WO2015054853A1 - 分流方法、基站及用户设备 - Google Patents
分流方法、基站及用户设备 Download PDFInfo
- Publication number
- WO2015054853A1 WO2015054853A1 PCT/CN2013/085340 CN2013085340W WO2015054853A1 WO 2015054853 A1 WO2015054853 A1 WO 2015054853A1 CN 2013085340 W CN2013085340 W CN 2013085340W WO 2015054853 A1 WO2015054853 A1 WO 2015054853A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- user equipment
- base station
- wlan
- data stream
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/062—Pre-authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0457—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply dynamic encryption, e.g. stream encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W72/00—Local resource management
- H04W72/20—Control channels or signalling for resource management
- H04W72/21—Control channels or signalling for resource management in the uplink direction of a wireless link, i.e. towards the network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W72/00—Local resource management
- H04W72/20—Control channels or signalling for resource management
- H04W72/23—Control channels or signalling for resource management in the downlink direction of a wireless link, i.e. towards a terminal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/02—Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
- H04W84/10—Small scale networks; Flat hierarchical networks
- H04W84/12—WLAN [Wireless Local Area Networks]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/02—Terminal devices
- H04W88/06—Terminal devices adapted for operation in multiple networks or having at least two operational modes, e.g. multi-mode terminals
Definitions
- the present invention relates to a radio access technology, and in particular, to a shunting method, a base station, and a user equipment, and belongs to the technical field of wireless communications. Background technique
- CA Carrier Aggregation
- Carrier aggregation in the same system means that the carriers used by one UE are carriers in the same system.
- the carriers are all Long Term Evolution (LTE) systems, or the carriers are all Universal Mobile Telecommunications. System, referred to as UMTS).
- LTE Long Term Evolution
- UMTS Universal Mobile Telecommunications. System
- Carrier aggregation of different systems refers to that the carriers used by one UE belong to different systems, such as carriers belonging to LTE and UMTS, LTE and Wireless Local Access Network (WLAN) or UMTS and WLAN systems.
- Carrier aggregation of different systems can make full use of the characteristics of various communication systems to achieve efficient and low-cost transmission.
- the embodiment of the present invention provides a method for offloading data, a base station, and a user base station, to implement data splitting in carrier aggregation of different systems, and to solve the problem of using the carrier aggregation of different systems including the WLAN to perform data service splitting. Long delay leads to data traffic disruption question.
- an embodiment of the present invention provides a method for offloading, including:
- the base station sends an authentication authentication indication to the user equipment, where the authentication authentication indication is used to instruct the user equipment to initiate authentication with the wireless local area network WLAN, and the base station implements wireless communication based on a cellular wireless communication technology, and the WLAN is based on wireless
- the Fidelity Wi-Fi access technology implements wireless communication; the base station acquires an authentication authentication status report that the user equipment is admitted to the WLAN; and the base station determines, according to the authentication and authentication status report, the WLAN
- the access point interacts with the first data stream of the data stream to be processed, where the data stream to be processed is a data stream to be sent by the base station to the user equipment or a data stream to be sent by the user equipment to the base station.
- the sending, by the base station, the authentication authentication indication to the user equipment specifically includes:
- the base station sends the authentication authentication indication to the user equipment, where the authentication authentication indication includes the identifier of the WLAN, so that the user equipment performs authentication authentication with the WLAN according to the identifier of the WLAN.
- the second possible implementation manner further includes:
- the base station acquires a key by using the authentication, the key is used by the user equipment and the base station to perform encryption and decryption of a second data stream of the to-be-processed data stream, where the second data stream is a data stream sent by the base station to the user equipment based on the cellular wireless communication technology;
- the base station indicates to the WLAN access point that the user equipment is a trusted device, and the trusted device indicates that the user equipment is admitted to the WLAN access point via the authentication authentication;
- the WLAN access point sends the key, and the key is further used by the user equipment to perform encryption and decryption of the first data stream with the WLAN access point.
- the method further includes:
- the base station sends the authentication request to the authentication server, so that the authentication server and the user equipment perform the authentication and authentication through a downlink tunnel.
- an embodiment of the present invention provides a method for distributing a flow, including: The user equipment receives the authentication authentication indication sent by the base station, where the authentication authentication indication is used to instruct the user equipment to initiate authentication with the wireless local area network WLAN, and the base station implements wireless communication based on the cellular wireless communication technology, where the WLAN is based on Wireless fidelity Wi-Fi access technology to achieve wireless communication;
- the user equipment and the base station exchange the first data stream of the data stream to be processed by the access point of the WLAN, where the data stream to be processed is a data stream to be sent by the base station to the user equipment or Describe the data stream to be sent by the user equipment to the base station.
- the authentication authentication indication includes the
- the identifier of the WLAN further includes:
- the second possible implementation manner further includes:
- the user equipment completes the admission by using an access point of the WLAN or the base station
- the method further includes:
- the user equipment encrypts and decrypts a second data stream of the to-be-processed data stream transmitted between the user equipment and the base station by using a key acquired by the base station by using the authentication, the second data stream. And the data stream sent by the base station to the user equipment based on the cellular wireless communication technology; the user equipment uses the key to encrypt and decrypt the transmission between the user equipment and an access point of the WLAN The first data stream of the data stream to be processed.
- the method further includes:
- the user equipment sends an authentication request to the base station by using an uplink tunnel with the base station, where the authentication request is used by the user equipment to initiate the authentication authentication.
- an embodiment of the present invention provides a base station, including:
- a sending unit configured to send an authentication authentication indication to the user equipment, where the authentication authentication indication is used to instruct the user equipment to initiate authentication authentication with a wireless local area network WLAN, and the base station is based on cellular wireless
- the communication technology implements wireless communication, and the WLAN implements wireless communication based on a wireless fidelity Wi-Fi access technology;
- An obtaining unit configured to obtain an authentication and authentication status report that the user equipment is admitted to the WLAN.
- the splitting unit is configured to determine, according to the authentication and authentication status report, the data stream to be processed to be accessed by the access point of the WLAN.
- the first data stream, where the data stream to be processed is a data stream to be sent by the base station to the user equipment or a data stream to be sent by the user equipment to the base station.
- the sending unit is specifically configured to:
- the authentication authentication indication includes the identifier of the WLAN, so that the user equipment performs authentication authentication with the WLAN according to the identifier of the WLAN.
- the acquiring unit is further configured to acquire a key by using the authentication, where the key is used by the user equipment and the base station to perform encryption and decryption of a second data stream of the to-be-processed data stream, where The second data stream is a data stream sent by the base station to the user equipment based on the cellular wireless communication technology;
- the base station further includes an indication unit, configured to indicate, to the WLAN access point, that the user equipment is a trusted device, where the trusted device indicates that the user equipment accesses the WLAN access via the authentication authentication Point
- the sending unit is further configured to send the key to the WLAN access point, where the key is further used by the user equipment to perform encryption and decryption of the first data stream with the WLAN access point.
- the acquiring unit is further configured to receive an authentication request sent by the user equipment by using an uplink tunnel with the user equipment, where the authentication request is used by the user equipment to initiate the authentication authentication;
- the unit is further configured to send the authentication request to the authentication server, so that the authentication server and the user equipment perform the authentication and authentication through a downlink tunnel.
- an embodiment of the present invention provides a user equipment, including: a receiving unit, configured to receive an authentication authentication indication sent by the base station, where the authentication authentication indication is used to instruct the user equipment to initiate authentication with a wireless local area network WLAN, and the base station implements wireless communication based on a cellular wireless communication technology.
- the WLAN implements wireless communication based on a wireless fidelity Wi-Fi access technology;
- a sending unit configured to send, to the base station, an authentication authentication status report that the user equipment is admitted to the WLAN;
- the receiving unit is further configured to: interact with the base station to access a first data stream of a data stream to be processed by using an access point of the WLAN, where the to-be-processed data stream is data that is sent by the base station to the user equipment.
- the authentication authentication indication includes the
- the identifier of the WLAN, where the user equipment further includes:
- a processing unit configured to perform authentication authentication with the WLAN according to the identifier of the WLAN.
- the processing unit is specifically configured to:
- the access to the WLAN authentication process is completed by the access point of the WLAN or the base station.
- the method further includes:
- Encryption and decryption unit used to:
- the sending unit is further configured to be used between the base station and the base station
- the uplink tunnel sends an authentication request to the base station, where the authentication request is used by the user equipment to initiate the authentication authentication.
- an embodiment of the present invention provides a base station, including:
- a transmitter configured to send an authentication authentication indication to the user equipment, where the authentication authentication indication is used to refer to Demonstrating that the user equipment initiates authentication authentication with a wireless local area network WLAN, the base station implements wireless communication based on a cellular wireless communication technology, and the WLAN implements wireless communication based on a wireless fidelity Wi-Fi access technology;
- a receiver configured to obtain an authentication authentication status report that the user equipment is admitted to the WLAN
- a processor configured to determine, according to the authentication and authentication status report, a data flow to be processed to be exchanged with the access point of the WLAN
- the first data stream where the data stream to be processed is a data stream to be sent by the base station to the user equipment or a data stream to be sent by the user equipment to the base station.
- the transmitter is specifically configured to:
- the authentication authentication indication includes the identifier of the WLAN, so that the user equipment performs authentication authentication with the WLAN according to the identifier of the WLAN.
- the receiver is further configured to acquire a key by using the authentication, the key is used by the user equipment and the base station to perform encryption and decryption of a second data stream of the to-be-processed data stream, where the second The data stream is a data stream that is sent by the base station to the user equipment based on the cellular radio communication technology;
- the transmitter is further configured to indicate to the WLAN access point that the user equipment is a trusted device, where the trusted The device indicates that the user equipment is admitted to the WLAN access point via the authentication authentication;
- the transmitter is further configured to send the key to the WLAN access point, where the key is further used by the user equipment to perform encryption and decryption of the first data stream with the WLAN access point.
- the receiver is further configured to receive, by using an uplink tunnel with the user equipment, an authentication request sent by the user equipment, where the authentication request is used by the user equipment to initiate the authentication and authentication;
- the transmitter is further configured to send the authentication request to the authentication server, so that the authentication server and the user equipment perform the authentication and authentication through a downlink tunnel.
- an embodiment of the present invention provides a user equipment, including:
- a receiver configured to receive an authentication authentication indication sent by the base station, where the authentication authentication indication is used to refer to Demonstrating that the user equipment initiates authentication with a wireless local area network WLAN, the base station implements wireless communication based on a cellular wireless communication technology, and the WLAN implements wireless communication based on a wireless fidelity Wi-Fi access technology;
- a transmitter configured to send, to the base station, an authentication and authentication status report that the user equipment is admitted to the WLAN;
- the receiver is further configured to: interact with the base station, by using an access point of the WLAN, a first data stream of a data stream to be processed, where the to-be-processed data stream is data that is sent by the base station to the user equipment.
- the authentication authentication indication includes the identifier of the WLAN, where the user equipment further includes:
- a processor configured to perform authentication authentication with the WLAN according to the identifier of the WLAN.
- the processor is specifically configured to:
- the access to the WLAN authentication process is completed by the access point of the WLAN or the base station.
- the processor is further configured to:
- the transmitter is further configured to:
- the invention sends the authentication authentication indication to the user equipment in advance by the base station before the data is offloaded, so that the base station performs the traffic distribution according to the authentication and authentication status report to avoid the authentication of the WLAN when the service data is offloaded.
- the interruption of the data service is caused by the long delay of the WLAN authentication authentication.
- 2 is a network topology diagram of user equipment performing authentication and authentication in a tunnel manner
- Embodiment 3 is a schematic flowchart of Embodiment 2 of a method for distributing a flow according to the present invention
- Embodiment 4 is a signaling interaction diagram of Embodiment 3 of a traffic distribution method according to the present invention.
- FIG. 5 is a structural diagram of Embodiment 1 of a base station according to the present invention.
- Embodiment 2 of a base station is a structural diagram of Embodiment 2 of a base station according to the present invention.
- Embodiment 7 is a structural diagram of Embodiment 1 of a user equipment according to the present invention.
- Embodiment 8 is a structural diagram of Embodiment 2 of a user equipment according to the present invention.
- Embodiment 9 is a structural diagram of Embodiment 3 of a base station according to the present invention.
- FIG. 10 is a structural diagram of Embodiment 3 of a user equipment according to the present invention. detailed description
- GSM Global System for Mobile Communications
- CDMA Shima Division Multiple Access
- TDMA Time Division Multiple Access
- WCDMA Wideband Code Division Multiple Access
- FDMA Frequency Division Multiple Access
- FDMA Frequency Division Multiple Addressing
- OFDM Orthogonal Frequency-Division Multiple Access
- SC-FDMA single carrier FDMA
- GPRS General Packet Radio Service
- LTE Long Term Evolution
- the terminal which may be a wireless terminal or a wired terminal, may be a device that provides voice and/or data connectivity to the user, a handheld device with wireless connectivity, or other processing device connected to the wireless modem.
- the wireless terminal can communicate with one or more core networks via a radio access network (eg, RAN, Radio Access Network), which can be a mobile terminal, such as a mobile phone (or "cellular" phone) and with a mobile terminal
- RAN Radio Access Network
- the computers for example, can be portable, pocket-sized, handheld, computer-integrated or in-vehicle mobile devices that exchange language and/or data with the wireless access network.
- a wireless terminal may also be called a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, an access point, or an access point.
- Remote Terminal Access Terminal, User Terminal, User Agent, User Device, or User Equipment.
- a base station can refer to a device in an access network that communicates with a wireless terminal over one or more sectors over an air interface.
- the base station can be used to convert the received air frame to the IP packet as a router between the wireless terminal and the rest of the access network, wherein the remainder of the access network can include an Internet Protocol (IP) network.
- IP Internet Protocol
- the base station can also coordinate attribute management of the air interface.
- the base station may be a base station (BTS, Base Transceiver Station) in GSM or CDMA, or may be a base station (NodeB) in WCDMA, or may be an evolved base station in LTE (NodeB or eNB or e-NodeB, evolutional Node B), the invention is not limited.
- Embodiment 1 is a flowchart of Embodiment 1 of a method for offloading according to the present invention.
- the method in this embodiment is applicable to a wireless communication system, and the execution subject is a base station.
- the method includes the following steps:
- Step 101 The base station sends an authentication authentication indication to the user equipment, where the authentication authentication indication is used to instruct the user equipment to initiate authentication with the WLAN, and the base station implements wireless communication based on a cellular wireless communication technology, where the WLAN is based on Wireless fidelity (Wi-Fi) Access technology enables wireless communication.
- Wi-Fi Wireless fidelity
- the base station may send, to the user equipment, an authentication authentication indication of the WLAN in a broadcast manner;
- the base station may also send an authentication authentication indication of the WLAN to the user equipment by using a Radio Resource Control (RRC) signaling.
- RRC Radio Resource Control
- the sending, by the base station, the authentication authentication indication to the user equipment specifically:
- the base station sends the authentication authentication indication to the user equipment, where the authentication authentication indication includes the identifier of the WLAN, so that the user equipment performs authentication authentication with the WLAN according to the identifier of the WLAN.
- the authentication authentication indication includes the identifier of the WLAN, so that the user equipment performs authentication authentication with the WLAN according to the identifier of the WLAN.
- the identifier of the WLAN For example, the Basic Service Set Identifier (BSSID) or / and the Service Set Identifier (SSID).
- BSSID Basic Service Set Identifier
- SSID Service Set Identifier
- the indication information may further include a WLAN advance authentication authentication indication permission indication.
- a WLAN advance authentication authentication indication permission indication For example, a Boolean type indication can be used, which is set to true “True”, which means that the user equipment is allowed to perform pre-authentication authentication on the WLAN.
- Step 102 The base station acquires an authentication and authentication status report that the user equipment is admitted to the WLAN.
- the user equipment receives the authentication authentication indication of the WLAN sent by the base station, according to the related content in the indication information, such as the identifier of the WLAN or whether the user equipment is allowed to authenticate the WLAN in advance, the user equipment is selected to perform authentication authentication on the relevant WLAN.
- a web page (WEB) authentication or an extensible authentication protocol-expressible authentication protocol-Subscriber Identity Modules/Authentication and Key Agreement (EAP-SIM/AKA authentication method) may be used.
- the authentication indication information does not include the identifier of the specified WLAN
- the user equipment may also select the relevant WLAN as the designated WLAN for authentication according to the network condition of the user.
- the obtaining, by the base station, the authentication and authentication status report of the user equipment to the WLAN includes: the base station receiving, by the user equipment, the authentication and authentication of the WLAN that is sent after the user equipment completes the authentication and authentication process.
- the status report is; or, the base station receives the authentication and authentication status report of the WLAN that is sent by the WLAN after completing the authentication and authentication process.
- the user equipment can directly send a report of the authentication status to the base station.
- the report of the authentication and authentication status can be completed by using an RRC message.
- the base station can return an acknowledgement message to the user equipment.
- the base station may store the authentication and authentication status report, and may also forward the authentication and authentication status report to the Mobility Management Entity (MME) for storage.
- MME Mobility Management Entity
- the WLAN sends an authentication authentication status notification message to the base station, and the authentication authentication status notification message may be forwarded to the base station by using the MME, and the base station may parse the pre-registration status update from the authentication authentication status notification message. Notify relevant information.
- Step 103 The base station determines, according to the authentication and authentication status report, a first data stream that interacts with the access point of the WLAN to process a data stream, where the to-be-processed data stream is sent by the base station to the A data stream of the user equipment or a data stream to be sent by the user equipment to the base station.
- the base station when performing the WLAN offload data decision, refers to the current authentication and authentication status of the user equipment, that is, only the user equipment and the WLAN through which the authentication is authenticated can perform data shunting.
- the traffic flow factor may also be considered. For example, if the data service requires high reliability of the transmission data, the base station may consider not selecting the carrier aggregation offload because of the handover loss rate of the WLAN.
- carrier shunting can be prioritized, especially for relatively static, indoor active network environments.
- the base station authenticates the WLAN, and the data service offload is interrupted due to the long delay of the authentication of the WLAN.
- This embodiment sends the data service to the user equipment in advance.
- the authentication authentication indication of the WLAN is implemented to perform traffic distribution according to the WLAN authentication and authentication status report when the base station performs data classification, so as to avoid authentication and authentication of the WLAN when the service data is offloaded, so as to implement seamless offloading.
- the method further includes:
- the base station acquires a key by using the authentication, the key is used by the user equipment and the base station to perform encryption and decryption of a second data stream of the to-be-processed data stream, where the second data stream is The data stream that the base station interacts with the user equipment based on the cellular wireless communication technology;
- the base station indicates to the WLAN access point that the user equipment is a trusted device, and the trusted device indicates that the user equipment is admitted to the WLAN access point via the authentication authentication;
- the WLAN access point sends the key, and the key is further used by the user equipment and the WLAN access point to perform encryption and decryption of the first data stream.
- the base station indicates that the key used in the WLAN may be a key used for data transmission between the base station and the user equipment, and thus, the first data stream and the second data stream that are exchanged between the WLAN, the base station, and the user equipment.
- the keys used are consistent, avoiding data shunting at the base station.
- the processing caused by using multiple keys is complicated.
- the direct reply authentication succeeds, and the authentication server does not need to be transferred to the authentication server to improve the efficiency of the authentication.
- the method further includes:
- the base station sends the authentication request to the authentication server, so that the authentication server and the user equipment perform the authentication and authentication through a downlink tunnel.
- the network architecture diagram includes user equipment, WLAN access point, base station, and mobile management entity server.
- the authentication server first, the user equipment sends a UL Information Transfer message to the base station; the EAP-SIM authentication message is encapsulated in the UL Information Transfer message from the terminal to the base station; and the authentication WLAN routing information is used to identify the authentication.
- Uplink WLAN AKA Tunneling Uplink WLAN AKA Tunneling
- the message exchange of the authentication authentication is completed by the downlink tunnel message.
- the authentication server sends an EAP Success message to the base station, and the generated WLAN access point and the WLAN user equipment are generated.
- the confidentiality of the inter-link protection and the authentication key of the integrity protection are transmitted to the base station.
- the user equipment sends the relevant key to the base station; the base station saves the key as part of the user equipment context.
- the base station selects the WLAN offload data
- the base station sends an authentication success identifier and a related key to the WLAN access point; the user equipment accesses the WLAN access point, and uses related key encryption and integrity protection.
- the user equipment and the authentication server can perform authentication and authentication by using the uplink and downlink tunnels established with the base station, thereby improving the security and reliability of the authentication authentication.
- Embodiment 1 is a flowchart of Embodiment 1 of the method for offloading according to the present invention.
- the method in this embodiment is applicable to a wireless communication system, such as a 2G ⁇ 3G ⁇ 4G communication system, and the execution subject is a user equipment, such as a smart phone, as shown in FIG.
- the method includes the following steps:
- Step 301 The user equipment receives an authentication authentication indication sent by the base station, where the authentication authentication indication is used to instruct the user equipment to initiate authentication authentication with the WLAN, and the base station implements wireless communication according to a cellular wireless communication technology, where the WLAN Wireless communication is implemented based on Wi-Fi access technology.
- the authentication authentication indication includes the identifier of the WLAN
- the method further includes: the user equipment performing authentication authentication with the WLAN according to the identifier of the WLAN.
- Step 302 The user equipment sends, to the base station, an authentication and authentication status report that the user equipment is admitted to the WLAN.
- the user equipment After receiving the authentication and authentication indication, the user equipment initiates authentication and authentication with the WLAN of the wireless local area network.
- the user equipment may include:
- the user equipment completes the admission of the WLAN authentication authentication process by using an access point of the WLAN or the base station.
- the status of the authentication authentication is reported to the base station for transmission.
- Step 303 The user equipment and the base station exchange the first data stream of the data stream to be processed by the access point of the WLAN, where the data stream to be processed is a data stream to be sent by the base station to the user equipment. Or a data stream to be sent by the user equipment to the base station.
- the UE performs the authentication authentication on the WLAN that participates in the offloading by receiving the authentication authentication indication sent by the base station, so as to solve the problem that the WLAN is authenticated during the data offloading in the prior art.
- the service interruption problem that causes the traffic off is longer, and the service data carrier is switched seamlessly.
- the method further includes:
- the user equipment encrypts and decrypts a second data stream of the to-be-processed data stream transmitted between the user equipment and the base station by using a key acquired by the base station by using the authentication, the second data stream.
- the user equipment encrypts and decrypts the first data stream and the second data stream of the to-be-processed data stream by using the key acquired by the base station via the authentication authentication, so that interaction between the WLAN, the base station, and the user equipment is performed.
- the keys used by the first data stream and the second data stream are all consistent, and the processing caused by using multiple keys when the base station performs data offloading is complicated. Further, by indicating that the user equipment is a trusted user equipment, after receiving the authentication request sent by the user equipment, the direct reply authentication succeeds, and the authentication server is not required to be authenticated to improve the authentication. effectiveness.
- the user equipment sends an authentication request to the base station by using an uplink tunnel with the base station, where the authentication request is used by the user equipment to initiate the authentication.
- the authentication request is used by the user equipment to initiate the authentication.
- the user equipment and the authentication server can perform authentication and authentication by using the uplink and downlink tunnels established with the base station, thereby improving the security and reliability of the authentication authentication.
- FIG. 4 is a signaling interaction diagram of a third embodiment of the method for offloading according to the present invention.
- the embodiment includes a specific interaction process between a base station, a user equipment, and a WLAN.
- the signaling interaction specifically includes:
- Step 401 The base station sends an authentication authentication indication of the designated WLAN to the user equipment.
- the identifier information of the WLAN may or may not be included. If the authentication authentication indication does not include the WLAN identity, the user sets the operation of detecting the access points of all the WLANs to perform the authentication authentication.
- Step 402 The user equipment sends an authentication request for the WLAN to the WLAN.
- any authentication method of the WEB or the EAP-SIM/AKA may be used. If the indication information includes the identifier of the specified WLAN, the authentication authentication request is sent to the designated WLAN; if the indication information does not include the identifier of the specified WLAN, Then, the user equipment specifies the WLAN according to its own network condition and sends an authentication request to the designated WLAN.
- Step 403 The authentication authentication is completed between the WLAN and the authentication server according to the authentication request of the WLAN.
- Step 404 The WLAN sends a WLAN authentication and authentication status report to the user equipment.
- the WLAN may directly send the authentication and authentication status report to the base station, and the base station forwards the authentication and authentication status report to the user equipment.
- Step 405 The user equipment forwards the WLAN authentication and authentication status report to the base station.
- Step 406 The base station classifies the to-be-processed data service.
- the base station sends the first data stream in the to-be-processed data service to the user equipment through the WLAN, and the base station directly sends the second data stream to the user equipment, thereby implementing traffic distribution.
- FIG. 5 is a structural diagram of Embodiment 1 of a base station according to the present invention.
- the base station can be used in a wireless communication system such as 2G/3G/4G, such as an eNodeB in an LTE system, where the base station includes:
- the sending unit 51 is configured to send, to the user equipment, an authentication authentication indication, where the authentication authentication indication is used to instruct the user equipment to initiate authentication with the wireless local area network WLAN, and the base station implements wireless communication based on the cellular wireless communication technology, WLAN implements wireless communication based on wireless fidelity Wi-Fi access technology;
- the obtaining unit 52 is configured to obtain an authentication and authentication status report that the user equipment is admitted to the WLAN;
- the offloading unit 53 is configured to determine, according to the authentication and authentication status report, a first data stream that is to be exchanged with the access point of the WLAN, where the to-be-processed data stream is to be sent by the base station to the A data stream of the user equipment or a data stream to be sent by the user equipment to the base station.
- the device in this embodiment is used to perform the technical solution of the method embodiment shown in FIG. 1.
- the implementation principle and technical effects are similar, and details are not described herein again.
- FIG. 6 is a structural diagram of Embodiment 2 of a base station according to the present invention. As shown in FIG. 6, the base station in this embodiment is based on the structure of the base station shown in FIG. 5, and optionally, the sending unit 51 is specifically configured to:
- the authentication authentication indication includes the identifier of the WLAN, so that the user equipment performs authentication authentication with the WLAN according to the identifier of the WLAN.
- the acquiring unit 52 is further configured to acquire a key by using the authentication, where the key is used by the user equipment and the base station to perform a second data flow of the to-be-processed data stream.
- Decrypting, the second data stream is a data stream sent by the base station to the user equipment based on the cellular wireless communication technology;
- the base station further includes an indication unit 61, configured to indicate to the WLAN access point that the user equipment is a trusted device, and the trusted device indicates that the user equipment is admitted to the WLAN through the authentication authentication. Entry point
- the sending unit 51 is further configured to send the key to the WLAN access point, where the key is further used by the user equipment to perform encryption and decryption of the first data stream with the WLAN access point.
- the obtaining unit 52 is further configured to receive, by using an uplink tunnel with the user equipment, an authentication request sent by the user equipment, where the authentication request is used by the user equipment to initiate the Authentication and certification;
- the sending unit 51 is further configured to send the authentication request to the authentication server, so that the authentication server and the user equipment perform the authentication and authentication through a downlink tunnel.
- the user equipment is indicated as a trusted device by the indication unit in the base station, so that after receiving the authentication request sent by the user equipment, the authentication is successful, and the authentication server is not required to be authenticated to improve the authentication. Efficiency at the time of certification.
- the key used for data transmission such that the first data stream and the second data stream used for interaction between the WLAN, the base station, and the user equipment are all consistent, and multiple keys are avoided when the base station performs data offloading. The resulting processing is complicated.
- FIG. 7 is a structural diagram of Embodiment 1 of a user equipment according to the present invention.
- the user equipment can be used in a wireless communication system such as 2G/3G/4G, and the user equipment includes:
- the receiving unit 71 is configured to receive an authentication authentication indication sent by the base station, where the authentication authentication indication is used to instruct the user equipment to initiate authentication authentication with a wireless local area network WLAN, and the base station implements wireless communication based on a cellular wireless communication technology.
- the WLAN implements wireless communication based on a wireless fidelity Wi-Fi access technology;
- the sending unit 72 is configured to send, to the base station, an authentication authentication status report that the user equipment is admitted to the WLAN;
- the receiving unit 71 is further configured to use, by the base station, a first data stream of a to-be-processed data stream that is exchanged with the access point of the WLAN by the base station, where the to-be-processed data stream is sent by the base station to the user equipment.
- the device in this embodiment is used to perform the technical solution of the method embodiment shown in FIG. 3, and the implementation principle and the technical effect are similar, and details are not described herein again.
- FIG 8 is a structural diagram of Embodiment 2 of the user equipment of the present invention.
- the user equipment of this embodiment is based on the structure of the user equipment shown in Figure 7.
- the user equipment further includes:
- the processing unit 81 is configured to perform authentication authentication with the WLAN according to the identifier of the WLAN.
- the processing unit 81 is specifically configured to:
- the accessing the WLAN authentication authentication process is completed by the access point of the WLAN or the base station.
- the user equipment further includes:
- the encryption and decryption unit 82 is configured to:
- the sending unit 72 is further configured to send an authentication request to the base station by using an uplink tunnel with the base station, where the authentication request is used by the user equipment to initiate the authentication authentication.
- the user equipment sends an authentication request to the base station by using the sending unit on the uplink tunnel with the base station, so as to improve the security and reliability of the authentication.
- the user equipment encrypts and decrypts the first data stream and the second data stream of the to-be-processed data stream by using the key acquired by the base station via the authentication authentication by using the sending unit and the receiving unit, such that
- the WLAN, the first data stream between the base station and the user equipment and the key used by the second data stream are all consistent, and the processing caused by using multiple keys when the base station performs data offloading is complicated.
- FIG. 9 is a structural diagram of Embodiment 3 of a base station according to the present invention.
- the base station 90 provided in this embodiment includes:
- the transmitter 91 is configured to send an authentication authentication indication to the user equipment, where the authentication authentication indication is used to instruct the user equipment to initiate authentication authentication with the WLAN, and the base station implements wireless communication based on a cellular wireless communication technology, where the WLAN is based on Wi-Fi access technology enables wireless communication;
- the receiver 92 is configured to obtain an authentication and authentication status report that the user equipment is admitted to the WLAN.
- the processor 93 is configured to determine, according to the authentication and authentication status report, that the access point of the WLAN is to be processed. a first data stream of the data stream, where the data stream to be processed is a data stream to be sent by the base station to the user equipment or a data stream to be sent by the user equipment to the base station.
- the transmitter 91 is specifically configured to:
- the authentication authentication indication includes the identifier of the WLAN, so that the user equipment performs authentication authentication with the WLAN according to the identifier of the WLAN.
- the receiver 92 is further configured to acquire a key by using the authentication, where the key is used by the user equipment and the base station to perform encryption and decryption of a second data stream of the to-be-processed data stream, where The second data stream is a data stream that is sent by the base station to the user equipment based on the cellular radio communication technology;
- the transmitter 91 is further configured to indicate to the WLAN access point that the user equipment is a trusted device, The trusted device indicates that the user equipment is admitted to the WLAN access point via the authentication authentication;
- the transmitter 91 is further configured to send the key to the WLAN access point, where the key is further used by the user equipment to perform encryption and decryption of the first data stream with the WLAN access point.
- the receiver 92 is further configured to receive, by using an uplink tunnel with the user equipment, an authentication request sent by the user equipment, where the authentication request is used by the user equipment to initiate the authentication authentication; And sending the authentication request to the authentication server, so that the authentication server and the user equipment perform the authentication and authentication through a downlink tunnel.
- the processor 93 executes the execution instruction, so that the base station performs the method as described in FIG. 1 , and the implementation principle and technical effects are similar, and details are not described herein again.
- FIG. 10 is a structural diagram of Embodiment 3 of a user equipment according to the present invention.
- the user equipment 100 provided in this embodiment includes:
- the receiver 101 is configured to receive an authentication authentication indication sent by the base station, where the authentication authentication indication is used to instruct the user equipment to initiate authentication authentication with a WLAN, and the base station implements wireless communication based on a cellular wireless communication technology, WLAN implements wireless communication based on Wi-Fi access technology;
- the transmitter 102 is configured to send, to the base station, an authentication authentication status report that the user equipment is admitted to the WLAN;
- the receiver 101 is further configured to: interact with the base station to access a first data stream of a data stream to be processed by using an access point of the WLAN, where the to-be-processed data stream is sent by the base station to the user equipment.
- the authentication authentication indication includes an identifier of the WLAN, where the user equipment further includes:
- the processor 103 is configured to perform authentication authentication with the WLAN according to the identifier of the WLAN.
- the processor 103 is specifically configured to:
- the processor 103 is further configured to:
- the transmitter 102 is further configured to:
- the processor 103 executes the execution instruction, so that the user equipment performs the method as described in FIG. 3, and the implementation principle and technical effects are similar, and details are not described herein again.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本发明实施例提供一种分流方法、基站及用户设备。本发明方法,包括:基站向用户设备发送鉴权认证指示;所述基站获取所述用户设备准入所述WLAN的鉴权认证状态报告;所述基站根据所述鉴权认证状态报告,确定与所述WLAN的接入点交互待处理数据流的第一数据流,所述待处理数据流为所述基站待发送给所述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。本发明通过基站在数据分流前提前向用户设备发送鉴权认证指示,实现基站根据所述鉴权认证状态报告对业务数据进行分流,避免在业务数据分流时才对WLAN进行鉴权认证,以解决现有技术中因WLAN鉴权认证时延较长而导致数据业务分流时的中断问题。
Description
分流方法、 基站及用户设备
技术领域
本发明涉及无线接入技术, 尤其涉及一种分流方法、 基站及用户设备, 属于无线通信技术领域。 背景技术
随着移动通信系统的发展,用户业务对传输速率提出了越来越高的要求, 为了在不增加配置带宽的情况下, 保证一般用户的传输速率, 同时为用户提 供更高的吞吐量, 第三代合作伙伴计划 (The 3rd Generation Partnership Project, 简称 3GPP) 引入了载波聚合(Carrier Aggregation, 简称 CA)技术, 载波聚合是指用户设备 (User Equipment, 简称 UE) 可以同时使用多个成员 载波 (Component Carrier, 简称 CC)进行上下行通信, 从而支持高速数据传 输。
按照聚合的载波的类型, 分为同一系统的载波聚合和不同系统的载波聚 合两类。 同一系统的载波聚合, 指的是一个 UE使用的载波均为同一系统内的 载波, 比如载波均属于长期演进 (Long Term Evolution, 简称 LTE) 系统, 或 者载波均属于通用移动通信系统 (Universal Mobile Telecommunications System, 简称 UMTS)。 不同系统的载波聚合, 指的是一个 UE使用的载波属于 不同的系统, 比如载波属于 LTE和 UMTS、 LTE和无线局域网 (Wireless Local Access Network, 简称 WLAN)或 UMTS和 WLAN等系统。 不同系统的载波聚 合可以充分利用各种通信系统的特点, 达到高效低成本的传输效果。
现有技术中使用包括 WLAN的不同系统的载波聚合进行数据分流时,会 出现数据业务中断, 影响传输效率。 发明内容
本发明实施例提供一种分流方法、 基站及用户基站, 以实现不同系统的 载波聚合中的数据分流,解决使用包括 WLAN的不同系统的载波聚合进行数 据业务分流时, 由于 WLAN的鉴权认证时延较长导致数据业务分流中断等问
题。
第一个方面, 本发明实施例提供一种分流方法, 包括:
基站向用户设备发送鉴权认证指示, 所述鉴权认证指示用于指示所述用 户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝无线通信技 术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线通信; 所述基站获取所述用户设备准入所述 WLAN的鉴权认证状态报告; 所述基站根据所述鉴权认证状态报告,确定与所述 WLAN的接入点交互 待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用 户设备的数据流或为所述用户设备待发送给所述基站的数据流。
结合第一个方面, 在第一个方面第一种可能实现的方式中, 所述基站向 用户设备发送鉴权认证指示, 具体包括:
所述基站向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所 述 WLAN的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN 进行鉴权认证。
结合第一个方面或者第一个方面第一种可能的实现方式, 在第一个方面 第二种可能实现的方式中, 还包括:
所述基站经由所述鉴权认证获取密钥, 所述密钥用于所述用户设备与所 述基站进行所述待处理数据流的第二数据流的加解密, 所述第二数据流为所 述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
所述基站向所述 WLAN接入点指示所述用户设备为可信任设备,所述可 信任设备表示所述用户设备经由所述鉴权认证准入所述 WLAN接入点; 所述基站向所述 WLAN接入点发送所述密钥,所述密钥进一步用于所述 用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
结合第一个方面、 第一个方面第一种至第二种可能的实现方式, 在第一 个方面第三种可能实现的方式中, 还包括:
所述基站通过与所述用户设备之间的上行隧道接收所述用户设备发送的 鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证;
所述基站向鉴权服务器发送所述鉴权请求, 以便所述鉴权服务器与所述 用户设备通过下行隧道进行所述鉴权认证。
第二个方面, 本发明实施例提供一种分流方法, 包括:
用户设备接收基站发送的鉴权认证指示, 所述鉴权认证指示用于指示所 述用户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝无线通 信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线通 信;
所述用户设备向所述基站发送所述用户设备准入所述 WLAN 的鉴权认 证状态报告;
所述用户设备与所述基站通过所述 WLAN 的接入点交互待处理数据流 的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设备的数据 流或为所述用户设备待发送给所述基站的数据流。
在第二个方面第一种可能的实现方式中, 所述鉴权认证指示包括所述
WLAN的标识, 所述方法还包括:
所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权认证。 结合第二个方面或者第二个方面第一种可能的实现方式, 在第二个方面 第二种可能的实现方式中, 还包括:
所述用户设备通过所述 WLAN 的接入点或所述基站完成准入所述
WLAN鉴权认证流程。
结合第二个方面、 第二个方面第一种至第二种可能的实现方式, 在第二 个方面第三种可能的实现方式中, 还包括:
所述用户设备使用所述基站经由所述鉴权认证获取的密钥加解密所述用 户设备与所述基站之间传输的所述待处理数据流的第二数据流, 所述第二数 据流为所述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据流; 所述用户设备使用所述密钥加解密所述用户设备与所述 WLAN 的接入 点之间传输的所述待处理数据流的所述第一数据流。
结合第二个方面、 第二个方面第一种至第三种可能的实现方式, 在第二 个方面第四种可能的实现方式中, 还包括:
所述用户设备通过与所述基站之间的上行隧道向所述基站发送鉴权请 求, 所述鉴权请求用于所述用户设备发起所述鉴权认证。
第三个方面, 本发明实施例提供一种基站, 包括:
发送单元, 用于向用户设备发送鉴权认证指示, 所述鉴权认证指示用于 指示所述用户设备发起与无线局域网 WLAN的鉴权认证,基站基于蜂窝无线
通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线 通信;
获取单元, 用于获取所述用户设备准入所述 WLAN 的鉴权认证状态报 告. 分流单元, 用于根据所述鉴权认证状态报告, 确定向所述 WLAN的接入 点交互待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送给 所述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。
结合第三个方面, 在第三个方面第一种可能实现的方式中, 所述发送单 元, 具体用于:
向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所述 WLAN 的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权 认证。
结合第三个方面或者第三个方面第一种可能的实现方式, 在第三个方面 第二种可能实现的方式中:
所述获取单元还用于经由所述鉴权认证获取密钥, 所述密钥用于所述用 户设备与所述基站进行所述待处理数据流的第二数据流的加解密, 所述第二 数据流为所述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据 流;
所述基站还包括指示单元,用于向所述 WLAN接入点指示所述用户设备 为可信任设备, 所述可信任设备表示所述用户设备经由所述鉴权认证准入所 述 WLAN接入点;
所述发送单元还用于向所述 WLAN接入点发送所述密钥,所述密钥进一 步用于所述用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
结合第三个方面、 第三个方面第一种至第二种可能的实现方式, 在第三 个方面第三种可能实现的方式中:
所述获取单元还用于通过与所述用户设备之间的上行隧道接收所述用户 设备发送的鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证; 所述发送单元还用于向鉴权服务器发送所述鉴权请求, 以便所述鉴权服 务器与所述用户设备通过下行隧道进行所述鉴权认证。
第四个方面, 本发明实施例提供一种用户设备, 包括:
接收单元, 用于接收基站发送的鉴权认证指示, 所述鉴权认证指示用于 指示所述用户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝 无线通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现 无线通信;
发送单元,用于向所述基站发送所述用户设备准入所述 WLAN的鉴权认 证状态报告;
所述接收单元,还用于与所述基站通过所述 WLAN的接入点交互待处理 数据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设备 的数据流或为所述用户设备待发送给所述基站的数据流。
在第四个方面第一种可能的实现方式中, 所述鉴权认证指示包括所述
WLAN的标识, 所述用户设备还包括:
处理单元, 用于根据所述 WLAN的标识与所述 WLAN进行鉴权认证。 结合第四个方面或者第四个方面第一种可能的实现方式, 在第四个方面 第二种可能的实现方式中, 所述处理单元, 具体用于:
通过所述 WLAN的接入点或所述基站完成准入所述 WLAN鉴权认证流 程。
结合第四个方面、 第四个方面第一种至第二种可能的实现方式, 在第四 个方面第三种可能的实现方式中, 还包括:
加解密单元, 用于:
使用所述基站经由所述鉴权认证获取的密钥加解密所述用户设备与所述 基站之间传输的所述待处理数据流的第二数据流, 所述第二数据流为所述基 站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
使用所述密钥加解密所述用户设备与所述 WLAN 的接入点之间传输的 所述待处理数据流的所述第一数据流。
结合第四个方面、 第四个方面第一种至第三种可能的实现方式, 在第四 个方面第四种可能的实现方式中, 所述发送单元还用于通过与所述基站之间 的上行隧道向所述基站发送鉴权请求, 所述鉴权请求用于所述用户设备发起 所述鉴权认证。
第五个方面, 本发明实施例提供一种基站, 包括:
发射器, 用于向用户设备发送鉴权认证指示, 所述鉴权认证指示用于指
示所述用户设备发起与无线局域网 WLAN的鉴权认证,基站基于蜂窝无线通 信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线通 信;
接收器, 用于获取所述用户设备准入所述 WLAN的鉴权认证状态报告; 处理器, 用于根据所述鉴权认证状态报告, 确定与所述 WLAN的接入点 交互待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送给所 述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。
结合第五个方面, 在第五个方面第一种可能实现的方式中, 所述发射器, 具体用于:
向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所述 WLAN 的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权 认证。
结合第五个方面或者第五个方面第一种可能的实现方式, 在第五个方面 第二种可能实现的方式中:
接收器, 还用于经由所述鉴权认证获取密钥, 所述密钥用于所述用户设 备与所述基站进行所述待处理数据流的第二数据流的加解密, 所述第二数据 流为所述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据流; 发射器, 还用于向所述 WLAN接入点指示所述用户设备为可信任设备, 所述可信任设备表示所述用户设备经由所述鉴权认证准入所述 WLAN接入 点;
发射器, 还用于向所述 WLAN接入点发送所述密钥, 所述密钥进一步用 于所述用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
结合第五个方面、 第五个方面第一种至第二种可能的实现方式, 在第五 个方面第三种可能实现的方式中:
接收器, 还用于通过与所述用户设备之间的上行隧道接收所述用户设备 发送的鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证;
发射器, 还用于向鉴权服务器发送所述鉴权请求, 以便所述鉴权服务器 与所述用户设备通过下行隧道进行所述鉴权认证。
第六个方面, 本发明实施例提供一种用户设备, 包括:
接收器, 用于接收基站发送的鉴权认证指示, 所述鉴权认证指示用于指
示所述用户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝无 线通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无 线通信;
发射器,用于向所述基站发送所述用户设备准入所述 WLAN的鉴权认证 状态报告;
所述接收器,还用于与所述基站通过所述 WLAN的接入点交互待处理数 据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设备的 数据流或为所述用户设备待发送给所述基站的数据流。
在第六个方面第一种可能的实现方式中, 所述鉴权认证指示包括所述 WLAN的标识, 所述用户设备还包括:
处理器, 用于根据所述 WLAN的标识与所述 WLAN进行鉴权认证。 结合第六个方面或者第六个方面第一种可能的实现方式, 在第六个方面 第二种可能的实现方式中, 所述处理器, 具体用于:
通过所述 WLAN的接入点或所述基站完成准入所述 WLAN鉴权认证流 程。
结合第六个方面、 第六个方面第一种至第二种可能的实现方式, 在第六 个方面第三种可能的实现方式中, 所述处理器, 还用于:
使用所述基站经由所述鉴权认证获取的密钥加解密所述用户设备与所述 基站之间传输的所述待处理数据流的第二数据流, 所述第二数据流为所述基 站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
使用所述密钥加解密所述用户设备与所述 WLAN接入点之间传输的所 述待处理数据流的所述第一数据流。
结合第六个方面、 第六个方面第一种至第三种可能的实现方式, 在第六 个方面第四种可能的实现方式中, 所述发射器, 还用于:
通过与所述基站之间的上行隧道向所述基站发送鉴权请求, 所述鉴权请 求用于所述用户设备发起所述鉴权认证。
本发明通过基站在数据分流前提前向用户设备发送鉴权认证指示, 实现 基站根据所述鉴权认证状态报告对业务数据进行分流, 避免在业务数据分流 时才对 WLAN进行鉴权认证, 以解决现有技术中因 WLAN鉴权认证时延较 长而导致数据业务分流时的中断问题。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实 施例或现有技术描述中所需要使用的附图作一简单地介绍, 显而易见地, 下 面描述中的附图是本发明的一些实施例, 对于本领域普通技术人员来讲, 在 不付出创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。 图 1为本发明分流方法实施例一的流程图;
图 2是用户设备通过隧道方式进行鉴权认证的网络拓扑图;
图 3为本发明分流方法实施例二的流程示意图;
图 4为本发明分流方法实施例三的信令交互图;
图 5为本发明基站实施例一的结构图;
图 6为本发明基站实施例二的结构图;
图 7为本发明用户设备实施例一的结构图;
图 8为本发明用户设备实施例二的结构图;
图 9为本发明基站实施例三的结构图;
图 10为本发明用户设备实施例三的结构图。 具体实施方式
为使本发明实施例的目的、 技术方案和优点更加清楚, 下面将结合本发 明实施例中的附图, 对本发明实施例中的技术方案进行清楚、 完整地描述, 显然, 所描述的实施例是本发明一部分实施例, 而不是全部的实施例。 基于 本发明中的实施例, 本领域普通技术人员在没有作出创造性劳动前提下所获 得的所有其他实施例, 都属于本发明保护的范围。
本文中描述的各种技术可用于各种无线通信系统, 例如当前 2G, 3G通 信系统和下一代通信系统, 例如全球移动通信系统(GSM, Global System for Mobile communications ), 石马分多址 (CDMA, Code Division Multiple Access ) 系统, 时分多址 (TDMA, Time Division Multiple Access )系统, 宽带码分多 址 (WCDMA, Wideband Code Division Multiple Access Wireless ) , 频分多址 ( FDMA , Frequency Division Multiple Addressing ) 系统, 正交频分多址 ( OFDM A, Orthogonal Frequency-Division Multiple Access ) 系统, 单载波
FDMA (SC-FDMA)系统, 通用分组无线业务(GPRS , General Packet Radio Service)系统, 长期演进(LTE, Long Term Evolution )系统, 以及其他此类 通信系统。
本文中结合终端和 /或基站和 /或基站控制器来描述各种方面。
终端, 可以是无线终端也可以是有线终端, 无线终端可以是指向用户提 供语音和 /或数据连通性的设备, 具有无线连接功能的手持式设备、 或连接到 无线调制解调器的其他处理设备。无线终端可以经无线接入网(例如, RAN, Radio Access Network) 与一个或多个核心网进行通信, 无线终端可以是移动 终端, 如移动电话 (或称为"蜂窝"电话) 和具有移动终端的计算机, 例如, 可以是便携式、 袖珍式、 手持式、 计算机内置的或者车载的移动装置, 它们 与无线接入网交换语言和 /或数据。 例如, 个人通信业务 (PCS , Personal Communication Service) 电话、 无绳电话、 会话发起协议 (SIP) 话机、 无线 本地环路(WLL, Wireless Local Loop )站、个人数字助理(PDA, Personal Digital Assistant)等设备。 无线终端也可以称为系统、 订户单元(Subscriber Unit) 、 订户站 (Subscriber Station) , 移动站 (Mobile Station) 、 移动台 (Mobile) 、 远程站( Remote Station )、接入点( Access Point )、远程终端( Remote Terminal )、 接入终端 (Access Terminal) 、 用户终端 ( User Terminal ) 、 用户代理 (User Agent) 、 用户设备 (User Device) 、 或用户装备 (User Equipment) 。
基站 (例如, 接入点) 可以是指接入网中在空中接口上通过一个或多个 扇区与无线终端通信的设备。基站可用于将收到的空中帧与 IP分组进行相互 转换, 作为无线终端与接入网的其余部分之间的路由器, 其中接入网的其余 部分可包括网际协议 (IP ) 网络。 基站还可协调对空中接口的属性管理。 例 如, 基站可以是 GSM或 CDMA中的基站(BTS, Base Transceiver Station) , 也可以是 WCDMA中的基站(NodeB ),还可以是 LTE中的演进型基站(NodeB 或 eNB或 e-NodeB, evolutional Node B ) , 本发明并不限定。
图 1为本发明分流方法实施例一的流程图,本实施例的方法适用于无线通 信系统, 执行主体是基站, 如图 1所示, 该方法包括以下步骤:
步骤 101、 基站向用户设备发送鉴权认证指示, 所述鉴权认证指示用于 指示所述用户设备发起与 WLAN的鉴权认证,所述基站基于蜂窝无线通信技 术实现无线通信, 所述 WLAN基于无线保真 (wireless fidelity, 简称 Wi-Fi)
接入技术实现无线通信。
可选地,在具体实施时,所述基站向用户设备可以以广播形式发送 WLAN 的鉴权认证指示;
或者, 所述基站也可以通过无线资源控制协议 (Radio Resource Control, 简称 RRC) 信令向用户设备发送 WLAN的鉴权认证指示。
可选地, 所述基站向用户设备发送鉴权认证指示, 具体包括:
所述基站向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所 述 WLAN的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN 进行鉴权认证。 比如基本服务集标识符 (Basic Service Set Identifier, 简称 BSSID)或 /和服务集标识 (Service Set Identifier, 简称 SSID)。
可选地, 所述指示信息还可以包括 WLAN提前鉴权认证指示允许指示。 比如可使用一位布尔类型的指示, 设置为真" True" , 表示允许用户设备对 WLAN进行提前鉴权认证。
步骤 102、 所述基站获取所述用户设备准入所述 WLAN的鉴权认证状态 报告。
用户设备如果接收到基站发送的 WLAN的鉴权认证指示,根据指示信息 中的相关内容, 比如 WLAN的标识或者是否允许用户设备对 WLAN的提前 鉴权认证, 选择对相关的 WLAN进行鉴权认证, 比如可以使用网页 (WEB ) 认证或者可扩展认证协议-用户身份单元 /认证与密钥协商协议 (extensible authentication protocol-Subscriber Identity Modules/ Authentication and Key Agreement, 简称 EAP-SIM/AKA认证方法。 需要说明的是, 当鉴权指示信息 中不包含指定 WLAN的标识时,用户设备也可以根据自身的网络情况而选择 相关的 WLAN作为指定 WLAN进行认证。
可选地,所述基站获取所述用户设备准入所述 WLAN的鉴权认证状态报 告, 包括: 所述基站接收所述用户设备在完成鉴权认证流程后发送的所述 WLAN的鉴权认证状态报告; 或者, 所述基站接收所述 WLAN在完成鉴权 认证流程后发送的所述 WLAN 的鉴权认证状态报告。 下面举例进行详细说 明, 用户设备在完成鉴权认证流程后, 可以直接向基站发送鉴权认证状态的 报告。鉴权认证状态的报告是可以通过一个 RRC消息来完成的, 基站收到来 自用户设备发送的鉴权认证状态报告后, 可返回一个确认消息给用户设备。
基站可以存储鉴权认证状态报告, 也可以将鉴权认证状态报告转发给移动管 理实体 (Mobility Management Entity, 简称 MME) 进行存储。 或者, 在完成 鉴权认证流程后, WLAN向基站发送鉴权认证状态通知消息, 鉴权认证状态 通知消息可以经 MME转发到基站, 基站可以从鉴权认证状态通知消息中解 析出预注册状态更新通知相关的信息。
步骤 103、 所述基站根据所述鉴权认证状态报告, 确定与所述 WLAN的 接入点交互待处理数据流的第一数据流, 所述待处理数据流为所述基站待发 送给所述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。
本步骤中, 基站在做 WLAN分流数据判决时, 将参考用户设备当前的鉴 权认证状态, 即只有鉴权认证通过的用户设备和 WLAN才可以进行数据的分 流。 可选地, 基站在分流时, 还可以考虑业务流量因素, 比如, 若数据业务 要求传输数据可靠性比较高, 则因 WLAN的切换丢包率, 因此基站可以考虑不 选择载波聚合分流。 但对于数据业务流量比较大, 且覆盖范围比较小, 可以 优先考虑使用载波分流, 尤其是相对静止的、 室内活动的网络环境。
相比于现有技术中, 在数据分流时, 基站才对 WLAN进行鉴权认证, 而 由于 WLAN的鉴权认证时延较长而导致的数据业务分流中断,本实施例通过 提前向用户设备发送 WLAN的鉴权认证指示, 实现在基站进行数据分类时, 直接根据 WLAN的鉴权认证状态报告进行分流,避免在业务数据分流时才对 WLAN进行鉴权认证, 以实现无缝的分流。
可选地, 在本实施例的基础上, 还包括:
所述基站经由所述鉴权认证获取密钥, 所述密钥用于所述用户设备与所 述基站进行所述待处理数据流的第二数据流的加解密, 所述第二数据流为所 述基站基于所述蜂窝无线通信技术与所述用户设备交互的数据流;
所述基站向所述 WLAN接入点指示所述用户设备为可信任设备,所述可 信任设备表示所述用户设备经由所述鉴权认证准入所述 WLAN接入点; 所述基站向所述 WLAN接入点发送所述密钥, 所述密钥进一步用于所述 用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
通过上述技术方案, 基站指示在 WLAN使用的密钥可以是基站与用户设 备之间数据传输使用的密钥, 这样, 在 WLAN、 基站和用户设备之间交互的 第一数据流和第二数据流使用的密钥都是一致的, 避免在基站进行数据分流
时使用多个密钥导致的处理复杂。 进一步地, 通过指示该用户设备为可信任 用户设备, 实现在接收到用户设备发送的认证请求后, 直接回复认证成功, 无需再转给认证服务器进行认证, 以提高鉴权认证时的效率。
可选地, 在本实施例的基础上, 还包括:
所述基站通过与所述用户设备之间的上行隧道接收所述用户设备发送的 鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证;
所述基站向鉴权服务器发送所述鉴权请求, 以便所述鉴权服务器与所述 用户设备通过下行隧道进行所述鉴权认证。
图 2是用户设备通过隧道方式进行鉴权认证的网络拓扑图, 以 LTE系统为 例, 如图 2所示, 在本网络架构图中包括用户设备, WLAN接入点, 基站、 移 动管理实体服务器以及认证服务器, 首先用户设备发上行信息传递 (UL Information Transfer) 消息到基站; EAP-SIM鉴权消息封装在 UL Information Transfer消息中从终端透传到基站; 鉴权 WLAN路由信息用于标识鉴权对象的 WLAN网络; 基站发送上行 WLAN认证与密钥协商协议(Uplink WLAN AKA Tunneling)消息经过 MME到认证服务器; 认证服务器识别出用户准备使用的 认证方法为 EAP-AKA。通过下行隧道消息完成鉴权认证的消息交互; 用户设 备和认证服务器间完成鉴权认证后,认证服务器发送 EAP成功(EAP Success) 消息给基站, 将产生的用于 WLAN接入点和 WLAN用户设备间链路保护的 机密性和\或完整性保护的鉴权密钥发送基站。 或者有用户设备将相关密钥发 送给基站; 基站作为用户设备上下文一部分, 保存该密钥。 当基站选择该 WLAN分流数据时, 基站发送鉴权成功标识和相关密钥给 WLAN接入点; 用 户设备接入 WLAN接入点, 使用相关密钥加密和完整性保护。
通过上述技术方案, 用户设备与鉴权服务器可以通过使用与基站之间建 立的上下行隧道进行鉴权认证, 提高了鉴权认证的安全性和可靠性。
图 3为本发明分流方法实施例一的流程图,本实施例的方法适用于无线通 信系统, 比如 2G\3G\4G通信系统, 执行主体是用户设备, 比如智能手机, 如 图 3所示, 该方法包括以下步骤:
步骤 301、 用户设备接收基站发送的鉴权认证指示, 所述鉴权认证指示 用于指示所述用户设备发起与 WLAN的鉴权认证,所述基站基于蜂窝无线通 信技术实现无线通信, 所述 WLAN基于 Wi-Fi接入技术实现无线通信。
可选地, 所述鉴权认证指示包括所述 WLAN的标识, 所述方法还包括: 所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权认证。 比 如 BSSID或者 SSID
步骤 302、 所述用户设备向所述基站发送所述用户设备准入所述 WLAN 的鉴权认证状态报告。
用户设备接收到所述鉴权认证指示后,发起与无线局域网 WLAN的鉴权 认证, 具体实施时, 可选地, 可以包括:
所述用户设备通过所述 WLAN 的接入点或所述基站完成准入所述 WLAN鉴权认证流程。
在用户设备完成准入所述 WLAN鉴权认证流程后,将鉴权认证的状态报 告基站发送。
步骤 303、 所述用户设备与所述基站通过所述 WLAN的接入点交互待处 理数据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设 备的数据流或为所述用户设备待发送给所述基站的数据流。
本实施例, UE通过接收基站发送的鉴权认证指示, 对参与分流的 WLAN 进行提前鉴权认证, 以解决现有技术中, 在数据分流时再对 WLAN进行鉴权 认证, 由于 WLAN认证的时间较长导致分流的业务中断问题, 实现业务数据 载波分流时无缝切换。
可选地, 在本实施例的基础上, 还包括:
所述用户设备使用所述基站经由所述鉴权认证获取的密钥加解密所述用 户设备与所述基站之间传输的所述待处理数据流的第二数据流, 所述第二数 据流为所述基站基于所述蜂窝无线通信技术与所述用户设备交互的数据流; 所述用户设备使用所述密钥加解密所述用户设备与所述 WLAN 的接入 点之间传输的所述待处理数据流的所述第一数据流。
通过上述技术方案, 用户设备使用所述基站经由所述鉴权认证获取的密 钥加解密待处理数据流的第一数据流和第二数据流, 这样, 在 WLAN、 基站 和用户设备之间交互的第一数据流和第二数据流使用的密钥都是一致的, 避 免在基站进行数据分流时使用多个密钥导致的处理复杂。 进一步地, 通过指 示该用户设备为可信任用户设备,实现在接收到用户设备发送的认证请求后, 直接回复认证成功, 无需再转给认证服务器进行认证, 以提高鉴权认证时的
效率。
可选地, 在本实施例的基础上, 所述用户设备通过与所述基站之间的上 行隧道向所述基站发送鉴权请求, 所述鉴权请求用于所述用户设备发起所述 鉴权认证。
通过上述技术方案, 用户设备与鉴权服务器可以通过使用与基站之间建 立的上下行隧道进行鉴权认证, 提高了鉴权认证的安全性和可靠性。
图 4为本发明分流方法实施例三的信令交互图, 该实施例包括基站、用户 设备以及 WLAN之间的具体交互流程, 该信令交互具体包括:
步骤 401、 基站向用户设备发送指定 WLAN的鉴权认证指示。
具体实施时, 可以包含 WLAN的标识信息, 也可以不包含 WLAN的标识 信息。若鉴权认证指示不包含 WLAN标识,则由用户设置将探测到所有 WLAN 的接入点进行准入鉴权认证的操作。
步骤 402、 用户设备向 WLAN发送 WLAN的鉴权认证请求。
具体实施时,可以使用 WEB或者 EAP-SIM/AKA任意一种认证方法,若指 示信息中包含指定 WLAN的标识, 则向指定 WLAN发送鉴权认证请求; 如果 指示信息中不包含指定 WLAN的标识, 则用户设备根据自身的网络情况指定 WLAN并向指定 WLAN发送鉴权认证请求。
步骤 403、 WLAN与认证服务器之间根据 WLAN的鉴权认证请求完成鉴权 认证。
步骤 404、 WLAN将 WLAN鉴权认证状态报告发送给用户设备。
本步骤中, WLAN也可以直接将鉴权认证状态报告发送给基站, 基站再 将鉴权认证状态报告转发给用户设备。
步骤 405、 用户设备将 WLAN鉴权认证状态报告转发给基站。
步骤 406、 基站将待处理数据业务分类。
基站将待处理数据业务中的第一数据流经过 WLAN再发送到用户设备 上, 而基站将第二数据流直接发送用户设备上, 从而实现业务数据的分流。
上述技术方案中, 通过基站在数据分流前, 向用户设备发送鉴权认证指 示, 实现是基站数据分流时, 直接根据 WLAN鉴权认证状态报告进行数据业 务分类, 将其中的一部分数据业务通过无线通信系统直接发送给用户设备, 另一部分数据通过 WLAN转发给用户设备, 从而实现无缝分流。
图 5为本发明基站实施例一的结构图, 该基站可以用于 2G/3G/4G等无线 通信系统, 如 LTE系统中的 eNodeB, 该基站包括:
发送单元 51, 用于向用户设备发送鉴权认证指示, 所述鉴权认证指示用 于指示所述用户设备发起与无线局域网 WLAN的鉴权认证,基站基于蜂窝无 线通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无 线通信;
获取单元 52, 用于获取所述用户设备准入所述 WLAN的鉴权认证状态 报告;
分流单元 53, 用于根据所述鉴权认证状态报告, 确定与所述 WLAN的 接入点交互待处理数据流的第一数据流, 所述待处理数据流为所述基站待发 送给所述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。
本实施例的装置, 用于执行图 1所示方法实施例的技术方案, 其实现原理 和技术效果类似, 此处不再赘述。
图 6为本发明基站实施例二的结构图, 如图 6所示, 本实施例的基站, 在图 5所示基站结构的基础上, 可选地, 所述发送单元 51, 具体用于:
向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所述 WLAN 的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权认 证。
可选地, 所述获取单元 52还用于经由所述鉴权认证获取密钥, 所述密钥 用于所述用户设备与所述基站进行所述待处理数据流的第二数据流的加解 密, 所述第二数据流为所述基站基于所述蜂窝无线通信技术向所述用户设备 发送的数据流;
所述基站还包括指示单元 61, 用于向所述 WLAN接入点指示所述用户 设备为可信任设备, 所述可信任设备表示所述用户设备经由所述鉴权认证准 入所述 WLAN接入点;
所述发送单元 51还用于向所述 WLAN接入点发送所述密钥, 所述密钥 进一步用于所述用户设备与所述 WLAN接入点进行所述第一数据流的加解 密。
可选地,所述获取单元 52还用于通过与所述用户设备之间的上行隧道接 收所述用户设备发送的鉴权请求, 所述鉴权请求用于所述用户设备发起所述
鉴权认证;
所述发送单元 51还用于向鉴权服务器发送所述鉴权请求, 以便所述鉴权 服务器与所述用户设备通过下行隧道进行所述鉴权认证。
上述实施例, 通过基站中的指示单元指示所述用户设备为可信任设备, 使得在接收到用户设备发送的认证请求后, 直接回复认证成功, 无需再转给 认证服务器进行认证, 以提高鉴权认证时的效率。 且通过基站的获取单元经 由所述鉴权认证获取密钥, 并通过所述发送单元向所述 WLAN接入点发送所 述密钥, 使得在 WLAN使用的密钥可以是基站与用户设备之间数据传输使用 的密钥, 这样, 在 WLAN、 基站和用户设备之间交互的第一数据流和第二数 据流使用的密钥都是一致的, 避免在基站进行数据分流时使用多个密钥导致 的处理复杂。
图 7为本发明用户设备实施例一的结构图, 该用户设备可以用于 2G/3G/4G等无线通信系统, 该用户设备包括:
接收单元 71, 用于接收基站发送的鉴权认证指示, 所述鉴权认证指示用 于指示所述用户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂 窝无线通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实 现无线通信;
发送单元 72, 用于向所述基站发送所述用户设备准入所述 WLAN的鉴 权认证状态报告;
所述接收单元 71, 还用于与所述基站通过所述 WLAN的接入点交互的 待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用 户设备的数据流或为所述用户设备待发送给所述基站的数据流。
本实施例的装置, 用于执行图 3所示方法实施例的技术方案, 其实现原理 和技术效果类似, 此处不再赘述。
图 8为本发明用户设备实施例二的结构图, 如图 8所示, 本实施例的用户 设备, 在图 7所示用户设备结构的基础上, 可选地, 所述用户设备还包括: 处理单元 81,用于根据所述 WLAN的标识与所述 WLAN进行鉴权认证。 可选地, 所述处理单元 81, 具体用于:
通过所述 WLAN的接入点或所述基站完成准入所述 WLAN鉴权认证流 程。
可选地, 所述用户设备, 还包括:
加解密单元 82, 用于:
使用所述基站经由所述鉴权认证获取的密钥加解密所述用户设备与所述 基站之间传输的所述待处理数据流的第二数据流, 所述第二数据流为所述基 站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
使用所述密钥加解密所述用户设备与所述 WLAN 的接入点之间传输的 所述待处理数据流的所述第一数据流。
可选地,所述发送单元 72还用于通过与所述基站之间的上行隧道向所述 基站发送鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证。
上述实施例, 用户设备通过发送单元在与所述基站之间的上行隧道上向 所述基站发送鉴权请求, 以提高鉴权认证的安全性和可靠性。
而且, 用户设备通过发送单元和接收单元, 使用所述基站经由所述鉴权 认证获取的密钥加解密待处理数据流的第一数据流和第二数据流, 这样, 在
WLAN, 基站和用户设备之间的第一数据流和第二数据流使用的密钥都是一 致的, 避免在基站进行数据分流时使用多个密钥导致的处理复杂。
图 9为本发明基站实施例三的结构图, 如图 9所示, 本实施例提供的基 站 90, 包括:
发射器 91, 用于向用户设备发送鉴权认证指示, 所述鉴权认证指示用于 指示所述用户设备发起与 WLAN的鉴权认证,基站基于蜂窝无线通信技术实 现无线通信, 所述 WLAN基于 Wi-Fi接入技术实现无线通信;
接收器 92, 用于获取所述用户设备准入所述 WLAN的鉴权认证状态报 告. 处理器 93, 用于根据所述鉴权认证状态报告, 确定与所述 WLAN的接 入点交互待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送 给所述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。
可选地, 在本实施例的基础上, 所述发射器 91, 具体用于:
向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所述 WLAN 的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权 认证。
可选地, 在本实施例的基础上, 其中:
接收器 92, 还用于经由所述鉴权认证获取密钥, 所述密钥用于所述用户 设备与所述基站进行所述待处理数据流的第二数据流的加解密, 所述第二数 据流为所述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据流; 发射器 91, 还用于向所述 WLAN接入点指示所述用户设备为可信任设 备,所述可信任设备表示所述用户设备经由所述鉴权认证准入所述 WLAN接 入点;
发射器 91, 还用于向所述 WLAN接入点发送所述密钥, 所述密钥进一 步用于所述用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
可选地, 在本实施例的基础上, 其中:
接收器 92, 还用于通过与所述用户设备之间的上行隧道接收所述用户设 备发送的鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证; 发射器 91, 还用于向鉴权服务器发送所述鉴权请求, 以便所述鉴权服务 器与所述用户设备通过下行隧道进行所述鉴权认证。
上述实施例中,所述处理器 93执行所述执行指令使得所述基站执行如图 1中所述的方法, 其实现原理和技术效果类似, 此处不再赘述。
图 10为本发明用户设备实施例三的结构图, 如图 10所示, 本实施例提 供的用户设备 100, 包括:
接收器 101, 用于接收基站发送的鉴权认证指示, 所述鉴权认证指示用 于指示所述用户设备发起与 WLAN的鉴权认证,所述基站基于蜂窝无线通信 技术实现无线通信, 所述 WLAN基于 Wi-Fi接入技术实现无线通信;
发射器 102, 用于向所述基站发送所述用户设备准入所述 WLAN的鉴权 认证状态报告;
所述接收器 101, 还用于与所述基站通过所述 WLAN的接入点交互待处 理数据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设 备的数据流或为所述用户设备待发送给所述基站的数据流。
可选地, 所述鉴权认证指示包括所述 WLAN的标识, 所述用户设备还包 括:
处理器 103, 用于根据所述 WLAN的标识与所述 WLAN进行鉴权认证。 可选地, 所述处理器 103, 具体用于:
通过所述 WLAN的接入点或所述基站完成准入所述 WLAN鉴权认证流
程。
可选地, 所述处理器 103, 还用于:
使用所述基站经由所述鉴权认证获取的密钥加解密所述用户设备与所述 基站之间传输的所述待处理数据流的第二数据流, 所述第二数据流为所述基 站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
使用所述密钥加解密所述用户设备与所述 WLAN接入点之间传输的所 述待处理数据流的所述第一数据流。
可选地, 所述发射器 102, 还用于:
通过与所述基站之间的上行隧道向所述基站发送鉴权请求, 所述鉴权请 求用于所述用户设备发起所述鉴权认证。
本实施例中, 所述处理器 103执行所述执行指令使得所述用户设备执行 如图 3中所述的方法, 其实现原理和技术效果类似, 此处不再赘述。
本领域普通技术人员可以理解: 实现上述方法实施例的全部或部分步骤 可以通过程序指令相关的硬件来完成, 前述的程序可以存储于一计算机可读 取存储介质中, 该程序在执行时, 执行包括上述方法实施例的步骤; 而前述 的存储介质包括: ROM、 RAM, 磁碟或者光盘等各种可以存储程序代码的介 质。
最后应说明的是: 以上各实施例仅用以说明本发明的技术方案, 而非对 其限制; 尽管参照前述各实施例对本发明进行了详细的说明, 本领域的普通 技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改, 或者对其中部分或者全部技术特征进行等同替换; 而这些修改或者替换, 并 不使相应技术方案的本质脱离本发明各实施例技术方案的范围。
Claims
1、 一种分流方法, 其特征在于, 包括:
基站向用户设备发送鉴权认证指示, 所述鉴权认证指示用于指示所述用 户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝无线通信技 术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线通信; 所述基站获取所述用户设备准入所述 WLAN的鉴权认证状态报告; 所述基站根据所述鉴权认证状态报告,确定与所述 WLAN的接入点交互 待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用 户设备的数据流或为所述用户设备待发送给所述基站的数据流。
2、 根据权利要求 1所述的方法, 其特征在于, 所述基站向用户设备发送 鉴权认证指示, 具体包括:
所述基站向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所 述 WLAN的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN 进行鉴权认证。
3、 根据权利要求 1或 2所述的方法, 其特征在于, 还包括:
所述基站经由所述鉴权认证获取密钥, 所述密钥用于所述用户设备与所 述基站进行所述待处理数据流的第二数据流的加解密, 所述第二数据流为所 述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
所述基站向所述 WLAN接入点指示所述用户设备为可信任设备,所述可 信任设备表示所述用户设备经由所述鉴权认证准入所述 WLAN接入点; 所述基站向所述 WLAN接入点发送所述密钥,所述密钥进一步用于所述 用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
4、 根据权利要求 1-3任一所述的方法, 其特征在于, 还包括: 所述基站通过与所述用户设备之间的上行隧道接收所述用户设备发送的 鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证;
所述基站向鉴权服务器发送所述鉴权请求, 以便所述鉴权服务器与所述 用户设备通过下行隧道进行所述鉴权认证。
5、 一种分流方法, 其特征在于, 包括:
用户设备接收基站发送的鉴权认证指示, 所述鉴权认证指示用于指示所 述用户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝无线通
信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线通 信;
所述用户设备向所述基站发送所述用户设备准入所述 WLAN 的鉴权认 证状态报告;
所述用户设备与所述基站通过所述 WLAN 的接入点交互待处理数据流 的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设备的数据 流或为所述用户设备待发送给所述基站的数据流。
6、 根据权利要求 5所述的方法, 其特征在于, 所述鉴权认证指示包括所 述 WLAN的标识, 所述方法还包括:
所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权认证。
7、 根据权利要求 5或 6所述的方法, 其特征在于, 还包括:
所述用户设备通过所述 WLAN 的接入点或所述基站完成准入所述 WLAN鉴权认证流程。
8、 根据权利要求 5-7任一所述的方法, 其特征在于, 还包括: 所述用户设备使用所述基站经由所述鉴权认证获取的密钥加解密所述用 户设备与所述基站之间传输的所述待处理数据流的第二数据流, 所述第二数 据流为所述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据流; 所述用户设备使用所述密钥加解密所述用户设备与所述 WLAN 的接入 点之间传输的所述待处理数据流的所述第一数据流。
9、 根据权利要求 5-8任一所述的方法, 其特征在于, 还包括: 所述用户设备通过与所述基站之间的上行隧道向所述基站发送鉴权请 求, 所述鉴权请求用于所述用户设备发起所述鉴权认证。
10、 一种基站, 其特征在于, 包括:
发送单元, 用于向用户设备发送鉴权认证指示, 所述鉴权认证指示用于 指示所述用户设备发起与无线局域网 WLAN的鉴权认证,基站基于蜂窝无线 通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线 通信;
获取单元, 用于获取所述用户设备准入所述 WLAN 的鉴权认证状态报 告. 分流单元, 用于根据所述鉴权认证状态报告, 确定与所述 WLAN的接入
点交互待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送给 所述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。
11、 根据权利要求 10所述的基站, 其特征在于, 所述发送单元, 具体用 于:
向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所述 WLAN 的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权 认证。
12、 根据权利要求 10或 11所述的基站, 其特征在于:
所述获取单元还用于经由所述鉴权认证获取密钥, 所述密钥用于所述用 户设备与所述基站进行所述待处理数据流的第二数据流的加解密, 所述第二 数据流为所述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据 流;
所述基站还包括指示单元,用于向所述 WLAN接入点指示所述用户设备 为可信任设备, 所述可信任设备表示所述用户设备经由所述鉴权认证准入所 述 WLAN接入点;
所述发送单元还用于向所述 WLAN接入点发送所述密钥,所述密钥进一 步用于所述用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
13、 根据权利要求 10-12任一所述的基站, 其特征在于:
所述获取单元还用于通过与所述用户设备之间的上行隧道接收所述用户 设备发送的鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证; 所述发送单元还用于向鉴权服务器发送所述鉴权请求, 以便所述鉴权服 务器与所述用户设备通过下行隧道进行所述鉴权认证。
14、 一种用户设备, 其特征在于, 包括:
接收单元, 用于接收基站发送的鉴权认证指示, 所述鉴权认证指示用于 指示所述用户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝 无线通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现 无线通信;
发送单元,用于向所述基站发送所述用户设备准入所述 WLAN的鉴权认 证状态报告;
所述接收单元,还用于与所述基站通过所述 WLAN的接入点交互待处理
数据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设备 的数据流或为所述用户设备待发送给所述基站的数据流。
15、 根据权利要求 14所述的用户设备, 其特征在于, 所述鉴权认证指示 包括所述 WLAN的标识, 所述用户设备还包括:
处理单元, 用于根据所述 WLAN的标识与所述 WLAN进行鉴权认证。
16、 根据权利要求 14或 15所述的用户设备, 其特征在于, 所述处理单 元, 具体用于:
通过所述 WLAN的接入点或所述基站完成准入所述 WLAN鉴权认证流 程。
17、 根据权利要求 14-16任一所述的用户设备, 其特征在于, 还包括: 加解密单元, 用于:
使用所述基站经由所述鉴权认证获取的密钥加解密所述用户设备与所述 基站之间传输的所述待处理数据流的第二数据流, 所述第二数据流为所述基 站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
使用所述密钥加解密所述用户设备与所述 WLAN 的接入点之间传输的 所述待处理数据流的所述第一数据流。
18、 根据权利要求 14-17任一所述的用户设备, 其特征在于, 所述发送 单元还用于通过与所述基站之间的上行隧道向所述基站发送鉴权请求, 所述 鉴权请求用于所述用户设备发起所述鉴权认证。
19、 一种基站, 其特征在于, 包括:
发射器, 用于向用户设备发送鉴权认证指示, 所述鉴权认证指示用于指 示所述用户设备发起与无线局域网 WLAN的鉴权认证,基站基于蜂窝无线通 信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无线通 信;
接收器, 用于获取所述用户设备准入所述 WLAN的鉴权认证状态报告; 处理器, 用于根据所述鉴权认证状态报告, 确定与所述 WLAN的接入点 交互待处理数据流的第一数据流, 所述待处理数据流为所述基站待发送给所 述用户设备的数据流或为所述用户设备待发送给所述基站的数据流。
20、根据权利要求 19所述的基站, 其特征在于,所述发射器,具体用于: 向用户设备发送所述鉴权认证指示, 所述鉴权认证指示包括所述 WLAN
的标识, 以使所述用户设备根据所述 WLAN的标识与所述 WLAN进行鉴权 认证。
21、 根据权利要求 19或 20所述的基站, 其特征在于:
接收器, 还用于经由所述鉴权认证获取密钥, 所述密钥用于所述用户设 备与所述基站进行所述待处理数据流的第二数据流的加解密, 所述第二数据 流为所述基站基于所述蜂窝无线通信技术向所述用户设备发送的数据流; 发射器, 还用于向所述 WLAN接入点指示所述用户设备为可信任设备, 所述可信任设备表示所述用户设备经由所述鉴权认证准入所述 WLAN接入 点;
发射器, 还用于向所述 WLAN接入点发送所述密钥, 所述密钥进一步用 于所述用户设备与所述 WLAN接入点进行所述第一数据流的加解密。
22、 根据权利要求 19-21任一所述的基站, 其特征在于:
接收器, 还用于通过与所述用户设备之间的上行隧道接收所述用户设备 发送的鉴权请求, 所述鉴权请求用于所述用户设备发起所述鉴权认证;
发射器, 还用于向鉴权服务器发送所述鉴权请求, 以便所述鉴权服务器 与所述用户设备通过下行隧道进行所述鉴权认证。
23、 一种用户设备, 其特征在于, 包括:
接收器, 用于接收基站发送的鉴权认证指示, 所述鉴权认证指示用于指 示所述用户设备发起与无线局域网 WLAN的鉴权认证,所述基站基于蜂窝无 线通信技术实现无线通信, 所述 WLAN基于无线保真 Wi-Fi接入技术实现无 线通信;
发射器,用于向所述基站发送所述用户设备准入所述 WLAN的鉴权认证 状态报告;
所述接收器,还用于与所述基站通过所述 WLAN的接入点交互待处理数 据流的第一数据流, 所述待处理数据流为所述基站待发送给所述用户设备的 数据流或为所述用户设备待发送给所述基站的数据流。
24、 根据权利要求 23所述的用户设备, 其特征在于, 所述鉴权认证指示 包括所述 WLAN的标识, 所述用户设备还包括:
处理器, 用于根据所述 WLAN的标识与所述 WLAN进行鉴权认证。
25、 根据权利要求 23或 24所述的用户设备, 其特征在于, 所述处理器,
具体用于:
通过所述 WLAN的接入点或所述基站完成准入所述 WLAN鉴权认证流 程。
26、 根据权利要求 23-25任一所述的用户设备, 其特征在于, 所述处理 器, 还用于:
使用所述基站经由所述鉴权认证获取的密钥加解密所述用户设备与所述 基站之间传输的所述待处理数据流的第二数据流, 所述第二数据流为所述基 站基于所述蜂窝无线通信技术向所述用户设备发送的数据流;
使用所述密钥加解密所述用户设备与所述 WLAN接入点之间传输的所 述待处理数据流的所述第一数据流。
27、 根据权利要求 23-26任一所述的用户设备, 其特征在于, 所述发射 器, 还用于:
通过与所述基站之间的上行隧道向所述基站发送鉴权请求, 所述鉴权请 求用于所述用户设备发起所述鉴权认证。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP13895624.8A EP3046362B1 (en) | 2013-10-16 | 2013-10-16 | Distribution method, base station and user equipment |
| CN201380003278.8A CN104770002B (zh) | 2013-10-16 | 2013-10-16 | 分流方法、基站及用户设备 |
| PCT/CN2013/085340 WO2015054853A1 (zh) | 2013-10-16 | 2013-10-16 | 分流方法、基站及用户设备 |
| US15/098,776 US10123204B2 (en) | 2013-10-16 | 2016-04-14 | Splitting method, base station, and user equipment |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2013/085340 WO2015054853A1 (zh) | 2013-10-16 | 2013-10-16 | 分流方法、基站及用户设备 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US15/098,776 Continuation US10123204B2 (en) | 2013-10-16 | 2016-04-14 | Splitting method, base station, and user equipment |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2015054853A1 true WO2015054853A1 (zh) | 2015-04-23 |
Family
ID=52827557
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/085340 Ceased WO2015054853A1 (zh) | 2013-10-16 | 2013-10-16 | 分流方法、基站及用户设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US10123204B2 (zh) |
| EP (1) | EP3046362B1 (zh) |
| CN (1) | CN104770002B (zh) |
| WO (1) | WO2015054853A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10581842B2 (en) | 2017-03-30 | 2020-03-03 | At&T Intellectual Property I, L.P. | Seamless authentication device |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP5987707B2 (ja) * | 2013-01-25 | 2016-09-07 | ソニー株式会社 | 端末装置、プログラム及び通信システム |
| US9906996B2 (en) * | 2015-06-23 | 2018-02-27 | At&T Intellectual Property I, L.P. | Facilitation of wireless network session continuity |
| US10194379B2 (en) * | 2015-08-06 | 2019-01-29 | Arris Enterprises Llc | Discovery and security in LWA communication |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102215530A (zh) * | 2011-05-27 | 2011-10-12 | 上海华为技术有限公司 | 一种数据流传输方法及相关设备、系统 |
| CN102740366A (zh) * | 2012-07-06 | 2012-10-17 | 华为技术有限公司 | 一种实现无线网络接入的方法、装置和系统 |
| WO2013040978A1 (zh) * | 2011-09-19 | 2013-03-28 | 华为技术有限公司 | 数据分流触发方法、网络侧设备和用户设备及网络系统 |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013052805A1 (en) * | 2011-10-07 | 2013-04-11 | Interdigital Patent Holdings Inc. | Method and apparatus for integrating different radio access technologies using carrier aggregation |
| US9473997B2 (en) * | 2011-12-27 | 2016-10-18 | Lg Electronics Inc. | Method for offloading data in wireless communication system and apparatus for same |
| US9629028B2 (en) * | 2012-03-16 | 2017-04-18 | Qualcomm Incorporated | System and method for heterogeneous carrier aggregation |
| WO2013169073A1 (en) * | 2012-05-10 | 2013-11-14 | Samsung Electronics Co., Ltd. | Method and system for connectionless transmission during uplink and downlink of data packets |
| EP2675241A1 (en) * | 2012-06-11 | 2013-12-18 | Alcatel Lucent | Interworking base station between a wireless network and a cellular network |
| US9155006B2 (en) * | 2012-07-26 | 2015-10-06 | Lg Electronics Inc. | Method of supporting signal transmission and reception using at least two radio access technologies and apparatus therefor |
| US9900832B2 (en) * | 2012-11-07 | 2018-02-20 | Lg Electronics Inc. | Method and an apparatus for access network selection in a wireless communication system |
| US9655012B2 (en) * | 2012-12-21 | 2017-05-16 | Qualcomm Incorporated | Deriving a WLAN security context from a WWAN security context |
| US9106421B1 (en) * | 2013-01-15 | 2015-08-11 | Sprint Spectrum L.P. | Securing communications over a first communication link with encryption managed by a second communication link |
-
2013
- 2013-10-16 WO PCT/CN2013/085340 patent/WO2015054853A1/zh not_active Ceased
- 2013-10-16 CN CN201380003278.8A patent/CN104770002B/zh active Active
- 2013-10-16 EP EP13895624.8A patent/EP3046362B1/en active Active
-
2016
- 2016-04-14 US US15/098,776 patent/US10123204B2/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102215530A (zh) * | 2011-05-27 | 2011-10-12 | 上海华为技术有限公司 | 一种数据流传输方法及相关设备、系统 |
| WO2013040978A1 (zh) * | 2011-09-19 | 2013-03-28 | 华为技术有限公司 | 数据分流触发方法、网络侧设备和用户设备及网络系统 |
| CN102740366A (zh) * | 2012-07-06 | 2012-10-17 | 华为技术有限公司 | 一种实现无线网络接入的方法、装置和系统 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP3046362A4 * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10581842B2 (en) | 2017-03-30 | 2020-03-03 | At&T Intellectual Property I, L.P. | Seamless authentication device |
Also Published As
| Publication number | Publication date |
|---|---|
| CN104770002A (zh) | 2015-07-08 |
| US10123204B2 (en) | 2018-11-06 |
| EP3046362B1 (en) | 2018-08-15 |
| US20160234687A1 (en) | 2016-08-11 |
| EP3046362A4 (en) | 2016-09-21 |
| EP3046362A1 (en) | 2016-07-20 |
| CN104770002B (zh) | 2019-03-08 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN113395693B (zh) | 用于802.1x载体热点和Wi-Fi呼叫认证的基于经加密的IMSI的方案 | |
| EP3195642B1 (en) | Interworking and integration of different radio access networks | |
| US10624020B2 (en) | Non-access stratum transport for non-mobility management messages | |
| JP6329277B2 (ja) | データ伝送方法およびデバイス | |
| US10798082B2 (en) | Network authentication triggering method and related device | |
| US20170359719A1 (en) | Key generation method, device, and system | |
| US10659370B2 (en) | Wireless local area network (WLAN) node, a wireless device, and methods therein | |
| JP2017538345A (ja) | 方法、装置およびシステム | |
| US11310724B2 (en) | Key management for fast transitions | |
| US11206576B2 (en) | Rapidly disseminated operational information for WLAN management | |
| CN106797559B (zh) | 一种接入认证方法及装置 | |
| US10123204B2 (en) | Splitting method, base station, and user equipment | |
| WO2024145946A1 (en) | Apparatus, method, and computer program | |
| CN107211488B (zh) | 对业务数据应用安全的方法、wlan节点和无线设备 | |
| US10278068B2 (en) | Device and method of handling cellular-wireless local area network aggregation | |
| CN102711100A (zh) | 语音加解密处理方法、基站及网络系统 | |
| TW201742477A (zh) | 處理安全驗證的裝置及方法 | |
| TWI602446B (zh) | 處理認證程序的裝置及方法 | |
| WO2025026232A1 (zh) | 会话建立方法及相关装置 | |
| CN102378167A (zh) | 安全信息获取方法及多系统网络 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13895624 Country of ref document: EP Kind code of ref document: A1 |
|
| REEP | Request for entry into the european phase |
Ref document number: 2013895624 Country of ref document: EP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2013895624 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |