Background technology
Home eNodeB (Home Node B, HNB) or the Home eNodeB of evolution (Home evolved NodeB HeNB) is the novel household equipment that arises at the historic moment in order to solve the indoor wireless covering problem.HeNB under the R9 agreement has three kinds of mode of operations: open (Open) pattern, and closed (Closed) pattern and multiplexing (Hybrid) pattern, the HNB under the R8 agreement has only Closed pattern.
Below, the principle of above-mentioned various mode of operations is described in detail:
Under the Open pattern, HeNB is equivalent to a macro base station, and all users can both pass through the HeNB access network.
Under the Closed pattern, the user who only has certain authority could pass through HeNB or HNB access network, in concrete application scenarios, user with certain authority generally is meant closed user group (ClosedSubscriber Group, CSG), wherein, CSG is meant the user that the user the formed group that is linked into one or more CSG sub-district by authority, is divided into casual user and permanent user;
Need to prove that further the CSG sub-district is the sub-district of Home eNodeB.Each CSG sub-district have and only have a CSG ID and this identify label of broadcasting in broadcast (Identity, ID), the CSG user that the CSG sub-district of a Closed pattern can only be belonged to this CSG ID inserts.
Under the Hybrid pattern, all users can both pass through the HeNB access network, but CSG user has the preferential acquisition power of resource, when the HeNB inadequate resource, the resource that discharges non-CSG user is satisfied CSG user use.
In order to realize above-mentioned each mode of operation, (Allowed CSG List ACL), is the tabulation of the CSG ID of the CSG sub-district that can insert of recording user to need to set up the CSG tabulation that allows.ACL is that operator can set, it is the part of user signing contract information, be stored in home subscriber server (Home SubscriberServer, HSS) and conventional wireless communication systems (Universal Mobile Telecommunication System, USIM) in.(Public LandMobile-communication Network PLMN) stores ACL among the HSS, and promptly CSG ID among the PLMN_1 and the CSG ID among the PLMN_2 are relatively independent when storage according to public land mobile communication network.Present conclusion is, which PLMN UE resides among, and HSS just sends to the part that belongs to this PLMN among the ACL the current Mobility Management Entity of UE, carries out access control.But do not get rid of the progress along with standard, HSS can send to complete ACL the possibility of Mobility Management Entity.
In ACL, comprise CSG ID time limit parameter (CSG ID expiration time), the expression casual user is to the expiration time (expiration time) of the access authority of certain CSG ID, and each CSG ID has corresponding expiration time.When the expiration of certain CSG ID time is expired, the casual user can not insert this CSG sub-district with the CSG user identity again.The storage schematic diagram of CSG ID and the ACL of expiration time in HSS thereof as shown in Figure 1.Wherein, if certain CSG ID does not have corresponding expirationtime, the expression user is the permanent user of this CSG sub-district.
By above-mentioned a series of settings, system can realize access control (Access Control) to the user, and in concrete application scenarios, access control is meant judges that can CSG user pass through the process of H (e) NB access network.For the R8 agreement support later on the CSG function subscriber equipment (User Equipment, UE), access control by core net (Core Network, CN) node carries out, for example, MME or SGSN.MME or SGSN check CSG ID whether among the ACL in the UE CAMEL-Subscription-Information, if, then allow this user to insert current network, otherwise, refuse this user and insert.
HeNB and eNB do not do differentiation in tracing area (Tracking Area), the mobile management that relates to definition among the mobility management process of HeNB and the TS 23.401 is basic identical, and difference is need carry out access control as the user during by H (e) NB access network.
In the prior art, the application scenarios of H (e) NB specifically as shown in Figure 2, when the UE of connected state enters the coverage of H (e) NB from macrocell, if the CSG ID of this H (e) NB in the ACL of UE, Target cell can take place then is the switching (In-bound H (e) NB Handover) of H (e) NB.In order to carry out access control in switching, Mobility Management Entity (MME, SGSN or MSC) need be known CSG ID and the access module of purpose H (e) NB, and the ACL of its place PLMN will be arranged in the Mobility Management Entity.
Regulation among the TS 36.300, in switching set-up procedure, UE can report the cell-of-origin with the signal strength signal intensity of neighbor cell, cell ID etc.If neighbor cell is the CSG sub-district of Closed pattern, UE will only report the CSG sub-district of CSG ID in the ACL of UE, for the CSG ID Closed pattern CSG sub-district in the ACL of UE not, even its signal strength signal intensity is enough good, UE can not classify it as optional aim sub-district yet and report.
Two conclusions based on present SA2 meeting (are not transmitted the ACL of UE between the CN node; The ACL that has only PLMN under self in the CN node), when the CN node before and after switching changes, to be that to switch (inter-MME in-bound H (e) NBhandover) or Target cell be that the wireless access type of H (e) NB switches (inter Radio AccessTechnology in-bound H (e) NB handover for the mobile management entity of H (e) NB at Target cell, inter RAT in-bound H (e) NB handover) carries out access control under the scene, need extra processing procedure.
The scene that Inter-MME or inter-RAT switch as shown in Figure 3, wherein the CN node is MME in EPC, is SGSN in 3G network.Source CN node and purpose CN node may belong to same PLMN, also may not belong to same PLMN.
Step S301, UE send the measurement report of neighbor cell to source base station.If neighbor cell has the CSG sub-district of Closed pattern, then UE only reports CSG ID CSG sub-district in the ACL of UE.
Step S302, source base station carry out switch decision, select suitable purpose sub-district.
Step S303, source base station send handoff request message (Handover Required) to source CN node.
Step S304, source CN node send handoff request message (ForwardRelocation Request) to purpose CN node.
Access control is carried out by the CN node, does not determine in the agreement at present to carry out access control by that side CN node.If carry out by source CN node, then between step S303 and step S304, carry out access control; If carry out by purpose CN node, then after step S304, carry out access control.
In realizing process of the present invention, the inventor finds that there is following problem at least in prior art:
In existing technical scheme, do not determine Inter-PLMN in-bound H (e) NB handover, and under the scenes such as intra-PLMN, inter-MME/inter RAT handover, the CN node obtains the method for ACL.
Summary of the invention
The invention provides acquisition methods and the equipment of a kind of ACL, make network node, and under the scenes such as intra-PLMN, inter-MME/inter RAT handover, obtain ACL at Inter-PLMN in-bound H (e) NB handover.
For achieving the above object, one aspect of the present invention provides the acquisition methods of a kind of closed user group-list ACL of permission, comprising:
The network node that carries out access control in the current network system sends the ACL request message that comprises public land mobile communication network PLMN identifying information to the network equipment that stores ACL;
Described network node receives the ACL response message that the described network equipment sends, and comprises the ACL with the corresponding purpose PLMN of described PLMN identifying information in the described ACL response message;
Wherein, described network node is not preserved the ACL of terminal equipment UE at described purpose PLMN.
Preferably, the network node that carries out access control in the described current network system is specially:
Source CN node or purpose CN node.
Preferably, when the network node that carries out access control in the described current network system was specially source CN node, the network equipment of the described ACL of storing was specially home subscriber server HSS;
Preferably, when the network node that carries out access control in the described current network system was specially purpose CN node, the network equipment of the described ACL of storing was specially HSS or stores the source core net CN node of the ACL of purpose CSG sub-district place PLMN.
Preferably, when described source CN node or purpose CN node send when comprising the ACL request message of PLMN identifying information to HSS,
Described source CN node or described purpose CN node are specially location update request message to the ACL request message that described HSS sends, and wherein, comprise the updating type parameter;
The PLMN identifying information that is comprised in the described ACL request message is specially the PLMN ID of purpose PLMN;
The ACL response message that described source CN node or described purpose CN node receive described HSS transmission is specially position renewal response message.
Preferably, the occurrence of described updating type parameter is only for the sign of upgrading ACL.
Preferably, when described purpose CN node sends when comprising the ACL request message of PLMN identifying information to the source of the ACL that stores purpose CSG sub-district place PLMN CN node,,
The ACL request message that described purpose CN node sends to the described source CN node that stores the ACL of purpose CSG sub-district place PLMN is specially ACL and obtains request message;
The PLMN identifying information that is comprised in the described ACL request message is specially the PLMN ID of purpose PLMN;
The ACL request message that the described source CN node that stores the ACL of purpose CSG sub-district place PLMN of described purpose CN node reception sends is specially ACL and obtains response message.
Preferably, when the network equipment of the described ACL of storing is the source CN node that stores the ACL of purpose CSG sub-district place PLMN, and when comprising the PLMN ID of purpose PLMN in the described ACL request message, described network node receives before the ACL response message of described network equipment transmission, also comprises:
The described source CN node that stores the ACL of purpose CSG sub-district place PLMN obtains the ACL of described purpose PLMN according to the PLMN ID of described purpose PLMN.
On the other hand, the present invention also provides a kind of apparatus for network node, comprising:
Generation module is used to generate the ACL request message that comprises the PLMN identifying information;
Communication module, be used for the ACL request message that comprises the PLMN identifying information that described generation module generates is sent to the network equipment that stores ACL, and the ACL response message that returns of the network equipment that receives the described ACL of storing, comprise ACL in the described ACL response message with the corresponding purpose PLMN of described PLMN identifying information;
Acquisition module, be used for obtaining described communication module that comprise with the ACL corresponding purpose PLMN of described PLMN identifying information;
Wherein, described network node is not preserved the ACL of terminal equipment UE at described purpose PLMN.
Preferably, described apparatus for network node is specially:
Source CN node or purpose CN node.
Preferably, when described apparatus for network node was specially source CN node, the network equipment of the described ACL of storing was specially home subscriber server HSS;
Preferably, when described apparatus for network node was specially purpose CN node, the network equipment of the described ACL of storing was specially HSS or stores the source CN node of the ACL of purpose CSG sub-district place PLMN.
Preferably, when described apparatus for network node is when storing the source CN node of ACL of purpose CSG sub-district place PLMN, described communication module also is used to receive the ACL that purpose CN node sends and obtains request message, and the ACL that returns the ACL that comprises purpose PLMN to described purpose CN node obtains response message.
Compared with prior art, the present invention has the following advantages:
By the present invention, network node can get access to the ACL of corresponding target PLMN, thereby can effectively carry out user's access control, improves the efficient of user access administration, ensures security of network system.
Embodiment
As stated in the Background Art, owing to be not defined in Inter-PLMN in-boundH (e) NB handover in the existing technical scheme, and under the scenes such as intra-PLMN, inter-MME/inter RAT handover, network node obtains the processing policy of ACL, therefore, carry out the network node of access control if desired and do not preserve the ACL of UE, then may influence access control efficient the user at purpose PLMN.
In order to overcome above-mentioned defective, the embodiment of the invention provides the acquisition methods of a kind of ACL, as shown in Figure 4, specifically may further comprise the steps:
The network node that carries out access control in step S401, the current network system sends the ACL request message that comprises the PLMN identifying information to the network equipment that stores ACL.
In concrete application scenarios, the above-mentioned network equipment that stores ACL is specially HSS or stores the source CN node of the ACL of purpose CSG sub-district place PLMN.
Further, according to the above-mentioned entity type difference of carrying out the access control network node, the entity type of the network equipment of storing ACL accordingly is also distinct, specifically comprises following two kinds of situations:
Situation one, when the network node that carries out access control in the current network system is specially source CN node or purpose CN node, the network equipment that stores ACL can be HSS.
In this case, source CN node or purpose CN node are specially location update request message (Update Location Request) to the ACL request message that HSS sends, wherein, further comprise the updating type parameter in this message, here need to prove, here mentioned updating type parameter can be the new parameter identification of setting separately, also can be to give the parameter identification that has defined in the prior art scheme of concrete parameter value, for example: the Update Type parameter that has defined among the CT4, in above-mentioned technical scheme proposed by the invention, the concrete parameter value of this Update Type parameter is only for the sign (ACL only) of upgrading ACL, represent that current Update Location Request message just is used for the ACL to HSS request purpose PLMN, the purpose of She Zhiing is to avoid HSS owing to receive Update LocationRequest message like this, and directly positional information is fed back to corresponding network node, promptly avoid unnecessary transfer of data, can not cause waste of network resources.
Further, obtain to HSS under the enforcement scene of ACL at this provenance CN node or purpose CN node, the PLMN identifying information that is comprised in the above-mentioned ACL request message (Update Location Request) is specially the PLMN ID of purpose PLMN.
Situation two, when the network node that carries out access control in the current network system is specially purpose CN node, the network equipment that stores ACL is the source CN node that stores the ACL of purpose CSG sub-district place PLMN.
In this case, the ACL request message that sends to the source of the ACL that stores purpose CSG sub-district place PLMN CN node of purpose CN node is specially ACL and obtains request message (Retrieve ACLRequest).
Further, the PLMN identifying information that is comprised in the ACL request message is specially the PLMN ID of purpose PLMN.
In concrete enforcement scene, source CN node obtains corresponding ACL according to purpose PLMN ID, and then, source CN node feeds back this ACL to purpose CN node.
Step S402, network node receive the ACL response message that the network equipment sends, and wherein, the ACL response message comprises the ACL with the corresponding purpose PLMN of PLMN identifying information.
In this step, there is corresponding situation difference according to above-mentioned network entity difference equally, specifies as follows:
Situation one, when source CN node or purpose CN node when HSS obtains ACL, the ACL response message that source CN node or purpose CN node receive the HSS transmission is specially position renewal response message (UpdateLocation Ack), wherein, the ACL that includes purpose PLMN correspondence.
Situation two, when purpose CN node when the source of the ACL that stores purpose CSG sub-district place PLMN CN node obtains ACL, the ACL request message that purpose CN node reception sources CN node sends is specially ACL and obtains response message (Retrieval ACL Response), wherein, the ACL that includes purpose PLMN correspondence.
In concrete application scenarios, the sort of situation does not influence protection scope of the present invention more than concrete the application.
By above-mentioned steps, the network node that carries out access control in the current network system finally gets access to the ACL of purpose PLMN correspondence, carries out corresponding user access control according to the CSG ID and the access style (access mode) of purpose CSG sub-district.
Compared with prior art, the present invention has the following advantages:
By the present invention, network node can get access to the ACL of corresponding target PLMN, thereby can effectively carry out user's access control, improves the efficient of user access administration, ensures security of network system.
Below, the application scenarios in conjunction with concrete is elaborated to the technical scheme that the embodiment of the invention proposed.
In the user network handoff procedure, do not store the ACL of UE in purpose PLMN if carry out the CN node of access control, then can obtain by following dual mode:
1, source CN contact or purpose CN node send ACL to HSS and obtain request, and this method is applicable to all handoff scenario;
2, purpose CN node sends ACL to source CN node and obtains request, and this method is applicable to that purpose CN node carries out access control, and the scene of the ACL of purpose PLMN is arranged in the CN node of source.
Specifically adopt above-mentioned which kind of mode to carry out ACL and obtain in the scene concrete enforcement, do not influence protection scope of the present invention.
At first, the embodiment of the invention describes as follows for source CN contact or purpose CN node to the scheme of HSS request ACL:
This method is applicable to all handoff scenario, and promptly the CN node is in or be not in same PLMN, and the CN node is that MME or SGSN can not exert an influence to technical scheme of the present invention.
As long as carry out not having in the CN node of access control the ACL of storage purpose CSG sub-district place PLMN, can use this method to obtain corresponding ACL.This method increases by two message in the access control process, branch source CN node side joint is gone into control and purpose CN node side joint and gone into to control the coming year various situations and be described below.
Situation one, obtain ACL to HSS by source CN node.
As shown in Figure 5, in the access control process,, then carry out ACL by the following method and obtain, specifically may further comprise the steps if carry out the ACL that the source CN node of access control does not have purpose PLMN:
Step S501, source CN node send Update Location Request to HSS.
Wherein, existing C T4 agreement has defined the Update Type parameter in this message, and the occurrence that can establish this parameter herein is " ACL only ", shows that this message only is used to ask the ACL of UE.
Further, also should carry the PLMN ID of purpose PLMN in this message, be the ACL of which PLMN so that HSS can discern that source CN node wishes to obtain.
Step S502, HSS return Update Location Ack to source CN node.
Update Location Ack message comprises IMSI and Subscription data information, and wherein, Subscription data only comprises the ACL of UE at purpose PLMN.
In this step, the ACL that HSS fed back is that the PLMN ID according to purpose PLMN entrained among the Update Location Request carries out or gets.Implement in the scene concrete, corresponding identification information also can be other identification informations that can characterize PLMN, and such variation does not influence protection scope of the present invention.
By above-mentioned steps, source CN node can carry out access control to the user according to the CSG ID and the access mode of purpose CSG sub-district.
Situation two, obtain ACL to HSS by purpose CN node.
As shown in Figure 6, in the access control process,, then carry out ACL by the following method and obtain, specifically may further comprise the steps if carry out the ACL that the purpose CN node of access control does not have purpose PLMN:
Step S601, purpose CN node send Update Location Request to HSS.
Wherein, the concrete parameter value of the Update Type that carries among the Update Location Request is made as " ACL only ", shows that this message only is used to ask the ACL of UE, can not cause HSS and send Cancel Location message to source CN node.
Further, also should carry the PLMN ID of purpose PLMN in this message, be the ACL of which PLMN so that HSS can discern that source CN node wishes to obtain.
Step S602, HSS return Update Location Ack to purpose CN node.
Update Location Ack message comprises IMSI and Subscription data information.Wherein, Subscription data only comprises the ACL of UE at purpose PLMN.
In this step, the ACL that HSS fed back is that the PLMN ID according to purpose PLMN entrained among the Update Location Request carries out or gets.Implement in the scene concrete, corresponding identification information also can be other identification informations that can characterize PLMN, and such variation does not influence protection scope of the present invention.
By above-mentioned steps, source CN node can carry out access control to the user according to the CSG ID and the access mode of purpose CSG sub-district.
Next, the embodiment of the invention describes as follows for purpose CN node to the scheme of source CN node request ACL:
If determine to carry out access control by purpose CN node, then can be to source CN node request ACL.
When source CN node and purpose CN node were in same PLMN, this method was obviously applicable, and at this moment, the ACL that keeps in the CN node of source is exactly the ACL among the purpose PLMN.
On the other hand, when source CN node and purpose CN node did not belong to same PLMN, agreement did not determine necessarily only to preserve in the CN node ACL of PLMN under self at present, is that source CN node may be preserved complete ACL yet.In this case, also can use this method.
This method is passed through two message to source CN node request ACL.
As shown in Figure 7, in the access control process,, then carry out ACL to source CN node by the following method and obtain, specifically may further comprise the steps if carry out the ACL that the purpose CN node of access control does not have purpose PLMN:
Step S701, purpose CN node send Retrieve ACL Request message to source CN node.
Step S702, source CN node are known the PLMN ID of purpose PLMN according to purpose CN node ID, and the ACL that returns in Retrieval ACL Response message among this PLMN gives purpose CN node.
By above-mentioned steps, purpose CN node can carry out access control to the user according to the CSG ID and the accessmode of purpose CSG sub-district.
Compared with prior art, the present invention has the following advantages:
By the present invention, network node can get access to the ACL of corresponding target PLMN, thereby can effectively carry out user's access control, improves the efficient of user access administration, ensures security of network system.
In order to realize above-mentioned technical scheme proposed by the invention, the present invention also provides a kind of apparatus for network node, as shown in Figure 8, specifically comprises:
Generation module 81 is used to generate the ACL request message that comprises the PLMN identifying information.
Communication module 82, be used for the ACL request message that comprises the PLMN identifying information thatgeneration module 81 generates is sent to the network equipment that stores ACL, and receive the ACL response message that the network equipment store ACL returns, comprise ACL in the ACL response message with the corresponding purpose PLMN of PLMN identifying information.
Wherein, the network equipment that stores ACL is specially HSS, or stores the source CN node of the ACL of purpose CSG sub-district place PLMN.
Accordingly, when apparatus for network node is specially source CN node or purpose CN node, can obtain ACL to HSS;
When apparatus for network node is specially purpose CN node, can obtain ACL to the source of the ACL that stores purpose CSG sub-district place PLMN CN node.
Acquisition module 83 is used for obtainingcommunication module 82 ACL with the corresponding purpose PLMN of PLMN identifying information that comprise.
In concrete application scenarios, when apparatus for network node is when storing the source CN node of ACL of purpose CSG sub-district place PLMN,communication module 82 also is used to receive the ACL that purpose CN node sends and obtains request message, and obtain response message to the ACL that purpose CN node returns the ACL that comprises purpose PLMN, accordingly, apparatus for network node also comprises:
Compared with prior art, the present invention has the following advantages:
By the present invention, network node can get access to the ACL of corresponding target PLMN, thereby can effectively carry out user's access control, improves the efficient of user access administration, ensures security of network system.
Through the above description of the embodiments, those skilled in the art can be well understood to the present invention and can realize by hardware, also can realize by the mode that software adds necessary general hardware platform.Based on such understanding, technical scheme of the present invention can embody with the form of software product, it (can be CD-ROM that this software product can be stored in a non-volatile memory medium, USB flash disk, portable hard drive etc.) in, comprise some instructions with so that computer equipment (can be personal computer, service end, the perhaps network equipment etc.) each implements the described method of scene to carry out the present invention.
It will be appreciated by those skilled in the art that accompanying drawing is a preferred schematic diagram of implementing scene, module in the accompanying drawing or flow process might not be that enforcement the present invention is necessary.
It will be appreciated by those skilled in the art that the module in the device of implementing in the scene can be distributed in the device of implementing scene according to implementing scene description, also can carry out respective change and be arranged in the one or more devices that are different from this enforcement scene.The module of above-mentioned enforcement scene can be merged into a module, also can further split into a plurality of submodules.
The invention described above sequence number is not represented the quality of implementing scene just to description.
More than disclosed only be several concrete enforcement scene of the present invention, still, the present invention is not limited thereto, any those skilled in the art can think variation all should fall into protection scope of the present invention.