[go: up one dir, main page]

HK1260371B - Support of emergency services over wlan access to 3gpp evolved packet core for unauthenticated users - Google Patents

Support of emergency services over wlan access to 3gpp evolved packet core for unauthenticated users

Info

Publication number
HK1260371B
HK1260371B HK19120057.5A HK19120057A HK1260371B HK 1260371 B HK1260371 B HK 1260371B HK 19120057 A HK19120057 A HK 19120057A HK 1260371 B HK1260371 B HK 1260371B
Authority
HK
Hong Kong
Prior art keywords
access
network
user equipment
3gpp
authentication
Prior art date
Application number
HK19120057.5A
Other languages
Chinese (zh)
Other versions
HK1260371A1 (en
Inventor
Laurent Thiebaut
Bruno Landais
Nicolas Drevon
Original Assignee
Alcatel Lucent
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alcatel Lucent filed Critical Alcatel Lucent
Publication of HK1260371A1 publication Critical patent/HK1260371A1/en
Publication of HK1260371B publication Critical patent/HK1260371B/en

Links

Description

对于未认证用户通过WLAN接入3GPP演进分组核心支持紧急 服务Supports emergency services for unauthenticated users accessing the 3GPP Evolved Packet Core via WLAN.

技术领域Technical Field

本发明一般涉及移动通信网络和系统。The present invention generally relates to mobile communication networks and systems.

背景技术Background Art

移动网络和系统的描述可以在文献中找到,例如尤其是在由诸如3GPP(第三代合作伙伴计划)的标准化机构发布的技术规范中。Descriptions of mobile networks and systems can be found in the literature, for example in particular in technical specifications published by standardization bodies such as 3GPP (3rd Generation Partnership Project).

3GPP移动系统的示例是EPS(演进分组系统)。EPS网络包括可通过3GPP接入(诸如E-UTRAN)或者通过可信或不可信的非3GPP接入(诸如可信或不可信WLAN)接入的被称为EPC(演进分组核心)的核心网络。3GPP接入EPC特别在针对E-UTRAN接入的3GPP TS 23.401中规定。非3GPP接入EPC特别在3GPP TS 23.402中规定。在图1中回顾了用于3GPP和非3GPP(可信和不可信)接入EPC的架构的示例(摘自3GPP TS 23.402)。An example of a 3GPP mobile system is the EPS (Evolved Packet System). The EPS network includes a core network called the Evolved Packet Core (EPC), which is accessible via 3GPP access (such as E-UTRAN) or via trusted or untrusted non-3GPP access (such as trusted or untrusted WLAN). 3GPP access to the EPC is specifically specified in 3GPP TS 23.401 for E-UTRAN access. Non-3GPP access to the EPC is specifically specified in 3GPP TS 23.402. An example of the architecture for 3GPP and non-3GPP (trusted and untrusted) access to the EPC is reviewed in Figure 1 (excerpted from 3GPP TS 23.402).

在诸如EPS的系统中,UE可以经由提供连接性(被称为PDN连接性)服务的EPC连接各种外部网络(被称为分组数据网络PDN,其中一个示例是运营商的IMS网络)。认证通常在准许接入并提供连接性服务之前执行。然而,对于未认证的用户设备,也可能需要支持诸如紧急服务的某些服务。在本文中,未认证的用户设备意味着无需认证用户身份(例如,未向网络提供任何用户身份(例如,用户设备不包含USIM)或者用户身份(例如,IMSI)未获得网络认证)地设计用户设备。In systems such as EPS, UEs can connect to various external networks (called packet data networks (PDNs), an example of which is an operator's IMS network) via an EPC that provides connectivity (called PDN connectivity) services. Authentication is typically performed before access is granted and connectivity services are provided. However, for unauthenticated user equipment, it may also be necessary to support certain services, such as emergency services. In this context, an unauthenticated user equipment means a user equipment designed without the need for authentication of the user identity (e.g., no user identity is provided to the network (e.g., the user equipment does not contain a USIM) or the user identity (e.g., IMSI) is not authenticated by the network).

需要改进在这样的系统中对紧急服务的支持。尤其是对于未认证的用户设备,当前不支持通过可信或不可信WLAN接入3GPP EPC的紧急服务,需要提供这种支持。Improved support for emergency services in such systems is needed, particularly for unauthenticated user devices that currently do not support emergency services accessing the 3GPP EPC via trusted or untrusted WLANs.

发明内容Summary of the Invention

本发明的实施例尤其满足这种需求。Embodiments of the present invention address this need, among other things.

在一个方面,这些和其它目的通过一种用户设备UE来实现,所述用户设备UE用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务,其被配置为:In one aspect, these and other objects are achieved by a user equipment (UE) configured to support emergency services for unauthenticated user equipment accessing a 3GPP Evolved Packet Core (EPC) via a WLAN, the UE being configured to:

-响应于提供用于接入认证的用户身份的请求,提供特定的基于NAI(网络接入标识)的用户身份,所述特定的用户身份具有指示对紧急服务的未认证接入的领域(realm)部分。- In response to a request to provide a user identity for access authentication, providing a specific NAI (Network Access Identity) based user identity having a realm portion indicating unauthenticated access to emergency services.

在另一方面,这些和其它目的通过诸如用于可信WLAN接入EPC的TWAN实体或用于不可信WLAN接入EPC的ePDG的认证装置来实现,所述认证装置用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务,其被配置为:In another aspect, these and other objects are achieved by an authentication device, such as a TWAN entity for trusted WLAN access to EPC or an ePDG for untrusted WLAN access to EPC, for supporting emergency services for unauthenticated user equipment accessing 3GPP Evolved Packet Core (EPC) via WLAN, configured to:

-根据基于NAI(网络接入标识)的用户身份的指示对紧急服务的未认证接入的领域部分,向服务专用于对紧急服务的未认证接入的域的特定的3GPP AAA服务器路由来自用户设备UE的消息。- Routing the message from the user equipment UE towards a specific 3GPP AAA server serving a domain dedicated to unauthenticated access to emergency services according to the domain part indicating unauthenticated access to emergency services based on the user identity of NAI (Network Access Identity).

在另一方面,这些和其它目的通过3GPP AAA服务器来实现,所述3GPP AAA服务器用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务,其被配置为:In another aspect, these and other objects are achieved by a 3GPP AAA server for supporting emergency services for unauthenticated user equipment accessing a 3GPP Evolved Packet Core (EPC) via WLAN, configured to:

-服务专用于对紧急服务的未认证接入的域;- a domain dedicated to unauthenticated access to emergency services;

-对未认证用户设备UE准许接入;- Grant access to unauthenticated user equipment UE;

-向所述UE提供允许对紧急服务的网络接入的特定授权数据。- Providing the UE with specific authorization data allowing network access for emergency services.

在另一方面,这些和其它目标通过3GPP AAA代理实现,所述3GPP代理用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务,其被配置为:In another aspect, these and other objects are achieved by a 3GPP AAA proxy for supporting emergency services for unauthenticated user equipment accessing a 3GPP Evolved Packet Core (EPC) over WLAN, configured to:

-在检测到不可能联系HPLMN中的3GPP AAA服务器以进行与用户设备的紧急情况相关联的接入认证尝试时,基于本地政策,将接入认证请求重定向到服务专用于对紧急服务的未认证接入的域的本地AAA服务器。- Upon detecting that it is impossible to contact the 3GPP AAA server in the HPLMN for an access authentication attempt associated with an emergency situation of the user equipment, redirecting the access authentication request to a local AAA server serving a domain dedicated to unauthenticated access to emergency services, based on local policy.

在其它方面,这些和其它目的通过各种包括在诸如上述用户设备、认证装置、3GPPAAA服务器、3GPP AAA代理的各种实体中的一个或多个处执行的步骤的方法来实现。In other aspects, these and other objects are achieved by various methods including steps performed at one or more of various entities such as the user equipment, authentication device, 3GPP AAA server, 3GPP AAA proxy as described above.

附图说明BRIEF DESCRIPTION OF THE DRAWINGS

现在仅以示例的方式参考附图来描述根据本发明的实施例的装置和/或方法的一些实施例,其中:Some embodiments of apparatus and/or methods according to embodiments of the present invention will now be described, by way of example only, with reference to the accompanying drawings, in which:

-图1旨在回顾3GPP和非3GPP(可信或不可信)接入EPC的架构的示例;Figure 1 is intended to review examples of 3GPP and non-3GPP (trusted or untrusted) access architectures to the EPC.

-图2旨在示出根据本发明的实施例的信令流程的示例。- Figure 2 is intended to illustrate an example of a signaling flow according to an embodiment of the present invention.

具体实施方式DETAILED DESCRIPTION

缩略词Abbreviations

AAA 认证授权计费AAA authentication, authorization, and accounting

AKA 认证和密钥协商AKA Authentication and Key Agreement

APN 接入点名称APN Access Point Name

AVP 属性值对AVP attribute-value pair

CK 加密密钥CK encryption key

DEA Diameter EAP应答DEA Diameter EAP Response

DER Diameter EAP请求DER Diameter EAP Request

EAP 可扩展认证协议EAP Extensible Authentication Protocol

EPC 演进分组核心EPC Evolved Packet Core

ePDG 演进分组数据网关ePDG Evolved Packet Data Gateway

EPS 演进分组系统EPS Evolved Packet System

E-UTRAN 演进通用陆地无线接入网络E-UTRAN Evolved Universal Terrestrial Radio Access Network

HPLMN 归属公共陆地移动网络HPLMN Home Public Land Mobile Network

HSS 归属用户服务器HSS Home Subscriber Server

IK 完整性密钥IK Integrity Key

IMSI 国际移动用户识别码IMSI International Mobile Subscriber Identity

IMEI 国际移动设备识别码IMEI International Mobile Equipment Identity

IMS IP多媒体子系统IMS IP Multimedia Subsystem

LTE 长期演进LTE Long Term Evolution

MCM 多连接模式MCM Multi-Connection Mode

MK 主密钥MK Master Key

MSK 主会话密钥MSK Master Session Key

NAI 网络接入标识符NAI Network Access Identifier

PDN 分组数据网络PDN Packet Data Network

PDN GW PDN网关PDN GW PDN Gateway

PLMN 公共陆地移动网络PLMN Public Land Mobile Network

PRF 伪随机函数PRF pseudorandom function

SCM 单连接模式SCM single connection mode

SIM 用户身份模块SIM Subscriber Identity Module

TSCM 透明的单连接模式TSCM transparent single connection mode

TWAN 可信WLAN接入网络TWAN Trusted WLAN Access Network

UWAN 不可信WLAN接入网络UWAN Untrusted WLAN Access Network

UE 用户设备UE User Equipment

USIM 通用用户身份模块USIM Universal Subscriber Identity Module

WLAN 无线局域网WLAN Wireless Local Area Network

WLCP WLAN控制协议WLCP WLAN Control Protocol

技术背景Technical Background

-3GPP TS33.402第6.1节规定了一般规则:“在EPS中用于非3GPP接入的接入认证应当基于EAP-AKA(RFC 4187[7])或者基于EAP-AKA'(RFC 5448[23])”。- 3GPP TS 33.402 Section 6.1 specifies the general rule: "Access authentication for non-3GPP access in EPS shall be based on EAP-AKA (RFC 4187[7]) or EAP-AKA' (RFC 5448[23])".

-如在3GPP TS 23.402第16.2节中定义的,为了接入TWAN,UE应当首先使用EAP进行认证(“EAP认证过程被启动并被执行,其中涉及UE、TWAN和3GPP AAA服务器”)。- As defined in 3GPP TS 23.402 section 16.2, in order to access the TWAN, the UE shall first authenticate using EAP ("The EAP authentication procedure is initiated and performed involving the UE, TWAN and 3GPP AAA server").

-如在3GPP TS 33.402第8.2节“用于建立UE发起的IPsec隧道的机制”中定义的,“在IKEv2(如在RFC 5996[30]中规定的)内的EAP-AKA(如在RFC 4187[7]中规定的)应当被用于认证UE”。- As defined in 3GPP TS 33.402 section 8.2 "Mechanisms for establishing UE-initiated IPsec tunnels", "EAP-AKA (as specified in RFC 4187 [7]) within IKEv2 (as specified in RFC 5996 [30]) SHOULD be used to authenticate the UE."

-3GPP TS 29.273当前不支持通过AAA接口的对未认证UE的认证和授权过程。- 3GPP TS 29.273 currently does not support authentication and authorization procedures for unauthenticated UEs through the AAA interface.

本发明的各个方面和/或实施例的描述Description of various aspects and/or embodiments of the present invention

在一些国家,移动网络(被称为PLMN)由于本地规则而需要支持用于未认证UE(例如,用于不包含USIM的UE的移动电话)的紧急会话。该特征意味着网络接入层和服务层两者都支持未认证UE发出紧急会话。In some countries, mobile networks (called PLMNs) are required by local regulations to support emergency sessions for unauthenticated UEs (e.g., mobile phones for UEs that do not contain a USIM). This feature means that both the network access layer and the service layer support unauthenticated UEs initiating emergency sessions.

3GPP已经针对以下项提供了此功能:3GPP has provided this functionality for:

-CS(电路交换)域,针对接入层和服务层两者。这例如在3GPP TS24.008中定义。- CS (Circuit Switched) domain, for both access and service stratum. This is defined, for example, in 3GPP TS 24.008.

-IMS域,针对依赖于IP的会话建立的服务层。这在3GPP TS 23.167中定义。- IMS domain, a service layer for IP-based session establishment. This is defined in 3GPP TS 23.167.

-EUTRAN(LTE)接入,针对依赖于IP的会话建立的3GPP接入层。这在3GPP TS23.401中定义。- EUTRAN (LTE) access, 3GPP access stratum for IP-based session establishment. This is defined in 3GPP TS 23.401.

在3GPP规范中缺乏针对未认证UE支持通过WLAN的紧急会话。这种支持应当在3GPPTS 23.402中定义的可信接入(TWAN)和不可信接入(UWAN)EPC(演进分组核心)这两种情况中提供。3GPP specifications lack support for emergency sessions over WLAN for unauthenticated UEs. Such support should be provided in both trusted access (TWAN) and untrusted access (UWAN) EPC (Evolved Packet Core) scenarios as defined in 3GPP TS 23.402.

下面将描述允许这种支持的本发明的各个方面和/或实施例。Various aspects and/or embodiments of the present invention that enable such support are described below.

在一些实施例中,对于需要通过WLAN建立EPC接入以发起紧急会话的UE,当其从认证装置接收到提供其身份的请求(作为EAP身份请求的一部分)时,In some embodiments, for a UE that needs to establish EPC access over WLAN to initiate an emergency session, when it receives a request to provide its identity from an authentication device (as part of an EAP identity request),

-即使UE没有接入EPC的凭据(UE没有USIM),UE也会发送支持NAI格式并且基于其IMEI(在3GPP TS 23.003中定义的国际移动台设备识别码)以及基于专用于支持3GPP网络内的紧急服务的特定领域而构建的特定身份。- Even if the UE does not have credentials to access the EPC (UE does not have a USIM), the UE will send a specific identity that supports the NAI format and is based on its IMEI (International Mobile Station Equipment Identity defined in 3GPP TS 23.003) and is built based on a specific field dedicated to supporting emergency services within the 3GPP network.

-当UE具有凭据(USIM)但知道它不能获得认证时,UE发送支持NAI格式并且基于其IMSI以及基于专用于支持3GPP网络内的紧急服务的特定领域而构建的特定身份。- When the UE has credentials (USIM) but knows that it cannot get authenticated, the UE sends a specific identity that supports the NAI format and is built based on its IMSI and based on a specific domain dedicated to supporting emergency services within the 3GPP network.

在一些实施例中,该接入请求基于NAI的领域被路由到特定的3GPPAAA服务器功能,其准许接入,但提供仅允许对紧急服务的网络接入的特定授权数据。In some embodiments, the access request is routed based on the realm of the NAI to a specific 3GPP AAA server function, which grants access but provides specific authorization data that only allows network access for emergency services.

在一些操作实例中,当UE应当正常地获得认证,但3GPP AAA代理发现某些网络问题阻止发起紧急请求的UE的正常认证时,3GPP AAA代理可以(基于本地政策)将与UE的认证/授权有关的AAA信令转发到相同的特定3GPP AAA服务器功能。这需要由特定3GPP AAA服务器向UE发送回告知接入不能正常地获得认证(例如,不能正常地进行EAP-AKA/EAP-AKA认证)的特定指示。In some operational examples, when the UE should be authenticated normally, but the 3GPP AAA proxy discovers that certain network issues prevent the normal authentication of the UE initiating the emergency request, the 3GPP AAA proxy may (based on local policy) forward the AAA signaling related to the UE's authentication/authorization to the same specific 3GPP AAA server function. This requires a specific indication sent back by the specific 3GPP AAA server to the UE informing it that the access cannot be authenticated normally (e.g., EAP-AKA/EAP-AKA authentication cannot be performed normally).

在一些实施例中,除了与认证和MSK确定相关的特例之外,EAP-AKA/EAP-AKA'和AAA过程如正常认证的UE的情况那样地进行。EAP过程向UE和网络提供MSK(主会话密钥)以用于无线接口上的安全性。MSK基于与实际认证的UE的情况不同的准则来确定。In some embodiments, EAP-AKA/EAP-AKA' and AAA procedures proceed as for a normally authenticated UE, except for special cases related to authentication and MSK determination. The EAP procedure provides the UE and network with an MSK (Master Session Key) for security on the wireless interface. The MSK is determined based on different criteria than for an actually authenticated UE.

本发明的实施例的益处包括:Benefits of embodiments of the present invention include:

-针对对紧急服务的接入重复使用接入常规UE的准则(以及UE与网络之间的信息交换,尤其是在TWAN接入(*)的情况下):使用EAP过程,由3GPP AAA服务器准许的UE授权接入EPC网络进一步提供安全性材料:- Reuse of the criteria for access to regular UEs for access to emergency services (and the information exchange between the UE and the network, especially in the case of TWAN access(*)): Using EAP procedures, the UE is authorized to access the EPC network by the 3GPP AAA server. Further security material is provided:

○(*)例如,运行用于无需认证地接入紧急服务的特定EAP过程,以允许UE与网络交换它们在正常认证的情况下经由EAP-AKA'交换的参数。o(*) For example, a specific EAP procedure for accessing emergency services without authentication is run to allow the UE and the network to exchange parameters that they would exchange via EAP-AKA' in the case of normal authentication.

-在漫游的情况下不需要由HPLMN支持。- Does not need to be supported by the HPLMN in case of roaming.

在一些实施例中,当UE需要发起紧急服务并且没有接入网络的凭据(例如,UE没有(U)SIM)时,UE发送具有以下特性的一部分或全部的特定身份来作为对来自认证装置(*)的EAP身份请求的应答:In some embodiments, when the UE needs to initiate emergency services and does not have credentials to access the network (e.g., the UE does not have a (U)SIM), the UE sends a specific identity with some or all of the following characteristics as a response to the EAP Identity Request from the authentication device (*):

-支持NAI格式:身份应当采用NAI的形式,并且应当具有如在IETFRFC 4282第2.1条中规定的“用户名@领域(username@realm)”形式。- Supported NAI format: The identity shall be in the form of a NAI and shall have the "username@realm" format as specified in IETF RFC 4282 section 2.1.

-在NAI的用户名部分中具有IMEI。-Has IMEI in the username portion of the NAI.

-在NAI的领域部分中具有指示支持用于3GPP终端的未认证紧急服务的特定值。该领域部分(本发明的实施例的一部分)将由例如3GPP的标准定义。- Having a specific value in the domain part of the NAI indicating support for unauthenticated emergency services for 3GPP terminals. This domain part (part of an embodiment of the present invention) will be defined by a standard such as 3GPP.

(*)认证装置是基于来自(3GPP)AAA服务器的授权信息来控制UE接入网络的实体。在TWAN(可信WLAN接入EPC)的情况下,认证装置在TWAN中,而在UWAN(不可信WLAN接入EPC)的情况下,它是ePDG。(*) The authentication device is the entity that controls UE access to the network based on authorization information from the (3GPP) AAA server. In the case of TWAN (Trusted WLAN Access EPC), the authentication device is in the TWAN, while in the case of UWAN (Untrusted WLAN Access EPC), it is the ePDG.

在一些实施例中,认证装置然后尝试联系负责NAI的领域部分的AAA服务器。在一些实施例中,当该领域部分专用于支持紧急服务时,认证装置联系专用AAA服务器。该专用AAA服务器应当与认证装置位于相同的国家/地区。由于UE没有USIM,所以在“HPLMN”中没有可联系的AAA服务器实体,因此本地网络不能确定用于UE的HPLMN。In some embodiments, the authentication device then attempts to contact the AAA server responsible for the domain portion of the NAI. In some embodiments, when the domain portion is dedicated to supporting emergency services, the authentication device contacts a dedicated AAA server. This dedicated AAA server should be located in the same country/region as the authentication device. Since the UE does not have a USIM, there is no AAA server entity to contact in the "HPLMN", and therefore the local network cannot determine the HPLMN for the UE.

在一些实施例中,可以在可信WLAN接入实例中提供以下步骤中的一部分或全部。In some embodiments, some or all of the following steps may be provided in a trusted WLAN access instance.

-在正常认证的情况下,运行用于无需认证地接入紧急服务的特定EAP过程以允许UE与网络交换它们经由EAP-AKA'交换的参数(例如,在SCM中来自UE的对IP版本的请求;在MCM中的TWAN控制平面地址)。该过程重复使用EAP-AKA',但由于UE与网络之间没有相互认证而对其进行修改。尽管如此,它重复使用了迄今为止在EAP-AKA'中定义的所有机制以在UE与网络之间协商TWAN模式(SCM/MCM)以及协商在SCM中的PDN连接的参数。In the case of normal authentication, a specific EAP procedure for accessing emergency services without authentication is run to allow the UE and the network to exchange parameters that they exchanged via EAP-AKA' (e.g., the request for IP version from the UE in the SCM; the TWAN control plane address in the MCM). This procedure reuses EAP-AKA', but is modified because there is no mutual authentication between the UE and the network. However, it reuses all the mechanisms defined so far in EAP-AKA' to negotiate the TWAN mode (SCM/MCM) between the UE and the network and to negotiate the parameters of the PDN connection in the SCM.

-在单连接模式(SCM)和多连接模式(MCM)两者中,UE还包括新的紧急指示信息以向AAA服务器指示在EAP-AKA'中建立了紧急PDN连接(对于正常认证的情况,该指示已经在3GPP TR 23.771中提及,但是本发明的部分实施例将其作为EAP-AKA'的一部分包括在内)。对于多连接模式(MCM)中的可信WLAN接入,UE还包括新的紧急指示(已经在3GPP TR 23.771中提及)作为附着到网络之后的WLCP PDN连接请求的一部分。- In both Single Connectivity Mode (SCM) and Multiple Connectivity Mode (MCM), the UE also includes new emergency indication information to indicate to the AAA server that an emergency PDN connection is established in EAP-AKA' (for normal authentication, this indication is already mentioned in 3GPP TR 23.771, but some embodiments of the present invention include it as part of EAP-AKA'). For trusted WLAN access in Multiple Connectivity Mode (MCM), the UE also includes a new emergency indication (already mentioned in 3GPP TR 23.771) as part of the WLCP PDN Connection Request after attaching to the network.

在一些实施例中,当本地规则允许未认证的紧急会话时,服务用于紧急服务的专用领域的AAA服务器接受接入请求(没有诸如从HSS获取的认证向量的任何安全性材料,没有从HSS下载的任何订阅数据)并提供允许UE继续进行紧急会话但禁止任何其它服务的授权数据:AAA服务器旁路惯常的授权检查(例如,针对订阅的APN,针对UE可请求非3GPP接入EPC的位置,针对用户是否具有非3GPP接入订阅等)。对于可信WLAN接入,AAA服务器通过STa向TWAN发送新的紧急指示AVP(已经在3GPP TR 23.771中提及)以指示这是紧急附着,并且因此(已经在3GPPTR 23.771中提及):In some embodiments, when local rules allow unauthenticated emergency sessions, the AAA server serving the dedicated domain for emergency services accepts the access request (without any security material such as authentication vectors obtained from the HSS, without any subscription data downloaded from the HSS) and provides authorization data that allows the UE to continue with the emergency session but prohibits any other services: the AAA server bypasses the usual authorization checks (e.g., for subscribed APNs, for the location of the EPC where the UE can request non-3GPP access, for whether the user has a non-3GPP access subscription, etc.). For trusted WLAN access, the AAA server sends a new Emergency Indication AVP (already mentioned in 3GPP TR 23.771) to the TWAN over STa to indicate that this is an emergency attach, and therefore (already mentioned in 3GPP TR 23.771):

·在SCM中,TWAG应当建立用于紧急服务的PDN连接。• In SCM, TWAG shall establish a PDN connection for emergency services.

·在MCM中,TWAG应当只接受来自UE的针对紧急服务的PDN连接的WLCP请求。• In MCM, TWAG shall only accept WLCP requests from UE for PDN connections for emergency services.

在这两种情况下(SCM/MCM),TWAG使用其本地配置的紧急配置数据(而不是使用由UE提供的连接性参数)来确定将要建立的PDN连接的参数。In both cases (SCM/MCM), the TWAG uses its locally configured emergency configuration data (instead of using the connectivity parameters provided by the UE) to determine the parameters of the PDN connection to be established.

在一些实施例中,由于专用AAA服务器与认证装置位于相同的国家/地区中,因此在漫游的情况下,只有国家/地区本地的实体被涉及以支持用于未认证UE的紧急服务。这允许来自未允许或未部署用于未认证UE的紧急会话的国家/地区的漫游用户在允许未认证的紧急会话的国家/地区中发起未认证的紧急会话。In some embodiments, since the dedicated AAA server is located in the same country/region as the authentication device, only entities local to the country/region are involved in supporting emergency services for unauthenticated UEs in the case of roaming. This allows roaming users from countries/regions that do not allow or deploy emergency sessions for unauthenticated UEs to initiate unauthenticated emergency sessions in countries/regions that allow unauthenticated emergency sessions.

作为实现选项,该专用AAA服务器可以与认证装置(ePDG)位于相同的位置,或者位于由认证装置(TWAP)联系的AAA代理中。As an implementation option, the dedicated AAA server can be co-located with the authentication device (ePDG) or located in an AAA proxy contacted by the authentication device (TWAP).

在本发明的一些实施例中,在UE、TWAN和ePDG级别上允许使用现有的过程以用于通过可信/不可信WLAN接入EPC,即:In some embodiments of the present invention, existing procedures are allowed to be used at the UE, TWAN and ePDG levels for accessing the EPC via trusted/untrusted WLAN, namely:

-使用EAP(即过程)以发起UE接入网络,并且网络告知UE其可以继续进行用于未认证紧急服务的网络接入。当这种接入不被允许时,本地AAA实体应当拒绝EAP请求;有必要重复使用EAP以支持通过可信WLAN接入(在SCM和MCM中)的用于未认证UE的紧急PDN连接,因为EAP在SCM中被用于将参数从UE传送到TWAN,并且在MCM中被用于将TWAN参数(例如,TWAN控制平面IPv4或IPv6地址)传送到UE。- Use EAP (i.e., procedure) to initiate UE access to the network, and the network informs the UE that it can proceed with network access for unauthenticated emergency services. When such access is not allowed, the local AAA entity should reject the EAP request; it is necessary to reuse EAP to support emergency PDN connectivity for unauthenticated UEs over trusted WLAN access (in SCM and MCM), because EAP is used in SCM to transfer parameters from UE to TWAN, and in MCM to transfer TWAN parameters (e.g., TWAN control plane IPv4 or IPv6 address) to UE.

-使用AAA服务器,控制UE接入网络(对于可信和不可信WLAN接入)。- Using AAA server, control UE access to the network (for trusted and untrusted WLAN access).

在一些实施例中,当EAP被使用时(作为通过WLAN接入EPC的现有过程的一部分),认证装置(TWAN/EPDG)和UE期望EAP过程输出将用于无线接口上的安全性的MSK(主会话密钥,该MSK在3GPP AAA服务器处以及在UE中计算)。在一些实施例中,重复使用类似的准则:In some embodiments, when EAP is used (as part of the existing process of accessing the EPC over WLAN), the authentication device (TWAN/EPDG) and the UE expect the EAP process to output an MSK (Master Session Key, which is calculated at the 3GPP AAA server and in the UE) to be used for security on the wireless interface. In some embodiments, similar principles are reused:

-在可信WLAN接入的情况下,UE和3GPP AAA服务器使用NAI的用户部分作为输入,基于密钥导出函数在本地确定MSK;与对于正常的3GPP接入(根据IETF RFC 5448)的MSK确定的区别在于:不能使用基于AKA的认证过程的加密密钥CK/IK输出,因为在未认证接入EPC的情况下不存在认证。该MSK被从3GPP AAA服务器传送到TWAP,然后被传送到WLAN AN,并且允许使用未修改的WLAN AN。In the case of trusted WLAN access, the UE and the 3GPP AAA server determine the MSK locally based on a key derivation function using the user part of the NAI as input. This differs from the MSK determination for normal 3GPP access (according to IETF RFC 5448) in that the encryption keys CK/IK output from the AKA-based authentication process cannot be used because there is no authentication in the case of unauthenticated access to the EPC. This MSK is transferred from the 3GPP AAA server to the TWAP and then to the WLAN AN, allowing the unmodified WLAN AN to be used.

○在IETF RFC 5448中,如下地实现密钥导出(如下地导出并使用MK):○ In IETF RFC 5448, key derivation is implemented as follows (MK is derived and used as follows):

MK=PRF'(IK'|CK',"EAP-AKA'"|身份)(PRF=在RFC 5448中定义的伪随机函数)MK = PRF'(IK'|CK', "EAP-AKA'"|Identity) (PRF = pseudorandom function defined in RFC 5448)

K_encr=MK[0..127]K_encr=MK[0..127]

K_aut=MK[128..383]K_aut=MK[128..383]

K_re=MK[384..639]K_re=MK[384..639]

MSK=MK[640..1151]”MSK=MK[640..1151]”

○在一些实施例中,如下地导出并使用MK:o In some embodiments, MK is derived and used as follows:

MK=PRF'("EAP-AKA'"|身份)MK=PRF'("EAP-AKA'|identity)

其中,“身份”基于UE已通过EAP提供的内容:IMEI(无SIM接入)或IMSI(UE具有SIM但不可能认证它)。Here, the "identity" is based on what the UE has provided via EAP: IMEI (for SIM-less access) or IMSI (the UE has a SIM but it is not possible to authenticate it).

K_encr、K_aut、K_re和MSK如IETF RFC 5448中所描述的基于MK而确定。K_encr, K_aut, K_re and MSK are determined based on MK as described in IETF RFC 5448.

在一些实施例中,当在认证装置的国家/地区本地被允许时,应用如上所述的相同的机制以支持UE具有USIM但不能获得认证的情况(本地网络与UE的HPLMN之间没有AAA关系(直接或间接的),因此不能继续进行UE的认证)。In some embodiments, when allowed locally in the country/region of the authentication device, the same mechanism as described above is applied to support the situation where the UE has a USIM but cannot obtain authentication (there is no AAA relationship (direct or indirect) between the local network and the UE's HPLMN, so authentication of the UE cannot proceed).

在这种情况下,UE创建具有特定领域的NAI,但在作为由认证装置发起的EAP身份的应答而提供的NAI的用户名部分中提供IMSI(而不是IMEI)。In this case, the UE creates a NAI with a specific realm, but provides the IMSI (instead of the IMEI) in the username portion of the NAI provided as a response to the EAP Identity initiated by the authentication device.

这对应于具有USIM,需要建立紧急会话但没有找到允许其获得HPLMN的认证的任何适用的WLAN网络的UE。This corresponds to a UE having a USIM that needs to establish an emergency session but has not found any applicable WLAN network that allows it to get authenticated with the HPLMN.

该过程的其余部分与用于无SIM UE的过程相同,除了使用IMSI而不是IMEI作为用户识别码(例如,使用IMSI而不是IMEI来导出MK,并且因此导出MSK)。在这种情况下,UE事先获知其不能获得认证,从而MSK不基于EAP-AKA'认证的输出来确定。The rest of the process is the same as for a SIM-less UE, except that IMSI is used instead of IMEI as the subscriber identity (e.g., IMSI is used instead of IMEI to derive the MK, and hence the MSK). In this case, the UE knows in advance that it cannot obtain authentication, so the MSK is not determined based on the outcome of the EAP-AKA' authentication.

在一些实施例中,在AAA代理(例如,漫游情况下的3GPP AAA代理)检测到它不可能联系HPLMN中的3GPP AAA服务器并且接入尝试与紧急情况相关联的情况下,基于本地政策,其可以将接入请求(EAP-AKA信令)重定向到服务与用于支持用于3GPP终端的未认证紧急服务相同的领域的本地AAA服务器。In some embodiments, when the AAA proxy (e.g., a 3GPP AAA proxy in the roaming case) detects that it is not possible to contact the 3GPP AAA server in the HPLMN and the access attempt is associated with an emergency, based on local policy it can redirect the access request (EAP-AKA signaling) to a local AAA server serving the same domain as used to support unauthenticated emergency services for 3GPP terminals.

例如,这可能是因为常规3GPP服务器停止服务、拥塞或联系不上。For example, this may be because the regular 3GPP server is out of service, congested, or unreachable.

本地政策取决于本地规则是否接受未认证的紧急会话。Local policy determines whether unauthenticated emergency sessions are accepted or not, depending on local rules.

在这种情况下,应用相同的过程:UE实际上未被认证,并且MSK基于伪随机函数来确定,其考虑了固定序列的字符以及用户身份(IMSI)而不是基于AKA的认证过程的加密密钥CK/IK输出;此外,在该情况下,UE不应尝试认证网络。In this case, the same procedure applies: the UE is not actually authenticated and the MSK is determined based on a pseudo-random function that takes into account a fixed sequence of characters and the user identity (IMSI) instead of the encryption keys CK/IK output of the AKA-based authentication procedure; moreover, in this case the UE should not attempt to authenticate the network.

在一些实施例中,由于UE不能事先获知不会对紧急服务的EPC接入进行任何认证,因此网络在发送到UE的EAP-AKA'信令中以及在发送到认证装置的AAA信令中指示这是针对无需认证的有限服务的接入。In some embodiments, since the UE cannot know in advance that no authentication will be performed for EPC access to emergency services, the network indicates in the EAP-AKA' signaling sent to the UE and in the AAA signaling sent to the authentication device that this is access for limited services without authentication.

为了使该过程更具稳健性且更具普遍性,该指示也可以在上述两种其它情况下提供给UE(以及认证装置)。In order to make the procedure more robust and more general, the indication may also be provided to the UE (and the authentication device) in the two other cases mentioned above.

-用于紧急服务的无SIM接入(UE提供其IMEI作为身份)。- SIM-less access for emergency services (UE provides its IMEI as identity).

-UE提供其IMSI(UE具有SIM)但知道它不能获得认证。- The UE provides its IMSI (UE has a SIM) but knows that it cannot get authenticated.

图2示出了用于SCM未认证紧急会话的TWAN认证和授权过程的调用流程的示例。FIG2 shows an example of a call flow for the TWAN authentication and authorization process for an SCM unauthenticated emergency session.

可以提供以下步骤,其中与3GPP TS 29.273的附录A.2-1的调用流程的区别在下面的描述中着重说明。The following steps may be provided, wherein the differences from the calling flow of Appendix A.2-1 of 3GPP TS 29.273 are highlighted in the following description.

1.使用基于IEEE 802.11[40]的特定过程,在UE与TWAN之间建立连接。1. Establish a connection between the UE and the TWAN using specific procedures based on IEEE 802.11[40].

2.TWAN向UE发送EAP请求/身份。2. TWAN sends EAP request/identity to UE.

3.UE向TWAN发送EAP响应/身份消息,其在用户部分中包含IMEI(无SIM UE)(或者 在UE不能获得认证的情况下包含IMSI),以及用于对紧急服务的未认证接入的特定域3. The UE sends an EAP Response/Identity message to the TWAN, which contains the IMEI (SIM-less UE) in the user part (or IMSI if the UE cannot be authenticated), and a specific domain for unauthenticated access to emergency services .

4.TWAN将从UE接收的EAP有效载荷转发到3GPP AAA服务器(服务用于对紧急服务 的未认证接入的特定域),并且还在DER消息中指示所支持的TWAN连接模式。4. TWAN forwards the EAP payload received from the UE to the 3GPP AAA server ( serving a specific domain for unauthenticated access to emergency services) and also indicates the supported TWAN connection modes in the DER message.

5.空缺。5. Vacant.

6.3GPP AAA服务器向UE发送EAP请求/AKA'质询,其中它向UE指示由网络支持的TWAN连接模式(例如,TSCM、SCM和MCM),并且指示这是针对无需认证的有限服务的接入。DEA消息中的结果代码AVP被设置为“DIAMETER_MULTI_ROUND_AUTH”。TWAN-S2a连接指示符没有在DEA标志AVP中设置。DEA消息还包含这是针对无需认证的有限服务的接入的指示6. The 3GPP AAA server sends an EAP-Request/AKA'-Challenge to the UE, in which it indicates to the UE the TWAN connection modes supported by the network (e.g., TSCM, SCM, and MCM) and that this is for access to limited services without authentication . The Result-Code AVP in the DEA message is set to "DIAMETER_MULTI_ROUND_AUTH". The TWAN-S2a Connection Indicator is not set in the DEA-Flags AVP. The DEA message also includes an indication that this is for access to limited services without authentication .

7.TWAN向UE转发EAP有效载荷。UE不应尝试认证网络7. TWAN forwards the EAP payload to the UE. The UE should not attempt to authenticate with the network .

8.UE发送EAP响应/AKA'质询,其中它指示所请求的连接模式。如果UE请求SCM,则UE还指示所请求的会话的参数:紧急服务的指示符、PDN类型(在该情况下不提供APN)、PDN类型(IPv4或IPv6)、初始附着/切换指示和/或PCO。8. The UE sends an EAP response/AKA' challenge, which indicates the requested connection mode. If the UE requests an SCM, the UE also indicates the parameters of the requested session: indicator for emergency services, PDN type (in this case no APN is provided), PDN type (IPv4 or IPv6), initial attach/handover indication, and/or PCO.

9.TWAN向3GPP AAA服务器转发EAP有效载荷。9. TWAN forwards the EAP payload to the 3GPP AAA server.

10.空缺。10. Vacant.

11.在该情况下(紧急),3GPP AAA服务器应当接受UE可能发送的任何质询响应,并 授权给UE所请求的模式(在此为SCM)。3GPP AAA服务器包括UE所请求的会话的参数:紧急服务的指示符、PDN类型、初始附着/切换指示和/或DEA消息中的PCO,其中,结果代码AVP被设置为“DIAMETER_MULTI_ROUND_AUTH”。3GPP AAA服务器还设置DEA标志AVP中的TWAN-S2a连接指示符以请求TWAN继续建立S2a连接。11. In this case (emergency), the 3GPP AAA server shall accept any challenge response that the UE may send and authorize the mode requested by the UE (here, SCM). The 3GPP AAA server includes the parameters of the session requested by the UE: indicator for emergency services, PDN type, initial attach/handover indication, and/or PCO in the DEA message, where the Result Code AVP is set to "DIAMETER_MULTI_ROUND_AUTH". The 3GPP AAA server also sets the TWAN-S2a Connection Indicator in the DEA Flags AVP to request that TWAN continue to establish the S2a connection.

12.TWAN向PDN GW发送创建会话请求/PBU消息以发起S2a隧道建立。TWAG提供IMEI 作为UE身份(无SIMUE)(或者在UE不能获得的情况下提供IMSI)。[在针对无SIM UE通过3GPP接入建立紧急呼叫的情况下,通过GTP-c接口向PGW提供IMEI]12. The TWAN sends a Create Session Request/PBU message to the PDN GW to initiate the S2a tunnel establishment. The TWAG provides the IMEI as the UE identity (for SIM-less UEs) (or IMSI if the UE cannot obtain it) . [In the case of emergency calls established for SIM-less UEs over 3GPP access, the IMEI is provided to the PGW over the GTP-c interface]

13.PDN GW向3GPP AAA服务器通知(S6b授权请求)其PDN GW身份和与UE的PDN连接对应的APN,以及永久用户身份(当PGW尚未从ePDG/TWAG接收到IMSI时,NAI在用户部分中包 括IMEI)。AAA服务器授权对紧急PDN连接的请求而不进行任何进一步的检查。3GPPAAA服务 器不用PGW地址更新HSS13. The PDN GW notifies the 3GPP AAA server (S6b Authorization Request) of its PDN GW identity and the APN corresponding to the UE's PDN connection, as well as the permanent user identity ( NAI includes the IMEI in the user part when the PGW has not yet received the IMSI from the ePDG/TWAG ). The AAA server authorizes the request for the emergency PDN connection without any further checks. The 3GPP AAA server does not update the HSS with the PGW address .

14.PDN GW向TWAN返回创建会话响应/PBA消息,包括为UE分配的IP地址。14. The PDN GW returns a Create Session Response/PBA message to the TWAN, including the IP address allocated to the UE.

15.TWAN包括从PDN GW接收的所提供的连接性参数,并设置发往3GPP AAA服务器的DER消息中的DER标志AVP中的TWAN-S2a连接指示符。3GPP AAA服务器忽略包括在DER消息中的EAP有效载荷。15. The TWAN includes the provided connectivity parameters received from the PDN GW and sets the TWAN-S2a Connection Indicator in the DER Flags AVP in the DER message sent to the 3GPP AAA server. The 3GPP AAA server ignores the EAP payload included in the DER message.

16.3GPP AAA服务器在AKA'通知中包括PDN连接性参数,并向TWAN发送DEA消息。DEA消息中的结果代码AVP被设置为“DIAMETER_MULTI_ROUND_AUTH”。TWAN-S2a连接指示符没有在DEA标志AVP中设置。16. The 3GPP AAA server includes the PDN connectivity parameters in the AKA' notification and sends a DEA message to the TWAN. The Result-Code AVP in the DEA message is set to "DIAMETER_MULTI_ROUND_AUTH". The TWAN-S2a connection indicator is not set in the DEA Flags AVP.

17.TWAN向UE转发EAP有效载荷。17. TWAN forwards the EAP payload to the UE.

18-19.UE用TWAN向3GPP AAA服务器转发的EAP-RSP/AKA'通知消息进行响应。18-19. The UE responds with the EAP-RSP/AKA' notification message forwarded by TWAN to the 3GPP AAA server.

20-21.3GPP AAA服务器发送TWAN向UE转发的EAP成功消息。DEA消息中的结果代码AVP被设置为“DIAMETER_SUCESS”。20-21. The 3GPP AAA server sends an EAP Success message, which is forwarded by TWAN to the UE. The Result-Code AVP in the DEA message is set to "DIAMETER_SUCESS".

在一些实施例中,考虑TWAN接入EPC作为示例,在未认证UE(例如,无SIM UE)的情况下,AAA服务器可以(这仅是说明性示例)在认证和授权应答消息中向TWAN提供以下信息(参见3GPP TS 29.273):In some embodiments, considering TWAN accessing EPC as an example, in the case of an unauthenticated UE (e.g., SIM-less UE), the AAA server may (this is just an illustrative example) provide the following information to the TWAN in the authentication and authorization answer message (see 3GPP TS 29.273):

本发明的各方面包括(但不限于)以下方面。Aspects of the present invention include (but are not limited to) the following.

一方面是一种用户设备UE,其被配置用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务。One aspect is a user equipment (UE) configured to support emergency services for unauthenticated user equipment accessing a 3GPP evolved packet core (EPC) via a WLAN.

根据各种组合可以提供各种实施例,包括(但不限于)以下可单独或组合地采用的实施例。Various embodiments may be provided according to various combinations, including but not limited to the following embodiments, which may be employed alone or in combination.

在实施例中,所述用户设备被配置为:In an embodiment, the user equipment is configured to:

-响应于提供用于接入认证的用户身份的请求,提供特定的基于网络接入标识NAI的用户身份,所述特定的用户身份具有指示对紧急服务的未认证接入的领域部分。- in response to a request to provide a user identity for access authentication, providing a specific user identity based on a Network Access Identity (NAI), said specific user identity having a realm part indicating unauthenticated access to emergency services.

在实施例中,所述用户设备被配置为:In an embodiment, the user equipment is configured to:

-在以下的情况之一中提供所述特定的用户身份:- providing the specific user identity in one of the following situations:

·所述UE没有IMSI;The UE does not have an IMSI;

·所述UE具有IMSI,但知道它不能获得认证。• The UE has an IMSI but knows that it cannot get authenticated.

在实施例中,所述用户设备被配置为:In an embodiment, the user equipment is configured to:

-如果所述UE没有IMSI,则提供具有基于IMEI的用户名部分的特定的基于NAI的用户身份。- If the UE does not have an IMSI, a specific NAI based user identity with a username part based on the IMEI is provided.

在实施例中,所述用户设备被配置为:In an embodiment, the user equipment is configured to:

-执行用于无需认证地接入紧急服务的特定的基于EAP的过程,所述特定的基于EAP的过程相对于正常的基于EAP的过程包括以下中的至少一项:- performing a special EAP-based procedure for accessing emergency services without authentication, wherein the special EAP-based procedure includes at least one of the following relative to a normal EAP-based procedure:

·不尝试认证所述网络;Do not attempt to authenticate the network;

·无需使用加密密钥CK和完整性密钥IK而导出主密钥MK。The master key MK is derived without using the encryption key CK and the integrity key IK.

另一方面是一种认证装置,诸如用于可信WLAN接入EPC的TWAN实体或用于不可信WLAN接入EPC的ePDG,其被配置用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务:Another aspect is an authentication device, such as a TWAN entity for trusted WLAN access to an EPC or an ePDG for untrusted WLAN access to an EPC, configured to support emergency services for unauthenticated user equipment accessing a 3GPP Evolved Packet Core (EPC) via WLAN:

根据各种组合可以提供各种实施例,包括(但不限于)以下可单独或组合地采用的实施例。Various embodiments may be provided according to various combinations, including but not limited to the following embodiments, which may be employed alone or in combination.

在实施例中,所述认证装置被配置为:In an embodiment, the authentication device is configured to:

-根据基于网络接入标识NAI的用户身份的指示对紧急服务的未认证接入的领域部分,向服务专用于对紧急服务的未认证接入的域的特定的3GPP AAA服务器路由来自用户设备UE的消息。- Routing the message from the user equipment UE to a specific 3GPP AAA server serving a domain dedicated to unauthenticated access to emergency services according to the domain part indicating unauthenticated access to emergency services based on the user identity of the network access identity NAI.

在实施例中,所述认证装置被配置为:In an embodiment, the authentication device is configured to:

-处理来自所述3GPP AAA服务器的接入是针对有限服务的指示;- processing the indication from the 3GPP AAA server that the access is for limited service;

-处理来自所述3GPP AAA服务器的所述用户身份尚未被认证的指示,并将该信息中继到PDN GW。- Process the indication from the 3GPP AAA server that the user identity has not been authenticated and relay this information to the PDN GW.

另一方面是一种3GPP AAA服务器,其被配置用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务。Another aspect is a 3GPP AAA server configured to support emergency services for unauthenticated user equipment accessing a 3GPP Evolved Packet Core (EPC) via a WLAN.

根据各种组合可以提供各种实施例,包括(但不限于)以下可单独或组合地采用的实施例。Various embodiments may be provided according to various combinations, including but not limited to the following embodiments, which may be employed alone or in combination.

在实施例中,所述3GPP AAA服务器被配置为:In an embodiment, the 3GPP AAA server is configured to:

-服务专用于对紧急服务的未认证接入的域;- a domain dedicated to unauthenticated access to emergency services;

-对未认证用户设备UE准许接入;- Grant access to unauthenticated user equipment UE;

-向所述UE提供允许对紧急服务的网络接入的特定授权数据。- Providing the UE with specific authorization data allowing network access for emergency services.

在实施例中,所述3GPP AAA服务器被配置为:In an embodiment, the 3GPP AAA server is configured to:

-执行用于无需认证地接入紧急服务的特定的基于EAP的过程,所述特定的基于EAP的过程相对于正常的基于EAP的过程包括以下中的至少一项:- performing a special EAP-based procedure for accessing emergency services without authentication, wherein the special EAP-based procedure includes at least one of the following relative to a normal EAP-based procedure:

-不从HSS获取用于所述UE的认证向量;- not obtaining the authentication vector for the UE from the HSS;

-提供所述接入是针对无需认证的有限服务的指示;- providing an indication that the access is to a limited service that does not require authentication;

-接受由所述UE发送的任何质询响应;- accept any challenge response sent by the UE;

-不从所述HSS下载所述用户的订阅信息;- not downloading the user's subscription information from the HSS;

-接受对紧急PDN连接的请求而不进行任何进一步的检查;- accept the request for an emergency PDN connection without any further checks;

-导出主密钥MK而无需使用加密密钥CK和完整性密钥IK;- derive the master key MK without using the encryption key CK and the integrity key IK;

-同时它支持常规3GPP AAA服务器的一些特征,诸如在TWAN接入的情况下,协商所述接入的模式或者在基于EAP的信令与认证装置之间中继信息。- At the same time it supports some features of a regular 3GPP AAA server, such as negotiating the mode of said access or relaying information between EAP-based signaling and authentication means in case of TWAN access.

在实施例中,所述3GPP AAA服务器被配置为:In an embodiment, the 3GPP AAA server is configured to:

-向所述UE和所述接入认证所涉及的认证装置发信令通知所述接入是针对无需认证的有限服务的接入。- Signaling to the UE and the authentication device involved in the access authentication that the access is for limited services that do not require authentication.

在实施例中,所述3GPP AAA服务器被配置为:In an embodiment, the 3GPP AAA server is configured to:

-向所述接入认证所涉及的认证装置发信令通知它在信令中向所述认证装置提供的IMSI尚未被认证。- Signalling to the authentication device involved in the access authentication that the IMSI provided to the authentication device in the signalling has not been authenticated.

另一方面是一种3GPP AAA代理,其被配置用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务。Another aspect is a 3GPP AAA proxy configured to support emergency services for unauthenticated user equipment accessing a 3GPP Evolved Packet Core (EPC) via a WLAN.

可以提供各种实施例,包括(但不限于)以下实施例。Various embodiments may be provided, including but not limited to the following.

在实施例中,所述3GPP AAA代理被配置为:In an embodiment, the 3GPP AAA proxy is configured to:

-在检测到不可能联系HPLMN中的3GPP AAA服务器以进行与用户设备的紧急情况相关联的接入认证尝试时,基于本地政策,将接入认证请求重定向到服务专用于对紧急服务的未认证接入的域的本地AAA服务器。- Upon detecting that it is impossible to contact the 3GPP AAA server in the HPLMN for an access authentication attempt associated with an emergency situation of the user equipment, redirecting the access authentication request to a local AAA server serving a domain dedicated to unauthenticated access to emergency services, based on local policy.

另一方面是一种用于针对未认证用户设备支持通过WLAN接入3GPP演进分组核心EPC的紧急服务的方法。Another aspect is a method for supporting emergency services for unauthenticated user equipment accessing a 3GPP Evolved Packet Core (EPC) over a WLAN.

根据各种组合可以提供各种实施例,包括(但不限于)以下可单独或组合地采用的实施例。Various embodiments may be provided according to various combinations, including but not limited to the following embodiments, which may be employed alone or in combination.

在实施例中,所述方法包括:In an embodiment, the method comprises:

-特定的3GPP AAA服务器服务专用于对紧急服务的未认证接入的域;向未认证用户设备准许接入;以及向所述UE提供允许对紧急服务的网络接入的特定授权数据。- A specific 3GPP AAA server serves a domain dedicated to unauthenticated access to emergency services; grants access to unauthenticated user equipment; and provides the UE with specific authorization data allowing network access to emergency services.

在实施例中,所述方法包括:In an embodiment, the method comprises:

-响应于提供用于接入认证的用户身份的请求,用户设备UE提供特定的基于NAI的用户身份,所述特定的用户身份具有指示对紧急服务的未认证接入的领域部分;- in response to a request to provide a user identity for access authentication, the user equipment UE provides a specific NAI-based user identity having a realm part indicating unauthenticated access to emergency services;

-诸如用于可信WLAN接入的TWAN实体或用于不可信WLAN接入的ePDG的认证装置基于所述领域部分向所述特定的3GPP AAA服务器路由来自所述UE的消息。- An authentication means such as a TWAN entity for trusted WLAN access or an ePDG for untrusted WLAN access routes the message from the UE towards the specific 3GPP AAA server based on the realm part.

在实施例中,所述方法包括:In an embodiment, the method comprises:

-在检测到不可能联系HPLMN中的3GPP AAA服务器以进行与用户设备的紧急情况相关联的接入认证尝试时,3GPP AAA代理基于本地政策将针对所述UE的接入认证请求重定向到服务专用于对紧急服务的未认证接入的域的本地AAA服务器。- Upon detecting that it is impossible to contact the 3GPP AAA server in the HPLMN for an access authentication attempt associated with an emergency situation of a user equipment, the 3GPP AAA proxy redirects the access authentication request for said UE to a local AAA server serving a domain dedicated to unauthenticated access to emergency services based on local policy.

在实施例中,所述方法包括:In an embodiment, the method comprises:

-3GPP AAA服务器向所述UE和所述认证装置指示接入对应于针对未认证设备的紧急服务的接入,并因此被限于支持紧急服务。- The 3GPP AAA server indicates to the UE and the authentication means that the access corresponds to access to emergency services for unauthenticated devices and is therefore restricted to supporting emergency services.

根据上述用户设备、认证装置、3GPP AAA服务器、3GPP AAA代理的各种实施例,可以提供所述方法的各种其它实施例。According to various embodiments of the above-mentioned user equipment, authentication device, 3GPP AAA server, and 3GPP AAA agent, various other embodiments of the method may be provided.

本领域的技术人员将容易认识到,各种上述方法的步骤可以由编程计算机执行。在本文中,一些实施例还旨在涵盖程序存储设备,例如数字数据存储介质,其是机器或计算机可读的并且对机器可执行或计算机可执行指令程序进行编码,其中所述指令执行上述方法中步骤的一部分或全部。程序存储设备例如可以是数字存储器、诸如磁盘和磁带的磁存储介质、硬盘驱动器或光学可读数字数据存储介质。这些实施例还旨在涵盖被编程为执行上述方法的所述步骤的计算机。Those skilled in the art will readily recognize that the steps of the various methods described above can be performed by a programmed computer. Some embodiments herein are also intended to encompass program storage devices, such as digital data storage media, which are machine or computer readable and encode a program of machine-executable or computer-executable instructions, wherein the instructions perform some or all of the steps of the methods described above. The program storage device can be, for example, a digital memory, a magnetic storage medium such as a disk or tape, a hard drive, or an optically readable digital data storage medium. These embodiments are also intended to encompass computers programmed to perform the steps of the methods described above.

Claims (12)

1.一种装置,包括:1. An apparatus comprising: 处理器;以及Processor; and 存储器,其存储有指令,所述指令在被执行时使所述装置:A memory that stores instructions, which, when executed, cause the device to: ·在用户设备与网络之间执行特定的基于可扩展认证协议的过程而无需相互认证,用于由所述用户设备通过可信无线局域网接入演进分组核心网络而接入紧急服务;• Perform a specific process based on an extensible authentication protocol between the user equipment and the network without mutual authentication, for the user equipment to access emergency services by accessing the evolved packet core network via a trusted wireless LAN; ·在所述过程内,从所述网络接收所述接入是针对无需认证的有限服务的指示;• During the process, receiving the access from the network is an indication for limited services that do not require authentication; ·在所述过程内,与所述网络协商用于所述接入的连接模式。• During the process, negotiate the connection mode for the access with the network. 2.根据权利要求1所述的装置,其中,所述指令在被执行时使所述装置:2. The apparatus of claim 1, wherein the instruction, when executed, causes the apparatus to: ·如果基于国际移动用户识别码的用户身份不能获得所述网络的认证,则接收所述指示。• If the user's identity based on the International Mobile Subscriber Identity (IMSI) cannot be authenticated by the network, then the instruction is received. 3.根据权利要求1所述的装置,其中,所述连接模式包括单连接模式和多连接模式中的一个。3. The apparatus according to claim 1, wherein the connection mode includes one of a single connection mode and a multiple connection mode. 4.根据权利要求1至3中任一项所述的装置,其中,所述指令在被执行时使所述装置:4. The apparatus according to any one of claims 1 to 3, wherein, when the instruction is executed, the apparatus: ·导出用于所述接入的主会话密钥,而无需使用加密密钥和完整性密钥,但使用由所述用户设备提供的身份。• Export the master session key used for the access without using the encryption key and integrity key, but using the identity provided by the user equipment. 5.一种用于通信的方法,包括:5. A method for communication, comprising: ·在用户设备与网络之间执行特定的基于可扩展认证协议的过程而无需相互认证,用于由所述用户设备通过可信无线局域网接入演进分组核心网络而接入紧急服务;• Perform a specific process based on an extensible authentication protocol between the user equipment and the network without mutual authentication, for the user equipment to access emergency services by accessing the evolved packet core network via a trusted wireless LAN; ·在所述过程内,从所述网络接收所述接入是针对无需认证的有限服务的指示;• During the process, receiving the access from the network is an indication for limited services that do not require authentication; ·在所述过程内,与所述网络协商用于所述接入的连接模式。• During the process, negotiate the connection mode for the access with the network. 6.根据权利要求5所述的方法,包括:6. The method according to claim 5, comprising: ·如果基于国际移动用户识别码的用户身份不能获得所述网络的认证,则接收所述指示。• If the user's identity based on the International Mobile Subscriber Identity (IMSI) cannot be authenticated by the network, then the instruction is received. 7.根据权利要求6所述的方法,其中,所述连接模式包括单连接模式和多连接模式中的一个。7. The method according to claim 6, wherein the connection mode includes one of a single connection mode and a multiple connection mode. 8.根据权利要求5至7中任一项所述的方法,包括:8. The method according to any one of claims 5 to 7, comprising: ·导出用于所述接入的主会话密钥,而无需使用加密密钥和完整性密钥,但使用由所述用户设备提供的身份。• Export the master session key used for the access without using the encryption key and integrity key, but using the identity provided by the user equipment. 9.一种装置,包括:9. An apparatus comprising: 处理器;以及Processor; and 存储器,其存储有指令,所述指令在被执行时使所述装置:A memory that stores instructions, which, when executed, cause the device to: ·在用户设备与网络之间执行特定的基于可扩展认证协议的过程而无需相互认证,用于由所述用户设备通过可信无线局域网接入演进分组核心网络而接入紧急服务;• Perform a specific process based on an extensible authentication protocol between the user equipment and the network without mutual authentication, for the user equipment to access emergency services by accessing the evolved packet core network via a trusted wireless LAN; ·在所述过程内,向所述用户设备发送所述接入是针对无需认证的有限服务的指示;• During the process, an indication is sent to the user equipment that the access is for a limited service that does not require authentication; ·在所述过程内,与所述用户设备协商用于所述接入的连接模式。• During the process, negotiate the connection mode for the access with the user equipment. 10.根据权利要求9所述的装置,其中,所述指令在被执行时使所述装置:10. The apparatus of claim 9, wherein the instruction, when executed, causes the apparatus to: ·如果基于国际移动用户识别码的用户身份不能获得所述网络的认证,则发送所述指示。• If the user's identity based on the International Mobile Subscriber Identity (IMSI) cannot be authenticated by the network, then the instruction is sent. 11.根据权利要求9所述的装置,其中,所述连接模式包括单连接模式和多连接模式中的一个。11. The apparatus of claim 9, wherein the connection mode includes one of a single connection mode and a multiple connection mode. 12.根据权利要求9至11中任一项所述的装置,其中,所述指令在被执行时使所述装置:12. The apparatus according to any one of claims 9 to 11, wherein the instructions, when executed, cause the apparatus to: ·导出用于所述接入的主会话密钥,而无需使用加密密钥和完整性密钥,但使用由所述用户设备提供的身份。• Export the master session key used for the access without using the encryption key and integrity key, but using the identity provided by the user equipment.
HK19120057.5A 2015-11-05 2016-11-03 Support of emergency services over wlan access to 3gpp evolved packet core for unauthenticated users HK1260371B (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
EP15306757.4 2015-11-05

Publications (2)

Publication Number Publication Date
HK1260371A1 HK1260371A1 (en) 2019-12-20
HK1260371B true HK1260371B (en) 2022-02-11

Family

ID=

Similar Documents

Publication Publication Date Title
CN108464027B (en) Supports emergency services for unauthenticated users accessing 3GPP Evolved Packet Core via WLAN
DK2642723T3 (en) DEVICE AND PROCEDURE FOR AUTHENTICATING A USER BY ACCESSING MULTIMEDIA SERVICES
CN101606372B (en) Support of UICC-less calls
EP3310018A1 (en) Access through a second mobile telecommunication network to services offered by a first mobile telecommunication network
US20130121322A1 (en) Method for establishing data connectivity between a wireless communication device and a core network over an ip access network, wireless communication device and communicatin system
US20170289883A1 (en) Emergency services handover between untrusted wlan access and cellular access
US20070143613A1 (en) Prioritized network access for wireless access networks
US20110271117A1 (en) User equipment (ue), home agent node (ha), methods, and telecommunications system for home network prefix (hnp) assignment
US11490252B2 (en) Protecting WLCP message exchange between TWAG and UE
JP6522799B2 (en) Method for discovering handover functionality of a mobile communication network, system for discovering handover functionality of a mobile communication network, user equipment, program and computer program product
EP1693995B1 (en) A method for implementing access authentication of wlan user
WO2010086029A1 (en) Method and radio communication system for establishing an access to a mobile network domain
CN108496398B (en) Method and device for supporting WLAN position change report or acquisition
EP3169033A1 (en) Support of imei checking procedure for wlan access by an user equipment to 3gpp evolved packet core
CN109479051B (en) Supporting a dedicated core network for WLAN access
HK1260371B (en) Support of emergency services over wlan access to 3gpp evolved packet core for unauthenticated users
HK1260371A1 (en) Support of emergency services over wlan access to 3gpp evolved packet core for unauthenticated users