[go: up one dir, main page]
More Web Proxy on the site http://driver.im/

CN105991479A - Access control method for shared type fixed access network - Google Patents

Access control method for shared type fixed access network Download PDF

Info

Publication number
CN105991479A
CN105991479A CN201510067488.4A CN201510067488A CN105991479A CN 105991479 A CN105991479 A CN 105991479A CN 201510067488 A CN201510067488 A CN 201510067488A CN 105991479 A CN105991479 A CN 105991479A
Authority
CN
China
Prior art keywords
access node
vno
access
user
described user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201510067488.4A
Other languages
Chinese (zh)
Inventor
杨水根
张凯宾
温海波
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nokia Shanghai Bell Co Ltd
Original Assignee
Alcatel Lucent Shanghai Bell Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alcatel Lucent Shanghai Bell Co Ltd filed Critical Alcatel Lucent Shanghai Bell Co Ltd
Priority to CN201510067488.4A priority Critical patent/CN105991479A/en
Publication of CN105991479A publication Critical patent/CN105991479A/en
Pending legal-status Critical Current

Links

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention provides an access control method for the shared type fixed access network. The shared type fixed access network comprises at least one access node and a controller, the access node comprises multiple virtual access nodes which are managed by virtual network operators (VNO) respectively. The method comprises that A) a scanning request is received from a user, and used to obtain available VNOs in the access node; B) IDs of the available VNOs are provided for the user; and C) a connection establishing request is received from the user, and used to require for establishing connection with the VNO selected by the user. According to the invention, the VNOs can provide different services, rely on the physical fixed access network is not needed, and limitations in the present fixed access network and a defect in flexibility are overcome.

Description

A kind of method being used for implementing Access Control in shared fixed access network
Technical field
The present invention relates to a kind of in shared fixed access network for implementing the side of Access Control Method.
Background technology
At present, it is exclusive that fixed access network is typically operator, the fixing access of such as telecommunications Net is merely able to be used alone by telecommunications.Access Control for obtaining the security request to service is Very important.The usual mode being currently used for controlling the access of service is based on certification, awards Power and (AAA) framework that accounts.But, owing to the AAA model of standard integrally controls To the access of fixing network, it will limit same user simultaneously to multiple different operators The access of service.Such as, in the case of user is linked into communication network, if this user While obtaining the service (such as, video, voice) that telecommunications is provided, want again to pass through This communication network obtains the service of UNICOM, and this can not realize under AAA model.
In future, owing to trend is shared by fixed access network, therefore it will be more and more open, To overcome present in the current fixed access network, some limit and motility defects.Become at this In gesture, fixed access network can be disposed by an infrastructure device business, and this fixed access network can To share to multiple VNO (visual network operator, VNO) simultaneously (such as, telecommunications, UNICOM etc.).The virtual fixed access network being consequently formed can be by accordingly VNO operation, control and manage.VNO provides various different service subsequently, and nothing The fixed access network of physics need to be depended on.
Summary of the invention
Here, the present invention will be based on above-mentioned background, it is proposed that a kind of in shared fixing access For the method for Access Control in net, it enables to unique user can be same in use VNO, service and and these clothes are freely selected under conditions of fixed access network Be engaged in relevant service provider, namely this user can enjoy in Same Physical network simultaneously The service of different VNOs.
According to the first aspect of the invention, it is proposed that a kind of in shared fixed access network For the method implementing Access Control, wherein said shared fixed access network in access node Including at least one access node and controller, and described access node includes multiple virtual Access node, it manages by multiple VNOs respectively, and described method includes: A. from User receives scan request, and it is for obtaining virtual network fortune available in described access node Battalion business;B., the ID of available VNO is provided to described user;And C. from Described user receives connection establishment request, and it is used for indicating described user to ask to set up to described The connection of the VNO that user selects.
According to the second aspect of the invention, it is proposed that a kind of in shared fixed access network For assisting the method implementing Access Control, wherein said shared fixed access network in user Including at least one access node, and each access node includes multiple virtual access node, It is managed by multiple VNOs respectively, and described method includes: send out to access node Sending scan request, it is for obtaining VNO available in described access node; The ID of available VNO is received from described access node;From described available void Intend Virtual network operator selects a VNO;And send out to described access node Sending connection establishment to ask, it is set up to described user selection for indicating described user to ask The connection of VNO.
According to the third aspect of the invention we, it is proposed that a kind of in shared fixed access network For the method implementing Access Control, wherein said shared fixed access network bag in controller Include at least one access node, and each access node include multiple virtual access node, It is managed by multiple VNOs respectively, and described method includes: connect from access node Receiving scan request, it is for obtaining VNO available in described access node; The ID of available VNO is sent to described access node;From described access node Reception connection establishment is asked, and it asks to set up the void selected to described user for indicating user Intend the connection of Virtual network operator;And sending configuration information to described access node, it includes The ID of VNO that described user selects and corresponding with this VNO The ID of virtual access node.
According to the fourth aspect of the invention, it is proposed that a kind of in shared fixed access network For the method implementing Access Control, wherein said shared fixing access in aaa server Net includes at least one access node and controller, and each access node includes multiple void Intending access node, it is managed by multiple VNOs respectively, and each virtual network is transported Battalion business includes that aaa server, described method include respectively: receives to access from access node and asks Ask the ID of service that message, described access request message includes that user needs, described user choosing The VNO that the ID of the VNO selected selects with described user is corresponding The ID of virtual access node.
Therefore, by the present invention, user can determine it from which VNO accesses to independently Service supplier.This means its multiple users that allow for sharing identical fixed access network Different VNO can be used to access identical or different service simultaneously.Additionally, by this Invention makes physics fixed access network can be shared by multiple virtual networks.These virtual networks Can be operated by VNO, control and manage.By according to the solution of the present invention, VNO energy Different services is enough provided, and need not rely upon physics fixed access network.The present invention is well Avoid the restriction in existing fixed access network and motility defect, therefore will be by widely Use.
Accompanying drawing explanation
By reading retouching in detail with reference to made non-limiting example is made of the following drawings Stating, the other features, objects and advantages of the present invention will become more apparent:
Fig. 1 shows the framework of shared fixed access network according to an embodiment of the invention Schematic diagram;
Fig. 2 shows a kind of in shared fixed access network according to an embodiment of the invention For the method implementing Access Control;And
Fig. 3 shows a kind of at shared fixed access network in accordance with another embodiment of the present invention In for the method for implementing Access Control.
In the drawings, running through different diagrams, same or similar reference represents identical or phase Corresponding parts or feature.
Detailed description of the invention
Herein propose for shared fixed access network share Access Control scheme based on Following basic ideas:
The VNO choice phase: user selects in multiple VNO and sets up to VNO Connection.At this stage, such as user can ask to obtain in shared fixing access The list of VNO accessible in net.Such as, these accessible VNO are with VNO ID Mode present.In order to improve extensibility and the management of network, each virtual access node Identified with unique ID by VNO, referred to as virtual access node (VAN) ID.This frame Structure mode (combination of VNO ID and VAN ID) allows each VNO all of to name VAN, and specify that the corresponding relation of all of VAN of VNO and its management.When complete After becoming the VNO choice phase, AAA aspect is open for a user, can be used for Further process, and data plane is still closed.
The AAA stage: complete Access Control, to obtain the security request to service.At this Stage, to extend existing AAA flow process in the following way:
(1) upon receipt of the access request message sent by user, access point will thereon Affix corresponding VAN ID, and this message is forwarded to aaa server.
(2) in order to solve the multiple AAA processing procedures from identical user, in AN Port is divided into and services associated plurality of example with each.Each example is by from user The source & destination-mac address mark of message, vlan identifier and/or any other be suitable for Identifier identify.Thus, the physical port of AN will be such as divided into respectively with user Multiple logic ports of the multiple service correspondences required, such that it is able to process same use simultaneously The multiple service request at family.
(3) aaa server defines and is associated with the service that must be processed by Network Provider Policy.
(4) fixed access network controller configuration AN, to control the access to each service, And the normal offer of service is provided.After the AAA stage completes, data plane is to user For be also open, for access service.
Fig. 1 shows the frame of shared fixed access network according to an embodiment of the invention Structure schematic diagram.Schematically illustrate 3 users in FIG, i.e. user 1, user 2, User 3.Additionally, figure 1 illustrates access node AN.In this embodiment, This access node AN is divided into 2 VAN, namely VAN1 and VAN2.Above-mentioned two Individual VAN is respectively by two VNO1 and VNO2 management.In VNO1 and VNO2 respectively It is configured with an aaa server.Here, exemplarily only show an access node, It will be appreciated by those skilled in the art that actually, can have an arbitrarily access node, and Each VNO can also manage the multiple VAN being distributed in multiple access node.Additionally, Schematically illustrate three kinds of services, namely service 1, service 2, service 3 in FIG, It can be provided by identical and/or different service provider.Service 1 can be such as to regard Be taken in small doses at short intervals business, and service 2 can be such as voice service, and servicing 3 can be such as that network connects Enter.Thus, said structure constitutes multiple virtual fixed access network (VFAN).
Therefore, in FIG, AN is virtualized into some bursts for sharing the net of physics Network, the most each VAN has the aaa server of himself.Each VAN is by its VNO Operate, control and manage.VNO comes by providing safety, nomadic access or multicast support Improve service to provide.Each VNO is identified by unique VNO ID.Further, each AN Burst is identified by the unique ID (VAN ID) in VNO.As it was previously stated, by this The framework of (combination of VNO ID and VAN ID) can easily improve the expansible of network Property and management.Here, the architecture combined of this VNO ID and VAN ID allows each VNO Name all relevant VAN.Additionally, configured AN by controller, to control to each The normal offer accessing and guaranteeing service of service.Controller the most such as can provide mobile Property management, call treatment, url management and handover mechanism.By above-mentioned framework, it is allowed to altogether The multiple users enjoying identical first mile (first mile) use different operators to come simultaneously Access identical or different service.
Fig. 2 shows a kind of at shared fixed access network according to an embodiment of the invention In for the method for implementing Access Control.In the embodiment of fig. 2, do not have in AN The list of currently available VNO.Therefore, user must from controller obtain available The list of VNO.
Flow chart in Fig. 2 is to operate mould for general AAA based on IEEE 802.1X The extension of type.This main flow process includes two stages: the VNO choice phase (step 1 to 5) and the AAA stage (step 6 to 15).
As in figure 2 it is shown, step 1: user's (via broadcast or clean culture) sends scan request and disappears Breath, to obtain VNO available in AN.This scan request message will be forwarded by AN To controller for processing further.
Step 2: in response to this request, controller sends available virtual network operation to AN Business ID.Such as, controller can be with one packet of clean culture, and it is included in AN accessible The list of VNO.
Step 3: user select from available VNO a VNO and ask set up to The connection of this VNO.Specifically, AN receives connection establishment request from user, and it is used for referring to Show the VNO that user selects.Then, AN forwards the request to controller.
Step 4: controller is responded with specific network configuration parameters.Such as, controller will be joined Confidence breath is sent to AN.These network configuration parameters and the VNO must being configured on AN Corresponding.This configuration information such as include the VNO that user selects ID and with this VNO pair The VAN ID answered.Here, the important parameter of the two is to have to use in the AAA stage VNO ID and VAN ID.
Step 5: after completing the VNO choice phase, AAA aspect is for a user Open, can be used for further processing, and data plane is still closed.Here, as front Described, in order to solve the multiple AAA processing procedures from identical user, the end in AN Mouth is divided into and services associated plurality of example with each.Each example is by from user's The source & destination-mac address mark of message, vlan identifier and/or any other be suitable for Identifier identifies.Thus, the physical port of AN will be such as divided into and be wanted with user respectively Multiple logic ports of the multiple service correspondences asked, such that it is able to process same user simultaneously Multiple service request.
Step 6: user starts the AAA stage by sending EAPoL start message.
Step 7:AN sends instruction message to user, and its instruction user provides it required Service ID.Step 6 and 7 such as can be corresponding to the corresponding step in AAA model.
Step 8: user is responded by access request message.This access request message includes needing The ID of the VNO that the service ID wanted and user select.
Step 9:AN upon receipt of access request message, AN by affix wherein with The ID of the VAN corresponding for VNO that user selects, and this access request message is sent extremely The aaa server of the VNO that user selects.
In subsequent step 10 to 15, user provides with AN, aaa server, service Business and controller make user access the service of needs alternately.These steps can phase Should be in the corresponding step in AAA model.Reader interested can also see AAA mould Type obtains details.Following step will be simply introduced at this.
Step 10: user and aaa server start EAP alternately based on unitcast request-response Request and response.
The definition of step 11:AAA server is associated with the service that must be processed by VNO Policy.Such as: the quality of the idle bandwidth in VFAN, the quality of service request (are trembled Dynamic, time delay etc.).Relevant policies are determined to be sent to controller by aaa server.
Step 12: controller will perform the policy of aaa server definition, and configures AN Control the access to each service, so that it is guaranteed that the normal offer of service.
Step 13: upon configuration, the data Layer user oriented of AN is open, for accessing clothes Business.
Step 14: carry out 4 four hand shake procedure between user and AN.
Step 15: behind, completes the AAA stage, and user can be via selected by it VNO access to request service.
Although it will be appreciated by those skilled in the art that only describing user at this obtains a kind of clothes The mode of business, but this mode can also be applied to multiple service.
Fig. 3 shows a kind of in shared fixing access in accordance with another embodiment of the present invention For the method implementing Access Control in net.This main flow process includes two stage: VNO Choice phase (step 1 to 4) and AAA stage (step 5 to 14).In this embodiment In, AN has the list of available VNO.This such as can implement by being pre-configured with.
Step 1: user's (via broadcast or clean culture) sends scan request message, to obtain VNO available in AN.
Step 2: in response to this request, AN sends available VNO to user ID.AN such as can be with one packet of clean culture, and it is included in AN accessible VNO List.
Step 3: user select from available VNO a VNO and ask set up to The connection of this VNO.Specifically, AN receives connection establishment request from user, and it is used for referring to Show the VNO that user selects.
Step 4 is identical with corresponding step 5-15 in first embodiment to 14.At this not Describing in detail, reader interested may refer to the corresponding step in first embodiment again.
It should be noted that above-described embodiment is only exemplary, rather than the limit to the present invention System.Any technical scheme without departing substantially from spirit of the present invention all should fall into protection scope of the present invention Within, this includes using the different technologies feature occurred in different embodiments to be combined, To obtain beneficial effect.Additionally, " an including " word is not excluded for other claim or explanation Device unlisted in book or step.

Claims (14)

1. for implementing Access Control in the access node in shared fixed access network Method, wherein said shared fixed access network includes at least one access node and controller, And described access node includes multiple virtual access node, it is transported by multiple virtual networks respectively Battalion's business's management, described method includes:
A. receiving scan request from user, it is available virtual for obtaining in described access node Virtual network operator;
B., the ID of available VNO is provided to described user;And
C. receiving connection establishment request from described user, it is used for indicating described user to ask to set up Connection to the VNO that described user selects.
Method the most according to claim 1, it is characterised in that when in described access node In when not having about the information of available VNO, described step B farther includes:
B1. described scan request is forwarded to described controller;
B2. the ID of available VNO is received from described controller;
B3. the ID of described available VNO is forwarded to described user;
And described step C farther includes:
The request of described connection establishment is forwarded to described controller.
Method the most according to claim 2, it is characterised in that described method also includes step Rapid D:
Receiving configuration information from described controller, it includes the virtual network fortune that described user selects The ID and the ID of the virtual access node corresponding with this VNO of battalion business.
4. according to the method described in claim 1 or 3, it is characterised in that described method is also wrapped Include following steps:
EAPOL-Start message is received from described user;And
Sending instruction message to described user, its described user of instruction provides the ID of the service of needs.
Method the most according to claim 4, it is characterised in that described method also include with Lower step:
Receiving access request message from described user, described access request message includes the clothes of needs The ID of the VNO that the ID of business and described user select;And
The VNO that affix selects with described user in described access request message The ID of corresponding virtual access node, and this access request message is sent to described user choosing The aaa server of the VNO selected.
Method the most according to claim 5, it is characterised in that described method also include as Lower step: mutual with described aaa server, service provider, controller and described user Described user is made to access the service of needs.
7. for assisting enforcement Access Control in the user in shared fixed access network Method, wherein said shared fixed access network includes at least one access node, and each Access node includes multiple virtual access node, and it is managed by multiple VNOs respectively, Described method includes:
Sending scan request to access node, it is for obtaining void available in described access node Intend Virtual network operator;
The ID of available VNO is received from described access node;
A VNO is selected from described available VNO;And
Sending connection establishment request to described access node, it is used for indicating described user request to build Stand to described user the connection of the VNO selected.
Method the most according to claim 7, it is characterised in that described method also include as Lower step:
EAPOL-Start message is sent to described access node;And
Receiving instruction message from described access node, it indicates described user to provide the service of needs ID.
Method the most according to claim 8, it is characterised in that described method also include as Lower step:
Sending access request message to described access node, described access request message includes needs The ID of service and the ID of VNO that selects of described user.
Method the most according to claim 9, it is characterised in that described method also include as Lower step: make the service that described user accesses described needs alternately with described access node.
For implementing Access Control in 11. 1 kinds of controllers in shared fixed access network Method, wherein said shared fixed access network includes at least one access node, and each Access node includes multiple virtual access node, and it is managed by multiple VNOs respectively, Described method includes:
Receiving scan request from access node, it is for obtaining void available in described access node Intend Virtual network operator;
The ID of available VNO is sent to described access node;
Receive connection establishment request from described access node, its be used for indicating user ask to set up to The connection of the VNO that described user selects;And
Sending configuration information to described access node, it includes the virtual network that described user selects The ID and the ID of the virtual access node corresponding with this VNO of operator.
12. methods according to claim 11, it is characterised in that described method also includes Following steps: mutual with the aaa server of described access node and described VNO Described user is made to access the service of needs.
13. 1 kinds of aaa servers in shared fixed access network are used for implement to access control The method of system, wherein said shared fixed access network includes at least one access node and control Device, and each access node includes multiple virtual access node, and it is respectively by multiple virtual nets Network operator manages, and each VNO includes aaa server, described method respectively Including:
Receiving access request message from access node, described access request message includes that user needs The ID of service, the ID of VNO that selects of described user and described user select The ID of virtual access node corresponding to VNO.
14. methods according to claim 13, it is characterised in that described method also includes Following steps: make described user access the service of needs alternately with described controller.
CN201510067488.4A 2015-02-09 2015-02-09 Access control method for shared type fixed access network Pending CN105991479A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510067488.4A CN105991479A (en) 2015-02-09 2015-02-09 Access control method for shared type fixed access network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510067488.4A CN105991479A (en) 2015-02-09 2015-02-09 Access control method for shared type fixed access network

Publications (1)

Publication Number Publication Date
CN105991479A true CN105991479A (en) 2016-10-05

Family

ID=57040965

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510067488.4A Pending CN105991479A (en) 2015-02-09 2015-02-09 Access control method for shared type fixed access network

Country Status (1)

Country Link
CN (1) CN105991479A (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113852534A (en) * 2020-06-28 2021-12-28 上海诺基亚贝尔股份有限公司 Method and equipment for transmitting traffic of VNO access network slice through PBB tunnel

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1934891A (en) * 2004-03-23 2007-03-21 艾利森电话股份有限公司 Method of and system for selecting a PLMN for network sharing
CN101394610A (en) * 2008-11-10 2009-03-25 华为技术有限公司 Method and device for realizing network sharing under network gateway core network configuration
CN101500278A (en) * 2008-02-01 2009-08-05 华为技术有限公司 Method, apparatus and system for selecting wireless network cell
CN103155667A (en) * 2010-09-27 2013-06-12 阿尔卡特朗讯公司 Method and base station system for providing access to a mobile communication network
CN103516760A (en) * 2012-06-28 2014-01-15 上海贝尔股份有限公司 Virtual network system accessing method, device and system

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1934891A (en) * 2004-03-23 2007-03-21 艾利森电话股份有限公司 Method of and system for selecting a PLMN for network sharing
CN101500278A (en) * 2008-02-01 2009-08-05 华为技术有限公司 Method, apparatus and system for selecting wireless network cell
CN101394610A (en) * 2008-11-10 2009-03-25 华为技术有限公司 Method and device for realizing network sharing under network gateway core network configuration
CN103155667A (en) * 2010-09-27 2013-06-12 阿尔卡特朗讯公司 Method and base station system for providing access to a mobile communication network
CN103516760A (en) * 2012-06-28 2014-01-15 上海贝尔股份有限公司 Virtual network system accessing method, device and system

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113852534A (en) * 2020-06-28 2021-12-28 上海诺基亚贝尔股份有限公司 Method and equipment for transmitting traffic of VNO access network slice through PBB tunnel
CN113852534B (en) * 2020-06-28 2022-09-27 上海诺基亚贝尔股份有限公司 Method and equipment for transmitting traffic of VNO access network slice through PBB tunnel

Similar Documents

Publication Publication Date Title
WO2020073919A1 (en) Packet transmission method and apparatus
JP6995189B2 (en) Data transmission methods, devices, and systems
CN112235121B (en) Method, device, equipment and storage medium for realizing online conference
CN102137401B (en) WLAN centralization 802.1X authentication methods and device and system
CN105338023B (en) A kind of method, apparatus and system of smart machine control
CN111436160A (en) Local area network communication method, device and system
US20150029302A1 (en) Multi-enterprise video conference service
EP2624525A1 (en) Method, apparatus and virtual private network system for issuing routing information
US9191378B2 (en) Communication apparatus and communication method
US11284271B2 (en) Extending wireless local guest access to private radio services
EP4221126A1 (en) Network slice usage
KR20210044831A (en) Session management method and device for user group
US20210337463A1 (en) Systems and methods for prioritizing service set identifiers on a wireless access point
WO2019042912A1 (en) Application function in a network and control thereof
US8914520B2 (en) System and method for providing enterprise integration in a network environment
US8611358B2 (en) Mobile network traffic management
CN112134866B (en) Service access control method, device and system and computer readable storage medium
US20150256627A1 (en) Method and system for establishing a connection between a seeker device and a target device
KR20170125929A (en) METHOD, DEVICE, AND SYSTEM
US12081534B2 (en) Onboarding client device to user-defined network using federation-based network identity
WO2016179966A1 (en) Method for realizing network access, terminal and computer storage medium
CN104254129B (en) Close on the resource allocation method and device of service discovering
US20230254292A1 (en) Private and Secure Chat Connection Mechanism for Use in a Private Communication Architecture
CN103987091B (en) A kind of service bandwidth variation, controller and system
CN109891921A (en) The certification of Successor-generation systems

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information
CB02 Change of applicant information

Address after: 201206 Shanghai, Pudong Jinqiao Ning Bridge Road, No. 388, No.

Applicant after: Shanghai NOKIA Baer Limited by Share Ltd

Address before: 201206 Shanghai, Pudong Jinqiao Ning Bridge Road, No. 388, No.

Applicant before: Shanghai Alcatel-Lucent Co., Ltd.

RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20161005