WO2018188482A1 - Connection establishment method and apparatus - Google Patents

Connection establishment method and apparatus Download PDF

Info

Publication number
WO2018188482A1
WO2018188482A1 PCT/CN2018/080853 CN2018080853W WO2018188482A1 WO 2018188482 A1 WO2018188482 A1 WO 2018188482A1 CN 2018080853 W CN2018080853 W CN 2018080853W WO 2018188482 A1 WO2018188482 A1 WO 2018188482A1
Authority
WO
WIPO (PCT)
Prior art keywords
secure connection
terminal
connection establishment
address
access device
Prior art date
Application number
PCT/CN2018/080853
Other languages
French (fr)
Chinese (zh)
Inventor
孙立新
丁颖哲
周明宇
路杨
Original Assignee
北京佰才邦技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 北京佰才邦技术有限公司 filed Critical 北京佰才邦技术有限公司
Publication of WO2018188482A1 publication Critical patent/WO2018188482A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys

Definitions

  • the sending the security connection establishment response information to the access device of the terminal where the first IP address carried in the secure connection establishment request information is used to trigger an access device that allows the terminal to establish
  • the first secure connection establishment response information for instructing the access device of the terminal to establish the secure connection is sent to the access device of the terminal.
  • Step S404 Receive secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether to establish a secure connection;

Abstract

The present application provides a connection establishment method and apparatus. The method comprises: obtaining secure connection establishment request information sent by an access device of a terminal; in response to secure connection establishment request information, sending secure connection establishment response information to the access device of the terminal; and in a case in which the secure connection establishment response is used for instructing the access device of the terminal to establish a secure connection, sending secure connection establishment instruction information to a first remote device. The problem in the related art of low security of data transmission between a terminal and a device in the Internet is resolved, thereby improving the security of the data transmission between the terminal and the device in the Internet.

Description

连接建立方法及装置Connection establishment method and device
本申请要求于2017年04月14日提交中国专利局、申请号为201710248345.2、发明名称为“连接建立方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。The present application claims the priority of the Chinese Patent Application, filed on Apr. 14, 2017, the application Serial No.
技术领域Technical field
本申请涉及通信领域,具体而言,涉及一种连接建立方法及装置。The present application relates to the field of communications, and in particular, to a connection establishment method and apparatus.
背景技术Background technique
3GPP标准化组织引入的本地IP接入(Local IP Access,LIPA)与选择性IP流量卸载(Selected IP Traffic Offload,简称为SIPTO)技术最初是基于毫微微小区(Femtocell)网络提出的,其作用是用户的数据可直接连接到家里的局域网络到因特网(Internet),不经过营运商的核心网络,因此减轻核心网络的负荷和传输成本。The Local IP Access (LIPA) and Selective IP Traffic Offload (SIPTO) technologies introduced by the 3GPP standardization organization were originally proposed based on the Femtocell network, and their functions are users. The data can be directly connected to the home network to the Internet (Internet), without going through the operator's core network, thus reducing the load and transmission costs of the core network.
在LIPA/SIPTO技术中,UE注册到网络后,核心网可以选择基站或本地网关作为UE的数据网关,使UE发送到Internet的数据可以不用通过核心网而是从基站或本地网关处直接发送到Internet,来自Internet的数据也可以不用经过核心网而直接发送到UE所接入的基站或网关。UE与Internet节点间的数据传递完全可以直接通过基站或本地网关实现,而毋须再传递到核心网络,这样既能减少数据传输时延,也能减少核心网络的负荷与降低传输成本。一般来说,LIPA技术在HeNB(Home evolved NodeB,家庭演进基站)上实现,图1为在HeNB上实现LIPA的网络架构,其方法为在HeNB上新增一个本地网关(Local Gateway,L-GW),其功能与PGW相似并可以透过直接通道不通过S-GW直接连接HeNB,来自UE的数据可以通过L-GW直接发送到Internet。SIPTO技术一般在宏基站上实现,图2为在宏基站上实现SIPTO的网络架构。如图2所示,MME在为UE选择P-GW的时候,要考虑用户的位置,选择一个在地理/逻辑上靠 近UE的L-GW来执行SIPTO(本地S-GW和本地P-GW可合设)。In the LIPA/SIPTO technology, after the UE registers with the network, the core network can select the base station or the local gateway as the data gateway of the UE, so that the data sent by the UE to the Internet can be directly sent from the base station or the local gateway without going through the core network. Internet, data from the Internet can also be sent directly to the base station or gateway accessed by the UE without going through the core network. The data transmission between the UE and the Internet node can be directly implemented by the base station or the local gateway without being transmitted to the core network, which can reduce the data transmission delay, reduce the load of the core network and reduce the transmission cost. In general, the LIPA technology is implemented on a Home evolved NodeB (HeNB). FIG. 1 is a network architecture for implementing LIPA on a HeNB by adding a local gateway (Local Gateway, L-GW) to the HeNB. ), its function is similar to PGW and can directly connect to HeNB through S-GW through direct channel. Data from UE can be directly sent to the Internet through L-GW. The SIPTO technology is generally implemented on a macro base station, and FIG. 2 is a network architecture for implementing SIPTO on a macro base station. As shown in FIG. 2, when selecting a P-GW for a UE, the MME considers the location of the user, and selects an L-GW that is geographically/logically close to the UE to perform SIPTO (the local S-GW and the local P-GW may be Set up).
在现有技术中,UE的接入设备(无线网络接入点或者本地网关)一般是跟核心网的安全网关之间建立有安全连接(如IPSec隧道,VPN连接),但是从无线网络接入点/本地网关分流到Internet的数据或Internet发送到无线网络接入点/本地网关的用户数据不经过核心网,因此分流到Internet的数据缺少安全保证机制,很容易被网络黑客攻击、窃取或篡改。即使是同一个运营商或设备提供商子网之间也无法保证传输的安全性。例如,图1是根据相关技术的LIPA网络架构的示意图,如图1所示,在LIPA网络架构中,HeNB与安全网关SeGW之间建立IPSec隧道,保证HeNB与核心网之间传输的安全性,但无法保证从HeNB分流到Internet的数据的安全性;图2是根据相关技术的SIPTO网络架构的示意图,如图2所示,在SIPTO网络架构中,eNB与S-GW之间的连接保证了eNB与核心网之间传输的安全性,但无法保证从SGW分流到Internet的数据的安全性。In the prior art, the access device (the wireless network access point or the local gateway) of the UE generally establishes a secure connection (such as an IPSec tunnel, a VPN connection) with the security gateway of the core network, but accesses from the wireless network. The data that is distributed to the Internet by the point/local gateway or the user data sent by the Internet to the wireless network access point/local gateway does not pass through the core network. Therefore, the data that is offloaded to the Internet lacks a security guarantee mechanism, and is easily attacked, stolen or tampered by cyber hackers. . Transmission security is not guaranteed even between the same carrier or device provider subnet. For example, FIG. 1 is a schematic diagram of a LIPA network architecture according to the related art. As shown in FIG. 1, in an LIPA network architecture, an IPSec tunnel is established between a HeNB and a security gateway SeGW to ensure security between a HeNB and a core network. However, the security of the data that is offloaded from the HeNB to the Internet cannot be guaranteed; FIG. 2 is a schematic diagram of the SIPTO network architecture according to the related art. As shown in FIG. 2, in the SIPTO network architecture, the connection between the eNB and the S-GW is guaranteed. The security of transmission between the eNB and the core network, but the security of data diverted from the SGW to the Internet cannot be guaranteed.
针对相关技术中终端与Internet网络中的设备传输数据的安全性低的问题,目前还没有有效地解决方案。In view of the low security of data transmission between devices in terminals and Internet networks in related art, there is currently no effective solution.
申请内容Application content
本申请实施例提供了一种连接建立方法及装置,以至少解决相关技术中终端与Internet网络中的设备传输数据的安全性低的问题。The embodiment of the present application provides a connection establishment method and device, so as to at least solve the problem that the security of data transmitted by a device in a terminal and an Internet network in the related art is low.
根据本申请的一个实施例,提供了一种连接建立方法,用于安全连接管理设备,包括:获取终端的接入设备发送的安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立所述终端的接入设备与互联网中的第一远端设备之间的安全连接;响应于所述安全连接建立请求信息向所述终端的接入设备发送安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示所述终端的接入设备是否建立所述安全连接;在所述安全连接建立响应用于指示所述终端的接入设备建立所述安全连接的情况下,向所述第一远端设备发送安全连接建立指示信息,其中,所述安全连接建立指示信息用于指示所述第一远端设备建立所述安全连接。According to an embodiment of the present application, a connection establishment method is provided for securely connecting a management device, including: acquiring secure connection establishment request information sent by an access device of a terminal, wherein the secure connection establishment request information is used for Requesting to establish a secure connection between the access device of the terminal and the first remote device in the Internet; and transmitting the secure connection establishment response information to the access device of the terminal in response to the secure connection establishment request information, where The secure connection establishment response information is used to indicate whether the access device of the terminal establishes the secure connection; and in the case that the secure connection establishment response is used to indicate that the access device of the terminal establishes the secure connection, Sending the secure connection establishment indication information to the first remote device, where the secure connection establishment indication information is used to instruct the first remote device to establish the secure connection.
可选地,向所述终端的接入设备发送所述安全连接建立响应信息包括:在所述安全连接建立请求信息中携带的第一IP地址用于触发允许所述终端的接入设备建立所述安全连接的情况下,向所述终端的接入设备发送用于指示所述终端的接入设备建立所述安全连接的第一安全连接建立响应信息。Optionally, the sending the security connection establishment response information to the access device of the terminal, where the first IP address carried in the secure connection establishment request information is used to trigger an access device that allows the terminal to establish In the case of the secure connection, the first secure connection establishment response information for instructing the access device of the terminal to establish the secure connection is sent to the access device of the terminal.
可选地,向所述终端的接入设备发送所述安全连接建立响应信息包括:在所述安全连接建立请求信息中携带的第一IP地址用于触发不允许所述终端的接入设备建立所述安全连接的情况下,向所述终端的接入设备发送用于指示所述终端的接入设备不建立所述安全连接的第二安全连接建立响应信息。Optionally, the sending, by the access device of the terminal, the security connection establishment response information includes: the first IP address carried in the secure connection establishment request information is used to trigger establishment of an access device that does not allow the terminal to be established. In the case of the secure connection, the second access connection establishment response information for indicating that the access device of the terminal does not establish the secure connection is sent to the access device of the terminal.
可选地,向所述终端的接入设备发送所述第一安全连接建立响应信息包括:根据所述第一IP地址确定与所述终端的接入设备建立所述安全连接的第二远端设备,其中,所述第二远端设备包括所述第一IP地址对应的设备或者所述第一IP地址对应的设备所在网络中的网络设备;向所述终端的接入设备发送所述第一安全连接建立响应信息,其中,所述第一安全连接建立响应信息携带有所述第二远端设备的第二IP地址和所述安全连接的配置信息。Optionally, the sending, by the access device of the terminal, the first secure connection setup response information includes: determining, according to the first IP address, a second remote end that establishes the secure connection with an access device of the terminal The device, wherein the second remote device includes a device corresponding to the first IP address or a network device in a network where the device corresponding to the first IP address is located; and the device is sent to the access device of the terminal A secure connection establishment response message, wherein the first secure connection setup response information carries a second IP address of the second remote device and configuration information of the secure connection.
可选地,所述第一IP地址对应的设备所在网络中的网络设备包括以下之一:服务提供商部署所述第一IP地址对应的设备所在网络中的网络设备时登记的所述第一IP地址对应的设备所在网络的安全网关或者路由器;使用所述第一IP地址对应的终端设备接入网络时登记的所述第一IP地址对应的终端设备接入的接入点设备、安全网关或者路由器;所述第一远端设备。Optionally, the network device in the network where the device corresponding to the first IP address is located includes one of the following: the first one registered when the service provider deploys the network device in the network where the device corresponding to the first IP address is located The security gateway or router of the network where the device corresponding to the IP address is located; the access point device and the security gateway accessed by the terminal device corresponding to the first IP address registered when the terminal device corresponding to the first IP address accesses the network Or a router; the first remote device.
可选地,所述安全连接建立请求信息中携带的第一IP地址用于触发允许所述终端的接入设备建立所述安全连接包括:在所述终端的接入设备的IP地址与所述第一IP地址属于同一服务提供商部署的设备的IP地址的情况下,确定所述安全连接建立请求信息中携带的第一IP地址用于触发允许所述终端的接入设备建立所述安全连接,其中,所述服务提供商部署的设备包括:接入设备、终端设备或者 用户终端。Optionally, the first IP address carried in the secure connection establishment request information is used to trigger an access device that allows the terminal to establish the secure connection, including: an IP address of the access device at the terminal, and the If the first IP address belongs to the IP address of the device deployed by the same service provider, the first IP address carried in the secure connection establishment request information is used to trigger the access device of the terminal to establish the secure connection. The device deployed by the service provider includes: an access device, a terminal device, or a user terminal.
可选地,所述安全连接建立请求信息中携带的第一IP地址用于触发不允许所述终端的接入设备建立所述安全连接包括:在所述终端的接入设备的IP地址与所述第一IP地址不属于同一服务提供商部署的设备的IP地址的情况下,确定所述安全连接建立请求信息中携带的第一IP地址用于触发不允许所述终端的接入设备建立所述安全连接,其中,所述服务提供商部署的设备包括:接入设备、终端设备或者用户终端。Optionally, the first IP address carried in the secure connection establishment request information is used to trigger an access device that does not allow the terminal to establish the secure connection, including: an IP address and an address of the access device at the terminal If the first IP address does not belong to the IP address of the device deployed by the same service provider, the first IP address carried in the secure connection establishment request information is used to trigger the establishment of the access device that does not allow the terminal to be established. The secure connection, wherein the device deployed by the service provider comprises: an access device, a terminal device, or a user terminal.
根据本申请的另一个实施例,提供了一种连接建立方法,用于终端接入设备,包括:向安全连接管理设备发送安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;接收所述安全连接管理设备响应于所述安全连接建立请求信息的安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示是否建立所述安全连接;在所述安全连接建立响应用于指示建立所述安全连接的情况下,根据所述安全连接建立响应信息的指示建立所述安全连接。According to another embodiment of the present application, a connection establishment method is provided for a terminal access device, including: sending a secure connection establishment request message to a secure connection management device, wherein the secure connection establishment request information is used for a request Establishing a secure connection with the first remote device in the Internet; receiving secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, wherein the secure connection establishment response information is used for Determining whether the secure connection is established; and in the case that the secure connection establishment response is used to indicate that the secure connection is established, establishing the secure connection according to the indication of the secure connection establishment response information.
可选地,发送所述安全连接建立请求信息包括:对终端数据进行检测,得到所述终端数据的第一IP地址,其中,所述第一IP地址为所述第一远端设备的IP地址;发送携带有所述第一IP地址的所述安全连接建立请求信息。Optionally, the sending the secure connection establishment request information includes: detecting, by the terminal data, a first IP address of the terminal data, where the first IP address is an IP address of the first remote device Sending the secure connection establishment request information carrying the first IP address.
可选地,在发送携带有所述第一IP地址的所述安全连接建立请求信息之前,所述方法还包括:判断是否已建立所述第一IP地址对应的安全连接;在判断出已建立所述第一IP地址对应的安全连接的情况下,通过已建立的所述第一IP地址对应的安全连接发送上述终端数据;在判断出未建立所述第一IP地址对应的安全连接的情况下,确定发送携带有所述第一IP地址的所述安全连接建立请求信息。Optionally, before the sending the secure connection establishment request information that carries the first IP address, the method further includes: determining whether a secure connection corresponding to the first IP address has been established; determining that the established connection is established In the case of the secure connection corresponding to the first IP address, the terminal data is sent through the established secure connection corresponding to the first IP address; and it is determined that the secure connection corresponding to the first IP address is not established. And determining to send the secure connection establishment request information carrying the first IP address.
根据本申请的另一个实施例,提供了一种连接建立装置,用于安全连接管理设备,包括:第一接收模块,用于接收终端的接入设备发送的安全连接建立请求信息,其中,所述安全连接建立请求信 息用于请求建立所述终端的接入设备与互联网中的第一远端设备之间的安全连接;第一发送模块,用于响应于所述安全连接建立请求信息向所述终端的接入设备发送安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示所述终端的接入设备是否建立所述安全连接;第二发送模块,用于在所述安全连接建立响应用于指示所述终端的接入设备建立所述安全连接的情况下,向所述第一远端设备发送安全连接建立指示信息,其中,所述安全连接建立指示信息用于指示所述第一远端设备建立所述安全连接。According to another embodiment of the present application, a connection establishing apparatus is provided for securely connecting a management device, including: a first receiving module, configured to receive secure connection establishment request information sent by an access device of the terminal, where The secure connection establishment request information is used to request to establish a secure connection between the access device of the terminal and the first remote device in the Internet; the first sending module is configured to respond to the secure connection establishment request information The access device of the terminal sends the security connection establishment response information, where the security connection establishment response information is used to indicate whether the access device of the terminal establishes the secure connection; and the second sending module is configured to use the security The connection establishment response is used to send the secure connection establishment indication information to the first remote device, where the access device of the terminal establishes the secure connection, where the secure connection establishment indication information is used to indicate The first remote device establishes the secure connection.
根据本申请的另一个实施例,提供了一种连接建立装置,用于终端接入设备,包括:第三发送模块,用于向安全连接管理设备发送安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;第二接收模块,用于接收所述安全连接管理设备响应于所述安全连接建立请求信息的安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示是否建立所述安全连接;建立模块,用于在所述安全连接建立响应用于指示建立所述安全连接的情况下,根据所述安全连接建立响应信息的指示建立所述安全连接。According to another embodiment of the present application, a connection establishing apparatus is provided for a terminal access device, including: a third sending module, configured to send secure connection establishment request information to a secure connection management device, where the security The connection establishment request information is used to request to establish a secure connection with the first remote device in the Internet; the second receiving module is configured to receive the secure connection establishment of the secure connection management device in response to the secure connection establishment request information Response information, wherein the secure connection establishment response information is used to indicate whether the secure connection is established; and an establishing module, configured to perform security according to the security connection establishment response for indicating establishment of the secure connection The indication of the connection establishment response information establishes the secure connection.
根据本申请的另一个实施例,提供了一种连接建立装置,用于安全连接管理设备,包括:第一处理器和第一通讯接口,其中,所述第一处理器,与所述第一通讯接口连接,所述第一处理器用于获取通过所述第一通讯接口接收到的终端的接入设备发送的安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立所述终端的接入设备与互联网中的第一远端设备之间的安全连接;响应于所述安全连接建立请求信息指示所述第一通讯接口向所述终端的接入设备发送安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示所述终端的接入设备是否建立所述安全连接;在所述安全连接建立响应用于指示所述终端的接入设备建立所述安全连接的情况下,指示所述第一通讯接口向所述第一远端设备发送安全连接建立指示信息,其中,所述安全连接建立指示信息用于指示 所述第一远端设备建立所述安全连接。According to another embodiment of the present application, a connection establishing apparatus is provided for securely connecting a management device, including: a first processor and a first communication interface, wherein the first processor, and the first a communication interface connection, the first processor is configured to acquire secure connection establishment request information sent by an access device of the terminal received by the first communication interface, where the secure connection establishment request information is used to request to establish the a secure connection between the access device of the terminal and the first remote device in the Internet; and in response to the secure connection establishment request information, the first communication interface sends a secure connection establishment response message to the access device of the terminal The secure connection establishment response information is used to indicate whether the access device of the terminal establishes the secure connection; and the secure connection establishment response is used to indicate that the access device of the terminal establishes the secure connection. In the case, the first communication interface is instructed to send the secure connection establishment indication information to the first remote device, where the security Connection establishment instruction information for instructing the remote device establishing the first secure connection.
根据本申请的另一个实施例,提供了一种连接建立装置,用于终端接入设备,包括:第二处理器和第二通讯接口,其中,所述第二处理器,与所述第二通讯接口连接,所述第二处理器用于指示所述第二通讯接口向安全连接管理设备发送安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;通过所述第二通讯接口接收所述安全连接管理设备响应于所述安全连接建立请求信息的安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示是否建立所述安全连接;在所述安全连接建立响应用于指示建立所述安全连接的情况下,根据所述安全连接建立响应信息的指示建立所述安全连接。According to another embodiment of the present application, a connection establishing apparatus is provided for a terminal access device, including: a second processor and a second communication interface, wherein the second processor and the second a communication interface, the second processor is configured to instruct the second communication interface to send secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request to establish the first distance in the Internet a secure connection between the end devices; receiving, by the second communication interface, secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, wherein the secure connection establishment response information is used to indicate Whether to establish the secure connection; and in the case that the secure connection setup response is used to indicate that the secure connection is established, the secure connection is established according to the indication of the secure connection establishment response information.
根据本申请的另一个实施例,提供了一种存储介质,所述存储介质被设置为存储用于执行以下步骤的程序代码:According to another embodiment of the present application, a storage medium is provided, the storage medium being arranged to store program code for performing the following steps:
获取终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;Acquiring the secure connection establishment request information sent by the access device of the terminal, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet;
响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;Sending the secure connection establishment response information to the access device of the terminal in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection;
在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接。And the secure connection establishment indication information is used to indicate that the first remote device establishes security, where the security connection establishment response is used to indicate that the access device of the terminal establishes a secure connection. connection.
可选地,所述存储介质还被设置为存储用于执行以下步骤的程序代码:Optionally, the storage medium is further arranged to store program code for performing the following steps:
向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;Sending the secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request a secure connection between the access device of the establishment terminal and the first remote device in the Internet;
接收安全连接管理设备响应于安全连接建立请求信息的安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接 入设备是否建立安全连接;Receiving the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, wherein the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection;
在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接。In the case that the secure connection setup response is used to indicate that the access device of the terminal establishes a secure connection, the secure connection is established according to the indication of the secure connection establishment response information.
通过本申请,接收终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接,由此可见,采用上述方案根据安全连接建立请求信息指示终端的接入设备是否建立安全连接,并在允许建立连接的情况下利用安全连接建立指示信息通知第一远端设备建立该安全连接,通过安全连接的建立使数据在安全环境中传输,因此,提高了终端与Internet网络中的设备传输数据的安全性,从而解决了相关技术中终端与Internet网络中的设备传输数据的安全性低的问题。The secure connection establishment request information sent by the access device of the terminal is received by the access device, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet; The secure connection establishment request information is sent to the access device of the terminal, where the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection; and the secure connection establishment response is used to indicate the connection of the terminal. The security connection establishment indication information is sent to the first remote device, where the security connection establishment indication information is used to indicate that the first remote device establishes a secure connection, and thus, the foregoing solution is adopted according to the security. The connection establishment request information indicates whether the access device of the terminal establishes a secure connection, and uses the secure connection establishment indication information to notify the first remote device to establish the secure connection when the connection is allowed to be established, and the data is in a secure environment through the establishment of the secure connection. Medium transmission, therefore, improved terminal Internet data transmission security devices in the network, so as to solve the security problems of low data transmission terminals and related technologies in the Internet network equipment.
附图说明DRAWINGS
此处所说明的附图用来提供对本申请的进一步理解,构成本申请的一部分,本申请的示意性实施例及其说明用于解释本申请,并不构成对本申请的不当限定。在附图中:The drawings described herein are intended to provide a further understanding of the present application, and are intended to be a part of this application. In the drawing:
图1是根据相关技术的LIPA网络架构的示意图;1 is a schematic diagram of a LIPA network architecture according to related art;
图2是根据相关技术的SIPTO网络架构的示意图;2 is a schematic diagram of a SIPTO network architecture according to the related art;
图3是根据本申请实施例的一种连接建立方法的流程图;FIG. 3 is a flowchart of a connection establishment method according to an embodiment of the present application; FIG.
图4是根据本申请实施例的另一种连接建立方法的流程图;4 is a flowchart of another connection establishment method according to an embodiment of the present application;
图5是根据本申请实施例的一种连接建立装置的结构框图一;FIG. 5 is a structural block diagram 1 of a connection establishing apparatus according to an embodiment of the present application; FIG.
图6是根据本申请实施例的一种连接建立装置的结构框图二;6 is a structural block diagram 2 of a connection establishing apparatus according to an embodiment of the present application;
图7是根据本申请可选实施例的一种建立安全连接的方法的示意图一;7 is a first schematic diagram of a method for establishing a secure connection according to an alternative embodiment of the present application;
图8是根据本申请可选实施例的一种建立安全连接的方法的示意图二。FIG. 8 is a second schematic diagram of a method of establishing a secure connection according to an alternative embodiment of the present application.
具体实施方式detailed description
下文中将参考附图并结合实施例来详细说明本申请。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。The present application will be described in detail below with reference to the drawings in conjunction with the embodiments. It should be noted that the embodiments in the present application and the features in the embodiments may be combined with each other without conflict.
需要说明的是,本申请的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or order.
实施例1Example 1
在本实施例中提供了一种连接建立方法,该方法可以但不限于用于安全连接管理设备,图3是根据本申请实施例的一种连接建立方法的流程图,如图3所示,该流程包括如下步骤:In this embodiment, a connection establishment method is provided, which may be, but is not limited to, a security connection management device. FIG. 3 is a flowchart of a connection establishment method according to an embodiment of the present application, as shown in FIG. The process includes the following steps:
步骤S302,获取终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;Step S302: Acquire secure connection establishment request information sent by the access device of the terminal, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet;
步骤S304,响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;Step S304, sending security connection establishment response information to the access device of the terminal, in response to the secure connection establishment request information, where the security connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection;
步骤S306,在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接。Step S306, in the case that the secure connection establishment response is used to indicate that the access device of the terminal establishes a secure connection, the security connection establishment indication information is sent to the first remote device, where the secure connection establishment indication information is used to indicate the first remote end. The device establishes a secure connection.
可选地,上述连接建立方法可以但不限于应用于终端与Internet网络中的设备传输数据的场景中。例如:使用本地IP接入(Local IP Access,简称为LIPA)与选择性IP流量卸载(Selected IP Traffic Offload,简称为SIPTO)技术。Optionally, the foregoing connection establishment method may be, but is not limited to, being applied to a scenario in which a terminal and a device in an Internet network transmit data. For example, Local IP Access (LIPA for short) and Selective IP Traffic Offload (SIPTO) technology are used.
可选地,上述连接建立方法可以但不限于应用于网络管理设备。Optionally, the foregoing connection establishment method may be, but is not limited to, applied to a network management device.
通过上述步骤,获取终端的接入设备发送的安全连接建立请求 信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接,由此可见,采用上述方案根据安全连接建立请求信息指示终端的接入设备是否建立安全连接,并在允许建立连接的情况下利用安全连接建立指示信息通知第一远端设备建立该安全连接,通过安全连接的建立使数据在安全环境中传输,因此,提高了终端与Internet网络中的设备传输数据的安全性,从而解决了相关技术中终端与Internet网络中的设备传输数据的安全性低的问题。Obtaining the secure connection establishment request information sent by the access device of the terminal, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet; The secure connection establishment request information is sent to the access device of the terminal, where the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection; and the secure connection establishment response is used to indicate the connection of the terminal. The security connection establishment indication information is sent to the first remote device, where the security connection establishment indication information is used to indicate that the first remote device establishes a secure connection, and thus, the foregoing solution is adopted according to the security. The connection establishment request information indicates whether the access device of the terminal establishes a secure connection, and uses the secure connection establishment indication information to notify the first remote device to establish the secure connection when the connection is allowed to be established, and the data is in a secure environment through the establishment of the secure connection. In transit, therefore, improved the end The security of transmitting data between the terminal and the device in the Internet network solves the problem that the security of the data transmitted by the device in the terminal and the Internet network in the related art is low.
可选地,在上述步骤S304中,可以但不限于根据安全连接建立请求信息中携带的第一IP地址来触发是否允许终端的接入设备建立安全连接,并根据第一IP地址发送用于指示该判断结果的安全连接建立响应信息。例如:在安全连接建立请求信息中携带的第一IP地址用于触发允许终端的接入设备建立安全连接的情况下,向终端的接入设备发送用于指示终端的接入设备建立安全连接的第一安全连接建立响应信息,在安全连接建立请求信息中携带的第一IP地址用于触发不允许终端的接入设备建立安全连接的情况下,向终端的接入设备发送用于指示终端的接入设备不建立安全连接的第二安全连接建立响应信息。Optionally, in the foregoing step S304, the first IP address carried in the secure connection establishment request information may be triggered to trigger whether the access device of the terminal is allowed to establish a secure connection, and the indication is sent according to the first IP address. The secure connection of the judgment result establishes response information. For example, if the first IP address carried in the secure connection establishment request information is used to trigger the access device of the terminal to establish a secure connection, the access device for indicating the terminal establishes a secure connection. The first secure connection establishment response information is sent to the access device of the terminal to indicate the terminal when the first IP address carried in the secure connection establishment request information is used to trigger the access device that does not allow the terminal to establish a secure connection. The second secure connection establishment response information of the access device does not establish a secure connection.
可选地,通知终端的接入设备允许建立安全连接的方式可以但不限于是向终端的接入设备发送上述第一安全连接建立响应信息,第一安全连接建立响应信息中可以但不限于携带将于终端的接入设备建立安全连接的第二远端设备的第二IP地址和安全连接的配置信息。例如:根据第一IP地址确定与终端的接入设备建立安全连接的第二远端设备,其中,第二远端设备包括第一IP地址对应的设备或 者第一IP地址对应的设备所在网络中的网络设备,并向终端的接入设备发送第一安全连接建立响应信息,其中,第一安全连接建立响应信息携带有第二远端设备的第二IP地址和安全连接的配置信息。Optionally, the manner in which the access device of the terminal is allowed to establish a secure connection may be, but is not limited to, sending the first secure connection establishment response information to the access device of the terminal, where the first secure connection establishment response information may be, but is not limited to, carrying The second IP address and the configuration information of the secure connection of the second remote device that will establish a secure connection to the access device of the terminal. For example, the second remote device that establishes a secure connection with the access device of the terminal is determined according to the first IP address, where the second remote device includes the device corresponding to the first IP address or the device corresponding to the device with the first IP address. The network device sends the first secure connection setup response information to the access device of the terminal, where the first secure connection setup response information carries the second IP address of the second remote device and the configuration information of the secure connection.
可选地,第一IP地址对应的设备所在网络中的网络设备可以但不限于包括以下之一:服务提供商部署第一IP地址对应的设备所在网络中的网络设备时登记的第一IP地址对应的设备所在网络的安全网关或者路由器;使用第一IP地址对应的终端设备接入网络时登记的第一IP地址对应的终端设备接入的接入点设备、安全网关或者路由器;第一远端设备。Optionally, the network device in the network where the device corresponding to the first IP address is located may be, but is not limited to, one of the following: the first IP address that is registered when the service provider deploys the network device in the network where the device corresponding to the first IP address is located. The security gateway or router of the network where the corresponding device is located; the access point device, security gateway, or router accessed by the terminal device corresponding to the first IP address registered when the terminal device corresponding to the first IP address accesses the network; End device.
可选地,在终端的接入设备的IP地址与第一IP地址属于同一服务提供商部署的设备的IP地址的情况下,确定安全连接建立请求信息中携带的第一IP地址用于触发允许终端的接入设备建立安全连接,其中,服务提供商部署的设备包括:接入设备、终端设备或者用户终端,在终端的接入设备的IP地址与第一IP地址不属于同一服务提供商部署的设备的IP地址的情况下,确定安全连接建立请求信息中携带的第一IP地址用于触发不允许终端的接入设备建立安全连接,其中,服务提供商部署的设备包括:接入设备、终端设备或者用户终端。Optionally, in the case that the IP address of the access device of the terminal and the IP address of the device deployed by the same service provider belong to the same IP address, the first IP address carried in the secure connection establishment request information is used to trigger the permission. The access device of the terminal establishes a secure connection, where the device deployed by the service provider includes: an access device, a terminal device, or a user terminal, where the IP address of the access device of the terminal does not belong to the same service provider deployment as the first IP address. In the case of the IP address of the device, the first IP address carried in the secure connection establishment request information is used to trigger the access device that does not allow the terminal to establish a secure connection, where the device deployed by the service provider includes: an access device, Terminal device or user terminal.
在本实施例中提供了另一种连接建立方法,该方法可以但不限于用于终端接入设备,图4是根据本申请实施例的另一种连接建立方法的流程图,如图4所示,该流程包括如下步骤:Another connection establishment method is provided in this embodiment, which may be, but is not limited to, a terminal access device. FIG. 4 is a flowchart of another connection establishment method according to an embodiment of the present application, as shown in FIG. The process includes the following steps:
步骤S402,向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;Step S402, sending secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request to establish a secure connection with the first remote device in the Internet;
步骤S404,接收安全连接管理设备响应于安全连接建立请求信息的安全连接建立响应信息,其中,安全连接建立响应信息用于指示是否建立安全连接;Step S404: Receive secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether to establish a secure connection;
步骤S406,在安全连接建立响应用于指示建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接。Step S406: In the case that the secure connection establishment response is used to indicate that the secure connection is established, the secure connection is established according to the indication of the secure connection establishment response information.
可选地,上述连接建立方法可以但不限于应用于终端与Internet网络中的设备传输数据的场景中。例如:使用本地IP接入(Local IP Access,简称为LIPA)与选择性IP流量卸载(Selected IP Traffic Offload,简称为SIPTO)技术。Optionally, the foregoing connection establishment method may be, but is not limited to, being applied to a scenario in which a terminal and a device in an Internet network transmit data. For example, Local IP Access (LIPA for short) and Selective IP Traffic Offload (SIPTO) technology are used.
可选地,上述连接建立方法可以但不限于应用于终端的接入设备,例如:无线网络接入点、服务网关等。Optionally, the foregoing connection establishment method may be, but is not limited to, an access device applied to the terminal, for example, a wireless network access point, a service gateway, and the like.
通过上述步骤,向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;接收安全连接管理设备响应于安全连接建立请求信息的安全连接建立响应信息,其中,安全连接建立响应信息用于指示是否建立安全连接;在安全连接建立响应用于指示建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接,由此可见,采用上述方案通过发送安全连接建立请求信息请求建立安全连接,接收响应于上述安全连接建立响应信息,并根据安全连接建立响应信息的指示建立安全连接,通过安全连接的建立使数据在安全环境中传输,因此,提高了终端与Internet网络中的设备传输数据的安全性,从而解决了相关技术中终端与Internet网络中的设备传输数据的安全性低的问题。Through the above steps, the secure connection establishment request information is sent to the secure connection management device, wherein the secure connection establishment request information is used to request to establish a secure connection with the first remote device in the Internet; and the secure connection management device is received in response to the security The secure connection establishment response information of the connection establishment request information, wherein the secure connection establishment response information is used to indicate whether to establish a secure connection; and in the case that the secure connection establishment response is used to indicate that the secure connection is established, the indication of establishing the response information according to the secure connection is established. The secure connection can be seen by using the above solution to establish a secure connection by sending a secure connection establishment request message, receiving a response to the secure connection establishment response, and establishing a secure connection according to the indication of the secure connection establishment response information, and establishing the secure connection. The data is transmitted in a secure environment. Therefore, the security of the data transmitted by the terminal and the device in the Internet network is improved, thereby solving the problem that the security of the data transmitted by the device in the terminal and the Internet network in the related art is low.
可选地,在上述步骤S402中,通过对终端数据的检测,将检测到的与终端进行数据传输的第一远端设备的IP地址携带在安全连接建立请求信息,并发送该携带有第一IP地址的安全连接建立请求信息。例如:对终端数据进行检测,得到终端数据的第一IP地址,其中,第一IP地址为第一远端设备的IP地址,发送携带有第一IP地址的安全连接建立请求信息。Optionally, in the foregoing step S402, by detecting the terminal data, the detected IP address of the first remote device that performs data transmission with the terminal is carried in the secure connection establishment request information, and the first carrier is sent. The secure connection establishment request information of the IP address. For example, the terminal data is detected to obtain the first IP address of the terminal data, wherein the first IP address is the IP address of the first remote device, and the secure connection establishment request information carrying the first IP address is sent.
可选地,在发送携带有第一IP地址的安全连接建立请求信息之前,可以先判断是否已经存在了第一IP地址对应的安全连接,如果安全连接已经存在,则利用已经存在的安全连接传输数据,如果安全连接不存在,再建立安全连接建立请求信息请求的安全连接。例如:判断是否已建立第一IP地址对应的安全连接,在判断出已建立 第一IP地址对应的安全连接的情况下,通过已建立的第一IP地址对应的安全连接发送上述终端数据,在判断出未建立第一IP地址对应的安全连接的情况下,确定发送携带有第一IP地址的安全连接建立请求信息。Optionally, before the secure connection establishment request information carrying the first IP address is sent, it may be determined whether a secure connection corresponding to the first IP address already exists, and if the secure connection already exists, the existing secure connection is used to transmit. Data, if the secure connection does not exist, establish a secure connection for the secure connection establishment request information request. For example, determining whether a secure connection corresponding to the first IP address has been established, and if it is determined that the secure connection corresponding to the first IP address has been established, transmitting the terminal data through the secure connection corresponding to the established first IP address, When it is determined that the secure connection corresponding to the first IP address is not established, it is determined that the secure connection establishment request information carrying the first IP address is sent.
实施例2Example 2
在本实施例中还提供了一种连接建立装置,该装置可以但不限于用于安全连接管理设备,该装置用于实现上述实施例及优选实施方式,已经进行过说明的不再赘述。如以下所使用的,术语“模块”可以实现预定功能的软件和/或硬件的组合。尽管以下实施例所描述的装置较佳地以软件来实现,但是硬件,或者软件和硬件的组合的实现也是可能并被构想的。In this embodiment, a connection establishment device is also provided, which may be, but is not limited to, a security connection management device, which is used to implement the foregoing embodiments and preferred embodiments, and has not been described again. As used below, the term "module" may implement a combination of software and/or hardware of a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware, is also possible and contemplated.
图5是根据本申请实施例的一种连接建立装置的结构框图一,如图5所示,该装置包括:FIG. 5 is a structural block diagram 1 of a connection establishing apparatus according to an embodiment of the present application. As shown in FIG. 5, the apparatus includes:
获取模块52,用于获取终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;The obtaining module 52 is configured to obtain secure connection establishment request information sent by the access device of the terminal, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet. ;
第一发送模块54,耦合至获取模块52,用于响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;The first sending module 54 is coupled to the obtaining module 52, configured to send the secure connection establishing response information to the access device of the terminal, where the secure connection establishing response information is used to indicate whether the access device of the terminal is Establish a secure connection;
第二发送模块56,耦合至第一发送模块54,用于在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接。The second sending module 56 is coupled to the first sending module 54 and configured to send the secure connection establishing indication information to the first remote device, where the secure connection establishing response is used to indicate that the access device of the terminal establishes a secure connection, where The secure connection establishment indication information is used to indicate that the first remote device establishes a secure connection.
可选地,上述连接建立装置可以但不限于应用于终端与Internet网络中的设备传输数据的场景中。例如:使用本地IP接入(Local IP Access,简称为LIPA)与选择性IP流量卸载(Selected IP Traffic Offload,简称为SIPTO)技术。Optionally, the foregoing connection establishing apparatus may be, but is not limited to, being applied to a scenario in which a terminal and a device in an Internet network transmit data. For example, Local IP Access (LIPA for short) and Selective IP Traffic Offload (SIPTO) technology are used.
可选地,上述连接建立装置可以但不限于应用于网络管理设备。Alternatively, the above connection establishing means may be, but not limited to, applied to a network management device.
通过上述步骤,获取模块获取终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;第一发送模块响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;第二发送模块在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接,由此可见,采用上述方案根据安全连接建立请求信息指示终端的接入设备是否建立安全连接,并在允许建立连接的情况下利用安全连接建立指示信息通知第一远端设备建立该安全连接,通过安全连接的建立使数据在安全环境中传输,因此,提高了终端与Internet网络中的设备传输数据的安全性,从而解决了相关技术中终端与Internet网络中的设备传输数据的安全性低的问题。The obtaining module acquires the secure connection establishment request information sent by the access device of the terminal, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet. The first sending module sends the secure connection establishment response information to the access device of the terminal in response to the secure connection establishment request information, wherein the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection; the second sending module is The secure connection establishment response is used to send the secure connection establishment indication information to the first remote device, where the security connection establishment indication information is used to indicate that the first remote device establishes a secure connection. Therefore, the foregoing solution is used to indicate whether the access device of the terminal establishes a secure connection according to the secure connection establishment request information, and notify the first remote device to establish the secure connection by using the secure connection establishment indication information when the connection is allowed to be established. Make data through the establishment of a secure connection Transmission security environment, therefore, improve the security of data transmission and Internet terminal devices in a network, so as to solve the security problems of low data transmission terminals and related technologies in the Internet network equipment.
可选地,第一发送模块54用于:在安全连接建立请求信息中携带的第一IP地址用于触发允许终端的接入设备建立安全连接的情况下,向终端的接入设备发送用于指示终端的接入设备建立安全连接的第一安全连接建立响应信息。Optionally, the first sending module 54 is configured to send, when the first IP address carried in the secure connection establishment request information is used to trigger the access device of the terminal to establish a secure connection, to send to the access device of the terminal, The first secure connection establishment response information indicating that the access device of the terminal establishes a secure connection.
可选地,第一发送模块54用于:在安全连接建立请求信息中携带的第一IP地址用于触发不允许终端的接入设备建立安全连接的情况下,向终端的接入设备发送用于指示终端的接入设备不建立安全连接的第二安全连接建立响应信息。Optionally, the first sending module 54 is configured to: when the first IP address carried in the secure connection establishment request information is used to trigger the access device that does not allow the terminal to establish a secure connection, send the information to the access device of the terminal. Establishing response information for the second secure connection indicating that the access device of the terminal does not establish a secure connection.
可选地,第一发送模块54用于:根据第一IP地址确定与终端的接入设备建立安全连接的第二远端设备,其中,第二远端设备包括第一IP地址对应的设备或者第一IP地址对应的设备所在网络中的网络设备;向终端的接入设备发送第一安全连接建立响应信息,其中,第一安全连接建立响应信息携带有第二远端设备的第二IP地址和安全连接的配置信息。Optionally, the first sending module 54 is configured to: determine, according to the first IP address, a second remote device that establishes a secure connection with the access device of the terminal, where the second remote device includes the device corresponding to the first IP address or The network device in the network where the device corresponding to the first IP address is located; the first secure connection establishment response information is sent to the access device of the terminal, where the first secure connection establishment response information carries the second IP address of the second remote device Configuration information for secure connections.
可选地,第一IP地址对应的设备所在网络中的网络设备包括以下之一:服务提供商部署第一IP地址对应的设备所在网络中的网络设备时登记的第一IP地址对应的设备所在网络的安全网关或者路由器;使用第一IP地址对应的终端设备接入网络时登记的第一IP地址对应的终端设备接入的接入点设备、安全网关或者路由器;第一远端设备。Optionally, the network device in the network where the device corresponding to the first IP address is located includes one of the following: the device corresponding to the first IP address registered when the service provider deploys the network device in the network where the device corresponding to the first IP address is located The security gateway or the router of the network; the access point device, the security gateway or the router accessed by the terminal device corresponding to the first IP address registered when the terminal device corresponding to the first IP address accesses the network; the first remote device.
可选地,第一发送模块54用于:在终端的接入设备的IP地址与第一IP地址属于同一服务提供商部署的设备的IP地址的情况下,确定安全连接建立请求信息中携带的第一IP地址用于触发允许终端的接入设备建立安全连接,其中,服务提供商部署的设备包括:接入设备、终端设备或者用户终端。Optionally, the first sending module 54 is configured to: when the IP address of the access device of the terminal and the IP address of the device where the first IP address belongs to the same service provider, determine the information carried in the secure connection establishment request information. The first IP address is used to trigger an access device that allows the terminal to establish a secure connection, where the device deployed by the service provider includes: an access device, a terminal device, or a user terminal.
可选地,第一发送模块54用于:在终端的接入设备的IP地址与第一IP地址不属于同一服务提供商部署的设备的IP地址的情况下,确定安全连接建立请求信息中携带的第一IP地址用于触发不允许终端的接入设备建立安全连接,其中,服务提供商部署的设备包括:接入设备、终端设备或者用户终端。Optionally, the first sending module 54 is configured to: when the IP address of the access device of the terminal and the IP address of the device where the first IP address does not belong to the same service provider, determine that the secure connection establishment request information is carried in The first IP address is used to trigger an access device that does not allow the terminal to establish a secure connection, where the device deployed by the service provider includes: an access device, a terminal device, or a user terminal.
在本实施例中还提供了另一种连接建立装置,该装置可以但不限于用于终端接入设备,该装置用于实现上述实施例及优选实施方式,已经进行过说明的不再赘述。如以下所使用的,术语“模块”可以实现预定功能的软件和/或硬件的组合。尽管以下实施例所描述的装置较佳地以软件来实现,但是硬件,或者软件和硬件的组合的实现也是可能并被构想的。Another connection establishment device is also provided in this embodiment, and the device may be used for the terminal access device, and the device is used to implement the foregoing embodiments and preferred embodiments, and details are not described herein. As used below, the term "module" may implement a combination of software and/or hardware of a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware, is also possible and contemplated.
图6是根据本申请实施例的一种连接建立装置的结构框图二,如图6所示,该装置包括:FIG. 6 is a structural block diagram 2 of a connection establishing apparatus according to an embodiment of the present application. As shown in FIG. 6, the apparatus includes:
第三发送模块62,用于向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;The third sending module 62 is configured to send the secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request to establish a secure connection with the first remote device in the Internet;
接收模块64,耦合至第三发送模块62,用于接收安全连接管理设备响应于安全连接建立请求信息的安全连接建立响应信息,其中, 安全连接建立响应信息用于指示是否建立安全连接;The receiving module 64 is coupled to the third sending module 62, configured to receive the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether to establish a secure connection;
建立模块66,耦合至接收模块64,用于在安全连接建立响应用于指示建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接。The establishing module 66 is coupled to the receiving module 64, for establishing a secure connection according to the indication of the secure connection establishment response information, in case the secure connection establishment response is used to indicate that the secure connection is established.
可选地,上述连接建立装置可以但不限于应用于终端与Internet网络中的设备传输数据的场景中。例如:使用本地IP接入(Local IP Access,简称为LIPA)与选择性IP流量卸载(Selected IP Traffic Offload,简称为SIPTO)技术。Optionally, the foregoing connection establishing apparatus may be, but is not limited to, being applied to a scenario in which a terminal and a device in an Internet network transmit data. For example, Local IP Access (LIPA for short) and Selective IP Traffic Offload (SIPTO) technology are used.
可选地,上述连接建立装置可以但不限于应用于终端的接入设备,例如:无线网络接入点、服务网关等。Optionally, the foregoing connection establishing apparatus may be, but not limited to, an access device applied to the terminal, such as a wireless network access point, a service gateway, or the like.
通过上述装置,第三发送模块向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;第二接收模块接收安全连接管理设备响应于安全连接建立请求信息的安全连接建立响应信息,其中,安全连接建立响应信息用于指示是否建立安全连接;建立模块在安全连接建立响应用于指示建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接,由此可见,采用上述方案通过发送安全连接建立请求信息请求建立安全连接,接收响应于上述安全连接建立响应信息,并根据安全连接建立响应信息的指示建立安全连接,通过安全连接的建立使数据在安全环境中传输,因此,提高了终端与Internet网络中的设备传输数据的安全性,从而解决了相关技术中终端与Internet网络中的设备传输数据的安全性低的问题。Through the above device, the third sending module sends the secure connection establishment request information to the secure connection management device, wherein the secure connection establishment request information is used to request to establish a secure connection with the first remote device in the Internet; the second receiving module Receiving the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, wherein the secure connection establishment response information is used to indicate whether to establish a secure connection; and the establishing module is configured to indicate that the secure connection is established in response to the secure connection establishment response Establishing a secure connection according to the indication of the security connection establishment response information, so that the foregoing solution is used to establish a secure connection by sending a secure connection establishment request information, receiving response information in response to the secure connection establishment, and establishing response information according to the secure connection. Indicates that a secure connection is established, and data is transmitted in a secure environment through the establishment of a secure connection. Therefore, the security of data transmitted by the terminal and the device in the Internet network is improved, thereby solving the related art in the terminal and the Internet network. The problem of low security of data transmitted by the device.
可选地,第三发送模块用于:对终端数据进行检测,得到终端数据的第一IP地址,其中,第一IP地址为第一远端设备的IP地址;发送携带有第一IP地址的安全连接建立请求信息。Optionally, the third sending module is configured to: detect the terminal data, and obtain a first IP address of the terminal data, where the first IP address is an IP address of the first remote device; and the sending carries the first IP address. Secure connection establishment request information.
可选地,上述装置还包括:判断模块,用于判断是否已建立第一IP地址对应的安全连接;第四发送模块,耦合至判断模块,用于在判断出已建立第一IP地址对应的安全连接的情况下,通过已建立 的第一IP地址对应的安全连接发送上述终端数据;确定模块,耦合至第四发送模块与第三发送模块之间,用于在判断出未建立第一IP地址对应的安全连接的情况下,确定发送携带有第一IP地址的安全连接建立请求信息。Optionally, the device further includes: a determining module, configured to determine whether a secure connection corresponding to the first IP address has been established; and a fourth sending module, coupled to the determining module, configured to determine that the first IP address is established In the case of a secure connection, the terminal data is sent through the secure connection corresponding to the established first IP address; the determining module is coupled between the fourth sending module and the third sending module, and is configured to determine that the first IP is not established. In the case of a secure connection corresponding to the address, it is determined that the secure connection establishment request information carrying the first IP address is sent.
需要说明的是,上述各个模块是可以通过软件或硬件来实现的,对于后者,可以通过以下方式实现,但不限于此:上述模块均位于同一处理器中;或者,上述模块分别位于多个处理器中。It should be noted that each of the above modules may be implemented by software or hardware. For the latter, the foregoing may be implemented by, but not limited to, the foregoing modules are all located in the same processor; or, the modules are located in multiple In the processor.
实施例3Example 3
在本实施例中还提供了一种连接建立装置,用于安全连接管理设备,该装置包括:第一处理器和第一通讯接口,其中,In the embodiment, a connection establishing device is further provided for securely connecting the management device, the device comprising: a first processor and a first communication interface, wherein
第一处理器,与第一通讯接口连接,第一处理器用于获取通过第一通讯接口接收到的终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;响应于安全连接建立请求信息指示第一通讯接口向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,指示第一通讯接口向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接。The first processor is connected to the first communication interface, and the first processor is configured to acquire secure connection establishment request information sent by the access device of the terminal received through the first communication interface, where the secure connection establishment request information is used to request to establish a secure connection between the access device of the terminal and the first remote device in the Internet; in response to the secure connection establishment request information, the first communication interface sends a secure connection establishment response message to the access device of the terminal, wherein the secure connection is established The response information is used to indicate whether the access device of the terminal establishes a secure connection. In case the secure connection establishment response is used to indicate that the access device of the terminal establishes a secure connection, the first communication interface is instructed to send a secure connection to the first remote device. The indication information, wherein the secure connection establishment indication information is used to indicate that the first remote device establishes a secure connection.
可选地,第一处理器还用于:在安全连接建立请求信息中携带的第一IP地址用于触发允许终端的接入设备建立安全连接的情况下,向终端的接入设备发送用于指示终端的接入设备建立安全连接的第一安全连接建立响应信息。Optionally, the first processor is further configured to send, when the first IP address carried in the secure connection establishment request information is used to trigger the access device of the terminal to establish a secure connection, to send to the access device of the terminal, The first secure connection establishment response information indicating that the access device of the terminal establishes a secure connection.
可选地,第一处理器还用于:在安全连接建立请求信息中携带的第一IP地址用于触发不允许终端的接入设备建立安全连接的情况下,向终端的接入设备发送用于指示终端的接入设备不建立安全连接的第二安全连接建立响应信息。Optionally, the first processor is further configured to: when the first IP address carried in the secure connection establishment request information is used to trigger the access device that does not allow the terminal to establish a secure connection, send the information to the access device of the terminal. Establishing response information for the second secure connection indicating that the access device of the terminal does not establish a secure connection.
可选地,第一处理器还用于:根据第一IP地址确定与终端的接入设备建立安全连接的第二远端设备,其中,第二远端设备包括第一IP地址对应的设备或者第一IP地址对应的设备所在网络中的网络设备;向终端的接入设备发送第一安全连接建立响应信息,其中,第一安全连接建立响应信息携带有第二远端设备的第二IP地址和安全连接的配置信息Optionally, the first processor is further configured to: determine, according to the first IP address, a second remote device that establishes a secure connection with the access device of the terminal, where the second remote device includes the device corresponding to the first IP address or The network device in the network where the device corresponding to the first IP address is located; the first secure connection establishment response information is sent to the access device of the terminal, where the first secure connection establishment response information carries the second IP address of the second remote device And secure connection configuration information
可选地,第一IP地址对应的设备所在网络中的网络设备包括以下之一:服务提供商部署第一IP地址对应的设备所在网络中的网络设备时登记的第一IP地址对应的设备所在网络的安全网关或者路由器;使用第一IP地址对应的终端设备接入网络时登记的第一IP地址对应的终端设备接入的接入点设备、安全网关或者路由器;第一远端设备。Optionally, the network device in the network where the device corresponding to the first IP address is located includes one of the following: the device corresponding to the first IP address registered when the service provider deploys the network device in the network where the device corresponding to the first IP address is located The security gateway or the router of the network; the access point device, the security gateway or the router accessed by the terminal device corresponding to the first IP address registered when the terminal device corresponding to the first IP address accesses the network; the first remote device.
可选地,第一处理器还用于:在终端的接入设备的IP地址与第一IP地址属于同一服务提供商部署的设备的IP地址的情况下,确定安全连接建立请求信息中携带的第一IP地址用于触发允许终端的接入设备建立安全连接,其中,服务提供商部署的设备包括:接入设备、终端设备或者用户终端。Optionally, the first processor is further configured to: when the IP address of the access device of the terminal and the IP address of the device where the first IP address belongs to the same service provider, determine the information carried in the secure connection establishment request information. The first IP address is used to trigger an access device that allows the terminal to establish a secure connection, where the device deployed by the service provider includes: an access device, a terminal device, or a user terminal.
可选地,第一处理器还用于:在终端的接入设备的IP地址与第一IP地址不属于同一服务提供商部署的设备的IP地址的情况下,确定安全连接建立请求信息中携带的第一IP地址用于触发不允许终端的接入设备建立安全连接,其中,服务提供商部署的设备包括:接入设备、终端设备或者用户终端。Optionally, the first processor is further configured to: when the IP address of the access device of the terminal and the IP address of the device where the first IP address does not belong to the same service provider, determine that the secure connection establishment request information is carried in The first IP address is used to trigger an access device that does not allow the terminal to establish a secure connection, where the device deployed by the service provider includes: an access device, a terminal device, or a user terminal.
在本实施例中还提供了一种连接建立装置,用于终端接入设备,该装置包括:第二处理器和第二通讯接口,其中,In the embodiment, a connection establishing device is further provided for the terminal access device, the device comprising: a second processor and a second communication interface, wherein
第二处理器,与第二通讯接口连接,第二处理器用于指示第二通讯接口向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;通过第二通讯接口接收安全连接管理设备响应于安全连接建立请求信息的安全连接建立响应信息,其中,安全连接建 立响应信息用于指示是否建立安全连接;在安全连接建立响应用于指示建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接。The second processor is connected to the second communication interface, where the second processor is configured to instruct the second communication interface to send the secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request to establish the a secure connection between the remote devices; receiving, by the second communication interface, the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, wherein the secure connection establishment response information is used to indicate whether to establish a secure connection; The secure connection setup response is used to indicate that a secure connection is established, and a secure connection is established based on the indication of the secure connection establishment response information.
可选地,第二处理器还用于:对终端数据进行检测,得到终端数据的第一IP地址,其中,第一IP地址为第一远端设备的IP地址;发送携带有第一IP地址的安全连接建立请求信息。Optionally, the second processor is further configured to: detect the terminal data, and obtain a first IP address of the terminal data, where the first IP address is an IP address of the first remote device; and the sending carries the first IP address. The secure connection establishes the request information.
可选地,第二处理器还用于:判断是否已建立第一IP地址对应的安全连接;在判断出已建立第一IP地址对应的安全连接的情况下,通过已建立的第一IP地址对应的安全连接发送上述终端数据;在判断出未建立第一IP地址对应的安全连接的情况下,确定发送携带有第一IP地址的安全连接建立请求信息。Optionally, the second processor is further configured to: determine whether a secure connection corresponding to the first IP address has been established; and if it is determined that the secure connection corresponding to the first IP address is established, pass the established first IP address. The corresponding secure connection sends the terminal data. If it is determined that the secure connection corresponding to the first IP address is not established, it is determined that the secure connection establishment request information carrying the first IP address is sent.
下面结合本申请可选实施例进行详细说明。The following is a detailed description in conjunction with the optional embodiments of the present application.
在相关技术中,UE的接入设备(无线网络接入点或者本地网关)一般是跟核心网的安全网关之间建立有安全连接(如IPSec隧道,VPN连接),但是从UE的接入设备分流到Internet的数据或Internet发送到UE的接入设备的数据不经过核心网,因此分流到Internet的数据缺少安全保证机制,很容易被网络黑客攻击、窃取或篡改。In the related art, an access device (a wireless network access point or a local gateway) of a UE generally establishes a secure connection (such as an IPSec tunnel, a VPN connection) with a security gateway of a core network, but an access device from the UE. The data that is offloaded to the Internet or the data that the Internet sends to the access device of the UE does not pass through the core network. Therefore, the data that is offloaded to the Internet lacks a security guarantee mechanism, and is easily attacked, stolen, or tampered with by network hackers.
本申请可选实施例提供了一种建立安全连接的方法,在应用本地卸载技术的无线通信网络中使用该方法,可以保障从UE从接入设备直接分流到Internet的数据或者从Internet直接经由UE接入设备发送给UE的数据的安全性。An optional embodiment of the present application provides a method for establishing a secure connection. In the wireless communication network to which the local offloading technology is applied, the method can be used to ensure that data that is directly offloaded from the UE to the Internet from the access device or directly from the Internet via the UE. The security of the data sent by the access device to the UE.
下面通过几个可选实施例对本申请可选实施例提供的建立安全连接的方法进行描述与说明。The method for establishing a secure connection provided by an alternative embodiment of the present application is described and illustrated below through several alternative embodiments.
可选实施例一Alternative embodiment 1
本可选实施例提供了一种建立安全连接的方法,可以但不限于用于采用LIPA技术进行本地业务分流的无线网络中。图7是根据本申请可选实施例的一种建立安全连接的方法的示意图一,如图7所示,UE的接入设备为无线网络接入点,采用该方法可保证经由UE的接入设备直接接入Internet的数据的安全性。该流程包括以下步 骤:This alternative embodiment provides a method for establishing a secure connection, which may be, but is not limited to, a wireless network for performing local service offload using LIPA technology. FIG. 7 is a first schematic diagram of a method for establishing a secure connection according to an alternative embodiment of the present application. As shown in FIG. 7 , an access device of a UE is a wireless network access point, and the method can ensure access via a UE. The security of data directly connected to the Internet by the device. The process includes the following steps:
步骤S702,无线网络接入点对所接入的使用LIPA技术进行本地分流的UE数据进行检测,获取UE通过无线接入点的L-GW直接发送或接收数据的IP地址。Step S702: The wireless network access point detects the accessed UE data that is locally offloaded by using the LIPA technology, and acquires an IP address that the UE directly sends or receives data through the L-GW of the wireless access point.
在本可选实施例中,上述无线网络接入点为已配置自动建立安全连接功能的无线接入设备。管理设备可根据网络管理策略为无线网络接入点配置自动建立安全连接的功能,当无线网络接入点配置有自动建立安全连接功能后,对所接入的使用LIPA技术进行本地IP业务分流的UE进行IP数据包检测,以便于获得该UE发送的端到端数据包的远端IP地址,并进一步地建立针对该IP地址的安全连接。由于实际网络结构和业务的多样性,无线网络接入点检测到的IP地址可能为终端用户/目标服务器的IP地址,也可能是终端用户/目标服务器所连接的无线网络接入点的IP地址,还可能是终端用户/目标服务器所连接的安全网关或路由器的IP地址。该安全连接可以是直接与该IP地址建立的安全连接,也可以是与该IP所属网络的网络设备((无线)接入点、安全网关或路由器)之间建立的安全连接。该安全连接可以是标准的IPSec隧道也可以是任何私有安全连接。In this optional embodiment, the wireless network access point is a wireless access device configured to automatically establish a secure connection function. The management device can configure the wireless network access point to automatically establish a secure connection according to the network management policy. When the wireless network access point is configured to automatically establish a secure connection function, the accessed IPPA technology is used to perform local IP service offloading. The UE performs IP packet inspection to obtain the remote IP address of the end-to-end packet sent by the UE, and further establishes a secure connection for the IP address. Due to the actual network structure and service diversity, the IP address detected by the wireless network access point may be the IP address of the end user/target server, or the IP address of the wireless network access point to which the end user/target server is connected. It may also be the IP address of the security gateway or router to which the end user/target server is connected. The secure connection may be a secure connection established directly with the IP address, or may be a secure connection established with a network device ((wireless) access point, security gateway or router) of the network to which the IP belongs. The secure connection can be a standard IPSec tunnel or any private secure connection.
步骤S704,无线网络接入点判断是否已建立有针对上述IP地址的安全连接,若没有建立,则向管理设备发送自动安全连接建立请求,其中携带有上述IP地址。Step S704, the wireless network access point determines whether a secure connection for the IP address has been established, and if not, sends an automatic secure connection establishment request to the management device, where the IP address is carried.
在本可选实施例中,无线网络接入点判断是否已建立针对该IP地址的安全连接,包括与该IP地址建立有安全连接或者与该IP所属的网络中的网络设备((无线)接入点、安全网关或路由器)之间已建立有安全连接,若已建立则通过该IP地址的安全连接发送向该IP地址的数据或者从安全连接接收来自该IP地址的数据;若没有建立,则向管理设备发送自动安全连接建立请求,其中携带有上述IP地址,以请求建立针对该IP地址的安全连接。In this alternative embodiment, the wireless network access point determines whether a secure connection to the IP address has been established, including establishing a secure connection with the IP address or a network device (wireless) in the network to which the IP belongs. A secure connection has been established between the ingress point, the security gateway or the router. If it is established, the data to the IP address is sent over the secure connection of the IP address or the data from the IP address is received from the secure connection; if not, And sending an automatic secure connection establishment request to the management device, where the IP address is carried, to request to establish a secure connection for the IP address.
步骤S706,管理设备收到自动安全连接建立请求后,向无线网络接入点发送自动安全连接建立响应,以指示无线网络接入点是否 建立针对该IP地址的安全连接。Step S706: After receiving the automatic secure connection establishment request, the management device sends an automatic secure connection establishment response to the wireless network access point to indicate whether the wireless network access point establishes a secure connection for the IP address.
在本可选实施例中,管理设备收到自动安全连接建立请求后,确定是否允许无线网络接入点建立针对该IP地址的安全连接。例如,当保存有该IP地址的相关信息,如子网掩码、无线接入点、安全网关或路由器地址、建立针对该IP地址的安全连接的目标IP地址和安全连接配置信息时,管理设备允许建立针对该IP地址的安全连接。In this optional embodiment, after receiving the automatic secure connection establishment request, the management device determines whether the wireless network access point is allowed to establish a secure connection for the IP address. For example, when the related information of the IP address, such as a subnet mask, a wireless access point, a security gateway or a router address, a destination IP address and a secure connection configuration information for establishing a secure connection to the IP address, are saved, the management device is managed. Allows a secure connection to be established for this IP address.
若不允许建立,则向无线网络接入点发送自动安全连接建立响应指示无线网络接入点不建立针对该IP地址的安全连接。If setup is not allowed, an automatic secure connection setup response is sent to the wireless network access point indicating that the wireless network access point does not establish a secure connection for the IP address.
否则,允许建立,则向无线网络接入点发送自动安全连接建立响应指示无线网络接入点建立针对该IP地址的安全连接。Otherwise, to allow establishment, an automatic secure connection setup response is sent to the wireless network access point instructing the wireless network access point to establish a secure connection for the IP address.
自动安全连接建立响应中包含针对该IP地址建立的安全连接的远端设备IP地址和该安全连接的配置信息,其中,该安全连接的远端设备可以是该IP地址设备或者该IP地址设备所属的网络中的网络设备(如接入点设备、安全网关或路由器等)。The automatic secure connection establishment response includes a remote device IP address and a configuration information of the secure connection for the secure connection established by the IP address, wherein the remote device of the secure connection may be the IP address device or the IP address device belongs to Network devices in the network (such as access point devices, security gateways, routers, etc.).
其中,上述安全连接的配置信息包括本地标识(本地IP地址或本地主机名)、远端标识(远端IP地址或远端主机名)、安全协议、所要保护的数据流(例如以UDP/TCP端口号标识)、密钥和算法信息,其中密钥和算法包括该安全连接使用的身份认证、数据完整性保护或数据加密所需的密钥和算法。举例来说,若安全连接为IPSec隧道,则配置信息包括IKE策略(IKE的hash算法、加密算法、D-H组和生存时间)、预共享密钥、所要保护的数据流、本地标识、远端标识、所要保护的数据流使用的加密算法和安全协议、IPSec SA的生存时间、是否支持PFS等。The configuration information of the foregoing secure connection includes a local identifier (local IP address or local host name), a remote identifier (a remote IP address or a remote host name), a security protocol, and a data stream to be protected (for example, UDP/TCP) Port number identification), key and algorithm information, where the key and algorithm include the keys and algorithms required for identity authentication, data integrity protection, or data encryption used by the secure connection. For example, if the secure connection is an IPSec tunnel, the configuration information includes an IKE policy (the IKE hash algorithm, the encryption algorithm, the DH group, and the lifetime), the pre-shared key, the data stream to be protected, the local identifier, and the remote identifier. The encryption algorithm and security protocol used by the data stream to be protected, the lifetime of the IPSec SA, and whether PFS is supported.
步骤S708,若管理设备指示无线网络接入点建立针对该IP地址的安全连接,管理设备向该安全连接的远端设备发送自动安全连接建立指示消息。Step S708: If the management device instructs the wireless network access point to establish a secure connection for the IP address, the management device sends an automatic secure connection establishment indication message to the remotely connected remote device.
根据以上步骤,若管理设备指示无线网络接入点建立针对该IP地址的安全连接,则管理设备向该安全连接的远端设备发送自动安全连接建立指示消息,其中包括该安全连接的配置信息,以便于该 无线网络接入点与该远端设备之间建立针对该IP地址的安全连接。例如,如图3所示,安全连接的远端设备为一个网关设备,管理设备向该网关设备发送自动安全连接建立指示消息。According to the above steps, if the management device instructs the wireless network access point to establish a secure connection for the IP address, the management device sends an automatic secure connection establishment indication message to the remotely connected remote device, including configuration information of the secure connection, A secure connection for the IP address is established between the wireless network access point and the remote device. For example, as shown in FIG. 3, the remotely connected device is a gateway device, and the management device sends an automatic secure connection establishment indication message to the gateway device.
其中,上述安全连接的配置信息包括本地标识(本地IP地址或本地主机名)、远端标识(远端IP地址或远端主机名)、安全协议、所要保护的数据流(例如以UDP/TCP端口号标识)、密钥和算法信息,其中密钥和算法包括该安全连接使用的身份认证、数据完整性保护或数据加密所需的密钥和算法。举例来说,若安全连接为IPSec隧道,则配置信息包括IKE策略(IKE的hash算法、加密算法、D-H组和生存时间)、预共享密钥、所要保护的数据流、本地标识、远端标识、所要保护的数据流使用的加密算法和安全协议、IPSec SA的生存时间、是否支持PFS等。The configuration information of the foregoing secure connection includes a local identifier (local IP address or local host name), a remote identifier (a remote IP address or a remote host name), a security protocol, and a data stream to be protected (for example, UDP/TCP) Port number identification), key and algorithm information, where the key and algorithm include the keys and algorithms required for identity authentication, data integrity protection, or data encryption used by the secure connection. For example, if the secure connection is an IPSec tunnel, the configuration information includes an IKE policy (the IKE hash algorithm, the encryption algorithm, the DH group, and the lifetime), the pre-shared key, the data stream to be protected, the local identifier, and the remote identifier. The encryption algorithm and security protocol used by the data stream to be protected, the lifetime of the IPSec SA, and whether PFS is supported.
步骤S710,无线网络接入点与该远端设备之间建立安全连接,通过安全连接发送该UE发送到该IP地址的数据并通过该安全连接接收来自该IP地址的数据。Step S710: The wireless network access point establishes a secure connection with the remote device, and sends data sent by the UE to the IP address through the secure connection and receives data from the IP address through the secure connection.
例如,无线网络接入点与网关设备之间建立安全连接。For example, a secure connection is established between a wireless network access point and a gateway device.
可选实施例二Alternative embodiment 2
本可选实施例提供了一种建立安全连接的方法,可以但不限于用于采用SIPTO技术进行本地流量卸载的网络中。图8是根据本申请可选实施例的一种建立安全连接的方法的示意图二,如图8所示,UE的接入设备为服务网关,采用该方法可保证经由UE的接入设备直接接入Internet的数据的安全性。该流程包括以下步骤:The present optional embodiment provides a method for establishing a secure connection, which may be, but is not limited to, used in a network for performing local traffic offload using SIPTO technology. FIG. 8 is a second schematic diagram of a method for establishing a secure connection according to an alternative embodiment of the present application. As shown in FIG. 8 , an access device of a UE is a serving gateway, and the method can ensure direct connection of an access device via a UE. The security of data entering the Internet. The process includes the following steps:
步骤S802,服务网关对所接入的使用SIPTO技术进行本地流量卸载的UE数据进行检测,获取UE通过服务网关直接发送或接收数据的IP地址。Step S802: The serving gateway detects the accessed UE data for performing local traffic offloading using the SIPTO technology, and acquires an IP address that the UE directly sends or receives data through the serving gateway.
在本可选实施例中,上述服务网关为已配置自动建立安全连接功能的设备。管理设备可根据网络管理策略为服务网关配置自动建立安全连接的功能,当服务网关配置有自动建立安全连接功能后,对所接入的使用SIPTO技术进行本地IP流量卸载的UE进行IP数 据包检测,以便于获得该UE发送的端到端数据包的远端IP地址,并进一步地建立针对该IP地址的安全连接。由于实际网络结构和业务的多样性,服务网关检测到的IP地址可能为终端用户/目标服务器的IP地址,也可能是终端用户/目标服务器所连接的无线网络接入点的IP地址,还可能是终端用户/目标服务器所连接的安全网关或路由器的IP地址。该安全连接可以是直接与该IP地址建立的安全连接,也可以是与该IP所连接的无线接入点、安全网关或路由器之间建立的安全连接。In this optional embodiment, the service gateway is a device that has been configured to automatically establish a secure connection function. The management device can configure the automatic establishment of a secure connection function for the service gateway according to the network management policy. When the service gateway is configured with the automatic establishment of the secure connection function, the IP data packet detection is performed on the UE that is connected to the local IP traffic offload using the SIPTO technology. In order to obtain the remote IP address of the end-to-end data packet sent by the UE, and further establish a secure connection for the IP address. Due to the actual network structure and service diversity, the IP address detected by the service gateway may be the IP address of the end user/target server, or the IP address of the wireless network access point to which the end user/target server is connected. Is the IP address of the security gateway or router to which the end user/target server is connected. The secure connection may be a secure connection established directly with the IP address or a secure connection established between the wireless access point, security gateway or router to which the IP is connected.
步骤S804,服务网关判断是否已建立有针对上述IP地址的安全连接,若没有建立,则向管理设备发送自动安全连接建立请求,其中携带有上述IP地址。Step S804, the serving gateway determines whether a secure connection for the IP address has been established, and if not, sends an automatic secure connection establishment request to the management device, where the IP address is carried.
本步骤的具体实现方式与上述步骤S704类似,在此不再赘述。The specific implementation of this step is similar to the foregoing step S704, and details are not described herein again.
步骤S806,管理设备收到自动安全连接建立请求后,向服务网关发送自动安全连接建立响应,以指示服务网关是否建立针对该IP地址的安全连接。Step S806, after receiving the automatic secure connection establishment request, the management device sends an automatic secure connection establishment response to the service gateway to indicate whether the service gateway establishes a secure connection for the IP address.
本步骤的具体实现方式与上述步骤S706类似,在此不再赘述。The specific implementation of this step is similar to the foregoing step S706, and details are not described herein again.
步骤S808,若管理设备指示服务网关建立针对该IP地址的安全连接,管理设备向该安全连接的远端设备发送自动安全连接建立指示消息。Step S808: If the management device instructs the serving gateway to establish a secure connection for the IP address, the management device sends an automatic secure connection establishment indication message to the remotely connected remote device.
根据以上步骤,若管理设备指示服务网关建立针对该IP地址的安全连接,则管理设备向该安全连接的远端设备发送自动安全连接建立指示消息,其中包括该安全连接的配置信息,以便于该服务网关与该远端设备之间建立针对该IP地址的安全连接。例如,如图4所示,安全连接的远端设备为一个无线接入点设备,管理设备向该无线接入点设备发送自动安全连接建立指示消息。According to the above steps, if the management device instructs the service gateway to establish a secure connection for the IP address, the management device sends an automatic secure connection establishment indication message to the remote device of the secure connection, including configuration information of the secure connection, to facilitate the A secure connection is established between the serving gateway and the remote device for the IP address. For example, as shown in FIG. 4, the remotely connected remote device is a wireless access point device, and the management device sends an automatic secure connection establishment indication message to the wireless access point device.
步骤S810,服务网关与该远端设备之间建立安全连接,通过安全连接发送该UE发送到该IP地址的数据并通过该安全连接接收来自该IP地址的数据。Step S810, the serving gateway establishes a secure connection with the remote device, and sends data sent by the UE to the IP address through the secure connection and receives data from the IP address through the secure connection.
例如,服务网关与无线接入点设备之间建立安全连接。For example, a secure connection is established between the serving gateway and the wireless access point device.
可选实施例三Alternative embodiment three
本可选实施例描述上述可选实施例一的步骤S706以及上述可选实施例二的步骤S806,在本可选实施例中,管理设备收到自动安全连接建立请求后,向UE的接入设备(无线接入点或服务网关)发送自动安全连接建立响应,以指示UE的接入设备是否建立针对请求消息中指定的IP地址的安全连接的具体实施方法。The optional embodiment describes the step S706 of the foregoing optional embodiment 1 and the step S806 of the optional embodiment 2. In the optional embodiment, after the management device receives the automatic secure connection establishment request, the management device accesses the UE. The device (wireless access point or serving gateway) sends an automatic secure connection setup response to indicate whether the access device of the UE establishes a secure connection for the secure connection specified in the request message.
管理设备收到自动安全连接建立请求后,确定是否允许建立针对该IP地址的安全连接。例如,当保存有该IP地址的相关信息,如子网掩码、无线接入点、安全网关或路由器地址、建立针对该IP地址的安全连接的目标IP地址和安全连接配置信息时,管理设备允许建立针对该IP地址的安全连接。After receiving the automatic secure connection establishment request, the management device determines whether to establish a secure connection for the IP address. For example, when the related information of the IP address, such as a subnet mask, a wireless access point, a security gateway or a router address, a destination IP address and a secure connection configuration information for establishing a secure connection to the IP address, are saved, the management device is managed. Allows a secure connection to be established for this IP address.
若不允许建立,则向UE的接入设备发送自动安全连接建立响应指示无线网络接入点不建立针对该IP地址的安全连接。If setup is not allowed, an automatic secure connection setup response is sent to the access device of the UE indicating that the wireless network access point does not establish a secure connection for the IP address.
否则,允许建立,管理设备首先确定针对该IP地址的安全连接的远端设备。该远端设备可以是该IP地址设备或该IP地址设备所属的网络中的网络设备。Otherwise, the establishment is allowed, and the management device first determines the remote device for the secure connection of the IP address. The remote device may be the IP address device or a network device in a network to which the IP address device belongs.
在一些可行的实施方式中,该IP地址设备所属的网络中的网络设备为服务提供商部署该IP地址的网络设备时在管理设备处登记的其所属网络的安全网关或路由器的IP地址,或者为,使用该IP地址的终端设备接入网络时,在管理设备中登记的该IP地址的终端设备所接入的接入点设备、安全网关或路由器的IP地址。In some feasible implementation manners, the network device in the network to which the IP address device belongs is the IP address of the security gateway or router of the network to which the service provider registers when the service provider deploys the network device of the IP address, or The IP address of the access point device, security gateway, or router accessed by the terminal device of the IP address registered in the management device when the terminal device using the IP address accesses the network.
在一些可行的实施方式中,该IP地址设备所属的网络中的网络设备为UE的接入设备发送的自动安全连接建立请求所指示的远端设备。其中,自动安全连接建立请求所指示的远端设备的地址是UE的接入设备通过自动路由发现功能获取的设备地址。UE的接入设备在发送安全连接建立请求之前,可以通过自动路由发现功能获取数据到达该IP地址所经路径上的网关和路由器的地址。In some possible implementations, the network device in the network to which the IP address device belongs is the remote device indicated by the automatic secure connection establishment request sent by the access device of the UE. The address of the remote device indicated by the automatic secure connection establishment request is the device address obtained by the access device of the UE through the automatic route discovery function. The access device of the UE may obtain the address of the gateway and the router on the path through which the data arrives by the automatic route discovery function before sending the secure connection establishment request.
自动路由发现的实现就是利用了ICMP协议对TTL超时报文的处理。其实现过程如下:源主机先向目的主机发送一个回应请求报文 (IP协议类型8),其中TTL值设为1,第一个路由器收到后将TTL减1,这样TTL变为0,分组被丢弃,同时第一个路由器向源主机发送一个TTL超时报文(IP协议类型为11),其IP包头中的源IP地址就是第一个路由器的IP地址。源主机就可以通过对该TTL超时报文的分析得到第一个路由器的IP地址,使用同样的方法,源主机发送TTL等于2的报文得到第二个路由器地址,发送TTL为3的报文,如此下去直到收到目的主机的回应应答报文(IP协议类型为0)或目的不可达报文(IP协议类型为3)。The implementation of automatic route discovery is to use the ICMP protocol to process TTL timeout packets. The implementation process is as follows: The source host first sends an echo request message (IP protocol type 8) to the destination host, where the TTL value is set to 1, and the first router receives the TTL minus 1, so that the TTL becomes 0, the packet is The first router sends a TTL timeout packet (the IP protocol type is 11) to the source host. The source IP address in the IP header is the IP address of the first router. The source host can obtain the IP address of the first router by analyzing the TTL timeout packet. In the same way, the source host sends a packet with the TTL equal to 2 to obtain the second router address, and sends a packet with the TTL of 3. The process continues until the destination host receives an echo response message (IP protocol type is 0) or destination unreachable message (IP protocol type is 3).
然后,管理设备向无线网络接入点或服务网关发送自动安全连接建立响应指示无线网络接入点建立针对该IP地址的安全连接。The management device then sends an automatic secure connection setup response to the wireless network access point or the serving gateway instructing the wireless network access point to establish a secure connection for the IP address.
自动安全连接建立响应中包含针对该IP地址建立的安全连接的远端设备IP地址和该安全连接的配置信息。The automatic secure connection setup response includes the remote device IP address of the secure connection established for the IP address and configuration information of the secure connection.
可选实施例四Alternative embodiment four
本可选实施例描述上述可选实施例一的步骤S706以及上述可选实施例二的步骤S806,在本可选实施例中,管理设备收到自动安全连接建立请求后确定是否允许建立针对指定IP地址的安全连接的具体实施方法。The optional embodiment describes the step S706 of the foregoing optional embodiment 1 and the step S806 of the optional embodiment 2. In the optional embodiment, after the management device receives the automatic secure connection establishment request, it is determined whether to allow the establishment of the designated A specific implementation method of a secure connection of an IP address.
在一些可行的实施方式中,支持对指定服务提供商(包括运营商、设备提供商或内容提供商)的UE的直接由接入点或服务网关分流到Internet的数据进行安全性保护。具体的,管理设备可以判断UE的接入设备(例如无线接入设备或服务网关设备)与自动安全连接建立请求中的IP地址分别属于同一个服务提供商部署的接入设备和用户终端的IP地址,或者判断UE的接入设备与该IP地址属于同一个服务提供商所部署的网络设备,若是则允许建立针对该IP地址的安全连接,否则不允许建立。In some possible implementations, data protection for data destined for the Internet directly by an access point or a serving gateway of a UE of a designated service provider (including an operator, a device provider, or a content provider) is supported. Specifically, the management device may determine that the IP address in the access device (for example, the wireless access device or the service gateway device) of the UE and the automatic security connection establishment request belong to the access device and the IP address of the user terminal deployed by the same service provider. Address, or determine that the access device of the UE and the IP address belong to the network device deployed by the same service provider. If yes, the secure connection for the IP address is allowed to be established, otherwise the establishment is not allowed.
为了使管理设备能够根据自动安全连接建立请求中的IP地址判断是否允许建立安全连接,管理设备可以保存指定服务提供商所部署的网络设备(包括(无线)接入点设备、安全网关或路由器)的IP地址。当终端设备接入指定运营商、设备提供商、服务提供商或内 容提供商所部署的网络时,管理设备保存该终端设备的IP地址;特别地,为了建立与终端设备所连接的网络设备(接入点设备、安全网关或路由器)之间的安全连接,终端接入指定服务提供商所部署的网络时,管理设备还可同时保存终端设备的IP地址及其所接入的网络设备(无线接入点设备、安全网关或路由器)的IP地址。In order to enable the management device to determine whether to allow a secure connection to be established according to the IP address in the automatic secure connection establishment request, the management device may save the network device (including (wireless) access point device, security gateway or router) deployed by the specified service provider. IP address. When the terminal device accesses a network deployed by a designated operator, a device provider, a service provider, or a content provider, the management device saves the IP address of the terminal device; in particular, in order to establish a network device connected to the terminal device ( A secure connection between an access point device, a security gateway, or a router. When the terminal accesses a network deployed by a specified service provider, the management device can also save the IP address of the terminal device and the network device to which it is connected (wireless IP address of the access point device, security gateway, or router.
可选地,本申请中所述的无线接入点,可以是蜂窝移动通信网络中的基站(或手机)、WiFi的AP、蓝牙接收设备,或者其它能够发送或接收无线信号的设备,包括用户设备(终端)、个人数字助理(PDA)、无线调制调解器、无线通信装置、手持装置、膝上型计算机、无绳电话、无线本地回路(WLL)站、能够将移动信号转换为wifi信号的CPE或Mifi、智能家电、或其它不通过人的操作就能自发与移动通信网络通信的设备等。Optionally, the wireless access point described in this application may be a base station (or mobile phone) in a cellular mobile communication network, an AP of a WiFi, a Bluetooth receiving device, or other device capable of transmitting or receiving a wireless signal, including a user. Devices (terminals), personal digital assistants (PDAs), wireless modems, wireless communication devices, handheld devices, laptop computers, cordless phones, wireless local loop (WLL) stations, CPE capable of converting mobile signals into wifi signals Or Mifi, smart home appliances, or other devices that can spontaneously communicate with the mobile communication network without human intervention.
可选地,在本申请中,基站的形式不限,可以是宏基站(Macro Base Station)、微基站(Pico Base Station)、Node B、增强型基站(ENB)、家庭增强型基站(Femto eNB或Home eNode B或Home eNB或HENB)、中继站、接入点、RRU、RRH等。Optionally, in the present application, the form of the base station is not limited, and may be a Macro Base Station, a Pico Base Station, a Node B, an Enhanced Base Station (ENB), and a Home Enhanced Base Station (Femto eNB). Or Home eNode B or Home eNB or HENB), relay station, access point, RRU, RRH, etc.
综上所述,在应用本地卸载技术的无线通信网络中使用本申请实施例、可选实施例提供的连接建立方法,可以保障从UE从接入设备直接分流到Internet的数据或者从Internet直接经由UE接入设备发送给UE的数据的安全性。In summary, in the wireless communication network to which the local offloading technology is applied, the connection establishment method provided by the embodiment and the optional embodiment of the present application can ensure that data that is directly offloaded from the UE to the Internet from the access device or directly from the Internet. The security of the data that the UE accesses the device to send to the UE.
以上实施例仅用以说明本申请的技术方案而非对其进行限制,本领域的普通技术人员可以对本申请的技术方案进行修改或者等同替换,而不脱离本申请的精神和范围,本申请的保护范围应以权利要求所述为准。The above embodiments are only used to describe the technical solutions of the present application, and the technical solutions of the present application may be modified or equivalently replaced by those skilled in the art without departing from the spirit and scope of the present application. The scope of protection shall be as stated in the claims.
实施例3Example 3
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到根据上述实施例的方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技 术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,或者网络设备等)执行本申请各个实施例所述的方法。Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, by hardware, but in many cases, the former is A better implementation. Based on such understanding, the technical solution of the present application, which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a storage medium (such as ROM/RAM, disk, The optical disc includes a number of instructions for causing a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) to perform the methods described in various embodiments of the present application.
本申请的实施例还提供了一种存储介质。可选地,在本实施例中,上述存储介质可以被设置为存储用于执行以下步骤的程序代码:Embodiments of the present application also provide a storage medium. Optionally, in the embodiment, the foregoing storage medium may be configured to store program code for performing the following steps:
S11,获取终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;S11, the secure connection establishment request information sent by the access device of the terminal is obtained, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet;
S12,响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;S12. The security connection establishment response information is sent to the access device of the terminal, where the security connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection.
S13,在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接。S13, in the case that the secure connection establishment response is used to indicate that the access device of the terminal establishes a secure connection, sending the secure connection establishment indication information to the first remote device, where the secure connection establishment indication information is used to indicate the first remote device. Establish a secure connection.
可选地,存储介质还被设置为存储用于执行上述实施例记载的方法步骤的程序代码:Optionally, the storage medium is further arranged to store program code for performing the method steps recited in the above embodiments:
S21,向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;S21: Send secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request a secure connection between the access device of the establishment terminal and the first remote device in the Internet;
S22,接收安全连接管理设备响应于安全连接建立请求信息的安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;S22. Receive secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection.
S23,在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接。S23. In a case that the secure connection establishment response is used to indicate that the access device of the terminal establishes a secure connection, establishing a secure connection according to the indication of the security connection establishment response information.
可选地,在本实施例中,上述存储介质可以包括但不限于:U盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。Optionally, in this embodiment, the foregoing storage medium may include, but not limited to, a USB flash drive, a Read-Only Memory (ROM), a Random Access Memory (RAM), a mobile hard disk, and a magnetic memory. A variety of media that can store program code, such as a disc or a disc.
可选地,在本实施例中,处理器根据存储介质中已存储的程序代码执行上述实施例记载的方法步骤。Optionally, in this embodiment, the processor executes the method steps described in the foregoing embodiments according to the stored program code in the storage medium.
可选地,本实施例中的具体示例可以参考上述实施例及可选实施方式中所描述的示例,本实施例在此不再赘述。For example, the specific examples in this embodiment may refer to the examples described in the foregoing embodiments and the optional embodiments, and details are not described herein again.
显然,本领域的技术人员应该明白,上述的本申请的各模块或各步骤可以用通用的计算装置来实现,它们可以集中在单个的计算装置上,或者分布在多个计算装置所组成的网络上,可选地,它们可以用计算装置可执行的程序代码来实现,从而,可以将它们存储在存储装置中由计算装置来执行,并且在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤,或者将它们分别制作成各个集成电路模块,或者将它们中的多个模块或步骤制作成单个集成电路模块来实现。这样,本申请不限制于任何特定的硬件和软件结合。Obviously, those skilled in the art should understand that the above modules or steps of the present application can be implemented by a general computing device, which can be concentrated on a single computing device or distributed in a network composed of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device such that they may be stored in the storage device by the computing device and, in some cases, may be different from the order herein. The steps shown or described are performed, or they are separately fabricated into individual integrated circuit modules, or a plurality of modules or steps thereof are fabricated as a single integrated circuit module. Thus, the application is not limited to any particular combination of hardware and software.
以上所述仅为本申请的优选实施例而已,并不用于限制本申请,对于本领域的技术人员来说,本申请可以有各种更改和变化。凡在本申请的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。The above description is only the preferred embodiment of the present application, and is not intended to limit the present application, and various changes and modifications may be made to the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this application are intended to be included within the scope of the present application.

Claims (16)

  1. 一种连接建立方法,用于安全连接管理设备,其特征在于,包括:A connection establishment method for a secure connection management device, comprising:
    获取终端的接入设备发送的安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立所述终端的接入设备与互联网中的第一远端设备之间的安全连接;Acquiring the secure connection establishment request information sent by the access device of the terminal, where the secure connection establishment request information is used to request to establish a secure connection between the access device of the terminal and the first remote device in the Internet;
    响应于所述安全连接建立请求信息向所述终端的接入设备发送安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示所述终端的接入设备是否建立所述安全连接;Sending the secure connection establishment response information to the access device of the terminal in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether the access device of the terminal establishes the secure connection;
    在所述安全连接建立响应用于指示所述终端的接入设备建立所述安全连接的情况下,向所述第一远端设备发送安全连接建立指示信息,其中,所述安全连接建立指示信息用于指示所述第一远端设备建立所述安全连接。And the secure connection establishment indication information is sent to the first remote device, where the secure connection establishment response is used to indicate that the access device of the terminal establishes the secure connection, where the secure connection establishment indication information is And configured to instruct the first remote device to establish the secure connection.
  2. 根据权利要求1所述的方法,其特征在于,向所述终端的接入设备发送所述安全连接建立响应信息包括:The method according to claim 1, wherein the sending the secure connection establishment response information to the access device of the terminal comprises:
    在所述安全连接建立请求信息中携带的第一IP地址用于触发允许所述终端的接入设备建立所述安全连接的情况下,向所述终端的接入设备发送用于指示所述终端的接入设备建立所述安全连接的第一安全连接建立响应信息。When the first IP address carried in the secure connection establishment request information is used to trigger the access device of the terminal to establish the secure connection, send the terminal to the access device of the terminal to indicate the terminal The access device establishes a first secure connection setup response message of the secure connection.
  3. 根据权利要求1所述的方法,其特征在于,向所述终端的接入设备发送所述安全连接建立响应信息包括:The method according to claim 1, wherein the sending the secure connection establishment response information to the access device of the terminal comprises:
    在所述安全连接建立请求信息中携带的第一IP地址用于触发不允许所述终端的接入设备建立所述安全连接的情况下,向所述终端的接入设备发送用于指示所述终端的接入设备不建立所述安全连接的第二安全连接建立响应信息。And sending, by the access device of the terminal, the indication that the first IP address that is carried in the security connection establishment request information is used to trigger the access device that does not allow the terminal to establish the secure connection. The access device of the terminal does not establish the second secure connection establishment response information of the secure connection.
  4. 根据权利要求2所述的方法,其特征在于,向所述终端的接入设备发送所述第一安全连接建立响应信息包括:The method according to claim 2, wherein the sending the first secure connection setup response information to the access device of the terminal comprises:
    根据所述第一IP地址确定与所述终端的接入设备建立所述安全连接的第二远端设备,其中,所述第二远端设备包括所述第一IP地 址对应的设备或者所述第一IP地址对应的设备所在网络中的网络设备;Determining, according to the first IP address, a second remote device that establishes the secure connection with the access device of the terminal, where the second remote device includes the device corresponding to the first IP address or the The network device in the network where the device corresponding to the first IP address is located;
    向所述终端的接入设备发送所述第一安全连接建立响应信息,其中,所述第一安全连接建立响应信息携带有所述第二远端设备的第二IP地址和所述安全连接的配置信息。Sending the first secure connection setup response information to the access device of the terminal, where the first secure connection setup response information carries the second IP address of the second remote device and the secure connection Configuration information.
  5. 根据权利要求4所述的方法,其特征在于,所述第一IP地址对应的设备所在网络中的网络设备包括以下之一:The method according to claim 4, wherein the network device in the network where the device corresponding to the first IP address is located comprises one of the following:
    服务提供商部署所述第一IP地址对应的设备所在网络中的网络设备时登记的所述第一IP地址对应的设备所在网络的安全网关或者路由器;a security gateway or router of a network where the device corresponding to the first IP address that is registered when the service provider deploys the network device in the network where the device corresponding to the first IP address is located;
    使用所述第一IP地址对应的终端设备接入网络时登记的所述第一IP地址对应的终端设备接入的接入点设备、安全网关或者路由器;An access point device, a security gateway, or a router accessed by the terminal device corresponding to the first IP address that is registered when the terminal device corresponding to the first IP address accesses the network;
    所述第一远端设备。The first remote device.
  6. 根据权利要求2所述的方法,其特征在于,所述安全连接建立请求信息中携带的第一IP地址用于触发允许所述终端的接入设备建立所述安全连接包括:The method according to claim 2, wherein the first IP address carried in the secure connection establishment request information is used to trigger the access device of the terminal to establish the secure connection, including:
    在所述终端的接入设备的IP地址与所述第一IP地址属于同一服务提供商部署的设备的IP地址的情况下,确定所述安全连接建立请求信息中携带的第一IP地址用于触发允许所述终端的接入设备建立所述安全连接,其中,所述服务提供商部署的设备包括:接入设备、终端设备或者用户终端。Determining, in the case that the IP address of the access device of the terminal and the first IP address belong to the IP address of the device deployed by the same service provider, the first IP address carried in the secure connection establishment request information is used for The device is configured to allow the access device of the terminal to establish the secure connection, where the device deployed by the service provider includes: an access device, a terminal device, or a user terminal.
  7. 根据权利要求3所述的方法,其特征在于,所述安全连接建立请求信息中携带的第一IP地址用于触发不允许所述终端的接入设备建立所述安全连接包括:The method according to claim 3, wherein the first IP address carried in the secure connection establishment request information is used to trigger an access device that does not allow the terminal to establish the secure connection, including:
    在所述终端的接入设备的IP地址与所述第一IP地址不属于同一服务提供商部署的设备的IP地址的情况下,确定所述安全连接建立请求信息中携带的第一IP地址用于触发不允许所述终端的接入设备建立所述安全连接,其中,所述服务提供商部署的设备包括:接入设备、终端设备或者用户终端。And determining, in the case that the IP address of the access device of the terminal is not the IP address of the device deployed by the same service provider, the first IP address carried in the secure connection establishment request information. The device that is not allowed to be connected to the terminal is configured to establish the secure connection, where the device deployed by the service provider includes: an access device, a terminal device, or a user terminal.
  8. 一种连接建立方法,用于终端接入设备,其特征在于,包括:A method for establishing a connection, which is used for a terminal access device, and includes:
    向安全连接管理设备发送安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;Sending secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request to establish a secure connection with the first remote device in the Internet;
    接收所述安全连接管理设备响应于所述安全连接建立请求信息的安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示是否建立所述安全连接;Receiving the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, wherein the secure connection establishment response information is used to indicate whether the secure connection is established;
    在所述安全连接建立响应用于指示建立所述安全连接的情况下,根据所述安全连接建立响应信息的指示建立所述安全连接。And establishing, in the case that the secure connection establishment response is used to indicate that the secure connection is established, establishing the secure connection according to the indication of the secure connection establishment response information.
  9. 根据权利要求5所述的方法,其特征在于,发送所述安全连接建立请求信息包括:The method according to claim 5, wherein the transmitting the secure connection establishment request information comprises:
    对终端数据进行检测,得到所述终端数据的第一IP地址,其中,所述第一IP地址为所述第一远端设备的IP地址;Detecting the terminal data, and obtaining a first IP address of the terminal data, where the first IP address is an IP address of the first remote device;
    发送携带有所述第一IP地址的所述安全连接建立请求信息。Sending the secure connection establishment request information carrying the first IP address.
  10. 根据权利要求9所述的方法,其特征在于,在发送携带有所述第一IP地址的所述安全连接建立请求信息之前,所述方法还包括:The method according to claim 9, wherein before the sending the secure connection establishment request information carrying the first IP address, the method further comprises:
    判断是否已建立所述第一IP地址对应的安全连接;Determining whether a secure connection corresponding to the first IP address has been established;
    在判断出已建立所述第一IP地址对应的安全连接的情况下,通过已建立的所述第一IP地址对应的安全连接发送上述终端数据;When it is determined that the secure connection corresponding to the first IP address has been established, the terminal data is sent by using the established secure connection corresponding to the first IP address;
    在判断出未建立所述第一IP地址对应的安全连接的情况下,确定发送携带有所述第一IP地址的所述安全连接建立请求信息。When it is determined that the secure connection corresponding to the first IP address is not established, determining to send the secure connection establishment request information carrying the first IP address.
  11. 一种连接建立装置,用于安全连接管理设备,其特征在于,包括:A connection establishing device, configured for a secure connection management device, comprising:
    获取模块,用于获取终端的接入设备发送的安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立所述终端的接入设备与互联网中的第一远端设备之间的安全连接;An obtaining module, configured to acquire secure connection establishment request information sent by an access device of the terminal, where the secure connection establishment request information is used to request to establish an access device between the terminal and a first remote device in the Internet Secure connection
    第一发送模块,用于响应于所述安全连接建立请求信息向所述 终端的接入设备发送安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示所述终端的接入设备是否建立所述安全连接;a first sending module, configured to send, according to the secure connection establishment request information, the secure connection establishment response information to the access device of the terminal, where the secure connection establishment response information is used to indicate the access device of the terminal Whether to establish the secure connection;
    第二发送模块,用于在所述安全连接建立响应用于指示所述终端的接入设备建立所述安全连接的情况下,向所述第一远端设备发送安全连接建立指示信息,其中,所述安全连接建立指示信息用于指示所述第一远端设备建立所述安全连接。a second sending module, configured to send the secure connection establishment indication information to the first remote device, where the security connection establishment response is used to indicate that the access device of the terminal establishes the secure connection, where The secure connection establishment indication information is used to instruct the first remote device to establish the secure connection.
  12. 一种连接建立装置,用于终端接入设备,其特征在于,包括:A connection establishing device, configured for a terminal access device, includes:
    第三发送模块,用于向安全连接管理设备发送安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;a third sending module, configured to send the secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request to establish a secure connection with the first remote device in the Internet;
    接收模块,用于接收所述安全连接管理设备响应于所述安全连接建立请求信息的安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示是否建立所述安全连接;a receiving module, configured to receive the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether the secure connection is established;
    建立模块,用于在所述安全连接建立响应用于指示建立所述安全连接的情况下,根据所述安全连接建立响应信息的指示建立所述安全连接。And a establishing module, configured to establish the secure connection according to the indication of the secure connection establishment response information, in a case that the secure connection establishment response is used to indicate that the secure connection is established.
  13. 一种连接建立装置,用于安全连接管理设备,其特征在于,包括:第一处理器和第一通讯接口,其中,A connection establishing device, configured for a secure connection management device, comprising: a first processor and a first communication interface, wherein
    所述第一处理器,与所述第一通讯接口连接,所述第一处理器用于获取通过所述第一通讯接口接收到的终端的接入设备发送的安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立所述终端的接入设备与互联网中的第一远端设备之间的安全连接;响应于所述安全连接建立请求信息指示所述第一通讯接口向所述终端的接入设备发送安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示所述终端的接入设备是否建立所述安全连接;在所述安全连接建立响应用于指示所述终端的接入设备建立所述安全连接的情况下,指示所述第一通讯接口向所述第一远端设备发送安全连接建立指示信息,其中,所述安全连接建立指示信息用 于指示所述第一远端设备建立所述安全连接。The first processor is connected to the first communication interface, and the first processor is configured to acquire secure connection establishment request information sent by an access device of the terminal received by the first communication interface, where The secure connection establishment request information is used to request to establish a secure connection between the access device of the terminal and the first remote device in the Internet; and the first communication interface is indicated in response to the secure connection establishment request information The access device of the terminal sends the security connection establishment response information, where the security connection establishment response information is used to indicate whether the access device of the terminal establishes the secure connection; and the secure connection establishment response is used to indicate the location In the case that the access device of the terminal establishes the secure connection, the first communication interface is instructed to send the secure connection establishment indication information to the first remote device, where the secure connection establishment indication information is used to indicate the location The first remote device establishes the secure connection.
  14. 一种连接建立装置,用于终端接入设备,其特征在于,包括:第二处理器和第二通讯接口,其中,A connection establishing device, configured for a terminal access device, comprising: a second processor and a second communication interface, wherein
    所述第二处理器,与所述第二通讯接口连接,所述第二处理器用于指示所述第二通讯接口向安全连接管理设备发送安全连接建立请求信息,其中,所述安全连接建立请求信息用于请求建立与互联网中的第一远端设备之间的安全连接;通过所述第二通讯接口接收所述安全连接管理设备响应于所述安全连接建立请求信息的安全连接建立响应信息,其中,所述安全连接建立响应信息用于指示是否建立所述安全连接;在所述安全连接建立响应用于指示建立所述安全连接的情况下,根据所述安全连接建立响应信息的指示建立所述安全连接。The second processor is connected to the second communication interface, and the second processor is configured to instruct the second communication interface to send secure connection establishment request information to the secure connection management device, where the secure connection establishment request is The information is used to request to establish a secure connection with the first remote device in the Internet; and receive, by the second communication interface, the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, The secure connection establishment response information is used to indicate whether the secure connection is established; and in the case that the secure connection establishment response is used to indicate that the secure connection is established, the indication of establishing the response information according to the secure connection is established. Said a secure connection.
  15. 一种存储介质,其特征在于,所述存储介质被设置为存储用于执行以下步骤的程序代码:A storage medium characterized in that the storage medium is arranged to store program code for performing the following steps:
    获取终端的接入设备发送的安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;Acquiring the secure connection establishment request information sent by the access device of the terminal, where the secure connection establishment request information is used to request a secure connection between the access device of the terminal and the first remote device in the Internet;
    响应于安全连接建立请求信息向终端的接入设备发送安全连接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;Sending the secure connection establishment response information to the access device of the terminal in response to the secure connection establishment request information, where the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection;
    在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,向第一远端设备发送安全连接建立指示信息,其中,安全连接建立指示信息用于指示第一远端设备建立安全连接。And the secure connection establishment indication information is used to indicate that the first remote device establishes security, where the security connection establishment response is used to indicate that the access device of the terminal establishes a secure connection. connection.
  16. 根据权利要求15所述的存储介质,其特征在于,所述存储介质还被设置为存储用于执行以下步骤的程序代码:A storage medium according to claim 15, wherein said storage medium is further arranged to store program code for performing the following steps:
    向安全连接管理设备发送安全连接建立请求信息,其中,安全连接建立请求信息用于请求建立终端的接入设备与互联网中的第一远端设备之间的安全连接;Sending the secure connection establishment request information to the secure connection management device, where the secure connection establishment request information is used to request a secure connection between the access device of the establishment terminal and the first remote device in the Internet;
    接收安全连接管理设备响应于安全连接建立请求信息的安全连 接建立响应信息,其中,安全连接建立响应信息用于指示终端的接入设备是否建立安全连接;Receiving the secure connection establishment response information of the secure connection management device in response to the secure connection establishment request information, wherein the secure connection establishment response information is used to indicate whether the access device of the terminal establishes a secure connection;
    在安全连接建立响应用于指示终端的接入设备建立安全连接的情况下,根据安全连接建立响应信息的指示建立安全连接。In the case that the secure connection setup response is used to indicate that the access device of the terminal establishes a secure connection, the secure connection is established according to the indication of the secure connection establishment response information.
PCT/CN2018/080853 2017-04-14 2018-03-28 Connection establishment method and apparatus WO2018188482A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710248345.2 2017-04-14
CN201710248345.2A CN106982427B (en) 2017-04-14 2017-04-14 Connection establishment method and device

Publications (1)

Publication Number Publication Date
WO2018188482A1 true WO2018188482A1 (en) 2018-10-18

Family

ID=59343982

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/080853 WO2018188482A1 (en) 2017-04-14 2018-03-28 Connection establishment method and apparatus

Country Status (2)

Country Link
CN (1) CN106982427B (en)
WO (1) WO2018188482A1 (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106982427B (en) * 2017-04-14 2020-08-18 北京佰才邦技术有限公司 Connection establishment method and device
CN109963280B (en) * 2017-12-14 2022-06-03 中国电信股份有限公司 Bidirectional authentication method, device and system, and computer readable storage medium
CN113472622A (en) * 2020-03-30 2021-10-01 华为技术有限公司 Method and equipment for transmitting service in network

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101909297A (en) * 2010-08-20 2010-12-08 中兴通讯股份有限公司 Mutual authenticating method between access network equipment and access network equipment
WO2011109936A1 (en) * 2010-03-09 2011-09-15 上海贝尔股份有限公司 Method and equipment for authenticating subscriber terminal
US20150365845A1 (en) * 2014-06-16 2015-12-17 Freescale Semiconductor, Inc. Wireless communication system with sipto continuity
CN105681268A (en) * 2014-11-21 2016-06-15 中兴通讯股份有限公司 Data transmission method and device
CN106982427A (en) * 2017-04-14 2017-07-25 北京佰才邦技术有限公司 Connect method for building up and device

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101645814B (en) * 2008-08-04 2012-05-23 上海华为技术有限公司 Method, equipment and system for enabling access points to access mobile core network
CN101925064A (en) * 2010-06-12 2010-12-22 中兴通讯股份有限公司 SIPTO decision making method and device of H(e)NB system
CN102469087A (en) * 2010-11-17 2012-05-23 中兴通讯股份有限公司 Method and system for realizing control of quality of service,
CN103763785A (en) * 2013-12-31 2014-04-30 哈尔滨工业大学 VANET message broadcasting method based on distances

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011109936A1 (en) * 2010-03-09 2011-09-15 上海贝尔股份有限公司 Method and equipment for authenticating subscriber terminal
CN101909297A (en) * 2010-08-20 2010-12-08 中兴通讯股份有限公司 Mutual authenticating method between access network equipment and access network equipment
US20150365845A1 (en) * 2014-06-16 2015-12-17 Freescale Semiconductor, Inc. Wireless communication system with sipto continuity
CN105681268A (en) * 2014-11-21 2016-06-15 中兴通讯股份有限公司 Data transmission method and device
CN106982427A (en) * 2017-04-14 2017-07-25 北京佰才邦技术有限公司 Connect method for building up and device

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
NEC: "Correction on the another secured interface for LIPA", R3-130808, 3GPP TSG-RAN WG3 MEETING #80, 8 May 2013 (2013-05-08), Fukuoka, Japan, XP050700827 *

Also Published As

Publication number Publication date
CN106982427B (en) 2020-08-18
CN106982427A (en) 2017-07-25

Similar Documents

Publication Publication Date Title
US9985931B2 (en) Mobile hotspot managed by access controller
US10757629B2 (en) Handover method
US9232404B2 (en) Method, apparatus, and system for data transmission
US8826413B2 (en) Wireless local area network infrastructure devices having improved firewall features
US9027111B2 (en) Relay node authentication method, apparatus, and system
EP3360386B1 (en) Transparent per-bearer switching between wwan and wlan
CN102172059A (en) Handling of local breakout traffic in a home base station
JP2013526087A (en) Handover method, handover system, and apparatus for UE connected to local IP network
WO2017219355A1 (en) Multi-connection communications method and device
WO2018188482A1 (en) Connection establishment method and apparatus
US11882445B2 (en) Authentication system
US11882105B2 (en) Authentication system when authentication is not functioning
Namal et al. Realization of mobile femtocells: operational and protocol requirements
JP5820782B2 (en) Flow distribution system, flow distribution apparatus, flow distribution method, and program
US20230224795A1 (en) Communication method and apparatus
RU2780823C2 (en) Device and method for processing of wireless communication by transit connection
GB2548894A (en) Handover method

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18783940

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 03/02/2020)

122 Ep: pct application non-entry in european phase

Ref document number: 18783940

Country of ref document: EP

Kind code of ref document: A1