WO2023001046A1 - 一种通信方法及装置 - Google Patents

一种通信方法及装置 Download PDF

Info

Publication number
WO2023001046A1
WO2023001046A1 PCT/CN2022/105550 CN2022105550W WO2023001046A1 WO 2023001046 A1 WO2023001046 A1 WO 2023001046A1 CN 2022105550 W CN2022105550 W CN 2022105550W WO 2023001046 A1 WO2023001046 A1 WO 2023001046A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal device
information
access network
fixed network
network
Prior art date
Application number
PCT/CN2022/105550
Other languages
English (en)
French (fr)
Inventor
徐艺珊
谭仕勇
诸华林
马川
李�赫
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to JP2024503392A priority Critical patent/JP2024530416A/ja
Priority to KR1020247005503A priority patent/KR20240027855A/ko
Priority to EP22845211.6A priority patent/EP4369756A1/en
Publication of WO2023001046A1 publication Critical patent/WO2023001046A1/zh
Priority to US18/415,324 priority patent/US20240155705A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/12Setup of transport tunnels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L1/00Arrangements for detecting or preventing errors in the information received
    • H04L1/12Arrangements for detecting or preventing errors in the information received by using return channel
    • H04L1/16Arrangements for detecting or preventing errors in the information received by using return channel in which the return channel carries supervisory signals, e.g. repetition request signals
    • H04L1/1607Details of the supervisory signal
    • H04L1/1642Formats specially adapted for sequence numbers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/18Selecting a network or a communication service
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/20Transfer of user or subscriber data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/22Processing or transfer of terminal data, e.g. status or physical capabilities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/22Processing or transfer of terminal data, e.g. status or physical capabilities
    • H04W8/24Transfer of terminal data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/25Mapping addresses of the same type
    • H04L61/2503Translation of Internet protocol [IP] addresses
    • H04L61/2514Translation of Internet protocol [IP] addresses between local and global IP addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • H04L61/5014Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/08Access point devices

Definitions

  • the embodiments of the present application relate to the field of communication technologies, and in particular, to a communication method and device.
  • Fixed-line networks usually provide broadband services to households, shops, and other places based on fixed lines.
  • fixed network terminals such as customer-premises equipment (CPE)
  • CPE customer-premises equipment
  • BNG broadband network gateway
  • IPoE IP over ethernet
  • PPPoE point-to-point protocol over ethernet
  • the access network device supporting 3GPP access technology is used as the intermediate node between the terminal device and the fixed network gateway device, the terminal device uses the 3GPP access technology to establish a connection with the access network device, and the access network device
  • the data of the terminal equipment can be transmitted to the fixed network gateway equipment, so that the terminal equipment can also obtain fixed network broadband services through 3GPP access.
  • wired access to the fixed-line network can simplify deployment, enhance coverage, and improve communication system performance.
  • the first information is from the first terminal device, and the first information indicates that a type of the first terminal device is the target type.
  • the first information is preconfigured in the access network device or the first information comes from the first fixed network gateway device; wherein the first information includes the Subscription data information corresponding to the first terminal device, where the subscription data information is used to determine that the first terminal device is allowed to obtain services through the first fixed network gateway device. Establishing a user plane connection in this way can simplify the access process of the terminal device, and can save signaling overhead and reduce costs.
  • the access network device executes a user plane connection management process according to the third information; wherein, the user plane management process includes at least one of the following operations: establishing user plane resources, modifying user plane resources or release user plane resources.
  • the method further includes: the access network device acquiring fourth information from the first terminal device, where the fourth information is used to determine the security context of the first terminal device information; the access network device uses the security context information of the first terminal device to establish a secure connection between the access network device and the first terminal device according to the fourth information. Establishing a secure connection between the access network device and the terminal device by using the security context information of the terminal device can improve communication security.
  • Capability information of the access network device the capability information indicating that the access network device supports fixed network transmission; identification information of the fixed network network supported by the access network device, and fixed network transmission supported by the access network device
  • the network network includes a fixed network network corresponding to the first fixed network gateway device; network priority information, where the network priority information is used to indicate the priority of the mobile operator to which the access network device belongs.
  • the embodiment of the present application provides a communication device, which is applied to an access network device supporting a 3GPP access technology.
  • the communication device may be an access network device, or a device in the access network device, or a device that can be matched and used with the access network device.
  • the communication device may include a one-to-one corresponding module for executing the method/operation/step/action described in the first aspect.
  • the module may be a hardware circuit, or software, or a combination of hardware circuit and software.
  • the communication device may include a processing module and a communication module. Exemplarily,
  • a communication module configured to obtain first information
  • a processing module configured to establish a user plane connection with a first terminal device according to the first information
  • the communication module is also configured to obtain the first information through the user plane connection.
  • User plane data of the terminal device and send the user plane data to the first fixed network gateway device.
  • the first information is from the first terminal device, and the first information indicates that a type of the first terminal device is the target type.
  • the communication module is further configured to send second information to the first fixed network gateway device, and the second information is used to request management of a connection between the first terminal device and the first fixed network gateway device .
  • management may include establishing, modifying, releasing or deleting and so on.
  • FIG. 8 is a schematic diagram of a protocol stack architecture provided by an embodiment of the present application.
  • FIG. 2 shows a fixed network transmission protocol stack.
  • the aforementioned fixed network terminal accesses the fixed network in a wired manner through the access node, such as the connection between the fixed network terminal and the access node, and between the access node and the BNG through an optical cable .
  • Fixed network terminal and BNG can communicate through IPoE or PPPoE protocol. If the terminal device uses IPoE, it needs to go through the authentication process and obtain an IP address. If the terminal adopts PPPoE, it will establish a PPPoE connection with the BNG and obtain the PPPoE session ID.
  • the fixed network terminal can convert the wired broadband network into a WiFi network for notebooks, mobile phones, etc.
  • an IPoE communication flow is illustrated, which illustrates the process of a fixed network terminal performing IPoE authentication and obtaining an IP address.
  • BNG which can be BRAS or SR
  • DHCP server dynamic host configuration protocol server
  • AAA authentication, authorization, accounting
  • the DHCP Server is used to assign IP addresses to fixed network terminals that have passed the authentication
  • the AAA server is used to perform authentication, such as whether the authentication allows the fixed network terminal to go online, or whether to authenticate whether the fixed network terminal is enabled for broadband services.
  • the specific steps are as follows:
  • the fixed network terminal initiates a DHCP Discover (DHCP Discover) message, and carries information that can indicate the type of the fixed network terminal in the Option 60 field in the DHCP Discover message.
  • DHCP Discover DHCP Discover
  • the access node AN
  • receives the DHCP Discover message it can insert information for indicating the location of the fixed network terminal device in Option 82 of the DHCP Discover message, and then send the DHCP Discover to the BNG.
  • the process involved in the access node is omitted in FIG. 3 .
  • the AAA server authenticates the fixed network terminal; if the authentication fails, a rejection message such as access deny is fed back, the DHCP Server feeds back DHCP NACK to the BNG, and the BNG sends the fixed network terminal through the access node (AN) Feedback DHCP NACK; if the authentication is passed, an acceptance message is returned, such as access accept (access accept), the DHCP server assigns an IP address, and encapsulates the IP address assigned to the fixed network terminal into a DHCP response (DHCP Offer) message, Send it to the fixed network terminal through BNG; the authentication information (Option 125) is also inserted in the DHCP Offer message, so that the fixed network terminal can authenticate the DHCP Offer message and identify whether the DHCP Offer message comes from a trusted DHCP Server.
  • a rejection message such as access deny is fed back
  • the DHCP Server feeds back DHCP NACK to the BNG, and the BNG sends the fixed network terminal through the access node (AN) Feedback DHCP
  • Fig. 3 shows a possible execution of S34 with a dotted line, that is, S34a in Fig. 3: the DHCP server sends a DHCP NACK to the BNG, and the BNG sends the DHCP NACK to the fixed network terminal through the access node.
  • S34a in Fig. 3 the DHCP server sends a DHCP NACK to the BNG, and the BNG sends the DHCP NACK to the fixed network terminal through the access node.
  • Another possible execution of S34 is illustrated by a solid line, that is, S34b in FIG. 3 : the DHCP server sends a DHCP response to the BNG, and the BNG sends the DHCP response to the fixed network terminal through the access node.
  • a PPPoE communication process is illustrated, which illustrates the process of establishing a session between a PPPoE client (client) and a PPPoE server (server).
  • the PPPoE client may be the aforementioned fixed network terminal
  • the PPPoE server may be the aforementioned BNG.
  • a fixed network terminal is used to represent a PPPoE client
  • a BNG is used to represent a PPPoE server
  • the fixed network terminal sends a PPPoE active discovery initiation (PPPoE active discovery initiation, PADI) message to the BNG through the access node AN; the message is sent in the form of broadcast, and the message includes the service name of the service requested by the fixed network terminal.
  • PPPoE active discovery initiation PADI
  • the access node AN between the fixed network terminal equipment and the BNG is omitted.
  • the BNG After receiving the PADI message, the BNG judges whether it can provide the service. If it can provide the service, it will respond by sending a PPPoE Active Discovery Offer (PADO) message to the fixed network terminal through the access node. .
  • the PADO message includes the same service name as the name of the PPPoE server (ie, BNG) in the PADI message. If BNG cannot provide this service, no PADO message will be sent.
  • FIG. 4 schematically shows the situation that the BNG can provide services, that is, S42: the BNG sends a PADO message to the fixed network terminal.
  • the AN is omitted, that is, the BNG sends the PADO message; the AN receives the PADO message and sends the PADO message to the fixed network terminal.
  • the fixed network terminal may receive more than one PADO message.
  • the fixed network terminal may select according to the server name in the PADO or the service provided.
  • a PPPoE server that is, BNG
  • PPPoE Active Discovery Request PPPoE Active Discovery Request, PADR
  • the PADR message includes the services requested by the fixed network terminal.
  • the BNG After the BNG receives the PADR message sent by the fixed network terminal, the BNG sends a PPPoE Active Discovery Session-confirmation (PADS) message to the fixed network terminal through the access node as a response.
  • the PADS is used to set up a PPPoE session, such as BNG creates a PPPoE session ID (Session ID) for the PPPoE session, and the PADS message includes the PPPoE session ID. Then both communication parties can obtain the session ID and the MAC address (address) of the other party, and then define a PPPoE session based on the session ID (Session ID) and the MAC address.
  • the authentication phase between the fixed network terminal and the BNG involves Password Authentication Protocol (Password Authentication Protocol, PAP) and Challenge Handshake Authentication Protocol (Challenge Handshake Authentication Protocol, CHAP).
  • Password Authentication Protocol PAP
  • Challenge Handshake Authentication Protocol CHAP
  • the wired access fixed network solution introduced above involves the laying of optical cables. However, for some remote areas, limited by the environment or actual regional jurisdiction, it is impossible or difficult to lay optical fibers, resulting in a low rate of optical fiber access. It can be seen that the technology of obtaining broadband services through wired access to fixed networks is not suitable for these areas.
  • a plurality referred to in this application refers to two or more than two.
  • "And/or” describes the association relationship of associated objects, indicating that there may be three types of relationships, for example, A and/or B may indicate: A exists alone, A and B exist simultaneously, and B exists independently.
  • the character "/” generally indicates that the contextual objects are an "or” relationship.
  • first, second, etc. may be used to describe various data in the embodiments of the present invention, these data should not be limited to these terms. These terms are only used to distinguish data from one another.
  • the access network device may also be a base station device in a 5G network or a network device in a future evolved public land mobile network (public land mobile network, PLMN) network.
  • the access network equipment may support 3GPP technology. It can be understood that the access network device can fully support the 3GPP protocol stack, or support a part of the 3GPP protocol stack, for example, only support part or all of the physical layer, MAC layer, RLC layer, PDCP layer, SDAP layer, and RRC layer protocol stack.
  • the fixed network gateway device involved in this embodiment of the present application may be a broadband network gateway BNG or other gateway devices.
  • the access network equipment may be deployed by a mobile operator, and the fixed network operator to which the fixed network gateway equipment belongs may lease the access network equipment by signing a contract with the mobile operator.
  • the access network equipment may not only serve the mobile operator's terminal equipment, but also serve the fixed network terminal of the fixed network operator with which the mobile operator signs a contract.
  • the access network equipment may be independently deployed by the fixed network operator.
  • the access network device may only serve the fixed network terminal of the fixed network operator.
  • the following describes in detail the scheme in which the terminal equipment accesses the fixed network through the access network equipment using the 3GPP access technology.
  • the network selection method mainly includes the following processes:
  • the terminal device receives a message sent by at least one access network device, and the message sent by each access network device includes the capability information of the access network device and/or indicates the fixed network network supported by the access network device. Identification information.
  • the message can be sent in the form of broadcast.
  • the capability information indicates whether the access network device supports fixed network transmission, or indicates whether it supports data transmission of a fixed network terminal such as a home gateway, and the aforementioned identification information may be a fixed network identifier and/or an identifier of a fixed network service provider.
  • An access network device may support one or more fixed network networks, and each fixed network network may include (or be called, correspond to) at least one fixed network gateway device.
  • the access network device may be connected to at least one fixed network gateway device in the fixed network network.
  • the access network device may be connected to at least one fixed network gateway device in each fixed network network network.
  • FIG. 6 schematically shows three access network devices, which are access network device 1, access network device 2, and access network device 3, respectively.
  • S601 in FIG. 6 specifically shows that the terminal device receives broadcast messages sent from the access network device 1 , the access network device 2 and the access network device 3 .
  • the terminal device performs network selection and cell selection according to the messages sent by each access network device.
  • the terminal device may perform network selection according to at least one of the information of the capability information of each access network device, fixed network identifier, fixed network service provider identifier information, and network priority information (hereinafter referred to as network selection).
  • network selection may be performed according to at least one of the information of the capability information of each access network device, fixed network identifier, fixed network service provider identifier information, and network priority information (hereinafter referred to as network selection).
  • network selection network
  • cell selection For example, a terminal device can select an access network device that supports fixed network transmission, and the terminal device can select a fixed network network among the fixed network networks corresponding to one or more fixed network gateway devices supported by the access network device that supports fixed network transmission , such as selecting the fixed network network corresponding to the first fixed network gateway device.
  • the access network device Based on the interaction process between the access network device and the terminal device, when the access network device receives the connection request, it can implicitly determine that the terminal device needs to obtain services through the fixed network gateway device supported by the access network device; or it can understand , the terminal device indirectly (or implicitly) reports to the network device through the connection request that it needs to obtain services through the fixed network gateway device supported by the access network device.
  • the access network device can also determine the type of the terminal device according to the format or protocol of the interactive message between the terminal device and the access network device.
  • the terminal device may include information indicating that the type of the terminal device is the target type in the connection request, and report the type of the terminal device to the access network device in a direct (or display) manner .
  • the terminal device may receive network information sent by at least one access network device, and select a network according to configuration information. Wherein, the network information may be sent in the form of broadcast.
  • the terminal device can also select an accessible cell according to requirements such as cell signal quality, and establish a control plane connection with the access network device corresponding to the selected network.
  • three access network devices are shown in FIG. 7 , which are access network device 1 , access network device 2 and access network device 3 .
  • the terminal device selects the access network device 1 and establishes a control plane connection (RRC connection) with the access network device 1 .
  • RRC connection control plane connection
  • the terminal device sends a first RRC message to the access network device 1.
  • the first RRC message includes at least one of the following information: information indicating that the type of the terminal device is the target type, and identification information of the fixed network network that the terminal device requests to access; wherein,
  • the aforementioned target types include one or more of home gateways, home terminals, and client terminal devices, and may also include mobile phones, AR/VR terminals, Pads, and other types of terminals, which are not limited in this embodiment of the present application; the aforementioned solid
  • the network identification information may include a fixed network identification and/or an identification provided by a service provider.
  • the access network device 1 may be agreed upon the type of terminal device that needs to access the fixed network, and if the first RRC message only includes the identification information of the fixed network network that the terminal device requests to access, the access network device 1 also The type of the terminal device may be judged according to the first RRC message. That is, in this case, the terminal device indirectly (or implicitly) reports its own type to the access network device 1 through the first RRC message.
  • different types of terminal devices and network devices may also be configured to have different message formats for interaction, for example, different signaling sizes. With such a design, the network device can determine the type of the terminal device according to the interaction between the terminal device and the network device.
  • the access network device 1 judges whether it supports fixed network transmission and data transmission requested by the terminal device.
  • the access network device 1 learns that the terminal device is a fixed network terminal such as a home gateway, a client terminal, or a home terminal according to the first RRC message, and determines that it can support fixed network transmission, it can judge according to the fixed network identifier/service provider identifier Whether it can support the data transmission requested by the aforementioned terminal equipment.
  • a fixed network terminal such as a home gateway, a client terminal, or a home terminal according to the first RRC message
  • S705 the access network device 1 sends a third RRC message to the terminal device, and the third RRC message includes information instructing the terminal device to perform network reselection and/or cell reselection.
  • S706 The access network device 1 releases the control plane connection (or RRC connection) with the terminal device. Furthermore, in the case that the access network device 1 does not support the data transmission of the terminal device, it is necessary to re-execute the network selection process until a suitable network and cell supporting its data transmission is selected for the terminal device.
  • an embodiment of the present application provides a protocol stack architecture, specifically illustrating a control plane protocol stack and a user plane protocol stack.
  • implementing the second solution may construct the protocol stack architecture, or it can be understood that the protocol stack architecture can be applied to the first solution.
  • the protocol stack shown in FIG. 8 is only used as a possible implementation manner, and this solution 1 may also adopt other protocol stack architectures, which are not limited in this embodiment of the present application.
  • the user plane protocol stack on the access network device side for communication with terminal devices is divided into 802.1ad protocol layer, SDAP layer, PDCP layer, RLC layer, MAC layer, and PHY layer.
  • the user plane protocol stack on the access network device side to communicate with the fixed network gateway device is divided into 802.1ad protocol layer, MAC layer, and PHY layer.
  • the user plane protocol stack on the fixed network gateway device side is divided into IPoE/PPPoE protocol layer, 802.1ad protocol layer, MAC layer, and PHY layer.
  • Access network equipment supports 3GPP access technology.
  • Terminal equipment and access network equipment can be transmitted through 3GPP technology (or cellular air interface).
  • terminal equipment can establish a control plane connection with access network equipment, and control plane messages can be transmitted through RRC Signaling is transmitted; the terminal device can establish a user plane connection with the access network device, and user plane messages can be transmitted through the user plane connection.
  • the access network device acts as a switch to transmit data with the fixed network gateway device in a wired manner.
  • the access network device can fully support the 3GPP protocol stack, and can also support part of the 3GPP protocol stack.
  • the access network device can support part or all of the protocol stacks in the PHY layer, MAC layer, RLC layer, PDCP layer, SDAP layer, and RRC layer. .
  • the following describes in detail different implementation manners of performing authentication and/or authentication of the terminal device in the process of accessing the network.
  • Method 1 The access network device acquires information used for authentication and authentication of the terminal device, and performs authentication and authentication of the terminal device.
  • a communication method is illustrated, which mainly includes the following process.
  • An access network device acquires first information, where the access network device supports a 3GPP access technology.
  • the access network equipment supports 3GPP access technology, which may include that the access network equipment supports air interface transmission of wireless networks such as 4G/5G.
  • the first information may be information pre-configured in the access network device or the first information is obtained from at least one fixed network gateway device connected to the access network device; wherein the first information includes at least one
  • the subscription data information corresponding to the terminal device the subscription data information is used to determine that the terminal device is allowed to obtain services through the fixed network gateway device, or the subscription data information is used to determine that the terminal device is not allowed to obtain fixed network services through the fixed network gateway device.
  • the subscription data information may include one or more of fixed network service information, service quality (quality of service, QoS) information, and priority information, and the QoS information and/or priority information may be used as subsequent user plane configuration information for the terminal device. basis for resources.
  • the first information may also include security context information and an identification set of the aforementioned at least one terminal device; wherein the security context information is used to establish a secure connection between the access network device and the terminal device, and the security context information may specifically include a root key, One or more of the public key, private key, certificate, and other information used to establish a secure connection.
  • Establishing a secure connection may include processes such as an authentication process or key negotiation.
  • the identification set may include a first sequence set and a second sequence set. It can be understood that the first sequence set includes at least one sequence number that is currently used to indicate the security context information of the terminal device, and the second sequence set includes multiple sequence numbers that are not currently used to indicate the security context information of the terminal device.
  • the access network device acquires fourth information from the first terminal device, where the fourth information is used to determine security context information of the first terminal device.
  • the fourth information may also include identification information of the fixed network network corresponding to the fixed network gateway device supported by the first terminal device, and the identification information of the fixed network network may include a fixed network identification and/or a fixed network service provider identification.
  • the fixed network gateway device supported by the first terminal device is the first fixed network gateway device, that is, the first fixed network gateway device can provide fixed network services for the first terminal device, and the fourth information includes the fixed network gateway device corresponding to the first fixed network gateway device.
  • the first fixed network gateway device may be included in at least one fixed network gateway device connected to the access network device.
  • the first terminal device may complete network selection according to any one of the foregoing two network selection methods. It can be understood that the first terminal device selects the access network device described in S902, and the first terminal device establishes a control plane connection with the access network device. Then the access network device may receive the fourth information sent by the first terminal device through the control plane connection between the access network device and the first terminal device.
  • the first terminal device completes network selection, establishes a control plane connection with the access network device, and the access network device connects through the control plane, and receives the first terminal device from the first terminal device.
  • the first terminal device completes network selection, establishes a control plane connection with the access network device, and the access network device connects through the control plane, and receives the first terminal device from the first terminal device.
  • the access network device establishes a secure connection between the access network device and the first terminal device according to the fourth information.
  • the access network device may acquire security context information and an identification set of at least one terminal device. For example, the first information introduced in S901 above, the access network device can obtain the security context information and the identification set of at least one terminal device from the first information; then the access network device determines that the first serial number set in the identification set includes the first serial number, the access network device may acquire the security context information of the first terminal device from the security context information and identification set of the at least one terminal device according to the first serial number, and use the first
  • the security context information of a terminal device establishes a secure connection between the access network device and the first terminal device. For example, the access network device may perform mutual authentication with the first terminal device according to the security context information corresponding to the first serial number, so as to determine that both the access network device and the first terminal device are trustworthy devices for each other.
  • the access network device may also replace the first serial number with a second serial number in the second serial number set, and send the A terminal device sends the second serial number, where the second serial number is used to indicate the security context information of the first terminal device.
  • the serial number used to indicate the security context information of the first terminal device stored in the first terminal device is replaced by the original first serial number Update to the second serial number.
  • the implementation time (or implementation stage) of replacing the first serial number with the second serial number may be performed immediately after S903, such as replacing the first serial number with the second serial number after S903 and before S904.
  • the second serial number; or, the first serial number may be replaced with the second serial number after the first terminal device accesses the fixed network.
  • the specific implementation time of the operation is not limited.
  • S912 to S914 after S911 in FIG. 9 illustrate the operation of replacing the first serial number with the second serial number.
  • the access network device establishes a user plane connection with the first terminal device according to the first information.
  • the access network device determines whether the first terminal device is allowed to obtain services through the first fixed network gateway device according to the subscription data information of the first terminal device. If it is determined that the first terminal device is allowed to obtain services through the first fixed network gateway device, the access network device, according to the fixed network service information, priority information, QoS information, etc. in the subscription data information corresponding to the first terminal device, and the first terminal device A terminal device establishes a user plane connection, that is, establishes a user plane resource such as a data radio bearer (data radio bearer, DRB), and continues to execute the procedures after S904. If it is determined that the first terminal device is not allowed to obtain the fixed network service through the first fixed network gateway device, the process after S904 may not be performed, or the process after S904 may continue to be performed.
  • a user plane connection that is, establishes a user plane resource such as a data radio bearer (data radio bearer, DRB)
  • DRB data radio bearer
  • the first terminal device has the right to obtain services, and the first terminal device can obtain services through the first fixed network gateway device; or in other words, the first The terminal device activates the service that needs to be obtained through the first fixed network gateway device.
  • the first terminal device has no authorization to obtain services, and the first terminal device cannot obtain services through the first fixed network gateway device; or in other words, the first terminal device The device has not subscribed to services that need to be obtained through the first fixed network gateway device.
  • the access network device sends second information to the first fixed network gateway device, where the second information is used to request management of a connection between the first terminal device and the first fixed network gateway device.
  • management includes creation, modification, release or deletion.
  • the access network device may obtain a DHCP Discover (DHCP Discover) message from the first terminal device. If it is determined that the first terminal device is allowed to obtain services through the first fixed network gateway device, the access network device adds an accessible identifier to the DHCP Discover message sent by the first terminal device, and the accessible identifier is used to indicate that the first terminal The device is allowed to obtain services through the first fixed network gateway device.
  • DHCP Discover DHCP Discover
  • the access network device adds an inaccessible identifier to the DHCP Discover message sent by the first terminal device, and the inaccessible identifier is used to indicate The first terminal device is not allowed to obtain services through the first fixed network gateway device.
  • the first terminal device may send a DHCP Discover message to the access network device through the control plane connection between the first terminal device and the access network device; or, the first terminal device may also communicate with the first terminal device through the first terminal device.
  • the user plane connection between access network devices sends a DHCP Discover message to the access network devices, which is not limited here.
  • the access network device can obtain the PPPoE active discovery start (PPPoE active discovery initiation, PADI) message, if it is determined that the first terminal device is allowed to obtain services through the first fixed network gateway device, the access network device adds an accessible identifier to the PADI message sent by the first terminal device, and the accessible identifier It is used to indicate that the first terminal device is allowed to obtain services through the first fixed network gateway device.
  • PPPoE active discovery start PPPoE active discovery start
  • the access network device adds an inaccessible identifier to the PADI message sent by the first terminal device, and the inaccessible identifier is used to indicate that the first terminal The device is not allowed to obtain services through the first fixed network gateway device.
  • the first terminal device may also send a PADI message to the access network device through the control plane connection between the first terminal device and the access network device; or, the first terminal device may also send a PADI message to the access network device through the first terminal device and the The user plane connection between the access network devices sends PADI messages to the access network devices.
  • the first information obtained by the access network device in S901 may further include an accessible identifier set and an inaccessible identifier set.
  • the access network device may select an accessible identifier from the aforementioned accessible identifier set and add it to the DHCP Discover message or the PADI message, so as to generate the aforementioned second information.
  • the second information refers to a DHCP Discover message added with an accessible identifier or a PADI message added with an accessible identifier.
  • an accessible identifier or an inaccessible identifier can be specifically represented by a Line ID.
  • the accessible identifier set can include one or more accessible Line IDs
  • the inaccessible identifier set can include one or Multiple inaccessible Line IDs. That is, the Line ID in this method 1 is used to indicate whether the terminal device supports the fixed network service supported by the fixed network gateway device.
  • the values of the accessible identifier and the inaccessible identifier are different, for example, the value of the accessible identifier is "1", and the value of the inaccessible identifier is "0"; or, The value of the access identifier is "0", and the value of the inaccessible identifier is "1".
  • FIG. 9 takes communication between the first terminal device and the first fixed network gateway device through the IPoE protocol as an example, and shows that S905 includes: the first terminal device sends a DHCP discovery message to the access network device; then The network access device adds an accessible identifier to the DHCP discovery message sent by the first terminal device, that is, generates second information; the access network device sends the DHCP discovery message added with the accessible identifier to the first fixed network gateway device.
  • the first fixed network gateway device sends the received DHCP discovery message to the DHCP server.
  • the DHCP server sends an access request (access request) message to the AAA server, and the access request message carries the accessible identifier or the inaccessible identifier in the DHCP discovery message, so that the AAA server can use the aforementioned accessible identifier or
  • the inaccessible identifier determines whether the first terminal device can access the fixed network network corresponding to the first fixed network gateway, or it can be understood as: the AAA server determines whether the aforementioned access network device On the basis of authentication or authentication, the first terminal device is further authenticated to determine whether the first terminal device can pass the authentication.
  • the AAA server may send an access accept (access accept) message to the DHCP server; if the AAA server obtains an inaccessible identifier, the AAA server may send an access accept message to the DHCP server. Incoming denial (access deny) message.
  • FIG. 9 shows a situation where the AAA server sends an access accept message to the DHCP server.
  • the DHCP server can send a DHCP response (DHCP Offer) message to the first terminal device through the first fixed network gateway device and the access network device; if the DHCP What the server receives is an access deny (access deny) message, and then the DHCP server can send a DHCP NACK message to the first terminal device through the first fixed network gateway device and the access network device.
  • DHCP Offer DHCP response
  • the DHCP server may send a DHCP response (DHCP Offer) message to the first terminal device through the first fixed network gateway device and the access network device.
  • DHCP Offer DHCP response
  • the first terminal device may send a DHCP request (DHCP Request) message to the DHCP server through the access network device and the first fixed network gateway device.
  • DHCP Request DHCP request
  • the DHCP server may send a DHCP ACK message to the first terminal device through the first fixed network gateway device and the access network device, where the DHCP ACK message is used to indicate the connection between the first terminal device and the first fixed network gateway device successfully built.
  • the DHCP server sends a DHCP ACK message to the first fixed network gateway device, the first fixed network gateway device forwards the DHCP ACK message to the access network device, and the access network device forwards the DHCP ACK message to the first terminal device.
  • the access network device When the access network device receives the DHCP ACK message, it can be determined that the connection between the first terminal device and the first fixed network gateway device is successfully established, and if the access network device does not receive the DHCP ACK message, it can be regarded as the first terminal device The connection with the first fixed network gateway device is not successfully established. S912. The access network device replaces the first serial number with the second serial number in the second serial number set.
  • the access network device sends update instruction information to the first terminal device, where the update instruction information is used to instruct the first terminal device to update the serial number corresponding to its security context information.
  • the update indication information may include a second serial number.
  • the update instruction information may also include identification information of the fixed network network corresponding to the fixed network gateway device supported by the first terminal device mentioned in S902.
  • the update instruction information can also be understood as being used to instruct the first terminal device to update the fourth information.
  • the first terminal device sends update response information to the access network device in response to the update indication information, where the update response information is used to indicate that the first terminal device has successfully received the update indication information.
  • the DHCP discovery message sent by the first terminal device in S906 above may be replaced by a PADI message.
  • Subsequent S907-S911 may also be adjusted accordingly based on the PPPoE communication process as described above in S42-S48, which will not be repeated in this embodiment of the present application. Part or all of the processes S901-S911 involved in the above method 1 can be selectively executed according to actual needs. The application embodiment does not limit this.
  • S904 may be performed after S901 is performed, without performing S902-S903 or omitting S902-S904.
  • the embodiment of the present application does not limit the execution order of the processes S901 to S914, and the execution order of some of the processes may be exchanged or executed in parallel according to the actual situation.
  • the first terminal device sends user plane data to the access network device through the user plane connection, and the access network device sends the user plane data from the first terminal device to the first fixed network gateway device, and then the first fixed network gateway device Then send the user plane data to the application server.
  • the user plane data sent by the first terminal device may also be understood as uplink data.
  • the user plane data sent by the first terminal device may be the user plane data of the first terminal device itself, or may be users of other terminal devices within the coverage of the first terminal device that use the first terminal device to provide wireless local area network communication capabilities. surface data.
  • the application server sends the user plane data of the first terminal device to the first fixed network gateway device, and the first fixed network gateway device sends the user plane data received from the AAA to the access network device, and then the access network device sends data from The user plane data of the first fixed network device is sent to the first terminal device through the user plane connection.
  • the user plane data from the application server can also be understood as downlink data.
  • the embodiment of the present application does not limit the execution order of S1001 and S1002, and S1001 may be executed first, and then S1002 may be executed; or S1002 may be executed first, and then S1001 is executed.
  • the first method provided by the embodiment of the present application can simplify the access process of the terminal device, and can save signaling overhead and reduce costs. Furthermore, the authentication and authentication of the terminal equipment can be performed to ensure the establishment of secure transmission.
  • Method 2 The access network device performs terminal device authentication based on the information used for terminal device authentication, and the fixed network gateway device performs terminal device authentication.
  • a communication method is illustrated, which mainly includes the following process.
  • An access network device acquires security context information and an identifier set of at least one terminal device, where the access network device supports 3GPP access technology. It can be understood that the access network equipment supports 3GPP access technology, which may include that the access network equipment supports air interface transmission technologies such as 4G/5G.
  • the aforementioned security context information and identity set of at least one terminal device may be pre-configured in the access network device, or may be from at least one fixed network gateway device.
  • the security context information is used to establish a secure connection between the access network device and the terminal device, and the security context information may specifically include one or more of root key, public key, private key, certificate, and other information used to establish a secure connection.
  • Establishing a secure connection may include processes such as an authentication process or key negotiation.
  • the identification set may include a first sequence set and a second sequence set. It can be understood that the first sequence set includes at least one sequence number that is currently used to indicate the security context information of the terminal device, and the second sequence set includes multiple sequence numbers that are not currently used to indicate the security context information of the terminal device.
  • the sequence numbers in the first sequence set/second sequence set can be changed dynamically.
  • a serial number can be selected from the second sequence set, such as serial number A; the current corresponding serial number of the security context information involved in the authentication process (such as serial number B ) is replaced with the previously selected serial number A. That is, the selected serial number A is incorporated into the first sequence set, and the original sequence number B in the first sequence set is eliminated.
  • the serial number B can also be incorporated into the second sequence set for subsequent use again.
  • the access network device acquires fourth information from the first terminal device, where the fourth information is used to determine security context information of the first terminal device.
  • the first terminal device may be any one of the at least one terminal device mentioned in S1101.
  • the fourth information includes the first serial number corresponding to the security context information of the first terminal device.
  • the first serial number may be a terminal identifier corresponding to the first terminal device, or a security context identifier.
  • the fourth information may also include identification information of the fixed network network corresponding to the fixed network gateway device supported by the first terminal device, and the identification information of the fixed network network may include a fixed network identification and/or a fixed network service provider identification.
  • the fixed network gateway device supported by the first terminal device is the first fixed network gateway device, that is, the first fixed network gateway device can provide fixed network services for the first terminal device, and the fourth information includes the fixed network gateway device corresponding to the first fixed network gateway device.
  • the first fixed network gateway device may be included in at least one fixed network gateway device connected to the access network device.
  • the first terminal device may complete network selection according to any one of the aforementioned two network selection methods. It can be understood that the first terminal device selects the access network device described in S1102, and the first terminal device establishes a control plane connection with the access network device. Then the access network device may receive the fourth information sent by the first terminal device through the control plane connection between the access network device and the first terminal device. In addition, during the network selection process, if the terminal device adopts the method of implicitly reporting the type, the access network device may determine the type of the first terminal device based on the interaction between the terminal device and the access network device.
  • the terminal device adopts the method of explicitly reporting the type, such as sending first information to the access network device; wherein, the first information may indicate that the type of the first terminal device is the target type, and the target type It includes one or more of a home gateway, a home terminal, and a client terminal device, and may also include a mobile phone, an AR/VR terminal, a Pad, and other types of terminals, which are not limited in this embodiment of the present application.
  • the access network device may also determine the type of the first terminal device by acquiring the first information from the terminal device.
  • the access network device establishes a secure connection between the access network device and the first terminal device according to the fourth information.
  • the access network device may obtain security context information and an identification set of at least one terminal device.
  • the access network device can obtain the security context information and identification set of at least one terminal device from the first information; then the access network device determines that the first serial number set in the identification set includes the first serial number, the access network device may obtain the security context information of the first terminal device from the security context information and identification set of the at least one terminal device according to the first serial number, and use the first terminal device Establish a secure connection between the access network device and the first terminal device based on the security context information.
  • the access network device may perform mutual authentication with the first terminal device according to the security context information corresponding to the first serial number, so as to determine that both the access network device and the first terminal device are trustworthy devices for each other.
  • the access network device may also replace the first serial number with a second serial number in the second serial number set, and send the The first terminal device sends the second serial number, where the second serial number is used to indicate the security context information of the first terminal device.
  • the serial number used to indicate the security context information of the first terminal device stored in the first terminal device is replaced by the original first serial number Update to the second serial number.
  • the implementation time (or implementation stage) of replacing the first serial number with the second serial number may be performed immediately after S1103, such as replacing the first serial number with the second serial number after S1103 and before S1104.
  • the second serial number; or, the first serial number may be replaced with the second serial number after the first terminal device accesses the fixed network.
  • the specific implementation time of the operation is not limited.
  • S1112 to S1114 after S1111 in FIG. 11 illustrate the operation of replacing the first serial number with the second serial number.
  • the access network device establishes a user plane connection with the first terminal device.
  • the user plane connection of the access network device established in this process corresponds to the establishment of a temporary user plane resource, and the temporary user plane resource can be used to carry the DHCP message sent by the first terminal device to the access network device in S1105.
  • Discovery news or PADI news can be used as an optional process. It can be omitted, that is, S1105 is directly executed after S1103 is executed.
  • the access network device sends second information to the first fixed network gateway device, where the second information is used to request management of a connection between the first terminal device and the first fixed network gateway device.
  • management includes establishment, modification, release or deletion, etc.
  • the access network device may obtain a DHCP Discover (DHCP Discover) message from the first terminal device.
  • the access network device adds identification information of the first terminal device to the DHCP Discover message sent by the first terminal device, where the identification information of the first terminal device may be determined according to the MAC address of the first terminal device or the aforementioned first serial number,
  • the identification information of the first terminal device can be the first serial number or the line identification (Line ID); perhaps, the identification information of the first terminal device can be determined according to the position of the first terminal device, such as the Line ID can be adopted in the second mode.
  • the ID is used as identification information of the first terminal device, and is used to indicate the location of the first terminal device.
  • the first terminal device may send a DHCP Discover message to the access network device through the control plane connection between the first terminal device and the access network device; or, when S1104 is executed, that is, the user plane connection is established
  • the first terminal device may also send a DHCP Discover message to the access network device through the user plane connection between the first terminal device and the access network device.
  • the access network device can obtain the PPPoE active discovery start (PPPoE active discovery initiation, PADI) message.
  • PPPoE active discovery start PPPoE active discovery initiation, PADI
  • the access network device adding the identification information of the first terminal device to the PADI message sent by the first terminal device may be determined according to the MAC address of the first terminal device or the aforementioned first sequence number, for example, the identification information of the first terminal device may be It is the first serial number or line identification (Line ID); or, the identification information of the first terminal equipment can be determined according to the position of the first terminal equipment, such as the Line ID can be used as the identification information of the first terminal equipment in this mode two , used to indicate the location of the first terminal device.
  • the first terminal device may send a PADI message to the access network device through the control plane connection between the first terminal device and the access network device; or, when S1104 is executed, that is, the user plane connection is established , the first terminal device may also send the PADI message to the access network device through the user plane connection between the first terminal device and the access network device.
  • FIG. 1 Exemplarily, FIG. 1
  • S1105 includes: the first terminal device sends a DHCP discovery message to the access network device; then The network access device adds the identification information of the first terminal device to the DHCP discovery message sent by the first terminal device, that is, generates the second information; the access network device sends the DHCP discovery message added with the identification information of the first terminal device to the first terminal device.
  • a fixed network gateway device is a fixed network gateway device.
  • the first fixed network gateway device sends the received DHCP discovery message to the DHCP server.
  • the DHCP server sends an access request (access request) message to the AAA server.
  • the access request message carries identification information of the first terminal device.
  • the AAA server may determine the subscription data information corresponding to the first terminal device according to the identification information of the first terminal device, the subscription data information is used to determine that the first terminal device is allowed to obtain services through the first fixed network gateway device, or the subscription data information is used It is determined that the first terminal device is not allowed to obtain services through the first fixed network gateway device.
  • the subscription data information may include one or more of fixed network service information, QoS information, and priority information, and the QoS information and/or priority information may be used as a subsequent adjustment to the temporary user plane resources previously configured by the first terminal device time basis.
  • the AAA server may determine whether the first terminal device is allowed to obtain services through the first fixed network gateway device according to the subscription data information corresponding to the first terminal device, or determine whether the first terminal device is authenticated.
  • the first terminal device has the right to obtain services, and the first terminal device can obtain services through the first fixed network gateway device; or in other words, the first The terminal device activates the service that needs to be obtained through the first fixed network gateway device.
  • the first terminal device has no authorization to obtain services, and the first terminal device cannot obtain services through the first fixed network gateway device; or in other words, the first terminal device The device has not subscribed to services that need to be obtained through the first fixed network gateway device.
  • the AAA server may send an access accept (access accept) message to the DHCP server; if the AAA server determines that the first terminal device has not passed the authentication, the AAA server may send the DHCP The server sends an access deny message.
  • Fig. 11 shows a situation where the AAA server sends an access accept message to the DHCP server.
  • the DHCP server can send a DHCP response (DHCP Offer) message to the first terminal device through the first fixed network gateway device and the access network device; if the DHCP What the server receives is an access deny (access deny) message, and then the DHCP server can send a DHCP NACK message to the first terminal device through the first fixed network gateway device and the access network device.
  • DHCP Offer DHCP response
  • the DHCP server may send a DHCP response (DHCP Offer) message to the first terminal device through the first fixed network gateway device and the access network device.
  • DHCP Offer DHCP response
  • the first terminal device may send a DHCP request (DHCP Request) message to the DHCP server through the access network device and the first fixed network gateway device.
  • DHCP Request DHCP request
  • the DHCP server may send third information to the first terminal device through the first fixed network gateway device and the access network device, where the third information is used to indicate the connection between the first terminal device and the first fixed network gateway device successfully built.
  • the DHCP server sends the third information to the first fixed network gateway device, the first fixed network gateway device forwards the third information to the access network device, and the access network device forwards the third information to the first terminal device.
  • the access network device After the access network device receives the third information, it can be determined that the connection between the first terminal device and the first fixed network gateway device is successfully established, and if the access network device does not receive the third information, it can be regarded as the first terminal device The connection with the first fixed network gateway device is not successfully established.
  • the third information may specifically be implemented using a DHCP ACK message.
  • the foregoing third information may also include at least one of the following: identification information of the first terminal device; authentication information of the first terminal device, where the authentication information is used to instruct the first terminal device to pass through the first fixed network gateway The authentication of the fixed network network corresponding to the device, or the authentication information is used to indicate that the first terminal device has not passed the authentication of the fixed network network corresponding to the first fixed network gateway device; the subscription corresponding to the first terminal device Data information, where the subscription data information includes one or more of fixed network service information, QoS information, and priority information.
  • the DHCP ACK message may include subscription data information of the first terminal device and authentication information of the first terminal device, and the authentication information included in the DHCP ACK message is used to indicate that the first terminal device A terminal device passes the authentication of the fixed network network corresponding to the first fixed network gateway device; or, using a DHCP ACK message to indicate that the first terminal device passes the authentication of the fixed network network corresponding to the first fixed network gateway device
  • the DHCP ACK message may only include the subscription data information of the first terminal device.
  • the access network device may execute a user plane connection management process according to the third information.
  • the user plane management process includes at least one of the following operations: reserving user plane resources, establishing user plane resources, modifying user plane resources, or releasing user plane resources.
  • the access network device may reserve temporary user plane resources without adjusting them according to the subscription data information corresponding to the first terminal device.
  • the access network device may add user plane resources on the basis of the aforementioned temporary user plane resources according to the subscription data information corresponding to the first terminal device.
  • modification of user plane resources the access network device may modify the user plane resources on the basis of the aforementioned temporary user plane resources according to the subscription data information corresponding to the first terminal device.
  • release of user plane resources the access network device can release the aforementioned temporary user plane resources when receiving a message such as a DHCP NACK.
  • the access network device replaces the first serial number with the second serial number in the second serial number set.
  • the access network device sends update instruction information to the first terminal device, where the update instruction information is used to instruct the first terminal device to update the serial number corresponding to its security context information.
  • the update indication information may include a second serial number.
  • the update indication information may also include identification information of the fixed network network corresponding to the fixed network gateway device supported by the first terminal device mentioned in S1102.
  • the update instruction information can also be understood as being used to instruct the first terminal device to update the fourth information.
  • the first terminal device sends update response information to the access network device in response to the update indication information, where the update response information is used to indicate that the first terminal device has successfully received the update indication information.
  • the DHCP discovery message sent by the first terminal device in S1105 above may be replaced by a PADI message.
  • Subsequent S1107-S1111 may also be adjusted accordingly based on the PPPoE communication process as described above in S42-S48, which will not be repeated in this embodiment of the present application. Part or all of the processes S1101 ⁇ S1111 involved in the above method 1 can be selectively executed according to actual needs. The application embodiment does not limit this.
  • S1104 may be performed after S1101 is performed, without performing S1102-S1103 or omitting S1102-S1104.
  • the embodiment of the present application does not limit the execution order of the processes S1101 to S1114, and the execution order of some of the processes may be exchanged or executed in parallel according to the actual situation.
  • the second method provided by the embodiment of the present application can simplify the access process of the terminal device, and can save signaling overhead and reduce costs.
  • the access network device performs the authentication process of the terminal device. After passing the authentication, the access network device can establish temporary user plane resources with the terminal device for forwarding related messages that the terminal device wishes to establish an IPoE or PPPoE connection. By including the subscription data information of the terminal device in the DHCP ACK message, the access network device can establish or modify the user plane resources of the terminal device in a targeted manner according to the subscription data information, and the difference between different terminal devices can be achieved. processing to improve user experience.
  • Method 3 The fixed network gateway device performs authentication of the terminal device and sends authentication information to the access network device.
  • the access network device establishes a secure connection with the terminal device based on the authentication information (when the authentication passes) or releases air interface resources (when the authentication fails) .
  • a communication method is illustrated, which mainly includes the following process.
  • the first terminal device completes network selection, and establishes a control plane connection with the access network device.
  • the first terminal device may complete network selection according to any one of the aforementioned two network selection methods. It can be understood that the first terminal device selects the access network device described in FIG. 12 and the fixed network network corresponding to the first fixed network gateway device, and the first terminal device establishes a control plane connection with the access network device.
  • the access network device may determine the type of the first terminal device based on the interaction between the terminal device and the access network device.
  • the terminal device adopts the method of explicitly reporting the type such as sending first information to the access network device; wherein, the first information may indicate that the type of the first terminal device is the target type, and the target type It includes one or more of a home gateway, a home terminal, and a client terminal device, and may also include a mobile phone, an AR/VR terminal, a Pad, and other types of terminals, which are not limited in this embodiment of the present application.
  • the access network device may also determine the type of the first terminal device by acquiring the first information from the terminal device.
  • the access network device establishes a user plane connection with the first terminal device.
  • the user plane connection of the access network device established in this process corresponds to the establishment of a temporary user plane resource, and the temporary user plane resource can be used to carry the DHCP message sent by the first terminal device to the access network device in S1203.
  • Discovery news or PADI news can be regarded as an optional process. It can be omitted, that is, S1203 is directly executed after S1201 is executed.
  • the access network device sends second information to the first fixed network gateway device, where the second information is used to request management of a connection between the first terminal device and the first fixed network gateway device.
  • management includes establishment, modification, release or deletion, etc.
  • the access network device may obtain a DHCP Discover (DHCP Discover) message from the first terminal device.
  • the access network device adds the identification information of the first terminal device to the DHCP Discover message sent by the first terminal device, and the identification information of the first terminal device may be based on the MAC address of the first terminal device or the C-
  • the RNTI is determined, and the C-RNTI refers to the identifier used by the access network equipment to mark the first terminal device; or, the identification information of the first terminal device can be determined according to the location of the first terminal device, for example, Line The ID is used as identification information of the first terminal device, and is used to indicate the location of the first terminal device.
  • the first terminal device may send a DHCP Discover message to the access network device through the control plane connection between the first terminal device and the access network device; or, when S1202 is executed, that is, the user plane connection is established Next, the first terminal device may also send a DHCP Discover message to the access network device through the user plane connection between the first terminal device and the access network device.
  • the access network device can obtain the PPPoE active discovery start (PPPoE active discovery initiation, PADI) message.
  • PPPoE active discovery start PPPoE active discovery initiation, PADI
  • the access network device adding the identification information of the first terminal device to the PADI message sent by the first terminal device may be determined according to the MAC address of the first terminal device or the C-RNTI of the first terminal device, and the C-RNTI refers to
  • the access network device marks the identifier used by the first terminal device; or, the identification information of the first terminal device can be determined according to the location of the first terminal device, such as the Line ID can be used as the identification information of the first terminal device in the third method , used to indicate the location of the first terminal device.
  • the first terminal device may send a PADI message to the access network device through the control plane connection between the first terminal device and the access network device; or, when S1202 is executed, that is, the user plane connection is established , the first terminal device may also send the PADI message to the access network device through the user plane connection between the first terminal device and the access network device.
  • FIG. 12 takes communication between the first terminal device and the first fixed network gateway device as an example through the PPPoE protocol, and shows that S1203 includes: the first terminal device sends a PADI message to the access network device; The network device adds the identification information of the first terminal device to the PADI message sent by the first terminal device, that is, generates the second information; the access network device sends the PADI message added with the identification information of the first terminal device to the first fixed network gateway device.
  • the first terminal device sends a PPPoE Active Discovery Request (PPPoE Active Discovery Request, PADR) message to the first fixed network gateway device through the access network device.
  • PPPoE Active Discovery Request PPPoE Active Discovery Request, PADR
  • the first fixed network gateway device After receiving the PADR message, the first fixed network gateway device sends a PPPoE active discovery session configuration (PPPoE Active Discovery Session-confirmation, PADS) message to the first terminal device through the access network device as a response.
  • PPPoE Active Discovery Session-confirmation, PADS PPPoE Active Discovery Session-confirmation
  • the first terminal device interacts to complete Challenge Handshake Authentication Protocol (Challenge Handshake Authentication Protocol, CHAP) authentication.
  • CHAP Challenge Handshake Authentication Protocol
  • the first fixed network gateway device forwards the authentication message between the first terminal device and the AAA server.
  • the authentication method may be authentication through user name and password, and the message is transmitted in cipher text, which is relatively safe.
  • the first terminal device and the first fixed network gateway device perform a network side parameter (Network Control Protocol, NCP) negotiation phase, which involves the interaction between the first fixed network gateway device and DHCP, and the first terminal device can obtain at this stage IP address.
  • NCP Network Control Protocol
  • the first fixed network gateway device learns that the first terminal device has passed the authentication, and sends third information to the access network device through the interface between the first fixed network gateway device and the access network device, where the third information is used to indicate that the first terminal device The connection between the terminal device and the first fixed network gateway device is successfully established.
  • the foregoing third information may include one or more of the following information: identification information of the first terminal device; security context information of the first terminal device; authentication information of the first terminal device , the authentication information is used to indicate whether the first terminal device has passed the authentication of the fixed network network corresponding to the first fixed network gateway device, or the authentication information is used to indicate whether the first terminal device has passed the authentication of the fixed network network corresponding to the first fixed network gateway device.
  • the access network device may identify the first terminal device according to the identification information of the first terminal device, and when the authentication information of the first terminal device indicates that it has passed the authentication of the AAA server, use the first
  • the security context information of the terminal device establishes a secure connection between the access network device and the first terminal device, for example, the access network device uses the security context information of the first terminal device to mutually authenticate with the first terminal device. If the authentication information of the first terminal device indicates that it has not passed the authentication of the AAA server, the access network device does not need to mutually authenticate with the first terminal device.
  • FIG. 12 illustrates a situation where the authentication information of the first terminal device indicates that it has passed the authentication of the AAA server.
  • the access network device may execute a user plane connection management process according to the third information.
  • the user plane management process includes at least one of the following operations: reserving user plane resources, establishing user plane resources, modifying user plane resources, or releasing user plane resources.
  • the access network device can perform one or more of the following operations according to the subscription data information of the first terminal device: reserve user plane resources, establish user plane Resources, modify user plane resources.
  • the access network device may perform an operation of releasing user plane resources.
  • the access network device may reserve the temporary user plane resources in S1202 above without adjusting them according to the subscription data information corresponding to the first terminal device.
  • the access network device may add user plane resources on the basis of the temporary user plane resources in S1202 above according to the subscription data information corresponding to the first terminal device.
  • modification of user plane resources the access network device may modify the user plane resources on the basis of the aforementioned temporary user plane resources according to the subscription data information corresponding to the first terminal device.
  • the access network device may release the aforementioned temporary user plane resources when determining that the first terminal device has not passed the authentication of the AAA server.
  • S1210 may be executed first and S1211 may be executed first, or S1211 may be executed first and then S1210 is executed.
  • the PADI message sent by the first terminal device in S1204 above may be replaced with a DHCP discovery message.
  • Subsequent S1205-S1211 may also be adjusted accordingly based on the IPoE communication process as described above in S31-S36, which will not be repeated in this embodiment of the present application.
  • Part or all of the processes S1201-S1211 involved in the above method 1 can be selectively executed according to actual needs.
  • the application embodiment does not limit this.
  • Exemplarily, for some scenarios where terminal device authentication does not need to be performed, S1210 may be omitted.
  • the embodiment of the present application does not limit the execution order of the processes S1201 to S1211, and the execution order of some of the processes may be exchanged or executed in parallel according to the actual situation.
  • the third method provided by the embodiment of this application can simplify the access process of the terminal device, save signaling overhead and reduce costs.
  • the fixed network gateway device After the terminal device and the fixed network gateway device complete the authentication, the fixed network gateway device sends the authentication result, security context information, priority information, QoS information, etc. about the terminal device to the access network device through the enhanced interface, which can reduce the complexity of the aforementioned information. Leakage, improve communication security.
  • the access network device can also establish or modify the user plane resources of the terminal device in a targeted manner according to the priority information and QoS information, which can achieve differentiated processing between different terminal devices and improve user experience.
  • the embodiment of the present application provides another protocol stack architecture, specifically illustrating a control plane protocol stack and a user plane protocol stack.
  • implementing the second solution may construct the protocol stack architecture, or it can be understood that the protocol stack architecture can be applied to the second solution.
  • FIG. 13 is a possible implementation manner, and this solution 2 may also adopt other protocol stack architectures, which are not limited in this embodiment of the present application.
  • the control plane protocol stack on the terminal equipment side and the access network equipment side is divided into RRC layer, Packet Data Convergence Protocol (Packet Data Convergence Protocol, PDCP) layer, radio link layer control protocol (Radio Link Control, RLC) layer, Medium access control (medium access control, MAC) layer, physical (physical, PHY) layer.
  • the user plane protocol stack on the terminal device side is divided into IPoE/PPPoE protocol layer, 802.1ad protocol layer, Service Data Adaptation Protocol (Service Data Adaptation Protocol, SDAP) layer, PDCP layer, RRC layer, PDCP layer, RLC layer, MAC layer , PHY layer.
  • the user plane protocol stack on the access network device side for communication with terminal devices is divided into IPoE/PPPoE protocol layer, 802.1ad protocol layer, SDAP layer, PDCP layer, RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer.
  • the user plane protocol stack on the side of the access network device for communication with the fixed network gateway device is divided into IPoE/PPPoE protocol layer, 802.1ad protocol layer, MAC layer, and PHY layer.
  • the user plane protocol stack on the fixed network gateway device side is divided into IPoE/PPPoE protocol layer, 802.1ad protocol layer, MAC layer, and PHY layer.
  • the access network device can fully support the 3GPP protocol stack, and can also support part of the 3GPP protocol stack. For example, the access network device can support part or all of the protocol stacks in the PHY layer, MAC layer, RLC layer, PDCP layer, SDAP layer, and RRC layer. .
  • Access network equipment supports 3GPP access technology.
  • Terminal equipment and access network equipment can be transmitted through 3GPP technology (or cellular air interface).
  • terminal equipment can establish a control plane connection with access network equipment, and control plane messages can be transmitted through RRC Signaling is transmitted; the terminal device can establish a user plane connection with the access network device, and user plane messages can be transmitted through the user plane connection.
  • the access network device establishes a connection with the fixed network gateway device, such as a fixed network connection, such as data transmission according to the IPoE/PPPoE protocol. Then the access network device can send data from the terminal device to the fixed network gateway device, and can also send data from the fixed network gateway device to the terminal device.
  • the access network device can also be understood as the connection between the terminal device and the fixed network gateway device. bridge between.
  • core network-related protocol layers such as the non-access (non-access stratum, NAS) layer.
  • a communication method is illustrated, which mainly includes the following process.
  • An access network device acquires first information, where the access network device supports a 3GPP access technology.
  • the access network equipment supports 3GPP access technology, which may include that the access network equipment supports air interface transmission technologies such as 4G/5G.
  • the first information may be information pre-stored in the access network device or the first information is obtained from at least one fixed network gateway device connected to the access network device; wherein the first information includes at least one terminal
  • the subscription data information corresponding to the device, the subscription data information is used to determine that the terminal device is allowed to obtain services through the fixed network gateway device, or the subscription data information is used to determine that the terminal device is not allowed to obtain services through the fixed network gateway device.
  • the subscription data information may include one or more of fixed network service information, QoS information, and priority information, and the QoS information and/or priority information may be used as a basis for subsequently configuring user plane resources for the terminal device.
  • the first information may also include security context information and an identification set of the aforementioned at least one terminal device; wherein, the security context information may specifically include one or Multiple.
  • Establishing a secure connection may include processes such as an authentication process or key negotiation.
  • the identification set may include a first sequence set and a second sequence set. It can be understood that the first sequence set includes at least one sequence number that is currently used to indicate the security context information of the terminal device, and the second sequence set includes multiple sequence numbers that are not currently used to indicate the security context information of the terminal device.
  • the sequence numbers in the first sequence set/second sequence set can be changed dynamically.
  • a serial number can be selected from the second sequence set, such as serial number A; the current corresponding serial number of the security context information involved in the authentication process (such as serial number B ) is replaced with the previously selected serial number A. That is, the selected serial number A is incorporated into the first sequence set, and the original sequence number B in the first sequence set is eliminated.
  • the serial number B can also be incorporated into the second sequence set for subsequent use again.
  • the first information may further include an IP address resource pool, and the IP address resource pool includes multiple IP addresses to be allocated.
  • the access network device sends a DHCP discovery (DHCP Discover) message or PADI message to at least one fixed network gateway device, and the DHCP discovery message or PADI message is used to request to establish a connection between the access network device and at least one fixed network gateway device connections, such as fixed network connections.
  • DHCP Discover DHCP Discover
  • PADI message PADI message
  • the DHCP discovery message or the PADI message may carry an accessible identifier, such as an accessible Line ID, to ensure that the access network device successfully establishes a connection with the fixed network gateway device through authentication.
  • FIG. 14 takes the communication between the access network device and the first fixed network gateway device among at least one fixed network gateway device as an example, which shows that S1402 includes: the access network device sends the first fixed network gateway device The fixed network gateway device sends a DHCP discovery message.
  • the first fixed network gateway device sends the received DHCP discovery message to the DHCP server.
  • the DHCP server sends an access request (access request) message to the AAA server, and the access request message carries the accessible identifier in the DHCP discovery message, so that the AAA server determines the access network device according to the aforementioned accessible identifier Can be certified.
  • the AAA server obtains the access identifier, and then the AAA server may send an access accept (access accept) message to the DHCP server.
  • the DHCP server receives the access accept (access accept) message, then the DHCP server may send a DHCP response (DHCP Offer) message to the access network device through the first fixed network gateway device.
  • DHCP Offer DHCP response
  • the access network device sends a DHCP request (DHCP Request) message to the DHCP server through the first fixed network gateway device.
  • DHCP Request DHCP request
  • the DHCP server sends a DHCP ACK message to the access network device through the first fixed network gateway device, and the DHCP ACK message indicates that the connection between the access network device and the first fixed network gateway device is successfully established.
  • the access network device acquires fourth information from the first terminal device, where the fourth information is used to determine security context information of the first terminal device.
  • the first terminal device may be any one of the at least one terminal device mentioned in S1401.
  • the fourth information includes the first serial number corresponding to the security context information of the first terminal device.
  • the first serial number may be a terminal identifier corresponding to the first terminal device, or a security context identifier.
  • the fourth information may also include identification information of the fixed network network corresponding to the fixed network gateway device supported by the first terminal device, and the identification information of the fixed network network may include a fixed network identification and/or a fixed network service provider identification .
  • the first terminal device supports the fixed network gateway device as the first fixed network gateway device, that is, the first fixed network gateway device can provide fixed network services for the first terminal device, and the fourth information includes the fixed network address corresponding to the first fixed network gateway device. Identifying information for the network.
  • the first fixed network gateway device may be included in at least one fixed network gateway device that establishes a connection with the access network device.
  • the first terminal device may complete network selection according to any one of the foregoing two network selection methods. It can be understood that the first terminal device selects the access network device described in FIG. 14 , and the first terminal device establishes a control plane connection with the access network device. Then the access network device may receive the fourth information sent by the first terminal device through the control plane connection between the access network device and the first terminal device.
  • the first terminal device completes the network selection, establishes a control plane connection with the access network device, and the access network device connects through the control plane, and receives the first terminal device from the first terminal device.
  • the access network device connects through the control plane, and receives the first terminal device from the first terminal device.
  • the access network device establishes a secure connection between the access network device and the first terminal device according to the fourth information.
  • the access network device may obtain security context information and an identification set of at least one terminal device.
  • the access network device can obtain the security context information and identification set of at least one terminal device from the first information; then the access network device determines that the first serial number set in the identification set includes the first serial number, the access network device may obtain the security context information of the first terminal device from the security context information and identification set of the at least one terminal device according to the first serial number, and use the first terminal device
  • the security context information establishes a secure connection between the access network device and the first terminal device.
  • the access network device may perform mutual authentication with the first terminal device according to the security context information corresponding to the first serial number, so as to determine that both the access network device and the first terminal device are trustworthy devices for each other.
  • the access network device may also replace the first serial number with a second serial number in the second serial number set, and send the A terminal device sends the second serial number, where the second serial number is used to indicate the security context information of the first terminal device.
  • the serial number used to indicate the security context information of the first terminal device stored in the first terminal device is replaced by the original first serial number Update to the second serial number.
  • the implementation time (or implementation stage) of replacing the first serial number with the second serial number may be performed immediately after S1410, such as replacing the first serial number with the second serial number after S1410 and before S1411.
  • the second serial number; or, the first serial number may be replaced with the second serial number after the first terminal device accesses the fixed network.
  • the specific implementation time of the operation is not limited.
  • S1412 to S1414 after S1411 in FIG. 14 illustrate the operation of replacing the first serial number with the second serial number.
  • the access network device establishes a user plane connection with the first terminal device according to the first information.
  • the access network device determines whether the first terminal device is allowed to obtain services through the first fixed network gateway device according to the subscription data information of the first terminal device.
  • the first terminal device is allowed to obtain services through the first fixed network gateway device, it can be understood that the first terminal device has the right to obtain services, and the first terminal device can obtain services through the first fixed network gateway device; or in other words, the first terminal device Activate the services that need to be obtained through the first fixed network gateway device.
  • the first terminal device is not allowed to obtain services through the first fixed network gateway device. It can be understood that the first terminal device does not have the right to obtain services, and the first terminal device cannot obtain services through the first fixed network gateway device; Activate the services that need to be obtained through the first fixed network gateway device.
  • the access network device When the access network device determines that the first terminal device is allowed to obtain services through the first fixed network gateway device, the access network device, according to the priority information and QoS information in the subscription data information corresponding to the first terminal device, contacts the first The terminal device establishes a user plane connection, that is, establishes a user plane resource such as a data radio bearer (data radio bearer, DRB), and allocates an IP address to the first terminal device based on the IP address resource pool of the first information.
  • a user plane connection that is, establishes a user plane resource such as a data radio bearer (data radio bearer, DRB)
  • DRB data radio bearer
  • the access network device replaces the first serial number with the second serial number in the second serial number set.
  • the access network device sends update instruction information to the first terminal device, where the update instruction information is used to instruct the first terminal device to update the serial number corresponding to its security context information.
  • the update indication information may include a second serial number.
  • the update instruction information may also include identification information of the fixed network network corresponding to the fixed network gateway device supported by the first terminal device mentioned in S1410.
  • the update instruction information can also be understood as being used to instruct the first terminal device to update the fourth information.
  • the first terminal device sends update response information to the access network device in response to the update indication information, where the update response information is used to indicate that the first terminal device has successfully received the update indication information.
  • the access network device and the first fixed network gateway device need to communicate through the PPPoE protocol, the DHCP discovery message sent by the access network device in S1402 above may be replaced by a PADI message. Subsequent S1402-S1408 may also be adjusted accordingly based on the PPPoE communication process as described above in S42-S48, which will not be repeated in this embodiment of the present application.
  • Part or all of the processes S1401-S1414 involved in the above method 1 can be selectively executed according to actual needs.
  • the application embodiment does not limit this. Exemplarily, for some scenarios that do not need to perform serial number update and replacement, S1412-S1414 may not be performed.
  • the embodiment of the present application does not limit the execution order of the processes S1401 to S1414, and the execution order of some of the processes can be exchanged or executed in parallel according to the actual situation.
  • the access network device in the second solution has an IPoE or PPPoE protocol stack
  • the access network device can directly communicate with the fixed network gateway device as a fixed network terminal.
  • a connection shared by multiple terminal devices connected to the access network device can be established, and the RAN can also perform network address translation (NAT), so that the connections between multiple terminal devices and the access network device can be mapped to the connection between the access network device and the fixed network gateway device.
  • NAT network address translation
  • FIG. 15 it illustrates a data transmission mode of a terminal device, which mainly includes the following process.
  • the first terminal device sends the first uplink data to the access network device, the source IP address of the message corresponding to the first uplink data is recorded as IP@1, and the port number (port) is 1.
  • the second terminal device sends the second uplink data to the access network device.
  • the source IP address of the message corresponding to the second uplink data is recorded as IP@2, and the port number is 1.
  • the first uplink data sent by the first terminal device may be the user plane data of the first terminal device itself, or it may be other data within the coverage of the first terminal device that uses the first terminal device to provide wireless local area network communication capabilities.
  • User plane data of terminal equipment may be the user plane data of the first terminal device itself, or it may be other data within the coverage of the first terminal device that uses the first terminal device to provide wireless local area network communication capabilities.
  • the access network device replaces the source IP address of the message corresponding to the first uplink data with IP@3, the port number (port) is 2, and sends the first uplink after replacing the source IP address to the application server through the fixed network gateway device data.
  • the second uplink data sent by the second terminal device may be the user plane data of the second terminal device itself, or it may be other data within the coverage of the second terminal device that uses the second terminal device to provide wireless local area network communication capabilities.
  • User plane data of terminal equipment may be the user plane data of the second terminal device itself, or it may be other data within the coverage of the second terminal device that uses the second terminal device to provide wireless local area network communication capabilities.
  • the access network device replaces the source IP address of the message corresponding to the second uplink data with IP@3, and the port number (port) is 3, and sends the second uplink after replacing the source IP address to the application server through the fixed network gateway device data.
  • the access network device obtains the downlink data from the application server through the fixed network gateway device.
  • the destination IP address of the message corresponding to the downlink data is recorded as: IP@3, and the port number is 2.
  • the access network device determines that the downlink data is to be sent to the first terminal device according to the obtained destination IP address of the message corresponding to the downlink data, and the access network device replaces the destination IP address of the message corresponding to the downlink data with IP@1 , the port number (port) is 1, and the downlink data after replacing the destination IP address is sent to the first terminal device.
  • the access network device establishes a connection with the fixed network gateway device in advance.
  • the access network device can directly establish user plane resources with the terminal device and assign an IP address (if the established PPPoE connection, the access network device will also assign a PPPoE session ID), that is, the access network device has the NAT function.
  • IP address if the established PPPoE connection, the access network device will also assign a PPPoE session ID, that is, the access network device has the NAT function.
  • the embodiment of the present application provides a communication device 1600 , where the communication device 1600 includes a communication module 1601 and a processing module 1602 .
  • the communication apparatus 1600 may be an access network device, or may be an apparatus applied to the access network device and capable of supporting the access network device to execute the aforementioned communication method.
  • the communication module may also be referred to as a transceiver module, a transceiver, a transceiver, a transceiver device, and the like.
  • a processing module may also be called a processor, a processing board, a processing unit, a processing device, and the like.
  • the device used to implement the receiving function in the communication module can be regarded as a receiving unit. It should be understood that the communication module is used to perform the sending and receiving operations on the access network device side in the above method embodiments, and the communication module in the communication module
  • the device used to realize the sending function is regarded as a sending unit, that is, the communication module includes a receiving unit and a sending unit.
  • the receiving unit included in its communication module 1601 is used to perform receiving operations on the access network equipment side, such as receiving fourth information from the first terminal equipment; its communication module 1601 includes The sending unit is configured to perform a sending operation on the access network device side, for example, send the second information to the first fixed network gateway device.
  • the communication module may be an input and output circuit and/or a communication interface, which performs input operations (corresponding to the aforementioned receiving operations) and output operations (corresponding to the aforementioned sending operations);
  • the processing module is an integrated processor or microprocessor or integrated circuit.
  • the communication device 1600 includes:
  • a communication module 1601, configured to acquire first information.
  • the processing module 1602 is configured to establish a user plane connection with the first terminal device according to the first information.
  • the communication module 1601 is further configured to acquire user plane data of the first terminal device through the user plane connection, and send the user plane data to the first fixed network gateway device.
  • the access network device supporting 3GPP access technology is used as the intermediate node between the terminal device and the fixed network gateway device, the terminal device uses the 3GPP access technology to establish a connection with the access network device, and the access network device
  • the data of the terminal equipment can be transmitted to the fixed network gateway equipment, so that the terminal equipment can also obtain fixed network broadband services through 3GPP access.
  • wired access to the fixed-line network can simplify deployment, enhance coverage, and improve the performance of the communication system.
  • the first information is used to indicate that the type of the first terminal device is a target type and/or is used to indicate that the first terminal device is allowed to pass through the first fixed network gateway
  • the device acquires services; wherein, the target type includes one or more of a home gateway, a home terminal, and a client terminal device, and may also include a mobile phone, an AR/VR terminal, a Pad, and other types of terminals. No limitation is imposed.
  • the first information comes from the first terminal device, and the first information indicates that the type of the first terminal device is the target type, and may also include mobile phone, AR/ VR terminals, Pads, and other types of terminals are not limited in this embodiment of the present application.
  • the first information is preconfigured in the access network device or the first information comes from the first fixed network gateway device; wherein the first information includes the Subscription data information corresponding to the first terminal device, where the subscription data information is used to determine that the first terminal device is allowed to obtain services through the first fixed network gateway device.
  • the communication module 1601 is further configured to send second information to the first fixed network gateway device, where the second information is used to request management of communication between the first terminal device and the first fixed network gateway device connect.
  • the communication module 1601 is further configured to receive third information from the first fixed network gateway device, where the third information includes at least one of the following: the first terminal device the identification information of the first terminal device; the authentication information of the first terminal device, the authentication information is used to indicate that the first terminal device passes the authentication of the fixed network network corresponding to the first fixed network gateway device; the first terminal device Corresponding subscription data information, the subscription data information includes one or more of fixed network service information, QoS information, and priority information; security context information of the first terminal device, the security context information is used to establish the secure connection between the access network device and the first terminal device.
  • the third information includes at least one of the following: the first terminal device the identification information of the first terminal device; the authentication information of the first terminal device, the authentication information is used to indicate that the first terminal device passes the authentication of the fixed network network corresponding to the first fixed network gateway device; the first terminal device Corresponding subscription data information, the subscription data information includes one or more of fixed network service information, QoS information, and priority information; security context information of the first
  • the processing module 1602 is further configured to execute a user plane connection management process according to the third information; wherein the user plane management process includes at least one of the following operations: establishing a user plane resources, modify user plane resources, or release user plane resources.
  • a connection is established between the access network device and at least one fixed network gateway device, and the at least one fixed network gateway device includes the first fixed network gateway device.
  • the communication module 1601 is further configured to obtain fourth information from the first terminal device, where the fourth information is used to determine security context information of the first terminal device
  • the processing module is further configured to use the security context information of the first terminal device to establish a secure connection between the access network device and the first terminal device according to the fourth information.
  • the fourth information includes a first serial number corresponding to the security context information of the first terminal device; the processing module 1602 is further configured to: obtain through the communication module 1601 Security context information and an identification set of at least one terminal device, the identification set including a first sequence number set used to indicate the security context information of the at least one terminal device, the first sequence number set including the first sequence number number; obtain the security context information of the first terminal device from the security context information and identification set of the at least one terminal device according to the first sequence number; the access network device adopts the security context information of the first terminal device The security context information is used to establish a secure connection between the access network device and the first terminal device.
  • the identification set further includes a second serial number set;
  • the processing module 1602 is further configured to execute establishing the access network device by using the security context information of the first terminal device After the secure connection with the first terminal device, replace the first serial number with the second serial number in the second serial number set;
  • the communication module 1601 is also configured to send the first serial number to the first terminal The device sends the second serial number, where the second serial number is used to indicate the security context information of the first terminal device.
  • the fourth information further includes identification information of a fixed network network corresponding to the first fixed network gateway device.
  • the communication module 1601 is further configured to: send at least one of the following information: capability information of the access network device, the capability information indicating that the access network device supports fixed network transmission; the identification information of the fixed network network supported by the access network device, the fixed network network supported by the access network device includes the fixed network network corresponding to the first fixed network gateway device; network priority information, the The network priority information is used to indicate the priority of the mobile operator to which the access network device belongs.
  • the communication module 1601 acquires the information sent by the first terminal device for indicating that the type of the first terminal device is the target type and/or the information sent by the first terminal device
  • the identification information of the fixed network network that requests access the processing module 1602 is further configured to determine according to the type of the first terminal device and/or the identification information of the fixed network network that the first terminal device requests to access
  • the access network device supports fixed network transmission of the first terminal device.
  • the communication device 1700 may be a chip or a chip system.
  • the system-on-a-chip may be composed of chips, or may include chips and other discrete devices.
  • the communication device 1700 may be used to implement functions of terminal equipment, access network equipment, or fixed network gateway equipment in the communication system shown in FIG. 5 .
  • the communication device 1700 may include at least one processor 1710, and the processor 1710 is coupled to a memory.
  • the memory may be located within the device, the memory may be integrated with the processor, or the memory may be located outside the device.
  • the communication device 1700 may further include at least one memory 1720 .
  • the memory 1720 stores necessary computer programs, configuration information, computer programs or instructions and/or data for implementing any of the above embodiments; the processor 1710 may execute the computer programs stored in the memory 1720 to complete the methods in any of the above embodiments.
  • the coupling in the embodiments of the present application is an indirect coupling or a communication connection between devices, units or modules, which may be in electrical, mechanical or other forms, and is used for information exchange between devices, units or modules.
  • the processor 1710 may operate in cooperation with the memory 1720 .
  • a specific connection medium among the communication interface 1730, the processor 1710, and the memory 1720 is not limited.
  • the communication device 1700 may further include a communication interface 1730, and the communication device 1700 may perform information exchange with other devices through the communication interface 1730.
  • the communication interface 1730 may be a transceiver, a circuit, a bus, a module or other types of communication interfaces.
  • the communication interface 1730 in the device 1700 can also be an input and output circuit, which can input information (or call it, receive information) and output information (or call it, send information),
  • the processor is an integrated processor or a microprocessor or an integrated circuit or a logic circuit, and the processor can determine output information according to input information.
  • the communication interface 1730 , the processor 1710 , and the memory 1720 are connected to each other through a bus 1740 .
  • the bus 1740 may be a peripheral component interconnect standard (peripheral component interconnect, PCI) bus or an extended industry standard architecture (extended industry standard architecture, EISA) bus or the like.
  • PCI peripheral component interconnect
  • EISA extended industry standard architecture
  • the bus can be divided into address bus, data bus, control bus and so on. For ease of representation, only one thick line is used in FIG. 17 , but it does not mean that there is only one bus or one type of bus.
  • the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or Execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application.
  • a general purpose processor may be a microprocessor or any conventional processor or the like. The steps of the methods disclosed in connection with the embodiments of the present application may be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.
  • the memory may be a non-volatile memory, such as a hard disk (hard disk drive, HDD) or a solid-state drive (solid-state drive, SSD), etc., and may also be a volatile memory (volatile memory), such as Random-access memory (RAM).
  • a memory is, but is not limited to, any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer.
  • the memory in the embodiment of the present application may also be a circuit or any other device capable of implementing a storage function, and is used for storing program instructions and/or data.
  • the communication device 1700 can be applied to a terminal device.
  • the communication device 1700 can be a terminal device, or can support a terminal device, and realize the functions of the terminal device in any of the above-mentioned embodiments. device.
  • the memory 1720 stores necessary computer programs, computer programs or instructions and/or data for realizing the functions of the terminal device in any of the foregoing embodiments.
  • the processor 1710 may execute the computer program stored in the memory 1720 to complete the method performed by the terminal device in any of the foregoing embodiments.
  • the communication interface in the communication apparatus 1700 can be used to interact with network equipment, send information to network equipment or receive information from network equipment.
  • the communication device 1700 can be applied to access network equipment, and the specific communication device 1700 can be an access network device, or can support an access network device, to implement any of the above-mentioned embodiments A device that accesses the functions of network equipment.
  • the memory 1720 stores necessary computer programs, computer programs or instructions and/or data for realizing the functions of the access network device in any of the foregoing embodiments.
  • the processor 1710 may execute the computer program stored in the memory 1720 to complete the method performed by the access network device in any of the foregoing embodiments.
  • the communication interface in the communication device 1700 can be used to interact with the terminal device, send information to the terminal device or receive information from the terminal device; or, the communication interface in the communication device 1700 can be used to communicate with the fixed
  • the network gateway device interacts, sends information to the fixed network gateway device or receives information from the fixed network gateway device.
  • the communication device 1700 can be applied to a fixed network gateway device, and the specific communication device 1700 can be a fixed network gateway device, or can support a fixed network gateway device, to implement any of the above-mentioned embodiments A device that functions as a gateway device in a fixed network.
  • the memory 1720 stores necessary computer programs, computer programs or instructions and/or data for realizing the functions of the fixed network gateway device in any of the above embodiments.
  • the processor 1710 may execute the computer program stored in the memory 1720 to complete the method performed by the fixed network gateway device in any of the foregoing embodiments.
  • the communication interface in the communication device 1700 can be used to interact with access network equipment, send information to the access network equipment or receive information from the access network equipment.
  • the communication apparatus 1700 provided in this embodiment can be applied to a terminal device to complete the method performed by the terminal device, or applied to a network device to complete the method performed by the network device. Therefore, the technical effects that can be obtained can refer to the above-mentioned method embodiments, and will not be repeated here.
  • the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or Execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application.
  • a general purpose processor may be a microprocessor or any conventional processor or the like. The steps of the methods disclosed in connection with the embodiments of the present application may be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.
  • the memory may be a non-volatile memory, such as a hard disk (hard disk drive, HDD) or a solid-state drive (solid-state drive, SSD), etc., and may also be a volatile memory (volatile memory), such as Random-access memory (RAM).
  • the memory may also be, but is not limited to, any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer.
  • the memory in the embodiment of the present application may also be a circuit or any other device capable of implementing a storage function, for storing computer programs, computer programs or instructions and/or data.
  • this embodiment of the present application also provides a computer program that, when the computer program is run on a computer, enables the computer to execute the steps shown in Figure 6, Figure 9, and Figure 10 from the perspective of the terminal device side or the network device side. , the data transmission method provided in the embodiment shown in FIG. 11 and FIG. 14 .
  • this embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a computer, the computer makes the From a side angle, execute the data transmission method provided in the above method embodiment.
  • the storage medium may be any available medium that can be accessed by a computer.
  • computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or may be used to carry or store information in the form of instructions or data structures desired program code and any other medium that can be accessed by a computer.
  • this embodiment of the present application provides a communication system, including terminal equipment, access network equipment, and fixed network gateway equipment, wherein the terminal equipment, network equipment, and fixed network gateway equipment can implement the above-mentioned embodiment.
  • the embodiments of the present application also provide a chip, which is used to read the computer program stored in the memory, and realize the data transmission provided in the above method embodiments from the perspective of the terminal device side or the network device side method.
  • an embodiment of the present application provides a chip system
  • the chip system includes a processor, and is used to support a computer device to implement the functions involved in the terminal device, access network device or fixed network gateway device in the above method embodiments .
  • the chip system further includes a memory, and the memory is used to store necessary programs and data of the computer device.
  • the system-on-a-chip may consist of chips, or may include chips and other discrete devices.
  • the technical solutions provided by the embodiments of the present application may be fully or partially implemented by software, hardware, firmware or any combination thereof.
  • software When implemented using software, it may be implemented in whole or in part in the form of a computer program product.
  • the computer program product includes one or more computer instructions.
  • the computer program instructions When the computer program instructions are loaded and executed on the computer, the processes or functions according to the embodiments of the present invention will be generated in whole or in part.
  • the computer may be a general computer, a special computer, a computer network, a network device, a terminal device or other programmable devices.
  • the computer instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website, computer, server or data center Transmission to another website site, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.).
  • the computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center integrated with one or more available media.
  • the available medium may be a magnetic medium (for example, a floppy disk, a hard disk, or a magnetic tape), an optical medium (for example, a digital video disc (digital video disc, DVD)), or a semiconductor medium.
  • the various embodiments may refer to each other, for example, the methods and/or terms between the method embodiments may refer to each other, such as the functions and/or terms between the device embodiments Or terms may refer to each other, for example, functions and/or terms between the apparatus embodiment and the method embodiment may refer to each other.
  • These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing apparatus to operate in a specific manner, such that the instructions stored in the computer-readable memory produce an article of manufacture comprising instruction means, the instructions
  • the device realizes the function specified in one or more procedures of the flowchart and/or one or more blocks of the block diagram.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Databases & Information Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请提供一种通信方法及装置,用以解决光纤铺设困难无法采用有线接入获取固网业务的问题。该方法包括:接入网设备获取第一信息,接入网设备支持第三代合作伙伴计划3GPP接入技术;接入网设备根据第一信息与第一终端设备建立用户面连接;接入网设备通过用户面连接获取第一终端设备的用户面数据,并向第一固网网关设备发送用户面数据。

Description

一种通信方法及装置
相关申请的交叉引用
本申请要求在2021年07月19日提交中华人民共和国知识产权局、申请号为202110812409.3、申请名称为“一种通信方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请实施例涉及通信技术领域,尤其涉及一种通信方法及装置。
背景技术
固网网络通常基于固定的线路为家庭住宅、商店等场所提供宽带服务。目前,固网的终端例如客户终端设备(customer-premises equipment,CPE),需通过光纤等有线方式接入固网,与固网的宽带网络网关(Broadband Network Gateway,BNG)通过以太网承载IP协议(internet protocol over ethernet,IPoE)或以太网承载PPP协议(point-to-point protocol over ethernet,PPPoE)通信。
对于一些偏远地区来说,铺设光纤较为困难,光纤入户率较低。通过有线接入获取宽带业务的方式并不适用于这些地区,如何让光纤铺设困难的地区使用宽带业务成为一个值得研究的问题。
发明内容
本申请实施例提供一种通信方法及装置,以期通过支持第三代合作伙伴计划(3rd generation partnership project,3GPP)的接入网设备提供无线接入固网方式以及带宽业务。
第一方面,本申请实施例提供一种通信方法,包括:接入网设备获取第一信息,所述接入网设备支持3GPP接入技术;所述接入网设备根据所述第一信息与第一终端设备建立用户面连接;所述接入网设备通过所述用户面连接获取所述第一终端设备的用户面数据,并向第一固网网关设备发送所述用户面数据。
本申请实施例中,采用支持3GPP接入技术的接入网设备作为终端设备与固网网关设备之间的中间节点,终端设备采用3GPP接入技术与接入网设备建立连接,接入网设备可向固网网关设备传输终端设备的数据,使得终端设备以3GPP接入的方式也能获取固网宽带业务。相较于传统固网终端以有线接入固网网络的方式可以简化部署,且可以增强覆盖,提升通信系统的性能。
在一种可能的设计中,所述第一信息用于指示所述第一终端设备的类型为目标类型和/或用于指示所述第一终端设备允许通过所述第一固网网关设备获取业务;其中,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个。
在一种可能的设计中,所述第一信息来自所述第一终端设备,所述第一信息指示所述第一终端设备的类型为所述目标类型。在另一种可能的设计中,所述第一信息预配置于所述接入网设备中或者所述第一信息来自所述第一固网网关设备;其中,所述第一信息包括 所述第一终端设备对应的签约数据信息,所述签约数据信息用于确定所述第一终端设备允许通过所述第一固网网关设备获取业务。通过这样的方式建立用户面连接可简化终端设备的接入流程,能够节省信令开销降低成本。
在一种可能的设计中,所述方法还包括:所述接入网设备向所述第一固网网关设备发送第二信息,所述第二信息用于请求管理所述第一终端设备与所述第一固网网关设备之间的连接。其中,管理可以包括建立、修改、释放或者删除等。
在一种可能的设计中,所述接入网设备接收来自所述第一固网网关设备的第三信息;所述第三信息包括以下至少一个:所述第一终端设备的标识信息;所述第一终端设备的认证信息,所述认证信息用于指示所述第一终端设备通过所述第一固网网关设备对应的固网网络的认证;所述第一终端设备的签约数据信息,所述签约数据信息包括固网业务信息、服务质量QoS信息、优先级信息中的一个或多个;所述第一终端设备的安全上下文信息,所述安全上下文信息用于建立所述接入网设备与所述第一终端设备的安全连接。根据终端设备的相关特性如其签约数据信息,对终端设备执行针对性的用户面连接管理流程,能够提升用户体验。
在一种可能的设计中,所述接入网设备根据所述第三信息,执行用户面连接管理流程;其中,所述用户面管理流程包括以下至少一个操作:建立用户面资源、修改用户面资源或者释放用户面资源。
在一种可能的设计中,所述接入网设备与至少一个固网网关设备建立连接,所述至少一个固网网关设备包括所述第一固网网关设备。
在一种可能的设计中,所述方法还包括:所述接入网设备获取来自所述第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息;所述接入网设备根据所述第四信息,采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接。采用终端设备的安全上下文信息建立接入网设备与终端设备的安全连接,能够提升通信安全。
在一种可能的设计中,所述第四信息包括所述第一终端设备的安全上下文信息对应的第一序列号;所述接入网设备根据所述第四信息,采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接,包括:所述接入网设备获取至少一个终端设备的安全上下文信息和标识集合,所述标识集合包括用于指示所述至少一个终端设备的安全上下文信息的第一序列号集合,所述第一序列号集合包括所述第一序列号;所述接入网设备根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取所述第一终端设备的安全上下文信息;所述接入网设备采用所述第一终端设备的安全上下文信息,建立所述接入网设备与所述第一终端设备的安全连接。
在一种可能的设计中,所述标识集合还包括第二序列号集合;在所述接入网设备采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接之后,所述方法还包括:将所述第一序列号替换为所述第二序列号集合中的第二序列号,并向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。执行完鉴权流程后更新安全上下文信息的序列号,以使得安全上下文的标识或索引号是动态变化的,能够进一步提升通信安全性。
在一种可能的设计中,所述第四信息还包括所述第一固网网关设备对应的固网网络的标识信息。
在一种可能的设计中,所述方法还包括:所述接入网设备发送以下至少一个信息:
所述接入网设备的能力信息,所述能力信息指示所述接入网设备支持固网传输;所述接入网设备支持的固网网络的标识信息,所述接入网设备支持的固网网络包括所述第一固网网关设备对应的固网网络;网络优先级信息,所述网络优先级信息用于指示所述接入网设备所属的移动运营商的优先级。
在一种可能的设计中,所述方法还包括:
所述接入网设备获取所述第一终端设备发送的用于指示所述第一终端设备的类型为目标类型的信息和/或所述第一终端设备请求接入的固网网络的标识信息;所述接入网设备根据所述第一终端设备的类型和/或所述第一终端设备请求接入的固网网络的标识信息,确定所述接入网设备支持所述第一终端设备的固网传输。
第二方面,本申请实施例提供一种通信装置,应用于支持3GPP接入技术的接入网设备。该通信装置可以是接入网设备,也可以是接入网设备中的装置,或者是能够和接入网设备匹配使用的装置。一种设计中,该通信装置可以包括执行第一方面中所描述的方法/操作/步骤/动作所一一对应的模块,该模块可以是硬件电路,也可是软件,也可以是硬件电路结合软件实现。一种设计中,该通信装置可以包括处理模块和通信模块。示例性地,
通信模块,用于获取第一信息;处理模块,用于根据所述第一信息与第一终端设备建立用户面连接;所述通信模块,还用于通过所述用户面连接获取所述第一终端设备的用户面数据,并向第一固网网关设备发送所述用户面数据。
本申请实施例中,采用支持3GPP接入技术的接入网设备作为终端设备与固网网关设备之间的中间节点,终端设备采用3GPP接入技术与接入网设备建立连接,接入网设备可向固网网关设备传输终端设备的数据,使得终端设备以3GPP接入的方式也能获取固网宽带业务。相较于传统固网终端以有线接入固网网络的方式可简化部署,且可以增强覆盖,提升通信系统的性能。
在一种可能的设计中,所述第一信息用于指示所述第一终端设备的类型为目标类型和/或用于指示所述第一终端设备允许通过所述第一固网网关设备获取业务;其中,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个,还可以包括手机、AR/VR终端、Pad、以及其他类型终端,本申请实施例对此并不进行限制。
在一种可能的设计中,所述第一信息来自所述第一终端设备,所述第一信息指示所述第一终端设备的类型为所述目标类型。
在一种可能的设计中,所述第一信息预配置于所述接入网设备中或者所述第一信息来自所述第一固网网关设备;其中,所述第一信息包括所述第一终端设备对应的签约数据信息,所述签约数据信息用于确定所述第一终端设备允许通过所述第一固网网关设备获取业务。
在一种可能的设计中,
所述通信模块,还用于向所述第一固网网关设备发送第二信息,所述第二信息用于请求管理所述第一终端设备与所述第一固网网关设备之间的连接。其中,管理可以包括建立、修改、释放或者删除等。在一种可能的设计中,所述通信模块,还用于接收来自所述第一固网网关设备的第三信息;所述第三信息包括以下至少一个:所述第一终端设备的标识信息;所述第一终端设备的认证信息,所述认证信息用于指示所述第一终端设备通过所述第 一固网网关设备对应的固网网络的认证;所述第一终端设备对应的签约数据信息,所述签约数据信息包括固网业务信息、QoS信息、优先级信息中的一个或多个;所述第一终端设备的安全上下文信息,所述安全上下文信息用于建立所述接入网设备与所述第一终端设备的安全连接。
在一种可能的设计中,所述处理模块,还用于根据所述第三信息,执行用户面连接管理流程;其中,所述用户面管理流程包括以下至少一个操作:建立用户面资源、修改用户面资源或者释放用户面资源。
在一种可能的设计中,所述接入网设备与至少一个固网网关设备之间建立连接,所述至少一个固网网关设备包括所述第一固网网关设备。
在一种可能的设计中,所述通信模块,还用于获取来自所述第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息;所述处理模块,还用于根据所述第四信息,采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接。
在一种可能的设计中,所述第四信息包括所述第一终端设备的安全上下文信息对应的第一序列号;所述处理模块,还用于:通过所述通信模块获取至少一个终端设备的安全上下文信息和标识集合,所述标识集合包括用于指示所述至少一个终端设备的安全上下文信息的第一序列号集合,所述第一序列号集合包括所述第一序列号;根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取所述第一终端设备的安全上下文信息;所述接入网设备采用所述第一终端设备的安全上下文信息,建立所述接入网设备与所述第一终端设备的安全连接。
在一种可能的设计中,所述标识集合还包括第二序列号集合;所述处理模块,还用于在采用所述第一终端设备安全上下文信息执行建立所述接入网设备与所述第一终端设备的安全连接之后,将所述第一序列号替换为所述第二序列号集合中的第二序列号;所述通信模块,还用于向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。
在一种可能的设计中,所述第四信息还包括所述第一固网网关设备对应的固网网络的标识信息。
在一种可能的设计中,所述通信模块还用于发送以下至少一个信息:所述接入网设备的能力信息,所述能力信息指示所述接入网设备支持固网传输;所述接入网设备支持的固网网络的标识信息,所述接入网设备支持的固网网络包括所述第一固网网关设备对应的固网网络;网络优先级信息,所述网络优先级信息用于指示所述接入网设备所属的移动运营商的优先级。
在一种可能的设计中,所述通信模块,还用于获取所述第一终端设备发送的用于指示所述第一终端设备的类型为目标类型的信息和/或所述第一终端设备请求接入的固网网络的标识信息;所述处理模块,还用于根据所述第一终端设备的类型和/或所述第一终端设备请求接入的固网网络的标识信息,确定所述接入网设备支持所述第一终端设备的固网传输。
第三方面,本申请实施例提供一种通信装置,所述通信装置包括处理器,用于实现上述第一方面描述的方法。所述通信装置还可以包括存储器,用于存储指令和数据。所述存储器与所述处理器耦合,所述处理器执行所述存储器中存储的指令时,可以实现上述第一 方面描述的方法。所述装置还可以包括通信接口,所述通信接口用于该装置与其它设备进行通信,示例性的,通信接口可以是收发器、电路、总线、模块或其它类型的通信接口,其它设备可以为网络设备。在一种可能的设备中,该装置包括:
存储器,用于存储程序指令;
处理器,用于通过通信接口获取第一信息,根据所述第一信息与第一终端设备建立用户面连接;并通过所述用户面连接获取所述第一终端设备的用户面数据,向第一固网网关设备发送所述用户面数据。
第四方面,本申请实施例还提供了一种计算机程序,当所述计算机程序在计算机上运行时,使得所述计算机执行上述第一方面提供的方法。
第五方面,本申请实施例还提供了一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序,当所述计算机程序被计算机执行时,使得所述计算机执行上述第一方面提供的方法。
第六方面,本申请实施例还提供了一种芯片,所述芯片用于读取存储器中存储的计算机程序,执行上述第一方面提供的方法。
第七方面,本申请实施例还提供了一种芯片系统,该芯片系统包括处理器,用于支持计算机装置实现上述第一方面任一方面提供的方法。在一种可能的设计中,所述芯片系统还包括存储器,所述存储器用于保存该计算机装置必要的程序和数据。该芯片系统可以由芯片构成,也可以包含芯片和其他分立器件。
上述第二方面至第七方面可以达到的技术效果请参照上述第一方面中相应技术方案可以带来的技术效果说明,此处不再重复赘述。
附图说明
图1为一种固定有线网络架构示意图;
图2为一种固网传输协议栈示意图;
图3为一种IPoE通信流程示意图;
图4为一种PPPoE通信流程示意图;
图5为本申请实施例提供的一种通信系统架构示意图;
图6为本申请实施例提供的一种选网方法流程示意图;
图7为本申请实施例提供的另一种选网方法流程示意图;
图8为本申请实施例提供的一种协议栈架构示意图;
图9为本申请实施例提供的通信方法的流程示意图之一;
图10为本申请实施例提供的一种数据传输流程示意图;
图11为本申请实施例提供的通信方法的流程示意图之一;
图12为本申请实施例提供的通信方法的流程示意图之一;
图13为本申请实施例提供的另一种协议栈架构示意图;
图14为本申请实施例提供的通信方法的流程示意图之一;
图15为本申请实施例提供的另一种数据传输流程示意图;
图16为本申请实施例提供的一种通信装置的结构示意图;
图17为本申请实施例提供的另一种通信装置的结构示意图。
具体实施方式
以下先结合图1~4,对有线接入固网涉及的技术方案进行说明。
参见图1示意一种固定有线网络架构,固定有线网络(fixed wireline network)可以简单地分为四个部分,分别是固网终端、接入节点(access node,AN)、宽带网络网关(broadband network gateway,BNG)以及服务提供商网络(service provider network)。图1中的接入节点也可以替换为接入网络(access network,AN),且图1中的接入节点指的是有线接入节点,接入网络指的是有线接入网络。
固网终端,或可以称为客户终端设备(customer-premises equipment,CPE)。其中,CPE例如电话,路由器,网络交换机,家庭网关(residential gateway,RG),机顶盒,固定移动融合产品,家庭网络适配器和互联网接入网关等设备。CPE是一种可以接收移动信号和/或者宽带信号,并以无线保真(wireless fidelity,WIFI)信号转发出来的设备,例如CPE可以将高速4G或者5G信号转换成WIFI信号,CPE也可以将宽带信号转换成WIFI信号,CPE能够支持数量较多的移动终端同时上网。其中,移动终端可以是笔记本电脑、手机、平板电脑、网络电视机等可基于WIFI上网的设备。CPE既支持有线接入,如通过有线方式接入固定有线网络(如有线宽带网络)。也支持无线接入,无线接入可以理解为通过第三代合作伙伴计划(3rd generation partnership project,3GPP)接入类型接入移动网络。
接入节点(access node,AN)是在交换网中,用户传输信号接入或者退出通信网的某个节点。接入节点能够实现多种功能,如协议转换和编码转换,为对象存储的访问入口,负责验证用户请求的认证授权信息,同时将数据写入底层存储节点。接入节点可以包括以太网接入节点(Ethernet Access Node),它支持基于以太网的用户线和到基于以太网的聚合网络的上行链路以及(media access control,MAC)强制转发。有线接入网络(wireline access network)包括有线接入节点(wireline access node)和可选的某种形式的聚合。
宽带网络网关(broadband network gateway,BNG)为网际互连协议(internet protocol,IP)边缘节点,可以细分为宽带远程接入服务器(broadband remote access server,BRAS)和业务路由器(service router,SR)。其中,BRAS可作为传统的互联网业务的入口,SR可作为新的精品业务的入口。SR与BRAS类似,用来终结和管理用户(即CPE)的PPPoE/IPoE会话。
如图2示意一种固网传输协议栈,前述固网终端通过接入节点以有线的方式接入固网,如固网终端和接入节点之间、接入节点和BNG之间通过光缆连接。固网终端与BNG可以通过IPoE或PPPoE协议通信。若终端设备采用IPoE,需进行认证流程,并获取IP地址。若终端采用PPPoE,则它与BNG之间会建立PPPoE连接,并获取PPPoE会话标识。在固定有线网络结构中,固网终端可以把有线宽带网络转成供笔记本、手机等使用的WiFi网络。
下面对固网终端与BNG通过IPoE或PPPoE协议通信的方案进行说明。
参见图3示意一种IPoE通信流程,示意出了固网终端进行IPoE认证以及获取IP地址的过程。涉及固网终端、BNG(可以为BRAS或者SR)、动态主机配置协议服务器(dynamic host configuration protocol server,DHCP server)以及认证、授权和计费(authentication、authorization、accounting,AAA)服务器之间的交互。其中,DHCP Server用于为认证通过的固网终端分配IP地址,AAA服务器用于执行认证,如认证是否允许固网终端上线, 或称认证固网终端是否开通宽带业务。具体的步骤如下:
S31,固网终端发起DHCP发现(DHCP Discover)消息,并在DHCP Discover消息中的Option 60字段携带可以指示固网终端类型的信息。接入节点(AN)接收该DHCP Discover消息后,可在DHCP Discover消息的选项(Option)82中插入用于指示固网终端设备位置的信息,然后将DHCP Discover发送给BNG。其中,图3中省略了接入节点涉及的流程。
示例性的,可在DHCP Discover消息的Option 82中插入Line ID,这里的Line ID是基于位置来决定的,即采用Line ID指示固网终端的位置。比如地址为XX省XX市XX区XX路XX号XX室的家庭,对应于一个Line ID。若该地址开通了家庭宽带业务,则BNG/AAA可获知该Line ID对应的用户(即固网终端)开通了家庭宽带业务,因此对于该固网终端的认证可以通过。
S32,BNG收到固网终端发送的DHCP Discover消息后,标记相应的Option 82信息,并向DHCP服务器发送DHCP Discover消息。
S33,DHCP服务器收到该DHCP Discover消息后,提取出DHCP Discover消息中的相关信息,构造认证所需的用户名(Username)和构造需要认证的信息Nas-Port-ID(或者,也可以是Line ID);并通过接入请求(access request)消息将Username、Nas-Port-ID发送给AAA服务器进行认证。
S34,AAA服务器对固网终端进行认证;若认证不通过,则反馈拒绝报文如接入拒绝(access deny),DHCP Server向BNG反馈DHCP NACK,BNG通过接入节点(AN)向固网终端反馈DHCP NACK;若认证通过,则返回接受报文如接入接受(access accept),则DHCP服务器分配IP地址,并将分配给固网终端的IP地址封装进DHCP响应(DHCP Offer)消息中,通过BNG发给固网终端;其中DHCP Offer消息中还插入认证信息(Option 125),以便固网终端能够对此DHCP Offer消息进行鉴权,识别该DHCP Offer消息是否来自可信的DHCP Server。
示例性的,图3以虚线示意出了一种可能执行的S34,即图3中的S34a:DHCP服务器向BNG发送DHCP NACK,BNG通过接入节点向固网终端发送该DHCP NACK。以实线示意出了另一种可能执行的S34,即图3中的S34b:DHCP服务器向BNG发送DHCP响应,BNG通过接入节点向固网终端发送该DHCP响应。
S35,由于步骤S31中的DHCP Discover消息属于广播消息,可能有多个DHCP服务器接收到,因此在步骤S34中,也可能会有多个DHCP服务器对固网终端分配IP地址并发送DHCP Offer消息;若固网终端接收来自多个DHCP服务器发送的DHCP Offer消息后,可根据其中一个DHCP Offer消息发送DHCP请求(DHCP Request)消息,其中,DHCP Request消息包含该DHCP服务器分配的IP地址。其中,固网终端可根据最先收到的DHCP Offer来发送DHCP Request消息。
示例性的,假设图3中示意的DHCP服务器发送的DHCP响应是固网终端最先收到的,则如图3中的S35:固网终端在收到DHCP响应之后,可通过接入节点向BNG发送向DHCP请求消息,BNG再向该DHCP服务器发送DHCP请求消息。
S36,分配IP地址的DHCP服务器收到来自固网终端的DHCP请求消息后,根据该DHCP请求消息中包含的IP地址识别该IP地址是自己分配的,则向BNG反馈DHCP ACK,BNG再通过接入节点向固网终端反馈DHCP ACK。类似地,针对其它也分配了IP地址的DHCP服务器可获知该IP地址不是自己分配的,则释放分配的IP地址,且无需向固网终 端反馈响应消息。
通过以上步骤,固网终端通过了认证,并获取IP地址,从而可以发送或接收业务流数据。
参见图4示意一种PPPoE通信流程,示意了PPPoE客户端(client)与PPPoE服务器(server)建立会话的流程。其中,PPPoE客户端可以是前述的固网终端,PPPoE服务器可以是前述BNG。图4中以固网终端示意PPPoE客户端,以BNG示意PPPoE服务器,描述了固网终端与BNG之间建立PPPoE连接包括如下步骤。
S41,固网终端通过接入节点AN向BNG发送PPPoE主动发现启动(PPPoE active discovery initiation,PADI)消息;该消息是以广播的形式发送,该消息包括固网终端请求的服务的服务名。图4中省略了处于固网终端设备与BNG之间的接入节点AN。
S42,当BNG收到PADI消息后,判断自己是否能够提供该服务,如果能够提供服务的话,会通过接入节点向固网终端发送PPPoE主动发现回应(PPPoE Active Discovery Offer,PADO)消息来进行回应。PADO消息包括PPPoE服务器(即BNG)名称与PADI消息中相同的服务名。若BNG不能提供该服务,则不发送PADO消息。图4中示意出了BNG能够提供服务的情况,也即S42:BNG向固网终端发送PADO消息。其中省略了AN,即具体的是BNG发送PADO消息;AN接收该PADO消息,并向固网终端发送PADO消息。
S43,由于PADI是以广播的形式发送出去的,则固网终端可能收到不止一个PADO消息,固网终端在接收到多个PADO消息时,可根据PADO中的服务器名或所提供的服务选择一个PPPoE服务器(即BNG),并通过接入节点向选中的BNG发送PPPoE主动发现请求(PPPoE Active Discovery Request,PADR)消息。PADR消息包括固网终端所请求的服务。
S44,当BNG收到固网终端发送的PADR消息后,BNG通过接入节点向固网终端发送PPPoE主动发现会话配置(PPPoE Active Discovery Session-confirmation,PADS)消息作为响应。该PADS用于建立一个PPPoE会话,如BNG为PPPoE会话创建一个PPPoE会话标识(Session ID),PADS消息中包括PPPoE会话标识。则通信双方都可得会话标识和对方的MAC地址(address),进而基于会话标识(Session ID)和MAC地址定义一个PPPoE会话。
进一步,固网终端与BNG交互链路配置协议(Link Configure Protocol,LCP)消息,以完成数据链路参数的配置。包括S45中的:固网终端向BNG发送链路配置请求(Link Configure-Request)消息以及S46中BNG向固网终端那发送链路配置确认(LCP Configure-Ack)消息。
S47,固网终端和BNG进行认证阶段,涉及密码验证协议(Password Authentication Protocol,PAP)以及挑战握手认证协议(Challenge Handshake Authentication Protocol,CHAP)。
S48,固网终端和BNG进行网络侧参数(Network Control Protocol,NCP)协商阶段,固网终端在此阶段获取IP地址。
以上介绍的有线接入固网方案涉及光缆的铺设,然而对于一些偏远地区来说,受环境或者实际地区管辖等限制,无法铺设光纤或者光纤铺设较为困难,导致光纤入户率较低。可见通过有线接入固网获取宽带业务的技术并不适用于这些地区。
有基于此,本申请实施例提供一种通信方法,以期通过引入支持3GPP接入技术的接入网设备,实现无线接入固网的方式,为无法铺设有线线路的地区提供相应的宽带业务。 下面结合附图对本申请实施例进行进一步介绍。
本申请中涉及的多个,是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。字符“/”一般表示前后关联对象是一种“或”的关系。另外,应当理解,尽管在本发明实施例中可能采用术语第一、第二等来描述各数据、但这些数据不应限于这些术语。这些术语仅用来将各数据彼此区分开。
参见图5示意的一种通信系统架构,本申请实施例提供的通信方法能够应用于该通信系统,该通信系统包括至少一个终端设备、至少一个支持3GPP接入技术的接入网设备以及至少一个固网网关设备。示例性的,图5中示意出了一个终端设备、一个接入网设备,以及一个固网网关设备即第一固网网关设备。
其中,终端设备,或称用户设备(user equipment,UE)、接入终端、终端、终端装置等。终端设备可以接收移动信号,为其覆盖范围内的至少一个终端设备提供无线局域网通信能力,无线局域网可以是无线保真(wireless fidelity,WIFI)网络、蓝牙等。示例性的,终端设备的类型可以是前述的固网终端,例如家庭网关、家庭终端、客户终端设备CPE等。
本申请实施例涉及的接入网设备,也可以称作基站设备,也可以称作基站、中继站或无线接入点(radio access node,RAN)等。示例性的,接入网设备可以是全球移动通信系统(global system for mobile communication,GSM)或码分多址(code division multiple access,CDMA)网络中的基站收发信台(base transceiver station,BTS),也可以是宽带码分多址(wideband code division multiple access,WCDMA)网络中的NB(NodeB),还可以是长期演进(long term evolution,LTE)系统中的eNB或eNodeB(evolutional NodeB)。接入网设备还可以是5G网络中的基站设备或者未来演进的公共陆地移动网络(public land mobile network,PLMN)网络中的网络设备。接入网设备可以支持3GPP技术。可以理解为,接入网设备可以是完全支持3GPP协议栈,也可以是支持部分3GPP协议栈,例如只支持物理层、MAC层、RLC层、PDCP层、SDAP层、RRC层中的部分或全部协议栈。
本申请实施例涉及的固网网关设备可以是宽带网络网关BNG或者其他网关设备。可选的,接入网设备可以是移动运营商部署的,固网网关设备所属的固网运营商可通过与移动运营商签订合约的方式,租用该接入网设备。对于此场景,接入网设备可能既服务于该移动运营商的终端设备,也服务于该移动运营商签订合约的固网运营商的固网终端。或者,可选的,接入网设备可以是固网运营商自己单独部署的。对于此场景,该接入网设备可以只服务固网运营商的固网终端。
终端设备经由鉴权和/或认证,与接入网设备建立安全的空口连接,通过接入网设备以无线的方式接入固网网络,实现数据传输获取相关的固网业务。其中,鉴权可以是网络与终端设备根据预配置的安全方案鉴权对方是否为可信的设备或网络;认证可以是判断终端设备是否允许获取业务(如家庭宽带业务),认证终端设备的标识或用户名密码等。终端设备采用3GPP接入技术接入网络,相较于传统固网网络有线接入的方式简化了部署,且可以增强覆盖,提升通信系统的性能。
下面对于终端设备采用3GPP接入技术通过接入网设备接入固网网络的方案进行详细描述。
首先介绍一下终端设备接入固网网络之前的选网过程。
参见图6示意一种选网方法流程示意图,该选网方法主要包括如下流程:
S601,终端设备接收来自至少一个接入网设备发送的消息,每个接入网设备的发送的消息包括该接入网设备的能力信息和/或指示该接入网设备支持的固网网络的标识信息。可选的,该消息可以以广播的形式发送。
其中,能力信息指示接入网设备是否支持固网传输,或者指示是否支持固网终端如家庭网关的数据传输,前述标识信息可以是固网网络标识和/或固网服务提供商标识。一个接入网设备可以支持一个或多个固网网络,每个固网网络可以包括(或称,对应)至少一个固网网关设备。示例性的,针对接入网设备支持一个固网网络而言,接入网设备可以与该固网网络中的至少一个固网网关设备连接。又如,针对接入网设备支持多个固网网络而言,接入网设备可以与每个固网网络中的至少一个固网网关设备连接。
此外可选的,该消息中还可包括网络优先级信息,该网络优先级信息用于指示接入网设备所属移动运营商的优先级。其中,移动运营商能够提供移动网络能力。具体的,对应前述场景:接入网设备可以是移动运营商部署的,固网网关设备所属的固网运营商可通过与移动运营商签订合约的方式租用该接入网设备。即接入网设备既服务于移动运营商的终端,也服务于固网运营商的终端(即固网终端)。固网运营商可能与多个移动运营商签订了合约,因此终端设备所在区域可能存在不同移动运营商的接入网设备能够提供固网传输的能力,则可采用网络优先级信息指示各个移动运营商网络的优先级,使得终端设备基于网络优先级信息选择合适的网络,选择能提供固网传输能力的小区。
作为示例,图6示意出了三个接入网设备,分别为接入网设备1、接入网设备2、接入网设备3。其中,图6中的S601具体示意出了终端设备接收来自接入网设备1、接入网设备2以及接入网设备3发送的广播消息。
S602,终端设备根据各个接入网设备发送的消息,进行网络选择和小区选择。
具体的,终端设备可根据各接入网设备的能力信息、固网网络标识、固网服务提供商标识信息、网络优先级信息中的至少一种信息进行网络选择(以下,简称网络选择为选网)和小区选择。例如终端设备可以选择支持固网传输的接入网设备,终端设备可以在支持固网传输的接入网设备所支持的一个或多个固网网关设备对应的固网网络中选择一个固网网络,如选择第一固网网关设备对应的固网网络。
S603,若终端设备在S602中选择了接入网设备1,那么终端设备可与接入网设备1建立控制面连接,或称终端设备可与接入网设备1建立无线资源控制(radio resource Control,RRC)信令连接。
具体的,终端设备可向接入网设备1发送连接请求,所述连接请求用于请求建立控制面连接;接入网设备与终端设备建立所述控制面连接。
一种可选的实施方式中,由于接入网设备在接收来自终端设备的该连接请求之前,可以与该终端设备进行交互,通过该交互过程,接入网设备可以根据与终端设备的交互消息隐式地判断终端设备的类型为目标类型和/或终端设备允许通过固网网关设备获取业务。例如接入网设备向终端设备发送接入网设备的能力信息和/或指示该接入网设备支持的固网网络的标识信息。则基于接入网设备与终端设备的交互流程,接入网设备在收到连接请求时,可以隐式地确定终端设备需要通过接入网设备所支持的固网网关设备获取业务;或者可以理解,终端设备通过连接请求间接(或称隐式)地向网络设备上报了其需要通过接入网设备所支持的固网网关设备获取业务。另外,接入网设备还可以根据终端设备与接入网 设备之间的交互消息格式或协议等,判断出该终端设备的类型。另一种可选的实施方式中,终端设备可以在连接请求中包括用于指示终端设备的类型为目标类型的信息,以直接(或称显示)的方式向接入网设备上报终端设备的类型。其中,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个,还可以包括手机、AR/VR终端、Pad、以及其他类型终端,本申请实施例对此并不进行限制。
参见图7示意另一种选网方法流程示意图,该选网方法主要包括如下流程:
S701,终端设备选取至少一个接入网设备中的一个接入网设备,与该接入网设备建立控制面连接。
可选的,终端设备可接收至少一个接入网设备发送的网络信息,根据配置信息选择网络。其中,该网络信息可以以广播的形式发送。终端设备还可根据小区信号质量等要求选择可接入的小区,并与选择的网络对应的接入网设备建立控制面连接。示例性的,图7中示意出了三个接入网设备,分别为接入网设备1、接入网设备2以及接入网设备3。终端设备选取接入网设备1,并与该接入网设备1建立控制面连接(RRC连接)。
S702,终端设备向接入网设备1发送第一RRC消息。
其中,该第一RRC消息中包括如下信息中的至少一个:用于指示所述终端设备的类型为所述目标类型的信息、所述终端设备请求接入的固网网络的标识信息;其中,前述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个,还可以包括手机、AR/VR终端、Pad、以及其他类型终端,本申请实施例对此并不进行限制;前述固网网络的标识信息可以包括固网网络标识和/或服务商提供标识。可选的,可以约定需接入固网网络的终端设备的类型,则在第一RRC消息仅包括所述终端设备请求接入的固网网络的标识信息的情况下,接入网设备1也可以根据第一RRC消息判断终端设备的类型。也即在该情况下,终端设备通过第一RRC消息间接(或称隐式)地向接入网设备1上报了自身的类型。或者可选的,也可以配置不同类型的终端设备与网络设备之间交互的消息格式不同,例如信令大小不同等。通过这样的设计,网络设备可以根据终端设备与网络设备之间的交互,来判断终端设备的类型。
S703,接入网设备1判断是否支持固网传输及终端设备请求的数据传输。
接入网设备1在根据第一RRC消息得知终端设备为家庭网关、客户端终端、家庭终端等固网终端,确定可以支持固网传输时,可以根据固网网络标识/服务提供商标识判断是否能够支持前述终端设备请求的数据传输。
若是,则执行S704:接入网设备1向终端设备发送第二RRC消息,第二RRC消息用于指示接受或者支持该终端设备的数据传输。接入网设备1在确定能够支持前述终端设备的数据传输时,也可以不发送RRC消息,表示默认接受或者支持该终端设备的数据传输,并保持控制面连接。
否则执行S705和S706,其中S705:接入网设备1向终端设备发送第三RRC消息,该第三RRC消息中包括指示终端设备进行网络重选和/或小区重选的信息。S706:接入网设备1与终端设备释放控制面连接(或称,RRC连接)。进而在接入网设备1不支持终端设备的数据传输的情况下,需要重新执行网络选择流程,直到为终端设备选择到支持其数据传输的合适网络和小区。
然后,结合下述方案一和方案二对于终端设备接入固网网络,进行数据传输的过程进行详细介绍。
方案一:
参见图8,本申请实施例提供一种协议栈架构,具体示意出了控制面协议栈以及用户面协议栈。作为一种可选的实施方式,实施本方案二可以构建该协议栈架构,或者可以理解,该协议栈架构能够应用于本方案一。另外需要说明的是,图8示意的协议栈仅作为一种可能的实施方式,本方案一还可以采用其它的协议栈架构,本申请实施例对此不进行限制。
其中,终端设备侧以及接入网设备侧的控制面协议栈分为RRC层、分组数据汇聚协议(Packet Data Convergence Protocol,PDCP)层、无线链路层控制协议(Radio Link Control,RLC)层、介质访问控制(medium access control,MAC)层、物理(physical,PHY)层。终端设备侧的用户面协议栈分为IPoE/PPPoE协议层、802.1ad协议层、服务数据适配协议(Service Data Adaptation Protocol,SDAP)层、PDCP层、RLC层、MAC层、PHY层。接入网设备侧面向与终端设备通信的用户面协议栈分为802.1ad协议层、SDAP层、PDCP层、RLC层、MAC层、PHY层。接入网设备侧面向与固网网关设备通信的用户面协议栈分为802.1ad协议层、MAC层、PHY层。固网网关设备侧的用户面协议栈分为IPoE/PPPoE协议层、802.1ad协议层、MAC层、PHY层。
接入网设备支持3GPP接入技术,终端设备可与接入网设备通过3GPP技术(或称蜂窝空口)传输,如终端设备可与接入网设备建立控制面连接,控制面的消息可通过RRC信令进行传输;终端设备可与接入网设备建立用户面连接,用户面的消息可通过该用户面连接进行传输。接入网设备作为交换机以有线的方式与固网网关设备进行数据传输。则终端设备可通过接入网设备与固网网关设备建立连接,即如图8示意,终端设备与固网网关设备按照PPPoE或IPoE协议通信,接入网设备起转发作用,能够将来自终端设备的数据转发至固网网关设备,也能够将来自固网网关设备的数据转发至终端设备,接入网设备也可以理解为终端设备和固网网关设备之间的桥梁。另外需要说明的是,由于无需与核心网进行交互,本方案一中的终端设备无需支持核心网相关的协议层,如非接入(non-access stratum,NAS)层。接入网设备可以完全支持3GPP协议栈,也可以支持部分3GPP协议栈,例如接入网设备可支持PHY层,MAC层,RLC层,PDCP层,SDAP层,RRC层中的部分或全部协议栈。
以下对于在接入网络过程中,执行终端设备的鉴权和/或认证的不同实施方式进行详细说明。
方式一:接入网设备获取用于终端设备鉴权和认证的信息,执行终端设备的鉴权和认证。
参见图9示意一种通信方法,主要包括如下流程。
S901,接入网设备获取第一信息,所述接入网设备支持3GPP接入技术。其中,接入网设备支持3GPP接入技术,可以包括接入网设备支持4G/5G等无线网络的空口传输。
所述第一信息可以是预配置于所述接入网设备中的信息或者所述第一信息是从接入网设备连接的至少一个固网网关设备获取的;其中,第一信息包括至少一个终端设备对应的签约数据信息,所述签约数据信息用于确定终端设备允许通过固网网关设备获取业务,或者所述签约数据信息用于确定终端设备不允许通过固网网关设备获取固网业务。签约数据信息可以包括固网业务信息、服务质量(quality of service,QoS)信息、优先级信息中的一个或多个,所述QoS信息和/或优先级信息可作为后续给终端设备配置用户面资源时 的依据。
此外,第一信息还可以包括前述至少一个终端设备的安全上下文信息以及标识集合;其中,安全上下文信息用于建立接入网设备与终端设备的安全连接,安全上下文信息可以具体包括根密钥、公钥、私钥、证书等用于建立安全连接的信息中的一个或多个。建立安全连接可以包括鉴权流程或者密钥协商等流程。标识集合可以包括第一序列集合以及第二序列集合。可以理解,第一序列集合包括当前用于指示终端设备的安全上下文信息的至少一个序列号,第二序列集合包括当前未被用于指示终端设备的安全上下文信息的多个序列号。第一序列集合/第二序列集合中的序列号是可以动态变化的。例如完成一次鉴权流程后,可从第二序列集合中选取出一个序列号,如记为序列号A;将该鉴权流程涉及的安全上下文信息当前对应的序列号(如记为序列号B)更换成前述被选取的序列号A。即将该选取的序列号A并入到第一序列集合中,而第一序列集合中原有的序列号B剔除,可选的,还可以将序列号B并入到第二序列集合中以备后续再次使用。
S902,所述接入网设备获取来自第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息。
其中,第一终端设备可以是S901中提及的至少一个终端设备中的任意一个终端设备。可选的,第四信息包括第一终端设备的安全上下文信息对应的第一序列号。可选的,第一序列号可以是第一终端设备对应的终端标识,或者安全上下文标识。
第四信息还可以包括第一终端设备支持的固网网关设备所对应固网网络的标识信息,固网网络的标识信息可以包括固网网络标识和/或固网服务提供商标识。例如第一终端设备支持的固网网关设备为第一固网网关设备,即第一固网网关设备可以为第一终端设备提供固网业务,第四信息包括第一固网网关设备所对应固网网络的标识信息。第一固网网关设备可以包括于接入网设备连接的至少一个固网网关设备中。
在接入网设备获取第四信息之前,第一终端设备还可以按照前述两种选网方法中的任意一种完成选网。可以理解第一终端设备选择了S902中所描述的接入网设备,第一终端设备与该接入网设备建立控制面连接。则接入网设备可通过接入网设备与第一终端设备之间的控制面连接,接收第一终端设备发送的第四信息。
示例性的,图9中在S902中示意出如下过程:第一终端设备完成选网,与接入网设备建立控制面连接,接入网设备通过控制面连接,接收来自第一终端设备的第四信息。
S903,接入网设备根据所述第四信息,建立接入网设备与第一终端设备的安全连接。
所述接入网设备可获取至少一个终端设备的安全上下文信息和标识集合。例如前述S901介绍的第一信息,接入网设备可从第一信息中获取至少一个终端设备的安全上下文信息和标识集合;进而接入网设备确定标识集合中的第一序列号集合包括第一序列号,则所述接入网设备可根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取所述第一终端设备的安全上下文信息,并采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接。如接入网设备可根据第一序列号对应的安全上下文信息与第一终端设备进行相互鉴权,以确定接入网设备与第一终端设备对于对方来说均是可信任的设备。
在接入网设备与第一终端设备的安全连接建立后,接入网设备还可以将所述第一序列号替换为所述第二序列号集合中的第二序列号,并向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。或者可以理解,在接 入网设备与第一终端设备的安全连接建立后,第一终端设备中所存储的用于指示第一终端设备的安全上下文信息的序列号,由原来的第一序列号更新为第二序列号。另外需要说明的是,关于第一序列号替换为第二序列号的实施时间(或称,实施阶段),可以是紧跟S903执行,如在S903之后在S904之前将第一序列号替换为第二序列号;或者,也可以在第一终端设备接入固网网络之后再将第一序列号替换为第二序列号。本申请实施例对于将第一序列号替换为第二序列号的操作,并不限制操作具体的实施时间。作为示例,图9中在S911之后的S912~S914示意出了将第一序列号替换为第二序列号的操作。
S904,所述接入网设备根据所述第一信息与第一终端设备建立用户面连接。
具体地,接入网设备根据第一终端设备的签约数据信息,确定第一终端设备是否允许通过所述第一固网网关设备获取业务。若确定第一终端设备允许通过第一固网网关设备获取业务,则接入网设备根据第一终端设备所对应的签约数据信息中的固网业务信息、优先级信息、QoS信息等,与第一终端设备建立用户面连接也即建立用户面资源如数据无线承载(data radio bearer,DRB),并继续执行S904之后的流程。若确定第一终端设备不允许通过第一固网网关设备获取固网业务,则可以不再执行S904之后的流程,或者也可以继续执行S904之后的流程。
此外,针对上述第一终端设备允许通过第一固网网关设备获取业务,可以理解为第一终端设备拥有获取权限,第一终端设备能够通过第一固网网关设备获取业务;或者说,第一终端设备开通需通过第一固网网关设备获取的业务。针对上述第一终端设备不允许通过第一固网网关设备获取业务,可以理解为第一终端设备没有获取权限,第一终端设备不能通过第一固网网关设备获取业务;或者说,第一终端设备未开通需通过第一固网网关设备获取的业务。
S905,所述接入网设备向第一固网网关设备发送第二信息,所述第二信息用于请求管理第一终端设备与第一固网网关设备之间的连接。其中,管理包括建立、修改、释放或者删除等。一种可选的实施方式中,若第一终端设备与第一固网网关设备之间需通过IPoE协议进行通信,接入网设备可获取来自第一终端设备的DHCP发现(DHCP Discover)消息。若确定第一终端设备允许通过第一固网网关设备获取业务,则接入网设备在该第一终端设备发送的DHCP Discover消息中添加可接入标识,可接入标识用于指示第一终端设备允许通过第一固网网关设备获取业务。若确定第一终端设备不支持第一固网网关设备提供的固网业务,则接入网设备在该第一终端设备发送的DHCP Discover消息中添加不可接入标识,不可接入标识用于指示第一终端设备不允许通过第一固网网关设备获取业务。可选的,第一终端设备可通过第一终端设备与接入网设备之间的控制面连接,向接入网设备发送DHCP Discover消息;或者,第一终端设备也可以通过第一终端设备与接入网设备之间的用户面连接,向接入网设备发送DHCP Discover消息,此处不做限定。
另一种可选的实施方式中,若第一终端设备与第一固网网关设备之间需通过PPPoE协议进行通信,接入网设备可获取来自第一终端设备的PPPoE主动发现启动(PPPoE active discovery initiation,PADI)消息,若确定第一终端设备允许通过第一固网网关设备获取业务,则接入网设备在该第一终端设备发送的PADI消息中添加可接入标识,可接入标识用于指示第一终端设备允许通过第一固网网关设备获取业务。若确定第一终端设备不允许通过第一固网网关设备获取业务,则接入网设备在该第一终端设备发送的PADI消息中添加不可接入标识,不可接入标识用于指示第一终端设备不允许通过第一固网网关设备获取业 务。可选的,第一终端设备还可通过第一终端设备与接入网设备之间的控制面连接,向接入网设备发送PADI消息;或者,第一终端设备也可以通过第一终端设备与接入网设备之间的用户面连接,向接入网设备发送PADI消息。关于可接入标识以及不可接入标识:一种可选的实施方式中,前述S901中接入网设备获取的第一信息还可以包括可接入标识集合以及不可接入标识集合。接入网设备可从前述可接入标识集合中选取一个可接入标识添加在DHCP Discover消息或者PADI消息中,以生成前述第二信息。可以理解,第二信息指的是添加了可接入标识的DHCP Discover消息或者是添加了可接入标识的PADI消息。示例性的,可接入标识或者不可接入标识,具体可以采用Line ID表示,如可接入标识集合中可以包括一个或多个可接入的Line ID,不可接入标识集合可以包括一个或多个不可接入的Line ID。即本方式一中的Line ID用于指示终端设备是否支持固网网关设备支持的固网业务。另一种可选的实施方式中,可接入标识与不可接入标识的取值不同,例如可接入标识取值为“1”,不可接入标识取值为“0”;或者,可接入标识取值为“0”,不可接入标识取值为“1”。
示例性的,图9以第一终端设备与第一固网网关设备之间需通过IPoE协议进行通信为例,示意出了S905包括:第一终端设备向接入网设备发送DHCP发现消息;接入网设备在第一终端设备发送的DHCP发现消息中添加可接入标识,即生成第二信息;接入网设备将添加了可接入标识的DHCP发现消息发送至第一固网网关设备。
S906,第一固网网关设备将接收到的DHCP发现消息发送给DHCP服务器。
S907,DHCP服务器向AAA服务器发送接入请求(access request)消息,该接入请求消息中携带DHCP发现消息中的可接入标识或不可接入标识,以使AAA服务器根据前述可接入标识或不可接入标识,确定第一终端设备是否可以接入第一固网网关对应的固网网络,或者可以理解为:AAA服务器根据前述可接入标识或不可接入标识,在前述接入网设备鉴权或认证的基础上对第一终端设备进一步认证,确定第一终端设备是否可以通过认证。
S908,若AAA服务器获取的是可接入标识,则AAA服务器可以向DHCP服务器发送接入接受(access accept)消息;若AAA服务器获取的是不可接入标识,则AAA服务器可以向DHCP服务器发送接入拒绝(access deny)消息。
示例性的,图9中示意出了AAA服务器向DHCP服务器发送接入接受消息的情况。
S909,若DHCP服务器接收的是接入接受(access accept)消息,则DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP响应(DHCP Offer)消息;若DHCP服务器接收的是接入拒绝(access deny)消息,则DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP NACK消息。
可以理解,DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP响应(DHCP Offer)消息。
示例性的,图9中示意出了DHCP服务器通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP响应消息的情况。具体的包括:DHCP服务器向第一固网网关设备发送DHCP响应消息,第一固网网关设备向接入网设备转发DHCP响应消息,接入网设备向第一终端设备转发DHCP响应消息。
S910,第一终端设备可以通过接入网设备以及第一固网网关设备,向DHCP服务器发送DHCP请求(DHCP Request)消息。
S911,DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发 送DHCP ACK消息,该DHCP ACK消息用于指示第一终端设备与第一固网网关设备之间的连接成功建立。具体地,DHCP服务器向第一固网网关设备发送DHCP ACK消息,第一固网网关设备向接入网设备转发DHCP ACK消息,接入网设备向第一终端设备转发DHCP ACK消息。接入网设备接收到DHCP ACK消息,则可确定第一终端设备与第一固网网关设备之间的连接成功建立,若接入网设备未收到DHCP ACK消息则可视为第一终端设备与第一固网网关设备之间的连接未成功建立。S912,接入网设备将第一序列号替换为所述第二序列号集合中的第二序列号。
S913,接入网设备向第一终端设备发送更新指示信息,该更新指示信息用于指示第一终端设备对其安全上下文信息对应的序列号进行更新。该更新指示信息可以包括第二序列号。进一步的,该更新指示信息还可以包括S902中提及的第一终端设备支持的固网网关设备所对应固网网络的标识信息。此外,该更新指示信息也可以理解为用于指示第一终端设备更新第四信息。
S914,第一终端设备响应于更新指示信息,向接入网设备发送更新响应信息,该更新响应信息用于指示第一终端设备成功接收更新指示信息。
此外需要说明的是,若第一终端设备与第一固网网关设备之间需通过PPPoE协议进行通信,上述S906中第一终端设备发送的DHCP发现消息可以替换成PADI消息。后续的S907~S911也可以基于PPPoE通信流程如前述S42~S48进行相应的调整,本申请实施例对此不再进行赘述。根据实际需求可以选择性的执行上述方式一涉及的流程S901~S911中的部分或全部,即应当理解,上述流程S901~S911中的部分流程可视为可选流程,可以执行或者不执行,本申请实施例对此并不进行限制。示例性的,如对于一些无需执行终端设备鉴权的场景,可以在执行完S901后就执行S904,而不执行S902~S903或称省略S902~S904。本申请实施例对流程S901~S914的执行顺序并不进行限制,根据实际情况可以调换其中部分流程的执行顺序,或者并列执行。
进一步,参见图10,关于第一终端设备的数据传输,可参照如下方式实施:
S1001,第一终端设备通过用户面连接向接入网设备发送用户面数据,接入网设备将来自第一终端设备的用户面数据发送给第一固网网关设备,进而第一固网网关设备再将该用户面数据发送给应用服务器。其中,第一终端设备发送的用户面数据也可以理解为上行数据。第一终端设备发送的用户面数据可以是该第一终端设备自身的用户面数据,也可以是第一终端设备覆盖范围内,使用该第一终端设备提供无线局域网通信能力的其他终端设备的用户面数据。
S1002,应用服务器向第一固网网关设备发送第一终端设备的用户面数据,第一固网网关设备将从AAA接收的该用户面数据发送给接入网设备,进而接入网设备将来自第一固网设备的用户面数据通过用户面连接发送给第一终端设备。其中,来自应用服务器的用户面数据也可以理解为下行数据。
需要说明的是,本申请实施例并不限定S1001和S1002的执行顺序,可以先执行S1001,后执行S1002;也可以先执行S1002,后执行S1001。
本申请实施例提供的方式一,可简化终端设备的接入流程,能够节省信令开销降低成本。且执行终端设备的鉴权与认证,能够确保建立安全传输。
方式二:接入网设备根据用于终端设备鉴权的信息,执行终端设备的鉴权,固网网关 设备执行终端设备的认证。
参见图11示意一种通信方法,主要包括如下流程。
S1101,接入网设备获取至少一个终端设备的安全上下文信息以及标识集合,所述接入网设备支持3GPP接入技术。可以理解,接入网设备支持3GPP接入技术,可以包括接入网设备支持4G/5G等空口传输技术。
具体地,前述至少一个终端设备的安全上下文信息以及标识集合可以是预配置在接入网设备中的,也可以是来自至少一个固网网关设备的。
安全上下文信息用于建立接入网设备与终端设备的安全连接,安全上下文信息可以具体包括根密钥、公钥、私钥、证书等用于建立安全连接的信息中的一个或多个。建立安全连接可以包括鉴权流程或者密钥协商等流程。标识集合可以包括第一序列集合以及第二序列集合。可以理解,第一序列集合包括当前用于指示终端设备的安全上下文信息的至少一个序列号,第二序列集合包括当前未被用于指示终端设备的安全上下文信息的多个序列号。第一序列集合/第二序列集合中的序列号是可以动态变化的。例如完成一次鉴权流程后,可从第二序列集合中选取出一个序列号,如记为序列号A;将该鉴权流程涉及的安全上下文信息当前对应的序列号(如记为序列号B)更换成前述被选取的序列号A。即将该选取的序列号A并入到第一序列集合中,而第一序列集合中原有的序列号B剔除,可选的,还可以将序列号B并入到第二序列集合中以备后续再次使用。
S1102,所述接入网设备获取来自第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息。
其中,第一终端设备可以是S1101中提及的至少一个终端设备中的任意一个终端设备。可选的,第四信息包括第一终端设备的安全上下文信息对应的第一序列号。可选的,第一序列号可以是第一终端设备对应的终端标识,或者安全上下文标识。
第四信息还可以包括第一终端设备支持的固网网关设备所对应固网网络的标识信息,固网网络的标识信息可以包括固网网络标识和/或固网服务提供商标识。例如第一终端设备支持的固网网关设备为第一固网网关设备,即第一固网网关设备可以为第一终端设备提供固网业务,第四信息包括第一固网网关设备所对应固网网络的标识信息。第一固网网关设备可以包括于接入网设备连接的至少一个固网网关设备中。
第一终端设备在接入网设备获取第四信息之前,还可以按照前述两种选网方法中的任意一种完成选网。可以理解第一终端设备选择了S1102中所描述的接入网设备,第一终端设备与该接入网设备建立控制面连接。则接入网设备可通过接入网设备与第一终端设备之间的控制面连接,接收第一终端设备发送的第四信息。此外在选网过程中,若终端设备采用隐式上报类型的方式,接入网设备可基于终端设备与接入网设备之间的交互判断第一终端设备的类型。或者,若终端设备采用显式上报类型的方式,如发送第一信息给接入网设备;其中,该第一信息可指示所述第一终端设备的类型为所述目标类型,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个,还可以包括手机、AR/VR终端、Pad、以及其他类型终端,本申请实施例对此并不进行限制。那么接入网设备也可通过获取来自终端设备的第一信息来判断第一终端设备的类型。
示例性的,图11中在S1102中示意出如下过程:第一终端设备完成选网,与接入网设备建立控制面连接,接入网设备通过控制面连接,接收来自第一终端设备的第四信息。
S1103,接入网设备根据所述第四信息,建立接入网设备与第一终端设备的安全连接。
具体地,所述接入网设备可获取至少一个终端设备的安全上下文信息和标识集合。例如前述S1101介绍的第一信息,接入网设备可从第一信息中获取至少一个终端设备的安全上下文信息和标识集合;进而接入网设备确定标识集合中的第一序列号集合包括第一序列号,则所述接入网设备可根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取第一终端设备的安全上文信息,并采用第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接。如接入网设备可根据第一序列号对应的安全上下文信息与第一终端设备进行互相鉴权,以确定接入网设备与第一终端设备对于对方来说均是可信任的设备。
建立所述接入网设备与所述第一终端设备的安全连接,接入网设备还可将所述第一序列号替换为所述第二序列号集合中的第二序列号,并向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。或者可以理解,在接入网设备与第一终端设备的安全连接建立后,第一终端设备中所存储的用于指示第一终端设备的安全上下文信息的序列号,由原来的第一序列号更新为第二序列号。另外需要说明的是,关于第一序列号替换为第二序列号的实施时间(或称,实施阶段),可以是紧跟S1103执行,如在S1103之后在S1104之前将第一序列号替换为第二序列号;或者,也可以在第一终端设备接入固网网络之后再将第一序列号替换为第二序列号。本申请实施例对于将第一序列号替换为第二序列号的操作,并不限制操作具体的实施时间。作为示例,图11中在S1111之后的S1112~S1114示意出了将第一序列号替换为第二序列号的操作。
S1104,所述接入网设备与第一终端设备建立用户面连接。
可以理解,此流程S1104中所建立接入网设备用户面连接,对应建立的是临时的用户面资源,该临时的用户面资源可用于承载S1105中第一终端设备向接入网设备发送的DHCP发现消息或PADI消息。可选的,S1104可以作为一个可选流程。可以被省略,即执行S1103之后直接执行S1105。
S1105,所述接入网设备向第一固网网关设备发送第二信息,所述第二信息用于请求管理第一终端设备与第一固网网关设备之间的连接。其中,管理包括建立、修改、释放或删除等。
一种可选的实施方式中,若第一终端设备与第一固网网关设备之间需通过IPoE协议进行通信,接入网设备可获取来自第一终端设备的DHCP发现(DHCP Discover)消息。接入网设备在该第一终端设备发送的DHCP Discover消息中添加第一终端设备的标识信息,该第一终端设备的标识信息可以根据第一终端设备的MAC地址或者前述第一序列号确定,例如第一终端设备的标识信息可以是第一序列号或线路标识(Line ID);或者,该第一终端设备的标识信息可以根据第一终端设备的位置确定,如本方式二中可采用Line ID作为第一终端设备的标识信息,用于指示第一终端设备的位置。可选的,第一终端设备可通过第一终端设备与接入网设备之间的控制面连接,向接入网设备发送DHCP Discover消息;或者,在执行S1104也即建立了用户面连接的情况下,第一终端设备也可以通过第一终端设备与接入网设备之间的用户面连接,向接入网设备发送DHCP Discover消息。
另一种可选的实施方式中,若第一终端设备与第一固网网关设备之间需通过PPPoE协议进行通信,接入网设备可获取来自第一终端设备的PPPoE主动发现启动(PPPoE active discovery initiation,PADI)消息。接入网设备在该第一终端设备发送的PADI消息中添加该第一终端设备的标识信息可以根据第一终端设备的MAC地址或者前述第一序列号确定, 例如第一终端设备的标识信息可以是第一序列号或者线路标识(Line ID);或者,该第一终端设备的标识信息可以根据第一终端设备的位置确定,如本方式二中可采用Line ID作为第一终端设备的标识信息,用于指示第一终端设备的位置。可选的,第一终端设备可通过第一终端设备与接入网设备之间的控制面连接,向接入网设备发送PADI消息;或者,在执行S1104也即建立了用户面连接的情况下,第一终端设备也可以通过第一终端设备与接入网设备之间的用户面连接,向接入网设备发送PADI消息。示例性的,图11以第一终端设备与第一固网网关设备之间需通过IPoE协议进行通信为例,示意出了S1105包括:第一终端设备向接入网设备发送DHCP发现消息;接入网设备在第一终端设备发送的DHCP发现消息中添加第一终端设备的标识信息,即生成第二信息;接入网设备将添加了第一终端设备的标识信息的DHCP发现消息发送至第一固网网关设备。
S1106,第一固网网关设备将接收到的DHCP发现消息发送给DHCP服务器。
S1107,DHCP服务器向AAA服务器发送接入请求(access request)消息。该接入请求消息中携带第一终端设备的标识信息。
AAA服务器可以根据第一终端设备的标识信息,确定第一终端设备对应的签约数据信息,该签约数据信息用于确定第一终端设备允许通过第一固网网关设备获取业务,或者签约数据信息用于确定第一终端设备不允许通过第一固网网关设备获取业务。签约数据信息可以包括固网业务信息、QoS信息、优先级信息中的一个或多个,所述QoS信息和/或优先级信息可作为后续对此前第一终端设备配置的临时用户面资源进行调整时的依据。进而,AAA服务器可根据第一终端设备对应的签约数据信息,确定第一终端设备是否允许通过第一固网网关设备获取业务,或称确定第一终端设备是否通过认证。
其中,针对上述第一终端设备允许通过第一固网网关设备获取业务,可以理解为第一终端设备拥有获取权限,第一终端设备能够通过第一固网网关设备获取业务;或者说,第一终端设备开通需通过第一固网网关设备获取的业务。针对上述第一终端设备不允许通过第一固网网关设备获取业务,可以理解为第一终端设备没有获取权限,第一终端设备不能通过第一固网网关设备获取业务;或者说,第一终端设备未开通需通过第一固网网关设备获取的业务。
S1108,若AAA服务器确定第一终端设备通过认证时,则AAA服务器可以向DHCP服务器发送接入接受(access accept)消息;若AAA服务器确定第一终端设备未通过认证时,则AAA服务器可以向DHCP服务器发送接入拒绝(access deny)消息。
示例性的,图11中示意出了AAA服务器向DHCP服务器发送接入接受消息的情况。
S1109,若DHCP服务器接收的是接入接受(access accept)消息,则DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP响应(DHCP Offer)消息;若DHCP服务器接收的是接入拒绝(access deny)消息,则DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP NACK消息。
可以理解,DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP响应(DHCP Offer)消息。
示例性的,图11中示意出了DHCP服务器通过第一固网网关设备以及接入网设备,向第一终端设备发送DHCP响应消息的情况。具体的包括:DHCP服务器向第一固网网关设备发送DHCP响应消息,第一固网网关设备向接入网设备转发DHCP响应消息,接入网设备向第一终端设备转发DHCP响应消息。
S1110,第一终端设备可以通过接入网设备以及第一固网网关设备,向DHCP服务器发送DHCP请求(DHCP Request)消息。
S1111,DHCP服务器可以通过第一固网网关设备以及接入网设备,向第一终端设备发送第三信息,该第三信息用于指示第一终端设备与第一固网网关设备之间的连接成功建立。
具体的,DHCP服务器向第一固网网关设备发送第三信息,第一固网网关设备向接入网设备转发第三信息,接入网设备向第一终端设备转发第三信息。接入网设备接收到第三信息,则可确定第一终端设备与第一固网网关设备之间的连接成功建立,若接入网设备未收到第三信息则可视为第一终端设备与第一固网网关设备之间的连接未成功建立。
可选的,如图11中的S1111示意,第三信息具体可采用DHCP ACK消息实现。
前述第三信息还可以包括如下至少一个:第一终端设备的标识信息;所述第一终端设备的认证信息,所述认证信息用于指示所述第一终端设备通过所述第一固网网关设备对应的固网网络的认证,或者所述认证信息用于指示所述第一终端设备未通过所述第一固网网关设备对应的固网网络的认证;所述第一终端设备对应的签约数据信息,所述签约数据信息包括固网业务信息、QoS信息、优先级信息中的一个或多个。示例性的,第三信息采用DHCP ACK消息实现时,DHCP ACK消息可以包括第一终端设备的签约数据信息以及第一终端设备的认证信息,该DHCP ACK消息包括的认证信息用于指示所述第一终端设备通过所述第一固网网关设备对应的固网网络的认证;或者,采用DHCP ACK消息指示所述第一终端设备通过,所述第一固网网关设备对应的固网网络的认证DHCP ACK消息可以只包括第一终端设备的签约数据信息。
进而,接入网设备可根据所述第三信息,执行用户面连接管理流程。其中,所述用户面管理流程包括以下至少一个操作:保留用户面资源、建立用户面资源、修改用户面资源或者释放用户面资源。
示例性的,关于保留用户面资源:接入网设备可以根据第一终端设备对应的签约数据信息,保留临时用户面资源,不对其进行调整。关于建立用户面资源:接入网设备可以根据第一终端设备对应的签约数据信息,在前述临时用户面资源的基础上新增用户面资源。关于修改用户面资源:接入网设备可以根据第一终端设备对应的签约数据信息,在前述临时用户面资源的基础上修改用户面资源。关于释放用户面资源:接入网设备可以在收到如DHCP NACK消息时,可释放前述临时用户面资源。
S1112,接入网设备将第一序列号替换为所述第二序列号集合中的第二序列号。
S1113,接入网设备向第一终端设备发送更新指示信息,该更新指示信息用于指示第一终端设备对其安全上下文信息对应的序列号进行更新。
可选的,该更新指示信息可以包括第二序列号。进一步的,该更新指示信息还可以包括S1102中提及的第一终端设备支持的固网网关设备所对应固网网络的标识信息。此外,该更新指示信息也可以理解为用于指示第一终端设备更新第四信息。
S1114,第一终端设备响应于更新指示信息,向接入网设备发送更新响应信息,该更新响应信息用于指示第一终端设备成功接收更新指示信息。
此外需要说明的是,若第一终端设备与第一固网网关设备之间需通过PPPoE协议进行通信,上述S1105中第一终端设备发送的DHCP发现消息可以替换成PADI消息。后续的S1107~S1111也可以基于PPPoE通信流程如前述S42~S48进行相应的调整,本申请实施例对此不再进行赘述。根据实际需求可以选择性的执行上述方式一涉及的流程S1101~S1111 中的部分或全部,即应当理解,上述流程S1101~S1111中的部分流程可视为可选流程,可以执行或者不执行,本申请实施例对此并不进行限制。示例性的,如对于一些无需执行终端设备鉴权的场景,可以在执行完S1101后就执行S1104,而不执行S1102~S1103或称省略S1102~S1104。本申请实施例对流程S1101~S1114的执行顺序并不进行限制,根据实际情况可以调换其中部分流程的执行顺序,或者并列执行。
进一步,关于第一终端设备的数据传输,可参照图10中的方式实施,本申请实施例对此不再进行赘述。
本申请实施例提供的方式二,可简化终端设备的接入流程,能够节省信令开销降低成本。由接入网设备执行终端设备的鉴权流程,通过鉴权后,接入网设备可与终端设备建立临时用户面资源,以用于转发终端设备希望建立IPoE或PPPoE连接的相关消息。通过在DHCP ACK消息中包含终端设备的签约数据信息,使得接入网设备能根据该签约数据信息,具有针对性地建立或修改终端设备的用户面资源,可以做到不同终端设备之间的差异化处理,能够提升用户体验。
方式三:固网网关设备执行终端设备的认证,并向接入网设备发送认证信息,接入网设备根据认证信息与终端设备建立安全连接(认证通过时)或者释放空口资源(认证失败时)。
参见图12示意一种通信方法,主要包括如下流程。
S1201,第一终端设备完成网络选择,与接入网设备建立控制面连接。
第一终端设备可按照前述两种选网方法中的任意一种完成网络选择。可以理解第一终端设备选择了图12中所描述的接入网设备以及第一固网网关设备对应的固网网络,第一终端设备与该接入网设备建立控制面连接。
在选网过程中,若终端设备采用隐式上报类型的方式,接入网设备可基于终端设备与接入网设备之间的交互判断第一终端设备的类型。或者,若终端设备采用显式上报类型的方式,如发送第一信息给接入网设备;其中,该第一信息可指示所述第一终端设备的类型为所述目标类型,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个,还可以包括手机、AR/VR终端、Pad、以及其他类型终端,本申请实施例对此并不进行限制。那么接入网设备也可通过获取来自终端设备的第一信息来判断第一终端设备的类型。
S1202,所述接入网设备与第一终端设备建立用户面连接。
可以理解,此流程S1204中所建立接入网设备用户面连接,对应建立的是临时的用户面资源,该临时的用户面资源可用于承载S1203中第一终端设备向接入网设备发送的DHCP发现消息或PADI消息。其中S1202可以作为一个可选流程。可以被省略,即执行S1201之后直接执行S1203。
S1203,所述接入网设备向第一固网网关设备发送第二信息,所述第二信息用于请求管理第一终端设备与第一固网网关设备之间的连接。其中,管理包括建立,修改、释放或删除等。
一种可选的实施方式中,若第一终端设备与第一固网网关设备之间需通过IPoE协议进行通信,接入网设备可获取来自第一终端设备的DHCP发现(DHCP Discover)消息。接入网设备在该第一终端设备发送的DHCP Discover消息中添加第一终端设备的标识信息,该第一终端设备的标识信息可以根据第一终端设备的MAC地址或者第一终端设备的 C-RNTI确定,C-RNTI指的是接入网设备标记第一终端设备所用的标识;或者,该第一终端设备的标识信息可以根据第一终端设备的位置确定,如本方式三中可采用Line ID作为第一终端设备的标识信息,用于指示第一终端设备的位置。可选的,第一终端设备可通过第一终端设备与接入网设备之间的控制面连接,向接入网设备发送DHCP Discover消息;或者,在执行S1202也即建立了用户面连接的情况下,第一终端设备也可以通过第一终端设备与接入网设备之间的用户面连接,向接入网设备发送DHCP Discover消息。
另一种可选的实施方式中,若第一终端设备与第一固网网关设备之间需通过PPPoE协议进行通信,接入网设备可获取来自第一终端设备的PPPoE主动发现启动(PPPoE active discovery initiation,PADI)消息。接入网设备在该第一终端设备发送的PADI消息中添加该第一终端设备的标识信息可以根据第一终端设备的MAC地址或者第一终端设备的C-RNTI确定,C-RNTI指的是接入网设备标记第一终端设备所用的标识;或者,该第一终端设备的标识信息可以根据第一终端设备的位置确定,如本方式三中可采用Line ID作为第一终端设备的标识信息,用于指示第一终端设备的位置。可选的,第一终端设备可通过第一终端设备与接入网设备之间的控制面连接,向接入网设备发送PADI消息;或者,在执行S1202也即建立了用户面连接的情况下,第一终端设备也可以通过第一终端设备与接入网设备之间的用户面连接,向接入网设备发送PADI消息。
示例性的,图12以第一终端设备与第一固网网关设备之间需通过PPPoE协议进行通信为例,示意出了S1203包括:第一终端设备向接入网设备发送PADI消息;接入网设备在第一终端设备发送的PADI消息中添加第一终端设备的标识信息,即生成第二信息;接入网设备将添加了第一终端设备的标识信息的PADI消息发送至第一固网网关设备。
S1204,第一固网网关设备在接收到PADI消息后,通过接入网设备向第一终端设备发送PPPoE主动发现回应(PPPoE Active Discovery Offer,PADO)消息来进行回应作为响应。
S1205,第一终端设备通过接入网设备向第一固网网关设备发送PPPoE主动发现请求(PPPoE Active Discovery Request,PADR)消息。
S1206,第一固网网关设备在接收到PADR消息后,通过接入网设备向第一终端设备发送PPPoE主动发现会话配置(PPPoE Active Discovery Session-confirmation,PADS)消息作为响应。
S1207,第一终端设备、第一固网网关设备、AAA服务器交互完成挑战握手认证协议(Challenge Handshake Authentication Protocol,CHAP)认证。其中,第一固网网关设备会转发第一终端设备与AAA服务器之间认证的消息,该认证方式可以是通过用户名密码的方式认证,且消息传递是密文方式传输,较为安全。
S1208,第一终端设备和第一固网网关设备进行网络侧参数(Network Control Protocol,NCP)协商阶段,涉及第一固网网关设备与DHCP之间的交互,第一终端设备可在此阶段获取IP地址。
S1209,第一固网网关设备获知第一终端设备通过认证,则通过第一固网网关设备与接入网设备的接口向接入网设备发送第三信息,该第三信息用于指示第一终端设备与第一固网网关设备之间的连接成功建立。
可选的,前述第三信息可以包括如下信息中的一项或多项:所述第一终端设备的标识信息;所述第一终端设备的安全上下文信息;所述第一终端设备的认证信息,所述认证信息用于指示所述第一终端设备是否通过所述第一固网网关设备对应的固网网络的认证,或 称所述认证信息用于指示所述第一终端设备是否通过所述第一固网网关设备关联的AAA服务器的认证;所述第一终端设备对应的签约数据信息,所述签约数据信息包括固网业务信息、QoS信息、优先级信息中的一个或多个;所述第一终端设备的安全上下文信息,所述安全上下文信息用于建立所述接入网设备与所述第一终端设备的安全连接,安全上下文信息可以具体包括根密钥、公钥、私钥、证书等用于建立安全连接的信息中的一个或多个,建立安全连接可以包括鉴权流程或者密钥协商等流程。
S1210,接入网设备可根据所述第一终端设备的标识信息,识别第一终端设备,并在第一终端设备的认证信息指示其通过AAA服务器的认证时,采用第三信息中的第一终端设备的安全上下文信息,建立接入网设备与第一终端设备的安全连接,如接入网设备采用第一终端设备的安全上下文信息与第一终端设备相互鉴权。若第一终端设备的认证信息指示其未通过AAA服务器的认证,则接入网设备无需与第一终端设备相互鉴权。
作为示例,图12中示意出了第一终端设备的认证信息指示其通过AAA服务器的认证的情况。
S1211,接入网设备可以根据第三信息,执行用户面连接管理流程。其中,所述用户面管理流程包括以下至少一个操作:保留用户面资源、建立用户面资源、修改用户面资源或者释放用户面资源。
在第一终端设备的认证信息指示其通过AAA服务器的认证时,接入网设备可根据第一终端设备的签约数据信息,执行如下操作的一种或多种:保留用户面资源、建立用户面资源、修改用户面资源。在第一终端设备的认证信息指示其未通过AAA服务器的认证时,接入网设备可执行释放用户面资源的操作。
示例性的,关于保留用户面资源:接入网设备可以根据第一终端设备对应的签约数据信息,保留前述S1202中临时的用户面资源,不对其进行调整。关于建立用户面资源:接入网设备可以根据第一终端设备对应的签约数据信息,在前述S1202中临时的用户面资源的基础上新增用户面资源。关于修改用户面资源:接入网设备可以根据第一终端设备对应的签约数据信息,在前述临时用户面资源的基础上修改用户面资源。关于释放用户面资源:接入网设备可在确定第一终端设备未通过AAA服务器的认证时,释放前述临时用户面资源。
本申请实施例对于S1210和S1211的执行顺序并不进行限制,可以先执行S1210后执行S1211,也可以是先执行S1211后执行S1210。
此外需要说明的是,若第一终端设备与第一固网网关设备之间需通过IPoE协议进行通信,上述S1204中第一终端设备发送的PADI消息可以替换成DHCP发现消息。后续的S1205~S1211也可以基于IPoE通信流程如前述S31~S36进行相应的调整,本申请实施例对此不再进行赘述。根据实际需求可以选择性的执行上述方式一涉及的流程S1201~S1211中的部分或全部,即应当理解,上述流程S1201~S1211中的部分流程可视为可选流程,可以执行或者不执行,本申请实施例对此并不进行限制。示例性的,如对于一些无需执行终端设备鉴权的场景,可以省略S1210。本申请实施例对流程S1201~S1211的执行顺序并不进行限制,根据实际情况可以调换其中部分流程的执行顺序,或者并列执行。
进一步,关于第一终端设备的数据传输,可参照图10中的方式实施,本申请实施例对此不再进行赘述。
本申请实施例提供的方式三,可以简化终端设备的接入流程,能够节省信令开销降低 成本。终端设备与固网网关设备完成认证后,固网网关设备通过增强接口,才向接入网设备发送关于终端设备的认证结果、安全上下文信息、优先级信息、QoS信息等,能够减少前述信息的泄露,提升通信安全。进而接入网设备也能根据优先级信息、QoS信息,具有针对性地建立或修改终端设备的用户面资源,可以做到不同终端设备之间的差异化处理,能够提升用户体验。
方案二:
参见图13,本申请实施例提供另一种协议栈架构,具体示意出了控制面协议栈以及用户面协议栈。作为一种可选的实施方式,实施本方案二可以构建该协议栈架构,或者可以理解,该协议栈架构能够应用于本方案二。需要说明的是,图13为一种可能的实施方式,本方案二也可以采用其它的协议栈架构,本申请实施例对此并不进行限制。
其中,终端设备侧以及接入网设备侧的控制面协议栈分为RRC层、分组数据汇聚协议(Packet Data Convergence Protocol,PDCP)层、无线链路层控制协议(Radio Link Control,RLC)层、介质访问控制(medium access control,MAC)层、物理(physical,PHY)层。终端设备侧的用户面协议栈分为IPoE/PPPoE协议层、802.1ad协议层、服务数据适配协议(Service Data Adaptation Protocol,SDAP)层、PDCP层、RRC层、PDCP层、RLC层、MAC层、PHY层。接入网设备侧面向与终端设备通信的用户面协议栈分为IPoE/PPPoE协议层、802.1ad协议层、SDAP层、PDCP层、RRC层、PDCP层、RLC层、MAC层、PHY层。接入网设备侧面向与固网网关设备通信的用户面协议栈分为IPoE/PPPoE协议层、802.1ad协议层、MAC层、PHY层。固网网关设备侧的用户面协议栈分为IPoE/PPPoE协议层、802.1ad协议层、MAC层、PHY层。接入网设备可以完全支持3GPP协议栈,也可以支持部分3GPP协议栈,例如接入网设备可支持PHY层,MAC层,RLC层,PDCP层,SDAP层,RRC层中的部分或全部协议栈。
接入网设备支持3GPP接入技术,终端设备可与接入网设备通过3GPP技术(或称蜂窝空口)传输,如终端设备可与接入网设备建立控制面连接,控制面的消息可通过RRC信令进行传输;终端设备可与接入网设备建立用户面连接,用户面的消息可通过用户面连接进行传输。接入网设备与固网网关设备建立连接,如固网连接,如按照IPoE/PPPoE协议进行数据传输。则接入网设备能够将来自终端设备的数据发送给固网网关设备,也能够将来自固网网关设备的数据发送至终端设备,接入网设备也可以理解为终端设备和固网网关设备之间的桥梁。另外需要说明的是,由于无需与核心网进行交互,本方案一中的终端设备无需支持核心网相关的协议层,如非接入(non-access stratum,NAS)层。
以下对于在接入网络过程中,执行终端设备的鉴权和/或认证的实施方式进行详细说明。
参见图14示意一种通信方法,主要包括如下流程。
S1401,接入网设备获取第一信息,所述接入网设备支持3GPP接入技术。其中,接入网设备支持3GPP接入技术,可以包括接入网设备支持4G/5G等空口传输技术。
所述第一信息可以是所述接入网设备中预先存储的信息或者所述第一信息是从接入网设备连接的至少一个固网网关设备获取的;其中,第一信息包括至少一个终端设备对应的签约数据信息,所述签约数据信息用于确定终端设备允许通过固网网关设备获取业务,或者所述签约数据信息用于确定终端设备不允许通过固网网关设备获取业务。签约数据信 息可以包括固网业务信息、QoS信息和优先级信息中的一个或多个,所述QoS信息和/或优先级信息可作为后续给终端设备配置用户面资源时的依据。
第一信息还可以包括前述至少一个终端设备的安全上下文信息以及标识集合;其中,安全上下文信息可以具体包括根密钥、公钥、私钥、证书等用于建立安全连接的信息中的一个或多个。建立安全连接可以包括鉴权流程或者密钥协商等流程。标识集合可以包括第一序列集合以及第二序列集合。可以理解,第一序列集合包括当前用于指示终端设备的安全上下文信息的至少一个序列号,第二序列集合包括当前未被用于指示终端设备的安全上下文信息的多个序列号。第一序列集合/第二序列集合中的序列号是可以动态变化的。例如完成一次鉴权流程后,可从第二序列集合中选取出一个序列号,如记为序列号A;将该鉴权流程涉及的安全上下文信息当前对应的序列号(如记为序列号B)更换成前述被选取的序列号A。即将该选取的序列号A并入到第一序列集合中,而第一序列集合中原有的序列号B剔除,可选的,还可以将序列号B并入到第二序列集合中以备后续再次使用。
此外可选的,第一信息还可以包括IP地址资源池,IP地址资源池中包括多个待分配的IP地址。
S1402,所述接入网设备向至少一个固网网关设备发送DHCP发现(DHCP Discover)消息或者PADI消息,该DHCP发现消息或者PADI消息用于请求建立接入网设备与至少一个固网网关设备之间的连接,如固网连接。
示例性的,DHCP发现消息或者PADI消息中可以携带可接入的标识,如可接入Line ID,以确保接入网设备通过认证与固网网关设备成功建立连接。示例性的,图14以接入网设备与至少一个固网网关设备中的第一固网网关设备之间需通过IPoE协议进行通信为例,示意出了S1402包括:接入网设备向第一固网网关设备发送DHCP发现消息。
S1403,第一固网网关设备将接收到的DHCP发现消息发送给DHCP服务器。
S1404,DHCP服务器向AAA服务器发送接入请求(access request)消息,该接入请求消息中携带DHCP发现消息中的可接入标识,以使AAA服务器根据前述可接入标识,确定接入网设备可以通过认证。
S1405,AAA服务器获取到可接入标识,则AAA服务器可以向DHCP服务器发送接入接受(access accept)消息。
S1406,DHCP服务器接收到接入接受(access accept)消息,则DHCP服务器可以通过第一固网网关设备向接入网设备发送DHCP响应(DHCP Offer)消息。
S1407,接入网设备通过第一固网网关设备,向DHCP服务器发送DHCP请求(DHCP Request)消息。
S1408,DHCP服务器通过第一固网网关设备,向接入网设备发送DHCP ACK消息,该DHCP ACK消息指示接入网设备与第一固网网关设备之间的连接成功建立。
S1409,接入网设备获取来自第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息。
其中,第一终端设备可以是S1401中提及的至少一个终端设备中的任意一个终端设备。可选的,第四信息包括第一终端设备的安全上下文信息对应的第一序列号。可选的,第一序列号可以是第一终端设备对应的终端标识,或者安全上下文标识。
可选的,第四信息还可以包括第一终端设备支持的固网网关设备所对应固网网络的标识信息,固网网络的标识信息可以包括固网网络标识和/或固网服务提供商标识。例如第一 终端设备支持固网网关设备为第一固网网关设备,即第一固网网关设备可以为第一终端设备提供固网业务,第四信息包括第一固网网关设备所对应固网网络的标识信息。第一固网网关设备可以包括于与接入网设备建立连接的至少一个固网网关设备中。
在接入网设备获取第四信息之前,第一终端设备还可以按照前述两种选网方法中的任意一种完成选网。可以理解第一终端设备选择了图14所描述的接入网设备,第一终端设备与该接入网设备建立控制面连接。则接入网设备可通过接入网设备与第一终端设备之间的控制面连接,接收第一终端设备发送的第四信息。
示例性的,图14中在S1409中示意出如下过程:第一终端设备完成选网,与接入网设备建立控制面连接,接入网设备通过控制面连接,接收来自第一终端设备的第四信息。
S1410,接入网设备根据所述第四信息,建立接入网设备与第一终端设备的安全连接。
具体地,所述接入网设备可获取至少一个终端设备的安全上下文信息和标识集合。例如前述S1401介绍的第一信息,接入网设备可从第一信息中获取至少一个终端设备的安全上下文信息和标识集合;进而接入网设备确定标识集合中的第一序列号集合包括第一序列号,则所述接入网设备可根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取第一终端设备的安全上文信息,并采用第一终端设备的安全上下文信息建立接入网设备与第一终端设备的安全连接。如接入网设备可根据第一序列号对应的安全上下文信息与第一终端设备进行互相鉴权,以确定接入网设备与第一终端设备对于对方来说均是可信任的设备。
在接入网设备与第一终端设备的安全连接建立后,接入网设备还可以将所述第一序列号替换为所述第二序列号集合中的第二序列号,并向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。或者可以理解,在接入网设备与第一终端设备的安全连接建立后,第一终端设备中所存储的用于指示第一终端设备的安全上下文信息的序列号,由原来的第一序列号更新为第二序列号。另外需要说明的是,关于第一序列号替换为第二序列号的实施时间(或称,实施阶段),可以是紧跟S1410执行,如在S1410之后在S1411之前将第一序列号替换为第二序列号;或者,也可以在第一终端设备接入固网网络之后再将第一序列号替换为第二序列号。本申请实施例对于将第一序列号替换为第二序列号的操作,并不限制操作具体的实施时间。作为示例,图14中在S1411之后的S1412~S1414示意出了将第一序列号替换为第二序列号的操作。
S1411,所述接入网设备根据所述第一信息与第一终端设备建立用户面连接。
可选的,接入网设备根据第一终端设备的签约数据信息,确定第一终端设备是否允许通过所述第一固网网关设备获取业务。其中,第一终端设备允许通过第一固网网关设备获取业务,可以理解为第一终端设备拥有获取权限,第一终端设备能够通过第一固网网关设备获取业务;或者说,第一终端设备开通需通过第一固网网关设备获取的业务。第一终端设备不允许通过第一固网网关设备获取业务,可以理解为第一终端设备没有获取权限,第一终端设备不能通过第一固网网关设备获取业务;或者说,第一终端设备未开通需通过第一固网网关设备获取的业务。
在接入网设备确定第一终端设备允许通过第一固网网关设备获取业务时,接入网设备根据第一终端设备所对应的签约数据信息中的优先级信息、QoS信息等,与第一终端设备建立用户面连接也即建立用户面资源如数据无线承载(data radio bearer,DRB),并基于第一信息的IP地址资源池为第一终端设备分配IP地址。
S1412,接入网设备将第一序列号替换为所述第二序列号集合中的第二序列号。
S1413,接入网设备向第一终端设备发送更新指示信息,该更新指示信息用于指示第一终端设备对其安全上下文信息对应的序列号进行更新。
可选的,该更新指示信息可以包括第二序列号。进一步的,该更新指示信息还可以包括S1410中提及的第一终端设备支持的固网网关设备所对应固网网络的标识信息。此外,该更新指示信息也可以理解为用于指示第一终端设备更新第四信息。
S1414,第一终端设备响应于更新指示信息,向接入网设备发送更新响应信息,该更新响应信息用于指示第一终端设备成功接收更新指示信息。
此外需要说明的是,若接入网设备与第一固网网关设备之间需通过PPPoE协议进行通信,上述S1402中接入网设备发送的DHCP发现消息可以替换成PADI消息。后续的S1402~S1408也可以基于PPPoE通信流程如前述S42~S48进行相应的调整,本申请实施例对此不再进行赘述。根据实际需求可以选择性的执行上述方式一涉及的流程S1401~S1414中的部分或全部,即应当理解,上述流程S1401~S1414中的部分流程可视为可选流程,可以执行或者不执行,本申请实施例对此并不进行限制。示例性的,如对于一些无需执行序列号更新替换的场景,可以不执行S1412~S1414。本申请实施例对流程S1401~S1414的执行顺序并不进行限制,根据实际情况可以调换其中部分流程的执行顺序,或者并列执行。
进一步,由于本方案二中接入网设备具有IPoE或PPPoE协议栈,接入网设备可以作为一种固网终端直接与固网网关设备通信。可选的,可以建立一条供接入网设备连着的多个终端设备所共享的连接,RAN还可以通过做网络地址转换(NAT),使得多个终端设备与接入网设备的连接能够映射到该接入网设备与固网网关设备之间的连接。下面以两个终端设备(第一终端设备、第二终端设备)连接接入网设备为例,对接入网设备在终端设备的上下行数据传输过程中做NAT的方法进行详细说明。
参见图15,示意一种终端设备的数据传输方式,主要包括如下流程。
S1501a,第一终端设备向接入网设备发送第一上行数据,该第一上行数据对应消息的源IP地址记为IP@1,端口号(port)为1。
S1501b,第二终端设备向接入网设备发送第二上行数据,该第二上行数据对应消息的源IP地址记为IP@2,端口号为1。
其中,第一终端设备所发送的第一上行数据可以是该第一终端设备自身的用户面数据,也可以是第一终端设备覆盖范围内,使用该第一终端设备提供无线局域网通信能力的其他终端设备的用户面数据。
S1502a,接入网设备将第一上行数据对应消息的源IP地址替换为IP@3,端口号(port)为2,并通过固网网关设备向应用服务器发送替换源IP地址后的第一上行数据。
其中,第二终端设备所发送的第二上行数据可以是该第二终端设备自身的用户面数据,也可以是第二终端设备覆盖范围内,使用该第二终端设备提供无线局域网通信能力的其他终端设备的用户面数据。
S1502b,接入网设备将第二上行数据对应消息的源IP地址替换为IP@3,端口号(port)为3,并通过固网网关设备向应用服务器发送替换源IP地址后的第二上行数据。
S1503,接入网设备通过固网网关设备获取来自应用服务器的下行数据,该下行数据对应消息的目的IP地址记为:IP@3,端口号为2。
S1504,接入网设备根据获取的下行数据对应消息的目的IP地址,确定该下行数据要 发往第一终端设备,则接入网设备将该下行数据对应消息的目的IP地址替换为IP@1,端口号(port)为1,并向第一终端设备发送替换目的IP地址后的下行数据。
本方案二中,接入网设备预先与固网网关设备建立连接,对于后续终端设备要建立连接,接入网设备可以直接与该终端设备建立用户面资源并分配IP地址(若建立的是PPPoE连接,则接入网设备还会分配PPPoE会话标识),即接入网设备具备NAT功能。其好处在于,接入网设备与固网网关设备之间只需建立一个或少数几个的连接,接入网设备可以直接根据终端设备的鉴权、认证结果(或签约数据)来确定是否需要与终端设备建立用户面资源并分配IP地址。
对应上述实施例,参见图16,本申请实施例提供了一种通信装置1600,该通信装置1600包括通信模块1601和处理模块1602。该通信装置1600可以是接入网设备,也可以是应用于接入网设备,能够支持接入网设备执行前述通信方法的装置。
其中,通信模块也可以称为收发模块、收发器、收发机、收发装置等。处理模块也可以称为处理器,处理单板,处理单元、处理装置等。可选的,可以将通信模块中用于实现接收功能的器件视为接收单元,应理解,通信模块用于执行上述方法实施例中接入网设备侧的发送操作和接收操作,将通信模块中用于实现发送功能的器件视为发送单元,即通信模块包括接收单元和发送单元。该通信装置1600应用于接入网设备时,其通信模块1601包括的接收单元用于执行接入网设备侧的接收操作,例如接收来自第一终端设备的第四信息;其通信模块1601包括的发送单元用于执行接入网设备侧的发送操作,例如向第一固网网关设备发送第二信息。此外需要说明的是,若该装置采用芯片/芯片电路实现,所述通信模块可以是输入输出电路和/或通信接口,执行输入操作(对应前述接收操作)、输出操作(对应前述发送操作);处理模块为集成的处理器或者微处理器或者集成电路。
以下对该通信装置1600应用于接入网设备的实施方式进行详细说明。
该通信装置1600,包括:
通信模块1601,用于获取第一信息。
处理模块1602,用于根据所述第一信息与第一终端设备建立用户面连接。
所述通信模块1601,还用于通过所述用户面连接获取所述第一终端设备的用户面数据,并向第一固网网关设备发送所述用户面数据。
本申请实施例中,采用支持3GPP接入技术的接入网设备作为终端设备与固网网关设备之间的中间节点,终端设备采用3GPP接入技术与接入网设备建立连接,接入网设备可向固网网关设备传输终端设备的数据,使得终端设备以3GPP接入的方式也能获取固网宽带业务。相较于传统固网终端以有线接入固网网络的方式可简化部署,且可以增强覆盖,提升通信系统的性能。
在一种可选的实施方式中,所述第一信息用于指示所述第一终端设备的类型为目标类型和/或用于指示所述第一终端设备允许通过所述第一固网网关设备获取业务;其中,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个,还可以包括手机、AR/VR终端、Pad、以及其他类型终端,本申请实施例对此并不进行限制。
在一种可选的实施方式中,所述第一信息来自所述第一终端设备,所述第一信息指示所述第一终端设备的类型为所述目标类型,还可以包括手机、AR/VR终端、Pad、以及其他类型终端,本申请实施例对此并不进行限制。
在一种可选的实施方式中,所述第一信息预配置于所述接入网设备中或者所述第一信息来自所述第一固网网关设备;其中,所述第一信息包括所述第一终端设备对应的签约数据信息,所述签约数据信息用于确定所述第一终端设备允许通过所述第一固网网关设备获取业务。
在一种可选的实施方式中,在所述通信模块1601通过所述用户面连接获取所述第一终端设备的用户面数据之前:
所述通信模块1601,还用于向所述第一固网网关设备发送第二信息,所述第二信息用于请求管理所述第一终端设备与所述第一固网网关设备之间的连接。
在一种可选的实施方式中,所述通信模块1601,还用于接收来自所述第一固网网关设备的第三信息,所述第三信息包括以下至少一个:所述第一终端设备的标识信息;所述第一终端设备的认证信息,所述认证信息用于指示所述第一终端设备通过所述第一固网网关设备对应的固网网络的认证;所述第一终端设备对应的签约数据信息,所述签约数据信息包括固网业务信息、QoS信息、优先级信息中的一个或多个;所述第一终端设备的安全上下文信息,所述安全上下文信息用于建立所述接入网设备与所述第一终端设备的安全连接。
在一种可选的实施方式中,所述处理模块1602,还用于根据所述第三信息,执行用户面连接管理流程;其中,所述用户面管理流程包括以下至少一个操作:建立用户面资源、修改用户面资源或者释放用户面资源。
在一种可选的实施方式中,所述接入网设备与至少一个固网网关设备之间建立连接,所述至少一个固网网关设备包括所述第一固网网关设备。
在一种可选的实施方式中,所述通信模块1601,还用于获取来自所述第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息;所述处理模块,还用于根据所述第四信息,采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接。
在一种可选的实施方式中,所述第四信息包括所述第一终端设备的安全上下文信息对应的第一序列号;所述处理模块1602,还用于:通过所述通信模块1601获取至少一个终端设备的安全上下文信息和标识集合,所述标识集合包括用于指示所述至少一个终端设备的安全上下文信息的第一序列号集合,所述第一序列号集合包括所述第一序列号;根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取所述第一终端设备的安全上下文信息;所述接入网设备采用所述第一终端设备的安全上下文信息,建立所述接入网设备与所述第一终端设备的安全连接。
在一种可选的实施方式中,所述标识集合还包括第二序列号集合;所述处理模块1602,还用于在采用所述第一终端设备安全上下文信息执行建立所述接入网设备与所述第一终端设备的安全连接之后,将所述第一序列号替换为所述第二序列号集合中的第二序列号;所述通信模块1601,还用于向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。
在一种可选的实施方式中,所述第四信息还包括所述第一固网网关设备对应的固网网络的标识信息。
在一种可选的实施方式中,所述通信模块1601,还用于:发送以下至少一个信息:所述接入网设备的能力信息,所述能力信息指示所述接入网设备支持固网传输;所述接入网设备支持的固网网络的标识信息,所述接入网设备支持的固网网络包括所述第一固网网关 设备对应的固网网络;网络优先级信息,所述网络优先级信息用于指示所述接入网设备所属的移动运营商的优先级。
在一种可选的实施方式中,所述通信模块1601,获取所述第一终端设备发送的用于指示所述第一终端设备的类型为目标类型的信息和/或所述第一终端设备请求接入的固网网络的标识信息;所述处理模块1602,还用于根据所述第一终端设备的类型和/或所述第一终端设备请求接入的固网网络的标识信息,确定所述接入网设备支持所述第一终端设备的固网传输。
本申请实施例中对模块的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,另外,在本申请各个实施例中的各功能模块可以集成在一个处理器中,也可以是单独物理存在,也可以两个或两个以上模块集成在一个模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。
基于相同的技术构思,本申请还提供了一种通信装置1700。该通信装置1700可以是芯片或者芯片系统。可选的,在本申请实施例中芯片系统可以由芯片构成,也可以包含芯片和其他分立器件。
通信装置1700可用于实现图5所示的通信系统中终端设备、接入网设备或者固网网关设备的功能。通信装置1700可以包括至少一个处理器1710,该处理器1710与存储器耦合,可选的,存储器可以位于该装置之内,存储器可以和处理器集成在一起,存储器也可以位于该装置之外。例如,通信装置1700还可以包括至少一个存储器1720。存储器1720保存实施上述任一实施例中必要计算机程序、配置信息、计算机程序或指令和/或数据;处理器1710可能执行存储器1720中存储的计算机程序,完成上述任一实施例中的方法。
本申请实施例中的耦合是装置、单元或模块之间的间接耦合或通信连接,可以是电性,机械或其它的形式,用于装置、单元或模块之间的信息交互。处理器1710可能和存储器1720协同操作。本申请实施例中不限定上述通信接口1730、处理器1710以及存储器1720之间的具体连接介质。
通信装置1700中还可以包括通信接口1730,通信装置1700可以通过通信接口1730和其它设备进行信息交互。示例性的,所述通信接口1730可以是收发器、电路、总线、模块或其它类型的通信接口。当该通信装置1700为芯片类的装置或者电路时,该装置1700中的通信接口1730也可以是输入输出电路,可以输入信息(或称,接收信息)和输出信息(或称,发送信息),处理器为集成的处理器或者微处理器或者集成电路或则逻辑电路,处理器可以根据输入信息确定输出信息。
可选的,参见图17,所述通信接口1730、所述处理器1710以及所述存储器1720之间通过总线1740相互连接。所述总线1740可以是外设部件互连标准(peripheral component interconnect,PCI)总线或扩展工业标准结构(extended industry standard architecture,EISA)总线等。所述总线可以分为地址总线、数据总线、控制总线等。为便于表示,图17中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。
在本申请实施例中,处理器可以是通用处理器、数字信号处理器、专用集成电路、现场可编程门阵列或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件,可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。
在本申请实施例中,存储器可以是非易失性存储器,比如硬盘(hard disk drive,HDD)或固态硬盘(solid-state drive,SSD)等,还可以是易失性存储器(volatile memory),例如随机存取存储器(random-access memory,RAM)。存储器是能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。本申请实施例中的存储器还可以是电路或者其它任意能够实现存储功能的装置,用于存储程序指令和/或数据。
在一种可能的实施方式中,该通信装置1700可以应用于终端设备,具体通信装置1700可以是终端设备,也可以是能够支持终端设备,实现上述涉及的任一实施例中终端设备的功能的装置。存储器1720保存实现上述任一实施例中的终端设备的功能的必要计算机程序、计算机程序或指令和/或数据。处理器1710可执行存储器1720存储的计算机程序,完成上述任一实施例中终端设备执行的方法。应用于终端设备,该通信装置1700中的通信接口可用于与网络设备进行交互,向网络设备发送信息或者接收来自网络设备的信息。
在一种可能的实施方式中,该通信装置1700可以应用于接入网设备,具体通信装置1700可以是接入网设备,也可以是能够支持接入网设备,实现上述涉及的任一实施例中接入网设备的功能的装置。存储器1720保存实现上述任一实施例中的接入网设备的功能的必要计算机程序、计算机程序或指令和/或数据。处理器1710可执行存储器1720存储的计算机程序,完成上述任一实施例中接入网设备执行的方法。应用于接入网设备,该通信装置1700中的通信接口可用于与终端设备进行交互,向终端设备发送信息或者接收来自终端设备的信息;或者,该通信装置1700中的通信接口可用于与固网网关设备进行交互,向固网网关设备发送信息或者接收来自固网网关设备的信息。
在一种可能的实施方式中,该通信装置1700可以应用于固网网关设备,具体通信装置1700可以是固网网关设备,也可以是能够支持固网网关设备,实现上述涉及的任一实施例中固网网关设备的功能的装置。存储器1720保存实现上述任一实施例中的固网网关设备的功能的必要计算机程序、计算机程序或指令和/或数据。处理器1710可执行存储器1720存储的计算机程序,完成上述任一实施例中固网网关设备执行的方法。应用于固网网关设备,该通信装置1700中的通信接口可用于与接入网设备进行交互,向接入网设备发送信息或者接收来自接入网设备的信息。
由于本实施例提供的通信装置1700可应用于终端设备,完成上述终端设备执行的方法,或者应用于网络设备,完成网络设备执行的方法。因此其所能获得的技术效果可参考上述方法实施例,在此不再赘述。
在本申请实施例中,处理器可以是通用处理器、数字信号处理器、专用集成电路、现场可编程门阵列或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件,可以实施或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。
在本申请实施例中,存储器可以是非易失性存储器,比如硬盘(hard disk drive,HDD)或固态硬盘(solid-state drive,SSD)等,还可以是易失性存储器(volatile memory),例如随机存取存储器(random-access memory,RAM)。存储器还可以是能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。本申请实施例中的存储器还可以是电路或者其它任意能够实施存储功能的装置,用于 存储计算机程序、计算机程序或指令和/或数据。
基于以上实施例,本申请实施例还提供了一种计算机程序,当所述计算机程序在计算机上运行时,使得所述计算机从终端设备侧或者网络设备侧角度执行图6、图9、图10、图11、图14所示的实施例中所提供的数据传输方法。
基于以上实施例,本申请实施例还提供了一种计算机可读存储介质,该计算机可读存储介质中存储有计算机程序,所述计算机程序被计算机执行时,使得计算机从终端设备侧或者网络设备侧角度执行上述方法实施例中所提供的数据传输方法。其中,存储介质可以是计算机能够存取的任何可用介质。以此为例但不限于:计算机可读介质可以包括RAM、ROM、EEPROM、CD-ROM或其他光盘存储、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质。
基于以上实施例,本申请实施例提供了一种通信系统,包括终端设备、接入网设备以及固网网关设备,其中,所述终端设备、网络设备以及固网网关设备可以实现上述实施例中所提供的通信方法。
基于以上实施例,本申请实施例还提供了一种芯片,所述芯片用于读取存储器中存储的计算机程序,从终端设备侧或者网络设备侧角度实现上述方法实施例中所提供的数据传输方法。
基于以上实施例,本申请实施例提供了一种芯片系统,该芯片系统包括处理器,用于支持计算机装置实现上述方法实施例中终端设备、接入网设备或固网网关设备所涉及的功能。在一种可能的设计中,所述芯片系统还包括存储器,所述存储器用于保存该计算机装置必要的程序和数据。该芯片系统,可以由芯片构成,也可以包含芯片和其他分立器件。
本申请实施例提供的技术方案可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本发明实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、网络设备、终端设备或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(digital subscriber line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机可以存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质(例如,软盘、硬盘、磁带)、光介质(例如,数字视频光盘(digital video disc,DVD))、或者半导体介质等。
在本申请实施例中,在无逻辑矛盾的前提下,各实施例之间可以相互引用,例如方法实施例之间的方法和/或术语可以相互引用,例如装置实施例之间的功能和/或术语可以相互引用,例如装置实施例和方法实施例之间的功能和/或术语可以相互引用。
本申请是参照根据本申请的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指 令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
显然,本领域的技术人员可以对本申请进行各种改动和变型而不脱离本申请的范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。

Claims (30)

  1. 一种通信方法,其特征在于,包括:
    接入网设备获取第一信息,所述接入网设备支持第三代合作伙伴计划3GPP接入技术;
    所述接入网设备根据所述第一信息与第一终端设备建立用户面连接;
    所述接入网设备通过所述用户面连接获取所述第一终端设备的用户面数据,并向第一固网网关设备发送所述用户面数据。
  2. 如权利要求1所述的方法,其特征在于,所述第一信息用于指示所述第一终端设备的类型为目标类型和/或用于指示所述第一终端设备允许通过所述第一固网网关设备获取业务;其中,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多个。
  3. 如权利要求1或2所述的方法,其特征在于,所述第一信息来自所述第一终端设备,所述第一信息指示所述第一终端设备的类型为所述目标类型。
  4. 如权利要求1或2所述的方法,其特征在于,所述第一信息预配置于所述接入网设备中或者所述第一信息来自所述第一固网网关设备;其中,所述第一信息包括所述第一终端设备对应的签约数据信息,所述签约数据信息用于确定所述第一终端设备允许通过所述第一固网网关设备获取业务。
  5. 如权利要求1-4任一项所述的方法,其特征在于,所述方法还包括:
    所述接入网设备向所述第一固网网关设备发送第二信息,所述第二信息用于请求管理所述第一终端设备与所述第一固网网关设备之间的连接。
  6. 如权利要求5所述的方法,其特征在于,所述方法还包括:
    所述接入网设备接收来自所述第一固网网关设备的第三信息;所述第三信息包括以下至少一个:
    所述第一终端设备的标识信息;
    所述第一终端设备的认证信息,所述认证信息用于指示所述第一终端设备通过所述第一固网网关设备对应的固网网络的认证;
    所述第一终端设备的签约数据信息,所述签约数据信息包括固网业务信息、服务质量QoS信息、优先级信息中的一个或多个;
    所述第一终端设备的安全上下文信息,所述安全上下文信息用于建立所述接入网设备与所述第一终端设备的安全连接。
  7. 如权利要求6所述的方法,其特征在于,所述方法还包括:
    所述接入网设备根据所述第三信息,执行用户面连接管理流程;其中,所述用户面管理流程包括以下至少一个操作:建立用户面资源、修改用户面资源或者释放用户面资源。
  8. 如权利要求1-4任一项所述的方法,其特征在于,
    所述接入网设备与至少一个固网网关设备建立连接,所述至少一个固网网关设备包括所述第一固网网关设备。
  9. 如权利要求1-8任一项所述的方法,其特征在于,所述方法还包括:
    所述接入网设备获取来自所述第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息;
    所述接入网设备根据所述第四信息,采用所述第一终端设备的安全上下文信息建立所 述接入网设备与所述第一终端设备的安全连接。
  10. 如权利要求9所述的方法,其特征在于,所述第四信息包括所述第一终端设备的安全上下文信息对应的第一序列号;
    所述接入网设备根据所述第四信息,采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接,包括:
    所述接入网设备获取至少一个终端设备的安全上下文信息和标识集合,所述标识集合包括用于指示所述至少一个终端设备的安全上下文信息的第一序列号集合,所述第一序列号集合包括所述第一序列号;
    所述接入网设备根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取所述第一终端设备的安全上下文信息;
    所述接入网设备采用所述第一终端设备的安全上下文信息,建立所述接入网设备与所述第一终端设备的安全连接。
  11. 如权利要求10所述的方法,其特征在于,所述标识集合还包括第二序列号集合;
    在所述接入网设备采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接之后,所述方法还包括:
    将所述第一序列号替换为所述第二序列号集合中的第二序列号,并向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。
  12. 如权利要求9-11任一项所述的方法,其特征在于,所述第四信息还包括所述第一固网网关设备对应的固网网络的标识信息。
  13. 如权利要求9-12任一项所述的方法,其特征在于,所述方法还包括:
    所述接入网设备发送以下至少一个信息:
    所述接入网设备的能力信息,所述能力信息指示所述接入网设备支持固网传输;
    所述接入网设备支持的固网网络的标识信息,所述接入网设备支持的固网网络包括所述第一固网网关设备对应的固网网络;
    网络优先级信息,所述网络优先级信息用于指示所述接入网设备所属的移动运营商的优先级。
  14. 如权利要求9-12任一项所述的方法,其特征在于,所述方法还包括:
    所述接入网设备获取所述第一终端设备发送的用于指示所述第一终端设备的类型为目标类型的信息和/或所述第一终端设备请求接入的固网网络的标识信息;
    所述接入网设备根据所述第一终端设备的类型和/或所述第一终端设备请求接入的固网网络的标识信息,确定所述接入网设备支持所述第一终端设备的固网传输。
  15. 一种通信装置,其特征在于,应用于支持第三代合作伙伴计划3GPP接入技术的接入网设备,包括:
    通信模块,用于获取第一信息;
    处理模块,用于根据所述第一信息与第一终端设备建立用户面连接;
    所述通信模块,还用于通过所述用户面连接获取所述第一终端设备的用户面数据,并向第一固网网关设备发送所述用户面数据。
  16. 如权利要求15所述的通信装置,其特征在于,所述第一信息用于指示所述第一终端设备的类型为目标类型和/或用于指示所述第一终端设备允许通过所述第一固网网关设备获取业务;其中,所述目标类型包括家庭网关、家庭终端、客户终端设备中的一个或多 个。
  17. 如权利要求15或16所述的通信装置,其特征在于,所述第一信息来自所述第一终端设备,所述第一信息指示所述第一终端设备的类型为所述目标类型。
  18. 如权利要求15或16所述的通信装置,其特征在于,所述第一信息预配置于所述接入网设备中或者所述第一信息来自所述第一固网网关设备;其中,所述第一信息包括所述第一终端设备对应的签约数据信息,所述签约数据信息用于确定所述第一终端设备允许通过所述第一固网网关设备获取业务。
  19. 如权利要求15-18任一项所述的通信装置,其特征在于,
    所述通信模块,还用于向所述第一固网网关设备发送第二信息,所述第二信息用于请求管理所述第一终端设备与所述第一固网网关设备之间的连接。
  20. 如权利要求19所述的通信装置,其特征在于,所述通信模块,还用于接收来自所述第一固网网关设备的第三信息;所述第三信息包括以下至少一个:
    所述第一终端设备的标识信息;
    所述第一终端设备的认证信息,所述认证信息用于指示所述第一终端设备通过所述第一固网网关设备对应的固网网络的认证;
    所述第一终端设备对应的签约数据信息,所述签约数据信息包括固网业务信息、服务质量QoS信息、优先级信息中的一个或多个;
    所述第一终端设备的安全上下文信息,所述安全上下文信息用于建立所述接入网设备与所述第一终端设备的安全连接。
  21. 如权利要求20所述的通信装置,其特征在于,
    所述处理模块,还用于根据所述第三信息,执行用户面连接管理流程;其中,所述用户面管理流程包括以下至少一个操作:建立用户面资源、修改用户面资源或者释放用户面资源。
  22. 如权利要求15-18任一项所述的通信装置,其特征在于,所述接入网设备与至少一个固网网关设备之间建立连接,所述至少一个固网网关设备包括所述第一固网网关设备。
  23. 如权利要求15-22任一项所述的通信装置,其特征在于,
    所述通信模块,还用于获取来自所述第一终端设备的第四信息,所述第四信息用于确定所述第一终端设备的安全上下文信息;
    所述处理模块,还用于根据所述第四信息,采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接。
  24. 如权利要求23所述的通信装置,其特征在于,所述第四信息包括所述第一终端设备的安全上下文信息对应的第一序列号;所述处理模块,还用于:
    通过所述通信模块获取至少一个终端设备的安全上下文信息和标识集合,所述标识集合包括用于指示所述至少一个终端设备的安全上下文信息的第一序列号集合,所述第一序列号集合包括所述第一序列号;
    根据所述第一序列号在所述至少一个终端设备的安全上下文信息和标识集合中获取所述第一终端设备的安全上下文信息;
    所述接入网设备采用所述第一终端设备的安全上下文信息,建立所述接入网设备与所述第一终端设备的安全连接。
  25. 如权利要求24所述的通信装置,其特征在于,所述标识集合还包括第二序列号集 合;
    所述处理模块,还用于在采用所述第一终端设备的安全上下文信息建立所述接入网设备与所述第一终端设备的安全连接之后,将所述第一序列号替换为所述第二序列号集合中的第二序列号;
    所述通信模块,还用于向所述第一终端设备发送所述第二序列号,所述第二序列号用于指示所述第一终端设备的安全上下文信息。
  26. 如权利要求23-25任一项所述的通信装置,其特征在于,所述第四信息还包括所述第一固网网关设备对应的固网网络的标识信息。
  27. 如权利要求23-26任一项所述的通信装置,其特征在于,所述通信模块,还用于发送以下至少一个信息:
    所述接入网设备的能力信息,所述能力信息指示所述接入网设备支持固网传输;
    所述接入网设备支持的固网网络的标识信息,所述接入网设备支持的固网网络包括所述第一固网网关设备对应的固网网络;
    网络优先级信息,所述网络优先级信息用于指示所述接入网设备所属的移动运营商的优先级。
  28. 如权利要求23-26任一项所述的通信装置,其特征在于,
    所述通信模块,还用于获取所述第一终端设备发送的用于指示所述第一终端设备的类型为目标类型的信息和/或所述第一终端设备请求接入的固网网络的标识信息;
    所述处理模块,还用于根据所述第一终端设备的类型和/或所述第一终端设备请求接入的固网网络的标识信息,确定所述接入网设备支持所述第一终端设备的固网传输。
  29. 一种通信装置,其特征在于,所述通信装置包括处理器和存储器,所述存储器和所述处理器耦合,所述处理器用于执行权利要求1至14任一项所述的方法。
  30. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质包括指令,当其在计算机上运行时,使得计算机执行权利要求1至14任一项所述的方法。
PCT/CN2022/105550 2021-07-19 2022-07-13 一种通信方法及装置 WO2023001046A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
JP2024503392A JP2024530416A (ja) 2021-07-19 2022-07-13 通信方法および装置
KR1020247005503A KR20240027855A (ko) 2021-07-19 2022-07-13 통신 방법 및 장치
EP22845211.6A EP4369756A1 (en) 2021-07-19 2022-07-13 Communication method and apparatus
US18/415,324 US20240155705A1 (en) 2021-07-19 2024-01-17 Communication method and apparatus

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110812409.3A CN115643562A (zh) 2021-07-19 2021-07-19 一种通信方法及装置
CN202110812409.3 2021-07-19

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US18/415,324 Continuation US20240155705A1 (en) 2021-07-19 2024-01-17 Communication method and apparatus

Publications (1)

Publication Number Publication Date
WO2023001046A1 true WO2023001046A1 (zh) 2023-01-26

Family

ID=84940129

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/105550 WO2023001046A1 (zh) 2021-07-19 2022-07-13 一种通信方法及装置

Country Status (6)

Country Link
US (1) US20240155705A1 (zh)
EP (1) EP4369756A1 (zh)
JP (1) JP2024530416A (zh)
KR (1) KR20240027855A (zh)
CN (1) CN115643562A (zh)
WO (1) WO2023001046A1 (zh)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1767484A (zh) * 2004-10-27 2006-05-03 华为技术有限公司 一种无线接入网络构架及实现资源分配的方法
CN1996913A (zh) * 2005-12-31 2007-07-11 华为技术有限公司 一种控制与承载分离的网络互连系统及方法
EP2178329A1 (en) * 2008-10-16 2010-04-21 Vodafone Group PLC Method to interface over mobile and fixed communication networks and communication system
CN103533599A (zh) * 2012-07-03 2014-01-22 中兴通讯股份有限公司 一种固网移动融合场景下的策略控制方法
CN107979860A (zh) * 2016-10-25 2018-05-01 华为技术有限公司 支持non-3GPP接入的用户面功能实体选择方法、设备及系统
WO2018191854A1 (zh) * 2017-04-17 2018-10-25 华为技术有限公司 接入固定网络的方法和接入网关网元

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1767484A (zh) * 2004-10-27 2006-05-03 华为技术有限公司 一种无线接入网络构架及实现资源分配的方法
CN1996913A (zh) * 2005-12-31 2007-07-11 华为技术有限公司 一种控制与承载分离的网络互连系统及方法
EP2178329A1 (en) * 2008-10-16 2010-04-21 Vodafone Group PLC Method to interface over mobile and fixed communication networks and communication system
CN103533599A (zh) * 2012-07-03 2014-01-22 中兴通讯股份有限公司 一种固网移动融合场景下的策略控制方法
CN107979860A (zh) * 2016-10-25 2018-05-01 华为技术有限公司 支持non-3GPP接入的用户面功能实体选择方法、设备及系统
WO2018191854A1 (zh) * 2017-04-17 2018-10-25 华为技术有限公司 接入固定网络的方法和接入网关网元

Also Published As

Publication number Publication date
US20240155705A1 (en) 2024-05-09
CN115643562A (zh) 2023-01-24
KR20240027855A (ko) 2024-03-04
EP4369756A1 (en) 2024-05-15
JP2024530416A (ja) 2024-08-21

Similar Documents

Publication Publication Date Title
EP3627793B1 (en) Session processing method and device
CN109391940B (zh) 一种接入网络的方法、设备及系统
EP4117340A1 (en) Business processing method, device and system for proximity service
US10432632B2 (en) Method for establishing network connection, gateway, and terminal
US11647452B2 (en) Application-driven user slice selection for mobile networks
WO2018014539A1 (zh) 一种信息传输方法、融合网关及系统
CN111200859A (zh) 一种网络切片的选择方法、网络设备及终端
JP5982690B2 (ja) ネットワークコンバージェンスの方法、デバイス、および通信システム
US20170244705A1 (en) Method of using converged core network service, universal control entity, and converged core network system
CN106470465B (zh) Wifi语音业务发起方法、lte通信设备、终端及通信系统
WO2013155920A1 (zh) D2D终端接入控制方法、D2D终端、eNB和MME
CN116325845A (zh) 一种安全通信方法、装置及系统
US20240098583A1 (en) PDU session continuity for a UE moving between a telecommunications network and a gateway device
JP7416984B2 (ja) サービス取得方法、装置、通信機器及び可読記憶媒体
CN114731460B (zh) 一种多播会话的建立方法及网络设备
KR102055911B1 (ko) 세션 연결을 위한 시그널링 방법, 그리고 이를 구현한 장치
WO2024000975A1 (zh) 一种会话建立系统、方法、电子设备及存储介质
WO2023001046A1 (zh) 一种通信方法及装置
WO2022213792A1 (zh) 通信方法和通信装置
WO2021233235A1 (zh) 连接建立的方法、装置和系统
CN103975641B (zh) 一种会话建立方法及装置
WO2021081900A1 (zh) 通信方法及相关装置
EP4030689A1 (en) Data transmission method and apparatus, system, and storage medium
WO2023001015A1 (zh) 一种传输数据的方法和装置
WO2024060472A1 (zh) 数据分流方法、双域专网系统、设备、存储介质及程序产品

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22845211

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2024503392

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 202427003732

Country of ref document: IN

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112024001080

Country of ref document: BR

WWE Wipo information: entry into national phase

Ref document number: 2022845211

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2022845211

Country of ref document: EP

Effective date: 20240205

ENP Entry into the national phase

Ref document number: 20247005503

Country of ref document: KR

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 1020247005503

Country of ref document: KR

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 11202400417X

Country of ref document: SG

ENP Entry into the national phase

Ref document number: 112024001080

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20240118