WO2020238149A1 - 小基站接入方法、装置、设备、系统以及存储介质 - Google Patents

小基站接入方法、装置、设备、系统以及存储介质 Download PDF

Info

Publication number
WO2020238149A1
WO2020238149A1 PCT/CN2019/124695 CN2019124695W WO2020238149A1 WO 2020238149 A1 WO2020238149 A1 WO 2020238149A1 CN 2019124695 W CN2019124695 W CN 2019124695W WO 2020238149 A1 WO2020238149 A1 WO 2020238149A1
Authority
WO
WIPO (PCT)
Prior art keywords
base station
domain name
small base
address
network element
Prior art date
Application number
PCT/CN2019/124695
Other languages
English (en)
French (fr)
Inventor
曾宪平
Original Assignee
京信通信系统(中国)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 京信通信系统(中国)有限公司 filed Critical 京信通信系统(中国)有限公司
Publication of WO2020238149A1 publication Critical patent/WO2020238149A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/45Network directories; Name-to-address mapping
    • H04L61/4505Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
    • H04L61/4511Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]

Definitions

  • This application relates to the field of mobile communication technology, and in particular to a small base station access method, device, equipment, system and storage medium.
  • the URL (Uniform Resource Locator) address of the network element of the small cell system adopts a method of configuring a fixed IP (Internet Protocol, Internet Protocol) address.
  • IP Internet Protocol, Internet Protocol
  • an embodiment of the present application provides a small cell access method, which includes the following steps:
  • the small base station obtains the DNS address of the network element of the small base station system.
  • the small base station transmits a domain name resolution request to the domain name server configured by the small base station system network element according to the DNS address; the domain name resolution request includes the network element domain name configured by the small base station and corresponding to the small base station system network element.
  • the small base station receives the network element IP address transmitted by the domain name server, and accesses the network element of the small base station system according to the network element IP address; the network element IP address is obtained after the network element domain name is resolved by the domain name server.
  • the embodiment of the present application also provides a small base station access method, including the following steps:
  • the small base station system network element receives the domain name resolution request transmitted by the small base station based on the acquired DNS address through the configured domain name server; the domain name resolution request includes the network element domain name corresponding to the small base station system network element configured by the small base station.
  • the small base station system network element transmits the network element IP address obtained by analyzing the domain name of the network element to the small base station through the domain name server; the network element IP address is used to instruct the small base station to access the small base station system network element.
  • this application also provides a base station access device, including:
  • the DNS address obtaining module is used to obtain the DNS address of the network element of the small cell system.
  • the domain name resolution request module is used to transmit a domain name resolution request to the domain name server configured by the small cell system network element according to the DNS address; the domain name resolution request includes the network element domain name configured by the small cell system and corresponding to the small cell system network element.
  • the IP address acquisition module is used for the network element IP address transmitted by the domain name server, and is connected to the small base station system network element according to the network element IP address; the network element IP address is obtained after the network element domain name is resolved by the domain name server.
  • this application also provides a base station access device, including:
  • the network element domain name acquisition module is used to receive the domain name resolution request transmitted by the small cell based on the obtained DNS address through the configured domain name server; the domain name resolution request includes the network element domain name of the corresponding small cell system network element configured by the small cell.
  • the IP address feedback module is used to transmit the network element IP address obtained by analyzing the domain name of the network element to the small base station through the domain name server; the network element IP address is used to instruct the small base station to access the small base station system network element.
  • the present application also provides a device for executing the small cell access method applied to the small cell in any one of the embodiments of the first aspect.
  • this application also provides a device for executing a small base station access method applied to a network element of a small base station system as in any one of the embodiments of the second aspect described above.
  • this application also provides a system, including: a small base station and a small base station system network element.
  • the small base station is used to execute the small base station access method applied to the small base station as in any embodiment of the first aspect.
  • the small base station system network element is used to execute the small base station access method applied to the small base station system network element as in any one of the embodiments of the second aspect.
  • the present application also provides a computer storage medium on which a computer program is stored, and when the program is executed by a processor, the small base station access method as in the first aspect and the second aspect is implemented.
  • the small cell configures the network element domain name of the network element in the small cell system, interacts with the domain name server, converts the domain name to obtain the corresponding IP address, and then establishes a connection with the network element.
  • the domain name configuration is used to replace the fixed IP address, which can avoid exposing the IP address of the security gateway on the small base station's local debugging customer service terminal, reduce the risk of network attacks and small base station network paralysis, and improve the small base station system. Security and stability.
  • Figure 1 is an application environment diagram of a small base station access method in an embodiment
  • FIG. 2 is a first schematic flowchart of a small base station access method on the small base station side in an embodiment
  • FIG. 3 is a second schematic flowchart of a small base station access method on the small base station side in an embodiment
  • FIG. 4 is a third schematic flowchart of a small base station access method on the small base station side in an embodiment
  • FIG. 5 is a fourth schematic flowchart of a small base station access method on the small base station side in an embodiment
  • FIG. 6 is a first schematic flowchart of a method for accessing a small base station on the network element side in an embodiment
  • FIG. 7 is a first schematic flowchart of a method for accessing a small base station on the network element side in an embodiment
  • FIG. 8 is a schematic structural diagram of a base station access device on a small base station side in an embodiment
  • FIG. 9 is a schematic structural diagram of a base station access device on the network element side in an embodiment
  • Figure 10 is a first schematic flow chart of the system in an embodiment
  • Figure 11 is a second schematic flowchart of the system in an embodiment
  • Figure 12 is a third schematic flowchart of the system in an embodiment
  • Figure 13 is a fourth schematic flowchart of the system in an embodiment.
  • an element when considered to be “connected” to another element, it may be directly connected to and integrated with another element, or there may be a centering element at the same time.
  • the network management URL addresses, security gateway URL addresses, and signaling gateway URL addresses of small base stations on the live network all use fixed IP addresses. That is, small base stations use fixed IP methods to perform data with each network element in the networking system. Interactive.
  • IP address cutover or change such as network management IP address change, security gateway IP address change, or signaling gateway IP address change
  • the IP configuration parameters of all small cells need to be modified and replaced, which cannot be done Seamless cutover, therefore, it is easy to withdraw a large number of small base stations due to IP address mismatch.
  • IP addresses of small cell security gateways, small cell network management, and small cell signaling gateways are exposed on the small cell’s local debugging customer service terminal, which can be easily obtained by criminals and carry out related network attacks, which may bring risks such as network storms.
  • small cells The network management, small cell security gateway, or small cell signaling gateway server is under tremendous network pressure, causing server rock machines, etc.
  • DNS Domain Name System
  • TCP Transmission Control Protocol/Internet Protocol
  • Transmission Control Protocol/Internet Protocol Transmission Control Protocol/Internet Protocol
  • IP network is mainly used to replace boring and hard-to-remember IP addresses with user friendly and friendly names to locate corresponding computers and corresponding services. Therefore, if you want a friendly and friendly name to be recognized by the network, you need a "translator" between the name and the IP address, who can translate the relevant domain name into the corresponding IP address that the network can accept, that is, the domain name server (Also called DNS server).
  • Also called DNS server the domain name server
  • the embodiments of the present application provide a small base station access method, device, equipment, system, and storage medium, which use domain name servers for interaction, and obtain IP addresses through domain name resolution, without revealing the true nature of network elements in the networking system. IP address to avoid artificial network attacks and reduce the risk of network system paralysis; at the same time, when the network element IP address is cut over or replaced, there is no need to change the IP parameter configuration of the small cell, just adjust the domain name and IP address in the domain name server The corresponding relationship is sufficient, which reduces the risk of a large number of base stations withdrawing service.
  • the embodiments of the present application can be applied to the small cell networking system shown in FIG. 1.
  • the small cell system is mainly composed of small cell, transmission network, DHCP (Dynamic Host Configuration Protocol, dynamic host configuration protocol) server 102, small cell security gateway 104, small cell signaling gateway 106 and small cell network management 108.
  • DHCP Dynamic Host Configuration Protocol, dynamic host configuration protocol
  • server 102 Small cell security gateway 104
  • small cell signaling gateway 106 small cell network management 108.
  • the main functions can be as follows:
  • Small base station responsible for wireless resource management, integrating some functions similar to GSM (Global System for Mobile Communications)/LTE (Long Term Evolution) base station and base station controller.
  • GSM Global System for Mobile Communications
  • LTE Long Term Evolution
  • DHCP server realizes the function of assigning IP addresses to small base stations.
  • Small base station network management system monitors and manages small base stations, which can realize the functions of configuring, upgrading and alerting small base stations.
  • Small cell security gateway implements data and signaling security encryption tunnels, and forwarding functions.
  • Small cell signaling gateway realizes small cell signaling aggregation and other functions.
  • the small cell configures the address of the network element in the small cell system in the form of a domain name, performs DNS domain name conversion, and then obtains the IP address corresponding to the network element, and then can access the network element and provide services such as the cell.
  • the small base station has a small coverage area and a small system capacity, and can transmit data between the macro base station and the user equipment. For example, it may include a wireless router used in a general home or office.
  • the small base station in the embodiment of the present application may also be referred to as "small cell", “small station”, “high frequency small station” or “millimeter wave small station", etc.
  • a small cell access method which can be applied to a small cell configured with a network element domain name; as shown in FIG. 2, the small cell access method includes:
  • Step S110 The small base station obtains the DNS address of the network element of the small base station system.
  • Step S120 The small base station transmits a domain name resolution request to the domain name server configured by the small base station system network element according to the DNS address; the domain name resolution request includes the network element domain name configured by the small base station and corresponding to the small base station system network element.
  • Step S130 the small base station receives the network element IP address transmitted by the domain name server, and accesses the network element of the small base station system according to the network element IP address; the network element IP address is obtained after the network element domain name is resolved by the domain name server.
  • the small base station may configure or preset the address of each network element in the small base station system to be accessed in a domain name after leaving the factory, that is, the network element domain name.
  • the network element domain name can be used to identify the network element and is mapped to the network element’s IP address; specifically, such as smallcell.secgw.com.cn, etc., the network element domain name can be set according to the actual networking configuration, and there is no specific restriction here .
  • the small cell After the small cell is started, it can obtain the DNS address of the network element of the small cell system from the DHCP server or other servers.
  • the DNS address is the address of a domain name server configured for the network element of the small cell system.
  • the domain name server is configured with mapping data between the network element domain name and the network element IP address, which can be used to process domain name resolution requests and feed back the IP address corresponding to the network element domain name.
  • the small base station may establish a communication connection with the corresponding domain name server according to the DNS address, and send a domain name resolution request message to the domain name server.
  • the domain name resolution request message contains the network element domain name configured by the small cell; the domain name server receives the domain name resolution request message, and can parse it to obtain the network element domain name, and obtain the corresponding network element according to the mapping relationship between the network element domain name and the IP address. Meta IP address; further, when the domain name server feeds back the network element IP address to the small base station, it can add the network element IP address to the domain name resolution response message and send it to the small base station.
  • the type of the domain name resolution response message mentioned in the embodiment of the application may be the same as the type of the domain name resolution request message, and the specific message type may be determined by the protocol used in the actual networking, and is not limited here.
  • the small base station can obtain the network element IP address based on the domain name resolution response message, and based on the network element IP address, establish a communication connection with the corresponding small base station system network element, exchange data with the network element, and then access the entire networking system .
  • the network elements of the small base station system may be network elements such as a security gateway, a signaling gateway, or a network management server, and there is no specific restriction here.
  • Each small base station system network element can be configured with a corresponding domain name server; and, the domain name server can be configured in the corresponding network element server, and can be set on the same device with the network element, or on a different device with the network element.
  • the small base station configures the network element domain name of the network element in the small base station system, interacts with the domain name server, converts the domain name to obtain the corresponding IP address, and then realizes the connection with the network element.
  • the domain name configuration is used to replace the fixed IP address, which can avoid exposing the IP address of the security gateway on the small base station's local debugging customer service terminal, reduce the risk of network attacks and small base station network paralysis, and improve the performance of the small base station system. Security and stability.
  • the network element of the small base station system is a security gateway.
  • the steps for the small cell to obtain the DNS address of the network element of the small cell system include:
  • Step S112 the small base station sends DHCP request information to the DHCP server;
  • Step S114 the small base station receives the DNS address fed back by the DHCP server based on the DHCP request information; the DNS address is the address of the domain name server configured by the security gateway.
  • the DHCP server can be used to allocate an IP address for the small cell and feed back the address of the domain name server.
  • the small base station may send a DHCP request message to the DHCP server after accessing the networking system.
  • the DHCP server assigns an IP address to the small cell according to the DHCP request message, and feeds back the domain name server address of the security gateway to the small cell; specifically, the DHCP server can add the assigned IP address and the domain name server address of the security gateway to the DHCP response Message and sent to the small cell.
  • the small base station obtains and parses the DHCP response message, can configure its own address parameters according to the assigned IP address, and can interact with the corresponding domain name server according to the domain name server address of the security gateway, and configure the security gateway for the small cell itself through the domain name server
  • the domain name is converted to obtain the security gateway address, which can then establish a connection with the security gateway.
  • network elements such as security gateways, network management servers, and signaling gateways use fixed IP methods to exchange data with all small cells in the existing network, and the aforementioned network risks exist.
  • the current industry customer service terminals (including customer service terminals in other fields) only support one method of domain name resolution, that is, most base stations only configure a set of domain names. If the network elements in the networking system are distributed in both the local area network and the wide area network, This method cannot solve when the base station needs to access the local area network and the wide area network through the domain name resolution method at the same time.
  • the network element of the small cell system is a signaling gateway or a network management server.
  • the steps for the small cell to obtain the DNS address of the network element of the small cell system include:
  • Step S116 The small base station transmits a DNS address request to the security gateway.
  • Step S118 the small base station receives the DNS address fed back by the security gateway based on the DNS address request; the DNS address includes the address of the domain name server configured by the signaling gateway, and/or the address of the domain name server configured by the network management server.
  • the small base station accesses the security gateway, it can negotiate with the security gateway to obtain the domain name server address of the signaling gateway and the domain name server address of the network management server.
  • the small cell can send a DNS address request message to the security gateway to request feedback of the address of the domain name server; the type of the DNS address request message can be determined according to the protocol or connection mode between the small cell and the security gateway, here No specific restrictions.
  • the security gateway feeds back the address of the corresponding domain name server to the small cell according to the DNS address request message; specifically, the security gateway may add the address of the corresponding domain name server to the DNS address response message and send it to the small cell.
  • the domain name server corresponding to the signaling gateway can be configured with mapping data between the signaling gateway domain name and the signaling gateway IP address, which can be used to process domain name resolution requests and feed back the IP address corresponding to the signaling gateway domain name.
  • the domain name server corresponding to the network management server can be configured with mapping data between the network management server domain name and the gateway server IP address, which can be used to process domain name resolution requests and feedback the IP address corresponding to the gateway server domain name.
  • the small base station can also configure the addresses of multiple network elements in the small base station networking system in the form of domain names; accordingly, each network element can also be configured with a corresponding domain name server. Based on this, after establishing a communication connection with the security gateway, the small base station can request the security gateway for the address of the domain name server of other network elements in the networking system, and then interact with the corresponding domain name server to realize the network element domain name and network element IP Address conversion to obtain an IP address and access the corresponding network element. It should be noted that the small base station here can establish a connection with the security gateway by configuring a fixed IP, and can also establish a connection with the security gateway by configuring the network element address as a domain name.
  • a domain name configuration address can be used for multiple network elements.
  • the security gateway, signaling gateway, and network management server in the small base station system all use domain name configuration addresses.
  • the small base station can adopt multiple sets of domain name networking methods, support multiple sets of domain name resolution IP methods, and then can realize the function of domain name resolution in the WAN and LAN at the same time.
  • the small base station may be configured with a security gateway domain name and a signaling gateway domain name.
  • the small cell can obtain the DNS address of the signaling gateway based on the security gateway, and transmit a domain name resolution request to the domain name server configured by the signaling gateway according to the address; the domain name resolution request includes the signaling gateway domain name configured by the small cell.
  • the small base station receives the signaling gateway IP address transmitted by the domain name server, and accesses the signaling gateway according to the signaling gateway IP address, and performs signaling data exchange with the signaling gateway; the signaling gateway IP address is determined by the signaling gateway domain name via the domain name server Get after parsing.
  • the small cell after the small cell sends a DNS address request message to the security gateway, it can obtain the DNS address corresponding to the signaling gateway from the security gateway.
  • the small base station can establish a communication connection with the domain name server corresponding to the signaling gateway, and send a domain name resolution request message to the domain name server.
  • the domain name resolution request message contains the signaling gateway domain name configured by the small cell; the domain name server receives the domain name resolution request message, and can parse it to obtain the signaling gateway domain name, and obtain it according to the mapping relationship between the signaling gateway domain name and the IP address The corresponding signaling gateway IP address.
  • the domain name server may add the signaling gateway IP address to the domain name resolution response message and send it to the small cell.
  • the domain name server can be configured in the signaling gateway server, and can be set on the same device together with the signaling gateway, or on a different device from the signaling gateway.
  • the small base station can parse the response message based on the domain name, obtain the signaling gateway IP address, and based on the signaling gateway IP address, establish a communication connection with the signaling gateway, access the signaling gateway, and exchange signaling data with the signaling gateway, and then It can realize core network registration and other functions.
  • the security gateway and the signaling gateway of the small cell networking system may be respectively configured with domain name servers; accordingly, the small cell configures the addresses of the security gateway and the signaling gateway in the form of domain names.
  • the small base station After the small base station is connected to the security gateway, it can obtain the address of the domain name server of the signaling gateway, and then can convert the domain name of the signaling gateway to obtain the corresponding IP address and access the signaling gateway.
  • the small base station supports multiple sets of domain name resolution IP methods, which can use domain name resolution together with the security gateway and signaling gateway to obtain the IP address corresponding to the domain name.
  • the small base station is configured with a security gateway domain name and a network management server domain name.
  • the small base station can obtain the DNS address of the network management server based on the security gateway, and transmit a domain name resolution request to the domain name server configured by the network management server according to the address; the domain name resolution request includes the domain name of the network management server configured by the small base station.
  • the small base station receives the network management server IP address transmitted by the domain name server, and accesses the network management server according to the network management server IP address, and performs signaling data exchange with the network management server; the network management server IP address is obtained after the network management server domain name is resolved by the domain name server.
  • the small cell after the small cell sends a DNS address request message to the security gateway, it can obtain the DNS address corresponding to the network management server from the security gateway.
  • the small base station can establish a communication connection with the domain name server corresponding to the network management server according to the DNS address, and send a domain name resolution request message to the domain name server.
  • the domain name resolution request message contains the domain name of the network management server configured by the small cell; the domain name server receives the domain name resolution request message, and can parse it to obtain the domain name of the network management server, and obtain the corresponding network management according to the mapping relationship between the domain name and IP address of the network management server Server IP address.
  • the IP address of the network management server may be added to the domain name resolution response message and sent to the small base station.
  • the domain name server can be configured in the network management server server, and the network management server can be set on the same device, or it can be set on a different device from the network management server.
  • the small base station can obtain the IP address of the network management server based on the domain name resolution response message, and based on the network management server IP address, establish a communication connection with the network management server, access the network management server, and exchange monitoring data with the network management server, thereby realizing remote monitoring and small Base station configuration, small cell upgrade, and small cell alarm functions.
  • the security gateway and the network management server of the small base station networking system may be respectively configured with domain name servers; accordingly, the small base station configures the addresses of the security gateway and the network management server in the form of domain names.
  • the small base station After the small base station is connected to the security gateway, it can obtain the address of the domain name server of the network management server, and then can convert the domain name of the network management server to obtain the corresponding IP address and access the network management server.
  • the small base station supports multiple sets of domain name resolution IP methods, which can use domain name resolution together with the security gateway and network management server to obtain the IP address corresponding to the domain name.
  • Step S108 the small base station transmits an IKE_INIT request message to the security gateway based on the IP address of the security gateway; the IKE_INIT request message is used to instruct the security gateway to establish an IPSec connection with the small base station.
  • the small base station sends an IKE_INIT request message to the security gateway according to the IP address of the security gateway, and then obtains the IKE_INIT response message fed back by the security gateway, and establishes an IPSec connection with the security gateway.
  • the IKE_INIT request message can be used to initiate the establishment of an IPSec connection, and can also be used to negotiate IKE encryption algorithms and secret keys.
  • an IPSec connection can be established between the small base station and the security gateway, which improves the security of the networking system, especially the security of address data transmission.
  • the DNS address request message sent by the small cell to the security gateway may be an IKE_AUTH request message.
  • the security gateway receives the IKE_AUTH request message, adds the DNS address to the IKE_AUTH response message, and feeds the IKE_AUTH response message back to the small cell.
  • the small base station Based on the IPSec connection, receives and parses the IKE_AUTH response message to obtain the DNS address.
  • the IKE_AUTH request message can be used to request feedback of the address of the domain name server, and can also be used to negotiate ESP (Encapsulating Security Payload) encryption algorithm, secret key, tunnel IP, etc.
  • ESP Encapsulating Security Payload
  • the security gateway adds the DNS address to the IKE_AUTH response message, it can add the address to the protocol field agreed upon by the small cell and the supporting network element, or add the address to the blank protocol field, so that the small cell can be used from different vendors’ network elements. Get the address data in.
  • the DNS address request is an IKE_AUTH request message generated by the small cell based on the IPSec connection.
  • the small base station receives the DNS address fed back by the security gateway based on the DNS address request;
  • the DNS address is the address of the domain name server configured by the signaling gateway or the address of the domain name server configured by the network management server.
  • the steps include:
  • Step S119 The small base station receives the IKE_AUTH response message transmitted by the security gateway; the IKE_AUTH response message is a message with the DNS address added to the Attribute Type field.
  • the IKE_AUTH optional field of the IPsec protocol can be used to obtain the address of the domain name server; in the IKE_AUTH response message, the Attribute Type field is a blank protocol field, and the security gateway can add the DNS address to the Attribute Type field in.
  • the small base station can obtain the DNS address by parsing the Attribute Type field in the IKE_AUTH response message.
  • the multiple sets of addresses can be stored in the relevant configuration files of the small base station.
  • the small base station can use the domain name of the network element to be connected to poll multiple sets of DNS addresses to obtain the network element IP address provided by the corresponding domain name server; it can also use one of the DNS addresses to perform polling calls for multiple sets of network elements to be connected.
  • the domain name performs a polling call to obtain the network element IP address corresponding to the domain name server.
  • a small cell access method is provided, which is applied to a small cell system network element configured with a domain name server; as shown in FIG. 6, the small cell access method includes:
  • Step S210 The small cell system network element receives the domain name resolution request transmitted by the small cell based on the acquired DNS address through the configured domain name server; the domain name resolution request includes the network element domain name of the small cell system network element corresponding to the small cell configuration.
  • Step S220 the small base station system network element transmits the network element IP address obtained by analyzing the domain name of the network element to the small base station through the domain name server; the network element IP address is used to instruct the small base station to access the small base station system network element.
  • the network element of the small base station system is configured with a domain name server, which contains the mapping data between the domain name of the network element and the IP address of the network element.
  • the domain name server receives the domain name resolution request message, obtains the network element domain name therein, obtains the network element IP address corresponding to the network element domain name according to the mapping data, and sends the network element IP address to the small base station.
  • the domain name resolution request message is a message sent by the small base station to the domain name server according to the acquired address of the domain name server, and the small base station is configured with a security gateway domain name.
  • the network element of the small base station system is configured with a corresponding domain name server.
  • the small base station interacts with the domain name server of the network element according to the configured domain name of the network element, converts the domain name to obtain the corresponding IP address, and then establishes with the network element connection. Based on this, it can avoid exposing the IP address of the security gateway on the small cell local debugging customer service terminal, and reduce the risk of network attacks and small cell network paralysis.
  • the IP address of the security gateway is cut over, there is no need to change the IP parameter configuration of the small cell, just adjust the correspondence between the domain name and the IP address in the domain name server of the security gateway, which effectively reduces the risk of a large number of base stations withdrawing service.
  • the small cell system network element is a security gateway; the IP address of the network element is the security gateway IP address.
  • the small cell system network element After the small cell system network element transmits the network element IP address obtained by analyzing the domain name of the network element to the small cell through the domain name server, the following steps are included:
  • the security gateway When receiving the DNS address request transmitted by the small base station, the security gateway transmits the address of the domain name server configured by the signaling gateway and/or the address of the domain name server configured by the network management server to the small base station.
  • each network element in the small base station system can be configured with a corresponding domain name server, and at the same time, the small base station can configure the address of each network element in the form of a domain name.
  • the small base station interacts with the security gateway according to the security gateway IP address fed back by the security gateway domain name server, and can further obtain the domain name server addresses of other network elements in the small base station system, and then can realize the corresponding domain name conversion to obtain the IP addresses of related network elements
  • the specific process can be as described in the previous embodiment, and will not be repeated here.
  • the security gateway when receiving the DNS address request transmitted by the small cell, transmits the address of the domain name server configured by the signaling gateway and/or the address of the domain name server configured by the network management server to Before the steps of the small base station, it also includes the following steps:
  • Step S230 The security gateway receives the IKE_INIT request message transmitted by the small base station based on the IP address of the security gateway.
  • step S240 the security gateway establishes an IPSec connection with the small cell based on the IKE_INIT request message.
  • the DNS address request is an IKE_AUTH request message.
  • the security gateway transmits the address of the domain name server configured by the signaling gateway and/or the address of the domain name server configured by the network management server to the small base station, including:
  • Step S252 The security gateway adds the address of the domain name server configured by the signaling gateway and/or the address of the domain name server configured by the network management server in the Attribute Type field, and generates an IKE_AUTH response message.
  • step S254 the security gateway transmits the IKE_AUTH response message to the small cell.
  • the small cell system network element transmits the network element IP address obtained by resolving the domain name resolution request to the small cell through the domain name server:
  • Step S222 The network element of the small base station system randomly allocates a network element IP address to the small base station from among the multiple network element IP addresses corresponding to the network element domain name through the domain name server.
  • multiple network element IP addresses can be configured for one network element domain name.
  • the domain name server can randomly assign a network element IP address to the small cell.
  • the embodiment of this application uses a set of domain names to match multiple IP addresses to ensure that the small cell system network elements do not use fixed IP to interact with all small cells in the networking system, which can further reduce the risk of network attacks and network storms , To avoid causing network paralysis.
  • FIGS. 2 to 7 are displayed in sequence as indicated by the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless specifically stated in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least some of the steps in FIGS. 2 to 7 may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. These sub-steps or stages The execution order of is not necessarily performed sequentially, but may be performed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.
  • a small base station access device which is applied to a small base station configured with a network element domain name; as shown in FIG. 8, the small base station access device includes:
  • the DNS address obtaining module is used to obtain the DNS address of the network element of the small cell system.
  • the domain name resolution request module is used to transmit a domain name resolution request to the domain name server configured by the small cell system network element according to the DNS address; the domain name resolution request includes the network element domain name configured by the small cell and corresponding to the small cell system network element.
  • the IP address acquisition module is used for the network element IP address transmitted by the domain name server, and is connected to the small base station system network element according to the network element IP address; the network element IP address is obtained after the network element domain name is resolved by the domain name server.
  • a small base station access device which is applied to a small base station system network element configured with a domain name server; as shown in FIG. 9, the small base station access device includes:
  • the network element domain name acquisition module is used to receive the domain name resolution request transmitted by the small cell based on the obtained DNS address through the configured domain name server; the domain name resolution request includes the network element domain name of the corresponding small cell system network element configured by the small cell.
  • the IP address feedback module is used to transmit the network element IP address obtained by analyzing the domain name of the network element to the small base station through the domain name server; the network element IP address is used to instruct the small base station to access the network element of the small base station system.
  • Each module in the aforementioned small base station access device can be implemented in whole or in part by software, hardware, and combinations thereof.
  • the above-mentioned modules may be embedded in the form of hardware or independent of the processor in the computer equipment, or may be stored in the memory of the computer equipment in the form of software, so that the processor can call and execute the operations corresponding to the above-mentioned modules.
  • a device is provided, and the device is configured to execute the above-mentioned small cell access method applied to a small cell.
  • a device is provided, and the device is configured to execute the above small cell access method applied to a network element of a small cell system.
  • the device may be a security gateway, a signaling gateway, or a network management server, and there is no specific limitation here.
  • a system including: a small base station and a network element of a small base station system.
  • the small base station is used to execute the above small base station access method applied to the small base station;
  • the small base station system network element is used to execute the above small base station access method applied to the small base station system network element.
  • the small base station can establish a communication connection with the network element of the small base station system.
  • the system further includes a DHCP server for communicating with the small base station.
  • a DHCP server for communicating with the small base station.
  • Step 1 After the small cell leaves the factory, its small cell security gateway address is configured as a domain name (for example, the domain name is: smallcell.secgw.com.cn). After the small cell is started, it automatically initiates a DHCP request message to the DHCP server.
  • domain name for example, the domain name is: smallcell.secgw.com.cn.
  • Step 2 After receiving the request, the DHCP server randomly allocates the small cell's own IP address and DNS IP address (that is, the domain name server address of the security gateway) to each small cell.
  • the small cell's own IP address can be 10.92.127.122
  • the DNS IP address can be 20.96.128.166; this DNS IP address is used by the small cell to initiate a domain name resolution request to the security gateway.
  • Step 3 The small base station initiates a domain name resolution request to the small base station security gateway domain name server, and obtains the IP address of the small base station security gateway.
  • Step 4 The small cell security gateway domain name server responds to the small cell request message and replies with the small cell security gateway IP address.
  • the security gateway address is: 20.96.128.170; it should be noted that the IP address is not unique.
  • Step 5 The small cell and the small cell security gateway use the acquired IP to exchange data.
  • the system further includes a signaling gateway configured with a domain name server, and/or a network management server configured with a domain name server.
  • the small base station is also configured with a signaling gateway domain name and/or a network management server domain name.
  • the domain name server of the signaling gateway is used to randomly assign a signaling gateway IP address to the small base station among multiple signaling gateway IP addresses corresponding to the signaling gateway domain name.
  • the domain name server of the network management server is used for randomly assigning a signaling gateway IP address to the small cell among multiple signaling gateway IP addresses corresponding to the signaling gateway domain name.
  • different domain name servers can correspond to multiple IP addresses. After each domain name server resolves the domain name, one is randomly assigned The IP address interacts with the small cell.
  • the system further includes a signaling gateway configured with a domain name server; the small cell is also configured with a signaling gateway domain name; as shown in Figure 11, the system can implement the following steps:
  • Step 1 After the small cell leaves the factory, its small cell security gateway address is configured as a domain name (for example, the domain name is: smallcell.secgw.com.cn). After the small cell is started, it automatically initiates a DHCP request message to the DHCP server.
  • domain name for example, the domain name is: smallcell.secgw.com.cn.
  • Step 2 After receiving the request, the DHCP server randomly allocates the small cell's own IP address and DNS IP address to each small cell (for example, the small cell's own IP address is 10.92.127.122, and the DNS IP address is 20.96.128.166).
  • the DNS IP address is used by the small cell to initiate a domain name resolution request to the security gateway.
  • Step 3 The small base station initiates a domain name resolution request to the small base station security gateway domain name server, and obtains the IP address of the small base station security gateway.
  • Step 4 The small cell security gateway domain name server responds to the small cell request message and replies to the small cell security gateway IP address (for example, the security gateway address is 20.96.128.170), which is not unique.
  • Step 5 The small base station and the small base station security gateway IP interact, initiate an IPSec establishment request IKE_INIT message to the small base station security gateway, and negotiate the IKE encryption algorithm and secret key.
  • Step 6 The small cell security gateway replies an IKE_INIT message to the small cell.
  • Step 7 The small base station initiates an IKE_AUTH request to the small base station security gateway to negotiate the ESP encryption algorithm, secret key, tunnel IP, DNS IP address, etc.
  • Step 8 The small cell security gateway replies to the small cell with an IKE_AUTH message, and the small cell resolves the DNS IP address from the message (for example, the small cell signaling gateway DNS IP address is 100.96.128.16).
  • Step 9 After the small cell leaves the factory, its small cell signaling gateway address is configured as a domain name (for example, the domain name is smallcell.agw.com.cn), and the small cell initiates domain name resolution request information to the small cell signaling gateway domain name server.
  • the domain name is smallcell.agw.com.cn
  • Step 10 The small cell signaling gateway domain name server returns a domain name resolution result message to the small cell, and replies with the small cell signaling gateway IP address (for example, the small cell signaling gateway address is 200.96.128.100), which is not unique.
  • Step 11 The small base station exchanges signaling data with the small base station signaling gateway, and completes core network registration.
  • the system further includes a network management server configured with a domain name server; the small base station is also configured with a network management server domain name; as shown in Figure 12, the system can implement the following steps:
  • Step 1 After the small cell leaves the factory, its small cell security gateway address is configured as a domain name (for example, the domain name is: smallcell.secgw.com.cn). After the small cell is started, it automatically initiates a DHCP request message to the DHCP server.
  • domain name for example, the domain name is: smallcell.secgw.com.cn.
  • Step 2 After receiving the request, the DHCP server randomly assigns each small cell's own IP address and DNS IP address (for example, the small cell's own IP address is 10.92.127.122, and the DNS IP address is 20.96.128.166).
  • the DNS IP address is used by the small cell to initiate a domain name resolution request to the security gateway.
  • Step 3 The small base station initiates a domain name resolution request to the small base station security gateway domain name server, and obtains the IP address of the small base station security gateway.
  • Step 4 The small cell security gateway domain name server responds to the small cell request message and replies to the small cell security gateway IP address (for example, the security gateway address is 20.96.128.170), which is not unique.
  • Step 5 The small base station and the small base station security gateway IP interact, initiate an IPSec establishment request IKE_INIT message to the small base station security gateway, and negotiate the IKE encryption algorithm and secret key.
  • Step 6 The small cell security gateway replies an IKE_INIT message to the small cell.
  • Step 7 The small base station initiates an IKE_AUTH request to the small base station security gateway to negotiate the ESP encryption algorithm, secret key, tunnel IP, DNS IP address, etc.
  • Step 8 The small cell security gateway replies to the small cell with an IKE_AUTH message, and the small cell resolves the DNS IP address from the message (for example, the small cell network management DNS IP address is 200.96.128.16).
  • Step 9 The small base station initiates domain name resolution request information to the small cell network management domain name server (for example, the domain name is smallcell.hms.com.cn);
  • Step 10 The small base station network management domain name server returns a domain name resolution result message to the small base station, and replies to the small base station network management IP address (for example, the small base station network management address is 200.96.128.100), which is not unique.
  • Step 11 The small base station and the small base station network manager exchange monitoring data to complete functions such as remote monitoring.
  • the system can implement the following steps:
  • Step 1 The small base station initiates DHCP request information to the DHCP server.
  • Step 2 The DHCP server allocates a small cell's own IP address and DNS IP address (denoted as DNS IP1) to the small cell.
  • DNS IP1 DNS IP address
  • Step 3 The small base station initiates a domain name resolution request to the security gateway domain name server, and obtains the IP address of the small base station security gateway.
  • Step 4 The small cell security gateway domain name server responds to the small cell request message and replies to its small cell security gateway IP address, which is not unique.
  • Step 5 The small base station initiates an IPSec establishment request IKE_INIT message to the small base station security gateway according to the acquired IP address of the small base station security gateway, and negotiates the IKE encryption algorithm and secret key.
  • Step 6 The small cell security gateway replies an IKE_INIT message to the small cell.
  • Step 7 The small base station initiates an IKE_AUTH request to the small base station security gateway to negotiate the ESP encryption algorithm, secret key, tunnel IP, DNS IP address, etc.
  • Step 8 The small cell security gateway replies to the small cell with an IKE_AUTH message, and the small cell resolves the DNS IP address (denoted as: DNS IP2 and DNS IP3) from the message.
  • Step 9 The small cell initiates a domain name resolution request to the small cell signaling gateway domain name server, and obtains the IP address of the small cell signaling gateway.
  • Step 10 The small cell signaling gateway domain name server returns a domain name resolution result message to the small cell, and randomly assigns the small cell signaling gateway IP address to different small cells. This IP address is not unique.
  • Step 11 The small cell and the small cell signaling gateway exchange signaling data to complete the core network registration process.
  • Step 12 The small base station initiates domain name resolution request information to the small cell network management domain name server (for example, the domain name is smallcell.hms.com.cn).
  • the domain name is smallcell.hms.com.cn.
  • Step 13 The small base station network management domain name server returns a domain name resolution result message to the small base station, and randomly assigns the small base station network management IP address to different small base stations. This IP address is not unique.
  • Step 14 The small base station and the small base station network manager exchange monitoring data to complete functional tasks such as remote monitoring.
  • a computer storage medium is provided, and a computer program is stored thereon, and when the program is executed by a processor, the above small base station access method is implemented.
  • the foregoing storage medium please refer to the above limitation on the access method of the small base station, which will not be repeated here.
  • Non-volatile memory may include read only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory.
  • Volatile memory may include random access memory (RAM) or external cache memory.
  • RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous chain Channel (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请涉及一种小基站接入方法、装置、设备、系统以及存储介质。其中,小基站接入方法,小基站获取小基站系统网元的DNS地址;根据所述DNS地址,向所述小基站系统网元配置的域名服务器传输、包含所述小基站配置的网元域名的域名解析请求;接收所述域名服务器传输的网元IP地址,并根据所述网元IP地址接入所述小基站系统网元。在小基站组网系统中,配置有网元域名的小基站通过域名解析的方式来得到小基站系统网元的IP地址。基于此,可不暴露网元的IP地址,降低网络攻击和小基站网络瘫痪的风险。同时,在安全网关的IP地址割接时,无需变更小基站的IP参数配置,只需调整域名服务器中域名与IP地址的对应关系即可,有效降低大批量基站退服的风险。

Description

小基站接入方法、装置、设备、系统以及存储介质 技术领域
本申请涉及移动通信技术领域,特别是涉及一种小基站接入方法、装置、设备、系统以及存储介质。
背景技术
随着移动通信信息化以及移动互联网的飞速发展,室内信号覆盖在通信业务中的比重也日渐提升。通过小基站将传统的通信业务延伸到室内环境,打破了原有的通信网络部署格局,同时也产生了诸多的新问题。
目前,小基站系统网元的URL(Uniform Resource Locator,统一资源定位符)地址是采用配置固定IP(Internet Protocol,互联网协议)地址的方式。在实现过程中,发明人发现传统技术中至少存在如下问题:小基站与小基站系统网元采用配置固定IP地址进行交互的方式,容易遭受网络攻击,引发网络风暴。
发明内容
基于此,有必要针对传统技术存在易遭受网络攻击,引发网络风暴的问题,提供一种小基站接入方法、装置、设备、系统以及存储介质。
为了实现上述目的,第一方面,本申请实施例提供了一种小基站接入方法,包括以下步骤:
小基站获取小基站系统网元的DNS地址。
小基站根据DNS地址,向小基站系统网元配置的域名服务器传输域名解析请求;域名解析请求包含小基站配置的、对应小基站系统网元的网元域名。
小基站接收域名服务器传输的网元IP地址,并根据网元IP地址接入小基站系统网元;网元IP地址由网元域名经域名服务器解析后得到。
第二方面,本申请实施例还提供了一种小基站接入方法,包括以下步骤:
小基站系统网元通过配置的域名服务器,接收小基站基于获取到的DNS地址传输的域名解析请求;域名解析请求包含小基站配置的对应小基站系统网元的网元域名。
小基站系统网元通过域名服务器,将解析网元域名得到的网元IP地址传输给小基站;网元IP地址用于指示小基站接入小基站系统网元。
第三方面,本申请还提供了一种基站接入装置,包括:
DNS地址获取模块,用于获取小基站系统网元的DNS地址。
域名解析请求模块,用于根据DNS地址,向小基站系统网元配置的域名服务器传输域名解析请求;域名解析请求包含小基站配置的、对应小基站系统网元的网元域名。
IP地址获取模块,用于域名服务器传输的网元IP地址,并根据网元IP地址接入小基站系统网元;网元IP地址由网元域名经域名服务器解析后得到。
第四方面,本申请还提供了一种基站接入装置,包括:
网元域名获取模块,用于通过配置的域名服务器,接收小基站基于获取到 的DNS地址传输的域名解析请求;域名解析请求包含小基站配置的对应小基站系统网元的网元域名。
IP地址反馈模块,用于通过域名服务器,将解析网元域名得到的网元IP地址传输给小基站;网元IP地址用于指示小基站接入小基站系统网元。
第五方面,本申请还提供了一种设备,用于执行如第一方面任一实施例应用于小基站的小基站接入方法。
同时,本申请还提供了一种设备,用于执行如上述第二方面任一实施例应用于小基站系统网元的小基站接入方法。
第六方面,本申请还提供了一种系统,包括:小基站和小基站系统网元。
小基站用于执行如第一方面任一实施例应用于小基站的小基站接入方法。
小基站系统网元用于执行如第二方面任一实施例应用于小基站系统网元的小基站接入方法。
第七方面,本申请还提供了一种计算机存储介质,其上存储有计算机程序,该程序被处理器执行时实现如第一方面和第二方面的小基站接入方法。
上述技术方案中的一个技术方案具有如下优点和有益效果:
在小基站组网系统中,小基站配置小基站系统中网元的网元域名,通过与域名服务器进行交互,转换域名得到相应的IP地址,进而与网元建立连接。基于此,在小基站中,采用域名配置代替固定的IP地址,可避免在小基站本地调试客服端上暴露安全网关的IP地址,降低网络攻击和小基站网络瘫痪的风险,提高小基站系统的安全性和稳定性。同时,在网元的IP地址割接时,无需变更小基站的IP参数配置,只需调整域名服务器中域名与IP地址的对应关系即可,有效降低大批量基站退服的风险。
附图说明
通过阅读参照以下附图所作的对非限制性实施例所作的详细描述,本申请的其它特征、目的和优点将会变得更明显:
图1为一个实施例中小基站接入方法的应用环境图;
图2为一个实施例中小基站侧小基站接入方法的第一示意性流程图;
图3为一个实施例中小基站侧小基站接入方法的第二示意性流程图;
图4为一个实施例中小基站侧小基站接入方法的第三示意性流程图;
图5为一个实施例中小基站侧小基站接入方法的第四示意性流程图;
图6为一个实施例中网元侧小基站接入方法的第一示意性流程图;
图7为一个实施例中网元侧小基站接入方法的第一示意性流程图;
图8为一个实施例中小基站侧基站接入装置的结构示意图;
图9为一个实施例中网元侧基站接入装置的结构示意图;
图10为一个实施例中系统的第一示意性流程图;
图11为一个实施例中系统的第二示意性流程图;
图12为一个实施例中系统的第三示意性流程图;
图13为一个实施例中系统的第四示意性流程图。
具体实施方式
为了便于理解本申请,下面将参照相关附图对本申请进行更全面的描述。附图中给出了本申请的首选实施例。但是,本申请可以以许多不同的形式来实现,并不限于本文所描述的实施例。相反地,提供这些实施例的目的是使对本申请的公开内容更加透彻全面。
需要说明的是,当一个元件被认为是“连接”另一个元件,它可以是直接连接到另一个元件并与之结合为一体,或者可能同时存在居中元件。
除非另有定义,本文所使用的所有的技术和科学术语与属于本申请的技术领域的技术人员通常理解的含义相同。本文中在本申请的说明书中所使用的术语只是为了描述具体的实施例的目的,不是旨在于限制本申请。本文所使用的术语“和/或”包括一个或多个相关的所列项目的任意的和所有的组合。
目前,现网的小基站的网管URL地址、安全网关URL地址、信令网关URL地址都采用配置固定IP地址的方式,即,小基站采用固定IP方式与组网系统中的各网元进行数据交互。但在小基站组网系统出现IP地址割接或变更时(例如网管IP地址变更、安全网关IP地址变更或信令网关IP地址变更),需要修改替换所有小基站的IP配置参数,无法做到无缝割接,因此,容易因为IP地址不匹配而造成大批量小基站退服。此外,小基站安全网关、小基站网管、小基站信令网关的IP地址暴露在小基站本地调试客服端,易被不法分子获取,进行相关网络攻击,带来网络风暴等风险,例如,小基站网管、小基站安全网关或小基站信令网关服务器受到巨大网络压力,造成服务器岩机等。
而在IP网络中,DNS(Domain Name System,域名系统)是一种组织成域层次结构的计算机和网络服务命名系统,它用于TCP(Transmission Control Protocol/Internet Protocol,传输控制协议/因特网互联协议)/IP网络,主要是用来通过用户亲切而友好的名称代替枯燥而难记的IP地址,以定位相应的计算机和相应服务。因此,要想让亲切而友好的名称能被网络所认识,则需要在名称和IP地址之间有一位“翻译官”,能将相关的域名翻译成网络能接受的相应IP地址,即域名服务器(也称DNS服务器)。
因此,本申请实施例提供一种小基站接入方法、装置、设备、系统以及存储介质,采用域名服务器进行交互,通过域名解析的方式来获取IP地址,不暴露组网系统中网元的真实IP地址,避免人为带来网络攻击,降低组网系统瘫痪风险;同时,在网元IP地址割接或替换时,无需变更小基站的IP参数配置,只需调整域名服务器中域名和IP地址的对应关系即可,降低大批量基站退服的风险。具体地,本申请实施例可应用于如图1所示的小基站组网系统中。小基站系统主要由小基站、传输网络、DHCP(Dynamic Host Configuration Protocol,动态主机配置协议)服务器102、小基站安全网关104、小基站信令网关106和小基站网管108等组成,各网元的主要功能可如下:
(1)小基站:负责无线资源管理,集成了部分类似GSM(Global System for Mobile Communications,全球移动通信系统)/LTE(Long Term Evolution,长期演进)基站和基站控制器的功能。
(2)DHCP服务器:实现给小基站分配IP地址的功能。
(3)小基站网管系统:监控、管理小基站,可实现对小基站进行配置、升级以及告警等功能。
(4)小基站安全网关:实现数据、信令安全加密隧道,以及转发功能。
(5)小基站信令网关:实现小基站信令汇聚等功能。
本申请实施例中,小基站以域名的方式配置小基站系统中网元的地址,通过执行DNS域名转换,进而获取到网元对应的IP地址,进而可接入网元,提供小区等服务。需要说明的是,小基站的覆盖面积小,系统容量小,能够在宏基站和用户设备之间进行数据传递,例如可以包括一般家庭或办公室使用的无线路由器等。本申请实施例中的小基站也可以称为“small cell”、“小站”、“高频小站”或“毫米波小站”等。
在一个实施例中,提供了一种小基站接入方法,可应用于配置有网元域名的小基站;如图2所示,小基站接入方法包括:
步骤S110,小基站获取小基站系统网元的DNS地址。
步骤S120,小基站根据DNS地址,向小基站系统网元配置的域名服务器传输域名解析请求;域名解析请求包含小基站配置的、对应小基站系统网元的网元域名。
步骤S130,小基站接收域名服务器传输的网元IP地址,并根据网元IP地址接入小基站系统网元;网元IP地址由网元域名经域名服务器解析后得到。
具体而言,小基站可在出厂后,以域名的方式配置或预设待接入的小基站系统中各网元的地址,即网元域名。网元域名可用于标识网元,且与网元的IP地址相互映射;具体地,例如smallcell.secgw.com.cn等,网元域名可根据实际组网配置进行设置,此处不做具体限制。小基站在启动后,可向DHCP服务器或其他服务器获取到小基站系统网元的DNS地址。其中,DNS地址为小基站系统网元配置的域名服务器的地址,该域名服务器配置有网元域名与网元IP地址的映射数据,可用于处理域名解析请求,反馈网元域名对应的IP地址。
小基站根据DNS地址,可与对应的域名服务器建立通信连接,向该域名服务器发送域名解析请求消息。域名解析请求消息包含有小基站配置的网元域名;域名服务器接收到域名解析请求消息,可对其进行解析,得到网元域名,并根据网元域名与IP地址的映射关系,获取相应的网元IP地址;进一步地,域名服务器在向小基站反馈网元IP地址时,可将网元IP地址加入到域名解析响应消息中并发送给小基站。应该注意的是,本申请实施例提及的域名解析响应消息的类型可与域名解析请求消息的类型相同,具体的消息类型可由实际组网采用的协议来确定,在此不做限定。小基站可基于域名解析响应消息,获取网元IP地址,并根据该网元IP地址,与对应的小基站系统网元建立通信连接,与网元进行数据交互,进而接入整个组网系统中。
需要说明的是,小基站系统网元可为安全网关、信令网关或网管服务器等网元,此处不做具体限制。各小基站系统网元可配置对应的域名服务器;并且,域名服务器可配置于对应的网元服务器中,与网元一起设置在同一台设备上,也可与网元设于不同的设备上。
本申请实施例中,小基站配置小基站系统中网元的网元域名,通过与域名 服务器进行交互,转换域名得到相应的IP地址,进而实现与网元的连接。基于此,在小基站中,采用域名配置代替固定的IP地址,可避免在小基站本地调试客服端上暴露安全网关的IP地址,降低网络攻击和小基站网络瘫痪的风险,提高小基站系统的安全性和稳定性。同时,在网元的IP地址割接时,无需变更小基站的IP参数配置,只需调整域名服务器中域名与IP地址的对应关系即可,有效降低大批量基站退服的风险。
在一个实施例中,小基站系统网元为安全网关。
如图3所示,小基站获取小基站系统网元的DNS地址的步骤包括:
步骤S112,小基站向DHCP服务器发送DHCP请求信息;
步骤S114,小基站接收DHCP服务器基于DHCP请求信息反馈的DNS地址;DNS地址为安全网关配置的域名服务器的地址。
具体而言,DHCP服务器可用于为小基站分配IP地址并反馈域名服务器的地址。小基站可在接入组网系统后,发送DHCP请求消息给DHCP服务器。DHCP服务器根据DHCP请求消息,为该小基站分配IP地址,并向该小基站反馈安全网关的域名服务器地址;具体地,DHCP服务器可将分配的IP地址与安全网关的域名服务器地址加入到DHCP响应消息中,并发送给小基站。小基站获取DHCP响应消息并进行解析,可根据分配的IP地址对自身进行地址参数配置,且可根据安全网关的域名服务器地址与对应的域名服务器交互,通过域名服务器对小基站自身配置的安全网关域名进行转换,得到安全网关地址,进而可与安全网关建立连接。
传统的小基站系统中,安全网关、网管服务器、信令网关等网元都是采用固定IP方式与现网所有小基站进行数据交互,存在前述网络隐患。同时,目前业界客服端(含其它领域客服端)只支持配置一种域名解析的方法,即,大部分基站只配置一套域名,若组网系统中的网元同时分布在局域网和广域网中,则该方式无法解决当基站需要同时通过域名解析方法访问局域网和广域网。
为此,在一个实施例中,小基站系统网元为信令网关或网管服务器。
如图4所示,小基站获取小基站系统网元的DNS地址的步骤包括:
步骤S116,小基站向安全网关传输DNS地址请求。
步骤S118,小基站接收安全网关基于DNS地址请求反馈的DNS地址;DNS地址包括信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址。
具体而言,小基站接入安全网关后,可与安全网关协商,获取信令网关的域名服务器地址、网管服务器的域名服务器地址。具体地,小基站可通过发送DNS地址请求消息给安全网关,请求反馈域名服务器的地址;其中,DNS地址请求消息的类型可根据小基站与安全网关之间的协议或连接方式来确定,此处不做具体限定。安全网关根据DNS地址请求消息,向小基站反馈相应的域名服务器的地址;具体地,安全网关可将相应的域名服务器的地址加入到DNS地址响应消息中并发送给小基站。
需要说明的是,信令网关对应的域名服务器可配置有信令网关域名与信令网关IP地址的映射数据,可用于处理域名解析请求,反馈信令网关域名对应的 IP地址。网管服务器对应的域名服务器可配置有网管服务器域名与网关服务器IP地址的映射数据,可用于处理域名解析请求,反馈网关服务器域名对应的IP地址。
本申请实施例中,小基站还能以域名的方式配置小基站组网系统中的多个网元的地址;相应地,各网元也可配置对应的域名服务器。基于此,小基站在与安全网关建立通信连接后,可向安全网关请求组网系统中其他网元的域名服务器的地址,进而可与相应的域名服务器进行交互,实现网元域名与网元IP地址的转换,从而得到IP地址并接入对应的网元。应该注意的是,此处小基站可通过配置固定IP的方式与安全网关建立连接,也可通过上述为将网元地址配置为域名的方式与安全网关建立连接。
本申请实施例在小基站系统中,可对多个网元均采用域名配置地址的方式,例如,对小基站系统中安全网关、信令网关和网管服务器都采用域名配置地址。基于此,小基站可采用多套域名组网的方式,支持多套域名解析IP方法,进而可实现同时在广域网及局域网内进行域名解析的功能。
在一个实施例中,小基站可配置有安全网关域名和信令网关域名。
小基站可基于安全网关获取信令网关的DNS地址,根据该地址向信令网关配置的域名服务器传输域名解析请求;该域名解析请求包含小基站配置的信令网关域名。
小基站接收域名服务器传输的信令网关IP地址,并根据信令网关IP地址接入信令网关,与信令网关进行信令数据交互;该信令网关IP地址由信令网关域名经域名服务器解析后得到。
具体而言,小基站向安全网关发送DNS地址请求消息后,可从安全网关获取到信令网关对应的DNS地址。小基站根据该DNS地址,可与信令网关对应的域名服务器建立通信连接,向该域名服务器发送域名解析请求消息。域名解析请求消息包含有小基站配置的信令网关域名;域名服务器接收到域名解析请求消息,可对其进行解析,得到信令网关域名,并根据信令网关域名与IP地址的映射关系,获取相应的信令网关IP地址。进一步地,域名服务器在向小基站反馈信令网关IP地址时,可将信令网关IP地址加入到域名解析响应消息中并发送给小基站。需要说明的是,该域名服务器可配置于信令网关服务器中,与信令网关一起设置在同一台设备上,也可与信令网关设于不同的设备上。
小基站可基于域名解析响应消息,获取信令网关IP地址,并根据该信令网关IP地址,与信令网关建立通信连接,接入信令网关,与信令网关进行信令数据交互,进而可实现核心网注册等功能。
本申请实施例中,小基站组网系统的安全网关和信令网关可分别配置有域名服务器;相应地,小基站以域名的方式配置安全网关和信令网关的地址。小基站在接入安全网关后,可获取信令网关的域名服务器的地址,进而能够转换信令网关域名,得到对应的IP地址并接入信令网关。基于此,小基站支持多套域名解析IP方式,可与安全网关和信令网关同时采用域名解析,得到域名对应的IP地址。
在一个实施例中,小基站配置有安全网关域名和网管服务器域名。
小基站可基于安全网关获取网管服务器的DNS地址,根据该地址向网管服务器配置的域名服务器传输域名解析请求;该域名解析请求包含小基站配置的网管服务器域名。
小基站接收域名服务器传输的网管服务器IP地址,并根据网管服务器IP地址接入网管服务器,与网管服务器进行信令数据交互;该网管服务器IP地址由网管服务器域名经域名服务器解析后得到。
具体而言,小基站向安全网关发送DNS地址请求消息后,可从安全网关获取到网管服务器对应的DNS地址。小基站根据该DNS地址,可与网管服务器对应的域名服务器建立通信连接,向该域名服务器发送域名解析请求消息。域名解析请求消息包含有小基站配置的网管服务器域名;域名服务器接收到域名解析请求消息,可对其进行解析,得到网管服务器域名,并根据网管服务器域名与IP地址的映射关系,获取相应的网管服务器IP地址。进一步地,域名服务器在向小基站反馈网管服务器IP地址时,可将网管服务器IP地址加入到域名解析响应消息中并发送给小基站。需要说明的是,该域名服务器可配置于网管服务器服务器中,与网管服务器一起设置在同一台设备上,也可与网管服务器设于不同的设备上。
小基站可基于域名解析响应消息,获取网管服务器IP地址,并根据该网管服务器IP地址,与网管服务器建立通信连接,接入网管服务器,与网管服务器进行监控数据交互,进而可实现远程监控、小基站配置、小基站升级以及小基站告警等功能。
本申请实施例中,小基站组网系统的安全网关和网管服务器可分别配置有域名服务器;相应地,小基站以域名的方式配置安全网关和网管服务器的地址。小基站在接入安全网关后,可获取网管服务器的域名服务器的地址,进而能够转换网管服务器域名,得到对应的IP地址并接入网管服务器。基于此,小基站支持多套域名解析IP方式,可与安全网关和网管服务器同时采用域名解析,得到域名对应的IP地址。
在一个实施例中,如图5所示,小基站向安全网关传输DNS地址请求的步骤之前,包括步骤:
步骤S108,小基站基于安全网关IP地址,向安全网关传输IKE_INIT请求消息;IKE_INIT请求消息用于指示安全网关与小基站建立IPSec连接。
具体而言,小基站根据安全网关IP地址,向安全网关发送IKE_INIT请求消息,进而可获得安全网关反馈的IKE_INIT响应消息,与安全网关建立IPSec连接。需要说明的是,IKE_INIT请求消息可用于发起建立IPSec连接,还可用于协商IKE加密算法及秘钥等。本申请实施例中,小基站与安全网关之间可建立IPSec连接,提高组网系统的安全性,尤其是地址数据传输的安全性。
进一步地,基于IPSec连接,小基站向安全网关发送的DNS地址请求消息可为IKE_AUTH请求消息。安全网关接收该IKE_AUTH请求消息,将DNS地址加入到IKE_AUTH响应消息中,并将该IKE_AUTH响应消息反馈给小基站。小基站基于IPSec连接,接收IKE_AUTH响应消息并进行解析,可得到DNS地址。
需要说明的是,IKE_AUTH请求消息可用于请求反馈域名服务器的地址,还可用于协商ESP(Encapsulating Security Payload,封装安全负载)加密算法、秘钥和隧道IP等。安全网关将DNS地址加入到IKE_AUTH响应消息时,可将地址加入到小基站与配套网元约定的协议字段中,也可将地址加入到空白的协议字段中,以便小基站从不同厂商的网元中获取到地址数据。
在一个实施例中,DNS地址请求为小基站基于IPSec连接生成的IKE_AUTH请求消息。
如图5所示,小基站接收安全网关基于DNS地址请求反馈的DNS地址;DNS地址为信令网关配置的域名服务器的地址,或网管服务器配置的域名服务器的地址的步骤包括:
步骤S119,小基站接收安全网关传输的IKE_AUTH响应消息;IKE_AUTH响应消息为Attribute Type字段中加入了DNS地址的消息。
具体而言,利用对IPsec协议的IKE_AUTH可选字段,可达到获取域名服务器的地址的效果;在IKE_AUTH响应消息中,Attribute Type字段属于空白的协议字段,安全网关可将DNS地址加入到Attribute Type字段中。小基站通过解析IKE_AUTH响应消息中的Attribute Type字段,可得到DNS地址。
进一步地,小基站获取到多套域名服务器的地址时,可将多套地址存储在小基站的相关配置文件中。小基站可采用待连接网元的域名、对多套DNS地址进行轮询调用,从而获取对应的域名服务器提供的网元IP地址;也可采用其中一个DNS地址、对多个待连接网元的域名进行轮询调用,从而获取该域名服务器对应的网元IP地址。
在一个实施例中,提供了一种小基站接入方法,应用于配置有域名服务器的小基站系统网元;如图6所示,小基站接入方法包括:
步骤S210,小基站系统网元通过配置的域名服务器,接收小基站基于获取到的DNS地址传输的域名解析请求;域名解析请求包含小基站配置的对应小基站系统网元的网元域名。
步骤S220,小基站系统网元通过域名服务器,将解析网元域名得到的网元IP地址传输给小基站;网元IP地址用于指示小基站接入小基站系统网元。
具体而言,小基站系统网元配置了域名服务器,该域名服务器包含了网元域名与网元IP地址的映射数据。该域名服务器接收域名解析请求消息,获取其中的网元域名,并根据映射数据,得到网元域名对应的网元IP地址,将该网元IP地址发送给小基站。域名解析请求消息为小基站根据获取到的域名服务器的地址、向该域名服务器发送的消息,并且,小基站配置有安全网关域名。
本申请实施例中,小基站系统网元配置有相应的域名服务器,小基站根据配置的网元域名、通过与网元的域名服务器进行交互,转换域名得到相应的IP地址,进而与网元建立连接。基于此,可避免在小基站本地调试客服端上暴露安全网关的IP地址,降低网络攻击和小基站网络瘫痪的风险。同时,在安全网关的IP地址割接时,无需变更小基站的IP参数配置,只需调整安全网关的域名服务器中域名与IP地址的对应关系即可,有效降低大批量基站退服的风险。
在一个实施例中,小基站系统网元为安全网关;网元IP地址为安全网关IP 地址。
小基站系统网元通过域名服务器,将解析网元域名得到的网元IP地址传输给小基站的步骤之后,包括步骤:
安全网关在接收到小基站传输的DNS地址请求时,将信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址传输给小基站。
具体而言,小基站系统中各网元均可配置相应的域名服务器,同时,小基站可以域名的方式配置各网元的地址。小基站根据安全网关域名服务器反馈的安全网关IP地址,与安全网关进行交互,可进一步获取小基站系统中其他网元的域名服务器地址,进而可实现相应的域名转换,得到相关网元的IP地址,完成进一步地接入,具体过程可如前文实施例所述,此处不再赘述。
在一个实施例中,如图7所示,安全网关在接收到小基站传输的DNS地址请求时,将信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址传输给小基站的步骤之前,还包括步骤:
步骤S230,安全网关接收小基站基于安全网关IP地址传输的IKE_INIT请求消息。
步骤S240,安全网关基于IKE_INIT请求消息与小基站建立IPSec连接。
在一个实施例中,DNS地址请求为IKE_AUTH请求消息。
如图7所示,安全网关将信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址传输给小基站的步骤,包括:
步骤S252,安全网关在Attribute Type字段中加入信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址,生成IKE_AUTH响应消息。
步骤S254,安全网关将IKE_AUTH响应消息传输给小基站。
在一个实施例中,如图7所示,小基站系统网元通过域名服务器,将解析域名解析请求得到的网元IP地址传输给小基站的步骤包括:
步骤S222,小基站系统网元通过域名服务器,在网元域名对应的多个网元IP地址中、随机分配一个网元IP地址给小基站。
具体而言,网元的域名服务器中,针对一个网元域名,可配置多个网元IP地址。在获取到网元域名时,该域名服务器可随机分配一个网元IP地址给小基站。基于此,本申请实施例采用一套域名匹配多个IP地址的方式,确保小基站系统网元不是采用固定IP与组网系统中所有小基站进行交互,可进一步降低网络攻击和网络风暴的风险,避免造成网络瘫痪。
应该理解的是,虽然图2至7的流程图中的各个步骤按照箭头的指示依次显示,但是这些步骤并不是必然按照箭头指示的顺序依次执行。除非本文中有明确的说明,这些步骤的执行并没有严格的顺序限制,这些步骤可以以其它的顺序执行。而且,图2至7中的至少一部分步骤可以包括多个子步骤或者多个阶段,这些子步骤或者阶段并不必然是在同一时刻执行完成,而是可以在不同的时刻执行,这些子步骤或者阶段的执行顺序也不必然是依次进行,而是可以与其它步骤或者其它步骤的子步骤或者阶段的至少一部分轮流或者交替地执行。
在一个实施例中,提供了一种小基站接入装置,应用于配置有网元域名的 小基站;如图8所示,小基站接入装置包括:
DNS地址获取模块,用于获取小基站系统网元的DNS地址。
域名解析请求模块,用于根据DNS地址,向小基站系统网元配置的域名服务器传输域名解析请求;域名解析请求包含小基站配置的、对应小基站系统网元的网元域名。
IP地址获取模块,用于域名服务器传输的网元IP地址,并根据网元IP地址接入小基站系统网元;网元IP地址由网元域名经域名服务器解析后得到。
在一个实施例中,提供了一种小基站接入装置,应用于配置有域名服务器的小基站系统网元;如图9所示,小基站接入装置包括:
网元域名获取模块,用于通过配置的域名服务器,接收小基站基于获取到的DNS地址传输的域名解析请求;域名解析请求包含小基站配置的对应小基站系统网元的网元域名。
IP地址反馈模块,用于通过域名服务器,将解析网元域名得到的网元IP地址传输给小基站;网元IP地址用于指示小基站接入小基站系统网元。
关于小基站接入装置的具体限定可以参见上文中对于小基站接入方法的限定,此处不再赘述。上述小基站接入装置中的各个模块可全部或部分通过软件、硬件及其组合来实现。上述各模块可以硬件形式内嵌于或独立于计算机设备中的处理器中,也可以以软件形式存储于计算机设备中的存储器中,以便于处理器调用执行以上各个模块对应的操作。
在一个实施例中,提供了一种设备,设备用于执行上述应用于小基站的小基站接入方法。
在一个实施例中,提供了一种设备,设备用于执行上述应用于小基站系统网元的小基站接入方法。可选地,该设备可为安全网关、信令网关或网管服务器,此处不做具体限制。
关于上述设备的具体限定可以参见上文中对于小基站接入方法的限定,此处不再赘述。
在一个实施例中,提供了一种系统,包括:小基站和小基站系统网元。其中,小基站用于执行上述应用于小基站的小基站接入方法;小基站系统网元用于执行上述应用于小基站系统网元的小基站接入方法。其中,小基站可与小基站系统网元建立通信连接。
关于上述系统的具体限定可以参见上文中对于小基站接入方法的限定,此处不再赘述。
在一个实施例中,系统还包括DHCP服务器,用于与小基站通信连接。如图10所示,该系统可实现如下步骤:
第1步:小基站出厂后其小基站安全网关地址配置为域名(如,域名为:smallcell.secgw.com.cn),小基站启动后,自动向DHCP服务器发起DHCP请求消息。
第2步:DHCP服务器收到请求后,对每台小基站随机分配小基站自身IP地址及DNS IP地址(即,安全网关的域名服务器地址),例如,小基站自身IP地址可为10.92.127.122,DNS IP地址可为20.96.128.166;此DNS IP地址用于 小基站对安全网关发起域名解析请求。
第3步:小基站对小基站安全网关域名服务器发起域名解析请求,获取到小基站安全网关的IP地址。
第4步:小基站安全网关域名服务器响应小基站请求消息,回复小基站安全网关IP地址,例如,安全网关地址为:20.96.128.170;应该注意的是,该IP地址不唯一。
第5步:小基站与小基站安全网关采用获取到的IP进行数据交互。
在一个实施例中,系统还包括配置有域名服务器的信令网关,和/或配置有域名服务器的网管服务器。小基站还配置有信令网关域名和/或网管服务器域名。
信令网关的域名服务器,用于在信令网关域名对应的多个信令网关IP地址中,随机分配一个信令网关IP地址给小基站。
网管服务器的域名服务器,用于在信令网关域名对应的多个信令网关IP地址中,随机分配一个信令网关IP地址给小基站。
具体而言,不同域名服务器(至少包括小基站安全网关域名服务器、小基站信令网关域名服务器和小基站网管域名服务器)均可对应多个IP地址,每台域名服务器解析域名后,随机分配一个IP地址给小基站进行交互。
在一个实施例中,系统还包括配置有域名服务器的信令网关;小基站还配置有信令网关域名;如图11所示,系统可实现如下步骤:
第1步:小基站出厂后其小基站安全网关地址配置为域名(如,域名为:smallcell.secgw.com.cn),小基站启动后,其自动向DHCP服务器发起DHCP请求消息。
第2步:DHCP服务器收到请求后,对每台小基站随机分配小基站自身IP地址及DNS IP地址(如,小基站自身IP地址为10.92.127.122,DNS IP地址为20.96.128.166),此DNS IP地址用于小基站对安全网关发起域名解析请求。
第3步:小基站对小基站安全网关域名服务器发起域名解析请求,获取到小基站安全网关的IP地址。
第4步:小基站安全网关域名服务器响应小基站请求消息,回复小基站安全网关IP地址(如,安全网关地址为:20.96.128.170),此IP地址不唯一。
第5步:小基站与小基站安全网关IP采用交互,对小基站安全网关发起IPSec建立请求IKE_INIT消息,协商IKE加密算法及秘钥等。
第6步:小基站安全网关对小基站回复IKE_INIT消息。
第7步:小基站对小基站安全网关发起IKE_AUTH请求,协商ESP加密算法、秘钥、隧道IP、DNS IP地址等。
第8步:小基站安全网关对小基站回复IKE_AUTH消息,小基站从消息里面解析出DNS IP地址(如:小基站信令网关DNS IP地址为100.96.128.16)。
第9步:小基站出厂后其小基站信令网关地址配置为域名(如,域名为smallcell.agw.com.cn),小基站对其发起域名解析请求信息到小基站信令网关域名服务器。
第10步:小基站信令网关域名服务器返回域名解析结果消息到小基站,回复小基站信令网关IP地址(如,小基站信令网关地址为:200.96.128.100),此 IP地址不唯一。
第11步:小基站与小基站信令网关进行信令数据交互,完成核心网注册等。
在一个实施例中,系统还包括配置有域名服务器的网管服务器;小基站还配置有网管服务器域名;如图12所示,系统可实现如下步骤:
第1步:小基站出厂后其小基站安全网关地址配置为域名(如,域名为:smallcell.secgw.com.cn),小基站启动后,其自动向DHCP服务器发起DHCP请求消息。
第2步:DHCP服务器收到请求后,对每台小基站随机分配小基站自身IP地址及DNS IP地址(如,小基站自身IP地址为10.92.127.122,DNS IP地址为20.96.128.166),此DNS IP地址用于小基站对安全网关发起域名解析请求。
第3步:小基站对小基站安全网关域名服务器发起域名解析请求,获取到小基站安全网关的IP地址。
第4步:小基站安全网关域名服务器响应小基站请求消息,回复小基站安全网关IP地址(如,安全网关地址为:20.96.128.170),此IP地址不唯一。
第5步:小基站与小基站安全网关IP采用交互,对小基站安全网关发起IPSec建立请求IKE_INIT消息,协商IKE加密算法及秘钥等。
第6步:小基站安全网关对小基站回复IKE_INIT消息。
第7步:小基站对小基站安全网关发起IKE_AUTH请求,协商ESP加密算法、秘钥、隧道IP、DNS IP地址等。
第8步:小基站安全网关对小基站回复IKE_AUTH消息,小基站从消息里面解析出DNS IP地址(如:小基站网管DNS IP地址为200.96.128.16)。
第9步:小基站对小基站网管域名服务器(如,域名为smallcell.hms.com.cn)发起域名解析请求信息;
第10步:小基站网管域名服务器返回域名解析结果消息到小基站,回复小基站网管IP地址(如,小基站网管地址为:200.96.128.100),此IP地址不唯一。
第11步:小基站与小基站网管进行监控数据交互,完成远程监控等功能。
在一个实施例中,如图13所示,系统可实现如下步骤:
第1步:小基站对DHCP服务器发起DHCP请求信息。
第2步:DHCP服务器对小基站分配一个小基站自身IP地址及DNS IP地址(记为DNS IP1)。
第3步:小基站对安全网关域名服务器发起域名解析请求,获取到小基站安全网关的IP地址。
第4步:小基站安全网关域名服务器响应小基站请求消息,回复其小基站安全网关IP地址,此IP地址不唯一。
第5步:小基站根据获取到小基站安全网关IP地址,对小基站安全网关发起IPSec建立请求IKE_INIT消息,协商IKE加密算法及秘钥等。
第6步:小基站安全网关对小基站回复IKE_INIT消息。
第7步:小基站对小基站安全网关发起IKE_AUTH请求,协商ESP加密算法、秘钥、隧道IP、DNS IP地址等。
第8步:小基站安全网关对小基站回复IKE_AUTH消息,小基站从消息里面解析出DNS IP地址(记为:DNS IP2及DNS IP3)。
第9步:小基站对小基站信令网关域名服务器发起域名解析请求,获取到小基站信令网关的IP地址。
第10步:小基站信令网关域名服务器返回域名解析结果消息到小基站,随机给不同小基站分配小基站信令网关IP地址,此IP地址不唯一。
第11步:小基站与小基站信令网关进行信令数据交互,完成核心网注册等流程。
第12步:小基站对小基站网管域名服务器(如,域名为smallcell.hms.com.cn)发起域名解析请求信息。
第13步:小基站网管域名服务器返回域名解析结果消息到小基站,随机给不同小基站分配小基站网管IP地址,此IP地址不唯一。
第14步:小基站与小基站网管进行监控数据交互,完成远程监控等功能任务。
在一个实施例中,提供了一种计算机存储介质,其上存储有计算机程序,该程序被处理器执行时实现如上述的小基站接入方法。关于上述存储介质的具体限定可以参见上文中对于小基站接入方法的限定,此处不再赘述。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,所述的计算机程序可存储于一非易失性计算机可读取存储介质中,该计算机程序在执行时,可包括如上述各方法的实施例的流程。其中,本申请所提供的各实施例中所使用的对存储器、存储、数据库或其它介质的任何引用,均可包括非易失性和/或易失性存储器。非易失性存储器可包括只读存储器(ROM)、可编程ROM(PROM)、电可编程ROM(EPROM)、电可擦除可编程ROM(EEPROM)或闪存。易失性存储器可包括随机存取存储器(RAM)或者外部高速缓冲存储器。作为说明而非局限,RAM以多种形式可得,诸如静态RAM(SRAM)、动态RAM(DRAM)、同步DRAM(SDRAM)、双数据率SDRAM(DDRSDRAM)、增强型SDRAM(ESDRAM)、同步链路(Synchlink)DRAM(SLDRAM)、存储器总线(Rambus)直接RAM(RDRAM)、直接存储器总线动态RAM(DRDRAM)、以及存储器总线动态RAM(RDRAM)等。
以上所述实施例的各技术特征可以进行任意的组合,为使描述简洁,未对上述实施例中的各个技术特征所有可能的组合都进行描述,然而,只要这些技术特征的组合不存在矛盾,都应当认为是本说明书记载的范围。
以上所述实施例仅表达了本申请的几种实施方式,其描述较为具体和详细,但并不能因此而理解为对本申请范围的限制。应当指出的是,对于本领域的普通技术人员来说,在不脱离本申请构思的前提下,还可以做出若干变形和改进,这些都属于本申请的保护范围。因此,本申请的保护范围应以所附权利要求为准。

Claims (13)

  1. 一种小基站接入方法,包括以下步骤:
    所述小基站获取小基站系统网元的DNS地址;
    所述小基站根据所述DNS地址,向所述小基站系统网元配置的域名服务器传输域名解析请求;所述域名解析请求包含所述小基站配置的、对应所述小基站系统网元的网元域名;
    所述小基站接收所述域名服务器传输的网元IP地址,并根据所述网元IP地址接入所述小基站系统网元;所述网元IP地址由所述网元域名经所述域名服务器解析后得到。
  2. 根据权利要求1所述的小基站接入方法,其特征在于,所述小基站系统网元为安全网关;
    所述小基站获取小基站系统网元的DNS地址的步骤包括:
    所述小基站向DHCP服务器发送DHCP请求信息;
    所述小基站接收所述DHCP服务器基于所述DHCP请求信息反馈的所述DNS地址;所述DNS地址为所述安全网关配置的域名服务器的地址。
  3. 根据权利要求1所述的小基站接入方法,其特征在于,所述小基站系统网元为信令网关或网管服务器;
    小基站获取小基站系统网元的DNS地址的步骤,包括:
    所述小基站向安全网关传输DNS地址请求;
    所述小基站接收所述安全网关基于所述DNS地址请求反馈的所述DNS地址;所述DNS地址为所述信令网关配置的域名服务器的地址,或所述网管服务器配置的域名服务器的地址。
  4. 根据权利要求3所述的小基站接入方法,其特征在于,所述小基站向安全网关传输DNS地址请求的步骤之前,包括步骤:
    所述小基站基于安全网关IP地址,向所述安全网关传输IKE_INIT请求消息;所述IKE_INIT请求消息用于指示所述安全网关与所述小基站建立IPSec连接;
    所述DNS地址请求为所述小基站基于所述IPSec连接生成的IKE_AUTH请求消息;
    所述小基站接收所述安全网关基于所述DNS地址请求反馈的所述DNS地址;所述DNS地址包括所述信令网关配置的域名服务器的地址,和/或所述网管服务器配置的域名服务器的地址的步骤包括:
    所述小基站接收所述安全网关传输的IKE_AUTH响应消息;所述IKE_AUTH响应消息为Attribute Type字段中加入了所述DNS地址的消息。
  5. 一种小基站接入方法,包括以下步骤:
    小基站系统网元通过配置的域名服务器,接收小基站基于获取到的DNS地址传输的域名解析请求;所述域名解析请求包含所述小基站配置的对应所述小基站系统网元的网元域名;
    所述小基站系统网元通过所述域名服务器,将解析所述网元域名得到的网元IP地址传输给小基站;所述网元IP地址用于指示所述小基站接入所述小基站系统网元。
  6. 根据权利要求5所述的小基站接入方法,其特征在于,所述小基站系统网元为安全网关;所述网元IP地址为安全网关IP地址;
    所述小基站系统网元通过所述域名服务器,将解析所述网元域名得到的网元IP地址传输给小基站的步骤之后,包括步骤:
    所述安全网关在接收到所述小基站传输的DNS地址请求时,将信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址传输给所述小基站。
  7. 根据权利要求6所述的小基站接入方法,其特征在于,所述安全网关在接收到所述小基站传输的DNS地址请求时,将信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址传输给所述小基站的步骤之前,还包括步骤:
    所述安全网关接收所述小基站基于所述安全网关IP地址传输的IKE_INIT请求消息;
    所述安全网关基于所述IKE_INIT请求消息与所述小基站建立IPSec连接;所述DNS地址请求为IKE_AUTH请求消息;
    所述安全网关将信令网关配置的域名服务器的地址,和/或网管服务器配置的域名服务器的地址传输给所述小基站的步骤,包括:
    所述安全网关在Attribute Type字段中加入所述信令网关配置的域名服务器的地址,和/或所述网管服务器配置的域名服务器的地址,生成IKE_AUTH响应消息;
    所述安全网关将所述IKE_AUTH响应消息传输给所述小基站。
  8. 根据权利要求5至7任一项所述的小基站接入方法,其特征在于,所述小基站系统网元通过所述域名服务器,将解析所述域名解析请求得到的网元IP地址传输给小基站的步骤包括:
    所述小基站系统网元通过所述域名服务器,在所述网元域名对应的多个网元IP地址中、随机分配一个所述网元IP地址给所述小基站。
  9. 一种小基站接入装置,包括:
    DNS地址获取模块,用于获取小基站系统网元的DNS地址;
    域名解析请求模块,用于根据所述DNS地址,向所述小基站系统网元配置的域名服务器传输域名解析请求;所述域名解析请求包含所述小基站配置的、对应所述小基站系统网元的网元域名;
    IP地址获取模块,用于所述域名服务器传输的网元IP地址,并根据所述网元IP地址接入所述小基站系统网元;所述网元IP地址由所述网元域名经所述域名服务器解析后得到。
  10. 一种小基站接入装置,包括:
    网元域名获取模块,用于通过配置的域名服务器,接收小基站基于获取到的DNS地址传输的域名解析请求;所述域名解析请求包含所述小基站配置的对应所述小基站系统网元的网元域名;
    IP地址反馈模块,用于通过所述域名服务器,将解析所述网元域名得到的网元IP地址传输给小基站;所述网元IP地址用于指示所述小基站接入所述小基 站系统网元。
  11. 一种设备,所述设备用于执行如权利要求1至8中任一项所述的小基站接入方法。
  12. 一种小基站系统,包括:小基站和小基站系统网元;
    所述小基站用于执行如权利要求1至4中任一项所述的小基站接入方法;
    所述小基站系统网元用于执行如权利要求5至8中任一项所述的小基站接入方法。
  13. 一种计算机存储介质,其上存储有计算机程序,该程序被处理器执行时实现如权利要求1至8任一项所述的小基站接入方法。
PCT/CN2019/124695 2019-05-29 2019-12-11 小基站接入方法、装置、设备、系统以及存储介质 WO2020238149A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910457208.9A CN110166583A (zh) 2019-05-29 2019-05-29 小基站接入方法、装置、设备、系统以及存储介质
CN201910457208.9 2019-05-29

Publications (1)

Publication Number Publication Date
WO2020238149A1 true WO2020238149A1 (zh) 2020-12-03

Family

ID=67629743

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/124695 WO2020238149A1 (zh) 2019-05-29 2019-12-11 小基站接入方法、装置、设备、系统以及存储介质

Country Status (2)

Country Link
CN (1) CN110166583A (zh)
WO (1) WO2020238149A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110166583A (zh) * 2019-05-29 2019-08-23 京信通信系统(中国)有限公司 小基站接入方法、装置、设备、系统以及存储介质
CN112788782B (zh) * 2020-12-31 2023-08-22 瑞斯康达科技发展股份有限公司 一种小基站、小基站系统和小基站系统的开通方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101515881A (zh) * 2008-02-21 2009-08-26 华为技术有限公司 下发接入点设备初始配置信息的方法、装置及系统
CN101674624A (zh) * 2008-09-11 2010-03-17 三星电子株式会社 家用基站网关动态切换方法
US20160219017A1 (en) * 2013-09-09 2016-07-28 Telefonaktiebolaget Lm Ericsson (Publ) Connecting radio base stations via a third party network
CN110166583A (zh) * 2019-05-29 2019-08-23 京信通信系统(中国)有限公司 小基站接入方法、装置、设备、系统以及存储介质

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100372330C (zh) * 2005-10-31 2008-02-27 华为技术有限公司 一种基站选择接入服务网络网关的方法
CN101360094B (zh) * 2007-08-03 2012-06-13 中兴通讯股份有限公司 一种家庭基站配置服务器自动发现的方法
CN106803846A (zh) * 2015-11-26 2017-06-06 中国电信股份有限公司 为wlan中ap分配工作ac的方法、设备以及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101515881A (zh) * 2008-02-21 2009-08-26 华为技术有限公司 下发接入点设备初始配置信息的方法、装置及系统
CN101674624A (zh) * 2008-09-11 2010-03-17 三星电子株式会社 家用基站网关动态切换方法
US20160219017A1 (en) * 2013-09-09 2016-07-28 Telefonaktiebolaget Lm Ericsson (Publ) Connecting radio base stations via a third party network
CN110166583A (zh) * 2019-05-29 2019-08-23 京信通信系统(中国)有限公司 小基站接入方法、装置、设备、系统以及存储介质

Also Published As

Publication number Publication date
CN110166583A (zh) 2019-08-23

Similar Documents

Publication Publication Date Title
US11576023B2 (en) Method and apparatus for providing a secure communication in a self-organizing network
CN110087236B (zh) 用于通过无线网络与匿名主机建立安全通信会话的协议
EP1872250B1 (en) Wireless device discovery and configuration
EP2950497B1 (en) Method and apparatus for controlling access in wireless communication system
WO2019149097A1 (zh) 一种待配网设备接入网络热点设备的方法和系统
CN107113299B (zh) 向设备的租用的分配
WO2019223887A1 (en) Methods for processing encrypted domain name server, dns, queries received from user equipment in a telecommunication network
US10075410B2 (en) Apparatus and methods for assigning internetwork addresses
US11196703B2 (en) Connecting radio base stations via a third party network
WO2020238149A1 (zh) 小基站接入方法、装置、设备、系统以及存储介质
WO2021197175A1 (zh) 应用服务器的发现方法及相关装置
US8400990B1 (en) Global service set identifiers
US20220263879A1 (en) Multicast session establishment method and network device
WO2019009263A1 (ja) 機器をリモートで管理するための装置、方法及びそのためのプログラム
US9413590B2 (en) Method for management of a secured transfer session through an address translation device, corresponding server and computer program
WO2018054272A1 (zh) 数据的发送方法和装置、计算机存储介质
CN110278558B (zh) 报文的交互方法及wlan系统
CN102883265B (zh) 接入用户的位置信息发送和接收方法、设备及系统
CN105340238A (zh) 使用公共anqp组版本的anqp查询的系统和方法
CN109120738B (zh) Dhcp服务器及其进行网络内部设备管理的方法
CN114025010B (zh) 建立连接的方法和网络设备
WO2020253343A1 (zh) 一种管理服务的发现方法及装置
WO2023141945A1 (en) Authentication mechanism for access to an edge data network based on tls-psk
WO2023011158A1 (zh) 一种证书管理方法和装置
Goto et al. Proposal of an extended CYPHONIC adapter supporting general nodes using virtual IPv6 addresses

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19930206

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19930206

Country of ref document: EP

Kind code of ref document: A1