WO2005004384A1 - An alternation disposal method for network selection information of user terminal in wlan - Google Patents

An alternation disposal method for network selection information of user terminal in wlan Download PDF

Info

Publication number
WO2005004384A1
WO2005004384A1 PCT/CN2004/000738 CN2004000738W WO2005004384A1 WO 2005004384 A1 WO2005004384 A1 WO 2005004384A1 CN 2004000738 W CN2004000738 W CN 2004000738W WO 2005004384 A1 WO2005004384 A1 WO 2005004384A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
user terminal
wlan
information
access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2004/000738
Other languages
English (en)
French (fr)
Inventor
Wenlin Zhang
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to BRPI0412316-6A priority Critical patent/BRPI0412316A/pt
Priority to CA002531141A priority patent/CA2531141A1/en
Priority to EP04738336A priority patent/EP1643676A4/en
Priority to JP2006517939A priority patent/JP2007507124A/ja
Publication of WO2005004384A1 publication Critical patent/WO2005004384A1/zh
Priority to US11/324,860 priority patent/US20060179310A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/084Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/162Implementing security features at a particular protocol layer at the data link layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/18Selecting a network or a communication service
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/26Network addressing or numbering for mobility support
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Definitions

  • the present invention relates to network access technology, and particularly to a method for interactively processing network selection information of a user terminal in a wireless local area network (WLAN).
  • WLAN wireless local area network
  • Wireless local area network includes a variety of different technologies.
  • IEEE 802.11b which uses the 2.4GHz band.
  • the highest data transmission rate can reach 11Mbps.
  • IEEE 802.11g and Bluetooth are also used in this band.
  • Technology, among which, the highest data transmission rate of 802.11g can reach 54Mbps.
  • Other new technologies such as IEEE 802.11a and ETSI BRAN Hiperlan2 all use the 5GHz band, and the maximum transmission rate can reach 54Mbps.
  • WLANs are used to transmit Internet Protocol (IP) packet data packets.
  • IP Internet Protocol
  • the specific WLAN access technology it uses is generally transparent to the upper-layer IP.
  • Its basic structure uses an access point (AP) to complete the wireless access of user terminals, and forms an IP transmission network through network control and connection of device connections.
  • AP access point
  • WLAN and various wireless mobile communication networks such as: GSM, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, Time Division Duplex-Synchronous Code Division Multiple Access
  • 3GPP 3rd Generation Partnership Project
  • user terminals can interact with the Internet (Intemet) and internal enterprises through an WLAN access network. It is connected to the Internet, and can also be connected to the home network of the 3GPP system or the access network of the 3GPP system through the WLAN access network. Specifically, when the WLAN user terminal accesses locally, the home network is connected to the 3GPP home via the WLAN access network.
  • the network is connected, as shown in Figure 2.
  • When roaming it is connected to the 3GPP access network via the WLAN access network, and some entities in the 3GPP access network are interconnected with corresponding entities in the 3GPP home network, for example: 3GPP access network 3GPP Authentication, Authorization and Accounting (AAA) proxy and 3GPP Authentication, Authorization and Accounting (AAA) server in the 3GPP home network; the Wireless Local Area Network Access Gateway (WAG) in the 3GPP access network and the coarse data gateway in the 3GPP home network ( PDG, Packet Data Gateway, and so on, as shown in Figure 1.
  • FIG. 1 and FIG. 2 are schematic diagrams of the networking structure of interworking between the WLAN system and the 3GPP system in a roaming situation and a non-roaming situation, respectively.
  • the 3GPP system in the 3GPP system, it mainly includes a Home Subscriber Subscriber Server (HSS) / Home Location Register (HLR), a 3GPP AAA server, a 3GPP AAA proxy, a WAG, a packet data gateway, and a charging gateway (CGw ) / Charging Information Collection System (CCF) and Online Charging System (OCS).
  • HSS Home Subscriber Subscriber Server
  • HLR Home Location Register
  • 3GPP AAA server 3GPP AAA proxy
  • WAG packet data gateway
  • CGw Charging Information Collection System
  • OCS Online Charging System
  • the user terminal, the WLAN access network, and all entities of the 3GPP system form a 3GPP-WLAN interactive network.
  • This 3GPP-WLAN interactive network can be used as a wireless local area network service system.
  • the 3GPP AAA server is responsible for user authentication, authorization, and charging, and collects and transmits the charging information sent by the WLAN access network to the charging system;
  • the packet data gateway is responsible for transferring user data from the WLAN access network to the 3GPP Data transmission of the network or other packet networks;
  • the billing system mainly receives and records user billing information from the network, and also includes the OCS instructs the network to periodically transmit online billing information according to the billing situation of online billing users, and performs statistics and control.
  • a WLAN user terminal wants to directly access the Internet / Intranet
  • the user terminal after the user terminal completes the access authentication and authorization through the WLAN access network and the AAA server (AS), the user terminal can access the WLAN access network.
  • Internet / Intranet If the LAN user terminal also wants to access the 3GPP packet switched (PS) domain service, it can further provide
  • PS packet switched
  • the home network applies for an interworking scenario 3 (Scenario3) service, that is, the WLAN user terminal initiates a service authorization request for the interworking scenario 3 to the AS of the 3GPP home network, and the AS of the 3GPP home network performs service authentication and authorization on the service authorization request.
  • scenario3 interworking scenario 3
  • the AS sends an access permission message to the user terminal, and the AS assigns the corresponding PDG to the user terminal.
  • the AS can access 3GPP PS domain services.
  • CGw / CCF and OCS record charging information based on the network usage of the user terminal.
  • the user terminal may apply to the 3GPP home network to access the Internet / Intranet through the 3GPP access network. If the user terminal also wishes to apply for the interworking scenario 3 service and access the 3GPP PS domain service, the user terminal needs to initiate a service authorization process to the 3GPP home network through the 3GPP access network.
  • This process is also between the user terminal and the AS of the 3GPP home network.
  • the AS allocates the corresponding home PDG to the user terminal.
  • the user terminal After the user terminal establishes a tunnel between the WAG in the network and the allocated PDG through the 3GPP, the user terminal can access the 3GPP PS domain service of the home network.
  • the 3GPP access network refers to access to a public land mobile network (VPLMN), After the WLAN user terminal accesses the WLAN, it is necessary to select the VPLMN network that it wants to access.
  • VPLMN public land mobile network
  • a WLAN access network is connected to two VPLMN operating networks of China Mobile and China Unicom at the same time. Then, users of China Unicom After accessing from WLAN, it is necessary to instruct the WLAN access network to access China Unicom's VPLMN operating network.
  • a French user roams to a WLAN in China. If the French user's home network has roaming agreements with China Mobile and China Unicom, then the WLAN access network is connected to China Mobile and China Unicom. In this case, after the French user accesses the WLAN, the user needs to select the VPLMN network to be accessed. However, how does the user terminal inform the WLAN access network of the information of the selected network to be accessed, and how is the 3GPP-WLAN interworking network? In the process of interactively processing the network selection information of the user terminal, no specific solution has been proposed at present. Summary of the invention
  • the main object of the present invention is to provide a method for interactively processing network selection information of user terminals in a wireless local area network, so that when a user terminal accesses from a WLAN connected to multiple mobile communication operation networks, the user terminal can select as required. Appropriate mobile communication network access.
  • An interactive processing method for user terminal network selection information in a wireless local area network includes the following steps:
  • the network or the WLAN user terminal After the WLAN user terminal establishes a wireless connection with the WLAN access network, the network or the WLAN user terminal initiates an access authentication process, and the WLAN access network sends a user name request message to the WLAN user terminal;
  • the network judges whether the network selection information in the received message belongs to the mobile communication operating network of the current WLAN connection, and if so, sends the access authentication request of the WLAN user terminal to the mobile identified by the network selection information A communication operation network; otherwise, the network sends notification signaling to the WLAN user terminal, and the WLAN user terminal completes subsequent operations according to the content of the notification signaling.
  • step a the WLAN user terminal initiates an access authentication process, and step a further includes: before the access authentication is initiated, the WLAN user terminal sends a network information download request to the network.
  • the WLAN user terminal sends a request for downloading network information to the network by using an extensible authentication protocol (EAP) signaling request, or by using a portal interaction method.
  • EAP extensible authentication protocol
  • Step b further includes: after the WLAN user terminal receives the request username message, The network sends a request for downloading network information, and after receiving the request, the network sends mobile communication operation network information to the WLAN user terminal; the WLAN user terminal selects a network according to the received mobile communication operation network information, and accesses the WLAN again.
  • the network sends an access authentication request carrying new network selection information.
  • the download network information request is a specific field placed in the response message, or a specific value of a user name field in the response message, or a message set separately.
  • step c the network sends a notification signaling to the WLAN user terminal containing the mobile communication operation network information to be released, and the method further includes: after receiving the notification signaling, the WLAN user terminal reselects a mobile communication The operation network, and obtains the network information corresponding to the selected mobile communication operation network according to the network information in the notification signaling; and then sends a message carrying the new network selection information to the WLAN access network, and returns to step c.
  • the method further includes: the network waits for a response message of the user terminal after the notification signaling is issued, and does not receive a response after waiting for a certain time, the network actively sends a selection result request to the WLAN user terminal.
  • the network ends the current authentication process after issuing the notification signaling, and after the WLAN user terminal reselects the mobile communication operation network, it initiates an access authentication process to the WLAN access network again, and sends an access carrying the new network selection information. Certification Information.
  • step c the network sends a notification signaling to the WLAN user terminal indicating that the currently selected network of the user terminal is invalid and the mobile communication operation network information needs to be downloaded, and the method further includes: the WLAN user terminal determines whether the mobile communication operation network needs to be downloaded. Information, if necessary, the WLAN user terminal returns a response to the network that needs to download network information; after receiving the response, the network publishes mobile communication operation network information to the WLAN user terminal; and the WLAN user terminal obtains mobile communication operation After selecting the network information, reselect a mobile communication operation network, and resend the access authentication request carrying the new network selection information to the WLAN access network, and return to step c; otherwise, no processing is performed or response information that does not need to be downloaded is returned.
  • the method further includes: the network waits for a response message from the user terminal after issuing the notification signaling, and does not receive a response after waiting for a certain period of time, the network actively issues a mobile communication to the WLAN user terminal Letter operation network information. Alternatively, the network ends the current processing flow after the notification signaling is issued. If the WLAN user terminal needs to download network information, the WLAN user terminal actively sends a request to initiate a network information download flow.
  • the WLAN user terminal automatically selects mobile communication operation network information delivered by the network according to a preset parameter.
  • step c further includes: the network determines whether the network selection information includes access network information, and if it includes, the ij WLAN access
  • the network sends the access authentication request to the authentication authorization and accounting proxy (AAA Proxy) of the visited network to which the user terminal currently belongs according to the visited network information; otherwise, the WLAN access network sends the access according to the network selection information
  • AAA Proxy authentication authorization and accounting proxy
  • step c further includes: after receiving the access authentication request of the WLAN user terminal, the AAA proxy parses out the user identification field The home network domain name in the home network, and then sends the WLAN user terminal's access authentication request to the home network's AAA server to complete the access authentication and authorization according to the home network domain name.
  • the method further includes: after receiving the access authentication request of the WLAN user terminal, the AAA proxy determines that the user identification field contains the access network information, and the access network information is the information on the network, and then changes the user identification field to only Including the home network domain name, and then sending the modified request to the home network of the WLAN user terminal.
  • the sending of the judgment and notification signaling described in step c is completed by a preset network information judgment and notification sending unit.
  • the network information judgment and notification sending unit is set in an access control device (AC); or it is set in an authentication, authorization and accounting (AAA) server of any mobile communication operation network, or a preset AAA proxy device.
  • the current network of the WLAN user terminal is the home network of the user terminal, but the access authentication information sent by the WLAN user terminal contains the access network information.
  • the access network information in the authentication request is changed to the home network information.
  • the current network of the WLAN user terminal is the home network of the user terminal, but the access authentication information sent by the WLAN user terminal contains the access network information, the current network notifies the current network of the WLAN user terminal as its home network, and then determines the network Whether the WLAN user terminal selects a home network, and if so, the current network performs access authentication on the WLAN user terminal; otherwise, the roaming network performs access authentication on the WLAN user terminal.
  • the method further includes: when the network delivers the current WLAN-connected mobile communication operation network information, selecting the visited network information that has a roaming relationship with the home network indicated by the current user terminal and delivering the information.
  • the WLAN network uses the EAP notification message EAP-Request / notification to deliver the mobile communication operation network information provided to the WLAN user terminal.
  • the method for interactively processing network selection information of a user terminal in a wireless local area network provided by the present invention, the user terminal directly carries its own network selection information through an access authentication request when accessing the WLAN;
  • the mobile communication operation network information sent is selected, and the network selection information is sent to the WLAN access network through an access authentication request, so that the WLAN access network can determine the user terminal to access based on the network selection information of the user terminal.
  • Mobile communication operation network, and the mobile communication operation network selected by the user terminal authenticates the user terminal, and solves the problem of interactive processing of network selection information between the user terminal and the network when the WLAN user terminal autonomously selects the mobile communication operation network .
  • Figure 1 is a schematic diagram of the network structure for interworking between the WLAN system and the 3GPP system in the case of roaming
  • Figure 2 is a schematic diagram of the network structure for interworking between the WLAN system and the 3GPP system in the non-roaming situation
  • FIG. 3 is a schematic diagram of a network structure in which a WLAN is connected to multiple access networks;
  • FIG. 4 is a schematic flowchart of interactive processing of user terminal network selection information according to the present invention;
  • FIG. 5 is a schematic flowchart of user terminal access authentication and authorization according to the present invention;
  • FIG. 6 is a schematic flowchart of a first embodiment of network selection information interaction processing according to the present invention
  • FIG. 7 is a schematic flowchart of a second embodiment of network selection information interaction processing according to the present invention.
  • the basic idea of the present invention is: a WLAN user terminal sends network selection information to a WLAN access network through an access authentication request, and the WLAN access network can identify the mobile communication operation that the user terminal wants to access according to the carried network selection information. Network, and connect the current user terminal to the selected network for access authentication and subsequent operations.
  • the network selection information refers to the mobile communication operation network information connected to the WLAN network that the user terminal is currently accessing.
  • the selection information may be preselected by the user terminal, or may be a mobile communication operation network issued by the user terminal according to the network. Select information selected.
  • the network selection information may be placed in a field separately set in the access authentication request, or may be placed in a user identification field defined in a network access identification (NAI) format in the access authentication request.
  • NAI network access identification
  • the interactive processing process of the user terminal selecting to access the mobile communication operation network information in the present invention includes the following steps:
  • Step 401 When a WLAN user terminal accesses a 3GPP-WLAN interworking network through a WLAN, the WLAN user terminal or network initiates an access authentication process. The following takes the WLAN user terminal to initiate an access authentication process as an example. The WLAN user finally accesses the WLAN first. Network sends access authentication request;
  • Step 402 After the WLAN access network receives the request, an access authentication process is started between the WLAN access network and the user terminal, and the authentication protocol (EAP) process can be extended. Specifically, the WLAN access network sends a user identification request message to the user terminal requesting the user name of the current user terminal; after the WLAN user terminal receives the request, it sends a network containing the network to the WLAN access network.
  • the response user identification message of the network selection information is shown in steps 502 and 503 in FIG. 5.
  • the network selection information may be placed in a user identification field in the NAI format. In the following, the network selection information is placed in a user identification field as an example.
  • the user identification field includes a user name and a domain name.
  • Step 403 404 After receiving the response message carrying the network selection information, the WLAN access network analyzes the user identification field in the response message; determines whether the network selection information carried in the user identification field is for the WLAN connection If it is a mobile communication operation network, step 405 is performed; otherwise, that is, if the mobile communication operation network WLAN carried in the network selection information cannot be identified, step 406 is performed.
  • Step 405 According to the network selection information in the user identification field NAI, determine the mobile communication operating network to which the current user terminal is to access, and the WLAN access network sends the access authentication request of the current user terminal to the mobile communication identified by the network selection information.
  • the operating network performs access authentication processing.
  • the WLAN access network determines that the access network information is included according to the network selection information carried in the user identification field
  • the WLAN access network sends the access authentication request to the user terminal according to the access network information in the user identification field.
  • the AAA Proxy of the access network to which it belongs, and the AAA Proxy forwards the access authentication request to the 3GPP AAA server of the home network of the user terminal for access authentication processing; otherwise, the WLAN access network
  • the access authentication request is sent to the AAA server of the network to which the user terminal belongs according to the network selection information in the user identification field for access authentication processing, as shown in step 506 in FIG. 5.
  • the AAA proxy accessing the network receives the access authentication request from the user terminal, it determines that the user identification field contains the access network information, and the access network information is the information on the network. Then the domain name part in the user identification field is changed to only Include the home network domain name, and then send the modified request to the home network of the user terminal.
  • the WLAN network where the WLAN user terminal is currently located is directly connected to the home network of the WLAN user terminal, but the user terminal initiates an access authentication request by using a roaming identifier, That is, the carried network selection information contains visited network information, and the current network can directly change the visited network information in the user identification field NAI to the home network information; or, the current network can send a notification to the user terminal to remind the user of the current network.
  • the current network For its home network, if the user terminal initiates an access authentication request again with the home network information, the current network directly completes the inbound authentication process, but if the user terminal still confirms that it wants to choose a roaming network, the current network will pass the roaming network to the user terminal Perform access authentication and provide follow-up services.
  • Steps 406 to 407 The network side sends notification signaling to the current user terminal, and the current user terminal continues subsequent operations according to the content of the notification signaling.
  • the notification signaling may directly use the notification message EAP-Request / Notification in the WLAN protocol, or a separately set notification signaling.
  • the notification signaling sent by the network to the user terminal is divided into two cases: one is that the notification signaling directly contains the mobile communication operating network information to be released by the network, so that the WLAN user terminal or user can directly select; One is that the notification signaling is only used as a signaling to notify the user terminal that the currently selected mobile communication operation network information is invalid, and instruct the user terminal to download the mobile communication operation network information.
  • the user terminal may reselect a mobile communication operation network after receiving, and obtain the information according to the network information in the notification signaling.
  • the network information corresponding to the mobile communication operation network is selected, and then the selected mobile communication operation network information is placed in the user identification field NAI of the response message, and is again sent to the WLAN access network for determination, and returns to step 403.
  • the network may wait for the selection response of the user terminal after issuing the notification signaling, and after waiting for a certain period of time, if no response is received, the network actively sends a selection result request to the user terminal; the network may not After waiting for the selection response from the user terminal, the current processing flow is ended, and the user terminal actively initiates the second access authentication process again.
  • the WLAN user terminal may automatically select or whether the user selects whether to download the mobile communication operation network information, and the WLAN user terminal automatically Selection means that the user terminal can automatically process the information delivered by the network according to the user's preset parameters, automatically select the appropriate mobile communication operating network, and can also display the information to the user for selection when necessary.
  • the user terminal may determine to choose to display information that has a roaming relationship with the user's home network. If downloading is needed, the WLAN user terminal returns a response to the network to download the network information. After receiving the response, the network publishes the mobile communication operation network information to the user terminal.
  • the WLAN user terminal After the WLAN user terminal obtains the mobile communication operation network information, it selects again A mobile communication operation network, and re-initiates an access authentication request carrying new network selection information, and returns to step 403; if downloading is not required, the WLAN user terminal does not process or returns response information that does not require downloading.
  • the network may wait for the selection response of the user terminal after issuing the notification signaling, and after waiting for a certain period of time, if no response is received, the network proactively publishes the mobile communication operation network information to the user terminal; the network may also issue the notification signaling after Without waiting for the user terminal's selection response, the current processing flow ends. If the user terminal needs to download network information, the user terminal actively sends a request to initiate a network information download flow.
  • the mobile communication operation network information provided by the network to the user terminal for selection is stored in a dedicated network information storage unit, which generally includes the following parameters: network name, network bearer capacity QOS, bandwidth, service capacity, WLAN interworking scenarios, rates, and types of service providers.
  • a dedicated network information storage unit which generally includes the following parameters: network name, network bearer capacity QOS, bandwidth, service capacity, WLAN interworking scenarios, rates, and types of service providers.
  • the determination of the network selection information in step 404 and the transmission of the notification information in step 406 may be completed by the same network entity, which may be referred to as a network information determination and notification sending unit, and the network information determination and notification
  • the sending unit may exist in a WLAN access network, for example, it may be provided in an access control device (AC); it may also exist outside the current WLAN access network and in a mobile communication operation network connected to the current WLAN access network, Serve multiple WLAN access networks at the same time, for example, set in an AAA server; Set a default AAA proxy as the network information judgment and notification sending unit.
  • the user terminal may send the access authentication request before or at the same time, or at the same time.
  • a request is sent to the network for downloading the information of the current mobile communication operation network of the WLAN connection, that is, the user terminal can initiate the access authentication process after obtaining the information of the mobile communication operation network and selecting the network; or download
  • the network information process is parallel to the access authentication process.
  • the WLAN user terminal may send a request for downloading network information to the network by using EAP signaling or using a portal interaction mode.
  • the user terminal may also send a request for downloading the information of the mobile communication operating network of the current WLAN connection to the network after receiving the user identification message from the WLAN access network, and the request may be sent as an independent signaling;
  • the request identifier may also be placed in the response user identifier ⁇ : Gen text, for example: the preset download request field is set in response to the user name being empty, or it is directly agreed that the user name in the response is OxFFFF, indicating that network information needs to be downloaded.
  • a default AAA proxy is set in advance as a network information judgment and notification sending unit, and the network information judgment and notification sending unit may serve one or more WLAN access networks, as shown in the figure.
  • the interactive processing process of the network selection information of the present invention includes the following steps:
  • Steps 601 to 603 After a WLAN user terminal establishes a wireless connection with a WLAN access network, the user terminal sends an access authentication request to the WLAN access network; after the LAN access network receives the request user name, The message EAPoL-Request [Identity]; After receiving the message, the user terminal sends a response user name message carrying the NAI format user identification field to the WLAN access network.
  • the message EAPoL-Request [Identity] contains the network Select information.
  • Steps 604 to 605 The WLAN access network according to the user identification field in the received message, Determine the routing of the WLAN user terminal access authentication request. If the WLAN access network finds that the user identification field cannot be identified, that is, it does not belong to one of the mobile communication operating networks connected to itself, it routes the access authentication request to the default AAA proxy.
  • Step 606 After receiving the access authentication request, the default AAA proxy finds that the network selection information in it does not match the mobile communication operation network connected to the WLAN network, and sends a notification signaling EAP-Request / Notification to the WLAN connection.
  • Network access the LAN access network sends the notification signaling to the user terminal.
  • the notification signaling carries information of a mobile communication operation network connected to the WLAN, and the notification signaling may deliver one or more pieces of information, and decide to end the interaction according to the indication information in the last EAP message.
  • Step 607 After receiving the mobile communication operation network information carried in the notification signaling, the user terminal performs network selection again.
  • the AAA proxy and the WLAN access network deliver the notification signaling, they wait for a response from the user terminal.
  • Steps 608 to 609 The AAA Proxy sends the EAP-Request [Identity] signaling to the current LAN user terminal again to request the user identity. After receiving the current WLAN user terminal, it returns the user identity carrying the new network selection information through the EAPoL-Response [Identity] message.
  • Steps 610 to 611 The WLAN access network determines the mobile communication operating network to which the user terminal is to access based on the new network selection information sent by the current user terminal, which refers to the VPLMN network, and sends the access authentication request information to the identified Access authentication processing is performed in the AAA proxy and AS of the VPLMN network.
  • Embodiment two Embodiment two:
  • a default AAA proxy is set in advance as a network information judgment and notification sending unit, and the network information judgment and notification sending unit may serve one or more WLAN access networks, as shown in the figure.
  • the network selection letter of the present invention The interactive process of information includes the following steps:
  • Steps 701 to 707 are exactly the same as the steps 601 to 607 in the first embodiment, except that after the AAA proxy and the WLAN access network send notification signaling, they do not wait for a response from the user terminal, and directly end the current related process.
  • Step 708 Since the AAA proxy and the WLAN access network do not wait for the user terminal to respond, the current WLAN user terminal re-selects the network according to the mobile communication operating network information in the notification signaling, and then initiates the initiative again through the initial authentication message EAPOL-Start Access authentication process.
  • Steps 709 to 710 After the WLAN access network receives the EAPOL-Start message, it again sends an EAP-Request [Identity] signaling to the WLAN user terminal to request the user identity again; the WLAN user terminal passes the EAPoL- Response [Identity ] The message returns the user identification carrying the new network selection information to the WLAN access network.
  • Steps 711 712 After receiving the new user identity, the WLAN access network determines the mobile communication operation network selected by the WLAN user terminal according to the new network selection information therein, and sends the access authentication request information of the WLAN user terminal to Access authentication processing is performed in the AAA proxy and AS of the network identified by the network selection information.
  • the access network information in the user identification field is first changed to the home network information of the user terminal, and then the connection carrying the modified user identification field is accessed.
  • the incoming authentication request information is sent to the AS of the user terminal's home network for authentication processing.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Small-Scale Networks (AREA)

Description

无线局域网中用户终端网络选择信息的交互处理方法 技术领域
本发明涉及网络接入技术, 特别是指一种无线局域网(WLAN )中对 用户终端网络选择信息的交互处理方法。 发明背景
由于用户对无线接入速率的要求越来越高, 无线局域网 (WLAN, Wireless Local AreaNetwork )应运而生, 它能在较小范围内提供高速的无 线数据接入。无线局域网包括多种不同技术, 目前应用较为广泛的一个技 术标准是 IEEE 802.11b, 它采用 2.4GHz 频段,. 最高数据传输速率可达 11Mbps, 使用该频段的还有 IEEE 802.11g和蓝牙 (Bluetooth )技术, 其 中, 802.11g最高数据传输速率可达 54Mbps。其它新技术诸如 IEEE 802.11a 和 ETSI BRAN Hiperlan2 都使用 5GHz频段, 最高传输速率也可达到 54Mbps。
尽管有多种不同的无线接入技术, 大部分 WLAN都用来传输因特网 协议(IP )分组数据包。 对于一个无线 IP网络, 其采用的具体 WLAN接 入技术对于上层的 IP—般是透明的。其基本的结构都是利用接入点(AP ) 完成用户终端的无线接入, 通过网络控制和连接设备连接组成 IP传输网 络。
随着 WLAN技术的兴起和发展, WLAN与各种无线移动通信网, 诸 如: GSM、 码分多址 ( CDMA ) 系统、 宽带码分多址 ( WCDMA ) 系统、 时分双工-同步码分多址(TD-SCDMA ) 系统、 CDMA2000系统的互通正 成为当前研究的重点。 在第三代合作伙伴计划 (3GPP )标准化组织中, 用户终端可以通过 WLAN 的接入网络与因特网 (Intemet )、 企业内部互 联网 (Intranet )相连, 还可以经由 WLAN接入网絡与 3GPP系统的归属 网络或 3GPP系统的访问网络连接,具体地说就是, WLAN用户终端在本 地接入时, 经由 WLAN接入网絡与 3GPP的归属网络相连, 如图 2所示; 在漫游时, 经由 WLAN接入网络与 3GPP的访问网络相连, 3GPP访问网 络中的部分实体分别与 3GPP 归属网络中的相应实体互连, 比如: 3GPP 访问网络中的 3GPP认证授权计费 (AAA )代理和 3GPP归属网络中的 3GPP认证授权计费 (AAA )服务器; 3GPP访问网絡中的无线局域网接 入关口 (WAG )与 3GPP归属网络中的分粗数据关口 (PDG, Packet Data Gateway )等等, 如图 1所示。 其中, 图 1、 图 2分别为漫游情况下和非 漫游情况下 WLAN系统与 3GPP系统互通的组网结构示意图。
参见图 1、 图 2所示, 在 3GPP系统中, 主要包括归属签约用户服务 器(HSS ) /归属位置寄存器(HLR )、 3GPP AAA服务器、 3GPP AAA代 理、 WAG、 分组数据关口、 计费关口 (CGw ) /计费信息收集系统(CCF ) 及在线计费系统(OCS )。 用户终端、 WLAN接入网络与 3GPP系统的所 有实体共同构成了 3GPP-WLAN交互网络, 此 3GPP-WLAN交互网絡可 作为一种无线局域网服务系统。其中, 3GPP AAA服务器负责对用户的鉴 权、 授权和计费, 对 WLAN接入网络送来的计费信息收集并传送给计费 系统; 分组数据关口负责将用户数据从 WLAN接入网络到 3GPP网络或 其他分组网络的数据传输;计费系统主要接收和记录网络传来的用户计费 信息, 还包括 OCS根据在线计费用户的费用情况指示网络周期性的传送 在线费用信息, 并进行统计和控制。
在非漫游情况下, 当 WLAN用户终端希望直接接入 Internet/Intranet 时, 用户终端通过 WLAN接入网与 AAA服务器(AS ) 完成接入认证授 权后,用户终端可通过 WLAN接入网接入到 Internet/Intranet。如果 LAN 用户终端还希望接入 3GPP分组交换(PS )域业务, 则可进一步向 3GPP 归属网络申请互通场景 3 ( Scenario3 ) 的业务, 即: WLAN用户终端向 3GPP归属网絡的 AS发起互通场景 3的业务授权请求, 3GPP归属网络的 AS对该业务授权请求进行业务鉴权和授权, 如果成功, 则 AS给用户终 端发送接入允许消息,且 AS给用户终端分配相应的 PDG,用户终端与所 分配的 PDG之间建立隧道后,即可接入 3GPP PS域业务。同时, CGw/CCF 和 OCS根据用户终端的网絡使用情况记录计费信息。 在漫游情况下, 当 WLAN用户终端希望直接接入 Internet/Intranet时,用户终端可通过 3GPP 访问网络向 3GPP归属网络申请接入到 Internet/Intranet。 如果用户终端还 希望申请互通场景 3业务, 接入到 3GPP PS域业务, 则用户终端需要通 过 3GPP访问网络向 3GPP归属网络发起业务授权过程, 该过程同样在用 户终端和 3GPP归属网络的 AS之间进行, 当授权成功后, AS给用户终 端分配相应的归属 PDG,用户终端通过 3GPP访问网络中的 WAG与分配 的 PDG之间建立隧道后,用户终端即可接入归属网络的 3GPP PS域业务。
如图 3所示, 在 3GPP-WLAN互通网络中, 如果一个 WLAN同时与 多个 3GPP访问网络, 即与多个移动通信运营网相连, 这里 3GPP访问网 络就是指访问公众陆地移动网络 ( VPLMN ), 则 WLAN用户终端接入该 WLAN后, 就需要选择希望接入的 VPLMN网络, 比如: 在中国, 一个 WLAN接入网同时与中国移动、 中国联通两个 VPLMN运营网络连接, 那么, 中国联通的用户从 WLAN接入后, 就需要指示 WLAN接入网接入 中国联通的 VPLMN运营网络。
再比如, 某法国用户漫游到中国的某个 WLAN中, 如果该法国用户 的归属网络同时与中国移动、 中国联通都有漫游协议, 那么, 在 WLAN 接入网与中国移动、中国联通都相连的情况下,该法国用户在接入 WLAN 后, 就需要选择接入的 VPLMN网络。 但是, 用户终端如何将自身所选择 的需接入网络信息通知 WLAN接入网, 以及 3GPP-WLAN互通网络如何 利用用户终端的网络选择信息进行交互处理的过程,目前尚未有人提出具 体的解决方案。 发明内容
有鉴于此,本发明的主要目的在于提供一种无线局域网中用户终端网 络选择信息的交互处理方法,使用户终端在从一个连接有多个移动通信运 营网的 WLAN接入时, 能够根据需要选择适当的移动通信运营网接入。
为达到上述目的, 本发明的技术方案是这样实现的:
一种无线局域网(WLAN )中用户终端网络选择信息的交互处理方法, 该方法包括以下步驟:
a. WLAN用户终端与 WLAN接入网建立无线连接后 ,网络或 WLAN 用户终端发起接入认证过程, WLAN接入网向该 WLAN用户终端发送请 求用户名报文;
b. 所述 WLAN用户终端收到请求用户名报文后, 向 WLAN接入网 返回携带有网絡选择信息的报文;
c 网络判断所收到的报文中的向络选择信息是否属于当前 WLAN连 接的移动通信运营网, 如果是, 则将所述 WLAN用户终端的接入认证请 求发送至网络选择信息所标识的移动通信运营网, 否则, 网络向所述 WLAN用户终端发送通知信令, WLAN用户终端根据通知信令的内容完 成后续操作。
步驟 a中由 WLAN用户终端发起接入认证过程, 则步骤 a进一步包 括: 所述 WLAN用户终端在接入认证发起之前向网络发送下载网络信息 请求。 其中, 所述 WLAN用户终端向网络发送下载网络信息请求采用可 扩展认证协议(EAP )信令请求、 或采用门户 (Portal ) 交互方式请求。
步骤 b进一步包括: WLAN用户终端收到请求用户名报文后, 向网 络发送下载网络信息请求, 网络收到该请求后向该 WLAN用户终端下发 移动通信运营网信息; 该 WLAN用户终端才艮据收到的移动通信运营网信 息选择网络, 并重新向 WLAN接入网发送携带有新网络选择信息的接入 认证请求。其中, 所述下载网絡信息请求为放置于响应报文中的一个特定 字段, 或为响应报文中用户名字段的一个特定值, 或为单独设置的报文。
步骤 c中网络向所述 WLAN用户终端发送含有要发布的移动通信运 营网信息的通知信令, 则该方法进一步包括: 所述 WLAN用户终端收到 该通知信令后, 重新选定一个移动通信运营网, 并根据通知信令中的网络 信息得到该选定移动通信运营网对应的网络信息;然后再将携带有新网络 选择信息的报文发送给 WLAN接入网, 返回步骤 c。 这种情况下, 该方 法进一步包括: 网络在下发通知信令后等待用户终端的响应报文,等待一 定时间后未收到响应, 则网络主动向所述 WLAN用户终端下发选择结果 请求。 或者, 网络在下发通知信令后结束当前认证处理, 所述 WLAN用 户终端重新选定移动通信运营网后, 重新向 WLAN接入网发起接入认证 过程, 发送携带有新网络选择信息的接入认证信息。
步骤 c中网络向所述 WLAN用户终端发送指示用户终端当前所选网 络无效需要下载移动通信运营网信息的通知信令, 则该方法进一步包括: 所述 WLAN用户终端确定是否需要下载移动通信运营网信息,如果需要, 则所述 WLAN用户终端向网络返回需要下载网络信息的响应; 网络收到 该响应后,向所述 WLAN用户终端发布移动通信运营网信息;所述 WLAN 用户终端获得移动通信运营网信息后, 重新选择一个移动通信运营网, 并 重新向 WLAN接入网发送携带有新网络选择信息的接入认证请求, 返回 步驟 c; 否则, 不做处理或返回不需要下载的响应信息。 这种情况下, 该 方法进一步包括: 网絡在下发通知信令后等待用户终端的响应报文,等待 一定时间后未收到响应, 则网络主动向所述 WLAN用户终端下发移动通 信运营网信息。 或者, 网络在下发通知信令后结束当前处理流程, 如果所 述 WLAN用户终端需要下载网络信息,则该 WLAN用户终端主动发请求 发起网络信息下载流程。
上述方案中, 所述 WLAN用户终端根据预先设定的参数对网络下发 的移动通信运营网信息自动选择。
上述方案中, WLAN用户终端发送的网络选择信息属于当前 WLAN 连接的移动通信运营网, 则步骤 c进一步包括: 网絡判断所述网络选择信 息中是否包括访问网信息, 如果包括, 贝 ij WLAN接入网根据该访问网信 息将所述接入认证请求送至该用户终端当前所属访问网络的认证授权计 费代理(AAA Proxy ); 否则, WLAN接入网根据所述网络选择信息将所 述接入认证请求送至该用户终端归属网络的 AAA服务器。 如果所述网络 选择信息放置于网络接入标识(NAI )格式定义的用户标识字段中, 则步 骤 c进一步包括: AAA Proxy收到所述 WLAN用户终端的接入认证请求 后, 解析出用户标识字段中的归属网域名, 再根据归属网域名将所述 WLAN用户终端的接入认证请求送至归属网络的 AAA服务器完成接入认 证和授权。 该方法还进一步包括: AAA Proxy收到所述 WLAN用户终端 的接入认证请求后,判断出用户标识字段中包含访问网信息,且访问网信 息为本网信息, 则将用户标识字段改为只包含归属网域名, 然后再将修改 后的请求送往所述 WLAN用户终端的归属网絡。
步骤 c 中所述的判断和通知信令的发送由预先设定的网络信息判断 及通知发送单元完成。其中,所述网络信息判断及通知发送单元设置于接 入控制设备(AC ) 中; 或设置于任意移动通信运营网的认证授权计费 ( AAA )服务器中, 或为预先设置的 AAA代理设备。
WLAN用户终端当前所在网络为该用户终端的归属网络, 但 WLAN 用户终端发送的接入认证请求中包含有访问网信息,则当前网络直接将接 入认证请求中的访问网信息改为归属网信息。
WLAN用户终端当前所在网络为该用户终端的归属网络, 但 WLAN 用户终端发送的接入认证请求中包含有访问网信息, 则当前网络通知该 WLAN用户终端当前所在网絡为其归属网络, 然后判断该 WLAN用户终 端是否选择归属网络, 如果是, 则由当前网络对该 WLAN用户终端进行 接入认证; 否则, 由漫游网络对该 WLAN用户终端进行接入认证。
该方法进一步包括: 网络下发当前 WLAN连接的移动通信运营网信 息时 ,选择与当前用户终端所指示的归属网络有漫游关系的访问网络信息 下发。
上述方案中, WLAN网络采用 EAP通知报文 EAP-Request/notification 下发提供给 WLAN用户终端的移动通信运营网信息。
本发明所提供的无线局域网中用户终端网络选择信息的交互处理方 法, 由用户终端在接入 WLAN时直接通过接入认证请求携带自身的网絡 选择信息; 或是由用户终端根据 WLAN接入网下发的移动通信运营网信 息进行选择,并将网络选择信息通过接入认证请求发送给 WLAN接入网 , 以使 WLAN接入网能够根据用户终端的网络选择信息, 确定该用户终端 要接入的移动通信运营网,并由用户终端选定的移动通信运营网对该用户 终端进行认证, 解决了 WLAN用户终端自主选择移动通信运营网络时, 网络选择信息在用户终端和网络之间的交互处理问题。 附图简要说明
图 1为漫游情况下 WLAN系统与 3GPP系统互通的网络结构示意图; 图 2为非漫游情况下 WLAN系统与 3GPP系统互通的网络结构示意 图;
图 3为 WLAN与多个访问网络连接的网络结构示意图; 图 4为本发明用户终端网络选择信息的交互处理流程示意图; 图 5为本发明用户终端接入认证授权的流程示意图;
图 6为本发明网络选择信息交互处理实施例一的流程示意图; 图 7为本发明网络选择信息交互处理实施例二的流程示意图。 实施本发明的方式
本发明的基本思想是: WLAN用户终端通过接入认证请求将网络选 择信息发送给 WLAN接入网, WLAN接入网可以根据所携带的网络选择 信息,识别该用户终端所要接入的移动通信运营网,并将当前用户终端连 至所选的网络中进行接入认证及后续操作。
这里, 网络选择信息是指用户终端当前所要接入的与 WLAN网絡相 连的移动通信运营网信息,该选择信息可以是用户终端预先选定的,也可 以是用户终端根据网絡发布的移动通信运营网选择信息选定的。该网络选 择信息可以放置于接入认证请求中单独设置的字段内,也可以放置于接入 认证请求中以网络接入标识 ( NAI )格式定义的用户标识字段内。
基于图 3所示的网络结构,本发明中用户终端选择接入移动通信运营 网信息的交互处理过程, 如图 4所示, 包括以下步骤:
步骤 401: WLAN用户终端通过 WLAN接入 3GPP-WLAN互通网络 时, 由 WLAN用户终端或网络发起接入认证过程, 以下以 WLAN用户终 端发起接入认证过程为例 , WLAN用户终先向 WLAN接入网发送接入认 证请求;
步骤 402: WLAN接入网收到请求后, WLAN接入网与用户终端之 间开始接入认证过程, 即可扩展认证协议(EAP )过程。 具体地说就是: WLAN接入网向用户终端发送请求用户标识报文, 请求当前用户终端的 用户名; WLAN用户终端收到该请求后 , 向 WLAN接入网发送包含有网 络选择信息的响应用户标识报文, 如图 5中步骤 502、 503所示。 该网络 选择信息可放置于 NAI格式的用户标识字段中, 下面均以网絡选择信息 放置在用户标识字段为例, 所述用户标识字段包括用户名和域名两部分。
步骤 403 404: WLAN接入网收到携带有网络选择信息的响应报文 后,对该响应报文中的用户标识字段进行分析; 判断用户标识字段中携带 的网络选择信息是否为本 WLAN连接的移动通信运营网络, 如果是, 则 执行步骤 405; 否则, 即网絡选择信息中携带的移动通信运营网络 WLAN 不能识别, 则执行步骤 406。
步骤 405:根据用户标识字段 NAI中的网络选择信息,确定当前用户 终端要接入的移动通信运营网络, WLAN接入网将当前用户终端的接入 认证请求送到网络选择信息所标识的移动通信运营网络进行接入认证处 理。
这里, 如果 WLAN接入网根据用户标识字段中携带的网络选择信息 判断出包括访问网信息, 则 WLAN接入网根据用户标识字段中的访问网 信息将所述接入认证请求送至该用户终端所属访问网络的认证授权计费 代理( AAA Proxy ), 再由该 AAA Proxy将所述的接入认证请求转送至该 用户终端归属网络的 3GPP AAA服务器进行接入认证处理;否则, WLAN 接入网根据用户标识字段中的网络选择信息将所述接入认证请求送至该 用户终端归属网络的 AAA服务器进行接入认证处理, 如图 5中步驟 506 所示。 其中, 访问网络的 AAA Proxy收到用户终端的接入认证请求后, 判断出用户标识字段中包含访问网信息,且访问网信息为本网信息, 则将 用户标识字段中的域名部分改为只包含归属网域名,然后再将修改后的请 求送往该用户终端的归属网絡。
如果 WLAN用户终端当前所在的 WLAN网络就与该 WLAN用户终 端的归属网络直接相连, 但该用户终端采用漫游标识发起接入认证请求, 即所携带的网络选择信息中含有访问网信息,则当前网络可以直接将用户 标识字段 NAI中的访问网信息改为归属网络信息; 或者, 当前网络可以 向该用户终端发送通知提示用户当前所在网络为其归属网络,如果用户终 端重新以归属网信息发起接入认证请求,则当前网絡直接完成结入认证流 程,但如果用户终端仍确认要选择漫游网络,则当前网络通过漫游网络对 该用户终端进行接入认证并提供后续服务。
步骤 406〜407: 网络侧向当前用户终端发送通知信令, 当前用户终端 根据通知信令的内容继续后续的操作。这里,所述的通知信令可以直接采 用 WLAN协议中的通知报文 EAP-Request/Notification, 也可以采用一条 单独设置的通知信令。 所述网络向用户终端发送的通知信令分为两种情 况: 一种是在通知信令中直接包含有网络要发布的移动通信运营网信息, 以便 WLAN用户终端或用户直接进行选择; 另一种是该通知信令只作为 一个通知用户终端当前所选移动通信运营网信息无效,并指示用户终端需 要下载移动通信运营网信息的信令。
对于第一种情况, 由于该通知信令中包括本 WLAN所连接移动通信 运营网络信息, 则用户终端收到后可以重新选定一个移动通信运营网, 并 根据通知信令中的网络信息得到该选定移动通信运营网对应的网络信息 , 然后再将所选定的移动通信运营网信息放置在响应报文的用户标识字段 NAI中, 再次送给 WLAN接入网络进行判别, 返回步骤 403。 这里, 网 络可以在下发通知信令后等待用户终端的选择响应,等待一定时间后,如 果未收到响应, 则网络主动向用户终端下发选择结果请求; 网络也可以在 下发通知信令后不等待用户终端的选择响应,就结束当前处理流程, 由用 户终端重新主动发起第二次接入认证过程。
对于第二种情况, WLAN用户终端收到通知信令后, 可以自动选择 或由用户选择是否下载移动通信运营网信息, 所迷 WLAN用户终端自动 选择是指用户终端可以根据用户预先设定的参数对网络下发的信息自动 处理, 自动选择适当的移动通信运营网,也可以在必要时把信息显示给用 户进行选择,给用户显示信息时,用户终端可以判断选择显示与用户归属 网络有漫游关系的信息。 如果需要下载, 则由 WLAN用户终端向网络返 回需要下载网络信息的响应; 网络收到该响应后, 向该用户终端发布移动 通信运营网信息; WLAN用户终端获得移动通信运营网信息后, 重新选 择一个移动通信运营网,并重新发起携带有新网络选择信息的接入认证请 求, 返回步骤 403; 如果不需要下载, 则 WLAN用户终端不做处理或返 回不需要下载的响应信息。这里, 网络可以在下发通知信令后等待用户终 端的选择响应, 等待一定时间后, 如果未收到响应, 则网络主动向用户终 端发布移动通信运营网信息;网絡也可以在下发通知信令后不等待用户终 端的选择响应, 就结束当前处理流程, 如果用户终端需要下载网络信息, 则由用户终端主动发请求发起网络信息下载流程。
在上述两种情况下,网络提供给用户终端进行选择的移动通信运营网 信息存储在专门的网絡信息存储单元, 一般包括以下参数: 网络名称、 网 络承载能力 QOS、 带宽、 业务能力、 能够提供的 WLAN互通场景情况、 费率情况、 业务者种类等等。 网络下发当前 WLAN连接的移动通信运营 网信息时,可选择与当前用户终端所指示的归属网络有漫游关系的访问网 络信息下发, 如果没有则可以不下发, 或通知用户没有漫游关系存在。
在上述方案中,步骤 404中对网络选择信息的判断和步骤 406中通知 信息的发送可由同一个网络实体完成,该网络实体可称之为网络信息判断 及通知发送单元, 该网络信息判断及通知发送单元可以存在于 WLAN接 入网中, 比如设置于接入控制设备 ( AC ) 中; 也可以存在于当前 WLAN 接入网外、 某个与当前 WLAN接入网相连的移动通信运营网中, 同时为 多个 WLAN接入网服务, 比如设置在一个 AAA服务器中; 还可以预先 设置一个缺省的 AAA Proxy作为该网絡信息判断及通知发送单元。
在上述方案中,如果由用户终端发起接入认证流程, 而用户终端在接 入认证时不能确定所要选择的移动通信运营网,则用户终端可以在发送接 入认证请求之前或同时、或在接入认证过程中, 向网絡发送需要下载当前 WLAN连接的移动通信运营网信息的请求, 也就是说, 用户终端可在获 得移动通信运营网信息并选择网络后,再发起接入认证过程; 或下载网络 信息过程与接入认证过程并行。这里, WLAN用户终端可采用 EAP信令、 或釆用门户 (Portal ) 交互方式向网络发送下载网络信息请求。 该用户终 端也可以在收到 WLAN接入网发来的请求用户标识报文后, 向网络发送 需要下载当前 WLAN连接的移动通信运营网信息的请求, 该请求可以作 为一个独立的信令发送; 也可以将请求标识放置在响应用户标识^ :艮文中, 比如: 响应用户名为空而预先设定的下载请求字段被设置,或直接约定响 应中用户名为 OxFFFF时表示需要下载网络信息。 实施例一:
本实施例为 3GPP-WLAN 交互网络中, 预先设置一个缺省的 AAA Proxy作为网絡信息判断及通知发送单元, 该网络信息判断及通知发送单 元可为一个或多个 WLAN接入网服务, 如图 6所示, 本发明网络选择信 息的交互处理过程包括以下的步驟:
步骤 601〜603: 当一个 WLAN用户终端和 WLAN接入网建立无线连 接后, 该用户终端向 WLAN接入网发送接入认证请求; LAN接入网收 到后, 向该用户终端发送请求用户名报文 EAPoL-Request[Identity]; 该用 户终端收到后, 向 WLAN接入网发送携带有 NAI格式用户标识字段的响 应用户名报文 EAPoL- Response[Identity], 该用户标识字段中携带有网络 选择信息。
步骤 604〜605: WLAN接入网根据所接收到报文中的用户标识字段, 决定该 WLAN用户终端接入认证请求的发送路由。如果 WLAN接入网发 现用户标识字段无法识别, 即不属于与自身相连的移动通信运营网之一, 则将该接入认证请求路由到缺省 AAA Proxy。
步骤 606:缺省 AAA Proxy收到该接入认证请求后,发现其中的网络 选择信息与本 WLAN网所连接的移动通信运营网都不符合, 则发送通知 信令 EAP-Request/Notification给 WLAN接入网; LAN接入网再将该通 知信令下发给用户终端。 按照 EAP协议, WLAN接入网收到信令后和用 户接收信令后都会立即直接响应表明收到。 所述通知信令中携带有本 WLAN所连接的移动通信运营网信息, 该通知信令可以下发一条或多条, 根据最后一条 EAP报文中的指示信息决定结束交互。
步驟 607: 用户终端收到通知信令中携带的移动通信运营网信息后, 重新进行网络选择。这里, AAA Proxy和 WLAN接入网下发通知信令后, 会等待用户终端的响应。
步骤 608〜609: AAA Proxy 再次向当前 LAN 用户终端下发 EAP-Request [Identity]信令,请求用户标识。当前 WLAN用户终端收到后, 通过 EAPoL- Response[Identity]报文返回携带有新网络选择信息的用户标 识。
步骤 610~611: WLAN接入网根据当前用户终端发送的新网络选择信 息, 确定该用户终端所要接入的移动通信运营网, 这里指 VPLMN网络, 并将接入认证请求信息送到所标识的 VPLMN网络的 AAA Proxy及 AS 中进行接入认证处理。 实施例二:
本实施例为 3GPP-WLAN 交互网络中, 预先设置一个缺省的 AAA Proxy作为网络信息判断及通知发送单元, 该网络信息判断及通知发送单 元可为一个或多个 WLAN接入网服务, 如图 7所示, 本发明网络选择信 息的交互处理过程包括以下的步驟:
步骤 701〜707: 与实施例一中的步棟 601~607完全相同, 只是 AAA Proxy和 WLAN接入网下发通知信令后, 不等待用户终端的响应, 而直 接结束当前相关流程。
步骤 708: 由于 AAA Proxy和 WLAN接入网不等待用户终端响应, 因此, 当前 WLAN用户终端根据通知信令中的移动通信运营网信息重新 选择网络后, 通过初始认证报文 EAPOL-Start再次主动发起接入认证过 程。
步骤 709〜710: WLAN接入网收到 EAPOL-Start报文后,向该 WLAN 用户终端再次下发 EAP-Request[Identity]信令, 重新请求用户标识; 该 WLAN用户终端通过 EAPoL- Response [Identity]报文向 WLAN接入网返 回携带有新网络选择信息的用户标识。
步骤 711 712: WLAN接入网收到新的用户标识后,根据其中的新网 络选择信息确定该 WLAN 用户终端所选择的移动通信运营网, 并将该 WLAN用户终端的接入认证请求信息送到网絡选择信息所标识的网絡的 AAA Proxy及 AS中进行接入认证处理。这里, WLAN用户终端所选择的 漫游网络收到接入认证请求信息后,先将用户标识字段中的访问网信息改 为该用户终端的归属网信息,再将携带有修改后用户标识字段的接入认证 请求信息送至该用户终端归属网络的 AS进行认证处理。
以上所述,仅 本发明的较佳实施例而已, 并非用于限制本发明的保 护范围。

Claims

权利要求书
1、 一种无线局域网 (WLAN ) 中用户终端网络选择信息的交互处理 方法, 其特征在于, 该方法包括以下步骤:
a. WLAN用户终端与 WLAN接入网建立无线连接后,网络或 WLAN 用户终端发起接入认证过程, WLAN接入网向该 WLAN用户终端发送请 求用户名 ·ί艮文;
b. 所述 "WLAN用户终端收到请求用户名报文后 , 向 WLAN接入网 返回携带有网络选择信息的报文;
c 网络判断所收到的报文中的网絡选择信息是否属于当前 WLAN连 接的移动通信运营网, 如果是, 则将所述 WLAN用户终端的接入认证请 求发送至网絡选择信息所标识的移动通信运营网, 否则, 网络向所述 WLAN用户终端发送通知信令, WLAN用户终端根据通知信令的内容完 成后续操作。
2、 根据权利要求 1所述的方法, 其特征在于, 步骤 a中由 WLAN用 户终端发起接入认证过程, 则步骤 a进一步包括: 所述 WLAN用户终端 在接入认证发起之前向网络发送下载网络信息请求。
3、根据权利要求 2所述的方法, 其特征在于, 所述 WLAN用户终端 向网络发送下载网络信息请求采用可扩展认证协议(EAP )信令请求、 或 采用门户 (Portal ) 交互方式请求。
4、 根据权利要求 1所述的方法, 其特征在于, 步驟 b进一步包括: WLAN用户终端收到请求用户名报文后, 向网络发送下载网络信息请求, 网络收到该请求后向该 WLAN用户终端下发移动通信运营网信息; 该 WLA 用户终端根据收到的移动通信运营网信息选择网络, 并重新向 WLAN接入网发送携带有新网络选择信息的接入认证请求。
5、 根据权利要求 4所述的方法, 其特征在于, 所述下载网络信息请 求为放置于响应报文中的一个特定字段,或为响应报文中用户名字段的一 个特定值, 或为单独设置的报文。
6、 根据权利要求 1所述的方法, 其特征在于, 步驟 c中网络向所述 WLAN 用户终端发送含有要发布的移动通信运营网信息的通知信令, 则 该方法进一步包括: 所述 WLAN用户终端收到该通知信令后, 重新选定 一个移动通信运营网,并根据通知信令中的网络信息得到该选定移动通信 运营网对应的网络信息; 然后再将携带有新网络选择信息的报文发送给 WLAN接入网, 返回步骤
7、 根据权利要求 6所述的方法, 其特征在于, 该方法进一步包括: 网络在下发通知信令后等待用户终端的响应报文,等待一定时间后未收到 响应, 则网络主动向所述 WLAN用户终端下发选择结果请求。
8、 根据权利要求 6所述的方法, 其特征在于, 该方法进一步包括: 网络在下发通知信令后结束当前认证处理, 所述 WLAN用户终端重新选 定移动通信运营网后, 重新向 WLAN接入网发起接入认证过程, 发送携 带有新网络选择信息的接入认证信息。
9、 根据权利要求 1所述的方法, 其特征在于, 步驟 c中网絡向所述 WLAN用户终端发送指示用户终端当前所选网络无效需要下载移动通信 运营网信息的通知信令, 则该方法进一步包括: 所述 WLAN用户终端确 定是否需要下载移动通信运营网信息, 如果需要, 则所述 WLAN用户终 端向网絡返回需要下载网络信息的响应; 网络收到该响应后, 向所述 WLAN用户终端发布移动通信运营网信息; 所述 WLAN用户终端获得移 动通信运营网信息后, 重新选择一个移动通信运营网, 并重新向 WLAN 接入网发送携带有新网络选择信息的接入认证请求, 返回步驟 c; 否则, 不做处理或返回不需要下载的响应信息。
10、 居权利要求 9所述的方法, 其特征在于, 该方法进一步包括: 网絡在下发通知信令后等待用户终端的响应报文,等待一定时间后未收到 响应, 则网络主动向所述 LAN用户终端下发移动通信运营网信息。
11、 根据权利要求 9所述的方法, 其特征在于, 该方法进一步包括: 网络在下发通知信令后结束当前处理流程, 如果所述 WLAN用户终端需 要下载网络信息, 则该 WLAN用户终端主动发请求发起网络信息下载流 程。
12、 根据权利要求 6或 9所述的方法, 其特征在于, 所述 WLAN用 户终端根据预先设定的参数对网络下发的移动通信运营网信息自动选择。
13、 根据权利要求 1所述的方法, 其特征在于, WLAN用户终端发 送的网络选择信息属于当前 WLAN连接的移动通信运营网, 则步骤 c进 一步包括:网络判断所述网络选择信息中是否包括访问网信息,如果包括, 则 WLAN接入网根据该访问网信息将所述接入认证请求送至该用户终端 当前所属访问网络的认证授权计费代理(AAA Proxy ); 否则, WLAN接 入网根据所述网络选择信息将所述接入认证请求送至该用户终端归属网 络的 AAA服务器。
14、 根据权利要求 13所述的方法, 其特征在于, 所述网络选择信息 放置于网络接入标识(NAI )格式定义的用户标识字段中, 步骤 c进一步 包括: AAA Proxy收到所述 WLAN用户终端的接入认证请求后, 解析出 用户标识字段中的归属网域名, 再根据归属网域名将所述 WLAN用户终 端的接入认证请求送至归属网络的 AAA服务器完成接入认证和授权。
15、根据权利要求 14所述的方法, 其特征在于, 该方法进一步包括: AAA Proxy收到所述 WLAN用户终端的接入认证请求后, 判断出用户标 识字段中包含访问网信息,且访问网信息为本网信息, 则将用户标识字段 改为只包含归属网域名, 然后再将修改后的请求送往所述 WLAN用户终 端的归属网络。
16、根据权利要求 1所述的方法, 其特征在于, 步骤 c中所述的判断 和通知信令的发送由预先设定的网络信息判断及通知发送单元完成。
17、 根据权利要求 16所述的方法, 其特征在于, 所述网络信息判断 及通知发送单元设置于接入控制设备(AC ) 中; 或设置于任意移动通信 运营网的认证授权计费(AAA )服务器中, 或为预先设置的 AAA代理设 备。
18、 根据权利要求 1所述的方法, 其特征在于, WLAN用户终端当 前所在网絡为该用户终端的归属网络, 但 WLAN用户终端发送的接入认 证请求中包含有访问网信息,则当前网络直接将接入认证请求中的访问网 信息改为归属网信息。
19、 根据权利要求 1所述的方法, 其特征在于, WLAN用户终端当 前所在网絡为该用户终端的归属网络, 但 WLAN用户终端发送的接入认 证请求中包含有访问网信息, 则当前网络通知该 WLAN用户终端当前所 在网络为其归属网络, 然后判断该 WLAN用户终端是否选择归属网络, 如果是, 则由当前网络对该 WLAN用户终端进行接入认证; 否则, 由漫 游网络对该 WLAN用户终端进行接入认证。
20、 根据权利要求 4、 6或 9所述的方法, 其特征在于, 该方法进一 步包括: 网络下发当前 WLAN连接的移动通信运营网信息时, 选择与当 前用户终端所指示的归属网络有漫游关系的访问网络信息下发。
21、 根据权利要求 6或 9所述的方法, 其特征在于, WLAN网絡采 用 EAP通知报文 EAP-Request/notification下发提供给 WLA 用户终端的 移动通信运营网信息。
PCT/CN2004/000738 2003-07-04 2004-07-02 An alternation disposal method for network selection information of user terminal in wlan Ceased WO2005004384A1 (en)

Priority Applications (5)

Application Number Priority Date Filing Date Title
BRPI0412316-6A BRPI0412316A (pt) 2003-07-04 2004-07-02 método de processamento interativo para informações de seleção de rede de terminal do usuário em uma rede de área local sem fio
CA002531141A CA2531141A1 (en) 2003-07-04 2004-07-02 Interactive processing method for network selection information of user terminal in wireless local area network
EP04738336A EP1643676A4 (en) 2003-07-04 2004-07-02 ALTERNATIVE REJECTION METHOD FOR NETWORK SELECTION INFORMATION OF A USER TERMINAL IN A WIRELESS LOCAL NETWORK
JP2006517939A JP2007507124A (ja) 2003-07-04 2004-07-02 無線ローカルエリアネットワーク内のユーザ端末のネットワーク選択情報の変更処理方法
US11/324,860 US20060179310A1 (en) 2003-07-04 2006-01-04 Interactive processing method for selecting network information for a user terminal in a wireless local area network

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN03146218.9 2003-07-04
CNB031462189A CN1271822C (zh) 2003-07-04 2003-07-04 无线局域网中用户终端网络选择信息的交互处理方法

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US11/324,860 Continuation-In-Part US20060179310A1 (en) 2003-07-04 2006-01-04 Interactive processing method for selecting network information for a user terminal in a wireless local area network

Publications (1)

Publication Number Publication Date
WO2005004384A1 true WO2005004384A1 (en) 2005-01-13

Family

ID=33557737

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2004/000738 Ceased WO2005004384A1 (en) 2003-07-04 2004-07-02 An alternation disposal method for network selection information of user terminal in wlan

Country Status (7)

Country Link
US (1) US20060179310A1 (zh)
EP (1) EP1643676A4 (zh)
JP (1) JP2007507124A (zh)
CN (1) CN1271822C (zh)
BR (1) BRPI0412316A (zh)
CA (1) CA2531141A1 (zh)
WO (1) WO2005004384A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007044969A3 (en) * 2005-10-12 2007-06-14 Cingular Wireless Ii Llc Architecture that manages access between a mobile communications device and an ip network

Families Citing this family (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1277380C (zh) * 2003-08-07 2006-09-27 华为技术有限公司 无线局域网中用户终端确定网络选择信息的交互方法
DE102005013908A1 (de) * 2005-03-24 2006-09-28 Siemens Ag Optimale Auswahl eines Kommunikationsnetzes im Aufenthaltsort eines Endgerätes
EP1988730A4 (en) * 2006-02-22 2011-09-28 Nec Corp RADIO ACCESS SYSTEM AND RADIO ACCESS METHOD
US20070268908A1 (en) * 2006-05-17 2007-11-22 T-Mobile Usa, Inc. System and method for authorizing access to a UMA network based on access point identifier
DE102006038591B4 (de) * 2006-08-17 2008-07-03 Siemens Ag Verfahren und Anordnung zum Bereitstellen eines drahtlosen Mesh-Netzwerks
US7885654B2 (en) * 2006-10-10 2011-02-08 Apple Inc. Dynamic carrier selection
CA2619397C (en) 2006-10-20 2015-03-31 T-Mobile Usa, Inc. System and method for authorizing access to an ip-based wireless telecommunications service
KR100864902B1 (ko) 2007-04-17 2008-10-22 성균관대학교산학협력단 확장 가능 인증프로토콜을 사용하는 인증 방법, 인증시스템 및 그 프로그램이 기록된 기록매체
WO2008154218A1 (en) * 2007-06-06 2008-12-18 Interdigital Technology Corporation Method and apparatus for providing cell information list for non-3gpp capable user equipment operating in a 3gpp network and supporting layer-2 based handoff from a utran system to a non-3gpp system
CN101478576B (zh) * 2008-01-03 2012-02-15 华为技术有限公司 选择服务网络的方法、装置和系统
US9301238B2 (en) * 2009-03-06 2016-03-29 Qualcomm Incorporated Methods and apparatus for automated local network formation using alternate connected interfaces
US9629038B2 (en) * 2009-06-04 2017-04-18 Blackberry Limited Methods and apparatus for use in facilitating the communication of neighboring network information to a mobile terminal with use of a radius compatible protocol
CN102056168A (zh) * 2009-10-28 2011-05-11 中兴通讯股份有限公司 接入方法及装置
CN103973658A (zh) * 2013-02-04 2014-08-06 中兴通讯股份有限公司 静态用户终端认证处理方法及装置
CN104468574B (zh) * 2014-12-05 2018-03-23 中国联合网络通信集团有限公司 一种虚拟机动态获取ip地址的方法、系统及装置
CN108616490B (zh) * 2016-12-13 2020-11-03 腾讯科技(深圳)有限公司 一种网络访问控制方法、装置及系统

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1259811A (zh) * 1998-05-07 2000-07-12 朗迅科技公司 用于在通信系统中进行鉴权的方法和装置
WO2002023819A2 (en) * 2000-09-15 2002-03-21 Koninklijke Philips Electronics N.V. Dynamic channel selection scheme for idee 802.11 wlans

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FI114276B (fi) * 2002-01-11 2004-09-15 Nokia Corp Verkkovierailun järjestäminen
US7835317B2 (en) * 2002-10-08 2010-11-16 Nokia Corporation Network selection in a WLAN
CA2527831C (en) * 2003-06-30 2014-06-10 Telecom Italia S.P.A. A method for network selection in communication networks, related network and computer program product therefor

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1259811A (zh) * 1998-05-07 2000-07-12 朗迅科技公司 用于在通信系统中进行鉴权的方法和装置
WO2002023819A2 (en) * 2000-09-15 2002-03-21 Koninklijke Philips Electronics N.V. Dynamic channel selection scheme for idee 802.11 wlans

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP1643676A4 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007044969A3 (en) * 2005-10-12 2007-06-14 Cingular Wireless Ii Llc Architecture that manages access between a mobile communications device and an ip network
US9775093B2 (en) 2005-10-12 2017-09-26 At&T Mobility Ii Llc Architecture that manages access between a mobile communications device and an IP network

Also Published As

Publication number Publication date
BRPI0412316A (pt) 2006-08-22
CN1271822C (zh) 2006-08-23
US20060179310A1 (en) 2006-08-10
CN1567872A (zh) 2005-01-19
EP1643676A4 (en) 2006-08-02
JP2007507124A (ja) 2007-03-22
CA2531141A1 (en) 2005-01-13
EP1643676A1 (en) 2006-04-05

Similar Documents

Publication Publication Date Title
JP4335918B2 (ja) 利用者端末が、wlanインターワーキングネットワークにおいてアクセスするべき移動通信ネットワークを高速に選択するための相互接続方法
WO2005011305A1 (en) A optimization mutual method of the user terminal select accessing mobile network in wlan
EP1693988B1 (en) A method of the subscriber terminal selecting the packet data gateway in the wireless local network
WO2005004403A1 (en) A method for processing the network-selected information at the user terminal in a wireless local area network
WO2005018140A1 (en) Method of user terminal accessing quickly home network in wireless local area network
WO2004109980A1 (en) A method of user access authorization in the wlan
WO2009100676A1 (zh) 用户设备选择网络的方法及装置
WO2005004384A1 (en) An alternation disposal method for network selection information of user terminal in wlan
WO2005076532A1 (en) The interactive method for re-selecting the operation network by the wireless area network wlan user terminal
WO2004114588A1 (fr) Procede de transmission de donnees de trafic a des utilisateurs d'un reseau local sans fil
JP4309426B2 (ja) ワイアレスローカルエリアネットワークにおけるユーザー端末のネットワーク選択情報を決定する対話型方法
WO2005015822A1 (en) A method of avoiding selecting network frequently in wireless local area network
WO2007082479A1 (en) A method and system for establishing the tunnel in wlan
WO2005074194A1 (fr) Procede interactif d'un terminal d'utilisateur de reseau local sans fil de reselection d'un reseau de gestion
WO2005018148A1 (fr) Procede de maintien par le terminal utilisateur d'une configuration de selection de reseau initiale dans un reseau local sans fil
US8458773B2 (en) Method, device, and system for authentication
WO2005069533A1 (en) A method of acquiring permanent user identification by the packet data gateway (pdg) in the wlan
WO2005062631A1 (en) Method of redirecting packet data gateway in wireless local area network
KR100664604B1 (ko) 무선 근거리 통신망에서 사용자 단말기의 네트워크 선택 정보를 결정하는 인터랙티브 방법
CN100387010C (zh) 无线局域网中用户终端获取分组数据关口信息的方法
WO2004114589A1 (en) A method of transmitting traffic data to the users of wireless local area network
WO2005074192A1 (en) A method of obtaining the packet data gateway (pdg) address for the user terminal in wireless local area network (wlan)
WO2005004504A1 (en) A method about network transmit information to user terminal

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): BW GH GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 2531141

Country of ref document: CA

WWE Wipo information: entry into national phase

Ref document number: 11324860

Country of ref document: US

Ref document number: 2006517939

Country of ref document: JP

WWE Wipo information: entry into national phase

Ref document number: 2004738336

Country of ref document: EP

WWP Wipo information: published in national office

Ref document number: 2004738336

Country of ref document: EP

WWP Wipo information: published in national office

Ref document number: 11324860

Country of ref document: US

ENP Entry into the national phase

Ref document number: PI0412316

Country of ref document: BR