WO2017036107A1 - 用户设备差异化接入网络的方法、基站及计算机存储介质 - Google Patents

用户设备差异化接入网络的方法、基站及计算机存储介质 Download PDF

Info

Publication number
WO2017036107A1
WO2017036107A1 PCT/CN2016/074596 CN2016074596W WO2017036107A1 WO 2017036107 A1 WO2017036107 A1 WO 2017036107A1 CN 2016074596 W CN2016074596 W CN 2016074596W WO 2017036107 A1 WO2017036107 A1 WO 2017036107A1
Authority
WO
WIPO (PCT)
Prior art keywords
target
cell
imsi information
access
information
Prior art date
Application number
PCT/CN2016/074596
Other languages
English (en)
French (fr)
Inventor
江坤俊
付昂
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2017036107A1 publication Critical patent/WO2017036107A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/062Pre-authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/26Network addressing or numbering for mobility support
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/20Selecting an access point

Definitions

  • the present invention relates to the field of communications, and in particular, to a method for a user equipment (UE, User Equipment) to differentiate access to a network, a base station, and a computer storage medium.
  • UE user equipment
  • the access to the network is usually performed according to the access class (AC, Access Class) of the UE; the AC is written in the SIM card of the UE to indicate the priority of the UE accessing the network.
  • AC access class
  • the AC is 0 to 9 is the normal priority, and the AC is 11 to 15 is the high priority.
  • the protocol stipulates that a high-priority UE has priority access rights, and a low-priority user can access only when a high-priority UE is allowed to access the cell.
  • the cell can preferentially enable high-priority users to access and ensure resources of high-priority users by setting the system information block 1 (SIB1, System Information Block Type 1) and SIB2 related fields. distribution.
  • SIB1 System Information Block 1
  • SIB2 System Information Block Type 1
  • scenario 1 a specific-purpose cell, only certain specific international mobile subscriber identity codes (IMSI, International Mobile Subscriber) are allowed. The identification of the UE can be accessed, and other UEs cannot access in any way.
  • scenario 2 When an important conference is held in the country, many high-priority users access the same cell. The cell load is heavy and may have business performance. Certainly, UEs with special users (such as full-time reporters) need exclusive resources and do not want to be affected by any other UE.
  • IMSI international mobile subscriber identity codes
  • the evolved base station eNB, Evolved Node B
  • the evolved base station cannot know the IMSI of the UE, and cannot perform targeted processing on a specific UE with a specific IMSI.
  • the AC of the SIM card of the specific UE is the highest level 15, access by other UEs with an AC of 15 cannot be prohibited. That is, no matter how the configuration is performed, even if the AC of a specific UE is changed to a high priority, the effect of accessing only a specific UE and prohibiting other high priority UEs from being accessed normally cannot be achieved.
  • embodiments of the present invention are directed to a method, a base station, and a computer storage medium for a UE differentiated access network.
  • a method for UE differential access to a network includes:
  • the analog core network sends an identity identification request to the UE
  • the UE corresponding to the target IMSI information is accessed by the target cell.
  • the receiving the identity response returned by the UE, and extracting and obtaining the IMSI information from the identity recognition response includes:
  • the identity recognition response as an identity recognition response including an IMSI code
  • the NAS code stream is in a plain text form or an integrity protection form.
  • the local cell that obtains the IMSI information is extracted as a target cell
  • the user access policy of the target cell includes allowing access to the target UE with the target IMSI information, prohibiting access to other UEs that do not have the target IMSI information, or allowing no
  • the other UEs with the target IMSI information are forcibly switched to the neighboring cells that are covered by the target cell; the The UE corresponding to the target IMSI information accesses the corresponding target cell, including:
  • the IMSI information is the target IMSI information, allowing the UE corresponding to the IMSI information to access the target cell;
  • the UE corresponding to the IMSI information is not allowed to access the target cell; or the UE corresponding to the IMSI information is allowed to access the target cell, and After the access, the handover request message is sent to the neighboring cell that is covered by the target cell, and the handover request message is used by the neighboring cell to allow the UE corresponding to the IMSI information to be accessed after receiving the handover request message.
  • the local cell that obtains the IMSI information is the same coverage neighboring cell of the target cell, and the user policy of the target cell is to prohibit direct access by the UE, and to allow switching from the same coverage neighboring cell of the target cell.
  • the user access policy of the neighboring cell is to allow all UEs to access, and the target UE with the target IMSI information is forcibly switched to the target cell after being accessed; and the target IMSI information is corresponding according to the user access policy.
  • the UE accesses the corresponding target cell, including:
  • the UE corresponding to the target IMSI information is allowed to access, and after the access, the handover request message is sent to the target cell, where the handover request message is used by the target cell to receive the After the handover request message is described, the UE corresponding to the target IMSI information is allowed to access.
  • the local cell that obtains the IMSI information is not the target cell, and the local cell user access policy includes allowing all UEs to access, and the target UE having the target IMSI information carries the obtained target in the subsequent handover request message.
  • the UE corresponding to the IMSI information is allowed to access the local cell, and when the cell handover is required or when the target UE moves to the target cell coverage, the UE carries the target.
  • the handover request message of the corresponding information of the IMSI information or the target IMSI information is mapped to the handover cell or the target cell; the target IMSI information is used by the target cell to allow the target corresponding to the target IMSI information after receiving the handover request message UE access.
  • the handover request message carrying the corresponding information of the target IMSI information or the target IMSI information mapping is sent to the handover cell or the target cell, including:
  • the protocol extension field Transmitting, by the protocol extension field, the new protocol protocol, or the multiplexed current protocol function, the conflicting field, the target IMSI information, or the mapping information of the target IMSI information, to the handover cell or target.
  • the corresponding information of the target IMSI information mapping is used by the handover cell or the target cell to obtain the target IMSI information.
  • a base station comprising:
  • a sending unit configured to simulate that the core network sends an identity identification request to the UE
  • a receiving unit configured to receive an identity response returned by the UE
  • An extracting unit configured to extract and obtain IMSI information from an identity response received by the receiving unit
  • the access processing unit is configured to access, according to the user access policy, the UE corresponding to the target IMSI information to the target cell when the IMSI information extracted by the extracting unit is the target IMSI information.
  • the base station further includes: a determining unit; wherein
  • the determining unit is configured to: after the access unit receives the identity recognition response, determine a NAS code stream according to an access layer NAS protocol and a NAS code stream in the identity recognition response; and according to a NAS protocol and Determining, by the NAS code stream form, the identity recognition response as an identity recognition response including an IMSI code;
  • the extracting unit is configured to, after the determining unit determines that the identity recognition response is an identity recognition response including an IMSI code, according to the NAS protocol and the NAS code stream form, from the IMSI code The IMSI information is extracted in the identity response.
  • the NAS code stream is in a plain text form or an integrity protection form.
  • the local cell that obtains the IMSI information is extracted as a target cell
  • the user access policy of the target cell includes allowing access to the target UE with the target IMSI information, prohibiting access to other UEs that do not have the target IMSI information, or allowing no
  • the other UEs with the target IMSI information are forcibly switched to the neighboring cells covered by the target cell;
  • the access processing unit is configured to allow the UE corresponding to the IMSI information to access the target cell when the IMSI information is target IMSI information, or configured to: when the IMSI information is not When the target IMSI information is not allowed, the UE corresponding to the IMSI information is not allowed to access the target cell; or the UE corresponding to the IMSI information is allowed to access the target cell, and after accessing the
  • the target cell and the neighboring cell that are in the coverage send a handover request message, where the handover request message is used by the neighboring cell to allow the UE corresponding to the IMSI information to access after receiving the handover request message.
  • the local cell that obtains the IMSI information is the same coverage neighboring cell of the target cell, and the user policy of the target cell is to prohibit direct access by the UE, and to allow switching from the same coverage neighboring cell of the target cell.
  • the user policy of the local cell is to allow all UEs to access, and the target UE with the target IMSI information is forcibly switched to the target cell after accessing;
  • the access processing unit is configured to allow the UE corresponding to the IMSI information to access the local cell when the IMSI information is not the target IMSI information; or configured to be in the IMSI information
  • the UE corresponding to the target IMSI information is allowed to access the local cell, and after the access, the handover request message is sent to the target cell, where the handover request message is used by the target cell to receive the handover.
  • the UE corresponding to the target IMSI information is allowed to access.
  • the local cell that obtains the IMSI information is not the target cell, and the local cell user access policy includes allowing all UEs to access, and the target UE having the target IMSI information carries the obtained target in the subsequent handover request message. IMSI information or corresponding information mapped by the target IMSI information;
  • the access processing unit is configured to allow the UE corresponding to the IMSI information to access the local cell when the IMSI information is not the target IMSI information; or configured to be in the IMSI information
  • the target IMSI information is used, the UE corresponding to the IMSI information is allowed to access the local cell, and when the cell handover is required or when the target UE moves to the target cell coverage, the target IMSI information or the target IMSI information is transmitted.
  • the target IMSI information is used by the target cell to allow the target UE corresponding to the target IMSI information to access after receiving the handover request message by the target cell.
  • the access processing unit is configured to carry the target IMSI information or the target IMSI information in the handover request message by using a protocol extension field, a new protocol cell carrying, or a multiplexing current protocol function non-collision field.
  • the mapped corresponding information is sent to the handover cell or the target cell; the mapping information of the target IMSI information is used for the handover cell or the target cell to obtain the target IMSI information.
  • a computer storage medium comprising a set of instructions that, when executed, cause at least one processor to perform the UE of any one of claims 1 to A method of differentiated access networks.
  • An embodiment of the present invention provides a method for a UE to differentiate access to a network, a base station, and a computer storage medium, where the simulated core network sends an identity identification request to the UE, receives an identity recognition response returned by the UE, and receives the identity recognition response from the UE. And extracting the IMSI information; according to the user access policy, when the IMSI information is the target IMSI information, the UE corresponding to the target IMSI information is accessed by the target cell.
  • the embodiment of the present invention can obtain the IMSI information of the user, and apply the IMSI information to access a specific user with the target IMSI information to a specific target cell.
  • FIG. 1 is a schematic flowchart of a method for a UE to differentiate access to a network according to Embodiment 1 of the present invention
  • FIG. 2 is a schematic flowchart of a method for a UE to differentiate access to a network according to Embodiment 2 of the present invention
  • FIG. 3 is a schematic diagram of a two-cell scenario according to Embodiment 2 of the present invention.
  • FIG. 4 is a schematic diagram of a three-cell scenario according to Embodiment 2 of the present invention.
  • FIG. 5 is a structural block diagram of a base station according to Embodiment 3 of the present invention.
  • the base station simulates a core network to send an identity identification request to the UE, receives an identity recognition response returned by the UE, and extracts and obtains IMSI information from the identity recognition response; according to the user access policy, When the IMSI information is the target IMSI information, the UE corresponding to the target IMSI information is accessed by the target cell.
  • An embodiment of the present invention provides a method for a UE to differentiate access to a network, as shown in FIG. 1 .
  • the methods include:
  • Step 101 The analog core network sends an identity identification request to the UE.
  • the UE When the UE searches for the local cell under the eNB and prepares to access the local cell, the UE needs to establish a radio resource control (RRC) connection with the eNB.
  • RRC radio resource control
  • the eNB After the eNB receives the RRC connection setup complete (Connection Setup Complete), the RRC connection is established between the eNB and the UE, and the RRC message can be transmitted.
  • the RRC message can carry the non-access stratum (NAS, Non Access Stratum) letter.
  • NAS Non Access Stratum
  • the core network can send an identity request (IDENTITIY REQUEST).
  • the IMSI information of the UE is obtained in the process of the UE accessing the cell, and the core network randomly sends an identity identification request to the UE by using the eNB, and the eNB cannot guarantee that the UE can be informed in time during the process of accessing the cell by the UE.
  • the IMSI information of the UE, and in the existing network, the eNB only forwards the identity identification request and the identity response returned by the UE, and does not have the function of analyzing the identity identification response to obtain the IMSI information. Therefore, in this embodiment, the eNB needs to simulate the core network.
  • the identity request is sent and the identity response is received and parsed to obtain IMSI information, so that a specific UE with specific IMSI information can be accessed to a specific cell according to the IMSI information.
  • Step 102 Receive an identity recognition response returned by the UE, and extract and obtain IMSI information from the identity recognition response.
  • the UE After receiving the identity request sent by the eNB to simulate the core network, the UE considers that it is an identity identification request sent by the core network, and the UE returns an identity response that includes the IMSI information according to the provisions of the related network communication protocol. After receiving the identity response returned by the UE, the eNB extracts and obtains IMSI information from the identity recognition response.
  • Step 103 According to the user access policy, when the IMSI information is the target IMSI information, the UE corresponding to the target IMSI information is accessed by the target cell.
  • the method of this embodiment is to access a specific UE with specific IMSI information to a specific destination. Standard cell. There are three situations at this time:
  • the first case is that the local cell in the eNB that obtains the IMSI information is the target cell in the foregoing embodiment, and the user access policy of the target cell includes the target UE that has the target IMSI information, and is prohibited. Accessing another UE that does not have the target IMSI information or allowing other UEs that do not have the target IMSI information to access to the neighboring cell that is covered by the target cell; in this case, according to the user access policy, When the IMSI information is the target IMSI information, the UE corresponding to the IMSI information is directly accessed by the target cell; when the IMSI information is not the target IMSI information, the UE corresponding to the IMSI information is not allowed to access.
  • the target cell is configured to allow the UE corresponding to the IMSI information to access the target cell, and send a handover request message to the neighboring cell that is covered by the target cell after the access, where the handover request message is used.
  • the UE is allowed to access after receiving the handover request message by the neighboring cell.
  • the target cell accesses only the target UE with the target IMSI information, and other UEs prohibit access or forcibly switch to other cells after access.
  • the second case is that the local cell under the eNB that extracts the IMSI information in the foregoing embodiment is the same coverage neighboring cell of the target cell, and the user policy of the target cell is to prohibit direct access by the UE, allowing the The user of the target cell is in contact with the neighboring cell to be handed over; the user policy of the same neighboring cell is to allow all UEs to access, and the target UE with the target IMSI information is forcibly switched to the target cell; Allowing the UE corresponding to the IMSI information to access the local cell when the IMSI information is not the target IMSI information; allowing the UE corresponding to the target IMSI information to access when the IMSI information is the target IMSI information And sending, after the access, the handover request message to the target cell, where the handover request message is used to allow the UE corresponding to the target IMSI information to be accessed after the target cell receives the handover request message.
  • the target UE may access the same coverage neighboring cell of the target cell. Then switch directly to the target cell.
  • the third case is that the local cell in the eNB that extracts the IMSI information in the foregoing embodiment may also be another cell, and the local user access policy includes allowing access to all UEs, and the target UE having the target IMSI information is in the subsequent
  • the handover request message carries the obtained target IMSI information or the mapping information of the target IMSI information mapping; therefore, according to the user policy, when the IMSI information is not the target IMSI information, the corresponding IMSI information is allowed to be
  • the UE accesses the local cell; when the IMSI information is the target IMSI information, the UE corresponding to the IMSI information is allowed to access the local cell, and the cell handover is required or the target UE moves to the target cell coverage.
  • the target UE corresponding to the information is accessed.
  • the target UE with the target IMSI information accesses the other cell, the target UE with the target IMSI information can be accessed to the target cell when the target UE moves to the target cell coverage.
  • the target UE may switch to a plurality of other cells to move to the target cell coverage.
  • the handover request message carries the target IMSI information or the target IMSI information of the target UE.
  • the local cell is the target cell or not
  • the UE with the target IMSI information when the UE with the target IMSI information enters the target range of the target cell, it can directly access or switch to access the target cell, and the UE without the IMSI information cannot access the UE.
  • the target cell so that the method in this embodiment can only access the UE with the target IMSI information to the target cell according to the obtained IMSI information.
  • the problem that the specific UE cannot be accessed to a specific cell in the prior art (such as scenario 1 and scenario 2) is solved.
  • An embodiment of the present invention provides a method for a UE to differentiate access to a network. As shown in FIG. 2, the method includes:
  • Step 201 The simulated core network sends an identity identification request to the UE.
  • the UE When the UE searches for the local cell under the eNB and prepares to access the local cell, it needs to establish an RRC connection with the eNB first.
  • the UE sends an RRC connection request (Connection Request) to the eNB; after receiving the RRC Connection Request, the eNB sends an RRC connection setup (Connection Setup) to the UE; after receiving the RRC Connection Setup, the UE carries the RRC Connection Setup according to the RRC Connection Setup.
  • the parameters set the UE and send an RRC Connection Setup Complete to the eNB after the setup is complete.
  • the IDENTITIY REQUEST is a downlink (DL, Down Link) information transfer (Information Transfer) NAS signaling:
  • the NAS code stream of the NAS signaling may be in the form of a plain text or an integrity protection, and is not limited herein. Assuming that the NAS signaling-IDENTITIY REQUEST is sent in clear text, the NAS stream should be 07 55 01 (hexadecimal) according to the existing NAS protocol.
  • Step 202 Receive an identity recognition response fed back by the UE.
  • the UE After receiving the identity request sent by the eNB to simulate the core network, the UE considers that it is an identity identification request sent by the core network, and the UE returns an identity response (IMSENTITY RESPONSE) containing the IMSI information according to the provisions of the relevant network communication protocol. ), the IDENTITIY REQUEST is an uplink (UL, Up Link) information transmission (Information Transfer) NAS signaling. The eNodeB receives the identity response fed back by the UE.
  • Step 203 Determine a NAS code stream form according to the access layer NAS protocol and the NAS code stream in the identity recognition response.
  • the NAS code stream form includes a plaintext form or an integrity protection form.
  • the eNB After receiving the NAS signaling returned by the UE: IDENTITY RESPONSE, the eNB first determines the form of the received NAS code stream in the identity response. The eNB needs to know the value of the upper 4 bits of the first byte of the NAS code stream. If the value is 0000, the NAS code stream is in the plain text format. If the value is 0001, the NAS code stream is in the form of integrity protection. form. These are all well defined in the existing NAS protocol, and the eNB can determine the form of the NAS code stream according to the NAS protocol in combination with the NAS code stream.
  • Step 204 Determine, according to the NAS protocol and the NAS code stream form, that the identity recognition response is an identity recognition response that includes an IMSI code.
  • the eNB After the eNB establishes an RRC connection with the UE, the eNB can receive many types of NAS signaling. Therefore, after receiving the NAS signaling sent by the UE, the eNB needs to determine whether the NAS signaling is an identity response that includes the IMSI code.
  • the NAS signaling may be IDENTITY RESPONSE according to the meaning of each hexadecimal code in different forms of NAS signaling specified by the NAS protocol, and An identity response that contains an IMSI code.
  • the second byte of the NAS stream is taken as decimal 86 to determine that the NAS signaling is IDENTITY RESPONSE; and the lower 3 bits of the 4th byte of the NAS code stream A value of 001 determines that the NAS signaling is an identity response containing the IMSI code.
  • the 8th byte of the NAS code stream is taken as decimal 86 to determine that the NAS signaling is IDENTITY RESPONSE; and the lower 3 bits of the 10th byte of the NAS code stream For 001, the NAS signaling is determined to be an identity containing the IMSI code. Don't respond.
  • Step 205 Extract and obtain IMSI information from the identifier response including the IMSI code according to the NAS protocol and the NAS code stream form.
  • the eNB may extract the IMSI information from the NAS code stream of the NAS signaling according to the correspondence between the IMSI information specified by the NAS protocol and the NAS code stream.
  • the hexadecimal NAS code stream carried in the NAS signaling received in step 202 is: 07 56 08 49 06 10 56 34 12 40 49; the first byte of the NAS code stream is hexadecimal 07, converted into The binary is 00000111, and its high 4bit value is 0000.
  • the NAS signaling is determined to be in plain text according to the NAS protocol. According to the NAS protocol, for the NAS signaling in the plaintext form, the second byte of the NAS code stream is 56 in decimal hexadecimal 86, and the NAS signaling is determined to be IDENTITY RESPONSE.
  • the fourth byte of the NAS code stream is 49 in hexadecimal, converted to binary 1001001, and the lower 3 bit value is 001, then the NAS signaling is determined to be an identity response including the IMSI code.
  • the IMSI number is extracted according to the NAS protocol, for example, starting from the 4th byte of the NAS code stream according to the NAS protocol, that is, excluding the code stream in the parentheses (07) 56 08) 49 06 10 56 34 12 40 49, the 4th byte high 4bit is the first digit of the IMSI, which is 4; for the remaining bytes, the lower 4bit is extracted for each byte, and then the high 4bit is extracted;
  • the lower 4 bits of the 5th byte are the 2nd digit of the IMSI, that is, the 6th
  • the high 4bit is the 3rd digit of the IMSI, that is, 0; the last I
  • the hexadecimal NAS code stream carried in the received NAS signaling is: 17 05 a6 07 b1 d0 07 56 08 49 06 10 17 00 56 42 45; the first byte of the NAS code stream is hexadecimal 17 It is converted to binary number 00010111, and its high 4 bit value is 0001.
  • the NAS signaling is determined to be an integrity protection form according to the NAS protocol. Integrity protection according to NAS protocol For the NAS signaling, the 8th byte of the NAS code stream is 56 in decimal hexadecimal 86, and the NAS signaling is determined to be IDENTITY RESPONSE; and the NAS code stream is 10th byte hexadecimal.
  • a value of 49 is converted to a binary of 1001001 and a low 3 bit is taken to be 001.
  • the NAS signaling is determined to be an identity response containing the IMSI code.
  • the IMSI number is extracted according to the NAS protocol, for example, starting from the 10th byte of the NAS code stream according to the NAS protocol, that is, excluding the code stream in the parentheses (17 05 a6 07 b1 d0 07 56 08) 49 06 10 17 00 56 42 45, the 10th byte high 4bit is the first digit of the IMSI, which is 4; for the remaining bytes, the first byte is extracted first The lower 4 bits, the higher 4 bits are extracted; for example, the lower 4 bits of the 11th byte are the 2nd digit of the IMSI, that is, the 6th, the high 4bit is the 3rd digit of the IMSI, that is, 0; the last I
  • Step 206 According to the user access policy, when the IMSI information is the target IMSI information, the UE corresponding to the target IMSI information is accessed by the target cell.
  • the first case is that the local cell in the eNB that obtains the IMSI information is the target cell in the foregoing embodiment, and the user access policy of the target cell includes the target UE that has the target IMSI information, and is prohibited. Accessing another UE that does not have the target IMSI information or allowing other UEs that do not have the target IMSI information to access to the neighboring cell that is covered by the target cell; in this case, according to the user access policy, When the IMSI information is the target IMSI information, the UE corresponding to the IMSI information is directly accessed by the target cell; when the IMSI information is not the target IMSI information, the UE corresponding to the IMSI information is not allowed to access.
  • the target cell is configured to allow the UE corresponding to the IMSI information to access the target cell, and send a handover request message to the neighboring cell that is covered by the target cell after the access, where the handover request message is used.
  • the UE is allowed to access after receiving the handover request message by the neighboring cell.
  • cell 1 is a local cell; cell 2 is covered with cell 1.
  • the neighboring cell; the cell 1 is a target cell with exclusive resources, and the cell 2 is a common cell; the application scenario is a high-level conference scenario, and the UE0 of a special user, such as a full-time reporter, needs to access the cell 1 exclusive resource, and does not want to be any other UE. Influencing the use of cell 1.
  • the user access policy of the target cell may be the UE 0 accessing the cell 1 exclusive resource with the target IMSI information, that is, the full-time reporter with the IMSI number of 460013511111111, and prohibiting access to other UEs that do not have the target IMSI information.
  • the base station where the cell 1 is located and the UE 0 performs the steps 201-205 to obtain the IMSI number of the UE 0, and the IMSI number of the UE 0 is 460013511111111, and the base station where the cell 1 is located accesses the UE 0 corresponding to the IMSI number of 460013511111111. 1.
  • the IMSI number of the UE 1 is 460013511122211, and the base station where the cell 1 is located does not allow the UE corresponding to the IMSI number to be 46300131151122211. 1 accessing the cell 1; the UE1 needs to continue searching for a cell that can be accessed, such as the same coverage neighboring cell-cell 2 of the cell 1, and the cell 2 is a normal cell, allowing all UEs to access; thus the UE 1 can access Go to cell 2.
  • the user access policy of the local cell may also be that the UE 0 that has the target IMSI information, that is, the full-time reporter whose IMSI number is 460013511111111, accesses the cell 1 exclusive resource, and allows other UEs that do not have the target IMSI information to access the UE.
  • the handover is forced to the neighboring cell covered by the target cell.
  • the base station where the cell 1 is located and the UE 0 performs the steps 201-205 to obtain the IMSI number of the UE 0, and the IMSI number of the UE 0 is 460013511111111, and the base station where the cell 1 is located accesses the UE corresponding to the IMSI number of 4620101311111111 to the cell 1. .
  • the IMSI number of the UE1 is 460013511122211, and the base station where the cell 1 is located allows the UE1 with the IMSI number of 460013511122211 to access.
  • the second case is that the local cell in the eNB that obtains the IMSI information in the foregoing embodiment is the same coverage neighboring cell of the target cell, and the user policy of the target cell is to prohibit direct access by the UE.
  • the user access policy when the IMSI information is not the target IMSI information, allowing the UE corresponding to the IMSI information to access the local cell; when the IMSI information is the target IMSI information, The UE corresponding to the target IMSI information is allowed to access, and after the access, the handover request message is sent to the target cell, where the handover request message is used to allow the target IMSI information after the target cell receives the handover request message.
  • the user access when the IMSI information is not the target IMSI information
  • the cell 2 is a local cell; the cell 1 is a neighboring cell that is in the same coverage as the cell 2; the cell 1 is a target cell that is exclusive to the resource, and the cell 2 is a common cell;
  • the UE 0 of a special user such as a full-time reporter needs to access the cell 1 exclusive resource, and does not want to be affected by the cell 1 by any other UE.
  • the user access policy of the target cell that is, the cell 1 is forbidden to directly access the UE, and the UE that is switched from the coverage neighboring cell of the target cell is allowed to access; the same coverage neighboring cell of the target cell is
  • the user access policy of the cell 2 may be allowed to be accessed by all the UEs.
  • the UE 0 having the target IMSI information that is, the full-time reporter whose IMSI number is 460013511111111, accesses the cell 2 and then forcibly switches to the target cell, that is, the cell 1 exclusive resource.
  • the base station where the cell 2 is located and the UE 0 performs the steps 201-205 to obtain the IMSI number of the UE 0, and the IMSI number of the UE 0 is 460013511111111, and the base station where the cell 2 is located accesses the UE 0 corresponding to the IMSI number of 460013511111111.
  • the user access policy of the local cell, that is, the cell 2 is a full-time record with the target IMSI information, that is, the IMSI number is 460013511111111. After the UE 0 accesses the cell 2, it is forcibly switched to the target cell, that is, the cell 1 exclusive resource.
  • the base station sends a handover request message to the cell 1 according to the user access policy of the cell 2, so that the cell 1 directly allows the UE 0 to access the cell 1 after receiving the handover request message, so that the UE 0 can accept the cell 1 Exclusive resources.
  • the IMSI number of the UE 1 is 460013511122211, and the base station where the cell 1 is located allows all UEs to access the cell 2, that is, the cell 2
  • the base station at the base station accesses UE 1 to cell 2. Since the IMSI number of the UE1 is 460013511122211, which is not the target IMSI information, the UE 1 remains in the cell 2 to receive the service.
  • the third case is that the local cell under the eNB that extracts the IMSI information in the foregoing embodiment is another cell, and the local cell user access policy includes allowing all UEs to access, and the target UE having the target IMSI information is in the subsequent
  • the handover request message carries the obtained target IMSI information or the mapping information of the target IMSI information mapping; therefore, according to the user policy, when the IMSI information is not the target IMSI information, the corresponding IMSI information is allowed to be
  • the UE accesses the local cell; when the IMSI information is the target IMSI information, the UE corresponding to the IMSI information is allowed to access the local cell, and the cell handover is required or the target UE moves to the target cell coverage.
  • the target UE corresponding to the information is accessed.
  • the cell 3 is a local cell; the cell 1 is a cell that is covered with the cell 2; the cell 3 and the cell 2 are neighboring cells; wherein the cell 1 is a target cell with exclusive resources, and the cell 2 and the cell 3 is a common cell; the application scenario is a high-level conference scenario, and the UE 0 of a special user such as a full-time reporter needs to access the cell 1 exclusive resource, and does not want to be affected by the cell 1 by any other UE.
  • a special user such as a full-time reporter needs to access the cell 1 exclusive resource, and does not want to be affected by the cell 1 by any other UE.
  • the SIB2 of the cell 1 may be set to not allow the access state, and the user access policy of the cell 3 may be that the UE 0 having the target IMSI information, that is, the full-time reporter whose IMSI number is 460013511111111 is carried in the subsequent handover request message.
  • the base station where the cell 3 is located and the UE 0 perform the steps 201-205 to obtain the IMSI number of the UE 0, and the IMSI number of the UE 0 is 460013511111111, and the base station where the cell 3 is located corresponds to the IMSI number of 460013511111111.
  • the UE 0 accesses the cell 3, and the UE 0 is not in the coverage of the cell 1 at this time, so the UE 0 is not switched to the cell 1 after the access is completed.
  • the cell 3 sends a handover request message to the cell 1.
  • the handover request message carries the IMSI number of the UE 0; the cell 1 is the target cell, and the IMSI number is allowed.
  • the UE 0 of the 460013511111111 is accessed; after receiving the handover request message, the cell 1 allows the UE 0 with the IMSI number of 4,601,013,111,111,1 to access the cell 1, so that the UE 0 can accept the resource exclusive of the cell 1.
  • the UE 0 of the full-time reporter may need to switch a lot of other cells to move to the coverage of the target cell, that is, the coverage of the cell 1, in each handover process, the handover request message It must carry its IMSI information such as IMSI number 460013511111111; thus, when UE 0 enters the coverage of cell 1, cell 1 can allow UE 0 with the IMSI number of 460013511111111 to access cell 1 according to the IMSI information in the handover request. Therefore, UE0 can accept the resource exclusive of cell 1.
  • the base station where the cell 3 is located and the UE 1 perform the steps 201-205 to obtain the IMSI number of the UE1, and the IMSI number of the UE1 is 460013522222222, and the base station where the cell 3 is located corresponds to the IMSI number of 460013522222222.
  • the UE 1 normally accesses the cell 3 and shares the cell 3 resources with other common UEs.
  • the cell 3 When the coverage of the cell 1 moves out of the coverage of the cell 3 and the coverage of the cell 2 and the cell 1, the cell 3 sends a handover request message to the cell 1 or the cell 2, and the handover request message does not carry the UE 1 IMSI number;
  • the cell 1 is the target cell, and the UE0 with the IMSI number is 460013511111111 is allowed to access; after receiving the handover request message, the cell 1 does not allow the UE 1 to access the cell 1, and the cell 2 is the target cell, allowing all UEs to access; After receiving the handover request message, the cell 2 is allowed to access the cell 2, and the handover process of the UE 1 from the cell 3 to the cell 2 is the same as that in the prior art, and details are not described herein.
  • the handover request may be an S1 handover request (S1HANDOVER REQUIRED) or an X2 handover request (X2HANDOVER REQUEST);
  • Corresponding information carrying the target IMSI information or the target IMSI information mapping ; carrying the target IMSI information or target in the handover request message by using a protocol extension field, a new protocol cell carrying or multiplexing a current protocol function non-collision field
  • the corresponding information of the IMSI information mapping is sent to the opposite cell, that is, the handover cell or the target cell; after the target cell extracts the target IMSI information or decomposes the target IMSI information according to the mapping information mapped by the target IMSI information, It can be processed according to the user access policy of the peer cell.
  • the encryption algorithm and the key that are mutually agreed upon after the mutual negotiation and the peer cell are set, and the IMSI number is encrypted according to the encryption algorithm and the key in the current cell.
  • the opposite cell is decrypted to obtain an IMSI number.
  • the target UE is switched to the target cell in the second case.
  • the second case is that the target UE is switched from the same coverage neighboring cell of the target cell to the target cell.
  • the target IMSI may not carry the target IMSI information in the handover request message sent in the handover process.
  • the target UE is handed over from the other cell to the target cell, and the handover request message sent during the handover process needs to carry the target IMSI. information.
  • the embodiment of the present invention further provides a base station.
  • the base station includes: a sending unit 501, a receiving unit 502, an extracting unit 503, and an access processing unit 504.
  • the sending unit 501 is configured to: the analog core network sends an identity identification request to the UE;
  • the receiving unit 502 is configured to receive an identity response returned by the UE;
  • the extracting unit 503 is configured to extract and obtain the IMSI information from the identity recognition response received by the receiving unit 502.
  • the access processing unit 504 is configured to access the UE corresponding to the target IMSI information to the target cell when the IMSI information extracted by the extracting unit 503 is the target IMSI information according to the user access policy.
  • the base station further includes: a determining unit 505.
  • the determining unit 505 is configured to: after the access unit 502 receives the identity recognition response, according to an access layer NAS protocol and Determining the NAS code stream form in the NAS code stream in the identification response; and determining, according to the NAS protocol and the NAS code stream form, the identity recognition response as an identity recognition response including an IMSI code; wherein the NAS code stream form includes Plain form or integrity protection form.
  • the extracting unit 504 is configured to: after the determining unit 505 determines that the identity recognition response is an identity identification response that includes an IMSI code, according to the NAS protocol and the NAS code stream form, from the IMSI code The IMSI information is extracted in the identity response.
  • Extracting the local cell that obtains the IMSI information as the target cell the user access policy of the target cell includes allowing access to the target UE with the target IMSI information, prohibiting access to other UEs that do not have the target IMSI information, or allowing the target IMSI to be disabled. After the other UEs of the information are accessed, the UE is forcibly switched to the neighboring cell covered by the target cell;
  • the access processing unit 504 is configured to: when the IMSI information is the target IMSI information, allow the UE corresponding to the IMSI information to access the target cell; when the IMSI information is not the target IMSI information, The UE corresponding to the IMSI information is not allowed to access the target cell; or the UE corresponding to the IMSI information is allowed to access the target cell, and is covered by the target cell after accessing
  • the neighboring cell sends a handover request message, and the cut The request message is used by the neighboring cell to allow the UE corresponding to the IMSI information to access after receiving the handover request message.
  • Extracting the local cell that obtains the IMSI information is the same coverage neighboring cell of the target cell, where the user policy of the target cell is to prohibit direct access by the UE, and to allow UE access from the same coverage neighboring cell of the target cell to be accessed;
  • the user policy of the neighboring cell is configured to allow all UEs to access, and the target UE with the target IMSI information is forcibly switched to the target cell after being accessed;
  • the access processing unit 504 is specifically configured to be in the IMSI information.
  • the UE corresponding to the IMSI information is allowed to access the local cell; when the IMSI information is the target IMSI information, the UE corresponding to the target IMSI information is allowed to access the local cell, After the access, the handover request message is sent to the target cell, where the handover request message is used by the target cell to allow the UE corresponding to the target IMSI information to be accessed after receiving the handover request message.
  • the local cell that obtains the IMSI information is not the target cell, and the local cell user access policy includes allowing all UEs to access, and the target UE having the target IMSI information carries the obtained target IMSI information in the subsequent handover request message or
  • the target IMSI information is mapped to the local cell;
  • the access processing unit 504 is configured to allow the UE corresponding to the IMSI information to access the local cell when the IMSI information is not the target IMSI information;
  • the IMSI information is the target IMSI information
  • the UE corresponding to the IMSI information is allowed to access the local cell, and when the cell handover is required or when the target UE moves to the target cell coverage, the UE carries the target.
  • the handover request message of the corresponding information of the IMSI information or the target IMSI information is mapped to the handover cell or the target cell; the target IMSI information is used by the target cell to allow the target corresponding to the target IMSI information after receiving the handover request message UE access.
  • the access processing unit 504 is specifically configured to carry the target in the handover request message by using a protocol extension field, a new protocol cell carrying, or a multiplexing current protocol function non-collision field.
  • the mapping information of the IMSI information or the target IMSI information is sent to the handover cell or the target cell; the mapping information of the target IMSI information is used for the handover cell or the target cell to obtain the target IMSI information.
  • the sending unit 501 and the receiving unit 502 in the embodiment may be implemented by a transceiver in a base station; the extracting unit 503, the access processing unit 504, and the determining unit 505 may be implemented by a central processing unit (CPU in the base station). ), microprocessor (MPU), digital signal processor (DSP) or field programmable gate array (FPGA) and other devices.
  • CPU central processing unit
  • MPU microprocessor
  • DSP digital signal processor
  • FPGA field programmable gate array
  • embodiments of the present invention can be provided as a method, system, or computer program product. Accordingly, the present invention can take the form of a hardware embodiment, a software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) including computer usable program code.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded into a computer or other programmable data processing device Having a series of operational steps performed on a computer or other programmable device to produce computer-implemented processing such that instructions executed on a computer or other programmable device are provided for implementing one or more processes in a flowchart and/or Or block diagram the steps of a function specified in a box or multiple boxes.
  • an embodiment of the present invention further provides a computer storage medium, the computer storage medium comprising a set of instructions, when the instruction is executed, causing at least one processor to perform the method of the UE differentiated access network.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Databases & Information Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种用户设备差异化接入网络的方法,包括:模拟核心网向用户设备发送身份识别请求;接收所述用户设备返回的身份识别响应,并从所述身份识别响应中提取获得IMSI信息;根据用户接入策略,在所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的用户设备接入目标小区。本发明同时还公开了一种基站及计算机存储介质。

Description

用户设备差异化接入网络的方法、基站及计算机存储介质 技术领域
本发明涉及通信领域,尤其涉及一种用户设备(UE,User Equipment)差异化接入网络的方法、基站及计算机存储介质。
背景技术
在UE接入小区过程中,通常是根据UE的接入等级(AC,Access Class)来接入网络的;AC在UE的SIM卡中写入,来表明UE接入网络的优先级。可以有很多UE处于一个相同的AC。通常AC为0~9的是普通优先级,AC为11~15的是高优先级。协议规定,高优先级的UE有优先接入权,只有当高优先级的UE都允许接入小区时,低优先级用户才能接入。当不同AC的UE接入小区时,小区可以通过对系统信息块1(SIB1,System Information Block Type1)和SIB2相关字段的设置,优先让高优先级用户接入,并保证高优先级用户的资源分配。
但是在一些特定场景,目前的设置还不能让一些特定的UE接入特定的小区中,如场景1:特定用途的小区,只允许具有某些特定的国际移动用户识别码(IMSI,International Mobile Subscriber Identification Number)的UE才能接入,其他UE不能以任何方式接入;场景2:当国家召开重要会议时,有很多高优先级用户在同一个小区接入,小区负荷重,可能对业务性能有一定影响,而有特殊用户(比如专职记者)的UE需要独享资源,不希望被任何其他UE影响小区使用。
在上述场景下,演进型基站(eNB,Evolved Node B)无法知道UE的IMSI,无法对具有特定IMSI的特定UE做到针对性处理。即使该特定UE的SIM卡的AC为最高等级15,也不能禁止AC为15的其他UE的接入。 即无论怎样配置,即便将特定UE的AC换为高优先级,也无法达到只接入特定UE,而禁止其他高优先级UE正常接入的效果。
发明内容
有鉴于此,本发明实施例期望提供一种UE差异化接入网络的方法、基站及计算机存储介质。
为达到上述目的,本发明实施例的技术方案是这样实现的:
一种UE差异化接入网络的方法,包括:
模拟核心网向UE发送身份识别请求;
接收所述UE返回的身份识别响应,并从所述身份识别响应中提取获得IMSI信息;
根据用户接入策略,在所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的UE接入目标小区。
上述方案中,所述接收所述UE返回的身份识别响应,并从所述身份识别响应中提取获得IMSI信息,包括:
接收所述身份识别响应,根据接入层NAS协议以及所述身份识别响应中的NAS码流确定NAS码流形式;
根据NAS协议以及所述NAS码流形式确定所述身份识别响应为包含IMSI码的身份识别响应;
根据所述NAS协议以及所述NAS码流形式从所述包含IMSI码的身份识别响应中提取获得IMSI信息。
上述方案中,所述NAS码流形式为明文形式、或为完整性保护形式。
上述方案中,提取获得IMSI信息的本地小区为目标小区,所述目标小区的用户接入策略包括允许接入具有目标IMSI信息的目标UE,禁止接入不具有目标IMSI信息的其他UE或者允许不具有目标IMSI信息的其他UE接入后强制切换到目标小区同覆盖的邻近小区;所述根据用户接入策略将 目标IMSI信息对应的UE接入相应的目标小区,包括:
在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述目标小区;
或者,
在所述IMSI信息不是目标IMSI信息时,不允许所述IMSI信息对应的所述UE接入所述目标小区;或者,允许所述IMSI信息对应的所述UE接入所述目标小区,并在接入后向所述目标小区同覆盖的邻近小区发送切换请求消息,所述切换请求消息用于邻近小区接收到所述切换请求消息后允许所述IMSI信息对应的所述UE接入。
上述方案中,提取获得IMSI信息的本地小区为所述目标小区的同覆盖邻接小区,所述目标小区的用户策略为禁止UE直接接入,允许从所述目标小区的同覆盖邻接小区切换来的UE接入;所述同覆盖邻接小区的用户策略为允许所有UE接入,具有目标IMSI信息的目标UE接入后强制切换到所述目标小区;所述根据用户接入策略将目标IMSI信息对应的UE接入相应的目标小区,包括:
在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;
或者,
在所述IMSI信息是目标IMSI信息时,允许所述目标IMSI信息对应的UE接入,并在接入后向所述目标小区发送切换请求消息,所述切换请求消息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述UE接入。
上述方案中,所述提取获得IMSI信息的本地小区不是目标小区,所述本地小区用户接入策略包括允许所有UE接入,具有目标IMSI信息的目标UE在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI 信息映射后的对应信息;则根据用户接入策略将所述IMSI信息对应的所述UE接入小区,包括:
在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;
或者,
在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入本地小区,在需要小区切换或者在所述目标UE移动到所述目标小区覆盖范围时,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区;所述目标IMSI信息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述目标UE接入。
上述方案中,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区,包括:
在所述切换请求消息中通过协议扩展字段、新增协议信元携带或者复用当前协议功能不冲突字段携带所述目标IMSI信息或者目标IMSI信息映射后的对应信息发送给所述切换小区或目标小区;目标IMSI信息映射后的对应信息用于所述切换小区或目标小区反解获得所述目标IMSI信息。
一种基站,所述基站包括:
发送单元,配置为模拟核心网向UE发送身份识别请求;
接收单元,配置为接收所述UE返回的身份识别响应;
提取单元,配置为从所述接收单元接收的身份识别响应中提取获得IMSI信息;
接入处理单元,配置为根据用户接入策略,在所述提取单元提取到的所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的UE接入目标小区。
上述方案中,所述基站还包括:确定单元;其中,
所述确定单元,配置为在所述接入单元接收到所述身份识别响应后,根据接入层NAS协议以及所述身份识别响应中的NAS码流确定NAS码流形式;并根据NAS协议以及所述NAS码流形式确定所述身份识别响应为包含IMSI码的身份识别响应;
相应地,所述提取单元,配置为在所述确定单元确定所述身份识别响应为包含IMSI码的身份识别响应后,根据所述NAS协议以及所述NAS码流形式从所述包含IMSI码的身份识别响应中提取获得IMSI信息。
上述方案中,所述NAS码流形式为明文形式、或为完整性保护形式。
上述方案中,提取获得IMSI信息的本地小区为目标小区,所述目标小区的用户接入策略包括允许接入具有目标IMSI信息的目标UE,禁止接入不具有目标IMSI信息的其他UE或者允许不具有目标IMSI信息的其他UE接入后强制切换到目标小区同覆盖的邻近小区;
相应地,所述接入处理单元,配置为在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述目标小区;或者,配置为在所述IMSI信息不是目标IMSI信息时,不允许所述IMSI信息对应的所述UE接入所述目标小区;或者,允许所述IMSI信息对应的所述UE接入所述目标小区,并在接入后向所述目标小区同覆盖的邻近小区发送切换请求消息,所述切换请求消息用于邻近小区接收到所述切换请求消息后允许所述IMSI信息对应的所述UE接入。
上述方案中,提取获得IMSI信息的本地小区为所述目标小区的同覆盖邻接小区,所述目标小区的用户策略为禁止UE直接接入,允许从所述目标小区的同覆盖邻接小区切换来的UE接入;所述本地小区的用户策略为允许所有UE接入,具有目标IMSI信息的目标UE接入后强制切换到所述目标小区;
相应地,所述接入处理单元,配置为在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;或者,配置为在所述IMSI信息是目标IMSI信息时,允许所述目标IMSI信息对应的UE接入所述本地小区,并在接入后向所述目标小区发送切换请求消息,所述切换请求消息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述UE接入。
上述方案中,所述提取获得IMSI信息的本地小区不是目标小区,所述本地小区用户接入策略包括允许所有UE接入,具有目标IMSI信息的目标UE在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI信息映射后的对应信息;
相应地,所述接入处理单元,配置为在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;或者,配置为在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入本地小区,在需要小区切换或者在所述目标UE移动到所述目标小区覆盖范围时,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区;所述目标IMSI信息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述目标UE接入。
上述方案中,所述接入处理单元,配置为在所述切换请求消息中通过协议扩展字段、新增协议信元携带或者复用当前协议功能不冲突字段携带所述目标IMSI信息或者目标IMSI信息映射后的对应信息发送给所述切换小区或目标小区;目标IMSI信息映射后的对应信息用于所述切换小区或目标小区反解获得所述目标IMSI信息。
一种计算机存储介质,所述计算机存储介质包括一组指令,当执行所述指令时,引起至少一个处理器执行如权利要求1至7任一项所述的UE 差异化接入网络的方法。
本发明实施例提供了一种UE差异化接入网络的方法、基站及计算机存储介质,模拟核心网向UE发送身份识别请求;接收所述UE返回的身份识别响应,并从所述身份识别响应中提取获得IMSI信息;根据用户接入策略,在所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的UE接入目标小区。本发明实施例可以获取到用户的IMSI信息,并应用该IMSI信息,将具有目标IMSI信息的特定用户接入到特定的目标小区。
附图说明
图1为本发明实施例1提供的一种UE差异化接入网络的方法流程示意图;
图2为本发明实施例2提供的一种UE差异化接入网络的方法流程示意图;
图3为本发明实施例2提供的一种两小区场景示意图;
图4为本发明实施例2提供的一种三小区场景示意图;
图5为本发明实施例3提供的一种基站的结构框图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述。
在本发明的各种实施例中:基站模拟核心网向UE发送身份识别请求;接收所述UE返回的身份识别响应,并从所述身份识别响应中提取获得IMSI信息;根据用户接入策略,在所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的UE接入目标小区。
实施例1
本发明实施例提供了一种UE差异化接入网络的方法,如图1所示,所 述方法包括:
步骤101、模拟核心网向UE发送身份识别请求。
UE在搜索到eNB下的本地小区,准备接入该本地小区时中,需要先与eNB建立无线资源控制(RRC,Radio Resource Control)连接。当eNB收到RRC连接设置完成(Connection Setup Complete)后,eNB与UE之间就建立了RRC连接,就可以传输RRC消息了,RRC消息中可以携带非接入层(NAS,Non Access Stratum)信令;这样,在eNB收到RRC连接设置完成(Connection Setup Complete)后就可以模拟核心网下发身份识别请求(IDENTITIY REQUEST)。
本实施例中需要在UE接入小区的过程中获得UE的IMSI信息,而核心网是随机通过eNB向所述UE发送身份识别请求的,eNB不能保证在UE接入小区的过程中能及时获知UE的IMSI信息,且在现有的网络中eNB只是转发该身份识别请求以及UE返回的身份识别响应,并不具有解析身份识别响应获得IMSI信息的功能,故本实施例中eNB需要模拟核心网下发身份识别请求并接收和解析身份识别响应获得IMSI信息,这样才能根据IMSI信息将具有特定IMSI信息的特定UE接入特定的小区。
步骤102、接收所述UE返回的身份识别响应,并从所述身份识别响应中提取获得IMSI信息。
UE接收到eNB模拟核心网发送的身份识别请求后,会认为是核心网发送过来的身份识别请求,所述UE就会按照相关网络通信协议的规定返回包含有IMSI信息的身份识别响应。所述eNB接收所述UE返回的身份识别响应后,从所述身份识别响应中提取获得IMSI信息。
步骤103、根据用户接入策略,在所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的UE接入目标小区。
本实施例方法是为了将具有特定IMSI信息的特定UE接入到特定的目 标小区。这时有三种情况:
第一种情况是本实施例中上述的提取获得IMSI信息的eNB下的本地小区为目标小区,此时,所述目标小区的用户接入策略包括允许接入具有目标IMSI信息的目标UE,禁止接入不具有目标IMSI信息的其他UE或者允许不具有目标IMSI信息的其他UE接入后强制切换到目标小区同覆盖的邻近小区;这种情况下,根据所述用户接入策略,在所述IMSI信息是目标IMSI信息时,直接将所述IMSI信息对应的所述UE接入所述目标小区;在所述IMSI信息不是目标IMSI信息时,不允许所述IMSI信息对应的所述UE接入所述目标小区;或者,允许所述IMSI信息对应的所述UE接入所述目标小区,并在接入后向所述目标小区同覆盖的邻近小区发送切换请求消息,所述切换请求消息用于邻近小区接收到所述切换请求消息后允许所述UE接入。
在第一种情况下,目标小区只接入具有目标IMSI信息的目标UE,其他UE禁止接入或者接入后强制切换到其他小区。
第二种情况是本实施例中上述的提取获得IMSI信息的eNB下的本地小区是所述目标小区的同覆盖邻接小区,所述目标小区的用户策略为禁止UE直接接入,允许从所述目标小区的同覆盖邻接小区切换来的UE接入;所述同覆盖邻接小区的用户策略为允许所有UE接入,具有目标IMSI信息的目标UE接入后强制切换到所述目标小区;这样,在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;在所述IMSI信息是目标IMSI信息时,允许所述目标IMSI信息对应的UE接入,并在接入后向所述目标小区发送切换请求消息,所述切换请求消息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述UE接入。
在第二种情况下,目标UE可以在接入所述目标小区的同覆盖邻接小区 后直接切换到所述目标小区。
第三种情况是本实施例中上述的提取获得IMSI信息的eNB下的本地小区也可以是其他小区,所述本地用户接入策略包括允许接入所有UE,具有目标IMSI信息的目标UE在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI信息映射后的对应信息;故根据所述用户策略,在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入本地小区;在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入本地小区,在需要小区切换或者在所述目标UE移动到所述目标小区覆盖范围时,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区;所述目标IMSI信息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述目标UE接入。
这样,具有目标IMSI信息的目标UE接入到其他小区后,可以在目标UE移动到所述目标小区覆盖范围时,将具有目标IMSI信息的目标UE接入到目标小区。当然在此过程中可能目标UE切换过很多个其他小区才能移动到所述目标小区覆盖范围,在每次的切换过程中,切换请求消息里都携带有该目标UE的目标IMSI信息或者目标IMSI信息映射后的对应信息,这样才能在移动到所述目标小区覆盖范围时,向目标小区发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息,目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的目标UE接入。
不管本地小区是不是目标小区,当具有目标IMSI信息的UE进入到目标小区的目标范围,都可以直接接入或切换接入到所述目标小区,而不具有IMSI信息的UE则不能接入到所述目标小区,这样本实施例方法就可以根据获得的IMSI信息,只将具有目标IMSI信息的UE接入到目标小区, 解决了现有技术(如场景1和场景2)中不能将特定UE接入到特定小区的问题。
实施例2
本发明实施例提供了一种UE差异化接入网络的方法,如图2所示,所述方法包括:
步骤201、模拟核心网向UE下发身份识别请求。
UE在搜索到eNB下的本地小区,准备接入该本地小区时中,需要先与eNB建立RRC连接。在建立RRC连接时,UE会向eNB发送RRC连接请求(Connection Request);eNB接收到RRC Connection Request后向UE发送RRC连接设置(Connection Setup);UE接收到RRC Connection Setup后根据RRC Connection Setup中携带的参数设置UE,并在设置完成后向eNB发送RRC Connection Setup Complete。
当eNB收到RRC Connection Setup Complete后,eNB与UE之间就可以发送RRC消息了,该RRC消息中可以携带NAS信令;这样,在eNB收到RRC Connection Setup Complete后就可以模拟核心网下发一个IDENTITIY REQUEST。所述IDENTITIY REQUEST是一个下行(DL,Down Link)信息传输(Information Transfer)的NAS信令:
这个NAS信令的NAS码流可以是明文形式的,也可以是完整性保护形式,在此并不做限制。假设NAS信令-IDENTITIY REQUEST是以明文形式下发的,则按照现有NAS协议其NAS码流应该为07 55 01(十六进制)。
步骤202、接收所述UE反馈的身份识别响应。
UE接收到eNB模拟核心网发送的身份识别请求后,会认为是核心网发送过来的身份识别请求,所述UE就会按照相关网络通信协议的规定返回包含有IMSI信息的身份识别响应(IDENTITY RESPONSE),所述IDENTITIY REQUEST是一个上行(UL,Up Link)信息传输(Information  Transfer)的NAS信令。eNodeB接收所述UE反馈的身份识别响应。
步骤203、根据接入层NAS协议以及所述身份识别响应中的NAS码流确定NAS码流形式。
所述NAS码流形式包括明文形式或完整性保护形式。
eNB在接收到上述UE返回的NAS信令:IDENTITY RESPONSE后,会首先判断接收到的所述身份识别响应中的NAS码流的形式。eNB需要获知其NAS码流的第1字节的高4bit取值,若取值是0000则该NAS码流的形式为明文形式;若取值为0001则该NAS码流的形式为完整性保护形式。这些都是现有NAS协议中规定好的,eNB可以根据NAS协议结合该NAS码流来确定该NAS码流的形式。
步骤204、根据NAS协议以及所述NAS码流形式确定所述身份识别响应为包含IMSI码的身份识别响应。
eNB在与UE建立好RRC连接后,可以收到很多类型的NAS信令,故eNB接收到UE发送的NAS信令后需要确定该NAS信令是否为包含IMSI码的身份识别响应。
eNB在步骤203中确定好该NAS信令的NAS码流形式后,可以根据NAS协议规定的不同形式的NAS信令中各个十六进制码的含义来确定该NAS信令是IDENTITY RESPONSE,且为包含IMSI码的身份识别响应。
对于NAS码流为明文形式的NAS信令来说,其NAS码流的第2字节取值为十进制86则确定该NAS信令为IDENTITY RESPONSE;且其NAS码流第4字节的低3bit取值为001则确定该NAS信令为包含IMSI码的身份识别响应。
对于完整性保护形式的NAS信令来说,其NAS码流的第8字节取值为十进制86则确定该NAS信令为IDENTITY RESPONSE;且其NAS码流第10字节的低3bit取值为001则确定该NAS信令为包含IMSI码的身份识 别响应。
步骤205、根据所述NAS协议以及所述NAS码流形式从所述包含IMSI码的身份识别响应中提取获得IMSI信息。
eNB确定好该NAS信令为包含IMSI码的身份识别响应后,就可以按照NAS协议规定的IMSI信息与该NAS码流之间的对应关系,从NAS信令的NAS码流提取出IMSI信息。
以下举例来说明步骤203-205的具体流程:
假设步骤202中接收到的NAS信令中携带的16进制NAS码流为:07 56 08 49 06 10 56 34 12 40 49;该NAS码流的第1字节16进制为07,转换成二进制为00000111,其高4bit取值为0000,根据NAS协议规定确定该NAS信令为明文形式。根据NAS协议规定对于明文形式的NAS信令来说,该NAS码流的第2字节16进制为56取值为十进制86,则确定该NAS信令为IDENTITY RESPONSE。且该NAS码流第4字节16进制为49,转换成二进制为1001001,低3bit取值为001,则确定该NAS信令为包含IMSI码的身份识别响应。确定该NAS信令为明文形式的包含IMSI码的身份识别响应时,根据NAS协议提取IMSI号,如:根据NAS协议从NAS码流的第4字节开始,即排除括号内的码流(07 56 08)49 06 10 56 34 12 40 49,第4字节高4bit为IMSI的第1个数字,即为4;对于剩余字节,对每个字节先提取低4bit,后提取高4bit;例如,第5字节的低4bit为IMSI的第2个数字,即为6,高4bit为IMSI的第3个数字,即为0;最后IMSI提取为:460016543210494。
假设接收到的NAS信令中携带的16进制NAS码流为:17 05 a6 07 b1 d0 07 56 08 49 06 10 17 00 56 42 45;该NAS码流的第1字节16进制为17,转换成二进制为00010111,其高4bit取值为0001,根据NAS协议规定确定该NAS信令为完整性保护形式。根据NAS协议规定对于完整性保护形 式的NAS信令来说,该NAS码流的第8字节16进制为56取值为十进制86,则确定该NAS信令为IDENTITY RESPONSE;且该NAS码流第10字节16进制为49,转换成二进制为1001001,低3bit取值为001,则确定该NAS信令为包含IMSI码的身份识别响应。确定该NAS信令为完整性保护形式的包含IMSI码的身份识别响应时,根据NAS协议提取IMSI号,如:根据NAS协议从NAS码流的第10字节开始,即排除括号内的码流(17 05 a6 07 b1 d0 07 56 08)49 06 10 17 00 56 42 45,第10字节高4bit为IMSI的第1个数字,即为4;对于剩余字节,对每个字节先提取低4bit,后提取高4bit;例如,第11字节的低4bit为IMSI的第2个数字,即为6,高4bit为IMSI的第3个数字,即为0;最后IMSI提取为:460017100652454。
步骤206、根据用户接入策略,在所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的UE接入目标小区。
这时有三种情况:
第一种情况是本实施例中上述的提取获得IMSI信息的eNB下的本地小区为目标小区,此时,所述目标小区的用户接入策略包括允许接入具有目标IMSI信息的目标UE,禁止接入不具有目标IMSI信息的其他UE或者允许不具有目标IMSI信息的其他UE接入后强制切换到目标小区同覆盖的邻近小区;这种情况下,根据所述用户接入策略,在所述IMSI信息是目标IMSI信息时,直接将所述IMSI信息对应的所述UE接入所述目标小区;在所述IMSI信息不是目标IMSI信息时,不允许所述IMSI信息对应的所述UE接入所述目标小区;或者,允许所述IMSI信息对应的所述UE接入所述目标小区,并在接入后向所述目标小区同覆盖的邻近小区发送切换请求消息,所述切换请求消息用于邻近小区接收到所述切换请求消息后允许所述UE接入。
示例地,如图3所示,小区1为本地小区;小区2为与小区1同覆盖 的邻近小区;其中小区1是资源独享的目标小区,小区2为普通小区;应用场景为高级会议场景,特殊用户比如专职记者的UE0需要接入小区1独享资源,不希望被任何其他UE影响小区1使用。
此时,目标小区即小区1的用户接入策略可以为具有目标IMSI信息即IMSI号为460013511111111的专职记者的UE 0接入小区1独享资源,禁止接入不具有目标IMSI信息的其他UE。
小区1所在基站与UE 0进行步骤201-205获得所述UE 0的IMSI号,所述UE 0的IMSI号为460013511111111,则小区1所在基站将IMSI号为460013511111111对应的所述UE 0接入小区1。
小区1所在基站与其他UE如UE 1进行步骤201-205获得所述UE 1的IMSI号,所述UE 1的IMSI号为460013511122211,则小区1所在基站不允许IMSI号为460013511122211对应的所述UE 1接入小区1;所述UE1就需要继续搜索可以接入的小区如小区1的同覆盖邻近小区-小区2,小区2为普通小区,允许所有UE接入;这样UE 1就可以进而接入到小区2。
此时,本地小区即小区1的用户接入策略还可以为允许具有目标IMSI信息即IMSI号为460013511111111的专职记者的UE 0接入小区1独享资源,允许不具有目标IMSI信息的其他UE接入后强制切换到目标小区同覆盖的邻近小区。
小区1所在基站与UE 0进行步骤201-205获得所述UE 0的IMSI号,所述UE 0的IMSI号为460013511111111,则小区1所在基站将IMSI号为460013511111111对应的所述UE接入小区1。
小区1所在基站与其他UE如UE 1进行步骤201-205获得所述UE 1的IMSI号,所述UE1的IMSI号为460013511122211,则小区1所在基站允许IMSI号为460013511122211对应的所述UE1接入小区1;并在接入后向所述小区1同覆盖的邻近小区即小区2发送切换请求消息,小区2为普 通小区,允许所有UE接入;这样小区2接收到该切换请求消息后允许所述UE1接入小区2。
第二种情况是本实施例中上述的提取获得IMSI信息的eNB下的本地小区为所述目标小区的同覆盖邻接小区,此时,所述目标小区的用户策略为禁止UE直接接入,允许从所述目标小区的同覆盖邻接小区切换来的UE接入;所述同覆盖邻接小区的用户策略为允许所有UE接入,具有目标IMSI信息的目标UE接入后强制切换到所述目标小区;则,根据所述用户接入策略,在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;在所述IMSI信息是目标IMSI信息时,允许所述目标IMSI信息对应的UE接入,并在接入后向所述目标小区发送切换请求消息,所述切换请求消息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述UE接入。
示例地,如图3所示,小区2为本地小区;小区1为与小区2同覆盖的邻近小区;其中小区1是资源独享的目标小区,小区2为普通小区;应用场景为高级会议场景,特殊用户比如专职记者的UE 0需要接入小区1独享资源,不希望被任何其他UE影响小区1使用。
此时,所述目标小区即小区1的用户接入策略为禁止UE直接接入,允许从所述目标小区的同覆盖邻接小区切换来的UE接入;所述目标小区的同覆盖邻接小区即小区2的用户接入策略可以为允许所有UE接入,具有目标IMSI信息即IMSI号为460013511111111的专职记者的UE 0接入小区2后强制切换到所述目标小区即小区1独享资源。
小区2所在基站与UE 0进行步骤201-205获得所述UE 0的IMSI号,所述UE 0的IMSI号为460013511111111,则小区2所在基站将IMSI号为460013511111111对应的所述UE 0接入小区2。由于本地小区即小区2的用户接入策略为具有目标IMSI信息即IMSI号为460013511111111的专职记 者的UE 0接入小区2后强制切换到所述目标小区即小区1独享资源。故,基站根据所述小区2的用户接入策略,向小区1发送切换请求消息,这样小区1接收到该切换请求消息后就直接允许UE 0接入小区1,这样UE 0就可以接受小区1的资源独享。
小区2所在基站与其他UE如UE 1进行步骤201-205获得所述UE 1的IMSI号,所述UE 1的IMSI号为460013511122211,则小区1所在基站允许所有UE接入小区2,即小区2所在基站将UE 1接入小区2。由于所述UE1的IMSI号为460013511122211,不是目标IMSI信息,故所述UE 1就保持在小区2接受服务。
第三种情况是本实施例中上述的提取获得IMSI信息的eNB下的本地小区是其他小区,则所述本地小区用户接入策略包括允许所有UE接入,具有目标IMSI信息的目标UE在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI信息映射后的对应信息;故根据所述用户策略,在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入本地小区;在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入本地小区,在需要小区切换或者在所述目标UE移动到所述目标小区覆盖范围时,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区;所述目标IMSI信息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述目标UE接入。
示例地,如图4所示,所述小区3为本地小区;小区1为与小区2同覆盖的小区;小区3和小区2为邻近的小区;其中小区1是资源独享的目标小区,小区2和小区3为普通小区;应用场景为高级会议场景,特殊用户比如专职记者的UE 0需要接入小区1独享资源,不希望被任何其他UE影响小区1使用。
此时,小区1的SIB2中可以设置成不允许接入状态,小区3的用户接入策略可以为具有目标IMSI信息即IMSI号为460013511111111的专职记者的UE 0在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI信息映射后的对应信息。
对于专职记者的UE 0,小区3所在基站与UE 0进行步骤201-205获得所述UE 0的IMSI号,所述UE 0的IMSI号为460013511111111,则小区3所在基站将IMSI号为460013511111111对应的所述UE 0接入小区3,此时所述UE 0不在小区1的覆盖范围,故UE 0接入完成后不会被切换到小区1。当所述UE 0移动到小区1的覆盖范围时,小区3会向所述小区1发送切换请求消息,该切换请求消息中携带有UE 0的IMSI号;小区1为目标小区,允许IMSI号为460013511111111的UE 0接入;这样小区1接收到该切换请求消息后允许所述IMSI号为460013511111111的UE 0接入小区1,这样UE 0就可以接受小区1的资源独享。
在这里需要说明的是,对于专职记者的UE 0可能需要切换过很多个其他小区才能移动到所述目标小区即小区1的覆盖范围,在每次的切换过程中,所述切换请求消息中都必须携带有其IMSI信息如IMSI号460013511111111;这样,在UE 0进入到小区1的覆盖范围时,小区1才能根据该切换请求中的IMSI信息允许所述IMSI号为460013511111111的UE 0接入小区1,这样UE0就可以接受小区1的资源独享。
对于其他用户的UE如UE 1,小区3所在基站与UE 1进行步骤201-205获得所述UE1的IMSI号,所述UE1的IMSI号为460013522222222,则小区3所在基站将IMSI号为460013522222222对应的所述UE 1正常接入到小区3,与其他普通UE一起共享小区3资源。当所述UE 1移动出小区3的覆盖范围进入到小区2和小区1的覆盖范围时,小区3会向所述小区1或小区2发送切换请求消息,该切换请求消息中不携带有UE 1的IMSI号; 小区1为目标小区,允许IMSI号为460013511111111的UE0接入;这样小区1接收到该切换请求消息后不允许所述UE 1接入小区1,小区2为目标小区,允许所有UE接入;这样小区2接收到该切换请求消息后就会允许所述UE 1接入小区2,UE 1从小区3切换到小区2的切换过程与现有技术中相同,不再赘述。
第三种情况中,目标IMSI信息对应的UE在从本侧小区向对端小区切换时,发送的切换请求可以是S1切换请求(S1HANDOVER REQUIRED)或者X2切换请求(X2HANDOVER REQUEST);该切换请求中携带有目标IMSI信息或者目标IMSI信息映射后的对应信息;在所述切换请求消息中通过协议扩展字段、新增协议信元携带或者复用当前协议功能不冲突字段携带所述目标IMSI信息或者目标IMSI信息映射后的对应信息发送给对端小区即所述切换小区或目标小区;对端小区提取出目标IMSI信息或者根据所述目标IMSI信息映射后的对应信息分解出所述目标IMSI信息后,就可以根据对端小区的用户接入策略进行处理。
当所述IMSI信息为IMSI号时,为了安全,可以在本侧小区与对端小区设置相互协商后认可的加密算法和密钥,在本侧小区对IMSI号根据加密算法和密钥进行加密,在对端小区进行解密获得IMSI号。
第二种情况与第三种情况目标UE都是切换接入到目标小区的,不同的是,第二种情况下所述目标UE是从所述目标小区的同覆盖邻近小区切换到目标小区的,在切换过程中发送的切换请求消息内可以不携带目标IMSI信息;第三种情况下所述目标UE是从其他小区切换到目标小区的,在切换过程中发送的切换请求消息需要携带目标IMSI信息。
实施例3
本发明实施例还提供了一种基站,如图5所示,所述基站包括:发送单元501、接收单元502、提取单元503、接入处理单元504;其中,
发送单元501,配置为模拟核心网向UE发送身份识别请求;
接收单元502,配置为接收所述UE返回的身份识别响应;
提取单元503,配置为从所述接收单元502接收的身份识别响应中提取获得IMSI信息;
接入处理单元504,配置为根据用户接入策略,在所述提取单元503提取到的所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的UE接入目标小区。
如图5所示,所述基站还包括:确定单元505;其中,所述确定单元505,配置为在所述接入单元502接收到所述身份识别响应后,根据接入层NAS协议以及所述身份识别响应中的NAS码流确定NAS码流形式;并根据NAS协议以及所述NAS码流形式确定所述身份识别响应为包含IMSI码的身份识别响应;其中,所述NAS码流形式包括明文形式或完整性保护形式。
所述提取单元504,具体配置为在所述确定单元505确定所述身份识别响应为包含IMSI码的身份识别响应后,根据所述NAS协议以及所述NAS码流形式从所述包含IMSI码的身份识别响应中提取获得IMSI信息。
提取获得IMSI信息的本地小区为目标小区,则所述目标小区的用户接入策略包括允许接入具有目标IMSI信息的目标UE,禁止接入不具有目标IMSI信息的其他UE或者允许不具有目标IMSI信息的其他UE接入后强制切换到目标小区同覆盖的邻近小区;
所述接入处理单元504,具体配置为在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述目标小区;在所述IMSI信息不是目标IMSI信息时,不允许所述IMSI信息对应的所述UE接入所述目标小区;或者,允许所述IMSI信息对应的所述UE接入所述目标小区,并在接入后向所述目标小区同覆盖的邻近小区发送切换请求消息,所述切 换请求消息用于邻近小区接收到所述切换请求消息后允许所述IMSI信息对应的所述UE接入。
提取获得IMSI信息的本地小区为所述目标小区的同覆盖邻接小区,所述目标小区的用户策略为禁止UE直接接入,允许从所述目标小区的同覆盖邻接小区切换来的UE接入;所述同覆盖邻接小区的用户策略为允许所有UE接入,具有目标IMSI信息的目标UE接入后强制切换到所述目标小区;所述接入处理单元504,具体配置为在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;在所述IMSI信息是目标IMSI信息时,允许所述目标IMSI信息对应的UE接入所述本地小区,并在接入后向所述目标小区发送切换请求消息,所述切换请求消息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述UE接入。
所述提取获得IMSI信息的本地小区不是目标小区,则所述本地小区用户接入策略包括允许所有UE接入,具有目标IMSI信息的目标UE在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI信息映射后的对应信息;所述接入处理单元504,具体配置为在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入所述本地小区;在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述UE接入本地小区,在需要小区切换或者在所述目标UE移动到所述目标小区覆盖范围时,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区;所述目标IMSI信息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述目标UE接入。
所述接入处理单元504,具体配置为在所述切换请求消息中通过协议扩展字段、新增协议信元携带或者复用当前协议功能不冲突字段携带所述目 标IMSI信息或者目标IMSI信息映射后的对应信息发送给所述切换小区或目标小区;目标IMSI信息映射后的对应信息用于所述切换小区或目标小区反解获得所述目标IMSI信息。
在实际应用中,本实施例中所述的发送单元501、接收单元502可由基站中的收发机实现;提取单元503、接入处理单元504以及确定单元505可以由基站中的中央处理器(CPU)、微处理器(MPU)、数字信号处理器(DSP)或现场可编程门阵列(FPGA)等器件实现。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用硬件实施例、软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备 上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
基于此,本发明实施例还提供了一种计算机存储介质,所述计算机存储介质包括一组指令,当执行所述指令时,引起至少一个处理器执行上述的UE差异化接入网络的方法。
以上所述,仅为本发明的较佳实施例而已,并非用于限定本发明的保护范围。

Claims (15)

  1. 一种用户设备差异化接入网络的方法,所述方法包括:
    模拟核心网向用户设备发送身份识别请求;
    接收所述用户设备返回的身份识别响应,并从所述身份识别响应中提取获得国际移动用户识别码IMSI信息;
    根据用户接入策略,在所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的用户设备接入目标小区。
  2. 根据权利要求1所述的方法,其中,所述接收所述用户设备返回的身份识别响应,并从所述身份识别响应中提取获得IMSI信息,包括:
    接收所述身份识别响应,根据接入层NAS协议以及所述身份识别响应中的NAS码流确定NAS码流形式;
    根据NAS协议以及所述NAS码流形式确定所述身份识别响应为包含IMSI码的身份识别响应;
    根据所述NAS协议以及所述NAS码流形式从所述包含IMSI码的身份识别响应中提取获得IMSI信息。
  3. 根据权利要求2所述的方法,其中,所述NAS码流形式为明文形式、或为完整性保护形式。
  4. 根据权利要求1所述的方法,其中,提取获得IMSI信息的本地小区为目标小区,所述目标小区的用户接入策略包括允许接入具有目标IMSI信息的目标用户设备,禁止接入不具有目标IMSI信息的其他用户设备或者允许不具有目标IMSI信息的其他用户设备接入后强制切换到目标小区同覆盖的邻近小区;所述根据用户接入策略将目标IMSI信息对应的用户设备接入相应的目标小区,包括:
    在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述用户设备接入所述目标小区;
    或者,
    在所述IMSI信息不是目标IMSI信息时,不允许所述IMSI信息对应的所述用户设备接入所述目标小区;或者,允许所述IMSI信息对应的所述用户设备接入所述目标小区,并在接入后向所述目标小区同覆盖的邻近小区发送切换请求消息,所述切换请求消息用于邻近小区接收到所述切换请求消息后允许所述IMSI信息对应的所述用户设备接入。
  5. 根据权利要求1所述的方法,其中,提取获得IMSI信息的本地小区为所述目标小区的同覆盖邻接小区,所述目标小区的用户策略为禁止用户设备直接接入,允许从所述目标小区的同覆盖邻接小区切换来的用户设备接入;所述同覆盖邻接小区的用户策略为允许所有用户设备接入,具有目标IMSI信息的目标用户设备接入后强制切换到所述目标小区;所述根据用户接入策略将目标IMSI信息对应的用户设备接入相应的目标小区,包括:
    在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述用户设备接入所述本地小区;
    或者,
    在所述IMSI信息是目标IMSI信息时,允许所述目标IMSI信息对应的用户设备接入,并在接入后向所述目标小区发送切换请求消息,所述切换请求消息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述用户设备接入。
  6. 根据权利要求1所述的方法,其中,所述提取获得IMSI信息的本地小区不是目标小区,所述本地小区用户接入策略包括允许所有用户设备接入,具有目标IMSI信息的目标用户设备在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI信息映射后的对应信息;所述根据用户接入策略将所述IMSI信息对应的所述用户设备接入小区,包括:
    在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所 述用户设备接入所述本地小区;
    或者,
    在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述用户设备接入本地小区,在需要小区切换或者在所述目标用户设备移动到所述目标小区覆盖范围时,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区;所述目标IMSI信息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述目标用户设备接入。
  7. 根据权利要求6所述的方法,其中,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区,包括:
    在所述切换请求消息中通过协议扩展字段、新增协议信元携带或者复用当前协议功能不冲突字段携带所述目标IMSI信息或者目标IMSI信息映射后的对应信息发送给所述切换小区或目标小区;目标IMSI信息映射后的对应信息用于所述切换小区或目标小区反解获得所述目标IMSI信息。
  8. 一种基站,所述基站包括:
    发送单元,配置为模拟核心网向用户设备发送身份识别请求;
    接收单元,配置为接收所述用户设备返回的身份识别响应;
    提取单元,配置为从所述接收单元接收的身份识别响应中提取获得国际移动用户识别码IMSI信息;
    接入处理单元,配置为根据用户接入策略,在所述提取单元提取到的所述IMSI信息为目标IMSI信息时,将所述目标IMSI信息对应的用户设备接入目标小区。
  9. 根据权利要求8所述的基站,其中,所述基站还包括:确定单元;其中,
    所述确定单元,配置为在所述接入单元接收到所述身份识别响应后,根据接入层NAS协议以及所述身份识别响应中的NAS码流确定NAS码流形式;并根据NAS协议以及所述NAS码流形式确定所述身份识别响应为包含IMSI码的身份识别响应;
    相应地,所述提取单元,配置为在所述确定单元确定所述身份识别响应为包含IMSI码的身份识别响应后,根据所述NAS协议以及所述NAS码流形式从所述包含IMSI码的身份识别响应中提取获得IMSI信息。
  10. 根据权利要求9所述的基站,其中,所述NAS码流形式为明文形式、或为完整性保护形式。
  11. 根据权利要求8所述的基站,其中,提取获得IMSI信息的本地小区为目标小区,所述目标小区的用户接入策略包括允许接入具有目标IMSI信息的目标用户设备,禁止接入不具有目标IMSI信息的其他用户设备或者允许不具有目标IMSI信息的其他用户设备接入后强制切换到目标小区同覆盖的邻近小区;
    相应地,所述接入处理单元,配置为在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述用户设备接入所述目标小区;或者,配置为在所述IMSI信息不是目标IMSI信息时,不允许所述IMSI信息对应的所述用户设备接入所述目标小区;或者,允许所述IMSI信息对应的所述用户设备接入所述目标小区,并在接入后向所述目标小区同覆盖的邻近小区发送切换请求消息,所述切换请求消息用于邻近小区接收到所述切换请求消息后允许所述IMSI信息对应的所述用户设备接入。
  12. 根据权利要求8所述的基站,其中,提取获得IMSI信息的本地小区为所述目标小区的同覆盖邻接小区,所述目标小区的用户策略为禁止用户设备直接接入,允许从所述目标小区的同覆盖邻接小区切换来的用户设备接入;所述本地小区的用户策略为允许所有用户设备接入,具有目标IMSI 信息的目标用户设备接入后强制切换到所述目标小区;
    相应地,所述接入处理单元,配置为在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述用户设备接入所述本地小区;或者,配置为在所述IMSI信息是目标IMSI信息时,允许所述目标IMSI信息对应的用户设备接入所述本地小区,并在接入后向所述目标小区发送切换请求消息,所述切换请求消息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述用户设备接入。
  13. 权利要求8所述的基站,其中,所述提取获得IMSI信息的本地小区不是目标小区,所述本地小区用户接入策略包括允许所有用户设备接入,具有目标IMSI信息的目标用户设备在后续的切换请求消息中携带获得的目标IMSI信息或者所述目标IMSI信息映射后的对应信息;
    相应地,所述接入处理单元,配置为在所述IMSI信息不是目标IMSI信息时,允许所述IMSI信息对应的所述用户设备接入所述本地小区;或者,配置为在所述IMSI信息是目标IMSI信息时,允许所述IMSI信息对应的所述用户设备接入本地小区,在需要小区切换或者在所述目标用户设备移动到所述目标小区覆盖范围时,发送携带有目标IMSI信息或者目标IMSI信息映射后的对应信息的切换请求消息给切换小区或目标小区;所述目标IMSI信息用于目标小区接收到所述切换请求消息后允许所述目标IMSI信息对应的所述目标用户设备接入。
  14. 根据权利要求13所述的基站,其中,所述接入处理单元,配置为在所述切换请求消息中通过协议扩展字段、新增协议信元携带或者复用当前协议功能不冲突字段携带所述目标IMSI信息或者目标IMSI信息映射后的对应信息发送给所述切换小区或目标小区;目标IMSI信息映射后的对应信息用于所述切换小区或目标小区反解获得所述目标IMSI信息。
  15. 一种计算机存储介质,所述计算机存储介质包括一组指令,当执 行所述指令时,引起至少一个处理器执行如权利要求1至7任一项所述的用户设备差异化接入网络的方法。
PCT/CN2016/074596 2015-09-02 2016-02-25 用户设备差异化接入网络的方法、基站及计算机存储介质 WO2017036107A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510556292.1 2015-09-02
CN201510556292.1A CN106488442A (zh) 2015-09-02 2015-09-02 一种用户设备差异化接入网络的方法及基站

Publications (1)

Publication Number Publication Date
WO2017036107A1 true WO2017036107A1 (zh) 2017-03-09

Family

ID=58186469

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/074596 WO2017036107A1 (zh) 2015-09-02 2016-02-25 用户设备差异化接入网络的方法、基站及计算机存储介质

Country Status (2)

Country Link
CN (1) CN106488442A (zh)
WO (1) WO2017036107A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023073400A1 (en) * 2021-10-26 2023-05-04 Pismo Labs Technology Limited Method and apparatus for improving data transmission
US11991525B2 (en) 2021-12-02 2024-05-21 T-Mobile Usa, Inc. Wireless device access and subsidy control

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113950013B (zh) * 2020-07-16 2023-03-28 中国移动通信有限公司研究院 一种消息发送、接收方法、设备及介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2013058687A1 (en) * 2011-10-19 2013-04-25 Telefonaktiebolaget L M Ericsson (Publ) Methods and devices for deriving a permanent ue identifier
CN103229537A (zh) * 2012-11-28 2013-07-31 华为技术有限公司 无线通信建立方法和设备
CN103888980A (zh) * 2014-03-21 2014-06-25 京信通信系统(广州)有限公司 一种访问控制列表的管理方法和小型基站

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2013058687A1 (en) * 2011-10-19 2013-04-25 Telefonaktiebolaget L M Ericsson (Publ) Methods and devices for deriving a permanent ue identifier
CN103229537A (zh) * 2012-11-28 2013-07-31 华为技术有限公司 无线通信建立方法和设备
CN103888980A (zh) * 2014-03-21 2014-06-25 京信通信系统(广州)有限公司 一种访问控制列表的管理方法和小型基站

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023073400A1 (en) * 2021-10-26 2023-05-04 Pismo Labs Technology Limited Method and apparatus for improving data transmission
GB2616489A (en) * 2021-10-26 2023-09-13 Pismo Labs Technology Ltd Method and apparatus for improving data transmission
US11991525B2 (en) 2021-12-02 2024-05-21 T-Mobile Usa, Inc. Wireless device access and subsidy control

Also Published As

Publication number Publication date
CN106488442A (zh) 2017-03-08

Similar Documents

Publication Publication Date Title
US9049594B2 (en) Method and device for key generation
US11265704B2 (en) Security key generation for communications between base station and terminal based on beam selection
CN104219722B (zh) 双连接无线承载的迁移处理、迁移方法及装置
CN102090093B (zh) 空口链路安全机制建立的方法、设备
CN102869007B (zh) 安全算法协商的方法、装置及网络系统
US20210329456A1 (en) Signalling storm mitigation in a secured radio access network
JP5422037B2 (ja) セルラー無線システムにおける無線基地局鍵を生成する方法と装置
CN102404721B (zh) Un接口的安全保护方法、装置和基站
EP3534633B1 (en) Communication system, base station and control method
WO2013118096A1 (en) Method, apparatus and computer program for facilitating secure d2d discovery information
CN101917272A (zh) 一种邻居用户终端间保密通信方法及系统
EP2997767A1 (en) Mobility in mobile communications network
CN106899562A (zh) 物联网的安全算法协商方法、网元及物联网终端
CN108293259A (zh) 一种nas消息处理、小区列表更新方法及设备
CN108702303B (zh) 一种为无线承载进行安全配置方法和设备
WO2017036107A1 (zh) 用户设备差异化接入网络的方法、基站及计算机存储介质
EP3171635A1 (en) Path switching method, mobile anchor point and base station
EP2648437A1 (en) Method, apparatus and system for key generation
WO2022025566A1 (en) Methods and systems for deriving cu-up security keys for disaggregated gnb architecture
CN108631962B (zh) 一种重复数据的传输方法及通信设备
US20180160258A1 (en) Deterrence of User Equipment Device Location Tracking
JP6954385B2 (ja) 無線装置、基地局、端末装置、無線通信システムおよび通信方法
CN110830421B (zh) 数据传输方法和设备
EP2550818A1 (en) Method of protecting an identity of a mobile station in a communications network
CN107005410B (zh) 因特网协议安全性隧道建立方法,用户设备及基站

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16840538

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16840538

Country of ref document: EP

Kind code of ref document: A1