WO2017147993A1 - VoWi-Fi网络的接入方法及接入装置 - Google Patents

VoWi-Fi网络的接入方法及接入装置 Download PDF

Info

Publication number
WO2017147993A1
WO2017147993A1 PCT/CN2016/080602 CN2016080602W WO2017147993A1 WO 2017147993 A1 WO2017147993 A1 WO 2017147993A1 CN 2016080602 W CN2016080602 W CN 2016080602W WO 2017147993 A1 WO2017147993 A1 WO 2017147993A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
vowi
access point
access
unique identifier
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/080602
Other languages
English (en)
French (fr)
Inventor
张子敬
张晴
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Publication of WO2017147993A1 publication Critical patent/WO2017147993A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method for accessing a VoWi-Fi network and an access device for a VoWi-Fi network.
  • VoLTE Voice over LTE
  • IMS Internet Protocol Multimedia Subsystem
  • IP Multimedia Subsystem IP Multimedia Subsystem
  • VoLTE is the ultimate voice solution of LTE.
  • the voice can be implemented by using the PS (Packet Switch) domain.
  • PS Packet Switch
  • the access network is carried over the PS packet domain.
  • the session control and service data transmission are implemented based on IP.
  • Wi-Fi hotspot coverage and signal quality are ideal in indoor and large shopping malls. It is believed that VoWi-Fi is popular in indoor and large shopping malls and other similar scenes.
  • VoWi-Fi accesses the IMS network through the Wi-Fi network, and the voice can also be implemented on the IP.
  • the coverage of a Wi-Fi hotspot is relatively small.
  • the coverage of Wi-Fi is usually extended by the ESS (Extended Service Set) network.
  • the access network of VoWi-Fi can also use this extension mechanism. Expand the coverage of VoWi-Fi.
  • ESS networks are often subject to security threats from Wi-Fi rogue access points.
  • the connected Wi-Fi of the UE User Equipment
  • the attacker establishes a rogue hotspot with the same name as the hotspot connected to the UE before, and the attacker increases.
  • the transmit power of the hotspots of the rogues causes interference to normal hotspots, forcing the UE to be unable to connect to normal hotspots.
  • the attacker knows the key of the ESS network (such as a public hotspot), the UE may directly connect to the rogue hotspot forged by the attacker, and the attacker will steal the data in the UE.
  • VoWi-Fi networks this threat is even more critical. If you connect to a rogue VoWi-Fi hotspot, it may falsely cause the IMS network to obtain data from users, especially during initial registration, because it is through plaintext. To transfer user data, it will seriously threaten the security of user data.
  • the invention is based on at least one of the above technical problems, and proposes a new access scheme of the VoWi-Fi network, which can ensure that the user equipment accesses the legal VoWi-Fi network and improves the security of the VoWi-Fi network access. Sexually protects the security of user data.
  • a method for accessing a VoWi-Fi network including: a user equipment acquiring a unique identifier of an access point in a VoWi-Fi network to be accessed; and a mobile communication network Sending the unique identifier to the IMS network, for the IMS network to verify the validity of the access point, receiving the verification result fed back by the IMS network, and determining whether to access the VoWi according to the verification result.
  • Fi network Sending the unique identifier to the IMS network, for the IMS network to verify the validity of the access point, receiving the verification result fed back by the IMS network, and determining whether to access the VoWi according to the verification result.
  • the user equipment obtains the unique identifier of the access point in the VoWi-Fi network to be accessed, and sends the obtained unique identifier to the IMS network through the mobile communication network, so that the IMS network can wait for the user equipment.
  • the legality of the accessed VoWi-Fi network is verified, thereby ensuring that the user equipment accesses the legitimate VoWi-Fi network, improves the security of the VoWi-Fi network access, and effectively protects the security of the user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the step of determining whether to access the VoWi-Fi network according to the verification result includes: when the verification result indicates that the access point is a legal access point, accessing The VoWi-Fi network; and denying access to the VoWi-Fi network when the verification result indicates that the access point is a rogue access point.
  • the VoWi-Fi network when the verification result reported by the IMS network indicates that the access point is a legal access point, the VoWi-Fi network is accessed, and when the verification result indicates that the access point is an illegal access point, the access is denied.
  • the VoWI-Fi network ensures that user equipment is connected to a legitimate VoWi-Fi network, effectively protecting the security of user data.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • a method for accessing a VoWi-Fi network including: Receiving, by the IMS network, a unique identifier of any access point sent by the user equipment through the mobile communication network; verifying the legality of the access point according to the unique identifier of the any access point, to obtain a verification result; The verification result is sent to the user equipment, for the user equipment to determine whether to access the VoWi-Fi network based on the any access point according to the verification result.
  • the IMS network receives the unique identifier of any access point sent by the user equipment through the mobile communication network, and verifies the legality of the access point according to the received unique identifier, so that the IMS network can The legality of the VoWi-Fi network to be accessed is verified, thereby ensuring that the user equipment accesses the legal VoWi-Fi network, improves the security of the VoWi-Fi network access, and effectively protects the security of the user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the home subscriber server ie, the HSS, the Home Subscriber Server
  • the home subscriber server stores a unique identifier of at least one legal access point
  • the step of uniquely identifying the legality of verifying any of the access points includes:
  • the unique identifier of the legal access point may be stored in the HSS of the IMS network in advance, and then the IMS network can receive the unique identifier of any access point sent by the user equipment according to the HSS.
  • the unique identifier stored in the network determines whether the access point in the VoWi-Fi network to which the user equipment is to be accessed is a legitimate access point.
  • the unique identifier of the at least one legal access point stored in the HSS is corresponding to each ESS, that is, the unique identifier of the at least one legal access point is corresponding to the ESS to which the legal access point belongs. Storing, and determining whether the unique identifier of any access point is stored in the HSS, the ESS to which the access point belongs may be determined first, and then the unique identifier of the legal access point corresponding to the ESS is searched for A unique identifier for an access point.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • an access device for a VoWi-Fi network is also proposed, which is applicable to a user equipment, comprising: an obtaining unit, configured to obtain a unique identifier of an access point in a VoWi-Fi network to be accessed; and a sending unit, configured to send the unique identifier to the IMS network through the mobile communication network, where The IMS network verifies the validity of the access point; the receiving unit is configured to receive the verification result fed back by the IMS network; and the processing unit is configured to determine whether to access the VoWi-Fi network according to the verification result.
  • the user equipment obtains the unique identifier of the access point in the VoWi-Fi network to be accessed, and sends the obtained unique identifier to the IMS network through the mobile communication network, so that the IMS network can wait for the user equipment.
  • the legality of the accessed VoWi-Fi network is verified, thereby ensuring that the user equipment accesses the legitimate VoWi-Fi network, improves the security of the VoWi-Fi network access, and effectively protects the security of the user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the processing unit is specifically configured to: when the verification result indicates that the access point is a legal access point, access the VoWi-Fi network; and in the verification result When the access point is an illegal access point, the access to the VoWi-Fi network is denied.
  • the VoWi-Fi network when the verification result reported by the IMS network indicates that the access point is a legal access point, the VoWi-Fi network is accessed, and when the verification result indicates that the access point is an illegal access point, the access is denied.
  • the VoWI-Fi network ensures that user equipment is connected to a legitimate VoWi-Fi network, effectively protecting the security of user data.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • an access device of a VoWi-Fi network is further provided, which is applicable to an IMS network side device, and includes: a receiving unit, configured to receive any access point sent by the user equipment through the mobile communication network. a unique identifier; a verification unit, configured to verify validity of the access point according to the unique identifier of any one of the access points to obtain a verification result; and a sending unit, configured to send the verification result to the Describe the user equipment, for the user equipment to determine whether to access the VoWi-Fi network based on the any access point according to the verification result.
  • the IMS network receives the unique identifier of any access point sent by the user equipment through the mobile communication network, and verifies the legality of the access point according to the received unique identifier, so that the IMS network can The legality of the VoWi-Fi network to be accessed is verified, thereby ensuring that the user equipment accesses the legal VoWi-Fi network and improves the security of the VoWi-Fi network access. Sexually protects the security of user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the home subscription server in the IMS network stores a unique identifier of at least one legal access point
  • the verification unit includes: a determining unit, configured to determine whether a unique identifier of any one of the access points is stored in the home subscription user server in the IMS network; and a determining unit, configured to determine, by the determining unit, When the unique identifier of any one of the access points is stored in the home subscriber network, the access point is determined to be a legal access point, and is used by the determining unit to determine that the home subscriber server is not When storing the unique identifier of any of the access points, determining that any of the access points is an illegal access point.
  • the unique identifier of the legal access point may be stored in the HSS of the IMS network in advance, and then the IMS network can receive the unique identifier of any access point sent by the user equipment according to the HSS.
  • the unique identifier stored in the network determines whether the access point in the VoWi-Fi network to which the user equipment is to be accessed is a legitimate access point.
  • the unique identifier of the at least one legal access point stored in the HSS is corresponding to each ESS, that is, the unique identifier of the at least one legal access point is corresponding to the ESS to which the legal access point belongs. Storing, and determining whether the unique identifier of any access point is stored in the HSS, the ESS to which the access point belongs may be determined first, and then the unique identifier of the legal access point corresponding to the ESS is searched for A unique identifier for an access point.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • the user equipment can be ensured to access the legal VoWi-Fi network, the security of the VoWi-Fi network access is improved, and the security of the user data is effectively protected.
  • FIG. 1 is a schematic flow chart showing an access method of a VoWi-Fi network according to a first embodiment of the present invention
  • FIG. 2 is a schematic block diagram of an access device of a VoWi-Fi network according to a first embodiment of the present invention
  • FIG. 3 shows a schematic block diagram of a user equipment according to an embodiment of the present invention
  • FIG. 4 is a schematic flow chart showing an access method of a VoWi-Fi network according to a second embodiment of the present invention.
  • FIG. 5 is a schematic block diagram of an access device of a VoWi-Fi network according to a second embodiment of the present invention.
  • FIG. 6 shows a schematic block diagram of an IMS network side device according to an embodiment of the present invention
  • FIG. 7 is a schematic diagram showing an access procedure of a VoWi-Fi network according to an embodiment of the present invention.
  • FIG. 8 is a schematic flow chart showing an access method of a VoWi-Fi network according to a third embodiment of the present invention.
  • FIG. 1 shows a schematic flow chart of an access method of a VoWi-Fi network according to a first embodiment of the present invention.
  • an access method of a VoWi-Fi network includes:
  • Step 102 The user equipment acquires a unique identifier of the access point in the VoWi-Fi network to be accessed.
  • Step 104 Send the unique identifier to the IMS network by using a mobile communication network, so that the IMS network verifies the legitimacy of the access point.
  • Step 106 Receive a verification result fed back by the IMS network, and determine, according to the verification result, whether to access the VoWi-Fi network.
  • the user equipment obtains the unique identifier of the access point in the VoWi-Fi network to be accessed, and sends the obtained unique identifier to the IMS network through the mobile communication network, so that the IMS network can wait for the user equipment.
  • the legality of the accessed VoWi-Fi network is verified, thereby ensuring that the user equipment accesses the legitimate VoWi-Fi network, and the security of the VoWi-Fi network access is improved. Effectively protects the security of user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the step of determining whether to access the VoWi-Fi network according to the verification result includes: when the verification result indicates that the access point is a legal access point, accessing The VoWi-Fi network; and denying access to the VoWi-Fi network when the verification result indicates that the access point is a rogue access point.
  • the VoWi-Fi network when the verification result reported by the IMS network indicates that the access point is a legal access point, the VoWi-Fi network is accessed, and when the verification result indicates that the access point is an illegal access point, the access is denied.
  • the VoWI-Fi network ensures that user equipment is connected to a legitimate VoWi-Fi network, effectively protecting the security of user data.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • FIG. 2 is a schematic block diagram of an access device of a VoWi-Fi network in accordance with a first embodiment of the present invention.
  • the access device 200 of the VoWi-Fi network is applicable to user equipment, and includes: an obtaining unit 202, a transmitting unit 204, a receiving unit 206, and a processing unit 208.
  • the obtaining unit 202 is configured to obtain a unique identifier of the access point in the VoWi-Fi network to be accessed, and the sending unit 204 is configured to send the unique identifier to the IMS network through the mobile communication network, where the IMS is used.
  • the network verifies the validity of the access point; the receiving unit 206 is configured to receive the verification result of the IMS network feedback; and the processing unit 208 is configured to determine whether to access the VoWi-Fi network according to the verification result.
  • the user equipment obtains the unique identifier of the access point in the VoWi-Fi network to be accessed, and sends the obtained unique identifier to the IMS network through the mobile communication network, so that the IMS network can wait for the user equipment.
  • the legality of the accessed VoWi-Fi network is verified, thereby ensuring that the user equipment accesses the legitimate VoWi-Fi network, improves the security of the VoWi-Fi network access, and effectively protects the security of the user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the processing unit 208 is specifically configured to: when the verification result indicates that the access point is a legal access point, access the VoWi-Fi network; and in the verifying The result indicates that when the access point is an illegal access point, the access to the VoWi-Fi network is denied.
  • the VoWi-Fi network when the verification result reported by the IMS network indicates that the access point is a legal access point, the VoWi-Fi network is accessed, and when the verification result indicates that the access point is an illegal access point, the access is denied.
  • the VoWI-Fi network ensures that user equipment is connected to a legitimate VoWi-Fi network, effectively protecting the security of user data.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • FIG. 3 shows a schematic block diagram of a user equipment in accordance with an embodiment of the present invention.
  • the user equipment 300 includes an access device 200 of a VoWi-Fi network as shown in FIG. 2.
  • FIG. 4 is a schematic flow chart showing an access method of a VoWi-Fi network according to a second embodiment of the present invention.
  • an access method of a VoWi-Fi network includes:
  • Step 402 The IMS network receives a unique identifier of any access point sent by the user equipment through the mobile communication network.
  • Step 404 Verify the validity of the access point according to the unique identifier of any of the access points, to obtain a verification result.
  • Step 406 Send the verification result to the user equipment, for the user equipment to determine whether to access the VoWi-Fi network based on the any access point according to the verification result.
  • the IMS network receives the unique identifier of any access point sent by the user equipment through the mobile communication network, and verifies the legality of the access point according to the received unique identifier, so that the IMS network can The legality of the VoWi-Fi network to be accessed is verified, thereby ensuring that the user equipment accesses the legal VoWi-Fi network, improves the security of the VoWi-Fi network access, and effectively protects the security of the user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the home subscription subscriber server (ie, the HSS) in the IMS network stores a unique identifier of at least one legal access point; and the verification is performed according to the unique identifier of any of the access points.
  • the steps of legality of any access point include:
  • the unique identifier of the legal access point may be stored in the HSS of the IMS network in advance, and then the IMS network can receive the unique identifier of any access point sent by the user equipment according to the HSS.
  • the unique identifier stored in the network determines whether the access point in the VoWi-Fi network to which the user equipment is to be accessed is a legitimate access point.
  • the unique identifier of the at least one legal access point stored in the HSS is corresponding to each ESS, that is, the unique identifier of the at least one legal access point is corresponding to the ESS to which the legal access point belongs. Storing, and determining whether the unique identifier of any access point is stored in the HSS, the ESS to which the access point belongs may be determined first, and then the unique identifier of the legal access point corresponding to the ESS is searched for A unique identifier for an access point.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • FIG. 5 shows a schematic block diagram of an access device of a VoWi-Fi network in accordance with a second embodiment of the present invention.
  • the access device 500 of the VoWi-Fi network is applicable to an IMS network side device, and includes: a receiving unit 502, a verification unit 504, and a sending unit 506.
  • the receiving unit 502 is configured to receive a unique identifier of any access point sent by the user equipment by using the mobile communication network, and the verification unit 504 is configured to verify, according to the unique identifier of the any access point, the any access. The validity of the point is obtained to obtain the verification result; the sending unit 506 is configured to send the verification result to the user equipment, where the user equipment determines, according to the verification result, whether the access is based on the access Point the VoWi-Fi network.
  • the IMS network receives the unique identifier of any access point sent by the user equipment through the mobile communication network, and verifies the legality of the access point according to the received unique identifier, so that the IMS network can The legality of the VoWi-Fi network to be accessed is verified, thereby ensuring that the user equipment accesses the legal VoWi-Fi network, improves the security of the VoWi-Fi network access, and effectively protects the security of the user data.
  • the mobile communication network is any one of a 2G network, a 3G network, a 4G network, and a VoLTE network.
  • the verification unit includes: a determining unit 5042, configured to determine whether a unique identifier of any one of the access points is stored in the home subscription user server in the IMS network; and determining unit 5044, configured to be in the determining unit When determining that the unique identifier of the any access point is stored in the home subscriber network, determining that the access point is a legal access point, and determining, by the determining unit 5042, the attribution subscription When the unique identifier of any one of the access points is not stored in the user server, it is determined that the access point is an illegal access point.
  • the unique identifier of the legal access point may be stored in the HSS of the IMS network in advance, and then the IMS network can receive the unique identifier of any access point sent by the user equipment according to the HSS.
  • the unique identifier stored in the network determines whether the access point in the VoWi-Fi network to which the user equipment is to be accessed is a legitimate access point.
  • the unique identifier of the at least one legal access point stored in the HSS is corresponding to each ESS, that is, the unique identifier of the at least one legal access point is corresponding to the ESS to which the legal access point belongs. Storing, and determining whether the unique identifier of any access point is stored in the HSS, the ESS to which the access point belongs may be determined first, and then the unique identifier of the legal access point corresponding to the ESS is searched for A unique identifier for an access point.
  • the unique identifier comprises: a MAC address.
  • the unique identifier of the access point may also be unique identification information assigned by the network to each access point.
  • FIG. 6 shows a schematic block diagram of an IMS network side device in accordance with an embodiment of the present invention.
  • an IMS network side device 600 includes an access device 500 of a VoWi-Fi network as shown in FIG.
  • VoLTE As domestic operators have begun to deploy VoLTE networks, with the development of network technologies, VoWi-Fi networks will inevitably be deployed. Therefore, UEs will inevitably be in a state where VoLTE and VoWi-Fi are simultaneously camped.
  • the technical solution of the present invention mainly transmits the unique identifier of the VoWi-Fi hotspot to be verified through the mobile communication network (hereinafter, the MAC address is taken as an example), and then the IMS The network verifies the legitimacy of the VoWi-Fi hotspot.
  • the UE acquires the association (the association here is understood to be that the UE has acquired the MAC address of the VoWi-Fi hotspot, but has not yet accessed the VoWI-Fi hotspot) the MAC address of the VoWi-Fi hotspot, and
  • the MAC address is sent to the IMS core network for verification by the mobile communication network, and the IMS core network verifies the legality of the VoWi-Fi hotspot associated with the UE through the HSS server. After the verification is passed, the UE can perform the session on the VoWi-Fi network. Otherwise, the hotspot is added to the blacklist and access is prohibited.
  • the UE When the UE is associated with the VoWi-Fi hotspot, it first sends the hotspot's MAC address to the IMS network through the mobile access network (such as the LTE network shown in FIG. 7, which is hereby exemplified, not limited).
  • the IMS network queries the HSS server to verify the validity of the hotspot.
  • the HSS server in the IMS network needs to be filed, so that each legal VoWi-Fi hotspot is stored in the IMS network. information. In the case of filing, the storage may be corresponding according to the ESS to which each VoWi-Fi hotspot belongs.
  • the UE After verifying that the VoWi-Fi hotspot is legal, the UE will initiate an IMS session through the hotspot, such as registration.
  • E-UTRAN Evolved Universal Terrestrial Radio Access Network
  • MME Mobility Management Entity
  • P-GW Packet Data Network Gateway
  • S-GW Serving Gateway, service gateway
  • EPC network is 4G core network
  • AC Access Controller, access controller
  • P-CSCF Proxy Call Session Control Function
  • I-CSCF Interrogation Call Session
  • S-CSCF Serving Call Session Control Function
  • P-CSCF Proxy Call Session Control Function
  • HLR Home Location Register
  • HSS Home Subscriber Server
  • Step 802 After being associated with the AP, the UE acquires a MAC address of the VoWi-Fi hotspot based on the associated AP.
  • Step 804 The UE sends the MAC address of the associated AP to the S-CSCF of the IMS network.
  • the MAC address of the VoWi-Fi can be carried through the INVITE message and sent through the VoLTE network (here, by way of example only, not limited, or through the 2/3/4G network).
  • Step 806 the S-CSCF of the IMS network sends the MAC address of the VoWi-Fi to the HSS. Legality verification.
  • the S-CSCF may send the MAC address of the VoWi-Fi to the HSS through the auth_request message.
  • step 808 the HSS returns the verification result to the S-CSCF.
  • the HSS may send the authentication result to the S-CSCF through the auth_response message.
  • step 810 the S-CSCF determines the authentication result. If it is 1 (here is only an example and is not limited), the authentication is passed; if it is 0 (here is only an example, not limited), the authentication is performed. failure. When the authentication is passed, step 812 is performed; when the authentication fails, step 816 is performed.
  • Step 812 The S-CSCF sends a message that the authentication is passed to the UE, such as a 200 OK message.
  • Step 814 After determining that the hotspot is legal, the UE initiates a subsequent session.
  • Step 816 The S-CSCF sends a message that the authentication fails, such as a 403 Forbidden message, to the UE.
  • Step 818 When determining that the hotspot is illegal, the UE prohibits access to the hotspot and adds it to the blacklist.
  • Step 820 After the UE adds the hotspot to the blacklist, the association with the hotspot is released.
  • the above technical solution of the solution of the present invention can improve the security of VoWi-Fi network access and protect the security of user data.
  • the present invention provides a new access scheme for a VoWi-Fi network, which ensures that the user equipment accesses a legitimate VoWi-Fi network and improves the VoWi-Fi network connection.
  • Security is added to protect the security of user data.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明提供了一种VoWi-Fi网络的接入方法及接入装置,其中,VoWi-Fi网络的接入方法,包括:用户设备获取待接入的VoWi-Fi网络中接入点的唯一标识;通过移动通信网络将所述唯一标识发送至IMS网络,以供所述IMS网络验证所述接入点的合法性;接收所述IMS网络反馈的验证结果,并根据所述验证结果确定是否接入所述VoWi-Fi网络。本发明的技术方案可以确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。

Description

VoWi-Fi网络的接入方法及接入装置
本申请要求于2016年2月29日提交中国专利局,申请号为201610111038.5、发明名称为“VoWi-Fi网络的接入方法及接入装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信技术领域,具体而言,涉及一种VoWi-Fi网络的接入方法和一种VoWi-Fi网络的接入装置。
背景技术
VoLTE(Voice over LTE)是基于IMS(Internet Protocol Multimedia Subsystem,网际协议多媒体子系统,简称IP多媒体子系统)的语音业务。VoLTE是LTE的终极语音解决方案,其语音可以完全使用PS(Packet Switch,分组交换)域来实现,在接入网通过PS分组域承载,其会话控制以及业务数据传输基于IP实现。然而在室内以及大型的购物商场中Wi-Fi热点的覆盖以及信号质量都是比较理想的,相信在室内以及大型的购物商场等类似场景中VoWi-Fi是大家所青睐的。VoWi-Fi通过Wi-Fi网络接入到IMS网络,同样可以完成语音在IP上承载实现。然而一个Wi-Fi热点覆盖范围是比较小的,通常通过ESS(Extended Service Set,扩展服务集合)网络来扩展Wi-Fi的覆盖范围,VoWi-Fi的接入网络同样可以使用这种扩展机制去扩充VoWi-Fi的覆盖范围。
目前,ESS网络中经常会受到Wi-Fi流氓接入点的安全威胁。比如:UE(User Equipment,用户设备)已连接的Wi-Fi突然断开,却又无法重新连接上,这可能是攻击者建立一个和UE之前连接的热点相同名称的流氓热点,攻击者通过增大流氓热点的发射功率,对正常的热点造成干扰,迫使UE无法连接正常热点。如果攻击者知道该ESS网络的密钥(如公共热点),则UE可能会直接连接上攻击者伪造的流氓热点,此时攻击者会窃取UE中的资料。对于VoWi-Fi网络来说,这种威胁更为严峻,如果连接上流氓VoWi-Fi热点,其可能会伪造成IMS网络向用户获取数据,尤其在初始注册时,由于是通过明文 来传送用户数据,因此将会严重威胁到用户数据的安全性。
因此,如何能够保证用户设备接入合法的VoWi-Fi网络,提高VoWi-Fi网络接入的安全性,保护用户数据的安全成为亟待解决的技术问题。
发明内容
本发明正是基于上述技术问题至少之一,提出了一种新的VoWi-Fi网络的接入方案,可以确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。
有鉴于此,根据本发明的第一方面,提出了一种VoWi-Fi网络的接入方法,包括:用户设备获取待接入的VoWi-Fi网络中接入点的唯一标识;通过移动通信网络将所述唯一标识发送至IMS网络,以供所述IMS网络验证所述接入点的合法性;接收所述IMS网络反馈的验证结果,并根据所述验证结果确定是否接入所述VoWi-Fi网络。
在该技术方案中,用户设备通过获取待接入的VoWi-Fi网络中接入点的唯一标识,并通过移动通信网络将获取到的唯一标识发送至IMS网络,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,根据所述验证结果确定是否接入所述VoWi-Fi网络的步骤,具体包括:在所述验证结果表明所述接入点为合法接入点时,接入所述VoWi-Fi网络;以及在所述验证结果表明所述接入点为非法接入点时,拒绝接入所述VoWi-Fi网络。
在该技术方案中,通过在IMS网络反馈的验证结果表明接入点为合法接入点时,接入VoWi-Fi网络,而在验证结果表明接入点为非法接入点时,拒绝接入VoWI-Fi网络,使得能够确保用户设备接入合法的VoWi-Fi网络,有效保护用户数据的安全性。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
根据本发明的第二方面,还提出了一种VoWi-Fi网络的接入方法,包括: IMS网络接收用户设备通过移动通信网络发送的任一接入点的唯一标识;根据所述任一接入点的唯一标识验证所述任一接入点的合法性,以得到验证结果;将所述验证结果发送至所述用户设备,以供所述用户设备根据所述验证结果确定是否接入基于所述任一接入点的VoWi-Fi网络。
在该技术方案中,IMS网络通过接收用户设备通过移动通信网络发送的任一接入点的唯一标识,并根据接收到的唯一标识验证该接入点的合法性,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,所述IMS网络中的归属签约用户服务器(即HSS,Home Subscriber Server)中存储有至少一个合法接入点的唯一标识;则根据所述任一接入点的唯一标识验证所述任一接入点的合法性的步骤,具体包括:
判断所述IMS网络中的归属签约用户服务器中是否存储有所述任一接入点的唯一标识;在所述归属签约用户服务器中存储有所述任一接入点的唯一标识时,判定所述任一接入点为合法接入点;在所述归属签约用户服务器中未存储所述任一接入点的唯一标识时,判定所述任一接入点为非法接入点。
在该技术方案中,具体地,可以事先在IMS网络的HSS中存储合法的接入点的唯一标识,进而在IMS网络接收到用户设备发送的任一接入点的唯一标识时,能够根据HSS中存储的唯一标识确定用户设备待接入的VoWi-Fi网络中的接入点是否为合法接入点。
其中,作为一个优选实施例,HSS中存储的至少一个合法接入点的唯一标识是与每个ESS相对应的,即将至少一个合法接入点的唯一标识按照合法接入点所属的ESS来对应存储,进而在确定HSS中是否存储有任一接入点的唯一标识时,可以先确定该任一接入点所属的ESS,然后在该ESS对应的合法接入点的唯一标识中查找该任一接入点的唯一标识。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
根据本发明的第三方面,还提出了一种VoWi-Fi网络的接入装置,适用于 用户设备,包括:获取单元,用于获取待接入的VoWi-Fi网络中接入点的唯一标识;发送单元,用于通过移动通信网络将所述唯一标识发送至IMS网络,以供所述IMS网络验证所述接入点的合法性;接收单元,用于接收所述IMS网络反馈的验证结果;处理单元,用于根据所述验证结果确定是否接入所述VoWi-Fi网络。
在该技术方案中,用户设备通过获取待接入的VoWi-Fi网络中接入点的唯一标识,并通过移动通信网络将获取到的唯一标识发送至IMS网络,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,所述处理单元具体用于:在所述验证结果表明所述接入点为合法接入点时,接入所述VoWi-Fi网络;以及在所述验证结果表明所述接入点为非法接入点时,拒绝接入所述VoWi-Fi网络。
在该技术方案中,通过在IMS网络反馈的验证结果表明接入点为合法接入点时,接入VoWi-Fi网络,而在验证结果表明接入点为非法接入点时,拒绝接入VoWI-Fi网络,使得能够确保用户设备接入合法的VoWi-Fi网络,有效保护用户数据的安全性。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
根据本发明的第四方面,还提出了一种VoWi-Fi网络的接入装置,适用于IMS网络侧设备,包括:接收单元,用于接收用户设备通过移动通信网络发送的任一接入点的唯一标识;验证单元,用于根据所述任一接入点的唯一标识验证所述任一接入点的合法性,以得到验证结果;发送单元,用于将所述验证结果发送至所述用户设备,以供所述用户设备根据所述验证结果确定是否接入基于所述任一接入点的VoWi-Fi网络。
在该技术方案中,IMS网络通过接收用户设备通过移动通信网络发送的任一接入点的唯一标识,并根据接收到的唯一标识验证该接入点的合法性,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全 性,有效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,所述IMS网络中的归属签约用户服务器中存储有至少一个合法接入点的唯一标识;
所述验证单元,包括:判断单元,用于判断所述IMS网络中的归属签约用户服务器中是否存储有所述任一接入点的唯一标识;确定单元,用于在所述判断单元判定所述归属签约用户服务器中存储有所述任一接入点的唯一标识时,确定所述任一接入点为合法接入点,并用于在所述判断单元判定所述归属签约用户服务器中未存储所述任一接入点的唯一标识时,确定所述任一接入点为非法接入点。
在该技术方案中,具体地,可以事先在IMS网络的HSS中存储合法的接入点的唯一标识,进而在IMS网络接收到用户设备发送的任一接入点的唯一标识时,能够根据HSS中存储的唯一标识确定用户设备待接入的VoWi-Fi网络中的接入点是否为合法接入点。
其中,作为一个优选实施例,HSS中存储的至少一个合法接入点的唯一标识是与每个ESS相对应的,即将至少一个合法接入点的唯一标识按照合法接入点所属的ESS来对应存储,进而在确定HSS中是否存储有任一接入点的唯一标识时,可以先确定该任一接入点所属的ESS,然后在该ESS对应的合法接入点的唯一标识中查找该任一接入点的唯一标识。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
通过以上技术方案,可以确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。
附图说明
图1示出了根据本发明的第一个实施例的VoWi-Fi网络的接入方法的示意流程图;
图2示出了根据本发明的第一个实施例的VoWi-Fi网络的接入装置的示意框图;
图3示出了根据本发明的实施例的用户设备的示意框图;
图4示出了根据本发明的第二个实施例的VoWi-Fi网络的接入方法的示意流程图;
图5示出了根据本发明的第二个实施例的VoWi-Fi网络的接入装置的示意框图;
图6示出了根据本发明的实施例的IMS网络侧设备的示意框图;
图7示出了根据本发明的实施例的VoWi-Fi网络的接入过程示意图;
图8示出了根据本发明的第三个实施例的VoWi-Fi网络的接入方法的示意流程图。
具体实施方式
为了能够更清楚地理解本发明的上述目的、特征和优点,下面结合附图和具体实施方式对本发明进行进一步的详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明,但是,本发明还可以采用其他不同于在此描述的其他方式来实施,因此,本发明的保护范围并不受下面公开的具体实施例的限制。
图1示出了根据本发明的第一个实施例的VoWi-Fi网络的接入方法的示意流程图。
如图1所示,根据本发明的第一个实施例的VoWi-Fi网络的接入方法,包括:
步骤102,用户设备获取待接入的VoWi-Fi网络中接入点的唯一标识;
步骤104,通过移动通信网络将所述唯一标识发送至IMS网络,以供所述IMS网络验证所述接入点的合法性;
步骤106,接收所述IMS网络反馈的验证结果,并根据所述验证结果确定是否接入所述VoWi-Fi网络。
在该技术方案中,用户设备通过获取待接入的VoWi-Fi网络中接入点的唯一标识,并通过移动通信网络将获取到的唯一标识发送至IMS网络,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有 效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,根据所述验证结果确定是否接入所述VoWi-Fi网络的步骤,具体包括:在所述验证结果表明所述接入点为合法接入点时,接入所述VoWi-Fi网络;以及在所述验证结果表明所述接入点为非法接入点时,拒绝接入所述VoWi-Fi网络。
在该技术方案中,通过在IMS网络反馈的验证结果表明接入点为合法接入点时,接入VoWi-Fi网络,而在验证结果表明接入点为非法接入点时,拒绝接入VoWI-Fi网络,使得能够确保用户设备接入合法的VoWi-Fi网络,有效保护用户数据的安全性。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
图2示出了根据本发明的第一个实施例的VoWi-Fi网络的接入装置的示意框图。
如图2所示,根据本发明的第一个实施例的VoWi-Fi网络的接入装置200,适用于用户设备,包括:获取单元202、发送单元204、接收单元206和处理单元208。
其中,获取单元202,用于获取待接入的VoWi-Fi网络中接入点的唯一标识;发送单元204,用于通过移动通信网络将所述唯一标识发送至IMS网络,以供所述IMS网络验证所述接入点的合法性;接收单元206,用于接收所述IMS网络反馈的验证结果;处理单元208,用于根据所述验证结果确定是否接入所述VoWi-Fi网络。
在该技术方案中,用户设备通过获取待接入的VoWi-Fi网络中接入点的唯一标识,并通过移动通信网络将获取到的唯一标识发送至IMS网络,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,所述处理单元208具体用于:在所述验证结果表明所述接入点为合法接入点时,接入所述VoWi-Fi网络;以及在所述验证 结果表明所述接入点为非法接入点时,拒绝接入所述VoWi-Fi网络。
在该技术方案中,通过在IMS网络反馈的验证结果表明接入点为合法接入点时,接入VoWi-Fi网络,而在验证结果表明接入点为非法接入点时,拒绝接入VoWI-Fi网络,使得能够确保用户设备接入合法的VoWi-Fi网络,有效保护用户数据的安全性。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
图3示出了根据本发明的实施例的用户设备的示意框图。
如图3所示,根据本发明的实施例的用户设备300,包括:如图2中所示的VoWi-Fi网络的接入装置200。
图4示出了根据本发明的第二个实施例的VoWi-Fi网络的接入方法的示意流程图。
如图4所示,根据本发明的第二个实施例的VoWi-Fi网络的接入方法,包括:
步骤402,IMS网络接收用户设备通过移动通信网络发送的任一接入点的唯一标识;
步骤404,根据所述任一接入点的唯一标识验证所述任一接入点的合法性,以得到验证结果;
步骤406,将所述验证结果发送至所述用户设备,以供所述用户设备根据所述验证结果确定是否接入基于所述任一接入点的VoWi-Fi网络。
在该技术方案中,IMS网络通过接收用户设备通过移动通信网络发送的任一接入点的唯一标识,并根据接收到的唯一标识验证该接入点的合法性,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,所述IMS网络中的归属签约用户服务器(即HSS)中存储有至少一个合法接入点的唯一标识;则根据所述任一接入点的唯一标识验证所述任一接入点的合法性的步骤,具体包括:
判断所述IMS网络中的归属签约用户服务器中是否存储有所述任一接入 点的唯一标识;在所述归属签约用户服务器中存储有所述任一接入点的唯一标识时,判定所述任一接入点为合法接入点;在所述归属签约用户服务器中未存储所述任一接入点的唯一标识时,判定所述任一接入点为非法接入点。
在该技术方案中,具体地,可以事先在IMS网络的HSS中存储合法的接入点的唯一标识,进而在IMS网络接收到用户设备发送的任一接入点的唯一标识时,能够根据HSS中存储的唯一标识确定用户设备待接入的VoWi-Fi网络中的接入点是否为合法接入点。
其中,作为一个优选实施例,HSS中存储的至少一个合法接入点的唯一标识是与每个ESS相对应的,即将至少一个合法接入点的唯一标识按照合法接入点所属的ESS来对应存储,进而在确定HSS中是否存储有任一接入点的唯一标识时,可以先确定该任一接入点所属的ESS,然后在该ESS对应的合法接入点的唯一标识中查找该任一接入点的唯一标识。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
图5示出了根据本发明的第二个实施例的VoWi-Fi网络的接入装置的示意框图。
如图5所示,根据本发明的第二个实施例的VoWi-Fi网络的接入装置500,适用于IMS网络侧设备,包括:接收单元502、验证单元504和发送单元506。
其中,接收单元502,用于接收用户设备通过移动通信网络发送的任一接入点的唯一标识;验证单元504,用于根据所述任一接入点的唯一标识验证所述任一接入点的合法性,以得到验证结果;发送单元506,用于将所述验证结果发送至所述用户设备,以供所述用户设备根据所述验证结果确定是否接入基于所述任一接入点的VoWi-Fi网络。
在该技术方案中,IMS网络通过接收用户设备通过移动通信网络发送的任一接入点的唯一标识,并根据接收到的唯一标识验证该接入点的合法性,使得IMS网络能够对用户设备待接入的VoWi-Fi网络的合法性进行验证,进而能够确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。其中,移动通信网络是2G网络、3G网络、4G网络、VoLTE网络中的任一网络。
在上述技术方案中,优选地,所述IMS网络中的归属签约用户服务器中 存储有至少一个合法接入点的唯一标识;
所述验证单元,包括:判断单元5042,用于判断所述IMS网络中的归属签约用户服务器中是否存储有所述任一接入点的唯一标识;确定单元5044,用于在所述判断单元5042判定所述归属签约用户服务器中存储有所述任一接入点的唯一标识时,确定所述任一接入点为合法接入点,并用于在所述判断单元5042判定所述归属签约用户服务器中未存储所述任一接入点的唯一标识时,确定所述任一接入点为非法接入点。
在该技术方案中,具体地,可以事先在IMS网络的HSS中存储合法的接入点的唯一标识,进而在IMS网络接收到用户设备发送的任一接入点的唯一标识时,能够根据HSS中存储的唯一标识确定用户设备待接入的VoWi-Fi网络中的接入点是否为合法接入点。
其中,作为一个优选实施例,HSS中存储的至少一个合法接入点的唯一标识是与每个ESS相对应的,即将至少一个合法接入点的唯一标识按照合法接入点所属的ESS来对应存储,进而在确定HSS中是否存储有任一接入点的唯一标识时,可以先确定该任一接入点所属的ESS,然后在该ESS对应的合法接入点的唯一标识中查找该任一接入点的唯一标识。
在上述任一技术方案中,优选地,所述唯一标识包括:MAC地址。此外,接入点的唯一标识还可以是网络为每个接入点分配的唯一标识信息。
图6示出了根据本发明的实施例的IMS网络侧设备的示意框图。
如图6所示,根据本发明的实施例的IMS网络侧设备600,包括:如图5中所示的VoWi-Fi网络的接入装置500。
以下结合图7和图8详细说明本发明的技术方案。
由于目前国内运营商已经开始部署VoLTE网络,随着网络技术的发展,必然会部署VoWi-Fi网络,因此UE必然会出现VoLTE和VoWi-Fi同时驻留的状态。
为了防止VoWi-Fi的ESS网络流氓热点的攻击,本发明的技术方案主要是通过移动通信网络来传输待验证的VoWi-Fi热点的唯一标识(以下以MAC地址为例进行说明),进而由IMS网络来验证该VoWi-Fi热点的合法性。具体地,首先UE获取关联(此处的关联理解为UE已获取了VoWi-Fi热点的MAC地址,但是还未接入VoWI-Fi热点)VoWi-Fi热点的MAC地址,并将 该MAC地址通过移动通信网络发送到IMS核心网进行验证,IMS核心网通过HSS服务器来验证UE所关联的VoWi-Fi热点的合法性,验证通过后,UE才可在VoWi-Fi网络上进行会话,否则将该热点加入到黑名单,禁止接入。
具体如图7所示:
当UE关联到VoWi-Fi热点时,其首先会将该热点的MAC地址通过移动接入网(如图7中所示的LTE网络,在此仅为示例,不做限定)发送到IMS网络,由IMS网络查询HSS服务器来验证该热点的合法性,当然在部署该VoWi-Fi的热点时需要在IMS网络中的HSS服务器进行备案,这样IMS网络中就会存储各个合法的VoWi-Fi热点的信息。其中,在进行备案时,可以根据每个VoWi-Fi热点所属的ESS来对应存储。
当验证该VoWi-Fi热点是合法的之后,UE才会通过该热点发起IMS会话,如注册等。
其中,图7中所示的英文缩写的含义如下:
E-UTRAN(Evolved Universal Terrestrial Radio Access Network,演进的陆地通用无线接入网络)、MME(Mobility Management Entity,移动性管理实体)、P-GW(Packet Data Network Gateway,数据网络网关)、S-GW(Serving Gateway,服务网关)、EPC网络为4G核心网络、AC(Access Controller,接入控制器)、P-CSCF(Proxy Call Session Control Function,代理呼叫会话控制功能)、I-CSCF(Interrogation Call Session Control Function,问询呼叫会话控制功能)、S-CSCF(Serving Call Session Control Function,服务呼叫会话控制功能)、P-CSCF(Proxy Call Session Control Function,代理呼叫会话控制功能)、HLR(Home Location Register,归属位置寄存器)、HSS(Home Subscriber Server,归属签约用户服务器)。
具体地交互过程如图8所示,包括:
步骤802,UE在与AP关联之后,获取基于关联AP的VoWi-Fi热点的MAC地址。
步骤804,UE将关联AP的MAC地址发送至IMS网络的S-CSCF。优选地,可以通过INVITE消息携带VoWi-Fi的MAC地址,并通过VoLTE网络(此处仅为示例,并不做限定,也可以通过2/3/4G网络)发送。
步骤806,IMS网络的S-CSCF将VoWi-Fi的MAC地址发送至HSS进行 合法性验证。优选地,S-CSCF可以通过auth_request消息携带VoWi-Fi的MAC地址发送至HSS。
步骤808,HSS向S-CSCF返回验证结果。优选地,HSS可以通过auth_response消息携带认证结果发送至S-CSCF。
步骤810,S-CSCF判断认证结果,若为1(此处仅为示例,并不做限定),则表示认证通过;若为0(此处仅为示例,并不做限定),则表示认证失败。当认证通过时,执行步骤812;当认证失败时,执行步骤816。
步骤812,S-CSCF向UE发送认证通过的消息,如200OK消息。
步骤814,UE在确定该热点合法后,发起后续会话。
步骤816,S-CSCF向UE发送认证失败的消息,如403Forbidden消息。
步骤818,UE在确定该热点非法时,禁止接入该热点,并将其加入黑名单。
步骤820,在UE将热点加入黑名单后,解除与该热点之间的关联。
本发明方案的上述技术方案可以提高VoWi-Fi网络接入的安全性,保护用户数据的安全。
以上结合附图详细说明了本发明的技术方案,本发明提出了一种新的VoWi-Fi网络的接入方案,可以确保用户设备接入合法的VoWi-Fi网络,提高了VoWi-Fi网络接入的安全性,有效保护了用户数据的安全性。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。

Claims (10)

  1. 一种VoWi-Fi网络的接入方法,其特征在于,包括:
    用户设备获取待接入的VoWi-Fi网络中接入点的唯一标识;
    通过移动通信网络将所述唯一标识发送至IMS网络,以供所述IMS网络验证所述接入点的合法性;
    接收所述IMS网络反馈的验证结果,并根据所述验证结果确定是否接入所述VoWi-Fi网络。
  2. 根据权利要求1所述的VoWi-Fi网络的接入方法,其特征在于,根据所述验证结果确定是否接入所述VoWi-Fi网络的步骤,具体包括:
    在所述验证结果表明所述接入点为合法接入点时,接入所述VoWi-Fi网络;以及
    在所述验证结果表明所述接入点为非法接入点时,拒绝接入所述VoWi-Fi网络。
  3. 根据权利要求1或2所述的VoWi-Fi网络的接入方法,其特征在于,所述唯一标识包括:MAC地址。
  4. 一种VoWi-Fi网络的接入方法,其特征在于,包括:
    IMS网络接收用户设备通过移动通信网络发送的任一接入点的唯一标识;
    根据所述任一接入点的唯一标识验证所述任一接入点的合法性,以得到验证结果;
    将所述验证结果发送至所述用户设备,以供所述用户设备根据所述验证结果确定是否接入基于所述任一接入点的VoWi-Fi网络。
  5. 根据权利要求4所述的VoWi-Fi网络的接入方法,其特征在于,所述IMS网络中的归属签约用户服务器中存储有至少一个合法接入点的唯一标识;
    则根据所述任一接入点的唯一标识验证所述任一接入点的合法性的步骤,具体包括:
    判断所述IMS网络中的归属签约用户服务器中是否存储有所述任一接入点的唯一标识;
    在所述归属签约用户服务器中存储有所述任一接入点的唯一标识时,判定所述任一接入点为合法接入点;
    在所述归属签约用户服务器中未存储所述任一接入点的唯一标识时,判定所述任一接入点为非法接入点。
  6. 一种VoWi-Fi网络的接入装置,适用于用户设备,其特征在于,包括:
    获取单元,用于获取待接入的VoWi-Fi网络中接入点的唯一标识;
    发送单元,用于通过移动通信网络将所述唯一标识发送至IMS网络,以供所述IMS网络验证所述接入点的合法性;
    接收单元,用于接收所述IMS网络反馈的验证结果;
    处理单元,用于根据所述验证结果确定是否接入所述VoWi-Fi网络。
  7. 根据权利要求6所述的VoWi-Fi网络的接入装置,其特征在于,所述处理单元具体用于:
    在所述验证结果表明所述接入点为合法接入点时,接入所述VoWi-Fi网络;以及
    在所述验证结果表明所述接入点为非法接入点时,拒绝接入所述VoWi-Fi网络。
  8. 根据权利要求6或7所述的VoWi-Fi网络的接入装置,其特征在于,所述唯一标识包括:MAC地址。
  9. 一种VoWi-Fi网络的接入装置,适用于IMS网络侧设备,其特征在于,包括:
    接收单元,用于接收用户设备通过移动通信网络发送的任一接入点的唯一标识;
    验证单元,用于根据所述任一接入点的唯一标识验证所述任一接入点的合法性,以得到验证结果;
    发送单元,用于将所述验证结果发送至所述用户设备,以供所述用户设备根据所述验证结果确定是否接入基于所述任一接入点的VoWi-Fi网络。
  10. 根据权利要求9所述的VoWi-Fi网络的接入装置,其特征在于,所述IMS网络中的归属签约用户服务器中存储有至少一个合法接入点的唯一标识;
    所述验证单元,包括:
    判断单元,用于判断所述IMS网络中的归属签约用户服务器中是否存储有所述任一接入点的唯一标识;
    确定单元,用于在所述判断单元判定所述归属签约用户服务器中存储有所 述任一接入点的唯一标识时,确定所述任一接入点为合法接入点,并用于在所述判断单元判定所述归属签约用户服务器中未存储所述任一接入点的唯一标识时,确定所述任一接入点为非法接入点。
PCT/CN2016/080602 2016-02-29 2016-04-29 VoWi-Fi网络的接入方法及接入装置 Ceased WO2017147993A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610111038.5 2016-02-29
CN201610111038.5A CN105704716A (zh) 2016-02-29 2016-02-29 VoWi-Fi网络的接入方法及接入装置

Publications (1)

Publication Number Publication Date
WO2017147993A1 true WO2017147993A1 (zh) 2017-09-08

Family

ID=56222725

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/080602 Ceased WO2017147993A1 (zh) 2016-02-29 2016-04-29 VoWi-Fi网络的接入方法及接入装置

Country Status (2)

Country Link
CN (1) CN105704716A (zh)
WO (1) WO2017147993A1 (zh)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109275173A (zh) * 2017-07-17 2019-01-25 中创通信技术(深圳)有限公司 一种利用wifi强连的方法、装置以及电子设备
CN107493565A (zh) * 2017-09-19 2017-12-19 深圳天珑无线科技有限公司 Wi‑Fi连接方法、移动终端及计算机可读存储介质
CN109803350B (zh) 2017-11-17 2021-06-08 华为技术有限公司 一种安全通信方法和装置
CN110572820B (zh) * 2019-08-09 2022-01-25 中移(杭州)信息技术有限公司 Ims终端的注册方法、装置、位置信息服务器及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080259885A1 (en) * 2007-04-23 2008-10-23 Cingular Wireless Ii, Llc Dual mode device with mac address capture and pairing
US20100008259A1 (en) * 2008-07-14 2010-01-14 Qualcomm Incorporated Systems, methods and apparatus to facilitate identification and acquisition of access points
CN104066109A (zh) * 2014-06-30 2014-09-24 中国联合网络通信集团有限公司 Ims网络的注册管理方法、装置及系统
CN104066086A (zh) * 2014-06-30 2014-09-24 中国联合网络通信集团有限公司 语音通信的方法及装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080259885A1 (en) * 2007-04-23 2008-10-23 Cingular Wireless Ii, Llc Dual mode device with mac address capture and pairing
US20100008259A1 (en) * 2008-07-14 2010-01-14 Qualcomm Incorporated Systems, methods and apparatus to facilitate identification and acquisition of access points
CN104066109A (zh) * 2014-06-30 2014-09-24 中国联合网络通信集团有限公司 Ims网络的注册管理方法、装置及系统
CN104066086A (zh) * 2014-06-30 2014-09-24 中国联合网络通信集团有限公司 语音通信的方法及装置

Also Published As

Publication number Publication date
CN105704716A (zh) 2016-06-22

Similar Documents

Publication Publication Date Title
EP3629613B1 (en) Network verification method, and relevant device and system
US11089479B2 (en) Signaling attack prevention method and apparatus
JP7047921B2 (ja) 通信装置、第1のネットワーク装置、通信装置の方法、及び第1のネットワーク装置の方法
KR101475349B1 (ko) 이동 통신 시스템에서 단말 보안 능력 관련 보안 관리 방안및 장치
EP2258126B1 (en) Security for a non-3gpp access to an evolved packet system
US8428554B2 (en) Method for authenticating a mobile unit attached to a femtocell that operates according to code division multiple access
KR101121465B1 (ko) Ims과 같은 시큐어 코어 네트워크와 통신하는 펨토셀에 부착된 모바일 유닛들을 인증하기 위한 방법
EP2276281B1 (en) Method, system and device for obtaining a trust type of a non-3gpp access system
US20230396602A1 (en) Service authorization method and system, and communication apparatus
CN100499536C (zh) 无线局域网中选定业务的解析接入处理方法
CN108307296B (zh) 对国际位置中的用户设备提供差异化服务的系统和方法
KR102390380B1 (ko) 비인증 사용자에 대한 3gpp 진화된 패킷 코어로의 wlan 액세스를 통한 긴급 서비스의 지원
CN101816200B (zh) 认证附着到与诸如ims的安全核心网通信的毫微微蜂窝上的移动单元的方法
KR20110091305A (ko) Mocn에서 긴급 호를 위한 plmn 선택 방법 및 장치
CN108353283B (zh) 防止来自伪基站的攻击的方法和装置
WO2010000185A1 (zh) 一种网络认证的方法、装置、系统及服务器
WO2013185709A1 (zh) 一种呼叫认证方法、设备和系统
WO2017147993A1 (zh) VoWi-Fi网络的接入方法及接入装置
EP1757139A1 (en) Method of preventing or limiting the number of simultaneous sessions in wireless local area network (wlan)
CN104935557A (zh) 本地网络访问的控制方法及装置
JP2018514166A (ja) アクセスポイント名許可方法、アクセスポイント名許可装置、およびアクセスポイント名許可システム
US20180343559A1 (en) Method and device for obtaining user equipment identifier, and method and device for sending user equipment identifier

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16892182

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 16892182

Country of ref document: EP

Kind code of ref document: A1