WO2016155012A1 - 一种无线通信网络中的接入方法、相关装置及*** - Google Patents

一种无线通信网络中的接入方法、相关装置及*** Download PDF

Info

Publication number
WO2016155012A1
WO2016155012A1 PCT/CN2015/075897 CN2015075897W WO2016155012A1 WO 2016155012 A1 WO2016155012 A1 WO 2016155012A1 CN 2015075897 W CN2015075897 W CN 2015075897W WO 2016155012 A1 WO2016155012 A1 WO 2016155012A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobility management
network element
management network
message
gateway
Prior art date
Application number
PCT/CN2015/075897
Other languages
English (en)
French (fr)
Inventor
李欢
于游洋
靳维生
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2015/075897 priority Critical patent/WO2016155012A1/zh
Priority to KR1020177031204A priority patent/KR101930382B1/ko
Priority to RU2017134503A priority patent/RU2682856C1/ru
Priority to EP15886982.6A priority patent/EP3267707B1/en
Priority to CN201580065448.4A priority patent/CN107005843B/zh
Publication of WO2016155012A1 publication Critical patent/WO2016155012A1/zh
Priority to US15/722,140 priority patent/US10419935B2/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/06Registration at serving network Location Register, VLR or user mobility server
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/18Selecting a network or a communication service
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/04Registration at HLR or HSS [Home Subscriber Server]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/18Service support devices; Network management devices
    • H04W88/182Network node acting on behalf of an other network entity, e.g. proxy
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/17Selecting a data network PoA [Point of Attachment]

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to an access method, related apparatus, and system in a wireless communication network.
  • 3GPP 3rd Generation Partnership Project
  • LTE Long Term Evolution
  • 2G second generation
  • 3G Third Generation
  • PS Packet Switching
  • Evolved 3GPP Packet Switched Domain also known as Evolved Packet System (EPS).
  • EPS Evolved Packet System
  • the core network of the new mobile communication network not only supports 3GPP access technology, but also supports non-3GPP (Non 3GPP) access technologies, such as Code Division Multiple Access 2000 (Code). Division Multiple Access 2000, CDMA2000), Worldwide Interoperability for Microwave Access (WiMAX), and Wireless Local Area Networks (WLAN).
  • Non 3GPP Non 3GPP access technologies, such as Code Division Multiple Access 2000 (Code). Division Multiple Access 2000, CDMA2000), Worldwide Interoperability for Microwave Access (WiMAX), and Wireless Local Area Networks (WLAN).
  • the user equipment when the user equipment (User Equipment, UE) accesses the EPC from the non-3GPP side, it can access from the trusted non-3GPP side, and can also be from the untrusted 3GPP. Side access.
  • the Evolved Packet Data Gateway ePDG selects the packet data gateway (Packet Data) for the APN of the UE.
  • P-GW Packet Data Network Gateway
  • PDN packet data network
  • P-GW Packet Data Network Gateway
  • P-GW Packet Data Network Gateway
  • the P-GW passes its own identity (ie, P-GW ID) through itself and 3GPP Authentication, Authorization and Accounting Server (3GPP Authentication, Authorization, and Accounting Server, 3GPP AAA)
  • 3GPP AAA 3GPP Authentication, Authorization, and Accounting Server
  • the S6b interface between the Servers is sent to the 3GPP AAA Server; the 3GPP AAA Server then registers the received P-GW identity with the home subscriber server/system (HSS), thereby implementing the non-trusted 3GPP side connection.
  • HSS home subscriber server/system
  • the process of the UE accessing the EPC network from the non-3GPP side requires the participation of the 3GPP AAA Server.
  • the embodiments of the present invention provide an access method, a related device, and a system in a wireless communication network, which can adapt to a new simplified network architecture, and implement the UE accessing the EPC network from the non-3GPP network.
  • an embodiment of the present invention provides an access method in a wireless communication network, including:
  • the non-3GPP access gateway selects a target mobility management network element for the UE, and the target mobility management network element supports the non-3GPP access Authentication authorization function for accessing the network;
  • the non-3GPP access gateway sends an authentication and authorization request message to the target mobility management network element, where the authentication and authorization request message is used to request authentication and authorization for the UE;
  • the non-3GPP access gateway selects a packet data gateway P-GW for the access point name APN of the UE;
  • the non-3GPP access gateway establishes a packet data network PDN connection between the non-3GPP access gateway and the selected P-GW for the APN of the UE;
  • non-3GPP access gateway registers the identifier of the selected P-GW to the home subscriber server HSS by using the target mobility management network element.
  • the method further includes:
  • the non-3GPP access gateway determines an APN of the UE.
  • the non-3GPP access gateway uses the target mobility management network element to select the selected
  • the registration of the P-GW's logo to the HSS includes:
  • an embodiment of the present invention provides an access method in a wireless communication network, including:
  • the mobility management network element supporting the authentication authorization function of the non-3GPP access network receives the authentication and authorization sent by the non-3GPP access gateway. a request message, where the authentication and authorization request message is used to request authentication and authorization for the UE;
  • the mobility management network element performs authentication and authorization on the UE according to the authentication and authorization request message
  • the mobility management network element After the authentication and authorization of the UE is successful, the mobility management network element receives the access point name APN of the UE and the non-3GPP access gateway sent by the non-3GPP access gateway.
  • the mobility management network element sends an APN of the UE and an identifier of the selected P-GW to the HSS.
  • an embodiment of the present invention provides a method for updating subscription data, where a mobility management network element receives a data update request message sent by a home subscriber server HSS after the subscription data of the user equipment UE is updated, and the data update request is sent.
  • the message includes an International Mobile Subscriber Identity (IMSI) of the UE, updated subscription data of the UE, and an access type corresponding to the updated subscription data, where the data update request message is an insertion subscription data message and a push subscription request.
  • IMSI International Mobile Subscriber Identity
  • the mobility management network element sends an update message to the target gateway, where the update message is used to request the target gateway to update subscription data of the UE, where the update message includes updated subscription data and a location of the UE
  • the IMSI of the UE sends an update message to the target gateway, where the update message is used to request the target gateway to update subscription data of the UE, where the update message includes updated subscription data and a location of the UE
  • the IMSI of the UE sends an update message to the target gateway, where the update message is used to request the target gateway to update subscription data of the UE, where the update message includes updated subscription data and a location of the UE The IMSI of the UE.
  • an embodiment of the present invention provides a method for updating subscription data, where include:
  • the home subscriber server HSS After the subscription data of the user equipment UE is updated, the home subscriber server HSS sends a data update request message to the mobility management network element, where the data update request message includes the international mobile subscriber identity (IMSI) of the UE, and the UE The access type corresponding to the updated subscription data and the updated subscription data, so that the mobility management network element determines, according to the data update request message, a target gateway corresponding to the access type and to the target gateway.
  • Sending an update message the update message is used to request the target gateway to update subscription data of the UE, where the update message includes updated subscription data of the UE and an IMSI of the UE;
  • the data update request message is an insertion subscription data message, a push subscription request message, or an insertion user data message.
  • the target gateway is an evolved packet data gateway ePDG. a trusted wireless local area network access network TWAN or a high speed packet data service gateway HSGW, wherein the update message sent by the mobility management network element to the target gateway is a user subscription data update message; or, when the access When the type belongs to the access technology of the 3GPP, the target gateway is an S-GW, and the update message sent by the mobility management network element to the target gateway is a bearer modification command.
  • an embodiment of the present invention provides a method for updating subscription data, which includes:
  • the mobility management network element supporting the authentication authorization function of the non-3th generation partner plan 3GPP access network receives the data update request message sent by the home subscriber server HSS after the subscription data of the user equipment UE is updated, the data update request message An international mobile subscriber identity IMSI of the UE, updated subscription data of the UE, where the data update request message is an insertion subscription data message, a push subscription request message, or an insertion user data message;
  • the mobility management network element sends a bearer modification command to the S-GW connected to the mobility management network element according to the data update request message, and connects to all non-3GPPs connected to the mobility management network element.
  • the inbound gateway sends a user subscription data update message, where the bearer modification command and the user subscription data update message both include updated subscription data of the UE and an IMSI of the UE.
  • Embodiments of the present invention provide an access method in a wireless communication network, which is capable of 3GPP AAA
  • the authentication authorization function of the non-3GPP access network of the server is integrated into the mobility management network element, so that the non-3GPP access gateway may select to support the non-3GPP access network after the UE accesses the non-3GPP access network.
  • the mobility management network element of the authorization function is a target mobility management network element, and requests the target mobility management network element to perform authentication and authorization on the UE.
  • the The non-3GPP access gateway may select a P-GW for the UE, and establish a PDN connection between the UE and the selected P-GW for the UE, and implement the UE to access from the non-3GPP access network. Go to the EPC network.
  • 1 is a schematic diagram of a system architecture of an evolved packet system
  • FIG. 2(a) is a schematic diagram of an architecture of a 3GPP AAA Server and an MME according to an embodiment of the present invention
  • FIG. 2(b) is a schematic diagram of another architecture of a 3GPP AAA Server and an MME according to an embodiment of the present invention
  • FIG. 3 is a flowchart of an access method in a wireless communication network according to an embodiment of the present invention.
  • FIG. 4 is a flowchart of still another access method in a wireless communication network according to an embodiment of the present invention.
  • FIG. 5 is a flowchart of a method for updating subscription data according to an embodiment of the present invention.
  • FIG. 6 is a flowchart of still another method for updating subscription data according to an embodiment of the present invention.
  • FIG. 7 is a flowchart of still another method for updating subscription data according to an embodiment of the present invention.
  • FIG. 8 is a schematic diagram of an access gateway according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram of a mobility management network element according to an embodiment of the present invention.
  • FIG. 10 is a schematic diagram of still another mobility management network element according to an embodiment of the present invention.
  • FIG. 11 is a schematic diagram of a home subscriber server according to an embodiment of the present invention.
  • FIG. 12 is a schematic diagram of still another mobility management network element according to an embodiment of the present invention.
  • FIG. 13 is a schematic structural diagram of a computer processing apparatus according to an embodiment of the present invention.
  • the embodiments of the present invention provide an access method in a wireless communication network, which can implement access of a UE from a non-3GPP network based on a simplified network architecture.
  • the embodiment of the present invention further provides a corresponding device and system.
  • the core network EPC mainly includes a Mobility Management Entity (MME) and a General Packet Radio Service (GPRS) service support node (Serving GPRS Support). Node, SGSN), Serving Gateway (S-GW), and P-GW; wherein the MME is mainly responsible for non-access stratum (NAS) signaling with the user equipment, and is a user equipment.
  • MME Mobility Management Entity
  • GPRS General Packet Radio Service
  • S-GW Serving Gateway
  • P-GW Packet Radio Service
  • NAS non-access stratum
  • the S-GW is a mobility anchor for switching between the local eNodeBs, and providing a lawful interception related function;
  • the GW is mainly responsible for user address allocation, policy control and enforcement of charging rules, and lawful interception related functions.
  • the UE When the UE accesses the EPC from the non-3GPP network, the UE can access through the interface between the trusted non-3GPP access network and the P-GW, for example, through a trusted WLAN access network (TWAN) and P.
  • TWAN trusted WLAN access network
  • the S2a interface between the GW and the P-GW can also be accessed through the interface between the non-trusted non-3GPP access network and the P-GW, for example, through the S2b interface between the ePDG and the P-GW, where the ePDG /TWAN is mainly responsible for forwarding the mobile IP address of the UE allocated by the P-GW, registering the local IP address of the UE, and binding the mobile IP address of the UE with the local IP address.
  • 3GPP AAA server When accessing from a non-3GPP network, another important network element is a 3GPP AAA server, which is mainly responsible for implementing an authentication and authorization operation for the UE through interaction with the HSS, and a P-GW identifier used for each PDN connection established by the UE. Registered in the HSS, and the HSS is mainly used to store the user's subscription information.
  • the 3GPP AAA function is integrated with the existing network elements, thereby saving several interfaces related to 3GPP AAA.
  • the technology will not be able to achieve the UE accessing the EPC network from the non-3GPP side.
  • the embodiment of the present invention provides an access method in a wireless communication network, which can integrate some or all of the logical functions of the 3GPP AAA Server into the mobility management network element, so that the user equipment UE accesses
  • the non-3GPP access gateway that is, the access gateway of the non-3GPP network, selects to support the authentication and authorization function of the non-3GPP access network.
  • the mobility management network element performs authentication and authorization for the UE, and after the PDN connection is established, the target mobility management network element registers the identifier of the selected P-GW to the home subscriber server HSS.
  • the UE accesses from the non-3GPP network to the EPC network.
  • the HSS needs to update the updated subscription data to the corresponding gateway. Specifically, if the subscription data of the UE accessed through the 3GPP network is updated, the HSS needs to be updated. Notifying the MME/SGSN that the updated subscription data is updated by the MME/SGSN to the S-GW; if the subscription data of the UE accessed through the non-3GPP network is updated, the HSS needs to notify the 3GPP AAA Server that the 3GPP AAA Server will be updated.
  • the subscription data is updated to a non-3GPP access gateway, such as ePDG or TWAN or High Rate Packet Data (HRPD) Serving Gateway (HSGW).
  • a non-3GPP access gateway such as ePDG or TWAN or High Rate Packet Data (HRPD) Serving Gateway (HSGW).
  • the embodiment of the present invention further proposes an update subscription. Data method, related device and system.
  • the mobility management network element may be an MME, and may also be an SGSN (such as GnGp-SGSN or S4-SGSN); a non-3GPP access gateway (ie, an access gateway of a non-3GPP network, which is convenient for subsequent description).
  • the non-3GPP access gateway may be an ePDG, or may be a TWAN, or may be an HSGW, which is not limited herein.
  • the mobility management network element is used as the MME
  • the non-3GPP access gateway is the ePDG as an example
  • an architecture diagram of the 3GPP AAA Server and the MME is proposed, as shown in FIG. 2(a) and FIG. 2 ( b) shown.
  • the logical function of the 3GPP AAA Server is deployed to the MME, and an independent SWx interface is added between the MME and the HSS, as shown in FIG. 2(a), or the S6a interface between the MME and the HSS is upgraded to support the 3GPP AAA Server and the HSS.
  • the SWx interface is shown in Figure 2(b), and the SWm interface between the ePDG and the 3GPP AAA Server can be deployed between the MME and the ePDG.
  • the S6b interface between the ePDG and the 3GPP AAA Server is no longer deployed.
  • 3GPP AAA The SWa interface between the Server and the untrusted 3GPP access network can also be deployed, which greatly simplifies the network architecture.
  • the MME can be replaced by the SGSN, that is, the logical function of the 3GPP AAA Server is deployed to the SGSN, and accordingly, the S6a interface between the MME and the HSS is replaced with the S6d interface or the Gr interface between the SGSN and the HSS (if supported) MAP protocol), the S11 interface between the MME and the S-GW is replaced by S4 between the SGSN and the S-GW, which is not shown in the figure.
  • the S6a interface between the MME and the HSS is replaced with the S6d interface or the Gr interface between the SGSN and the HSS (if supported) MAP protocol)
  • the S11 interface between the MME and the S-GW is replaced by S4 between the SGSN and the S-GW, which is not shown in the figure.
  • the ePDG may be replaced with a TWAN/HSGW, and accordingly, the SWm interface between the ePDG and the MME/SGSN is replaced with the STa interface between the TWAG/HSGW and the MME/SGSN, and the ePDG and the P-GW are
  • the S2b interface between the TWAN/HSGW and the P-GW can be replaced by the S2b interface.
  • the S6b interface between the TWAN/HSGW and the 3GPP AAA Server is no longer deployed.
  • the 3GPP AAA Server and the trusted device are not trusted.
  • the SWa interface between the 3GPP access networks is no longer deployed, greatly simplifying the network architecture.
  • an embodiment of the present invention provides an access method in a wireless communication network, which can integrate an authentication authorization function of a non-3GPP access network of a 3GPP AAA Server into a mobility management network element to implement a UE.
  • the method of accessing from the non-3GPP network to the EPC network is as follows.
  • the non-3GPP access gateway selects a target mobility management network element for the UE, and the target mobility management network element supports authentication of the non-3GPP access network. Authorization function.
  • the target mobility management network element is a mobility management network element in the foregoing converged architecture, and incorporates an authentication authorization function of a non-3GPP access network of the 3GPP AAA Server, for example, when the non-3GPP access network is a WALN,
  • the target mobility management network element supports the authentication and authorization function of the WALN, and can authenticate and authorize the UE accessed from the WALN.
  • the mobility management network element supporting the authentication authorization function of the non-3GPP access network means that the mobility management network element can be from the non-3GPP access network (such as WLAN, CDMA2000 or WiMAX).
  • the accessed UE performs authentication and authorization.
  • the non-3GPP access gateway sends an authentication and authorization request (Authentication and Authorization Request) message to the target mobility management network element, where the authentication and authorization request message is used to request authentication of the UE. With authorization.
  • Authentication and Authorization Request Authentication and Authorization Request
  • the non-3GPP access gateway may request authentication and authorization for the UE, for example, through an added SWm interface between the non-3GPP access gateway and the mobility management network element or The STa interface sends the authentication and authorization request message.
  • the target mobility management network element may be configured according to the authentication and authorization request message to the UE Perform authentication and authorization.
  • the subscription data of the UE may be obtained from the HSS, and the UE is authorized according to the subscription data of the UE; the target mobility management network element may further acquire an authentication vector of the UE from the HSS.
  • the authentication is performed by using the authentication vector of the UE, where the authentication may include the network side (ie, the target mobility management network element) authenticating the UE and the UE authenticating the network side, or may only The network side is configured to authenticate the UE, which is not limited herein.
  • the authentication and authorization success message may be returned to the UE.
  • the foregoing authentication and authorization process is similar to the process in which the 3GPP AAA Server authenticates and authorizes the UE in the prior art, and details are not described herein again.
  • the UE accesses the 3GPP access network before accessing the non-3GPP access network, and performs an authentication process and the authentication succeeds, the The authentication and authorization of the UE by the target mobility management network element may mean that only the UE is authorized, and the UE is no longer authenticated.
  • the non-3GPP access gateway selects a P-GW for the APN of the UE.
  • the non-3GPP access gateway may select a P-GW for the APN of the UE.
  • the non-3GPP access gateway may also determine an APN of the UE before selecting a P-GW for the APN of the UE.
  • APN of the UE and the P-GW for the APN For the manner of determining the APN of the UE and the P-GW for the APN, reference may be made to the manner described in the following embodiments, which is not limited herein.
  • the non-3GPP access gateway establishes a PDN connection between the non-3GPP access gateway and the selected P-GW for the APN of the UE.
  • the non-3GPP access gateway registers the identifier of the selected P-GW to the HSS by using the target mobility management network element.
  • the non-3GPP access gateway may send the APN of the UE and the identifier of the selected P-GW to the target mobility management network element, so that the target mobility management network element passes a notification message (Notify Request) Or the non-3GPP IP Access Registration Request message sends the APN of the UE and the selected P-GW identity to the HSS to implement registration of the identity of the P-GW.
  • the UE is accessed from the non-3GPP access network to the EPC network.
  • the authentication authorization function of the non-3GPP access network of the 3GPP AAA Server is used.
  • the mobility management network element is integrated into the mobility management network element, so that the non-3GPP access gateway can select the mobility management network element that supports the authentication authorization function of the non-3GPP access network as the target mobile after the UE accesses the non-3GPP access network. And managing the network element, and requesting the target mobility management network element to perform authentication and authorization on the UE.
  • the non-3GPP access gateway may select P for the UE. - GW, and establishing a PDN connection between the UE and the selected P-GW for the UE, so that the UE accesses the EPC network from the non-3GPP access network.
  • the non-3GPP access gateway selects the target mobility management network element according to the pre-configuration information.
  • the pre-configuration information includes a correspondence between the location information of the UE and an identifier of the target mobility management network element, or the pre-configuration information includes an identifier of the non-3GPP access gateway and the target mobility management network element. Correspondence of the identity;
  • the non-3GPP access gateway sends an International Mobile Subscriber Identification Number (IMSI) of the UE to a Diameter Routing Agent (DRA), so that the DRA is according to the UE.
  • IMSI International Mobile Subscriber Identification Number
  • DRA Diameter Routing Agent
  • the IMSI selects the target mobility management network element for the UE;
  • the non-3GPP access gateway constructs a Fully Qualified Domain Name (FQDN) of the mobility management network element according to the location information of the UE, and sends the FQDN to the domain name resolution server (Domain Name Server) Or Domain Name System (DNS), such that the DNS may determine a mobility management network element according to the fully qualified domain, and receive an identifier of the mobility management network element determined by the DNS according to the FQDN, determined from the DNS Selecting, in the mobility management network element, a mobility management network element supporting the authentication authorization function of the non-3GPP access network as the target mobility management network element, because the target mobility management network element is based on the location of the UE
  • the fully qualified domain name of the information structure is determined so that the location of the selected target mobility management network element can be made close to the UE.
  • the 3GPP interface between the mobility management network element and the HSS in the existing architecture may be used, as shown in FIG. 2
  • the S6a interface in (b) the HSS may not be aware of the change of the network element architecture or improve the HSS; or may be added between the mobility management network element and the HSS by using the converged architecture.
  • Non-3GPP interface, such as using the SWx interface in Figure 2 (a) then the HSS can be To perceive changes in the network element architecture.
  • the UE that accesses from the 3GPP network and the UE that is accessed from the non-3GPP network needs to interact with the HSS by using the mobility management network element, and the HSS is difficult to determine the identifier of the P-GW and The information of the APN or the like interaction is from a UE accessing the 3GPP network or a UE of the non-3GPP network. Therefore, in the embodiment of the present invention, the non-3GPP access gateway may further determine an access type (RAT type) of the UE, where an access type of the UE may be used to indicate which connection the UE adopts.
  • RAT type access type
  • the access type information may be set to a WLAN, or a trusted WLAN or a non-trusted WLAN.
  • the non-3GPP access gateway may send the access type of the UE to the target mobility management network element together with the APN of the UE and the identifier of the selected P-GW, so that the target mobile Transmitting the APN of the UE, the identifier of the selected P-GW, and the access type of the UE to the HSS, so that the HSS may use the APN of the UE, the selected The identity of the P-GW and the access type of the UE and the correspondence between them are saved.
  • the non-3GPP access gateway may also determine the access type of the UE, and the access management type of the UE is directly determined by the mobility management network element, which is not limited herein.
  • the mobility management network element is used as the MME, and the non-3GPP access gateway is the ePDG as an example.
  • the mobility management network element is the SGSN or the non-3GPP access gateway is the TWAN/HSGW, the following method may also be used for the UE.
  • the access flow from the non-3GPP side is not described herein again.
  • an embodiment of the present invention provides a P-GW selection method, as shown in FIG.
  • the UE may perform signaling interaction with the access gateway ePDG of the WLAN to perform an authentication and authorization process of the WLAN access network.
  • S401 is an optional step.
  • the UE initiates an IKEv2 Authentication and Tunnel Setup (IKEv2Authentication and Tunnel Setup) process to the ePDG.
  • IKEv2Authentication and Tunnel Setup IKEv2Authentication and Tunnel Setup
  • the ePDG may be selected, and IKEv2 is initiated to the ePDG.
  • An authentication and channel establishment procedure to request authentication of the UE and establish a PDN connection for the UE.
  • the ePDG selects a target MME that supports an authentication authorization function of the WLAN.
  • the ePDG may select a target MME that supports the authentication and authorization function of the WLAN according to the pre-configuration information, thereby performing authentication and authorization on the UE.
  • the pre-configuration information may include a correspondence between the location information and the MME, and the ePDG may determine, according to the location information of the UE, an MME corresponding to the location information of the UE in the pre-configuration information. And as a target MME.
  • the MME corresponding to the ePDG may be specified in the pre-configuration information, and the MME corresponding to the ePDG in the pre-configuration information is used as the target MME, so that the ePDG may select the same for the UE connected to itself. MME.
  • the mapping between the IMSI and the MME may be configured in the DRA, for example, the IMS of the certain range of IMSIs or the corresponding relationship between the IMSI and the used MME, so that the ePDG may use the IMSI of the UE.
  • the DMA is sent to the DRA, and the DMA determines the target MME of the UE according to the IMSI of the UE.
  • the ePDG may construct an FQDN according to the location information of the UE, and send the FQDN to the DNS, and receive an identifier of the MME determined by the DNS according to the FQDN, and select support from the MME determined by the DNS.
  • the MME of the authentication and authorization function of the WLAN is used as the target MME, so that the MME that is closer to the UE can be selected as the target MME.
  • the foregoing target MME supports the authentication and authorization function of the WLAN.
  • the ePDG sends an authentication and authorization request message to the target MME, where the authentication and authorization request message is used to request authentication and authorization for the UE.
  • the non-3GPP access gateway may also perform the selection of the target MME by using the foregoing method, or may request the authentication by using an authentication and authorization request message.
  • the UE performs authentication and authorization.
  • the target MME sends an authentication request message to the HSS through the SWx interface, where the authentication request message is used to request to obtain an authentication vector of the UE.
  • the target MME may acquire subscription data of the UE, and authorize the UE.
  • the HSS returns an authentication response message to the MME through the SWx interface, where the authentication response message includes an authentication vector of the UE.
  • the target MME authenticates the UE by using an authentication vector of the UE.
  • the foregoing authentication process is similar to the process in which the 3GPP AAA Server authenticates and authorizes the UE in the prior art, and details are not described herein again.
  • the ePDG determines an APN of the UE, and selects a P-GW for an APN of the UE.
  • the ePDG may determine an APN of the UE. If the UE requests the APN, and the subscription data of the UE includes the APN requested by the UE, the ePDG may use the APN requested by the UE as the APN of the UE, if the UE requests The APN, the subscription data of the UE does not include the APN requested by the UE, and the ePDG may reject the authentication and authorization request; if the UE does not request, the ePDG may use the subscription data of the UE.
  • the default APN in the medium is used as the APN of the UE.
  • the ePDG may select a P-GW based on the APN of the UE; for example, The ePDG may send the target APN to the DNS server, and the DNS server may return a P-GW list (PGW list or P-GW list) that can connect to the target APN, and the ePDG may be from the P-GW. Select the appropriate P-GW from the list. If the ePDG determines that the UE is accessed through a multiple access or handover procedure, the ePDG may use a P-GW corresponding to the APN in the subscription data of the UE as The selected P-GW.
  • PGW list P-GW list
  • the ePDG establishes a PDN connection between the ePDG and the selected P-GW for an APN of the UE.
  • the ePDG sends an authorization request message to the target MME, where the authorization request message includes an APN of the UE and an identifier of the selected PGW.
  • the 3GPP AAA Sever is no longer deployed, and there is no interface between the P-GW and the target MME, which is different from the solution in the prior art that the P-GW registers its identity with the 3GPP AAA Sever. Therefore, the identifier of the selected P-GW can be registered by the ePDG to the HSS by using the target MME, thereby ensuring that the UE uses the same P-GW when switching between the 3GPP network and the non-3GPP network, thereby ensuring continuity of services. Sex.
  • the target MME sends a non-3GPP IP Protocol Registration Request (Non 3GPP Internet Protocol Access Registration Request) message to the HSS through a SWx interface, where the non-3GPP IP access registration request message includes an APN of the UE.
  • An identifier of the selected PGW to register the identity of the P-GW to the HSS.
  • the authentication and authorization of the UE after accessing from the non-3GPP side and the registration of the P-GW are performed through the SWx interface between the MME and the HSS, and the signaling interaction of the UE after access from the 3GPP side is performed.
  • the S6a interface between the MME and the HSS in the prior art is still used, so that the HSS can judge whether the message is from the 3GPP network or the non-3GPP network through the interface of the received message.
  • the identifier of the P-GW and the APN sent by the MME are received from the SWx interface, it may be determined that the identifier and the APN of the P-GW are UEs for accessing from the non-3GPP network, if the MME is received from the S6a interface.
  • the identity of the P-GW and the APN may determine that the identity of the P-GW and the APN are UEs for access from the 3GPP network.
  • S411 can also be replaced by:
  • the target MME sends a notification message (Notify Request) to the HSS through the S6a interface, where the notification message includes an APN of the UE and an identifier of the selected PGW to identify the P-GW. Register to the HSS.
  • the authentication and authorization after the UE accesses from the non-3GPP side is performed through the SWx interface between the MME and the HSS, and the registration of the P-GW is through the S6a between the MME and the HSS.
  • the HSS cannot judge whether the message is from the 3GPP network or the non-3GPP network through the interface of the received message.
  • the notification message may further include an access type of the UE, where the access type is used to indicate which access technology is used by the UE, for example, when the UE is connected from a WLAN.
  • the access type of the UE may be a WLAN, a trusted WLAN, or a non-trusted WLAN. Therefore, the HSS may determine, according to the access type, whether the APN of the UE and the identifier of the selected PGW are for a 3GPP network or a non-3GPP network.
  • the mobility management network element is not an MME, for example, an SGSN
  • the method described in S411 may be used, or the method described in S411 may be used.
  • the method is only when the method of S411' is adopted, and the notification message is transmitted through a 3GPP interface between the mobility management network element and the HSS, such as an S6d interface or a Gr interface between the SGSN and the HSS.
  • S412 Perform an IP security tunnel setup (IPSec Tunnel Setup) between the UE and the ePDG.
  • IP security tunnel setup IPSec Tunnel Setup
  • the ePDG may notify the UE that the IP security tunnel establishment is complete, and send the IP address of the PDN connection to the UE.
  • the architecture shown in (a) is adopted.
  • the frame shown in (b) since the SW6 interface is not added, the S6a interface is enhanced, so only S405 and S406 are passed.
  • the SWx interface sends the authentication request message and the authentication response message to be sent through the S6a interface, and replaces S411a with S411b, that is, sends a notification message to the HSS through the S6a interface to register the identifier of the selected P-GW to The same is true for the HSS.
  • the notification message may also include an access type of the UE.
  • the embodiment of the present invention provides a method for updating the subscription data, and the method includes:
  • the mobility management network element supporting the authentication authorization function of the non-3GPP access network receives a data update request message sent by the HSS after the subscription data of the UE is updated, where the data update request message includes the international mobile of the UE.
  • the subscription data of the UE is stored in the HSS, and different subscription data may be used for different access technologies. Therefore, when the subscription data is updated, the access type corresponding to the updated subscription data needs to be sent to the mobility management network. And the mobility management network element may determine, according to the access type, the target gateway, and send the updated subscription data to the corresponding target gateway.
  • the mobility management network element determines, according to the data update request message, a target gateway corresponding to the access type.
  • the target gateway is a non-3GPP access gateway, such as an ePDG/TWAN/HSGW.
  • the target gateway is an S-GW.
  • the mobility management network element sends an update message to the target gateway, where the update message is used to request the target gateway to update subscription data of the UE, where the update message includes updated subscription data of the UE. And the IMSI of the UE.
  • the update message may be a user subscription update (User Profile Update) message, and when the target gateway is an S-GW, the update message may be a bearer modification command (Modify). Bearer Command).
  • the target gateway may not only update the subscription data of the UE, but also send the updated subscription data of the UE to the corresponding P-GW, so that the P-GW also updates the UE. Signing data.
  • the mobility management network element may further send a data update response message to the HSS, where the data update response message includes the access type, and the data
  • the update response message may be an insert contract data response message, a push subscription response message, or a plug-in user data response message.
  • the mobility management network element may determine the target gateway according to the access type corresponding to the updated subscription data of the UE, so as to update the updated subscription data of the UE to the target gateway, and
  • the updated subscription data of the UE is updated to the P-GW by the target gateway, and the update of the user subscription data is implemented, and the subscription data of the UE is guaranteed to be used normally.
  • the following describes the method for updating the subscription data provided by the embodiment of the present invention by using the mobility management network element as the MME and the non-3GPP access gateway as the ePDG, as shown in FIG. 6 .
  • the mobility management network element is the SGSN or the non-3GPP access gateway is the TWAN/HSGW
  • the update of the subscription data may be referred to by the following method, and details are not described herein again.
  • the HSS sends an insertion subscription data message to the MME, where the insertion subscription data message includes an IMSI of the UE, updated subscription data of the UE, and an access type corresponding to the updated subscription data, the access type.
  • the insertion subscription data message includes an IMSI of the UE, updated subscription data of the UE, and an access type corresponding to the updated subscription data, the access type.
  • the access type For WLAN.
  • the MME can determine the target gateway according to the access type, because the access type of the subscription data is also sent to the MME. And sending the updated subscription data to a corresponding target gateway.
  • the HSS may send the subscription data message through its S6a interface with the MME.
  • the HSS may further send the IMSI of the UE, the updated subscription data of the UE, and the access type corresponding to the updated subscription data to the MME by using a push subscription request message by using a SWx interface.
  • the HSS may use the push subscription request message to correspond to the IMSI of the UE, the updated subscription data of the UE, and the updated subscription data.
  • the access type is sent to the SGSN, and the above information can be sent to the SGSN by using the S6d interface or the Gr interface to insert the user data message.
  • the MME determines, according to the access type, that the target gateway corresponding to the access type is an ePDG.
  • the MME sends a user subscription data update message to the ePDG, where the user subscription data update message includes updated subscription data of the UE and an IMSI of the UE.
  • the MME may also use the user subscription data update message to update the subscription data and the location of the UE.
  • the IMSI of the UE is sent to the TWAN or the HSGW.
  • S604 The ePDG returns a User Profile Update Ack message to the MME according to the user subscription data update message.
  • the IMSI of the UE may be included in the user subscription data update confirmation message.
  • the MME returns an Insert Subscription Data Ack message to the HSS, where the insertion subscription data response message includes the access type.
  • the insertion subscription data response message returned by the MME includes the access type, or may further include an IMSI of the UE, so that the HSS may determine which insertion is according to the information included in the insertion subscription data response message.
  • the ePDG sends a Modify Bearer Command to the P-GW, where the changed bearer command includes the updated subscription data to update the updated subscription data to the P-GW.
  • S604 and S606 has no order relationship, and S S604 may be executed first, or S606 may be executed first, or S606 may be executed first and then S604 may be executed.
  • the embodiment of the present invention further provides a method for updating subscription data. As shown in FIG. 7, the method includes:
  • the mobility management network element that supports the authentication authorization function of the non-3GPP access network receives the request message sent by the HSS after the subscription data of the UE is updated, where the data update request message includes the IMSI of the UE, the The updated subscription data of the UE, the data update request message is an insertion subscription data message, a push subscription request message, or an insertion user data message.
  • the mobility management network element sends a bearer modification command to the S-GW connected to the mobility management network element according to the data update request message, and all non-connections to the mobility management network element.
  • the 3GPP access gateway sends a user subscription data update message, where the bearer modification command and the user subscription data update message both include updated subscription data of the UE and an IMSI of the UE.
  • the S-GW may update the subscription data of the UE according to the bearer modification command, and the S-GW may further update the updated subscription data of the UE to the corresponding P-GW.
  • the non-3GPP access gateway may also update the subscription data of the UE according to the user subscription data update message, or may also update the updated subscription data of the UE to the corresponding P-GW.
  • the non-3GPP access gateway may be an ePDG, a TWAN, or an HSGW.
  • the mobility management network element supports the authentication authorization function of the non-3GPP access network. Therefore, when updating the subscription data, the HSS may only send the mobility management network element to the mobile device.
  • the S-GW and the non-3GPP access gateway can update the updated subscription data to the corresponding P-GW to implement the update of the subscription data.
  • FIG. 3 or FIG. 4 corresponds to an access method in the wireless communication network in the method embodiment
  • the embodiment provides an access gateway 80.
  • the access gateway 80 is an access gateway of a non-3th generation partnership plan 3GPP network, and the access gateway 80 includes a first selection unit 801.
  • the sending unit 802, the second selecting unit 803, and the establishing unit 804; the access gateway 80 may be the non-3GPP access gateway in the corresponding method embodiment of FIG. 3, or may be the ePDG in the corresponding method embodiment of FIG.
  • the first selecting unit 801 is configured to select a target mobility management network element for the UE after the user equipment UE accesses the non-3GPP access network, where the target mobility management network element supports the non-3GPP connection Authentication authorization function for accessing the network;
  • the sending unit 802 is configured to send an authentication and authorization request message to the target mobility management network element, where the authentication and authorization request message is used to request authentication and authorization for the UE;
  • the second selecting unit 803 is configured to select a packet data gateway P-GW for the APN of the UE;
  • the establishing unit 804 is configured to establish, after the target mobility management network element authenticates and authorizes the UE, the non-3GPP access gateway and the selected P- for the APN of the UE. PDN connection between GWs;
  • the sending unit 802 is further configured to register the identifier of the selected P-GW to the home subscriber server HSS by using the target mobility management network element, for example, the APN of the UE and the selected P-GW.
  • the identifier is sent to the target mobility management network element, so that the target mobility management network element identifies the APN of the UE and the selected P-GW by using a notification message or an IP access registration request message of a non-3GPP Sent to the HSS.
  • the second selecting unit 803 is further configured to determine an access type of the UE, where the sending unit 802 may specifically: the APN of the UE, the identifier and location of the selected P-GW. Transmitting an access type of the UE to the target mobility management network element, so that the target mobility management network element sends the APN of the UE by using a notification message or an IP access registration request message of a non-3GPP, the selected The identity of the P-GW and the access type of the UE are sent to the HSS.
  • the first selecting unit 801 may select the target mobility management network element according to the pre-configuration information;
  • the pre-configuration information includes a correspondence between the location information of the UE and an identifier of the target mobility management network element, or the pre-configuration information includes an identifier of the non-3GPP access gateway and the target mobility management. Correspondence relationship between the identifiers of the network elements;
  • the first selecting unit 801 sends the UE's International Mobile Subscriber Identity (IMSI) to the routing proxy node, so that the routing proxy node selects the target mobility management network for the UE according to the IMSI of the UE.
  • IMSI International Mobile Subscriber Identity
  • the first selecting unit 801 constructs a fully qualified domain name of the mobility management network element according to the location information of the UE, and sends the fully qualified domain name to the domain name resolution server DNS, and receives the DNS according to the full qualification.
  • An identifier of the mobility management network element determined by the domain name and selecting, from the mobility management network element determined by the DNS, a mobility management network element supporting the authentication authorization function of the non-3GPP access network as the target mobility management Network element.
  • the authentication authorization function of the non-3GPP access network of the 3GPP AAA server is integrated into the mobility management network element, so that the first selection unit 801 in the access gateway 80 of the non-3GPP network can be connected to the UE.
  • the mobility management network element that supports the authentication and authorization function of the non-3GPP access network is the target mobility management network element, and the sending unit 802 can pass the authentication and authorization request message.
  • the second selecting unit 803 may select a P-GW for the UE,
  • the establishing unit 804 establishes a PDN connection between the UE and the selected P-GW for the UE, and implements the UE accessing the EPC network from the non-3GPP access network.
  • the embodiment of the present invention provides a mobility management network element 90.
  • the mobility management network element 90 supports non-3GPP.
  • the mobility management network element 90 may be in the corresponding method embodiment of FIG.
  • the mobility management network element may also be the MME in the embodiment of the method corresponding to FIG. 4.
  • the receiving unit 901 is configured to: after the user equipment UE accesses the non-3GPP access network, receive an authentication and authorization request message sent by the non-3GPP access gateway, where the authentication and authorization request message is used to request Performing authentication and authorization on the UE;
  • the authentication and authorization unit sending unit 903 is configured to perform authentication and authorization on the UE according to the authentication and authorization request message.
  • the receiving unit 901 is further configured to: after the authentication and authorization unit successfully authenticates and authorizes the UE, receive an access point name APN and the non-the UE of the UE sent by the non-3GPP access gateway.
  • the sending unit 903 is further configured to send an APN of the UE and an identifier of the selected P-GW to the HSS, so as to implement registration of the P-GW identifier.
  • the sending unit 903 may specifically send the APN of the UE and the identifier of the selected P-GW to the HSS by using a notification message or an IP access registration request message of the non-3GPP.
  • the receiving unit 901 is further configured to receive an authentication response message returned by the HSS, where the authentication response message includes an authentication vector of the UE, and the sending unit 903 is further configured to use The authentication vector of the UE sends an authentication request message to the UE.
  • the mobility management network element 90 may further include:
  • the obtaining unit 904 is configured to determine an access type of the UE or receive an access type of the UE sent by the non-3GPP access gateway, where the sending unit 903 may use a notification message or non-3GPP IP access.
  • the registration request message sends the APN of the UE, the identifier of the selected P-GW, and the access type of the UE to the HSS. Therefore, the HSS may determine, according to the access type, whether the APN of the UE and the identifier of the selected PGW are for a 3GPP network or a non-3GPP network.
  • the HSS stores the subscription data of the UE, and the same subscription data may be used for different access technologies.
  • the HSS needs to update the updated subscription data to the corresponding network element. Therefore, the receiving unit 901 may be further configured to receive a data update request message that is sent by the HSS after the subscription data of the UE is updated, where the data update request message includes an International Mobile Subscriber Identity (IMSI) of the UE.
  • IMSI International Mobile Subscriber Identity
  • the data update request message is an insertion subscription data message, a push subscription request message, or an insertion user data message;
  • the sending unit 903 is further configured to: according to the data update request message, An S-GW connected to the mobility management network element sends a bearer modification command and sends a user subscription data update message to all non-3GPP access gateways connected to the mobility management network element, where the bearer modification command is signed by the user.
  • the data update messages each contain updated subscription data for the UE and an IMSI of the UE.
  • the receiving unit 901 is further configured to receive a data update request message that is sent by the HSS after the subscription data of the UE is updated, where the data update request message includes an International Mobile Subscriber Identity (IMSI) of the UE.
  • IMSI International Mobile Subscriber Identity
  • the new request message is an insertion subscription data message, a push subscription request message, or an insertion user data message.
  • the mobility management network element may further include a determining unit 905, configured to determine, according to the data update request message, the access type.
  • the sending unit 903 may further send an update message to the target gateway, where the update message is used to request the target gateway to update subscription data of the UE, where the update message includes an update of the UE The subscription data and the IMSI of the UE.
  • the authentication authorization function of the non-3GPP access network of the 3GPP AAA Server is integrated into the mobility management network element 90, so that the non-3GPP access gateway can select after the UE accesses the non-3GPP access network.
  • the mobility management network element 90 supporting the authentication authorization function of the non-3GPP access network is a target mobility management network element, and the receiving unit 901 of the mobility management network element 90 can receive the template sent by the non-3GPP access gateway.
  • the sending unit 903 may initiate an authentication process to the UE by using an authentication vector of the UE, where the receiving unit 901 may further receive the UE sent by the non-3GPP access gateway.
  • the embodiment of the present invention provides a mobility management network element 100, as shown in FIG. 10, the mobility management network element 100 includes a receiving unit 1001, and determines a method for updating the subscription data.
  • the unit 1002 and the sending unit 1003; the mobility management network element 100 may be the mobility management network element in the corresponding method embodiment of FIG. 5, or may be the MME in the corresponding method embodiment of FIG. 6.
  • the receiving unit 1001 is configured to receive a data update request message that is sent by the HSS after the subscription data of the UE is updated, where the data update request message includes the IMSI of the UE, the updated subscription data of the UE, and The access type corresponding to the updated subscription data, where the data update request message is an insertion subscription data message, a push subscription request message, or an insertion user data message;
  • the determining unit 1002 is configured to determine, according to the data update request message, a target gateway corresponding to the access type;
  • the sending unit 1003 is configured to send an update message to the target gateway, where the update message is used to request the target gateway to update subscription data of the UE, where the update message includes updated subscription data of the UE and The IMSI of the UE.
  • the target gateway is an ePDG, a trusted WLAN access network TWAN, or a high speed packet data serving gateway HSGW
  • the update message sent by the mobility management network element to the target gateway is a user subscription data update message; or, when the access type belongs to an access technology of the 3GPP, the target gateway is an S-GW, The update message sent by the mobility management network element to the target gateway is a bearer modification command.
  • the sending unit 1003 is further configured to send a data update response message to the HSS, where the data update response message includes the access type, where the data update response message is an insertion subscription data response message, and a push subscription Respond to the message or insert a user data response message.
  • the determining unit 1002 may determine the target gateway according to the access type corresponding to the updated subscription data of the UE, so that the sending unit 1003 may update the updated subscription data of the UE to the
  • the target gateway and the updated subscription data of the UE are updated to the P-GW by the target gateway, so that the subscription data of the user is updated, and the subscription data of the UE is guaranteed to be used normally.
  • the method for updating subscription data according to FIG. 5 or FIG. 6 provides a home subscriber server 110.
  • the home subscriber server 110 includes a sending unit 1101.
  • the home subscriber server 110 may It is the HSS in the embodiment of the method corresponding to FIG. 5, and may also be the HSS in the embodiment of the corresponding method in FIG. 6;
  • the sending unit 1101 is configured to send, after the subscription data of the user equipment UE is updated, a data update request message to the mobility management network element, where the data update request message includes an international mobile subscriber identity of the UE.
  • An IMSI an updated subscription data of the UE, and an access type corresponding to the updated subscription data, so that the mobility management network element determines, according to the data update request message, a target gateway corresponding to the access type.
  • sending an update message to the target gateway where the update message is used to request the target gateway to update subscription data of the UE, where the update message includes updated subscription data of the UE and an IMSI of the UE;
  • the data update request message is an insert subscription data message, a push subscription request message, or an insert user data message.
  • the target gateway is an ePDG, a trusted wireless local area network access network (TWAN), or a high speed packet data service.
  • the service gateway HSGW the update message sent by the mobility management network element to the target gateway is a user subscription data update message; or, when the access type belongs to an access technology of 3GPP, the target gateway is The S-GW, the update message sent by the mobility management network element to the target gateway is a bearer modification command.
  • the home subscriber server may further include:
  • the receiving unit 1102 is configured to receive a data update response message sent by the mobility management network element, where the data update response message includes the access type, where the data update response message is an insertion subscription data response message, and a push subscription response. A message or a user data response message is inserted.
  • the sending unit 1101 may: after the subscription data of the UE is updated, the international mobile subscriber identity IMSI of the UE, the updated subscription data of the UE, and the updated subscription data.
  • the corresponding access type is sent to the mobility management network element, so that the mobility management network element can determine the target gateway according to the access type corresponding to the updated subscription data of the UE, and implement the subscription of the update of the UE.
  • the data is updated to the target gateway, and the updated subscription data of the UE is updated to the P-GW through the target gateway, thereby implementing update of the user subscription data, and ensuring that the subscription data of the UE is used normally.
  • the embodiment of the present invention provides a mobility management network element 120.
  • the mobility management network element 120 supports authentication of a non-3GPP access network.
  • the mobility management network element 120 includes a receiving unit 1201 and a sending unit 1202.
  • the mobility management network element 120 may be a mobility management network element in the method embodiment corresponding to FIG. 7;
  • the receiving unit 1201 is configured to receive a data update request message that is sent by the home subscriber server HSS after the subscription data of the user equipment UE is updated, where the data update request message includes an International Mobile Subscriber Identity (IMSI) of the UE, The updated subscription data of the UE; wherein the data update request message is an insertion subscription data message, a push subscription request message, or an insertion user data message;
  • IMSI International Mobile Subscriber Identity
  • the sending unit 1202 is configured to send, according to the data update request message, a bearer modification command to an S-GW connected to the mobility management network element, and to all non-3GPPs connected to the mobility management network element.
  • the access gateway sends a user subscription data update message, where the bearer modification command and the user subscription data update message both include updated subscription data of the UE and an IMSI of the UE.
  • the mobility management network element 120 supports the authentication authorization function of the non-3GPP access network. Therefore, when updating the subscription data, the HSS may only send the information to the mobility management network element 120. Transmitted by the transmitting unit 1202 of the mobility management network element 120 to the S-GW and all non-3GPP access gateways, so that the S-GW and the non-3GPP access gateway can update the updated subscription data to the corresponding P-GW, thereby realizing Update of contract data.
  • FIG. 13 is a computer processing device according to an embodiment of the present invention.
  • the device may include:
  • the processor 1301, the memory 1302, and the communication interface 1305 are connected by a bus 1304 and complete communication with each other.
  • Processor 1301 may be a single core or multi-core central processing unit, or a particular integrated circuit, or one or more integrated circuits configured to implement embodiments of the present invention.
  • the memory 1302 may be a high speed RAM memory or a non-volatile memory such as at least one disk memory.
  • Memory 1302 is for computer execution instructions 1303. Specifically, the program code may be included in the computer execution instruction 1303.
  • the processor 1301 runs the computer execution instruction 1303, and may execute the method flow of the method embodiment corresponding to any one of FIG. 3 to FIG.
  • the device may be a non-3GPP access gateway (such as ePDG or TWAN or HSGW) or a mobility management network element (such as MME or SGSN).
  • the apparatus may be a mobility management network element (such as MME or SGSN) or an HSS; when performing the update subscription data described in FIG.
  • the method may be a mobility management network element (such as an MME or an SGSN).
  • the embodiment of the present invention provides a computer readable medium, including a computer executing instruction, when the processor of the computer executes the computer to execute an instruction, the computer performs the access in the wireless communication network in FIG. 3 or FIG. method.
  • the embodiment of the present invention provides a computer readable medium, comprising: computer executed instructions for executing, by a processor of a computer, the wireless communication of any one of FIG. 5 to FIG. Access method in the network.
  • the embodiment of the present invention provides an access system, which includes: an access gateway 80 and a mobility management network element 90; actions performed by the access gateway 80 and the mobility management network element 90, and interactions between them,
  • an access system which includes: an access gateway 80 and a mobility management network element 90; actions performed by the access gateway 80 and the mobility management network element 90, and interactions between them.
  • the embodiment of the present invention provides an access system, which includes: a mobility management network element 100 and a home subscriber server 110; actions performed by the mobility management network element 100 and the home subscriber server 110, and interactions between them,
  • an access system which includes: a mobility management network element 100 and a home subscriber server 110; actions performed by the mobility management network element 100 and the home subscriber server 110, and interactions between them.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present invention contributes in essence or to the prior art, or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium.
  • a number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .
  • the disclosed systems, devices, and methods may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, or an electrical, mechanical or other form of connection.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the embodiments of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Databases & Information Systems (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例提供了一种无线通信网络中的接入方法,能够将3GPP AAA Server的非3GPP接入网的鉴权授权功能融合到移动性管理网元中,从而非3GPP接入网关在UE接入非3GPP接入网之后,可以选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元为目标移动性管理网元,并请求所述目标移动性管理网元对所述UE进行鉴权与授权,在对所述UE进行鉴权与授权之后,该非3GPP接入网关可以为所述UE选择P-GW,并为所述UE建立自身与所述选择的P-GW之间PDN连接,实现了所述UE从所述非3GPP接入网接入到EPC网络。

Description

一种无线通信网络中的接入方法、相关装置及*** 技术领域
本发明涉及通信技术领域,具体涉及一种无线通信网络中的接入方法、相关装置及***。
背景技术
为了应对无线宽带技术的挑战,保持第三代伙伴计划(3rd Generation Partnership Project,3GPP)网络的领先优势,3GPP在2004年底制定了移动通信网络的长期演进(Long Term Evolution,LTE)计划,在此演进计划的指导下,定义了新的移动通信网络架构,如图1所示。该架构比第二代(Second Generation,2G)网络和第三代(Third Generation,3G)网络更加扁平化,并且只保留了分组交换(Packet Switching,PS)域,因此可以称为演进的3GPP分组交换域(Evolved 3GPP Packet Switched Domain),也可称之为演进的分组***(Evolved Packet System,EPS)。
该新的移动通信网络的核心网即演进的分组核心网(Evolved Packet Core Network,EPC)不但支持3GPP接入技术,还支持非3GPP(Non 3GPP)接入技术,如码分多址2000(Code Division Multiple Access 2000,CDMA2000)、全球微波互联接入(Worldwide Interoperability for Microwave Access,WiMAX)和无线局域网络(Wireless Local Area Networks,WLAN)。
在现有网络架构下(如图1所示),用户设备(User Equipment,UE)从非3GPP侧接入EPC时,可以从可信的非3GPP侧接入,还可以从非可信的3GPP侧接入。以UE从非可信的3GPP侧接入(如UE从非可信WLAN接入)为例,演进的分组数据网关(Evolved Packet Data Gateway,ePDG)为该UE的APN选择分组数据网关(Packet Data Network Gateway,P-GW),并向上述选择的P-GW发起分组数据网(Packet Data Network,PDN)连接建立流程;该P-GW将自身的标识(即P-GW ID)通过自身与3GPP鉴权、授权及计费服务器(3GPP Authentication,Authorization,and Accounting Server,3GPP AAA  Server)之间的S6b接口发送给3GPP AAA Server;3GPP AAA Server再将收到的P-GW标识注册到归属用户服务器(home subscriber server/system,HSS),从而实现从非可信的3GPP侧接入。
然而,现有技术中,UE从非3GPP侧接入EPC网络的过程,需要3GPP AAA Server的参与。但后续网络部署时,运营商希望尽量简化网络架构,例如不用单独部署3GPP AAA server,从而节约3GPP AAA相关的几个接口。这样基于现有方案无法实现UE从非3GPP侧的接入,严重影响用户体验。
发明内容
针对现有技术的上述问题,本发明实施例提供一种无线通信网络中的接入方法、相关装置及***,能够适应新的简化的网络架构,实现UE从非3GPP网络接入EPC网络。
第一方面,本发明实施例提供了一种无线通信网络中的接入方法,包括:
在用户设备UE接入到非第三代伙伴计划3GPP接入网之后,非3GPP接入网关为所述UE选择目标移动性管理网元,所述目标移动性管理网元支持所述非3GPP接入网的鉴权授权功能;
所述非3GPP接入网关向所述目标移动性管理网元发送鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
在所述目标移动性管理网元对所述UE进行鉴权与授权成功之后,所述非3GPP接入网关为所述UE的接入点名称APN选择分组数据网关P-GW;
所述非3GPP接入网关为所述UE的APN建立所述非3GPP接入网关与所述选择的P-GW之间的分组数据网PDN连接;
所述非3GPP接入网关通过所述目标移动性管理网元将所述选择的P-GW的标识注册到归属用户服务器HSS。
结合第一方面,在第一种可能的实现方式中,所述非3GPP接入网关为所述UE的接入点名称APN选择分组数据网关P-GW之前,所述方法还包括:
所述非3GPP接入网关确定所述UE的APN。
结合第一方面或者第一方面的第一种可能的实现方式,在第二种可能的实现方式中,所述非3GPP接入网关通过所述目标移动性管理网元将所述选择的 P-GW的标识注册到HSS包括:
所述非3GPP接入网关将所述UE的APN和所述选择的P-GW的标识发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的网络之间互连的协议IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
第二方面,本发明实施例提供了一种无线通信网络中的接入方法,包括:
在用户设备UE接入到非第三代伙伴计划3GPP接入网之后,支持所述非3GPP接入网的鉴权授权功能的移动性管理网元接收非3GPP接入网关发送的鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
所述移动性管理网元根据所述鉴权与授权请求消息,对所述UE进行鉴权与授权;
在对所述UE进行鉴权与授权成功后,所述移动性管理网元接收所述非3GPP接入网关发送的所述UE的接入点名称APN和所述非3GPP接入网关为所述UE的APN选择的分组数据网关P-GW的标识;
所述移动性管理网元将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
第三方面,本发明实施例提供了一种更新签约数据的方法,移动性管理网元接收归属用户服务器HSS在用户设备UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关;
所述移动性管理网元向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
第四方面,本发明实施例提供了一种更新签约数据的方法,其特征在于, 包括:
在用户设备UE的签约数据发生更新后,归属用户服务器HSS向移动性管理网元发送数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,以便所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关并向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI;
其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息。
结合第三方面或者第三方面,在第一种可能的实现方式中,当所述接入类型属于非第三代伙伴计划3GPP的接入技术时,所述目标网关为演进的分组数据网关ePDG、可信无线局域网络接入网络TWAN或者高速分组数据服务网关HSGW,所述移动性管理网元向所述目标网关发送的所述更新消息为用户签约数据更新消息;或者,当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW,所述移动性管理网元向所述目标网关发送的所述更新消息为承载修改命令。
第五方面,本发明实施例提供了一种更新签约数据的方法,其特征在于,包括:
支持非第三代伙伴计划3GPP接入网的鉴权授权功能的移动性管理网元接收归属用户服务器HSS在用户设备UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据;其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
所述移动性管理网元根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令,以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
本发明实施例提供了一种无线通信网络中的接入方法,能够将3GPP AAA  Server的非3GPP接入网的鉴权授权功能融合到移动性管理网元中,从而非3GPP接入网关在UE接入非3GPP接入网之后,可以选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元为目标移动性管理网元,并请求所述目标移动性管理网元对所述UE进行鉴权与授权,在对所述UE进行鉴权与授权之后,该非3GPP接入网关可以为所述UE选择P-GW,并为所述UE建立自身与所述选择的P-GW之间PDN连接,实现了所述UE从所述非3GPP接入网接入到EPC网络。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是一种演进的分组***的***架构示意图;
图2(a)是本发明实施例提供的一种3GPP AAA Server与MME融合的架构的示意图;
图2(b)是本发明实施例提供的又一种3GPP AAA Server与MME融合的架构的示意图;
图3是本发明实施例提供的一种无线通信网络中的接入方法的流程图;
图4是本发明实施例提供的又一种无线通信网络中的接入方法的流程图;
图5是本发明实施例提供的一种更新签约数据的方法的流程图;
图6是本发明实施例提供的又一种更新签约数据的方法的流程图;
图7是本发明实施例提供的又一种更新签约数据的方法的流程图;
图8是本发明实施例提供的一种接入网关的示意图;
图9是本发明实施例提供的一种移动性管理网元的示意图;
图10是本发明实施例提供的又一种移动性管理网元的示意图;
图11是本发明实施例提供的一种归属用户服务器的示意图;
图12是本发明实施例提供的又一种移动性管理网元的示意图;
图13是本发明实施例提供的一种计算机处理装置的组成结构示意图。
具体实施方式
本发明实施例提供一种无线通信网络中的接入方法,能够基于简化的网络架构,实现UE从非3GPP网络的接入,本发明实施例还提供了相应的设备及***。
如图1所示,在现有的网络架构下,核心网EPC主要包括移动性管理实体(Mobility Management Entity,MME)、通用分组无线***(General Packet Radio Service,GPRS)业务支持节点(Serving GPRS Support Node,SGSN)、服务网关(Serving Gateway,S-GW)和P-GW;其中,MME是主要负责与用户设备之间的非接入层(Non-Access Stratum,NAS)信令,为用户设备分配临时身份标识,为3GPP接入的用户设备选择S-GW和P-GW等核心网网元;S-GW是本地eNodeB之间切换的移动性锚点,并提供合法监听相关功能;P-GW主要负责用户地址分配、策略控制和计费规则的执行和以及合法监听相关功能。
当UE从非3GPP网络接入EPC时,UE可以通过可信非3GPP接入网与P-GW之间的接口接入,例如通过可信WLAN接入网络(trusted WLAN access network,TWAN)与P-GW之间的S2a接口接入,还可以通过非可信非3GPP接入网与P-GW之间的接口接入,例如通过ePDG与P-GW之间的S2b接口接入,其中,ePDG/TWAN主要负责转发P-GW分配的UE的移动IP地址,注册UE的本地IP地址,并将UE的移动IP地址和本地IP地址进行绑定。从非3GPP网络接入时,还有一个重要网元是3GPP AAA server,主要负责通过与HSS的交互实现对UE的鉴权授权操作,以及将UE建立的每个PDN连接所用的P-GW标识注册到HSS中,而HSS主要用于存储用户的签约信息。
由于后续网络部署时,运营商希望尽量简化网络架构,例如不用单独部署3GPP AAA server,而将3GPP AAA功能与现有的网元相融合,从而节约3GPP AAA相关的几个接口,这样利用现有技术将无法无法实现UE从非3GPP侧接入EPC网络。有鉴于此,本发明实施例提供了一种无线通信网络中的接入方法,能够将3GPP AAA Server的部分/全部的逻辑功能融合到移动性管理网元中,使得在用户设备UE接入到非第三代伙伴计划3GPP接入网之后,由非3GPP接入网关,即非3GPP网络的接入网关,选择支持所述非3GPP接入网的鉴权授权功能 的移动性管理网元为所述UE进行鉴权与授权,并在PDN连接建立之后,通过所述目标移动性管理网元将所述选择的P-GW的标识注册到归属用户服务器HSS,实现了UE从非3GPP网络接入到EPC网络。
此外,在现有技术中,当用户的签约数据发生更新时,HSS需要将更新的签约数据更新到相应的网关,具体地,如果是通过3GPP网络接入的UE的签约数据更新,则HSS需要通知MME/SGSN,由MME/SGSN将更新的签约数据更新到S-GW;如果是通过非3GPP网络接入的UE的签约数据更新,则HSS需要通知3GPP AAA Server,由3GPP AAA Server将更新的签约数据更新到非3GPP接入网关,如ePDG或者TWAN或者高速分组数据(High Rate Packet Data,HRPD)服务网关(HRPD Serving Gateway,HSGW)。然而基于本发明实施例中提出的3GPP AAA Server与MME融合的架构,现有技术的方案无法实现用户的签约数据的更新,因此,为了解决这个问题,本发明实施例还提出了一种更新签约数据的方法、相关装置及***。
在本发明实施例中,移动性管理网元可以是MME,还可以是SGSN(如GnGp-SGSN或者S4-SGSN);非3GPP接入网关(即非3GPP网络的接入网关,后续为描述方便,简称为非3GPP接入网关)可以是ePDG,还可以是TWAN,或者还可以是HSGW,本发明实施例在此不作限定。
在本发明实施例中,以移动性管理网元为MME,非3GPP接入网关为ePDG为例,提出了一种3GPP AAA Server与MME融合的架构图,如图2(a)和图2(b)所示。将3GPP AAA Server的逻辑功能部署到MME,在MME与HSS之间增加独立的SWx接口,如图2(a)所示,或者将MME与HSS之间的S6a接口升级支持3GPP AAA Server与HSS之间的SWx接口,如图2(b)所示,而ePDG与3GPP AAA Server之间的SWm接口可以部署在MME于ePDG之间,ePDG与3GPP AAA Server之间的S6b接口不再部署,3GPP AAA Server与非可信的3GPP接入网之间的SWa接口也可以不再部署,大大简化了网络架构。
同理,也可以将MME换成SGSN,即将3GPP AAA Server的逻辑功能部署到SGSN,相应地,将MME与HSS之间的S6a接口换成SGSN与HSS之间的S6d接口或者Gr接口(如果支持MAP协议),将MME与S-GW之间的S11接口换成SGSN与S-GW之间的S4即可,图中未示出。
可选地,也可以将ePDG换成TWAN/HSGW,相应地,将ePDG与MME/SGSN之间的SWm接口换成TWAG/HSGW与MME/SGSN之间的STa接口,将ePDG与P-GW之间的S2b接口换成TWAN/HSGW与P-GW之间的S2a接口即可,图中未示出,则TWAN/HSGW与3GPP AAA Server之间的S6b接口不再部署,3GPP AAA Server与可信的3GPP接入网之间的SWa接口也不再部署,大大简化了网络架构。
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述。
如图3所示,本发明实施例提供了一种无线通信网络中的接入方法,可以将3GPP AAA Server的非3GPP接入网的鉴权授权功能融合到移动性管理网元中,实现UE从非3GPP网络接入到EPC网络,具体方法如下。
S301:在UE接入到非3GPP接入网之后,非3GPP接入网关为所述UE选择目标移动性管理网元,所述目标移动性管理网元支持所述非3GPP接入网的鉴权授权功能。
所述目标移动性管理网元为上述融合架构中的移动性管理网元,融合了3GPP AAA Server的非3GPP接入网的鉴权授权功能,例如当所述非3GPP接入网为WALN时,所述目标移动性管理网元支持WALN的鉴权授权功能,能够对从WALN接入的UE进行鉴权与授权。
在本发明各实施例中,移动性管理网元支持非3GPP接入网的鉴权授权功能是指该移动性管理网元能够对从所述非3GPP接入网(如WLAN、CDMA2000或者WiMAX)接入的UE进行鉴权与授权。
S302:所述非3GPP接入网关向所述目标移动性管理网元发送鉴权与授权请求(Authentication and Authorization Request)消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权。
在所述UE接入到非3GPP接入网之后,非3GPP接入网关可以请求对该UE进行鉴权与授权,例如通过非3GPP接入网关与移动性管理网元之间增加的SWm接口或者STa接口发送所述鉴权与授权请求消息。
所述目标移动性管理网元可以根据所述鉴权与授权请求消息,对所述UE 进行鉴权与授权。具体地,例如可以从HSS获取所述UE的签约数据,根据所述UE的签约数据,对所述UE进行授权;所述目标移动性管理网元还可以从HSS获取所述UE的鉴权向量,利用所述UE的鉴权向量进行鉴权,上述鉴权可以包括网络侧(即目标性移动管理网元)对所述UE进行鉴权和所述UE对网络侧进行鉴权,也可以只包括网络侧对所述UE进行鉴权,本发明实施例在此不作限定。如果所述目标移动性管理网元对所述UE进行鉴权与授权成功之后,可以向所述UE返回鉴权与授权成功消息。上述鉴权与授权流程与现有技术中3GPP AAA Server对UE进行鉴权与授权的流程类似,本发明实施例在此不再赘述。
需要说明的是,在本发明各实施例中,如果所述UE在接入到所述非3GPP接入网之前,接入到了3GPP接入网,执行了鉴权流程且鉴权成功,则所述目标移动性管理网元对所述UE进行鉴权与授权可以是指,只对所述UE进行授权,而不再对所述UE进行鉴权。
S303:所述非3GPP接入网关为所述UE的APN选择P-GW。
在所述目标移动性管理网元对所述UE进行鉴权与授权成功之后,所述非3GPP接入网关可以为所述UE的APN选择P-GW。
在对所述UE的APN选择P-GW之前,所述非3GPP接入网关还可以确定所述UE的APN。确定所述UE的APN以及为所述APN选择P-GW的方式,可以参考下一实施例中所述的方式,本发明实施例在此不作限定。
S304:所述非3GPP接入网关为所述UE的APN建立所述非3GPP接入网关与所述选择的P-GW之间的PDN连接。
S305:所述非3GPP接入网关通过所述目标移动性管理网元将所述选择的P-GW的标识注册到HSS。
所述非3GPP接入网关可以将所述UE的APN和所述选择的P-GW的标识发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息(Notify Request)或者非3GPP的IP接入注册请求(Non-3GPP IP Access Registration request)消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS,实现P-GW的标识的注册,实现了所述UE从非3GPP接入网接入到EPC网络。
在本发明实施例中,将3GPP AAA Server的非3GPP接入网的鉴权授权功能 融合到移动性管理网元中,从而非3GPP接入网关在UE接入非3GPP接入网之后,可以选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元为目标移动性管理网元,并请求所述目标移动性管理网元对所述UE进行鉴权与授权,在对所述UE进行鉴权与授权之后,该非3GPP接入网关可以为所述UE选择P-GW,并为所述UE建立自身与所述选择的P-GW之间PDN连接,实现了所述UE从所述非3GPP接入网接入到EPC网络。
可选地,S301中,在确定目标移动性管理网元时可以有多种方式,例如,所述非3GPP接入网关根据预配置信息,选择所述目标移动性管理网元;其中,所述预配置信息包含所述UE的位置信息与所述目标移动性管理网元的标识的对应关系,或者所述预配置信息包含所述非3GPP接入网关的标识与所述目标移动性管理网元的标识的对应关系;
或者,所述非3GPP接入网关将所述UE的国际移动用户识别码(International Mobile Subscriber Identification Number,IMSI)发送给路由代理节点(Diameter Routing Agent,DRA),以便所述DRA根据所述UE的IMSI为所述UE选择所述目标移动性管理网元;
或者,所述非3GPP接入网关根据所述UE的位置信息,构造移动性管理网元的完全合格域名(Fully Qualified Domain Name,FQDN),并将所述FQDN发送给域名解析服务器(Domain Name Server or Domain Name System,DNS),从而所述DNS可以根据所述完全合格域确定移动性管理网元,接收所述DNS根据所述FQDN确定的移动性管理网元的标识,从所述DNS确定的移动性管理网元中选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元作为所述目标移动性管理网元,由于所述目标移动性管理网元是根据UE的位置信息构造的完全合格域名所确定的,因此可以使得选择的目标移动性管理网元的位置靠近UE。
需要说明的是,上述实施例中,所述目标移动性管理网元与所述HSS进行交互时,可以使用现有架构下移动性管理网元与HSS之间的3GPP的接口,如使用图2(b)中的S6a接口,则此时所述HSS可以不感知网元架构的变化,也无需对所述HSS进行改进;还可以使用融合架构下在移动性管理网元与HSS之间新增的非3GPP的接口,如使用图2(a)中的SWx接口,则此时所述HSS可 以感知网元架构的变化。
由于在本发明实施例中,对应从3GPP网络接入的UE和从非3GPP网络接入的UE,都需要利用移动性管理网元与HSS进行交互,所述HSS难以确定P-GW的标识和APN等交互的信息是来自接入3GPP网络的UE还是非3GPP网络的UE。从而,在本发明实施例中,所述非3GPP接入网关还可以确定所述UE的接入类型(RAT type),所述UE的接入类型可以用于指示所述UE采用的何种接入技术接入的,例如,当所述UE是通过无线局域网络(Wireless Local Area Networks,WLAN)接入时,所述接入类型信息可以设置为WLAN,或可信WLAN或非可信WLAN等;所述非3GPP接入网关可以将所述UE的接入类型与所述UE的APN和所述选择的P-GW的标识一起发送给所述目标移动性管理网元,以便所述目标移动性管理网元将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述HSS,从而所述HSS可以将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型及其它们之间的对应关系保存起来。此外,所述非3GPP接入网关也可以不确定所述UE的接入类型,而由所述移动性管理网元直接确定所述UE的接入类型,本发明实施例在此不作限定。
下面以移动性管理网元为MME,非3GPP接入网关为ePDG为例,进行说明,当移动性管理网元为SGSN或者非3GPP接入网关为TWAN/HSGW时,也可以参考如下方法进行UE从非3GPP侧的接入流程,本发明实施例在此不再赘述。结合图2(a)所述的网络架构,本发明实施例提供了一种P-GW的选择方法,如图4所示。
S401:UE接入WLAN接入网后,执行所述WLAN接入网的鉴权与授权流程。
UE在接入WLAN接入网后,可以与WLAN的接入网关ePDG进行信令交互,执行WLAN接入网的鉴权与授权流程。S401为可选步骤。
S402:所述UE向ePDG发起IKEv2鉴权和通道建立(Internet Key Exchange Version 2Authentication and Tunnel Setup,IKEv2Authentication and Tunnel Setup)流程。
所述UE接入WLAN接入网后,可以选择ePDG,并向该ePDG发起IKEv2 鉴权和通道建立流程,以请求对所述UE进行鉴权,并且为所述UE建立PDN连接。
S403:所述ePDG选择支持WLAN的鉴权授权功能的目标MME。
所述ePDG可以根据预配置信息,选择支持WLAN的鉴权授权功能的目标MME,从而对所述UE进行鉴权与授权。例如,所述预配置信息中可包含位置信息与MME之间的对应关系,所述ePDG可以根据所述UE的位置信息,确定所述预配置信息中与所述UE的位置信息对应的MME,并将其作为目标MME。或者,所述预配置信息中可以指定与所述ePDG对应的MME,将所述预配置信息中与所述ePDG对应的MME作为目标MME,从而所述ePDG可以为连接到自己的UE都选择相同的MME。
或者,还可以预先在DRA中配置IMSI与MME的对应关系,例如某段范围的IMSI对应哪个MME或者某个IMSI与其使用过的MME的对应关系等,从而所述ePDG可以将所述UE的IMSI发送给DRA,由DRA根据所述UE的IMSI,确定所述UE的目标MME。
或者,所述ePDG可以根据所述UE的位置信息,构造FQDN,并将所述FQDN发送给DNS,接收所述DNS根据所述FQDN确定的MME的标识,从所述DNS确定的MME中选择支持WLAN的鉴权授权功能的MME作为所述目标MME,从而可以选择离所述UE较近的MME作为目标MME
需要注意的是,上述目标MME支持WLAN的鉴权授权功能。
S404:所述ePDG向所述目标MME发送鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权。
当所述非3GPP接入网关不为ePDG,例如为TWAN或者HSGW时,所述非3GPP接入网关也可以采用上述方法进行目标MME的选择,也可以通过鉴权与授权请求消息请求对所述UE进行鉴权与授权。
S405:所述目标MME通过SWx接口向HSS发送鉴权请求消息(authentication request),所述鉴权请求消息用以请求获取所述UE的鉴权向量。
S405之前,所述目标MME可以获取所述UE的签约数据,对所述UE进行授权。
S406:所述HSS通过SWx接口向所述MME返回鉴权响应消息(authentication response),所述鉴权响应消息中包含所述UE的鉴权向量。
S407:所述目标MME利用所述UE的鉴权向量,对所述UE进行鉴权。
上述鉴权流程与现有技术中3GPP AAA Server对UE进行鉴权与授权的流程类似,本发明实施例在此不再赘述。
S408:所述ePDG确定所述UE的APN,并为所述UE的APN选择P-GW。
在上述鉴权与授权成功后,所述ePDG可以确定所述UE的APN。如果所述UE请求了APN,且所述UE的签约数据中包含了所述UE请求的APN,则所述ePDG可以将所述UE请求的APN作为所述UE的APN,如果所述UE请求了APN,所述UE的签约数据中不包含所述UE请求的APN,则所述ePDG可以拒绝该鉴权与授权请求;如果所述UE没有请求,,所述ePDG可以使用所述UE的签约数据中的缺省APN作为所述UE的APN。
在进行P-GW的选择时,如果所述ePDG确定所述UE是通过初始附着(initial attach)流程接入的,则所述ePDG可以基于所述UE的APN,选择P-GW;例如,所述ePDG可以将目标APN发送给DNS服务器,所述DNS服务器可以向所述ePDG返回能够连接该目标APN的P-GW列表(PGW list或者P-GW list),所述ePDG可以从该P-GW列表中选择合适的P-GW。如果所述ePDG确定所述UE是通过多接入流程(multiple access)或者切换(handover)流程接入的,则所述ePDG可以使用所述UE的签约数据中的APN所对应的P-GW作为所述选择的P-GW。
S409:所述ePDG为所述UE的APN建立所述ePDG与所述选择的P-GW之间的PDN连接。
S410:所述ePDG向所述目标MME发送授权请求消息,所述授权请求消息中包括所述UE的APN和所述选择的PGW的标识。
不同于现有技术中P-GW将自身的标识通过3GPP AAA Sever注册到HSS的方案,在本发明实施例中,3GPP AAA Sever不再部署,且P-GW与所述目标MME之间没有接口,因此可以由ePDG将所述选择的P-GW的标识通过所述目标MME注册到HSS,从而保证UE在3GPP网络与非3GPP网络之间切换时使用相同的P-GW,保证了业务的连续性。
S411a:所述目标MME通过SWx接口向所述HSS发送非3GPP IP接入注册请求(Non 3GPP Internet Protocol Access Registration request)消息,所述非3GPP IP接入注册请求消息中包含所述UE的APN和所述选择的PGW的标识,以将所述P-GW的标识注册到所述HSS。
在本发明实施例中,UE从非3GPP侧接入后的鉴权与授权以及P-GW的注册均通过MME与HSS之间的SWx接口进行,而UE从3GPP侧接入后的信令交互仍然采用现有技术中MME与HSS之间的S6a接口进行,从而HSS通过接受到的消息的接口,就可以判断该消息是来自3GPP网络还是非3GPP网络。例如,如果从SWx接口接收到MME发送的P-GW的标识和APN,则可以确定该P-GW的标识和APN是用于从非3GPP网络接入的UE,如果从S6a接口接收到MME发送的P-GW的标识和APN,则可以确定该P-GW的标识和APN是用于从3GPP网络接入的UE。
可选地,S411也可替换为:
S411b:所述目标MME通过S6a接口向所述HSS发送通知消息(Notify Request),所述通知消息中包含所述UE的APN和所述选择的PGW的标识,以将所述P-GW的标识注册到所述HSS。
如果采用S411b所述的方法,则说明UE从非3GPP侧接入后的鉴权与授权是通过MME与HSS之间的SWx接口进行,而P-GW的注册是通过MME与HSS之间的S6a接口进行,则HSS无法通过接受到的消息的接口判断该消息是来自3GPP网络还是非3GPP网络。
可选地,所述通知消息中还可以包含所述UE的接入类型,所述接入类型用于指示所述UE是采用何种接入技术接入的,例如当所述UE从WLAN接入时,所述UE的接入类型可以是WLAN、可信WLAN或者非可信WLAN。从而所述HSS根据所述接入类型,可以确定所述UE的APN和所述选择的PGW的标识是为了3GPP网络还是非3GPP网络。
需要说明的是,当所述移动性管理网元不为MME,例如为SGSN时,注册所述选择的P-GW的标识时,既可以采用S411所述的方法,也可以采用S411’所述的方法,只是采用S411’的方法时,所述通知消息是通过移动性管理网元与HSS之间的3GPP接口传输,如SGSN与HSS之间的S6d接口或者Gr接口。
S412:所述UE与所述ePDG之间进行IP安全隧道建立(IPSec Tunnel Setup)。
当IP安全隧道建立完成后,所述ePDG可以通知所述UE IP安全隧道建立完成,并将所述PDN连接的IP地址发送给UE。
上述实施例中,采用的是(a)所示的架构,当采用(b)所示的框架时,由于没有增加SWx接口,是对S6a接口进行了增强,因此只需将S405与S406中通过SWx接口发送鉴权请求消息和鉴权响应消息改成通过S6a接口发送,并将S411a替换成S411b,即通过S6a接口向所述HSS发送通知消息来将所述选择的P-GW的标识注册到HSS,同理,所述通知消息中还可以包含所述UE的接入类型。
在上述3GPP AAA Server与移动性管理网元的融合架构下,为了实现UE的签约数据的更新,本发明实施例提出了一种更新签约数据的方法,所述方法包括:
S501:支持非3GPP接入网的鉴权授权功能的移动性管理网元接收HSS在UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更新请求消息为***签约数据消息(Insert Subscription Data)、推送签约请求消息(Push Profile Request)或者***用户数据消息(Insert Subscriber Data)。
所述HSS中保存有UE的签约数据,由于针对不同的接入技术可能使用不同的签约数据,因而在签约数据更新时,需要将更新的签约数据对应的接入类型也发送给移动性管理网元,从而移动性管理网元可以根据所述接入类型,确定目标网关,将所述更新的签约数据发送给对应的目标网关。
S502:所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关。
当所述接入类型属于非3GPP的接入技术时,所述目标网关为非3GPP接入网关,如ePDG/TWAN/HSGW。或者,当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW。
S503:所述移动性管理网元向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
所述目标网关为非3GPP接入网关,则所述更新消息可以为用户签约数据更新(User Profile Update)消息,所述目标网关为S-GW时,所述更新消息可以为承载修改命令(Modify Bearer Command)。
所述目标网关在收到所述更新消息后,不仅可以自身更新所述UE的签约数据,还可以将所述UE的更新的签约数据发送给相应的P-GW,使得P-GW也更新UE的签约数据。
可选地,所述移动性管理网元在接收到所述数据更新请求消息之后,还可以向所述HSS发送数据更新响应消息,所述数据更新响应消息包含所述接入类型,所述数据更新响应消息可以为***签约数据响应消息、推送签约响应消息或者***用户数据响应消息。
在本发明实施例中,移动性管理网元可以根据所述UE的更新的签约数据对应的接入类型,确定目标网关,从而实现将所述UE的更新的签约数据更新到所述目标网关以及通过目标网关将所述所述UE的更新的签约数据更新到P-GW,实现了用户签约数据的更新,保证了UE的签约数据被正常使用。
下面以移动性管理网元为MME,非3GPP接入网关为ePDG为例,对本发明实施例提供的更新签约数据的方法进行说明,如图6所示。当移动性管理网元为SGSN或者非3GPP接入网关为TWAN/HSGW时,也可以参考如下方法签约数据的更新,本发明实施例在此不再赘述。
S601:HSS向MME发送***签约数据消息,所述***签约数据消息包含所述UE的IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述接入类型为WLAN。
由于针对不同的接入技术可能使用不同的签约数据,因而在签约数据更新时,需要将更新的签约数据对应的接入类型也发送给MME,从而MME可以根据所述接入类型,确定目标网关,将所述更新的签约数据发送给对应的目标网关。
所述HSS可以通过其与所述MME之间的S6a接口发送所述签约数据消息。
可选地,所述HSS还可以通过SWx接口利用推送签约请求消息将所述UE的IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型发送给所述MME。
需要说明的是,如果移动性管理网元为SGSN,则所述HSS即可以SWx接口利用推送签约请求消息将所述UE的IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型发送给SGSN,又可以通过S6d接口或者Gr接口利用***用户数据消息,将上述信息发送给SGSN。
S602:所述MME根据所述接入类型,确定与所述接入类型对应的目标网关为ePDG。
S603:所述MME向所述ePDG发送用户签约数据更新消息,所述用户签约数据更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
需要说明的是,当与所述接入类型对应的目标网关不为ePDG,为TWAN或者HSGW时,所述MME也可以利用所述用户签约数据更新消息将所述UE的更新的签约数据和所述UE的IMSI发送给TWAN或者HSGW。
S604:所述ePDG根据所述用户签约数据更新消息,向所述MME返回用户签约数据更新确认(User Profile Update Ack)消息。
所述用户签约数据更新确认消息中可以包含所述UE的IMSI。
S605:所述MME向所述HSS返回***签约数据响应(Insert Subscription Data Ack)消息,***签约数据响应消息中包含所述接入类型。
所述MME返回的***签约数据响应消息中包含所述接入类型,或者还可以包含所述UE的IMSI,以便所述HSS根据所述***签约数据响应消息中包含的信息,可以确定是哪个***签约数据消息的响应消息,即确定是哪个UE的哪个签约数据更新成功。
S606:所述ePDG向P-GW发送更改承载命令(Modify Bearer Command),所述更改承载命令中包含所述更新的签约数据,以将所述更新的签约数据更新到所述P-GW。
需要说明的是,S604和S606的执行无顺序关系,既可以先执行S604,再执行S606,也可以先执行S606再执行S604。
在上述实施例中,针对不同的接入技术具有相应的签约数据,而在某些情况下,针对不同的接入技术也可以采用相同的签约数据,因而UE的签约数据发生更新时,需要更新到3GPP网络和非3GPP网络,有鉴于此,本发明实施例还提出了一种更新签约数据的方法,如图7所示,所述方法包括:
S701:支持非3GPP接入网的鉴权授权功能的移动性管理网元接收HSS在UE的签约数据发生更新后发送的请求消息,所述数据更新请求消息中包含所述UE的IMSI、所述UE的更新的签约数据,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息。
S702:所述移动性管理网元根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令,以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
所述S-GW可以根据所述承载修改命令,更新所述UE的签约数据,所述S-GW还可以将所述UE的更新的签约数据更新到相应的P-GW。所述非3GPP接入网关也可以根据用户签约数据更新消息,更新所述UE的签约数据,或者还可以将所述UE的更新的签约数据更新到相应的P-GW。其中,所述非3GPP接入网关可以为ePDG、TWAN或者HSGW。
在本发明实施例中,在融合的架构下,移动性管理网元支持非3GPP接入网的鉴权授权功能,因而HSS在更新签约数据时,可以只发送给移动性管理网元,由移动性管理网元发送给S-GW和所有非3GPP接入网关,从而S-GW和非3GPP接入网关可以将更新的签约数据更新到相应的P-GW,实现了签约数据的更新。
需要说明的是,图5-图7任意之一对应的实施例所述的更新签约数据的方法,可以与图3或图4对应的方法实施例所述的无线通信网络中的接入方法结合使用,本发明实施例在此不再赘述。
图3或图4对应方法实施例中的所述的无线通信网络中的接入方法,本发 明实施例提供了一种接入网关80,如图8所示,所述接入网关80为非第三代伙伴计划3GPP网的接入网关,所述接入网关80包括第一选择单元801、发送单元802、第二选择单元803和建立单元804;所述接入网关80可以是图3对应方法实施例中的非3GPP接入网关,也可以是图4对应方法实施例中的ePDG。
所述第一选择单元801,用于在用户设备UE接入到非3GPP接入网之后,为所述UE选择目标移动性管理网元,所述目标移动性管理网元支持所述非3GPP接入网的鉴权授权功能;
所述发送单元802,用于向所述目标移动性管理网元发送鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
所述第二选择单元803,用于为所述UE的APN选择分组数据网关P-GW;
所述建立单元804,用于在所述目标移动性管理网元对所述UE进行鉴权与授权成功之后,为所述UE的APN建立所述非3GPP接入网关与所述选择的P-GW之间的PDN连接;
所述发送单元802还用于通过所述目标移动性管理网元将所述选择的P-GW的标识注册到归属用户服务器HSS,例如将所述UE的APN和所述选择的P-GW的标识发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
可选地,所述第二选择单元803还可以用于确定所述UE的接入类型;则所述发送单元802具体可以将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述HSS。
可选地,所述第一选择单元801为所述UE选择目标移动性管理网元时,可以是所述第一选择单元801根据预配置信息,选择所述目标移动性管理网元;其中,所述预配置信息包含所述UE的位置信息与所述目标移动性管理网元的标识的对应关系,或者所述预配置信息包含所述非3GPP接入网关的标识与所述目标移动性管理网元的标识的对应关系;
或者,所述第一选择单元801将所述UE的国际移动用户识别码IMSI发送给路由代理节点,以便所述路由代理节点根据所述UE的IMSI为所述UE选择所述目标移动性管理网元;
或者,所述第一选择单元801根据所述UE的位置信息构造移动性管理网元的完全合格域名,并将所述完全合格域名发送给域名解析服务器DNS,接收所述DNS根据所述完全合格域名确定的移动性管理网元的标识,从所述DNS确定的移动性管理网元中选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元作为所述目标移动性管理网元。
本发明实施例中,将3GPP AAA Server的非3GPP接入网的鉴权授权功能融合到移动性管理网元中,从而非3GPP网络的接入网关80中的第一选择单元801可以在UE接入非3GPP接入网之后,选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元为目标移动性管理网元,所述发送单元802可以通过鉴权与授权请求消息并请求所述目标移动性管理网元对所述UE进行鉴权与授权,在对所述UE进行鉴权与授权之后,所述第二选择单元803可以为所述UE选择P-GW,所述建立单元804为所述UE建立自身与所述选择的P-GW之间PDN连接,实现了所述UE从所述非3GPP接入网接入到EPC网络。
对应图3或图4所述的无线通信网络中的接入方法,本发明实施例提供了一种移动性管理网元90,如图9所示,所述移动性管理网元90支持非3GPP接入网的鉴权授权功能;所述移动性管理网元90包括接收单元901、鉴权授权单元902和发送单元903;所述移动性管理网元90可以是图3对应方法实施例中的移动性管理网元,也可以是图4对应方法实施例中的MME。
所述接收单元901,用于在用户设备UE接入到所述非3GPP接入网之后,接收非3GPP接入网关发送的鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
所述鉴权授权单元发送单元903,用于根据所述鉴权与授权请求消息,对所述UE进行鉴权与授权;
所述接收单元901还用于在所述鉴权授权单元对所述UE进行鉴权与授权成功后,接收所述非3GPP接入网关发送的所述UE的接入点名称APN和所述非 3GPP接入网关为所述UE的APN选择的分组数据网关P-GW的标识;
所述发送单元903还用于将所述UE的APN和所述选择的P-GW的标识发送给所述HSS,从而实现P-GW标识的注册。可选地,所述发送单元903具体可以通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
可选地,所述接收单元901还用于接收所述HSS返回的鉴权响应消息,所述鉴权响应消息中包含所述UE的鉴权向量;所述发送单元903还用于用于利用所述UE的鉴权向量向所述UE发送鉴权请求消息。
可选地,所述移动性管理网元90还可以包括:
获取单元904,用于确定所述UE的接入类型或者接收所述非3GPP接入网关发送的所述UE的接入类型;则所述发送单元903可以通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述HSS。从而所述HSS根据所述接入类型,可以确定所述UE的APN和所述选择的PGW的标识是为了3GPP网络还是非3GPP网络。
可选地,所述HSS中保存有UE的签约数据,针对不同的接入技术可能采用相同的签约数据,在签约数据更新时,所述HSS需要将更新的签约数据更新到对应的网元。从而,所述接收单元901可以还用于接收所述HSS在所述UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;所述发送单元903还可以用于根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
可选地,针对不同的接入技术可能使用不同的签约数据,在签约数据更新时,所述HSS需要将更新的签约数据更新到对应的网元。所述接收单元901还可以用于接收所述HSS在所述UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更 新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;所述移动性管理网元还可以包括确定单元905,用于根据所述数据更新请求消息,确定与所述接入类型对应的目标网关;所述发送单元903还可以向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
本发明实施例中,将3GPP AAA Server的非3GPP接入网的鉴权授权功能融合到移动性管理网元90中,从而非3GPP接入网关在UE接入非3GPP接入网之后,可以选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元90为目标移动性管理网元,所述移动性管理网元90的接收单元901可以接收非3GPP接入网关发送的鉴权与授权请求消息,所述发送单元903可以利用所述UE的鉴权向量向所述UE发起鉴权流程,所述接收单元901还可以接收所述非3GPP接入网关发送的所述UE的接入点名称APN和所述非3GPP接入网关为所述UE的APN选择的P-GW的标识,所述发送单元903还用于将所述UE的APN和所述选择的P-GW的标识发送给所述HSS,实现了所述UE从所述非3GPP接入网接入到EPC网络。
对应图5或图6所述的更新签约数据的方法,本发明实施例提供了一种移动性管理网元100,如图10所示,所述移动性管理网元100包括接收单元1001、确定单元1002和发送单元1003;所述移动性管理网元100可以是图5对应方法实施例中的移动性管理网元,也可以是图6对应方法实施例中的MME。
其中,所述接收单元1001,用于接收HSS在UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
所述确定单元1002,用于根据所述数据更新请求消息,确定与所述接入类型对应的目标网关;
所述发送单元1003,用于向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
可选地,当所述接入类型属于非第三代伙伴计划3GPP的接入技术时,所述目标网关为ePDG、可信无线局域网络接入网络TWAN或者高速分组数据服务网关HSGW,所述移动性管理网元向所述目标网关发送的所述更新消息为用户签约数据更新消息;或者,当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW,所述移动性管理网元向所述目标网关发送的所述更新消息为承载修改命令。
可选地,所述发送单元1003还用于向所述HSS发送数据更新响应消息,所述数据更新响应消息包含所述接入类型,所述数据更新响应消息为***签约数据响应消息、推送签约响应消息或者***用户数据响应消息。
在本发明实施例中,确定单元1002可以根据所述UE的更新的签约数据对应的接入类型,确定目标网关,从而所述发送单元1003可以将所述UE的更新的签约数据更新到所述目标网关以及通过目标网关将所述所述UE的更新的签约数据更新到P-GW,实现了用户签约数据的更新,保证了UE的签约数据被正常使用。
对应图5或图6所述的更新签约数据的方法,本发明实施例提供了归属用户服务器110,如图11所示,所述归属用户服务器110包括发送单元1101;所述归属用户服务器110可以是图5对应方法实施例中的HSS,也可以是图6对应方法实施例中的HSS;
其中,所述发送单元1101,用于在用户设备UE的签约数据发生更新后,向移动性管理网元发送数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,以便所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关并向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI;其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息。
可选地,当所述接入类型属于非第三代伙伴计划3GPP的接入技术时,所述目标网关为ePDG、可信无线局域网络接入网络TWAN或者高速分组数据服 务网关HSGW,所述移动性管理网元向所述目标网关发送的所述更新消息为用户签约数据更新消息;或者,当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW,所述移动性管理网元向所述目标网关发送的所述更新消息为承载修改命令。
可选地,所述归属用户服务器,还可以包括:
接收单元1102,用于接收所述移动性管理网元发送的数据更新响应消息,所述数据更新响应消息包含所述接入类型,所述数据更新响应消息为***签约数据响应消息、推送签约响应消息或者***用户数据响应消息。
在本发明实施例中,所述发送单元1101可以在UE的签约数据发生更新后,可以将所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型发送给移动性管理网元,从而所述移动性管理网元可以根据所述UE的更新的签约数据对应的接入类型,确定目标网关,实现将所述UE的更新的签约数据更新到所述目标网关以及通过目标网关将所述所述UE的更新的签约数据更新到P-GW,进而实现用户签约数据的更新,保证了UE的签约数据被正常使用。
对应图7所述的更新签约数据的方法,本发明实施例提供了一种移动性管理网元120,如图12所示,所述移动性管理网元120支持非3GPP接入网的鉴权授权功能;所述移动性管理网元120包括接收单元1201和发送单元1202;所述移动性管理网元120可以是图7对应方法实施例中的移动性管理网元;
其中,所述接收单元1201,用于接收归属用户服务器HSS在用户设备UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据;其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
所述发送单元1202,用于根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令,以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
在本发明实施例中,在融合的架构下,移动性管理网元120支持非3GPP接入网的鉴权授权功能,因而HSS在更新签约数据时,可以只发送给移动性管理网元120,由移动性管理网元120的发送单元1202发送给S-GW和所有非3GPP接入网关,从而S-GW和非3GPP接入网关可以将更新的签约数据更新到相应的P-GW,实现了签约数据的更新。
如图13,为本发明实施例提供的一种计算机处理装置,所述装置可以包括:
处理器1301、存储器1302、总线1304和通信接口1305。处理器1301、存储器1302和通信接口1305之间通过总线1304连接并完成相互间的通信。
处理器1301可能为单核或多核中央处理单元,或者为特定集成电路,或者为被配置成实施本发明实施例的一个或多个集成电路。
存储器1302可以为高速RAM存储器,也可以为非易失性存储器(non-volatile memory),例如至少一个磁盘存储器。
存储器1302用于计算机执行指令1303。具体的,计算机执行指令1303中可以包括程序代码。
当所述装置运行时,处理器1301运行计算机执行指令1303,可以执行图3至图7任意之一对应的方法实施例的方法流程。当执行图3或者图4中所述的无线通信网络中的接入方法时,所述装置可以为非3GPP接入网关(如ePDG或者TWAN或者HSGW)或者移动性管理网元(如MME或者SGSN);当执行图5或者图6中所述的更新签约数据的方法时,所述装置可以为移动性管理网元(如MME或者SGSN)或者HSS;当执行图6中所述的更新签约数据的方法时,所述装置可以为移动性管理网元(如MME或者SGSN)。
本发明实施例提供了一种计算机可读介质,包括计算机执行指令,以供计算机的处理器执行所述计算机执行指令时,所述计算机执行图3或者图4中的无线通信网络中的接入方法。
本发明实施例提供了一种计算机可读介质,包括计算机执行指令,以供计算机的处理器执行所述计算机执行指令时,所述计算机执行图5至图7中任意之一所述的无线通信网络中的接入方法。
本发明实施例提供了一种接入***,该***包括:接入网关80和移动性管理网元90;接入网关80和移动性管理网元90各自执行的动作以及它们之间的交互,可以参见图3和图4对应的方法实施例的描述,也可以参考图8和图9对应的装置实施例的描述。
本发明实施例提供了一种接入***,该***包括:移动性管理网元100和归属用户服务器110;移动性管理网元100和归属用户服务器110各自执行的动作以及它们之间的交互,可以参见图5和图6对应的方法实施例的描述,也可以参考图10和图11对应的装置实施例的描述。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以是两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分,或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、计算机软件或者二者的结合来实现,为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地描述了各示例的组成及步骤。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本发明的范 围。
所属领域的技术人员可以清楚地了解到,为了描述的方便和简洁,上述描述的***、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的***、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个***,或一些特征可以忽略,或不执行。另外,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口、装置或单元的间接耦合或通信连接,也可以是电的,机械的或其它的形式连接。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本发明实施例方案的目的。
以上所述,仅为本发明的具体实施方式,但本发明的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本发明揭露的技术范围内,可轻易想到各种等效的修改或替换,这些修改或替换都应涵盖在本发明的保护范围之内。因此,本发明的保护范围应以权利要求的保护范围为准。

Claims (32)

  1. 一种无线通信网络中的接入方法,其特征在于,包括:
    在用户设备UE接入到非第三代伙伴计划3GPP接入网之后,非3GPP接入网关为所述UE选择目标移动性管理网元,所述目标移动性管理网元支持所述非3GPP接入网的鉴权授权功能;
    所述非3GPP接入网关向所述目标移动性管理网元发送鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
    在所述目标移动性管理网元对所述UE进行鉴权与授权成功之后,所述非3GPP接入网关为所述UE的接入点名称APN选择分组数据网关P-GW;
    所述非3GPP接入网关为所述UE的APN建立所述非3GPP接入网关与所述选择的P-GW之间的分组数据网PDN连接;
    所述非3GPP接入网关通过所述目标移动性管理网元将所述选择的P-GW的标识注册到归属用户服务器HSS。
  2. 根据权利要求1所述的方法,其特征在于,所述非3GPP接入网关通过所述目标移动性管理网元将所述选择的P-GW的标识注册到HSS包括:
    所述非3GPP接入网关将所述UE的APN和所述选择的P-GW的标识发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的网络之间互连的协议IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
  3. 根据权利要求2所述的方法,其特征在于,所述方法还包括:
    所述非3GPP接入网关确定所述UE的接入类型;
    其中,所述非3GPP接入网关将所述UE的APN和所述选择的P-GW的标识发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS包括:
    所述非3GPP接入网关将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述HSS。
  4. 根据权利要求1-3任一项所述的方法,其特征在于,所述非3GPP接入网关为所述UE选择目标移动性管理网元包括:
    所述非3GPP接入网关根据预配置信息,选择所述目标移动性管理网元;其中,所述预配置信息包含所述UE的位置信息与所述目标移动性管理网元的标识的对应关系,或者所述预配置信息包含所述非3GPP接入网关的标识与所述目标移动性管理网元的标识的对应关系;
    或者,
    所述非3GPP接入网关将所述UE的国际移动用户识别码IMSI发送给路由代理节点,以便所述路由代理节点根据所述UE的IMSI为所述UE选择所述目标移动性管理网元;
    或者,
    所述非3GPP接入网关根据所述UE的位置信息构造移动性管理网元的完全合格域名,并将所述完全合格域名发送给域名解析服务器DNS,接收所述DNS根据所述完全合格域名确定的移动性管理网元的标识,从所述DNS确定的移动性管理网元中选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元作为所述目标移动性管理网元。
  5. 一种无线通信网络中的接入方法,其特征在于,包括:
    在用户设备UE接入到非第三代伙伴计划3GPP接入网之后,支持所述非3GPP接入网的鉴权授权功能的移动性管理网元接收非3GPP接入网关发送的鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
    所述移动性管理网元根据所述鉴权与授权请求消息,对所述UE进行鉴权与授权;
    在对所述UE进行鉴权与授权成功后,所述移动性管理网元接收所述非3GPP接入网关发送的所述UE的接入点名称APN和所述非3GPP接入网关为所述UE的APN选择的分组数据网关P-GW的标识;
    所述移动性管理网元将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
  6. 根据权利要求5所述的方法,其特征在于,所述移动性管理网元将所述 UE的APN和所述选择的P-GW的标识发送给所述HSS包括:
    所述移动性管理网元通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
  7. 根据权利要求6所述的方法,其特征在于,所述方法还包括:
    所述移动性管理网元确定所述UE的接入类型或者接收所述非3GPP接入网关发送的所述UE的接入类型;
    其中,所述移动性管理网元通过通知消息或者非3GPP的网络之间互连的协议IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS包括:
    所述移动性管理网元通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述HSS。
  8. 根据权利要求5-7任一项所述的方法,其特征在于,所述方法还包括:
    所述移动性管理网元接收所述HSS在所述UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    所述移动性管理网元根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
  9. 根据权利要求5-7任一项所述的方法,其特征在于,所述方法还包括:
    所述移动性管理网元接收所述HSS在所述UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关;
    所述移动性管理网元向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
  10. 一种更新签约数据的方法,其特征在于,包括:
    移动性管理网元接收归属用户服务器HSS在用户设备UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关;
    所述移动性管理网元向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
  11. 根据权利要求10所述的方法,其特征在于,
    当所述接入类型属于非第三代伙伴计划3GPP的接入技术时,所述目标网关为演进的分组数据网关ePDG、可信无线局域网络接入网络TWAN或者高速分组数据服务网关HSGW,所述移动性管理网元向所述目标网关发送的所述更新消息为用户签约数据更新消息;或者,
    当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW,所述移动性管理网元向所述目标网关发送的所述更新消息为承载修改命令。
  12. 根据权利要求10或11所述的方法,其特征在于,所述方法还包括:
    所述移动性管理网元向所述HSS发送数据更新响应消息,所述数据更新响应消息包含所述接入类型,所述数据更新响应消息为***签约数据响应消息、推送签约响应消息或者***用户数据响应消息。
  13. 一种更新签约数据的方法,其特征在于,包括:
    在用户设备UE的签约数据发生更新后,归属用户服务器HSS向移动性管理网元发送数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应 的接入类型,以便所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关并向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI;
    其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息。
  14. 根据权利要求13所述的方法,其特征在于,
    当所述接入类型属于非第三代伙伴计划3GPP的接入技术时,所述目标网关为演进的分组数据网关ePDG、可信无线局域网络接入网络TWAN或者高速分组数据服务网关HSGW,所述移动性管理网元向所述目标网关发送的所述更新消息为用户签约数据更新消息;或者,
    当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW,所述移动性管理网元向所述目标网关发送的所述更新消息为承载修改命令。
  15. 根据权利要求13或14所述的方法,其特征在于,所述方法还包括:
    所述HSS接收所述移动性管理网元发送的数据更新响应消息,所述数据更新响应消息包含所述接入类型,所述数据更新响应消息为***签约数据响应消息、推送签约响应消息或者***用户数据响应消息。
  16. 一种更新签约数据的方法,其特征在于,包括:
    支持非第三代伙伴计划3GPP接入网的鉴权授权功能的移动性管理网元接收归属用户服务器HSS在用户设备UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据;其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    所述移动性管理网元根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令,以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
  17. 一种接入网关,其特征在于,所述接入网关为非第三代伙伴计划3GPP网的接入网关,所述接入网关包括:
    第一选择单元,用于在用户设备UE接入到非第三代伙伴计划3GPP接入网之后,为所述UE选择目标移动性管理网元,所述目标移动性管理网元支持所述非3GPP接入网的鉴权授权功能;
    发送单元,用于向所述目标移动性管理网元发送鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
    第二选择单元,用于在所述目标移动性管理网元对所述UE进行鉴权与授权成功之后,为所述UE的接入点名称APN选择分组数据网关P-GW;
    建立单元,用于为所述UE的APN建立所述非3GPP接入网关与所述选择的P-GW之间的分组数据网PDN连接;
    其中,所述发送单元还用于通过所述目标移动性管理网元将所述选择的P-GW的标识注册到归属用户服务器HSS。
  18. 根据权利要求17所述的接入网关,其特征在于,所述发送单元具体用于将所述UE的APN和所述选择的P-GW的标识发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的网络之间互连的协议IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
  19. 根据权利要求18所述的接入网关,其特征在于,所述第二选择单元还用于确定所述UE的接入类型;
    则所述发送单元具体用于将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述目标移动性管理网元,以便所述目标移动性管理网元通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述HSS。
  20. 根据权利要求17-19任一项所述的接入网关,其特征在于,所述第一选择单元为所述UE选择目标移动性管理网元包括:
    所述第一选择单元根据预配置信息,选择所述目标移动性管理网元;其中,所述预配置信息包含所述UE的位置信息与所述目标移动性管理网元的标识的对应关系,或者所述预配置信息包含所述非3GPP接入网关的标识与所述目标移动性管理网元的标识的对应关系;
    或者,
    所述第一选择单元将所述UE的国际移动用户识别码IMSI发送给路由代理节点,以便所述路由代理节点根据所述UE的IMSI为所述UE选择所述目标移动性管理网元;
    或者,
    所述第一选择单元根据所述UE的位置信息构造移动性管理网元的完全合格域名,并将所述完全合格域名发送给域名解析服务器DNS,接收所述DNS根据所述完全合格域名确定的移动性管理网元的标识,从所述DNS确定的移动性管理网元中选择支持所述非3GPP接入网的鉴权授权功能的移动性管理网元作为所述目标移动性管理网元。
  21. 一种移动性管理网元,其特征在于,所述移动性管理网元支持非3GPP接入网的鉴权授权功能;所述移动性管理网元包括:
    接收单元,用于在用户设备UE接入到所述非3GPP接入网之后,接收非3GPP接入网关发送的鉴权与授权请求消息,所述鉴权与授权请求消息用以请求对所述UE进行鉴权与授权;
    鉴权授权单元,用于根据所述鉴权与授权请求消息,对所述UE进行鉴权与授权;
    所述接收单元还用于在所述鉴权授权单元对所述UE进行鉴权与授权成功后,接收所述非3GPP接入网关发送的所述UE的接入点名称APN和所述非3GPP接入网关为所述UE的APN选择的分组数据网关P-GW的标识;
    所述移动性管理网元还包括:发送单元,用于将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
  22. 根据权利要求21所述的移动性管理网元,其特征在于,所述发送单元具体用于通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN和所述选择的P-GW的标识发送给所述HSS。
  23. 根据权利要求22所述的移动性管理网元,其特征在于,还包括:
    获取单元,用于确定所述UE的接入类型或者接收所述非3GPP接入网关发送的所述UE的接入类型;
    所述发送单元具体用于通过通知消息或者非3GPP的IP接入注册请求消息将所述UE的APN、所述选择的P-GW的标识和所述UE的接入类型发送给所述 HSS。
  24. 根据权利要求21-23任一项所述的移动性管理网元,其特征在于,所述接收单元还用于接收所述HSS在所述UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    所述发送单元还用于根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
  25. 权利要求21-23任一项所述的移动性管理网元,其特征在于,所述接收单元还用于接收所述HSS在所述UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    所述移动性管理网元还包括确定单元,用于根据所述数据更新请求消息,确定与所述接入类型对应的目标网关;
    所述发送单元还用于向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
  26. 一种移动性管理网元,其特征在于,包括:
    接收单元,用于接收归属用户服务器HSS在用户设备UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    确定单元,用于根据所述数据更新请求消息,确定与所述接入类型对应的目标网关;
    发送单元,用于向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI。
  27. 根据权利要求26所述的移动性管理网元,其特征在于,当所述接入类型属于非第三代伙伴计划3GPP的接入技术时,所述目标网关为演进的分组数据网关ePDG、可信无线局域网络接入网络TWAN或者高速分组数据服务网关HSGW,所述移动性管理网元向所述目标网关发送的所述更新消息为用户签约数据更新消息;或者
    当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW,所述移动性管理网元向所述目标网关发送的所述更新消息为承载修改命令。
  28. 根据权利要求26或27所述的移动性管理网元,其特征在于,所述发送单元还用于向所述HSS发送数据更新响应消息,所述数据更新响应消息包含所述接入类型,所述数据更新响应消息为***签约数据响应消息、推送签约响应消息或者***用户数据响应消息。
  29. 一种归属用户服务器,其特征在于,包括:
    发送单元,用于在用户设备UE的签约数据发生更新后,向移动性管理网元发送数据更新请求消息,所述数据更新请求消息中包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据和所述更新的签约数据对应的接入类型,以便所述移动性管理网元根据所述数据更新请求消息,确定与所述接入类型对应的目标网关并向所述目标网关发送更新消息,所述更新消息用于请求所述目标网关更新所述UE的签约数据,所述更新消息包含所述UE的更新的签约数据和所述UE的IMSI;
    其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息。
  30. 根据权利要求29所述的归属用户服务器,其特征在于,当所述接入类型属于非第三代伙伴计划3GPP的接入技术时,所述目标网关为演进的分组数据网关ePDG、可信无线局域网络接入网络TWAN或者高速分组数据服务网关HSGW,所述移动性管理网元向所述目标网关发送的所述更新消息为用户签约数据更新消息;或者,
    当所述接入类型属于3GPP的接入技术时,所述目标网关为S-GW,所述移动性管理网元向所述目标网关发送的所述更新消息为承载修改命令。
  31. 根据权利要求29或30所述的归属用户服务器,其特征在于,还包括:
    接收单元,用于接收所述移动性管理网元发送的数据更新响应消息,所述数据更新响应消息包含所述接入类型,所述数据更新响应消息为***签约数据响应消息、推送签约响应消息或者***用户数据响应消息。
  32. 一种移动性管理网元,其特征在于,所述移动性管理网元支持非第三代伙伴计划3GPP接入网的鉴权授权功能;所述移动性管理网元包括:
    接收单元,用于接收归属用户服务器HSS在用户设备UE的签约数据发生更新后发送的数据更新请求消息,所述数据更新请求消息包含所述UE的国际移动用户识别码IMSI、所述UE的更新的签约数据;其中,所述数据更新请求消息为***签约数据消息、推送签约请求消息或者***用户数据消息;
    发送单元,用于根据所述数据更新请求消息,向与所述移动性管理网元连接的S-GW发送承载修改命令,以及向与所述移动性管理网元连接的所有非3GPP接入网关发送用户签约数据更新消息,所述承载修改命令和用户签约数据更新消息均包含所述UE的更新的签约数据和所述UE的IMSI。
PCT/CN2015/075897 2015-04-03 2015-04-03 一种无线通信网络中的接入方法、相关装置及*** WO2016155012A1 (zh)

Priority Applications (6)

Application Number Priority Date Filing Date Title
PCT/CN2015/075897 WO2016155012A1 (zh) 2015-04-03 2015-04-03 一种无线通信网络中的接入方法、相关装置及***
KR1020177031204A KR101930382B1 (ko) 2015-04-03 2015-04-03 무선 통신 네트워크에서의 액세스 방법, 관련 장치 및 시스템
RU2017134503A RU2682856C1 (ru) 2015-04-03 2015-04-03 Способ доступа в сети беспроводной связи, соответствующие устройство и система
EP15886982.6A EP3267707B1 (en) 2015-04-03 2015-04-03 Access methods in wireless communication network
CN201580065448.4A CN107005843B (zh) 2015-04-03 2015-04-03 一种无线通信网络中的接入方法、相关装置及***
US15/722,140 US10419935B2 (en) 2015-04-03 2017-10-02 Access method in wireless communications network, related apparatus, and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/075897 WO2016155012A1 (zh) 2015-04-03 2015-04-03 一种无线通信网络中的接入方法、相关装置及***

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/722,140 Continuation US10419935B2 (en) 2015-04-03 2017-10-02 Access method in wireless communications network, related apparatus, and system

Publications (1)

Publication Number Publication Date
WO2016155012A1 true WO2016155012A1 (zh) 2016-10-06

Family

ID=57005595

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/075897 WO2016155012A1 (zh) 2015-04-03 2015-04-03 一种无线通信网络中的接入方法、相关装置及***

Country Status (6)

Country Link
US (1) US10419935B2 (zh)
EP (1) EP3267707B1 (zh)
KR (1) KR101930382B1 (zh)
CN (1) CN107005843B (zh)
RU (1) RU2682856C1 (zh)
WO (1) WO2016155012A1 (zh)

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
ES2751653T3 (es) * 2015-05-12 2020-04-01 Ericsson Telefon Ab L M Método y nodos para gestionar acceso a servicios de EPC a través de una red no de 3GPP
FR3039954A1 (fr) 2015-08-05 2017-02-10 Orange Procede et dispositif d'identification de serveurs d'authentification visite et de domicile
FR3039953A1 (fr) * 2015-08-05 2017-02-10 Orange Procedes et dispositifs d'identification d'un serveur d'authentification
US10805217B2 (en) * 2015-11-10 2020-10-13 At&T Intellectual Property I, L.P. Control plane device selection for broadcast session exchange
CN110650489B (zh) 2018-06-26 2022-02-15 华为技术有限公司 一种管理监控事件的方法及装置
KR102571312B1 (ko) * 2018-08-09 2023-08-28 노키아 테크놀로지스 오와이 이종 액세스 네트워크를 통한 연결의 보안 실현을 위한 방법 및 장치
US11076321B2 (en) 2018-10-11 2021-07-27 Cisco Technology, Inc. Selecting 5G non-standalone architecture capable MME during registration and handover
US12014740B2 (en) 2019-01-08 2024-06-18 Fidelity Information Services, Llc Systems and methods for contactless authentication using voice recognition
US11290951B2 (en) * 2019-02-12 2022-03-29 Cisco Technology, Inc. Providing optimal packet data network gateway selection for 5G network environments upon initial user equipment attachment via a WiFi evolved packet data gateway

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101516083A (zh) * 2008-02-22 2009-08-26 中兴通讯股份有限公司 一种切换时漫游协议类型的获取方法
CN101909274A (zh) * 2008-08-01 2010-12-08 华为技术有限公司 进行信息交互的方法及存储用户签约数据的节点
CN103313239A (zh) * 2012-03-06 2013-09-18 中兴通讯股份有限公司 一种用户设备接入融合核心网的方法及***
US20140050132A1 (en) * 2012-07-03 2014-02-20 Telefonaktiebolaget L M Ericsson (Publ) Method For Revocable Deletion of PDN Connection

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2007162A3 (en) 2007-06-18 2011-11-16 Motorola Mobility, Inc. Non-3GPP IP access to E-UTRAN access inter-RAT handover
JP4966432B2 (ja) * 2008-04-11 2012-07-04 テレフオンアクチーボラゲット エル エム エリクソン(パブル) 非3gppアクセスネットワーク経由のアクセス
CN101286915B (zh) * 2008-06-11 2012-05-09 中兴通讯股份有限公司 分组数据网络的接入控制方法和***、pcrf实体
CN101610201A (zh) 2008-06-20 2009-12-23 大唐移动通信设备有限公司 实现pdn连接释放的方法、装置和***
CN101789912B (zh) * 2009-01-23 2012-06-27 华为技术有限公司 更新分组数据网络网关信息的方法、装置及***
CN101998348A (zh) * 2009-08-25 2011-03-30 中兴通讯股份有限公司 一种计费***及其进行计费的方法
WO2011094933A1 (en) * 2010-02-03 2011-08-11 Huawei Technologies Co., Ltd. System and method for managing an access network re-selection
CN102316548A (zh) * 2010-07-07 2012-01-11 中兴通讯股份有限公司 信息传递方法和***
CN102340866B (zh) * 2010-07-14 2016-04-13 中兴通讯股份有限公司 一种上报固网接入信息的方法及***
US8554933B2 (en) * 2010-10-05 2013-10-08 Verizon Patent And Licensing Inc. Dynamic selection of packet data network gateways
CN103209401B (zh) * 2012-01-12 2018-07-24 中兴通讯股份有限公司 一种融合网络中策略控制方法及***
KR101436060B1 (ko) * 2012-12-07 2014-09-01 주식회사 엘지유플러스 이종 통신망 간 가입자 위치 정보 동기화 방법, 이종 통신망 간 가입자 위치 정보에 기반한 이종 통신망 서비스 처리 방법, 및 그를 위한 장치
EP3207744B1 (en) * 2014-10-15 2022-09-07 Telefonaktiebolaget LM Ericsson (publ) Methods and network nodes for reuse of epc session between 3gpp and wlan

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101516083A (zh) * 2008-02-22 2009-08-26 中兴通讯股份有限公司 一种切换时漫游协议类型的获取方法
CN101909274A (zh) * 2008-08-01 2010-12-08 华为技术有限公司 进行信息交互的方法及存储用户签约数据的节点
CN103313239A (zh) * 2012-03-06 2013-09-18 中兴通讯股份有限公司 一种用户设备接入融合核心网的方法及***
US20140050132A1 (en) * 2012-07-03 2014-02-20 Telefonaktiebolaget L M Ericsson (Publ) Method For Revocable Deletion of PDN Connection

Also Published As

Publication number Publication date
KR20170132273A (ko) 2017-12-01
US10419935B2 (en) 2019-09-17
EP3267707A4 (en) 2018-05-30
EP3267707A1 (en) 2018-01-10
CN107005843B (zh) 2020-02-14
US20180027414A1 (en) 2018-01-25
CN107005843A (zh) 2017-08-01
RU2682856C1 (ru) 2019-03-21
KR101930382B1 (ko) 2018-12-18
EP3267707B1 (en) 2019-06-12

Similar Documents

Publication Publication Date Title
WO2016155012A1 (zh) 一种无线通信网络中的接入方法、相关装置及***
CN110495214B (zh) 用于处理pdu会话建立过程的方法和amf节点
US8769626B2 (en) Web authentication support for proxy mobile IP
US9167430B2 (en) Access method and system, and mobile intelligent access point
US10432632B2 (en) Method for establishing network connection, gateway, and terminal
US9560048B2 (en) Method for updating identity information about packet gateway, AAA server and packet gateway
KR102390380B1 (ko) 비인증 사용자에 대한 3gpp 진화된 패킷 코어로의 wlan 액세스를 통한 긴급 서비스의 지원
US20110271117A1 (en) User equipment (ue), home agent node (ha), methods, and telecommunications system for home network prefix (hnp) assignment
US20160380962A1 (en) Wireless access gateway
WO2009152676A1 (zh) Aaa服务器、p-gw、pcrf、用户设备标识的获取方法和***
US20190223013A1 (en) Method for establishing public data network connection and related device
WO2010091589A1 (zh) 一种安全认证方法
WO2017129101A1 (zh) 路由控制方法、装置及***
CN107005929B (zh) 一种分组数据网关的选择方法、相关装置及***
US11729739B2 (en) Support of WLAN location change reporting or retrieval for untrusted WLAN access to a 3GPP packet core network
EP3117686B1 (en) Wireless access gateway
JP6732794B2 (ja) モバイル無線通信ネットワーク及び通信ネットワークデバイスへのモバイル端末の接続を確立するための方法
CN107925861A (zh) 一种无线通信网络的接入方法及相关装置
CN116686333A (zh) 用于外部认证和授权的方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15886982

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2017134503

Country of ref document: RU

NENP Non-entry into the national phase

Ref country code: DE

REEP Request for entry into the european phase

Ref document number: 2015886982

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 20177031204

Country of ref document: KR

Kind code of ref document: A