • the terminal extracts an authentication registration message when registering in the first network connection state.
  • the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network.
  • extracting an authentication registration message when registering in a first network connection state including:
  • the mobile terminal in order to save the initial registration step when the next network switches from LTE to other networks, extracts the authentication registration message during the foregoing registration step, so that after the subsequent network handover The authentication registration message can be directly used for authentication registration.
  • the authentication verification request is used to request the multimedia subsystem network to perform authentication verification on the authentication registration message.
  • the first network is a mobile network that provides voice services, a wireless local area network that provides voice services, or wireless fidelity that provides voice services;
  • the second network is a mobile network providing voice services, a wireless local area network providing voice services, or wireless fidelity providing voice services;
  • the first network is different from the second network.
  • the mobile phone when the mobile phone is switched from the LTE network connection to the Wi-Fi network connection, the mobile phone sends the extracted authentication registration message to the IMS network through the Wi-Fi network, requesting the IMS.
  • the network authenticates its authentication.
  • the terminal receives the acknowledgement message sent by the multimedia subsystem network.
  • the confirmation message refers to that after the IMS network authenticates and authenticates the authentication registration information,
  • the confirmation message sent to the terminal is used to notify the terminal that the authentication verification has passed, and the authentication registration is completed.
  • the mobile phone sends the extracted authentication registration message to the IMS network through the Wi-Fi network, and requests the IMS network to authenticate the authentication, so that the IMS network registers the authentication.
  • the information is authenticated and verified.
  • the IMS network sends an acknowledgement message to the mobile phone, so that the mobile phone receives the acknowledgement message sent by the IMS network, thereby completing the authentication registration.
  • the multimedia subsystem network updates the communication link information of the terminal from the first network to the second network.
  • the IMS service of the mobile phone may be implemented based on the Wi-Fi network, so that the IMS network will update the communication of the terminal.
  • Link information such as the IP address of the terminal, is related to the communication link, such as updating the IP address of the terminal from the IP address of the LTE network to the IP address of the wireless Wi-Fi, thereby ensuring that the VoWiFi service works normally.
  • the multimedia subsystem network switches the core network related session control resources.
  • the core network related session control resources include an I-CSCF, an S-CSCF, and other resources related to the IMS service.
  • the IMS network switches the core network session control resource and the network related resource from the LTE network line to the wireless Wi-Fi network, thereby ensuring that the VoWiFi service is normal. jobs.
  • the multimedia subsystem network releases the first network communication link resource.
  • the IMS network releases the LTE network communication link resources, thereby saving power consumption.
  • step S309 and step S310 do not have a strict sequence of execution.
  • the terminal suspends operation of the first network access module.
  • the mobile phone after the mobile phone is switched from VoLTE to VoWiFi, the mobile phone suspends the work of the LTE network access module, thereby saving power consumption of the mobile phone.
  • the terminal extracts an authentication registration message when registering in the first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network; And the terminal is configured to send an authentication verification request to the multimedia subsystem network by using the authentication registration message, where the authentication verification request is used to request the multimedia.
  • the subsystem network performs authentication verification on the authentication registration message; if the authentication is performed After the verification is passed, an acknowledgement message sent by the multimedia subsystem network is received, and the multimedia subsystem network is requested to update the communication link information of the terminal from the first network to the second network.
  • the authentication registration message By storing the authentication registration message when registering in the first network connection state, the authentication registration message is directly used for authentication registration when registering in the second network connection state, thereby eliminating the initial registration step, and the operation steps are greatly Simplification also reduces the signaling load registered during network switching.
  • the authentication registration is a ciphertext registration, thereby eliminating the initial registration step when the network is switched, thereby preventing leakage of user account privacy during initial registration, and improving the security of the registration process. Sex.
  • the embodiment of the present invention further provides a terminal, where the terminal includes:
  • An extraction module configured to extract an authentication registration message when registering in a first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network;
  • a sending module configured to send an authentication verification request to the multimedia subsystem network by using the authentication registration message, if the terminal switches from the first network connection state to the second network connection state, where the authentication is performed
  • the verification request is used to request the multimedia subsystem network to perform authentication verification on the authentication registration message
  • FIG. 4 is a schematic structural diagram of a terminal according to a fourth embodiment of the present invention.
  • a terminal 400 according to the fourth embodiment of the present invention may include:
  • the extraction module 410 the sending module 420, and the first requesting module 430.
  • the extraction module 410 is configured to extract an authentication registration message when registering in the first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network.
  • the first network connection state refers to that the terminal currently uses the communication link of the first network to implement network communication
  • the terminal refers to the terminal with the network connection function, which can be a UE (user equipment) terminal or a wireless network interface card ( Station, STA) terminals, such as mobile phones, tablets, multimedia devices, etc., for example, when the user's mobile phone uses 4G (the 4th Generation mobile communication technology) network for network connection, the user's mobile phone is in the 4G network.
  • Connection Status can be a UE (user equipment) terminal or a wireless network interface card ( Station, STA) terminals, such as mobile phones, tablets, multimedia devices, etc.
  • the process when the terminal registers with the IMS network includes initial registration and authentication registration.
  • the initial registration process is a registration process initiated by the terminal to the IMS network.
  • the registration message will pass through the eNodeB (Evolved Node B, base station), P-CSCF (Proxy Call Session Control Function), and I-CSCF (Interrogating).
  • the CSCF which queries the CSCF, is then sent to the S-CSCF (Serving CSCF, Serving CSCF) and authenticated by the HSS (Home Subscriber Server).
  • S-CSCF Serving CSCF
  • HSS Home Subscriber Server
  • the IMS network sends a 401 unauthorized response and carries an authentication verification parameter (RAND, AUTH) to challenge the terminal, and after receiving the response, the terminal performs an authentication response parameter according to the response.
  • RAND authentication verification parameter
  • the terminal performs an authentication response parameter according to the response.
  • the calculation obtains the response response and the authentication key, and then initiates the authentication registration process;
  • the authentication registration process is a process in which the terminal sends the response response and the authentication key to the IMS network, and the IMS network completes the authentication and key agreement process. And return a confirmation message 200 (OK) for successful registration.
  • the information that the terminal sends the initial registration request message carries the identity of the private user.
  • the private user identity is: username@reaml, where usename is the IMSI (International Mobile Subscriber Identification Number) number of the user, and reaml is the home network domain name.
  • IMSI International Mobile Subscriber Identification Number
  • the terminal and the S-CSCF can pass the AKA (Authentication and Key Agreement,
  • AKA Authentication and Key Agreement
  • the security key negotiated by the authentication and key agreement protocol of the third generation mobile communication network encrypts the transmission information, but the registration request message is sent before the terminal and the S-CSCF communicate, that is, It is sent when the security key has not been negotiated, so the message is not protected by any security but sent in clear text.
  • the authentication registration information refers to intermediate information used for authentication registration saved after the initial registration and before the authentication registration.
  • the authentication registration information may be an authentication response parameter according to a certain rule by using a 401 unauthorized response and an authentication verification parameter (RAND, AUTH) carried therein.
  • RAND authentication verification parameter
  • the authentication key and the response are obtained, so that after the initial registration registration information is extracted, the terminal may not need to perform initial authentication at the next registration, and the authentication registration may be directly performed.
  • the authentication registration information can be directly used for authentication registration when the network is switched, thereby eliminating the step of initial registration.
  • the sending module 420 is configured to send, by using the authentication registration message, an authentication verification request to the multimedia subsystem network, if the terminal switches from the first network connection state to the second network connection state, where The right verification request is used to request the multimedia subsystem network to perform authentication verification on the authentication registration message.
  • the switching of the terminal from the first network connection state to the second network connection state refers to that the terminal switches from a state in which network communication is performed using the first network communication link to a state in which network communication is performed using the second network communication link, such as a terminal.
  • the terminal Before using the 4G network for communication, and then entering the range of wireless Wi-Fi coverage, the terminal switched from the original 4G network communication to wireless communication using wireless Wi-Fi.
  • the authentication registration information sent by the terminal to the multimedia subsystem is an authentication key and an response response calculated by the terminal in response to the unauthorized response and using the authentication verification parameter.
  • the authentication verification request refers to an authentication verification request sent by the terminal to the IMS network when the authentication is registered, and requests the IMS network to perform authentication verification on the authentication registration information sent by the terminal.
  • the mobile phone when the first network is an LTE network and the second network is wireless Wi-Fi, the mobile phone uses an LTE network when it is outdoors, when the mobile phone enters indoor wireless Wi-Fi. After the coverage point, the connection network of the mobile phone is switched from the LTE network to the Wi-Fi network.
  • the authentication registration request is sent to the IMS network by using the authentication registration message, and the request is made. Authentication verification.
  • the first requesting module 430 if the authentication verification is passed, receiving an acknowledgement message sent by the multimedia subsystem network, and requesting the multimedia subsystem network to update the communication link information of the terminal from the first network to Second network.
  • the confirmation message is an acknowledgement message sent to the terminal after the authentication and verification of the authentication registration information by the IMS network, and is used to notify the terminal that the authentication verification has passed, and the authentication registration is completed;
  • the communication link information refers to the network link between the terminal and the IMS network, and can be a network provided by the mobile operator.
  • the voice service provided by the IMS network can be accessed through the LTE network, that is, VoLTE.
  • the Wi-Fi accesses the voice service provided by the IMS network, that is, VoWiFi, and the communication link information may also be other network links.
  • the IMS network service is implemented based on the second network.
  • the IMS network updates the information related to the communication link, such as the IP address of the terminal.
  • the mobile phone when the first network is an LTE network, and the second network is wireless Wi-Fi, the mobile phone uses an LTE network when it is outdoors, and when the mobile phone enters the room, the mobile phone The connection network is switched from the LTE network to the Wi-Fi network.
  • an authentication verification request is sent to the IMS network by using an authentication registration message, requesting authentication verification, and After the right verification is passed, the IMS network sends a 200 confirmation message to the terminal, indicating that the wireless Wi-Fi based authentication registration is successful, and the terminal's IMS network can be performed based on the wireless Wi-Fi, so that the IMS network will update the terminal's IP address and the like.
  • Link-related information such as updating the IP address of the terminal from the IP address of the LTE network to the IP address of the wireless Wi-Fi.
  • the terminal 400 extracts an authentication registration message when registering in the first network connection state, where the authentication registration message is used for the terminal to perform authentication registration on the multimedia subsystem network;
  • the terminal 400 switches from the first network connection state to the second network connection state, and the terminal 400 sends an authentication verification request to the multimedia subsystem network by using the authentication registration message, where the authentication verification request is used for And requesting the multimedia subsystem network to perform authentication verification on the authentication registration message; if the authentication verification is passed, the terminal 400 receives an acknowledgement message sent by the multimedia subsystem network, and requests the multimedia subsystem network
  • the communication link information of the terminal is updated from the first network to the second network.
  • the authentication registration message By storing the authentication registration message when registering in the first network connection state, the authentication registration message is directly used for authentication registration when registering in the second network connection state, thereby eliminating the initial registration step, and the operation steps are greatly Simplification also reduces the signaling load registered during network switching.
  • the authentication registration is a ciphertext registration, thereby eliminating the initial registration step when the network is switched, thereby preventing leakage of user account privacy during initial registration, and improving the security of the registration process. Sex.
  • FIG. 5 is a schematic structural diagram of a terminal according to a fifth embodiment of the present invention.
  • a terminal 500 according to a fifth embodiment of the present invention may include:
  • the extraction module 510 the sending module 520, and the first requesting module 530.
  • the functions of the extraction module 510, the sending module 520, and the first requesting module 530 are the same as the functions of the extracting module 410, the sending module 420, and the first requesting module 430 provided by the fourth embodiment of the present invention, and the fourth embodiment of the present invention. The same function is not described herein again.
  • the wearable device 500 of the fifth embodiment of the present invention is supplemented by the wearable device 400 of the fourth embodiment of the present invention, which is described in detail below.
  • the terminal 500 is further configured to:
  • the authentication registration message is used to perform authentication registration.
  • the extraction module 510 is specifically configured to:
  • the authentication parameter carried by the unauthorized response is sent to the terminal by the IMS network, and is used by the terminal to generate an authentication registration message by using the verification parameter to negotiate with the two, and then the IMS network verifies whether the calculation of the authentication registration message is performed. Correct, so as to make a response to whether the authentication is successful.
  • the verification parameter includes two parameters (RAND, AUTH).
  • the response is calculated by the terminal using the IMS network to obtain an unauthorized response, and is used by the IMS to determine whether the authentication is successful by using the response response, so as to whether the authentication succeeds.
  • the authentication registration message further includes an authentication key carried by the response response.
  • the authentication key includes a secret key (CK) and an integrity key (IK).
  • the terminal when the terminal registers with the IMS network in the first network connection state, the terminal first sends an initial registration request to the IMS network, where the registration request includes the terminal private user identity information. Since the IMS has not authenticated the identity of the terminal at this time, the IMS network responds to the initial registration request, returns an unauthorized response message to the terminal, and requests the terminal to perform further authentication verification. After receiving the unauthorized response message, the terminal receives the unauthorized response message. Using the unauthorized response to generate an authentication registration message, and then using the response response in the authentication registration message for authentication, it can be understood that the authentication registration message can be directly saved, thereby further authenticating by using the authentication registration message. Registration, the step of initial registration can be omitted, the unauthorized response message can be saved, and the authentication response message can be generated by using the unauthorized response message, and the initial registration step can be omitted.
  • the terminal further includes:
  • the suspending module 540 is configured to suspend operation of the first network access module of the terminal, and request the multimedia subsystem network to release the first network communication link resource.
  • the terminal accesses the IMS network by using the second network communication link, and the first network communication link can be suspended. All work, that is, suspending the work of the first network access module of the terminal, and releasing the resources of the first network communication link by the IMS network, can save power consumption.
  • the mobile phone when the mobile phone is switched from the LTE network to the Wi-Fi network, and the mobile phone successfully registers with the IMS network through the Wi-Fi network, so that the mobile phone's IMS network can be based on the Wi-Fi network, the mobile phone can suspend its LTE network connection.
  • the operation of the module is entered, and the IMS network releases the LET network communication link resources, thereby saving resources and power consumption.
  • the terminal further includes:
  • the second requesting module 550 is configured to request the multimedia subsystem network to switch the core network related session control resources.
  • the terminal when the terminal is successfully switched from the first network state to the second network state, after the terminal successfully registers with the IMS network, the terminal accesses the IMS network by using the second network communication link, and the IMS network associates the IMS service with the session.
  • the control resource is switched to the second network communication link so that the IMS service can be performed based on the second network.
  • the core network related session control resources include an I-CSCF, an S-CSCF, and other resources related to the IMS service.
  • the first network is a mobile network that provides voice services, a wireless local area network that provides voice services, or wireless fidelity that provides voice services;
  • the second network is a mobile network providing voice services, a wireless local area network providing voice services, or Provide wireless fidelity for voice services;
  • the first network is different from the second network.
  • the network switching method does not limit the network, and can switch between various networks.
  • the second network when the first network is LTE, the second network may be Wi-Fi or Wlan, so that switching from VoLTE to VoWiFi or VoWlan may be implemented.
  • the second network when the first network is Wi-Fi, the second network may be LTE, so that switching from VoWiFi to VoLTE may be implemented.
  • the voice communication when switching from VoLTE to VoWiFi, can be switched from VoWiFi to VoLTE in the same manner, and the authentication registration message may also be performed for the first time in VoLTE.
  • Initial registration and authentication registration messages saved during authentication registration.
  • the terminal 500 extracts an authentication registration message when registering in the first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network;
  • the terminal 500 switches from the first network connection state to the second network connection state, and the terminal 500 sends an authentication verification request to the multimedia subsystem network by using the authentication registration message, where the authentication verification request is used for And requesting the multimedia subsystem network to perform authentication verification on the authentication registration message; if the authentication verification is passed, the terminal 500 receives an acknowledgement message sent by the multimedia subsystem network, and requests the multimedia subsystem network
  • the communication link information of the terminal is updated from the first network to the second network.
  • the authentication registration message By storing the authentication registration message when registering in the first network connection state, the authentication registration message is directly used for authentication registration when registering in the second network connection state, thereby eliminating the initial registration step, and the operation steps are greatly Simplification also reduces the signaling load registered during network switching.
  • the authentication registration is a ciphertext registration, thereby eliminating the initial registration step when the network is switched, thereby preventing leakage of user account privacy during initial registration, and improving the security of the registration process. Sex.
  • FIG. 6 is a schematic structural diagram of a terminal according to a sixth embodiment of the present invention.
  • a terminal 600 according to a sixth embodiment of the present invention may include: at least one bus 601, and At least one processor 602 connected to the bus and at least one memory 603 connected to the bus.
  • the processor 602 calls the code stored in the memory 603 through the bus 601 for extracting an authentication registration message when registering in the first network connection state, where the authentication registration message is used by the terminal to perform the multimedia subsystem network.
  • Authentication registration if the terminal switches from the first network connection state to the second network connection state, sending an authentication verification request to the multimedia subsystem network by using the authentication registration message, the authentication verification Requesting to request the multimedia subsystem network to perform authentication verification on the authentication registration message; if the authentication verification passes, receiving an acknowledgement message sent by the multimedia subsystem network, and requesting the multimedia subsystem
  • the network updates the communication link information of the terminal from the first network to the second network.
  • the first network connection state refers to that the terminal currently uses the communication link of the first network to implement network communication
  • the terminal refers to the terminal with the network connection function, which can be a UE (user equipment) terminal or a wireless network interface card ( Station, STA) terminals, such as mobile phones, tablets, multimedia devices, etc., for example, when the user's mobile phone uses 4G (the 4th Generation mobile communication technology) network for network connection, the user's mobile phone is in the 4G network.
  • Connection Status can be a UE (user equipment) terminal or a wireless network interface card ( Station, STA) terminals, such as mobile phones, tablets, multimedia devices, etc.
  • the processor 602 when the registering in the first network connection state, the processor 602 is configured to:
  • the authentication parameter carried by the unauthorized response is sent by the IMS network to the terminal, and is used by the terminal to generate an authentication registration message by using the verification parameter, and then the IMS network verifies the Whether the calculation of the authentication registration message is correct, thereby making a response whether the authentication is successful.
  • the verification parameter includes two parameters (RAND, AUTH).
  • the response is calculated by the terminal using the IMS network to obtain an unauthorized response, and is used by the IMS to determine whether the authentication is successful by using the response response, so as to whether the authentication succeeds.
  • the authentication registration message further includes an authentication key carried by the response response.
  • the authentication key includes a secret key (CK) and an integrity key (IK).
  • the processor 602 is further configured to:
  • the processor 602 is further configured to:
  • the multimedia subsystem network is requested to switch the core network related session control resources.
  • the first network is a mobile network that provides voice services, a wireless local area network that provides voice services, or wireless fidelity that provides voice services;
  • the second network is a mobile network providing voice services, a wireless local area network providing voice services, or wireless fidelity providing voice services;
  • the first network is different from the second network.
  • the network switching method does not limit the network, and can switch between various networks.
  • the terminal 600 extracts an authentication registration message when registering in the first network connection state, where the authentication registration message is used by the terminal to perform authentication registration on the multimedia subsystem network;
  • the terminal 600 switches from the first network connection state to the second network connection state, and the terminal 600 sends an authentication verification request to the multimedia subsystem network by using the authentication registration message, where the authentication verification request is used for Requesting the multimedia subsystem network to authenticate the authentication registration message If the authentication verification is passed, the terminal 600 receives the acknowledgement message sent by the multimedia subsystem network, and requests the multimedia subsystem network to update the communication link information of the terminal from the first network to the first Two networks.
  • the authentication registration message By storing the authentication registration message when registering in the first network connection state, the authentication registration message is directly used for authentication registration when registering in the second network connection state, thereby eliminating the initial registration step, and the operation steps are greatly Simplification also reduces the signaling load registered during network switching.
  • the authentication registration is a ciphertext registration, thereby eliminating the initial registration step when the network is switched, thereby preventing leakage of user account privacy during initial registration, and improving the security of the registration process. Sex.
  • the embodiment of the present invention further provides a computer storage medium, wherein the computer storage medium can store a program, and the program includes some or all of the steps of the network switching method described in the foregoing method embodiments.
  • the disclosed apparatus may be implemented in other ways.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or may be Integrate into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be electrical or otherwise.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present invention which is essential or contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product stored in a storage medium.
  • a number of instructions are included to cause a computer device (which may be a personal computer, server or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a removable hard disk, a magnetic disk, or an optical disk, and the like. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Business, Economics & Management (AREA)
  • General Business, Economics & Management (AREA)
  • Multimedia (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例公开了一种网络切换方法及终端,所述方法,包括:提取在第一网络连接状态下注册时的鉴权注册消息;若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求;若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。本发明实施例通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。

Description

一种网络切换方法及终端 技术领域
本发明涉及通信领域,具体涉及一种网络切换方法及终端。
背景技术
IMS(IP Multimedia Subsystem,IP多媒体子系统)是一种全新的多媒体业务形式,它能够满足现在的终端客户更新颖、更多样化多媒体业务的需求,VoLTE(Voice over Long Term Evolution,基于IMS的语音业务)指语音业务构架于运营商网络之上,从而运营商能够为VoLTE提供更高级别的控制和管理,VoWiFi(Voice over Wireless Fidelity,通过Wi-Fi接入IMS)是指将WiFi作为接入网接入IMS从而实现IMS业务。
随着通信技术的发展,无线Wi-Fi以其覆盖越来越广泛并且信号质量好的优点为大家所青睐,所以VoWiFi通过Wi-Fi接入IMS成为VoLTE以外的另一IMS网络的普遍接入形式。而目前为了实现在VoLTE和VoWiFi之间的切换,如从VoLTE网络切换到VoWiFi网络,通常采用的是首先在VoLTE上注销,然后再在VoWiFi网络上重新注册,而由于IMS网络注册包括初始注册和鉴权注册两个流程,注册过程复杂,从而采用此种切换注册方法将导致较大的信令负荷,切换注册时步骤繁琐。
发明内容
本发明实施例提供了一种网络切换方法及终端,以期终端在网络切换时,减少注册到IMS网络的步骤,降低信令负荷。
本发明实施例第一方面提供一种网络切换方法,包括:
提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;
若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请 求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;
若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
本发明实施例第二方面提供一种终端,包括:
提取模块,用于提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;
发送模块,用于若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;
第一请求模块,若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
可以看出,在本发明实施例提供的技术方案中,终端提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。
更进一步地,由于初始注册为明文注册,鉴权注册为密文注册,从而在网络切换注册时通过省去了初始注册的步骤,可防止初始注册时用户帐户隐私的泄露,提高注册过程的安全性。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施 例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1-a是本发明第一实施例提供的一种网络切换方法的流程示意图;
图1-b是本发明实施例提供的网络切换方法中终端注册IMS网络的交互流程示意图;
图1-c是本发明实施例提供的网络架构图;
图2是本发明第二实施例提供一种网络切换方法的流程示意图;
图3是本发明第三实施例提供的一种网络切换方法的流程示意图;
图4是本发明第四实施例提供的一种终端的结构示意图;
图5是本发明第五实施例提供的一种终端的结构示意图;
图6是本发明第六实施例提供的一种终端的结构示意图。
具体实施方式
本发明实施例提供了一种网络切换方法及终端,以期终端在网络切换时,减少注册到IMS网络的步骤,降低信令负荷。
为了使本技术领域的人员更好地理解本发明方案,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分的实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本发明保护的范围。
本发明的说明书和权利要求书及上述附图中的术语“第一”、“第二”和“第三”等是用于区别不同对象,而非用于描述特定顺序。此外,术语“包括”以及它们任何变形,意图在于覆盖不排他的包含。例如包含了一系列步骤或单元的过程、方法、系统、产品或设备没有限定于已列出的步骤或单元,而是可选地还包括没有列出的步骤或单元,或可选地还包括对于这些过程、方法、产品或设备固有的其它步骤或单元。
本发明实施例的一种网络切换方法,一种网络切换方法包括:提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端从所述第一网络连接状态切换至第二网 络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
首先参见图1-a和图1-b,图1-a是本发明第一实施例提供的一种网络切换方法的流程示意图,图1-b是本发明实施例提供的网络切换方法中终端注册IMS网络的交互流程示意图,图1-c是本发明实施例提供的网络架构图。其中,如图1所示,本发明第一实施例提供的一种网络切换方法可以包括:
S101、提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册。
其中,第一网络连接状态是指终端当前使用的是第一网络的通信链路实现网络通信,终端是指具有网络连接功能的终端,可以为UE(user equipment)终端或携带无线网络接口卡(Station,STA)终端,如手机、平板电脑、多媒体设备等,例如,当用户手机使用4G(the 4th Generation mobile communication technology,第四代移动通信技术)网络进行网络连接时,则用户手机处于4G网络连接状态。
其中,参见图1-b和图1-c,需要说明,一般情况下,如当终端初次注册IMS网络时,终端注册IMS网络时的流程包括初始注册和鉴权注册。初始注册过程是由终端向IMS网络发起的注册过程,注册消息将依次通过eNodeB(Evolved Node B,基站)、P-CSCF(Proxy Call Session Control Function,代理呼叫会话控制功能)、I-CSCF(Interrogating CSCF,查询CSCF)再发送至S-CSCF(Serving CSCF,服务CSCF),并通过HSS(Home Subscriber Server,归属签约用户服务器)对其进行身份认证。从而当终端向IMS网络发起注册请求时,IMS网络会发送401未授权响应并携带鉴权验证参数(RAND,AUTH)向终端发起挑战,终端接收到该响应后会根据该响应进行鉴权响应参数的计算得到应答响应及鉴权密钥,之后再发起鉴权注册流程;鉴权注册流程是终端将应答响应及鉴权密钥发送给IMS网络,由IMS网络完成鉴权及密钥协商的过程,并返回注册成功的确认消息200(OK)。
其中,终端发送初始注册请求消息中携带有私有用户身份标识的信息。通 常对于VoLTE用户来说,其私有用户身份标识是:username@reaml,其中,usename是用户的IMSI(International Mobile Subscriber Identification Number,国际移动用户识别码)号码,reaml是归属网络域名。例如:当某用户的IMSI号码:234150999999999,则私有用户身份标识的形式为:234150999999999@ims.mnc015.mcc234.3gppnetwork.org,虽然终端和S-CSCF之间可以通过AKA(Authentication and Key Agreement,第三代移动通讯网络的认证与密钥协商协议)机制协商的安全性密钥对传输信息进行加密性和完整性保护,但是注册请求消息由于是终端和S-CSCF未通信之前发送的,也即是在安全密钥尚未协商时发送的,所以该消息没有受到任何安全保护而是用明文发送的。
其中,鉴权注册信息是指在初始注册以后、鉴权注册之前保存的用于鉴权注册的中间信息。
可选地,在本发明的另一些可能的实施方式中,鉴权注册信息可以为利用401未授权响应及其携带的鉴权验证参数(RAND,AUTH)按照一定的规则进行鉴权响应参数的计算后得到的鉴权密钥及应答响应,从而当提取了初始注册以后的鉴权注册信息后,则在下次注册的时候可以不需要再对终端进行初始鉴权,可直接进行鉴权注册。
可以理解,通过提取鉴权注册信息,则可以在切换网络时直接利用鉴权注册信息进行鉴权注册,从而省去了初始注册的步骤。
S102、若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证。
其中,终端从第一网络连接状态切换至第二网络连接状态是指终端从使用第一网络通信链路进行网络通信的状态下切换至使用第二网络通信链路进行网络通信的状态,如终端之前利用4G网络进行通信,然后在进入无线Wi-Fi覆盖的范围后,终端的从原来的4G网络通信转为利用无线Wi-Fi进行网络通信。
可选地,在本发明的一些可能实施方式中,终端向多媒体子系统发送的鉴权注册信息为终端响应未授权响应并利用鉴权验证参数计算出来的鉴权密钥以及应答响应。
其中,鉴权验证请求是指终端在鉴权注册时向IMS网络发送的鉴权验证请求,请求IMS网络对终端发送的鉴权注册信息进行鉴权验证。
举例说明,在本发明的一些可能的实施方式中,当第一网络为LTE网络,第二网络为无线Wi-Fi时,手机在室外时使用的是LTE网络,当手机进入室内无线Wi-Fi覆盖点后,手机的连接网络从LTE网络转为Wi-Fi网络,为了利用Wi-Fi网络做为IMS网络的接入点,则利用鉴权注册消息向IMS网络发送鉴权验证请求,请求进行鉴权验证。
S103、若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
其中,确认消息是指当IMS网络对鉴权注册信息进行鉴权验证并且通过后,向终端发送的确认消息,用于通知终端鉴权验证已通过,鉴权注册完成;
通信链路信息是指终端与IMS网络之间进行通信的网络链路,可以为移动运营商提供的网络,此时可通过LTE网络接入IMS网络提供的语音业务,也即VoLTE,也可以通过Wi-Fi接入IMS网络提供的语音业务,也即VoWiFi,该通信链路信息还可以为其它网络链路。
可选地,在本发明的一些可能的实施方式中,当多媒体子系统网络将终端的通信链路信息从第一网络更新至第二网络后,则IMS网络业务基于第二网络实现。
可选地,在本发明的一些可能的实施方式中,当通信链路变更后,IMS网络更新终端的IP地址等与通信链路相关的信息。
举例说明,在本发明的一些可能的实施方式中,当第一网络为LTE网络,第二网络为无线Wi-Fi时,手机在室外时使用的是LTE网络,当手机进入室内后,手机的连接网络从LTE网络转为Wi-Fi网络,为了利用Wi-Fi网络做为IMS网络的接入点,则利用鉴权注册消息向IMS网络发送鉴权验证请求,请求进行鉴权验证,当鉴权验证通过后,IMS网络向终端发送200确认消息,说明基于无线Wi-Fi的鉴权注册成功,终端的IMS网络可基于无线Wi-Fi进行,从而IMS网络将更新终端的IP地址等与通信链路相关的信息,如将终端的IP地址从LTE网络的IP地址更新至无线Wi-Fi的IP地址。
可以看出,本实施例的方案中,终端提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴 权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。
更进一步地,由于初始注册为明文注册,鉴权注册为密文注册,从而在网络切换注册时通过省去了初始注册的步骤,可防止初始注册时用户帐户隐私的泄露,提高注册过程的安全性。
可选地,在本发明的一些可能的实施方式中,所述在所述第一网络连接状态下注册,包括:
所述终端向所述多媒体子系统网络发送初始注册请求;
接收所述多媒体子系统网络返回的未授权响应消息,其中,所述未授权响应消息包括未授权响应及所述未授权响应携带的验证参数;
利用所述未授权响应消息生成鉴权注册消息,所述鉴权注册消息包括应答响应;
利用所述鉴权注册消息进行鉴权注册。可选地,在本发明的一些可能的实施方式中,所述提取在第一网络连接状态下注册时的鉴权注册消息,包括:
保存所述未授权响应消息,并利用所述未授权响应消息生成所述鉴权注册消息;
或,保存所述鉴权注册消息。
其中,未授权响应携带的验证参数为IMS网络发送给终端的,用于让终端利用该验证参数利用两者协商的方式生成鉴权注册消息,再由IMS网络验证该鉴权注册消息的计算是否正确,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,该验证参数包括(RAND,AUTH)两个参数。
其中,应答响应为终端利用IMS网络发送的未授权响应利用一定的方式计算得到的,用于IMS利用应答响应判断鉴权是否成功,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,所述鉴权注册消息还包括应答响应携带的鉴权密钥。
可选地,在本发明的一些可能的实施方式中,鉴权密钥包括保密性密钥(CK),以及完整性密钥(IK)。
上述注册流程也即,终端在第一网络连接状态下向IMS网络注册时,首先向IMS网络发送初始注册请求,该注册请求中包含终端私有用户身份标识信息,由于此时IMS还没有对终端的身份进行认证,所以IMS网络对初始注册请求做出响应,返回未授权响应消息给终端,要求终端进行进一步的鉴权验证,终端接收到该未授权响应消息后,利用该未授权响应生成鉴权注册消息,再利用该鉴权注册消息中的应答响应进行鉴权,那么可以理解,可直接保存鉴权注册消息,从而利用鉴权注册消息进行进一步地鉴权注册,可省去初始注册的步骤,也可保存未授权响应消息,再利用未授权响应消息生成鉴权注册消息,同样可省去初始注册的步骤。
可选地,在本发明的一些可能的实施方式中,所述若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络后,所述方法还包括:
暂停所述终端第一网络接入模块的工作,并请求所述多媒体子系统网络释放所述第一网络通信链路资源。
可以理解,当在终端从第一网络状态切换至第二网络状态下,终端对IMS网络注册成功后,终端即利用第二网络通信链路接入IMS网络,可以中止第一网络通信链路的所有工作,也即暂停终端第一网络接入模块的工作,以及IMS网络释放第一网络通信链路资源,从而可以节约功耗。
举例说明,当手机从LTE网络切换至Wi-Fi网络后,并且手机通过Wi-Fi网络向IMS网络注册成功,从而手机的IMS网络可基于Wi-Fi网络进行,那么手机可暂停其LTE网络接入模块的工作,并且IMS网络释放LET网络通信链路资源,从而节约资源与功耗。
可选地,在本发明的一些可能的实施方式中,所述若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络后,所述方法还包括:
请求所述多媒体子系统网络切换核心网相关会话控制资源。
可以理解,当终端从第一网络状态切换至第二网络状态下,终端对IMS网络注册成功后,终端即利用第二网络通信链路接入IMS网络,IMS网络将其与IMS业务相关的会话控制资源切换至第二网络通信链路,从而可以基于第二网络进行IMS业务。
可选地,在本发明的一些可能的实施方式中,核心网相关会话控制资源包括I-CSCF、S-CSCF及其它与IMS业务相关的资源。
可选地,在本发明的一些可能的实施方式中,所述第一网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
所述第二网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
其中,所述第一网络与所述第二网络不同。
可以理解,该网络切换方法不对网络进行限制,可以在各种不同的网络之间进行切换。
可选地,在本发明的一些可能实施方式中,当第一网络为LTE时,第二网络可以为Wi-Fi或Wlan,从而可实现从VoLTE到VoWiFi或VoWlan的切换。
可选地,在本发明的另一些可能的实施方式中,当第一网络为Wi-Fi时,第二网络可以为LTE,从而可实现从VoWiFi到VoLTE的切换。
可选地,在本发明的另一些可能的实施方式中,当从VoLTE切换至VoWiFi,又可以以同样的方式从VoWiFi切换至VoLTE,此时鉴权注册消息还可以为第一次在VoLTE进行初始注册以及鉴权注册时保存的鉴权注册消息。
为了便于更好理解和实施本发明实施例的上述方案,下面结合一些具体的应用场景进行举例说明。
请参见图2,图2是本发明第二实施例提供一种网络切换方法的流程示意图,其中,如图2所示,本发明第二实施例提供一种网络切换方法可以包括:
S201、在第一网络连接状态下,终端向多媒体子系统网络发送初始注册请求。
其中,第一网络连接状态是指终端当前使用的是第一网络的通信链路实现网络通信,终端是指具有网络连接功能的终端,可以为UE(user equipment)终端或携带无线网络接口卡(Station,STA)终端,如手机、平板电脑、多媒体设备等,例如,当用户手机使用4G(the 4th Generation mobile communication  technology,第四代移动通信技术)网络进行网络连接时,则用户手机处于4G网络连接状态。
其中,参见图1-b,需要说明,一般情况下,如当终端初次注册IMS网络时,终端注册IMS网络时的流程包括初始注册和鉴权注册。初始注册过程是由终端向IMS网络发起的注册过程,注册消息将依次通过eNodeB(Evolved Node B,基站)、P-CSCF(Proxy Call Session Control Function,代理呼叫会话控制功能)、I-CSCF(Interrogating CSCF,查询CSCF)再发送至S-CSCF(Serving CSCF,服务CSCF),由于此时还没有进行身份认证,所以当终端向IMS网络发起注册请求时,IMS网络会发送401未授权响应并携带鉴权验证参数(RAND,AUTH)向终端发起挑战,终端接收到该响应后会根据该响应进行鉴权响应参数的计算得到应答响应及鉴权密钥,之后再发起鉴权注册流程;鉴权注册流程是终端将应答响应及鉴权密钥发送给IMS网络,由IMS网络完成鉴权及密钥协商的过程,并返回注册成功的确认消息200(OK)。
其中,初始注册请求是指终端进行初始注册时向IMS网络发送的携带有私有用户身份标识的信息。
举例说明,在本发明的一些可能的实施方式中,当用户手机在LTE网络下需要注册VoLTE,则向IMS网络发送初始注册请求。
S202、接收多媒体子系统网络返回的未授权响应消息,其中,未授权响应消息包括未授权响应及未授权响应携带的验证参数。
其中,未授权响应携带的验证参数为IMS网络发送给终端的,用于让终端利用该验证参数利用两者协商的方式生成鉴权注册消息,再由IMS网络验证该鉴权注册消息的计算是否正确,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,该验证参数包括(RAND,AUTH)两个参数。
举例说明,在本发明的一些可能的实施方式中,当用户手机在LTE网络下需要注册VoLTE,则向IMS网络发送初始注册请求,由于此时IMS网络还没有对终端的身份进行认证,所以IMS网络对初始注册请求做出响应,返回未授权响应消息给终端,要求终端进行进一步的鉴权验证。
S203、利用未授权响应消息生成鉴权注册消息,鉴权注册消息包括应答响应。
其中,应答响应为终端利用IMS网络发送的未授权响应利用一定的方式计算得到的,用于IMS利用应答响应判断鉴权是否成功,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,所述鉴权注册消息还包括应答响应携带的鉴权密钥
可选地,在本发明的一些可能的实施方式中,鉴权密钥包括保密性密钥(CK),以及完整性密钥(IK)。
举例说明,在本发明的一些可能的实施方式中,当用户手机在LTE网络下需要注册VoLTE,则向IMS网络发送初始注册请求,由于此时IMS网络还没有对终端的身份进行认证,所以IMS网络对初始注册请求做出响应,返回未授权响应消息给终端,要求终端进行进一步的鉴权验证,从而终端利用未授权响应消息生成鉴权注册消息。
S204、利用鉴权注册消息进行鉴权注册。
可选地,在本发明的一些可能的实施方式中,终端利用鉴权注册消息进行鉴权注册时,终端向IMS网络发送鉴权注册消息,IMS网络对该鉴权注册消息进行鉴权验证,当验证通过,IMS返回确认消息,鉴权注册完成。
可以理解,当生成鉴权注册消息后,则可以利用该鉴权注册消息进行鉴权注册,从而完成终端向IMS网络的注册。
S205、提取在第一网络连接状态下注册时的鉴权注册消息。
其中,鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册。
其中,鉴权注册信息是指在初始注册以后、鉴权注册之前保存的用于鉴权注册的中间信息。
可选地,在本发明的另一些可能的实施方式中,鉴权注册消息可以为利用401未授权响应及其携带的鉴权验证参数(RAND,AUTH)按照一定的规则进行鉴权响应参数的计算后得到的鉴权密钥及应答响应,从而当提取了初始注册以后的鉴权注册信息后,则在下次注册的时候可以不需要再对终端进行初始鉴权,可直接进行鉴权注册。
可选地,在本发明的一些可能的实施方式中,提取在第一网络连接状态下注册时的鉴权注册消息,包括:
保存所述未授权响应消息,并利用所述未授权响应消息生成所述鉴权注册 消息;
或,保存所述鉴权注册消息。
可以理解,通过提取鉴权注册信息,则可以在切换网络时直接利用鉴权注册信息进行鉴权注册,从而省去了初始注册的步骤。
S206、若终端从所述第一网络连接状态切换至第二网络连接状态,则利用鉴权注册消息向多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求多媒体子系统网络对鉴权注册消息进行鉴权验证。
其中,终端从第一网络连接状态切换至第二网络连接状态是指终端从使用第一网络通信链路进行网络通信的状态下切换至使用第二网络通信链路进行网络通信的状态,如终端之前利用4G网络进行通信,然后在进入无线Wi-Fi覆盖的范围后,终端的从原来的4G网络通信转为利用无线Wi-Fi进行网络通信。
其中,鉴权验证请求是指终端在鉴权注册时向IMS网络发送的鉴权验证请求,请求IMS网络对终端发送的鉴权注册信息进行鉴权验证。
可选地,在本发明的一些可能实施方式中,终端向多媒体子系统发送的鉴权注册信息为终端响应未授权响应并利用鉴权验证参数计算出来的鉴权密钥以及应答响应。
可选地,在本发明的一些可能的实施方式中,所述第一网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
所述第二网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
其中,所述第一网络与所述第二网络不同。
可以理解,该网络切换方法不对网络进行限制,可以在各种不同的网络之间进行切换。
可选地,在本发明的一些可能实施方式中,当第一网络为LTE时,第二网络可以为Wi-Fi或Wlan,从而可实现从VoLTE到VoWiFi或VoWlan的切换。
可选地,在本发明的另一些可能的实施方式中,当第一网络为Wi-Fi时,第二网络可以为LTE,从而可实现从VoWiFi到VoLTE的切换。
可选地,在本发明的另一些可能的实施方式中,当从VoLTE切换至VoWiFi,又可以以同样的方式从VoWiFi切换至VoLTE,此时鉴权注册消息还可以为第一次在VoLTE进行初始注册以及鉴权注册时保存的鉴权注册消息。
举例说明,在本发明的一些可能的实施方式中,当第一网络为LTE网络,第二网络为无线Wi-Fi时,手机在室外时使用的是LTE网络,当手机进入室内无线Wi-Fi覆盖点后,手机的连接网络从LTE网络转为Wi-Fi网络,为了利用Wi-Fi网络做为IMS网络的接入点,则利用鉴权注册消息向IMS网络发送鉴权验证请求,请求进行鉴权验证。
S207、若鉴权验证通过,则接收多媒体子系统网络发送的确认消息,并请求多媒体子系统网络将终端的通信链路信息从第一网络更新至第二网络。
其中,确认消息是指当IMS网络对鉴权注册信息进行鉴权验证并且通过后,向终端发送的确认消息,用于通知终端鉴权验证已通过,鉴权注册完成;
通信链路信息是指终端与IMS网络之间进行通信的网络链路,可以为移动运营商提供的网络,此时可通过LTE网络接入IMS网络提供的语音业务,也即VoLTE,也可以通过Wi-Fi接入IMS网络提供的语音业务,也即VoWiFi,该通信链路信息还可以为其它网络链路。
可选地,在本发明的一些可能的实施方式中,当多媒体子系统网络将终端的通信链路信息从第一网络更新至第二网络后,则IMS网络业务基于第二网络实现。
可选地,在本发明的一些可能的实施方式中,当通信链路变更后,IMS网络更新终端的IP地址等与通信链路相关的信息。
举例说明,在本发明的一些可能的实施方式中,当第一网络为LTE网络,第二网络为无线Wi-Fi时,手机在室外时使用的是LTE网络,当手机进入室内后,手机的连接网络从LTE网络转为Wi-Fi网络,为了利用Wi-Fi网络做为IMS网络的接入点,则利用鉴权注册消息向IMS网络发送鉴权验证请求,请求进行鉴权验证,当鉴权验证通过后,IMS网络向终端发送200确认消息,说明基于无线Wi-Fi的鉴权注册成功,终端的IMS网络可基于无线Wi-Fi进行,从而IMS网络将更新终端的IP地址等与通信链路相关的信息,如将终端的IP地址从LTE网络的IP地址更新至无线Wi-Fi的IP地址。
S208、请求多媒体子系统网络切换核心网相关会话控制资源。
可以理解,当终端从第一网络状态切换至第二网络状态下,终端对IMS网络注册成功后,终端即利用第二网络通信链路接入IMS网络,IMS网络将其与IMS业务相关的会话控制资源切换至第二网络通信链路,从而可以基于第二网 络进行IMS业务。
可选地,在本发明的一些可能的实施方式中,核心网相关会话控制资源包括I-CSCF、S-CSCF及其它与IMS业务相关的资源。
S209、暂停终端第一网络接入模块的工作,并请求多媒体子系统网络释放第一网络通信链路资源。
可以理解,当在终端从第一网络状态切换至第二网络状态下,终端对IMS网络注册成功后,终端即利用第二网络通信链路接入IMS网络,可以中止第一网络通信链路的所有工作,也即暂停终端第一网络接入模块的工作,以及IMS网络释放第一网络通信链路资源,从而可以节约功耗。
举例说明,当手机从LTE网络切换至Wi-Fi网络后,并且手机通过Wi-Fi网络向IMS网络注册成功,从而手机的IMS网络可基于Wi-Fi网络进行,那么手机可暂停其LTE网络接入模块的工作,并且IMS网络释放LET网络通信链路资源,从而节约资源与功耗。
可以看出,本实施例的方案中,终端提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。
更进一步地,由于初始注册为明文注册,鉴权注册为密文注册,从而在网络切换注册时通过省去了初始注册的步骤,可防止初始注册时用户帐户隐私的泄露,提高注册过程的安全性。
为了更好地理解本发明和实施本发明实施例的上述方案,下面再以交互的方式举实施例进行说明,请参见图3,图3是本发明第三实施例提供的一种网络切换方法的流程示意图,其中,如图3所示,本发明的第三实施例提供的一种网络切换可以包括:
S301、在第一网络连接状态下,终端向多媒体子系统网络发送初始注册请求。
举例说明,在本发明的一些可能的实施方式中,当用户手机在LTE网络下需要注册VoLTE,则手机终端向IMS网络发送初始注册请求。
S302、终端接收多媒体子系统网络返回的未授权响应消息。
其中,未授权响应消息包括未授权响应及未授权响应携带的验证参数。
其中,未授权响应携带的验证参数为IMS网络发送给终端的,用于让终端利用该验证参数利用两者协商的方式生成鉴权注册消息,再由IMS网络验证该鉴权注册消息的计算是否正确,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,该验证参数包括(RAND,AUTH)两个参数。
举例说明,在本发明的一些可能的实施方式中,当用户手机在LTE网络下需要注册VoLTE,则向IMS网络发送初始注册请求,由于此时IMS网络还没有对终端的身份进行认证,所以IMS网络对初始注册请求做出响应,返回未授权响应消息给终端,要求手机终端进行进一步的鉴权验证。
S303、终端利用未授权响应消息生成鉴权注册消息。
其中,鉴权注册消息包括应答响应及应答响应携带的鉴权密钥。
可选地,在本发明的一些可能的实施方式中,所述鉴权注册消息还包括应答响应携带的鉴权密钥。
其中,应答响应为终端利用IMS网络发送的未授权响应利用一定的方式计算得到的,用于IMS利用应答响应判断鉴权是否成功,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,鉴权密钥包括保密性密钥(CK),以及完整性密钥(IK)。
举例说明,在本发明的一些可能的实施方式中,当用户手机在LTE网络下需要注册VoLTE,则向IMS网络发送初始注册请求,由于此时IMS网络还没有对终端的身份进行认证,所以IMS网络对初始注册请求做出响应,返回未授权响应消息给终端,要求手机终端进行进一步的鉴权验证,从而手机终端利用未授权响应消息生成鉴权注册消息。
S304、终端利用鉴权注册消息进行鉴权注册。
可选地,在本发明的一些可能的实施方式中,终端利用鉴权注册消息进行鉴权注册时,终端向IMS网络发送鉴权注册消息,IMS网络对该鉴权注册消息进行鉴权验证,当验证通过,IMS返回确认消息,鉴权注册完成。
举例说明,在本发明的一些可能的实施方式中,当手机终端利用未授权响应生成鉴权注册消息后,将该鉴权注册消息通过LTE发送至IMS网络,IMS网络对该鉴权注册消息进行鉴权验证,当验证通过,IMS返回确认消息,鉴权注册完成,即实现VoLTE。
S305、终端提取在第一网络连接状态下注册时的鉴权注册消息。
其中,鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册。
可选地,在本发明的一些可能的实施方式中,提取在第一网络连接状态下注册时的鉴权注册消息,包括:
保存未授权响应消息,并利用未授权响应消息生成所述鉴权注册消息;
或,保存鉴权注册消息。
举例说明,在本发明的一些可能的实施方式中,为了在下次网络从LTE切换至其它网络时节约初始注册步骤,手机终端提取前述注册步骤过程中的鉴权注册消息,从而在后续网络切换后可直接利用该鉴权注册消息进行鉴权注册。
S306、若终端从第一网络连接状态切换至第二网络连接状态,则利用鉴权注册消息向多媒体子系统网络发送鉴权验证请求。
其中,鉴权验证请求用于请求多媒体子系统网络对鉴权注册消息进行鉴权验证。
可选地,在本发明的一些可能的实施方式中,所述第一网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
所述第二网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
其中,所述第一网络与所述第二网络不同。
举例说明,在本发明的一些可能的实施方式中,当手机从LTE网络连接切换至Wi-Fi网络连接时,手机利用提取到的鉴权注册消息通过Wi-Fi网络发送至IMS网络,请求IMS网络对其鉴权验证。
S307、若鉴权验证通过,则终端接收多媒体子系统网络发送的确认消息。
其中,确认消息是指当IMS网络对鉴权注册信息进行鉴权验证并且通过后, 向终端发送的确认消息,用于通知终端鉴权验证已通过,鉴权注册完成。
举例说明,在本发明的一些可能的实施方式中,手机利用提取到的鉴权注册消息通过Wi-Fi网络发送至IMS网络,请求IMS网络对其鉴权验证,从而IMS网络对该鉴权注册信息进行鉴权验证,当验证通过后,IMS网络发送确认消息给手机,从而手机接收到IMS网络发送的确认消息,从而完成鉴权注册。
S308、多媒体子系统网络将终端的通信链路信息从第一网络更新至第二网络。
举例说明,在本发明的一些可能的实施方式中,当手机基于Wi-Fi网络的鉴权验证通过后,则说明手机的IMS业务可基于Wi-Fi网络实现,从而IMS网络将更新终端的通信链路信息,如终端的IP地址等与通信链路相关的信息,如将终端的IP地址从LTE网络的IP地址更新至无线Wi-Fi的IP地址,从而保证VoWiFi业务正常工作。
S309、多媒体子系统网络切换核心网相关会话控制资源。
可选地,在本发明的一些可能的实施方式中,核心网相关会话控制资源包括I-CSCF、S-CSCF及其它与IMS业务相关的资源。
举例说明,在本发明的一些可能的实施方式中,当手机从VoLTE切换至VoWiFi后,IMS网络切换核心网会话控制资源与网络相关资源从LTE网线至无线Wi-Fi网络,从而保证VoWiFi业务正常工作。
S310、多媒体子系统网络释放第一网络通信链路资源。
举例说明,在本发明的一些可能的实施方式中,当手机从VoLTE切换至VoWiFi后,IMS网络释放LTE网络通信链路资源,从而节约功耗。
需要说明,步骤S309和步骤S310没有严格的先后执行顺序。
S311、终端暂停第一网络接入模块的工作。
举例说明,在本发明的一些可能的实施方式中,当手机从VoLTE切换至VoWiFi后,手机暂停LTE网络接入模块的工作,从而从而可以节约手机功耗。
可以看出,本实施例的方案中,终端提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权 验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。
更进一步地,由于初始注册为明文注册,鉴权注册为密文注册,从而在网络切换注册时通过省去了初始注册的步骤,可防止初始注册时用户帐户隐私的泄露,提高注册过程的安全性。
本发明实施例还提供终端,该终端包括:
提取模块,用于提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;
发送模块,用于若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;
第一请求模块,若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
具体的,请参见图4,图4是本发明第四实施例提供的一种终端的结构示意图,其中,如图4所示,本发明第四实施例提供的一种终端400可以包括:
提取模块410、发送模块420和第一请求模块430。
其中,提取模块410,用于提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册。
其中,第一网络连接状态是指终端当前使用的是第一网络的通信链路实现网络通信,终端是指具有网络连接功能的终端,可以为UE(user equipment)终端或携带无线网络接口卡(Station,STA)终端,如手机、平板电脑、多媒体设备等,例如,当用户手机使用4G(the 4th Generation mobile communication technology,第四代移动通信技术)网络进行网络连接时,则用户手机处于4G网络连接状态。
其中,参见图1-b,需要说明,一般情况下,如当终端初次注册IMS网络时, 终端注册IMS网络时的流程包括初始注册和鉴权注册。初始注册过程是由终端向IMS网络发起的注册过程,注册消息将依次通过eNodeB(Evolved Node B,基站)、P-CSCF(Proxy Call Session Control Function,代理呼叫会话控制功能)、I-CSCF(Interrogating CSCF,查询CSCF)再发送至S-CSCF(Serving CSCF,服务CSCF),并通过HSS(Home Subscriber Server,归属签约用户服务器)对其进行身份认证。从而当终端向IMS网络发起注册请求时,IMS网络会发送401未授权响应并携带鉴权验证参数(RAND,AUTH)向终端发起挑战,终端接收到该响应后会根据该响应进行鉴权响应参数的计算得到应答响应及鉴权密钥,之后再发起鉴权注册流程;鉴权注册流程是终端将应答响应及鉴权密钥发送给IMS网络,由IMS网络完成鉴权及密钥协商的过程,并返回注册成功的确认消息200(OK)。
其中,终端发送初始注册请求消息中携带有私有用户身份标识的信息。通常对于VoLTE用户来说,其私有用户身份标识是:username@reaml,其中,usename是用户的IMSI(International Mobile Subscriber Identification Number,国际移动用户识别码)号码,reaml是归属网络域名。例如:当某用户的IMSI号码:234150999999999,则私有用户身份标识的形式为:234150999999999@ims.mnc015.mcc234.3gppnetwork.org,虽然终端和S-CSCF之间可以通过AKA(Authentication and Key Agreement,第三代移动通讯网络的认证与密钥协商协议)机制协商的安全性密钥对传输信息进行加密性和完整性保护,但是注册请求消息由于是终端和S-CSCF未通信之前发送的,也即是在安全密钥尚未协商时发送的,所以该消息没有受到任何安全保护而是用明文发送的。
其中,鉴权注册信息是指在初始注册以后、鉴权注册之前保存的用于鉴权注册的中间信息。
可选地,在本发明的另一些可能的实施方式中,鉴权注册信息可以为利用401未授权响应及其携带的鉴权验证参数(RAND,AUTH)按照一定的规则进行鉴权响应参数的计算后得到的鉴权密钥及应答响应,从而当提取了初始注册以后的鉴权注册信息后,则在下次注册的时候可以不需要再对终端进行初始鉴权,可直接进行鉴权注册。
可以理解,通过提取鉴权注册信息,则可以在切换网络时直接利用鉴权注册信息进行鉴权注册,从而省去了初始注册的步骤。
发送模块420,用于若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证。
其中,终端从第一网络连接状态切换至第二网络连接状态是指终端从使用第一网络通信链路进行网络通信的状态下切换至使用第二网络通信链路进行网络通信的状态,如终端之前利用4G网络进行通信,然后在进入无线Wi-Fi覆盖的范围后,终端的从原来的4G网络通信转为利用无线Wi-Fi进行网络通信。
可选地,在本发明的一些可能实施方式中,终端向多媒体子系统发送的鉴权注册信息为终端响应未授权响应并利用鉴权验证参数计算出来的鉴权密钥以及应答响应。
其中,鉴权验证请求是指终端在鉴权注册时向IMS网络发送的鉴权验证请求,请求IMS网络对终端发送的鉴权注册信息进行鉴权验证。
举例说明,在本发明的一些可能的实施方式中,当第一网络为LTE网络,第二网络为无线Wi-Fi时,手机在室外时使用的是LTE网络,当手机进入室内无线Wi-Fi覆盖点后,手机的连接网络从LTE网络转为Wi-Fi网络,为了利用Wi-Fi网络做为IMS网络的接入点,则利用鉴权注册消息向IMS网络发送鉴权验证请求,请求进行鉴权验证。
第一请求模块430,若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
其中,确认消息是指当IMS网络对鉴权注册信息进行鉴权验证并且通过后,向终端发送的确认消息,用于通知终端鉴权验证已通过,鉴权注册完成;
通信链路信息是指终端与IMS网络之间进行通信的网络链路,可以为移动运营商提供的网络,此时可通过LTE网络接入IMS网络提供的语音业务,也即VoLTE,也可以通过Wi-Fi接入IMS网络提供的语音业务,也即VoWiFi,该通信链路信息还可以为其它网络链路。
可选地,在本发明的一些可能的实施方式中,当多媒体子系统网络将终端的通信链路信息从第一网络更新至第二网络后,则IMS网络业务基于第二网络实现。
可选地,在本发明的一些可能的实施方式中,当通信链路变更后,IMS网络更新终端的IP地址等与通信链路相关的信息。
举例说明,在本发明的一些可能的实施方式中,当第一网络为LTE网络,第二网络为无线Wi-Fi时,手机在室外时使用的是LTE网络,当手机进入室内后,手机的连接网络从LTE网络转为Wi-Fi网络,为了利用Wi-Fi网络做为IMS网络的接入点,则利用鉴权注册消息向IMS网络发送鉴权验证请求,请求进行鉴权验证,当鉴权验证通过后,IMS网络向终端发送200确认消息,说明基于无线Wi-Fi的鉴权注册成功,终端的IMS网络可基于无线Wi-Fi进行,从而IMS网络将更新终端的IP地址等与通信链路相关的信息,如将终端的IP地址从LTE网络的IP地址更新至无线Wi-Fi的IP地址。
可以理解的是,本实施例的终端400的各功能模块的功能可根据上述方法实施例中的方法具体实现,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
可以看出,本实施例的方案中,终端400提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端400从所述第一网络连接状态切换至第二网络连接状态,则终端400利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权验证通过,则终端400接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。
更进一步地,由于初始注册为明文注册,鉴权注册为密文注册,从而在网络切换注册时通过省去了初始注册的步骤,可防止初始注册时用户帐户隐私的泄露,提高注册过程的安全性。
请参见图5,图5是本发明第五实施例提供的一种终端的结构示意图,其中,如图5所示,本发明第五实施例提供的一种终端500可以包括:
提取模块510、发送模块520和第一请求模块530。
其中,提取模块510、发送模块520和第一请求模块530的部分功能和本发明第四实施例提供的提取模块410、发送模块420和第一请求模块430功能一样,与本发明第四实施例相同的功能在此不再赘述,另外,本发明第五实施例的可穿戴设备500在本发明第四实施例的可穿戴设备400的基础上有所补充,详述如下。
可选地,在本发明的一些可能的实施方式中,所述终端500还用于:
所述终端向所述多媒体子系统网络发送初始注册请求;
接收所述多媒体子系统网络返回的未授权响应消息,其中,所述未授权响应消息包括未授权响应;
利用所述未授权响应消息生成鉴权注册消息,所述鉴权注册消息包括应答响应及所述应答响应携带的鉴权密钥;
利用所述鉴权注册消息进行鉴权注册。
可选地,在本发明的一些可能的实施方式中,所述提取模块510具体用于:
保存所述未授权响应消息,并利用所述未授权响应消息生成所述鉴权注册消息;
或,保存所述鉴权注册消息。
其中,未授权响应携带的验证参数为IMS网络发送给终端的,用于让终端利用该验证参数利用两者协商的方式生成鉴权注册消息,再由IMS网络验证该鉴权注册消息的计算是否正确,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,该验证参数包括(RAND,AUTH)两个参数。
其中,应答响应为终端利用IMS网络发送的未授权响应利用一定的方式计算得到的,用于IMS利用应答响应判断鉴权是否成功,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,所述鉴权注册消息还包括应答响应携带的鉴权密钥。
可选地,在本发明的一些可能的实施方式中,鉴权密钥包括保密性密钥(CK),以及完整性密钥(IK)。
上述注册流程也即,终端在第一网络连接状态下向IMS网络注册时,首先向IMS网络发送初始注册请求,该注册请求中包含终端私有用户身份标识信息, 由于此时IMS还没有对终端的身份进行认证,所以IMS网络对初始注册请求做出响应,返回未授权响应消息给终端,要求终端进行进一步的鉴权验证,终端接收到该未授权响应消息后,利用该未授权响应生成鉴权注册消息,再利用该鉴权注册消息中的应答响应进行鉴权,那么可以理解,可直接保存鉴权注册消息,从而利用鉴权注册消息进行进一步地鉴权注册,可省去初始注册的步骤,也可保存未授权响应消息,再利用未授权响应消息生成鉴权注册消息,同样可省去初始注册的步骤。
可选地,在本发明的一些可能的实施方式中,所述终端还包括:
暂停模块540,用于暂停所述终端第一网络接入模块的工作,并请求所述多媒体子系统网络释放所述第一网络通信链路资源。
可以理解,当在终端从第一网络状态切换至第二网络状态下,终端对IMS网络注册成功后,终端即利用第二网络通信链路接入IMS网络,可以中止第一网络通信链路的所有工作,也即暂停终端第一网络接入模块的工作,以及IMS网络释放第一网络通信链路资源,从而可以节约功耗。
举例说明,当手机从LTE网络切换至Wi-Fi网络后,并且手机通过Wi-Fi网络向IMS网络注册成功,从而手机的IMS网络可基于Wi-Fi网络进行,那么手机可暂停其LTE网络接入模块的工作,并且IMS网络释放LET网络通信链路资源,从而节约资源与功耗。
可选地,在本发明的一些可能的实施方式中,所述终端还包括:
第二请求模块550,用于请求所述多媒体子系统网络切换核心网相关会话控制资源。
可以理解,当终端从第一网络状态切换至第二网络状态下,终端对IMS网络注册成功后,终端即利用第二网络通信链路接入IMS网络,IMS网络将其与IMS业务相关的会话控制资源切换至第二网络通信链路,从而可以基于第二网络进行IMS业务。
可选地,在本发明的一些可能的实施方式中,核心网相关会话控制资源包括I-CSCF、S-CSCF及其它与IMS业务相关的资源。
可选地,在本发明的一些可能的实施方式中,所述第一网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
所述第二网络为提供语音服务的移动网络、提供语音服务的无线局域网或 提供语音服务的无线保真;
其中,所述第一网络与所述第二网络不同。
可以理解,该网络切换方法不对网络进行限制,可以在各种不同的网络之间进行切换。
可选地,在本发明的一些可能实施方式中,当第一网络为LTE时,第二网络可以为Wi-Fi或Wlan,从而可实现从VoLTE到VoWiFi或VoWlan的切换。
可选地,在本发明的另一些可能的实施方式中,当第一网络为Wi-Fi时,第二网络可以为LTE,从而可实现从VoWiFi到VoLTE的切换。
可选地,在本发明的另一些可能的实施方式中,当从VoLTE切换至VoWiFi,又可以以同样的方式从VoWiFi切换至VoLTE,此时鉴权注册消息还可以为第一次在VoLTE进行初始注册以及鉴权注册时保存的鉴权注册消息。
可以理解的是,本实施例的终端500的各功能模块的功能可根据上述方法实施例中的方法具体实现,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
可以看出,本实施例的方案中,终端500提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端500从所述第一网络连接状态切换至第二网络连接状态,则终端500利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权验证通过,则终端500接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。
更进一步地,由于初始注册为明文注册,鉴权注册为密文注册,从而在网络切换注册时通过省去了初始注册的步骤,可防止初始注册时用户帐户隐私的泄露,提高注册过程的安全性。
参见图6,图6是本发明第六实施例提供的一种终端的结构示意图。如图6所示,本发明第六实施例提供的一种终端600可以包括:至少一个总线601、与 总线相连的至少一个处理器602以及与总线相连的至少一个存储器603。
其中,处理器602通过总线601,调用存储器603中存储的代码以用于提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
其中,第一网络连接状态是指终端当前使用的是第一网络的通信链路实现网络通信,终端是指具有网络连接功能的终端,可以为UE(user equipment)终端或携带无线网络接口卡(Station,STA)终端,如手机、平板电脑、多媒体设备等,例如,当用户手机使用4G(the 4th Generation mobile communication technology,第四代移动通信技术)网络进行网络连接时,则用户手机处于4G网络连接状态。
可选地,在本发明的一些可能的实施方式中,所述在所述第一网络连接状态下注册时,所述处理器602用于:
所述终端向所述多媒体子系统网络发送初始注册请求;
接收所述多媒体子系统网络返回的未授权响应消息,其中,所述未授权响应消息包括未授权响应;
利用所述未授权响应消息生成鉴权注册消息,所述鉴权注册消息包括应答响应及所述应答响应携带的鉴权密钥;
利用所述鉴权注册消息进行鉴权注册;
所述提取在第一网络连接状态下注册时的鉴权注册消息,所述处理器602用于:
保存所述未授权响应消息,并利用所述未授权响应消息生成所述鉴权注册消息;
或,保存所述鉴权注册消息。
其中,未授权响应携带的验证参数为IMS网络发送给终端的,用于让终端利用该验证参数利用两者协商的方式生成鉴权注册消息,再由IMS网络验证该 鉴权注册消息的计算是否正确,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,该验证参数包括(RAND,AUTH)两个参数。
其中,应答响应为终端利用IMS网络发送的未授权响应利用一定的方式计算得到的,用于IMS利用应答响应判断鉴权是否成功,从而做出是否鉴权成功的应答。
可选地,在本发明的一些可能的实施方式中,所述鉴权注册消息还包括应答响应携带的鉴权密钥。
可选地,在本发明的一些可能的实施方式中,鉴权密钥包括保密性密钥(CK),以及完整性密钥(IK)。
可选地,在本发明的一些可能的实施方式中,所述处理器602还用于:
暂停所述终端第一网络接入模块的工作,并请求所述多媒体子系统网络释放所述第一网络通信链路资源。
可选地,在本发明的一些可能的实施方式中,所述处理器602还用于:
请求所述多媒体子系统网络切换核心网相关会话控制资源。
可选地,在本发明的一些可能的实施方式中,所述第一网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
所述第二网络为提供语音服务的移动网络、提供语音服务的无线局域网或提供语音服务的无线保真;
其中,所述第一网络与所述第二网络不同。
可以理解,该网络切换方法不对网络进行限制,可以在各种不同的网络之间进行切换。
可以理解的是,本实施例的终端600的各功能模块的功能可根据上述方法实施例中的方法具体实现,其具体实现过程可以参照上述方法实施例的相关描述,此处不再赘述。
可以看出,本实施例的方案中,终端600提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;若所述终端600从所述第一网络连接状态切换至第二网络连接状态,则终端600利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴 权验证;若所述鉴权验证通过,则终端600接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。通过保存在第一网络连接状态下注册时的鉴权注册消息,从而在第二网络连接状态下注册时直接利用该鉴权注册消息进行鉴权注册,省去了初始注册的步骤,操作步骤大大简化,也降低了网络切换时注册的信令负荷。
更进一步地,由于初始注册为明文注册,鉴权注册为密文注册,从而在网络切换注册时通过省去了初始注册的步骤,可防止初始注册时用户帐户隐私的泄露,提高注册过程的安全性。
本发明实施例还提供一种计算机存储介质,其中,该计算机存储介质可存储有程序,该程序执行时包括上述方法实施例中记载的网络切换方法的部分或全部步骤。
需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本发明并不受所描述的动作顺序的限制,因为依据本发明,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本发明所必须的。
在上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。
在本申请所提供的几个实施例中,应该理解到,所揭露的装置,可通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明的各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可为个人计算机、服务器或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,以上实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的范围。

Claims (10)

  1. 一种网络切换方法,其特征在于,所述方法包括:
    提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;
    若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;
    若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
  2. [根据细则26改正11.12.2015]
    根据权利要求1所述的方法,其特征在于,所述在所述第一网络连接状态下注册,包括:
    所述终端向所述多媒体子系统网络发送初始注册请求;
    接收所述多媒体子系统网络返回的未授权响应消息,其中,所述未授权响应消息包括未授权响应及所述未授权响应携带的验证参数;
    利用所述未授权响应消息生成鉴权注册消息,所述鉴权注册消息包括应答响应;
    利用所述鉴权注册消息进行鉴权注册。
  3. [根据细则26改正11.12.2015] 
    根据权利要求2所述的方法,其特征在于,所述提取在第一网络连接状态下注册时的鉴权注册消息,包括:保存所述未授权响应消息,并利用所述未授权响应消息生成所述鉴权注册消息;或,保存所述鉴权注册消息。
  4. 根据权利要求1-3任一所述的方法,其特征在于,所述若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络后,所述方法还包括:
    暂停所述终端第一网络接入模块的工作,并请求所述多媒体子系统网络释放所述第一网络通信链路资源。
  5. 根据权利要求4所述的方法,其特征在于,所述若所述鉴权验证通过, 则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络后,所述方法还包括:
    请求所述多媒体子系统网络切换核心网相关会话控制资源。
  6. 一种终端,其特征在于,所述终端包括:
    提取模块,用于提取在第一网络连接状态下注册时的鉴权注册消息,所述鉴权注册消息用于终端向多媒体子系统网络进行鉴权注册;
    发送模块,用于若所述终端从所述第一网络连接状态切换至第二网络连接状态,则利用所述鉴权注册消息向所述多媒体子系统网络发送鉴权验证请求,所述鉴权验证请求用于请求所述多媒体子系统网络对所述鉴权注册消息进行鉴权验证;
    第一请求模块,若所述鉴权验证通过,则接收所述多媒体子系统网络发送的确认消息,并请求所述多媒体子系统网络将所述终端的通信链路信息从第一网络更新至第二网络。
  7. 根据权利要求6所述终端,其特征在于,所述终端还用于:
    所述终端向所述多媒体子系统网络发送初始注册请求;
    接收所述多媒体子系统网络返回的未授权响应消息,其中,所述未授权响应消息包括未授权响应及所述未授权响应携带的验证参数;
    利用所述未授权响应消息生成鉴权注册消息,所述鉴权注册消息包括应答响应;
    利用所述鉴权注册消息进行鉴权注册。
  8. 根据权利要求7所述的终端,其特征在于,所述提取模块用于:
    保存所述未授权响应消息,并利用所述未授权响应消息生成所述鉴权注册消息;
    或,保存所述鉴权注册消息。
  9. 根据权利要求6-8任一所述的终端,其特征在于,所述终端还包括:
    暂停模块,用于暂停所述终端第一网络接入模块的工作,并请求所述多媒体子系统网络释放所述第一网络通信链路资源。
  10. 根据权利要求9所述的终端,其特征在于,所述终端还包括:
    第二请求模块,用于请求所述多媒体子系统网络切换核心网相关会话控制资源。
PCT/CN2015/091374 2015-08-11 2015-09-30 一种网络切换方法及终端 WO2017024671A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510489642.7 2015-08-11
CN201510489642.7A CN105049442B (zh) 2015-08-11 2015-08-11 一种网络切换方法及终端

Publications (1)

Publication Number Publication Date
WO2017024671A1 true WO2017024671A1 (zh) 2017-02-16

Family

ID=54455653

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/091374 WO2017024671A1 (zh) 2015-08-11 2015-09-30 一种网络切换方法及终端

Country Status (2)

Country Link
CN (1) CN105049442B (zh)
WO (1) WO2017024671A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110800334A (zh) * 2017-10-26 2020-02-14 深圳市欢太科技有限公司 一种用户设备通话检测方法及相关产品
CN111314922A (zh) * 2020-02-21 2020-06-19 宇龙计算机通信科技(深圳)有限公司 释放频谱资源的方法及相关装置
US10791154B2 (en) * 2018-02-01 2020-09-29 Edgewater Networks, Inc. Holding registration messages during communication session switching
CN112911554A (zh) * 2021-01-29 2021-06-04 中国联合网络通信集团有限公司 业务开通的方法和装置、终端

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107231332B (zh) * 2016-03-24 2020-09-25 华为技术有限公司 安全策略确定方法及装置
CN107529200B (zh) * 2016-06-21 2021-02-23 中兴通讯股份有限公司 一种VoLTE中终端发生网络切换后释放资源的方法及装置
CN107529160B (zh) * 2016-06-21 2022-07-15 中兴通讯股份有限公司 一种VoWiFi网络接入方法和系统、终端及无线访问接入点设备
CN106658630B (zh) * 2016-06-30 2021-01-26 努比亚技术有限公司 一种通信终端、基站、系统及方法
CN107786975B (zh) * 2016-08-30 2022-05-13 中兴通讯股份有限公司 一种语音业务注册方法及装置、移动终端
WO2018152961A1 (zh) * 2017-02-22 2018-08-30 华为技术有限公司 一种信息传输方法及设备
CN109104397A (zh) * 2017-06-21 2018-12-28 中兴通讯股份有限公司 一种自适应接入网络的实现方法及终端
CN109302728B (zh) * 2017-07-24 2020-10-20 展讯通信(上海)有限公司 通话切换方法及装置、存储介质、基站、终端
CN111565388B (zh) * 2020-04-02 2023-09-19 维沃移动通信有限公司 一种网络注册方法及电子设备
CN111669818B (zh) * 2020-06-03 2022-08-02 维沃移动通信有限公司 Wi-Fi控制方法、装置及电子设备
CN112601224B (zh) * 2020-12-03 2023-02-10 海能达通信股份有限公司 一种呼叫切换方法、装置及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2009009519A1 (en) * 2007-07-09 2009-01-15 Interdigital Technology Corporation Method and apparatus for handover and session continuity using pre-registration tunneling procedure
CN101478796A (zh) * 2009-01-20 2009-07-08 中国科学院计算技术研究所 一种异构网络分级切换控制信令系统及其切换方法
CN101932057B (zh) * 2009-06-22 2013-08-28 华为技术有限公司 切换处理方法、切换处理的通信装置及通信系统
CN103458450A (zh) * 2009-06-22 2013-12-18 华为技术有限公司 切换处理方法、切换处理的通信装置及通信系统

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101175329A (zh) * 2007-11-02 2008-05-07 华为技术有限公司 基于ip多媒体子系统的跨分组域切换方法、系统及设备
CN102056251B (zh) * 2009-11-04 2013-04-03 中国移动通信集团公司 一种网络切换的方法、系统及设备
CN104185220B (zh) * 2013-05-22 2018-05-01 中国电信股份有限公司 Ims核心网设备失效切换方法和边缘接入控制设备
CN104038974B (zh) * 2014-06-11 2017-03-29 中国联合网络通信集团有限公司 一种语音业务的处理方法及装置
CN104519537A (zh) * 2014-12-31 2015-04-15 华为技术有限公司 通信方法、用户设备及通信装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2009009519A1 (en) * 2007-07-09 2009-01-15 Interdigital Technology Corporation Method and apparatus for handover and session continuity using pre-registration tunneling procedure
CN101478796A (zh) * 2009-01-20 2009-07-08 中国科学院计算技术研究所 一种异构网络分级切换控制信令系统及其切换方法
CN101932057B (zh) * 2009-06-22 2013-08-28 华为技术有限公司 切换处理方法、切换处理的通信装置及通信系统
CN103458450A (zh) * 2009-06-22 2013-12-18 华为技术有限公司 切换处理方法、切换处理的通信装置及通信系统

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110800334A (zh) * 2017-10-26 2020-02-14 深圳市欢太科技有限公司 一种用户设备通话检测方法及相关产品
US10791154B2 (en) * 2018-02-01 2020-09-29 Edgewater Networks, Inc. Holding registration messages during communication session switching
CN111314922A (zh) * 2020-02-21 2020-06-19 宇龙计算机通信科技(深圳)有限公司 释放频谱资源的方法及相关装置
CN111314922B (zh) * 2020-02-21 2023-09-15 宇龙计算机通信科技(深圳)有限公司 释放频谱资源的方法及相关装置
CN112911554A (zh) * 2021-01-29 2021-06-04 中国联合网络通信集团有限公司 业务开通的方法和装置、终端

Also Published As

Publication number Publication date
CN105049442B (zh) 2018-06-15
CN105049442A (zh) 2015-11-11

Similar Documents

Publication Publication Date Title
WO2017024671A1 (zh) 一种网络切换方法及终端
CN109842880B (zh) 路由方法、装置及系统
US11582602B2 (en) Key obtaining method and device, and communications system
US11178584B2 (en) Access method, device and system for user equipment (UE)
US10798082B2 (en) Network authentication triggering method and related device
US10708783B2 (en) Method for performing multiple authentications within service registration procedure
JP2013524556A (ja) 通信システム
CN107567017B (zh) 无线连接系统、装置及方法
CN110858992A (zh) 路由方法、装置及系统
CN102318386A (zh) 向网络的基于服务的认证
WO2016161832A1 (zh) 一种通过托管sim卡实现移动通信的系统及相应的方法
CN108781110B (zh) 用于通过通信网络中继数据的系统和方法
EP3284232B1 (en) Wireless communications
CN108476212A (zh) 动态wlan连接
WO2015100975A1 (zh) 一种选择认证算法的方法、装置及系统
US9326141B2 (en) Internet protocol multimedia subsystem (IMS) authentication for non-IMS subscribers
WO2013152740A1 (zh) 用户设备的认证方法、装置及系统
CN109982319A (zh) 用户认证方法、装置、系统、节点、服务器及存储介质
KR101485801B1 (ko) 이동 통신 시스템의 인증과 비계층 프로토콜 보안 운영을 효율적으로 지원하는 관리 방법 및 시스템
EP4203392A1 (en) Authentication support for an electronic device to connect to a telecommunications network
WO2020049210A1 (en) Method and apparatus for determining user equipment status for serving call state control function
WO2017132906A1 (zh) 获取、发送用户设备标识的方法及设备
CN108632936B (zh) 一种锚定核心网的方法、ue和pgw
WO2023126296A1 (en) Authentication support for an electronic device to connect to a telecommunications network
JP7028583B2 (ja) Lte通信システム及び通信制御方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15900866

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15900866

Country of ref document: EP

Kind code of ref document: A1