WO2017167249A1 - 一种专网接入方法、装置及系统 - Google Patents

一种专网接入方法、装置及系统 Download PDF

Info

Publication number
WO2017167249A1
WO2017167249A1 PCT/CN2017/078910 CN2017078910W WO2017167249A1 WO 2017167249 A1 WO2017167249 A1 WO 2017167249A1 CN 2017078910 W CN2017078910 W CN 2017078910W WO 2017167249 A1 WO2017167249 A1 WO 2017167249A1
Authority
WO
WIPO (PCT)
Prior art keywords
private network
mobile terminal
mobile
tunnel
network gateway
Prior art date
Application number
PCT/CN2017/078910
Other languages
English (en)
French (fr)
Inventor
丰孝英
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2017167249A1 publication Critical patent/WO2017167249A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4633Interconnection of networks using encapsulation techniques, e.g. tunneling
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • H04W12/033Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • H04W12/037Protecting confidentiality, e.g. by encryption of the control plane, e.g. signalling traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a private network access method, apparatus, and system.
  • networks with high security requirements such as public security and military network systems, are separated from other computer network systems by establishing a private network because of the particularity of the application environment. Highly secure.
  • the user access location and access device in the private network are fixed, and security is easy to be guaranteed.
  • the location of the terminal is fixed, which also brings a lot of inconveniences.
  • With the rapid development of mobile broadband and the intelligentization of mobile terminals if private network users can use mobile terminals to access private networks through mobile networks, it will bring great convenience. For example, police officers handling cases or traveling on the road need to check in time. Important information in the internal network, etc., if you can use the mobile terminal to access the private network will bring convenience.
  • the technical problem to be solved by the present invention is to provide a private network access method, device and system for solving the problem that the mobile terminal accessing the private network is inconvenient or insecure in the prior art.
  • the present invention provides a private network access method, including: a mobile network gateway establishes a forwarding tunnel between the mobile terminal and a corresponding private network according to a session establishment request of the mobile terminal; The forwarding tunnel forwards the encrypted signaling between the mobile terminal and the corresponding private network, so that the mobile terminal obtains the IP (Internet Protocol) allocated by the corresponding private network to the mobile terminal by using the encrypted signaling. An internetwork protocol) address; the mobile network gateway forwards communication data between the mobile terminal and the corresponding private network through the forwarding tunnel in the form of encrypted data.
  • IP Internet Protocol
  • the mobile network gateway establishes a forwarding tunnel between the mobile terminal and the corresponding private network according to the session establishment request of the mobile terminal, where the mobile network gateway searches for the mobile terminal according to the session establishment request.
  • the mobile network gateway sends a tunnel establishment request message to the corresponding private network, where the tunnel establishment request message carries the identification information of the mobile terminal; the mobile network gateway receives the corresponding private network
  • the tunnel establishment response message forwards the tunnel establishment response message to the mobile terminal.
  • the sending, by the mobile network gateway, the tunnel establishment request message to the corresponding private network the mobile network gateway directly sending a tunnel establishment request message to the security processing device of the corresponding private network, or the mobile network gateway And sending, by the gateway corresponding to the private network, a tunnel establishment request message to the security processing device of the corresponding private network.
  • the present invention further provides a private network access method, including: a corresponding private network of a mobile terminal establishes a forwarding tunnel with the mobile terminal by using the mobile network gateway according to a request of the mobile network gateway; The private network allocates an IP address to the mobile terminal, and sends the IP address to the mobile terminal through the forwarding tunnel in the form of encrypted signaling; the corresponding private network passes the forwarding tunnel in the form of encrypted data. Communicating with the mobile terminal.
  • the method further includes: performing, by the corresponding private network, the mobile terminal And, in the case that the authentication is passed, the forwarding tunnel with the mobile terminal is established by the mobile network gateway according to the request of the mobile network gateway.
  • the corresponding private network of the mobile terminal establishes a forwarding tunnel with the mobile terminal by using the mobile network gateway according to the request of the mobile network gateway, and the corresponding private network of the mobile terminal receives the sending of the mobile network gateway.
  • a tunnel establishment request message where the tunnel establishment request message carries the identification information of the mobile terminal; the corresponding private network sends a tunnel establishment response message to the mobile network gateway, to establish and describe by the mobile network gateway The forwarding tunnel of the mobile terminal.
  • the present invention further provides a private network access method, including: a mobile terminal initiates a session establishment request to a mobile network gateway, to establish a forwarding tunnel between the mobile terminal and a corresponding private network by using the mobile network gateway.
  • the mobile terminal requests an IP address from the mobile network gateway to the corresponding private network by using the mobile network gateway; the mobile terminal communicates with the corresponding private network through the forwarding tunnel in the form of encrypted data.
  • the present invention further provides a private network access apparatus, including: an establishing unit, configured to establish a forwarding tunnel between the mobile terminal and a corresponding private network according to a session establishment request of the mobile terminal; and a signaling forwarding unit And transmitting, by the forwarding unit, the forwarding tunnel, the encrypted signaling between the mobile terminal and the corresponding private network, so that the mobile terminal obtains the corresponding private network by using the encrypted signaling.
  • the IP address allocated by the mobile terminal; the data forwarding unit is configured to forward the communication data between the mobile terminal and the corresponding private network through the forwarding tunnel in the form of encrypted data.
  • the establishing unit includes: a searching module, configured to search, according to the session establishment request, a corresponding private network of the mobile terminal, and a sending module, configured to send a tunnel establishment request message to the corresponding private network, where The tunnel establishment request message carries the identification information of the mobile terminal, and the receiving module is configured to receive a tunnel establishment response message from the corresponding private network; the sending module is further configured to: send the tunnel establishment response message to The mobile terminal forwards.
  • the sending module is configured to: directly send a tunnel establishment request message to the security processing device of the corresponding private network, or send the message to the security processing device of the corresponding private network by using the gateway of the corresponding private network Tunnel establishment request message.
  • the present invention further provides a private network access apparatus, including: a private network establishing unit, configured to establish, by the mobile network gateway, a forwarding tunnel with a mobile terminal according to a request of the mobile network gateway; and an address allocation unit, configured to: Assigning an IP address to the mobile terminal, and transmitting the IP address to the mobile terminal in the form of encrypted signaling through the forwarding tunnel; and a communication unit, configured to pass the forwarding tunnel and the encrypted data The mobile terminal communicates.
  • a private network establishing unit configured to establish, by the mobile network gateway, a forwarding tunnel with a mobile terminal according to a request of the mobile network gateway
  • an address allocation unit configured to: Assigning an IP address to the mobile terminal, and transmitting the IP address to the mobile terminal in the form of encrypted signaling through the forwarding tunnel
  • a communication unit configured to pass the forwarding tunnel and the encrypted data The mobile terminal communicates.
  • the apparatus further includes an authentication unit configured to establish through the mobile network gateway according to a request of the mobile network gateway Before the forwarding tunnel of the mobile terminal, the mobile terminal is authenticated; the private network establishing unit is specifically configured to pass the request of the mobile network gateway according to the request of the mobile network gateway if the authentication unit passes the authentication The mobile network gateway establishes a forwarding tunnel with the mobile terminal.
  • the private network establishing unit is specifically configured to: receive a tunnel establishment request message that is sent by the mobile network gateway, where the tunnel establishment request message carries the identification information of the mobile terminal; to the mobile network The gateway sends a tunnel setup response message to establish a forwarding tunnel with the mobile terminal through the mobile network gateway.
  • the present invention further provides a private network access device, including: a terminal establishing unit, configured to initiate a session establishment request to a mobile network gateway, to establish the mobile terminal and the corresponding private network by using the mobile network gateway An address forwarding unit, configured to request an IP address from the mobile network gateway to the corresponding private network by using an encrypted signaling manner; and a terminal communication unit, configured to transmit the tunnel through the forwarding tunnel in the form of encrypted data The corresponding private network communication.
  • a terminal establishing unit configured to initiate a session establishment request to a mobile network gateway, to establish the mobile terminal and the corresponding private network by using the mobile network gateway
  • An address forwarding unit configured to request an IP address from the mobile network gateway to the corresponding private network by using an encrypted signaling manner
  • a terminal communication unit configured to transmit the tunnel through the forwarding tunnel in the form of encrypted data The corresponding private network communication.
  • the present invention also provides a mobile network gateway, including any corresponding private network access device provided by the present invention.
  • the present invention also provides a private network device, including any corresponding private network access device provided by the present invention.
  • the present invention also provides a mobile terminal, including any corresponding private network access device provided by the present invention.
  • the present invention further provides a private network access system, including any of the mobile network gateways, private network devices, and mobile terminals provided by the present invention.
  • the mobile network gateway can establish a forwarding tunnel between the mobile terminal and the corresponding private network according to the session establishment request of the mobile terminal, and Transmitting the encryption signaling between the mobile terminal and the corresponding private network, so that the mobile terminal obtains the IP address allocated by the corresponding private network for the mobile terminal by using the encrypted signaling, and then encrypts the data.
  • the mobile terminal can access the corresponding private network without using a separate mobile network, thereby facilitating the user and ensuring the private network and The security of its application access.
  • FIG. 1 is a flowchart of a method for accessing a private network according to an embodiment of the present invention
  • FIG. 2 is another flowchart of a private network access method according to an embodiment of the present invention.
  • FIG. 3 is still another flowchart of a private network access method according to an embodiment of the present invention.
  • FIG. 4 is a detailed flowchart of a method for accessing a private network according to an embodiment of the present invention
  • FIG. 5 is another detailed flowchart of a private network access method according to an embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of a private network access device according to an embodiment of the present invention.
  • FIG. 7 is another schematic structural diagram of a private network access device according to an embodiment of the present invention.
  • FIG. 8 is still another schematic structural diagram of a private network access device according to an embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of a private network access system according to an embodiment of the present invention.
  • an embodiment of the present invention provides a private network access method, including:
  • the mobile network gateway establishes a forwarding tunnel between the mobile terminal and the corresponding private network according to the session establishment request of the mobile terminal.
  • the mobile network gateway forwards the encrypted signaling between the mobile terminal and the corresponding private network by using the forwarding tunnel, so that the mobile terminal obtains the corresponding private network by using the encrypted signaling.
  • the mobile network gateway forwards, by using the forwarding tunnel, communication data between the mobile terminal and the corresponding private network in the form of encrypted data.
  • the mobile network gateway can establish a forwarding tunnel between the mobile terminal and the corresponding private network according to the session establishment request of the mobile terminal, and use the forwarding tunnel in the mobile terminal Transmitting the encryption signaling with the corresponding private network, so that the mobile terminal obtains the IP address allocated by the corresponding private network for the mobile terminal by using the encrypted signaling, and then passes the encrypted data in the form of encrypted data.
  • the forwarding tunnel forwards communication data between the mobile terminal and the corresponding private network.
  • the mobile terminal can access the corresponding private network without using a separate mobile network, thereby facilitating the user and ensuring the private network and The security of its application access.
  • a session establishment request is first initiated, including initiating an attachment or requesting to establish a new session.
  • the session establishment request may be transmitted to the mobile network gateway through processing and transmission by the wireless side network element.
  • the mobile terminal may send the NAS signaling to the MME (Mobil management entity), and the MME may be based on the APN (Access Point Name, access point name) carried by the NAS (Non-Access-Stratume) signaling.
  • APN Access Point Name, access point name
  • NAS Non-Access-Stratume
  • the mobile network gateway can establish a forwarding tunnel between the mobile terminal and the corresponding private network according to the session establishment request of the mobile terminal.
  • establishing a forwarding tunnel between the mobile terminal and the corresponding private network may include the following steps:
  • the mobile network gateway searches for a corresponding private network of the mobile terminal according to the session establishment request;
  • the mobile network gateway sends a tunnel establishment request message to the corresponding private network, where the tunnel establishment request message carries the identification information of the mobile terminal;
  • the mobile network gateway receives the tunnel establishment response message from the corresponding private network, and forwards the tunnel establishment response message to the mobile terminal.
  • the mobile network gateway can save the corresponding session/tunnel information. Then, according to a certain strategy, the corresponding private network gateway is selected for the mobile terminal.
  • the mobile terminal is generally specially designed for the internal network of the unit, and the mobile network gateway can identify the mobile terminal according to the identity information of the mobile terminal carried in the received session request message. Which private network belongs to, or which private network corresponds.
  • the identifier information may be an APN information, or may be an IMSI (International Mobile Subscriber Identification Number)/MSISDN (Mobile Subscriber International ISDN/PSTN number) information, or may be Other embodiments of the present invention are not limited to such other numbers or codes that can embody the identity of the mobile terminal.
  • the mobile network gateway may send a tunnel establishment request message to the corresponding private network, and carry the identification information of the mobile terminal in the tunnel establishment request message.
  • the mobile network gateway may directly send a tunnel establishment request message to the security processing device of the corresponding private network, or may use the gateway corresponding to the private network to the security processing device of the corresponding private network.
  • a tunnel establishment request message is sent, so that the security processing device of the corresponding private network performs security processing on the corresponding tunnel connection.
  • the mobile network gateway may forward the encrypted signaling between the mobile terminal and the corresponding private network through the forwarding tunnel, so that the mobile terminal passes the encrypted signaling. Obtaining an IP address assigned by the corresponding private network to the mobile terminal.
  • an embodiment of the present invention further provides a private network access method, including:
  • the corresponding private network of the mobile terminal establishes a forwarding tunnel with the mobile terminal by using the mobile network gateway according to the request of the mobile network gateway.
  • the corresponding private network allocates an IP address to the mobile terminal, and sends the IP address to the mobile terminal by using the forwarding tunnel in an encrypted signaling manner;
  • the corresponding private network communicates with the mobile terminal by using the forwarding tunnel in the form of encrypted data.
  • the corresponding private network of the mobile terminal can establish a forwarding tunnel with the mobile terminal through the mobile network gateway according to the request of the mobile network gateway, and allocate an IP address to the mobile terminal. And transmitting, by the forwarding tunnel, the IP address to the mobile terminal in the form of encrypted signaling, and then communicating with the mobile terminal through the forwarding tunnel in the form of encrypted data.
  • the mobile terminal since the process of acquiring the IP address by the mobile terminal and the data transmission process with the private network are encrypted, the mobile terminal can access the corresponding private network without using a separate mobile network, thereby facilitating the user and ensuring the private network and The security of its application access.
  • multiple network elements may be configured in the corresponding private network, where the security processing device is related to the private network security processing.
  • Which security processing device is specifically used to serve the mobile terminal may be selected differently according to specific conditions.
  • the mobile network gateway may directly select a security management device for the mobile terminal to serve, or the mobile network gateway may first communicate with the private network gateway, and the private network gateway selects a corresponding security processing device for the mobile terminal.
  • Embodiments of the invention are not limited in this regard.
  • the policy for selecting the security processing device may include multiple types, for example, may be selected according to APN or IMSI/MSISN information, or may be selected according to load conditions of each security processing device, which is not limited by the embodiment of the present invention.
  • the corresponding private network of the mobile terminal may include the following steps:
  • the corresponding private network of the mobile terminal receives the tunnel establishment request message sent by the mobile network gateway, where the tunnel establishment request message carries the identification information of the mobile terminal;
  • the corresponding private network of the mobile terminal establishes and moves with the mobile network gateway according to the request of the mobile network gateway.
  • the terminal may also include:
  • the corresponding private network authenticates the mobile terminal, and if the authentication is passed, the forwarding tunnel with the mobile terminal is established by the mobile network gateway according to the request of the mobile network gateway. For example, the corresponding private network may require the user of the mobile terminal to input a password or perform fingerprint identification to authenticate the mobile terminal. If the authentication is passed, the forwarding tunnel is established between the mobile network gateway and the mobile terminal. Otherwise, the forwarding tunnel is not established. .
  • an embodiment of the present invention further provides a private network access method, including:
  • the mobile terminal initiates a session establishment request to the mobile network gateway to establish a forwarding tunnel between the mobile terminal and the corresponding private network by using the mobile network gateway.
  • the mobile terminal requests an IP address from the mobile network gateway to the corresponding private network by using an encrypted signaling manner.
  • the mobile terminal communicates with the corresponding private network through the forwarding tunnel in the form of encrypted data.
  • the mobile terminal can initiate a session establishment request to the mobile network gateway to establish a forwarding tunnel between the mobile terminal and the corresponding private network by using the mobile network gateway, and encrypt the And obtaining, by the mobile network gateway, an IP address from the corresponding private network, and then communicating with the corresponding private network through the forwarding tunnel in the form of encrypted data.
  • the mobile terminal can access the corresponding private network without using a separate mobile network, thereby facilitating the user and ensuring the private network and The security of its application access.
  • the private network access method provided by the present invention is described in detail below through specific embodiments.
  • FIG. 4 is a flowchart of a private network access method provided by an embodiment of the present application.
  • the interface between the mobile network GW and the private network gateway is referred to as "I1"; the interface between the private network gateway and the security processing device is referred to as "I2".
  • the private network access method may include the following steps:
  • Step S1000 the terminal with encryption capability initiates attachment or requests to establish a new session
  • the mobile network GW receives the session establishment request message from the wireless side interface.
  • the mobile network GW selects a private network gateway for the terminal according to a certain policy, and may select according to the APN or IMSI/MSISN information, but is not limited thereto.
  • the mobile network GW allocates the local tunnel information of the I1, and sends a session request packet to the private network gateway, and carries the local tunnel information of the I1.
  • the mobile network GW can also directly select the security processing device, and directly establish a tunnel between the mobile network GW and the security processing device.
  • Step S1020 The private network gateway selects a security processing device for the terminal according to a certain policy, and may select according to the APN or IMSI/MSISN information, but is not limited thereto.
  • the private network gateway allocates the local tunnel information of the I2, and sends a session request packet to the security processing device, and carries the local tunnel information of the I2.
  • Step 1030 The security processing device optionally performs identity authentication on the terminal, saves the peer tunnel information of the I2, uses the subsequent data forwarding, allocates the local tunnel information of the I2, and constructs a session establishment response message, and sends the session to the private network.
  • the gateway carries the local tunnel information of I2.
  • Step 1040 The private network gateway obtains the information of the peer tunnel of the I2 from the session response message, and saves it, and uses it for subsequent data forwarding. At this point, the I2 tunnel is established.
  • the private network gateway allocates the local tunnel information of I1, constructs a session establishment response message, and sends it to the mobile network GW to carry the local tunnel information of I1.
  • the mobile network GW obtains the peer tunnel information of the I1 from the session response message, and saves it, and uses it for subsequent data forwarding. At this point, the I1 tunnel is established.
  • the mobile network GW constructs a session setup response message on the wireless side interface.
  • the IP address in the session establishment response message on the wireless side interface may be a meaningless fixed address; thus, the terminal is successfully attached in the mobile network, and the session is completed. set up.
  • Step 1060 The terminal constructs an IP address request packet, and encrypts the packet, and sends the packet to the mobile network GW through the mobile network.
  • the IP address request packet may be DHCP (Dynamic Host Configuration Protocol).
  • the packet may also be an IKE (Internet Key Exchange) message, and the present invention is not limited.
  • the mobile terminal can also obtain an address by locally configuring the IP address, and send the address to the mobile network gateway by means of encrypted signaling. The invention is not limited thereto.
  • Step 1070 The mobile network GW receives the encrypted IP address request packet from the wireless side tunnel, re-encapsulates the tunnel information of the I1 interface, and sends the tunnel information to the private network gateway.
  • Step 1080 The private network gateway receives the encrypted IP address request packet from the I1 tunnel, and re-encapsulates the tunnel information of the I2 interface, and sends the information to the security processing device.
  • Step 1090 The security processing device receives the encrypted IP address request packet from the I2 tunnel, decrypts the packet, and forwards the packet to the IP address management unit in the private network.
  • the IP address management unit is a logical functional unit that can be combined with a security processing device, and the present invention is not limited.
  • Step 1100 The IP address management unit allocates an IP address to the terminal, and constructs an IP address response packet, and sends the response to the security processing device.
  • Step 1110 The security processing device encrypts the IP address response packet, and sends the packet to the private network gateway through the previously established tunnel.
  • Step 1120 The private network gateway receives the encrypted IP address response packet from the I2 tunnel, and re-encapsulates the tunnel information of the I1 interface, and sends the information to the mobile network GW.
  • Step 1130 The mobile network GW receives the encrypted IP address response packet from the I1 tunnel, re-encapsulates the tunnel information of the wireless side interface, and sends the information to the terminal through the mobile network.
  • the terminal receives the IP address response packet, performs decoding processing, and obtains an IP address. At this point, the terminal has the condition for accessing the service/application in the private network through the mobile network.
  • Step 1140 the terminal accesses the service/application in the private network, constructs an uplink data packet, and encrypts the packet, and sends the packet to the mobile network GW through the mobile network;
  • Step 1150 The mobile network GW receives the encrypted uplink data packet from the wireless side tunnel, re-encapsulates the tunnel information of the I1 interface, and sends the tunnel information to the private network gateway.
  • Step 1160 The private network gateway receives the encrypted uplink data packet from the I1 tunnel, and re-encapsulates the tunnel information of the I2 interface, and sends the information to the security processing device.
  • Step 1170 The security processing device receives the encrypted uplink data packet from the I2 tunnel, decrypts the packet, and forwards the packet to the service/application unit in the private network.
  • Step 1180 The application/service device in the private network processes the service request of the terminal, and constructs a downlink data packet, and sends the data packet to the security processing device.
  • Step 1190 The security processing device encrypts the downlink data packet, and sends the packet to the private network gateway through the previously established tunnel.
  • Step 1200 The private network gateway receives the encrypted downlink data packet from the I2 tunnel, and re-encapsulates the tunnel information of the I1 interface, and sends the information to the mobile network GW.
  • Step 1210 The mobile network GW receives the encrypted downlink data packet from the I1 tunnel, re-encapsulates the tunnel information of the wireless side interface, and sends the tunnel information to the terminal through the mobile network.
  • the terminal receives the downlink data packet, performs decoding processing, and acquires service/application information.
  • another embodiment of the present invention provides a security method for a mobile terminal to access a private network.
  • the LTE mobile network is taken as an example in this embodiment, the present invention is not limited to the LTE mobile network; although the address is allocated to the user by using the DHCP method as an example, the present invention is not limited to the DHCP mode allocation address; For example, the invention does not limit any services/applications.
  • the security method for the mobile terminal to access the private network may include the following steps:
  • Step S2000 the terminal with the encryption capability initiates the attachment or requests to establish a new session, and sends the NAS signaling to the MME.
  • step S2010 the MME selects an appropriate SGW and a PDN-GW (Packet Data Network Gateway) for the terminal according to the APN information carried by the NAS (Non-Access-Stratiction) signaling, and constructs The session establishment request message is sent to the SGW/PDN-GW;
  • PDN-GW Packet Data Network Gateway
  • the PDN-GW receives the session establishment request message, and saves the session/tunnel information of the SGW.
  • the private network gateway is selected according to a certain policy, and may be selected according to the APN or IMSI/MSISN information, but is not limited thereto.
  • the PGW-GW allocates the local tunnel information and sends a session establishment request to the private network gateway.
  • the TEID-C (Tunnel Endpoint Identifier-control) or TEID-U (Tunnel Endpoint Identifier-user) Endpoint ID) is the session/tunnel tag of the local end;
  • the private network gateway receives the session establishment request message, and saves the session/tunnel information of the PDN-GW.
  • the security processing device is selected for the terminal according to a certain policy, and may be selected according to the APN or IMSI/MSISN information, but is not limited thereto.
  • the private network gateway allocates the local tunnel information, and sends a session establishment request to the security processing device, which is carried.
  • TEID-C/TEID-U is the session/tunnel tag of the local end;
  • Step 2040 The security processing device optionally performs identity authentication on the terminal, saves the private network gateway tunnel information, uses the subsequent data forwarding, allocates the local tunnel information, constructs a session establishment response, and sends the response to the private network gateway.
  • TEID-C/TEID-U is the session/tunnel tag of the local end.
  • the private network gateway obtains the session/tunnel information of the security processing device from the session establishment response, and saves it, and uses the subsequent session management and data forwarding.
  • the session of the private network gateway and the security processing device and the default bearer tunnel are established.
  • the private network gateway allocates the local tunnel information, constructs a session establishment response message, and sends it to the PDN-GW.
  • the TEID-C/TEID-U carries the session/tunnel label of the local end.
  • Step 2060 The PDN-GW obtains session/tunnel information of the private gateway from the session establishment response, saves it, uses it for subsequent session management and data forwarding, and thus, the session between the PDN-GW and the private gateway and the default bearer tunnel
  • the establishment is completed; the PDN-GW constructs a session establishment response message on the S5/S8 interface, and completes the standard process inside the mobile network.
  • the IP address in the session establishment response message on the S5/S8 interface may be a meaningless fixed address;
  • step 2070 the MME responds to the service request of the terminal.
  • the terminal is successfully attached in the mobile network, or the establishment of the PDN session is completed.
  • Step 2080 The terminal constructs a DHCP signaling packet to obtain an IP address, and encrypts the packet and sends the packet to the PDN-GW through the mobile network.
  • the IP address request packet may be a DHCP packet or an IKE packet. The invention is not limited;
  • the PDN-GW receives the encrypted DHCP message, decapsulates and re-encapsulates the tunnel information between the private network gateway and sends the information to the private network gateway.
  • Step 2100 The private network gateway receives the encrypted DHCP message, decapsulates and re-encapsulates the tunnel information between the security processing device and sends the information to the security processing device.
  • Step 2110 The security processing device receives the encrypted DHCP packet, and decrypts the packet to the DHCP server in the private network.
  • Step 2120 The DHCP server allocates an IP address to the terminal, and constructs a DHCP response packet to be sent to the security processing device.
  • Step 2130 The security processing device encrypts the DHCP response packet and sends the packet to the private network gateway through the previously established tunnel.
  • Step 2140 The private network gateway receives the encrypted DHCP response message, decapsulates and re-encapsulates the tunnel information between the PDN and the GW, and sends the information to the PDN-GW.
  • Step 2150 The PDN-GW receives the encrypted DHCP response packet, decapsulates the tunnel information of the S5/S8 interface, and sends the tunnel information to the terminal through the mobile network.
  • the terminal receives the DHCP signaling response message, performs decoding processing, and obtains an IP address. At this point, the terminal has the condition for accessing the service/application in the private network through the mobile network.
  • Step 2160 the terminal accesses the web service, constructs an uplink data packet to obtain a webpage, and encrypts the packet, and sends the packet to the PDN-GW through the mobile network;
  • Step 2170 The PDN-GW receives the encrypted uplink data packet to obtain a webpage, and decapsulates the tunnel information that is re-encapsulated to the private network gateway, and sends the information to the private network gateway.
  • Step 2180 The private network gateway receives the encrypted uplink data packet to obtain the webpage, decapsulates the tunnel information that is re-encapsulated to the security processing device, and sends the information to the security processing device.
  • Step 2190 The security processing device receives the encrypted uplink data packet to obtain a webpage, decrypts the packet, and forwards the packet to the Web server in the private network.
  • Step 2200 The Web server in the private network processes the service request of the terminal, and constructs a downlink data packet http 200ok to respond to the user request, and sends the request to the security processing device.
  • Step 2210 The security processing device encrypts the response of the downlink data packet webpage request, and sends the response to the private network gateway through the previously established tunnel.
  • Step 2220 The private network gateway receives the encrypted downlink data packet request response, decapsulates the tunnel information that is re-encapsulated to the PDN-GW, and sends the information to the PDN-GW.
  • the PDN-GW receives the encrypted downlink data packet request response, decapsulates the tunnel information of the S5/S8 interface, and sends the information to the terminal through the mobile network.
  • the terminal receives the downlink data packet webpage request response, performs decryption processing, and acquires the web service information.
  • an embodiment of the present invention further provides a private network access device 6, including:
  • the establishing unit 61 is configured to establish a forwarding tunnel between the mobile terminal and the corresponding private network according to the session establishment request of the mobile terminal;
  • the signaling forwarding unit 62 is configured to forward, by using the forwarding tunnel established by the establishing unit, the encryption signaling between the mobile terminal and the corresponding private network, so that the mobile terminal acquires the Corresponding to the IP address assigned by the private network to the mobile terminal;
  • the data forwarding unit 63 is configured to forward, by using the forwarding tunnel, communication data between the mobile terminal and the corresponding private network in the form of encrypted data.
  • the private network access device 6 provided by the embodiment of the present invention can establish a forwarding tunnel between the mobile terminal and the corresponding private network according to the session establishment request of the mobile terminal, and the signaling forwarding unit 62 can perform the forwarding The tunnel forwards the encrypted signaling between the mobile terminal and the corresponding private network, so that the mobile terminal obtains the IP address allocated by the corresponding private network for the mobile terminal by using the encrypted signaling, and the data forwarding unit 63.
  • the communication data between the mobile terminal and the corresponding private network can be forwarded through the forwarding tunnel in the form of encrypted data.
  • the mobile terminal can access the corresponding private network without using a separate mobile network, thereby facilitating the user and ensuring the private network and The security of its application access.
  • the establishing unit 61 may specifically include:
  • a searching module configured to search for a corresponding private network of the mobile terminal according to the session establishment request
  • a sending module configured to send a tunnel establishment request message to the corresponding private network, where the tunnel establishment request message carries the identification information of the mobile terminal;
  • a receiving module configured to receive a tunnel establishment response message from the corresponding private network
  • the sending module is further configured to forward the tunnel establishment response message to the mobile terminal.
  • the sending module is specifically configured to: directly send a tunnel establishment request message to the security processing device of the corresponding private network, or send the gateway to the security processing device of the corresponding private network by using the gateway of the corresponding private network Tunnel establishment request message.
  • an embodiment of the present invention further provides a private network access device 7, which may include:
  • the private network establishing unit 71 establishes a forwarding tunnel with the mobile terminal by using the mobile network gateway according to the request of the mobile network gateway;
  • An address allocation unit 72 configured to allocate an IP address to the mobile terminal, and send the IP address to the mobile terminal by using the forwarding tunnel in an encrypted signaling manner;
  • the communication unit 73 is configured to communicate with the mobile terminal through the forwarding tunnel in the form of encrypted data.
  • the private network establishing unit 71 can establish a forwarding tunnel with the mobile terminal through the mobile network gateway according to the request of the mobile network gateway, and the address allocating unit 72 can be the The mobile terminal allocates an IP address, and transmits the IP address to the mobile terminal through the forwarding tunnel in the form of encrypted signaling, and the communication unit 73 can communicate with the mobile terminal through the forwarding tunnel in the form of encrypted data. .
  • the mobile terminal since the process of acquiring the IP address by the mobile terminal and the data transmission process with the private network are encrypted, the mobile terminal can access the corresponding private network without using a separate mobile network, thereby facilitating the user and ensuring the private network and The security of its application access.
  • the private network access device 7 may further include an authentication unit, configured to establish, by the mobile network gateway, a forwarding tunnel with the mobile terminal according to a request of the mobile network gateway.
  • the private network establishing unit 71 is configured to establish, by the mobile network gateway, the mobile network gateway according to the request of the mobile network gateway, if the authentication unit passes the authentication. The forwarding tunnel of the mobile terminal.
  • the private network establishing unit 71 is specifically configured to:
  • an embodiment of the present invention further provides a private network access device 8, which includes:
  • a terminal establishing unit 81 configured to initiate a session establishment request to the mobile network gateway, to establish a forwarding tunnel between the mobile terminal and the corresponding private network by using the mobile network gateway;
  • the address requesting unit 82 is configured to request an IP address from the mobile network gateway to the corresponding private network by using an encrypted signaling manner;
  • the terminal communication unit 83 is configured to communicate with the corresponding private network through the forwarding tunnel in the form of encrypted data.
  • the terminal establishing unit 81 can initiate a session establishment request to the mobile network gateway to establish a forwarding tunnel between the mobile terminal and the corresponding private network through the mobile network gateway, and the address Request The unit 82 can request an IP address from the mobile network gateway to the corresponding private network by using the mobile network gateway, and the terminal communication unit 83 can communicate with the corresponding private network through the forwarding tunnel in the form of encrypted data.
  • the mobile terminal since the process of acquiring the IP address by the mobile terminal and the data transmission process with the private network are encrypted, the mobile terminal can access the corresponding private network without using a separate mobile network, thereby facilitating the user and ensuring the private network and The security of its application access.
  • the embodiment of the present invention further provides a mobile network gateway, where the private network gateway is provided with any of the private network access devices 6 provided in the foregoing embodiments, so that the corresponding beneficial effects can also be achieved.
  • the corresponding description is not repeated here.
  • the embodiment of the present invention further provides a private network device, where the private network access device 7 provided in the foregoing embodiment is provided, so that the corresponding beneficial effects can also be achieved.
  • the corresponding description is not repeated here.
  • an embodiment of the present invention further provides a mobile terminal, where the private network access device 8 provided by the foregoing embodiment is provided, so that corresponding beneficial effects can also be achieved, and the foregoing has been performed accordingly. Description, no more details here.
  • the embodiment of the present invention further provides a private network access system, including any one of the mobile network gateways provided by the foregoing embodiments, any private network device, and any mobile terminal.
  • the private network access system may include a mobile terminal 100, a wireless access network 200, a mobile network GW 300, a private network gateway 400, and a private network security processing device 500. , private network application / service equipment 600.
  • the mobile terminal 100 attaches or requests to establish a new session, it does not need to obtain an IP address; after the connection is successful or the session is established, the IP address is obtained from the private network through separate signaling, and the signaling for obtaining the IP address is encrypted.
  • the information is protected; when the data is sent, the content of the data message and the IP information are encrypted by using an encryption algorithm; when the data is received, the data message is decrypted to obtain the original data information.
  • the wireless access network 200 may be a GPRS (General Packet Radio Service) network and a SGSN (Serving GPRS Support Node) network element; it may be an LTE (Long Term Evolution) network. And a SGW (Serving GateWay) network element; or an eHRPD (Evolved High Rate Package Data) network and an HSGW (HRPD Serving GateWay) network element, including everything that can be connected Access to the mobile network GW (GateWay, gateway).
  • a mobility management unit of the access network such as an MME (Mobility Management Entity) in an LTE (Long Term Evolution) network, selects a suitable mobile network GW according to APN information or IMSI/MSISDN information of the terminal. ;
  • the mobile network GW300 that is, the mobile network gateway, when receiving the session establishment request, is different from the prior art in that it does not allocate an address for the user, but selects a suitable private network gateway for the user, and can be based on the APN information or the terminal IMSI/MSISDN information. And initiating a tunnel establishment request to the selected private network gateway to establish a forwarding tunnel for signaling and data packets between the terminal and the private network.
  • the private network gateway 400 when receiving the request for establishing a tunnel by the mobile network GW, selects a suitable private network security processing device for the user, and may according to the APN information or the terminal IMSI/MSISDN information, or according to the load condition of the security processing device; A tunnel establishment request is initiated to the selected security processing device to establish a forwarding tunnel for signaling and data packets between the terminal and the private network.
  • the private network gateway 400 is an optional unit, and the mobile network GW300 can also directly select a private network security processing device and establish a tunnel with the user.
  • the security processing device 500 may be responsible for allocating an IP address to the terminal; or an IP address allocation unit may be deployed after the security processing device of the private network, and is responsible for assigning an IP address to the terminal.
  • the security processing device sends signaling and data packets to the central terminal, the encryption algorithm is used to encrypt the content and IP information of the data packet.
  • the data packet is decrypted to obtain the original data information, and the data is forwarded to the special data.
  • Application/service devices in the network may be responsible for allocating an IP address to the terminal; or an IP address allocation unit may be deployed after the security processing device of the private network, and is responsible for assigning an IP address to the terminal.
  • the above-described units or steps of the present invention may be implemented by a general-purpose computing device, which may be centralized on a single computing device or distributed over a network of multiple computing devices. Alternatively, they may Implemented by program code executable by the computing device, such that they can be stored in a storage device for execution by the computing device, and in some cases, the steps shown or described can be performed in a different order than the ones described herein. Alternatively, they may be fabricated into individual integrated circuit modules, or a plurality of modules or steps thereof may be fabricated into a single integrated circuit module. Thus, the invention is not limited to any specific combination of hardware and software.
  • the invention is applicable to the field of communication technology, and can realize that the mobile terminal can access the corresponding private network without using an independent mobile network, which is convenient for the user and ensures the security of the access of the private network and its application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开一种专网接入方法、装置及系统,涉及通信技术领域,用以解决现有技术中移动终端接入专网不便或者不安全的问题。所述方法包括:移动网网关根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道;所述移动网网关通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址;所述移动网网关以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。

Description

一种专网接入方法、装置及系统 技术领域
本发明涉及通信技术领域,特别是涉及一种专网接入方法、装置及系统。
背景技术
一般的,安全性要求很高的网络,例如公安、军队网络系统等,由于应用环境的特殊性,都是通过建立专网将用户及内部服务器等和其他的计算机网络系统隔离开来,确保网络的高度安全。
专网中的用户接入位置及接入设备固定,安全容易得到保障。但是终端的位置固定,也带来了使用的诸多不便。随着移动宽带的快速发展以及移动终端的智能化,如果专网用户能使用移动终端通过移动网络接入专网,则会带来极大的便利,例如公安干警办案或者出差途中,需要及时查询内部网络中的重要资料等,如果能使用移动终端访问专网则会带来便利。
为保证专网的高度安全,按照已有隔离网络的思路,需要建立独立的移动网络接入专网,这极大的增加了投入成本。如果通过普通的移动网络接入,又对专网及其内部应用系统引入了安全风险。
发明内容
本发明要解决的技术问题是提供一种专网接入方法、装置及系统,用以解决现有技术中移动终端接入专网不便或者不安全的问题。
一方面,本发明提供一种专网接入方法,包括:移动网网关根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道;所述移动网网关通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP(Internet Protocol,网间互联协议)地址;所述移动网网关以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。
可选的,所述移动网网关根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道包括:所述移动网网关根据所述会话建立请求查找到所述移动终端的对应专网;所述移动网网关向所述对应专网发送隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;所述移动网网关接收来自所述对应专网的隧道建立响应消息,并将所述隧道建立响应消息向所述移动终端转发。
可选的,所述移动网网关向所述对应专网发送隧道建立请求消息包括:所述移动网网关直接向所述对应专网的安全处理设备发送隧道建立请求消息,或者所述移动网网关通过所述对应专网的网关向所述对应专网的安全处理设备发送隧道建立请求消息。
另一方面,本发明还提供一种专网接入方法,包括:移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道;所述对应专网为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送;所述对应专网以加密数据的形式通过所述转发隧道与所述移动终端通信。
所述移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道之前,所述方法还包括:所述对应专网对所述移动终端进行鉴权,在鉴权通过的情况下,根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道。
可选的,移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道包括:所述移动终端的对应专网接收所述移动网网关的发送的隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;所述对应专网向所述移动网网关发送隧道建立响应消息,以通过所述移动网网关建立与所述移动终端的转发隧道。
另一方面,本发明还提供一种专网接入方法,包括:移动终端向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道;所述移动终端以加密信令方式通过所述移动网网关向所述对应专网请求IP地址;所述移动终端以加密数据的形式,通过所述转发隧道与所述对应专网通信。
另一方面,本发明还提供一种专网接入装置,包括:建立单元,用于根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道;信令转发单元,用于通过所述建立单元建立的转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址;数据转发单元,用于以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。
可选的,所述建立单元,包括:查找模块,用于根据所述会话建立请求查找到所述移动终端的对应专网;发送模块,用于向所述对应专网发送隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;接收模块,用于接收来自所述对应专网的隧道建立响应消息;所述发送模块,还用于将所述隧道建立响应消息向所述移动终端转发。
可选的,所述发送模块,具体用于:直接向所述对应专网的安全处理设备发送隧道建立请求消息,或者通过所述对应专网的网关向所述对应专网的安全处理设备发送隧道建立请求消息。
另一方面,本发明还提供一种专网接入装置,包括:专网建立单元,根据移动网网关的请求,通过所述移动网网关建立与移动终端的转发隧道;地址分配单元,用于为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送;通信单元,用于以加密数据的形式通过所述转发隧道与所述移动终端通信。
所述装置还包括鉴权单元,用于在根据移动网网关的请求,通过所述移动网网关建立 与所述移动终端的转发隧道之前,对所述移动终端进行鉴权;所述专网建立单元,具体用于在所述鉴权单元鉴权通过的情况下,根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道。
可选的,所述专网建立单元,具体用于:接收所述移动网网关的发送的隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;向所述移动网网关发送隧道建立响应消息,以通过所述移动网网关建立与所述移动终端的转发隧道。
另一方面,本发明还提供一种专网接入装置,包括:终端建立单元,用于向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道;地址请求单元,用于以加密信令方式通过所述移动网网关向所述对应专网请求IP地址;终端通信单元,用于以加密数据的形式,通过所述转发隧道与所述对应专网通信。
另一方面,本发明还提供一种移动网网关,包括本发明提供的任一种相应的专网接入装置。
另一方面,本发明还提供一种专网设备,包括本发明提供的任一种相应的专网接入装置。
另一方面,本发明还提供一种移动终端,包括本发明提供的任一种相应的专网接入装置。
另一方面,本发明还提供一种专网接入系统,包括本发明提供的任一种移动网网关,专网设备,以及移动终端。
本发明实施例提供的专网接入方法、装置及系统,移动网网关能够根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道,并通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址,然后以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。这样,由于移动终端获取IP地址的过程和与专网的数据传输过程都进行了加密,移动终端无需借助独立的移动网络即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。
附图说明
图1是本发明实施例提供的专网接入方法的一种流程图;
图2是本发明实施例提供的专网接入方法的另一种流程图;
图3是本发明实施例提供的专网接入方法的又一种流程图;
图4是本发明实施例提供的专网接入方法的一种详细流程图;
图5是本发明实施例提供的专网接入方法的另一种详细流程图;
图6是本发明实施例提供的专网接入装置的一种结构示意图;
图7是本发明实施例提供的专网接入装置的另一种结构示意图;
图8是本发明实施例提供的专网接入装置的又一种结构示意图;
图9是本发明实施例提供的专网接入系统的一种结构示意图。
具体实施方式
以下结合附图对本发明进行详细说明。应当理解,此处所描述的具体实施例仅仅用以解释本发明,并不限定本发明。
如图1所示,本发明实施例提供一种专网接入方法,包括:
S11,移动网网关根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道;
S12,所述移动网网关通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址;
S13,所述移动网网关以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。
本发明实施例提供的专网接入方法,移动网网关能够根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道,并通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址,然后以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。这样,由于移动终端获取IP地址的过程和与专网的数据传输过程都进行了加密,移动终端无需借助独立的移动网络即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。
当移动终端需要与专网进行连接通信时,首先会发起会话建立请求,包括发起附着或者请求建立新会话。该会话建立请求经过无线侧网元的处理和传输可以传送到移动网网关。例如,移动终端可以向MME(Mobil management entity,移动管理实体)发送NAS信令,MME可根据NAS(Non-Access-Stratum,非接入层)信令携带的APN(Access PointName,接入点名称)信息等,为终端选择合适的SGW和PDN-GW(Packet Data NetworkGateway,分组数据网络网关),并构造会话建立请求消息发送给SGW/PDN-GW。
在步骤S11中,移动网网关即可根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道。可选的,建立移动终端与对应专网之间的转发隧道可包括如下步骤:
移动网网关根据所述会话建立请求查找到所述移动终端的对应专网;
移动网网关向所述对应专网发送隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
移动网网关接收来自所述对应专网的隧道建立响应消息,并将所述隧道建立响应消息向所述移动终端转发。
也就是说,移动网网关接收到会话建立请求消息后,可以保存相应的会话/隧道信息, 然后按照一定的策略为该移动终端选择相应的专网网关。例如,移动终端一般是单位内部特制的,用于该单位内部的专用网络,因此,移动网网关可以根据接收到的会话请求消息中携带的该移动终端的身份标识信息等,来识别该移动终端属于哪个专网,或者与哪个专网相对应。可选的,这些身份标识信息可以是APN信息,也可以是IMSI(International Mobile Subscriber Identification Number,国际移动用户识别码)/MSISDN(Mobile Subscriber International ISDN/PSTN number,移动用户号码)信息,还可以是其他能够体现移动终端身份的标号或代码等,本发明的实施例对此不限。
查找到移动终端的对应专网后,移动网网关即可向所述对应专网发送隧道建立请求消息,并在该隧道建立请求消息中携带所述移动终端的标识信息。可选的,本步骤中,移动网网关既可以直接向所述对应专网的安全处理设备发送隧道建立请求消息,也可以通过所述对应专网的网关向所述对应专网的安全处理设备发送隧道建立请求消息,以便使对应专网的安全处理设备对相应的隧道连接进行安全方面的处理。
建立好转发隧道后,在步骤S12中,移动网网关可以通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址。
相应的,如图2所示,本发明的实施例还提供一种专网接入方法,包括:
S21,移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道;
S22,所述对应专网为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送;
S23,所述对应专网以加密数据的形式通过所述转发隧道与所述移动终端通信。
本发明实施例提供的专网接入方法,移动终端的对应专网能够根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道,为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送,然后以加密数据的形式通过所述转发隧道与所述移动终端通信。这样,由于移动终端获取IP地址的过程和与专网的数据传输过程都进行了加密,移动终端无需借助独立的移动网络即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。
可选的,对应专网中可以设置有多个网元,其中,与专网安全处理相关的为安全处理设备。具体使用哪个安全处理设备来为该移动终端服务,可以根据具体情况进行不同选择。例如,既可以由移动网网关直接为移动终端选择为其服务的安全管理设备,也可以由移动网网关先与专网网关通信,由专网网关为该移动终端选择相应的安全处理设备。本发明的实施例对此不限。
可选的,选择安全处理设备的策略可以包括多种,例如可以根据APN或者IMSI/MSISN信息选择,也可以根据各安全处理设备的负载情况进行选择,本发明的实施例对此不限。
具体而言,移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道可包括如下步骤:
所述移动终端的对应专网接收所述移动网网关的发送的隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
所述对应专网向所述移动网网关发送隧道建立响应消息,以通过所述移动网网关建立与所述移动终端的转发隧道。
为了进一步提高移动终端接入专网的安全性,进一步的,在本发明的一个实施例中,在移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道之前,还可包括:
所述对应专网对所述移动终端进行鉴权,在鉴权通过的情况下,根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道。例如,对应专网可以要求移动终端的用户输入密码或进行指纹识别等来对移动终端进行鉴权,如果鉴权通过,则通过移动网网关与移动终端建立转发隧道,否则,不建立该转发隧道。
相应的,如图3所示,本发明的实施例还提供一种专网接入方法,包括:
S31,移动终端向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道;
S32,所述移动终端以加密信令方式通过所述移动网网关向所述对应专网请求IP地址;
S33,所述移动终端以加密数据的形式,通过所述转发隧道与所述对应专网通信。
本发明实施例提供的专网接入方法,移动终端能够向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道,并以加密信令方式通过所述移动网网关向所述对应专网请求IP地址,然后以加密数据的形式,通过所述转发隧道与所述对应专网通信。这样,由于移动终端获取IP地址的过程和与专网的数据传输过程都进行了加密,移动终端无需借助独立的移动网络即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。
下面通过具体实施例来对本发明提供的专网接入方法进行详细说明。
图4是本申请实施方式提供的专网接入方法的一种流程图。为了描述方便,将移动网GW和专网网关之间的接口称之为“I1”;专网网关和安全处理设备之间的接口称之为“I2”。如图4所示,本实施例中,专网接入方法可包括如下步骤:
步骤S1000,具有加密能力的终端发起附着或者请求建立新会话;
步骤S1010,移动网GW从无线侧接口接收到会话建立请求消息。移动网GW按照一定的策略为终端选择专网网关,可以根据APN或者IMSI/MSISN信息选择,但不限于此。移动网GW分配I1的本端隧道信息,向专网网关发送会话请求报文,携带I1的本端隧道信息;
可选的,此步骤,移动网GW也可以直接选择安全处理设备,移动网GW和安全处理设备之间直接建立隧道。
步骤S1020,专网网关按照一定的策略为终端选择安全处理设备,可以根据APN或者IMSI/MSISN信息选择,但不限于此。专网网关分配I2的本端隧道信息,向安全处理设备发送会话请求报文,携带I2的本端隧道信息;
步骤1030,安全处理设备可选的对终端进行身份认证等,保存I2的对端隧道信息,后续数据转发时使用,同时分配I2的本端隧道信息,并构造会话建立响应消息,发送给专网网关,携带I2的本端隧道信息。
步骤1040,专网网关从会话响应消息中获取到I2的对端隧道信息,保存之,后续数据转发时使用。至此,I2隧道建立完成。专网网关分配I1的本端隧道信息,构造会话建立响应消息,发送给移动网GW,携带I1的本端隧道信息。
步骤1050,移动网GW从会话响应消息中获取到I1的对端隧道信息,保存之,后续数据转发时使用。至此,I1隧道建立完成。移动网GW构造无线侧接口上的会话建立响应消息。为避免移动网现有设备的改造,可选的,无线侧接口上的会话建立响应消息中的IP地址可为一个无意义的固定地址;至此,终端在移动网中附着成功,完成了会话的建立。
步骤1060,终端构造IP地址请求报文,并对报文进行加密处理,通过移动网发送给移动网GW;IP地址请求报文可选的可以是DHCP(Dynamic Host Configuration Protocol,动态主机配置协议)报文也可以IKE(Internet Key Exchange,因特网密钥交换协议)报文,本发明不限制。可选的,移动终端也可以通过本地配置IP的方式获取地址,并将该地址以加密信令的方式发送给移动网网关。本发明对此不作限制。
步骤1070,移动网GW从无线侧隧道中接收到加密后的IP地址请求报文,重新封装I1接口的隧道信息,发送给专网网关;
步骤1080,专网网关从I1隧道中接收到加密后的IP地址请求报文,重新封装I2接口的隧道信息,发送给安全处理设备;
步骤1090,安全处理设备从I2隧道中接收到加密后的IP地址请求报文,对其进行解密处理,将报文转发给专网中的IP地址管理单元;
说明:IP地址管理单元是一个逻辑功能单元,可以和安全处理设备合设,本发明不限制。
步骤1100,IP地址管理单元为终端分配IP地址,并构造IP地址响应报文,发送给安全处理设备;
步骤1110,安全处理设备对IP地址响应报文进行加密处理,并通过之前建立的隧道发送给专网网关;
步骤1120,专网网关从I2隧道中接收到加密后的IP地址响应报文,重新封装I1接口的隧道信息,发送给移动网GW;
步骤1130,移动网GW从I1隧道中接收到加密后的IP地址响应报文,重新封装无线侧接口的隧道信息,通过移动网络发送给终端。终端接收到IP地址响应报文,进行解码处理,获取IP地址,至此,终端就具有了通过移动网络访问专网中服务/应用的条件。
步骤1140,终端访问专网中服务/应用,构造上行数据报文,并对报文进行加密处理,通过移动网发送给移动网GW;
步骤1150,移动网GW从无线侧隧道中接收到加密后的上行数据报文,重新封装I1接口的隧道信息,发送给专网网关;
步骤1160,专网网关从I1隧道中接收到加密后的上行数据报文,重新封装I2接口的隧道信息,发送给安全处理设备;
步骤1170,安全处理设备从I2隧道中接收到加密后的上行数据报文,对其进行解密处理,将报文转发给专网中的服务/应用单元;
步骤1180,专网中的应用/服务设备处理终端的业务请求,并构造下行数据报文,发送给安全处理设备;
步骤1190,安全处理设备对下行数据报文进行加密处理,并通过之前建立的隧道发送给专网网关;
步骤1200,专网网关从I2隧道中接收到加密后的下行数据报文,重新封装I1接口的隧道信息,发送给移动网GW;
步骤1210,移动网GW从I1隧道中接收到加密后的下行数据报文,重新封装无线侧接口的隧道信息,通过移动网络发送给终端。终端接收到下行数据报文,进行解码处理,获取服务/应用信息。
如图5所示,本发明的另一个实施例提供了一种移动终端接入专网的安全方法。需要说明的是,虽然本实施例以LTE移动网为例,但本发明不限于LTE移动网;虽然以DHCP方式为用户分配地址为例,但本发明不限于DHCP方式分配地址;虽然以Web服务为例,但本发明不限制任何服务/应用。如图5所示,本实施例中,移动终端接入专网的安全方法可包括如下步骤:
步骤S2000,具有加密能力的终端发起附着或者请求建立新会话,向MME发送NAS信令;
步骤S2010,MME根据NAS(Non-Access-Stratum,非接入层)信令携带的APN信息等,为终端选择合适的SGW和PDN-GW(Packet Data Network Gateway,分组数据网络网关),并构造会话建立请求消息发送给SGW/PDN-GW;
步骤S2020,PDN-GW接收到会话建立请求消息,保存SGW的会话/隧道信息;按照一定的策略为终端选择专网网关,可以根据APN或者IMSI/MSISN信息选择,但不限于此。PGW-GW分配本端隧道信息,向专网网关发送会话建立请求,携带的TEID-C(Tunnel Endpoint Identifier-control,控制面隧道端点标识)/TEID-U(Tunnel Endpoint Identifier-user,用户面隧道端点标识)是本端的会话/隧道标记;
步骤S2030,专网网关接收到会话建立请求消息,保存PDN-GW的会话/隧道信息;按照一定的策略为终端选择安全处理设备,可以根据APN或者IMSI/MSISN信息选择,但不限于此。专网网关分配本端隧道信息,向安全处理设备发送会话建立请求,携带的 TEID-C/TEID-U是本端的会话/隧道标记;
步骤2040,安全处理设备可选的对终端进行身份认证等,保存专网网关隧道信息,后续数据转发时使用,同时分配本端隧道信息,并构造会话建立响应,发送给专网网关,携带的TEID-C/TEID-U是本端的会话/隧道标记。
步骤2050,专网网关从会话建立响应中获取安全处理设备的会话/隧道信息,保存之,后续会话管理及数据转发时使用,至此,专网网关和安全处理设备的会话及默认承载隧道建立完成;专网网关分配本端隧道信息,构造会话建立响应消息,发送给PDN-GW,携带TEID-C/TEID-U是本端的会话/隧道标记。
步骤2060,PDN-GW从会话建立响应中获取专有网关的会话/隧道信息,保存之,后续会话管理及数据转发时使用,至此,PDN-GW和专有网关之间的会话及默认承载隧道建立完成;PDN-GW构造S5/S8接口上的会话建立响应消息,完成移动网内部的标准流程。为避免移动网现有设备的改造,可选的,S5/S8接口上的会话建立响应消息中的IP地址可为一个无意义的固定地址;
步骤2070,MME响应终端的业务请求。至此,终端在移动网中附着成功,或者完成了PDN会话的建立。
步骤2080,终端构造DHCP信令报文以获取IP地址,对报文进行加密处理后通过移动网发送给PDN-GW;IP地址请求报文可选可以是DHCP报文,也可以IKE报文,本发明不限制;
步骤2090,PDN-GW接收到加密后的DHCP报文,解封转后重新封装和专网网关之间的隧道信息,发送给专网网关;
步骤2100,专网网关接收到加密后的DHCP报文,解封装后重新封装和安全处理设备之间的隧道信息,发送给安全处理设备;
步骤2110,安全处理设备接收到加密后的DHCP报文,解密后将报文转发给专网中的DHCP Server;
步骤2120,DHCP Server为终端分配IP地址,并构造DHCP响应报文,发送给安全处理设备;
步骤2130,安全处理设备对DHCP响应报文进行加密处理,并通过之前建立的隧道发送给专网网关;
步骤2140,专网网关接收到加密后的DHCP响应报文,解封装后重新封装和PDN-GW之间的隧道信息,发送给PDN-GW;
步骤2150,PDN-GW接收到加密后的DHCP响应报文,解封装后重新封装S5/S8接口的隧道信息,通过移动网络发送给终端。终端接收到DHCP信令响应报文,进行解码处理,获取IP地址,至此,终端就具有了通过移动网络访问专网中服务/应用的条件。
步骤2160,终端访问web业务,构造上行数据报文获取网页,并对报文进行加密处理,通过移动网发送给PDN-GW;
步骤2170,PDN-GW接收到加密后的上行数据报文获取网页,解封装后重新封装到专网网关的隧道信息,发送给专网网关;
步骤2180,专网网关接收到加密后的上行数据报文获取网页,解封装后重新封装到安全处理设备的隧道信息,发送给安全处理设备;
步骤2190,安全处理设备接收到加密后的上行数据报文获取网页,对其进行解密处理,将报文转发给专网中Web Server;
步骤2200,专网中的Web Server处理终端的业务请求,并构造下行数据报文http 200ok响应用户请求,发送给安全处理设备;
步骤2210,安全处理设备对下行数据报文网页请求响应进行加密处理,并通过之前建立的隧道发送给专网网关;
步骤2220,专网网关接收到加密后的下行数据报文网页请求响应,解封装后重新封装到PDN-GW的隧道信息,发送给PDN-GW;
步骤2230,PDN-GW接收到加密后的下行数据报文网页请求响应,解封装后重新封装S5/S8接口的隧道信息,通过移动网络发送给终端。终端接收到下行数据报文网页请求响应,进行解密处理,获取Web服务信息。
相应的,如图6所示,本发明的实施例还提供一种专网接入装置6,包括:
建立单元61,用于根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道;
信令转发单元62,用于通过所述建立单元建立的转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址;
数据转发单元63,用于以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。
本发明实施例提供的专网接入装置6,建立单元61能够根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道,信令转发单元62能够通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址,数据转发单元63能够以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。这样,由于移动终端获取IP地址的过程和与专网的数据传输过程都进行了加密,移动终端无需借助独立的移动网络即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。
可选的,建立单元61,具体可包括:
查找模块,用于根据所述会话建立请求查找到所述移动终端的对应专网;
发送模块,用于向所述对应专网发送隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
接收模块,用于接收来自所述对应专网的隧道建立响应消息;
所述发送模块,还用于将所述隧道建立响应消息向所述移动终端转发。
可选的,所述发送模块,具体可用于:直接向所述对应专网的安全处理设备发送隧道建立请求消息,或者通过所述对应专网的网关向所述对应专网的安全处理设备发送隧道建立请求消息。
相应的,如图7所示,本发明的实施例还提供一种专网接入装置7,可包括:
专网建立单元71,根据移动网网关的请求,通过所述移动网网关建立与移动终端的转发隧道;
地址分配单元72,用于为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送;
通信单元73,用于以加密数据的形式通过所述转发隧道与所述移动终端通信。
本发明实施例提供的专网接入装置7,专网建立单元71能够根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道,地址分配单元72能够为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送,通信单元73能够以加密数据的形式通过所述转发隧道与所述移动终端通信。这样,由于移动终端获取IP地址的过程和与专网的数据传输过程都进行了加密,移动终端无需借助独立的移动网络即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。
进一步的,在本发明的一个实施例中,专网接入装置7还可包括鉴权单元,用于在根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道之前,对所述移动终端进行鉴权;专网建立单元71,具体用于在所述鉴权单元鉴权通过的情况下,根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道。
可选的,专网建立单元71,具体可用于:
接收所述移动网网关的发送的隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
向所述移动网网关发送隧道建立响应消息,以通过所述移动网网关建立与所述移动终端的转发隧道。
相应的,如图8所示,本发明的实施例还提供一种专网接入装置8,包括:
终端建立单元81,用于向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道;
地址请求单元82,用于以加密信令方式通过所述移动网网关向所述对应专网请求IP地址;
终端通信单元83,用于以加密数据的形式,通过所述转发隧道与所述对应专网通信。
本发明实施例提供的专网接入装置8,终端建立单元81能够向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道,地址请求 单元82能够以加密信令方式通过所述移动网网关向所述对应专网请求IP地址,终端通信单元83能够以加密数据的形式,通过所述转发隧道与所述对应专网通信。这样,由于移动终端获取IP地址的过程和与专网的数据传输过程都进行了加密,移动终端无需借助独立的移动网络即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。
相应的,本发明的实施例还提供一种移动网网关,该移动网网关中设置有前述实施例提供的任一种专网接入装置6,因此也能实现相应的有益效果,前文已经进行了相应说明,此处不再赘述。
相应的,本发明的实施例还提供一种专网设备,该专网设备中设置有前述实施例提供的任一种专网接入装置7,因此也能实现相应的有益效果,前文已经进行了相应说明,此处不再赘述。
相应的,本发明的实施例还提供一种移动终端,该移动终端中设置有前述实施例提供的任一种专网接入装置8,因此也能实现相应的有益效果,前文已经进行了相应说明,此处不再赘述。
相应的,本发明的实施例还提供一种专网接入系统,包括上述实施例提供的任一种移动网网关,任一种专网设备,以及任一种移动终端。
举例说明,如图9所示,在本发明的一个实施例中,专网接入系统可包括移动终端100、无线接入网络200、移动网GW300、专网网关400、专网安全处理设备500、专网应用/服务设备600。
具体的,移动终端100附着或者请求建立新会话时,不需要获取IP地址;附着成功或者会话建立完成后,通过单独的信令从专网中获取IP地址,获取IP地址的信令通过加密处理对信息进行保护;发送数据时使用加密算法对数据报文的内容及IP信息进行加密;接收数据时,对数据报文进行解密操作获取原始数据信息。
无线接入网络200,可以是GPRS(General Packet Radio Service,通用分组无线服务技术)网络及SGSN(Serving GPRS Support Node,服务GPRS支持节点)网元;可以是LTE(Long Term Evolution,长期演进)网络及SGW(Serving GateWay,服务网关)网元;也可以是eHRPD(Evolved High Rate Package Data,演进的高速分组网络)网路及HSGW(HRPD Serving GateWay,HRPD服务网关)网元等,包括一切可以接入到移动网GW(GateWay,网关)的接入方式。接入网络的移动管理单元,例如LTE(Long Term Evolution,长期演进)网络中的MME(Mobility Management Entity,移动管理实体),根据APN信息或者是终端的IMSI/MSISDN信息等选择合适的移动网GW;
移动网GW300,即移动网网关,接收到会话建立请求时,区别于现有技术,不为用户分配地址,而是为用户选择合适的专网网关,可以根据APN信息或者终端IMSI/MSISDN信息等;并向所选专网网关发起隧道建立请求,为终端和专网之间的信令及数据报文建立转发隧道。
专网网关400,接收到移动网GW建立隧道的请求时,为用户选择合适的专网安全处理设备,可以根据APN信息或者终端IMSI/MSISDN信息,也可以根据安全处理设备的负荷情况等;并向所选安全处理设备发起隧道建立请求,为终端和专网之间的信令及数据报文建立转发隧道。
其中,专网网关400为可选单元,移动网GW300也可以直接选择专网安全处理设备,并且与之为用户建立隧道。
安全处理设备500,作为专网的安全门户,可以负责为终端分配IP地址;也可以在专网的安全处理设备之后部署IP地址分配单元,负责为终端分配IP地址。安全处理设备在向中终端发送信令及数据报文时,使用加密算法对数据报文的内容及IP信息进行加密,接收数据时,对数据报文进行解密操作获取原始数据信息,转发至专网中的应用/服务设备。
从上面的实施例,本领域的技术人员应该明白,终端访问专网的所有信息及IP地址在移动网络中是无法识别,从而保证了专网信息的安全性。另外,上述的本发明的各单元或各步骤可以用通用的计算装置来实现,它们可以集中在单个的计算装置上,或者分布在多个计算装置所组成的网络上,可选地,它们可以用计算装置可执行的程序代码来实现,从而,可以将它们存储在存储装置中由计算装置来执行,并且在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤,或者将它们分别制作成各个集成电路模块,或者将它们中的多个模块或步骤制作成单个集成电路模块来实现。这样,本发明不限制于任何特定的硬件和软件结合。
尽管为示例目的,已经公开了本发明的优选实施例,本领域的技术人员将意识到各种改进、增加和取代也是可能的,因此,本发明的范围应当不限于上述实施例。
工业实用性
本发明适用于通信技术领域,用以实现在无需借助独立的移动网络的情况下,移动终端即可接入相应的专用网络,方便用户的同时又保障了专网及其应用访问的安全性。

Claims (18)

  1. 一种专网接入方法,包括:
    移动网网关根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道;
    所述移动网网关通过所述转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址;
    所述移动网网关以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。
  2. 根据权利要求1所述的方法,其中所述移动网网关根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道包括:
    所述移动网网关根据所述会话建立请求查找到所述移动终端的对应专网;
    所述移动网网关向所述对应专网发送隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
    所述移动网网关接收来自所述对应专网的隧道建立响应消息,并将所述隧道建立响应消息向所述移动终端转发。
  3. 根据权利要求2所述的方法,其中所述移动网网关向所述对应专网发送隧道建立请求消息包括:
    所述移动网网关直接向所述对应专网的安全处理设备发送隧道建立请求消息,或者
    所述移动网网关通过所述对应专网的网关向所述对应专网的安全处理设备发送隧道建立请求消息。
  4. 一种专网接入方法,包括:
    移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道;
    所述对应专网为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送;
    所述对应专网以加密数据的形式通过所述转发隧道与所述移动终端通信。
  5. 根据权利要求4所述的方法,其中所述移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道之前,所述方法还包括:
    所述对应专网对所述移动终端进行鉴权,在鉴权通过的情况下,根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道。
  6. 根据权利要求4或5所述的方法,其中移动终端的对应专网根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道包括:
    所述移动终端的对应专网接收所述移动网网关的发送的隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
    所述对应专网向所述移动网网关发送隧道建立响应消息,以通过所述移动网网关建立与所述移动终端的转发隧道。
  7. 一种专网接入方法,包括:
    移动终端向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道;
    所述移动终端以加密信令方式通过所述移动网网关向所述对应专网请求IP地址;
    所述移动终端以加密数据的形式,通过所述转发隧道与所述对应专网通信。
  8. 一种专网接入装置,包括:
    建立单元,设置为根据移动终端的会话建立请求,建立所述移动终端与对应专网之间的转发隧道;
    信令转发单元,设置为通过所述建立单元建立的转发隧道在所述移动终端与所述对应专网之间转发加密信令,以使所述移动终端通过所述加密信令获取所述对应专网为所述移动终端分配的IP地址;
    数据转发单元,设置为以加密数据的形式,通过所述转发隧道转发所述移动终端与所述对应专网之间的通信数据。
  9. 根据权利要求8所述的装置,其中所述建立单元,包括:
    查找模块,设置为根据所述会话建立请求查找到所述移动终端的对应专网;
    发送模块,设置为向所述对应专网发送隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
    接收模块,设置为接收来自所述对应专网的隧道建立响应消息;
    所述发送模块,还设置为将所述隧道建立响应消息向所述移动终端转发。
  10. 根据权利要求9所述的装置,其中所述发送模块,设置为:
    直接向所述对应专网的安全处理设备发送隧道建立请求消息,或者
    通过所述对应专网的网关向所述对应专网的安全处理设备发送隧道建立请求消息。
  11. 一种专网接入装置,包括:
    专网建立单元,根据移动网网关的请求,通过所述移动网网关建立与移动终端的转发隧道;
    地址分配单元,设置为为所述移动终端分配IP地址,并将所述IP地址以加密信令的形式通过所述转发隧道向所述移动终端发送;
    通信单元,设置为以加密数据的形式通过所述转发隧道与所述移动终端通信。
  12. 根据权利要求11所述的装置,其中还包括鉴权单元,设置为在根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道之前,对所述移动终端进行鉴权;
    所述专网建立单元,设置为在所述鉴权单元鉴权通过的情况下,根据移动网网关的请求,通过所述移动网网关建立与所述移动终端的转发隧道。
  13. 根据权利要求11或12所述的装置,其中所述专网建立单元,设置为:
    接收所述移动网网关的发送的隧道建立请求消息,所述隧道建立请求消息中携带所述移动终端的标识信息;
    向所述移动网网关发送隧道建立响应消息,以通过所述移动网网关建立与所述移动终端的转发隧道。
  14. 一种专网接入装置,包括:
    终端建立单元,设置为向移动网网关发起会话建立请求,以通过所述移动网网关建立所述移动终端与对应专网之间的转发隧道;
    地址请求单元,设置为以加密信令方式通过所述移动网网关向所述对应专网请求IP地址;
    终端通信单元,设置为以加密数据的形式,通过所述转发隧道与所述对应专网通信。
  15. 一种移动网网关,包括权利要求8至10中任一项所述的专网接入装置。
  16. 一种专网设备,包括权利要求11至13中任一项所述的专网接入装置。
  17. 一种移动终端,包括权利要求14所述的专网接入装置。
  18. 一种专网接入系统,包括权利要求15所述的移动网网关,权利要求16所述的专网设备,以及权利要求17所述的移动终端。
PCT/CN2017/078910 2016-04-01 2017-03-31 一种专网接入方法、装置及系统 WO2017167249A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610201231.8A CN107295507A (zh) 2016-04-01 2016-04-01 一种专网接入方法、装置及系统
CN201610201231.8 2016-04-01

Publications (1)

Publication Number Publication Date
WO2017167249A1 true WO2017167249A1 (zh) 2017-10-05

Family

ID=59963535

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/078910 WO2017167249A1 (zh) 2016-04-01 2017-03-31 一种专网接入方法、装置及系统

Country Status (2)

Country Link
CN (1) CN107295507A (zh)
WO (1) WO2017167249A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113709732A (zh) * 2020-05-21 2021-11-26 阿里巴巴集团控股有限公司 网络接入方法、用户设备、网络实体及存储介质
CN114422875A (zh) * 2021-12-29 2022-04-29 广东柯内特环境科技有限公司 一种环境信息采集终端
CN114531279A (zh) * 2022-01-25 2022-05-24 中国联合网络通信集团有限公司 专网接入方法、服务器及存储介质

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109982311B (zh) * 2017-12-28 2022-01-14 中国移动通信集团北京有限公司 一种终端接入核心网设备方法及终端、mme和saegw
CN108966368B (zh) * 2018-06-29 2021-02-23 成都鼎桥通信技术有限公司 一种lte专网在公共安全领域的组网方法和系统
CN110881014B (zh) * 2018-09-05 2021-09-28 普天信息技术有限公司 一种对无线专网的业务进行物理隔离的方法及装置
CN113411286B (zh) * 2020-03-16 2023-05-30 北京沃东天骏信息技术有限公司 基于5g技术的访问处理方法及装置、电子设备、存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101651743A (zh) * 2009-09-10 2010-02-17 华耀环宇科技(北京)有限公司 一种面向手机终端用户的远程桌面接入系统
CN102143492A (zh) * 2010-12-06 2011-08-03 东莞宇龙通信科技有限公司 Vpn连接建立方法、移动终端、服务器
CN102348210A (zh) * 2011-10-19 2012-02-08 迈普通信技术股份有限公司 一种安全性移动办公的方法和移动安全设备
EP2790384A2 (en) * 2013-04-12 2014-10-15 Research In Motion Limited Secure network tunnel between a computing device and an endpoint

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101651743A (zh) * 2009-09-10 2010-02-17 华耀环宇科技(北京)有限公司 一种面向手机终端用户的远程桌面接入系统
CN102143492A (zh) * 2010-12-06 2011-08-03 东莞宇龙通信科技有限公司 Vpn连接建立方法、移动终端、服务器
CN102348210A (zh) * 2011-10-19 2012-02-08 迈普通信技术股份有限公司 一种安全性移动办公的方法和移动安全设备
EP2790384A2 (en) * 2013-04-12 2014-10-15 Research In Motion Limited Secure network tunnel between a computing device and an endpoint

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113709732A (zh) * 2020-05-21 2021-11-26 阿里巴巴集团控股有限公司 网络接入方法、用户设备、网络实体及存储介质
CN114422875A (zh) * 2021-12-29 2022-04-29 广东柯内特环境科技有限公司 一种环境信息采集终端
CN114422875B (zh) * 2021-12-29 2024-03-15 广东柯内特环境科技有限公司 一种环境信息采集终端
CN114531279A (zh) * 2022-01-25 2022-05-24 中国联合网络通信集团有限公司 专网接入方法、服务器及存储介质
CN114531279B (zh) * 2022-01-25 2023-12-22 中国联合网络通信集团有限公司 专网接入方法、服务器及存储介质

Also Published As

Publication number Publication date
CN107295507A (zh) 2017-10-24

Similar Documents

Publication Publication Date Title
WO2017167249A1 (zh) 一种专网接入方法、装置及系统
TWI713614B (zh) 用於使用支援多個連線性和服務上下文的安全模型的無線通訊的方法和裝置
JP6882255B2 (ja) ネットワークセキュリティアーキテクチャ
CN112997454B (zh) 经由移动通信网络连接到家庭局域网
CN108293223B (zh) 一种数据传输方法、用户设备和网络侧设备
US8077681B2 (en) Method and system for establishing a connection via an access network
WO2019017840A1 (zh) 网络验证方法、相关设备及系统
WO2018087696A1 (en) User plane model for non-3gpp access to fifth generation core network
JP2018526869A (ja) 暗号化されたクライアントデバイスコンテキストを用いたネットワークアーキテクチャおよびセキュリティ
WO2015101125A1 (zh) 网络接入控制方法和设备
WO2013118096A1 (en) Method, apparatus and computer program for facilitating secure d2d discovery information
WO2014102525A1 (en) Method and device for secure network access
WO2022075815A1 (en) Methods and systems for authentication and establishment of secure connection for edge computing services
WO2019096287A1 (zh) 鉴权的方法和装置
CN108616877B (zh) 一种小型基站的通信方法、系统及设备
WO2017143902A1 (zh) 一种分组数据网关、跨分组数据网关的切换方法和系统
WO2014201783A1 (zh) 一种自组网的加密鉴权方法、系统及终端
WO2014047923A1 (zh) 接入网络的方法和装置
US9667652B2 (en) Mobile remote access
KR102209289B1 (ko) 이동 통신 시스템 환경에서 프록시미티 기반 서비스를 위한 보안 및 정보 지원 방법 및 시스템
JP6892846B2 (ja) 認証用装置とサービス用装置とを含むコアネットワークシステムのユーザ認証方法
EP3454583B1 (en) Network connection method, and secure node determination method and device
JP5947763B2 (ja) 通信システム、通信方法、および、通信プログラム
EP3200420B1 (en) Providing communications security to an end-to-end communication connection
JP7076051B1 (ja) Ipネットワークにアクセスするための通信サービスを提供するための装置、方法及びそのためのプログラム

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17773279

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 17773279

Country of ref document: EP

Kind code of ref document: A1